diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index d5ac949e9d06..681d985efceb 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -27749,6 +27749,12 @@ githubId = 1939855; name = "Kimmo Suominen"; }; + suorcd = { + email = "fair.sand8703@fastmail.com"; + github = "suorcd"; + githubId = 60907848; + name = "suorcd"; + }; supa = { email = "supa.codes@gmail.com"; github = "0Supa"; diff --git a/nixos/doc/manual/release-notes/rl-2611.section.md b/nixos/doc/manual/release-notes/rl-2611.section.md index deb30bbdc45c..496e5eb33a5c 100644 --- a/nixos/doc/manual/release-notes/rl-2611.section.md +++ b/nixos/doc/manual/release-notes/rl-2611.section.md @@ -64,6 +64,8 @@ - [P2Pool](https://github.com/SChernykh/p2pool), a decentralized mining pool for Monero. Available as [services.p2pool](#opt-services.p2pool.enable). +- [SSTorytime](https://github.com/markburgess/SSTorytime), graph knowledge base on PostgreSQL with an N4L CLI and a small HTTP UI. Available as [services.sstorytime](#opt-services.sstorytime.enable). + - [Freescout](https://freescout.net/), a free, open source Helpdesk and shared mailbox. Available as [services.freescout](#opt-services.freescout.enable). - [Lix TOML remote builders](https://docs.lix.systems/manual/lix/stable/advanced-topics/distributed-builds.html#using-a-toml-configuration), remote builder configuration using lix's TOML format. Available as [lix.buildMachines](#opt-lix.buildMachines). Note: incompatible with `nix.buildMachines`. @@ -76,6 +78,8 @@ - [Solaar](https://github.com/pwr-Solaar/Solaar), a program to control logitech devices. +- [Kener](https://kener.ing), a modern, open-source status page application built with Node.js. Available as [services.kener](#opt-services.kener.enable). + - [FlapAlerted](https://github.com/Kioubit/FlapAlerted), detects BGP flapping events and provides statistics based on BGP update messages. Available as [services.flap-alerted](#opt-services.flap-alerted.enable). - [gocron](https://github.com/flohoss/gocron), a task scheduler with web interface. Available as [services.gocron](#opt-services.gocron.enable). diff --git a/nixos/modules/misc/documentation/modular-services.nix b/nixos/modules/misc/documentation/modular-services.nix index 102fa396a758..7fab6c1b456b 100644 --- a/nixos/modules/misc/documentation/modular-services.nix +++ b/nixos/modules/misc/documentation/modular-services.nix @@ -27,6 +27,7 @@ let "" = fakeSubmodule pkgs.ktls-utils.services.default; "" = fakeSubmodule pkgs.php.services.default; "" = fakeSubmodule pkgs.snid.services.default; + "" = fakeSubmodule pkgs.trailbase.services.default; }; }; in diff --git a/nixos/modules/module-list.nix b/nixos/modules/module-list.nix index 981e0f4ecf44..4587363a2993 100644 --- a/nixos/modules/module-list.nix +++ b/nixos/modules/module-list.nix @@ -1069,6 +1069,7 @@ ./services/monitoring/incron.nix ./services/monitoring/kapacitor.nix ./services/monitoring/karma.nix + ./services/monitoring/kener.nix ./services/monitoring/kthxbye.nix ./services/monitoring/librenms.nix ./services/monitoring/loki.nix @@ -1841,6 +1842,7 @@ ./services/web-apps/sogo.nix ./services/web-apps/speedtest-tracker.nix ./services/web-apps/sshwifty.nix + ./services/web-apps/sstorytime.nix ./services/web-apps/stash.nix ./services/web-apps/stirling-pdf.nix ./services/web-apps/strfry.nix diff --git a/nixos/modules/security/tpm2.nix b/nixos/modules/security/tpm2.nix index b7e5bdd98cd6..91344069edf4 100644 --- a/nixos/modules/security/tpm2.nix +++ b/nixos/modules/security/tpm2.nix @@ -273,6 +273,23 @@ in (lib.getLib cfg.pkcs11.package) ]; + # Register the module with p11-kit, so that PKCS#11 consumers going + # through the p11-kit proxy (e.g. the OpenSSL pkcs11 engine/provider + # from libp11, GnuTLS, Firefox) discover the TPM2 token without + # per-application module path configuration. + # Upstream ships this registration and installs it into p11-kit's + # module config directory, as queried from p11-kit's pkg-config; see + # https://github.com/tpm2-software/tpm2-pkcs11/blob/1.10.1/misc/p11-kit/tpm2_pkcs11.module + # On NixOS that directory is p11-kit's own immutable store path, so + # the file never reaches the p11-kit actually in use. Register the + # module in the system config directory instead (/etc/pkcs11, from + # p11-kit's --sysconfdir=/etc), which p11-kit reads at runtime. + environment.etc."pkcs11/modules/tpm2_pkcs11.module" = lib.mkIf cfg.pkcs11.enable { + text = '' + module: ${lib.getLib cfg.pkcs11.package}/lib/libtpm2_pkcs11.so + ''; + }; + services.udev.extraRules = lib.mkIf cfg.applyUdevRules (udevRules cfg.tssUser cfg.tssGroup); # Create the tss user and group only if the default value is used diff --git a/nixos/modules/services/monitoring/kener.nix b/nixos/modules/services/monitoring/kener.nix new file mode 100644 index 000000000000..fcd8480b7b8f --- /dev/null +++ b/nixos/modules/services/monitoring/kener.nix @@ -0,0 +1,156 @@ +{ + config, + options, + pkgs, + lib, + ... +}: +let + cfg = config.services.kener; + opt = options.services.kener; + isRedisUnixSocket = lib.hasPrefix "/" cfg.redis.host; +in +{ + + meta.maintainers = [ lib.maintainers.albertlarsan68 ]; + + options = { + services.kener = { + enable = lib.mkEnableOption "Kener, this assumes a reverse proxy to be set"; + + package = lib.mkPackageOption pkgs "kener" { }; + + environmentFile = lib.mkOption { + type = lib.types.path; + default = null; + description = "Environment file, to put KENER_SECRET_KEY and other sensible values."; + }; + + redis = { + createLocally = lib.mkOption { + description = '' + Whether to configure a local Redis server for Kener. + The connection is performed via Unix sockets by default, + but that can be changed by disabling this option and + configuring {option}`${opt.redis.host}` and {option}`${opt.redis.port}`. + ''; + type = lib.types.bool; + default = true; + }; + host = lib.mkOption { + type = lib.types.str; + default = config.services.redis.servers.kener.unixSocket; + defaultText = lib.literalExpression "config.services.redis.servers.kener.unixSocket"; + description = "The host that redis will listen on."; + }; + port = lib.mkOption { + type = lib.types.port; + default = 0; + description = "The port that redis will listen on. Set to zero to disable TCP."; + }; + }; + + settings = lib.mkOption { + type = lib.types.submodule { freeformType = with lib.types; attrsOf str; }; + default = { }; + example = { + PORT = "4000"; + NODE_EXTRA_CA_CERTS = lib.literalExpression "config.security.pki.caBundle"; + }; + description = '' + Additional configuration for Kener, see + + for supported values. + ''; + }; + }; + }; + + config = lib.mkIf cfg.enable { + assertions = [ + { + assertion = ( + config.services.kener.redis.createLocally + -> (config.services.kener.redis.host == config.services.redis.servers.kener.unixSocket) + ); + message = "createLocally should only be used with the local unix socket"; + } + ]; + + services.redis.servers = lib.mkIf cfg.redis.createLocally { + kener = { + enable = true; + port = cfg.redis.port; + bind = lib.mkIf (!isRedisUnixSocket) cfg.redis.host; + }; + }; + + services.kener.settings = + let + redisEnv = + if isRedisUnixSocket then + { REDIS_URL = "unix://${cfg.redis.host}"; } + else + { + REDIS_URL = "redis://${cfg.redis.host}:${toString cfg.redis.port}"; + }; + in + redisEnv + // { + NODE_ENV = lib.mkDefault "production"; + DATABASE_URL = lib.mkDefault "sqlite:///var/lib/kener/kener.sqlite.db"; + HOST = lib.mkDefault "127.0.0.1"; + PORT = lib.mkDefault "3001"; + }; + + systemd.services.kener = { + description = "Kener"; + after = [ "network.target" ] ++ lib.optional cfg.redis.createLocally "redis-kener.service"; + wantedBy = [ "multi-user.target" ]; + environment = cfg.settings; + path = with pkgs; [ unixtools.ping ]; + serviceConfig = { + Type = "simple"; + StateDirectory = "kener"; + StateDirectoryMode = "750"; + DynamicUser = true; + ExecStart = "${cfg.package}/bin/kener-server"; + Restart = "on-failure"; + AmbientCapabilities = ""; + CapabilityBoundingSet = ""; + LockPersonality = true; + MemoryDenyWriteExecute = false; # enabling it breaks execution + MountAPIVFS = true; + NoNewPrivileges = true; + PrivateDevices = true; + PrivateMounts = true; + PrivateTmp = true; + PrivateUsers = true; + ProtectClock = true; + ProtectControlGroups = "strict"; + ProtectHome = true; + ProtectHostname = true; + ProtectKernelLogs = true; + ProtectKernelModules = true; + ProtectKernelTunables = true; + ProtectProc = "invisible"; + ProtectSystem = "strict"; + RemoveIPC = true; + RestrictAddressFamilies = [ + "AF_INET" + "AF_INET6" + "AF_UNIX" + "AF_NETLINK" + ]; + RestrictNamespaces = true; + RestrictRealtime = true; + RestrictSUIDSGID = true; + SystemCallArchitectures = "native"; + UMask = 27; + SupplementaryGroups = lib.mkIf (cfg.redis.createLocally && isRedisUnixSocket) [ + config.services.redis.servers.kener.group + ]; + }; + }; + }; +} diff --git a/nixos/modules/services/networking/pdns-recursor.nix b/nixos/modules/services/networking/pdns-recursor.nix index bed9eb636086..76d5dc51a829 100644 --- a/nixos/modules/services/networking/pdns-recursor.nix +++ b/nixos/modules/services/networking/pdns-recursor.nix @@ -94,6 +94,13 @@ in ''; }; + api.enable = mkEnableOption '' + the built-in webserver. It serves the REST API (which additionally needs + an API key set via {option}`services.pdns-recursor.settings.webservice.api_key`) + and, at `/metrics`, statistics in Prometheus format. Without this the + `api.address`, `api.port` and `api.allowFrom` options have no effect, as + the webserver stays disabled''; + api.address = mkOption { type = types.str; default = "0.0.0.0"; @@ -222,6 +229,7 @@ in }; webservice = mkDefaultAttrs { + webserver = cfg.api.enable; address = cfg.api.address; port = cfg.api.port; allow_from = cfg.api.allowFrom; diff --git a/nixos/modules/services/web-apps/sstorytime.nix b/nixos/modules/services/web-apps/sstorytime.nix new file mode 100644 index 000000000000..0a9184afa13e --- /dev/null +++ b/nixos/modules/services/web-apps/sstorytime.nix @@ -0,0 +1,284 @@ +{ + config, + lib, + pkgs, + ... +}: +let + inherit (lib) + mkEnableOption + mkPackageOption + mkOption + mkIf + mkDefault + mkMerge + types + ; + + cfg = config.services.sstorytime; + dbName = "sstoryline"; + configPath = "/etc/sstorytime"; + stateDir = "/var/lib/sstorytime"; + + defaultDatabaseUri = "postgresql://${dbName}@/${dbName}?host=/run/postgresql"; + + commonServiceConfig = { + User = dbName; + Group = dbName; + StateDirectory = "sstorytime"; + WorkingDirectory = "%S/sstorytime"; + EnvironmentFile = lib.optional (cfg.environmentFile != null) cfg.environmentFile; + }; + + # linkding-manage / lasuite-*-manage: same user/state/env as the long-running unit. + systemdRunArgs = lib.escapeShellArgs ( + [ + "--quiet" + "--collect" + "--pipe" + "--wait" + "--service-type=exec" + "--uid=${commonServiceConfig.User}" + "--gid=${commonServiceConfig.Group}" + "--working-directory=${stateDir}" + "--property=StateDirectory=${commonServiceConfig.StateDirectory}" + ] + ++ lib.optional (cfg.environmentFile != null) "--property=EnvironmentFile=${cfg.environmentFile}" + ++ lib.mapAttrsToList (name: value: "--setenv=${name}=${value}") ( + cfg.settings + // { + PATH = lib.makeBinPath [ cfg.package ]; + } + ) + ++ [ "--" ] + ); + + sstorytime-run = pkgs.writeShellApplication { + name = "sstorytime-run"; + text = '' + exec ${lib.getExe' config.systemd.package "systemd-run"} \ + ${systemdRunArgs} \ + "$@" + ''; + }; +in +{ + meta.maintainers = lib.teams.ngi.members; + + options.services.sstorytime = { + enable = mkEnableOption "SSTorytime, a unified graph process for mapping knowledge"; + + package = mkPackageOption pkgs "sstorytime" { }; + + openFirewall = mkEnableOption "opening the SSTorytime ports in the firewall"; + + httpPort = mkOption { + type = types.port; + default = 8080; + description = "HTTP listen port (redirects to HTTPS)."; + }; + + httpsPort = mkOption { + type = types.port; + default = 8443; + description = "HTTPS listen port for the web UI and API."; + }; + + configDir = mkOption { + type = types.path; + default = "${cfg.package}/share/SSTconfig"; + defaultText = lib.literalExpression ''"''${config.services.sstorytime.package}/share/SSTconfig"''; + description = '' + Directory that contains configuration files to be installed under + {file}`${configPath}`. + ''; + }; + + settings = mkOption { + type = types.submodule { + freeformType = types.attrsOf (types.nullOr types.str); + options = { + POSTGRESQL_URI = mkOption { + type = types.nullOr types.str; + default = null; + example = "postgresql://sstoryline@/sstoryline?host=/run/postgresql"; + description = '' + PostgreSQL connection URI. When + {option}`database.createLocally` is true, defaults to a peer-auth + socket URI. For remote databases prefer + {option}`environmentFile` if the URI contains secrets. + ''; + }; + + SST_CONFIG_PATH = mkOption { + type = types.nullOr types.str; + default = null; + example = configPath; + description = '' + Directory of SSTconfig ontology files (arrows, closures, …). + Defaults to {file}`${configPath}` when the service is enabled. + ''; + }; + }; + }; + default = { }; + apply = lib.filterAttrs (_: v: v != null); + example = { + POSTGRESQL_URI = "postgresql://sstoryline@/sstoryline?host=/run/postgresql"; + }; + description = '' + Environment for the service and {command}`sstorytime-run`. + Null values are omitted. Extra freeform keys are passed through as + additional environment variables. + ''; + }; + + environmentFile = mkOption { + type = types.nullOr types.path; + default = null; + example = "/run/secrets/sstorytime.env"; + description = '' + Optional EnvironmentFile (e.g. secrets for `POSTGRESQL_URI` via sops). + Used by the service and by {command}`sstorytime-run`. + ''; + }; + + database = { + createLocally = mkOption { + type = types.bool; + default = true; + description = '' + Local PostgreSQL role/database `sstoryline` and default + {option}`settings.POSTGRESQL_URI` using the Unix socket at + {file}`/run/postgresql` (peer auth as user `sstoryline`). + ''; + }; + }; + + finalPackage = mkOption { + type = types.package; + visible = false; + readOnly = true; + default = sstorytime-run; + defaultText = lib.literalExpression "sstorytime-run (systemd-run wrapper)"; + description = '' + Runs tools in a transient unit with the same user, state directory, + and environment as {option}`systemd.services.sstorytime`. + Example: {command}`sstorytime-run N4L -u notes.n4l`. + ''; + }; + }; + + config = mkIf cfg.enable { + assertions = [ + { + assertion = + cfg.database.createLocally || cfg.settings ? POSTGRESQL_URI || cfg.environmentFile != null; + message = '' + services.sstorytime: when database.createLocally is false, set + settings.POSTGRESQL_URI or environmentFile (e.g. sops) so the service + can reach PostgreSQL. + ''; + } + ]; + + # `/*` makes etc a directory of links so nested entries can extend it. + environment.etc.sstorytime.source = "${cfg.configDir}/*"; + + environment.systemPackages = [ + cfg.package + cfg.finalPackage + ]; + + users.users.${dbName} = { + isSystemUser = true; + group = dbName; + description = "SSTorytime service and database user"; + }; + users.groups.${dbName} = { }; + + services.sstorytime.settings = mkMerge [ + { + SST_CONFIG_PATH = mkDefault configPath; + } + (mkIf cfg.database.createLocally { + POSTGRESQL_URI = mkDefault defaultDatabaseUri; + }) + ]; + + systemd.services.sstorytime = { + description = "SSTorytime Server"; + wantedBy = [ "multi-user.target" ]; + after = [ "network.target" ] ++ lib.optionals cfg.database.createLocally [ "postgresql.target" ]; + path = [ pkgs.openssl ]; + environment = cfg.settings; + unitConfig = { + StartLimitBurst = 5; + StartLimitIntervalSec = 100; + }; + preStart = '' + mkdir -p cacheroot + if [ ! -f cert.pem ] || [ ! -f key.pem ]; then + openssl req -x509 -newkey rsa:4096 \ + -keyout key.pem -out cert.pem \ + -days 365 -nodes \ + -subj "/CN=localhost" + fi + ''; + serviceConfig = commonServiceConfig // { + Restart = "on-failure"; + RestartSec = 5; + ExecStart = lib.escapeShellArgs [ + (lib.getExe' cfg.package "http_server") + "-http" + ":${toString cfg.httpPort}" + "-https" + ":${toString cfg.httpsPort}" + "-cert" + "cert.pem" + "-key" + "key.pem" + ]; + + # MemoryDenyWriteExecute breaks Go. + CapabilityBoundingSet = ""; + LockPersonality = true; + NoNewPrivileges = true; + PrivateDevices = true; + PrivateTmp = true; + ProtectClock = true; + ProtectControlGroups = true; + ProtectHome = true; + ProtectHostname = true; + ProtectKernelLogs = true; + ProtectKernelModules = true; + ProtectKernelTunables = true; + ProtectSystem = "strict"; + RestrictAddressFamilies = [ + "AF_INET" + "AF_INET6" + "AF_UNIX" + ]; + RestrictNamespaces = true; + RestrictRealtime = true; + SystemCallArchitectures = "native"; + }; + }; + + networking.firewall.allowedTCPPorts = lib.optionals cfg.openFirewall [ + cfg.httpPort + cfg.httpsPort + ]; + + services.postgresql = mkIf cfg.database.createLocally { + enable = true; + ensureUsers = [ + { + name = dbName; + ensureDBOwnership = true; + } + ]; + ensureDatabases = [ dbName ]; + }; + }; +} diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index 1f549b1ef5ce..a6d423faeb2e 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -905,6 +905,7 @@ in kea = runTest ./kea.nix; keepalived = discoverTests (import ./keepalived.nix); keepassxc = runTest ./keepassxc.nix; + kener = runTest ./kener.nix; kerberos = handleTest ./kerberos/default.nix { }; kernel-generic = handleTest ./kernel-generic { }; kernel-latest-ath-user-regd = runTest ./kernel-latest-ath-user-regd.nix; @@ -1636,6 +1637,7 @@ in sslh = handleTest ./sslh.nix { }; sssd-ldap = handleTestOn [ "x86_64-linux" "aarch64-linux" ] ./sssd-ldap.nix { }; sssd-legacy-config = handleTestOn [ "x86_64-linux" "aarch64-linux" ] ./sssd-legacy-config.nix { }; + sstorytime = runTest ./sstorytime.nix; stalwart = runTest ./stalwart/stalwart.nix; stardust-xr-atmosphere = runTest ./stardust-xr/atmosphere.nix; stardust-xr-flatland = runTest ./stardust-xr/flatland.nix; @@ -1820,6 +1822,7 @@ in tracee = handleTestOn [ "x86_64-linux" ] ./tracee.nix { }; traefik = runTestOn [ "aarch64-linux" "x86_64-linux" ] ./traefik.nix; trafficserver = runTest ./trafficserver.nix; + trailbase = runTest ./trailbase; tranquil-pds = runTest ./tranquil-pds.nix; transfer-sh = runTest ./transfer-sh.nix; transmission_4 = runTest ./transmission.nix; diff --git a/nixos/tests/kener.nix b/nixos/tests/kener.nix new file mode 100644 index 000000000000..1fd06d4e7f92 --- /dev/null +++ b/nixos/tests/kener.nix @@ -0,0 +1,27 @@ +{ lib, ... }: + +{ + name = "kener"; + meta.maintainers = with lib.maintainers; [ albertlarsan68 ]; + + containers.machine = + { pkgs, ... }: + { + services.kener = { + enable = true; + environmentFile = pkgs.writeText "kener-env" '' + KENER_SECRET_KEY=kener_secret_key_do_not_use + ''; + settings = { + ORIGIN = "http://localhost:3001"; + }; + }; + }; + + testScript = '' + machine.start() + machine.wait_for_unit("kener.service") + machine.wait_for_open_port(3001) + machine.wait_until_succeeds("curl --fail http://localhost:3001/healthcheck?strict=1") + ''; +} diff --git a/nixos/tests/pdns-recursor.nix b/nixos/tests/pdns-recursor.nix index 160d9a0fd2a0..c15ad62c0085 100644 --- a/nixos/tests/pdns-recursor.nix +++ b/nixos/tests/pdns-recursor.nix @@ -6,7 +6,9 @@ nodes.server = { services.pdns-recursor.enable = true; + services.pdns-recursor.api.enable = true; services.pdns-recursor.exportHosts = true; + services.pdns-recursor.settings.webservice.api_key = "supersecret"; networking.hosts."192.0.2.1" = [ "example.com" ]; }; @@ -17,5 +19,13 @@ with subtest("can resolve names"): assert "192.0.2.1" in server.succeed("host example.com localhost") + + with subtest("api is working"): + server.wait_for_open_port(8082) + server.succeed("curl -f -H 'X-API-Key: supersecret' http://localhost:8082/api/v1/servers") + server.fail("curl -f http://localhost:8082/api/v1/servers") + + with subtest("metrics are exported"): + assert "pdns_recursor_" in server.succeed("curl -f -H 'X-API-Key: supersecret' http://localhost:8082/metrics") ''; } diff --git a/nixos/tests/sstorytime.nix b/nixos/tests/sstorytime.nix new file mode 100644 index 000000000000..7afd6d5bb807 --- /dev/null +++ b/nixos/tests/sstorytime.nix @@ -0,0 +1,53 @@ +{ lib, ... }: +{ + name = "sstorytime"; + + meta = { + maintainers = lib.teams.ngi.members; + }; + + nodes.machine = + { pkgs, ... }: + { + services.sstorytime = { + enable = true; + httpPort = 18080; + httpsPort = 18443; + database.createLocally = true; + }; + + environment.etc."sstorytime/test".source = pkgs.writeText "sstorytime-test" "extra-config-ok\n"; + }; + + testScript = + { nodes, ... }: + let + inherit (nodes.machine.services.sstorytime) package httpPort httpsPort; + in + '' + start_all() + + machine.wait_for_unit("sstorytime.service") + machine.wait_for_open_port(${toString httpPort}) + machine.wait_for_open_port(${toString httpsPort}) + + machine.succeed("test -d /etc/sstorytime") + machine.succeed("test -f /etc/sstorytime/arrows-LT-1.sst") + machine.succeed("test -f /etc/sstorytime/closures.sst") + machine.succeed("test -f /etc/sstorytime/test") + machine.succeed("grep -q extra-config-ok /etc/sstorytime/test") + + machine.succeed("ln -s ${package.examples}/share/examples /tmp/examples") + + machine.succeed("sstorytime-run N4L -v -u /tmp/examples/SSTorytime.n4l") + + output = machine.succeed("sstorytime-run searchN4L -v SSTorytime") + assert "notes about SSTorytime in N4L" in output, "Failed to search for term in graph." + + output = machine.succeed('sstorytime-run N4L -s -adj="pe" /tmp/examples/chinese.n4l') + assert "Incidence summary of raw declarations" in output, "Failed to get relation sub-graph." + + output = machine.succeed('sstorytime-run N4L -s -adj="" /tmp/examples/Mary.n4l') + assert "Incidence summary of raw declarations" in output, "Failed to summarize graph." + ''; +} diff --git a/nixos/tests/tpm2/tpm2-abrmd.nix b/nixos/tests/tpm2/tpm2-abrmd.nix index f0d28d932756..718b4bda523e 100644 --- a/nixos/tests/tpm2/tpm2-abrmd.nix +++ b/nixos/tests/tpm2/tpm2-abrmd.nix @@ -32,6 +32,8 @@ environment.systemPackages = [ pkgs.tpm2-tools pkgs.openssl + pkgs.p11-kit + pkgs.opensc ]; }; @@ -39,6 +41,15 @@ machine.start() machine.wait_for_unit("multi-user.target") + with subtest("p11-kit discovers the tpm2_pkcs11 module"): + machine.succeed("p11-kit list-modules | grep 'library-description: TPM2.0 Cryptoki'") + + with subtest("TPM2 token is reachable through the p11-kit proxy"): + machine.succeed( + "pkcs11-tool --module ${lib.getLib pkgs.p11-kit}/lib/p11-kit-proxy.so --list-slots" + " | grep 'token state'" + ) + with subtest("/dev/tpmrm0 has correct ownership"): machine.succeed('[ `stat -c "%U" /dev/tpmrm0` = "tss" ]') machine.succeed('[ `stat -c "%G" /dev/tpmrm0` = "tss" ]') diff --git a/nixos/tests/tpm2/tpm2-tpmrm.nix b/nixos/tests/tpm2/tpm2-tpmrm.nix index 3f777c7c2ba3..7b6013b89dad 100644 --- a/nixos/tests/tpm2/tpm2-tpmrm.nix +++ b/nixos/tests/tpm2/tpm2-tpmrm.nix @@ -30,6 +30,8 @@ environment.systemPackages = [ pkgs.tpm2-tools pkgs.openssl + pkgs.p11-kit + pkgs.opensc ]; }; @@ -37,6 +39,15 @@ machine.start() machine.wait_for_unit("multi-user.target") + with subtest("p11-kit discovers the tpm2_pkcs11 module"): + machine.succeed("p11-kit list-modules | grep 'library-description: TPM2.0 Cryptoki'") + + with subtest("TPM2 token is reachable through the p11-kit proxy"): + machine.succeed( + "pkcs11-tool --module ${lib.getLib pkgs.p11-kit}/lib/p11-kit-proxy.so --list-slots" + " | grep 'token state'" + ) + with subtest("/dev/tpmrm0 has correct ownership"): machine.succeed('[ `stat -c "%U" /dev/tpmrm0` = "root" ]') machine.succeed('[ `stat -c "%G" /dev/tpmrm0` = "tss" ]') diff --git a/nixos/tests/trailbase/api.py b/nixos/tests/trailbase/api.py new file mode 100644 index 000000000000..39d1adfd907d --- /dev/null +++ b/nixos/tests/trailbase/api.py @@ -0,0 +1,67 @@ +import argparse +from pathlib import Path + +from trailbase import Client, FetchException + +SITE = "http://127.0.0.1:4000" +NOTES_SQL = ( + "CREATE TABLE notes (id INTEGER PRIMARY KEY, body TEXT NOT NULL) STRICT;" +) +RECORD_API = """ +record_apis: [{ + name: "notes" + table_name: "notes" + acl_authenticated: [CREATE, READ, UPDATE, DELETE] +}] +""" + + +def connect(password): + client = Client(SITE) + client.login("admin@localhost", password) + user = client.user() + assert user is not None + assert user.email == "admin@localhost", user.email + return client + + +def setup(password): + client = connect(password) + assert client.tokens() is not None + assert client.refresh_auth_tokens(force=True) + client.logout() + assert client.tokens() is None + + client = connect(password) + client.fetch("api/_admin/query", method="POST", data={"query": NOTES_SQL}) + with Path("/var/lib/trailbase/config.textproto").open("a") as cfg: + cfg.write(RECORD_API) + + +def crud(password): + notes = connect(password).records("notes") + note_id = notes.create({"body": "hello from nixos"}) + listed = notes.list() + found = any(note_id.id in str(row) for row in listed.records) + assert found, listed.records + assert "hello from nixos" in str(notes.read(note_id)) + notes.update(note_id, {"body": "updated"}) + assert "updated" in str(notes.read(note_id)) + notes.delete(note_id) + try: + notes.read(note_id) + except FetchException: + return + raise SystemExit("deleted record still readable") + + +def main(): + parser = argparse.ArgumentParser() + parser.add_argument("command", choices=["setup", "crud"]) + parser.add_argument("--password", required=True) + args = parser.parse_args() + (setup if args.command == "setup" else crud)(args.password) + + +if __name__ == "__main__": + main() diff --git a/nixos/tests/trailbase/default.nix b/nixos/tests/trailbase/default.nix new file mode 100644 index 000000000000..7b712ef51a41 --- /dev/null +++ b/nixos/tests/trailbase/default.nix @@ -0,0 +1,50 @@ +{ lib, pkgs, ... }: +{ + _class = "nixosTest"; + name = "trailbase"; + + nodes = { + machine = + { pkgs, ... }: + { + environment.systemPackages = [ + pkgs.curl + (pkgs.writers.writePython3Bin "trailbase-api" { + libraries = [ pkgs.python3Packages.trailbase ]; + } (builtins.readFile ./api.py)) + ]; + + system.services.trailbase = { + imports = [ pkgs.trailbase.services.default ]; + trailbase.address = "127.0.0.1:4000"; + }; + }; + }; + + testScript = '' + import re + + start_all() + machine.wait_for_unit("trailbase.service") + machine.wait_for_open_port(4000) + machine.succeed("curl --fail http://127.0.0.1:4000/api/healthcheck") + machine.succeed("curl --fail -o /dev/null http://127.0.0.1:4000/_/admin/") + + journal = machine.succeed("journalctl -u trailbase.service --no-pager") + match = re.search(r"password:\s*'([^']+)'", journal) + assert match, f"admin password not in journal:\n{journal}" + password = match.group(1) + + machine.succeed(f"trailbase-api --password {password!r} setup") + machine.succeed("systemctl restart trailbase.service") + machine.wait_for_unit("trailbase.service") + machine.wait_for_open_port(4000) + machine.succeed("curl --fail http://127.0.0.1:4000/api/healthcheck") + machine.succeed(f"trailbase-api --password {password!r} crud") + ''; + + meta = { + maintainers = [ lib.maintainers.lucasew ]; + teams = [ lib.teams.ngi ]; + }; +} diff --git a/pkgs/applications/editors/vscode/extensions/default.nix b/pkgs/applications/editors/vscode/extensions/default.nix index 6921fdc38438..c3cb299341e6 100644 --- a/pkgs/applications/editors/vscode/extensions/default.nix +++ b/pkgs/applications/editors/vscode/extensions/default.nix @@ -2487,6 +2487,23 @@ let jacobdufault.fuzzy-search = callPackage ./jacobdufault.fuzzy-search { }; + jacqueslucke.gcov-viewer = buildVscodeMarketplaceExtension { + mktplcRef = { + name = "gcov-viewer"; + publisher = "JacquesLucke"; + version = "0.6.0"; + hash = "sha256-iKaBN2af0Zqu6qsS9A85+7Jjwd9NueE/XCRkexAfB1Q="; + }; + meta = { + changelog = "https://marketplace.visualstudio.com/items/JacquesLucke.gcov-viewer/changelog"; + description = "Decorate C/C++ source files with code coverage information generated by gcov"; + downloadPage = "https://marketplace.visualstudio.com/items?itemName=JacquesLucke.gcov-viewer"; + homepage = "https://github.com/JacquesLucke/gcov-viewer"; + license = lib.licenses.mit; + maintainers = [ lib.maintainers.sempiternal-aurora ]; + }; + }; + jakestanger.corn = callPackage ./jakestanger.corn { }; james-yu.latex-workshop = callPackage ./james-yu.latex-workshop { }; @@ -3711,6 +3728,8 @@ let nsd.vscode-epics = callPackage ./nsd.vscode-epics { }; + ocamlpro.superbol = callPackage ./ocamlpro.superbol { }; + ocamllabs.ocaml-platform = buildVscodeMarketplaceExtension { meta = { changelog = "https://marketplace.visualstudio.com/items/ocamllabs.ocaml-platform/changelog"; diff --git a/pkgs/applications/editors/vscode/extensions/ocamlpro.superbol/default.nix b/pkgs/applications/editors/vscode/extensions/ocamlpro.superbol/default.nix new file mode 100644 index 000000000000..2bbf39d23064 --- /dev/null +++ b/pkgs/applications/editors/vscode/extensions/ocamlpro.superbol/default.nix @@ -0,0 +1,102 @@ +{ + lib, + stdenv, + fetchNpmDeps, + ocamlPackages, + vscode-utils, + npmHooks, + nodejs-slim, + llvmPackages_20, + dune_3, + pkg-config, + libsecret, + vsce, +}: + +let + vsixStdenv = if stdenv.cc.isClang then llvmPackages_20.stdenv else stdenv; + vsix = vsixStdenv.mkDerivation (finalAttrs: { + name = "superbol-studio-oss-${finalAttrs.version}.vsix"; + pname = "superbol-studio-oss-vsix"; + + strictDeps = true; + __structuredAttrs = true; + + inherit (ocamlPackages.superbol-studio-oss) version src patches; + + prePatch = '' + rm -rf import/gnucobol* + ''; + + # [ERROR] Big integer literals are not available in the configured target environment ("es2015") + postPatch = '' + substituteInPlace Makefile.vsix-rules \ + --replace-fail '--target=es6' '--target=es2020' + ''; + + npmDeps = fetchNpmDeps { + name = "${finalAttrs.pname}-npm-deps"; + inherit (finalAttrs) src; + hash = "sha256-7wu+iPsVUz9qVFZonF7pGrrwSPyGdFWOonUttWe53lM="; + }; + + nativeBuildInputs = [ + nodejs-slim + nodejs-slim.npm + nodejs-slim.python + npmHooks.npmConfigHook + ocamlPackages.ocaml + ocamlPackages.gen_js_api + ocamlPackages.js_of_ocaml + dune_3 + pkg-config + vsce + ]; + + buildInputs = [ + ocamlPackages.superbol-studio-oss + libsecret + ]; + + buildPhase = '' + runHook preBuild + + # Taken from the steps of `make compile` in the upstream repo + make build-release DUNE=dune LINKING_MODE=static + ln -s ${lib.getExe ocamlPackages.superbol-studio-oss} _dist + vsce package --no-git-tag-version --no-update-package-json \ + --out package.vsix "$version" + + runHook postBuild + ''; + + installPhase = '' + runHook preInstall + install -m644 package.vsix $out + runHook postInstall + ''; + }); +in +vscode-utils.buildVscodeExtension (finalAttrs: { + pname = "superbol-studio-oss"; + inherit (finalAttrs.src) version; + + vscodeExtPublisher = "OCamlPro"; + vscodeExtName = "SuperBOL"; + vscodeExtUniqueId = "${finalAttrs.vscodeExtPublisher}.${finalAttrs.vscodeExtName}"; + + src = vsix; + + passthru = { + vsix = finalAttrs.src; + }; + + meta = { + description = "Visual Studio Code extension for COBOL"; + downloadPage = "https://marketplace.visualstudio.com/items?itemName=OCamlPro.SuperBOL"; + homepage = "https://superbol.eu/en"; + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ sempiternal-aurora ]; + teams = [ lib.teams.ngi ]; + }; +}) diff --git a/pkgs/by-name/al/alembic/package.nix b/pkgs/by-name/al/alembic/package.nix index 43ce605db4c8..a99d19482487 100644 --- a/pkgs/by-name/al/alembic/package.nix +++ b/pkgs/by-name/al/alembic/package.nix @@ -52,6 +52,13 @@ stdenv.mkDerivation (finalAttrs: { "-DConfigPackageLocation=${placeholder "dev"}/lib/cmake/Alembic" "-DCMAKE_INSTALL_PREFIX=${placeholder "dev"}" "-DQUIET=ON" + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ + # Upstream defaults the dylib's install RPATH to $dev/..., embedding a $dev + # path in the $lib output and cycling with the CMake config in $dev. Linux + # is spared by patchelf --shrink-rpath; Darwin has no such step. Overriding + # the (guarded) default to the real lib dir breaks the cycle without a patch. + "-DCMAKE_INSTALL_RPATH=${placeholder "lib"}/lib" ]; postPatch = '' diff --git a/pkgs/by-name/an/anytype-heart/package.nix b/pkgs/by-name/an/anytype-heart/package.nix index 13b8d25a84b7..2a636353222d 100644 --- a/pkgs/by-name/an/anytype-heart/package.nix +++ b/pkgs/by-name/an/anytype-heart/package.nix @@ -25,7 +25,7 @@ buildGoModule (finalAttrs: { # Use only versions specified in anytype-ts middleware.version file: # https://github.com/anyproto/anytype-ts/blob/v/middleware.version - version = "0.50.18"; + version = "0.51.0-rc1"; # Update only together with 'anytype' package. # nixpkgs-update: no auto update @@ -33,10 +33,10 @@ buildGoModule (finalAttrs: { owner = "anyproto"; repo = "anytype-heart"; tag = "v${finalAttrs.version}"; - hash = "sha256-OnDhtK9niJlHwW8BNBVwAfgf8nUKX4qtwdu7kXKqYKg="; + hash = "sha256-Hxch8p+fIUOyhePZPmb9i1O7IyPMlwZP8ElRu42DEzk="; }; - vendorHash = "sha256-n0fcWzUSv4AuAbepWPk5c8DldClQX+Juo3MLca+tLV4="; + vendorHash = "sha256-6LLIs4iT3qwV6luZ08RS05CmUFnNFYLazHeKNG76gV4="; subPackages = [ "cmd/grpcserver" ]; tags = [ diff --git a/pkgs/by-name/an/anytype/package.nix b/pkgs/by-name/an/anytype/package.nix index fac3d442eb07..1ce2d4af2561 100644 --- a/pkgs/by-name/an/anytype/package.nix +++ b/pkgs/by-name/an/anytype/package.nix @@ -24,7 +24,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { pname = "anytype"; - version = "0.56.1"; + version = "0.56.5"; strictDeps = true; @@ -32,14 +32,14 @@ stdenvNoCC.mkDerivation (finalAttrs: { owner = "anyproto"; repo = "anytype-ts"; tag = "v${finalAttrs.version}"; - hash = "sha256-7e8wGrha3eiW1ou0vJa/njDna87wDOPzpk4fX6qj9qA="; + hash = "sha256-X1z2lQtmMuyJKLL43hBYQCj976rCmha43gffZeLrnMY="; }; locales = fetchFromGitHub { owner = "anyproto"; repo = "l10n-anytype-ts"; - rev = "c16beda3d1a931d3330b1f7cc99185f7bdcba2f5"; - hash = "sha256-ludb8WyECZW0PxnhR/znHS3uXQuk8KDIXHujha4YeA0="; + rev = "2bb4678cebd453559dc17e7bab204f237fa17553"; + hash = "sha256-e3DfvUlfRJhwp6lLqPEkm4bD1bl+KLP6laVnRaHOYsU="; }; node_modules = stdenvNoCC.mkDerivation { @@ -87,7 +87,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { dontFixup = true; - outputHash = "sha256-i2GPGi7LgIy8y+//rR0H+vX+bc/v2NKd7xGLargd044="; + outputHash = "sha256-phvOKUOqXwqNvZ6njyEf6CTBlDTP8CmSglmaUWqDXqI="; outputHashMode = "recursive"; }; diff --git a/pkgs/by-name/be/bencher-cli/package.nix b/pkgs/by-name/be/bencher-cli/package.nix index fa7d8bdc979f..09ebeec58a2f 100644 --- a/pkgs/by-name/be/bencher-cli/package.nix +++ b/pkgs/by-name/be/bencher-cli/package.nix @@ -9,7 +9,7 @@ }: rustPlatform.buildRustPackage (finalAttrs: { pname = "bencher-cli"; - version = "0.6.11"; + version = "0.6.12"; __structuredAttrs = true; strictDeps = true; @@ -17,10 +17,10 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "bencherdev"; repo = "bencher"; rev = "v${finalAttrs.version}"; - hash = "sha256-xn91uP7BOa8rQx/Cmk9hfCNBsQkCiMjEKmeX/dxxDTE="; + hash = "sha256-7tM35WsQfnGj/xLj8/GICsd6gELh82LP+aCwXLM9byA="; }; - cargoHash = "sha256-K7aVNm7rqL3bc+/pU005irucS8/8bvZbPmYrjNMpvkA="; + cargoHash = "sha256-EuRobN0g/3iA8YqrrMV5O3WfZHNVWW6yaO6esY/uXOU="; nativeBuildInputs = [ mold ]; nativeInstallCheckInputs = [ versionCheckHook ]; diff --git a/pkgs/by-name/ch/chainsaw/package.nix b/pkgs/by-name/ch/chainsaw/package.nix index 26983a117f5a..a3d0b26cfa87 100644 --- a/pkgs/by-name/ch/chainsaw/package.nix +++ b/pkgs/by-name/ch/chainsaw/package.nix @@ -7,16 +7,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "chainsaw"; - version = "2.16.4"; + version = "2.16.5"; src = fetchFromGitHub { owner = "WithSecureLabs"; repo = "chainsaw"; tag = "v${finalAttrs.version}"; - hash = "sha256-J+yIAhiZE1MK5lGZtlxqmElrO/KqEdtkKE4nKPxMGzw="; + hash = "sha256-BTN+yDeiP47UEPNEYoWMRbaKPZY+dvyeUUw3M/4Lr3I="; }; - cargoHash = "sha256-q959QVqdISSI2SkUgamtR29DKd7oF/5eGsXpwHir1nE="; + cargoHash = "sha256-xIh5a+0xvpbuoL3J6WETJ+BjFLmNwJXemn2KXPOFZpU="; ldflags = [ "-s" ]; diff --git a/pkgs/by-name/cu/cups/package.nix b/pkgs/by-name/cu/cups/package.nix index 10abd55a5977..dd12a5dcef57 100644 --- a/pkgs/by-name/cu/cups/package.nix +++ b/pkgs/by-name/cu/cups/package.nix @@ -14,6 +14,7 @@ systemdLibs, acl, gmp, + darwin, libusb1 ? null, gnutls ? null, avahi ? null, @@ -39,7 +40,6 @@ stdenv.mkDerivation (finalAttrs: { "lib" "dev" "man" - "doc" ]; postPatch = '' diff --git a/pkgs/by-name/es/essh/package.nix b/pkgs/by-name/es/essh/package.nix index 1ec379dc7fe6..82424e24d327 100644 --- a/pkgs/by-name/es/essh/package.nix +++ b/pkgs/by-name/es/essh/package.nix @@ -1,5 +1,6 @@ { lib, + stdenv, fetchFromGitHub, pkg-config, rustPlatform, @@ -9,18 +10,18 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "essh"; - version = "0.2.8"; + version = "0.3.3"; src = fetchFromGitHub { owner = "matthart1983"; repo = "essh"; tag = "v${finalAttrs.version}"; - hash = "sha256-njBhA3CSTAlWjcgY3y+hvl19By2QGy2tHP8+FxgycIA="; + hash = "sha256-dK9M730LgS4CG/BAOSfvH2T06RJsEWHVFT0/VoFvt3Q="; }; __structuredAttrs = true; - cargoHash = "sha256-TlvUdlKnRA/L5oePn+YWum1wy3ktHFuXP5V+nH2QNnc="; + cargoHash = "sha256-2ZAvm3LJHpLF99ahLdTFKuneRMLn6XryNd+ZT2uSawE="; nativeBuildInputs = [ pkg-config ]; @@ -34,6 +35,15 @@ rustPlatform.buildRustPackage (finalAttrs: { checkFlags = [ "--skip=mock_ssh_server_drives_real_connect_flow_end_to_end" + "--skip=an_unroutable_address_fails_on_our_timeout_not_the_os" + "--skip=an_unreachable_host_does_not_wedge_the_ui" + "--skip=help_teaches_a_binding_that_works_everywhere" + "--skip=it_starts_and_shows_the_launcher" + "--skip=typing_in_the_launcher_filters_without_stalling" + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ + "--skip=macos_command_set_produces_real_readings_on_this_host" + "--skip=a_closed_port_is_named_as_refused_not_as_a_timeout" ]; meta = { diff --git a/pkgs/by-name/fs/fscan/package.nix b/pkgs/by-name/fs/fscan/package.nix index d7f229604a6f..35e62016dc78 100644 --- a/pkgs/by-name/fs/fscan/package.nix +++ b/pkgs/by-name/fs/fscan/package.nix @@ -6,13 +6,13 @@ buildGoModule (finalAttrs: { pname = "fscan"; - version = "2.2.0"; + version = "2.2.1"; src = fetchFromGitHub { owner = "shadow1ng"; repo = "fscan"; tag = "v${finalAttrs.version}"; - hash = "sha256-05z5DuW25/hVoTdUtGGuaCBPtO1QyGqgvKWSpO8DBpQ="; + hash = "sha256-awg6YqZyhlt04JobZXZx/PYuw2X7gsYKWb8480ymcN8="; }; vendorHash = "sha256-IlGHY0KbYsy/5Yz11XhkcS9yS8byY3vhPZiTwnJM6/Q="; diff --git a/pkgs/by-name/gn/gnucobol/hello.cbl b/pkgs/by-name/gn/gnucobol/hello.cbl new file mode 100644 index 000000000000..5092715e11f3 --- /dev/null +++ b/pkgs/by-name/gn/gnucobol/hello.cbl @@ -0,0 +1,6 @@ + IDENTIFICATION DIVISION. + PROGRAM-ID. HELLO. + + PROCEDURE DIVISION. + DISPLAY "Hello, COBOL!". + STOP RUN. diff --git a/pkgs/by-name/gn/gnucobol/package.nix b/pkgs/by-name/gn/gnucobol/package.nix index a4d5cf34a611..d03bb2032ce3 100644 --- a/pkgs/by-name/gn/gnucobol/package.nix +++ b/pkgs/by-name/gn/gnucobol/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchurl, + autoreconfHook, autoconf, automake, libtool, @@ -18,6 +19,8 @@ texliveBasic, # test perl, + runCommandCC, + versionCheckHook, }: let nistTestSuite = fetchurl { @@ -30,6 +33,8 @@ stdenv.mkDerivation (finalAttrs: { pname = "gnucobol"; version = "3.2"; + strictDeps = true; + src = fetchurl { url = "mirror://gnu/gnucobol/gnucobol-${finalAttrs.version}.tar.xz"; hash = "sha256-O7SK9GztR3n6z0H9wu5g5My4bqqZ0BCzZoUxXfOcLuI="; @@ -37,14 +42,23 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ pkg-config - autoconf - automake help2man libtool perl texinfo texliveBasic - ]; + ] + ++ ( + if stdenv.hostPlatform.isDarwin then + # autoreconf runs aclocal before autoconf, which messes up some compiler + # definition and causes many tests to fail (with segfaults) + [ + automake + autoconf + ] + else + [ autoreconfHook ] + ); buildInputs = [ cjson @@ -69,23 +83,21 @@ stdenv.mkDerivation (finalAttrs: { # Skips a broken test postPatch = '' - sed -i '/^AT_CHECK.*crud\.cob/i AT_SKIP_IF([true])' tests/testsuite.src/listings.at # upstream reports the following tests as known failures - # test 843 (runtime check: write to internal storage (1)) - sed -i "/^843;/d" tests/testsuite - # test 875 (INDEXED sample) - sed -i "/^875;/d" tests/testsuite - + sed -i '/AT_SETUP(\[runtime check: write to internal storage (1)\])/a \ + AT_SKIP_IF(\[true\])' tests/testsuite.src/run_misc.at # gnucobol.texi:2765: no matching `@end verbatim' sed -i "214i @end verbatim" doc/cbrunt.tex + '' + + lib.optionalString stdenv.hostPlatform.isDarwin '' + sed -i '/AT_SETUP(\[INDEXED sample\])/a \ + AT_SKIP_IF(\[true\])' tests/testsuite.src/run_file.at ''; - preConfigure = '' + preConfigure = lib.optionalString stdenv.hostPlatform.isDarwin '' autoconf aclocal automake - '' - + lib.optionalString stdenv.hostPlatform.isDarwin '' # when building with nix on darwin, configure will use GNU strip, # which fails due to using --strip-unneeded, which is not supported substituteInPlace configure --replace-fail '"GNU strip"' 'FAKE GNU strip' @@ -93,63 +105,50 @@ stdenv.mkDerivation (finalAttrs: { # GCC 15 changed some warnings to errors, particularly around function pointer types # (C23 empty parentheses means no args, not unspecified). These flags are needed - # until gnucobol is updated to compile cleanly with GCC 15. + # until gnucobol is updated to compile cleanly with GCC 15+/latest LLVM. # See: https://gcc.gnu.org/gcc-15/porting_to.html - env.CFLAGS = - let - # Clang needs -Wno-error=implicit-function-declaration for xmlCleanupParser - clangFlags = "-Wno-error=implicit-function-declaration"; - # GCC 15+ needs additional flags for incompatible pointer type errors - gcc15Flags = "-Wno-error=incompatible-pointer-types -std=gnu11"; - in - if stdenv.cc.isGNU && lib.versionAtLeast stdenv.cc.version "15.0.0" then - gcc15Flags - else if stdenv.cc.isClang then - clangFlags - else - ""; - + env.CFLAGS = "-std=gnu17"; enableParallelBuilding = true; installFlags = [ + "localedir=$out/share/locale" + ] + ++ lib.optionals (stdenv.hostPlatform.isDarwin) [ "install-pdf" "install-html" - "localedir=$out/share/locale" ]; - # Tests must run after install. + # Needs to be install check for macos, inbuilt tests fail unless they are installed first doCheck = false; - - doInstallCheck = true; + doInstallCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform; + nativeInstallCheckInputs = [ versionCheckHook ]; + versionCheckProgram = "${placeholder "bin"}/bin/cob-config"; installCheckPhase = '' runHook preInstallCheck - # Run tests + # Run tests (parallel via autoconf testscript) TESTSUITEFLAGS="--jobs=$NIX_BUILD_CORES" make check - # Run NIST tests + # Run NIST tests (parallel via make) cp -v ${nistTestSuite} ./tests/cobol85/newcob.val.tar.gz - TESTSUITEFLAGS="--jobs=$NIX_BUILD_CORES" make test - - # Sanity check - message="Hello, COBOL!" - # XXX: Don't for a second think you can just get rid of these spaces, they - # are load bearing. - tee hello.cbl <stderr.log || true + cat stderr.log + grep -qF "Could not find private key" stderr.log + if grep -qF "Unable to load PKCS#11 module" stderr.log; then + echo "the pkcs11 engine failed to load its default PKCS#11 module" >&2 + exit 1 + fi + + touch $out + ''; + }; meta = { description = "Small layer on top of PKCS#11 API to make PKCS#11 implementations easier"; diff --git a/pkgs/by-name/lx/lxmf-rs/package.nix b/pkgs/by-name/lx/lxmf-rs/package.nix index 5f4166d144d4..86facd808d7e 100644 --- a/pkgs/by-name/lx/lxmf-rs/package.nix +++ b/pkgs/by-name/lx/lxmf-rs/package.nix @@ -25,6 +25,13 @@ rustPlatform.buildRustPackage (finalAttrs: { cargoHash = "sha256-RKVHLKjfukNwIXsAz4CnJDy1oOM4McQeE31Ch+WHc5w="; + cargoBuildFlags = [ + "--workspace" + "--exclude" + "xtask" + ]; + cargoTestFlags = finalAttrs.cargoBuildFlags; + nativeBuildInputs = [ pkg-config ]; diff --git a/pkgs/by-name/ma/matterjs-server/package.nix b/pkgs/by-name/ma/matterjs-server/package.nix index 5d09144d25b7..f6bcd73b35c5 100644 --- a/pkgs/by-name/ma/matterjs-server/package.nix +++ b/pkgs/by-name/ma/matterjs-server/package.nix @@ -36,6 +36,13 @@ buildNpmPackage (finalAttrs: { preBuild = "npm run version -- --apply"; + # remove temporary build files + postBuild = '' + shopt -s globstar + rm node_modules/**/build/{config.gypi,Makefile,*.target.mk} + shopt -u globstar + ''; + dontNpmInstall = true; makeWrapperArgs = [ diff --git a/pkgs/by-name/of/officecli/package.nix b/pkgs/by-name/of/officecli/package.nix index ce4bcea860b5..9784dd4cb7b8 100644 --- a/pkgs/by-name/of/officecli/package.nix +++ b/pkgs/by-name/of/officecli/package.nix @@ -8,7 +8,7 @@ buildDotnetModule (finalAttrs: { pname = "officecli"; - version = "1.0.143"; + version = "1.0.144"; strictDeps = true; __structuredAttrs = true; @@ -17,7 +17,7 @@ buildDotnetModule (finalAttrs: { owner = "iOfficeAI"; repo = "OfficeCLI"; tag = "v${finalAttrs.version}"; - hash = "sha256-v2tG0sPoc1CGnYl1qIipkEofKlO4wv3oVFrkvjzFrhU="; + hash = "sha256-PSnU9ij9xbFGqe6ziv7x437Y1vWpJ7CRYCpwcUQ0bS0="; }; projectFile = "src/officecli/officecli.csproj"; diff --git a/pkgs/by-name/pa/panache/package.nix b/pkgs/by-name/pa/panache/package.nix index 75069cb7c645..5009281efc7b 100644 --- a/pkgs/by-name/pa/panache/package.nix +++ b/pkgs/by-name/pa/panache/package.nix @@ -9,16 +9,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "panache"; - version = "3.4.0"; + version = "3.6.1"; src = fetchFromGitHub { owner = "jolars"; repo = "panache"; tag = "v${finalAttrs.version}"; - hash = "sha256-4AVuGnj1Y3h6wkJC6ytqQb5wPJvXmYL49YAPJirt7h4="; + hash = "sha256-zUSx97thgYaVcQr1wImMLsey075XERNTOdZdOIIMbmw="; }; - cargoHash = "sha256-4d21IpmX8mn/y0WdWnZx/64hMyHNipTyWaTTDttMpN4="; + cargoHash = "sha256-lf65tFVeEr5rIhC95GojSFNb3SEcp6DOFVNox9H9fB0="; nativeBuildInputs = [ installShellFiles diff --git a/pkgs/by-name/pe/peergos/package.nix b/pkgs/by-name/pe/peergos/package.nix index 4a7114954353..6b0253d2388c 100644 --- a/pkgs/by-name/pe/peergos/package.nix +++ b/pkgs/by-name/pe/peergos/package.nix @@ -41,13 +41,13 @@ let in stdenv.mkDerivation rec { pname = "peergos"; - version = "1.31.0"; + version = "1.32.0"; src = fetchFromGitHub { owner = "Peergos"; repo = "web-ui"; rev = "v${version}"; - hash = "sha256-axiedPKId1OmQvYqKiShI7rgWEJ+6zMcTRSuChKuPcw="; + hash = "sha256-p559HACpt6oPVncb/hYSu7/rC9agsVOtHS9GRGsce4s="; fetchSubmodules = true; }; diff --git a/pkgs/by-name/so/sonarqube-cli/package.nix b/pkgs/by-name/so/sonarqube-cli/package.nix index 4921665c860a..8db26b69c245 100644 --- a/pkgs/by-name/so/sonarqube-cli/package.nix +++ b/pkgs/by-name/so/sonarqube-cli/package.nix @@ -9,7 +9,7 @@ stdenv.mkDerivation (finalAttrs: { __structuredAttrs = true; pname = "sonarqube-cli"; - version = "1.5.0.4158"; + version = "1.6.0.4255"; src = let @@ -18,15 +18,15 @@ stdenv.mkDerivation (finalAttrs: { { x86_64-linux = fetchurl { url = "${baseUrl}/linux/sonarqube-cli-${finalAttrs.version}-linux-x86-64.bin"; - hash = "sha256-29TuICV/cwEK1/iiwlUjcwOe42EK8lJBbm8T9/+RVGA="; + hash = "sha256-397cnvrCuT0mNLlxsnI0iMzIwwoQ/+1ddgK9uleobWU="; }; aarch64-linux = fetchurl { url = "${baseUrl}/linux/sonarqube-cli-${finalAttrs.version}-linux-arm64.bin"; - hash = "sha256-WWAY7AP2KCWI5r3laQRiWkq9DGXD5Nw+Bans0oOBxkQ="; + hash = "sha256-483uWjI5lWTTd6dnzj6k/8Pw1WsAdeBJDfshqhROZDM="; }; aarch64-darwin = fetchurl { url = "${baseUrl}/macos/sonarqube-cli-${finalAttrs.version}-macos-arm64.bin"; - hash = "sha256-GB32aiW2yrakQo94L+J54BN0CIwfMkD9lG97kdNUV+Y="; + hash = "sha256-X/OdRLCEXkEzNHGOw3zfh2zuqitdOxB285lCb+9i71s="; }; } .${stdenv.hostPlatform.system} or (throw "Unsupported system: ${stdenv.hostPlatform.system}"); diff --git a/pkgs/by-name/ss/sstorytime/package.nix b/pkgs/by-name/ss/sstorytime/package.nix new file mode 100644 index 000000000000..1a3a1c91b231 --- /dev/null +++ b/pkgs/by-name/ss/sstorytime/package.nix @@ -0,0 +1,138 @@ +{ + lib, + buildGoModule, + fetchFromGitHub, + makeWrapper, + postgresql, + postgresqlTestHook, + writableTmpDirAsHomeHook, + nix-update-script, + nixosTests, +}: + +buildGoModule (finalAttrs: { + pname = "sstorytime"; + version = "0-unstable-2026-08-12"; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "markburgess"; + repo = "SSTorytime"; + rev = "9085a82bd2357e914d862879224bc9d807f7e049"; + hash = "sha256-ZA3qN//bkCU+yl7uych8Pz7J4AbtlBwRxqV/d/GkEZg="; + }; + + vendorHash = "sha256-lei5IG02QYSigHmLArlE7huDFVGoVMkw8DTEQeJWFX0="; + + nativeBuildInputs = [ makeWrapper ]; + + ldflags = [ + "-s" + "-w" + ]; + + excludedPackages = [ + "API_EXAMPLE" + "demo_pocs" + ]; + + outputs = [ + "out" + "examples" + ]; + + # Prefer installCheck so a cd into tests/ cannot clobber install. + # postgresqlTestHook only registers preCheck/postCheck hooks, so start/stop explicitly. + doCheck = false; + doInstallCheck = true; + + nativeInstallCheckInputs = [ + postgresql + postgresqlTestHook + writableTmpDirAsHomeHook + ]; + + # Peer on the hook's Unix socket: role = build user. SUPERUSER for schema setup. + env = { + PGUSER = "nixbld"; + PGDATABASE = "sstoryline"; + postgresqlTestUserOptions = "LOGIN SUPERUSER"; + }; + + postInstall = '' + # cmd/server installs as "server"; upstream Makefile calls it http_server. + mv $out/bin/server $out/bin/http_server + + mkdir -p $examples/share + cp -a examples $examples/share/ + install -Dm644 SSTconfig/* -t $out/share/SSTconfig + ''; + + postFixup = '' + for bin in $out/bin/*; do + wrapProgram "$bin" \ + --set-default SST_CONFIG_PATH "$out/share/SSTconfig" + done + ''; + + installCheckPhase = '' + runHook preInstallCheck + + postgresqlStart + export POSTGRESQL_URI="postgresql://$PGUSER@/$PGDATABASE?host=$PGHOST" + + failed=0 + bin=$out/bin/N4L + + for f in tests/pass_*.in; do + if "$bin" -adj=all "$f" >/dev/null; then + echo "ok $f" + else + echo "FAIL $f" + failed=1 + fi + done + + for f in tests/fail_*.in; do + if "$bin" "$f" >/dev/null 2>&1; then + echo "FAIL $f (expected non-zero exit)" + failed=1 + else + echo "ok $f" + fi + done + + if "$bin" -u examples/doors.n4l >/dev/null; then + echo "ok N4L -u doors.n4l" + else + echo "FAIL N4L -u doors.n4l" + failed=1 + fi + + postgresqlStop + + if [ "$failed" -ne 0 ]; then + exit 1 + fi + + runHook postInstallCheck + ''; + + passthru = { + tests = { inherit (nixosTests) sstorytime; }; + updateScript = nix-update-script { + extraArgs = [ "--version=branch" ]; + }; + }; + + meta = { + description = "Unified graph process for mapping knowledge"; + homepage = "https://github.com/markburgess/SSTorytime"; + license = lib.licenses.asl20; + platforms = lib.platforms.linux; + teams = [ lib.teams.ngi ]; + maintainers = [ lib.maintainers.lucasew ]; + mainProgram = "N4L"; + }; +}) diff --git a/pkgs/by-name/tr/trailbase/package.nix b/pkgs/by-name/tr/trailbase/package.nix new file mode 100644 index 000000000000..2ca06a58f780 --- /dev/null +++ b/pkgs/by-name/tr/trailbase/package.nix @@ -0,0 +1,123 @@ +{ + lib, + rustPlatform, + fetchFromGitHub, + fetchPnpmDeps, + pkg-config, + protobuf, + cmake, + cacert, + geos, + nodejs, + pnpm_11, + pnpmConfigHook, + versionCheckHook, + nix-update-script, + nixosTests, +}: + +let + pnpm = pnpm_11; +in +rustPlatform.buildRustPackage (finalAttrs: { + pname = "trailbase"; + version = "0.32.2"; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "trailbaseio"; + repo = "trailbase"; + tag = "v${finalAttrs.version}"; + hash = "sha256-b+HtxTg9UN5uvix9FkzRnRr7eP6dLVGz0v8UPqeTqaM="; + fetchSubmodules = true; + }; + + cargoHash = "sha256-RUbP49jXJj8UC2Sww0UlH8uyEpkshi2gewNqZ7XYeG4="; + + patches = [ ./skip-pnpm-install.patch ]; + + # Skip cargo's workspace-wide pnpm install; pnpmConfigHook already did it. + env.TRAILBASE_SKIP_PNPM_INSTALL = "1"; + + # Package plus its workspace dependencies: + # https://pnpm.io/filtering#--filter-package_name-1 + pnpmWorkspaces = [ "trailbase-admin-ui..." ]; + + pnpmDeps = fetchPnpmDeps { + inherit (finalAttrs) + pname + version + src + pnpmWorkspaces + ; + inherit pnpm; + fetcherVersion = 4; + hash = "sha256-ue2hqveVMWEIB9GUD3NCohPO2VW2G+17L/OqLhz6UeE="; + }; + + # wasmtime's cargo-auditable build is broken: + # https://github.com/rust-secure-code/cargo-auditable/issues/124 + auditable = false; + + nativeBuildInputs = [ + cmake + pkg-config + protobuf + nodejs + pnpm + pnpmConfigHook + rustPlatform.bindgenHook + ]; + + buildInputs = [ geos ]; + + postPatch = '' + # `trail --version` prints the git tag. fetchFromGitHub has no .git. + substituteInPlace crates/build/src/version.rs \ + --replace-fail 'get_output("git", &["describe", "--tags", "--match=v*", "--long"])' \ + 'Some("v${finalAttrs.version}".to_string())' + ''; + + cargoBuildFlags = [ + "--bin" + "trail" + ]; + + # test_utils is behind `#[cfg(debug_assertions)]`. + checkType = "debug"; + + # reqwest/rustls refuses to build a client without a CA bundle, + # even for the local HTTP OAuth mock. + nativeCheckInputs = [ cacert ]; + + # Full client e2e needs a seeded depot, WASM guests, and email. + # The NixOS test covers login + record CRUD against the packaged server. + checkFlags = [ "--skip=client_integration_test" ]; + + nativeInstallCheckInputs = [ versionCheckHook ]; + versionCheckProgramArg = "--version"; + doInstallCheck = true; + + passthru = { + tests = { + inherit (nixosTests) trailbase; + }; + services.default = { + imports = [ (lib.modules.importApply ./service.nix { }) ]; + trailbase.package = lib.mkDefault finalAttrs.finalPackage; + }; + updateScript = nix-update-script { }; + }; + + meta = { + description = "Single-executable Firebase alternative with type-safe APIs, auth, and an admin UI"; + homepage = "https://trailbase.io"; + changelog = "https://github.com/trailbaseio/trailbase/releases/tag/v${finalAttrs.version}"; + license = lib.licenses.osl3; + maintainers = [ lib.maintainers.lucasew ]; + teams = [ lib.teams.ngi ]; + mainProgram = "trail"; + platforms = lib.platforms.unix; + }; +}) diff --git a/pkgs/by-name/tr/trailbase/service.nix b/pkgs/by-name/tr/trailbase/service.nix new file mode 100644 index 000000000000..1eaafc4baa42 --- /dev/null +++ b/pkgs/by-name/tr/trailbase/service.nix @@ -0,0 +1,84 @@ +# Non-module dependencies (`importApply`) +{ }: + +# Service module +{ + lib, + config, + options, + ... +}: +let + inherit (lib) + getExe + mkOption + types + ; + cfg = config.trailbase; +in +{ + _class = "service"; + + meta = { + maintainers = [ lib.maintainers.lucasew ]; + teams = [ lib.teams.ngi ]; + }; + + options = { + trailbase = { + package = mkOption { + description = "Package to use for TrailBase."; + defaultText = "The package that provided this module."; + type = types.package; + }; + + address = mkOption { + description = "Authority (`:`) the HTTP server binds to."; + type = types.str; + default = "127.0.0.1:4000"; + example = "0.0.0.0:4000"; + }; + + depot = mkOption { + description = "Directory for runtime files including the databases."; + type = types.str; + default = "/var/lib/trailbase"; + }; + + extraArgs = mkOption { + description = "Extra arguments to pass to `trail run`."; + type = types.listOf types.str; + default = [ ]; + }; + }; + }; + + config = { + process.argv = [ + (getExe cfg.package) + "--depot" + cfg.depot + "run" + "--address" + cfg.address + ] + ++ cfg.extraArgs; + } + // lib.optionalAttrs (options ? systemd) { + systemd.service = { + description = "TrailBase"; + after = [ "network.target" ]; + wants = [ "network.target" ]; + wantedBy = [ "multi-user.target" ]; + serviceConfig = { + Type = "simple"; + Restart = "on-failure"; + DynamicUser = true; + StateDirectory = "trailbase"; + StateDirectoryMode = "0700"; + WorkingDirectory = "%S/trailbase"; + UMask = "0077"; + }; + }; + }; +} diff --git a/pkgs/by-name/tr/trailbase/skip-pnpm-install.patch b/pkgs/by-name/tr/trailbase/skip-pnpm-install.patch new file mode 100644 index 000000000000..f4292029b583 --- /dev/null +++ b/pkgs/by-name/tr/trailbase/skip-pnpm-install.patch @@ -0,0 +1,81 @@ +Skip workspace-wide `pnpm install` when JS deps are already installed. + +Nixpkgs installs the filtered admin UI workspace via pnpmConfigHook. +A second install walks every workspace member and fails offline. + +--- a/crates/build/src/lib.rs ++++ b/crates/build/src/lib.rs +@@ -92,39 +92,43 @@ + Ok("TRUE") | Ok("true") | Ok("1") + ); + +- // Note that `--frozen-lockfile` and `-ignore-workspace` are practically exclusive +- // Because ignoring the workspace one, will require to create a new lockfile. +- let out_dir = std::env::var("OUT_DIR").unwrap(); +- let build_result = if out_dir.contains("target/package") { +- // When we build cargo packages, we cannot rely on the workspace itself and prior installs. +- pnpm_run(&["--dir", &path, "install", "--ignore-workspace"]) +- } else { +- // `trailbase-assets` and `trailbase-js` both build JS packages. We've seen issues with +- // parallel installs in the past. Our current approach is to recommend installing workspace +- // JS deps upfront in combination with `--prefer-offline`. We used to use plain `--offline`, +- // however this adds an extra mandatory step when vendoring trailbase for framework use-cases. +- let args = if strict_offline { +- ["--dir", &path, "install", "--frozen-lockfile", "--offline"] ++ // Packagers such as Nixpkgs install JS deps before `cargo build`. ++ // Skip the extra workspace-wide install in that case. ++ if std::env::var_os("TRAILBASE_SKIP_PNPM_INSTALL").is_none() { ++ // Note that `--frozen-lockfile` and `-ignore-workspace` are practically exclusive ++ // Because ignoring the workspace one, will require to create a new lockfile. ++ let out_dir = std::env::var("OUT_DIR").unwrap(); ++ let build_result = if out_dir.contains("target/package") { ++ // When we build cargo packages, we cannot rely on the workspace itself and prior installs. ++ pnpm_run(&["--dir", &path, "install", "--ignore-workspace"]) + } else { +- [ +- "--dir", +- &path, +- "install", +- "--prefer-frozen-lockfile", +- "--prefer-offline", +- ] ++ // `trailbase-assets` and `trailbase-js` both build JS packages. We've seen issues with ++ // parallel installs in the past. Our current approach is to recommend installing workspace ++ // JS deps upfront in combination with `--prefer-offline`. We used to use plain `--offline`, ++ // however this adds an extra mandatory step when vendoring trailbase for framework use-cases. ++ let args = if strict_offline { ++ ["--dir", &path, "install", "--frozen-lockfile", "--offline"] ++ } else { ++ [ ++ "--dir", ++ &path, ++ "install", ++ "--prefer-frozen-lockfile", ++ "--prefer-offline", ++ ] ++ }; ++ let build_result = pnpm_run(&args); ++ if build_result.is_err() { ++ error!( ++ "`pnpm {}` failed. Make sure to install all JS deps first using `pnpm install`", ++ args.join(" ") ++ ) ++ } ++ build_result + }; +- let build_result = pnpm_run(&args); +- if build_result.is_err() { +- error!( +- "`pnpm {}` failed. Make sure to install all JS deps first using `pnpm install`", +- args.join(" ") +- ) +- } +- build_result +- }; + +- let _ = build_result?; ++ let _ = build_result?; ++ } + + // Enable source maps for debug builds: + // let build_output = pnpm_run(&["--dir", &path, "build", "--sourcemap", "inline"]); diff --git a/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix b/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix index f3e28bf47d1a..9872efd70681 100644 --- a/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix +++ b/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix @@ -235,10 +235,10 @@ }; cairo = { - version = "0-unstable-2026-06-14"; + version = "0-unstable-2026-07-23"; url = "github:starkware-libs/tree-sitter-cairo"; - rev = "b04ffb8c10a1a9faaea71a6757753fed4e1fcbfb"; - hash = "sha256-XMv3E/QVL3JroaHUc+ao7bfINB+q1J78hfttXk3GtS4="; + rev = "638b096f276196e0e201970f39f665c2e4613b0d"; + hash = "sha256-96ez0mUvbnKqs/ciI4sg7FryXd7w+FXxTI07fmPpZwo="; meta = { license = lib.licenses.asl20; maintainers = with lib.maintainers; [ @@ -516,9 +516,9 @@ }; diff = { - version = "0.1.0"; + version = "0.2.0"; url = "github:the-mikedavis/tree-sitter-diff"; - hash = "sha256-8rYLNGgoZSvvfqO2++nAgFKmvbkKJ3m+9B8bTXp6Us4="; + hash = "sha256-5HCBFE/99DJ9AYWSk18WRF3RGQpgpYAYA37bT54F0DI="; meta = { license = lib.licenses.mit; maintainers = with lib.maintainers; [ @@ -625,7 +625,7 @@ }; ebnf = { - version = "0-unstable-2023-02-06"; + version = "0.1.1-unstable-2023-02-06"; url = "github:RubixDev/ebnf"; rev = "8e635b0b723c620774dfb8abf382a7f531894b40"; hash = "sha256-Cch6WCYq9bsWGypzDGapxBLJ0ZB432uAl6YjEjBJ5yg="; @@ -2619,9 +2619,9 @@ }; robot = { - version = "1.4.0"; + version = "1.5.0"; url = "github:Hubro/tree-sitter-robot"; - hash = "sha256-U89K9S7zkUZ0CoT2FgvKIvQ3ApjRe59YoWrks/iQ0FM="; + hash = "sha256-LRVkqtEAYO3jHQTGTgO6I4ZNlYRrMRK8+FCd0expFK0="; meta = { license = lib.licenses.isc; maintainers = with lib.maintainers; [ @@ -2713,9 +2713,9 @@ }; scala = { - version = "0.26.0"; + version = "0.26.2"; url = "github:tree-sitter/tree-sitter-scala"; - hash = "sha256-CnTcQFqYp60rGkLVLRHokUwBenqtWV4hw8boFYNRkbw="; + hash = "sha256-PRyNcsiGeGfKtHvbLaGtiog/P8QEs117rqoBZZOXbeE="; meta = { license = lib.licenses.mit; }; @@ -2910,9 +2910,9 @@ }; ssh-client-config = rec { - version = "2026.7.9"; + version = "2026.8.20"; url = "github:metio/tree-sitter-ssh-client-config?ref=${version}"; - hash = "sha256-La1h6uJC5gUA84OAr3zBbQiR+AnrhcUhNf6r4HUpwhg="; + hash = "sha256-uwiDL2Rc2kW7TiRqtjmAocceLJOFT/9yDtR4c1IU7PI="; meta.license = lib.licenses.cc0; }; @@ -3006,9 +3006,9 @@ }; systemverilog = { - version = "0.3.1"; + version = "0.4.0"; url = "github:gmlarumbe/tree-sitter-systemverilog"; - hash = "sha256-wzsjHDn6ZdGfOlufARurxCTwT8HqMvyfsnIIpXzRUYs="; + hash = "sha256-ig4mpzN/bvnD5e5MN11a7YkONDeJ3R8kz/AbS0GDreI="; meta.license = lib.licenses.mit; }; @@ -3200,9 +3200,9 @@ }; tql = { - version = "1.1.0"; + version = "1.2.0"; url = "github:tenzir/tree-sitter-tql"; - hash = "sha256-2XbSwUKSNcODT2GIQ/k4w+4DSbV8dH689DrYBnWhPfU="; + hash = "sha256-lfrEKZSHFA4JYjDQ98bVTORPlgSV2veGcGwYbspaYaA="; meta.license = lib.licenses.mit; }; @@ -3384,10 +3384,10 @@ }; vhdl = { - version = "1.5.0-unstable-2026-06-06"; + version = "1.5.0-unstable-2026-08-10"; url = "github:jpt13653903/tree-sitter-vhdl"; - rev = "e97406d6ddfbed73dd8cdfcc3cf4c7b200b4211d"; - hash = "sha256-2vSkL8DetMtTRpvujg4tzxW2AbAhz56qBWRmgA8u3qk="; + rev = "68dc07f69d9571c2ebea6b32f995925905d09741"; + hash = "sha256-TWn6KXkn+FTIATpATrMTCWk8HknZCUEK0dllkljP/z4="; meta = { license = lib.licenses.mit; maintainers = with lib.maintainers; [ @@ -3410,10 +3410,10 @@ }; vim = { - version = "0.8.1-unstable-2026-02-26"; + version = "0.8.1-unstable-2026-07-12"; url = "github:tree-sitter-grammars/tree-sitter-vim"; - rev = "3092fcd99eb87bbd0fc434aa03650ba58bd5b43b"; - hash = "sha256-MnLBFuJCJbetcS07fG5fkCwHtf/EcNP+Syf0Gn0K39c="; + rev = "039c8d0aa1deae00ddeb0374dd70bcc0ec56938d"; + hash = "sha256-i+CfSWLRXhR2g98cGlfW4iRhNb3nt8O+WJ1Bjf2tnEM="; meta = { license = lib.licenses.mit; }; diff --git a/pkgs/by-name/va/vacuum-go/package.nix b/pkgs/by-name/va/vacuum-go/package.nix index 892d91c19f21..5b34c6c79898 100644 --- a/pkgs/by-name/va/vacuum-go/package.nix +++ b/pkgs/by-name/va/vacuum-go/package.nix @@ -7,16 +7,16 @@ buildGoModule (finalAttrs: { pname = "vacuum-go"; - version = "0.30.0"; + version = "0.30.1"; src = fetchFromGitHub { owner = "daveshanley"; repo = "vacuum"; tag = "v${finalAttrs.version}"; - hash = "sha256-jWOCStvDpY+luK17H09qysveMXCW+LYbXk+/1Y/4zgs="; + hash = "sha256-P9d24F2ij32QG7j9bOch9EEGepDV77lLMpMO3pEzMIg="; }; - vendorHash = "sha256-GOZNxnzk0rpm+rWKSEVsgVyITQRV6hv+sOwOQ9dByF4="; + vendorHash = "sha256-IX80z+3IpgZPqdklJzTZyOlLDM6Qbw8y1Q344r5TYpc="; env.CGO_ENABLED = 0; ldflags = [ diff --git a/pkgs/by-name/xs/xssearch/package.nix b/pkgs/by-name/xs/xssearch/package.nix new file mode 100644 index 000000000000..2dd5ccbacf38 --- /dev/null +++ b/pkgs/by-name/xs/xssearch/package.nix @@ -0,0 +1,38 @@ +{ + lib, + fetchFromGitHub, + nix-update-script, + rustPlatform, + versionCheckHook, +}: + +rustPlatform.buildRustPackage (finalAttrs: { + pname = "xssearch"; + version = "0.1.9"; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "affolter-engineering"; + repo = "xssearch"; + tag = finalAttrs.version; + hash = "sha256-09knkYBnIjZsdAlczYIeqtn0XGAvCD+RF3o9sGSUorw="; + }; + + cargoHash = "sha256-t+IcNrjHlVVKrYuLiRrlteT4jQLRiWUsj9RTTTflTiA="; + + nativeInstallCheckInputs = [ versionCheckHook ]; + + doInstallCheck = true; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "Advanced XSS detection tool"; + homepage = "https://github.com/affolter-engineering/xssearch"; + changelog = "https://github.com/affolter-engineering/xssearch/releases/tag/${finalAttrs.src.tag}"; + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ fab ]; + mainProgram = "xssearch"; + }; +}) diff --git a/pkgs/development/ocaml-modules/autofonce/default.nix b/pkgs/development/ocaml-modules/autofonce/default.nix new file mode 100644 index 000000000000..8b1661c9016a --- /dev/null +++ b/pkgs/development/ocaml-modules/autofonce/default.nix @@ -0,0 +1,65 @@ +{ + lib, + buildDunePackage, + fetchFromGitHub, + ppx_expect, + ppx_inline_test, + ocplib_stuff, + ez_file, + ez_cmdliner, + ansiterminal, + crunch, + toml, +}: + +buildDunePackage (finalAttrs: { + pname = "autofonce"; + version = "0.9-unstable-2026-06-25"; + + minimalOCamlVersion = "4.10"; + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "OCamlPro"; + repo = "autofonce"; + rev = "36c577b642ba5355e5a448ccef62a973fadd1eb6"; + hash = "sha256-mdnPBFN57aYglcIKHlYEwzBLh97yJVIrzS0JJTIC0lI="; + }; + + nativeBuildInputs = [ + crunch + ]; + + propagatedBuildInputs = [ + ppx_expect + ppx_inline_test + ocplib_stuff + ez_file + ez_cmdliner + ansiterminal + toml + ]; + + dunePackages = [ + "autofonce" + "autofonce_core" + "autofonce_lib" + "autofonce_m4" + "autofonce_share" + "autofonce_patch" + "autofonce_config" + "autofonce_misc" + "ez_win32" + "ez_call" + ]; + + doCheck = true; + + meta = { + description = "Modern runner for GNU Autoconf testsuites in m4"; + homepage = "https://ocamlpro.github.io/autofonce/sphinx/"; + license = lib.licenses.gpl3Only; + maintainers = [ lib.maintainers.sempiternal-aurora ]; + mainProgram = "autofonce"; + }; +}) diff --git a/pkgs/development/ocaml-modules/camomile/0.8.5.nix b/pkgs/development/ocaml-modules/camomile/0.8.5.nix deleted file mode 100644 index ebf33cec061d..000000000000 --- a/pkgs/development/ocaml-modules/camomile/0.8.5.nix +++ /dev/null @@ -1,43 +0,0 @@ -{ - stdenv, - lib, - fetchurl, - fetchpatch, - ocaml, - findlib, - camlp4, -}: - -stdenv.mkDerivation { - pname = "camomile"; - version = "0.8.5"; - - src = fetchurl { - url = "https://github.com/yoriyuki/Camomile/releases/download/rel-0.8.5/camomile-0.8.5.tar.bz2"; - sha256 = "003ikpvpaliy5hblhckfmln34zqz0mk3y2m1fqvbjngh3h2np045"; - }; - - patches = [ - (fetchpatch { - url = "https://raw.githubusercontent.com/ocaml/opam-repository/master/packages/camomile/camomile.0.8.5/files/4.05-typing-fix.patch"; - sha256 = "167279lia6qx62mdcyc5rjsi4gf4yi52wn9mhgd9y1v3754z7fwb"; - }) - ]; - - nativeBuildInputs = [ - ocaml - findlib - camlp4 - ]; - - strictDeps = true; - - createFindlibDestdir = true; - - meta = { - homepage = "https://github.com/yoriyuki/Camomile/tree/master/Camomile"; - description = "Comprehensive Unicode library for OCaml"; - license = lib.licenses.lgpl21; - inherit (ocaml.meta) platforms; - }; -} diff --git a/pkgs/development/ocaml-modules/drom/default.nix b/pkgs/development/ocaml-modules/drom/default.nix new file mode 100644 index 000000000000..409d06fdd38e --- /dev/null +++ b/pkgs/development/ocaml-modules/drom/default.nix @@ -0,0 +1,71 @@ +{ + lib, + buildDunePackage, + fetchFromGitHub, + ppx_expect, + ppx_inline_test, + ppx_protocol_conv, + otoml, + jingoo, + ez_subst, + ez_opam_file, + ez_file, + ez_cmdliner, + directories, + bos, + fmt, + omd, + iso8601, + menhir, + menhirLib, +}: + +buildDunePackage (finalAttrs: { + pname = "drom"; + version = "0.9.3"; + + minimalOCamlVersion = "4.14"; + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "OCamlPro"; + repo = "drom"; + tag = "v${finalAttrs.version}"; + hash = "sha256-R/n3mVxMVJ1Fnmy+tU5gMngF9oFbdTEiils2hJGTWzk="; + }; + + nativeBuildInputs = [ menhir ]; + + propagatedBuildInputs = [ + ppx_inline_test + ppx_expect + ppx_protocol_conv + otoml + jingoo + ez_subst + ez_opam_file + ez_file + ez_cmdliner + directories + bos + fmt + omd + iso8601 + menhirLib + ]; + + dunePackages = [ + "drom" + "drom_lib" + "drom_toml" + ]; + + doCheck = true; + + meta = { + description = "Drom is a wrapper over opam/dune in an attempt to provide a cargo-like user experience"; + homepage = "https://ocamlpro.github.io/drom/"; + license = lib.licenses.WITH lib.licenses.lgpl21Only lib.licenses.ocamlLgplLinkingException; + maintainers = [ lib.maintainers.sempiternal-aurora ]; + }; +}) diff --git a/pkgs/development/ocaml-modules/ez_api/default.nix b/pkgs/development/ocaml-modules/ez_api/default.nix new file mode 100644 index 000000000000..28b1f6992718 --- /dev/null +++ b/pkgs/development/ocaml-modules/ez_api/default.nix @@ -0,0 +1,38 @@ +{ + lib, + buildDunePackage, + fetchFromGitHub, + json-data-encoding, + ezjsonm, + uuidm, +}: + +buildDunePackage (finalAttrs: { + pname = "ez_api"; + version = "3.0.0"; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "OCamlPro"; + repo = "ez_api"; + tag = finalAttrs.version; + hash = "sha256-Z/mtgVzwJ118QLF3p6qy5jtYDstX2zUj2AlS+QVugDQ="; + }; + + propagatedBuildInputs = [ + json-data-encoding + ezjsonm + uuidm + ]; + + doCheck = true; + + meta = { + description = "Easily build clients and servers on top of a common REST API, automatically derived from OCaml types"; + homepage = "https://github.com/OCamlPro/ez_api"; + license = lib.licenses.WITH lib.licenses.lgpl21Only lib.licenses.ocamlLgplLinkingException; + maintainers = with lib.maintainers; [ sempiternal-aurora ]; + mainProgram = "ezserve"; + }; +}) diff --git a/pkgs/development/ocaml-modules/ez_cmdliner/default.nix b/pkgs/development/ocaml-modules/ez_cmdliner/default.nix new file mode 100644 index 000000000000..a0c41667ec6d --- /dev/null +++ b/pkgs/development/ocaml-modules/ez_cmdliner/default.nix @@ -0,0 +1,40 @@ +{ + lib, + buildDunePackage, + fetchFromGitHub, + ocplib_stuff, + ez_subst, + cmdliner, + ppx_inline_test, + ppx_expect, +}: +buildDunePackage (finalAttrs: { + pname = "ez_cmdliner"; + version = "0.5.0"; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "OCamlPro"; + repo = "ez_cmdliner"; + tag = "v${finalAttrs.version}"; + hash = "sha256-YZJLFoPlbGmbizapkrAofbrRRnUI4axW9fTwDpVv27U="; + }; + + propagatedBuildInputs = [ + ocplib_stuff + ez_subst + cmdliner + ppx_inline_test + ppx_expect + ]; + + doCheck = true; + + meta = { + description = "Easy Cmdliner"; + homepage = "https://github.com/OCamlPro/ez_cmdliner"; + license = lib.licenses.WITH lib.licenses.lgpl21Only lib.licenses.ocamlLgplLinkingException; + maintainers = [ lib.maintainers.sempiternal-aurora ]; + }; +}) diff --git a/pkgs/development/ocaml-modules/ez_file/default.nix b/pkgs/development/ocaml-modules/ez_file/default.nix new file mode 100644 index 000000000000..a0e9cab2ee94 --- /dev/null +++ b/pkgs/development/ocaml-modules/ez_file/default.nix @@ -0,0 +1,38 @@ +{ + lib, + buildDunePackage, + fetchFromGitHub, + re, + ocplib_stuff, + ppx_expect, +}: + +buildDunePackage (finalAttrs: { + pname = "ez_file"; + version = "0.5.0"; + + minimalOCamlVersion = "4.11"; + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "OCamlPro"; + repo = "ez_file"; + tag = "v${finalAttrs.version}"; + hash = "sha256-Lhnx2Co2qx4mPn9U1AXJpXJY5SgMQC1VtCxeN4bcK1w="; + }; + + propagatedBuildInputs = [ + re + ocplib_stuff + ppx_expect + ]; + + doCheck = true; + + meta = { + description = "Library with helpers to manipulate files, read/write their content, search directories, etc"; + homepage = "https://github.com/OCamlPro/ez_file"; + license = lib.licenses.WITH lib.licenses.lgpl21Only lib.licenses.ocamlLgplLinkingException; + maintainers = [ lib.maintainers.sempiternal-aurora ]; + }; +}) diff --git a/pkgs/development/ocaml-modules/ez_opam_file/default.nix b/pkgs/development/ocaml-modules/ez_opam_file/default.nix new file mode 100644 index 000000000000..b71dae6d1fa9 --- /dev/null +++ b/pkgs/development/ocaml-modules/ez_opam_file/default.nix @@ -0,0 +1,39 @@ +{ + lib, + buildDunePackage, + fetchFromGitHub, + ppx_inline_test, + ppx_expect, + opam-file-format, +}: + +buildDunePackage (finalAttrs: { + pname = "ez_opam_file"; + version = "0.1.0"; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "OCamlPro"; + repo = "ez_opam_file"; + tag = "v${finalAttrs.version}"; + hash = "sha256-L8IjDrmaA88sE43hTvMyJrSg7LqMD/UvTJdPsL+mq4g="; + }; + + patches = [ ./fix_version_check.patch ]; + + propagatedBuildInputs = [ + ppx_inline_test + ppx_expect + opam-file-format + ]; + + doCheck = true; + + meta = { + description = "Compatibility library for opam-file-format"; + homepage = "https://github.com/OCamlPro/ez_opam_file"; + license = lib.licenses.WITH lib.licenses.lgpl21Only lib.licenses.ocamlLgplLinkingException; + maintainers = [ lib.maintainers.sempiternal-aurora ]; + }; +}) diff --git a/pkgs/development/ocaml-modules/ez_opam_file/fix_version_check.patch b/pkgs/development/ocaml-modules/ez_opam_file/fix_version_check.patch new file mode 100644 index 000000000000..c4cb4eb5fea2 --- /dev/null +++ b/pkgs/development/ocaml-modules/ez_opam_file/fix_version_check.patch @@ -0,0 +1,41 @@ +diff --git a/src/ez_opam_file/dune b/src/ez_opam_file/dune +index 2d4f448..8430268 100644 +--- a/src/ez_opam_file/dune ++++ b/src/ez_opam_file/dune +@@ -1,35 +1,11 @@ +-(* -*- tuareg -*- *) +- +-let () = +- let version = ref "new" in +- let dir = Sys.getenv "OPAM_SWITCH_PREFIX" in +- let packages_dir = dir ^ "/.opam-switch/packages" in +- let packages = Sys.readdir packages_dir in +- Array.iter (fun package -> +- try +- let pos = String.index package '.' in +- let name = String.sub package 0 pos in +- let vers = String.sub package +- (pos+1) (String.length package - pos - 1) in +- if name = "opam-file-format" && vers < "2.1.1" then version := "old" +- with _ -> +- Printf.eprintf "package %s\n%!" package +- ) packages; +- +- let version = !version in +- Printf.kprintf +- Jbuild_plugin.V1.send +-{| + (library + (name ez_opam_file) + (public_name ez_opam_file) + (wrapped true) + (libraries opam-file-format +- (select v1.ml from ( -> v1.%s.ml)) ++ (select v1.ml from ( -> v1.new.ml)) + ) + ) + + (documentation + (package ez_opam_file)) +-|} +-version diff --git a/pkgs/development/ocaml-modules/ez_subst/default.nix b/pkgs/development/ocaml-modules/ez_subst/default.nix new file mode 100644 index 000000000000..c530dd3bd665 --- /dev/null +++ b/pkgs/development/ocaml-modules/ez_subst/default.nix @@ -0,0 +1,36 @@ +{ + lib, + buildDunePackage, + fetchFromGitHub, + ppx_expect, + ppx_inline_test, +}: + +buildDunePackage (finalAttrs: { + pname = "ez_subst"; + version = "0.2.1"; + + minimalOCamlVersion = "4.10"; + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "OCamlPro"; + repo = "ez_subst"; + tag = "v${finalAttrs.version}"; + hash = "sha256-d0+H9dxLioa9QHnf2mF+MBk563qxc7YBhpmV1A0uv0s="; + }; + + propagatedBuildInputs = [ + ppx_inline_test + ppx_expect + ]; + + doCheck = true; + + meta = { + description = "Simple substitution module for OCaml"; + homepage = "https://github.com/OCamlPro/ez_subst"; + license = lib.licenses.WITH lib.licenses.lgpl21Only lib.licenses.ocamlLgplLinkingException; + maintainers = [ lib.maintainers.sempiternal-aurora ]; + }; +}) diff --git a/pkgs/development/ocaml-modules/goblint-cil/default.nix b/pkgs/development/ocaml-modules/goblint-cil/default.nix new file mode 100644 index 000000000000..552585e1d0d2 --- /dev/null +++ b/pkgs/development/ocaml-modules/goblint-cil/default.nix @@ -0,0 +1,56 @@ +{ + lib, + buildDunePackage, + fetchFromGitHub, + hevea, + zarith, + dune-configurator, + stdlib-shims, + ppx_deriving_yojson, + yojson, + findlib, + cppo, + gcc, + perl, +}: + +buildDunePackage (finalAttrs: { + pname = "goblint-cil"; + version = "2.1.1"; + + minimalOCamlVersion = "4.12"; + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "goblint"; + repo = "cil"; + tag = finalAttrs.version; + hash = "sha256-nfu8LqTNyx/pkTlAHSay8q3KSYQ+asNAnnZjPUhkNwg="; + }; + + nativeBuildInputs = [ + hevea + cppo + gcc + ]; + + propagatedBuildInputs = [ + zarith + dune-configurator + stdlib-shims + ppx_deriving_yojson + yojson + findlib + perl + ]; + + # Currently broken, doesn't properly pass all tests, fails with many compile errors + doCheck = false; + + meta = { + description = "Front-end for the C programming language that facilitates program analysis and transformation"; + homepage = "https://goblint.github.io/cil/"; + license = lib.licenses.bsd3; + maintainers = [ lib.maintainers.sempiternal-aurora ]; + }; +}) diff --git a/pkgs/development/ocaml-modules/janestreet/0.12.nix b/pkgs/development/ocaml-modules/janestreet/0.12.nix deleted file mode 100644 index 01f91f7b9522..000000000000 --- a/pkgs/development/ocaml-modules/janestreet/0.12.nix +++ /dev/null @@ -1,586 +0,0 @@ -{ - self, - openssl, -}: - -with self; - -{ - - ocaml-compiler-libs = janePackage { - pname = "ocaml-compiler-libs"; - hash = "0g9y1ljjsj1nw0lz460ivb6qmz9vhcmfl8krlmqfrni6pc7b0r6f"; - meta.description = "OCaml compiler libraries repackaged"; - }; - - sexplib0 = janePackage { - pname = "sexplib0"; - hash = "13xdd0pvypxqn0ldwdgikmlinrp3yfh8ixknv1xrpxbx3np4qp0g"; - meta.description = "Library containing the definition of S-expressions and some base converters"; - }; - - base = janePackage { - pname = "base"; - version = "0.12.2"; - hash = "0gl89zpgsf3n30nb6v5cns27g2bfg4rf3s2427gqvwbkr5gcf7ri"; - meta.description = "Full standard library replacement for OCaml"; - propagatedBuildInputs = [ sexplib0 ]; - buildInputs = [ dune-configurator ]; - }; - - stdio = janePackage { - pname = "stdio"; - hash = "1pn8jjcb79n6crpw7dkp68s4lz2mw103lwmfslil66f05jsxhjhg"; - meta.description = "Standard IO library for OCaml"; - propagatedBuildInputs = [ base ]; - }; - - ppx_sexp_conv = janePackage { - pname = "ppx_sexp_conv"; - hash = "0idzp1kzds0gnilschzs9ydi54if8y5xpn6ajn710vkipq26qcld"; - meta.description = "[@@deriving] plugin to generate S-expression conversion functions"; - propagatedBuildInputs = [ ppxlib ]; - }; - - ppx_here = janePackage { - pname = "ppx_here"; - hash = "07qbchwif1i9ii8z7v1bib57d3mjv0b27i8iixw78i83wnsycmdx"; - meta.description = "Expands [%here] into its location"; - propagatedBuildInputs = [ ppxlib ]; - }; - - ppx_compare = janePackage { - pname = "ppx_compare"; - hash = "0n1ax4k2smhps9hc2v58lc06a0fgimwvbi1aj4x78vwh5j492bys"; - meta.description = "Generation of comparison functions from types"; - propagatedBuildInputs = [ ppxlib ]; - }; - - ppx_assert = janePackage { - pname = "ppx_assert"; - hash = "0as6mzr6ki2a9d4k6132p9dskn0qssla1s7j5rkzp75bfikd0ip8"; - meta.description = "Assert-like extension nodes that raise useful errors on failure"; - propagatedBuildInputs = [ - ppx_compare - ppx_here - ppx_sexp_conv - ]; - }; - - ppx_inline_test = janePackage { - pname = "ppx_inline_test"; - hash = "0nyz411zim94pzbxm2l2v2l9jishcxwvxhh142792g2s18r4vn50"; - meta.description = "Syntax extension for writing in-line tests in ocaml code"; - propagatedBuildInputs = [ ppxlib ]; - }; - - ppx_custom_printf = janePackage { - pname = "ppx_custom_printf"; - version = "0.12.1"; - hash = "0q7591agvd3qy9ihhbyk4db48r0ng7yxspfj8afxxiawl7k5bas6"; - meta.description = "Printf-style format-strings for user-defined string conversion"; - propagatedBuildInputs = [ ppx_sexp_conv ]; - }; - - fieldslib = janePackage { - pname = "fieldslib"; - hash = "0dlgr7cimqmjlcymk3bdcyzqzvdy12q5lqa844nqix0k2ymhyphf"; - meta.description = "Syntax extension to define first class values representing record fields, to get and set record fields, iterate and fold over all fields of a record and create new record values"; - propagatedBuildInputs = [ base ]; - }; - - ppx_fields_conv = janePackage { - pname = "ppx_fields_conv"; - hash = "0flrdyxdfcqcmdrbipxdjq0s3djdgs7z5pvjdycsvs6czbixz70v"; - meta.description = "Generation of accessor and iteration functions for ocaml records"; - propagatedBuildInputs = [ - fieldslib - ppxlib - ]; - }; - - variantslib = janePackage { - pname = "variantslib"; - hash = "1cclb5magk63gyqmkci8abhs05g2pyhyr60a2c1bvmig0faqcnsf"; - meta.description = "Part of Jane Street's Core library"; - propagatedBuildInputs = [ base ]; - }; - - ppx_variants_conv = janePackage { - pname = "ppx_variants_conv"; - hash = "05j9bgra8xq6fcp12ch3z9vjrk139p2wrcjjcs4h52n5hhc8vzbz"; - meta.description = "Generation of accessor and iteration functions for ocaml variant types"; - propagatedBuildInputs = [ - variantslib - ppxlib - ]; - }; - - ppx_expect = janePackage { - pname = "ppx_expect"; - hash = "1wawsbjfkri4sw52n8xqrzihxc3xfpdicv3ahz83a1rsn4lb8j5q"; - meta.description = "Cram like framework for OCaml"; - propagatedBuildInputs = [ - ppx_assert - ppx_custom_printf - ppx_fields_conv - ppx_inline_test - ppx_variants_conv - re - ]; - }; - - ppx_enumerate = janePackage { - pname = "ppx_enumerate"; - hash = "08zfpq6bdm5lh7xj9k72iz9f2ihv3aznl3nypw3x78vz1chj8dqa"; - meta.description = "Generate a list containing all values of a finite type"; - propagatedBuildInputs = [ ppxlib ]; - }; - - ppx_hash = janePackage { - pname = "ppx_hash"; - hash = "1dfsfvhiyp1mnf24mr93svpdn432kla0y7x631lssacxxp2sadbg"; - meta.description = "PPX rewriter that generates hash functions from type expressions and definitions"; - propagatedBuildInputs = [ - ppx_compare - ppx_sexp_conv - ]; - }; - - ppx_js_style = janePackage { - pname = "ppx_js_style"; - hash = "1lz931m3qdv3yzqy6dnb8fq1d99r61w0n7cwf3b9fl9rhk0pggwh"; - meta.description = "Code style checker for Jane Street Packages"; - propagatedBuildInputs = [ - octavius - ppxlib - ]; - }; - - ppx_base = janePackage { - pname = "ppx_base"; - hash = "0vd96rp2l084iamkwmvizzhl9625cagjb6gzzbir06czii5mlq2p"; - meta.description = "Base set of ppx rewriters"; - propagatedBuildInputs = [ - ppx_enumerate - ppx_hash - ppx_js_style - ]; - }; - - ppx_bench = janePackage { - pname = "ppx_bench"; - hash = "1ib81irawxzq091bmpi50z0kmpx6z2drg14k2xcgmwbb1d4063xn"; - meta.description = "Syntax extension for writing in-line benchmarks in ocaml code"; - propagatedBuildInputs = [ ppx_inline_test ]; - }; - - ppx_sexp_message = janePackage { - pname = "ppx_sexp_message"; - hash = "0yskd6v48jc6wa0nhg685kylh1n9qb6b7d1wglr9wnhl9sw990mc"; - meta.description = "PPX rewriter for easy construction of s-expressions"; - propagatedBuildInputs = [ - ppx_here - ppx_sexp_conv - ]; - }; - - splittable_random = janePackage { - pname = "splittable_random"; - hash = "1wpyz7807cgj8b50gdx4rw6f1zsznp4ni5lzjbnqdwa66na6ynr4"; - meta.description = "PRNG that can be split into independent streams"; - propagatedBuildInputs = [ - base - ppx_assert - ppx_bench - ppx_sexp_message - ]; - }; - - ppx_let = janePackage { - pname = "ppx_let"; - hash = "146dmyzkbmafa3giz69gpxccvdihg19cvk4xsg8krbbmlkvdda22"; - meta.description = "Monadic let-bindings"; - propagatedBuildInputs = [ ppxlib ]; - }; - - base_quickcheck = janePackage { - version = "0.12.1"; - pname = "base_quickcheck"; - hash = "sha256-ABfUtOzdtGrYR6EgtVYkmxRvsH48jJwSVVOwf4Od12Y="; - meta.description = "Randomized testing framework, designed for compatibility with Base"; - propagatedBuildInputs = [ - ppx_base - ppx_fields_conv - ppx_let - splittable_random - ]; - }; - - ppx_stable = janePackage { - pname = "ppx_stable"; - hash = "15zvf66wlkvz0yd4bkvndkpq74dj20jv1qkljp9n52hh7d0f9ykh"; - meta.description = "Stable types conversions generator"; - propagatedBuildInputs = [ ppxlib ]; - }; - - bin_prot = janePackage { - pname = "bin_prot"; - hash = "0hh6s7g9s004z35hsr8z6nw5phlcvcd6g2q3bj4f0s1s0anlsswm"; - meta.description = "Binary protocol generator"; - propagatedBuildInputs = [ - ppx_compare - ppx_custom_printf - ppx_fields_conv - ppx_variants_conv - ]; - }; - - ppx_bin_prot = janePackage { - pname = "ppx_bin_prot"; - version = "0.12.1"; - hash = "1j0kjgmv58dmg3x5dj5zrfbm920rwq21lvkkaqq493y76cd0x8xg"; - meta.description = "Generation of bin_prot readers and writers from types"; - propagatedBuildInputs = [ - bin_prot - ppx_here - ]; - }; - - ppx_fail = janePackage { - pname = "ppx_fail"; - hash = "0krsv6z9gi0ifxmw5ss6gwn108qhywyhbs41an10x9d5zpgf4l1n"; - meta.description = "Add location to calls to failwiths"; - propagatedBuildInputs = [ ppx_here ]; - }; - - jst-config = janePackage { - pname = "jst-config"; - hash = "0yxcz13vda1mdh9ah7qqxwfxpcqang5sgdssd8721rszbwqqaw93"; - meta.description = "Compile-time configuration for Jane Street libraries"; - buildInputs = [ - dune-configurator - ppx_assert - ]; - }; - - ppx_optcomp = janePackage { - pname = "ppx_optcomp"; - hash = "0bdbx01kz0174g1szdhv3mcfqxqqf2frxq7hk13xaf6fsz04kwmj"; - meta.description = "Optional compilation for OCaml"; - propagatedBuildInputs = [ ppxlib ]; - }; - - jane-street-headers = janePackage { - pname = "jane-street-headers"; - hash = "0qa4llf812rjqa8nb63snmy8d8ny91p3anwhb50afb7vjaby8m34"; - meta.description = "Jane Street C header files"; - }; - - time_now = janePackage { - pname = "time_now"; - hash = "169mgsb3rja4j1j9nj5xa7bbkd21p9kfpskqz0wjf9x2fpxqsniq"; - meta.description = "Reports the current time"; - buildInputs = [ - jst-config - ppx_optcomp - ]; - propagatedBuildInputs = [ - jane-street-headers - base - ppx_base - ]; - }; - - ppx_module_timer = janePackage { - pname = "ppx_module_timer"; - hash = "0yziakm7f4c894na76k1z4bp7azy82xc33mh36fj761w1j9zy3wm"; - meta.description = "Ppx rewriter that records top-level module startup times"; - propagatedBuildInputs = [ time_now ]; - }; - - ppx_optional = janePackage { - pname = "ppx_optional"; - hash = "07i0iipbd5xw2bc604qkwlcxmhncfpm3xmrr6svyj2ij86pyssh8"; - meta.description = "Pattern matching on flat options"; - propagatedBuildInputs = [ ppxlib ]; - }; - - ppx_pipebang = janePackage { - pname = "ppx_pipebang"; - hash = "1p4pdpl8h2bblbhpn5nk17ri4rxpz0aih0gffg3cl1186irkj0xj"; - meta.description = "PPX rewriter that inlines reverse application operators `|>` and `|!`"; - propagatedBuildInputs = [ ppxlib ]; - }; - - ppx_sexp_value = janePackage { - pname = "ppx_sexp_value"; - hash = "1mg81834a6dx1x7x9zb9wc58438cabjjw08yhkx6i386hxfy891p"; - meta.description = "PPX rewriter that simplifies building s-expressions from ocaml values"; - propagatedBuildInputs = [ - ppx_here - ppx_sexp_conv - ]; - }; - - typerep = janePackage { - pname = "typerep"; - hash = "1psl6gsk06a62szh60y5sc1s92xpmrl1wpw3rhha09v884b7arbc"; - meta.description = "Typerep is a library for runtime types"; - propagatedBuildInputs = [ base ]; - }; - - ppx_typerep_conv = janePackage { - pname = "ppx_typerep_conv"; - hash = "09vik6qma1id44k8nz87y48l9wbjhqhap1ar1hpfdfkjai1hrzzq"; - meta.description = "Generation of runtime types from type declarations"; - propagatedBuildInputs = [ - ppxlib - typerep - ]; - }; - - ppx_jane = janePackage { - pname = "ppx_jane"; - hash = "1a2602isqzsh640q20qbmarx0sc316mlsqc3i25ysv2kdyhh0kyw"; - meta.description = "Standard Jane Street ppx rewriters"; - propagatedBuildInputs = [ - base_quickcheck - ppx_bench - ppx_bin_prot - ppx_expect - ppx_fail - ppx_module_timer - ppx_optcomp - ppx_optional - ppx_pipebang - ppx_sexp_value - ppx_stable - ppx_typerep_conv - ]; - }; - - base_bigstring = janePackage { - pname = "base_bigstring"; - hash = "0rbgyg511847fbnxad40prz2dyp4da6sffzyzl88j18cxqxbh1by"; - meta.description = "String type based on [Bigarray], for use in I/O and C-bindings"; - propagatedBuildInputs = [ ppx_jane ]; - }; - - parsexp = janePackage { - pname = "parsexp"; - hash = "1974i9s2c2n03iffxrm6ncwbd2gg6j6avz5jsxfd35scc2zxcd4l"; - meta.description = "S-expression parsing library"; - propagatedBuildInputs = [ - base - sexplib0 - ]; - }; - - sexplib = janePackage { - pname = "sexplib"; - hash = "0780klc5nnv0ij6aklzra517cfnfkjdlp8ylwjrqwr8dl9rvxza2"; - meta.description = "Library for serializing OCaml values to and from S-expressions"; - propagatedBuildInputs = [ - num - parsexp - ]; - }; - - core_kernel = janePackage { - pname = "core_kernel"; - version = "0.12.3"; - hash = "sha256-bDgxuOILAs4FYB8o92ysPHDdEzflZMsU/jk5hB9xfuc="; - meta.description = "System-independent part of Core"; - buildInputs = [ jst-config ]; - propagatedBuildInputs = [ - base_bigstring - sexplib - ]; - }; - - spawn = janePackage { - pname = "spawn"; - version = "0.13.0"; - hash = "1w003k1kw1lmyiqlk58gkxx8rac7dchiqlz6ah7aj7bh49b36ppf"; - meta.description = "Spawning sub-processes"; - buildInputs = [ ppx_expect ]; - }; - - core = janePackage { - pname = "core"; - version = "0.12.3"; - hash = "1vmjqiafkg45hqfvahx6jnlaww1q4a4215k8znbgprf0qn3zymnj"; - meta.description = "System-independent part of Core"; - buildInputs = [ jst-config ]; - propagatedBuildInputs = [ - core_kernel - spawn - ]; - }; - - async_kernel = janePackage { - pname = "async_kernel"; - hash = "1d9illx7vvpblj1i2r9y0f2yff2fbhy3rp4hhvamq1n9n3lvxmh2"; - meta.description = "Monadic concurrency library"; - propagatedBuildInputs = [ core_kernel ]; - }; - - protocol_version_header = janePackage { - pname = "protocol_version_header"; - hash = "14vqhx3r84rlfhcjq52gxdqksckiaswlck9s47g7y2z1lsc17v7r"; - meta.description = "Protocol versioning"; - propagatedBuildInputs = [ core_kernel ]; - }; - - async_rpc_kernel = janePackage { - pname = "async_rpc_kernel"; - hash = "1znhqbzx4fp58i7dbcgyv5rx7difbhb5d8cbqzv96yqvbn67lsjk"; - meta.description = "Platform-independent core of Async RPC library"; - propagatedBuildInputs = [ - async_kernel - protocol_version_header - ]; - }; - - async_unix = janePackage { - pname = "async_unix"; - hash = "09h10rdyykbm88n6r9nb5a22mlb6vcxa04q6hvrcr0kys6qhhqmb"; - meta.description = "Monadic concurrency library"; - propagatedBuildInputs = [ - async_kernel - core - ]; - }; - - async_extra = janePackage { - pname = "async_extra"; - hash = "10j4mwlyqvf67yrp5dwd857llqjinpnnykmlzw2gpmks9azxk6mh"; - meta.description = "Monadic concurrency library"; - propagatedBuildInputs = [ - async_rpc_kernel - async_unix - ]; - }; - - textutils = janePackage { - pname = "textutils"; - hash = "0302awqihf3abib9mvzvn4g8m364hm6jxry1r3kc01hzybhy9acq"; - meta.description = "Text output utilities"; - propagatedBuildInputs = [ core ]; - }; - - async = janePackage { - pname = "async"; - hash = "0pk7z3h2gi21nfchvmjz2wx516bynf9vgwf84zf5qhvlvqqsmyrx"; - meta.description = "Monadic concurrency library"; - propagatedBuildInputs = [ - async_extra - textutils - ]; - }; - - async_find = janePackage { - pname = "async_find"; - hash = "0qsz9f15s5rlk6za10s810v6nlkdxg2g9p1827lcpa7nhjcpi673"; - meta.description = "Directory traversal with Async"; - propagatedBuildInputs = [ async ]; - }; - - re2 = janePackage { - pname = "re2"; - version = "0.12.1"; - hash = "sha256-NPQKKUSwckZx4GN4wX2sc0Mn7bes6p79oZrN6xouc6o="; - meta.description = "OCaml bindings for RE2, Google's regular expression library"; - propagatedBuildInputs = [ core_kernel ]; - prePatch = '' - substituteInPlace src/re2_c/dune --replace 'CXX=g++' 'CXX=c++' - substituteInPlace src/dune --replace '(cxx_flags (:standard \ -pedantic) (-I re2_c/libre2))' '(cxx_flags (:standard \ -pedantic) (-I re2_c/libre2) (-x c++))' - ''; - }; - - shell = janePackage { - pname = "shell"; - hash = "158857rdr6qgglc5iksg0l54jgf51b5lmsw7nlazpxwdwc9fcn5n"; - meta.description = "Yet another implementation of fork&exec and related functionality"; - buildInputs = [ jst-config ]; - propagatedBuildInputs = [ - re2 - textutils - ]; - }; - - async_shell = janePackage { - pname = "async_shell"; - hash = "0cxln9hkc3cy522la9yi9p23qjwl69kqmadsq4lnjh5bxdad06sv"; - meta.description = "Shell helpers for Async"; - propagatedBuildInputs = [ - async - shell - ]; - }; - - core_bench = janePackage { - pname = "core_bench"; - hash = "00hyzbbj19dkcw0vhfnc8w0ca3zkjriwwvl00ssa0a2g9mygijdm"; - meta.description = "Benchmarking library"; - propagatedBuildInputs = [ textutils ]; - }; - - core_extended = janePackage { - pname = "core_extended"; - hash = "1gwx66235irpf5krb1r25a3c7w52qhmass8hp7rdv89il9jn49w4"; - meta.description = "Extra components that are not as closely vetted or as stable as Core"; - propagatedBuildInputs = [ core ]; - }; - - sexp_pretty = janePackage { - pname = "sexp_pretty"; - hash = "06hdsaszc5cd7fphiblbn4r1sh36xgjwf2igzr2rvlzqs7jiv2v4"; - meta.description = "S-expression pretty-printer"; - propagatedBuildInputs = [ - ppx_base - re - sexplib - ]; - }; - - expect_test_helpers_kernel = janePackage { - pname = "expect_test_helpers_kernel"; - hash = "18ya187y2i2hfxr771sd9vy5jdsa30vhs56yjdhwk06v01b2fzbq"; - meta.description = "Helpers for writing expectation tests"; - buildInputs = [ ppx_jane ]; - propagatedBuildInputs = [ - core_kernel - sexp_pretty - ]; - }; - - expect_test_helpers = janePackage { - pname = "expect_test_helpers"; - hash = "0ixqck2lnsmz107yw0q2sr8va80skjpldx7lz4ymjiq2vsghk0rb"; - meta.description = "Async helpers for writing expectation tests"; - propagatedBuildInputs = [ - async - expect_test_helpers_kernel - ]; - }; - - patience_diff = janePackage { - pname = "patience_diff"; - hash = "055kd3piadjnplip8c8q99ssh79d4irmhg2wng7aida5pbqp2p9f"; - meta.description = "Diff library using Bram Cohen's patience diff algorithm"; - propagatedBuildInputs = [ core_kernel ]; - }; - - ecaml = janePackage { - pname = "ecaml"; - hash = "0n9xi6agc3lgyj2nsi10cbif0xwn57xyaranad9r285rmbxrgjh7"; - meta.description = "Library for writing Emacs plugin in OCaml"; - propagatedBuildInputs = [ - async - expect_test_helpers_kernel - ]; - }; - -} diff --git a/pkgs/development/ocaml-modules/janestreet/default.nix b/pkgs/development/ocaml-modules/janestreet/default.nix deleted file mode 100644 index a496c2c73cf9..000000000000 --- a/pkgs/development/ocaml-modules/janestreet/default.nix +++ /dev/null @@ -1,27 +0,0 @@ -{ }: - -# Minimal set of names assumed to be defined by the rest of ocamlPackages -{ - async = null; - async_kernel = null; - async_unix = null; - base = null; - core = null; - core_bench = null; - core_kernel = null; - ocaml-compiler-libs = null; - ppx_custom_printf = null; - ppx_expect = null; - ppx_hash = null; - ppx_here = null; - ppx_inline_test = null; - ppx_jane = null; - ppx_js_style = null; - ppx_let = null; - ppx_optcomp = null; - ppx_sexp_conv = null; - sexplib0 = null; - sexplib = null; - spawn = null; - stdio = null; -} diff --git a/pkgs/development/ocaml-modules/jsonoo/default.nix b/pkgs/development/ocaml-modules/jsonoo/default.nix new file mode 100644 index 000000000000..2f3e66226b74 --- /dev/null +++ b/pkgs/development/ocaml-modules/jsonoo/default.nix @@ -0,0 +1,40 @@ +{ + lib, + buildDunePackage, + fetchFromGitHub, + ojs, + gen_js_api, +}: + +buildDunePackage (finalAttrs: { + pname = "jsonoo"; + version = "0.3.0"; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "mlantas"; + repo = "jsonoo"; + tag = "v${finalAttrs.version}"; + hash = "sha256-BElpGAAIiC6Y7TY7yTW60Er5YJVwbn179+vdOZB4jNY="; + }; + + nativeBuildInputs = [ + gen_js_api + ]; + + propagatedBuildInputs = [ + ojs + gen_js_api + ]; + + # Depends on unpackaged webtest + doCheck = false; + + meta = { + description = "JSON library for Js_of_ocaml"; + homepage = "https://github.com/mlantas/jsonoo"; + license = lib.licenses.mit; + maintainers = [ lib.maintainers.sempiternal-aurora ]; + }; +}) diff --git a/pkgs/development/ocaml-modules/ocaml-solo5/default.nix b/pkgs/development/ocaml-modules/ocaml-solo5/default.nix new file mode 100644 index 000000000000..83913643d8f7 --- /dev/null +++ b/pkgs/development/ocaml-modules/ocaml-solo5/default.nix @@ -0,0 +1,154 @@ +{ + lib, + stdenv, + fetchFromGitHub, + buildDunePackage, + ocaml, + findlib, + fmt, + opam, + solo5, + target ? + if stdenv.targetPlatform.isx86_64 then + "x86_64-solo5-none-static" + else if stdenv.targetPlatform.isAarch64 then + "aarch64-solo5-none-static" + else + throw "ocaml-solo5 does not support ${stdenv.targetPlatform.system}", +}: + +assert lib.asserts.assertOneOf "ocaml-solo5's ocaml version" ocaml.version [ + "5.4.1" + "5.5.0" +]; + +stdenv.mkDerivation (finalAttrs: { + pname = "ocaml-solo5"; + version = "1.3.3"; + + src = fetchFromGitHub { + owner = "mirage"; + repo = "ocaml-solo5"; + tag = "v${finalAttrs.version}"; + hash = "sha256-/xUF98MPhjv9yRWoRDx2uIkCr2Furz1qUJexIxnHhI4="; + }; + + strictDeps = true; + __structuredAttrs = true; + + nativeBuildInputs = [ + findlib + ocaml + opam + solo5 + ]; + + propagatedBuildInputs = [ solo5 ]; + + setupHook = ./setup-hook.sh; + + # upstream uses `ocamlfind query ocaml-src` and patch with opatch + # override with `ocaml.src` and apply patches + postPatch = '' + mkdir ocaml + tar xf ${ocaml.src} -C ocaml --strip-components=1 + version=$(head -n1 ocaml/VERSION) + if test -d "patches/$version"; then + for p in "patches/$version"/*; do + patch -d ocaml -p1 < "$p" + done + fi + ''; + + # stdenv exports these environment variables + # ocaml configure script allow env vars to override target tool detection + # which would produce incorrect cross compiler setup + # see install check below + preConfigure = '' + unset CC CXX LD AR AS NM OBJCOPY OBJDUMP RANLIB READELF SIZE STRINGS STRIP + ''; + + configureScript = "./configure.sh"; + configureFlags = [ "--target=${target}" ]; + # only have --prefix, --sysroot, --target, --othertoolprefix, --ocaml-configure-option + # don't allow stdenv configurePhase append autotools flags + dontAddDisableDepTrack = true; + dontAddStaticConfigureFlags = true; + configurePlatforms = [ ]; + + dontStrip = true; + + enableParallelBuilding = true; + + doCheck = true; + checkTarget = "test"; + + doInstallCheck = true; + installCheckPhase = '' + runHook preInstallCheck + $out/lib/ocaml-solo5/bin/ocamlopt.opt -config | grep "^c_compiler: .*-solo5-ocaml-" + runHook postInstallCheck + ''; + + passthru = { + inherit target; + + tests = + let + example = + mode: attrs: + buildDunePackage ( + { + pname = "ocaml-solo5-example-${mode}"; + inherit (finalAttrs) version src; + sourceRoot = "${finalAttrs.src.name}/example"; + + __structuredAttrs = true; + + nativeBuildInputs = [ finalAttrs.finalPackage ]; + + buildInputs = [ fmt ]; + + env.MODE = mode; + + buildPhase = '' + runHook preBuild + dune build @default + runHook postBuild + ''; + + doCheck = true; + checkPhase = '' + runHook preCheck + dune build @runtest --display short + runHook postCheck + ''; + + installPhase = '' + runHook preInstall + install -D _build/solo5/hello.exe $out/hello.${mode} + runHook postInstall + ''; + } + // attrs + ); + in + { + example-spt = example "spt" { }; + example-hvt = example "hvt" { requiredSystemFeatures = [ "kvm" ]; }; + }; + }; + + meta = { + description = "OCaml cross-compiler to the freestanding Solo5 backend"; + homepage = "https://github.com/mirage/ocaml-solo5"; + changelog = "https://raw.githubusercontent.com/mirage/ocaml-solo5/v${finalAttrs.version}/CHANGES.md"; + license = lib.licenses.mit; + maintainers = [ lib.maintainers.stepbrobd ]; + teams = [ lib.teams.ngi ]; + platforms = [ + "aarch64-linux" + "x86_64-linux" + ]; + }; +}) diff --git a/pkgs/development/ocaml-modules/ocaml-solo5/setup-hook.sh b/pkgs/development/ocaml-modules/ocaml-solo5/setup-hook.sh new file mode 100644 index 000000000000..a4a15f866936 --- /dev/null +++ b/pkgs/development/ocaml-modules/ocaml-solo5/setup-hook.sh @@ -0,0 +1,25 @@ +# Expose solo5 findlib config for +# `ocamlfind -toolchain solo5` +# dune setup with solo5 toolchain +# etc. + +exportSolo5FindlibConf() { + command -v ocamlfind >/dev/null || return 0 + + local confdir baseconf + baseconf="${OCAMLFIND_CONF:-$(ocamlfind printconf conf 2>/dev/null)}" + [ -e "$baseconf" ] || return 0 + + confdir="$(mktemp -d)" + mkdir -p "$confdir/findlib.conf.d" + cat "$baseconf" > "$confdir/findlib.conf" + cp "${baseconf%/*}/findlib.conf.d/"*.conf "$confdir/findlib.conf.d/" 2>/dev/null || true + + sed -e "s|^path(solo5) = \"\(.*\)\"|path(solo5) = \"\1${OCAMLPATH:+:${OCAMLPATH%:}}\"|" \ + "@out@/lib/findlib.conf.d/solo5.conf" \ + > "$confdir/findlib.conf.d/solo5.conf" + + export OCAMLFIND_CONF="$confdir/findlib.conf" +} + +postHooks+=(exportSolo5FindlibConf) diff --git a/pkgs/development/ocaml-modules/ocamlformat-mlx/default.nix b/pkgs/development/ocaml-modules/ocamlformat-mlx/default.nix index 2ed0aa7a0acd..3eb1840b14a5 100644 --- a/pkgs/development/ocaml-modules/ocamlformat-mlx/default.nix +++ b/pkgs/development/ocaml-modules/ocamlformat-mlx/default.nix @@ -7,7 +7,6 @@ }: buildDunePackage { pname = "ocamlformat-mlx"; - minimalOcamlVersion = "4.08"; inherit (ocamlformat-mlx-lib) version src meta; diff --git a/pkgs/development/ocaml-modules/ocplib_stuff/default.nix b/pkgs/development/ocaml-modules/ocplib_stuff/default.nix new file mode 100644 index 000000000000..e1e359477a43 --- /dev/null +++ b/pkgs/development/ocaml-modules/ocplib_stuff/default.nix @@ -0,0 +1,35 @@ +{ + lib, + buildDunePackage, + fetchFromGitHub, + ppx_expect, + ppx_inline_test, +}: + +buildDunePackage (finalAttrs: { + pname = "ocplib_stuff"; + version = "0.4.0"; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "OCamlPro"; + repo = "ocplib_stuff"; + tag = "v${finalAttrs.version}"; + hash = "sha256-eTRdsJttkIthdgGbBEosjgrzES29kgQV2WaIAGCixTo="; + }; + + propagatedBuildInputs = [ + ppx_expect + ppx_inline_test + ]; + + doCheck = true; + + meta = { + description = "Some basic stuff that is used in some OCP libraries and applications"; + homepage = "https://github.com/OCamlPro/ocplib_stuff"; + license = lib.licenses.WITH lib.licenses.lgpl21Only lib.licenses.ocamlLgplLinkingException; + maintainers = [ lib.maintainers.sempiternal-aurora ]; + }; +}) diff --git a/pkgs/development/ocaml-modules/ppx_deriving_encoding/default.nix b/pkgs/development/ocaml-modules/ppx_deriving_encoding/default.nix new file mode 100644 index 000000000000..34ddf6fd08f3 --- /dev/null +++ b/pkgs/development/ocaml-modules/ppx_deriving_encoding/default.nix @@ -0,0 +1,35 @@ +{ + lib, + buildDunePackage, + fetchFromGitLab, + ppxlib, + json-data-encoding, +}: + +buildDunePackage (finalAttrs: { + pname = "ppx_deriving_encoding"; + version = "0.4.2"; + + minimalOCamlVersion = "4.13"; + __structuredAttrs = true; + + src = fetchFromGitLab { + domain = "gitlab.com"; + owner = "o-labs"; + repo = "ppx_deriving_encoding"; + tag = finalAttrs.version; + hash = "sha256-EJTc5nYvKXkYlfFyTKRm7z/H9EKWtHZFmhyjYCUAMUs="; + }; + + propagatedBuildInputs = [ + ppxlib + json-data-encoding + ]; + + meta = { + description = "Ppx deriver for json_encoding"; + homepage = "https://gitlab.com/o-labs/ppx_deriving_encoding"; + license = lib.licenses.WITH lib.licenses.lgpl21Only lib.licenses.ocamlLgplLinkingException; + maintainers = [ lib.maintainers.sempiternal-aurora ]; + }; +}) diff --git a/pkgs/development/ocaml-modules/ppx_protocol_conv/default.nix b/pkgs/development/ocaml-modules/ppx_protocol_conv/default.nix new file mode 100644 index 000000000000..3467abacb860 --- /dev/null +++ b/pkgs/development/ocaml-modules/ppx_protocol_conv/default.nix @@ -0,0 +1,41 @@ +{ + lib, + buildDunePackage, + fetchFromGitHub, + ppxlib, + ppx_expect, + ppx_sexp_conv, + sexplib, + alcotest, +}: + +buildDunePackage (finalAttrs: { + pname = "ppx_protocol_conv"; + version = "5.2.3"; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "andersfugmann"; + repo = "ppx_protocol_conv"; + tag = finalAttrs.version; + hash = "sha256-G6zMgHioPUCh2i50cjQ6talN8CYO6UhEaWgi0xe3CWA="; + }; + + propagatedBuildInputs = [ ppxlib ]; + + doCheck = true; + checkInputs = [ + ppx_expect + ppx_sexp_conv + sexplib + alcotest + ]; + + meta = { + description = "Pluggable serialization and deserialization of ocaml data strucures based on type_conv"; + homepage = "https://github.com/andersfugmann/ppx_protocol_conv"; + license = lib.licenses.bsd3; + maintainers = [ lib.maintainers.sempiternal-aurora ]; + }; +}) diff --git a/pkgs/development/ocaml-modules/superbol-studio-oss/default.nix b/pkgs/development/ocaml-modules/superbol-studio-oss/default.nix new file mode 100644 index 000000000000..f4bf444125be --- /dev/null +++ b/pkgs/development/ocaml-modules/superbol-studio-oss/default.nix @@ -0,0 +1,199 @@ +{ + lib, + stdenv, + buildDunePackage, + fetchFromGitHub, + gnucobol, + menhir, + js_of_ocaml, + gen_js_api, + jsonoo, + promise_jsoo, + ppx_deriving, + ppx_expect, + ppx_import, + ppx_deriving_encoding, + menhirSdk, + menhirLib, + fmt, + ocplib_stuff, + ez_file, + ez_api, + ez_cmdliner, + zarith, + zarith_stubs_js, + iso8601, + lwt, + ocamlgraph, + jsonrpc, + lsp, + toml, + camlp-streams, + ansiterminal, + alcotest, + autofonce, + goblint-cil, + gcc, + bison, + buildPackages, + versionCheckHook, +}: + +buildDunePackage (finalAttrs: { + pname = "superbol-studio-oss"; + version = "1.0.0"; + + minimalOCamlVersion = "4.14"; + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "OCamlPro"; + repo = "superbol-studio-oss"; + tag = finalAttrs.version; + hash = "sha256-/MO229R61r+Wix0rmSw/VEWmTOeq48/RvqaS3Xa1kmI="; + fetchSubmodules = true; + }; + + patches = [ + ./update-dependencies.patch + ]; + + nativeBuildInputs = [ + menhir + gen_js_api + gcc + ] + ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ + finalAttrs.passthru.gnucobol.bin + ]; + + propagatedBuildInputs = [ + js_of_ocaml + jsonoo + promise_jsoo + ppx_deriving + ppx_expect + ppx_import + ppx_deriving_encoding + menhirSdk + menhirLib + fmt + ocplib_stuff + ez_file + ez_api + ez_cmdliner + zarith + zarith_stubs_js + iso8601 + lwt + ocamlgraph + jsonrpc + lsp + toml + camlp-streams + goblint-cil + ]; + + dunePackages = [ + "superbol-studio-oss" + "superbol-vscode-lib" + "superbol-free" + "superbol_free_lib" + "superbol_project" + "node-js-stubs" + "interop-js-stubs" + "vscode-js-stubs" + "vscode-json" + "vscode-languageclient-js-stubs" + "superbol_preprocs" + "superbol_platform" + "sql_preproc" + "sql_ast" + "sql_parser" + "ez_toml" + "ezr_toml" + "cobol_typeck" + "cobol_parser" + "cobol_lsp" + "cobol_indent" + "cobol_common" + "cobol_config" + "cobol_cfg" + "cobol_preproc" + "cobol_data" + "cobol_ptree" + "cobol_unit" + "pretty" + "ppx_cobcflags" + "ebcdic_lib" + "h2mlstubs" + ] + ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ + # Requires a pre-release version of gnucobol that macos cannot build + "ezlibcob" + ]; + + preBuild = '' + dune build src/lsp/cobol_parser + ''; + + # It's broken currently + doCheck = false; + checkInputs = [ + ansiterminal + alcotest + autofonce + ]; + + doInstallCheck = true; + nativeInstallCheckInputs = [ versionCheckHook ]; + versionCheckProgram = "${placeholder "out"}/bin/superbol-free"; + + passthru.gnucobol = gnucobol.overrideAttrs (old: { + version = "3.2-unstable-2025-12-04"; + src = fetchFromGitHub { + owner = "OCamlPro"; + repo = "gnucobol"; + rev = "4b8c07b3dfd125f4379599cf45756c076f7699c7"; + hash = "sha256-QNWiDHILDCGh+rFbacSXi8cwPAwaHoG8nNb3KBlvCPc="; + }; + + nativeBuildInputs = old.nativeBuildInputs ++ [ + bison + buildPackages.flex + ]; + + postPatch = '' + # upstream reports the following tests as known failures + sed -i '/AT_SETUP(\[runtime check: write to internal storage (1)\])/a \ + AT_SKIP_IF(\[true\])' tests/testsuite.src/run_misc.at + sed -i '/AT_SETUP(\[OPEN OUTPUT COMMIT \/ ROLLBACK\])/a \ + AT_SKIP_IF(\[true\])' tests/testsuite.src/run_file.at + ''; + installFlags = [ "localedir=$out/share/locale" ]; + + dontVersionCheck = true; + + # Requires a full autoreconf run, but this doesn't work on macos + # Somehow causes segmentation faults when running the tests + meta = old.meta // { + broken = stdenv.hostPlatform.isDarwin; + }; + }); + + meta = { + description = "Open-Source part of SuperBOL Studio, including the Visual Studio Code extension and its LSP server"; + homepage = "https://superbol.eu/"; + license = + with lib.licenses; + AND [ + agpl3Only # For the src/lsp directory, the actual lsp `superbol-free` + mit # For vscode extension + isc # Some content in src/vendor + gpl3Only # for import/superbol-vscode-debug + ]; + maintainers = [ lib.maintainers.sempiternal-aurora ]; + teams = [ lib.teams.ngi ]; + mainProgram = "superbol-free"; + }; +}) diff --git a/pkgs/development/ocaml-modules/superbol-studio-oss/update-dependencies.patch b/pkgs/development/ocaml-modules/superbol-studio-oss/update-dependencies.patch new file mode 100644 index 000000000000..761d8f49e8f4 --- /dev/null +++ b/pkgs/development/ocaml-modules/superbol-studio-oss/update-dependencies.patch @@ -0,0 +1,442 @@ +--- a/src/autofonce/autofonce_config/ezToml.ml ++++ b/src/autofonce/autofonce_config/ezToml.ml +@@ -44,21 +44,21 @@ module EZ = struct + match Toml.Parser.from_filename filename with + | `Ok content -> content + | `Error (s, loc) -> +- Printf.kprintf failwith "Could not parse %S: %s at %s" filename s ++ Printf.ksprintf failwith "Could not parse %S: %s at %s" filename s + (string_of_location loc) + + let from_string_exn content = + match Toml.Parser.from_string content with + | `Ok content -> content + | `Error (s, loc) -> +- Printf.kprintf failwith "Could not parse toml content: %s at %s" s ++ Printf.ksprintf failwith "Could not parse toml content: %s at %s" s + (string_of_location loc) + end + + open TYPES + include EZ + +-let failwith fmt = Printf.kprintf failwith fmt ++let failwith fmt = Printf.ksprintf failwith fmt + + let key2str key = String.concat "." key + +--- a/src/autofonce/autofonce_lib/logging.ml ++++ b/src/autofonce/autofonce_lib/logging.ml +@@ -30,7 +30,7 @@ let indents = Array.init 10 (fun i -> String.make i ' ') + let log_header ?(indent=0) state fmt = + let b = state.state_buffer in + let indent = indents.( indent ) in +- Printf.kprintf (fun s -> ++ Printf.ksprintf (fun s -> + Printf.bprintf b "\n%s#######################################\n" indent; + Printf.bprintf b "%s#\n%s# %50s\n%s#\n" indent indent s indent; + Printf.bprintf b "%s#######################################\n\n" indent; +--- a/src/autofonce/autofonce_lib/runner_common.ml ++++ b/src/autofonce/autofonce_lib/runner_common.ml +@@ -82,7 +82,7 @@ let spaces = String.make 80 ' ' + + let test_status ter fmt = + let t = ter.tester_test in +- Printf.kprintf (fun s -> ++ Printf.ksprintf (fun s -> + let len = String.length s in + let status_len = if len > status_len then len else status_len in + let test_id = Printf.sprintf "%04d" t.test_id in +@@ -114,7 +114,7 @@ let commented s = + "# " ^ String.concat "\n# " (EzString.split s '\n') + + let output state fmt = +- Printf.kprintf (fun s -> ++ Printf.ksprintf (fun s -> + Terminal.move_bol (); + Terminal.erase Eol; + Terminal.printf [] "%s\n%!" s; +@@ -194,7 +194,7 @@ let exec_action_no_check ter action = + | AT_CHECK _ + | AF_COPY _ + -> +- Printf.kprintf failwith "exec_action: %s not implemented" ++ Printf.ksprintf failwith "exec_action: %s not implemented" + ( string_of_action action ) + + let check_of_AT_XFAIL_IF ter check_step check_loc check_command = +--- a/src/autofonce/autofonce_m4/m4Lexer.mll ++++ b/src/autofonce/autofonce_m4/m4Lexer.mll +@@ -123,7 +123,7 @@ rule shell = parse + count_newlines lexbuf ; + arg lexbuf } + | _ +- { Printf.kprintf failwith "Unexpected char %S" (Lexing.lexeme lexbuf) } ++ { Printf.ksprintf failwith "Unexpected char %S" (Lexing.lexeme lexbuf) } + + and end_of_line = parse + | [ ^ '\n' '#' ]* as line { line } +--- a/src/autofonce/autofonce_m4/m4Parser.ml ++++ b/src/autofonce/autofonce_m4/m4Parser.ml +@@ -14,14 +14,14 @@ open Ez_file.V1 + open M4Types + + let macro_error macro fmt = +- Printf.kprintf (fun s -> ++ Printf.ksprintf (fun s -> + Autofonce_misc.Misc.error "Error %s at %s, in macro %s" s + (M4Printer.string_of_location macro.loc) + (M4Printer.string_of_macro macro) + ) fmt + + let error loc fmt = +- Printf.kprintf (fun s -> raise ( Error (s, loc))) fmt ++ Printf.ksprintf (fun s -> raise ( Error (s, loc))) fmt + + let unescape ?last s = + M4Lexer.unescape ?last ( Lexing.from_string s ) +--- a/src/autofonce/autofonce_misc/misc.ml ++++ b/src/autofonce/autofonce_misc/misc.ml +@@ -16,22 +16,22 @@ open EzFile.OP + exception Error of string + + let _TODO_ loc s = +- Printf.kprintf failwith "Feature not implemented %s at %s" s loc ++ Printf.ksprintf failwith "Feature not implemented %s at %s" s loc + + let set_signal_handle signal handle = + ignore (Sys.set_signal signal (Sys.Signal_handle (fun _ -> handle ()))) + + let error fmt = +- Printf.kprintf (fun s -> raise (Error s)) fmt ++ Printf.ksprintf (fun s -> raise (Error s)) fmt + + let command fmt = +- Printf.kprintf (fun cmd -> ++ Printf.ksprintf (fun cmd -> + let retcode = Sys.command cmd in + assert ( retcode = 0 ) + ) fmt + + let command_ fmt = +- Printf.kprintf (fun cmd -> ++ Printf.ksprintf (fun cmd -> + ignore ( Sys.command cmd ) + ) fmt + +--- a/src/autofonce/ez_call/v1.ml ++++ b/src/autofonce/ez_call/v1.ml +@@ -24,14 +24,14 @@ module EzCall = struct + let verbose _ = !debug + end + module ERROR = struct +- let raise fmt = Printf.kprintf failwith fmt ++ let raise fmt = Printf.ksprintf failwith fmt + end + + + (* [BEGIN] The following part is similar to ocamlup:call.ml *) + + let command ?on_error fmt = +- Printf.kprintf (fun cmd -> ++ Printf.ksprintf (fun cmd -> + Printf.eprintf "%s\n%!" cmd; + let retcode = Sys.command cmd in + if retcode <> 0 then begin +--- a/src/lsp/cobol_indent/editor.ml ++++ b/src/lsp/cobol_indent/editor.ml +@@ -71,7 +71,7 @@ let apply_edits ~contents ~range ~config ~filename ~edits ~symbolic = + if nbefore > 0 then + let c = contents.[pos] in + if c = '\n' || c = '\r' then +- Printf.kprintf failwith ++ Printf.ksprintf failwith + "Cobol_indent.Editor.skip_before: char \\%3d at pos %d, line %d, skipping %d" (int_of_char c) pos line nbefore ; + + if c = '\t' then +--- a/src/lsp/cobol_indent/engine.ml ++++ b/src/lsp/cobol_indent/engine.ml +@@ -205,7 +205,7 @@ let indent_tokens ~config tokens = + | _ + -> () + (* +- Printf.kprintf failwith "No END-%s token" ++ Printf.ksprintf failwith "No END-%s token" + ( Misc.string_of_token token ) + *) + in +--- a/src/lsp/cobol_indent/misc.ml ++++ b/src/lsp/cobol_indent/misc.ml +@@ -61,7 +61,7 @@ let () = + + let log : ( 'a, unit, string, unit) format4 -> 'a = + let f fmt = +- Printf.kprintf (fun s -> ++ Printf.ksprintf (fun s -> + match !oc with + | None -> () + | Some oc -> +--- a/src/lsp/cobol_lsp/lsp_diagnostics.ml ++++ b/src/lsp/cobol_lsp/lsp_diagnostics.ml +@@ -43,7 +43,7 @@ let translate_one ?focus_on_main_doc ~rootdir ~uri (diag: DIAG.t) = + | DIAG.Unused -> Lsp.Types.DiagnosticTag.Unnecessary + | Deprecated -> Deprecated + ) (DIAG.tags diag) with [] -> None | tags -> Some tags) +- ~message:Pretty.(to_string "%a" DIAG.pp_msg diag) ++ ~message:(`String Pretty.(to_string "%a" DIAG.pp_msg diag)) + in + URIMap.singleton uri [diag] + +--- a/src/lsp/cobol_lsp/lsp_server.ml ++++ b/src/lsp/cobol_lsp/lsp_server.ml +@@ -242,7 +242,7 @@ let start_watching_config_of ~project registry ~pattern_kind = + | `any -> + `RelativePattern (RelativePattern.create + ~pattern:"**/superbol.toml" +- ~baseUri:(`URI rooturi)) ++ ~baseUri:()) + | `absolute -> (* assume root path is ok as a pattern *) + `Pattern (DocumentUri.to_path rooturi ^ "/superbol.toml") + in +@@ -445,7 +445,7 @@ let request_n_use_client_config_for ~project + await_response registry + ~request:(WorkspaceConfiguration + { items = [ ConfigurationItem.create () +- ~scopeUri:(Lsp.Uri.to_string uri) ++ ~scopeUri:uri + ~section:"superbol.cobol" ] }) + ~f:(use_client_config_for ~project) + end +--- a/src/lsp/ebcdic_lib/ebcdic.ml ++++ b/src/lsp/ebcdic_lib/ebcdic.ml +@@ -680,7 +680,7 @@ let read_gnucobol_collation_file filename = + if len > 0 && line.[0] <> '#' then + let items = String.split_on_char ' ' line in + if List.length items <> 16 then +- Printf.kprintf failwith "Wrong number of items on line %S" line; ++ Printf.ksprintf failwith "Wrong number of items on line %S" line; + let items = List.map (fun hh -> + int_of_string ( "0x" ^ hh ) + ) items in +--- a/src/lsp/grammarware/recover/gen_recover.ml ++++ b/src/lsp/grammarware/recover/gen_recover.ml +@@ -52,12 +52,11 @@ let () = + (st' :> int) + ) (Lr1.transitions st); + fprintf ppf "Reductions:\n"; +- List.iter (fun (t,ps) -> +- let p : production = List.hd ps in ++ List.iter (fun (t,p) -> + fprintf ppf " - on %a, reduce %d:\n %a\n" + Print.terminal t +- (p :> int) Print.production p +- ) (Lr1.reductions st); ++ (Production.to_int p) Print.production p ++ ) (Lr1.get_reductions st); + ); + Production.iter (fun (p : production) -> + fprintf ppf "\n# Production p%d\n%a" +--- a/src/lsp/grammarware/recover/synthesis.ml ++++ b/src/lsp/grammarware/recover/synthesis.ml +@@ -129,13 +129,11 @@ struct + ) [] (Lr1.transitions st) + in + let cost = List.fold_left +- (fun acc (_, prods) -> +- List.fold_left (fun acc prod -> +- if Production.rhs prod = [||] && Production.lhs prod = n then +- min_float (cost_of_prod prod) acc +- else acc +- ) acc prods +- ) infinity (Lr1.reductions st) ++ (fun acc (_, prod) -> ++ if Production.rhs prod = [||] && Production.lhs prod = n then ++ min_float (cost_of_prod prod) acc ++ else acc ++ ) infinity (Lr1.get_reductions st) + in + if cost < infinity || acc <> [] then + (fun v -> List.fold_left (fun cost f -> min_float cost (f v)) cost acc) +@@ -210,13 +208,11 @@ struct + ) acc (Lr1.transitions st) + in + let acc = List.fold_left +- (fun acc (_, prods) -> +- List.fold_left (fun acc prod -> +- if Production.rhs prod = [||] && Production.lhs prod = n then +- select (Reduce prod) acc +- else acc +- ) acc prods +- ) acc (Lr1.reductions st) ++ (fun acc (_, prod) -> ++ if Production.rhs prod = [||] && Production.lhs prod = n then ++ select (Reduce prod) acc ++ else acc ++ ) acc (Lr1.get_reductions st) + in + [acc] + +--- a/src/lsp/ppx_cobcflags/flag.ml ++++ b/src/lsp/ppx_cobcflags/flag.ml +@@ -57,6 +57,7 @@ let extension_flag = + (value_binding + ~pat:(ppat_var __') + ~expr:(pexp_tuple __) ++ ~constraint_:none + ^::nil) + ^:: nil)) + (expand_flag false) +@@ -70,6 +71,7 @@ let extension_flag_on = + (value_binding + ~pat:(ppat_var __') + ~expr:(pexp_tuple __) ++ ~constraint_:none + ^::nil) + ^:: nil)) + (expand_flag true) +--- a/src/lsp/ppx_cobcflags/flag_rq.ml ++++ b/src/lsp/ppx_cobcflags/flag_rq.ml +@@ -129,6 +129,7 @@ let extension_flag_rq = + (value_binding + ~pat:(ppat_constraint (ppat_var __') __') + ~expr:(pexp_tuple __) ++ ~constraint_:none + ^::nil) + ^:: nil)) + expand_flag_rq +--- a/src/lsp/pretty/pretty.ml ++++ b/src/lsp/pretty/pretty.ml +@@ -65,7 +65,7 @@ let pp_set_margin ppf margin = + + (** Sends right margin to virtual infinity *) + let blast_margin ppf = (* see https://github.com/ocaml/ocaml/issues/10592 *) +- pp_set_margin ppf max_int ++ pp_set_margin ppf 1000000000 + + (** Version of {!Format.asprintf} with virtually no right margin *) + let to_string: ('a, string) func = fun fmt -> +--- a/src/lsp/sql_preproc/misc.ml ++++ b/src/lsp/sql_preproc/misc.ml +@@ -19,7 +19,7 @@ let loc_of_edit ~filename e = + } + + let error ?loc fmt = +- Printf.kprintf ++ Printf.ksprintf + (fun s -> + Printf.eprintf "Error"; + begin +@@ -33,7 +33,7 @@ let error ?loc fmt = + fmt + + let warning ?loc fmt = +- Printf.kprintf ++ Printf.ksprintf + (fun s -> + Printf.eprintf "Warning"; + begin +--- a/src/lsp/superbol_free_lib/call.ml ++++ b/src/lsp/superbol_free_lib/call.ml +@@ -19,14 +19,14 @@ module GLOBALS = struct + let verbose _ = !debug + end + module ERROR = struct +- let raise fmt = Printf.kprintf failwith fmt ++ let raise fmt = Printf.ksprintf failwith fmt + end + + + (* [BEGIN] The following part is similar to ocamlup:call.ml *) + + let command ?on_error fmt = +- Printf.kprintf (fun cmd -> ++ Printf.ksprintf (fun cmd -> + Printf.eprintf "%s\n%!" cmd; + let retcode = Sys.command cmd in + if retcode <> 0 then begin +--- a/src/lsp/superbol_free_lib/command_texi2rst.ml ++++ b/src/lsp/superbol_free_lib/command_texi2rst.ml +@@ -48,7 +48,7 @@ module INPUT = struct + let close_in ic = close_in ic.ic + + let error ?ic fmt = +- Printf.kprintf (fun s -> ++ Printf.ksprintf (fun s -> + begin + match ic with + | Some ic -> +@@ -61,7 +61,7 @@ module INPUT = struct + ) fmt + + let warning ic fmt = +- Printf.kprintf (fun s -> ++ Printf.ksprintf (fun s -> + Printf.eprintf "Warning at %s:%d: %s\n%!" + ic.filename ic.line s; + ) fmt +--- a/src/lsp/superbol_free_lib/misc.ml ++++ b/src/lsp/superbol_free_lib/misc.ml +@@ -14,7 +14,7 @@ + open Ez_file.V1 + + let error fmt = +- Printf.kprintf (fun s -> ++ Printf.ksprintf (fun s -> + Printf.eprintf "Error: %s\n%!" s; + exit 2 + ) fmt +--- a/src/vendor/ez_toml/internal_printer.ml ++++ b/src/vendor/ez_toml/internal_printer.ml +@@ -58,7 +58,7 @@ let bprint_key_path b key_path = + else + if String.contains key '"' then + if String.contains key '\'' then +- Printf.kprintf failwith ++ Printf.ksprintf failwith + "Key %S cannot contain both simple and double quotes" key + else + Printf.bprintf b "'%s'" key +--- a/src/vscode/vscode-json/ezjsonm.ml ++++ b/src/vscode/vscode-json/ezjsonm.ml +@@ -165,7 +165,7 @@ let to_channel ?minify oc json = value_to_channel ?minify oc (json :> value) + exception Parse_error of value * string + + let parse_error t fmt = +- Printf.kprintf (fun msg -> ++ Printf.ksprintf (fun msg -> + raise (Parse_error (t, msg)) + ) fmt + +--- a/src/vscode/vscode-json/main.ml ++++ b/src/vscode/vscode-json/main.ml +@@ -70,7 +70,7 @@ type state = { + } + + let add_error ?(error=true) state fmt = +- Printf.kprintf (fun s -> ++ Printf.ksprintf (fun s -> + if error then + state.errors <- s :: state.errors + else +--- a/test/testsuite_utils/testsuite_utils.ml ++++ b/test/testsuite_utils/testsuite_utils.ml +@@ -26,7 +26,7 @@ let find_dir anchor = + else + let path' = Filename.dirname path in + if path = path' then +- Printf.kprintf failwith "Anchor %S not found from %s" anchor curdir; ++ Printf.ksprintf failwith "Anchor %S not found from %s" anchor curdir; + iter path' + in + iter curdir +--- a/vendors/ANSITerminal/src/ANSITerminal_win.ml ++++ b/vendors/ANSITerminal/src/ANSITerminal_win.ml +@@ -121,7 +121,7 @@ let print ch styles txt = + let print_string = print stdout + let prerr_string = print stderr + +-let printf style = kprintf (print_string style) ++let printf style = ksprintf (print_string style) + + let eprintf style = ksprintf (prerr_string style) + diff --git a/pkgs/development/python-modules/claude-agent-sdk/default.nix b/pkgs/development/python-modules/claude-agent-sdk/default.nix index 332f44ac8482..8fb8c3fdceb3 100644 --- a/pkgs/development/python-modules/claude-agent-sdk/default.nix +++ b/pkgs/development/python-modules/claude-agent-sdk/default.nix @@ -14,14 +14,14 @@ buildPythonPackage (finalAttrs: { pname = "claude-agent-sdk"; - version = "0.2.143"; + version = "0.2.144"; pyproject = true; src = fetchFromGitHub { owner = "anthropics"; repo = "claude-agent-sdk-python"; tag = "v${finalAttrs.version}"; - hash = "sha256-e3tRDJFm+wLx0rzz3VyOBgmLSu9Ng5JGFapx9UDpjQY="; + hash = "sha256-udXb9fCnOsi89HA2kLByintMcjyROa9Zk1cz59F/L9A="; }; build-system = [ hatchling ]; diff --git a/pkgs/development/python-modules/django-health-check/default.nix b/pkgs/development/python-modules/django-health-check/default.nix index 2cdb55ac1044..66cae7acffe8 100644 --- a/pkgs/development/python-modules/django-health-check/default.nix +++ b/pkgs/development/python-modules/django-health-check/default.nix @@ -22,14 +22,14 @@ buildPythonPackage (finalAttrs: { pname = "django-health-check"; - version = "4.5.0"; + version = "4.5.1"; pyproject = true; src = fetchFromGitHub { owner = "codingjoe"; repo = "django-health-check"; tag = finalAttrs.version; - hash = "sha256-YisYa2YAVhg9fganL7w1fnanXvtQJh6iccDDOxHG5WQ="; + hash = "sha256-PbimG445XclS7A4SBAZ+9W0WpoerhpqOI4A36Vyqscc="; }; build-system = [ diff --git a/pkgs/development/python-modules/mintotp/default.nix b/pkgs/development/python-modules/mintotp/default.nix new file mode 100644 index 000000000000..188baf5732e4 --- /dev/null +++ b/pkgs/development/python-modules/mintotp/default.nix @@ -0,0 +1,28 @@ +{ + lib, + buildPythonPackage, + fetchPypi, + setuptools, +}: + +buildPythonPackage (finalAttrs: { + pname = "mintotp"; + version = "0.3.0"; + pyproject = true; + + src = fetchPypi { + inherit (finalAttrs) pname version; + hash = "sha256-0PTbXts4p0gRIBdqUm6MKVObnoBYHdLcwYEVV9d8+tU="; + }; + + build-system = [ setuptools ]; + + pythonImportsCheck = [ "mintotp" ]; + + meta = { + description = "Minimal TOTP generator"; + homepage = "https://github.com/susam/mintotp"; + license = lib.licenses.mit; + maintainers = [ lib.maintainers.lucasew ]; + }; +}) diff --git a/pkgs/development/python-modules/resend/default.nix b/pkgs/development/python-modules/resend/default.nix index fa574b641b86..a0ba7296d30e 100644 --- a/pkgs/development/python-modules/resend/default.nix +++ b/pkgs/development/python-modules/resend/default.nix @@ -11,14 +11,14 @@ buildPythonPackage (finalAttrs: { pname = "resend"; - version = "2.36.0"; + version = "2.40.1"; pyproject = true; src = fetchFromGitHub { owner = "resend"; repo = "resend-python"; tag = "v${finalAttrs.version}"; - hash = "sha256-7ok/Bze68hJLrDL2kjdjCzWNt7mYpTfedBEe9KAFwXY="; + hash = "sha256-KWerfj1iay7Bik6igy9cRopdVnpQ8HB9qcKjG6NsavU="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/tencentcloud-sdk-python/default.nix b/pkgs/development/python-modules/tencentcloud-sdk-python/default.nix index 5f84eae84aee..663af3c3403f 100644 --- a/pkgs/development/python-modules/tencentcloud-sdk-python/default.nix +++ b/pkgs/development/python-modules/tencentcloud-sdk-python/default.nix @@ -9,14 +9,14 @@ buildPythonPackage (finalAttrs: { pname = "tencentcloud-sdk-python"; - version = "3.1.164"; + version = "3.1.165"; pyproject = true; src = fetchFromGitHub { owner = "TencentCloud"; repo = "tencentcloud-sdk-python"; tag = finalAttrs.version; - hash = "sha256-cjj5bQ6zhsVbUQ1rfN6ilxrrim6rUlsOVTuJ3CJ2rMo="; + hash = "sha256-yNhBFAMsw9nZxGgMOjKxnKbUHS67Vf+aAIEnj6FPUJs="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/trailbase/default.nix b/pkgs/development/python-modules/trailbase/default.nix new file mode 100644 index 000000000000..b0c1ef17a86e --- /dev/null +++ b/pkgs/development/python-modules/trailbase/default.nix @@ -0,0 +1,85 @@ +{ + lib, + buildPythonPackage, + fetchPypi, + poetry-core, + pythonOlder, + httpx, + pyjwt, + cryptography, + pytestCheckHook, + mintotp, + trailbase, + writableTmpDirAsHomeHook, + nix-update-script, +}: + +buildPythonPackage (finalAttrs: { + pname = "trailbase"; + version = "0.7.2"; + pyproject = true; + + disabled = pythonOlder "3.13"; + + src = fetchPypi { + inherit (finalAttrs) pname version; + hash = "sha256-iWdxMgjEPd5RkCRY3JnzuaJ1nW6LOESciTB6j2lzPzM="; + }; + + # Tests are not on PyPI. + prePatch = '' + cp -r ${trailbase.src}/client/python/tests tests + chmod -R u+w tests + ''; + + patches = [ ./use-packaged-server.patch ]; + + build-system = [ poetry-core ]; + + pythonRelaxDeps = [ + "httpx" + "cryptography" + ]; + + dependencies = [ + cryptography + httpx + pyjwt + ]; + + nativeCheckInputs = [ + mintotp + pytestCheckHook + trailbase + writableTmpDirAsHomeHook + ]; + + preCheck = '' + export TRAILBASE_BIN=${lib.getExe trailbase} + export TRAILBASE_TESTFIXTURE="$TMPDIR/testfixture" + cp -r ${trailbase.src}/client/testfixture "$TRAILBASE_TESTFIXTURE" + chmod -R u+w "$TRAILBASE_TESTFIXTURE" + + # promote_anonymous tries to send mail; the fixture has no SMTP. + mkdir -p "$TMPDIR/bin" + printf '%s\n' '#!/bin/sh' 'cat >/dev/null' > "$TMPDIR/bin/sendmail" + chmod +x "$TMPDIR/bin/sendmail" + export PATH="$TMPDIR/bin:$PATH" + ''; + + pythonImportsCheck = [ "trailbase" ]; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "TrailBase client for Python"; + homepage = "https://pypi.org/project/trailbase/"; + changelog = "https://github.com/trailbaseio/trailbase/releases"; + license = with lib.licenses; [ + asl20 + osl3 + ]; + maintainers = [ lib.maintainers.lucasew ]; + teams = [ lib.teams.ngi ]; + }; +}) diff --git a/pkgs/development/python-modules/trailbase/use-packaged-server.patch b/pkgs/development/python-modules/trailbase/use-packaged-server.patch new file mode 100644 index 000000000000..6fe12376fd8a --- /dev/null +++ b/pkgs/development/python-modules/trailbase/use-packaged-server.patch @@ -0,0 +1,24 @@ +--- a/tests/test_client.py ++++ b/tests/test_client.py +@@ -37,19 +37,12 @@ + process: None | subprocess.Popen[bytes] + + def __init__(self) -> None: +- cwd = os.getcwd() +- traildepot = "../testfixture" if cwd.endswith("python") else "client/testfixture" +- +- logger.info("Building TrailBase") +- build = subprocess.run(["cargo", "build"]) +- assert build.returncode == 0, f"{build.stderr}" ++ traildepot = os.environ["TRAILBASE_TESTFIXTURE"] + + logger.info("Starting TrailBase") + self.process = subprocess.Popen( + [ +- "cargo", +- "run", +- "--", ++ os.environ.get("TRAILBASE_BIN", "trail"), + "--data-dir", + traildepot, + "run", diff --git a/pkgs/development/python-modules/ttp-templates/default.nix b/pkgs/development/python-modules/ttp-templates/default.nix index 6ec517d32208..107ff75553a3 100644 --- a/pkgs/development/python-modules/ttp-templates/default.nix +++ b/pkgs/development/python-modules/ttp-templates/default.nix @@ -8,14 +8,14 @@ buildPythonPackage (finalAttrs: { pname = "ttp-templates"; - version = "0.5.9"; + version = "0.5.11"; pyproject = true; src = fetchFromGitHub { owner = "dmulyalin"; repo = "ttp_templates"; tag = finalAttrs.version; - hash = "sha256-AWEEwvrNap+XivFKi1XubXmPLQMaOifT/e+mk3wXoNc="; + hash = "sha256-0QFo/ZnOLX43oBj9KQoMmXL7SDHYN42K3dWuGTaUNqQ="; }; build-system = [ poetry-core ]; diff --git a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix index 456d1e4199e3..534e258f8554 100644 --- a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix +++ b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix @@ -15,14 +15,14 @@ let variants = { # ./update-xanmod.sh lts lts = { - version = "6.18.45"; - hash = "sha256-nY5SSwySTxBEMF3FfMsEaAyzQkBoWrRzVtTTr9l6bCQ="; + version = "6.18.46"; + hash = "sha256-MQm9lAw5U3s9p99XT8eDechXj4lhsv6Gmf79+QF3xYU="; isLTS = true; }; # ./update-xanmod.sh main main = { - version = "7.1.9"; - hash = "sha256-CtI5ExbqLKer2H3YdT6SbTSJfIfRfdIYUHnf96PXGgk="; + version = "7.1.10"; + hash = "sha256-W5ipVe/kCQtR2YNsbB7YDEMM1FQUxWrF3HcFzf7i7/I="; }; }; diff --git a/pkgs/servers/http/angie/default.nix b/pkgs/servers/http/angie/default.nix index e6445dc79297..54cfe4a72e4c 100644 --- a/pkgs/servers/http/angie/default.nix +++ b/pkgs/servers/http/angie/default.nix @@ -39,12 +39,13 @@ callPackage ../nginx/generic.nix args rec { meta = { description = "Angie is an efficient, powerful, and scalable web server that was forked from nginx"; - homepage = "https://angie.software/en/"; + homepage = "https://en.angie.software/"; + mainProgram = "angie"; license = lib.licenses.bsd2; platforms = lib.platforms.all; - maintainers = with lib.maintainers; [ izorkin ]; - knownVulnerabilities = [ - "angie is insufficiently maintained in nixpkgs. Security updates are frequently delayed. Please consider stepping up as maintainer or switching to an alternative." + maintainers = with lib.maintainers; [ + izorkin + suorcd ]; }; } diff --git a/pkgs/top-level/ocaml-packages.nix b/pkgs/top-level/ocaml-packages.nix index 572353bc1f09..f0de3b81d84d 100644 --- a/pkgs/top-level/ocaml-packages.nix +++ b/pkgs/top-level/ocaml-packages.nix @@ -94,6 +94,8 @@ let inherit (pkgs) augeas; }; + autofonce = callPackage ../development/ocaml-modules/autofonce { }; + awa = callPackage ../development/ocaml-modules/awa { }; awa-mirage = callPackage ../development/ocaml-modules/awa/mirage.nix { }; @@ -196,11 +198,7 @@ let camlp-streams = callPackage ../development/ocaml-modules/camlp-streams { }; - camlp4 = - if lib.versionOlder "4.02" ocaml.version then - callPackage ../development/tools/ocaml/camlp4 { } - else - null; + camlp4 = callPackage ../development/tools/ocaml/camlp4 { }; camlp5 = callPackage ../development/tools/ocaml/camlp5 { }; @@ -211,11 +209,7 @@ let camlzip = callPackage ../development/ocaml-modules/camlzip { }; - camomile = - if lib.versionOlder "4.02" ocaml.version then - callPackage ../development/ocaml-modules/camomile { } - else - callPackage ../development/ocaml-modules/camomile/0.8.5.nix { }; + camomile = callPackage ../development/ocaml-modules/camomile { }; capnp = callPackage ../development/ocaml-modules/capnp { }; @@ -506,6 +500,8 @@ let dream-pure = callPackage ../development/ocaml-modules/dream/pure.nix { }; + drom = callPackage ../development/ocaml-modules/drom { }; + dscheck = callPackage ../development/ocaml-modules/dscheck { }; dssi = callPackage ../development/ocaml-modules/dssi { }; @@ -618,6 +614,12 @@ let extunix = callPackage ../development/ocaml-modules/extunix/default.nix { }; + ez_api = callPackage ../development/ocaml-modules/ez_api { }; + ez_cmdliner = callPackage ../development/ocaml-modules/ez_cmdliner { }; + ez_file = callPackage ../development/ocaml-modules/ez_file { }; + ez_opam_file = callPackage ../development/ocaml-modules/ez_opam_file { }; + ez_subst = callPackage ../development/ocaml-modules/ez_subst { }; + ezgzip = callPackage ../development/ocaml-modules/ezgzip { }; ezjsonm = callPackage ../development/ocaml-modules/ezjsonm { }; @@ -786,13 +788,11 @@ let inherit (pkgs) gnuplot; }; + goblint-cil = callPackage ../development/ocaml-modules/goblint-cil { }; + grace = callPackage ../development/ocaml-modules/grace { }; - graphics = - if lib.versionOlder "4.09" ocaml.version then - callPackage ../development/ocaml-modules/graphics { } - else - null; + graphics = callPackage ../development/ocaml-modules/graphics { }; graphql = callPackage ../development/ocaml-modules/graphql { }; @@ -948,12 +948,8 @@ let callPackage ../development/ocaml-modules/janestreet/janePackage_0_16.nix { } else if lib.versionOlder "4.10.2" ocaml.version then callPackage ../development/ocaml-modules/janestreet/janePackage_0_15.nix { } - else if lib.versionOlder "4.08" ocaml.version then - callPackage ../development/ocaml-modules/janestreet/janePackage_0_14.nix { } - else if lib.versionOlder "4.07" ocaml.version then - callPackage ../development/ocaml-modules/janestreet/janePackage_0_12.nix { } else - null; + callPackage ../development/ocaml-modules/janestreet/janePackage_0_14.nix { }; janeStreet = lib.recurseIntoAttrs ( if lib.versionOlder "5.1" ocaml.version then @@ -993,7 +989,7 @@ let zstd ; } - else if lib.versionOlder "4.08" ocaml.version then + else import ../development/ocaml-modules/janestreet/0.14.nix { inherit self; inherit (pkgs) @@ -1003,16 +999,6 @@ let zstd ; } - else if lib.versionOlder "4.07" ocaml.version then - import ../development/ocaml-modules/janestreet/0.12.nix { - self = self // { - ppxlib = ppxlib.override { version = "0.8.1"; }; - }; - inherit (pkgs) openssl; - } - else - import ../development/ocaml-modules/janestreet { - } ); javalib = callPackage ../development/ocaml-modules/javalib { }; @@ -1045,6 +1031,8 @@ let jsonm = callPackage ../development/ocaml-modules/jsonm { }; + jsonoo = callPackage ../development/ocaml-modules/jsonoo { }; + jsont = callPackage ../development/ocaml-modules/jsont { }; jsonrpc = callPackage ../development/ocaml-modules/ocaml-lsp/jsonrpc.nix { }; @@ -1463,11 +1451,7 @@ let inherit (pkgs.python3Packages) numpy; }; - num = - if lib.versionOlder "4.06" ocaml.version then - callPackage ../development/ocaml-modules/num { } - else - null; + num = callPackage ../development/ocaml-modules/num { }; ### O ### @@ -1513,15 +1497,15 @@ let ocaml-sat-solvers = callPackage ../development/ocaml-modules/ocaml-sat-solvers { }; + ocaml-solo5 = callPackage ../development/ocaml-modules/ocaml-solo5 { + inherit (pkgs) opam solo5; + }; + ocaml-syntax-shims = callPackage ../development/ocaml-modules/ocaml-syntax-shims { }; ocaml-version = callPackage ../development/ocaml-modules/ocaml-version { }; - ocamlbuild = - if lib.versionOlder "4.03" ocaml.version then - callPackage ../development/tools/ocaml/ocamlbuild { } - else - null; + ocamlbuild = callPackage ../development/tools/ocaml/ocamlbuild { }; ocamlc-loc = callPackage ../development/ocaml-modules/ocamlc-loc { }; @@ -1595,6 +1579,8 @@ let ocplib-simplex_0_4 = callPackage ../development/ocaml-modules/ocplib-simplex/0_4.nix { }; + ocplib_stuff = callPackage ../development/ocaml-modules/ocplib_stuff { }; + ocsigen-ppx-rpc = callPackage ../development/ocaml-modules/ocsigen-ppx-rpc { }; ocsigen_server = callPackage ../development/ocaml-modules/ocsigen-server { }; @@ -1812,6 +1798,8 @@ let cmdliner = cmdliner_1; }; + ppx_deriving_encoding = callPackage ../development/ocaml-modules/ppx_deriving_encoding { }; + ppx_deriving_protobuf = callPackage ../development/ocaml-modules/ppx_deriving_protobuf { }; ppx_deriving_qcheck = callPackage ../development/ocaml-modules/qcheck/ppx_deriving_qcheck.nix { }; @@ -1840,15 +1828,13 @@ let ppx_monad = callPackage ../development/ocaml-modules/ppx_monad { }; + ppx_protocol_conv = callPackage ../development/ocaml-modules/ppx_protocol_conv { }; + ppx_repr = callPackage ../development/ocaml-modules/repr/ppx.nix { }; ppx_show = callPackage ../development/ocaml-modules/ppx_show { }; - ppx_tools = - if lib.versionAtLeast ocaml.version "4.02" then - callPackage ../development/ocaml-modules/ppx_tools { } - else - null; + ppx_tools = callPackage ../development/ocaml-modules/ppx_tools { }; ppx_tools_versioned = callPackage ../development/ocaml-modules/ppx_tools_versioned { }; @@ -2087,6 +2073,8 @@ let stringext = callPackage ../development/ocaml-modules/stringext { }; + superbol-studio-oss = callPackage ../development/ocaml-modules/superbol-studio-oss { }; + swhid_core = callPackage ../development/ocaml-modules/swhid_core { }; symex = callPackage ../development/ocaml-modules/symex { }; diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index e97f43ae9966..578bb447a2f6 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -10828,6 +10828,8 @@ self: super: with self; { miniupnpc = callPackage ../development/python-modules/miniupnpc { }; + mintotp = callPackage ../development/python-modules/mintotp { }; + mip = callPackage ../development/python-modules/mip { }; mir-eval = callPackage ../development/python-modules/mir-eval { }; @@ -20975,6 +20977,8 @@ self: super: with self; { trafilatura = callPackage ../development/python-modules/trafilatura { }; + trailbase = callPackage ../development/python-modules/trailbase { inherit (pkgs) trailbase; }; + trailrunner = callPackage ../development/python-modules/trailrunner { }; trainer = callPackage ../development/python-modules/trainer { }; diff --git a/pkgs/top-level/release-unfree-redistributable.nix b/pkgs/top-level/release-unfree-redistributable.nix index cf5c8a4d4987..8ec12c4c4d2e 100644 --- a/pkgs/top-level/release-unfree-redistributable.nix +++ b/pkgs/top-level/release-unfree-redistributable.nix @@ -34,7 +34,7 @@ config = { allowAliases = false; allowUnfree = true; - cudaSupport = true; + cudaSupport = false; inHydra = true; }; @@ -93,7 +93,7 @@ let attrPath: !(lib.hasPrefix "linuxKernel" attrPath || lib.hasPrefix "linuxPackages" attrPath); # This is handled by release-cuda.nix - isNotCudaPackage = attrPath: !(lib.hasPrefix "cuda" attrPath); + isNotCudaPackage = attrPath: !(lib.hasInfix "cuda" attrPath || lib.hasInfix "nvidia" attrPath); canSubstituteSrc = pkg: