From 75e5449f6413dc6e9e4ca07dbbfe08f4305ea2b3 Mon Sep 17 00:00:00 2001 From: Ryan Hendrickson Date: Thu, 18 May 2023 21:31:03 -0400 Subject: [PATCH 01/35] maptool: init at 1.13.0 (cherry picked from commit 45eb557afafd24a5d938e753ba1c6f8edee978a7) --- pkgs/games/maptool/default.nix | 119 ++++++++++++++++++++++++++++++++ pkgs/top-level/all-packages.nix | 8 +++ 2 files changed, 127 insertions(+) create mode 100644 pkgs/games/maptool/default.nix diff --git a/pkgs/games/maptool/default.nix b/pkgs/games/maptool/default.nix new file mode 100644 index 000000000000..53d8d89d6920 --- /dev/null +++ b/pkgs/games/maptool/default.nix @@ -0,0 +1,119 @@ +{ lib +, copyDesktopItems +, fetchurl +, ffmpeg +, gitUpdater +, jre +, libarchive +, makeDesktopItem +, openjfx +, stdenvNoCC +, wrapGAppsHook +}: +let + pname = "maptool"; + version = "1.13.0"; + repoBase = "https://github.com/RPTools/${pname}"; + src = fetchurl { + url = "${repoBase}/releases/download/${version}/MapTool-${version}.jar"; + hash = "sha256-0jiUYdr2KwMNc8VBgJsEsf4dkrzYfMGwv+jT1RLhUAg="; + }; + + icon = fetchurl { + url = "https://raw.githubusercontent.com/RPTools/${pname}/${version}/package/linux/MapTool.png"; + hash = "sha256-xkVYjMprTanHu8r4b9PHORI8E1aJp+9KDSP5mqCE8ew="; + }; + + meta = with lib; { + description = "Virtual Tabletop for playing roleplaying games with remote players or face to face"; + homepage = "https://www.rptools.net/toolbox/maptool/"; + sourceProvenance = with sourceTypes; [ + binaryBytecode + binaryNativeCode + ]; + license = licenses.agpl3; + maintainers = with maintainers; [ rhendric ]; + }; + + javafxModules = [ "base" "controls" "media" "swing" "web" "fxml" "graphics" ]; + + classpath = + lib.concatMap (mod: [ + "${openjfx}/modules_src/javafx.${mod}/module-info.java" + "${openjfx}/modules/javafx.${mod}" + "${openjfx}/modules_libs/javafx.${mod}" + ]) javafxModules ++ + [ src ]; + + jvmArgs = [ + "-cp" (lib.concatStringsSep ":" classpath) + "-Xss8M" + "-Dsun.java2d.d3d=false" + "-Dfile.encoding=UTF-8" + "-Dpolyglot.engine.WarnInterpreterOnly=false" + "-XX:+ShowCodeDetailsInExceptionMessages" + "--add-opens=java.desktop/java.awt=ALL-UNNAMED" + "--add-opens=java.desktop/java.awt.geom=ALL-UNNAMED" + "--add-opens=java.desktop/sun.awt.geom=ALL-UNNAMED" + "--add-opens=java.base/java.util=ALL-UNNAMED" + "--add-opens=javafx.web/javafx.scene.web=ALL-UNNAMED" + "--add-opens=javafx.web/com.sun.webkit=ALL-UNNAMED" + "--add-opens=javafx.web/com.sun.webkit.dom=ALL-UNNAMED" + "--add-opens=java.desktop/javax.swing=ALL-UNNAMED" + "--add-opens=java.desktop/sun.awt.shell=ALL-UNNAMED" + "--add-opens=java.desktop/com.sun.java.swing.plaf.windows=ALL-UNNAMED" + + # disable telemetry (the empty DSN disables the Sentry library, setting the + # environment to Development disables some logic inside MapTool) + "-Dsentry.dsn" + "-Dsentry.environment=Development" + ]; + + binName = pname; + rdnsName = "net.rptools.maptool"; +in +stdenvNoCC.mkDerivation { + inherit pname version src meta; + + dontUnpack = true; + dontBuild = true; + dontWrapGApps = true; + + nativeBuildInputs = [ + copyDesktopItems + libarchive + wrapGAppsHook + ]; + + desktopItems = [ + (makeDesktopItem { + name = rdnsName; + desktopName = "MapTool"; + icon = rdnsName; + exec = binName; + comment = meta.description; + categories = [ "Game" ]; + }) + ]; + + installPhase = '' + runHook preInstall + + mkdir -p $out/bin + makeWrapper ${jre}/bin/java $out/bin/${binName} \ + "''${gappsWrapperArgs[@]}" \ + --prefix LD_LIBRARY_PATH : ${lib.makeLibraryPath [ ffmpeg ]} \ + --add-flags '${lib.concatStringsSep " " jvmArgs} net.rptools.maptool.client.LaunchInstructions' + + dest=$out/share/icons/hicolor/256x256/apps + mkdir -p "$dest" + ln -s ${icon} "$dest/${rdnsName}.png" + + runHook postInstall + ''; + + passthru.updateScript = gitUpdater { + url = "${repoBase}.git"; + ignoredVersions = "-"; + }; +} diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 2178fd53afe1..8b0c380a81c2 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -36599,6 +36599,14 @@ with pkgs; gtk = gtk2; }; + maptool = callPackage ../games/maptool { + # MapTool is fussy about which JRE it uses; OpenJDK will leave it hanging + # at launch in a class initialization deadlock. MapTool ships Temurin with + # their pre-built releases so we might as well use it too. + jre = temurin-bin-17; + openjfx = openjfx17; + }; + mari0 = callPackage ../games/mari0 { }; manaplus = callPackage ../games/manaplus { stdenv = gcc11Stdenv; }; From ae78565412cec857d6f00f8bae7e336b4b3a9acc Mon Sep 17 00:00:00 2001 From: Sebastian Sellmeier Date: Sun, 16 Apr 2023 22:05:51 +0200 Subject: [PATCH 02/35] streamdeck-ui: add qt5.qtwayland on linux as dependency (cherry picked from commit 650468916e4c43ff3484339074d45641d9e30472) --- pkgs/applications/misc/streamdeck-ui/default.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/applications/misc/streamdeck-ui/default.nix b/pkgs/applications/misc/streamdeck-ui/default.nix index 21ac1939f4e9..1c1aa80de79c 100644 --- a/pkgs/applications/misc/streamdeck-ui/default.nix +++ b/pkgs/applications/misc/streamdeck-ui/default.nix @@ -7,6 +7,7 @@ , writeText , makeDesktopItem , xvfb-run +, qt5 }: python3Packages.buildPythonApplication rec { @@ -77,6 +78,8 @@ python3Packages.buildPythonApplication rec { pyside2 streamdeck xlib + ] ++ lib.optionals stdenv.isLinux [ + qt5.qtwayland ]; nativeCheckInputs = [ From 8ebdbefc23171bea98f5e7c289ce61164c85a896 Mon Sep 17 00:00:00 2001 From: pacien Date: Mon, 5 Jun 2023 20:04:48 +0200 Subject: [PATCH 03/35] nixos/exim: apply privilege restrictions Since 816614bd62b, the service is set to use the exim user so that systemd takes care of the credentials ownership. The executable is still required to run as root, to then drop privileges. The prefix '+' that was used however interfers with the use of privilege restrictions and other sandboxing options. Since we only want to escape the "User" setting, we can use the '!' prefix instead. (cherry picked from commit 54be076ae77da1f45fbc6c88419657f828e6237e) --- nixos/modules/services/mail/exim.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/nixos/modules/services/mail/exim.nix b/nixos/modules/services/mail/exim.nix index a9504acee351..1d1258913b67 100644 --- a/nixos/modules/services/mail/exim.nix +++ b/nixos/modules/services/mail/exim.nix @@ -116,8 +116,8 @@ in wantedBy = [ "multi-user.target" ]; restartTriggers = [ config.environment.etc."exim.conf".source ]; serviceConfig = { - ExecStart = "+${cfg.package}/bin/exim -bdf -q${cfg.queueRunnerInterval}"; - ExecReload = "+${coreutils}/bin/kill -HUP $MAINPID"; + ExecStart = "!${cfg.package}/bin/exim -bdf -q${cfg.queueRunnerInterval}"; + ExecReload = "!${coreutils}/bin/kill -HUP $MAINPID"; User = cfg.user; }; preStart = '' From 6f3fa4976f50a2a6083b2aab0ca8121a645efa1e Mon Sep 17 00:00:00 2001 From: Raito Bezarius Date: Sat, 27 May 2023 23:54:42 +0200 Subject: [PATCH 04/35] nixos/test-driver: add `timeout` option for `wait_for_console_text` Previously, `wait_for_console_text` would block indefinitely until there were lines shown in the buffer. This is highly annoying when testing for things that can just hang for some reasons. This introduces a classical timeout mechanism via non-blocking get on the Queue. (cherry picked from commit 406de94b416e7944ff981d6913ce578fd4aa3508) --- nixos/lib/test-driver/test_driver/machine.py | 21 ++++++++++++++++---- 1 file changed, 17 insertions(+), 4 deletions(-) diff --git a/nixos/lib/test-driver/test_driver/machine.py b/nixos/lib/test-driver/test_driver/machine.py index 1a97cedb2e81..3da7b8c96fdc 100644 --- a/nixos/lib/test-driver/test_driver/machine.py +++ b/nixos/lib/test-driver/test_driver/machine.py @@ -855,17 +855,30 @@ class Machine: with self.nested(f"waiting for {regex} to appear on screen"): retry(screen_matches) - def wait_for_console_text(self, regex: str) -> None: + def wait_for_console_text(self, regex: str, timeout: float | None = None) -> None: + """ + Wait for the provided regex to appear on console. + For each reads, + + If timeout is None, timeout is infinite. + + `timeout` is in seconds. + """ with self.nested(f"waiting for {regex} to appear on console"): # Buffer the console output, this is needed # to match multiline regexes. console = io.StringIO() + start = time.time() while True: try: - console.write(self.last_lines.get()) + # This will return as soon as possible and + # sleep 1 second. + console.write(self.last_lines.get(block=False)) except queue.Empty: - self.sleep(1) - continue + time.sleep(1) + if timeout is not None and time.time() - start >= timeout: + # If we reached here, we didn't honor our timeout constraint. + raise Exception(f"`wait_for_console_text` did not match `{regex}` after {timeout} seconds") console.seek(0) matches = re.search(regex, console.read()) if matches is not None: From 20955fa55ec6333ae0168a5bd6fa035fd5c06ec4 Mon Sep 17 00:00:00 2001 From: Raito Bezarius Date: Sun, 28 May 2023 00:07:43 +0200 Subject: [PATCH 05/35] nixos/test-driver: add `timeout` option for `wait_for_console_text` (variant 2) (cherry picked from commit d1104e2109a87447ec2faebd41f42638d6505ce0) --- nixos/lib/test-driver/test_driver/machine.py | 40 ++++++++++---------- 1 file changed, 21 insertions(+), 19 deletions(-) diff --git a/nixos/lib/test-driver/test_driver/machine.py b/nixos/lib/test-driver/test_driver/machine.py index 3da7b8c96fdc..3673271798a8 100644 --- a/nixos/lib/test-driver/test_driver/machine.py +++ b/nixos/lib/test-driver/test_driver/machine.py @@ -855,7 +855,7 @@ class Machine: with self.nested(f"waiting for {regex} to appear on screen"): retry(screen_matches) - def wait_for_console_text(self, regex: str, timeout: float | None = None) -> None: + def wait_for_console_text(self, regex: str, timeout: int | None = None) -> None: """ Wait for the provided regex to appear on console. For each reads, @@ -864,25 +864,27 @@ class Machine: `timeout` is in seconds. """ + # Buffer the console output, this is needed + # to match multiline regexes. + console = io.StringIO() + def console_matches() -> bool: + nonlocal console + try: + # This will return as soon as possible and + # sleep 1 second. + console.write(self.last_lines.get(block=False)) + except queue.Empty: + pass + console.seek(0) + matches = re.search(regex, console.read()) + return (matches is not None) + with self.nested(f"waiting for {regex} to appear on console"): - # Buffer the console output, this is needed - # to match multiline regexes. - console = io.StringIO() - start = time.time() - while True: - try: - # This will return as soon as possible and - # sleep 1 second. - console.write(self.last_lines.get(block=False)) - except queue.Empty: - time.sleep(1) - if timeout is not None and time.time() - start >= timeout: - # If we reached here, we didn't honor our timeout constraint. - raise Exception(f"`wait_for_console_text` did not match `{regex}` after {timeout} seconds") - console.seek(0) - matches = re.search(regex, console.read()) - if matches is not None: - return + if timeout is not None: + retry(console_matches, timeout) + else: + while not console_matches(): + pass def send_key( self, key: str, delay: Optional[float] = 0.01, log: Optional[bool] = True From 1616bfbde76a645a12c6ea4208af2f60e39abbfa Mon Sep 17 00:00:00 2001 From: Alyssa Ross Date: Sun, 28 May 2023 11:49:23 +0000 Subject: [PATCH 06/35] nixos/test-driver: fix formatting This caused the test driver to fail to build. Fixes: 406de94b416 ("nixos/test-driver: add `timeout` option for `wait_for_console_text`") --- nixos/lib/test-driver/test_driver/machine.py | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/nixos/lib/test-driver/test_driver/machine.py b/nixos/lib/test-driver/test_driver/machine.py index 3673271798a8..1d1d5bef9bf4 100644 --- a/nixos/lib/test-driver/test_driver/machine.py +++ b/nixos/lib/test-driver/test_driver/machine.py @@ -857,16 +857,17 @@ class Machine: def wait_for_console_text(self, regex: str, timeout: int | None = None) -> None: """ - Wait for the provided regex to appear on console. - For each reads, + Wait for the provided regex to appear on console. + For each reads, - If timeout is None, timeout is infinite. + If timeout is None, timeout is infinite. - `timeout` is in seconds. + `timeout` is in seconds. """ # Buffer the console output, this is needed # to match multiline regexes. console = io.StringIO() + def console_matches() -> bool: nonlocal console try: @@ -877,7 +878,7 @@ class Machine: pass console.seek(0) matches = re.search(regex, console.read()) - return (matches is not None) + return matches is not None with self.nested(f"waiting for {regex} to appear on console"): if timeout is not None: From e0371e6a233081274b410d96906527a0693a4ecb Mon Sep 17 00:00:00 2001 From: Lily Foster Date: Thu, 15 Jun 2023 06:47:49 -0400 Subject: [PATCH 07/35] nixos/test-driver: fix `timeout` option for `wait_for_console_text` --- nixos/lib/test-driver/test_driver/machine.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/nixos/lib/test-driver/test_driver/machine.py b/nixos/lib/test-driver/test_driver/machine.py index 1d1d5bef9bf4..523c16523272 100644 --- a/nixos/lib/test-driver/test_driver/machine.py +++ b/nixos/lib/test-driver/test_driver/machine.py @@ -868,7 +868,7 @@ class Machine: # to match multiline regexes. console = io.StringIO() - def console_matches() -> bool: + def console_matches(_: Any) -> bool: nonlocal console try: # This will return as soon as possible and @@ -884,7 +884,7 @@ class Machine: if timeout is not None: retry(console_matches, timeout) else: - while not console_matches(): + while not console_matches(False): pass def send_key( From cd5bf7221c50592f13b33de2311c0022e50ac55d Mon Sep 17 00:00:00 2001 From: Lily Foster Date: Thu, 15 Jun 2023 06:48:05 -0400 Subject: [PATCH 08/35] nixos/tests/systemd-initrd-vconsole: fix test and improve reliability --- nixos/tests/systemd-initrd-vconsole.nix | 17 +++++++++++++---- 1 file changed, 13 insertions(+), 4 deletions(-) diff --git a/nixos/tests/systemd-initrd-vconsole.nix b/nixos/tests/systemd-initrd-vconsole.nix index b74df410c422..d4c2a57680c1 100644 --- a/nixos/tests/systemd-initrd-vconsole.nix +++ b/nixos/tests/systemd-initrd-vconsole.nix @@ -2,7 +2,7 @@ import ./make-test-python.nix ({ lib, pkgs, ... }: { name = "systemd-initrd-vconsole"; nodes.machine = { pkgs, ... }: { - boot.kernelParams = [ "rd.systemd.unit=rescue.target" ]; + boot.kernelParams = lib.mkAfter [ "rd.systemd.unit=rescue.target" "loglevel=3" "udev.log_level=3" "systemd.log_level=warning" ]; boot.initrd.systemd = { enable = true; @@ -20,14 +20,23 @@ import ./make-test-python.nix ({ lib, pkgs, ... }: { machine.start() machine.wait_for_console_text("Press Enter for maintenance") machine.send_console("\n") - machine.wait_for_console_text("Logging in with home") + + # Wait for shell to become ready + for _ in range(300): + machine.send_console("printf '%s to receive commands:\\n' Ready\n") + try: + machine.wait_for_console_text("Ready to receive commands:", timeout=1) + break + except Exception: + continue + else: + raise RuntimeError("Rescue shell never became ready") # Check keymap - machine.send_console("(printf '%s to receive text: \\n' Ready && read text && echo \"$text\") Date: Fri, 9 Jun 2023 19:19:04 +0000 Subject: [PATCH 09/35] vault: 1.13.2 -> 1.13.3 (cherry picked from commit d34bb4ea41bec3f93d42fcb2d262d985e90d7008) --- pkgs/tools/security/vault/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/tools/security/vault/default.nix b/pkgs/tools/security/vault/default.nix index 042d7fa44e50..8d50e8c029bc 100644 --- a/pkgs/tools/security/vault/default.nix +++ b/pkgs/tools/security/vault/default.nix @@ -6,16 +6,16 @@ buildGoModule rec { pname = "vault"; - version = "1.13.2"; + version = "1.13.3"; src = fetchFromGitHub { owner = "hashicorp"; repo = "vault"; rev = "v${version}"; - sha256 = "sha256-U4V2+O8//6mkuznSHkPWeeJNK6NtUTEhFk7zz3FEe58="; + sha256 = "sha256-/AqUsjZArL4KjAzSkb1sM/xhKCIlg+2uvkV0TVwI1Q4="; }; - vendorHash = "sha256-eyXmmhMAbLJiLwQQAR4+baU53n2WY5laUKEGoPjpBg4="; + vendorHash = "sha256-Wt5VahshNI/etzQQdcKgD/TBuD4NMi5eVPMHiJYfScY="; subPackages = [ "." ]; From 750279bc61b29a6fa20e23d0ec28517695cf5f27 Mon Sep 17 00:00:00 2001 From: Atemu Date: Sun, 25 Jun 2023 17:52:55 +0200 Subject: [PATCH 10/35] linux_xanmod_latest: 6.3.5 -> 6.3.9 (cherry picked from commit 3364233f46fd5b87b6a9bbf1fdb45d902a93c6ac) --- pkgs/os-specific/linux/kernel/xanmod-kernels.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix index 8eaab5a6f8b1..4e00bb73f1dd 100644 --- a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix +++ b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix @@ -9,8 +9,8 @@ let }; mainVariant = { - version = "6.3.5"; - hash = "sha256-2+8WDj1VdmIdC0DjmKyY/fMi5zoiXDAWy7EAmkImvXk="; + version = "6.3.9"; + hash = "sha256-t1fKPZ+giANPmhM4zGoGtYWJF6rDnbpJaoHILl3nyRI="; variant = "main"; }; From f50014ce53a589d19a3ff67d7e47c16f71ca582f Mon Sep 17 00:00:00 2001 From: Atemu Date: Sun, 25 Jun 2023 17:53:12 +0200 Subject: [PATCH 11/35] linux_xanmod: 6.1.31 -> 6.1.35 (cherry picked from commit 986c78a3819e020c139ca4e11bfd29ecd61a7318) --- pkgs/os-specific/linux/kernel/xanmod-kernels.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix index 4e00bb73f1dd..d5be2d43d2c0 100644 --- a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix +++ b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix @@ -3,8 +3,8 @@ let # These names are how they are designated in https://xanmod.org. ltsVariant = { - version = "6.1.31"; - hash = "sha256-quYsp6h7IV6gUT0e55FeBlS8rH9OGrqdbM1XSIYNRV4="; + version = "6.1.35"; + hash = "sha256-CfrM2CNaGUTfkVteudL8xnAuCdZJxD5pUEC1YW9LiuU="; variant = "lts"; }; From 3033bae0ffa6bcdaa75fa802743e344929082d79 Mon Sep 17 00:00:00 2001 From: 06kellyjac Date: Wed, 14 Jun 2023 09:30:13 +0100 Subject: [PATCH 12/35] semgrep{,-core}: 1.15.0 -> 1.27.0 Now fetching semgrep-core from the python wheel as r2c don't add binaries to the GH releases anymore. (cherry picked from commit f3dde5bf8cbdcacce4d5272d5ad8209cc3757412) --- pkgs/tools/security/semgrep/common.nix | 55 +++++++----------- pkgs/tools/security/semgrep/default.nix | 17 ++++-- pkgs/tools/security/semgrep/semgrep-core.nix | 39 +++++++++++-- pkgs/tools/security/semgrep/update.sh | 60 ++++++++++++-------- 4 files changed, 102 insertions(+), 69 deletions(-) diff --git a/pkgs/tools/security/semgrep/common.nix b/pkgs/tools/security/semgrep/common.nix index 48381e9eb0e6..0ad680b0ddee 100644 --- a/pkgs/tools/security/semgrep/common.nix +++ b/pkgs/tools/security/semgrep/common.nix @@ -1,54 +1,39 @@ -{ lib, fetchFromGitHub, fetchzip, stdenv }: +{ lib }: rec { - version = "1.15.0"; + version = "1.27.0"; - src = fetchFromGitHub { - owner = "returntocorp"; - repo = "semgrep"; - rev = "v${version}"; - sha256 = "sha256-x+AOt6nn2hN4MODFZCvlq0kZ3VLoS7rVcFGGCEssIu0="; - }; + srcHash = "sha256-F6n3LQY4a5sO6c8SMQF9YjjgOS+v2SH+UQPwhg2EX7Q="; # submodule dependencies # these are fetched so we: # 1. don't fetch the many submodules we don't need # 2. avoid fetchSubmodules since it's prone to impurities submodules = { - "cli/src/semgrep/lang" = fetchFromGitHub { - owner = "returntocorp"; - repo = "semgrep-langs"; - rev = "08656cdefc9e6818c64e168cf51ee1e76ea8829e"; - sha256 = "sha256-vYf33JhfvEDmt/VW0hBOmqailIERS0GdUgrPuCxWt9I="; - }; - "cli/src/semgrep/semgrep_interfaces" = fetchFromGitHub { + "cli/src/semgrep/semgrep_interfaces" = { owner = "returntocorp"; repo = "semgrep-interfaces"; - rev = "ba9241ca8f13dea72a4ca5c5eae99f45c071c8b4"; - sha256 = "sha256-2rcMmN42445AivcyYLPeE+HBYOyxJijQME1UUr9HISA="; + rev = "213f67abea73546ca6111e1bbf0ef96aa917c940"; + hash = "sha256-HeNHJkTje9j16+dwsfyMhoqQn/J18q/7XvQPRwgTw/Y="; }; }; # fetch pre-built semgrep-core since the ocaml build is complex and relies on # the opam package manager at some point - core = rec { - data = { - x86_64-linux = { - suffix = "-ubuntu-16.04.tgz"; - sha256 = "sha256-vLtV1WAnOD6HhgrWYIP0NfXHKfvXORksdNp5UTG1QWc="; - }; - x86_64-darwin = { - suffix = "-osx.zip"; - sha256 = "sha256-6+ENjOOIJ5TSjpnJ5pDudblrWj/FLUe66UGr6V9c0HQ="; - }; + # pulling it out of the python wheel as r2c no longer release a built binary + # on github releases + core = { + x86_64-linux = { + platform = "any"; + hash = "sha256-cRj81dXpAE6S0EXajsRikOIAPzlUf42FhiDCWjv+wZQ="; }; - src = let - inherit (stdenv.hostPlatform) system; - selectSystemData = data: data.${system} or (throw "Unsupported system: ${system}"); - inherit (selectSystemData data) suffix sha256; - in fetchzip { - url = "https://github.com/returntocorp/semgrep/releases/download/v${version}/semgrep-v${version}${suffix}"; - inherit sha256; + x86_64-darwin = { + platform = "macosx_10_14_x86_64"; + hash = "sha256-jqfGVZGF/DFgXkr7kQg6QyqEELSr8AKE3Ga8kTftnIY="; + }; + aarch64-darwin = { + platform = "macosx_11_0_arm64"; + hash = "sha256-e/uCSRMdbVD0lvc0hukbiUzheqRNIIh1LgMq6Ae7JYI="; }; }; @@ -66,7 +51,5 @@ rec { ''; license = licenses.lgpl21Plus; maintainers = with maintainers; [ jk ambroisie ]; - # limited by semgrep-core - platforms = [ "x86_64-linux" "x86_64-darwin" ]; }; } diff --git a/pkgs/tools/security/semgrep/default.nix b/pkgs/tools/security/semgrep/default.nix index 0e9c3ddc391c..23749643a443 100644 --- a/pkgs/tools/security/semgrep/default.nix +++ b/pkgs/tools/security/semgrep/default.nix @@ -1,6 +1,5 @@ { lib , fetchFromGitHub -, callPackage , semgrep-core , buildPythonApplication , pythonPackages @@ -11,12 +10,20 @@ }: let - common = callPackage ./common.nix { }; + common = import ./common.nix { inherit lib; }; in buildPythonApplication rec { pname = "semgrep"; - inherit (common) src version; + inherit (common) version; + src = fetchFromGitHub { + owner = "returntocorp"; + repo = "semgrep"; + rev = "v${version}"; + hash = common.srcHash; + }; + # prepare a subset of the submodules as we only need a handful + # and there are many many submodules total postPatch = (lib.concatStringsSep "\n" (lib.mapAttrsToList ( path: submodule: '' @@ -27,7 +34,7 @@ buildPythonApplication rec { ln -s ${submodule}/ ${path} '' ) - common.submodules)) + '' + passthru.submodulesSubset)) + '' cd cli ''; @@ -97,10 +104,12 @@ buildPythonApplication rec { passthru = { inherit common; + submodulesSubset = lib.mapAttrs (k: args: fetchFromGitHub args) common.submodules; updateScript = ./update.sh; }; meta = common.meta // { description = common.meta.description + " - cli"; + inherit (semgrep-core.meta) platforms; }; } diff --git a/pkgs/tools/security/semgrep/semgrep-core.nix b/pkgs/tools/security/semgrep/semgrep-core.nix index e5ce941298a4..c4846c6d91d5 100644 --- a/pkgs/tools/security/semgrep/semgrep-core.nix +++ b/pkgs/tools/security/semgrep/semgrep-core.nix @@ -1,21 +1,52 @@ -{ lib, stdenvNoCC, callPackage }: +{ lib, stdenvNoCC, fetchPypi, unzip }: let - common = callPackage ./common.nix { }; + common = import ./common.nix { inherit lib; }; in stdenvNoCC.mkDerivation rec { pname = "semgrep-core"; inherit (common) version; - inherit (common.core) src; + # fetch pre-built semgrep-core since the ocaml build is complex and relies on + # the opam package manager at some point + # pulling it out of the python wheel as r2c no longer release a built binary + # on github releases + src = + let + inherit (stdenvNoCC.hostPlatform) system; + data = common.core.${system} or (throw "Unsupported system: ${system}"); + in + fetchPypi rec { + pname = "semgrep"; + inherit version; + format = "wheel"; + dist = python; + python = "cp37.cp38.cp39.py37.py38.py39"; + inherit (data) platform hash; + }; + + nativeBuildInputs = [ unzip ]; + + # _tryUnzip from unzip's setup-hook doesn't recognise .whl + # "do not know how to unpack source archive" + # perform unpack by hand + unpackPhase = '' + runHook preUnpack + LANG=en_US.UTF-8 unzip -qq "$src" + runHook postUnpack + ''; + + dontConfigure = true; + dontBuild = true; installPhase = '' runHook preInstall - install -Dm 755 -t $out/bin semgrep-core + install -Dm 755 -t $out/bin semgrep-${version}.data/purelib/semgrep/bin/semgrep-core runHook postInstall ''; meta = common.meta // { description = common.meta.description + " - core binary"; sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ]; + platforms = lib.attrNames common.core; }; } diff --git a/pkgs/tools/security/semgrep/update.sh b/pkgs/tools/security/semgrep/update.sh index 25b18edd6e2f..090d607a6928 100755 --- a/pkgs/tools/security/semgrep/update.sh +++ b/pkgs/tools/security/semgrep/update.sh @@ -1,5 +1,5 @@ #!/usr/bin/env nix-shell -#!nix-shell -i bash -p curl gnused jq +#!nix-shell -i bash -p curl gnused jq nix-prefetch set -euxo pipefail @@ -33,7 +33,7 @@ NEW_VERSION=$( ) # trim v prefix NEW_VERSION="${NEW_VERSION:1}" -OLD_VERSION="$(instantiateClean semgrep.common.version)" +OLD_VERSION="$(instantiateClean semgrep.passthru.common.version)" if [[ "$OLD_VERSION" == "$NEW_VERSION" ]]; then echo "Already up to date" @@ -50,43 +50,54 @@ fetchgithub() { set -eo pipefail } -fetchzip() { - set +eo pipefail - nix-build -E "with import $NIXPKGS_ROOT {}; fetchzip {url = \"$1\"; sha256 = lib.fakeSha256; }" 2>&1 >/dev/null | grep "got:" | cut -d':' -f2 | sed 's| ||g' - set -eo pipefail +fetch_arch() { + VERSION=$1 + PLATFORM=$2 + nix-prefetch "{ fetchPypi }: +fetchPypi rec { + pname = \"semgrep\"; + version = \"$VERSION\"; + format = \"wheel\"; + dist = python; + python = \"cp37.cp38.cp39.py37.py38.py39\"; + platform = \"$PLATFORM\"; +} +" } replace "$OLD_VERSION" "$NEW_VERSION" "$COMMON_FILE" echo "Updating src" -OLD_HASH="$(instantiateClean semgrep.common.src.outputHash)" +OLD_HASH="$(instantiateClean semgrep.passthru.common.srcHash)" echo "Old hash $OLD_HASH" TMP_HASH="sha256-AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=" replace "$OLD_HASH" "$TMP_HASH" "$COMMON_FILE" -NEW_HASH="$(fetchgithub semgrep.common.src)" +NEW_HASH="$(fetchgithub semgrep.src)" echo "New hash $NEW_HASH" replace "$TMP_HASH" "$NEW_HASH" "$COMMON_FILE" echo "Updated src" -# loop through platforms for core -nix-instantiate -E "with import $NIXPKGS_ROOT {}; builtins.attrNames semgrep.common.core.data" --eval --strict --json \ -| jq '.[]' -r \ -| while read -r PLATFORM; do - echo "Updating core for $PLATFORM" - SUFFIX=$(instantiateClean semgrep.common.core.data."$PLATFORM".suffix) - OLD_HASH=$(instantiateClean semgrep.common.core.data."$PLATFORM".sha256) - echo "Old hash $OLD_HASH" - NEW_URL="https://github.com/returntocorp/semgrep/releases/download/v$NEW_VERSION/semgrep-v$NEW_VERSION$SUFFIX" - NEW_HASH="$(fetchzip "$NEW_URL")" - echo "New hash $NEW_HASH" +update_core_platform() { + SYSTEM=$1 + echo "Updating core src $SYSTEM" + PLATFORM="$(instantiateClean "semgrep.passthru.common.core.$SYSTEM.platform")" + + OLD_HASH="$(instantiateClean "semgrep.passthru.common.core.$SYSTEM.hash")" + echo "Old core hash $OLD_HASH" + NEW_HASH="$(fetch_arch "$NEW_VERSION" "$PLATFORM")" + echo "New core hash $NEW_HASH" replace "$OLD_HASH" "$NEW_HASH" "$COMMON_FILE" - echo "Updated core for $PLATFORM" -done + echo "Updated core src $SYSTEM" +} + +update_core_platform "x86_64-linux" +update_core_platform "x86_64-darwin" +update_core_platform "aarch64-darwin" OLD_PWD=$PWD TMPDIR="$(mktemp -d)" @@ -109,7 +120,7 @@ nix-instantiate -E "with import $NIXPKGS_ROOT {}; builtins.attrNames semgrep.pas echo "Updating $SUBMODULE" OLD_REV=$(instantiateClean semgrep.passthru.common.submodules."$SUBMODULE".rev) echo "Old commit $OLD_REV" - OLD_HASH=$(instantiateClean semgrep.passthru.common.submodules."$SUBMODULE".outputHash) + OLD_HASH=$(instantiateClean semgrep.passthru.common.submodules."$SUBMODULE".hash) echo "Old hash $OLD_HASH" NEW_REV=$(get_submodule_commit "$SUBMODULE") @@ -120,13 +131,12 @@ nix-instantiate -E "with import $NIXPKGS_ROOT {}; builtins.attrNames semgrep.pas continue fi - NEW_URL=$(instantiateClean semgrep.passthru.common.submodules."$SUBMODULE".url | sed "s@$OLD_REV@$NEW_REV@g") - NEW_HASH=$(nix --experimental-features nix-command hash to-sri "sha256:$(nix-prefetch-url "$NEW_URL")") + NEW_URL=$(instantiateClean semgrep.passthru.submodulesSubset."$SUBMODULE".url | sed "s@$OLD_REV@$NEW_REV@g") TMP_HASH="sha256-AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=" replace "$OLD_REV" "$NEW_REV" "$COMMON_FILE" replace "$OLD_HASH" "$TMP_HASH" "$COMMON_FILE" - NEW_HASH="$(fetchgithub semgrep.passthru.common.submodules."$SUBMODULE")" + NEW_HASH="$(fetchgithub semgrep.passthru.submodulesSubset."$SUBMODULE")" echo "New hash $NEW_HASH" replace "$TMP_HASH" "$NEW_HASH" "$COMMON_FILE" From 815e01ac09973e09c826a18444af688a6abc175a Mon Sep 17 00:00:00 2001 From: Josh Hoffer Date: Mon, 26 Jun 2023 15:21:06 -0600 Subject: [PATCH 13/35] electron-mail: 5.1.6 -> 5.1.8 (cherry picked from commit c203643b82fc99785be7eb3559838e003382eb7f) --- .../networking/mailreaders/electron-mail/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/mailreaders/electron-mail/default.nix b/pkgs/applications/networking/mailreaders/electron-mail/default.nix index 20f3597b1517..a7b51585e3a0 100644 --- a/pkgs/applications/networking/mailreaders/electron-mail/default.nix +++ b/pkgs/applications/networking/mailreaders/electron-mail/default.nix @@ -2,12 +2,12 @@ let pname = "electron-mail"; - version = "5.1.6"; + version = "5.1.8"; name = "ElectronMail-${version}"; src = fetchurl { url = "https://github.com/vladimiry/ElectronMail/releases/download/v${version}/electron-mail-${version}-linux-x86_64.AppImage"; - sha256 = "sha256-lsXVsx7U43czWFWxAgwTUYTnUXSL4KPFnXLzUklieAo="; + sha256 = "sha256-btqlxFrQUyb728i99IE65A9jwEFNvJ5b6zji0kwwATU="; }; appimageContents = appimageTools.extract { inherit name src; }; From b45d372486014f7d1f592b93342842b279930fa1 Mon Sep 17 00:00:00 2001 From: Alyssa Ross Date: Mon, 26 Jun 2023 08:07:55 +0000 Subject: [PATCH 14/35] eos-installer: set meta.mainProgram (cherry picked from commit d57a08965239e9b32cdea58213ce99d699be3f04) --- pkgs/applications/misc/eos-installer/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/applications/misc/eos-installer/default.nix b/pkgs/applications/misc/eos-installer/default.nix index 5200907ff0db..67e6b2bc97ad 100644 --- a/pkgs/applications/misc/eos-installer/default.nix +++ b/pkgs/applications/misc/eos-installer/default.nix @@ -47,6 +47,7 @@ stdenv.mkDerivation rec { description = "Installer UI which writes images to disk"; license = licenses.gpl2Plus; maintainers = with maintainers; [ qyliss ]; + mainProgram = "gnome-image-installer"; platforms = platforms.linux; }; } From 88f925367be76b42322892300774627c786d4b7a Mon Sep 17 00:00:00 2001 From: Ulrik Strid Date: Tue, 27 Jun 2023 08:43:10 +0200 Subject: [PATCH 15/35] ocamlPackages.duff: fix tarball hash (cherry picked from commit 022350093894c7d3eff4db1ee3673c34abbd1309) --- pkgs/development/ocaml-modules/duff/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/development/ocaml-modules/duff/default.nix b/pkgs/development/ocaml-modules/duff/default.nix index 99261a5b324e..21e916b55e23 100644 --- a/pkgs/development/ocaml-modules/duff/default.nix +++ b/pkgs/development/ocaml-modules/duff/default.nix @@ -17,7 +17,7 @@ buildDunePackage rec { src = fetchurl { url = "https://github.com/mirage/duff/releases/download/v${version}/duff-${version}.tbz"; - sha256 = "sha256-0eqpfPWNOHYjkcjXRnZUTUFF0/L9E+TNoOqKCETN5hI="; + sha256 = "sha256-+UU89Ko7aFDv6MxvE/BT6+XyER+vF3zqv7sD5dmtbt4="; }; propagatedBuildInputs = [ fmt ]; From 649f4381d4c8a488f17b2500b15d20209451feaa Mon Sep 17 00:00:00 2001 From: Astro Date: Mon, 26 Jun 2023 02:50:12 +0200 Subject: [PATCH 16/35] stratovirt: add micro_vm-allow-SYS_clock_gettime.patch (cherry picked from commit 96032531bf22e4ecbe82986cf3290c76d1e3d931) --- .../virtualization/stratovirt/default.nix | 1 + .../micro_vm-allow-SYS_clock_gettime.patch | 25 +++++++++++++++++++ 2 files changed, 26 insertions(+) create mode 100644 pkgs/applications/virtualization/stratovirt/micro_vm-allow-SYS_clock_gettime.patch diff --git a/pkgs/applications/virtualization/stratovirt/default.nix b/pkgs/applications/virtualization/stratovirt/default.nix index 2c27b2f3cf46..b9fbc191d9c1 100644 --- a/pkgs/applications/virtualization/stratovirt/default.nix +++ b/pkgs/applications/virtualization/stratovirt/default.nix @@ -13,6 +13,7 @@ rustPlatform.buildRustPackage rec { rev = "v${version}"; sha256 = "sha256-K99CmaBrJu30/12FxnsNsDKsTyX4f2uQSO7cwHsPuDw="; }; + patches = [ ./micro_vm-allow-SYS_clock_gettime.patch ]; cargoSha256 = "sha256-SFIOGGRzGkVWHIXkviVWuhDN29pa0uD3GqKh+G421xI="; diff --git a/pkgs/applications/virtualization/stratovirt/micro_vm-allow-SYS_clock_gettime.patch b/pkgs/applications/virtualization/stratovirt/micro_vm-allow-SYS_clock_gettime.patch new file mode 100644 index 000000000000..6aa0da30c44a --- /dev/null +++ b/pkgs/applications/virtualization/stratovirt/micro_vm-allow-SYS_clock_gettime.patch @@ -0,0 +1,25 @@ +From af3001b1b2697ae3165e2fdf47a560fd9ab19a68 Mon Sep 17 00:00:00 2001 +From: Astro +Date: Sun, 18 Jun 2023 23:10:23 +0200 +Subject: [PATCH] micro_vm: allow SYS_clock_gettime + +--- + machine/src/micro_vm/syscall.rs | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/machine/src/micro_vm/syscall.rs b/machine/src/micro_vm/syscall.rs +index 89ce5c29..2a6aa0cc 100644 +--- a/machine/src/micro_vm/syscall.rs ++++ b/machine/src/micro_vm/syscall.rs +@@ -128,6 +128,8 @@ pub fn syscall_whitelist() -> Vec { + #[cfg(all(target_env = "gnu", target_arch = "x86_64"))] + BpfRule::new(libc::SYS_readlink), + BpfRule::new(libc::SYS_getrandom), ++ #[cfg(target_env = "gnu")] ++ BpfRule::new(libc::SYS_clock_gettime), + madvise_rule(), + ] + } +-- +2.41.0 + From 93d6fab25c012a9121ae223b944c73c808edda0b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Na=C3=AFm=20Favier?= Date: Mon, 12 Jun 2023 13:02:00 +0200 Subject: [PATCH 17/35] lib/types: add pathInStore (cherry picked from commit 14d3e5685a702c6eb4777eb6ba682324bbf3a187) --- lib/types.nix | 9 +++++++++ nixos/doc/manual/development/option-types.section.md | 5 +++++ 2 files changed, 14 insertions(+) diff --git a/lib/types.nix b/lib/types.nix index 9360d42f5850..638421260bc9 100644 --- a/lib/types.nix +++ b/lib/types.nix @@ -461,6 +461,7 @@ rec { # - strings with context, e.g. "${pkgs.foo}" or (toString pkgs.foo) # - hardcoded store path literals (/nix/store/hash-foo) or strings without context # ("/nix/store/hash-foo"). These get a context added to them using builtins.storePath. + # If you don't need a *top-level* store path, consider using pathInStore instead. package = mkOptionType { name = "package"; descriptionClass = "noun"; @@ -491,6 +492,14 @@ rec { merge = mergeEqualOption; }; + pathInStore = mkOptionType { + name = "pathInStore"; + description = "path in the Nix store"; + descriptionClass = "noun"; + check = x: isStringLike x && builtins.match "${builtins.storeDir}/[^.].*" (toString x) != null; + merge = mergeEqualOption; + }; + listOf = elemType: mkOptionType rec { name = "listOf"; description = "list of ${optionDescriptionPhrase (class: class == "noun" || class == "composite") elemType}"; diff --git a/nixos/doc/manual/development/option-types.section.md b/nixos/doc/manual/development/option-types.section.md index 9e156ebff9d3..44bb3b4782e1 100644 --- a/nixos/doc/manual/development/option-types.section.md +++ b/nixos/doc/manual/development/option-types.section.md @@ -20,6 +20,11 @@ merging is handled. coerced to a string. Even if derivations can be considered as paths, the more specific `types.package` should be preferred. +`types.pathInStore` + +: A path that is contained in the Nix store. This can be a top-level store + path like `pkgs.hello` or a descendant like `"${pkgs.hello}/bin/hello"`. + `types.package` : A top-level store path. This can be an attribute set pointing From 15b10135e664c8ccfd2d1a2b3af0c825af81da4e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Na=C3=AFm=20Favier?= Date: Mon, 12 Jun 2023 00:35:39 +0200 Subject: [PATCH 18/35] nixos/top-level: change extraDependencies from package to pathInStore Allows adding subdirectory flake inputs that aren't top-level store paths. (cherry picked from commit 0179d9f7e608b6e54fd1399689b335db360fc9e5) --- nixos/modules/system/activation/top-level.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/nixos/modules/system/activation/top-level.nix b/nixos/modules/system/activation/top-level.nix index c4427149d9c9..68eb0469d8ea 100644 --- a/nixos/modules/system/activation/top-level.nix +++ b/nixos/modules/system/activation/top-level.nix @@ -260,10 +260,10 @@ in }; system.extraDependencies = mkOption { - type = types.listOf types.package; + type = types.listOf types.pathInStore; default = []; description = lib.mdDoc '' - A list of packages that should be included in the system + A list of paths that should be included in the system closure but generally not visible to users. This option has also been used for build-time checks, but the From 49cb9d4e8ace014e1467bb295141474a18f40642 Mon Sep 17 00:00:00 2001 From: Robert Hensing Date: Mon, 26 Jun 2023 12:50:01 +0200 Subject: [PATCH 19/35] lib/tests/modules.sh: Test types.pathInStore Add missing test cases. I think the .links case should be rejected even though it's technically a path in the store. (cherry picked from commit 18111335ed4e9bd80243987b30d8c7705a95c8e1) --- lib/tests/modules.sh | 10 ++++++++++ lib/tests/modules/types.nix | 24 ++++++++++++++++++++++++ 2 files changed, 34 insertions(+) create mode 100644 lib/tests/modules/types.nix diff --git a/lib/tests/modules.sh b/lib/tests/modules.sh index a60228198fd7..c81febb4156f 100755 --- a/lib/tests/modules.sh +++ b/lib/tests/modules.sh @@ -63,6 +63,16 @@ checkConfigOutput '^"one two"$' config.result ./shorthand-meta.nix checkConfigOutput '^true$' config.result ./test-mergeAttrDefinitionsWithPrio.nix +# types.pathInStore +checkConfigOutput '".*/store/5lz9p8xhf89kb1c1kk6jxrzskaiygnlh-bash-5.2-p15.drv"' config.pathInStore.ok1 ./types.nix +checkConfigOutput '".*/store/xfb3ykw9r5hpayd05sr0cizwadzq1d8q-bash-5.2-p15"' config.pathInStore.ok2 ./types.nix +checkConfigOutput '".*/store/xfb3ykw9r5hpayd05sr0cizwadzq1d8q-bash-5.2-p15/bin/bash"' config.pathInStore.ok3 ./types.nix +checkConfigError 'A definition for option .* is not of type .path in the Nix store.. Definition values:\n\s*- In .*: ""' config.pathInStore.bad1 ./types.nix +checkConfigError 'A definition for option .* is not of type .path in the Nix store.. Definition values:\n\s*- In .*: ".*/store"' config.pathInStore.bad2 ./types.nix +checkConfigError 'A definition for option .* is not of type .path in the Nix store.. Definition values:\n\s*- In .*: ".*/store/"' config.pathInStore.bad3 ./types.nix +checkConfigError 'A definition for option .* is not of type .path in the Nix store.. Definition values:\n\s*- In .*: ".*/store/.links"' config.pathInStore.bad4 ./types.nix +checkConfigError 'A definition for option .* is not of type .path in the Nix store.. Definition values:\n\s*- In .*: "/foo/bar"' config.pathInStore.bad5 ./types.nix + # Check boolean option. checkConfigOutput '^false$' config.enable ./declare-enable.nix checkConfigError 'The option .* does not exist. Definition values:\n\s*- In .*: true' config.enable ./define-enable.nix diff --git a/lib/tests/modules/types.nix b/lib/tests/modules/types.nix new file mode 100644 index 000000000000..576db6b5b9ef --- /dev/null +++ b/lib/tests/modules/types.nix @@ -0,0 +1,24 @@ +{ lib, ... }: +let + inherit (builtins) + storeDir; + inherit (lib) + types + mkOption + ; +in +{ + options = { + pathInStore = mkOption { type = types.lazyAttrsOf types.pathInStore; }; + }; + config = { + pathInStore.ok1 = "${storeDir}/5lz9p8xhf89kb1c1kk6jxrzskaiygnlh-bash-5.2-p15.drv"; + pathInStore.ok2 = "${storeDir}/xfb3ykw9r5hpayd05sr0cizwadzq1d8q-bash-5.2-p15"; + pathInStore.ok3 = "${storeDir}/xfb3ykw9r5hpayd05sr0cizwadzq1d8q-bash-5.2-p15/bin/bash"; + pathInStore.bad1 = ""; + pathInStore.bad2 = "${storeDir}"; + pathInStore.bad3 = "${storeDir}/"; + pathInStore.bad4 = "${storeDir}/.links"; # technically true, but not reasonable + pathInStore.bad5 = "/foo/bar"; + }; +} From d0b1f7728b49cc37bdfdc7eef7bc0b6a686a7cf1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Na=C3=AFm=20Favier?= Date: Mon, 26 Jun 2023 13:20:01 +0200 Subject: [PATCH 20/35] lib/tests: remove experimental-features Now that the lib is tested with Nix 2.3, this isn't needed any more and causes warnings. (cherry picked from commit 4bdff8cbbb3ff52fc26cc74d1526617aac6ba22a) --- lib/tests/release.nix | 3 --- 1 file changed, 3 deletions(-) diff --git a/lib/tests/release.nix b/lib/tests/release.nix index c3bf58db241f..531986025083 100644 --- a/lib/tests/release.nix +++ b/lib/tests/release.nix @@ -38,9 +38,6 @@ let export PAGER=cat cacheDir=$TEST_ROOT/binary-cache - mkdir -p $NIX_CONF_DIR - echo "experimental-features = nix-command" >> $NIX_CONF_DIR/nix.conf - nix-store --init cp -r ${../.} lib From b32c53b9fd7cb54dd46e26abd52515e8760c1a6c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 25 Jun 2023 02:38:52 +0000 Subject: [PATCH 21/35] discord-development: 0.0.216 -> 0.0.217 (cherry picked from commit 9f5feba8955f3293e13934710d27fa330f0649ce) --- .../networking/instant-messengers/discord/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/instant-messengers/discord/default.nix b/pkgs/applications/networking/instant-messengers/discord/default.nix index 94fe22ea417d..ba77fa0f8be5 100644 --- a/pkgs/applications/networking/instant-messengers/discord/default.nix +++ b/pkgs/applications/networking/instant-messengers/discord/default.nix @@ -4,7 +4,7 @@ let stable = "0.0.27"; ptb = "0.0.42"; canary = "0.0.161"; - development = "0.0.216"; + development = "0.0.217"; } else { stable = "0.0.273"; ptb = "0.0.59"; @@ -28,7 +28,7 @@ let }; development = fetchurl { url = "https://dl-development.discordapp.net/apps/linux/${version}/discord-development-${version}.tar.gz"; - sha256 = "sha256-lQnIQC7Wek7OYDzZvLIJfb8I4oATD8pSB+mjQMPyqYQ="; + sha256 = "sha256-fzNFKrYo5qckrWZAkkiK337czCt6nOM1O8FeG18Q8Y0="; }; }; x86_64-darwin = { From 97a4a7b298510d75b663d7c7d4bb399d346fb2aa Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 27 Jun 2023 03:08:10 +0000 Subject: [PATCH 22/35] discord-ptb: 0.0.42 -> 0.0.43 (cherry picked from commit 0b9b910faa11d8258dbff62a9ef901a0bbd554d0) --- .../networking/instant-messengers/discord/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/instant-messengers/discord/default.nix b/pkgs/applications/networking/instant-messengers/discord/default.nix index ba77fa0f8be5..492482eca0d9 100644 --- a/pkgs/applications/networking/instant-messengers/discord/default.nix +++ b/pkgs/applications/networking/instant-messengers/discord/default.nix @@ -2,7 +2,7 @@ let versions = if stdenv.isLinux then { stable = "0.0.27"; - ptb = "0.0.42"; + ptb = "0.0.43"; canary = "0.0.161"; development = "0.0.217"; } else { @@ -20,7 +20,7 @@ let }; ptb = fetchurl { url = "https://dl-ptb.discordapp.net/apps/linux/${version}/discord-ptb-${version}.tar.gz"; - sha256 = "ZAMyAqyFEBJeTUqQzr5wK+BOFGURqhoHL8w2hJvL0vI="; + sha256 = "tG+QR62JcBYrvJS6KU6oAWSfQFdl68AMcU8E9Zahy2A="; }; canary = fetchurl { url = "https://dl-canary.discordapp.net/apps/linux/${version}/discord-canary-${version}.tar.gz"; From 4d5cf4c7c25f4d513a4e37ecf192be44570b6776 Mon Sep 17 00:00:00 2001 From: Yaya Date: Thu, 22 Jun 2023 05:53:22 +0000 Subject: [PATCH 23/35] gitlab: 16.0.5 -> 16.1.0 https://gitlab.com/gitlab-org/gitlab/-/blob/v16.1.0-ee/CHANGELOG.md (cherry picked from commit 9f01d4bca7803ec95018fc30baf38fa803434e1a) --- .../version-management/gitlab/data.json | 16 +- .../gitlab/gitaly/default.nix | 6 +- .../gitlab/gitlab-pages/default.nix | 6 +- .../gitlab/gitlab-shell/default.nix | 6 +- .../gitlab/gitlab-workhorse/default.nix | 4 +- .../gitlab/remove-hardcoded-locations.patch | 10 +- .../version-management/gitlab/rubyEnv/Gemfile | 56 ++-- .../gitlab/rubyEnv/Gemfile.lock | 173 ++++++------ .../gitlab/rubyEnv/gemset.nix | 250 +++++++++--------- 9 files changed, 276 insertions(+), 251 deletions(-) diff --git a/pkgs/applications/version-management/gitlab/data.json b/pkgs/applications/version-management/gitlab/data.json index 48a59f0c2cfe..488bf1218053 100644 --- a/pkgs/applications/version-management/gitlab/data.json +++ b/pkgs/applications/version-management/gitlab/data.json @@ -1,14 +1,14 @@ { - "version": "16.0.5", - "repo_hash": "sha256-hUEPJMdmR+p7nHWjdS+9SXcgm0LciPC9at+GP9UcUvI=", - "yarn_hash": "0yy04jnfvn5dgciqd105xiwg7chjwp3w6iqbjpylak9h82ci6wlh", + "version": "16.1.0", + "repo_hash": "sha256-sRel6okv2NYV4As3+AudqVvJ1/eLQGJGFvs+BA14wis=", + "yarn_hash": "1cqyf06810ls94nkys0l4p86ni902q32aqjp66m7j1x6ldh248al", "owner": "gitlab-org", "repo": "gitlab", - "rev": "v16.0.5-ee", + "rev": "v16.1.0-ee", "passthru": { - "GITALY_SERVER_VERSION": "16.0.5", - "GITLAB_PAGES_VERSION": "16.0.5", - "GITLAB_SHELL_VERSION": "14.20.0", - "GITLAB_WORKHORSE_VERSION": "16.0.5" + "GITALY_SERVER_VERSION": "16.1.0", + "GITLAB_PAGES_VERSION": "16.1.0", + "GITLAB_SHELL_VERSION": "14.23.0", + "GITLAB_WORKHORSE_VERSION": "16.1.0" } } diff --git a/pkgs/applications/version-management/gitlab/gitaly/default.nix b/pkgs/applications/version-management/gitlab/gitaly/default.nix index 2d44ed033000..38e8a72526f9 100644 --- a/pkgs/applications/version-management/gitlab/gitaly/default.nix +++ b/pkgs/applications/version-management/gitlab/gitaly/default.nix @@ -13,7 +13,7 @@ }: let - version = "16.0.5"; + version = "16.1.0"; package_version = "v${lib.versions.major version}"; gitaly_package = "gitlab.com/gitlab-org/gitaly/${package_version}"; @@ -24,10 +24,10 @@ let owner = "gitlab-org"; repo = "gitaly"; rev = "v${version}"; - sha256 = "sha256-YhqKMFDjjL2I82m51GdKNVO8vdJPppDKZDBQGskpyA4="; + sha256 = "sha256-+Fnj9fgQQtyGMWOL5NkNON/N9p6POjAtpF2O06iKh90="; }; - vendorSha256 = "sha256-KBhTI70eReZGSd7RxwGXcUGa0wDo7q5tU9fUhrLeFO0="; + vendorSha256 = "sha256-6oOFQGPwiMRQrESXsQsGzvWz9bCb0VTYIyyG/C2b3nA="; ldflags = [ "-X ${gitaly_package}/internal/version.version=${version}" "-X ${gitaly_package}/internal/version.moduleVersion=${version}" ]; diff --git a/pkgs/applications/version-management/gitlab/gitlab-pages/default.nix b/pkgs/applications/version-management/gitlab/gitlab-pages/default.nix index 64d8650a0b16..8d96d160f756 100644 --- a/pkgs/applications/version-management/gitlab/gitlab-pages/default.nix +++ b/pkgs/applications/version-management/gitlab/gitlab-pages/default.nix @@ -2,16 +2,16 @@ buildGoModule rec { pname = "gitlab-pages"; - version = "16.0.5"; + version = "16.1.0"; src = fetchFromGitLab { owner = "gitlab-org"; repo = "gitlab-pages"; rev = "v${version}"; - sha256 = "sha256-bZwq8nG3QmPCgfuBUQW6LQdi7F1+n2JfzfU3oP+QCJw="; + sha256 = "sha256-vAprB+pDwpr2Wq4aM0wnHlNzUvc1ajasdORwT0LDTTY="; }; - vendorHash = "sha256-s3HHoz9URACuVVhePQQFviTqlQU7vCLOjTJPBlus1Vo="; + vendorHash = "sha256-SN4r9hcTTQUr3miv2Cm7iBryyh7yG1xx9lCvq3vQwc0="; subPackages = [ "." ]; meta = with lib; { diff --git a/pkgs/applications/version-management/gitlab/gitlab-shell/default.nix b/pkgs/applications/version-management/gitlab/gitlab-shell/default.nix index 5dcb6e88a15c..2d8e52ee66b1 100644 --- a/pkgs/applications/version-management/gitlab/gitlab-shell/default.nix +++ b/pkgs/applications/version-management/gitlab/gitlab-shell/default.nix @@ -2,19 +2,19 @@ buildGoModule rec { pname = "gitlab-shell"; - version = "14.20.0"; + version = "14.23.0"; src = fetchFromGitLab { owner = "gitlab-org"; repo = "gitlab-shell"; rev = "v${version}"; - sha256 = "sha256-5rjrBt0AihSHMYOD6JbXGvvFaUbtYnMHX2Z4K+Svno0="; + sha256 = "sha256-nQJq9aPC5YtTbyiwtzKwDG95PnBr6XdNpSIJkfgvnzU="; }; buildInputs = [ ruby libkrb5 ]; patches = [ ./remove-hardcoded-locations.patch ]; - vendorSha256 = "sha256-kKbTbOCuAGIbnFXTOZyoVRM5PIackbmND6PrryVvLTM="; + vendorSha256 = "sha256-JEWgOuWvtuaipF8fFTsFbB+sYfaHEYUl9Z8Q1XAuJuE="; postInstall = '' cp -r "$NIX_BUILD_TOP/source"/bin/* $out/bin diff --git a/pkgs/applications/version-management/gitlab/gitlab-workhorse/default.nix b/pkgs/applications/version-management/gitlab/gitlab-workhorse/default.nix index 99fbe221d5d3..1f64e343056b 100644 --- a/pkgs/applications/version-management/gitlab/gitlab-workhorse/default.nix +++ b/pkgs/applications/version-management/gitlab/gitlab-workhorse/default.nix @@ -5,7 +5,7 @@ in buildGoModule rec { pname = "gitlab-workhorse"; - version = "16.0.5"; + version = "16.1.0"; src = fetchFromGitLab { owner = data.owner; @@ -16,7 +16,7 @@ buildGoModule rec { sourceRoot = "source/workhorse"; - vendorSha256 = "sha256-B9YZkqAMYvTnnWx2tYEF0VZ/+9LZaWS5euQ9ZX2m49E="; + vendorSha256 = "sha256-lKl/V2fti0eqrEoeJNNwvJbZO7z7v+5HlES+dyxxcP4="; buildInputs = [ git ]; ldflags = [ "-X main.Version=${version}" ]; doCheck = false; diff --git a/pkgs/applications/version-management/gitlab/remove-hardcoded-locations.patch b/pkgs/applications/version-management/gitlab/remove-hardcoded-locations.patch index e7d704237aed..1a468724e354 100644 --- a/pkgs/applications/version-management/gitlab/remove-hardcoded-locations.patch +++ b/pkgs/applications/version-management/gitlab/remove-hardcoded-locations.patch @@ -53,7 +53,7 @@ index d096174fca3a..02d0f689c523 100644 # Important: keep the satellites.path setting until GitLab 9.0 at # least. This setting is fed to 'rm -rf' in diff --git a/config/puma.rb.example b/config/puma.rb.example -index 9fc354a8fe8..2352ca9b58c 100644 +index 07a6f6a25015..14a718a43202 100644 --- a/config/puma.rb.example +++ b/config/puma.rb.example @@ -5,12 +5,8 @@ @@ -71,7 +71,7 @@ index 9fc354a8fe8..2352ca9b58c 100644 # Configure "min" to be the minimum number of threads to use to answer # requests and "max" the maximum. -@@ -31,12 +27,12 @@ queue_requests false +@@ -31,11 +27,11 @@ queue_requests false # Bind the server to "url". "tcp://", "unix://" and "ssl://" are the only # accepted protocols. @@ -81,14 +81,12 @@ index 9fc354a8fe8..2352ca9b58c 100644 workers 3 -require_relative "/home/git/gitlab/lib/gitlab/cluster/lifecycle_events" --require_relative "/home/git/gitlab/lib/gitlab/cluster/puma_worker_killer_initializer" +require_relative ENV['GITLAB_PATH'] + "lib/gitlab/cluster/lifecycle_events" -+require_relative ENV['GITLAB_PATH'] + "lib/gitlab/cluster/puma_worker_killer_initializer" on_restart do # Signal application hooks that we're about to restart -@@ -80,7 +76,7 @@ if defined?(nakayoshi_fork) - end +@@ -74,7 +70,7 @@ worker_timeout 60 + wait_for_less_busy_worker ENV.fetch('PUMA_WAIT_FOR_LESS_BUSY_WORKER', 0.001).to_f # Use json formatter -require_relative "/home/git/gitlab/lib/gitlab/puma_logging/json_formatter" diff --git a/pkgs/applications/version-management/gitlab/rubyEnv/Gemfile b/pkgs/applications/version-management/gitlab/rubyEnv/Gemfile index 10c4d6dc8d86..ef5a22d20140 100644 --- a/pkgs/applications/version-management/gitlab/rubyEnv/Gemfile +++ b/pkgs/applications/version-management/gitlab/rubyEnv/Gemfile @@ -25,7 +25,7 @@ gem 'responders', '~> 3.0' gem 'sprockets', '~> 3.7.0' -gem 'view_component', '~> 2.82.0' +gem 'view_component', '~> 3.2.0' # Supported DBs gem 'pg', '~> 1.5.3' @@ -46,9 +46,9 @@ gem 'devise', '~> 4.8.1' gem 'devise-pbkdf2-encryptable', '~> 0.0.0', path: 'vendor/gems/devise-pbkdf2-encryptable' gem 'bcrypt', '~> 3.1', '>= 3.1.14' gem 'doorkeeper', '~> 5.6', '>= 5.6.6' -gem 'doorkeeper-openid_connect', '~> 1.8', '>= 1.8.6' +gem 'doorkeeper-openid_connect', '~> 1.8', '>= 1.8.7' gem 'rexml', '~> 3.2.5' -gem 'ruby-saml', '~> 1.13.0' +gem 'ruby-saml', '~> 1.15.0' gem 'omniauth', '~> 2.1.0' gem 'omniauth-auth0', '~> 3.1' gem 'omniauth-azure-activedirectory-v2', '~> 2.0' @@ -61,6 +61,7 @@ gem 'omniauth-gitlab', '~> 4.0.0', path: 'vendor/gems/omniauth-gitlab' # See ven gem 'omniauth-google-oauth2', '~> 1.1' gem 'omniauth-oauth2-generic', '~> 0.2.2' gem 'omniauth-saml', '~> 2.1.0' +gem 'omniauth-shibboleth-redux', '~> 2.0' gem 'omniauth-twitter', '~> 1.4' gem 'omniauth_crowd', '~> 2.4.0', path: 'vendor/gems/omniauth_crowd' # See vendor/gems/omniauth_crowd/README.md gem 'omniauth_openid_connect', '~> 0.6.1' @@ -105,13 +106,13 @@ gem 'gpgme', '~> 2.0.22' # GitLab fork with several improvements to original library. For full list of changes # see https://github.com/intridea/omniauth-ldap/compare/master...gitlabhq:master gem 'gitlab_omniauth-ldap', '~> 2.2.0', require: 'omniauth-ldap' -gem 'net-ldap', '~> 0.17.1' +gem 'net-ldap', '~> 0.18.0' # API -gem 'grape', '~> 1.5.2' +gem 'grape', '~> 1.7.0' gem 'grape-entity', '~> 0.10.0' gem 'rack-cors', '~> 1.1.1', require: 'rack/cors' -gem 'grape-swagger', '~>1.5.0', group: [:development, :test] +gem 'grape-swagger', '~> 1.6.1', group: [:development, :test] gem 'grape-swagger-entity', '~> 0.5.1', group: [:development, :test] # GraphQL API @@ -172,9 +173,9 @@ gem 'seed-fu', '~> 2.3.7' gem 'elasticsearch-model', '~> 7.2' gem 'elasticsearch-rails', '~> 7.2', require: 'elasticsearch/rails/instrumentation' gem 'elasticsearch-api', '7.13.3' -gem 'aws-sdk-core', '~> 3.172.0' +gem 'aws-sdk-core', '~> 3.175.0' gem 'aws-sdk-cloudformation', '~> 1' -gem 'aws-sdk-s3', '~> 1.122.0' +gem 'aws-sdk-s3', '~> 1.126.0' gem 'faraday_middleware-aws-sigv4', '~>0.3.0' gem 'typhoeus', '~> 1.4.0' # Used with Elasticsearch to support http keep-alive connections @@ -182,7 +183,7 @@ gem 'typhoeus', '~> 1.4.0' # Used with Elasticsearch to support http keep-alive gem 'html-pipeline', '~> 2.14.3' gem 'deckar01-task_list', '2.3.2' gem 'gitlab-markup', '~> 1.9.0', require: 'github/markup' -gem 'commonmarker', '~> 0.23.6' +gem 'commonmarker', '~> 0.23.9' gem 'kramdown', '~> 2.3.1' gem 'RedCloth', '~> 4.3.2' gem 'rdoc', '~> 6.3.2' @@ -193,9 +194,9 @@ gem 'asciidoctor', '~> 2.0.18' gem 'asciidoctor-include-ext', '~> 0.4.0', require: false gem 'asciidoctor-plantuml', '~> 0.0.16' gem 'asciidoctor-kroki', '~> 0.8.0', require: false -gem 'rouge', '~> 4.1.0' +gem 'rouge', '~> 4.1.2' gem 'truncato', '~> 0.7.12' -gem 'nokogiri', '~> 1.14.3' +gem 'nokogiri', '~> 1.15', '>= 1.15.2' # Calendar rendering gem 'icalendar' @@ -210,8 +211,7 @@ gem 'rack', '~> 2.2.7' gem 'rack-timeout', '~> 0.6.3', require: 'rack/timeout/base' group :puma do - gem 'puma', '~> 5.6.5', require: false - gem 'puma_worker_killer', '~> 0.3.1', require: false + gem 'puma', '~> 6.3', require: false gem 'sd_notify', '~> 0.1.0', require: false end @@ -288,10 +288,10 @@ gem 'circuitbox', '2.0.0' # Sanitize user input gem 'sanitize', '~> 6.0' -gem 'babosa', '~> 1.0.4' +gem 'babosa', '~> 2.0' # Sanitizes SVG input -gem 'loofah', '~> 2.21.0' +gem 'loofah', '~> 2.21.3' # Working with license # Detects the open source license the repository includes @@ -323,7 +323,7 @@ gem 'gon', '~> 6.4.0' gem 'request_store', '~> 1.5.1' gem 'base32', '~> 0.3.0' -gem 'gitlab-license', '~> 2.2.1' +gem 'gitlab-license', '~> 2.3' # Protect against bruteforcing gem 'rack-attack', '~> 6.6.1' @@ -336,11 +336,11 @@ gem 'sentry-sidekiq', '~> 5.8.0' # PostgreSQL query parsing # -gem 'pg_query', '~> 2.2', '>= 2.2.1' +gem 'pg_query', '~> 4.2.1' gem 'premailer-rails', '~> 1.10.3' -gem 'gitlab-labkit', '~> 0.32.0' +gem 'gitlab-labkit', '~> 0.33.0' gem 'thrift', '>= 0.16.0' # I18n @@ -363,12 +363,12 @@ gem 'snowplow-tracker', '~> 0.8.0' # Metrics gem 'webrick', '~> 1.8.1', require: false -gem 'prometheus-client-mmap', '~> 0.23', require: 'prometheus/client' +gem 'prometheus-client-mmap', '~> 0.25', require: 'prometheus/client' gem 'warning', '~> 1.3.0' group :development do - gem 'lefthook', '~> 1.3.13', require: false + gem 'lefthook', '~> 1.4.2', require: false gem 'rubocop' gem 'solargraph', '~> 0.47.2', require: false @@ -376,7 +376,7 @@ group :development do gem 'lookbook', '~> 2.0', '>= 2.0.1' # Better errors handler - gem 'better_errors', '~> 2.10.0' + gem 'better_errors', '~> 2.10.1' gem 'sprite-factory', '~> 1.7' @@ -386,6 +386,7 @@ end group :development, :test do gem 'deprecation_toolkit', '~> 1.5.1', require: false gem 'bullet', '~> 7.0.2' + gem 'parser', '~> 3.2', '>= 3.2.2.3' gem 'pry-byebug' gem 'pry-rails', '~> 0.3.9' gem 'pry-shell', '~> 0.6.1' @@ -453,7 +454,7 @@ group :test do gem 'rspec-benchmark', '~> 0.6.0' gem 'rspec-parameterized', '~> 1.0', require: false - gem 'capybara', '~> 3.39' + gem 'capybara', '~> 3.39', '>= 3.39.1' gem 'capybara-screenshot', '~> 1.0.26' # 4.9.1 drops Ruby 2.7 support. We can upgrade further after we drop Ruby 2.7 support. gem 'selenium-webdriver', '= 4.9.0' @@ -472,6 +473,8 @@ group :test do # Moved in `test` because https://gitlab.com/gitlab-org/gitlab/-/issues/217527 gem 'derailed_benchmarks', require: false + + gem 'gitlab_quality-test_tooling', '~> 0.8.1', require: false end gem 'octokit', '~> 4.15' @@ -506,14 +509,14 @@ gem 'ssh_data', '~> 1.3' gem 'spamcheck', '~> 1.3.0' # Gitaly GRPC protocol definitions -gem 'gitaly', '~> 15.9.0-rc3' +gem 'gitaly', '~> 16.1.0-rc2' # KAS GRPC protocol definitions gem 'kas-grpc', '~> 0.1.0' gem 'grpc', '~> 1.42.0' -gem 'google-protobuf', '~> 3.22', '>= 3.22.3' +gem 'google-protobuf', '~> 3.23', '>= 3.23.3' gem 'toml-rb', '~> 2.2.0' @@ -587,7 +590,7 @@ gem 'cvss-suite', '~> 3.0.1', require: 'cvss_suite' gem 'arr-pm', '~> 0.0.12' # Remote Development -gem 'devfile', '~> 0.0.17.pre.alpha1' +gem 'devfile', '~> 0.0.19.pre.alpha1' # Apple plist parsing gem 'CFPropertyList', '~> 3.0.0' @@ -599,5 +602,8 @@ gem 'telesignenterprise', '~> 2.2' # BufferedIO patch # Updating this version will require updating scripts/allowed_warnings.txt gem 'net-protocol', '~> 0.1.3' +# Lock this until we make DNS rebinding work with the updated net-http: +# https://gitlab.com/gitlab-org/gitlab/-/issues/413528 +gem 'net-http', '= 0.1.1' gem 'duo_api', '~> 1.3' diff --git a/pkgs/applications/version-management/gitlab/rubyEnv/Gemfile.lock b/pkgs/applications/version-management/gitlab/rubyEnv/Gemfile.lock index 199c806a854c..3aaf6a459309 100644 --- a/pkgs/applications/version-management/gitlab/rubyEnv/Gemfile.lock +++ b/pkgs/applications/version-management/gitlab/rubyEnv/Gemfile.lock @@ -203,7 +203,7 @@ GEM aws-sdk-cloudformation (1.41.0) aws-sdk-core (~> 3, >= 3.99.0) aws-sigv4 (~> 1.1) - aws-sdk-core (3.172.0) + aws-sdk-core (3.175.0) aws-eventstream (~> 1, >= 1.0.2) aws-partitions (~> 1, >= 1.651.0) aws-sigv4 (~> 1.5) @@ -211,8 +211,8 @@ GEM aws-sdk-kms (1.64.0) aws-sdk-core (~> 3, >= 3.165.0) aws-sigv4 (~> 1.1) - aws-sdk-s3 (1.122.0) - aws-sdk-core (~> 3, >= 3.165.0) + aws-sdk-s3 (1.126.0) + aws-sdk-core (~> 3, >= 3.174.0) aws-sdk-kms (~> 1) aws-sigv4 (~> 1.4) aws-sigv4 (1.5.1) @@ -236,7 +236,7 @@ GEM faraday_middleware (~> 1.0, >= 1.0.0.rc1) net-http-persistent (~> 4.0) nokogiri (~> 1, >= 1.10.8) - babosa (1.0.4) + babosa (2.0.0) backport (1.2.0) base32 (0.3.2) batch-loader (2.0.1) @@ -248,7 +248,7 @@ GEM memory_profiler (~> 1) benchmark-perf (0.6.0) benchmark-trend (0.4.0) - better_errors (2.10.0) + better_errors (2.10.1) erubi (>= 1.0.0) rack (>= 0.9.0) rouge (>= 1.0.0) @@ -266,7 +266,7 @@ GEM bundler (>= 1.2.0, < 3) thor (>= 0.18, < 2) byebug (11.1.3) - capybara (3.39.0) + capybara (3.39.1) addressable matrix mini_mime (>= 0.1.3) @@ -307,7 +307,7 @@ GEM coercible (1.0.0) descendants_tracker (~> 0.0.1) colored2 (3.1.2) - commonmarker (0.23.6) + commonmarker (0.23.9) concurrent-ruby (1.2.2) connection_pool (2.3.0) cork (0.3.0) @@ -367,7 +367,7 @@ GEM thor (>= 0.19, < 2) descendants_tracker (0.0.4) thread_safe (~> 0.3, >= 0.3.1) - devfile (0.0.17.pre.alpha1) + devfile (0.0.19.pre.alpha1) device_detector (1.0.0) devise (4.8.1) bcrypt (~> 3.0) @@ -393,30 +393,24 @@ GEM unf (>= 0.0.5, < 1.0.0) doorkeeper (5.6.6) railties (>= 5) - doorkeeper-openid_connect (1.8.6) + doorkeeper-openid_connect (1.8.7) doorkeeper (>= 5.5, < 5.7) jwt (>= 2.5) dotenv (2.7.6) - dry-configurable (0.12.0) + dry-core (1.0.0) concurrent-ruby (~> 1.0) - dry-core (~> 0.5, >= 0.5.0) - dry-container (0.7.2) + zeitwerk (~> 2.6) + dry-inflector (1.0.0) + dry-logic (1.5.0) concurrent-ruby (~> 1.0) - dry-configurable (~> 0.1, >= 0.1.3) - dry-core (0.5.0) + dry-core (~> 1.0, < 2) + zeitwerk (~> 2.6) + dry-types (1.7.1) concurrent-ruby (~> 1.0) - dry-equalizer (0.3.0) - dry-inflector (0.2.0) - dry-logic (1.1.0) - concurrent-ruby (~> 1.0) - dry-core (~> 0.5, >= 0.5) - dry-types (1.4.0) - concurrent-ruby (~> 1.0) - dry-container (~> 0.3) - dry-core (~> 0.4, >= 0.4.4) - dry-equalizer (~> 0.3) - dry-inflector (~> 0.1, >= 0.1.2) - dry-logic (~> 1.0, >= 1.0.2) + dry-core (~> 1.0) + dry-inflector (~> 1.0) + dry-logic (~> 1.4) + zeitwerk (~> 2.6) dumb_delegator (1.0.0) duo_api (1.3.0) e2mmap (0.1.0) @@ -581,7 +575,7 @@ GEM rails (>= 3.2.0) git (1.11.0) rchardet (~> 1.8) - gitaly (15.9.0.pre.rc3) + gitaly (16.1.0.pre.rc2) grpc (~> 1.0) gitlab (4.19.0) httparty (~> 0.20) @@ -602,15 +596,15 @@ GEM fog-json (~> 1.2.0) mime-types ms_rest_azure (~> 0.12.0) - gitlab-labkit (0.32.0) + gitlab-labkit (0.33.0) actionpack (>= 5.0.0, < 8.0.0) activesupport (>= 5.0.0, < 8.0.0) grpc (>= 1.37) jaeger-client (~> 1.1.0) opentracing (~> 0.4) - pg_query (~> 2.1) + pg_query (~> 4.2.1) redis (> 3.0.0, < 6.0.0) - gitlab-license (2.2.2) + gitlab-license (2.3.0) gitlab-mail_room (0.0.23) jwt (>= 2.0) net-imap (>= 0.2.1) @@ -630,6 +624,15 @@ GEM omniauth (>= 1.3, < 3) pyu-ruby-sasl (>= 0.0.3.3, < 0.1) rubyntlm (~> 0.5) + gitlab_quality-test_tooling (0.8.1) + activesupport (>= 6.1, < 7.1) + gitlab (~> 4.19) + http (~> 5.0) + nokogiri (~> 1.10) + parallel (>= 1, < 2) + rainbow (>= 3, < 4) + table_print (= 1.5.7) + zeitwerk (>= 2, < 3) globalid (1.1.0) activesupport (>= 5.0) gon (6.4.0) @@ -691,7 +694,7 @@ GEM google-cloud-core (~> 1.6) googleauth (>= 0.16.2, < 2.a) mini_mime (~> 1.0) - google-protobuf (3.22.3) + google-protobuf (3.23.3) googleapis-common-protos (1.4.0) google-protobuf (~> 3.14) googleapis-common-protos-types (~> 1.2) @@ -707,7 +710,7 @@ GEM signet (>= 0.16, < 2.a) gpgme (2.0.22) mini_portile2 (~> 2.7) - grape (1.5.2) + grape (1.7.0) activesupport builder dry-types (>= 1.1) @@ -722,7 +725,7 @@ GEM grape (~> 1.3) rake (> 12) ruby2_keywords (~> 0.0.2) - grape-swagger (1.5.0) + grape-swagger (1.6.1) grape (~> 1.3) grape-swagger-entity (0.5.1) grape-entity (>= 0.6.0) @@ -878,7 +881,7 @@ GEM rest-client (~> 2.0) launchy (2.5.0) addressable (~> 2.7) - lefthook (1.3.13) + lefthook (1.4.2) letter_opener (1.7.0) launchy (~> 2.2) letter_opener_web (2.0.0) @@ -913,9 +916,9 @@ GEM activesupport (>= 4) railties (>= 4) request_store (~> 1.0) - loofah (2.21.0) + loofah (2.21.3) crass (~> 1.0.2) - nokogiri (>= 1.5.9) + nokogiri (>= 1.12.0) lookbook (2.0.1) activemodel css_parser @@ -949,7 +952,7 @@ GEM mini_histogram (0.3.1) mini_magick (4.10.1) mini_mime (1.1.2) - mini_portile2 (2.8.1) + mini_portile2 (2.8.2) minitest (5.11.3) mixlib-cli (2.1.8) mixlib-config (3.0.9) @@ -971,20 +974,23 @@ GEM multi_xml (0.6.0) multipart-post (2.2.3) murmurhash3 (0.1.7) - mustermann (1.1.1) + mustermann (3.0.0) ruby2_keywords (~> 0.0.1) - mustermann-grape (1.0.1) + mustermann-grape (1.0.2) mustermann (>= 1.0.0) nap (1.1.0) neighbor (0.2.3) activerecord (>= 5.2) nenv (0.3.0) + net-http (0.1.1) + net-protocol + uri net-http-persistent (4.0.1) connection_pool (~> 2.2) net-imap (0.3.4) date net-protocol - net-ldap (0.17.1) + net-ldap (0.18.0) net-ntp (2.1.3) net-pop (0.1.2) net-protocol @@ -998,8 +1004,8 @@ GEM netrc (0.11.0) nio4r (2.5.8) no_proxy_fix (0.1.2) - nokogiri (1.14.3) - mini_portile2 (~> 2.8.0) + nokogiri (1.15.2) + mini_portile2 (~> 2.8.2) racc (~> 1.4) notiffany (0.1.3) nenv (~> 0.1) @@ -1070,6 +1076,8 @@ GEM omniauth-saml (2.1.0) omniauth (~> 2.0) ruby-saml (~> 1.12) + omniauth-shibboleth-redux (2.0.0) + omniauth (>= 2.0.0) omniauth-twitter (1.4.0) omniauth-oauth (~> 1.1) rack @@ -1120,16 +1128,17 @@ GEM expgen (~> 0.1) rainbow (~> 3.1.1) parallel (1.22.1) - parser (3.2.0.0) + parser (3.2.2.3) ast (~> 2.4.1) + racc parslet (1.8.2) pastel (0.8.0) tty-color (~> 0.5) peek (1.1.0) railties (>= 4.0.0) pg (1.5.3) - pg_query (2.2.1) - google-protobuf (>= 3.19.2) + pg_query (4.2.1) + google-protobuf (>= 3.22.3) plist (3.6.0) png_quantizator (0.2.1) po_to_json (1.0.1) @@ -1145,7 +1154,7 @@ GEM coderay parser unparser - prometheus-client-mmap (0.23.1) + prometheus-client-mmap (0.25.0) rb_sys (~> 0.9) pry (0.14.2) coderay (~> 1.1) @@ -1160,11 +1169,8 @@ GEM tty-markdown tty-prompt public_suffix (5.0.0) - puma (5.6.5) + puma (6.3.0) nio4r (~> 2.0) - puma_worker_killer (0.3.1) - get_process_mem (~> 0.2) - puma (>= 2.7) pyu-ruby-sasl (0.0.3.3) raabro (1.4.0) racc (1.6.2) @@ -1226,7 +1232,7 @@ GEM rb-fsevent (0.11.2) rb-inotify (0.10.1) ffi (~> 1.0) - rb_sys (0.9.75) + rb_sys (0.9.78) rbtrace (0.4.14) ffi (>= 1.0.6) msgpack (>= 0.4.3) @@ -1273,7 +1279,7 @@ GEM rexml (3.2.5) rinku (2.0.0) rotp (6.2.0) - rouge (4.1.0) + rouge (4.1.2) rqrcode (0.7.0) chunky_png rqrcode-rails3 (0.1.7) @@ -1358,8 +1364,8 @@ GEM ruby-openai (3.7.0) httparty (>= 0.18.1) ruby-progressbar (1.11.0) - ruby-saml (1.13.0) - nokogiri (>= 1.10.5) + ruby-saml (1.15.0) + nokogiri (>= 1.13.10) rexml ruby-statistics (3.0.0) ruby2_keywords (0.0.5) @@ -1503,6 +1509,7 @@ GEM sys-filesystem (1.4.3) ffi (~> 1.1) sysexits (1.2.0) + table_print (1.5.7) tanuki_emoji (0.6.0) telesign (2.2.4) net-http-persistent (>= 3.0.0, < 5.0) @@ -1585,6 +1592,7 @@ GEM unparser (0.6.7) diff-lcs (~> 1.3) parser (>= 3.2.0) + uri (0.12.1) uri_template (0.7.0) valid_email (0.1.3) activemodel @@ -1600,7 +1608,7 @@ GEM activesupport (>= 3.0) version_gem (1.1.0) version_sorter (2.3.0) - view_component (2.82.0) + view_component (3.2.0) activesupport (>= 5.2.0, < 8.0) concurrent-ruby (~> 1.0) method_source (~> 1.0) @@ -1672,28 +1680,28 @@ DEPENDENCIES autoprefixer-rails (= 10.2.5.1) awesome_print aws-sdk-cloudformation (~> 1) - aws-sdk-core (~> 3.172.0) - aws-sdk-s3 (~> 1.122.0) + aws-sdk-core (~> 3.175.0) + aws-sdk-s3 (~> 1.126.0) axe-core-rspec - babosa (~> 1.0.4) + babosa (~> 2.0) base32 (~> 0.3.0) batch-loader (~> 2.0.1) bcrypt (~> 3.1, >= 3.1.14) benchmark-ips (~> 2.11.0) benchmark-memory (~> 0.1) - better_errors (~> 2.10.0) + better_errors (~> 2.10.1) bootsnap (~> 1.16.0) browser (~> 5.3.1) bullet (~> 7.0.2) bundler-audit (~> 0.7.0.1) bundler-checksum (~> 0.1.0)! - capybara (~> 3.39) + capybara (~> 3.39, >= 3.39.1) capybara-screenshot (~> 1.0.26) carrierwave (~> 1.3) charlock_holmes (~> 0.7.7) circuitbox (= 2.0.0) cloud_profiler_agent (~> 0.0.0)! - commonmarker (~> 0.23.6) + commonmarker (~> 0.23.9) concurrent-ruby (~> 1.1) connection_pool (~> 2.0) countries (~> 4.0.0) @@ -1705,7 +1713,7 @@ DEPENDENCIES declarative_policy (~> 1.1.0) deprecation_toolkit (~> 1.5.1) derailed_benchmarks - devfile (~> 0.0.17.pre.alpha1) + devfile (~> 0.0.19.pre.alpha1) device_detector devise (~> 4.8.1) devise-pbkdf2-encryptable (~> 0.0.0)! @@ -1714,7 +1722,7 @@ DEPENDENCIES diffy (~> 3.4) discordrb-webhooks (~> 3.4) doorkeeper (~> 5.6, >= 5.6.6) - doorkeeper-openid_connect (~> 1.8, >= 1.8.6) + doorkeeper-openid_connect (~> 1.8, >= 1.8.7) duo_api (~> 1.3) ed25519 (~> 1.3.0) elasticsearch-api (= 7.13.3) @@ -1741,13 +1749,13 @@ DEPENDENCIES gettext (~> 3.3) gettext_i18n_rails (~> 1.8.0) gettext_i18n_rails_js (~> 1.3) - gitaly (~> 15.9.0.pre.rc3) + gitaly (~> 16.1.0.pre.rc2) gitlab-chronic (~> 0.10.5) gitlab-dangerfiles (~> 3.10.0) gitlab-experiment (~> 0.7.1) gitlab-fog-azure-rm (~> 1.7.0) - gitlab-labkit (~> 0.32.0) - gitlab-license (~> 2.2.1) + gitlab-labkit (~> 0.33.0) + gitlab-license (~> 2.3) gitlab-mail_room (~> 0.0.23) gitlab-markup (~> 1.9.0) gitlab-net-dns (~> 0.9.2) @@ -1755,6 +1763,7 @@ DEPENDENCIES gitlab-styles (~> 10.0.0) gitlab_chronic_duration (~> 0.10.6.2) gitlab_omniauth-ldap (~> 2.2.0) + gitlab_quality-test_tooling (~> 0.8.1) gon (~> 6.4.0) google-apis-androidpublisher_v3 (~> 0.34.0) google-apis-cloudbilling_v1 (~> 0.21.0) @@ -1767,12 +1776,12 @@ DEPENDENCIES google-apis-serviceusage_v1 (~> 0.28.0) google-apis-sqladmin_v1beta4 (~> 0.41.0) google-cloud-storage (~> 1.44.0) - google-protobuf (~> 3.22, >= 3.22.3) + google-protobuf (~> 3.23, >= 3.23.3) gpgme (~> 2.0.22) - grape (~> 1.5.2) + grape (~> 1.7.0) grape-entity (~> 0.10.0) grape-path-helpers (~> 1.7.1) - grape-swagger (~> 1.5.0) + grape-swagger (~> 1.6.1) grape-swagger-entity (~> 0.5.1) grape_logging (~> 1.8) graphiql-rails (~> 1.8) @@ -1806,14 +1815,14 @@ DEPENDENCIES knapsack (~> 1.21.1) kramdown (~> 2.3.1) kubeclient (~> 4.11.0) - lefthook (~> 1.3.13) + lefthook (~> 1.4.2) letter_opener_web (~> 2.0.0) license_finder (~> 7.0) licensee (~> 9.15) listen (~> 3.7) lockbox (~> 1.1.1) lograge (~> 0.5) - loofah (~> 2.21.0) + loofah (~> 2.21.3) lookbook (~> 2.0, >= 2.0.1) lru_redux mail (= 2.8.1) @@ -1825,10 +1834,11 @@ DEPENDENCIES minitest (~> 5.11.0) multi_json (~> 1.14.1) neighbor (~> 0.2.3) - net-ldap (~> 0.17.1) + net-http (= 0.1.1) + net-ldap (~> 0.18.0) net-ntp net-protocol (~> 0.1.3) - nokogiri (~> 1.14.3) + nokogiri (~> 1.15, >= 1.15.2) oauth2 (~> 2.0) octokit (~> 4.15) ohai (~> 17.9) @@ -1848,6 +1858,7 @@ DEPENDENCIES omniauth-oauth2-generic (~> 0.2.2) omniauth-salesforce (~> 1.0.5)! omniauth-saml (~> 2.1.0) + omniauth-shibboleth-redux (~> 2.0) omniauth-twitter (~> 1.4) omniauth_crowd (~> 2.4.0)! omniauth_openid_connect (~> 0.6.1) @@ -1856,18 +1867,18 @@ DEPENDENCIES org-ruby (~> 0.9.12) pact (~> 1.63) parallel (~> 1.19) + parser (~> 3.2, >= 3.2.2.3) parslet (~> 1.8) peek (~> 1.1) pg (~> 1.5.3) - pg_query (~> 2.2, >= 2.2.1) + pg_query (~> 4.2.1) png_quantizator (~> 0.2.1) premailer-rails (~> 1.10.3) - prometheus-client-mmap (~> 0.23) + prometheus-client-mmap (~> 0.25) pry-byebug pry-rails (~> 0.3.9) pry-shell (~> 0.6.1) - puma (~> 5.6.5) - puma_worker_killer (~> 0.3.1) + puma (~> 6.3) rack (~> 2.2.7) rack-attack (~> 6.6.1) rack-cors (~> 1.1.1) @@ -1889,7 +1900,7 @@ DEPENDENCIES responders (~> 3.0) retriable (~> 3.1.2) rexml (~> 3.2.5) - rouge (~> 4.1.0) + rouge (~> 4.1.2) rqrcode-rails3 (~> 0.1.7) rspec-benchmark (~> 0.6.0) rspec-parameterized (~> 1.0) @@ -1902,7 +1913,7 @@ DEPENDENCIES ruby-magic (~> 0.6) ruby-openai (~> 3.7) ruby-progressbar (~> 1.10) - ruby-saml (~> 1.13.0) + ruby-saml (~> 1.15.0) ruby_parser (~> 3.20) rubyzip (~> 2.3.2) rugged (~> 1.5) @@ -1952,7 +1963,7 @@ DEPENDENCIES valid_email (~> 0.1) validates_hostname (~> 1.0.11) version_sorter (~> 2.3) - view_component (~> 2.82.0) + view_component (~> 3.2.0) vmstat (~> 2.3.0) warning (~> 1.3.0) webauthn (~> 3.0) @@ -1962,4 +1973,4 @@ DEPENDENCIES yajl-ruby (~> 1.4.3) BUNDLED WITH - 2.4.13 + 2.4.14 diff --git a/pkgs/applications/version-management/gitlab/rubyEnv/gemset.nix b/pkgs/applications/version-management/gitlab/rubyEnv/gemset.nix index ac66421c7094..9c71ff591aad 100644 --- a/pkgs/applications/version-management/gitlab/rubyEnv/gemset.nix +++ b/pkgs/applications/version-management/gitlab/rubyEnv/gemset.nix @@ -401,10 +401,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "06scfn1qjfqvgr05ddrcbihlnfi7bffk8r0m5z536w4mm1s3gh6x"; + sha256 = "1fbbzcszpdjy2yzxfvl5fzgn0jgznkwxvqpb46nxv69gqhv3dpsg"; type = "gem"; }; - version = "3.172.0"; + version = "3.175.0"; }; aws-sdk-kms = { dependencies = ["aws-sdk-core" "aws-sigv4"]; @@ -423,10 +423,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "01cryf8kfkmlsxb327szcwcagsp7lss5gmk6zxlgap65lv8bc7rx"; + sha256 = "17ya49rwjzimqhzsj6vlc4xfvj2sixy04kr4b6ddg3r6y0jrsixi"; type = "gem"; }; - version = "1.122.0"; + version = "1.126.0"; }; aws-sigv4 = { dependencies = ["aws-eventstream"]; @@ -499,10 +499,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "16dwqn33kmxkqkv51cwiikdkbrdjfsymlnc0rgbjwilmym8a9phq"; + sha256 = "19mqrnyizr1ipdp26vhrg0hwb851bwyvrs6xc29dk3ywljw8s8d6"; type = "gem"; }; - version = "1.0.4"; + version = "2.0.0"; }; backport = { groups = ["default" "development"]; @@ -611,10 +611,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0fhi891k7c4l967bacahq2jhnxswfmbpmbsg1yapczwpm1ynmaz3"; + sha256 = "0wqazisnn6hn1wsza412xribpw5wzx6b5z5p4mcpfgizr6xg367p"; type = "gem"; }; - version = "2.10.0"; + version = "2.10.1"; }; bindata = { groups = ["default"]; @@ -720,10 +720,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "06b4nlhirsq8ny17s8zgz7qyvl9v41rixj1xkviiiwxlnjz982d3"; + sha256 = "1qhg45jxxy5h90frmajrrh5sirmj29sbfhbf7q0qhjymc0w1p0r5"; type = "gem"; }; - version = "3.39.0"; + version = "3.39.1"; }; capybara-screenshot = { dependencies = ["capybara" "launchy"]; @@ -911,10 +911,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0f3v6ffikj694h925zvfzgx995q6l1ixnqpph3qpnjdsyjpsmbn8"; + sha256 = "074162raa8pc92q6833hgqdlfr3z5jgid9avdz5k25cnls2rqwrf"; type = "gem"; }; - version = "0.23.6"; + version = "0.23.9"; }; concurrent-ruby = { groups = ["default" "development" "test"]; @@ -1163,10 +1163,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0v34ivsfpc4d291j89jyg2jz970h94jbz01hdm2jwcmq798yfm98"; + sha256 = "1n4yxjijplg0klcnjdhk7kxmvlb0szchk1ad8flg5hb2j59c8a6r"; type = "gem"; }; - version = "0.0.17.pre.alpha1"; + version = "0.0.19.pre.alpha1"; }; device_detector = { groups = ["default"]; @@ -1300,10 +1300,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "00z0n4ix21nvqk74hhz5ab811366pdjx99cn2i26yiwpwr1nbi4d"; + sha256 = "11p7p3b0yb12xfdhxxsifc2mz0rj1hlgi8sbcwjzxvld24rszvbi"; type = "gem"; }; - version = "1.8.6"; + version = "1.8.7"; }; dotenv = { groups = ["default"]; @@ -1315,80 +1315,48 @@ src: }; version = "2.7.6"; }; - dry-configurable = { - dependencies = ["concurrent-ruby" "dry-core"]; - groups = ["default"]; - platforms = []; - source = { - remotes = ["https://rubygems.org"]; - sha256 = "0rvwvxrvcygvgfc3xjrihvdvnr0dh2144s8x80zfgfnz0jd5gac7"; - type = "gem"; - }; - version = "0.12.0"; - }; - dry-container = { - dependencies = ["concurrent-ruby" "dry-configurable"]; - groups = ["default"]; - platforms = []; - source = { - remotes = ["https://rubygems.org"]; - sha256 = "1npnhs3x2xcwwijpys5c8rpcvymrlab0y8806nr4h425ld5q4wd0"; - type = "gem"; - }; - version = "0.7.2"; - }; dry-core = { - dependencies = ["concurrent-ruby"]; - groups = ["default"]; + dependencies = ["concurrent-ruby" "zeitwerk"]; + groups = ["default" "development" "test"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "14s45hxcqpp2mbvwlwzn018i8qhcjzgkirigdrv31jd741rpgy9s"; + sha256 = "01gks2hrp7nl3pzb487azvd25dlbrc40d5cpk4n0szwnf2c0k4ks"; type = "gem"; }; - version = "0.5.0"; - }; - dry-equalizer = { - groups = ["default"]; - platforms = []; - source = { - remotes = ["https://rubygems.org"]; - sha256 = "0rsqpk0gjja6j6pjm0whx2px06cxr3h197vrwxp6k042p52r4v46"; - type = "gem"; - }; - version = "0.3.0"; + version = "1.0.0"; }; dry-inflector = { - groups = ["default"]; + groups = ["default" "development" "test"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "17mkdwglqsd9fg272y3zms7rixjgkb1km1xcb88ir5lxvk1jkky7"; + sha256 = "09hnvna3lg2x36li63988kv664d0zvy7y0z33803yvrdr9hj7lka"; type = "gem"; }; - version = "0.2.0"; + version = "1.0.0"; }; dry-logic = { - dependencies = ["concurrent-ruby" "dry-core"]; - groups = ["default"]; + dependencies = ["concurrent-ruby" "dry-core" "zeitwerk"]; + groups = ["default" "development" "test"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "17dnc3g9y2nj42rdx2bdvsvvms10vgw4qzjb2iw2gln9hj8b797c"; + sha256 = "05nldkc154r0qzlhss7n5klfiyyz05x2fkq08y13s34py6023vcr"; type = "gem"; }; - version = "1.1.0"; + version = "1.5.0"; }; dry-types = { - dependencies = ["concurrent-ruby" "dry-container" "dry-core" "dry-equalizer" "dry-inflector" "dry-logic"]; - groups = ["default"]; + dependencies = ["concurrent-ruby" "dry-core" "dry-inflector" "dry-logic" "zeitwerk"]; + groups = ["default" "development" "test"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1px1r5khlf4lw32gsrnnnsx7dvl2d94axx3h0b6zwxrhvfq3n038"; + sha256 = "1f6dz0hm67rhybh6xq2s3vvr700cp43kf50z2lids62s2i0mh5hj"; type = "gem"; }; - version = "1.4.0"; + version = "1.7.1"; }; dumb_delegator = { groups = ["default" "test"]; @@ -2134,10 +2102,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1gja1b2zirv1clavlg6c0c3xc0z2si2xvxcp9cd165q4lwh47ika"; + sha256 = "1bz3i05lr1nzm35xg11blaq78v96sg49aw1yh4hj7wfk3cbdn1q0"; type = "gem"; }; - version = "15.9.0.pre.rc3"; + version = "16.1.0.pre.rc2"; }; gitlab = { dependencies = ["httparty" "terminal-table"]; @@ -2200,20 +2168,20 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0vl64blqz850d5vahwpwyrsvw4iarn578p8bzmcw11imqpnk62pk"; + sha256 = "0nz0g5s65wkicsn9ianqxi7ys2w666n226gfblzllcfy1z9siyyi"; type = "gem"; }; - version = "0.32.0"; + version = "0.33.0"; }; gitlab-license = { groups = ["default"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "07pdi9zcifiw8vjv5zz5jdv2gmaq3rkyxfdkn0j3a0cdh9iwgjrc"; + sha256 = "0ms1kf5nmclsnmd2xa9k273asmb73ivaykwrb3g7sq263j3y7jk0"; type = "gem"; }; - version = "2.2.2"; + version = "2.3.0"; }; gitlab-mail_room = { dependencies = ["jwt" "net-imap" "oauth2"]; @@ -2289,6 +2257,17 @@ src: }; version = "2.2.0"; }; + gitlab_quality-test_tooling = { + dependencies = ["activesupport" "gitlab" "http" "nokogiri" "parallel" "rainbow" "table_print" "zeitwerk"]; + groups = ["test"]; + platforms = []; + source = { + remotes = ["https://rubygems.org"]; + sha256 = "02xwchhhfv8jkypap5pn1wjkdx92jxk4wsp71i2s0ymnqw98y401"; + type = "gem"; + }; + version = "0.8.1"; + }; globalid = { dependencies = ["activesupport"]; groups = ["default" "development" "test"]; @@ -2535,10 +2514,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1xcg53yz44cqhcpb85w3ay80kvnniy0v441c9p08wb6zzia2mnq9"; + sha256 = "1aczvz5jdslr1bfx08xrycp6ggdpaifdlh5hrdyd774mvcl0mg2d"; type = "gem"; }; - version = "3.22.3"; + version = "3.23.3"; }; googleapis-common-protos = { dependencies = ["google-protobuf" "googleapis-common-protos-types" "grpc"]; @@ -2586,14 +2565,14 @@ src: }; grape = { dependencies = ["activesupport" "builder" "dry-types" "mustermann-grape" "rack" "rack-accept"]; - groups = ["default"]; + groups = ["default" "development" "test"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0adf01kihxbmh8q84r6zyfgdmpbyb0lwcar3fi8j6bl6qcsbgwqx"; + sha256 = "0lbgysx2d64hsck11jajc4gwikj5nd82809bz0jibrnp4yb1lcw8"; type = "gem"; }; - version = "1.5.2"; + version = "1.7.0"; }; grape-entity = { dependencies = ["activesupport" "multi_json"]; @@ -2623,10 +2602,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1zy84lxrnnslray9rmfgb7ri295wda3cxx3xryz4lr5hd8r5p24w"; + sha256 = "17y6smk7shplblgic4jvi5njhd0x91n1xrvds3l6cjsjfs2d7lhg"; type = "gem"; }; - version = "1.5.0"; + version = "1.6.1"; }; grape-swagger-entity = { dependencies = ["grape-entity" "grape-swagger"]; @@ -3292,10 +3271,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0wnz60wh2yb7s5g7an64cw2brl9vvw960xnq4gs3q6drlgmbjl8g"; + sha256 = "0hqffqr2krk6gcjapriwwmdrjz56dczshxafnwrkipyxi51vwgvh"; type = "gem"; }; - version = "1.3.13"; + version = "1.4.2"; }; letter_opener = { dependencies = ["launchy"]; @@ -3410,10 +3389,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0nq23yca06rq8qxxymh4nfbx484k2yll54y780b4ilyvmcipyh7c"; + sha256 = "1p744kjpb5zk2ihklbykzii77alycjc04vpnm2ch2f3cp65imlj3"; type = "gem"; }; - version = "2.21.0"; + version = "2.21.3"; }; lookbook = { dependencies = ["activemodel" "css_parser" "htmlbeautifier" "htmlentities" "marcel" "railties" "redcarpet" "rouge" "view_component" "yard" "zeitwerk"]; @@ -3598,10 +3577,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1af4yarhbbx62f7qsmgg5fynrik0s36wjy3difkawy536xg343mp"; + sha256 = "0z7f38iq37h376n9xbl4gajdrnwzq284c9v1py4imw3gri2d5cj6"; type = "gem"; }; - version = "2.8.1"; + version = "2.8.2"; }; minitest = { groups = ["development" "test"]; @@ -3729,25 +3708,25 @@ src: }; mustermann = { dependencies = ["ruby2_keywords"]; - groups = ["default"]; + groups = ["default" "development" "test"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0ccm54qgshr1lq3pr1dfh7gphkilc19dp63rw6fcx7460pjwy88a"; + sha256 = "0rwbq20s2gdh8dljjsgj5s6wqqfmnbclhvv2c2608brv7jm6jdbd"; type = "gem"; }; - version = "1.1.1"; + version = "3.0.0"; }; mustermann-grape = { dependencies = ["mustermann"]; - groups = ["default"]; + groups = ["default" "development" "test"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0djlbi7nh161a5mwjdm1ya4hc6lyzc493ah48gn37gk6vyri5kh0"; + sha256 = "1zpmc099rcpxmlfxb71zd6l7f9fcsg1fhi6627r03y1qlgb0jlvg"; type = "gem"; }; - version = "1.0.1"; + version = "1.0.2"; }; nap = { groups = ["default" "development"]; @@ -3780,6 +3759,17 @@ src: }; version = "0.3.0"; }; + net-http = { + dependencies = ["net-protocol" "uri"]; + groups = ["default"]; + platforms = []; + source = { + remotes = ["https://rubygems.org"]; + sha256 = "11mymfxpsgpwr1qbv8vwj8av9kksqj0632p9s3x35bzrnq4y393m"; + type = "gem"; + }; + version = "0.1.1"; + }; net-http-persistent = { dependencies = ["connection_pool"]; groups = ["default"]; @@ -3807,10 +3797,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1ycw0qsw3hap8svakl0i30jkj0ffd4lpyrn17a1j0w8mz5ainmsj"; + sha256 = "0xqcffn3c1564c4fizp10dzw2v5g2pabdzrcn25hq05bqhsckbar"; type = "gem"; }; - version = "0.17.1"; + version = "0.18.0"; }; net-ntp = { groups = ["default"]; @@ -3912,10 +3902,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0fnw0z8zl8b5k35g9m5hhc1g4s6ajzjinhyxnqjrx7l7p07fw71v"; + sha256 = "1mr2ibfk874ncv0qbdkynay738w2mfinlkhnbd5lyk5yiw5q1p10"; type = "gem"; }; - version = "1.14.3"; + version = "1.15.2"; }; notiffany = { dependencies = ["nenv" "shellany"]; @@ -4175,6 +4165,17 @@ src: }; version = "2.1.0"; }; + omniauth-shibboleth-redux = { + dependencies = ["omniauth"]; + groups = ["default"]; + platforms = []; + source = { + remotes = ["https://rubygems.org"]; + sha256 = "1qgzp0xaka6vqpx69mw6nbqaqmyqrawi11cyak4gq19l23ym7cz9"; + type = "gem"; + }; + version = "2.0.0"; + }; omniauth-twitter = { dependencies = ["omniauth-oauth" "rack"]; groups = ["default"]; @@ -4344,15 +4345,15 @@ src: version = "1.22.1"; }; parser = { - dependencies = ["ast"]; + dependencies = ["ast" "racc"]; groups = ["coverage" "default" "development" "test"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0zk8mdyr0322r11d63rcp5jhz4lakxilhvyvdv0ql5dw4lb83623"; + sha256 = "1swigds85jddb5gshll1g8lkmbcgbcp9bi1d4nigwvxki8smys0h"; type = "gem"; }; - version = "3.2.0.0"; + version = "3.2.2.3"; }; parslet = { groups = ["default" "development" "test"]; @@ -4402,10 +4403,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1slcbzzqdv6104l5h8ql6kj43zmnm16g2dav8bc8dasfpwmrg1k0"; + sha256 = "0cs8c0f903phs3yjjbrhlyaipvmvm95xids06a761hf0s6lj0j5h"; type = "gem"; }; - version = "2.2.1"; + version = "4.2.1"; }; plist = { groups = ["default"]; @@ -4477,10 +4478,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0h4w0947zwwg6kbdnvg4vbmrsc8yf5ijb37sg758apks44imym28"; + sha256 = "14m09ysq0l6kih9pdy1mmdabdyjk09hvx4rzqh6phgb34s1w4pfp"; type = "gem"; }; - version = "0.23.1"; + version = "0.25.0"; }; pry = { dependencies = ["coderay" "method_source"]; @@ -4542,21 +4543,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0qzq0c791kacv68hgk9zqsd1p7zx1y1rr9j10rn9yphibb8jj436"; + sha256 = "1v7fmv0n4bhdcwh60dgza44iqai5pg34f5pzm4vh4i5fwx7mpqxh"; type = "gem"; }; - version = "5.6.5"; - }; - puma_worker_killer = { - dependencies = ["get_process_mem" "puma"]; - groups = ["puma"]; - platforms = []; - source = { - remotes = ["https://rubygems.org"]; - sha256 = "0jk1bhmx5px8y1ip4ky80cq5cwdaybdg4y55shd2vsdmjv938mcw"; - type = "gem"; - }; - version = "0.3.1"; + version = "6.3.0"; }; pyu-ruby-sasl = { groups = ["default"]; @@ -4797,10 +4787,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1zx8v677r2gs050z4cdiflp14kp6nx5z285ynj2ach0w0z7jfm23"; + sha256 = "09kszvsa9av8yb8pm9nz6p5jgshin3cqvknlvd1m927qfvdpalk3"; type = "gem"; }; - version = "0.9.75"; + version = "0.9.78"; }; rbtrace = { dependencies = ["ffi" "msgpack" "optimist"]; @@ -5068,10 +5058,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "046xwhfhi2krmbaqmg9vshf01vzld8smczx6dwppinv61ndc2vqg"; + sha256 = "0pym2zjwl6dwdfvbn7rbvmds32r70jx9qddhvvi6pqy6987ack1v"; type = "gem"; }; - version = "4.1.0"; + version = "4.1.2"; }; rqrcode = { dependencies = ["chunky_png"]; @@ -5363,10 +5353,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1706dyk5jdma75bnl9rhmx8vgzjw12ixnj3y32inmpcgzgsvs76k"; + sha256 = "18vnbzin5ypxrgcs9lllg7x311b69dyrdw2w1pwz84438hmxm79s"; type = "gem"; }; - version = "1.13.0"; + version = "1.15.0"; }; ruby-statistics = { groups = ["default" "test"]; @@ -6022,6 +6012,16 @@ src: }; version = "1.2.0"; }; + table_print = { + groups = ["default" "test"]; + platforms = []; + source = { + remotes = ["https://rubygems.org"]; + sha256 = "1jxmd1yg3h0g27wzfpvq1jnkkf7frwb5wy9m4f47nf4k3wl68rj3"; + type = "gem"; + }; + version = "1.5.7"; + }; tanuki_emoji = { groups = ["default"]; platforms = []; @@ -6463,6 +6463,16 @@ src: }; version = "0.6.7"; }; + uri = { + groups = ["default"]; + platforms = []; + source = { + remotes = ["https://rubygems.org"]; + sha256 = "1vigw7nfszfqgikr6n574k9bfh0rvs74z8xq46rz2zsm8249l8cc"; + type = "gem"; + }; + version = "0.12.1"; + }; uri_template = { groups = ["default"]; platforms = []; @@ -6543,10 +6553,10 @@ src: platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1bwvpkv1iqa8g5cmmllx8fx0nprapzrzfvf1m15rr3wxw5hrbdn8"; + sha256 = "08jc9k4qqazbf5frhdril5084adm90rs1lqbnqq3yfdm2dgaiyhx"; type = "gem"; }; - version = "2.82.0"; + version = "3.2.0"; }; virtus = { dependencies = ["axiom-types" "coercible" "descendants_tracker"]; From e31ddc46e75d079aba15baafea7b80a6bb534f31 Mon Sep 17 00:00:00 2001 From: Yaya Date: Mon, 26 Jun 2023 15:23:19 +0000 Subject: [PATCH 24/35] nixos/gitlab: Add an additional folder to systemd-tmpfiles (cherry picked from commit abc6a0a479d880a0a5b8a29680ad62f6881e5e4a) --- nixos/modules/services/misc/gitlab.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/nixos/modules/services/misc/gitlab.nix b/nixos/modules/services/misc/gitlab.nix index 9c18a2eed1c6..8958d375b2b5 100644 --- a/nixos/modules/services/misc/gitlab.nix +++ b/nixos/modules/services/misc/gitlab.nix @@ -1281,6 +1281,7 @@ in { "d ${gitlabConfig.production.shared.path}/pages 0750 ${cfg.user} ${cfg.group} -" "d ${gitlabConfig.production.shared.path}/registry 0750 ${cfg.user} ${cfg.group} -" "d ${gitlabConfig.production.shared.path}/terraform_state 0750 ${cfg.user} ${cfg.group} -" + "d ${gitlabConfig.production.shared.path}/ci_secure_files 0750 ${cfg.user} ${cfg.group} -" "L+ /run/gitlab/config - - - - ${cfg.statePath}/config" "L+ /run/gitlab/log - - - - ${cfg.statePath}/log" "L+ /run/gitlab/tmp - - - - ${cfg.statePath}/tmp" From ba972a474d43789458e1e6d1aba7bb9fa8b01856 Mon Sep 17 00:00:00 2001 From: Maxine Aubrey Date: Sun, 4 Jun 2023 10:39:14 +0200 Subject: [PATCH 25/35] _1password-gui: 8.10.6 -> 8.10.7 (cherry picked from commit 03951cc24a04b6662083bfc62f7b4188d4e9a73b) --- pkgs/applications/misc/1password-gui/default.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/applications/misc/1password-gui/default.nix b/pkgs/applications/misc/1password-gui/default.nix index 235bb9672722..780686df556d 100644 --- a/pkgs/applications/misc/1password-gui/default.nix +++ b/pkgs/applications/misc/1password-gui/default.nix @@ -9,25 +9,25 @@ let pname = "1password"; - version = if channel == "stable" then "8.10.6" else "8.10.7-11.BETA"; + version = if channel == "stable" then "8.10.7" else "8.10.7-11.BETA"; sources = { stable = { x86_64-linux = { url = "https://downloads.1password.com/linux/tar/stable/x86_64/1password-${version}.x64.tar.gz"; - sha256 = "sha256-wCY94x67z+X8l3wr79+BXuu6/UXJldbVIA67AAD9mj0="; + sha256 = "sha256-5KMAzstoPmNgFejp21R8PcdrmUtkX3qxHYX3rV5JqyE="; }; aarch64-linux = { url = "https://downloads.1password.com/linux/tar/stable/aarch64/1password-${version}.arm64.tar.gz"; - sha256 = "sha256-iLjuudWmkLMuoZSZZo9pRpx0MZludUrGTpTHCTNk4Vo="; + sha256 = "sha256-Tmof+ma1SJMQRSV1T5flLeXfe6W1a2U2mYzi+MrxvJM="; }; x86_64-darwin = { url = "https://downloads.1password.com/mac/1Password-${version}-x86_64.zip"; - sha256 = "sha256-FVj5x1RVBxPsgWhG6R4ykarZdLdJcj6gO5mQy3hHB4M="; + sha256 = "sha256-jtqgJJy1ZhyaEUEafT1ywD529aKGDqc0J3mgYSGVTWU="; }; aarch64-darwin = { url = "https://downloads.1password.com/mac/1Password-${version}-aarch64.zip"; - sha256 = "sha256-ilQP1OF4gydzlLZq3aZzqNbzvacRbruzWS7pVt6DP9g="; + sha256 = "sha256-qLqK6CZcqDfIGX0FzEnAZP3Rkxw8CNtT6sFy8u0IqwM="; }; }; beta = { From a610e3c15dbd2eb8915ee787d7ebb79915f623a3 Mon Sep 17 00:00:00 2001 From: Shane Sveller Date: Mon, 19 Jun 2023 08:18:08 -0500 Subject: [PATCH 26/35] elixir_1_15: init at 1.15.0 (cherry picked from commit 066f8e795274ea81e119ec9f6ab2d557ef76f14d) --- pkgs/development/beam-modules/default.nix | 5 +++++ pkgs/development/interpreters/elixir/1.15.nix | 7 +++++++ pkgs/top-level/all-packages.nix | 2 +- pkgs/top-level/beam-packages.nix | 2 +- 4 files changed, 14 insertions(+), 2 deletions(-) create mode 100644 pkgs/development/interpreters/elixir/1.15.nix diff --git a/pkgs/development/beam-modules/default.nix b/pkgs/development/beam-modules/default.nix index 98d9de9e70b2..421d5f7ffbc0 100644 --- a/pkgs/development/beam-modules/default.nix +++ b/pkgs/development/beam-modules/default.nix @@ -45,6 +45,11 @@ let # BEAM-based languages. elixir = elixir_1_14; + elixir_1_15 = lib'.callElixir ../interpreters/elixir/1.15.nix { + inherit erlang; + debugInfo = true; + }; + elixir_1_14 = lib'.callElixir ../interpreters/elixir/1.14.nix { inherit erlang; debugInfo = true; diff --git a/pkgs/development/interpreters/elixir/1.15.nix b/pkgs/development/interpreters/elixir/1.15.nix new file mode 100644 index 000000000000..0285616f7ea3 --- /dev/null +++ b/pkgs/development/interpreters/elixir/1.15.nix @@ -0,0 +1,7 @@ +{ mkDerivation }: +mkDerivation { + version = "1.15.0"; + sha256 = "sha256-o5MfA0UG8vpnPCH1EYspzcN62yKZQcz5uVUY47hOL9w="; + # https://hexdocs.pm/elixir/1.15.0/compatibility-and-deprecations.html#compatibility-between-elixir-and-erlang-otp + minimumOTPVersion = "24"; +} diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index ba40e4b6e906..267b82d70156 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -16920,7 +16920,7 @@ with pkgs; inherit (beam.interpreters) erlang erlang_25 erlang_24 erlang_23 erlang_odbc erlang_javac erlang_odbc_javac - elixir elixir_1_14 elixir_1_13 elixir_1_12 elixir_1_11 elixir_1_10 + elixir elixir_1_15 elixir_1_14 elixir_1_13 elixir_1_12 elixir_1_11 elixir_1_10 elixir-ls; erlang_nox = beam_nox.interpreters.erlang; diff --git a/pkgs/top-level/beam-packages.nix b/pkgs/top-level/beam-packages.nix index 3210dddfac96..e64a06cc3eaa 100644 --- a/pkgs/top-level/beam-packages.nix +++ b/pkgs/top-level/beam-packages.nix @@ -101,7 +101,7 @@ in # access for example elixir built with different version of Erlang, use # `beam.packages.erlang_24.elixir`. inherit (self.packages.erlang) - elixir elixir_1_14 elixir_1_13 elixir_1_12 elixir_1_11 elixir_1_10 elixir-ls lfe lfe_2_1; + elixir elixir_1_15 elixir_1_14 elixir_1_13 elixir_1_12 elixir_1_11 elixir_1_10 elixir-ls lfe lfe_2_1; } // interpretersAliases; # Helper function to generate package set with a specific Erlang version. From 47f95712770449202455aaaaa99b5797c8f3c755 Mon Sep 17 00:00:00 2001 From: Shane Sveller Date: Mon, 19 Jun 2023 08:47:00 -0500 Subject: [PATCH 27/35] elixir: Locate generate_app.escript via defaulted argument (cherry picked from commit e5df5ac630e2713ea362ef335be4631a23c957fb) --- pkgs/development/interpreters/elixir/1.15.nix | 1 + pkgs/development/interpreters/elixir/generic-builder.nix | 3 ++- 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/development/interpreters/elixir/1.15.nix b/pkgs/development/interpreters/elixir/1.15.nix index 0285616f7ea3..6dada168cc37 100644 --- a/pkgs/development/interpreters/elixir/1.15.nix +++ b/pkgs/development/interpreters/elixir/1.15.nix @@ -4,4 +4,5 @@ mkDerivation { sha256 = "sha256-o5MfA0UG8vpnPCH1EYspzcN62yKZQcz5uVUY47hOL9w="; # https://hexdocs.pm/elixir/1.15.0/compatibility-and-deprecations.html#compatibility-between-elixir-and-erlang-otp minimumOTPVersion = "24"; + escriptPath = "lib/elixir/scripts/generate_app.escript"; } diff --git a/pkgs/development/interpreters/elixir/generic-builder.nix b/pkgs/development/interpreters/elixir/generic-builder.nix index 5f08386c9f51..af6982156103 100644 --- a/pkgs/development/interpreters/elixir/generic-builder.nix +++ b/pkgs/development/interpreters/elixir/generic-builder.nix @@ -16,6 +16,7 @@ , sha256 ? null , rev ? "v${version}" , src ? fetchFromGitHub { inherit rev sha256; owner = "elixir-lang"; repo = "elixir"; } +, escriptPath ? "lib/elixir/generate_app.escript" } @ args: let @@ -38,7 +39,7 @@ stdenv.mkDerivation ({ buildFlags = optional debugInfo "ERL_COMPILER_OPTIONS=debug_info"; preBuild = '' - patchShebangs lib/elixir/generate_app.escript || true + patchShebangs ${escriptPath} || true substituteInPlace Makefile \ --replace "/usr/local" $out From 614a4fa8a48ee9b225fbd92f2bf1874d305f81c4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Felix=20Schr=C3=B6ter?= Date: Tue, 27 Jun 2023 14:17:40 +0200 Subject: [PATCH 28/35] mullvad-browser: 12.0.7 -> 12.5 (cherry picked from commit 06707cf89660ce60e45344d353c552fff1a0e709) --- .../networking/browsers/mullvad-browser/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/browsers/mullvad-browser/default.nix b/pkgs/applications/networking/browsers/mullvad-browser/default.nix index 753005a118f9..d166f044f7be 100644 --- a/pkgs/applications/networking/browsers/mullvad-browser/default.nix +++ b/pkgs/applications/networking/browsers/mullvad-browser/default.nix @@ -78,12 +78,12 @@ let ++ lib.optionals mediaSupport [ ffmpeg ] ); - version = "12.0.7"; + version = "12.5"; sources = { x86_64-linux = fetchurl { url = "https://cdn.mullvad.net/browser/${version}/mullvad-browser-linux64-${version}_ALL.tar.xz"; - hash = "sha256-8TcC39A9VFyhFb+pfefzvwJqXq1yF7C2YDcbCyEa0yo="; + hash = "sha256-RTDFi+vMkzRtDFgv9sP1bfIeWzzXR307aoMhNiT6vRs="; }; }; From be4b3e30c879eeb23952c09ff74a038b18ed0184 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Tue, 27 Jun 2023 18:51:28 +0200 Subject: [PATCH 29/35] [Backport release-23.05] nifi: 1.21.0 -> 1.22.0 (#240157) * nifi: 1.21.0 -> 1.22.0 Fixes CVE-2023-34468 and CVE-2023-34212. Advisories: https://nifi.apache.org/security.html#1.22.0 Release notes: https://cwiki.apache.org/confluence/display/NIFI/Release+Notes#ReleaseNotes-Version1.22.0 (cherry picked from commit bab7f803c813c82337f3a1ee85af1bad818823ba) * Update pkgs/servers/web-apps/nifi/default.nix (cherry picked from commit 3f9b1469d9ff6ce69d42f37e1441ebe2ef110333) --------- Co-authored-by: Thomas Gerbet Co-authored-by: Pol Dellaiera --- pkgs/servers/web-apps/nifi/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/web-apps/nifi/default.nix b/pkgs/servers/web-apps/nifi/default.nix index 87cfe7e21f5a..734ced245056 100644 --- a/pkgs/servers/web-apps/nifi/default.nix +++ b/pkgs/servers/web-apps/nifi/default.nix @@ -2,11 +2,11 @@ stdenv.mkDerivation rec { pname = "nifi"; - version = "1.21.0"; + version = "1.22.0"; src = fetchzip { url = "mirror://apache/nifi/${version}/nifi-${version}-bin.zip"; - sha256 = "sha256-AnDvZ9SV+VFdsP6KoqZIPNinAe2erT/IBY4c6i+2iTQ="; + hash = "sha256-IzTGsD6nL7UrXuHrJc8Dt1C6r137UjT/V4vES2m/8cg="; }; nativeBuildInputs = [ makeWrapper ]; From fb1f1eab356f1ab7e7113f8719b882b3190c7a9c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 13 Jun 2023 18:20:12 +0000 Subject: [PATCH 30/35] maptool: 1.13.0 -> 1.13.1 (cherry picked from commit 8879a43f7a0a95aa00b0b54dfce68ffc7d68aa3c) --- pkgs/games/maptool/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/games/maptool/default.nix b/pkgs/games/maptool/default.nix index 53d8d89d6920..5cba8c224704 100644 --- a/pkgs/games/maptool/default.nix +++ b/pkgs/games/maptool/default.nix @@ -12,11 +12,11 @@ }: let pname = "maptool"; - version = "1.13.0"; + version = "1.13.1"; repoBase = "https://github.com/RPTools/${pname}"; src = fetchurl { url = "${repoBase}/releases/download/${version}/MapTool-${version}.jar"; - hash = "sha256-0jiUYdr2KwMNc8VBgJsEsf4dkrzYfMGwv+jT1RLhUAg="; + hash = "sha256-EHisFvLaqi8VqIdygf0nxohKLL3c/yE5Y6jAcT0B2q0="; }; icon = fetchurl { From 7082245c71860da2edca3a1784d3ac3061843817 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Tue, 27 Jun 2023 21:42:09 +0200 Subject: [PATCH 31/35] nixos-render-docs: add missing head tag to html output (#240181) (cherry picked from commit 03ca5a47c10b16996c5249493835ebfe99624a87) Co-authored-by: pennae --- .../nix/nixos-render-docs/src/nixos_render_docs/manual.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/pkgs/tools/nix/nixos-render-docs/src/nixos_render_docs/manual.py b/pkgs/tools/nix/nixos-render-docs/src/nixos_render_docs/manual.py index 1963989d5365..6a2c28e85d63 100644 --- a/pkgs/tools/nix/nixos-render-docs/src/nixos_render_docs/manual.py +++ b/pkgs/tools/nix/nixos-render-docs/src/nixos_render_docs/manual.py @@ -306,7 +306,8 @@ class ManualHTMLRenderer(RendererMixin, HTMLRenderer): '', '', - ' ', + ' ', + ' ', f' {toc.target.title}', "".join((f'' for style in self._html_params.stylesheets)), From 0663d04ca4793486e3e09a7151242cca1607180f Mon Sep 17 00:00:00 2001 From: Yureka Date: Wed, 10 May 2023 14:27:35 +0200 Subject: [PATCH 32/35] fastnetmon-advanced: link gobgp binaries to /bin (cherry picked from commit b1547b53b576ba2715a54bd0b597c40dd2babcc5) --- pkgs/servers/fastnetmon-advanced/default.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/servers/fastnetmon-advanced/default.nix b/pkgs/servers/fastnetmon-advanced/default.nix index 53c1ef11e25c..2907d890a136 100644 --- a/pkgs/servers/fastnetmon-advanced/default.nix +++ b/pkgs/servers/fastnetmon-advanced/default.nix @@ -40,6 +40,9 @@ stdenv.mkDerivation rec { cp -r opt/fastnetmon/app/bin $out/bin cp -r opt/fastnetmon/libraries $out/libexec/fastnetmon + ln -s $out/libexec/fastnetmon/libraries/gobgp_2_27_0/gobgpd $out/bin/fnm-gobgpd + ln -s $out/libexec/fastnetmon/libraries/gobgp_2_27_0/gobgp $out/bin/fnm-gobgp + addAutoPatchelfSearchPath $out/libexec/fastnetmon/libraries ''; @@ -48,6 +51,8 @@ stdenv.mkDerivation rec { set +o pipefail $out/bin/fastnetmon 2>&1 | grep "Can't open log file" $out/bin/fcli 2>&1 | grep "Please run this tool with root rights" + $out/bin/fnm-gobgp --help 2>&1 | grep "Available Commands" + $out/bin/fnm-gobgpd --help 2>&1 | grep "Application Options" ''; meta = with lib; { From c6a74ebc8bfa168316918acaa8b91af913ef9dad Mon Sep 17 00:00:00 2001 From: Yureka Date: Tue, 27 Jun 2023 21:55:50 +0200 Subject: [PATCH 33/35] fastnetmon-advanced: 2.0.337 -> 2.0.342 (cherry picked from commit 3f2c39a06f16f88776755ff77fb2865c9d718f99) --- pkgs/servers/fastnetmon-advanced/default.nix | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/pkgs/servers/fastnetmon-advanced/default.nix b/pkgs/servers/fastnetmon-advanced/default.nix index 2907d890a136..35c1707a2d5a 100644 --- a/pkgs/servers/fastnetmon-advanced/default.nix +++ b/pkgs/servers/fastnetmon-advanced/default.nix @@ -2,11 +2,11 @@ stdenv.mkDerivation rec { pname = "fastnetmon-advanced"; - version = "2.0.337"; + version = "2.0.342"; src = fetchurl { url = "https://repo.fastnetmon.com/fastnetmon_ubuntu_jammy/pool/fastnetmon/f/fastnetmon/fastnetmon_${version}_amd64.deb"; - hash = "sha256-lYXJ0Q0iUiWk/n/I71BsKnnoRJh3a2EJT3EWV4+pQbM="; + hash = "sha256-H4e7ftuL39xxDYs2zVhgVI8voDBR2TQLWlWSBg3At2s="; }; nativeBuildInputs = [ @@ -40,8 +40,11 @@ stdenv.mkDerivation rec { cp -r opt/fastnetmon/app/bin $out/bin cp -r opt/fastnetmon/libraries $out/libexec/fastnetmon - ln -s $out/libexec/fastnetmon/libraries/gobgp_2_27_0/gobgpd $out/bin/fnm-gobgpd - ln -s $out/libexec/fastnetmon/libraries/gobgp_2_27_0/gobgp $out/bin/fnm-gobgp + readlink usr/sbin/gobgpd + readlink usr/bin/gobgp + + ln -s $(readlink usr/sbin/gobgpd | sed "s:/opt/fastnetmon:$out/libexec/fastnetmon:") $out/bin/fnm-gobgpd + ln -s $(readlink usr/bin/gobgp | sed "s:/opt/fastnetmon:$out/libexec/fastnetmon:") $out/bin/fnm-gobgp addAutoPatchelfSearchPath $out/libexec/fastnetmon/libraries ''; From 431197867f05ea99cbfe328b9c13bd100ecf706f Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Tue, 27 Jun 2023 22:36:52 +0200 Subject: [PATCH 34/35] ferretdb: 1.2.1 -> 1.3.0 (#240192) (cherry picked from commit 338cffa22232ecc34364e284feb995986b4710bf) Co-authored-by: noisersup --- pkgs/servers/nosql/ferretdb/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/servers/nosql/ferretdb/default.nix b/pkgs/servers/nosql/ferretdb/default.nix index c7c0bdfe8704..c2de7c0404d7 100644 --- a/pkgs/servers/nosql/ferretdb/default.nix +++ b/pkgs/servers/nosql/ferretdb/default.nix @@ -5,13 +5,13 @@ buildGoModule rec { pname = "ferretdb"; - version = "1.2.1"; + version = "1.3.0"; src = fetchFromGitHub { owner = "FerretDB"; repo = "FerretDB"; rev = "v${version}"; - sha256 = "sha256-j3gEC4/i+C35P8wf/A9lA5rnUB669/J+GpN/iiyjSlU="; + sha256 = "sha256-V33NeNpQZFUN/aUCaaxnCgIYaVgbAI5L6GZQo8ZMvUI="; }; postPatch = '' @@ -19,7 +19,7 @@ buildGoModule rec { echo nixpkgs > build/version/package.txt ''; - vendorSha256 = "sha256-6sddJcNzPxMarP0/QxpeWF0qXR8wT2kU6N6CtGKG1Tk="; + vendorSha256 = "sha256-QoDNQXZGfUq/t8fiovCv0+N9e4shJGpwS3y/z0YXMi4="; CGO_ENABLED = 0; From 4f412ee740a996c5de7fa034135fcdd10772b278 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Tue, 27 Jun 2023 22:39:14 +0200 Subject: [PATCH 35/35] ferretdb: 1.3.0 -> 1.4.0 (#240193) (cherry picked from commit 40c8a605a936958d2c623e72fcb30e87078b83c6) Co-authored-by: Julien Malka --- pkgs/servers/nosql/ferretdb/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/servers/nosql/ferretdb/default.nix b/pkgs/servers/nosql/ferretdb/default.nix index c2de7c0404d7..7173b90626d6 100644 --- a/pkgs/servers/nosql/ferretdb/default.nix +++ b/pkgs/servers/nosql/ferretdb/default.nix @@ -5,13 +5,13 @@ buildGoModule rec { pname = "ferretdb"; - version = "1.3.0"; + version = "1.4.0"; src = fetchFromGitHub { owner = "FerretDB"; repo = "FerretDB"; rev = "v${version}"; - sha256 = "sha256-V33NeNpQZFUN/aUCaaxnCgIYaVgbAI5L6GZQo8ZMvUI="; + sha256 = "sha256-WSjIUnjMdrRsdygDqQaxNosc/XGrSz/Yx3xauDkQDzU="; }; postPatch = '' @@ -19,7 +19,7 @@ buildGoModule rec { echo nixpkgs > build/version/package.txt ''; - vendorSha256 = "sha256-QoDNQXZGfUq/t8fiovCv0+N9e4shJGpwS3y/z0YXMi4="; + vendorSha256 = "sha256-xWmzTqy0yoOZRvMllsVaRkUmAUWE/Nn4UFyT+0JiCFU="; CGO_ENABLED = 0;