From 9da8edf8648b93099d8e41f08ca003e36adac478 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Philippe=20H=C3=BCrlimann?= Date: Mon, 17 Aug 2026 20:55:58 +0200 Subject: [PATCH 01/61] glib: remove util-linuxMinimal assertion when building for Linux According to 868eb8301916d, this assertion was introduced when glib started requiring this dependency by default due to libmount. However, it still supports building without libmount and without this dependency on Linux and this assertion prohibits doing this using overrides. This changes fixes that and does not affect the builds output. ``` % nix-build -A glib [...] /nix/store/c6p0n1xsd7zj2dnxm2d4m85nx5fgbjbj-glib-2.88.3-bin % git checkout HEAD^ [...] % nix-build -A glib /nix/store/c6p0n1xsd7zj2dnxm2d4m85nx5fgbjbj-glib-2.88.3-bin % ``` --- pkgs/by-name/gl/glib/package.nix | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/pkgs/by-name/gl/glib/package.nix b/pkgs/by-name/gl/glib/package.nix index d504331900ce..45f1a1c85d8a 100644 --- a/pkgs/by-name/gl/glib/package.nix +++ b/pkgs/by-name/gl/glib/package.nix @@ -23,7 +23,7 @@ docutils, gi-docgen, # use util-linuxMinimal to avoid circular dependency (util-linux, systemd, glib) - util-linuxMinimal ? null, + util-linuxMinimal, buildPackages, # this is just for tests (not in the closure of any regular package) @@ -43,8 +43,6 @@ && stdenv.hostPlatform.isLittleEndian == stdenv.buildPlatform.isLittleEndian, }: -assert stdenv.hostPlatform.isLinux -> util-linuxMinimal != null; - let glib-untested = glib.overrideAttrs { doCheck = false; }; # break dependency cycles From e93369306761124f88fcb4bde02fa6a09bc8c8c5 Mon Sep 17 00:00:00 2001 From: 1sixth <1sixth@azc.moe> Date: Mon, 7 Sep 2026 21:54:20 +0800 Subject: [PATCH 02/61] nixos/restic: fix repository initialization checks 1. Add `--no-lock` to `restic cat config`. 2. Run `restic init` only if the exit code is 10 (repository does not exist). --- nixos/modules/services/backup/restic.nix | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/nixos/modules/services/backup/restic.nix b/nixos/modules/services/backup/restic.nix index 8344fc84246a..65031ad0d077 100644 --- a/nixos/modules/services/backup/restic.nix +++ b/nixos/modules/services/backup/restic.nix @@ -478,7 +478,14 @@ in ${pkgs.writeScript "backupPrepareCommand" backup.backupPrepareCommand} ''} ${lib.optionalString backup.initialize '' - ${resticCmd} cat config > /dev/null || ${resticCmd} init + ${resticCmd} cat config --no-lock > /dev/null || { + status=$? + if [ "$status" -eq 10 ]; then + ${resticCmd} init + else + exit "$status" + fi + } ''} ${lib.optionalString (backup.paths != null && backup.paths != [ ]) '' cat ${pkgs.writeText "staticPaths" (lib.concatLines backup.paths)} >> ${filesFromTmpFile} From c392272b10faee8426cc75cb5e76c50ebe92f672 Mon Sep 17 00:00:00 2001 From: jopejoe1 Date: Fri, 11 Sep 2026 14:56:10 +0200 Subject: [PATCH 03/61] lib.licenses: expose mkLicense make it so others can make use of it --- lib/licenses/helpers.nix | 61 ++++++++++++++++++++++++++++++++++++++- lib/licenses/licenses.nix | 35 +--------------------- 2 files changed, 61 insertions(+), 35 deletions(-) diff --git a/lib/licenses/helpers.nix b/lib/licenses/helpers.nix index 37721489f77a..e54ae01b707f 100644 --- a/lib/licenses/helpers.nix +++ b/lib/licenses/helpers.nix @@ -1,7 +1,12 @@ { lib }: let - inherit (lib) all any elem; + inherit (lib) + all + any + elem + optionalAttrs + ; handleComplexProperty = evaluateSubProperty: AND: OR: license: if license.licenseType == "compound" then @@ -184,4 +189,58 @@ rec { "${mkBracket license.license}${license.operator}" else throw "Unknown license type"; + + /** + Create a license. + + # Inputs + + `licenseInfo` + : Attrset of license infromation + + # Type + + ``` + mkLicense :: AttrSet -> AttrSet + ``` + + # Example + :::{.example} + ## `lib.licenses.mkLicense` usage example + + ```nix + mkLicense { shortName = "my-license"; } + => { shortName = "my-license"; free = true; deprecated = false; redistributable = true; licenseType = "simple"; } + ``` + */ + mkLicense = + { + shortName, + # Most of our licenses are Free, explicitly declare unfree additions as such! + free ? true, + deprecated ? false, + spdxId ? null, + url ? null, + fullName ? null, + redistributable ? free, + }@attrs: + { + inherit + shortName + free + deprecated + redistributable + ; + licenseType = "simple"; + } + // optionalAttrs (attrs ? spdxId) { + inherit spdxId; + url = "https://spdx.org/licenses/${spdxId}.html"; + } + // optionalAttrs (attrs ? url) { + inherit url; + } + // optionalAttrs (attrs ? fullName) { + inherit fullName; + }; } diff --git a/lib/licenses/licenses.nix b/lib/licenses/licenses.nix index 6ddb588312fa..da253f7db94b 100644 --- a/lib/licenses/licenses.nix +++ b/lib/licenses/licenses.nix @@ -1,39 +1,6 @@ { lib }: let - inherit (lib) optionalAttrs; - - mkLicense = - lname: - { - shortName ? lname, - # Most of our licenses are Free, explicitly declare unfree additions as such! - free ? true, - deprecated ? false, - spdxId ? null, - url ? null, - fullName ? null, - redistributable ? free, - }@attrs: - { - inherit - shortName - free - deprecated - redistributable - ; - licenseType = "simple"; - } - // optionalAttrs (attrs ? spdxId) { - inherit spdxId; - url = "https://spdx.org/licenses/${spdxId}.html"; - } - // optionalAttrs (attrs ? url) { - inherit url; - } - // optionalAttrs (attrs ? fullName) { - inherit fullName; - }; - + mkLicense = shortName: license: lib.licenses.mkLicense ({ inherit shortName; } // license); in lib.mapAttrs mkLicense ( { From 295b7d18054ea572227bab5da0830253f5b9b4bf Mon Sep 17 00:00:00 2001 From: jopejoe1 Date: Fri, 11 Sep 2026 14:56:10 +0200 Subject: [PATCH 04/61] lib.licenses: improve doc-comments I was missing some understanding about the structure of doc-comments as I wrote these improved thes with a better understanding of how those get rendered. --- lib/licenses/helpers.nix | 132 +++++++++++++++++++++++-------------- lib/licenses/operators.nix | 84 +++++++++++++---------- 2 files changed, 131 insertions(+), 85 deletions(-) diff --git a/lib/licenses/helpers.nix b/lib/licenses/helpers.nix index 37721489f77a..b0a4b492df8c 100644 --- a/lib/licenses/helpers.nix +++ b/lib/licenses/helpers.nix @@ -22,22 +22,31 @@ rec { /** Evaluate a license expression for a given predicate. - # Example + # Inputs + + `predicate` + : Predicate which should get used for checking licenses + + `permissive` + : Whether to apply checks permissive or reciprocal + + `license` + : License expression which should be evaluated - ```nix - evaluateProperty (x: x.free) true (with lib.licenses; AND [ ncsa (WITH asl20 llvm-exception) ]) - ``` # Type ``` - evaluateProperty :: Function -> Bool -> AttrSet -> Bool + evaluateProperty :: (a -> Bool) -> Bool -> { [String] :: a } -> Bool ``` - # Arguments + # Example + :::{.example} + ## `lib.licenses.evaluateProperty usage example` - - [predicate] checks for each license included in the license expression - - [permissive] whether to apply checks permissive or reciprocal - - [license] license expression to check + ```nix + evaluateProperty (x: x.free) true (with lib.licenses; AND [ ncsa (WITH asl20 llvm-exception) ]) + => true + ``` */ evaluateProperty = predicate: permissive: @@ -53,22 +62,31 @@ rec { Evaluate a license expression for a given property name. The property must be defined as a boolean attribute of all licenses passed. - # Example + # Inputs + + `name` + : Name of the Attribute which should be checked + + `permissive` + : Whether to apply checks permissive or reciprocal + + `license` + : License expression which should be evaluated - ```nix - evaluateNamedProperty "deprecated" true (with lib.licenses; AND [ ncsa (WITH asl20 llvm-exception) ]) - ``` # Type ``` - evaluateProperty :: String -> Bool -> AttrSet -> Bool + evaluateNamedProperty :: String -> Bool -> AttrSet -> Bool ``` - # Arguments + # Example + :::{.example} + ## `lib.licenses.evaluateNamedProperty` usage example - - [name] name of the attribute to check - - [permissive] whether to apply checks permissive or reciprocal - - [license] license expression to check + ```nix + evaluateNamedProperty "deprecated" true (with lib.licenses; AND [ ncsa (WITH asl20 llvm-exception) ]) + => false + ``` */ evaluateNamedProperty = name: permissive: @@ -83,12 +101,10 @@ rec { /** Check whether a license expression is free. - # Example + # Inputs - ```nix - isFree (with lib.licenses; (AND [ ncsa (WITH asl20 llvm-exception) ])) - => true - ``` + `license` + : License expression which should be evaluated # Type @@ -96,21 +112,24 @@ rec { isFree :: AttrSet -> Bool ``` - # Arguments + # Example + :::{.example} + ## `lib.licenses.isFree` usage example - - [license] License expression to check if free + ```nix + isFree (with lib.licenses; (AND [ ncsa (WITH asl20 llvm-exception) ])) + => true + ``` */ isFree = evaluateNamedProperty "free" true; /** Check whether a license expression is redistributable. - # Example + # Inputs - ```nix - isRedistributable (with lib.licenses; (AND [ ncsa (WITH asl20 llvm-exception) ])) - => true - ``` + `license` + : License expression which should be evaluated # Type @@ -118,44 +137,52 @@ rec { isRedistributable :: AttrSet -> Bool ``` - # Arguments + # Example + :::{.example} + ## `lib.licenses.isRedistributable` usage example - - [license] License expression to check if redistributable + ```nix + isRedistributable (with lib.licenses; (AND [ ncsa (WITH asl20 llvm-exception) ])) + => true + ``` */ isRedistributable = evaluateNamedProperty "redistributable" true; /** Check whether any of the given licenses is required in the license expression. + # Inputs + + `licenses` + : List of licenses which are tested + + `license` + : License expression which should be evaluated + + # Type + + ``` + containsLicenses :: [AttrSet] -> AttrSet -> Bool + ``` + # Example + :::{.example} + ## `lib.licenses.containsLicenses` usage example ```nix containsLicenses [ lib.licenses.asl20 ] (with lib.licenses; (AND [ ncsa (WITH asl20 llvm-exception) ])) => true ``` - - # Type - - ``` - containsLicenses :: List -> AttrSet -> Bool - ``` - - # Arguments - - - [licenses] List of licenses to look - - [license] License expression to check */ containsLicenses = licenses: evaluateProperty (x: elem x licenses) false; /** Convert a license expression to an SPDX license expression string. - # Example + # Inputs - ```nix - toSPDX (with lib.licenses; AND [ ncsa (WITH asl20 llvm-exception) ]) - => "NCSA AND (Apache-2.0 WITH LLVM-exception)" - ``` + `license` + : License expression which to convert to an spdx expression # Type @@ -163,9 +190,14 @@ rec { toSPDX :: AttrSet -> String ``` - # Arguments + # Example + :::{.example} + ## `lib.licenses.toSPDX` usage example - - [license] License expression which to convert to spdx expression + ```nix + toSPDX (with lib.licenses; AND [ ncsa (WITH asl20 llvm-exception) ]) + => "NCSA AND (Apache-2.0 WITH LLVM-exception)" + ``` */ toSPDX = license: diff --git a/lib/licenses/operators.nix b/lib/licenses/operators.nix index db7cc25d37c6..b5326473b6da 100644 --- a/lib/licenses/operators.nix +++ b/lib/licenses/operators.nix @@ -3,22 +3,25 @@ This should be used when there is a choice of which license expression to use. This is a disjunctive binary "OR" operator. + # Inputs + + `licenses` + : Possible licenses to choose from + + # Type + + ``` + OR :: [AttrSet] -> AttrSet + ``` + # Example + :::{.example} + ## `lib.licenses.OR` usage example ```nix OR [ lib.licenses.mit lib.licenses.asl20 ] => { licenseType = "compound"; operator = "OR"; licenses = [ lib.licenses.mit lib.licenses.asl20 ] }; ``` - - # Type - - ``` - OR :: List -> AttrSet - ``` - - # Arguments - - - [licenses] Possible licenses to choose from */ OR = licenses: { licenseType = "compound"; @@ -30,22 +33,25 @@ Create a compound licenses where the user needs to follow both licenses, eqivialent of spdx `and` modifier. + # Inputs + + `licenses` + : Licenses required to use + + # Type + + ``` + AND :: [AttrsSet] -> AttrSet + ``` + # Example + :::{.example} + ## `lib.licenses.AND` usage example ```nix AND [ lib.licenses.mit lib.licenses.asl20 ] => { licenseType = "compound"; operator = "AND"; licenses = [ lib.licenses.mit lib.licenses.asl20 ] }; ``` - - # Type - - ``` - AND :: List -> AttrSet - ``` - - # Arguments - - - [licenses] Licenses required to use */ AND = licenses: { licenseType = "compound"; @@ -57,12 +63,13 @@ Create a licenses exception where a license has a license exception, eqivialent of spdx `with` modifier. - # Example + # Inputs - ```nix - WITH lib.licenses.lgpl21Only lib.licenses.ocamlLgplLinkingException - => { licenseType = "exception"; operator = "WITH"; license = lib.licenses.lgpl21Only; exception = lib.licenses.ocamlLgplLinkingException; }; - ``` + `license` + : License to which the exception applies + + `exception` + : Exception to apply # Type @@ -70,10 +77,14 @@ WITH :: AttrSet -> AttrSet -> AttrSet ``` - # Arguments + # Example + :::{.example} + ## `lib.licenses.WITH` usage example - - [license] License to which the exception applies - - [exception] Exception to apply + ```nix + WITH lib.licenses.lgpl21Only lib.licenses.ocamlLgplLinkingException + => { licenseType = "exception"; operator = "WITH"; license = lib.licenses.lgpl21Only; exception = lib.licenses.ocamlLgplLinkingException; }; + ``` */ WITH = license: exception: { licenseType = "exception"; @@ -85,12 +96,10 @@ Create a licenses which can be upgraded to any later version of itself, eqivialent of spdx `+` modifier - # Example + # Inputs - ```nix - PLUS lib.licenses.eupl11 - => { licenseType = "plus"; operator = "+"; license = lib.licenses.eupl11; }; - ``` + `license` + : License to which apply an exception # Type @@ -98,9 +107,14 @@ PLUS :: AttrSet -> AttrSet ``` - # Arguments + # Example + :::{.example} + ## `lib.licenses.PLUS` usage example - - [license] License to wich apply an exception + ```nix + PLUS lib.licenses.eupl11 + => { licenseType = "plus"; operator = "+"; license = lib.licenses.eupl11; }; + ``` */ PLUS = license: { licenseType = "plus"; From 6a259ddee155a4b962d4fd21b860a76f8fd9ad6e Mon Sep 17 00:00:00 2001 From: Atemu Date: Fri, 18 Sep 2026 18:05:22 +0200 Subject: [PATCH 05/61] aw-watcher-steam: init at 0-unstable-2025-06-16 --- pkgs/by-name/aw/aw-watcher-steam/package.nix | 44 ++++++++++++++++++++ 1 file changed, 44 insertions(+) create mode 100644 pkgs/by-name/aw/aw-watcher-steam/package.nix diff --git a/pkgs/by-name/aw/aw-watcher-steam/package.nix b/pkgs/by-name/aw/aw-watcher-steam/package.nix new file mode 100644 index 000000000000..791bd9909a21 --- /dev/null +++ b/pkgs/by-name/aw/aw-watcher-steam/package.nix @@ -0,0 +1,44 @@ +{ + lib, + python3Packages, + fetchFromGitHub, + unstableGitUpdater, +}: + +python3Packages.buildPythonApplication (finalAttrs: { + pname = "aw-watcher-steam"; + version = "0-unstable-2025-06-16"; + pyproject = true; + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "Edwardsoen"; + repo = "aw-watcher-steam"; + rev = "55ea988994acfbf729fa43612f2057a310c1cc8f"; + hash = "sha256-wd+q83MlgMeiYSHQwMtszwnDrkaDN3yVkV/P5HsU89U="; + }; + + build-system = [ + python3Packages.poetry-core + ]; + + dependencies = with python3Packages; [ + aw-client + requests + ]; + + pythonImportsCheck = [ + "aw_watcher_steam" + ]; + + passthru.updateScript = unstableGitUpdater { }; + + meta = { + homepage = "https://github.com/Edwardsoen/aw-watcher-steam"; + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ + atemu + ]; + mainProgram = "aw-watcher-steam"; + }; +}) From bf1b9393620b98d45bd2e1f7e568385ddeacc474 Mon Sep 17 00:00:00 2001 From: mtnash Date: Wed, 26 Aug 2026 08:48:21 -0400 Subject: [PATCH 06/61] nixos/discourse: update config to match v2026.8.0 --- nixos/modules/services/web-apps/discourse.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/nixos/modules/services/web-apps/discourse.nix b/nixos/modules/services/web-apps/discourse.nix index 7ad8705ae658..e5e61b73bac1 100644 --- a/nixos/modules/services/web-apps/discourse.nix +++ b/nixos/modules/services/web-apps/discourse.nix @@ -644,8 +644,8 @@ in s3_role_arn = null; s3_role_session_name = null; - max_user_api_reqs_per_minute = 20; - max_user_api_reqs_per_day = 2880; + max_user_api_reqs_per_minute = 50; + max_user_api_reqs_per_day = 4000; max_admin_api_reqs_per_minute = 60; max_reqs_per_ip_per_minute = 200; max_reqs_per_ip_per_10_seconds = 50; From 231356700c77e27ef5750b325aa7c56b64d35f86 Mon Sep 17 00:00:00 2001 From: mtnash Date: Wed, 26 Aug 2026 09:18:27 -0400 Subject: [PATCH 07/61] discourse: 2026.7.1 -> 2026.8.0 Upstream changes: https://releases.discourse.org/changelog/custom?end=v2026.8.0&start=v2026.7.1 Changes - fix patch to safe_exec, no change in function - patch all instances of PrecompiledBundle to store their output in frontend/ instead of tmp/ so it can be properly used. this replaces the previous patch with a similar function, that was specific to the asset_processor.rb code - fix update.py, fetchPnpmDeps no longer outputs the correct hash in errors unless the hash is set to an empty string. - automated updates (update.py) to main packages - automated updates (update.py) to plugins [discourse-prometheus] --- pkgs/servers/web-apps/discourse/default.nix | 10 +-- .../include-precompiled-bundles.patch | 26 +++++++ .../plugins/discourse-prometheus/default.nix | 4 +- .../discourse/prebuild-asset-processor.patch | 13 ---- .../web-apps/discourse/rubyEnv/Gemfile.lock | 76 +++++++++---------- .../web-apps/discourse/rubyEnv/gemset.nix | 48 ++++++------ .../discourse/safe-exec-from-nix-store.patch | 4 +- pkgs/servers/web-apps/discourse/update.py | 19 ++++- 8 files changed, 115 insertions(+), 85 deletions(-) create mode 100644 pkgs/servers/web-apps/discourse/include-precompiled-bundles.patch delete mode 100644 pkgs/servers/web-apps/discourse/prebuild-asset-processor.patch diff --git a/pkgs/servers/web-apps/discourse/default.nix b/pkgs/servers/web-apps/discourse/default.nix index b66d9ddfa942..d864f478c59f 100644 --- a/pkgs/servers/web-apps/discourse/default.nix +++ b/pkgs/servers/web-apps/discourse/default.nix @@ -54,13 +54,13 @@ }: let - version = "2026.7.1"; + version = "2026.8.0"; src = fetchFromGitHub { owner = "discourse"; repo = "discourse"; tag = "v${version}"; - hash = "sha256-sGygaOCygtDVjg8uBGdDVaRouUKib8aAukaBAY8aQ9w="; + hash = "sha256-UUDPZVBQXG6kfW8+TFFDHsNMdH8WLxsgva4jSdZWsC8="; }; pnpm = pnpm_10; @@ -350,7 +350,7 @@ let pname = "discourse-assets"; inherit version src pnpm; fetcherVersion = 3; - hash = "sha256-T0qcUYHqpjeGlyozcaiVI/Art0zh2PLyuMzbquhfe/o="; + hash = "sha256-fm6hboG2Bjq0HUnbwdLiC1FpoWRZvq+1bN5SupQ2P2k="; }; nativeBuildInputs = runtimeDeps ++ [ @@ -392,7 +392,7 @@ let # because we fail to copy tmp/ (the default directory where the asset processor is cached, # see notes in the discourse `installPhase`) we need to change the directory to something under # frontend/ which is moved over as expected. - ./prebuild-asset-processor.patch + ./include-precompiled-bundles.patch # safe_exec.rb, which is used to execute ImageMagick among other things, restricts executable paths to standard FHS paths # which breaks on nix. this patch adds the entire /nix/store to allowed paths, which is sub-optimal but @@ -507,7 +507,7 @@ let # because we fail to copy tmp/ (the default directory where the asset processor is cached, # see notes in the discourse `installPhase`) we need to change the directory to something under # frontend/ which is moved over as expected. - ./prebuild-asset-processor.patch + ./include-precompiled-bundles.patch # safe_exec.rb, which is used to execute ImageMagick among other things, restricts executable paths to standard FHS paths # which breaks on nix. this patch adds the entire /nix/store to allowed paths, which is sub-optimal but diff --git a/pkgs/servers/web-apps/discourse/include-precompiled-bundles.patch b/pkgs/servers/web-apps/discourse/include-precompiled-bundles.patch new file mode 100644 index 000000000000..962398f06eb9 --- /dev/null +++ b/pkgs/servers/web-apps/discourse/include-precompiled-bundles.patch @@ -0,0 +1,26 @@ +diff --git a/lib/asset_processor.rb b/lib/asset_processor.rb +index 0c602a85220..be1e22061b0 100644 +--- a/lib/asset_processor.rb ++++ b/lib/asset_processor.rb +@@ -5,7 +5,7 @@ class AssetProcessor + + BUNDLE = + PrecompiledBundle.new( +- dir: "tmp/asset-processor", ++ dir: "frontend/asset-processor.build", + filename_prefix: "asset-processor", + dependency_globs: %w[ + node_modules/.pnpm/lock.yaml +diff --git a/lib/pretty_text.rb b/lib/pretty_text.rb +index 6f176324799..9815f579212 100644 +--- a/lib/pretty_text.rb ++++ b/lib/pretty_text.rb +@@ -54,7 +54,7 @@ module PrettyText + + CORE_BUNDLE = + PrecompiledBundle.new( +- dir: "tmp/pretty-text-processor", ++ dir: "frontend/pretty-text-processor.build", + filename_prefix: "pretty-text", + dependency_globs: + %w[ diff --git a/pkgs/servers/web-apps/discourse/plugins/discourse-prometheus/default.nix b/pkgs/servers/web-apps/discourse/plugins/discourse-prometheus/default.nix index aa9437d33559..1f75f3cc44b9 100644 --- a/pkgs/servers/web-apps/discourse/plugins/discourse-prometheus/default.nix +++ b/pkgs/servers/web-apps/discourse/plugins/discourse-prometheus/default.nix @@ -10,8 +10,8 @@ mkDiscoursePlugin { src = fetchFromGitHub { owner = "discourse"; repo = "discourse-prometheus"; - rev = "ce51879d2c487cf74ca08d6d83d6ccb41cb28738"; - sha256 = "sha256-OhzWC8dgfwhre1HF5sjqXAeIJd3wuknzb12RMCz3+4Y="; + rev = "8850b2ee1acb69266f8697c3741f34cca80cad61"; + sha256 = "sha256-7koWRb0ifMwHdtpjV6X4yTiKmK7zVCdIJlewkY5Vgzs="; }; patches = [ diff --git a/pkgs/servers/web-apps/discourse/prebuild-asset-processor.patch b/pkgs/servers/web-apps/discourse/prebuild-asset-processor.patch deleted file mode 100644 index 774907ceaad2..000000000000 --- a/pkgs/servers/web-apps/discourse/prebuild-asset-processor.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/lib/asset_processor.rb b/lib/asset_processor.rb -index bacb376c856..11d7d7edd32 100644 ---- a/lib/asset_processor.rb -+++ b/lib/asset_processor.rb -@@ -3,7 +3,7 @@ - class AssetProcessor - BASE_COMPILER_VERSION = 113 - -- PROCESSOR_DIR = "tmp/asset-processor" -+ PROCESSOR_DIR = "frontend/asset-processor.build" - LOCK_FILE = "#{PROCESSOR_DIR}/build.lock" - - CACHE_DEPENDENCY_GLOBS = %w[ diff --git a/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile.lock b/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile.lock index d2cdb9f438e7..0e3517db3815 100644 --- a/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile.lock +++ b/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile.lock @@ -5,7 +5,7 @@ PATH activesupport colored2 i18n - markbridge (>= 0.3.1) + markbridge (>= 0.4.0) migrations-core pg zeitwerk @@ -53,16 +53,16 @@ GEM remote: https://rubygems.org/ specs: Ascii85 (2.0.1) - actionmailer (8.0.5) - actionpack (= 8.0.5) - actionview (= 8.0.5) - activejob (= 8.0.5) - activesupport (= 8.0.5) + actionmailer (8.0.5.1) + actionpack (= 8.0.5.1) + actionview (= 8.0.5.1) + activejob (= 8.0.5.1) + activesupport (= 8.0.5.1) mail (>= 2.8.0) rails-dom-testing (~> 2.2) - actionpack (8.0.5) - actionview (= 8.0.5) - activesupport (= 8.0.5) + actionpack (8.0.5.1) + actionview (= 8.0.5.1) + activesupport (= 8.0.5.1) nokogiri (>= 1.8.5) rack (>= 2.2.4) rack-session (>= 1.0.1) @@ -70,8 +70,8 @@ GEM rails-dom-testing (~> 2.2) rails-html-sanitizer (~> 1.6) useragent (~> 0.16) - actionview (8.0.5) - activesupport (= 8.0.5) + actionview (8.0.5.1) + activesupport (= 8.0.5.1) builder (~> 3.1) erubi (~> 1.11) rails-dom-testing (~> 2.2) @@ -80,16 +80,16 @@ GEM actionview (>= 6.0.a) active_model_serializers (0.8.4) activemodel (>= 3.0) - activejob (8.0.5) - activesupport (= 8.0.5) + activejob (8.0.5.1) + activesupport (= 8.0.5.1) globalid (>= 0.3.6) - activemodel (8.0.5) - activesupport (= 8.0.5) - activerecord (8.0.5) - activemodel (= 8.0.5) - activesupport (= 8.0.5) + activemodel (8.0.5.1) + activesupport (= 8.0.5.1) + activerecord (8.0.5.1) + activemodel (= 8.0.5.1) + activesupport (= 8.0.5.1) timeout (>= 0.4.0) - activesupport (8.0.5) + activesupport (8.0.5.1) base64 benchmark (>= 0.3) bigdecimal @@ -318,7 +318,7 @@ GEM simpleidn (~> 0.2) jwt (2.10.1) base64 - landlock (0.3) + landlock (0.4.1) language_server-protocol (3.17.0.5) libv8-node (24.12.0.1) libv8-node (24.12.0.1-aarch64-linux) @@ -355,7 +355,7 @@ GEM net-imap net-pop net-smtp - markbridge (0.3.1) + markbridge (0.4.0) matrix (0.4.3) maxminddb (0.1.22) memory_profiler (1.1.0) @@ -370,7 +370,7 @@ GEM mime-types-data (3.2026.0414) mini_mime (1.1.5) mini_portile2 (2.8.9) - mini_racer (0.21.4) + mini_racer (0.22.0) libv8-node (~> 24.12.0.1) mini_scheduler (0.20.0) sidekiq (>= 6.5, < 9.0) @@ -547,9 +547,9 @@ GEM rails_multisite (7.0.0) activerecord (>= 7.1) railties (>= 7.1) - railties (8.0.5) - actionpack (= 8.0.5) - activesupport (= 8.0.5) + railties (8.0.5.1) + actionpack (= 8.0.5.1) + activesupport (= 8.0.5.1) irb (~> 1.13) rackup (>= 1.0.0) rake (>= 12.2) @@ -563,7 +563,7 @@ GEM rb-fsevent (0.11.2) rb-inotify (0.11.1) ffi (~> 1.0) - rb_sys (0.9.128) + rb_sys (0.9.130) rake-compiler-dock (= 1.12.0) rbs (4.0.2) logger @@ -1007,15 +1007,15 @@ DEPENDENCIES CHECKSUMS Ascii85 (2.0.1) sha256=15cb5d941808543cbb9e7e6aea3c8ec3877f154c3461e8b3673e97f7ecedbe5a - actionmailer (8.0.5) sha256=7918fac842cfe985ed21692f3d212c914a0c816e30e6fa68633177bb22f38561 - actionpack (8.0.5) sha256=c9de868975dd124a0956499140bd5e63c367865deca01292df7c3195c8da4b35 - actionview (8.0.5) sha256=6d0fa9e63df0cf2729b1f54d0988336c149eb2bbc6049f4c2834d7b62f351413 + actionmailer (8.0.5.1) sha256=c3d2b3f96e1989ea25f51699786a97fcb2536eb7abfc2a667cb8f2376ec08403 + actionpack (8.0.5.1) sha256=a5595c9d824d68884ddc4d3965ab78c897760d3752e190df7efe897371caa1eb + actionview (8.0.5.1) sha256=472a108b9cc2295c4ac3ff09b028045e619875801f48c556f0085210b9cb1440 actionview_precompiler (0.4.0) sha256=33b6bd6ec4c1b856e02fdf5f6512c9eb4a92ac1c0545e941b3e354b7d540ed1c active_model_serializers (0.8.4) sha256=7350e3d3b6a5946bbec033241d908013cc85ff4d584230e6aa074225547c754c - activejob (8.0.5) sha256=2dabe5c3bfe284aba4687c52b930564335435dde3a60b047821f9d3bd0d2ea10 - activemodel (8.0.5) sha256=c796813d46dc1373f4c6c0ec91dfc520b53683ea773c3b3f9a12c4b3eb145bc2 - activerecord (8.0.5) sha256=89b261b6cd910c9431cf2475f3f6e5e2f5ce589805043a33ef2b004376a129e6 - activesupport (8.0.5) sha256=37f213ff6a37cf3fadfa1a28c1a9678e2cb73b59bb9ebd0eeeca653cccadcb23 + activejob (8.0.5.1) sha256=142407a21b6c3cbc6ddd92ca111ac18ea5c40298eb94d81845cd897a072a6880 + activemodel (8.0.5.1) sha256=559be32aa9c40db7a3ee0aef926d4508a9ebd22f96f7276c11326d21a7dff4a4 + activerecord (8.0.5.1) sha256=9252968fce404d75eb17092498a440d472167f2f8deee32b4658d6552b1eeea7 + activesupport (8.0.5.1) sha256=329a4280c4fbcfcf338ae2cb9df28b0b14527929dba105e10b3604516d998710 addressable (2.9.0) sha256=7fdf6ac3660f7f4e867a0838be3f6cf722ace541dd97767fa42bc6cfa980c7af afm (1.0.0) sha256=5bd4d6f6241e7014ef090985ec6f4c3e9745f6de0828ddd58bc1efdd138f4545 annotaterb (4.20.0) sha256=871b2e898d1d60c23bdc59b72a5b840678a56355bf5f6fdeb8c79d317ff98bf7 @@ -1127,7 +1127,7 @@ CHECKSUMS json_completer (1.2.0) sha256=4665749172634eccb208c562eb59ea81dd7a612a1fa9a36df441ac473ff177b1 json_schemer (2.5.0) sha256=2f01fb4cce721a4e08dd068fc2030cffd0702a7f333f1ea2be6e8991f00ae396 jwt (2.10.1) sha256=e6424ae1d813f63e761a04d6284e10e7ec531d6f701917fadcd0d9b2deaf1cc5 - landlock (0.3) sha256=841ae1ef1318082a485ae919b6a481ceb9c2d3ac9294ada27e2a3c529446b23c + landlock (0.4.1) sha256=95c9b119ff831fae35756ddcd5e9d5f99b9705be71f37a0972f86c825b78b14f language_server-protocol (3.17.0.5) sha256=fd1e39a51a28bf3eec959379985a72e296e9f9acfce46f6a79d31ca8760803cc libv8-node (24.12.0.1) sha256=d93d23b861bfe5de3ba829e34a142402fb83b4c3592dd58d9ac4e027588d739a libv8-node (24.12.0.1-aarch64-linux) sha256=22bd0246cde85d70c88cf772727ac3677a20ac1d169105f82efe5f1f7c39f755 @@ -1148,7 +1148,7 @@ CHECKSUMS lru_redux (1.1.0) sha256=ee71d0ccab164c51de146c27b480a68b3631d5b4297b8ffe8eda1c72de87affb lz4-ruby (0.3.3) sha256=011be5ee230cfddc8308d4e2e0b05300c7bc755a887de799377ca6c5b6aede89 mail (2.9.0) sha256=6fa6673ecd71c60c2d996260f9ee3dd387d4673b8169b502134659ece6d34941 - markbridge (0.3.1) sha256=a36dff4e79e666fe7f944d4a806f507212191b80d22878ab3ee9008d9df975a3 + markbridge (0.4.0) sha256=27645fd47489d2fd42068153fa471b7e5231dd8dabb31c1bf38c88aa37535b12 matrix (0.4.3) sha256=a0d5ab7ddcc1973ff690ab361b67f359acbb16958d1dc072b8b956a286564c5b maxminddb (0.1.22) sha256=50933be438fbed9dceabef4163eab41884bd8830d171fdb8f739bee769c4907e memory_profiler (1.1.0) sha256=79a17df7980a140c83c469785905409d3027ca614c42c086089d128b805aa8f8 @@ -1163,7 +1163,7 @@ CHECKSUMS mime-types-data (3.2026.0414) sha256=461c4c655373a44bd6c5fe54bcf5b7776026ea96e808144b1ec465c4b99148cc mini_mime (1.1.5) sha256=8681b7e2e4215f2a159f9400b5816d85e9d8c6c6b491e96a12797e798f8bccef mini_portile2 (2.8.9) sha256=0cd7c7f824e010c072e33f68bc02d85a00aeb6fce05bb4819c03dfd3c140c289 - mini_racer (0.21.4) sha256=ccf5e37288097f079d84449e111cd4e2170b37f3b80b30900766ffa6df4632db + mini_racer (0.22.0) sha256=52e4c1797bcb01be550d8317764ac5ca8aa96b37f8f72dec6e090db99847ae30 mini_scheduler (0.20.0) sha256=bd8948228bf4a48a603a8e20de850d16b68295413d8651c8c05288f4c6997b05 mini_sql (1.6.0) sha256=5296637f6a4af5bb43e06788037e9a2968ff9c8eb65928befcba8cb41f42d6ee mini_suffix (0.3.3) sha256=8d1d33f92f69a2247c9b7d27173235da90479d955cdb863b63a7f53843b722e7 @@ -1240,14 +1240,14 @@ CHECKSUMS rails-html-sanitizer (1.7.0) sha256=28b145cceaf9cc214a9874feaa183c3acba036c9592b19886e0e45efc62b1e89 rails_failover (2.3.0) sha256=eed6ea0674fd6f9f6b070ad297ad2ead121ecf9202920f6068b6a4f29d9491c9 rails_multisite (7.0.0) sha256=7aacf364ed86d2bee73fb679cbfe6c343ce89067b9746b3d5857fffc57f036f2 - railties (8.0.5) sha256=ad98c6e9a096b7e8cf63c70872b60ec6c1d4152be2a4ffa63483ec02a837a9d5 + railties (8.0.5.1) sha256=da1958e1d9dab04691a2f8721b3ff7fab323715d37f103c19972dedfd644d5c7 rainbow (3.1.1) sha256=039491aa3a89f42efa1d6dec2fc4e62ede96eb6acd95e52f1ad581182b79bc6a raindrops (0.20.1) sha256=aa0eb9ff6834f2d9e232ba688bd49cb30be893bc5a3452e74722c94c1fab4730 rake (13.4.2) sha256=cb825b2bd5f1f8e91ca37bddb4b9aaf345551b4731da62949be002fa89283701 rake-compiler-dock (1.12.0) sha256=f13205c2738f3d2053afcd03491a9e4541b22a59a0bfc53fc8bc883bd8188023 rb-fsevent (0.11.2) sha256=43900b972e7301d6570f64b850a5aa67833ee7d87b458ee92805d56b7318aefe rb-inotify (0.11.1) sha256=a0a700441239b0ff18eb65e3866236cd78613d6b9f78fea1f9ac47a85e47be6e - rb_sys (0.9.128) sha256=9ab81f4d6d4e1895de18762232362d1264475aa7035756b50441e442130538fd + rb_sys (0.9.130) sha256=7d486d99c1da02635515deaf9860fc5aea90bb4ab2589b2deec7fdc7d3548615 rbs (4.0.2) sha256=af75671e66cd03434cc546622741ebf83f6197ec4328375805306330bf78ef25 rbtrace (0.5.4) sha256=8279e40076530f0301e255d0669cfe0d7d31ef872d1ae475c486e5a1199b757b rchardet (1.10.2) sha256=e041cb195f464dc10e49ab130f78c8b5956cd9a4f4f6df84e0c183b87c135f33 diff --git a/pkgs/servers/web-apps/discourse/rubyEnv/gemset.nix b/pkgs/servers/web-apps/discourse/rubyEnv/gemset.nix index 9e781f718be7..13be53ad0101 100644 --- a/pkgs/servers/web-apps/discourse/rubyEnv/gemset.nix +++ b/pkgs/servers/web-apps/discourse/rubyEnv/gemset.nix @@ -12,10 +12,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0qc5ycibnxricdlgmrihds0hqjli5hhksbv947nqbsfg8b4gl63r"; + sha256 = "00w4q1p3gwmqgik2mz5bnxp57cpwjxm7i68nyljym28rdvwv7ln3"; type = "gem"; }; - version = "8.0.5"; + version = "8.0.5.1"; }; actionpack = { dependencies = [ @@ -37,10 +37,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0dabvb49acbwvy91587cbn36ghv3bsyl14a9aq4ll4nxfn4qdpn9"; + sha256 = "1sx1r9qp72gygvgr1qaj6w6pd5y8g2mnafadvi6qhs2dhafmqnd5"; type = "gem"; }; - version = "8.0.5"; + version = "8.0.5.1"; }; actionview = { dependencies = [ @@ -58,10 +58,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "04ql6lpvdmrl5169y166pfr9w53c6f40jkgmn4ljgkzh7pkaj3vd"; + sha256 = "0h0lrfwi0lh8y1bcaj0zh1srhqay0hlb02gzqd55qaf2kj5i0aj7"; type = "gem"; }; - version = "8.0.5"; + version = "8.0.5.1"; }; actionview_precompiler = { dependencies = [ "actionview" ]; @@ -94,10 +94,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "047asb83p78zh93v0q1svrfl6da3aqqbjlkwd2jap172pz1ybard"; + sha256 = "1038583pm2fd8lcdi57bk01c99cfq4d13jljvmnvqg3c3fi0f90l"; type = "gem"; }; - version = "8.0.5"; + version = "8.0.5.1"; }; activemodel = { dependencies = [ "activesupport" ]; @@ -110,10 +110,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1hjv2kmv7i0jk8zkng3pxa1kdd90qpgr3v60qvs764yw8qyq35n7"; + sha256 = "197lvykj2v9j25n2gxwn5z9fpa888mnr5vqaxsivf3f4m4mf76sm"; type = "gem"; }; - version = "8.0.5"; + version = "8.0.5.1"; }; activerecord = { dependencies = [ @@ -130,10 +130,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1ri9l5v4601bxwrkl105k1ccxxg2wpvg6x94rwqr834irnv63cl9"; + sha256 = "19zf3qmmbmjq8qmy7vld5xzicwnl82j9h9092zmpaka0rs7rcllj"; type = "gem"; }; - version = "8.0.5"; + version = "8.0.5.1"; }; activesupport = { dependencies = [ @@ -159,10 +159,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "08ybmp63qrfaxq7bv7mvb4xvfb4fcylw2a0szankzkrpdbzi7wip"; + sha256 = "0447k5nm211n1ghhb8fv55wm450bigr9vjz2i8rwzkzvqj0456ij"; type = "gem"; }; - version = "8.0.5"; + version = "8.0.5.1"; }; addressable = { dependencies = [ "public_suffix" ]; @@ -1497,10 +1497,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0g5j8sa54g1agsiav54jmk9w5fffh6jbc6g9b942l20q2gpy26l4"; + sha256 = "0kxig1dq4v7qf84pmwvipq2rg6zrsplxbp3dflssw7w3zwcv3jcm"; type = "gem"; }; - version = "0.3"; + version = "0.4.1"; }; language_server-protocol = { groups = [ @@ -1713,10 +1713,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "18vmz6fqs0797smpha6jh0dij4kja1pq0jjdjizzwrp6g57gyvd3"; + sha256 = "04jvacvsm24cycdircxbipfk2lky3d3zllw10r1gvll9fka5yr17"; type = "gem"; }; - version = "0.3.1"; + version = "0.4.0"; }; matrix = { groups = [ @@ -1929,10 +1929,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1nrj8vgsdzv60y8302xqycvhn5z2shf137j4hjfhfzq9i1rf7xfc"; + sha256 = "0c5f8ycbj389dvn2vxzq6xmsk2naqm57c5w31mavw0fbgdww3r2j"; type = "gem"; }; - version = "0.21.4"; + version = "0.22.0"; }; mini_scheduler = { dependencies = [ "sidekiq" ]; @@ -2858,10 +2858,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1md96yl05v436jkgz9725cax9hf61sv74267cg7yidwnl3lwd65d"; + sha256 = "1iym8kbdzpkjk70h7w9pbmqj7czsywzinwpqla8ldc6sv7hmh6fs"; type = "gem"; }; - version = "8.0.5"; + version = "8.0.5.1"; }; rainbow = { groups = [ @@ -2955,10 +2955,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1z9q0l9l5r210jsmcmq3lxd4fr0j5lv348kn33g9a62fdm6izf4s"; + sha256 = "05c6ak9wgzf7xqnrnn5j9axr1sjszih9ibyy2man60nsq6cnsj3x"; type = "gem"; }; - version = "0.9.128"; + version = "0.9.130"; }; rbs = { dependencies = [ diff --git a/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch b/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch index e3c444958a26..7e3799eccb33 100644 --- a/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch +++ b/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch @@ -1,11 +1,11 @@ diff --git a/lib/discourse/safe_exec.rb b/lib/discourse/safe_exec.rb -index c4b8a5e3ecb..31d6f0d469d 100644 +index dc32954245c..259bfd99f0c 100644 --- a/lib/discourse/safe_exec.rb +++ b/lib/discourse/safe_exec.rb @@ -5,7 +5,7 @@ require "landlock" module Discourse class SafeExec - DEFAULT_READ_PATHS = %w[/bin /etc /lib /lib64 /usr].freeze + DEFAULT_READ_PATHS = %w[/bin /lib /lib64 /usr].freeze - DEFAULT_EXECUTE_PATHS = %w[/bin /lib /lib64 /usr].freeze + DEFAULT_EXECUTE_PATHS = %w[/bin /lib /lib64 /usr /nix/store].freeze diff --git a/pkgs/servers/web-apps/discourse/update.py b/pkgs/servers/web-apps/discourse/update.py index 6a1fa3f64b9a..d169c4d5c3e0 100755 --- a/pkgs/servers/web-apps/discourse/update.py +++ b/pkgs/servers/web-apps/discourse/update.py @@ -276,6 +276,8 @@ def update(rev): subprocess.check_output(["rm", "-rf", "migrations"], cwd=rubyenv_dir) # -- end gitlab pkg code + click.echo("updating dart-sass") + # update the sass-embedded override # must run *after* the gemfile update! dart_sass_ver = _nix_eval('discourse.rubyEnv.gemset.sass-embedded.version') @@ -301,17 +303,32 @@ def update(rev): f.write(content) f.truncate() + click.echo("updating discourse package") + # update the discourse package itself _call_nix_update('discourse', version.version) + click.echo("querying old PNPM hash") old_pnpm_hash = _nix_eval('discourse.assets.pnpmDeps.outputHash') + + click.echo("finding new PNPM hash") + # the pnpm builder now requires the has to be set to "" to output a "got: sha256-" line + empty_hash_line = f"hash = \"\";#{old_pnpm_hash}"; + mk_hash_line = lambda hash: f"hash = \"{hash}\";" + with open(Path(__file__).parent / "default.nix", 'r+') as f: + content = f.read() + content = content.replace(mk_hash_line(old_pnpm_hash), empty_hash_line) + f.seek(0) + f.write(content) + f.truncate() new_pnpm_hash = _get_build_lock_hash() + if new_pnpm_hash is not None: click.echo(f"Updating pnpm lock hash: {old_pnpm_hash} -> {new_pnpm_hash}") with open(Path(__file__).parent / "default.nix", 'r+') as f: content = f.read() - content = content.replace(old_pnpm_hash, new_pnpm_hash) + content = content.replace(empty_hash_line, mk_hash_line(new_pnpm_hash)) f.seek(0) f.write(content) f.truncate() From 0ad08425d206e052f95a3fa756538904738b1c0a Mon Sep 17 00:00:00 2001 From: mtnash Date: Mon, 14 Sep 2026 14:53:04 -0400 Subject: [PATCH 08/61] discourse: fix restrictive imagemagick policy breaking on required symlinks in paths --- pkgs/servers/web-apps/discourse/default.nix | 3 +++ .../web-apps/discourse/optimize-image-fix.patch | 11 +++++++++++ .../web-apps/discourse/safe-exec-from-nix-store.patch | 8 +++++--- 3 files changed, 19 insertions(+), 3 deletions(-) create mode 100644 pkgs/servers/web-apps/discourse/optimize-image-fix.patch diff --git a/pkgs/servers/web-apps/discourse/default.nix b/pkgs/servers/web-apps/discourse/default.nix index d864f478c59f..cead7c2e22d2 100644 --- a/pkgs/servers/web-apps/discourse/default.nix +++ b/pkgs/servers/web-apps/discourse/default.nix @@ -517,6 +517,9 @@ let # Our app/assets/generated folder is a symlink, but the ruby File.mkdir_p doesn't allow # a symlink in the way to the last directory. This patch explicitly resolves the symlink. ./resolve_generated_assets_symlink.patch + + # in the imagemagick sandbox, symlinks permissions are checked (as you would hope) but this causes other problems.. + ./optimize-image-fix.patch ]; postPatch = '' diff --git a/pkgs/servers/web-apps/discourse/optimize-image-fix.patch b/pkgs/servers/web-apps/discourse/optimize-image-fix.patch new file mode 100644 index 000000000000..56632d374b42 --- /dev/null +++ b/pkgs/servers/web-apps/discourse/optimize-image-fix.patch @@ -0,0 +1,11 @@ +diff --git a/config/imagemagick/policy.xml b/config/imagemagick/policy.xml +index a29d02c021b..8075d701fee 100644 +--- a/config/imagemagick/policy.xml ++++ b/config/imagemagick/policy.xml +@@ -41,5 +41,5 @@ + + + +- ++ + diff --git a/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch b/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch index 7e3799eccb33..e652eff3924a 100644 --- a/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch +++ b/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch @@ -1,12 +1,14 @@ diff --git a/lib/discourse/safe_exec.rb b/lib/discourse/safe_exec.rb -index dc32954245c..259bfd99f0c 100644 +index dc32954245c..a89d9afac97 100644 --- a/lib/discourse/safe_exec.rb +++ b/lib/discourse/safe_exec.rb -@@ -5,7 +5,7 @@ require "landlock" +@@ -4,8 +4,8 @@ require "landlock" + module Discourse class SafeExec - DEFAULT_READ_PATHS = %w[/bin /lib /lib64 /usr].freeze +- DEFAULT_READ_PATHS = %w[/bin /lib /lib64 /usr].freeze - DEFAULT_EXECUTE_PATHS = %w[/bin /lib /lib64 /usr].freeze ++ DEFAULT_READ_PATHS = %w[/bin /lib /lib64 /usr /nix/store].freeze + DEFAULT_EXECUTE_PATHS = %w[/bin /lib /lib64 /usr /nix/store].freeze def self.capture( From dc128564d096dc61bc02d63bb4554f6b729a877f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 20 Sep 2026 01:05:53 +0000 Subject: [PATCH 09/61] moonlight: 2026.9.0 -> 2026.9.1 --- pkgs/by-name/mo/moonlight/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/mo/moonlight/package.nix b/pkgs/by-name/mo/moonlight/package.nix index daaa382d85d0..d51fd8d09afd 100644 --- a/pkgs/by-name/mo/moonlight/package.nix +++ b/pkgs/by-name/mo/moonlight/package.nix @@ -17,13 +17,13 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "moonlight"; - version = "2026.9.0"; + version = "2026.9.1"; src = fetchFromGitHub { owner = "moonlight-mod"; repo = "moonlight"; tag = "v${finalAttrs.version}"; - hash = "sha256-J78pFRFONALG2QWuRQSekiaG9TNctrEM/IYG2Iot9gk="; + hash = "sha256-Bcqtviy8In/aQn8qT4sbAJKKYuVp6bwzA1TKzy1p2bo="; }; nativeBuildInputs = [ From e958fba2175b8af6c8db2c0fbf0128f93b6186cd Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 20 Sep 2026 15:23:37 +0000 Subject: [PATCH 10/61] kimai: 2.66.0 -> 2.67.0 --- pkgs/by-name/ki/kimai/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ki/kimai/package.nix b/pkgs/by-name/ki/kimai/package.nix index 64033d34d98f..c469628eadc9 100644 --- a/pkgs/by-name/ki/kimai/package.nix +++ b/pkgs/by-name/ki/kimai/package.nix @@ -7,13 +7,13 @@ php.buildComposerProject2 (finalAttrs: { pname = "kimai"; - version = "2.66.0"; + version = "2.67.0"; src = fetchFromGitHub { owner = "kimai"; repo = "kimai"; tag = finalAttrs.version; - hash = "sha256-cL7XhcNkuXsDV9rbjXTt9N+3pN9lPqUEiuVZ9ZrHx4w="; + hash = "sha256-yeQFo6rwtsRL32Pw+o4uXeS80Hyij4MENtdMybq5WMU="; }; php = php.buildEnv { @@ -38,7 +38,7 @@ php.buildComposerProject2 (finalAttrs: { ''; }; - vendorHash = "sha256-TpQV62iRp9zEZsxbqg1EUt/dvU7NzS+K0J4gwcoBiPI="; + vendorHash = "sha256-VV4+pcMuxy0Xq31aq8J51xHUrt/6Bn4bDNb69OOFSo4="; composerNoPlugins = false; postInstall = '' From b63c64b6479cf56ffdb7fd5b26eede6ed917afd3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Gabriel=20N=C3=BCtzi?= Date: Wed, 23 Sep 2026 14:18:28 +0200 Subject: [PATCH 11/61] nixosTest.gitlab.runner: remove podman-executor - Remove the too complex podman executor and link to it in the documentation over the NixOS wiki. --- nixos/doc/manual/redirects.json | 3 - nixos/modules/services/misc/gitlab/default.md | 96 +--- nixos/tests/gitlab/runner.nix | 15 - .../gitlab/runner/podman-runner/default.nix | 435 ------------------ .../podman-runner/files/basicRoot/etc/group | 21 - .../files/basicRoot/etc/nsswitch.conf | 11 - .../podman-runner/files/basicRoot/etc/passwd | 34 -- .../containers/etc/containers/containers.conf | 2 - .../containers/etc/containers/mounts.conf | 2 - .../containers/etc/containers/policy.json | 12 - .../containers/etc/containers/registries.conf | 2 - .../registries.conf.d/000-shortnames.conf | 5 - .../etc/containers/registries.d/default.yaml | 27 -- .../registry.access.redhat.com.yaml | 3 - .../registries.d/registry.redhat.io.yaml | 3 - .../containers/etc/containers/storage.conf | 15 - .../runner/podman-runner/files/default.nix | 46 -- .../files/fake-nixpkgs/default.nix | 10 - .../gitlab/runner/podman-runner/nix-image.nix | 400 ---------------- .../runner/podman-runner/scripts/prebuild.nix | 55 --- .../runner/podman-runner/virtualization.nix | 43 -- 21 files changed, 1 insertion(+), 1239 deletions(-) delete mode 100644 nixos/tests/gitlab/runner/podman-runner/default.nix delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/group delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/nsswitch.conf delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/passwd delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/containers.conf delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/mounts.conf delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/policy.json delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf.d/000-shortnames.conf delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/default.yaml delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.access.redhat.com.yaml delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.redhat.io.yaml delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/storage.conf delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/default.nix delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/fake-nixpkgs/default.nix delete mode 100644 nixos/tests/gitlab/runner/podman-runner/nix-image.nix delete mode 100644 nixos/tests/gitlab/runner/podman-runner/scripts/prebuild.nix delete mode 100644 nixos/tests/gitlab/runner/podman-runner/virtualization.nix diff --git a/nixos/doc/manual/redirects.json b/nixos/doc/manual/redirects.json index 57c6a731ac68..ca7209ff5539 100644 --- a/nixos/doc/manual/redirects.json +++ b/nixos/doc/manual/redirects.json @@ -1502,9 +1502,6 @@ "module-services-gitlab-runner": [ "index.html#module-services-gitlab-runner" ], - "ex-gitlab-runner-podman": [ - "index.html#ex-gitlab-runner-podman" - ], "module-forgejo": [ "index.html#module-forgejo" ], diff --git a/nixos/modules/services/misc/gitlab/default.md b/nixos/modules/services/misc/gitlab/default.md index 4b0b105b1145..94d99202422d 100644 --- a/nixos/modules/services/misc/gitlab/default.md +++ b/nixos/modules/services/misc/gitlab/default.md @@ -150,99 +150,5 @@ configured executors The [services.gitlab-runner.services](https://search.nixos.org/options?query=services.gitlab-runner.services) documents a number of typical setups to configure multiple runners with -different executors. - -The [below example](#ex-gitlab-runner-podman) gives a **more elaborate** example how to +different executors. See also the [wiki section](https://wiki.nixos.org/wiki/Gitlab_runner#Configuring_a_podman-Executor_with_Nix_Store_Caching), which gives a **more elaborate** example how to configure a Gitlab Runner with caching and reasonably good security practices. - -::: {#ex-gitlab-runner-podman .example} - -## Gitlab Runner with `podman` and Nix Store Caching - -The [VM tested `podman-runner`](https://github.com/NixOS/nixpkgs/blob/master/nixos/tests/gitlab/runner/podman-runner/default.nix) -(a NixOS module for reuse) configures an advanced Gitlab runner with the following features: - -- The executor is `podman` which gives you better additional safety than - `docker`. That means every job is run in a `podman` container. - -- The following container **images** are built with Nix: - - **Container Images for Gitlab Jobs**: - - `local/alpine`: An image based on Alpine with a Nix installation - (attribute `jobImages.alpine`). - - `local/ubuntu`: An image based on Ubuntu with a Nix installation - (attribute `jobImages.ubuntu`). - - `local/nix`: An image based on Nix which only comes with `nix` - installed (attribute `jobImages.nix`). - - **Images for VM Setup**: - - `local/nix-daemon-image`: An image with a Nix daemon which is - used to share the `/nix/store` across jobs (variable `nixDaemonImage`) setup with some essentials derivations `bootstrapPkgs`. - - `local/podman-daemon-image`: An image with `podman` running as a daemon which is - used to run `podman` inside the above job containers images - (variable `podmanDaemonImage`). - -- Every job container runs in a `podman` container instance based by default on - `jobImage.ubuntu`. A pipeline job can override this with `image: local/alpine`. - - Each job container will have the `/nix/store` mounted from the container - `nix-daemon-container` (see registration flags - `--docker-volumes-from "nix-daemon-container:ro"`). - - The `nix-daemon-container` is a single container instance of a - `nixDaemonImage`. This enables caching of `/nix/store` paths across all jobs - in **all** runners. This makes **the host VM's `/nix/store` independent of the - Nix store used in the jobs**, which is good. - - ::: {.note} - **Security:** If you don't want this you need multiple `nixDaemonImage` - containers for each registered runner (`gitlab-runner.services.`). - ::: - - - Each job container will have the `/run/podman/podman.sock` socket mounted from the - `podman-daemon-container`. - - The `podman-daemon-container` is a single container of a `podmanDaemonImage` which runs - `podman` as a daemon. Job containers can use this daemon to spawn nested containers as well (podman-in-podman). - **Keep in mind that `bind` mounts are local to the `podman-daemon-container`** - and can be be worked around with a `podman volume create ` and manual copy-to/copy-from this volume ``. - - If you only need to build containers you don't need this feature (`podman-daemon-container`), see below point. - - Container configuration files (`auxRootFiles`) are copied to all containers to - ensure `podman` works consistently inside the job containers. - - - The job containers do **not** mount the `podman` socket from the host (NixOS - VM) mounted for security reasons. - - ::: {.note} - Building container images with `buildah` (stripped - `podman` for building images) inside a job which runs `jobImage.alpine` - is still possible. - ::: - - - **Cleanup Disk Space**: - - With this setup its really easy to clean the `nix-daemon-container` - (e.g. if you run out of disk space), then reboot and have the runner in a clean state. - You can do the following to effectively clean everything and start with fresh volumes safely: - - ```bash - # Stop the Gitlab runner. - systemctl stop gitlab-runner.service - # Stop `systemd`-managed containers, such that they get not recreated - # when deleting below. - systemctl stop podman-podman-daemon-container.service \ - podman-nix-daemon-container.service \ - podman-nix-container.service \ - podman-alpine-container.service \ - podman-ubuntu-container.service || true - - podman container rm -f --all - podman image rm -f --all - podman volumes rm -f --all - - reboot - # Systemd will restart all containers and create volumes etc. - ``` - -::: diff --git a/nixos/tests/gitlab/runner.nix b/nixos/tests/gitlab/runner.nix index 8a748f1298bf..ca12910d203d 100644 --- a/nixos/tests/gitlab/runner.nix +++ b/nixos/tests/gitlab/runner.nix @@ -31,21 +31,6 @@ let path = ./runner/shell-runner.nix; tokenFile = "${runnerTokenDir}/token-shell.env"; }; - - # The Gitlab runner which uses the Docker runner (we use podman). - # Features: - # - Daemonizes the Nix store into a container. - # - All jobs run in an unprivileged container, e.g. with image - # (`local/nix`, `local/alpine`, `local/ubuntu`) - podman = { - # Only enabled on x86_64-linux: due to container images. - # TODO: See https://github.com/NixOS/nixpkgs/issues/474409 - enabled = pkgs.stdenv.buildPlatform.isx86_64; - desc = "Podman runner (containers, shared containerized Nix store)"; - name = "podman"; - path = ./runner/podman-runner; - tokenFile = "${runnerTokenDir}/token-podman.env"; - }; }; in { diff --git a/nixos/tests/gitlab/runner/podman-runner/default.nix b/nixos/tests/gitlab/runner/podman-runner/default.nix deleted file mode 100644 index 885f0d191ae2..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/default.nix +++ /dev/null @@ -1,435 +0,0 @@ -{ runnerConfig }: -# Gitlab Runner Module -# -# This module will add a Gitlab-Runner -# with a nix-daemon running in a podman container `nix-daemon-container`. -# Check the documentation in the NixOS Manual. -# -# Debugging on the VM: -# -# - You can use `journalctl -u gitlab-runner.service`. -# -# - To run a job container inside the VM use: -# ```bash -# podman run --rm -it -# --volumes-from 'nix-daemon-container' -# -v "podman-daemon-socket:/run/podman" -# "local/alpine" \ -# bash -c "export CI_PIPELINE_ID=123456 && gitlab-runner-pre-build-script; echo hello" -# ``` -{ - lib, - pkgs, - ... -}: -let - # Switch to not use IFD in nixpkgs test. - # NOTE: When reusing this runner, you can set this to `true`. - useIFD = false; - - # Either we use a Nix as the base image or Alpine. - imageNames = { - default = imageNames.alpine; - - alpine = "local/alpine"; - nix = "local/nix"; - ubuntu = "local/ubuntu"; - - all = with imageNames; [ - alpine - nix - ubuntu - ]; - }; - - noPruneLabels = { - no-prune = "true"; - }; - - # This derivation will contain a folder `/etc` - files = pkgs.callPackage ./files { }; - preBuildScript = pkgs.callPackage ./scripts/prebuild.nix { }; - - # These derivations are Linked into the job images root dir. - bootstrapPkgs = [ - pkgs.nix - # Runtime dependencies of nix. - pkgs.gnutar - pkgs.gzip - pkgs.openssh - pkgs.xz - pkgs.cacert - - # Other stuff. - (lib.hiPrio pkgs.coreutils) - (lib.hiPrio pkgs.findutils) - pkgs.openssh - pkgs.bashInteractive - (lib.hiPrio pkgs.git) - pkgs.cachix - - pkgs.just - pkgs.podman # For nested containers. - - preBuildScript - - files.containers - files.nixConfig - ]; - - # All these packages are added to the Nix daemon. - nixStorePkgs = bootstrapPkgs ++ [ - # These files - files.basicRoot - files.fakeNixpkgs - ]; - - toEnvList = envs: lib.mapAttrsToList (k: v: "${k}=${v}") envs; - - # This is the Nix base image used for the Nix Daemon. - # The build script for the nixos/nix image is vendored due to Hydra limitations. - # cause it is IFD (Import from Derivation) which is not allowed. - # NOTE: When reusing this runner you can set `useIFD` to true: - nixImageBaseFn = - if !useIFD then - import ./nix-image.nix - else - import ( - (pkgs.fetchFromGitHub { - owner = "NixOS"; - repo = "nix"; - rev = "2.32.4"; - hash = "sha256-8QYnRyGOTm3h/Dp8I6HCmQzlO7C009Odqyp28pTWgcY="; - }) - + "/docker.nix" - ); - - nixImageBase = - nixConf: - pkgs.callPackage nixImageBaseFn { - name = "local/nix-base"; - tag = "latest"; - - bundleNixpkgs = false; - maxLayers = 2; - - # You can add here a user with uid,gid,uname,gname etc. - # We are using root. - - extraPkgs = nixStorePkgs; - - nixConf = { - cores = "0"; - experimental-features = [ - "nix-command" - "flakes" - ]; - } - // nixConf; - }; - - # This is the daemon image which provides the store - # as volumes. - nixDaemonImage = pkgs.dockerTools.buildLayeredImage { - fromImage = nixImageBase { - min-free = "1G"; # Triggers garbage collection. - max-free = "10G"; # Stops garbage collection at 10G free space. - - # Reduce disk usage by discarding old derivations/outputs - keep-derivations = false; - keep-outputs = false; - }; - name = "local/nix-daemon"; - tag = "latest"; - - config = { - Volumes = { - "/nix/store" = { }; - "/nix/var/nix/db" = { }; - "/nix/var/nix/daemon-socket" = { }; - }; - Labels = noPruneLabels; - }; - maxLayers = 4; - }; - - # This is the podman daemon image which enables - # a job image to use `podman` internally. - podmanDaemonImage = - let - # Update with: - # ```shell - # nix run "github:nixos/nixpkgs/nixos-unstable#nix-prefetch-docker" -- \ - # --image-name quay.io/podman/stable --image-tag v5.6.0 - # ``` - base = pkgs.dockerTools.pullImage { - imageName = "quay.io/podman/stable"; - imageDigest = "sha256:7c9381b9af167cf2218831c3af3135856c99f488b543b78435c8f18e19ad739a"; - hash = "sha256-pXXCu13fB/RN9qx8iLhE5Kko6glTrFrRhR7fo2OS7V0="; - finalImageName = "quay.io/podman/stable"; - finalImageTag = "v5.6.0"; - }; - in - pkgs.dockerTools.buildLayeredImage { - fromImage = base; - name = "local/podman-daemon"; - tag = "latest"; - - config = { - Labels = noPruneLabels; - }; - }; - - jobImages = - let - extraCommands = '' - set -eu - # Set missing Nix directories. - mkdir -p -m 0755 nix/var/log/nix/drvs - mkdir -p -m 0755 nix/var/nix/{gcroots,profiles,temproots,userpool} - mkdir -p -m 1777 nix/var/nix/{gcroots,profiles}/per-user - mkdir -p -m 0755 nix/var/nix/profiles/per-user/root - - # Need a HOME. - mkdir -vp root - mkdir -p -m 0700 root/.nix-defexpr - ''; - in - { - # The Nix image. - # Similar to https://github.com/nix-community/docker-nixpkgs/blob/main/images/nix/default.nix. - nix = pkgs.dockerTools.buildLayeredImage { - name = imageNames.nix; - tag = "latest"; - - extraCommands = extraCommands + '' - set -eu - # For `/usr/bin/env`. - mkdir -p usr && ln -s ../bin usr/bin - ''; - - contents = bootstrapPkgs ++ [ files.basicRoot ]; - # No store paths are copied into. We provide them by mounting the - # /nix/store. - includeStorePaths = false; - - config = { - Labels = noPruneLabels; - Env = toEnvList envs.nix; - }; - maxLayers = 2; - }; - - # This is the analog image to `local/nix` but Alpine based. - alpine = - let - # Update with: - # ```shell - # nix run "github:nixos/nixpkgs/nixos-unstable#nix-prefetch-docker" -- --image-name alpine --image-tag latest - # ``` - alpineBase = pkgs.dockerTools.pullImage { - imageName = "alpine"; - imageDigest = "sha256:beefdbd8a1da6d2915566fde36db9db0b524eb737fc57cd1367effd16dc0d06d"; - sha256 = "0gf7wbjp37zbni3pz8vdgq1mss6mz69wynms0gqhq7lsxfmg9xj9"; - finalImageName = "alpine"; - finalImageTag = "latest"; - }; - in - (pkgs.dockerTools.buildLayeredImage { - fromImage = alpineBase; - name = imageNames.alpine; - tag = "latest"; - - inherit extraCommands; - - contents = bootstrapPkgs; - # No store paths are copied into. We provide them by mounting the - # /nix/store. - includeStorePaths = false; - - config = { - Labels = noPruneLabels; - Env = toEnvList envs.nix; - }; - - # Only if `build buildLayeredImage`. - maxLayers = 3; - }); - - # This is the analog image to `local/nix` but Ubuntu based. - ubuntu = - let - # Update with: - # ```shell - # nix run "github:nixos/nixpkgs/nixos-unstable#nix-prefetch-docker" -- \ - # --image-name ubuntu --image-tag latest - # ``` - ubuntuBase = pkgs.dockerTools.pullImage { - imageName = "ubuntu"; - imageDigest = "sha256:1e622c5f073b4f6bfad6632f2616c7f59ef256e96fe78bf6a595d1dc4376ac02"; - hash = "sha256-aC8SgxdcMSaaU89YMr/uwE022Yqey2frmeZqr+L1xEU="; - finalImageName = "ubuntu"; - finalImageTag = "latest"; - }; - in - (pkgs.dockerTools.buildLayeredImage { - fromImage = ubuntuBase; - name = imageNames.ubuntu; - tag = "latest"; - - inherit extraCommands; - - contents = bootstrapPkgs; - # No store paths are copied into. We provide them by mounting the - # /nix/store. - includeStorePaths = false; - - config = { - Labels = noPruneLabels; - Env = toEnvList envs.ubuntu; - }; - - # Only if `build buildLayeredImage`. - maxLayers = 3; - }); - }; - - nixDaemonContainer = { - imageFile = nixDaemonImage; - image = "local/nix-daemon:latest"; - - volumes = [ - "nix-daemon-store:/nix/store" - "nix-daemon-db:/nix/var/nix/db" - "nix-daemon-socket:/nix/var/nix/daemon-socket" - ]; - cmd = [ - "nix" - "daemon" - ]; - }; - - podmanDaemonContainer = { - imageFile = podmanDaemonImage; - image = "local/podman-daemon:latest"; - volumes = [ - "podman-daemon-socket:/run/podman" - "podman-cache:/var/lib/container" - # Shared images, currently not needed. - "podman-shared:/var/lib/shared:ro" - ]; - privileged = true; - cmd = [ - "podman" - "system" - "service" - "--time=0" - "unix:///run/podman/podman.sock" - "--log-level" - "info" - ]; - }; - - # Environment variables for all job containers. - envs = rec { - common = { - # Access to the nix daemon. - NIX_REMOTE = "daemon"; - # Access to podman. - CONTAINER_HOST = "unix:///run/podman/podman.sock"; - - USER = "root"; - PATH = "/nix/var/nix/profiles/default/bin:/nix/var/nix/profiles/default/sbin:/bin:/sbin:/usr/bin:/usr/sbin"; - - SSL_CERT_FILE = "${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt"; - NIX_SSL_CERT_FILE = "${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt"; - - # For shells, source this file. - ENV = "${pkgs.nix}/etc/profile.d/nix-daemon.sh"; - BASH_ENV = "${pkgs.nix}/etc/profile.d/nix-daemon.sh"; - - # Make a fake nixpkgs which throws when using - # `nix repl -f ` for example. - NIX_PATH = "nixpkgs=${files.fakeNixpkgs}"; - }; - - nix = common // { - IMAGE_OS_DIST = "nix"; - }; - - alpine = common // { - IMAGE_OS_DIST = "alpine"; - }; - - ubuntu = common // { - IMAGE_OS_DIST = "ubuntu"; - }; - }; - - registrationFlags = [ - "--docker-volumes" - "gitlab-runner-scratch:/scratch" - - "--docker-volumes" - "podman-daemon-socket:/run/podman" - - "--docker-volumes-from" - "nix-daemon-container:ro" - - "--docker-pull-policy" - "if-not-present" - - "--docker-allowed-pull-policies" - "if-not-present" - - "--docker-host" - "unix:///var/run/podman/podman.sock" - - "--docker-network-mode" - "host" - ]; - -in -{ - imports = [ ./virtualization.nix ]; - - virtualisation.oci-containers = { - backend = "podman"; - - containers = { - nix-daemon-container = nixDaemonContainer; - podman-daemon-container = podmanDaemonContainer; - } - // - # Workaround to add the job images to the registry. - (lib.concatMapAttrs (name: image: { - "${name}-container" = { - imageFile = jobImages.${name}; - image = "${imageNames.${name}}:latest"; - extraOptions = [ - "--volumes-from" - "nix-daemon-container:ro" - ]; - dependsOn = [ "nix-daemon-container" ]; - cmd = [ "true" ]; - }; - }) jobImages); - }; - - # Define the Gitlab Runner. - services.gitlab-runner.services.podman-runner = { - description = runnerConfig.desc; - - inherit registrationFlags; - - authenticationTokenConfigFile = runnerConfig.tokenFile; - - executor = "docker"; - dockerImage = imageNames.default; - dockerAllowedImages = [ ]; - dockerPrivileged = false; - requestConcurrency = 4; - - preBuildScript = "${preBuildScript}/bin/gitlab-runner-pre-build-script"; - }; -} diff --git a/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/group b/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/group deleted file mode 100644 index 162f79fd7086..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/group +++ /dev/null @@ -1,21 +0,0 @@ -root:x:0: -wheel:x:1: -kmem:x:2: -tty:x:3: -messagebus:x:4: -disk:x:6: -audio:x:17: -floppy:x:18: -uucp:x:19: -lp:x:20: -cdrom:x:24: -tape:x:25: -video:x:26: -dialout:x:27: -utmp:x:29: -adm:x:55: -keys:x:96: -users:x:100: -input:x:174: -nixbld:x:30000:nixbld1,nixbld10,nixbld11,nixbld12,nixbld13,nixbld14,nixbld15,nixbld16,nixbld17,nixbld18,nixbld19,nixbld2,nixbld20,nixbld21,nixbld22,nixbld23,nixbld24,nixbld25,nixbld26,nixbld27,nixbld28,nixbld29,nixbld3,nixbld30,nixbld31,nixbld32,nixbld4,nixbld5,nixbld6,nixbld7,nixbld8,nixbld9 -nogroup:x:65534: diff --git a/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/nsswitch.conf b/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/nsswitch.conf deleted file mode 100644 index 59a21416fd8f..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/nsswitch.conf +++ /dev/null @@ -1,11 +0,0 @@ -passwd: files mymachines systemd -group: files mymachines systemd -shadow: files - -hosts: files mymachines dns myhostname -networks: files - -ethers: files -services: files -protocols: files -rpc: files diff --git a/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/passwd b/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/passwd deleted file mode 100644 index 006b53f7bf82..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/passwd +++ /dev/null @@ -1,34 +0,0 @@ -root:x:0:0:System administrator:/root:/bin/bash -nixbld1:x:30001:30000:Nix build user 1:/var/empty:/run/current-system/sw/bin/nologin -nixbld2:x:30002:30000:Nix build user 2:/var/empty:/run/current-system/sw/bin/nologin -nixbld3:x:30003:30000:Nix build user 3:/var/empty:/run/current-system/sw/bin/nologin -nixbld4:x:30004:30000:Nix build user 4:/var/empty:/run/current-system/sw/bin/nologin -nixbld5:x:30005:30000:Nix build user 5:/var/empty:/run/current-system/sw/bin/nologin -nixbld6:x:30006:30000:Nix build user 6:/var/empty:/run/current-system/sw/bin/nologin -nixbld7:x:30007:30000:Nix build user 7:/var/empty:/run/current-system/sw/bin/nologin -nixbld8:x:30008:30000:Nix build user 8:/var/empty:/run/current-system/sw/bin/nologin -nixbld9:x:30009:30000:Nix build user 9:/var/empty:/run/current-system/sw/bin/nologin -nixbld10:x:30010:30000:Nix build user 10:/var/empty:/run/current-system/sw/bin/nologin -nixbld11:x:30011:30000:Nix build user 11:/var/empty:/run/current-system/sw/bin/nologin -nixbld12:x:30012:30000:Nix build user 12:/var/empty:/run/current-system/sw/bin/nologin -nixbld13:x:30013:30000:Nix build user 13:/var/empty:/run/current-system/sw/bin/nologin -nixbld14:x:30014:30000:Nix build user 14:/var/empty:/run/current-system/sw/bin/nologin -nixbld15:x:30015:30000:Nix build user 15:/var/empty:/run/current-system/sw/bin/nologin -nixbld16:x:30016:30000:Nix build user 16:/var/empty:/run/current-system/sw/bin/nologin -nixbld17:x:30017:30000:Nix build user 17:/var/empty:/run/current-system/sw/bin/nologin -nixbld18:x:30018:30000:Nix build user 18:/var/empty:/run/current-system/sw/bin/nologin -nixbld19:x:30019:30000:Nix build user 19:/var/empty:/run/current-system/sw/bin/nologin -nixbld20:x:30020:30000:Nix build user 20:/var/empty:/run/current-system/sw/bin/nologin -nixbld21:x:30021:30000:Nix build user 21:/var/empty:/run/current-system/sw/bin/nologin -nixbld22:x:30022:30000:Nix build user 22:/var/empty:/run/current-system/sw/bin/nologin -nixbld23:x:30023:30000:Nix build user 23:/var/empty:/run/current-system/sw/bin/nologin -nixbld24:x:30024:30000:Nix build user 24:/var/empty:/run/current-system/sw/bin/nologin -nixbld25:x:30025:30000:Nix build user 25:/var/empty:/run/current-system/sw/bin/nologin -nixbld26:x:30026:30000:Nix build user 26:/var/empty:/run/current-system/sw/bin/nologin -nixbld27:x:30027:30000:Nix build user 27:/var/empty:/run/current-system/sw/bin/nologin -nixbld28:x:30028:30000:Nix build user 28:/var/empty:/run/current-system/sw/bin/nologin -nixbld29:x:30029:30000:Nix build user 29:/var/empty:/run/current-system/sw/bin/nologin -nixbld30:x:30030:30000:Nix build user 30:/var/empty:/run/current-system/sw/bin/nologin -nixbld31:x:30031:30000:Nix build user 31:/var/empty:/run/current-system/sw/bin/nologin -nixbld32:x:30032:30000:Nix build user 32:/var/empty:/run/current-system/sw/bin/nologin -nobody:x:65534:65534:Unprivileged account (don't use!):/var/empty:/run/current-system/sw/bin/nologin diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/containers.conf b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/containers.conf deleted file mode 100644 index 0bf45cd2a1a1..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/containers.conf +++ /dev/null @@ -1,2 +0,0 @@ -[engine] -cgroup_manager = "cgroupfs" diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/mounts.conf b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/mounts.conf deleted file mode 100644 index b54e7222210b..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/mounts.conf +++ /dev/null @@ -1,2 +0,0 @@ -/run/secrets/etc-pki-entitlement:/run/secrets/etc-pki-entitlement -/run/secrets/rhsm:/run/secrets/rhsm diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/policy.json b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/policy.json deleted file mode 100644 index 4724dd816814..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/policy.json +++ /dev/null @@ -1,12 +0,0 @@ -{ - "default": [ - { - "type": "insecureAcceptAnything" - } - ], - "transports": { - "docker-daemon": { - "": [{ "type": "insecureAcceptAnything" }] - } - } -} diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf deleted file mode 100644 index c3a575800d86..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf +++ /dev/null @@ -1,2 +0,0 @@ -unqualified-search-registries = ["registry.fedoraproject.org", "registry.access.redhat.com", "docker.io"] -short-name-mode = "enforcing" diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf.d/000-shortnames.conf b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf.d/000-shortnames.conf deleted file mode 100644 index 142e6158235c..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf.d/000-shortnames.conf +++ /dev/null @@ -1,5 +0,0 @@ -[aliases] - "buildah" = "quay.io/buildah/stable" - "podman" = "quay.io/podman/stable" - "alpine" = "docker.io/library/alpine" - "ubuntu" = "docker.io/library/ubuntu" diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/default.yaml b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/default.yaml deleted file mode 100644 index 9e892d760b21..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/default.yaml +++ /dev/null @@ -1,27 +0,0 @@ -# This is a default registries.d configuration file. You may -# add to this file or create additional files in registries.d/. -# -# lookaside: for reading/writing simple signing signatures -# lookaside-staging: for writing simple signing signatures, preferred over lookaside -# -# lookaside and lookaside-staging take a value of the following: -# lookaside: {schema}://location -# -# For reading signatures, schema may be http, https, or file. -# For writing signatures, schema may only be file. - -# The default locations are built-in, for both reading and writing: -# /var/lib/containers/sigstore for root, or -# ~/.local/share/containers/sigstore for non-root users. -default-docker: -# lookaside: https://… -# lookaside-staging: file:///… - -# The 'docker' indicator here is the start of the configuration -# for docker registries. -# -# docker: -# -# privateregistry.com: -# lookaside: https://privateregistry.com/sigstore/ -# lookaside-staging: /mnt/nfs/privateregistry/sigstore diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.access.redhat.com.yaml b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.access.redhat.com.yaml deleted file mode 100644 index 45018d5830a7..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.access.redhat.com.yaml +++ /dev/null @@ -1,3 +0,0 @@ -docker: - registry.access.redhat.com: - lookaside: https://access.redhat.com/webassets/docker/content/sigstore diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.redhat.io.yaml b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.redhat.io.yaml deleted file mode 100644 index ba1769320ce7..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.redhat.io.yaml +++ /dev/null @@ -1,3 +0,0 @@ -docker: - registry.redhat.io: - lookaside: https://registry.redhat.io/containers/sigstore diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/storage.conf b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/storage.conf deleted file mode 100644 index 9db50278d80b..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/storage.conf +++ /dev/null @@ -1,15 +0,0 @@ -[storage] -driver = "overlay" -runroot = "/run/containers/storage" -graphroot = "/var/lib/containers/storage" - -[storage.options] -additionalimagestores = [ -"/var/lib/shared", -"/usr/lib/containers/storage", -] -pull_options = {enable_partial_images = "true", use_hard_links = "false", ostree_repos=""} - -[storage.options.overlay] -mount_program = "/usr/bin/fuse-overlayfs" -mountopt = "nodev,fsync=0" diff --git a/nixos/tests/gitlab/runner/podman-runner/files/default.nix b/nixos/tests/gitlab/runner/podman-runner/files/default.nix deleted file mode 100644 index e791ae42367f..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/files/default.nix +++ /dev/null @@ -1,46 +0,0 @@ -# Specific files for the job images. -# -# - `basicRoot`: Some basic root files for the `jobImages.nix`. -# - `fakeNixpkgs`: A fake Nixpkg directory which is set as `NIX_PATH=nixpkgs:` -# which throws on load. -# - `nixConfig`: The Nix config with some options. -# - `containers`: -# These are some files which are copied to the job images needed for -# `buildah` (`podman`): -# -# ```bash -# podman create --name temp-buildah quay.io/buildah/stable:latest -# podman cp temp-buildah:/etc/containers ./etc/ -# find ./etc -type d -empty -delete -# podman container rm temp-buildah -#``` -# -{ pkgs, ... }: -let - - # We need proper derivations to add it to the nixImageBase. - mkDrv = - name: src: - pkgs.stdenv.mkDerivation { - inherit name src; - installPhase = '' - mkdir -p $out - cp -r $src/* $out/ - ''; - }; -in -{ - basicRoot = mkDrv "basic-root-files" ./basicRoot; - containers = mkDrv "containers-files" ./containers; - fakeNixpkgs = mkDrv "fake-nixpkgs" ./fake-nixpkgs; - - nixConfig = pkgs.writeTextFile { - name = "nix.conf"; - destination = "/etc/nix/nix.conf"; - text = '' - accept-flake-config = true - experimental-features = nix-command flakes - max-jobs = auto - ''; - }; -} diff --git a/nixos/tests/gitlab/runner/podman-runner/files/fake-nixpkgs/default.nix b/nixos/tests/gitlab/runner/podman-runner/files/fake-nixpkgs/default.nix deleted file mode 100644 index eee7aacaf920..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/files/fake-nixpkgs/default.nix +++ /dev/null @@ -1,10 +0,0 @@ -_: -throw '' - This container doesn't include nixpkgs. - - The best way to work around that is to pin your dependencies. See - https://nix.dev/tutorials/first-steps/towards-reproducibility-pinning-nixpkgs.html - - Or if you must, override the NIX_PATH environment variable with eg: - "NIX_PATH=nixpkgs=channel:nixos-unstable" -'' diff --git a/nixos/tests/gitlab/runner/podman-runner/nix-image.nix b/nixos/tests/gitlab/runner/podman-runner/nix-image.nix deleted file mode 100644 index bfb11e9573d9..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/nix-image.nix +++ /dev/null @@ -1,400 +0,0 @@ -# This is the vendored build script from -# https://raw.githubusercontent.com/NixOS/nix/refs/heads/master/docker.nix -# which builds the Nix image. -# This is only here to please Hydra which is not beeing able to build IFDs. -# `import (nixRepo + "./docker.nix")`. -{ - # Core dependencies - pkgs ? import { }, - lib ? pkgs.lib, - dockerTools ? pkgs.dockerTools, - runCommand ? pkgs.runCommand, - buildPackages ? pkgs.buildPackages, - # Image configuration - name ? "nix", - tag ? "latest", - bundleNixpkgs ? true, - channelName ? "nixpkgs", - channelURL ? "https://channels.nixos.org/nixpkgs-unstable", - extraPkgs ? [ ], - maxLayers ? 70, - nixConf ? { }, - flake-registry ? null, - uid ? 0, - gid ? 0, - uname ? "root", - gname ? "root", - Labels ? { - "org.opencontainers.image.title" = "Nix"; - "org.opencontainers.image.source" = "https://github.com/NixOS/nix"; - "org.opencontainers.image.vendor" = "Nix project"; - "org.opencontainers.image.version" = nix.version; - "org.opencontainers.image.description" = "Nix container image"; - }, - Cmd ? [ (lib.getExe bashInteractive) ], - # Default Packages - nix ? pkgs.nix, - bashInteractive ? pkgs.bashInteractive, - coreutils-full ? pkgs.coreutils-full, - gnutar ? pkgs.gnutar, - gzip ? pkgs.gzip, - gnugrep ? pkgs.gnugrep, - which ? pkgs.which, - curl ? pkgs.curl, - less ? pkgs.less, - wget ? pkgs.wget, - man ? pkgs.man, - cacert ? pkgs.cacert, - findutils ? pkgs.findutils, - iana-etc ? pkgs.iana-etc, - gitMinimal ? pkgs.gitMinimal, - openssh ? pkgs.openssh, - # Other dependencies - shadow ? pkgs.shadow, -}: -let - defaultPkgs = [ - nix - bashInteractive - coreutils-full - gnutar - gzip - gnugrep - which - curl - less - wget - man - cacert.out - findutils - iana-etc - gitMinimal - openssh - ] - ++ extraPkgs; - - users = { - - root = { - uid = 0; - shell = lib.getExe bashInteractive; - home = "/root"; - gid = 0; - groups = [ "root" ]; - description = "System administrator"; - }; - - nobody = { - uid = 65534; - shell = lib.getExe' shadow "nologin"; - home = "/var/empty"; - gid = 65534; - groups = [ "nobody" ]; - description = "Unprivileged account (don't use!)"; - }; - - } - // lib.optionalAttrs (uid != 0) { - "${uname}" = { - uid = uid; - shell = lib.getExe bashInteractive; - home = "/home/${uname}"; - gid = gid; - groups = [ "${gname}" ]; - description = "Nix user"; - }; - } - // lib.listToAttrs ( - map (n: { - name = "nixbld${toString n}"; - value = { - uid = 30000 + n; - gid = 30000; - groups = [ "nixbld" ]; - description = "Nix build user ${toString n}"; - }; - }) (lib.lists.range 1 32) - ); - - groups = { - root.gid = 0; - nixbld.gid = 30000; - nobody.gid = 65534; - } - // lib.optionalAttrs (gid != 0) { - "${gname}".gid = gid; - }; - - userToPasswd = ( - k: - { - uid, - gid ? 65534, - home ? "/var/empty", - description ? "", - shell ? "/bin/false", - groups ? [ ], - }: - "${k}:x:${toString uid}:${toString gid}:${description}:${home}:${shell}" - ); - passwdContents = (lib.concatStringsSep "\n" (lib.attrValues (lib.mapAttrs userToPasswd users))); - - userToShadow = k: { ... }: "${k}:!:1::::::"; - shadowContents = (lib.concatStringsSep "\n" (lib.attrValues (lib.mapAttrs userToShadow users))); - - # Map groups to members - # { - # group = [ "user1" "user2" ]; - # } - groupMemberMap = ( - let - # Create a flat list of user/group mappings - mappings = ( - builtins.foldl' ( - acc: user: - let - groups = users.${user}.groups or [ ]; - in - acc - ++ map (group: { - inherit user group; - }) groups - ) [ ] (lib.attrNames users) - ); - in - (builtins.foldl' ( - acc: v: - acc - // { - ${v.group} = acc.${v.group} or [ ] ++ [ v.user ]; - } - ) { } mappings) - ); - - groupToGroup = - k: - { gid }: - let - members = groupMemberMap.${k} or [ ]; - in - "${k}:x:${toString gid}:${lib.concatStringsSep "," members}"; - groupContents = (lib.concatStringsSep "\n" (lib.attrValues (lib.mapAttrs groupToGroup groups))); - - toConf = - with pkgs.lib.generators; - toKeyValue { - mkKeyValue = mkKeyValueDefault { - mkValueString = v: if lib.isList v then lib.concatStringsSep " " v else mkValueStringDefault { } v; - } " = "; - }; - - nixConfContents = toConf ( - { - sandbox = false; - build-users-group = "nixbld"; - trusted-public-keys = [ "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" ]; - } - // nixConf - ); - - userHome = if uid == 0 then "/root" else "/home/${uname}"; - - baseSystem = - let - nixpkgs = pkgs.path; - channel = runCommand "channel-nixos" { inherit bundleNixpkgs; } '' - mkdir $out - if [ "$bundleNixpkgs" ]; then - ln -s ${ - builtins.path { - path = nixpkgs; - name = "source"; - } - } $out/nixpkgs - echo "[]" > $out/manifest.nix - fi - ''; - # doc/manual/source/command-ref/files/manifest.nix.md - manifest = buildPackages.runCommand "manifest.nix" { } '' - cat > $out < $out/etc/passwd - echo "" >> $out/etc/passwd - - cat $groupContentsPath > $out/etc/group - echo "" >> $out/etc/group - - cat $shadowContentsPath > $out/etc/shadow - echo "" >> $out/etc/shadow - - mkdir -p $out/usr - ln -s /nix/var/nix/profiles/share $out/usr/ - - mkdir -p $out/nix/var/nix/gcroots - - mkdir $out/tmp - - mkdir -p $out/var/tmp - - mkdir -p $out/etc/nix - cat $nixConfContentsPath > $out/etc/nix/nix.conf - - mkdir -p $out${userHome} - mkdir -p $out/nix/var/nix/profiles/per-user/${uname} - - # see doc/manual/source/command-ref/files/profiles.md - ln -s ${profile} $out/nix/var/nix/profiles/default-1-link - ln -s /nix/var/nix/profiles/default-1-link $out/nix/var/nix/profiles/default - ln -s /nix/var/nix/profiles/default $out${userHome}/.nix-profile - - # see doc/manual/source/command-ref/files/channels.md - ln -s ${channel} $out/nix/var/nix/profiles/per-user/${uname}/channels-1-link - ln -s /nix/var/nix/profiles/per-user/${uname}/channels-1-link $out/nix/var/nix/profiles/per-user/${uname}/channels - - # see doc/manual/source/command-ref/files/default-nix-expression.md - mkdir -p $out${userHome}/.nix-defexpr - ln -s /nix/var/nix/profiles/per-user/${uname}/channels $out${userHome}/.nix-defexpr/channels - echo "${channelURL} ${channelName}" > $out${userHome}/.nix-channels - - # may get replaced by pkgs.dockerTools.binSh & pkgs.dockerTools.usrBinEnv - mkdir -p $out/bin $out/usr/bin - ln -s ${lib.getExe' coreutils-full "env"} $out/usr/bin/env - ln -s ${lib.getExe bashInteractive} $out/bin/sh - - '' - + (lib.optionalString (flake-registry-path != null) '' - nixCacheDir="${userHome}/.cache/nix" - mkdir -p $out$nixCacheDir - globalFlakeRegistryPath="$nixCacheDir/flake-registry.json" - ln -s ${flake-registry-path} $out$globalFlakeRegistryPath - mkdir -p $out/nix/var/nix/gcroots/auto - rootName=$(${lib.getExe' nix "nix"} --extra-experimental-features nix-command hash file --type sha1 --base32 <(echo -n $globalFlakeRegistryPath)) - ln -s $globalFlakeRegistryPath $out/nix/var/nix/gcroots/auto/$rootName - '') - ); - -in -dockerTools.buildLayeredImageWithNixDb { - - inherit - name - tag - maxLayers - uid - gid - uname - gname - ; - - contents = [ baseSystem ]; - - extraCommands = '' - rm -rf nix-support - ln -s /nix/var/nix/profiles nix/var/nix/gcroots/profiles - ''; - fakeRootCommands = '' - chmod 1777 tmp - chmod 1777 var/tmp - chown -R ${toString uid}:${toString gid} .${userHome} - chown -R ${toString uid}:${toString gid} nix - ''; - - config = { - inherit Cmd Labels; - User = "${toString uid}:${toString gid}"; - Env = [ - "USER=${uname}" - "PATH=${ - lib.concatStringsSep ":" [ - "${userHome}/.nix-profile/bin" - "/nix/var/nix/profiles/default/bin" - "/nix/var/nix/profiles/default/sbin" - ] - }" - "MANPATH=${ - lib.concatStringsSep ":" [ - "${userHome}/.nix-profile/share/man" - "/nix/var/nix/profiles/default/share/man" - ] - }" - "SSL_CERT_FILE=/nix/var/nix/profiles/default/etc/ssl/certs/ca-bundle.crt" - "GIT_SSL_CAINFO=/nix/var/nix/profiles/default/etc/ssl/certs/ca-bundle.crt" - "NIX_SSL_CERT_FILE=/nix/var/nix/profiles/default/etc/ssl/certs/ca-bundle.crt" - "NIX_PATH=/nix/var/nix/profiles/per-user/${uname}/channels:${userHome}/.nix-defexpr/channels" - ]; - }; - -} diff --git a/nixos/tests/gitlab/runner/podman-runner/scripts/prebuild.nix b/nixos/tests/gitlab/runner/podman-runner/scripts/prebuild.nix deleted file mode 100644 index 4e78638f09a5..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/scripts/prebuild.nix +++ /dev/null @@ -1,55 +0,0 @@ -{ writeShellScriptBin, nix }: -writeShellScriptBin "gitlab-runner-pre-build-script" - # bash - '' - set -e - set -u - - function section_start() { - local name="$1" - shift - echo -e "\e[0Ksection_start:$(date +%s):$name[collapsed=true]\r\e[0K$*" - } - - function section_end() { - local name="$1" - echo -e "\e[0Ksection_end:$(date +%s):$name\r\e[0K" - } - - function setup() { - # We need to allow modification of nix config for cachix as - # otherwise it is link to the read only file in the store. - cp --remove-destination \ - "$(readlink -f /etc/nix/nix.conf)" /etc/nix/nix.conf - - # shellcheck disable=SC1091 - . "${nix}/etc/profile.d/nix-daemon.sh" - } - - function setup_pipeline_scratch_dir() { - scratch_dir="/scratch/$CI_PIPELINE_ID" - - echo "Create scratch directory for pipeline: $scratch_dir" - mkdir -p "$scratch_dir" || { - echo "Could not create scratch dir '$scratch_dir'." >&2 - exit 1 - } - - export CI_CUSTOM_SCRATCH_DIR="$scratch_dir" - } - - function print_info() { - echo "Nix version:" - nix --version - } - - function main() { - print_info - setup - setup_pipeline_scratch_dir - } - - section_start gitlab-runner-prebuild "Gitlab-Runner PreBuild Script" - main "$@" - section_end gitlab-runner-prebuild - '' diff --git a/nixos/tests/gitlab/runner/podman-runner/virtualization.nix b/nixos/tests/gitlab/runner/podman-runner/virtualization.nix deleted file mode 100644 index 89a06023400d..000000000000 --- a/nixos/tests/gitlab/runner/podman-runner/virtualization.nix +++ /dev/null @@ -1,43 +0,0 @@ -{ lib, ... }: -{ - virtualisation.docker = { - enable = lib.mkForce false; - }; - - virtualisation.podman = { - enable = true; - - # Create a `docker` alias for podman, to use it as a drop-in replacement - # dockerCompat = true; - dockerSocket = { - enable = true; - }; - - # Required for containers under podman-compose to be able to talk to each other. - defaultNetwork.settings.dns_enabled = true; - - autoPrune = { - dates = "weekly"; - flags = [ - "--filter" - "label!=no-prune" - "--volumes" - "--log-level" - "debug" - ]; - }; - }; - - virtualisation.containers.storage.settings = { - storage = { - driver = "overlay"; - graphroot = "/var/lib/containers/storage"; - runroot = "/run/containers/storage"; - - # Does not work currently. - options.overlay = { - mountopt = "nodev,metacopy=on"; - }; - }; - }; -} From eb07b7d37defddbc85bd6169e07b2d5f0f2f4a1c Mon Sep 17 00:00:00 2001 From: yvnth Date: Thu, 24 Sep 2026 14:50:44 +0530 Subject: [PATCH 12/61] mangayomi: 0.9.2 -> 0.9.7 --- pkgs/by-name/ma/mangayomi/git-hashes.json | 2 +- pkgs/by-name/ma/mangayomi/package.nix | 4 +- pkgs/by-name/ma/mangayomi/pubspec.lock.json | 146 +++++++++++++++----- 3 files changed, 111 insertions(+), 41 deletions(-) diff --git a/pkgs/by-name/ma/mangayomi/git-hashes.json b/pkgs/by-name/ma/mangayomi/git-hashes.json index 5a33f28f92ed..fac1a5d0a497 100644 --- a/pkgs/by-name/ma/mangayomi/git-hashes.json +++ b/pkgs/by-name/ma/mangayomi/git-hashes.json @@ -6,7 +6,7 @@ "flutter_qjs": "sha256-sEcc87UV2xaXagv70YJO1cq9DVuck+Gq+Ch2MrZl7Zs=", "flutter_web_auth_2": "sha256-3aci73SP8eXg6++IQTQoyS+erUUuSiuXymvR32sxHFw=", "isar_community_generator": "sha256-4M5nmNvWGJK5CdK4oMrhFjOTdcGg5wo15zDruVEa97k=", - "m_extension_server": "sha256-Hi8/H3nFaY59FS9zaMRmXRV9wOgSiC5wU73X7/CUn5A=", + "m_extension_server": "sha256-TbnFcwtvZ/XvOcYCmDjIocUjKBktlwId7BB6nr3oT8c=", "media_kit": "sha256-YLMdwh9ch1C34X4McZd92WUo7lISwvK08zSGnVmZCeE=", "media_kit_libs_android_video": "sha256-YLMdwh9ch1C34X4McZd92WUo7lISwvK08zSGnVmZCeE=", "media_kit_libs_ios_video": "sha256-YLMdwh9ch1C34X4McZd92WUo7lISwvK08zSGnVmZCeE=", diff --git a/pkgs/by-name/ma/mangayomi/package.nix b/pkgs/by-name/ma/mangayomi/package.nix index 27e8c8d3cd86..263f9e25fd52 100644 --- a/pkgs/by-name/ma/mangayomi/package.nix +++ b/pkgs/by-name/ma/mangayomi/package.nix @@ -14,13 +14,13 @@ let pname = "mangayomi"; - version = "0.9.2"; + version = "0.9.7"; src = fetchFromGitHub { owner = "kodjodevf"; repo = "mangayomi"; tag = "v${version}"; - hash = "sha256-7geEJynXq2OcCLhTtm8KxvfuCagI5grCUUQ0K7jFkcY="; + hash = "sha256-5ZjyG3NRati8IWGI2QpV0Ywu9sAI4vrFGRJorH5MbQk="; }; metaCommon = { diff --git a/pkgs/by-name/ma/mangayomi/pubspec.lock.json b/pkgs/by-name/ma/mangayomi/pubspec.lock.json index 8e02c3d9e4e1..c439a1180e12 100644 --- a/pkgs/by-name/ma/mangayomi/pubspec.lock.json +++ b/pkgs/by-name/ma/mangayomi/pubspec.lock.json @@ -30,6 +30,16 @@ "source": "hosted", "version": "0.1.11" }, + "android_file_picker": { + "dependency": "transitive", + "description": { + "name": "android_file_picker", + "sha256": "014c74ab48d452c3252465682375a7fe6ddf56abb908ec361f207a3c4ffb2444", + "url": "https://pub.dev" + }, + "source": "hosted", + "version": "1.1.1" + }, "antlr4": { "dependency": "transitive", "description": { @@ -84,11 +94,11 @@ "dependency": "direct main", "description": { "name": "archive", - "sha256": "ace891da0862b0e4cabbb064ee3fd87b2728b898949fdb366d83fe98342c9f19", + "sha256": "6c5bcd986e06b94e3c40244af471750840a3d2341d1f9763a1100a14add517b4", "url": "https://pub.dev" }, "source": "hosted", - "version": "4.2.0" + "version": "4.3.0" }, "args": { "dependency": "transitive", @@ -264,11 +274,11 @@ "dependency": "direct main", "description": { "name": "code_assets", - "sha256": "bf394f466ba9205f1812a0433b392d6af280f155f56651eda7c18cc32ed493b8", + "sha256": "cfd4f5f575a49c5f10ca856e9846073f1e6c3ee94912377eea5f6cefc5272941", "url": "https://pub.dev" }, "source": "hosted", - "version": "1.2.1" + "version": "2.0.0" }, "code_builder": { "dependency": "transitive", @@ -281,7 +291,7 @@ "version": "4.11.1" }, "collection": { - "dependency": "transitive", + "dependency": "direct main", "description": { "name": "collection", "sha256": "2f5709ae4d3d59dd8f7cd309b4e023046b57d8a6c82130785d2b0e5868084e76", @@ -374,11 +384,11 @@ "dependency": "direct main", "description": { "name": "cupertino_ui", - "sha256": "7ed8ce4159d342eec4c65f4ea6eec57adaf9365404378541f38efc1da20a5b3d", + "sha256": "e9dfe7fac704028f8928cbe4028a0be5e8a709498e8daf8247de99e99a32aef3", "url": "https://pub.dev" }, "source": "hosted", - "version": "1.0.0" + "version": "1.0.2" }, "d4rt": { "dependency": "direct main", @@ -556,11 +566,11 @@ "dependency": "direct main", "description": { "name": "ffigen", - "sha256": "b7803707faeec4ce3c1b0c2274906504b796e3b70ad573577e72333bd1c9b3ba", + "sha256": "31b2ca630cede89babbbf31688d20b735967c51bf60572b06ec16718e5a7f1ec", "url": "https://pub.dev" }, "source": "hosted", - "version": "20.1.1" + "version": "22.0.0" }, "file": { "dependency": "transitive", @@ -576,11 +586,51 @@ "dependency": "direct main", "description": { "name": "file_picker", - "sha256": "fdc6a37f715d19f35b131decf1ce39242eeed5ddae18c0818c3eccb731ab76be", + "sha256": "9be6aac79508dbcf8dac80a4fb20f27ce6f910837ca27e3670b9295995cc0110", "url": "https://pub.dev" }, "source": "hosted", - "version": "12.0.0-beta.7" + "version": "12.3.0" + }, + "file_picker_darwin": { + "dependency": "transitive", + "description": { + "name": "file_picker_darwin", + "sha256": "59fa5394cfa5b6dc8bf491630cb17077b77b844adbb840df371e7be5355d6cf6", + "url": "https://pub.dev" + }, + "source": "hosted", + "version": "1.2.0" + }, + "file_picker_linux": { + "dependency": "transitive", + "description": { + "name": "file_picker_linux", + "sha256": "bd52ff1e0048f29df95f913c55ad2991c72791d93e6c42241912c4bdee946cb9", + "url": "https://pub.dev" + }, + "source": "hosted", + "version": "1.1.0" + }, + "file_picker_platform_interface": { + "dependency": "transitive", + "description": { + "name": "file_picker_platform_interface", + "sha256": "0355558fd9af6da499d18e333d6b3beb44b0bf19e00933fccd15d18eb8d0e9ca", + "url": "https://pub.dev" + }, + "source": "hosted", + "version": "3.4.0" + }, + "file_picker_web": { + "dependency": "transitive", + "description": { + "name": "file_picker_web", + "sha256": "935560a9d29fa6f006f2855addebb88e88d438e13627d4cc24187033c106f227", + "url": "https://pub.dev" + }, + "source": "hosted", + "version": "3.1.0" }, "fixnum": { "dependency": "direct main", @@ -811,11 +861,11 @@ "dependency": "direct main", "description": { "name": "flutter_secure_storage", - "sha256": "15e8c8fe269fdf7d469b23008ab3df521c8b826ed345820532364c31bdebace6", + "sha256": "d87713a152ee2f255117bdbbf43da1dea1797e0551e499e0334f0c9dcfafddd2", "url": "https://pub.dev" }, "source": "hosted", - "version": "11.0.0" + "version": "11.1.1" }, "flutter_secure_storage_darwin": { "dependency": "transitive", @@ -841,11 +891,11 @@ "dependency": "transitive", "description": { "name": "flutter_secure_storage_platform_interface", - "sha256": "788060052712555182aba55ecb5f8b6e5cb9cfe8f776c83249a61fe3ce877db4", + "sha256": "4bc033841169d07f690d46d89dbc3f5305b6562820822445384c82e0866e2719", "url": "https://pub.dev" }, "source": "hosted", - "version": "2.0.3" + "version": "2.1.0" }, "flutter_secure_storage_web": { "dependency": "transitive", @@ -964,11 +1014,11 @@ "dependency": "direct main", "description": { "name": "go_router", - "sha256": "d7a3576cb312649eaa51f2356450aed686085fb58fcdebda5b359aa951eef7ea", + "sha256": "008ab21d89d0de8ccd79586838f7533f126c2d894f50bf25f2947888d3c225b5", "url": "https://pub.dev" }, "source": "hosted", - "version": "17.5.0" + "version": "18.0.1" }, "google_fonts": { "dependency": "direct main", @@ -1104,11 +1154,11 @@ "dependency": "direct main", "description": { "name": "image", - "sha256": "1976370a4df3091bb0f72409c187ad1f9132a818bc6b95ca59c0bae1c75c688e", + "sha256": "a1e7f4951e538a568e14b856702afc9ae1d2f4b202daced8d22c1b9cd211ce89", "url": "https://pub.dev" }, "source": "hosted", - "version": "4.9.2" + "version": "4.10.1" }, "infinite_listview": { "dependency": "transitive", @@ -1386,11 +1436,11 @@ "description": { "path": ".", "ref": "HEAD", - "resolved-ref": "52dfe44bb19621a0adbd5d871d2fb47971e8ea47", + "resolved-ref": "afb3908993f0a249e6e597fbb74f719c9bdd0fcf", "url": "https://github.com/kodjodevf/m_extension_server.git" }, "source": "git", - "version": "0.0.8" + "version": "0.0.9" }, "marquee": { "dependency": "direct main", @@ -1422,6 +1472,16 @@ "source": "hosted", "version": "0.13.0" }, + "material_ui": { + "dependency": "transitive", + "description": { + "name": "material_ui", + "sha256": "fbfb53cab6c4629438feeade5f3d305f72944bc9d9f25786b19106d32b80ec45", + "url": "https://pub.dev" + }, + "source": "hosted", + "version": "1.2.0" + }, "media_kit": { "dependency": "direct main", "description": { @@ -1544,11 +1604,11 @@ "dependency": "direct main", "description": { "name": "native_toolchain_c", - "sha256": "a1c26117c48cebe5677b0cf0e33a980a79a7c5577effc86f52e5a0d309cdcb60", + "sha256": "9d233b6f2d9c52e1a2b5fbe70451d2c10ac674d3bb419d0ec8de14989d437c26", "url": "https://pub.dev" }, "source": "hosted", - "version": "0.19.3" + "version": "0.19.4" }, "nm": { "dependency": "transitive", @@ -1584,11 +1644,11 @@ "dependency": "transitive", "description": { "name": "objective_c", - "sha256": "b7fb95a6d9a4f009edd63dc5ac69f07420b23a16161c6dd8660290b59c602e8e", + "sha256": "ad56fd53a78ff6b1472fa59ff2a4e8b8ccabafc586fc263a1dfad0b99b5553e3", "url": "https://pub.dev" }, "source": "hosted", - "version": "9.5.0" + "version": "9.6.0" }, "package_config": { "dependency": "transitive", @@ -1821,6 +1881,16 @@ "source": "hosted", "version": "6.5.2" }, + "process": { + "dependency": "transitive", + "description": { + "name": "process", + "sha256": "4242ba3508d37e01808bdf71ad1d5bb93a8d671bf2e7450e6b1b353fb0808891", + "url": "https://pub.dev" + }, + "source": "hosted", + "version": "5.0.6" + }, "protobuf": { "dependency": "direct main", "description": { @@ -1885,11 +1955,11 @@ "dependency": "direct main", "description": { "name": "re_editor", - "sha256": "73e5daf7041b382c07ed707d5efd2d0a53851bb9eb6d6987260229ae0ed2f458", + "sha256": "66671c4774a6b4c5254c9a53ab35a083e7e7da9ae371c519bcf491c70a2a4e56", "url": "https://pub.dev" }, "source": "hosted", - "version": "0.9.0" + "version": "0.10.0" }, "re_highlight": { "dependency": "direct main", @@ -2100,16 +2170,6 @@ "source": "hosted", "version": "0.2.2" }, - "scrollable_positioned_list": { - "dependency": "direct main", - "description": { - "name": "scrollable_positioned_list", - "sha256": "1b54d5f1329a1e263269abc9e2543d90806131aa14fe7c6062a8054d57249287", - "url": "https://pub.dev" - }, - "source": "hosted", - "version": "0.3.8" - }, "share_plus": { "dependency": "direct main", "description": { @@ -2616,6 +2676,16 @@ "source": "hosted", "version": "0.0.4" }, + "windows_file_picker": { + "dependency": "transitive", + "description": { + "name": "windows_file_picker", + "sha256": "62e6e6e115231d1d1d71c7b5883b4091ce3e0190e49548dfb0ff8cba8d91ad96", + "url": "https://pub.dev" + }, + "source": "hosted", + "version": "1.3.0" + }, "xdg_directories": { "dependency": "transitive", "description": { @@ -2688,7 +2758,7 @@ } }, "sdks": { - "dart": ">=3.13.1 <4.0.0", + "dart": ">=3.13.4 <4.0.0", "flutter": ">=3.44.0" } } From cf2b85458db96496d79f67888ac6ab57852d985b Mon Sep 17 00:00:00 2001 From: yvnth Date: Thu, 24 Sep 2026 14:52:43 +0530 Subject: [PATCH 13/61] mangayomi: add yvnth as maintainer --- pkgs/by-name/ma/mangayomi/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/ma/mangayomi/package.nix b/pkgs/by-name/ma/mangayomi/package.nix index 263f9e25fd52..b56e34d6adb6 100644 --- a/pkgs/by-name/ma/mangayomi/package.nix +++ b/pkgs/by-name/ma/mangayomi/package.nix @@ -28,7 +28,7 @@ let description = "Reading manga, novels, and watching animes"; homepage = "https://github.com/kodjodevf/mangayomi"; license = lib.licenses.asl20; - maintainers = [ ]; + maintainers = with lib.maintainers; [ yvnth ]; platforms = lib.platforms.linux; }; From da25e48f4f395e5c1d6fa9de66a1e0353e3cf753 Mon Sep 17 00:00:00 2001 From: Karolis Stasaitis Date: Thu, 24 Sep 2026 11:27:39 +0200 Subject: [PATCH 14/61] kitty-bin: 0.49.0 -> 0.49.1 --- pkgs/by-name/ki/kitty-bin/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ki/kitty-bin/package.nix b/pkgs/by-name/ki/kitty-bin/package.nix index 4c0a9a8f0265..d6f54515c06f 100644 --- a/pkgs/by-name/ki/kitty-bin/package.nix +++ b/pkgs/by-name/ki/kitty-bin/package.nix @@ -8,14 +8,14 @@ stdenvNoCC.mkDerivation (finalAttrs: { pname = "kitty-bin"; - version = "0.49.0"; + version = "0.49.1"; __structuredAttrs = true; strictDeps = true; src = fetchurl { url = "https://github.com/kovidgoyal/kitty/releases/download/v${finalAttrs.version}/kitty-${finalAttrs.version}.dmg"; - hash = "sha256-jMIPsw6VpRQa1UNFFvyjMXcjOn9JI21DG6+c6QWD6Yw="; + hash = "sha256-0li23KsYZqm8RWxVs3VMbN9qemqT0DhHUnVnW7nyBTo="; }; nativeBuildInputs = [ _7zz ]; From 84104da134919a88d2b568c9c4e972ca84c3fb93 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 24 Sep 2026 21:21:00 +0000 Subject: [PATCH 15/61] libdwarf: 2.3.2 -> 2.3.3 --- pkgs/by-name/li/libdwarf/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libdwarf/package.nix b/pkgs/by-name/li/libdwarf/package.nix index 99f998365cca..0cd609de471a 100644 --- a/pkgs/by-name/li/libdwarf/package.nix +++ b/pkgs/by-name/li/libdwarf/package.nix @@ -11,13 +11,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "libdwarf"; - version = "2.3.2"; + version = "2.3.3"; src = fetchFromGitHub { owner = "davea42"; repo = "libdwarf-code"; tag = "v${finalAttrs.version}"; - hash = "sha256-65jEnM+eJ7HnZlpEM2D67W0Xgb9B/aa4JhajowG0Z8o="; + hash = "sha256-mO8fB369iS5l73iOB8zAqUjY8xl4PntV//2hRiirTtA="; }; nativeBuildInputs = [ From 084623396fa67de3baa449f7bf089d49c54a3c97 Mon Sep 17 00:00:00 2001 From: tree-sapii <144389458+tree-sapii@users.noreply.github.com> Date: Thu, 24 Sep 2026 19:37:53 -0400 Subject: [PATCH 16/61] cloudflared: 2026.9.1 -> 2026.9.3 --- pkgs/by-name/cl/cloudflared/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/cl/cloudflared/package.nix b/pkgs/by-name/cl/cloudflared/package.nix index 070b832ea7a5..e0137713f1f2 100644 --- a/pkgs/by-name/cl/cloudflared/package.nix +++ b/pkgs/by-name/cl/cloudflared/package.nix @@ -9,16 +9,16 @@ buildGoModule (finalAttrs: { pname = "cloudflared"; - version = "2026.9.1"; + version = "2026.9.3"; src = fetchFromGitHub { owner = "cloudflare"; repo = "cloudflared"; tag = finalAttrs.version; - hash = "sha256-w14ptM9nbfVz+8R51HOLJCGIMdQvxEQ0TsEsWcpuLZ4="; + hash = "sha256-hWU8hdIUqiwU3RfL4alL1pck0SGcbwxunv9Yw9+9xfY="; }; - vendorHash = "sha256-uqgFn1veadGiGPI75ULNZF4NoUERlCn3p6JFP+I4y6s="; + vendorHash = "sha256-mTNP7u+kCYR9rcYGJ20q7Tl/Oi6ZF/UdEfiI1C7mfpw="; ldflags = [ "-s" From b8d70ac769f73678a8e486dbc583a9aa2fc27da1 Mon Sep 17 00:00:00 2001 From: Quentin Frey <51170829+Limosine@users.noreply.github.com> Date: Fri, 25 Sep 2026 15:26:13 +0200 Subject: [PATCH 17/61] matrix-tuwunel: 1.9.2 -> 1.9.3 --- pkgs/by-name/ma/matrix-tuwunel/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ma/matrix-tuwunel/package.nix b/pkgs/by-name/ma/matrix-tuwunel/package.nix index 00c932c732b6..f7c01db606e4 100644 --- a/pkgs/by-name/ma/matrix-tuwunel/package.nix +++ b/pkgs/by-name/ma/matrix-tuwunel/package.nix @@ -89,13 +89,13 @@ let in rustPlatform.buildRustPackage (finalAttrs: { pname = "matrix-tuwunel"; - version = "1.9.2"; + version = "1.9.3"; src = fetchFromGitHub { owner = "matrix-construct"; repo = "tuwunel"; tag = "v${finalAttrs.version}"; - hash = "sha256-5X43mZamOaqRyyMChwJ966kpfCbNYBks4O8KM+3h2L4="; + hash = "sha256-29X+iSfCLo7hMvaCC/gw2zWfavC7lp3HEqTCpcBh2a0="; }; # Integration tests require networking. Only run the unit tests. @@ -104,7 +104,7 @@ rustPlatform.buildRustPackage (finalAttrs: { "--bins" ]; - cargoHash = "sha256-Jt03Xy2i0GZJcpgm35AvI+8huhidYG3FyDS1YOY2Rmw="; + cargoHash = "sha256-Oy8ymSbUNuNL8oDfnlNuZ8dUepiofE08By6hG3uLtBg="; nativeBuildInputs = [ pkg-config From 8a66a0b8fb36bf8a79c6fbf7b92d7f4dd3c6df93 Mon Sep 17 00:00:00 2001 From: Ihar Hrachyshka Date: Fri, 25 Sep 2026 10:20:24 -0400 Subject: [PATCH 18/61] element-desktop: avoid duplicating element-web https://github.com/NixOS/nixpkgs/pull/563892 added webapp.asar to satisfy electron-builder. This unintentionally left it in the app bundle (in addition to symlinked electron-web), bloating the package by ~140MB for no good reason. --- pkgs/by-name/el/element-desktop/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/el/element-desktop/package.nix b/pkgs/by-name/el/element-desktop/package.nix index 6d206b0d7faf..b658007cd006 100644 --- a/pkgs/by-name/el/element-desktop/package.nix +++ b/pkgs/by-name/el/element-desktop/package.nix @@ -112,6 +112,9 @@ stdenv.mkDerivation (finalAttrs: { asar pack tmp-app "$packed" + # element-web is linked into the output during installPhase. + find ./dist -name webapp.asar -delete + runHook postBuild ''; From ece774a34079a2d954b060603ffbf9077f000981 Mon Sep 17 00:00:00 2001 From: Lajdre Date: Fri, 25 Sep 2026 17:33:46 +0200 Subject: [PATCH 19/61] maintainers: add lajdre --- maintainers/maintainer-list.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index 2c763bbf13a4..de1ff2882613 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -15999,6 +15999,12 @@ githubId = 55911173; name = "Gwendolyn Quasebarth"; }; + lajdre = { + name = "Lajdre"; + email = "lajdre.dev@tuta.com"; + github = "lajdre"; + githubId = 110416923; + }; lajp = { email = "lajp@iki.fi"; github = "lajp"; From d298c3194148227e7ff4791ec9aeada97b63e25a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 25 Sep 2026 21:12:24 +0000 Subject: [PATCH 20/61] dblab: 0.50.0 -> 0.51.0 --- pkgs/by-name/db/dblab/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/db/dblab/package.nix b/pkgs/by-name/db/dblab/package.nix index d19807712541..566e068380e0 100644 --- a/pkgs/by-name/db/dblab/package.nix +++ b/pkgs/by-name/db/dblab/package.nix @@ -7,13 +7,13 @@ buildGoModule (finalAttrs: { pname = "dblab"; - version = "0.50.0"; + version = "0.51.0"; src = fetchFromGitHub { owner = "danvergara"; repo = "dblab"; tag = "v${finalAttrs.version}"; - hash = "sha256-cOUWl7ZWQ7iuOg3+eyKGq2jl6BVLlRmnMrftcY6H05E="; + hash = "sha256-Uwx3H4Pl1luhtln4QiURRrgj5+WERxQFkn+OVbYcs3w="; }; vendorHash = "sha256-nFgwoX2GxjRdqXcocTvz7L0NA+kN1+67uTpler8di/E="; From 285ccd7f475b0a47c15cda12330f08c2ce139444 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 25 Sep 2026 21:53:57 +0000 Subject: [PATCH 21/61] nerdctl: 2.3.5 -> 2.4.0 --- pkgs/by-name/ne/nerdctl/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ne/nerdctl/package.nix b/pkgs/by-name/ne/nerdctl/package.nix index 027c35db6de4..dc8b0d0270ef 100644 --- a/pkgs/by-name/ne/nerdctl/package.nix +++ b/pkgs/by-name/ne/nerdctl/package.nix @@ -14,16 +14,16 @@ buildGoModule (finalAttrs: { pname = "nerdctl"; - version = "2.3.5"; + version = "2.4.0"; src = fetchFromGitHub { owner = "containerd"; repo = "nerdctl"; tag = "v${finalAttrs.version}"; - hash = "sha256-4t6yyoFnYm5rGNw8SG1nfy5C0+nks/9G8pzhuZ4U0ag="; + hash = "sha256-2TSuLeG82CIIiR/koGJRiGNm4RpdOPlIZhiYB7NupUs="; }; - vendorHash = "sha256-hjqtwOph1grdmR2kHIbBVCxuNxNnUHPH8RJSCXo0rvU="; + vendorHash = "sha256-3FiGGr6m9HdXt1oFLLqDwakq0z0i4ZfwZEBWNd0RRQM="; nativeBuildInputs = [ makeWrapper From bd77871aba73759a0ff051fba5f9880c0e5047a0 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 25 Sep 2026 22:11:12 +0000 Subject: [PATCH 22/61] llmfit: 1.1.15 -> 1.1.16 --- pkgs/by-name/ll/llmfit/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ll/llmfit/package.nix b/pkgs/by-name/ll/llmfit/package.nix index 2da65a30b9ec..8931125d0b1d 100644 --- a/pkgs/by-name/ll/llmfit/package.nix +++ b/pkgs/by-name/ll/llmfit/package.nix @@ -8,7 +8,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "llmfit"; - version = "1.1.15"; + version = "1.1.16"; __structuredAttrs = true; @@ -16,10 +16,10 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "AlexsJones"; repo = "llmfit"; tag = "v${finalAttrs.version}"; - hash = "sha256-rAlWEpoHuh03sU+Ma9LqvjNMq8/1x8e0MAQRmt4etk4="; + hash = "sha256-EMCtdgfR4y9+UY3byg+jYUhkcWpt1ZU8/CIOHnMY3UQ="; }; - cargoHash = "sha256-RN5f0TGnhi2FrekmVmEYONU59g+akuewwCOj6kfcBjw="; + cargoHash = "sha256-aQEThRrqTh4m3KMJqCU4vcMGrQiIR23yiSibTIAywB8="; nativeInstallCheckInputs = [ versionCheckHook ]; doInstallCheck = true; From fb37e8e8bd6c8c6dd73434e565271239f27add27 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Wed, 23 Sep 2026 18:05:56 -0400 Subject: [PATCH 23/61] workflows/*: use self-repository syntax --- .github/actions/checkout/action.yml | 9 ++++++++- .github/workflows/build.yml | 6 +----- .github/workflows/check.yml | 14 ++------------ .github/workflows/eval.yml | 18 +++--------------- .github/workflows/lint.yml | 18 +++--------------- .github/workflows/merge-group.yml | 8 ++++---- .github/workflows/periodic-merge-24h.yml | 2 +- .github/workflows/periodic-merge-6h.yml | 2 +- .github/workflows/pull-request-target.yml | 10 +++++----- .github/workflows/test.yml | 4 ++-- 10 files changed, 30 insertions(+), 61 deletions(-) diff --git a/.github/actions/checkout/action.yml b/.github/actions/checkout/action.yml index 91cca324fcd4..ab8c663e0f0e 100644 --- a/.github/actions/checkout/action.yml +++ b/.github/actions/checkout/action.yml @@ -13,6 +13,13 @@ inputs: runs: using: composite steps: + # We don't actually need anything in this directory, but we need a small + # sparse checkout, and this directory is small. + - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + with: + persist-credentials: false + sparse-checkout: .github/actions + - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: MERGED_SHA: ${{ inputs.merged-as-untrusted-at }} @@ -37,7 +44,7 @@ runs: }) } - // These are set automatically by the spare checkout for .github/actions. + // These are set automatically by the sparse checkout for .github/actions. // Undo them, otherwise git fetch below will not do anything. await run('git', 'config', 'unset', 'remote.origin.promisor') await run('git', 'config', 'unset', 'remote.origin.partialclonefilter') diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index b7ba21272be1..c85a3989219e 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -49,12 +49,8 @@ jobs: runs-on: ${{ matrix.runner }} timeout-minutes: 60 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Checkout the merge commit - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} target-as-trusted-at: ${{ inputs.targetSha }} diff --git a/.github/workflows/check.yml b/.github/workflows/check.yml index faff91d48e6c..84c34887b7f3 100644 --- a/.github/workflows/check.yml +++ b/.github/workflows/check.yml @@ -190,13 +190,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 5 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - - name: Checkout merge and target commits - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} target-as-trusted-at: ${{ inputs.targetSha }} @@ -219,13 +214,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 5 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - - name: Checkout merge and target commits - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} target-as-trusted-at: ${{ inputs.targetSha }} diff --git a/.github/workflows/eval.yml b/.github/workflows/eval.yml index 61d8b60d2bab..f971aa0229da 100644 --- a/.github/workflows/eval.yml +++ b/.github/workflows/eval.yml @@ -174,12 +174,8 @@ jobs: sudo mkswap /swap sudo swapon /swap - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Check out the PR at merged and target commits - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: # For versioned evals, use the target as the untrusted base and apply the pin-bump commit merged-as-untrusted-at: ${{ matrix.version && inputs.targetSha || inputs.mergedSha }} @@ -259,12 +255,8 @@ jobs: statuses: write # creating 'Eval Summary' commit statuses timeout-minutes: 5 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Check out the PR at the target commit - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} target-as-trusted-at: ${{ inputs.targetSha }} @@ -477,12 +469,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 10 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Checkout the merge commit - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index b90840319c5b..faa978b13227 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -26,12 +26,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 10 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Checkout the merge commit - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} @@ -61,12 +57,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 10 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Checkout the merge commit - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} @@ -90,12 +82,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 10 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Checkout merge and target commits - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} target-as-trusted-at: ${{ inputs.targetSha }} diff --git a/.github/workflows/merge-group.yml b/.github/workflows/merge-group.yml index 1156c2a616eb..e111c35ca7c8 100644 --- a/.github/workflows/merge-group.yml +++ b/.github/workflows/merge-group.yml @@ -63,7 +63,7 @@ jobs: check: name: Check needs: [prepare] - uses: ./.github/workflows/check.yml + uses: $/.github/workflows/check.yml permissions: pull-requests: write # cherry-picks: unused in merge queue but required for check workflow secrets: @@ -75,7 +75,7 @@ jobs: lint: name: Lint needs: [prepare] - uses: ./.github/workflows/lint.yml + uses: $/.github/workflows/lint.yml secrets: CACHIX_AUTH_TOKEN_GHA: ${{ secrets.CACHIX_AUTH_TOKEN_GHA }} with: @@ -85,7 +85,7 @@ jobs: eval: name: Eval needs: [prepare] - uses: ./.github/workflows/eval.yml + uses: $/.github/workflows/eval.yml # The eval workflow requests these permissions so we must explicitly allow them, # even though they are unused when working with the merge queue. permissions: @@ -103,7 +103,7 @@ jobs: build: name: Build needs: [prepare] - uses: ./.github/workflows/build.yml + uses: $/.github/workflows/build.yml secrets: CACHIX_AUTH_TOKEN_GHA: ${{ secrets.CACHIX_AUTH_TOKEN_GHA }} with: diff --git a/.github/workflows/periodic-merge-24h.yml b/.github/workflows/periodic-merge-24h.yml index d14c482df755..c6e31f737b6e 100644 --- a/.github/workflows/periodic-merge-24h.yml +++ b/.github/workflows/periodic-merge-24h.yml @@ -40,7 +40,7 @@ jobs: - name: merge-base(master,staging) → haskell-updates from: master staging into: haskell-updates - uses: ./.github/workflows/periodic-merge.yml + uses: $/.github/workflows/periodic-merge.yml with: from: ${{ matrix.pairs.from }} into: ${{ matrix.pairs.into }} diff --git a/.github/workflows/periodic-merge-6h.yml b/.github/workflows/periodic-merge-6h.yml index ad81eb6c9a3b..0da0a3336364 100644 --- a/.github/workflows/periodic-merge-6h.yml +++ b/.github/workflows/periodic-merge-6h.yml @@ -37,7 +37,7 @@ jobs: into: staging - from: master into: staging-nixos - uses: ./.github/workflows/periodic-merge.yml + uses: $/.github/workflows/periodic-merge.yml with: from: ${{ matrix.pairs.from }} into: ${{ matrix.pairs.into }} diff --git a/.github/workflows/pull-request-target.yml b/.github/workflows/pull-request-target.yml index aa42175a0cc1..98d463cb588d 100644 --- a/.github/workflows/pull-request-target.yml +++ b/.github/workflows/pull-request-target.yml @@ -75,7 +75,7 @@ jobs: check: name: Check needs: [prepare] - uses: ./.github/workflows/check.yml + uses: $/.github/workflows/check.yml permissions: # cherry-picks pull-requests: write @@ -92,7 +92,7 @@ jobs: lint: name: Lint needs: [prepare] - uses: ./.github/workflows/lint.yml + uses: $/.github/workflows/lint.yml with: mergedSha: ${{ needs.prepare.outputs.mergedSha }} targetSha: ${{ needs.prepare.outputs.targetSha }} @@ -100,7 +100,7 @@ jobs: eval: name: Eval needs: [prepare] - uses: ./.github/workflows/eval.yml + uses: $/.github/workflows/eval.yml permissions: # compare pull-requests: write @@ -119,7 +119,7 @@ jobs: bot: name: Bot needs: [prepare, eval] - uses: ./.github/workflows/bot.yml + uses: $/.github/workflows/bot.yml permissions: issues: write pull-requests: write @@ -131,7 +131,7 @@ jobs: build: name: Build needs: [prepare] - uses: ./.github/workflows/build.yml + uses: $/.github/workflows/build.yml with: artifact-prefix: ${{ inputs.artifact-prefix }} baseBranch: ${{ needs.prepare.outputs.baseBranch }} diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index ad1aaed202ff..35208ae4fab2 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -103,7 +103,7 @@ jobs: if: needs.prepare.outputs.merge-group name: Merge Group needs: [prepare] - uses: ./.github/workflows/merge-group.yml + uses: $/.github/workflows/merge-group.yml # Those are actually only used on the merge_group event, but will throw an error if not set. permissions: pull-requests: write # unused on pull_request, required by merge-group workflow @@ -117,7 +117,7 @@ jobs: if: needs.prepare.outputs.pr name: PR needs: [prepare] - uses: ./.github/workflows/pull-request-target.yml + uses: $/.github/workflows/pull-request-target.yml # Those are actually only used on the pull_request_target event, but will throw an error if not set. permissions: issues: write # unused on pull_request, required by bot workflow From d61db5aa6b86df0e8cdd242dc7eb5c8909d0be74 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Fri, 25 Sep 2026 21:03:08 -0400 Subject: [PATCH 24/61] ci/pinned.json: update [nixpkgs-26.05-darwin] Changes: - revision: 51fe96f9107566e6b8eeb7fc4ba696c01e548b04 + revision: 7486293a941f7b0ec123f0c431517027f705f60f - url: https://github.com/NixOS/nixpkgs/archive/51fe96f9107566e6b8eeb7fc4ba696c01e548b04.tar.gz + url: https://github.com/NixOS/nixpkgs/archive/7486293a941f7b0ec123f0c431517027f705f60f.tar.gz - hash: sha256-yj0LPLnsmYoLmA3FGANjeTEwej0/DHjZBXWnDQDUuIs= + hash: sha256-WQhNWIW3PPijuZexyl5Zf0tJuQ7sKt5C9WPXVO4pMuM= [nixpkgs] Changes: - revision: 7525d999cd850b9a488817abc89c75dc733acf17 + revision: 7d5589bbf421c7b6f4185371abe3c465b1b557e9 - url: https://github.com/NixOS/nixpkgs/archive/7525d999cd850b9a488817abc89c75dc733acf17.tar.gz + url: https://github.com/NixOS/nixpkgs/archive/7d5589bbf421c7b6f4185371abe3c465b1b557e9.tar.gz - hash: sha256-4IHyyLgLBdKefkljdKod4IMn023pQiDXAWJA187cmdY= + hash: sha256-8emM5Z42GzMSLLvjJt7UkX1j2k2TKXQIS7FnPTfeHno= --- ci/pinned.json | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/ci/pinned.json b/ci/pinned.json index 32f5e186650c..a30aff6f92f8 100644 --- a/ci/pinned.json +++ b/ci/pinned.json @@ -9,9 +9,9 @@ }, "branch": "nixpkgs-unstable", "submodules": false, - "revision": "7525d999cd850b9a488817abc89c75dc733acf17", - "url": "https://github.com/NixOS/nixpkgs/archive/7525d999cd850b9a488817abc89c75dc733acf17.tar.gz", - "hash": "sha256-4IHyyLgLBdKefkljdKod4IMn023pQiDXAWJA187cmdY=" + "revision": "7d5589bbf421c7b6f4185371abe3c465b1b557e9", + "url": "https://github.com/NixOS/nixpkgs/archive/7d5589bbf421c7b6f4185371abe3c465b1b557e9.tar.gz", + "hash": "sha256-8emM5Z42GzMSLLvjJt7UkX1j2k2TKXQIS7FnPTfeHno=" }, "nixpkgs-26.05-darwin": { "type": "Git", @@ -22,9 +22,9 @@ }, "branch": "nixpkgs-26.05-darwin", "submodules": false, - "revision": "51fe96f9107566e6b8eeb7fc4ba696c01e548b04", - "url": "https://github.com/NixOS/nixpkgs/archive/51fe96f9107566e6b8eeb7fc4ba696c01e548b04.tar.gz", - "hash": "sha256-yj0LPLnsmYoLmA3FGANjeTEwej0/DHjZBXWnDQDUuIs=" + "revision": "7486293a941f7b0ec123f0c431517027f705f60f", + "url": "https://github.com/NixOS/nixpkgs/archive/7486293a941f7b0ec123f0c431517027f705f60f.tar.gz", + "hash": "sha256-WQhNWIW3PPijuZexyl5Zf0tJuQ7sKt5C9WPXVO4pMuM=" } }, "version": 8 From b7395edf46d458ea7c95c1b0e71ff21d0307df9f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 26 Sep 2026 01:05:37 +0000 Subject: [PATCH 25/61] sub-store-frontend: 2.32.2 -> 2.34.0 --- pkgs/by-name/su/sub-store-frontend/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/su/sub-store-frontend/package.nix b/pkgs/by-name/su/sub-store-frontend/package.nix index 77829b5c17cc..f72b225d21bd 100644 --- a/pkgs/by-name/su/sub-store-frontend/package.nix +++ b/pkgs/by-name/su/sub-store-frontend/package.nix @@ -14,13 +14,13 @@ let in buildNpmPackage (finalAttrs: { pname = "sub-store-frontend"; - version = "2.32.2"; + version = "2.34.0"; src = fetchFromGitHub { owner = "sub-store-org"; repo = "Sub-Store-Front-End"; tag = finalAttrs.version; - hash = "sha256-TbKJNSA+ivUd7bHDtE9COaZFMqxRkRdBXWkK7y7JMSU="; + hash = "sha256-jphgUjJouLky6jxTSk+6YBbwaNTV7+/oTu2RXc3UNk0="; }; nativeBuildInputs = [ From 53bc4d6aa3a65bd08347344fa05c4d680a9d3088 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Fri, 25 Sep 2026 21:21:45 -0400 Subject: [PATCH 26/61] various: fix formatting --- nixos/modules/hardware/facter/camera/ipu6.nix | 2 +- nixos/modules/services/x11/desktop-managers/xfce.nix | 6 +++--- nixos/tests/moduleStateRevisions.nix | 2 +- pkgs/build-support/dart/pub2nix/pubspec-lock.nix | 2 +- pkgs/by-name/in/iniparser/package.nix | 6 +++--- pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix | 6 +++--- 6 files changed, 12 insertions(+), 12 deletions(-) diff --git a/nixos/modules/hardware/facter/camera/ipu6.nix b/nixos/modules/hardware/facter/camera/ipu6.nix index 5319d8bf3d49..799c22188824 100644 --- a/nixos/modules/hardware/facter/camera/ipu6.nix +++ b/nixos/modules/hardware/facter/camera/ipu6.nix @@ -66,7 +66,7 @@ let in bus_type.name == "PCI" && devices - ? "${vendorHex}:${deviceHex}:${subVendorHex}:${subDeviceHex}/${baseClassHex}-${subClassHex}-${revisionHex}" + ? "${vendorHex}:${deviceHex}:${subVendorHex}:${subDeviceHex}/${baseClassHex}-${subClassHex}-${revisionHex}" ); in { diff --git a/nixos/modules/services/x11/desktop-managers/xfce.nix b/nixos/modules/services/x11/desktop-managers/xfce.nix index 332c78b3658a..d448f10cdfa8 100644 --- a/nixos/modules/services/x11/desktop-managers/xfce.nix +++ b/nixos/modules/services/x11/desktop-managers/xfce.nix @@ -209,9 +209,9 @@ in DesktopNames=XFCE Keywords=xfce;wayland;desktop;environment;session; '').overrideAttrs - (_: { - passthru.providedSessions = [ "xfce-wayland" ]; - }) + (_: { + passthru.providedSessions = [ "xfce-wayland" ]; + }) ) ]; diff --git a/nixos/tests/moduleStateRevisions.nix b/nixos/tests/moduleStateRevisions.nix index 3bce4c312488..9b2cc98dc715 100644 --- a/nixos/tests/moduleStateRevisions.nix +++ b/nixos/tests/moduleStateRevisions.nix @@ -15,7 +15,7 @@ let testModule = path: evalModuleStateRevisions (lib.setAttrByPath path { enable = true; }) - ? "${builtins.concatStringsSep "." path}.stateRevision"; + ? "${builtins.concatStringsSep "." path}.stateRevision"; in assert evalModuleStateRevisions { } == { }; assert testModule [ diff --git a/pkgs/build-support/dart/pub2nix/pubspec-lock.nix b/pkgs/build-support/dart/pub2nix/pubspec-lock.nix index 73788f535a90..2a6973c90043 100644 --- a/pkgs/build-support/dart/pub2nix/pubspec-lock.nix +++ b/pkgs/build-support/dart/pub2nix/pubspec-lock.nix @@ -151,7 +151,7 @@ let "sdk" = mkSdkDependencySource; } .${details.source} - name + name ) details )) diff --git a/pkgs/by-name/in/iniparser/package.nix b/pkgs/by-name/in/iniparser/package.nix index 3d1a5af3a3f4..f02b029cee4e 100644 --- a/pkgs/by-name/in/iniparser/package.nix +++ b/pkgs/by-name/in/iniparser/package.nix @@ -54,9 +54,9 @@ stdenv.mkDerivation (finalAttrs: { (unity-test.override { supportDouble = true; }).overrideAttrs - { - doCheck = false; - } + { + doCheck = false; + } ) ]; diff --git a/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix b/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix index 80dad06be8f8..a5220d11a2fa 100644 --- a/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix +++ b/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix @@ -28,9 +28,9 @@ runCommand "${pname}-filtered-src" enableOpenSSL = false; enableLZ4 = false; }).overrideAttrs - { - doCheck = false; - } + { + doCheck = false; + } ) ]; } From 69945735936247442f2defa8dca713dccf1a41e7 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 26 Sep 2026 02:40:06 +0000 Subject: [PATCH 27/61] step-cli: 0.30.6 -> 0.31.0 --- pkgs/by-name/st/step-cli/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/st/step-cli/package.nix b/pkgs/by-name/st/step-cli/package.nix index 10ae33e4cf52..dac4a0e10a5a 100644 --- a/pkgs/by-name/st/step-cli/package.nix +++ b/pkgs/by-name/st/step-cli/package.nix @@ -8,7 +8,7 @@ unixtools, }: let - version = "0.30.6"; + version = "0.31.0"; in buildGoModule { pname = "step-cli"; @@ -18,7 +18,7 @@ buildGoModule { owner = "smallstep"; repo = "cli"; tag = "v${version}"; - hash = "sha256-fMHvv14ToKq73h3aLJBebzhIJQghfBOX6C0hvDODHN8="; + hash = "sha256-v8insc/+vnc4JVNeHeF3UU+rYdNtMeQkdWxVc+vq7ms="; # this file change depending on git branch status (via .gitattributes) # https://github.com/NixOS/nixpkgs/issues/84312 postFetch = '' @@ -39,7 +39,7 @@ buildGoModule { patchShebangs integration/openssl-jwt.sh ''; - vendorHash = "sha256-DTFp9K5iiS50QuD2knN/8miYb2k/7O1d3GyEf79i69Q="; + vendorHash = "sha256-UNrUy0aWl7w5SmlsxLpmx6WxI2AElHE6llAMLRLi0r0="; nativeBuildInputs = [ installShellFiles ]; nativeCheckInputs = [ From 3b6c99011c84d10d2171e773e41ef715e26d5975 Mon Sep 17 00:00:00 2001 From: Markus Hauck Date: Sat, 26 Sep 2026 08:20:46 +0200 Subject: [PATCH 28/61] claude-code: 2.1.281 -> 2.1.283 Changelog: https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md Assisted-by: Claude Code (Claude Opus 5.5) --- pkgs/by-name/cl/claude-code/manifest.zst.json | 54 +++++++++---------- 1 file changed, 27 insertions(+), 27 deletions(-) diff --git a/pkgs/by-name/cl/claude-code/manifest.zst.json b/pkgs/by-name/cl/claude-code/manifest.zst.json index d7c4c6b3d738..cae90932dfdc 100644 --- a/pkgs/by-name/cl/claude-code/manifest.zst.json +++ b/pkgs/by-name/cl/claude-code/manifest.zst.json @@ -1,63 +1,61 @@ { - "version": "2.1.281", + "version": "2.1.283", "manifestSignatureEnforcement": "flag", - "commit": "3e320108de6831eb996e9a3f7795152073cc0d0c", - "modsCommit": "56f36532530f88b572854538d685fcf781141e8c", - "buildDate": "2026-09-23T02:34:19Z", + "commit": "4631ccd7cfe41e69bc72d3b5b9dc7282536e4985", + "modsCommit": "684ffc4da0eaaddcafa61842dc719c6a8febc5c2", + "buildDate": "2026-09-25T01:40:44Z", "platforms": { "darwin-arm64": { "binary": "claude.zst", - "checksum": "056662a4e3a5ca37770730a59345d1b5796ef65444c32b97d236651ab68f3fa1", - "size": 74110572, + "checksum": "485d6883c023368800626e0d1f2e4382c3e1bdc760fae12cb2f6e3054f218eec", + "size": 75461598, "bundle": { - "checksum": "01c192d55a6fa8fcc84557bbd913dfb43ae65f15c39bd1fba9161fc4ff7de175", - "size": 74115578 + "checksum": "f22ac793e83fbaa4ec74a1194c98c4f9c8cd808cfa2a238aecb561a342420b3e", + "size": 75465975 } }, "darwin-x64": { "binary": "claude.zst", - "checksum": "085dd9952999c742cf262d0fed571c3bcd749d5127eb7dd455bc5be0948c7b9d", - "size": 78229557, + "checksum": "2ac2ccd98433c2727de1b7142dd808f355e7764fa573ab891666f496a3a669ee", + "size": 79614241, "bundle": { - "checksum": "05e821e3c9f1178b603c6f7fcb3e05b1a038f885cb55eed42ad8df9bbfc7fdad", - "size": 78233701 + "checksum": "7a9ef7b6b7ccdb343c3c2c160efc1984bda9f9f446bca97603008cfdfe99835f", + "size": 79613206 } }, "linux-arm64": { "binary": "claude.zst", - "checksum": "7583b65585561c714e18caca45e0e0fb9bdba6d7ed6ee5d5171834d5c657aea6", - "size": 83227605 + "checksum": "7ff80952f5cf74fa593432ec19fc7bef1b4461b365092fe2b6c6060d4fbad1ec", + "size": 84571156 }, "linux-x64": { "binary": "claude.zst", - "checksum": "4ffb9f6baada4d88bbd8c586773efd0605c524c7a31cc3833eeda229717a7b25", - "size": 83964259 + "checksum": "94345861e88be3d67a8393494f98f5b1c67604c14ccd4ef3c7a51e3643fa25eb", + "size": 85309419 }, "linux-arm64-musl": { "binary": "claude.zst", - "checksum": "b5400b7f787e78f6c206c1adf70c65b5b6835f2899b61edfa83a117be92111d5", - "size": 81645720 + "checksum": "12ab758aca002744a1364328536d0b30d510707262d9eb116390a14b269a3c79", + "size": 82977461 }, "linux-x64-musl": { "binary": "claude.zst", - "checksum": "3921fd07a12e93f858c8b706eca0e4d7b12af14f4af5378d3b87254b4231def5", - "size": 82393109 + "checksum": "118b07bbe50b9ca5ab303ed070fb5d065696c413ae62f9dc1c8f64f2c9d824ec", + "size": 83744817 }, "win32-x64": { "binary": "claude.exe.zst", - "checksum": "62f544612ca7e31cdc197bdf8651abcc529bd716964d2517e101177c6b94c70a", - "size": 86264937 + "checksum": "b201734251f1d6470a65453192422d1b03d6f3a5c1365b43dc7d2b65cd135233", + "size": 87607368 }, "win32-arm64": { "binary": "claude.exe.zst", - "checksum": "41b632497a440de03904c03483d000b4004b908a5f3eb71f139de6dbd40cd685", - "size": 82711371 + "checksum": "302ac016e1f3487b87945596388d38cf9b2974597375ec24447278d5019e7c6e", + "size": 83948914 } }, "sdkCompat": { "testedWrapperVersions": [ - "0.3.241", - "0.3.242", "0.3.243", "0.3.245", "0.3.246", @@ -72,6 +70,7 @@ "0.3.260", "0.3.261", "0.3.263", + "0.3.265", "0.3.266", "0.3.267", "0.3.268", @@ -85,7 +84,8 @@ "0.3.276", "0.3.277", "0.3.278", - "0.3.280" + "0.3.280", + "0.3.281" ], "harnessSchema": 1 } From 043287a5708ce6a52c285957fe433716ce8f3adc Mon Sep 17 00:00:00 2001 From: Markus Hauck Date: Sat, 26 Sep 2026 08:20:46 +0200 Subject: [PATCH 29/61] vscode-extensions.anthropic.claude-code: 2.1.281 -> 2.1.283 Changelog: https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md Assisted-by: Claude Code (Claude Opus 5.5) --- .../vscode/extensions/anthropic.claude-code/default.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/applications/editors/vscode/extensions/anthropic.claude-code/default.nix b/pkgs/applications/editors/vscode/extensions/anthropic.claude-code/default.nix index e0e20ba34234..8b0326a3cb3f 100644 --- a/pkgs/applications/editors/vscode/extensions/anthropic.claude-code/default.nix +++ b/pkgs/applications/editors/vscode/extensions/anthropic.claude-code/default.nix @@ -21,22 +21,22 @@ vscode-utils.buildVscodeMarketplaceExtension (finalAttrs: { sources = { "x86_64-linux" = { arch = "linux-x64"; - hash = "sha256-pXzLJ/1g33JUorADMf0EzvI7DY2kbAZSnkttPY5ekOs="; + hash = "sha256-yUrFhJa/DkAQXH/0EZ3N0axloCNtrPvaFfmJ5/bnqRg="; }; "aarch64-linux" = { arch = "linux-arm64"; - hash = "sha256-CEKNRiYs8Grko5nVGSanAgj5WmLC7hnMBC9OXElrmoQ="; + hash = "sha256-2L5+MZNnBraXmX4npH1/aLlU+uBRsGEKdpAZ6kh7krc="; }; "aarch64-darwin" = { arch = "darwin-arm64"; - hash = "sha256-eu+5zAGdzFsx/PeAgCj60ppP0CMQEsZGaVlR+8OfFbQ="; + hash = "sha256-Ztzy6ZrqdhCy/bd+zAxGaq07KZBKHS4GMGTAe62Dxk8="; }; }; in { name = "claude-code"; publisher = "anthropic"; - version = "2.1.281"; + version = "2.1.283"; } // sources.${stdenvNoCC.hostPlatform.system} or (throw "Unsupported system ${stdenvNoCC.hostPlatform.system}"); From 88d393ffbabdccbd01acfa68fb9a624875c8fd7c Mon Sep 17 00:00:00 2001 From: Matthias Beyer Date: Sat, 26 Sep 2026 10:02:30 +0200 Subject: [PATCH 30/61] llmfit: Skip tests that rely on system stuff Signed-off-by: Matthias Beyer --- pkgs/by-name/ll/llmfit/package.nix | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/pkgs/by-name/ll/llmfit/package.nix b/pkgs/by-name/ll/llmfit/package.nix index 8931125d0b1d..7afde4ba9bea 100644 --- a/pkgs/by-name/ll/llmfit/package.nix +++ b/pkgs/by-name/ll/llmfit/package.nix @@ -26,6 +26,13 @@ rustPlatform.buildRustPackage (finalAttrs: { passthru.updateScript = nix-update-script { }; + # These seem to rely on system state that we do not have inside nix builds + checkFlags = [ + "--skip=json_apple_gpu_skips_successful_text_probe" + "--skip=json_apple_gpu_survives_failed_text_probe" + "--skip=text_probe_recovers_when_json_fails" + ]; + meta = { description = "TUI to find LLM models right sized for the system's RAM, CPU, and GPU"; homepage = "https://github.com/AlexsJones/llmfit"; From 039a9aa75465b26596d42d3878c6caead9ef7b45 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 26 Sep 2026 08:08:53 +0000 Subject: [PATCH 31/61] peazip: 11.2.0 -> 11.3.0 --- pkgs/by-name/pe/peazip/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/pe/peazip/package.nix b/pkgs/by-name/pe/peazip/package.nix index 1793baac82cd..db1114ec613e 100644 --- a/pkgs/by-name/pe/peazip/package.nix +++ b/pkgs/by-name/pe/peazip/package.nix @@ -24,13 +24,13 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "peazip"; - version = "11.2.0"; + version = "11.3.0"; src = fetchFromGitHub { owner = "peazip"; repo = "peazip"; rev = finalAttrs.version; - hash = "sha256-zaadYVbeNhlHl/2g7yldG4ZlyL2DEyzwODvomuCBSkE="; + hash = "sha256-NeFfXFsDYpRHPrIZGkJMvplYxsTw+QzQ33TJzgyDZ+c="; }; sourceRoot = "${finalAttrs.src.name}/peazip-sources"; From cb0296095bd85bf7c180e12f30015358985684f6 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 26 Sep 2026 11:29:06 +0000 Subject: [PATCH 32/61] apm-cli: 0.29.0 -> 0.32.0 --- pkgs/by-name/ap/apm-cli/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ap/apm-cli/package.nix b/pkgs/by-name/ap/apm-cli/package.nix index 12430503cde0..60f0eab8b7b9 100644 --- a/pkgs/by-name/ap/apm-cli/package.nix +++ b/pkgs/by-name/ap/apm-cli/package.nix @@ -7,7 +7,7 @@ python3Packages.buildPythonApplication (finalAttrs: { pname = "apm-cli"; - version = "0.29.0"; + version = "0.32.0"; pyproject = true; __structuredAttrs = true; @@ -16,7 +16,7 @@ python3Packages.buildPythonApplication (finalAttrs: { owner = "microsoft"; repo = "apm"; tag = "v${finalAttrs.version}"; - hash = "sha256-0aVqPRRaVjV3qoE+Fh3L98HUmBlAtu3pMiTSxVDj4Ak="; + hash = "sha256-yGgLFNwvJkZx0yX8PtUjeg/XdCYBD7YRb0OXoA8knno="; }; postPatch = '' From 9324ab88f2a23ca21b28b84fe3de161b21402098 Mon Sep 17 00:00:00 2001 From: Lajdre Date: Fri, 25 Sep 2026 17:43:57 +0200 Subject: [PATCH 33/61] tern: init at 2.4.3 --- pkgs/by-name/te/tern/package.nix | 68 ++++++++++++++++++++++++++++++++ 1 file changed, 68 insertions(+) create mode 100644 pkgs/by-name/te/tern/package.nix diff --git a/pkgs/by-name/te/tern/package.nix b/pkgs/by-name/te/tern/package.nix new file mode 100644 index 000000000000..230d7756a70e --- /dev/null +++ b/pkgs/by-name/te/tern/package.nix @@ -0,0 +1,68 @@ +{ + lib, + buildGoModule, + fetchFromGitHub, + nix-update-script, + versionCheckHook, + postgresql, + postgresqlTestHook, +}: + +buildGoModule (finalAttrs: { + pname = "tern"; + version = "2.4.3"; + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "jackc"; + repo = "tern"; + tag = "v${finalAttrs.version}"; + hash = "sha256-K76TowSW1bdyqVoZdlnqXV2Jlk9exMS2D/keE/9buFc="; + }; + + vendorHash = "sha256-rUPJTwGdZABZxEjON7JeB38GDpV+KN7VfbNyU//SadM="; + + nativeCheckInputs = [ + postgresql + postgresqlTestHook + ]; + + # Tests drop/recreate the database via dropdb/createdb + postgresqlTestUserOptions = "LOGIN CREATEDB"; + + # Sets variables read by tests that are normally set by tern's + # scripts/dev-env.bash + postgresqlTestSetupPost = '' + # tern uses a separate database for the migration tests, because go test + # runs the root and migrate package tests in parallel, and the migrate + # tests drop/recreate their database + export MIGRATE_TEST_DATABASE=test_db_migrate + createdb "$MIGRATE_TEST_DATABASE" + export MIGRATE_TEST_CONN_STRING="host=$PGHOST user=$PGUSER database=$MIGRATE_TEST_DATABASE sslmode=disable" + + export TERN_TEST_CONFIG=$NIX_BUILD_TOP/tern-test.conf + export TERN_TEST_CONN_STRING="host=$PGHOST user=$PGUSER database=$PGDATABASE sslmode=disable" + cat << EOF > "$TERN_TEST_CONFIG" + [database] + host = $PGHOST + user = $PGUSER + database = $PGDATABASE + sslmode = disable + EOF + ''; + + doInstallCheck = true; + nativeInstallCheckInputs = [ versionCheckHook ]; + versionCheckProgramArg = "version"; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "Standalone PostgreSQL database migration tool"; + homepage = "https://github.com/jackc/tern"; + changelog = "https://github.com/jackc/tern/releases/tag/${finalAttrs.src.tag}"; + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ lajdre ]; + mainProgram = "tern"; + }; +}) From a9468d53e3ba64fd551aca52deccce68110a382a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 26 Sep 2026 08:44:32 +0000 Subject: [PATCH 34/61] python3Packages.evosax: 0.2.0 -> 0.3.1 --- .../python-modules/evosax/default.nix | 20 +++++++++---------- 1 file changed, 10 insertions(+), 10 deletions(-) diff --git a/pkgs/development/python-modules/evosax/default.nix b/pkgs/development/python-modules/evosax/default.nix index e0de3f633427..66aa3647a67b 100644 --- a/pkgs/development/python-modules/evosax/default.nix +++ b/pkgs/development/python-modules/evosax/default.nix @@ -14,24 +14,24 @@ numpy, # tests - # brax, (unpackaged) - # gymnax, (unpackaged) + brax, pytestCheckHook, torch, torchvision, writableTmpDirAsHomeHook, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "evosax"; - version = "0.2.0"; + version = "0.3.1"; pyproject = true; + __structuredAttrs = true; src = fetchFromGitHub { owner = "RobertTLange"; repo = "evosax"; - tag = "v.${version}"; - hash = "sha256-ye5IHM8Pn/+BXI9kcB3W281Gna9hXV8DwsaJ9Xu06fU="; + tag = "v.${finalAttrs.version}"; + hash = "sha256-iuhqlpwU4puAxzepXAixpBrLajkGNgBxXijwoNX36+8="; }; build-system = [ setuptools ]; @@ -47,8 +47,8 @@ buildPythonPackage rec { pythonImportsCheck = [ "evosax" ]; nativeCheckInputs = [ - # brax - # gymnax + brax + # gymnax (unpackaged) pytestCheckHook torch torchvision @@ -80,8 +80,8 @@ buildPythonPackage rec { meta = { description = "Evolution Strategies in JAX"; homepage = "https://github.com/RobertTLange/evosax"; - changelog = "https://github.com/RobertTLange/evosax/releases/tag/v.${version}"; + changelog = "https://github.com/RobertTLange/evosax/releases/tag/${finalAttrs.src.tag}"; license = lib.licenses.asl20; maintainers = with lib.maintainers; [ GaetanLepage ]; }; -} +}) From 5e489f6a53fc2dbe66ac7f49e3726d24739b5422 Mon Sep 17 00:00:00 2001 From: Nikolay Korotkiy Date: Sat, 26 Sep 2026 15:59:17 +0400 Subject: [PATCH 35/61] llmfit: set __darwinAllowLocalNetworking --- pkgs/by-name/ll/llmfit/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/ll/llmfit/package.nix b/pkgs/by-name/ll/llmfit/package.nix index 7afde4ba9bea..411e4ff476b7 100644 --- a/pkgs/by-name/ll/llmfit/package.nix +++ b/pkgs/by-name/ll/llmfit/package.nix @@ -33,6 +33,8 @@ rustPlatform.buildRustPackage (finalAttrs: { "--skip=text_probe_recovers_when_json_fails" ]; + __darwinAllowLocalNetworking = true; + meta = { description = "TUI to find LLM models right sized for the system's RAM, CPU, and GPU"; homepage = "https://github.com/AlexsJones/llmfit"; From 994894afd356e638d1574d9a563eec91511aabf1 Mon Sep 17 00:00:00 2001 From: Nico Felbinger Date: Sat, 26 Sep 2026 14:18:59 +0200 Subject: [PATCH 36/61] netboxPlugins.netbox-fms: fix meta.changelog --- pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix b/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix index a8c59234ad30..1ef6787b91c4 100644 --- a/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix +++ b/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix @@ -36,7 +36,7 @@ buildPythonPackage (finalAttrs: { meta = { description = "NetBox plugin for Fiber Management System: fiber cable management, splice planning, and circuit provisioning"; homepage = "https://jsenecal.github.io/netbox-fms/"; - changelog = "https://jsenecal.github.io/netbox-fms/releases/tag/${finalAttrs.src.tag}"; + changelog = "https://github.com/jsenecal/netbox-fms/releases/tag/${finalAttrs.src.tag}"; license = lib.licenses.agpl3Only; maintainers = with lib.maintainers; [ felbinger ]; platforms = lib.platforms.linux; From 94ed349bd2d415f567c9d34764f99213e214f9b9 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 26 Sep 2026 12:19:30 +0000 Subject: [PATCH 37/61] home-assistant-custom-components.battery_notes: 3.6.3 -> 3.7.0 --- .../custom-components/battery_notes/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/home-assistant/custom-components/battery_notes/package.nix b/pkgs/servers/home-assistant/custom-components/battery_notes/package.nix index b368f1af798c..4734a64412ea 100644 --- a/pkgs/servers/home-assistant/custom-components/battery_notes/package.nix +++ b/pkgs/servers/home-assistant/custom-components/battery_notes/package.nix @@ -7,13 +7,13 @@ buildHomeAssistantComponent rec { owner = "andrew-codechimp"; domain = "battery_notes"; - version = "3.6.3"; + version = "3.7.0"; src = fetchFromGitHub { inherit owner; repo = "HA-Battery-Notes"; tag = version; - hash = "sha256-TlrFWmgnvFHAvTiGNXkY2TZOo77yU6eVY0o3WDWNRpI="; + hash = "sha256-nqYAi+Fgdag+9B7IBDWngdzlPORirOyiPjYxwY8Iorc="; }; # has no tests From f773eae1bf1a0a866877cd29ddcf958d505f728b Mon Sep 17 00:00:00 2001 From: Nico Felbinger Date: Sat, 26 Sep 2026 14:20:00 +0200 Subject: [PATCH 38/61] netboxPlugins.netbox-fms: 0.3.0 -> 0.5.0 --- pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix b/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix index 1ef6787b91c4..d1f96f14e66c 100644 --- a/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix +++ b/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix @@ -8,7 +8,7 @@ }: buildPythonPackage (finalAttrs: { pname = "netbox-fms"; - version = "0.3.0"; + version = "0.5.0"; pyproject = true; __structuredAttrs = true; @@ -16,7 +16,7 @@ buildPythonPackage (finalAttrs: { owner = "jsenecal"; repo = "netbox-fms"; tag = "v${finalAttrs.version}"; - hash = "sha256-5RPcJFxwQYJWUipHU05gp7zovWPnviWHlkqCHEs16tw="; + hash = "sha256-TOSrSY/5nZaLQyPVkwTZ4szz+TK4fpSgWlfJnKtZwkM="; }; build-system = [ setuptools ]; From c25fee756f669ad75aee1e1be20e8276f6fac9e3 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 26 Sep 2026 13:30:11 +0000 Subject: [PATCH 39/61] perplexity-mcp: 0-unstable-2026-08-27 -> 0-unstable-2026-09-25 --- pkgs/by-name/pe/perplexity-mcp/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/pe/perplexity-mcp/package.nix b/pkgs/by-name/pe/perplexity-mcp/package.nix index c751ed92ac63..ab59279fe9b4 100644 --- a/pkgs/by-name/pe/perplexity-mcp/package.nix +++ b/pkgs/by-name/pe/perplexity-mcp/package.nix @@ -7,16 +7,16 @@ buildNpmPackage (finalAttrs: { pname = "perplexity-mcp"; - version = "0-unstable-2026-08-27"; + version = "0-unstable-2026-09-25"; src = fetchFromGitHub { owner = "perplexityai"; repo = "modelcontextprotocol"; - rev = "c73c8561bbc2d9eb666334a53c311b50f4f4cf76"; - hash = "sha256-zOYRSTK5N79l3jAEnPMuBrYDMyD5zm0QKEopqwlV7/E="; + rev = "c58e4ad254608952606f09a40934ab6cca65bfad"; + hash = "sha256-j0DiITMVEw7e6Cw42kW5iPwIdRt//X2a3Dm2S3IXsbU="; }; - npmDepsHash = "sha256-eKLKHkoXcmk1OdPkgIQjPKBFXEwnV7nKeE98weE25+0="; + npmDepsHash = "sha256-wKw19ha7hQrBTM0caEBZazV6qC+VXihV6i0nf8H/u+Q="; passthru = { updateScript = nix-update-script { From 8bfcec0f1e7fe9ce17891026d4700bbebe6f6e3f Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Sat, 26 Sep 2026 15:08:42 +0100 Subject: [PATCH 40/61] diffoscope: 329 -> 331 Changes: - https://diffoscope.org/news/diffoscope-330-released/ - https://diffoscope.org/news/diffoscope-331-released/ --- pkgs/by-name/di/diffoscope/package.nix | 5 ++--- pkgs/by-name/di/diffoscope/radare2.patch | 26 ------------------------ 2 files changed, 2 insertions(+), 29 deletions(-) delete mode 100644 pkgs/by-name/di/diffoscope/radare2.patch diff --git a/pkgs/by-name/di/diffoscope/package.nix b/pkgs/by-name/di/diffoscope/package.nix index 2263f209d1c4..69289fed16b0 100644 --- a/pkgs/by-name/di/diffoscope/package.nix +++ b/pkgs/by-name/di/diffoscope/package.nix @@ -112,12 +112,12 @@ in # Note: when upgrading this package, please run the list-missing-tools.sh script as described below! python.pkgs.buildPythonApplication rec { pname = "diffoscope"; - version = "329"; + version = "331"; pyproject = true; src = fetchurl { url = "https://diffoscope.org/archive/diffoscope-${version}.tar.bz2"; - hash = "sha256-UPe+Mko9r4qoSTPbDurF64aZgmPLizV8iK2UlCfyfxk="; + hash = "sha256-x1Sc1S3PER3m1+maUZjDofoGqiOoYIm2Oso7Q5NKNtw="; }; outputs = [ @@ -128,7 +128,6 @@ python.pkgs.buildPythonApplication rec { patches = [ ./androguard-4.1.4.patch ./ignore_links.patch - ./radare2.patch ]; postPatch = '' diff --git a/pkgs/by-name/di/diffoscope/radare2.patch b/pkgs/by-name/di/diffoscope/radare2.patch deleted file mode 100644 index 0a51f4354a4e..000000000000 --- a/pkgs/by-name/di/diffoscope/radare2.patch +++ /dev/null @@ -1,26 +0,0 @@ -Fix comparing ELF objects when r2 is in PATH - -https://github.com/radareorg/radare2/issues/21201 renamed the "offset" key of -the json output diffoscope uses to "addr". As a result running diffoscope on an -ELF object results in this error: -KeyError: 'offset' - -This patch does not include the modifications to the test suite required to -submit it upstream. - -Upstream issue: https://salsa.debian.org/reproducible-builds/diffoscope/-/work_items/432 - -diff --git a/diffoscope/comparators/decompile.py b/diffoscope/comparators/decompile.py -index bf85deb9..f6a5564f 100644 ---- a/diffoscope/comparators/decompile.py -+++ b/diffoscope/comparators/decompile.py -@@ -242,6 +242,9 @@ class AsmFunction(File): - - @property - def offset(self): -+ if "addr" in self.data_dict: -+ return self.data_dict["addr"] -+ # backward compat with r2 version < 5.9.0 - return self.data_dict["offset"] - - @property From 3e58a13a910877703d6b7b043363f32449c92b8b Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sat, 8 Aug 2026 23:24:08 +0200 Subject: [PATCH 41/61] python3Packages.django_6: 6.0.8 -> 6.1.1 https://docs.djangoproject.com/en/6.1/releases/6.1/ https://docs.djangoproject.com/en/6.1/releases/6.1.1/ https://www.djangoproject.com/weblog/2026/aug/05/django-61-released/ Splits off 6.0.x as django_6_0 for continued package compatibility. --- .../django/6.0/skip-flaky-tests.patch | 12 ++ pkgs/development/python-modules/django/6.nix | 6 +- .../django/6.x/skip-flaky-tests.patch | 10 +- .../development/python-modules/django/6_0.nix | 147 ++++++++++++++++++ pkgs/top-level/python-packages.nix | 2 + 5 files changed, 168 insertions(+), 9 deletions(-) create mode 100644 pkgs/development/python-modules/django/6.0/skip-flaky-tests.patch create mode 100644 pkgs/development/python-modules/django/6_0.nix diff --git a/pkgs/development/python-modules/django/6.0/skip-flaky-tests.patch b/pkgs/development/python-modules/django/6.0/skip-flaky-tests.patch new file mode 100644 index 000000000000..e9f3dda965be --- /dev/null +++ b/pkgs/development/python-modules/django/6.0/skip-flaky-tests.patch @@ -0,0 +1,12 @@ +diff --git a/tests/serializers/test_deserialization.py b/tests/serializers/test_deserialization.py +index a718a99038..8c9296e1a7 100644 +--- a/tests/serializers/test_deserialization.py ++++ b/tests/serializers/test_deserialization.py +@@ -138,6 +138,7 @@ class TestDeserializer(SimpleTestCase): + self.assertEqual(first_item.object, self.jane) + self.assertEqual(second_item.object, self.joe) + ++ @unittest.skip("flaky") + def test_crafted_xml_performance(self): + """The time to process invalid inputs is not quadratic.""" + diff --git a/pkgs/development/python-modules/django/6.nix b/pkgs/development/python-modules/django/6.nix index bf4f64be7887..1bf6ff170394 100644 --- a/pkgs/development/python-modules/django/6.nix +++ b/pkgs/development/python-modules/django/6.nix @@ -42,7 +42,7 @@ buildPythonPackage (finalAttrs: { pname = "django"; - version = "6.0.8"; + version = "6.1.1"; pyproject = true; disabled = pythonOlder "3.12"; @@ -51,7 +51,7 @@ buildPythonPackage (finalAttrs: { owner = "django"; repo = "django"; tag = finalAttrs.version; - hash = "sha256-hQQMKa8YirrTAoCrW1nn3RqRXv0szLgeSOjeKxBfiSo="; + hash = "sha256-jOshsS3ceWEJoxOuyUSEJvIPE5LLMrzMXEhVgX6wDPQ="; }; patches = [ @@ -62,8 +62,6 @@ buildPythonPackage (finalAttrs: { ./6.x/pythonpath.patch # test_incorrect_timezone should raise but doesn't ./6.x/disable-failing-test.patch - # some perf tests are often flaky under pressure - ./6.x/skip-flaky-tests.patch # https://code.djangoproject.com/ticket/36997 # https://github.com/django/django/pull/21019 ./6.x/invalidate-importlib-cache.patch diff --git a/pkgs/development/python-modules/django/6.x/skip-flaky-tests.patch b/pkgs/development/python-modules/django/6.x/skip-flaky-tests.patch index e9f3dda965be..7753f904a445 100644 --- a/pkgs/development/python-modules/django/6.x/skip-flaky-tests.patch +++ b/pkgs/development/python-modules/django/6.x/skip-flaky-tests.patch @@ -1,12 +1,12 @@ diff --git a/tests/serializers/test_deserialization.py b/tests/serializers/test_deserialization.py -index a718a99038..8c9296e1a7 100644 +index f4be93957a..a4556134af 100644 --- a/tests/serializers/test_deserialization.py +++ b/tests/serializers/test_deserialization.py -@@ -138,6 +138,7 @@ class TestDeserializer(SimpleTestCase): +@@ -137,6 +137,7 @@ class TestDeserializer(SimpleTestCase): self.assertEqual(first_item.object, self.jane) self.assertEqual(second_item.object, self.joe) + @unittest.skip("flaky") - def test_crafted_xml_performance(self): - """The time to process invalid inputs is not quadratic.""" - + def test_crafted_xml_rejected(self): + depth = 100 + leaf_text_len = 1000 diff --git a/pkgs/development/python-modules/django/6_0.nix b/pkgs/development/python-modules/django/6_0.nix new file mode 100644 index 000000000000..9c28d53b96f1 --- /dev/null +++ b/pkgs/development/python-modules/django/6_0.nix @@ -0,0 +1,147 @@ +{ + lib, + stdenv, + buildPythonPackage, + fetchFromGitHub, + pythonOlder, + replaceVars, + + # build-system + setuptools, + + # patched in + geos, + gdal, + withGdal ? false, + + # dependencies + asgiref, + sqlparse, + + # optional-dependencies + argon2-cffi, + bcrypt, + + # tests + aiosmtpd, + docutils, + geoip2, + jinja2, + numpy, + pillow, + pylibmc, + pymemcache, + python, + pyyaml, + pytz, + redis, + selenium, + tblib, + tzdata, +}: + +buildPythonPackage (finalAttrs: { + pname = "django"; + version = "6.0.8"; + pyproject = true; + + disabled = pythonOlder "3.12"; + + src = fetchFromGitHub { + owner = "django"; + repo = "django"; + tag = finalAttrs.version; + hash = "sha256-hQQMKa8YirrTAoCrW1nn3RqRXv0szLgeSOjeKxBfiSo="; + }; + + patches = [ + (replaceVars ./6.x/zoneinfo.patch { + zoneinfo = tzdata + "/share/zoneinfo"; + }) + # prevent tests from messing with our pythonpath + ./6.x/pythonpath.patch + # test_incorrect_timezone should raise but doesn't + ./6.x/disable-failing-test.patch + # some perf tests are often flaky under pressure + ./6.0/skip-flaky-tests.patch + # https://code.djangoproject.com/ticket/36997 + # https://github.com/django/django/pull/21019 + ./6.x/invalidate-importlib-cache.patch + ] + ++ lib.optionals withGdal [ + (replaceVars ./6.x/gdal.patch { + geos = geos; + gdal = gdal; + extension = stdenv.hostPlatform.extensions.sharedLibrary; + }) + ]; + + postPatch = '' + substituteInPlace tests/utils_tests/test_autoreload.py \ + --replace-fail "/usr/bin/python" "${python.interpreter}" + ''; + + build-system = [ setuptools ]; + + dependencies = [ + asgiref + sqlparse + ]; + + optional-dependencies = { + argon2 = [ argon2-cffi ]; + bcrypt = [ bcrypt ]; + }; + + nativeCheckInputs = [ + # tests/requirements/py3.txt + aiosmtpd + docutils + geoip2 + jinja2 + numpy + pillow + pylibmc + pymemcache + pyyaml + pytz + redis + selenium + tblib + tzdata + ] + ++ lib.concatAttrValues finalAttrs.passthru.optional-dependencies; + + preCheck = '' + # make sure the installed library gets imported + rm -rf django + + # fails to import github_links from docs/_ext/github_links.py + rm tests/sphinx/test_github_links.py + + # provide timezone data, works only on linux + export TZDIR=${tzdata}/${python.sitePackages}/tzdata/zoneinfo + + export PYTHONPATH=$PWD/docs/_ext:$PYTHONPATH + ''; + + checkPhase = '' + runHook preCheck + + pushd tests + ${python.interpreter} runtests.py --settings=test_sqlite --parallel=$NIX_BUILD_CORES + popd + + runHook postCheck + ''; + + __darwinAllowLocalNetworking = true; + + meta = with lib; { + changelog = "https://docs.djangoproject.com/en/${lib.versions.majorMinor finalAttrs.version}/releases/${finalAttrs.version}/"; + description = "High-level Python Web framework that encourages rapid development and clean, pragmatic design"; + homepage = "https://www.djangoproject.com"; + license = licenses.bsd3; + maintainers = with maintainers; [ hexa ]; + }; +}) diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index f26aea5146bf..6ab9d797b1bf 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -4956,6 +4956,8 @@ self: super: with self; { django_6 = callPackage ../development/python-modules/django/6.nix { }; + django_6_0 = callPackage ../development/python-modules/django/6_0.nix { }; + djangocms-admin-style = callPackage ../development/python-modules/djangocms-admin-style { }; djangocms-alias = callPackage ../development/python-modules/djangocms-alias { }; From 1413f638ec2aa33f35726ee458661c9692eb3403 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Fri, 25 Sep 2026 23:26:14 +0200 Subject: [PATCH 42/61] python3Packages.djangorestframework_3_17: init at 3.17.1 --- .../djangorestframework/3_17.nix | 78 +++++++++++++++++++ pkgs/top-level/python-packages.nix | 4 + 2 files changed, 82 insertions(+) create mode 100644 pkgs/development/python-modules/djangorestframework/3_17.nix diff --git a/pkgs/development/python-modules/djangorestframework/3_17.nix b/pkgs/development/python-modules/djangorestframework/3_17.nix new file mode 100644 index 000000000000..b915ae89d2f9 --- /dev/null +++ b/pkgs/development/python-modules/djangorestframework/3_17.nix @@ -0,0 +1,78 @@ +{ + lib, + buildPythonPackage, + fetchFromGitHub, + pythonOlder, + + # build-system + setuptools, + + # dependencies + django, + + # optional-dependencies + coreapi, + coreschema, + django-guardian, + inflection, + psycopg2, + pygments, + pyyaml, + + # tests + pytestCheckHook, + pytest-django, + pytz, +}: + +buildPythonPackage (finalAttrs: { + pname = "djangorestframework"; + version = "3.17.1"; + pyproject = true; + + src = fetchFromGitHub { + owner = "encode"; + repo = "django-rest-framework"; + tag = finalAttrs.version; + hash = "sha256-hDAtICtVFeEXRgR5Shb0IdVlLkpf/TBDWw+2cOLJTfw="; + }; + + build-system = [ setuptools ]; + + dependencies = [ + django + ]; + + optional-dependencies = { + complete = [ + coreapi + coreschema + django-guardian + inflection + psycopg2 + pygments + pyyaml + ]; + }; + + nativeCheckInputs = [ + pytest-django + pytestCheckHook + pytz + ] + ++ finalAttrs.passthru.optional-dependencies.complete; + + disabledTests = [ + # https://github.com/encode/django-rest-framework/issues/9422 + "test_urlpatterns" + ]; + + pythonImportsCheck = [ "rest_framework" ]; + + meta = { + changelog = "https://github.com/encode/django-rest-framework/releases/tag/${finalAttrs.src.tag}"; + description = "Web APIs for Django, made easy"; + homepage = "https://www.django-rest-framework.org/"; + license = lib.licenses.bsd2; + }; +}) diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index 6ab9d797b1bf..d61c14f995ef 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -4998,6 +4998,10 @@ self: super: with self; { djangorestframework-stubs = callPackage ../development/python-modules/djangorestframework-stubs { }; + djangorestframework_3_17 = + callPackage ../development/python-modules/djangorestframework/3_17.nix + { }; + djangosaml2 = callPackage ../development/python-modules/djangosaml2 { }; djmail = callPackage ../development/python-modules/djmail { }; From dcaf625d88e133c47bb78d646e020e7fa2291f61 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sat, 26 Sep 2026 01:37:31 +0200 Subject: [PATCH 43/61] python3Packages.django-ninja: 1.6.2 -> 1.7.1 https://github.com/vitalik/django-ninja/releases/tag/v1.6.3 https://github.com/vitalik/django-ninja/releases/tag/v1.7.0 https://github.com/vitalik/django-ninja/releases/tag/v1.7.1 --- pkgs/development/python-modules/django-ninja/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/django-ninja/default.nix b/pkgs/development/python-modules/django-ninja/default.nix index 54c1be0159ff..13caa6338943 100644 --- a/pkgs/development/python-modules/django-ninja/default.nix +++ b/pkgs/development/python-modules/django-ninja/default.nix @@ -13,14 +13,14 @@ buildPythonPackage rec { pname = "django-ninja"; - version = "1.6.2"; + version = "1.7.1"; pyproject = true; src = fetchFromGitHub { owner = "vitalik"; repo = "django-ninja"; tag = "v${version}"; - hash = "sha256-nnGIhNGnK7q0nbw7EYJP+xCeS1uiuTrhQxf49dA+Sc8="; + hash = "sha256-/KsFq6LgaRMxMHmWO5vuzeVZTsmnERTbuS2ne4jc6eA="; }; build-system = [ flit-core ]; From ec860401bb61acfece186cfcbd6c8aad2acdf980 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sat, 8 Aug 2026 23:36:49 +0200 Subject: [PATCH 44/61] python3Packages.djangorestframework: 3.17.1 -> 3.18.1 https://github.com/encode/django-rest-framework/releases/tag/3.18.0 https://github.com/encode/django-rest-framework/releases/tag/3.18.1 --- .../python-modules/djangorestframework/default.nix | 12 ++++-------- 1 file changed, 4 insertions(+), 8 deletions(-) diff --git a/pkgs/development/python-modules/djangorestframework/default.nix b/pkgs/development/python-modules/djangorestframework/default.nix index b915ae89d2f9..32cc7104d79c 100644 --- a/pkgs/development/python-modules/djangorestframework/default.nix +++ b/pkgs/development/python-modules/djangorestframework/default.nix @@ -2,7 +2,6 @@ lib, buildPythonPackage, fetchFromGitHub, - pythonOlder, # build-system setuptools, @@ -20,6 +19,7 @@ pyyaml, # tests + dj-database-url, pytestCheckHook, pytest-django, pytz, @@ -27,14 +27,14 @@ buildPythonPackage (finalAttrs: { pname = "djangorestframework"; - version = "3.17.1"; + version = "3.18.1"; pyproject = true; src = fetchFromGitHub { owner = "encode"; repo = "django-rest-framework"; tag = finalAttrs.version; - hash = "sha256-hDAtICtVFeEXRgR5Shb0IdVlLkpf/TBDWw+2cOLJTfw="; + hash = "sha256-ZOzGJOIyN6X7NxplIDUeII87IlsXViNLPeW7f4/vIfY="; }; build-system = [ setuptools ]; @@ -56,17 +56,13 @@ buildPythonPackage (finalAttrs: { }; nativeCheckInputs = [ + dj-database-url pytest-django pytestCheckHook pytz ] ++ finalAttrs.passthru.optional-dependencies.complete; - disabledTests = [ - # https://github.com/encode/django-rest-framework/issues/9422 - "test_urlpatterns" - ]; - pythonImportsCheck = [ "rest_framework" ]; meta = { From f94549214574b870186113d09389a6de8ddbb4f7 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sun, 9 Aug 2026 00:26:02 +0200 Subject: [PATCH 45/61] python3Packages.django-formtools: disable failing test --- .../python-modules/django-formtools/default.nix | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/pkgs/development/python-modules/django-formtools/default.nix b/pkgs/development/python-modules/django-formtools/default.nix index a5e1c9ad8304..653ec7e7fc6e 100644 --- a/pkgs/development/python-modules/django-formtools/default.nix +++ b/pkgs/development/python-modules/django-formtools/default.nix @@ -40,9 +40,10 @@ buildPythonPackage (finalAttrs: { disabledTests = [ # mismatch between test collection of django and pytest-django "TestStorage" - # Django 6.0.6/5.2.15 compat issue - # https://github.com/jazzband/django-formtools/issues/298 - "test_reset_cookie" + ] + ++ lib.optionals (lib.versionAtLeast django.version "6.1") [ + # https://github.com/jazzband/django-formtools/issues/303 + "test_manipulated_cookie" ]; pythonImportsCheck = [ "formtools" ]; From d93afa1b7628c5b421e7b28ce678c82f80a3b9c7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Sun, 23 Aug 2026 11:08:41 +0200 Subject: [PATCH 46/61] python3Packages.django-async-backend: 6.0.7 -> 6.1.2 Somehow pytest-django is not running migration and causing some test failures. The package can be build with glitchtip.python.pkgs.django-async-backend Diff: https://github.com/Arfey/django-async-backend/compare/v6.0.7...v6.1.2 Changelog: https://github.com/Arfey/django-async-backend/releases/tag/v6.0.8 Changelog: https://github.com/Arfey/django-async-backend/releases/tag/v6.0.9 Changelog: https://github.com/Arfey/django-async-backend/releases/tag/v6.1.0 Changelog: https://github.com/Arfey/django-async-backend/releases/tag/v6.1.1 Changelog: https://github.com/Arfey/django-async-backend/releases/tag/v6.1.2 --- .../django-async-backend/default.nix | 21 +++++++++++-------- 1 file changed, 12 insertions(+), 9 deletions(-) diff --git a/pkgs/development/python-modules/django-async-backend/default.nix b/pkgs/development/python-modules/django-async-backend/default.nix index 404ecff96939..63d8fd4ee26f 100644 --- a/pkgs/development/python-modules/django-async-backend/default.nix +++ b/pkgs/development/python-modules/django-async-backend/default.nix @@ -3,6 +3,7 @@ buildPythonPackage, django, fetchFromGitHub, + libcst, poetry-core, postgresql, postgresqlTestHook, @@ -14,14 +15,14 @@ buildPythonPackage rec { pname = "django-async-backend"; - version = "6.0.7"; + version = "6.1.2"; pyproject = true; src = fetchFromGitHub { owner = "Arfey"; repo = "django-async-backend"; tag = "v${version}"; - hash = "sha256-4zaXPfHIE9RwkSbHPt1DHFInn8LP+JXiBiMJYkZeR6M="; + hash = "sha256-pfcqTtyV37bZFSZaRcFIt9cgR8XZ7PDijVC18lMziRU="; }; postPatch = '' @@ -47,24 +48,26 @@ buildPythonPackage rec { PGUSER = "postgres"; }; - preCheck = '' - export PYTHONPATH=$PYTHONPATH:$PWD/tests + checkPhase = '' + runHook preCheck + + cd tests/ + python manage.py test + + runHook postCheck ''; nativeCheckInputs = [ django # must come first as vtasks only works with django 6 + libcst postgresql postgresqlTestHook psycopg-pool - pytest-django - pytestCheckHook ]; - pytestFlags = [ "./tests" ]; - meta = { - description = "Django extension providing async capabilities for database and other components"; + description = "True async Django ORM and PostgreSQL backend with connection pooling and async transactions"; homepage = "https://github.com/Arfey/django-async-backend"; changelog = "https://github.com/Arfey/django-async-backend/releases/tag/${src.tag}"; license = lib.licenses.asl20; From 377a2ea04b4b32cace40bacf69a30b109cdd0415 Mon Sep 17 00:00:00 2001 From: Minijackson Date: Tue, 15 Sep 2026 09:02:36 +0200 Subject: [PATCH 47/61] python3Packages.strawberry-graphql-django: remove django-mptt dependency It doesn't seems used anymore --- .../python-modules/strawberry-graphql-django/default.nix | 2 -- 1 file changed, 2 deletions(-) diff --git a/pkgs/development/python-modules/strawberry-graphql-django/default.nix b/pkgs/development/python-modules/strawberry-graphql-django/default.nix index 305a82c01bd8..b5ffc13b5fc8 100644 --- a/pkgs/development/python-modules/strawberry-graphql-django/default.nix +++ b/pkgs/development/python-modules/strawberry-graphql-django/default.nix @@ -20,7 +20,6 @@ pytestCheckHook, django-guardian, django-model-utils, - django-mptt, django-polymorphic, django-tree-queries, factory-boy, @@ -74,7 +73,6 @@ buildPythonPackage rec { django-guardian django-model-utils - django-mptt django-polymorphic django-tree-queries factory-boy From c34b588fd5648ff6999235543d102de476a087fd Mon Sep 17 00:00:00 2001 From: Minijackson Date: Tue, 15 Sep 2026 09:03:04 +0200 Subject: [PATCH 48/61] python3Packages.django-guardian: 3.3.3 -> 3.5.0 Upgrade past 3.4.0 required to for Django 6.1. https://github.com/django-guardian/django-guardian/releases/tag/3.3.4 https://github.com/django-guardian/django-guardian/releases/tag/3.4.0 https://github.com/django-guardian/django-guardian/releases/tag/3.4.1 https://github.com/django-guardian/django-guardian/releases/tag/3.5.0 --- pkgs/development/python-modules/django-guardian/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/django-guardian/default.nix b/pkgs/development/python-modules/django-guardian/default.nix index 3103f6f116a1..f94b38ccb680 100644 --- a/pkgs/development/python-modules/django-guardian/default.nix +++ b/pkgs/development/python-modules/django-guardian/default.nix @@ -12,14 +12,14 @@ buildPythonPackage (finalAttrs: { pname = "django-guardian"; - version = "3.3.3"; + version = "3.5.0"; pyproject = true; src = fetchFromGitHub { owner = "django-guardian"; repo = "django-guardian"; tag = finalAttrs.version; - hash = "sha256-0zUdcDeJ40AuYSzhjy3/htU43cy6T54rZOj2zFo6J+8="; + hash = "sha256-viqICF6zfJxAj1jEYtBXCR2NbUR26Q8SeKVFTMVzisQ="; }; build-system = [ setuptools ]; From d0001b3f9eff2956bba6c74c4d49b18b85f03b20 Mon Sep 17 00:00:00 2001 From: Minijackson Date: Tue, 15 Sep 2026 09:03:38 +0200 Subject: [PATCH 49/61] python3Packages.django-debug-toolbar: 7.0.0 -> 8.0.0 Needed to upgrade to Django 6.1 --- .../python-modules/django-debug-toolbar/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/django-debug-toolbar/default.nix b/pkgs/development/python-modules/django-debug-toolbar/default.nix index 8137ea09057f..b9e76e9d78d1 100644 --- a/pkgs/development/python-modules/django-debug-toolbar/default.nix +++ b/pkgs/development/python-modules/django-debug-toolbar/default.nix @@ -19,14 +19,14 @@ buildPythonPackage rec { pname = "django-debug-toolbar"; - version = "7.0.0"; + version = "8.0.0"; pyproject = true; src = fetchFromGitHub { owner = "jazzband"; repo = "django-debug-toolbar"; tag = version; - hash = "sha256-Xwl6LsNW3/VXJ59QaW4l6D+8VEbl45ysv5KaySbS4M4="; + hash = "sha256-OwMul+wGKLU9LwybsCtqV51lp/CQvexP0TWJSg8E3iQ="; }; postPatch = '' From 1c0e708fef84c8e8114e1f0197f7ebf0e7eacded Mon Sep 17 00:00:00 2001 From: Minijackson Date: Tue, 15 Sep 2026 09:03:58 +0200 Subject: [PATCH 50/61] python3Packages.django-mptt: disable tests when using Django 6 The tests seem to only fail due to HTML differences. --- pkgs/development/python-modules/django-mptt/default.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/development/python-modules/django-mptt/default.nix b/pkgs/development/python-modules/django-mptt/default.nix index 50cda6412332..e2f03a59e8f4 100644 --- a/pkgs/development/python-modules/django-mptt/default.nix +++ b/pkgs/development/python-modules/django-mptt/default.nix @@ -37,6 +37,9 @@ buildPythonPackage rec { pytest-django ]; + # XXX: some HTML tests fail with Django 6.1+ + doCheck = lib.versionOlder django.version "6.1"; + preCheck = '' export DJANGO_SETTINGS_MODULE=tests.settings export PYTHONPATH=$(pwd)/tests:$PYTHONPATH From 5a39c8bdf1cdafb311c18218a84fa6de31191fe8 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sat, 26 Sep 2026 12:28:06 +0200 Subject: [PATCH 51/61] python3Packages.drf-spectacular: update test setup --- pkgs/development/python-modules/drf-spectacular/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/drf-spectacular/default.nix b/pkgs/development/python-modules/drf-spectacular/default.nix index 3afbf1cc7263..b9378cf2fc69 100644 --- a/pkgs/development/python-modules/drf-spectacular/default.nix +++ b/pkgs/development/python-modules/drf-spectacular/default.nix @@ -8,6 +8,7 @@ django-oauth-toolkit, django-polymorphic, django-rest-auth, + django-rest-knox, django-rest-polymorphic, djangorestframework, djangorestframework-camel-case, @@ -60,6 +61,7 @@ buildPythonPackage rec { django-oauth-toolkit django-polymorphic django-rest-auth + django-rest-knox django-rest-polymorphic djangorestframework-camel-case djangorestframework-dataclasses @@ -77,8 +79,6 @@ buildPythonPackage rec { disabledTestPaths = [ # django-oauth-toolkit 3.4.1 added a new error that the example application has "tests/test_command.py::test_command_check" - # django-rest-knox is not packaged - "tests/contrib/test_knox_auth_token.py" # Outdated test artifact "tests/contrib/test_pydantic.py" # Test requires django with gdal From 68550897064df95f051c224b8f889b38d3303d93 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sat, 26 Sep 2026 13:50:18 +0200 Subject: [PATCH 52/61] python3Packages.drf-spectacular: disable failing tests --- pkgs/development/python-modules/drf-spectacular/default.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/development/python-modules/drf-spectacular/default.nix b/pkgs/development/python-modules/drf-spectacular/default.nix index b9378cf2fc69..60c49e8182a2 100644 --- a/pkgs/development/python-modules/drf-spectacular/default.nix +++ b/pkgs/development/python-modules/drf-spectacular/default.nix @@ -83,6 +83,9 @@ buildPythonPackage rec { "tests/contrib/test_pydantic.py" # Test requires django with gdal "tests/contrib/test_rest_framework_gis.py" + # OpenAPI schema failure with DRF 3.18.x + "tests/test_fields.py::test_fields" + "tests/test_fields.py::test_fields_oas_3_1" ]; pythonImportsCheck = [ "drf_spectacular" ]; From be25580448474463a930a6c7a3f378a18b92ff9c Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sat, 26 Sep 2026 13:56:36 +0200 Subject: [PATCH 53/61] pretalx: pin django 6.0 --- pkgs/by-name/pr/pretalx/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/pr/pretalx/package.nix b/pkgs/by-name/pr/pretalx/package.nix index 8edf195f9177..269d88566812 100644 --- a/pkgs/by-name/pr/pretalx/package.nix +++ b/pkgs/by-name/pr/pretalx/package.nix @@ -14,7 +14,7 @@ let python = python314.override { self = python; packageOverrides = final: prev: { - django = prev.django_6; + django = prev.django_6_0; django-hierarkey = prev.django-hierarkey.overrideAttrs (oldAttrs: { version = "2.0.1"; From 9eb52abbb0ae0deccacacbc992b533339ecc1f00 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sat, 26 Sep 2026 14:05:04 +0200 Subject: [PATCH 54/61] pretix: pin drf at 3.17.x --- pkgs/by-name/pr/pretix/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/pr/pretix/package.nix b/pkgs/by-name/pr/pretix/package.nix index 117a5e877b7c..9bc17d212b33 100644 --- a/pkgs/by-name/pr/pretix/package.nix +++ b/pkgs/by-name/pr/pretix/package.nix @@ -19,6 +19,7 @@ let packageOverrides = self: super: { chardet = super.chardet_5; django = super.django_5; + djangorestframework = super.djangorestframework_3_17; django-oauth-toolkit = super.django-oauth-toolkit.overridePythonAttrs (oldAttrs: rec { version = "2.3.0"; From 67c2b1206a20843fe6833b707dfed9eacda41e3f Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sat, 26 Sep 2026 14:19:58 +0200 Subject: [PATCH 55/61] paperless-ngx: relax django-guardian constraint --- pkgs/by-name/pa/paperless-ngx/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/pa/paperless-ngx/package.nix b/pkgs/by-name/pa/paperless-ngx/package.nix index c7c61af3083a..ff56e114cbfc 100644 --- a/pkgs/by-name/pa/paperless-ngx/package.nix +++ b/pkgs/by-name/pa/paperless-ngx/package.nix @@ -96,6 +96,7 @@ pythonPackages.buildPythonApplication (finalAttrs: { pythonRelaxDeps = [ "django-allauth" "django-filter" + "django-guardian" "drf-spectacular-sidecar" "redis" "regex" From b91eccd4a31730f5112b7c8c0307ab91de06898e Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sat, 26 Sep 2026 16:31:39 +0200 Subject: [PATCH 56/61] weblate: pin django at 6.0.x --- pkgs/by-name/we/weblate/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/we/weblate/package.nix b/pkgs/by-name/we/weblate/package.nix index fd826bca0ec9..4c4efe191349 100644 --- a/pkgs/by-name/we/weblate/package.nix +++ b/pkgs/by-name/we/weblate/package.nix @@ -28,7 +28,7 @@ let python = python3.override { self = python; packageOverrides = _final: prev: { - django = prev.django_6; + django = prev.django_6_0; }; }; python3Packages = python.pkgs; From 9d6614ba99bab322b0272f001403ea179df286e4 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sat, 26 Sep 2026 16:58:52 +0200 Subject: [PATCH 57/61] python3Packages.django*: add cpe and purl identifiers --- pkgs/development/python-modules/django/5.nix | 22 ++++++++++++++----- pkgs/development/python-modules/django/6.nix | 12 ++++++++++ .../development/python-modules/django/6_0.nix | 12 ++++++++++ 3 files changed, 41 insertions(+), 5 deletions(-) diff --git a/pkgs/development/python-modules/django/5.nix b/pkgs/development/python-modules/django/5.nix index d9ec648838c7..8d37a45947ac 100644 --- a/pkgs/development/python-modules/django/5.nix +++ b/pkgs/development/python-modules/django/5.nix @@ -39,7 +39,7 @@ tzdata, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "django"; version = "5.2.17"; pyproject = true; @@ -47,7 +47,7 @@ buildPythonPackage rec { src = fetchFromGitHub { owner = "django"; repo = "django"; - tag = version; + tag = finalAttrs.version; hash = "sha256-7it3opzsiN/hHhpipZz4ogmRKGz7E9/LmTF03/UYIB0="; }; @@ -102,7 +102,7 @@ buildPythonPackage rec { tblib tzdata ] - ++ lib.concatAttrValues optional-dependencies; + ++ lib.concatAttrValues finalAttrs.passthru.optional-dependencies; preCheck = '' # make sure the installed library gets imported @@ -131,10 +131,22 @@ buildPythonPackage rec { __darwinAllowLocalNetworking = true; meta = { - changelog = "https://docs.djangoproject.com/en/${lib.versions.majorMinor version}/releases/${version}/"; + changelog = "https://docs.djangoproject.com/en/${lib.versions.majorMinor finalAttrs.version}/releases/${finalAttrs.version}/"; description = "High-level Python Web framework that encourages rapid development and clean, pragmatic design"; homepage = "https://www.djangoproject.com"; + identifiers = { + cpeParts = { + inherit (finalAttrs) version; + product = "django"; + update = "*"; + vendor = "djangoproject"; + }; + purlParts = { + type = "pypi"; + spec = "django@${finalAttrs.version}"; + }; + }; license = lib.licenses.bsd3; maintainers = with lib.maintainers; [ hexa ]; }; -} +}) diff --git a/pkgs/development/python-modules/django/6.nix b/pkgs/development/python-modules/django/6.nix index 1bf6ff170394..472c5d7fa3ff 100644 --- a/pkgs/development/python-modules/django/6.nix +++ b/pkgs/development/python-modules/django/6.nix @@ -139,6 +139,18 @@ buildPythonPackage (finalAttrs: { changelog = "https://docs.djangoproject.com/en/${lib.versions.majorMinor finalAttrs.version}/releases/${finalAttrs.version}/"; description = "High-level Python Web framework that encourages rapid development and clean, pragmatic design"; homepage = "https://www.djangoproject.com"; + identifiers = { + cpeParts = { + inherit (finalAttrs) version; + product = "django"; + update = "*"; + vendor = "djangoproject"; + }; + purlParts = { + type = "pypi"; + spec = "django@${finalAttrs.version}"; + }; + }; license = licenses.bsd3; maintainers = with maintainers; [ hexa ]; }; diff --git a/pkgs/development/python-modules/django/6_0.nix b/pkgs/development/python-modules/django/6_0.nix index 9c28d53b96f1..58cd89174997 100644 --- a/pkgs/development/python-modules/django/6_0.nix +++ b/pkgs/development/python-modules/django/6_0.nix @@ -141,6 +141,18 @@ buildPythonPackage (finalAttrs: { changelog = "https://docs.djangoproject.com/en/${lib.versions.majorMinor finalAttrs.version}/releases/${finalAttrs.version}/"; description = "High-level Python Web framework that encourages rapid development and clean, pragmatic design"; homepage = "https://www.djangoproject.com"; + identifiers = { + cpeParts = { + inherit (finalAttrs) version; + product = "django"; + update = "*"; + vendor = "djangoproject"; + }; + purlParts = { + type = "pypi"; + spec = "django@${finalAttrs.version}"; + }; + }; license = licenses.bsd3; maintainers = with maintainers; [ hexa ]; }; From 6f02ff318769aa23ce9ffcadf5edd89b1b3dd7d2 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 26 Sep 2026 15:06:09 +0000 Subject: [PATCH 58/61] cargo-binstall: 1.23.0 -> 1.24.0 --- pkgs/by-name/ca/cargo-binstall/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ca/cargo-binstall/package.nix b/pkgs/by-name/ca/cargo-binstall/package.nix index a52acd8f2b3a..a4123250b5a8 100644 --- a/pkgs/by-name/ca/cargo-binstall/package.nix +++ b/pkgs/by-name/ca/cargo-binstall/package.nix @@ -11,16 +11,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "cargo-binstall"; - version = "1.23.0"; + version = "1.24.0"; src = fetchFromGitHub { owner = "cargo-bins"; repo = "cargo-binstall"; tag = "v${finalAttrs.version}"; - hash = "sha256-Z65k76pcm/j9loXI3KHJi6zSibZY90KJ2aNPycHhp9g="; + hash = "sha256-DD4GJXaKr96JD+5pE/RQeaPoB2vj+2J8S8ZlV29J/ZE="; }; - cargoHash = "sha256-xT4BzFPdQPPGOUsDBLEaM+0yod1+ww6zyi9tkw2cIJk="; + cargoHash = "sha256-g4mLtyv2rHavQOJjLnxn+IR+WBvenLP0yamH0xKWzZg="; nativeBuildInputs = [ pkg-config From c96e84833638c5176b9558b1d84ff0ca4f358984 Mon Sep 17 00:00:00 2001 From: RTUnreal Date: Sat, 26 Sep 2026 17:43:28 +0200 Subject: [PATCH 59/61] icu*: add license --- pkgs/development/libraries/icu/make-icu.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/development/libraries/icu/make-icu.nix b/pkgs/development/libraries/icu/make-icu.nix index 7dd0310648ea..b5118f833ba1 100644 --- a/pkgs/development/libraries/icu/make-icu.nix +++ b/pkgs/development/libraries/icu/make-icu.nix @@ -88,6 +88,7 @@ let description = "Unicode and globalization support library"; homepage = "https://icu.unicode.org/"; maintainers = with lib.maintainers; [ raskin ]; + license = lib.licenses.unicode-30; pkgConfigModules = [ "icu-i18n" "icu-io" From 3312dbf41a41ab1cc115e4920eb4cecc4015907a Mon Sep 17 00:00:00 2001 From: Tom Herbers Date: Fri, 25 Sep 2026 01:19:54 +0200 Subject: [PATCH 60/61] incus-lts: backport 7.5 security fixes sourced from: - https://github.com/lxc/incus/pull/4071 - https://github.com/lxc/incus/commits/stable-7.0/?before=f22d8a92dff8e4cf01260ab85405db754bcfc026+35 - https://salsa.debian.org/go-team/packages/incus/-/commit/4992bd88f727414d9f02e9966feb235daf8d755d - https://salsa.debian.org/go-team/packages/incus/-/commit/bdec650ea4657450a90300c1e25e4d9b5ba71547 --- pkgs/by-name/in/incus/lts.nix | 57 ++++++++++++++++++++++++++++++++++- 1 file changed, 56 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/in/incus/lts.nix b/pkgs/by-name/in/incus/lts.nix index a0185fba0496..db6653351259 100644 --- a/pkgs/by-name/in/incus/lts.nix +++ b/pkgs/by-name/in/incus/lts.nix @@ -111,7 +111,62 @@ import ./generic.nix { url = "https://github.com/lxc/incus/commit/9e188e31e43c21fa8f2a4cac265aa246d4c947f2.patch?full_index=1"; hash = "sha256-KFYKB9PJK/U4/jSe3rmMeR9FWevvvi47BRy055Zj8Io="; }) - + # incus/file: Contain recursive pull symlinks + (fetchpatch2 { + url = "https://salsa.debian.org/go-team/packages/incus/-/raw/4992bd88f727414d9f02e9966feb235daf8d755d/debian/patches/126-GHSA-wfvq-qh87-gm4j.patch"; + hash = "sha256-hD7l9/mlUuISLV1hrvuYMyPFYe1XUWnLO15RJyO1ZlA="; + }) + # incusd: Don't follow symlinks when receiving migration + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/9afa3d58ef9ffae40eb1980bd33592d00fe1feba.patch?full_index=1"; + hash = "sha256-SJKrTdR/BKNVPa9P7Yowukfm71D3M9yGh1iGQpkhEDE="; + }) + # incusd/storage: Treat volume creation with a source as a copy (sourced from stable-7.0) + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/e59d35263a0e027b4a0344ab8d05c80c622a21e2.patch?full_index=1"; + hash = "sha256-oHM9IGGjPRwsmc5JAYaBY65HV+H3ZC1/ebqQts/tDow="; + }) + # incusd/storage/drivers: Confine btrfs subvolume paths + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/99a8ba3101e91be6cd7013e80ff916f32d495b71.patch?full_index=1"; + hash = "sha256-iwybe/E8Lucwf6ih6gWt3b/jnG3UGYep2GoqL/h4qn8="; + }) + # incusd/storage: Validate dependent volume names on backup import + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/2ef78c71a5f3c9db4a6ad438563ec99497686d83.patch?full_index=1"; + hash = "sha256-apBgxM15JA+8q/lR5mJRG85rBn+2pEuZdcgOjPn/y8g="; + }) + # incusd/storage: Ignore backup project for dependent + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/10d6ea9a7163c2a7b16f9e9ccf0bd45981c3355e.patch?full_index=1"; + hash = "sha256-5gkMiAb5Ewzsiv9LmZ2oJx+7xTdIbkVnXEkt67metlU="; + }) + # incusd/storage/s3: Require x-amz-* headers to be signed + (fetchpatch2 { + url = "https://salsa.debian.org/go-team/packages/incus/-/raw/4992bd88f727414d9f02e9966feb235daf8d755d/debian/patches/123-GHSA-mmj7-8rgf-mx2h.patch"; + hash = "sha256-OHjdOPQ3UyNfucLElKXA4iRYVhOF6fq+m0wUnaYGoiI="; + }) + # incusd/operations: Check project access on operation get and wait + # incusd/operations: Hide access token operations from non-admins + (fetchpatch2 { + url = "https://salsa.debian.org/go-team/packages/incus/-/raw/bdec650ea4657450a90300c1e25e4d9b5ba71547/debian/patches/125-GHSA-mfwv-x733-9446.patch"; + hash = "sha256-LMx5sb7rC5U9BLsXYhqN3SaW7K/d4q2H1OvcDQPNm7w="; + }) + # incusd/storage/buckets: Require can_edit to read bucket keys + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/1eaf9b8bfed2b8cf09182c88fd81b10327605ade.patch?full_index=1"; + hash = "sha256-KrQtsS8Ug7K5bMeduV9tPeunHOnCXfNNqlbpVMTNzws="; + }) + # incusd/project: Restrict volume options on update and copy + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/da36896aa8af65080a79fd1a4b8abcf75d46cbd1.patch?full_index=1"; + hash = "sha256-+W+2RXtJO/IGd+ejpkylsaNfH8JtSIMTun9bxbtbPxU="; + }) + # incusd/instances: Check project restrictions on clustered refresh + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/f22d8a92dff8e4cf01260ab85405db754bcfc026.patch?full_index=1"; + hash = "sha256-LwQRWQzZewU0QjdaerKFJb4h99RKuTLBZ80PifJONkM="; + }) ]; lts = true; nixUpdateExtraArgs = [ From f037615fca373033d0f19b8c886c807b4a323922 Mon Sep 17 00:00:00 2001 From: jopejoe1 Date: Sat, 26 Sep 2026 16:38:47 +0200 Subject: [PATCH 61/61] alac: drop Is unmaintained and vulnerable --- pkgs/by-name/al/alac/package.nix | 42 ---------------------- pkgs/by-name/sh/shairport-sync/package.nix | 4 --- pkgs/top-level/aliases.nix | 1 + 3 files changed, 1 insertion(+), 46 deletions(-) delete mode 100644 pkgs/by-name/al/alac/package.nix diff --git a/pkgs/by-name/al/alac/package.nix b/pkgs/by-name/al/alac/package.nix deleted file mode 100644 index bb2d20b84405..000000000000 --- a/pkgs/by-name/al/alac/package.nix +++ /dev/null @@ -1,42 +0,0 @@ -{ - autoreconfHook, - fetchFromGitHub, - lib, - stdenv, - testers, - unstableGitUpdater, -}: -stdenv.mkDerivation (finalAttrs: { - pname = "alac"; - version = "0.0.7-unstable-2026-04-10"; - - outputs = [ - "out" - "dev" - ]; - - src = fetchFromGitHub { - owner = "mikebrady"; - repo = "alac"; - rev = "5d8c5db0dfcadd5872f28e665cf4f4303447352a"; - hash = "sha256-Wb6I5YHGvBVjVgOutICbRKH96odR3ZgmNS6HQedVahk="; - }; - - nativeBuildInputs = [ - autoreconfHook - ]; - - passthru = { - updateScript = unstableGitUpdater { }; - tests.pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage; - }; - - meta = { - description = "Apple Lossless Codec and Utility with Autotools"; - homepage = "https://github.com/mikebrady/alac"; - license = lib.licenses.asl20; - pkgConfigModules = [ "alac" ]; - platforms = lib.platforms.all; - maintainers = with lib.maintainers; [ jopejoe1 ]; - }; -}) diff --git a/pkgs/by-name/sh/shairport-sync/package.nix b/pkgs/by-name/sh/shairport-sync/package.nix index 8c1f9f03eb6d..6451c02c06bc 100644 --- a/pkgs/by-name/sh/shairport-sync/package.nix +++ b/pkgs/by-name/sh/shairport-sync/package.nix @@ -26,7 +26,6 @@ nix-update-script, pipewire, soxr, - alac, sndio, enableAvahi ? true, enableAirplay2 ? false, @@ -44,7 +43,6 @@ enableMqttClient ? true, enableDbus ? stdenv.hostPlatform.isLinux, enableSoxr ? true, - enableAlac ? !enableAirplay2, # airplay2 build uses ffmpeg for alac enableConvolution ? true, enableLibdaemon ? false, enableTinySVCmDNS ? true, @@ -96,7 +94,6 @@ stdenv.mkDerivation (finalAttrs: { ++ optional enableJack libjack2 ++ optional enableSoundio libsoundio ++ optional enableSoxr soxr - ++ optional enableAlac alac ++ optional enableConvolution libsndfile ++ optionals enableAirplay2 [ libplist @@ -130,7 +127,6 @@ stdenv.mkDerivation (finalAttrs: { ++ optional enableStdout "--with-stdout" ++ optional enablePipe "--with-pipe" ++ optional enableSoxr "--with-soxr" - ++ optional enableAlac "--with-apple-alac" ++ optional enableConvolution "--with-convolution" ++ optional enableDbus "--with-dbus-interface" ++ optional enableMetadata "--with-metadata" diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index 1150da98a4da..f5d1e3ca68b5 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -287,6 +287,7 @@ mapAliases { akkoma-emoji = throw "'akkoma-emoji' has been renamed to/replaced by 'blobs_gg'"; # Converted to throw 2025-10-27 akkoma-frontends.admin-fe = throw "'akkoma-frontends.admin-fe' has been renamed to/replaced by 'akkoma-admin-fe'"; # Converted to throw 2025-10-27 akkoma-frontends.akkoma-fe = throw "'akkoma-frontends.akkoma-fe' has been renamed to/replaced by 'akkoma-fe'"; # Converted to throw 2025-10-27 + alac = throw "'alac' has been removed, as it was unmaintained and contains several vulnerabilities"; # Added 2026-09-26 alexandria = throw "'alexandria' has been removed as it was unmaintained upstream and depended on webkitgtk 4.0 and libsoup 2.4 via Tauri v1"; # Added 2026-06-07 amazon-ecs-cli = throw "'amazon-ecs-cli' has been removed due to being unmaintained upstream"; # Added 2026-01-19 amazon-qldb-shell = throw "'amazon-qldb-shell' has been removed due to being unmaintained upstream"; # Added 2025-07-30