From 9da8edf8648b93099d8e41f08ca003e36adac478 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Philippe=20H=C3=BCrlimann?=
Date: Mon, 17 Aug 2026 20:55:58 +0200
Subject: [PATCH 01/61] glib: remove util-linuxMinimal assertion when building
for Linux
According to 868eb8301916d, this assertion was introduced when glib
started requiring this dependency by default due to libmount. However,
it still supports building without libmount and without this dependency
on Linux and this assertion prohibits doing this using overrides.
This changes fixes that and does not affect the builds output.
```
% nix-build -A glib
[...]
/nix/store/c6p0n1xsd7zj2dnxm2d4m85nx5fgbjbj-glib-2.88.3-bin
% git checkout HEAD^
[...]
% nix-build -A glib
/nix/store/c6p0n1xsd7zj2dnxm2d4m85nx5fgbjbj-glib-2.88.3-bin
%
```
---
pkgs/by-name/gl/glib/package.nix | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/pkgs/by-name/gl/glib/package.nix b/pkgs/by-name/gl/glib/package.nix
index d504331900ce..45f1a1c85d8a 100644
--- a/pkgs/by-name/gl/glib/package.nix
+++ b/pkgs/by-name/gl/glib/package.nix
@@ -23,7 +23,7 @@
docutils,
gi-docgen,
# use util-linuxMinimal to avoid circular dependency (util-linux, systemd, glib)
- util-linuxMinimal ? null,
+ util-linuxMinimal,
buildPackages,
# this is just for tests (not in the closure of any regular package)
@@ -43,8 +43,6 @@
&& stdenv.hostPlatform.isLittleEndian == stdenv.buildPlatform.isLittleEndian,
}:
-assert stdenv.hostPlatform.isLinux -> util-linuxMinimal != null;
-
let
glib-untested = glib.overrideAttrs { doCheck = false; };
# break dependency cycles
From e93369306761124f88fcb4bde02fa6a09bc8c8c5 Mon Sep 17 00:00:00 2001
From: 1sixth <1sixth@azc.moe>
Date: Mon, 7 Sep 2026 21:54:20 +0800
Subject: [PATCH 02/61] nixos/restic: fix repository initialization checks
1. Add `--no-lock` to `restic cat config`.
2. Run `restic init` only if the exit code is 10 (repository does not exist).
---
nixos/modules/services/backup/restic.nix | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/nixos/modules/services/backup/restic.nix b/nixos/modules/services/backup/restic.nix
index 8344fc84246a..65031ad0d077 100644
--- a/nixos/modules/services/backup/restic.nix
+++ b/nixos/modules/services/backup/restic.nix
@@ -478,7 +478,14 @@ in
${pkgs.writeScript "backupPrepareCommand" backup.backupPrepareCommand}
''}
${lib.optionalString backup.initialize ''
- ${resticCmd} cat config > /dev/null || ${resticCmd} init
+ ${resticCmd} cat config --no-lock > /dev/null || {
+ status=$?
+ if [ "$status" -eq 10 ]; then
+ ${resticCmd} init
+ else
+ exit "$status"
+ fi
+ }
''}
${lib.optionalString (backup.paths != null && backup.paths != [ ]) ''
cat ${pkgs.writeText "staticPaths" (lib.concatLines backup.paths)} >> ${filesFromTmpFile}
From c392272b10faee8426cc75cb5e76c50ebe92f672 Mon Sep 17 00:00:00 2001
From: jopejoe1
Date: Fri, 11 Sep 2026 14:56:10 +0200
Subject: [PATCH 03/61] lib.licenses: expose mkLicense
make it so others can make use of it
---
lib/licenses/helpers.nix | 61 ++++++++++++++++++++++++++++++++++++++-
lib/licenses/licenses.nix | 35 +---------------------
2 files changed, 61 insertions(+), 35 deletions(-)
diff --git a/lib/licenses/helpers.nix b/lib/licenses/helpers.nix
index 37721489f77a..e54ae01b707f 100644
--- a/lib/licenses/helpers.nix
+++ b/lib/licenses/helpers.nix
@@ -1,7 +1,12 @@
{ lib }:
let
- inherit (lib) all any elem;
+ inherit (lib)
+ all
+ any
+ elem
+ optionalAttrs
+ ;
handleComplexProperty =
evaluateSubProperty: AND: OR: license:
if license.licenseType == "compound" then
@@ -184,4 +189,58 @@ rec {
"${mkBracket license.license}${license.operator}"
else
throw "Unknown license type";
+
+ /**
+ Create a license.
+
+ # Inputs
+
+ `licenseInfo`
+ : Attrset of license infromation
+
+ # Type
+
+ ```
+ mkLicense :: AttrSet -> AttrSet
+ ```
+
+ # Example
+ :::{.example}
+ ## `lib.licenses.mkLicense` usage example
+
+ ```nix
+ mkLicense { shortName = "my-license"; }
+ => { shortName = "my-license"; free = true; deprecated = false; redistributable = true; licenseType = "simple"; }
+ ```
+ */
+ mkLicense =
+ {
+ shortName,
+ # Most of our licenses are Free, explicitly declare unfree additions as such!
+ free ? true,
+ deprecated ? false,
+ spdxId ? null,
+ url ? null,
+ fullName ? null,
+ redistributable ? free,
+ }@attrs:
+ {
+ inherit
+ shortName
+ free
+ deprecated
+ redistributable
+ ;
+ licenseType = "simple";
+ }
+ // optionalAttrs (attrs ? spdxId) {
+ inherit spdxId;
+ url = "https://spdx.org/licenses/${spdxId}.html";
+ }
+ // optionalAttrs (attrs ? url) {
+ inherit url;
+ }
+ // optionalAttrs (attrs ? fullName) {
+ inherit fullName;
+ };
}
diff --git a/lib/licenses/licenses.nix b/lib/licenses/licenses.nix
index 6ddb588312fa..da253f7db94b 100644
--- a/lib/licenses/licenses.nix
+++ b/lib/licenses/licenses.nix
@@ -1,39 +1,6 @@
{ lib }:
let
- inherit (lib) optionalAttrs;
-
- mkLicense =
- lname:
- {
- shortName ? lname,
- # Most of our licenses are Free, explicitly declare unfree additions as such!
- free ? true,
- deprecated ? false,
- spdxId ? null,
- url ? null,
- fullName ? null,
- redistributable ? free,
- }@attrs:
- {
- inherit
- shortName
- free
- deprecated
- redistributable
- ;
- licenseType = "simple";
- }
- // optionalAttrs (attrs ? spdxId) {
- inherit spdxId;
- url = "https://spdx.org/licenses/${spdxId}.html";
- }
- // optionalAttrs (attrs ? url) {
- inherit url;
- }
- // optionalAttrs (attrs ? fullName) {
- inherit fullName;
- };
-
+ mkLicense = shortName: license: lib.licenses.mkLicense ({ inherit shortName; } // license);
in
lib.mapAttrs mkLicense (
{
From 295b7d18054ea572227bab5da0830253f5b9b4bf Mon Sep 17 00:00:00 2001
From: jopejoe1
Date: Fri, 11 Sep 2026 14:56:10 +0200
Subject: [PATCH 04/61] lib.licenses: improve doc-comments
I was missing some understanding about the structure of doc-comments as
I wrote these improved thes with a better understanding of how those get rendered.
---
lib/licenses/helpers.nix | 132 +++++++++++++++++++++++--------------
lib/licenses/operators.nix | 84 +++++++++++++----------
2 files changed, 131 insertions(+), 85 deletions(-)
diff --git a/lib/licenses/helpers.nix b/lib/licenses/helpers.nix
index 37721489f77a..b0a4b492df8c 100644
--- a/lib/licenses/helpers.nix
+++ b/lib/licenses/helpers.nix
@@ -22,22 +22,31 @@ rec {
/**
Evaluate a license expression for a given predicate.
- # Example
+ # Inputs
+
+ `predicate`
+ : Predicate which should get used for checking licenses
+
+ `permissive`
+ : Whether to apply checks permissive or reciprocal
+
+ `license`
+ : License expression which should be evaluated
- ```nix
- evaluateProperty (x: x.free) true (with lib.licenses; AND [ ncsa (WITH asl20 llvm-exception) ])
- ```
# Type
```
- evaluateProperty :: Function -> Bool -> AttrSet -> Bool
+ evaluateProperty :: (a -> Bool) -> Bool -> { [String] :: a } -> Bool
```
- # Arguments
+ # Example
+ :::{.example}
+ ## `lib.licenses.evaluateProperty usage example`
- - [predicate] checks for each license included in the license expression
- - [permissive] whether to apply checks permissive or reciprocal
- - [license] license expression to check
+ ```nix
+ evaluateProperty (x: x.free) true (with lib.licenses; AND [ ncsa (WITH asl20 llvm-exception) ])
+ => true
+ ```
*/
evaluateProperty =
predicate: permissive:
@@ -53,22 +62,31 @@ rec {
Evaluate a license expression for a given property name. The property must
be defined as a boolean attribute of all licenses passed.
- # Example
+ # Inputs
+
+ `name`
+ : Name of the Attribute which should be checked
+
+ `permissive`
+ : Whether to apply checks permissive or reciprocal
+
+ `license`
+ : License expression which should be evaluated
- ```nix
- evaluateNamedProperty "deprecated" true (with lib.licenses; AND [ ncsa (WITH asl20 llvm-exception) ])
- ```
# Type
```
- evaluateProperty :: String -> Bool -> AttrSet -> Bool
+ evaluateNamedProperty :: String -> Bool -> AttrSet -> Bool
```
- # Arguments
+ # Example
+ :::{.example}
+ ## `lib.licenses.evaluateNamedProperty` usage example
- - [name] name of the attribute to check
- - [permissive] whether to apply checks permissive or reciprocal
- - [license] license expression to check
+ ```nix
+ evaluateNamedProperty "deprecated" true (with lib.licenses; AND [ ncsa (WITH asl20 llvm-exception) ])
+ => false
+ ```
*/
evaluateNamedProperty =
name: permissive:
@@ -83,12 +101,10 @@ rec {
/**
Check whether a license expression is free.
- # Example
+ # Inputs
- ```nix
- isFree (with lib.licenses; (AND [ ncsa (WITH asl20 llvm-exception) ]))
- => true
- ```
+ `license`
+ : License expression which should be evaluated
# Type
@@ -96,21 +112,24 @@ rec {
isFree :: AttrSet -> Bool
```
- # Arguments
+ # Example
+ :::{.example}
+ ## `lib.licenses.isFree` usage example
- - [license] License expression to check if free
+ ```nix
+ isFree (with lib.licenses; (AND [ ncsa (WITH asl20 llvm-exception) ]))
+ => true
+ ```
*/
isFree = evaluateNamedProperty "free" true;
/**
Check whether a license expression is redistributable.
- # Example
+ # Inputs
- ```nix
- isRedistributable (with lib.licenses; (AND [ ncsa (WITH asl20 llvm-exception) ]))
- => true
- ```
+ `license`
+ : License expression which should be evaluated
# Type
@@ -118,44 +137,52 @@ rec {
isRedistributable :: AttrSet -> Bool
```
- # Arguments
+ # Example
+ :::{.example}
+ ## `lib.licenses.isRedistributable` usage example
- - [license] License expression to check if redistributable
+ ```nix
+ isRedistributable (with lib.licenses; (AND [ ncsa (WITH asl20 llvm-exception) ]))
+ => true
+ ```
*/
isRedistributable = evaluateNamedProperty "redistributable" true;
/**
Check whether any of the given licenses is required in the license expression.
+ # Inputs
+
+ `licenses`
+ : List of licenses which are tested
+
+ `license`
+ : License expression which should be evaluated
+
+ # Type
+
+ ```
+ containsLicenses :: [AttrSet] -> AttrSet -> Bool
+ ```
+
# Example
+ :::{.example}
+ ## `lib.licenses.containsLicenses` usage example
```nix
containsLicenses [ lib.licenses.asl20 ] (with lib.licenses; (AND [ ncsa (WITH asl20 llvm-exception) ]))
=> true
```
-
- # Type
-
- ```
- containsLicenses :: List -> AttrSet -> Bool
- ```
-
- # Arguments
-
- - [licenses] List of licenses to look
- - [license] License expression to check
*/
containsLicenses = licenses: evaluateProperty (x: elem x licenses) false;
/**
Convert a license expression to an SPDX license expression string.
- # Example
+ # Inputs
- ```nix
- toSPDX (with lib.licenses; AND [ ncsa (WITH asl20 llvm-exception) ])
- => "NCSA AND (Apache-2.0 WITH LLVM-exception)"
- ```
+ `license`
+ : License expression which to convert to an spdx expression
# Type
@@ -163,9 +190,14 @@ rec {
toSPDX :: AttrSet -> String
```
- # Arguments
+ # Example
+ :::{.example}
+ ## `lib.licenses.toSPDX` usage example
- - [license] License expression which to convert to spdx expression
+ ```nix
+ toSPDX (with lib.licenses; AND [ ncsa (WITH asl20 llvm-exception) ])
+ => "NCSA AND (Apache-2.0 WITH LLVM-exception)"
+ ```
*/
toSPDX =
license:
diff --git a/lib/licenses/operators.nix b/lib/licenses/operators.nix
index db7cc25d37c6..b5326473b6da 100644
--- a/lib/licenses/operators.nix
+++ b/lib/licenses/operators.nix
@@ -3,22 +3,25 @@
This should be used when there is a choice of which license expression to use.
This is a disjunctive binary "OR" operator.
+ # Inputs
+
+ `licenses`
+ : Possible licenses to choose from
+
+ # Type
+
+ ```
+ OR :: [AttrSet] -> AttrSet
+ ```
+
# Example
+ :::{.example}
+ ## `lib.licenses.OR` usage example
```nix
OR [ lib.licenses.mit lib.licenses.asl20 ]
=> { licenseType = "compound"; operator = "OR"; licenses = [ lib.licenses.mit lib.licenses.asl20 ] };
```
-
- # Type
-
- ```
- OR :: List -> AttrSet
- ```
-
- # Arguments
-
- - [licenses] Possible licenses to choose from
*/
OR = licenses: {
licenseType = "compound";
@@ -30,22 +33,25 @@
Create a compound licenses where the user needs to follow both licenses,
eqivialent of spdx `and` modifier.
+ # Inputs
+
+ `licenses`
+ : Licenses required to use
+
+ # Type
+
+ ```
+ AND :: [AttrsSet] -> AttrSet
+ ```
+
# Example
+ :::{.example}
+ ## `lib.licenses.AND` usage example
```nix
AND [ lib.licenses.mit lib.licenses.asl20 ]
=> { licenseType = "compound"; operator = "AND"; licenses = [ lib.licenses.mit lib.licenses.asl20 ] };
```
-
- # Type
-
- ```
- AND :: List -> AttrSet
- ```
-
- # Arguments
-
- - [licenses] Licenses required to use
*/
AND = licenses: {
licenseType = "compound";
@@ -57,12 +63,13 @@
Create a licenses exception where a license has a license exception,
eqivialent of spdx `with` modifier.
- # Example
+ # Inputs
- ```nix
- WITH lib.licenses.lgpl21Only lib.licenses.ocamlLgplLinkingException
- => { licenseType = "exception"; operator = "WITH"; license = lib.licenses.lgpl21Only; exception = lib.licenses.ocamlLgplLinkingException; };
- ```
+ `license`
+ : License to which the exception applies
+
+ `exception`
+ : Exception to apply
# Type
@@ -70,10 +77,14 @@
WITH :: AttrSet -> AttrSet -> AttrSet
```
- # Arguments
+ # Example
+ :::{.example}
+ ## `lib.licenses.WITH` usage example
- - [license] License to which the exception applies
- - [exception] Exception to apply
+ ```nix
+ WITH lib.licenses.lgpl21Only lib.licenses.ocamlLgplLinkingException
+ => { licenseType = "exception"; operator = "WITH"; license = lib.licenses.lgpl21Only; exception = lib.licenses.ocamlLgplLinkingException; };
+ ```
*/
WITH = license: exception: {
licenseType = "exception";
@@ -85,12 +96,10 @@
Create a licenses which can be upgraded to any later version of itself,
eqivialent of spdx `+` modifier
- # Example
+ # Inputs
- ```nix
- PLUS lib.licenses.eupl11
- => { licenseType = "plus"; operator = "+"; license = lib.licenses.eupl11; };
- ```
+ `license`
+ : License to which apply an exception
# Type
@@ -98,9 +107,14 @@
PLUS :: AttrSet -> AttrSet
```
- # Arguments
+ # Example
+ :::{.example}
+ ## `lib.licenses.PLUS` usage example
- - [license] License to wich apply an exception
+ ```nix
+ PLUS lib.licenses.eupl11
+ => { licenseType = "plus"; operator = "+"; license = lib.licenses.eupl11; };
+ ```
*/
PLUS = license: {
licenseType = "plus";
From 6a259ddee155a4b962d4fd21b860a76f8fd9ad6e Mon Sep 17 00:00:00 2001
From: Atemu
Date: Fri, 18 Sep 2026 18:05:22 +0200
Subject: [PATCH 05/61] aw-watcher-steam: init at 0-unstable-2025-06-16
---
pkgs/by-name/aw/aw-watcher-steam/package.nix | 44 ++++++++++++++++++++
1 file changed, 44 insertions(+)
create mode 100644 pkgs/by-name/aw/aw-watcher-steam/package.nix
diff --git a/pkgs/by-name/aw/aw-watcher-steam/package.nix b/pkgs/by-name/aw/aw-watcher-steam/package.nix
new file mode 100644
index 000000000000..791bd9909a21
--- /dev/null
+++ b/pkgs/by-name/aw/aw-watcher-steam/package.nix
@@ -0,0 +1,44 @@
+{
+ lib,
+ python3Packages,
+ fetchFromGitHub,
+ unstableGitUpdater,
+}:
+
+python3Packages.buildPythonApplication (finalAttrs: {
+ pname = "aw-watcher-steam";
+ version = "0-unstable-2025-06-16";
+ pyproject = true;
+ __structuredAttrs = true;
+
+ src = fetchFromGitHub {
+ owner = "Edwardsoen";
+ repo = "aw-watcher-steam";
+ rev = "55ea988994acfbf729fa43612f2057a310c1cc8f";
+ hash = "sha256-wd+q83MlgMeiYSHQwMtszwnDrkaDN3yVkV/P5HsU89U=";
+ };
+
+ build-system = [
+ python3Packages.poetry-core
+ ];
+
+ dependencies = with python3Packages; [
+ aw-client
+ requests
+ ];
+
+ pythonImportsCheck = [
+ "aw_watcher_steam"
+ ];
+
+ passthru.updateScript = unstableGitUpdater { };
+
+ meta = {
+ homepage = "https://github.com/Edwardsoen/aw-watcher-steam";
+ license = lib.licenses.mit;
+ maintainers = with lib.maintainers; [
+ atemu
+ ];
+ mainProgram = "aw-watcher-steam";
+ };
+})
From bf1b9393620b98d45bd2e1f7e568385ddeacc474 Mon Sep 17 00:00:00 2001
From: mtnash
Date: Wed, 26 Aug 2026 08:48:21 -0400
Subject: [PATCH 06/61] nixos/discourse: update config to match v2026.8.0
---
nixos/modules/services/web-apps/discourse.nix | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/nixos/modules/services/web-apps/discourse.nix b/nixos/modules/services/web-apps/discourse.nix
index 7ad8705ae658..e5e61b73bac1 100644
--- a/nixos/modules/services/web-apps/discourse.nix
+++ b/nixos/modules/services/web-apps/discourse.nix
@@ -644,8 +644,8 @@ in
s3_role_arn = null;
s3_role_session_name = null;
- max_user_api_reqs_per_minute = 20;
- max_user_api_reqs_per_day = 2880;
+ max_user_api_reqs_per_minute = 50;
+ max_user_api_reqs_per_day = 4000;
max_admin_api_reqs_per_minute = 60;
max_reqs_per_ip_per_minute = 200;
max_reqs_per_ip_per_10_seconds = 50;
From 231356700c77e27ef5750b325aa7c56b64d35f86 Mon Sep 17 00:00:00 2001
From: mtnash
Date: Wed, 26 Aug 2026 09:18:27 -0400
Subject: [PATCH 07/61] discourse: 2026.7.1 -> 2026.8.0
Upstream changes: https://releases.discourse.org/changelog/custom?end=v2026.8.0&start=v2026.7.1
Changes
- fix patch to safe_exec, no change in function
- patch all instances of PrecompiledBundle to store their output in frontend/ instead of tmp/ so it can be properly used. this replaces the previous patch with a similar function, that was specific to the asset_processor.rb code
- fix update.py, fetchPnpmDeps no longer outputs the correct hash in errors unless the hash is set to an empty string.
- automated updates (update.py) to main packages
- automated updates (update.py) to plugins [discourse-prometheus]
---
pkgs/servers/web-apps/discourse/default.nix | 10 +--
.../include-precompiled-bundles.patch | 26 +++++++
.../plugins/discourse-prometheus/default.nix | 4 +-
.../discourse/prebuild-asset-processor.patch | 13 ----
.../web-apps/discourse/rubyEnv/Gemfile.lock | 76 +++++++++----------
.../web-apps/discourse/rubyEnv/gemset.nix | 48 ++++++------
.../discourse/safe-exec-from-nix-store.patch | 4 +-
pkgs/servers/web-apps/discourse/update.py | 19 ++++-
8 files changed, 115 insertions(+), 85 deletions(-)
create mode 100644 pkgs/servers/web-apps/discourse/include-precompiled-bundles.patch
delete mode 100644 pkgs/servers/web-apps/discourse/prebuild-asset-processor.patch
diff --git a/pkgs/servers/web-apps/discourse/default.nix b/pkgs/servers/web-apps/discourse/default.nix
index b66d9ddfa942..d864f478c59f 100644
--- a/pkgs/servers/web-apps/discourse/default.nix
+++ b/pkgs/servers/web-apps/discourse/default.nix
@@ -54,13 +54,13 @@
}:
let
- version = "2026.7.1";
+ version = "2026.8.0";
src = fetchFromGitHub {
owner = "discourse";
repo = "discourse";
tag = "v${version}";
- hash = "sha256-sGygaOCygtDVjg8uBGdDVaRouUKib8aAukaBAY8aQ9w=";
+ hash = "sha256-UUDPZVBQXG6kfW8+TFFDHsNMdH8WLxsgva4jSdZWsC8=";
};
pnpm = pnpm_10;
@@ -350,7 +350,7 @@ let
pname = "discourse-assets";
inherit version src pnpm;
fetcherVersion = 3;
- hash = "sha256-T0qcUYHqpjeGlyozcaiVI/Art0zh2PLyuMzbquhfe/o=";
+ hash = "sha256-fm6hboG2Bjq0HUnbwdLiC1FpoWRZvq+1bN5SupQ2P2k=";
};
nativeBuildInputs = runtimeDeps ++ [
@@ -392,7 +392,7 @@ let
# because we fail to copy tmp/ (the default directory where the asset processor is cached,
# see notes in the discourse `installPhase`) we need to change the directory to something under
# frontend/ which is moved over as expected.
- ./prebuild-asset-processor.patch
+ ./include-precompiled-bundles.patch
# safe_exec.rb, which is used to execute ImageMagick among other things, restricts executable paths to standard FHS paths
# which breaks on nix. this patch adds the entire /nix/store to allowed paths, which is sub-optimal but
@@ -507,7 +507,7 @@ let
# because we fail to copy tmp/ (the default directory where the asset processor is cached,
# see notes in the discourse `installPhase`) we need to change the directory to something under
# frontend/ which is moved over as expected.
- ./prebuild-asset-processor.patch
+ ./include-precompiled-bundles.patch
# safe_exec.rb, which is used to execute ImageMagick among other things, restricts executable paths to standard FHS paths
# which breaks on nix. this patch adds the entire /nix/store to allowed paths, which is sub-optimal but
diff --git a/pkgs/servers/web-apps/discourse/include-precompiled-bundles.patch b/pkgs/servers/web-apps/discourse/include-precompiled-bundles.patch
new file mode 100644
index 000000000000..962398f06eb9
--- /dev/null
+++ b/pkgs/servers/web-apps/discourse/include-precompiled-bundles.patch
@@ -0,0 +1,26 @@
+diff --git a/lib/asset_processor.rb b/lib/asset_processor.rb
+index 0c602a85220..be1e22061b0 100644
+--- a/lib/asset_processor.rb
++++ b/lib/asset_processor.rb
+@@ -5,7 +5,7 @@ class AssetProcessor
+
+ BUNDLE =
+ PrecompiledBundle.new(
+- dir: "tmp/asset-processor",
++ dir: "frontend/asset-processor.build",
+ filename_prefix: "asset-processor",
+ dependency_globs: %w[
+ node_modules/.pnpm/lock.yaml
+diff --git a/lib/pretty_text.rb b/lib/pretty_text.rb
+index 6f176324799..9815f579212 100644
+--- a/lib/pretty_text.rb
++++ b/lib/pretty_text.rb
+@@ -54,7 +54,7 @@ module PrettyText
+
+ CORE_BUNDLE =
+ PrecompiledBundle.new(
+- dir: "tmp/pretty-text-processor",
++ dir: "frontend/pretty-text-processor.build",
+ filename_prefix: "pretty-text",
+ dependency_globs:
+ %w[
diff --git a/pkgs/servers/web-apps/discourse/plugins/discourse-prometheus/default.nix b/pkgs/servers/web-apps/discourse/plugins/discourse-prometheus/default.nix
index aa9437d33559..1f75f3cc44b9 100644
--- a/pkgs/servers/web-apps/discourse/plugins/discourse-prometheus/default.nix
+++ b/pkgs/servers/web-apps/discourse/plugins/discourse-prometheus/default.nix
@@ -10,8 +10,8 @@ mkDiscoursePlugin {
src = fetchFromGitHub {
owner = "discourse";
repo = "discourse-prometheus";
- rev = "ce51879d2c487cf74ca08d6d83d6ccb41cb28738";
- sha256 = "sha256-OhzWC8dgfwhre1HF5sjqXAeIJd3wuknzb12RMCz3+4Y=";
+ rev = "8850b2ee1acb69266f8697c3741f34cca80cad61";
+ sha256 = "sha256-7koWRb0ifMwHdtpjV6X4yTiKmK7zVCdIJlewkY5Vgzs=";
};
patches = [
diff --git a/pkgs/servers/web-apps/discourse/prebuild-asset-processor.patch b/pkgs/servers/web-apps/discourse/prebuild-asset-processor.patch
deleted file mode 100644
index 774907ceaad2..000000000000
--- a/pkgs/servers/web-apps/discourse/prebuild-asset-processor.patch
+++ /dev/null
@@ -1,13 +0,0 @@
-diff --git a/lib/asset_processor.rb b/lib/asset_processor.rb
-index bacb376c856..11d7d7edd32 100644
---- a/lib/asset_processor.rb
-+++ b/lib/asset_processor.rb
-@@ -3,7 +3,7 @@
- class AssetProcessor
- BASE_COMPILER_VERSION = 113
-
-- PROCESSOR_DIR = "tmp/asset-processor"
-+ PROCESSOR_DIR = "frontend/asset-processor.build"
- LOCK_FILE = "#{PROCESSOR_DIR}/build.lock"
-
- CACHE_DEPENDENCY_GLOBS = %w[
diff --git a/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile.lock b/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile.lock
index d2cdb9f438e7..0e3517db3815 100644
--- a/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile.lock
+++ b/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile.lock
@@ -5,7 +5,7 @@ PATH
activesupport
colored2
i18n
- markbridge (>= 0.3.1)
+ markbridge (>= 0.4.0)
migrations-core
pg
zeitwerk
@@ -53,16 +53,16 @@ GEM
remote: https://rubygems.org/
specs:
Ascii85 (2.0.1)
- actionmailer (8.0.5)
- actionpack (= 8.0.5)
- actionview (= 8.0.5)
- activejob (= 8.0.5)
- activesupport (= 8.0.5)
+ actionmailer (8.0.5.1)
+ actionpack (= 8.0.5.1)
+ actionview (= 8.0.5.1)
+ activejob (= 8.0.5.1)
+ activesupport (= 8.0.5.1)
mail (>= 2.8.0)
rails-dom-testing (~> 2.2)
- actionpack (8.0.5)
- actionview (= 8.0.5)
- activesupport (= 8.0.5)
+ actionpack (8.0.5.1)
+ actionview (= 8.0.5.1)
+ activesupport (= 8.0.5.1)
nokogiri (>= 1.8.5)
rack (>= 2.2.4)
rack-session (>= 1.0.1)
@@ -70,8 +70,8 @@ GEM
rails-dom-testing (~> 2.2)
rails-html-sanitizer (~> 1.6)
useragent (~> 0.16)
- actionview (8.0.5)
- activesupport (= 8.0.5)
+ actionview (8.0.5.1)
+ activesupport (= 8.0.5.1)
builder (~> 3.1)
erubi (~> 1.11)
rails-dom-testing (~> 2.2)
@@ -80,16 +80,16 @@ GEM
actionview (>= 6.0.a)
active_model_serializers (0.8.4)
activemodel (>= 3.0)
- activejob (8.0.5)
- activesupport (= 8.0.5)
+ activejob (8.0.5.1)
+ activesupport (= 8.0.5.1)
globalid (>= 0.3.6)
- activemodel (8.0.5)
- activesupport (= 8.0.5)
- activerecord (8.0.5)
- activemodel (= 8.0.5)
- activesupport (= 8.0.5)
+ activemodel (8.0.5.1)
+ activesupport (= 8.0.5.1)
+ activerecord (8.0.5.1)
+ activemodel (= 8.0.5.1)
+ activesupport (= 8.0.5.1)
timeout (>= 0.4.0)
- activesupport (8.0.5)
+ activesupport (8.0.5.1)
base64
benchmark (>= 0.3)
bigdecimal
@@ -318,7 +318,7 @@ GEM
simpleidn (~> 0.2)
jwt (2.10.1)
base64
- landlock (0.3)
+ landlock (0.4.1)
language_server-protocol (3.17.0.5)
libv8-node (24.12.0.1)
libv8-node (24.12.0.1-aarch64-linux)
@@ -355,7 +355,7 @@ GEM
net-imap
net-pop
net-smtp
- markbridge (0.3.1)
+ markbridge (0.4.0)
matrix (0.4.3)
maxminddb (0.1.22)
memory_profiler (1.1.0)
@@ -370,7 +370,7 @@ GEM
mime-types-data (3.2026.0414)
mini_mime (1.1.5)
mini_portile2 (2.8.9)
- mini_racer (0.21.4)
+ mini_racer (0.22.0)
libv8-node (~> 24.12.0.1)
mini_scheduler (0.20.0)
sidekiq (>= 6.5, < 9.0)
@@ -547,9 +547,9 @@ GEM
rails_multisite (7.0.0)
activerecord (>= 7.1)
railties (>= 7.1)
- railties (8.0.5)
- actionpack (= 8.0.5)
- activesupport (= 8.0.5)
+ railties (8.0.5.1)
+ actionpack (= 8.0.5.1)
+ activesupport (= 8.0.5.1)
irb (~> 1.13)
rackup (>= 1.0.0)
rake (>= 12.2)
@@ -563,7 +563,7 @@ GEM
rb-fsevent (0.11.2)
rb-inotify (0.11.1)
ffi (~> 1.0)
- rb_sys (0.9.128)
+ rb_sys (0.9.130)
rake-compiler-dock (= 1.12.0)
rbs (4.0.2)
logger
@@ -1007,15 +1007,15 @@ DEPENDENCIES
CHECKSUMS
Ascii85 (2.0.1) sha256=15cb5d941808543cbb9e7e6aea3c8ec3877f154c3461e8b3673e97f7ecedbe5a
- actionmailer (8.0.5) sha256=7918fac842cfe985ed21692f3d212c914a0c816e30e6fa68633177bb22f38561
- actionpack (8.0.5) sha256=c9de868975dd124a0956499140bd5e63c367865deca01292df7c3195c8da4b35
- actionview (8.0.5) sha256=6d0fa9e63df0cf2729b1f54d0988336c149eb2bbc6049f4c2834d7b62f351413
+ actionmailer (8.0.5.1) sha256=c3d2b3f96e1989ea25f51699786a97fcb2536eb7abfc2a667cb8f2376ec08403
+ actionpack (8.0.5.1) sha256=a5595c9d824d68884ddc4d3965ab78c897760d3752e190df7efe897371caa1eb
+ actionview (8.0.5.1) sha256=472a108b9cc2295c4ac3ff09b028045e619875801f48c556f0085210b9cb1440
actionview_precompiler (0.4.0) sha256=33b6bd6ec4c1b856e02fdf5f6512c9eb4a92ac1c0545e941b3e354b7d540ed1c
active_model_serializers (0.8.4) sha256=7350e3d3b6a5946bbec033241d908013cc85ff4d584230e6aa074225547c754c
- activejob (8.0.5) sha256=2dabe5c3bfe284aba4687c52b930564335435dde3a60b047821f9d3bd0d2ea10
- activemodel (8.0.5) sha256=c796813d46dc1373f4c6c0ec91dfc520b53683ea773c3b3f9a12c4b3eb145bc2
- activerecord (8.0.5) sha256=89b261b6cd910c9431cf2475f3f6e5e2f5ce589805043a33ef2b004376a129e6
- activesupport (8.0.5) sha256=37f213ff6a37cf3fadfa1a28c1a9678e2cb73b59bb9ebd0eeeca653cccadcb23
+ activejob (8.0.5.1) sha256=142407a21b6c3cbc6ddd92ca111ac18ea5c40298eb94d81845cd897a072a6880
+ activemodel (8.0.5.1) sha256=559be32aa9c40db7a3ee0aef926d4508a9ebd22f96f7276c11326d21a7dff4a4
+ activerecord (8.0.5.1) sha256=9252968fce404d75eb17092498a440d472167f2f8deee32b4658d6552b1eeea7
+ activesupport (8.0.5.1) sha256=329a4280c4fbcfcf338ae2cb9df28b0b14527929dba105e10b3604516d998710
addressable (2.9.0) sha256=7fdf6ac3660f7f4e867a0838be3f6cf722ace541dd97767fa42bc6cfa980c7af
afm (1.0.0) sha256=5bd4d6f6241e7014ef090985ec6f4c3e9745f6de0828ddd58bc1efdd138f4545
annotaterb (4.20.0) sha256=871b2e898d1d60c23bdc59b72a5b840678a56355bf5f6fdeb8c79d317ff98bf7
@@ -1127,7 +1127,7 @@ CHECKSUMS
json_completer (1.2.0) sha256=4665749172634eccb208c562eb59ea81dd7a612a1fa9a36df441ac473ff177b1
json_schemer (2.5.0) sha256=2f01fb4cce721a4e08dd068fc2030cffd0702a7f333f1ea2be6e8991f00ae396
jwt (2.10.1) sha256=e6424ae1d813f63e761a04d6284e10e7ec531d6f701917fadcd0d9b2deaf1cc5
- landlock (0.3) sha256=841ae1ef1318082a485ae919b6a481ceb9c2d3ac9294ada27e2a3c529446b23c
+ landlock (0.4.1) sha256=95c9b119ff831fae35756ddcd5e9d5f99b9705be71f37a0972f86c825b78b14f
language_server-protocol (3.17.0.5) sha256=fd1e39a51a28bf3eec959379985a72e296e9f9acfce46f6a79d31ca8760803cc
libv8-node (24.12.0.1) sha256=d93d23b861bfe5de3ba829e34a142402fb83b4c3592dd58d9ac4e027588d739a
libv8-node (24.12.0.1-aarch64-linux) sha256=22bd0246cde85d70c88cf772727ac3677a20ac1d169105f82efe5f1f7c39f755
@@ -1148,7 +1148,7 @@ CHECKSUMS
lru_redux (1.1.0) sha256=ee71d0ccab164c51de146c27b480a68b3631d5b4297b8ffe8eda1c72de87affb
lz4-ruby (0.3.3) sha256=011be5ee230cfddc8308d4e2e0b05300c7bc755a887de799377ca6c5b6aede89
mail (2.9.0) sha256=6fa6673ecd71c60c2d996260f9ee3dd387d4673b8169b502134659ece6d34941
- markbridge (0.3.1) sha256=a36dff4e79e666fe7f944d4a806f507212191b80d22878ab3ee9008d9df975a3
+ markbridge (0.4.0) sha256=27645fd47489d2fd42068153fa471b7e5231dd8dabb31c1bf38c88aa37535b12
matrix (0.4.3) sha256=a0d5ab7ddcc1973ff690ab361b67f359acbb16958d1dc072b8b956a286564c5b
maxminddb (0.1.22) sha256=50933be438fbed9dceabef4163eab41884bd8830d171fdb8f739bee769c4907e
memory_profiler (1.1.0) sha256=79a17df7980a140c83c469785905409d3027ca614c42c086089d128b805aa8f8
@@ -1163,7 +1163,7 @@ CHECKSUMS
mime-types-data (3.2026.0414) sha256=461c4c655373a44bd6c5fe54bcf5b7776026ea96e808144b1ec465c4b99148cc
mini_mime (1.1.5) sha256=8681b7e2e4215f2a159f9400b5816d85e9d8c6c6b491e96a12797e798f8bccef
mini_portile2 (2.8.9) sha256=0cd7c7f824e010c072e33f68bc02d85a00aeb6fce05bb4819c03dfd3c140c289
- mini_racer (0.21.4) sha256=ccf5e37288097f079d84449e111cd4e2170b37f3b80b30900766ffa6df4632db
+ mini_racer (0.22.0) sha256=52e4c1797bcb01be550d8317764ac5ca8aa96b37f8f72dec6e090db99847ae30
mini_scheduler (0.20.0) sha256=bd8948228bf4a48a603a8e20de850d16b68295413d8651c8c05288f4c6997b05
mini_sql (1.6.0) sha256=5296637f6a4af5bb43e06788037e9a2968ff9c8eb65928befcba8cb41f42d6ee
mini_suffix (0.3.3) sha256=8d1d33f92f69a2247c9b7d27173235da90479d955cdb863b63a7f53843b722e7
@@ -1240,14 +1240,14 @@ CHECKSUMS
rails-html-sanitizer (1.7.0) sha256=28b145cceaf9cc214a9874feaa183c3acba036c9592b19886e0e45efc62b1e89
rails_failover (2.3.0) sha256=eed6ea0674fd6f9f6b070ad297ad2ead121ecf9202920f6068b6a4f29d9491c9
rails_multisite (7.0.0) sha256=7aacf364ed86d2bee73fb679cbfe6c343ce89067b9746b3d5857fffc57f036f2
- railties (8.0.5) sha256=ad98c6e9a096b7e8cf63c70872b60ec6c1d4152be2a4ffa63483ec02a837a9d5
+ railties (8.0.5.1) sha256=da1958e1d9dab04691a2f8721b3ff7fab323715d37f103c19972dedfd644d5c7
rainbow (3.1.1) sha256=039491aa3a89f42efa1d6dec2fc4e62ede96eb6acd95e52f1ad581182b79bc6a
raindrops (0.20.1) sha256=aa0eb9ff6834f2d9e232ba688bd49cb30be893bc5a3452e74722c94c1fab4730
rake (13.4.2) sha256=cb825b2bd5f1f8e91ca37bddb4b9aaf345551b4731da62949be002fa89283701
rake-compiler-dock (1.12.0) sha256=f13205c2738f3d2053afcd03491a9e4541b22a59a0bfc53fc8bc883bd8188023
rb-fsevent (0.11.2) sha256=43900b972e7301d6570f64b850a5aa67833ee7d87b458ee92805d56b7318aefe
rb-inotify (0.11.1) sha256=a0a700441239b0ff18eb65e3866236cd78613d6b9f78fea1f9ac47a85e47be6e
- rb_sys (0.9.128) sha256=9ab81f4d6d4e1895de18762232362d1264475aa7035756b50441e442130538fd
+ rb_sys (0.9.130) sha256=7d486d99c1da02635515deaf9860fc5aea90bb4ab2589b2deec7fdc7d3548615
rbs (4.0.2) sha256=af75671e66cd03434cc546622741ebf83f6197ec4328375805306330bf78ef25
rbtrace (0.5.4) sha256=8279e40076530f0301e255d0669cfe0d7d31ef872d1ae475c486e5a1199b757b
rchardet (1.10.2) sha256=e041cb195f464dc10e49ab130f78c8b5956cd9a4f4f6df84e0c183b87c135f33
diff --git a/pkgs/servers/web-apps/discourse/rubyEnv/gemset.nix b/pkgs/servers/web-apps/discourse/rubyEnv/gemset.nix
index 9e781f718be7..13be53ad0101 100644
--- a/pkgs/servers/web-apps/discourse/rubyEnv/gemset.nix
+++ b/pkgs/servers/web-apps/discourse/rubyEnv/gemset.nix
@@ -12,10 +12,10 @@ src: {
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
- sha256 = "0qc5ycibnxricdlgmrihds0hqjli5hhksbv947nqbsfg8b4gl63r";
+ sha256 = "00w4q1p3gwmqgik2mz5bnxp57cpwjxm7i68nyljym28rdvwv7ln3";
type = "gem";
};
- version = "8.0.5";
+ version = "8.0.5.1";
};
actionpack = {
dependencies = [
@@ -37,10 +37,10 @@ src: {
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
- sha256 = "0dabvb49acbwvy91587cbn36ghv3bsyl14a9aq4ll4nxfn4qdpn9";
+ sha256 = "1sx1r9qp72gygvgr1qaj6w6pd5y8g2mnafadvi6qhs2dhafmqnd5";
type = "gem";
};
- version = "8.0.5";
+ version = "8.0.5.1";
};
actionview = {
dependencies = [
@@ -58,10 +58,10 @@ src: {
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
- sha256 = "04ql6lpvdmrl5169y166pfr9w53c6f40jkgmn4ljgkzh7pkaj3vd";
+ sha256 = "0h0lrfwi0lh8y1bcaj0zh1srhqay0hlb02gzqd55qaf2kj5i0aj7";
type = "gem";
};
- version = "8.0.5";
+ version = "8.0.5.1";
};
actionview_precompiler = {
dependencies = [ "actionview" ];
@@ -94,10 +94,10 @@ src: {
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
- sha256 = "047asb83p78zh93v0q1svrfl6da3aqqbjlkwd2jap172pz1ybard";
+ sha256 = "1038583pm2fd8lcdi57bk01c99cfq4d13jljvmnvqg3c3fi0f90l";
type = "gem";
};
- version = "8.0.5";
+ version = "8.0.5.1";
};
activemodel = {
dependencies = [ "activesupport" ];
@@ -110,10 +110,10 @@ src: {
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
- sha256 = "1hjv2kmv7i0jk8zkng3pxa1kdd90qpgr3v60qvs764yw8qyq35n7";
+ sha256 = "197lvykj2v9j25n2gxwn5z9fpa888mnr5vqaxsivf3f4m4mf76sm";
type = "gem";
};
- version = "8.0.5";
+ version = "8.0.5.1";
};
activerecord = {
dependencies = [
@@ -130,10 +130,10 @@ src: {
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
- sha256 = "1ri9l5v4601bxwrkl105k1ccxxg2wpvg6x94rwqr834irnv63cl9";
+ sha256 = "19zf3qmmbmjq8qmy7vld5xzicwnl82j9h9092zmpaka0rs7rcllj";
type = "gem";
};
- version = "8.0.5";
+ version = "8.0.5.1";
};
activesupport = {
dependencies = [
@@ -159,10 +159,10 @@ src: {
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
- sha256 = "08ybmp63qrfaxq7bv7mvb4xvfb4fcylw2a0szankzkrpdbzi7wip";
+ sha256 = "0447k5nm211n1ghhb8fv55wm450bigr9vjz2i8rwzkzvqj0456ij";
type = "gem";
};
- version = "8.0.5";
+ version = "8.0.5.1";
};
addressable = {
dependencies = [ "public_suffix" ];
@@ -1497,10 +1497,10 @@ src: {
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
- sha256 = "0g5j8sa54g1agsiav54jmk9w5fffh6jbc6g9b942l20q2gpy26l4";
+ sha256 = "0kxig1dq4v7qf84pmwvipq2rg6zrsplxbp3dflssw7w3zwcv3jcm";
type = "gem";
};
- version = "0.3";
+ version = "0.4.1";
};
language_server-protocol = {
groups = [
@@ -1713,10 +1713,10 @@ src: {
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
- sha256 = "18vmz6fqs0797smpha6jh0dij4kja1pq0jjdjizzwrp6g57gyvd3";
+ sha256 = "04jvacvsm24cycdircxbipfk2lky3d3zllw10r1gvll9fka5yr17";
type = "gem";
};
- version = "0.3.1";
+ version = "0.4.0";
};
matrix = {
groups = [
@@ -1929,10 +1929,10 @@ src: {
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
- sha256 = "1nrj8vgsdzv60y8302xqycvhn5z2shf137j4hjfhfzq9i1rf7xfc";
+ sha256 = "0c5f8ycbj389dvn2vxzq6xmsk2naqm57c5w31mavw0fbgdww3r2j";
type = "gem";
};
- version = "0.21.4";
+ version = "0.22.0";
};
mini_scheduler = {
dependencies = [ "sidekiq" ];
@@ -2858,10 +2858,10 @@ src: {
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
- sha256 = "1md96yl05v436jkgz9725cax9hf61sv74267cg7yidwnl3lwd65d";
+ sha256 = "1iym8kbdzpkjk70h7w9pbmqj7czsywzinwpqla8ldc6sv7hmh6fs";
type = "gem";
};
- version = "8.0.5";
+ version = "8.0.5.1";
};
rainbow = {
groups = [
@@ -2955,10 +2955,10 @@ src: {
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
- sha256 = "1z9q0l9l5r210jsmcmq3lxd4fr0j5lv348kn33g9a62fdm6izf4s";
+ sha256 = "05c6ak9wgzf7xqnrnn5j9axr1sjszih9ibyy2man60nsq6cnsj3x";
type = "gem";
};
- version = "0.9.128";
+ version = "0.9.130";
};
rbs = {
dependencies = [
diff --git a/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch b/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch
index e3c444958a26..7e3799eccb33 100644
--- a/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch
+++ b/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch
@@ -1,11 +1,11 @@
diff --git a/lib/discourse/safe_exec.rb b/lib/discourse/safe_exec.rb
-index c4b8a5e3ecb..31d6f0d469d 100644
+index dc32954245c..259bfd99f0c 100644
--- a/lib/discourse/safe_exec.rb
+++ b/lib/discourse/safe_exec.rb
@@ -5,7 +5,7 @@ require "landlock"
module Discourse
class SafeExec
- DEFAULT_READ_PATHS = %w[/bin /etc /lib /lib64 /usr].freeze
+ DEFAULT_READ_PATHS = %w[/bin /lib /lib64 /usr].freeze
- DEFAULT_EXECUTE_PATHS = %w[/bin /lib /lib64 /usr].freeze
+ DEFAULT_EXECUTE_PATHS = %w[/bin /lib /lib64 /usr /nix/store].freeze
diff --git a/pkgs/servers/web-apps/discourse/update.py b/pkgs/servers/web-apps/discourse/update.py
index 6a1fa3f64b9a..d169c4d5c3e0 100755
--- a/pkgs/servers/web-apps/discourse/update.py
+++ b/pkgs/servers/web-apps/discourse/update.py
@@ -276,6 +276,8 @@ def update(rev):
subprocess.check_output(["rm", "-rf", "migrations"], cwd=rubyenv_dir)
# -- end gitlab pkg code
+ click.echo("updating dart-sass")
+
# update the sass-embedded override
# must run *after* the gemfile update!
dart_sass_ver = _nix_eval('discourse.rubyEnv.gemset.sass-embedded.version')
@@ -301,17 +303,32 @@ def update(rev):
f.write(content)
f.truncate()
+ click.echo("updating discourse package")
+
# update the discourse package itself
_call_nix_update('discourse', version.version)
+ click.echo("querying old PNPM hash")
old_pnpm_hash = _nix_eval('discourse.assets.pnpmDeps.outputHash')
+
+ click.echo("finding new PNPM hash")
+ # the pnpm builder now requires the has to be set to "" to output a "got: sha256-" line
+ empty_hash_line = f"hash = \"\";#{old_pnpm_hash}";
+ mk_hash_line = lambda hash: f"hash = \"{hash}\";"
+ with open(Path(__file__).parent / "default.nix", 'r+') as f:
+ content = f.read()
+ content = content.replace(mk_hash_line(old_pnpm_hash), empty_hash_line)
+ f.seek(0)
+ f.write(content)
+ f.truncate()
new_pnpm_hash = _get_build_lock_hash()
+
if new_pnpm_hash is not None:
click.echo(f"Updating pnpm lock hash: {old_pnpm_hash} -> {new_pnpm_hash}")
with open(Path(__file__).parent / "default.nix", 'r+') as f:
content = f.read()
- content = content.replace(old_pnpm_hash, new_pnpm_hash)
+ content = content.replace(empty_hash_line, mk_hash_line(new_pnpm_hash))
f.seek(0)
f.write(content)
f.truncate()
From 0ad08425d206e052f95a3fa756538904738b1c0a Mon Sep 17 00:00:00 2001
From: mtnash
Date: Mon, 14 Sep 2026 14:53:04 -0400
Subject: [PATCH 08/61] discourse: fix restrictive imagemagick policy breaking
on required symlinks in paths
---
pkgs/servers/web-apps/discourse/default.nix | 3 +++
.../web-apps/discourse/optimize-image-fix.patch | 11 +++++++++++
.../web-apps/discourse/safe-exec-from-nix-store.patch | 8 +++++---
3 files changed, 19 insertions(+), 3 deletions(-)
create mode 100644 pkgs/servers/web-apps/discourse/optimize-image-fix.patch
diff --git a/pkgs/servers/web-apps/discourse/default.nix b/pkgs/servers/web-apps/discourse/default.nix
index d864f478c59f..cead7c2e22d2 100644
--- a/pkgs/servers/web-apps/discourse/default.nix
+++ b/pkgs/servers/web-apps/discourse/default.nix
@@ -517,6 +517,9 @@ let
# Our app/assets/generated folder is a symlink, but the ruby File.mkdir_p doesn't allow
# a symlink in the way to the last directory. This patch explicitly resolves the symlink.
./resolve_generated_assets_symlink.patch
+
+ # in the imagemagick sandbox, symlinks permissions are checked (as you would hope) but this causes other problems..
+ ./optimize-image-fix.patch
];
postPatch = ''
diff --git a/pkgs/servers/web-apps/discourse/optimize-image-fix.patch b/pkgs/servers/web-apps/discourse/optimize-image-fix.patch
new file mode 100644
index 000000000000..56632d374b42
--- /dev/null
+++ b/pkgs/servers/web-apps/discourse/optimize-image-fix.patch
@@ -0,0 +1,11 @@
+diff --git a/config/imagemagick/policy.xml b/config/imagemagick/policy.xml
+index a29d02c021b..8075d701fee 100644
+--- a/config/imagemagick/policy.xml
++++ b/config/imagemagick/policy.xml
+@@ -41,5 +41,5 @@
+
+
+
+-
++
+
diff --git a/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch b/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch
index 7e3799eccb33..e652eff3924a 100644
--- a/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch
+++ b/pkgs/servers/web-apps/discourse/safe-exec-from-nix-store.patch
@@ -1,12 +1,14 @@
diff --git a/lib/discourse/safe_exec.rb b/lib/discourse/safe_exec.rb
-index dc32954245c..259bfd99f0c 100644
+index dc32954245c..a89d9afac97 100644
--- a/lib/discourse/safe_exec.rb
+++ b/lib/discourse/safe_exec.rb
-@@ -5,7 +5,7 @@ require "landlock"
+@@ -4,8 +4,8 @@ require "landlock"
+
module Discourse
class SafeExec
- DEFAULT_READ_PATHS = %w[/bin /lib /lib64 /usr].freeze
+- DEFAULT_READ_PATHS = %w[/bin /lib /lib64 /usr].freeze
- DEFAULT_EXECUTE_PATHS = %w[/bin /lib /lib64 /usr].freeze
++ DEFAULT_READ_PATHS = %w[/bin /lib /lib64 /usr /nix/store].freeze
+ DEFAULT_EXECUTE_PATHS = %w[/bin /lib /lib64 /usr /nix/store].freeze
def self.capture(
From dc128564d096dc61bc02d63bb4554f6b729a877f Mon Sep 17 00:00:00 2001
From: "R. Ryantm"
Date: Sun, 20 Sep 2026 01:05:53 +0000
Subject: [PATCH 09/61] moonlight: 2026.9.0 -> 2026.9.1
---
pkgs/by-name/mo/moonlight/package.nix | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/pkgs/by-name/mo/moonlight/package.nix b/pkgs/by-name/mo/moonlight/package.nix
index daaa382d85d0..d51fd8d09afd 100644
--- a/pkgs/by-name/mo/moonlight/package.nix
+++ b/pkgs/by-name/mo/moonlight/package.nix
@@ -17,13 +17,13 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "moonlight";
- version = "2026.9.0";
+ version = "2026.9.1";
src = fetchFromGitHub {
owner = "moonlight-mod";
repo = "moonlight";
tag = "v${finalAttrs.version}";
- hash = "sha256-J78pFRFONALG2QWuRQSekiaG9TNctrEM/IYG2Iot9gk=";
+ hash = "sha256-Bcqtviy8In/aQn8qT4sbAJKKYuVp6bwzA1TKzy1p2bo=";
};
nativeBuildInputs = [
From e958fba2175b8af6c8db2c0fbf0128f93b6186cd Mon Sep 17 00:00:00 2001
From: "R. Ryantm"
Date: Sun, 20 Sep 2026 15:23:37 +0000
Subject: [PATCH 10/61] kimai: 2.66.0 -> 2.67.0
---
pkgs/by-name/ki/kimai/package.nix | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/pkgs/by-name/ki/kimai/package.nix b/pkgs/by-name/ki/kimai/package.nix
index 64033d34d98f..c469628eadc9 100644
--- a/pkgs/by-name/ki/kimai/package.nix
+++ b/pkgs/by-name/ki/kimai/package.nix
@@ -7,13 +7,13 @@
php.buildComposerProject2 (finalAttrs: {
pname = "kimai";
- version = "2.66.0";
+ version = "2.67.0";
src = fetchFromGitHub {
owner = "kimai";
repo = "kimai";
tag = finalAttrs.version;
- hash = "sha256-cL7XhcNkuXsDV9rbjXTt9N+3pN9lPqUEiuVZ9ZrHx4w=";
+ hash = "sha256-yeQFo6rwtsRL32Pw+o4uXeS80Hyij4MENtdMybq5WMU=";
};
php = php.buildEnv {
@@ -38,7 +38,7 @@ php.buildComposerProject2 (finalAttrs: {
'';
};
- vendorHash = "sha256-TpQV62iRp9zEZsxbqg1EUt/dvU7NzS+K0J4gwcoBiPI=";
+ vendorHash = "sha256-VV4+pcMuxy0Xq31aq8J51xHUrt/6Bn4bDNb69OOFSo4=";
composerNoPlugins = false;
postInstall = ''
From b63c64b6479cf56ffdb7fd5b26eede6ed917afd3 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Gabriel=20N=C3=BCtzi?=
Date: Wed, 23 Sep 2026 14:18:28 +0200
Subject: [PATCH 11/61] nixosTest.gitlab.runner: remove podman-executor
- Remove the too complex podman executor and link to it in the
documentation over the NixOS wiki.
---
nixos/doc/manual/redirects.json | 3 -
nixos/modules/services/misc/gitlab/default.md | 96 +---
nixos/tests/gitlab/runner.nix | 15 -
.../gitlab/runner/podman-runner/default.nix | 435 ------------------
.../podman-runner/files/basicRoot/etc/group | 21 -
.../files/basicRoot/etc/nsswitch.conf | 11 -
.../podman-runner/files/basicRoot/etc/passwd | 34 --
.../containers/etc/containers/containers.conf | 2 -
.../containers/etc/containers/mounts.conf | 2 -
.../containers/etc/containers/policy.json | 12 -
.../containers/etc/containers/registries.conf | 2 -
.../registries.conf.d/000-shortnames.conf | 5 -
.../etc/containers/registries.d/default.yaml | 27 --
.../registry.access.redhat.com.yaml | 3 -
.../registries.d/registry.redhat.io.yaml | 3 -
.../containers/etc/containers/storage.conf | 15 -
.../runner/podman-runner/files/default.nix | 46 --
.../files/fake-nixpkgs/default.nix | 10 -
.../gitlab/runner/podman-runner/nix-image.nix | 400 ----------------
.../runner/podman-runner/scripts/prebuild.nix | 55 ---
.../runner/podman-runner/virtualization.nix | 43 --
21 files changed, 1 insertion(+), 1239 deletions(-)
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/default.nix
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/group
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/nsswitch.conf
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/passwd
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/containers.conf
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/mounts.conf
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/policy.json
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf.d/000-shortnames.conf
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/default.yaml
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.access.redhat.com.yaml
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.redhat.io.yaml
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/storage.conf
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/default.nix
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/files/fake-nixpkgs/default.nix
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/nix-image.nix
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/scripts/prebuild.nix
delete mode 100644 nixos/tests/gitlab/runner/podman-runner/virtualization.nix
diff --git a/nixos/doc/manual/redirects.json b/nixos/doc/manual/redirects.json
index 57c6a731ac68..ca7209ff5539 100644
--- a/nixos/doc/manual/redirects.json
+++ b/nixos/doc/manual/redirects.json
@@ -1502,9 +1502,6 @@
"module-services-gitlab-runner": [
"index.html#module-services-gitlab-runner"
],
- "ex-gitlab-runner-podman": [
- "index.html#ex-gitlab-runner-podman"
- ],
"module-forgejo": [
"index.html#module-forgejo"
],
diff --git a/nixos/modules/services/misc/gitlab/default.md b/nixos/modules/services/misc/gitlab/default.md
index 4b0b105b1145..94d99202422d 100644
--- a/nixos/modules/services/misc/gitlab/default.md
+++ b/nixos/modules/services/misc/gitlab/default.md
@@ -150,99 +150,5 @@ configured executors
The
[services.gitlab-runner.services](https://search.nixos.org/options?query=services.gitlab-runner.services)
documents a number of typical setups to configure multiple runners with
-different executors.
-
-The [below example](#ex-gitlab-runner-podman) gives a **more elaborate** example how to
+different executors. See also the [wiki section](https://wiki.nixos.org/wiki/Gitlab_runner#Configuring_a_podman-Executor_with_Nix_Store_Caching), which gives a **more elaborate** example how to
configure a Gitlab Runner with caching and reasonably good security practices.
-
-::: {#ex-gitlab-runner-podman .example}
-
-## Gitlab Runner with `podman` and Nix Store Caching
-
-The [VM tested `podman-runner`](https://github.com/NixOS/nixpkgs/blob/master/nixos/tests/gitlab/runner/podman-runner/default.nix)
-(a NixOS module for reuse) configures an advanced Gitlab runner with the following features:
-
-- The executor is `podman` which gives you better additional safety than
- `docker`. That means every job is run in a `podman` container.
-
-- The following container **images** are built with Nix:
-
- **Container Images for Gitlab Jobs**:
- - `local/alpine`: An image based on Alpine with a Nix installation
- (attribute `jobImages.alpine`).
- - `local/ubuntu`: An image based on Ubuntu with a Nix installation
- (attribute `jobImages.ubuntu`).
- - `local/nix`: An image based on Nix which only comes with `nix`
- installed (attribute `jobImages.nix`).
-
- **Images for VM Setup**:
- - `local/nix-daemon-image`: An image with a Nix daemon which is
- used to share the `/nix/store` across jobs (variable `nixDaemonImage`) setup with some essentials derivations `bootstrapPkgs`.
- - `local/podman-daemon-image`: An image with `podman` running as a daemon which is
- used to run `podman` inside the above job containers images
- (variable `podmanDaemonImage`).
-
-- Every job container runs in a `podman` container instance based by default on
- `jobImage.ubuntu`. A pipeline job can override this with `image: local/alpine`.
- - Each job container will have the `/nix/store` mounted from the container
- `nix-daemon-container` (see registration flags
- `--docker-volumes-from "nix-daemon-container:ro"`).
-
- The `nix-daemon-container` is a single container instance of a
- `nixDaemonImage`. This enables caching of `/nix/store` paths across all jobs
- in **all** runners. This makes **the host VM's `/nix/store` independent of the
- Nix store used in the jobs**, which is good.
-
- ::: {.note}
- **Security:** If you don't want this you need multiple `nixDaemonImage`
- containers for each registered runner (`gitlab-runner.services.`).
- :::
-
- - Each job container will have the `/run/podman/podman.sock` socket mounted from the
- `podman-daemon-container`.
-
- The `podman-daemon-container` is a single container of a `podmanDaemonImage` which runs
- `podman` as a daemon. Job containers can use this daemon to spawn nested containers as well (podman-in-podman).
- **Keep in mind that `bind` mounts are local to the `podman-daemon-container`**
- and can be be worked around with a `podman volume create ` and manual copy-to/copy-from this volume ``.
-
- If you only need to build containers you don't need this feature (`podman-daemon-container`), see below point.
-
- Container configuration files (`auxRootFiles`) are copied to all containers to
- ensure `podman` works consistently inside the job containers.
-
- - The job containers do **not** mount the `podman` socket from the host (NixOS
- VM) mounted for security reasons.
-
- ::: {.note}
- Building container images with `buildah` (stripped
- `podman` for building images) inside a job which runs `jobImage.alpine`
- is still possible.
- :::
-
- - **Cleanup Disk Space**:
-
- With this setup its really easy to clean the `nix-daemon-container`
- (e.g. if you run out of disk space), then reboot and have the runner in a clean state.
- You can do the following to effectively clean everything and start with fresh volumes safely:
-
- ```bash
- # Stop the Gitlab runner.
- systemctl stop gitlab-runner.service
- # Stop `systemd`-managed containers, such that they get not recreated
- # when deleting below.
- systemctl stop podman-podman-daemon-container.service \
- podman-nix-daemon-container.service \
- podman-nix-container.service \
- podman-alpine-container.service \
- podman-ubuntu-container.service || true
-
- podman container rm -f --all
- podman image rm -f --all
- podman volumes rm -f --all
-
- reboot
- # Systemd will restart all containers and create volumes etc.
- ```
-
-:::
diff --git a/nixos/tests/gitlab/runner.nix b/nixos/tests/gitlab/runner.nix
index 8a748f1298bf..ca12910d203d 100644
--- a/nixos/tests/gitlab/runner.nix
+++ b/nixos/tests/gitlab/runner.nix
@@ -31,21 +31,6 @@ let
path = ./runner/shell-runner.nix;
tokenFile = "${runnerTokenDir}/token-shell.env";
};
-
- # The Gitlab runner which uses the Docker runner (we use podman).
- # Features:
- # - Daemonizes the Nix store into a container.
- # - All jobs run in an unprivileged container, e.g. with image
- # (`local/nix`, `local/alpine`, `local/ubuntu`)
- podman = {
- # Only enabled on x86_64-linux: due to container images.
- # TODO: See https://github.com/NixOS/nixpkgs/issues/474409
- enabled = pkgs.stdenv.buildPlatform.isx86_64;
- desc = "Podman runner (containers, shared containerized Nix store)";
- name = "podman";
- path = ./runner/podman-runner;
- tokenFile = "${runnerTokenDir}/token-podman.env";
- };
};
in
{
diff --git a/nixos/tests/gitlab/runner/podman-runner/default.nix b/nixos/tests/gitlab/runner/podman-runner/default.nix
deleted file mode 100644
index 885f0d191ae2..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/default.nix
+++ /dev/null
@@ -1,435 +0,0 @@
-{ runnerConfig }:
-# Gitlab Runner Module
-#
-# This module will add a Gitlab-Runner
-# with a nix-daemon running in a podman container `nix-daemon-container`.
-# Check the documentation in the NixOS Manual.
-#
-# Debugging on the VM:
-#
-# - You can use `journalctl -u gitlab-runner.service`.
-#
-# - To run a job container inside the VM use:
-# ```bash
-# podman run --rm -it
-# --volumes-from 'nix-daemon-container'
-# -v "podman-daemon-socket:/run/podman"
-# "local/alpine" \
-# bash -c "export CI_PIPELINE_ID=123456 && gitlab-runner-pre-build-script; echo hello"
-# ```
-{
- lib,
- pkgs,
- ...
-}:
-let
- # Switch to not use IFD in nixpkgs test.
- # NOTE: When reusing this runner, you can set this to `true`.
- useIFD = false;
-
- # Either we use a Nix as the base image or Alpine.
- imageNames = {
- default = imageNames.alpine;
-
- alpine = "local/alpine";
- nix = "local/nix";
- ubuntu = "local/ubuntu";
-
- all = with imageNames; [
- alpine
- nix
- ubuntu
- ];
- };
-
- noPruneLabels = {
- no-prune = "true";
- };
-
- # This derivation will contain a folder `/etc`
- files = pkgs.callPackage ./files { };
- preBuildScript = pkgs.callPackage ./scripts/prebuild.nix { };
-
- # These derivations are Linked into the job images root dir.
- bootstrapPkgs = [
- pkgs.nix
- # Runtime dependencies of nix.
- pkgs.gnutar
- pkgs.gzip
- pkgs.openssh
- pkgs.xz
- pkgs.cacert
-
- # Other stuff.
- (lib.hiPrio pkgs.coreutils)
- (lib.hiPrio pkgs.findutils)
- pkgs.openssh
- pkgs.bashInteractive
- (lib.hiPrio pkgs.git)
- pkgs.cachix
-
- pkgs.just
- pkgs.podman # For nested containers.
-
- preBuildScript
-
- files.containers
- files.nixConfig
- ];
-
- # All these packages are added to the Nix daemon.
- nixStorePkgs = bootstrapPkgs ++ [
- # These files
- files.basicRoot
- files.fakeNixpkgs
- ];
-
- toEnvList = envs: lib.mapAttrsToList (k: v: "${k}=${v}") envs;
-
- # This is the Nix base image used for the Nix Daemon.
- # The build script for the nixos/nix image is vendored due to Hydra limitations.
- # cause it is IFD (Import from Derivation) which is not allowed.
- # NOTE: When reusing this runner you can set `useIFD` to true:
- nixImageBaseFn =
- if !useIFD then
- import ./nix-image.nix
- else
- import (
- (pkgs.fetchFromGitHub {
- owner = "NixOS";
- repo = "nix";
- rev = "2.32.4";
- hash = "sha256-8QYnRyGOTm3h/Dp8I6HCmQzlO7C009Odqyp28pTWgcY=";
- })
- + "/docker.nix"
- );
-
- nixImageBase =
- nixConf:
- pkgs.callPackage nixImageBaseFn {
- name = "local/nix-base";
- tag = "latest";
-
- bundleNixpkgs = false;
- maxLayers = 2;
-
- # You can add here a user with uid,gid,uname,gname etc.
- # We are using root.
-
- extraPkgs = nixStorePkgs;
-
- nixConf = {
- cores = "0";
- experimental-features = [
- "nix-command"
- "flakes"
- ];
- }
- // nixConf;
- };
-
- # This is the daemon image which provides the store
- # as volumes.
- nixDaemonImage = pkgs.dockerTools.buildLayeredImage {
- fromImage = nixImageBase {
- min-free = "1G"; # Triggers garbage collection.
- max-free = "10G"; # Stops garbage collection at 10G free space.
-
- # Reduce disk usage by discarding old derivations/outputs
- keep-derivations = false;
- keep-outputs = false;
- };
- name = "local/nix-daemon";
- tag = "latest";
-
- config = {
- Volumes = {
- "/nix/store" = { };
- "/nix/var/nix/db" = { };
- "/nix/var/nix/daemon-socket" = { };
- };
- Labels = noPruneLabels;
- };
- maxLayers = 4;
- };
-
- # This is the podman daemon image which enables
- # a job image to use `podman` internally.
- podmanDaemonImage =
- let
- # Update with:
- # ```shell
- # nix run "github:nixos/nixpkgs/nixos-unstable#nix-prefetch-docker" -- \
- # --image-name quay.io/podman/stable --image-tag v5.6.0
- # ```
- base = pkgs.dockerTools.pullImage {
- imageName = "quay.io/podman/stable";
- imageDigest = "sha256:7c9381b9af167cf2218831c3af3135856c99f488b543b78435c8f18e19ad739a";
- hash = "sha256-pXXCu13fB/RN9qx8iLhE5Kko6glTrFrRhR7fo2OS7V0=";
- finalImageName = "quay.io/podman/stable";
- finalImageTag = "v5.6.0";
- };
- in
- pkgs.dockerTools.buildLayeredImage {
- fromImage = base;
- name = "local/podman-daemon";
- tag = "latest";
-
- config = {
- Labels = noPruneLabels;
- };
- };
-
- jobImages =
- let
- extraCommands = ''
- set -eu
- # Set missing Nix directories.
- mkdir -p -m 0755 nix/var/log/nix/drvs
- mkdir -p -m 0755 nix/var/nix/{gcroots,profiles,temproots,userpool}
- mkdir -p -m 1777 nix/var/nix/{gcroots,profiles}/per-user
- mkdir -p -m 0755 nix/var/nix/profiles/per-user/root
-
- # Need a HOME.
- mkdir -vp root
- mkdir -p -m 0700 root/.nix-defexpr
- '';
- in
- {
- # The Nix image.
- # Similar to https://github.com/nix-community/docker-nixpkgs/blob/main/images/nix/default.nix.
- nix = pkgs.dockerTools.buildLayeredImage {
- name = imageNames.nix;
- tag = "latest";
-
- extraCommands = extraCommands + ''
- set -eu
- # For `/usr/bin/env`.
- mkdir -p usr && ln -s ../bin usr/bin
- '';
-
- contents = bootstrapPkgs ++ [ files.basicRoot ];
- # No store paths are copied into. We provide them by mounting the
- # /nix/store.
- includeStorePaths = false;
-
- config = {
- Labels = noPruneLabels;
- Env = toEnvList envs.nix;
- };
- maxLayers = 2;
- };
-
- # This is the analog image to `local/nix` but Alpine based.
- alpine =
- let
- # Update with:
- # ```shell
- # nix run "github:nixos/nixpkgs/nixos-unstable#nix-prefetch-docker" -- --image-name alpine --image-tag latest
- # ```
- alpineBase = pkgs.dockerTools.pullImage {
- imageName = "alpine";
- imageDigest = "sha256:beefdbd8a1da6d2915566fde36db9db0b524eb737fc57cd1367effd16dc0d06d";
- sha256 = "0gf7wbjp37zbni3pz8vdgq1mss6mz69wynms0gqhq7lsxfmg9xj9";
- finalImageName = "alpine";
- finalImageTag = "latest";
- };
- in
- (pkgs.dockerTools.buildLayeredImage {
- fromImage = alpineBase;
- name = imageNames.alpine;
- tag = "latest";
-
- inherit extraCommands;
-
- contents = bootstrapPkgs;
- # No store paths are copied into. We provide them by mounting the
- # /nix/store.
- includeStorePaths = false;
-
- config = {
- Labels = noPruneLabels;
- Env = toEnvList envs.nix;
- };
-
- # Only if `build buildLayeredImage`.
- maxLayers = 3;
- });
-
- # This is the analog image to `local/nix` but Ubuntu based.
- ubuntu =
- let
- # Update with:
- # ```shell
- # nix run "github:nixos/nixpkgs/nixos-unstable#nix-prefetch-docker" -- \
- # --image-name ubuntu --image-tag latest
- # ```
- ubuntuBase = pkgs.dockerTools.pullImage {
- imageName = "ubuntu";
- imageDigest = "sha256:1e622c5f073b4f6bfad6632f2616c7f59ef256e96fe78bf6a595d1dc4376ac02";
- hash = "sha256-aC8SgxdcMSaaU89YMr/uwE022Yqey2frmeZqr+L1xEU=";
- finalImageName = "ubuntu";
- finalImageTag = "latest";
- };
- in
- (pkgs.dockerTools.buildLayeredImage {
- fromImage = ubuntuBase;
- name = imageNames.ubuntu;
- tag = "latest";
-
- inherit extraCommands;
-
- contents = bootstrapPkgs;
- # No store paths are copied into. We provide them by mounting the
- # /nix/store.
- includeStorePaths = false;
-
- config = {
- Labels = noPruneLabels;
- Env = toEnvList envs.ubuntu;
- };
-
- # Only if `build buildLayeredImage`.
- maxLayers = 3;
- });
- };
-
- nixDaemonContainer = {
- imageFile = nixDaemonImage;
- image = "local/nix-daemon:latest";
-
- volumes = [
- "nix-daemon-store:/nix/store"
- "nix-daemon-db:/nix/var/nix/db"
- "nix-daemon-socket:/nix/var/nix/daemon-socket"
- ];
- cmd = [
- "nix"
- "daemon"
- ];
- };
-
- podmanDaemonContainer = {
- imageFile = podmanDaemonImage;
- image = "local/podman-daemon:latest";
- volumes = [
- "podman-daemon-socket:/run/podman"
- "podman-cache:/var/lib/container"
- # Shared images, currently not needed.
- "podman-shared:/var/lib/shared:ro"
- ];
- privileged = true;
- cmd = [
- "podman"
- "system"
- "service"
- "--time=0"
- "unix:///run/podman/podman.sock"
- "--log-level"
- "info"
- ];
- };
-
- # Environment variables for all job containers.
- envs = rec {
- common = {
- # Access to the nix daemon.
- NIX_REMOTE = "daemon";
- # Access to podman.
- CONTAINER_HOST = "unix:///run/podman/podman.sock";
-
- USER = "root";
- PATH = "/nix/var/nix/profiles/default/bin:/nix/var/nix/profiles/default/sbin:/bin:/sbin:/usr/bin:/usr/sbin";
-
- SSL_CERT_FILE = "${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt";
- NIX_SSL_CERT_FILE = "${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt";
-
- # For shells, source this file.
- ENV = "${pkgs.nix}/etc/profile.d/nix-daemon.sh";
- BASH_ENV = "${pkgs.nix}/etc/profile.d/nix-daemon.sh";
-
- # Make a fake nixpkgs which throws when using
- # `nix repl -f ` for example.
- NIX_PATH = "nixpkgs=${files.fakeNixpkgs}";
- };
-
- nix = common // {
- IMAGE_OS_DIST = "nix";
- };
-
- alpine = common // {
- IMAGE_OS_DIST = "alpine";
- };
-
- ubuntu = common // {
- IMAGE_OS_DIST = "ubuntu";
- };
- };
-
- registrationFlags = [
- "--docker-volumes"
- "gitlab-runner-scratch:/scratch"
-
- "--docker-volumes"
- "podman-daemon-socket:/run/podman"
-
- "--docker-volumes-from"
- "nix-daemon-container:ro"
-
- "--docker-pull-policy"
- "if-not-present"
-
- "--docker-allowed-pull-policies"
- "if-not-present"
-
- "--docker-host"
- "unix:///var/run/podman/podman.sock"
-
- "--docker-network-mode"
- "host"
- ];
-
-in
-{
- imports = [ ./virtualization.nix ];
-
- virtualisation.oci-containers = {
- backend = "podman";
-
- containers = {
- nix-daemon-container = nixDaemonContainer;
- podman-daemon-container = podmanDaemonContainer;
- }
- //
- # Workaround to add the job images to the registry.
- (lib.concatMapAttrs (name: image: {
- "${name}-container" = {
- imageFile = jobImages.${name};
- image = "${imageNames.${name}}:latest";
- extraOptions = [
- "--volumes-from"
- "nix-daemon-container:ro"
- ];
- dependsOn = [ "nix-daemon-container" ];
- cmd = [ "true" ];
- };
- }) jobImages);
- };
-
- # Define the Gitlab Runner.
- services.gitlab-runner.services.podman-runner = {
- description = runnerConfig.desc;
-
- inherit registrationFlags;
-
- authenticationTokenConfigFile = runnerConfig.tokenFile;
-
- executor = "docker";
- dockerImage = imageNames.default;
- dockerAllowedImages = [ ];
- dockerPrivileged = false;
- requestConcurrency = 4;
-
- preBuildScript = "${preBuildScript}/bin/gitlab-runner-pre-build-script";
- };
-}
diff --git a/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/group b/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/group
deleted file mode 100644
index 162f79fd7086..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/group
+++ /dev/null
@@ -1,21 +0,0 @@
-root:x:0:
-wheel:x:1:
-kmem:x:2:
-tty:x:3:
-messagebus:x:4:
-disk:x:6:
-audio:x:17:
-floppy:x:18:
-uucp:x:19:
-lp:x:20:
-cdrom:x:24:
-tape:x:25:
-video:x:26:
-dialout:x:27:
-utmp:x:29:
-adm:x:55:
-keys:x:96:
-users:x:100:
-input:x:174:
-nixbld:x:30000:nixbld1,nixbld10,nixbld11,nixbld12,nixbld13,nixbld14,nixbld15,nixbld16,nixbld17,nixbld18,nixbld19,nixbld2,nixbld20,nixbld21,nixbld22,nixbld23,nixbld24,nixbld25,nixbld26,nixbld27,nixbld28,nixbld29,nixbld3,nixbld30,nixbld31,nixbld32,nixbld4,nixbld5,nixbld6,nixbld7,nixbld8,nixbld9
-nogroup:x:65534:
diff --git a/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/nsswitch.conf b/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/nsswitch.conf
deleted file mode 100644
index 59a21416fd8f..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/nsswitch.conf
+++ /dev/null
@@ -1,11 +0,0 @@
-passwd: files mymachines systemd
-group: files mymachines systemd
-shadow: files
-
-hosts: files mymachines dns myhostname
-networks: files
-
-ethers: files
-services: files
-protocols: files
-rpc: files
diff --git a/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/passwd b/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/passwd
deleted file mode 100644
index 006b53f7bf82..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/files/basicRoot/etc/passwd
+++ /dev/null
@@ -1,34 +0,0 @@
-root:x:0:0:System administrator:/root:/bin/bash
-nixbld1:x:30001:30000:Nix build user 1:/var/empty:/run/current-system/sw/bin/nologin
-nixbld2:x:30002:30000:Nix build user 2:/var/empty:/run/current-system/sw/bin/nologin
-nixbld3:x:30003:30000:Nix build user 3:/var/empty:/run/current-system/sw/bin/nologin
-nixbld4:x:30004:30000:Nix build user 4:/var/empty:/run/current-system/sw/bin/nologin
-nixbld5:x:30005:30000:Nix build user 5:/var/empty:/run/current-system/sw/bin/nologin
-nixbld6:x:30006:30000:Nix build user 6:/var/empty:/run/current-system/sw/bin/nologin
-nixbld7:x:30007:30000:Nix build user 7:/var/empty:/run/current-system/sw/bin/nologin
-nixbld8:x:30008:30000:Nix build user 8:/var/empty:/run/current-system/sw/bin/nologin
-nixbld9:x:30009:30000:Nix build user 9:/var/empty:/run/current-system/sw/bin/nologin
-nixbld10:x:30010:30000:Nix build user 10:/var/empty:/run/current-system/sw/bin/nologin
-nixbld11:x:30011:30000:Nix build user 11:/var/empty:/run/current-system/sw/bin/nologin
-nixbld12:x:30012:30000:Nix build user 12:/var/empty:/run/current-system/sw/bin/nologin
-nixbld13:x:30013:30000:Nix build user 13:/var/empty:/run/current-system/sw/bin/nologin
-nixbld14:x:30014:30000:Nix build user 14:/var/empty:/run/current-system/sw/bin/nologin
-nixbld15:x:30015:30000:Nix build user 15:/var/empty:/run/current-system/sw/bin/nologin
-nixbld16:x:30016:30000:Nix build user 16:/var/empty:/run/current-system/sw/bin/nologin
-nixbld17:x:30017:30000:Nix build user 17:/var/empty:/run/current-system/sw/bin/nologin
-nixbld18:x:30018:30000:Nix build user 18:/var/empty:/run/current-system/sw/bin/nologin
-nixbld19:x:30019:30000:Nix build user 19:/var/empty:/run/current-system/sw/bin/nologin
-nixbld20:x:30020:30000:Nix build user 20:/var/empty:/run/current-system/sw/bin/nologin
-nixbld21:x:30021:30000:Nix build user 21:/var/empty:/run/current-system/sw/bin/nologin
-nixbld22:x:30022:30000:Nix build user 22:/var/empty:/run/current-system/sw/bin/nologin
-nixbld23:x:30023:30000:Nix build user 23:/var/empty:/run/current-system/sw/bin/nologin
-nixbld24:x:30024:30000:Nix build user 24:/var/empty:/run/current-system/sw/bin/nologin
-nixbld25:x:30025:30000:Nix build user 25:/var/empty:/run/current-system/sw/bin/nologin
-nixbld26:x:30026:30000:Nix build user 26:/var/empty:/run/current-system/sw/bin/nologin
-nixbld27:x:30027:30000:Nix build user 27:/var/empty:/run/current-system/sw/bin/nologin
-nixbld28:x:30028:30000:Nix build user 28:/var/empty:/run/current-system/sw/bin/nologin
-nixbld29:x:30029:30000:Nix build user 29:/var/empty:/run/current-system/sw/bin/nologin
-nixbld30:x:30030:30000:Nix build user 30:/var/empty:/run/current-system/sw/bin/nologin
-nixbld31:x:30031:30000:Nix build user 31:/var/empty:/run/current-system/sw/bin/nologin
-nixbld32:x:30032:30000:Nix build user 32:/var/empty:/run/current-system/sw/bin/nologin
-nobody:x:65534:65534:Unprivileged account (don't use!):/var/empty:/run/current-system/sw/bin/nologin
diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/containers.conf b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/containers.conf
deleted file mode 100644
index 0bf45cd2a1a1..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/containers.conf
+++ /dev/null
@@ -1,2 +0,0 @@
-[engine]
-cgroup_manager = "cgroupfs"
diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/mounts.conf b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/mounts.conf
deleted file mode 100644
index b54e7222210b..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/mounts.conf
+++ /dev/null
@@ -1,2 +0,0 @@
-/run/secrets/etc-pki-entitlement:/run/secrets/etc-pki-entitlement
-/run/secrets/rhsm:/run/secrets/rhsm
diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/policy.json b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/policy.json
deleted file mode 100644
index 4724dd816814..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/policy.json
+++ /dev/null
@@ -1,12 +0,0 @@
-{
- "default": [
- {
- "type": "insecureAcceptAnything"
- }
- ],
- "transports": {
- "docker-daemon": {
- "": [{ "type": "insecureAcceptAnything" }]
- }
- }
-}
diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf
deleted file mode 100644
index c3a575800d86..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf
+++ /dev/null
@@ -1,2 +0,0 @@
-unqualified-search-registries = ["registry.fedoraproject.org", "registry.access.redhat.com", "docker.io"]
-short-name-mode = "enforcing"
diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf.d/000-shortnames.conf b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf.d/000-shortnames.conf
deleted file mode 100644
index 142e6158235c..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.conf.d/000-shortnames.conf
+++ /dev/null
@@ -1,5 +0,0 @@
-[aliases]
- "buildah" = "quay.io/buildah/stable"
- "podman" = "quay.io/podman/stable"
- "alpine" = "docker.io/library/alpine"
- "ubuntu" = "docker.io/library/ubuntu"
diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/default.yaml b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/default.yaml
deleted file mode 100644
index 9e892d760b21..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/default.yaml
+++ /dev/null
@@ -1,27 +0,0 @@
-# This is a default registries.d configuration file. You may
-# add to this file or create additional files in registries.d/.
-#
-# lookaside: for reading/writing simple signing signatures
-# lookaside-staging: for writing simple signing signatures, preferred over lookaside
-#
-# lookaside and lookaside-staging take a value of the following:
-# lookaside: {schema}://location
-#
-# For reading signatures, schema may be http, https, or file.
-# For writing signatures, schema may only be file.
-
-# The default locations are built-in, for both reading and writing:
-# /var/lib/containers/sigstore for root, or
-# ~/.local/share/containers/sigstore for non-root users.
-default-docker:
-# lookaside: https://…
-# lookaside-staging: file:///…
-
-# The 'docker' indicator here is the start of the configuration
-# for docker registries.
-#
-# docker:
-#
-# privateregistry.com:
-# lookaside: https://privateregistry.com/sigstore/
-# lookaside-staging: /mnt/nfs/privateregistry/sigstore
diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.access.redhat.com.yaml b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.access.redhat.com.yaml
deleted file mode 100644
index 45018d5830a7..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.access.redhat.com.yaml
+++ /dev/null
@@ -1,3 +0,0 @@
-docker:
- registry.access.redhat.com:
- lookaside: https://access.redhat.com/webassets/docker/content/sigstore
diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.redhat.io.yaml b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.redhat.io.yaml
deleted file mode 100644
index ba1769320ce7..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/registries.d/registry.redhat.io.yaml
+++ /dev/null
@@ -1,3 +0,0 @@
-docker:
- registry.redhat.io:
- lookaside: https://registry.redhat.io/containers/sigstore
diff --git a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/storage.conf b/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/storage.conf
deleted file mode 100644
index 9db50278d80b..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/files/containers/etc/containers/storage.conf
+++ /dev/null
@@ -1,15 +0,0 @@
-[storage]
-driver = "overlay"
-runroot = "/run/containers/storage"
-graphroot = "/var/lib/containers/storage"
-
-[storage.options]
-additionalimagestores = [
-"/var/lib/shared",
-"/usr/lib/containers/storage",
-]
-pull_options = {enable_partial_images = "true", use_hard_links = "false", ostree_repos=""}
-
-[storage.options.overlay]
-mount_program = "/usr/bin/fuse-overlayfs"
-mountopt = "nodev,fsync=0"
diff --git a/nixos/tests/gitlab/runner/podman-runner/files/default.nix b/nixos/tests/gitlab/runner/podman-runner/files/default.nix
deleted file mode 100644
index e791ae42367f..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/files/default.nix
+++ /dev/null
@@ -1,46 +0,0 @@
-# Specific files for the job images.
-#
-# - `basicRoot`: Some basic root files for the `jobImages.nix`.
-# - `fakeNixpkgs`: A fake Nixpkg directory which is set as `NIX_PATH=nixpkgs:`
-# which throws on load.
-# - `nixConfig`: The Nix config with some options.
-# - `containers`:
-# These are some files which are copied to the job images needed for
-# `buildah` (`podman`):
-#
-# ```bash
-# podman create --name temp-buildah quay.io/buildah/stable:latest
-# podman cp temp-buildah:/etc/containers ./etc/
-# find ./etc -type d -empty -delete
-# podman container rm temp-buildah
-#```
-#
-{ pkgs, ... }:
-let
-
- # We need proper derivations to add it to the nixImageBase.
- mkDrv =
- name: src:
- pkgs.stdenv.mkDerivation {
- inherit name src;
- installPhase = ''
- mkdir -p $out
- cp -r $src/* $out/
- '';
- };
-in
-{
- basicRoot = mkDrv "basic-root-files" ./basicRoot;
- containers = mkDrv "containers-files" ./containers;
- fakeNixpkgs = mkDrv "fake-nixpkgs" ./fake-nixpkgs;
-
- nixConfig = pkgs.writeTextFile {
- name = "nix.conf";
- destination = "/etc/nix/nix.conf";
- text = ''
- accept-flake-config = true
- experimental-features = nix-command flakes
- max-jobs = auto
- '';
- };
-}
diff --git a/nixos/tests/gitlab/runner/podman-runner/files/fake-nixpkgs/default.nix b/nixos/tests/gitlab/runner/podman-runner/files/fake-nixpkgs/default.nix
deleted file mode 100644
index eee7aacaf920..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/files/fake-nixpkgs/default.nix
+++ /dev/null
@@ -1,10 +0,0 @@
-_:
-throw ''
- This container doesn't include nixpkgs.
-
- The best way to work around that is to pin your dependencies. See
- https://nix.dev/tutorials/first-steps/towards-reproducibility-pinning-nixpkgs.html
-
- Or if you must, override the NIX_PATH environment variable with eg:
- "NIX_PATH=nixpkgs=channel:nixos-unstable"
-''
diff --git a/nixos/tests/gitlab/runner/podman-runner/nix-image.nix b/nixos/tests/gitlab/runner/podman-runner/nix-image.nix
deleted file mode 100644
index bfb11e9573d9..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/nix-image.nix
+++ /dev/null
@@ -1,400 +0,0 @@
-# This is the vendored build script from
-# https://raw.githubusercontent.com/NixOS/nix/refs/heads/master/docker.nix
-# which builds the Nix image.
-# This is only here to please Hydra which is not beeing able to build IFDs.
-# `import (nixRepo + "./docker.nix")`.
-{
- # Core dependencies
- pkgs ? import { },
- lib ? pkgs.lib,
- dockerTools ? pkgs.dockerTools,
- runCommand ? pkgs.runCommand,
- buildPackages ? pkgs.buildPackages,
- # Image configuration
- name ? "nix",
- tag ? "latest",
- bundleNixpkgs ? true,
- channelName ? "nixpkgs",
- channelURL ? "https://channels.nixos.org/nixpkgs-unstable",
- extraPkgs ? [ ],
- maxLayers ? 70,
- nixConf ? { },
- flake-registry ? null,
- uid ? 0,
- gid ? 0,
- uname ? "root",
- gname ? "root",
- Labels ? {
- "org.opencontainers.image.title" = "Nix";
- "org.opencontainers.image.source" = "https://github.com/NixOS/nix";
- "org.opencontainers.image.vendor" = "Nix project";
- "org.opencontainers.image.version" = nix.version;
- "org.opencontainers.image.description" = "Nix container image";
- },
- Cmd ? [ (lib.getExe bashInteractive) ],
- # Default Packages
- nix ? pkgs.nix,
- bashInteractive ? pkgs.bashInteractive,
- coreutils-full ? pkgs.coreutils-full,
- gnutar ? pkgs.gnutar,
- gzip ? pkgs.gzip,
- gnugrep ? pkgs.gnugrep,
- which ? pkgs.which,
- curl ? pkgs.curl,
- less ? pkgs.less,
- wget ? pkgs.wget,
- man ? pkgs.man,
- cacert ? pkgs.cacert,
- findutils ? pkgs.findutils,
- iana-etc ? pkgs.iana-etc,
- gitMinimal ? pkgs.gitMinimal,
- openssh ? pkgs.openssh,
- # Other dependencies
- shadow ? pkgs.shadow,
-}:
-let
- defaultPkgs = [
- nix
- bashInteractive
- coreutils-full
- gnutar
- gzip
- gnugrep
- which
- curl
- less
- wget
- man
- cacert.out
- findutils
- iana-etc
- gitMinimal
- openssh
- ]
- ++ extraPkgs;
-
- users = {
-
- root = {
- uid = 0;
- shell = lib.getExe bashInteractive;
- home = "/root";
- gid = 0;
- groups = [ "root" ];
- description = "System administrator";
- };
-
- nobody = {
- uid = 65534;
- shell = lib.getExe' shadow "nologin";
- home = "/var/empty";
- gid = 65534;
- groups = [ "nobody" ];
- description = "Unprivileged account (don't use!)";
- };
-
- }
- // lib.optionalAttrs (uid != 0) {
- "${uname}" = {
- uid = uid;
- shell = lib.getExe bashInteractive;
- home = "/home/${uname}";
- gid = gid;
- groups = [ "${gname}" ];
- description = "Nix user";
- };
- }
- // lib.listToAttrs (
- map (n: {
- name = "nixbld${toString n}";
- value = {
- uid = 30000 + n;
- gid = 30000;
- groups = [ "nixbld" ];
- description = "Nix build user ${toString n}";
- };
- }) (lib.lists.range 1 32)
- );
-
- groups = {
- root.gid = 0;
- nixbld.gid = 30000;
- nobody.gid = 65534;
- }
- // lib.optionalAttrs (gid != 0) {
- "${gname}".gid = gid;
- };
-
- userToPasswd = (
- k:
- {
- uid,
- gid ? 65534,
- home ? "/var/empty",
- description ? "",
- shell ? "/bin/false",
- groups ? [ ],
- }:
- "${k}:x:${toString uid}:${toString gid}:${description}:${home}:${shell}"
- );
- passwdContents = (lib.concatStringsSep "\n" (lib.attrValues (lib.mapAttrs userToPasswd users)));
-
- userToShadow = k: { ... }: "${k}:!:1::::::";
- shadowContents = (lib.concatStringsSep "\n" (lib.attrValues (lib.mapAttrs userToShadow users)));
-
- # Map groups to members
- # {
- # group = [ "user1" "user2" ];
- # }
- groupMemberMap = (
- let
- # Create a flat list of user/group mappings
- mappings = (
- builtins.foldl' (
- acc: user:
- let
- groups = users.${user}.groups or [ ];
- in
- acc
- ++ map (group: {
- inherit user group;
- }) groups
- ) [ ] (lib.attrNames users)
- );
- in
- (builtins.foldl' (
- acc: v:
- acc
- // {
- ${v.group} = acc.${v.group} or [ ] ++ [ v.user ];
- }
- ) { } mappings)
- );
-
- groupToGroup =
- k:
- { gid }:
- let
- members = groupMemberMap.${k} or [ ];
- in
- "${k}:x:${toString gid}:${lib.concatStringsSep "," members}";
- groupContents = (lib.concatStringsSep "\n" (lib.attrValues (lib.mapAttrs groupToGroup groups)));
-
- toConf =
- with pkgs.lib.generators;
- toKeyValue {
- mkKeyValue = mkKeyValueDefault {
- mkValueString = v: if lib.isList v then lib.concatStringsSep " " v else mkValueStringDefault { } v;
- } " = ";
- };
-
- nixConfContents = toConf (
- {
- sandbox = false;
- build-users-group = "nixbld";
- trusted-public-keys = [ "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" ];
- }
- // nixConf
- );
-
- userHome = if uid == 0 then "/root" else "/home/${uname}";
-
- baseSystem =
- let
- nixpkgs = pkgs.path;
- channel = runCommand "channel-nixos" { inherit bundleNixpkgs; } ''
- mkdir $out
- if [ "$bundleNixpkgs" ]; then
- ln -s ${
- builtins.path {
- path = nixpkgs;
- name = "source";
- }
- } $out/nixpkgs
- echo "[]" > $out/manifest.nix
- fi
- '';
- # doc/manual/source/command-ref/files/manifest.nix.md
- manifest = buildPackages.runCommand "manifest.nix" { } ''
- cat > $out < $out/etc/passwd
- echo "" >> $out/etc/passwd
-
- cat $groupContentsPath > $out/etc/group
- echo "" >> $out/etc/group
-
- cat $shadowContentsPath > $out/etc/shadow
- echo "" >> $out/etc/shadow
-
- mkdir -p $out/usr
- ln -s /nix/var/nix/profiles/share $out/usr/
-
- mkdir -p $out/nix/var/nix/gcroots
-
- mkdir $out/tmp
-
- mkdir -p $out/var/tmp
-
- mkdir -p $out/etc/nix
- cat $nixConfContentsPath > $out/etc/nix/nix.conf
-
- mkdir -p $out${userHome}
- mkdir -p $out/nix/var/nix/profiles/per-user/${uname}
-
- # see doc/manual/source/command-ref/files/profiles.md
- ln -s ${profile} $out/nix/var/nix/profiles/default-1-link
- ln -s /nix/var/nix/profiles/default-1-link $out/nix/var/nix/profiles/default
- ln -s /nix/var/nix/profiles/default $out${userHome}/.nix-profile
-
- # see doc/manual/source/command-ref/files/channels.md
- ln -s ${channel} $out/nix/var/nix/profiles/per-user/${uname}/channels-1-link
- ln -s /nix/var/nix/profiles/per-user/${uname}/channels-1-link $out/nix/var/nix/profiles/per-user/${uname}/channels
-
- # see doc/manual/source/command-ref/files/default-nix-expression.md
- mkdir -p $out${userHome}/.nix-defexpr
- ln -s /nix/var/nix/profiles/per-user/${uname}/channels $out${userHome}/.nix-defexpr/channels
- echo "${channelURL} ${channelName}" > $out${userHome}/.nix-channels
-
- # may get replaced by pkgs.dockerTools.binSh & pkgs.dockerTools.usrBinEnv
- mkdir -p $out/bin $out/usr/bin
- ln -s ${lib.getExe' coreutils-full "env"} $out/usr/bin/env
- ln -s ${lib.getExe bashInteractive} $out/bin/sh
-
- ''
- + (lib.optionalString (flake-registry-path != null) ''
- nixCacheDir="${userHome}/.cache/nix"
- mkdir -p $out$nixCacheDir
- globalFlakeRegistryPath="$nixCacheDir/flake-registry.json"
- ln -s ${flake-registry-path} $out$globalFlakeRegistryPath
- mkdir -p $out/nix/var/nix/gcroots/auto
- rootName=$(${lib.getExe' nix "nix"} --extra-experimental-features nix-command hash file --type sha1 --base32 <(echo -n $globalFlakeRegistryPath))
- ln -s $globalFlakeRegistryPath $out/nix/var/nix/gcroots/auto/$rootName
- '')
- );
-
-in
-dockerTools.buildLayeredImageWithNixDb {
-
- inherit
- name
- tag
- maxLayers
- uid
- gid
- uname
- gname
- ;
-
- contents = [ baseSystem ];
-
- extraCommands = ''
- rm -rf nix-support
- ln -s /nix/var/nix/profiles nix/var/nix/gcroots/profiles
- '';
- fakeRootCommands = ''
- chmod 1777 tmp
- chmod 1777 var/tmp
- chown -R ${toString uid}:${toString gid} .${userHome}
- chown -R ${toString uid}:${toString gid} nix
- '';
-
- config = {
- inherit Cmd Labels;
- User = "${toString uid}:${toString gid}";
- Env = [
- "USER=${uname}"
- "PATH=${
- lib.concatStringsSep ":" [
- "${userHome}/.nix-profile/bin"
- "/nix/var/nix/profiles/default/bin"
- "/nix/var/nix/profiles/default/sbin"
- ]
- }"
- "MANPATH=${
- lib.concatStringsSep ":" [
- "${userHome}/.nix-profile/share/man"
- "/nix/var/nix/profiles/default/share/man"
- ]
- }"
- "SSL_CERT_FILE=/nix/var/nix/profiles/default/etc/ssl/certs/ca-bundle.crt"
- "GIT_SSL_CAINFO=/nix/var/nix/profiles/default/etc/ssl/certs/ca-bundle.crt"
- "NIX_SSL_CERT_FILE=/nix/var/nix/profiles/default/etc/ssl/certs/ca-bundle.crt"
- "NIX_PATH=/nix/var/nix/profiles/per-user/${uname}/channels:${userHome}/.nix-defexpr/channels"
- ];
- };
-
-}
diff --git a/nixos/tests/gitlab/runner/podman-runner/scripts/prebuild.nix b/nixos/tests/gitlab/runner/podman-runner/scripts/prebuild.nix
deleted file mode 100644
index 4e78638f09a5..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/scripts/prebuild.nix
+++ /dev/null
@@ -1,55 +0,0 @@
-{ writeShellScriptBin, nix }:
-writeShellScriptBin "gitlab-runner-pre-build-script"
- # bash
- ''
- set -e
- set -u
-
- function section_start() {
- local name="$1"
- shift
- echo -e "\e[0Ksection_start:$(date +%s):$name[collapsed=true]\r\e[0K$*"
- }
-
- function section_end() {
- local name="$1"
- echo -e "\e[0Ksection_end:$(date +%s):$name\r\e[0K"
- }
-
- function setup() {
- # We need to allow modification of nix config for cachix as
- # otherwise it is link to the read only file in the store.
- cp --remove-destination \
- "$(readlink -f /etc/nix/nix.conf)" /etc/nix/nix.conf
-
- # shellcheck disable=SC1091
- . "${nix}/etc/profile.d/nix-daemon.sh"
- }
-
- function setup_pipeline_scratch_dir() {
- scratch_dir="/scratch/$CI_PIPELINE_ID"
-
- echo "Create scratch directory for pipeline: $scratch_dir"
- mkdir -p "$scratch_dir" || {
- echo "Could not create scratch dir '$scratch_dir'." >&2
- exit 1
- }
-
- export CI_CUSTOM_SCRATCH_DIR="$scratch_dir"
- }
-
- function print_info() {
- echo "Nix version:"
- nix --version
- }
-
- function main() {
- print_info
- setup
- setup_pipeline_scratch_dir
- }
-
- section_start gitlab-runner-prebuild "Gitlab-Runner PreBuild Script"
- main "$@"
- section_end gitlab-runner-prebuild
- ''
diff --git a/nixos/tests/gitlab/runner/podman-runner/virtualization.nix b/nixos/tests/gitlab/runner/podman-runner/virtualization.nix
deleted file mode 100644
index 89a06023400d..000000000000
--- a/nixos/tests/gitlab/runner/podman-runner/virtualization.nix
+++ /dev/null
@@ -1,43 +0,0 @@
-{ lib, ... }:
-{
- virtualisation.docker = {
- enable = lib.mkForce false;
- };
-
- virtualisation.podman = {
- enable = true;
-
- # Create a `docker` alias for podman, to use it as a drop-in replacement
- # dockerCompat = true;
- dockerSocket = {
- enable = true;
- };
-
- # Required for containers under podman-compose to be able to talk to each other.
- defaultNetwork.settings.dns_enabled = true;
-
- autoPrune = {
- dates = "weekly";
- flags = [
- "--filter"
- "label!=no-prune"
- "--volumes"
- "--log-level"
- "debug"
- ];
- };
- };
-
- virtualisation.containers.storage.settings = {
- storage = {
- driver = "overlay";
- graphroot = "/var/lib/containers/storage";
- runroot = "/run/containers/storage";
-
- # Does not work currently.
- options.overlay = {
- mountopt = "nodev,metacopy=on";
- };
- };
- };
-}
From eb07b7d37defddbc85bd6169e07b2d5f0f2f4a1c Mon Sep 17 00:00:00 2001
From: yvnth
Date: Thu, 24 Sep 2026 14:50:44 +0530
Subject: [PATCH 12/61] mangayomi: 0.9.2 -> 0.9.7
---
pkgs/by-name/ma/mangayomi/git-hashes.json | 2 +-
pkgs/by-name/ma/mangayomi/package.nix | 4 +-
pkgs/by-name/ma/mangayomi/pubspec.lock.json | 146 +++++++++++++++-----
3 files changed, 111 insertions(+), 41 deletions(-)
diff --git a/pkgs/by-name/ma/mangayomi/git-hashes.json b/pkgs/by-name/ma/mangayomi/git-hashes.json
index 5a33f28f92ed..fac1a5d0a497 100644
--- a/pkgs/by-name/ma/mangayomi/git-hashes.json
+++ b/pkgs/by-name/ma/mangayomi/git-hashes.json
@@ -6,7 +6,7 @@
"flutter_qjs": "sha256-sEcc87UV2xaXagv70YJO1cq9DVuck+Gq+Ch2MrZl7Zs=",
"flutter_web_auth_2": "sha256-3aci73SP8eXg6++IQTQoyS+erUUuSiuXymvR32sxHFw=",
"isar_community_generator": "sha256-4M5nmNvWGJK5CdK4oMrhFjOTdcGg5wo15zDruVEa97k=",
- "m_extension_server": "sha256-Hi8/H3nFaY59FS9zaMRmXRV9wOgSiC5wU73X7/CUn5A=",
+ "m_extension_server": "sha256-TbnFcwtvZ/XvOcYCmDjIocUjKBktlwId7BB6nr3oT8c=",
"media_kit": "sha256-YLMdwh9ch1C34X4McZd92WUo7lISwvK08zSGnVmZCeE=",
"media_kit_libs_android_video": "sha256-YLMdwh9ch1C34X4McZd92WUo7lISwvK08zSGnVmZCeE=",
"media_kit_libs_ios_video": "sha256-YLMdwh9ch1C34X4McZd92WUo7lISwvK08zSGnVmZCeE=",
diff --git a/pkgs/by-name/ma/mangayomi/package.nix b/pkgs/by-name/ma/mangayomi/package.nix
index 27e8c8d3cd86..263f9e25fd52 100644
--- a/pkgs/by-name/ma/mangayomi/package.nix
+++ b/pkgs/by-name/ma/mangayomi/package.nix
@@ -14,13 +14,13 @@
let
pname = "mangayomi";
- version = "0.9.2";
+ version = "0.9.7";
src = fetchFromGitHub {
owner = "kodjodevf";
repo = "mangayomi";
tag = "v${version}";
- hash = "sha256-7geEJynXq2OcCLhTtm8KxvfuCagI5grCUUQ0K7jFkcY=";
+ hash = "sha256-5ZjyG3NRati8IWGI2QpV0Ywu9sAI4vrFGRJorH5MbQk=";
};
metaCommon = {
diff --git a/pkgs/by-name/ma/mangayomi/pubspec.lock.json b/pkgs/by-name/ma/mangayomi/pubspec.lock.json
index 8e02c3d9e4e1..c439a1180e12 100644
--- a/pkgs/by-name/ma/mangayomi/pubspec.lock.json
+++ b/pkgs/by-name/ma/mangayomi/pubspec.lock.json
@@ -30,6 +30,16 @@
"source": "hosted",
"version": "0.1.11"
},
+ "android_file_picker": {
+ "dependency": "transitive",
+ "description": {
+ "name": "android_file_picker",
+ "sha256": "014c74ab48d452c3252465682375a7fe6ddf56abb908ec361f207a3c4ffb2444",
+ "url": "https://pub.dev"
+ },
+ "source": "hosted",
+ "version": "1.1.1"
+ },
"antlr4": {
"dependency": "transitive",
"description": {
@@ -84,11 +94,11 @@
"dependency": "direct main",
"description": {
"name": "archive",
- "sha256": "ace891da0862b0e4cabbb064ee3fd87b2728b898949fdb366d83fe98342c9f19",
+ "sha256": "6c5bcd986e06b94e3c40244af471750840a3d2341d1f9763a1100a14add517b4",
"url": "https://pub.dev"
},
"source": "hosted",
- "version": "4.2.0"
+ "version": "4.3.0"
},
"args": {
"dependency": "transitive",
@@ -264,11 +274,11 @@
"dependency": "direct main",
"description": {
"name": "code_assets",
- "sha256": "bf394f466ba9205f1812a0433b392d6af280f155f56651eda7c18cc32ed493b8",
+ "sha256": "cfd4f5f575a49c5f10ca856e9846073f1e6c3ee94912377eea5f6cefc5272941",
"url": "https://pub.dev"
},
"source": "hosted",
- "version": "1.2.1"
+ "version": "2.0.0"
},
"code_builder": {
"dependency": "transitive",
@@ -281,7 +291,7 @@
"version": "4.11.1"
},
"collection": {
- "dependency": "transitive",
+ "dependency": "direct main",
"description": {
"name": "collection",
"sha256": "2f5709ae4d3d59dd8f7cd309b4e023046b57d8a6c82130785d2b0e5868084e76",
@@ -374,11 +384,11 @@
"dependency": "direct main",
"description": {
"name": "cupertino_ui",
- "sha256": "7ed8ce4159d342eec4c65f4ea6eec57adaf9365404378541f38efc1da20a5b3d",
+ "sha256": "e9dfe7fac704028f8928cbe4028a0be5e8a709498e8daf8247de99e99a32aef3",
"url": "https://pub.dev"
},
"source": "hosted",
- "version": "1.0.0"
+ "version": "1.0.2"
},
"d4rt": {
"dependency": "direct main",
@@ -556,11 +566,11 @@
"dependency": "direct main",
"description": {
"name": "ffigen",
- "sha256": "b7803707faeec4ce3c1b0c2274906504b796e3b70ad573577e72333bd1c9b3ba",
+ "sha256": "31b2ca630cede89babbbf31688d20b735967c51bf60572b06ec16718e5a7f1ec",
"url": "https://pub.dev"
},
"source": "hosted",
- "version": "20.1.1"
+ "version": "22.0.0"
},
"file": {
"dependency": "transitive",
@@ -576,11 +586,51 @@
"dependency": "direct main",
"description": {
"name": "file_picker",
- "sha256": "fdc6a37f715d19f35b131decf1ce39242eeed5ddae18c0818c3eccb731ab76be",
+ "sha256": "9be6aac79508dbcf8dac80a4fb20f27ce6f910837ca27e3670b9295995cc0110",
"url": "https://pub.dev"
},
"source": "hosted",
- "version": "12.0.0-beta.7"
+ "version": "12.3.0"
+ },
+ "file_picker_darwin": {
+ "dependency": "transitive",
+ "description": {
+ "name": "file_picker_darwin",
+ "sha256": "59fa5394cfa5b6dc8bf491630cb17077b77b844adbb840df371e7be5355d6cf6",
+ "url": "https://pub.dev"
+ },
+ "source": "hosted",
+ "version": "1.2.0"
+ },
+ "file_picker_linux": {
+ "dependency": "transitive",
+ "description": {
+ "name": "file_picker_linux",
+ "sha256": "bd52ff1e0048f29df95f913c55ad2991c72791d93e6c42241912c4bdee946cb9",
+ "url": "https://pub.dev"
+ },
+ "source": "hosted",
+ "version": "1.1.0"
+ },
+ "file_picker_platform_interface": {
+ "dependency": "transitive",
+ "description": {
+ "name": "file_picker_platform_interface",
+ "sha256": "0355558fd9af6da499d18e333d6b3beb44b0bf19e00933fccd15d18eb8d0e9ca",
+ "url": "https://pub.dev"
+ },
+ "source": "hosted",
+ "version": "3.4.0"
+ },
+ "file_picker_web": {
+ "dependency": "transitive",
+ "description": {
+ "name": "file_picker_web",
+ "sha256": "935560a9d29fa6f006f2855addebb88e88d438e13627d4cc24187033c106f227",
+ "url": "https://pub.dev"
+ },
+ "source": "hosted",
+ "version": "3.1.0"
},
"fixnum": {
"dependency": "direct main",
@@ -811,11 +861,11 @@
"dependency": "direct main",
"description": {
"name": "flutter_secure_storage",
- "sha256": "15e8c8fe269fdf7d469b23008ab3df521c8b826ed345820532364c31bdebace6",
+ "sha256": "d87713a152ee2f255117bdbbf43da1dea1797e0551e499e0334f0c9dcfafddd2",
"url": "https://pub.dev"
},
"source": "hosted",
- "version": "11.0.0"
+ "version": "11.1.1"
},
"flutter_secure_storage_darwin": {
"dependency": "transitive",
@@ -841,11 +891,11 @@
"dependency": "transitive",
"description": {
"name": "flutter_secure_storage_platform_interface",
- "sha256": "788060052712555182aba55ecb5f8b6e5cb9cfe8f776c83249a61fe3ce877db4",
+ "sha256": "4bc033841169d07f690d46d89dbc3f5305b6562820822445384c82e0866e2719",
"url": "https://pub.dev"
},
"source": "hosted",
- "version": "2.0.3"
+ "version": "2.1.0"
},
"flutter_secure_storage_web": {
"dependency": "transitive",
@@ -964,11 +1014,11 @@
"dependency": "direct main",
"description": {
"name": "go_router",
- "sha256": "d7a3576cb312649eaa51f2356450aed686085fb58fcdebda5b359aa951eef7ea",
+ "sha256": "008ab21d89d0de8ccd79586838f7533f126c2d894f50bf25f2947888d3c225b5",
"url": "https://pub.dev"
},
"source": "hosted",
- "version": "17.5.0"
+ "version": "18.0.1"
},
"google_fonts": {
"dependency": "direct main",
@@ -1104,11 +1154,11 @@
"dependency": "direct main",
"description": {
"name": "image",
- "sha256": "1976370a4df3091bb0f72409c187ad1f9132a818bc6b95ca59c0bae1c75c688e",
+ "sha256": "a1e7f4951e538a568e14b856702afc9ae1d2f4b202daced8d22c1b9cd211ce89",
"url": "https://pub.dev"
},
"source": "hosted",
- "version": "4.9.2"
+ "version": "4.10.1"
},
"infinite_listview": {
"dependency": "transitive",
@@ -1386,11 +1436,11 @@
"description": {
"path": ".",
"ref": "HEAD",
- "resolved-ref": "52dfe44bb19621a0adbd5d871d2fb47971e8ea47",
+ "resolved-ref": "afb3908993f0a249e6e597fbb74f719c9bdd0fcf",
"url": "https://github.com/kodjodevf/m_extension_server.git"
},
"source": "git",
- "version": "0.0.8"
+ "version": "0.0.9"
},
"marquee": {
"dependency": "direct main",
@@ -1422,6 +1472,16 @@
"source": "hosted",
"version": "0.13.0"
},
+ "material_ui": {
+ "dependency": "transitive",
+ "description": {
+ "name": "material_ui",
+ "sha256": "fbfb53cab6c4629438feeade5f3d305f72944bc9d9f25786b19106d32b80ec45",
+ "url": "https://pub.dev"
+ },
+ "source": "hosted",
+ "version": "1.2.0"
+ },
"media_kit": {
"dependency": "direct main",
"description": {
@@ -1544,11 +1604,11 @@
"dependency": "direct main",
"description": {
"name": "native_toolchain_c",
- "sha256": "a1c26117c48cebe5677b0cf0e33a980a79a7c5577effc86f52e5a0d309cdcb60",
+ "sha256": "9d233b6f2d9c52e1a2b5fbe70451d2c10ac674d3bb419d0ec8de14989d437c26",
"url": "https://pub.dev"
},
"source": "hosted",
- "version": "0.19.3"
+ "version": "0.19.4"
},
"nm": {
"dependency": "transitive",
@@ -1584,11 +1644,11 @@
"dependency": "transitive",
"description": {
"name": "objective_c",
- "sha256": "b7fb95a6d9a4f009edd63dc5ac69f07420b23a16161c6dd8660290b59c602e8e",
+ "sha256": "ad56fd53a78ff6b1472fa59ff2a4e8b8ccabafc586fc263a1dfad0b99b5553e3",
"url": "https://pub.dev"
},
"source": "hosted",
- "version": "9.5.0"
+ "version": "9.6.0"
},
"package_config": {
"dependency": "transitive",
@@ -1821,6 +1881,16 @@
"source": "hosted",
"version": "6.5.2"
},
+ "process": {
+ "dependency": "transitive",
+ "description": {
+ "name": "process",
+ "sha256": "4242ba3508d37e01808bdf71ad1d5bb93a8d671bf2e7450e6b1b353fb0808891",
+ "url": "https://pub.dev"
+ },
+ "source": "hosted",
+ "version": "5.0.6"
+ },
"protobuf": {
"dependency": "direct main",
"description": {
@@ -1885,11 +1955,11 @@
"dependency": "direct main",
"description": {
"name": "re_editor",
- "sha256": "73e5daf7041b382c07ed707d5efd2d0a53851bb9eb6d6987260229ae0ed2f458",
+ "sha256": "66671c4774a6b4c5254c9a53ab35a083e7e7da9ae371c519bcf491c70a2a4e56",
"url": "https://pub.dev"
},
"source": "hosted",
- "version": "0.9.0"
+ "version": "0.10.0"
},
"re_highlight": {
"dependency": "direct main",
@@ -2100,16 +2170,6 @@
"source": "hosted",
"version": "0.2.2"
},
- "scrollable_positioned_list": {
- "dependency": "direct main",
- "description": {
- "name": "scrollable_positioned_list",
- "sha256": "1b54d5f1329a1e263269abc9e2543d90806131aa14fe7c6062a8054d57249287",
- "url": "https://pub.dev"
- },
- "source": "hosted",
- "version": "0.3.8"
- },
"share_plus": {
"dependency": "direct main",
"description": {
@@ -2616,6 +2676,16 @@
"source": "hosted",
"version": "0.0.4"
},
+ "windows_file_picker": {
+ "dependency": "transitive",
+ "description": {
+ "name": "windows_file_picker",
+ "sha256": "62e6e6e115231d1d1d71c7b5883b4091ce3e0190e49548dfb0ff8cba8d91ad96",
+ "url": "https://pub.dev"
+ },
+ "source": "hosted",
+ "version": "1.3.0"
+ },
"xdg_directories": {
"dependency": "transitive",
"description": {
@@ -2688,7 +2758,7 @@
}
},
"sdks": {
- "dart": ">=3.13.1 <4.0.0",
+ "dart": ">=3.13.4 <4.0.0",
"flutter": ">=3.44.0"
}
}
From cf2b85458db96496d79f67888ac6ab57852d985b Mon Sep 17 00:00:00 2001
From: yvnth
Date: Thu, 24 Sep 2026 14:52:43 +0530
Subject: [PATCH 13/61] mangayomi: add yvnth as maintainer
---
pkgs/by-name/ma/mangayomi/package.nix | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/pkgs/by-name/ma/mangayomi/package.nix b/pkgs/by-name/ma/mangayomi/package.nix
index 263f9e25fd52..b56e34d6adb6 100644
--- a/pkgs/by-name/ma/mangayomi/package.nix
+++ b/pkgs/by-name/ma/mangayomi/package.nix
@@ -28,7 +28,7 @@ let
description = "Reading manga, novels, and watching animes";
homepage = "https://github.com/kodjodevf/mangayomi";
license = lib.licenses.asl20;
- maintainers = [ ];
+ maintainers = with lib.maintainers; [ yvnth ];
platforms = lib.platforms.linux;
};
From da25e48f4f395e5c1d6fa9de66a1e0353e3cf753 Mon Sep 17 00:00:00 2001
From: Karolis Stasaitis
Date: Thu, 24 Sep 2026 11:27:39 +0200
Subject: [PATCH 14/61] kitty-bin: 0.49.0 -> 0.49.1
---
pkgs/by-name/ki/kitty-bin/package.nix | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/pkgs/by-name/ki/kitty-bin/package.nix b/pkgs/by-name/ki/kitty-bin/package.nix
index 4c0a9a8f0265..d6f54515c06f 100644
--- a/pkgs/by-name/ki/kitty-bin/package.nix
+++ b/pkgs/by-name/ki/kitty-bin/package.nix
@@ -8,14 +8,14 @@
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "kitty-bin";
- version = "0.49.0";
+ version = "0.49.1";
__structuredAttrs = true;
strictDeps = true;
src = fetchurl {
url = "https://github.com/kovidgoyal/kitty/releases/download/v${finalAttrs.version}/kitty-${finalAttrs.version}.dmg";
- hash = "sha256-jMIPsw6VpRQa1UNFFvyjMXcjOn9JI21DG6+c6QWD6Yw=";
+ hash = "sha256-0li23KsYZqm8RWxVs3VMbN9qemqT0DhHUnVnW7nyBTo=";
};
nativeBuildInputs = [ _7zz ];
From 84104da134919a88d2b568c9c4e972ca84c3fb93 Mon Sep 17 00:00:00 2001
From: "R. Ryantm"
Date: Thu, 24 Sep 2026 21:21:00 +0000
Subject: [PATCH 15/61] libdwarf: 2.3.2 -> 2.3.3
---
pkgs/by-name/li/libdwarf/package.nix | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/pkgs/by-name/li/libdwarf/package.nix b/pkgs/by-name/li/libdwarf/package.nix
index 99f998365cca..0cd609de471a 100644
--- a/pkgs/by-name/li/libdwarf/package.nix
+++ b/pkgs/by-name/li/libdwarf/package.nix
@@ -11,13 +11,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libdwarf";
- version = "2.3.2";
+ version = "2.3.3";
src = fetchFromGitHub {
owner = "davea42";
repo = "libdwarf-code";
tag = "v${finalAttrs.version}";
- hash = "sha256-65jEnM+eJ7HnZlpEM2D67W0Xgb9B/aa4JhajowG0Z8o=";
+ hash = "sha256-mO8fB369iS5l73iOB8zAqUjY8xl4PntV//2hRiirTtA=";
};
nativeBuildInputs = [
From 084623396fa67de3baa449f7bf089d49c54a3c97 Mon Sep 17 00:00:00 2001
From: tree-sapii <144389458+tree-sapii@users.noreply.github.com>
Date: Thu, 24 Sep 2026 19:37:53 -0400
Subject: [PATCH 16/61] cloudflared: 2026.9.1 -> 2026.9.3
---
pkgs/by-name/cl/cloudflared/package.nix | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/pkgs/by-name/cl/cloudflared/package.nix b/pkgs/by-name/cl/cloudflared/package.nix
index 070b832ea7a5..e0137713f1f2 100644
--- a/pkgs/by-name/cl/cloudflared/package.nix
+++ b/pkgs/by-name/cl/cloudflared/package.nix
@@ -9,16 +9,16 @@
buildGoModule (finalAttrs: {
pname = "cloudflared";
- version = "2026.9.1";
+ version = "2026.9.3";
src = fetchFromGitHub {
owner = "cloudflare";
repo = "cloudflared";
tag = finalAttrs.version;
- hash = "sha256-w14ptM9nbfVz+8R51HOLJCGIMdQvxEQ0TsEsWcpuLZ4=";
+ hash = "sha256-hWU8hdIUqiwU3RfL4alL1pck0SGcbwxunv9Yw9+9xfY=";
};
- vendorHash = "sha256-uqgFn1veadGiGPI75ULNZF4NoUERlCn3p6JFP+I4y6s=";
+ vendorHash = "sha256-mTNP7u+kCYR9rcYGJ20q7Tl/Oi6ZF/UdEfiI1C7mfpw=";
ldflags = [
"-s"
From b8d70ac769f73678a8e486dbc583a9aa2fc27da1 Mon Sep 17 00:00:00 2001
From: Quentin Frey <51170829+Limosine@users.noreply.github.com>
Date: Fri, 25 Sep 2026 15:26:13 +0200
Subject: [PATCH 17/61] matrix-tuwunel: 1.9.2 -> 1.9.3
---
pkgs/by-name/ma/matrix-tuwunel/package.nix | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/pkgs/by-name/ma/matrix-tuwunel/package.nix b/pkgs/by-name/ma/matrix-tuwunel/package.nix
index 00c932c732b6..f7c01db606e4 100644
--- a/pkgs/by-name/ma/matrix-tuwunel/package.nix
+++ b/pkgs/by-name/ma/matrix-tuwunel/package.nix
@@ -89,13 +89,13 @@ let
in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "matrix-tuwunel";
- version = "1.9.2";
+ version = "1.9.3";
src = fetchFromGitHub {
owner = "matrix-construct";
repo = "tuwunel";
tag = "v${finalAttrs.version}";
- hash = "sha256-5X43mZamOaqRyyMChwJ966kpfCbNYBks4O8KM+3h2L4=";
+ hash = "sha256-29X+iSfCLo7hMvaCC/gw2zWfavC7lp3HEqTCpcBh2a0=";
};
# Integration tests require networking. Only run the unit tests.
@@ -104,7 +104,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
"--bins"
];
- cargoHash = "sha256-Jt03Xy2i0GZJcpgm35AvI+8huhidYG3FyDS1YOY2Rmw=";
+ cargoHash = "sha256-Oy8ymSbUNuNL8oDfnlNuZ8dUepiofE08By6hG3uLtBg=";
nativeBuildInputs = [
pkg-config
From 8a66a0b8fb36bf8a79c6fbf7b92d7f4dd3c6df93 Mon Sep 17 00:00:00 2001
From: Ihar Hrachyshka
Date: Fri, 25 Sep 2026 10:20:24 -0400
Subject: [PATCH 18/61] element-desktop: avoid duplicating element-web
https://github.com/NixOS/nixpkgs/pull/563892 added webapp.asar to
satisfy electron-builder. This unintentionally left it in the app bundle
(in addition to symlinked electron-web), bloating the package by ~140MB
for no good reason.
---
pkgs/by-name/el/element-desktop/package.nix | 3 +++
1 file changed, 3 insertions(+)
diff --git a/pkgs/by-name/el/element-desktop/package.nix b/pkgs/by-name/el/element-desktop/package.nix
index 6d206b0d7faf..b658007cd006 100644
--- a/pkgs/by-name/el/element-desktop/package.nix
+++ b/pkgs/by-name/el/element-desktop/package.nix
@@ -112,6 +112,9 @@ stdenv.mkDerivation (finalAttrs: {
asar pack tmp-app "$packed"
+ # element-web is linked into the output during installPhase.
+ find ./dist -name webapp.asar -delete
+
runHook postBuild
'';
From ece774a34079a2d954b060603ffbf9077f000981 Mon Sep 17 00:00:00 2001
From: Lajdre
Date: Fri, 25 Sep 2026 17:33:46 +0200
Subject: [PATCH 19/61] maintainers: add lajdre
---
maintainers/maintainer-list.nix | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix
index 2c763bbf13a4..de1ff2882613 100644
--- a/maintainers/maintainer-list.nix
+++ b/maintainers/maintainer-list.nix
@@ -15999,6 +15999,12 @@
githubId = 55911173;
name = "Gwendolyn Quasebarth";
};
+ lajdre = {
+ name = "Lajdre";
+ email = "lajdre.dev@tuta.com";
+ github = "lajdre";
+ githubId = 110416923;
+ };
lajp = {
email = "lajp@iki.fi";
github = "lajp";
From d298c3194148227e7ff4791ec9aeada97b63e25a Mon Sep 17 00:00:00 2001
From: "R. Ryantm"
Date: Fri, 25 Sep 2026 21:12:24 +0000
Subject: [PATCH 20/61] dblab: 0.50.0 -> 0.51.0
---
pkgs/by-name/db/dblab/package.nix | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/pkgs/by-name/db/dblab/package.nix b/pkgs/by-name/db/dblab/package.nix
index d19807712541..566e068380e0 100644
--- a/pkgs/by-name/db/dblab/package.nix
+++ b/pkgs/by-name/db/dblab/package.nix
@@ -7,13 +7,13 @@
buildGoModule (finalAttrs: {
pname = "dblab";
- version = "0.50.0";
+ version = "0.51.0";
src = fetchFromGitHub {
owner = "danvergara";
repo = "dblab";
tag = "v${finalAttrs.version}";
- hash = "sha256-cOUWl7ZWQ7iuOg3+eyKGq2jl6BVLlRmnMrftcY6H05E=";
+ hash = "sha256-Uwx3H4Pl1luhtln4QiURRrgj5+WERxQFkn+OVbYcs3w=";
};
vendorHash = "sha256-nFgwoX2GxjRdqXcocTvz7L0NA+kN1+67uTpler8di/E=";
From 285ccd7f475b0a47c15cda12330f08c2ce139444 Mon Sep 17 00:00:00 2001
From: "R. Ryantm"
Date: Fri, 25 Sep 2026 21:53:57 +0000
Subject: [PATCH 21/61] nerdctl: 2.3.5 -> 2.4.0
---
pkgs/by-name/ne/nerdctl/package.nix | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/pkgs/by-name/ne/nerdctl/package.nix b/pkgs/by-name/ne/nerdctl/package.nix
index 027c35db6de4..dc8b0d0270ef 100644
--- a/pkgs/by-name/ne/nerdctl/package.nix
+++ b/pkgs/by-name/ne/nerdctl/package.nix
@@ -14,16 +14,16 @@
buildGoModule (finalAttrs: {
pname = "nerdctl";
- version = "2.3.5";
+ version = "2.4.0";
src = fetchFromGitHub {
owner = "containerd";
repo = "nerdctl";
tag = "v${finalAttrs.version}";
- hash = "sha256-4t6yyoFnYm5rGNw8SG1nfy5C0+nks/9G8pzhuZ4U0ag=";
+ hash = "sha256-2TSuLeG82CIIiR/koGJRiGNm4RpdOPlIZhiYB7NupUs=";
};
- vendorHash = "sha256-hjqtwOph1grdmR2kHIbBVCxuNxNnUHPH8RJSCXo0rvU=";
+ vendorHash = "sha256-3FiGGr6m9HdXt1oFLLqDwakq0z0i4ZfwZEBWNd0RRQM=";
nativeBuildInputs = [
makeWrapper
From bd77871aba73759a0ff051fba5f9880c0e5047a0 Mon Sep 17 00:00:00 2001
From: "R. Ryantm"
Date: Fri, 25 Sep 2026 22:11:12 +0000
Subject: [PATCH 22/61] llmfit: 1.1.15 -> 1.1.16
---
pkgs/by-name/ll/llmfit/package.nix | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/pkgs/by-name/ll/llmfit/package.nix b/pkgs/by-name/ll/llmfit/package.nix
index 2da65a30b9ec..8931125d0b1d 100644
--- a/pkgs/by-name/ll/llmfit/package.nix
+++ b/pkgs/by-name/ll/llmfit/package.nix
@@ -8,7 +8,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "llmfit";
- version = "1.1.15";
+ version = "1.1.16";
__structuredAttrs = true;
@@ -16,10 +16,10 @@ rustPlatform.buildRustPackage (finalAttrs: {
owner = "AlexsJones";
repo = "llmfit";
tag = "v${finalAttrs.version}";
- hash = "sha256-rAlWEpoHuh03sU+Ma9LqvjNMq8/1x8e0MAQRmt4etk4=";
+ hash = "sha256-EMCtdgfR4y9+UY3byg+jYUhkcWpt1ZU8/CIOHnMY3UQ=";
};
- cargoHash = "sha256-RN5f0TGnhi2FrekmVmEYONU59g+akuewwCOj6kfcBjw=";
+ cargoHash = "sha256-aQEThRrqTh4m3KMJqCU4vcMGrQiIR23yiSibTIAywB8=";
nativeInstallCheckInputs = [ versionCheckHook ];
doInstallCheck = true;
From fb37e8e8bd6c8c6dd73434e565271239f27add27 Mon Sep 17 00:00:00 2001
From: Michael Daniels
Date: Wed, 23 Sep 2026 18:05:56 -0400
Subject: [PATCH 23/61] workflows/*: use self-repository syntax
---
.github/actions/checkout/action.yml | 9 ++++++++-
.github/workflows/build.yml | 6 +-----
.github/workflows/check.yml | 14 ++------------
.github/workflows/eval.yml | 18 +++---------------
.github/workflows/lint.yml | 18 +++---------------
.github/workflows/merge-group.yml | 8 ++++----
.github/workflows/periodic-merge-24h.yml | 2 +-
.github/workflows/periodic-merge-6h.yml | 2 +-
.github/workflows/pull-request-target.yml | 10 +++++-----
.github/workflows/test.yml | 4 ++--
10 files changed, 30 insertions(+), 61 deletions(-)
diff --git a/.github/actions/checkout/action.yml b/.github/actions/checkout/action.yml
index 91cca324fcd4..ab8c663e0f0e 100644
--- a/.github/actions/checkout/action.yml
+++ b/.github/actions/checkout/action.yml
@@ -13,6 +13,13 @@ inputs:
runs:
using: composite
steps:
+ # We don't actually need anything in this directory, but we need a small
+ # sparse checkout, and this directory is small.
+ - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ with:
+ persist-credentials: false
+ sparse-checkout: .github/actions
+
- uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
MERGED_SHA: ${{ inputs.merged-as-untrusted-at }}
@@ -37,7 +44,7 @@ runs:
})
}
- // These are set automatically by the spare checkout for .github/actions.
+ // These are set automatically by the sparse checkout for .github/actions.
// Undo them, otherwise git fetch below will not do anything.
await run('git', 'config', 'unset', 'remote.origin.promisor')
await run('git', 'config', 'unset', 'remote.origin.partialclonefilter')
diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml
index b7ba21272be1..c85a3989219e 100644
--- a/.github/workflows/build.yml
+++ b/.github/workflows/build.yml
@@ -49,12 +49,8 @@ jobs:
runs-on: ${{ matrix.runner }}
timeout-minutes: 60
steps:
- - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- with:
- persist-credentials: false
- sparse-checkout: .github/actions
- name: Checkout the merge commit
- uses: ./.github/actions/checkout
+ uses: $/.github/actions/checkout
with:
merged-as-untrusted-at: ${{ inputs.mergedSha }}
target-as-trusted-at: ${{ inputs.targetSha }}
diff --git a/.github/workflows/check.yml b/.github/workflows/check.yml
index faff91d48e6c..84c34887b7f3 100644
--- a/.github/workflows/check.yml
+++ b/.github/workflows/check.yml
@@ -190,13 +190,8 @@ jobs:
runs-on: ubuntu-24.04-arm
timeout-minutes: 5
steps:
- - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- with:
- persist-credentials: false
- sparse-checkout: .github/actions
-
- name: Checkout merge and target commits
- uses: ./.github/actions/checkout
+ uses: $/.github/actions/checkout
with:
merged-as-untrusted-at: ${{ inputs.mergedSha }}
target-as-trusted-at: ${{ inputs.targetSha }}
@@ -219,13 +214,8 @@ jobs:
runs-on: ubuntu-24.04-arm
timeout-minutes: 5
steps:
- - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- with:
- persist-credentials: false
- sparse-checkout: .github/actions
-
- name: Checkout merge and target commits
- uses: ./.github/actions/checkout
+ uses: $/.github/actions/checkout
with:
merged-as-untrusted-at: ${{ inputs.mergedSha }}
target-as-trusted-at: ${{ inputs.targetSha }}
diff --git a/.github/workflows/eval.yml b/.github/workflows/eval.yml
index 61d8b60d2bab..f971aa0229da 100644
--- a/.github/workflows/eval.yml
+++ b/.github/workflows/eval.yml
@@ -174,12 +174,8 @@ jobs:
sudo mkswap /swap
sudo swapon /swap
- - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- with:
- persist-credentials: false
- sparse-checkout: .github/actions
- name: Check out the PR at merged and target commits
- uses: ./.github/actions/checkout
+ uses: $/.github/actions/checkout
with:
# For versioned evals, use the target as the untrusted base and apply the pin-bump commit
merged-as-untrusted-at: ${{ matrix.version && inputs.targetSha || inputs.mergedSha }}
@@ -259,12 +255,8 @@ jobs:
statuses: write # creating 'Eval Summary' commit statuses
timeout-minutes: 5
steps:
- - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- with:
- persist-credentials: false
- sparse-checkout: .github/actions
- name: Check out the PR at the target commit
- uses: ./.github/actions/checkout
+ uses: $/.github/actions/checkout
with:
merged-as-untrusted-at: ${{ inputs.mergedSha }}
target-as-trusted-at: ${{ inputs.targetSha }}
@@ -477,12 +469,8 @@ jobs:
runs-on: ubuntu-24.04-arm
timeout-minutes: 10
steps:
- - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- with:
- persist-credentials: false
- sparse-checkout: .github/actions
- name: Checkout the merge commit
- uses: ./.github/actions/checkout
+ uses: $/.github/actions/checkout
with:
merged-as-untrusted-at: ${{ inputs.mergedSha }}
diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml
index b90840319c5b..faa978b13227 100644
--- a/.github/workflows/lint.yml
+++ b/.github/workflows/lint.yml
@@ -26,12 +26,8 @@ jobs:
runs-on: ubuntu-24.04-arm
timeout-minutes: 10
steps:
- - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- with:
- persist-credentials: false
- sparse-checkout: .github/actions
- name: Checkout the merge commit
- uses: ./.github/actions/checkout
+ uses: $/.github/actions/checkout
with:
merged-as-untrusted-at: ${{ inputs.mergedSha }}
@@ -61,12 +57,8 @@ jobs:
runs-on: ubuntu-24.04-arm
timeout-minutes: 10
steps:
- - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- with:
- persist-credentials: false
- sparse-checkout: .github/actions
- name: Checkout the merge commit
- uses: ./.github/actions/checkout
+ uses: $/.github/actions/checkout
with:
merged-as-untrusted-at: ${{ inputs.mergedSha }}
@@ -90,12 +82,8 @@ jobs:
runs-on: ubuntu-24.04-arm
timeout-minutes: 10
steps:
- - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- with:
- persist-credentials: false
- sparse-checkout: .github/actions
- name: Checkout merge and target commits
- uses: ./.github/actions/checkout
+ uses: $/.github/actions/checkout
with:
merged-as-untrusted-at: ${{ inputs.mergedSha }}
target-as-trusted-at: ${{ inputs.targetSha }}
diff --git a/.github/workflows/merge-group.yml b/.github/workflows/merge-group.yml
index 1156c2a616eb..e111c35ca7c8 100644
--- a/.github/workflows/merge-group.yml
+++ b/.github/workflows/merge-group.yml
@@ -63,7 +63,7 @@ jobs:
check:
name: Check
needs: [prepare]
- uses: ./.github/workflows/check.yml
+ uses: $/.github/workflows/check.yml
permissions:
pull-requests: write # cherry-picks: unused in merge queue but required for check workflow
secrets:
@@ -75,7 +75,7 @@ jobs:
lint:
name: Lint
needs: [prepare]
- uses: ./.github/workflows/lint.yml
+ uses: $/.github/workflows/lint.yml
secrets:
CACHIX_AUTH_TOKEN_GHA: ${{ secrets.CACHIX_AUTH_TOKEN_GHA }}
with:
@@ -85,7 +85,7 @@ jobs:
eval:
name: Eval
needs: [prepare]
- uses: ./.github/workflows/eval.yml
+ uses: $/.github/workflows/eval.yml
# The eval workflow requests these permissions so we must explicitly allow them,
# even though they are unused when working with the merge queue.
permissions:
@@ -103,7 +103,7 @@ jobs:
build:
name: Build
needs: [prepare]
- uses: ./.github/workflows/build.yml
+ uses: $/.github/workflows/build.yml
secrets:
CACHIX_AUTH_TOKEN_GHA: ${{ secrets.CACHIX_AUTH_TOKEN_GHA }}
with:
diff --git a/.github/workflows/periodic-merge-24h.yml b/.github/workflows/periodic-merge-24h.yml
index d14c482df755..c6e31f737b6e 100644
--- a/.github/workflows/periodic-merge-24h.yml
+++ b/.github/workflows/periodic-merge-24h.yml
@@ -40,7 +40,7 @@ jobs:
- name: merge-base(master,staging) → haskell-updates
from: master staging
into: haskell-updates
- uses: ./.github/workflows/periodic-merge.yml
+ uses: $/.github/workflows/periodic-merge.yml
with:
from: ${{ matrix.pairs.from }}
into: ${{ matrix.pairs.into }}
diff --git a/.github/workflows/periodic-merge-6h.yml b/.github/workflows/periodic-merge-6h.yml
index ad81eb6c9a3b..0da0a3336364 100644
--- a/.github/workflows/periodic-merge-6h.yml
+++ b/.github/workflows/periodic-merge-6h.yml
@@ -37,7 +37,7 @@ jobs:
into: staging
- from: master
into: staging-nixos
- uses: ./.github/workflows/periodic-merge.yml
+ uses: $/.github/workflows/periodic-merge.yml
with:
from: ${{ matrix.pairs.from }}
into: ${{ matrix.pairs.into }}
diff --git a/.github/workflows/pull-request-target.yml b/.github/workflows/pull-request-target.yml
index aa42175a0cc1..98d463cb588d 100644
--- a/.github/workflows/pull-request-target.yml
+++ b/.github/workflows/pull-request-target.yml
@@ -75,7 +75,7 @@ jobs:
check:
name: Check
needs: [prepare]
- uses: ./.github/workflows/check.yml
+ uses: $/.github/workflows/check.yml
permissions:
# cherry-picks
pull-requests: write
@@ -92,7 +92,7 @@ jobs:
lint:
name: Lint
needs: [prepare]
- uses: ./.github/workflows/lint.yml
+ uses: $/.github/workflows/lint.yml
with:
mergedSha: ${{ needs.prepare.outputs.mergedSha }}
targetSha: ${{ needs.prepare.outputs.targetSha }}
@@ -100,7 +100,7 @@ jobs:
eval:
name: Eval
needs: [prepare]
- uses: ./.github/workflows/eval.yml
+ uses: $/.github/workflows/eval.yml
permissions:
# compare
pull-requests: write
@@ -119,7 +119,7 @@ jobs:
bot:
name: Bot
needs: [prepare, eval]
- uses: ./.github/workflows/bot.yml
+ uses: $/.github/workflows/bot.yml
permissions:
issues: write
pull-requests: write
@@ -131,7 +131,7 @@ jobs:
build:
name: Build
needs: [prepare]
- uses: ./.github/workflows/build.yml
+ uses: $/.github/workflows/build.yml
with:
artifact-prefix: ${{ inputs.artifact-prefix }}
baseBranch: ${{ needs.prepare.outputs.baseBranch }}
diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml
index ad1aaed202ff..35208ae4fab2 100644
--- a/.github/workflows/test.yml
+++ b/.github/workflows/test.yml
@@ -103,7 +103,7 @@ jobs:
if: needs.prepare.outputs.merge-group
name: Merge Group
needs: [prepare]
- uses: ./.github/workflows/merge-group.yml
+ uses: $/.github/workflows/merge-group.yml
# Those are actually only used on the merge_group event, but will throw an error if not set.
permissions:
pull-requests: write # unused on pull_request, required by merge-group workflow
@@ -117,7 +117,7 @@ jobs:
if: needs.prepare.outputs.pr
name: PR
needs: [prepare]
- uses: ./.github/workflows/pull-request-target.yml
+ uses: $/.github/workflows/pull-request-target.yml
# Those are actually only used on the pull_request_target event, but will throw an error if not set.
permissions:
issues: write # unused on pull_request, required by bot workflow
From d61db5aa6b86df0e8cdd242dc7eb5c8909d0be74 Mon Sep 17 00:00:00 2001
From: Michael Daniels
Date: Fri, 25 Sep 2026 21:03:08 -0400
Subject: [PATCH 24/61] ci/pinned.json: update
[nixpkgs-26.05-darwin] Changes:
- revision: 51fe96f9107566e6b8eeb7fc4ba696c01e548b04
+ revision: 7486293a941f7b0ec123f0c431517027f705f60f
- url: https://github.com/NixOS/nixpkgs/archive/51fe96f9107566e6b8eeb7fc4ba696c01e548b04.tar.gz
+ url: https://github.com/NixOS/nixpkgs/archive/7486293a941f7b0ec123f0c431517027f705f60f.tar.gz
- hash: sha256-yj0LPLnsmYoLmA3FGANjeTEwej0/DHjZBXWnDQDUuIs=
+ hash: sha256-WQhNWIW3PPijuZexyl5Zf0tJuQ7sKt5C9WPXVO4pMuM=
[nixpkgs] Changes:
- revision: 7525d999cd850b9a488817abc89c75dc733acf17
+ revision: 7d5589bbf421c7b6f4185371abe3c465b1b557e9
- url: https://github.com/NixOS/nixpkgs/archive/7525d999cd850b9a488817abc89c75dc733acf17.tar.gz
+ url: https://github.com/NixOS/nixpkgs/archive/7d5589bbf421c7b6f4185371abe3c465b1b557e9.tar.gz
- hash: sha256-4IHyyLgLBdKefkljdKod4IMn023pQiDXAWJA187cmdY=
+ hash: sha256-8emM5Z42GzMSLLvjJt7UkX1j2k2TKXQIS7FnPTfeHno=
---
ci/pinned.json | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/ci/pinned.json b/ci/pinned.json
index 32f5e186650c..a30aff6f92f8 100644
--- a/ci/pinned.json
+++ b/ci/pinned.json
@@ -9,9 +9,9 @@
},
"branch": "nixpkgs-unstable",
"submodules": false,
- "revision": "7525d999cd850b9a488817abc89c75dc733acf17",
- "url": "https://github.com/NixOS/nixpkgs/archive/7525d999cd850b9a488817abc89c75dc733acf17.tar.gz",
- "hash": "sha256-4IHyyLgLBdKefkljdKod4IMn023pQiDXAWJA187cmdY="
+ "revision": "7d5589bbf421c7b6f4185371abe3c465b1b557e9",
+ "url": "https://github.com/NixOS/nixpkgs/archive/7d5589bbf421c7b6f4185371abe3c465b1b557e9.tar.gz",
+ "hash": "sha256-8emM5Z42GzMSLLvjJt7UkX1j2k2TKXQIS7FnPTfeHno="
},
"nixpkgs-26.05-darwin": {
"type": "Git",
@@ -22,9 +22,9 @@
},
"branch": "nixpkgs-26.05-darwin",
"submodules": false,
- "revision": "51fe96f9107566e6b8eeb7fc4ba696c01e548b04",
- "url": "https://github.com/NixOS/nixpkgs/archive/51fe96f9107566e6b8eeb7fc4ba696c01e548b04.tar.gz",
- "hash": "sha256-yj0LPLnsmYoLmA3FGANjeTEwej0/DHjZBXWnDQDUuIs="
+ "revision": "7486293a941f7b0ec123f0c431517027f705f60f",
+ "url": "https://github.com/NixOS/nixpkgs/archive/7486293a941f7b0ec123f0c431517027f705f60f.tar.gz",
+ "hash": "sha256-WQhNWIW3PPijuZexyl5Zf0tJuQ7sKt5C9WPXVO4pMuM="
}
},
"version": 8
From b7395edf46d458ea7c95c1b0e71ff21d0307df9f Mon Sep 17 00:00:00 2001
From: "R. Ryantm"
Date: Sat, 26 Sep 2026 01:05:37 +0000
Subject: [PATCH 25/61] sub-store-frontend: 2.32.2 -> 2.34.0
---
pkgs/by-name/su/sub-store-frontend/package.nix | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/pkgs/by-name/su/sub-store-frontend/package.nix b/pkgs/by-name/su/sub-store-frontend/package.nix
index 77829b5c17cc..f72b225d21bd 100644
--- a/pkgs/by-name/su/sub-store-frontend/package.nix
+++ b/pkgs/by-name/su/sub-store-frontend/package.nix
@@ -14,13 +14,13 @@ let
in
buildNpmPackage (finalAttrs: {
pname = "sub-store-frontend";
- version = "2.32.2";
+ version = "2.34.0";
src = fetchFromGitHub {
owner = "sub-store-org";
repo = "Sub-Store-Front-End";
tag = finalAttrs.version;
- hash = "sha256-TbKJNSA+ivUd7bHDtE9COaZFMqxRkRdBXWkK7y7JMSU=";
+ hash = "sha256-jphgUjJouLky6jxTSk+6YBbwaNTV7+/oTu2RXc3UNk0=";
};
nativeBuildInputs = [
From 53bc4d6aa3a65bd08347344fa05c4d680a9d3088 Mon Sep 17 00:00:00 2001
From: Michael Daniels
Date: Fri, 25 Sep 2026 21:21:45 -0400
Subject: [PATCH 26/61] various: fix formatting
---
nixos/modules/hardware/facter/camera/ipu6.nix | 2 +-
nixos/modules/services/x11/desktop-managers/xfce.nix | 6 +++---
nixos/tests/moduleStateRevisions.nix | 2 +-
pkgs/build-support/dart/pub2nix/pubspec-lock.nix | 2 +-
pkgs/by-name/in/iniparser/package.nix | 6 +++---
pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix | 6 +++---
6 files changed, 12 insertions(+), 12 deletions(-)
diff --git a/nixos/modules/hardware/facter/camera/ipu6.nix b/nixos/modules/hardware/facter/camera/ipu6.nix
index 5319d8bf3d49..799c22188824 100644
--- a/nixos/modules/hardware/facter/camera/ipu6.nix
+++ b/nixos/modules/hardware/facter/camera/ipu6.nix
@@ -66,7 +66,7 @@ let
in
bus_type.name == "PCI"
&& devices
- ? "${vendorHex}:${deviceHex}:${subVendorHex}:${subDeviceHex}/${baseClassHex}-${subClassHex}-${revisionHex}"
+ ? "${vendorHex}:${deviceHex}:${subVendorHex}:${subDeviceHex}/${baseClassHex}-${subClassHex}-${revisionHex}"
);
in
{
diff --git a/nixos/modules/services/x11/desktop-managers/xfce.nix b/nixos/modules/services/x11/desktop-managers/xfce.nix
index 332c78b3658a..d448f10cdfa8 100644
--- a/nixos/modules/services/x11/desktop-managers/xfce.nix
+++ b/nixos/modules/services/x11/desktop-managers/xfce.nix
@@ -209,9 +209,9 @@ in
DesktopNames=XFCE
Keywords=xfce;wayland;desktop;environment;session;
'').overrideAttrs
- (_: {
- passthru.providedSessions = [ "xfce-wayland" ];
- })
+ (_: {
+ passthru.providedSessions = [ "xfce-wayland" ];
+ })
)
];
diff --git a/nixos/tests/moduleStateRevisions.nix b/nixos/tests/moduleStateRevisions.nix
index 3bce4c312488..9b2cc98dc715 100644
--- a/nixos/tests/moduleStateRevisions.nix
+++ b/nixos/tests/moduleStateRevisions.nix
@@ -15,7 +15,7 @@ let
testModule =
path:
evalModuleStateRevisions (lib.setAttrByPath path { enable = true; })
- ? "${builtins.concatStringsSep "." path}.stateRevision";
+ ? "${builtins.concatStringsSep "." path}.stateRevision";
in
assert evalModuleStateRevisions { } == { };
assert testModule [
diff --git a/pkgs/build-support/dart/pub2nix/pubspec-lock.nix b/pkgs/build-support/dart/pub2nix/pubspec-lock.nix
index 73788f535a90..2a6973c90043 100644
--- a/pkgs/build-support/dart/pub2nix/pubspec-lock.nix
+++ b/pkgs/build-support/dart/pub2nix/pubspec-lock.nix
@@ -151,7 +151,7 @@ let
"sdk" = mkSdkDependencySource;
}
.${details.source}
- name
+ name
)
details
))
diff --git a/pkgs/by-name/in/iniparser/package.nix b/pkgs/by-name/in/iniparser/package.nix
index 3d1a5af3a3f4..f02b029cee4e 100644
--- a/pkgs/by-name/in/iniparser/package.nix
+++ b/pkgs/by-name/in/iniparser/package.nix
@@ -54,9 +54,9 @@ stdenv.mkDerivation (finalAttrs: {
(unity-test.override {
supportDouble = true;
}).overrideAttrs
- {
- doCheck = false;
- }
+ {
+ doCheck = false;
+ }
)
];
diff --git a/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix b/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix
index 80dad06be8f8..a5220d11a2fa 100644
--- a/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix
+++ b/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix
@@ -28,9 +28,9 @@ runCommand "${pname}-filtered-src"
enableOpenSSL = false;
enableLZ4 = false;
}).overrideAttrs
- {
- doCheck = false;
- }
+ {
+ doCheck = false;
+ }
)
];
}
From 69945735936247442f2defa8dca713dccf1a41e7 Mon Sep 17 00:00:00 2001
From: "R. Ryantm"
Date: Sat, 26 Sep 2026 02:40:06 +0000
Subject: [PATCH 27/61] step-cli: 0.30.6 -> 0.31.0
---
pkgs/by-name/st/step-cli/package.nix | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/pkgs/by-name/st/step-cli/package.nix b/pkgs/by-name/st/step-cli/package.nix
index 10ae33e4cf52..dac4a0e10a5a 100644
--- a/pkgs/by-name/st/step-cli/package.nix
+++ b/pkgs/by-name/st/step-cli/package.nix
@@ -8,7 +8,7 @@
unixtools,
}:
let
- version = "0.30.6";
+ version = "0.31.0";
in
buildGoModule {
pname = "step-cli";
@@ -18,7 +18,7 @@ buildGoModule {
owner = "smallstep";
repo = "cli";
tag = "v${version}";
- hash = "sha256-fMHvv14ToKq73h3aLJBebzhIJQghfBOX6C0hvDODHN8=";
+ hash = "sha256-v8insc/+vnc4JVNeHeF3UU+rYdNtMeQkdWxVc+vq7ms=";
# this file change depending on git branch status (via .gitattributes)
# https://github.com/NixOS/nixpkgs/issues/84312
postFetch = ''
@@ -39,7 +39,7 @@ buildGoModule {
patchShebangs integration/openssl-jwt.sh
'';
- vendorHash = "sha256-DTFp9K5iiS50QuD2knN/8miYb2k/7O1d3GyEf79i69Q=";
+ vendorHash = "sha256-UNrUy0aWl7w5SmlsxLpmx6WxI2AElHE6llAMLRLi0r0=";
nativeBuildInputs = [ installShellFiles ];
nativeCheckInputs = [
From 3b6c99011c84d10d2171e773e41ef715e26d5975 Mon Sep 17 00:00:00 2001
From: Markus Hauck
Date: Sat, 26 Sep 2026 08:20:46 +0200
Subject: [PATCH 28/61] claude-code: 2.1.281 -> 2.1.283
Changelog: https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md
Assisted-by: Claude Code (Claude Opus 5.5)
---
pkgs/by-name/cl/claude-code/manifest.zst.json | 54 +++++++++----------
1 file changed, 27 insertions(+), 27 deletions(-)
diff --git a/pkgs/by-name/cl/claude-code/manifest.zst.json b/pkgs/by-name/cl/claude-code/manifest.zst.json
index d7c4c6b3d738..cae90932dfdc 100644
--- a/pkgs/by-name/cl/claude-code/manifest.zst.json
+++ b/pkgs/by-name/cl/claude-code/manifest.zst.json
@@ -1,63 +1,61 @@
{
- "version": "2.1.281",
+ "version": "2.1.283",
"manifestSignatureEnforcement": "flag",
- "commit": "3e320108de6831eb996e9a3f7795152073cc0d0c",
- "modsCommit": "56f36532530f88b572854538d685fcf781141e8c",
- "buildDate": "2026-09-23T02:34:19Z",
+ "commit": "4631ccd7cfe41e69bc72d3b5b9dc7282536e4985",
+ "modsCommit": "684ffc4da0eaaddcafa61842dc719c6a8febc5c2",
+ "buildDate": "2026-09-25T01:40:44Z",
"platforms": {
"darwin-arm64": {
"binary": "claude.zst",
- "checksum": "056662a4e3a5ca37770730a59345d1b5796ef65444c32b97d236651ab68f3fa1",
- "size": 74110572,
+ "checksum": "485d6883c023368800626e0d1f2e4382c3e1bdc760fae12cb2f6e3054f218eec",
+ "size": 75461598,
"bundle": {
- "checksum": "01c192d55a6fa8fcc84557bbd913dfb43ae65f15c39bd1fba9161fc4ff7de175",
- "size": 74115578
+ "checksum": "f22ac793e83fbaa4ec74a1194c98c4f9c8cd808cfa2a238aecb561a342420b3e",
+ "size": 75465975
}
},
"darwin-x64": {
"binary": "claude.zst",
- "checksum": "085dd9952999c742cf262d0fed571c3bcd749d5127eb7dd455bc5be0948c7b9d",
- "size": 78229557,
+ "checksum": "2ac2ccd98433c2727de1b7142dd808f355e7764fa573ab891666f496a3a669ee",
+ "size": 79614241,
"bundle": {
- "checksum": "05e821e3c9f1178b603c6f7fcb3e05b1a038f885cb55eed42ad8df9bbfc7fdad",
- "size": 78233701
+ "checksum": "7a9ef7b6b7ccdb343c3c2c160efc1984bda9f9f446bca97603008cfdfe99835f",
+ "size": 79613206
}
},
"linux-arm64": {
"binary": "claude.zst",
- "checksum": "7583b65585561c714e18caca45e0e0fb9bdba6d7ed6ee5d5171834d5c657aea6",
- "size": 83227605
+ "checksum": "7ff80952f5cf74fa593432ec19fc7bef1b4461b365092fe2b6c6060d4fbad1ec",
+ "size": 84571156
},
"linux-x64": {
"binary": "claude.zst",
- "checksum": "4ffb9f6baada4d88bbd8c586773efd0605c524c7a31cc3833eeda229717a7b25",
- "size": 83964259
+ "checksum": "94345861e88be3d67a8393494f98f5b1c67604c14ccd4ef3c7a51e3643fa25eb",
+ "size": 85309419
},
"linux-arm64-musl": {
"binary": "claude.zst",
- "checksum": "b5400b7f787e78f6c206c1adf70c65b5b6835f2899b61edfa83a117be92111d5",
- "size": 81645720
+ "checksum": "12ab758aca002744a1364328536d0b30d510707262d9eb116390a14b269a3c79",
+ "size": 82977461
},
"linux-x64-musl": {
"binary": "claude.zst",
- "checksum": "3921fd07a12e93f858c8b706eca0e4d7b12af14f4af5378d3b87254b4231def5",
- "size": 82393109
+ "checksum": "118b07bbe50b9ca5ab303ed070fb5d065696c413ae62f9dc1c8f64f2c9d824ec",
+ "size": 83744817
},
"win32-x64": {
"binary": "claude.exe.zst",
- "checksum": "62f544612ca7e31cdc197bdf8651abcc529bd716964d2517e101177c6b94c70a",
- "size": 86264937
+ "checksum": "b201734251f1d6470a65453192422d1b03d6f3a5c1365b43dc7d2b65cd135233",
+ "size": 87607368
},
"win32-arm64": {
"binary": "claude.exe.zst",
- "checksum": "41b632497a440de03904c03483d000b4004b908a5f3eb71f139de6dbd40cd685",
- "size": 82711371
+ "checksum": "302ac016e1f3487b87945596388d38cf9b2974597375ec24447278d5019e7c6e",
+ "size": 83948914
}
},
"sdkCompat": {
"testedWrapperVersions": [
- "0.3.241",
- "0.3.242",
"0.3.243",
"0.3.245",
"0.3.246",
@@ -72,6 +70,7 @@
"0.3.260",
"0.3.261",
"0.3.263",
+ "0.3.265",
"0.3.266",
"0.3.267",
"0.3.268",
@@ -85,7 +84,8 @@
"0.3.276",
"0.3.277",
"0.3.278",
- "0.3.280"
+ "0.3.280",
+ "0.3.281"
],
"harnessSchema": 1
}
From 043287a5708ce6a52c285957fe433716ce8f3adc Mon Sep 17 00:00:00 2001
From: Markus Hauck
Date: Sat, 26 Sep 2026 08:20:46 +0200
Subject: [PATCH 29/61] vscode-extensions.anthropic.claude-code: 2.1.281 ->
2.1.283
Changelog: https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md
Assisted-by: Claude Code (Claude Opus 5.5)
---
.../vscode/extensions/anthropic.claude-code/default.nix | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/pkgs/applications/editors/vscode/extensions/anthropic.claude-code/default.nix b/pkgs/applications/editors/vscode/extensions/anthropic.claude-code/default.nix
index e0e20ba34234..8b0326a3cb3f 100644
--- a/pkgs/applications/editors/vscode/extensions/anthropic.claude-code/default.nix
+++ b/pkgs/applications/editors/vscode/extensions/anthropic.claude-code/default.nix
@@ -21,22 +21,22 @@ vscode-utils.buildVscodeMarketplaceExtension (finalAttrs: {
sources = {
"x86_64-linux" = {
arch = "linux-x64";
- hash = "sha256-pXzLJ/1g33JUorADMf0EzvI7DY2kbAZSnkttPY5ekOs=";
+ hash = "sha256-yUrFhJa/DkAQXH/0EZ3N0axloCNtrPvaFfmJ5/bnqRg=";
};
"aarch64-linux" = {
arch = "linux-arm64";
- hash = "sha256-CEKNRiYs8Grko5nVGSanAgj5WmLC7hnMBC9OXElrmoQ=";
+ hash = "sha256-2L5+MZNnBraXmX4npH1/aLlU+uBRsGEKdpAZ6kh7krc=";
};
"aarch64-darwin" = {
arch = "darwin-arm64";
- hash = "sha256-eu+5zAGdzFsx/PeAgCj60ppP0CMQEsZGaVlR+8OfFbQ=";
+ hash = "sha256-Ztzy6ZrqdhCy/bd+zAxGaq07KZBKHS4GMGTAe62Dxk8=";
};
};
in
{
name = "claude-code";
publisher = "anthropic";
- version = "2.1.281";
+ version = "2.1.283";
}
// sources.${stdenvNoCC.hostPlatform.system}
or (throw "Unsupported system ${stdenvNoCC.hostPlatform.system}");
From 88d393ffbabdccbd01acfa68fb9a624875c8fd7c Mon Sep 17 00:00:00 2001
From: Matthias Beyer
Date: Sat, 26 Sep 2026 10:02:30 +0200
Subject: [PATCH 30/61] llmfit: Skip tests that rely on system stuff
Signed-off-by: Matthias Beyer
---
pkgs/by-name/ll/llmfit/package.nix | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/pkgs/by-name/ll/llmfit/package.nix b/pkgs/by-name/ll/llmfit/package.nix
index 8931125d0b1d..7afde4ba9bea 100644
--- a/pkgs/by-name/ll/llmfit/package.nix
+++ b/pkgs/by-name/ll/llmfit/package.nix
@@ -26,6 +26,13 @@ rustPlatform.buildRustPackage (finalAttrs: {
passthru.updateScript = nix-update-script { };
+ # These seem to rely on system state that we do not have inside nix builds
+ checkFlags = [
+ "--skip=json_apple_gpu_skips_successful_text_probe"
+ "--skip=json_apple_gpu_survives_failed_text_probe"
+ "--skip=text_probe_recovers_when_json_fails"
+ ];
+
meta = {
description = "TUI to find LLM models right sized for the system's RAM, CPU, and GPU";
homepage = "https://github.com/AlexsJones/llmfit";
From 039a9aa75465b26596d42d3878c6caead9ef7b45 Mon Sep 17 00:00:00 2001
From: "R. Ryantm"
Date: Sat, 26 Sep 2026 08:08:53 +0000
Subject: [PATCH 31/61] peazip: 11.2.0 -> 11.3.0
---
pkgs/by-name/pe/peazip/package.nix | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/pkgs/by-name/pe/peazip/package.nix b/pkgs/by-name/pe/peazip/package.nix
index 1793baac82cd..db1114ec613e 100644
--- a/pkgs/by-name/pe/peazip/package.nix
+++ b/pkgs/by-name/pe/peazip/package.nix
@@ -24,13 +24,13 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "peazip";
- version = "11.2.0";
+ version = "11.3.0";
src = fetchFromGitHub {
owner = "peazip";
repo = "peazip";
rev = finalAttrs.version;
- hash = "sha256-zaadYVbeNhlHl/2g7yldG4ZlyL2DEyzwODvomuCBSkE=";
+ hash = "sha256-NeFfXFsDYpRHPrIZGkJMvplYxsTw+QzQ33TJzgyDZ+c=";
};
sourceRoot = "${finalAttrs.src.name}/peazip-sources";
From cb0296095bd85bf7c180e12f30015358985684f6 Mon Sep 17 00:00:00 2001
From: "R. Ryantm"
Date: Sat, 26 Sep 2026 11:29:06 +0000
Subject: [PATCH 32/61] apm-cli: 0.29.0 -> 0.32.0
---
pkgs/by-name/ap/apm-cli/package.nix | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/pkgs/by-name/ap/apm-cli/package.nix b/pkgs/by-name/ap/apm-cli/package.nix
index 12430503cde0..60f0eab8b7b9 100644
--- a/pkgs/by-name/ap/apm-cli/package.nix
+++ b/pkgs/by-name/ap/apm-cli/package.nix
@@ -7,7 +7,7 @@
python3Packages.buildPythonApplication (finalAttrs: {
pname = "apm-cli";
- version = "0.29.0";
+ version = "0.32.0";
pyproject = true;
__structuredAttrs = true;
@@ -16,7 +16,7 @@ python3Packages.buildPythonApplication (finalAttrs: {
owner = "microsoft";
repo = "apm";
tag = "v${finalAttrs.version}";
- hash = "sha256-0aVqPRRaVjV3qoE+Fh3L98HUmBlAtu3pMiTSxVDj4Ak=";
+ hash = "sha256-yGgLFNwvJkZx0yX8PtUjeg/XdCYBD7YRb0OXoA8knno=";
};
postPatch = ''
From 9324ab88f2a23ca21b28b84fe3de161b21402098 Mon Sep 17 00:00:00 2001
From: Lajdre
Date: Fri, 25 Sep 2026 17:43:57 +0200
Subject: [PATCH 33/61] tern: init at 2.4.3
---
pkgs/by-name/te/tern/package.nix | 68 ++++++++++++++++++++++++++++++++
1 file changed, 68 insertions(+)
create mode 100644 pkgs/by-name/te/tern/package.nix
diff --git a/pkgs/by-name/te/tern/package.nix b/pkgs/by-name/te/tern/package.nix
new file mode 100644
index 000000000000..230d7756a70e
--- /dev/null
+++ b/pkgs/by-name/te/tern/package.nix
@@ -0,0 +1,68 @@
+{
+ lib,
+ buildGoModule,
+ fetchFromGitHub,
+ nix-update-script,
+ versionCheckHook,
+ postgresql,
+ postgresqlTestHook,
+}:
+
+buildGoModule (finalAttrs: {
+ pname = "tern";
+ version = "2.4.3";
+ __structuredAttrs = true;
+
+ src = fetchFromGitHub {
+ owner = "jackc";
+ repo = "tern";
+ tag = "v${finalAttrs.version}";
+ hash = "sha256-K76TowSW1bdyqVoZdlnqXV2Jlk9exMS2D/keE/9buFc=";
+ };
+
+ vendorHash = "sha256-rUPJTwGdZABZxEjON7JeB38GDpV+KN7VfbNyU//SadM=";
+
+ nativeCheckInputs = [
+ postgresql
+ postgresqlTestHook
+ ];
+
+ # Tests drop/recreate the database via dropdb/createdb
+ postgresqlTestUserOptions = "LOGIN CREATEDB";
+
+ # Sets variables read by tests that are normally set by tern's
+ # scripts/dev-env.bash
+ postgresqlTestSetupPost = ''
+ # tern uses a separate database for the migration tests, because go test
+ # runs the root and migrate package tests in parallel, and the migrate
+ # tests drop/recreate their database
+ export MIGRATE_TEST_DATABASE=test_db_migrate
+ createdb "$MIGRATE_TEST_DATABASE"
+ export MIGRATE_TEST_CONN_STRING="host=$PGHOST user=$PGUSER database=$MIGRATE_TEST_DATABASE sslmode=disable"
+
+ export TERN_TEST_CONFIG=$NIX_BUILD_TOP/tern-test.conf
+ export TERN_TEST_CONN_STRING="host=$PGHOST user=$PGUSER database=$PGDATABASE sslmode=disable"
+ cat << EOF > "$TERN_TEST_CONFIG"
+ [database]
+ host = $PGHOST
+ user = $PGUSER
+ database = $PGDATABASE
+ sslmode = disable
+ EOF
+ '';
+
+ doInstallCheck = true;
+ nativeInstallCheckInputs = [ versionCheckHook ];
+ versionCheckProgramArg = "version";
+
+ passthru.updateScript = nix-update-script { };
+
+ meta = {
+ description = "Standalone PostgreSQL database migration tool";
+ homepage = "https://github.com/jackc/tern";
+ changelog = "https://github.com/jackc/tern/releases/tag/${finalAttrs.src.tag}";
+ license = lib.licenses.mit;
+ maintainers = with lib.maintainers; [ lajdre ];
+ mainProgram = "tern";
+ };
+})
From a9468d53e3ba64fd551aca52deccce68110a382a Mon Sep 17 00:00:00 2001
From: "R. Ryantm"
Date: Sat, 26 Sep 2026 08:44:32 +0000
Subject: [PATCH 34/61] python3Packages.evosax: 0.2.0 -> 0.3.1
---
.../python-modules/evosax/default.nix | 20 +++++++++----------
1 file changed, 10 insertions(+), 10 deletions(-)
diff --git a/pkgs/development/python-modules/evosax/default.nix b/pkgs/development/python-modules/evosax/default.nix
index e0de3f633427..66aa3647a67b 100644
--- a/pkgs/development/python-modules/evosax/default.nix
+++ b/pkgs/development/python-modules/evosax/default.nix
@@ -14,24 +14,24 @@
numpy,
# tests
- # brax, (unpackaged)
- # gymnax, (unpackaged)
+ brax,
pytestCheckHook,
torch,
torchvision,
writableTmpDirAsHomeHook,
}:
-buildPythonPackage rec {
+buildPythonPackage (finalAttrs: {
pname = "evosax";
- version = "0.2.0";
+ version = "0.3.1";
pyproject = true;
+ __structuredAttrs = true;
src = fetchFromGitHub {
owner = "RobertTLange";
repo = "evosax";
- tag = "v.${version}";
- hash = "sha256-ye5IHM8Pn/+BXI9kcB3W281Gna9hXV8DwsaJ9Xu06fU=";
+ tag = "v.${finalAttrs.version}";
+ hash = "sha256-iuhqlpwU4puAxzepXAixpBrLajkGNgBxXijwoNX36+8=";
};
build-system = [ setuptools ];
@@ -47,8 +47,8 @@ buildPythonPackage rec {
pythonImportsCheck = [ "evosax" ];
nativeCheckInputs = [
- # brax
- # gymnax
+ brax
+ # gymnax (unpackaged)
pytestCheckHook
torch
torchvision
@@ -80,8 +80,8 @@ buildPythonPackage rec {
meta = {
description = "Evolution Strategies in JAX";
homepage = "https://github.com/RobertTLange/evosax";
- changelog = "https://github.com/RobertTLange/evosax/releases/tag/v.${version}";
+ changelog = "https://github.com/RobertTLange/evosax/releases/tag/${finalAttrs.src.tag}";
license = lib.licenses.asl20;
maintainers = with lib.maintainers; [ GaetanLepage ];
};
-}
+})
From 5e489f6a53fc2dbe66ac7f49e3726d24739b5422 Mon Sep 17 00:00:00 2001
From: Nikolay Korotkiy
Date: Sat, 26 Sep 2026 15:59:17 +0400
Subject: [PATCH 35/61] llmfit: set __darwinAllowLocalNetworking
---
pkgs/by-name/ll/llmfit/package.nix | 2 ++
1 file changed, 2 insertions(+)
diff --git a/pkgs/by-name/ll/llmfit/package.nix b/pkgs/by-name/ll/llmfit/package.nix
index 7afde4ba9bea..411e4ff476b7 100644
--- a/pkgs/by-name/ll/llmfit/package.nix
+++ b/pkgs/by-name/ll/llmfit/package.nix
@@ -33,6 +33,8 @@ rustPlatform.buildRustPackage (finalAttrs: {
"--skip=text_probe_recovers_when_json_fails"
];
+ __darwinAllowLocalNetworking = true;
+
meta = {
description = "TUI to find LLM models right sized for the system's RAM, CPU, and GPU";
homepage = "https://github.com/AlexsJones/llmfit";
From 994894afd356e638d1574d9a563eec91511aabf1 Mon Sep 17 00:00:00 2001
From: Nico Felbinger
Date: Sat, 26 Sep 2026 14:18:59 +0200
Subject: [PATCH 36/61] netboxPlugins.netbox-fms: fix meta.changelog
---
pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix b/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix
index a8c59234ad30..1ef6787b91c4 100644
--- a/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix
+++ b/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix
@@ -36,7 +36,7 @@ buildPythonPackage (finalAttrs: {
meta = {
description = "NetBox plugin for Fiber Management System: fiber cable management, splice planning, and circuit provisioning";
homepage = "https://jsenecal.github.io/netbox-fms/";
- changelog = "https://jsenecal.github.io/netbox-fms/releases/tag/${finalAttrs.src.tag}";
+ changelog = "https://github.com/jsenecal/netbox-fms/releases/tag/${finalAttrs.src.tag}";
license = lib.licenses.agpl3Only;
maintainers = with lib.maintainers; [ felbinger ];
platforms = lib.platforms.linux;
From 94ed349bd2d415f567c9d34764f99213e214f9b9 Mon Sep 17 00:00:00 2001
From: "R. Ryantm"
Date: Sat, 26 Sep 2026 12:19:30 +0000
Subject: [PATCH 37/61] home-assistant-custom-components.battery_notes: 3.6.3
-> 3.7.0
---
.../custom-components/battery_notes/package.nix | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/pkgs/servers/home-assistant/custom-components/battery_notes/package.nix b/pkgs/servers/home-assistant/custom-components/battery_notes/package.nix
index b368f1af798c..4734a64412ea 100644
--- a/pkgs/servers/home-assistant/custom-components/battery_notes/package.nix
+++ b/pkgs/servers/home-assistant/custom-components/battery_notes/package.nix
@@ -7,13 +7,13 @@
buildHomeAssistantComponent rec {
owner = "andrew-codechimp";
domain = "battery_notes";
- version = "3.6.3";
+ version = "3.7.0";
src = fetchFromGitHub {
inherit owner;
repo = "HA-Battery-Notes";
tag = version;
- hash = "sha256-TlrFWmgnvFHAvTiGNXkY2TZOo77yU6eVY0o3WDWNRpI=";
+ hash = "sha256-nqYAi+Fgdag+9B7IBDWngdzlPORirOyiPjYxwY8Iorc=";
};
# has no tests
From f773eae1bf1a0a866877cd29ddcf958d505f728b Mon Sep 17 00:00:00 2001
From: Nico Felbinger
Date: Sat, 26 Sep 2026 14:20:00 +0200
Subject: [PATCH 38/61] netboxPlugins.netbox-fms: 0.3.0 -> 0.5.0
---
pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix b/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix
index 1ef6787b91c4..d1f96f14e66c 100644
--- a/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix
+++ b/pkgs/by-name/ne/netbox/plugins/netbox-fms/package.nix
@@ -8,7 +8,7 @@
}:
buildPythonPackage (finalAttrs: {
pname = "netbox-fms";
- version = "0.3.0";
+ version = "0.5.0";
pyproject = true;
__structuredAttrs = true;
@@ -16,7 +16,7 @@ buildPythonPackage (finalAttrs: {
owner = "jsenecal";
repo = "netbox-fms";
tag = "v${finalAttrs.version}";
- hash = "sha256-5RPcJFxwQYJWUipHU05gp7zovWPnviWHlkqCHEs16tw=";
+ hash = "sha256-TOSrSY/5nZaLQyPVkwTZ4szz+TK4fpSgWlfJnKtZwkM=";
};
build-system = [ setuptools ];
From c25fee756f669ad75aee1e1be20e8276f6fac9e3 Mon Sep 17 00:00:00 2001
From: "R. Ryantm"
Date: Sat, 26 Sep 2026 13:30:11 +0000
Subject: [PATCH 39/61] perplexity-mcp: 0-unstable-2026-08-27 ->
0-unstable-2026-09-25
---
pkgs/by-name/pe/perplexity-mcp/package.nix | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/pkgs/by-name/pe/perplexity-mcp/package.nix b/pkgs/by-name/pe/perplexity-mcp/package.nix
index c751ed92ac63..ab59279fe9b4 100644
--- a/pkgs/by-name/pe/perplexity-mcp/package.nix
+++ b/pkgs/by-name/pe/perplexity-mcp/package.nix
@@ -7,16 +7,16 @@
buildNpmPackage (finalAttrs: {
pname = "perplexity-mcp";
- version = "0-unstable-2026-08-27";
+ version = "0-unstable-2026-09-25";
src = fetchFromGitHub {
owner = "perplexityai";
repo = "modelcontextprotocol";
- rev = "c73c8561bbc2d9eb666334a53c311b50f4f4cf76";
- hash = "sha256-zOYRSTK5N79l3jAEnPMuBrYDMyD5zm0QKEopqwlV7/E=";
+ rev = "c58e4ad254608952606f09a40934ab6cca65bfad";
+ hash = "sha256-j0DiITMVEw7e6Cw42kW5iPwIdRt//X2a3Dm2S3IXsbU=";
};
- npmDepsHash = "sha256-eKLKHkoXcmk1OdPkgIQjPKBFXEwnV7nKeE98weE25+0=";
+ npmDepsHash = "sha256-wKw19ha7hQrBTM0caEBZazV6qC+VXihV6i0nf8H/u+Q=";
passthru = {
updateScript = nix-update-script {
From 8bfcec0f1e7fe9ce17891026d4700bbebe6f6e3f Mon Sep 17 00:00:00 2001
From: Sergei Trofimovich
Date: Sat, 26 Sep 2026 15:08:42 +0100
Subject: [PATCH 40/61] diffoscope: 329 -> 331
Changes:
- https://diffoscope.org/news/diffoscope-330-released/
- https://diffoscope.org/news/diffoscope-331-released/
---
pkgs/by-name/di/diffoscope/package.nix | 5 ++---
pkgs/by-name/di/diffoscope/radare2.patch | 26 ------------------------
2 files changed, 2 insertions(+), 29 deletions(-)
delete mode 100644 pkgs/by-name/di/diffoscope/radare2.patch
diff --git a/pkgs/by-name/di/diffoscope/package.nix b/pkgs/by-name/di/diffoscope/package.nix
index 2263f209d1c4..69289fed16b0 100644
--- a/pkgs/by-name/di/diffoscope/package.nix
+++ b/pkgs/by-name/di/diffoscope/package.nix
@@ -112,12 +112,12 @@ in
# Note: when upgrading this package, please run the list-missing-tools.sh script as described below!
python.pkgs.buildPythonApplication rec {
pname = "diffoscope";
- version = "329";
+ version = "331";
pyproject = true;
src = fetchurl {
url = "https://diffoscope.org/archive/diffoscope-${version}.tar.bz2";
- hash = "sha256-UPe+Mko9r4qoSTPbDurF64aZgmPLizV8iK2UlCfyfxk=";
+ hash = "sha256-x1Sc1S3PER3m1+maUZjDofoGqiOoYIm2Oso7Q5NKNtw=";
};
outputs = [
@@ -128,7 +128,6 @@ python.pkgs.buildPythonApplication rec {
patches = [
./androguard-4.1.4.patch
./ignore_links.patch
- ./radare2.patch
];
postPatch = ''
diff --git a/pkgs/by-name/di/diffoscope/radare2.patch b/pkgs/by-name/di/diffoscope/radare2.patch
deleted file mode 100644
index 0a51f4354a4e..000000000000
--- a/pkgs/by-name/di/diffoscope/radare2.patch
+++ /dev/null
@@ -1,26 +0,0 @@
-Fix comparing ELF objects when r2 is in PATH
-
-https://github.com/radareorg/radare2/issues/21201 renamed the "offset" key of
-the json output diffoscope uses to "addr". As a result running diffoscope on an
-ELF object results in this error:
-KeyError: 'offset'
-
-This patch does not include the modifications to the test suite required to
-submit it upstream.
-
-Upstream issue: https://salsa.debian.org/reproducible-builds/diffoscope/-/work_items/432
-
-diff --git a/diffoscope/comparators/decompile.py b/diffoscope/comparators/decompile.py
-index bf85deb9..f6a5564f 100644
---- a/diffoscope/comparators/decompile.py
-+++ b/diffoscope/comparators/decompile.py
-@@ -242,6 +242,9 @@ class AsmFunction(File):
-
- @property
- def offset(self):
-+ if "addr" in self.data_dict:
-+ return self.data_dict["addr"]
-+ # backward compat with r2 version < 5.9.0
- return self.data_dict["offset"]
-
- @property
From 3e58a13a910877703d6b7b043363f32449c92b8b Mon Sep 17 00:00:00 2001
From: Martin Weinelt
Date: Sat, 8 Aug 2026 23:24:08 +0200
Subject: [PATCH 41/61] python3Packages.django_6: 6.0.8 -> 6.1.1
https://docs.djangoproject.com/en/6.1/releases/6.1/
https://docs.djangoproject.com/en/6.1/releases/6.1.1/
https://www.djangoproject.com/weblog/2026/aug/05/django-61-released/
Splits off 6.0.x as django_6_0 for continued package compatibility.
---
.../django/6.0/skip-flaky-tests.patch | 12 ++
pkgs/development/python-modules/django/6.nix | 6 +-
.../django/6.x/skip-flaky-tests.patch | 10 +-
.../development/python-modules/django/6_0.nix | 147 ++++++++++++++++++
pkgs/top-level/python-packages.nix | 2 +
5 files changed, 168 insertions(+), 9 deletions(-)
create mode 100644 pkgs/development/python-modules/django/6.0/skip-flaky-tests.patch
create mode 100644 pkgs/development/python-modules/django/6_0.nix
diff --git a/pkgs/development/python-modules/django/6.0/skip-flaky-tests.patch b/pkgs/development/python-modules/django/6.0/skip-flaky-tests.patch
new file mode 100644
index 000000000000..e9f3dda965be
--- /dev/null
+++ b/pkgs/development/python-modules/django/6.0/skip-flaky-tests.patch
@@ -0,0 +1,12 @@
+diff --git a/tests/serializers/test_deserialization.py b/tests/serializers/test_deserialization.py
+index a718a99038..8c9296e1a7 100644
+--- a/tests/serializers/test_deserialization.py
++++ b/tests/serializers/test_deserialization.py
+@@ -138,6 +138,7 @@ class TestDeserializer(SimpleTestCase):
+ self.assertEqual(first_item.object, self.jane)
+ self.assertEqual(second_item.object, self.joe)
+
++ @unittest.skip("flaky")
+ def test_crafted_xml_performance(self):
+ """The time to process invalid inputs is not quadratic."""
+
diff --git a/pkgs/development/python-modules/django/6.nix b/pkgs/development/python-modules/django/6.nix
index bf4f64be7887..1bf6ff170394 100644
--- a/pkgs/development/python-modules/django/6.nix
+++ b/pkgs/development/python-modules/django/6.nix
@@ -42,7 +42,7 @@
buildPythonPackage (finalAttrs: {
pname = "django";
- version = "6.0.8";
+ version = "6.1.1";
pyproject = true;
disabled = pythonOlder "3.12";
@@ -51,7 +51,7 @@ buildPythonPackage (finalAttrs: {
owner = "django";
repo = "django";
tag = finalAttrs.version;
- hash = "sha256-hQQMKa8YirrTAoCrW1nn3RqRXv0szLgeSOjeKxBfiSo=";
+ hash = "sha256-jOshsS3ceWEJoxOuyUSEJvIPE5LLMrzMXEhVgX6wDPQ=";
};
patches = [
@@ -62,8 +62,6 @@ buildPythonPackage (finalAttrs: {
./6.x/pythonpath.patch
# test_incorrect_timezone should raise but doesn't
./6.x/disable-failing-test.patch
- # some perf tests are often flaky under pressure
- ./6.x/skip-flaky-tests.patch
# https://code.djangoproject.com/ticket/36997
# https://github.com/django/django/pull/21019
./6.x/invalidate-importlib-cache.patch
diff --git a/pkgs/development/python-modules/django/6.x/skip-flaky-tests.patch b/pkgs/development/python-modules/django/6.x/skip-flaky-tests.patch
index e9f3dda965be..7753f904a445 100644
--- a/pkgs/development/python-modules/django/6.x/skip-flaky-tests.patch
+++ b/pkgs/development/python-modules/django/6.x/skip-flaky-tests.patch
@@ -1,12 +1,12 @@
diff --git a/tests/serializers/test_deserialization.py b/tests/serializers/test_deserialization.py
-index a718a99038..8c9296e1a7 100644
+index f4be93957a..a4556134af 100644
--- a/tests/serializers/test_deserialization.py
+++ b/tests/serializers/test_deserialization.py
-@@ -138,6 +138,7 @@ class TestDeserializer(SimpleTestCase):
+@@ -137,6 +137,7 @@ class TestDeserializer(SimpleTestCase):
self.assertEqual(first_item.object, self.jane)
self.assertEqual(second_item.object, self.joe)
+ @unittest.skip("flaky")
- def test_crafted_xml_performance(self):
- """The time to process invalid inputs is not quadratic."""
-
+ def test_crafted_xml_rejected(self):
+ depth = 100
+ leaf_text_len = 1000
diff --git a/pkgs/development/python-modules/django/6_0.nix b/pkgs/development/python-modules/django/6_0.nix
new file mode 100644
index 000000000000..9c28d53b96f1
--- /dev/null
+++ b/pkgs/development/python-modules/django/6_0.nix
@@ -0,0 +1,147 @@
+{
+ lib,
+ stdenv,
+ buildPythonPackage,
+ fetchFromGitHub,
+ pythonOlder,
+ replaceVars,
+
+ # build-system
+ setuptools,
+
+ # patched in
+ geos,
+ gdal,
+ withGdal ? false,
+
+ # dependencies
+ asgiref,
+ sqlparse,
+
+ # optional-dependencies
+ argon2-cffi,
+ bcrypt,
+
+ # tests
+ aiosmtpd,
+ docutils,
+ geoip2,
+ jinja2,
+ numpy,
+ pillow,
+ pylibmc,
+ pymemcache,
+ python,
+ pyyaml,
+ pytz,
+ redis,
+ selenium,
+ tblib,
+ tzdata,
+}:
+
+buildPythonPackage (finalAttrs: {
+ pname = "django";
+ version = "6.0.8";
+ pyproject = true;
+
+ disabled = pythonOlder "3.12";
+
+ src = fetchFromGitHub {
+ owner = "django";
+ repo = "django";
+ tag = finalAttrs.version;
+ hash = "sha256-hQQMKa8YirrTAoCrW1nn3RqRXv0szLgeSOjeKxBfiSo=";
+ };
+
+ patches = [
+ (replaceVars ./6.x/zoneinfo.patch {
+ zoneinfo = tzdata + "/share/zoneinfo";
+ })
+ # prevent tests from messing with our pythonpath
+ ./6.x/pythonpath.patch
+ # test_incorrect_timezone should raise but doesn't
+ ./6.x/disable-failing-test.patch
+ # some perf tests are often flaky under pressure
+ ./6.0/skip-flaky-tests.patch
+ # https://code.djangoproject.com/ticket/36997
+ # https://github.com/django/django/pull/21019
+ ./6.x/invalidate-importlib-cache.patch
+ ]
+ ++ lib.optionals withGdal [
+ (replaceVars ./6.x/gdal.patch {
+ geos = geos;
+ gdal = gdal;
+ extension = stdenv.hostPlatform.extensions.sharedLibrary;
+ })
+ ];
+
+ postPatch = ''
+ substituteInPlace tests/utils_tests/test_autoreload.py \
+ --replace-fail "/usr/bin/python" "${python.interpreter}"
+ '';
+
+ build-system = [ setuptools ];
+
+ dependencies = [
+ asgiref
+ sqlparse
+ ];
+
+ optional-dependencies = {
+ argon2 = [ argon2-cffi ];
+ bcrypt = [ bcrypt ];
+ };
+
+ nativeCheckInputs = [
+ # tests/requirements/py3.txt
+ aiosmtpd
+ docutils
+ geoip2
+ jinja2
+ numpy
+ pillow
+ pylibmc
+ pymemcache
+ pyyaml
+ pytz
+ redis
+ selenium
+ tblib
+ tzdata
+ ]
+ ++ lib.concatAttrValues finalAttrs.passthru.optional-dependencies;
+
+ preCheck = ''
+ # make sure the installed library gets imported
+ rm -rf django
+
+ # fails to import github_links from docs/_ext/github_links.py
+ rm tests/sphinx/test_github_links.py
+
+ # provide timezone data, works only on linux
+ export TZDIR=${tzdata}/${python.sitePackages}/tzdata/zoneinfo
+
+ export PYTHONPATH=$PWD/docs/_ext:$PYTHONPATH
+ '';
+
+ checkPhase = ''
+ runHook preCheck
+
+ pushd tests
+ ${python.interpreter} runtests.py --settings=test_sqlite --parallel=$NIX_BUILD_CORES
+ popd
+
+ runHook postCheck
+ '';
+
+ __darwinAllowLocalNetworking = true;
+
+ meta = with lib; {
+ changelog = "https://docs.djangoproject.com/en/${lib.versions.majorMinor finalAttrs.version}/releases/${finalAttrs.version}/";
+ description = "High-level Python Web framework that encourages rapid development and clean, pragmatic design";
+ homepage = "https://www.djangoproject.com";
+ license = licenses.bsd3;
+ maintainers = with maintainers; [ hexa ];
+ };
+})
diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix
index f26aea5146bf..6ab9d797b1bf 100644
--- a/pkgs/top-level/python-packages.nix
+++ b/pkgs/top-level/python-packages.nix
@@ -4956,6 +4956,8 @@ self: super: with self; {
django_6 = callPackage ../development/python-modules/django/6.nix { };
+ django_6_0 = callPackage ../development/python-modules/django/6_0.nix { };
+
djangocms-admin-style = callPackage ../development/python-modules/djangocms-admin-style { };
djangocms-alias = callPackage ../development/python-modules/djangocms-alias { };
From 1413f638ec2aa33f35726ee458661c9692eb3403 Mon Sep 17 00:00:00 2001
From: Martin Weinelt
Date: Fri, 25 Sep 2026 23:26:14 +0200
Subject: [PATCH 42/61] python3Packages.djangorestframework_3_17: init at
3.17.1
---
.../djangorestframework/3_17.nix | 78 +++++++++++++++++++
pkgs/top-level/python-packages.nix | 4 +
2 files changed, 82 insertions(+)
create mode 100644 pkgs/development/python-modules/djangorestframework/3_17.nix
diff --git a/pkgs/development/python-modules/djangorestframework/3_17.nix b/pkgs/development/python-modules/djangorestframework/3_17.nix
new file mode 100644
index 000000000000..b915ae89d2f9
--- /dev/null
+++ b/pkgs/development/python-modules/djangorestframework/3_17.nix
@@ -0,0 +1,78 @@
+{
+ lib,
+ buildPythonPackage,
+ fetchFromGitHub,
+ pythonOlder,
+
+ # build-system
+ setuptools,
+
+ # dependencies
+ django,
+
+ # optional-dependencies
+ coreapi,
+ coreschema,
+ django-guardian,
+ inflection,
+ psycopg2,
+ pygments,
+ pyyaml,
+
+ # tests
+ pytestCheckHook,
+ pytest-django,
+ pytz,
+}:
+
+buildPythonPackage (finalAttrs: {
+ pname = "djangorestframework";
+ version = "3.17.1";
+ pyproject = true;
+
+ src = fetchFromGitHub {
+ owner = "encode";
+ repo = "django-rest-framework";
+ tag = finalAttrs.version;
+ hash = "sha256-hDAtICtVFeEXRgR5Shb0IdVlLkpf/TBDWw+2cOLJTfw=";
+ };
+
+ build-system = [ setuptools ];
+
+ dependencies = [
+ django
+ ];
+
+ optional-dependencies = {
+ complete = [
+ coreapi
+ coreschema
+ django-guardian
+ inflection
+ psycopg2
+ pygments
+ pyyaml
+ ];
+ };
+
+ nativeCheckInputs = [
+ pytest-django
+ pytestCheckHook
+ pytz
+ ]
+ ++ finalAttrs.passthru.optional-dependencies.complete;
+
+ disabledTests = [
+ # https://github.com/encode/django-rest-framework/issues/9422
+ "test_urlpatterns"
+ ];
+
+ pythonImportsCheck = [ "rest_framework" ];
+
+ meta = {
+ changelog = "https://github.com/encode/django-rest-framework/releases/tag/${finalAttrs.src.tag}";
+ description = "Web APIs for Django, made easy";
+ homepage = "https://www.django-rest-framework.org/";
+ license = lib.licenses.bsd2;
+ };
+})
diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix
index 6ab9d797b1bf..d61c14f995ef 100644
--- a/pkgs/top-level/python-packages.nix
+++ b/pkgs/top-level/python-packages.nix
@@ -4998,6 +4998,10 @@ self: super: with self; {
djangorestframework-stubs = callPackage ../development/python-modules/djangorestframework-stubs { };
+ djangorestframework_3_17 =
+ callPackage ../development/python-modules/djangorestframework/3_17.nix
+ { };
+
djangosaml2 = callPackage ../development/python-modules/djangosaml2 { };
djmail = callPackage ../development/python-modules/djmail { };
From dcaf625d88e133c47bb78d646e020e7fa2291f61 Mon Sep 17 00:00:00 2001
From: Martin Weinelt
Date: Sat, 26 Sep 2026 01:37:31 +0200
Subject: [PATCH 43/61] python3Packages.django-ninja: 1.6.2 -> 1.7.1
https://github.com/vitalik/django-ninja/releases/tag/v1.6.3
https://github.com/vitalik/django-ninja/releases/tag/v1.7.0
https://github.com/vitalik/django-ninja/releases/tag/v1.7.1
---
pkgs/development/python-modules/django-ninja/default.nix | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/pkgs/development/python-modules/django-ninja/default.nix b/pkgs/development/python-modules/django-ninja/default.nix
index 54c1be0159ff..13caa6338943 100644
--- a/pkgs/development/python-modules/django-ninja/default.nix
+++ b/pkgs/development/python-modules/django-ninja/default.nix
@@ -13,14 +13,14 @@
buildPythonPackage rec {
pname = "django-ninja";
- version = "1.6.2";
+ version = "1.7.1";
pyproject = true;
src = fetchFromGitHub {
owner = "vitalik";
repo = "django-ninja";
tag = "v${version}";
- hash = "sha256-nnGIhNGnK7q0nbw7EYJP+xCeS1uiuTrhQxf49dA+Sc8=";
+ hash = "sha256-/KsFq6LgaRMxMHmWO5vuzeVZTsmnERTbuS2ne4jc6eA=";
};
build-system = [ flit-core ];
From ec860401bb61acfece186cfcbd6c8aad2acdf980 Mon Sep 17 00:00:00 2001
From: Martin Weinelt
Date: Sat, 8 Aug 2026 23:36:49 +0200
Subject: [PATCH 44/61] python3Packages.djangorestframework: 3.17.1 -> 3.18.1
https://github.com/encode/django-rest-framework/releases/tag/3.18.0
https://github.com/encode/django-rest-framework/releases/tag/3.18.1
---
.../python-modules/djangorestframework/default.nix | 12 ++++--------
1 file changed, 4 insertions(+), 8 deletions(-)
diff --git a/pkgs/development/python-modules/djangorestframework/default.nix b/pkgs/development/python-modules/djangorestframework/default.nix
index b915ae89d2f9..32cc7104d79c 100644
--- a/pkgs/development/python-modules/djangorestframework/default.nix
+++ b/pkgs/development/python-modules/djangorestframework/default.nix
@@ -2,7 +2,6 @@
lib,
buildPythonPackage,
fetchFromGitHub,
- pythonOlder,
# build-system
setuptools,
@@ -20,6 +19,7 @@
pyyaml,
# tests
+ dj-database-url,
pytestCheckHook,
pytest-django,
pytz,
@@ -27,14 +27,14 @@
buildPythonPackage (finalAttrs: {
pname = "djangorestframework";
- version = "3.17.1";
+ version = "3.18.1";
pyproject = true;
src = fetchFromGitHub {
owner = "encode";
repo = "django-rest-framework";
tag = finalAttrs.version;
- hash = "sha256-hDAtICtVFeEXRgR5Shb0IdVlLkpf/TBDWw+2cOLJTfw=";
+ hash = "sha256-ZOzGJOIyN6X7NxplIDUeII87IlsXViNLPeW7f4/vIfY=";
};
build-system = [ setuptools ];
@@ -56,17 +56,13 @@ buildPythonPackage (finalAttrs: {
};
nativeCheckInputs = [
+ dj-database-url
pytest-django
pytestCheckHook
pytz
]
++ finalAttrs.passthru.optional-dependencies.complete;
- disabledTests = [
- # https://github.com/encode/django-rest-framework/issues/9422
- "test_urlpatterns"
- ];
-
pythonImportsCheck = [ "rest_framework" ];
meta = {
From f94549214574b870186113d09389a6de8ddbb4f7 Mon Sep 17 00:00:00 2001
From: Martin Weinelt
Date: Sun, 9 Aug 2026 00:26:02 +0200
Subject: [PATCH 45/61] python3Packages.django-formtools: disable failing test
---
.../python-modules/django-formtools/default.nix | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/pkgs/development/python-modules/django-formtools/default.nix b/pkgs/development/python-modules/django-formtools/default.nix
index a5e1c9ad8304..653ec7e7fc6e 100644
--- a/pkgs/development/python-modules/django-formtools/default.nix
+++ b/pkgs/development/python-modules/django-formtools/default.nix
@@ -40,9 +40,10 @@ buildPythonPackage (finalAttrs: {
disabledTests = [
# mismatch between test collection of django and pytest-django
"TestStorage"
- # Django 6.0.6/5.2.15 compat issue
- # https://github.com/jazzband/django-formtools/issues/298
- "test_reset_cookie"
+ ]
+ ++ lib.optionals (lib.versionAtLeast django.version "6.1") [
+ # https://github.com/jazzband/django-formtools/issues/303
+ "test_manipulated_cookie"
];
pythonImportsCheck = [ "formtools" ];
From d93afa1b7628c5b421e7b28ce678c82f80a3b9c7 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Sandro=20J=C3=A4ckel?=
Date: Sun, 23 Aug 2026 11:08:41 +0200
Subject: [PATCH 46/61] python3Packages.django-async-backend: 6.0.7 -> 6.1.2
Somehow pytest-django is not running migration and causing some test failures.
The package can be build with glitchtip.python.pkgs.django-async-backend
Diff: https://github.com/Arfey/django-async-backend/compare/v6.0.7...v6.1.2
Changelog: https://github.com/Arfey/django-async-backend/releases/tag/v6.0.8
Changelog: https://github.com/Arfey/django-async-backend/releases/tag/v6.0.9
Changelog: https://github.com/Arfey/django-async-backend/releases/tag/v6.1.0
Changelog: https://github.com/Arfey/django-async-backend/releases/tag/v6.1.1
Changelog: https://github.com/Arfey/django-async-backend/releases/tag/v6.1.2
---
.../django-async-backend/default.nix | 21 +++++++++++--------
1 file changed, 12 insertions(+), 9 deletions(-)
diff --git a/pkgs/development/python-modules/django-async-backend/default.nix b/pkgs/development/python-modules/django-async-backend/default.nix
index 404ecff96939..63d8fd4ee26f 100644
--- a/pkgs/development/python-modules/django-async-backend/default.nix
+++ b/pkgs/development/python-modules/django-async-backend/default.nix
@@ -3,6 +3,7 @@
buildPythonPackage,
django,
fetchFromGitHub,
+ libcst,
poetry-core,
postgresql,
postgresqlTestHook,
@@ -14,14 +15,14 @@
buildPythonPackage rec {
pname = "django-async-backend";
- version = "6.0.7";
+ version = "6.1.2";
pyproject = true;
src = fetchFromGitHub {
owner = "Arfey";
repo = "django-async-backend";
tag = "v${version}";
- hash = "sha256-4zaXPfHIE9RwkSbHPt1DHFInn8LP+JXiBiMJYkZeR6M=";
+ hash = "sha256-pfcqTtyV37bZFSZaRcFIt9cgR8XZ7PDijVC18lMziRU=";
};
postPatch = ''
@@ -47,24 +48,26 @@ buildPythonPackage rec {
PGUSER = "postgres";
};
- preCheck = ''
- export PYTHONPATH=$PYTHONPATH:$PWD/tests
+ checkPhase = ''
+ runHook preCheck
+
+ cd tests/
+ python manage.py test
+
+ runHook postCheck
'';
nativeCheckInputs = [
django # must come first as vtasks only works with django 6
+ libcst
postgresql
postgresqlTestHook
psycopg-pool
- pytest-django
- pytestCheckHook
];
- pytestFlags = [ "./tests" ];
-
meta = {
- description = "Django extension providing async capabilities for database and other components";
+ description = "True async Django ORM and PostgreSQL backend with connection pooling and async transactions";
homepage = "https://github.com/Arfey/django-async-backend";
changelog = "https://github.com/Arfey/django-async-backend/releases/tag/${src.tag}";
license = lib.licenses.asl20;
From 377a2ea04b4b32cace40bacf69a30b109cdd0415 Mon Sep 17 00:00:00 2001
From: Minijackson
Date: Tue, 15 Sep 2026 09:02:36 +0200
Subject: [PATCH 47/61] python3Packages.strawberry-graphql-django: remove
django-mptt dependency
It doesn't seems used anymore
---
.../python-modules/strawberry-graphql-django/default.nix | 2 --
1 file changed, 2 deletions(-)
diff --git a/pkgs/development/python-modules/strawberry-graphql-django/default.nix b/pkgs/development/python-modules/strawberry-graphql-django/default.nix
index 305a82c01bd8..b5ffc13b5fc8 100644
--- a/pkgs/development/python-modules/strawberry-graphql-django/default.nix
+++ b/pkgs/development/python-modules/strawberry-graphql-django/default.nix
@@ -20,7 +20,6 @@
pytestCheckHook,
django-guardian,
django-model-utils,
- django-mptt,
django-polymorphic,
django-tree-queries,
factory-boy,
@@ -74,7 +73,6 @@ buildPythonPackage rec {
django-guardian
django-model-utils
- django-mptt
django-polymorphic
django-tree-queries
factory-boy
From c34b588fd5648ff6999235543d102de476a087fd Mon Sep 17 00:00:00 2001
From: Minijackson
Date: Tue, 15 Sep 2026 09:03:04 +0200
Subject: [PATCH 48/61] python3Packages.django-guardian: 3.3.3 -> 3.5.0
Upgrade past 3.4.0 required to for Django 6.1.
https://github.com/django-guardian/django-guardian/releases/tag/3.3.4
https://github.com/django-guardian/django-guardian/releases/tag/3.4.0
https://github.com/django-guardian/django-guardian/releases/tag/3.4.1
https://github.com/django-guardian/django-guardian/releases/tag/3.5.0
---
pkgs/development/python-modules/django-guardian/default.nix | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/pkgs/development/python-modules/django-guardian/default.nix b/pkgs/development/python-modules/django-guardian/default.nix
index 3103f6f116a1..f94b38ccb680 100644
--- a/pkgs/development/python-modules/django-guardian/default.nix
+++ b/pkgs/development/python-modules/django-guardian/default.nix
@@ -12,14 +12,14 @@
buildPythonPackage (finalAttrs: {
pname = "django-guardian";
- version = "3.3.3";
+ version = "3.5.0";
pyproject = true;
src = fetchFromGitHub {
owner = "django-guardian";
repo = "django-guardian";
tag = finalAttrs.version;
- hash = "sha256-0zUdcDeJ40AuYSzhjy3/htU43cy6T54rZOj2zFo6J+8=";
+ hash = "sha256-viqICF6zfJxAj1jEYtBXCR2NbUR26Q8SeKVFTMVzisQ=";
};
build-system = [ setuptools ];
From d0001b3f9eff2956bba6c74c4d49b18b85f03b20 Mon Sep 17 00:00:00 2001
From: Minijackson
Date: Tue, 15 Sep 2026 09:03:38 +0200
Subject: [PATCH 49/61] python3Packages.django-debug-toolbar: 7.0.0 -> 8.0.0
Needed to upgrade to Django 6.1
---
.../python-modules/django-debug-toolbar/default.nix | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/pkgs/development/python-modules/django-debug-toolbar/default.nix b/pkgs/development/python-modules/django-debug-toolbar/default.nix
index 8137ea09057f..b9e76e9d78d1 100644
--- a/pkgs/development/python-modules/django-debug-toolbar/default.nix
+++ b/pkgs/development/python-modules/django-debug-toolbar/default.nix
@@ -19,14 +19,14 @@
buildPythonPackage rec {
pname = "django-debug-toolbar";
- version = "7.0.0";
+ version = "8.0.0";
pyproject = true;
src = fetchFromGitHub {
owner = "jazzband";
repo = "django-debug-toolbar";
tag = version;
- hash = "sha256-Xwl6LsNW3/VXJ59QaW4l6D+8VEbl45ysv5KaySbS4M4=";
+ hash = "sha256-OwMul+wGKLU9LwybsCtqV51lp/CQvexP0TWJSg8E3iQ=";
};
postPatch = ''
From 1c0e708fef84c8e8114e1f0197f7ebf0e7eacded Mon Sep 17 00:00:00 2001
From: Minijackson
Date: Tue, 15 Sep 2026 09:03:58 +0200
Subject: [PATCH 50/61] python3Packages.django-mptt: disable tests when using
Django 6
The tests seem to only fail due to HTML differences.
---
pkgs/development/python-modules/django-mptt/default.nix | 3 +++
1 file changed, 3 insertions(+)
diff --git a/pkgs/development/python-modules/django-mptt/default.nix b/pkgs/development/python-modules/django-mptt/default.nix
index 50cda6412332..e2f03a59e8f4 100644
--- a/pkgs/development/python-modules/django-mptt/default.nix
+++ b/pkgs/development/python-modules/django-mptt/default.nix
@@ -37,6 +37,9 @@ buildPythonPackage rec {
pytest-django
];
+ # XXX: some HTML tests fail with Django 6.1+
+ doCheck = lib.versionOlder django.version "6.1";
+
preCheck = ''
export DJANGO_SETTINGS_MODULE=tests.settings
export PYTHONPATH=$(pwd)/tests:$PYTHONPATH
From 5a39c8bdf1cdafb311c18218a84fa6de31191fe8 Mon Sep 17 00:00:00 2001
From: Martin Weinelt
Date: Sat, 26 Sep 2026 12:28:06 +0200
Subject: [PATCH 51/61] python3Packages.drf-spectacular: update test setup
---
pkgs/development/python-modules/drf-spectacular/default.nix | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/pkgs/development/python-modules/drf-spectacular/default.nix b/pkgs/development/python-modules/drf-spectacular/default.nix
index 3afbf1cc7263..b9378cf2fc69 100644
--- a/pkgs/development/python-modules/drf-spectacular/default.nix
+++ b/pkgs/development/python-modules/drf-spectacular/default.nix
@@ -8,6 +8,7 @@
django-oauth-toolkit,
django-polymorphic,
django-rest-auth,
+ django-rest-knox,
django-rest-polymorphic,
djangorestframework,
djangorestframework-camel-case,
@@ -60,6 +61,7 @@ buildPythonPackage rec {
django-oauth-toolkit
django-polymorphic
django-rest-auth
+ django-rest-knox
django-rest-polymorphic
djangorestframework-camel-case
djangorestframework-dataclasses
@@ -77,8 +79,6 @@ buildPythonPackage rec {
disabledTestPaths = [
# django-oauth-toolkit 3.4.1 added a new error that the example application has
"tests/test_command.py::test_command_check"
- # django-rest-knox is not packaged
- "tests/contrib/test_knox_auth_token.py"
# Outdated test artifact
"tests/contrib/test_pydantic.py"
# Test requires django with gdal
From 68550897064df95f051c224b8f889b38d3303d93 Mon Sep 17 00:00:00 2001
From: Martin Weinelt
Date: Sat, 26 Sep 2026 13:50:18 +0200
Subject: [PATCH 52/61] python3Packages.drf-spectacular: disable failing tests
---
pkgs/development/python-modules/drf-spectacular/default.nix | 3 +++
1 file changed, 3 insertions(+)
diff --git a/pkgs/development/python-modules/drf-spectacular/default.nix b/pkgs/development/python-modules/drf-spectacular/default.nix
index b9378cf2fc69..60c49e8182a2 100644
--- a/pkgs/development/python-modules/drf-spectacular/default.nix
+++ b/pkgs/development/python-modules/drf-spectacular/default.nix
@@ -83,6 +83,9 @@ buildPythonPackage rec {
"tests/contrib/test_pydantic.py"
# Test requires django with gdal
"tests/contrib/test_rest_framework_gis.py"
+ # OpenAPI schema failure with DRF 3.18.x
+ "tests/test_fields.py::test_fields"
+ "tests/test_fields.py::test_fields_oas_3_1"
];
pythonImportsCheck = [ "drf_spectacular" ];
From be25580448474463a930a6c7a3f378a18b92ff9c Mon Sep 17 00:00:00 2001
From: Martin Weinelt
Date: Sat, 26 Sep 2026 13:56:36 +0200
Subject: [PATCH 53/61] pretalx: pin django 6.0
---
pkgs/by-name/pr/pretalx/package.nix | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/pkgs/by-name/pr/pretalx/package.nix b/pkgs/by-name/pr/pretalx/package.nix
index 8edf195f9177..269d88566812 100644
--- a/pkgs/by-name/pr/pretalx/package.nix
+++ b/pkgs/by-name/pr/pretalx/package.nix
@@ -14,7 +14,7 @@ let
python = python314.override {
self = python;
packageOverrides = final: prev: {
- django = prev.django_6;
+ django = prev.django_6_0;
django-hierarkey = prev.django-hierarkey.overrideAttrs (oldAttrs: {
version = "2.0.1";
From 9eb52abbb0ae0deccacacbc992b533339ecc1f00 Mon Sep 17 00:00:00 2001
From: Martin Weinelt
Date: Sat, 26 Sep 2026 14:05:04 +0200
Subject: [PATCH 54/61] pretix: pin drf at 3.17.x
---
pkgs/by-name/pr/pretix/package.nix | 1 +
1 file changed, 1 insertion(+)
diff --git a/pkgs/by-name/pr/pretix/package.nix b/pkgs/by-name/pr/pretix/package.nix
index 117a5e877b7c..9bc17d212b33 100644
--- a/pkgs/by-name/pr/pretix/package.nix
+++ b/pkgs/by-name/pr/pretix/package.nix
@@ -19,6 +19,7 @@ let
packageOverrides = self: super: {
chardet = super.chardet_5;
django = super.django_5;
+ djangorestframework = super.djangorestframework_3_17;
django-oauth-toolkit = super.django-oauth-toolkit.overridePythonAttrs (oldAttrs: rec {
version = "2.3.0";
From 67c2b1206a20843fe6833b707dfed9eacda41e3f Mon Sep 17 00:00:00 2001
From: Martin Weinelt
Date: Sat, 26 Sep 2026 14:19:58 +0200
Subject: [PATCH 55/61] paperless-ngx: relax django-guardian constraint
---
pkgs/by-name/pa/paperless-ngx/package.nix | 1 +
1 file changed, 1 insertion(+)
diff --git a/pkgs/by-name/pa/paperless-ngx/package.nix b/pkgs/by-name/pa/paperless-ngx/package.nix
index c7c61af3083a..ff56e114cbfc 100644
--- a/pkgs/by-name/pa/paperless-ngx/package.nix
+++ b/pkgs/by-name/pa/paperless-ngx/package.nix
@@ -96,6 +96,7 @@ pythonPackages.buildPythonApplication (finalAttrs: {
pythonRelaxDeps = [
"django-allauth"
"django-filter"
+ "django-guardian"
"drf-spectacular-sidecar"
"redis"
"regex"
From b91eccd4a31730f5112b7c8c0307ab91de06898e Mon Sep 17 00:00:00 2001
From: Martin Weinelt
Date: Sat, 26 Sep 2026 16:31:39 +0200
Subject: [PATCH 56/61] weblate: pin django at 6.0.x
---
pkgs/by-name/we/weblate/package.nix | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/pkgs/by-name/we/weblate/package.nix b/pkgs/by-name/we/weblate/package.nix
index fd826bca0ec9..4c4efe191349 100644
--- a/pkgs/by-name/we/weblate/package.nix
+++ b/pkgs/by-name/we/weblate/package.nix
@@ -28,7 +28,7 @@ let
python = python3.override {
self = python;
packageOverrides = _final: prev: {
- django = prev.django_6;
+ django = prev.django_6_0;
};
};
python3Packages = python.pkgs;
From 9d6614ba99bab322b0272f001403ea179df286e4 Mon Sep 17 00:00:00 2001
From: Martin Weinelt
Date: Sat, 26 Sep 2026 16:58:52 +0200
Subject: [PATCH 57/61] python3Packages.django*: add cpe and purl identifiers
---
pkgs/development/python-modules/django/5.nix | 22 ++++++++++++++-----
pkgs/development/python-modules/django/6.nix | 12 ++++++++++
.../development/python-modules/django/6_0.nix | 12 ++++++++++
3 files changed, 41 insertions(+), 5 deletions(-)
diff --git a/pkgs/development/python-modules/django/5.nix b/pkgs/development/python-modules/django/5.nix
index d9ec648838c7..8d37a45947ac 100644
--- a/pkgs/development/python-modules/django/5.nix
+++ b/pkgs/development/python-modules/django/5.nix
@@ -39,7 +39,7 @@
tzdata,
}:
-buildPythonPackage rec {
+buildPythonPackage (finalAttrs: {
pname = "django";
version = "5.2.17";
pyproject = true;
@@ -47,7 +47,7 @@ buildPythonPackage rec {
src = fetchFromGitHub {
owner = "django";
repo = "django";
- tag = version;
+ tag = finalAttrs.version;
hash = "sha256-7it3opzsiN/hHhpipZz4ogmRKGz7E9/LmTF03/UYIB0=";
};
@@ -102,7 +102,7 @@ buildPythonPackage rec {
tblib
tzdata
]
- ++ lib.concatAttrValues optional-dependencies;
+ ++ lib.concatAttrValues finalAttrs.passthru.optional-dependencies;
preCheck = ''
# make sure the installed library gets imported
@@ -131,10 +131,22 @@ buildPythonPackage rec {
__darwinAllowLocalNetworking = true;
meta = {
- changelog = "https://docs.djangoproject.com/en/${lib.versions.majorMinor version}/releases/${version}/";
+ changelog = "https://docs.djangoproject.com/en/${lib.versions.majorMinor finalAttrs.version}/releases/${finalAttrs.version}/";
description = "High-level Python Web framework that encourages rapid development and clean, pragmatic design";
homepage = "https://www.djangoproject.com";
+ identifiers = {
+ cpeParts = {
+ inherit (finalAttrs) version;
+ product = "django";
+ update = "*";
+ vendor = "djangoproject";
+ };
+ purlParts = {
+ type = "pypi";
+ spec = "django@${finalAttrs.version}";
+ };
+ };
license = lib.licenses.bsd3;
maintainers = with lib.maintainers; [ hexa ];
};
-}
+})
diff --git a/pkgs/development/python-modules/django/6.nix b/pkgs/development/python-modules/django/6.nix
index 1bf6ff170394..472c5d7fa3ff 100644
--- a/pkgs/development/python-modules/django/6.nix
+++ b/pkgs/development/python-modules/django/6.nix
@@ -139,6 +139,18 @@ buildPythonPackage (finalAttrs: {
changelog = "https://docs.djangoproject.com/en/${lib.versions.majorMinor finalAttrs.version}/releases/${finalAttrs.version}/";
description = "High-level Python Web framework that encourages rapid development and clean, pragmatic design";
homepage = "https://www.djangoproject.com";
+ identifiers = {
+ cpeParts = {
+ inherit (finalAttrs) version;
+ product = "django";
+ update = "*";
+ vendor = "djangoproject";
+ };
+ purlParts = {
+ type = "pypi";
+ spec = "django@${finalAttrs.version}";
+ };
+ };
license = licenses.bsd3;
maintainers = with maintainers; [ hexa ];
};
diff --git a/pkgs/development/python-modules/django/6_0.nix b/pkgs/development/python-modules/django/6_0.nix
index 9c28d53b96f1..58cd89174997 100644
--- a/pkgs/development/python-modules/django/6_0.nix
+++ b/pkgs/development/python-modules/django/6_0.nix
@@ -141,6 +141,18 @@ buildPythonPackage (finalAttrs: {
changelog = "https://docs.djangoproject.com/en/${lib.versions.majorMinor finalAttrs.version}/releases/${finalAttrs.version}/";
description = "High-level Python Web framework that encourages rapid development and clean, pragmatic design";
homepage = "https://www.djangoproject.com";
+ identifiers = {
+ cpeParts = {
+ inherit (finalAttrs) version;
+ product = "django";
+ update = "*";
+ vendor = "djangoproject";
+ };
+ purlParts = {
+ type = "pypi";
+ spec = "django@${finalAttrs.version}";
+ };
+ };
license = licenses.bsd3;
maintainers = with maintainers; [ hexa ];
};
From 6f02ff318769aa23ce9ffcadf5edd89b1b3dd7d2 Mon Sep 17 00:00:00 2001
From: "R. Ryantm"
Date: Sat, 26 Sep 2026 15:06:09 +0000
Subject: [PATCH 58/61] cargo-binstall: 1.23.0 -> 1.24.0
---
pkgs/by-name/ca/cargo-binstall/package.nix | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/pkgs/by-name/ca/cargo-binstall/package.nix b/pkgs/by-name/ca/cargo-binstall/package.nix
index a52acd8f2b3a..a4123250b5a8 100644
--- a/pkgs/by-name/ca/cargo-binstall/package.nix
+++ b/pkgs/by-name/ca/cargo-binstall/package.nix
@@ -11,16 +11,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cargo-binstall";
- version = "1.23.0";
+ version = "1.24.0";
src = fetchFromGitHub {
owner = "cargo-bins";
repo = "cargo-binstall";
tag = "v${finalAttrs.version}";
- hash = "sha256-Z65k76pcm/j9loXI3KHJi6zSibZY90KJ2aNPycHhp9g=";
+ hash = "sha256-DD4GJXaKr96JD+5pE/RQeaPoB2vj+2J8S8ZlV29J/ZE=";
};
- cargoHash = "sha256-xT4BzFPdQPPGOUsDBLEaM+0yod1+ww6zyi9tkw2cIJk=";
+ cargoHash = "sha256-g4mLtyv2rHavQOJjLnxn+IR+WBvenLP0yamH0xKWzZg=";
nativeBuildInputs = [
pkg-config
From c96e84833638c5176b9558b1d84ff0ca4f358984 Mon Sep 17 00:00:00 2001
From: RTUnreal
Date: Sat, 26 Sep 2026 17:43:28 +0200
Subject: [PATCH 59/61] icu*: add license
---
pkgs/development/libraries/icu/make-icu.nix | 1 +
1 file changed, 1 insertion(+)
diff --git a/pkgs/development/libraries/icu/make-icu.nix b/pkgs/development/libraries/icu/make-icu.nix
index 7dd0310648ea..b5118f833ba1 100644
--- a/pkgs/development/libraries/icu/make-icu.nix
+++ b/pkgs/development/libraries/icu/make-icu.nix
@@ -88,6 +88,7 @@ let
description = "Unicode and globalization support library";
homepage = "https://icu.unicode.org/";
maintainers = with lib.maintainers; [ raskin ];
+ license = lib.licenses.unicode-30;
pkgConfigModules = [
"icu-i18n"
"icu-io"
From 3312dbf41a41ab1cc115e4920eb4cecc4015907a Mon Sep 17 00:00:00 2001
From: Tom Herbers
Date: Fri, 25 Sep 2026 01:19:54 +0200
Subject: [PATCH 60/61] incus-lts: backport 7.5 security fixes
sourced from:
- https://github.com/lxc/incus/pull/4071
- https://github.com/lxc/incus/commits/stable-7.0/?before=f22d8a92dff8e4cf01260ab85405db754bcfc026+35
- https://salsa.debian.org/go-team/packages/incus/-/commit/4992bd88f727414d9f02e9966feb235daf8d755d
- https://salsa.debian.org/go-team/packages/incus/-/commit/bdec650ea4657450a90300c1e25e4d9b5ba71547
---
pkgs/by-name/in/incus/lts.nix | 57 ++++++++++++++++++++++++++++++++++-
1 file changed, 56 insertions(+), 1 deletion(-)
diff --git a/pkgs/by-name/in/incus/lts.nix b/pkgs/by-name/in/incus/lts.nix
index a0185fba0496..db6653351259 100644
--- a/pkgs/by-name/in/incus/lts.nix
+++ b/pkgs/by-name/in/incus/lts.nix
@@ -111,7 +111,62 @@ import ./generic.nix {
url = "https://github.com/lxc/incus/commit/9e188e31e43c21fa8f2a4cac265aa246d4c947f2.patch?full_index=1";
hash = "sha256-KFYKB9PJK/U4/jSe3rmMeR9FWevvvi47BRy055Zj8Io=";
})
-
+ # incus/file: Contain recursive pull symlinks
+ (fetchpatch2 {
+ url = "https://salsa.debian.org/go-team/packages/incus/-/raw/4992bd88f727414d9f02e9966feb235daf8d755d/debian/patches/126-GHSA-wfvq-qh87-gm4j.patch";
+ hash = "sha256-hD7l9/mlUuISLV1hrvuYMyPFYe1XUWnLO15RJyO1ZlA=";
+ })
+ # incusd: Don't follow symlinks when receiving migration
+ (fetchpatch2 {
+ url = "https://github.com/lxc/incus/commit/9afa3d58ef9ffae40eb1980bd33592d00fe1feba.patch?full_index=1";
+ hash = "sha256-SJKrTdR/BKNVPa9P7Yowukfm71D3M9yGh1iGQpkhEDE=";
+ })
+ # incusd/storage: Treat volume creation with a source as a copy (sourced from stable-7.0)
+ (fetchpatch2 {
+ url = "https://github.com/lxc/incus/commit/e59d35263a0e027b4a0344ab8d05c80c622a21e2.patch?full_index=1";
+ hash = "sha256-oHM9IGGjPRwsmc5JAYaBY65HV+H3ZC1/ebqQts/tDow=";
+ })
+ # incusd/storage/drivers: Confine btrfs subvolume paths
+ (fetchpatch2 {
+ url = "https://github.com/lxc/incus/commit/99a8ba3101e91be6cd7013e80ff916f32d495b71.patch?full_index=1";
+ hash = "sha256-iwybe/E8Lucwf6ih6gWt3b/jnG3UGYep2GoqL/h4qn8=";
+ })
+ # incusd/storage: Validate dependent volume names on backup import
+ (fetchpatch2 {
+ url = "https://github.com/lxc/incus/commit/2ef78c71a5f3c9db4a6ad438563ec99497686d83.patch?full_index=1";
+ hash = "sha256-apBgxM15JA+8q/lR5mJRG85rBn+2pEuZdcgOjPn/y8g=";
+ })
+ # incusd/storage: Ignore backup project for dependent
+ (fetchpatch2 {
+ url = "https://github.com/lxc/incus/commit/10d6ea9a7163c2a7b16f9e9ccf0bd45981c3355e.patch?full_index=1";
+ hash = "sha256-5gkMiAb5Ewzsiv9LmZ2oJx+7xTdIbkVnXEkt67metlU=";
+ })
+ # incusd/storage/s3: Require x-amz-* headers to be signed
+ (fetchpatch2 {
+ url = "https://salsa.debian.org/go-team/packages/incus/-/raw/4992bd88f727414d9f02e9966feb235daf8d755d/debian/patches/123-GHSA-mmj7-8rgf-mx2h.patch";
+ hash = "sha256-OHjdOPQ3UyNfucLElKXA4iRYVhOF6fq+m0wUnaYGoiI=";
+ })
+ # incusd/operations: Check project access on operation get and wait
+ # incusd/operations: Hide access token operations from non-admins
+ (fetchpatch2 {
+ url = "https://salsa.debian.org/go-team/packages/incus/-/raw/bdec650ea4657450a90300c1e25e4d9b5ba71547/debian/patches/125-GHSA-mfwv-x733-9446.patch";
+ hash = "sha256-LMx5sb7rC5U9BLsXYhqN3SaW7K/d4q2H1OvcDQPNm7w=";
+ })
+ # incusd/storage/buckets: Require can_edit to read bucket keys
+ (fetchpatch2 {
+ url = "https://github.com/lxc/incus/commit/1eaf9b8bfed2b8cf09182c88fd81b10327605ade.patch?full_index=1";
+ hash = "sha256-KrQtsS8Ug7K5bMeduV9tPeunHOnCXfNNqlbpVMTNzws=";
+ })
+ # incusd/project: Restrict volume options on update and copy
+ (fetchpatch2 {
+ url = "https://github.com/lxc/incus/commit/da36896aa8af65080a79fd1a4b8abcf75d46cbd1.patch?full_index=1";
+ hash = "sha256-+W+2RXtJO/IGd+ejpkylsaNfH8JtSIMTun9bxbtbPxU=";
+ })
+ # incusd/instances: Check project restrictions on clustered refresh
+ (fetchpatch2 {
+ url = "https://github.com/lxc/incus/commit/f22d8a92dff8e4cf01260ab85405db754bcfc026.patch?full_index=1";
+ hash = "sha256-LwQRWQzZewU0QjdaerKFJb4h99RKuTLBZ80PifJONkM=";
+ })
];
lts = true;
nixUpdateExtraArgs = [
From f037615fca373033d0f19b8c886c807b4a323922 Mon Sep 17 00:00:00 2001
From: jopejoe1
Date: Sat, 26 Sep 2026 16:38:47 +0200
Subject: [PATCH 61/61] alac: drop
Is unmaintained and vulnerable
---
pkgs/by-name/al/alac/package.nix | 42 ----------------------
pkgs/by-name/sh/shairport-sync/package.nix | 4 ---
pkgs/top-level/aliases.nix | 1 +
3 files changed, 1 insertion(+), 46 deletions(-)
delete mode 100644 pkgs/by-name/al/alac/package.nix
diff --git a/pkgs/by-name/al/alac/package.nix b/pkgs/by-name/al/alac/package.nix
deleted file mode 100644
index bb2d20b84405..000000000000
--- a/pkgs/by-name/al/alac/package.nix
+++ /dev/null
@@ -1,42 +0,0 @@
-{
- autoreconfHook,
- fetchFromGitHub,
- lib,
- stdenv,
- testers,
- unstableGitUpdater,
-}:
-stdenv.mkDerivation (finalAttrs: {
- pname = "alac";
- version = "0.0.7-unstable-2026-04-10";
-
- outputs = [
- "out"
- "dev"
- ];
-
- src = fetchFromGitHub {
- owner = "mikebrady";
- repo = "alac";
- rev = "5d8c5db0dfcadd5872f28e665cf4f4303447352a";
- hash = "sha256-Wb6I5YHGvBVjVgOutICbRKH96odR3ZgmNS6HQedVahk=";
- };
-
- nativeBuildInputs = [
- autoreconfHook
- ];
-
- passthru = {
- updateScript = unstableGitUpdater { };
- tests.pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage;
- };
-
- meta = {
- description = "Apple Lossless Codec and Utility with Autotools";
- homepage = "https://github.com/mikebrady/alac";
- license = lib.licenses.asl20;
- pkgConfigModules = [ "alac" ];
- platforms = lib.platforms.all;
- maintainers = with lib.maintainers; [ jopejoe1 ];
- };
-})
diff --git a/pkgs/by-name/sh/shairport-sync/package.nix b/pkgs/by-name/sh/shairport-sync/package.nix
index 8c1f9f03eb6d..6451c02c06bc 100644
--- a/pkgs/by-name/sh/shairport-sync/package.nix
+++ b/pkgs/by-name/sh/shairport-sync/package.nix
@@ -26,7 +26,6 @@
nix-update-script,
pipewire,
soxr,
- alac,
sndio,
enableAvahi ? true,
enableAirplay2 ? false,
@@ -44,7 +43,6 @@
enableMqttClient ? true,
enableDbus ? stdenv.hostPlatform.isLinux,
enableSoxr ? true,
- enableAlac ? !enableAirplay2, # airplay2 build uses ffmpeg for alac
enableConvolution ? true,
enableLibdaemon ? false,
enableTinySVCmDNS ? true,
@@ -96,7 +94,6 @@ stdenv.mkDerivation (finalAttrs: {
++ optional enableJack libjack2
++ optional enableSoundio libsoundio
++ optional enableSoxr soxr
- ++ optional enableAlac alac
++ optional enableConvolution libsndfile
++ optionals enableAirplay2 [
libplist
@@ -130,7 +127,6 @@ stdenv.mkDerivation (finalAttrs: {
++ optional enableStdout "--with-stdout"
++ optional enablePipe "--with-pipe"
++ optional enableSoxr "--with-soxr"
- ++ optional enableAlac "--with-apple-alac"
++ optional enableConvolution "--with-convolution"
++ optional enableDbus "--with-dbus-interface"
++ optional enableMetadata "--with-metadata"
diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix
index 1150da98a4da..f5d1e3ca68b5 100644
--- a/pkgs/top-level/aliases.nix
+++ b/pkgs/top-level/aliases.nix
@@ -287,6 +287,7 @@ mapAliases {
akkoma-emoji = throw "'akkoma-emoji' has been renamed to/replaced by 'blobs_gg'"; # Converted to throw 2025-10-27
akkoma-frontends.admin-fe = throw "'akkoma-frontends.admin-fe' has been renamed to/replaced by 'akkoma-admin-fe'"; # Converted to throw 2025-10-27
akkoma-frontends.akkoma-fe = throw "'akkoma-frontends.akkoma-fe' has been renamed to/replaced by 'akkoma-fe'"; # Converted to throw 2025-10-27
+ alac = throw "'alac' has been removed, as it was unmaintained and contains several vulnerabilities"; # Added 2026-09-26
alexandria = throw "'alexandria' has been removed as it was unmaintained upstream and depended on webkitgtk 4.0 and libsoup 2.4 via Tauri v1"; # Added 2026-06-07
amazon-ecs-cli = throw "'amazon-ecs-cli' has been removed due to being unmaintained upstream"; # Added 2026-01-19
amazon-qldb-shell = throw "'amazon-qldb-shell' has been removed due to being unmaintained upstream"; # Added 2025-07-30