Merge release-25.11 into staging-next-25.11

This commit is contained in:
nixpkgs-ci[bot]
2026-05-25 00:47:56 +00:00
committed by GitHub
24 changed files with 610 additions and 531 deletions

View File

@@ -33,4 +33,15 @@
- maintainers/github-teams.json
- base-branch: ['master']
"backport release-26.05":
- all:
- changed-files:
- any-glob-to-any-file:
- .github/actions/**/*
- .github/workflows/*
- .github/labeler*.yml
- ci/**/*.*
- maintainers/github-teams.json
- base-branch: ['master']
# keep-sorted end

View File

@@ -35,7 +35,7 @@ jobs:
into: staging-next-25.11
- from: staging-next-25.11
into: staging-25.11
- from: master
- from: release-26.05
into: staging-next-26.05
- from: staging-next-26.05
into: staging-26.05

View File

@@ -660,46 +660,66 @@ in
}
);
systemd.services = toHardenedClientAttrs (
client:
nameValuePair client.service.name (
mkIf client.hardened {
serviceConfig = {
RuntimeDirectoryMode = "0750";
systemd.services = mkMerge [
# netbird services
(toHardenedClientAttrs (
client:
nameValuePair client.service.name (
mkIf client.hardened {
serviceConfig = {
RuntimeDirectoryMode = "0750";
User = client.user.name;
Group = client.user.group;
User = client.user.name;
Group = client.user.group;
# settings implied by DynamicUser=true, without actually using it,
# see https://www.freedesktop.org/software/systemd/man/latest/systemd.exec.html#DynamicUser=
RemoveIPC = true;
PrivateTmp = true;
ProtectSystem = "strict";
ProtectHome = "yes";
# settings implied by DynamicUser=true, without actually using it,
# see https://www.freedesktop.org/software/systemd/man/latest/systemd.exec.html#DynamicUser=
RemoveIPC = true;
PrivateTmp = true;
ProtectSystem = "strict";
ProtectHome = "yes";
AmbientCapabilities = [
# see https://man7.org/linux/man-pages/man7/capabilities.7.html
# see https://docs.netbird.io/how-to/installation#running-net-bird-in-docker
#
# seems to work fine without CAP_SYS_ADMIN and CAP_SYS_RESOURCE
# CAP_NET_BIND_SERVICE could be added to allow binding on low ports, but is not required,
# see https://github.com/netbirdio/netbird/pull/1513
AmbientCapabilities = [
# see https://man7.org/linux/man-pages/man7/capabilities.7.html
# see https://docs.netbird.io/how-to/installation#running-net-bird-in-docker
#
# seems to work fine without CAP_SYS_ADMIN and CAP_SYS_RESOURCE
# CAP_NET_BIND_SERVICE could be added to allow binding on low ports, but is not required,
# see https://github.com/netbirdio/netbird/pull/1513
# failed creating tunnel interface wt-priv: [operation not permitted
"CAP_NET_ADMIN"
# failed to pull up wgInterface [wt-priv]: failed to create ipv4 raw socket: socket: operation not permitted
"CAP_NET_RAW"
]
# required for eBPF filter, used to be subset of CAP_SYS_ADMIN
++ optional (versionAtLeast kernel.version "5.8") "CAP_BPF"
++ optional (versionOlder kernel.version "5.8") "CAP_SYS_ADMIN"
++ optional (
client.dns-resolver.address != null && client.dns-resolver.port < 1024
) "CAP_NET_BIND_SERVICE";
};
}
)
);
# failed creating tunnel interface wt-priv: [operation not permitted
"CAP_NET_ADMIN"
# failed to pull up wgInterface [wt-priv]: failed to create ipv4 raw socket: socket: operation not permitted
"CAP_NET_RAW"
]
# required for eBPF filter, used to be subset of CAP_SYS_ADMIN
++ optional (versionAtLeast kernel.version "5.8") "CAP_BPF"
++ optional (versionOlder kernel.version "5.8") "CAP_SYS_ADMIN"
++ optional (
client.dns-resolver.address != null && client.dns-resolver.port < 1024
) "CAP_NET_BIND_SERVICE";
};
}
)
))
# netbird-login services
(toHardenedClientAttrs (
client:
nameValuePair "${client.service.name}-login" (
mkIf client.hardened {
serviceConfig = {
User = client.user.name;
Group = client.user.group;
RemoveIPC = true;
PrivateTmp = "disconnected"; # "disconnected" puts /tmp on `tmpfs`
ProtectSystem = "strict";
ProtectHome = "yes";
};
}
)
))
];
# see https://github.com/systemd/systemd/blob/17f3e91e8107b2b29fe25755651b230bbc81a514/src/resolve/org.freedesktop.resolve1.policy#L43-L43
# see all actions used at https://github.com/netbirdio/netbird/blob/13e7198046a0d73a9cd91bf8e063fafb3d41885c/client/internal/dns/systemd_linux.go#L29-L32
@@ -736,47 +756,29 @@ in
Type = "oneshot";
RemainAfterExit = true;
User = client.user.name;
Group = client.user.group;
RemoveIPC = true;
PrivateTmp = "disconnected"; # "disconnected" puts /tmp on `tmpfs`
ProtectSystem = "strict";
ProtectHome = "yes";
LoadCredential = [ "setup-key:${client.login.setupKeyFile}" ];
};
environment.NB_SETUP_KEY_FILE = "%d/setup-key";
/*
might want to do something similar to the docker entrypoint (watching log messages) instead
see https://github.com/netbirdio/netbird/blob/dc30dcacce4c322502975f1f491e6774efd7e1e9/client/netbird-entrypoint.sh
*/
script = ''
set -x
# uses a file on a `tmpfs`, because variable updates get lost in the loop
status_file="/tmp/status.txt"
refresh_status() {
'${lib.getExe client.wrapper}' status &>"$status_file" || :
}
print_short_setup_key() {
cut -b1-8 <"$NB_SETUP_KEY_FILE"
get_status() {
'${lib.getExe client.wrapper}' status 2>&1 || :
}
main() {
refresh_status
<"$status_file" sed 's/^/STATUS:PRE-CONNECT : /g'
until refresh_status && <"$status_file" grep --quiet 'Connected\|NeedsLogin' ; do
# grep for `: Connected` as well, as `Connected` appears other
# places even when not connected, and before NeedsLogin
until get_status | grep --quiet ': Connected\|NeedsLogin' ; do
sleep 1
done
<"$status_file" sed 's/^/STATUS:POST-CONNECT: /g'
if <"$status_file" grep --quiet 'NeedsLogin' ; then
echo "Using Setup Key File with key: $(print_short_setup_key)" >&2
'${lib.getExe client.wrapper}' up --setup-key-file="$NB_SETUP_KEY_FILE"
if get_status | grep --quiet 'NeedsLogin' ; then
# setup key is in $NB_SETUP_KEY_FILE, and is
# automatically picked up by the cli
'${lib.getExe client.wrapper}' up
fi
}

View File

@@ -3,24 +3,24 @@
let
pname = "brave";
version = "1.90.122";
version = "1.90.124";
allArchives = {
aarch64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_arm64.deb";
hash = "sha256-RjmldIesTEVkIlLM9+nHGb4sPjLGKhJTOtLLBsJLYN8=";
hash = "sha256-+ZJxwwL5jPO49anc+6aBA5jlAsFw7BSHt6lXjFseJ3c=";
};
x86_64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_amd64.deb";
hash = "sha256-jeEFsbXmPykkzOBIdB4Oe9towuwSHjApa485w2NO6A8=";
hash = "sha256-mcqe531FqdBVIgZrQLOVDgIi2JBPSKadD4fCLQMimwI=";
};
aarch64-darwin = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-v${version}-darwin-arm64.zip";
hash = "sha256-0QH9hJGCXRjSRANLPp3ivLvKfbH3qIfFs8i/p5BduKE=";
hash = "sha256-u3KmZffPQpHzS9IxZ7UsL7D6ETGJxExil20vmD6flMo=";
};
x86_64-darwin = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-v${version}-darwin-x64.zip";
hash = "sha256-CZhfmjMbXwDizEk6xNzIZfGhiCUwHrJ/V1mqoCMV7TM=";
hash = "sha256-jSWamdWVBCR9uPY/i0awwdhTG3pD/iVdJIeYBnG747k=";
};
};

View File

@@ -8,15 +8,15 @@
}:
let
version = "7.1.190";
version = "7.1.200";
srcs = {
x86_64-linux = fetchurl {
url = "https://github.com/aunetx/deezer-linux/releases/download/v${version}/deezer-desktop-${version}-x64.tar.xz";
hash = "sha256-XoZRlFMiN5VVp3vkTwGDMekhW1KzmvuN9oYTXZFn6B4=";
hash = "sha256-FrAFUkxv4/GGhDO/2g+0Kym1LCV+YoIee7rmOAw17/Q=";
};
aarch64-linux = fetchurl {
url = "https://github.com/aunetx/deezer-linux/releases/download/v${version}/deezer-desktop-${version}-arm64.tar.xz";
hash = "sha256-ChPuz8wd3SOxRmxM5bEbz3paBw7pfIVfSY23nasRI4A=";
hash = "sha256-FcP4jAVvIA71GCtVoWEIA4AynsHOAn0/zt3rNB6Q25Y=";
};
};

View File

@@ -16,6 +16,7 @@
fetchPnpmDeps,
pnpmConfigHook,
pnpm,
faketty,
asar,
copyDesktopItems,
darwin,
@@ -27,13 +28,13 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "element-desktop";
version = "1.12.14";
version = "1.12.18";
src = fetchFromGitHub {
owner = "element-hq";
repo = "element-web";
tag = "v${finalAttrs.version}";
hash = "sha256-yy7CfMOMT1DBXHDHaDyAaOgp3s2KQIKA1A6zUhVOUhM=";
hash = "sha256-G2HEOv1fHVgbT79bo8ibp9VmtQ8o5vA6/i6Q5TUKqdw=";
};
pnpmDeps = fetchPnpmDeps {
@@ -43,7 +44,7 @@ stdenv.mkDerivation (finalAttrs: {
src
;
fetcherVersion = 3;
hash = "sha256-0yqWObZtRntsH7gk+OB8pMuWsrvCQ4L9173Qv0o5abk=";
hash = "sha256-0iGzjwT+99tvRuxYD+1+SrYrCYAI1dcjhXT3x6E/wHg=";
};
env.ELECTRON_SKIP_BINARY_DOWNLOAD = "1";
@@ -57,6 +58,7 @@ stdenv.mkDerivation (finalAttrs: {
pnpm
pnpmConfigHook
tsx
faketty
]
++ lib.optionals stdenv.hostPlatform.isDarwin [
darwin.autoSignDarwinBinariesHook
@@ -81,13 +83,15 @@ stdenv.mkDerivation (finalAttrs: {
cd ../../
'';
# faketty is required to work around a bug in nx.
# See: https://github.com/nrwl/nx/issues/22445
buildPhase = ''
runHook preBuild
export VERSION=${finalAttrs.version}
pnpm -C apps/desktop run build:ts
pnpm -C apps/desktop run build:res
faketty pnpm -C apps/desktop exec nx build:ts
faketty pnpm -C apps/desktop exec nx build:res
pnpm -C apps/desktop exec electron-builder --dir -c.electronDist=electron-dist -c.electronVersion=${electron.version} -c.mac.identity=null
cd apps/desktop

View File

@@ -24,20 +24,20 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "element-web";
version = "1.12.14";
version = "1.12.18";
src = fetchFromGitHub {
owner = "element-hq";
repo = "element-web";
tag = "v${finalAttrs.version}";
hash = "sha256-yy7CfMOMT1DBXHDHaDyAaOgp3s2KQIKA1A6zUhVOUhM=";
hash = "sha256-G2HEOv1fHVgbT79bo8ibp9VmtQ8o5vA6/i6Q5TUKqdw=";
};
pnpmDeps = fetchPnpmDeps {
pname = "element";
inherit (finalAttrs) version src;
fetcherVersion = 3;
hash = "sha256-0yqWObZtRntsH7gk+OB8pMuWsrvCQ4L9173Qv0o5abk=";
hash = "sha256-0iGzjwT+99tvRuxYD+1+SrYrCYAI1dcjhXT3x6E/wHg=";
};
nativeBuildInputs = [

View File

@@ -12,13 +12,13 @@
}:
let
version = "2.63.3";
version = "2.63.5";
src = fetchFromGitHub {
owner = "filebrowser";
repo = "filebrowser";
rev = "v${version}";
hash = "sha256-v3cC8opClvt91MqUIKNZdvCv0hPeCvWPi0IlOMHlWbQ=";
hash = "sha256-/X/TztbZDC1hkRL97jkm6Ak8QmKFDMycekLl6NVPS0k=";
};
frontend = buildNpmPackage rec {
@@ -41,7 +41,7 @@ let
;
fetcherVersion = 3;
pnpm = pnpm_10;
hash = "sha256-g8BWDEymQNOkLYBws0ii4iLnpjB7X4EQl0OzR3GXeq0=";
hash = "sha256-UwTA7Eogp2GrvmXDbdfGBTJS3DuOTJ42e6fHlQxSHoA=";
};
installPhase = ''

View File

@@ -1,4 +1,4 @@
{ callPackage }:
{ callPackage, runCommand }:
let
src = callPackage ./src.nix { };
in
@@ -32,10 +32,6 @@ rec {
sed -i '/# This must remain last./i gkrust_features += ["glean_disable_upload"]\'$'\n' toolkit/library/rust/gkrust-features.mozbuild
# Temporary fix used with patches/rust-build.patch
sed -i 's/9456ca46168ef86c98399a2536f577ef7be3cdde90c0c51392d8ac48519d3fae/60cd124908737068ab21c7773b3df71d00e186cd605f15bad9977232830aabc0/g' third_party/rust/encoding_rs/.cargo-checksum.json
sed -i 's/d7405d2bcf99cf9729075473c45f677630f4c1947c8ba9757db607f2025a7da2/a066ad881d5a74386e666fc844f7fecbbd70021d0330c1b08a2d7a2a67437ccf/g' third_party/rust/encoding_rs/.cargo-checksum.json
cp ${source}/patches/pref-pane/category-librewolf.svg browser/themes/shared/preferences
cp ${source}/patches/pref-pane/librewolf.css browser/themes/shared/preferences
cp ${source}/patches/pref-pane/librewolf.inc.xhtml browser/components/preferences
@@ -55,7 +51,16 @@ rec {
done
'';
extraPrefsFiles = [ "${source}/settings/librewolf.cfg" ];
localSettingsPrefs = runCommand "local-settings.js" { } ''
# Import of `librewolf.cfg` file is already being done manually.
substitute ${source}/settings/defaults/pref/local-settings.js $out \
--replace-fail 'pref("general.config.filename", "librewolf.cfg");' ""
'';
extraPrefsFiles = [
"${source}/settings/librewolf.cfg"
localSettingsPrefs
];
extraPoliciesFiles = [ "${source}/settings/distribution/policies.json" ];

View File

@@ -1,11 +1,11 @@
{
"packageVersion": "150.0.3-1",
"packageVersion": "151.0.1-2",
"source": {
"rev": "150.0.3-1",
"hash": "sha256-ScwnfmK2zUFQLoy1Z9P9xQ2iTss2ufbzji/IHJSri9U="
"rev": "151.0.1-2",
"hash": "sha256-6C048VV6NECGTcdGla4qIa88z677ZTjORf5FM0a4xMM="
},
"firefox": {
"version": "150.0.3",
"hash": "sha512-hFLaYSAPjuZnkNP/8jDKhLKskpGvK1fgGEhsUPk4xTxvtJQ/5s/h6ZuXg0ZvsAv3B/oAYpN1OsaYYY/B47cKSg=="
"version": "151.0.1",
"hash": "sha512-hJKhu5VrODcxU5OL0YsOGOOkrQ0qvCAXtF4CvCdoyPRo1cBjKaMkhaA6Z7ucIhAuar/x5zCAx3dkc11DDcdydw=="
}
}

View File

@@ -14,21 +14,26 @@
python3Packages.buildPythonApplication rec {
pname = "matrix-synapse";
version = "1.152.1";
version = "1.153.0";
pyproject = true;
src = fetchFromGitHub {
owner = "element-hq";
repo = "synapse";
rev = "v${version}";
hash = "sha256-81nqT6/TuqtQjjqnT6O+72WCCPlZ9JJKbWczMh6mbcU=";
hash = "sha256-2/KzRPUMfOOmI8j8WZsVU2ubNxidTb+FW0MZF+ktSSQ=";
};
cargoDeps = rustPlatform.fetchCargoVendor {
inherit pname version src;
hash = "sha256-RwUsiS6JM5dmqquKVtyaBp67DYZys6Uecy0V6AabTk4=";
hash = "sha256-Cu5bXS6BprXr/dwkNXDjcP9hOfqQddoC5BxOus4rteM=";
};
postPatch = ''
substituteInPlace pyproject.toml \
--replace-fail "attrs>=26.1.0,!=21.1.0" "attrs>=19.2.0,!=21.1.0"
'';
build-system =
with python3Packages;
[

View File

@@ -170,11 +170,11 @@ let
in
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "microsoft-edge";
version = "148.0.3967.54";
version = "148.0.3967.70";
src = fetchurl {
url = "https://packages.microsoft.com/repos/edge/pool/main/m/microsoft-edge-stable/microsoft-edge-stable_${finalAttrs.version}-1_amd64.deb";
hash = "sha256-ccMYxwaQ70p+za3LoM0vT+lXiRIlYmoldVDqsHT7I9o=";
hash = "sha256-rwG3zPxMHjC00P591/CZIWRIHb4td4q3Rfz4fvf89k0=";
};
# With strictDeps on, some shebangs were not being patched correctly

View File

@@ -11,10 +11,11 @@
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "msedgedriver";
version = "148.0.3967.54";
version = "148.0.3967.70";
src = fetchzip {
url = "https://msedgedriver.microsoft.com/${finalAttrs.version}/edgedriver_linux64.zip";
hash = "sha256-woGkky1i9so+1D61irtJYjDQ0xoHUeGQsJi/eQ4VGhU=";
hash = "sha256-e0WYaLmuR/ebupSYnS1D4BpTWJldMmiR1TqbTA5Fl0s=";
stripRoot = false;
};

View File

@@ -14,7 +14,9 @@
nodejs,
npmHooks,
openssl,
pipewire, # pw-metadata for bit-perfect sample rate queries
pkg-config,
pulseaudio, # pactl for PipeWire device enumeration and sink routing
rustPlatform,
webkitgtk_4_1,
wrapGAppsHook3,
@@ -66,6 +68,12 @@ rustPlatform.buildRustPackage (finalAttrs: {
postInstall = ''
gappsWrapperArgs+=(
--prefix PATH : ${
lib.makeBinPath [
pulseaudio
pipewire
]
}
--prefix LD_LIBRARY_PATH : ${
lib.makeLibraryPath [
libappindicator

View File

@@ -2,22 +2,21 @@
lib,
appimageTools,
fetchurl,
gitUpdater,
stdenv,
}:
let
pname = "simplex-chat-desktop";
version = "6.5.1";
version = "6.5.2";
sources = {
"aarch64-linux" = fetchurl {
url = "https://github.com/simplex-chat/simplex-chat/releases/download/v${version}/simplex-desktop-aarch64.AppImage";
hash = "sha256-CvHwYKbieRYbBKUCoKAa11rTy5Opdfb7FKS4poantKs=";
hash = "sha256-VrPNKXgVO/9yvGqseOVkYKMFVqhtExL2PCJb6stn3ko=";
};
"x86_64-linux" = fetchurl {
url = "https://github.com/simplex-chat/simplex-chat/releases/download/v${version}/simplex-desktop-x86_64.AppImage";
hash = "sha256-xRHMdHaV+ppxAm1BDOP743N53oDnVPt8b7H+cRqzuZE=";
hash = "sha256-caRL09PKJ33XHRReZ5qSpfgKH0wpJxGSHXfA83sz5UE=";
};
};
@@ -46,11 +45,9 @@ appimageTools.wrapType2 {
cp -r ${appimageContents}/usr/share/icons $out/share
'';
passthru.updateScript = gitUpdater {
url = "https://github.com/simplex-chat/simplex-chat";
rev-prefix = "v";
# skip tags that does not correspond to official releases, like vX.Y.Z-(beta,fdroid,armv7a).
ignoredVersions = "-";
passthru = {
inherit sources;
updateScript = ./update.sh;
};
meta = {

View File

@@ -0,0 +1,32 @@
#!/usr/bin/env nix-shell
#!nix-shell -i bash -p curl jq common-updater-scripts
set -euo pipefail
attr="simplex-chat-desktop"
# Get the latest non-prerelease tag from GitHub.
latest=$(curl -fsSL ${GITHUB_TOKEN:+" -u \":$GITHUB_TOKEN\""} \
"https://api.github.com/repos/simplex-chat/simplex-chat/releases/latest" \
| jq -r '.tag_name')
# Strip the leading "v".
version="${latest#v}"
# Current version in nixpkgs (so we can short-circuit if unchanged).
current=$(nix-instantiate --eval -E "with import ./. {}; ${attr}.version" \
| tr -d '"')
if [[ "$version" == "$current" ]]; then
echo "${attr} is already at ${version}"
exit 0
fi
# Update each per-system source independently.
update-source-version "$attr" "$version" \
--source-key=sources.x86_64-linux
# --ignore-same-version flag silences warning because previous invocation bumped version
update-source-version "$attr" "$version" \
--ignore-same-version \
--source-key=sources.aarch64-linux

View File

@@ -8,16 +8,16 @@
buildGo125Module (finalAttrs: {
pname = "traefik";
version = "3.6.10";
version = "3.6.17";
# Archive with static assets for webui
src = fetchzip {
url = "https://github.com/traefik/traefik/releases/download/v${finalAttrs.version}/traefik-v${finalAttrs.version}.src.tar.gz";
hash = "sha256-WYHHpS721dlkWdOEj+jwJkQ/vsiP2PnmFI50M9I8sbs=";
hash = "sha256-Tqm8Fb+3X/I3v1PG5qfgFMnhbBjKJ5i+3qfd7YuRzFI=";
stripRoot = false;
};
vendorHash = "sha256-q2uy0YrE1D8V0EopKWJLbq2hFcjn3oyanwNJ27yyC+k=";
vendorHash = "sha256-k61m/fnyA9GH57BsylqhUoRao+ujqyDdho9HQNICbhs=";
proxyVendor = true;

View File

@@ -35,15 +35,15 @@
],
}:
stdenv.mkDerivation rec {
stdenv.mkDerivation (finalAttrs: {
pname = "xreader";
version = "4.6.0";
version = "4.6.4";
src = fetchFromGitHub {
owner = "linuxmint";
repo = "xreader";
rev = version;
hash = "sha256-cp/pZ42AS98AD78BVMeY3SHQHkYA2h4o0kddr/H+kUA=";
rev = finalAttrs.version;
hash = "sha256-upX2+Hwdss7OfIWFg5MALoF9LIw5mk6+NYR+NEbcDX4=";
};
nativeBuildInputs = [
@@ -92,4 +92,4 @@ document formats like PDF and Postscript";
platforms = lib.platforms.linux;
teams = [ lib.teams.cinnamon ];
};
}
})

View File

@@ -31,16 +31,16 @@
gitUpdater,
}:
stdenv.mkDerivation rec {
stdenv.mkDerivation (finalAttrs: {
pname = "atril";
version = "1.28.2";
version = "1.28.5";
src = fetchFromGitHub {
owner = "mate-desktop";
repo = "atril";
tag = "v${version}";
tag = "v${finalAttrs.version}";
fetchSubmodules = true;
hash = "sha256-NnWD3Gcxn8ZZKdHzg6iclLiSwj3sBvF+BwpNtcU+dSY=";
hash = "sha256-iG+FFvxxL2/6HqGchoaIDqx8Gfo1wxqM4GW66ScZlao=";
};
nativeBuildInputs = [
@@ -73,7 +73,11 @@ stdenv.mkDerivation rec {
configureFlags =
[ ]
++ lib.optionals enableDjvu [ "--enable-djvu" ]
++ lib.optionals enableEpub [ "--enable-epub" ]
++ lib.optionals enableEpub [
# FIXME: We ship this with non-existent fallback mathjax-directory
# because `MathJax.js` is only available in MathJax 2.7.x.
"--enable-epub"
]
++ lib.optionals enablePostScript [ "--enable-ps" ]
++ lib.optionals enableXps [ "--enable-xps" ]
++ lib.optionals enableImages [ "--enable-pixbuf" ];
@@ -96,4 +100,4 @@ stdenv.mkDerivation rec {
platforms = lib.platforms.unix;
teams = [ lib.teams.mate ];
};
}
})

View File

@@ -5,18 +5,18 @@
"lts": false
},
"6.1": {
"version": "6.1.173",
"hash": "sha256:163dhycch5pw1vc87mm13djghwwyz182ljway5w19hz8zdn2rwy4",
"version": "6.1.174",
"hash": "sha256:0vp07x4v82qnmc1pifv3ynp2ab5mvlbfnpqvs5893bi3yrnk927d",
"lts": true
},
"5.15": {
"version": "5.15.207",
"hash": "sha256:13hlwrfi7hp3lxg5v4kx5ykycb64iwc7xhg4rbjk0pvl0yipzssh",
"version": "5.15.208",
"hash": "sha256:0wmi50q8vgblhbh77d1a4sw4snymr6srqd22bxcjg9i7wcv70gdm",
"lts": true
},
"5.10": {
"version": "5.10.256",
"hash": "sha256:0pwf9nsr7clqm0bxvyrp3k79d5i6f9xqq58i31xvvra1xk4dmsgi",
"version": "5.10.257",
"hash": "sha256:1lghcrxc1fqarvym03jrcda2a3labc887ci9yjqgbmv3nphzvc88",
"lts": true
},
"6.6": {

View File

@@ -12,13 +12,13 @@ let
# override options if they need using lib.mkForce (that has 50 priority)
mkKernelOverride = lib.mkOverride 90;
suffix = "zen2";
suffix = "zen1";
in
buildLinux (
args
// rec {
version = "7.0.9";
version = "7.0.10";
pname = "linux-zen";
modDirVersion = lib.versions.pad 3 "${version}-${suffix}";
isZen = true;
@@ -27,7 +27,7 @@ buildLinux (
owner = "zen-kernel";
repo = "zen-kernel";
rev = "v${version}-${suffix}";
sha256 = "1x2s9pv8frq77fish833mnwrrdglxssbqrsjnnizj3ayylw41qkd";
sha256 = "1xh7bbis9v7yq2s1zwdnmsx54zz9kcmyn1cnrqqlsassk7fzl7nx";
};
# This is based on the following source:

View File

@@ -47,5 +47,10 @@ callPackage ./generic.nix args {
url = "https://github.com/nginx/nginx/commit/39d7d0ba0799fcff6baee52b6525f45739593cfd.patch";
hash = "sha256-6PwV0iz4kQGGBwVk9129aH+TFzbSx3QSVpp22AoKQY4=";
})
(fetchpatch {
name = "CVE-2026-9256.patch";
url = "https://github.com/nginx/nginx/commit/ca4f92a27464ae6c2082245e4f67048c633aa032.patch";
hash = "sha256-tf3KNIki5m8ADj+ghhSlVOsmY5yoLI1HH6/MID+UxbM=";
})
];
}

View File

@@ -36,5 +36,10 @@ callPackage ./generic.nix args {
url = "https://github.com/nginx/nginx/commit/39d7d0ba0799fcff6baee52b6525f45739593cfd.patch";
hash = "sha256-6PwV0iz4kQGGBwVk9129aH+TFzbSx3QSVpp22AoKQY4=";
})
(fetchpatch {
name = "CVE-2026-9256.patch";
url = "https://github.com/nginx/nginx/commit/ca4f92a27464ae6c2082245e4f67048c633aa032.patch";
hash = "sha256-tf3KNIki5m8ADj+ghhSlVOsmY5yoLI1HH6/MID+UxbM=";
})
];
}