mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-09-29 19:30:11 +00:00
Merge release-25.11 into staging-next-25.11
This commit is contained in:
11
.github/labeler-no-sync.yml
vendored
11
.github/labeler-no-sync.yml
vendored
@@ -33,4 +33,15 @@
|
||||
- maintainers/github-teams.json
|
||||
- base-branch: ['master']
|
||||
|
||||
"backport release-26.05":
|
||||
- all:
|
||||
- changed-files:
|
||||
- any-glob-to-any-file:
|
||||
- .github/actions/**/*
|
||||
- .github/workflows/*
|
||||
- .github/labeler*.yml
|
||||
- ci/**/*.*
|
||||
- maintainers/github-teams.json
|
||||
- base-branch: ['master']
|
||||
|
||||
# keep-sorted end
|
||||
|
||||
2
.github/workflows/periodic-merge-24h.yml
vendored
2
.github/workflows/periodic-merge-24h.yml
vendored
@@ -35,7 +35,7 @@ jobs:
|
||||
into: staging-next-25.11
|
||||
- from: staging-next-25.11
|
||||
into: staging-25.11
|
||||
- from: master
|
||||
- from: release-26.05
|
||||
into: staging-next-26.05
|
||||
- from: staging-next-26.05
|
||||
into: staging-26.05
|
||||
|
||||
@@ -660,46 +660,66 @@ in
|
||||
}
|
||||
);
|
||||
|
||||
systemd.services = toHardenedClientAttrs (
|
||||
client:
|
||||
nameValuePair client.service.name (
|
||||
mkIf client.hardened {
|
||||
serviceConfig = {
|
||||
RuntimeDirectoryMode = "0750";
|
||||
systemd.services = mkMerge [
|
||||
# netbird services
|
||||
(toHardenedClientAttrs (
|
||||
client:
|
||||
nameValuePair client.service.name (
|
||||
mkIf client.hardened {
|
||||
serviceConfig = {
|
||||
RuntimeDirectoryMode = "0750";
|
||||
|
||||
User = client.user.name;
|
||||
Group = client.user.group;
|
||||
User = client.user.name;
|
||||
Group = client.user.group;
|
||||
|
||||
# settings implied by DynamicUser=true, without actually using it,
|
||||
# see https://www.freedesktop.org/software/systemd/man/latest/systemd.exec.html#DynamicUser=
|
||||
RemoveIPC = true;
|
||||
PrivateTmp = true;
|
||||
ProtectSystem = "strict";
|
||||
ProtectHome = "yes";
|
||||
# settings implied by DynamicUser=true, without actually using it,
|
||||
# see https://www.freedesktop.org/software/systemd/man/latest/systemd.exec.html#DynamicUser=
|
||||
RemoveIPC = true;
|
||||
PrivateTmp = true;
|
||||
ProtectSystem = "strict";
|
||||
ProtectHome = "yes";
|
||||
|
||||
AmbientCapabilities = [
|
||||
# see https://man7.org/linux/man-pages/man7/capabilities.7.html
|
||||
# see https://docs.netbird.io/how-to/installation#running-net-bird-in-docker
|
||||
#
|
||||
# seems to work fine without CAP_SYS_ADMIN and CAP_SYS_RESOURCE
|
||||
# CAP_NET_BIND_SERVICE could be added to allow binding on low ports, but is not required,
|
||||
# see https://github.com/netbirdio/netbird/pull/1513
|
||||
AmbientCapabilities = [
|
||||
# see https://man7.org/linux/man-pages/man7/capabilities.7.html
|
||||
# see https://docs.netbird.io/how-to/installation#running-net-bird-in-docker
|
||||
#
|
||||
# seems to work fine without CAP_SYS_ADMIN and CAP_SYS_RESOURCE
|
||||
# CAP_NET_BIND_SERVICE could be added to allow binding on low ports, but is not required,
|
||||
# see https://github.com/netbirdio/netbird/pull/1513
|
||||
|
||||
# failed creating tunnel interface wt-priv: [operation not permitted
|
||||
"CAP_NET_ADMIN"
|
||||
# failed to pull up wgInterface [wt-priv]: failed to create ipv4 raw socket: socket: operation not permitted
|
||||
"CAP_NET_RAW"
|
||||
]
|
||||
# required for eBPF filter, used to be subset of CAP_SYS_ADMIN
|
||||
++ optional (versionAtLeast kernel.version "5.8") "CAP_BPF"
|
||||
++ optional (versionOlder kernel.version "5.8") "CAP_SYS_ADMIN"
|
||||
++ optional (
|
||||
client.dns-resolver.address != null && client.dns-resolver.port < 1024
|
||||
) "CAP_NET_BIND_SERVICE";
|
||||
};
|
||||
}
|
||||
)
|
||||
);
|
||||
# failed creating tunnel interface wt-priv: [operation not permitted
|
||||
"CAP_NET_ADMIN"
|
||||
# failed to pull up wgInterface [wt-priv]: failed to create ipv4 raw socket: socket: operation not permitted
|
||||
"CAP_NET_RAW"
|
||||
]
|
||||
# required for eBPF filter, used to be subset of CAP_SYS_ADMIN
|
||||
++ optional (versionAtLeast kernel.version "5.8") "CAP_BPF"
|
||||
++ optional (versionOlder kernel.version "5.8") "CAP_SYS_ADMIN"
|
||||
++ optional (
|
||||
client.dns-resolver.address != null && client.dns-resolver.port < 1024
|
||||
) "CAP_NET_BIND_SERVICE";
|
||||
};
|
||||
}
|
||||
)
|
||||
))
|
||||
# netbird-login services
|
||||
(toHardenedClientAttrs (
|
||||
client:
|
||||
nameValuePair "${client.service.name}-login" (
|
||||
mkIf client.hardened {
|
||||
serviceConfig = {
|
||||
User = client.user.name;
|
||||
Group = client.user.group;
|
||||
|
||||
RemoveIPC = true;
|
||||
PrivateTmp = "disconnected"; # "disconnected" puts /tmp on `tmpfs`
|
||||
ProtectSystem = "strict";
|
||||
ProtectHome = "yes";
|
||||
};
|
||||
}
|
||||
)
|
||||
))
|
||||
];
|
||||
|
||||
# see https://github.com/systemd/systemd/blob/17f3e91e8107b2b29fe25755651b230bbc81a514/src/resolve/org.freedesktop.resolve1.policy#L43-L43
|
||||
# see all actions used at https://github.com/netbirdio/netbird/blob/13e7198046a0d73a9cd91bf8e063fafb3d41885c/client/internal/dns/systemd_linux.go#L29-L32
|
||||
@@ -736,47 +756,29 @@ in
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
|
||||
User = client.user.name;
|
||||
Group = client.user.group;
|
||||
|
||||
RemoveIPC = true;
|
||||
PrivateTmp = "disconnected"; # "disconnected" puts /tmp on `tmpfs`
|
||||
ProtectSystem = "strict";
|
||||
ProtectHome = "yes";
|
||||
|
||||
LoadCredential = [ "setup-key:${client.login.setupKeyFile}" ];
|
||||
};
|
||||
|
||||
environment.NB_SETUP_KEY_FILE = "%d/setup-key";
|
||||
/*
|
||||
might want to do something similar to the docker entrypoint (watching log messages) instead
|
||||
see https://github.com/netbirdio/netbird/blob/dc30dcacce4c322502975f1f491e6774efd7e1e9/client/netbird-entrypoint.sh
|
||||
*/
|
||||
|
||||
script = ''
|
||||
set -x
|
||||
# uses a file on a `tmpfs`, because variable updates get lost in the loop
|
||||
status_file="/tmp/status.txt"
|
||||
|
||||
refresh_status() {
|
||||
'${lib.getExe client.wrapper}' status &>"$status_file" || :
|
||||
}
|
||||
|
||||
print_short_setup_key() {
|
||||
cut -b1-8 <"$NB_SETUP_KEY_FILE"
|
||||
get_status() {
|
||||
'${lib.getExe client.wrapper}' status 2>&1 || :
|
||||
}
|
||||
|
||||
main() {
|
||||
refresh_status
|
||||
<"$status_file" sed 's/^/STATUS:PRE-CONNECT : /g'
|
||||
|
||||
until refresh_status && <"$status_file" grep --quiet 'Connected\|NeedsLogin' ; do
|
||||
# grep for `: Connected` as well, as `Connected` appears other
|
||||
# places even when not connected, and before NeedsLogin
|
||||
until get_status | grep --quiet ': Connected\|NeedsLogin' ; do
|
||||
sleep 1
|
||||
done
|
||||
<"$status_file" sed 's/^/STATUS:POST-CONNECT: /g'
|
||||
|
||||
if <"$status_file" grep --quiet 'NeedsLogin' ; then
|
||||
echo "Using Setup Key File with key: $(print_short_setup_key)" >&2
|
||||
'${lib.getExe client.wrapper}' up --setup-key-file="$NB_SETUP_KEY_FILE"
|
||||
if get_status | grep --quiet 'NeedsLogin' ; then
|
||||
# setup key is in $NB_SETUP_KEY_FILE, and is
|
||||
# automatically picked up by the cli
|
||||
'${lib.getExe client.wrapper}' up
|
||||
fi
|
||||
}
|
||||
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -3,24 +3,24 @@
|
||||
|
||||
let
|
||||
pname = "brave";
|
||||
version = "1.90.122";
|
||||
version = "1.90.124";
|
||||
|
||||
allArchives = {
|
||||
aarch64-linux = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_arm64.deb";
|
||||
hash = "sha256-RjmldIesTEVkIlLM9+nHGb4sPjLGKhJTOtLLBsJLYN8=";
|
||||
hash = "sha256-+ZJxwwL5jPO49anc+6aBA5jlAsFw7BSHt6lXjFseJ3c=";
|
||||
};
|
||||
x86_64-linux = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_amd64.deb";
|
||||
hash = "sha256-jeEFsbXmPykkzOBIdB4Oe9towuwSHjApa485w2NO6A8=";
|
||||
hash = "sha256-mcqe531FqdBVIgZrQLOVDgIi2JBPSKadD4fCLQMimwI=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-v${version}-darwin-arm64.zip";
|
||||
hash = "sha256-0QH9hJGCXRjSRANLPp3ivLvKfbH3qIfFs8i/p5BduKE=";
|
||||
hash = "sha256-u3KmZffPQpHzS9IxZ7UsL7D6ETGJxExil20vmD6flMo=";
|
||||
};
|
||||
x86_64-darwin = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-v${version}-darwin-x64.zip";
|
||||
hash = "sha256-CZhfmjMbXwDizEk6xNzIZfGhiCUwHrJ/V1mqoCMV7TM=";
|
||||
hash = "sha256-jSWamdWVBCR9uPY/i0awwdhTG3pD/iVdJIeYBnG747k=";
|
||||
};
|
||||
};
|
||||
|
||||
|
||||
@@ -8,15 +8,15 @@
|
||||
}:
|
||||
|
||||
let
|
||||
version = "7.1.190";
|
||||
version = "7.1.200";
|
||||
srcs = {
|
||||
x86_64-linux = fetchurl {
|
||||
url = "https://github.com/aunetx/deezer-linux/releases/download/v${version}/deezer-desktop-${version}-x64.tar.xz";
|
||||
hash = "sha256-XoZRlFMiN5VVp3vkTwGDMekhW1KzmvuN9oYTXZFn6B4=";
|
||||
hash = "sha256-FrAFUkxv4/GGhDO/2g+0Kym1LCV+YoIee7rmOAw17/Q=";
|
||||
};
|
||||
aarch64-linux = fetchurl {
|
||||
url = "https://github.com/aunetx/deezer-linux/releases/download/v${version}/deezer-desktop-${version}-arm64.tar.xz";
|
||||
hash = "sha256-ChPuz8wd3SOxRmxM5bEbz3paBw7pfIVfSY23nasRI4A=";
|
||||
hash = "sha256-FcP4jAVvIA71GCtVoWEIA4AynsHOAn0/zt3rNB6Q25Y=";
|
||||
};
|
||||
};
|
||||
|
||||
|
||||
@@ -16,6 +16,7 @@
|
||||
fetchPnpmDeps,
|
||||
pnpmConfigHook,
|
||||
pnpm,
|
||||
faketty,
|
||||
asar,
|
||||
copyDesktopItems,
|
||||
darwin,
|
||||
@@ -27,13 +28,13 @@ let
|
||||
in
|
||||
stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "element-desktop";
|
||||
version = "1.12.14";
|
||||
version = "1.12.18";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "element-hq";
|
||||
repo = "element-web";
|
||||
tag = "v${finalAttrs.version}";
|
||||
hash = "sha256-yy7CfMOMT1DBXHDHaDyAaOgp3s2KQIKA1A6zUhVOUhM=";
|
||||
hash = "sha256-G2HEOv1fHVgbT79bo8ibp9VmtQ8o5vA6/i6Q5TUKqdw=";
|
||||
};
|
||||
|
||||
pnpmDeps = fetchPnpmDeps {
|
||||
@@ -43,7 +44,7 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
src
|
||||
;
|
||||
fetcherVersion = 3;
|
||||
hash = "sha256-0yqWObZtRntsH7gk+OB8pMuWsrvCQ4L9173Qv0o5abk=";
|
||||
hash = "sha256-0iGzjwT+99tvRuxYD+1+SrYrCYAI1dcjhXT3x6E/wHg=";
|
||||
};
|
||||
|
||||
env.ELECTRON_SKIP_BINARY_DOWNLOAD = "1";
|
||||
@@ -57,6 +58,7 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
pnpm
|
||||
pnpmConfigHook
|
||||
tsx
|
||||
faketty
|
||||
]
|
||||
++ lib.optionals stdenv.hostPlatform.isDarwin [
|
||||
darwin.autoSignDarwinBinariesHook
|
||||
@@ -81,13 +83,15 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
cd ../../
|
||||
'';
|
||||
|
||||
# faketty is required to work around a bug in nx.
|
||||
# See: https://github.com/nrwl/nx/issues/22445
|
||||
buildPhase = ''
|
||||
runHook preBuild
|
||||
|
||||
export VERSION=${finalAttrs.version}
|
||||
|
||||
pnpm -C apps/desktop run build:ts
|
||||
pnpm -C apps/desktop run build:res
|
||||
faketty pnpm -C apps/desktop exec nx build:ts
|
||||
faketty pnpm -C apps/desktop exec nx build:res
|
||||
pnpm -C apps/desktop exec electron-builder --dir -c.electronDist=electron-dist -c.electronVersion=${electron.version} -c.mac.identity=null
|
||||
|
||||
cd apps/desktop
|
||||
|
||||
@@ -24,20 +24,20 @@ let
|
||||
in
|
||||
stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "element-web";
|
||||
version = "1.12.14";
|
||||
version = "1.12.18";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "element-hq";
|
||||
repo = "element-web";
|
||||
tag = "v${finalAttrs.version}";
|
||||
hash = "sha256-yy7CfMOMT1DBXHDHaDyAaOgp3s2KQIKA1A6zUhVOUhM=";
|
||||
hash = "sha256-G2HEOv1fHVgbT79bo8ibp9VmtQ8o5vA6/i6Q5TUKqdw=";
|
||||
};
|
||||
|
||||
pnpmDeps = fetchPnpmDeps {
|
||||
pname = "element";
|
||||
inherit (finalAttrs) version src;
|
||||
fetcherVersion = 3;
|
||||
hash = "sha256-0yqWObZtRntsH7gk+OB8pMuWsrvCQ4L9173Qv0o5abk=";
|
||||
hash = "sha256-0iGzjwT+99tvRuxYD+1+SrYrCYAI1dcjhXT3x6E/wHg=";
|
||||
};
|
||||
|
||||
nativeBuildInputs = [
|
||||
|
||||
@@ -12,13 +12,13 @@
|
||||
}:
|
||||
|
||||
let
|
||||
version = "2.63.3";
|
||||
version = "2.63.5";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "filebrowser";
|
||||
repo = "filebrowser";
|
||||
rev = "v${version}";
|
||||
hash = "sha256-v3cC8opClvt91MqUIKNZdvCv0hPeCvWPi0IlOMHlWbQ=";
|
||||
hash = "sha256-/X/TztbZDC1hkRL97jkm6Ak8QmKFDMycekLl6NVPS0k=";
|
||||
};
|
||||
|
||||
frontend = buildNpmPackage rec {
|
||||
@@ -41,7 +41,7 @@ let
|
||||
;
|
||||
fetcherVersion = 3;
|
||||
pnpm = pnpm_10;
|
||||
hash = "sha256-g8BWDEymQNOkLYBws0ii4iLnpjB7X4EQl0OzR3GXeq0=";
|
||||
hash = "sha256-UwTA7Eogp2GrvmXDbdfGBTJS3DuOTJ42e6fHlQxSHoA=";
|
||||
};
|
||||
|
||||
installPhase = ''
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
{ callPackage }:
|
||||
{ callPackage, runCommand }:
|
||||
let
|
||||
src = callPackage ./src.nix { };
|
||||
in
|
||||
@@ -32,10 +32,6 @@ rec {
|
||||
|
||||
sed -i '/# This must remain last./i gkrust_features += ["glean_disable_upload"]\'$'\n' toolkit/library/rust/gkrust-features.mozbuild
|
||||
|
||||
# Temporary fix used with patches/rust-build.patch
|
||||
sed -i 's/9456ca46168ef86c98399a2536f577ef7be3cdde90c0c51392d8ac48519d3fae/60cd124908737068ab21c7773b3df71d00e186cd605f15bad9977232830aabc0/g' third_party/rust/encoding_rs/.cargo-checksum.json
|
||||
sed -i 's/d7405d2bcf99cf9729075473c45f677630f4c1947c8ba9757db607f2025a7da2/a066ad881d5a74386e666fc844f7fecbbd70021d0330c1b08a2d7a2a67437ccf/g' third_party/rust/encoding_rs/.cargo-checksum.json
|
||||
|
||||
cp ${source}/patches/pref-pane/category-librewolf.svg browser/themes/shared/preferences
|
||||
cp ${source}/patches/pref-pane/librewolf.css browser/themes/shared/preferences
|
||||
cp ${source}/patches/pref-pane/librewolf.inc.xhtml browser/components/preferences
|
||||
@@ -55,7 +51,16 @@ rec {
|
||||
done
|
||||
'';
|
||||
|
||||
extraPrefsFiles = [ "${source}/settings/librewolf.cfg" ];
|
||||
localSettingsPrefs = runCommand "local-settings.js" { } ''
|
||||
# Import of `librewolf.cfg` file is already being done manually.
|
||||
substitute ${source}/settings/defaults/pref/local-settings.js $out \
|
||||
--replace-fail 'pref("general.config.filename", "librewolf.cfg");' ""
|
||||
'';
|
||||
|
||||
extraPrefsFiles = [
|
||||
"${source}/settings/librewolf.cfg"
|
||||
localSettingsPrefs
|
||||
];
|
||||
|
||||
extraPoliciesFiles = [ "${source}/settings/distribution/policies.json" ];
|
||||
|
||||
|
||||
@@ -1,11 +1,11 @@
|
||||
{
|
||||
"packageVersion": "150.0.3-1",
|
||||
"packageVersion": "151.0.1-2",
|
||||
"source": {
|
||||
"rev": "150.0.3-1",
|
||||
"hash": "sha256-ScwnfmK2zUFQLoy1Z9P9xQ2iTss2ufbzji/IHJSri9U="
|
||||
"rev": "151.0.1-2",
|
||||
"hash": "sha256-6C048VV6NECGTcdGla4qIa88z677ZTjORf5FM0a4xMM="
|
||||
},
|
||||
"firefox": {
|
||||
"version": "150.0.3",
|
||||
"hash": "sha512-hFLaYSAPjuZnkNP/8jDKhLKskpGvK1fgGEhsUPk4xTxvtJQ/5s/h6ZuXg0ZvsAv3B/oAYpN1OsaYYY/B47cKSg=="
|
||||
"version": "151.0.1",
|
||||
"hash": "sha512-hJKhu5VrODcxU5OL0YsOGOOkrQ0qvCAXtF4CvCdoyPRo1cBjKaMkhaA6Z7ucIhAuar/x5zCAx3dkc11DDcdydw=="
|
||||
}
|
||||
}
|
||||
|
||||
@@ -14,21 +14,26 @@
|
||||
|
||||
python3Packages.buildPythonApplication rec {
|
||||
pname = "matrix-synapse";
|
||||
version = "1.152.1";
|
||||
version = "1.153.0";
|
||||
pyproject = true;
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "element-hq";
|
||||
repo = "synapse";
|
||||
rev = "v${version}";
|
||||
hash = "sha256-81nqT6/TuqtQjjqnT6O+72WCCPlZ9JJKbWczMh6mbcU=";
|
||||
hash = "sha256-2/KzRPUMfOOmI8j8WZsVU2ubNxidTb+FW0MZF+ktSSQ=";
|
||||
};
|
||||
|
||||
cargoDeps = rustPlatform.fetchCargoVendor {
|
||||
inherit pname version src;
|
||||
hash = "sha256-RwUsiS6JM5dmqquKVtyaBp67DYZys6Uecy0V6AabTk4=";
|
||||
hash = "sha256-Cu5bXS6BprXr/dwkNXDjcP9hOfqQddoC5BxOus4rteM=";
|
||||
};
|
||||
|
||||
postPatch = ''
|
||||
substituteInPlace pyproject.toml \
|
||||
--replace-fail "attrs>=26.1.0,!=21.1.0" "attrs>=19.2.0,!=21.1.0"
|
||||
'';
|
||||
|
||||
build-system =
|
||||
with python3Packages;
|
||||
[
|
||||
|
||||
@@ -170,11 +170,11 @@ let
|
||||
in
|
||||
stdenvNoCC.mkDerivation (finalAttrs: {
|
||||
pname = "microsoft-edge";
|
||||
version = "148.0.3967.54";
|
||||
version = "148.0.3967.70";
|
||||
|
||||
src = fetchurl {
|
||||
url = "https://packages.microsoft.com/repos/edge/pool/main/m/microsoft-edge-stable/microsoft-edge-stable_${finalAttrs.version}-1_amd64.deb";
|
||||
hash = "sha256-ccMYxwaQ70p+za3LoM0vT+lXiRIlYmoldVDqsHT7I9o=";
|
||||
hash = "sha256-rwG3zPxMHjC00P591/CZIWRIHb4td4q3Rfz4fvf89k0=";
|
||||
};
|
||||
|
||||
# With strictDeps on, some shebangs were not being patched correctly
|
||||
|
||||
@@ -11,10 +11,11 @@
|
||||
|
||||
stdenvNoCC.mkDerivation (finalAttrs: {
|
||||
pname = "msedgedriver";
|
||||
version = "148.0.3967.54";
|
||||
version = "148.0.3967.70";
|
||||
|
||||
src = fetchzip {
|
||||
url = "https://msedgedriver.microsoft.com/${finalAttrs.version}/edgedriver_linux64.zip";
|
||||
hash = "sha256-woGkky1i9so+1D61irtJYjDQ0xoHUeGQsJi/eQ4VGhU=";
|
||||
hash = "sha256-e0WYaLmuR/ebupSYnS1D4BpTWJldMmiR1TqbTA5Fl0s=";
|
||||
stripRoot = false;
|
||||
};
|
||||
|
||||
|
||||
@@ -14,7 +14,9 @@
|
||||
nodejs,
|
||||
npmHooks,
|
||||
openssl,
|
||||
pipewire, # pw-metadata for bit-perfect sample rate queries
|
||||
pkg-config,
|
||||
pulseaudio, # pactl for PipeWire device enumeration and sink routing
|
||||
rustPlatform,
|
||||
webkitgtk_4_1,
|
||||
wrapGAppsHook3,
|
||||
@@ -66,6 +68,12 @@ rustPlatform.buildRustPackage (finalAttrs: {
|
||||
|
||||
postInstall = ''
|
||||
gappsWrapperArgs+=(
|
||||
--prefix PATH : ${
|
||||
lib.makeBinPath [
|
||||
pulseaudio
|
||||
pipewire
|
||||
]
|
||||
}
|
||||
--prefix LD_LIBRARY_PATH : ${
|
||||
lib.makeLibraryPath [
|
||||
libappindicator
|
||||
|
||||
@@ -2,22 +2,21 @@
|
||||
lib,
|
||||
appimageTools,
|
||||
fetchurl,
|
||||
gitUpdater,
|
||||
stdenv,
|
||||
}:
|
||||
|
||||
let
|
||||
pname = "simplex-chat-desktop";
|
||||
version = "6.5.1";
|
||||
version = "6.5.2";
|
||||
|
||||
sources = {
|
||||
"aarch64-linux" = fetchurl {
|
||||
url = "https://github.com/simplex-chat/simplex-chat/releases/download/v${version}/simplex-desktop-aarch64.AppImage";
|
||||
hash = "sha256-CvHwYKbieRYbBKUCoKAa11rTy5Opdfb7FKS4poantKs=";
|
||||
hash = "sha256-VrPNKXgVO/9yvGqseOVkYKMFVqhtExL2PCJb6stn3ko=";
|
||||
};
|
||||
"x86_64-linux" = fetchurl {
|
||||
url = "https://github.com/simplex-chat/simplex-chat/releases/download/v${version}/simplex-desktop-x86_64.AppImage";
|
||||
hash = "sha256-xRHMdHaV+ppxAm1BDOP743N53oDnVPt8b7H+cRqzuZE=";
|
||||
hash = "sha256-caRL09PKJ33XHRReZ5qSpfgKH0wpJxGSHXfA83sz5UE=";
|
||||
};
|
||||
};
|
||||
|
||||
@@ -46,11 +45,9 @@ appimageTools.wrapType2 {
|
||||
cp -r ${appimageContents}/usr/share/icons $out/share
|
||||
'';
|
||||
|
||||
passthru.updateScript = gitUpdater {
|
||||
url = "https://github.com/simplex-chat/simplex-chat";
|
||||
rev-prefix = "v";
|
||||
# skip tags that does not correspond to official releases, like vX.Y.Z-(beta,fdroid,armv7a).
|
||||
ignoredVersions = "-";
|
||||
passthru = {
|
||||
inherit sources;
|
||||
updateScript = ./update.sh;
|
||||
};
|
||||
|
||||
meta = {
|
||||
|
||||
32
pkgs/by-name/si/simplex-chat-desktop/update.sh
Executable file
32
pkgs/by-name/si/simplex-chat-desktop/update.sh
Executable file
@@ -0,0 +1,32 @@
|
||||
#!/usr/bin/env nix-shell
|
||||
#!nix-shell -i bash -p curl jq common-updater-scripts
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
attr="simplex-chat-desktop"
|
||||
|
||||
# Get the latest non-prerelease tag from GitHub.
|
||||
latest=$(curl -fsSL ${GITHUB_TOKEN:+" -u \":$GITHUB_TOKEN\""} \
|
||||
"https://api.github.com/repos/simplex-chat/simplex-chat/releases/latest" \
|
||||
| jq -r '.tag_name')
|
||||
|
||||
# Strip the leading "v".
|
||||
version="${latest#v}"
|
||||
|
||||
# Current version in nixpkgs (so we can short-circuit if unchanged).
|
||||
current=$(nix-instantiate --eval -E "with import ./. {}; ${attr}.version" \
|
||||
| tr -d '"')
|
||||
|
||||
if [[ "$version" == "$current" ]]; then
|
||||
echo "${attr} is already at ${version}"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# Update each per-system source independently.
|
||||
update-source-version "$attr" "$version" \
|
||||
--source-key=sources.x86_64-linux
|
||||
|
||||
# --ignore-same-version flag silences warning because previous invocation bumped version
|
||||
update-source-version "$attr" "$version" \
|
||||
--ignore-same-version \
|
||||
--source-key=sources.aarch64-linux
|
||||
@@ -8,16 +8,16 @@
|
||||
|
||||
buildGo125Module (finalAttrs: {
|
||||
pname = "traefik";
|
||||
version = "3.6.10";
|
||||
version = "3.6.17";
|
||||
|
||||
# Archive with static assets for webui
|
||||
src = fetchzip {
|
||||
url = "https://github.com/traefik/traefik/releases/download/v${finalAttrs.version}/traefik-v${finalAttrs.version}.src.tar.gz";
|
||||
hash = "sha256-WYHHpS721dlkWdOEj+jwJkQ/vsiP2PnmFI50M9I8sbs=";
|
||||
hash = "sha256-Tqm8Fb+3X/I3v1PG5qfgFMnhbBjKJ5i+3qfd7YuRzFI=";
|
||||
stripRoot = false;
|
||||
};
|
||||
|
||||
vendorHash = "sha256-q2uy0YrE1D8V0EopKWJLbq2hFcjn3oyanwNJ27yyC+k=";
|
||||
vendorHash = "sha256-k61m/fnyA9GH57BsylqhUoRao+ujqyDdho9HQNICbhs=";
|
||||
|
||||
proxyVendor = true;
|
||||
|
||||
|
||||
@@ -35,15 +35,15 @@
|
||||
],
|
||||
}:
|
||||
|
||||
stdenv.mkDerivation rec {
|
||||
stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "xreader";
|
||||
version = "4.6.0";
|
||||
version = "4.6.4";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "linuxmint";
|
||||
repo = "xreader";
|
||||
rev = version;
|
||||
hash = "sha256-cp/pZ42AS98AD78BVMeY3SHQHkYA2h4o0kddr/H+kUA=";
|
||||
rev = finalAttrs.version;
|
||||
hash = "sha256-upX2+Hwdss7OfIWFg5MALoF9LIw5mk6+NYR+NEbcDX4=";
|
||||
};
|
||||
|
||||
nativeBuildInputs = [
|
||||
@@ -92,4 +92,4 @@ document formats like PDF and Postscript";
|
||||
platforms = lib.platforms.linux;
|
||||
teams = [ lib.teams.cinnamon ];
|
||||
};
|
||||
}
|
||||
})
|
||||
|
||||
@@ -31,16 +31,16 @@
|
||||
gitUpdater,
|
||||
}:
|
||||
|
||||
stdenv.mkDerivation rec {
|
||||
stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "atril";
|
||||
version = "1.28.2";
|
||||
version = "1.28.5";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "mate-desktop";
|
||||
repo = "atril";
|
||||
tag = "v${version}";
|
||||
tag = "v${finalAttrs.version}";
|
||||
fetchSubmodules = true;
|
||||
hash = "sha256-NnWD3Gcxn8ZZKdHzg6iclLiSwj3sBvF+BwpNtcU+dSY=";
|
||||
hash = "sha256-iG+FFvxxL2/6HqGchoaIDqx8Gfo1wxqM4GW66ScZlao=";
|
||||
};
|
||||
|
||||
nativeBuildInputs = [
|
||||
@@ -73,7 +73,11 @@ stdenv.mkDerivation rec {
|
||||
configureFlags =
|
||||
[ ]
|
||||
++ lib.optionals enableDjvu [ "--enable-djvu" ]
|
||||
++ lib.optionals enableEpub [ "--enable-epub" ]
|
||||
++ lib.optionals enableEpub [
|
||||
# FIXME: We ship this with non-existent fallback mathjax-directory
|
||||
# because `MathJax.js` is only available in MathJax 2.7.x.
|
||||
"--enable-epub"
|
||||
]
|
||||
++ lib.optionals enablePostScript [ "--enable-ps" ]
|
||||
++ lib.optionals enableXps [ "--enable-xps" ]
|
||||
++ lib.optionals enableImages [ "--enable-pixbuf" ];
|
||||
@@ -96,4 +100,4 @@ stdenv.mkDerivation rec {
|
||||
platforms = lib.platforms.unix;
|
||||
teams = [ lib.teams.mate ];
|
||||
};
|
||||
}
|
||||
})
|
||||
|
||||
@@ -5,18 +5,18 @@
|
||||
"lts": false
|
||||
},
|
||||
"6.1": {
|
||||
"version": "6.1.173",
|
||||
"hash": "sha256:163dhycch5pw1vc87mm13djghwwyz182ljway5w19hz8zdn2rwy4",
|
||||
"version": "6.1.174",
|
||||
"hash": "sha256:0vp07x4v82qnmc1pifv3ynp2ab5mvlbfnpqvs5893bi3yrnk927d",
|
||||
"lts": true
|
||||
},
|
||||
"5.15": {
|
||||
"version": "5.15.207",
|
||||
"hash": "sha256:13hlwrfi7hp3lxg5v4kx5ykycb64iwc7xhg4rbjk0pvl0yipzssh",
|
||||
"version": "5.15.208",
|
||||
"hash": "sha256:0wmi50q8vgblhbh77d1a4sw4snymr6srqd22bxcjg9i7wcv70gdm",
|
||||
"lts": true
|
||||
},
|
||||
"5.10": {
|
||||
"version": "5.10.256",
|
||||
"hash": "sha256:0pwf9nsr7clqm0bxvyrp3k79d5i6f9xqq58i31xvvra1xk4dmsgi",
|
||||
"version": "5.10.257",
|
||||
"hash": "sha256:1lghcrxc1fqarvym03jrcda2a3labc887ci9yjqgbmv3nphzvc88",
|
||||
"lts": true
|
||||
},
|
||||
"6.6": {
|
||||
|
||||
@@ -12,13 +12,13 @@ let
|
||||
# override options if they need using lib.mkForce (that has 50 priority)
|
||||
mkKernelOverride = lib.mkOverride 90;
|
||||
|
||||
suffix = "zen2";
|
||||
suffix = "zen1";
|
||||
in
|
||||
|
||||
buildLinux (
|
||||
args
|
||||
// rec {
|
||||
version = "7.0.9";
|
||||
version = "7.0.10";
|
||||
pname = "linux-zen";
|
||||
modDirVersion = lib.versions.pad 3 "${version}-${suffix}";
|
||||
isZen = true;
|
||||
@@ -27,7 +27,7 @@ buildLinux (
|
||||
owner = "zen-kernel";
|
||||
repo = "zen-kernel";
|
||||
rev = "v${version}-${suffix}";
|
||||
sha256 = "1x2s9pv8frq77fish833mnwrrdglxssbqrsjnnizj3ayylw41qkd";
|
||||
sha256 = "1xh7bbis9v7yq2s1zwdnmsx54zz9kcmyn1cnrqqlsassk7fzl7nx";
|
||||
};
|
||||
|
||||
# This is based on the following source:
|
||||
|
||||
@@ -47,5 +47,10 @@ callPackage ./generic.nix args {
|
||||
url = "https://github.com/nginx/nginx/commit/39d7d0ba0799fcff6baee52b6525f45739593cfd.patch";
|
||||
hash = "sha256-6PwV0iz4kQGGBwVk9129aH+TFzbSx3QSVpp22AoKQY4=";
|
||||
})
|
||||
(fetchpatch {
|
||||
name = "CVE-2026-9256.patch";
|
||||
url = "https://github.com/nginx/nginx/commit/ca4f92a27464ae6c2082245e4f67048c633aa032.patch";
|
||||
hash = "sha256-tf3KNIki5m8ADj+ghhSlVOsmY5yoLI1HH6/MID+UxbM=";
|
||||
})
|
||||
];
|
||||
}
|
||||
|
||||
@@ -36,5 +36,10 @@ callPackage ./generic.nix args {
|
||||
url = "https://github.com/nginx/nginx/commit/39d7d0ba0799fcff6baee52b6525f45739593cfd.patch";
|
||||
hash = "sha256-6PwV0iz4kQGGBwVk9129aH+TFzbSx3QSVpp22AoKQY4=";
|
||||
})
|
||||
(fetchpatch {
|
||||
name = "CVE-2026-9256.patch";
|
||||
url = "https://github.com/nginx/nginx/commit/ca4f92a27464ae6c2082245e4f67048c633aa032.patch";
|
||||
hash = "sha256-tf3KNIki5m8ADj+ghhSlVOsmY5yoLI1HH6/MID+UxbM=";
|
||||
})
|
||||
];
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user