From bba8b3a2a9bdb1f7407986047ef3ce3f75df1be8 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Gutyina=20Gerg=C5=91?= Date: Tue, 3 Mar 2026 12:18:25 +0100 Subject: [PATCH 001/117] cisco-packet-tracer_9: add mime files This fixes the system not recognizing file types like .pkt and not opening them with packet tracer. --- pkgs/by-name/ci/cisco-packet-tracer_9/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/ci/cisco-packet-tracer_9/package.nix b/pkgs/by-name/ci/cisco-packet-tracer_9/package.nix index 4dba6142cfc4..cb146023df08 100644 --- a/pkgs/by-name/ci/cisco-packet-tracer_9/package.nix +++ b/pkgs/by-name/ci/cisco-packet-tracer_9/package.nix @@ -75,6 +75,8 @@ appimageTools.wrapType2 rec { install -Dm444 ${contents}/usr/share/icons/hicolor/48x48/apps/app.png $out/share/icons/hicolor/48x48/apps/cisco-packet-tracer-9.png cp -r ${contents}/usr/share/icons/gnome/48x48/mimetypes $out/share/icons/hicolor/48x48/ + cp -r ${contents}/usr/share/mime $out/share/ + for desktop in $out/share/applications/*.desktop; do sed -i '/^\[Desktop Entry\]/a StartupWMClass=PacketTracer' "$desktop" done From 51a9e8c3dbbcb84b35b81fdef68d3ffa458824bf Mon Sep 17 00:00:00 2001 From: Sandro Date: Thu, 11 Jun 2026 17:24:36 +0200 Subject: [PATCH 002/117] nixos/installer: fix defaultText rendering as plain string --- nixos/modules/installer/tools/tools.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nixos/modules/installer/tools/tools.nix b/nixos/modules/installer/tools/tools.nix index 8fd268ee0d2d..8cc045304da2 100644 --- a/nixos/modules/installer/tools/tools.nix +++ b/nixos/modules/installer/tools/tools.nix @@ -287,7 +287,7 @@ in { options.system.tools.${name}.enable = lib.mkEnableOption "${name} script" // { default = config.nix.enable && !config.system.disableInstallerTools; - defaultText = "config.nix.enable && !config.system.disableInstallerTools"; + defaultText = lib.literalExpression "config.nix.enable && !config.system.disableInstallerTools"; }; config = lib.mkIf config.system.tools.${name}.enable { From 6ac56136e5ca34117b18f98cae244b934182a0c8 Mon Sep 17 00:00:00 2001 From: Felix Stupp Date: Tue, 16 Jun 2026 00:25:37 +0000 Subject: [PATCH 003/117] nixos/adguardhome: allow AF_UNIX when log.file=="syslog" --- nixos/modules/services/networking/adguardhome.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/nixos/modules/services/networking/adguardhome.nix b/nixos/modules/services/networking/adguardhome.nix index 1df503146b54..9a0eec481062 100644 --- a/nixos/modules/services/networking/adguardhome.nix +++ b/nixos/modules/services/networking/adguardhome.nix @@ -228,6 +228,8 @@ in "AF_INET" "AF_INET6" ] + # AF_UNIX to be able to connect to e.g. /dev/log + ++ lib.optionals (cfg.settings.log.file or "" == "syslog") [ "AF_UNIX" ] ++ lib.optionals cfg.allowDHCP [ "AF_PACKET" ]; RestrictNamespaces = true; RestrictRealtime = true; From 8c75f138ffdd6ab8dbc6eeb82d1144ef83db3b33 Mon Sep 17 00:00:00 2001 From: Felix Stupp Date: Tue, 16 Jun 2026 00:26:41 +0000 Subject: [PATCH 004/117] nixos/adguardhome: add tests ensuring logging to syslog works --- nixos/tests/adguardhome.nix | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/nixos/tests/adguardhome.nix b/nixos/tests/adguardhome.nix index 48bed55e3187..9c8b90cebcd8 100644 --- a/nixos/tests/adguardhome.nix +++ b/nixos/tests/adguardhome.nix @@ -22,6 +22,14 @@ }; }; + syslogConf = { + services.adguardhome = { + enable = true; + + settings.log.file = "syslog"; + }; + }; + declarativeConf = { services.adguardhome = { enable = true; @@ -122,6 +130,12 @@ schemaVersionBefore23.wait_for_unit("adguardhome.service") schemaVersionBefore23.wait_for_open_port(3000) + with subtest("Logging to syslog test"): + # AdGuard is expected to fail when it cannot connect to syslog + # hence its sufficient to look whether the service starts at all + syslogConf.wait_for_unit("adguardhome.service") + syslogConf.wait_for_open_port(3000) + with subtest("Declarative config test, DNS will be reachable"): declarativeConf.wait_for_unit("adguardhome.service") declarativeConf.wait_for_open_port(53) From d611102d5d22b20f2695d33ab5ee2753f2ad21ee Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Niklas=20Hamb=C3=BCchen?= Date: Thu, 20 Aug 2026 12:40:12 +0000 Subject: [PATCH 005/117] ceph: 20.2.3 -> 20.2.4 --- nixos/tests/ceph-single-node-bluestore.nix | 34 +++++++++++++++------- pkgs/by-name/ce/ceph/src.nix | 4 +-- 2 files changed, 25 insertions(+), 13 deletions(-) diff --git a/nixos/tests/ceph-single-node-bluestore.nix b/nixos/tests/ceph-single-node-bluestore.nix index f65241629ee5..e6629d59b397 100644 --- a/nixos/tests/ceph-single-node-bluestore.nix +++ b/nixos/tests/ceph-single-node-bluestore.nix @@ -9,17 +9,14 @@ let }; osd0 = { name = "0"; - key = "AQBCEJNa3s8nHRAANvdsr93KqzBznuIWm2gOGg=="; uuid = "55ba2294-3e24-478f-bee0-9dca4c231dd9"; }; osd1 = { name = "1"; - key = "AQBEEJNac00kExAAXEgy943BGyOpVH1LLlHafQ=="; uuid = "5e97a838-85b6-43b0-8950-cb56d554d1e5"; }; osd2 = { name = "2"; - key = "AQAdyhZeIaUlARAAGRoidDAmS6Vkp546UFEf5w=="; uuid = "ea999274-13d0-4dd5-9af9-ad25a324f72f"; }; }; @@ -115,13 +112,18 @@ let "sudo -u ceph ceph-authtool --create-keyring /tmp/ceph.mon.keyring --gen-key -n mon. --cap mon 'allow *'", "sudo -u ceph ceph-authtool --create-keyring /etc/ceph/ceph.client.admin.keyring --gen-key -n client.admin --cap mon 'allow *' --cap osd 'allow *' --cap mds 'allow *' --cap mgr 'allow *'", "sudo -u ceph ceph-authtool /tmp/ceph.mon.keyring --import-keyring /etc/ceph/ceph.client.admin.keyring", - "monmaptool --create --add ${cfg.monA.name} ${cfg.monA.ip} --fsid ${cfg.clusterId} /tmp/monmap", + # Create the monmap with both a msgr2 (v2) and a legacy (v1) address. + # Using plain `--add` yields a v1-only monmap, which leaves the cluster + # in HEALTH_WARN with MON_MSGR2_NOT_ENABLED. Running `ceph mon + # enable-msgr2` afterwards is not enough: it rewrites the monmap (a + # subsequent `ceph mon dump` does show the v2 address), but the health + # check keeps reporting the mon as v1-only indefinitely. + "monmaptool --create --addv ${cfg.monA.name} '[v2:${cfg.monA.ip}:3300,v1:${cfg.monA.ip}:6789]' --fsid ${cfg.clusterId} /tmp/monmap", "sudo -u ceph ceph-mon --mkfs -i ${cfg.monA.name} --monmap /tmp/monmap --keyring /tmp/ceph.mon.keyring", "sudo -u ceph touch /var/lib/ceph/mon/ceph-${cfg.monA.name}/done", "systemctl start ceph-mon-${cfg.monA.name}", ) monA.wait_for_unit("ceph-mon-${cfg.monA.name}") - monA.succeed("ceph mon enable-msgr2") monA.succeed("ceph config set mon auth_allow_insecure_global_id_reclaim false") # Can't check ceph status until a mon is up @@ -148,14 +150,24 @@ let "mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd2.name}", "echo bluestore > /var/lib/ceph/osd/ceph-${cfg.osd2.name}/type", "ln -sf /dev/vdd /var/lib/ceph/osd/ceph-${cfg.osd2.name}/block", - "ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd0.name}/keyring --name osd.${cfg.osd0.name} --add-key ${cfg.osd0.key}", - "ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd1.name}/keyring --name osd.${cfg.osd1.name} --add-key ${cfg.osd1.key}", - "ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd2.name}/keyring --name osd.${cfg.osd2.name} --add-key ${cfg.osd2.key}", - 'echo \'{"cephx_secret": "${cfg.osd0.key}"}\' | ceph osd new ${cfg.osd0.uuid} -i -', - 'echo \'{"cephx_secret": "${cfg.osd1.key}"}\' | ceph osd new ${cfg.osd1.uuid} -i -', - 'echo \'{"cephx_secret": "${cfg.osd2.key}"}\' | ceph osd new ${cfg.osd2.uuid} -i -', + "ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd0.name}/keyring --name osd.${cfg.osd0.name} --gen-key", + "ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd1.name}/keyring --name osd.${cfg.osd1.name} --gen-key", + "ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd2.name}/keyring --name osd.${cfg.osd2.name} --gen-key", ) + # Register the OSDs with the generated keys read back from their keyrings. + for osd_name, osd_uuid in [ + ("${cfg.osd0.name}", "${cfg.osd0.uuid}"), + ("${cfg.osd1.name}", "${cfg.osd1.uuid}"), + ("${cfg.osd2.name}", "${cfg.osd2.uuid}"), + ]: + key = monA.succeed( + f"ceph-authtool --print-key /var/lib/ceph/osd/ceph-{osd_name}/keyring --name osd.{osd_name}" + ).strip() + monA.succeed( + f"echo '{{\"cephx_secret\": \"{key}\"}}' | ceph osd new {osd_uuid} -i -" + ) + # Initialize the OSDs with regular filestore monA.succeed( "ceph-osd -i ${cfg.osd0.name} --mkfs --osd-uuid ${cfg.osd0.uuid}", diff --git a/pkgs/by-name/ce/ceph/src.nix b/pkgs/by-name/ce/ceph/src.nix index 71baf1bf3667..4bf3475af3dd 100644 --- a/pkgs/by-name/ce/ceph/src.nix +++ b/pkgs/by-name/ce/ceph/src.nix @@ -6,11 +6,11 @@ applyPatches (final: { pname = "ceph-src"; - version = "20.2.3"; + version = "20.2.4"; src = fetchurl { url = "https://download.ceph.com/tarballs/ceph-${final.version}.tar.gz"; - hash = "sha256-y3bZm2lkHiebXYNbZA7jN4VXCLaDEElYvpyuglLISi0="; + hash = "sha256-XzRWkkGiiQRGuTHwbNhE+TvKZl90CiBjFCnS1Vsemzc="; }; patches = [ From 23fb8b42d4677d3dc849e7f80e4d2516f5cad084 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Niklas=20Hamb=C3=BCchen?= Date: Thu, 20 Aug 2026 12:40:24 +0000 Subject: [PATCH 006/117] rl: Mention recommended Ceph vulnerability key rotation --- doc/release-notes/rl-2611.section.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/doc/release-notes/rl-2611.section.md b/doc/release-notes/rl-2611.section.md index 51c0a4e2ccb7..e5ee3715fb7c 100644 --- a/doc/release-notes/rl-2611.section.md +++ b/doc/release-notes/rl-2611.section.md @@ -184,6 +184,10 @@ To prevent loading the `early-default` library, set `inhibit-early-default-init` in `early-init.el`. +- Ceph has a vulnerability in old generated CephX keys. + The project recommends to rotate old keys. + This is a manual process, see https://ceph.io/en/news/blog/2026/v20-2-4-v19-2-6-combo-released + - `services.ceph` enabled the generation of Ceph log files at `/var/log/ceph/`. They were missing before because Ceph omitted logs when this directory was missing. Ceph logs can grow large, so you may want to configure rotation of these logs. From 2888c1ab837dcc3cd35a4054772ea3c4f5b559f1 Mon Sep 17 00:00:00 2001 From: benaryorg Date: Tue, 25 Aug 2026 03:20:20 +0000 Subject: [PATCH 007/117] ceph.tests: latest linux kernel This is required for the tests to pass since the `aes256k` cipher (the secure one) is only available since version 7.0. Signed-off-by: benaryorg --- nixos/tests/ceph-multi-node-bluestore.nix | 5 +++++ nixos/tests/ceph-multi-node-deprecated-filestore.nix | 5 +++++ nixos/tests/ceph-single-node-bluestore-dmcrypt.nix | 5 +++++ nixos/tests/ceph-single-node-bluestore.nix | 5 +++++ nixos/tests/ceph-single-node-deprecated-filestore.nix | 5 +++++ 5 files changed, 25 insertions(+) diff --git a/nixos/tests/ceph-multi-node-bluestore.nix b/nixos/tests/ceph-multi-node-bluestore.nix index 96fefca78230..a4e7b8fd047a 100644 --- a/nixos/tests/ceph-multi-node-bluestore.nix +++ b/nixos/tests/ceph-multi-node-bluestore.nix @@ -209,6 +209,11 @@ let vlans = [ 1 ]; }; + # Ceph 20.2.4 introduced the aes256k cipher for authentication. + # Linux started supporting these in kernel version 7.0. + # Remove this line at the earliest convenience (i.e. when tests are run by 7.0 or higher by default). + boot.kernelPackages = pkgs.linuxPackages_latest; + networking = networkConfig; environment.systemPackages = with pkgs; [ diff --git a/nixos/tests/ceph-multi-node-deprecated-filestore.nix b/nixos/tests/ceph-multi-node-deprecated-filestore.nix index 992a74f72972..f0705dece1ae 100644 --- a/nixos/tests/ceph-multi-node-deprecated-filestore.nix +++ b/nixos/tests/ceph-multi-node-deprecated-filestore.nix @@ -47,6 +47,11 @@ let vlans = [ 1 ]; }; + # Ceph 20.2.4 introduced the aes256k cipher for authentication. + # Linux started supporting these in kernel version 7.0. + # Remove this line at the earliest convenience (i.e. when tests are run by 7.0 or higher by default). + boot.kernelPackages = pkgs.linuxPackages_latest; + networking = networkConfig; environment.systemPackages = with pkgs; [ diff --git a/nixos/tests/ceph-single-node-bluestore-dmcrypt.nix b/nixos/tests/ceph-single-node-bluestore-dmcrypt.nix index 8ab8cbba3a62..a5782abbc7c8 100644 --- a/nixos/tests/ceph-single-node-bluestore-dmcrypt.nix +++ b/nixos/tests/ceph-single-node-bluestore-dmcrypt.nix @@ -34,6 +34,11 @@ in 20480 ]; + # Ceph 20.2.4 introduced the aes256k cipher for authentication. + # Linux started supporting these in kernel version 7.0. + # Remove this line at the earliest convenience (i.e. when tests are run by 7.0 or higher by default). + boot.kernelPackages = pkgs.linuxPackages_latest; + # networking setup (no external connectivity required, only local IPv6) networking.useDHCP = false; systemd.network = { diff --git a/nixos/tests/ceph-single-node-bluestore.nix b/nixos/tests/ceph-single-node-bluestore.nix index e6629d59b397..192f6de94a84 100644 --- a/nixos/tests/ceph-single-node-bluestore.nix +++ b/nixos/tests/ceph-single-node-bluestore.nix @@ -48,6 +48,11 @@ let vlans = [ 1 ]; }; + # Ceph 20.2.4 introduced the aes256k cipher for authentication. + # Linux started supporting these in kernel version 7.0. + # Remove this line at the earliest convenience (i.e. when tests are run by 7.0 or higher by default). + boot.kernelPackages = pkgs.linuxPackages_latest; + networking = networkConfig; environment.systemPackages = with pkgs; [ diff --git a/nixos/tests/ceph-single-node-deprecated-filestore.nix b/nixos/tests/ceph-single-node-deprecated-filestore.nix index 715f7bed9da6..dd8e09f3e1cf 100644 --- a/nixos/tests/ceph-single-node-deprecated-filestore.nix +++ b/nixos/tests/ceph-single-node-deprecated-filestore.nix @@ -52,6 +52,11 @@ let vlans = [ 1 ]; }; + # Ceph 20.2.4 introduced the aes256k cipher for authentication. + # Linux started supporting these in kernel version 7.0. + # Remove this line at the earliest convenience (i.e. when tests are run by 7.0 or higher by default). + boot.kernelPackages = pkgs.linuxPackages_latest; + networking = networkConfig; environment.systemPackages = with pkgs; [ From edf461ab8b21f044141b4c62d0519e3ac3e73e0d Mon Sep 17 00:00:00 2001 From: benaryorg Date: Tue, 25 Aug 2026 04:02:35 +0000 Subject: [PATCH 008/117] ceph.tests: dashboard test in multi-node setup Signed-off-by: benaryorg --- nixos/tests/ceph-multi-node-bluestore.nix | 68 +++++++++++++++++++++++ 1 file changed, 68 insertions(+) diff --git a/nixos/tests/ceph-multi-node-bluestore.nix b/nixos/tests/ceph-multi-node-bluestore.nix index a4e7b8fd047a..60887bc2431f 100644 --- a/nixos/tests/ceph-multi-node-bluestore.nix +++ b/nixos/tests/ceph-multi-node-bluestore.nix @@ -145,6 +145,11 @@ let enable = true; daemons = [ cfg.monA.name ]; }; + # TODO: move this to a separate machine + rgw = { + enable = true; + daemons = [ cfg.monA.name ]; + }; } # The MDS daemon (which provides CephFS) is only configured in the CephFS # variant of this test. @@ -290,6 +295,8 @@ let # Based on the "manual deployment" approach from: # https://docs.ceph.com/en/tentacle/install/manual-deployment/ baseScript = '' + import json + start_all() monA.wait_for_unit("network.target") @@ -401,6 +408,67 @@ let "ceph osd pool delete multi-node-other-test multi-node-other-test --yes-i-really-really-mean-it", ) + # Bootstrap RGW + monA.succeed( + "sudo -u ceph mkdir -p /var/lib/ceph/radosgw/ceph-${cfg.monA.name}", + "ceph auth get-or-create client.${cfg.monA.name} osd 'allow rwx' mon 'allow rw' > /var/lib/ceph/radosgw/ceph-${cfg.monA.name}/keyring", + "chown ceph:ceph /var/lib/ceph/radosgw/ceph-${cfg.monA.name}/keyring", + "systemctl start ceph-rgw-${cfg.monA.name}", + ) + monA.wait_for_unit("ceph-rgw-${cfg.monA.name}") + monA.wait_for_open_port(7480) + + # Enable the dashboard and recheck health + monA.succeed( + "ceph mgr module enable dashboard", + "ceph config set mgr mgr/dashboard/ssl false", + # default is 8080 but it's better to be explicit + "ceph config set mgr mgr/dashboard/server_port 8080", + ) + + # The dashboard does not listen on localhost: + # `server_addr` defaults to the wildcard address, but the dashboard module + # resolves that to the active mgr's own IP and binds only to it, + # so loopback is never bound. + # See https://github.com/ceph/ceph/blob/v20.2.2/src/pybind/mgr/dashboard/module.py#L213-L214 + # Therefore address the dashboard via the mgr's IP instead of localhost. + dashboard = "http://${cfg.monA.ip}:8080" + + monA.wait_for_open_port(8080, addr="${cfg.monA.ip}") + monA.wait_until_succeeds(f"curl -q --fail {dashboard}") + monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") + + # Initialize dashboard creds. + # In a the query below, we test the Dashboard's `/api/rgw/daemon`, + # which needs that the dashboard can talk to RGW. + # `set-rgw-credentials` needs a running RGW daemon. + monA.succeed( + "echo 'foo bar baz qux' > /tmp/dashboard_pw", + "ceph dashboard ac-user-create admin -i /tmp/dashboard_pw administrator", + "ceph dashboard set-rgw-credentials", + "sync", + ) + + # Get dashboard auth token + auth_payload = json.dumps({"username": "admin", "password": "foo bar baz qux"}) + auth_response = json.loads(monA.succeed( + f"curl --fail -s -X POST -H 'Accept: application/vnd.ceph.api.v1.0+json' -H 'Content-Type: application/json' -d '{auth_payload}' {dashboard}/api/auth", + )) + token = auth_response["token"] + + # Check cluster health via dashboard API + health = json.loads(monA.succeed( + f"curl --fail -s -H 'Accept: application/vnd.ceph.api.v1.0+json' -H 'Authorization: Bearer {token}' {dashboard}/api/health/minimal", + )) + assert health["health"]["status"] == "HEALTH_OK" + + # List daemons via REST API. + # This also requires a running RGW daemon, as it asserts on the first one. + rgw_daemons = json.loads(monA.succeed( + f"curl --fail -s -H 'Accept: application/vnd.ceph.api.v1.0+json' -H 'Authorization: Bearer {token}' {dashboard}/api/rgw/daemon", + )) + assert rgw_daemons[0]["id"] == "${cfg.monA.name}" + # Shut down ceph on all machines in a very unpolite way monA.crash() osd0.crash() From 0fdef1d59a9518a98f4cc59805509d70d2aaa959 Mon Sep 17 00:00:00 2001 From: benaryorg Date: Tue, 25 Aug 2026 04:04:28 +0000 Subject: [PATCH 009/117] ceph.tests: cleanup of deprecated tests The old tests should be completely superseded by the new ones at this point. I left in the *ceph-single-node-bluestore* test because covering single node setups might be beneficial, even if it duplicates a lot of the code. However we should be able to trim down the single node code quite a bit, basically if RADOS works then we should be able to assume everything else works too, as long as the multi-node tests pass. Signed-off-by: benaryorg --- nixos/tests/all-tests.nix | 12 - nixos/tests/ceph-multi-node-bluestore.nix | 1 + .../ceph-multi-node-deprecated-filestore.nix | 296 ------------------ .../ceph-single-node-bluestore-dmcrypt.nix | 274 ---------------- .../ceph-single-node-deprecated-filestore.nix | 254 --------------- pkgs/by-name/ce/ceph/ceph.nix | 3 - 6 files changed, 1 insertion(+), 839 deletions(-) delete mode 100644 nixos/tests/ceph-multi-node-deprecated-filestore.nix delete mode 100644 nixos/tests/ceph-single-node-bluestore-dmcrypt.nix delete mode 100644 nixos/tests/ceph-single-node-deprecated-filestore.nix diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index 47c566171e56..745561b37cfc 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -345,22 +345,10 @@ in ceph-multi-node-bluestore-cephfs = runTestOn [ "aarch64-linux" "x86_64-linux" ] ( import ./ceph-multi-node-bluestore.nix { withCephfs = true; } ); - ceph-multi-node-deprecated-filestore = runTestOn [ - "aarch64-linux" - "x86_64-linux" - ] ./ceph-multi-node-deprecated-filestore.nix; ceph-single-node-bluestore = runTestOn [ "aarch64-linux" "x86_64-linux" ] ./ceph-single-node-bluestore.nix; - ceph-single-node-bluestore-dmcrypt = runTestOn [ - "aarch64-linux" - "x86_64-linux" - ] ./ceph-single-node-bluestore-dmcrypt.nix; - ceph-single-node-deprecated-filestore = runTestOn [ - "aarch64-linux" - "x86_64-linux" - ] ./ceph-single-node-deprecated-filestore.nix; certmgr = import ./certmgr.nix { inherit pkgs runTest; }; cfssl = runTestOn [ "aarch64-linux" "x86_64-linux" ] ./cfssl.nix; cgit = runTest ./cgit.nix; diff --git a/nixos/tests/ceph-multi-node-bluestore.nix b/nixos/tests/ceph-multi-node-bluestore.nix index 60887bc2431f..57b60d63b2ac 100644 --- a/nixos/tests/ceph-multi-node-bluestore.nix +++ b/nixos/tests/ceph-multi-node-bluestore.nix @@ -401,6 +401,7 @@ let "ceph osd pool ls | grep 'multi-node-other-test'", ) monA.succeed("ceph osd pool set multi-node-other-test size 2") + # TODO: actually write to the pool using rados directly monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") monA.wait_until_succeeds("! ceph -s | grep -e 'unknown' -e 'pgs inactive'") monA.fail( diff --git a/nixos/tests/ceph-multi-node-deprecated-filestore.nix b/nixos/tests/ceph-multi-node-deprecated-filestore.nix deleted file mode 100644 index f0705dece1ae..000000000000 --- a/nixos/tests/ceph-multi-node-deprecated-filestore.nix +++ /dev/null @@ -1,296 +0,0 @@ -# Tests the legacy FileStore OSD backend. -{ lib, ... }: -let - cfg = { - clusterId = "066ae264-2a5d-4729-8001-6ad265f50b03"; - monA = { - name = "a"; - ip = "192.168.1.1"; - }; - osd0 = { - name = "0"; - ip = "192.168.1.2"; - key = "AQBCEJNa3s8nHRAANvdsr93KqzBznuIWm2gOGg=="; - uuid = "55ba2294-3e24-478f-bee0-9dca4c231dd9"; - }; - osd1 = { - name = "1"; - ip = "192.168.1.3"; - key = "AQBEEJNac00kExAAXEgy943BGyOpVH1LLlHafQ=="; - uuid = "5e97a838-85b6-43b0-8950-cb56d554d1e5"; - }; - osd2 = { - name = "2"; - ip = "192.168.1.4"; - key = "AQAdyhZeIaUlARAAGRoidDAmS6Vkp546UFEf5w=="; - uuid = "ea999274-13d0-4dd5-9af9-ad25a324f72f"; - }; - }; - generateCephConfig = - { daemonConfig }: - { - enable = true; - global = { - fsid = cfg.clusterId; - monHost = cfg.monA.ip; - monInitialMembers = cfg.monA.name; - }; - } - // daemonConfig; - - generateHost = - { cephConfig, networkConfig }: - { pkgs, ... }: - { - virtualisation = { - emptyDiskImages = [ 20480 ]; - vlans = [ 1 ]; - }; - - # Ceph 20.2.4 introduced the aes256k cipher for authentication. - # Linux started supporting these in kernel version 7.0. - # Remove this line at the earliest convenience (i.e. when tests are run by 7.0 or higher by default). - boot.kernelPackages = pkgs.linuxPackages_latest; - - networking = networkConfig; - - environment.systemPackages = with pkgs; [ - bash - sudo - ceph - xfsprogs - netcat - ]; - - boot.kernelModules = [ "xfs" ]; - - services.ceph = cephConfig; - }; - - networkMonA = { - dhcpcd.enable = false; - interfaces.eth1.ipv4.addresses = lib.mkOverride 0 [ - { - address = cfg.monA.ip; - prefixLength = 24; - } - ]; - firewall = { - allowedTCPPorts = [ - 6789 - 3300 - ]; - allowedTCPPortRanges = [ - { - from = 6800; - to = 7300; - } - ]; - }; - }; - cephConfigMonA = generateCephConfig { - daemonConfig = { - mon = { - enable = true; - daemons = [ cfg.monA.name ]; - }; - mgr = { - enable = true; - daemons = [ cfg.monA.name ]; - }; - }; - }; - - networkOsd = osd: { - dhcpcd.enable = false; - interfaces.eth1.ipv4.addresses = lib.mkOverride 0 [ - { - address = osd.ip; - prefixLength = 24; - } - ]; - firewall = { - allowedTCPPortRanges = [ - { - from = 6800; - to = 7300; - } - ]; - }; - }; - - cephConfigOsd = - osd: - generateCephConfig { - daemonConfig = { - osd = { - enable = true; - daemons = [ osd.name ]; - }; - }; - }; - - # Following deployment is based on the manual deployment described here: - # https://docs.ceph.com/docs/master/install/manual-deployment/ - # For other ways to deploy a ceph cluster, look at the documentation at - # https://docs.ceph.com/docs/master/ - testscript = - { ... }: - '' - start_all() - - monA.wait_for_unit("network.target") - osd0.wait_for_unit("network.target") - osd1.wait_for_unit("network.target") - osd2.wait_for_unit("network.target") - - # Bootstrap ceph-mon daemon - monA.succeed( - "sudo -u ceph ceph-authtool --create-keyring /tmp/ceph.mon.keyring --gen-key -n mon. --cap mon 'allow *'", - "sudo -u ceph ceph-authtool --create-keyring /etc/ceph/ceph.client.admin.keyring --gen-key -n client.admin --cap mon 'allow *' --cap osd 'allow *' --cap mds 'allow *' --cap mgr 'allow *'", - "sudo -u ceph ceph-authtool /tmp/ceph.mon.keyring --import-keyring /etc/ceph/ceph.client.admin.keyring", - "monmaptool --create --add ${cfg.monA.name} ${cfg.monA.ip} --fsid ${cfg.clusterId} /tmp/monmap", - "sudo -u ceph ceph-mon --mkfs -i ${cfg.monA.name} --monmap /tmp/monmap --keyring /tmp/ceph.mon.keyring", - "sudo -u ceph mkdir -p /var/lib/ceph/mgr/ceph-${cfg.monA.name}/", - "sudo -u ceph touch /var/lib/ceph/mon/ceph-${cfg.monA.name}/done", - "systemctl start ceph-mon-${cfg.monA.name}", - ) - monA.wait_for_unit("ceph-mon-${cfg.monA.name}") - monA.succeed("ceph mon enable-msgr2") - monA.succeed("ceph config set mon auth_allow_insecure_global_id_reclaim false") - - # Can't check ceph status until a mon is up - monA.succeed("ceph -s | grep 'mon: 1 daemons'") - - # Start the ceph-mgr daemon, it has no deps and hardly any setup - monA.succeed( - "ceph auth get-or-create mgr.${cfg.monA.name} mon 'allow profile mgr' osd 'allow *' mds 'allow *' > /var/lib/ceph/mgr/ceph-${cfg.monA.name}/keyring", - "sync", # to ensure shell redirection above is durable - "systemctl start ceph-mgr-${cfg.monA.name}", - ) - monA.wait_for_unit("ceph-mgr-a") - monA.wait_until_succeeds("ceph -s | grep 'quorum ${cfg.monA.name}'") - monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'") - - # Send the admin keyring to the OSD machines - monA.succeed("cp /etc/ceph/ceph.client.admin.keyring /tmp/shared") - osd0.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph") - osd1.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph") - osd2.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph") - - # Bootstrap OSDs - osd0.succeed( - "mkfs.xfs /dev/vdb", - "mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd0.name}", - "mount /dev/vdb /var/lib/ceph/osd/ceph-${cfg.osd0.name}", - "ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd0.name}/keyring --name osd.${cfg.osd0.name} --add-key ${cfg.osd0.key}", - 'echo \'{"cephx_secret": "${cfg.osd0.key}"}\' | ceph osd new ${cfg.osd0.uuid} -i -', - ) - osd1.succeed( - "mkfs.xfs /dev/vdb", - "mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd1.name}", - "mount /dev/vdb /var/lib/ceph/osd/ceph-${cfg.osd1.name}", - "ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd1.name}/keyring --name osd.${cfg.osd1.name} --add-key ${cfg.osd1.key}", - 'echo \'{"cephx_secret": "${cfg.osd1.key}"}\' | ceph osd new ${cfg.osd1.uuid} -i -', - ) - osd2.succeed( - "mkfs.xfs /dev/vdb", - "mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd2.name}", - "mount /dev/vdb /var/lib/ceph/osd/ceph-${cfg.osd2.name}", - "ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd2.name}/keyring --name osd.${cfg.osd2.name} --add-key ${cfg.osd2.key}", - 'echo \'{"cephx_secret": "${cfg.osd2.key}"}\' | ceph osd new ${cfg.osd2.uuid} -i -', - ) - - # We `sync` so that the config survives the forced crashes below. - osd0.succeed( - "ceph-osd -i ${cfg.osd0.name} --mkfs --osd-uuid ${cfg.osd0.uuid}", - "chown -R ceph:ceph /var/lib/ceph/osd", - "sync", - "systemctl start ceph-osd-${cfg.osd0.name}", - ) - osd1.succeed( - "ceph-osd -i ${cfg.osd1.name} --mkfs --osd-uuid ${cfg.osd1.uuid}", - "chown -R ceph:ceph /var/lib/ceph/osd", - "sync", - "systemctl start ceph-osd-${cfg.osd1.name}", - ) - osd2.succeed( - "ceph-osd -i ${cfg.osd2.name} --mkfs --osd-uuid ${cfg.osd2.uuid}", - "chown -R ceph:ceph /var/lib/ceph/osd", - "sync", - "systemctl start ceph-osd-${cfg.osd2.name}", - ) - monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'") - monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'") - monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") - - monA.succeed( - "ceph osd pool create multi-node-test 32 32", - "ceph osd pool ls | grep 'multi-node-test'", - - # We need to enable an application on the pool, otherwise it will - # stay unhealthy in state POOL_APP_NOT_ENABLED. - # Creating a CephFS would do this automatically, but we haven't done that here. - # See: https://docs.ceph.com/en/reef/rados/operations/pools/#associating-a-pool-with-an-application - # We use the custom application name "nixos-test" for this. - "ceph osd pool application enable multi-node-test nixos-test", - - "ceph osd pool rename multi-node-test multi-node-other-test", - "ceph osd pool ls | grep 'multi-node-other-test'", - ) - monA.wait_until_succeeds("ceph -s | grep '2 pools, 33 pgs'") - monA.succeed("ceph osd pool set multi-node-other-test size 2") - monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") - monA.wait_until_succeeds("ceph -s | grep '33 active+clean'") - monA.fail( - "ceph osd pool ls | grep 'multi-node-test'", - "ceph osd pool delete multi-node-other-test multi-node-other-test --yes-i-really-really-mean-it", - ) - - # Shut down ceph on all machines in a very unpolite way - monA.crash() - osd0.crash() - osd1.crash() - osd2.crash() - - # Start it up - osd0.start() - osd1.start() - osd2.start() - monA.start() - - # Ensure the cluster comes back up again - monA.succeed("ceph -s | grep 'mon: 1 daemons'") - monA.wait_until_succeeds("ceph -s | grep 'quorum ${cfg.monA.name}'") - monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'") - monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'") - monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") - ''; -in -{ - name = "basic-multi-node-ceph-cluster-deprecated-filestore"; - meta = with lib.maintainers; { - maintainers = [ lejonet ]; - }; - - nodes = { - monA = generateHost { - cephConfig = cephConfigMonA; - networkConfig = networkMonA; - }; - osd0 = generateHost { - cephConfig = cephConfigOsd cfg.osd0; - networkConfig = networkOsd cfg.osd0; - }; - osd1 = generateHost { - cephConfig = cephConfigOsd cfg.osd1; - networkConfig = networkOsd cfg.osd1; - }; - osd2 = generateHost { - cephConfig = cephConfigOsd cfg.osd2; - networkConfig = networkOsd cfg.osd2; - }; - }; - - testScript = testscript; -} diff --git a/nixos/tests/ceph-single-node-bluestore-dmcrypt.nix b/nixos/tests/ceph-single-node-bluestore-dmcrypt.nix deleted file mode 100644 index a5782abbc7c8..000000000000 --- a/nixos/tests/ceph-single-node-bluestore-dmcrypt.nix +++ /dev/null @@ -1,274 +0,0 @@ -{ lib, ... }: - -let - # the single node ipv6 address - ip = "2001:db8:ffff::"; - # the global ceph cluster id - cluster = "54465b37-b9d8-4539-a1f9-dd33c75ee45a"; - # the fsids of OSDs - osd-fsid-map = { - "0" = "1c1b7ea9-06bf-4d30-9a01-37ac3a0254aa"; - "1" = "bd5a6f49-69d5-428c-ac25-a99f0c44375c"; - "2" = "c90de6c7-86c6-41da-9694-e794096dfc5c"; - }; -in -{ - name = "basic-single-node-ceph-cluster-bluestore-dmcrypt"; - meta.maintainers = with lib.maintainers; [ - benaryorg - nh2 - ]; - - nodes.ceph = - { - lib, - pkgs, - config, - ... - }: - { - # disks for bluestore - virtualisation.emptyDiskImages = [ - 20480 - 20480 - 20480 - ]; - - # Ceph 20.2.4 introduced the aes256k cipher for authentication. - # Linux started supporting these in kernel version 7.0. - # Remove this line at the earliest convenience (i.e. when tests are run by 7.0 or higher by default). - boot.kernelPackages = pkgs.linuxPackages_latest; - - # networking setup (no external connectivity required, only local IPv6) - networking.useDHCP = false; - systemd.network = { - enable = true; - wait-online.extraArgs = [ - "-i" - "lo" - ]; - networks = { - "40-loopback" = { - enable = true; - name = "lo"; - DHCP = "no"; - addresses = [ { Address = "${ip}/128"; } ]; - }; - }; - }; - - # do not start the ceph target by default so we can format the disks first - systemd.targets.ceph.wantedBy = lib.mkForce [ ]; - - # add the packages to systemPackages so the testscript doesn't run into any unexpected issues - # this shouldn't be required on production systems which have their required packages in the unit paths only - # but it helps in case one needs to actually run the tooling anyway - environment.systemPackages = with pkgs; [ - ceph - cryptsetup - lvm2 - ]; - - services.ceph = { - enable = true; - client.enable = true; - extraConfig = { - public_addr = ip; - cluster_addr = ip; - # ipv6 - ms_bind_ipv4 = "false"; - ms_bind_ipv6 = "true"; - # msgr2 settings - ms_cluster_mode = "secure"; - ms_service_mode = "secure"; - ms_client_mode = "secure"; - ms_mon_cluster_mode = "secure"; - ms_mon_service_mode = "secure"; - ms_mon_client_mode = "secure"; - # less default modules, cuts down on memory and startup time in the tests - mgr_initial_modules = ""; - # distribute by OSD, not by host, as per https://docs.ceph.com/en/reef/cephadm/install/#single-host - osd_crush_chooseleaf_type = "0"; - }; - client.extraConfig."mon.0" = { - host = "ceph"; - mon_addr = "v2:[${ip}]:3300"; - public_addr = "v2:[${ip}]:3300"; - }; - global = { - fsid = cluster; - clusterNetwork = "${ip}/64"; - publicNetwork = "${ip}/64"; - monInitialMembers = "0"; - }; - - mon = { - enable = true; - daemons = [ "0" ]; - }; - - osd = { - enable = true; - daemons = builtins.attrNames osd-fsid-map; - }; - - mgr = { - enable = true; - daemons = [ "ceph" ]; - }; - }; - - systemd.services = - let - osd-name = id: "ceph-osd-${id}"; - osd-pre-start = id: [ - "!${config.services.ceph.osd.package.out}/bin/ceph-volume lvm activate --bluestore ${id} ${osd-fsid-map.${id}} --no-systemd" - "${config.services.ceph.osd.package.lib}/libexec/ceph/ceph-osd-prestart.sh --id ${id} --cluster ${config.services.ceph.global.clusterName}" - ]; - osd-post-stop = id: [ - "!${config.services.ceph.osd.package.out}/bin/ceph-volume lvm deactivate ${id}" - ]; - map-osd = id: { - name = osd-name id; - value = { - serviceConfig.ExecStartPre = lib.mkForce (osd-pre-start id); - serviceConfig.ExecStopPost = osd-post-stop id; - unitConfig.ConditionPathExists = lib.mkForce [ ]; - unitConfig.StartLimitBurst = lib.mkForce 4; - path = with pkgs; [ - util-linux - lvm2 - cryptsetup - ]; - }; - }; - in - lib.pipe config.services.ceph.osd.daemons [ - (map map-osd) - builtins.listToAttrs - ]; - }; - - testScript = '' - start_all() - - ceph.wait_for_unit("default.target") - - # Bootstrap ceph-mon daemon - ceph.succeed( - "mkdir -p /var/lib/ceph/bootstrap-osd", - "ceph-authtool --create-keyring /tmp/ceph.mon.keyring --gen-key -n mon. --cap mon 'allow *'", - "ceph-authtool --create-keyring /etc/ceph/ceph.client.admin.keyring --gen-key -n client.admin --cap mon 'allow *' --cap osd 'allow *' --cap mds 'allow *' --cap mgr 'allow *'", - "ceph-authtool --create-keyring /var/lib/ceph/bootstrap-osd/ceph.keyring --gen-key -n client.bootstrap-osd --cap mon 'profile bootstrap-osd' --cap mgr 'allow r'", - "ceph-authtool /tmp/ceph.mon.keyring --import-keyring /etc/ceph/ceph.client.admin.keyring", - "ceph-authtool /tmp/ceph.mon.keyring --import-keyring /var/lib/ceph/bootstrap-osd/ceph.keyring", - "monmaptool --create --fsid ${cluster} --addv 0 'v2:[${ip}]:3300/0' --clobber /tmp/ceph.initial-monmap", - "mkdir -p /var/lib/ceph/mon/ceph-0", - "ceph-mon --mkfs -i 0 --monmap /tmp/ceph.initial-monmap --keyring /tmp/ceph.mon.keyring", - "chown ceph:ceph -R /tmp/ceph.mon.keyring /var/lib/ceph", - "systemctl start ceph-mon-0.service", - ) - - ceph.wait_for_unit("ceph-mon-0.service") - # should the mon not start or bind for some reason this gives us a better error message than the config commands running into a timeout - ceph.wait_for_open_port(3300, "${ip}") - ceph.succeed( - # required for HEALTH_OK - "ceph config set mon auth_allow_insecure_global_id_reclaim false", - # IPv6 - "ceph config set global ms_bind_ipv4 false", - "ceph config set global ms_bind_ipv6 true", - # the new (secure) protocol - "ceph config set global ms_bind_msgr1 false", - "ceph config set global ms_bind_msgr2 true", - # just a small little thing - "ceph config set mon mon_compact_on_start true", - ) - - # Can't check ceph status until a mon is up - ceph.succeed("ceph -s | grep 'mon: 1 daemons'") - - # Bootstrap OSDs (do this before starting the mgr because cryptsetup and the mgr both eat a lot of memory) - ceph.succeed( - # this will automatically do what's required for LVM, cryptsetup, and stores all the data in Ceph's internal databases - "ceph-volume lvm prepare --bluestore --data /dev/vdb --dmcrypt --no-systemd --osd-id 0 --osd-fsid ${osd-fsid-map."0"}", - "ceph-volume lvm prepare --bluestore --data /dev/vdc --dmcrypt --no-systemd --osd-id 1 --osd-fsid ${osd-fsid-map."1"}", - "ceph-volume lvm prepare --bluestore --data /dev/vdd --dmcrypt --no-systemd --osd-id 2 --osd-fsid ${osd-fsid-map."2"}", - "sudo ceph-volume lvm deactivate 0", - "sudo ceph-volume lvm deactivate 1", - "sudo ceph-volume lvm deactivate 2", - "chown -R ceph:ceph /var/lib/ceph", - ) - - # Start OSDs (again, argon2id eats memory, so this happens before starting the mgr) - ceph.succeed( - "systemctl start ceph-osd-0.service", - "systemctl start ceph-osd-1.service", - "systemctl start ceph-osd-2.service", - ) - ceph.wait_until_succeeds("ceph -s | grep 'quorum 0'") - ceph.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'") - - # Start the ceph-mgr daemon, after copying in the keyring - ceph.succeed( - "mkdir -p /var/lib/ceph/mgr/ceph-ceph/", - "ceph auth get-or-create -o /var/lib/ceph/mgr/ceph-ceph/keyring mgr.ceph mon 'allow profile mgr' osd 'allow *' mds 'allow *'", - "chown -R ceph:ceph /var/lib/ceph/mgr/ceph-ceph/", - "systemctl start ceph-mgr-ceph.service", - ) - ceph.wait_for_unit("ceph-mgr-ceph") - ceph.wait_until_succeeds("ceph -s | grep 'quorum 0'") - ceph.wait_until_succeeds("ceph -s | grep 'mgr: ceph(active,'") - ceph.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'") - ceph.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") - - # test the actual storage - ceph.succeed( - "ceph osd pool create single-node-test 32 32", - "ceph osd pool ls | grep 'single-node-test'", - - # We need to enable an application on the pool, otherwise it will - # stay unhealthy in state POOL_APP_NOT_ENABLED. - # Creating a CephFS would do this automatically, but we haven't done that here. - # See: https://docs.ceph.com/en/reef/rados/operations/pools/#associating-a-pool-with-an-application - # We use the custom application name "nixos-test" for this. - "ceph osd pool application enable single-node-test nixos-test", - - "ceph osd pool rename single-node-test single-node-other-test", - "ceph osd pool ls | grep 'single-node-other-test'", - ) - ceph.wait_until_succeeds("ceph -s | grep '2 pools, 33 pgs'") - ceph.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") - ceph.wait_until_succeeds("ceph -s | grep '33 active+clean'") - ceph.fail( - # the old pool should be gone - "ceph osd pool ls | grep 'multi-node-test'", - # deleting the pool should fail without setting mon_allow_pool_delete - "ceph osd pool delete single-node-other-test single-node-other-test --yes-i-really-really-mean-it", - ) - - # rebooting gets rid of any potential tmpfs mounts or device-mapper devices - ceph.shutdown() - ceph.start() - ceph.wait_for_unit("default.target") - - # Start it up (again OSDs first due to memory constraints of cryptsetup and mgr) - ceph.systemctl("start ceph-mon-0.service") - ceph.wait_for_unit("ceph-mon-0") - ceph.systemctl("start ceph-osd-0.service") - ceph.wait_for_unit("ceph-osd-0") - ceph.systemctl("start ceph-osd-1.service") - ceph.wait_for_unit("ceph-osd-1") - ceph.systemctl("start ceph-osd-2.service") - ceph.wait_for_unit("ceph-osd-2") - ceph.systemctl("start ceph-mgr-ceph.service") - ceph.wait_for_unit("ceph-mgr-ceph") - - # Ensure the cluster comes back up again - ceph.succeed("ceph -s | grep 'mon: 1 daemons'") - ceph.wait_until_succeeds("ceph -s | grep 'quorum 0'") - ceph.wait_until_succeeds("ceph osd stat | grep -E '3 osds: 3 up[^,]*, 3 in'") - ceph.wait_until_succeeds("ceph -s | grep 'mgr: ceph(active,'") - ceph.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") - ''; -} diff --git a/nixos/tests/ceph-single-node-deprecated-filestore.nix b/nixos/tests/ceph-single-node-deprecated-filestore.nix deleted file mode 100644 index dd8e09f3e1cf..000000000000 --- a/nixos/tests/ceph-single-node-deprecated-filestore.nix +++ /dev/null @@ -1,254 +0,0 @@ -{ lib, ... }: - -let - cfg = { - clusterId = "066ae264-2a5d-4729-8001-6ad265f50b03"; - monA = { - name = "a"; - ip = "192.168.1.1"; - }; - osd0 = { - name = "0"; - key = "AQBCEJNa3s8nHRAANvdsr93KqzBznuIWm2gOGg=="; - uuid = "55ba2294-3e24-478f-bee0-9dca4c231dd9"; - }; - osd1 = { - name = "1"; - key = "AQBEEJNac00kExAAXEgy943BGyOpVH1LLlHafQ=="; - uuid = "5e97a838-85b6-43b0-8950-cb56d554d1e5"; - }; - osd2 = { - name = "2"; - key = "AQAdyhZeIaUlARAAGRoidDAmS6Vkp546UFEf5w=="; - uuid = "ea999274-13d0-4dd5-9af9-ad25a324f72f"; - }; - }; - generateCephConfig = - { daemonConfig }: - { - enable = true; - global = { - fsid = cfg.clusterId; - monHost = cfg.monA.ip; - monInitialMembers = cfg.monA.name; - }; - } - // daemonConfig; - - generateHost = - { - cephConfig, - networkConfig, - }: - { pkgs, ... }: - { - virtualisation = { - memorySize = 2048; - emptyDiskImages = [ - 20480 - 20480 - 20480 - ]; - vlans = [ 1 ]; - }; - - # Ceph 20.2.4 introduced the aes256k cipher for authentication. - # Linux started supporting these in kernel version 7.0. - # Remove this line at the earliest convenience (i.e. when tests are run by 7.0 or higher by default). - boot.kernelPackages = pkgs.linuxPackages_latest; - - networking = networkConfig; - - environment.systemPackages = with pkgs; [ - bash - sudo - ceph - xfsprogs - ]; - - boot.kernelModules = [ "xfs" ]; - - services.ceph = cephConfig; - }; - - networkMonA = { - dhcpcd.enable = false; - interfaces.eth1.ipv4.addresses = lib.mkOverride 0 [ - { - address = cfg.monA.ip; - prefixLength = 24; - } - ]; - }; - cephConfigMonA = generateCephConfig { - daemonConfig = { - mon = { - enable = true; - daemons = [ cfg.monA.name ]; - }; - mgr = { - enable = true; - daemons = [ cfg.monA.name ]; - }; - osd = { - enable = true; - daemons = [ - cfg.osd0.name - cfg.osd1.name - cfg.osd2.name - ]; - }; - rgw = { - enable = true; - daemons = [ cfg.monA.name ]; - }; - }; - }; - - # Following deployment is based on the manual deployment described here: - # https://docs.ceph.com/docs/master/install/manual-deployment/ - # For other ways to deploy a ceph cluster, look at the documentation at - # https://docs.ceph.com/docs/master/ - testScript = '' - start_all() - - monA.wait_for_unit("network.target") - - # Bootstrap ceph-mon daemon - monA.succeed( - "sudo -u ceph ceph-authtool --create-keyring /tmp/ceph.mon.keyring --gen-key -n mon. --cap mon 'allow *'", - "sudo -u ceph ceph-authtool --create-keyring /etc/ceph/ceph.client.admin.keyring --gen-key -n client.admin --cap mon 'allow *' --cap osd 'allow *' --cap mds 'allow *' --cap mgr 'allow *'", - "sudo -u ceph ceph-authtool /tmp/ceph.mon.keyring --import-keyring /etc/ceph/ceph.client.admin.keyring", - "monmaptool --create --add ${cfg.monA.name} ${cfg.monA.ip} --fsid ${cfg.clusterId} /tmp/monmap", - "sudo -u ceph ceph-mon --mkfs -i ${cfg.monA.name} --monmap /tmp/monmap --keyring /tmp/ceph.mon.keyring", - "sudo -u ceph touch /var/lib/ceph/mon/ceph-${cfg.monA.name}/done", - "systemctl start ceph-mon-${cfg.monA.name}", - ) - monA.wait_for_unit("ceph-mon-${cfg.monA.name}") - monA.succeed("ceph mon enable-msgr2") - monA.succeed("ceph config set mon auth_allow_insecure_global_id_reclaim false") - - # Can't check ceph status until a mon is up - monA.succeed("ceph -s | grep 'mon: 1 daemons'") - - # Start the ceph-mgr daemon, after copying in the keyring - monA.succeed( - "sudo -u ceph mkdir -p /var/lib/ceph/mgr/ceph-${cfg.monA.name}/", - "ceph auth get-or-create mgr.${cfg.monA.name} mon 'allow profile mgr' osd 'allow *' mds 'allow *' > /var/lib/ceph/mgr/ceph-${cfg.monA.name}/keyring", - "systemctl start ceph-mgr-${cfg.monA.name}", - ) - monA.wait_for_unit("ceph-mgr-a") - monA.wait_until_succeeds("ceph -s | grep 'quorum ${cfg.monA.name}'") - monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'") - - # Bootstrap OSDs - monA.succeed( - "mkfs.xfs /dev/vdb", - "mkfs.xfs /dev/vdc", - "mkfs.xfs /dev/vdd", - "mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd0.name}", - "mount /dev/vdb /var/lib/ceph/osd/ceph-${cfg.osd0.name}", - "mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd1.name}", - "mount /dev/vdc /var/lib/ceph/osd/ceph-${cfg.osd1.name}", - "mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd2.name}", - "mount /dev/vdd /var/lib/ceph/osd/ceph-${cfg.osd2.name}", - "ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd0.name}/keyring --name osd.${cfg.osd0.name} --add-key ${cfg.osd0.key}", - "ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd1.name}/keyring --name osd.${cfg.osd1.name} --add-key ${cfg.osd1.key}", - "ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd2.name}/keyring --name osd.${cfg.osd2.name} --add-key ${cfg.osd2.key}", - 'echo \'{"cephx_secret": "${cfg.osd0.key}"}\' | ceph osd new ${cfg.osd0.uuid} -i -', - 'echo \'{"cephx_secret": "${cfg.osd1.key}"}\' | ceph osd new ${cfg.osd1.uuid} -i -', - 'echo \'{"cephx_secret": "${cfg.osd2.key}"}\' | ceph osd new ${cfg.osd2.uuid} -i -', - ) - - # Initialize the OSDs with regular filestore - monA.succeed( - "ceph-osd -i ${cfg.osd0.name} --mkfs --osd-uuid ${cfg.osd0.uuid}", - "ceph-osd -i ${cfg.osd1.name} --mkfs --osd-uuid ${cfg.osd1.uuid}", - "ceph-osd -i ${cfg.osd2.name} --mkfs --osd-uuid ${cfg.osd2.uuid}", - "chown -R ceph:ceph /var/lib/ceph/osd", - "systemctl start ceph-osd-${cfg.osd0.name}", - "systemctl start ceph-osd-${cfg.osd1.name}", - "systemctl start ceph-osd-${cfg.osd2.name}", - ) - monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'") - monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'") - monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") - - monA.succeed( - "ceph osd pool create single-node-test 32 32", - "ceph osd pool ls | grep 'single-node-test'", - - # We need to enable an application on the pool, otherwise it will - # stay unhealthy in state POOL_APP_NOT_ENABLED. - # Creating a CephFS would do this automatically, but we haven't done that here. - # See: https://docs.ceph.com/en/reef/rados/operations/pools/#associating-a-pool-with-an-application - # We use the custom application name "nixos-test" for this. - "ceph osd pool application enable single-node-test nixos-test", - - "ceph osd pool rename single-node-test single-node-other-test", - "ceph osd pool ls | grep 'single-node-other-test'", - ) - monA.wait_until_succeeds("ceph -s | grep '2 pools, 33 pgs'") - monA.succeed( - "ceph osd getcrushmap -o crush", - "crushtool -d crush -o decrushed", - "sed 's/step chooseleaf firstn 0 type host/step chooseleaf firstn 0 type osd/' decrushed > modcrush", - "crushtool -c modcrush -o recrushed", - "ceph osd setcrushmap -i recrushed", - "ceph osd pool set single-node-other-test size 2", - ) - monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") - monA.wait_until_succeeds("ceph -s | grep '33 active+clean'") - monA.fail( - "ceph osd pool ls | grep 'multi-node-test'", - "ceph osd pool delete single-node-other-test single-node-other-test --yes-i-really-really-mean-it", - ) - - # Bootstrap RGW - monA.succeed( - "sudo -u ceph mkdir -p /var/lib/ceph/radosgw/ceph-${cfg.monA.name}", - "ceph auth get-or-create client.${cfg.monA.name} osd 'allow rwx' mon 'allow rw' > /var/lib/ceph/radosgw/ceph-${cfg.monA.name}/keyring", - "chown ceph:ceph /var/lib/ceph/radosgw/ceph-${cfg.monA.name}/keyring", - "systemctl start ceph-rgw-${cfg.monA.name}", - ) - monA.wait_for_unit("ceph-rgw-${cfg.monA.name}") - monA.wait_for_open_port(7480) - - # Shut down ceph by stopping ceph.target. - monA.succeed("systemctl stop ceph.target") - - # Start it up - monA.succeed("systemctl start ceph.target") - monA.wait_for_unit("ceph-mon-${cfg.monA.name}") - monA.wait_for_unit("ceph-mgr-${cfg.monA.name}") - monA.wait_for_unit("ceph-osd-${cfg.osd0.name}") - monA.wait_for_unit("ceph-osd-${cfg.osd1.name}") - monA.wait_for_unit("ceph-osd-${cfg.osd2.name}") - monA.wait_for_unit("ceph-rgw-${cfg.monA.name}") - - # Ensure the cluster comes back up again - monA.succeed("ceph -s | grep 'mon: 1 daemons'") - monA.wait_until_succeeds("ceph -s | grep 'quorum ${cfg.monA.name}'") - monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'") - monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'") - monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") - ''; -in -{ - name = "basic-single-node-ceph-cluster-deprecated-filestore"; - meta = with lib.maintainers; { - maintainers = [ - lejonet - johanot - ]; - }; - - nodes = { - monA = generateHost { - cephConfig = cephConfigMonA; - networkConfig = networkMonA; - }; - }; - - inherit testScript; -} diff --git a/pkgs/by-name/ce/ceph/ceph.nix b/pkgs/by-name/ce/ceph/ceph.nix index 8fee8f501db9..7f0a51e8195e 100644 --- a/pkgs/by-name/ce/ceph/ceph.nix +++ b/pkgs/by-name/ce/ceph/ceph.nix @@ -395,10 +395,7 @@ stdenv.mkDerivation { inherit (nixosTests) ceph-multi-node-bluestore ceph-multi-node-bluestore-cephfs - ceph-multi-node-deprecated-filestore ceph-single-node-bluestore - ceph-single-node-bluestore-dmcrypt - ceph-single-node-deprecated-filestore ; }; }; From 593dd64de28040026978c8d149eea5205f6b9889 Mon Sep 17 00:00:00 2001 From: benaryorg Date: Tue, 25 Aug 2026 04:08:19 +0000 Subject: [PATCH 010/117] ceph.tests: osd creation via ceph-volume Signed-off-by: benaryorg --- nixos/tests/ceph-multi-node-bluestore.nix | 92 ++++++++++++++--------- 1 file changed, 55 insertions(+), 37 deletions(-) diff --git a/nixos/tests/ceph-multi-node-bluestore.nix b/nixos/tests/ceph-multi-node-bluestore.nix index 57b60d63b2ac..73c120a246fd 100644 --- a/nixos/tests/ceph-multi-node-bluestore.nix +++ b/nixos/tests/ceph-multi-node-bluestore.nix @@ -81,6 +81,7 @@ let bash sudo ceph + cryptsetup netcat ]; @@ -332,54 +333,55 @@ let monA.wait_until_succeeds("ceph -s | grep 'quorum ${cfg.monA.name}'") monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'") - # Send the admin keyring to the OSD machines. - monA.succeed("cp /etc/ceph/ceph.client.admin.keyring /tmp/shared") - osd0.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph") - osd1.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph") - osd2.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph") + # Send the bootstrap-osd keyring to the OSD machines. + monA.succeed("ceph auth get client.bootstrap-osd -o /etc/ceph/ceph.client.bootstrap-osd.keyring") + monA.succeed("cp /etc/ceph/ceph.client.bootstrap-osd.keyring /tmp/shared") # Bootstrap the BlueStore OSDs. - osd0.succeed( - "mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd0.name}", - "echo bluestore > /var/lib/ceph/osd/ceph-${cfg.osd0.name}/type", - "ln -sf /dev/vdb /var/lib/ceph/osd/ceph-${cfg.osd0.name}/block", - "ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd0.name}/keyring --name osd.${cfg.osd0.name} --add-key ${cfg.osd0.key}", - 'echo \'{"cephx_secret": "${cfg.osd0.key}"}\' | ceph osd new ${cfg.osd0.uuid} -i -', - ) - osd1.succeed( - "mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd1.name}", - "echo bluestore > /var/lib/ceph/osd/ceph-${cfg.osd1.name}/type", - "ln -sf /dev/vdb /var/lib/ceph/osd/ceph-${cfg.osd1.name}/block", - "ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd1.name}/keyring --name osd.${cfg.osd1.name} --add-key ${cfg.osd1.key}", - 'echo \'{"cephx_secret": "${cfg.osd1.key}"}\' | ceph osd new ${cfg.osd1.uuid} -i -', - ) - osd2.succeed( - "mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd2.name}", - "echo bluestore > /var/lib/ceph/osd/ceph-${cfg.osd2.name}/type", - "ln -sf /dev/vdb /var/lib/ceph/osd/ceph-${cfg.osd2.name}/block", - "ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd2.name}/keyring --name osd.${cfg.osd2.name} --add-key ${cfg.osd2.key}", - 'echo \'{"cephx_secret": "${cfg.osd2.key}"}\' | ceph osd new ${cfg.osd2.uuid} -i -', - ) + # + # The steps for this are roughly the same for all OSDs: + # 1. get the bootstrap-osd keyring + # 2. prepare the osd via ceph-volume lvm, the second line contains the OSD specific configuration + # 3. deactivate it to unmount the tmpfs + # 4. activate it without a tmpfs for persistent data + # 5. sync, so the osd has at least one consistent state saved + # 6. start it - # We `sync` so that the config survives the forced crashes below. + # osd.0: plain osd0.succeed( - "ceph-osd -i ${cfg.osd0.name} --mkfs --osd-uuid ${cfg.osd0.uuid}", - "chown -R ceph:ceph /var/lib/ceph/osd", + "mkdir -p /var/lib/ceph/bootstrap-osd", + "cp /tmp/shared/ceph.client.bootstrap-osd.keyring /var/lib/ceph/bootstrap-osd/ceph.keyring", + "ceph-volume lvm prepare --objectstore bluestore --no-systemd --osd-id ${cfg.osd0.name} --osd-fsid ${cfg.osd0.uuid} " + "--data /dev/vdb", + "ceph-volume lvm deactivate ${cfg.osd0.name} ${cfg.osd0.uuid}", + "ceph-volume lvm activate --no-tmpfs --no-systemd ${cfg.osd0.name} ${cfg.osd0.uuid}", "sync", "systemctl start ceph-osd-${cfg.osd0.name}", ) + # osd.1: plain osd1.succeed( - "ceph-osd -i ${cfg.osd1.name} --mkfs --osd-uuid ${cfg.osd1.uuid}", - "chown -R ceph:ceph /var/lib/ceph/osd", + "mkdir -p /var/lib/ceph/bootstrap-osd", + "cp /tmp/shared/ceph.client.bootstrap-osd.keyring /var/lib/ceph/bootstrap-osd/ceph.keyring", + "ceph-volume lvm prepare --objectstore bluestore --no-systemd --osd-id ${cfg.osd1.name} --osd-fsid ${cfg.osd1.uuid} " + "--data /dev/vdb --dmcrypt", + "ceph-volume lvm deactivate ${cfg.osd1.name} ${cfg.osd1.uuid}", + "ceph-volume lvm activate --no-tmpfs --no-systemd ${cfg.osd1.name} ${cfg.osd1.uuid}", "sync", "systemctl start ceph-osd-${cfg.osd1.name}", ) + # osd.2: plain osd2.succeed( - "ceph-osd -i ${cfg.osd2.name} --mkfs --osd-uuid ${cfg.osd2.uuid}", - "chown -R ceph:ceph /var/lib/ceph/osd", + "mkdir -p /var/lib/ceph/bootstrap-osd", + "cp /tmp/shared/ceph.client.bootstrap-osd.keyring /var/lib/ceph/bootstrap-osd/ceph.keyring", + "ceph-volume lvm prepare --objectstore bluestore --no-systemd --osd-fsid ${cfg.osd2.uuid} --osd-id ${cfg.osd2.name} " + "--data /dev/vdb", + "ceph-volume lvm deactivate ${cfg.osd2.name} ${cfg.osd2.uuid}", + "ceph-volume lvm activate --no-tmpfs --no-systemd ${cfg.osd2.name} ${cfg.osd2.uuid}", "sync", "systemctl start ceph-osd-${cfg.osd2.name}", ) + + monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'") monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'") monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") @@ -476,17 +478,33 @@ let osd1.crash() osd2.crash() - # Start it up + # Start the mon first and mark the OSDs as down. + # Since the heartbeats are pretty high by default, the OSDs would otherwise be marked as up still. + # However we do not want to lower the heartbeats since this might cause flakey tests. + monA.start() + monA.wait_for_unit("ceph-mon-${cfg.monA.name}") + monA.wait_until_succeeds("ceph osd down all") + # Then start the OSDs as normal. osd0.start() osd1.start() osd2.start() - monA.start() + # Ensure they are all up. + osd0.wait_for_unit("network.target") + osd1.wait_for_unit("network.target") + osd2.wait_for_unit("network.target") - # Ensure the cluster comes back up again. + # FIXME: dmcrypt OSDs currently do not work out of the box. + # For a potential long-term fix see: https://github.com/NixOS/nixpkgs/pull/512912#discussion_r3140295546 + osd1.succeed( + "ceph-volume lvm activate --no-tmpfs --no-systemd ${cfg.osd1.name} ${cfg.osd1.uuid}", + "systemctl start ceph-osd-${cfg.osd1.name}", + ) + + # Test the cluster state thoroughly. monA.wait_until_succeeds("ceph -s | grep 'mon: 1 daemons'") monA.wait_until_succeeds("ceph -s | grep 'quorum ${cfg.monA.name}'") - monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'") monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'") + monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'") monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") # Verify the recovery. From 635b6734966ad2b2f9f9f9ba84380ae4f336c628 Mon Sep 17 00:00:00 2001 From: benaryorg Date: Tue, 25 Aug 2026 04:46:02 +0000 Subject: [PATCH 011/117] ceph.tests: fixes for 20.2.4 --- nixos/tests/ceph-multi-node-bluestore.nix | 73 +++++++++++++++-------- 1 file changed, 49 insertions(+), 24 deletions(-) diff --git a/nixos/tests/ceph-multi-node-bluestore.nix b/nixos/tests/ceph-multi-node-bluestore.nix index 73c120a246fd..19e0d0d5e4ac 100644 --- a/nixos/tests/ceph-multi-node-bluestore.nix +++ b/nixos/tests/ceph-multi-node-bluestore.nix @@ -25,19 +25,16 @@ let osd0 = { name = "0"; ip = "192.168.1.2"; - key = "AQBCEJNa3s8nHRAANvdsr93KqzBznuIWm2gOGg=="; uuid = "55ba2294-3e24-478f-bee0-9dca4c231dd9"; }; osd1 = { name = "1"; ip = "192.168.1.3"; - key = "AQBEEJNac00kExAAXEgy943BGyOpVH1LLlHafQ=="; uuid = "5e97a838-85b6-43b0-8950-cb56d554d1e5"; }; osd2 = { name = "2"; ip = "192.168.1.4"; - key = "AQAdyhZeIaUlARAAGRoidDAmS6Vkp546UFEf5w=="; uuid = "ea999274-13d0-4dd5-9af9-ad25a324f72f"; }; # Client that mounts CephFS using the in-kernel client. @@ -58,6 +55,9 @@ let monHost = cfg.monA.ip; monInitialMembers = cfg.monA.name; }; + extraConfig = { + mon_host = "v2:${cfg.monA.ip}:3300 v1:${cfg.monA.ip}:6789"; + }; } // daemonConfig; @@ -310,14 +310,15 @@ let "sudo -u ceph ceph-authtool --create-keyring /tmp/ceph.mon.keyring --gen-key -n mon. --cap mon 'allow *'", "sudo -u ceph ceph-authtool --create-keyring /etc/ceph/ceph.client.admin.keyring --gen-key -n client.admin --cap mon 'allow *' --cap osd 'allow *' --cap mds 'allow *' --cap mgr 'allow *'", "sudo -u ceph ceph-authtool /tmp/ceph.mon.keyring --import-keyring /etc/ceph/ceph.client.admin.keyring", - "monmaptool --create --add ${cfg.monA.name} ${cfg.monA.ip} --fsid ${cfg.clusterId} /tmp/monmap", + # Creating the mon with v2 (and a legacy v1) address right away removes the need for running `enable-msgr2` later on. + # It is also makes the test more consistent by fixing the address to a known value instead of letting it derive the address. + "monmaptool --create --addv ${cfg.monA.name} '[v2:${cfg.monA.ip}:3300,v1:${cfg.monA.ip}:6789]' --auth-allowed-ciphers aes256k --auth-preferred-cipher aes256k --auth-service-cipher aes256k --fsid ${cfg.clusterId} /tmp/monmap", "sudo -u ceph ceph-mon --mkfs -i ${cfg.monA.name} --monmap /tmp/monmap --keyring /tmp/ceph.mon.keyring", "sudo -u ceph mkdir -p /var/lib/ceph/mgr/ceph-${cfg.monA.name}/", "sudo -u ceph touch /var/lib/ceph/mon/ceph-${cfg.monA.name}/done", "systemctl start ceph-mon-${cfg.monA.name}", ) monA.wait_for_unit("ceph-mon-${cfg.monA.name}") - monA.succeed("ceph mon enable-msgr2") monA.succeed("ceph config set mon auth_allow_insecure_global_id_reclaim false") # Can't check ceph status until a mon is up @@ -387,6 +388,9 @@ let monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") monA.succeed( + # Autoscaling will cause PGs to be peering, causing the tests to become flakey. + "ceph osd pool set noautoscale", + "ceph osd pool create multi-node-test 32 32", "ceph osd pool ls | grep 'multi-node-test'", @@ -536,45 +540,50 @@ let # Create a CephFS. monA.succeed( - "ceph osd pool create cephfs-data 32 32", - "ceph osd pool create cephfs-metadata 32 32", - "ceph fs new cephfs cephfs-metadata cephfs-data", + "ceph fs volume create testing", + "ceph osd pool set cephfs.testing.data pg_num 32", + "ceph osd pool set cephfs.testing.meta pg_num 32", ) # Wait for the MDS to claim the filesystem and become active. - monA.wait_until_succeeds("ceph fs status cephfs | grep -e 'active'", timeout=60) + monA.wait_until_succeeds("ceph fs status testing | grep -e 'active'", timeout=60) - # Distribute the admin keyring (and a plain secret file for the kernel - # client) to both client machines, so that they can authenticate. + # Create a subvolume, issue credentials, then distribute those credentials. monA.succeed( - "cp /etc/ceph/ceph.client.admin.keyring /tmp/shared", - "ceph-authtool -p /etc/ceph/ceph.client.admin.keyring > /tmp/shared/admin.secret", + "ceph fs subvolumegroup create testing group", + "ceph fs subvolume create testing subvolume --group_name group", + "ceph fs subvolume authorize testing subvolume kclient group", + "ceph fs subvolume authorize testing subvolume fuseclient group", + "ceph auth get client.kclient -o /tmp/shared/ceph.client.kclient.keyring", + "ceph auth get client.fuseclient -o /tmp/shared/ceph.client.fuseclient.keyring", ) - kclient.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph") - fuseclient.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph") - kclient.succeed("cp /tmp/shared/admin.secret /etc/ceph/admin.secret") + kclient.succeed("cp /tmp/shared/ceph.client.kclient.keyring /etc/ceph") + fuseclient.succeed("cp /tmp/shared/ceph.client.fuseclient.keyring /etc/ceph") + + # Get the volume path generated by Ceph. + volume_path = monA.succeed("ceph fs subvolume getpath testing subvolume group | tee /dev/stderr").strip() # Mount CephFS on the kernel client. # We force the messenger v2 protocol via "ms_mode=secure"; the cluster - # has msgr2 enabled (see "ceph mon enable-msgr2" above) and the legacy v1 + # has msgr2 enabled (the monmap is created with a v2 address above) and the legacy v1 # protocol apparently does not reconnect reliably after the servers are restarted. # The msgr2 monitor listens on port 3300 (instead of legacy v1 port 6789), # so we have to point the device string at that port explicitly. # `recover_session=clean` makes the kernel client automatically reconnect # (discarding its stale session) after the whole cluster has been down, - # which would otherwise leave the mount blocklisted and hanging forever. + # which would otherwise leave the mount blocklisted and hanging. # Real CephFS use may not prefer hanging `recover_session=clean`, and # prefer manual de-blocklisting to avoid any failed OS syscalls, # but for this test, discarding stale sessions is good enough. kclient.succeed("mkdir -p /mnt/cephfs") kclient.wait_until_succeeds( - "mount -t ceph ${cfg.monA.ip}:3300:/ /mnt/cephfs -o name=admin,secretfile=/etc/ceph/admin.secret,ms_mode=secure,recover_session=clean" + f"mount -t ceph kclient@.testing={volume_path} /mnt/cephfs -o ms_mode=secure,recover_session=clean" ) kclient.succeed("mountpoint /mnt/cephfs") # Mount CephFS on the FUSE client using ceph-fuse. fuseclient.succeed("mkdir -p /mnt/cephfs") fuseclient.wait_until_succeeds( - "ceph-fuse --id admin -m ${cfg.monA.ip}:6789 /mnt/cephfs" + f"ceph-fuse --id fuseclient -m ${cfg.monA.ip}:3300 -r {volume_path} /mnt/cephfs" ) fuseclient.succeed("mountpoint /mnt/cephfs") @@ -602,24 +611,40 @@ let osd1.crash() osd2.crash() - # Start it up + # Start the mon first and mark the OSDs as down. + # Since the heartbeats are pretty high by default, the OSDs would otherwise be marked as up still. + # However we do not want to lower the heartbeats since this might cause flakey tests. + monA.start() + monA.wait_for_unit("ceph-mon-${cfg.monA.name}") + monA.wait_until_succeeds("ceph osd down all") + # Then start the OSDs as normal. osd0.start() osd1.start() osd2.start() - monA.start() + # Ensure they are all up. + osd0.wait_for_unit("network.target") + osd1.wait_for_unit("network.target") + osd2.wait_for_unit("network.target") + + # FIXME: dmcrypt OSDs currently do not work out of the box. + # For a potential long-term fix see: https://github.com/NixOS/nixpkgs/pull/512912#discussion_r3140295546 + osd1.succeed( + "ceph-volume lvm activate --no-tmpfs --no-systemd ${cfg.osd1.name} ${cfg.osd1.uuid}", + "systemctl start ceph-osd-${cfg.osd1.name}", + ) # Ensure the cluster comes back up again. # See the note above on why this uses `wait_until_succeeds`. monA.wait_until_succeeds("ceph -s | grep 'mon: 1 daemons'") monA.wait_until_succeeds("ceph -s | grep 'quorum ${cfg.monA.name}'") - monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'") monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'") + monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'") monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'", timeout=60) # Ensure the MDS/CephFS comes back up again, too. monA.wait_for_unit("ceph-mds-${cfg.monA.name}") - monA.wait_until_succeeds("ceph fs status cephfs | grep -e 'active'", timeout=60) + monA.wait_until_succeeds("ceph fs status testing | grep -e 'active'", timeout=60) monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") # The clients kept running across the outage, so their CephFS mounts From 08eff661f245e0b315bc338e2e236cfe8864c3e0 Mon Sep 17 00:00:00 2001 From: benaryorg Date: Tue, 25 Aug 2026 05:01:35 +0000 Subject: [PATCH 012/117] ceph.tests: comprehensive output This will make the output much more verbose, but also show the actual errors in the test output if there are any. Signed-off-by: benaryorg --- nixos/tests/ceph-multi-node-bluestore.nix | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/nixos/tests/ceph-multi-node-bluestore.nix b/nixos/tests/ceph-multi-node-bluestore.nix index 19e0d0d5e4ac..9f61df41ee35 100644 --- a/nixos/tests/ceph-multi-node-bluestore.nix +++ b/nixos/tests/ceph-multi-node-bluestore.nix @@ -56,6 +56,11 @@ let monInitialMembers = cfg.monA.name; }; extraConfig = { + log_to_syslog = "false"; + log_to_file = "false"; + log_to_stderr = "true"; + debug_rocksdb = "1/5"; + debug_mgr = "1/5"; mon_host = "v2:${cfg.monA.ip}:3300 v1:${cfg.monA.ip}:6789"; }; } @@ -442,7 +447,7 @@ let dashboard = "http://${cfg.monA.ip}:8080" monA.wait_for_open_port(8080, addr="${cfg.monA.ip}") - monA.wait_until_succeeds(f"curl -q --fail {dashboard}") + monA.wait_until_succeeds(f"curl -s --fail {dashboard}") monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'") # Initialize dashboard creds. From 84f7cb0e630fa019b862ea785f01ddd0016551aa Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Sat, 5 Sep 2026 22:07:59 +0200 Subject: [PATCH 013/117] matrix-sdk-crypto-nodejs: 0.4.0-beta.1 -> 0.6.6 Diff: https://github.com/matrix-org/matrix-rust-sdk-crypto-nodejs/compare/v0.4.0-beta.1...v0.6.6 Changelog: https://github.com/matrix-org/matrix-rust-sdk-crypto-nodejs/blob/main/CHANGELOG.md --- pkgs/by-name/ma/matrix-sdk-crypto-nodejs/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/ma/matrix-sdk-crypto-nodejs/package.nix b/pkgs/by-name/ma/matrix-sdk-crypto-nodejs/package.nix index 0b12740e1440..593fa9eafa67 100644 --- a/pkgs/by-name/ma/matrix-sdk-crypto-nodejs/package.nix +++ b/pkgs/by-name/ma/matrix-sdk-crypto-nodejs/package.nix @@ -12,18 +12,18 @@ stdenv.mkDerivation (finalAttrs: { pname = "matrix-sdk-crypto-nodejs"; - version = "0.4.0-beta.1"; + version = "0.6.6"; src = fetchFromGitHub { owner = "matrix-org"; repo = "matrix-rust-sdk-crypto-nodejs"; rev = "v${finalAttrs.version}"; - hash = "sha256-Rl0xtaEj2RnW9HPN94hjETwiMInxT1XGa1BocldQAPs="; + hash = "sha256-itTtLOLkqhcEQDmeVbYVokbTZw0xxdEi4BblIzY0iVY="; }; cargoDeps = rustPlatform.fetchCargoVendor { inherit (finalAttrs) pname version src; - hash = "sha256-4AC+l52I8Z3sXiViNPe6GLCl1Z+GpqjbwkcFX6BhxDA="; + hash = "sha256-sFN2V+Du7ZsN992E6btI0R5iGO9835+0z+Uxw4VzvoM="; }; nativeBuildInputs = [ @@ -47,7 +47,7 @@ stdenv.mkDerivation (finalAttrs: { installPhase = '' runHook preInstall - local -r outPath="$out/lib/node_modules/@matrix-org/${finalAttrs.pname}" + local -r outPath="$out/lib/node_modules/@matrix-org/matrix-sdk-crypto-nodejs" mkdir -p "$outPath" cp package.json index.js index.d.ts matrix-sdk-crypto.*.node "$outPath" From 6c1cf8bb4f832fbcfd27bd71cd1f62d7a6848f69 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Sat, 5 Sep 2026 20:05:38 +0200 Subject: [PATCH 014/117] mjolnir: 1.9.2 -> 1.12.1 --- .../mjolnir/001-disable-nsfwprotection.patch | 320 ++++++++++++------ pkgs/by-name/mj/mjolnir/package.nix | 12 +- 2 files changed, 230 insertions(+), 102 deletions(-) diff --git a/pkgs/by-name/mj/mjolnir/001-disable-nsfwprotection.patch b/pkgs/by-name/mj/mjolnir/001-disable-nsfwprotection.patch index 2566f65b1d1b..1ee429377583 100644 --- a/pkgs/by-name/mj/mjolnir/001-disable-nsfwprotection.patch +++ b/pkgs/by-name/mj/mjolnir/001-disable-nsfwprotection.patch @@ -1,9 +1,9 @@ diff --git a/src/protections/NsfwProtection.ts b/src/protections/NsfwProtection.ts deleted file mode 100644 -index a6f45b2..0000000 +index 54b6e8f..0000000 --- a/src/protections/NsfwProtection.ts +++ /dev/null -@@ -1,115 +0,0 @@ +@@ -1,118 +0,0 @@ -/* -Copyright 2024 The Matrix.org Foundation C.I.C. - @@ -25,6 +25,7 @@ index a6f45b2..0000000 -import * as nsfw from "nsfwjs"; -import { LogLevel, LogService } from "@vector-im/matrix-bot-sdk"; -import { node } from "@tensorflow/tfjs-node"; +-import { getMXCsInMessage } from "../utils"; - -export class NsfwProtection extends Protection { - settings = {}; @@ -51,76 +52,78 @@ index a6f45b2..0000000 - } - - public async handleEvent(mjolnir: Mjolnir, roomId: string, event: any): Promise { -- if (event["type"] === "m.room.message") { -- let content = JSON.stringify(event["content"]); -- if (!content.toLowerCase().includes("mxc")) { -- return; -- } -- // try and grab a human-readable alias for more helpful management room output -- const maybeAlias = await mjolnir.client.getPublishedAlias(roomId); -- const room = maybeAlias ? maybeAlias : roomId; +- if (event.type !== "m.room.message" && event.type !== "m.sticker") { +- return; +- } - -- const mxcs = content.match(/(mxc?:\/\/[^\s'"]+)/gim); -- if (!mxcs) { -- //something's gone wrong with the regex -- await mjolnir.managementRoomOutput.logMessage( -- LogLevel.ERROR, -- "NSFWProtection", -- `Unable to find any mxcs in ${event["event_id"]} in ${room}`, -- ); -- return; +- const mxcs = getMXCsInMessage(event.content); +- if (mxcs.length <= 0) { +- return; // nothing to do +- } +- +- // try and grab a human-readable alias for more helpful management room output +- const maybeAlias = await mjolnir.client.getPublishedAlias(roomId); +- const room = maybeAlias ? maybeAlias : roomId; +- +- // Skip classification if sensitivity is 0, as it's a waste of resources +- // We are using 0.0001 as a threshold to avoid floating point errors +- if (mjolnir.config.nsfwSensitivity <= 0.0001) { +- await this.redactEvent(mjolnir, roomId, event, room); +- return; +- } +- +- for (const mxc of mxcs) { +- const image = await mjolnir.client.downloadContent(`mxc://${mxc.domain}/${mxc.mediaId}`); +- +- let decodedImage; +- try { +- decodedImage = await node.decodeImage(image.data, 3); +- } catch (e) { +- LogService.error("NsfwProtection", `There was an error processing an image: ${e}`); +- continue; - } - -- // @ts-ignore - see null check immediately above -- for (const mxc of mxcs) { -- const image = await mjolnir.client.downloadContent(mxc); +- const predictions = await this.model.classify(decodedImage); - -- let decodedImage; -- try { -- decodedImage = await node.decodeImage(image.data, 3); -- } catch (e) { -- LogService.error("NsfwProtection", `There was an error processing an image: ${e}`); -- continue; -- } -- -- const predictions = await this.model.classify(decodedImage); -- -- for (const prediction of predictions) { -- if (["Hentai", "Porn"].includes(prediction["className"])) { -- if (prediction["probability"] > mjolnir.config.nsfwSensitivity) { -- try { -- await mjolnir.client.redactEvent(roomId, event["event_id"]); -- } catch (err) { -- await mjolnir.managementRoomOutput.logMessage( -- LogLevel.ERROR, -- "NSFWProtection", -- `There was an error redacting ${event["event_id"]} in ${room}: ${err}`, -- ); -- } -- let eventId = event["event_id"]; -- let body = `Redacted an image in ${room} ${eventId}`; -- let formatted_body = `
-- Redacted an image in ${room} --
${eventId}
${room}
--
`; -- const msg = { -- msgtype: "m.notice", -- body: body, -- format: "org.matrix.custom.html", -- formatted_body: formatted_body, -- }; -- await mjolnir.client.sendMessage(mjolnir.managementRoomId, msg); -- break; -- } +- for (const prediction of predictions) { +- if (["Hentai", "Porn"].includes(prediction["className"])) { +- if (prediction["probability"] > mjolnir.config.nsfwSensitivity) { +- await this.redactEvent(mjolnir, roomId, event, room); +- break; - } - } -- decodedImage.dispose(); - } +- decodedImage.dispose(); - } - } +- +- private async redactEvent(mjolnir: Mjolnir, roomId: string, event: any, room: string): Promise { +- try { +- await mjolnir.client.redactEvent(roomId, event["event_id"]); +- } catch (err) { +- await mjolnir.managementRoomOutput.logMessage( +- LogLevel.ERROR, +- "NSFWProtection", +- `There was an error redacting ${event["event_id"]} in ${room}: ${err}`, +- ); +- } +- let eventId = event["event_id"]; +- let body = `Redacted an image in ${room} ${eventId}`; +- let formatted_body = `
+- Redacted an image in ${room} +-
${eventId}
${room}
+-
`; +- const msg = { +- msgtype: "m.notice", +- body: body, +- format: "org.matrix.custom.html", +- formatted_body: formatted_body, +- }; +- await mjolnir.client.sendMessage(mjolnir.managementRoomId, msg); +- } -} diff --git a/src/protections/ProtectionManager.ts b/src/protections/ProtectionManager.ts -index 485f05e..6ffb0d1 100644 +index bb29e40..8ec1635 100644 --- a/src/protections/ProtectionManager.ts +++ b/src/protections/ProtectionManager.ts @@ -31,7 +31,6 @@ import { htmlEscape } from "../utils"; @@ -129,17 +132,17 @@ index 485f05e..6ffb0d1 100644 import { LocalAbuseReports } from "./LocalAbuseReports"; -import { NsfwProtection } from "./NsfwProtection"; import { MentionSpam } from "./MentionSpam"; - - const PROTECTIONS: Protection[] = [ -@@ -44,7 +43,6 @@ const PROTECTIONS: Protection[] = [ + import { MessageIsVideo } from "./MessageIsVideo"; + import { FirstMessageIsLink } from "./FirstMessageIsLink"; +@@ -46,7 +45,6 @@ const PROTECTIONS: Protection[] = [ new DetectFederationLag(), new JoinWaveShortCircuit(), new LocalAbuseReports(), - new NsfwProtection(), new MentionSpam(), - ]; - -@@ -106,9 +104,6 @@ export class ProtectionManager { + new MessageIsVideo(), + new FirstMessageIsLink(), +@@ -110,9 +108,6 @@ export class ProtectionManager { protection.settings[key].setValue(value); } if (protection.enabled) { @@ -151,31 +154,41 @@ index 485f05e..6ffb0d1 100644 } diff --git a/test/integration/nsfwProtectionTest.ts b/test/integration/nsfwProtectionTest.ts deleted file mode 100644 -index ed215e0..0000000 +index c35b2e7..0000000 --- a/test/integration/nsfwProtectionTest.ts +++ /dev/null -@@ -1,89 +0,0 @@ +@@ -1,214 +0,0 @@ -import { newTestUser } from "./clientHelper"; - --import { MatrixClient } from "@vector-im/matrix-bot-sdk"; +-import { MatrixClient, MXCUrl } from "@vector-im/matrix-bot-sdk"; -import { getFirstReaction } from "./commands/commandUtils"; --import { strict as assert } from "assert"; +-import { equal } from "node:assert/strict"; -import { readFileSync } from "fs"; +-import { ProtectionManager } from "../../src/protections/ProtectionManager"; - -describe("Test: NSFW protection", function () { -- let client: MatrixClient; +- let modClient: MatrixClient; +- let spammer: MatrixClient; - let room: string; - this.beforeEach(async function () { -- client = await newTestUser(this.config.homeserverUrl, { name: { contains: "nsfw-protection" } }); -- await client.start(); +- // verify mjolnir is admin +- const admin = await this.mjolnir.isSynapseAdmin(); +- if (!admin) { +- throw new Error(`Mjolnir needs to be admin for this test.`); +- } +- modClient = await newTestUser(this.config.homeserverUrl, { name: { contains: "nsfw-protection-moderator" } }); +- spammer = await newTestUser(this.config.homeserverUrl, { name: { contains: "nsfw-protection-spammer" } }); +- await modClient.start(); - const mjolnirId = await this.mjolnir.client.getUserId(); -- room = await client.createRoom({ invite: [mjolnirId] }); -- await client.joinRoom(room); -- await client.joinRoom(this.config.managementRoom); -- await client.setUserPowerLevel(mjolnirId, room, 100); +- const spammerId = await spammer.getUserId(); +- room = await modClient.createRoom({ invite: [mjolnirId, spammerId] }); +- await spammer.joinRoom(room); +- await modClient.joinRoom(room); +- await modClient.joinRoom(this.config.managementRoom); +- await modClient.setUserPowerLevel(mjolnirId, room, 100); - }); - this.afterEach(async function () { -- await client.stop(); +- await modClient.stop(); - }); - - function delay(ms: number) { @@ -185,25 +198,25 @@ index ed215e0..0000000 - it("Nsfw protection doesn't redact sfw images", async function () { - this.timeout(20000); - -- await client.sendMessage(this.mjolnir.managementRoomId, { +- await modClient.sendMessage(this.mjolnir.managementRoomId, { - msgtype: "m.text", - body: `!mjolnir rooms add ${room}`, - }); -- await getFirstReaction(client, this.mjolnir.managementRoomId, "✅", async () => { -- return await client.sendMessage(this.mjolnir.managementRoomId, { +- await getFirstReaction(modClient, this.mjolnir.managementRoomId, "✅", async () => { +- return await modClient.sendMessage(this.mjolnir.managementRoomId, { - msgtype: "m.text", - body: `!mjolnir enable NsfwProtection`, - }); - }); - - const data = readFileSync("test_tree.jpg"); -- const mxc = await client.uploadContent(data, "image/png"); +- const mxc = await spammer.uploadContent(data, "image/png"); - let content = { msgtype: "m.image", body: "test.jpeg", url: mxc }; -- let imageMessage = await client.sendMessage(room, content); +- let imageMessage = await spammer.sendMessage(room, content); - - await delay(500); -- let processedImage = await client.getEvent(room, imageMessage); -- assert.equal(Object.keys(processedImage.content).length, 3, "This event should not have been redacted"); +- let processedImage = await spammer.getEvent(room, imageMessage); +- equal(Object.keys(processedImage.content).length, 3, "This event should not have been redacted"); - }); - - it("Nsfw protection redacts nsfw images", async function () { @@ -211,21 +224,21 @@ index ed215e0..0000000 - // dial the sensitivity on the protection way up so that all images are flagged as NSFW - this.mjolnir.config.nsfwSensitivity = 0.0; - -- await client.sendMessage(this.mjolnir.managementRoomId, { +- await modClient.sendMessage(this.mjolnir.managementRoomId, { - msgtype: "m.text", - body: `!mjolnir rooms add ${room}`, - }); -- await getFirstReaction(client, this.mjolnir.managementRoomId, "✅", async () => { -- return await client.sendMessage(this.mjolnir.managementRoomId, { +- await getFirstReaction(modClient, this.mjolnir.managementRoomId, "✅", async () => { +- return await modClient.sendMessage(this.mjolnir.managementRoomId, { - msgtype: "m.text", - body: `!mjolnir enable NsfwProtection`, - }); - }); - - const data = readFileSync("test_tree.jpg"); -- const mxc = await client.uploadContent(data, "image/png"); +- const mxc = await spammer.uploadContent(data, "image/png"); - let content = { msgtype: "m.image", body: "test.jpeg", url: mxc }; -- let imageMessage = await client.sendMessage(room, content); +- let imageMessage = await spammer.sendMessage(room, content); - - let formatted_body = ``; - let htmlContent = { @@ -234,13 +247,128 @@ index ed215e0..0000000 - format: "org.matrix.custom.html", - formatted_body: formatted_body, - }; -- let htmlMessage = await client.sendMessage(room, htmlContent); +- let htmlMessage = await spammer.sendMessage(room, htmlContent); - - await delay(500); -- let processedImage = await client.getEvent(room, imageMessage); -- assert.equal(Object.keys(processedImage.content).length, 0, "This event should have been redacted"); +- let processedImage = await modClient.getEvent(room, imageMessage); +- equal(Object.keys(processedImage.content).length, 0, "This event should have been redacted"); - -- let processedHtml = await client.getEvent(room, htmlMessage); -- assert.equal(Object.keys(processedHtml.content).length, 0, "This html image event should have been redacted"); +- let processedHtml = await modClient.getEvent(room, htmlMessage); +- equal(Object.keys(processedHtml.content).length, 0, "This html image event should have been redacted"); +- }); +- +- it("Nsfw protection redacts nsfw images", async function () { +- this.timeout(20000); +- // dial the sensitivity on the protection way up so that all images are flagged as NSFW +- this.mjolnir.config.nsfwSensitivity = 0.0; +- +- await modClient.sendMessage(this.mjolnir.managementRoomId, { +- msgtype: "m.text", +- body: `!mjolnir rooms add ${room}`, +- }); +- await getFirstReaction(modClient, this.mjolnir.managementRoomId, "✅", async () => { +- return await modClient.sendMessage(this.mjolnir.managementRoomId, { +- msgtype: "m.text", +- body: `!mjolnir enable NsfwProtection`, +- }); +- }); +- +- const data = readFileSync("test_tree.jpg"); +- const mxc = await spammer.uploadContent(data, "image/png"); +- const mediaId = MXCUrl.parse(mxc).mediaId; +- let content = { msgtype: "m.image", body: "test.jpeg", url: mxc }; +- let imageMessage = await spammer.sendMessage(room, content); +- +- let formatted_body = ``; +- let htmlContent = { +- msgtype: "m.image", +- body: formatted_body, +- format: "org.matrix.custom.html", +- formatted_body: formatted_body, +- }; +- let htmlMessage = await spammer.sendMessage(room, htmlContent); +- +- await delay(500); +- let processedImage = await modClient.getEvent(room, imageMessage); +- equal(Object.keys(processedImage.content).length, 0, "This event should have been redacted"); +- +- let processedHtml = await modClient.getEvent(room, htmlMessage); +- equal(Object.keys(processedHtml.content).length, 0, "This html image event should have been redacted"); +- }); +- +- it("Nsfw protection does not react messages without any MXCs", async function () { +- this.timeout(20000); +- +- const protectionManager = this.mjolnir.protectionManager as ProtectionManager; +- +- // Hack our way into the protection manager to determine if it has processed an event. +- let sentEventId: string; +- const handledEventPromise = new Promise((resolve) => { +- const handleEvent = protectionManager["handleEvent"].bind(protectionManager); +- protectionManager["handleEvent"] = async (roomId, event) => { +- try { +- return handleEvent(roomId, event); +- } finally { +- if (sentEventId === event.event_id) { +- resolve(); +- } +- } +- }; +- }); +- +- await modClient.sendMessage(this.mjolnir.managementRoomId, { +- msgtype: "m.text", +- body: `!mjolnir rooms add ${room}`, +- }); +- +- await getFirstReaction(modClient, this.mjolnir.managementRoomId, "✅", async () => { +- return await modClient.sendMessage(this.mjolnir.managementRoomId, { +- msgtype: "m.text", +- body: `!mjolnir enable NsfwProtection`, +- }); +- }); +- +- let content = { body: "This is just some text", msgtype: "m.text" }; +- sentEventId = await spammer.sendMessage(room, content); +- await handledEventPromise; +- let processedEvent = await modClient.getEvent(room, sentEventId); +- equal(Object.keys(processedEvent.content).length, 2, "This event should not have been redacted"); +- }); +- it("Nsfw protection does not redact images from moderators", async function () { +- this.timeout(20000); +- // dial the sensitivity on the protection way up so that all images are flagged as NSFW +- this.mjolnir.config.nsfwSensitivity = 0.0; +- +- await modClient.sendMessage(this.mjolnir.managementRoomId, { +- msgtype: "m.text", +- body: `!mjolnir rooms add ${room}`, +- }); +- await getFirstReaction(modClient, this.mjolnir.managementRoomId, "✅", async () => { +- return await modClient.sendMessage(this.mjolnir.managementRoomId, { +- msgtype: "m.text", +- body: `!mjolnir enable NsfwProtection`, +- }); +- }); +- +- const data = readFileSync("test_tree.jpg"); +- const mxc = await modClient.uploadContent(data, "image/png"); +- let content = { msgtype: "m.image", body: "test.jpeg", url: mxc }; +- let imageMessage = await modClient.sendMessage(room, content); +- +- let formatted_body = ``; +- let htmlContent = { +- msgtype: "m.image", +- body: formatted_body, +- format: "org.matrix.custom.html", +- formatted_body: formatted_body, +- }; +- let htmlMessage = await modClient.sendMessage(room, htmlContent); +- +- await delay(500); +- let processedImage = await modClient.getEvent(room, imageMessage); +- equal(Object.keys(processedImage.content).length, 3, "This event should not have been redacted"); +- +- let processedHtml = await modClient.getEvent(room, htmlMessage); +- equal(Object.keys(processedHtml.content).length, 4, "This html image event should not have been redacted"); - }); -}); diff --git a/pkgs/by-name/mj/mjolnir/package.nix b/pkgs/by-name/mj/mjolnir/package.nix index 7f97fc48f1b0..cf25f0e8af5c 100644 --- a/pkgs/by-name/mj/mjolnir/package.nix +++ b/pkgs/by-name/mj/mjolnir/package.nix @@ -4,7 +4,7 @@ yarnConfigHook, yarnBuildHook, yarnInstallHook, - nodejs, + nodejs_22, fetchFromGitHub, fetchYarnDeps, matrix-sdk-crypto-nodejs, @@ -14,13 +14,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "mjolnir"; - version = "1.9.2"; + version = "1.12.1"; src = fetchFromGitHub { owner = "matrix-org"; repo = "mjolnir"; tag = "v${finalAttrs.version}"; - hash = "sha256-OxHnCMP6IP0EaAs4YQgmV04tq6IdAYmKQX8O9Q48CPk="; + hash = "sha256-PWPtp1KVOBNH7lu99Yy3hmj8wGOZe+YKjPq/SyO7oLM="; }; patches = [ @@ -30,14 +30,14 @@ stdenv.mkDerivation (finalAttrs: { offlineCache = fetchYarnDeps { yarnLock = "${finalAttrs.src}/yarn.lock"; - hash = "sha256-1V7ooONt9j+4hk/3w6Dsv/SdWwa1xsLk97EwhuPegNo="; + hash = "sha256-M4gsuzSxKOIDPL4J2HnveRDjviB0RPBmLVYBlTVz788="; }; nativeBuildInputs = [ yarnConfigHook yarnBuildHook yarnInstallHook - nodejs + nodejs_22 makeWrapper ]; @@ -47,7 +47,7 @@ stdenv.mkDerivation (finalAttrs: { rm -rf $out/lib/node_modules/mjolnir/node_modules/@matrix-org/matrix-sdk-crypto-nodejs ln -s ${matrix-sdk-crypto-nodejs}/lib/node_modules/@matrix-org/matrix-sdk-crypto-nodejs $out/lib/node_modules/mjolnir/node_modules/@matrix-org/matrix-sdk-crypto-nodejs - makeWrapper ${nodejs}/bin/node "$out/bin/mjolnir" \ + makeWrapper ${nodejs_22}/bin/node "$out/bin/mjolnir" \ --add-flags "$out/lib/node_modules/mjolnir/lib/index.js" ''; From cc13c84a7660e1d8a027556a2776366a0c1c1c7d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Sat, 5 Sep 2026 20:05:50 +0200 Subject: [PATCH 015/117] nixos/mjolnir: add support for using native encryption --- nixos/modules/services/matrix/mjolnir.nix | 35 ++++++++++++++++++----- 1 file changed, 28 insertions(+), 7 deletions(-) diff --git a/nixos/modules/services/matrix/mjolnir.nix b/nixos/modules/services/matrix/mjolnir.nix index 27a7b1c3ea82..d17634ac9572 100644 --- a/nixos/modules/services/matrix/mjolnir.nix +++ b/nixos/modules/services/matrix/mjolnir.nix @@ -20,11 +20,16 @@ let rawHomeserverUrl = cfg.homeserverUrl; pantalaimon = { - inherit (cfg.pantalaimon) username; - use = cfg.pantalaimon.enable; + } + // lib.optionalAttrs cfg.pantalaimon.enable { + inherit (cfg.pantalaimon) username; password = "@PANTALAIMON_PASSWORD@"; # will be replaced in "generateConfig" }; + encryption = { + inherit (cfg.settings.encryption) username; + password = "@ENCRYPTION_PASSWORD@"; # will be replaced in "generateConfig" + }; }; moduleConfigFile = pkgs.writeText "module-config.yaml" ( @@ -72,6 +77,9 @@ let ${lib.optionalString (cfg.pantalaimon.passwordFile != null) '' ${pkgs.replace-secret}/bin/replace-secret '@PANTALAIMON_PASSWORD@' '${cfg.pantalaimon.passwordFile}' ${cfg.dataPath}/config/default.yaml ''} + ${lib.optionalString (cfg.encryption.passwordFile != null) '' + ${pkgs.replace-secret}/bin/replace-secret '@ENCRYPTION_PASSWORD@' '${cfg.encryption.passwordFile}' ${cfg.dataPath}/config/default.yaml + ''} '' ); in @@ -98,6 +106,14 @@ in ''; }; + encryption.passwordFile = lib.mkOption { + type = with lib.types; nullOr path; + default = null; + description = '' + File containing the matrix password for the `mjolnir` user. + ''; + }; + pantalaimon = lib.mkOption { description = '' `pantalaimon` options (enables E2E Encryption support). @@ -186,17 +202,22 @@ in config = lib.mkIf config.services.mjolnir.enable { assertions = [ + { + assertion = !(cfg.settings.encryption.use && cfg.encryption.passwordFile == null); + message = "encryption.passwordFile must be specified when native encryption is used."; + } { assertion = !(cfg.pantalaimon.enable && cfg.pantalaimon.passwordFile == null); - message = "Specify pantalaimon.passwordFile"; + message = "pantalaimon.passwordFile must be specified when pantalaimon is enabled."; } { - assertion = !(cfg.pantalaimon.enable && cfg.accessTokenFile != null); - message = "Do not specify accessTokenFile when using pantalaimon"; + assertion = cfg.accessTokenFile == null -> cfg.pantalaimon.enable || cfg.settings.encryption.use; + message = "Do not specify accessTokenFile when using native encryption or pantalaimon"; } { - assertion = !(!cfg.pantalaimon.enable && cfg.accessTokenFile == null); - message = "Specify accessTokenFile when not using pantalaimon"; + assertion = + !(!cfg.pantalaimon.enable && !cfg.settings.encryption.use && cfg.accessTokenFile == null); + message = "Specify accessTokenFile when not using pantalaimon or native encryption."; } ]; From a8018b043e4d3bd19d1311a419fff81ed9f712ad Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Tue, 8 Sep 2026 20:52:07 +0200 Subject: [PATCH 016/117] nixos/engelsystem: do not require mkForce ot overwrite default pm.* settings --- nixos/modules/services/web-apps/engelsystem.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nixos/modules/services/web-apps/engelsystem.nix b/nixos/modules/services/web-apps/engelsystem.nix index 792bf1c29f82..37c1e8448e17 100644 --- a/nixos/modules/services/web-apps/engelsystem.nix +++ b/nixos/modules/services/web-apps/engelsystem.nix @@ -116,7 +116,7 @@ in services.phpfpm.pools.engelsystem = { user = "engelsystem"; - settings = { + settings = lib.mapAttrs (_: v: lib.mkDefault v) { "listen.owner" = config.services.nginx.user; "pm" = "dynamic"; "pm.max_children" = 32; From 8db81476007c9c3ba02f0e2799b3ac4348c382fe Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Tue, 8 Sep 2026 20:46:38 +0200 Subject: [PATCH 017/117] nixos/paperless: allow overwriting exporter settings without mkForce --- nixos/modules/services/misc/paperless.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/nixos/modules/services/misc/paperless.nix b/nixos/modules/services/misc/paperless.nix index db2406603c39..56fe5c646fd8 100644 --- a/nixos/modules/services/misc/paperless.nix +++ b/nixos/modules/services/misc/paperless.nix @@ -717,7 +717,9 @@ in "d '${cfg.exporter.directory}' - ${cfg.user} ${config.users.users.${cfg.user}.group} - -" ]; - services.paperless.exporter.settings = options.services.paperless.exporter.settings.default; + services.paperless.exporter.settings = lib.mapAttrs ( + _: v: lib.mkDefault v + ) options.services.paperless.exporter.settings.default; systemd.services.paperless-exporter = { startAt = lib.defaultTo [ ] cfg.exporter.onCalendar; From 495e968f9ff2e0e9a61f7429c0f211575b39963b Mon Sep 17 00:00:00 2001 From: Tyce Herrman Date: Wed, 2 Sep 2026 11:42:55 -0400 Subject: [PATCH 018/117] lix: 2.95.2 -> 2.95.3 Assisted-by: Codex (gpt-5.6-sol) Assisted-by: Codex (GPT-6) --- pkgs/tools/package-management/lix/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/package-management/lix/default.nix b/pkgs/tools/package-management/lix/default.nix index 55c0a1c86c0a..5edfe3b5518b 100644 --- a/pkgs/tools/package-management/lix/default.nix +++ b/pkgs/tools/package-management/lix/default.nix @@ -217,14 +217,14 @@ lib.makeExtensible ( attrName = "lix_2_95"; lix-args = rec { - version = "2.95.2"; + version = "2.95.3"; src = fetchFromGitea { domain = "git.lix.systems"; owner = "lix-project"; repo = "lix"; rev = version; - hash = "sha256-nFxJMIdcGTI9NiHAa5HZ2BmcGFLwC2pTq+V4Gjc499I="; + hash = "sha256-rEhhsqccghnnJHjsqCCBzdD7PyF/ibDe8zadnajBmjI="; }; cargoDeps = rustPlatform.fetchCargoVendor { From 53819b8cb06fe2800c5ddab81bb4d948334a01f6 Mon Sep 17 00:00:00 2001 From: Tyce Herrman Date: Wed, 2 Sep 2026 11:43:41 -0400 Subject: [PATCH 019/117] lix: add update script for 2.95 releases Extract version, source, and Cargo definitions consistently for 2.94, 2.95, and the development snapshot. Keep scope construction, patches, and aliases in default.nix. Isolate the 2.95 updater in its release file so replacing a shared Cargo hash cannot modify the development snapshot. Restrict automated updates to the 2.95 release series. Assisted-by: Codex (gpt-5.6-sol) Assisted-by: Codex (GPT-6) --- pkgs/tools/package-management/lix/2.94.nix | 21 +++++++ pkgs/tools/package-management/lix/2.95.nix | 30 ++++++++++ .../package-management/lix/common-lix.nix | 2 + pkgs/tools/package-management/lix/default.nix | 55 ++----------------- pkgs/tools/package-management/lix/git.nix | 21 +++++++ 5 files changed, 78 insertions(+), 51 deletions(-) create mode 100644 pkgs/tools/package-management/lix/2.94.nix create mode 100644 pkgs/tools/package-management/lix/2.95.nix create mode 100644 pkgs/tools/package-management/lix/git.nix diff --git a/pkgs/tools/package-management/lix/2.94.nix b/pkgs/tools/package-management/lix/2.94.nix new file mode 100644 index 000000000000..978712923cca --- /dev/null +++ b/pkgs/tools/package-management/lix/2.94.nix @@ -0,0 +1,21 @@ +{ + fetchFromGitea, + rustPlatform, +}: +rec { + version = "2.94.2"; + + src = fetchFromGitea { + domain = "git.lix.systems"; + owner = "lix-project"; + repo = "lix"; + rev = version; + hash = "sha256-Nmqsl/YCnBW5U3TUfFWHGVUbyS2/Ll655BAE3qZilC4="; + }; + + cargoDeps = rustPlatform.fetchCargoVendor { + name = "lix-${version}"; + inherit src; + hash = "sha256-APm8m6SVEAO17BBCka13u85/87Bj+LePP7Y3zHA3Mpg="; + }; +} diff --git a/pkgs/tools/package-management/lix/2.95.nix b/pkgs/tools/package-management/lix/2.95.nix new file mode 100644 index 000000000000..ee81bcbb5081 --- /dev/null +++ b/pkgs/tools/package-management/lix/2.95.nix @@ -0,0 +1,30 @@ +{ + fetchFromGitea, + nix-update-script, + rustPlatform, +}: +rec { + version = "2.95.3"; + + src = fetchFromGitea { + domain = "git.lix.systems"; + owner = "lix-project"; + repo = "lix"; + rev = version; + hash = "sha256-rEhhsqccghnnJHjsqCCBzdD7PyF/ibDe8zadnajBmjI="; + }; + + cargoDeps = rustPlatform.fetchCargoVendor { + name = "lix-${version}"; + inherit src; + hash = "sha256-a5XtutX+NS4wOqxeqbscWZMs99teKick5+cQfbCRGxQ="; + }; + + updateScript = nix-update-script { + attrPath = "lixPackageSets.lix_2_95.lix"; + extraArgs = [ + "--override-filename=pkgs/tools/package-management/lix/2.95.nix" + "--version-regex=^(2[.]95[.][0-9]+)$" + ]; + }; +} diff --git a/pkgs/tools/package-management/lix/common-lix.nix b/pkgs/tools/package-management/lix/common-lix.nix index b783fe1671d5..2c22bdbd0272 100644 --- a/pkgs/tools/package-management/lix/common-lix.nix +++ b/pkgs/tools/package-management/lix/common-lix.nix @@ -10,6 +10,7 @@ docCargoDeps ? null, patches ? [ ], knownVulnerabilities ? [ ], + updateScript ? null, }@args: assert lib.assertMsg ( @@ -504,6 +505,7 @@ stdenv.mkDerivation (finalAttrs: { passthru = { inherit aws-sdk-cpp boehmgc; + inherit updateScript; tests = { misc = nixosTests.nix-misc.default.passthru.override { nixPackage = finalAttrs.finalPackage; }; installer = nixosTests.installer.simple.override { selectNixPackage = _: finalAttrs.finalPackage; }; diff --git a/pkgs/tools/package-management/lix/default.nix b/pkgs/tools/package-management/lix/default.nix index 5edfe3b5518b..208815aefb03 100644 --- a/pkgs/tools/package-management/lix/default.nix +++ b/pkgs/tools/package-management/lix/default.nix @@ -28,6 +28,7 @@ nixos-rebuild-ng, colmena, nix-update, + nix-update-script, nix-init, nurl, @@ -190,23 +191,7 @@ lib.makeExtensible ( lix_2_94 = self.makeLixScope { attrName = "lix_2_94"; - lix-args = rec { - version = "2.94.2"; - - src = fetchFromGitea { - domain = "git.lix.systems"; - owner = "lix-project"; - repo = "lix"; - rev = version; - hash = "sha256-Nmqsl/YCnBW5U3TUfFWHGVUbyS2/Ll655BAE3qZilC4="; - }; - - cargoDeps = rustPlatform.fetchCargoVendor { - name = "lix-${version}"; - inherit src; - hash = "sha256-APm8m6SVEAO17BBCka13u85/87Bj+LePP7Y3zHA3Mpg="; - }; - + lix-args = (import ./2.94.nix { inherit fetchFromGitea rustPlatform; }) // { patches = [ lixMdbookPatch ]; @@ -216,23 +201,7 @@ lib.makeExtensible ( lix_2_95 = self.makeLixScope { attrName = "lix_2_95"; - lix-args = rec { - version = "2.95.3"; - - src = fetchFromGitea { - domain = "git.lix.systems"; - owner = "lix-project"; - repo = "lix"; - rev = version; - hash = "sha256-rEhhsqccghnnJHjsqCCBzdD7PyF/ibDe8zadnajBmjI="; - }; - - cargoDeps = rustPlatform.fetchCargoVendor { - name = "lix-${version}"; - inherit src; - hash = "sha256-a5XtutX+NS4wOqxeqbscWZMs99teKick5+cQfbCRGxQ="; - }; - + lix-args = (import ./2.95.nix { inherit fetchFromGitea rustPlatform nix-update-script; }) // { patches = [ lixFunctional2TimeoutPatch ]; @@ -242,23 +211,7 @@ lib.makeExtensible ( git = self.makeLixScope { attrName = "git"; - lix-args = rec { - version = "2.96.0-pre-20260408_${builtins.substring 0 12 src.rev}"; - - src = fetchFromGitea { - domain = "git.lix.systems"; - owner = "lix-project"; - repo = "lix"; - rev = "bc9fb560ac2d36cd317a856ee96785ea2055fbff"; - hash = "sha256-bONRPjhk5OZdnkQZexZNJzlvwIPg31Gy7fNiwGoX3BQ="; - }; - - cargoDeps = rustPlatform.fetchCargoVendor { - name = "lix-${version}"; - inherit src; - hash = "sha256-a5XtutX+NS4wOqxeqbscWZMs99teKick5+cQfbCRGxQ="; - }; - }; + lix-args = import ./git.nix { inherit fetchFromGitea rustPlatform; }; }; latest = self.lix_2_95; diff --git a/pkgs/tools/package-management/lix/git.nix b/pkgs/tools/package-management/lix/git.nix new file mode 100644 index 000000000000..541a2bbac196 --- /dev/null +++ b/pkgs/tools/package-management/lix/git.nix @@ -0,0 +1,21 @@ +{ + fetchFromGitea, + rustPlatform, +}: +rec { + version = "2.96.0-pre-20260408_${builtins.substring 0 12 src.rev}"; + + src = fetchFromGitea { + domain = "git.lix.systems"; + owner = "lix-project"; + repo = "lix"; + rev = "bc9fb560ac2d36cd317a856ee96785ea2055fbff"; + hash = "sha256-bONRPjhk5OZdnkQZexZNJzlvwIPg31Gy7fNiwGoX3BQ="; + }; + + cargoDeps = rustPlatform.fetchCargoVendor { + name = "lix-${version}"; + inherit src; + hash = "sha256-a5XtutX+NS4wOqxeqbscWZMs99teKick5+cQfbCRGxQ="; + }; +} From 6cf20e6351ed57da89d7e8902ca47151d000be96 Mon Sep 17 00:00:00 2001 From: Tyce Herrman Date: Wed, 2 Sep 2026 11:43:43 -0400 Subject: [PATCH 020/117] lix: add tyceherrman as maintainer Assisted-by: Codex (gpt-5.6-sol) --- pkgs/tools/package-management/lix/common-lix.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/tools/package-management/lix/common-lix.nix b/pkgs/tools/package-management/lix/common-lix.nix index 2c22bdbd0272..c5782b122c6a 100644 --- a/pkgs/tools/package-management/lix/common-lix.nix +++ b/pkgs/tools/package-management/lix/common-lix.nix @@ -527,6 +527,7 @@ stdenv.mkDerivation (finalAttrs: { homepage = "https://lix.systems"; license = lib.licenses.lgpl21Plus; teams = [ lib.teams.lix ]; + maintainers = [ lib.maintainers.tyceherrman ]; platforms = lib.platforms.unix; outputsToInstall = [ "out" ] ++ lib.optional enableDocumentation "man"; mainProgram = "nix"; From 0fbaab0484a72c5f531c66de4e2be37b5b1e08c0 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 9 Sep 2026 07:39:54 +0000 Subject: [PATCH 021/117] qgis: 4.2.1 -> 4.2.2 --- pkgs/applications/gis/qgis/unwrapped.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/gis/qgis/unwrapped.nix b/pkgs/applications/gis/qgis/unwrapped.nix index cb0efdb25402..7be40652954e 100644 --- a/pkgs/applications/gis/qgis/unwrapped.nix +++ b/pkgs/applications/gis/qgis/unwrapped.nix @@ -88,14 +88,14 @@ let in stdenv.mkDerivation rec { pname = "qgis-unwrapped"; - version = "4.2.1"; + version = "4.2.2"; outputs = [ "out" ] ++ lib.optional (!stdenv.hostPlatform.isDarwin) "man"; src = fetchFromGitHub { owner = "qgis"; repo = "QGIS"; rev = "final-${lib.replaceStrings [ "." ] [ "_" ] version}"; - hash = "sha256-tdZNSA6kZHwS96YRbN7YF+ODPJrnINa/QGCo8pw196I="; + hash = "sha256-gEUShI09n7fpLcfKaNmiatB8pco0yJ227Ge7pPnMxCY="; }; postPatch = '' From cd8b8156e07bd268278bb08aa71987e6aa40224a Mon Sep 17 00:00:00 2001 From: Elias Khanzada Date: Fri, 18 Sep 2026 13:59:11 -0700 Subject: [PATCH 022/117] gnome-mahjongg: 49.1.1 -> 51.0 Assisted-by: Claude Code (model: Claude Opus 5, claude-opus-5) --- pkgs/by-name/gn/gnome-mahjongg/package.nix | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/gn/gnome-mahjongg/package.nix b/pkgs/by-name/gn/gnome-mahjongg/package.nix index 05fc12f048d7..1545277bb26e 100644 --- a/pkgs/by-name/gn/gnome-mahjongg/package.nix +++ b/pkgs/by-name/gn/gnome-mahjongg/package.nix @@ -9,7 +9,6 @@ libadwaita, librsvg, gettext, - itstool, libxml2, meson, ninja, @@ -20,11 +19,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "gnome-mahjongg"; - version = "49.1.1"; + version = "51.0"; src = fetchurl { url = "mirror://gnome/sources/gnome-mahjongg/${lib.versions.major finalAttrs.version}/gnome-mahjongg-${finalAttrs.version}.tar.xz"; - hash = "sha256-6e3TGsJpi42aW+HRHGDUNFCoifh2nMoL7zOVoRpdX9E="; + hash = "sha256-g4moJK97Xq6S1snGLqn94VJ/iAwQ/lEkbTi+7DG4wog="; }; nativeBuildInputs = [ @@ -34,7 +33,6 @@ stdenv.mkDerivation (finalAttrs: { desktop-file-utils pkg-config libxml2 - itstool gettext wrapGAppsHook4 glib # for glib-compile-schemas @@ -59,7 +57,7 @@ stdenv.mkDerivation (finalAttrs: { description = "Disassemble a pile of tiles by removing matching pairs"; mainProgram = "gnome-mahjongg"; teams = [ lib.teams.gnome ]; - license = lib.licenses.gpl2Plus; + license = lib.licenses.gpl3Plus; platforms = lib.platforms.unix; }; }) From 906ded2f2e8c20b101da1d8651ff1ca062f0e88a Mon Sep 17 00:00:00 2001 From: Elias Khanzada Date: Fri, 18 Sep 2026 14:01:32 -0700 Subject: [PATCH 023/117] gnome-mahjongg: enable tests Assisted-by: Claude Code (model: Claude Opus 5, claude-opus-5) --- pkgs/by-name/gn/gnome-mahjongg/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/gn/gnome-mahjongg/package.nix b/pkgs/by-name/gn/gnome-mahjongg/package.nix index 1545277bb26e..15b3f296cd57 100644 --- a/pkgs/by-name/gn/gnome-mahjongg/package.nix +++ b/pkgs/by-name/gn/gnome-mahjongg/package.nix @@ -45,6 +45,8 @@ stdenv.mkDerivation (finalAttrs: { librsvg ]; + doCheck = true; + passthru = { updateScript = gnome.updateScript { packageName = "gnome-mahjongg"; From bd8ef45bbeb262a43f58a77de1b2bc6a238d88d5 Mon Sep 17 00:00:00 2001 From: gregory langlais <_@gregorylanglais.com> Date: Wed, 23 Sep 2026 16:19:24 -0700 Subject: [PATCH 024/117] maintainers: add gregl83 --- maintainers/maintainer-list.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index c3680f85b6ce..591b329918ab 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -10799,6 +10799,12 @@ githubId = 273582; name = "greg"; }; + gregl83 = { + email = "general+nixpkgs@gregorylanglais.com"; + github = "gregl83"; + githubId = 1258023; + name = "gregory langlais"; + }; gregshuflin = { email = "greg@everdayimshuflin.com"; github = "neunenak"; From e20afc048e0121de5a4259dd66443e138f34c44b Mon Sep 17 00:00:00 2001 From: gregory langlais <_@gregorylanglais.com> Date: Wed, 23 Sep 2026 16:19:28 -0700 Subject: [PATCH 025/117] paq: add gregl83 as maintainer --- pkgs/by-name/pa/paq/package.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/pa/paq/package.nix b/pkgs/by-name/pa/paq/package.nix index b0ea3853eb73..ef8ce99cabe8 100644 --- a/pkgs/by-name/pa/paq/package.nix +++ b/pkgs/by-name/pa/paq/package.nix @@ -29,7 +29,10 @@ rustPlatform.buildRustPackage (finalAttrs: { homepage = "https://github.com/gregl83/paq"; changelog = "https://github.com/gregl83/paq/releases/tag/v${finalAttrs.version}"; license = lib.licenses.mit; - maintainers = with lib.maintainers; [ lafrenierejm ]; + maintainers = with lib.maintainers; [ + gregl83 + lafrenierejm + ]; mainProgram = "paq"; }; }) From e0cf42a68af9ffea7049594f6844d26d2bc26828 Mon Sep 17 00:00:00 2001 From: Vladislav Grechannik Date: Thu, 24 Sep 2026 16:59:41 +0200 Subject: [PATCH 026/117] element-desktop: 1.12.28 -> 1.12.29 Diff: https://github.com/element-hq/element-web/compare/v1.12.28...v1.12.29 Changelog: https://github.com/element-hq/element-web/blob/v1.12.29/CHANGELOG.md --- pkgs/by-name/el/element-desktop/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/el/element-desktop/package.nix b/pkgs/by-name/el/element-desktop/package.nix index 6d206b0d7faf..f9e406d7b9b2 100644 --- a/pkgs/by-name/el/element-desktop/package.nix +++ b/pkgs/by-name/el/element-desktop/package.nix @@ -30,13 +30,13 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "element-desktop"; - version = "1.12.28"; + version = "1.12.29"; src = fetchFromGitHub { owner = "element-hq"; repo = "element-web"; tag = "v${finalAttrs.version}"; - hash = "sha256-goP/f1Go7227R2euXu8aJrwHeUp84DQ+18ztyf4uXhM="; + hash = "sha256-0LiasFrVMnMX1Z4TcP+Eti58X7+ICksqKnerQKj2ayI="; }; pnpmDeps = fetchPnpmDeps { @@ -152,7 +152,7 @@ stdenv.mkDerivation (finalAttrs: { ''; # The desktop item properties should be kept in sync with data from upstream: - # https://github.com/element-hq/element-desktop/blob/develop/package.json + # https://github.com/element-hq/element-web/blob/develop/apps/desktop/package.json desktopItems = [ (makeDesktopItem { name = "element-desktop"; From 3bf5a0f631e40a6304d619a1083d44c929e823b0 Mon Sep 17 00:00:00 2001 From: Vladislav Grechannik Date: Thu, 24 Sep 2026 17:09:18 +0200 Subject: [PATCH 027/117] element-web: 1.12.28 -> 1.12.29 Diff: https://github.com/element-hq/element-web/compare/v1.12.28...v1.12.29 Changelog: https://github.com/element-hq/element-web/blob/v1.12.29/CHANGELOG.md --- pkgs/by-name/el/element-web-unwrapped/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/el/element-web-unwrapped/package.nix b/pkgs/by-name/el/element-web-unwrapped/package.nix index 418d0beb6db6..e82460c6102c 100644 --- a/pkgs/by-name/el/element-web-unwrapped/package.nix +++ b/pkgs/by-name/el/element-web-unwrapped/package.nix @@ -25,13 +25,13 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "element-web"; - version = "1.12.28"; + version = "1.12.29"; src = fetchFromGitHub { owner = "element-hq"; repo = "element-web"; tag = "v${finalAttrs.version}"; - hash = "sha256-goP/f1Go7227R2euXu8aJrwHeUp84DQ+18ztyf4uXhM="; + hash = "sha256-0LiasFrVMnMX1Z4TcP+Eti58X7+ICksqKnerQKj2ayI="; }; pnpmDeps = fetchPnpmDeps { From fb9f61bf1d9e3813517d8347a60b8cb21211c162 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 25 Sep 2026 22:02:15 +0000 Subject: [PATCH 028/117] phpExtensions.blackfire: 2026.9.0 -> 2026.9.2 --- pkgs/by-name/bl/blackfire/php-probe.nix | 42 ++++++++++++------------- 1 file changed, 21 insertions(+), 21 deletions(-) diff --git a/pkgs/by-name/bl/blackfire/php-probe.nix b/pkgs/by-name/bl/blackfire/php-probe.nix index 941339a35b3b..ed53bfc1ecfe 100644 --- a/pkgs/by-name/bl/blackfire/php-probe.nix +++ b/pkgs/by-name/bl/blackfire/php-probe.nix @@ -16,47 +16,47 @@ let phpMajor = lib.versions.majorMinor php.version; inherit (stdenv.hostPlatform) system; - version = "2026.9.0"; + version = "2026.9.2"; hashes = { "x86_64-linux" = { system = "amd64"; hash = { - "8.1" = "sha256-0AAgiBdiIQOxSSttD2ERzSTqPM1rLwlQFHZ6ARRSgmI="; - "8.2" = "sha256-usSNoM1XeVWKuHLlSMvONAucVa1ZEAb3+I66oOnzGB0="; - "8.3" = "sha256-65GoEhgFsQbQleSVuRnHPSZAiCfEUmyVWWhnybnrgaA="; - "8.4" = "sha256-0if1fQa7b41TjC3d1ck65cJP7lKdoL670V9t+PLL+qk="; - "8.5" = "sha256-3k5jQ+vbxLGp78MRzjiw7uP+tCcEs5gAYM2MEoiYdtk="; + "8.1" = "sha256-Rh26CehFWvZbri+wE+NOit6Mc6LB55IVZ0FT63/GBew="; + "8.2" = "sha256-HoaC8XAGxqPvQPkpsqTjBxd6Z8FnB/cjk5uC9ogNMAs="; + "8.3" = "sha256-nRwvQYootheK0qEWbEJoC82butcJRFz65zhxey56/Bk="; + "8.4" = "sha256-rqo9U0S2Cuhy+CiILeXo2DW22y9xb/7QB3l7Et0IbTM="; + "8.5" = "sha256-hf/pe+Go8qhHxqAodbLyn60t1FJGZtQ965pMFCJ4t0M="; }; }; "i686-linux" = { system = "i386"; hash = { - "8.1" = "sha256-fmmbY4ecnE05XNxGKq11HcYhs9z7SggLx9iXICHE6DQ="; - "8.2" = "sha256-9WP+FpULl0PQJ+0qxxZfm5xJS/A6N137yGk9gv4cYvI="; - "8.3" = "sha256-Io2gGAhXLAVdHoaKwKvJWA1N71IJAKeJkudLs8DZUl8="; - "8.4" = "sha256-JoGiB8ew3D/qSi7Pg/q67mXLsUy4UDVsazgxgb5BJTM="; - "8.5" = "sha256-bSfbhFHV8Zs4cpOfDnKItNlF9++0opUtosTpnosacdU="; + "8.1" = "sha256-BgOAsLqMqsyXfEIgx/Buaz4jjU1TN8lxVPTSvQzCn7M="; + "8.2" = "sha256-D1FiwfYF8tRM1uMEWPauY+SzQNyL9kszVb5pD5vOBwA="; + "8.3" = "sha256-SZ9KFC+ISp5LgElLeQTOInlgoSqWV9+oRdC6yJ5P3WA="; + "8.4" = "sha256-x4ZTJs1VLipdEEAhjb+pG4Q25a2czBkEPtucHGdZINw="; + "8.5" = "sha256-zzSZsGu2POr97O5fwKRCwJqs6+lO1HqfG6o5HKL4zVQ="; }; }; "aarch64-linux" = { system = "arm64"; hash = { - "8.1" = "sha256-7/2Q9Kx3ZEpI0Inj88CfTDzr0sjVpws3DH8KTP26PR0="; - "8.2" = "sha256-suFGyE94wY4xHfPk77OXzkqU+Ulb+f42drDZY/M9ZNs="; - "8.3" = "sha256-z5IfXX7DElerdRTnq3R95t8IvG0Hl9EKXBw1QbRlDkY="; - "8.4" = "sha256-ceTjQ6gtiWJEte5WuVuyc+eTEb3khobYoCWNGP+Vkeo="; - "8.5" = "sha256-1jX564B/tLBgb7jN6MB5DfpRgYy0xxmtAaAv768FQqo="; + "8.1" = "sha256-QGe/XJt2N7UFpW0ahKo+hCZO7X80L31hAp0D6oreGt4="; + "8.2" = "sha256-QyhbXXlhBdoNUYJcPOt4w4sA45ELtY4IERD8GUS3I4c="; + "8.3" = "sha256-+l9RGCmhQsdtqntfUk22d1zVIcAxuLw4mHpe4WcfGr8="; + "8.4" = "sha256-hUI/z+PNAj7gl9UCGes/TnhV6zK82LMfhEfi72gsy7c="; + "8.5" = "sha256-MaqGbXacLeDUPlskuETtzv1cXZTO0/EF0IW49N6eZMY="; }; }; "aarch64-darwin" = { system = "arm64"; hash = { - "8.1" = "sha256-JQZKX8qChvBS3S8cqtxmooZMsFlFqfffnQbNldYNR+M="; - "8.2" = "sha256-nGQdweskEw9tiK51IGcu7cGKJJwtmNBL9fZLMUCuiB8="; - "8.3" = "sha256-sHQOg6QC+Mm5KwQVwKmeOVR3fUkN2NH9utHs667Oipw="; - "8.4" = "sha256-Btrz+U9ejW/Jl1cWBRt5XGV1IzjxK+FJaQwXIgYR/NI="; - "8.5" = "sha256-zSQeBioU/3c7HrqEz+9z8vam3EHkR0KbC80/mIuTAFE="; + "8.1" = "sha256-oG7Doie9hoieBM649S1XlagBaYAWAjJu2PrzYSDLKL0="; + "8.2" = "sha256-MJi0cve8+eItBcC6UkuxYTzclB3OMC+Hhlmd++xD1MU="; + "8.3" = "sha256-3oJtMuVKGUgpduMp7snSdGE/BH764EA7yz+N70+qFNg="; + "8.4" = "sha256-0HOCBB9dgU9Vq5/F0iKCzumjwT81qxHElPsLGKgVhr0="; + "8.5" = "sha256-Hi9bC/CigkA3VWFTqfE7JzBcGGJAhUwnmMndHgbFIW4="; }; }; }; From 833acbe17624d1ff5189e76313426f24e378073a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 26 Sep 2026 07:53:41 +0000 Subject: [PATCH 029/117] blackfire: 2026.9.0 -> 2026.9.1 --- pkgs/by-name/bl/blackfire/package.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/bl/blackfire/package.nix b/pkgs/by-name/bl/blackfire/package.nix index 52d71979fc3e..e855e44a1ddd 100644 --- a/pkgs/by-name/bl/blackfire/package.nix +++ b/pkgs/by-name/bl/blackfire/package.nix @@ -11,7 +11,7 @@ stdenv.mkDerivation rec { pname = "blackfire"; - version = "2026.9.0"; + version = "2026.9.1"; src = passthru.sources.${stdenv.hostPlatform.system} @@ -60,19 +60,19 @@ stdenv.mkDerivation rec { sources = { "x86_64-linux" = fetchurl { url = "https://packages.blackfire.io/debian/pool/any/main/b/blackfire/blackfire_${version}_amd64.deb"; - hash = "sha256-mm93TmfrSMP5+hVtWQ2CkUqmDqYraL4H7NVLXZ7xDqs="; + hash = "sha256-ElktV5SSt4zhvVnQS8qljbPDGH0qM85i7WztyoDyvcM="; }; "i686-linux" = fetchurl { url = "https://packages.blackfire.io/debian/pool/any/main/b/blackfire/blackfire_${version}_i386.deb"; - hash = "sha256-nz0YYTdH0Rcs4f0aJu8Bkg/NwLNxiFwSq8kkRoa+VEA="; + hash = "sha256-vl6PvMsqc3GyIsrYl1WpV1psxuuszSfN1TdRH5FW9qE="; }; "aarch64-linux" = fetchurl { url = "https://packages.blackfire.io/debian/pool/any/main/b/blackfire/blackfire_${version}_arm64.deb"; - hash = "sha256-RTTNU3c9gJQRh8vjrCnhPh/mKWKs9jHUd3gund3UZWM="; + hash = "sha256-fjcp+gOHna7grTl972jslY8hYdjWhfxbA4ncHfCAkGw="; }; "aarch64-darwin" = fetchurl { url = "https://packages.blackfire.io/blackfire/${version}/blackfire-darwin_arm64.pkg.tar.gz"; - hash = "sha256-xa9lqDOVS0uPLeAyQ3fvkp3SNN8Hhv66gitjgKk/p6M="; + hash = "sha256-xNn78U4jdABzWrSKMSSZXE5tuf/SRK8OwdhldKBBKk0="; }; }; From 57e9bc9f54f951e4b4c1b355303ebf8e71e2c799 Mon Sep 17 00:00:00 2001 From: wrench-exile-legacy Date: Sat, 26 Sep 2026 15:01:28 +0100 Subject: [PATCH 030/117] maintainers: update wrench-exile-legacy --- maintainers/maintainer-list.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index 050f0d950ba3..c5cb38ee85d2 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -31571,10 +31571,10 @@ ]; }; wrench-exile-legacy = { - email = "user@wrench-exile-legacy.site"; + email = "hello@wrenchd.dev"; github = "wrench-exile-legacy"; githubId = 280737824; - name = "wrench"; + name = "wrenchd"; }; wrmilling = { name = "Winston R. Milling"; From a7c694d3d807468e71866166d1e09f3db4500c6a Mon Sep 17 00:00:00 2001 From: Luflosi Date: Sat, 26 Sep 2026 18:20:28 +0200 Subject: [PATCH 031/117] proj: Fix compatibility issue with mapnik Without this change, mapnik fails to compile with the following strange error message: ``` CMake Error in CMakeLists.txt: No known features for C compiler "" version . ``` --- pkgs/by-name/pr/proj/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/pr/proj/package.nix b/pkgs/by-name/pr/proj/package.nix index 90edb8a6665a..326f2c579c16 100644 --- a/pkgs/by-name/pr/proj/package.nix +++ b/pkgs/by-name/pr/proj/package.nix @@ -14,6 +14,7 @@ python3, cacert, writableTmpDirAsHomeHook, + fetchpatch2, }: stdenv.mkDerivation (finalAttrs: { @@ -32,6 +33,14 @@ stdenv.mkDerivation (finalAttrs: { patches = [ # https://github.com/OSGeo/PROJ/pull/3252 ./only-add-curl-for-static-builds.patch + + # Unbreak mapnik + (fetchpatch2 { + name = "fix_issue_with_target_compile_features.patch"; + # https://github.com/OSGeo/PROJ/pull/4863 + url = "https://github.com/OSGeo/PROJ/commit/7ea0fd3ba479845464b34ccf5265b8e6d055cde5.patch?full_index=1"; + hash = "sha256-IIe0T1/8Jv7tvhUupFn46PaFi7zggAT79EC55cmxHSs="; + }) ]; outputs = [ From 0790a027a9e66eacdf9126e719692e2b5a36bb27 Mon Sep 17 00:00:00 2001 From: Sizhe Zhao Date: Sun, 27 Sep 2026 01:38:49 +0800 Subject: [PATCH 032/117] nixosTests.pocket-id: fix postgresql test Assisted-by: Pi coding agent (gpt-5.6-sol) --- nixos/tests/pocket-id.nix | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/nixos/tests/pocket-id.nix b/nixos/tests/pocket-id.nix index d79866882c17..5acbd9e5575d 100644 --- a/nixos/tests/pocket-id.nix +++ b/nixos/tests/pocket-id.nix @@ -36,13 +36,18 @@ in enable = true; settings = { PORT = 10001; - DB_CONNECTION_STRING = "host=/run/postgresql user=${username} database=${username}"; + DB_CONNECTION_STRING = "postgresql:///${username}?host=/run/postgresql"; }; credentials = { inherit ENCRYPTION_KEY; }; }; + systemd.services.pocket-id = { + after = [ "postgresql.target" ]; + requires = [ "postgresql.target" ]; + }; + services.postgresql = { enable = true; ensureUsers = [ From ce00c9e1ae262e1472c8d6888c9ea60ef308d9df Mon Sep 17 00:00:00 2001 From: Luflosi Date: Mon, 30 Jun 2025 17:46:44 +0200 Subject: [PATCH 033/117] python3Packages.tsv: init at 1.2 https://github.com/adamnovak/tsv --- .../python-modules/tsv/default.nix | 32 +++++++++++++++++++ pkgs/top-level/python-packages.nix | 2 ++ 2 files changed, 34 insertions(+) create mode 100644 pkgs/development/python-modules/tsv/default.nix diff --git a/pkgs/development/python-modules/tsv/default.nix b/pkgs/development/python-modules/tsv/default.nix new file mode 100644 index 000000000000..de77aab6f7dc --- /dev/null +++ b/pkgs/development/python-modules/tsv/default.nix @@ -0,0 +1,32 @@ +{ + lib, + buildPythonPackage, + fetchFromGitHub, + setuptools, +}: + +buildPythonPackage { + pname = "tsv"; + version = "1.2"; + pyproject = true; + + src = fetchFromGitHub { + owner = "adamnovak"; + repo = "tsv"; + rev = "379189e9da4c1b65d0587bb32f3b51e6a7c936c8"; # No Git Tags + hash = "sha256-Axs597Ir7h4mB07Vfy3Xiqwag2rimqBAnodPrO1Lxa4="; + }; + + build-system = [ + setuptools + ]; + + pythonImportsCheck = [ "tsv" ]; + + meta = { + description = "Tab-Separated Value IO Library"; + homepage = "https://github.com/adamnovak/tsv"; + license = with lib.licenses; [ mit ]; + maintainers = with lib.maintainers; [ Luflosi ]; + }; +} diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index d61c14f995ef..82df39eb5e79 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -21263,6 +21263,8 @@ self: super: with self; { tstr = callPackage ../development/python-modules/tstr { }; + tsv = callPackage ../development/python-modules/tsv { }; + tt-flash = callPackage ../development/python-modules/tt-flash { }; tt-perf-report = callPackage ../development/python-modules/tt-perf-report { }; From 050004990a54899a2ba52c8b7eaedfb32c45bbd9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Sat, 26 Sep 2026 20:56:13 +0200 Subject: [PATCH 034/117] home-assistant-custom-lovelace-modules.tankerkoenig-card: 1.8.2 -> 1.9.0 Diff: https://github.com/timmaurice/lovelace-tankerkoenig-card/compare/1.8.2...1.9.0 Changelog: https://github.com/timmaurice/lovelace-tankerkoenig-card/releases/tag/1.9.0 --- .../custom-lovelace-modules/tankerkoenig-card/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/servers/home-assistant/custom-lovelace-modules/tankerkoenig-card/package.nix b/pkgs/servers/home-assistant/custom-lovelace-modules/tankerkoenig-card/package.nix index ba9c48ee6e6b..4717b6c2ebd9 100644 --- a/pkgs/servers/home-assistant/custom-lovelace-modules/tankerkoenig-card/package.nix +++ b/pkgs/servers/home-assistant/custom-lovelace-modules/tankerkoenig-card/package.nix @@ -6,16 +6,16 @@ buildNpmPackage (finalAttrs: { pname = "tankerkoenig-card"; - version = "1.8.2"; + version = "1.9.0"; src = fetchFromGitHub { owner = "timmaurice"; repo = "lovelace-tankerkoenig-card"; tag = finalAttrs.version; - hash = "sha256-GMX6kIyoZN26NCgqPTj44TC3Yo+zTcmSm5ToakgIojA="; + hash = "sha256-wRwTr7sMS32NIrVqF7+oFwlB1/h8pR908Nd0K8IbRts="; }; - npmDepsHash = "sha256-OrEQjE2XMcumCyfdKKMkFWO1vgOytVjsguTuU6AkZr0="; + npmDepsHash = "sha256-QbvLeAVTp7V185hens+TPpW0Wo0PwFdCMRF2akxZJ9I="; installPhase = '' runHook preInstall From 726f5db117214a5ed60d0a7b23cd170e91653489 Mon Sep 17 00:00:00 2001 From: Luflosi Date: Mon, 30 Jun 2025 17:47:49 +0200 Subject: [PATCH 035/117] python3Packages.rebiber: init at 1.3.0 https://github.com/yuchenlin/rebiber --- .../python-modules/rebiber/default.nix | 41 +++++++++++++++++++ pkgs/top-level/python-packages.nix | 2 + 2 files changed, 43 insertions(+) create mode 100644 pkgs/development/python-modules/rebiber/default.nix diff --git a/pkgs/development/python-modules/rebiber/default.nix b/pkgs/development/python-modules/rebiber/default.nix new file mode 100644 index 000000000000..6714e9fbc3cf --- /dev/null +++ b/pkgs/development/python-modules/rebiber/default.nix @@ -0,0 +1,41 @@ +{ + lib, + buildPythonPackage, + fetchFromGitHub, + hatchling, + bibtexparser, + requests, + tqdm, +}: + +buildPythonPackage (finalAttrs: { + pname = "rebiber"; + version = "1.3.0"; + pyproject = true; + + src = fetchFromGitHub { + owner = "yuchenlin"; + repo = "rebiber"; + rev = "v${finalAttrs.version}"; + hash = "sha256-feV6xVb9g2rDG7cPYvccVmJsJMGpevVTYDD82OCcR6Y="; + }; + + build-system = [ + hatchling + ]; + + dependencies = [ + bibtexparser + requests + tqdm + ]; + + pythonImportsCheck = [ "rebiber" ]; + + meta = { + description = "Simple tool to update bib entries with their official information (e.g., DBLP or the ACL anthology)"; + homepage = "https://github.com/yuchenlin/rebiber"; + license = with lib.licenses; [ mit ]; + maintainers = with lib.maintainers; [ Luflosi ]; + }; +}) diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index 82df39eb5e79..f5486f4cda23 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -17886,6 +17886,8 @@ self: super: with self; { realtime = callPackage ../development/python-modules/realtime { }; + rebiber = callPackage ../development/python-modules/rebiber { }; + rebulk = callPackage ../development/python-modules/rebulk { }; recipe-scrapers = callPackage ../development/python-modules/recipe-scrapers { }; From d9107ea2c8c8a2735ea888b63229a46abd34dfb3 Mon Sep 17 00:00:00 2001 From: coolcuber Date: Sat, 26 Sep 2026 17:41:22 -0400 Subject: [PATCH 036/117] jack-autoconnect: fix version, modernize --- pkgs/by-name/ja/jack-autoconnect/package.nix | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/ja/jack-autoconnect/package.nix b/pkgs/by-name/ja/jack-autoconnect/package.nix index f46a4882b66b..09f70f8ddf51 100644 --- a/pkgs/by-name/ja/jack-autoconnect/package.nix +++ b/pkgs/by-name/ja/jack-autoconnect/package.nix @@ -10,7 +10,10 @@ stdenv.mkDerivation { pname = "jack_autoconnect"; # It does not have any versions (yet?) - version = "unstable-2021-02-01"; + version = "0-unstable-2021-02-01"; + + strictDeps = true; + __structuredAttrs = true; src = fetchFromGitHub { owner = "kripton"; @@ -31,8 +34,10 @@ stdenv.mkDerivation { ]; installPhase = '' + runHook preInstall mkdir -p -- "$out/bin" cp -- jack_autoconnect "$out/bin" + runHook postInstall ''; meta = { From ef9988601313b9cdd071de65047b24e611d3003a Mon Sep 17 00:00:00 2001 From: coolcuber Date: Sat, 26 Sep 2026 19:11:59 -0400 Subject: [PATCH 037/117] mmh: fix version; enable strictDeps, structuredAttrs --- pkgs/by-name/mm/mmh/package.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/mm/mmh/package.nix b/pkgs/by-name/mm/mmh/package.nix index 1618352e38ab..3c1aa096c0ec 100644 --- a/pkgs/by-name/mm/mmh/package.nix +++ b/pkgs/by-name/mm/mmh/package.nix @@ -11,7 +11,10 @@ let in stdenv.mkDerivation { pname = "mmh"; - version = "unstable-2023-09-24"; + version = "0.4-unstable-2023-09-24"; + + strictDeps = true; + __structuredAttrs = true; src = fetchurl { url = "http://git.marmaro.de/?p=mmh;a=snapshot;h=${rev};sf=tgz"; From 09b5d3436b87ad7c4b0dd4a9cd36a6053b37642c Mon Sep 17 00:00:00 2001 From: Otavio Salvador Date: Sun, 26 Jul 2026 01:05:40 -0300 Subject: [PATCH 038/117] whisrs: init at 0.1.27 Assisted-by: Claude Code (claude-opus-5) --- pkgs/by-name/wh/whisrs/package.nix | 67 ++++++++++++++++++++++++++++++ 1 file changed, 67 insertions(+) create mode 100644 pkgs/by-name/wh/whisrs/package.nix diff --git a/pkgs/by-name/wh/whisrs/package.nix b/pkgs/by-name/wh/whisrs/package.nix new file mode 100644 index 000000000000..9157f48e4919 --- /dev/null +++ b/pkgs/by-name/wh/whisrs/package.nix @@ -0,0 +1,67 @@ +{ + lib, + rustPlatform, + fetchFromGitHub, + + cmake, + installShellFiles, + llvmPackages, + pkg-config, + + alsa-lib, + libxkbcommon, + + nix-update-script, + versionCheckHook, +}: +rustPlatform.buildRustPackage (finalAttrs: { + pname = "whisrs"; + version = "0.1.27"; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "y0sif"; + repo = "whisrs"; + tag = "v${finalAttrs.version}"; + hash = "sha256-sBBxtq1YXKbYoXtaEfoUWLJjfVgGKrfnXbPXYE798tQ="; + }; + + cargoHash = "sha256-Us7WkzNUPYCwv+UfdEwkZe9Xdk9ejwnEJ8t8ZPEWujA="; + + nativeBuildInputs = [ + cmake + installShellFiles + llvmPackages.clang + pkg-config + rustPlatform.bindgenHook + ]; + + buildInputs = [ + alsa-lib + libxkbcommon + ]; + + # contrib/99-whisrs.rules is deliberately not installed: it grants /dev/uinput + # to the `input` group and would override the `uinput` group set by NixOS's + # hardware.uinput.enable. Users should enable that option instead. + postInstall = '' + installManPage contrib/whisrs.1 contrib/whisrsd.1 + install -Dm644 contrib/whisrs.service -t $out/lib/systemd/user + ''; + + versionCheckProgram = "${placeholder "out"}/bin/whisrsd"; + nativeInstallCheckInputs = [ versionCheckHook ]; + doInstallCheck = true; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "Voice-to-text dictation daemon that types transcriptions into the focused window"; + homepage = "https://github.com/y0sif/whisrs"; + license = lib.licenses.mit; + mainProgram = "whisrs"; + maintainers = with lib.maintainers; [ otavio ]; + platforms = lib.platforms.linux; + }; +}) From da0c95f456bf8c7f892cb4a59b1367f0c6d08fe6 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Sun, 27 Sep 2026 11:45:04 +1000 Subject: [PATCH 039/117] kexec-tools: add maintainer --- pkgs/by-name/ke/kexec-tools/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/ke/kexec-tools/package.nix b/pkgs/by-name/ke/kexec-tools/package.nix index fa65622e8444..bfcde6c16868 100644 --- a/pkgs/by-name/ke/kexec-tools/package.nix +++ b/pkgs/by-name/ke/kexec-tools/package.nix @@ -78,5 +78,6 @@ stdenv.mkDerivation rec { ]; license = lib.licenses.gpl2Only; mainProgram = "kexec"; + maintainers = [ lib.maintainers.zowoq ]; }; } From c3a2a89dc2a10f96af8ddc05d41137d0343c3de4 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Sun, 27 Sep 2026 11:50:15 +1000 Subject: [PATCH 040/117] nixos/kexec: add maintainer --- nixos/modules/system/boot/kexec.nix | 4 ++++ nixos/tests/kexec.nix | 2 +- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/nixos/modules/system/boot/kexec.nix b/nixos/modules/system/boot/kexec.nix index d5272ff4da95..89a8f752678c 100644 --- a/nixos/modules/system/boot/kexec.nix +++ b/nixos/modules/system/boot/kexec.nix @@ -9,6 +9,10 @@ let cfg = config.boot.kexec; in { + meta = { + inherit (pkgs.kexec-tools.meta) maintainers; + }; + options.boot.kexec = { enable = lib.mkEnableOption "kexec" // { default = lib.meta.availableOn pkgs.stdenv.hostPlatform pkgs.kexec-tools; diff --git a/nixos/tests/kexec.nix b/nixos/tests/kexec.nix index 0e40796a86c0..84af2ead82eb 100644 --- a/nixos/tests/kexec.nix +++ b/nixos/tests/kexec.nix @@ -2,7 +2,7 @@ { name = "kexec"; meta = with lib.maintainers; { - maintainers = [ + maintainers = pkgs.kexec-tools.meta.maintainers ++ [ flokli lassulus ]; From a53d27da92d583911473e56f39996ab418134bf3 Mon Sep 17 00:00:00 2001 From: Ethan Carter Edwards Date: Sun, 27 Sep 2026 01:01:49 -0400 Subject: [PATCH 041/117] newflasher: modernize Signed-off-by: Ethan Carter Edwards --- pkgs/by-name/ne/newflasher/package.nix | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/ne/newflasher/package.nix b/pkgs/by-name/ne/newflasher/package.nix index 3b2842119ffb..06ffc58ddb1c 100644 --- a/pkgs/by-name/ne/newflasher/package.nix +++ b/pkgs/by-name/ne/newflasher/package.nix @@ -2,14 +2,19 @@ lib, stdenv, fetchFromGitHub, + installShellFiles, expat, zlib, + versionCheckHook, }: stdenv.mkDerivation (finalAttrs: { pname = "newflasher"; version = "61"; + strictDeps = true; + __structuredAttrs = true; + src = fetchFromGitHub { owner = "munjeni"; repo = "newflasher"; @@ -17,6 +22,8 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-9qEGFzA5sMn+1MOKNTJeBukurzytksXitgXraPL0KDU="; }; + nativeBuildInputs = [ installShellFiles ]; + buildInputs = [ expat zlib @@ -24,10 +31,14 @@ stdenv.mkDerivation (finalAttrs: { installPhase = '' runHook preInstall - install -Dm755 newflasher $out/bin/newflasher + installBin newflasher + installManPage newflasher.1 runHook postInstall ''; + nativeInstallCheckInputs = [ versionCheckHook ]; + doInstallCheck = true; + meta = { description = "Flash tool for new Sony flash tool protocol (Xperia XZ Premium and newer)"; homepage = "https://github.com/munjeni/newflasher"; From cd64f70e6b997a118d6b1f1bffbe05336d6b6917 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 27 Sep 2026 06:48:41 +0000 Subject: [PATCH 042/117] python3Packages.pysillaprism: 0.2.0 -> 0.2.1 --- pkgs/development/python-modules/pysillaprism/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/pysillaprism/default.nix b/pkgs/development/python-modules/pysillaprism/default.nix index c1cddd06321e..f82219ded274 100644 --- a/pkgs/development/python-modules/pysillaprism/default.nix +++ b/pkgs/development/python-modules/pysillaprism/default.nix @@ -10,14 +10,14 @@ buildPythonPackage (finalAttrs: { pname = "pysillaprism"; - version = "0.2.0"; + version = "0.2.1"; pyproject = true; src = fetchFromGitHub { owner = "ebaschiera"; repo = "pysillaprism"; tag = "v${finalAttrs.version}"; - hash = "sha256-KpjKn62KOivu95thLeHiU8U+9xK1oVdE+yWN7NGFEA0="; + hash = "sha256-EkaHeudneVUlbH1dxF1uIXEnh4tfIppp9DzFz9L2GuM="; }; build-system = [ hatchling ]; From ff1380b1d2e9e94c456b7d954d03af5cd04a8bac Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 27 Sep 2026 06:59:13 +0000 Subject: [PATCH 043/117] tree-sitter-grammars.tree-sitter-php-only: 0.24.2-unstable-2026-03-19 -> 0.25.0-unstable-2026-09-24 --- pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix b/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix index 0b9866a57f61..b7b056934de2 100644 --- a/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix +++ b/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix @@ -2260,10 +2260,10 @@ }; php-only = { - version = "0.24.2-unstable-2026-03-19"; + version = "0.25.0-unstable-2026-09-24"; url = "github:tree-sitter/tree-sitter-php"; - rev = "3f2465c217d0a966d41e584b42d75522f2a3149e"; - hash = "sha256-RV6wHYVTOFdRYMqXdPw2Ryk3FadJJ4jcJVFjsJG8Ri0="; + rev = "92b5271b60bec77fb65b5e5bc41561e8dac81299"; + hash = "sha256-EkKYb9jatSl0/o+7tO2O3vx44ufDmZ4YJ/6t4il/Yk0="; meta = { license = lib.licenses.mit; maintainers = with lib.maintainers; [ From 8a766bf2a94020654f956c2bc7b2fa18084d603e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 27 Sep 2026 07:00:33 +0000 Subject: [PATCH 044/117] tree-sitter-grammars.tree-sitter-pkl: 0.20.0-unstable-2026-03-27 -> 0.21.0-unstable-2026-09-25 --- pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix b/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix index 0b9866a57f61..90eeb5b95f9a 100644 --- a/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix +++ b/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix @@ -2290,10 +2290,10 @@ }; pkl = { - version = "0.20.0-unstable-2026-03-27"; + version = "0.21.0-unstable-2026-09-25"; url = "github:apple/tree-sitter-pkl"; - rev = "f5beed1da8e5fc856a1a11e29a929d0b7cdcfe3c"; - hash = "sha256-q0K+q8GEOiwbgFjA/jiY/Hg6kPlgqMUvH8g+GdEDU3I="; + rev = "c95d8284940f5e1da2cd0d8f1ee45d7ef9ef75d1"; + hash = "sha256-dnGqTZ7Kga1sIJkzRSbqkhvIrPJMxOEhHnDKJuLyudM="; meta = { license = lib.licenses.asl20; maintainers = with lib.maintainers; [ From 73fb6a442fa6faad28f5659683387f5e0c06a86f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 27 Sep 2026 07:22:40 +0000 Subject: [PATCH 045/117] python3Packages.pyhik: 0.4.6 -> 0.4.7 --- pkgs/development/python-modules/pyhik/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/pyhik/default.nix b/pkgs/development/python-modules/pyhik/default.nix index 18ba93e0830a..c7ffc6fb67e6 100644 --- a/pkgs/development/python-modules/pyhik/default.nix +++ b/pkgs/development/python-modules/pyhik/default.nix @@ -9,14 +9,14 @@ buildPythonPackage (finalAttrs: { pname = "pyhik"; - version = "0.4.6"; + version = "0.4.7"; pyproject = true; src = fetchFromGitHub { owner = "mezz64"; repo = "pyHik"; tag = finalAttrs.version; - hash = "sha256-UlKQxbTnqxdyRYbpecP5OEnCILnAhifIsjEixxvVBjc="; + hash = "sha256-4XNp/qw4CLir05saCr8SDaOl6B1T58rDwZRnjinJOmc="; }; build-system = [ From 8f5692f40859d3182ecd6b3d6078ebcf365a33b1 Mon Sep 17 00:00:00 2001 From: Minijackson Date: Fri, 11 Sep 2026 08:43:35 +0200 Subject: [PATCH 046/117] python3Packages.django-pgware: init at 1.0.0 Needed by NetBox 4.7.0 --- .../python-modules/django-pgware/default.nix | 70 +++++++++++++++++++ pkgs/top-level/python-packages.nix | 2 + 2 files changed, 72 insertions(+) create mode 100644 pkgs/development/python-modules/django-pgware/default.nix diff --git a/pkgs/development/python-modules/django-pgware/default.nix b/pkgs/development/python-modules/django-pgware/default.nix new file mode 100644 index 000000000000..f03fbcb1c98c --- /dev/null +++ b/pkgs/development/python-modules/django-pgware/default.nix @@ -0,0 +1,70 @@ +{ + lib, + buildPythonPackage, + fetchFromGitHub, + hatchling, + django, + postgresql, + postgresqlTestHook, + pytestCheckHook, + pytest-django, + pytest-asyncio, + psycopg2, + psycopg, + nix-update-script, +}: + +buildPythonPackage (finalAttrs: { + pname = "django-pgware"; + version = "1.0.0"; + pyproject = true; + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "Xof"; + repo = "django-pgware"; + tag = "v${finalAttrs.version}"; + hash = "sha256-OvdgqM0W6KPkszNrpeRjmg/powepPyKhfP1OsWaDMSE="; + }; + + build-system = [ hatchling ]; + dependencies = [ django ]; + nativeCheckInputs = [ + postgresql + postgresqlTestHook + pytestCheckHook + pytest-django + pytest-asyncio + psycopg2 + ]; + + optional-dependencies = { + psycopg2 = [ + psycopg2 + ]; + psycopg3 = [ + psycopg + ]; + }; + + pythonImportsCheck = [ "django_pg_utils" ]; + + env.PGDATABASE = "django_pg_utils"; + + preCheck = '' + # Else we get: + # django.core.exceptions.ImproperlyConfigured: Requested setting , but settings are not configured + export DJANGO_SETTINGS_MODULE="tests.django_settings" + export POSTGRES_HOST="$PGHOST" + ''; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "Useful PostgreSQL-specific Django utiites"; + homepage = "https://github.com/Xof/django-pgware"; + changelog = "https://github.com/Xof/django-pgware/blob/${finalAttrs.src.rev}/CHANGELOG.md"; + license = [ lib.licenses.postgresql ]; + maintainers = with lib.maintainers; [ minijackson ]; + }; +}) diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index d61c14f995ef..bb149a0fd53d 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -4799,6 +4799,8 @@ self: super: with self; { django-pgtrigger = callPackage ../development/python-modules/django-pgtrigger { }; + django-pgware = callPackage ../development/python-modules/django-pgware { }; + django-phonenumber-field = callPackage ../development/python-modules/django-phonenumber-field { }; django-picklefield = callPackage ../development/python-modules/django-picklefield { }; From c962694a080dd59d2ff92fc002dbebeb2598ece0 Mon Sep 17 00:00:00 2001 From: Minijackson Date: Fri, 11 Sep 2026 09:00:20 +0200 Subject: [PATCH 047/117] netbox: 4.6.8 -> 4.7.0 --- .../manual/release-notes/rl-2611.section.md | 8 +++-- nixos/modules/services/web-apps/netbox.nix | 33 +++++++------------ pkgs/by-name/ne/netbox/package.nix | 13 ++------ pkgs/top-level/aliases.nix | 1 + pkgs/top-level/all-packages.nix | 2 +- 5 files changed, 21 insertions(+), 36 deletions(-) diff --git a/nixos/doc/manual/release-notes/rl-2611.section.md b/nixos/doc/manual/release-notes/rl-2611.section.md index 7bfb43ae3aa1..87c4514e0f7b 100644 --- a/nixos/doc/manual/release-notes/rl-2611.section.md +++ b/nixos/doc/manual/release-notes/rl-2611.section.md @@ -300,9 +300,11 @@ - `chatgpt` has been retargeted to OpenAI's new ChatGPT desktop app, while the previous app has been renamed to `chatgpt-classic`. -- NetBox was updated to `>= 4.6.8`. Have a look at the breaking changes - of the [4.6 release](https://github.com/netbox-community/netbox/releases/tag/v4.6.0), - make the required changes to your database, if needed, then upgrade by setting `services.netbox.package = pkgs.netbox_4_6;` in your configuration. +- NetBox was updated to `>= 4.7.0`. Have a look at the breaking changes + of the [4.6 release](https://github.com/netbox-community/netbox/releases/tag/v4.6.0) + and the [4.7 release](https://github.com/netbox-community/netbox/releases/tag/v4.7.0), + make the required changes to your configuration and database, if needed, + before you upgrade to NixOS 26.11. - The COSMIC desktop module now enables by default `system76-power` and `system76-scheduler` following upstream recommended packages. The previous power managment service can be enabled back by setting `services.power-profiles-daemon.enable = true`. diff --git a/nixos/modules/services/web-apps/netbox.nix b/nixos/modules/services/web-apps/netbox.nix index 3bf417d9129c..22ff64c36f5a 100644 --- a/nixos/modules/services/web-apps/netbox.nix +++ b/nixos/modules/services/web-apps/netbox.nix @@ -434,10 +434,10 @@ in package = lib.mkOption { type = types.package; default = - if lib.versionAtLeast config.system.stateVersion "26.11" then pkgs.netbox_4_6 else pkgs.netbox_4_5; + if lib.versionAtLeast config.system.stateVersion "26.11" then pkgs.netbox_4_7 else pkgs.netbox_4_5; defaultText = lib.literalExpression '' if lib.versionAtLeast config.system.stateVersion "26.11" then - pkgs.netbox_4_6 + pkgs.netbox_4_7 else pkgs.netbox_4_5; ''; @@ -563,6 +563,15 @@ in config = lib.mkIf cfg.enable ( lib.mkMerge [ { + assertions = [ + { + assertion = + cfg.postgresql.createLocally + -> lib.versionAtLeast config.services.postgresql.finalPackage.version "15"; + message = "NetBox requires PostgreSQL >= 15. Please read the NixOS manual to upgrade your PostgreSQL version."; + } + ]; + services.netbox.plugins = lib.mkIf enableLDAP (ps: [ ps.django-auth-ldap ]); services.redis.servers.netbox.enable = cfg.redis.createLocally; @@ -733,26 +742,6 @@ in PrivateTmp = true; }; }; - - netbox-housekeeping = defaultUnitConfig // { - description = "NetBox housekeeping job"; - - wantedBy = [ "multi-user.target" ]; - - after = [ - "network-online.target" - "netbox.service" - ]; - wants = [ "network-online.target" ]; - - serviceConfig = defaultServiceConfig // { - Type = "oneshot"; - ExecStart = toString [ - (lib.getExe finalPackage) - "housekeeping" - ]; - }; - }; }; systemd.timers.netbox-housekeeping = { diff --git a/pkgs/by-name/ne/netbox/package.nix b/pkgs/by-name/ne/netbox/package.nix index 249f5c8a072d..24539cd138a0 100644 --- a/pkgs/by-name/ne/netbox/package.nix +++ b/pkgs/by-name/ne/netbox/package.nix @@ -2,7 +2,6 @@ lib, fetchFromGitHub, python3, - fetchpatch2, plugins ? _ps: [ ], nixosTests, nix-update-script, @@ -21,24 +20,18 @@ py.pkgs.buildPythonApplication (finalAttrs: { __structuredAttrs = true; pname = "netbox"; - version = "4.6.8"; + version = "4.7.0"; pyproject = false; src = fetchFromGitHub { owner = "netbox-community"; repo = "netbox"; tag = "v${finalAttrs.version}"; - hash = "sha256-fhEcQBYL5R9Tv9CpAf3Ce1oIzsXCjtH5j+dP9sD6kdg="; + hash = "sha256-u6gS/k2WJuziuENIF4DbepvOKFNN6kxAIyX22J9xP7Q="; }; patches = [ ./custom-static-root.patch - # TODO: remove before upgrading to NetBox v4.7 - (fetchpatch2 { - name = "upgrade-django-tables2-v3.0.patch"; - url = "https://github.com/netbox-community/netbox/commit/d57346d9f0eef8126eafcd5033ea43864faeaf0d.patch"; - hash = "sha256-6/wdd8wDVT4eqDKMNx8tmoPTDvw8OE7atf9nzg3LZzk="; - }) ]; dependencies = @@ -53,7 +46,7 @@ py.pkgs.buildPythonApplication (finalAttrs: { django-graphiql-debug-toolbar django-htmx django-mptt - django-pglocks + django-pgware django-prometheus django-redis django-rq diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index 1150da98a4da..c28926a26fc7 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -1804,6 +1804,7 @@ mapAliases { netbox_4_3 = throw "netbox 4.3 series has been removed as it was EOL"; # Added 2026-08-24 netbox_4_4 = throw "netbox 4.4 series has been removed as it was EOL"; # Added 2026-08-24 netbox_4_5 = throw "netbox 4.5 series has been removed as it was EOL"; # Added 2026-08-24 + netbox_4_6 = throw "netbox 4.6 series has been removed as it was EOL"; # Added 2026-08-24 netbsdCross = throw "'netbsdCross' has been renamed to/replaced by 'netbsd'"; # Converted to throw 2025-10-27 netsurf.browser = throw "'netsurf.browser' has been renamed to/replaced by 'netsurf-browser'"; # Converted to throw 2025-10-27 netsurf.buildsystem = throw "'netsurf.buildsystem' has been renamed to/replaced by 'netsurf-buildsystem'"; # Converted to throw 2025-10-27 diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 4cce505519d7..d6c2b51c2481 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -2495,7 +2495,7 @@ with pkgs; ioskeley-mono = recurseIntoAttrs (callPackage ../data/fonts/ioskeley-mono { }); - netbox_4_6 = netbox; + netbox_4_7 = netbox; netboxPlugins = recurseIntoAttrs netbox.plugins; From fda892a9880eeca65c36566ad6037b8da7051d1b Mon Sep 17 00:00:00 2001 From: Minijackson Date: Tue, 15 Sep 2026 09:00:09 +0200 Subject: [PATCH 048/117] nixos/tests/netbox: enable ssh backdoor for interactive tests --- nixos/tests/web-apps/netbox/default.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/nixos/tests/web-apps/netbox/default.nix b/nixos/tests/web-apps/netbox/default.nix index f69eb85cf72e..c76be640a66e 100644 --- a/nixos/tests/web-apps/netbox/default.nix +++ b/nixos/tests/web-apps/netbox/default.nix @@ -126,6 +126,8 @@ in networking.firewall.allowedTCPPorts = [ 80 ]; }; + interactive.sshBackdoor.enable = true; + testScript = let changePassword = pkgs.writeText "change-password.py" '' From 9a084098065be1553f60c5de31365a86e553dd89 Mon Sep 17 00:00:00 2001 From: Minijackson Date: Sat, 26 Sep 2026 19:25:02 +0200 Subject: [PATCH 049/117] netbox: 4.7.0 -> 4.7.1 Remove django-graphiql-debug-toolbar from dependencies, as it was removed from base_requirements.txt upstream. --- pkgs/by-name/ne/netbox/package.nix | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ne/netbox/package.nix b/pkgs/by-name/ne/netbox/package.nix index 24539cd138a0..8239843cd53c 100644 --- a/pkgs/by-name/ne/netbox/package.nix +++ b/pkgs/by-name/ne/netbox/package.nix @@ -20,14 +20,14 @@ py.pkgs.buildPythonApplication (finalAttrs: { __structuredAttrs = true; pname = "netbox"; - version = "4.7.0"; + version = "4.7.1"; pyproject = false; src = fetchFromGitHub { owner = "netbox-community"; repo = "netbox"; tag = "v${finalAttrs.version}"; - hash = "sha256-u6gS/k2WJuziuENIF4DbepvOKFNN6kxAIyX22J9xP7Q="; + hash = "sha256-6IJrDD+1yBv15cbJwZOLkwiAlGZH2zRC+a/CG79C10Y="; }; patches = [ @@ -43,7 +43,6 @@ py.pkgs.buildPythonApplication (finalAttrs: { django-cors-headers django-debug-toolbar django-filter - django-graphiql-debug-toolbar django-htmx django-mptt django-pgware From 9871fe9f1a1dc9fd3cca15c488c29a705041df99 Mon Sep 17 00:00:00 2001 From: Diogo Correia Date: Sun, 27 Sep 2026 09:45:29 +0100 Subject: [PATCH 050/117] bazarr: 1.6.1 -> 1.6.2 https://github.com/morpheus65535/bazarr/releases/tag/v1.6.2 --- pkgs/by-name/ba/bazarr/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ba/bazarr/package.nix b/pkgs/by-name/ba/bazarr/package.nix index 2ef6fec81732..fa97f688597d 100644 --- a/pkgs/by-name/ba/bazarr/package.nix +++ b/pkgs/by-name/ba/bazarr/package.nix @@ -12,13 +12,13 @@ }: python313Packages.buildPythonApplication (finalAttrs: { pname = "bazarr"; - version = "1.6.1"; + version = "1.6.2"; src = fetchFromGitHub { owner = "morpheus65535"; repo = "bazarr"; tag = "v${finalAttrs.version}"; - hash = "sha256-m9429gSt9xrA3N9w6eIBtHmQWOZDiRKIsu52fusQutU="; + hash = "sha256-5bhNbLfuL1wzraO3UypRRstC1+ULTaFVNJC++Qov6AE="; }; dependencies = with python313Packages; [ @@ -76,7 +76,7 @@ python313Packages.buildPythonApplication (finalAttrs: { nodejs = nodejs_24; - npmDepsHash = "sha256-82hLGQBuymU7DhDn+aYQIay1cVR+d4E3nU+ZNhJ8xJ0="; + npmDepsHash = "sha256-uvUXk5+/WOfFRuBnC/SQOkau+0uIkJ4OTofMXckmwzw="; nativeBuildInputs = [ dart-sass ]; From 927786e0b2d7d6c0e0ef94f4fee1b39a972c4357 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 27 Sep 2026 09:04:26 +0000 Subject: [PATCH 051/117] vscode-extensions.ms-azuretools.vscode-containers: 2.5.1 -> 2.5.2 --- .../extensions/ms-azuretools.vscode-containers/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/editors/vscode/extensions/ms-azuretools.vscode-containers/default.nix b/pkgs/applications/editors/vscode/extensions/ms-azuretools.vscode-containers/default.nix index 163d16f23ebe..0ad6d5dbc0b9 100644 --- a/pkgs/applications/editors/vscode/extensions/ms-azuretools.vscode-containers/default.nix +++ b/pkgs/applications/editors/vscode/extensions/ms-azuretools.vscode-containers/default.nix @@ -7,8 +7,8 @@ vscode-utils.buildVscodeMarketplaceExtension { mktplcRef = { publisher = "ms-azuretools"; name = "vscode-containers"; - version = "2.5.1"; - hash = "sha256-FHS93HCKHFzleRIJP+pxpdTZZjqBkZOjHlmJ5M0ojbs="; + version = "2.5.2"; + hash = "sha256-ERpwIOxLZxelWPRFYwsaEcbnOxW3cC3vGOKIkg92ztw="; }; meta = { From 5acd5f7d47f455f20179bfd3e9e88dc1d63cd33d Mon Sep 17 00:00:00 2001 From: Akira Komamura Date: Tue, 22 Sep 2026 21:31:45 +0900 Subject: [PATCH 052/117] ocamlPackages.capnp-rpc: init at 2.1.2-unstable-2026-09-13 --- .../ocaml-modules/capnp-rpc/default.nix | 56 +++++++++++++++++++ pkgs/top-level/ocaml-packages.nix | 2 + 2 files changed, 58 insertions(+) create mode 100644 pkgs/development/ocaml-modules/capnp-rpc/default.nix diff --git a/pkgs/development/ocaml-modules/capnp-rpc/default.nix b/pkgs/development/ocaml-modules/capnp-rpc/default.nix new file mode 100644 index 000000000000..88a8653ce46a --- /dev/null +++ b/pkgs/development/ocaml-modules/capnp-rpc/default.nix @@ -0,0 +1,56 @@ +{ + lib, + buildDunePackage, + fetchFromGitHub, + alcotest, + astring, + capnp, + capnproto, + eio, + fmt, + logs, + stdint, + uri, +}: + +buildDunePackage (finalAttrs: { + pname = "capnp-rpc"; + version = "2.1.2-unstable-2026-09-13"; + + minimalOCamlVersion = "5.2"; + + src = fetchFromGitHub { + owner = "mirage"; + repo = "capnp-rpc"; + rev = "256ad12f21931f04eb88ad4d5cc966b7829bd906"; + hash = "sha256-zibjsyp4Vin0sZrwWio+h/88bdsVfmFEA7aPmc1IRg0="; + }; + + nativeBuildInputs = [ + capnp + capnproto + ]; + + propagatedBuildInputs = [ + astring + capnp + fmt + logs + eio + stdint + uri + ]; + + checkInputs = [ + alcotest + ]; + + doCheck = true; + + meta = { + description = "Cap'n Proto RPC library for OCaml"; + homepage = "https://github.com/mirage/capnp-rpc"; + changelog = "https://github.com/mirage/capnp-rpc/blob/v${finalAttrs.version}/CHANGES.md"; + license = lib.licenses.asl20; + }; +}) diff --git a/pkgs/top-level/ocaml-packages.nix b/pkgs/top-level/ocaml-packages.nix index ab60a963ef31..20e3a8008bc6 100644 --- a/pkgs/top-level/ocaml-packages.nix +++ b/pkgs/top-level/ocaml-packages.nix @@ -217,6 +217,8 @@ let capnp = callPackage ../development/ocaml-modules/capnp { }; + capnp-rpc = callPackage ../development/ocaml-modules/capnp-rpc { }; + caqti = callPackage ../development/ocaml-modules/caqti { }; caqti-async = callPackage ../development/ocaml-modules/caqti/async.nix { }; From 186b37584666be715d210e7033336c95009fb643 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 27 Sep 2026 10:45:37 +0000 Subject: [PATCH 053/117] rusthound-ce: 2.5.13 -> 2.5.14 --- pkgs/by-name/ru/rusthound-ce/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ru/rusthound-ce/package.nix b/pkgs/by-name/ru/rusthound-ce/package.nix index 8e747c46d392..4f2c1da5e937 100644 --- a/pkgs/by-name/ru/rusthound-ce/package.nix +++ b/pkgs/by-name/ru/rusthound-ce/package.nix @@ -10,14 +10,14 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "rusthound-ce"; - version = "2.5.13"; + version = "2.5.14"; src = fetchCrate { inherit (finalAttrs) pname version; - hash = "sha256-YDW7tL37rKOm+PU98NhtimirVLla40dLx2VGOLfDVho="; + hash = "sha256-VJFwR/iGAdNazZBEkyPfYgW9gDfPJR0xa3LhtiJ4cLg="; }; - cargoHash = "sha256-5z7VBRua+plcMOf1kY8MxYKPbmKlo4yVEz8WzX6oVWA="; + cargoHash = "sha256-q1NwitdAHgP6LmQ6SgKD8CnNNoyaoUha2v1edUp6Jbc="; nativeBuildInputs = [ pkg-config From dd6cdf39477ed517698af51ca6316cfb67c972e8 Mon Sep 17 00:00:00 2001 From: Akira Komamura Date: Tue, 22 Sep 2026 21:43:12 +0900 Subject: [PATCH 054/117] ocamlPackages.capnp-rpc-net: init at 2.1.2-unstable-2026-09-13 Co-authored-by: StepBroBD --- .../ocaml-modules/capnp-rpc/net.nix | 53 +++++++++++++++++++ pkgs/top-level/ocaml-packages.nix | 2 + 2 files changed, 55 insertions(+) create mode 100644 pkgs/development/ocaml-modules/capnp-rpc/net.nix diff --git a/pkgs/development/ocaml-modules/capnp-rpc/net.nix b/pkgs/development/ocaml-modules/capnp-rpc/net.nix new file mode 100644 index 000000000000..5e799c439ac5 --- /dev/null +++ b/pkgs/development/ocaml-modules/capnp-rpc/net.nix @@ -0,0 +1,53 @@ +{ + buildDunePackage, + asn1-combinators, + astring, + base64, + capnp, + capnp-rpc, + capnproto, + cstruct, + fmt, + logs, + mirage-crypto, + mirage-crypto-rng, + prometheus, + ptime, + tls-eio, + uri, + x509, +}: + +buildDunePackage { + pname = "capnp-rpc-net"; + + minimalOCamlVersion = "5.2"; + + inherit (capnp-rpc) src version; + + nativeBuildInputs = [ + capnproto + ]; + + propagatedBuildInputs = [ + asn1-combinators + astring + base64 + capnp + capnp-rpc + cstruct + fmt + logs + mirage-crypto + mirage-crypto-rng + prometheus + ptime + tls-eio + uri + x509 + ]; + + meta = capnp-rpc.meta // { + description = "Network and TLS support for Cap'n Proto RPC services"; + }; +} diff --git a/pkgs/top-level/ocaml-packages.nix b/pkgs/top-level/ocaml-packages.nix index 20e3a8008bc6..c5c7d106d0e9 100644 --- a/pkgs/top-level/ocaml-packages.nix +++ b/pkgs/top-level/ocaml-packages.nix @@ -219,6 +219,8 @@ let capnp-rpc = callPackage ../development/ocaml-modules/capnp-rpc { }; + capnp-rpc-net = callPackage ../development/ocaml-modules/capnp-rpc/net.nix { }; + caqti = callPackage ../development/ocaml-modules/caqti { }; caqti-async = callPackage ../development/ocaml-modules/caqti/async.nix { }; From 31ec9cb6697c8b12611b05f996fbe68ab2c0c689 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 27 Sep 2026 14:26:15 +0000 Subject: [PATCH 055/117] aptakube: 1.20.4 -> 1.20.5 --- pkgs/by-name/ap/aptakube/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ap/aptakube/package.nix b/pkgs/by-name/ap/aptakube/package.nix index b8d06ab1b713..baa8bc2ce74c 100644 --- a/pkgs/by-name/ap/aptakube/package.nix +++ b/pkgs/by-name/ap/aptakube/package.nix @@ -23,11 +23,11 @@ stdenvNoCC.mkDerivation ( sources = { aarch64-darwin = { name = "Aptakube_${finalAttrs.version}_universal.dmg"; - hash = "sha256-wDfb2B5KMIkQcwO9JkX2b5FpgzJaUSKZTFQCqRkfLls="; + hash = "sha256-qIaTUvZ1RLCucB1FG92rh8rApltstxaq8XEXblnFKrI="; }; x86_64-linux = { name = "aptakube_${finalAttrs.version}_amd64.deb"; - hash = "sha256-HDbRWTNFX2V0kgeFIZPLNLRTRxx/eETQiyLD1Yf6YYg="; + hash = "sha256-YDPEy3wiPohl0Ql5ITNA2UxdpuG4tjGnA0WN6Qt9pd8="; }; }; @@ -42,7 +42,7 @@ stdenvNoCC.mkDerivation ( in { pname = "aptakube"; - version = "1.20.4"; + version = "1.20.5"; __structuredAttrs = true; strictDeps = true; From 5a4557d5cb3263f827b45533ec6d7a5b59eaf101 Mon Sep 17 00:00:00 2001 From: J0schu Date: Sun, 27 Sep 2026 19:26:39 +0200 Subject: [PATCH 056/117] vivaldi: 8.2.4133.52 -> 8.2.4133.76 --- pkgs/by-name/vi/vivaldi/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/vi/vivaldi/package.nix b/pkgs/by-name/vi/vivaldi/package.nix index ef0186dce750..a7a6ed82b172 100644 --- a/pkgs/by-name/vi/vivaldi/package.nix +++ b/pkgs/by-name/vi/vivaldi/package.nix @@ -66,7 +66,7 @@ stdenv.mkDerivation rec { pname = "vivaldi"; - version = "8.2.4133.52"; + version = "8.2.4133.76"; suffix = { @@ -79,8 +79,8 @@ stdenv.mkDerivation rec { url = "https://downloads.vivaldi.com/stable/vivaldi-stable_${version}-1_${suffix}.deb"; hash = { - aarch64-linux = "sha256-5v9DCL6B8JnZrFoniAFg5fpLD1ojOnT7HIt4HuQZJzI="; - x86_64-linux = "sha256-QOXpNQULSr7dR98o2AODBHMbvw/3NhqXlh1iB6i8rQM="; + aarch64-linux = "sha256-co8BxKbDVyjYWOEIg4MOHiNB1GnHQjm8Z9nWabyaivA="; + x86_64-linux = "sha256-WPfZYy+cCxSKFdLbD5MpTb4lovGk0nDVRcjpXxbOwGI="; } .${stdenv.hostPlatform.system} or (throw "Unsupported system: ${stdenv.hostPlatform.system}"); }; From 7316a726db147dcb643fbb464d4522d03a268fd0 Mon Sep 17 00:00:00 2001 From: J0schu Date: Sun, 27 Sep 2026 19:42:46 +0200 Subject: [PATCH 057/117] maintainers: add J0schu --- maintainers/maintainer-list.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index 2ae586a6b875..09ceb6a9dcb8 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -12651,6 +12651,12 @@ github = "j0hax"; githubId = 3802620; }; + j0schu = { + name = "Jonas"; + email = "Joschu2015@t-online.de"; + github = "J0schu"; + githubId = 56407950; + }; j0xaf = { email = "j0xaf@j0xaf.de"; name = "Jörn Gersdorf"; From 386fb1a5c85324b17bcfc483865e3c70a40d7964 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Linnea=20Gr=C3=A4f?= Date: Sun, 27 Sep 2026 18:13:45 +0200 Subject: [PATCH 058/117] httpstat: fix version detection in setup.py --- pkgs/by-name/ht/httpstat/package.nix | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/ht/httpstat/package.nix b/pkgs/by-name/ht/httpstat/package.nix index fc9382a891fe..e8790b593fea 100644 --- a/pkgs/by-name/ht/httpstat/package.nix +++ b/pkgs/by-name/ht/httpstat/package.nix @@ -17,9 +17,15 @@ python3Packages.buildPythonApplication (finalAttrs: { sha256 = "sha256-dOHFLw8suvpuZkcKEzq5HktMYBGE7+vtTD609TkAFfw="; }; + # python3.8+ changed AST parsing, so until upstream builds against newer versions this has to do + postPatch = '' + substituteInPlace setup.py --replace-fail \ + "version=get_version()" \ + "version='${finalAttrs.version}'" + ''; + build-system = with python3Packages; [ setuptools ]; - doCheck = false; # No tests buildInputs = [ glibcLocales ]; runtimeDeps = [ curl ]; From 42477dabb6447e4c4e6e13c81ed582723410b1aa Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 27 Sep 2026 19:23:50 +0000 Subject: [PATCH 059/117] nerdlog: 1.11.0 -> 1.12.0 --- pkgs/by-name/ne/nerdlog/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ne/nerdlog/package.nix b/pkgs/by-name/ne/nerdlog/package.nix index 0fd85e3f9f47..63ad16e50fa8 100644 --- a/pkgs/by-name/ne/nerdlog/package.nix +++ b/pkgs/by-name/ne/nerdlog/package.nix @@ -8,7 +8,7 @@ }: buildGoModule (finalAttrs: { pname = "nerdlog"; - version = "1.11.0"; + version = "1.12.0"; __structuredAttrs = true; @@ -16,10 +16,10 @@ buildGoModule (finalAttrs: { owner = "dimonomid"; repo = "nerdlog"; tag = "v${finalAttrs.version}"; - hash = "sha256-jKOpFPLqRy4aU3RTEloX+RjFTW0E65XbbL/uSMRHyJA="; + hash = "sha256-Q478aeetAu+lWJYCn3IE4anpghNXRazlFIKPXf+hEhA="; }; - vendorHash = "sha256-D/1iKXTJuV9RM4IbC/FmpxJDIaBDBts1GEO8YyCGq7A="; + vendorHash = "sha256-joQY9gJiyw0fit6bp0gHZ31VxQ4+qHlqeOr/fXfnDPg="; buildInputs = [ libx11 ]; From 12a6d767c1b2a3d40feb47401a7439f268697878 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sun, 27 Sep 2026 22:12:54 +0200 Subject: [PATCH 060/117] python3Packages.editdistpy: add pkg-resources-backport --- pkgs/development/python-modules/editdistpy/default.nix | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/editdistpy/default.nix b/pkgs/development/python-modules/editdistpy/default.nix index 1ff194c42743..cf97a6dd2272 100644 --- a/pkgs/development/python-modules/editdistpy/default.nix +++ b/pkgs/development/python-modules/editdistpy/default.nix @@ -5,8 +5,9 @@ pytestCheckHook, - setuptools, cython, + pkg-resources-backport, + setuptools, symspellpy, numpy, @@ -26,8 +27,9 @@ buildPythonPackage rec { }; build-system = [ - setuptools cython + pkg-resources-backport + setuptools ]; # error: infinite recursion encountered From 3c2e59eb5f998a2a926877d3d7cf4323d27175df Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sun, 27 Sep 2026 22:14:56 +0200 Subject: [PATCH 061/117] python3Packages.editdistpy: modernize - migrate to finalAttrs - Update ordering --- .../python-modules/editdistpy/default.nix | 29 +++++++++---------- 1 file changed, 13 insertions(+), 16 deletions(-) diff --git a/pkgs/development/python-modules/editdistpy/default.nix b/pkgs/development/python-modules/editdistpy/default.nix index cf97a6dd2272..49fc36e69254 100644 --- a/pkgs/development/python-modules/editdistpy/default.nix +++ b/pkgs/development/python-modules/editdistpy/default.nix @@ -1,20 +1,17 @@ { lib, buildPythonPackage, - fetchFromGitHub, - - pytestCheckHook, - cython, - pkg-resources-backport, - setuptools, - - symspellpy, - numpy, editdistpy, + fetchFromGitHub, + numpy, + pkg-resources-backport, + pytestCheckHook, + setuptools, + symspellpy, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "editdistpy"; version = "0.1.6"; pyproject = true; @@ -22,7 +19,7 @@ buildPythonPackage rec { src = fetchFromGitHub { owner = "mammothb"; repo = "editdistpy"; - tag = "v${version}"; + tag = "v${finalAttrs.version}"; hash = "sha256-bUdwhMFDIhHuIlcqIZt6mSh8xwW/2igw0QiWGvQBLC8="; }; @@ -32,9 +29,6 @@ buildPythonPackage rec { setuptools ]; - # error: infinite recursion encountered - doCheck = false; - nativeCheckInputs = [ pytestCheckHook symspellpy @@ -45,6 +39,9 @@ buildPythonPackage rec { rm -r editdistpy ''; + # error: infinite recursion encountered + doCheck = false; + passthru.tests = { check = editdistpy.overridePythonAttrs (_: { doCheck = true; @@ -56,8 +53,8 @@ buildPythonPackage rec { meta = { description = "Fast Levenshtein and Damerau optimal string alignment algorithms"; homepage = "https://github.com/mammothb/editdistpy"; - changelog = "https://github.com/mammothb/editdistpy/releases/tag/${src.tag}"; + changelog = "https://github.com/mammothb/editdistpy/releases/tag/${finalAttrs.src.tag}"; license = lib.licenses.mit; maintainers = with lib.maintainers; [ vizid ]; }; -} +}) From b6dde7a2e72c8d107f80c57da55a6c8d20cd854e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 27 Sep 2026 20:17:58 +0000 Subject: [PATCH 062/117] pgschema: 1.13.0 -> 1.13.1 --- pkgs/by-name/pg/pgschema/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/pg/pgschema/package.nix b/pkgs/by-name/pg/pgschema/package.nix index 46de161a458d..872ce1656046 100644 --- a/pkgs/by-name/pg/pgschema/package.nix +++ b/pkgs/by-name/pg/pgschema/package.nix @@ -10,14 +10,14 @@ buildGoModule (finalAttrs: { pname = "pgschema"; - version = "1.13.0"; + version = "1.13.1"; __structuredAttrs = true; src = fetchFromGitHub { owner = "pgplex"; repo = "pgschema"; tag = "v${finalAttrs.version}"; - hash = "sha256-w1MLl9NFAS+7a1CzS5IMQUw6BzL8sifNPdnStLySFVg="; + hash = "sha256-hSS+S16LidfSEaSJPkJiaDTdtjaJS1h3wORqpZYyT44="; }; # Adapted from $src/nix/pgschema.nix From 38a640953eafa80cd188cd9e23c3596f189b6ad3 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sun, 27 Sep 2026 22:25:41 +0200 Subject: [PATCH 063/117] python3Packages.jenkinsapi: 0.3.17 -> 0.3.23 Changelog: https://github.com/pycontribs/jenkinsapi/releases/tag/0.3.23 --- .../python-modules/jenkinsapi/default.nix | 24 +++++++++---------- 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/pkgs/development/python-modules/jenkinsapi/default.nix b/pkgs/development/python-modules/jenkinsapi/default.nix index 2fd4d7167762..a76f2192498a 100644 --- a/pkgs/development/python-modules/jenkinsapi/default.nix +++ b/pkgs/development/python-modules/jenkinsapi/default.nix @@ -2,55 +2,55 @@ lib, buildPythonPackage, fetchFromGitHub, + docker, hatchling, mock, + pyprojectVersionPatchHook, pytest-mock, + pytest-xdist, pytestCheckHook, pytz, requests, - six, }: buildPythonPackage rec { pname = "jenkinsapi"; - version = "0.3.17"; + version = "0.3.23"; pyproject = true; src = fetchFromGitHub { owner = "pycontribs"; repo = "jenkinsapi"; tag = version; - hash = "sha256-1dTcT84cDpP9V4tVrgW2MTYx4jQj0/tZiAuakC+orUQ="; + hash = "sha256-NtILbbXu4dtYda28WaFiGkICf0bOmVMKOOnnrHptxsg="; }; - build-system = [ - hatchling - ]; + build-system = [ hatchling ]; + + nativeBuildInputs = [ pyprojectVersionPatchHook ]; dependencies = [ pytz requests - six ]; nativeCheckInputs = [ + docker mock pytest-mock + pytest-xdist pytestCheckHook ]; # don't run tests that try to spin up jenkins disabledTests = [ "systests" ]; - pythonImportsCheck = [ - "jenkinsapi" - "jenkinsapi.utils" - "jenkinsapi.utils.jenkins_launcher" - ]; + pythonImportsCheck = [ "jenkinsapi" ]; meta = { description = "Python API for accessing resources on a Jenkins continuous-integration server"; homepage = "https://github.com/salimfadhley/jenkinsapi"; + changelog = "https://github.com/pycontribs/jenkinsapi/releases/tag/${src.tag}"; maintainers = with lib.maintainers; [ de11n despsyched From e4f633c5e20bc935d6ff90ada33b02dc5a432dc2 Mon Sep 17 00:00:00 2001 From: quantenzitrone Date: Sun, 27 Sep 2026 22:26:50 +0200 Subject: [PATCH 064/117] dosfstools: use tag and hash instead of rev and sha256 in src --- pkgs/by-name/do/dosfstools/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/do/dosfstools/package.nix b/pkgs/by-name/do/dosfstools/package.nix index a647a51f4a81..225f072598b9 100644 --- a/pkgs/by-name/do/dosfstools/package.nix +++ b/pkgs/by-name/do/dosfstools/package.nix @@ -17,8 +17,8 @@ stdenv.mkDerivation (finalAttrs: { src = fetchFromGitHub { owner = "dosfstools"; repo = "dosfstools"; - rev = "v${finalAttrs.version}"; - sha256 = "sha256-2gxB0lQixiHOHw8uTetHekaM57fvUd9zOzSxWnvUz/c="; + tag = "v${finalAttrs.version}"; + hash = "sha256-2gxB0lQixiHOHw8uTetHekaM57fvUd9zOzSxWnvUz/c="; }; patches = [ From 16754faf479ebd063f79dc31af5e26c54ff7a153 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sun, 27 Sep 2026 22:27:27 +0200 Subject: [PATCH 065/117] python3Packages.jenkinsapi: migrate to finalAttrs --- pkgs/development/python-modules/jenkinsapi/default.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/development/python-modules/jenkinsapi/default.nix b/pkgs/development/python-modules/jenkinsapi/default.nix index a76f2192498a..296ea97310e8 100644 --- a/pkgs/development/python-modules/jenkinsapi/default.nix +++ b/pkgs/development/python-modules/jenkinsapi/default.nix @@ -13,7 +13,7 @@ requests, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "jenkinsapi"; version = "0.3.23"; pyproject = true; @@ -21,7 +21,7 @@ buildPythonPackage rec { src = fetchFromGitHub { owner = "pycontribs"; repo = "jenkinsapi"; - tag = version; + tag = finalAttrs.version; hash = "sha256-NtILbbXu4dtYda28WaFiGkICf0bOmVMKOOnnrHptxsg="; }; @@ -49,8 +49,8 @@ buildPythonPackage rec { meta = { description = "Python API for accessing resources on a Jenkins continuous-integration server"; - homepage = "https://github.com/salimfadhley/jenkinsapi"; - changelog = "https://github.com/pycontribs/jenkinsapi/releases/tag/${src.tag}"; + homepage = "https://github.com/pycontribs/jenkinsapi"; + changelog = "https://github.com/pycontribs/jenkinsapi/releases/tag/${finalAttrs.version}"; maintainers = with lib.maintainers; [ de11n despsyched @@ -58,4 +58,4 @@ buildPythonPackage rec { ]; license = lib.licenses.mit; }; -} +}) From b9a3267a1d48140c69a47d4bb09ca75d8ef6fab9 Mon Sep 17 00:00:00 2001 From: quantenzitrone Date: Sun, 27 Sep 2026 22:27:46 +0200 Subject: [PATCH 066/117] dosfstools: fix license upstream uses the GPL-3.0-or-later header in the files --- pkgs/by-name/do/dosfstools/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/do/dosfstools/package.nix b/pkgs/by-name/do/dosfstools/package.nix index 225f072598b9..1397ce3d5585 100644 --- a/pkgs/by-name/do/dosfstools/package.nix +++ b/pkgs/by-name/do/dosfstools/package.nix @@ -64,6 +64,6 @@ stdenv.mkDerivation (finalAttrs: { description = "Utilities for creating and checking FAT and VFAT file systems"; homepage = "https://github.com/dosfstools/dosfstools"; platforms = lib.platforms.unix; - license = lib.licenses.gpl3; + license = lib.licenses.gpl3Plus; }; }) From 8ba8775282a5924c7a986d14e44f18829ac727ee Mon Sep 17 00:00:00 2001 From: quantenzitrone Date: Sun, 27 Sep 2026 22:28:21 +0200 Subject: [PATCH 067/117] dosfstools: adopt --- pkgs/by-name/do/dosfstools/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/do/dosfstools/package.nix b/pkgs/by-name/do/dosfstools/package.nix index 1397ce3d5585..0abd7a97e2f7 100644 --- a/pkgs/by-name/do/dosfstools/package.nix +++ b/pkgs/by-name/do/dosfstools/package.nix @@ -65,5 +65,6 @@ stdenv.mkDerivation (finalAttrs: { homepage = "https://github.com/dosfstools/dosfstools"; platforms = lib.platforms.unix; license = lib.licenses.gpl3Plus; + maintainers = [ lib.maintainers.quantenzitrone ]; }; }) From 62c4412db2c62e4d6e78bdec04489bfafba6955b Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sun, 27 Sep 2026 22:31:20 +0200 Subject: [PATCH 068/117] python3Packages.isbnlib: add pkg-resources-backport --- pkgs/development/python-modules/isbnlib/default.nix | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/pkgs/development/python-modules/isbnlib/default.nix b/pkgs/development/python-modules/isbnlib/default.nix index a6383e0573b1..7907cfcf76c7 100644 --- a/pkgs/development/python-modules/isbnlib/default.nix +++ b/pkgs/development/python-modules/isbnlib/default.nix @@ -6,6 +6,7 @@ # build-system setuptools, + pkg-resources-backport, # tests pytestCheckHook, @@ -29,9 +30,7 @@ buildPythonPackage (finalAttrs: { build-system = [ setuptools ]; - dependencies = [ - setuptools # needed for 'pkg_resources' - ]; + dependencies = [ pkg-resources-backport ]; nativeCheckInputs = [ pytestCheckHook From 58aa05565f67661071fd379cd192ccaaf0a210ef Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 27 Sep 2026 20:34:54 +0000 Subject: [PATCH 069/117] sable-unwrapped: 1.22.6 -> 1.22.9 --- pkgs/by-name/sa/sable-unwrapped/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/sa/sable-unwrapped/package.nix b/pkgs/by-name/sa/sable-unwrapped/package.nix index e66e79524833..6c4f634796da 100644 --- a/pkgs/by-name/sa/sable-unwrapped/package.nix +++ b/pkgs/by-name/sa/sable-unwrapped/package.nix @@ -20,13 +20,13 @@ stdenvNoCC.mkDerivation (finalAttrs: { strictDeps = true; pname = "sable-unwrapped"; - version = "1.22.6"; + version = "1.22.9"; src = fetchFromGitHub { owner = "SableClient"; repo = "Sable"; tag = "v${finalAttrs.version}"; - hash = "sha256-AZ2gKcCLJvllC/lOL+l/zt3/RxztWd8mu25Eo0vyMBY="; + hash = "sha256-TZycPD+lor6pCTcJaZLUvb84CyFn5jBROltdz9hSdLg="; }; pnpmDeps = fetchPnpmDeps { From 96b0ae40db51f27810ae1b09132f69bb6fe9455c Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sun, 27 Sep 2026 23:29:26 +0200 Subject: [PATCH 070/117] python3Packages.opentelemetry-instrumentation-urllib3: add mocket --- .../opentelemetry-instrumentation-urllib3/default.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/python-modules/opentelemetry-instrumentation-urllib3/default.nix b/pkgs/development/python-modules/opentelemetry-instrumentation-urllib3/default.nix index ee2b18f00773..9bccc9526e6f 100644 --- a/pkgs/development/python-modules/opentelemetry-instrumentation-urllib3/default.nix +++ b/pkgs/development/python-modules/opentelemetry-instrumentation-urllib3/default.nix @@ -16,6 +16,7 @@ # tests httpretty, + mocket, opentelemetry-test-utils, pytestCheckHook, respx, @@ -48,6 +49,7 @@ buildPythonPackage { nativeCheckInputs = [ httpretty + mocket opentelemetry-test-utils pytestCheckHook respx From 5a10fb0292f0d93c6a52564c078f42b4d560cf5a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 27 Sep 2026 21:37:10 +0000 Subject: [PATCH 071/117] python3Packages.cwl-utils: 0.44 -> 0.45 --- pkgs/development/python-modules/cwl-utils/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/cwl-utils/default.nix b/pkgs/development/python-modules/cwl-utils/default.nix index e5005353c9e7..6d434f8c0e2f 100644 --- a/pkgs/development/python-modules/cwl-utils/default.nix +++ b/pkgs/development/python-modules/cwl-utils/default.nix @@ -18,14 +18,14 @@ buildPythonPackage (finalAttrs: { pname = "cwl-utils"; - version = "0.44"; + version = "0.45"; pyproject = true; src = fetchFromGitHub { owner = "common-workflow-language"; repo = "cwl-utils"; tag = "v${finalAttrs.version}"; - hash = "sha256-SKMyzJEmQdnRlrHnvXqsSk2zRW5eQf0QyFdva5hueLg="; + hash = "sha256-TyPRF47G4FrMY59dXzVPfZ25qsAv24T5M2ByQjEGJp8="; }; build-system = [ hatchling ]; From 1a0efb51f92109046d26b611ab1e3004b6d5efb0 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 27 Sep 2026 21:52:33 +0000 Subject: [PATCH 072/117] snx-rs: 6.3.1 -> 6.4.1 --- pkgs/by-name/sn/snx-rs/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/sn/snx-rs/package.nix b/pkgs/by-name/sn/snx-rs/package.nix index b17cedf2f4e8..90a72c9dffd6 100644 --- a/pkgs/by-name/sn/snx-rs/package.nix +++ b/pkgs/by-name/sn/snx-rs/package.nix @@ -15,13 +15,13 @@ }: rustPlatform.buildRustPackage (finalAttrs: { pname = "snx-rs"; - version = "6.3.1"; + version = "6.4.1"; src = fetchFromGitHub { owner = "ancwrd1"; repo = "snx-rs"; tag = "v${finalAttrs.version}"; - hash = "sha256-2cRTD3fVn8Ko5nZ3L+/hsXOT8Gc91hk6+0mvxLKMa08="; + hash = "sha256-J0wjLavv6OCdYzIMsRnQEoK4OJU68QLvTbIL4hTOOCU="; }; passthru.updateScript = nix-update-script { }; @@ -49,7 +49,7 @@ rustPlatform.buildRustPackage (finalAttrs: { versionCheckHook ]; - cargoHash = "sha256-Qvx8bb2Mr8UQYrk++wOoDqqAe/BA0LlbQUS8Y+TCYNo="; + cargoHash = "sha256-nQ2lQbPaK0rZE3XscSBgeceIHqLAFxeU9agBoPlffBI="; doInstallCheck = true; versionCheckProgram = "${placeholder "out"}/bin/snx-rs"; From cf2bc81331aee8ab89ba3249b352d5700933bed8 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 27 Sep 2026 22:15:37 +0000 Subject: [PATCH 073/117] nezha: 2.3.12 -> 2.3.14 --- pkgs/by-name/ne/nezha/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ne/nezha/package.nix b/pkgs/by-name/ne/nezha/package.nix index c4ef024a9cc2..44f2a377739b 100644 --- a/pkgs/by-name/ne/nezha/package.nix +++ b/pkgs/by-name/ne/nezha/package.nix @@ -49,13 +49,13 @@ let in buildGoModule (finalAttrs: { pname = "nezha"; - version = "2.3.12"; + version = "2.3.14"; src = fetchFromGitHub { owner = "nezhahq"; repo = "nezha"; tag = "v${finalAttrs.version}"; - hash = "sha256-XgTbDpfGYbpiFseJjwraDg3svyT0EpgvoY2dvLbtZtQ="; + hash = "sha256-xWJfTop9U3Ms5oeTD4Sdn6ZmESjrx5H9WnAn9KJq608="; }; proxyVendor = true; From 820c4b78196ea808567124c48bfb315f56c6fa78 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 27 Sep 2026 22:44:55 +0000 Subject: [PATCH 074/117] sublime4: 4200 -> 4215 --- pkgs/applications/editors/sublime/4/packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/editors/sublime/4/packages.nix b/pkgs/applications/editors/sublime/4/packages.nix index 162e385f909e..2eec00b1c852 100644 --- a/pkgs/applications/editors/sublime/4/packages.nix +++ b/pkgs/applications/editors/sublime/4/packages.nix @@ -5,9 +5,9 @@ let in { sublime4 = common { - buildVersion = "4200"; - x64sha256 = "NvacVRrRjuRgAr5NnFI/5UXZO2f+pnvupzHnJARLRp8="; - aarch64sha256 = "z0tqp06ioqqwLhRFmc+eSkI8u5VDwiH32hCVqVSVVmo="; + buildVersion = "4215"; + x64sha256 = "wVP0GNOrJrkOzOjAKoLk6WECXtemX34lBgpUV9Q+iNk="; + aarch64sha256 = "0xRmWkJy8zVRUDQyNyo0UW27WpoS3OKkcELBlC9m7nk="; } { }; sublime4-dev = common { From 0f6171af436bb758ee2754d2fe6223a4446021c1 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sun, 27 Sep 2026 23:19:34 +0200 Subject: [PATCH 075/117] discourse: 2026.8.0 -> 2026.9.0 https://releases.discourse.org/changelog/v2026.9.0/ Fixes: - CVE-2026-91159 Stored oEmbed HTML injection via allowed iframe - CVE-2026-91157 Media uploads remain publicly accessible after category permissions are restricted - CVE-2026-91156 Chat MessageBus delivers read-restricted messages to unauthorized users --- pkgs/servers/web-apps/discourse/default.nix | 25 +- .../include-precompiled-bundles.patch | 26 +- .../plugins/discourse-docs/default.nix | 4 +- .../discourse-yearly-review/default.nix | 4 +- .../web-apps/discourse/rubyEnv/Gemfile | 64 +- .../web-apps/discourse/rubyEnv/Gemfile.lock | 652 +++++++++--------- .../web-apps/discourse/rubyEnv/gemset.nix | 536 +++++++------- .../sass_embedded_vendored_dart_sass.patch | 12 +- .../discourse/voice-plugin-assets.patch | 38 + 9 files changed, 699 insertions(+), 662 deletions(-) create mode 100644 pkgs/servers/web-apps/discourse/voice-plugin-assets.patch diff --git a/pkgs/servers/web-apps/discourse/default.nix b/pkgs/servers/web-apps/discourse/default.nix index cead7c2e22d2..17f75b2048a0 100644 --- a/pkgs/servers/web-apps/discourse/default.nix +++ b/pkgs/servers/web-apps/discourse/default.nix @@ -54,13 +54,13 @@ }: let - version = "2026.8.0"; + version = "2026.9.0"; src = fetchFromGitHub { owner = "discourse"; repo = "discourse"; tag = "v${version}"; - hash = "sha256-UUDPZVBQXG6kfW8+TFFDHsNMdH8WLxsgva4jSdZWsC8="; + hash = "sha256-xOZyoDA+/UPV/art5z8lNSM7RfNejeYcZAL+JzrPk7A="; }; pnpm = pnpm_10; @@ -180,8 +180,8 @@ let rubyEnv = let # these hashes are auto-updated by update.py - dart-x64-hash = "sha256-2rnqNeEr8PFMuFa4IhutxxXui1dCw3XQVqCV5ZwsUR8="; - dart-arm64-hash = "sha256-8sgc9IaeWSRnURFtMuSOqnKACkDc5WynmLIboYWwoSM="; + dart-x64-hash = "sha256-pNK3ekjTYP/FCInhtb5uxDBDP/yA79fnE76avxoHt9k="; + dart-arm64-hash = "sha256-B6OWLvW7dM6DIeO5A6WbpQ0IHJca54HZCRLyAn2XKK0="; in bundlerEnv rec { name = "discourse-ruby-env-${version}"; @@ -274,7 +274,7 @@ let unpackPhase nativeBuildInputs ; - hash = "sha256-OIkSavAjja1atbeyPAKFXsXoYI3nUk9c5G3RFBj53Uk="; + hash = "sha256-2OITwITCGoAIahIXpemWP38iFGSlrycUV319pmdD1dY="; }; dontBuild = false; @@ -350,7 +350,7 @@ let pname = "discourse-assets"; inherit version src pnpm; fetcherVersion = 3; - hash = "sha256-fm6hboG2Bjq0HUnbwdLiC1FpoWRZvq+1bN5SupQ2P2k="; + hash = "sha256-oahr5SJzHfIfcB7NFxeeEYDf3Q4m/iC/JMpNjlEWgSE="; }; nativeBuildInputs = runtimeDeps ++ [ @@ -471,6 +471,8 @@ let dontCheckForBrokenSymlinks = true; }; + voiceAssets = rubyEnv.gems.discourse_voice_assets; + discourse = stdenv.mkDerivation { pname = "discourse"; inherit version src; @@ -520,6 +522,9 @@ let # in the imagemagick sandbox, symlinks permissions are checked (as you would hope) but this causes other problems.. ./optimize-image-fix.patch + + # Skip voice plugin asset symlink removal/recreation at runtime. + ./voice-plugin-assets.patch ]; postPatch = '' @@ -565,6 +570,14 @@ let p: "ln -sf ${p} $out/share/discourse/plugins/${p.pluginName or ""}" ) plugins} + # The voice plugin creates its asset symlink below its source tree. That + # works during the asset build, but the package source tree is read-only + # at runtime.. + mkdir -p $out/share/discourse/plugins/voice/public/javascripts + ln -sf \ + ${voiceAssets}/lib/ruby/gems/${rubyEnv.ruby.version.libDir}/gems/discourse_voice_assets-${voiceAssets.version}/vendor \ + $out/share/discourse/plugins/voice/public/javascripts/${voiceAssets.version} + runHook postInstall ''; diff --git a/pkgs/servers/web-apps/discourse/include-precompiled-bundles.patch b/pkgs/servers/web-apps/discourse/include-precompiled-bundles.patch index 962398f06eb9..60bc5b8394dd 100644 --- a/pkgs/servers/web-apps/discourse/include-precompiled-bundles.patch +++ b/pkgs/servers/web-apps/discourse/include-precompiled-bundles.patch @@ -1,5 +1,5 @@ diff --git a/lib/asset_processor.rb b/lib/asset_processor.rb -index 0c602a85220..be1e22061b0 100644 +index 95b1245391e..adff8527457 100644 --- a/lib/asset_processor.rb +++ b/lib/asset_processor.rb @@ -5,7 +5,7 @@ class AssetProcessor @@ -11,16 +11,16 @@ index 0c602a85220..be1e22061b0 100644 filename_prefix: "asset-processor", dependency_globs: %w[ node_modules/.pnpm/lock.yaml -diff --git a/lib/pretty_text.rb b/lib/pretty_text.rb -index 6f176324799..9815f579212 100644 ---- a/lib/pretty_text.rb -+++ b/lib/pretty_text.rb -@@ -54,7 +54,7 @@ module PrettyText +diff --git a/lib/pretty_text/core_bundle.rb b/lib/pretty_text/core_bundle.rb +index 963dfb1ac6b..97b717e7569 100644 +--- a/lib/pretty_text/core_bundle.rb ++++ b/lib/pretty_text/core_bundle.rb +@@ -21,7 +21,7 @@ module PrettyText - CORE_BUNDLE = - PrecompiledBundle.new( -- dir: "tmp/pretty-text-processor", -+ dir: "frontend/pretty-text-processor.build", - filename_prefix: "pretty-text", - dependency_globs: - %w[ + BUNDLE = + PrecompiledBundle.new( +- dir: "tmp/pretty-text-processor", ++ dir: "frontend/pretty-text-processor.build", + filename_prefix: "pretty-text", + dependency_globs: + %w[ diff --git a/pkgs/servers/web-apps/discourse/plugins/discourse-docs/default.nix b/pkgs/servers/web-apps/discourse/plugins/discourse-docs/default.nix index da083a671aab..5b93c678e59f 100644 --- a/pkgs/servers/web-apps/discourse/plugins/discourse-docs/default.nix +++ b/pkgs/servers/web-apps/discourse/plugins/discourse-docs/default.nix @@ -9,8 +9,8 @@ mkDiscoursePlugin { src = fetchFromGitHub { owner = "discourse"; repo = "discourse-docs"; - rev = "0796384551e3f9d328c57e88577098be05d816c7"; - sha256 = "sha256-lZ8BlFaQcd9H+bom2igbJl4Ty7qmqtpbOpGbqIF8nEo="; + rev = "89bae0e929387ed5697fd3c5eedf9b3dbe85bead"; + sha256 = "sha256-ycDyYRi7uab4vxHY8K2kUytWBmTuFTFHYGD1AHpzC+0="; }; meta = { homepage = "https://github.com/discourse/discourse-docs"; diff --git a/pkgs/servers/web-apps/discourse/plugins/discourse-yearly-review/default.nix b/pkgs/servers/web-apps/discourse/plugins/discourse-yearly-review/default.nix index 132422792950..0e42e98bedfc 100644 --- a/pkgs/servers/web-apps/discourse/plugins/discourse-yearly-review/default.nix +++ b/pkgs/servers/web-apps/discourse/plugins/discourse-yearly-review/default.nix @@ -9,8 +9,8 @@ mkDiscoursePlugin { src = fetchFromGitHub { owner = "discourse"; repo = "discourse-yearly-review"; - rev = "97720c573f04ce32544ef1e9353b12005de0bdec"; - sha256 = "sha256-ZhkrPYFjhtNoh6jQhqPTMZJqHMyZo3tdbtSl3MuOJz0="; + rev = "a4e9ee393de923332609d0436e3c1c8757f6cb1c"; + sha256 = "sha256-WHU7vYTnavX3waJWjHn11kg70TCoFH9cdmdPRSsNZO4="; }; meta = { homepage = "https://github.com/discourse/discourse-yearly-review"; diff --git a/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile b/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile index 0cb16063f2c9..e706d9ef881a 100644 --- a/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile +++ b/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile @@ -8,13 +8,13 @@ source "https://rubygems.org" gem "bootsnap", require: false, platform: :mri -gem "actionmailer", "~> 8.0.0" -gem "actionpack", "~> 8.0.0" -gem "actionview", "~> 8.0.0" -gem "activemodel", "~> 8.0.0" -gem "activerecord", "~> 8.0.0" -gem "activesupport", "~> 8.0.0" -gem "railties", "~> 8.0.0" +gem "actionmailer", "~> 8.1.0" +gem "actionpack", "~> 8.1.0" +gem "actionview", "~> 8.1.0" +gem "activemodel", "~> 8.1.0" +gem "activerecord", "~> 8.1.0" +gem "activesupport", "~> 8.1.0" +gem "railties", "~> 8.1.0" gem "propshaft" gem "json" @@ -60,6 +60,8 @@ gem "message_bus" gem "rails_multisite" gem "fastimage" +gem "msgpack" +gem "ruby-vips", "~> 2.3", require: false gem "aws-sdk-s3", require: false gem "aws-sdk-sns", require: false @@ -80,13 +82,13 @@ gem "loofah" gem "css_parser", require: false gem "omniauth" -gem "omniauth-facebook" -gem "omniauth-twitter" -gem "omniauth-github" +gem "omniauth-facebook", require: false +gem "omniauth-twitter", require: false +gem "omniauth-github", require: false gem "omniauth-oauth2", require: false -gem "omniauth-google-oauth2" +gem "omniauth-google-oauth2", require: false gem "oj" @@ -114,7 +116,7 @@ gem "rack-protection" # security gem "cbor", require: false gem "cose", require: false gem "addressable" -gem "json_schemer" +gem "json_schemer", require: false gem "net-smtp", require: false gem "net-pop", require: false @@ -126,37 +128,36 @@ group :test do gem "capybara", require: false gem "webmock", require: false gem "simplecov", require: false - gem "test-prof" + gem "test-prof", require: false gem "rails-dom-testing", require: false - gem "minio_runner", require: false - gem "capybara-playwright-driver" + gem "capybara-playwright-driver", require: false gem "puma", require: false end group :test, :development do - gem "rspec" + gem "rspec", require: false gem "listen", require: false gem "certified", require: false gem "fabrication", require: false gem "mocha", require: false - gem "rb-fsevent", require: RUBY_PLATFORM =~ /darwin/i ? "rb-fsevent" : false + gem "rb-fsevent", require: false - gem "rspec-rails" + gem "rspec-rails", require: false gem "shoulda-matchers", require: false - gem "rspec-html-matchers" + gem "rspec-html-matchers", require: false gem "debug", ">= 1.0.0", require: "debug/prelude" gem "rubocop-discourse", require: false - gem "parallel_tests" + gem "parallel_tests", require: false - gem "rswag-specs" + gem "rswag-specs", require: false - gem "annotaterb" + gem "annotaterb", require: false - gem "syntax_tree" + gem "syntax_tree", require: false - gem "rspec-multi-mock" + gem "rspec-multi-mock", require: false end group :development do @@ -175,8 +176,8 @@ if ENV["ALLOW_DEV_POPULATE"] == "1" gem "faker" else group :development, :test do - gem "discourse_dev_assets" - gem "faker" + gem "discourse_dev_assets", require: false + gem "faker", require: false end end @@ -224,7 +225,7 @@ gem "sassc-embedded" gem "rotp", require: false -gem "rqrcode" +gem "rqrcode", require: false gem "rubyzip", require: false @@ -232,10 +233,10 @@ gem "landlock", require: false gem "sshkey", require: false -gem "rchardet", require: false gem "lz4-ruby", require: false, platform: :ruby gem "sanitize" +gem "reverse_markdown", "3.0.2", require: false if ENV["IMPORT"] == "1" gem "mysql2" @@ -244,7 +245,6 @@ if ENV["IMPORT"] == "1" # NOTE: in import mode the version of sqlite can matter a lot, so we stick it to a specific one gem "sqlite3", "~> 1.3", ">= 1.3.13" gem "ruby-bbcode-to-md", git: "https://github.com/nlalonde/ruby-bbcode-to-md" - gem "reverse_markdown" gem "tiny_tds" gem "csv" end @@ -273,6 +273,9 @@ gem "cgi", ">= 0.3.6", require: false gem "tzinfo-data" gem "csv", require: false +# Rails 8.1 drops its own dependency on `benchmark`. +gem "benchmark", require: false + # dependencies for the automation plugin gem "iso8601" gem "rrule" @@ -308,6 +311,9 @@ gem "tiktoken_ruby", require: false gem "smarter_json", require: false gem "json_completer", require: false gem "discourse_ai-tokenizers", require: false + +# for the voice plugin +gem "discourse_voice_assets", require: false gem "ed25519" # TODO: remove this as existing ssl gem should handle this gem "Ascii85", require: false gem "ruby-rc4", require: false diff --git a/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile.lock b/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile.lock index 0e3517db3815..173b0a828fff 100644 --- a/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile.lock +++ b/pkgs/servers/web-apps/discourse/rubyEnv/Gemfile.lock @@ -4,9 +4,11 @@ PATH migrations-converters (0.0.1) activesupport colored2 + discourse-emojis i18n markbridge (>= 0.4.0) migrations-core + mini_racer pg zeitwerk @@ -53,16 +55,16 @@ GEM remote: https://rubygems.org/ specs: Ascii85 (2.0.1) - actionmailer (8.0.5.1) - actionpack (= 8.0.5.1) - actionview (= 8.0.5.1) - activejob (= 8.0.5.1) - activesupport (= 8.0.5.1) + actionmailer (8.1.3.1) + actionpack (= 8.1.3.1) + actionview (= 8.1.3.1) + activejob (= 8.1.3.1) + activesupport (= 8.1.3.1) mail (>= 2.8.0) rails-dom-testing (~> 2.2) - actionpack (8.0.5.1) - actionview (= 8.0.5.1) - activesupport (= 8.0.5.1) + actionpack (8.1.3.1) + actionview (= 8.1.3.1) + activesupport (= 8.1.3.1) nokogiri (>= 1.8.5) rack (>= 2.2.4) rack-session (>= 1.0.1) @@ -70,8 +72,8 @@ GEM rails-dom-testing (~> 2.2) rails-html-sanitizer (~> 1.6) useragent (~> 0.16) - actionview (8.0.5.1) - activesupport (= 8.0.5.1) + actionview (8.1.3.1) + activesupport (= 8.1.3.1) builder (~> 3.1) erubi (~> 1.11) rails-dom-testing (~> 2.2) @@ -80,23 +82,23 @@ GEM actionview (>= 6.0.a) active_model_serializers (0.8.4) activemodel (>= 3.0) - activejob (8.0.5.1) - activesupport (= 8.0.5.1) + activejob (8.1.3.1) + activesupport (= 8.1.3.1) globalid (>= 0.3.6) - activemodel (8.0.5.1) - activesupport (= 8.0.5.1) - activerecord (8.0.5.1) - activemodel (= 8.0.5.1) - activesupport (= 8.0.5.1) + activemodel (8.1.3.1) + activesupport (= 8.1.3.1) + activerecord (8.1.3.1) + activemodel (= 8.1.3.1) + activesupport (= 8.1.3.1) timeout (>= 0.4.0) - activesupport (8.0.5.1) + activesupport (8.1.3.1) base64 - benchmark (>= 0.3) bigdecimal concurrent-ruby (~> 1.0, >= 1.3.1) connection_pool (>= 2.2.5) drb i18n (>= 1.6, < 2) + json logger (>= 1.4.2) minitest (>= 5.1) securerandom (>= 0.3) @@ -108,15 +110,17 @@ GEM annotaterb (4.20.0) activerecord (>= 6.0.0) activesupport (>= 6.0.0) + anonymous_loader (0.1.3) + version_gem (~> 1.1, >= 1.1.14) ast (2.4.3) - auth-sanitizer (0.1.4) - version_gem (~> 1.1, >= 1.1.9) + auth-sanitizer (0.2.3) + version_gem (~> 1.1, >= 1.1.14) aws-eventstream (1.4.0) - aws-partitions (1.1134.0) - aws-sdk-bedrockruntime (1.74.0) - aws-sdk-core (~> 3, >= 3.244.0) + aws-partitions (1.1284.0) + aws-sdk-bedrockruntime (1.83.0) + aws-sdk-core (~> 3, >= 3.254.0) aws-sigv4 (~> 1.5) - aws-sdk-core (3.254.0) + aws-sdk-core (3.255.0) aws-eventstream (~> 1, >= 1.3.0) aws-partitions (~> 1, >= 1.992.0) aws-sigv4 (~> 1.9) @@ -124,6 +128,7 @@ GEM bigdecimal jmespath (~> 1, >= 1.6.1) logger + rexml (~> 3.4, >= 3.4.2) aws-sdk-kms (1.99.0) aws-sdk-core (~> 3, >= 3.216.0) aws-sigv4 (~> 1.5) @@ -149,10 +154,10 @@ GEM rack (>= 0.9.0) rouge (>= 1.0.0) bigdecimal (3.3.1) - bootsnap (1.24.5) - msgpack (~> 1.2) + bootsnap (1.25.0) + msgpack (~> 1.5) builder (3.3.0) - bullet (8.1.3) + bullet (8.2.0) activesupport (>= 3.0.0) uniform_notifier (~> 1.11) capybara (3.40.0) @@ -164,19 +169,19 @@ GEM rack-test (>= 0.6.3) regexp_parser (>= 1.5, < 3.0) xpath (~> 3.2) - capybara-playwright-driver (0.5.9) + capybara-playwright-driver (0.5.10) addressable capybara playwright-ruby-client (>= 1.16.0) cbor (0.5.10.3) certified (1.0.0) - cgi (0.5.1) + cgi (0.5.2) chunky_png (1.4.0) coderay (1.1.3) colored2 (4.0.3) - concurrent-ruby (1.3.7) + concurrent-ruby (1.3.8) connection_pool (2.5.5) - console (1.36.0) + console (1.37.0) fiber-annotation fiber-local (~> 1.1) json @@ -187,11 +192,11 @@ GEM crack (1.0.1) bigdecimal rexml - crass (1.0.6) + crass (1.0.7) css_parser (3.0.0) addressable ssrf_filter (~> 1.5) - csv (3.3.5) + csv (3.3.6) date (3.5.1) debug (1.11.1) irb (~> 1.10) @@ -213,17 +218,17 @@ GEM faker (~> 3.5.1) literate_randomizer discourse_math_bundle (1.0.1) - docile (1.4.1) + discourse_voice_assets (0.1.0) drb (2.2.3) dry-initializer (3.2.0) ed25519 (1.4.0) - email_reply_trimmer (0.2.0) - erb (6.0.4) + email_reply_trimmer (0.4.0) + erb (6.0.7) erubi (1.13.1) - excon (1.5.0) + excon (1.7.1) logger exifr (1.5.1) - extralite-bundle (2.14) + extralite-bundle (3.0.1) fabrication (3.0.0) faker (3.5.3) i18n (>= 1.8.11, < 2) @@ -251,30 +256,30 @@ GEM fiber-storage fiber-storage (1.0.1) fspath (3.1.2) - globalid (1.3.0) + globalid (1.4.0) activesupport (>= 6.1) goldiloader (6.0.0) activerecord (>= 7.2, < 8.3) activesupport (>= 7.2, < 8.3) - google-protobuf (4.35.0) + google-protobuf (4.36.1) bigdecimal rake (~> 13.3) - google-protobuf (4.35.0-aarch64-linux-gnu) + google-protobuf (4.36.1-aarch64-linux-gnu) bigdecimal rake (~> 13.3) - google-protobuf (4.35.0-aarch64-linux-musl) + google-protobuf (4.36.1-aarch64-linux-musl) bigdecimal rake (~> 13.3) - google-protobuf (4.35.0-arm64-darwin) + google-protobuf (4.36.1-arm64-darwin) bigdecimal rake (~> 13.3) - google-protobuf (4.35.0-x86_64-darwin) + google-protobuf (4.36.1-x86_64-darwin) bigdecimal rake (~> 13.3) - google-protobuf (4.35.0-x86_64-linux-gnu) + google-protobuf (4.36.1-x86_64-linux-gnu) bigdecimal rake (~> 13.3) - google-protobuf (4.35.0-x86_64-linux-musl) + google-protobuf (4.36.1-x86_64-linux-musl) bigdecimal rake (~> 13.3) guess_html_encoding (0.0.11) @@ -298,7 +303,7 @@ GEM image_size (3.6.0) in_threads (1.6.0) inflection (1.0.0) - io-console (0.8.2) + io-console (0.9.2) irb (1.18.0) pp (>= 0.6.0) prism (>= 1.3.0) @@ -306,7 +311,7 @@ GEM reline (>= 0.4.2) iso8601 (0.13.0) jmespath (1.6.2) - json (2.19.9) + json (2.21.2) json-schema (6.2.0) addressable (~> 2.8) bigdecimal (>= 3.1, < 5) @@ -316,10 +321,10 @@ GEM hana (~> 1.3) regexp_parser (~> 2.0) simpleidn (~> 0.2) - jwt (2.10.1) + jwt (3.2.0) base64 - landlock (0.4.1) - language_server-protocol (3.17.0.5) + landlock (0.5.1) + language_server-protocol (3.17.0.6) libv8-node (24.12.0.1) libv8-node (24.12.0.1-aarch64-linux) libv8-node (24.12.0.1-aarch64-linux-musl) @@ -337,19 +342,19 @@ GEM rb-inotify (~> 0.9, >= 0.9.10) literate_randomizer (0.4.0) logger (1.7.0) - lograge (0.14.0) + lograge (0.15.0) actionpack (>= 4) activesupport (>= 4) railties (>= 4) request_store (~> 1.0) logstash-event (1.2.02) logster (2.21.0) - loofah (2.25.1) + loofah (2.25.2) crass (~> 1.0.2) nokogiri (>= 1.12.0) lru_redux (1.1.0) lz4-ruby (0.3.3) - mail (2.9.0) + mail (2.9.1) logger mini_mime (>= 0.1.1) net-imap @@ -359,7 +364,8 @@ GEM matrix (0.4.3) maxminddb (0.1.22) memory_profiler (1.1.0) - message_bus (4.5.2) + message_bus (5.0.0) + logger rack (> 2, < 4) messageformat-wrapper (1.1.0) mini_racer (>= 0.6.3) @@ -367,76 +373,79 @@ GEM mime-types (3.7.0) logger mime-types-data (~> 3.2025, >= 3.2025.0507) - mime-types-data (3.2026.0414) + mime-types-data (3.2026.0701) mini_mime (1.1.5) mini_portile2 (2.8.9) - mini_racer (0.22.0) + mini_racer (0.22.1) libv8-node (~> 24.12.0.1) mini_scheduler (0.20.0) sidekiq (>= 6.5, < 9.0) mini_sql (1.6.0) mini_suffix (0.3.3) ffi (~> 1.9) - minio_runner (1.1.0) minitest (6.0.6) drb (~> 2.0) prism (~> 1.5) mocha (3.1.0) ruby2_keywords (>= 0.0.5) - msgpack (1.8.3) - multi_json (1.20.1) + msgpack (1.8.4) + multi_json (1.21.1) multi_xml (0.9.1) bigdecimal (>= 3.1, < 5) multipart-post (2.4.1) - mustache (1.1.2) + mustache (1.1.3) net-http (0.9.1) uri (>= 0.11.1) - net-imap (0.6.4.1) + net-imap (0.6.6) date net-protocol net-pop (0.1.2) net-protocol - net-protocol (0.2.2) + net-protocol (0.3.0) timeout net-smtp (0.5.1) net-protocol nio4r (2.7.5) - nokogiri (1.19.3) + nokogiri (1.19.4) mini_portile2 (~> 2.8.2) racc (~> 1.4) - nokogiri (1.19.3-aarch64-linux-gnu) + nokogiri (1.19.4-aarch64-linux-gnu) racc (~> 1.4) - nokogiri (1.19.3-aarch64-linux-musl) + nokogiri (1.19.4-aarch64-linux-musl) racc (~> 1.4) - nokogiri (1.19.3-arm64-darwin) + nokogiri (1.19.4-arm64-darwin) racc (~> 1.4) - nokogiri (1.19.3-x86_64-darwin) + nokogiri (1.19.4-x86_64-darwin) racc (~> 1.4) - nokogiri (1.19.3-x86_64-linux-gnu) + nokogiri (1.19.4-x86_64-linux-gnu) racc (~> 1.4) - nokogiri (1.19.3-x86_64-linux-musl) + nokogiri (1.19.4-x86_64-linux-musl) racc (~> 1.4) - oauth (1.1.5) - auth-sanitizer (~> 0.1, >= 0.1.3) + oauth (1.1.8) + anonymous_loader (~> 0.1, >= 0.1.3) + auth-sanitizer (~> 0.2, >= 0.2.3) base64 (~> 0.1) - cgi - oauth-tty (~> 1.0, >= 1.0.8) - snaky_hash (~> 2.0, >= 2.0.4) - version_gem (~> 1.1, >= 1.1.9) - oauth-tty (1.0.8) - auth-sanitizer (~> 0.1, >= 0.1.3) - cgi - version_gem (~> 1.1, >= 1.1.9) - oauth2 (1.4.11) - faraday (>= 0.17.3, < 3.0) - jwt (>= 1.0, < 3.0) - multi_json (~> 1.3) + oauth-tty (~> 1.0, >= 1.0.13) + snaky_hash (~> 2.0, >= 2.0.7) + version_gem (~> 1.1, >= 1.1.14) + oauth-tty (1.0.13) + anonymous_loader (~> 0.1, >= 0.1.3) + auth-sanitizer (~> 0.2, >= 0.2.3) + version_gem (~> 1.1, >= 1.1.14) + oauth2 (2.0.25) + anonymous_loader (~> 0.1, >= 0.1.3) + auth-sanitizer (~> 0.2, >= 0.2.3) + faraday (>= 0.17.3, < 4.0) + jwt (>= 1.0, < 4.0) + logger (~> 1.2) multi_xml (~> 0.5) rack (>= 1.2, < 4) + snaky_hash (~> 2.0, >= 2.0.7) + version_gem (~> 1.1, >= 1.1.14) octokit (10.0.0) faraday (>= 1, < 3) sawyer (~> 0.9) - oj (3.16.12) + oj (3.17.6) bigdecimal (>= 3.0) ostruct (>= 0.2) omniauth (2.1.2) @@ -446,25 +455,26 @@ GEM omniauth-facebook (10.0.0) bigdecimal omniauth-oauth2 (>= 1.2, < 3) - omniauth-github (2.0.0) + omniauth-github (2.0.1) omniauth (~> 2.0) - omniauth-oauth2 (~> 1.7.1) - omniauth-google-oauth2 (1.0.1) - jwt (>= 2.0) - oauth2 (~> 1.1) + omniauth-oauth2 (~> 1.8) + omniauth-google-oauth2 (1.2.3) + jwt (>= 2.9.2, < 4) + oauth2 (~> 2.0) omniauth (~> 2.0) - omniauth-oauth2 (~> 1.7.1) + omniauth-oauth2 (~> 1.8) omniauth-oauth (1.2.1) oauth omniauth (>= 1.0, < 3) rack (>= 1.6.2, < 4) - omniauth-oauth2 (1.7.3) - oauth2 (>= 1.4, < 3) - omniauth (>= 1.9, < 3) - omniauth-twitter (1.4.0) - omniauth-oauth (~> 1.1) + omniauth-oauth2 (1.9.0) + oauth2 (>= 2.0.2, < 3) + omniauth (~> 2.0) + omniauth-twitter (1.5.0) + cgi + omniauth-oauth (~> 1.2) rack - openssl (3.3.2) + openssl (4.0.2) openssl-signature_algorithm (1.3.0) openssl (> 2.0) optimist (3.2.1) @@ -472,16 +482,15 @@ GEM parallel (2.1.0) parallel_tests (5.7.0) parallel - parser (3.3.11.1) + parser (3.3.12.0) ast (~> 2.4.1) racc pastel (0.8.0) tty-color (~> 0.5) - pdf-reader (2.15.1) + pdf-reader (2.16.0) Ascii85 (>= 1.0, < 3.0, != 2.0.0) afm (>= 0.2.1, < 2) hashery (~> 2.0) - ruby-rc4 ttfunk pg (1.6.3) pg (1.6.3-aarch64-linux) @@ -493,11 +502,11 @@ GEM pitchfork (0.18.2) logger rack (>= 2.0) - playwright-ruby-client (1.60.0) + playwright-ruby-client (1.62.0) base64 concurrent-ruby (>= 1.1.6) mime-types (>= 3.0) - pp (0.6.3) + pp (0.6.4) prettyprint prettier_print (1.2.1) prettyprint (0.2.0) @@ -513,15 +522,12 @@ GEM reline (>= 0.6.0) pry-rails (0.3.11) pry (>= 0.13.0) - psych (5.4.0) - date - stringio public_suffix (7.0.5) puma (8.0.2) nio4r (~> 2.0) racc (1.8.1) - rack (2.2.23) - rack-mini-profiler (4.0.1) + rack (2.2.24) + rack-mini-profiler (5.0.0) rack (>= 1.2.0) rack-protection (3.2.0) base64 (>= 0.1.0) @@ -537,19 +543,19 @@ GEM activesupport (>= 5.0.0) minitest nokogiri (>= 1.6) - rails-html-sanitizer (1.7.0) - loofah (~> 2.25) + rails-html-sanitizer (1.7.1) + loofah (~> 2.25, >= 2.25.2) nokogiri (>= 1.15.7, != 1.16.7, != 1.16.6, != 1.16.5, != 1.16.4, != 1.16.3, != 1.16.2, != 1.16.1, != 1.16.0.rc1, != 1.16.0) rails_failover (2.3.0) activerecord (>= 6.1, < 9.0) concurrent-ruby railties (>= 6.1, < 9.0) - rails_multisite (7.0.0) - activerecord (>= 7.1) - railties (>= 7.1) - railties (8.0.5.1) - actionpack (= 8.0.5.1) - activesupport (= 8.0.5.1) + rails_multisite (9.0.0) + activerecord (>= 7.2) + railties (>= 7.2) + railties (8.1.3.1) + actionpack (= 8.1.3.1) + activesupport (= 8.1.3.1) irb (~> 1.13) rackup (>= 1.0.0) rake (>= 12.2) @@ -565,35 +571,37 @@ GEM ffi (~> 1.0) rb_sys (0.9.130) rake-compiler-dock (= 1.12.0) - rbs (4.0.2) + rbs (4.2.0) logger prism (>= 1.6.0) tsort - rbtrace (0.5.4) + rbtrace (0.5.5) ffi (>= 1.0.6) msgpack (>= 0.4.3) optimist (>= 3.0.0) - rchardet (1.10.2) - rdoc (7.2.0) + rdoc (8.0.0) erb - psych (>= 4.0.0) + prism (>= 1.6.0) + rbs (>= 4.0.0) tsort redcarpet (3.6.1) - redis (5.4.0) - redis-client (>= 0.22.0) - redis-client (0.30.0) + redis (6.0.0) + redis-client (= 0.30.1) + redis-client (0.30.1) connection_pool redis-namespace (1.11.0) redis (>= 4) regexp_parser (2.12.0) - reline (0.6.3) + reline (0.7.0) io-console (~> 0.5) request_store (1.7.0) rack (>= 1.4) + reverse_markdown (3.0.2) + nokogiri rexml (3.4.4) rinku (2.0.6) rotp (6.3.0) - rouge (5.0.0) + rouge (5.1.0) strscan (~> 3.1) rqrcode (3.2.0) chunky_png (~> 1.0) @@ -636,8 +644,8 @@ GEM rspec-core (>= 2.14) rtlcss (0.2.1) mini_racer (>= 0.6.3) - rubocop (1.86.1) - json (~> 2.3) + rubocop (1.91.0) + json (>= 2.3) language_server-protocol (~> 3.17.0.2) lint_roller (~> 1.1.0) parallel (>= 1.10) @@ -647,13 +655,13 @@ GEM rubocop-ast (>= 1.49.0, < 2.0) ruby-progressbar (~> 1.7) unicode-display_width (>= 2.4.0, < 4.0) - rubocop-ast (1.49.1) + rubocop-ast (1.50.0) parser (>= 3.3.7.2) prism (~> 1.7) - rubocop-capybara (2.23.0) + rubocop-capybara (3.0.0) lint_roller (~> 1.1) rubocop (~> 1.81) - rubocop-discourse (3.18.0) + rubocop-discourse (3.20.0) activesupport (>= 6.1) lint_roller (>= 1.1.0) rubocop-capybara (>= 2.23.0) @@ -667,20 +675,21 @@ GEM rubocop-factory_bot (2.28.0) lint_roller (~> 1.1) rubocop (~> 1.72, >= 1.72.1) - rubocop-rails (2.34.3) + rubocop-rails (2.37.0) activesupport (>= 4.2.0) lint_roller (~> 1.1) rack (>= 1.1) - rubocop (>= 1.75.0, < 2.0) + rubocop (>= 1.89.0, < 2.0) rubocop-ast (>= 1.44.0, < 2.0) - rubocop-rspec (3.9.0) + rubocop-rspec (3.10.2) lint_roller (~> 1.1) - rubocop (~> 1.81) + regexp_parser (>= 2.0) + rubocop (~> 1.86, >= 1.86.2) rubocop-rspec_rails (2.32.0) lint_roller (~> 1.1) rubocop (~> 1.72, >= 1.72.1) rubocop-rspec (~> 3.5) - ruby-lsp (0.26.9) + ruby-lsp (0.26.11) language_server-protocol (~> 3.17.0) prism (>= 1.2, < 2.0) rbs (>= 3, < 5) @@ -696,80 +705,80 @@ GEM ruby-readability (0.7.3) guess_html_encoding (>= 0.0.4) nokogiri (>= 1.6.0) + ruby-vips (2.3.0) + ffi (~> 1.12) + logger ruby2_keywords (0.0.5) - rubyzip (3.3.1) + rubyzip (3.6.0) samovar (2.5.1) console (~> 1.0) sanitize (7.0.0) crass (~> 1.0.2) nokogiri (>= 1.16.8) - sass-embedded (1.100.0) + sass-embedded (1.104.0) google-protobuf (~> 4.31) rake (>= 13) - sass-embedded (1.100.0-aarch64-linux-gnu) + sass-embedded (1.104.0-aarch64-linux-gnu) google-protobuf (~> 4.31) - sass-embedded (1.100.0-aarch64-linux-musl) + sass-embedded (1.104.0-aarch64-linux-musl) google-protobuf (~> 4.31) - sass-embedded (1.100.0-arm64-darwin) + sass-embedded (1.104.0-arm64-darwin) google-protobuf (~> 4.31) - sass-embedded (1.100.0-x86_64-darwin) + sass-embedded (1.104.0-x86_64-darwin) google-protobuf (~> 4.31) - sass-embedded (1.100.0-x86_64-linux-gnu) + sass-embedded (1.104.0-x86_64-linux-gnu) google-protobuf (~> 4.31) - sass-embedded (1.100.0-x86_64-linux-musl) + sass-embedded (1.104.0-x86_64-linux-musl) google-protobuf (~> 4.31) - sassc-embedded (1.80.8) + sassc-embedded (1.80.9) sass-embedded (~> 1.80) sawyer (0.9.3) addressable (>= 2.3.5) faraday (>= 0.17.3, < 3) securerandom (0.4.1) - shoulda-matchers (7.0.1) - activesupport (>= 7.1) + shoulda-matchers (8.0.1) + activesupport (>= 7.2) sidekiq (7.3.10) base64 connection_pool (>= 2.3.0, < 3) logger rack (>= 2.2.4, < 3.3) redis-client (>= 0.23.0, < 1) - simplecov (0.22.0) - docile (~> 1.1) - simplecov-html (~> 0.11) - simplecov_json_formatter (~> 0.1) - simplecov-html (0.13.2) - simplecov_json_formatter (0.1.4) - simpleidn (0.2.3) + simplecov (1.1.1) + simpleidn (0.3.0) smarter_json (1.2.6) bigdecimal - snaky_hash (2.0.4) + snaky_hash (2.0.7) hashie (>= 0.1.0, < 6) - version_gem (>= 1.1.8, < 3) - sqlite3 (2.9.5) + version_gem (~> 1.1, >= 1.1.14) + sqlite3 (2.9.6) mini_portile2 (~> 2.8.0) - sqlite3 (2.9.5-aarch64-linux-gnu) - sqlite3 (2.9.5-aarch64-linux-musl) - sqlite3 (2.9.5-arm64-darwin) - sqlite3 (2.9.5-x86_64-darwin) - sqlite3 (2.9.5-x86_64-linux-gnu) - sqlite3 (2.9.5-x86_64-linux-musl) + sqlite3 (2.9.6-aarch64-linux-gnu) + sqlite3 (2.9.6-aarch64-linux-musl) + sqlite3 (2.9.6-arm64-darwin) + sqlite3 (2.9.6-x86_64-darwin) + sqlite3 (2.9.6-x86_64-linux-gnu) + sqlite3 (2.9.6-x86_64-linux-musl) sshkey (3.0.0) ssrf_filter (1.5.0) stackprof (0.2.28) - stringio (3.2.0) - stripe (11.1.0) + stripe (19.6.2) + bigdecimal + logger strscan (3.1.8) syntax_tree (6.3.0) prettier_print (>= 1.2.0) - test-prof (1.6.1) + test-prof (1.6.3) + logger thor (1.5.0) - tiktoken_ruby (0.0.16) + tiktoken_ruby (0.0.17) rb_sys (~> 0.9) - tiktoken_ruby (0.0.16-aarch64-linux) - tiktoken_ruby (0.0.16-aarch64-linux-musl) - tiktoken_ruby (0.0.16-arm64-darwin) - tiktoken_ruby (0.0.16-x86_64-darwin) - tiktoken_ruby (0.0.16-x86_64-linux) - tiktoken_ruby (0.0.16-x86_64-linux-musl) + tiktoken_ruby (0.0.17-aarch64-linux) + tiktoken_ruby (0.0.17-aarch64-linux-musl) + tiktoken_ruby (0.0.17-arm64-darwin) + tiktoken_ruby (0.0.17-x86_64-darwin) + tiktoken_ruby (0.0.17-x86_64-linux) + tiktoken_ruby (0.0.17-x86_64-linux-musl) timeout (0.6.1) tokenizers (0.6.4) rb_sys @@ -794,7 +803,7 @@ GEM tty-screen (0.8.2) tzinfo (2.0.6) concurrent-ruby (~> 1.0) - tzinfo-data (1.2026.2) + tzinfo-data (1.2026.3) tzinfo (>= 1.0.0) unf (0.2.0) unicode-display_width (3.2.0) @@ -803,11 +812,11 @@ GEM uniform_notifier (1.18.0) uri (1.1.1) useragent (0.16.11) - version_gem (1.1.13) - web-push (3.0.1) - jwt (~> 2.0) - openssl (~> 3.0) - webmock (3.26.2) + version_gem (1.1.15) + web-push (3.1.0) + jwt (~> 3.0) + openssl (>= 3.0) + webmock (3.26.4) addressable (>= 2.8.0) crack (>= 0.3.2) hashdiff (>= 0.4.0, < 2.0.0) @@ -816,12 +825,13 @@ GEM xpath (3.2.0) nokogiri (~> 1.8) yaml-lint (0.1.2) - yard (0.9.44) - zeitwerk (2.8.2) - zendesk_api (1.38.0.rc1) + yard (0.9.45) + zeitwerk (2.8.3) + zendesk_api (3.1.2) + base64 faraday (> 2.0.0) faraday-multipart - hashie (>= 3.5.2, < 6.0.0) + hashie (>= 3.5.2) inflection mini_mime multipart-post (~> 2.0) @@ -837,14 +847,14 @@ PLATFORMS DEPENDENCIES Ascii85 - actionmailer (~> 8.0.0) - actionpack (~> 8.0.0) - actionview (~> 8.0.0) + actionmailer (~> 8.1.0) + actionpack (~> 8.1.0) + actionview (~> 8.1.0) actionview_precompiler active_model_serializers (~> 0.8.3) - activemodel (~> 8.0.0) - activerecord (~> 8.0.0) - activesupport (~> 8.0.0) + activemodel (~> 8.1.0) + activerecord (~> 8.1.0) + activesupport (~> 8.1.0) addressable afm annotaterb @@ -853,6 +863,7 @@ DEPENDENCIES aws-sdk-s3 aws-sdk-sns aws-sdk-sts + benchmark better_errors bootsnap bullet @@ -875,6 +886,7 @@ DEPENDENCIES discourse_ai-tokenizers discourse_dev_assets discourse_math_bundle + discourse_voice_assets dry-initializer (~> 3.1) ed25519 email_reply_trimmer @@ -920,8 +932,8 @@ DEPENDENCIES mini_scheduler mini_sql mini_suffix - minio_runner mocha + msgpack multi_json multipart-post mustache @@ -951,15 +963,15 @@ DEPENDENCIES rails-dom-testing rails_failover rails_multisite - railties (~> 8.0.0) + railties (~> 8.1.0) raindrops rake rb-fsevent rbtrace - rchardet redcarpet redis redis-namespace + reverse_markdown (= 3.0.2) rinku rotp rqrcode @@ -978,6 +990,7 @@ DEPENDENCIES ruby-prof ruby-rc4 ruby-readability + ruby-vips (~> 2.3) rubyzip sanitize sassc-embedded @@ -1007,24 +1020,25 @@ DEPENDENCIES CHECKSUMS Ascii85 (2.0.1) sha256=15cb5d941808543cbb9e7e6aea3c8ec3877f154c3461e8b3673e97f7ecedbe5a - actionmailer (8.0.5.1) sha256=c3d2b3f96e1989ea25f51699786a97fcb2536eb7abfc2a667cb8f2376ec08403 - actionpack (8.0.5.1) sha256=a5595c9d824d68884ddc4d3965ab78c897760d3752e190df7efe897371caa1eb - actionview (8.0.5.1) sha256=472a108b9cc2295c4ac3ff09b028045e619875801f48c556f0085210b9cb1440 + actionmailer (8.1.3.1) sha256=88ea441b28ff02a0c6c006468892642a3d9942affce9d294e81a74504aa5c43c + actionpack (8.1.3.1) sha256=974cb7154548e81f470b1b0f247b99cb38e87825899dca58610596e2817723d0 + actionview (8.1.3.1) sha256=2da68b8414c47b43bfbed1ce69c5afe1c04f78c267aacb5660a4cab5ca12cfb6 actionview_precompiler (0.4.0) sha256=33b6bd6ec4c1b856e02fdf5f6512c9eb4a92ac1c0545e941b3e354b7d540ed1c active_model_serializers (0.8.4) sha256=7350e3d3b6a5946bbec033241d908013cc85ff4d584230e6aa074225547c754c - activejob (8.0.5.1) sha256=142407a21b6c3cbc6ddd92ca111ac18ea5c40298eb94d81845cd897a072a6880 - activemodel (8.0.5.1) sha256=559be32aa9c40db7a3ee0aef926d4508a9ebd22f96f7276c11326d21a7dff4a4 - activerecord (8.0.5.1) sha256=9252968fce404d75eb17092498a440d472167f2f8deee32b4658d6552b1eeea7 - activesupport (8.0.5.1) sha256=329a4280c4fbcfcf338ae2cb9df28b0b14527929dba105e10b3604516d998710 + activejob (8.1.3.1) sha256=1c8dd275df930df40deecffec63d913a550a33fd94bd298f69721dd96939954a + activemodel (8.1.3.1) sha256=99cc02ce2faec371d14440949d85787ebd23a907c9baef0a9d4bcd4d21888f88 + activerecord (8.1.3.1) sha256=0a2fb6c28f4938f6b013a3a549bec0a7e37d535f3dc8990e804bcc3258c0403b + activesupport (8.1.3.1) sha256=85458765f25ea48b9019c46b6bb3fa5683197bf4280d9f06710a6e8d7a831376 addressable (2.9.0) sha256=7fdf6ac3660f7f4e867a0838be3f6cf722ace541dd97767fa42bc6cfa980c7af afm (1.0.0) sha256=5bd4d6f6241e7014ef090985ec6f4c3e9745f6de0828ddd58bc1efdd138f4545 annotaterb (4.20.0) sha256=871b2e898d1d60c23bdc59b72a5b840678a56355bf5f6fdeb8c79d317ff98bf7 + anonymous_loader (0.1.3) sha256=084a18e2439144d955447dc11dfc982f41fcd1583ad32d4d55151325dc44cb55 ast (2.4.3) sha256=954615157c1d6a382bc27d690d973195e79db7f55e9765ac7c481c60bdb4d383 - auth-sanitizer (0.1.4) sha256=ded72221d4d3a7c91e34e8a87b21e6a42cbf7829697f140dcf49d542422faedc + auth-sanitizer (0.2.3) sha256=db10aac92cfbe4c64ab637eebcbe1d67395d1694798041362173370f59933e3c aws-eventstream (1.4.0) sha256=116bf85c436200d1060811e6f5d2d40c88f65448f2125bc77ffce5121e6e183b - aws-partitions (1.1134.0) sha256=28f5f6156777ac346904a79ce6cb3b14a521e3866fee12a0da86d7b500266d3e - aws-sdk-bedrockruntime (1.74.0) sha256=fc5eb0ab9485fc847bfcef058b8c50f2f7996d4a8266ce3562da2daa5bf1dea5 - aws-sdk-core (3.254.0) sha256=ee3e3220b8468a3c9e59daba18e6ec897bf5c7ce8adcc0670cfa2f1f092112fe + aws-partitions (1.1284.0) sha256=026432da13da430a31ba7c30c0c210b35fa7d738399977f033d4a5a354de58dc + aws-sdk-bedrockruntime (1.83.0) sha256=6e47a53f890fadd8e572335b933d13cd09530f8e63fc6c99fbb608c048936cb9 + aws-sdk-core (3.255.0) sha256=2bac7fbc8796e4e2eb8e6a6edebcb880d7023a922af97b15d2a8a26c9283343f aws-sdk-kms (1.99.0) sha256=ba292fc3ffd672532aae2601fe55ff424eee78da8e23c23ba6ce4037138275a8 aws-sdk-mediaconvert (1.165.0) sha256=d955a571cd8b0407c0778e1d0f2333a70bf9ab48e36c81da8c5b317db24001e4 aws-sdk-s3 (1.227.0) sha256=552b23bf9a37c7db4957e9291543e61c8de886cf31d1d45ea3b429df0feea939 @@ -1035,26 +1049,26 @@ CHECKSUMS benchmark (0.5.0) sha256=465df122341aedcb81a2a24b4d3bd19b6c67c1530713fd533f3ff034e419236c better_errors (2.10.1) sha256=f798f1bac93f3e775925b7fcb24cffbcf0bb62ee2210f5350f161a6b75fc0a73 bigdecimal (3.3.1) sha256=eaa01e228be54c4f9f53bf3cc34fe3d5e845c31963e7fcc5bedb05a4e7d52218 - bootsnap (1.24.5) sha256=36b677448524d279b470469aabd5dff4a980e3fa4931a0df68da4a500eb1b6c4 + bootsnap (1.25.0) sha256=41059e7d0f9cb4023a33465d095f64b913fc9d1b808d6524c307da945fbcffcf builder (3.3.0) sha256=497918d2f9dca528fdca4b88d84e4ef4387256d984b8154e9d5d3fe5a9c8835f - bullet (8.1.3) sha256=c8163c527324fe1180775be48719875726891622f0a73784658b2992acf3c7cb + bullet (8.2.0) sha256=921ed8cde81c939e4eda041345f44f0d0d72c6fbb63aec07d11e5bf653bbe473 capybara (3.40.0) sha256=42dba720578ea1ca65fd7a41d163dd368502c191804558f6e0f71b391054aeef - capybara-playwright-driver (0.5.9) sha256=4c17fed20817b7e1bde2cfc8186e7bf5cd72017ce1aa695e35130f8e600e7282 + capybara-playwright-driver (0.5.10) sha256=e48e572d72bc1043c644fab44985be0a1e75d7d6917dc298355581848982a2c3 cbor (0.5.10.3) sha256=c3aa1d0c7e9bbffe8de4bed554f588d7926c62276ffe2dd7fabb65bae801d28a certified (1.0.0) sha256=aa4cdf0e90e7ee96f6e0ce3daae39eaa8f0486124e0d92daf64d2105aeb9069c - cgi (0.5.1) sha256=e93fcafc69b8a934fe1e6146121fa35430efa8b4a4047c4893764067036f18e9 + cgi (0.5.2) sha256=61ca30298171190fd4fa0d8018e57ada456eae9b7a2b78526debf7f0a0e6f8bb chunky_png (1.4.0) sha256=89d5b31b55c0cf4da3cf89a2b4ebc3178d8abe8cbaf116a1dba95668502fdcfe coderay (1.1.3) sha256=dc530018a4684512f8f38143cd2a096c9f02a1fc2459edcfe534787a7fc77d4b colored2 (4.0.3) sha256=63e1038183976287efc43034f5cca17fb180b4deef207da8ba78d051cbce2b37 - concurrent-ruby (1.3.7) sha256=4412caec3a5ea2e5fdc52076724c071a81f2c0593d83b2ac8cbb8ca63b3151b0 + concurrent-ruby (1.3.8) sha256=b2f1be836e968ccc78ccfce277ea79c72a88633f22306782c16ff23fb415d1e1 connection_pool (2.5.5) sha256=e54ff92855753df1fd7c59fa04a398833355f27dd14c074f8c83a05f72a716ad - console (1.36.0) sha256=45599ea906cf80a73d8941f03abf873fe66a6a954e0bac5bc1c01e2cdc406f07 + console (1.37.0) sha256=8093b286c2595a063849c098594fee5155ecc7967d36f3aa8cbe7569c8f3efd7 cose (1.3.1) sha256=d5d4dbcd6b035d513edc4e1ab9bc10e9ce13b4011c96e3d1b8fe5e6413fd6de5 cppjieba_rb (0.4.4) sha256=319a7ab57b6ec28a8d1b223487ecd114432f1930d7740db2f99c1991e6c8faaf crack (1.0.1) sha256=ff4a10390cd31d66440b7524eb1841874db86201d5b70032028553130b6d4c7e - crass (1.0.6) sha256=dc516022a56e7b3b156099abc81b6d2b08ea1ed12676ac7a5657617f012bd45d + crass (1.0.7) sha256=94868719948664c89ddcaf0a37c65048413dfcb1c869470a5f7a7ceb5390b295 css_parser (3.0.0) sha256=eaf0e9283fd581d06e815235ceef4f0910c0b394c606355dbc69f93e84443885 - csv (3.3.5) sha256=6e5134ac3383ef728b7f02725d9872934f523cb40b961479f69cf3afa6c8e73f + csv (3.3.6) sha256=aba61e7e507a66f03d45cb1f3c4b6359861c3504038b422962875dce099e4456 date (3.5.1) sha256=750d06384d7b9c15d562c76291407d89e368dda4d4fff957eb94962d325a0dc0 debug (1.11.1) sha256=2e0b0ac6119f2207a6f8ac7d4a73ca8eb4e440f64da0a3136c30343146e952b6 diff-lcs (1.6.2) sha256=9ae0d2cba7d4df3075fe8cd8602a8604993efc0dfa934cff568969efb1909962 @@ -1067,16 +1081,16 @@ CHECKSUMS discourse_ai-tokenizers (0.4.2) sha256=61c2f254582a3ae69255115b2b072904361003612b5b0f52aa64773817aae413 discourse_dev_assets (0.0.6) sha256=4dfe7946927aa3d61a4ba89b5aef39d6daaeb70e35d7125dc481806a5c0aea4e discourse_math_bundle (1.0.1) sha256=c7d82fa65c9680cab2f77daeba32c1b89e500faccd2269e050ab27d5e1bc8337 - docile (1.4.1) sha256=96159be799bfa73cdb721b840e9802126e4e03dfc26863db73647204c727f21e + discourse_voice_assets (0.1.0) sha256=67bfbc3e9eaa1805e71ac3c5e2172d8beefdecbfa7b956ed5426e7e057c10cc2 drb (2.2.3) sha256=0b00d6fdb50995fe4a45dea13663493c841112e4068656854646f418fda13373 dry-initializer (3.2.0) sha256=37d59798f912dc0a1efe14a4db4a9306989007b302dcd5f25d0a2a20c166c4e3 ed25519 (1.4.0) sha256=16e97f5198689a154247169f3453ef4cfd3f7a47481fde0ae33206cdfdcac506 - email_reply_trimmer (0.2.0) sha256=05843fa5ee1a2037235f1f3c876e922f613e2b4406fea5bb14212d1708d6c525 - erb (6.0.4) sha256=38e3803694be357fe2bfe312487c74beaf9fb4e5beb3e22498952fe1645b95d9 + email_reply_trimmer (0.4.0) sha256=cdb8e90649f0d3972c17392063af052e337d13902f5a33a04fac900d544f8f57 + erb (6.0.7) sha256=c5ca6dc25b0ef974a44dc8f59fe847577122483b1968a38dec305c60bf91ee92 erubi (1.13.1) sha256=a082103b0885dbc5ecf1172fede897f9ebdb745a4b97a5e8dc63953db1ee4ad9 - excon (1.5.0) sha256=c503ad1d0123bc8ab2a062ff3789dc891ec368cb9e13765ab88a9c58c8bb6d50 + excon (1.7.1) sha256=dd2d870eece1b5ce4e4f9efd938e67a69ccd8c003c3825b638b937e1082eaac2 exifr (1.5.1) sha256=ad87a5dbc92946fbf1d8ccd178d557d95d9168e8b3c5c5f381ea2bffcc312521 - extralite-bundle (2.14) sha256=906c6e61dba586d6a0857e96ba985eef458ecd1b5ee009c8495c2c92ce6f18f4 + extralite-bundle (3.0.1) sha256=49b9b6d459b194b44519d80936d6a98a9e54522e34a8a725fd4e81fdb3944aac fabrication (3.0.0) sha256=a6a0bfad9071348ad3cb1701df788524b888c0cdd044b988893e7509f7463be3 faker (3.5.3) sha256=b961482dc0bb15ccb9a98ea7878b925669e9ae8f5e59b607da540b768137d765 faraday (2.14.3) sha256=1882247e6766615c8220b4392bf1d27f6ebb63d8e28267587cef1fb0bf37f278 @@ -1096,15 +1110,15 @@ CHECKSUMS fiber-local (1.1.0) sha256=c885f94f210fb9b05737de65d511136ea602e00c5105953748aa0f8793489f06 fiber-storage (1.0.1) sha256=f48e5b6d8b0be96dac486332b55cee82240057065dc761c1ea692b2e719240e1 fspath (3.1.2) sha256=b5ac9bafb97e2c8f8f9e303cd98ebd484be76fe9aa588bc4d01c6d99e78c9d75 - globalid (1.3.0) sha256=05c639ad6eb4594522a0b07983022f04aa7254626ab69445a0e493aa3786ff11 + globalid (1.4.0) sha256=037f12fbf1d9d7a014d501c2d5c77356fd4ddd96d7a7991d6700bba96706f427 goldiloader (6.0.0) sha256=613db1b28e9964291255a67a521f04d481b6afd6b9ca56ea1a612fd86e9a89c7 - google-protobuf (4.35.0) sha256=95346162c792ed78c9a28cbf2d937a53f706de6df36a27471582f63f03c30c0d - google-protobuf (4.35.0-aarch64-linux-gnu) sha256=2cabd61b420918aec1564f9f7414e455bf922d20c5f8139d62783df5558a7aea - google-protobuf (4.35.0-aarch64-linux-musl) sha256=f6b11f3420a4564f68e8233c95eac6924f6a727dfc2f81a56af2e09add551501 - google-protobuf (4.35.0-arm64-darwin) sha256=66ab26d3fc82b8950702e53ab16c198e3c0ea3f2a38aaaf1f32152da45593ac5 - google-protobuf (4.35.0-x86_64-darwin) sha256=05eb5c8bc9899135befff496fc0a3642e7ff3d0943f043841dcc456f5654fea0 - google-protobuf (4.35.0-x86_64-linux-gnu) sha256=999226f3b00cd9fddb1b26851d16060212fa1d90c406aaad47e574682b716059 - google-protobuf (4.35.0-x86_64-linux-musl) sha256=be0218520d77b2aee898b363514b03819f6f63f9c041ae0d0d79b4ce5247bffd + google-protobuf (4.36.1) sha256=893ac9d66b36b6ea50da5418f856bc7c2d2072099a578aeefc2d7757dcab6a77 + google-protobuf (4.36.1-aarch64-linux-gnu) sha256=3883fa1b0e99221f68f4a8511bc4fb1888897dcb6cc8bf2805c92c16fc99b499 + google-protobuf (4.36.1-aarch64-linux-musl) sha256=6da393554ecc96168ae6ddf663392bf8ce4e4fce7c18fda348882ce2e97d6a87 + google-protobuf (4.36.1-arm64-darwin) sha256=4d82184f4582dfa123f9793cd7a73beca9b0d3f0d3717948c4120b6cc0d50f2d + google-protobuf (4.36.1-x86_64-darwin) sha256=e92bf3c90c0a9c410cbe430cf366190b1b9b5b2b784f6195a43a178c2ef7e338 + google-protobuf (4.36.1-x86_64-linux-gnu) sha256=e735a3f3d6596b1010013c2030778bc030770e659106fe7e4ae0f07631b551cb + google-protobuf (4.36.1-x86_64-linux-musl) sha256=ae2712b7960e8b1f96d52fef8c2c0dc1cd230f2be13e48492dad0aa2a6a7cf03 guess_html_encoding (0.0.11) sha256=cab6468b945f38673fc41ad147fbbc89693b3c6c34b03b071e2ed669a603e098 hana (1.3.7) sha256=5425db42d651fea08859811c29d20446f16af196308162894db208cac5ce9b0d hashdiff (1.2.1) sha256=9c079dbc513dfc8833ab59c0c2d8f230fa28499cc5efb4b8dd276cf931457cd1 @@ -1118,17 +1132,17 @@ CHECKSUMS image_size (3.6.0) sha256=1b9c4196cb658bf503a887920543a3991e927a4b767a5c770fb9665bce0dcb28 in_threads (1.6.0) sha256=91a7e6138d279dc632f59b8a9a409e47148948e297c0f69c92f9a2479a182149 inflection (1.0.0) sha256=ceba9b26fc28b9af82e33e822d28f78a4312af75687efec81d5ef1062498d355 - io-console (0.8.2) sha256=d6e3ae7a7cc7574f4b8893b4fca2162e57a825b223a177b7afa236c5ef9814cc + io-console (0.9.2) sha256=efa74f891dd03c0939a931dfc6e74c2813d904763d456ea9762b0525e748db08 irb (1.18.0) sha256=de9454a0703a54704b9811a5ef31a60c86949fbf4013fcf244fabc7c775248e3 iso8601 (0.13.0) sha256=298c2b15b7be5fa95a1372813d36a2257656cd8e906dfbc1f5cb409851425aa2 jmespath (1.6.2) sha256=238d774a58723d6c090494c8879b5e9918c19485f7e840f2c1c7532cf84ebcb1 - json (2.19.9) sha256=9b9025b7cdddafa38d316eca0b2358488e42d417045c1b90d216a9fefe46b79a + json (2.21.2) sha256=1f1d3b7cf2b3ba1a69beca0bb6db13d5438b80bff3cd54cdaaa620b9b07c1c6a json-schema (6.2.0) sha256=e8bff46ed845a22c1ab2bd0d7eccf831c01fe23bb3920caa4c74db4306813666 json_completer (1.2.0) sha256=4665749172634eccb208c562eb59ea81dd7a612a1fa9a36df441ac473ff177b1 json_schemer (2.5.0) sha256=2f01fb4cce721a4e08dd068fc2030cffd0702a7f333f1ea2be6e8991f00ae396 - jwt (2.10.1) sha256=e6424ae1d813f63e761a04d6284e10e7ec531d6f701917fadcd0d9b2deaf1cc5 - landlock (0.4.1) sha256=95c9b119ff831fae35756ddcd5e9d5f99b9705be71f37a0972f86c825b78b14f - language_server-protocol (3.17.0.5) sha256=fd1e39a51a28bf3eec959379985a72e296e9f9acfce46f6a79d31ca8760803cc + jwt (3.2.0) sha256=5419b1fe37b1da0982bd07051f573a8b8789ab724c2aa7e785e4784a3ed217d7 + landlock (0.5.1) sha256=4c66c5ea238ce0fb4dbf0ea8697da3af01f396f86b34f1f5c323969bc524eba0 + language_server-protocol (3.17.0.6) sha256=5ef2c0c138f8267e1bc631d3328347d354f96724b0af22f2c79516120443b7f0 libv8-node (24.12.0.1) sha256=d93d23b861bfe5de3ba829e34a142402fb83b4c3592dd58d9ac4e027588d739a libv8-node (24.12.0.1-aarch64-linux) sha256=22bd0246cde85d70c88cf772727ac3677a20ac1d169105f82efe5f1f7c39f755 libv8-node (24.12.0.1-aarch64-linux-musl) sha256=791b5960f79525e87d1bd1e5f2bf3715ef2a38bac6c97f297853e98a8411ba89 @@ -1141,18 +1155,18 @@ CHECKSUMS listen (3.10.0) sha256=c6e182db62143aeccc2e1960033bebe7445309c7272061979bb098d03760c9d2 literate_randomizer (0.4.0) sha256=05073c9b383983b1ed7e26c40b963468e91bc86e663b3eeff3a4af91b84217b1 logger (1.7.0) sha256=196edec7cc44b66cfb40f9755ce11b392f21f7967696af15d274dde7edff0203 - lograge (0.14.0) sha256=42371a75823775f166f727639f5ddce73dd149452a55fc94b90c303213dc9ae1 + lograge (0.15.0) sha256=34072c1f50b95019dc185137f5fec1a6759f5a1b6d55c28163d0cba204e6df16 logstash-event (1.2.02) sha256=89a7dc60fac67070a5f60ba07409e541b09cb58906c391e90cb74b9f217467ae logster (2.21.0) sha256=5edc71ea98d5f89fe081556893f77b7c4d2617341dae7d421fc37539cfb13a02 - loofah (2.25.1) sha256=d436c73dbd0c1147b16c4a41db097942d217303e1f7728704b37e4df9f6d2e04 + loofah (2.25.2) sha256=2007f746959ac65552456e04b433e83deb22759ab38c838b4445c70e43425918 lru_redux (1.1.0) sha256=ee71d0ccab164c51de146c27b480a68b3631d5b4297b8ffe8eda1c72de87affb lz4-ruby (0.3.3) sha256=011be5ee230cfddc8308d4e2e0b05300c7bc755a887de799377ca6c5b6aede89 - mail (2.9.0) sha256=6fa6673ecd71c60c2d996260f9ee3dd387d4673b8169b502134659ece6d34941 + mail (2.9.1) sha256=06574eca475253d6c18145dd70af80d0eb970182d55053497c5f4d797ea160e8 markbridge (0.4.0) sha256=27645fd47489d2fd42068153fa471b7e5231dd8dabb31c1bf38c88aa37535b12 matrix (0.4.3) sha256=a0d5ab7ddcc1973ff690ab361b67f359acbb16958d1dc072b8b956a286564c5b maxminddb (0.1.22) sha256=50933be438fbed9dceabef4163eab41884bd8830d171fdb8f739bee769c4907e memory_profiler (1.1.0) sha256=79a17df7980a140c83c469785905409d3027ca614c42c086089d128b805aa8f8 - message_bus (4.5.2) sha256=f1381bce05d9560e5ea7dfa56e44dfdf0080bda0ac02f4011eb662bb7dd9e778 + message_bus (5.0.0) sha256=9bbb413b8103140885172db6d0674a2eb95c18c98faca0acfdc1126ec5a4c0cf messageformat-wrapper (1.1.0) sha256=ecea879626e412d1bc841c457dacfcbb1a62cf88ca83573e4ea34bb371f160bc method_source (1.1.0) sha256=181301c9c45b731b4769bc81e8860e72f9161ad7d66dd99103c9ab84f560f5c5 migrations-converters (0.0.1) @@ -1160,55 +1174,54 @@ CHECKSUMS migrations-importer (0.0.1) migrations-tooling (0.0.1) mime-types (3.7.0) sha256=dcebf61c246f08e15a4de34e386ebe8233791e868564a470c3fe77c00eed5e56 - mime-types-data (3.2026.0414) sha256=461c4c655373a44bd6c5fe54bcf5b7776026ea96e808144b1ec465c4b99148cc + mime-types-data (3.2026.0701) sha256=cd8811e1fb89d836499ba0582368a10ee74cef929ba956d1d5ddca045e6a730f mini_mime (1.1.5) sha256=8681b7e2e4215f2a159f9400b5816d85e9d8c6c6b491e96a12797e798f8bccef mini_portile2 (2.8.9) sha256=0cd7c7f824e010c072e33f68bc02d85a00aeb6fce05bb4819c03dfd3c140c289 - mini_racer (0.22.0) sha256=52e4c1797bcb01be550d8317764ac5ca8aa96b37f8f72dec6e090db99847ae30 + mini_racer (0.22.1) sha256=c0a7baa4035fe57488bf9856bdafb657c99997cbe0441b1838cfd886fe21518a mini_scheduler (0.20.0) sha256=bd8948228bf4a48a603a8e20de850d16b68295413d8651c8c05288f4c6997b05 mini_sql (1.6.0) sha256=5296637f6a4af5bb43e06788037e9a2968ff9c8eb65928befcba8cb41f42d6ee mini_suffix (0.3.3) sha256=8d1d33f92f69a2247c9b7d27173235da90479d955cdb863b63a7f53843b722e7 - minio_runner (1.1.0) sha256=ebb2bedea253011fcd34ed3229706c9b453f0f363601dee7ce065e0163bdcf2f minitest (6.0.6) sha256=153ea36d1d987a62942382b61075745042a2b3123b1cd48f4c3675af9cc7d6f1 mocha (3.1.0) sha256=75f42d69ebfb1f10b32489dff8f8431d37a418120ecdfc07afe3bc183d4e1d56 - msgpack (1.8.3) sha256=8bda4a6428d3244e50d6bd55854d354edbada88a4e1f4f5731a39a0f86bee6a1 - multi_json (1.20.1) sha256=2f3934e805cc45ef91b551a1f89d0e9191abd06a5e04a2ef09a6a036c452ca6d + msgpack (1.8.4) sha256=4411c22d350dd1c20250f7eada3cca2695438c2f769cf0782f0cd065d90a3e7b + multi_json (1.21.1) sha256=e6126a31808e3b4d19f483c775ceac34df190dffa62adfb63a165ee14ba68080 multi_xml (0.9.1) sha256=7ce766b59c17241ed62976caeae1fae9b2431b263398c35396239a68c4a64e57 multipart-post (2.4.1) sha256=9872d03a8e552020ca096adadbf5e3cb1cd1cdd6acd3c161136b8a5737cdb4a8 - mustache (1.1.2) sha256=d420243400354da78ded2d81541b381ad8d94e8e9b95022d0d71d66f8ef36c00 + mustache (1.1.3) sha256=75bdfeaa17e4af168fae2c262867b2992087aef39d8580965cb90d37a7d093c2 net-http (0.9.1) sha256=25ba0b67c63e89df626ed8fac771d0ad24ad151a858af2cc8e6a716ca4336996 - net-imap (0.6.4.1) sha256=29f0360d75a7efd3539f16ac1957dea5c0a51ddeceb348db4553c3120914ea0d + net-imap (0.6.6) sha256=96aa4ee50df3060203e649efc341f53480b791d49e150f2fdebf68beb141a8df net-pop (0.1.2) sha256=848b4e982013c15b2f0382792268763b748cce91c9e91e36b0f27ed26420dff3 - net-protocol (0.2.2) sha256=aa73e0cba6a125369de9837b8d8ef82a61849360eba0521900e2c3713aa162a8 + net-protocol (0.3.0) sha256=ba310c3d4f1cad46bb1ab20336b06669b1ff8f7c568d9cb9342b32a718547472 net-smtp (0.5.1) sha256=ed96a0af63c524fceb4b29b0d352195c30d82dd916a42f03c62a3a70e5b70736 nio4r (2.7.5) sha256=6c90168e48fb5f8e768419c93abb94ba2b892a1d0602cb06eef16d8b7df1dca1 - nokogiri (1.19.3) sha256=78312cbac32a40c812780d9678221b79d51288eec00054c1a8d15f7ce05960e8 - nokogiri (1.19.3-aarch64-linux-gnu) sha256=46b89e5d7b9e844c2ee360794240c6ea2a4e6fa0c5892a4ed487db621224b639 - nokogiri (1.19.3-aarch64-linux-musl) sha256=8392dfdcd21be7a94dbbe9ccc138dea01b97b24cb2dc02a114ca98bfb1d9a0b7 - nokogiri (1.19.3-arm64-darwin) sha256=71b9bd424b1b7abc18b05052a1a3cfd3627abdca62be280854cc411791357e42 - nokogiri (1.19.3-x86_64-darwin) sha256=77f3fba57d46c53ab31e62fc6c28f705109d1bf6264356c76f132b2be5728d4d - nokogiri (1.19.3-x86_64-linux-gnu) sha256=2f5078620fe12e83669b5b17311b32532a8153d02eee7ad06948b926d6080976 - nokogiri (1.19.3-x86_64-linux-musl) sha256=248c906d2166eca5efb56d52fdee5f9a1f51d69a72e2b64fdac647b4ce39ea3f - oauth (1.1.5) sha256=0ec467908f5819a54d1659d33e8bb520e8475cc87a452d6ecfaa5db351999cca - oauth-tty (1.0.8) sha256=d9a63b67af17c22517f868c59f12178e4ee19a367536d1a6dcb74d9d07a41e07 - oauth2 (1.4.11) sha256=6739fcc8872bc94f476b0cae3e8bd78a56d8364b1b79b0757794c25e152d5c10 + nokogiri (1.19.4) sha256=50c951611c92bca05c51411aef45f1cbc50f2821c4802758c5c6d34696533ab5 + nokogiri (1.19.4-aarch64-linux-gnu) sha256=1269fb644a6de405057a53dd5c762b1209b43ca7424f839454d3dbc677c31a8f + nokogiri (1.19.4-aarch64-linux-musl) sha256=35c65b9ce72b3bb03207bdbe7067915019dc18c1b9b59139684bd6690fdd01af + nokogiri (1.19.4-arm64-darwin) sha256=a46db9853286e6597b36ebc6953817d15acf3a299583eb3f89fdc6f91dd63527 + nokogiri (1.19.4-x86_64-darwin) sha256=7fd17057d3e1f00e9954a74b3cd76595d3d4a5ef233b7ed9599047c204f70551 + nokogiri (1.19.4-x86_64-linux-gnu) sha256=379fae440b28915e3f19d752ce2dcf8465ed2b2fbefd2a7ca0dd497bc981a06a + nokogiri (1.19.4-x86_64-linux-musl) sha256=17dfb7c1fa194ae02fbf7c51a7afc8d278045ab3fdacfd86f91d02d7b274470b + oauth (1.1.8) sha256=7bf0b774391af4f820a86ce2cc7fa38c3fad5121b5563592535cff4b2e16d50e + oauth-tty (1.0.13) sha256=71ad5f93ceea6fd21fe9a731dc02a4b892c5de9d77e0b303e81bd73f9daeb4a3 + oauth2 (2.0.25) sha256=2f736a2f93c2caa67c1b08dc3c9889bb907d62643f3183fefaa1723cba6a82ac octokit (10.0.0) sha256=82e99a539b7637b7e905e6d277bb0c1a4bed56735935cc33db6da7eae49a24e8 - oj (3.16.12) sha256=ad9fad6a06dabcf4cfe6a420690a4375377685c16eee0ae88e8d38a43ed7b556 + oj (3.17.6) sha256=f511257e01a12030c3ceb8023cd2e96fca924ea9c741f57ea366816f1fd8e68c omniauth (2.1.2) sha256=def03277298b8f8a5d3ff16cdb2eb5edb9bffed60ee7dda24cc0c89b3ae6a0ce omniauth-facebook (10.0.0) sha256=dfdc6cbada5387572d554784861546cf6382f9fa16c4731cbe5813e570fcb9e1 - omniauth-github (2.0.0) sha256=1ca26576125a97e27d3f8dc39cd98853d7382dd0fc04a40d3b9ec345ee378649 - omniauth-google-oauth2 (1.0.1) sha256=2ed7a4ac8d98ab824c95e0d6760784abf1248262b3ba2ab56ec7ebd7074d12a6 + omniauth-github (2.0.1) sha256=8ff8e70ac6d6db9d52485eef52cfa894938c941496e66b52b5e2773ade3ccad4 + omniauth-google-oauth2 (1.2.3) sha256=bdbab67e64e50b7902eee2dcfc2225575cefba15ab89a3b6e92c8947987c1da9 omniauth-oauth (1.2.1) sha256=25bf22c90234280fa825200490f03ff1ce7d76f1a4fbd6c882c6c5b169c58da8 - omniauth-oauth2 (1.7.3) sha256=3f5a8f99fa72e0f91d2abd7475ceb972a4ae67ed59e049f314c0c1bad81f4745 - omniauth-twitter (1.4.0) sha256=c5cc6c77cd767745ffa9ebbd5fbd694a3fa99d1d2d82a4d7def0bf3b6131b264 - openssl (3.3.2) sha256=7f4e01215dc9c4be1fca71d692406be3e6340b39c1f71a47fea9c497decd0f6c + omniauth-oauth2 (1.9.0) sha256=ed15f6d9d20991807ce114cc5b9c1453bce3645b64e51c68c90cff5ff153fee8 + omniauth-twitter (1.5.0) sha256=f7d488524113b2f654e1d7f722790dc03d92102cb7c947331ad2d68340a362e3 + openssl (4.0.2) sha256=1037ad2868ae58df9ad917891c0c0f9815a1172f6846d4bcdd508e4c2ee747c2 openssl-signature_algorithm (1.3.0) sha256=a3b40b5e8276162d4a6e50c7c97cdaf1446f9b2c3946a6fa2c14628e0c957e80 optimist (3.2.1) sha256=8cf8a0fd69f3aa24ab48885d3a666717c27bc3d9edd6e976e18b9d771e72e34e ostruct (0.6.3) sha256=95a2ed4a4bd1d190784e666b47b2d3f078e4a9efda2fccf18f84ddc6538ed912 parallel (2.1.0) sha256=b35258865c2e31134c5ecb708beaaf6772adf9d5efae28e93e99260877b09356 parallel_tests (5.7.0) sha256=3f1762c46ca2c223b8af8ef877217f9d76974e191bfa934f2580b58bcf1d005c - parser (3.3.11.1) sha256=d17ace7aabe3e72c3cc94043714be27cc6f852f104d81aa284c2281aecc65d54 + parser (3.3.12.0) sha256=21a6d7f755d5a24dfbdc6e6b772e4e879a52e7631a88bc5a3a134606052c9828 pastel (0.8.0) sha256=481da9fb7d2f6e6b1a08faf11fa10363172dc40fd47848f096ae21209f805a75 - pdf-reader (2.15.1) sha256=18c6a986a84a3117fa49f4279fc2de51f5d2399b71833df5d2bccd595c7068ce + pdf-reader (2.16.0) sha256=bf1b5564c085264d8279bde3cf1467778b75841494d20c0fe7da3dad475f3732 pg (1.6.3) sha256=1388d0563e13d2758c1089e35e973a3249e955c659592d10e5b77c468f628a99 pg (1.6.3-aarch64-linux) sha256=0698ad563e02383c27510b76bf7d4cd2de19cd1d16a5013f375dd473e4be72ea pg (1.6.3-aarch64-linux-musl) sha256=06a75f4ea04b05140146f2a10550b8e0d9f006a79cdaf8b5b130cde40e3ecc2c @@ -1217,8 +1230,8 @@ CHECKSUMS pg (1.6.3-x86_64-linux) sha256=5d9e188c8f7a0295d162b7b88a768d8452a899977d44f3274d1946d67920ae8d pg (1.6.3-x86_64-linux-musl) sha256=9c9c90d98c72f78eb04c0f55e9618fe55d1512128e411035fe229ff427864009 pitchfork (0.18.2) sha256=95d0b5a25792ebc94d627abd8a206652ff22acff1cc32ecd42c71669ead4ab94 - playwright-ruby-client (1.60.0) sha256=942242d6130e797b21213d9c49dc09d31235cab429a9edae73401ed112c94853 - pp (0.6.3) sha256=2951d514450b93ccfeb1df7d021cae0da16e0a7f95ee1e2273719669d0ab9df6 + playwright-ruby-client (1.62.0) sha256=44eb6051ab7987f68a1288a7db7892403e59680116739987729c5fecfdb55715 + pp (0.6.4) sha256=dfcb0fce700c41456265922884f9fe195d7fbb0674a3578e6c0f69588e82b570 prettier_print (1.2.1) sha256=a72838b5f23facff21f90a5423cdcdda19e4271092b41f4ea7f50b83929e6ff9 prettyprint (0.2.0) sha256=2bc9e15581a94742064a3cc8b0fb9d45aae3d03a1baa6ef80922627a0766f193 prism (1.9.0) sha256=7b530c6a9f92c24300014919c9dcbc055bf4cdf51ec30aed099b06cd6674ef85 @@ -1226,21 +1239,20 @@ CHECKSUMS propshaft (1.3.2) sha256=1d56a3e56a92c21bfc29caf07406b5386b00d4c47ddf357cf989a5a234b1389e pry (0.16.0) sha256=d76c69065698ed1f85e717bd33d7942c38a50868f6b0673c636192b3d1b6054e pry-rails (0.3.11) sha256=a69e28e24a34d75d1f60bcf241192a54253f8f7ef8a62cba1e75750a9653593d - psych (5.4.0) sha256=14f72d69a611af663d7d70e4a7b67d9eb1f3ae9f8d916b478961d5a0075ba5b7 public_suffix (7.0.5) sha256=1a8bb08f1bbea19228d3bed6e5ed908d1cb4f7c2726d18bd9cadf60bc676f623 puma (8.0.2) sha256=c8ed871dfbbe66448ea9ffd46692342d9804d4071522b52b5331b7b6e7b686fb racc (1.8.1) sha256=4a7f6929691dbec8b5209a0b373bc2614882b55fc5d2e447a21aaa691303d62f - rack (2.2.23) sha256=a8fe9d7e07064770b8ec123663fded8a59ef7e2b6db5cda7173d45a5718ab69c - rack-mini-profiler (4.0.1) sha256=485810c23211f908196c896ea10cad72ed68780ee2998bec1f1dfd7558263d78 + rack (2.2.24) sha256=ef16526a0d871c43753452338c754040a664c8b41bf0dd7450b85f7772adca5f + rack-mini-profiler (5.0.0) sha256=99c5ba087fa91c8d9ba80a43f6b2213f1ebead6e863d49286170129d391302e1 rack-protection (3.2.0) sha256=3c74ba7fc59066453d61af9bcba5b6fe7a9b3dab6f445418d3b391d5ea8efbff rack-session (1.0.2) sha256=a02115e5420b4de036839b9811e3f7967d73446a554b42aa45106af335851d76 rack-test (2.2.0) sha256=005a36692c306ac0b4a9350355ee080fd09ddef1148a5f8b2ac636c720f5c463 rackup (1.0.1) sha256=ba86604a28989fe1043bff20d819b360944ca08156406812dca6742b24b3c249 rails-dom-testing (2.3.0) sha256=8acc7953a7b911ca44588bf08737bc16719f431a1cc3091a292bca7317925c1d - rails-html-sanitizer (1.7.0) sha256=28b145cceaf9cc214a9874feaa183c3acba036c9592b19886e0e45efc62b1e89 + rails-html-sanitizer (1.7.1) sha256=e797a7c9b01e567307e317c576b49ab4168017e63eea4dba9ce3cb587e2f22c2 rails_failover (2.3.0) sha256=eed6ea0674fd6f9f6b070ad297ad2ead121ecf9202920f6068b6a4f29d9491c9 - rails_multisite (7.0.0) sha256=7aacf364ed86d2bee73fb679cbfe6c343ce89067b9746b3d5857fffc57f036f2 - railties (8.0.5.1) sha256=da1958e1d9dab04691a2f8721b3ff7fab323715d37f103c19972dedfd644d5c7 + rails_multisite (9.0.0) sha256=2bc88f0405cb88d1055712095a11c4eb8ce1d4a36599d1226c6779946be495e6 + railties (8.1.3.1) sha256=2388a232579a00cefea4487de66c8553c3408c1300abdc6cf1799d86ffb04487 rainbow (3.1.1) sha256=039491aa3a89f42efa1d6dec2fc4e62ede96eb6acd95e52f1ad581182b79bc6a raindrops (0.20.1) sha256=aa0eb9ff6834f2d9e232ba688bd49cb30be893bc5a3452e74722c94c1fab4730 rake (13.4.2) sha256=cb825b2bd5f1f8e91ca37bddb4b9aaf345551b4731da62949be002fa89283701 @@ -1248,21 +1260,21 @@ CHECKSUMS rb-fsevent (0.11.2) sha256=43900b972e7301d6570f64b850a5aa67833ee7d87b458ee92805d56b7318aefe rb-inotify (0.11.1) sha256=a0a700441239b0ff18eb65e3866236cd78613d6b9f78fea1f9ac47a85e47be6e rb_sys (0.9.130) sha256=7d486d99c1da02635515deaf9860fc5aea90bb4ab2589b2deec7fdc7d3548615 - rbs (4.0.2) sha256=af75671e66cd03434cc546622741ebf83f6197ec4328375805306330bf78ef25 - rbtrace (0.5.4) sha256=8279e40076530f0301e255d0669cfe0d7d31ef872d1ae475c486e5a1199b757b - rchardet (1.10.2) sha256=e041cb195f464dc10e49ab130f78c8b5956cd9a4f4f6df84e0c183b87c135f33 - rdoc (7.2.0) sha256=8650f76cd4009c3b54955eb5d7e3a075c60a57276766ebf36f9085e8c9f23192 + rbs (4.2.0) sha256=51f7b886dcc05bc09e10b901daa6a81829f6adc03101d6ca9ea4aac6103e0674 + rbtrace (0.5.5) sha256=ed0200ffeac4251f3464412e52f36cd64c473673c2739129e0b48c568672fe68 + rdoc (8.0.0) sha256=03bf8c08a9639658855a0cfd77c0abca8325c227693f7f33f82957811348c469 redcarpet (3.6.1) sha256=d444910e6aa55480c6bcdc0cdb057626e8a32c054c29e793fa642ba2f155f445 - redis (5.4.0) sha256=798900d869418a9fc3977f916578375b45c38247a556b61d58cba6bb02f7d06b - redis-client (0.30.0) sha256=743f11ed42f0a41a0341554087b077479fec7e2d47a7c123fd90a12c0db5e477 + redis (6.0.0) sha256=de71c10edd106986b759ec7ecdd08b63b9c0ee7414a0d0c1da73d31ba2bccda6 + redis-client (0.30.1) sha256=5151bc5c7bbfe48623732cdae3b900d8a22dc691cc7cdfacfb351ac55116522d redis-namespace (1.11.0) sha256=e91a1aa2b2d888b6dea1d4ab8d39e1ae6fac3426161feb9d91dd5cca598a2239 regexp_parser (2.12.0) sha256=35a916a1d63190ab5c9009457136ae5f3c0c7512d60291d0d1378ba18ce08ebb - reline (0.6.3) sha256=1198b04973565b36ec0f11542ab3f5cfeeec34823f4e54cebde90968092b1835 + reline (0.7.0) sha256=5b012d8e55dbf9d450f12bde2cf7d15ff546ae80b3f8f3b30e570d431815583d request_store (1.7.0) sha256=e1b75d5346a315f452242a68c937ef8e48b215b9453a77a6c0acdca2934c88cb + reverse_markdown (3.0.2) sha256=818ebb92ce39dbb1a291690dd1ec9a6d62530d4725296b17e9c8f668f9a5b8af rexml (3.4.4) sha256=19e0a2c3425dfbf2d4fc1189747bdb2f849b6c5e74180401b15734bc97b5d142 rinku (2.0.6) sha256=8b60670e3143f3db2b37efa262971ce3619ec23092045498ef9f077d82828d7d rotp (6.3.0) sha256=75d40087e65ed0d8022c33055a6306c1c400d1c12261932533b5d6cbcd868854 - rouge (5.0.0) sha256=e2de9bba2f9cb88f8a73bca3643b560b2b398f32f91bf716f584477bc0175ebc + rouge (5.1.0) sha256=b77c632842ab7f5147940212f0345808cccfbce864fd5b631d7d12a35ac85452 rqrcode (3.2.0) sha256=64c1494ca6bb67d731330f38b50e3fd09eeab4f5dcd04b608e21218d1d0b9542 rqrcode_core (2.1.0) sha256=f303b85df89c1b8fc5ee8dc19808c9dc4330e6329b660d99d4a8cbb36ca13051 rrule (0.8.0) sha256=abb19a334efe441879012de9c2f5589372a20097a63a70f5ff9d3b0b4504a4f2 @@ -1277,67 +1289,65 @@ CHECKSUMS rss (0.3.3) sha256=37ef1ec4d691d67edbe92159079a4e89a0965e6a6b32246009ae3d734d12d1ab rswag-specs (2.17.0) sha256=a3b2bdf6df89f8741fe4a4ee47ceb1e77dc13e1c96bbe07352117d6e61afa9e3 rtlcss (0.2.1) sha256=213d5a00bf61267f93a7a516d699d77e1cc5f396743abb33c01e3f3243a7bf60 - rubocop (1.86.1) sha256=44415f3f01d01a21e01132248d2fd0867572475b566ca188a0a42133a08d4531 - rubocop-ast (1.49.1) sha256=4412f3ee70f6fe4546cc489548e0f6fcf76cafcfa80fa03af67098ffed755035 - rubocop-capybara (2.23.0) sha256=f9ea1ba3a7561ee8e88cf76fc378ce517ce5327155f305ee7b5c2500e5aee357 - rubocop-discourse (3.18.0) sha256=bdb31f13cbb1ed82443b5a53b36efbce3b52a77b7a0f3ee7b421ce81d937ce0b + rubocop (1.91.0) sha256=9c82b7bf391c5d7e3798c5b9996e22a1fe3bd7468e351dfdeb96140c058296d0 + rubocop-ast (1.50.0) sha256=b9ca88300da0803ee222ad20cdb30494c0a784eed06fdc35d254b06d662788db + rubocop-capybara (3.0.0) sha256=7a64655238acda7f8f3c87e37ac825a64c615a79c17c253f1a28270dc3768c4b + rubocop-discourse (3.20.0) sha256=47086bcf9b937e469398e82615fc4a6b86bd40df73bf85611a9109a83a1e9c70 rubocop-discourse-base (1.0.0) sha256=a4121f0f2a8e32c3259fee22106af9fd35372cbeac14b0c69673bdee79b472b7 rubocop-factory_bot (2.28.0) sha256=4b17fc02124444173317e131759d195b0d762844a71a29fe8139c1105d92f0cb - rubocop-rails (2.34.3) sha256=10d37989024865ecda8199f311f3faca990143fbac967de943f88aca11eb9ad2 - rubocop-rspec (3.9.0) sha256=8fa70a3619408237d789aeecfb9beef40576acc855173e60939d63332fdb55e2 + rubocop-rails (2.37.0) sha256=6e1645add5060e0328f8ddda0d820f55697c591394398bf14bb9dccb62f14b7e + rubocop-rspec (3.10.2) sha256=0b3e2ecc592cd10ecbf0095bb58d1e357905276e069643523cc19eb7495f65e2 rubocop-rspec_rails (2.32.0) sha256=4a0d641c72f6ebb957534f539d9d0a62c47abd8ce0d0aeee1ef4701e892a9100 - ruby-lsp (0.26.9) sha256=33a01c001c00a76b4e821efc04ed7572983430f31ca5d6f3e343d0b6ccab4129 + ruby-lsp (0.26.11) sha256=4cc8f1587237ff8c9031680b5491df901a82559eeaa1ae96863ffe700b32583d ruby-lsp-rails (0.4.8) sha256=f09d1f926d4063deeb2f3049311925c20dfe6c912371e3bcd04a265a865c44ae ruby-lsp-rspec (0.1.29) sha256=798be579723376cd56b17d32373288fb1163e4cfe2024c7d068516a1cf214ee5 ruby-prof (2.0.5) sha256=dbc3b5112089538ac33303145db0cbd77cbdcdbc05b09e44a967ff72a36d6c0e ruby-progressbar (1.13.0) sha256=80fc9c47a9b640d6834e0dc7b3c94c9df37f08cb072b7761e4a71e22cff29b33 ruby-rc4 (0.1.5) sha256=00cc40a39d20b53f5459e7ea006a92cf584e9bc275e2a6f7aa1515510e896c03 ruby-readability (0.7.3) sha256=bd213fab037118cc15d999e167a8ea2cc6b689dc78c033e78fb36a2a37efc241 + ruby-vips (2.3.0) sha256=e685ec02c13969912debbd98019e50492e12989282da5f37d05f5471442f5374 ruby2_keywords (0.0.5) sha256=ffd13740c573b7301cf7a2e61fc857b2a8e3d3aff32545d6f8300d8bae10e3ef - rubyzip (3.3.1) sha256=2ed92112c7c43ba2b2527f35e6d99d9c2c99270b640aad5227516436481b1e4e + rubyzip (3.6.0) sha256=268994d44d62282d1cfd99bf10eae48d7267199158ad7ea3e1fee2da9458b695 samovar (2.5.1) sha256=8a9fc41eb8868084f0321eb41678c485cfbc7d282fb306c0be67c3284b1d2394 sanitize (7.0.0) sha256=269d1b9d7326e69307723af5643ec032ff86ad616e72a3b36d301ac75a273984 - sass-embedded (1.100.0) sha256=b7d4831f304be5ba8717b2a1307644164b63dc158113a67f469e90578d3fc092 - sass-embedded (1.100.0-aarch64-linux-gnu) sha256=c13187f8eaae7e7e64246b18eb896534a84465a17198829ef65730db4662860e - sass-embedded (1.100.0-aarch64-linux-musl) sha256=1b0945a66cd4e40f505db73b1e790e2561e07e6d9fd04ef6ebbf279835666b3f - sass-embedded (1.100.0-arm64-darwin) sha256=d294b32c3b7bed293ad39bd392713c07f1df5454e65fa0f8d80dadbdba8a0cf4 - sass-embedded (1.100.0-x86_64-darwin) sha256=3db80c837a60712de3461d5aa1be43c7056a0584d7182a8ae7a8996d64ab46d3 - sass-embedded (1.100.0-x86_64-linux-gnu) sha256=58dd0a8a4f0dd78881b90d8b0e4d0eed042d54865b19b71384d91091ade93e18 - sass-embedded (1.100.0-x86_64-linux-musl) sha256=03dbee81bf93e770c725caf0c895e04c7b049ebef56b8a7002fcf21e6bedf7c5 - sassc-embedded (1.80.8) sha256=ea62825e4031cc8267e6befd492bcf8e29f11ccc18500f4e8ee9adb7feb6d563 + sass-embedded (1.104.0) sha256=308c7cc890de96d77556d515e5958ba2fcfbc69978496ea2b2f0565dd5869bfd + sass-embedded (1.104.0-aarch64-linux-gnu) sha256=99e2b95e8101928f8976c7a3f7cced5c5e4289ceb8aca0e1dedd9bb13645e417 + sass-embedded (1.104.0-aarch64-linux-musl) sha256=d54f9dc45e753d29a999021f24cfc126b49c61f14bcb8e96209a02288cde22c3 + sass-embedded (1.104.0-arm64-darwin) sha256=b1409415e06931b43c2a498fc430fe8ddbad9706be5bb3c4e20b60c14f56b122 + sass-embedded (1.104.0-x86_64-darwin) sha256=d463b65e6fefcae614352f7a4dcea61d399f35a1238822b38d88471cee954717 + sass-embedded (1.104.0-x86_64-linux-gnu) sha256=7aeaa07beff7db254836599f1524ac7b67216729613ebc57e3828b94345f0488 + sass-embedded (1.104.0-x86_64-linux-musl) sha256=bc14555f68aa7057e923d400726c1623bb603101eef6340962e4e80ee89e67ba + sassc-embedded (1.80.9) sha256=bf90ad875181548646c1dcc317f985471980a7f5a71a87103536a6d3810dfeaa sawyer (0.9.3) sha256=0d0f19298408047037638639fe62f4794483fb04320269169bd41af2bdcf5e41 securerandom (0.4.1) sha256=cc5193d414a4341b6e225f0cb4446aceca8e50d5e1888743fac16987638ea0b1 - shoulda-matchers (7.0.1) sha256=b4bfd8744c10e0a36c8ac1a687f921ee7e25ed529e50488d61b79a8688749c77 + shoulda-matchers (8.0.1) sha256=5dbb46e5765b9da225111b085e0819e8c8a121ff94bba430a153eb1ea2c60288 sidekiq (7.3.10) sha256=781eb4f65ef36042534ad73d72f211283afb7fee82eec786ada4ed1972ef8e3c - simplecov (0.22.0) sha256=fe2622c7834ff23b98066bb0a854284b2729a569ac659f82621fc22ef36213a5 - simplecov-html (0.13.2) sha256=bd0b8e54e7c2d7685927e8d6286466359b6f16b18cb0df47b508e8d73c777246 - simplecov_json_formatter (0.1.4) sha256=529418fbe8de1713ac2b2d612aa3daa56d316975d307244399fa4838c601b428 - simpleidn (0.2.3) sha256=08ce96f03fa1605286be22651ba0fc9c0b2d6272c9b27a260bc88be05b0d2c29 + simplecov (1.1.1) sha256=25825ef13f0b2e74694d769817dad6ab8e90131dabdaa666e522fea105521e78 + simpleidn (0.3.0) sha256=12ca730bed2f3db04d11e9bfd1bca3e11fb37f55b21eb2e9793fb5814bf54d03 smarter_json (1.2.6) sha256=6638a2d23954e26d268212b4c8f5b9871d31b72f3d169371cca1082c1a722b45 - snaky_hash (2.0.4) sha256=2b12758c57defa6796341a1620f84b1a23737421d8d7e2575d0550b53cc4fece - sqlite3 (2.9.5) sha256=04572973a3f943ad50a8adfffc8dd752a5f06e4c3db2026f71838fed8a982606 - sqlite3 (2.9.5-aarch64-linux-gnu) sha256=78075b6337d3d182c6d2b4691049ed45cd220826160c9ea18946bf6a1de200dc - sqlite3 (2.9.5-aarch64-linux-musl) sha256=18c801185deb4adc01ddb281e8f672a39e3d1729979ca91e39439cd3eac0402d - sqlite3 (2.9.5-arm64-darwin) sha256=d0cf444a70fc9395d513cfbcc1e6719e224aa645314e3824cb0474c721425aa2 - sqlite3 (2.9.5-x86_64-darwin) sha256=8e9caae38bd7ebb29cbeee3e7ab1d12dc2327d9a1b92c7fcf0dda05589627a81 - sqlite3 (2.9.5-x86_64-linux-gnu) sha256=233dbcb6714148dd23bc5aeb33e8efd6eac974969564ddd5794c23d5f52b231e - sqlite3 (2.9.5-x86_64-linux-musl) sha256=e7d3a7474e8af0f96150c21abc203fbab5437206bfcdf11deab7741c0ca516f2 + snaky_hash (2.0.7) sha256=7d02c70012a3f932e48860cd024577908300c9aa615e0cb9b450aaa749cbcb4d + sqlite3 (2.9.6) sha256=956fe606956420d04ac7157d3ace620c8caba2135b2e05c76e483493da24d08e + sqlite3 (2.9.6-aarch64-linux-gnu) sha256=d8b1f7d23efd7abac285775a9566562fc7debfef79d594e3a20354406fb7907c + sqlite3 (2.9.6-aarch64-linux-musl) sha256=3579e1c98cdc7ff5c3722847bb63ed4e1efb7ff675cb5e1e48ef2d4da5fb3bc9 + sqlite3 (2.9.6-arm64-darwin) sha256=849b5d7f795e60fe25076d62c72dd722beb45b3850b516ad978d60ee848ec15b + sqlite3 (2.9.6-x86_64-darwin) sha256=b5842fea77781c14da03fa7bc0feb82db03a69e135affcb6f5399cbd2797a5f3 + sqlite3 (2.9.6-x86_64-linux-gnu) sha256=613188ce02f614126ddbc38c5e217ccffd6306d0dcd9adca9764547aa890a634 + sqlite3 (2.9.6-x86_64-linux-musl) sha256=d493b11818a3573387a1d56e1ee8fa00da23a683a7a1cc063e7a0feeed843abf sshkey (3.0.0) sha256=655ba351d6e01a48dfe59d65530af8975c777b8cc57a061770de3228ff2d11cd ssrf_filter (1.5.0) sha256=e03dcdb9d1730d7f6710532a606b3543df2a448a0293ce04a2d995523c5a97f6 stackprof (0.2.28) sha256=4ec2ace02f386012b40ca20ef80c030ad711831f59511da12e83b34efb0f9a04 - stringio (3.2.0) sha256=c37cb2e58b4ffbd33fe5cd948c05934af997b36e0b6ca6fdf43afa234cf222e1 - stripe (11.1.0) sha256=a76e82cc7e4d2433803ca5fbe9453d019df376236f0b9fbcb7f36e6dd327f98d + stripe (19.6.2) sha256=9a614976a25aba0adbef9ce770c1e242b0e7fcb20d61924fed5e79e1e10dd49c strscan (3.1.8) sha256=aae2db611a225559f21ffbb71765c9a4e60fd262534a9ea84f4f11c7f32f679e syntax_tree (6.3.0) sha256=56e25a9692c798ec94c5442fe94c5e94af76bef91edc8bb02052cbdecf35f13d - test-prof (1.6.1) sha256=0332d9c39a7c118ed942b2db582f055d9f24964d150004ec6b964d2fa262499e + test-prof (1.6.3) sha256=027aea17612b2776069820e4209f6b446ece7ad6dc693f4aed0b742bcb3817a1 thor (1.5.0) sha256=e3a9e55fe857e44859ce104a84675ab6e8cd59c650a49106a05f55f136425e73 - tiktoken_ruby (0.0.16) sha256=2bac3503f1830b11f5fbe64ea8b7696f0ba995a721fad2c75b3f76350ae1504d - tiktoken_ruby (0.0.16-aarch64-linux) sha256=014e5ba44b99158916ff57db61d2cb3fdbc6d176644d3f6bbf36a7d36ef9467d - tiktoken_ruby (0.0.16-aarch64-linux-musl) sha256=0519bb7eed1ebe0202c302103e9edf8754e4ea3029f63573c0d0a24649f701aa - tiktoken_ruby (0.0.16-arm64-darwin) sha256=3da6fe850bf920d08c7eb736673f50bc9d08e8f2e17d34904ad3185a73fc9da7 - tiktoken_ruby (0.0.16-x86_64-darwin) sha256=4776d9f6d2f00ec4386260f3ef379347fd2dc375361c750fef7e96b57364c5be - tiktoken_ruby (0.0.16-x86_64-linux) sha256=4d970b8e68a86972ec81799306116480b33a558c06bb4fe0092852280a4b76b2 - tiktoken_ruby (0.0.16-x86_64-linux-musl) sha256=6a0400a7aba9da6146b30af5d7e4375167c5e5a291853ce47768985916c4d183 + tiktoken_ruby (0.0.17) sha256=9e2a8bcd9eab75d8ba5a9aa75234a6134970c13243132d8b46da7f5f36ea27c3 + tiktoken_ruby (0.0.17-aarch64-linux) sha256=73c1b3065e3356274ff7f9f612b80531029d59c6474f6a73c8bae913cd3fd731 + tiktoken_ruby (0.0.17-aarch64-linux-musl) sha256=038e114be72b2cbd9db2e3555a9a153e0638183447cfde9b1561775b7c4119d4 + tiktoken_ruby (0.0.17-arm64-darwin) sha256=3e76e75218864f7315f83969533ddbe3eb0b927c357bd747acd156412ed6c2e9 + tiktoken_ruby (0.0.17-x86_64-darwin) sha256=da7152cee74943f83d066a425f289db6e116ff05b347735fb2fc1035323f5381 + tiktoken_ruby (0.0.17-x86_64-linux) sha256=c5bfe3067b0d0776028be2112a18f9031d69ed250427a575a4a0b51a0507906b + tiktoken_ruby (0.0.17-x86_64-linux-musl) sha256=d5dbae406a95a93cbf638f2a45aed9e71dea7eb987526df0474cf5db33b35de6 timeout (0.6.1) sha256=78f57368a7e7bbadec56971f78a3f5ecbcfb59b7fcbb0a3ed6ddc08a5094accb tokenizers (0.6.4) sha256=7881f2afee7e605dec6be0c382d4bd138622b77263a67ca66f4ef3156e8e8f47 tokenizers (0.6.4-aarch64-linux) sha256=4898a86c726106967a929a318ffaacb7fa99a6cba5b50e3957f80151c0d7789a @@ -1354,23 +1364,23 @@ CHECKSUMS tty-reader (0.9.0) sha256=c62972c985c0b1566f0e56743b6a7882f979d3dc32ff491ed490a076f899c2b1 tty-screen (0.8.2) sha256=c090652115beae764336c28802d633f204fb84da93c6a968aa5d8e319e819b50 tzinfo (2.0.6) sha256=8daf828cc77bcf7d63b0e3bdb6caa47e2272dcfaf4fbfe46f8c3a9df087a829b - tzinfo-data (1.2026.2) sha256=7db0d3d3d53b8d7601fc183fccc8c6d056a3004e14eb59ea995bf6aec4ae10bc + tzinfo-data (1.2026.3) sha256=478fbc5356f13c1004cf8372b1336f3dad4055c96340fc4c881a3738da8cf7f9 unf (0.2.0) sha256=e6bcc2e101d80e3f9459753db747d5926aada1aaaf61e629e93359da9a5b04ab unicode-display_width (3.2.0) sha256=0cdd96b5681a5949cdbc2c55e7b420facae74c4aaf9a9815eee1087cb1853c42 unicode-emoji (4.2.0) sha256=519e69150f75652e40bf736106cfbc8f0f73aa3fb6a65afe62fefa7f80b0f80f uniform_notifier (1.18.0) sha256=4787785556f66f6418486da0f1d78b3239aaff98e2e7938fb05e2062b0ffce9d uri (1.1.1) sha256=379fa58d27ffb1387eaada68c749d1426738bd0f654d812fcc07e7568f5c57c6 useragent (0.16.11) sha256=700e6413ad4bb954bb63547fa098dddf7b0ebe75b40cc6f93b8d54255b173844 - version_gem (1.1.13) sha256=77f3035ac45877cd14610648fec2d23bd8c10fa13dfcf63a588825aa98587260 - web-push (3.0.1) sha256=5b4dd2f2bba3bd8951da6416492fe920a6f203d14d3080f943c5d01c0cc4b18d - webmock (3.26.2) sha256=774556f2ea6371846cca68c01769b2eac0d134492d21f6d0ab5dd643965a4c90 + version_gem (1.1.15) sha256=a73241587b29252e3567e0c818ded80730eb754d43b508f6ce4db22ca9ba27d0 + web-push (3.1.0) sha256=501ab00340c58fb70dabda59f28a86b3cccb0930c6f1f30721b2a5b24de7187d + webmock (3.26.4) sha256=8d8da206d217ebe6968cfb09c77f4533c23074e1432bad865f3994eacbaad50d webrick (1.9.2) sha256=beb4a15fc474defed24a3bda4ffd88a490d517c9e4e6118c3edce59e45864131 wisper (2.0.1) sha256=ce17bc5c3a166f241a2e6613848b025c8146fce2defba505920c1d1f3f88fae6 xpath (3.2.0) sha256=6dfda79d91bb3b949b947ecc5919f042ef2f399b904013eb3ef6d20dd3a4082e yaml-lint (0.1.2) sha256=e3960b171766ae187338a169815e99fe10fcb0d9c22b1c539e8d57e114324c8a - yard (0.9.44) sha256=eb087e9b631ccd887b049f303d489963945452d5e2a7eb49a5a74a7cf6887f28 - zeitwerk (2.8.2) sha256=7212a61311083c604184b1ea2574b9aa05cd14f855a0841c06985cabe9181d12 - zendesk_api (1.38.0.rc1) sha256=9ebe2575d223ed1c0651b2d10df6c010141cda49d524c38532b472f7e8bb3f7a + yard (0.9.45) sha256=52e211493f7cb8a3ebf7e104a25a1e73937a3103092545d34cb88fafebb3dc51 + zeitwerk (2.8.3) sha256=2c85125a8467ce069e20123d1e709a08955c9d29c118c25b46b7b7fafdbb92e5 + zendesk_api (3.1.2) sha256=3f726c133af8ed3518a9e7cfa9015a368617bd210754ed9173d984f12ddcec15 RUBY VERSION ruby 3.4.7p58 diff --git a/pkgs/servers/web-apps/discourse/rubyEnv/gemset.nix b/pkgs/servers/web-apps/discourse/rubyEnv/gemset.nix index 13be53ad0101..61d4903a63a4 100644 --- a/pkgs/servers/web-apps/discourse/rubyEnv/gemset.nix +++ b/pkgs/servers/web-apps/discourse/rubyEnv/gemset.nix @@ -12,10 +12,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "00w4q1p3gwmqgik2mz5bnxp57cpwjxm7i68nyljym28rdvwv7ln3"; + sha256 = "0g64lm550x0sx2ad5sgwmx19jg9acj98hih6q33a00pz50dl9sl8"; type = "gem"; }; - version = "8.0.5.1"; + version = "8.1.3.1"; }; actionpack = { dependencies = [ @@ -37,10 +37,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1sx1r9qp72gygvgr1qaj6w6pd5y8g2mnafadvi6qhs2dhafmqnd5"; + sha256 = "1l13fy0y55h5c5ccm7c94mwfhf6bk5xj83qv1d3izs288lavfk4p"; type = "gem"; }; - version = "8.0.5.1"; + version = "8.1.3.1"; }; actionview = { dependencies = [ @@ -58,10 +58,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0h0lrfwi0lh8y1bcaj0zh1srhqay0hlb02gzqd55qaf2kj5i0aj7"; + sha256 = "1dng2b5bbjm4c1bcpak7q9w4zh71mz2nkknipszl6yy42j28p9id"; type = "gem"; }; - version = "8.0.5.1"; + version = "8.1.3.1"; }; actionview_precompiler = { dependencies = [ "actionview" ]; @@ -94,10 +94,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1038583pm2fd8lcdi57bk01c99cfq4d13jljvmnvqg3c3fi0f90l"; + sha256 = "0jlm75lxj7bjd67jkgclzlrhlm9sj4ywdzngxq6z83ckvxsx538w"; type = "gem"; }; - version = "8.0.5.1"; + version = "8.1.3.1"; }; activemodel = { dependencies = [ "activesupport" ]; @@ -110,10 +110,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "197lvykj2v9j25n2gxwn5z9fpa888mnr5vqaxsivf3f4m4mf76sm"; + sha256 = "124gi0hlvkabkl5fzfn90ylj7gbyg22rv5208k8p3hxf5z705k4r"; type = "gem"; }; - version = "8.0.5.1"; + version = "8.1.3.1"; }; activerecord = { dependencies = [ @@ -130,20 +130,20 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "19zf3qmmbmjq8qmy7vld5xzicwnl82j9h9092zmpaka0rs7rcllj"; + sha256 = "0fs0q1c35k2bh079kj1xbx9pvqx7q2z4k9d32fqgcf29iz1bcbqa"; type = "gem"; }; - version = "8.0.5.1"; + version = "8.1.3.1"; }; activesupport = { dependencies = [ "base64" - "benchmark" "bigdecimal" "concurrent-ruby" "connection_pool" "drb" "i18n" + "json" "logger" "minitest" "securerandom" @@ -159,10 +159,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0447k5nm211n1ghhb8fv55wm450bigr9vjz2i8rwzkzvqj0456ij"; + sha256 = "0xhkhdx8svhaf439y398yixik0snzarnnsy43688p92yy9jqfic5"; type = "gem"; }; - version = "8.0.5.1"; + version = "8.1.3.1"; }; addressable = { dependencies = [ "public_suffix" ]; @@ -206,6 +206,17 @@ src: { }; version = "4.20.0"; }; + anonymous_loader = { + dependencies = [ "version_gem" ]; + groups = [ "default" ]; + platforms = [ ]; + source = { + remotes = [ "https://rubygems.org" ]; + sha256 = "0mfb8kf2a4qmam6jvlrsb38zqh9gk3y1vhbx8iaxji4i8gi1hjh8"; + type = "gem"; + }; + version = "0.1.3"; + }; Ascii85 = { groups = [ "default" ]; platforms = [ ]; @@ -236,10 +247,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1p5f5x145ma9rw6i8zv955wbyb54wqhppa786hgck9ykshhj5myy"; + sha256 = "0g1yjdchydvk44v4303rjhb5sfb73nzbrvipnr5cdr7v5k4sl46v"; type = "gem"; }; - version = "0.1.4"; + version = "0.2.3"; }; aws-eventstream = { groups = [ "default" ]; @@ -256,10 +267,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0gkd4q0bbmw6vah15vkghvij398l7g5yd7570ilk9b3pcwazdx98"; + sha256 = "1p2qvraa79fl6gq7g69r73bsfpxk231c0c3wp8qhlhys2gd34r02"; type = "gem"; }; - version = "1.1134.0"; + version = "1.1284.0"; }; aws-sdk-bedrockruntime = { dependencies = [ @@ -270,10 +281,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "19fyy5dslbfsc8swwrl299nrkxzja268n1ggzixq9z45jjmv0ppw"; + sha256 = "1fbcjd4c025nzfcnrz33iq7m62fd2cyr6nrkfbjxib8gi4zsaivf"; type = "gem"; }; - version = "1.74.0"; + version = "1.83.0"; }; aws-sdk-core = { dependencies = [ @@ -284,15 +295,16 @@ src: { "bigdecimal" "jmespath" "logger" + "rexml" ]; groups = [ "default" ]; platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1zhj444iybzs1ikw1p4arv3zayw9xkk1ifnsb6g3r2j6p0h34gpf"; + sha256 = "0grlhf96r8m8s8appy9aj8x05mw0p2ydwvkaivmy5r4nhyy7zb1b"; type = "gem"; }; - version = "3.254.0"; + version = "3.255.0"; }; aws-sdk-kms = { dependencies = [ @@ -463,10 +475,10 @@ src: { ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1i5nn4750jnsd3gs0ca9zbiq1aglvzasp6j6f2s7kli4hm27gdin"; + sha256 = "1kzzpigr9nh7qcj6b3c03ffzq4xrcighjpa66cx05d4w1xyrw1a1"; type = "gem"; }; - version = "1.24.5"; + version = "1.25.0"; }; builder = { groups = [ @@ -491,10 +503,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1jy7yfn94acbcn23g9zh48b8j9jphwcqgr2vfy013zi4fd93q5n8"; + sha256 = "0wz4pd9zcnqys43yqfmnzg37438d9zs4a4q4v979x4qwx36xh7lj"; type = "gem"; }; - version = "8.1.3"; + version = "8.2.0"; }; capybara = { dependencies = [ @@ -526,10 +538,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "10kj1rh8w3qk6mg6kap1gh0p5kgmgdp1ij6gwayy3dqp139gw5sc"; + sha256 = "1hx2ha4q90am6ncc4zcisvbpa7haps2lkd7s8k34645wf8nmg3p4"; type = "gem"; }; - version = "0.5.9"; + version = "0.5.10"; }; cbor = { groups = [ "default" ]; @@ -559,10 +571,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1s8qdw1nfh3njd47q154njlfyc2llcgi4ik13vz39adqd7yclgz9"; + sha256 = "1fzqwshg1xzbdm97havskfp6wifsgbjii00dzba0y6bih4lk1jk1"; type = "gem"; }; - version = "0.5.1"; + version = "0.5.2"; }; chunky_png = { groups = [ "default" ]; @@ -607,10 +619,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1c2i64xsd35vijnb50rxb70g508s0x674xi0qpyyb8jy7bncl4j4"; + sha256 = "1qfi2ns3zwkgq616fc127xiqhan7g7m7gqpwriwcr34nds1vxwdj"; type = "gem"; }; - version = "1.3.7"; + version = "1.3.8"; }; connection_pool = { groups = [ @@ -640,10 +652,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "01vg83f2q7n0q5dsq2sfjmm6mrizhyzkmw21i4ysg06g0slrwna5"; + sha256 = "1mzgyg46jxdyijmg6dkxjv3yqmaixr7mk66094w0cnjrqa3b54w0"; type = "gem"; }; - version = "1.36.0"; + version = "1.37.0"; }; cose = { dependencies = [ @@ -695,10 +707,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0pfl5c0pyqaparxaqxi6s4gfl21bdldwiawrc0aknyvflli60lfw"; + sha256 = "15djj19ynz3sbw54fsf8n7y3sha8a333f2mgvjfwhr46jhcqg1ll"; type = "gem"; }; - version = "1.0.6"; + version = "1.0.7"; }; css_parser = { dependencies = [ @@ -719,10 +731,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0gz7r2kazwwwyrwi95hbnhy54kwkfac5swh2gy5p5vw36fn38lbf"; + sha256 = "0mj4kq4wwpc7c8ll52q30hsir1jrcd5kq7yb8lyz0rksa1z1x9mb"; type = "gem"; }; - version = "3.3.5"; + version = "3.3.6"; }; date = { groups = [ @@ -878,18 +890,15 @@ src: { }; version = "1.0.1"; }; - docile = { - groups = [ - "default" - "test" - ]; + discourse_voice_assets = { + groups = [ "default" ]; platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "07pj4z3h8wk4fgdn6s62vw1lwvhj0ac0x10vfbdkr9xzk7krn5cn"; + sha256 = "1hhcq5by1rr6aknmdfd7pzngvvlb5lby5if33bkha65akqzbrgv7"; type = "gem"; }; - version = "1.4.1"; + version = "0.1.0"; }; drb = { groups = [ @@ -931,10 +940,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "09f5sq41fb912jxsbzh68hmkwq9gj9p8fg0zbwikf80sxsjkz105"; + sha256 = "0mwg9xa0v45c9yh36nigj09pscrf0npn681r2wn9glzh943fkf6d"; type = "gem"; }; - version = "0.2.0"; + version = "0.4.0"; }; erb = { groups = [ @@ -945,10 +954,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1ncmbdjf2bwmk0jf5cxywns9zbxyfiy4h4p3pzi7yddyjhv81qrq"; + sha256 = "14pfj6zn0p1hxj6s6s0r7d424wap8zl9zxf89nj79y8fbg16vjn5"; type = "gem"; }; - version = "6.0.4"; + version = "6.0.7"; }; erubi = { groups = [ @@ -977,10 +986,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0l3dpg45i74ap1d7c4wyrdlc67l9vj4kgzv2l2r8mg1304fss0y5"; + sha256 = "1hma5q4f2dxr72v2af1w026cv756cy797zcy9x7cxdg1xh78fbfx"; type = "gem"; }; - version = "1.5.0"; + version = "1.7.1"; }; exifr = { groups = [ "default" ]; @@ -1000,10 +1009,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1x0qdz794b2w9740kq2y3g6qwiggbscbm5kyhnhdd1m5vdhnwv4h"; + sha256 = "1b2ajjrzv0afzljsga1l5r9597lam7b3c2fq352v955ib7abdfa9"; type = "gem"; }; - version = "2.14"; + version = "3.0.1"; }; fabrication = { groups = [ @@ -1187,10 +1196,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "04gzhqvsm4z4l12r9dkac9a75ah45w186ydhl0i4andldsnkkih5"; + sha256 = "09zl0rkskfq0cwfrk9ypjvflvzanfg3xbhh1slaa1myry7xi4zq3"; type = "gem"; }; - version = "1.3.0"; + version = "1.4.0"; }; goldiloader = { dependencies = [ @@ -1215,10 +1224,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "038cqc1kzxl22m3jfspkdpg0dxskga9jvgwclb4pivcjqxi62d4m"; + sha256 = "0xvamgf5fxrdzkp8lmws15r20bbwpibgh62lv98fmdindgbcjfl9"; type = "gem"; }; - version = "4.35.0"; + version = "4.36.1"; }; guess_html_encoding = { groups = [ "default" ]; @@ -1377,10 +1386,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1k0lk3pwadm2myvpg893n8jshmrf2sigrd4ki15lymy7gixaxqyn"; + sha256 = "026v93kja19bfslnwi9xfq2dj4r89kkwdprim4whjg6h3n4lz9zg"; type = "gem"; }; - version = "0.8.2"; + version = "0.9.2"; }; irb = { dependencies = [ @@ -1432,10 +1441,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "16mp8vzgxa8nsa81np042za453j8b0ihpjkf666s7byxrnvjb44v"; + sha256 = "0shwgjqbj856mb6m9kgkpy08nhym2gdvc2yaprlimfmky9y3n78z"; type = "gem"; }; - version = "2.19.9"; + version = "2.21.2"; }; json-schema = { dependencies = [ @@ -1487,20 +1496,20 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1i8wmzgb5nfhvkx1f6bhdwfm7v772172imh439v3xxhkv3hllhp6"; + sha256 = "1mqps8z4ly74hpksfajcfamqk1wb79biy187pn10knmi6zzb26al"; type = "gem"; }; - version = "2.10.1"; + version = "3.2.0"; }; landlock = { groups = [ "default" ]; platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0kxig1dq4v7qf84pmwvipq2rg6zrsplxbp3dflssw7w3zwcv3jcm"; + sha256 = "187b4k2rp5i3qgsz2d3bz2bg60dgldynka0fpx6zpq4c4gmcarjc"; type = "gem"; }; - version = "0.4.1"; + version = "0.5.1"; }; language_server-protocol = { groups = [ @@ -1511,10 +1520,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1k0311vah76kg5m6zr7wmkwyk5p2f9d9hyckjpn3xgr83ajkj7px"; + sha256 = "1w5p8c2145lmqzr25bxh4ikzjm6k8y1k5lriqqdpw9pq730w1wjy"; type = "gem"; }; - version = "3.17.0.5"; + version = "3.17.0.6"; }; libv8-node = { groups = [ "default" ]; @@ -1612,10 +1621,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1qcsvh9k4c0cp6agqm9a8m4x2gg7vifryqr7yxkg2x9ph9silds2"; + sha256 = "05nzwq2a5jyhcf0w4mbd3dd9yxd6q7zgadsi33f1jl5ra0gjq1rl"; type = "gem"; }; - version = "0.14.0"; + version = "0.15.0"; }; logstash-event = { groups = [ "default" ]; @@ -1650,10 +1659,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "011fdngxzr1p9dq2hxqz7qq1glj2g44xnhaadjqlf48cplywfdnl"; + sha256 = "062r891hxis58j5q735kk9sj5srxx0rv813f8m95bilsjm3gf1r0"; type = "gem"; }; - version = "2.25.1"; + version = "2.25.2"; }; lru_redux = { groups = [ @@ -1700,10 +1709,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0ha9sgkfqna62c1basc17dkx91yk7ppgjq32k4nhrikirlz6g9kg"; + sha256 = "1s30l5z7jkazgi4m6l6mh80rgsyhh2pp1pa5h70xclsj8z54wmq6"; type = "gem"; }; - version = "2.9.0"; + version = "2.9.1"; }; markbridge = { groups = [ @@ -1759,15 +1768,18 @@ src: { version = "1.1.0"; }; message_bus = { - dependencies = [ "rack" ]; + dependencies = [ + "logger" + "rack" + ]; groups = [ "default" ]; platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0y77v5yvnqmn3q0z80mcl2yq006zvx26x9fzlxg0wmnr0p71nf7i"; + sha256 = "1ky0lk2nw4n1znna1b4gr4c5rf9f99kx1did2y2hh503h4xl3fwv"; type = "gem"; }; - version = "4.5.2"; + version = "5.0.0"; }; messageformat-wrapper = { dependencies = [ "mini_racer" ]; @@ -1794,9 +1806,11 @@ src: { dependencies = [ "activesupport" "colored2" + "discourse-emojis" "i18n" "markbridge" "migrations-core" + "mini_racer" "pg" "zeitwerk" ]; @@ -1890,10 +1904,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1k28j6ww8rf43r5i8278jvm2cq3pnzsvqm7yqpb4p93kadjlq726"; + sha256 = "03vkd9g09jnxsp8mdacvjbplrrqfl5l26n50kd4kdn49zghi326d"; type = "gem"; }; - version = "3.2026.0414"; + version = "3.2026.0701"; }; mini_mime = { groups = [ @@ -1925,14 +1939,17 @@ src: { }; mini_racer = { dependencies = [ "libv8-node" ]; - groups = [ "default" ]; + groups = [ + "default" + "migrations" + ]; platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0c5f8ycbj389dvn2vxzq6xmsk2naqm57c5w31mavw0fbgdww3r2j"; + sha256 = "12ji47z8dn6g70c1ni70rfbrkjapnspvsmlqpy479raz0fjbm9y0"; type = "gem"; }; - version = "0.22.0"; + version = "0.22.1"; }; mini_scheduler = { dependencies = [ "sidekiq" ]; @@ -1966,16 +1983,6 @@ src: { }; version = "0.3.3"; }; - minio_runner = { - groups = [ "test" ]; - platforms = [ ]; - source = { - remotes = [ "https://rubygems.org" ]; - sha256 = "0bygpmih2ph6rvkxw09n6q7kyicvdiq2jcpd6k6iy0aklbgbxcpb"; - type = "gem"; - }; - version = "1.1.0"; - }; minitest = { dependencies = [ "drb" @@ -2021,20 +2028,20 @@ src: { ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "18g6ps30z6m365bly7sfialavnsf6m6qamdxsr84w96k51j4mnlb"; + sha256 = "0yry1bcnbl0c5xwg173n5y647596r8ydmsppa01c5l8d6lnw44a4"; type = "gem"; }; - version = "1.8.3"; + version = "1.8.4"; }; multi_json = { groups = [ "default" ]; platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0vfaab23d85617ps412ydb8ap4ci1sfzi8ainn8yyifc0pl38f9g"; + sha256 = "1040lr5y2phn7avdyam6zw6ikprlmk77biw3yhclsfwfh0qnl4p6"; type = "gem"; }; - version = "1.20.1"; + version = "1.21.1"; }; multi_xml = { dependencies = [ "bigdecimal" ]; @@ -2062,10 +2069,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "003cyf76zmki1lnh55cvir7dkn0s70dm909dxn6sfk9m00s2886l"; + sha256 = "1hlks2kkf3drbjb811cxyfp8f84rn9kjh9icms7idbz42ymgxgbm"; type = "gem"; }; - version = "1.1.2"; + version = "1.1.3"; }; net-http = { dependencies = [ "uri" ]; @@ -2087,10 +2094,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "03ga2h4i5hsk8pdlicyfvqfsbh55vrbikb0nkx9x7vx7fl6kdw19"; + sha256 = "1px886qvws5zvqphy5cysj8vg01lym0w7vs9wq1h41pk1pjlxaln"; type = "gem"; }; - version = "0.6.4.1"; + version = "0.6.6"; }; net-pop = { dependencies = [ "net-protocol" ]; @@ -2109,10 +2116,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1a32l4x73hz200cm587bc29q8q9az278syw3x6fkc9d1lv5y0wxa"; + sha256 = "0wklahcafcib6jwrr3angj7zzcb9csq3c0xj3axldb8w9wyhqcds"; type = "gem"; }; - version = "0.2.2"; + version = "0.3.0"; }; net-smtp = { dependencies = [ "net-protocol" ]; @@ -2151,16 +2158,16 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1s30b7h7qpyim30m8060xs415mbr3ci7i5hdg09chh1aqfx2qcbq"; + sha256 = "1d9safb4dly6qmc2g06444l0zifby52yy6j1a5fa1g4j3ihm3jah"; type = "gem"; }; - version = "1.19.3"; + version = "1.19.4"; }; oauth = { dependencies = [ + "anonymous_loader" "auth-sanitizer" "base64" - "cgi" "oauth-tty" "snaky_hash" "version_gem" @@ -2169,42 +2176,46 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1jlwk58v6pdarxp2sibsr1f4gs10nn5kxlsr2r6sa6aqiy86gi0f"; + sha256 = "03nm2qp4pzswaf93ammm458ssgwcldzwrqkcm0hgix0s75sbgw3v"; type = "gem"; }; - version = "1.1.5"; + version = "1.1.8"; }; oauth-tty = { dependencies = [ + "anonymous_loader" "auth-sanitizer" - "cgi" "version_gem" ]; groups = [ "default" ]; platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "01qylh3rskdpvjkd2dkm6sdf2klf2w99zib8z0bjbhhpmxkkp9nr"; + sha256 = "18xlmsfkzmqvx01v7q3pkpgcb4mqlh1dqcd7x4gx4vzars9mzbbi"; type = "gem"; }; - version = "1.0.8"; + version = "1.0.13"; }; oauth2 = { dependencies = [ + "anonymous_loader" + "auth-sanitizer" "faraday" "jwt" - "multi_json" + "logger" "multi_xml" "rack" + "snaky_hash" + "version_gem" ]; groups = [ "default" ]; platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "042w5lamxhllfxsv0y8v9cvdhmlasy5kxbhcdd3lzj9bhz4gqfb7"; + sha256 = "1b42dax3qwm1zbz86c9zcii7v45vi6c3rp083dyadjn2jcpnlwrg"; type = "gem"; }; - version = "1.4.11"; + version = "2.0.25"; }; octokit = { dependencies = [ @@ -2229,10 +2240,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0mmmswza8f4divl0mvkfq62pcdvm8c56j854wv7z9g6s0rmav7xd"; + sha256 = "1376v0gnz0b6ldzgahf7m5795jkgx793q0mqrv1k085105z2a4gm"; type = "gem"; }; - version = "3.16.12"; + version = "3.17.6"; }; omniauth = { dependencies = [ @@ -2272,10 +2283,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0jc66zp4bhwy7c6s817ws0nkimski3crrhwd7xyy55ss29v6b8hw"; + sha256 = "1m6a7kg3lxz2nm96prln2ja8r4wlm37m5vsy9199vnynqq5fgy4g"; type = "gem"; }; - version = "2.0.0"; + version = "2.0.1"; }; omniauth-google-oauth2 = { dependencies = [ @@ -2288,10 +2299,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "19hj9l3xgsy7dssjmfmkca129wdbhh3pdmp0jm685awqinna9mrf"; + sha256 = "1a8xgjc4g29cx6va72db2nxfyp2p4ligrp72xq17j2z5cizbdfmx"; type = "gem"; }; - version = "1.0.1"; + version = "1.2.3"; }; omniauth-oauth = { dependencies = [ @@ -2317,13 +2328,14 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0ia73zcbmhf02krlkq2rxmksx93jp777ax5x58fzkq3jzacqyniz"; + sha256 = "1s7yagqmzzqcr5l1rrb4bdjf7g2k2jf5pk0lw5y81489sbczc5gd"; type = "gem"; }; - version = "1.7.3"; + version = "1.9.0"; }; omniauth-twitter = { dependencies = [ + "cgi" "omniauth-oauth" "rack" ]; @@ -2331,20 +2343,20 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0r5j65hkpgzhvvbs90id3nfsjgsad6ymzggbm7zlaxvnrmvnrk65"; + sha256 = "1qv2ld087mnj38rlgjdp5h894gf01mwj5xypw5agdchk8598im7p"; type = "gem"; }; - version = "1.4.0"; + version = "1.5.0"; }; openssl = { groups = [ "default" ]; platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0v0grpg9gi59zr3imxy1745k9rp3dd095mkir8gvxi69blhh2kkz"; + sha256 = "1hj7wwp4r3jhvnyd8ik85wbs25cq1w61r28pv6ddyn5fd0lasdqh"; type = "gem"; }; - version = "3.3.2"; + version = "4.0.2"; }; openssl-signature_algorithm = { dependencies = [ "openssl" ]; @@ -2435,10 +2447,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0m2xqvn1la62hji1mn04y59giikww95p2hs0r4y2rrz3mdxcwyni"; + sha256 = "0a4q5h2hcihk79dbr20scgkm56l79qp7fsvfvkxlv8nmapvxg9i1"; type = "gem"; }; - version = "3.3.11.1"; + version = "3.3.12.0"; }; pastel = { dependencies = [ "tty-color" ]; @@ -2456,17 +2468,16 @@ src: { "Ascii85" "afm" "hashery" - "ruby-rc4" "ttfunk" ]; groups = [ "default" ]; platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1kk8f1f5kkdwsbskv0vikcwx5xaivv19y9zl97x1fcaam23akihq"; + sha256 = "0cipbx3ssgfsww7hrlll2j27b2vpcwaczqxxg614s9l5q1j5a6xz"; type = "gem"; }; - version = "2.15.1"; + version = "2.16.0"; }; pg = { groups = [ @@ -2508,10 +2519,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0ls8r49d27j0ffpfva99nk53a4nk17f4k71x44hpny8f2gb448ll"; + sha256 = "05apnpyyqpwwfa3rjwqn05l5jgj0j9wdp9w82a5gd1vrmd8n1ss4"; type = "gem"; }; - version = "1.60.0"; + version = "1.62.0"; }; pp = { dependencies = [ "prettyprint" ]; @@ -2523,10 +2534,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1xlxmg86k5kifci1xvlmgw56x88dmqf04zfzn7zcr4qb8ladal99"; + sha256 = "0w5mha75hs8gdj75g8vl0sxpyp8rzvwq8a4jcmi4ah8cf370zjyz"; type = "gem"; }; - version = "0.6.3"; + version = "0.6.4"; }; prettier_print = { groups = [ @@ -2622,24 +2633,6 @@ src: { }; version = "0.3.11"; }; - psych = { - dependencies = [ - "date" - "stringio" - ]; - groups = [ - "default" - "development" - "test" - ]; - platforms = [ ]; - source = { - remotes = [ "https://rubygems.org" ]; - sha256 = "1dx5bc3s1mb1i53np4cdkypg7ccygnvagr3hglyndbqilrljvxql"; - type = "gem"; - }; - version = "5.4.0"; - }; public_suffix = { groups = [ "default" @@ -2695,10 +2688,10 @@ src: { ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "175ni9qsai9x2ykwvdbd5dzfyncaxpyn6dhjxjw70iq60xz9vzm8"; + sha256 = "0pyammr7fpxqa1sdvw0vnk4699j081sqqcsj6isl67471mm545pg"; type = "gem"; }; - version = "2.2.23"; + version = "2.2.24"; }; rack-mini-profiler = { dependencies = [ "rack" ]; @@ -2706,10 +2699,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0y1x4rc7bz8x3zn8p6g21rw6ivbjml6a2vl9dhchiy8i6b110n28"; + sha256 = "1q822cwrs4khc4l4jgc6dsnvw7iz46rgchqam2dqs759gw4bmicr"; type = "gem"; }; - version = "4.0.1"; + version = "5.0.0"; }; rack-protection = { dependencies = [ @@ -2805,10 +2798,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "128y5g3fyi8fds41jasrr4va1jrs7hcamzklk1523k7rxb64bc98"; + sha256 = "1hi25xz5ijz3kjx4vsiywqbq05mlkas7di8pwc3p6mhyn34sg5z7"; type = "gem"; }; - version = "1.7.0"; + version = "1.7.1"; }; rails_failover = { dependencies = [ @@ -2834,10 +2827,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1winy1bzrzspb0ynnx5rcy8fhg1ldkzcnydn7zkvxll6xmjg7b3s"; + sha256 = "1rlmwimr8yb7dhid36b5lgaf337bqh8ml28jaw2x326b0l28zj1b"; type = "gem"; }; - version = "7.0.0"; + version = "9.0.0"; }; railties = { dependencies = [ @@ -2858,10 +2851,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1iym8kbdzpkjk70h7w9pbmqj7czsywzinwpqla8ldc6sv7hmh6fs"; + sha256 = "11s4n3zqd7bry5ndraq02f641hskhmnfcza8lkzcw04sawra5213"; type = "gem"; }; - version = "8.0.5.1"; + version = "8.1.3.1"; }; rainbow = { groups = [ @@ -2969,14 +2962,15 @@ src: { groups = [ "default" "development" + "test" ]; platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "09ggg2zk0qrh0mc3fa23xjbn2gzqxd0jfqj6qm6460ydcqg6fxdg"; + sha256 = "0x067q8cdam4kv5dc09iq2nzca8qm2kdl0dr22gc0ny0vj3bixsi"; type = "gem"; }; - version = "4.0.2"; + version = "4.2.0"; }; rbtrace = { dependencies = [ @@ -2995,25 +2989,16 @@ src: { ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0yvmkccs3rc6qisy86idhzpk2z8dzsf6dl2mw80h63skfq0f8yc2"; + sha256 = "0s7yfa35d35lw0lr2wy2fcv4fk6ndkrm4bj1chs1y9f4xbzh00pd"; type = "gem"; }; - version = "0.5.4"; - }; - rchardet = { - groups = [ "default" ]; - platforms = [ ]; - source = { - remotes = [ "https://rubygems.org" ]; - sha256 = "0csz2dybi0y1w22dzxpllkcnr5dmr1w0y4xb947c2ka6bwcwnhg0"; - type = "gem"; - }; - version = "1.10.2"; + version = "0.5.5"; }; rdoc = { dependencies = [ "erb" - "psych" + "prism" + "rbs" "tsort" ]; groups = [ @@ -3024,10 +3009,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "14iiyb4yi1chdzrynrk74xbhmikml3ixgdayjma3p700singfl46"; + sha256 = "0sf4909q2mr9z0rpygv94z12b0yamg07gz8cba2mi5k3m448rgq3"; type = "gem"; }; - version = "7.2.0"; + version = "8.0.0"; }; redcarpet = { groups = [ "generic_import" ]; @@ -3045,10 +3030,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0syhyw1bp9nbb0fvcmm58y1c6iav6xw6b4bzjz1rz2j1d7c012br"; + sha256 = "19ndpji1plvkvb0x180lfkpc1fb3ig8cszpcb6vqcs8hvl7c2wfy"; type = "gem"; }; - version = "5.4.0"; + version = "6.0.0"; }; redis-client = { dependencies = [ "connection_pool" ]; @@ -3056,10 +3041,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0xz4nl6jr8chzliw39s75mzfr7s7fyq8fh2m841im97h8bni2gvl"; + sha256 = "0baj2r8wa6imzfndyz6cj732v8nq02wy7nicfciqdr5zgdfbqlai"; type = "gem"; }; - version = "0.30.0"; + version = "0.30.1"; }; redis-namespace = { dependencies = [ "redis" ]; @@ -3096,10 +3081,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0d8q5c4nh2g9pp758kizh8sfrvngynrjlm0i1zn3cnsnfd4v160i"; + sha256 = "0gaq2lc463ap1srz7y5kh2p4dxazs7vjrpiby58d9yfvan72s0av"; type = "gem"; }; - version = "0.6.3"; + version = "0.7.0"; }; request_store = { dependencies = [ "rack" ]; @@ -3112,6 +3097,17 @@ src: { }; version = "1.7.0"; }; + reverse_markdown = { + dependencies = [ "nokogiri" ]; + groups = [ "default" ]; + platforms = [ ]; + source = { + remotes = [ "https://rubygems.org" ]; + sha256 = "1bxqlpwnixn8x4bnna958w6m6qkdkbnd23b9j6ib3nrrrs9bp3l1"; + type = "gem"; + }; + version = "3.0.2"; + }; rexml = { groups = [ "default" @@ -3161,10 +3157,10 @@ src: { ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1g2y2z07niw4ylbgf6zr6a7kjaqbaqxn98xwff58zf4w5yx9ppp2"; + sha256 = "0ljlr1da64kx3mimpzb4x2yczk08b0sg04h2ji3m2zxb88l66z5p"; type = "gem"; }; - version = "5.0.0"; + version = "5.1.0"; }; rqrcode = { dependencies = [ @@ -3399,10 +3395,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0ca5inh368d4l24a2v2nbd3p4xc6s0pqs91j27h226nh04zmyha4"; + sha256 = "1l4nh82hq54nxgyisdcf8vbkpzm149p9kff5k0vpwp8w76zvg0lw"; type = "gem"; }; - version = "1.86.1"; + version = "1.91.0"; }; rubocop-ast = { dependencies = [ @@ -3417,10 +3413,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0dahfpnzz63hyqxa03x8rypnrxzwyvh4i5a8ri34bzpnf3pg64j4"; + sha256 = "1nw84xk6vc2ls8sxqvyhxs2agh4l0jrws85d4bi3x0501lq8ijmr"; type = "gem"; }; - version = "1.49.1"; + version = "1.50.0"; }; rubocop-capybara = { dependencies = [ @@ -3435,10 +3431,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0mz3mvjh09awggp0bwsmf4rfaz2irrwc6vzpiklfh7jnlyiipspr"; + sha256 = "0jwcfv1hs9r838zjaz61g5d62k564p47mqw77j7pznmc7196ar3s"; type = "gem"; }; - version = "2.23.0"; + version = "3.0.0"; }; rubocop-discourse = { dependencies = [ @@ -3458,10 +3454,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "02yf6zcq3ki1nkkkw3vsgfkm4fyfzdpb6lss7d285vdirc9izcxx"; + sha256 = "0w4w3qxah2ci39hqbgvkvx0bv1kb9by1a9p8k29lczlkkg7nn227"; type = "gem"; }; - version = "3.18.0"; + version = "3.20.0"; }; rubocop-discourse-base = { dependencies = [ "rubocop" ]; @@ -3512,14 +3508,15 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1llsxc8wm2pq8glpv5mczd1h36fazbri3wwrh7dfqra80a4pklqh"; + sha256 = "0zjby5icpp5r9gqqnfcl2dcpqsam1y10vnnxz0l063h6snnla5kf"; type = "gem"; }; - version = "2.34.3"; + version = "2.37.0"; }; rubocop-rspec = { dependencies = [ "lint_roller" + "regexp_parser" "rubocop" ]; groups = [ @@ -3530,10 +3527,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1qjmvcpk6qwxjdh3w5smr2n7c1glxsdzpv5fi7bkg0j034v0m9wg"; + sha256 = "1qk5bx4vg7n17i9475h6dqkhay9m3s6vanq9y35hxl9cb762wghb"; type = "gem"; }; - version = "3.9.0"; + version = "3.10.2"; }; rubocop-rspec_rails = { dependencies = [ @@ -3564,10 +3561,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0aa1mg6bdl23wgrxd98wycq3963jfpnh9z0yh976p9q03h01r81k"; + sha256 = "0gaq685p1zizhsbax8gakraq46lhvy8m82v86688rzrpf9cg3j2c"; type = "gem"; }; - version = "0.26.9"; + version = "0.26.11"; }; ruby-lsp-rails = { dependencies = [ "ruby-lsp" ]; @@ -3650,6 +3647,20 @@ src: { }; version = "0.7.3"; }; + ruby-vips = { + dependencies = [ + "ffi" + "logger" + ]; + groups = [ "default" ]; + platforms = [ ]; + source = { + remotes = [ "https://rubygems.org" ]; + sha256 = "0x2k5x272m2zs0vmznl2jac14bj9a2g0365xxcnr2s9rq41fr1g6"; + type = "gem"; + }; + version = "2.3.0"; + }; ruby2_keywords = { groups = [ "default" @@ -3669,10 +3680,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0khy3d43cr2i4x9as2k41ckrjb4wkpcycdbzaara4fy4qw923n9f"; + sha256 = "15dnb2admqpyw6ipxbaqj4cnfwldwkm11gwrzlf2sa329pa99296"; type = "gem"; }; - version = "3.3.1"; + version = "3.6.0"; }; samovar = { dependencies = [ "console" ]; @@ -3711,10 +3722,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "14n07y6mg44y8rzsc4w12pf66jqn8iv318dj2y3vmrab60gq7m5p"; + sha256 = "1zcvhvamsmphnai6wjbqk73gpz52ifaya5fmarsxg5nyj347r31h"; type = "gem"; }; - version = "1.100.0"; + version = "1.104.0"; }; sassc-embedded = { dependencies = [ "sass-embedded" ]; @@ -3722,10 +3733,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0qymnvzbgbg9ir70yl0qrhfg2acfrwmlkzdywrkq5k1i81g84qpa"; + sha256 = "1apy1n0x79in6l88f6m7ynkq06a7hpwighywq538cm41a63sv45z"; type = "gem"; }; - version = "1.80.8"; + version = "1.80.9"; }; sawyer = { dependencies = [ @@ -3765,10 +3776,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0xwwfj48d6mpc66lhl4yabnjazpf47wqg9n1i9na7q0h9isdigxl"; + sha256 = "1202qsi1xsskl4qa9fwlzwhs3j783445w20v24js57avfvjldfsx"; type = "gem"; }; - version = "7.0.1"; + version = "8.0.1"; }; sidekiq = { dependencies = [ @@ -3788,55 +3799,24 @@ src: { version = "7.3.10"; }; simplecov = { - dependencies = [ - "docile" - "simplecov-html" - "simplecov_json_formatter" - ]; groups = [ "test" ]; platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "198kcbrjxhhzca19yrdcd6jjj9sb51aaic3b0sc3pwjghg3j49py"; + sha256 = "0y0ya82s3zi2wmkadnmb3l9r13mbsvd1g63n9mlp8bhb7zqmx0i5"; type = "gem"; }; - version = "0.22.0"; - }; - simplecov-html = { - groups = [ - "default" - "test" - ]; - platforms = [ ]; - source = { - remotes = [ "https://rubygems.org" ]; - sha256 = "0ikjfwydgs08nm3xzc4cn4b6z6rmcrj2imp84xcnimy2wxa8w2xx"; - type = "gem"; - }; - version = "0.13.2"; - }; - simplecov_json_formatter = { - groups = [ - "default" - "test" - ]; - platforms = [ ]; - source = { - remotes = [ "https://rubygems.org" ]; - sha256 = "0a5l0733hj7sk51j81ykfmlk2vd5vaijlq9d5fn165yyx3xii52j"; - type = "gem"; - }; - version = "0.1.4"; + version = "1.1.1"; }; simpleidn = { groups = [ "default" ]; platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0a9c1mdy12y81ck7mcn9f9i2s2wwzjh1nr92ps354q517zq9dkh8"; + sha256 = "00sdym5q3d9zg7lv47mjamzv67z1lfyd3gz9256v0g9gxl5p7jhj"; type = "gem"; }; - version = "0.2.3"; + version = "0.3.0"; }; smarter_json = { dependencies = [ "bigdecimal" ]; @@ -3858,10 +3838,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1kpyqhybal05bmby5myq45s768qs9gw205hs6jb6gynyay67a4ib"; + sha256 = "0kfbrd4sgajhnjwhqpk1mb4h10whfx2h5kb0i3j35yd3280cf0kx"; type = "gem"; }; - version = "2.0.4"; + version = "2.0.7"; }; sqlite3 = { dependencies = [ "mini_portile2" ]; @@ -3869,10 +3849,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "01i6k25fv3w3f5ph5cix9ipg19ajsy6zrzxdm18ashzrldrjjmq4"; + sha256 = "13nh4kd96d28dv3habjv2fiap30ccb73lz8mqx5d0834jl3fcvwm"; type = "gem"; }; - version = "2.9.5"; + version = "2.9.6"; }; sshkey = { groups = [ "default" ]; @@ -3911,29 +3891,19 @@ src: { }; version = "0.2.28"; }; - stringio = { - groups = [ - "default" - "development" - "test" - ]; - platforms = [ ]; - source = { - remotes = [ "https://rubygems.org" ]; - sha256 = "1q92y9627yisykyscv0bdsrrgyaajc2qr56dwlzx7ysgigjv4z63"; - type = "gem"; - }; - version = "3.2.0"; - }; stripe = { + dependencies = [ + "bigdecimal" + "logger" + ]; groups = [ "default" ]; platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "13gr4z9nsvpknyy9y2vg4dvg77817m2ykyx57j03692dgv684vm7"; + sha256 = "176l1phy2yayxm7r4q8dnbyfgc22wb0p1rwwxzdhmfjsl9v4jqcs"; type = "gem"; }; - version = "11.1.0"; + version = "19.6.2"; }; strscan = { groups = [ @@ -3970,14 +3940,15 @@ src: { version = "6.3.0"; }; test-prof = { + dependencies = [ "logger" ]; groups = [ "test" ]; platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "17j9cai2ykcndgn0800m9nb297sx0lpminxj8bcqw4bwkb1xjch3"; + sha256 = "188p735jnx0bxm53ysfwsrxcwvj4dfgj1r10k037c9rbc4bylyh2"; type = "gem"; }; - version = "1.6.1"; + version = "1.6.3"; }; thor = { groups = [ @@ -3999,10 +3970,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0kahw453axizbg3x5yi1lyasj2vgd6vshkp6zgsi22w3y41kbb1b"; + sha256 = "1hr7x8v5yzys8s5js4s36b0p0j8klqs559wsbaxdhxdbkv6qnaly"; type = "gem"; }; - version = "0.0.16"; + version = "0.0.17"; }; timeout = { groups = [ @@ -4136,10 +4107,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "1g0hmv2axxjvk7m5ksql9q0a6mnhqv4cqgqqzh0pd39vsp9x7c3x"; + sha256 = "1ygpikd3hdqsi16gqh33r5al1b9xdwrv2wl3rw210g7iar9vr3s7"; type = "gem"; }; - version = "1.2026.2"; + version = "1.2026.3"; }; unf = { groups = [ "default" ]; @@ -4229,10 +4200,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0q3jb2cal9c8b0xgdz1xl47w3n1vsb1gwj06c4acsxsqqid07wvp"; + sha256 = "1l17paljrcjdrvv0ida39msync07v3g1ij70cwsjw999gdc42cm7"; type = "gem"; }; - version = "1.1.13"; + version = "1.1.15"; }; web-push = { dependencies = [ @@ -4243,10 +4214,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "13diqh61rl658gwq0c2ds41z59i0x4plj5k4v98qkgd3pgrd4kav"; + sha256 = "0z8qwx6v59dj443z7wf6604wpk5khs5g4nfsmc6vg3y5801v06jh"; type = "gem"; }; - version = "3.0.1"; + version = "3.1.0"; }; webmock = { dependencies = [ @@ -4258,10 +4229,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "142cbab47mjxmg8gc89d94sd3h7an9ligh38r9n88wb3xbr5cibp"; + sha256 = "03fmmb5ym51rby3asas3w5s31hik8mzwf2gvijbfdsqps83a53cd"; type = "gem"; }; - version = "3.26.2"; + version = "3.26.4"; }; webrick = { groups = [ @@ -4316,10 +4287,10 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0a3zi3v7qjm7lm4yp9z2sm959533k543sc4z0ixqik8wcfdpw27b"; + sha256 = "0lfwngmsz3xq9k9la9890cqpm4vk3rda4171yzms7f3w7x4i3qjj"; type = "gem"; }; - version = "0.9.44"; + version = "0.9.45"; }; zeitwerk = { groups = [ @@ -4331,13 +4302,14 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "04hx33lsnp4q0qf8982mz0acs1dap5s2bsmihi0n0g08249sc4kj"; + sha256 = "1rcjpgyzmdxp8rdw466156fmr588k9q1wg8j42g0dkk7hid1519c"; type = "gem"; }; - version = "2.8.2"; + version = "2.8.3"; }; zendesk_api = { dependencies = [ + "base64" "faraday" "faraday-multipart" "hashie" @@ -4349,9 +4321,9 @@ src: { platforms = [ ]; source = { remotes = [ "https://rubygems.org" ]; - sha256 = "0yizpglgfwml6a2w696m97d1q50hq3v0vldja431rv93s9sjbgly"; + sha256 = "05gcvhnz316rff8ysm0746yig1inb80skkz7m4c3bvgq789nqwiz"; type = "gem"; }; - version = "1.38.0.rc1"; + version = "3.1.2"; }; } diff --git a/pkgs/servers/web-apps/discourse/sass_embedded_vendored_dart_sass.patch b/pkgs/servers/web-apps/discourse/sass_embedded_vendored_dart_sass.patch index 8d7f55794fa4..eb18dc3380d0 100644 --- a/pkgs/servers/web-apps/discourse/sass_embedded_vendored_dart_sass.patch +++ b/pkgs/servers/web-apps/discourse/sass_embedded_vendored_dart_sass.patch @@ -1,21 +1,19 @@ diff --git a/ext/sass/Rakefile b/ext/sass/Rakefile -index d542efd..93f97cf 100644 +index a36b11a..93f97cf 100644 --- a/ext/sass/Rakefile +++ b/ext/sass/Rakefile -@@ -84,11 +84,18 @@ file File.absolute_path('node_modules/sass', ARCHDIR) do +@@ -84,10 +84,18 @@ file File.absolute_path('node_modules/sass', ARCHDIR) do end task 'dart-sass' => ( -- begin -- SassConfig.dart_sass +- if SassConfig.dart_support? - File.absolute_path('dart-sass/sass', ARCHDIR) -- rescue NotImplementedError -- File.absolute_path('node_modules/sass', ARCHDIR) + p ENV + if ENV.has_key?('DART_SASS_VENDORED') + mkdir_p ARCHDIR + cp_r ENV.fetch('DART_SASS_VENDORED'), File.absolute_path('dart-sass', ARCHDIR) -+ else + else +- File.absolute_path('node_modules/sass', ARCHDIR) + raise Errno::EINVAL, "no vendored SASS" + begin + SassConfig.dart_sass diff --git a/pkgs/servers/web-apps/discourse/voice-plugin-assets.patch b/pkgs/servers/web-apps/discourse/voice-plugin-assets.patch new file mode 100644 index 000000000000..51092bc9d6e4 --- /dev/null +++ b/pkgs/servers/web-apps/discourse/voice-plugin-assets.patch @@ -0,0 +1,38 @@ +diff --git a/plugins/voice/plugin.rb b/plugins/voice/plugin.rb +index a715e9364e0..29b7eeb3c72 100644 +--- a/plugins/voice/plugin.rb ++++ b/plugins/voice/plugin.rb +@@ -15,18 +15,22 @@ require "discourse_voice_assets" + # immutable, so the versioned URL is what busts caches on a gem bump. The + # client learns the current base path from the site serializer. + voice_javascripts_dir = File.join(__dir__, "public", "javascripts") +-FileUtils.mkdir_p(voice_javascripts_dir) +-Dir +- .children(voice_javascripts_dir) +- .each do |entry| +- if entry != DiscourseVoiceAssets::VERSION +- FileUtils.rm_rf(File.join(voice_javascripts_dir, entry)) +- end +- end +-Discourse::Utils.atomic_ln_s( +- DiscourseVoiceAssets.vendor_path, +- File.join(voice_javascripts_dir, DiscourseVoiceAssets::VERSION), ++unless File.symlink?( ++ File.join(voice_javascripts_dir, DiscourseVoiceAssets::VERSION) + ) ++ FileUtils.mkdir_p(voice_javascripts_dir) ++ Dir ++ .children(voice_javascripts_dir) ++ .each do |entry| ++ if entry != DiscourseVoiceAssets::VERSION ++ FileUtils.rm_rf(File.join(voice_javascripts_dir, entry)) ++ end ++ end ++ Discourse::Utils.atomic_ln_s( ++ DiscourseVoiceAssets.vendor_path, ++ File.join(voice_javascripts_dir, DiscourseVoiceAssets::VERSION), ++ ) ++end + + enabled_site_setting :voice_enabled + From 675cc8a99c120364e382ff63078bcbf35698674a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 28 Sep 2026 01:44:12 +0000 Subject: [PATCH 076/117] rainfrog: 0.4.5 -> 0.4.6 --- pkgs/by-name/ra/rainfrog/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ra/rainfrog/package.nix b/pkgs/by-name/ra/rainfrog/package.nix index ff3072485ad7..cfe6d02bea64 100644 --- a/pkgs/by-name/ra/rainfrog/package.nix +++ b/pkgs/by-name/ra/rainfrog/package.nix @@ -8,7 +8,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "rainfrog"; - version = "0.4.5"; + version = "0.4.6"; __structuredAttrs = true; @@ -16,10 +16,10 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "achristmascarl"; repo = "rainfrog"; tag = "v${finalAttrs.version}"; - hash = "sha256-kA3rIGmSid3qbIasqoSnFv4w0P+RrAWoH8PszY9xSGs="; + hash = "sha256-fcQFHUw1+h1PqmPlanvcFsudUb9nePZA0yJaFOwvx3U="; }; - cargoHash = "sha256-A3gZF2oJVt5WR56JVwsPOVvgu/d9veD01+gQESNV0Qc="; + cargoHash = "sha256-IXbPCxz+plIa6jYMTRcG44e7sHmwxzA+lbtWb/ukzcU="; nativeInstallCheckInputs = [ versionCheckHook ]; doInstallCheck = true; From 0d996e3d247a86ce58536618d4d02a505b549068 Mon Sep 17 00:00:00 2001 From: Akira Komamura Date: Tue, 22 Sep 2026 21:55:59 +0900 Subject: [PATCH 077/117] ocamlPackages.capnp-rpc-unix: init at 2.1.2-unstable-2026-09-13 Co-authored-by: StepBroBD --- .../ocaml-modules/capnp-rpc/unix.nix | 65 +++++++++++++++++++ pkgs/top-level/ocaml-packages.nix | 2 + 2 files changed, 67 insertions(+) create mode 100644 pkgs/development/ocaml-modules/capnp-rpc/unix.nix diff --git a/pkgs/development/ocaml-modules/capnp-rpc/unix.nix b/pkgs/development/ocaml-modules/capnp-rpc/unix.nix new file mode 100644 index 000000000000..f65db1a13e5a --- /dev/null +++ b/pkgs/development/ocaml-modules/capnp-rpc/unix.nix @@ -0,0 +1,65 @@ +{ + buildDunePackage, + alcotest, + astring, + base64, + capnp, + capnp-rpc, + capnp-rpc-net, + capnproto, + cmdliner, + cstruct, + eio, + eio_main, + fmt, + ipaddr, + logs, + mdx, + mirage-crypto-rng, +}: + +buildDunePackage { + pname = "capnp-rpc-unix"; + + minimalOCamlVersion = "5.2"; + + inherit (capnp-rpc) src version; + + nativeBuildInputs = [ + capnp + capnproto + ]; + + propagatedBuildInputs = [ + astring + base64 + capnp-rpc + capnp-rpc-net + cmdliner + cstruct + eio + fmt + ipaddr + logs + mirage-crypto-rng + ]; + + checkInputs = [ + alcotest + eio_main + (mdx.override { inherit logs; }) + ]; + + nativeCheckInputs = [ mdx.bin ]; + + doCheck = true; + __darwinAllowLocalNetworking = true; + + preCheck = '' + export XDG_CACHE_HOME="$TMPDIR/cache" + ''; + + meta = capnp-rpc.meta // { + description = "Unix helpers for Cap'n Proto RPC services"; + }; +} diff --git a/pkgs/top-level/ocaml-packages.nix b/pkgs/top-level/ocaml-packages.nix index c5c7d106d0e9..f8e7f16a1d61 100644 --- a/pkgs/top-level/ocaml-packages.nix +++ b/pkgs/top-level/ocaml-packages.nix @@ -221,6 +221,8 @@ let capnp-rpc-net = callPackage ../development/ocaml-modules/capnp-rpc/net.nix { }; + capnp-rpc-unix = callPackage ../development/ocaml-modules/capnp-rpc/unix.nix { }; + caqti = callPackage ../development/ocaml-modules/caqti { }; caqti-async = callPackage ../development/ocaml-modules/caqti/async.nix { }; From 690e4593bd05bebb808fb01c3ee070ab3bc35996 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 28 Sep 2026 03:42:24 +0000 Subject: [PATCH 078/117] tree-sitter-grammars.tree-sitter-sshclientconfig: 2026.8.27 -> 2026.9.24 --- pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix b/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix index 0b9866a57f61..cf1f12199f9a 100644 --- a/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix +++ b/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix @@ -2910,9 +2910,9 @@ }; sshclientconfig = rec { - version = "2026.8.27"; + version = "2026.9.24"; url = "github:metio/tree-sitter-ssh-client-config?ref=${version}"; - hash = "sha256-yTdEinKdEmWPiw6+fBq15tXe8GsoC7PFk2pVaDSFCYA="; + hash = "sha256-M5PwCbNxs8Ow5YZl178PLJy3Lq9vxm9PEDvsR5UVJHE="; meta = { license = lib.licenses.cc0; maintainers = with lib.maintainers; [ From fa1b73f8137fe7d933c9245505a4e9f80a7591be Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 28 Sep 2026 04:07:01 +0000 Subject: [PATCH 079/117] python3Packages.cpe-search: 0.2.11 -> 0.2.12 --- pkgs/development/python-modules/cpe-search/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/cpe-search/default.nix b/pkgs/development/python-modules/cpe-search/default.nix index 4b76790e840f..e3b867e771ad 100644 --- a/pkgs/development/python-modules/cpe-search/default.nix +++ b/pkgs/development/python-modules/cpe-search/default.nix @@ -13,14 +13,14 @@ buildPythonPackage (finalAttrs: { pname = "cpe-search"; - version = "0.2.11"; + version = "0.2.12"; pyproject = true; src = fetchFromGitHub { owner = "ra1nb0rn"; repo = "cpe_search"; tag = "v${finalAttrs.version}"; - hash = "sha256-wRuzIQKexlDb2u9fSk0hJg2OU6ahHuzJWQy4HrQrBFY="; + hash = "sha256-HtcNyh5I372gUOyMGPbxudZonJ/OmH+zOajisxo/Hqs="; }; build-system = [ hatchling ]; From eb32b5a3d404181be06e4f823de06dd3a72af950 Mon Sep 17 00:00:00 2001 From: Ethan Carter Edwards Date: Mon, 28 Sep 2026 00:13:33 -0400 Subject: [PATCH 080/117] cudaPackages.cuda_cuobjdump: set meta.mainProgram Signed-off-by: Ethan Carter Edwards --- pkgs/development/cuda-modules/packages/cuda_cuobjdump.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/development/cuda-modules/packages/cuda_cuobjdump.nix b/pkgs/development/cuda-modules/packages/cuda_cuobjdump.nix index 754c70915497..d534a0873cb1 100644 --- a/pkgs/development/cuda-modules/packages/cuda_cuobjdump.nix +++ b/pkgs/development/cuda-modules/packages/cuda_cuobjdump.nix @@ -13,5 +13,6 @@ buildRedist { ptx text from host binaries. ''; homepage = "https://docs.nvidia.com/cuda/cuda-binary-utilities#cuobjdump"; + mainProgram = "cuobjdump"; }; } From aea5872510ef34026ae1535cc1cf2dd80437c13f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 28 Sep 2026 04:41:30 +0000 Subject: [PATCH 081/117] terraform-providers.heroku_heroku: 5.4.0 -> 5.4.1 --- .../networking/cluster/terraform-providers/providers.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/cluster/terraform-providers/providers.json b/pkgs/applications/networking/cluster/terraform-providers/providers.json index ae3545baac06..29b54ef5e8c5 100644 --- a/pkgs/applications/networking/cluster/terraform-providers/providers.json +++ b/pkgs/applications/networking/cluster/terraform-providers/providers.json @@ -715,11 +715,11 @@ "vendorHash": "sha256-47xWjlzpQ/EYzjbuuMKQiu5cfYAXdYkXRl+AOEP+sA4=" }, "heroku_heroku": { - "hash": "sha256-AmHgAlz4J3l9OCjUMVxLMWtKZB1LpNOyX1exUI6fWHA=", + "hash": "sha256-FnJn/kFnTOOcnJtVdlSFpZh9S+BZodhk6IcvG0DFaLg=", "homepage": "https://registry.terraform.io/providers/heroku/heroku", "owner": "heroku", "repo": "terraform-provider-heroku", - "rev": "v5.4.0", + "rev": "v5.4.1", "spdx": "MPL-2.0", "vendorHash": null }, From dcb658e33994db940b21ef1ec83364559dc6eb97 Mon Sep 17 00:00:00 2001 From: Ethan Carter Edwards Date: Mon, 28 Sep 2026 00:16:53 -0400 Subject: [PATCH 082/117] cudaPackages.cuda_nvdisasm: set meta.mainProgram Signed-off-by: Ethan Carter Edwards --- pkgs/development/cuda-modules/packages/cuda_nvdisasm.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/development/cuda-modules/packages/cuda_nvdisasm.nix b/pkgs/development/cuda-modules/packages/cuda_nvdisasm.nix index 981a0ce420a7..96530a119d88 100644 --- a/pkgs/development/cuda-modules/packages/cuda_nvdisasm.nix +++ b/pkgs/development/cuda-modules/packages/cuda_nvdisasm.nix @@ -14,5 +14,6 @@ buildRedist { also does control flow analysis to annotate jump/branch targets and makes the output easier to read. ''; homepage = "https://docs.nvidia.com/cuda/cuda-binary-utilities#nvdisasm"; + mainProgram = "nvdisasm"; }; } From 715faad1baa966add40e149dc20e871359d21b8f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 28 Sep 2026 06:16:30 +0000 Subject: [PATCH 083/117] terraform-providers.topicusonderwijs_octodns: 1.2.0 -> 1.3.0 --- .../networking/cluster/terraform-providers/providers.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/cluster/terraform-providers/providers.json b/pkgs/applications/networking/cluster/terraform-providers/providers.json index ae3545baac06..c7a8a1ae73ff 100644 --- a/pkgs/applications/networking/cluster/terraform-providers/providers.json +++ b/pkgs/applications/networking/cluster/terraform-providers/providers.json @@ -1391,13 +1391,13 @@ "vendorHash": "sha256-Bat/S4e5vzT0/XOhJ9zCWLa4IE4owLC6ec1yvEh+c0Y=" }, "topicusonderwijs_octodns": { - "hash": "sha256-gbw0Na3m5X5CjoaXHPREfQIpwzQ9hpa7A3Hn+rwcjEA=", + "hash": "sha256-ewCWuQlmyrP0mrIz0k+YYUzheeFBPh1bEyRueFC8b3w=", "homepage": "https://registry.terraform.io/providers/topicusonderwijs/octodns", "owner": "topicusonderwijs", "repo": "terraform-provider-octodns", - "rev": "v1.2.0", + "rev": "v1.3.0", "spdx": "MPL-2.0", - "vendorHash": "sha256-da0+/aLNEuMZWD7+zMUGpc1Ch5VKyN+EyO0Mp4mZWv8=" + "vendorHash": "sha256-YDTR4twyHhBqOEPbzMtkO2DWj41VhJ1PAVU3nNVh3l8=" }, "trozz_pocketid": { "hash": "sha256-+jIdj9tUV0ScX4y7lm3IWSLHsxwHGp+KXVfaY0K86uk=", From c9151ff47e0537e1ec6e6037abf78077b4132d5e Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Mon, 28 Sep 2026 08:20:18 +0200 Subject: [PATCH 084/117] python3Packages.iamdata: 0.1.202609271 -> 0.1.202609281 Diff: https://github.com/cloud-copilot/iam-data-python/compare/v0.1.202609271...v0.1.202609281 Changelog: https://github.com/cloud-copilot/iam-data-python/releases/tag/v0.1.202609281 --- pkgs/development/python-modules/iamdata/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/iamdata/default.nix b/pkgs/development/python-modules/iamdata/default.nix index 436a8f682699..90ab25b9b373 100644 --- a/pkgs/development/python-modules/iamdata/default.nix +++ b/pkgs/development/python-modules/iamdata/default.nix @@ -8,14 +8,14 @@ buildPythonPackage (finalAttrs: { pname = "iamdata"; - version = "0.1.202609271"; + version = "0.1.202609281"; pyproject = true; src = fetchFromGitHub { owner = "cloud-copilot"; repo = "iam-data-python"; tag = "v${finalAttrs.version}"; - hash = "sha256-P3aUN/WHgN9zAql0lhWPohHGkJ9LA2EZWOg3QgvQQsA="; + hash = "sha256-vh+KVvkg1B6EV/9EabnEJvnWk+yycxVnIH2xO2g/F/o="; }; __darwinAllowLocalNetworking = true; From cd22c439df7a77a77aeb5d2084bc65b8fe35aac9 Mon Sep 17 00:00:00 2001 From: Augustin Trancart Date: Sun, 27 Sep 2026 15:25:48 +0200 Subject: [PATCH 085/117] qgis: fix tests --- nixos/tests/qgis.nix | 1 - 1 file changed, 1 deletion(-) diff --git a/nixos/tests/qgis.nix b/nixos/tests/qgis.nix index bc6866b00326..fbf6ddfb3dca 100644 --- a/nixos/tests/qgis.nix +++ b/nixos/tests/qgis.nix @@ -90,7 +90,6 @@ import ./make-test-python.nix ( # test server machine.succeed("${qgisPackage}/bin/qgis_mapserver --version | grep 'QGIS ${qgisPackage.version}'") - machine.succeed("curl --head http://localhost | grep 'Server:.*${qgisPackage.version}'") machine.succeed("curl http://localhost/index.json | grep 'Landing page as JSON'") ''; } From c6439d7af9e1447d7b3bd1c40b738fb2c133c47b Mon Sep 17 00:00:00 2001 From: Uwe Schlifkowitz Date: Mon, 28 Sep 2026 09:03:09 +0200 Subject: [PATCH 086/117] maintainer: update email for 365tuwe --- maintainers/maintainer-list.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index a0c2320711c3..3bdb8dac247e 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -251,7 +251,7 @@ }; _365tuwe = { name = "Uwe Schlifkowitz"; - email = "supertuwe@gmail.com"; + email = "uwe.schlifkowitz@secunet.com"; github = "365tuwe"; githubId = 10263091; }; From 4b383bc744c9d1035165066ab80a83f4272b4ead Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 28 Sep 2026 07:12:31 +0000 Subject: [PATCH 087/117] steelix: 0-unstable-2026-05-21 -> 0-unstable-2026-09-26 --- pkgs/by-name/st/steelix/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/st/steelix/package.nix b/pkgs/by-name/st/steelix/package.nix index 01b7f2968c0c..8493a02bfd95 100644 --- a/pkgs/by-name/st/steelix/package.nix +++ b/pkgs/by-name/st/steelix/package.nix @@ -35,18 +35,18 @@ let steelix-unwrapped = helix-unwrapped.overrideAttrs ( finalAttrs: _: { pname = "steelix-unwrapped"; - version = "0-unstable-2026-05-21"; + version = "0-unstable-2026-09-26"; src = fetchFromGitHub { owner = "mattwparas"; repo = "helix"; - rev = "4d86612df48447088ef4190bf503fd54a7562aa9"; - hash = "sha256-qAUODNxHM9K6CrRCFgfBcbqzRd+YHiWn9fEfmIzrohA="; + rev = "df595c7dc5729e2712c79dd2e35977e3474b3ec6"; + hash = "sha256-zWOzgArhg4PCgi8AMKLtcttBtchlQJay6atEpobCASk="; }; cargoDeps = rustPlatform.fetchCargoVendor { inherit (finalAttrs) src pname version; - hash = "sha256-6bu8sIM4So3AbnHHYbh8uu+rEB4IjMQjDgh7/AkLQs0="; + hash = "sha256-h4HkOppmseHzX1gHUGO1XSwrg4uCJ4PjmI/3WsYp2C4="; }; cargoBuildFlags = [ From 817ed95c2ffe0fb9f3dbe63049159bbd5fe19069 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 28 Sep 2026 07:26:13 +0000 Subject: [PATCH 088/117] go-judge: 1.12.3 -> 1.13.0 --- pkgs/by-name/go/go-judge/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/go/go-judge/package.nix b/pkgs/by-name/go/go-judge/package.nix index 3d7320b78e07..60182d2dcf2c 100644 --- a/pkgs/by-name/go/go-judge/package.nix +++ b/pkgs/by-name/go/go-judge/package.nix @@ -6,16 +6,16 @@ buildGoModule (finalAttrs: { pname = "go-judge"; - version = "1.12.3"; + version = "1.13.0"; src = fetchFromGitHub { owner = "criyle"; repo = "go-judge"; rev = "v${finalAttrs.version}"; - hash = "sha256-uRwB6Ir1A+RmSqeOp6rCdFnJgRqrrbatRFgKHzFtF9o="; + hash = "sha256-uxFpW4c1xISbgLUR1wDDoR0/+wUT326e69nTDGqCdOQ="; }; - vendorHash = "sha256-jbV58oJX9Bddq5aqi9rfpkrPdGmlyMM6CKrQf1C9ZgI="; + vendorHash = "sha256-qYB3IutGOKHiTt8kwqexgSyut6xbigdYw6A1I1pyG44="; tags = [ "nomsgpack" From d88ac2ec0086682f507e3a0e80b4103f929609ea Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 28 Sep 2026 07:28:41 +0000 Subject: [PATCH 089/117] goshs: 2.1.6 -> 2.1.7 --- pkgs/by-name/go/goshs/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/go/goshs/package.nix b/pkgs/by-name/go/goshs/package.nix index a34eb5e38b90..c67eee670808 100644 --- a/pkgs/by-name/go/goshs/package.nix +++ b/pkgs/by-name/go/goshs/package.nix @@ -8,16 +8,16 @@ buildGoModule (finalAttrs: { pname = "goshs"; - version = "2.1.6"; + version = "2.1.7"; src = fetchFromGitHub { owner = "goshs-labs"; repo = "goshs"; tag = "v${finalAttrs.version}"; - hash = "sha256-0d4iB6Mtann0OZd/KyWnwq7+fCcWEibAzHSYe30Mce0="; + hash = "sha256-RnpzlAH5wbes40FkCvDhzwbg6oaHbMkg2I/U7Lm9IFs="; }; - vendorHash = "sha256-E+GZn7Trnz3KqzTsEfavWxP1dhsGPx4PyYYae8wjCb4="; + vendorHash = "sha256-G8QG2h44d8IjhfDGTt8ObTXOzv9jnz8HHB/Ctr4wU8c="; patches = [ # No upstream fix yet; remove when updating to a release that uses goldmark 1.7.17 or later. From 14377089fec29d9701d26c5900981da37abdf522 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 28 Sep 2026 08:02:34 +0000 Subject: [PATCH 090/117] python3Packages.soco: 0.31.2 -> 0.31.4 --- pkgs/development/python-modules/soco/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/soco/default.nix b/pkgs/development/python-modules/soco/default.nix index 9a79fa651032..44887ef0c547 100644 --- a/pkgs/development/python-modules/soco/default.nix +++ b/pkgs/development/python-modules/soco/default.nix @@ -18,14 +18,14 @@ buildPythonPackage (finalAttrs: { pname = "soco"; - version = "0.31.2"; + version = "0.31.4"; pyproject = true; src = fetchFromGitHub { owner = "SoCo"; repo = "SoCo"; tag = "v${finalAttrs.version}"; - hash = "sha256-TCnKzAOrpQxh8JaBkoPs2e81xUS/iQ8D/Qtt3WU9J1k="; + hash = "sha256-v24UzJ+/TlEBmNYP51UTI96bvi10E5orNFKS5q1bSyE="; }; build-system = [ setuptools ]; From 6025007e0e2267beda27e5d52d598c79162fd5e7 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Sat, 26 Sep 2026 21:24:57 +0100 Subject: [PATCH 091/117] nixos-version: add --kernel-version and --specialisations --- nixos/modules/installer/tools/nixos-version.sh | 15 +++++++++++++++ nixos/modules/installer/tools/tools.nix | 10 +++++++++- 2 files changed, 24 insertions(+), 1 deletion(-) diff --git a/nixos/modules/installer/tools/nixos-version.sh b/nixos/modules/installer/tools/nixos-version.sh index 39e34a3718cb..c9ca4a634d82 100644 --- a/nixos/modules/installer/tools/nixos-version.sh +++ b/nixos/modules/installer/tools/nixos-version.sh @@ -20,6 +20,21 @@ case "$1" in fi echo "@configurationRevision@" ;; + --kernel-version) + if [[ "@kernelVersion@" =~ "@" ]]; then + echo "$0: kernel version is unknown" >&2 + exit 1 + fi + echo "@kernelVersion@" + ;; + --specialisations) + if [[ -z "@specialisations@" ]]; then + echo "$0: no specialisations found" >&2 + exit 1 + else + echo "@specialisations@" + fi + ;; --json) cat < Date: Sat, 26 Sep 2026 21:25:22 +0100 Subject: [PATCH 092/117] nixos-rebuild-ng: extract kernelVersion, nixosVersion and specialisation from nixos-version Before this PR we needed to parse the filesystem to extract some information to build the `nixos-rebuild list-generation` output. We already used `nixos-version --configuration-revision` to extract the `configurationRevision` key, but now we can use the `nixos-version --json` output to extract all the information we need, now that the previous commit added support for `kernelVersion` and `specialisation` fields (`nixosVersion` was already available before hand). This is a first step to allow `nixos-rebuild list-generation` to target remote hosts. The second step will come after a new Nix version is released with https://github.com/NixOS/nix/issues/5144 and that version is used by default by nixpkgs. After that we can also run the `nix-env --list-generations` remotely to get all generations before scrapping the additional information needed by `nixos-rebuild list-generations`. --- .../src/nixos_rebuild/models.py | 12 +++- .../nixos-rebuild-ng/src/nixos_rebuild/nix.py | 35 ++++----- .../ni/nixos-rebuild-ng/src/tests/test_nix.py | 71 +++++++++++++++++-- 3 files changed, 90 insertions(+), 28 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py index 56aecb868bb6..61b28050e6cf 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py @@ -5,7 +5,7 @@ from argparse import Namespace from dataclasses import dataclass from enum import Enum from pathlib import Path -from typing import Any, ClassVar, Self, TypedDict, override +from typing import Any, ClassVar, NotRequired, Self, TypedDict, override from . import nix from .process import Remote, run_wrapper @@ -170,6 +170,16 @@ class FlakeMetadataJson(TypedDict): resolvedUrl: str +class NixOSVersionJson(TypedDict): + nixosVersion: str + # Those keys are only set in nixos-version when it exists + configurationRevision: NotRequired[str] + kernelVersion: NotRequired[str] + # The reason this key are NotRequired even when they're always set in + # nixos-version is because older generations may not have them yet + specialisations: NotRequired[list[str]] + + @dataclass(frozen=True) class GroupedNixArgs: build_flags: Args diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py index 40cd1ad9e345..3616b7c9f1e7 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py @@ -24,6 +24,7 @@ from .models import ( GenerationJson, ImageVariants, NixOSRebuildError, + NixOSVersionJson, Profile, Remote, ) @@ -509,37 +510,25 @@ def list_generations(profile: Profile) -> list[GenerationJson]: generation_path = ( profile.path.parent / f"{profile.path.name}-{generation.id}-link" ) + + j: NixOSVersionJson try: - nixos_version = (generation_path / "nixos-version").read_text().strip() - except OSError as ex: - logger.debug("could not get nixos-version: %s", ex) - nixos_version = "Unknown" - try: - kernel_version = next( - (generation_path / "kernel-modules/lib/modules").iterdir() - ).name - except OSError as ex: - logger.debug("could not get kernel version: %s", ex) - kernel_version = "Unknown" - specialisations = [ - s.name for s in (generation_path / "specialisation").glob("*") if s.is_dir() - ] - try: - configuration_revision = run_wrapper( - [generation_path / "sw/bin/nixos-version", "--configuration-revision"], + result = run_wrapper( + [generation_path / "sw/bin/nixos-version", "--json"], capture_output=True, - ).stdout.strip() + ).stdout + j = json.loads(result) except (OSError, CalledProcessError) as ex: logger.debug("could not get configuration revision: %s", ex) - configuration_revision = "Unknown" + j = {"nixosVersion": "Unknown"} return GenerationJson( generation=generation.id, date=generation.timestamp, - nixosVersion=nixos_version, - kernelVersion=kernel_version, - configurationRevision=configuration_revision, - specialisations=specialisations, + nixosVersion=j["nixosVersion"], + kernelVersion=j.get("kernelVersion", "Unknown"), + configurationRevision=j.get("configurationRevision", "Unknown"), + specialisations=j.get("specialisations", []), current=generation.current, ) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py index 51b4cde3bfe0..3b243678bf07 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py @@ -3,7 +3,7 @@ import sys import textwrap import uuid from pathlib import Path -from subprocess import PIPE, CompletedProcess +from subprocess import PIPE, CalledProcessError, CompletedProcess from typing import Any from unittest.mock import ANY, Mock, call, patch @@ -584,9 +584,72 @@ def test_get_generations_from_nix_env(tmp_path: Path) -> None: ), ], ) -def test_list_generations(mock_get_generations: Mock, tmp_path: Path) -> None: - # Probably better to test this function in a real system, this test is - # mostly to make sure it doesn't break horribly +@patch(get_qualified_name(n.run_wrapper, n), autospec=True) +def test_list_generations( + mock_run: Mock, + mock_get_generations: Mock, + tmp_path: Path, +) -> None: + mock_run.return_value = CompletedProcess( + args=[], + returncode=0, + stdout=json.dumps({"nixosVersion": "26.11.20260926.dirty"}), + ) + assert n.list_generations(m.Profile("system", tmp_path)) == [ + { + "configurationRevision": "Unknown", + "current": True, + "date": "2024-11-07 23:54:17", + "generation": 2, + "kernelVersion": "Unknown", + "nixosVersion": "26.11.20260926.dirty", + "specialisations": [], + }, + { + "configurationRevision": "Unknown", + "current": False, + "date": "2024-11-07 23:54:17", + "generation": 1, + "kernelVersion": "Unknown", + "nixosVersion": "26.11.20260926.dirty", + "specialisations": [], + }, + ] + + mock_run.return_value = CompletedProcess( + args=[], + returncode=0, + stdout=json.dumps( + { + "configurationRevision": "dirty", + "kernelVersion": "7.2.8", + "nixosVersion": "26.11.20260926.dirty", + "specialisations": [], + } + ), + ) + assert n.list_generations(m.Profile("system", tmp_path)) == [ + { + "configurationRevision": "dirty", + "current": True, + "date": "2024-11-07 23:54:17", + "generation": 2, + "kernelVersion": "7.2.8", + "nixosVersion": "26.11.20260926.dirty", + "specialisations": [], + }, + { + "configurationRevision": "dirty", + "current": False, + "date": "2024-11-07 23:54:17", + "generation": 1, + "kernelVersion": "7.2.8", + "nixosVersion": "26.11.20260926.dirty", + "specialisations": [], + }, + ] + + mock_run.side_effect = CalledProcessError(returncode=1, cmd=[]) assert n.list_generations(m.Profile("system", tmp_path)) == [ { "configurationRevision": "Unknown", From f24bbb01a4677f150960675062a755c47a5c4793 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Mon, 28 Sep 2026 10:48:33 +0200 Subject: [PATCH 093/117] nerva: 1.70.0 -> 1.70.1 Diff: https://github.com/praetorian-inc/nerva/compare/v1.70.0...v1.70.1 Changelog: https://github.com/praetorian-inc/nerva/blob/v1.70.1/CHANGELOG.md --- pkgs/by-name/ne/nerva/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ne/nerva/package.nix b/pkgs/by-name/ne/nerva/package.nix index 2f1c0408e8e0..b91bc4300e2b 100644 --- a/pkgs/by-name/ne/nerva/package.nix +++ b/pkgs/by-name/ne/nerva/package.nix @@ -6,13 +6,13 @@ buildGo127Module (finalAttrs: { pname = "nerva"; - version = "1.70.0"; + version = "1.70.1"; src = fetchFromGitHub { owner = "praetorian-inc"; repo = "nerva"; tag = "v${finalAttrs.version}"; - hash = "sha256-WKGcn1F2uF5vUVVL8oBDmBG5434bLXzCyyFL95Y3t/Y="; + hash = "sha256-8XEoNhczrDQ2vrgimfYxJ3jQFGsZmfM7vWTa6vfOmW0="; }; vendorHash = "sha256-Fjxs+JKq9Lv9wBQEjvSlEw9cpgm/Ye1l4iqdjRa8+X8="; From 0d9c0797313a3a96420d0a22ebe8407c664a35f6 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 28 Sep 2026 08:55:52 +0000 Subject: [PATCH 094/117] mongosh: 2.11.1 -> 2.12.0 --- pkgs/by-name/mo/mongosh/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/mo/mongosh/package.nix b/pkgs/by-name/mo/mongosh/package.nix index e91e5709ca8b..4b12a78e1f87 100644 --- a/pkgs/by-name/mo/mongosh/package.nix +++ b/pkgs/by-name/mo/mongosh/package.nix @@ -6,16 +6,16 @@ buildNpmPackage (finalAttrs: { pname = "mongosh"; - version = "2.11.1"; + version = "2.12.0"; src = fetchFromGitHub { owner = "mongodb-js"; repo = "mongosh"; tag = "v${finalAttrs.version}"; - hash = "sha256-h1OUm4fPYdDpU1K1a65Q5xeBHEryA1O05k0wr/x/yUQ="; + hash = "sha256-P6gT2+cFuPYc3oN2O0h/83Tz7J65tQfD92GDLBybY3M="; }; - npmDepsHash = "sha256-/pHYIFybLfpj5B88T+B1stDnwMEOBIhIRX83ipSIAvo="; + npmDepsHash = "sha256-UhSze1kTMzJ2OuEEn6D0oTtuV5titsaFrWS/Gm1HJtU="; postPatch = '' # Disable telemetry by default; users can still opt in via enableTelemetry(). From f2b8e80ec8d23a6b6b655f8a92fd6298063a80fe Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Mon, 28 Sep 2026 08:54:35 +0000 Subject: [PATCH 095/117] config: add enableCudaDriverCompat --- .../cuda-modules/packages/cuda_compat.nix | 12 +++++++++++- pkgs/top-level/config.nix | 11 +++++++++++ 2 files changed, 22 insertions(+), 1 deletion(-) diff --git a/pkgs/development/cuda-modules/packages/cuda_compat.nix b/pkgs/development/cuda-modules/packages/cuda_compat.nix index 09f04f143322..08ba2218f84a 100644 --- a/pkgs/development/cuda-modules/packages/cuda_compat.nix +++ b/pkgs/development/cuda-modules/packages/cuda_compat.nix @@ -1,4 +1,8 @@ -{ buildRedist }: +{ + buildRedist, + config, + lib, +}: buildRedist { redistName = "cuda"; pname = "cuda_compat"; @@ -16,5 +20,11 @@ buildRedist { meta = { description = "Provides minor version forward compatibility for the CUDA runtime"; homepage = "https://docs.nvidia.com/deploy/cuda-compatibility"; + problems = lib.optionalAttrs config.enableCudaDriverCompat { + cuda-compat-disabled = { + kind = "broken"; + message = "cuda_compat must be explicitly enabled using config.enableCudaDriverCompat."; + }; + }; }; } diff --git a/pkgs/top-level/config.nix b/pkgs/top-level/config.nix index 1e776f3e8774..a08f8341cc5b 100644 --- a/pkgs/top-level/config.nix +++ b/pkgs/top-level/config.nix @@ -348,6 +348,17 @@ let ''; }; + enableCudaDriverCompat = mkOption { + type = types.bool; + default = false; + description = '' + Whether to enable the cuda_compat package which provides user mode backports of newer kernel + mode driver functionality. + Ony enable this if your host driver is older than the driver provided by the default + cudaPackages package set. + ''; + }; + replaceBootstrapFiles = mkMassRebuild { type = types.functionTo (types.attrsOf types.package); default = lib.id; From 9195c8c1d33c1ba7d407c33896767bf17e1be765 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 28 Sep 2026 09:01:26 +0000 Subject: [PATCH 096/117] graff: 0.0.299 -> 0.0.302.6 --- pkgs/by-name/gr/graff/manifest.json | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/pkgs/by-name/gr/graff/manifest.json b/pkgs/by-name/gr/graff/manifest.json index cb36ad95da69..2c5b6d3cfbd9 100644 --- a/pkgs/by-name/gr/graff/manifest.json +++ b/pkgs/by-name/gr/graff/manifest.json @@ -1,21 +1,21 @@ { - "version": "0.0.299", + "version": "0.0.302.6", "assets": { "x86_64-linux": { - "url": "https://github.com/justrach/codegraff/releases/download/v0.0.299/graff-x86_64-linux.tar.gz", - "hash": "sha256-qVS6Q3ccVgaJMaCnRX44JRZulQciS02R+D3+rmt73wI=" + "url": "https://github.com/justrach/codegraff/releases/download/v0.0.302.6/graff-x86_64-linux.tar.gz", + "hash": "sha256-d7J21dWTRlkdca4JCqoQFXPz/TVXBuo07JE7IsFErvg=" }, "aarch64-linux": { - "url": "https://github.com/justrach/codegraff/releases/download/v0.0.299/graff-aarch64-linux.tar.gz", - "hash": "sha256-GHGgCopNQMNKiRv/LElYbRVYif8L9TLUoUsku0uEPfU=" + "url": "https://github.com/justrach/codegraff/releases/download/v0.0.302.6/graff-aarch64-linux.tar.gz", + "hash": "sha256-aJAs7dmk5B6OAJQagJrgfaJ1yO3q5pVms630OBtcehQ=" }, "aarch64-darwin": { - "url": "https://github.com/justrach/codegraff/releases/download/v0.0.299/graff-aarch64-macos.tar.gz", - "hash": "sha256-gyGFMTS8wH9cFGRBnCJtq0GtvxCg4VzNoVTnET+ELQ4=" + "url": "https://github.com/justrach/codegraff/releases/download/v0.0.302.6/graff-aarch64-macos.tar.gz", + "hash": "sha256-6D4EsH0whHy3F1fhpyQ9eXVJ54HabS0zU1fJaN7YH2k=" }, "x86_64-darwin": { - "url": "https://github.com/justrach/codegraff/releases/download/v0.0.299/graff-x86_64-macos.tar.gz", - "hash": "sha256-akWs/kk/iptGnzDzzerdQbZoFF9k/HcguQvpvdnoSPs=" + "url": "https://github.com/justrach/codegraff/releases/download/v0.0.302.6/graff-x86_64-macos.tar.gz", + "hash": "sha256-IcsCVeQt1zCYPpXN7lpUXMOeEmL8lTt3SAt5oKf8pCw=" } } } From b19cbd07b1a60f898128604b0876960e2c6246b7 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Sun, 27 Sep 2026 08:43:25 +0100 Subject: [PATCH 097/117] nixos-version: update manpage --- .../installer/tools/manpages/nixos-version.8 | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/nixos/modules/installer/tools/manpages/nixos-version.8 b/nixos/modules/installer/tools/manpages/nixos-version.8 index f661611599fb..e2851852cf19 100644 --- a/nixos/modules/installer/tools/manpages/nixos-version.8 +++ b/nixos/modules/installer/tools/manpages/nixos-version.8 @@ -72,6 +72,20 @@ $ nixos-version --configuration-revision aa314ebd1592f6cdd53cb5bba8bcae97d9323de8 .Ed . +.It Fl -kernel-version +Show the kernel version, e.g. +.Bd -literal -offset indent +$ nixos-version --kernel-version +7.2.5 +.Ed +. +.It Fl -specialisations +Show specialisations, separated by spaces, if available, e.g. +.Bd -literal -offset indent +$ nixos-version --specialisations +foo bar +.Ed +. .It Fl -json Print a JSON representation of the versions of NixOS and the top-level configuration flake. From 896eba9b0d68dbe6f75b44df7e60651f9f8b429d Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Mon, 28 Sep 2026 09:43:06 +0100 Subject: [PATCH 098/117] nixos-rebuild-ng: make nixosVersion key NotRequired --- .../by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py | 6 ++---- pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py | 5 ++--- 2 files changed, 4 insertions(+), 7 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py index 61b28050e6cf..186b25503dc4 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py @@ -171,12 +171,10 @@ class FlakeMetadataJson(TypedDict): class NixOSVersionJson(TypedDict): - nixosVersion: str - # Those keys are only set in nixos-version when it exists + # Keys are NotRequired here so we need to parse them safely + nixosVersion: NotRequired[str] configurationRevision: NotRequired[str] kernelVersion: NotRequired[str] - # The reason this key are NotRequired even when they're always set in - # nixos-version is because older generations may not have them yet specialisations: NotRequired[list[str]] diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py index 3616b7c9f1e7..d157839a38b7 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py @@ -511,7 +511,7 @@ def list_generations(profile: Profile) -> list[GenerationJson]: profile.path.parent / f"{profile.path.name}-{generation.id}-link" ) - j: NixOSVersionJson + j: NixOSVersionJson = {} try: result = run_wrapper( [generation_path / "sw/bin/nixos-version", "--json"], @@ -520,12 +520,11 @@ def list_generations(profile: Profile) -> list[GenerationJson]: j = json.loads(result) except (OSError, CalledProcessError) as ex: logger.debug("could not get configuration revision: %s", ex) - j = {"nixosVersion": "Unknown"} return GenerationJson( generation=generation.id, date=generation.timestamp, - nixosVersion=j["nixosVersion"], + nixosVersion=j.get("nixosVersion", "Unknown"), kernelVersion=j.get("kernelVersion", "Unknown"), configurationRevision=j.get("configurationRevision", "Unknown"), specialisations=j.get("specialisations", []), From 852e4543e58344ff456394d25e7ce79fb124789f Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Mon, 28 Sep 2026 09:20:30 +0000 Subject: [PATCH 099/117] cudaPackages.cuda_compat: fix meta.problems condition --- pkgs/development/cuda-modules/packages/cuda_compat.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/development/cuda-modules/packages/cuda_compat.nix b/pkgs/development/cuda-modules/packages/cuda_compat.nix index 08ba2218f84a..76239b729cb2 100644 --- a/pkgs/development/cuda-modules/packages/cuda_compat.nix +++ b/pkgs/development/cuda-modules/packages/cuda_compat.nix @@ -20,7 +20,7 @@ buildRedist { meta = { description = "Provides minor version forward compatibility for the CUDA runtime"; homepage = "https://docs.nvidia.com/deploy/cuda-compatibility"; - problems = lib.optionalAttrs config.enableCudaDriverCompat { + problems = lib.optionalAttrs (!config.enableCudaDriverCompat) { cuda-compat-disabled = { kind = "broken"; message = "cuda_compat must be explicitly enabled using config.enableCudaDriverCompat."; From 3df7f5b1d388e019e01cd837fac95983030c5b01 Mon Sep 17 00:00:00 2001 From: Jonas Heinrich Date: Wed, 2 Sep 2026 12:46:45 +0200 Subject: [PATCH 100/117] nixos/wordpress: auto migrate database --- .../manual/release-notes/rl-2611.section.md | 2 ++ nixos/modules/services/web-apps/wordpress.nix | 26 +++++++++++++++++++ 2 files changed, 28 insertions(+) diff --git a/nixos/doc/manual/release-notes/rl-2611.section.md b/nixos/doc/manual/release-notes/rl-2611.section.md index d8f5a489908f..3e5d224e5a3f 100644 --- a/nixos/doc/manual/release-notes/rl-2611.section.md +++ b/nixos/doc/manual/release-notes/rl-2611.section.md @@ -356,6 +356,8 @@ - `boot.loader.systemd-boot` gained support for [Automatic Boot Assessment](https://systemd.io/AUTOMATIC_BOOT_ASSESSMENT/) via the new [`boot.loader.systemd-boot.bootCounting`](#opt-boot.loader.systemd-boot.bootCounting.enable) options, allowing automatic detection of and recovery from bad NixOS generations. As part of this change, boot loader entries on the ESP/XBOOTLDR partition are now named `nixos-.conf` instead of `nixos-generation-.conf`; existing entries are migrated automatically on the next `nixos-rebuild boot`/`switch`. +- The Wordpress module now supports auto database migrations using wp-cli, which gets triggered after every package version update. + - `services.nginx` gained a [`lua`](#opt-services.nginx.lua.enable) option to enable Lua scripting via OpenResty's lua-nginx-module on a stock nginx, configuring `lua_package_path`/`lua_package_cpath` from the packages listed in [`services.nginx.lua.extraPackages`](#opt-services.nginx.lua.extraPackages). Use this to add Lua to a regular nginx; for the full OpenResty platform (libraries that rely on its bundled lualib, such as `lua-resty-openidc`), set `services.nginx.package` to `pkgs.openresty` instead — the option configures the Lua search path for it too. - `services.nginx.virtualHosts..locations.` gained a new `useGrpcErrorPages` option. If enabled, it sets up error pages that are valid gRPC messages. This is useful if you proxy gRPC and want to emit errors from nginx, for example when adding authentication on top. diff --git a/nixos/modules/services/web-apps/wordpress.nix b/nixos/modules/services/web-apps/wordpress.nix index 6f44a7e84653..43119592e972 100644 --- a/nixos/modules/services/web-apps/wordpress.nix +++ b/nixos/modules/services/web-apps/wordpress.nix @@ -555,7 +555,33 @@ in before = [ "phpfpm-wordpress-${hostName}.service" ]; after = optional cfg.database.createLocally "mysql.service"; script = secretsScript (stateDir hostName); + serviceConfig = { + Type = "oneshot"; + User = user; + Group = webserver.group; + }; + }) + ) eachSite) + (mapAttrs' ( + hostName: cfg: + (nameValuePair "wordpress-migrate-database-${hostName}" { + wantedBy = [ "multi-user.target" ]; + after = [ + "phpfpm-wordpress-${hostName}.service" + ] + ++ optional cfg.database.createLocally "mysql.service"; + script = '' + # Auto migrate database after version update + versionFile="${stateDir hostName}/src-version" + version=$(cat "$versionFile" 2>/dev/null || echo 0) + if [[ $version != 0 && $version != ${cfg.package.version} ]]; then + echo "Executing database migration" + ${lib.getExe pkgs.wp-cli} --path="${cfg.finalPackage}/share/wordpress" \ + --skip-plugins --skip-themes core update-db + fi + echo ${cfg.package.version} > "$versionFile" + ''; serviceConfig = { Type = "oneshot"; User = user; From e1b3c9afa5f53744f2563f810945aa4a074b4f8b Mon Sep 17 00:00:00 2001 From: Ali Heydari Date: Sun, 27 Sep 2026 17:08:59 +0330 Subject: [PATCH 101/117] antigravity-acp: 1.1.1 -> 1.2.1 --- pkgs/by-name/an/antigravity-acp/package.nix | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/pkgs/by-name/an/antigravity-acp/package.nix b/pkgs/by-name/an/antigravity-acp/package.nix index 344019d271ca..ac17cc77e372 100644 --- a/pkgs/by-name/an/antigravity-acp/package.nix +++ b/pkgs/by-name/an/antigravity-acp/package.nix @@ -10,16 +10,16 @@ let sources = { x86_64-linux = { - url = "https://dl.google.com/agy-extensions/releases/linux/agy-acp-server-agy_acp_server_1.1.1-linux-x86_64.zip"; - hash = "sha256-OPYtAbMt6wkHs9OacewwH9Njafb/0c8mLUrzhRd/ed8="; + url = "https://dl.google.com/agy-extensions/releases/linux/agy-acp-server-1.2.1-linux-x86_64.zip"; + hash = "sha256-n78L1YSiZHgWH2N8q9dRE/clQchC0Uj1eO8aap7cuEM="; }; aarch64-linux = { - url = "https://dl.google.com/agy-extensions/releases/linux/agy-acp-server-agy_acp_server_1.1.1-linux-arm64.zip"; - hash = "sha256-7WnmSzCPyxI6tUvzJ3v5yw1lEGT4hepaqw/1IMcXU5g="; + url = "https://dl.google.com/agy-extensions/releases/linux/agy-acp-server-1.2.1-linux-arm64.zip"; + hash = "sha256-fn70CIvBheGvQgQCng9OxCEK8gck8/8mIYasC86mqg4="; }; aarch64-darwin = { - url = "https://dl.google.com/agy-extensions/releases/macos/agy-acp-server-agy_acp_server_1.1.1-darwin-arm64.zip"; - hash = "sha256-/fqRVlLNt7qAhcyP/+0HLL4AklGqLJUaq92geowooYk="; + url = "https://dl.google.com/agy-extensions/releases/macos/agy-acp-server-1.2.1-darwin-arm64.zip"; + hash = "sha256-D6uZOIEuazKztUPmXk86ACXO73VUE9sTVC2am4HqgDw="; }; }; @@ -29,7 +29,7 @@ let in stdenv.mkDerivation { pname = "antigravity-acp"; - version = "1.1.1"; # https://github.com/agentclientprotocol/registry/blob/main/antigravity-acp/agent.json + version = "1.2.1"; # https://github.com/agentclientprotocol/registry/blob/main/antigravity-acp/agent.json src = fetchurl { inherit (srcInfo) url hash; From 7a109bef650bfa6faf5e228d787aba0676b55408 Mon Sep 17 00:00:00 2001 From: Pratham Patel Date: Tue, 22 Sep 2026 23:54:43 +0530 Subject: [PATCH 102/117] cudaPackages.buildRedist: match major.minor CUDA variants --- .../cuda-modules/_cuda/lib/cuda.nix | 18 ++++++++++++------ .../cuda-modules/_cuda/lib/default.nix | 2 +- .../cuda-modules/buildRedist/default.nix | 18 +++++++++++++----- pkgs/development/cuda-modules/default.nix | 1 + 4 files changed, 27 insertions(+), 12 deletions(-) diff --git a/pkgs/development/cuda-modules/_cuda/lib/cuda.nix b/pkgs/development/cuda-modules/_cuda/lib/cuda.nix index 2ce8bbcc0d0a..15667283e282 100644 --- a/pkgs/development/cuda-modules/_cuda/lib/cuda.nix +++ b/pkgs/development/cuda-modules/_cuda/lib/cuda.nix @@ -73,14 +73,14 @@ lowerBoundSatisfied && upperBoundSatisfied; /** - Generates a CUDA variant name from a version. + Generates CUDA variant names from a version. NOTE: No guarantees are made about this function's stability. You may use it at your own risk. # Type ``` - _mkCudaVariant :: (version :: String) -> String + _mkCudaVariants :: (version :: String) -> [ String ] ``` # Inputs @@ -92,15 +92,21 @@ # Examples :::{.example} - ## `_cuda.lib._mkCudaVariant` usage examples + ## `_cuda.lib._mkCudaVariants` usage examples ```nix - _mkCudaVariant "11.0" - => "cuda11" + _mkCudaVariants "13.2.2" + => [ "cuda13.2.2" "cuda13.2" "cuda13" ] ``` ::: */ - _mkCudaVariant = version: "cuda${lib.versions.major version}"; + _mkCudaVariants = + cudaMajorMinorPatchVersion: + lib.map (f: "cuda" + (f cudaMajorMinorPatchVersion)) [ + lib.id + lib.versions.majorMinor + lib.versions.major + ]; /** A predicate which, given a package, returns true if the package has a free license or one of NVIDIA's licenses. diff --git a/pkgs/development/cuda-modules/_cuda/lib/default.nix b/pkgs/development/cuda-modules/_cuda/lib/default.nix index 53ee8a1247a3..3efe83316499 100644 --- a/pkgs/development/cuda-modules/_cuda/lib/default.nix +++ b/pkgs/development/cuda-modules/_cuda/lib/default.nix @@ -14,7 +14,7 @@ inherit (import ./cuda.nix { inherit _cuda lib; }) _cudaCapabilityIsDefault _cudaCapabilityIsSupported - _mkCudaVariant + _mkCudaVariants allowUnfreeCudaPredicate ; diff --git a/pkgs/development/cuda-modules/buildRedist/default.nix b/pkgs/development/cuda-modules/buildRedist/default.nix index dba14cd7c27c..bdf8a75494a1 100644 --- a/pkgs/development/cuda-modules/buildRedist/default.nix +++ b/pkgs/development/cuda-modules/buildRedist/default.nix @@ -6,6 +6,7 @@ autoAddDriverRunpath, autoPatchelfHook, backendStdenv, + cudaMajorMinorPatchVersion, cudaMajorMinorVersion, cudaMajorVersion, cudaNamePrefix, @@ -21,7 +22,7 @@ }: let inherit (backendStdenv) hostRedistSystem; - inherit (_cuda.lib) getNixSystems _mkCudaVariant mkRedistUrl; + inherit (_cuda.lib) getNixSystems _mkCudaVariants mkRedistUrl; inherit (lib.attrsets) foldlAttrs getDev @@ -70,7 +71,7 @@ let getSupportedReleases = let - desiredCudaVariant = _mkCudaVariant cudaMajorVersion; + desiredCudaVariants = _mkCudaVariants cudaMajorMinorPatchVersion; in release: # Always show preference to the "source", then "linux-all" redistSystem if they are available, as they are @@ -92,9 +93,16 @@ let acc # If the value is an attribute, and when hasCudaVariants is true it has the relevant CUDA variant, # then add it to the set. - // optionalAttrs (isAttrs value && (hasCudaVariants -> hasAttr desiredCudaVariant value)) { - ${name} = value.${desiredCudaVariant} or value; - } + // ( + let + desiredCudaVariant = findFirst ( + variant: isAttrs value && hasAttr variant value + ) null desiredCudaVariants; + in + optionalAttrs (isAttrs value && (hasCudaVariants -> desiredCudaVariant != null)) { + ${name} = if desiredCudaVariant == null then value else value.${desiredCudaVariant}; + } + ) ) { } release; getPreferredRelease = diff --git a/pkgs/development/cuda-modules/default.nix b/pkgs/development/cuda-modules/default.nix index 2acd56edef5f..714921dc479d 100644 --- a/pkgs/development/cuda-modules/default.nix +++ b/pkgs/development/cuda-modules/default.nix @@ -146,6 +146,7 @@ let inherit (finalCudaPackages) autoAddCudaCompatRunpath backendStdenv + cudaMajorMinorPatchVersion cudaMajorMinorVersion cudaMajorVersion cudaNamePrefix From c76523c9bba19fed65c04bc1d2e288f54fd64686 Mon Sep 17 00:00:00 2001 From: Raito Bezarius Date: Mon, 28 Sep 2026 11:25:25 +0200 Subject: [PATCH 103/117] libucontext: build the hand-written asm files with -Wa,--noexecstack meson.build omits the flag the Makefile passes, giving every static consumer (e.g. pkgsStatic.lix via capnproto) an executable stack. :) Signed-off-by: Raito Bezarius --- pkgs/by-name/li/libucontext/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/li/libucontext/package.nix b/pkgs/by-name/li/libucontext/package.nix index 36c010c7218b..1349bde56c0d 100644 --- a/pkgs/by-name/li/libucontext/package.nix +++ b/pkgs/by-name/li/libucontext/package.nix @@ -23,6 +23,11 @@ stdenv.mkDerivation (finalAttrs: { ninja ]; + # Makefile builds the asm files with -Wa,--noexecstack, meson.build does not. + # If you do not pass it, you get PT_GNU_STACK=RWE on static consumers of the library. + # https://github.com/kaniini/libucontext/issues/83 + env.NIX_CFLAGS_COMPILE = "-Wa,--noexecstack"; + passthru.updateScript = nix-update-script { }; meta = { From 97bf56b78d978b6735d5fb4bc8a72e2e18261bb1 Mon Sep 17 00:00:00 2001 From: Raito Bezarius Date: Mon, 28 Sep 2026 11:26:19 +0200 Subject: [PATCH 104/117] lix: link with -z,noexecstack Defense-in-depth so a dependency cannot give lix an executable stack, like libucontext did. Signed-off-by: Raito Bezarius --- pkgs/tools/package-management/lix/common-lix.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/tools/package-management/lix/common-lix.nix b/pkgs/tools/package-management/lix/common-lix.nix index 0247befc396c..a785d8cf2abc 100644 --- a/pkgs/tools/package-management/lix/common-lix.nix +++ b/pkgs/tools/package-management/lix/common-lix.nix @@ -287,6 +287,10 @@ stdenv.mkDerivation (finalAttrs: { "${finalAttrs.cargoDeps}/source-registry-0" else "lix: no `MESON_PACKAGE_CACHE_DIR`, set `cargoDeps`"; + + # Defense-in-depth: never inherit an executable stack from a dependency. + # It does happen: https://github.com/NixOS/nixpkgs/issues/567777. + NIX_LDFLAGS = "-z,noexecstack"; }; propagatedBuildInputs = [ From 3da6fd3924e075259f0ebd4a08bd777c48733693 Mon Sep 17 00:00:00 2001 From: Jonas Heinrich Date: Sat, 26 Sep 2026 12:02:09 +0200 Subject: [PATCH 105/117] convey: init at 50.2-1 --- pkgs/by-name/co/convey/package.nix | 161 +++++++++++++++++++++++++++++ 1 file changed, 161 insertions(+) create mode 100644 pkgs/by-name/co/convey/package.nix diff --git a/pkgs/by-name/co/convey/package.nix b/pkgs/by-name/co/convey/package.nix new file mode 100644 index 000000000000..3af8f7197948 --- /dev/null +++ b/pkgs/by-name/co/convey/package.nix @@ -0,0 +1,161 @@ +{ + lib, + stdenv, + fetchFromGitLab, + pkg-config, + gtk4, + vala, + enchant, + wrapGAppsHook3, + meson, + ninja, + desktop-file-utils, + gnome-online-accounts, + gsettings-desktop-schemas, + adwaita-icon-theme, + libpeas2, + libsecret, + gmime3, + isocodes, + icu, + libxml2, + gettext, + sqlite, + json-glib, + itstool, + libgee, + webkitgtk_6_0, + python3, + gnutls, + cacert, + xvfb-run, + glibcLocales, + dbus, + shared-mime-info, + libunwind, + folks, + glib-networking, + gobject-introspection, + gspell, + libstemmer, + libytnef, + libhandy, + gsound, + cmake, + gcr_4, + libspelling, + libadwaita, + gst_all_1, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "convey"; + version = "50.2-1"; + + src = fetchFromGitLab { + domain = "gitlab.gnome.org"; + owner = "donnybeelo"; + repo = "convey"; + tag = finalAttrs.version; + hash = "sha256-YFdAhC7xPGaqEdDuv1Kb6b1NHjivfkc+TnXEGhpkdQw="; + }; + + strictDeps = true; + __structuredAttrs = true; + + nativeBuildInputs = [ + desktop-file-utils + gettext + gobject-introspection + itstool + libxml2 # for xmllint for xml-stripblanks preprocessing + meson + ninja + pkg-config + python3 + vala + wrapGAppsHook3 + cmake + ]; + + buildInputs = [ + adwaita-icon-theme + enchant + folks + gcr_4 + glib-networking + gmime3 + gnome-online-accounts + gsettings-desktop-schemas + gsound + gspell + gst_all_1.gst-plugins-bad + gst_all_1.gst-plugins-base + gtk4 + icu + isocodes + json-glib + libadwaita + libgee + libhandy + libpeas2 + libsecret + libspelling + libstemmer + libunwind + libxml2 + libytnef + sqlite + webkitgtk_6_0 + ]; + + nativeCheckInputs = [ + dbus + gnutls # for certtool + cacert # trust store for glib-networking + xvfb-run + glibcLocales # required by Geary.ImapDb.DatabaseTest/utf8_case_insensitive_collation + ]; + + mesonFlags = [ + "-Dprofile=release" + "-Dcontractor=enabled" # install the contractor file (Pantheon specific) + ]; + + postPatch = '' + chmod +x build-aux/git_version.py + patchShebangs build-aux/git_version.py + chmod +x desktop/convey-attach + ''; + + # Some tests time out. + doCheck = false; + + checkPhase = '' + runHook preCheck + + NO_AT_BRIDGE=1 \ + GIO_EXTRA_MODULES=$GIO_EXTRA_MODULES:${glib-networking}/lib/gio/modules \ + HOME=$TMPDIR \ + XDG_DATA_DIRS=$XDG_DATA_DIRS:${gsettings-desktop-schemas}/share/gsettings-schemas/${gsettings-desktop-schemas.name}:${shared-mime-info}/share:${folks}/share/gsettings-schemas/${folks.name} \ + xvfb-run -s '-screen 0 800x600x24' dbus-run-session \ + --config-file=${dbus}/share/dbus-1/session.conf \ + meson test -v --no-stdsplit + + runHook postCheck + ''; + + preFixup = '' + # Add geary to path for geary-attach + gappsWrapperArgs+=(--prefix PATH : "$out/bin") + ''; + + meta = { + homepage = "https://gitlab.gnome.org/donnybeelo/convey"; + changelog = "https://gitlab.gnome.org/donnybeelo/convey/-/blob/${finalAttrs.version}/NEWS?ref_type=tags"; + description = "Mail client for GNOME 3"; + teams = [ lib.teams.gnome ]; + license = lib.licenses.lgpl21Plus; + platforms = lib.platforms.linux; + }; +}) From 716f0c4e1800df5d279366369f3356732853da90 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Mon, 28 Sep 2026 09:58:40 +0100 Subject: [PATCH 106/117] nixos-rebuild-ng: handle JSONDecodeError --- .../nixos-rebuild-ng/src/nixos_rebuild/nix.py | 5 +- .../ni/nixos-rebuild-ng/src/tests/test_nix.py | 67 +++++++++---------- 2 files changed, 36 insertions(+), 36 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py index d157839a38b7..de6d5ff8b60e 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py @@ -511,15 +511,16 @@ def list_generations(profile: Profile) -> list[GenerationJson]: profile.path.parent / f"{profile.path.name}-{generation.id}-link" ) - j: NixOSVersionJson = {} + j: NixOSVersionJson try: result = run_wrapper( [generation_path / "sw/bin/nixos-version", "--json"], capture_output=True, ).stdout j = json.loads(result) - except (OSError, CalledProcessError) as ex: + except (OSError, CalledProcessError, json.JSONDecodeError) as ex: logger.debug("could not get configuration revision: %s", ex) + j = {} return GenerationJson( generation=generation.id, diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py index 3b243678bf07..e65531090a2e 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py @@ -590,65 +590,64 @@ def test_list_generations( mock_get_generations: Mock, tmp_path: Path, ) -> None: - mock_run.return_value = CompletedProcess( - args=[], - returncode=0, - stdout=json.dumps({"nixosVersion": "26.11.20260926.dirty"}), - ) - assert n.list_generations(m.Profile("system", tmp_path)) == [ - { - "configurationRevision": "Unknown", - "current": True, - "date": "2024-11-07 23:54:17", - "generation": 2, - "kernelVersion": "Unknown", - "nixosVersion": "26.11.20260926.dirty", - "specialisations": [], - }, - { - "configurationRevision": "Unknown", - "current": False, - "date": "2024-11-07 23:54:17", - "generation": 1, - "kernelVersion": "Unknown", - "nixosVersion": "26.11.20260926.dirty", - "specialisations": [], - }, - ] - + # happy path mock_run.return_value = CompletedProcess( args=[], returncode=0, stdout=json.dumps( { - "configurationRevision": "dirty", + "configurationRevision": "3f0180ea99a4c8277961825ec5fca2b50a0eca75", "kernelVersion": "7.2.8", - "nixosVersion": "26.11.20260926.dirty", - "specialisations": [], + "nixosVersion": "26.11.20260925.e94cb15", + "specialisations": ["foo", "bar"], } ), ) assert n.list_generations(m.Profile("system", tmp_path)) == [ { - "configurationRevision": "dirty", + "configurationRevision": "3f0180ea99a4c8277961825ec5fca2b50a0eca75", "current": True, "date": "2024-11-07 23:54:17", "generation": 2, "kernelVersion": "7.2.8", - "nixosVersion": "26.11.20260926.dirty", - "specialisations": [], + "nixosVersion": "26.11.20260925.e94cb15", + "specialisations": ["foo", "bar"], }, { - "configurationRevision": "dirty", + "configurationRevision": "3f0180ea99a4c8277961825ec5fca2b50a0eca75", "current": False, "date": "2024-11-07 23:54:17", "generation": 1, "kernelVersion": "7.2.8", - "nixosVersion": "26.11.20260926.dirty", + "nixosVersion": "26.11.20260925.e94cb15", + "specialisations": ["foo", "bar"], + }, + ] + + # parsing invalid JSON + mock_run.return_value = CompletedProcess(args=[], returncode=0, stdout="garbage") + assert n.list_generations(m.Profile("system", tmp_path)) == [ + { + "configurationRevision": "Unknown", + "current": True, + "date": "2024-11-07 23:54:17", + "generation": 2, + "kernelVersion": "Unknown", + "nixosVersion": "Unknown", + "specialisations": [], + }, + { + "configurationRevision": "Unknown", + "current": False, + "date": "2024-11-07 23:54:17", + "generation": 1, + "kernelVersion": "Unknown", + "nixosVersion": "Unknown", "specialisations": [], }, ] + # error calling nixos-version mock_run.side_effect = CalledProcessError(returncode=1, cmd=[]) assert n.list_generations(m.Profile("system", tmp_path)) == [ { From 58f58d96a2af42be4caf98b7fb140bb417b27a4c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 28 Sep 2026 09:48:20 +0000 Subject: [PATCH 107/117] terraform-providers.datadog_datadog: 4.21.0 -> 4.22.0 --- .../networking/cluster/terraform-providers/providers.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/cluster/terraform-providers/providers.json b/pkgs/applications/networking/cluster/terraform-providers/providers.json index e3525c5569d1..34e0bc23e566 100644 --- a/pkgs/applications/networking/cluster/terraform-providers/providers.json +++ b/pkgs/applications/networking/cluster/terraform-providers/providers.json @@ -292,13 +292,13 @@ "vendorHash": "sha256-3o6YRDrq4rQhNAFyqiGJrAoxuAykWw85OExRGSE3kGI=" }, "datadog_datadog": { - "hash": "sha256-a84guU5oeG+BwmPoPCyGZRBOB/dzaPCLwxKH3BYSj6A=", + "hash": "sha256-Unz4DuY30UuEktduVQNjTfqwSpIXI4n3nJlHE6piiOw=", "homepage": "https://registry.terraform.io/providers/DataDog/datadog", "owner": "DataDog", "repo": "terraform-provider-datadog", - "rev": "v4.21.0", + "rev": "v4.22.0", "spdx": "MPL-2.0", - "vendorHash": "sha256-KBzkbWlFM0SB+YzVU4YIaJxvQlMHalPeKPvvHh4L2kw=" + "vendorHash": "sha256-77BV9XKSwB0s2Grfh3w0XESxYvohNPG6g22+5cVUiVU=" }, "datadrivers_nexus": { "hash": "sha256-+MTyr7voagijpqTb7vswO8PAFZpxz3UWAQLEs0os4+s=", From b758ee3a74ed8f51c2719868b8b978c65557712c Mon Sep 17 00:00:00 2001 From: Adam Dinwoodie Date: Fri, 25 Sep 2026 11:51:47 +0200 Subject: [PATCH 108/117] nixosTests.syncthing-folders: avoid IFD Avoid import-from-derivation and non-reproducible derivations by generating node configurations for Syncthing tests in advance, rather than generating them at eval time. The latter requires import-from-derivation and also means every time the node configurations are generated, syncthing will generate unique certificates, meaning those derivations are different on every build. While we're rewriting things, convert the IFD part to a script that can be run to generate new Syncthing certificates and node IDs, and which was used to generate the certificates and IDs in this commit. --- nixos/tests/syncthing/folders.nix | 65 ++++++++++++++------- nixos/tests/syncthing/test-nodes/a/cert.pem | 11 ++++ nixos/tests/syncthing/test-nodes/a/id | 1 + nixos/tests/syncthing/test-nodes/a/key.pem | 3 + nixos/tests/syncthing/test-nodes/b/cert.pem | 11 ++++ nixos/tests/syncthing/test-nodes/b/id | 1 + nixos/tests/syncthing/test-nodes/b/key.pem | 3 + nixos/tests/syncthing/test-nodes/c/cert.pem | 11 ++++ nixos/tests/syncthing/test-nodes/c/id | 1 + nixos/tests/syncthing/test-nodes/c/key.pem | 3 + 10 files changed, 88 insertions(+), 22 deletions(-) create mode 100644 nixos/tests/syncthing/test-nodes/a/cert.pem create mode 100644 nixos/tests/syncthing/test-nodes/a/id create mode 100644 nixos/tests/syncthing/test-nodes/a/key.pem create mode 100644 nixos/tests/syncthing/test-nodes/b/cert.pem create mode 100644 nixos/tests/syncthing/test-nodes/b/id create mode 100644 nixos/tests/syncthing/test-nodes/b/key.pem create mode 100644 nixos/tests/syncthing/test-nodes/c/cert.pem create mode 100644 nixos/tests/syncthing/test-nodes/c/id create mode 100644 nixos/tests/syncthing/test-nodes/c/key.pem diff --git a/nixos/tests/syncthing/folders.nix b/nixos/tests/syncthing/folders.nix index 1a182da4c845..267926135ee3 100644 --- a/nixos/tests/syncthing/folders.nix +++ b/nixos/tests/syncthing/folders.nix @@ -1,15 +1,8 @@ { lib, pkgs, ... }: let - genNodeId = - name: - pkgs.runCommand "syncthing-test-certs-${name}" { } '' - mkdir -p $out - ${pkgs.syncthing}/bin/syncthing generate --home=$out - ${pkgs.libxml2}/bin/xmllint --xpath 'string(configuration/device/@id)' $out/config.xml > $out/id - ''; - idA = genNodeId "a"; - idB = genNodeId "b"; - idC = genNodeId "c"; + nodeA = ./test-nodes/a; + nodeB = ./test-nodes/b; + nodeC = ./test-nodes/c; testPassword = "it's a secret"; in { @@ -24,12 +17,12 @@ in services.syncthing = { enable = true; openDefaultPorts = true; - cert = "${idA}/cert.pem"; - key = "${idA}/key.pem"; + cert = "${nodeA}/cert.pem"; + key = "${nodeA}/key.pem"; guiAddress = "unix:///run/syncthing/syncthing.sock"; settings = { - devices.b.id = lib.fileContents "${idB}/id"; - devices.c.id = lib.fileContents "${idC}/id"; + devices.b.id = lib.fileContents "${nodeB}/id"; + devices.c.id = lib.fileContents "${nodeC}/id"; folders.foo = { path = "/var/lib/syncthing/foo"; devices = [ "b" ]; @@ -67,11 +60,11 @@ in services.syncthing = { enable = true; openDefaultPorts = true; - cert = "${idB}/cert.pem"; - key = "${idB}/key.pem"; + cert = "${nodeB}/cert.pem"; + key = "${nodeB}/key.pem"; settings = { - devices.a.id = lib.fileContents "${idA}/id"; - devices.c.id = lib.fileContents "${idC}/id"; + devices.a.id = lib.fileContents "${nodeA}/id"; + devices.c.id = lib.fileContents "${nodeC}/id"; folders.foo = { path = "/var/lib/syncthing/foo"; devices = [ "a" ]; @@ -115,11 +108,11 @@ in services.syncthing = { enable = true; openDefaultPorts = true; - cert = "${idC}/cert.pem"; - key = "${idC}/key.pem"; + cert = "${nodeC}/cert.pem"; + key = "${nodeC}/key.pem"; settings = { - devices.a.id = lib.fileContents "${idA}/id"; - devices.b.id = lib.fileContents "${idB}/id"; + devices.a.id = lib.fileContents "${nodeA}/id"; + devices.b.id = lib.fileContents "${nodeB}/id"; folders.bar = { path = "/var/lib/syncthing/bar"; devices = [ @@ -143,6 +136,34 @@ in }; }; + # Run from the root of the nixpkgs repository with + # + # nix-build -A nixosTests.syncthing-folders.genNodeData && + # ./result/bin/genNodeData.sh + # + # This generates new keys, certificates, and overall Syncthing config, and + # updates the certificate and key files and the ID file extracted from the + # overall Syncthing config file. + passthru.genNodeData = pkgs.writeShellApplication { + name = "genNodeData.sh"; + runtimeInputs = with pkgs; [ + syncthing + libxml2 + ]; + text = '' + rm -r nixos/tests/syncthing/test-nodes + mkdir nixos/tests/syncthing/test-nodes + cd nixos/tests/syncthing/test-nodes + + for d in a b c; do + mkdir -- "$d" + syncthing generate --home="$d" + xmllint --xpath 'string(configuration/device/@id)' "$d"/config.xml >"$d"/id + rm -f -- "$d"/.syncthing.tmp.* "$d"/config.xml + done + ''; + }; + testScript = '' start_all() diff --git a/nixos/tests/syncthing/test-nodes/a/cert.pem b/nixos/tests/syncthing/test-nodes/a/cert.pem new file mode 100644 index 000000000000..e4a948a25727 --- /dev/null +++ b/nixos/tests/syncthing/test-nodes/a/cert.pem @@ -0,0 +1,11 @@ +-----BEGIN CERTIFICATE----- +MIIBoDCCAVKgAwIBAgIJAJ7l/z0JF6aOMAUGAytlcDBKMRIwEAYDVQQKEwlTeW5j +dGhpbmcxIDAeBgNVBAsTF0F1dG9tYXRpY2FsbHkgR2VuZXJhdGVkMRIwEAYDVQQD +EwlzeW5jdGhpbmcwHhcNMjYwNDAyMDAwMDAwWhcNNDYwMzI4MDAwMDAwWjBKMRIw +EAYDVQQKEwlTeW5jdGhpbmcxIDAeBgNVBAsTF0F1dG9tYXRpY2FsbHkgR2VuZXJh +dGVkMRIwEAYDVQQDEwlzeW5jdGhpbmcwKjAFBgMrZXADIQBCsJ1O6QrxxFP/YKKj +WAjdZp07AiTIIC0/p/mHGbmyraNVMFMwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQW +MBQGCCsGAQUFBwMBBggrBgEFBQcDAjAMBgNVHRMBAf8EAjAAMBQGA1UdEQQNMAuC +CXN5bmN0aGluZzAFBgMrZXADQQBqGFXpwvEoAc7N6mT9evXI3++STiTE6Lu3Z2z3 +ecp5vU3fS5U+b0fO4BEUrNoaDdXurfOal6+LoydAnJcFamwN +-----END CERTIFICATE----- diff --git a/nixos/tests/syncthing/test-nodes/a/id b/nixos/tests/syncthing/test-nodes/a/id new file mode 100644 index 000000000000..97a37907b52c --- /dev/null +++ b/nixos/tests/syncthing/test-nodes/a/id @@ -0,0 +1 @@ +F2ACIUG-FML5RHY-ATV55ZN-5KGVUIV-RWFG3Y6-QPLTKZB-NWUZAGD-7QRCWAP diff --git a/nixos/tests/syncthing/test-nodes/a/key.pem b/nixos/tests/syncthing/test-nodes/a/key.pem new file mode 100644 index 000000000000..bb6111462cfc --- /dev/null +++ b/nixos/tests/syncthing/test-nodes/a/key.pem @@ -0,0 +1,3 @@ +-----BEGIN PRIVATE KEY----- +MC4CAQAwBQYDK2VwBCIEIE2ls259KcQgtizG7hwP3aBhlYBNuPJwSBG8d4uVBFOh +-----END PRIVATE KEY----- diff --git a/nixos/tests/syncthing/test-nodes/b/cert.pem b/nixos/tests/syncthing/test-nodes/b/cert.pem new file mode 100644 index 000000000000..a3fbcd34dc46 --- /dev/null +++ b/nixos/tests/syncthing/test-nodes/b/cert.pem @@ -0,0 +1,11 @@ +-----BEGIN CERTIFICATE----- +MIIBnzCCAVGgAwIBAgIIKyLKAcqLWn4wBQYDK2VwMEoxEjAQBgNVBAoTCVN5bmN0 +aGluZzEgMB4GA1UECxMXQXV0b21hdGljYWxseSBHZW5lcmF0ZWQxEjAQBgNVBAMT +CXN5bmN0aGluZzAeFw0yNjA0MDIwMDAwMDBaFw00NjAzMjgwMDAwMDBaMEoxEjAQ +BgNVBAoTCVN5bmN0aGluZzEgMB4GA1UECxMXQXV0b21hdGljYWxseSBHZW5lcmF0 +ZWQxEjAQBgNVBAMTCXN5bmN0aGluZzAqMAUGAytlcAMhABoahydRmwpbCII6mz9i +E8FeGH7YdHqgMeAmLiFZu2wMo1UwUzAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYw +FAYIKwYBBQUHAwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQCMAAwFAYDVR0RBA0wC4IJ +c3luY3RoaW5nMAUGAytlcANBADFVKB2vF16j0gc/h71x3vUi042FbmXTPk9kMb2O +9O0NnWSoMuOGPFDEoHWBFuUuixQ/3cw45zw+fea28m95gQo= +-----END CERTIFICATE----- diff --git a/nixos/tests/syncthing/test-nodes/b/id b/nixos/tests/syncthing/test-nodes/b/id new file mode 100644 index 000000000000..a96022726527 --- /dev/null +++ b/nixos/tests/syncthing/test-nodes/b/id @@ -0,0 +1 @@ +LOB4D2H-OYG64QZ-NDX43LJ-NYR4HQU-BRNXCNI-ERACWFP-OVURLBI-63MR5QP diff --git a/nixos/tests/syncthing/test-nodes/b/key.pem b/nixos/tests/syncthing/test-nodes/b/key.pem new file mode 100644 index 000000000000..4253bf0f9255 --- /dev/null +++ b/nixos/tests/syncthing/test-nodes/b/key.pem @@ -0,0 +1,3 @@ +-----BEGIN PRIVATE KEY----- +MC4CAQAwBQYDK2VwBCIEIJtOML1Tshk03rB41IX5ajEeem50CdWzHDimotheTyZi +-----END PRIVATE KEY----- diff --git a/nixos/tests/syncthing/test-nodes/c/cert.pem b/nixos/tests/syncthing/test-nodes/c/cert.pem new file mode 100644 index 000000000000..1561c4ac3465 --- /dev/null +++ b/nixos/tests/syncthing/test-nodes/c/cert.pem @@ -0,0 +1,11 @@ +-----BEGIN CERTIFICATE----- +MIIBoDCCAVKgAwIBAgIJAIZk5+sv3EbTMAUGAytlcDBKMRIwEAYDVQQKEwlTeW5j +dGhpbmcxIDAeBgNVBAsTF0F1dG9tYXRpY2FsbHkgR2VuZXJhdGVkMRIwEAYDVQQD +EwlzeW5jdGhpbmcwHhcNMjYwNDAyMDAwMDAwWhcNNDYwMzI4MDAwMDAwWjBKMRIw +EAYDVQQKEwlTeW5jdGhpbmcxIDAeBgNVBAsTF0F1dG9tYXRpY2FsbHkgR2VuZXJh +dGVkMRIwEAYDVQQDEwlzeW5jdGhpbmcwKjAFBgMrZXADIQB0QK+PM7oLutgCKoIo +UOh8/XiSmGJWbkN175hALTIaYKNVMFMwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQW +MBQGCCsGAQUFBwMBBggrBgEFBQcDAjAMBgNVHRMBAf8EAjAAMBQGA1UdEQQNMAuC +CXN5bmN0aGluZzAFBgMrZXADQQAbedm895vhgYizMXc38IwhquYv2S4ORHZac0Bw +ZYKJKze7EhKzqvdxcU5uVIUaMPSGi86wtmmsiijfhY8rnD0E +-----END CERTIFICATE----- diff --git a/nixos/tests/syncthing/test-nodes/c/id b/nixos/tests/syncthing/test-nodes/c/id new file mode 100644 index 000000000000..492e50839af2 --- /dev/null +++ b/nixos/tests/syncthing/test-nodes/c/id @@ -0,0 +1 @@ +MPGAF2L-AUIF5DE-UCI3AMX-PTGF3ZI-XDS6UJI-YUU4ZWT-UUWY7X6-N2DAAQG diff --git a/nixos/tests/syncthing/test-nodes/c/key.pem b/nixos/tests/syncthing/test-nodes/c/key.pem new file mode 100644 index 000000000000..2577c5f60064 --- /dev/null +++ b/nixos/tests/syncthing/test-nodes/c/key.pem @@ -0,0 +1,3 @@ +-----BEGIN PRIVATE KEY----- +MC4CAQAwBQYDK2VwBCIEIMSmcIlXQTKkaMaOLh+zsgU1ULCvCz949E56OzQ1dsMK +-----END PRIVATE KEY----- From 6455637cda21eb0dc3cd3516ad1593752d71674c Mon Sep 17 00:00:00 2001 From: Adam Dinwoodie Date: Mon, 28 Sep 2026 11:59:34 +0200 Subject: [PATCH 109/117] nixosTests.syncthing-{folders,no-settings}: clarify names Change test names to match the name of the test, so different syncthing tests can be distinguished. --- nixos/tests/syncthing/folders.nix | 2 +- nixos/tests/syncthing/no-settings.nix | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/nixos/tests/syncthing/folders.nix b/nixos/tests/syncthing/folders.nix index 267926135ee3..d0d889e7d6d5 100644 --- a/nixos/tests/syncthing/folders.nix +++ b/nixos/tests/syncthing/folders.nix @@ -6,7 +6,7 @@ let testPassword = "it's a secret"; in { - name = "syncthing"; + name = "syncthing-folders"; meta.maintainers = with pkgs.lib.maintainers; [ zarelit ]; nodes = { diff --git a/nixos/tests/syncthing/no-settings.nix b/nixos/tests/syncthing/no-settings.nix index ee79d389e92a..c389d95ac7fa 100644 --- a/nixos/tests/syncthing/no-settings.nix +++ b/nixos/tests/syncthing/no-settings.nix @@ -1,6 +1,6 @@ { lib, pkgs, ... }: { - name = "syncthing"; + name = "syncthing-no-settings"; meta.maintainers = with pkgs.lib.maintainers; [ chkno ]; nodes = { From 0db3be3aca444a5c29a5b635d8b60eeb0e773d32 Mon Sep 17 00:00:00 2001 From: Adam Dinwoodie Date: Fri, 25 Sep 2026 11:51:47 +0200 Subject: [PATCH 110/117] nixosTests.syncthing-folders: refactor for clarity Rewrite the test node configuration to use multiple modules and group config according to the Syncthing folder it's being used for, rather than by node, to make the different test cases clearer. --- nixos/tests/syncthing/folders.nix | 290 ++++++++++++++++-------------- 1 file changed, 159 insertions(+), 131 deletions(-) diff --git a/nixos/tests/syncthing/folders.nix b/nixos/tests/syncthing/folders.nix index d0d889e7d6d5..06ee16e1c3a6 100644 --- a/nixos/tests/syncthing/folders.nix +++ b/nixos/tests/syncthing/folders.nix @@ -1,141 +1,161 @@ { lib, pkgs, ... }: let - nodeA = ./test-nodes/a; - nodeB = ./test-nodes/b; - nodeC = ./test-nodes/c; + nodeNames = [ + "a" + "b" + "c" + ]; + nodeDirs = lib.genAttrs nodeNames (n: ./test-nodes + "/${n}"); + nodeData = lib.mapAttrs (n: v: { + cert = "${v}/cert.pem"; + key = "${v}/key.pem"; + id = lib.fileContents (v + "/id"); + }) nodeDirs; + testPassword = "it's a secret"; + + commonNodeConfigModule = { + services.syncthing = { + enable = true; + openDefaultPorts = true; + settings.devices = lib.mapAttrs (n: v: { inherit (v) id; }) nodeData; + }; + }; + + nodeConfigModules = { + a = { + services.syncthing = { + inherit (nodeData.a) cert key; + guiAddress = "unix:///run/syncthing/syncthing.sock"; + }; + }; + b = { + services.syncthing = { inherit (nodeData.b) cert key; }; + }; + c = { + services.syncthing = { inherit (nodeData.c) cert key; }; + }; + }; + + nodeFolderConfigModules = [ + # "foo" is a folder that is synchronised only between nodes a and b. + rec { + a = { + services.syncthing.settings.folders.foo = { + path = "/var/lib/syncthing/foo"; + devices = [ + "a" + "b" + ]; + }; + }; + + b = a; + + c = { }; + } + + # "bar" is synchronised between a and c, and between b and c, but c only + # gets an encrypted copy, and a and b never synchronise directly to each + # other. + rec { + a = + { config, ... }: + { + environment.etc.bar-encryption-password.text = testPassword; + + services.syncthing.settings.folders.bar = { + path = "/var/lib/syncthing/bar"; + devices = [ + { + name = "c"; + encryptionPasswordFile = "/etc/${config.environment.etc.bar-encryption-password.target}"; + } + ]; + }; + }; + + b = a; + + c = { + services.syncthing.settings.folders.bar = { + path = "/var/lib/syncthing/bar"; + devices = [ + "a" + "b" + ]; + type = "receiveencrypted"; + }; + }; + } + + # "baz" is synchronised between all three nodes, but has filters on b and c + # that mean they shouldn't receive certain files. + { + a = { + services.syncthing.settings.folders.baz = { + path = "/var/lib/syncthing/baz"; + devices = [ + "b" + "c" + ]; + ignorePatterns = [ ]; + }; + }; + + b = { + services.syncthing.settings.folders.baz = { + path = "/var/lib/syncthing/baz"; + devices = [ + "a" + "c" + ]; + ignorePatterns = [ + "notB" + # Just test that an apostrophe doesn't break the curl config + # commands. See: https://github.com/NixOS/nixpkgs/issues/554744 + "apostrophe'" + ]; + }; + }; + + c = { + services.syncthing.settings.folders.baz = { + path = "/var/lib/syncthing/baz"; + devices = [ + "a" + "b" + ]; + ignorePatterns = [ "notC" ]; + }; + }; + } + + # "foo bar" tests handling whitespace in folder IDs. + { + a = { + services.syncthing.settings.folders."foo bar" = { + path = "/var/lib/syncthing/foo-bar"; + devices = [ "b" ]; + }; + }; + + b = { + services.syncthing.settings.folders."foo bar" = { + path = "/var/lib/syncthing/foo-bar"; + devices = [ "a" ]; + ignorePatterns = [ "notB" ]; + }; + }; + + c = { }; + } + ]; in { name = "syncthing-folders"; meta.maintainers = with pkgs.lib.maintainers; [ zarelit ]; - nodes = { - a = - { config, ... }: - { - environment.etc.bar-encryption-password.text = testPassword; - services.syncthing = { - enable = true; - openDefaultPorts = true; - cert = "${nodeA}/cert.pem"; - key = "${nodeA}/key.pem"; - guiAddress = "unix:///run/syncthing/syncthing.sock"; - settings = { - devices.b.id = lib.fileContents "${nodeB}/id"; - devices.c.id = lib.fileContents "${nodeC}/id"; - folders.foo = { - path = "/var/lib/syncthing/foo"; - devices = [ "b" ]; - }; - folders.bar = { - path = "/var/lib/syncthing/bar"; - devices = [ - { - name = "c"; - encryptionPasswordFile = "/etc/${config.environment.etc.bar-encryption-password.target}"; - } - ]; - }; - folders.baz = { - path = "/var/lib/syncthing/baz"; - devices = [ - "b" - "c" - ]; - ignorePatterns = [ ]; - }; - folders."foo bar" = { - path = "/var/lib/syncthing/foo-bar"; - devices = [ - "b" - ]; - }; - }; - }; - }; - b = - { config, ... }: - { - environment.etc.bar-encryption-password.text = testPassword; - services.syncthing = { - enable = true; - openDefaultPorts = true; - cert = "${nodeB}/cert.pem"; - key = "${nodeB}/key.pem"; - settings = { - devices.a.id = lib.fileContents "${nodeA}/id"; - devices.c.id = lib.fileContents "${nodeC}/id"; - folders.foo = { - path = "/var/lib/syncthing/foo"; - devices = [ "a" ]; - }; - folders.bar = { - path = "/var/lib/syncthing/bar"; - devices = [ - { - name = "c"; - encryptionPasswordFile = "/etc/${config.environment.etc.bar-encryption-password.target}"; - } - ]; - }; - folders.baz = { - path = "/var/lib/syncthing/baz"; - devices = [ - "a" - "c" - ]; - ignorePatterns = [ - "notB" - ]; - }; - # Test how we handle white spaces in folder IDs - folders."foo bar" = { - path = "/var/lib/syncthing/foo-bar"; - devices = [ - "a" - ]; - ignorePatterns = [ - "notB" - # Just test that an apostrophe doesn't break the curl config - # commands. See: https://github.com/NixOS/nixpkgs/issues/554744 - "apostrophe'" - ]; - }; - }; - }; - }; - c = { - services.syncthing = { - enable = true; - openDefaultPorts = true; - cert = "${nodeC}/cert.pem"; - key = "${nodeC}/key.pem"; - settings = { - devices.a.id = lib.fileContents "${nodeA}/id"; - devices.b.id = lib.fileContents "${nodeB}/id"; - folders.bar = { - path = "/var/lib/syncthing/bar"; - devices = [ - "a" - "b" - ]; - type = "receiveencrypted"; - }; - folders.baz = { - path = "/var/lib/syncthing/baz"; - devices = [ - "a" - "b" - ]; - ignorePatterns = [ - "notC" - ]; - }; - }; - }; - }; - }; - # Run from the root of the nixpkgs repository with # # nix-build -A nixosTests.syncthing-folders.genNodeData && @@ -155,7 +175,7 @@ in mkdir nixos/tests/syncthing/test-nodes cd nixos/tests/syncthing/test-nodes - for d in a b c; do + for d in ${lib.escapeShellArgs nodeNames}; do mkdir -- "$d" syncthing generate --home="$d" xmllint --xpath 'string(configuration/device/@id)' "$d"/config.xml >"$d"/id @@ -164,6 +184,14 @@ in ''; }; + nodes = lib.genAttrs nodeNames (n: { + imports = [ + commonNodeConfigModule + nodeConfigModules."${n}" + ] + ++ map (builtins.getAttr n) nodeFolderConfigModules; + }); + testScript = '' start_all() From a8fb7a7eb1e32cd8296564b9a719ab0b2dfb3883 Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Mon, 28 Sep 2026 09:40:29 +0000 Subject: [PATCH 111/117] cudaPackages.cuda_compat: add missing openssl on x86_64 --- .../development/cuda-modules/packages/cuda_compat.nix | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/pkgs/development/cuda-modules/packages/cuda_compat.nix b/pkgs/development/cuda-modules/packages/cuda_compat.nix index 76239b729cb2..4e6f0aab18db 100644 --- a/pkgs/development/cuda-modules/packages/cuda_compat.nix +++ b/pkgs/development/cuda-modules/packages/cuda_compat.nix @@ -2,6 +2,8 @@ buildRedist, config, lib, + openssl, + stdenv, }: buildRedist { redistName = "cuda"; @@ -11,10 +13,19 @@ buildRedist { # To avoid that (and troubleshooting why), we just use a single output. outputs = [ "out" ]; + # libnvidia-pkcs11{-openssl3}.so is only shipped on x86_64-linux + buildInputs = lib.optionals stdenv.hostPlatform.isx86_64 [ + openssl + ]; + autoPatchelfIgnoreMissingDeps = [ "libnvdla_runtime.so" "libnvrm_gpu.so" "libnvrm_mem.so" + ] + ++ lib.optionals stdenv.hostPlatform.isx86_64 [ + # Used by libnvidia-pkcs11.so but openssl_1_1 has been removed from nixpkgs (EoL) + "libcrypto.so.1.1" ]; meta = { From 6500ce6442ad9d48bdb36734aa1b7725e3c23902 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Mon, 28 Sep 2026 10:57:35 +0100 Subject: [PATCH 112/117] nixos-version: escape specialisations and use kernel.modDirVersion if available --- nixos/modules/installer/tools/nixos-version.sh | 8 ++++---- nixos/modules/installer/tools/tools.nix | 12 +++++++++--- 2 files changed, 13 insertions(+), 7 deletions(-) diff --git a/nixos/modules/installer/tools/nixos-version.sh b/nixos/modules/installer/tools/nixos-version.sh index c9ca4a634d82..a2aa76db9cd2 100644 --- a/nixos/modules/installer/tools/nixos-version.sh +++ b/nixos/modules/installer/tools/nixos-version.sh @@ -28,15 +28,15 @@ case "$1" in echo "@kernelVersion@" ;; --specialisations) - if [[ -z "@specialisations@" ]]; then + specialisations=@specialisations@ + if [[ -z "$specialisations" ]]; then echo "$0: no specialisations found" >&2 exit 1 - else - echo "@specialisations@" fi + printf '%s\n' "$specialisations" ;; --json) - cat < Date: Mon, 28 Sep 2026 10:54:39 +0200 Subject: [PATCH 113/117] dokuwiki: move from rec to finalAttrs --- pkgs/by-name/do/dokuwiki/package.nix | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/pkgs/by-name/do/dokuwiki/package.nix b/pkgs/by-name/do/dokuwiki/package.nix index 3059ee06e05a..7b842d6306e3 100644 --- a/pkgs/by-name/do/dokuwiki/package.nix +++ b/pkgs/by-name/do/dokuwiki/package.nix @@ -7,14 +7,14 @@ dokuwiki, }: -stdenv.mkDerivation rec { +stdenv.mkDerivation (finalAttrs: { pname = "dokuwiki"; version = "2026-07-14c"; src = fetchFromGitHub { owner = "dokuwiki"; repo = "dokuwiki"; - rev = "release-${version}"; + rev = "release-${finalAttrs.version}"; sha256 = "sha256-84kMuFTWYo6Cjd6qpkZsLZoECIP9IzSrc9dX1uKMp0M="; }; @@ -49,9 +49,9 @@ stdenv.mkDerivation rec { mkdir -p $out/share/dokuwiki cp -r * $out/share/dokuwiki - cp ${preload} $out/share/dokuwiki/inc/preload.php - cp ${phpLocalConfig} $out/share/dokuwiki/conf/local.php - cp ${phpPluginsLocalConfig} $out/share/dokuwiki/conf/plugins.local.php + cp ${finalAttrs.preload} $out/share/dokuwiki/inc/preload.php + cp ${finalAttrs.phpLocalConfig} $out/share/dokuwiki/conf/local.php + cp ${finalAttrs.phpPluginsLocalConfig} $out/share/dokuwiki/conf/plugins.local.php runHook postInstall ''; @@ -115,4 +115,4 @@ stdenv.mkDerivation rec { e1mo ]; }; -} +}) From 911885045fc1b6666d0f32d7bc5c4058a9b345f7 Mon Sep 17 00:00:00 2001 From: Nina Fromm Date: Mon, 28 Sep 2026 10:54:53 +0200 Subject: [PATCH 114/117] dokuwiki: add correct CPE information --- pkgs/by-name/do/dokuwiki/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/do/dokuwiki/package.nix b/pkgs/by-name/do/dokuwiki/package.nix index 7b842d6306e3..79a40f6b3ae2 100644 --- a/pkgs/by-name/do/dokuwiki/package.nix +++ b/pkgs/by-name/do/dokuwiki/package.nix @@ -110,6 +110,7 @@ stdenv.mkDerivation (finalAttrs: { license = lib.licenses.gpl2Only; homepage = "https://www.dokuwiki.org"; platforms = lib.platforms.all; + identifiers.cpeParts = lib.meta.cpeFullVersionWithVendor "dokuwiki" finalAttrs.version; maintainers = with lib.maintainers; [ _1000101 e1mo From 78204cf312204af06a0e59ca63e7a9c0186c8e43 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Wed, 9 Sep 2026 02:15:35 +0200 Subject: [PATCH 115/117] nixos/go-neb: move mkRemovedOptionModule to rename.nix --- nixos/modules/module-list.nix | 1 - nixos/modules/rename.nix | 4 ++++ nixos/modules/services/networking/go-neb.nix | 10 ---------- 3 files changed, 4 insertions(+), 11 deletions(-) delete mode 100644 nixos/modules/services/networking/go-neb.nix diff --git a/nixos/modules/module-list.nix b/nixos/modules/module-list.nix index ad42c9606bc6..dd2a09f305f8 100644 --- a/nixos/modules/module-list.nix +++ b/nixos/modules/module-list.nix @@ -1256,7 +1256,6 @@ ./services/networking/gnunet.nix ./services/networking/go-autoconfig.nix ./services/networking/go-camo.nix - ./services/networking/go-neb.nix ./services/networking/go-shadowsocks2.nix ./services/networking/gobgpd.nix ./services/networking/godns.nix diff --git a/nixos/modules/rename.nix b/nixos/modules/rename.nix index 630e88beeb5b..1c59dccae9e1 100644 --- a/nixos/modules/rename.nix +++ b/nixos/modules/rename.nix @@ -486,6 +486,10 @@ in See https://www.isc.org/blogs/isc-dhcp-eol/ for details. Please switch to a different implementation like kea or dnsmasq. '') + (lib.mkRemovedOptionModule [ "services" "go-neb" ] '' + The Go-NEB project was discontinued by Matrix.org and archived in June + 2023. Use matrix-hookshot or another maintained Matrix bot instead. + '') (mkRemovedOptionModule [ "services" "gsignond" ] '' The corresponding package was unmaintained, abandoned upstream, used outdated library and thus removed from nixpkgs. '') diff --git a/nixos/modules/services/networking/go-neb.nix b/nixos/modules/services/networking/go-neb.nix deleted file mode 100644 index 1e900c729acb..000000000000 --- a/nixos/modules/services/networking/go-neb.nix +++ /dev/null @@ -1,10 +0,0 @@ -{ lib, ... }: - -{ - imports = [ - (lib.mkRemovedOptionModule [ "services" "go-neb" ] '' - The Go-NEB project was discontinued by Matrix.org and archived in June - 2023. Use matrix-hookshot or another maintained Matrix bot instead. - '') - ]; -} From 06f7935788124a58f853891e9e0657f8ec89aefc Mon Sep 17 00:00:00 2001 From: Luflosi Date: Mon, 30 Jun 2025 17:49:15 +0200 Subject: [PATCH 116/117] aclpubcheck: init at 0.1-unstable-2026-09-11 https://github.com/acl-org/aclpubcheck --- pkgs/by-name/ac/aclpubcheck/package.nix | 50 +++++++++++++++++++ pkgs/by-name/ac/aclpubcheck/test/default.nix | 29 +++++++++++ .../ac/aclpubcheck/test/expected-output.txt | 28 +++++++++++ 3 files changed, 107 insertions(+) create mode 100644 pkgs/by-name/ac/aclpubcheck/package.nix create mode 100644 pkgs/by-name/ac/aclpubcheck/test/default.nix create mode 100644 pkgs/by-name/ac/aclpubcheck/test/expected-output.txt diff --git a/pkgs/by-name/ac/aclpubcheck/package.nix b/pkgs/by-name/ac/aclpubcheck/package.nix new file mode 100644 index 000000000000..48cfd29f5d01 --- /dev/null +++ b/pkgs/by-name/ac/aclpubcheck/package.nix @@ -0,0 +1,50 @@ +{ + lib, + python3Packages, + fetchFromGitHub, + callPackage, +}: + +python3Packages.buildPythonApplication { + pname = "aclpubcheck"; + version = "0.1-unstable-2026-09-11"; + pyproject = true; + + src = fetchFromGitHub { + owner = "acl-org"; + repo = "aclpubcheck"; + rev = "237bee3a554f2d2fcda69cd0cf1edf4168e3d339"; # No Git Tags + hash = "sha256-s9kegTZOZEgGx0Yj8jOfzAyjyy1EuabOybMDBoodRvo="; + }; + + strictDeps = true; + __structuredAttrs = true; + + build-system = with python3Packages; [ + setuptools + ]; + + dependencies = with python3Packages; [ + tqdm + termcolor + pandas + pdfplumber + rebiber + pybtex + pylatexenc + unidecode + tsv + ]; + + passthru.tests = { + example-pdf = callPackage ./test { }; + }; + + meta = { + description = "Tool for checking ACL paper submissions"; + homepage = "https://github.com/acl-org/aclpubcheck"; + license = with lib.licenses; [ mit ]; + mainProgram = "aclpubcheck"; + maintainers = with lib.maintainers; [ Luflosi ]; + }; +} diff --git a/pkgs/by-name/ac/aclpubcheck/test/default.nix b/pkgs/by-name/ac/aclpubcheck/test/default.nix new file mode 100644 index 000000000000..bfda119f09c1 --- /dev/null +++ b/pkgs/by-name/ac/aclpubcheck/test/default.nix @@ -0,0 +1,29 @@ +{ + runCommand, + aclpubcheck, +}: +runCommand "aclpubcheck-test-example-pdf" { nativeBuildInputs = [ aclpubcheck ]; } '' + # aclpubcheck prints out the path that was passed to it, which may change over time if it is a Nix store path. + # Since we're comparing the output of aclpubcheck, this would break the test. + # To avoid this, pass aclpubcheck a relative path to a symlink in the current working directory instead of the absolute path. + # Simply using `cd` to change directories into the example directory does not work, + # since aclpubcheck wants to write some files to the current working directory. + ln -s '${aclpubcheck.src}/example/2023.acl-tutorials.1.pdf' 2023.acl-tutorials.1.pdf + + aclpubcheck --paper_type long 2023.acl-tutorials.1.pdf > actual-output.txt + + exit_code="$?" + if [ "$exit_code" != 0 ]; then + echo "Exit code of aclpubcheck was $exit_code while 0 was expected." + exit 1 + fi + + if ! diff '${./expected-output.txt}' actual-output.txt; then + echo + echo "ERROR: The output was different than expected!" + echo "The diff is above." + exit 1 + fi + + touch "$out" +'' diff --git a/pkgs/by-name/ac/aclpubcheck/test/expected-output.txt b/pkgs/by-name/ac/aclpubcheck/test/expected-output.txt new file mode 100644 index 000000000000..c580da68bbd8 --- /dev/null +++ b/pkgs/by-name/ac/aclpubcheck/test/expected-output.txt @@ -0,0 +1,28 @@ +Checking 2023.acl-tutorials.1.pdf +Found text violation: Margin.BOTTOM {'top': 780, 'bottom': 841} +Found text violation: Margin.BOTTOM {'top': 780, 'bottom': 841} +Found text violation: Margin.BOTTOM {'top': 780, 'bottom': 841} +Found text violation: Margin.BOTTOM {'top': 780, 'bottom': 841} +Found text violation: Margin.BOTTOM {'top': 780, 'bottom': 841} +Found text violation: Margin.BOTTOM {'top': 780, 'bottom': 841} +Found text violation: Margin.BOTTOM {'top': 780, 'bottom': 841} +Found text violation: Margin.BOTTOM {'top': 780, 'bottom': 841} +Found text violation: Margin.BOTTOM {'top': 780, 'bottom': 841} +Found text violation: Margin.BOTTOM {'top': 780, 'bottom': 841} +Errors. Check errors-2023.acl-tutorials.1.json for details. +Error (Margin): Text on page 1 bleeds into the bottom margin. It should be empty (e.g., without page number) and populated when building the proceedings. +Error (Margin): Text on page 2 bleeds into the bottom margin. It should be empty (e.g., without page number) and populated when building the proceedings. +Error (Margin): Text on page 3 bleeds into the bottom margin. It should be empty (e.g., without page number) and populated when building the proceedings. +Error (Margin): Text on page 4 bleeds into the bottom margin. It should be empty (e.g., without page number) and populated when building the proceedings. +Error (Margin): Text on page 5 bleeds into the bottom margin. It should be empty (e.g., without page number) and populated when building the proceedings. +Error (Margin): Text on page 6 bleeds into the bottom margin. It should be empty (e.g., without page number) and populated when building the proceedings. +Error (Margin): Text on page 7 bleeds into the bottom margin. It should be empty (e.g., without page number) and populated when building the proceedings. +Error (Margin): Text on page 8 bleeds into the bottom margin. It should be empty (e.g., without page number) and populated when building the proceedings. +Error (Margin): Text on page 9 bleeds into the bottom margin. It should be empty (e.g., without page number) and populated when building the proceedings. +Error (Margin): Text on page 10 bleeds into the bottom margin. It should be empty (e.g., without page number) and populated when building the proceedings. + +We detected 10 errors and 0 warnings in your paper. +In general, it is required that you fix errors for your paper to be published. Fixing warnings is optional, but recommended. +Important: Some of the margin errors may be spurious. The library detects the location of images, but not whether they have a white background that blends in. +Important: Some of the warnings generated for citations may be spurious and inaccurate, due to parsing and indexing errors. +We encourage you to double check the citations and update them depending on the latest source. If you believe that your citation is updated and correct, then please ignore those warnings. From f89e83b15711fdd1d0a0ff08b57c77927b2ec4f9 Mon Sep 17 00:00:00 2001 From: Marcus Ramberg Date: Mon, 28 Sep 2026 10:48:00 +0200 Subject: [PATCH 117/117] enroll: init at 1.2.8 Assisted-By: Claude Opus 5.5 --- pkgs/by-name/en/enroll/package.nix | 40 ++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) create mode 100644 pkgs/by-name/en/enroll/package.nix diff --git a/pkgs/by-name/en/enroll/package.nix b/pkgs/by-name/en/enroll/package.nix new file mode 100644 index 000000000000..dd2bf182e95a --- /dev/null +++ b/pkgs/by-name/en/enroll/package.nix @@ -0,0 +1,40 @@ +{ + rustPlatform, + fetchFromGitHub, + libcosmicAppHook, + lib, +}: +rustPlatform.buildRustPackage (finalAttrs: { + pname = "enroll"; + version = "1.2.8"; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "cosmic-utils"; + repo = "enroll"; + tag = "v${finalAttrs.version}"; + hash = "sha256-mzB1BCurNoY0JB4Tx+yR6whzBCplVmQqGKC2vmJbjYI="; + }; + cargoHash = "sha256-WfzSdvU8HoSLrZ3l9n4J/qFaPvcBHYcNlcb7UC080ZE="; + + nativeBuildInputs = [ libcosmicAppHook ]; + + # The justfile installs under a mismatched appid case; match the desktop file's Icon= instead. + postInstall = '' + install -Dm0644 resources/org.cosmic_utils.enroll.desktop -t $out/share/applications + install -Dm0644 resources/org.cosmic_utils.enroll.metainfo.xml -t $out/share/metainfo + install -Dm0644 resources/icons/hicolor/scalable/apps/enroll.svg \ + $out/share/icons/hicolor/scalable/apps/org.cosmic_utils.enroll.svg + ''; + + meta = { + description = "Fingerprint enrollment for COSMIC"; + license = lib.licenses.mpl20; + maintainers = with lib.maintainers; [ marcusramberg ]; + homepage = "https://github.com/cosmic-utils/enroll"; + changelog = "https://github.com/cosmic-utils/enroll/releases/tag/v${finalAttrs.version}"; + mainProgram = "cosmic-utils-enroll"; + platforms = lib.platforms.linux; + }; +})