Merge staging-next-26.05 into staging-26.05

This commit is contained in:
nixpkgs-ci[bot]
2026-09-22 00:29:12 +00:00
committed by GitHub
21 changed files with 154 additions and 57 deletions

View File

@@ -189,11 +189,6 @@ in
wivrn = {
description = "WiVRn XR runtime service";
environment = recursiveUpdate {
# Default options
# https://gitlab.freedesktop.org/monado/monado/-/blob/598080453545c6bf313829e5780ffb7dde9b79dc/src/xrt/targets/service/monado.in.service#L12
XRT_COMPOSITOR_LOG = "debug";
XRT_PRINT_OPTIONS = "on";
IPC_EXIT_ON_DISCONNECT = "off";
PRESSURE_VESSEL_IMPORT_OPENXR_1_RUNTIMES = mkIf cfg.steam.importOXRRuntimes "1";
} cfg.monadoEnvironment;
# WiVRn scans for .desktop files in $XDG_DATA_DIRS for the application launcher,

View File

@@ -3,7 +3,7 @@
name = "miracle-wm";
meta = {
maintainers = with lib.maintainers; [ OPNA2608 ];
maintainers = [ ];
};
nodes.machine =

View File

@@ -17,6 +17,8 @@ let
"TestHandler"
"TestClone"
"TestRunner_ReusableWorkflowGitHubInstance"
"TestInitRepoIfRequired/clone"
"TestInitRepoIfRequired/clone_different_remote"
]
++ lib.optionals stdenv.hostPlatform.isDarwin [
# listen tcp 127.0.0.1:0: bind: operation not permitted
@@ -27,17 +29,17 @@ let
in
buildGoModule (finalAttrs: {
pname = "forgejo-runner";
version = "13.1.0";
version = "13.2.0";
src = fetchFromGitea {
domain = "code.forgejo.org";
owner = "forgejo";
repo = "runner";
rev = "v${finalAttrs.version}";
hash = "sha256-0LVia4B9n2zuuHDGFnBVM1mrbI7XBhMfy25kRSN5/WQ=";
hash = "sha256-2P3lWzC3yxcyiBltFDC1dwwv8Xx2XxEGSa16MdjnV38=";
};
vendorHash = "sha256-2QwltVOR6MJO8rLNgktN1ulvP0YrnqQorNnfJXzRmJs=";
vendorHash = "sha256-iyXO3LYTr4v1OoD9PS5ksEDIkCIq8hgwgtkLR0bzUZg=";
nativeBuildInputs = [ makeWrapper ];

View File

@@ -63,8 +63,6 @@ stdenv.mkDerivation (finalAttrs: {
qtWrapperArgs = [
"--set QT_STYLE_OVERRIDE Fusion"
"--set NIX_SSL_CERT_FILE ${cacert}/etc/ssl/certs/ca-bundle.crt"
# Disable hardware acceleration to fix severe flickering in video playback.
"--set-default QTWEBENGINE_FORCE_USE_GBM 0"
];
postInstall = lib.optionalString stdenv.hostPlatform.isDarwin ''

View File

@@ -0,0 +1,26 @@
From 5f13afa1cecfae398ff7d84ed89fc45b14b71c61 Mon Sep 17 00:00:00 2001
From: Shadowghost <Ghost_of_Stone@web.de>
Date: Thu, 4 Jun 2026 19:00:03 +0200
Subject: [PATCH] Fix playlist visibility
---
MediaBrowser.Controller/Entities/Folder.cs | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/MediaBrowser.Controller/Entities/Folder.cs b/MediaBrowser.Controller/Entities/Folder.cs
--- a/MediaBrowser.Controller/Entities/Folder.cs
+++ b/MediaBrowser.Controller/Entities/Folder.cs
@@ -811,7 +811,10 @@ namespace MediaBrowser.Controller.Entities
private bool RequiresPostFiltering2(InternalItemsQuery query)
{
- if (query.IncludeItemTypes.Length == 1 && query.IncludeItemTypes[0] == BaseItemKind.BoxSet)
+ // BoxSets and Playlists can have per-user visibility (shares/open access) that is stored in the
+ // serialized item data and cannot be evaluated by the database query, so filter them in memory.
+ if (query.IncludeItemTypes.Length > 0
+ && query.IncludeItemTypes.All(t => t == BaseItemKind.BoxSet || t == BaseItemKind.Playlist))
{
Logger.LogDebug("Query requires post-filtering due to BoxSet query");
return true;
--
2.51.0

View File

@@ -1,6 +1,7 @@
{
lib,
fetchFromGitHub,
fetchpatch,
nixosTests,
dotnetCorePackages,
buildDotnetModule,
@@ -23,6 +24,34 @@ buildDotnetModule (finalAttrs: {
hash = "sha256-HCs4ZsutVoVH+bBZANjpPeMyV8e63Yemjg9DSr0R9zg=";
};
patches = [
# Prevent SSRF, local file disclosure and DoS via external references in SVG rendering.
# (No public PR.)
(fetchpatch {
url = "https://github.com/jellyfin/jellyfin/commit/cefa78fc1de2410e5c5c6da5062c98fe98b22d17.patch";
hash = "sha256-TxGo+sLLG+C9omxrwvO6byzw+iRqONVLXrQKwkrY22s=";
})
# Fix MaxLoginAttempts not honored.
# https://github.com/jellyfin/jellyfin/pull/17274
(fetchpatch {
url = "https://github.com/jellyfin/jellyfin/commit/8b826d981bcfec22063d6008e38016f4b77790d0.patch";
hash = "sha256-Nav05TcpjBJABybU0BVyJ0UyxKi+6nDNBQ6tjY0DPT8=";
})
# GHSA-9x85-gx46-6522
# Reject user impersonation when retrieving private playlist items.
# (No public PR.)
(fetchpatch {
url = "https://github.com/jellyfin/jellyfin/commit/911ac3769cdcce50a8f6e0b3c0739d509bd9a23f.patch";
hash = "sha256-MwaTwqhuBc7yWW3cL6htlyDQ9O1wt5iFCOM/oVTi6P0=";
})
# Don't let unauthorized users to list other's private playlists.
# https://github.com/jellyfin/jellyfin/pull/17025
./fix-playlist-visibility.patch
];
propagatedBuildInputs = [ sqlite ];
projectFile = "Jellyfin.Server/Jellyfin.Server.csproj";

View File

@@ -27,10 +27,13 @@
#
# Ensure you also check ../mattermostLatest/package.nix.
regex = "^v(11\\.7\\.[0-9]+)$";
version = "11.7.8";
srcHash = "sha256-HH+LioMTxu0+VLr6+fpa/O9YduChIF0ieSgMBaS91uc=";
vendorHash = "sha256-FytvnZcPStztvUJLEnC3DUeyhmYWKP+/8xqv4suDZNE=";
npmDepsHash = "sha256-d1X33SV0c1l0e9fCIWEx7opeWByyovj0zNs+aGddRJc=";
version = "11.7.11";
srcHash = "sha256-C0t/PITQ1R4VRHQk+bQE8GPfdy5GjxLsHtRgYq6qgSw=";
vendorHash = "sha256-V63mY8za59WOI7dk8wMuHxWs2cs2rfZ9Ubpm5O+KMYU=";
npmDepsHash = "sha256-mK5wrX9dWDC+8dn/J7E1EOiwHekAzt5yQCJ8xqfKa3g=";
lockfileOverlay = ''
.packages["node_modules/rollup"] |= (del(.resolved, .integrity) | .version = "2.80.0")
'';
},
...
}:
@@ -257,7 +260,7 @@ buildMattermost rec {
# See: https://github.com/tcoopman/image-webpack-loader#deprecated
postPatch = ''
substituteInPlace channels/webpack.config.js \
--replace-fail 'options: {}' 'options: { disable: true }'
--replace-quiet 'options: {}' 'options: { disable: true }'
'';
inherit nodejs;

View File

@@ -15,10 +15,10 @@ mattermost.override (
# and make sure the version regex is up to date here.
# Ensure you also check ../mattermost/package.nix for ESR releases.
regex = "^v(11\\.[0-9]+\\.[0-9]+)$";
version = "11.8.3";
srcHash = "sha256-OWHW6UifUljL+yyWtc5XD/spbn7Yu1FqZ8gQAs073gY=";
vendorHash = "sha256-F2QMrLbio7812ZTGQZZPTqHWtIXbwbDmjUhtvv0DJ9s=";
npmDepsHash = "sha256-C8L5g+HY5aArLJzPbw3fESvA+U4JK1OQFWA4wwaan1M=";
version = "11.10.2";
srcHash = "sha256-d4sOH9L2vawyiRLXIhZLzEqExiYbrdy/h0v4GZW7DNc=";
vendorHash = "sha256-k3JPDzrZzLeKb20o2aLZR/TX7dN7nhpQs6UZ5olvV94=";
npmDepsHash = "sha256-jDGUbBwxjZ50bbbnUJVMCzKJMlHYhUKy7Be9zsWjMqg=";
autoUpdate = ./package.nix;
};
}

View File

@@ -136,7 +136,7 @@ stdenv.mkDerivation (finalAttrs: {
changelog = "https://github.com/miracle-wm-org/miracle-wm/releases/tag/v${finalAttrs.version}";
license = lib.licenses.gpl3Only;
mainProgram = "miracle-wm";
maintainers = with lib.maintainers; [ OPNA2608 ];
maintainers = [ ];
platforms = lib.platforms.linux;
};
})

View File

@@ -8,7 +8,7 @@
}:
let
version = "1.5.2";
version = "1.5.3";
in
rustPlatform.buildRustPackage {
@@ -19,10 +19,10 @@ rustPlatform.buildRustPackage {
owner = "twosigma";
repo = "nsncd";
tag = "v${version}";
hash = "sha256-HNg2pf6dUQW95B8x/xWa53+GZVWzpTMRVeqWT3dp/M8=";
hash = "sha256-CyZlvyD8PDPxnIGoQrOvx++GLNBatqfM9c+Ekt0PXHs=";
};
cargoHash = "sha256-kjxRhrgKPLCKWc3/gOvdcmQX7IdxFLuwcV7DRZIte78=";
cargoHash = "sha256-MC/WMnBrUr16tOhtP9ueHNLb2cLT8o3A6kwWOWLvFPk=";
checkFlags = [
# Relies on the test environment to be able to resolve "localhost"

View File

@@ -50,7 +50,7 @@ buildGoModule (finalAttrs: {
ldflags = [
"-s"
"-X \"github.com/OpenListTeam/OpenList/v4/internal/conf.GitAuthor=The OpenList Projects Contributors <noreply@openlist.team>\""
"-X \"github.com/OpenListTeam/OpenList/v4/internal/conf.GitAuthor=The OpenList Projects Contributors <noreply@oplist.org>\""
"-X github.com/OpenListTeam/OpenList/v4/internal/conf.Version=${finalAttrs.version}"
"-X github.com/OpenListTeam/OpenList/v4/internal/conf.WebVersion=${finalAttrs.frontend.version}"
];

View File

@@ -42,13 +42,13 @@
}:
buildGoModule (finalAttrs: {
pname = "podman";
version = "5.8.6";
version = "5.8.7";
src = fetchFromGitHub {
owner = "containers";
repo = "podman";
tag = "v${finalAttrs.version}";
hash = "sha256-a0m6y4Cwm395qYsDO0CFInUkm1AbGHCfBg3/RNMEoQs=";
hash = "sha256-E13EjBqCK/ABVxWJSZKn6vqpYXjTqqoBR5N7YnOqURI=";
};
patches = [

View File

@@ -11,16 +11,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "ripdrag";
version = "0.4.12";
version = "0.4.13";
src = fetchFromGitHub {
owner = "nik012003";
repo = "ripdrag";
tag = "v${finalAttrs.version}";
hash = "sha256-syirR3t3AxThwIPMviGaSeXpDz2ApDGZOozPJ5bGEt4=";
hash = "sha256-zpfT/nMy+sndDg3RWjbJ3ZxyBWoCst+cA+GKUBCTd1g=";
};
cargoHash = "sha256-/OczChiDDK6Y2CxpjfgWkTwweKe4FVpOMlsB+qMp/r8=";
cargoHash = "sha256-JitYn3SDCG/1UG2FZyGbhvXqTUJ/g977IBK84pgDcNw=";
nativeBuildInputs = [
pkg-config

View File

@@ -93,6 +93,7 @@ stdenv.mkDerivation (finalAttrs: {
gnome._gdkPixbufCacheBuilder_DO_NOT_USE {
extraLoaders = [
libheif.lib
librsvg
];
}
}"

View File

@@ -5,7 +5,7 @@
fetchFromGitHub,
alsa-utils,
copyDesktopItems,
electron_42,
electron_43,
libicns,
makeDesktopItem,
makeWrapper,
@@ -15,20 +15,20 @@
}:
let
electron = electron_42;
electron = electron_43;
in
buildNpmPackage rec {
pname = "teams-for-linux";
version = "2.17.1";
version = "2.22.0";
src = fetchFromGitHub {
owner = "IsmaelMartinez";
repo = "teams-for-linux";
tag = "v${version}";
hash = "sha256-qI8+QqnrkGmQGweMcfyaXQnjNMf4htJAF9Gk97zL9jg=";
hash = "sha256-FcAYtEX6SjXeJfxwCq9uSD2dOJt+WkBTQnP+SmSy5bY=";
};
npmDepsHash = "sha256-wPHap85tS3JrN4ei/HRYyzwFfVFcPkBdbY5ViEk4bwE=";
npmDepsHash = "sha256-t5Mz3X/VnMmEuy/dGJC17/Wk8WwLdmF0rVQ445T5YP4=";
nativeBuildInputs = [
makeWrapper

View File

@@ -177,6 +177,7 @@ stdenv.mkDerivation (finalAttrs: {
];
dontWrapQtApps = true;
separateDebugInfo = true;
preFixup = lib.optional (!clientLibOnly) ''
wrapProgram "$out/bin/wivrn-server" \

View File

@@ -0,0 +1,33 @@
From 938f8ba11c0676a1b9090c1cf788321ec24979e6 Mon Sep 17 00:00:00 2001
From: Steve Kowalik <steven@wedontsleep.org>
Date: Fri, 29 May 2026 12:00:23 +1000
Subject: [PATCH] Support Python 3.14 pickle changes
pickle.dump() and friends in Python 3.14 will now raise PicklingError
rather than AttributeError when they encounter something that can not be
pickled, extend test_385 to handle both exceptions.
---
tests/tests.py | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/tests/tests.py b/tests/tests.py
index f99f8e26..5ad67a55 100644
--- a/tests/tests.py
+++ b/tests/tests.py
@@ -2,6 +2,7 @@
from functools import reduce
import operator
import re
+from pickle import PicklingError
import platform
import unittest
from unittest import mock
@@ -659,7 +660,7 @@ def test_366(self):
def test_385(self):
Client.objects.create(name='Client Name')
- with self.assertRaisesRegex(AttributeError, "local object"):
+ with self.assertRaisesRegex((AttributeError, PicklingError), "local object"):
Client.objects.filter(name='Client Name').cache().first()
invalidate_model(Client)

View File

@@ -1,7 +1,8 @@
{
lib,
buildPythonPackage,
fetchPypi,
fetchFromGitHub,
fetchpatch,
django,
funcy,
redis,
@@ -18,17 +19,24 @@
setuptools,
}:
buildPythonPackage rec {
buildPythonPackage (finalAttrs: {
pname = "django-cacheops";
version = "7.2";
pyproject = true;
src = fetchPypi {
pname = "django_cacheops";
inherit version;
hash = "sha256-y8EcwDISlaNkTie8smlA8Iy5wucdPuUGy8/wvdoanzM=";
src = fetchFromGitHub {
owner = "Suor";
repo = "django-cacheops";
tag = finalAttrs.version;
hash = "sha256-o0QPBfoYZzBPMjDQt8ck2Tkx3qInyfnN88buire0yc4=";
};
patches = [
# Fixes failure with python3.14 pickle changes
# https://github.com/Suor/django-cacheops/pull/511
./Support-Python-3.14-pickle-changes.patch
];
pythonRelaxDeps = [ "funcy" ];
build-system = [ setuptools ];
@@ -59,8 +67,8 @@ buildPythonPackage rec {
meta = {
description = "Slick ORM cache with automatic granular event-driven invalidation for Django";
homepage = "https://github.com/Suor/django-cacheops";
changelog = "https://github.com/Suor/django-cacheops/blob/${version}/CHANGELOG";
changelog = "https://github.com/Suor/django-cacheops/blob/${finalAttrs.version}/CHANGELOG";
license = lib.licenses.bsd3;
maintainers = with lib.maintainers; [ onny ];
};
}
})

View File

@@ -23,7 +23,8 @@
}:
buildPythonPackage (finalAttrs: {
pname = "qtile-extras";
version = "0.36.0";
version = "0.37.1";
# nixpkgs-update: no auto update
# should be updated alongside with `qtile`
pyproject = true;
@@ -32,7 +33,7 @@ buildPythonPackage (finalAttrs: {
owner = "elParaguayo";
repo = "qtile-extras";
tag = "v${finalAttrs.version}";
hash = "sha256-H2A5Y+ukTkUqjQB5eQVuOMYpf7T8RgQlNlQ25wlWwr8=";
hash = "sha256-sR/+Nmd/reMSi2Cu3WBKgsBsTmNiNWsFsEhap2YHqF4=";
};
build-system = [ setuptools-scm ];

View File

@@ -71,7 +71,7 @@
buildPythonPackage (finalAttrs: {
pname = "qtile";
version = "0.36.0";
version = "0.37.1";
# nixpkgs-update: no auto update
# should be updated alongside with `qtile-extras`
@@ -81,7 +81,7 @@ buildPythonPackage (finalAttrs: {
owner = "qtile";
repo = "qtile";
tag = "v${finalAttrs.version}";
hash = "sha256-yFh9h3djV52zdZjPYwOWaMzN9ZNhFdZYyxFJreoJBCk=";
hash = "sha256-n45e5/XvzKjH/ehatDPA+UWIlaiwSUhYnoPQOb5cLnA=";
};
build-system = [
@@ -209,8 +209,8 @@ buildPythonPackage (finalAttrs: {
};
postInstall = ''
install resources/qtile.desktop -Dt $out/share/xsessions
install resources/qtile-wayland.desktop -Dt $out/share/wayland-sessions
install -Dm644 resources/qtile-generic.desktop $out/share/xsessions/qtile.desktop
install -Dm644 resources/qtile-generic.desktop $out/share/wayland-sessions/qtile.desktop
'';
meta = {

View File

@@ -1,7 +1,7 @@
{
"testing": {
"version": "7.3-rc3",
"hash": "sha256:0zrdl82lfs3jxbx9gfi9klaq5078r18277bhikxyibx0mq78ykax",
"version": "7.3-rc4",
"hash": "sha256:0bsd7w8xsd06g1kf5ildf6jnsryk5s2w5838ihp3237fh2sz8agr",
"lts": false
},
"6.1": {
@@ -25,18 +25,18 @@
"lts": true
},
"6.12": {
"version": "6.12.110",
"hash": "sha256:0k2w1lr3h1d814707vfmj826gaz67a9n3msla96zzdlvhghikvlc",
"version": "6.12.111",
"hash": "sha256:044qhkby6dgrb4mmggk6j0m6dmlw96c9a7v0lq9gm221c9kxqncy",
"lts": true
},
"6.18": {
"version": "6.18.52",
"hash": "sha256:1f11had1amrvhl5f606ikc9ykrlyf0rvln8rkf2hrsjggm7mcs9b",
"version": "6.18.53",
"hash": "sha256:1q6gfh9v2p5v82p84xjypcdb6kxyp4w4sjhlnjkhhjr4qaavlvsd",
"lts": true
},
"7.2": {
"version": "7.2.6",
"hash": "sha256:01pnc344dx239hkfl84hpfdpm7gc08yzrz7llgnlm6dhya2fz6h3",
"version": "7.2.7",
"hash": "sha256:0nhl8fniqz9v95d54d39pbh045zzj7cghhrrf6rgyh15vd3lrhsa",
"lts": false
}
}