Compare commits

...

481 Commits

Author SHA1 Message Date
nixpkgs-ci[bot]
2ba8b0c93e Merge master into staging-next 2026-07-26 00:35:08 +00:00
isabel
929adb31f5 {tranquil-pds, tranquil-pds-frontend}: 0.6.5 -> 0.6.6 (#545777) 2026-07-26 00:24:52 +00:00
Sandro
92d6c402cc lunar-client: 3.7.11 -> 3.7.12 (#544738) 2026-07-26 00:24:45 +00:00
Sandro
4cb5271844 python3Packages.ezdxf: 1.4.3 -> 1.4.4 (#442194) 2026-07-26 00:23:09 +00:00
Sandro
dd252872db houdini: update link to download requireFile (#519775) 2026-07-26 00:16:08 +00:00
Justin Bedő
4bb9026bef R updates (#539315) 2026-07-26 00:02:08 +00:00
dotlambda
e488d836cf bitwarden-cli: 2026.6.0 -> 2026.7.0 (#545775) 2026-07-25 23:28:15 +00:00
Heitor Augusto
e9370c55d1 polonium: 1.2.0 -> 1.2.1 (#545536) 2026-07-25 23:27:45 +00:00
Yohann Boniface
025c5c6988 pappl: 1.4.10 -> 1.4.11 (#528597) 2026-07-25 23:22:55 +00:00
Emily
a4d98e40c7 chromium: remove broken pulseSupport = false; override (#540868) 2026-07-25 23:18:16 +00:00
Thiago Kenji Okada
aa3f875ae2 libretro.dolphin: 0-unstable-2026-07-12 -> 0-unstable-2026-07-23 (#545494) 2026-07-25 22:48:17 +00:00
Bruno BELANYI
d65da55c82 python3Packages.django-scopes: 2.0.0 -> 2.1.0 (#545578) 2026-07-25 22:47:03 +00:00
nelind
86dc66e4ee tranquil-pds-frontend: 0.6.5 -> 0.6.6 2026-07-26 00:46:10 +02:00
TomaSajt
01ca76dcbc rPackages.talib: fix build 2026-07-26 08:39:54 +10:00
TomaSajt
28a7542ca2 rPackages.{BayesPET,GapAnalysis}: fix build 2026-07-26 08:39:54 +10:00
TomaSajt
4959772f70 rPackages.{minimaxALT,netboost,impARI,telegramR}: fix build 2026-07-26 08:39:54 +10:00
TomaSajt
b850a337c8 rPackages.Rmpi: remove unnecessary configure flags 2026-07-26 08:39:53 +10:00
TomaSajt
ab1fe49f69 rPackages.npRmpi: fix build 2026-07-26 08:39:53 +10:00
TomaSajt
99ec020953 rPackages: fix more builds 2026-07-26 08:39:53 +10:00
TomaSajt
9b2b89eeca rPackages.{RFIF,gridmicrotex}: fix build 2026-07-26 08:39:52 +10:00
TomaSajt
a6f3f5e1a1 rPackages.{BinaryDosage,cmtkr,drogonR,lstar}: fix build 2026-07-26 08:39:52 +10:00
TomaSajt
9bc8a2ef64 rPackages.{automerge,libipldr}: fix build 2026-07-26 08:39:52 +10:00
TomaSajt
1c13ea5c1f rPackages.rvMF: fix build 2026-07-26 08:39:51 +10:00
TomaSajt
497ff4c10e rPackages.mx_crypto: fix build 2026-07-26 08:39:51 +10:00
TomaSajt
3c5a75f40e rPackages.sundialr: fix build 2026-07-26 08:39:51 +10:00
TomaSajt
2ab6dfb50c rPackages.scip: fix build 2026-07-26 08:39:50 +10:00
TomaSajt
088cf6c9f2 rPackages.Uno: fix build 2026-07-26 08:39:50 +10:00
TomaSajt
febfb4bdfa rPackages.buildRPackage: patch shebangs automatically in configure 2026-07-26 08:39:50 +10:00
László Kupcsik
9a18c35488 rPackages: Remove explicit references to split outputs
Clean up
2026-07-26 08:39:49 +10:00
TomaSajt
38e6d10918 R: move to pkgs/by-name 2026-07-26 08:39:49 +10:00
TomaSajt
73a89410bf R: move default withRecommendedPackages value into package file 2026-07-26 08:39:49 +10:00
László Kupcsik
2867d59a3e rPackages.fraq: add missing deps 2026-07-26 08:39:48 +10:00
TomaSajt
1c9b1139d5 rPackages.redatamx: fix build, set unfree 2026-07-26 08:39:48 +10:00
László Kupcsik
134290ea71 rPackages.HiSpaR: add missing dep 2026-07-26 08:39:48 +10:00
TomaSajt
444678226f rPackages.{FactoMineR,pander}: remove extra RDepends 2026-07-26 08:39:47 +10:00
TomaSajt
7c7dab194d rPackages: append extra RDepends to propagatedBuildInputs 2026-07-26 08:39:47 +10:00
László Kupcsik
4a25c9a06f rPackages.SingleR: fix build 2026-07-26 08:39:47 +10:00
TomaSajt
d50bfc3ff7 rPackages.stringfish: don't use vendored pcre2 2026-07-26 08:39:46 +10:00
TomaSajt
d7d3021eb7 rPackages: unify and fix packages using R CMD config --ldflags 2026-07-26 08:39:46 +10:00
TomaSajt
ab4af867cf rPackages: prune packagesToSkipCheck 2026-07-26 08:39:46 +10:00
TomaSajt
f9effd3338 rPackages.Rmpi: fix missing symbol error 2026-07-26 08:39:45 +10:00
TomaSajt
2f8f40d2ea rPackages.V8: unpin icu 2026-07-26 08:39:45 +10:00
TomaSajt
e0ff180112 rPackages: fix strictDeps build for broken packages 2026-07-26 08:39:45 +10:00
TomaSajt
b3bd3fef87 rPackages.cn_farms: fix build by dropping patch 2026-07-26 08:39:45 +10:00
TomaSajt
97b1439fc9 rPackages: fix strictDeps build for several packages (part 6) 2026-07-26 08:39:44 +10:00
TomaSajt
9684a329bf rPackages: fix strictDeps build for several packages (part 5) 2026-07-26 08:39:44 +10:00
TomaSajt
8d9e8784da rPackages: fix strictDeps build for several packages (part 4) 2026-07-26 08:39:44 +10:00
TomaSajt
8529f99427 rPackages: fix strictDeps build for several packages (part 3) 2026-07-26 08:39:43 +10:00
TomaSajt
6e5e7484d6 rPackages.{unix,RAppArmor}: use libapparmor 2026-07-26 08:39:43 +10:00
TomaSajt
70ed89608f rPackages: fix strictDeps build for several packages (part 2) 2026-07-26 08:39:43 +10:00
TomaSajt
747d9feae6 rPackages: apply keep-sorted directives 2026-07-26 08:39:42 +10:00
TomaSajt
378d5c7497 rPackages: add keep-sorted directives 2026-07-26 08:39:42 +10:00
TomaSajt
662771f792 rPackages.pathfindR: remove broken patch 2026-07-26 08:39:41 +10:00
TomaSajt
8706bc4b89 jasp-desktop: 0.97.1 -> 0.98.1 2026-07-26 08:39:41 +10:00
TomaSajt
9651249dd1 rPackages: fix strictDeps build for several packages (part 1) 2026-07-26 08:39:41 +10:00
Dev
e072c356b1 rPackages.V8: fixed build 2026-07-26 08:39:41 +10:00
Justin Bedo
014130f610 rPackages.pak: fix build 2026-07-26 08:39:40 +10:00
Justin Bedo
052bce2493 rPackages.RSQLite: fix build 2026-07-26 08:39:40 +10:00
Justin Bedo
e061c6a434 rPackages: CRAN and BioC update 2026-07-26 08:39:39 +10:00
Justin Bedo
519bc6a880 R: 4.6.0 -> 4.6.1 2026-07-26 08:39:38 +10:00
nelind
ac312f87f9 tranquil-pds: 0.6.5 -> 0.6.6 2026-07-26 00:35:31 +02:00
zowoq
9df45099c2 terraform-providers.hashicorp_azurerm: 4.79.0 -> 4.81.0 (#545639) 2026-07-25 22:32:09 +00:00
R. Ryantm
6942ec2e59 bitwarden-cli: 2026.6.0 -> 2026.7.0 2026-07-25 22:27:54 +00:00
nixpkgs-ci[bot]
161c72f5cd fosrl-newt: 1.14.0 -> 1.15.0 (#545433) 2026-07-25 22:26:55 +00:00
Masum Reza
9112783bed hyprlandPlugins.hy3: 0.55.0 -> 0.56.0.1 (#545727) 2026-07-25 22:20:56 +00:00
Stefan Frijters
fbccc899b5 wildergarden-maim: __structuredAttrs fix (#545771) 2026-07-25 22:08:58 +00:00
nikstur
61b75d16de nix-store-veritysetup-generator: 1.0.0 -> 1.0.1 (#545728) 2026-07-25 22:05:36 +00:00
Yohann Boniface
393884397a panache: enable install check (#545712) 2026-07-25 22:02:01 +00:00
Yohann Boniface
2f478a0b4a valgrind: add albfsg as maintainer (#545510) 2026-07-25 21:55:31 +00:00
Martin Weinelt
db67362752 hedgedoc: 1.11.0 -> 1.11.1 (#545446) 2026-07-25 21:52:45 +00:00
Jo
83b7df8e6b buildFHSEnv, appimageTools: support finalAttrs (#498806) 2026-07-25 21:52:39 +00:00
Felix Bargfeldt
91f1117bdd par-lang: 0-unstable-2026-07-15 -> 0-unstable-2026-07-24 (#545765) 2026-07-25 21:39:19 +00:00
Michael Daniels
39b8e3e862 wildergarden-maim: __structuredAttrs fix 2026-07-25 17:35:59 -04:00
Michael Daniels
c6a0ce5b10 blueprint-compiler: set strictDeps (#526175) 2026-07-25 21:32:40 +00:00
R. Ryantm
a7503406b2 par-lang: 0-unstable-2026-07-15 -> 0-unstable-2026-07-24 2026-07-25 21:27:32 +00:00
nixpkgs-ci[bot]
0f2f872495 libdisplay-info: 0.3.0 -> 0.4.0 (#545480) 2026-07-25 21:26:35 +00:00
nixpkgs-ci[bot]
c8c029256f nushellPlugins.skim: 0.29.0 -> 0.29.1 (#542147) 2026-07-25 21:26:15 +00:00
Martin Weinelt
645360ba39 python3Packages.gpiozero: 2.0.1 -> 2.0.1.post2 (#545761) 2026-07-25 21:24:12 +00:00
dotlambda
e6a80147f8 python3Packages.elevenlabs: 2.58.0 -> 2.59.0 (#545758) 2026-07-25 21:18:41 +00:00
Martin Weinelt
02723ee212 python3Packages.gpiozero: 2.0.1 -> 2.0.1.post2
https://github.com/gpiozero/gpiozero/blob/v2.0.1.post2/docs/changelog.rst
2026-07-25 23:18:21 +02:00
uku
147944a023 simplenote: add missing desktopName 2026-07-25 23:06:41 +02:00
uku
a9d937331d pixinsight: inherit meta correctly 2026-07-25 23:06:41 +02:00
uku
2e8c34b71a appimageTools: support finalAttrs
Replaces function invocation with lib.extendMkDerivation.
Warning: wrapAppImage now takes a `contents` argument instead of `src`,
to avoid shadowing the original AppImage file (eg. when using wrapType2)
The extracted archive can be accessed in derivations via `finalAttrs.contents`
2026-07-25 23:06:41 +02:00
uku
47b6451999 buildFHSEnv: support finalAttrs
this commit removes the usage of runCommandLocal in favor of a normal
mkDerivation that does the exact same thing, with the added benefit of
using extendMkDerivation
2026-07-25 23:06:34 +02:00
Markus Kowalewski
e624729bd3 octopus: 16.3 -> 16.4, add cuda and hip support (#544827) 2026-07-25 21:06:31 +00:00
Stefan Frijters
5918980a5f diodon: 1.13.0 -> 1.14.0 (#545595) 2026-07-25 21:06:15 +00:00
R. Ryantm
4723fa5617 python3Packages.elevenlabs: 2.58.0 -> 2.59.0 2026-07-25 21:02:23 +00:00
Nikolay Korotkiy
e38cb26f3d python3Packages.oelint-parser: 8.11.6 -> 8.12.1 (#545599) 2026-07-25 20:58:28 +00:00
Francesco Gazzetta
953b3a389c tclPackages.cffi: init at 2.0.3 (#367883) 2026-07-25 20:49:41 +00:00
Alexis Hildebrandt
198048016f kopuz: 0.10.0 -> 0.12.0 (#545694) 2026-07-25 20:48:14 +00:00
Alexis Hildebrandt
5b7a0b225f wayle: 0.6.0 -> 0.7.0 (#545646) 2026-07-25 20:47:47 +00:00
Francesco Gazzetta
a9214c8c1e tcl-9_0: 9.0.3 -> 9.0.4 (#537864) 2026-07-25 20:45:38 +00:00
dotlambda
b3bd1a11ab home-assistant-custom-components.cover_time_based: 4.7.2 -> 4.9.0 (#545745) 2026-07-25 20:45:15 +00:00
Nikolay Korotkiy
034f182418 dracut: add patch for CVE-2026-6893 (#545539) 2026-07-25 20:40:16 +00:00
Fabian Affolter
76e8396b35 python3Packages.vsure: 2.9.0 -> 2.10.0 (#545417) 2026-07-25 20:36:38 +00:00
Fabian Affolter
bf4ac76fa1 python313Packages.pyeconet: 0.2.2 -> 0.2.5 (#544457) 2026-07-25 20:35:14 +00:00
Nikolay Korotkiy
f07170e43e dump1090-fa: 10.2 -> 11.1 (#545152) 2026-07-25 20:35:12 +00:00
Thomas Butter
8be50135f3 dracut: add patch for CVE-2026-6893 2026-07-25 20:35:09 +00:00
Fabian Affolter
c2b9f6777a troubadix: 26.7.1 -> 26.7.2 (#545613) 2026-07-25 20:34:42 +00:00
R. Ryantm
c3aec2ba8d home-assistant-custom-components.cover_time_based: 4.7.2 -> 4.9.0 2026-07-25 20:33:27 +00:00
Fabian Affolter
80e5c29a8d python3Packages.pyeconet: 0.2.2 -> 0.2.5 (#545568) 2026-07-25 20:30:48 +00:00
Fabian Affolter
88ddc79783 kingfisher: 1.107.0 -> 1.109.0 (#545550) 2026-07-25 20:30:21 +00:00
dotlambda
faa7f7ec44 buildFHSEnv: enable strictDeps (#544967) 2026-07-25 20:27:36 +00:00
Adam C. Stephens
c2809ca95b claude-code: allow easily overriding manifest (#545424) 2026-07-25 20:16:14 +00:00
Adam C. Stephens
4d0ba85856 nixos/release-notes: fix option references for virtualisation.containers.registries (#545686) 2026-07-25 20:15:35 +00:00
nixpkgs-ci[bot]
3ddac825f8 opentofu-mcp-server: 1.0.0-unstable-2026-06-09 -> 1.0.0-unstable-2026-07-15 (#541840) 2026-07-25 20:04:27 +00:00
dish
0267914b93 noctalia: 5.0.0-beta.4 -> 5.0.0-beta.5 (#545720) 2026-07-25 19:55:02 +00:00
Daru
57154f3d7f hyprlandPlugins.hy3: 0.55.0 -> 0.56.0.1 2026-07-25 21:50:19 +02:00
dish
dd904cf110 noctalia: 5.0.0-beta.4 -> 5.0.0-beta.5
Changelog: https://noctalia.dev/changelogs#v5.0.0-beta.5
2026-07-25 15:50:09 -04:00
R. Ryantm
1f6d4ed2df nix-store-veritysetup-generator: 1.0.0 -> 1.0.1 2026-07-25 19:46:21 +00:00
nixpkgs-ci[bot]
9ee20e0f94 bento: 1.18.1 -> 1.19.0 (#545703) 2026-07-25 19:34:55 +00:00
nixpkgs-ci[bot]
42547fa6cc kicad-testing-small: 10.0-2026-07-09 -> 10.0-2026-07-21 (#544528) 2026-07-25 19:34:30 +00:00
Sandro
f0fe1ac48c stremio-service: init at 0.1.21 (#545675) 2026-07-25 19:30:23 +00:00
Sandro
7b130a7b75 rustfs: 1.0.0-beta.10 -> 1.0.0-beta.11 (#545692) 2026-07-25 19:23:57 +00:00
Sandro
877c6e9372 python3Packages.daphne: 4.2.2 -> 4.2.3 (#545096) 2026-07-25 19:15:03 +00:00
Rachala Raj
7c51ba2a3e stremio-service: init at 0.1.21 2026-07-26 00:43:41 +05:30
Michael Daniels
92ff601c5c nixos/mango: rename from mangowc (#539030) 2026-07-25 19:12:09 +00:00
Mauricio Collares
dad717e04c sage: rename python package from sagelib to sagemath (#545640) 2026-07-25 19:11:38 +00:00
Ben Siraphob
f2da850dfd blueprint-compiler: set strictDeps
Co-authored-by: Michael Daniels <mdaniels5757@gmail.com>
2026-07-25 15:07:45 -04:00
Johan Larsson
ca74517126 panache: enable install check
versionCheckHook only runs when doInstallCheck is set.
2026-07-25 21:01:39 +02:00
Ihar Hrachyshka
0457e97587 xclock: 1.2.0 -> 1.2.1 (#545551) 2026-07-25 18:46:49 +00:00
nixpkgs-ci[bot]
9a346bf20e nushell-plugin-hcl: 0.114.0 -> 0.114.1 (#545710) 2026-07-25 18:43:57 +00:00
R. Ryantm
32ae284834 nushell-plugin-hcl: 0.114.0 -> 0.114.1 2026-07-25 18:32:13 +00:00
nixpkgs-ci[bot]
136ea50568 rustnet: 1.3.0 -> 1.5.0 (#533408) 2026-07-25 18:26:43 +00:00
nixpkgs-ci[bot]
2c891a6f1f Merge master into staging-next 2026-07-25 18:18:43 +00:00
Username404-59
e9d32fcea2 wayle: 0.6.0 -> 0.7.0 2026-07-25 20:14:11 +02:00
R. Ryantm
cfb4cc0d96 bento: 1.18.1 -> 1.19.0 2026-07-25 18:03:26 +00:00
Sandro
4ad1e78bb6 legendsviewer-next: init at 1.2.5 (#405918) 2026-07-25 18:00:11 +00:00
nixpkgs-ci[bot]
ec01aa24a0 cargo-shear: 1.13.2 -> 1.13.3 (#545688) 2026-07-25 17:57:36 +00:00
dotlambda
cc1396afd1 python3Packages.pyisy: 3.6.1 -> 3.7.0 (#545696) 2026-07-25 17:53:49 +00:00
Samuel Ainsworth
b2a8a65ad0 python3Packages.mhcgnomes: 3.32.1 -> 3.33.4 (#545509) 2026-07-25 17:37:07 +00:00
R. Ryantm
610928778e python3Packages.pyisy: 3.6.1 -> 3.7.0 2026-07-25 17:31:48 +00:00
temidaradev
14f9cea17e kopuz: 0.10.0 -> 0.12.0 2026-07-25 20:30:50 +03:00
Sandro
1169e0abeb OVMF: ship qemu firmware descriptors (#539233) 2026-07-25 17:30:50 +00:00
Michael Daniels
4d1e3ff59e quarkdown: init at 1.6.1 (#422160) 2026-07-25 17:13:59 +00:00
nixpkgs-ci[bot]
adcdea620d bisq1: 1.10.3 -> 1.10.4 (#545622) 2026-07-25 17:02:57 +00:00
nixpkgs-ci[bot]
56de350dcd glaze: 7.9.0 -> 7.9.1 (#545603) 2026-07-25 17:02:55 +00:00
Jo
e9ca7aa0bd python3Packages.flask-reverse-proxy-file: use lib.licenses.ogluk30 (#540724) 2026-07-25 16:59:17 +00:00
Yohann Boniface
ae2c2f465e fsuae: enable parallel building (#545629) 2026-07-25 16:56:59 +00:00
R. Ryantm
ca59ee9ad2 cargo-shear: 1.13.2 -> 1.13.3 2026-07-25 16:54:06 +00:00
Sandro Jäckel
e4c7ce47ac nixos/release-notes: fix option references for virtualisation.containers.registries 2026-07-25 18:45:38 +02:00
Jo
0361d27e98 lib.licenses.stk: use upstream spdx info (#541831) 2026-07-25 16:44:19 +00:00
Michael Daniels
50febbbce7 cargo-binstall: 1.21.0 -> 1.21.1 (#545647) 2026-07-25 16:42:18 +00:00
nixpkgs-ci[bot]
4076bf8495 lstk: 0.17.0 -> 0.18.0 (#545606) 2026-07-25 16:35:17 +00:00
nixpkgs-ci[bot]
2f88416c69 graphicsmagick: 1.3.47 -> 1.3.48 (#545268) 2026-07-25 16:35:08 +00:00
Florian
2f4a136ec7 octoprint: 1.11.7 -> 1.11.8 (#545567) 2026-07-25 16:31:06 +00:00
dish
337eba0612 overseerr: migrate overseerr to seerr (#450096) 2026-07-25 16:27:42 +00:00
Pol Dellaiera
e6994d7d89 vscode-extensions.oxc.oxc-vscode: 1.58.0 -> 1.59.0 (#545656) 2026-07-25 16:18:25 +00:00
Sandro
997a0b100d nixos/qemu-firmware: init (#538983) 2026-07-25 16:13:16 +00:00
Maciej Krüger
c7ecec0ae3 openclaw: 2026.6.11 -> 2026.6.33 (#544629) 2026-07-25 16:12:43 +00:00
Cosima Neidahl
c41ff93dad libayatana-common: 0.9.11 -> 0.9.13 (#532139) 2026-07-25 16:03:54 +00:00
Michael Daniels
aa47e78b28 python3Packages.sqlobject: remove paste from dependencies (#538451) 2026-07-25 16:02:00 +00:00
Gergő Gutyina
cea6971180 bottom: 0.14.4 -> 0.14.6 (#545621) 2026-07-25 16:01:16 +00:00
Sandro
f491c9ef41 intel-llvm: fix build (#542193) 2026-07-25 15:55:43 +00:00
R. Ryantm
55a5ffdda8 vscode-extensions.oxc.oxc-vscode: 1.58.0 -> 1.59.0 2026-07-25 15:55:41 +00:00
Michael Daniels
e27d2a93fd mangowc: alias mango instead of throwing
See https://github.com/NixOS/nixpkgs/pull/539030#issuecomment-4930104543
2026-07-25 11:55:37 -04:00
Michael Daniels
11d31fc14e wildergarden-maim: init at 0-unstable-2025-12-17 (#461467) 2026-07-25 15:55:24 +00:00
Yohann Boniface
3d5bfdf361 python3Packages.pyimouapi: improve meta.changelog (#545632) 2026-07-25 15:48:32 +00:00
Ludovic Ortega
90b33c2f2d overseerr: migrate overseerr to seerr
Signed-off-by: Ludovic Ortega <ludovic.ortega@adminafk.fr>
2026-07-25 17:45:39 +02:00
Sandro
36d67faffa as-tree: fix version scheme (#542399) 2026-07-25 15:44:51 +00:00
Sandro
9705e3bf68 python3Packages.flashinfer: add missing requests dependency (#544692) 2026-07-25 15:42:43 +00:00
Sandro
d28d49d4a4 umple-lsp: init at 1.0.2 (#537938) 2026-07-25 15:42:05 +00:00
Sandro
3988a1454b azure-mcp: init at 3.0.0-beta.10 (#491453) 2026-07-25 15:41:35 +00:00
nixpkgs-ci[bot]
36e3d11cf2 bant: 0.3.0 -> 0.3.3 (#545624) 2026-07-25 15:41:33 +00:00
Sandro
c2e917178d python3Packages.outlines: add missing pillow dependency (#544694) 2026-07-25 15:40:49 +00:00
mrtnvgr
ea14011c43 wildergarden-maim: init at 1.1.1-unstable-2025-12-17
Co-authored-by: Michael Daniels <mdaniels5757@gmail.com>
2026-07-25 11:40:20 -04:00
Michael Daniels
40dbc22cd8 flux-build: init at 3.0.10 (#440282) 2026-07-25 15:39:03 +00:00
R. Ryantm
6b7fb8f2ce cargo-binstall: 1.21.0 -> 1.21.1 2026-07-25 15:36:27 +00:00
Robert Schütz
3baf5a75f4 python3Packages.sqlobject: remove paste from dependencies
It's not listed in install_requires.
2026-07-25 11:35:08 -04:00
Ludovic Ortega
ba2fbde84c maintainers: drop jf-uu
Signed-off-by: Ludovic Ortega <ludovic.ortega@adminafk.fr>
2026-07-25 17:34:45 +02:00
R. Ryantm
c6c6e3ee3a terraform-providers.hashicorp_azurerm: 4.79.0 -> 4.81.0 2026-07-25 15:25:03 +00:00
Yohann Boniface
37bfb33419 python3Packages.stripe: 15.3.0 -> 15.3.1 (#545452) 2026-07-25 15:19:31 +00:00
Marcel
f846b7a768 rustfs: 1.0.0-beta.10 -> 1.0.0-beta.11
Diff: https://github.com/rustfs/rustfs/compare/1.0.0-beta.10...1.0.0-beta.11
2026-07-25 17:17:33 +02:00
Cosima Neidahl
25a327121b miriway: 26.01 -> 26.06.3 (#532137) 2026-07-25 15:13:58 +00:00
nixpkgs-ci[bot]
87ab7b5bde pimsync: 0.5.10 -> 0.5.11 (#543147) 2026-07-25 15:10:29 +00:00
Max Thomson
95d4c6bc0b flux-build: init at 3.0.10
Co-authored-by: Michael Daniels <mdaniels5757@gmail.com>
2026-07-25 11:07:18 -04:00
Max Thomson
add81a03c2 maintainers: add MNThomson 2026-07-25 11:07:18 -04:00
Yohann Boniface
f79d8318a2 xpipe: 23.7 -> 23.8 (#545450) 2026-07-25 15:06:21 +00:00
Yohann Boniface
45c46c594f python3Packages.pyimouapi: 1.3.0 -> 1.3.2 (#545503) 2026-07-25 15:04:49 +00:00
Sigmanificient
039d87ba01 python3Packages.pyimouapi: improve meta.changelog 2026-07-25 17:03:30 +02:00
Sigmanificient
88c98a0d79 fsuae: enable parallel building 2026-07-25 16:52:57 +02:00
Yohann Boniface
630bb08227 fsuae: drop unused gtk2 (#545453) 2026-07-25 14:49:42 +00:00
Anton Tayanovskyy
6935b590e8 sage: rename python package from sagelib to sagemath
This change fixes `nix build .#sage`. The regression is due to a new check, pythonMetadataCheckHook,
introduced in #532778; the check enforces that pname matches the metadata name of the underlying Python
project being built, typically in pyproject.toml; in this case the underlying name is "sagemath".
2026-07-25 10:44:15 -04:00
Thomas Gerbet
2252d3e2ad ocelot-desktop: avoid putting empty segments in PATH and LD_LIBRARY_PATH (#545608) 2026-07-25 14:42:52 +00:00
nixpkgs-ci[bot]
10b08b8854 davinci-resolve: 21.0.1 -> 21.0.3 (#539038) 2026-07-25 14:40:27 +00:00
adisbladis
10438afccd emacsPackages.majutsu: update to 0.6.0-unstable-2026-07-23 (#545620) 2026-07-25 14:33:58 +00:00
R. Ryantm
122a9f7be6 bant: 0.3.0 -> 0.3.3 2026-07-25 14:32:11 +00:00
R. Ryantm
081e6f29ef bisq1: 1.10.3 -> 1.10.4 2026-07-25 14:26:22 +00:00
Sandro
9a75b2270a raspi-utils: init at 0-unstable-2026-07-08 (#542262) 2026-07-25 14:22:45 +00:00
Arthur Heymans
138f9b0486 emacsPackages.majutsu: update to 0.6.0-unstable-2026-07-23
Update to the latest upstream commit and include the newly required
consult and plz dependencies.
2026-07-25 16:19:59 +02:00
Sandro
7a610a393f nixos/unbound: resolveLocalQueries with resolved (#539991) 2026-07-25 14:19:13 +00:00
Sandro
a75c838377 nixos/nsd: After/Want network-online.target (#541061) 2026-07-25 14:18:51 +00:00
R. Ryantm
976a38d3a8 bottom: 0.14.4 -> 0.14.6 2026-07-25 14:14:19 +00:00
Marcin Serwin
d271bcee7e SDL_mixer: 1.2.12 -> 1.2.12-unstable-2026-05-11 (#544613) 2026-07-25 14:13:47 +00:00
Gergő Gutyina
bd3349d2db pnpm: 11.16.0 -> 11.17.0 (#545526) 2026-07-25 14:05:05 +00:00
Marcin Serwin
f8dc89327e cubeb: 0-unstable-2026-07-16 -> 0-unstable-2026-07-25 (#545525) 2026-07-25 14:00:00 +00:00
nixpkgs-ci[bot]
acb0147cce gearboy: 3.8.9 -> 3.8.11 (#545605) 2026-07-25 13:57:04 +00:00
nixpkgs-ci[bot]
e3e28ba32a deno: 2.9.3 -> 2.9.4 (#545216) 2026-07-25 13:56:50 +00:00
R. Ryantm
c16695a7b7 troubadix: 26.7.1 -> 26.7.2 2026-07-25 13:36:01 +00:00
Thomas Gerbet
827022194a docker: avoid setting empty path segments into PATH (#545560) 2026-07-25 13:31:23 +00:00
Donovan Glover
d13603be1d hyprlandPlugins.hypr-darkwindow: 0.55.4 -> 0.56.0 (#545374) 2026-07-25 13:30:06 +00:00
Martin Weinelt
335d4b802d home-assistant: 2026.7.3 -> 2026.7.4 (#545439) 2026-07-25 13:24:43 +00:00
Thomas Gerbet
d92de35181 ocelot-desktop: avoid putting empty segments in PATH and LD_LIBRARY_PATH 2026-07-25 15:23:38 +02:00
nicoo
cfe6a78499 python3Packages.pysimplesoap: migrate to pyproject (#543346) 2026-07-25 13:21:39 +00:00
R. Ryantm
25fca87ec6 lstk: 0.17.0 -> 0.18.0 2026-07-25 13:18:54 +00:00
R. Ryantm
7f5568e6cf gearboy: 3.8.9 -> 3.8.11 2026-07-25 13:18:48 +00:00
Francesco Gazzetta
12766e45af tclPackages.cffi: init at 2.0.3 2026-07-25 15:12:41 +02:00
Sandro
1968d142a8 sbsigntool: make unused-but-set-variable non-fatal for gcc 16 (#537411) 2026-07-25 13:01:07 +00:00
R. Ryantm
5e002b0a52 davinci-resolve: 21.0.1 -> 21.0.3 2026-07-25 12:52:44 +00:00
nicoo
897981fe69 pulumi: 3.192.0 -> 3.253.0 (#536699) 2026-07-25 12:50:12 +00:00
R. Ryantm
eb2ab8368b python3Packages.oelint-parser: 8.11.6 -> 8.12.1 2026-07-25 12:49:37 +00:00
R. Ryantm
4664e700a0 glaze: 7.9.0 -> 7.9.1 2026-07-25 12:46:26 +00:00
nicoo
25f9933883 pulumi, pulumi-python, python3Packages.pulumi: add nicoo as maintainer 2026-07-25 12:44:29 +00:00
Robert Hensing
bf57aa089b nixosTests.ghostunnel-modular: fix test (#541269) 2026-07-25 12:43:25 +00:00
nixpkgs-ci[bot]
beafba482d automatic-timezoned: 2.0.143 -> 2.0.149 (#545502) 2026-07-25 12:42:53 +00:00
nixpkgs-ci[bot]
03502b7d6a google-lighthouse: 13.4.0 -> 13.4.1 (#545273) 2026-07-25 12:42:38 +00:00
Sandro
166a63ea12 brave, brave-origin: extract shared builder, init at 1.92.144 (#540488) 2026-07-25 12:37:05 +00:00
R. Ryantm
9186f602e0 diodon: 1.13.0 -> 1.14.0 2026-07-25 12:34:48 +00:00
nikstur
50c0be3803 nixos/userborn: fix cross compilation with userborn.static.enable (#545490) 2026-07-25 12:33:51 +00:00
Sandro
9922327b5b rapidyaml: 0.11.1 -> 0.16.0 (#517494) 2026-07-25 12:24:26 +00:00
Sandro
5cd6f09987 modsecurity_standalone: pcre -> pcre2 (#545558) 2026-07-25 12:23:14 +00:00
Sandro
863d0e6c48 python3Packages.yoto-api: 4.3.1 -> 4.3.2 (#545566) 2026-07-25 12:22:49 +00:00
Sandro
0812368cb9 home-assistant-custom-components.hochwasserportal: 1.0.8 -> 1.0.9 (#545337) 2026-07-25 12:22:12 +00:00
Sandro
6853058efa home-assistant-custom-components.cover_time_based: init at 4.7.2 (#543698) 2026-07-25 12:20:00 +00:00
Marc Jakobi
f3ca8c8be6 vimPlugins.fff-nvim: fix illegal instructions by targetting a baseline CPU (#545572) 2026-07-25 12:16:45 +00:00
Nikolay Korotkiy
d654dd76ab mapnik: 4.2.2 -> 4.3.0 (#545557) 2026-07-25 12:09:49 +00:00
Martin Weinelt
883b729777 home-assistant.python3Packages.pytest-homeassistant-custom-component: 0.13.347 -> 0.13.348
https://github.com/MatthewFlamm/pytest-homeassistant-custom-component/blob/0.13.348/CHANGELOG.md
2026-07-25 14:05:36 +02:00
R. Ryantm
f22784b1b7 rapidyaml: 0.11.1 -> 0.16.0 2026-07-25 11:55:47 +00:00
Gergő Gutyina
e9518a982a dbeaver-bin: 26.1.1 -> 26.1.3 (#544907) 2026-07-25 11:54:04 +00:00
R. Ryantm
c9a0980d21 python3Packages.django-scopes: 2.0.0 -> 2.1.0 2026-07-25 11:25:10 +00:00
Thomas Gerbet
3c293e782c zellij: avoid putting empty path segment into PATH when extraPackages is empty (#545564) 2026-07-25 11:18:08 +00:00
Yt
edcd9e9929 gotosocial: fix cross-compilation on RISCV (#544570) 2026-07-25 11:17:21 +00:00
R. Ryantm
e79819a2a8 python3Packages.pyeconet: 0.2.2 -> 0.2.5 2026-07-25 10:55:26 +00:00
Sandro
9bb5bf1ea8 mitmproxy: unpinn all dependencies (#545405) 2026-07-25 10:54:35 +00:00
Masum Reza
eafe84dfd8 libaribcaption: 1.1.1 -> 1.1.2 (#545544) 2026-07-25 10:48:44 +00:00
Masum Reza
f9eab6eaf1 python3Packages.oelint-data: 1.5.10 -> 1.5.12 (#545546) 2026-07-25 10:48:38 +00:00
Masum Reza
ba4c9417bd algol68g: 3.12.2 -> 3.12.3 (#545547) 2026-07-25 10:48:22 +00:00
Masum Reza
d60fdc080d xkbprint: 1.0.7 -> 1.0.8 (#545548) 2026-07-25 10:48:16 +00:00
Masum Reza
99dc0aad21 stoat-desktop: 1.4.0 -> 1.4.2 (#545559) 2026-07-25 10:47:59 +00:00
Masum Reza
7bffb8137a buzztrax: switch from gtk2 to gtk3 (#545535) 2026-07-25 10:47:39 +00:00
xiaodong.jia
66bd9979a5 octoprint: 1.11.7 -> 1.11.8
https://github.com/OctoPrint/OctoPrint/releases/tag/1.11.8

Also bumps the bundled plugins in lockstep, as required by 1.11.8:

- OctoPrint-FileCheck: 2024.11.12 -> 2025.7.23
- OctoPrint-FirmwareCheck: 2021.10.11 -> 2025.7.23
- OctoPrint-PiSupport: 2023.10.10 -> 2025.7.23

Pin to python313, since OctoPrint requires Python >=3.7, <3.14 and the
default python3 now points at 3.14, which fails to build (e.g. class-doc).

Drop the tornado 6.4.2 override: the multiple-host-headers fix is in the
tornado 6.5.x now in nixpkgs, which also satisfies OctoPrint's
tornado>=6.5.1,<6.6 requirement.

Track upstream dependency changes: add babel, libpass (replaces passlib),
limits, packaging, pytz and wheel; drop immutabledict.

Disable tests/http_api, which require a live OctoPrint server and are
excluded by upstream's pytest.ini (removed during the build).
2026-07-25 18:47:31 +08:00
Saad Nadeem
8ce69b14f4 vimPlugins.fff-nvim: fix illegal instructions by targetting a baseline CPU 2026-07-25 06:47:16 -04:00
Thomas Gerbet
d782d6e1db zellij: avoid putting empty path segment into PATH when extraPackages is empty 2026-07-25 12:43:27 +02:00
R. Ryantm
d4ddaa94ab python3Packages.yoto-api: 4.3.1 -> 4.3.2 2026-07-25 10:38:20 +00:00
Thomas Gerbet
c57addab0d docker: avoid setting empty path segments into PATH
Fixes #530304
2026-07-25 12:32:28 +02:00
patka
1993a70695 modsecurity_standalone: pcre -> pcre2 2026-07-25 12:06:19 +02:00
R. Ryantm
5f7d67a4e1 stoat-desktop: 1.4.0 -> 1.4.2 2026-07-25 09:59:59 +00:00
R. Ryantm
d71f49f361 mapnik: 4.2.2 -> 4.3.0 2026-07-25 09:53:14 +00:00
Jo
12ed470109 alistral: 0.6.7 -> 0.6.8 (#545179) 2026-07-25 09:45:10 +00:00
Thiago Kenji Okada
bfc41e6078 libretro.beetle-vb: 0-unstable-2026-06-14 -> 0-unstable-2026-07-22 (#545532) 2026-07-25 09:30:08 +00:00
Thiago Kenji Okada
1c8bd6f104 libretro.melonds: 0-unstable-2026-06-25 -> 0-unstable-2026-07-19 (#545529) 2026-07-25 09:29:49 +00:00
Thiago Kenji Okada
8d462aa3e6 libretro.picodrive: 0-unstable-2026-04-02 -> 0-unstable-2026-07-23 (#545482) 2026-07-25 09:28:40 +00:00
Thiago Kenji Okada
061490506c linuxKernel.kernels.linux_zen: 7.1.3 -> 7.1.4 (#545410) 2026-07-25 09:28:13 +00:00
R. Ryantm
de2aae02a6 xclock: 1.2.0 -> 1.2.1 2026-07-25 09:27:46 +00:00
R. Ryantm
c19d3ebf38 kingfisher: 1.107.0 -> 1.109.0 2026-07-25 09:26:53 +00:00
Thomas Butter
c2ce3cdea7 algol68g: 3.12.2 -> 3.12.3 2026-07-25 09:26:53 +00:00
R. Ryantm
fcb270ccb9 xkbprint: 1.0.7 -> 1.0.8 2026-07-25 09:24:36 +00:00
Pavol Rusnak
7ac4a2b500 ollama: 0.32.1 -> 0.32.3 (#544928) 2026-07-25 09:16:46 +00:00
R. Ryantm
be2807d4fc python3Packages.oelint-data: 1.5.10 -> 1.5.12 2026-07-25 09:16:02 +00:00
Lukas Epple
b48ac115da strawberry: 1.2.18 -> 1.2.21 (#513573) 2026-07-25 09:15:01 +00:00
R. Ryantm
bb213d9d4a polonium: 1.2.0 -> 1.2.1 2026-07-25 08:36:01 +00:00
Herwig Hochleitner
7b882f05f2 buzztrax: switch from gtk2 to gtk3 2026-07-25 10:32:37 +02:00
nixpkgs-ci[bot]
56931fcce4 tremotesf: 2.9.1 -> 2.10.0 (#544020) 2026-07-25 08:32:03 +00:00
Pol Dellaiera
0f2cca0b37 python3Packages.rns: 1.4.0 -> 1.4.1 (#545531) 2026-07-25 08:28:35 +00:00
Oleksii Filonenko
90136fe8a3 jftui: enable darwin support (#517271) 2026-07-25 08:18:28 +00:00
Oleksii Filonenko
c3a6c7546f communique: 1.2.1 -> 1.2.3 (#545476) 2026-07-25 08:17:31 +00:00
Pol Dellaiera
2c73b96824 python3Packages.rns: 1.4.0 -> 1.4.1
Changelog: https://github.com/markqvist/Reticulum/blob/1.4.1/Changelog.md
2026-07-25 10:17:05 +02:00
R. Ryantm
052a8a41df libretro.beetle-vb: 0-unstable-2026-06-14 -> 0-unstable-2026-07-22 2026-07-25 08:16:55 +00:00
Oleksii Filonenko
3a843f2b5a aube: 1.29.1 -> 1.32.0 (#545440) 2026-07-25 08:16:39 +00:00
LIN, Jian
328e42b4f8 b4: expose misc/ source tree via passthru.src-misc & emacs & vim plugin (#543347) 2026-07-25 08:08:13 +00:00
R. Ryantm
e51a4d900d libaribcaption: 1.1.1 -> 1.1.2 2026-07-25 07:54:53 +00:00
Sefa Eyeoglu
eee706d3b9 pnpm: 11.16.0 -> 11.17.0
https://github.com/pnpm/pnpm/releases/tag/v11.17.0

Signed-off-by: Sefa Eyeoglu <contact@scrumplex.net>
2026-07-25 09:48:12 +02:00
R. Ryantm
36188b18a1 libretro.melonds: 0-unstable-2026-06-25 -> 0-unstable-2026-07-19 2026-07-25 07:47:02 +00:00
nixpkgs-ci[bot]
b6df579bc5 mymake: 2.4.4 -> 2.4.5 (#545487) 2026-07-25 07:45:27 +00:00
nixpkgs-ci[bot]
a0382bc1a4 gridtracker2: 2.260714.0 -> 2.260723.0 (#545420) 2026-07-25 07:45:26 +00:00
Alexis Hildebrandt
94edb80278 socket-vmnet: init at 1.2.2; minikube: add socket_vmnet support (#543157) 2026-07-25 07:39:30 +00:00
Ramses
7822200edd traefik: 3.7.6 -> 3.7.8 (#545148) 2026-07-25 07:35:11 +00:00
K900
8b49416599 Revert "nixos/modular-services: add portable process.environment" (#545519) 2026-07-25 07:24:21 +00:00
Sizhe Zhao
967b5e7105 uv: 0.11.28 -> 0.11.32 (#545236) 2026-07-25 07:19:31 +00:00
K900
ec69cf3f7b Revert "nixos/modular-services: add portable process.environment" 2026-07-25 10:19:30 +03:00
Sizhe Zhao
38affae6a5 python3Packages.lark-oapi: 1.6.9 -> 1.7.1 (#539410) 2026-07-25 07:16:24 +00:00
nixpkgs-ci[bot]
9e3461d3ed tideways-daemon: 1.18.0 -> 1.18.2 (#545484) 2026-07-25 06:57:37 +00:00
R. Ryantm
9de8e0f7e2 cubeb: 0-unstable-2026-07-16 -> 0-unstable-2026-07-25 2026-07-25 06:52:02 +00:00
Michele Guerini Rocco
65e299ca3b pdns-recursor: 5.4.3 -> 5.4.4 (#545365) 2026-07-25 06:48:33 +00:00
nixpkgs-ci[bot]
bb8534b07d Merge master into staging-next 2026-07-25 06:47:35 +00:00
Vlad M.
e0166b2fe1 claude-code: 2.1.218 -> 2.1.219 (#545319) 2026-07-25 06:35:27 +00:00
Martin Weinelt
6c534f04d3 nixos/home-assistant: allow serial for zbt1/zbt2
They use universal silabs flasher for updates over serial.
2026-07-25 08:18:29 +02:00
nixpkgs-ci[bot]
76ffe07b40 cloudflared: 2026.7.2 -> 2026.7.3 (#545500) 2026-07-25 06:00:51 +00:00
R. Ryantm
59fdf1c191 python3Packages.mhcgnomes: 3.32.1 -> 3.33.4 2026-07-25 05:42:19 +00:00
nixpkgs-ci[bot]
8eb42e621f fasmg: l7xm -> l8vn (#545473) 2026-07-25 05:11:02 +00:00
nixpkgs-ci[bot]
b0dbf02481 kchat: 3.3.3 -> 3.3.5 (#545454) 2026-07-25 05:10:42 +00:00
nixpkgs-ci[bot]
3ac61b583e s-search: 0.7.5 -> 0.8.0 (#545185) 2026-07-25 05:08:15 +00:00
R. Ryantm
649f551194 python3Packages.pyimouapi: 1.3.0 -> 1.3.2 2026-07-25 05:07:09 +00:00
R. Ryantm
b6daa60814 automatic-timezoned: 2.0.143 -> 2.0.149 2026-07-25 04:58:21 +00:00
R. Ryantm
92fdff41d6 cloudflared: 2026.7.2 -> 2026.7.3 2026-07-25 04:52:23 +00:00
dotlambda
3f38696610 python3Packages.imgw-pib: 2.4.3 -> 2.5.0 (#545488) 2026-07-25 04:49:12 +00:00
dotlambda
f35962ee24 pdf2svg: remove unused gtk2 dependency (#545056) 2026-07-25 04:48:59 +00:00
R. Ryantm
ad43cfde13 libretro.dolphin: 0-unstable-2026-07-12 -> 0-unstable-2026-07-23 2026-07-25 04:32:20 +00:00
Asa Paparo
be5fbdd94f nixos/userborn: fix cross compilation with userborn.static.enable
`services.userborn.static = true` causes userborn to build
a `static-userborn` derivation, which directly referenced
`${cfg.package}`, which broke on cross compilation. This commit passes
`cfg.package` as a `nativeBuildInput` so it uses the proper spliced
pkgs, fixes #545478.
2026-07-24 23:12:46 -05:00
R. Ryantm
57e38620ce python3Packages.imgw-pib: 2.4.3 -> 2.5.0 2026-07-25 04:10:21 +00:00
R. Ryantm
1e3e322248 mymake: 2.4.4 -> 2.4.5 2026-07-25 04:10:17 +00:00
Masum Reza
461ce04b99 gtkspell2: drop (#545093) 2026-07-25 04:00:55 +00:00
Masum Reza
b002a5b1ec jitsi: drop (#545120) 2026-07-25 03:58:08 +00:00
Masum Reza
955d274ac2 opencv4: drop gtk2 support for highgui (#545459) 2026-07-25 03:56:53 +00:00
R. Ryantm
611eeadc37 tideways-daemon: 1.18.0 -> 1.18.2 2026-07-25 03:54:36 +00:00
R. Ryantm
aee66850fb libretro.picodrive: 0-unstable-2026-04-02 -> 0-unstable-2026-07-23 2026-07-25 03:51:46 +00:00
Masum Reza
1045bcf482 apriltag: drop GTK2 support from opencv4 (#545102) 2026-07-25 03:43:28 +00:00
Dennis Gosnell
9b6f782419 freqle: init at 0.1.0 (#538294) 2026-07-25 12:38:02 +09:00
Masum Reza
109e19daf6 openjfx: remove gtk2 support from openjfx17, cleanup (#545111) 2026-07-25 03:30:54 +00:00
Ihar Hrachyshka
cdca3edfe9 fromager: 0.71.0 -> 0.91.0; python3Packages.pypi-simple: init at 1.8.0; python3Packages.mailbits: init at 0.2.3 (#513528) 2026-07-25 03:26:49 +00:00
R. Ryantm
f34ccff1bf rustnet: 1.3.0 -> 1.5.0 2026-07-25 03:25:42 +00:00
R. Ryantm
5ad3074a6c communique: 1.2.1 -> 1.2.3 2026-07-25 03:23:09 +00:00
Masum Reza
87f1cd6f4b openasar: 0-unstable-2026-07-12 -> 0-unstable-2026-07-24 (#545474) 2026-07-25 03:22:35 +00:00
Ihar Hrachyshka
350b25e579 fromager: 0.71.0 -> 0.91.0 2026-07-24 22:58:43 -04:00
R. Ryantm
b19aa3bf5f openasar: 0-unstable-2026-07-12 -> 0-unstable-2026-07-24 2026-07-25 02:56:21 +00:00
tomberek
c2d648625c tenv: 4.14.8 -> 4.15.1 (#545251) 2026-07-25 02:51:53 +00:00
R. Ryantm
02763c6450 fasmg: l7xm -> l8vn 2026-07-25 02:51:10 +00:00
Sandro
6ce157fcd7 diffyml: 1.7.0 -> 1.7.1 (#543489) 2026-07-25 02:47:09 +00:00
Ihar Hrachyshka
ccd93dcec1 python3Packages.pypi-simple: init at 1.8.0 2026-07-24 22:46:03 -04:00
Ihar Hrachyshka
05bb946302 python3Packages.mailbits: init at 0.2.3 2026-07-24 22:46:00 -04:00
Michael Daniels
c6ca7a20f1 kubernetes: 1.36.2 -> 1.36.3 (#545156) 2026-07-25 02:24:25 +00:00
Michael Daniels
500dca3897 parla: 0.7.0 -> 0.7.2 (#544471) 2026-07-25 02:24:12 +00:00
Michael Daniels
6701006109 ccusage: 20.0.6 -> 20.0.17 (#542709) 2026-07-25 02:23:25 +00:00
Michael Daniels
1055989ba1 python3Packages.google-cloud-container: 2.64.0 -> 2.65.0 (#528664) 2026-07-25 02:22:54 +00:00
Rachala Raj
a16f93f8da brave, brave-origin: extract shared builder, init at 1.92.144
Introduce brave-origin variant and extract a shared builder for Brave.

- brave: 1.92.144
- brave-origin: new, 1.92.144

Brave Origin is a stripped-down build that drops non-privacy extras
(rewards, wallet, AI, etc.) while keeping Shields and the Chromium engine.

The shared builder lives outside pkgs/by-name/ because by-name forbids
cross-directory file references. Layout follows the firefox pattern.

Co-authored-by: buckley310 <buckley310@users.noreply.github.com>
2026-07-25 07:41:08 +05:30
dotlambda
6d37c01148 cutemaze: 1.3.6 -> 1.3.7 (#545078) 2026-07-25 02:11:05 +00:00
Nick Cao
cc56d7d0b1 bazel-remote: 2.6.1 -> 2.6.2 (#544936) 2026-07-25 02:08:55 +00:00
Nick Cao
4c818080da python3Packages.monzopy: 1.5.1 -> 1.6.0 (#545311) 2026-07-25 02:08:43 +00:00
Jared Baur
ea4c60137f switch-to-configuration-ng: /etc/os-release should not be required (#543312) 2026-07-25 02:07:18 +00:00
dish
d37727ba4b tailscale: 1.98.8 -> 1.98.9 (#545359) 2026-07-25 01:48:31 +00:00
Mathew Polzin
3665b4066c bruno: 3.5.2 -> 4.0.0 (#545164) 2026-07-25 01:48:29 +00:00
tomberek
0359400aa9 soundsource: 6.0.2 -> 6.1.0 (#545291) 2026-07-25 01:46:18 +00:00
tomberek
0de0ef693b gitkraken: 12.2.1 -> 12.3.1 (#545307) 2026-07-25 01:45:53 +00:00
Michael Daniels
09d9cc74a8 shell: pin a Nixpkgs that supports x86_64-darwin (#545390) 2026-07-25 01:36:39 +00:00
夜坂雅
e589763ae0 opencv4: drop gtk2 support for highgui 2026-07-25 09:18:27 +08:00
夜坂雅
c485262d71 fsuae: drop unused gtk2 2026-07-25 09:15:22 +08:00
Martin Weinelt
701b3fd657 vaultwarden: 1.36.0 -> 1.37.0 (#545340) 2026-07-25 01:10:35 +00:00
Adam C. Stephens
cbf83bb332 jjui: 0.10.8 -> 0.10.9 (#545401) 2026-07-25 01:00:38 +00:00
R. Ryantm
3927e90c19 libdisplay-info: 0.3.0 -> 0.4.0 2026-07-25 00:50:32 +00:00
R. Ryantm
f6ac678e71 kchat: 3.3.3 -> 3.3.5 2026-07-25 00:50:12 +00:00
R. Ryantm
a08dbb1895 python3Packages.stripe: 15.3.0 -> 15.3.1 2026-07-25 00:43:28 +00:00
R. Ryantm
cfb5b9e004 xpipe: 23.7 -> 23.8 2026-07-25 00:39:41 +00:00
Adam C. Stephens
5371195501 python3Packages.ct3: rename from cheetah3 (#545346) 2026-07-25 00:34:24 +00:00
nixpkgs-ci[bot]
00d0b792cc Merge master into staging-next 2026-07-25 00:32:53 +00:00
Sandro Jäckel
0471148d15 hedgedoc: 1.11.0 -> 1.11.1
Diff: https://github.com/hedgedoc/hedgedoc/compare/1.11.0...1.11.1
2026-07-25 02:29:58 +02:00
Martin Weinelt
77c44d7620 home-assistant-custom-lovelace-modules.multiple-entity-row: 4.7.0 -> 4.7.1
https://github.com/benct/lovelace-multiple-entity-row/blob/v4.7.1/CHANGELOG.md
2026-07-25 01:55:10 +02:00
chillcicada
64cb9bd361 aube: 1.29.1 -> 1.32.0 2026-07-25 07:54:34 +08:00
R. Ryantm
36fbe6bc2b fosrl-newt: 1.14.0 -> 1.15.0 2026-07-24 23:31:21 +00:00
Martin Weinelt
e770f303ab python3Packages.homeassistant-stubs: 2026.7.3 -> 2026.7.4
https://github.com/KapJI/homeassistant-stubs/releases/tag/2026.7.4
2026-07-25 01:08:39 +02:00
Martin Weinelt
cb187f88a6 home-assistant: 2026.7.3 -> 2026.7.4
https://github.com/home-assistant/core/releases/tag/2026.7.4
2026-07-25 00:59:16 +02:00
Martin Weinelt
109e168b03 python3Packages.yoto-api: 4.3.1 -> 4.3.2
https://github.com/cdnninja/yoto_api/releases/tag/v4.3.2
2026-07-25 00:59:10 +02:00
Martin Weinelt
d1fd431204 python3Packages.pylamarzocco: 2.4.2 -> 2.4.3
https://github.com/zweckj/pylamarzocco/releases/tag/v2.4.3
2026-07-25 00:58:56 +02:00
Martin Weinelt
4f22b00129 python3Packages.pybravia: 0.4.1 -> 0.5.1
https://github.com/Drafteed/pybravia/releases/tag/v0.5.1
2026-07-25 00:58:34 +02:00
Thomas BESSOU
eb60e6ac5b claude-code: allow easily overriding manifest 2026-07-25 00:52:20 +02:00
Robert Schütz
c705f56ade vaultwarden: 1.36.0 -> 1.37.0
Diff: https://github.com/dani-garcia/vaultwarden/compare/1.36.0...1.37.0

Changelog: https://github.com/dani-garcia/vaultwarden/releases/tag/1.37.0

Co-Authored-By: Martin Weinelt <hexa@darmstadt.ccc.de>
2026-07-25 00:33:35 +02:00
R. Ryantm
e50015067e gridtracker2: 2.260714.0 -> 2.260723.0 2026-07-24 22:20:54 +00:00
R. Ryantm
2d50e90f1a python3Packages.vsure: 2.9.0 -> 2.10.0 2026-07-24 22:06:53 +00:00
Sandro Jäckel
eb7e56fe88 mitmproxy: unpinn all dependencies 2026-07-24 23:41:51 +02:00
Matt Sturgeon
f86bce2497 shell: pin a Nixpkgs that supports x86_64-darwin
When instantiating a dev-shell for x86_64-darwin, we cannot use 26.11's
pinned revision. Instead, we must use a revision that still supports
x86_64-darwin.

Print a warning when we need to use that revision, because it is likely
there will be subtle formatting & linting differences vs CI.
2026-07-24 22:37:07 +01:00
Jost Alemann
7ce5dd4b46 jjui: 0.10.8 -> 0.10.9
Changelog: https://github.com/idursun/jjui/releases/tag/v0.10.9
Diff: https://github.com/idursun/jjui/compare/v0.10.8...v0.10.9

add __structuredAttrs = true
and strictDeps = true
2026-07-24 23:32:12 +02:00
R. Ryantm
c9ba965d27 linuxKernel.kernels.linux_zen: 7.1.3 -> 7.1.4 2026-07-24 21:29:13 +00:00
Alberto Francisco Solaz García
863a5fb60d valgrind: add albfsg as maintainer 2026-07-24 22:48:13 +02:00
Alberto Francisco Solaz García
a8602ba833 maintainers: add albfsg 2026-07-24 22:47:14 +02:00
Kirill Radzikhovskyy
af4df060ce jftui: enable darwin support 2026-07-25 06:38:09 +10:00
Bart Oostveen
cf8f9a948b tailscale: 1.98.8 -> 1.98.9
Diff: https://github.com/tailscale/tailscale/compare/v1.98.8...v1.98.9
Changelog: https://tailscale.com/changelog#client

Fixes the following security vulnerabilities:
- [TS-2026-004](https://tailscale.com/security-bulletins#ts-2026-004)
- [TS-2026-005](https://tailscale.com/security-bulletins#ts-2026-005)
- [TS-2026-006](https://tailscale.com/security-bulletins#ts-2026-006)
- [TS-2026-007](https://tailscale.com/security-bulletins#ts-2026-007)
- [TS-2026-008](https://tailscale.com/security-bulletins#ts-2026-008)
- [TS-2026-009](https://tailscale.com/security-bulletins#ts-2026-009)
2026-07-24 22:00:11 +02:00
sterni
4ed9282b38 strawberry: 1.2.18 -> 1.2.21
https://raw.githubusercontent.com/jonaski/strawberry/1.2.21/Changelog

Co-authored-by: oliverpool <git@olivier.pfad.fr>
2026-07-24 21:41:28 +02:00
Robert Schütz
ffc0a72876 home-assistant-custom-components.cover_time_based: init at 4.7.2 2026-07-24 12:33:32 -07:00
Gerhard Schwanzer
4bb6931ece pdns-recursor: 5.4.3 -> 5.4.4
https://doc.powerdns.com/recursor/changelog/5.4.html#change-5.4.4

Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)
2026-07-24 21:28:45 +02:00
Jamie Magee
e0c8b3d1f3 python3Packages.ct3: rename from cheetah3 2026-07-24 11:54:03 -07:00
nixpkgs-ci[bot]
f6055e87bf Merge master into staging-next 2026-07-24 18:30:55 +00:00
Sam Estep
e29c342b51 claude-code: 2.1.218 -> 2.1.219 2026-07-24 14:23:07 -04:00
Username404-59
928ccf6805 hyprlandPlugins.hypr-darkwindow: 0.55.4 -> 0.56.0 2026-07-24 19:42:35 +02:00
R. Ryantm
1ac1dd3921 python3Packages.monzopy: 1.5.1 -> 1.6.0 2026-07-24 17:36:23 +00:00
R. Ryantm
1a3ea561d1 gitkraken: 12.2.1 -> 12.3.1 2026-07-24 17:19:47 +00:00
9R
a294471a87 home-assistant-custom-components.hochwasserportal: 1.0.8 -> 1.0.9
release-note: https://github.com/stephan192/hochwasserportal/releases/tag/v1.0.9
2026-07-24 18:50:56 +02:00
9R
6b38ccd029 lhpapi: 1.0.10 -> 1.0.11
release note: https://github.com/stephan192/lhpapi/releases/tag/v1.0.11
2026-07-24 18:41:50 +02:00
Mynacol
e2ee5d659c deno: 2.9.3 -> 2.9.4
This also updates rusty-v8 from 149.4.0 to 150.2.0, and that required a
new patch to make it build.
And another deno test fails due to our build setup that we have to skip.
2026-07-24 16:27:40 +00:00
dfjay
ca2336b2e1 soundsource: add dfjay as maintainer
Assisted-by: Claude Code (Claude Opus 4.8)
2026-07-24 21:16:21 +05:00
dfjay
c9bc82d15e soundsource: add update script
Snapshots the rolling upstream download into the Wayback Machine so the
version/url/hash can be bumped reproducibly.

Assisted-by: Claude Code (Claude Opus 4.8)
2026-07-24 21:15:43 +05:00
dfjay
78db27d15d soundsource: use fetchzip
Fetch and hash the unpacked bundle rather than the zip bytes, which removes
the unzip build input (NixOS/nixpkgs#498552) and survives archive.org
re-serving the same file with different container metadata - a change on their
end previously broke the fixed-output hash (NixOS/nixpkgs#463091).

Assisted-by: Claude Code (Claude Opus 4.8)
2026-07-24 21:13:25 +05:00
dfjay
d1e0d72118 soundsource: 6.0.2 -> 6.1.0
https://rogueamoeba.com/support/releasenotes/?product=SoundSource

Assisted-by: Claude Code (Claude Opus 4.8)
2026-07-24 21:11:53 +05:00
R. Ryantm
6da6feecca google-lighthouse: 13.4.0 -> 13.4.1 2026-07-24 15:30:24 +00:00
R. Ryantm
23f2849e4d tenv: 4.14.8 -> 4.15.1 2026-07-24 14:16:17 +00:00
nicoo
00b024aca8 pulumi: 3.248.0 → 3.253.0
Co-authored-by: Robin Kneepkens <robin@skunk.team>
2026-07-24 13:50:32 +00:00
Holiu618
a25913208f bruno: 3.5.2 -> 4.0.0 2026-07-24 20:51:57 +08:00
R. Ryantm
0442655034 python3Packages.google-cloud-container: 2.64.0 -> 2.65.0 2026-07-24 14:45:35 +02:00
R. Ryantm
539ad7384e graphicsmagick: 1.3.47 -> 1.3.48 2026-07-24 12:31:41 +00:00
nixpkgs-ci[bot]
1edc097bd2 Merge master into staging-next 2026-07-24 12:31:11 +00:00
R. Ryantm
016e2c79d7 uv: 0.11.28 -> 0.11.32 2026-07-24 10:16:15 +00:00
R. Ryantm
be45d1efa9 s-search: 0.7.5 -> 0.8.0 2026-07-24 09:56:18 +00:00
R. Ryantm
196ae695a8 alistral: 0.6.7 -> 0.6.8 2026-07-24 09:31:40 +00:00
R. Ryantm
6b1008c206 kubernetes: 1.36.2 -> 1.36.3 2026-07-24 08:37:18 +00:00
Tony Wasserka
227c3aace0 python3Packages.flashinfer: add missing requests dependency
This was always missing but had previously been masked by torch covering the
library.
2026-07-24 10:15:27 +02:00
Ryan Omasta
674fde2484 dump1090-fa: add ryand56 as maintainer 2026-07-24 02:01:48 -06:00
Ryan Omasta
dc088c4465 dump1090-fa: 10.2 -> 11.1
Diff: https://github.com/flightaware/dump1090/compare/v10.2...v11.1
2026-07-24 02:01:48 -06:00
nixpkgs-ci[bot]
a0f7233e07 Merge master into staging-next 2026-07-24 06:51:50 +00:00
Gerhard Schwanzer
d46c595b68 traefik: 3.7.6 -> 3.7.8
https://github.com/traefik/traefik/releases/tag/v3.7.8

Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)
2026-07-24 08:37:06 +02:00
夜坂雅
0a646acd33 jitsi: drop 2026-07-24 12:21:45 +08:00
夜坂雅
d306537ce5 openjfx: remove gtk2 support from openjfx17, cleanup 2026-07-24 11:37:30 +08:00
夜坂雅
3cc7f6670b apriltag: drop GTK2 support from opencv4 2026-07-24 10:47:31 +08:00
sophiebsw
a35c0b0939 simplenote: remove ignored __structuredAttrs and strictDeps args 2026-07-23 19:40:51 -07:00
sophiebsw
ab79b9b43a buildFHSEnv: enable strictDeps 2026-07-23 19:38:52 -07:00
whispers
f44b368058 gtkspell2: drop
gtkspell2 is the port of the GtkSpell program to GTK 2, and is
considered legacy by upstream. Most in-tree consumers have migrated to
gtkspell3, so there's little reason to keep it around. The lone
exception is pidgin, which had optional support and is also dependent on
GTK 2, so we simply disable its gtkspell support.
2026-07-23 22:05:36 -04:00
whispers
f4828f51ce pidgin: disable gtkspell
gtkspell is optional, and is being removed from Nixpkgs due to its
dependence on GTK 2.
2026-07-23 22:03:20 -04:00
R. Ryantm
f43765f07a python3Packages.daphne: 4.2.2 -> 4.2.3 2026-07-24 00:57:36 +00:00
R. Ryantm
cd3449310a cutemaze: 1.3.6 -> 1.3.7 2026-07-24 00:32:49 +00:00
nixpkgs-ci[bot]
391874228d Merge master into staging-next 2026-07-24 00:29:28 +00:00
Robert Schütz
a2d7b92fac pdf2svg: remove unused gtk2 dependency
It was removed upstream: https://github.com/dawbarton/pdf2svg/issues/7
2026-07-23 15:17:34 -07:00
R. Ryantm
e8127dd752 opentofu-mcp-server: 1.0.0-unstable-2026-06-09 -> 1.0.0-unstable-2026-07-15 2026-07-23 19:15:57 +00:00
nixpkgs-ci[bot]
9ff109fb87 Merge master into staging-next 2026-07-23 18:27:29 +00:00
R. Ryantm
d798258c7a bazel-remote: 2.6.1 -> 2.6.2 2026-07-23 17:15:07 +00:00
Pavol Rusnak
ffc8c1c9eb ollama: 0.32.1 -> 0.32.3 2026-07-23 18:44:49 +02:00
Pavol Rusnak
97087f83d5 ollama: add update.sh which also updates llamaCppSrc 2026-07-23 18:44:48 +02:00
staticdev
17f903b426 dbeaver-bin: 26.1.1 -> 26.1.3
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Assisted-by: Sisyphus (OpenAI GPT-5.6 Sol)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-23 17:48:45 +02:00
Farid Zakaria
e7c911fdff emacsPackages.b4-review-mode: init at 0.15.2
b4's `misc/emacs/b4-review-mode.el` provides a major mode that
highlights the `b4 review` reply editor (autoloading for *.b4-review.eml
files). Package it via melpaBuild, sourced from the b4 package's
`passthru.src-misc` so the version stays in lockstep with b4 itself,
mirroring the b4-review-vim plugin.

Assisted-by: Claude Code (Claude Opus 4.8)
2026-07-23 08:06:31 -07:00
Farid Zakaria
9dca5046aa vimPlugins.b4-review-vim: init at 0.15.2
b4's `misc/vim` directory provides ftdetect/ftplugin/syntax files that
highlight the `b4 review` reply editor (activating for *.b4-review.eml
buffers). Package them as a Vim/Neovim plugin, sourced from the b4
package's `passthru.src-misc` so the version stays in lockstep with b4
itself, following the notmuch-vim/hurl precedent.

Assisted-by: Claude Code (Claude Opus 4.8)
2026-07-23 08:06:31 -07:00
nixpkgs-ci[bot]
66c61c3c1e Merge master into staging-next 2026-07-23 12:33:47 +00:00
Phillip Seeber
d557d9c091 octopus: add cuda and hip support 2026-07-23 11:56:05 +02:00
Phillip Seeber
db8e7c02bb octopus: 16.3 -> 16.4 2026-07-23 11:55:37 +02:00
nixpkgs-ci[bot]
10d1260d3a Merge master into staging-next 2026-07-23 06:51:29 +00:00
R. Ryantm
a82bdac5ff lunar-client: 3.7.11 -> 3.7.12 2026-07-23 01:01:16 +00:00
nixpkgs-ci[bot]
7bd1ed1622 Merge master into staging-next 2026-07-23 00:32:16 +00:00
Farid Zakaria
536da04b81 b4: expose misc/ source tree via passthru.src-misc
b4 ships editor helpers (Vim/Emacs syntax highlighting for the `b4
review` reply editor) and an `agent-reviewer.md` prompt under `misc/` in
its source tree, but these files are absent from the PyPI sdist the
package is built from. Fetch the matching git tag and expose it as
`passthru.src-misc` so downstream consumers (starting with the
`b4-review-vim` plugin) can reuse it instead of each fetching the
repository themselves. Pinning `rev` to `v${version}` keeps it in sync
with the packaged version.

Assisted-by: Claude Code (Claude Opus 4.8)
2026-07-22 17:24:31 -07:00
Tony Wasserka
38bf1d29cd python3Packages.outlines: add missing pillow dependency
This was always missing but had previously been masked by torch covering the
library unconditionally until #536976.

Notably this broke the CUDA build of vllm.
2026-07-22 23:30:09 +02:00
nixpkgs-ci[bot]
ffe6ce2a14 Merge master into staging-next 2026-07-22 18:26:08 +00:00
Chris Portela
f3d131212a openclaw: 2026.6.11 -> 2026.6.33 2026-07-22 18:09:53 +00:00
Grimmauld
d5a6c65fef SDL_mixer: 1.2.12 -> 1.2.12-unstable-2026-05-11 2026-07-22 17:44:37 +02:00
Jonas Heinrich
ce01b16cd6 gotosocial: fix cross-compilation on RISCV 2026-07-22 16:10:12 +02:00
nixpkgs-ci[bot]
ea1d43ed8a Merge master into staging-next 2026-07-22 12:33:42 +00:00
R. Ryantm
5e9376fc91 kicad-testing-small: 10.0-2026-07-09 -> 10.0-2026-07-21 2026-07-22 12:07:35 +00:00
R. Ryantm
90a6722c59 parla: 0.7.0 -> 0.7.2 2026-07-22 08:07:31 +00:00
Fabian Affolter
916c050a13 python313Packages.pyeconet: 0.2.2 -> 0.2.5
Diff: https://github.com/w1ll1am23/pyeconet/compare/v0.2.2...v0.2.5

Changelog: https://github.com/w1ll1am23/pyeconet/releases/tag/v0.2.5
2026-07-22 09:07:49 +02:00
nixpkgs-ci[bot]
1f22863ccd Merge master into staging-next 2026-07-22 06:53:00 +00:00
nixpkgs-ci[bot]
f412c70cf7 Merge master into staging-next 2026-07-22 00:30:23 +00:00
Jade Lynn Masker
82878a8688 legendsviewer-next: init at 1.2.5
This adds legendsviewer-next, a Dwarf Fortress exported legends viewer
2026-07-21 17:18:22 -04:00
Jade Lynn Masker
3e8b8d5454 maintainers: add donottellmetonottellyou 2026-07-21 17:16:54 -04:00
Paul Meyer
bc557b7168 nixos/qemu-firmware: init
Link QEMU firmware descriptors to /etc/qemu/firmware, where
systemd-vmspawn and other tools discover firmware for running VMs.

Signed-off-by: Paul Meyer <katexochen0@gmail.com>
2026-07-21 10:36:49 +02:00
R. Ryantm
a1836fd3b1 tremotesf: 2.9.1 -> 2.10.0 2026-07-21 00:28:02 +00:00
OPNA2608
36fd2c52cf libayatana-common: 0.9.11 -> 0.9.13 2026-07-19 16:27:01 +02:00
Sergei Zhekpisov
422436fc18 diffyml: 1.7.0 -> 1.7.1
Assisted-by: Claude Code (Claude Opus 4.8)
2026-07-19 13:50:54 +01:00
Sigmanificient
c504fe64e2 python3Packages.pysimplesoap: use finalAttrs 2026-07-19 00:12:00 +02:00
Sigmanificient
5ae7702a20 python3Packages.pysimplesoap: migrate to pyproject 2026-07-19 00:11:22 +02:00
Niklas Hambüchen
e022b86ee8 switch-to-configuration-ng: /etc/os-release should not be required
The comment

    // This is a NixOS installation if it has /etc/NIXOS or a proper /etc/os-release.

said OR but the code implemented AND because it errored out
if `/etc/os-release` did not exist.

This was a regression from the Perl-to-Rust rewrite.

See https://github.com/NixOS/nixpkgs/pull/308801#pullrequestreview-4718561904

Assisted-by: Claude Opus 4.8 in Zoo Code, human comment cleanup
2026-07-18 20:20:42 +00:00
Alexis Hildebrandt
0798b868b6 minikube: Add socket_vmnet support when building withQemu on darwin 2026-07-18 19:07:43 +02:00
Alexis Hildebrandt
5cb2dbb287 socket_vmnet: init at 1.2.2 2026-07-18 19:07:11 +02:00
R. Ryantm
4d617ddeb7 pimsync: 0.5.10 -> 0.5.11 2026-07-18 07:13:04 +00:00
Adam Thompson-Sharpe
0cae472909 umple-lsp: init at 1.0.2 2026-07-16 21:55:39 -04:00
R. Ryantm
736003fbad python3Packages.lark-oapi: 1.6.9 -> 1.7.1 2026-07-17 01:26:35 +00:00
OPNA2608
706bc06df6 miriway: 26.01 -> 26.06.3 2026-07-17 01:24:03 +02:00
Clara Engler
a4805bc6c9 nixos/nsd: After/Want network-online.target
This is required in the case one uses nsd as a primary name server.
Otherwise, the nsd instance cannot notify the secondary name servers
properly, as the network may still be unreachable by that point.
2026-07-17 00:05:18 +02:00
Miroslav Vadkerti
cb97856984 ccusage: 20.0.6 -> 20.0.17
Also bumps the embedded LiteLLM pricing pin to the revision ccusage locks
in its `flake.lock` at `v20.0.17` (`f27df8d5` -> `49ca04d8`), which the
`updateScript` from the previous commit now keeps in sync automatically.

Assisted-by: Claude Code
Signed-off-by: Miroslav Vadkerti <mvadkert@redhat.com>
2026-07-16 13:08:04 +02:00
Miroslav Vadkerti
6cf631626c ccusage: sync litellm pricing pin in updateScript
The `litellmPricing` fetch pins a `BerriAI/litellm` revision that must
track the `litellm` input in ccusage's own `flake.lock` at the matching
tag, so the embedded pricing table stays byte-identical to what upstream
ships. The previous `nix-update-script { }` only refreshed `version` and
the `src`/`cargo` hashes, leaving the pricing pin untouched — so every
automated (r-ryantm) bump silently shipped stale pricing data.

Replace it with a wrapper that runs `nix-update`, then reads the litellm
revision locked at the freshly-bumped tag and rewrites the new
`litellmPricingRev`/`litellmPricingHash` bindings to match.

Assisted-by: Claude Code
Signed-off-by: Miroslav Vadkerti <mvadkert@redhat.com>
2026-07-16 12:59:13 +02:00
jopejoe1
89be98d540 lib.licenses.stk: use upstream spdx info 2026-07-16 09:37:39 +02:00
Sigmanificient
eb88f6df7c as-tree: fix version scheme 2026-07-16 01:19:04 +02:00
kilyanni
28f54c2d43 intel-llvm: fix build 2026-07-15 19:38:10 +02:00
Jamie Magee
7c447c32bd raspi-utils: init at 0-unstable-2026-07-08
Co-authored-by: GiggleSquid <jack.connors@protonmail.com>
Co-authored-by: Stefan Frijters <sfrijters@gmail.com>
Assisted-by: GitHub Copilot CLI (GPT-5.6 Sol)
2026-07-15 08:48:43 -07:00
phanirithvij
57b0e5e803 nixosTests.ghostunnel-modular: fix test
Signed-off-by: phanirithvij <phanirithvij2000@gmail.com>
2026-07-15 21:16:49 +05:30
phanirithvij
698a70e9fe ghostunnel: use finalAttrs
Signed-off-by: phanirithvij <phanirithvij2000@gmail.com>
2026-07-15 21:16:48 +05:30
R. Ryantm
ed2bc926d1 nushellPlugins.skim: 0.29.0 -> 0.29.1 2026-07-15 07:59:07 +00:00
emilylange
bb50b6eb9d chromium: remove broken pulseSupport = false; override
As far as I can tell, this override broke almost 10 years ago in
8391241e0c.

When trying to build the fixup commit that followed immediately after
that (5f53fddf1e) the build fails with the
following error:

~~~
[11704/21910] CXX obj/media/media/vp9_compressed_header_parser.o
[11705/>
FAILED: obj/media/audio/audio/audio_manager_alsa.o
g++ -MMD -MF obj/media/audio/audio/audio_manager_alsa.o.d [...]
In file included from ../../media/audio/alsa/audio_manager_alsa.cc:28:0:
../../media/audio/pulse/audio_manager_pulse.h:8:30: fatal error: pulse/pulseaudio.h: No such file or directory
compilation terminated.
ninja: build stopped: subcommand failed.
~~~

And the same happens when trying to build chromium with
`pulseSupport = false;` and picking random releases between 17.03 and
now.

I don't think there is a good reason to keep this, especially since no
one bothered to test this in almost a decade. The chromium derivation is
a mess, so let's run with this rather small win and remove this broken,
mostly useless, obscure and untested permutation.
2026-07-11 23:35:23 +02:00
jopejoe1
253475c406 python3Packages.flask-reverse-proxy-file: use lib.licenses.ogluk30 2026-07-11 13:46:17 +02:00
jopejoe1
4b55fc928b lib.licenses: add ogluk30 2026-07-11 13:45:38 +02:00
Clara Engler
64f1104dea nixos/unbound: resolveLocalQueries with resolved
This adds support for services.unbound.resolveLocalQueries with
systemd-resolved by improving the general behavior similar to the
dnsmasq module.

With this change, it not only adjusts resolvconf (which is not used when
systemd-resolved is used) but also prepends the loopback addresses to
networking.nameservers.
2026-07-09 15:24:05 +02:00
Lyra Aranha
2822a3acce nixos/mango: rename from mangowc 2026-07-08 18:43:04 +02:00
Paul Meyer
3172f85a7e OVMF: ship qemu firmware descriptors
These can be used by libvirt or systemd-vmspawn to discover available
firmware.

Signed-off-by: Paul Meyer <katexochen0@gmail.com>
2026-07-07 13:25:59 +02:00
Jonas Carpay
f40e1287c3 freqle: init at 0.1.0 2026-07-06 12:28:52 +09:00
Jonas Carpay
b276999b1f maintainers: add jonascarpay 2026-07-06 12:28:52 +09:00
Francesco Gazzetta
1729877a4c tcl-9_0: 9.0.3 -> 9.0.4 2026-07-02 18:10:22 +02:00
Niklas Ravnsborg
fabe4a9ad0 pulumiPackages.pulumi-bun: init at 3.248.0 2026-07-02 07:34:45 +02:00
Niklas Ravnsborg
46714b0550 maintainers: add niklasravnsborg 2026-07-01 21:46:45 +02:00
Robin Kneepkens
9ca5a1b103 pulumiPackages.pulumi-python: 3.192.0 -> 3.248.0
- Update postInstall: pulumi-analyzer-policy not built anymore
- Skip new failing tests
- Skip pulumi python module langhost tests
2026-07-01 21:46:45 +02:00
Robin Kneepkens
1bfac9c378 pulumiPackages.node-js: 3.192.0 -> 3.248.0
- Skip newly failing tests
- Remove skip of removed test
- Update post-install: analyzer policy isn't built anymore
2026-07-01 21:46:45 +02:00
Robin Kneepkens
c210d6bb89 pulumiPackages.pulumi-go: 3.192.0 -> 3.248.0
- Skip new failing test cases
2026-07-01 21:46:45 +02:00
Robin Kneepkens
174e0a3aa3 pulumi: 3.192.0 -> 3.248.0
- Remove unnecessary skipped tests
- Add new tests to skip
2026-07-01 21:46:45 +02:00
whispers
775b868546 sbsigntool: make unused-but-set-variable non-fatal for gcc 16
since sbsigntool builds with -Werror by default, and gcc 16's unused
variable analysis is better than previous versions, this causes a build
failure.
2026-07-01 08:45:52 -04:00
Robin Kneepkens
e6c219c3d7 maintainers: add untio11 2026-06-29 15:57:12 +02:00
Gavin John
c72f684b1d quarkdown: init at 1.6.1 2026-06-28 11:47:38 -04:00
R. Ryantm
46f5fe2a35 pappl: 1.4.10 -> 1.4.11 2026-06-05 21:36:03 +00:00
R. Ryantm
d42e82be52 python3Packages.ezdxf: 1.4.3 -> 1.4.4 2026-05-17 15:24:49 +00:00
Anton Tetov
6f39241f33 houdini: update link to download requireFile
They make the houdini_launcher the standard way. I might need to look into packaging that too, since that's the quick way to install lab extensions.
2026-05-13 14:21:27 +02:00
Leonard Sheng Sheng Lee
83419e790f azure-mcp: init at 3.0.0-beta.10
See https://github.com/microsoft/mcp/blob/Azure.Mcp.Server-3.0.0-beta.10/servers/Azure.Mcp.Server/README.md.

Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
2026-05-13 13:04:07 +02:00
280 changed files with 16150 additions and 8921 deletions

View File

@@ -211,7 +211,7 @@ nixos/modules/installer/tools/nix-fallback-paths.nix @Artturin @Ericson2314 @lo
/pkgs/development/perl-modules @stigtsp @marcusramberg
# R
/pkgs/applications/science/math/R @jbedo
/pkgs/by-name/r/R @jbedo
/pkgs/development/r-modules @jbedo
# Rust

View File

@@ -12,6 +12,19 @@
"revision": "7525d999cd850b9a488817abc89c75dc733acf17",
"url": "https://github.com/NixOS/nixpkgs/archive/7525d999cd850b9a488817abc89c75dc733acf17.tar.gz",
"hash": "sha256-4IHyyLgLBdKefkljdKod4IMn023pQiDXAWJA187cmdY="
},
"nixpkgs-26.05-darwin": {
"type": "Git",
"repository": {
"type": "GitHub",
"owner": "NixOS",
"repo": "nixpkgs"
},
"branch": "nixpkgs-26.05-darwin",
"submodules": false,
"revision": "51fe96f9107566e6b8eeb7fc4ba696c01e548b04",
"url": "https://github.com/NixOS/nixpkgs/archive/51fe96f9107566e6b8eeb7fc4ba696c01e548b04.tar.gz",
"hash": "sha256-yj0LPLnsmYoLmA3FGANjeTEwej0/DHjZBXWnDQDUuIs="
}
},
"version": 8

View File

@@ -28,7 +28,7 @@ However, [those were unified early 2020](https://github.com/NixOS/nixpkgs/pull/8
```nix
{ appimageTools, fetchurl }:
let
appimageTools.wrapType2 {
pname = "nuclear";
version = "0.6.30";
@@ -36,8 +36,7 @@ let
url = "https://github.com/nukeop/nuclear/releases/download/v${version}/nuclear-v${version}.AppImage";
hash = "sha256-he1uGC1M/nFcKpMM9JKY4oeexJcnzV0ZRxhTjtJz6xw=";
};
in
appimageTools.wrapType2 { inherit pname version src; }
}
```
:::
@@ -56,7 +55,7 @@ There are a few ways to learn which dependencies an application needs:
```nix
{ appimageTools, fetchurl }:
let
appimageTools.wrapType2 {
pname = "irccloud";
version = "0.16.0";
@@ -64,9 +63,7 @@ let
url = "https://github.com/irccloud/irccloud-desktop/releases/download/v${version}/IRCCloud-${version}-linux-x86_64.AppImage";
hash = "sha256-/hMPvYdnVB1XjKgU2v47HnVvW4+uC3rhRjbucqin4iI=";
};
in
appimageTools.wrapType2 {
inherit pname version src;
extraPkgs = pkgs: [ pkgs.at-spi2-core ];
}
```
@@ -88,12 +85,12 @@ However, [those were unified early 2020](https://github.com/NixOS/nixpkgs/pull/8
# Extracting an AppImage to install extra files
This example was adapted from a real package in Nixpkgs to show how `extract` is usually used in combination with `wrapType2`.
Note how `appimageContents` is used in `extraInstallCommands` to install additional files that were extracted from the AppImage.
`wrapType2` automatically extracts the AppImage for you and makes it available via the `contents` attribute.
Note how `finalAttrs.contents` is used in `extraInstallCommands` to install additional files that were extracted from the AppImage.
```nix
{ appimageTools, fetchurl }:
let
appimageTools.wrapType2 (finalAttrs: {
pname = "irccloud";
version = "0.16.0";
@@ -102,27 +99,24 @@ let
hash = "sha256-/hMPvYdnVB1XjKgU2v47HnVvW4+uC3rhRjbucqin4iI=";
};
appimageContents = appimageTools.extract { inherit pname version src; };
in
appimageTools.wrapType2 {
inherit pname version src;
extraPkgs = pkgs: [ pkgs.at-spi2-core ];
extraInstallCommands = ''
mv $out/bin/irccloud-${version} $out/bin/irccloud
install -m 444 -D ${appimageContents}/irccloud.desktop $out/share/applications/irccloud.desktop
install -m 444 -D ${appimageContents}/usr/share/icons/hicolor/512x512/apps/irccloud.png \
install -m 444 -D ${finalAttrs.contents}/irccloud.desktop $out/share/applications/irccloud.desktop
install -m 444 -D ${finalAttrs.contents}/usr/share/icons/hicolor/512x512/apps/irccloud.png \
$out/share/icons/hicolor/512x512/apps/irccloud.png
substituteInPlace $out/share/applications/irccloud.desktop \
--replace-fail 'Exec=AppRun' 'Exec=irccloud'
'';
}
})
```
:::
The argument passed to `extract` can also contain a `postExtract` attribute, which allows you to execute additional commands after the files are extracted from the AppImage.
`appimageTools` also exposes the `extract` function should you need to do it manually, requiring `pname`, `version`, and `src` arguments (`src` being the AppImage file to extract).
The arguments passed to `extract` can also contain a `postExtract` attribute, which allows you to execute additional commands after the files are extracted from the AppImage.
`postExtract` must be a string with commands to run.
:::{.warning}
@@ -138,7 +132,7 @@ This is a rewrite of [](#ex-extracting-appimage) to use `postExtract` and `wrapA
```nix
{ appimageTools, fetchurl }:
let
appimageTools.wrapAppImage (finalAttrs: {
pname = "irccloud";
version = "0.16.0";
@@ -147,30 +141,22 @@ let
hash = "sha256-/hMPvYdnVB1XjKgU2v47HnVvW4+uC3rhRjbucqin4iI=";
};
appimageContents = appimageTools.extract {
inherit pname version src;
contents = appimageTools.extract {
inherit (finalAttrs) pname version src;
postExtract = ''
substituteInPlace $out/irccloud.desktop --replace-fail 'Exec=AppRun' 'Exec=irccloud'
'';
};
in
appimageTools.wrapAppImage {
inherit pname version;
src = appimageContents;
extraPkgs = pkgs: [ pkgs.at-spi2-core ];
extraInstallCommands = ''
mv $out/bin/irccloud-${version} $out/bin/irccloud
install -m 444 -D ${appimageContents}/irccloud.desktop $out/share/applications/irccloud.desktop
install -m 444 -D ${appimageContents}/usr/share/icons/hicolor/512x512/apps/irccloud.png \
install -m 444 -D ${finalAttrs.contents}/irccloud.desktop $out/share/applications/irccloud.desktop
install -m 444 -D ${finalAttrs.contents}/usr/share/icons/hicolor/512x512/apps/irccloud.png \
$out/share/icons/hicolor/512x512/apps/irccloud.png
'';
# specify src archive for nix-update
passthru.src = src;
}
})
```
:::

View File

@@ -741,7 +741,7 @@ Notable attributes:
Compliance suite for [modular service](https://nixos.org/manual/nixos/unstable/#modular-services) integrations.
Tests that a service manager integration correctly handles the portable modular services contract: `process.argv`, `process.environment` (including `null` values that unset a variable), sub-services, assertions, and warnings.
Tests that a service manager integration correctly handles the portable modular services contract: `process.argv`, sub-services, assertions, and warnings.
### Return value {#tester-modularServiceCompliance-return}

View File

@@ -129,6 +129,8 @@
- `super-productivity` has been updated. The binary has been renamed from `super-productivity` to `superproductivity`. A symlink from the old name is provided for backward compatibility.
- `buildFHSEnv`, `appimageTools.wrapAppImage`, and `appimageTools.wrapType2` now support the `finalAttrs` pattern. When using `wrapAppImage`, it is now recommended to pass the extracted AppImage to the `contents` attribute (instead of `src`), to avoid shadowing `src`. Passing the extracted contents to `src` is now deprecated and will be removed in a future release.
- Package-URL (PURL, https://github.com/package-url/purl-spec) metadata identifier has been added for `fetchgit`, `fetchpypi` and `fetchFromGithub` fetchers.
`mkDerivation` has been adjusted to reuse this information.
Package-URLs allow reliably identifying and locating software packages.

View File

@@ -199,7 +199,8 @@
&& system != "riscv64-linux"
# Exclude x86_64-freebsd because "Package go-1.22.12-freebsd-amd64-bootstrap in /nix/store/0yw40qnrar3lvc5hax5n49abl57apjbn-source/pkgs/development/compilers/go/binary.nix:50 is not available on the requested hostPlatform"
&& system != "x86_64-freebsd"
) (forAllSystems (system: (import ./ci { inherit system; }).fmt.pkg));
# TODO: revert to importing fmt.pkg directly from ./ci when support for 26.05 ends
) (forAllSystems (system: (import ./shell.nix { inherit system; }).formatter));
/**
A nested structure of [packages](https://nix.dev/manual/nix/latest/glossary#package-attribute-set) and other values.

View File

@@ -1259,6 +1259,11 @@ lib.mapAttrs mkLicense (
fullName = "SIL Open Font License 1.1";
};
ogluk30 = {
spdxId = "OGL-UK-3.0";
fullName = "Open Government Licence v3.0";
};
oml = {
spdxId = "OML";
fullName = "Open Market License";
@@ -1421,9 +1426,8 @@ lib.mapAttrs mkLicense (
};
stk = {
shortName = "stk";
fullName = "Synthesis Tool Kit 4.3";
url = "https://github.com/thestk/stk/blob/master/LICENSE";
spdxId = "MIT-STK";
fullName = "MIT-STK License";
};
sudo = {

View File

@@ -70,26 +70,6 @@ in
Command used for reloading in the underlying service manager to reload.
'';
};
environment = lib.mkOption {
type = types.lazyAttrsOf (
types.nullOr (types.coercedTo (types.either types.path types.package) (x: "${x}") types.str)
);
default = { };
example = lib.literalExpression ''{ FOO = "bar"; PATH = null; }'';
description = ''
Environment variables passed verbatim to the service process by the
service manager. Entries set to `null` actively unset the variable
before the process starts -- backends without native unset support use
a wrapper (e.g. `execline`'s `unexport`) so the variable is absent
even when the service manager or a backend-specific override would
otherwise supply it.
Values appear in the rendered unit and may be world-readable. For
secrets, use a backend-specific mechanism such as
`systemd.service.serviceConfig.EnvironmentFile`.
'';
};
};
notificationProtocol = mkOption {

View File

@@ -48,10 +48,6 @@ let
(dummyPkg "cowsay.sh")
"world"
];
environment = {
FOO = "bar";
DROPPED = null;
};
};
};
service3 = {
@@ -114,7 +110,6 @@ let
"/usr/bin/echo"
"hello"
];
environment = { };
};
services = { };
assertions = [
@@ -133,10 +128,6 @@ let
"${dummyPkg "cowsay.sh"}"
"world"
];
environment = {
FOO = "bar";
DROPPED = null;
};
};
services = { };
assertions = [ ];
@@ -145,7 +136,6 @@ let
service3 = {
process = {
argv = [ "/bin/false" ];
environment = { };
};
services.exclacow = {
process = {
@@ -153,7 +143,6 @@ let
"${dummyPkg "cowsay-ng"}/bin/cowsay"
"!"
];
environment = { };
};
services = { };
assertions = [

View File

@@ -1173,6 +1173,12 @@
}
];
};
albfsg = {
name = "Alberto Francisco Solaz García";
github = "albfsg";
githubId = 227897008;
email = "albfsg@proton.me";
};
alch-emi = {
email = "emi@alchemi.dev";
github = "Alch-Emi";
@@ -7333,6 +7339,13 @@
githubId = 39825;
name = "Dominik Honnef";
};
donottellmetonottellyou = {
name = "Jade Masker";
email = "donottellmetonottellyou@gmail.com";
github = "donottellmetonottellyou";
githubId = 115233539;
keys = [ { fingerprint = "5C8B 7128 4AB3 000D 4AC6 6234 9B81 35A2 4A75 CB86"; } ];
};
donovanglover = {
github = "donovanglover";
githubId = 2374245;
@@ -12953,11 +12966,6 @@
name = "Jez Cope";
keys = [ { fingerprint = "D9DA 3E47 E8BD 377D A317 B3D0 9E42 CE07 1C45 59D1"; } ];
};
jf-uu = {
github = "jf-uu";
githubId = 181011550;
name = "jf-uu";
};
jfchevrette = {
email = "jfchevrette@gmail.com";
github = "jfchevrette";
@@ -13574,6 +13582,12 @@
name = "Jonas Wunderlich";
matrix = "@matrix:03j.de";
};
jonascarpay = {
name = "Jonas Carpay";
email = "jonascarpay@gmail.com";
github = "jonascarpay";
githubId = 3593851;
};
jonasfranke = {
name = "Jonas Franke";
email = "info@jonasfranke.xyz";
@@ -18861,6 +18875,11 @@
githubId = 45770;
name = "Mitsuhiro Nakamura";
};
MNThomson = {
github = "MNThomson";
githubId = 73045936;
name = "Max Thomson";
};
moaxcp = {
email = "moaxcp@gmail.com";
github = "moaxcp";
@@ -20275,6 +20294,12 @@
github = "niklaskorz";
githubId = 590517;
};
niklasravnsborg = {
name = "Niklas Ravnsborg";
github = "niklasravnsborg";
githubId = 6717303;
keys = [ { fingerprint = "0C90 DD8A 0EE9 93DF 8D58 7AF9 8360 E6C5 8AE8 F3ED"; } ];
};
niklasthorild = {
name = "Niklas Thorild";
email = "niklas@thorild.se";
@@ -23308,6 +23333,13 @@
github = "DaRacci";
githubId = 90304606;
};
rachalaraj = {
name = "Rachala Raj Kumar";
email = "rachaalaraj@gmail.com";
matrix = "@rachalaraj:matrix.org";
github = "rachalaraj";
githubId = 124191100;
};
RadxaYuntian = {
# This is the work account for @MakiseKurisu
name = "ZHANG Yuntian";
@@ -29365,6 +29397,11 @@
github = "UnsolvedCypher";
githubId = 3170853;
};
untio11 = {
name = "Robin Kneepkens";
github = "untio11";
githubId = 14060658;
};
uralbash = {
email = "root@uralbash.ru";
github = "uralbash";

View File

@@ -152,16 +152,7 @@ let
};
systemdServiceOptions = buildPackages.nixosOptionsDoc {
inherit
(evalModules {
modules = [
(modules.importApply ../../modules/system/service/systemd/service.nix {
pkgs = throw "nixos docs / systemdServiceOptions: Do not reference pkgs in docs";
})
];
})
options
;
inherit (evalModules { modules = [ ../../modules/system/service/systemd/service.nix ]; }) options;
# TODO: filter out options that are not systemd-specific, maybe also change option prefix to just `service-opt-`?
inherit revision warningsAreErrors;
transformOptions =

View File

@@ -129,7 +129,7 @@
- [nvme-rs](https://github.com/liberodark/nvme-rs), NVMe monitoring [services.nvme-rs](#opt-services.nvme-rs.enable).
- [Overseerr](https://overseerr.dev), a request management and media discovery tool for the Plex ecosystem. Available as [services.overseerr](#opt-services.overseerr.enable).
- [Overseerr](https://overseerr.dev), a request management and media discovery tool for the Plex ecosystem. Available as {option}`opt-services.overseerr.enable`.
- [PairDrop](https://github.com/schlagmichdoch/pairdrop), a peer-to-peer file transfer web app. Available as [services.pairdrop](#opt-services.pairdrop.enable).

View File

@@ -84,7 +84,7 @@
- [PdfDing](https://www.pdfding.com/), manage, view and edit your PDFs seamlessly on all your devices wherever you are. Available as [services.pdfding](#opt-services.pdfding.enable).
- [mangowc](https://github.com/DreamMaoMao/mangowc), a lightweight and feature-rich Wayland compositor based on dwl. Available as [programs.mangowc](#opt-programs.mangowc.enable).
- [mangowc](https://github.com/DreamMaoMao/mangowc), a lightweight and feature-rich Wayland compositor based on dwl. Available as [programs.mangowc](#opt-programs.mango.enable).
- [reaction](https://reaction.ppom.me/), a daemon that scans program outputs for repeated patterns, and takes action. A common usage is to scan ssh and webserver logs, and to ban hosts that cause multiple authentication errors. A modern alternative to fail2ban. Available as [services.reaction](#opt-services.reaction.enable).

View File

@@ -89,9 +89,9 @@
- Apache Kafka has dropped support for ZooKeeper mode. The `apacheKafka_3_9` and `apacheKafka_4_0` packages have been removed, as every remaining packaged version is KRaft-only. The `services.apache-kafka.zookeeper` option (previously an alias for `services.apache-kafka.settings."zookeeper.connect"`) has been removed; migrate your cluster to [KRaft](#module-services-apache-kafka-kraft) mode instead.
- `virtualisation.registries.block` / `insecure` / `search` were deprecated,
- `virtualisation.containers.registries.block` / `insecure` / `search` were deprecated,
because they mapped to the deprecated V1 `registries.conf` format.
See the new option {option}`virtualisation.registries.settings`
See the new option {option}`virtualisation.containers.registries.settings`
and [containers-registries.conf(5)](https://github.com/containers/image/blob/main/docs/containers-registries.conf.5.md)
to migrate to the new configuration format.
@@ -113,6 +113,8 @@
- `services.komodo-periphery` has been updated to support version 2.0.0. Some options have been renamed to match the new configuration structure; compatibility aliases are provided for the renamed options. The `passkeys` and `outbound.onboardingKey` options have been removed; use `passkeyFiles`, `auth.privateKey`/`auth.corePublicKeys`, or `outbound.onboardingKeyFile` instead. New outbound mode configuration is available under `outbound.*`.
- Package `overseerr` has been removed as the `overseerr` and `jellyseerr` projects were merged under `seerr`.
## Other Notable Changes {#sec-release-26.11-notable-changes}
<!-- To avoid merge conflicts, consider adding your item at an arbitrary place in the list instead. -->
@@ -140,6 +142,8 @@
- `security.run0.persistentAuth` options have been added to support persistent Authentication of session. Timeout configurable via `security.polkit.settings.Polkitd.ExpirationSeconds`.
- [`virtualisation.qemu.firmware.enable`](#opt-virtualisation.qemu.firmware.enable) has been added to install QEMU firmware descriptors to {file}`/etc/qemu/firmware`, making the corresponding firmware images discoverable by tools such as `systemd-vmspawn`. By default this exposes the firmware bundled with QEMU. Further firmware can be added via [`virtualisation.qemu.firmware.packages`](#opt-virtualisation.qemu.firmware.packages), for example the new `OVMF-amdsev` and `OVMF-inteltdx` packages, which provide UEFI firmware for AMD SEV-SNP and Intel TDX confidential VMs.
- `boot.loader.systemd-boot` gained support for [Automatic Boot Assessment](https://systemd.io/AUTOMATIC_BOOT_ASSESSMENT/) via the new [`boot.loader.systemd-boot.bootCounting`](#opt-boot.loader.systemd-boot.bootCounting.enable) options, allowing automatic detection of and recovery from bad NixOS generations. As part of this change, boot loader entries on the ESP/XBOOTLDR partition are now named `nixos-<content-hash>.conf` instead of `nixos-generation-<n>.conf`; existing entries are migrated automatically on the next `nixos-rebuild boot`/`switch`.
- `services.nginx` gained a [`lua`](#opt-services.nginx.lua.enable) option to enable Lua scripting via OpenResty's lua-nginx-module on a stock nginx, configuring `lua_package_path`/`lua_package_cpath` from the packages listed in [`services.nginx.lua.extraPackages`](#opt-services.nginx.lua.extraPackages). Use this to add Lua to a regular nginx; for the full OpenResty platform (libraries that rely on its bundled lualib, such as `lua-resty-openidc`), set `services.nginx.package` to `pkgs.openresty` instead — the option configures the Lua search path for it too.

View File

@@ -355,7 +355,7 @@
./programs/wayland/hyprland.nix
./programs/wayland/hyprlock.nix
./programs/wayland/labwc.nix
./programs/wayland/mangowc.nix
./programs/wayland/mango.nix
./programs/wayland/miracle-wm.nix
./programs/wayland/niri.nix
./programs/wayland/pinnacle.nix
@@ -938,7 +938,6 @@
./services/misc/open-webui.nix
./services/misc/orthanc.nix
./services/misc/osrm.nix
./services/misc/overseerr.nix
./services/misc/owncast.nix
./services/misc/packagekit.nix
./services/misc/paisa.nix
@@ -2052,6 +2051,7 @@
./virtualisation/openvswitch.nix
./virtualisation/parallels-guest.nix
./virtualisation/podman/default.nix
./virtualisation/qemu-firmware.nix
./virtualisation/qemu-guest-agent.nix
./virtualisation/rosetta.nix
./virtualisation/spice-usb-redirection.nix

View File

@@ -14,56 +14,93 @@ in
Miriway, a Mir based Wayland compositor. You can manually launch Miriway by
executing "exec miriway" on a TTY, or launch it from a display manager. Copy
/etc/xdg/xdg-miriway/miriway-shell.config to ~/.config/miriway-shell.config
and /etc/xdg/xdg-miriway/miriway-shell.settings to ~/.config/miriway-shell.settings
to modify the system-wide configuration on a per-user basis. See <https://github.com/Miriway/Miriway>,
and "miriway --help" for more information'';
config = lib.mkOption {
description = ''
Contents of system-wide miriway-shell.config. See Miriway's configuration documentation for details.
'';
type = lib.types.lines;
default = ''
x11-window-title=Miriway (Mir-on-X)
idle-timeout=600
ctrl-alt=t:miriway-terminal # Default "terminal emulator finder"
shell-component=dbus-update-activation-environment --systemd DISPLAY WAYLAND_DISPLAY
meta=Left:@dock-left
meta=Right:@dock-right
meta=Space:@toggle-maximized
meta=Home:@workspace-begin
meta=End:@workspace-end
meta=Page_Up:@workspace-up
meta=Page_Down:@workspace-down
ctrl-alt=BackSpace:@exit
'';
example = ''
idle-timeout=300
ctrl-alt=t:weston-terminal
add-wayland-extensions=all
shell-components=dbus-update-activation-environment --systemd DISPLAY WAYLAND_DISPLAY
shell-component=waybar
shell-component=wbg Pictures/wallpaper
shell-meta=a:synapse
meta=Left:@dock-left
meta=Right:@dock-right
meta=Space:@toggle-maximized
meta=Home:@workspace-begin
meta=End:@workspace-end
meta=Page_Up:@workspace-up
meta=Page_Down:@workspace-down
ctrl-alt=BackSpace:@exit
'';
};
settings = lib.mkOption {
description = ''
Miriway's config. This will be installed system-wide.
The default will install the miriway package's barebones example config.
Contents of system-wide miriway-shell.settings. See Miriway's configuration documentation for details.
'';
type = lib.types.lines;
default = ''
command_ctrl_alt=t:miriway-terminal # Default "terminal emulator finder"
command_meta=Left:@dock-left
command_meta=Right:@dock-right
command_meta=Space:@toggle-maximized
command_meta=Home:@workspace-begin
command_meta=End:@workspace-end
command_meta=Page_Up:@workspace-up
command_meta=Page_Down:@workspace-down
command_ctrl_alt=BackSpace:@exit
'';
example = ''
command_ctrl_alt=t:weston-terminal
command_shell_meta=a:synapse
command_meta=Left:@dock-left
command_meta=Right:@dock-right
command_meta=Space:@toggle-maximized
command_meta=Home:@workspace-begin
command_meta=End:@workspace-end
command_meta=Page_Up:@workspace-up
command_meta=Page_Down:@workspace-down
command_ctrl_alt=BackSpace:@exit
'';
};
};
config = lib.mkIf cfg.enable {
warnings =
let
optionsNoLongerInConfig = [
"ctrl-alt"
"meta"
"shell-ctrl-alt"
"shell-meta"
"shell-plain"
"command_ctrl_alt"
"command_meta"
"command_shell_ctrl_alt"
"command_shell_meta"
"command_plain"
];
in
# Added 2026-07-17
lib.optional
(builtins.foldl' (
acc: option: acc || (lib.strings.hasInfix "${option}=" cfg.config)
) false optionsNoLongerInConfig)
''
Since Miriway 26.06, configuration options got partially renamed and split across different files.
A new option `programs.miriway.settings` got introduced for options that belong into miriway-shell.settings
instead of miriway-shell.config.
You appear to have one of the following options in `programs.miriway.config` that should now go into
`programs.miriway.settings`, and may need to be renamed:
${lib.strings.concatStringsSep ", " optionsNoLongerInConfig}
'';
environment = {
systemPackages = with pkgs; [
miriway
@@ -71,6 +108,7 @@ in
];
etc = {
"xdg/xdg-miriway/miriway-shell.config".text = cfg.config;
"xdg/xdg-miriway/miriway-shell.settings".text = cfg.settings;
};
};

View File

@@ -6,18 +6,22 @@
}:
let
cfg = config.programs.mangowc;
cfg = config.programs.mango;
in
{
options.programs.mangowc = {
enable = lib.mkEnableOption "MangoWC, a Wayland compositor based on dwl and scenefx";
options.programs.mango = {
enable = lib.mkEnableOption "Mango, a Wayland compositor based on dwl and scenefx";
package = lib.mkPackageOption pkgs "mangowc" {
default = [ "mangowc" ];
example = "pkgs.mangowc.override { enableXWayland = false; }";
package = lib.mkPackageOption pkgs "mango" {
default = [ "mango" ];
example = "pkgs.mango.override { enableXWayland = false; }";
};
};
imports = [
(lib.mkRenamedOptionModule [ "programs" "mangowc" ] [ "programs" "mango" ])
];
config = lib.mkIf cfg.enable {
environment.systemPackages = [ cfg.package ];

View File

@@ -539,6 +539,13 @@ in
(mkRemovedOptionModule [ "services" "xserver" "cmt" ] ''
services.xserver.cmt has been removed as it was broken and unmaintained upstream
'')
(mkRemovedOptionModule
[
"services"
"overseerr"
]
"`services.overseerr` has been replaced by `services.seerr` as the project has been merged with Jellyseerr under Seerr."
)
# Do NOT add any option renames here, see top of the file
];
}

View File

@@ -242,7 +242,9 @@ let
"elkm1"
"elv"
"enocean"
"homeassistant_connect_zbt2"
"homeassistant_hardware"
"homeassistant_sky_connect"
"homeassistant_yellow"
"firmata"
"flexit"

View File

@@ -1,89 +0,0 @@
{
config,
pkgs,
lib,
...
}:
let
cfg = config.services.overseerr;
in
{
meta.maintainers = [ lib.maintainers.jf-uu ];
options.services.overseerr = {
enable = lib.mkEnableOption "Overseerr, a request management and media discovery tool for the Plex ecosystem";
package = lib.mkPackageOption pkgs "overseerr" { };
openFirewall = lib.mkOption {
type = lib.types.bool;
default = false;
description = "Open a port in the firewall for the Overseerr web interface.";
};
port = lib.mkOption {
type = lib.types.port;
default = 5055;
description = "The port which the Overseerr web UI should listen on.";
};
};
config = lib.mkIf cfg.enable {
systemd.services.overseerr = {
description = "Request management and media discovery tool for the Plex ecosystem";
after = [ "network.target" ];
wantedBy = [ "multi-user.target" ];
environment = {
CONFIG_DIRECTORY = "/var/lib/overseerr";
PORT = toString cfg.port;
};
serviceConfig = {
CapabilityBoundingSet = "";
DynamicUser = true;
ExecStart = lib.getExe cfg.package;
LockPersonality = true;
NoNewPrivileges = true;
PrivateDevices = true;
PrivateIPC = true;
PrivateMounts = true;
PrivateTmp = true;
PrivateUsers = true;
ProcSubset = "pid";
ProtectClock = true;
ProtectControlGroups = true;
ProtectHome = true;
ProtectHostname = true;
ProtectKernelLogs = true;
ProtectKernelModules = true;
ProtectKernelTunables = true;
ProtectProc = "invisible";
ProtectSystem = "strict";
RemoveIPC = true;
Restart = "on-failure";
RestrictAddressFamilies = [
"AF_INET"
"AF_INET6"
"AF_UNIX"
];
RestrictNamespaces = true;
RestrictRealtime = true;
RestrictSUIDSGID = true;
StateDirectory = "overseerr";
StateDirectoryMode = "0700";
SystemCallArchitectures = "native";
SystemCallErrorNumber = "EPERM";
SystemCallFilter = [
"@system-service"
"~@privileged"
"~@resources"
];
Type = "exec";
};
};
networking.firewall = lib.mkIf cfg.openFirewall {
allowedTCPPorts = [ cfg.port ];
};
};
}

View File

@@ -988,8 +988,9 @@ in
systemd.services.nsd = {
description = "NSD authoritative only domain name service";
after = [ "network.target" ];
after = [ "network-online.target" ];
wantedBy = [ "multi-user.target" ];
wants = [ "network-online.target" ];
startLimitBurst = 4;
startLimitIntervalSec = 5 * 60; # 5 mins

View File

@@ -115,7 +115,7 @@ in
default = true;
description = ''
Whether unbound should resolve local queries (i.e. add 127.0.0.1 to
/etc/resolv.conf).
/etc/resolv.conf and set name servers to localhost respectively).
'';
};
@@ -276,6 +276,7 @@ in
resolvconf = {
useLocalResolver = mkDefault true;
};
nameservers = lib.mkBefore ([ "127.0.0.1" ] ++ (optional config.networking.enableIPv6 "::1"));
};
environment.etc."unbound/unbound.conf".source = confFile;

View File

@@ -36,8 +36,14 @@ let
userbornConfigJson = pkgs.writeText "userborn.json" (builtins.toJSON userbornConfig);
userbornStaticFiles =
pkgs.runCommand "static-userborn" { }
"mkdir -p $out; ${lib.getExe cfg.package} ${userbornConfigJson} $out";
pkgs.runCommand "static-userborn"
{
nativeBuildInputs = [ cfg.package ];
}
''
mkdir -p $out
userborn ${userbornConfigJson} $out
'';
previousConfigPath = "/var/lib/userborn/previous-userborn.json";
immutableEtc = config.system.etc.overlay.enable && !config.system.etc.overlay.mutable;

View File

@@ -1,9 +1,3 @@
# Non-module arguments
# These are separate from the module arguments to avoid implicit dependencies.
# This makes service modules self-contained, allowing mixing of Nixpkgs versions.
{ pkgs }:
# The module
{
lib,
config,
@@ -98,11 +92,6 @@ in
to prevent systemd substitution. Set this option explicitly to enable
systemd's substitution features.
When {option}`process.environment` contains keys set to `null`, the default
is automatically prefixed with `unexport KEY` invocations (from
`pkgs.execline`) so those variables are unset before the process starts,
regardless of what `Environment=` or inherited environment supplies.
To extend {option}`process.argv` with systemd specifiers, you can append
to the escaped arguments:
@@ -120,19 +109,8 @@ in
for available specifiers like `%n`, `%i`, `%t`.
'';
type = types.str;
default =
let
nullEnvKeys = lib.attrNames (lib.filterAttrs (_: v: v == null) config.process.environment);
in
if nullEnvKeys == [ ] then
config.systemd.lib.escapeSystemdExecArgs config.process.argv
else
lib.concatMapStringsSep " " (
k: "${escapeSystemdExecArg "${pkgs.execline}/bin/unexport"} ${escapeSystemdExecArg k}"
) nullEnvKeys
+ " "
+ config.systemd.lib.escapeSystemdExecArgs config.process.argv;
defaultText = lib.literalMD "The escaped `process.argv`, prefixed with `\"unexport\" \"KEY\"` (from `pkgs.execline`) for each key in `process.environment` set to `null`.";
default = config.systemd.lib.escapeSystemdExecArgs config.process.argv;
defaultText = lib.literalExpression "config.systemd.lib.escapeSystemdExecArgs config.process.argv";
};
systemd.mainExecReload = mkOption {
@@ -209,7 +187,7 @@ in
types.submoduleWith {
class = "service";
modules = [
(lib.modules.importApply ./service.nix { inherit pkgs; })
./service.nix
];
specialArgs = {
inherit systemdPackage;
@@ -229,9 +207,6 @@ in
systemd.services."" = {
# TODO description;
wantedBy = lib.mkDefault [ "multi-user.target" ];
environment = lib.mapAttrs (_: lib.mkDefault) (
lib.filterAttrs (_: v: v != null) config.process.environment
);
serviceConfig = {
ExecReload = config.systemd.mainExecReload;
Type = lib.mkDefault (if config.notificationProtocol.systemd then "notify" else "simple");

View File

@@ -63,7 +63,7 @@ let
modularServiceConfiguration = portable-lib.configure {
serviceManagerPkgs = pkgs;
extraRootModules = [
(lib.modules.importApply ./service.nix { inherit pkgs; })
./service.nix
./config-data-path.nix
];
extraRootSpecialArgs = {

View File

@@ -76,40 +76,6 @@ let
};
};
# Test that `process.environment` becomes `Environment=` entries on the unit,
# that null values are dropped from `Environment=` and wrapped with unexport
# in `ExecStart`.
system.services.envvars = {
process = {
argv = [ hello' ];
environment = {
FOO = "bar";
BAZ = "qux";
DROPPED = null;
};
};
};
# Test that an explicit `systemd.service.environment` override wins over
# the portable default produced by `process.environment`.
system.services.envvars-override = {
process = {
argv = [ hello' ];
environment.FOO = "from-process";
};
systemd.service.environment.FOO = "from-systemd";
};
# Test that `process.environment` `null` unsets via wrapper even when the
# systemd layer sets the same key (true unset, not just "skip setting").
system.services.envvars-unset = {
process = {
argv = [ hello' ];
environment.FOO = null;
};
systemd.service.environment.FOO = "leaked";
};
# Test extending process.argv with systemd specifiers
system.services.argv-extended =
{ config, ... }:
@@ -171,22 +137,6 @@ runCommand "test-modular-service-systemd-units"
# The base command should be escaped ($1 -> $$1, m%n -> m%%n), but the appended --systemd-unit %n should not be
grep -F 'ExecStart="${hello}/bin/hello" "--greeting" "Fun $$1 fact, remainder is often expressed as m%%n" --systemd-unit %n' ${toplevel}/etc/systemd/system/argv-extended.service >/dev/null
# process.environment becomes Environment= entries; null values are dropped
# from Environment= and wrapped with unexport in ExecStart.
grep -F 'Environment="FOO=bar"' ${toplevel}/etc/systemd/system/envvars.service >/dev/null
grep -F 'Environment="BAZ=qux"' ${toplevel}/etc/systemd/system/envvars.service >/dev/null
! grep -F 'Environment=.*DROPPED' ${toplevel}/etc/systemd/system/envvars.service
grep 'ExecStart=.*unexport.*DROPPED' ${toplevel}/etc/systemd/system/envvars.service >/dev/null
# systemd.service.environment override wins over process.environment.
grep -F 'Environment="FOO=from-systemd"' ${toplevel}/etc/systemd/system/envvars-override.service >/dev/null
! grep -F 'FOO=from-process' ${toplevel}/etc/systemd/system/envvars-override.service
# process.environment null uses unexport wrapper for true unset, even when
# the systemd layer has an Environment= entry for the same key.
grep -F 'Environment="FOO=leaked"' ${toplevel}/etc/systemd/system/envvars-unset.service >/dev/null
grep 'ExecStart=.*unexport.*FOO' ${toplevel}/etc/systemd/system/envvars-unset.service >/dev/null
[[ ! -e ${toplevel}/etc/systemd/system/foo.socket ]]
[[ ! -e ${toplevel}/etc/systemd/system/bar.socket ]]
[[ ! -e ${toplevel}/etc/systemd/system/bar-db.socket ]]

View File

@@ -69,7 +69,7 @@ in
config = lib.mkIf (cfg.enable) {
environment.systemPackages = [ cfg.package ];
# we also want these mounts in virtual machines.
fileSystems = if config.virtualisation ? qemu then lib.mkVMOverride mounts else mounts;
fileSystems = if config.virtualisation.qemu ? package then lib.mkVMOverride mounts else mounts;
# We no longer need those when using envfs
system.activationScripts.usrbinenv = lib.mkForce "";

View File

@@ -196,7 +196,7 @@ in
# that do not specify any nodes, or an empty attr set as nodes) will not
# have the QEMU module loaded and thuse these options can't and should not
# be set.
virtualisation = lib.optionalAttrs (options ? virtualisation.qemu) {
virtualisation = lib.optionalAttrs (options ? virtualisation.qemu.package) {
qemu = {
# NOTE: optionalAttrs
# test-instrumentation.nix appears to be used without qemu-vm.nix, so

View File

@@ -0,0 +1,50 @@
{
config,
lib,
pkgs,
...
}:
let
cfg = config.virtualisation.qemu.firmware;
in
{
options.virtualisation.qemu.firmware = {
enable = lib.mkEnableOption "QEMU firmware descriptors in {file}`/etc/qemu/firmware`";
packages = lib.mkOption {
type = lib.types.listOf lib.types.package;
default = [ pkgs.qemu ];
defaultText = lib.literalExpression "[ pkgs.qemu ]";
example = lib.literalExpression "[ pkgs.qemu pkgs.OVMF-amdsev.fd ]";
description = ''
Packages providing QEMU firmware descriptors under
{file}`share/qemu/firmware`, following the QEMU firmware interop
convention (see {file}`docs/interop/firmware.json` in the QEMU
source tree). The descriptors are merged and linked to
{file}`/etc/qemu/firmware`, where tools like
{command}`systemd-vmspawn` discover the firmware available for
running virtual machines.
The default exposes the descriptors of the firmware images
bundled with QEMU. Note that setting this option replaces the
default, so include `pkgs.qemu` when adding further firmware.
'';
};
};
config = lib.mkIf cfg.enable {
environment.etc."qemu/firmware".source =
let
merged = pkgs.buildEnv {
name = "qemu-firmware-descriptors";
paths = cfg.packages;
pathsToLink = [ "/share/qemu/firmware" ];
};
in
"${merged}/share/qemu/firmware";
};
meta.maintainers = [ lib.maintainers.katexochen ];
}

View File

@@ -1303,7 +1303,6 @@ in
osrm-backend = runTest ./osrm-backend.nix;
outline = runTest ./outline.nix;
overlayfs = runTest ./overlayfs.nix;
overseerr = runTest ./overseerr.nix;
owi = runTest ./owi.nix;
owncast = runTest ./owncast.nix;
oxidized = handleTest ./oxidized.nix { };
@@ -1449,6 +1448,7 @@ in
pykms = runTest ./pykms.nix;
qbittorrent = runTest ./qbittorrent.nix;
qboot = runTestOn [ "x86_64-linux" "i686-linux" ] ./qboot.nix;
qemu-firmware = runTestOn [ "x86_64-linux" ] ./qemu-firmware.nix;
qemu-vm-external-disk-image = runTest ./qemu-vm-external-disk-image.nix;
qemu-vm-restrictnetwork = handleTest ./qemu-vm-restrictnetwork.nix { };
qemu-vm-store = runTest ./qemu-vm-store.nix;

View File

@@ -33,13 +33,12 @@
add-wayland-extensions=all
enable-x11=
ctrl-alt=t:foot --maximized
ctrl-alt=a:env WINIT_UNIX_BACKEND=x11 WAYLAND_DISPLAY= alacritty --option window.startup_mode=\"maximized\"
shell-component=dbus-update-activation-environment --systemd DISPLAY WAYLAND_DISPLAY
shell-component=foot --maximized
'';
settings = ''
command_ctrl_alt=t:foot --maximized
command_ctrl_alt=a:env WINIT_UNIX_BACKEND=x11 WAYLAND_DISPLAY= alacritty --option window.startup_mode=\"maximized\"
'';
};
environment = {
@@ -59,8 +58,9 @@
etc."xdg/foot/foot.ini".source = (pkgs.formats.ini { }).generate "foot.ini" {
main = {
font = "inconsolata:size=16";
initial-color-theme = "light";
};
colors = rec {
colors-light = rec {
foreground = "000000";
background = "ffffff";
regular2 = foreground;

View File

@@ -1,20 +0,0 @@
{ lib, pkgs, ... }:
{
name = "overseerr";
meta.maintainers = with lib.maintainers; [ jf-uu ];
nodes.machine =
{ pkgs, ... }:
{
environment.systemPackages = [ pkgs.jq ];
services.overseerr.enable = true;
};
testScript = ''
machine.wait_for_unit("overseerr.service")
machine.wait_for_open_port(5055)
version = machine.succeed("curl --fail http://localhost:5055/api/v1/status | jq --raw-output .version").rstrip("\n")
assert version == "${pkgs.overseerr.version}", f"expected version to be ${pkgs.overseerr.version}, got {version}"
'';
}

View File

@@ -0,0 +1,41 @@
{ lib, ... }:
{
name = "qemu-firmware";
meta.maintainers = [ lib.maintainers.katexochen ];
nodes.machine =
{ pkgs, ... }:
{
virtualisation.qemu.firmware = {
enable = true;
packages = [
pkgs.qemu
pkgs.OVMF-amdsev.fd
pkgs.OVMF-inteltdx.fd
];
};
environment.systemPackages = [ pkgs.jq ];
};
testScript = ''
machine.wait_for_unit("multi-user.target")
with subtest("descriptors are merged into /etc/qemu/firmware"):
machine.succeed("test -e /etc/qemu/firmware/60-edk2-x86_64.json")
machine.succeed("test -e /etc/qemu/firmware/61-edk2-ovmf-x64-amdsev.json")
machine.succeed("test -e /etc/qemu/firmware/61-edk2-ovmf-x64-inteltdx.json")
with subtest("descriptors reference existing firmware images"):
machine.succeed(
"jq -er '.mapping | .filename // .executable.filename' "
+ "/etc/qemu/firmware/*.json | xargs stat --"
)
with subtest("systemd-vmspawn discovers the descriptors"):
listed = machine.succeed("systemd-vmspawn --firmware=list")
assert "61-edk2-ovmf-x64-amdsev.json" in listed
assert "61-edk2-ovmf-x64-inteltdx.json" in listed
assert "60-edk2-x86_64.json" in listed
'';
}

View File

@@ -91,6 +91,9 @@ let
click_when_unobstructed((By.XPATH, "//a[contains(., 'Skip to web app')]"))
# Skip the tour on first login
click_when_unobstructed((By.XPATH, "//button[contains(., 'Skip')]"))
click_when_unobstructed((By.XPATH, "//button[contains(., 'New item')]"))
driver.find_element(By.XPATH, '//input[@formcontrolname="name"]').send_keys(

View File

@@ -0,0 +1,19 @@
{
lib,
b4,
melpaBuild,
}:
melpaBuild {
pname = "b4-review-mode";
inherit (b4) version;
src = b4.src-misc;
sourceRoot = "${b4.src-misc.name}/misc/emacs";
meta = {
description = "Emacs major mode with highlighting for the b4 review reply editor";
homepage = "https://git.kernel.org/pub/scm/utils/b4/b4.git/about";
license = lib.licenses.gpl2Only;
maintainers = with lib.maintainers; [ fzakaria ];
};
}

View File

@@ -6,22 +6,26 @@
magit,
transient,
with-editor,
consult,
plz,
}:
melpaBuild {
pname = "majutsu";
version = "0.6.0-unstable-2026-07-09";
version = "0.6.0-unstable-2026-07-23";
src = fetchFromGitHub {
owner = "0WD0";
repo = "majutsu";
rev = "59aff9b93eac575fbccc1f4ab2d48d048e0ead9b";
hash = "sha256-GJ62hsHgLEFIY0ghij0VPFt1jMUGRKhI2eCroBjkxtc=";
rev = "8eaf8cb4db2f0737d0a131ef8b61ce6393660369";
hash = "sha256-QqvzRfqWa4Ql7bpuShqHmXzXJCu1VU8ObnImiK7ZyvE=";
};
packageRequires = [
magit
transient
with-editor
consult
plz
];
passthru.updateScript = nix-update-script { extraArgs = [ "--version=branch=main" ]; };

View File

@@ -0,0 +1,19 @@
{
lib,
vimUtils,
b4,
}:
vimUtils.buildVimPlugin {
pname = "b4-review-vim";
inherit (b4) version;
src = b4.src-misc;
sourceRoot = "${b4.src-misc.name}/misc/vim";
meta = {
description = "Vim syntax highlighting for the b4 review reply editor";
homepage = "https://git.kernel.org/pub/scm/utils/b4/b4.git/about";
license = lib.licenses.gpl2Only;
maintainers = with lib.maintainers; [ fzakaria ];
};
}

View File

@@ -74,6 +74,9 @@ let
];
env = {
# Build zlob for a portable CPU baseline (https://github.com/dmtrKovalenko/fff/issues/705)
CI = "1";
OPENSSL_NO_VENDOR = true;
# Allow undefined symbols on Darwin - they will be provided by Neovim's LuaJIT runtime

View File

@@ -21,22 +21,22 @@ vscode-utils.buildVscodeMarketplaceExtension (finalAttrs: {
sources = {
"x86_64-linux" = {
arch = "linux-x64";
hash = "sha256-Y6MXjJBmhMzuQMwhkPLHK/vtciTdjsGvkEblH3ofju0=";
hash = "sha256-Z/tQ+KV+3MdbknA/1kmiIpVfOsUM8NUu+0iHlPVbYV0=";
};
"aarch64-linux" = {
arch = "linux-arm64";
hash = "sha256-8VvDtb+8SoLTRC7pXwH40amRurxTQgCmhdi0u7e5AfU=";
hash = "sha256-d2GjWr0FHOoORI5KRdwUQvcFfBB8xV6j9wj5OS9VL9o=";
};
"aarch64-darwin" = {
arch = "darwin-arm64";
hash = "sha256-bqjEgsjY+zyG1g/KtkRNxAlazIpc+HwGWvsMQNnPI2M=";
hash = "sha256-dlfGTxf2EoiNb0g9uqwjTNW8fi2d1tzubGdIDyp4xTw=";
};
};
in
{
name = "claude-code";
publisher = "anthropic";
version = "2.1.218";
version = "2.1.219";
}
// sources.${stdenvNoCC.hostPlatform.system}
or (throw "Unsupported system ${stdenvNoCC.hostPlatform.system}");

View File

@@ -10,8 +10,8 @@ vscode-utils.buildVscodeMarketplaceExtension {
mktplcRef = {
publisher = "oxc";
name = "oxc-vscode";
version = "1.58.0";
hash = "sha256-30dFeguNbY8WM3fLym6aUMkHYH5wA5scSNn04Ukbj9U=";
version = "1.59.0";
hash = "sha256-avfW91oF8PGCoDYocC744wpQ3zE8fv5582n55Ugb8k8=";
};
nativeBuildInputs = [

View File

@@ -5,13 +5,13 @@
}:
mkLibretroCore {
core = "mednafen-vb";
version = "0-unstable-2026-06-14";
version = "0-unstable-2026-07-22";
src = fetchFromGitHub {
owner = "libretro";
repo = "beetle-vb-libretro";
rev = "38e7a0ec9ac7079ca1c1e3dd9aaf5b56f527efca";
hash = "sha256-+57qsfH2wygKdD66yauzKD9XDf01q4LeiWdIeYbVUmc=";
rev = "7cc663e9044459b3dab1790bdce8f48dc7358ed6";
hash = "sha256-ntw8SXzyu0PTDQgaLmT5Wy172A8TI3JLN6A5WQ2T/OI=";
};
makefile = "Makefile";

View File

@@ -20,13 +20,13 @@
}:
mkLibretroCore {
core = "dolphin";
version = "0-unstable-2026-07-12";
version = "0-unstable-2026-07-23";
src = fetchFromGitHub {
owner = "libretro";
repo = "dolphin";
rev = "0b766a68cc835775b3216500bb9af2f5d4602b12";
hash = "sha256-JaUiDc4/vEWjEXe6H9+i6pft2DTsl5my5wyFmtbjdR0=";
rev = "c6b869102f6b9f450f0a9878330d00484754879d";
hash = "sha256-7sImbA1uzpwGovo4+5bK9SJpIDIvdB5FhN2IuxVaiQ8=";
fetchSubmodules = true;
};

View File

@@ -7,13 +7,13 @@
}:
mkLibretroCore {
core = "melonds";
version = "0-unstable-2026-06-25";
version = "0-unstable-2026-07-19";
src = fetchFromGitHub {
owner = "libretro";
repo = "melonds";
rev = "c9550d18923fe86a5ad9faa159399b55c12b47f1";
hash = "sha256-xvBdt/TMxZOrC//DLHRWRMqIibt7dNsfLM/FeMTRA60=";
rev = "66b5d2634cd0a79030562811e6e05f5532f800ba";
hash = "sha256-nQvnXoB8UeaSr6QfYwn18Y18KyLyWvcv/Q3L3SHvaNU=";
};
extraBuildInputs = [

View File

@@ -5,13 +5,13 @@
}:
mkLibretroCore {
core = "picodrive";
version = "0-unstable-2026-04-02";
version = "0-unstable-2026-07-23";
src = fetchFromGitHub {
owner = "libretro";
repo = "picodrive";
rev = "f0d4a0118a9733a1f10bce5a4ac772c474f9300d";
hash = "sha256-q584bnqIbKoXSCRHUAcqSJAIhholnXfbphvLVcbm57o=";
rev = "78a662e3135871a6c657d5e61900f6704152e594";
hash = "sha256-3+x1ILIUq+/nwfUGXweNIq3PFTAaP56/6G+dX4dEZ/Y=";
fetchSubmodules = true;
};

View File

@@ -0,0 +1,37 @@
{ callPackage }:
let
flavorData = {
browser = {
optStem = "brave";
fileStem = "brave-browser";
appIdStem = "com.brave.Browser";
darwinStem = "Brave Browser";
changelogFile = "CHANGELOG_DESKTOP.md";
homepage = "https://brave.com/";
innerBinary = "brave";
};
origin = {
optStem = "brave-origin";
fileStem = "brave-origin";
appIdStem = "com.brave.Origin";
darwinStem = "Brave Origin";
changelogFile = "CHANGELOG_DESKTOP_ORIGIN.md";
homepage = "https://brave.com/origin/";
innerBinary = "brave";
};
};
mkBrave =
release:
let
pkg = import release;
fd = flavorData.${pkg.flavor or "browser"};
in
callPackage ./make-brave.nix { } (pkg // fd);
in
{
brave = mkBrave ./packages/brave.nix;
brave-origin = mkBrave ./packages/brave-origin.nix;
}

View File

@@ -49,26 +49,20 @@
coreutils,
libxcb,
zlib,
# Darwin dependencies
unzip,
makeWrapper,
# command line arguments which are always set e.g "--disable-gpu"
commandLineArgs ? "",
# Necessary for USB audio devices.
pulseSupport ? stdenv.hostPlatform.isLinux,
libpulseaudio,
# For GPU acceleration support on Wayland (without the lib it doesn't seem to work)
libGL,
# For video acceleration via VA-API (--enable-features=AcceleratedVideoDecodeLinuxGL,AcceleratedVideoEncoder)
libvaSupport ? stdenv.hostPlatform.isLinux,
libva,
enableVideoAcceleration ? libvaSupport,
# For Vulkan support (--enable-features=Vulkan); disabled by default as it seems to break VA-API
vulkanSupport ? false,
addDriverRunpath,
@@ -78,8 +72,22 @@
{
pname,
version,
hash,
url,
# Map from Nix system strings ("x86_64-linux", "aarch64-darwin", ...) to
# the corresponding upstream `{ url, hash }` record. Encoding the per-system
# sources as data rather than positional arguments lets channel-specific
# package.nix files drop platforms that upstream hasn't published yet.
archives,
# Upstream product flavor: "browser" (the regular Brave) or "origin" (the
# stripped-down Brave Origin).
flavor ? "browser",
# Flavor-specific paths supplied by the caller (default.nix).
optStem,
fileStem,
appIdStem,
darwinStem,
changelogFile,
homepage,
innerBinary,
}:
let
@@ -94,6 +102,19 @@ let
escapeShellArg
;
# /opt/brave.com/<optName>/
optName = optStem;
# Basename used for .desktop, gnome-control-center xml and icon files.
fileBase = fileStem;
# Secondary .desktop app-id.
appId = appIdStem;
# Upstream shell wrapper inside /opt.
innerWrapper = fileStem;
# macOS .app bundle name (inside the zip).
darwinApp = darwinStem;
# Upstream Exec= target in .desktop files (replaced with our wrapper).
upstreamBin = "brave-${flavor}-stable";
deps = [
alsa-lib
at-spi2-atk
@@ -156,13 +177,19 @@ let
] # disable automatic updates
# The feature disable is needed for VAAPI to work correctly: https://github.com/brave/brave-browser/issues/20935
++ optionals enableVideoAcceleration [ "UseChromeOSDirectVideoDecoder" ];
archive =
assert lib.assertMsg (builtins.hasAttr stdenv.hostPlatform.system archives)
"${pname} is not available for ${stdenv.hostPlatform.system}";
archives.${stdenv.hostPlatform.system};
in
stdenv.mkDerivation {
inherit pname version;
src = fetchurl {
inherit url hash;
};
__structuredAttrs = true;
strictDeps = true;
src = fetchurl { inherit (archive) url hash; };
dontConfigure = true;
dontBuild = true;
@@ -201,27 +228,27 @@ stdenv.mkDerivation {
cp -R usr/share $out
cp -R opt/ $out/opt
export BINARYWRAPPER=$out/opt/brave.com/brave/brave-browser
export BINARYWRAPPER=$out/opt/brave.com/${optName}/${innerWrapper}
# Fix path to bash in $BINARYWRAPPER
substituteInPlace $BINARYWRAPPER \
--replace-fail /bin/bash ${stdenv.shell} \
--replace-fail 'CHROME_WRAPPER' 'WRAPPER'
ln -sf $BINARYWRAPPER $out/bin/brave
ln -sf $BINARYWRAPPER $out/bin/${pname}
for exe in $out/opt/brave.com/brave/{brave,chrome_crashpad_handler}; do
for exe in $out/opt/brave.com/${optName}/{${innerBinary},chrome_crashpad_handler}; do
patchelf \
--set-interpreter "$(cat $NIX_CC/nix-support/dynamic-linker)" \
--set-rpath "${rpath}" $exe
done
# Fix paths
substituteInPlace $out/share/applications/{brave-browser,com.brave.Browser}.desktop \
--replace-fail /usr/bin/brave-browser-stable $out/bin/brave
substituteInPlace $out/share/gnome-control-center/default-apps/brave-browser.xml \
substituteInPlace $out/share/applications/{${fileBase},${appId}}.desktop \
--replace-fail /usr/bin/${upstreamBin} $out/bin/${pname}
substituteInPlace $out/share/gnome-control-center/default-apps/${fileBase}.xml \
--replace-fail /opt/brave.com $out/opt/brave.com
substituteInPlace $out/opt/brave.com/brave/default-app-block \
substituteInPlace $out/opt/brave.com/${optName}/default-app-block \
--replace-fail /opt/brave.com $out/opt/brave.com
# Correct icons location
@@ -229,13 +256,13 @@ stdenv.mkDerivation {
for icon in ''${icon_sizes[*]}
do
mkdir -p $out/share/icons/hicolor/$icon\x$icon/apps
ln -s $out/opt/brave.com/brave/product_logo_$icon.png $out/share/icons/hicolor/$icon\x$icon/apps/brave-browser.png
mkdir -p $out/share/icons/hicolor/''${icon}x''${icon}/apps
ln -s $out/opt/brave.com/${optName}/product_logo_''${icon}.png $out/share/icons/hicolor/''${icon}x''${icon}/apps/${fileBase}.png
done
# Replace xdg-settings and xdg-mime
ln -sf ${xdg-utils}/bin/xdg-settings $out/opt/brave.com/brave/xdg-settings
ln -sf ${xdg-utils}/bin/xdg-mime $out/opt/brave.com/brave/xdg-mime
ln -sf ${xdg-utils}/bin/xdg-settings $out/opt/brave.com/${optName}/xdg-settings
ln -sf ${xdg-utils}/bin/xdg-mime $out/opt/brave.com/${optName}/xdg-mime
runHook postInstall
''
@@ -244,9 +271,9 @@ stdenv.mkDerivation {
mkdir -p $out/{Applications,bin}
cp -r . "$out/Applications/Brave Browser.app"
cp -r . "$out/Applications/${darwinApp}.app"
makeWrapper "$out/Applications/Brave Browser.app/Contents/MacOS/Brave Browser" $out/bin/brave
makeWrapper "$out/Applications/${darwinApp}.app/Contents/MacOS/${darwinApp}" $out/bin/${pname}
runHook postInstall
'';
@@ -279,22 +306,33 @@ stdenv.mkDerivation {
installCheckPhase = ''
# Bypass upstream wrapper which suppresses errors
$out/opt/brave.com/brave/brave --version
$out/opt/brave.com/${optName}/brave --version
'';
passthru.updateScript = ./update.sh;
meta = {
homepage = "https://brave.com/";
description = "Privacy-oriented browser for Desktop and Laptop computers";
homepage = homepage;
description =
"Privacy-oriented browser for Desktop and Laptop computers"
+ lib.optionalString (flavor == "origin") " (Origin variant)";
changelog =
"https://github.com/brave/brave-browser/blob/master/CHANGELOG_DESKTOP.md#"
"https://github.com/brave/brave-browser/blob/master/${changelogFile}#"
+ lib.replaceStrings [ "." ] [ "" ] version;
longDescription = ''
Brave browser blocks the ads and trackers that slow you down,
chew up your bandwidth, and invade your privacy. Brave lets you
contribute to your favorite creators automatically.
'';
longDescription =
if flavor == "origin" then
''
Brave Origin is a stripped-down variant of the Brave browser that
removes most non-privacy features (rewards, wallet, AI, etc.) while
keeping the core privacy, adblock and Chromium-based browsing
experience.
''
else
''
Brave browser blocks the ads and trackers that slow you down,
chew up your bandwidth, and invade your privacy. Brave lets you
contribute to your favorite creators automatically.
'';
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
license = lib.licenses.mpl20;
maintainers = with lib.maintainers; [
@@ -302,12 +340,9 @@ stdenv.mkDerivation {
jefflabonte
nasirhm
buckley310
rachalaraj
];
platforms = [
"aarch64-linux"
"x86_64-linux"
"aarch64-darwin"
];
mainProgram = "brave";
platforms = builtins.attrNames archives;
mainProgram = if flavor == "origin" then "brave-origin" else "brave";
};
}

View File

@@ -0,0 +1,21 @@
# Expression generated by update.sh; do not edit it by hand!
rec {
pname = "brave-origin";
version = "1.92.144";
flavor = "origin";
archives = {
aarch64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin_${version}_arm64.deb";
hash = "sha256-zqjpiBMogYhtuEhIlPlK8J2j9hzfd1M8RYlT/c74Na8=";
};
x86_64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin_${version}_amd64.deb";
hash = "sha256-KF5WXF7GJPLCcEQyASEVfNrYyFJRXBSyWVPPAZPCa/E=";
};
aarch64-darwin = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin-v${version}-darwin-arm64.zip";
hash = "sha256-kkP8cBRnC34+SjC9EvkpKcDYP3cxW7sdJgni0+zXwbk=";
};
};
}

View File

@@ -0,0 +1,20 @@
# Expression generated by update.sh; do not edit it by hand!
rec {
pname = "brave";
version = "1.92.144";
archives = {
aarch64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_arm64.deb";
hash = "sha256-Z9uUJRaMx+P35oXtvAnjHyOQOXt8mW5oyyEtnD754x8=";
};
x86_64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_amd64.deb";
hash = "sha256-no/KD+3EB6CqvVWEmDB/8k2rv1wau469FBXMNWN7z6k=";
};
aarch64-darwin = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-v${version}-darwin-arm64.zip";
hash = "sha256-YidWCVGP36wn1goAulSbVrKFoHI1NA/pLtfPjIXBO48=";
};
};
}

View File

@@ -0,0 +1,100 @@
#!/usr/bin/env nix-shell
#!nix-shell -i bash -p curl nix jq
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" &>/dev/null && pwd)"
VERSIONS_URL="https://versions.brave.com/latest/brave-versions.json"
sri_hash() {
nix-hash --to-sri --type sha256 "$(nix-prefetch-url --type sha256 "$1")"
}
find_release_with_asset() {
local versionsJson="$1" channel="$2" template="$3"
local match
match="$(
jq -c --arg channel "$channel" --arg tmpl "$template" '
[.[]
| select(.channel == $channel)
| . as $r
| select(
$r.github.assets
| map(.name)
| any(. == ($tmpl | gsub("\\$\\{version\\}"; $r.name)))
)
]
| sort_by(.published)
| last
' <<<"$versionsJson"
)"
if [[ "$match" != "null" ]]; then
printf '%s' "$match"
return 0
fi
echo "update.sh: no ${channel} release with asset matching '${template}' found" >&2
return 1
}
emit_archive_entry() {
local releaseJson="$1" version="$2" template="$3" platform="$4"
local name="${template//\$\{version\}/$version}"
local url
url="$(
jq -r --arg n "$name" '
.github.assets[]
| select(.name == $n)
| .download_url
' <<<"$releaseJson"
)"
if [[ -z "$url" ]]; then
return 0
fi
local hash
hash="$(sri_hash "$url")"
local nixUrl="${url//${version}/\$\{version\}}"
cat <<EOF
${platform} = {
url = "${nixUrl}";
hash = "${hash}";
};
EOF
}
write_package_nix() {
local pname="$1" releaseJson="$2" debStem="$3" darwinStem="$4"
local version
version="$(jq -r '.name' <<<"$releaseJson")"
echo "=> ${pname}: ${version}" >&2
local flavorLine=""
if [[ "$pname" == brave-origin || "$pname" == brave-origin-* ]]; then
flavorLine=' flavor = "origin";'
fi
local outFile="${SCRIPT_DIR}/packages/${pname}.nix"
{
echo '# Expression generated by update.sh; do not edit it by hand!'
echo 'rec {'
echo " pname = \"${pname}\";"
echo " version = \"${version}\";"
[[ -n "$flavorLine" ]] && echo "$flavorLine"
echo ''
echo ' archives = {'
emit_archive_entry "$releaseJson" "$version" "${debStem}_\${version}_arm64.deb" "aarch64-linux"
emit_archive_entry "$releaseJson" "$version" "${debStem}_\${version}_amd64.deb" "x86_64-linux"
emit_archive_entry "$releaseJson" "$version" "${darwinStem}-v\${version}-darwin-arm64.zip" "aarch64-darwin"
echo ' };'
echo '}'
} > "$outFile"
}
versionsJson="$(curl --fail -s "$VERSIONS_URL")"
entries=(
"brave brave-browser brave"
"brave-origin brave-origin brave-origin"
)
for entry in "${entries[@]}"; do
read -r pname debStem darwinStem <<<"$entry"
releaseJson="$(find_release_with_asset "$versionsJson" "release" "${debStem}_\${version}_amd64.deb")"
write_package_nix "$pname" "$releaseJson" "$debStem" "$darwinStem"
done

View File

@@ -91,7 +91,6 @@
cupsSupport ? true,
cups ? null,
proprietaryCodecs ? true,
pulseSupport ? false,
libpulseaudio ? null,
ungoogled ? false,
ungoogled-chromium,
@@ -394,7 +393,9 @@ let
libgcrypt
cups
]
++ lib.optional pulseSupport libpulseaudio;
++ [
libpulseaudio
];
buildInputs = [
]
@@ -455,7 +456,9 @@ let
libgcrypt
cups
]
++ lib.optional pulseSupport libpulseaudio;
++ [
libpulseaudio
];
patches = [
./patches/cross-compile.patch
@@ -968,7 +971,7 @@ let
use_vaapi = false;
use_v4l2_codec = true;
}
// lib.optionalAttrs pulseSupport {
// {
use_pulseaudio = true;
link_pulseaudio = true;
}

View File

@@ -32,7 +32,6 @@
enableWideVine ? false,
ungoogled ? false, # Whether to build chromium or ungoogled-chromium
cupsSupport ? true,
pulseSupport ? config.pulseaudio or stdenv.hostPlatform.isLinux,
commandLineArgs ? "",
pkgsBuildBuild,
pkgs,
@@ -76,7 +75,6 @@ let
inherit
proprietaryCodecs
cupsSupport
pulseSupport
ungoogled
;
gnChromium = buildPackages.gn.override upstream-info.deps.gn;

View File

@@ -535,11 +535,11 @@
"vendorHash": null
},
"hashicorp_azurerm": {
"hash": "sha256-XJmSVCX6rigPD4oi0S4qUyvgvR5SkCHZV2rMAqsmIIo=",
"hash": "sha256-M8Kq0lVbPtob2g8j8k4OJenAz8f5jjSobf192TrpSEg=",
"homepage": "https://registry.terraform.io/providers/hashicorp/azurerm",
"owner": "hashicorp",
"repo": "terraform-provider-azurerm",
"rev": "v4.79.0",
"rev": "v4.81.0",
"spdx": "MPL-2.0",
"vendorHash": null
},

View File

@@ -13,7 +13,6 @@
gst_all_1,
gtk2,
gtk2-x11,
gtkspell2,
intltool,
lib,
libice,
@@ -94,7 +93,6 @@ let
]
++ lib.optionals stdenv.hostPlatform.isLinux [
gtk2
gtkspell2
farstream
]
++ lib.optional stdenv.hostPlatform.isDarwin gtk2-x11;
@@ -126,16 +124,14 @@ let
"--disable-nm"
"--disable-tcl"
"--disable-gevolution"
"--disable-gtkspell"
]
++ lib.optionals withCyrus_sasl [ "--enable-cyrus-sasl=yes" ]
++ lib.optionals withGnutls [
"--enable-gnutls=yes"
"--enable-nss=no"
]
++ lib.optionals stdenv.hostPlatform.isDarwin [
"--disable-gtkspell"
"--disable-vv"
]
++ lib.optionals stdenv.hostPlatform.isDarwin [ "--disable-vv" ]
++ lib.optionals stdenv.cc.isClang [ "CFLAGS=-Wno-error=int-conversion" ];
enableParallelBuilding = true;

View File

@@ -97,6 +97,82 @@ let
buildPrefix = "Build/*/*";
isQemuPlatform = builtins.elem projectDscPath [
"OvmfPkg/OvmfPkgX64.dsc"
"ArmVirtPkg/ArmVirtQemu.dsc"
"OvmfPkg/RiscVVirt/RiscVVirtQemu.dsc"
"OvmfPkg/LoongArchVirt/LoongArchVirtQemu.dsc"
];
# QEMU firmware interop descriptors to install, keyed by file name.
# Add an attribute to ship an additional descriptor.
qemuDescriptors =
let
description = "${fwPrefix} UEFI firmware for ${cpuName}${lib.optionalString secureBoot " with Secure Boot"}";
flashMapping = varsFile: {
device = "flash";
mode = "split";
executable = {
filename = "${placeholder "fd"}/FV/${fwPrefix}_CODE.fd";
format = "raw";
};
nvram-template = {
filename = "${placeholder "fd"}/FV/${varsFile}";
format = "raw";
};
};
common = {
interface-types = [ "uefi" ];
targets = [
{
architecture = cpuName;
machines =
{
x86_64 =
if systemManagementModeRequired then
[ "pc-q35-*" ]
else
[
"pc-i440fx-*"
"pc-q35-*"
];
aarch64 = [ "virt-*" ];
riscv64 = [ "virt*" ];
loongarch64 = [ "virt*" ];
}
.${cpuName} or [ ];
}
];
features =
lib.optionals stdenv.hostPlatform.isx86 [
"acpi-s3"
"amd-sev"
]
++ lib.optionals (stdenv.hostPlatform.isx86 && !systemManagementModeRequired) [ "amd-sev-es" ]
++ lib.optionals secureBoot [ "secure-boot" ]
++ lib.optionals systemManagementModeRequired [ "requires-smm" ]
++ lib.optionals (stdenv.hostPlatform.isx86 && !debug) [ "verbose-dynamic" ];
tags = [ ];
};
in
lib.optionalAttrs isQemuPlatform (
{
"50-edk2-${cpuName}${lib.optionalString secureBoot "-sb"}.json" = common // {
inherit description;
mapping = flashMapping "${fwPrefix}_VARS.fd";
};
}
// lib.optionalAttrs msVarsTemplate {
"40-edk2-${cpuName}${lib.optionalString secureBoot "-sb"}-enrolled.json" = common // {
description = "${description}, Microsoft keys enrolled";
mapping = flashMapping "${fwPrefix}_VARS.ms.fd";
features = common.features ++ [ "enrolled-keys" ];
};
}
);
in
assert msVarsTemplate -> fdSize4MB;
@@ -242,7 +318,17 @@ edk2.mkDerivation projectDscPath (finalAttrs: {
mkdir -vp $fd/AAVMF
ln -s $fd/FV/AAVMF_CODE.fd $fd/AAVMF/QEMU_EFI-pflash.raw
ln -s $fd/FV/AAVMF_VARS.fd $fd/AAVMF/vars-template-pflash.raw
'';
''
+ lib.optionalString (qemuDescriptors != { }) ''
mkdir -vp $fd/share/qemu/firmware
''
+ lib.concatStrings (
lib.mapAttrsToList (name: descriptor: ''
python3 -m json.tool > $fd/share/qemu/firmware/${name} <<'EOF'
${builtins.toJSON descriptor}
EOF
'') qemuDescriptors
);
dontPatchELF = true;

View File

@@ -143,6 +143,27 @@ let
hash = mobyHash;
};
extraMobyPath = lib.optionals stdenv.hostPlatform.isLinux (
lib.makeBinPath [
iproute2
iptables
e2fsprogs
xz
xfsprogs
procps
util-linuxMinimal
gitMinimal
]
);
extraMobyUserPath = lib.optionals (stdenv.hostPlatform.isLinux && !clientOnly) (
lib.makeBinPath [
rootlesskit
slirp4netns
fuse-overlayfs
]
);
moby = buildGoModule (
lib.optionalAttrs stdenv.hostPlatform.isLinux {
pname = "moby";
@@ -170,27 +191,6 @@ let
++ lib.optionals withSystemd [ systemd ]
++ lib.optionals withSeccomp [ libseccomp ];
extraPath = lib.optionals stdenv.hostPlatform.isLinux (
lib.makeBinPath [
iproute2
iptables
e2fsprogs
xz
xfsprogs
procps
util-linuxMinimal
gitMinimal
]
);
extraUserPath = lib.optionals (stdenv.hostPlatform.isLinux && !clientOnly) (
lib.makeBinPath [
rootlesskit
slirp4netns
fuse-overlayfs
]
);
postPatch = ''
patchShebangs hack/make.sh hack/make/
''
@@ -218,7 +218,9 @@ let
install -Dm755 ./bundles/dynbinary-daemon/docker-proxy $out/libexec/docker/docker-proxy
makeWrapper $out/libexec/docker/dockerd $out/bin/dockerd \
--prefix PATH : "$out/libexec/docker:$extraPath"
--prefix PATH : "$out/libexec/docker${
lib.optionalString (extraMobyPath != "") ":${extraMobyPath}"
}"
ln -s ${docker-containerd}/bin/containerd $out/libexec/docker/containerd
ln -s ${docker-containerd}/bin/containerd-shim${lib.optionalString (lib.versionAtLeast version "29.0.0") "-runc-v2"} $out/libexec/docker/containerd-shim${lib.optionalString (lib.versionAtLeast version "29.0.0") "-runc-v2"}
@@ -233,7 +235,9 @@ let
# rootless Docker
install -Dm755 ./contrib/dockerd-rootless.sh $out/libexec/docker/dockerd-rootless.sh
makeWrapper $out/libexec/docker/dockerd-rootless.sh $out/bin/dockerd-rootless \
--prefix PATH : "$out/libexec/docker:$extraPath:$extraUserPath"
--prefix PATH : "$out/libexec/docker${
lib.optionalString (extraMobyPath != "") ":${extraMobyPath}"
}${lib.optionalString (extraMobyUserPath != "") ":${extraMobyUserPath}"}"
runHook postInstall
'';
@@ -335,7 +339,7 @@ let
install -Dm755 ./build/docker $out/libexec/docker/docker
makeWrapper $out/libexec/docker/docker $out/bin/docker \
--prefix PATH : "$out/libexec/docker:$extraPath" \
--prefix PATH : "$out/libexec/docker" \
--prefix DOCKER_CLI_PLUGIN_DIRS : "${dockerCliPluginsDirs}"
''
+ lib.optionalString (!clientOnly) ''

View File

@@ -8,13 +8,13 @@
}:
mkHyprlandPlugin (finalAttrs: {
pluginName = "hy3";
version = "0.55.0";
version = "0.56.0.1";
src = fetchFromGitHub {
owner = "outfoxxed";
repo = "hy3";
tag = "hl${finalAttrs.version}";
hash = "sha256-P3wwiIfqo89evW7xzI+wOI/qM1WPZBiiSmGNtBmYeVk=";
hash = "sha256-iK0vERuy5aXisDXm/bzcJP0dgaIot5MLPoVG62DjqO4=";
};
nativeBuildInputs = [ cmake ];

View File

@@ -7,13 +7,13 @@
mkHyprlandPlugin (finalAttrs: {
pluginName = "hypr-darkwindow";
version = "0.55.4";
version = "0.56.0";
src = fetchFromGitHub {
owner = "micha4w";
repo = "Hypr-DarkWindow";
tag = "v${finalAttrs.version}";
hash = "sha256-91l5TD46OMfvmhd1WqWxm42cEnjR1yAj2Qk/73mr3ks=";
hash = "sha256-2upGTy7IRhrhxf+5VPjzrua8ebOtED6i8kSN8ka+ffg=";
};
installPhase = ''

View File

@@ -8,16 +8,18 @@
pv,
squashfsTools,
buildFHSEnv,
pkgs,
replaceVarsWith,
runtimeShell,
runCommand,
}:
rec {
appimage-exec = pkgs.replaceVarsWith {
appimage-exec = replaceVarsWith {
src = ./appimage-exec.sh;
isExecutable = true;
dir = "bin";
replacements = {
inherit (pkgs) runtimeShell;
inherit runtimeShell;
path = lib.makeBinPath [
bash
binutils-unwrapped
@@ -42,7 +44,7 @@ rec {
assert
name == null
|| throw "The `name` argument is deprecated. Use `pname` and `version` instead to construct the name.";
pkgs.runCommand "${pname}-${version}-extracted"
runCommand "${pname}-${version}-extracted"
{
nativeBuildInputs = [ appimage-exec ];
strictDeps = true;
@@ -57,60 +59,55 @@ rec {
extractType2 = extract;
wrapType1 = wrapType2;
wrapAppImage =
args@{
src,
extraPkgs ? pkgs: [ ],
meta ? { },
...
}:
buildFHSEnv (
wrapAppImage = lib.extendMkDerivation {
constructDrv = buildFHSEnv;
excludeDrvArgNames = [ "extraPkgs" ];
extendDrvArgs =
finalAttrs:
prev@{
contents ? prev.src,
extraPkgs ? pkgs: [ ],
meta ? { },
...
}:
defaultFhsEnvArgs
// {
targetPkgs = pkgs: [ appimage-exec ] ++ defaultFhsEnvArgs.targetPkgs pkgs ++ extraPkgs pkgs;
runScript = "appimage-exec.sh -w ${src} --";
runScript = "appimage-exec.sh -w ${finalAttrs.contents or prev.src} --";
meta = {
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
}
// meta;
}
// (removeAttrs args (builtins.attrNames (builtins.functionArgs wrapAppImage)))
);
};
};
wrapType2 =
args@{
src,
extraPkgs ? pkgs: [ ],
...
}:
wrapAppImage (
args
// {
inherit extraPkgs;
src = extract (
lib.filterAttrs (
key: value:
builtins.elem key [
"pname"
"version"
"src"
]
) args
);
# passthru src to make nix-update work
# hack to keep the origin position (unsafeGetAttrPos)
passthru =
lib.pipe args [
lib.attrNames
(lib.remove "src")
(removeAttrs args)
wrapType2 = lib.extendMkDerivation {
constructDrv = wrapAppImage;
extendDrvArgs = finalAttrs: args: {
contents = extract (
lib.filterAttrs (
key: value:
builtins.elem key [
"pname"
"version"
"src"
]
// args.passthru or { };
}
);
) finalAttrs
);
# passthru src to make nix-update work
# hack to keep the origin position (unsafeGetAttrPos)
passthru =
lib.pipe finalAttrs [
lib.attrNames
(lib.remove "src")
(removeAttrs finalAttrs)
]
// args.passthru or { };
};
};
defaultFhsEnvArgs = {
# Most of the packages were taken from the Steam chroot

View File

@@ -1,6 +1,7 @@
{
lib,
stdenv,
stdenvNoCC,
callPackage,
runCommandLocal,
writeShellScript,
@@ -11,30 +12,6 @@
bubblewrap,
}:
{
pname ? throw "You must provide either `name` or `pname`",
version ? throw "You must provide either `name` or `version`",
name ? "${pname}-${version}",
runScript ? "bash",
nativeBuildInputs ? [ ],
extraInstallCommands ? "",
executableName ? args.pname or name,
meta ? { },
passthru ? { },
extraPreBwrapCmds ? "",
extraBwrapArgs ? [ ],
unshareUser ? false,
unshareIpc ? false,
unsharePid ? false,
unshareNet ? false,
unshareUts ? false,
unshareCgroup ? false,
privateTmp ? false,
chdirToPwd ? true,
dieWithParent ? true,
...
}@args:
# NOTE:
# `pname` and `version` will throw if they were not provided.
# Use `name` instead of directly evaluating `pname` or `version`.
@@ -42,338 +19,358 @@
# If you need `pname` or `version` specifically, use `args` instead:
# e.g. `args.pname or ...`.
let
inherit (lib)
concatLines
concatStringsSep
escapeShellArgs
filter
optionalString
splitString
;
inherit (lib.attrsets) removeAttrs;
# The splicing code does not handle `pkgsi686Linux` well, so we have to be
# explicit about which package set it's coming from.
inherit (pkgsHostTarget) pkgsi686Linux;
# we don't know which have been supplied, and want to avoid defaulting missing attrs to null. Passed into runCommandLocal
nameAttrs = lib.filterAttrs (
key: value:
builtins.elem key [
"name"
"pname"
"version"
]
) args;
buildFHSEnv = callPackage ./buildFHSEnv.nix { };
fhsenv = buildFHSEnv (
removeAttrs args [
lib.makeOverridable (
lib.extendMkDerivation {
constructDrv = stdenvNoCC.mkDerivation;
excludeDrvArgNames = [
"multiPkgs"
"targetPkgs"
"runScript"
"extraInstallCommands"
"meta"
"passthru"
"extraPreBwrapCmds"
"extraBwrapArgs"
"dieWithParent"
"unshareUser"
"unshareCgroup"
"unshareUts"
"unshareNet"
"unsharePid"
"unshareIpc"
"privateTmp"
]
);
etcBindEntries =
let
files = [
# NixOS Compatibility
"static"
"nix" # mainly for nixVersions.git users, but also for access to nix/netrc
# Shells
"shells"
"bashrc"
"zshenv"
"zshrc"
"zinputrc"
"zprofile"
# Users, Groups, NSS
"passwd"
"group"
"shadow"
"hosts"
"resolv.conf"
"nsswitch.conf"
# User profiles
"profiles"
# Sudo & Su
"login.defs"
"sudoers"
"sudoers.d"
# Time
"localtime"
"zoneinfo"
# Other Core Stuff
"machine-id"
"os-release"
# PAM
"pam.d"
# Fonts
"fonts"
# ALSA
"alsa"
"asound.conf"
# SSL
"ssl/certs"
"ca-certificates"
"pki"
# Custom dconf profiles
"dconf"
];
in
map (path: "/etc/${path}") files;
# Here's the problem case:
# - we need to run bash to run the init script
# - LD_PRELOAD may be set to another dynamic library, requiring us to discover its dependencies
# - oops! ldconfig is part of the init script, and it hasn't run yet
# - everything explodes
#
# In particular, this happens with fhsenvs in fhsenvs, e.g. when running
# a wrapped game from Steam.
#
# So, instead of doing that, we build a tiny static (important!) shim
# that executes ldconfig in a completely clean environment to generate
# the initial cache, and then execs into the "real" init, which is the
# first time we see anything dynamically linked at all.
#
# Also, the real init is placed strategically at /init, so we don't
# have to recompile this every time.
containerInit =
runCommandCC "container-init"
];
extendDrvArgs =
finalAttrs:
{
buildInputs = [ stdenv.cc.libc.static or null ];
}
''
$CXX -static -s -o $out ${./container-init.cc}
'';
pname ? throw "You must provide either `name` or `pname`",
version ? throw "You must provide either `name` or `version`",
name ? "${pname}-${version}",
runScript ? "bash",
executableName ? args.pname or name,
meta ? { },
passthru ? { },
unshareUser ? false,
unshareIpc ? false,
unsharePid ? false,
unshareNet ? false,
unshareUts ? false,
unshareCgroup ? false,
privateTmp ? false,
chdirToPwd ? true,
dieWithParent ? true,
...
}@args:
let
inherit (lib)
concatLines
concatStringsSep
escapeShellArgs
filter
optionalString
splitString
removeAttrs
;
realInit =
run:
writeShellScript "${name}-init" ''
source /etc/profile
exec ${run} "$@"
'';
# The splicing code does not handle `pkgsi686Linux` well, so we have to be
# explicit about which package set it's coming from.
inherit (pkgsHostTarget) pkgsi686Linux;
indentLines = str: concatLines (map (s: " " + s) (filter (s: s != "") (splitString "\n" str)));
bwrapCmd =
{
initArgs ? "",
}:
''
ignored=(/nix /dev /proc /etc ${optionalString privateTmp "/tmp"})
ro_mounts=()
symlinks=()
etc_ignored=()
buildFHSEnv = callPackage ./buildFHSEnv.nix { };
${extraPreBwrapCmds}
fhsenv = buildFHSEnv (
removeAttrs args [
"runScript"
"extraInstallCommands"
"meta"
"passthru"
"extraPreBwrapCmds"
"extraBwrapArgs"
"dieWithParent"
"unshareUser"
"unshareCgroup"
"unshareUts"
"unshareNet"
"unsharePid"
"unshareIpc"
"privateTmp"
]
);
# loop through all entries of root in the fhs environment, except its /etc.
for i in ${fhsenv}/*; do
path="/''${i##*/}"
if [[ $path == '/etc' ]]; then
:
elif [[ -L $i ]]; then
symlinks+=(--symlink "$(${coreutils}/bin/readlink "$i")" "$path")
ignored+=("$path")
else
ro_mounts+=(--ro-bind "$i" "$path")
ignored+=("$path")
fi
done
etcBindEntries =
let
files = [
# NixOS Compatibility
"static"
"nix" # mainly for nixVersions.git users, but also for access to nix/netrc
# Shells
"shells"
"bashrc"
"zshenv"
"zshrc"
"zinputrc"
"zprofile"
# Users, Groups, NSS
"passwd"
"group"
"shadow"
"hosts"
"resolv.conf"
"nsswitch.conf"
# User profiles
"profiles"
# Sudo & Su
"login.defs"
"sudoers"
"sudoers.d"
# Time
"localtime"
"zoneinfo"
# Other Core Stuff
"machine-id"
"os-release"
# PAM
"pam.d"
# Fonts
"fonts"
# ALSA
"alsa"
"asound.conf"
# SSL
"ssl/certs"
"ca-certificates"
"pki"
# Custom dconf profiles
"dconf"
];
in
map (path: "/etc/${path}") files;
# loop through the entries of /etc in the fhs environment.
if [[ -d ${fhsenv}/etc ]]; then
for i in ${fhsenv}/etc/*; do
path="/''${i##*/}"
# NOTE: we're binding /etc/fonts and /etc/ssl/certs from the host so we
# don't want to override it with a path from the FHS environment.
if [[ $path == '/fonts' || $path == '/ssl' ]]; then
continue
fi
if [[ -L $i ]]; then
symlinks+=(--symlink "$i" "/etc$path")
else
ro_mounts+=(--ro-bind "$i" "/etc$path")
fi
etc_ignored+=("/etc$path")
done
fi
# propagate /etc from the actual host if nested
if [[ -e /.host-etc ]]; then
ro_mounts+=(--ro-bind /.host-etc /.host-etc)
else
ro_mounts+=(--ro-bind /etc /.host-etc)
fi
declare -A etc_ignored_set
for ign in "''${etc_ignored[@]}"; do
etc_ignored_set[$ign]=1
done
# link selected etc entries from the actual root
for i in ${escapeShellArgs etcBindEntries}; do
if [[ -n "''${etc_ignored_set[$i]:-}" ]]; then
continue
fi
if [[ -e $i ]]; then
symlinks+=(--symlink "/.host-etc/''${i#/etc/}" "$i")
fi
done
declare -A ignored_set
for ign in "''${ignored[@]}"; do
ignored_set[$ign]=1
done
declare -a auto_mounts
# loop through all directories in the root
for dir in /*; do
# if it is a directory and not already provided by the FHS env or
# explicitly ignored, bind-mount it into the chroot. Use exact match
# via associative array because regex substring matching incorrectly
# skips prefixes (e.g. /sb would match /sbin and never get mounted,
# breaking --chdir when CWD is on a custom mount like /sb/project).
# https://github.com/NixOS/nixpkgs/issues/241151
if [[ -d "$dir" ]] && [[ -z "''${ignored_set[$dir]:-}" ]]; then
# add it to the mount list
auto_mounts+=(--bind "$dir" "$dir")
fi
done
declare -a x11_args
# Always mount a tmpfs on /tmp/.X11-unix
# Rationale: https://github.com/flatpak/flatpak/blob/be2de97e862e5ca223da40a895e54e7bf24dbfb9/common/flatpak-run.c#L277
x11_args+=(--tmpfs /tmp/.X11-unix)
# Try to guess X socket path. This doesn't cover _everything_, but it covers some things.
if [[ "$DISPLAY" == *:* ]]; then
# recover display number from $DISPLAY formatted [host]:num[.screen]
display_nr=''${DISPLAY/#*:} # strip host
display_nr=''${display_nr/%.*} # strip screen
local_socket=/tmp/.X11-unix/X$display_nr
x11_args+=(--ro-bind-try "$local_socket" "$local_socket")
fi
${optionalString privateTmp ''
# sddm places XAUTHORITY in /tmp
if [[ "$XAUTHORITY" == /tmp/* ]]; then
x11_args+=(--ro-bind-try "$XAUTHORITY" "$XAUTHORITY")
fi
# dbus-run-session puts the socket in /tmp
IFS=";" read -ra addrs <<<"$DBUS_SESSION_BUS_ADDRESS"
for addr in "''${addrs[@]}"; do
[[ "$addr" == unix:* ]] || continue
IFS="," read -ra parts <<<"''${addr#unix:}"
for part in "''${parts[@]}"; do
printf -v part '%s' "''${part//\\/\\\\}"
printf -v part '%b' "''${part//%/\\x}"
[[ "$part" == path=/tmp/* ]] || continue
x11_args+=(--ro-bind-try "''${part#path=}" "''${part#path=}")
done
done
''}
cmd=(
${bubblewrap}/bin/bwrap
--dev-bind /dev /dev
--proc /proc
${optionalString chdirToPwd ''--chdir "$(pwd)"''}
${optionalString unshareUser "--unshare-user"}
${optionalString unshareIpc "--unshare-ipc"}
${optionalString unsharePid "--unshare-pid"}
${optionalString unshareNet "--unshare-net"}
${optionalString unshareUts "--unshare-uts"}
${optionalString unshareCgroup "--unshare-cgroup"}
${optionalString dieWithParent "--die-with-parent"}
--bind /nix /nix
${optionalString privateTmp "--tmpfs /tmp"}
# Our glibc will look for the cache in its own path in `/nix/store`.
# As such, we need a cache to exist there, because pressure-vessel
# depends on the existence of an ld cache. However, adding one
# globally proved to be a bad idea (see #100655), the solution we
# settled on being mounting one via bwrap.
# Also, the cache needs to go to both 32 and 64 bit glibcs, for games
# of both architectures to work.
--tmpfs ${glibc}/etc \
--tmpfs /etc \
--symlink /etc/ld.so.conf ${glibc}/etc/ld.so.conf \
--symlink /etc/ld.so.cache ${glibc}/etc/ld.so.cache \
--ro-bind ${glibc}/etc/rpc ${glibc}/etc/rpc \
--remount-ro ${glibc}/etc \
--symlink ${realInit runScript} /init \
''
+ optionalString fhsenv.isMultiBuild (indentLines ''
--tmpfs ${pkgsi686Linux.glibc}/etc \
--symlink /etc/ld.so.conf ${pkgsi686Linux.glibc}/etc/ld.so.conf \
--symlink /etc/ld.so.cache ${pkgsi686Linux.glibc}/etc/ld.so.cache \
--ro-bind ${pkgsi686Linux.glibc}/etc/rpc ${pkgsi686Linux.glibc}/etc/rpc \
--remount-ro ${pkgsi686Linux.glibc}/etc \
'')
+ ''
"''${ro_mounts[@]}"
"''${symlinks[@]}"
"''${auto_mounts[@]}"
"''${x11_args[@]}"
${concatStringsSep "\n " extraBwrapArgs}
${containerInit} ${initArgs}
)
exec "''${cmd[@]}"
'';
bin = writeShellScript "${name}-bwrap" (bwrapCmd {
initArgs = ''"$@"'';
});
in
runCommandLocal name
(
nameAttrs
// {
inherit nativeBuildInputs;
__structuredAttrs = true;
passthru = passthru // {
env =
runCommandLocal "${name}-shell-env"
# Here's the problem case:
# - we need to run bash to run the init script
# - LD_PRELOAD may be set to another dynamic library, requiring us to discover its dependencies
# - oops! ldconfig is part of the init script, and it hasn't run yet
# - everything explodes
#
# In particular, this happens with fhsenvs in fhsenvs, e.g. when running
# a wrapped game from Steam.
#
# So, instead of doing that, we build a tiny static (important!) shim
# that executes ldconfig in a completely clean environment to generate
# the initial cache, and then execs into the "real" init, which is the
# first time we see anything dynamically linked at all.
#
# Also, the real init is placed strategically at /init, so we don't
# have to recompile this every time.
containerInit =
runCommandCC "container-init"
{
shellHook = bwrapCmd { };
buildInputs = [ stdenv.cc.libc.static or null ];
}
''
echo >&2 ""
echo >&2 "*** User chroot 'env' attributes are intended for interactive nix-shell sessions, not for building! ***"
echo >&2 ""
exit 1
$CXX -static -s -o $out ${./container-init.cc}
'';
inherit args fhsenv;
realInit =
run:
writeShellScript "${name}-init" ''
source /etc/profile
exec ${run} "$@"
'';
indentLines = str: concatLines (map (s: " " + s) (filter (s: s != "") (splitString "\n" str)));
bwrapCmd =
{
initArgs ? "",
}:
''
ignored=(/nix /dev /proc /etc ${optionalString privateTmp "/tmp"})
ro_mounts=()
symlinks=()
etc_ignored=()
${finalAttrs.extraPreBwrapCmds or ""}
# loop through all entries of root in the fhs environment, except its /etc.
for i in ${fhsenv}/*; do
path="/''${i##*/}"
if [[ $path == '/etc' ]]; then
:
elif [[ -L $i ]]; then
symlinks+=(--symlink "$(${coreutils}/bin/readlink "$i")" "$path")
ignored+=("$path")
else
ro_mounts+=(--ro-bind "$i" "$path")
ignored+=("$path")
fi
done
# loop through the entries of /etc in the fhs environment.
if [[ -d ${fhsenv}/etc ]]; then
for i in ${fhsenv}/etc/*; do
path="/''${i##*/}"
# NOTE: we're binding /etc/fonts and /etc/ssl/certs from the host so we
# don't want to override it with a path from the FHS environment.
if [[ $path == '/fonts' || $path == '/ssl' ]]; then
continue
fi
if [[ -L $i ]]; then
symlinks+=(--symlink "$i" "/etc$path")
else
ro_mounts+=(--ro-bind "$i" "/etc$path")
fi
etc_ignored+=("/etc$path")
done
fi
# propagate /etc from the actual host if nested
if [[ -e /.host-etc ]]; then
ro_mounts+=(--ro-bind /.host-etc /.host-etc)
else
ro_mounts+=(--ro-bind /etc /.host-etc)
fi
declare -A etc_ignored_set
for ign in "''${etc_ignored[@]}"; do
etc_ignored_set[$ign]=1
done
# link selected etc entries from the actual root
for i in ${escapeShellArgs etcBindEntries}; do
if [[ -n "''${etc_ignored_set[$i]:-}" ]]; then
continue
fi
if [[ -e $i ]]; then
symlinks+=(--symlink "/.host-etc/''${i#/etc/}" "$i")
fi
done
declare -A ignored_set
for ign in "''${ignored[@]}"; do
ignored_set[$ign]=1
done
declare -a auto_mounts
# loop through all directories in the root
for dir in /*; do
# if it is a directory and not already provided by the FHS env or
# explicitly ignored, bind-mount it into the chroot. Use exact match
# via associative array because regex substring matching incorrectly
# skips prefixes (e.g. /sb would match /sbin and never get mounted,
# breaking --chdir when CWD is on a custom mount like /sb/project).
# https://github.com/NixOS/nixpkgs/issues/241151
if [[ -d "$dir" ]] && [[ -z "''${ignored_set[$dir]:-}" ]]; then
# add it to the mount list
auto_mounts+=(--bind "$dir" "$dir")
fi
done
declare -a x11_args
# Always mount a tmpfs on /tmp/.X11-unix
# Rationale: https://github.com/flatpak/flatpak/blob/be2de97e862e5ca223da40a895e54e7bf24dbfb9/common/flatpak-run.c#L277
x11_args+=(--tmpfs /tmp/.X11-unix)
# Try to guess X socket path. This doesn't cover _everything_, but it covers some things.
if [[ "$DISPLAY" == *:* ]]; then
# recover display number from $DISPLAY formatted [host]:num[.screen]
display_nr=''${DISPLAY/#*:} # strip host
display_nr=''${display_nr/%.*} # strip screen
local_socket=/tmp/.X11-unix/X$display_nr
x11_args+=(--ro-bind-try "$local_socket" "$local_socket")
fi
${optionalString privateTmp ''
# sddm places XAUTHORITY in /tmp
if [[ "$XAUTHORITY" == /tmp/* ]]; then
x11_args+=(--ro-bind-try "$XAUTHORITY" "$XAUTHORITY")
fi
# dbus-run-session puts the socket in /tmp
IFS=";" read -ra addrs <<<"$DBUS_SESSION_BUS_ADDRESS"
for addr in "''${addrs[@]}"; do
[[ "$addr" == unix:* ]] || continue
IFS="," read -ra parts <<<"''${addr#unix:}"
for part in "''${parts[@]}"; do
printf -v part '%s' "''${part//\\/\\\\}"
printf -v part '%b' "''${part//%/\\x}"
[[ "$part" == path=/tmp/* ]] || continue
x11_args+=(--ro-bind-try "''${part#path=}" "''${part#path=}")
done
done
''}
cmd=(
${bubblewrap}/bin/bwrap
--dev-bind /dev /dev
--proc /proc
${optionalString chdirToPwd ''--chdir "$(pwd)"''}
${optionalString unshareUser "--unshare-user"}
${optionalString unshareIpc "--unshare-ipc"}
${optionalString unsharePid "--unshare-pid"}
${optionalString unshareNet "--unshare-net"}
${optionalString unshareUts "--unshare-uts"}
${optionalString unshareCgroup "--unshare-cgroup"}
${optionalString dieWithParent "--die-with-parent"}
--bind /nix /nix
${optionalString privateTmp "--tmpfs /tmp"}
# Our glibc will look for the cache in its own path in `/nix/store`.
# As such, we need a cache to exist there, because pressure-vessel
# depends on the existence of an ld cache. However, adding one
# globally proved to be a bad idea (see #100655), the solution we
# settled on being mounting one via bwrap.
# Also, the cache needs to go to both 32 and 64 bit glibcs, for games
# of both architectures to work.
--tmpfs ${glibc}/etc \
--tmpfs /etc \
--symlink /etc/ld.so.conf ${glibc}/etc/ld.so.conf \
--symlink /etc/ld.so.cache ${glibc}/etc/ld.so.cache \
--ro-bind ${glibc}/etc/rpc ${glibc}/etc/rpc \
--remount-ro ${glibc}/etc \
--symlink ${realInit runScript} /init \
''
+ optionalString fhsenv.isMultiBuild (indentLines ''
--tmpfs ${pkgsi686Linux.glibc}/etc \
--symlink /etc/ld.so.conf ${pkgsi686Linux.glibc}/etc/ld.so.conf \
--symlink /etc/ld.so.cache ${pkgsi686Linux.glibc}/etc/ld.so.cache \
--ro-bind ${pkgsi686Linux.glibc}/etc/rpc ${pkgsi686Linux.glibc}/etc/rpc \
--remount-ro ${pkgsi686Linux.glibc}/etc \
'')
+ ''
"''${ro_mounts[@]}"
"''${symlinks[@]}"
"''${auto_mounts[@]}"
"''${x11_args[@]}"
${concatStringsSep "\n " (finalAttrs.extraBwrapArgs or [ ])}
${containerInit} ${initArgs}
)
exec "''${cmd[@]}"
'';
bin = writeShellScript "${name}-bwrap" (bwrapCmd {
initArgs = ''"$@"'';
});
in
{
buildCommand = ''
mkdir -p $out/bin
ln -s ${bin} $out/bin/${executableName}
${finalAttrs.extraInstallCommands or ""}
'';
__structuredAttrs = true;
strictDeps = true;
enableParallelBuilding = true;
preferLocalBuild = true;
allowSubstitutes = false;
passthru = passthru // {
env =
runCommandLocal "${name}-shell-env"
{
shellHook = bwrapCmd { };
}
''
echo >&2 ""
echo >&2 "*** User chroot 'env' attributes are intended for interactive nix-shell sessions, not for building! ***"
echo >&2 ""
exit 1
'';
inherit args fhsenv;
};
meta = {
mainProgram = executableName;
}
// meta;
};
meta = {
mainProgram = executableName;
}
// meta;
}
)
''
mkdir -p $out/bin
ln -s ${bin} $out/bin/${executableName}
${extraInstallCommands}
''
}
)

View File

@@ -29,10 +29,6 @@ let
services = {
svc = {
process.argv = [ "${coreutils}/bin/true" ];
process.environment = {
FOO = "bar";
DROPPED = null;
};
assertions = [
{
assertion = true;
@@ -74,19 +70,6 @@ let
expected = [ "${coreutils}/bin/true" ];
};
# A set environment variable round-trips through process.environment.
testProcessEnvironment = {
expr = c.process.environment.FOO;
expected = "bar";
};
# A null environment variable is preserved as null (unset request),
# rather than coerced to a string or dropped from the attrset.
testProcessEnvironmentNull = {
expr = c.process.environment.DROPPED;
expected = null;
};
testAssertions = {
expr = lib.elem {
assertion = true;
@@ -203,9 +186,6 @@ let
mkdir -p "$dir"
echo "$$" > "$dir/pid"
printf '%s\n' "$@" > "$dir/args"
# Record the process's own environment as received from the service
# manager (NUL-delimited, as the kernel stores it).
"${coreutils}/bin/cat" "/proc/$$/environ" > "$dir/environ"
exec "${coreutils}/bin/sleep" infinity
'';
@@ -258,31 +238,6 @@ let
|| { echo "${id}: expected arg ${lib.escapeShellArg arg} not found"; cat "${sharedDir}/${id}/args"; exit 1; }
'') expectedArgs;
/**
Shell snippet: assert that the service's recorded environment contains
each `present` entry (an exact `KEY=value` string) and contains no
variable named in `absent`.
*/
checkEnv =
id:
{
present ? [ ],
absent ? [ ],
}:
''
# The recorded environ is NUL-delimited; render one entry per line.
tr '\0' '\n' < "${sharedDir}/${id}/environ" > "${sharedDir}/${id}/environ.lines"
''
+ lib.concatMapStrings (entry: ''
grep -qxF -- ${lib.escapeShellArg entry} "${sharedDir}/${id}/environ.lines" \
|| { echo "${id}: expected env ${lib.escapeShellArg entry} not found"; cat "${sharedDir}/${id}/environ.lines"; exit 1; }
'') present
+ lib.concatMapStrings (key: ''
if grep -qE ${lib.escapeShellArg "^${key}="} "${sharedDir}/${id}/environ.lines"; then
echo "${id}: env variable ${lib.escapeShellArg key} should be unset"; exit 1
fi
'') absent;
mkTestScript =
name: text:
lib.getExe (writeShellApplication {
@@ -375,24 +330,6 @@ in
);
};
environment = mkTest {
name = "${namePrefix}-environment";
services.test = {
process.argv = mkArgv "env" [ ];
process.environment = {
FOO = "bar";
DROPPED = null;
};
};
testExe = mkTestScript "environment" (
waitAndCheck "env" [ ]
+ checkEnv "env" {
present = [ "FOO=bar" ];
absent = [ "DROPPED" ];
}
);
};
sub-services = mkTest {
name = "${namePrefix}-sub-services";
services.a = {

View File

@@ -15,12 +15,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "algol68g";
version = "3.12.2";
version = "3.12.3";
src = fetchurl {
# Uses archive.org because the original site removes older versions.
url = "https://web.archive.org/web/20260515052918/https://algol68genie.nl/algol68g-3.12.2.tar.gz";
hash = "sha256-4fiubqpgoH3YOlCg1bJHQ3kOayKNulW3CYbOK1awE7k";
url = "https://algol68genie.nl/algol68g-${finalAttrs.version}.tar.gz";
hash = "sha256-TS5m+Byi+5j4jiOuQbR159QERfNJsQiGNngtoyC9IrE=";
};
outputs = [
@@ -48,8 +47,8 @@ stdenv.mkDerivation (finalAttrs: {
postInstall =
let
pdfdoc = fetchurl {
url = "https://web.archive.org/web/20260503174213/https://algol68genie.nl/learning-algol-68-genie.pdf";
hash = "sha256-eLMRf3XcAkr/Dmk7ieRe62x76VcCj+2QltHH7YtL15s=";
url = "https://algol68genie.nl/learning-algol-68-genie.pdf";
hash = "sha256-BrVjYXd5sknV0+UCRgQMf0H3QMzMQcLhytEEuiTGkLE=";
};
in
lib.optionalString withPDFDoc ''

View File

@@ -12,16 +12,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "alistral";
version = "0.6.7";
version = "0.6.8";
src = fetchFromGitHub {
owner = "RustyNova016";
repo = "Alistral";
tag = "v${finalAttrs.version}";
hash = "sha256-XsN4UyIXkd0YVtO/q9EcFP/sBYkH9leISmbJZ93ef6E=";
hash = "sha256-NDWQl2Gq4Q0OMMCrHQhybInaJRjY3Fxe3GXrGb32MMY=";
};
cargoHash = "sha256-KFNFioZ/5moC5FNXw+hA+NrPjsqu+3V8A5mtZ4FZUHw=";
cargoHash = "sha256-QxTmjtntp5zy7UijRn0hF3DyOOl3dIpZjPSASCuHaEk=";
buildNoDefaultFeatures = true;
# Would be cleaner with an "--all-features" option

View File

@@ -9,7 +9,6 @@
let
opencv4WithGtk = python3Packages.opencv4.override {
enableGtk2 = true; # For GTK2 support
enableGtk3 = true; # For GTK3 support
};
in

View File

@@ -6,7 +6,7 @@
rustPlatform.buildRustPackage {
pname = "as-tree";
version = "unstable-2021-03-09";
version = "0.12.0-unstable-2021-03-09";
src = fetchFromGitHub {
owner = "jez";

View File

@@ -12,16 +12,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "aube";
version = "1.29.1";
version = "1.32.0";
src = fetchFromGitHub {
owner = "jdx";
repo = "aube";
tag = "v${finalAttrs.version}";
hash = "sha256-87r9qltKUhjnYG9O484OUzKFiO8Xoge9VZ13l6RgrdA=";
hash = "sha256-0BnaxRk6+KY4AGZ31lis0zxc9uWp3OrxCgp9SgOrqNI=";
};
cargoHash = "sha256-Cy5Ea/rF2IJ5WppKKI7E1toy9N+bQEArVW9o2pHzBMc=";
cargoHash = "sha256-vYbbnEpVWG6kjnycl1kk3D+lXuzTzOKuilA0ImBHYAI=";
nativeBuildInputs = [ cmake ]; # libz-ng-sys
@@ -36,6 +36,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
checkFlags = [
# failed on x86_64-linux
"--skip=concurrency::tests::floor_and_ceiling_inclusive"
"--skip=http::ticket_cache::tests::max_per_host_evicts_oldest"
"--skip=http::ticket_cache::tests::invalidate_removes_all_for_host"
# require network access

View File

@@ -7,16 +7,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "automatic-timezoned";
version = "2.0.143";
version = "2.0.149";
src = fetchFromGitHub {
owner = "maxbrunet";
repo = "automatic-timezoned";
rev = "v${finalAttrs.version}";
sha256 = "sha256-bbdhvQ9THiBRf1rLExXQiwlrkgZBFZlaV2CUszDmwo4=";
sha256 = "sha256-FQ4SJcHkdNJcZOncY0BHg+CwnUcyszzfYPCUhWZHhi0=";
};
cargoHash = "sha256-J7h1hVp8wK6UlkstcLCq4uMKJ9ZyLwGR75tcxpWnHT8=";
cargoHash = "sha256-4+gNtQrlaDrSCUFEIByFUQnITSkF9Mo9bq6Ug9d7t1w=";
nativeInstallCheckInputs = [ versionCheckHook ];

View File

@@ -0,0 +1,82 @@
{
lib,
stdenv,
fetchzip,
autoPatchelfHook,
azure-cli,
makeWrapper,
}:
let
version = "3.0.0-beta.10";
srcs = {
x86_64-linux = {
url = "https://github.com/microsoft/mcp/releases/download/Azure.Mcp.Server-${version}/Azure.Mcp.Server-linux-x64-native.zip";
hash = "sha256-2wrpyTVunT54dYD1ascVDRTW2AN5NpoV+q3UUt5dQSg=";
};
aarch64-linux = {
url = "https://github.com/microsoft/mcp/releases/download/Azure.Mcp.Server-${version}/Azure.Mcp.Server-linux-arm64.zip";
hash = "sha256-K1QRpj5/RzZx2mrmtnB5lGX9CoaAC+pRVGqqHtXWncY=";
};
x86_64-darwin = {
url = "https://github.com/microsoft/mcp/releases/download/Azure.Mcp.Server-${version}/Azure.Mcp.Server-osx-x64.zip";
hash = "sha256-ebT6sipbA7IdGx98kF/8GLpHL1fVSVqnmL4rEwsa43k=";
};
aarch64-darwin = {
url = "https://github.com/microsoft/mcp/releases/download/Azure.Mcp.Server-${version}/Azure.Mcp.Server-osx-arm64.zip";
hash = "sha256-33rg+fnIB/VJZbVKTP7b8829BbcDnfnaYFMOyPLFzEw=";
};
};
unavailable = throw "azure-mcp package is not available for this platform.";
src = fetchzip {
inherit (srcs.${stdenv.hostPlatform.system} or unavailable) url hash;
stripRoot = false;
};
in
stdenv.mkDerivation {
pname = "azure-mcp";
inherit version src;
strictDeps = true;
__structuredAttrs = true;
nativeBuildInputs = [
makeWrapper
]
++ lib.optionals stdenv.hostPlatform.isLinux [ autoPatchelfHook ];
buildInputs = lib.optionals stdenv.hostPlatform.isLinux [
stdenv.cc.cc.lib
];
dontConfigure = true;
dontBuild = true;
installPhase = ''
runHook preInstall
install -Dm755 ./azmcp $out/bin/azure-mcp
wrapProgram $out/bin/azure-mcp \
--prefix PATH : ${lib.makeBinPath [ azure-cli ]}
runHook postInstall
'';
meta = {
description = "Model Context Protocol server for Azure services";
longDescription = ''
The Azure MCP Server implements the Model Context Protocol (MCP)
specification to create a seamless connection between AI agents and
Azure services. It provides 321+ tools for interacting with Azure
resources including storage, compute, databases, and more.
'';
homepage = "https://github.com/microsoft/mcp";
changelog = "https://github.com/microsoft/mcp/blob/Azure.Mcp.Server-${version}/servers/Azure.Mcp.Server/CHANGELOG.md";
license = lib.licenses.mit;
sourceProvenance = [ lib.sourceTypes.binaryNativeCode ];
platforms = lib.attrNames srcs;
mainProgram = "azure-mcp";
maintainers = with lib.maintainers; [ sheeeng ];
};
}

View File

@@ -2,6 +2,7 @@
lib,
python3Packages,
fetchPypi,
fetchgit,
patatt,
}:
@@ -31,6 +32,15 @@ python3Packages.buildPythonApplication (finalAttrs: {
textual
];
passthru = {
src-misc = fetchgit {
url = "https://git.kernel.org/pub/scm/utils/b4/b4.git";
rev = "v${finalAttrs.version}";
hash = "sha256-NjYL3RKQpjDkU98qbXyl/cvLTJYVAfIowm8E2Rg8AgI=";
fetchSubmodules = false;
};
};
meta = {
homepage = "https://git.kernel.org/pub/scm/utils/b4/b4.git/about";
license = lib.licenses.gpl2Only;

View File

@@ -20,13 +20,13 @@ let
in
buildBazelPackage rec {
pname = "bant";
version = "0.3.0";
version = "0.3.3";
src = fetchFromGitHub {
owner = "hzeller";
repo = "bant";
rev = "v${version}";
hash = "sha256-T/BQRYCFAHkaGi5T485I9vbr3g7PzgIEHC27w6mg/3A=";
hash = "sha256-6c403+DK1tcQxC16FKEtdhnJEA9LJl8H8Usnw08FBnA=";
};
bazelFlags = [

View File

@@ -6,16 +6,16 @@
buildGoModule (finalAttrs: {
pname = "bazel-remote";
version = "2.6.1";
version = "2.6.2";
src = fetchFromGitHub {
owner = "buchgr";
repo = "bazel-remote";
rev = "v${finalAttrs.version}";
hash = "sha256-9vPaTm/HTJ3ftlFg+AkcwXX7xyhmGTgKL3PXhtUHRDk=";
hash = "sha256-wE0l1tBtj44l1Eamd4wCHzjnPhT7W5yZ5MkTA5cOUrg=";
};
vendorHash = "sha256-uh8ST1AQ8OsFMfXly23TMMcheNmhb1MknmPMjB76GIQ=";
vendorHash = "sha256-DGyGQLEAwy79ibWGxAWa7gmaXTajcW3jqGJou2Wnykc=";
subPackages = [ "." ];

View File

@@ -8,17 +8,17 @@
buildGoModule (finalAttrs: {
pname = "bento";
version = "1.18.1";
version = "1.19.0";
src = fetchFromGitHub {
owner = "warpstreamlabs";
repo = "bento";
tag = "v${finalAttrs.version}";
hash = "sha256-KIlCHOAHShOwrxO9F414PQ07+SzCWhpo8auhyjkuNZA=";
hash = "sha256-3ZISLZzh8FYAE9riZ5Ya5h3LhwzHK4a5jJl8jeHiNoA=";
};
proxyVendor = true;
vendorHash = "sha256-uzB98AiJKw9TCbKSdQDiztfw7nIT0mVt80JALAPp2Aw=";
vendorHash = "sha256-h9bH5aewbDAuOVAps3TMihjCITFiBT/bbqNJCUT0NN8=";
subPackages = [
"cmd/bento"

View File

@@ -1,8 +1,8 @@
# Generated by ./update.sh - do not update manually!
# Generated by ./update.sh
{
version = "1.10.3";
deb-hash = "sha256-kzLtadq8gfX6j9XU3PD5kNV43wLDoICPlXdJqULkAWE=";
sig-hash = "sha256-+51j+SBp7buukop1T4Gz0YDUga6540BVxDRoU2YE3pY=";
version = "1.10.4";
deb-hash = "sha256-rOFbiuEbeO2qZntUhO+LNhwX6XlvWRU9v0HIAjyHwd8=";
sig-hash = "sha256-3fAGauXHA8S+XIuHeOIFxp7TsXd1LdqFg8hpWIU4P7k=";
key-E222AA02-hash = "sha256-Ue/UmS6F440/ybEEIAR+pdPEIksAt6QSMN6G5TZVWzc=";
key-4A133008-hash = "sha256-UijG3DkJNNTakVJd2wl30mDepa27n6R/Xxfl4sjt0sk=";
key-387C8307-hash = "sha256-PrRYZLT0xv82dUscOBgQGKNf6zwzWUDhriAffZbNpmI=";

View File

@@ -14,13 +14,13 @@
buildNpmPackage (finalAttrs: {
pname = "bitwarden-cli";
version = "2026.6.0";
version = "2026.7.0";
src = fetchFromGitHub {
owner = "bitwarden";
repo = "clients";
tag = "cli-v${finalAttrs.version}";
hash = "sha256-JIIis3wW0cU33ovRQfJi3HlB2YdLZ5IPvueq1dGFbas=";
hash = "sha256-8PYjRa1lhs53FCfqPBqH9712X1ek02wbkI+kW5tkepE=";
};
postPatch = ''
@@ -31,7 +31,7 @@ buildNpmPackage (finalAttrs: {
nodejs = nodejs_22;
npmDepsFetcherVersion = 2;
npmDepsHash = "sha256-sXFSjQw9iM5Ye03BX+ZzpDfeAyLTJoG/k46NiI3O8+A=";
npmDepsHash = "sha256-WRxlvkgWboO0ukUHgjC5CrfgfwnmUfDXI4r5dx9CKww=";
nativeBuildInputs = lib.optionals stdenv.hostPlatform.isDarwin [
perl

View File

@@ -31,8 +31,10 @@ stdenv.mkDerivation (finalAttrs: {
'';
nativeBuildInputs = [
gobject-introspection
meson
ninja
python3
wrapGAppsNoGuiHook
];
@@ -86,6 +88,8 @@ stdenv.mkDerivation (finalAttrs: {
};
};
strictDeps = true;
meta = {
description = "Markup language for GTK user interface files";
mainProgram = "blueprint-compiler";

View File

@@ -12,16 +12,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "bottom";
version = "0.14.4";
version = "0.14.6";
src = fetchFromGitHub {
owner = "ClementTsang";
repo = "bottom";
tag = finalAttrs.version;
hash = "sha256-axzZEviUVosXo5XzQB32A2+sUdiLzEtjZg52Z6hp4lM=";
hash = "sha256-52aUYfFm72nSG7bAlwa18kMu13i+c4myl2QfaA2YZmw=";
};
cargoHash = "sha256-RUFlv95VoRhfHeIXWFWWtbwn71uJnEYoi2NozU4ybK8=";
cargoHash = "sha256-N+dfYORAdWAg5qUrFEgXbiRtYJpcvV1AcbLR5WiD0QI=";
nativeBuildInputs = [
autoAddDriverRunpath

View File

@@ -1,35 +0,0 @@
# Expression generated by update.sh; do not edit it by hand!
{ stdenv, callPackage, ... }@args:
let
pname = "brave";
version = "1.92.143";
allArchives = {
aarch64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_arm64.deb";
hash = "sha256-IHBJm9uow2d/X4Z9e117aGdP1Y+3R1ApWu40sPtdbr8=";
};
x86_64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_amd64.deb";
hash = "sha256-jaxNneurduBiw3jho5Fp7gXnBfSpLB5hlE06i/JK+ic=";
};
aarch64-darwin = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-v${version}-darwin-arm64.zip";
hash = "sha256-EvfZgO8FAijof1Ml6gqSOyRndL8KYFdT0MNmVmuxAnU=";
};
};
archive =
if builtins.hasAttr stdenv.system allArchives then
allArchives.${stdenv.system}
else
throw "Unsupported platform.";
in
callPackage ./make-brave.nix (removeAttrs args [ "callPackage" ]) (
archive
// {
inherit pname version;
}
)

View File

@@ -1,48 +0,0 @@
#!/usr/bin/env nix-shell
#!nix-shell -i bash -p curl gnused nix jq
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" &>/dev/null && pwd)"
latestVersion="$(curl --fail -s ${GITHUB_TOKEN:+-u ":$GITHUB_TOKEN"} "https://api.github.com/repos/brave/brave-browser/releases/latest" | jq -r '.tag_name' | sed 's/^v//')"
hashAarch64="$(nix-hash --to-sri --type sha256 "$(nix-prefetch-url --type sha256 "https://github.com/brave/brave-browser/releases/download/v${latestVersion}/brave-browser_${latestVersion}_arm64.deb")")"
hashAmd64="$(nix-hash --to-sri --type sha256 "$(nix-prefetch-url --type sha256 "https://github.com/brave/brave-browser/releases/download/v${latestVersion}/brave-browser_${latestVersion}_amd64.deb")")"
hashAarch64Darwin="$(nix-hash --to-sri --type sha256 "$(nix-prefetch-url --type sha256 "https://github.com/brave/brave-browser/releases/download/v${latestVersion}/brave-v${latestVersion}-darwin-arm64.zip")")"
cat > $SCRIPT_DIR/package.nix << EOF
# Expression generated by update.sh; do not edit it by hand!
{ stdenv, callPackage, ... }@args:
let
pname = "brave";
version = "${latestVersion}";
allArchives = {
aarch64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v\${version}/brave-browser_\${version}_arm64.deb";
hash = "${hashAarch64}";
};
x86_64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v\${version}/brave-browser_\${version}_amd64.deb";
hash = "${hashAmd64}";
};
aarch64-darwin = {
url = "https://github.com/brave/brave-browser/releases/download/v\${version}/brave-v\${version}-darwin-arm64.zip";
hash = "${hashAarch64Darwin}";
};
};
archive =
if builtins.hasAttr stdenv.system allArchives then
allArchives.\${stdenv.system}
else
throw "Unsupported platform.";
in
callPackage ./make-brave.nix (removeAttrs args [ "callPackage" ]) (
archive
// {
inherit pname version;
}
)
EOF

View File

@@ -21,13 +21,13 @@
buildNpmPackage rec {
pname = "bruno";
version = "3.5.2";
version = "4.0.0";
src = fetchFromGitHub {
owner = "usebruno";
repo = "bruno";
tag = "v${version}";
hash = "sha256-Lll/ywDkHv0xvLk8iiBEySek7A3dBmfO4V/q2xaNtBQ=";
hash = "sha256-M4oNx3nSe8hSAtZMVyXIW0qQIQkaOeQgpPsfjmmJ30E=";
postFetch = ''
${lib.getExe npm-lockfile-fix} $out/package-lock.json
@@ -36,7 +36,7 @@ buildNpmPackage rec {
nodejs = nodejs_22;
npmDepsHash = "sha256-4VsSXiHj/INCu4ryZ+JxPbfDpsgIb5eYvOUYz+gbKEE=";
npmDepsHash = "sha256-Jrlpztg1JxuPaLD4O9elOaU1eFH3dmr6oWwi4Ch9Zv8=";
npmFlags = [ "--legacy-peer-deps" ];
nativeBuildInputs = [
@@ -77,6 +77,10 @@ buildNpmPackage rec {
# fix version reported in sidebar and about page
${jq}/bin/jq '.version |= "${version}"' packages/bruno-electron/package.json | ${moreutils}/bin/sponge packages/bruno-electron/package.json
${jq}/bin/jq '.version |= "${version}"' packages/bruno-app/package.json | ${moreutils}/bin/sponge packages/bruno-app/package.json
# disable remote image download to prevent network calls to comply with build sandboxing
substituteInPlace packages/bruno-app/plugins/remote-images/loader.cjs \
--replace-fail 'const urls = findRemoteImageUrls(source, domains);' 'const urls = [];'
'';
postConfigure = ''

View File

@@ -13,7 +13,7 @@
clutter-gtk,
gst_all_1,
glib,
gtk2,
gtk3,
libgsf,
libxml2,
fluidsynth,
@@ -52,7 +52,7 @@ stdenv.mkDerivation {
gst_all_1.gst-plugins-base
gst_all_1.gst-plugins-good
glib
gtk2
gtk3
libgsf
libxml2
# optional packages

View File

@@ -11,16 +11,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cargo-binstall";
version = "1.21.0";
version = "1.21.1";
src = fetchFromGitHub {
owner = "cargo-bins";
repo = "cargo-binstall";
tag = "v${finalAttrs.version}";
hash = "sha256-6msYAVCN1i2srA4DquqcdJxUrJP1jub34c/a/4RbWCg=";
hash = "sha256-7YXdKK6P6LSf/DGDL6jroR3VVqAD4uGUOGJS/dZbcvw=";
};
cargoHash = "sha256-r9iGWxrLlD83QtvZuWXIxjI2S0RO1GNwOed531FVvJk=";
cargoHash = "sha256-iUYTFtx0KBi4qgJNyuIAGcTCbS4KMyBbTIgR3nDiNAI=";
nativeBuildInputs = [
pkg-config

View File

@@ -8,15 +8,15 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cargo-shear";
version = "1.13.2";
version = "1.13.3";
src = fetchCrate {
pname = "cargo-shear";
version = finalAttrs.version;
hash = "sha256-69OwhT4vc4xwvuVxZ0C7F/Us01TsuYJnnTKT6PHsOF8=";
hash = "sha256-Qaq3nBZZR0biG5kVL15zhI8GwLEWBNzgeD3rHeZZOeU=";
};
cargoHash = "sha256-x0lZ8E/P9IaPSdzUo2O3t5qR2I3959So9uaAm4PBM4E=";
cargoHash = "sha256-3YMdOCCK+rVx0XZfBqiMAw+aep1TBU5Ok6//c433h4o=";
env = {
# https://github.com/Boshen/cargo-shear/blob/v1.6.2/src/lib.rs#L51-L54

View File

@@ -8,40 +8,45 @@
apple-sdk_15,
libiconv,
versionCheckHook,
nix-update-script,
nix-update,
writeShellApplication,
curl,
runCommand,
jq,
}:
let
# ccusage embeds the LiteLLM model-pricing table at build time. Its build
# script otherwise downloads this file from the network, which fails in the
# sandbox. Upstream pins the data via a flake input and points
# CCUSAGE_PRICING_JSON_PATH at it; mirror that exact revision here so the
# build is offline and reproducible (see package.nix + flake.lock in the
# upstream repo at tag v20.0.6). Bump this revision together with the package
# version; nix-update only refreshes the src and cargo hashes.
# ccusage embeds the LiteLLM model-pricing table at build time instead of
# downloading it (the Nix sandbox has no network). Upstream pins the exact
# data revision via its flake.lock and points CCUSAGE_PRICING_JSON_PATH at it;
# we mirror that revision here so the build is offline, reproducible, and
# byte-identical to what upstream ships.
#
# Both values below are kept in sync with the package version by
# passthru.updateScript — do not edit them by hand.
litellmPricingRev = "49ca04d8c3ddea336237ce6f3082dbc26d19e944";
litellmPricingHash = "sha256-rkUyugxdoD7WlPN//6BQpl4OJQuBbc20db7gt7exqpc=";
litellmPricing = fetchurl {
url = "https://raw.githubusercontent.com/BerriAI/litellm/f27df8d516802ce4c1b32973992154fe83b851cf/model_prices_and_context_window.json";
hash = "sha256-zJa6H2EwP9s+hMVs78Y+hwo4UX1dHRtvX5J3MdGh5aI=";
url = "https://raw.githubusercontent.com/BerriAI/litellm/${litellmPricingRev}/model_prices_and_context_window.json";
hash = litellmPricingHash;
};
in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "ccusage";
version = "20.0.6";
version = "20.0.17";
src = fetchFromGitHub {
owner = "ccusage";
repo = "ccusage";
tag = "v${finalAttrs.version}";
hash = "sha256-uf/FlPprxx4jh74YwjmYMtoIHpTkKrWTLetbNoYiFv4=";
hash = "sha256-486iLPRqQVRnKVbVT93D08RTRzd6/h503ckB//24nho=";
};
# The Cargo workspace lives in rust/, not at the repo root.
cargoRoot = "rust";
buildAndTestSubdir = "rust";
cargoHash = "sha256-izA2Gs5nPmt0zn6/e1xM80vyyQHYKGEUDpUFRpyFiB8=";
cargoHash = "sha256-23l/BCCGcZ1i5mFBC6Q+FE7sQRHnPLbU4QoQe7TfoiQ=";
__structuredAttrs = true;
strictDeps = true;
@@ -72,7 +77,40 @@ rustPlatform.buildRustPackage (finalAttrs: {
doInstallCheck = true;
passthru = {
updateScript = nix-update-script { };
# Plain nix-update only refreshes version + src/cargo hashes; it can't know
# about the LiteLLM pricing pin above. This wrapper bumps the package as
# usual, then reads the litellm revision that ccusage locks at the new tag
# and rewrites litellmPricingRev/litellmPricingHash to match, so automated
# (r-ryantm) bumps stay complete instead of shipping stale pricing data.
updateScript = lib.getExe (writeShellApplication {
name = "ccusage-update";
runtimeInputs = [
curl
jq
nix-update
];
text = ''
set -euo pipefail
attr="''${UPDATE_NIX_ATTR_PATH:-ccusage}"
nix-update "$attr"
version=$(nix-instantiate --eval --raw -A "$attr.version")
rev=$(curl --fail --silent --show-error --location \
"https://raw.githubusercontent.com/ccusage/ccusage/v''${version}/flake.lock" \
| jq --raw-output '.nodes.litellm.locked.rev')
hash=$(nix-prefetch-url --type sha256 \
"https://raw.githubusercontent.com/BerriAI/litellm/''${rev}/model_prices_and_context_window.json" \
| xargs nix --extra-experimental-features nix-command hash convert --hash-algo sha256 --to sri)
file=$(nix-instantiate --eval --raw -A "$attr.meta.position" | sed -re 's/:[0-9]+$//')
sed -i \
-e "s|litellmPricingRev = \"[0-9a-f]*\"|litellmPricingRev = \"''${rev}\"|" \
-e "s|litellmPricingHash = \"sha256-[^\"]*\"|litellmPricingHash = \"''${hash}\"|" \
"$file"
'';
});
tests = {
# With no agent data on disk, ccusage must still emit a valid, empty JSON

View File

@@ -1,47 +1,47 @@
{
"version": "2.1.218",
"commit": "bce61b433bc397ce68686368abd12f545b0a013a",
"buildDate": "2026-07-22T18:42:19Z",
"version": "2.1.219",
"commit": "7006c4c3acac98e554d3997baeda6a7fa4d1ff7c",
"buildDate": "2026-07-24T03:34:26Z",
"platforms": {
"darwin-arm64": {
"binary": "claude",
"checksum": "71abaff59312c9a9b6a1d818365048b42e4e95cc521a823660eded3e0880d9b7",
"size": 255069680
"checksum": "a8e806faaefac53c7a0f26523d8a45c60dbef3407b14ef990c75765d08febc82",
"size": 256908272
},
"darwin-x64": {
"binary": "claude",
"checksum": "9862b74a083e8a4ed572f99cbd4895185e0dd5a0a601affb0fb8e43d8d1f40e6",
"size": 264548368
"checksum": "03be9f988ed88391b4a5f08e4c5dc317ce2fffa4a9dc66c01106326e7698ee76",
"size": 266381200
},
"linux-arm64": {
"binary": "claude",
"checksum": "295fd30481bd03b38450fdec2a6e25bb6472c2074f04b0c4a566cd5988f230bf",
"size": 269990816
"checksum": "1f834b322ba9d1291cc7ffeff16a6795a59145bda279dbd59cd7ecebc7b7f15a",
"size": 271825824
},
"linux-x64": {
"binary": "claude",
"checksum": "e12071751a9336b8af1012c103358ff04ac18f9aaff4a738cff7ba5cdfaf63f2",
"size": 273177584
"checksum": "22cfd6f5b3061c0391ba84e9cf8c9deaa37783aac18b004d42ec061e98f00691",
"size": 275004400
},
"linux-arm64-musl": {
"binary": "claude",
"checksum": "efcaae48f8f537a0e9a47b4317a5f8c184706c99ddd8ca0a9a21391e2a766ef8",
"size": 263239016
"checksum": "22b2c2e0f41ab0b7c7b8845be9c49fe6f27e4c344aab1bd174bdf84a4e6b0570",
"size": 265074024
},
"linux-x64-musl": {
"binary": "claude",
"checksum": "62986293277153f5db97404cf7e3e96de136f02c28f79ccd5c7bc99766224db4",
"size": 267801168
"checksum": "487008769dd69599adb779205b6b371de27b4245f0ad2ad70f15baf4eac5f81e",
"size": 269627984
},
"win32-x64": {
"binary": "claude.exe",
"checksum": "81fcf59bb7abb558aedc6f2361f4723b3d757d28e799962d88b18b4520df66ca",
"size": 263931552
"checksum": "10f4c1f85b07f3cf6b8fff930fd26ecd475bd146a378acfafa559a6db9d89637",
"size": 265714848
},
"win32-arm64": {
"binary": "claude.exe",
"checksum": "a7959fd87feb9557d56f4e5752f7ed1ddf405f3bea91b2571bf93af636efd193",
"size": 258307232
"checksum": "6a1db10161b93e81ac55537feeae8a299f0bf67601c1c0f2016e79c850302baa",
"size": 260090016
}
},
"sdkCompat": {
@@ -68,7 +68,8 @@
"0.3.208",
"0.3.209",
"0.3.215",
"0.3.217"
"0.3.217",
"0.3.218"
],
"harnessSchema": 1
}

View File

@@ -16,11 +16,11 @@
socat,
versionCheckHook,
writableTmpDirAsHomeHook,
manifest ? lib.importJSON ./manifest.json,
}:
let
stdenv = stdenvNoCC;
baseUrl = "https://downloads.claude.ai/claude-code-releases";
manifest = lib.importJSON ./manifest.json;
platformKey = "${stdenv.hostPlatform.node.platform}-${stdenv.hostPlatform.node.arch}";
platformManifestEntry = manifest.platforms.${platformKey};
in

View File

@@ -9,13 +9,13 @@
buildGoModule (finalAttrs: {
pname = "cloudflared";
version = "2026.7.2";
version = "2026.7.3";
src = fetchFromGitHub {
owner = "cloudflare";
repo = "cloudflared";
tag = finalAttrs.version;
hash = "sha256-fuJfvm5c63koMl46sJmZOiWuNKpOwH17MD20XD7q6s0=";
hash = "sha256-hIDx9Nd7CKlM0vCKqkVHxBMj4QzvnnsYYMjhzOqcECU=";
};
vendorHash = null;

View File

@@ -11,17 +11,17 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "communique";
version = "1.2.1";
version = "1.2.3";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "jdx";
repo = "communique";
tag = "v${finalAttrs.version}";
hash = "sha256-lQN6LViO3Ta6eCbU6j76OFN95R6A0hP3Pfc38KrHDng=";
hash = "sha256-F7m6PxPOuQlZFIVYBUl650JsaZVJJmC1c+6jMgmGgc8=";
};
cargoHash = "sha256-RJzjpDhxpi7Zmzw9kl48yq6//zTYOeJ+SrgAfqq/tl4=";
cargoHash = "sha256-KyGbkVNi2rHTJfIeeq6nVFDhkWmaKh/IZ6xiVxPaXWQ=";
nativeCheckInputs = [
cacert

View File

@@ -24,13 +24,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "cubeb";
version = "0-unstable-2026-07-16";
version = "0-unstable-2026-07-25";
src = fetchFromGitHub {
owner = "mozilla";
repo = "cubeb";
rev = "0942f635f78049fc8af24939effed255ae0d0044";
hash = "sha256-RQqmrRXRABsNDjGztsLLjsZlZFBEeAAc/ysoDj6CT1A=";
rev = "ef47ae581df7c2f76058d554b3edde17f9ee7cba";
hash = "sha256-vGTB0xsIv89ua9tltdjkxLChVvTKra4kxaWCxszG3x0=";
};
outputs = [

View File

@@ -8,11 +8,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "cutemaze";
version = "1.3.6";
version = "1.3.7";
src = fetchurl {
url = "https://gottcode.org/cutemaze/cutemaze-${finalAttrs.version}.tar.bz2";
hash = "sha256-Fl/fsKB04Kn4HwkNlpcuR3wTJFfn1gGgRGTwRUNDawY=";
hash = "sha256-iaT55oVw5j3ttAiWW5y6QlQDsoUKRppDtNSLKUBNr2E=";
};
nativeBuildInputs = [

View File

@@ -56,7 +56,7 @@ let
davinci = (
stdenv.mkDerivation rec {
pname = "davinci-resolve${lib.optionalString studioVariant "-studio"}";
version = "21.0.1";
version = "21.0.3";
nativeBuildInputs = [
appimageTools.appimage-exec
@@ -78,9 +78,9 @@ let
outputHashAlgo = "sha256";
outputHash =
if studioVariant then
"sha256-8JN3ptd8jcacxHihZHXuhdkyambUsnFIj+AruvpztKI="
"sha256-pEJF+FQlBngEi5YlKq/pFNCzBiQgqjQrTnfrlKEEi6s="
else
"sha256-ioAqvqHjwFX1ec6fDoxg2VUZy1moYoGx/aEewDuN1+g=";
"sha256-3SymaLm3ibyk8yOWcUS9fOfnKEmgVA5XXc5tls27qfo=";
impureEnvVars = lib.fetchers.proxyImpureEnvVars;

View File

@@ -19,7 +19,7 @@
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "dbeaver-bin";
version = "26.1.1";
version = "26.1.3";
src =
let
@@ -31,9 +31,9 @@ stdenvNoCC.mkDerivation (finalAttrs: {
aarch64-darwin = "macos-aarch64.dmg";
};
hash = selectSystem {
x86_64-linux = "sha256-atbQ00lq589FlNem85NgzTKGyhTRpFII8OSfVfYQuD0=";
aarch64-linux = "sha256-Sde0q31hXMqX2oxfhgj5EcpeUYYFZJy61usaJVpZkLM=";
aarch64-darwin = "sha256-PwuFwEE+aBEG/ykwNrEBl20yfrade8BdUUHdLJGBkwc=";
x86_64-linux = "sha256-cPRmReV6F+pCkrbF7d1m+bQjOaJCCFndNSThMWPGrsY=";
aarch64-linux = "sha256-bT1bCKzeiAMJbPa6I6fqQq7OrbkKhgDYAUEKuURHP5g=";
aarch64-darwin = "sha256-NYX651gUpEDh2O720ZKl7fUTYLFKpTJzyC/YnN4Vnys=";
};
in
fetchurl {

View File

@@ -33,7 +33,7 @@ let
in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "deno";
version = "2.9.3";
version = "2.9.4";
__structuredAttrs = true;
@@ -47,10 +47,10 @@ rustPlatform.buildRustPackage (finalAttrs: {
repo = "deno";
tag = "v${finalAttrs.version}";
fetchSubmodules = true; # required for tests
hash = "sha256-XMHlWK+lhyn1KO1CSxcuM3KzTjYviVrRw+FUL74bBPc=";
hash = "sha256-ivch++yGRUyWtox/5QqomC4DlTvMBxK+gIcN9/7tt5E=";
};
cargoHash = "sha256-WZxyoD9WMnaLyD3/86R90KWC+9OA15fIMw8SjmovNHA=";
cargoHash = "sha256-ynbHLZXkPPYpsC4dCu6jA6x8ftiTHWZ/uxzdbUcUaa0=";
patches = [
./patches/0002-tests-replace-hardcoded-paths.patch
@@ -211,6 +211,8 @@ rustPlatform.buildRustPackage (finalAttrs: {
++ lib.optionals stdenv.hostPlatform.isLinux [
# Wants to access /etc/resolv.conf: https://github.com/hickory-dns/hickory-dns/issues/2959
"--skip=tests::test_userspace_resolver"
# We don't have a tmp dir with sticky bit during build
"--skip=util::temp::test::test_ensure_secure_temp_parent_rejects_non_sticky_writable_dir"
];
__darwinAllowLocalNetworking = true;

View File

@@ -0,0 +1,16 @@
Submodule build contains modified content
diff --git a/build/config/compiler/BUILD.gn b/build/config/compiler/BUILD.gn
index 11ddb4916..0bd001600 100644
--- a/build/config/compiler/BUILD.gn
+++ b/build/config/compiler/BUILD.gn
@@ -2827,10 +2827,6 @@ config("split_dwarf") {
# thinlto requires -gsplit-dwarf in ldflags.
if (use_thin_lto && !is_apple) {
ldflags = split_dwarf_flags
- } else {
- # .dwo files are generated when ThinLTO is not used.
- c_additional_outputs =
- [ "{{target_out_dir}}/{{label_name}}/{{source_name_part}}.dwo" ]
}
}

View File

@@ -71,26 +71,27 @@ let
in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "rusty-v8";
version = "149.4.0";
version = "150.2.0";
src = fetchFromGitHub {
owner = "denoland";
repo = "rusty_v8";
tag = "v${finalAttrs.version}";
fetchSubmodules = true;
hash = "sha256-n4dKtki9ov0lWBeLmMDI4Tpk8zQ8YYSf04QW6DTYisY=";
hash = "sha256-Iwgc08bUHR4OiwqopJua6fkQYMOdC5k9TgoCmZQrWIw=";
};
patches = [
./librusty_v8_no_downloads.patch
./llvm22.patch
./gn_inputs_fix.patch
./c_additional_outputs.patch
]
++ lib.optionals stdenv.targetPlatform.isDarwin [
./librusty_v8-darwin-fix-__rust_no_alloc_shim_is_unstable_v2.patch
];
cargoHash = "sha256-bGqg/6sfBaF/JpObgXyP4Mh+4P9zfuzd454m4wjluGw=";
cargoHash = "sha256-M65ODvL+o3njO3SdbJaCvgRupoguCGCIoYY/dYiJPng=";
nativeBuildInputs = [
llvmPackages.clang

View File

@@ -8,15 +8,17 @@
buildGoModule (finalAttrs: {
pname = "diffyml";
version = "1.7.0";
version = "1.7.1";
__structuredAttrs = true;
__darwinAllowLocalNetworking = true;
src = fetchFromGitHub {
owner = "szhekpisov";
repo = "diffyml";
tag = "v${finalAttrs.version}";
hash = "sha256-DIKHvFY/eW3CAF/ojW+D737vFCcZk0peRrSb8I/an9Q=";
hash = "sha256-bfFerbjpwQuTCnGKfqUj3ydf1xBdNoP+qH7UTmtZvTk=";
};
vendorHash = "sha256-QE/EwVzMqUO24ZAl0WBibGx6x0kNo1AUTZtfnQvX50k=";

View File

@@ -20,13 +20,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "diodon";
version = "1.13.0";
version = "1.14.0";
src = fetchFromGitHub {
owner = "diodon-dev";
repo = "diodon";
tag = finalAttrs.version;
hash = "sha256-VCJANasrGmC0jIy8JNNURvmgpL/SLOaVsKo7Pf+X8DQ=";
hash = "sha256-lcDJe9uJeDPtVBwh3QzQdRX4/exOl6gLStpQxLiT10M=";
};
strictDeps = true;

View File

@@ -0,0 +1,126 @@
diff --git a/modules.d/35network-legacy/dhclient-script.sh b/modules.d/35network-legacy/dhclient-script.sh
index 0cb00ab..ae68952 100755
--- a/modules.d/35network-legacy/dhclient-script.sh
+++ b/modules.d/35network-legacy/dhclient-script.sh
@@ -20,11 +20,11 @@ setup_interface() {
mask=$new_subnet_mask
bcast=$new_broadcast_address
gw=${new_routers%%,*}
- domain=$new_domain_name
+ domain=$(printf -- "%s" "$new_domain_name" | tr -d '[:cntrl:]')
# get rid of control chars
search=$(printf -- "%s" "$new_domain_search" | tr -d '[:cntrl:]')
namesrv=$new_domain_name_servers
- hostname=$new_host_name
+ hostname=$(printf '%s' "$new_host_name" | tr -d -c 'a-zA-Z0-9.-')
[ -n "$new_dhcp_lease_time" ] && lease_time=$new_dhcp_lease_time
[ -n "$new_max_life" ] && lease_time=$new_max_life
preferred_lft=$lease_time
@@ -56,20 +56,32 @@ setup_interface() {
${preferred_lft:+preferred_lft ${preferred_lft}}
if [ -n "$gw" ]; then
- if [ "$mask" = "255.255.255.255" ]; then
- # point-to-point connection => set explicit route to gateway
- echo ip route add "$gw" dev "$netif" > /tmp/net."$netif".gw
- fi
+ gw_check=0
+ for g in $gw; do
+ case "$g" in
+ *[!0-9.]*)
+ gw_check=1
+ break
+ ;;
+ esac
+ done
- echo "$gw" | {
- IFS=' ' read -r main_gw other_gw
- echo ip route replace default via "$main_gw" dev "$netif" >> /tmp/net."$netif".gw
- if [ -n "$other_gw" ]; then
- for g in $other_gw; do
- echo ip route add default via "$g" dev "$netif" >> /tmp/net."$netif".gw
- done
- fi
- }
+ if [ $gw_check -eq 0 ]; then
+ if [ "$mask" = "255.255.255.255" ]; then
+ # point-to-point connection => set explicit route to gateway
+ echo ip route add "$gw" dev "$netif" > /tmp/net."$netif".gw
+ fi
+
+ echo "$gw" | {
+ IFS=' ' read -r main_gw other_gw
+ echo ip route replace default via "$main_gw" dev "$netif" >> /tmp/net."$netif".gw
+ if [ -n "$other_gw" ]; then
+ for g in $other_gw; do
+ echo ip route add default via "$g" dev "$netif" >> /tmp/net."$netif".gw
+ done
+ fi
+ }
+ fi
fi
if getargbool 1 rd.peerdns; then
@@ -82,15 +94,15 @@ setup_interface() {
fi
# Note: hostname can be fqdn OR short hostname, so chop off any
# trailing domain name and explicitly add any domain if set.
- [ -n "$hostname" ] && echo "echo ${hostname%."$domain"}${domain:+.$domain} > /proc/sys/kernel/hostname" > /tmp/net."$netif".hostname
+ [ -n "$hostname" ] && echo "echo '${hostname%."$domain"}${domain:+.$domain}' > /proc/sys/kernel/hostname" > /tmp/net."$netif".hostname
}
setup_interface6() {
- domain=$new_domain_name
+ domain=$(printf -- "%s" "$new_domain_name" | tr -d '[:cntrl:]')
# get rid of control chars
search=$(printf -- "%s" "$new_dhcp6_domain_search" | tr -d '[:cntrl:]')
namesrv=$new_dhcp6_name_servers
- hostname=$new_host_name
+ hostname=$(printf '%s' "$new_host_name" | tr -d -c 'a-zA-Z0-9.-')
[ -n "$new_dhcp_lease_time" ] && lease_time=$new_dhcp_lease_time
[ -n "$new_max_life" ] && lease_time=$new_max_life
preferred_lft=$lease_time
@@ -105,7 +117,7 @@ setup_interface6() {
# Note: hostname can be fqdn OR short hostname, so chop off any
# trailing domain name and explicitly add any domain if set.
- [ -n "$hostname" ] && echo "echo ${hostname%."$domain"}${domain:+.$domain} > /proc/sys/kernel/hostname" > /tmp/net."$netif".hostname
+ [ -n "$hostname" ] && echo "echo '${hostname%."$domain"}${domain:+.$domain}' > /proc/sys/kernel/hostname" > /tmp/net."$netif".hostname
}
parse_option_121() {
@@ -113,16 +125,18 @@ parse_option_121() {
# Each route is: <mask_width> <dest_octets...> <gateway_4_octets>
# mask_width determines how many destination octets follow (0-4)
#
- # This version validates arguments before operations to prevent
- # "integer expression expected" and "shift count out of range" errors.
+ # Validate all arguments are numeric upfront to prevent
+ # shell injection via crafted octets in destination/gateway.
+ for _octet in "$@"; do
+ case "$_octet" in
+ '' | *[!0-9]*) return 0 ;;
+ esac
+ done
while [ $# -ge 5 ]; do
mask="$1"
# Validate mask is a number between 0-32
- case "$mask" in
- '' | *[!0-9]*) return 0 ;;
- esac
if [ "$mask" -lt 0 ] 2> /dev/null || [ "$mask" -gt 32 ] 2> /dev/null; then
return 0
fi
@@ -150,9 +164,6 @@ parse_option_121() {
# Check if destination is multicast (224.0.0.0 - 239.255.255.255)
multicast=0
if [ $need_dest -ge 1 ]; then
- case "$1" in
- '' | *[!0-9]*) return 0 ;;
- esac
if [ "$1" -ge 224 ] 2> /dev/null && [ "$1" -lt 240 ] 2> /dev/null; then
multicast=1
fi

View File

@@ -38,6 +38,12 @@ stdenv.mkDerivation (finalAttrs: {
hash = "sha256-2jdS7/LGuLSBBXv1R/o8yjgwdXl2l2wNbZWxq01wSb0";
};
# Patch from https://github.com/dracut-ng/dracut/commit/11577739221ff38c1fd29abbba51a6c797376ed6 included in main branch.
# Adapted to version 111 (line number and small formatting diff)
patches = [
./CVE-2026-6893.patch
];
strictDeps = true;
__structuredAttrs = true;

View File

@@ -2,7 +2,6 @@
lib,
stdenv,
fetchFromGitHub,
fetchpatch2,
pkg-config,
hackrf,
libbladeRF,
@@ -15,23 +14,15 @@
stdenv.mkDerivation (finalAttrs: {
pname = "dump1090";
version = "10.2";
version = "11.1";
src = fetchFromGitHub {
owner = "flightaware";
repo = "dump1090";
tag = "v${finalAttrs.version}";
hash = "sha256-kTJ8FMugBRJaxWas/jEj4E5TmVnNpNdhq4r2YFFwgTU=";
hash = "sha256-A6nkct7jvpPtPZ+iM2UKVckIXgNxxq5sxhyPiw5+EZk=";
};
patches = [
# Fix compilation with GCC 15: https://github.com/flightaware/dump1090/pull/261
(fetchpatch2 {
url = "https://github.com/flightaware/dump1090/commit/93be1da123215e8ac15a0deaffedd480e8899f77.patch?full_index=1";
hash = "sha256-x+U86b1j+mSpqfG4oFnHEz3cd7/O57ezPUf8yBrLzbc=";
})
];
nativeBuildInputs = [ pkg-config ];
buildInputs = [
@@ -44,8 +35,6 @@ stdenv.mkDerivation (finalAttrs: {
]
++ lib.optional stdenv.hostPlatform.isLinux limesuite;
env.NIX_CFLAGS_COMPILE = lib.optionalString stdenv.cc.isClang "-Wno-implicit-function-declaration -Wno-int-conversion -Wno-unknown-warning-option";
buildFlags = [
"DUMP1090_VERSION=${finalAttrs.version}"
"showconfig"
@@ -74,6 +63,7 @@ stdenv.mkDerivation (finalAttrs: {
maintainers = with lib.maintainers; [
earldouglas
aciceri
ryand56
];
mainProgram = "dump1090";
};

View File

@@ -14,11 +14,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "fasmg";
version = "l7xm";
version = "l8vn";
src = fetchzip {
url = "https://flatassembler.net/fasmg.${finalAttrs.version}.zip";
sha256 = "sha256-m/mLZLluvoxr0VsNVcBnHvv1LlagafkX6fwZSovtO9s=";
sha256 = "sha256-/Izf7w7yofmPp1J85BgWbMLIGC4SGsCqXzhdecOo7CE=";
stripRoot = false;
};

View File

@@ -0,0 +1,34 @@
{
lib,
buildGoModule,
fetchFromGitHub,
nix-update-script,
}:
buildGoModule (finalAttrs: {
pname = "flux-build";
version = "3.0.10";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "DoodleScheduling";
repo = "flux-build";
tag = "v${finalAttrs.version}";
hash = "sha256-ToQVm69XqJgRahunUXjNnIiieqSV8TzgFdtFJktz5/g=";
};
vendorHash = "sha256-kVi/VVVPTblDvCjvnsKxfqYELBahHmzTlW74ktdZC7k=";
passthru.updateScript = nix-update-script { };
meta = {
description = "Build and test kustomize overlays with Flux HelmRelease templating";
homepage = "https://github.com/DoodleScheduling/flux-build";
license = lib.licenses.asl20;
changelog = "https://github.com/DoodleScheduling/flux-build/releases/tag/v${finalAttrs.version}";
mainProgram = "flux-build";
maintainers = with lib.maintainers; [ MNThomson ];
platforms = lib.platforms.unix;
};
})

Some files were not shown because too many files have changed in this diff Show More