mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-07-26 02:20:36 +00:00
Compare commits
481 Commits
haskell-up
...
staging-ne
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2ba8b0c93e | ||
|
|
929adb31f5 | ||
|
|
92d6c402cc | ||
|
|
4cb5271844 | ||
|
|
dd252872db | ||
|
|
4bb9026bef | ||
|
|
e488d836cf | ||
|
|
e9370c55d1 | ||
|
|
025c5c6988 | ||
|
|
a4d98e40c7 | ||
|
|
aa3f875ae2 | ||
|
|
d65da55c82 | ||
|
|
86dc66e4ee | ||
|
|
01ca76dcbc | ||
|
|
28a7542ca2 | ||
|
|
4959772f70 | ||
|
|
b850a337c8 | ||
|
|
ab1fe49f69 | ||
|
|
99ec020953 | ||
|
|
9b2b89eeca | ||
|
|
a6f3f5e1a1 | ||
|
|
9bc8a2ef64 | ||
|
|
1c13ea5c1f | ||
|
|
497ff4c10e | ||
|
|
3c5a75f40e | ||
|
|
2ab6dfb50c | ||
|
|
088cf6c9f2 | ||
|
|
febfb4bdfa | ||
|
|
9a18c35488 | ||
|
|
38e6d10918 | ||
|
|
73a89410bf | ||
|
|
2867d59a3e | ||
|
|
1c9b1139d5 | ||
|
|
134290ea71 | ||
|
|
444678226f | ||
|
|
7c7dab194d | ||
|
|
4a25c9a06f | ||
|
|
d50bfc3ff7 | ||
|
|
d7d3021eb7 | ||
|
|
ab4af867cf | ||
|
|
f9effd3338 | ||
|
|
2f8f40d2ea | ||
|
|
e0ff180112 | ||
|
|
b3bd3fef87 | ||
|
|
97b1439fc9 | ||
|
|
9684a329bf | ||
|
|
8d9e8784da | ||
|
|
8529f99427 | ||
|
|
6e5e7484d6 | ||
|
|
70ed89608f | ||
|
|
747d9feae6 | ||
|
|
378d5c7497 | ||
|
|
662771f792 | ||
|
|
8706bc4b89 | ||
|
|
9651249dd1 | ||
|
|
e072c356b1 | ||
|
|
014130f610 | ||
|
|
052bce2493 | ||
|
|
e061c6a434 | ||
|
|
519bc6a880 | ||
|
|
ac312f87f9 | ||
|
|
9df45099c2 | ||
|
|
6942ec2e59 | ||
|
|
161c72f5cd | ||
|
|
9112783bed | ||
|
|
fbccc899b5 | ||
|
|
61b75d16de | ||
|
|
393884397a | ||
|
|
2f478a0b4a | ||
|
|
db67362752 | ||
|
|
83b7df8e6b | ||
|
|
91f1117bdd | ||
|
|
39b8e3e862 | ||
|
|
c6a0ce5b10 | ||
|
|
a7503406b2 | ||
|
|
0f2f872495 | ||
|
|
c8c029256f | ||
|
|
645360ba39 | ||
|
|
e6a80147f8 | ||
|
|
02723ee212 | ||
|
|
147944a023 | ||
|
|
a9d937331d | ||
|
|
2e8c34b71a | ||
|
|
47b6451999 | ||
|
|
e624729bd3 | ||
|
|
5918980a5f | ||
|
|
4723fa5617 | ||
|
|
e38cb26f3d | ||
|
|
953b3a389c | ||
|
|
198048016f | ||
|
|
5b7a0b225f | ||
|
|
a9214c8c1e | ||
|
|
b3bd1a11ab | ||
|
|
034f182418 | ||
|
|
76e8396b35 | ||
|
|
bf4ac76fa1 | ||
|
|
f07170e43e | ||
|
|
8be50135f3 | ||
|
|
c2b9f6777a | ||
|
|
c3aec2ba8d | ||
|
|
80e5c29a8d | ||
|
|
88ddc79783 | ||
|
|
faa7f7ec44 | ||
|
|
c2809ca95b | ||
|
|
4d0ba85856 | ||
|
|
3ddac825f8 | ||
|
|
0267914b93 | ||
|
|
57154f3d7f | ||
|
|
dd904cf110 | ||
|
|
1f6d4ed2df | ||
|
|
9ee20e0f94 | ||
|
|
42547fa6cc | ||
|
|
f0fe1ac48c | ||
|
|
7b130a7b75 | ||
|
|
877c6e9372 | ||
|
|
7c51ba2a3e | ||
|
|
92ff601c5c | ||
|
|
dad717e04c | ||
|
|
f2da850dfd | ||
|
|
ca74517126 | ||
|
|
0457e97587 | ||
|
|
9a346bf20e | ||
|
|
32ae284834 | ||
|
|
136ea50568 | ||
|
|
2c891a6f1f | ||
|
|
e9d32fcea2 | ||
|
|
cfb4cc0d96 | ||
|
|
4ad1e78bb6 | ||
|
|
ec01aa24a0 | ||
|
|
cc1396afd1 | ||
|
|
b2a8a65ad0 | ||
|
|
610928778e | ||
|
|
14f9cea17e | ||
|
|
1169e0abeb | ||
|
|
4d1e3ff59e | ||
|
|
adcdea620d | ||
|
|
56de350dcd | ||
|
|
e9ca7aa0bd | ||
|
|
ae2c2f465e | ||
|
|
ca59ee9ad2 | ||
|
|
e4c7ce47ac | ||
|
|
0361d27e98 | ||
|
|
50febbbce7 | ||
|
|
4076bf8495 | ||
|
|
2f88416c69 | ||
|
|
2f4a136ec7 | ||
|
|
337eba0612 | ||
|
|
e6994d7d89 | ||
|
|
997a0b100d | ||
|
|
c7ecec0ae3 | ||
|
|
c41ff93dad | ||
|
|
aa47e78b28 | ||
|
|
cea6971180 | ||
|
|
f491c9ef41 | ||
|
|
55a5ffdda8 | ||
|
|
e27d2a93fd | ||
|
|
11d31fc14e | ||
|
|
3d5bfdf361 | ||
|
|
90b33c2f2d | ||
|
|
36d67faffa | ||
|
|
9705e3bf68 | ||
|
|
d28d49d4a4 | ||
|
|
3988a1454b | ||
|
|
36e3d11cf2 | ||
|
|
c2e917178d | ||
|
|
ea14011c43 | ||
|
|
40dbc22cd8 | ||
|
|
6b7fb8f2ce | ||
|
|
3baf5a75f4 | ||
|
|
ba2fbde84c | ||
|
|
c6c6e3ee3a | ||
|
|
37bfb33419 | ||
|
|
f846b7a768 | ||
|
|
25a327121b | ||
|
|
87ab7b5bde | ||
|
|
95d4c6bc0b | ||
|
|
add81a03c2 | ||
|
|
f79d8318a2 | ||
|
|
45c46c594f | ||
|
|
039d87ba01 | ||
|
|
88c98a0d79 | ||
|
|
630bb08227 | ||
|
|
6935b590e8 | ||
|
|
2252d3e2ad | ||
|
|
10b08b8854 | ||
|
|
10438afccd | ||
|
|
122a9f7be6 | ||
|
|
081e6f29ef | ||
|
|
9a75b2270a | ||
|
|
138f9b0486 | ||
|
|
7a610a393f | ||
|
|
a75c838377 | ||
|
|
976a38d3a8 | ||
|
|
d271bcee7e | ||
|
|
bd3349d2db | ||
|
|
f8dc89327e | ||
|
|
acb0147cce | ||
|
|
e3e28ba32a | ||
|
|
c16695a7b7 | ||
|
|
827022194a | ||
|
|
d13603be1d | ||
|
|
335d4b802d | ||
|
|
d92de35181 | ||
|
|
cfe6a78499 | ||
|
|
25fca87ec6 | ||
|
|
7f5568e6cf | ||
|
|
12766e45af | ||
|
|
1968d142a8 | ||
|
|
5e002b0a52 | ||
|
|
897981fe69 | ||
|
|
eb2ab8368b | ||
|
|
4664e700a0 | ||
|
|
25f9933883 | ||
|
|
bf57aa089b | ||
|
|
beafba482d | ||
|
|
03502b7d6a | ||
|
|
166a63ea12 | ||
|
|
9186f602e0 | ||
|
|
50c0be3803 | ||
|
|
9922327b5b | ||
|
|
5cd6f09987 | ||
|
|
863d0e6c48 | ||
|
|
0812368cb9 | ||
|
|
6853058efa | ||
|
|
f3ca8c8be6 | ||
|
|
d654dd76ab | ||
|
|
883b729777 | ||
|
|
f22784b1b7 | ||
|
|
e9518a982a | ||
|
|
c9a0980d21 | ||
|
|
3c293e782c | ||
|
|
edcd9e9929 | ||
|
|
e79819a2a8 | ||
|
|
9bb5bf1ea8 | ||
|
|
eafe84dfd8 | ||
|
|
f9eab6eaf1 | ||
|
|
ba4c9417bd | ||
|
|
d60fdc080d | ||
|
|
99dc0aad21 | ||
|
|
7bffb8137a | ||
|
|
66bd9979a5 | ||
|
|
8ce69b14f4 | ||
|
|
d782d6e1db | ||
|
|
d4ddaa94ab | ||
|
|
c57addab0d | ||
|
|
1993a70695 | ||
|
|
5f7d67a4e1 | ||
|
|
d71f49f361 | ||
|
|
12ed470109 | ||
|
|
bfc41e6078 | ||
|
|
1c8bd6f104 | ||
|
|
8d462aa3e6 | ||
|
|
061490506c | ||
|
|
de2aae02a6 | ||
|
|
c19d3ebf38 | ||
|
|
c2ce3cdea7 | ||
|
|
fcb270ccb9 | ||
|
|
7ac4a2b500 | ||
|
|
be2807d4fc | ||
|
|
b48ac115da | ||
|
|
bb213d9d4a | ||
|
|
7b882f05f2 | ||
|
|
56931fcce4 | ||
|
|
0f2cca0b37 | ||
|
|
90136fe8a3 | ||
|
|
c3a6c7546f | ||
|
|
2c73b96824 | ||
|
|
052a8a41df | ||
|
|
3a843f2b5a | ||
|
|
328e42b4f8 | ||
|
|
e51a4d900d | ||
|
|
eee706d3b9 | ||
|
|
36188b18a1 | ||
|
|
b6df579bc5 | ||
|
|
a0382bc1a4 | ||
|
|
94edb80278 | ||
|
|
7822200edd | ||
|
|
8b49416599 | ||
|
|
967b5e7105 | ||
|
|
ec69cf3f7b | ||
|
|
38affae6a5 | ||
|
|
9e3461d3ed | ||
|
|
9de8e0f7e2 | ||
|
|
65e299ca3b | ||
|
|
bb8534b07d | ||
|
|
e0166b2fe1 | ||
|
|
6c534f04d3 | ||
|
|
76ffe07b40 | ||
|
|
59fdf1c191 | ||
|
|
8eb42e621f | ||
|
|
b0dbf02481 | ||
|
|
3ac61b583e | ||
|
|
649f551194 | ||
|
|
b6daa60814 | ||
|
|
92fdff41d6 | ||
|
|
3f38696610 | ||
|
|
f35962ee24 | ||
|
|
ad43cfde13 | ||
|
|
be5fbdd94f | ||
|
|
57e38620ce | ||
|
|
1e3e322248 | ||
|
|
461ce04b99 | ||
|
|
b002a5b1ec | ||
|
|
955d274ac2 | ||
|
|
611eeadc37 | ||
|
|
aee66850fb | ||
|
|
1045bcf482 | ||
|
|
9b6f782419 | ||
|
|
109e19daf6 | ||
|
|
cdca3edfe9 | ||
|
|
f34ccff1bf | ||
|
|
5ad3074a6c | ||
|
|
87f1cd6f4b | ||
|
|
350b25e579 | ||
|
|
b19aa3bf5f | ||
|
|
c2d648625c | ||
|
|
02763c6450 | ||
|
|
6ce157fcd7 | ||
|
|
ccd93dcec1 | ||
|
|
05bb946302 | ||
|
|
c6ca7a20f1 | ||
|
|
500dca3897 | ||
|
|
6701006109 | ||
|
|
1055989ba1 | ||
|
|
a16f93f8da | ||
|
|
6d37c01148 | ||
|
|
cc56d7d0b1 | ||
|
|
4c818080da | ||
|
|
ea4c60137f | ||
|
|
d37727ba4b | ||
|
|
3665b4066c | ||
|
|
0359400aa9 | ||
|
|
0de0ef693b | ||
|
|
09d9cc74a8 | ||
|
|
e589763ae0 | ||
|
|
c485262d71 | ||
|
|
701b3fd657 | ||
|
|
cbf83bb332 | ||
|
|
3927e90c19 | ||
|
|
f6ac678e71 | ||
|
|
a08dbb1895 | ||
|
|
cfb5b9e004 | ||
|
|
5371195501 | ||
|
|
00d0b792cc | ||
|
|
0471148d15 | ||
|
|
77c44d7620 | ||
|
|
64cb9bd361 | ||
|
|
36fbe6bc2b | ||
|
|
e770f303ab | ||
|
|
cb187f88a6 | ||
|
|
109e168b03 | ||
|
|
d1fd431204 | ||
|
|
4f22b00129 | ||
|
|
eb60e6ac5b | ||
|
|
c705f56ade | ||
|
|
e50015067e | ||
|
|
2d50e90f1a | ||
|
|
eb7e56fe88 | ||
|
|
f86bce2497 | ||
|
|
7ce5dd4b46 | ||
|
|
c9ba965d27 | ||
|
|
863a5fb60d | ||
|
|
a8602ba833 | ||
|
|
af4df060ce | ||
|
|
cf8f9a948b | ||
|
|
4ed9282b38 | ||
|
|
ffc0a72876 | ||
|
|
4bb6931ece | ||
|
|
e0c8b3d1f3 | ||
|
|
f6055e87bf | ||
|
|
e29c342b51 | ||
|
|
928ccf6805 | ||
|
|
1ac1dd3921 | ||
|
|
1a3ea561d1 | ||
|
|
a294471a87 | ||
|
|
6b38ccd029 | ||
|
|
e2ee5d659c | ||
|
|
ca2336b2e1 | ||
|
|
c9bc82d15e | ||
|
|
78db27d15d | ||
|
|
d1e0d72118 | ||
|
|
6da6feecca | ||
|
|
23f2849e4d | ||
|
|
00b024aca8 | ||
|
|
a25913208f | ||
|
|
0442655034 | ||
|
|
539ad7384e | ||
|
|
1edc097bd2 | ||
|
|
016e2c79d7 | ||
|
|
be45d1efa9 | ||
|
|
196ae695a8 | ||
|
|
6b1008c206 | ||
|
|
227c3aace0 | ||
|
|
674fde2484 | ||
|
|
dc088c4465 | ||
|
|
a0f7233e07 | ||
|
|
d46c595b68 | ||
|
|
0a646acd33 | ||
|
|
d306537ce5 | ||
|
|
3cc7f6670b | ||
|
|
a35c0b0939 | ||
|
|
ab79b9b43a | ||
|
|
f44b368058 | ||
|
|
f4828f51ce | ||
|
|
f43765f07a | ||
|
|
cd3449310a | ||
|
|
391874228d | ||
|
|
a2d7b92fac | ||
|
|
e8127dd752 | ||
|
|
9ff109fb87 | ||
|
|
d798258c7a | ||
|
|
ffc8c1c9eb | ||
|
|
97087f83d5 | ||
|
|
17f903b426 | ||
|
|
e7c911fdff | ||
|
|
9dca5046aa | ||
|
|
66c61c3c1e | ||
|
|
d557d9c091 | ||
|
|
db8e7c02bb | ||
|
|
10d1260d3a | ||
|
|
a82bdac5ff | ||
|
|
7bd1ed1622 | ||
|
|
536da04b81 | ||
|
|
38bf1d29cd | ||
|
|
ffe6ce2a14 | ||
|
|
f3d131212a | ||
|
|
d5a6c65fef | ||
|
|
ce01b16cd6 | ||
|
|
ea1d43ed8a | ||
|
|
5e9376fc91 | ||
|
|
90a6722c59 | ||
|
|
916c050a13 | ||
|
|
1f22863ccd | ||
|
|
f412c70cf7 | ||
|
|
82878a8688 | ||
|
|
3e8b8d5454 | ||
|
|
bc557b7168 | ||
|
|
a1836fd3b1 | ||
|
|
36fd2c52cf | ||
|
|
422436fc18 | ||
|
|
c504fe64e2 | ||
|
|
5ae7702a20 | ||
|
|
e022b86ee8 | ||
|
|
0798b868b6 | ||
|
|
5cb2dbb287 | ||
|
|
4d617ddeb7 | ||
|
|
0cae472909 | ||
|
|
736003fbad | ||
|
|
706bc06df6 | ||
|
|
a4805bc6c9 | ||
|
|
cb97856984 | ||
|
|
6cf631626c | ||
|
|
89be98d540 | ||
|
|
eb88f6df7c | ||
|
|
28f54c2d43 | ||
|
|
7c447c32bd | ||
|
|
57b0e5e803 | ||
|
|
698a70e9fe | ||
|
|
ed2bc926d1 | ||
|
|
bb50b6eb9d | ||
|
|
253475c406 | ||
|
|
4b55fc928b | ||
|
|
64f1104dea | ||
|
|
2822a3acce | ||
|
|
3172f85a7e | ||
|
|
f40e1287c3 | ||
|
|
b276999b1f | ||
|
|
1729877a4c | ||
|
|
fabe4a9ad0 | ||
|
|
46714b0550 | ||
|
|
9ca5a1b103 | ||
|
|
1bfac9c378 | ||
|
|
c210d6bb89 | ||
|
|
174e0a3aa3 | ||
|
|
775b868546 | ||
|
|
e6c219c3d7 | ||
|
|
c72f684b1d | ||
|
|
46f5fe2a35 | ||
|
|
d42e82be52 | ||
|
|
6f39241f33 | ||
|
|
83419e790f |
@@ -211,7 +211,7 @@ nixos/modules/installer/tools/nix-fallback-paths.nix @Artturin @Ericson2314 @lo
|
||||
/pkgs/development/perl-modules @stigtsp @marcusramberg
|
||||
|
||||
# R
|
||||
/pkgs/applications/science/math/R @jbedo
|
||||
/pkgs/by-name/r/R @jbedo
|
||||
/pkgs/development/r-modules @jbedo
|
||||
|
||||
# Rust
|
||||
|
||||
@@ -12,6 +12,19 @@
|
||||
"revision": "7525d999cd850b9a488817abc89c75dc733acf17",
|
||||
"url": "https://github.com/NixOS/nixpkgs/archive/7525d999cd850b9a488817abc89c75dc733acf17.tar.gz",
|
||||
"hash": "sha256-4IHyyLgLBdKefkljdKod4IMn023pQiDXAWJA187cmdY="
|
||||
},
|
||||
"nixpkgs-26.05-darwin": {
|
||||
"type": "Git",
|
||||
"repository": {
|
||||
"type": "GitHub",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs"
|
||||
},
|
||||
"branch": "nixpkgs-26.05-darwin",
|
||||
"submodules": false,
|
||||
"revision": "51fe96f9107566e6b8eeb7fc4ba696c01e548b04",
|
||||
"url": "https://github.com/NixOS/nixpkgs/archive/51fe96f9107566e6b8eeb7fc4ba696c01e548b04.tar.gz",
|
||||
"hash": "sha256-yj0LPLnsmYoLmA3FGANjeTEwej0/DHjZBXWnDQDUuIs="
|
||||
}
|
||||
},
|
||||
"version": 8
|
||||
|
||||
@@ -28,7 +28,7 @@ However, [those were unified early 2020](https://github.com/NixOS/nixpkgs/pull/8
|
||||
|
||||
```nix
|
||||
{ appimageTools, fetchurl }:
|
||||
let
|
||||
appimageTools.wrapType2 {
|
||||
pname = "nuclear";
|
||||
version = "0.6.30";
|
||||
|
||||
@@ -36,8 +36,7 @@ let
|
||||
url = "https://github.com/nukeop/nuclear/releases/download/v${version}/nuclear-v${version}.AppImage";
|
||||
hash = "sha256-he1uGC1M/nFcKpMM9JKY4oeexJcnzV0ZRxhTjtJz6xw=";
|
||||
};
|
||||
in
|
||||
appimageTools.wrapType2 { inherit pname version src; }
|
||||
}
|
||||
```
|
||||
|
||||
:::
|
||||
@@ -56,7 +55,7 @@ There are a few ways to learn which dependencies an application needs:
|
||||
|
||||
```nix
|
||||
{ appimageTools, fetchurl }:
|
||||
let
|
||||
appimageTools.wrapType2 {
|
||||
pname = "irccloud";
|
||||
version = "0.16.0";
|
||||
|
||||
@@ -64,9 +63,7 @@ let
|
||||
url = "https://github.com/irccloud/irccloud-desktop/releases/download/v${version}/IRCCloud-${version}-linux-x86_64.AppImage";
|
||||
hash = "sha256-/hMPvYdnVB1XjKgU2v47HnVvW4+uC3rhRjbucqin4iI=";
|
||||
};
|
||||
in
|
||||
appimageTools.wrapType2 {
|
||||
inherit pname version src;
|
||||
|
||||
extraPkgs = pkgs: [ pkgs.at-spi2-core ];
|
||||
}
|
||||
```
|
||||
@@ -88,12 +85,12 @@ However, [those were unified early 2020](https://github.com/NixOS/nixpkgs/pull/8
|
||||
|
||||
# Extracting an AppImage to install extra files
|
||||
|
||||
This example was adapted from a real package in Nixpkgs to show how `extract` is usually used in combination with `wrapType2`.
|
||||
Note how `appimageContents` is used in `extraInstallCommands` to install additional files that were extracted from the AppImage.
|
||||
`wrapType2` automatically extracts the AppImage for you and makes it available via the `contents` attribute.
|
||||
Note how `finalAttrs.contents` is used in `extraInstallCommands` to install additional files that were extracted from the AppImage.
|
||||
|
||||
```nix
|
||||
{ appimageTools, fetchurl }:
|
||||
let
|
||||
appimageTools.wrapType2 (finalAttrs: {
|
||||
pname = "irccloud";
|
||||
version = "0.16.0";
|
||||
|
||||
@@ -102,27 +99,24 @@ let
|
||||
hash = "sha256-/hMPvYdnVB1XjKgU2v47HnVvW4+uC3rhRjbucqin4iI=";
|
||||
};
|
||||
|
||||
appimageContents = appimageTools.extract { inherit pname version src; };
|
||||
in
|
||||
appimageTools.wrapType2 {
|
||||
inherit pname version src;
|
||||
|
||||
extraPkgs = pkgs: [ pkgs.at-spi2-core ];
|
||||
|
||||
extraInstallCommands = ''
|
||||
mv $out/bin/irccloud-${version} $out/bin/irccloud
|
||||
install -m 444 -D ${appimageContents}/irccloud.desktop $out/share/applications/irccloud.desktop
|
||||
install -m 444 -D ${appimageContents}/usr/share/icons/hicolor/512x512/apps/irccloud.png \
|
||||
install -m 444 -D ${finalAttrs.contents}/irccloud.desktop $out/share/applications/irccloud.desktop
|
||||
install -m 444 -D ${finalAttrs.contents}/usr/share/icons/hicolor/512x512/apps/irccloud.png \
|
||||
$out/share/icons/hicolor/512x512/apps/irccloud.png
|
||||
substituteInPlace $out/share/applications/irccloud.desktop \
|
||||
--replace-fail 'Exec=AppRun' 'Exec=irccloud'
|
||||
'';
|
||||
}
|
||||
})
|
||||
```
|
||||
|
||||
:::
|
||||
|
||||
The argument passed to `extract` can also contain a `postExtract` attribute, which allows you to execute additional commands after the files are extracted from the AppImage.
|
||||
`appimageTools` also exposes the `extract` function should you need to do it manually, requiring `pname`, `version`, and `src` arguments (`src` being the AppImage file to extract).
|
||||
|
||||
The arguments passed to `extract` can also contain a `postExtract` attribute, which allows you to execute additional commands after the files are extracted from the AppImage.
|
||||
`postExtract` must be a string with commands to run.
|
||||
|
||||
:::{.warning}
|
||||
@@ -138,7 +132,7 @@ This is a rewrite of [](#ex-extracting-appimage) to use `postExtract` and `wrapA
|
||||
|
||||
```nix
|
||||
{ appimageTools, fetchurl }:
|
||||
let
|
||||
appimageTools.wrapAppImage (finalAttrs: {
|
||||
pname = "irccloud";
|
||||
version = "0.16.0";
|
||||
|
||||
@@ -147,30 +141,22 @@ let
|
||||
hash = "sha256-/hMPvYdnVB1XjKgU2v47HnVvW4+uC3rhRjbucqin4iI=";
|
||||
};
|
||||
|
||||
appimageContents = appimageTools.extract {
|
||||
inherit pname version src;
|
||||
contents = appimageTools.extract {
|
||||
inherit (finalAttrs) pname version src;
|
||||
postExtract = ''
|
||||
substituteInPlace $out/irccloud.desktop --replace-fail 'Exec=AppRun' 'Exec=irccloud'
|
||||
'';
|
||||
};
|
||||
in
|
||||
appimageTools.wrapAppImage {
|
||||
inherit pname version;
|
||||
|
||||
src = appimageContents;
|
||||
|
||||
extraPkgs = pkgs: [ pkgs.at-spi2-core ];
|
||||
|
||||
extraInstallCommands = ''
|
||||
mv $out/bin/irccloud-${version} $out/bin/irccloud
|
||||
install -m 444 -D ${appimageContents}/irccloud.desktop $out/share/applications/irccloud.desktop
|
||||
install -m 444 -D ${appimageContents}/usr/share/icons/hicolor/512x512/apps/irccloud.png \
|
||||
install -m 444 -D ${finalAttrs.contents}/irccloud.desktop $out/share/applications/irccloud.desktop
|
||||
install -m 444 -D ${finalAttrs.contents}/usr/share/icons/hicolor/512x512/apps/irccloud.png \
|
||||
$out/share/icons/hicolor/512x512/apps/irccloud.png
|
||||
'';
|
||||
|
||||
# specify src archive for nix-update
|
||||
passthru.src = src;
|
||||
}
|
||||
})
|
||||
```
|
||||
|
||||
:::
|
||||
|
||||
@@ -741,7 +741,7 @@ Notable attributes:
|
||||
|
||||
Compliance suite for [modular service](https://nixos.org/manual/nixos/unstable/#modular-services) integrations.
|
||||
|
||||
Tests that a service manager integration correctly handles the portable modular services contract: `process.argv`, `process.environment` (including `null` values that unset a variable), sub-services, assertions, and warnings.
|
||||
Tests that a service manager integration correctly handles the portable modular services contract: `process.argv`, sub-services, assertions, and warnings.
|
||||
|
||||
### Return value {#tester-modularServiceCompliance-return}
|
||||
|
||||
|
||||
@@ -129,6 +129,8 @@
|
||||
|
||||
- `super-productivity` has been updated. The binary has been renamed from `super-productivity` to `superproductivity`. A symlink from the old name is provided for backward compatibility.
|
||||
|
||||
- `buildFHSEnv`, `appimageTools.wrapAppImage`, and `appimageTools.wrapType2` now support the `finalAttrs` pattern. When using `wrapAppImage`, it is now recommended to pass the extracted AppImage to the `contents` attribute (instead of `src`), to avoid shadowing `src`. Passing the extracted contents to `src` is now deprecated and will be removed in a future release.
|
||||
|
||||
- Package-URL (PURL, https://github.com/package-url/purl-spec) metadata identifier has been added for `fetchgit`, `fetchpypi` and `fetchFromGithub` fetchers.
|
||||
`mkDerivation` has been adjusted to reuse this information.
|
||||
Package-URLs allow reliably identifying and locating software packages.
|
||||
|
||||
@@ -199,7 +199,8 @@
|
||||
&& system != "riscv64-linux"
|
||||
# Exclude x86_64-freebsd because "Package ‘go-1.22.12-freebsd-amd64-bootstrap’ in /nix/store/0yw40qnrar3lvc5hax5n49abl57apjbn-source/pkgs/development/compilers/go/binary.nix:50 is not available on the requested hostPlatform"
|
||||
&& system != "x86_64-freebsd"
|
||||
) (forAllSystems (system: (import ./ci { inherit system; }).fmt.pkg));
|
||||
# TODO: revert to importing fmt.pkg directly from ./ci when support for 26.05 ends
|
||||
) (forAllSystems (system: (import ./shell.nix { inherit system; }).formatter));
|
||||
|
||||
/**
|
||||
A nested structure of [packages](https://nix.dev/manual/nix/latest/glossary#package-attribute-set) and other values.
|
||||
|
||||
@@ -1259,6 +1259,11 @@ lib.mapAttrs mkLicense (
|
||||
fullName = "SIL Open Font License 1.1";
|
||||
};
|
||||
|
||||
ogluk30 = {
|
||||
spdxId = "OGL-UK-3.0";
|
||||
fullName = "Open Government Licence v3.0";
|
||||
};
|
||||
|
||||
oml = {
|
||||
spdxId = "OML";
|
||||
fullName = "Open Market License";
|
||||
@@ -1421,9 +1426,8 @@ lib.mapAttrs mkLicense (
|
||||
};
|
||||
|
||||
stk = {
|
||||
shortName = "stk";
|
||||
fullName = "Synthesis Tool Kit 4.3";
|
||||
url = "https://github.com/thestk/stk/blob/master/LICENSE";
|
||||
spdxId = "MIT-STK";
|
||||
fullName = "MIT-STK License";
|
||||
};
|
||||
|
||||
sudo = {
|
||||
|
||||
@@ -70,26 +70,6 @@ in
|
||||
Command used for reloading in the underlying service manager to reload.
|
||||
'';
|
||||
};
|
||||
|
||||
environment = lib.mkOption {
|
||||
type = types.lazyAttrsOf (
|
||||
types.nullOr (types.coercedTo (types.either types.path types.package) (x: "${x}") types.str)
|
||||
);
|
||||
default = { };
|
||||
example = lib.literalExpression ''{ FOO = "bar"; PATH = null; }'';
|
||||
description = ''
|
||||
Environment variables passed verbatim to the service process by the
|
||||
service manager. Entries set to `null` actively unset the variable
|
||||
before the process starts -- backends without native unset support use
|
||||
a wrapper (e.g. `execline`'s `unexport`) so the variable is absent
|
||||
even when the service manager or a backend-specific override would
|
||||
otherwise supply it.
|
||||
|
||||
Values appear in the rendered unit and may be world-readable. For
|
||||
secrets, use a backend-specific mechanism such as
|
||||
`systemd.service.serviceConfig.EnvironmentFile`.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
notificationProtocol = mkOption {
|
||||
|
||||
@@ -48,10 +48,6 @@ let
|
||||
(dummyPkg "cowsay.sh")
|
||||
"world"
|
||||
];
|
||||
environment = {
|
||||
FOO = "bar";
|
||||
DROPPED = null;
|
||||
};
|
||||
};
|
||||
};
|
||||
service3 = {
|
||||
@@ -114,7 +110,6 @@ let
|
||||
"/usr/bin/echo"
|
||||
"hello"
|
||||
];
|
||||
environment = { };
|
||||
};
|
||||
services = { };
|
||||
assertions = [
|
||||
@@ -133,10 +128,6 @@ let
|
||||
"${dummyPkg "cowsay.sh"}"
|
||||
"world"
|
||||
];
|
||||
environment = {
|
||||
FOO = "bar";
|
||||
DROPPED = null;
|
||||
};
|
||||
};
|
||||
services = { };
|
||||
assertions = [ ];
|
||||
@@ -145,7 +136,6 @@ let
|
||||
service3 = {
|
||||
process = {
|
||||
argv = [ "/bin/false" ];
|
||||
environment = { };
|
||||
};
|
||||
services.exclacow = {
|
||||
process = {
|
||||
@@ -153,7 +143,6 @@ let
|
||||
"${dummyPkg "cowsay-ng"}/bin/cowsay"
|
||||
"!"
|
||||
];
|
||||
environment = { };
|
||||
};
|
||||
services = { };
|
||||
assertions = [
|
||||
|
||||
@@ -1173,6 +1173,12 @@
|
||||
}
|
||||
];
|
||||
};
|
||||
albfsg = {
|
||||
name = "Alberto Francisco Solaz García";
|
||||
github = "albfsg";
|
||||
githubId = 227897008;
|
||||
email = "albfsg@proton.me";
|
||||
};
|
||||
alch-emi = {
|
||||
email = "emi@alchemi.dev";
|
||||
github = "Alch-Emi";
|
||||
@@ -7333,6 +7339,13 @@
|
||||
githubId = 39825;
|
||||
name = "Dominik Honnef";
|
||||
};
|
||||
donottellmetonottellyou = {
|
||||
name = "Jade Masker";
|
||||
email = "donottellmetonottellyou@gmail.com";
|
||||
github = "donottellmetonottellyou";
|
||||
githubId = 115233539;
|
||||
keys = [ { fingerprint = "5C8B 7128 4AB3 000D 4AC6 6234 9B81 35A2 4A75 CB86"; } ];
|
||||
};
|
||||
donovanglover = {
|
||||
github = "donovanglover";
|
||||
githubId = 2374245;
|
||||
@@ -12953,11 +12966,6 @@
|
||||
name = "Jez Cope";
|
||||
keys = [ { fingerprint = "D9DA 3E47 E8BD 377D A317 B3D0 9E42 CE07 1C45 59D1"; } ];
|
||||
};
|
||||
jf-uu = {
|
||||
github = "jf-uu";
|
||||
githubId = 181011550;
|
||||
name = "jf-uu";
|
||||
};
|
||||
jfchevrette = {
|
||||
email = "jfchevrette@gmail.com";
|
||||
github = "jfchevrette";
|
||||
@@ -13574,6 +13582,12 @@
|
||||
name = "Jonas Wunderlich";
|
||||
matrix = "@matrix:03j.de";
|
||||
};
|
||||
jonascarpay = {
|
||||
name = "Jonas Carpay";
|
||||
email = "jonascarpay@gmail.com";
|
||||
github = "jonascarpay";
|
||||
githubId = 3593851;
|
||||
};
|
||||
jonasfranke = {
|
||||
name = "Jonas Franke";
|
||||
email = "info@jonasfranke.xyz";
|
||||
@@ -18861,6 +18875,11 @@
|
||||
githubId = 45770;
|
||||
name = "Mitsuhiro Nakamura";
|
||||
};
|
||||
MNThomson = {
|
||||
github = "MNThomson";
|
||||
githubId = 73045936;
|
||||
name = "Max Thomson";
|
||||
};
|
||||
moaxcp = {
|
||||
email = "moaxcp@gmail.com";
|
||||
github = "moaxcp";
|
||||
@@ -20275,6 +20294,12 @@
|
||||
github = "niklaskorz";
|
||||
githubId = 590517;
|
||||
};
|
||||
niklasravnsborg = {
|
||||
name = "Niklas Ravnsborg";
|
||||
github = "niklasravnsborg";
|
||||
githubId = 6717303;
|
||||
keys = [ { fingerprint = "0C90 DD8A 0EE9 93DF 8D58 7AF9 8360 E6C5 8AE8 F3ED"; } ];
|
||||
};
|
||||
niklasthorild = {
|
||||
name = "Niklas Thorild";
|
||||
email = "niklas@thorild.se";
|
||||
@@ -23308,6 +23333,13 @@
|
||||
github = "DaRacci";
|
||||
githubId = 90304606;
|
||||
};
|
||||
rachalaraj = {
|
||||
name = "Rachala Raj Kumar";
|
||||
email = "rachaalaraj@gmail.com";
|
||||
matrix = "@rachalaraj:matrix.org";
|
||||
github = "rachalaraj";
|
||||
githubId = 124191100;
|
||||
};
|
||||
RadxaYuntian = {
|
||||
# This is the work account for @MakiseKurisu
|
||||
name = "ZHANG Yuntian";
|
||||
@@ -29365,6 +29397,11 @@
|
||||
github = "UnsolvedCypher";
|
||||
githubId = 3170853;
|
||||
};
|
||||
untio11 = {
|
||||
name = "Robin Kneepkens";
|
||||
github = "untio11";
|
||||
githubId = 14060658;
|
||||
};
|
||||
uralbash = {
|
||||
email = "root@uralbash.ru";
|
||||
github = "uralbash";
|
||||
|
||||
@@ -1,39 +0,0 @@
|
||||
#!/usr/bin/env nix-shell
|
||||
#!nix-shell -i bash
|
||||
#!nix-shell -p jq git
|
||||
# shellcheck shell=bash
|
||||
#
|
||||
# Usage: eval-pkg-sets.sh [extra flags for nix-* commands ...]
|
||||
#
|
||||
# Must be executed in a git checkout of Nixpkgs.
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
NIXPKGS="$(git rev-parse --show-toplevel)"
|
||||
PKGSETS="$(nix-env --readonly-mode --json --drv-path -f "$NIXPKGS" -qaP -A haskell.compiler "$@" \
|
||||
| jq -r 'to_entries | unique_by(.value.drvPath) .[] .key | sub("^haskell.compiler";"haskell.packages")')"
|
||||
|
||||
trap 'exit 1' SIGINT SIGTERM
|
||||
|
||||
set +e
|
||||
|
||||
badsets=""
|
||||
for set in $PKGSETS; do
|
||||
# Confirm an equivalent package set to haskell.compiler.$entry exists and is usable
|
||||
if ! nix-instantiate --readonly-mode -A "$set.ghc" "$@" > /dev/null 2>&1; then
|
||||
echo "Skipping $set... ($set.ghc does not evaluate)"
|
||||
else
|
||||
echo "Evaluating $set..."
|
||||
|
||||
if ! nix-env --readonly-mode -f "$NIXPKGS" -qaP --drv-path -A "$set" "$@" > /dev/null; then
|
||||
badsets+="$set "
|
||||
fi
|
||||
fi
|
||||
done
|
||||
|
||||
if [ -n "$badsets" ]; then
|
||||
echo "Found potential eval issues in the following sets:" >&2
|
||||
# shellcheck disable=SC2086
|
||||
printf '%s\n' $badsets
|
||||
exit 1
|
||||
fi
|
||||
@@ -33,7 +33,7 @@ fi
|
||||
|
||||
# Stackage solver to use, LTS or Nightly
|
||||
# (should be capitalized like the display name)
|
||||
SOLVER=Nightly
|
||||
SOLVER=LTS
|
||||
# Stackage solver verson, if any. Use latest if empty
|
||||
VERSION=
|
||||
TMP_TEMPLATE=update-stackage.XXXXXXX
|
||||
@@ -105,7 +105,6 @@ sed -r \
|
||||
-e '/ hledger-ui /d' \
|
||||
-e '/ hledger-web /d' \
|
||||
-e '/ spacecookie /d' \
|
||||
-e '/ hnix-store-core /d' \
|
||||
< "${tmpfile_new}" >> $stackage_config
|
||||
# Explanations:
|
||||
# cabal2nix, distribution-nixpkgs, jailbreak-cabal, language-nix: These are our packages and we know what we are doing.
|
||||
|
||||
@@ -152,16 +152,7 @@ let
|
||||
};
|
||||
|
||||
systemdServiceOptions = buildPackages.nixosOptionsDoc {
|
||||
inherit
|
||||
(evalModules {
|
||||
modules = [
|
||||
(modules.importApply ../../modules/system/service/systemd/service.nix {
|
||||
pkgs = throw "nixos docs / systemdServiceOptions: Do not reference pkgs in docs";
|
||||
})
|
||||
];
|
||||
})
|
||||
options
|
||||
;
|
||||
inherit (evalModules { modules = [ ../../modules/system/service/systemd/service.nix ]; }) options;
|
||||
# TODO: filter out options that are not systemd-specific, maybe also change option prefix to just `service-opt-`?
|
||||
inherit revision warningsAreErrors;
|
||||
transformOptions =
|
||||
|
||||
@@ -129,7 +129,7 @@
|
||||
|
||||
- [nvme-rs](https://github.com/liberodark/nvme-rs), NVMe monitoring [services.nvme-rs](#opt-services.nvme-rs.enable).
|
||||
|
||||
- [Overseerr](https://overseerr.dev), a request management and media discovery tool for the Plex ecosystem. Available as [services.overseerr](#opt-services.overseerr.enable).
|
||||
- [Overseerr](https://overseerr.dev), a request management and media discovery tool for the Plex ecosystem. Available as {option}`opt-services.overseerr.enable`.
|
||||
|
||||
- [PairDrop](https://github.com/schlagmichdoch/pairdrop), a peer-to-peer file transfer web app. Available as [services.pairdrop](#opt-services.pairdrop.enable).
|
||||
|
||||
|
||||
@@ -84,7 +84,7 @@
|
||||
|
||||
- [PdfDing](https://www.pdfding.com/), manage, view and edit your PDFs seamlessly on all your devices wherever you are. Available as [services.pdfding](#opt-services.pdfding.enable).
|
||||
|
||||
- [mangowc](https://github.com/DreamMaoMao/mangowc), a lightweight and feature-rich Wayland compositor based on dwl. Available as [programs.mangowc](#opt-programs.mangowc.enable).
|
||||
- [mangowc](https://github.com/DreamMaoMao/mangowc), a lightweight and feature-rich Wayland compositor based on dwl. Available as [programs.mangowc](#opt-programs.mango.enable).
|
||||
|
||||
- [reaction](https://reaction.ppom.me/), a daemon that scans program outputs for repeated patterns, and takes action. A common usage is to scan ssh and webserver logs, and to ban hosts that cause multiple authentication errors. A modern alternative to fail2ban. Available as [services.reaction](#opt-services.reaction.enable).
|
||||
|
||||
|
||||
@@ -89,9 +89,9 @@
|
||||
|
||||
- Apache Kafka has dropped support for ZooKeeper mode. The `apacheKafka_3_9` and `apacheKafka_4_0` packages have been removed, as every remaining packaged version is KRaft-only. The `services.apache-kafka.zookeeper` option (previously an alias for `services.apache-kafka.settings."zookeeper.connect"`) has been removed; migrate your cluster to [KRaft](#module-services-apache-kafka-kraft) mode instead.
|
||||
|
||||
- `virtualisation.registries.block` / `insecure` / `search` were deprecated,
|
||||
- `virtualisation.containers.registries.block` / `insecure` / `search` were deprecated,
|
||||
because they mapped to the deprecated V1 `registries.conf` format.
|
||||
See the new option {option}`virtualisation.registries.settings`
|
||||
See the new option {option}`virtualisation.containers.registries.settings`
|
||||
and [containers-registries.conf(5)](https://github.com/containers/image/blob/main/docs/containers-registries.conf.5.md)
|
||||
to migrate to the new configuration format.
|
||||
|
||||
@@ -113,6 +113,8 @@
|
||||
|
||||
- `services.komodo-periphery` has been updated to support version 2.0.0. Some options have been renamed to match the new configuration structure; compatibility aliases are provided for the renamed options. The `passkeys` and `outbound.onboardingKey` options have been removed; use `passkeyFiles`, `auth.privateKey`/`auth.corePublicKeys`, or `outbound.onboardingKeyFile` instead. New outbound mode configuration is available under `outbound.*`.
|
||||
|
||||
- Package `overseerr` has been removed as the `overseerr` and `jellyseerr` projects were merged under `seerr`.
|
||||
|
||||
## Other Notable Changes {#sec-release-26.11-notable-changes}
|
||||
|
||||
<!-- To avoid merge conflicts, consider adding your item at an arbitrary place in the list instead. -->
|
||||
@@ -140,6 +142,8 @@
|
||||
|
||||
- `security.run0.persistentAuth` options have been added to support persistent Authentication of session. Timeout configurable via `security.polkit.settings.Polkitd.ExpirationSeconds`.
|
||||
|
||||
- [`virtualisation.qemu.firmware.enable`](#opt-virtualisation.qemu.firmware.enable) has been added to install QEMU firmware descriptors to {file}`/etc/qemu/firmware`, making the corresponding firmware images discoverable by tools such as `systemd-vmspawn`. By default this exposes the firmware bundled with QEMU. Further firmware can be added via [`virtualisation.qemu.firmware.packages`](#opt-virtualisation.qemu.firmware.packages), for example the new `OVMF-amdsev` and `OVMF-inteltdx` packages, which provide UEFI firmware for AMD SEV-SNP and Intel TDX confidential VMs.
|
||||
|
||||
- `boot.loader.systemd-boot` gained support for [Automatic Boot Assessment](https://systemd.io/AUTOMATIC_BOOT_ASSESSMENT/) via the new [`boot.loader.systemd-boot.bootCounting`](#opt-boot.loader.systemd-boot.bootCounting.enable) options, allowing automatic detection of and recovery from bad NixOS generations. As part of this change, boot loader entries on the ESP/XBOOTLDR partition are now named `nixos-<content-hash>.conf` instead of `nixos-generation-<n>.conf`; existing entries are migrated automatically on the next `nixos-rebuild boot`/`switch`.
|
||||
|
||||
- `services.nginx` gained a [`lua`](#opt-services.nginx.lua.enable) option to enable Lua scripting via OpenResty's lua-nginx-module on a stock nginx, configuring `lua_package_path`/`lua_package_cpath` from the packages listed in [`services.nginx.lua.extraPackages`](#opt-services.nginx.lua.extraPackages). Use this to add Lua to a regular nginx; for the full OpenResty platform (libraries that rely on its bundled lualib, such as `lua-resty-openidc`), set `services.nginx.package` to `pkgs.openresty` instead — the option configures the Lua search path for it too.
|
||||
|
||||
@@ -355,7 +355,7 @@
|
||||
./programs/wayland/hyprland.nix
|
||||
./programs/wayland/hyprlock.nix
|
||||
./programs/wayland/labwc.nix
|
||||
./programs/wayland/mangowc.nix
|
||||
./programs/wayland/mango.nix
|
||||
./programs/wayland/miracle-wm.nix
|
||||
./programs/wayland/niri.nix
|
||||
./programs/wayland/pinnacle.nix
|
||||
@@ -938,7 +938,6 @@
|
||||
./services/misc/open-webui.nix
|
||||
./services/misc/orthanc.nix
|
||||
./services/misc/osrm.nix
|
||||
./services/misc/overseerr.nix
|
||||
./services/misc/owncast.nix
|
||||
./services/misc/packagekit.nix
|
||||
./services/misc/paisa.nix
|
||||
@@ -2052,6 +2051,7 @@
|
||||
./virtualisation/openvswitch.nix
|
||||
./virtualisation/parallels-guest.nix
|
||||
./virtualisation/podman/default.nix
|
||||
./virtualisation/qemu-firmware.nix
|
||||
./virtualisation/qemu-guest-agent.nix
|
||||
./virtualisation/rosetta.nix
|
||||
./virtualisation/spice-usb-redirection.nix
|
||||
|
||||
@@ -14,56 +14,93 @@ in
|
||||
Miriway, a Mir based Wayland compositor. You can manually launch Miriway by
|
||||
executing "exec miriway" on a TTY, or launch it from a display manager. Copy
|
||||
/etc/xdg/xdg-miriway/miriway-shell.config to ~/.config/miriway-shell.config
|
||||
and /etc/xdg/xdg-miriway/miriway-shell.settings to ~/.config/miriway-shell.settings
|
||||
to modify the system-wide configuration on a per-user basis. See <https://github.com/Miriway/Miriway>,
|
||||
and "miriway --help" for more information'';
|
||||
|
||||
config = lib.mkOption {
|
||||
description = ''
|
||||
Contents of system-wide miriway-shell.config. See Miriway's configuration documentation for details.
|
||||
'';
|
||||
type = lib.types.lines;
|
||||
default = ''
|
||||
x11-window-title=Miriway (Mir-on-X)
|
||||
idle-timeout=600
|
||||
ctrl-alt=t:miriway-terminal # Default "terminal emulator finder"
|
||||
|
||||
shell-component=dbus-update-activation-environment --systemd DISPLAY WAYLAND_DISPLAY
|
||||
|
||||
meta=Left:@dock-left
|
||||
meta=Right:@dock-right
|
||||
meta=Space:@toggle-maximized
|
||||
meta=Home:@workspace-begin
|
||||
meta=End:@workspace-end
|
||||
meta=Page_Up:@workspace-up
|
||||
meta=Page_Down:@workspace-down
|
||||
ctrl-alt=BackSpace:@exit
|
||||
'';
|
||||
example = ''
|
||||
idle-timeout=300
|
||||
ctrl-alt=t:weston-terminal
|
||||
add-wayland-extensions=all
|
||||
|
||||
shell-components=dbus-update-activation-environment --systemd DISPLAY WAYLAND_DISPLAY
|
||||
|
||||
shell-component=waybar
|
||||
shell-component=wbg Pictures/wallpaper
|
||||
|
||||
shell-meta=a:synapse
|
||||
|
||||
meta=Left:@dock-left
|
||||
meta=Right:@dock-right
|
||||
meta=Space:@toggle-maximized
|
||||
meta=Home:@workspace-begin
|
||||
meta=End:@workspace-end
|
||||
meta=Page_Up:@workspace-up
|
||||
meta=Page_Down:@workspace-down
|
||||
ctrl-alt=BackSpace:@exit
|
||||
'';
|
||||
};
|
||||
|
||||
settings = lib.mkOption {
|
||||
description = ''
|
||||
Miriway's config. This will be installed system-wide.
|
||||
The default will install the miriway package's barebones example config.
|
||||
Contents of system-wide miriway-shell.settings. See Miriway's configuration documentation for details.
|
||||
'';
|
||||
type = lib.types.lines;
|
||||
default = ''
|
||||
command_ctrl_alt=t:miriway-terminal # Default "terminal emulator finder"
|
||||
|
||||
command_meta=Left:@dock-left
|
||||
command_meta=Right:@dock-right
|
||||
command_meta=Space:@toggle-maximized
|
||||
command_meta=Home:@workspace-begin
|
||||
command_meta=End:@workspace-end
|
||||
command_meta=Page_Up:@workspace-up
|
||||
command_meta=Page_Down:@workspace-down
|
||||
command_ctrl_alt=BackSpace:@exit
|
||||
'';
|
||||
example = ''
|
||||
command_ctrl_alt=t:weston-terminal
|
||||
command_shell_meta=a:synapse
|
||||
|
||||
command_meta=Left:@dock-left
|
||||
command_meta=Right:@dock-right
|
||||
command_meta=Space:@toggle-maximized
|
||||
command_meta=Home:@workspace-begin
|
||||
command_meta=End:@workspace-end
|
||||
command_meta=Page_Up:@workspace-up
|
||||
command_meta=Page_Down:@workspace-down
|
||||
command_ctrl_alt=BackSpace:@exit
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
warnings =
|
||||
let
|
||||
optionsNoLongerInConfig = [
|
||||
"ctrl-alt"
|
||||
"meta"
|
||||
"shell-ctrl-alt"
|
||||
"shell-meta"
|
||||
"shell-plain"
|
||||
|
||||
"command_ctrl_alt"
|
||||
"command_meta"
|
||||
"command_shell_ctrl_alt"
|
||||
"command_shell_meta"
|
||||
"command_plain"
|
||||
];
|
||||
in
|
||||
# Added 2026-07-17
|
||||
lib.optional
|
||||
(builtins.foldl' (
|
||||
acc: option: acc || (lib.strings.hasInfix "${option}=" cfg.config)
|
||||
) false optionsNoLongerInConfig)
|
||||
''
|
||||
Since Miriway 26.06, configuration options got partially renamed and split across different files.
|
||||
A new option `programs.miriway.settings` got introduced for options that belong into miriway-shell.settings
|
||||
instead of miriway-shell.config.
|
||||
|
||||
You appear to have one of the following options in `programs.miriway.config` that should now go into
|
||||
`programs.miriway.settings`, and may need to be renamed:
|
||||
${lib.strings.concatStringsSep ", " optionsNoLongerInConfig}
|
||||
'';
|
||||
|
||||
environment = {
|
||||
systemPackages = with pkgs; [
|
||||
miriway
|
||||
@@ -71,6 +108,7 @@ in
|
||||
];
|
||||
etc = {
|
||||
"xdg/xdg-miriway/miriway-shell.config".text = cfg.config;
|
||||
"xdg/xdg-miriway/miriway-shell.settings".text = cfg.settings;
|
||||
};
|
||||
};
|
||||
|
||||
|
||||
@@ -6,18 +6,22 @@
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.programs.mangowc;
|
||||
cfg = config.programs.mango;
|
||||
in
|
||||
{
|
||||
options.programs.mangowc = {
|
||||
enable = lib.mkEnableOption "MangoWC, a Wayland compositor based on dwl and scenefx";
|
||||
options.programs.mango = {
|
||||
enable = lib.mkEnableOption "Mango, a Wayland compositor based on dwl and scenefx";
|
||||
|
||||
package = lib.mkPackageOption pkgs "mangowc" {
|
||||
default = [ "mangowc" ];
|
||||
example = "pkgs.mangowc.override { enableXWayland = false; }";
|
||||
package = lib.mkPackageOption pkgs "mango" {
|
||||
default = [ "mango" ];
|
||||
example = "pkgs.mango.override { enableXWayland = false; }";
|
||||
};
|
||||
};
|
||||
|
||||
imports = [
|
||||
(lib.mkRenamedOptionModule [ "programs" "mangowc" ] [ "programs" "mango" ])
|
||||
];
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
environment.systemPackages = [ cfg.package ];
|
||||
|
||||
@@ -539,6 +539,13 @@ in
|
||||
(mkRemovedOptionModule [ "services" "xserver" "cmt" ] ''
|
||||
services.xserver.cmt has been removed as it was broken and unmaintained upstream
|
||||
'')
|
||||
(mkRemovedOptionModule
|
||||
[
|
||||
"services"
|
||||
"overseerr"
|
||||
]
|
||||
"`services.overseerr` has been replaced by `services.seerr` as the project has been merged with Jellyseerr under Seerr."
|
||||
)
|
||||
# Do NOT add any option renames here, see top of the file
|
||||
];
|
||||
}
|
||||
|
||||
@@ -242,7 +242,9 @@ let
|
||||
"elkm1"
|
||||
"elv"
|
||||
"enocean"
|
||||
"homeassistant_connect_zbt2"
|
||||
"homeassistant_hardware"
|
||||
"homeassistant_sky_connect"
|
||||
"homeassistant_yellow"
|
||||
"firmata"
|
||||
"flexit"
|
||||
|
||||
@@ -1,89 +0,0 @@
|
||||
{
|
||||
config,
|
||||
pkgs,
|
||||
lib,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.services.overseerr;
|
||||
in
|
||||
{
|
||||
meta.maintainers = [ lib.maintainers.jf-uu ];
|
||||
|
||||
options.services.overseerr = {
|
||||
enable = lib.mkEnableOption "Overseerr, a request management and media discovery tool for the Plex ecosystem";
|
||||
|
||||
package = lib.mkPackageOption pkgs "overseerr" { };
|
||||
|
||||
openFirewall = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "Open a port in the firewall for the Overseerr web interface.";
|
||||
};
|
||||
|
||||
port = lib.mkOption {
|
||||
type = lib.types.port;
|
||||
default = 5055;
|
||||
description = "The port which the Overseerr web UI should listen on.";
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
systemd.services.overseerr = {
|
||||
description = "Request management and media discovery tool for the Plex ecosystem";
|
||||
after = [ "network.target" ];
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
environment = {
|
||||
CONFIG_DIRECTORY = "/var/lib/overseerr";
|
||||
PORT = toString cfg.port;
|
||||
};
|
||||
serviceConfig = {
|
||||
CapabilityBoundingSet = "";
|
||||
DynamicUser = true;
|
||||
ExecStart = lib.getExe cfg.package;
|
||||
LockPersonality = true;
|
||||
NoNewPrivileges = true;
|
||||
PrivateDevices = true;
|
||||
PrivateIPC = true;
|
||||
PrivateMounts = true;
|
||||
PrivateTmp = true;
|
||||
PrivateUsers = true;
|
||||
ProcSubset = "pid";
|
||||
ProtectClock = true;
|
||||
ProtectControlGroups = true;
|
||||
ProtectHome = true;
|
||||
ProtectHostname = true;
|
||||
ProtectKernelLogs = true;
|
||||
ProtectKernelModules = true;
|
||||
ProtectKernelTunables = true;
|
||||
ProtectProc = "invisible";
|
||||
ProtectSystem = "strict";
|
||||
RemoveIPC = true;
|
||||
Restart = "on-failure";
|
||||
RestrictAddressFamilies = [
|
||||
"AF_INET"
|
||||
"AF_INET6"
|
||||
"AF_UNIX"
|
||||
];
|
||||
RestrictNamespaces = true;
|
||||
RestrictRealtime = true;
|
||||
RestrictSUIDSGID = true;
|
||||
StateDirectory = "overseerr";
|
||||
StateDirectoryMode = "0700";
|
||||
SystemCallArchitectures = "native";
|
||||
SystemCallErrorNumber = "EPERM";
|
||||
SystemCallFilter = [
|
||||
"@system-service"
|
||||
"~@privileged"
|
||||
"~@resources"
|
||||
];
|
||||
Type = "exec";
|
||||
};
|
||||
};
|
||||
|
||||
networking.firewall = lib.mkIf cfg.openFirewall {
|
||||
allowedTCPPorts = [ cfg.port ];
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -988,8 +988,9 @@ in
|
||||
systemd.services.nsd = {
|
||||
description = "NSD authoritative only domain name service";
|
||||
|
||||
after = [ "network.target" ];
|
||||
after = [ "network-online.target" ];
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
wants = [ "network-online.target" ];
|
||||
|
||||
startLimitBurst = 4;
|
||||
startLimitIntervalSec = 5 * 60; # 5 mins
|
||||
|
||||
@@ -115,7 +115,7 @@ in
|
||||
default = true;
|
||||
description = ''
|
||||
Whether unbound should resolve local queries (i.e. add 127.0.0.1 to
|
||||
/etc/resolv.conf).
|
||||
/etc/resolv.conf and set name servers to localhost respectively).
|
||||
'';
|
||||
};
|
||||
|
||||
@@ -276,6 +276,7 @@ in
|
||||
resolvconf = {
|
||||
useLocalResolver = mkDefault true;
|
||||
};
|
||||
nameservers = lib.mkBefore ([ "127.0.0.1" ] ++ (optional config.networking.enableIPv6 "::1"));
|
||||
};
|
||||
|
||||
environment.etc."unbound/unbound.conf".source = confFile;
|
||||
|
||||
@@ -36,8 +36,14 @@ let
|
||||
|
||||
userbornConfigJson = pkgs.writeText "userborn.json" (builtins.toJSON userbornConfig);
|
||||
userbornStaticFiles =
|
||||
pkgs.runCommand "static-userborn" { }
|
||||
"mkdir -p $out; ${lib.getExe cfg.package} ${userbornConfigJson} $out";
|
||||
pkgs.runCommand "static-userborn"
|
||||
{
|
||||
nativeBuildInputs = [ cfg.package ];
|
||||
}
|
||||
''
|
||||
mkdir -p $out
|
||||
userborn ${userbornConfigJson} $out
|
||||
'';
|
||||
previousConfigPath = "/var/lib/userborn/previous-userborn.json";
|
||||
|
||||
immutableEtc = config.system.etc.overlay.enable && !config.system.etc.overlay.mutable;
|
||||
|
||||
@@ -1,9 +1,3 @@
|
||||
# Non-module arguments
|
||||
# These are separate from the module arguments to avoid implicit dependencies.
|
||||
# This makes service modules self-contained, allowing mixing of Nixpkgs versions.
|
||||
{ pkgs }:
|
||||
|
||||
# The module
|
||||
{
|
||||
lib,
|
||||
config,
|
||||
@@ -98,11 +92,6 @@ in
|
||||
to prevent systemd substitution. Set this option explicitly to enable
|
||||
systemd's substitution features.
|
||||
|
||||
When {option}`process.environment` contains keys set to `null`, the default
|
||||
is automatically prefixed with `unexport KEY` invocations (from
|
||||
`pkgs.execline`) so those variables are unset before the process starts,
|
||||
regardless of what `Environment=` or inherited environment supplies.
|
||||
|
||||
To extend {option}`process.argv` with systemd specifiers, you can append
|
||||
to the escaped arguments:
|
||||
|
||||
@@ -120,19 +109,8 @@ in
|
||||
for available specifiers like `%n`, `%i`, `%t`.
|
||||
'';
|
||||
type = types.str;
|
||||
default =
|
||||
let
|
||||
nullEnvKeys = lib.attrNames (lib.filterAttrs (_: v: v == null) config.process.environment);
|
||||
in
|
||||
if nullEnvKeys == [ ] then
|
||||
config.systemd.lib.escapeSystemdExecArgs config.process.argv
|
||||
else
|
||||
lib.concatMapStringsSep " " (
|
||||
k: "${escapeSystemdExecArg "${pkgs.execline}/bin/unexport"} ${escapeSystemdExecArg k}"
|
||||
) nullEnvKeys
|
||||
+ " "
|
||||
+ config.systemd.lib.escapeSystemdExecArgs config.process.argv;
|
||||
defaultText = lib.literalMD "The escaped `process.argv`, prefixed with `\"unexport\" \"KEY\"` (from `pkgs.execline`) for each key in `process.environment` set to `null`.";
|
||||
default = config.systemd.lib.escapeSystemdExecArgs config.process.argv;
|
||||
defaultText = lib.literalExpression "config.systemd.lib.escapeSystemdExecArgs config.process.argv";
|
||||
};
|
||||
|
||||
systemd.mainExecReload = mkOption {
|
||||
@@ -209,7 +187,7 @@ in
|
||||
types.submoduleWith {
|
||||
class = "service";
|
||||
modules = [
|
||||
(lib.modules.importApply ./service.nix { inherit pkgs; })
|
||||
./service.nix
|
||||
];
|
||||
specialArgs = {
|
||||
inherit systemdPackage;
|
||||
@@ -229,9 +207,6 @@ in
|
||||
systemd.services."" = {
|
||||
# TODO description;
|
||||
wantedBy = lib.mkDefault [ "multi-user.target" ];
|
||||
environment = lib.mapAttrs (_: lib.mkDefault) (
|
||||
lib.filterAttrs (_: v: v != null) config.process.environment
|
||||
);
|
||||
serviceConfig = {
|
||||
ExecReload = config.systemd.mainExecReload;
|
||||
Type = lib.mkDefault (if config.notificationProtocol.systemd then "notify" else "simple");
|
||||
|
||||
@@ -63,7 +63,7 @@ let
|
||||
modularServiceConfiguration = portable-lib.configure {
|
||||
serviceManagerPkgs = pkgs;
|
||||
extraRootModules = [
|
||||
(lib.modules.importApply ./service.nix { inherit pkgs; })
|
||||
./service.nix
|
||||
./config-data-path.nix
|
||||
];
|
||||
extraRootSpecialArgs = {
|
||||
|
||||
@@ -76,40 +76,6 @@ let
|
||||
};
|
||||
};
|
||||
|
||||
# Test that `process.environment` becomes `Environment=` entries on the unit,
|
||||
# that null values are dropped from `Environment=` and wrapped with unexport
|
||||
# in `ExecStart`.
|
||||
system.services.envvars = {
|
||||
process = {
|
||||
argv = [ hello' ];
|
||||
environment = {
|
||||
FOO = "bar";
|
||||
BAZ = "qux";
|
||||
DROPPED = null;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
# Test that an explicit `systemd.service.environment` override wins over
|
||||
# the portable default produced by `process.environment`.
|
||||
system.services.envvars-override = {
|
||||
process = {
|
||||
argv = [ hello' ];
|
||||
environment.FOO = "from-process";
|
||||
};
|
||||
systemd.service.environment.FOO = "from-systemd";
|
||||
};
|
||||
|
||||
# Test that `process.environment` `null` unsets via wrapper even when the
|
||||
# systemd layer sets the same key (true unset, not just "skip setting").
|
||||
system.services.envvars-unset = {
|
||||
process = {
|
||||
argv = [ hello' ];
|
||||
environment.FOO = null;
|
||||
};
|
||||
systemd.service.environment.FOO = "leaked";
|
||||
};
|
||||
|
||||
# Test extending process.argv with systemd specifiers
|
||||
system.services.argv-extended =
|
||||
{ config, ... }:
|
||||
@@ -171,22 +137,6 @@ runCommand "test-modular-service-systemd-units"
|
||||
# The base command should be escaped ($1 -> $$1, m%n -> m%%n), but the appended --systemd-unit %n should not be
|
||||
grep -F 'ExecStart="${hello}/bin/hello" "--greeting" "Fun $$1 fact, remainder is often expressed as m%%n" --systemd-unit %n' ${toplevel}/etc/systemd/system/argv-extended.service >/dev/null
|
||||
|
||||
# process.environment becomes Environment= entries; null values are dropped
|
||||
# from Environment= and wrapped with unexport in ExecStart.
|
||||
grep -F 'Environment="FOO=bar"' ${toplevel}/etc/systemd/system/envvars.service >/dev/null
|
||||
grep -F 'Environment="BAZ=qux"' ${toplevel}/etc/systemd/system/envvars.service >/dev/null
|
||||
! grep -F 'Environment=.*DROPPED' ${toplevel}/etc/systemd/system/envvars.service
|
||||
grep 'ExecStart=.*unexport.*DROPPED' ${toplevel}/etc/systemd/system/envvars.service >/dev/null
|
||||
|
||||
# systemd.service.environment override wins over process.environment.
|
||||
grep -F 'Environment="FOO=from-systemd"' ${toplevel}/etc/systemd/system/envvars-override.service >/dev/null
|
||||
! grep -F 'FOO=from-process' ${toplevel}/etc/systemd/system/envvars-override.service
|
||||
|
||||
# process.environment null uses unexport wrapper for true unset, even when
|
||||
# the systemd layer has an Environment= entry for the same key.
|
||||
grep -F 'Environment="FOO=leaked"' ${toplevel}/etc/systemd/system/envvars-unset.service >/dev/null
|
||||
grep 'ExecStart=.*unexport.*FOO' ${toplevel}/etc/systemd/system/envvars-unset.service >/dev/null
|
||||
|
||||
[[ ! -e ${toplevel}/etc/systemd/system/foo.socket ]]
|
||||
[[ ! -e ${toplevel}/etc/systemd/system/bar.socket ]]
|
||||
[[ ! -e ${toplevel}/etc/systemd/system/bar-db.socket ]]
|
||||
|
||||
@@ -69,7 +69,7 @@ in
|
||||
config = lib.mkIf (cfg.enable) {
|
||||
environment.systemPackages = [ cfg.package ];
|
||||
# we also want these mounts in virtual machines.
|
||||
fileSystems = if config.virtualisation ? qemu then lib.mkVMOverride mounts else mounts;
|
||||
fileSystems = if config.virtualisation.qemu ? package then lib.mkVMOverride mounts else mounts;
|
||||
|
||||
# We no longer need those when using envfs
|
||||
system.activationScripts.usrbinenv = lib.mkForce "";
|
||||
|
||||
@@ -196,7 +196,7 @@ in
|
||||
# that do not specify any nodes, or an empty attr set as nodes) will not
|
||||
# have the QEMU module loaded and thuse these options can't and should not
|
||||
# be set.
|
||||
virtualisation = lib.optionalAttrs (options ? virtualisation.qemu) {
|
||||
virtualisation = lib.optionalAttrs (options ? virtualisation.qemu.package) {
|
||||
qemu = {
|
||||
# NOTE: optionalAttrs
|
||||
# test-instrumentation.nix appears to be used without qemu-vm.nix, so
|
||||
|
||||
50
nixos/modules/virtualisation/qemu-firmware.nix
Normal file
50
nixos/modules/virtualisation/qemu-firmware.nix
Normal file
@@ -0,0 +1,50 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.virtualisation.qemu.firmware;
|
||||
in
|
||||
|
||||
{
|
||||
options.virtualisation.qemu.firmware = {
|
||||
enable = lib.mkEnableOption "QEMU firmware descriptors in {file}`/etc/qemu/firmware`";
|
||||
|
||||
packages = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.package;
|
||||
default = [ pkgs.qemu ];
|
||||
defaultText = lib.literalExpression "[ pkgs.qemu ]";
|
||||
example = lib.literalExpression "[ pkgs.qemu pkgs.OVMF-amdsev.fd ]";
|
||||
description = ''
|
||||
Packages providing QEMU firmware descriptors under
|
||||
{file}`share/qemu/firmware`, following the QEMU firmware interop
|
||||
convention (see {file}`docs/interop/firmware.json` in the QEMU
|
||||
source tree). The descriptors are merged and linked to
|
||||
{file}`/etc/qemu/firmware`, where tools like
|
||||
{command}`systemd-vmspawn` discover the firmware available for
|
||||
running virtual machines.
|
||||
|
||||
The default exposes the descriptors of the firmware images
|
||||
bundled with QEMU. Note that setting this option replaces the
|
||||
default, so include `pkgs.qemu` when adding further firmware.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
environment.etc."qemu/firmware".source =
|
||||
let
|
||||
merged = pkgs.buildEnv {
|
||||
name = "qemu-firmware-descriptors";
|
||||
paths = cfg.packages;
|
||||
pathsToLink = [ "/share/qemu/firmware" ];
|
||||
};
|
||||
in
|
||||
"${merged}/share/qemu/firmware";
|
||||
};
|
||||
|
||||
meta.maintainers = [ lib.maintainers.katexochen ];
|
||||
}
|
||||
@@ -1303,7 +1303,6 @@ in
|
||||
osrm-backend = runTest ./osrm-backend.nix;
|
||||
outline = runTest ./outline.nix;
|
||||
overlayfs = runTest ./overlayfs.nix;
|
||||
overseerr = runTest ./overseerr.nix;
|
||||
owi = runTest ./owi.nix;
|
||||
owncast = runTest ./owncast.nix;
|
||||
oxidized = handleTest ./oxidized.nix { };
|
||||
@@ -1449,6 +1448,7 @@ in
|
||||
pykms = runTest ./pykms.nix;
|
||||
qbittorrent = runTest ./qbittorrent.nix;
|
||||
qboot = runTestOn [ "x86_64-linux" "i686-linux" ] ./qboot.nix;
|
||||
qemu-firmware = runTestOn [ "x86_64-linux" ] ./qemu-firmware.nix;
|
||||
qemu-vm-external-disk-image = runTest ./qemu-vm-external-disk-image.nix;
|
||||
qemu-vm-restrictnetwork = handleTest ./qemu-vm-restrictnetwork.nix { };
|
||||
qemu-vm-store = runTest ./qemu-vm-store.nix;
|
||||
|
||||
@@ -33,13 +33,12 @@
|
||||
add-wayland-extensions=all
|
||||
enable-x11=
|
||||
|
||||
ctrl-alt=t:foot --maximized
|
||||
ctrl-alt=a:env WINIT_UNIX_BACKEND=x11 WAYLAND_DISPLAY= alacritty --option window.startup_mode=\"maximized\"
|
||||
|
||||
shell-component=dbus-update-activation-environment --systemd DISPLAY WAYLAND_DISPLAY
|
||||
|
||||
shell-component=foot --maximized
|
||||
'';
|
||||
settings = ''
|
||||
command_ctrl_alt=t:foot --maximized
|
||||
command_ctrl_alt=a:env WINIT_UNIX_BACKEND=x11 WAYLAND_DISPLAY= alacritty --option window.startup_mode=\"maximized\"
|
||||
'';
|
||||
};
|
||||
|
||||
environment = {
|
||||
@@ -59,8 +58,9 @@
|
||||
etc."xdg/foot/foot.ini".source = (pkgs.formats.ini { }).generate "foot.ini" {
|
||||
main = {
|
||||
font = "inconsolata:size=16";
|
||||
initial-color-theme = "light";
|
||||
};
|
||||
colors = rec {
|
||||
colors-light = rec {
|
||||
foreground = "000000";
|
||||
background = "ffffff";
|
||||
regular2 = foreground;
|
||||
|
||||
@@ -1,20 +0,0 @@
|
||||
{ lib, pkgs, ... }:
|
||||
{
|
||||
name = "overseerr";
|
||||
meta.maintainers = with lib.maintainers; [ jf-uu ];
|
||||
|
||||
nodes.machine =
|
||||
{ pkgs, ... }:
|
||||
{
|
||||
environment.systemPackages = [ pkgs.jq ];
|
||||
services.overseerr.enable = true;
|
||||
};
|
||||
|
||||
testScript = ''
|
||||
machine.wait_for_unit("overseerr.service")
|
||||
machine.wait_for_open_port(5055)
|
||||
|
||||
version = machine.succeed("curl --fail http://localhost:5055/api/v1/status | jq --raw-output .version").rstrip("\n")
|
||||
assert version == "${pkgs.overseerr.version}", f"expected version to be ${pkgs.overseerr.version}, got {version}"
|
||||
'';
|
||||
}
|
||||
41
nixos/tests/qemu-firmware.nix
Normal file
41
nixos/tests/qemu-firmware.nix
Normal file
@@ -0,0 +1,41 @@
|
||||
{ lib, ... }:
|
||||
|
||||
{
|
||||
name = "qemu-firmware";
|
||||
meta.maintainers = [ lib.maintainers.katexochen ];
|
||||
|
||||
nodes.machine =
|
||||
{ pkgs, ... }:
|
||||
{
|
||||
virtualisation.qemu.firmware = {
|
||||
enable = true;
|
||||
packages = [
|
||||
pkgs.qemu
|
||||
pkgs.OVMF-amdsev.fd
|
||||
pkgs.OVMF-inteltdx.fd
|
||||
];
|
||||
};
|
||||
environment.systemPackages = [ pkgs.jq ];
|
||||
};
|
||||
|
||||
testScript = ''
|
||||
machine.wait_for_unit("multi-user.target")
|
||||
|
||||
with subtest("descriptors are merged into /etc/qemu/firmware"):
|
||||
machine.succeed("test -e /etc/qemu/firmware/60-edk2-x86_64.json")
|
||||
machine.succeed("test -e /etc/qemu/firmware/61-edk2-ovmf-x64-amdsev.json")
|
||||
machine.succeed("test -e /etc/qemu/firmware/61-edk2-ovmf-x64-inteltdx.json")
|
||||
|
||||
with subtest("descriptors reference existing firmware images"):
|
||||
machine.succeed(
|
||||
"jq -er '.mapping | .filename // .executable.filename' "
|
||||
+ "/etc/qemu/firmware/*.json | xargs stat --"
|
||||
)
|
||||
|
||||
with subtest("systemd-vmspawn discovers the descriptors"):
|
||||
listed = machine.succeed("systemd-vmspawn --firmware=list")
|
||||
assert "61-edk2-ovmf-x64-amdsev.json" in listed
|
||||
assert "61-edk2-ovmf-x64-inteltdx.json" in listed
|
||||
assert "60-edk2-x86_64.json" in listed
|
||||
'';
|
||||
}
|
||||
@@ -91,6 +91,9 @@ let
|
||||
|
||||
click_when_unobstructed((By.XPATH, "//a[contains(., 'Skip to web app')]"))
|
||||
|
||||
# Skip the tour on first login
|
||||
click_when_unobstructed((By.XPATH, "//button[contains(., 'Skip')]"))
|
||||
|
||||
click_when_unobstructed((By.XPATH, "//button[contains(., 'New item')]"))
|
||||
|
||||
driver.find_element(By.XPATH, '//input[@formcontrolname="name"]').send_keys(
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
{
|
||||
lib,
|
||||
b4,
|
||||
melpaBuild,
|
||||
}:
|
||||
melpaBuild {
|
||||
pname = "b4-review-mode";
|
||||
inherit (b4) version;
|
||||
|
||||
src = b4.src-misc;
|
||||
sourceRoot = "${b4.src-misc.name}/misc/emacs";
|
||||
|
||||
meta = {
|
||||
description = "Emacs major mode with highlighting for the b4 review reply editor";
|
||||
homepage = "https://git.kernel.org/pub/scm/utils/b4/b4.git/about";
|
||||
license = lib.licenses.gpl2Only;
|
||||
maintainers = with lib.maintainers; [ fzakaria ];
|
||||
};
|
||||
}
|
||||
@@ -6,22 +6,26 @@
|
||||
magit,
|
||||
transient,
|
||||
with-editor,
|
||||
consult,
|
||||
plz,
|
||||
}:
|
||||
melpaBuild {
|
||||
pname = "majutsu";
|
||||
version = "0.6.0-unstable-2026-07-09";
|
||||
version = "0.6.0-unstable-2026-07-23";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "0WD0";
|
||||
repo = "majutsu";
|
||||
rev = "59aff9b93eac575fbccc1f4ab2d48d048e0ead9b";
|
||||
hash = "sha256-GJ62hsHgLEFIY0ghij0VPFt1jMUGRKhI2eCroBjkxtc=";
|
||||
rev = "8eaf8cb4db2f0737d0a131ef8b61ce6393660369";
|
||||
hash = "sha256-QqvzRfqWa4Ql7bpuShqHmXzXJCu1VU8ObnImiK7ZyvE=";
|
||||
};
|
||||
|
||||
packageRequires = [
|
||||
magit
|
||||
transient
|
||||
with-editor
|
||||
consult
|
||||
plz
|
||||
];
|
||||
|
||||
passthru.updateScript = nix-update-script { extraArgs = [ "--version=branch=main" ]; };
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
{
|
||||
lib,
|
||||
vimUtils,
|
||||
b4,
|
||||
}:
|
||||
vimUtils.buildVimPlugin {
|
||||
pname = "b4-review-vim";
|
||||
inherit (b4) version;
|
||||
|
||||
src = b4.src-misc;
|
||||
sourceRoot = "${b4.src-misc.name}/misc/vim";
|
||||
|
||||
meta = {
|
||||
description = "Vim syntax highlighting for the b4 review reply editor";
|
||||
homepage = "https://git.kernel.org/pub/scm/utils/b4/b4.git/about";
|
||||
license = lib.licenses.gpl2Only;
|
||||
maintainers = with lib.maintainers; [ fzakaria ];
|
||||
};
|
||||
}
|
||||
@@ -74,6 +74,9 @@ let
|
||||
];
|
||||
|
||||
env = {
|
||||
# Build zlob for a portable CPU baseline (https://github.com/dmtrKovalenko/fff/issues/705)
|
||||
CI = "1";
|
||||
|
||||
OPENSSL_NO_VENDOR = true;
|
||||
|
||||
# Allow undefined symbols on Darwin - they will be provided by Neovim's LuaJIT runtime
|
||||
|
||||
@@ -21,22 +21,22 @@ vscode-utils.buildVscodeMarketplaceExtension (finalAttrs: {
|
||||
sources = {
|
||||
"x86_64-linux" = {
|
||||
arch = "linux-x64";
|
||||
hash = "sha256-Y6MXjJBmhMzuQMwhkPLHK/vtciTdjsGvkEblH3ofju0=";
|
||||
hash = "sha256-Z/tQ+KV+3MdbknA/1kmiIpVfOsUM8NUu+0iHlPVbYV0=";
|
||||
};
|
||||
"aarch64-linux" = {
|
||||
arch = "linux-arm64";
|
||||
hash = "sha256-8VvDtb+8SoLTRC7pXwH40amRurxTQgCmhdi0u7e5AfU=";
|
||||
hash = "sha256-d2GjWr0FHOoORI5KRdwUQvcFfBB8xV6j9wj5OS9VL9o=";
|
||||
};
|
||||
"aarch64-darwin" = {
|
||||
arch = "darwin-arm64";
|
||||
hash = "sha256-bqjEgsjY+zyG1g/KtkRNxAlazIpc+HwGWvsMQNnPI2M=";
|
||||
hash = "sha256-dlfGTxf2EoiNb0g9uqwjTNW8fi2d1tzubGdIDyp4xTw=";
|
||||
};
|
||||
};
|
||||
in
|
||||
{
|
||||
name = "claude-code";
|
||||
publisher = "anthropic";
|
||||
version = "2.1.218";
|
||||
version = "2.1.219";
|
||||
}
|
||||
// sources.${stdenvNoCC.hostPlatform.system}
|
||||
or (throw "Unsupported system ${stdenvNoCC.hostPlatform.system}");
|
||||
|
||||
@@ -10,8 +10,8 @@ vscode-utils.buildVscodeMarketplaceExtension {
|
||||
mktplcRef = {
|
||||
publisher = "oxc";
|
||||
name = "oxc-vscode";
|
||||
version = "1.58.0";
|
||||
hash = "sha256-30dFeguNbY8WM3fLym6aUMkHYH5wA5scSNn04Ukbj9U=";
|
||||
version = "1.59.0";
|
||||
hash = "sha256-avfW91oF8PGCoDYocC744wpQ3zE8fv5582n55Ugb8k8=";
|
||||
};
|
||||
|
||||
nativeBuildInputs = [
|
||||
|
||||
@@ -5,13 +5,13 @@
|
||||
}:
|
||||
mkLibretroCore {
|
||||
core = "mednafen-vb";
|
||||
version = "0-unstable-2026-06-14";
|
||||
version = "0-unstable-2026-07-22";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "libretro";
|
||||
repo = "beetle-vb-libretro";
|
||||
rev = "38e7a0ec9ac7079ca1c1e3dd9aaf5b56f527efca";
|
||||
hash = "sha256-+57qsfH2wygKdD66yauzKD9XDf01q4LeiWdIeYbVUmc=";
|
||||
rev = "7cc663e9044459b3dab1790bdce8f48dc7358ed6";
|
||||
hash = "sha256-ntw8SXzyu0PTDQgaLmT5Wy172A8TI3JLN6A5WQ2T/OI=";
|
||||
};
|
||||
|
||||
makefile = "Makefile";
|
||||
|
||||
@@ -20,13 +20,13 @@
|
||||
}:
|
||||
mkLibretroCore {
|
||||
core = "dolphin";
|
||||
version = "0-unstable-2026-07-12";
|
||||
version = "0-unstable-2026-07-23";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "libretro";
|
||||
repo = "dolphin";
|
||||
rev = "0b766a68cc835775b3216500bb9af2f5d4602b12";
|
||||
hash = "sha256-JaUiDc4/vEWjEXe6H9+i6pft2DTsl5my5wyFmtbjdR0=";
|
||||
rev = "c6b869102f6b9f450f0a9878330d00484754879d";
|
||||
hash = "sha256-7sImbA1uzpwGovo4+5bK9SJpIDIvdB5FhN2IuxVaiQ8=";
|
||||
fetchSubmodules = true;
|
||||
};
|
||||
|
||||
|
||||
@@ -7,13 +7,13 @@
|
||||
}:
|
||||
mkLibretroCore {
|
||||
core = "melonds";
|
||||
version = "0-unstable-2026-06-25";
|
||||
version = "0-unstable-2026-07-19";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "libretro";
|
||||
repo = "melonds";
|
||||
rev = "c9550d18923fe86a5ad9faa159399b55c12b47f1";
|
||||
hash = "sha256-xvBdt/TMxZOrC//DLHRWRMqIibt7dNsfLM/FeMTRA60=";
|
||||
rev = "66b5d2634cd0a79030562811e6e05f5532f800ba";
|
||||
hash = "sha256-nQvnXoB8UeaSr6QfYwn18Y18KyLyWvcv/Q3L3SHvaNU=";
|
||||
};
|
||||
|
||||
extraBuildInputs = [
|
||||
|
||||
@@ -5,13 +5,13 @@
|
||||
}:
|
||||
mkLibretroCore {
|
||||
core = "picodrive";
|
||||
version = "0-unstable-2026-04-02";
|
||||
version = "0-unstable-2026-07-23";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "libretro";
|
||||
repo = "picodrive";
|
||||
rev = "f0d4a0118a9733a1f10bce5a4ac772c474f9300d";
|
||||
hash = "sha256-q584bnqIbKoXSCRHUAcqSJAIhholnXfbphvLVcbm57o=";
|
||||
rev = "78a662e3135871a6c657d5e61900f6704152e594";
|
||||
hash = "sha256-3+x1ILIUq+/nwfUGXweNIq3PFTAaP56/6G+dX4dEZ/Y=";
|
||||
fetchSubmodules = true;
|
||||
};
|
||||
|
||||
|
||||
37
pkgs/applications/networking/browsers/brave/default.nix
Normal file
37
pkgs/applications/networking/browsers/brave/default.nix
Normal file
@@ -0,0 +1,37 @@
|
||||
{ callPackage }:
|
||||
|
||||
let
|
||||
flavorData = {
|
||||
browser = {
|
||||
optStem = "brave";
|
||||
fileStem = "brave-browser";
|
||||
appIdStem = "com.brave.Browser";
|
||||
darwinStem = "Brave Browser";
|
||||
changelogFile = "CHANGELOG_DESKTOP.md";
|
||||
homepage = "https://brave.com/";
|
||||
innerBinary = "brave";
|
||||
};
|
||||
origin = {
|
||||
optStem = "brave-origin";
|
||||
fileStem = "brave-origin";
|
||||
appIdStem = "com.brave.Origin";
|
||||
darwinStem = "Brave Origin";
|
||||
changelogFile = "CHANGELOG_DESKTOP_ORIGIN.md";
|
||||
homepage = "https://brave.com/origin/";
|
||||
innerBinary = "brave";
|
||||
};
|
||||
};
|
||||
|
||||
mkBrave =
|
||||
release:
|
||||
let
|
||||
pkg = import release;
|
||||
fd = flavorData.${pkg.flavor or "browser"};
|
||||
in
|
||||
callPackage ./make-brave.nix { } (pkg // fd);
|
||||
|
||||
in
|
||||
{
|
||||
brave = mkBrave ./packages/brave.nix;
|
||||
brave-origin = mkBrave ./packages/brave-origin.nix;
|
||||
}
|
||||
@@ -49,26 +49,20 @@
|
||||
coreutils,
|
||||
libxcb,
|
||||
zlib,
|
||||
|
||||
# Darwin dependencies
|
||||
unzip,
|
||||
makeWrapper,
|
||||
|
||||
# command line arguments which are always set e.g "--disable-gpu"
|
||||
commandLineArgs ? "",
|
||||
|
||||
# Necessary for USB audio devices.
|
||||
pulseSupport ? stdenv.hostPlatform.isLinux,
|
||||
libpulseaudio,
|
||||
|
||||
# For GPU acceleration support on Wayland (without the lib it doesn't seem to work)
|
||||
libGL,
|
||||
|
||||
# For video acceleration via VA-API (--enable-features=AcceleratedVideoDecodeLinuxGL,AcceleratedVideoEncoder)
|
||||
libvaSupport ? stdenv.hostPlatform.isLinux,
|
||||
libva,
|
||||
enableVideoAcceleration ? libvaSupport,
|
||||
|
||||
# For Vulkan support (--enable-features=Vulkan); disabled by default as it seems to break VA-API
|
||||
vulkanSupport ? false,
|
||||
addDriverRunpath,
|
||||
@@ -78,8 +72,22 @@
|
||||
{
|
||||
pname,
|
||||
version,
|
||||
hash,
|
||||
url,
|
||||
# Map from Nix system strings ("x86_64-linux", "aarch64-darwin", ...) to
|
||||
# the corresponding upstream `{ url, hash }` record. Encoding the per-system
|
||||
# sources as data rather than positional arguments lets channel-specific
|
||||
# package.nix files drop platforms that upstream hasn't published yet.
|
||||
archives,
|
||||
# Upstream product flavor: "browser" (the regular Brave) or "origin" (the
|
||||
# stripped-down Brave Origin).
|
||||
flavor ? "browser",
|
||||
# Flavor-specific paths supplied by the caller (default.nix).
|
||||
optStem,
|
||||
fileStem,
|
||||
appIdStem,
|
||||
darwinStem,
|
||||
changelogFile,
|
||||
homepage,
|
||||
innerBinary,
|
||||
}:
|
||||
|
||||
let
|
||||
@@ -94,6 +102,19 @@ let
|
||||
escapeShellArg
|
||||
;
|
||||
|
||||
# /opt/brave.com/<optName>/
|
||||
optName = optStem;
|
||||
# Basename used for .desktop, gnome-control-center xml and icon files.
|
||||
fileBase = fileStem;
|
||||
# Secondary .desktop app-id.
|
||||
appId = appIdStem;
|
||||
# Upstream shell wrapper inside /opt.
|
||||
innerWrapper = fileStem;
|
||||
# macOS .app bundle name (inside the zip).
|
||||
darwinApp = darwinStem;
|
||||
# Upstream Exec= target in .desktop files (replaced with our wrapper).
|
||||
upstreamBin = "brave-${flavor}-stable";
|
||||
|
||||
deps = [
|
||||
alsa-lib
|
||||
at-spi2-atk
|
||||
@@ -156,13 +177,19 @@ let
|
||||
] # disable automatic updates
|
||||
# The feature disable is needed for VAAPI to work correctly: https://github.com/brave/brave-browser/issues/20935
|
||||
++ optionals enableVideoAcceleration [ "UseChromeOSDirectVideoDecoder" ];
|
||||
|
||||
archive =
|
||||
assert lib.assertMsg (builtins.hasAttr stdenv.hostPlatform.system archives)
|
||||
"${pname} is not available for ${stdenv.hostPlatform.system}";
|
||||
archives.${stdenv.hostPlatform.system};
|
||||
in
|
||||
stdenv.mkDerivation {
|
||||
inherit pname version;
|
||||
|
||||
src = fetchurl {
|
||||
inherit url hash;
|
||||
};
|
||||
__structuredAttrs = true;
|
||||
strictDeps = true;
|
||||
|
||||
src = fetchurl { inherit (archive) url hash; };
|
||||
|
||||
dontConfigure = true;
|
||||
dontBuild = true;
|
||||
@@ -201,27 +228,27 @@ stdenv.mkDerivation {
|
||||
cp -R usr/share $out
|
||||
cp -R opt/ $out/opt
|
||||
|
||||
export BINARYWRAPPER=$out/opt/brave.com/brave/brave-browser
|
||||
export BINARYWRAPPER=$out/opt/brave.com/${optName}/${innerWrapper}
|
||||
|
||||
# Fix path to bash in $BINARYWRAPPER
|
||||
substituteInPlace $BINARYWRAPPER \
|
||||
--replace-fail /bin/bash ${stdenv.shell} \
|
||||
--replace-fail 'CHROME_WRAPPER' 'WRAPPER'
|
||||
|
||||
ln -sf $BINARYWRAPPER $out/bin/brave
|
||||
ln -sf $BINARYWRAPPER $out/bin/${pname}
|
||||
|
||||
for exe in $out/opt/brave.com/brave/{brave,chrome_crashpad_handler}; do
|
||||
for exe in $out/opt/brave.com/${optName}/{${innerBinary},chrome_crashpad_handler}; do
|
||||
patchelf \
|
||||
--set-interpreter "$(cat $NIX_CC/nix-support/dynamic-linker)" \
|
||||
--set-rpath "${rpath}" $exe
|
||||
done
|
||||
|
||||
# Fix paths
|
||||
substituteInPlace $out/share/applications/{brave-browser,com.brave.Browser}.desktop \
|
||||
--replace-fail /usr/bin/brave-browser-stable $out/bin/brave
|
||||
substituteInPlace $out/share/gnome-control-center/default-apps/brave-browser.xml \
|
||||
substituteInPlace $out/share/applications/{${fileBase},${appId}}.desktop \
|
||||
--replace-fail /usr/bin/${upstreamBin} $out/bin/${pname}
|
||||
substituteInPlace $out/share/gnome-control-center/default-apps/${fileBase}.xml \
|
||||
--replace-fail /opt/brave.com $out/opt/brave.com
|
||||
substituteInPlace $out/opt/brave.com/brave/default-app-block \
|
||||
substituteInPlace $out/opt/brave.com/${optName}/default-app-block \
|
||||
--replace-fail /opt/brave.com $out/opt/brave.com
|
||||
|
||||
# Correct icons location
|
||||
@@ -229,13 +256,13 @@ stdenv.mkDerivation {
|
||||
|
||||
for icon in ''${icon_sizes[*]}
|
||||
do
|
||||
mkdir -p $out/share/icons/hicolor/$icon\x$icon/apps
|
||||
ln -s $out/opt/brave.com/brave/product_logo_$icon.png $out/share/icons/hicolor/$icon\x$icon/apps/brave-browser.png
|
||||
mkdir -p $out/share/icons/hicolor/''${icon}x''${icon}/apps
|
||||
ln -s $out/opt/brave.com/${optName}/product_logo_''${icon}.png $out/share/icons/hicolor/''${icon}x''${icon}/apps/${fileBase}.png
|
||||
done
|
||||
|
||||
# Replace xdg-settings and xdg-mime
|
||||
ln -sf ${xdg-utils}/bin/xdg-settings $out/opt/brave.com/brave/xdg-settings
|
||||
ln -sf ${xdg-utils}/bin/xdg-mime $out/opt/brave.com/brave/xdg-mime
|
||||
ln -sf ${xdg-utils}/bin/xdg-settings $out/opt/brave.com/${optName}/xdg-settings
|
||||
ln -sf ${xdg-utils}/bin/xdg-mime $out/opt/brave.com/${optName}/xdg-mime
|
||||
|
||||
runHook postInstall
|
||||
''
|
||||
@@ -244,9 +271,9 @@ stdenv.mkDerivation {
|
||||
|
||||
mkdir -p $out/{Applications,bin}
|
||||
|
||||
cp -r . "$out/Applications/Brave Browser.app"
|
||||
cp -r . "$out/Applications/${darwinApp}.app"
|
||||
|
||||
makeWrapper "$out/Applications/Brave Browser.app/Contents/MacOS/Brave Browser" $out/bin/brave
|
||||
makeWrapper "$out/Applications/${darwinApp}.app/Contents/MacOS/${darwinApp}" $out/bin/${pname}
|
||||
|
||||
runHook postInstall
|
||||
'';
|
||||
@@ -279,22 +306,33 @@ stdenv.mkDerivation {
|
||||
|
||||
installCheckPhase = ''
|
||||
# Bypass upstream wrapper which suppresses errors
|
||||
$out/opt/brave.com/brave/brave --version
|
||||
$out/opt/brave.com/${optName}/brave --version
|
||||
'';
|
||||
|
||||
passthru.updateScript = ./update.sh;
|
||||
|
||||
meta = {
|
||||
homepage = "https://brave.com/";
|
||||
description = "Privacy-oriented browser for Desktop and Laptop computers";
|
||||
homepage = homepage;
|
||||
description =
|
||||
"Privacy-oriented browser for Desktop and Laptop computers"
|
||||
+ lib.optionalString (flavor == "origin") " (Origin variant)";
|
||||
changelog =
|
||||
"https://github.com/brave/brave-browser/blob/master/CHANGELOG_DESKTOP.md#"
|
||||
"https://github.com/brave/brave-browser/blob/master/${changelogFile}#"
|
||||
+ lib.replaceStrings [ "." ] [ "" ] version;
|
||||
longDescription = ''
|
||||
Brave browser blocks the ads and trackers that slow you down,
|
||||
chew up your bandwidth, and invade your privacy. Brave lets you
|
||||
contribute to your favorite creators automatically.
|
||||
'';
|
||||
longDescription =
|
||||
if flavor == "origin" then
|
||||
''
|
||||
Brave Origin is a stripped-down variant of the Brave browser that
|
||||
removes most non-privacy features (rewards, wallet, AI, etc.) while
|
||||
keeping the core privacy, adblock and Chromium-based browsing
|
||||
experience.
|
||||
''
|
||||
else
|
||||
''
|
||||
Brave browser blocks the ads and trackers that slow you down,
|
||||
chew up your bandwidth, and invade your privacy. Brave lets you
|
||||
contribute to your favorite creators automatically.
|
||||
'';
|
||||
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
|
||||
license = lib.licenses.mpl20;
|
||||
maintainers = with lib.maintainers; [
|
||||
@@ -302,12 +340,9 @@ stdenv.mkDerivation {
|
||||
jefflabonte
|
||||
nasirhm
|
||||
buckley310
|
||||
rachalaraj
|
||||
];
|
||||
platforms = [
|
||||
"aarch64-linux"
|
||||
"x86_64-linux"
|
||||
"aarch64-darwin"
|
||||
];
|
||||
mainProgram = "brave";
|
||||
platforms = builtins.attrNames archives;
|
||||
mainProgram = if flavor == "origin" then "brave-origin" else "brave";
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,21 @@
|
||||
# Expression generated by update.sh; do not edit it by hand!
|
||||
rec {
|
||||
pname = "brave-origin";
|
||||
version = "1.92.144";
|
||||
flavor = "origin";
|
||||
|
||||
archives = {
|
||||
aarch64-linux = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin_${version}_arm64.deb";
|
||||
hash = "sha256-zqjpiBMogYhtuEhIlPlK8J2j9hzfd1M8RYlT/c74Na8=";
|
||||
};
|
||||
x86_64-linux = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin_${version}_amd64.deb";
|
||||
hash = "sha256-KF5WXF7GJPLCcEQyASEVfNrYyFJRXBSyWVPPAZPCa/E=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin-v${version}-darwin-arm64.zip";
|
||||
hash = "sha256-kkP8cBRnC34+SjC9EvkpKcDYP3cxW7sdJgni0+zXwbk=";
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,20 @@
|
||||
# Expression generated by update.sh; do not edit it by hand!
|
||||
rec {
|
||||
pname = "brave";
|
||||
version = "1.92.144";
|
||||
|
||||
archives = {
|
||||
aarch64-linux = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_arm64.deb";
|
||||
hash = "sha256-Z9uUJRaMx+P35oXtvAnjHyOQOXt8mW5oyyEtnD754x8=";
|
||||
};
|
||||
x86_64-linux = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_amd64.deb";
|
||||
hash = "sha256-no/KD+3EB6CqvVWEmDB/8k2rv1wau469FBXMNWN7z6k=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-v${version}-darwin-arm64.zip";
|
||||
hash = "sha256-YidWCVGP36wn1goAulSbVrKFoHI1NA/pLtfPjIXBO48=";
|
||||
};
|
||||
};
|
||||
}
|
||||
100
pkgs/applications/networking/browsers/brave/update.sh
Executable file
100
pkgs/applications/networking/browsers/brave/update.sh
Executable file
@@ -0,0 +1,100 @@
|
||||
#!/usr/bin/env nix-shell
|
||||
#!nix-shell -i bash -p curl nix jq
|
||||
set -euo pipefail
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" &>/dev/null && pwd)"
|
||||
VERSIONS_URL="https://versions.brave.com/latest/brave-versions.json"
|
||||
|
||||
sri_hash() {
|
||||
nix-hash --to-sri --type sha256 "$(nix-prefetch-url --type sha256 "$1")"
|
||||
}
|
||||
|
||||
find_release_with_asset() {
|
||||
local versionsJson="$1" channel="$2" template="$3"
|
||||
local match
|
||||
match="$(
|
||||
jq -c --arg channel "$channel" --arg tmpl "$template" '
|
||||
[.[]
|
||||
| select(.channel == $channel)
|
||||
| . as $r
|
||||
| select(
|
||||
$r.github.assets
|
||||
| map(.name)
|
||||
| any(. == ($tmpl | gsub("\\$\\{version\\}"; $r.name)))
|
||||
)
|
||||
]
|
||||
| sort_by(.published)
|
||||
| last
|
||||
' <<<"$versionsJson"
|
||||
)"
|
||||
if [[ "$match" != "null" ]]; then
|
||||
printf '%s' "$match"
|
||||
return 0
|
||||
fi
|
||||
echo "update.sh: no ${channel} release with asset matching '${template}' found" >&2
|
||||
return 1
|
||||
}
|
||||
|
||||
emit_archive_entry() {
|
||||
local releaseJson="$1" version="$2" template="$3" platform="$4"
|
||||
local name="${template//\$\{version\}/$version}"
|
||||
local url
|
||||
url="$(
|
||||
jq -r --arg n "$name" '
|
||||
.github.assets[]
|
||||
| select(.name == $n)
|
||||
| .download_url
|
||||
' <<<"$releaseJson"
|
||||
)"
|
||||
if [[ -z "$url" ]]; then
|
||||
return 0
|
||||
fi
|
||||
local hash
|
||||
hash="$(sri_hash "$url")"
|
||||
local nixUrl="${url//${version}/\$\{version\}}"
|
||||
cat <<EOF
|
||||
${platform} = {
|
||||
url = "${nixUrl}";
|
||||
hash = "${hash}";
|
||||
};
|
||||
EOF
|
||||
}
|
||||
|
||||
write_package_nix() {
|
||||
local pname="$1" releaseJson="$2" debStem="$3" darwinStem="$4"
|
||||
local version
|
||||
version="$(jq -r '.name' <<<"$releaseJson")"
|
||||
echo "=> ${pname}: ${version}" >&2
|
||||
local flavorLine=""
|
||||
if [[ "$pname" == brave-origin || "$pname" == brave-origin-* ]]; then
|
||||
flavorLine=' flavor = "origin";'
|
||||
fi
|
||||
local outFile="${SCRIPT_DIR}/packages/${pname}.nix"
|
||||
{
|
||||
echo '# Expression generated by update.sh; do not edit it by hand!'
|
||||
echo 'rec {'
|
||||
echo " pname = \"${pname}\";"
|
||||
echo " version = \"${version}\";"
|
||||
[[ -n "$flavorLine" ]] && echo "$flavorLine"
|
||||
echo ''
|
||||
echo ' archives = {'
|
||||
emit_archive_entry "$releaseJson" "$version" "${debStem}_\${version}_arm64.deb" "aarch64-linux"
|
||||
emit_archive_entry "$releaseJson" "$version" "${debStem}_\${version}_amd64.deb" "x86_64-linux"
|
||||
emit_archive_entry "$releaseJson" "$version" "${darwinStem}-v\${version}-darwin-arm64.zip" "aarch64-darwin"
|
||||
echo ' };'
|
||||
echo '}'
|
||||
} > "$outFile"
|
||||
}
|
||||
|
||||
versionsJson="$(curl --fail -s "$VERSIONS_URL")"
|
||||
|
||||
entries=(
|
||||
"brave brave-browser brave"
|
||||
"brave-origin brave-origin brave-origin"
|
||||
)
|
||||
|
||||
for entry in "${entries[@]}"; do
|
||||
read -r pname debStem darwinStem <<<"$entry"
|
||||
releaseJson="$(find_release_with_asset "$versionsJson" "release" "${debStem}_\${version}_amd64.deb")"
|
||||
write_package_nix "$pname" "$releaseJson" "$debStem" "$darwinStem"
|
||||
done
|
||||
@@ -91,7 +91,6 @@
|
||||
cupsSupport ? true,
|
||||
cups ? null,
|
||||
proprietaryCodecs ? true,
|
||||
pulseSupport ? false,
|
||||
libpulseaudio ? null,
|
||||
ungoogled ? false,
|
||||
ungoogled-chromium,
|
||||
@@ -394,7 +393,9 @@ let
|
||||
libgcrypt
|
||||
cups
|
||||
]
|
||||
++ lib.optional pulseSupport libpulseaudio;
|
||||
++ [
|
||||
libpulseaudio
|
||||
];
|
||||
|
||||
buildInputs = [
|
||||
]
|
||||
@@ -455,7 +456,9 @@ let
|
||||
libgcrypt
|
||||
cups
|
||||
]
|
||||
++ lib.optional pulseSupport libpulseaudio;
|
||||
++ [
|
||||
libpulseaudio
|
||||
];
|
||||
|
||||
patches = [
|
||||
./patches/cross-compile.patch
|
||||
@@ -968,7 +971,7 @@ let
|
||||
use_vaapi = false;
|
||||
use_v4l2_codec = true;
|
||||
}
|
||||
// lib.optionalAttrs pulseSupport {
|
||||
// {
|
||||
use_pulseaudio = true;
|
||||
link_pulseaudio = true;
|
||||
}
|
||||
|
||||
@@ -32,7 +32,6 @@
|
||||
enableWideVine ? false,
|
||||
ungoogled ? false, # Whether to build chromium or ungoogled-chromium
|
||||
cupsSupport ? true,
|
||||
pulseSupport ? config.pulseaudio or stdenv.hostPlatform.isLinux,
|
||||
commandLineArgs ? "",
|
||||
pkgsBuildBuild,
|
||||
pkgs,
|
||||
@@ -76,7 +75,6 @@ let
|
||||
inherit
|
||||
proprietaryCodecs
|
||||
cupsSupport
|
||||
pulseSupport
|
||||
ungoogled
|
||||
;
|
||||
gnChromium = buildPackages.gn.override upstream-info.deps.gn;
|
||||
|
||||
@@ -535,11 +535,11 @@
|
||||
"vendorHash": null
|
||||
},
|
||||
"hashicorp_azurerm": {
|
||||
"hash": "sha256-XJmSVCX6rigPD4oi0S4qUyvgvR5SkCHZV2rMAqsmIIo=",
|
||||
"hash": "sha256-M8Kq0lVbPtob2g8j8k4OJenAz8f5jjSobf192TrpSEg=",
|
||||
"homepage": "https://registry.terraform.io/providers/hashicorp/azurerm",
|
||||
"owner": "hashicorp",
|
||||
"repo": "terraform-provider-azurerm",
|
||||
"rev": "v4.79.0",
|
||||
"rev": "v4.81.0",
|
||||
"spdx": "MPL-2.0",
|
||||
"vendorHash": null
|
||||
},
|
||||
|
||||
@@ -13,7 +13,6 @@
|
||||
gst_all_1,
|
||||
gtk2,
|
||||
gtk2-x11,
|
||||
gtkspell2,
|
||||
intltool,
|
||||
lib,
|
||||
libice,
|
||||
@@ -94,7 +93,6 @@ let
|
||||
]
|
||||
++ lib.optionals stdenv.hostPlatform.isLinux [
|
||||
gtk2
|
||||
gtkspell2
|
||||
farstream
|
||||
]
|
||||
++ lib.optional stdenv.hostPlatform.isDarwin gtk2-x11;
|
||||
@@ -126,16 +124,14 @@ let
|
||||
"--disable-nm"
|
||||
"--disable-tcl"
|
||||
"--disable-gevolution"
|
||||
"--disable-gtkspell"
|
||||
]
|
||||
++ lib.optionals withCyrus_sasl [ "--enable-cyrus-sasl=yes" ]
|
||||
++ lib.optionals withGnutls [
|
||||
"--enable-gnutls=yes"
|
||||
"--enable-nss=no"
|
||||
]
|
||||
++ lib.optionals stdenv.hostPlatform.isDarwin [
|
||||
"--disable-gtkspell"
|
||||
"--disable-vv"
|
||||
]
|
||||
++ lib.optionals stdenv.hostPlatform.isDarwin [ "--disable-vv" ]
|
||||
++ lib.optionals stdenv.cc.isClang [ "CFLAGS=-Wno-error=int-conversion" ];
|
||||
|
||||
enableParallelBuilding = true;
|
||||
|
||||
@@ -97,6 +97,82 @@ let
|
||||
|
||||
buildPrefix = "Build/*/*";
|
||||
|
||||
isQemuPlatform = builtins.elem projectDscPath [
|
||||
"OvmfPkg/OvmfPkgX64.dsc"
|
||||
"ArmVirtPkg/ArmVirtQemu.dsc"
|
||||
"OvmfPkg/RiscVVirt/RiscVVirtQemu.dsc"
|
||||
"OvmfPkg/LoongArchVirt/LoongArchVirtQemu.dsc"
|
||||
];
|
||||
|
||||
# QEMU firmware interop descriptors to install, keyed by file name.
|
||||
# Add an attribute to ship an additional descriptor.
|
||||
qemuDescriptors =
|
||||
let
|
||||
description = "${fwPrefix} UEFI firmware for ${cpuName}${lib.optionalString secureBoot " with Secure Boot"}";
|
||||
|
||||
flashMapping = varsFile: {
|
||||
device = "flash";
|
||||
mode = "split";
|
||||
executable = {
|
||||
filename = "${placeholder "fd"}/FV/${fwPrefix}_CODE.fd";
|
||||
format = "raw";
|
||||
};
|
||||
nvram-template = {
|
||||
filename = "${placeholder "fd"}/FV/${varsFile}";
|
||||
format = "raw";
|
||||
};
|
||||
};
|
||||
|
||||
common = {
|
||||
interface-types = [ "uefi" ];
|
||||
targets = [
|
||||
{
|
||||
architecture = cpuName;
|
||||
machines =
|
||||
{
|
||||
x86_64 =
|
||||
if systemManagementModeRequired then
|
||||
[ "pc-q35-*" ]
|
||||
else
|
||||
[
|
||||
"pc-i440fx-*"
|
||||
"pc-q35-*"
|
||||
];
|
||||
aarch64 = [ "virt-*" ];
|
||||
riscv64 = [ "virt*" ];
|
||||
loongarch64 = [ "virt*" ];
|
||||
}
|
||||
.${cpuName} or [ ];
|
||||
}
|
||||
];
|
||||
features =
|
||||
lib.optionals stdenv.hostPlatform.isx86 [
|
||||
"acpi-s3"
|
||||
"amd-sev"
|
||||
]
|
||||
++ lib.optionals (stdenv.hostPlatform.isx86 && !systemManagementModeRequired) [ "amd-sev-es" ]
|
||||
++ lib.optionals secureBoot [ "secure-boot" ]
|
||||
++ lib.optionals systemManagementModeRequired [ "requires-smm" ]
|
||||
++ lib.optionals (stdenv.hostPlatform.isx86 && !debug) [ "verbose-dynamic" ];
|
||||
tags = [ ];
|
||||
};
|
||||
in
|
||||
lib.optionalAttrs isQemuPlatform (
|
||||
{
|
||||
"50-edk2-${cpuName}${lib.optionalString secureBoot "-sb"}.json" = common // {
|
||||
inherit description;
|
||||
mapping = flashMapping "${fwPrefix}_VARS.fd";
|
||||
};
|
||||
}
|
||||
// lib.optionalAttrs msVarsTemplate {
|
||||
"40-edk2-${cpuName}${lib.optionalString secureBoot "-sb"}-enrolled.json" = common // {
|
||||
description = "${description}, Microsoft keys enrolled";
|
||||
mapping = flashMapping "${fwPrefix}_VARS.ms.fd";
|
||||
features = common.features ++ [ "enrolled-keys" ];
|
||||
};
|
||||
}
|
||||
);
|
||||
|
||||
in
|
||||
|
||||
assert msVarsTemplate -> fdSize4MB;
|
||||
@@ -242,7 +318,17 @@ edk2.mkDerivation projectDscPath (finalAttrs: {
|
||||
mkdir -vp $fd/AAVMF
|
||||
ln -s $fd/FV/AAVMF_CODE.fd $fd/AAVMF/QEMU_EFI-pflash.raw
|
||||
ln -s $fd/FV/AAVMF_VARS.fd $fd/AAVMF/vars-template-pflash.raw
|
||||
'';
|
||||
''
|
||||
+ lib.optionalString (qemuDescriptors != { }) ''
|
||||
mkdir -vp $fd/share/qemu/firmware
|
||||
''
|
||||
+ lib.concatStrings (
|
||||
lib.mapAttrsToList (name: descriptor: ''
|
||||
python3 -m json.tool > $fd/share/qemu/firmware/${name} <<'EOF'
|
||||
${builtins.toJSON descriptor}
|
||||
EOF
|
||||
'') qemuDescriptors
|
||||
);
|
||||
|
||||
dontPatchELF = true;
|
||||
|
||||
|
||||
@@ -143,6 +143,27 @@ let
|
||||
hash = mobyHash;
|
||||
};
|
||||
|
||||
extraMobyPath = lib.optionals stdenv.hostPlatform.isLinux (
|
||||
lib.makeBinPath [
|
||||
iproute2
|
||||
iptables
|
||||
e2fsprogs
|
||||
xz
|
||||
xfsprogs
|
||||
procps
|
||||
util-linuxMinimal
|
||||
gitMinimal
|
||||
]
|
||||
);
|
||||
|
||||
extraMobyUserPath = lib.optionals (stdenv.hostPlatform.isLinux && !clientOnly) (
|
||||
lib.makeBinPath [
|
||||
rootlesskit
|
||||
slirp4netns
|
||||
fuse-overlayfs
|
||||
]
|
||||
);
|
||||
|
||||
moby = buildGoModule (
|
||||
lib.optionalAttrs stdenv.hostPlatform.isLinux {
|
||||
pname = "moby";
|
||||
@@ -170,27 +191,6 @@ let
|
||||
++ lib.optionals withSystemd [ systemd ]
|
||||
++ lib.optionals withSeccomp [ libseccomp ];
|
||||
|
||||
extraPath = lib.optionals stdenv.hostPlatform.isLinux (
|
||||
lib.makeBinPath [
|
||||
iproute2
|
||||
iptables
|
||||
e2fsprogs
|
||||
xz
|
||||
xfsprogs
|
||||
procps
|
||||
util-linuxMinimal
|
||||
gitMinimal
|
||||
]
|
||||
);
|
||||
|
||||
extraUserPath = lib.optionals (stdenv.hostPlatform.isLinux && !clientOnly) (
|
||||
lib.makeBinPath [
|
||||
rootlesskit
|
||||
slirp4netns
|
||||
fuse-overlayfs
|
||||
]
|
||||
);
|
||||
|
||||
postPatch = ''
|
||||
patchShebangs hack/make.sh hack/make/
|
||||
''
|
||||
@@ -218,7 +218,9 @@ let
|
||||
install -Dm755 ./bundles/dynbinary-daemon/docker-proxy $out/libexec/docker/docker-proxy
|
||||
|
||||
makeWrapper $out/libexec/docker/dockerd $out/bin/dockerd \
|
||||
--prefix PATH : "$out/libexec/docker:$extraPath"
|
||||
--prefix PATH : "$out/libexec/docker${
|
||||
lib.optionalString (extraMobyPath != "") ":${extraMobyPath}"
|
||||
}"
|
||||
|
||||
ln -s ${docker-containerd}/bin/containerd $out/libexec/docker/containerd
|
||||
ln -s ${docker-containerd}/bin/containerd-shim${lib.optionalString (lib.versionAtLeast version "29.0.0") "-runc-v2"} $out/libexec/docker/containerd-shim${lib.optionalString (lib.versionAtLeast version "29.0.0") "-runc-v2"}
|
||||
@@ -233,7 +235,9 @@ let
|
||||
# rootless Docker
|
||||
install -Dm755 ./contrib/dockerd-rootless.sh $out/libexec/docker/dockerd-rootless.sh
|
||||
makeWrapper $out/libexec/docker/dockerd-rootless.sh $out/bin/dockerd-rootless \
|
||||
--prefix PATH : "$out/libexec/docker:$extraPath:$extraUserPath"
|
||||
--prefix PATH : "$out/libexec/docker${
|
||||
lib.optionalString (extraMobyPath != "") ":${extraMobyPath}"
|
||||
}${lib.optionalString (extraMobyUserPath != "") ":${extraMobyUserPath}"}"
|
||||
|
||||
runHook postInstall
|
||||
'';
|
||||
@@ -335,7 +339,7 @@ let
|
||||
install -Dm755 ./build/docker $out/libexec/docker/docker
|
||||
|
||||
makeWrapper $out/libexec/docker/docker $out/bin/docker \
|
||||
--prefix PATH : "$out/libexec/docker:$extraPath" \
|
||||
--prefix PATH : "$out/libexec/docker" \
|
||||
--prefix DOCKER_CLI_PLUGIN_DIRS : "${dockerCliPluginsDirs}"
|
||||
''
|
||||
+ lib.optionalString (!clientOnly) ''
|
||||
|
||||
@@ -8,13 +8,13 @@
|
||||
}:
|
||||
mkHyprlandPlugin (finalAttrs: {
|
||||
pluginName = "hy3";
|
||||
version = "0.55.0";
|
||||
version = "0.56.0.1";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "outfoxxed";
|
||||
repo = "hy3";
|
||||
tag = "hl${finalAttrs.version}";
|
||||
hash = "sha256-P3wwiIfqo89evW7xzI+wOI/qM1WPZBiiSmGNtBmYeVk=";
|
||||
hash = "sha256-iK0vERuy5aXisDXm/bzcJP0dgaIot5MLPoVG62DjqO4=";
|
||||
};
|
||||
|
||||
nativeBuildInputs = [ cmake ];
|
||||
|
||||
@@ -7,13 +7,13 @@
|
||||
|
||||
mkHyprlandPlugin (finalAttrs: {
|
||||
pluginName = "hypr-darkwindow";
|
||||
version = "0.55.4";
|
||||
version = "0.56.0";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "micha4w";
|
||||
repo = "Hypr-DarkWindow";
|
||||
tag = "v${finalAttrs.version}";
|
||||
hash = "sha256-91l5TD46OMfvmhd1WqWxm42cEnjR1yAj2Qk/73mr3ks=";
|
||||
hash = "sha256-2upGTy7IRhrhxf+5VPjzrua8ebOtED6i8kSN8ka+ffg=";
|
||||
};
|
||||
|
||||
installPhase = ''
|
||||
|
||||
@@ -8,16 +8,18 @@
|
||||
pv,
|
||||
squashfsTools,
|
||||
buildFHSEnv,
|
||||
pkgs,
|
||||
replaceVarsWith,
|
||||
runtimeShell,
|
||||
runCommand,
|
||||
}:
|
||||
|
||||
rec {
|
||||
appimage-exec = pkgs.replaceVarsWith {
|
||||
appimage-exec = replaceVarsWith {
|
||||
src = ./appimage-exec.sh;
|
||||
isExecutable = true;
|
||||
dir = "bin";
|
||||
replacements = {
|
||||
inherit (pkgs) runtimeShell;
|
||||
inherit runtimeShell;
|
||||
path = lib.makeBinPath [
|
||||
bash
|
||||
binutils-unwrapped
|
||||
@@ -42,7 +44,7 @@ rec {
|
||||
assert
|
||||
name == null
|
||||
|| throw "The `name` argument is deprecated. Use `pname` and `version` instead to construct the name.";
|
||||
pkgs.runCommand "${pname}-${version}-extracted"
|
||||
runCommand "${pname}-${version}-extracted"
|
||||
{
|
||||
nativeBuildInputs = [ appimage-exec ];
|
||||
strictDeps = true;
|
||||
@@ -57,60 +59,55 @@ rec {
|
||||
extractType2 = extract;
|
||||
wrapType1 = wrapType2;
|
||||
|
||||
wrapAppImage =
|
||||
args@{
|
||||
src,
|
||||
extraPkgs ? pkgs: [ ],
|
||||
meta ? { },
|
||||
...
|
||||
}:
|
||||
buildFHSEnv (
|
||||
wrapAppImage = lib.extendMkDerivation {
|
||||
constructDrv = buildFHSEnv;
|
||||
excludeDrvArgNames = [ "extraPkgs" ];
|
||||
extendDrvArgs =
|
||||
finalAttrs:
|
||||
prev@{
|
||||
contents ? prev.src,
|
||||
extraPkgs ? pkgs: [ ],
|
||||
meta ? { },
|
||||
...
|
||||
}:
|
||||
defaultFhsEnvArgs
|
||||
// {
|
||||
targetPkgs = pkgs: [ appimage-exec ] ++ defaultFhsEnvArgs.targetPkgs pkgs ++ extraPkgs pkgs;
|
||||
|
||||
runScript = "appimage-exec.sh -w ${src} --";
|
||||
runScript = "appimage-exec.sh -w ${finalAttrs.contents or prev.src} --";
|
||||
|
||||
meta = {
|
||||
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
|
||||
}
|
||||
// meta;
|
||||
}
|
||||
// (removeAttrs args (builtins.attrNames (builtins.functionArgs wrapAppImage)))
|
||||
);
|
||||
};
|
||||
};
|
||||
|
||||
wrapType2 =
|
||||
args@{
|
||||
src,
|
||||
extraPkgs ? pkgs: [ ],
|
||||
...
|
||||
}:
|
||||
wrapAppImage (
|
||||
args
|
||||
// {
|
||||
inherit extraPkgs;
|
||||
src = extract (
|
||||
lib.filterAttrs (
|
||||
key: value:
|
||||
builtins.elem key [
|
||||
"pname"
|
||||
"version"
|
||||
"src"
|
||||
]
|
||||
) args
|
||||
);
|
||||
|
||||
# passthru src to make nix-update work
|
||||
# hack to keep the origin position (unsafeGetAttrPos)
|
||||
passthru =
|
||||
lib.pipe args [
|
||||
lib.attrNames
|
||||
(lib.remove "src")
|
||||
(removeAttrs args)
|
||||
wrapType2 = lib.extendMkDerivation {
|
||||
constructDrv = wrapAppImage;
|
||||
extendDrvArgs = finalAttrs: args: {
|
||||
contents = extract (
|
||||
lib.filterAttrs (
|
||||
key: value:
|
||||
builtins.elem key [
|
||||
"pname"
|
||||
"version"
|
||||
"src"
|
||||
]
|
||||
// args.passthru or { };
|
||||
}
|
||||
);
|
||||
) finalAttrs
|
||||
);
|
||||
|
||||
# passthru src to make nix-update work
|
||||
# hack to keep the origin position (unsafeGetAttrPos)
|
||||
passthru =
|
||||
lib.pipe finalAttrs [
|
||||
lib.attrNames
|
||||
(lib.remove "src")
|
||||
(removeAttrs finalAttrs)
|
||||
]
|
||||
// args.passthru or { };
|
||||
};
|
||||
};
|
||||
|
||||
defaultFhsEnvArgs = {
|
||||
# Most of the packages were taken from the Steam chroot
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
{
|
||||
lib,
|
||||
stdenv,
|
||||
stdenvNoCC,
|
||||
callPackage,
|
||||
runCommandLocal,
|
||||
writeShellScript,
|
||||
@@ -11,30 +12,6 @@
|
||||
bubblewrap,
|
||||
}:
|
||||
|
||||
{
|
||||
pname ? throw "You must provide either `name` or `pname`",
|
||||
version ? throw "You must provide either `name` or `version`",
|
||||
name ? "${pname}-${version}",
|
||||
runScript ? "bash",
|
||||
nativeBuildInputs ? [ ],
|
||||
extraInstallCommands ? "",
|
||||
executableName ? args.pname or name,
|
||||
meta ? { },
|
||||
passthru ? { },
|
||||
extraPreBwrapCmds ? "",
|
||||
extraBwrapArgs ? [ ],
|
||||
unshareUser ? false,
|
||||
unshareIpc ? false,
|
||||
unsharePid ? false,
|
||||
unshareNet ? false,
|
||||
unshareUts ? false,
|
||||
unshareCgroup ? false,
|
||||
privateTmp ? false,
|
||||
chdirToPwd ? true,
|
||||
dieWithParent ? true,
|
||||
...
|
||||
}@args:
|
||||
|
||||
# NOTE:
|
||||
# `pname` and `version` will throw if they were not provided.
|
||||
# Use `name` instead of directly evaluating `pname` or `version`.
|
||||
@@ -42,338 +19,358 @@
|
||||
# If you need `pname` or `version` specifically, use `args` instead:
|
||||
# e.g. `args.pname or ...`.
|
||||
|
||||
let
|
||||
inherit (lib)
|
||||
concatLines
|
||||
concatStringsSep
|
||||
escapeShellArgs
|
||||
filter
|
||||
optionalString
|
||||
splitString
|
||||
;
|
||||
|
||||
inherit (lib.attrsets) removeAttrs;
|
||||
|
||||
# The splicing code does not handle `pkgsi686Linux` well, so we have to be
|
||||
# explicit about which package set it's coming from.
|
||||
inherit (pkgsHostTarget) pkgsi686Linux;
|
||||
|
||||
# we don't know which have been supplied, and want to avoid defaulting missing attrs to null. Passed into runCommandLocal
|
||||
nameAttrs = lib.filterAttrs (
|
||||
key: value:
|
||||
builtins.elem key [
|
||||
"name"
|
||||
"pname"
|
||||
"version"
|
||||
]
|
||||
) args;
|
||||
|
||||
buildFHSEnv = callPackage ./buildFHSEnv.nix { };
|
||||
|
||||
fhsenv = buildFHSEnv (
|
||||
removeAttrs args [
|
||||
lib.makeOverridable (
|
||||
lib.extendMkDerivation {
|
||||
constructDrv = stdenvNoCC.mkDerivation;
|
||||
excludeDrvArgNames = [
|
||||
"multiPkgs"
|
||||
"targetPkgs"
|
||||
"runScript"
|
||||
"extraInstallCommands"
|
||||
"meta"
|
||||
"passthru"
|
||||
"extraPreBwrapCmds"
|
||||
"extraBwrapArgs"
|
||||
"dieWithParent"
|
||||
"unshareUser"
|
||||
"unshareCgroup"
|
||||
"unshareUts"
|
||||
"unshareNet"
|
||||
"unsharePid"
|
||||
"unshareIpc"
|
||||
"privateTmp"
|
||||
]
|
||||
);
|
||||
|
||||
etcBindEntries =
|
||||
let
|
||||
files = [
|
||||
# NixOS Compatibility
|
||||
"static"
|
||||
"nix" # mainly for nixVersions.git users, but also for access to nix/netrc
|
||||
# Shells
|
||||
"shells"
|
||||
"bashrc"
|
||||
"zshenv"
|
||||
"zshrc"
|
||||
"zinputrc"
|
||||
"zprofile"
|
||||
# Users, Groups, NSS
|
||||
"passwd"
|
||||
"group"
|
||||
"shadow"
|
||||
"hosts"
|
||||
"resolv.conf"
|
||||
"nsswitch.conf"
|
||||
# User profiles
|
||||
"profiles"
|
||||
# Sudo & Su
|
||||
"login.defs"
|
||||
"sudoers"
|
||||
"sudoers.d"
|
||||
# Time
|
||||
"localtime"
|
||||
"zoneinfo"
|
||||
# Other Core Stuff
|
||||
"machine-id"
|
||||
"os-release"
|
||||
# PAM
|
||||
"pam.d"
|
||||
# Fonts
|
||||
"fonts"
|
||||
# ALSA
|
||||
"alsa"
|
||||
"asound.conf"
|
||||
# SSL
|
||||
"ssl/certs"
|
||||
"ca-certificates"
|
||||
"pki"
|
||||
# Custom dconf profiles
|
||||
"dconf"
|
||||
];
|
||||
in
|
||||
map (path: "/etc/${path}") files;
|
||||
|
||||
# Here's the problem case:
|
||||
# - we need to run bash to run the init script
|
||||
# - LD_PRELOAD may be set to another dynamic library, requiring us to discover its dependencies
|
||||
# - oops! ldconfig is part of the init script, and it hasn't run yet
|
||||
# - everything explodes
|
||||
#
|
||||
# In particular, this happens with fhsenvs in fhsenvs, e.g. when running
|
||||
# a wrapped game from Steam.
|
||||
#
|
||||
# So, instead of doing that, we build a tiny static (important!) shim
|
||||
# that executes ldconfig in a completely clean environment to generate
|
||||
# the initial cache, and then execs into the "real" init, which is the
|
||||
# first time we see anything dynamically linked at all.
|
||||
#
|
||||
# Also, the real init is placed strategically at /init, so we don't
|
||||
# have to recompile this every time.
|
||||
containerInit =
|
||||
runCommandCC "container-init"
|
||||
];
|
||||
extendDrvArgs =
|
||||
finalAttrs:
|
||||
{
|
||||
buildInputs = [ stdenv.cc.libc.static or null ];
|
||||
}
|
||||
''
|
||||
$CXX -static -s -o $out ${./container-init.cc}
|
||||
'';
|
||||
pname ? throw "You must provide either `name` or `pname`",
|
||||
version ? throw "You must provide either `name` or `version`",
|
||||
name ? "${pname}-${version}",
|
||||
runScript ? "bash",
|
||||
executableName ? args.pname or name,
|
||||
meta ? { },
|
||||
passthru ? { },
|
||||
unshareUser ? false,
|
||||
unshareIpc ? false,
|
||||
unsharePid ? false,
|
||||
unshareNet ? false,
|
||||
unshareUts ? false,
|
||||
unshareCgroup ? false,
|
||||
privateTmp ? false,
|
||||
chdirToPwd ? true,
|
||||
dieWithParent ? true,
|
||||
...
|
||||
}@args:
|
||||
let
|
||||
inherit (lib)
|
||||
concatLines
|
||||
concatStringsSep
|
||||
escapeShellArgs
|
||||
filter
|
||||
optionalString
|
||||
splitString
|
||||
removeAttrs
|
||||
;
|
||||
|
||||
realInit =
|
||||
run:
|
||||
writeShellScript "${name}-init" ''
|
||||
source /etc/profile
|
||||
exec ${run} "$@"
|
||||
'';
|
||||
# The splicing code does not handle `pkgsi686Linux` well, so we have to be
|
||||
# explicit about which package set it's coming from.
|
||||
inherit (pkgsHostTarget) pkgsi686Linux;
|
||||
|
||||
indentLines = str: concatLines (map (s: " " + s) (filter (s: s != "") (splitString "\n" str)));
|
||||
bwrapCmd =
|
||||
{
|
||||
initArgs ? "",
|
||||
}:
|
||||
''
|
||||
ignored=(/nix /dev /proc /etc ${optionalString privateTmp "/tmp"})
|
||||
ro_mounts=()
|
||||
symlinks=()
|
||||
etc_ignored=()
|
||||
buildFHSEnv = callPackage ./buildFHSEnv.nix { };
|
||||
|
||||
${extraPreBwrapCmds}
|
||||
fhsenv = buildFHSEnv (
|
||||
removeAttrs args [
|
||||
"runScript"
|
||||
"extraInstallCommands"
|
||||
"meta"
|
||||
"passthru"
|
||||
"extraPreBwrapCmds"
|
||||
"extraBwrapArgs"
|
||||
"dieWithParent"
|
||||
"unshareUser"
|
||||
"unshareCgroup"
|
||||
"unshareUts"
|
||||
"unshareNet"
|
||||
"unsharePid"
|
||||
"unshareIpc"
|
||||
"privateTmp"
|
||||
]
|
||||
);
|
||||
|
||||
# loop through all entries of root in the fhs environment, except its /etc.
|
||||
for i in ${fhsenv}/*; do
|
||||
path="/''${i##*/}"
|
||||
if [[ $path == '/etc' ]]; then
|
||||
:
|
||||
elif [[ -L $i ]]; then
|
||||
symlinks+=(--symlink "$(${coreutils}/bin/readlink "$i")" "$path")
|
||||
ignored+=("$path")
|
||||
else
|
||||
ro_mounts+=(--ro-bind "$i" "$path")
|
||||
ignored+=("$path")
|
||||
fi
|
||||
done
|
||||
etcBindEntries =
|
||||
let
|
||||
files = [
|
||||
# NixOS Compatibility
|
||||
"static"
|
||||
"nix" # mainly for nixVersions.git users, but also for access to nix/netrc
|
||||
# Shells
|
||||
"shells"
|
||||
"bashrc"
|
||||
"zshenv"
|
||||
"zshrc"
|
||||
"zinputrc"
|
||||
"zprofile"
|
||||
# Users, Groups, NSS
|
||||
"passwd"
|
||||
"group"
|
||||
"shadow"
|
||||
"hosts"
|
||||
"resolv.conf"
|
||||
"nsswitch.conf"
|
||||
# User profiles
|
||||
"profiles"
|
||||
# Sudo & Su
|
||||
"login.defs"
|
||||
"sudoers"
|
||||
"sudoers.d"
|
||||
# Time
|
||||
"localtime"
|
||||
"zoneinfo"
|
||||
# Other Core Stuff
|
||||
"machine-id"
|
||||
"os-release"
|
||||
# PAM
|
||||
"pam.d"
|
||||
# Fonts
|
||||
"fonts"
|
||||
# ALSA
|
||||
"alsa"
|
||||
"asound.conf"
|
||||
# SSL
|
||||
"ssl/certs"
|
||||
"ca-certificates"
|
||||
"pki"
|
||||
# Custom dconf profiles
|
||||
"dconf"
|
||||
];
|
||||
in
|
||||
map (path: "/etc/${path}") files;
|
||||
|
||||
# loop through the entries of /etc in the fhs environment.
|
||||
if [[ -d ${fhsenv}/etc ]]; then
|
||||
for i in ${fhsenv}/etc/*; do
|
||||
path="/''${i##*/}"
|
||||
# NOTE: we're binding /etc/fonts and /etc/ssl/certs from the host so we
|
||||
# don't want to override it with a path from the FHS environment.
|
||||
if [[ $path == '/fonts' || $path == '/ssl' ]]; then
|
||||
continue
|
||||
fi
|
||||
if [[ -L $i ]]; then
|
||||
symlinks+=(--symlink "$i" "/etc$path")
|
||||
else
|
||||
ro_mounts+=(--ro-bind "$i" "/etc$path")
|
||||
fi
|
||||
etc_ignored+=("/etc$path")
|
||||
done
|
||||
fi
|
||||
|
||||
# propagate /etc from the actual host if nested
|
||||
if [[ -e /.host-etc ]]; then
|
||||
ro_mounts+=(--ro-bind /.host-etc /.host-etc)
|
||||
else
|
||||
ro_mounts+=(--ro-bind /etc /.host-etc)
|
||||
fi
|
||||
|
||||
declare -A etc_ignored_set
|
||||
for ign in "''${etc_ignored[@]}"; do
|
||||
etc_ignored_set[$ign]=1
|
||||
done
|
||||
|
||||
# link selected etc entries from the actual root
|
||||
for i in ${escapeShellArgs etcBindEntries}; do
|
||||
if [[ -n "''${etc_ignored_set[$i]:-}" ]]; then
|
||||
continue
|
||||
fi
|
||||
if [[ -e $i ]]; then
|
||||
symlinks+=(--symlink "/.host-etc/''${i#/etc/}" "$i")
|
||||
fi
|
||||
done
|
||||
|
||||
declare -A ignored_set
|
||||
for ign in "''${ignored[@]}"; do
|
||||
ignored_set[$ign]=1
|
||||
done
|
||||
|
||||
declare -a auto_mounts
|
||||
# loop through all directories in the root
|
||||
for dir in /*; do
|
||||
# if it is a directory and not already provided by the FHS env or
|
||||
# explicitly ignored, bind-mount it into the chroot. Use exact match
|
||||
# via associative array because regex substring matching incorrectly
|
||||
# skips prefixes (e.g. /sb would match /sbin and never get mounted,
|
||||
# breaking --chdir when CWD is on a custom mount like /sb/project).
|
||||
# https://github.com/NixOS/nixpkgs/issues/241151
|
||||
if [[ -d "$dir" ]] && [[ -z "''${ignored_set[$dir]:-}" ]]; then
|
||||
# add it to the mount list
|
||||
auto_mounts+=(--bind "$dir" "$dir")
|
||||
fi
|
||||
done
|
||||
|
||||
declare -a x11_args
|
||||
# Always mount a tmpfs on /tmp/.X11-unix
|
||||
# Rationale: https://github.com/flatpak/flatpak/blob/be2de97e862e5ca223da40a895e54e7bf24dbfb9/common/flatpak-run.c#L277
|
||||
x11_args+=(--tmpfs /tmp/.X11-unix)
|
||||
|
||||
# Try to guess X socket path. This doesn't cover _everything_, but it covers some things.
|
||||
if [[ "$DISPLAY" == *:* ]]; then
|
||||
# recover display number from $DISPLAY formatted [host]:num[.screen]
|
||||
display_nr=''${DISPLAY/#*:} # strip host
|
||||
display_nr=''${display_nr/%.*} # strip screen
|
||||
local_socket=/tmp/.X11-unix/X$display_nr
|
||||
x11_args+=(--ro-bind-try "$local_socket" "$local_socket")
|
||||
fi
|
||||
|
||||
${optionalString privateTmp ''
|
||||
# sddm places XAUTHORITY in /tmp
|
||||
if [[ "$XAUTHORITY" == /tmp/* ]]; then
|
||||
x11_args+=(--ro-bind-try "$XAUTHORITY" "$XAUTHORITY")
|
||||
fi
|
||||
|
||||
# dbus-run-session puts the socket in /tmp
|
||||
IFS=";" read -ra addrs <<<"$DBUS_SESSION_BUS_ADDRESS"
|
||||
for addr in "''${addrs[@]}"; do
|
||||
[[ "$addr" == unix:* ]] || continue
|
||||
IFS="," read -ra parts <<<"''${addr#unix:}"
|
||||
for part in "''${parts[@]}"; do
|
||||
printf -v part '%s' "''${part//\\/\\\\}"
|
||||
printf -v part '%b' "''${part//%/\\x}"
|
||||
[[ "$part" == path=/tmp/* ]] || continue
|
||||
x11_args+=(--ro-bind-try "''${part#path=}" "''${part#path=}")
|
||||
done
|
||||
done
|
||||
''}
|
||||
|
||||
cmd=(
|
||||
${bubblewrap}/bin/bwrap
|
||||
--dev-bind /dev /dev
|
||||
--proc /proc
|
||||
${optionalString chdirToPwd ''--chdir "$(pwd)"''}
|
||||
${optionalString unshareUser "--unshare-user"}
|
||||
${optionalString unshareIpc "--unshare-ipc"}
|
||||
${optionalString unsharePid "--unshare-pid"}
|
||||
${optionalString unshareNet "--unshare-net"}
|
||||
${optionalString unshareUts "--unshare-uts"}
|
||||
${optionalString unshareCgroup "--unshare-cgroup"}
|
||||
${optionalString dieWithParent "--die-with-parent"}
|
||||
--bind /nix /nix
|
||||
${optionalString privateTmp "--tmpfs /tmp"}
|
||||
# Our glibc will look for the cache in its own path in `/nix/store`.
|
||||
# As such, we need a cache to exist there, because pressure-vessel
|
||||
# depends on the existence of an ld cache. However, adding one
|
||||
# globally proved to be a bad idea (see #100655), the solution we
|
||||
# settled on being mounting one via bwrap.
|
||||
# Also, the cache needs to go to both 32 and 64 bit glibcs, for games
|
||||
# of both architectures to work.
|
||||
--tmpfs ${glibc}/etc \
|
||||
--tmpfs /etc \
|
||||
--symlink /etc/ld.so.conf ${glibc}/etc/ld.so.conf \
|
||||
--symlink /etc/ld.so.cache ${glibc}/etc/ld.so.cache \
|
||||
--ro-bind ${glibc}/etc/rpc ${glibc}/etc/rpc \
|
||||
--remount-ro ${glibc}/etc \
|
||||
--symlink ${realInit runScript} /init \
|
||||
''
|
||||
+ optionalString fhsenv.isMultiBuild (indentLines ''
|
||||
--tmpfs ${pkgsi686Linux.glibc}/etc \
|
||||
--symlink /etc/ld.so.conf ${pkgsi686Linux.glibc}/etc/ld.so.conf \
|
||||
--symlink /etc/ld.so.cache ${pkgsi686Linux.glibc}/etc/ld.so.cache \
|
||||
--ro-bind ${pkgsi686Linux.glibc}/etc/rpc ${pkgsi686Linux.glibc}/etc/rpc \
|
||||
--remount-ro ${pkgsi686Linux.glibc}/etc \
|
||||
'')
|
||||
+ ''
|
||||
"''${ro_mounts[@]}"
|
||||
"''${symlinks[@]}"
|
||||
"''${auto_mounts[@]}"
|
||||
"''${x11_args[@]}"
|
||||
${concatStringsSep "\n " extraBwrapArgs}
|
||||
${containerInit} ${initArgs}
|
||||
)
|
||||
exec "''${cmd[@]}"
|
||||
'';
|
||||
|
||||
bin = writeShellScript "${name}-bwrap" (bwrapCmd {
|
||||
initArgs = ''"$@"'';
|
||||
});
|
||||
in
|
||||
runCommandLocal name
|
||||
(
|
||||
nameAttrs
|
||||
// {
|
||||
inherit nativeBuildInputs;
|
||||
|
||||
__structuredAttrs = true;
|
||||
|
||||
passthru = passthru // {
|
||||
env =
|
||||
runCommandLocal "${name}-shell-env"
|
||||
# Here's the problem case:
|
||||
# - we need to run bash to run the init script
|
||||
# - LD_PRELOAD may be set to another dynamic library, requiring us to discover its dependencies
|
||||
# - oops! ldconfig is part of the init script, and it hasn't run yet
|
||||
# - everything explodes
|
||||
#
|
||||
# In particular, this happens with fhsenvs in fhsenvs, e.g. when running
|
||||
# a wrapped game from Steam.
|
||||
#
|
||||
# So, instead of doing that, we build a tiny static (important!) shim
|
||||
# that executes ldconfig in a completely clean environment to generate
|
||||
# the initial cache, and then execs into the "real" init, which is the
|
||||
# first time we see anything dynamically linked at all.
|
||||
#
|
||||
# Also, the real init is placed strategically at /init, so we don't
|
||||
# have to recompile this every time.
|
||||
containerInit =
|
||||
runCommandCC "container-init"
|
||||
{
|
||||
shellHook = bwrapCmd { };
|
||||
buildInputs = [ stdenv.cc.libc.static or null ];
|
||||
}
|
||||
''
|
||||
echo >&2 ""
|
||||
echo >&2 "*** User chroot 'env' attributes are intended for interactive nix-shell sessions, not for building! ***"
|
||||
echo >&2 ""
|
||||
exit 1
|
||||
$CXX -static -s -o $out ${./container-init.cc}
|
||||
'';
|
||||
inherit args fhsenv;
|
||||
|
||||
realInit =
|
||||
run:
|
||||
writeShellScript "${name}-init" ''
|
||||
source /etc/profile
|
||||
exec ${run} "$@"
|
||||
'';
|
||||
|
||||
indentLines = str: concatLines (map (s: " " + s) (filter (s: s != "") (splitString "\n" str)));
|
||||
bwrapCmd =
|
||||
{
|
||||
initArgs ? "",
|
||||
}:
|
||||
''
|
||||
ignored=(/nix /dev /proc /etc ${optionalString privateTmp "/tmp"})
|
||||
ro_mounts=()
|
||||
symlinks=()
|
||||
etc_ignored=()
|
||||
|
||||
${finalAttrs.extraPreBwrapCmds or ""}
|
||||
|
||||
# loop through all entries of root in the fhs environment, except its /etc.
|
||||
for i in ${fhsenv}/*; do
|
||||
path="/''${i##*/}"
|
||||
if [[ $path == '/etc' ]]; then
|
||||
:
|
||||
elif [[ -L $i ]]; then
|
||||
symlinks+=(--symlink "$(${coreutils}/bin/readlink "$i")" "$path")
|
||||
ignored+=("$path")
|
||||
else
|
||||
ro_mounts+=(--ro-bind "$i" "$path")
|
||||
ignored+=("$path")
|
||||
fi
|
||||
done
|
||||
|
||||
# loop through the entries of /etc in the fhs environment.
|
||||
if [[ -d ${fhsenv}/etc ]]; then
|
||||
for i in ${fhsenv}/etc/*; do
|
||||
path="/''${i##*/}"
|
||||
# NOTE: we're binding /etc/fonts and /etc/ssl/certs from the host so we
|
||||
# don't want to override it with a path from the FHS environment.
|
||||
if [[ $path == '/fonts' || $path == '/ssl' ]]; then
|
||||
continue
|
||||
fi
|
||||
if [[ -L $i ]]; then
|
||||
symlinks+=(--symlink "$i" "/etc$path")
|
||||
else
|
||||
ro_mounts+=(--ro-bind "$i" "/etc$path")
|
||||
fi
|
||||
etc_ignored+=("/etc$path")
|
||||
done
|
||||
fi
|
||||
|
||||
# propagate /etc from the actual host if nested
|
||||
if [[ -e /.host-etc ]]; then
|
||||
ro_mounts+=(--ro-bind /.host-etc /.host-etc)
|
||||
else
|
||||
ro_mounts+=(--ro-bind /etc /.host-etc)
|
||||
fi
|
||||
|
||||
declare -A etc_ignored_set
|
||||
for ign in "''${etc_ignored[@]}"; do
|
||||
etc_ignored_set[$ign]=1
|
||||
done
|
||||
|
||||
# link selected etc entries from the actual root
|
||||
for i in ${escapeShellArgs etcBindEntries}; do
|
||||
if [[ -n "''${etc_ignored_set[$i]:-}" ]]; then
|
||||
continue
|
||||
fi
|
||||
if [[ -e $i ]]; then
|
||||
symlinks+=(--symlink "/.host-etc/''${i#/etc/}" "$i")
|
||||
fi
|
||||
done
|
||||
|
||||
declare -A ignored_set
|
||||
for ign in "''${ignored[@]}"; do
|
||||
ignored_set[$ign]=1
|
||||
done
|
||||
|
||||
declare -a auto_mounts
|
||||
# loop through all directories in the root
|
||||
for dir in /*; do
|
||||
# if it is a directory and not already provided by the FHS env or
|
||||
# explicitly ignored, bind-mount it into the chroot. Use exact match
|
||||
# via associative array because regex substring matching incorrectly
|
||||
# skips prefixes (e.g. /sb would match /sbin and never get mounted,
|
||||
# breaking --chdir when CWD is on a custom mount like /sb/project).
|
||||
# https://github.com/NixOS/nixpkgs/issues/241151
|
||||
if [[ -d "$dir" ]] && [[ -z "''${ignored_set[$dir]:-}" ]]; then
|
||||
# add it to the mount list
|
||||
auto_mounts+=(--bind "$dir" "$dir")
|
||||
fi
|
||||
done
|
||||
|
||||
declare -a x11_args
|
||||
# Always mount a tmpfs on /tmp/.X11-unix
|
||||
# Rationale: https://github.com/flatpak/flatpak/blob/be2de97e862e5ca223da40a895e54e7bf24dbfb9/common/flatpak-run.c#L277
|
||||
x11_args+=(--tmpfs /tmp/.X11-unix)
|
||||
|
||||
# Try to guess X socket path. This doesn't cover _everything_, but it covers some things.
|
||||
if [[ "$DISPLAY" == *:* ]]; then
|
||||
# recover display number from $DISPLAY formatted [host]:num[.screen]
|
||||
display_nr=''${DISPLAY/#*:} # strip host
|
||||
display_nr=''${display_nr/%.*} # strip screen
|
||||
local_socket=/tmp/.X11-unix/X$display_nr
|
||||
x11_args+=(--ro-bind-try "$local_socket" "$local_socket")
|
||||
fi
|
||||
|
||||
${optionalString privateTmp ''
|
||||
# sddm places XAUTHORITY in /tmp
|
||||
if [[ "$XAUTHORITY" == /tmp/* ]]; then
|
||||
x11_args+=(--ro-bind-try "$XAUTHORITY" "$XAUTHORITY")
|
||||
fi
|
||||
|
||||
# dbus-run-session puts the socket in /tmp
|
||||
IFS=";" read -ra addrs <<<"$DBUS_SESSION_BUS_ADDRESS"
|
||||
for addr in "''${addrs[@]}"; do
|
||||
[[ "$addr" == unix:* ]] || continue
|
||||
IFS="," read -ra parts <<<"''${addr#unix:}"
|
||||
for part in "''${parts[@]}"; do
|
||||
printf -v part '%s' "''${part//\\/\\\\}"
|
||||
printf -v part '%b' "''${part//%/\\x}"
|
||||
[[ "$part" == path=/tmp/* ]] || continue
|
||||
x11_args+=(--ro-bind-try "''${part#path=}" "''${part#path=}")
|
||||
done
|
||||
done
|
||||
''}
|
||||
|
||||
cmd=(
|
||||
${bubblewrap}/bin/bwrap
|
||||
--dev-bind /dev /dev
|
||||
--proc /proc
|
||||
${optionalString chdirToPwd ''--chdir "$(pwd)"''}
|
||||
${optionalString unshareUser "--unshare-user"}
|
||||
${optionalString unshareIpc "--unshare-ipc"}
|
||||
${optionalString unsharePid "--unshare-pid"}
|
||||
${optionalString unshareNet "--unshare-net"}
|
||||
${optionalString unshareUts "--unshare-uts"}
|
||||
${optionalString unshareCgroup "--unshare-cgroup"}
|
||||
${optionalString dieWithParent "--die-with-parent"}
|
||||
--bind /nix /nix
|
||||
${optionalString privateTmp "--tmpfs /tmp"}
|
||||
# Our glibc will look for the cache in its own path in `/nix/store`.
|
||||
# As such, we need a cache to exist there, because pressure-vessel
|
||||
# depends on the existence of an ld cache. However, adding one
|
||||
# globally proved to be a bad idea (see #100655), the solution we
|
||||
# settled on being mounting one via bwrap.
|
||||
# Also, the cache needs to go to both 32 and 64 bit glibcs, for games
|
||||
# of both architectures to work.
|
||||
--tmpfs ${glibc}/etc \
|
||||
--tmpfs /etc \
|
||||
--symlink /etc/ld.so.conf ${glibc}/etc/ld.so.conf \
|
||||
--symlink /etc/ld.so.cache ${glibc}/etc/ld.so.cache \
|
||||
--ro-bind ${glibc}/etc/rpc ${glibc}/etc/rpc \
|
||||
--remount-ro ${glibc}/etc \
|
||||
--symlink ${realInit runScript} /init \
|
||||
''
|
||||
+ optionalString fhsenv.isMultiBuild (indentLines ''
|
||||
--tmpfs ${pkgsi686Linux.glibc}/etc \
|
||||
--symlink /etc/ld.so.conf ${pkgsi686Linux.glibc}/etc/ld.so.conf \
|
||||
--symlink /etc/ld.so.cache ${pkgsi686Linux.glibc}/etc/ld.so.cache \
|
||||
--ro-bind ${pkgsi686Linux.glibc}/etc/rpc ${pkgsi686Linux.glibc}/etc/rpc \
|
||||
--remount-ro ${pkgsi686Linux.glibc}/etc \
|
||||
'')
|
||||
+ ''
|
||||
"''${ro_mounts[@]}"
|
||||
"''${symlinks[@]}"
|
||||
"''${auto_mounts[@]}"
|
||||
"''${x11_args[@]}"
|
||||
${concatStringsSep "\n " (finalAttrs.extraBwrapArgs or [ ])}
|
||||
${containerInit} ${initArgs}
|
||||
)
|
||||
exec "''${cmd[@]}"
|
||||
'';
|
||||
|
||||
bin = writeShellScript "${name}-bwrap" (bwrapCmd {
|
||||
initArgs = ''"$@"'';
|
||||
});
|
||||
in
|
||||
{
|
||||
buildCommand = ''
|
||||
mkdir -p $out/bin
|
||||
ln -s ${bin} $out/bin/${executableName}
|
||||
|
||||
${finalAttrs.extraInstallCommands or ""}
|
||||
'';
|
||||
|
||||
__structuredAttrs = true;
|
||||
strictDeps = true;
|
||||
|
||||
enableParallelBuilding = true;
|
||||
preferLocalBuild = true;
|
||||
allowSubstitutes = false;
|
||||
|
||||
passthru = passthru // {
|
||||
env =
|
||||
runCommandLocal "${name}-shell-env"
|
||||
{
|
||||
shellHook = bwrapCmd { };
|
||||
}
|
||||
''
|
||||
echo >&2 ""
|
||||
echo >&2 "*** User chroot 'env' attributes are intended for interactive nix-shell sessions, not for building! ***"
|
||||
echo >&2 ""
|
||||
exit 1
|
||||
'';
|
||||
inherit args fhsenv;
|
||||
};
|
||||
|
||||
meta = {
|
||||
mainProgram = executableName;
|
||||
}
|
||||
// meta;
|
||||
};
|
||||
|
||||
meta = {
|
||||
mainProgram = executableName;
|
||||
}
|
||||
// meta;
|
||||
}
|
||||
)
|
||||
''
|
||||
mkdir -p $out/bin
|
||||
ln -s ${bin} $out/bin/${executableName}
|
||||
|
||||
${extraInstallCommands}
|
||||
''
|
||||
}
|
||||
)
|
||||
|
||||
@@ -29,10 +29,6 @@ let
|
||||
services = {
|
||||
svc = {
|
||||
process.argv = [ "${coreutils}/bin/true" ];
|
||||
process.environment = {
|
||||
FOO = "bar";
|
||||
DROPPED = null;
|
||||
};
|
||||
assertions = [
|
||||
{
|
||||
assertion = true;
|
||||
@@ -74,19 +70,6 @@ let
|
||||
expected = [ "${coreutils}/bin/true" ];
|
||||
};
|
||||
|
||||
# A set environment variable round-trips through process.environment.
|
||||
testProcessEnvironment = {
|
||||
expr = c.process.environment.FOO;
|
||||
expected = "bar";
|
||||
};
|
||||
|
||||
# A null environment variable is preserved as null (unset request),
|
||||
# rather than coerced to a string or dropped from the attrset.
|
||||
testProcessEnvironmentNull = {
|
||||
expr = c.process.environment.DROPPED;
|
||||
expected = null;
|
||||
};
|
||||
|
||||
testAssertions = {
|
||||
expr = lib.elem {
|
||||
assertion = true;
|
||||
@@ -203,9 +186,6 @@ let
|
||||
mkdir -p "$dir"
|
||||
echo "$$" > "$dir/pid"
|
||||
printf '%s\n' "$@" > "$dir/args"
|
||||
# Record the process's own environment as received from the service
|
||||
# manager (NUL-delimited, as the kernel stores it).
|
||||
"${coreutils}/bin/cat" "/proc/$$/environ" > "$dir/environ"
|
||||
exec "${coreutils}/bin/sleep" infinity
|
||||
'';
|
||||
|
||||
@@ -258,31 +238,6 @@ let
|
||||
|| { echo "${id}: expected arg ${lib.escapeShellArg arg} not found"; cat "${sharedDir}/${id}/args"; exit 1; }
|
||||
'') expectedArgs;
|
||||
|
||||
/**
|
||||
Shell snippet: assert that the service's recorded environment contains
|
||||
each `present` entry (an exact `KEY=value` string) and contains no
|
||||
variable named in `absent`.
|
||||
*/
|
||||
checkEnv =
|
||||
id:
|
||||
{
|
||||
present ? [ ],
|
||||
absent ? [ ],
|
||||
}:
|
||||
''
|
||||
# The recorded environ is NUL-delimited; render one entry per line.
|
||||
tr '\0' '\n' < "${sharedDir}/${id}/environ" > "${sharedDir}/${id}/environ.lines"
|
||||
''
|
||||
+ lib.concatMapStrings (entry: ''
|
||||
grep -qxF -- ${lib.escapeShellArg entry} "${sharedDir}/${id}/environ.lines" \
|
||||
|| { echo "${id}: expected env ${lib.escapeShellArg entry} not found"; cat "${sharedDir}/${id}/environ.lines"; exit 1; }
|
||||
'') present
|
||||
+ lib.concatMapStrings (key: ''
|
||||
if grep -qE ${lib.escapeShellArg "^${key}="} "${sharedDir}/${id}/environ.lines"; then
|
||||
echo "${id}: env variable ${lib.escapeShellArg key} should be unset"; exit 1
|
||||
fi
|
||||
'') absent;
|
||||
|
||||
mkTestScript =
|
||||
name: text:
|
||||
lib.getExe (writeShellApplication {
|
||||
@@ -375,24 +330,6 @@ in
|
||||
);
|
||||
};
|
||||
|
||||
environment = mkTest {
|
||||
name = "${namePrefix}-environment";
|
||||
services.test = {
|
||||
process.argv = mkArgv "env" [ ];
|
||||
process.environment = {
|
||||
FOO = "bar";
|
||||
DROPPED = null;
|
||||
};
|
||||
};
|
||||
testExe = mkTestScript "environment" (
|
||||
waitAndCheck "env" [ ]
|
||||
+ checkEnv "env" {
|
||||
present = [ "FOO=bar" ];
|
||||
absent = [ "DROPPED" ];
|
||||
}
|
||||
);
|
||||
};
|
||||
|
||||
sub-services = mkTest {
|
||||
name = "${namePrefix}-sub-services";
|
||||
services.a = {
|
||||
|
||||
@@ -15,12 +15,11 @@
|
||||
|
||||
stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "algol68g";
|
||||
version = "3.12.2";
|
||||
version = "3.12.3";
|
||||
|
||||
src = fetchurl {
|
||||
# Uses archive.org because the original site removes older versions.
|
||||
url = "https://web.archive.org/web/20260515052918/https://algol68genie.nl/algol68g-3.12.2.tar.gz";
|
||||
hash = "sha256-4fiubqpgoH3YOlCg1bJHQ3kOayKNulW3CYbOK1awE7k";
|
||||
url = "https://algol68genie.nl/algol68g-${finalAttrs.version}.tar.gz";
|
||||
hash = "sha256-TS5m+Byi+5j4jiOuQbR159QERfNJsQiGNngtoyC9IrE=";
|
||||
};
|
||||
|
||||
outputs = [
|
||||
@@ -48,8 +47,8 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
postInstall =
|
||||
let
|
||||
pdfdoc = fetchurl {
|
||||
url = "https://web.archive.org/web/20260503174213/https://algol68genie.nl/learning-algol-68-genie.pdf";
|
||||
hash = "sha256-eLMRf3XcAkr/Dmk7ieRe62x76VcCj+2QltHH7YtL15s=";
|
||||
url = "https://algol68genie.nl/learning-algol-68-genie.pdf";
|
||||
hash = "sha256-BrVjYXd5sknV0+UCRgQMf0H3QMzMQcLhytEEuiTGkLE=";
|
||||
};
|
||||
in
|
||||
lib.optionalString withPDFDoc ''
|
||||
|
||||
@@ -12,16 +12,16 @@
|
||||
|
||||
rustPlatform.buildRustPackage (finalAttrs: {
|
||||
pname = "alistral";
|
||||
version = "0.6.7";
|
||||
version = "0.6.8";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "RustyNova016";
|
||||
repo = "Alistral";
|
||||
tag = "v${finalAttrs.version}";
|
||||
hash = "sha256-XsN4UyIXkd0YVtO/q9EcFP/sBYkH9leISmbJZ93ef6E=";
|
||||
hash = "sha256-NDWQl2Gq4Q0OMMCrHQhybInaJRjY3Fxe3GXrGb32MMY=";
|
||||
};
|
||||
|
||||
cargoHash = "sha256-KFNFioZ/5moC5FNXw+hA+NrPjsqu+3V8A5mtZ4FZUHw=";
|
||||
cargoHash = "sha256-QxTmjtntp5zy7UijRn0hF3DyOOl3dIpZjPSASCuHaEk=";
|
||||
|
||||
buildNoDefaultFeatures = true;
|
||||
# Would be cleaner with an "--all-features" option
|
||||
|
||||
@@ -9,7 +9,6 @@
|
||||
|
||||
let
|
||||
opencv4WithGtk = python3Packages.opencv4.override {
|
||||
enableGtk2 = true; # For GTK2 support
|
||||
enableGtk3 = true; # For GTK3 support
|
||||
};
|
||||
in
|
||||
|
||||
@@ -6,7 +6,7 @@
|
||||
|
||||
rustPlatform.buildRustPackage {
|
||||
pname = "as-tree";
|
||||
version = "unstable-2021-03-09";
|
||||
version = "0.12.0-unstable-2021-03-09";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "jez";
|
||||
|
||||
@@ -12,16 +12,16 @@
|
||||
|
||||
rustPlatform.buildRustPackage (finalAttrs: {
|
||||
pname = "aube";
|
||||
version = "1.29.1";
|
||||
version = "1.32.0";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "jdx";
|
||||
repo = "aube";
|
||||
tag = "v${finalAttrs.version}";
|
||||
hash = "sha256-87r9qltKUhjnYG9O484OUzKFiO8Xoge9VZ13l6RgrdA=";
|
||||
hash = "sha256-0BnaxRk6+KY4AGZ31lis0zxc9uWp3OrxCgp9SgOrqNI=";
|
||||
};
|
||||
|
||||
cargoHash = "sha256-Cy5Ea/rF2IJ5WppKKI7E1toy9N+bQEArVW9o2pHzBMc=";
|
||||
cargoHash = "sha256-vYbbnEpVWG6kjnycl1kk3D+lXuzTzOKuilA0ImBHYAI=";
|
||||
|
||||
nativeBuildInputs = [ cmake ]; # libz-ng-sys
|
||||
|
||||
@@ -36,6 +36,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
|
||||
|
||||
checkFlags = [
|
||||
# failed on x86_64-linux
|
||||
"--skip=concurrency::tests::floor_and_ceiling_inclusive"
|
||||
"--skip=http::ticket_cache::tests::max_per_host_evicts_oldest"
|
||||
"--skip=http::ticket_cache::tests::invalidate_removes_all_for_host"
|
||||
# require network access
|
||||
|
||||
@@ -7,16 +7,16 @@
|
||||
|
||||
rustPlatform.buildRustPackage (finalAttrs: {
|
||||
pname = "automatic-timezoned";
|
||||
version = "2.0.143";
|
||||
version = "2.0.149";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "maxbrunet";
|
||||
repo = "automatic-timezoned";
|
||||
rev = "v${finalAttrs.version}";
|
||||
sha256 = "sha256-bbdhvQ9THiBRf1rLExXQiwlrkgZBFZlaV2CUszDmwo4=";
|
||||
sha256 = "sha256-FQ4SJcHkdNJcZOncY0BHg+CwnUcyszzfYPCUhWZHhi0=";
|
||||
};
|
||||
|
||||
cargoHash = "sha256-J7h1hVp8wK6UlkstcLCq4uMKJ9ZyLwGR75tcxpWnHT8=";
|
||||
cargoHash = "sha256-4+gNtQrlaDrSCUFEIByFUQnITSkF9Mo9bq6Ug9d7t1w=";
|
||||
|
||||
nativeInstallCheckInputs = [ versionCheckHook ];
|
||||
|
||||
|
||||
82
pkgs/by-name/az/azure-mcp/package.nix
Normal file
82
pkgs/by-name/az/azure-mcp/package.nix
Normal file
@@ -0,0 +1,82 @@
|
||||
{
|
||||
lib,
|
||||
stdenv,
|
||||
fetchzip,
|
||||
autoPatchelfHook,
|
||||
azure-cli,
|
||||
makeWrapper,
|
||||
}:
|
||||
|
||||
let
|
||||
version = "3.0.0-beta.10";
|
||||
srcs = {
|
||||
x86_64-linux = {
|
||||
url = "https://github.com/microsoft/mcp/releases/download/Azure.Mcp.Server-${version}/Azure.Mcp.Server-linux-x64-native.zip";
|
||||
hash = "sha256-2wrpyTVunT54dYD1ascVDRTW2AN5NpoV+q3UUt5dQSg=";
|
||||
};
|
||||
aarch64-linux = {
|
||||
url = "https://github.com/microsoft/mcp/releases/download/Azure.Mcp.Server-${version}/Azure.Mcp.Server-linux-arm64.zip";
|
||||
hash = "sha256-K1QRpj5/RzZx2mrmtnB5lGX9CoaAC+pRVGqqHtXWncY=";
|
||||
};
|
||||
x86_64-darwin = {
|
||||
url = "https://github.com/microsoft/mcp/releases/download/Azure.Mcp.Server-${version}/Azure.Mcp.Server-osx-x64.zip";
|
||||
hash = "sha256-ebT6sipbA7IdGx98kF/8GLpHL1fVSVqnmL4rEwsa43k=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://github.com/microsoft/mcp/releases/download/Azure.Mcp.Server-${version}/Azure.Mcp.Server-osx-arm64.zip";
|
||||
hash = "sha256-33rg+fnIB/VJZbVKTP7b8829BbcDnfnaYFMOyPLFzEw=";
|
||||
};
|
||||
};
|
||||
unavailable = throw "azure-mcp package is not available for this platform.";
|
||||
src = fetchzip {
|
||||
inherit (srcs.${stdenv.hostPlatform.system} or unavailable) url hash;
|
||||
stripRoot = false;
|
||||
};
|
||||
in
|
||||
stdenv.mkDerivation {
|
||||
pname = "azure-mcp";
|
||||
inherit version src;
|
||||
|
||||
strictDeps = true;
|
||||
__structuredAttrs = true;
|
||||
|
||||
nativeBuildInputs = [
|
||||
makeWrapper
|
||||
]
|
||||
++ lib.optionals stdenv.hostPlatform.isLinux [ autoPatchelfHook ];
|
||||
|
||||
buildInputs = lib.optionals stdenv.hostPlatform.isLinux [
|
||||
stdenv.cc.cc.lib
|
||||
];
|
||||
|
||||
dontConfigure = true;
|
||||
dontBuild = true;
|
||||
|
||||
installPhase = ''
|
||||
runHook preInstall
|
||||
|
||||
install -Dm755 ./azmcp $out/bin/azure-mcp
|
||||
|
||||
wrapProgram $out/bin/azure-mcp \
|
||||
--prefix PATH : ${lib.makeBinPath [ azure-cli ]}
|
||||
|
||||
runHook postInstall
|
||||
'';
|
||||
|
||||
meta = {
|
||||
description = "Model Context Protocol server for Azure services";
|
||||
longDescription = ''
|
||||
The Azure MCP Server implements the Model Context Protocol (MCP)
|
||||
specification to create a seamless connection between AI agents and
|
||||
Azure services. It provides 321+ tools for interacting with Azure
|
||||
resources including storage, compute, databases, and more.
|
||||
'';
|
||||
homepage = "https://github.com/microsoft/mcp";
|
||||
changelog = "https://github.com/microsoft/mcp/blob/Azure.Mcp.Server-${version}/servers/Azure.Mcp.Server/CHANGELOG.md";
|
||||
license = lib.licenses.mit;
|
||||
sourceProvenance = [ lib.sourceTypes.binaryNativeCode ];
|
||||
platforms = lib.attrNames srcs;
|
||||
mainProgram = "azure-mcp";
|
||||
maintainers = with lib.maintainers; [ sheeeng ];
|
||||
};
|
||||
}
|
||||
@@ -2,6 +2,7 @@
|
||||
lib,
|
||||
python3Packages,
|
||||
fetchPypi,
|
||||
fetchgit,
|
||||
patatt,
|
||||
}:
|
||||
|
||||
@@ -31,6 +32,15 @@ python3Packages.buildPythonApplication (finalAttrs: {
|
||||
textual
|
||||
];
|
||||
|
||||
passthru = {
|
||||
src-misc = fetchgit {
|
||||
url = "https://git.kernel.org/pub/scm/utils/b4/b4.git";
|
||||
rev = "v${finalAttrs.version}";
|
||||
hash = "sha256-NjYL3RKQpjDkU98qbXyl/cvLTJYVAfIowm8E2Rg8AgI=";
|
||||
fetchSubmodules = false;
|
||||
};
|
||||
};
|
||||
|
||||
meta = {
|
||||
homepage = "https://git.kernel.org/pub/scm/utils/b4/b4.git/about";
|
||||
license = lib.licenses.gpl2Only;
|
||||
|
||||
@@ -20,13 +20,13 @@ let
|
||||
in
|
||||
buildBazelPackage rec {
|
||||
pname = "bant";
|
||||
version = "0.3.0";
|
||||
version = "0.3.3";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "hzeller";
|
||||
repo = "bant";
|
||||
rev = "v${version}";
|
||||
hash = "sha256-T/BQRYCFAHkaGi5T485I9vbr3g7PzgIEHC27w6mg/3A=";
|
||||
hash = "sha256-6c403+DK1tcQxC16FKEtdhnJEA9LJl8H8Usnw08FBnA=";
|
||||
};
|
||||
|
||||
bazelFlags = [
|
||||
|
||||
@@ -6,16 +6,16 @@
|
||||
|
||||
buildGoModule (finalAttrs: {
|
||||
pname = "bazel-remote";
|
||||
version = "2.6.1";
|
||||
version = "2.6.2";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "buchgr";
|
||||
repo = "bazel-remote";
|
||||
rev = "v${finalAttrs.version}";
|
||||
hash = "sha256-9vPaTm/HTJ3ftlFg+AkcwXX7xyhmGTgKL3PXhtUHRDk=";
|
||||
hash = "sha256-wE0l1tBtj44l1Eamd4wCHzjnPhT7W5yZ5MkTA5cOUrg=";
|
||||
};
|
||||
|
||||
vendorHash = "sha256-uh8ST1AQ8OsFMfXly23TMMcheNmhb1MknmPMjB76GIQ=";
|
||||
vendorHash = "sha256-DGyGQLEAwy79ibWGxAWa7gmaXTajcW3jqGJou2Wnykc=";
|
||||
|
||||
subPackages = [ "." ];
|
||||
|
||||
|
||||
@@ -8,17 +8,17 @@
|
||||
|
||||
buildGoModule (finalAttrs: {
|
||||
pname = "bento";
|
||||
version = "1.18.1";
|
||||
version = "1.19.0";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "warpstreamlabs";
|
||||
repo = "bento";
|
||||
tag = "v${finalAttrs.version}";
|
||||
hash = "sha256-KIlCHOAHShOwrxO9F414PQ07+SzCWhpo8auhyjkuNZA=";
|
||||
hash = "sha256-3ZISLZzh8FYAE9riZ5Ya5h3LhwzHK4a5jJl8jeHiNoA=";
|
||||
};
|
||||
|
||||
proxyVendor = true;
|
||||
vendorHash = "sha256-uzB98AiJKw9TCbKSdQDiztfw7nIT0mVt80JALAPp2Aw=";
|
||||
vendorHash = "sha256-h9bH5aewbDAuOVAps3TMihjCITFiBT/bbqNJCUT0NN8=";
|
||||
|
||||
subPackages = [
|
||||
"cmd/bento"
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
# Generated by ./update.sh - do not update manually!
|
||||
# Generated by ./update.sh
|
||||
{
|
||||
version = "1.10.3";
|
||||
deb-hash = "sha256-kzLtadq8gfX6j9XU3PD5kNV43wLDoICPlXdJqULkAWE=";
|
||||
sig-hash = "sha256-+51j+SBp7buukop1T4Gz0YDUga6540BVxDRoU2YE3pY=";
|
||||
version = "1.10.4";
|
||||
deb-hash = "sha256-rOFbiuEbeO2qZntUhO+LNhwX6XlvWRU9v0HIAjyHwd8=";
|
||||
sig-hash = "sha256-3fAGauXHA8S+XIuHeOIFxp7TsXd1LdqFg8hpWIU4P7k=";
|
||||
key-E222AA02-hash = "sha256-Ue/UmS6F440/ybEEIAR+pdPEIksAt6QSMN6G5TZVWzc=";
|
||||
key-4A133008-hash = "sha256-UijG3DkJNNTakVJd2wl30mDepa27n6R/Xxfl4sjt0sk=";
|
||||
key-387C8307-hash = "sha256-PrRYZLT0xv82dUscOBgQGKNf6zwzWUDhriAffZbNpmI=";
|
||||
|
||||
@@ -14,13 +14,13 @@
|
||||
|
||||
buildNpmPackage (finalAttrs: {
|
||||
pname = "bitwarden-cli";
|
||||
version = "2026.6.0";
|
||||
version = "2026.7.0";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "bitwarden";
|
||||
repo = "clients";
|
||||
tag = "cli-v${finalAttrs.version}";
|
||||
hash = "sha256-JIIis3wW0cU33ovRQfJi3HlB2YdLZ5IPvueq1dGFbas=";
|
||||
hash = "sha256-8PYjRa1lhs53FCfqPBqH9712X1ek02wbkI+kW5tkepE=";
|
||||
};
|
||||
|
||||
postPatch = ''
|
||||
@@ -31,7 +31,7 @@ buildNpmPackage (finalAttrs: {
|
||||
nodejs = nodejs_22;
|
||||
npmDepsFetcherVersion = 2;
|
||||
|
||||
npmDepsHash = "sha256-sXFSjQw9iM5Ye03BX+ZzpDfeAyLTJoG/k46NiI3O8+A=";
|
||||
npmDepsHash = "sha256-WRxlvkgWboO0ukUHgjC5CrfgfwnmUfDXI4r5dx9CKww=";
|
||||
|
||||
nativeBuildInputs = lib.optionals stdenv.hostPlatform.isDarwin [
|
||||
perl
|
||||
|
||||
@@ -31,8 +31,10 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
'';
|
||||
|
||||
nativeBuildInputs = [
|
||||
gobject-introspection
|
||||
meson
|
||||
ninja
|
||||
python3
|
||||
wrapGAppsNoGuiHook
|
||||
];
|
||||
|
||||
@@ -86,6 +88,8 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
};
|
||||
};
|
||||
|
||||
strictDeps = true;
|
||||
|
||||
meta = {
|
||||
description = "Markup language for GTK user interface files";
|
||||
mainProgram = "blueprint-compiler";
|
||||
|
||||
@@ -12,16 +12,16 @@
|
||||
|
||||
rustPlatform.buildRustPackage (finalAttrs: {
|
||||
pname = "bottom";
|
||||
version = "0.14.4";
|
||||
version = "0.14.6";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "ClementTsang";
|
||||
repo = "bottom";
|
||||
tag = finalAttrs.version;
|
||||
hash = "sha256-axzZEviUVosXo5XzQB32A2+sUdiLzEtjZg52Z6hp4lM=";
|
||||
hash = "sha256-52aUYfFm72nSG7bAlwa18kMu13i+c4myl2QfaA2YZmw=";
|
||||
};
|
||||
|
||||
cargoHash = "sha256-RUFlv95VoRhfHeIXWFWWtbwn71uJnEYoi2NozU4ybK8=";
|
||||
cargoHash = "sha256-N+dfYORAdWAg5qUrFEgXbiRtYJpcvV1AcbLR5WiD0QI=";
|
||||
|
||||
nativeBuildInputs = [
|
||||
autoAddDriverRunpath
|
||||
|
||||
@@ -1,35 +0,0 @@
|
||||
# Expression generated by update.sh; do not edit it by hand!
|
||||
{ stdenv, callPackage, ... }@args:
|
||||
|
||||
let
|
||||
pname = "brave";
|
||||
version = "1.92.143";
|
||||
|
||||
allArchives = {
|
||||
aarch64-linux = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_arm64.deb";
|
||||
hash = "sha256-IHBJm9uow2d/X4Z9e117aGdP1Y+3R1ApWu40sPtdbr8=";
|
||||
};
|
||||
x86_64-linux = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_amd64.deb";
|
||||
hash = "sha256-jaxNneurduBiw3jho5Fp7gXnBfSpLB5hlE06i/JK+ic=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-v${version}-darwin-arm64.zip";
|
||||
hash = "sha256-EvfZgO8FAijof1Ml6gqSOyRndL8KYFdT0MNmVmuxAnU=";
|
||||
};
|
||||
};
|
||||
|
||||
archive =
|
||||
if builtins.hasAttr stdenv.system allArchives then
|
||||
allArchives.${stdenv.system}
|
||||
else
|
||||
throw "Unsupported platform.";
|
||||
|
||||
in
|
||||
callPackage ./make-brave.nix (removeAttrs args [ "callPackage" ]) (
|
||||
archive
|
||||
// {
|
||||
inherit pname version;
|
||||
}
|
||||
)
|
||||
@@ -1,48 +0,0 @@
|
||||
#!/usr/bin/env nix-shell
|
||||
#!nix-shell -i bash -p curl gnused nix jq
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" &>/dev/null && pwd)"
|
||||
|
||||
latestVersion="$(curl --fail -s ${GITHUB_TOKEN:+-u ":$GITHUB_TOKEN"} "https://api.github.com/repos/brave/brave-browser/releases/latest" | jq -r '.tag_name' | sed 's/^v//')"
|
||||
|
||||
hashAarch64="$(nix-hash --to-sri --type sha256 "$(nix-prefetch-url --type sha256 "https://github.com/brave/brave-browser/releases/download/v${latestVersion}/brave-browser_${latestVersion}_arm64.deb")")"
|
||||
hashAmd64="$(nix-hash --to-sri --type sha256 "$(nix-prefetch-url --type sha256 "https://github.com/brave/brave-browser/releases/download/v${latestVersion}/brave-browser_${latestVersion}_amd64.deb")")"
|
||||
hashAarch64Darwin="$(nix-hash --to-sri --type sha256 "$(nix-prefetch-url --type sha256 "https://github.com/brave/brave-browser/releases/download/v${latestVersion}/brave-v${latestVersion}-darwin-arm64.zip")")"
|
||||
|
||||
cat > $SCRIPT_DIR/package.nix << EOF
|
||||
# Expression generated by update.sh; do not edit it by hand!
|
||||
{ stdenv, callPackage, ... }@args:
|
||||
|
||||
let
|
||||
pname = "brave";
|
||||
version = "${latestVersion}";
|
||||
|
||||
allArchives = {
|
||||
aarch64-linux = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v\${version}/brave-browser_\${version}_arm64.deb";
|
||||
hash = "${hashAarch64}";
|
||||
};
|
||||
x86_64-linux = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v\${version}/brave-browser_\${version}_amd64.deb";
|
||||
hash = "${hashAmd64}";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://github.com/brave/brave-browser/releases/download/v\${version}/brave-v\${version}-darwin-arm64.zip";
|
||||
hash = "${hashAarch64Darwin}";
|
||||
};
|
||||
};
|
||||
|
||||
archive =
|
||||
if builtins.hasAttr stdenv.system allArchives then
|
||||
allArchives.\${stdenv.system}
|
||||
else
|
||||
throw "Unsupported platform.";
|
||||
|
||||
in
|
||||
callPackage ./make-brave.nix (removeAttrs args [ "callPackage" ]) (
|
||||
archive
|
||||
// {
|
||||
inherit pname version;
|
||||
}
|
||||
)
|
||||
EOF
|
||||
@@ -21,13 +21,13 @@
|
||||
|
||||
buildNpmPackage rec {
|
||||
pname = "bruno";
|
||||
version = "3.5.2";
|
||||
version = "4.0.0";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "usebruno";
|
||||
repo = "bruno";
|
||||
tag = "v${version}";
|
||||
hash = "sha256-Lll/ywDkHv0xvLk8iiBEySek7A3dBmfO4V/q2xaNtBQ=";
|
||||
hash = "sha256-M4oNx3nSe8hSAtZMVyXIW0qQIQkaOeQgpPsfjmmJ30E=";
|
||||
|
||||
postFetch = ''
|
||||
${lib.getExe npm-lockfile-fix} $out/package-lock.json
|
||||
@@ -36,7 +36,7 @@ buildNpmPackage rec {
|
||||
|
||||
nodejs = nodejs_22;
|
||||
|
||||
npmDepsHash = "sha256-4VsSXiHj/INCu4ryZ+JxPbfDpsgIb5eYvOUYz+gbKEE=";
|
||||
npmDepsHash = "sha256-Jrlpztg1JxuPaLD4O9elOaU1eFH3dmr6oWwi4Ch9Zv8=";
|
||||
npmFlags = [ "--legacy-peer-deps" ];
|
||||
|
||||
nativeBuildInputs = [
|
||||
@@ -77,6 +77,10 @@ buildNpmPackage rec {
|
||||
# fix version reported in sidebar and about page
|
||||
${jq}/bin/jq '.version |= "${version}"' packages/bruno-electron/package.json | ${moreutils}/bin/sponge packages/bruno-electron/package.json
|
||||
${jq}/bin/jq '.version |= "${version}"' packages/bruno-app/package.json | ${moreutils}/bin/sponge packages/bruno-app/package.json
|
||||
|
||||
# disable remote image download to prevent network calls to comply with build sandboxing
|
||||
substituteInPlace packages/bruno-app/plugins/remote-images/loader.cjs \
|
||||
--replace-fail 'const urls = findRemoteImageUrls(source, domains);' 'const urls = [];'
|
||||
'';
|
||||
|
||||
postConfigure = ''
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
clutter-gtk,
|
||||
gst_all_1,
|
||||
glib,
|
||||
gtk2,
|
||||
gtk3,
|
||||
libgsf,
|
||||
libxml2,
|
||||
fluidsynth,
|
||||
@@ -52,7 +52,7 @@ stdenv.mkDerivation {
|
||||
gst_all_1.gst-plugins-base
|
||||
gst_all_1.gst-plugins-good
|
||||
glib
|
||||
gtk2
|
||||
gtk3
|
||||
libgsf
|
||||
libxml2
|
||||
# optional packages
|
||||
|
||||
@@ -11,16 +11,16 @@
|
||||
|
||||
rustPlatform.buildRustPackage (finalAttrs: {
|
||||
pname = "cargo-binstall";
|
||||
version = "1.21.0";
|
||||
version = "1.21.1";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "cargo-bins";
|
||||
repo = "cargo-binstall";
|
||||
tag = "v${finalAttrs.version}";
|
||||
hash = "sha256-6msYAVCN1i2srA4DquqcdJxUrJP1jub34c/a/4RbWCg=";
|
||||
hash = "sha256-7YXdKK6P6LSf/DGDL6jroR3VVqAD4uGUOGJS/dZbcvw=";
|
||||
};
|
||||
|
||||
cargoHash = "sha256-r9iGWxrLlD83QtvZuWXIxjI2S0RO1GNwOed531FVvJk=";
|
||||
cargoHash = "sha256-iUYTFtx0KBi4qgJNyuIAGcTCbS4KMyBbTIgR3nDiNAI=";
|
||||
|
||||
nativeBuildInputs = [
|
||||
pkg-config
|
||||
|
||||
@@ -8,15 +8,15 @@
|
||||
|
||||
rustPlatform.buildRustPackage (finalAttrs: {
|
||||
pname = "cargo-shear";
|
||||
version = "1.13.2";
|
||||
version = "1.13.3";
|
||||
|
||||
src = fetchCrate {
|
||||
pname = "cargo-shear";
|
||||
version = finalAttrs.version;
|
||||
hash = "sha256-69OwhT4vc4xwvuVxZ0C7F/Us01TsuYJnnTKT6PHsOF8=";
|
||||
hash = "sha256-Qaq3nBZZR0biG5kVL15zhI8GwLEWBNzgeD3rHeZZOeU=";
|
||||
};
|
||||
|
||||
cargoHash = "sha256-x0lZ8E/P9IaPSdzUo2O3t5qR2I3959So9uaAm4PBM4E=";
|
||||
cargoHash = "sha256-3YMdOCCK+rVx0XZfBqiMAw+aep1TBU5Ok6//c433h4o=";
|
||||
|
||||
env = {
|
||||
# https://github.com/Boshen/cargo-shear/blob/v1.6.2/src/lib.rs#L51-L54
|
||||
|
||||
@@ -8,40 +8,45 @@
|
||||
apple-sdk_15,
|
||||
libiconv,
|
||||
versionCheckHook,
|
||||
nix-update-script,
|
||||
nix-update,
|
||||
writeShellApplication,
|
||||
curl,
|
||||
runCommand,
|
||||
jq,
|
||||
}:
|
||||
|
||||
let
|
||||
# ccusage embeds the LiteLLM model-pricing table at build time. Its build
|
||||
# script otherwise downloads this file from the network, which fails in the
|
||||
# sandbox. Upstream pins the data via a flake input and points
|
||||
# CCUSAGE_PRICING_JSON_PATH at it; mirror that exact revision here so the
|
||||
# build is offline and reproducible (see package.nix + flake.lock in the
|
||||
# upstream repo at tag v20.0.6). Bump this revision together with the package
|
||||
# version; nix-update only refreshes the src and cargo hashes.
|
||||
# ccusage embeds the LiteLLM model-pricing table at build time instead of
|
||||
# downloading it (the Nix sandbox has no network). Upstream pins the exact
|
||||
# data revision via its flake.lock and points CCUSAGE_PRICING_JSON_PATH at it;
|
||||
# we mirror that revision here so the build is offline, reproducible, and
|
||||
# byte-identical to what upstream ships.
|
||||
#
|
||||
# Both values below are kept in sync with the package version by
|
||||
# passthru.updateScript — do not edit them by hand.
|
||||
litellmPricingRev = "49ca04d8c3ddea336237ce6f3082dbc26d19e944";
|
||||
litellmPricingHash = "sha256-rkUyugxdoD7WlPN//6BQpl4OJQuBbc20db7gt7exqpc=";
|
||||
litellmPricing = fetchurl {
|
||||
url = "https://raw.githubusercontent.com/BerriAI/litellm/f27df8d516802ce4c1b32973992154fe83b851cf/model_prices_and_context_window.json";
|
||||
hash = "sha256-zJa6H2EwP9s+hMVs78Y+hwo4UX1dHRtvX5J3MdGh5aI=";
|
||||
url = "https://raw.githubusercontent.com/BerriAI/litellm/${litellmPricingRev}/model_prices_and_context_window.json";
|
||||
hash = litellmPricingHash;
|
||||
};
|
||||
in
|
||||
rustPlatform.buildRustPackage (finalAttrs: {
|
||||
pname = "ccusage";
|
||||
version = "20.0.6";
|
||||
version = "20.0.17";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "ccusage";
|
||||
repo = "ccusage";
|
||||
tag = "v${finalAttrs.version}";
|
||||
hash = "sha256-uf/FlPprxx4jh74YwjmYMtoIHpTkKrWTLetbNoYiFv4=";
|
||||
hash = "sha256-486iLPRqQVRnKVbVT93D08RTRzd6/h503ckB//24nho=";
|
||||
};
|
||||
|
||||
# The Cargo workspace lives in rust/, not at the repo root.
|
||||
cargoRoot = "rust";
|
||||
buildAndTestSubdir = "rust";
|
||||
|
||||
cargoHash = "sha256-izA2Gs5nPmt0zn6/e1xM80vyyQHYKGEUDpUFRpyFiB8=";
|
||||
cargoHash = "sha256-23l/BCCGcZ1i5mFBC6Q+FE7sQRHnPLbU4QoQe7TfoiQ=";
|
||||
|
||||
__structuredAttrs = true;
|
||||
strictDeps = true;
|
||||
@@ -72,7 +77,40 @@ rustPlatform.buildRustPackage (finalAttrs: {
|
||||
doInstallCheck = true;
|
||||
|
||||
passthru = {
|
||||
updateScript = nix-update-script { };
|
||||
# Plain nix-update only refreshes version + src/cargo hashes; it can't know
|
||||
# about the LiteLLM pricing pin above. This wrapper bumps the package as
|
||||
# usual, then reads the litellm revision that ccusage locks at the new tag
|
||||
# and rewrites litellmPricingRev/litellmPricingHash to match, so automated
|
||||
# (r-ryantm) bumps stay complete instead of shipping stale pricing data.
|
||||
updateScript = lib.getExe (writeShellApplication {
|
||||
name = "ccusage-update";
|
||||
runtimeInputs = [
|
||||
curl
|
||||
jq
|
||||
nix-update
|
||||
];
|
||||
text = ''
|
||||
set -euo pipefail
|
||||
|
||||
attr="''${UPDATE_NIX_ATTR_PATH:-ccusage}"
|
||||
|
||||
nix-update "$attr"
|
||||
|
||||
version=$(nix-instantiate --eval --raw -A "$attr.version")
|
||||
rev=$(curl --fail --silent --show-error --location \
|
||||
"https://raw.githubusercontent.com/ccusage/ccusage/v''${version}/flake.lock" \
|
||||
| jq --raw-output '.nodes.litellm.locked.rev')
|
||||
hash=$(nix-prefetch-url --type sha256 \
|
||||
"https://raw.githubusercontent.com/BerriAI/litellm/''${rev}/model_prices_and_context_window.json" \
|
||||
| xargs nix --extra-experimental-features nix-command hash convert --hash-algo sha256 --to sri)
|
||||
|
||||
file=$(nix-instantiate --eval --raw -A "$attr.meta.position" | sed -re 's/:[0-9]+$//')
|
||||
sed -i \
|
||||
-e "s|litellmPricingRev = \"[0-9a-f]*\"|litellmPricingRev = \"''${rev}\"|" \
|
||||
-e "s|litellmPricingHash = \"sha256-[^\"]*\"|litellmPricingHash = \"''${hash}\"|" \
|
||||
"$file"
|
||||
'';
|
||||
});
|
||||
|
||||
tests = {
|
||||
# With no agent data on disk, ccusage must still emit a valid, empty JSON
|
||||
|
||||
@@ -1,47 +1,47 @@
|
||||
{
|
||||
"version": "2.1.218",
|
||||
"commit": "bce61b433bc397ce68686368abd12f545b0a013a",
|
||||
"buildDate": "2026-07-22T18:42:19Z",
|
||||
"version": "2.1.219",
|
||||
"commit": "7006c4c3acac98e554d3997baeda6a7fa4d1ff7c",
|
||||
"buildDate": "2026-07-24T03:34:26Z",
|
||||
"platforms": {
|
||||
"darwin-arm64": {
|
||||
"binary": "claude",
|
||||
"checksum": "71abaff59312c9a9b6a1d818365048b42e4e95cc521a823660eded3e0880d9b7",
|
||||
"size": 255069680
|
||||
"checksum": "a8e806faaefac53c7a0f26523d8a45c60dbef3407b14ef990c75765d08febc82",
|
||||
"size": 256908272
|
||||
},
|
||||
"darwin-x64": {
|
||||
"binary": "claude",
|
||||
"checksum": "9862b74a083e8a4ed572f99cbd4895185e0dd5a0a601affb0fb8e43d8d1f40e6",
|
||||
"size": 264548368
|
||||
"checksum": "03be9f988ed88391b4a5f08e4c5dc317ce2fffa4a9dc66c01106326e7698ee76",
|
||||
"size": 266381200
|
||||
},
|
||||
"linux-arm64": {
|
||||
"binary": "claude",
|
||||
"checksum": "295fd30481bd03b38450fdec2a6e25bb6472c2074f04b0c4a566cd5988f230bf",
|
||||
"size": 269990816
|
||||
"checksum": "1f834b322ba9d1291cc7ffeff16a6795a59145bda279dbd59cd7ecebc7b7f15a",
|
||||
"size": 271825824
|
||||
},
|
||||
"linux-x64": {
|
||||
"binary": "claude",
|
||||
"checksum": "e12071751a9336b8af1012c103358ff04ac18f9aaff4a738cff7ba5cdfaf63f2",
|
||||
"size": 273177584
|
||||
"checksum": "22cfd6f5b3061c0391ba84e9cf8c9deaa37783aac18b004d42ec061e98f00691",
|
||||
"size": 275004400
|
||||
},
|
||||
"linux-arm64-musl": {
|
||||
"binary": "claude",
|
||||
"checksum": "efcaae48f8f537a0e9a47b4317a5f8c184706c99ddd8ca0a9a21391e2a766ef8",
|
||||
"size": 263239016
|
||||
"checksum": "22b2c2e0f41ab0b7c7b8845be9c49fe6f27e4c344aab1bd174bdf84a4e6b0570",
|
||||
"size": 265074024
|
||||
},
|
||||
"linux-x64-musl": {
|
||||
"binary": "claude",
|
||||
"checksum": "62986293277153f5db97404cf7e3e96de136f02c28f79ccd5c7bc99766224db4",
|
||||
"size": 267801168
|
||||
"checksum": "487008769dd69599adb779205b6b371de27b4245f0ad2ad70f15baf4eac5f81e",
|
||||
"size": 269627984
|
||||
},
|
||||
"win32-x64": {
|
||||
"binary": "claude.exe",
|
||||
"checksum": "81fcf59bb7abb558aedc6f2361f4723b3d757d28e799962d88b18b4520df66ca",
|
||||
"size": 263931552
|
||||
"checksum": "10f4c1f85b07f3cf6b8fff930fd26ecd475bd146a378acfafa559a6db9d89637",
|
||||
"size": 265714848
|
||||
},
|
||||
"win32-arm64": {
|
||||
"binary": "claude.exe",
|
||||
"checksum": "a7959fd87feb9557d56f4e5752f7ed1ddf405f3bea91b2571bf93af636efd193",
|
||||
"size": 258307232
|
||||
"checksum": "6a1db10161b93e81ac55537feeae8a299f0bf67601c1c0f2016e79c850302baa",
|
||||
"size": 260090016
|
||||
}
|
||||
},
|
||||
"sdkCompat": {
|
||||
@@ -68,7 +68,8 @@
|
||||
"0.3.208",
|
||||
"0.3.209",
|
||||
"0.3.215",
|
||||
"0.3.217"
|
||||
"0.3.217",
|
||||
"0.3.218"
|
||||
],
|
||||
"harnessSchema": 1
|
||||
}
|
||||
|
||||
@@ -16,11 +16,11 @@
|
||||
socat,
|
||||
versionCheckHook,
|
||||
writableTmpDirAsHomeHook,
|
||||
manifest ? lib.importJSON ./manifest.json,
|
||||
}:
|
||||
let
|
||||
stdenv = stdenvNoCC;
|
||||
baseUrl = "https://downloads.claude.ai/claude-code-releases";
|
||||
manifest = lib.importJSON ./manifest.json;
|
||||
platformKey = "${stdenv.hostPlatform.node.platform}-${stdenv.hostPlatform.node.arch}";
|
||||
platformManifestEntry = manifest.platforms.${platformKey};
|
||||
in
|
||||
|
||||
@@ -9,13 +9,13 @@
|
||||
|
||||
buildGoModule (finalAttrs: {
|
||||
pname = "cloudflared";
|
||||
version = "2026.7.2";
|
||||
version = "2026.7.3";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "cloudflare";
|
||||
repo = "cloudflared";
|
||||
tag = finalAttrs.version;
|
||||
hash = "sha256-fuJfvm5c63koMl46sJmZOiWuNKpOwH17MD20XD7q6s0=";
|
||||
hash = "sha256-hIDx9Nd7CKlM0vCKqkVHxBMj4QzvnnsYYMjhzOqcECU=";
|
||||
};
|
||||
|
||||
vendorHash = null;
|
||||
|
||||
@@ -11,17 +11,17 @@
|
||||
|
||||
rustPlatform.buildRustPackage (finalAttrs: {
|
||||
pname = "communique";
|
||||
version = "1.2.1";
|
||||
version = "1.2.3";
|
||||
__structuredAttrs = true;
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "jdx";
|
||||
repo = "communique";
|
||||
tag = "v${finalAttrs.version}";
|
||||
hash = "sha256-lQN6LViO3Ta6eCbU6j76OFN95R6A0hP3Pfc38KrHDng=";
|
||||
hash = "sha256-F7m6PxPOuQlZFIVYBUl650JsaZVJJmC1c+6jMgmGgc8=";
|
||||
};
|
||||
|
||||
cargoHash = "sha256-RJzjpDhxpi7Zmzw9kl48yq6//zTYOeJ+SrgAfqq/tl4=";
|
||||
cargoHash = "sha256-KyGbkVNi2rHTJfIeeq6nVFDhkWmaKh/IZ6xiVxPaXWQ=";
|
||||
|
||||
nativeCheckInputs = [
|
||||
cacert
|
||||
|
||||
@@ -24,13 +24,13 @@
|
||||
|
||||
stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "cubeb";
|
||||
version = "0-unstable-2026-07-16";
|
||||
version = "0-unstable-2026-07-25";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "mozilla";
|
||||
repo = "cubeb";
|
||||
rev = "0942f635f78049fc8af24939effed255ae0d0044";
|
||||
hash = "sha256-RQqmrRXRABsNDjGztsLLjsZlZFBEeAAc/ysoDj6CT1A=";
|
||||
rev = "ef47ae581df7c2f76058d554b3edde17f9ee7cba";
|
||||
hash = "sha256-vGTB0xsIv89ua9tltdjkxLChVvTKra4kxaWCxszG3x0=";
|
||||
};
|
||||
|
||||
outputs = [
|
||||
|
||||
@@ -8,11 +8,11 @@
|
||||
|
||||
stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "cutemaze";
|
||||
version = "1.3.6";
|
||||
version = "1.3.7";
|
||||
|
||||
src = fetchurl {
|
||||
url = "https://gottcode.org/cutemaze/cutemaze-${finalAttrs.version}.tar.bz2";
|
||||
hash = "sha256-Fl/fsKB04Kn4HwkNlpcuR3wTJFfn1gGgRGTwRUNDawY=";
|
||||
hash = "sha256-iaT55oVw5j3ttAiWW5y6QlQDsoUKRppDtNSLKUBNr2E=";
|
||||
};
|
||||
|
||||
nativeBuildInputs = [
|
||||
|
||||
@@ -56,7 +56,7 @@ let
|
||||
davinci = (
|
||||
stdenv.mkDerivation rec {
|
||||
pname = "davinci-resolve${lib.optionalString studioVariant "-studio"}";
|
||||
version = "21.0.1";
|
||||
version = "21.0.3";
|
||||
|
||||
nativeBuildInputs = [
|
||||
appimageTools.appimage-exec
|
||||
@@ -78,9 +78,9 @@ let
|
||||
outputHashAlgo = "sha256";
|
||||
outputHash =
|
||||
if studioVariant then
|
||||
"sha256-8JN3ptd8jcacxHihZHXuhdkyambUsnFIj+AruvpztKI="
|
||||
"sha256-pEJF+FQlBngEi5YlKq/pFNCzBiQgqjQrTnfrlKEEi6s="
|
||||
else
|
||||
"sha256-ioAqvqHjwFX1ec6fDoxg2VUZy1moYoGx/aEewDuN1+g=";
|
||||
"sha256-3SymaLm3ibyk8yOWcUS9fOfnKEmgVA5XXc5tls27qfo=";
|
||||
|
||||
impureEnvVars = lib.fetchers.proxyImpureEnvVars;
|
||||
|
||||
|
||||
@@ -19,7 +19,7 @@
|
||||
|
||||
stdenvNoCC.mkDerivation (finalAttrs: {
|
||||
pname = "dbeaver-bin";
|
||||
version = "26.1.1";
|
||||
version = "26.1.3";
|
||||
|
||||
src =
|
||||
let
|
||||
@@ -31,9 +31,9 @@ stdenvNoCC.mkDerivation (finalAttrs: {
|
||||
aarch64-darwin = "macos-aarch64.dmg";
|
||||
};
|
||||
hash = selectSystem {
|
||||
x86_64-linux = "sha256-atbQ00lq589FlNem85NgzTKGyhTRpFII8OSfVfYQuD0=";
|
||||
aarch64-linux = "sha256-Sde0q31hXMqX2oxfhgj5EcpeUYYFZJy61usaJVpZkLM=";
|
||||
aarch64-darwin = "sha256-PwuFwEE+aBEG/ykwNrEBl20yfrade8BdUUHdLJGBkwc=";
|
||||
x86_64-linux = "sha256-cPRmReV6F+pCkrbF7d1m+bQjOaJCCFndNSThMWPGrsY=";
|
||||
aarch64-linux = "sha256-bT1bCKzeiAMJbPa6I6fqQq7OrbkKhgDYAUEKuURHP5g=";
|
||||
aarch64-darwin = "sha256-NYX651gUpEDh2O720ZKl7fUTYLFKpTJzyC/YnN4Vnys=";
|
||||
};
|
||||
in
|
||||
fetchurl {
|
||||
|
||||
@@ -33,7 +33,7 @@ let
|
||||
in
|
||||
rustPlatform.buildRustPackage (finalAttrs: {
|
||||
pname = "deno";
|
||||
version = "2.9.3";
|
||||
version = "2.9.4";
|
||||
|
||||
__structuredAttrs = true;
|
||||
|
||||
@@ -47,10 +47,10 @@ rustPlatform.buildRustPackage (finalAttrs: {
|
||||
repo = "deno";
|
||||
tag = "v${finalAttrs.version}";
|
||||
fetchSubmodules = true; # required for tests
|
||||
hash = "sha256-XMHlWK+lhyn1KO1CSxcuM3KzTjYviVrRw+FUL74bBPc=";
|
||||
hash = "sha256-ivch++yGRUyWtox/5QqomC4DlTvMBxK+gIcN9/7tt5E=";
|
||||
};
|
||||
|
||||
cargoHash = "sha256-WZxyoD9WMnaLyD3/86R90KWC+9OA15fIMw8SjmovNHA=";
|
||||
cargoHash = "sha256-ynbHLZXkPPYpsC4dCu6jA6x8ftiTHWZ/uxzdbUcUaa0=";
|
||||
|
||||
patches = [
|
||||
./patches/0002-tests-replace-hardcoded-paths.patch
|
||||
@@ -211,6 +211,8 @@ rustPlatform.buildRustPackage (finalAttrs: {
|
||||
++ lib.optionals stdenv.hostPlatform.isLinux [
|
||||
# Wants to access /etc/resolv.conf: https://github.com/hickory-dns/hickory-dns/issues/2959
|
||||
"--skip=tests::test_userspace_resolver"
|
||||
# We don't have a tmp dir with sticky bit during build
|
||||
"--skip=util::temp::test::test_ensure_secure_temp_parent_rejects_non_sticky_writable_dir"
|
||||
];
|
||||
|
||||
__darwinAllowLocalNetworking = true;
|
||||
|
||||
16
pkgs/by-name/de/deno/rusty-v8/c_additional_outputs.patch
Normal file
16
pkgs/by-name/de/deno/rusty-v8/c_additional_outputs.patch
Normal file
@@ -0,0 +1,16 @@
|
||||
Submodule build contains modified content
|
||||
diff --git a/build/config/compiler/BUILD.gn b/build/config/compiler/BUILD.gn
|
||||
index 11ddb4916..0bd001600 100644
|
||||
--- a/build/config/compiler/BUILD.gn
|
||||
+++ b/build/config/compiler/BUILD.gn
|
||||
@@ -2827,10 +2827,6 @@ config("split_dwarf") {
|
||||
# thinlto requires -gsplit-dwarf in ldflags.
|
||||
if (use_thin_lto && !is_apple) {
|
||||
ldflags = split_dwarf_flags
|
||||
- } else {
|
||||
- # .dwo files are generated when ThinLTO is not used.
|
||||
- c_additional_outputs =
|
||||
- [ "{{target_out_dir}}/{{label_name}}/{{source_name_part}}.dwo" ]
|
||||
}
|
||||
}
|
||||
|
||||
@@ -71,26 +71,27 @@ let
|
||||
in
|
||||
rustPlatform.buildRustPackage (finalAttrs: {
|
||||
pname = "rusty-v8";
|
||||
version = "149.4.0";
|
||||
version = "150.2.0";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "denoland";
|
||||
repo = "rusty_v8";
|
||||
tag = "v${finalAttrs.version}";
|
||||
fetchSubmodules = true;
|
||||
hash = "sha256-n4dKtki9ov0lWBeLmMDI4Tpk8zQ8YYSf04QW6DTYisY=";
|
||||
hash = "sha256-Iwgc08bUHR4OiwqopJua6fkQYMOdC5k9TgoCmZQrWIw=";
|
||||
};
|
||||
|
||||
patches = [
|
||||
./librusty_v8_no_downloads.patch
|
||||
./llvm22.patch
|
||||
./gn_inputs_fix.patch
|
||||
./c_additional_outputs.patch
|
||||
]
|
||||
++ lib.optionals stdenv.targetPlatform.isDarwin [
|
||||
./librusty_v8-darwin-fix-__rust_no_alloc_shim_is_unstable_v2.patch
|
||||
];
|
||||
|
||||
cargoHash = "sha256-bGqg/6sfBaF/JpObgXyP4Mh+4P9zfuzd454m4wjluGw=";
|
||||
cargoHash = "sha256-M65ODvL+o3njO3SdbJaCvgRupoguCGCIoYY/dYiJPng=";
|
||||
|
||||
nativeBuildInputs = [
|
||||
llvmPackages.clang
|
||||
|
||||
@@ -8,15 +8,17 @@
|
||||
|
||||
buildGoModule (finalAttrs: {
|
||||
pname = "diffyml";
|
||||
version = "1.7.0";
|
||||
version = "1.7.1";
|
||||
|
||||
__structuredAttrs = true;
|
||||
|
||||
__darwinAllowLocalNetworking = true;
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "szhekpisov";
|
||||
repo = "diffyml";
|
||||
tag = "v${finalAttrs.version}";
|
||||
hash = "sha256-DIKHvFY/eW3CAF/ojW+D737vFCcZk0peRrSb8I/an9Q=";
|
||||
hash = "sha256-bfFerbjpwQuTCnGKfqUj3ydf1xBdNoP+qH7UTmtZvTk=";
|
||||
};
|
||||
|
||||
vendorHash = "sha256-QE/EwVzMqUO24ZAl0WBibGx6x0kNo1AUTZtfnQvX50k=";
|
||||
|
||||
@@ -20,13 +20,13 @@
|
||||
|
||||
stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "diodon";
|
||||
version = "1.13.0";
|
||||
version = "1.14.0";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "diodon-dev";
|
||||
repo = "diodon";
|
||||
tag = finalAttrs.version;
|
||||
hash = "sha256-VCJANasrGmC0jIy8JNNURvmgpL/SLOaVsKo7Pf+X8DQ=";
|
||||
hash = "sha256-lcDJe9uJeDPtVBwh3QzQdRX4/exOl6gLStpQxLiT10M=";
|
||||
};
|
||||
|
||||
strictDeps = true;
|
||||
|
||||
126
pkgs/by-name/dr/dracut/CVE-2026-6893.patch
Normal file
126
pkgs/by-name/dr/dracut/CVE-2026-6893.patch
Normal file
@@ -0,0 +1,126 @@
|
||||
diff --git a/modules.d/35network-legacy/dhclient-script.sh b/modules.d/35network-legacy/dhclient-script.sh
|
||||
index 0cb00ab..ae68952 100755
|
||||
--- a/modules.d/35network-legacy/dhclient-script.sh
|
||||
+++ b/modules.d/35network-legacy/dhclient-script.sh
|
||||
@@ -20,11 +20,11 @@ setup_interface() {
|
||||
mask=$new_subnet_mask
|
||||
bcast=$new_broadcast_address
|
||||
gw=${new_routers%%,*}
|
||||
- domain=$new_domain_name
|
||||
+ domain=$(printf -- "%s" "$new_domain_name" | tr -d '[:cntrl:]')
|
||||
# get rid of control chars
|
||||
search=$(printf -- "%s" "$new_domain_search" | tr -d '[:cntrl:]')
|
||||
namesrv=$new_domain_name_servers
|
||||
- hostname=$new_host_name
|
||||
+ hostname=$(printf '%s' "$new_host_name" | tr -d -c 'a-zA-Z0-9.-')
|
||||
[ -n "$new_dhcp_lease_time" ] && lease_time=$new_dhcp_lease_time
|
||||
[ -n "$new_max_life" ] && lease_time=$new_max_life
|
||||
preferred_lft=$lease_time
|
||||
@@ -56,20 +56,32 @@ setup_interface() {
|
||||
${preferred_lft:+preferred_lft ${preferred_lft}}
|
||||
|
||||
if [ -n "$gw" ]; then
|
||||
- if [ "$mask" = "255.255.255.255" ]; then
|
||||
- # point-to-point connection => set explicit route to gateway
|
||||
- echo ip route add "$gw" dev "$netif" > /tmp/net."$netif".gw
|
||||
- fi
|
||||
+ gw_check=0
|
||||
+ for g in $gw; do
|
||||
+ case "$g" in
|
||||
+ *[!0-9.]*)
|
||||
+ gw_check=1
|
||||
+ break
|
||||
+ ;;
|
||||
+ esac
|
||||
+ done
|
||||
|
||||
- echo "$gw" | {
|
||||
- IFS=' ' read -r main_gw other_gw
|
||||
- echo ip route replace default via "$main_gw" dev "$netif" >> /tmp/net."$netif".gw
|
||||
- if [ -n "$other_gw" ]; then
|
||||
- for g in $other_gw; do
|
||||
- echo ip route add default via "$g" dev "$netif" >> /tmp/net."$netif".gw
|
||||
- done
|
||||
- fi
|
||||
- }
|
||||
+ if [ $gw_check -eq 0 ]; then
|
||||
+ if [ "$mask" = "255.255.255.255" ]; then
|
||||
+ # point-to-point connection => set explicit route to gateway
|
||||
+ echo ip route add "$gw" dev "$netif" > /tmp/net."$netif".gw
|
||||
+ fi
|
||||
+
|
||||
+ echo "$gw" | {
|
||||
+ IFS=' ' read -r main_gw other_gw
|
||||
+ echo ip route replace default via "$main_gw" dev "$netif" >> /tmp/net."$netif".gw
|
||||
+ if [ -n "$other_gw" ]; then
|
||||
+ for g in $other_gw; do
|
||||
+ echo ip route add default via "$g" dev "$netif" >> /tmp/net."$netif".gw
|
||||
+ done
|
||||
+ fi
|
||||
+ }
|
||||
+ fi
|
||||
fi
|
||||
|
||||
if getargbool 1 rd.peerdns; then
|
||||
@@ -82,15 +94,15 @@ setup_interface() {
|
||||
fi
|
||||
# Note: hostname can be fqdn OR short hostname, so chop off any
|
||||
# trailing domain name and explicitly add any domain if set.
|
||||
- [ -n "$hostname" ] && echo "echo ${hostname%."$domain"}${domain:+.$domain} > /proc/sys/kernel/hostname" > /tmp/net."$netif".hostname
|
||||
+ [ -n "$hostname" ] && echo "echo '${hostname%."$domain"}${domain:+.$domain}' > /proc/sys/kernel/hostname" > /tmp/net."$netif".hostname
|
||||
}
|
||||
|
||||
setup_interface6() {
|
||||
- domain=$new_domain_name
|
||||
+ domain=$(printf -- "%s" "$new_domain_name" | tr -d '[:cntrl:]')
|
||||
# get rid of control chars
|
||||
search=$(printf -- "%s" "$new_dhcp6_domain_search" | tr -d '[:cntrl:]')
|
||||
namesrv=$new_dhcp6_name_servers
|
||||
- hostname=$new_host_name
|
||||
+ hostname=$(printf '%s' "$new_host_name" | tr -d -c 'a-zA-Z0-9.-')
|
||||
[ -n "$new_dhcp_lease_time" ] && lease_time=$new_dhcp_lease_time
|
||||
[ -n "$new_max_life" ] && lease_time=$new_max_life
|
||||
preferred_lft=$lease_time
|
||||
@@ -105,7 +117,7 @@ setup_interface6() {
|
||||
|
||||
# Note: hostname can be fqdn OR short hostname, so chop off any
|
||||
# trailing domain name and explicitly add any domain if set.
|
||||
- [ -n "$hostname" ] && echo "echo ${hostname%."$domain"}${domain:+.$domain} > /proc/sys/kernel/hostname" > /tmp/net."$netif".hostname
|
||||
+ [ -n "$hostname" ] && echo "echo '${hostname%."$domain"}${domain:+.$domain}' > /proc/sys/kernel/hostname" > /tmp/net."$netif".hostname
|
||||
}
|
||||
|
||||
parse_option_121() {
|
||||
@@ -113,16 +125,18 @@ parse_option_121() {
|
||||
# Each route is: <mask_width> <dest_octets...> <gateway_4_octets>
|
||||
# mask_width determines how many destination octets follow (0-4)
|
||||
#
|
||||
- # This version validates arguments before operations to prevent
|
||||
- # "integer expression expected" and "shift count out of range" errors.
|
||||
+ # Validate all arguments are numeric upfront to prevent
|
||||
+ # shell injection via crafted octets in destination/gateway.
|
||||
+ for _octet in "$@"; do
|
||||
+ case "$_octet" in
|
||||
+ '' | *[!0-9]*) return 0 ;;
|
||||
+ esac
|
||||
+ done
|
||||
|
||||
while [ $# -ge 5 ]; do
|
||||
mask="$1"
|
||||
|
||||
# Validate mask is a number between 0-32
|
||||
- case "$mask" in
|
||||
- '' | *[!0-9]*) return 0 ;;
|
||||
- esac
|
||||
if [ "$mask" -lt 0 ] 2> /dev/null || [ "$mask" -gt 32 ] 2> /dev/null; then
|
||||
return 0
|
||||
fi
|
||||
@@ -150,9 +164,6 @@ parse_option_121() {
|
||||
# Check if destination is multicast (224.0.0.0 - 239.255.255.255)
|
||||
multicast=0
|
||||
if [ $need_dest -ge 1 ]; then
|
||||
- case "$1" in
|
||||
- '' | *[!0-9]*) return 0 ;;
|
||||
- esac
|
||||
if [ "$1" -ge 224 ] 2> /dev/null && [ "$1" -lt 240 ] 2> /dev/null; then
|
||||
multicast=1
|
||||
fi
|
||||
@@ -38,6 +38,12 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
hash = "sha256-2jdS7/LGuLSBBXv1R/o8yjgwdXl2l2wNbZWxq01wSb0";
|
||||
};
|
||||
|
||||
# Patch from https://github.com/dracut-ng/dracut/commit/11577739221ff38c1fd29abbba51a6c797376ed6 included in main branch.
|
||||
# Adapted to version 111 (line number and small formatting diff)
|
||||
patches = [
|
||||
./CVE-2026-6893.patch
|
||||
];
|
||||
|
||||
strictDeps = true;
|
||||
__structuredAttrs = true;
|
||||
|
||||
|
||||
@@ -2,7 +2,6 @@
|
||||
lib,
|
||||
stdenv,
|
||||
fetchFromGitHub,
|
||||
fetchpatch2,
|
||||
pkg-config,
|
||||
hackrf,
|
||||
libbladeRF,
|
||||
@@ -15,23 +14,15 @@
|
||||
|
||||
stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "dump1090";
|
||||
version = "10.2";
|
||||
version = "11.1";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "flightaware";
|
||||
repo = "dump1090";
|
||||
tag = "v${finalAttrs.version}";
|
||||
hash = "sha256-kTJ8FMugBRJaxWas/jEj4E5TmVnNpNdhq4r2YFFwgTU=";
|
||||
hash = "sha256-A6nkct7jvpPtPZ+iM2UKVckIXgNxxq5sxhyPiw5+EZk=";
|
||||
};
|
||||
|
||||
patches = [
|
||||
# Fix compilation with GCC 15: https://github.com/flightaware/dump1090/pull/261
|
||||
(fetchpatch2 {
|
||||
url = "https://github.com/flightaware/dump1090/commit/93be1da123215e8ac15a0deaffedd480e8899f77.patch?full_index=1";
|
||||
hash = "sha256-x+U86b1j+mSpqfG4oFnHEz3cd7/O57ezPUf8yBrLzbc=";
|
||||
})
|
||||
];
|
||||
|
||||
nativeBuildInputs = [ pkg-config ];
|
||||
|
||||
buildInputs = [
|
||||
@@ -44,8 +35,6 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
]
|
||||
++ lib.optional stdenv.hostPlatform.isLinux limesuite;
|
||||
|
||||
env.NIX_CFLAGS_COMPILE = lib.optionalString stdenv.cc.isClang "-Wno-implicit-function-declaration -Wno-int-conversion -Wno-unknown-warning-option";
|
||||
|
||||
buildFlags = [
|
||||
"DUMP1090_VERSION=${finalAttrs.version}"
|
||||
"showconfig"
|
||||
@@ -74,6 +63,7 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
maintainers = with lib.maintainers; [
|
||||
earldouglas
|
||||
aciceri
|
||||
ryand56
|
||||
];
|
||||
mainProgram = "dump1090";
|
||||
};
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user