Compare commits

...

2244 Commits

Author SHA1 Message Date
nixpkgs-ci[bot]
c83ea88f6b Merge staging-next into staging 2026-09-29 00:26:41 +00:00
nixpkgs-ci[bot]
1de5ccf183 Merge master into staging-next 2026-09-29 00:26:10 +00:00
dotlambda
f22577a906 imagemagick: 7.1.2-31 -> 7.1.2-32 (#568033) 2026-09-29 00:19:33 +00:00
Sebastián Mancilla
e63c96e6b5 netmaker: 1.6.0 -> 1.7.0 (#558560) 2026-09-29 00:18:16 +00:00
Sebastián Mancilla
72d0c9473d libfastjson: 1.2304.0 -> 1.2609.0 (#558862) 2026-09-29 00:12:16 +00:00
Sebastián Mancilla
555fd8f41c openlibm: 0.8.7 -> 0.8.8 (#559120) 2026-09-28 23:51:46 +00:00
Sebastián Mancilla
dfb139b35d liblouis: 3.38.0 -> 3.39.0 (#558865) 2026-09-28 23:47:33 +00:00
Matt Sturgeon
bacda13ecd maintainers/github-teams.json: Automated sync (#567993) 2026-09-28 23:19:32 +00:00
Nick Cao
81a3b1f4c0 libkrun: 1.19.0 -> 1.19.5 (#535030) 2026-09-28 22:47:06 +00:00
Nick Cao
498b2fbd95 enpass-cli: 1.12.0 -> 1.14.0 (#567941) 2026-09-28 22:43:53 +00:00
Maximilian Bosch
41ad56f934 Revert "gixy: 0.1.21 -> 0.2.54, switch upstream to maintained gixy-ng fork" (#568041) 2026-09-28 22:27:00 +00:00
nixpkgs-ci[bot]
f632a53aae mdbook-rss-feed: 1.10.2 -> 2.0.0 (#568012) 2026-09-28 22:24:18 +00:00
Johannes Kirschbauer
e7bed1f4c1 doc/styleguide: use sentence case (#567377) 2026-09-28 22:21:27 +00:00
Maximilian Bosch
a198dfd0b9 Revert "gixy: 0.1.21 -> 0.2.54, switch upstream to maintained gixy-ng fork" 2026-09-29 00:20:28 +02:00
R. Ryantm
ab6ffe5aa3 imagemagick: 7.1.2-31 -> 7.1.2-32 2026-09-28 21:44:15 +00:00
Nick Cao
b9d401cc6e lazyworktree: 1.50.0 -> 1.50.1 (#567770) 2026-09-28 21:28:40 +00:00
nixpkgs-ci[bot]
1ae5a6fffc npc: 1.0.0 -> 1.0.1 (#568011) 2026-09-28 21:22:41 +00:00
nixpkgs-ci[bot]
ed36b0f6f4 egctl: 1.9.1 -> 1.9.2 (#567996) 2026-09-28 21:22:38 +00:00
nixpkgs-ci[bot]
1f3449f319 code-cursor: 3.21.9 -> 3.22.7 (#567925) 2026-09-28 21:22:32 +00:00
nixpkgs-ci[bot]
5749d055e3 lens: 2026.9.20601 -> 2026.9.181013 (#567917) 2026-09-28 21:22:31 +00:00
Fabian Affolter
f4f672dc5d python3Packages.gitpython: 3.1.58 -> 3.1.62 (#562268) 2026-09-28 21:19:22 +00:00
Yohann Boniface
0875123ad7 superfile: 1.3.3 -> 1.6.0 (#450661) 2026-09-28 21:11:09 +00:00
Yohann Boniface
2c6db2074f kubernix: modernize (#567911) 2026-09-28 21:07:57 +00:00
Martin Weinelt
2ce392d342 Firefox: 156.0.1 -> 157.0; 153.3.0esr -> 153.4.0esr; drop 140esr (#567873) 2026-09-28 21:03:46 +00:00
Tom
12e5c0fd41 ttf_bitstream_vera: use lib.licenses.bitstreamVera (#568013) 2026-09-28 21:00:19 +00:00
Fabian Affolter
cde5b336cb python3Packages.mammoth: 1.12.2 -> 1.13.0 (#567537) 2026-09-28 20:57:52 +00:00
Martin Weinelt
1500f776c8 firefox-esr-140-unwrapped: drop
This release series has reached its projected end of life.
2026-09-28 22:57:08 +02:00
Martin Weinelt
64ad630fb1 firefox-esr-153-unwrapped: 153.3.0esr -> 153.4.0esr
https://www.firefox.com/en-US/firefox/153.4.0/releasenotes/
2026-09-28 22:56:54 +02:00
Martin Weinelt
b63cad0a55 firefox-bin-unwrapped: 156.0.1 -> 157.0
https://www.firefox.com/en-US/firefox/157.0/releasenotes/
2026-09-28 22:56:54 +02:00
Martin Weinelt
a0a88763be firefox-unwrapped: 156.0.1 -> 157.0
https://www.firefox.com/en-US/firefox/157.0/releasenotes/
2026-09-28 22:56:54 +02:00
Martin Weinelt
36f5f9b26a nss_latest: 3.129 -> 3.130
https://github.com/mozilla/nss/blob/master/doc/src/releases/nss_3_130.md
2026-09-28 22:56:53 +02:00
whispers
ee26617b95 pcre2: 10.48 -> 10.49 (#567967) 2026-09-28 20:56:08 +00:00
Nick Cao
3291e6c8dd skate: 1.0.1 -> 1.1.0 (#567924) 2026-09-28 20:55:09 +00:00
jopejoe1
859fb687f8 ttf_bitstream_vera: use lib.licenses.bitstreamVera 2026-09-28 22:53:14 +02:00
Fabian Affolter
6821c13757 python3Packages.azure-mgmt-privatedns: 1.2.0 -> 2.0.0 (#548015) 2026-09-28 20:52:45 +00:00
Nick Cao
a884d1993f python3Packages.pyliebherrhomeapi: 0.5.1 -> 0.5.2 (#567977) 2026-09-28 20:52:29 +00:00
Nick Cao
73de79daeb terraform-providers.ovh_ovh: 2.20.0 -> 2.21.0 (#567975) 2026-09-28 20:52:02 +00:00
Nick Cao
f1edc98424 python3Packages.tencentcloud-sdk-python: 3.1.181 -> 3.1.182 (#567974) 2026-09-28 20:51:45 +00:00
Nick Cao
d7802e310b sacad: 3.0.1 -> 3.0.2 (#568010) 2026-09-28 20:49:53 +00:00
Nick Cao
390e25ab00 cargo-generate: fix build on darwin (#568008) 2026-09-28 20:49:08 +00:00
Nick Cao
895a2b7854 python3Packages.ingredient-parser-nlp: 2.7.0 -> 2.8.0 (#568001) 2026-09-28 20:48:34 +00:00
Nick Cao
805e2c9866 python3Packages.awslambdaric: 4.0.4 -> 4.1.0 (#568000) 2026-09-28 20:47:48 +00:00
nixpkgs-ci[bot]
64532b1b83 cpm-cmake: 0.42.3 -> 0.43.2 (#541759) 2026-09-28 20:46:39 +00:00
Nick Cao
50573ea5cc stalwart-cli: remove giomf as maintainer (#567992) 2026-09-28 20:46:03 +00:00
Arne Keller
9e7ec01ffb gixy: 0.1.21 -> 0.2.54, switch upstream to maintained gixy-ng fork (#527083) 2026-09-28 20:44:56 +00:00
Fabian Affolter
a66736e695 nagiosPlugins.check_ssl_cert: 2.103.1 -> 2.103.3 (#567973) 2026-09-28 20:39:49 +00:00
Nick Cao
e4b322d320 vscode-extensions.sas.sas-lsp: 1.20.0 -> 1.21.0 (#567559) 2026-09-28 20:35:23 +00:00
Nick Cao
b67003bbea python3Packages.exa-py: 2.21.0 -> 2.23.0 (#567552) 2026-09-28 20:34:34 +00:00
Nick Cao
a09946d853 vastai: 1.5.6 -> 1.8.2 (#567636) 2026-09-28 20:32:59 +00:00
Nick Cao
0bcc952e2e usql: 0.21.5 -> 0.21.6 (#567624) 2026-09-28 20:32:11 +00:00
Nick Cao
d71342c801 cocoon: 0.11.3 -> 0.11.4 (#567609) 2026-09-28 20:31:02 +00:00
nixpkgs-ci[bot]
770938f1af mochi: 26.8.2 -> 26.9.2 (#567190) 2026-09-28 20:29:57 +00:00
Nick Cao
8e89a4533f sioyek: 2.0.0-unstable-2026-08-18 -> 2.0.0-unstable-2026-09-24 (#567688) 2026-09-28 20:28:34 +00:00
Nick Cao
5c8c00253a libretro.swanstation: 0-unstable-2026-08-11 -> 0-unstable-2026-09-17 (#567670) 2026-09-28 20:26:32 +00:00
R. Ryantm
7bd5d25c46 mdbook-rss-feed: 1.10.2 -> 2.0.0 2026-09-28 20:26:27 +00:00
R. Ryantm
be4468b0ee npc: 1.0.0 -> 1.0.1 2026-09-28 20:25:47 +00:00
Nick Cao
7836f4a799 infrastructure-agent: 1.80.3 -> 1.80.4 (#567732) 2026-09-28 20:25:15 +00:00
Nick Cao
fdd15c8d39 python3Packages.pylsl: 1.18.4.b1 -> 1.18.5 (#567729) 2026-09-28 20:24:07 +00:00
R. Ryantm
1871c3168d sacad: 3.0.1 -> 3.0.2 2026-09-28 20:23:46 +00:00
Fabian Affolter
9f79c50a4d python3Packages.pure-magic-rs: 0.5.0 -> 0.5.1 (#568005) 2026-09-28 20:23:01 +00:00
Nick Cao
cbc4e3645f oauth2c: 1.21.0 -> 1.21.1 (#567727) 2026-09-28 20:22:30 +00:00
Fabian Affolter
9d01506f7d python3Packages.pyfaup-rs: 0.4.20 -> 0.4.22 (#568004) 2026-09-28 20:22:30 +00:00
Nick Cao
c7ed414332 gelly: 1.13.0 -> 1.14.0 (#567726) 2026-09-28 20:22:18 +00:00
Nick Cao
ecead498c3 nerva: 1.70.0 -> 1.70.1 (#567721) 2026-09-28 20:21:30 +00:00
Fabian Affolter
28da512ae9 python3Packages.google-cloud-dlp: 3.38.0 -> 3.39.0 (#560362) 2026-09-28 20:20:54 +00:00
Nick Cao
ecab0b87f5 libopenshot-audio: 1.0.0 -> 1.0.1 (#567719) 2026-09-28 20:20:53 +00:00
Karl Ericsson
b65eacbbaa cargo-generate: fix build on darwin 2026-09-28 22:20:42 +02:00
Nick Cao
8afb8e9c81 readsb: 3.16.16 -> 3.16.17 (#567709) 2026-09-28 20:19:39 +00:00
Nick Cao
2bb4274800 libretro.fmsx: 0-unstable-2026-09-06 -> 0-unstable-2026-09-26 (#567702) 2026-09-28 20:19:04 +00:00
Nick Cao
b1d2910726 cdk8s-cli: 2.207.58 -> 2.207.62 (#567776) 2026-09-28 20:18:13 +00:00
Fabian Affolter
fa5f799780 python3Packages.pyvips: 3.1.1 -> 3.2.0 (#558759) 2026-09-28 20:17:17 +00:00
Nick Cao
902d3d3143 mackerel-agent: 0.87.0 -> 0.87.1 (#567769) 2026-09-28 20:17:01 +00:00
Nick Cao
9a15f74c85 vpxtool: 0.34.1 -> 0.34.6 (#567761) 2026-09-28 20:15:18 +00:00
Pavol Rusnak
f9fcddf314 ollama: 0.34.3 -> 0.34.4 (#567980) 2026-09-28 20:13:21 +00:00
Nick Cao
1d2e2d281c mango: 0.17.3 -> 0.17.4 (#567757) 2026-09-28 20:12:35 +00:00
Nick Cao
20ed14a09e apftool-rs: 1.2.5 -> 1.2.6 (#567755) 2026-09-28 20:12:05 +00:00
Nick Cao
6a50c32990 vscode-extensions.bazelbuild.vscode-bazel: 0.14.0 -> 0.15.0 (#567753) 2026-09-28 20:11:38 +00:00
Nick Cao
511fd89bfd vscode-extensions.coder.coder-remote: 1.16.3 -> 1.16.4 (#567751) 2026-09-28 20:11:14 +00:00
Nick Cao
ad200ccb3a pcloud: 2.2.1 -> 2.3.0 (#567289) 2026-09-28 20:07:15 +00:00
R. Ryantm
34fd214026 python3Packages.pure-magic-rs: 0.5.0 -> 0.5.1 2026-09-28 20:06:46 +00:00
Nick Cao
6352287dea dorion: 6.13.1 -> 6.13.2 (#567286) 2026-09-28 20:06:11 +00:00
Nick Cao
48eeb9aea5 signalbackup-tools: 20260822 -> 20260927 (#567378) 2026-09-28 20:04:52 +00:00
Nick Cao
ece6c59edc python3Packages.appium-python-client: 6.0.6 -> 6.0.7 (#567365) 2026-09-28 20:03:59 +00:00
Nick Cao
d94c5ca12f vscode-extensions.dotenv.dotenv-vscode: 0.28.1 -> 1.5.7 (#567360) 2026-09-28 20:02:05 +00:00
Nick Cao
c20c3f9518 libretro.fceumm: 0-unstable-2026-08-22 -> 0-unstable-2026-09-26 (#567348) 2026-09-28 20:01:36 +00:00
R. Ryantm
d652b25111 python3Packages.pyfaup-rs: 0.4.20 -> 0.4.22 2026-09-28 20:01:26 +00:00
Nick Cao
0e712805af cargo-guppy: 0.18.0 -> 0.19.1 (#567343) 2026-09-28 20:01:12 +00:00
Nick Cao
9f5db2a673 vscode-extensions.leanprover.lean4: 0.0.239 -> 0.0.240 (#567332) 2026-09-28 19:59:49 +00:00
Jo
331d29b881 aspellDicts.en-{computers,science}: drop (#567990) 2026-09-28 19:59:12 +00:00
Nick Cao
bd40c992ed pybugz: 0.14 -> 0.15 (#567331) 2026-09-28 19:58:44 +00:00
Nick Cao
8cb69ff758 poco: 1.15.3 -> 1.15.4 (#567435) 2026-09-28 19:57:52 +00:00
Fabian Affolter
36d1cc151b python3Packages.rio-tiler: 9.4.6 -> 9.4.7 (#567914) 2026-09-28 19:57:37 +00:00
Fabian Affolter
e672874fb2 python3Packages.jh2: 5.0.13 -> 5.0.15 (#559785) 2026-09-28 19:55:37 +00:00
Nick Cao
f5a05b1145 python3Packages.aws-secretsmanager-caching: 1.1.3 -> 1.2.0 (#567434) 2026-09-28 19:55:31 +00:00
Nick Cao
e61153e9e3 mpris-scrobbler: 0.5.9 -> 0.5.10 (#567407) 2026-09-28 19:54:38 +00:00
Fabian Affolter
249cb02c74 python3Packages.pyinstaller: 6.22.2 -> 6.22.3 (#565053) 2026-09-28 19:53:05 +00:00
Grimmauld
cb27c8dc45 aspellDicts.en-{computers,science}: drop 2026-09-28 21:52:32 +02:00
Nick Cao
81903efb8a python3Packages.glyphslib: 6.14.0 -> 6.15.0 (#567399) 2026-09-28 19:51:28 +00:00
Nick Cao
7e9b30261d poetryPlugins.poetry-plugin-export: 1.10.0 -> 1.10.1 (#567479) 2026-09-28 19:49:55 +00:00
Nick Cao
91d5727f5e grafanaPlugins.grafana-exploretraces-app: 2.2.0 -> 2.2.1 (#567474) 2026-09-28 19:49:03 +00:00
Nick Cao
2e2646588b plakar: 1.1.6 -> 1.1.7 (#567453) 2026-09-28 19:48:30 +00:00
Martin Weinelt
2fc64713d0 libedgetpu: pin abseil-cpp to c++17 for gcc 16 (#567987) 2026-09-28 19:47:16 +00:00
nixpkgs-ci[bot]
c395711750 maintainers/github-teams.json: Automated sync 2026-09-28 19:46:45 +00:00
Fabian Affolter
1946d9cc26 python3Packages.jellyfin-apiclient-python: 1.18.0 -> 1.19.0 (#567273) 2026-09-28 19:45:51 +00:00
R. Ryantm
772ea9e390 python3Packages.ingredient-parser-nlp: 2.7.0 -> 2.8.0 2026-09-28 19:44:16 +00:00
Guillaume Fournier
b18681f9e5 stalwart-cli: remove giomf from maintainer 2026-09-28 21:43:38 +02:00
R. Ryantm
a41eee72fa python3Packages.awslambdaric: 4.0.4 -> 4.1.0 2026-09-28 19:43:17 +00:00
Fabian Affolter
677bae9616 python3Packages.python-gammu: 3.2.4 -> 3.5.0 (#547517) 2026-09-28 19:40:30 +00:00
Fabian Affolter
7aa30217fc python3Packages.proton-core: 0.7.0 -> 0.7.4 (#552138) 2026-09-28 19:38:43 +00:00
R. Ryantm
85972f1ca4 egctl: 1.9.1 -> 1.9.2 2026-09-28 19:37:00 +00:00
whispers
6f4b6d39fa libedgetpu: pin abseil-cpp to c++17 for gcc 16
gcc 16 defaults to c++20, so the abseil-cpp we provide to libedgetpu
builds with it as well. since abseil exposes different api surface based
on the standard, it needs to match libedgetpu, which we pin to c++17.
2026-09-28 15:33:31 -04:00
Nick Cao
cc8c4a16f5 await: 2.7.0 -> 2.8.0 (#567013) 2026-09-28 19:32:01 +00:00
Fabian Affolter
ac4937aaf7 python3Packages.azure-mgmt-privatedns: migrate to finalAttrs 2026-09-28 21:30:57 +02:00
Fabian Affolter
69185f36c3 python3Packages.proton-core: add changelog to meta 2026-09-28 21:27:31 +02:00
Fabian Affolter
6b80b94ab6 python3Packages.proton-core: mirate to finalAttrs 2026-09-28 21:26:04 +02:00
Nick Cao
826ab3c709 unnaturalscrollwheels: 1.4.0 -> 1.4.2 (#566995) 2026-09-28 19:22:52 +00:00
Fabian Affolter
b2871eccce python3Packages.mail-parser: 4.5.0 -> 4.6.5 (#552887) 2026-09-28 19:22:35 +00:00
Nick Cao
381a170454 grafanaPlugins.victoriametrics-metrics-datasource: 0.25.2 -> 0.26.1 (#566985) 2026-09-28 19:22:14 +00:00
Nick Cao
0e9c1f4e89 rbspy: 0.51.0 -> 0.53.0 (#566974) 2026-09-28 19:21:40 +00:00
Fabian Affolter
b44ca732c6 python3Packages.pywikibot: 11.6.0 -> 11.7.0 (#558675) 2026-09-28 19:21:33 +00:00
Fabian Affolter
5d9fbed71f python3Packages.pyrate-limiter: 4.4.0 -> 4.5.0 (#559021) 2026-09-28 19:17:35 +00:00
Nick Cao
48d7a389bd python3Packages.graphemeu: 0.10.0 -> 0.11.0 (#567050) 2026-09-28 19:16:36 +00:00
Nick Cao
bcfbea12bc python3Packages.yaspin: 3.5.0 -> 3.5.1 (#567041) 2026-09-28 19:15:11 +00:00
Nick Cao
bd6bb713ef miller: 6.21.0 -> 6.22.0 (#567034) 2026-09-28 19:12:58 +00:00
Nick Cao
c92efb59c8 python3Packages.denon-rs232: 4.2.2 -> 4.2.3 (#567031) 2026-09-28 19:12:04 +00:00
Nick Cao
6fa729f6ba hebcal: 5.15.0 -> 5.16.0 (#567028) 2026-09-28 19:11:39 +00:00
Nick Cao
ed5781a276 python3Packages.pycaption: 2.3.9 -> 2.3.10 (#567136) 2026-09-28 19:09:49 +00:00
Fabian Affolter
84d635a8e0 python3Packages.pyvips: modernize
- migrate to finalAttrs
- update ordering
2026-09-28 21:08:18 +02:00
Nick Cao
c36b201822 libretro.flycast: 0-unstable-2026-09-15 -> 0-unstable-2026-09-26 (#567089) 2026-09-28 19:06:12 +00:00
Nick Cao
aad1d85f7f libretro.bsnes: 0-unstable-2026-09-04 -> 0-unstable-2026-09-19 (#567074) 2026-09-28 19:05:08 +00:00
Nick Cao
133736278a ddccontrol-db: 20260915 -> 20260922 (#567069) 2026-09-28 19:04:30 +00:00
R. Ryantm
807bf6d122 cpm-cmake: 0.42.3 -> 0.43.2 2026-09-28 19:03:15 +00:00
Nick Cao
85b33d5d71 boilr: 1.9.6 -> 1.10.1 (#567184) 2026-09-28 19:02:56 +00:00
Nick Cao
d95ef89c24 git-town: 24.0.0 -> 24.1.0 (#567176) 2026-09-28 19:01:35 +00:00
Fabian Affolter
2c2883a987 python3Packages.pywikibot: migrate to finalAttrs 2026-09-28 21:00:54 +02:00
Nick Cao
909a9ddc08 markdownlint-cli2: 0.23.2 -> 0.23.3 (#567153) 2026-09-28 18:58:26 +00:00
whispers
e3f11b5271 python3Packages.mpd2: correct the alias (#567959) 2026-09-28 18:58:26 +00:00
Martin Weinelt
a005ed5e42 python3Packages.reuse: use finalAttrs (#567889) 2026-09-28 18:55:29 +00:00
Marc Jakobi
76a75a2944 luaPackages.fzf-lua: 0.0.2700-1 -> 0.0.2701-1 (#567949) 2026-09-28 18:52:37 +00:00
Nick Cao
7ef2d5f9da vscode-extensions.divyanshuagrawal.competitive-programming-helper: 2026.9.1789051951 -> 2026.9.1789578855 (#567249) 2026-09-28 18:52:26 +00:00
Nick Cao
dc672b5ba6 iana-etc: mark as supported on all platforms (#567244) 2026-09-28 18:51:27 +00:00
Nick Cao
f1cf1ffb65 macos-defaults: 0.2.0 -> 0.3.0 (#567229) 2026-09-28 18:50:01 +00:00
Nick Cao
5a17d08a7a protonup-rs: 0.15.0 -> 0.15.1 (#567228) 2026-09-28 18:49:06 +00:00
Nick Cao
a2867c8759 python3Packages.pure-magic-rs: fix license (#567223) 2026-09-28 18:45:19 +00:00
Nick Cao
df0385d6a1 kew: 4.3.6 -> 4.3.8 (#567210) 2026-09-28 18:44:11 +00:00
Fabian Affolter
5f8f77640d python3Packages.tencentcloud-sdk-python: 3.1.181 -> 3.1.182
Diff: https://github.com/TencentCloud/tencentcloud-sdk-python/compare/3.1.181...3.1.182

Changelog: https://github.com/TencentCloud/tencentcloud-sdk-python/blob/3.1.182/CHANGELOG.md
2026-09-28 20:32:21 +02:00
nixpkgs-ci[bot]
bf1a26661a flatpak-builder-tools: 0-unstable-2026-09-12 -> 0-unstable-2026-09-21 (#567733) 2026-09-28 18:30:57 +00:00
nixpkgs-ci[bot]
2f17a8752d stump: 0.1.7 -> 0.1.10 (#567294) 2026-09-28 18:30:47 +00:00
R. Ryantm
01855f42ba python3Packages.pyliebherrhomeapi: 0.5.1 -> 0.5.2 2026-09-28 18:26:47 +00:00
R. Ryantm
5d633e1f9a terraform-providers.ovh_ovh: 2.20.0 -> 2.21.0 2026-09-28 18:23:25 +00:00
Ryan Horiguchi
15232e7ad0 superfile: 1.3.3 -> 1.6.0#450661 2026-09-28 20:22:57 +02:00
Ryan Burns
6dc5827263 wally-cli: use the 2.0.1-osx tag (#567951) 2026-09-28 18:21:52 +00:00
Alexander Bantyev
6338d568f8 intel-oneapi-toolkit: fix C++ standard library headers in stdenv (#567067) 2026-09-28 18:20:47 +00:00
nixpkgs-ci[bot]
621952b876 Merge staging-next into staging 2026-09-28 18:13:18 +00:00
nixpkgs-ci[bot]
2755f69fcc Merge master into staging-next 2026-09-28 18:12:44 +00:00
Jo
99ce514ef8 joypixels: Fix license (#567953) 2026-09-28 18:06:45 +00:00
R. Ryantm
b2c10522e7 nagiosPlugins.check_ssl_cert: 2.103.1 -> 2.103.3 2026-09-28 18:04:26 +00:00
Ryan Burns
52c1587126 clinfo: modernize (#567948) 2026-09-28 18:02:05 +00:00
R. Ryantm
5df01aab75 pcre2: 10.48 -> 10.49 2026-09-28 18:00:07 +00:00
Yt
c5207a77c9 codex: 0.157.0 -> 0.158.0 (#567737) 2026-09-28 17:58:51 +00:00
R. Ryantm
3a5a267772 ollama: 0.34.3 -> 0.34.4 2026-09-28 17:58:45 +00:00
Pol Dellaiera
fba216b10d libsecretspec 0.21.0 (#566390) 2026-09-28 17:52:40 +00:00
Jo
165f957861 various: add CPE parts (#567438) 2026-09-28 17:50:20 +00:00
Adam C. Stephens
51647e1c2c beamPackages.mixRelease: refactor phases into hooks (#563431) 2026-09-28 17:46:27 +00:00
nixpkgs-ci[bot]
d3fba519f8 cog: 0.2.0 -> 0.2.1 (#567905) 2026-09-28 17:34:59 +00:00
adisbladis
6c6973cdf5 nixos/rundeck: fix module for rundeck 6.x (#563823) 2026-09-28 17:34:06 +00:00
Vladimír Čunát
3b45454971 staging-next 2026-09-23 (#566094) 2026-09-28 17:32:34 +00:00
Florian Franzen
b3d908c1ec python3Packages.reuse: use finalAttrs 2026-09-28 19:31:40 +02:00
Adam C. Stephens
37489e1ef9 omp: 18.3.3 -> 18.4.2 (#567934) 2026-09-28 17:27:04 +00:00
Jan Tojnar
26486f5e32 joypixels: Fix license 2026-09-28 19:25:38 +02:00
adisbladis
80ddb50e86 nixos/glpi-agent: fix cpu and memory reporting in inventory (#563155) 2026-09-28 17:23:57 +00:00
Florian Franzen
1803998d6a wally-cli: use the 2.0.1-osx tag 2026-09-28 19:19:59 +02:00
paperluigis
e72366cfc8 python3Packages.mpd2: correct the alias 2026-09-28 22:16:54 +05:00
Aaron Andersen
e38f76b59c eudev: 3.2.14 -> 3.2.15 (#567775) 2026-09-28 17:15:00 +00:00
Jonas Heinrich
09ffa5338a ollaya: init at 0.7.5 (#567898) 2026-09-28 17:14:05 +00:00
Ethan Carter Edwards
fb2b9561ba clinfo: modernize
Signed-off-by: Ethan Carter Edwards <ethan@ethancedwards.com>
2026-09-28 13:11:29 -04:00
Martin Weinelt
7d7a6ff4a7 python3Packages.untokenize: fix build with Python 3.14 (#567276) 2026-09-28 17:10:51 +00:00
Vladimír Čunát
bfefd3bd8c devenv: link libghostty-vt dynamically (#567929) 2026-09-28 17:07:20 +00:00
Ryan Burns
24bf7787b5 clinfo: 3.0.25.02.14 -> 3.1.26.09.26 (#567304) 2026-09-28 17:02:24 +00:00
Yohann Boniface
f70e174e71 subxt: add update script, version check and structuredAttrs (#567884) 2026-09-28 17:01:01 +00:00
R. Ryantm
1436e188f3 enpass-cli: 1.12.0 -> 1.14.0 2026-09-28 16:46:44 +00:00
K900
aeb99607ce netbird-dashboard: 2.92.0 -> 2.94.0 (#567930) 2026-09-28 16:39:20 +00:00
Diogo Correia
0695063323 nixos/tests/flaresolverr: fetch local webpage (#543242) 2026-09-28 16:34:18 +00:00
nixpkgs-ci[bot]
92f6072d63 tonearm: 1.5.0 -> 1.5.1 (#567928) 2026-09-28 16:30:09 +00:00
nixpkgs-ci[bot]
ed3fedb627 stalwart-cli: 1.0.12 -> 1.0.13 (#567926) 2026-09-28 16:30:08 +00:00
nixpkgs-ci[bot]
56cfcb187c grok-build: 1.0.34 -> 1.0.41 (#567923) 2026-09-28 16:30:07 +00:00
nixpkgs-ci[bot]
5f95687f9f gollama: 2.0.5 -> 2.0.6 (#567891) 2026-09-28 16:30:06 +00:00
nixpkgs-ci[bot]
14991153ee rclone-ui: 3.7.2 -> 3.7.5 (#560731) 2026-09-28 16:30:01 +00:00
Emily
643318e5a6 music-assistant: remove hexa and emilylange from maintainers (#567915) 2026-09-28 16:28:56 +00:00
John Ericson
bef5682420 cc-wrapper: Default-disable AltiVec with powerpc64-linux LLVM (#542358) 2026-09-28 16:25:30 +00:00
Adam C. Stephens
e32f5536ea omp: 18.3.3 -> 18.4.2
Changelog: https://github.com/can1357/oh-my-pi/releases/tag/v18.4.2
2026-09-28 12:23:57 -04:00
Adam C. Stephens
7b47c61b61 victoriametrics: 1.152.0 -> 1.153.0 (#567916) 2026-09-28 16:21:46 +00:00
Martin Weinelt
c4be7bfc87 music-assistant: remove hexa from maintainers
This includes various music-assistant dependencies.

I have never been satisified with music-assistant in production and the
recent upstream and downstream churn has been too much for me.
2026-09-28 18:16:48 +02:00
Adam C. Stephens
8754ffce60 netbird-dashboard: 2.92.0 -> 2.94.0
Diff: https://github.com/netbirdio/dashboard/compare/v2.92.0...v2.94.0
2026-09-28 12:15:59 -04:00
Sebastián Mancilla
3c1ed264fa yacreader: 10.0.0 -> 10.3.1 (#552381) 2026-09-28 16:10:41 +00:00
Domen Kožar
51564ebe4e devenv: link libghostty-vt dynamically
The static libghostty-vt archive fails to link into devenv on staging-next. Mold reports undefined symbols from compiler_rt.o, while ld.bfd rejects overlapping FDEs. Enable the link-dynamic feature so Cargo uses the packaged shared library.

Assisted-by: OpenAI Codex (GPT-6)
2026-09-28 18:06:18 +02:00
Fabian Affolter
1cb5777f02 checkip: 0.54.0 -> 0.55.0 (#567909) 2026-09-28 16:02:45 +00:00
Danila Vershinin
5a2375490c gixy: 0.1.21 -> 0.2.54, switch upstream to maintained gixy-ng fork
Assisted-by: Claude Code (Claude Opus 5.5)
2026-09-28 23:01:50 +07:00
R. Ryantm
d2d590f09f tonearm: 1.5.0 -> 1.5.1 2026-09-28 15:57:28 +00:00
Fabian Affolter
6b97a40055 python3Packages.pysigma-pipeline-windows: 2.0.0 -> 2.0.1 (#567814) 2026-09-28 15:57:12 +00:00
Fabian Affolter
7a35d3db83 python3Packages.xml-marshaller: 1.0.2 -> 1.0.3 (#564639) 2026-09-28 15:54:15 +00:00
Fabian Affolter
dd4c373304 python3Packages.pytapo: 3.4.18 -> 3.4.19 (#564631) 2026-09-28 15:53:15 +00:00
R. Ryantm
78bde1d058 stalwart-cli: 1.0.12 -> 1.0.13 2026-09-28 15:47:34 +00:00
R. Ryantm
b96c188918 skate: 1.0.1 -> 1.1.0 2026-09-28 15:46:34 +00:00
R. Ryantm
018d20c466 grok-build: 1.0.34 -> 1.0.41 2026-09-28 15:44:24 +00:00
Marcus Ramberg
62133d5cc1 perlPackages.XMLTwig: 3.52 -> 3.54 (#524693) 2026-09-28 15:43:11 +00:00
nixpkgs-ci[bot]
2f8b3cc868 stevenblack-blocklist: 3.16.115 -> 3.16.118 (#567458) 2026-09-28 15:42:00 +00:00
Marie Ramlow
47314b12cb masterpdfeditor: use archive.org as a fallback (#564139) 2026-09-28 15:41:44 +00:00
emilylange
509e0949d2 librespot-ma,go-librespot: remove emilylange from maintainers
Both packages are dependencies of music-assistant, which I stopped
maintaining in 77b64b02db
2026-09-28 17:32:36 +02:00
transcaffeine
7b95bdba78 victoriametrics: 1.152.0 -> 1.153.0
Release notes: https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.153.0
Full changelog: https://github.com/VictoriaMetrics/VictoriaMetrics/compare/v1.152.0...v1.153.0
2026-09-28 17:28:23 +02:00
Fabian Affolter
f9d72791a4 python3Packages.jellyfin-apiclient-python: add changelog to meta
Add changelog URL to the Jellyfin API client metadata.
2026-09-28 17:28:21 +02:00
Fabian Affolter
ddcc934c45 python3Pakcages.jellyfin-apiclient-python: migrate to finalAttrs 2026-09-28 17:27:16 +02:00
R. Ryantm
e79160925e lens: 2026.9.20601 -> 2026.9.181013 2026-09-28 15:26:19 +00:00
emilylange
77b64b02db music-assistant: remove emilylange from maintainers
due to lack of interest and lack of time
2026-09-28 17:26:08 +02:00
nixpkgs-ci[bot]
a0dedc81b9 snyk: 1.1307.1 -> 1.1307.4 (#567808) 2026-09-28 15:25:52 +00:00
Fabian Affolter
47f2c00b0e python3Packages.mammoth: migrate to finalAttrs 2026-09-28 17:25:42 +02:00
Ethan Carter Edwards
fdb5c4fe1b kubernix: modernize
Signed-off-by: Ethan Carter Edwards <ethan@ethancedwards.com>
2026-09-28 11:24:42 -04:00
Fabian Affolter
3ba0d8a979 python3Packages.types-mysqlclient: 2.2.0.20260508 -> 2.3.0.20260923 (#567333) 2026-09-28 15:20:09 +00:00
Fabian Affolter
a0a000a215 python3Packages.frida-python: 17.17.0 -> 17.19.0 (#564068) 2026-09-28 15:19:29 +00:00
Jan Tojnar
83e790a28b sublime4: Remove old code (#567864) 2026-09-28 15:18:47 +00:00
Fabian Affolter
2cf46ee55f python3Packages.tomlrt: 2.2.7 -> 2.2.14 (#564195) 2026-09-28 15:18:44 +00:00
Fabian Affolter
e3cca68cc1 python3Packages.motioneye-client: 0.3.14 -> 0.4.1 (#564095) 2026-09-28 15:18:16 +00:00
Maximilian Bosch
261daca02d nginxModules.otel: init at 0.1.2 (#561242) 2026-09-28 15:17:42 +00:00
R. Ryantm
035e827772 python3Packages.rio-tiler: 9.4.6 -> 9.4.7 2026-09-28 15:14:13 +00:00
R. Ryantm
18c0b743a5 checkip: 0.54.0 -> 0.55.0 2026-09-28 15:13:39 +00:00
R. Ryantm
f6e84e6c42 code-cursor: 3.21.9 -> 3.22.7 2026-09-28 15:12:20 +00:00
happysalada
824ebcb3e7 ollaya: init at 0.7.5 2026-09-28 11:06:01 -04:00
R. Ryantm
0b1eea0f08 cog: 0.2.0 -> 0.2.1 2026-09-28 15:04:51 +00:00
nixpkgs-ci[bot]
e221ea05c5 kubernix: 0.3.7 -> 0.4.1 (#567894) 2026-09-28 15:00:55 +00:00
Andrew Prokhorenkov
23111d1b8a codex: 0.157.0 -> 0.158.0 2026-09-28 09:58:23 -05:00
Nikolay Korotkiy
3cc569fcdf localsend: fix wm class (#567834) 2026-09-28 14:49:31 +00:00
Jan Tojnar
e3b7b25950 speechd: refactor and small improvements (#470797) 2026-09-28 14:43:07 +00:00
Jo
d3e86482e0 discord: update various (#567397) 2026-09-28 14:43:00 +00:00
R. Ryantm
2c2cc3d864 kubernix: 0.3.7 -> 0.4.1 2026-09-28 14:36:53 +00:00
pinage404
e96fca22db speechd: ensure to use the same option has given arguments 2026-09-28 16:35:04 +02:00
pinage404
75f645ed32 speechd: stricter deps 2026-09-28 16:35:04 +02:00
pinage404
035470c362 speechd: add version test 2026-09-28 16:35:04 +02:00
pinage404
484d0a73bd speechd: add pipewire option
this option come from here:

fbdb6b0bf2/configure.ac (L496)

Only adding it after `pulse` since the pipewire support is only initial according to [0.12 changelog](https://github.com/brailcom/speechd/releases/tag/0.12.0) and there have been [issues reported with it](https://github.com/brailcom/speechd/issues/884#issuecomment-3083838604).
2026-09-28 16:35:04 +02:00
pinage404
4ed122fa8f speechd: add --with-flite option
this option was missing

it comes from here:
fbdb6b0bf2/configure.ac (L241)
2026-09-28 16:35:04 +02:00
pinage404
3b86954bd0 speechd: actually disable options when disabling with override 2026-09-28 16:35:04 +02:00
pinage404
bea958bc85 speechd: make more explicit python packages 2026-09-28 16:35:04 +02:00
pinage404
f944aca5da speechd: update metadata
meld existing metadata with what is generated by nix-init
2026-09-28 16:35:04 +02:00
pinage404
afa239dcc9 speechd: refactor abort when the substitution fail 2026-09-28 16:35:03 +02:00
nixpkgs-ci[bot]
1be7652e6e opa-envoy-plugin: 1.20.2-envoy -> 1.21.0-envoy (#566643) 2026-09-28 14:27:53 +00:00
R. Ryantm
d2a5bb5618 gollama: 2.0.5 -> 2.0.6 2026-09-28 14:19:48 +00:00
Sandro
cb61085709 prometheus-redis-exporter: 1.91.1 -> 1.92.1 (#567778) 2026-09-28 14:17:00 +00:00
Sandro
5751d31928 zabbix74: 7.4.14 -> 7.4.15 (#567517) 2026-09-28 14:16:50 +00:00
Sandro
e71f1aa922 doublecmd: 1.2.8 -> 1.2.9 (#567530) 2026-09-28 14:16:48 +00:00
Sandro
490e0cdf15 python3Packages.pyexiv2: fix build (#567539) 2026-09-28 14:14:11 +00:00
Sandro
d8ae3102cf Zabbix70: 7.0.30 -> 7.0.31 (#567519) 2026-09-28 14:14:06 +00:00
Sandro
d0af5f4eca nwjs: 0.115.0 -> 0.117.0; use finalAttrs, add update script, ... (#567589) 2026-09-28 14:11:25 +00:00
Sandro
caec5dc486 python3Packages.bandcamp-async-api: 0.2.4 -> 0.2.6 (#567676) 2026-09-28 14:11:10 +00:00
Sandro
dd1b9083cb eilmeldung: 1.8.1 -> 1.9.0 (#567597) 2026-09-28 14:10:58 +00:00
Adam C. Stephens
887705a956 openssl_3: remove as end of life (#564269) 2026-09-28 14:09:36 +00:00
Sandro
175cf8387b miracle-wm: 0.10.1 -> 0.11.2 (#567790) 2026-09-28 14:07:06 +00:00
Sandro
27917999bd element-call: 0.26.0 -> 0.26.1 (#567845) 2026-09-28 14:06:17 +00:00
Sandro
0decbdeae0 freerdp: 3.32.0 -> 3.32.1 (#567822) 2026-09-28 14:05:40 +00:00
Adam C. Stephens
1f4520617f openssl_3: remove as end of life 2026-09-28 10:03:46 -04:00
Adam C. Stephens
7088afe070 treewide: move openssl_3 consumers to openssl_3_5 2026-09-28 10:03:44 -04:00
Grimmauld
a29052ad17 various: add meta.identifier.cpeParts to a batch of packages (#567827) 2026-09-28 14:01:01 +00:00
Florian Franzen
551ec7da15 subxt: add update script, version check and structuredAttrs 2026-09-28 15:59:50 +02:00
Austin Horstman
22ff060c06 luaPackages.fzf-lua: 0.0.2700-1 -> 0.0.2701-1 2026-09-28 08:59:45 -05:00
Sandro
bdf66df86e awscurl: init at 0.44 (#567837) 2026-09-28 13:56:34 +00:00
Leona Maroni
3044df680a firefox-beta: drop; firefox-devedition: remove me as maintainer (#567849) 2026-09-28 13:52:48 +00:00
Marcus Ramberg
461071d7ab nixos/beszel.agent: fix GPU monitoring, expose SKIP_GPU and GPU_COLLECTOR (#508090) 2026-09-28 13:51:39 +00:00
Sandro
7fd6b3400f nixos/librenms: use structuredAttrs instead of passAsFile (#563190) 2026-09-28 13:47:45 +00:00
lambda-mike
d1a24711da activemq: add cpe metadata 2026-09-28 15:25:24 +02:00
lambda-mike
da0014f6b7 activemq: use finalAttrs to get version 2026-09-28 15:25:03 +02:00
Daniel Schaefer
65511402a9 mbuffer: 20260511 -> 20260926 (#567708) 2026-09-28 13:24:56 +00:00
Sandro Jäckel
f0f4299f1b awscurl: init at 0.44 2026-09-28 15:23:30 +02:00
lambda-mike
46b4a7cffc a2ps: add cpe metadata 2026-09-28 15:23:10 +02:00
@mjones
ac00cc14d4 xpra: fix 6.5.4 hash (#567838) 2026-09-28 13:16:42 +00:00
Fabian Affolter
aaa3d52bc9 python3Packages.pysigma-pipeline-windows: migrate to finalAttrs 2026-09-28 15:15:20 +02:00
Jo
59b2130bae minimal-bootstrap: Refactor for gcc-ng (#532618) 2026-09-28 13:08:23 +00:00
Sandro
f45c6f04c2 glitchtip: support django-async-backend>=6.1 (#567847) 2026-09-28 13:04:38 +00:00
nixpkgs-ci[bot]
695d395b32 mago: 1.49.0 -> 1.50.0 (#567781) 2026-09-28 13:02:47 +00:00
nixpkgs-ci[bot]
76168462d0 claude-agent-acp: 0.79.0 -> 0.81.2 (#567689) 2026-09-28 13:02:44 +00:00
Jan Tojnar
1d278888f8 sublime4: Remove old code
The recent bump of stable to 4213 fixed most of the issues we had:
- Python 3.8 was migrated to Python 3.14, we have working plug-ins in stable again (on dev since 4205).
- Python 3.3 is now disabled by default, no need to disable it ourselves (dev 4206)
- pkexec is picked from PATH (dev 4205)
2026-09-28 14:51:12 +02:00
jopejoe1
1f427c337d firefox-devedition: remove me as maintainer 2026-09-28 14:49:54 +02:00
Aleksi Hannula
5fb0939f78 minimal-bootstrap.gcc-glibc: split for gcc-ng, use wrapper 2026-09-28 15:43:29 +03:00
Aleksi Hannula
d259989cd3 minimal-bootstrap.gcc-latest-unwrapped: split into gcc-ng packages
minimal-bootstrap.libgcc: init at 16.1.0
minimal-bootstrap.libstdcxx: init at 16.1.0

minimal-bootstrap.glibc:
Fix libgcc link paths. Remove hello-world test; glibc here is better
tested by the gcc-glibc wrapper test introduced in the next commit.
Keeping the test within glibc require manually setting linker flags that
place libgcc and glibc into the linker search paths.
2026-09-28 15:43:28 +03:00
@mjones
d4515b58d7 mattermostLatest: 11.10.2 -> 11.11.0 (#565972) 2026-09-28 12:34:09 +00:00
Jan Tojnar
8fac26bdd0 webkitgtk: 2.52.6 -> 2.54.0 (#567572) 2026-09-28 12:32:46 +00:00
Tom
3ad929f932 anarchism: 15.3-1 -> 15.3-4 (#567829) 2026-09-28 12:29:04 +00:00
Winter
2afe94de14 bcc: remove refs to LLVM static libs that bloated closure (#562660) 2026-09-28 12:23:26 +00:00
Marcus Ramberg
bfc8861744 perlPackages.*: fix homepages (#566986) 2026-09-28 12:20:41 +00:00
nixpkgs-ci[bot]
fc9baeb069 Merge staging-next into staging 2026-09-28 12:16:14 +00:00
nixpkgs-ci[bot]
e20e029207 Merge master into staging-next 2026-09-28 12:15:44 +00:00
Peder Bergebakken Sundt
14a1c726fb gradm: mark as broken on aarch64-linux (last successful Hydra build 2018) (#565149) 2026-09-28 12:10:36 +00:00
taku0
34fcbb5590 thunderbird-esr-bin-unwrapped: 153.3.0esr -> 153.3.1esr (#567441) 2026-09-28 12:09:22 +00:00
Winter
da597dd611 stdenv: Use lib.systems.equals to compare systems (#567846) 2026-09-28 12:08:51 +00:00
Marcus Ramberg
53d7456928 aclpubcheck: init at 0.1-unstable-2026-09-11 (#421305) 2026-09-28 12:06:41 +00:00
jopejoe1
451b949673 firefox-beta: drop 2026-09-28 14:05:35 +02:00
Sandro
df1f23dc72 nixos/installer: fix defaultText rendering as plain string (#530765) 2026-09-28 12:05:23 +00:00
Sandro
e6237fa9de mjolnir: 1.9.2 -> 1.12.1 (#560282) 2026-09-28 12:04:46 +00:00
Sandro
c963968c6a nixos/mjolnir: add support for using native encryption (#560285) 2026-09-28 12:04:27 +00:00
Sandro
5e4fbb7b8f nixos/paperless: allow overwriting exporter settings without mkForce (#561372) 2026-09-28 12:03:41 +00:00
Aspen Smith
abae62cff7 stdenv: Use lib.systems.equals to compare systems
I made an experimental version of nix that made all functions compare as
not equal (even if they have the same pointer) to sniff out bits of
nixpkgs that still depend on comparing functions. This commit stamps out
a few of those in pkgs/stdenv, which are necessary to allow that
experimental version to eval, eg, pkgs.hello (otherwise bootstrap
infinite recurses).
2026-09-28 08:00:58 -04:00
Marcus Ramberg
ce6b7baa24 enroll: init at 1.2.8 (#567818) 2026-09-28 11:57:36 +00:00
Sandro Jäckel
c6181fc777 python3Packages.django-async-backend: clean up unused inputs 2026-09-28 13:57:01 +02:00
Sandro Jäckel
ccf4053ac5 glitchtip: support django-async-backend>=6.1 2026-09-28 13:57:00 +02:00
Bart Oostveen
f7bf61fa5d element-call: 0.26.0 -> 0.26.1
Diff: https://github.com/element-hq/element-call/compare/v0.26.0...v0.26.1

Changelog: https://github.com/element-hq/element-call/releases/tag/v0.26.1
2026-09-28 13:56:32 +02:00
Marcus Ramberg
f89e83b157 enroll: init at 1.2.8
Assisted-By: Claude Opus 5.5
2026-09-28 13:51:14 +02:00
Grimmauld
2d140d8c70 gst_all_1.gst-plugins-good: drop aalib dependency (#567828) 2026-09-28 11:50:49 +00:00
Thiago Kenji Okada
4d7d643428 whisrs: init at 0.1.27 (#551545) 2026-09-28 11:50:30 +00:00
Sandro
3d72f480e1 nixos/engelsystem: do not require mkForce ot overwrite default pm.* settings (#561381) 2026-09-28 11:48:10 +00:00
Danila Vershinin
a735fa0084 python3Packages.ngxparse: init at 0.5.16
Assisted-by: Claude Code (Claude Opus 5.5)
2026-09-28 18:44:50 +07:00
Danila Vershinin
e64237c687 maintainers: add dvershinin
Assisted-by: Claude Code (Claude Opus 5.5)
2026-09-28 18:44:48 +07:00
whoomee
edd9e93be3 gst_all_1.gst-plugins-good: drop aalib dependency
aalib hasn't been updated in 25 years, and it is arguably an exotic
feature to use GStreamer to view a video as ASCII art.
2026-09-28 13:43:37 +02:00
Thiago Kenji Okada
79d2664797 nixos-rebuild-ng: extract kernelVersion, nixosVersion and specialisation from nixos-version (#567238) 2026-09-28 11:42:51 +00:00
Sandro
3fc35f09ac nixos/go-neb: move mkRemovedOptionModule to rename.nix (#561461) 2026-09-28 11:40:59 +00:00
Tom Hunze
401000c4b3 webkitgtk: 2.52.6 -> 2.54.0
https://github.com/WebKit/WebKit/compare/webkitgtk-2.52.6...webkitgtk-2.54.0
2026-09-28 13:40:16 +02:00
Luflosi
06f7935788 aclpubcheck: init at 0.1-unstable-2026-09-11
https://github.com/acl-org/aclpubcheck
2026-09-28 13:37:23 +02:00
teutat3s
d2b182649d element-desktop/element-web: 1.12.28 -> 1.12.29 (#566542) 2026-09-28 11:32:55 +00:00
Jo
44da68aa95 dokuwiki: switch to finalAttrs, add CPE information (#567819) 2026-09-28 11:30:41 +00:00
Sandro Jäckel
78204cf312 nixos/go-neb: move mkRemovedOptionModule to rename.nix 2026-09-28 13:25:37 +02:00
Sandro
01578902be home-assistant-custom-lovelace-modules.tankerkoenig-card: 1.8.2 -> 1.9.0 (#567220) 2026-09-28 11:25:02 +00:00
Morgan Jones
e9c28183c8 xpra: fix 6.5.4 hash 2026-09-28 04:24:36 -07:00
nixpkgs-ci[bot]
89c9521f0e sable-unwrapped: 1.22.6 -> 1.22.9 (#567638) 2026-09-28 11:22:53 +00:00
Matthieu Coudron
d8c7931cf8 tree-sitter-grammars.tree-sitter-sshclientconfig: 2026.8.27 -> 2026.9.24 (#560758) 2026-09-28 11:19:23 +00:00
Matthieu Coudron
a4c0478a84 tree-sitter-grammars.tree-sitter-php-only: 0.24.2-unstable-2026-03-19 -> 0.25.0-unstable-2026-09-24 (#519249) 2026-09-28 11:18:54 +00:00
Matthieu Coudron
8667e69194 tree-sitter-grammars.tree-sitter-pkl: 0.20.0-unstable-2026-03-27 -> 0.21.0-unstable-2026-09-25 (#538170) 2026-09-28 11:18:16 +00:00
Nina Fromm
911885045f dokuwiki: add correct CPE information 2026-09-28 13:14:24 +02:00
linsui
a8e048cfe8 localsend: fix wm class 2026-09-28 19:14:19 +08:00
Nina Fromm
44037b25af dokuwiki: move from rec to finalAttrs 2026-09-28 13:14:15 +02:00
Masum Reza
bebc4b2c97 antigravity-acp: 1.1.1 -> 1.2.1 (#567807) 2026-09-28 11:13:14 +00:00
Marcus Ramberg
1767c1d7a2 proj: Fix compatibility issue with mapnik (#567204) 2026-09-28 11:12:45 +00:00
misuzu
745bf3365c sublime4: 4200 -> 4215 (#567687) 2026-09-28 11:09:47 +00:00
nixpkgs-ci[bot]
5e0369da12 pgschema: 1.13.0 -> 1.13.1 (#567626) 2026-09-28 11:00:57 +00:00
nixpkgs-ci[bot]
88a7e2fde6 aptakube: 1.20.4 -> 1.20.5 (#567520) 2026-09-28 11:00:53 +00:00
Niklas Hambüchen
df105e7a76 ceph: 20.2.3 -> 20.2.4 (№2) (#560576) 2026-09-28 11:00:47 +00:00
zimward
e07e56fa5c anarchism: 15.3-1 -> 15.3-4 2026-09-28 12:59:18 +02:00
Marcus Ramberg
240f191daa nixosTests.pocket-id: fix postgresql test (#567211) 2026-09-28 10:50:31 +00:00
Grimmauld
222397a349 httpstat: fix version detection in setup.py (#567576) 2026-09-28 10:48:47 +00:00
lambda-mike
58e1bcc6a2 3proxy: add cpe metadata 2026-09-28 12:44:39 +02:00
Thiago Kenji Okada
6500ce6442 nixos-version: escape specialisations and use kernel.modDirVersion if available 2026-09-28 11:37:07 +01:00
zowoq
eba2814a27 terraform-providers.datadog_datadog: 4.21.0 -> 4.22.0 (#567820) 2026-09-28 10:31:40 +00:00
Martin Weinelt
a74f280edf python3Packages.pip: fix shell completions on cross (#567774) 2026-09-28 10:28:08 +00:00
Nivayu
2cfe289ec4 freerdp: 3.32.0 -> 3.32.1 2026-09-28 12:25:01 +02:00
Diogo Correia
cf19af06b1 nixosTests.syncthing-folders: avoid IFD (#505674) 2026-09-28 10:19:21 +00:00
Sefa Eyeoglu
62a09d5a50 prismlauncher: add CPE parts
Signed-off-by: Sefa Eyeoglu <contact@scrumplex.net>
2026-09-28 12:17:11 +02:00
Gaétan Lepage
dfdf9d874c cudaPackages.buildRedist: match major.minor CUDA variants (#567765) 2026-09-28 10:17:11 +00:00
Gaetan Lepage
a8fb7a7eb1 cudaPackages.cuda_compat: add missing openssl on x86_64 2026-09-28 10:16:30 +00:00
Adam Dinwoodie
0db3be3aca nixosTests.syncthing-folders: refactor for clarity
Rewrite the test node configuration to use multiple modules and group
config according to the Syncthing folder it's being used for, rather
than by node, to make the different test cases clearer.
2026-09-28 12:00:52 +02:00
Adam Dinwoodie
6455637cda nixosTests.syncthing-{folders,no-settings}: clarify names
Change test names to match the name of the test, so different syncthing
tests can be distinguished.
2026-09-28 11:59:34 +02:00
Adam Dinwoodie
b758ee3a74 nixosTests.syncthing-folders: avoid IFD
Avoid import-from-derivation and non-reproducible derivations by
generating node configurations for Syncthing tests in advance, rather
than generating them at eval time.  The latter requires
import-from-derivation and also means every time the node configurations
are generated, syncthing will generate unique certificates, meaning
those derivations are different on every build.

While we're rewriting things, convert the IFD part to a script that can
be run to generate new Syncthing certificates and node IDs, and which
was used to generate the certificates and IDs in this commit.
2026-09-28 11:57:18 +02:00
Tom
c76a93019c dosfstools: refactor, fix license, adopt (#567632) 2026-09-28 09:57:08 +00:00
Jonas Heinrich
1680ab8217 convey: init at 50.2-1 (#567143) 2026-09-28 09:56:07 +00:00
Leona Maroni
04ef8559d1 netbox: 4.6.8 -> 4.7.1 (#563496) 2026-09-28 09:53:45 +00:00
Ryan Lahfa
be05997bbd lix: 2.95.2 -> 2.95.3 (#559191) 2026-09-28 09:49:25 +00:00
R. Ryantm
58f58d96a2 terraform-providers.datadog_datadog: 4.21.0 -> 4.22.0 2026-09-28 09:48:20 +00:00
Ryan Lahfa
84e3caf22f libucontext: build the hand-written asm files with -Wa,--noexecstack (#567812) 2026-09-28 09:47:58 +00:00
Gergő Gutyina
30f7aae43b cisco-packet-tracer_9: add mime files (#496181) 2026-09-28 09:47:27 +00:00
Thiago Kenji Okada
716f0c4e18 nixos-rebuild-ng: handle JSONDecodeError 2026-09-28 10:46:01 +01:00
R. Ryantm
1e35d211ad python3Packages.pysigma-pipeline-windows: 2.0.0 -> 2.0.1 2026-09-28 09:39:09 +00:00
nixpkgs-ci[bot]
a705f94ebb graff: 0.0.299 -> 0.0.302.6 (#567791) 2026-09-28 09:38:25 +00:00
nixpkgs-ci[bot]
16500f118c mongosh: 2.11.1 -> 2.12.0 (#567787) 2026-09-28 09:38:21 +00:00
nixpkgs-ci[bot]
1f831a20bc steelix: 0-unstable-2026-05-21 -> 0-unstable-2026-09-26 (#567760) 2026-09-28 09:38:19 +00:00
nixpkgs-ci[bot]
0b72fef98d nezha: 2.3.12 -> 2.3.14 (#567675) 2026-09-28 09:38:16 +00:00
nixpkgs-ci[bot]
1b97d1625b rusthound-ce: 2.5.13 -> 2.5.14 (#567428) 2026-09-28 09:38:10 +00:00
Jonas Heinrich
3da6fd3924 convey: init at 50.2-1 2026-09-28 11:37:57 +02:00
Raito Bezarius
97bf56b78d lix: link with -z,noexecstack
Defense-in-depth so a dependency cannot give lix an executable stack,
like libucontext did.

Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
2026-09-28 11:37:32 +02:00
Raito Bezarius
c76523c9bb libucontext: build the hand-written asm files with -Wa,--noexecstack
meson.build omits the flag the Makefile passes, giving every static consumer
(e.g. pkgsStatic.lix via capnproto) an executable stack. :)

Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
2026-09-28 11:37:32 +02:00
Jonas Heinrich
d57a6a4ff0 nixos/wordpress: auto migrate database (#559092) 2026-09-28 09:35:44 +00:00
Pratham Patel
7a109bef65 cudaPackages.buildRedist: match major.minor CUDA variants 2026-09-28 09:34:05 +00:00
Ali Heydari
e1b3c9afa5 antigravity-acp: 1.1.1 -> 1.2.1 2026-09-28 13:02:29 +03:30
R. Ryantm
e9d69a6bba snyk: 1.1307.1 -> 1.1307.4 2026-09-28 09:30:13 +00:00
Gergő Gutyina
b5cbb4bc4f nixos/adguardhome: allow AF_UNIX when log.file=="syslog" (#532141) 2026-09-28 09:30:08 +00:00
Jonas Heinrich
3df7f5b1d3 nixos/wordpress: auto migrate database 2026-09-28 11:29:16 +02:00
Connor Baker
a3a8810e73 cudaPackages.cuda_compat: fix meta.problems condition (#567798) 2026-09-28 09:27:25 +00:00
Gaetan Lepage
852e4543e5 cudaPackages.cuda_compat: fix meta.problems condition 2026-09-28 09:20:30 +00:00
Leona Maroni
6e72fe44ce discourse: 2026.8.0 -> 2026.9.0 (#567703) 2026-09-28 09:18:37 +00:00
Thiago Kenji Okada
896eba9b0d nixos-rebuild-ng: make nixosVersion key NotRequired 2026-09-28 10:09:09 +01:00
Thiago Kenji Okada
b19cbd07b1 nixos-version: update manpage 2026-09-28 10:08:59 +01:00
Connor Baker
af9914894d config: add enableCudaDriverCompat (#567786) 2026-09-28 09:08:10 +00:00
Alexis Hildebrandt
619e4b0149 miracle-wm: 0.10.1 -> 0.11.2
Changelog: https://github.com/miracle-wm-org/miracle-wm/releases/tag/v0.11.2
2026-09-28 11:05:52 +02:00
R. Ryantm
9195c8c1d3 graff: 0.0.299 -> 0.0.302.6 2026-09-28 09:01:26 +00:00
Gaetan Lepage
f2b8e80ec8 config: add enableCudaDriverCompat 2026-09-28 08:59:22 +00:00
Fabian Affolter
ee6f3f08d8 nerva: 1.70.0 -> 1.70.1 (#567782) 2026-09-28 08:56:13 +00:00
R. Ryantm
0d9c079731 mongosh: 2.11.1 -> 2.12.0 2026-09-28 08:55:52 +00:00
Fabian Affolter
aaad19889f python3Packages.cpe-search: 0.2.11 -> 0.2.12 (#567736) 2026-09-28 08:54:19 +00:00
Fabian Affolter
7c0faa61c0 python3Packages.iamdata: 0.1.202609271 -> 0.1.202609281 (#567750) 2026-09-28 08:53:43 +00:00
Fabian Affolter
6ebc8cc17f python3Packages.soco: 0.31.2 -> 0.31.4 (#567773) 2026-09-28 08:53:35 +00:00
Fabian Affolter
609246e88e python3Packages.cwl-utils: 0.44 -> 0.45 (#567666) 2026-09-28 08:51:48 +00:00
Fabian Affolter
e40eafaa84 goshs: 2.1.6 -> 2.1.7 (#567763) 2026-09-28 08:50:51 +00:00
Yohann Boniface
c504b83132 maintainer: update email for 365tuwe (#567759) 2026-09-28 08:50:36 +00:00
Fabian Affolter
f24bbb01a4 nerva: 1.70.0 -> 1.70.1
Diff: https://github.com/praetorian-inc/nerva/compare/v1.70.0...v1.70.1

Changelog: https://github.com/praetorian-inc/nerva/blob/v1.70.1/CHANGELOG.md
2026-09-28 10:48:33 +02:00
Thiago Kenji Okada
deae30d7b7 nixos-rebuild-ng: extract kernelVersion, nixosVersion and specialisation from nixos-version
Before this PR we needed to parse the filesystem to extract some
information to build the `nixos-rebuild list-generation` output.
We already used `nixos-version --configuration-revision` to extract the
`configurationRevision` key, but now we can use the `nixos-version
--json` output to extract all the information we need, now that the
previous commit added support for `kernelVersion` and `specialisation`
fields (`nixosVersion` was already available before hand).

This is a first step to allow `nixos-rebuild list-generation` to target
remote hosts. The second step will come after a new Nix version is
released with https://github.com/NixOS/nix/issues/5144 and that version
is used by default by nixpkgs. After that we can also run the `nix-env
--list-generations` remotely to get all generations before scrapping the
additional information needed by `nixos-rebuild list-generations`.
2026-09-28 09:40:39 +01:00
Thiago Kenji Okada
6025007e0e nixos-version: add --kernel-version and --specialisations 2026-09-28 09:40:39 +01:00
R. Ryantm
02ebf54cdf mago: 1.49.0 -> 1.50.0 2026-09-28 08:39:09 +00:00
R. Ryantm
45c4af571e prometheus-redis-exporter: 1.91.1 -> 1.92.1 2026-09-28 08:28:49 +00:00
Diogo Correia
31d68abfc5 bazarr: 1.6.1 -> 1.6.2 (#567382) 2026-09-28 08:27:34 +00:00
R. Ryantm
8e69c8ffd7 cdk8s-cli: 2.207.58 -> 2.207.62 2026-09-28 08:24:56 +00:00
Connor Baker
0742f8b731 cudaPackages.cuda_nvdisasm: set meta.mainProgram (#567741) 2026-09-28 08:18:57 +00:00
Connor Baker
f322e3863a cudaPackages.cuda_cuobjdump: set meta.mainProgram (#567742) 2026-09-28 08:18:08 +00:00
nixpkgs-ci[bot]
8f83e21756 go-judge: 1.12.3 -> 1.13.0 (#567762) 2026-09-28 08:17:20 +00:00
nixpkgs-ci[bot]
f64dedb1b4 blackfire: 2026.9.0 -> 2026.9.1 (#567081) 2026-09-28 08:17:19 +00:00
nixpkgs-ci[bot]
715a3f0b62 phpExtensions.blackfire: 2026.9.0 -> 2026.9.2 (#566983) 2026-09-28 08:17:18 +00:00
Marcus Ramberg
6a18cc4600 vivaldi: 8.2.4133.52 -> 8.2.4133.76 (#567574) 2026-09-28 08:13:56 +00:00
Grimmauld
a6c5a14ae7 python3Packages.pip: fix shell completions on cross 2026-09-28 10:12:15 +02:00
Tom
926232a270 gnome-mahjongg: 49.1.1 -> 51.0 (#564416) 2026-09-28 08:09:23 +00:00
R. Ryantm
14377089fe python3Packages.soco: 0.31.2 -> 0.31.4 2026-09-28 08:02:34 +00:00
R. Ryantm
b4ff75e5b1 lazyworktree: 1.50.0 -> 1.50.1 2026-09-28 07:53:57 +00:00
R. Ryantm
628b0b1bac mackerel-agent: 0.87.0 -> 0.87.1 2026-09-28 07:52:53 +00:00
Ivan Mincik
4b539d5ab1 qgis: 4.2.1 -> 4.2.2 (#561524) 2026-09-28 07:44:44 +00:00
Yohann Boniface
850cc6fe67 paq: add gregl83 as maintainer (#566352) 2026-09-28 07:43:43 +00:00
R. Ryantm
d88ac2ec00 goshs: 2.1.6 -> 2.1.7 2026-09-28 07:28:41 +00:00
R. Ryantm
817ed95c2f go-judge: 1.12.3 -> 1.13.0 2026-09-28 07:26:13 +00:00
Yohann Boniface
4b3a6850b4 jack-autoconnect: fix version, modernize (#567252) 2026-09-28 07:22:03 +00:00
nixpkgs-ci[bot]
c17721e241 nerdlog: 1.11.0 -> 1.12.0 (#567605) 2026-09-28 07:19:04 +00:00
Yohann Boniface
875e26f600 python3Packages.pyhik: 0.4.6 -> 0.4.7 (#567356) 2026-09-28 07:16:43 +00:00
R. Ryantm
ab13c193cf vpxtool: 0.34.1 -> 0.34.6 2026-09-28 07:15:17 +00:00
Yohann Boniface
fad33d2b93 vscode-extensions.ms-azuretools.vscode-containers: 2.5.1 -> 2.5.2 (#567385) 2026-09-28 07:14:33 +00:00
R. Ryantm
4b383bc744 steelix: 0-unstable-2026-05-21 -> 0-unstable-2026-09-26 2026-09-28 07:12:31 +00:00
Uwe Schlifkowitz
c6439d7af9 maintainer: update email for 365tuwe 2026-09-28 09:03:09 +02:00
Yohann Boniface
7a0f122f50 maintainers: update wrench-exile-legacy (#567174) 2026-09-28 06:58:16 +00:00
Augustin Trancart
cd22c439df qgis: fix tests 2026-09-28 08:54:32 +02:00
nixpkgs-ci[bot]
ac2a1c8669 rainfrog: 0.4.5 -> 0.4.6 (#567718) 2026-09-28 06:52:14 +00:00
yvnth
beff6a09f7 mango: 0.17.3 -> 0.17.4 2026-09-28 12:22:12 +05:30
nixpkgs-ci[bot]
5cfd588811 snx-rs: 6.3.1 -> 6.4.1 (#567669) 2026-09-28 06:52:12 +00:00
zowoq
a749b0426d kexec-tools, nixos/kexec: add maintainer (#567312) 2026-09-28 06:48:31 +00:00
zowoq
24ab406b2a terraform-providers.topicusonderwijs_octodns: 1.2.0 -> 1.3.0 (#567752) 2026-09-28 06:47:06 +00:00
zowoq
e2f3ad474e terraform-providers.heroku_heroku: 5.4.0 -> 5.4.1 (#567740) 2026-09-28 06:47:04 +00:00
Yohann Boniface
dce8fd423b python3Packages.pysillaprism: 0.2.0 -> 0.2.1 (#567351) 2026-09-28 06:35:53 +00:00
Yohann Boniface
83baa7036b mmh: fix version; enable strictDeps, structuredAttrs (#567272) 2026-09-28 06:33:24 +00:00
Yohann Boniface
1d0af22685 newflasher: modernize (#567336) 2026-09-28 06:29:02 +00:00
R. Ryantm
43c528b76a apftool-rs: 1.2.5 -> 1.2.6 2026-09-28 06:28:43 +00:00
StepBroBD
e66726eb50 ocamlPackages.capnp-rpc{,-net,-unix}: init at 2.1.2 (#565838) 2026-09-28 06:26:02 +00:00
Fabian Affolter
467a533ac3 python3Packages.opentelemetry-instrumentation-urllib3: add mocket (#567662) 2026-09-28 06:23:13 +00:00
Fabian Affolter
783d8a0653 python3Packages.isbnlib: add pkg-resources-backport (#567633) 2026-09-28 06:23:07 +00:00
Fabian Affolter
c93c0aa300 python3Packages.jenkinsapi: 0.3.17 -> 0.3.23 (#567629) 2026-09-28 06:23:01 +00:00
Fabian Affolter
9cd63238db python3Packages.editdistpy: add pkg-resources-backport (#567621) 2026-09-28 06:22:55 +00:00
nixpkgs-ci[bot]
1f950b129d Merge staging-next into staging 2026-09-28 06:22:50 +00:00
nixpkgs-ci[bot]
134009e975 Merge master into staging-next 2026-09-28 06:22:20 +00:00
Fabian Affolter
c9151ff47e python3Packages.iamdata: 0.1.202609271 -> 0.1.202609281
Diff: https://github.com/cloud-copilot/iam-data-python/compare/v0.1.202609271...v0.1.202609281

Changelog: https://github.com/cloud-copilot/iam-data-python/releases/tag/v0.1.202609281
2026-09-28 08:20:18 +02:00
R. Ryantm
803b752cc0 vscode-extensions.bazelbuild.vscode-bazel: 0.14.0 -> 0.15.0 2026-09-28 06:17:13 +00:00
R. Ryantm
715faad1ba terraform-providers.topicusonderwijs_octodns: 1.2.0 -> 1.3.0 2026-09-28 06:16:30 +00:00
R. Ryantm
5a647f34e3 vscode-extensions.coder.coder-remote: 1.16.3 -> 1.16.4 2026-09-28 06:09:44 +00:00
nixpkgs-ci[bot]
3722331394 dotenvx: 2.28.0 -> 2.31.1 (#567713) 2026-09-28 05:59:48 +00:00
Vladimír Čunát
624274c6c9 gcc13: 13.4.0 -> 13.5.0 (#562297) 2026-09-28 05:58:05 +00:00
Vladimír Čunát
9d087851f0 thrift: disable tests on darwin for now
https://hydra.nixos.org/build/346751725/step/6/log
2026-09-28 08:09:14 +02:00
Vladimír Čunát
1dcd2d3b97 grpc: avoid another warning on darwin
https://hydra.nixos.org/build/346802192#tabs-buildsteps
2026-09-28 08:01:46 +02:00
Jared Baur
e6025a0259 dts-lsp: 0.1.5 -> 0.1.7 (#567628) 2026-09-28 05:39:07 +00:00
Pol Dellaiera
ad6b92f21c sleuthkit: 4.14.0 -> 4.15.0, autopsy: 4.22.1 -> 4.23.1 (#567571) 2026-09-28 05:34:31 +00:00
K900
8eea819084 kdePackages.ktextaddons: 2.1.2 -> 2.2.0 (#567715) 2026-09-28 05:25:33 +00:00
Ethan Carter Edwards
dcb658e339 cudaPackages.cuda_nvdisasm: set meta.mainProgram
Signed-off-by: Ethan Carter Edwards <ethan@ethancedwards.com>
2026-09-28 01:25:19 -04:00
Yohann Boniface
395669d34e xdg-desktop-portal-wlr: adopt (#567611) 2026-09-28 05:16:17 +00:00
Yohann Boniface
0f59c8769f python3Packages.odl-renderer: set meta.description (#567658) 2026-09-28 05:15:59 +00:00
Vladimír Čunát
046fe78bb8 [staging-next] rocmPackages.migraphx: explicitly specify c++17 for abseil-cpp (#567659) 2026-09-28 05:15:09 +00:00
Vladimír Čunát
1e3fc9670c [staging-next] zug: disable failing test with gcc 16 (#567620) 2026-09-28 05:14:27 +00:00
Yohann Boniface
66069d06fe sd-mux-ctrl: use git URL instead of https (#567673) 2026-09-28 05:12:40 +00:00
Yohann Boniface
17014b77a5 rustormy: add ethancedwards8 as maintainer (#567717) 2026-09-28 05:08:11 +00:00
Yohann Boniface
61fd9ace65 python3Packages.ha-garmin: 0.1.47 -> 0.1.48 (#567734) 2026-09-28 05:06:31 +00:00
kirillrdy
419fe0f449 process-compose: 1.120.0 -> 1.122.0 (#553782) 2026-09-28 04:45:22 +00:00
R. Ryantm
aea5872510 terraform-providers.heroku_heroku: 5.4.0 -> 5.4.1 2026-09-28 04:41:30 +00:00
Ethan Carter Edwards
eb32b5a3d4 cudaPackages.cuda_cuobjdump: set meta.mainProgram
Signed-off-by: Ethan Carter Edwards <ethan@ethancedwards.com>
2026-09-28 00:13:33 -04:00
R. Ryantm
fa1b73f813 python3Packages.cpe-search: 0.2.11 -> 0.2.12 2026-09-28 04:07:01 +00:00
R. Ryantm
690e4593bd tree-sitter-grammars.tree-sitter-sshclientconfig: 2026.8.27 -> 2026.9.24 2026-09-28 03:42:24 +00:00
R. Ryantm
5ebb82927c python3Packages.ha-garmin: 0.1.47 -> 0.1.48 2026-09-28 03:33:30 +00:00
Adam C. Stephens
55d33a38f8 matrix-continuwuity: 26.9.0 -> 26.9.1 (#567722) 2026-09-28 03:30:47 +00:00
Ryan Burns
16eca43345 aws-*: upgrade AWS C libraries to latest versions (#565568) 2026-09-28 03:25:56 +00:00
R. Ryantm
6bdb417bb9 flatpak-builder-tools: 0-unstable-2026-09-12 -> 0-unstable-2026-09-21 2026-09-28 03:20:15 +00:00
R. Ryantm
32b9f13c34 infrastructure-agent: 1.80.3 -> 1.80.4 2026-09-28 03:13:59 +00:00
Akira Komamura
0d996e3d24 ocamlPackages.capnp-rpc-unix: init at 2.1.2-unstable-2026-09-13
Co-authored-by: StepBroBD <ysun@duck.com>
2026-09-28 12:08:37 +09:00
nixpkgs-ci[bot]
ec07232412 torrserver: 144.4 -> 145 (#567593) 2026-09-28 02:46:32 +00:00
R. Ryantm
bbd41c656a python3Packages.pylsl: 1.18.4.b1 -> 1.18.5 2026-09-28 02:43:06 +00:00
zowoq
a596798d42 terraform-providers.vancluever_acme: 3.1.2 -> 3.2.0 (#567725) 2026-09-28 02:35:46 +00:00
R. Ryantm
29d8fc3400 oauth2c: 1.21.0 -> 1.21.1 2026-09-28 02:29:46 +00:00
R. Ryantm
8ec645138c rclone-ui: 3.7.2 -> 3.7.5 2026-09-28 02:25:32 +00:00
R. Ryantm
1118401a22 gelly: 1.13.0 -> 1.14.0 2026-09-28 02:12:04 +00:00
R. Ryantm
e23dda9920 terraform-providers.vancluever_acme: 3.1.2 -> 3.2.0 2026-09-28 02:11:29 +00:00
nixpkgs-ci[bot]
1dd1cea4b0 folia-major: 0.7.7 -> 0.7.9 (#567585) 2026-09-28 02:06:34 +00:00
nixpkgs-ci[bot]
66956d5e8d wiki-go: 1.9.1 -> 1.9.2 (#567579) 2026-09-28 02:06:33 +00:00
R. Ryantm
d924c7eb84 nerva: 1.70.0 -> 1.70.1 2026-09-28 01:57:40 +00:00
Henry-Hiles
32f8806c23 matrix-continuwuity: 26.9.0 -> 26.9.1 2026-09-27 21:48:24 -04:00
Ethan Carter Edwards
a49b8639f7 rustormy: add ethancedwards8 as maintainer
Helped my friend @joseg313 package this!

Signed-off-by: Ethan Carter Edwards <ethan@ethancedwards.com>
2026-09-27 21:45:31 -04:00
R. Ryantm
675cc8a99c rainfrog: 0.4.5 -> 0.4.6 2026-09-28 01:44:12 +00:00
R. Ryantm
570e94e642 libopenshot-audio: 1.0.0 -> 1.0.1 2026-09-28 01:41:16 +00:00
rewine
e5e99a12e7 neocmakelsp: 0.11.1 -> 0.11.2 (#567362) 2026-09-28 01:35:12 +00:00
Ilan Joselevich
dc1f2f3258 rustormy: init at 0.5.2 (#567704) 2026-09-28 01:22:30 +00:00
Ben Siraphob
7d1b2da911 phonon: disable unstable experimental API (#508812) 2026-09-28 01:18:08 +00:00
R. Ryantm
b143136ce0 dotenvx: 2.28.0 -> 2.31.1 2026-09-28 01:08:40 +00:00
nixpkgs-ci[bot]
9383a1fa06 aerion: 0.3.4 -> 0.3.5 (#567601) 2026-09-28 01:04:29 +00:00
nixpkgs-ci[bot]
a709492064 wrangler: 4.132.0 -> 4.141.0 (#567335) 2026-09-28 01:04:26 +00:00
kirillrdy
b79ca1666d python3Packages.scikit-base: 1.1.1 -> 1.2.0 (#567700) 2026-09-28 00:44:04 +00:00
R. Ryantm
4b91c2e333 kdePackages.ktextaddons: 2.1.2 -> 2.2.0 2026-09-28 00:43:08 +00:00
Gergő Gutyina
10b33c51ed feh: 3.13 -> 3.13.1 (#567338) 2026-09-28 00:41:15 +00:00
R. Ryantm
ec1019e02a readsb: 3.16.16 -> 3.16.17 2026-09-28 00:38:16 +00:00
R. Ryantm
92d5bf0393 mbuffer: 20260511 -> 20260926 2026-09-28 00:36:50 +00:00
Jose Garcia
44c43afccc rustormy: init at 0.5.2 2026-09-27 19:36:50 -05:00
nixpkgs-ci[bot]
e426276057 Merge staging-next into staging 2026-09-28 00:28:56 +00:00
nixpkgs-ci[bot]
362969a3a4 Merge master into staging-next 2026-09-28 00:28:27 +00:00
Martin Weinelt
0f6171af43 discourse: 2026.8.0 -> 2026.9.0
https://releases.discourse.org/changelog/v2026.9.0/

Fixes:
- CVE-2026-91159 Stored oEmbed HTML injection via allowed iframe
- CVE-2026-91157 Media uploads remain publicly accessible after category
  permissions are restricted
- CVE-2026-91156 Chat MessageBus delivers read-restricted messages to
  unauthorized users
2026-09-28 02:26:59 +02:00
Jose Garcia
e08a226805 maintainers: add joseg313 2026-09-27 19:19:29 -05:00
Katsumi Takeuchi
91ed2817f7 intel-oneapi-toolkit: fix C++ standard library headers in stdenv
The wrapped icpx could not find libstdc++ headers, so any C++ source
failed with e.g. "'type_traits' file not found". This broke the
headers-available and sycl-compile passthru tests.

cc-wrapper only adds libstdc++ include paths when the compiler sets
langCC, which the unwrapped icpx shim did not. Set it.

Assisted-by: Claude Code with Opus 5.5 medium (Anthropic)
2026-09-28 09:04:49 +09:00
R. Ryantm
88c4c23f3d libretro.fmsx: 0-unstable-2026-09-06 -> 0-unstable-2026-09-26 2026-09-27 23:50:24 +00:00
Martin Weinelt
e9227ddbcc python3Packages.pydantic-graph: 2.31.1 -> 2.51.0 (#567680) 2026-09-27 23:42:12 +00:00
R. Ryantm
40a0682936 python3Packages.scikit-base: 1.1.1 -> 1.2.0 2026-09-27 23:36:18 +00:00
nixpkgs-ci[bot]
02151a19ef skills: 1.6.0 -> 1.7.0 (#567491) 2026-09-27 23:20:39 +00:00
nixpkgs-ci[bot]
5587f33752 microcode-intel: 20260812 -> 20260925 (#567002) 2026-09-27 23:20:38 +00:00
Gaël James
04c3a5ee4c python3Packages.pydantic-ai-slim: 2.31.1 -> 2.51.0 2026-09-28 01:01:31 +02:00
Gaël James
ad9bdab780 python3Packages.genai-prices: 0.1.3 -> 0.1.9 2026-09-28 01:01:09 +02:00
zowoq
f3aa7d3d72 linux_testing: 7.3-rc4 -> 7.3-rc5 (#567667) 2026-09-27 22:59:41 +00:00
R. Ryantm
adda1ca2de claude-agent-acp: 0.79.0 -> 0.81.2 2026-09-27 22:51:35 +00:00
R. Ryantm
297a6c7a5d sioyek: 2.0.0-unstable-2026-08-18 -> 2.0.0-unstable-2026-09-24 2026-09-27 22:49:39 +00:00
R. Ryantm
820c4b7819 sublime4: 4200 -> 4215 2026-09-27 22:44:55 +00:00
@mjones
307a907beb xpra: 6.5.3 -> 6.5.4 (#566948) 2026-09-27 22:36:36 +00:00
Gaël James
1aca75d937 python3Packages.pydantic-graph: 2.31.1 -> 2.51.0 2026-09-28 00:36:09 +02:00
@mjones
0971a39b3e treewide: fix homepages [6/10] (#567133) 2026-09-27 22:35:27 +00:00
R. Ryantm
043116f501 python3Packages.bandcamp-async-api: 0.2.4 -> 0.2.6 2026-09-27 22:32:19 +00:00
@mjones
c0bd54b0d2 easyrsa: 3.2.6 -> 3.2.7 (#564956) 2026-09-27 22:31:41 +00:00
@mjones
67910de46d nixos/nebula: fix inverted tun.device length assertion (#565501) 2026-09-27 22:28:12 +00:00
@mjones
eb2e84e233 supercollider-with-plugins: fix plugin discovery (#566382) 2026-09-27 22:20:05 +00:00
Ihar Hrachyshka
afe9a9721b ramalama: 0.22.0 -> 0.25.0 (#567640) 2026-09-27 22:19:47 +00:00
@mjones
8f307c54cb muso: fix version, enable structuredAttrs (#567300) 2026-09-27 22:16:56 +00:00
R. Ryantm
cf2bc81331 nezha: 2.3.12 -> 2.3.14 2026-09-27 22:15:37 +00:00
Alex Martens
dd885ddf5b sd-mux-ctrl: use git URL instead of https
The https URL for git.tizen.org is throwing SSL errors.
2026-09-27 15:13:15 -07:00
R. Ryantm
68ca96ea3f libretro.swanstation: 0-unstable-2026-08-11 -> 0-unstable-2026-09-17 2026-09-27 22:01:18 +00:00
R. Ryantm
1a0efb51f9 snx-rs: 6.3.1 -> 6.4.1 2026-09-27 21:52:33 +00:00
azahi
385344272c iaito: remove breakpointHook (#567221) 2026-09-27 21:51:56 +00:00
azahi
ae98882493 soju: 0.11.0 -> 0.11.1 (#566856) 2026-09-27 21:49:38 +00:00
Ihar Hrachyshka
261ae965db fromager: temporarily serialize tests (#567607) 2026-09-27 21:48:44 +00:00
Ihar Hrachyshka
cf2d743716 fromager: 0.95.0 -> 0.97.0 (#567090) 2026-09-27 21:45:18 +00:00
Jack Boykin
108405fc4b linux_testing: 7.3-rc4 -> 7.3-rc5 2026-09-27 16:43:56 -05:00
R. Ryantm
5a10fb0292 python3Packages.cwl-utils: 0.44 -> 0.45 2026-09-27 21:37:10 +00:00
dish
bb84a203ca noctalia: 5.1.0 -> 5.2.0; noctalia-greeter: 1.5.0 -> 1.6.0 (#567586) 2026-09-27 21:32:18 +00:00
Fabian Affolter
96b0ae40db python3Packages.opentelemetry-instrumentation-urllib3: add mocket 2026-09-27 23:29:26 +02:00
Ben Siraphob
48813dcbf7 trealla: 3.10.3 -> 3.11.4 (#566819) 2026-09-27 21:28:08 +00:00
Sandro Jäckel
88b8d8a2f7 python3Packages.odl-renderer: set meta.description 2026-09-27 23:21:57 +02:00
eljamm
d17290da46 nwjs: sort inputs 2026-09-27 23:15:11 +02:00
nixpkgs-ci[bot]
99d93feef4 dae: 2.0.0 -> 2.1.1 (#567575) 2026-09-27 21:05:44 +00:00
Thomas Gerbet
1cf8addc17 brave{,-origin}: 1.95.104 -> 1.96.59 (#567185) 2026-09-27 20:52:32 +00:00
Luke Granger-Brown
a163b9ecfc isponsorblocktv: fix with async-cache 2.x (#567212) 2026-09-27 20:50:29 +00:00
Ihar Hrachyshka
bfc0e2f8ed ramalama: 0.22.0 -> 0.25.0 2026-09-27 16:49:51 -04:00
Wolfgang Walther
d1e21dfa35 postgresqlPackages.citus: 13.0.3 -> 14.2.0 (#567619) 2026-09-27 20:47:41 +00:00
whispers
4f6abeab07 rocmPackages.migraphx: explicitly specify c++17 for abseil-cpp
abseil exposes different interfaces depending on what is available in
std in a given C++ standard. gcc 16 defaults to C++20, thus causing the
default abseil-cpp to expose a different interface than the one
migraphx (built with C++17) expects. thus, we explicitly override abseil
to specify the desired C++ standard.

failing build logs: https://hydra.nixos.org/build/346880137
2026-09-27 16:45:50 -04:00
nixpkgs-ci[bot]
562377938a badness: 0.23.0 -> 0.24.0 (#567594) 2026-09-27 20:45:48 +00:00
nixpkgs-ci[bot]
b646a13af2 clifm: 1.28 -> 1.29 (#567541) 2026-09-27 20:45:47 +00:00
Felix Bargfeldt
fd29d673b0 radicle-explorer: 0-unstable-2026-09-14 -> 0-unstable-2026-09-25 (#567600) 2026-09-27 20:45:15 +00:00
Arne Keller
3093c65c6c kubernetes-polaris: 10.1.7 -> 10.2.5 (#534396) 2026-09-27 20:44:45 +00:00
Arne Keller
348b38185c librice: 0.3.0 -> 0.4.3 (#507569) 2026-09-27 20:44:40 +00:00
Ihar Hrachyshka
fadb9c2f2c fromager: temporarily serialize tests 2026-09-27 16:42:28 -04:00
StepBroBD
7276cb9606 ocamlPackages.*: fix homepages (#566982) 2026-09-27 20:36:40 +00:00
R. Ryantm
58aa05565f sable-unwrapped: 1.22.6 -> 1.22.9 2026-09-27 20:34:54 +00:00
nixpkgs-ci[bot]
0addfef054 framework-tool-tui: 0.8.5 -> 0.8.6 (#567625) 2026-09-27 20:32:50 +00:00
Fabian Affolter
62c4412db2 python3Packages.isbnlib: add pkg-resources-backport 2026-09-27 22:31:20 +02:00
R. Ryantm
738a39b82d vastai: 1.5.6 -> 1.8.2 2026-09-27 20:30:13 +00:00
quantenzitrone
8ba8775282 dosfstools: adopt 2026-09-27 22:28:21 +02:00
quantenzitrone
b9a3267a1d dosfstools: fix license
upstream uses the GPL-3.0-or-later header in the files
2026-09-27 22:27:46 +02:00
Fabian Affolter
16754faf47 python3Packages.jenkinsapi: migrate to finalAttrs 2026-09-27 22:27:27 +02:00
quantenzitrone
e4f633c5e2 dosfstools: use tag and hash instead of rev and sha256 in src 2026-09-27 22:26:50 +02:00
Wolfgang Walther
8f3a414f28 postgresql_19: 19beta3 -> 19beta4 (#566393) 2026-09-27 20:26:21 +00:00
Fabian Affolter
38a640953e python3Packages.jenkinsapi: 0.3.17 -> 0.3.23
Changelog: https://github.com/pycontribs/jenkinsapi/releases/tag/0.3.23
2026-09-27 22:25:41 +02:00
Ingo Reitz
47c86ae54f dts-lsp: 0.1.5 -> 0.1.7 2026-09-27 22:25:34 +02:00
R. Ryantm
b6dde7a2e7 pgschema: 1.13.0 -> 1.13.1 2026-09-27 20:17:58 +00:00
R. Ryantm
ac4612846d framework-tool-tui: 0.8.5 -> 0.8.6 2026-09-27 20:15:45 +00:00
R. Ryantm
942dbc1bcc usql: 0.21.5 -> 0.21.6 2026-09-27 20:15:13 +00:00
Fabian Affolter
3c2e59eb5f python3Packages.editdistpy: modernize
- migrate to finalAttrs
- Update ordering
2026-09-27 22:14:56 +02:00
Marcus Ramberg
1c7c25ed32 codex-security: init at 0.1.31 (#548525) 2026-09-27 20:13:58 +00:00
liberodark
865eb1b331 plakar: 1.1.6 -> 1.1.7 2026-09-27 22:13:05 +02:00
Fabian Affolter
12a6d767c1 python3Packages.editdistpy: add pkg-resources-backport 2026-09-27 22:12:54 +02:00
whispers
4aaac6299b zug: disable failing test with gcc 16
gcc 16 changed the behavior of std::generate_anonical to match P0952R2,
which changes some of the properties of random function output. the
simple random_sample test relied on these properties, and now fails. an
issue has been open upstream since may 2026, with no response. to work
around this, we disable the offending test.

an alternative would be to build zug with
`-D_GLIBCXX_USE_OLD_GENERATE_CANONICAL` to opt-out of this behavior,
but given that this is somewhat fragile in general, it seems fine to
just disable this test. there is another test with a custom
deterministic engine to validate that the code isn't broken as well.
2026-09-27 16:12:51 -04:00
Francesco Gazzetta
468ba8268a tcl.tclRequiresCheckHook: refer to tclsh by absolute path (#527901) 2026-09-27 20:07:37 +00:00
Martin Weinelt
ce23abec5c home-assistant: 2026.9.3 -> 2026.9.4 (#567554) 2026-09-27 20:05:07 +00:00
Anish Pallati
0029d87979 postgresqlPackages.citus: 13.0.3 -> 14.2.0
Signed-off-by: Anish Pallati <i@anish.land>
2026-09-27 16:04:52 -04:00
Anish Pallati
567af362b9 postgresqlPackages.citus: add anish as maintainer
Signed-off-by: Anish Pallati <i@anish.land>
2026-09-27 15:57:09 -04:00
nixpkgs-ci[bot]
c89322c9af olympus-unwrapped: 26.09.15.05 -> 26.09.27.01 (#567614) 2026-09-27 19:51:47 +00:00
Aaron Andersen
69fc1bbc4c eudev: 3.2.14 -> 3.2.15 2026-09-27 21:50:31 +02:00
Martin Weinelt
6789b948e9 evcc: 0.316.0 -> 0.316.1 (#567610) 2026-09-27 19:45:56 +00:00
R. Ryantm
cf33938246 python3Packages.tomlrt: 2.2.7 -> 2.2.14 2026-09-27 19:41:10 +00:00
Ihar Hrachyshka
f1223f4a2c podman-desktop: ignore pre-releases (#567577) 2026-09-27 19:38:52 +00:00
R. Ryantm
37b8eb7364 olympus-unwrapped: 26.09.15.05 -> 26.09.27.01 2026-09-27 19:38:48 +00:00
Fabian Affolter
d86a11d3f2 python3Packages.iamdata: 0.1.202609261 -> 0.1.202609271 (#567591) 2026-09-27 19:38:12 +00:00
Yohann Boniface
02eba545f4 pdfid: add eljamm as maintainer (#567444) 2026-09-27 19:36:09 +00:00
Ihar Hrachyshka
149c3704cc fromager: avoid http retry backoffs in sandbox (#567599) 2026-09-27 19:35:52 +00:00
Yohann Boniface
ca9249dea8 intel-oneapi-toolkit: add recutita as maintainer (#567059) 2026-09-27 19:35:08 +00:00
Anish Pallati
d3b77a9d6c postgresql_19: 19beta3 -> 19beta4
Signed-off-by: Anish Pallati <i@anish.land>
2026-09-27 15:32:19 -04:00
Martin Weinelt
1a3e1f020b evcc: 0.316.0 -> 0.316.1
https://github.com/evcc-io/evcc/releases/tag/0.316.1
2026-09-27 21:31:19 +02:00
R. Ryantm
8134b2e2e0 cocoon: 0.11.3 -> 0.11.4 2026-09-27 19:28:13 +00:00
Jo
531062ef77 lib.licenses: drop gfl in favor of lppl13c (#557118) 2026-09-27 19:26:05 +00:00
R. Ryantm
42477dabb6 nerdlog: 1.11.0 -> 1.12.0 2026-09-27 19:23:50 +00:00
nixpkgs-ci[bot]
892a408237 nest-cli: 12.0.3 -> 12.0.7 (#567361) 2026-09-27 19:23:36 +00:00
Martin Weinelt
51a0e0036e home-assistant: fix portainer test hang 2026-09-27 21:19:00 +02:00
Jan Tojnar
e1753014c8 meson: add disabledTests support (#552282) 2026-09-27 19:10:48 +00:00
nixpkgs-ci[bot]
c4259607f9 gogup: 1.9.3 -> 1.10.2 (#567497) 2026-09-27 19:08:08 +00:00
quantenzitrone
4ba5383ea3 xdg-desktop-portal-wlr: adopt 2026-09-27 21:07:35 +02:00
R. Ryantm
f8b2b12ffa aerion: 0.3.4 -> 0.3.5 2026-09-27 19:01:17 +00:00
Ihar Hrachyshka
8dd3c685a6 fromager: avoid http retry backoffs in sandbox
When running test suite under darwin sandbox, some tests fetch an
invalid http url. They assume the request will immediately return, but
instead in sandbox the http library retries with backoff.

Setting FROMAGER_HTTP_RETRIES=0 cuts backoffs short.
2026-09-27 15:00:17 -04:00
R. Ryantm
75ad98eeec radicle-explorer: 0-unstable-2026-09-14 -> 0-unstable-2026-09-25 2026-09-27 18:59:17 +00:00
Martin Weinelt
1cf7c44860 home-assistant-custom-lovelace-modules.multiple-entity-row: 4.11.1 -> 4.12.0
https://github.com/benct/lovelace-multiple-entity-row/blob/v4.12.0/CHANGELOG.md
2026-09-27 20:53:56 +02:00
Vladimír Čunát
bf5dbda6fd Merge branch 'staging-nixos' into staging-next 2026-09-27 20:52:34 +02:00
R. Ryantm
23143fdb48 eilmeldung: 1.8.1 -> 1.9.0 2026-09-27 18:51:02 +00:00
Jo
bea544dcf6 chromaprint: adopt (#567525) 2026-09-27 18:49:51 +00:00
Martin Weinelt
0f35f41ec0 home-assistant-custom-components.opendisplay: 2.0.2 -> 3.0.2
https://github.com/OpenDisplay/Home_Assistant_Integration/blob/3.0.2/CHANGELOG.md
2026-09-27 20:48:24 +02:00
Martin Weinelt
61f063af52 python3Packages.odl-renderer: init at 0.5.12
New dependency for the home-assistant opendisplay stack.
2026-09-27 20:48:23 +02:00
Fabian Affolter
372b3edfb3 essh: 0.4.0 -> 0.4.1 (#567339) 2026-09-27 18:46:38 +00:00
Fabian Affolter
6a46d06d83 python3Packages.asyncmy: 0.2.14 -> 0.2.15 (#567352) 2026-09-27 18:46:12 +00:00
Fabian Affolter
ff5b8c7908 trufflehog: 3.97.5 -> 3.97.9 (#567369) 2026-09-27 18:45:41 +00:00
Fabian Affolter
f2d32213fa python3Packages.aqualogic: 3.10 -> 3.11 (#567417) 2026-09-27 18:45:10 +00:00
R. Ryantm
6d8ca52a2a badness: 0.23.0 -> 0.24.0 2026-09-27 18:44:49 +00:00
Fabian Affolter
39f4eb7557 gvm-libs: 23.10.1 -> 23.11.0 (#567498) 2026-09-27 18:44:18 +00:00
Fabian Affolter
77fcd98bc3 python3Packages.iamdata: 0.1.202609261 -> 0.1.202609271
Diff: https://github.com/cloud-copilot/iam-data-python/compare/v0.1.202609261...v0.1.202609271

Changelog: https://github.com/cloud-copilot/iam-data-python/releases/tag/v0.1.202609271
2026-09-27 20:43:52 +02:00
Fabian Affolter
1a19694357 python3Packages.pydrawise: 2026.9.0 -> 2026.9.1 (#567516) 2026-09-27 18:43:32 +00:00
nixpkgs-ci[bot]
a7b9dc31fc umap: 3.7.3 -> 3.8.1 (#567180) 2026-09-27 18:43:27 +00:00
Fabian Affolter
3773e97d11 user-scanner: 1.5.1 -> 1.5.2 (#567535) 2026-09-27 18:43:08 +00:00
R. Ryantm
524fad3dc6 torrserver: 144.4 -> 145 2026-09-27 18:39:27 +00:00
dish
9ef5a9556b nixos/noctalia: Add freedesktop sound theme dep
Needed for 5.2.0 release, only a runtime dep so we don't add it to the
package
2026-09-27 14:26:22 -04:00
nixpkgs-ci[bot]
aae36d7f43 streamlink: 8.6.0 -> 8.6.1 (#566669) 2026-09-27 18:25:45 +00:00
dish
8762008071 noctalia-greeter: 1.5.0 -> 1.6.0 2026-09-27 14:20:27 -04:00
dish
d17ed31304 noctalia: 5.1.0 -> 5.2.0
https://noctalia.dev/changelogs#v5.2.0
2026-09-27 14:20:20 -04:00
Martin Weinelt
63b99ccb68 python3Packages.resize-image: init at 0.4.0
New dependency for odl-renderer, for opendisplay stack in home-assistant.
2026-09-27 20:18:24 +02:00
Thomas Gerbet
3965f24eff glpi-agent: 1.19 -> 1.20 (#567446) 2026-09-27 18:16:07 +00:00
R. Ryantm
9f523f77d9 folia-major: 0.7.7 -> 0.7.9 2026-09-27 18:14:39 +00:00
nixpkgs-ci[bot]
f709d88f54 Merge master into staging-nixos 2026-09-27 18:11:52 +00:00
eljamm
e03295e588 nwjs: 0.115.0 -> 0.117.0 2026-09-27 20:11:38 +02:00
eljamm
b4b6fca9c1 nwjs: refactor sources; use finalAttrs & add update script 2026-09-27 20:11:38 +02:00
nixpkgs-ci[bot]
56b01df19d Merge staging-next into staging 2026-09-27 18:11:19 +00:00
nixpkgs-ci[bot]
db0fb78f53 Merge master into staging-next 2026-09-27 18:10:35 +00:00
Martin Weinelt
8da3379959 home-assistant-custom-components.meshcore: 2.8.0 -> 2.10.0
https://github.com/meshcore-dev/meshcore-ha/releases/tag/v2.9.0
https://github.com/meshcore-dev/meshcore-ha/releases/tag/v2.10.0
2026-09-27 20:04:20 +02:00
Sandro
e0631e1eac blender-oneapi: init (#541907) 2026-09-27 18:02:12 +00:00
Maximilian Bosch
6bd2c4ab75 nginxStable: remove rtmp as default module (#567484) 2026-09-27 18:02:07 +00:00
nixpkgs-ci[bot]
98001a40b7 exa-agent-skills: 2026.09.16-73cc4b0 -> 2026.09.17-e27a85c (#567568) 2026-09-27 18:00:36 +00:00
Maximilian Bosch
c6636cbbd8 nginxMainline: use openssl_4 to support ECH (#567475) 2026-09-27 18:00:31 +00:00
Ihar Hrachyshka
aaa8dc2b4b podman-desktop: ignore pre-releases 2026-09-27 13:59:33 -04:00
R. Ryantm
b0e2067459 wiki-go: 1.9.1 -> 1.9.2 2026-09-27 17:59:19 +00:00
Linnea Gräf
386fb1a5c8 httpstat: fix version detection in setup.py 2026-09-27 19:56:43 +02:00
Martin Weinelt
edd8637d47 home-assistant-custom-components.localthings: 0.26.1 -> 0.29.0
https://github.com/mbillow/localthings/releases/tag/v0.27.0
https://github.com/mbillow/localthings/releases/tag/v0.28.0
https://github.com/mbillow/localthings/releases/tag/v0.28.1
https://github.com/mbillow/localthings/releases/tag/v0.29.0
2026-09-27 19:53:23 +02:00
Sandro
c4ab5fe26e bibata-caelestia: init at 0-unstable-2026-09-05 (#564814) 2026-09-27 17:52:56 +00:00
nixpkgs-ci[bot]
ae1e34a673 bootdev-cli: 1.32.4 -> 1.32.5 (#567533) 2026-09-27 17:51:22 +00:00
Martin Weinelt
145793a239 python3Packages.smartthings-local: 0.1.16 -> 0.1.20
https://github.com/QuiteYellow/SmartThings-Local/releases/tag/v0.1.20
2026-09-27 19:48:23 +02:00
J0schu
7316a726db maintainers: add J0schu 2026-09-27 19:42:46 +02:00
R. Ryantm
10818c166f dae: 2.0.0 -> 2.1.1 2026-09-27 17:42:25 +00:00
Martin Weinelt
cbffad69d4 home-assistant-custom-components.elegoo_printer: 2.12.2 -> 2.13.1
https://github.com/danielcherubini/elegoo-homeassistant/releases/tag/v2.13.0
https://github.com/danielcherubini/elegoo-homeassistant/releases/tag/v2.13.1
2026-09-27 19:40:29 +02:00
Yt
a702bebce2 grpc: 1.83.1 -> 1.84.0 (#567560) 2026-09-27 17:34:15 +00:00
Martin Weinelt
384d301e77 home-assistant-custom-components.econet300: 1.3.2 -> 1.3.3
https://github.com/jontofront/ecoNET-300-Home-Assistant-Integration/releases/tag/v1.3.3

Now licensed under MIT.
2026-09-27 19:33:24 +02:00
adisbladis
e3f4c7ed04 python3Packages.selfies: init at 2.2.0 (#558766) 2026-09-27 17:30:36 +00:00
Martin Weinelt
86d0b0f97c home-assistant-custom-components.blueprints-updater: 2.14.6 -> 2.15.0
https://github.com/luuquangvu/blueprints-updater/releases/tag/2.15.0
2026-09-27 19:30:20 +02:00
J0schu
5a4557d5cb vivaldi: 8.2.4133.52 -> 8.2.4133.76 2026-09-27 19:26:39 +02:00
R. Ryantm
fac6643e84 exa-agent-skills: 2026.09.16-73cc4b0 -> 2026.09.17-e27a85c 2026-09-27 17:25:55 +00:00
Martin Weinelt
0f42ed50fc home-assistant-custom-lovelace-modules.tankerkoenig-card: 1.8.2 -> 1.9.0
https://github.com/timmaurice/lovelace-tankerkoenig-card/releases/tag/1.9.0
2026-09-27 19:25:14 +02:00
Martin Weinelt
674d68f76a home-assistant-custom-lovelace-modules.meshcore-card: 1.0.0 -> 0.4.3
https://github.com/jpettitt/meshcore-card/releases/tag/v0.4.3
2026-09-27 19:25:14 +02:00
Martin Weinelt
ca3dcde94d home-assistant-custom-lovelace-modules.clock-weather-card: 2.9.4 -> 2.9.5
https://github.com/pkissling/clock-weather-card/blob/v2.9.5/CHANGELOG.md
2026-09-27 19:25:13 +02:00
Martin Weinelt
3d4655507b home-assistant-custom-components.powercalc: 1.25.4 -> 1.26.0
https://github.com/bramstroker/homeassistant-powercalc/releases/tag/v1.26.0
2026-09-27 19:25:13 +02:00
Martin Weinelt
a31999357b home-assistant-custom-lovelace-modules.bubble-card: 3.4.0 -> 3.4.1
https://github.com/Clooos/bubble-card/releases/tag/v3.4.1
2026-09-27 19:25:13 +02:00
Martin Weinelt
d7e7cfaf3b home-assistant-custom-components.versatile_thermostat: 10.1.0 -> 10.4.0
https://github.com/jmcollin78/versatile_thermostat/releases/tag/10.4.0
2026-09-27 19:25:13 +02:00
Martin Weinelt
017c1afdf2 home-assistant-custom-components.tuya_local: 2026.9.1 -> 2026.9.2-rel
https://github.com/make-all/tuya-local/releases/tag/2026.9.2-rel
2026-09-27 19:25:12 +02:00
Martin Weinelt
8446f2f758 home-assistant-custom-components.spook: 5.5.0 -> 5.5.1
https://github.com/frenck/spook/releases/tag/v5.5.1
2026-09-27 19:25:12 +02:00
Martin Weinelt
c2aad66285 home-assistant-custom-components.solax_modbus: 2026.09.2 -> 2026.09.3
https://github.com/wills106/homeassistant-solax-modbus/releases/tag/2026.09.3
2026-09-27 19:25:12 +02:00
Martin Weinelt
da8964a146 home-assistant-custom-components.simple_pid_controller: 1.6.0 -> 1.6.1
https://github.com/bvweerd/simple_pid_controller/releases/tag/v1.6.1
2026-09-27 19:25:12 +02:00
Martin Weinelt
d558edfc99 home-assistant-custom-components.octopus_energy: 19.1.0 -> 19.2.1
https://github.com/BottlecapDave/HomeAssistant-OctopusEnergy/releases/tag/v19.2.1
2026-09-27 19:25:11 +02:00
Martin Weinelt
fcfe155a42 home-assistant-custom-components.openai-tts: 3.9.1 -> 3.9.2
https://github.com/sfortis/openai_tts/releases/tag/v3.9.2
2026-09-27 19:25:11 +02:00
Martin Weinelt
36ed951d7f home-assistant-custom-components.cover_time_based: 4.11.0 -> 4.13.0
https://github.com/Sese-Schneider/ha-cover-time-based/blob/v4.13.0/CHANGELOG.md
2026-09-27 19:25:11 +02:00
Martin Weinelt
25045bd88a home-assistant-custom-components.versatile_thermostat: 10.1.0 -> 10.4.0 (#567524) 2026-09-27 17:23:43 +00:00
Leonard Sheng Sheng Lee
73f75429dd codex-security: init at 0.1.31
Package `@openai/codex-security`, the OpenAI Codex Security command
line interface and TypeScript software development kit for finding,
validating, and fixing security vulnerabilities in source code. Build
it from the `sdk/typescript` subdirectory with pnpm 11 and TypeScript.

Use the matching npm release for the prepacked plugin bundle that is
absent from the source tag. Remove non-host plugin and Android binaries
instead of suppressing missing dependency checks globally.

Assisted-by: GitHub Copilot CLI (GPT-5.6 Terra)
Signed-off-by: Leonard Sheng Sheng Lee <leonard.sheng.sheng.lee@gmail.com>
2026-09-27 19:20:04 +02:00
Zebreus
e48203435d autopsy: 4.22.1 -> 4.23.1
Assisted-by: claude-code with claude opus 5.5
2026-09-27 19:14:41 +02:00
Zebreus
09082a4274 sleuthkit: 4.14.0 -> 4.15.0
Both gcc 15 patches are included in this release.

Assisted-by: claude-code with claude opus 5.5
2026-09-27 19:14:41 +02:00
jopejoe1
45aacc1680 discord: update various
discord-canary: 1.0.1950 -> 1.0.2010
discord-development: 1.0.1011 -> 1.0.1012
discord-ptb: 1.0.215 -> 1.0.216
discord: 1.0.158 -> 1.0.159
pkgsCross.aarch64-darwin.discord-canary: 0.0.1338 -> 0.0.1345
pkgsCross.aarch64-darwin.discord-development: 1.0.1022 -> 1.0.1023
pkgsCross.aarch64-darwin.discord-ptb: 0.0.261 -> 0.0.262
pkgsCross.aarch64-darwin.discord: 0.0.412 -> 0.0.413
2026-09-27 19:07:56 +02:00
Martin Weinelt
1ec6be517a home-assistant.python3Packages.pytest-homeassistant-custom-component: 0.13.366 -> 0.13.367
https://github.com/MatthewFlamm/pytest-homeassistant-custom-component/blob/0.13.367/CHANGELOG.md
2026-09-27 19:05:57 +02:00
Martin Weinelt
15625e1f3d python3Packages.homeassistant-stubs: 2026.9.3 -> 2026.9.4
https://github.com/KapJI/homeassistant-stubs/releases/tag/2026.9.4
2026-09-27 19:05:17 +02:00
Jan Tojnar
e2113362f4 gnome{38,40,41,42,43,44,45,46,47}Extensions: drop (#567532) 2026-09-27 16:51:05 +00:00
scraptux
3f96e47753 python3Packages.grpcio-tools: 1.83.1 -> 1.84.0 2026-09-27 18:49:16 +02:00
scraptux
d70bc9a4f9 python3Packages.grpcio-testing: 1.83.1 -> 1.84.0 2026-09-27 18:49:14 +02:00
scraptux
cb9818dfd5 python3Packages.grpcio-status: 1.83.1 -> 1.84.0 2026-09-27 18:49:13 +02:00
scraptux
7da1ce38d9 python3Packages.grpcio-reflection: 1.83.1 -> 1.84.0 2026-09-27 18:49:12 +02:00
scraptux
68522d5b07 python3Packages.grpcio-health-checking: 1.83.1 -> 1.84.0 2026-09-27 18:49:10 +02:00
scraptux
503797daf0 python3Packages.grpcio-channelz: 1.83.1 -> 1.84.0 2026-09-27 18:49:09 +02:00
scraptux
5e9af01ff4 python3Packages.grpcio: 1.83.1 -> 1.84.0 2026-09-27 18:49:07 +02:00
scraptux
5a54998d1d grpc: 1.83.1 -> 1.84.0 2026-09-27 18:49:05 +02:00
scraptux
5b93833a9c vscode-extensions.sas.sas-lsp: 1.20.0 -> 1.21.0 2026-09-27 18:46:35 +02:00
Sandro
bacb5de9b9 marktext: 0.17.0-unstable-2025-11-19 -> 0.19.1 (migrating from yarn to pnpm) (#550608) 2026-09-27 16:39:48 +00:00
nixpkgs-ci[bot]
dbe2d7a68a ctx7: 0.5.10 -> 0.5.12 (#567544) 2026-09-27 16:36:01 +00:00
Martin Weinelt
aad72e3ade home-assistant: 2026.9.3 -> 2026.9.4
https://github.com/home-assistant/core/releases/tag/2026.9.4
2026-09-27 18:34:59 +02:00
Martin Weinelt
dd12c33113 python3Packages.pyenphase: 4.0.5 -> 4.0.6
https://github.com/pyenphase/pyenphase/blob/v4.0.6/CHANGELOG.md
2026-09-27 18:34:35 +02:00
Martin Weinelt
f29f851521 python3Packages.imgw-pib: 2.5.1 -> 2.5.2
https://github.com/bieniu/imgw-pib/releases/tag/2.5.2
2026-09-27 18:33:51 +02:00
R. Ryantm
2c48a5e227 python3Packages.exa-py: 2.21.0 -> 2.23.0 2026-09-27 16:26:46 +00:00
Vladimír Čunát
e24256eb40 julia: fix build with glibc 2.44 (#566255) 2026-09-27 16:26:21 +00:00
nixpkgs-ci[bot]
9698c1419a ecspresso: 2.8.6 -> 2.8.7 (#567528) 2026-09-27 16:23:57 +00:00
whispers
63699c9932 imlib2: 1.12.6 -> 1.12.7 (#558538) 2026-09-27 16:16:08 +00:00
R. Ryantm
04733f52e6 ctx7: 0.5.10 -> 0.5.12 2026-09-27 16:09:23 +00:00
Yt
6b59be98c8 stalwart_0_16: 0.16.22 -> 0.16.23 (#566142) 2026-09-27 16:02:48 +00:00
Bobby Rong
ec49a815e6 elementary-xfce-icon-theme: 0.22 -> 0.23 (#567526) 2026-09-27 15:59:46 +00:00
Matt Sturgeon
8c8a1dcbab doc/readme: Clarify variable literals (#567409) 2026-09-27 15:54:53 +00:00
nixpkgs-ci[bot]
cd370a248c colloid-cursors: 2025-07-19 -> 2026-08-10 (#554908) 2026-09-27 15:51:50 +00:00
Sandro
6cc971939d python3Packages.scienceplots: 2.1.1 -> 2.2.2 (#552741) 2026-09-27 15:51:41 +00:00
R. Ryantm
063d5391a0 clifm: 1.28 -> 1.29 2026-09-27 15:50:51 +00:00
Winter
f1e207dd38 wasm-tools: use nextest (#567465) 2026-09-27 15:49:37 +00:00
Matt Sturgeon
5188f6aaaa doc/readme: Minor tweaks (#567442) 2026-09-27 15:46:48 +00:00
nixpkgs-ci[bot]
1c9f28a663 freescout: 1.8.235 -> 1.8.241 (#556331) 2026-09-27 15:42:27 +00:00
Sandro
4295fb8fac pgcli: 4.6.0 -> 4.7.1 (#567251) 2026-09-27 15:40:51 +00:00
Diogo Correia
c5fa074b95 python3Packages.covdefaults: init at 2.3.0 (#567494) 2026-09-27 15:38:32 +00:00
Ihar Hrachyshka
f9040d8353 various: inline meta.homepage in src url (#565396) 2026-09-27 15:36:22 +00:00
Yohann Boniface
c47d92f7b5 python3Packages.crcmod: migrate to pyproject (#561573) 2026-09-27 15:35:23 +00:00
Yohann Boniface
85c9ac62a0 fable: fix changelog link (#567523) 2026-09-27 15:33:12 +00:00
Sandro
d344437491 changedetection-io: qualify Playwright container image (#561219) 2026-09-27 15:29:27 +00:00
Timo Gottszky
d80c44994b python3Packages.pyexiv2: fix build 2026-09-27 17:29:26 +02:00
Vladimír Čunát
46b72ad79c Merge master into staging-next 2026-09-27 17:27:07 +02:00
Antonio Spadaro
ff11fa1628 python3Packages.covdefaults: init at 2.3.0
It is going to be required by the check phase of the upcoming version of `datamodel-code-generator`.

Co-authored-by: Diogo Correia <me@diogotc.com>
2026-09-27 17:26:38 +02:00
Grimmauld
0c1fcfb1f2 libcamera: refactor mesonFlags and other improvements (#553394) 2026-09-27 15:24:32 +00:00
Tom Hunze
7d15903f68 gnomeExtensions: update for 2026-09-27
This reduces the size of `extensions.json` by ~6M.
2026-09-27 17:21:30 +02:00
Tom Hunze
9af9a16e00 gnome{38,40,41,42,43,44,45,46,47}Extensions: drop
These are extensions for historical versions of GNOME shell. Apparently
nobody ever removed these.
2026-09-27 17:21:20 +02:00
R. Ryantm
5ae6a3f73d python3Packages.mammoth: 1.12.2 -> 1.13.0 2026-09-27 15:18:13 +00:00
Mirza Arnaut
fdc3396349 nixos/beszel.agent: only allow /dev/zfs for zfs monitoring
The zfs commands only need the control device, so list it in
DeviceAllow instead of disabling PrivateDevices, as syncoid does.
PrivateUsers still has to go: zfs commands fail inside a user
namespace since zfs 2.2.
2026-09-27 17:13:52 +02:00
Vladimír Čunát
0b867cf7b6 [staging-next] uhd: 4.10.0.0 -> 4.11.0.0 (#566730) 2026-09-27 15:13:36 +00:00
R. Ryantm
bec1801793 user-scanner: 1.5.1 -> 1.5.2 2026-09-27 15:11:17 +00:00
Diogo Correia
526afc0ff2 pcsclite: fix pcsc-spy interpreter (#560165) 2026-09-27 15:10:00 +00:00
Leona Maroni
34b9e21553 themes: drop (#567527) 2026-09-27 15:04:11 +00:00
Sandro
d21e46039f chunkfs: port to fuse 3 (#564203) 2026-09-27 15:02:13 +00:00
Antonio Spadaro
545f85b20c maintainers: add ilovelinux 2026-09-27 17:02:05 +02:00
nixpkgs-ci[bot]
013163e6fa prl-tools: 27.0.1-58670 -> 27.0.2-58673 (#566726) 2026-09-27 15:00:46 +00:00
R. Ryantm
46389b253b bootdev-cli: 1.32.4 -> 1.32.5 2026-09-27 14:58:34 +00:00
jopejoe1
e522bc1377 themes: drop 2026-09-27 16:57:46 +02:00
Grimmauld
4ee904e535 unifiedpush-common-proxies: rename to common-proxies (#567500) 2026-09-27 14:56:14 +00:00
Mirza Arnaut
511fbd206e nixos/tests/beszel: check sandboxing and GPU collector wiring
The test VM has no GPU, but the effect of the collectors on the
generated unit can still be checked: add specialisations that are only
inspected, never activated, and assert the sandbox settings, device
access and capabilities they produce.
2026-09-27 16:55:19 +02:00
Mirza Arnaut
6c9cfec111 nixos/beszel.agent: expose GPU_COLLECTOR and refactor around it
Describe the supported GPU collectors in a single table and derive the
service path, capabilities, syscall filter and device access from it.

PrivateDevices is only relaxed when a selected collector actually needs
device nodes, and the nodes are listed in DeviceAllow so /dev stays an
allow-list, following the same pattern as ollama and the smartctl
exporter. PrivateUsers only has to go when a collector needs
capabilities, which are void on the host inside a user namespace; plain
device access (nvidia-smi) keeps it. When smartmon relies on full /dev
access no DeviceAllow is emitted at all, since any entry would turn
DevicePolicy=auto into an allow-list and lock the disks out.

amdgpu now defaults to amd_sysfs and intel to intel_sysfs (new in
beszel 0.20.0). Both read sysfs directly and need neither a package nor
/dev access; rocm-smi is deprecated upstream and intel_gpu_top is not
used on the xe driver. An
empty GPU_COLLECTOR is not exported, keeping upstream auto-detection.

GPU_COLLECTOR still accepts upstream's comma-separated string, which is
how it had to be set through the freeform environment until now.
2026-09-27 16:55:18 +02:00
Mirza Arnaut
cefee7ffe5 nixos/beszel.agent: fix GPU monitoring and expose SKIP_GPU
When `PrivateDevices=true`, systemd mounts an isolated `/dev` namespace,
blocking access to physical hardware nodes (like `/dev/nvidia0` or
`/dev/dri/`). This broke the agent's ability to collect GPU metrics out
of the box unless `smartmon` happened to be enabled.

This commit exposes the upstream `SKIP_GPU` environment variable in the
module's environment submodule (defaulting to `false` to match upstream
behavior) and uses it to conditionally toggle systemd sandboxing.

`PrivateDevices` are now disabled by default to allow hardware
observability, but will tightly sandbox the service if both
`smartmon.enable = false` and `environment.SKIP_GPU = true`.

Additionally, when `SKIP_GPU = true`, hardware diagnostic tools (e.g.,
`nvidia-smi`, `intel-gpu-tools`) are excluded from the service's `path`.
This trims unused packages from the system closure, saving disk space
when GPU monitoring is explicitly disabled.
2026-09-27 16:55:00 +02:00
Vladimír Čunát
40d49c8f53 [staging-next] folly: disable failing test with gcc 16 (#567521) 2026-09-27 14:50:47 +00:00
R. Ryantm
a81dfb0622 ecspresso: 2.8.6 -> 2.8.7 2026-09-27 14:49:06 +00:00
R. Ryantm
3eb669ab9d doublecmd: 1.2.8 -> 1.2.9 2026-09-27 14:48:31 +00:00
quantenzitrone
291a353230 chromaprint: adopt 2026-09-27 16:44:32 +02:00
quantenzitrone
b3325227be chromaprint: removed unused package function argument 2026-09-27 16:43:54 +02:00
R. Ryantm
8afd4234db elementary-xfce-icon-theme: 0.22 -> 0.23 2026-09-27 14:43:49 +00:00
nixpkgs-ci[bot]
d4e00cc559 kubectl: 1.37.0 -> 1.37.1 (#567303) 2026-09-27 14:42:43 +00:00
R. Ryantm
8d807540aa home-assistant-custom-components.versatile_thermostat: 10.1.0 -> 10.4.0 2026-09-27 14:40:41 +00:00
Sandro
633425cec1 px0: init at 0.1.4 (#564141) 2026-09-27 14:36:05 +00:00
whispers
af867e9b1e folly: disable failing test with gcc 16
this test is failing because it attempts to bound on the range of random
numbers. gcc 16 changes the implementation of std::generate_canonical to
match P0952R2, which changes properties of the observed random output.
folly bounds closely on these distribution properties, causing failures
with this new implementation. this thus disables the suite of tests that
check the random distributions in this way.

an alternative would be to build folly with
`-D_GLIBCXX_USE_OLD_GENERATE_CANONICAL` to opt-out of this behavior, but
given that this is somewhat fragile in general, it seems fine to just
disable this suite of tests.
2026-09-27 10:33:07 -04:00
mdarocha
cb8ead5730 fable: fix changelog link 2026-09-27 16:32:42 +02:00
Dmitry Kalinkin
15c78dc95e yoda: 2.1.2 -> 2.1.4 (#567381) 2026-09-27 14:29:53 +00:00
Thomas
cecc2cd1f1 Zabbix70: 7.0.30 -> 7.0.31 2026-09-27 16:26:54 +02:00
Vladimír Čunát
c173c24144 thunderbird-latest-unwrapped: 156.0 -> 156.0.1 (#567493) 2026-09-27 14:26:39 +00:00
R. Ryantm
31ec9cb669 aptakube: 1.20.4 -> 1.20.5 2026-09-27 14:26:15 +00:00
Thomas
04c5d96a63 zabbix74: 7.4.14 -> 7.4.15 2026-09-27 16:24:18 +02:00
nixpkgs-ci[bot]
568ef1dab4 defuddle: 0.19.3 -> 0.19.4 (#567366) 2026-09-27 14:20:10 +00:00
Matt Sturgeon
9258beb378 treefmt.withConfig: minor check drv improvements (#567512) 2026-09-27 14:18:30 +00:00
R. Ryantm
3ca15d4f78 python3Packages.motioneye-client: 0.3.14 -> 0.4.1 2026-09-27 14:18:08 +00:00
R. Ryantm
c033d66d54 python3Packages.pydrawise: 2026.9.0 -> 2026.9.1 2026-09-27 14:18:02 +00:00
Jan Tojnar
b5812ab110 gnome-shell: refresh icons after profile switches (#561029) 2026-09-27 14:16:08 +00:00
Jan Tojnar
9af913beb5 glib: watch XDG state profiles for application changes (#561023) 2026-09-27 14:15:47 +00:00
Jan Tojnar
cf32bc79da xdg-utils: patch out qtpaths runtime dependency (#488769) 2026-09-27 14:14:08 +00:00
Pol Dellaiera
d81c381e3e treefmt.withConfig: use gitSetupHook 2026-09-27 16:09:25 +02:00
Pol Dellaiera
1edf6e8f32 treefmt.withConfig: replace stdenv with stdenvNoCC 2026-09-27 16:09:25 +02:00
Pavol Rusnak
c04bfcc043 trezor-suite: 26.8.2 -> 26.9.2 (#566705) 2026-09-27 14:08:09 +00:00
Matthieu Coudron
2298a3cabd subnetcalc: 2.6.6 -> 2.7.5 (#565723) 2026-09-27 14:06:08 +00:00
Wolfgang Walther
f787845479 orioledb: 1.9-beta17 -> 1.10beta18 (#567501) 2026-09-27 14:04:44 +00:00
Matthieu Coudron
5ab674d8a5 treewide: fix homepages [4/10] (#566992) 2026-09-27 14:02:53 +00:00
zimward
cb09c5dff9 common-proxies: use correct homepage url 2026-09-27 16:01:33 +02:00
zimward
d6ee554cf6 unifiedpush-common-proxies: rename to common-proxies 2026-09-27 16:01:14 +02:00
Michele Guerini Rocco
3a52bd6031 wpa_supplicant: re-add erroneously dropped patch (#567010) 2026-09-27 13:57:20 +00:00
Matthieu Coudron
eb245531a7 treewide: fix homepages [7/10] (#567134) 2026-09-27 13:56:22 +00:00
Jo
333eadd9a5 python313Packages.notobuilder: 0-unstable-2026-06-26 -> 0-unstable-2026-09-24 (#567396) 2026-09-27 13:51:11 +00:00
Jan Tojnar
afdf031a91 xdg-utils: refactor (#567481) 2026-09-27 13:50:17 +00:00
Sandro
df90a044ff zulip: 5.13.1 → 5.13.2 (#565488) 2026-09-27 13:50:12 +00:00
Sandro
3e08891600 nixos/beszel-agent: enable zfs monitoring support (#566007) 2026-09-27 13:49:54 +00:00
Sandro
802cc4a532 python3Packages.pdf2image: patch remaining poppler_path defaults (#563612) 2026-09-27 13:48:45 +00:00
Sandro
d0b6ef39ae python3Packages.detect-secrets: disable tests for optional dependencies (#544215) 2026-09-27 13:48:25 +00:00
oddlama
90e4b90657 homebox: better test and tmpdir resolution (#481321) 2026-09-27 13:44:58 +00:00
Wolfgang Walther
ed3828dc95 postgresqlBuildExtension, buildPgrxExtension: enable __structuredAttrs (#566600) 2026-09-27 13:38:48 +00:00
Florian
33e1e4cac4 zabbix{60,70,74}.plugins.{ember-plus,mongodb,mssql,postgresql}: Init (#567440) 2026-09-27 13:38:30 +00:00
Akira Komamura
dd6cdf3947 ocamlPackages.capnp-rpc-net: init at 2.1.2-unstable-2026-09-13
Co-authored-by: StepBroBD <ysun@duck.com>
2026-09-27 22:33:37 +09:00
zowoq
637d421348 terraform-providers.hashicorp_google-beta: 8.3.0 -> 8.4.0 (#567414) 2026-09-27 13:32:41 +00:00
zowoq
875f43ab1f terraform-providers.aiven_aiven: 4.62.0 -> 4.63.0 (#567412) 2026-09-27 13:32:37 +00:00
nixpkgs-ci[bot]
ca95461e58 libvlc: 3.0.23-2 -> 3.0.24 (#566126) 2026-09-27 13:31:42 +00:00
Patrick
dbb6b83464 nixos/homebox: use fileblob options instead of moving TMPDIR 2026-09-27 15:23:23 +02:00
Patrick
d152c92d27 nixosTests.homebox: Add test to ensure item creation and attachment upload work
Assisted-by: pi (GPT-5.6 Sol)
2026-09-27 15:23:23 +02:00
Alexandre Esteves
bedf38b33b haskellPackages: fix a lot of failures with Darwin sandbox (#513476) 2026-09-27 13:22:37 +00:00
R. Ryantm
33f51d1d07 gvm-libs: 23.10.1 -> 23.11.0 2026-09-27 13:22:34 +00:00
R. Ryantm
ed1b00faee gogup: 1.9.3 -> 1.10.2 2026-09-27 13:21:54 +00:00
nixpkgs-ci[bot]
da0c9a9cb7 cargo-tarpaulin: 0.37.2 -> 0.37.5 (#567410) 2026-09-27 13:19:44 +00:00
Wolfgang Walther
cab4b5b057 orioledb: 1.9-beta17 -> 1.10beta18
Release Notes:
https://github.com/orioledb/orioledb/releases/tag/beta18
2026-09-27 15:14:36 +02:00
R. Ryantm
0de64f1354 thunderbird-latest-unwrapped: 156.0 -> 156.0.1 2026-09-27 13:12:54 +00:00
whoomee
2cb012041b libcamera: re-enable lc-compliance
The comment specifying that it doesn't work is not applicable anymore.
2026-09-27 15:09:34 +02:00
whoomee
97b876dfe0 libcamera: refactor mesonFlags 2026-09-27 15:09:34 +02:00
whoomee
bfbfe2f22c libcamera: specify and test meta.pkgConfigModules 2026-09-27 15:09:34 +02:00
whoomee
7a74f484f1 libcamera: add maintainer tmarkus 2026-09-27 15:09:34 +02:00
whoomee
591fd53448 libcamera: switch to fetchFromGitLab
Using fetchFromGitLab allows nix-update to autodetect the latest
version.
2026-09-27 15:09:33 +02:00
Toma
1764aa3453 rofi-games: 1.18.0 -> 1.19.0 (#567457) 2026-09-27 13:07:34 +00:00
Sandro
8634f4eb7d nixos/nix: move nix.nixPath into nix.settings.nix-path (#336545) 2026-09-27 13:07:10 +00:00
Pol Dellaiera
864eb18daf hunk: 0.21.1 -> 0.22.0 (#567355) 2026-09-27 13:05:51 +00:00
Leona Maroni
4575de1b7c nginxStable: remove rtmp as default module
Having `rtmp` as default module only in `nginxStable` seems like an odd
choice. Users likely expect that nginxStable and nginxMainline behave
equal in this regard.

It's unclear, why rtmp is in our default nginx, it's there since at least
2015[^1] and I couldn't find any reason why. It's also unmaintained with
its last release being made in 2021[^2].

[^1]: see 9424238d14
[^2]: https://github.com/arut/nginx-rtmp-module/tags
2026-09-27 15:04:19 +02:00
R. Ryantm
bd6c292e3d skills: 1.6.0 -> 1.7.0 2026-09-27 13:01:42 +00:00
nixpkgs-ci[bot]
675e21e47f xremap: 0.15.13 -> 0.15.14 (#567470) 2026-09-27 12:50:14 +00:00
nixpkgs-ci[bot]
90597df1f3 wavelog: 3.2.2 -> 3.2.3 (#567353) 2026-09-27 12:50:08 +00:00
Thomas
ce0b5f2533 Maintainers: Add thelolcoder2007 2026-09-27 14:46:49 +02:00
Thomas
61f0df8834 zabbix{60,70,74}.plugins.{ember-plus,mongodb,mssql,nviaid-gpu,postgresql}: Init 2026-09-27 14:44:38 +02:00
whoomee
82a6d6b246 xdg-utils: add versionCheckHook 2026-09-27 14:44:13 +02:00
whoomee
bd648f1b7b xdg-utils: specify downloadPage/changelog 2026-09-27 14:44:13 +02:00
R. Ryantm
b9e7e1fd70 poetryPlugins.poetry-plugin-export: 1.10.0 -> 1.10.1 2026-09-27 12:41:59 +00:00
Maximilian Bosch
46adb4465a epson-escpr2: 1.2.37 -> 1.2.42 (#565986) 2026-09-27 12:41:23 +00:00
Jonas Heinrich
8ce371ed06 euro-office-desktopeditors: init at 9.3.1-dev.1 (#536503) 2026-09-27 12:36:17 +00:00
whoomee
e098f8d329 xdg-utils: patch out qtpaths runtime dependency 2026-09-27 14:35:14 +02:00
Leona Maroni
8564b7572e nginxMainline: use openssl_4 to support ECH
ECH is only supported in OpenSSL >=4.0,
https://openssl-library.org/post/2026-03-11-ech/index.html

We already use openssl_4 for nginxStable
2026-09-27 14:32:48 +02:00
nixpkgs-ci[bot]
66042f6dab shelter: 0-unstable-2026-09-06 -> 0-unstable-2026-09-16 (#567284) 2026-09-27 12:31:27 +00:00
Maximilian Bosch
a34dc34d8c nixos/tests/systemd-shutdown: Test pre-exitrd shutdown scripts (#565136) 2026-09-27 12:29:35 +00:00
R. Ryantm
e49d7754e0 grafanaPlugins.grafana-exploretraces-app: 2.2.0 -> 2.2.1 2026-09-27 12:26:49 +00:00
R. Ryantm
5ef9cb9b4a xremap: 0.15.13 -> 0.15.14 2026-09-27 12:24:52 +00:00
Sandro
4c00ff2cb2 moonshine: 0.16.0 -> 0.16.1 (#563172) 2026-09-27 12:22:01 +00:00
Sandro
e8fddb171a doublecmd: fix lua support (#465246) 2026-09-27 12:21:31 +00:00
nixpkgs-ci[bot]
7c497bd138 Merge master into staging-nixos 2026-09-27 12:14:24 +00:00
nixpkgs-ci[bot]
80074c3b67 Merge staging-next into staging 2026-09-27 12:13:48 +00:00
nixpkgs-ci[bot]
5ec9cbdac1 Merge master into staging-next 2026-09-27 12:13:16 +00:00
Leona Maroni
811a2ab081 python3Packages.pyfribidi: drop (#567448) 2026-09-27 12:10:35 +00:00
Jo
dec5c85294 libeconf: fix darwin, add pkg-config and cpe to meta (#567451) 2026-09-27 12:09:26 +00:00
Winter
7c6ef8366c wasm-tools: use nextest
Has a lot of tests in a lot of different crates that run very quickly.
2026-09-27 14:05:02 +02:00
Wolfgang Walther
6f35b06544 postgresqlPackages.pgroonga: 4.0.5 -> 4.0.9 (#566413) 2026-09-27 12:03:31 +00:00
Adam C. Stephens
e63faa51ac incus-ui-canonical: 0.21.6 -> 0.21.7 (#567400) 2026-09-27 11:58:51 +00:00
xanderio
3181085bfd maintainers: add Matrix for aaravrav (#567411) 2026-09-27 11:55:07 +00:00
whoomee
f06fa3e828 python3Packages.pyfribidi: drop 2026-09-27 13:54:13 +02:00
Wolfgang Walther
554c5ed18d postgresql: allow third-party output plugins in tests (#566397) 2026-09-27 11:51:27 +00:00
Sefa Eyeoglu
9119beea47 immich: prevent node-gyp .pyc unreproducible files (#567235) 2026-09-27 11:46:30 +00:00
Grimmauld
f9f7fe4219 libeconf: add cpe 2026-09-27 13:43:11 +02:00
R. Ryantm
51e5d9c31b stevenblack-blocklist: 3.16.115 -> 3.16.118 2026-09-27 11:42:03 +00:00
nixpkgs-ci[bot]
92a5cb32f2 livekit-cli: 2.18.6 -> 2.18.8 (#566904) 2026-09-27 11:41:57 +00:00
R. Ryantm
b05edaf8d4 rofi-games: 1.18.0 -> 1.19.0 2026-09-27 11:41:38 +00:00
liberodark
574943e434 glpi-agent: 1.19 -> 1.20 2026-09-27 13:39:18 +02:00
Jo
324f656de1 firefox-{beta,devedition}-unwrapped: add cpe information (#567375) 2026-09-27 11:36:53 +00:00
Grimmauld
b65acf7cfc libeconf: test pkg-config 2026-09-27 13:36:20 +02:00
eljamm
393f08e232 pdfid: add eljamm as maintainer 2026-09-27 13:34:09 +02:00
Grimmauld
ca419d5410 libeconf: fix darwin build 2026-09-27 13:33:20 +02:00
nixpkgs-ci[bot]
9eb0650a9d restate: 1.7.10 -> 1.7.12 (#567347) 2026-09-27 11:31:49 +00:00
R. Ryantm
d90f750c7e python3Packages.frida-python: 17.17.0 -> 17.19.0 2026-09-27 11:31:11 +00:00
Jo
db258a9afd freecad: add cpe (#567429) 2026-09-27 11:27:13 +00:00
R. Ryantm
4bb9b32c98 thunderbird-esr-bin-unwrapped: 153.3.0esr -> 153.3.1esr 2026-09-27 11:26:09 +00:00
Sefa Eyeoglu
32aa99b2d5 doc/treewide: purge utilize in favor of use according to styleguide (#567384) 2026-09-27 11:25:32 +00:00
Jo
15741a51ef discord: move to pkgs/by-name (#560561) 2026-09-27 11:24:15 +00:00
nixpkgs-ci[bot]
63bf123fa0 cockpit: 367 -> 368 (#567437) 2026-09-27 11:23:48 +00:00
Felix Bühler
8016c29df5 graphify: 0.9.61 -> 0.9.66 (#566113) 2026-09-27 11:21:45 +00:00
Sefa Eyeoglu
229b363e79 unbound: add CPE parts
Signed-off-by: Sefa Eyeoglu <contact@scrumplex.net>
2026-09-27 13:18:52 +02:00
Sefa Eyeoglu
dc949ee517 kyverno: add CPE parts
Signed-off-by: Sefa Eyeoglu <contact@scrumplex.net>
2026-09-27 13:18:38 +02:00
Weijia Wang
0b2b57660f sarasa-gothic: 1.0.41 -> 1.0.42 (#567222) 2026-09-27 11:16:05 +00:00
Felix Bühler
1ab2938a70 ariang-native: init at 1.3.14 (#562354) 2026-09-27 11:14:57 +00:00
R. Ryantm
62e7db8d71 cockpit: 367 -> 368 2026-09-27 11:12:11 +00:00
Arne Keller
a6a9aafa53 maven_4: 4.0.0-rc-6 -> 4.0.0-rc-7 (#567363) 2026-09-27 10:59:53 +00:00
Sefa Eyeoglu
fa9ce4081d darwin.basic_cmds: set license to bsd3 (#555109) 2026-09-27 10:57:57 +00:00
Sefa Eyeoglu
b4735a8a2c darwin.shell_cmds: update license (#555119) 2026-09-27 10:57:40 +00:00
R. Ryantm
cc04c58436 python3Packages.aws-secretsmanager-caching: 1.1.3 -> 1.2.0 2026-09-27 10:57:34 +00:00
Grimmauld
ef0c36db1c freecad: add cpe 2026-09-27 12:54:40 +02:00
R. Ryantm
7bb21b4070 poco: 1.15.3 -> 1.15.4 2026-09-27 10:54:12 +00:00
R. Ryantm
186b375846 rusthound-ce: 2.5.13 -> 2.5.14 2026-09-27 10:45:37 +00:00
Felix Bühler
545c226a9a nixos/fedimintd: map vhost via lib.mkDefault (#544352) 2026-09-27 10:44:52 +00:00
Robert Hensing
a1364c73e7 lib.modules: document mkOverride (#512758) 2026-09-27 10:39:04 +00:00
Lukas Epple
b1ed9a0e76 inspircd: 4.12.0 -> 4.12.1 (#567173) 2026-09-27 10:37:16 +00:00
Léana
199ee26b83 lib.modules: document mkOverride
Co-authored-by: Robert Hensing <roberth@users.noreply.github.com>
2026-09-27 12:30:55 +02:00
Lukas Epple
7e35f59c1f jackline: fix version (#567253) 2026-09-27 10:28:42 +00:00
nixpkgs-ci[bot]
f93217b13c pycharm: 2026.2.0.1 -> 2026.2.3 (#567020) 2026-09-27 10:27:53 +00:00
nixpkgs-ci[bot]
2693544c76 paratest: 7.24.1 -> 7.25.0 (#567345) 2026-09-27 10:12:45 +00:00
Maximilian Bosch
4285877bb9 php84: 8.4.25 -> 8.4.26 (#567049) 2026-09-27 10:07:08 +00:00
Marc Jakobi
d123ce3ed0 doc/nvim: link to section on packaging vim plugins (#567403) 2026-09-27 10:05:55 +00:00
R. Ryantm
7115414009 python3Packages.aqualogic: 3.10 -> 3.11 2026-09-27 10:05:03 +00:00
Johannes Kirschbauer
278e412c8d nixos/misc/nixpkgs: add documentation for nixpkgs.config.allowUnfreePackages (#485365) 2026-09-27 10:02:30 +00:00
Grimmauld
4b87c05341 davs2: add cpe information (#567370) 2026-09-27 10:00:06 +00:00
Victor Engmark
974ed99229 doc/readme: Capitalise sentences in definition lists 2026-09-27 11:59:08 +02:00
Martin Häcker
f4f9faa564 nixos/misc/nixpkgs: add documentation for nixpkgs.config.allowUnfreePackages 2026-09-27 11:55:34 +02:00
nixpkgs-ci[bot]
79f2e0b776 sdrangel: 7.27.1 -> 7.27.2 (#554669) 2026-09-27 09:54:40 +00:00
nixpkgs-ci[bot]
5bf2111ed4 librewolf-unwrapped: 156.0-1 -> 156.0.1-1 (#565910) 2026-09-27 09:54:38 +00:00
nixpkgs-ci[bot]
00e92d4d0a simplebluez: 0.11.0 -> 1.1.0 (#516661) 2026-09-27 09:54:36 +00:00
Victor Engmark
8485056e31 doc/readme: Use active voice 2026-09-27 11:52:23 +02:00
aaravrav
c01431ab86 maintainers: add Matrix for aaravrav 2026-09-27 15:19:24 +05:30
R. Ryantm
9aa529f008 terraform-providers.hashicorp_google-beta: 8.3.0 -> 8.4.0 2026-09-27 09:48:30 +00:00
Maximilian Bosch
42f851d5e5 php83: 8.3.33 -> 8.3.35 (#567036) 2026-09-27 09:48:10 +00:00
theKlisha
0592871956 doc(nvim): reword to avoid anonyomus link 2026-09-27 11:46:37 +02:00
Victor Engmark
2754e18b47 doc/readme: Remove paragraph about the inspiration for literals 2026-09-27 11:46:19 +02:00
nixpkgs-ci[bot]
fdd2d385e5 aiken: 1.1.23 -> 1.1.24 (#567187) 2026-09-27 09:45:39 +00:00
R. Ryantm
58e086a953 terraform-providers.aiven_aiven: 4.62.0 -> 4.63.0 2026-09-27 09:45:19 +00:00
Victor Engmark
29fb5377de doc/readme: Explain how literals are formatted 2026-09-27 11:45:17 +02:00
Victor Engmark
851bc1b6db doc/readme: Clarify variable literals 2026-09-27 11:44:11 +02:00
R. Ryantm
4f352c8ff4 cargo-tarpaulin: 0.37.2 -> 0.37.5 2026-09-27 09:41:34 +00:00
Jappie Klooster
724ffde083 doc/treewide: purge "utilize" in favor of "use" following styleguide
Reapply "doc/treewide: purge utilize in favor of use according to styleguide"

This reverts commit 847e39f8f358af7f26e066b59c39e96a6f19cd9a.
2026-09-27 11:39:42 +02:00
Maximilian Bosch
5b92250acb php82: 8.2.33 -> 8.2.34 (#567027) 2026-09-27 09:38:50 +00:00
R. Ryantm
7c973f882d mpris-scrobbler: 0.5.9 -> 0.5.10 2026-09-27 09:36:20 +00:00
Tom Herbers
423c353636 incus-ui-canonical: 0.21.6 -> 0.21.7
Diff: https://github.com/zabbly/incus-ui-canonical/compare/incus-0.21.6...incus-0.21.7
2026-09-27 11:31:12 +02:00
Akira Komamura
5acd5f7d47 ocamlPackages.capnp-rpc: init at 2.1.2-unstable-2026-09-13 2026-09-27 18:29:24 +09:00
theKlisha
eb69748cbe doc(nvim): link to section on packaging vim plugins 2026-09-27 11:26:10 +02:00
jopejoe1
2e6c5ff68a python313Packages.notobuilder: 0-unstable-2026-06-26 -> 0-unstable-2026-09-24 2026-09-27 11:24:17 +02:00
Sefa Eyeoglu
c8506f6c70 doc/cosmic: remove filler words (#567388) 2026-09-27 09:23:43 +00:00
nixpkgs-ci[bot]
732e9cbbad todoist-cli: 5.3.6 -> 5.4.2 (#567189) 2026-09-27 09:22:29 +00:00
R. Ryantm
14e9b24072 python3Packages.glyphslib: 6.14.0 -> 6.15.0 2026-09-27 09:20:19 +00:00
Matt Sturgeon
9b5d3ab762 doc: Misc cleanup (#567371) 2026-09-27 09:17:35 +00:00
7c6f434c
c1ff07ae2b julia_113{,-bin}: init at 1.13.1 (#561865) 2026-09-27 09:17:02 +00:00
Maximilian Bosch
fd08b24fc6 php85: 8.5.10 -> 8.5.11 (#566591) 2026-09-27 09:16:21 +00:00
7c6f434c
075e34bded sgt-puzzles: 20260912.ea09098 -> 20260923.616da16 (#567318) 2026-09-27 09:14:47 +00:00
Marek Fajkus
d3ca72e686 elmPackages.elm-watch: init at 1.2.6 (#515825) 2026-09-27 09:14:34 +00:00
Matt Sturgeon
5fe040508f doc/readme: Simplify nix-direnv setup (#567379) 2026-09-27 09:14:23 +00:00
7c6f434c
86acb4b240 remind: 06.02.10 -> 06.03.04; Replace gitUpdate with custom update script (#565824) 2026-09-27 09:14:16 +00:00
Kenji Berthold
127988eea9 doc/cosmic: remove filler words
Align with the documentation styleguide and remove filler words.
2026-09-27 11:12:37 +02:00
7c6f434c
32fe9f06e6 wine-staging, winePackages.unstable: 11.16 -> 11.18 (#562801) 2026-09-27 09:11:36 +00:00
Victor Engmark
d06348039d doc/readme: Join overlapping sentences 2026-09-27 11:10:50 +02:00
Victor Engmark
b99a7f357d doc/readme: Clarify and format :doc REPL command
Co-authored-by: Matt Sturgeon <matt@sturgeon.me.uk>
2026-09-27 11:10:47 +02:00
Victor Engmark
5b1059092b doc/readme: Remove unnecessary punctuation
Co-authored-by: Matt Sturgeon <matt@sturgeon.me.uk>
2026-09-27 11:10:11 +02:00
Victor Engmark
9ac6245a02 doc/readme: Simplify nix-direnv setup
Co-Authored-By: Sefa Eyeoglu <contact@scrumplex.net>
2026-09-27 11:07:40 +02:00
Myxogastria0808
faf8f7063a elmPackages.elm-watch: init at 1.2.6 2026-09-27 18:07:13 +09:00
Myxogastria0808
2b43631ff2 maintainers: add Myxogastria0808 2026-09-27 18:07:01 +09:00
Grimmauld
760b9fc0f8 fribidi: 1.0.16 -> 1.0.17, modernize, adopt (#567373) 2026-09-27 09:06:40 +00:00
Sefa Eyeoglu
e4d4de495d doc/styleguide: fix meta-commentary example's styling (#567383) 2026-09-27 09:04:52 +00:00
R. Ryantm
927786e0b2 vscode-extensions.ms-azuretools.vscode-containers: 2.5.1 -> 2.5.2 2026-09-27 09:04:26 +00:00
Marie Ramlow
2d8c8f2184 appium-inspector: 2026.7.1 -> 2026.9.2 (#567330) 2026-09-27 09:01:31 +00:00
Coca
dae69f6c32 doc/styleguide: fix meta-commentary example's styling
Github's markdown renderer combines the two bad/good examples into one
line without a extra space leading to a incredible amount of confusion.

Co-Authored-By: ryndubei <vasily.sterekhov@protonmail.com>
Co-Authored-By: jappeace <jappieklooster@hotmail.com>
2026-09-27 10:57:08 +02:00
whoomee
48ba5d38f2 fribidi: specify identifiers.cpeParts 2026-09-27 10:57:02 +02:00
Martin Weinelt
11700d5bcd home-assistant-custom-lovelace-modules.light-entity-card: 6.4.0 -> 6.4.1 (#567334) 2026-09-27 08:49:34 +00:00
nixpkgs-ci[bot]
37afe39849 folo: 1.13.0 -> 1.14.0 (#567158) 2026-09-27 08:46:40 +00:00
Diogo Correia
9871fe9f1a bazarr: 1.6.1 -> 1.6.2
https://github.com/morpheus65535/bazarr/releases/tag/v1.6.2
2026-09-27 09:45:29 +01:00
whoomee
a82a222310 fribidi: add comment about depsBuildBuild 2026-09-27 10:38:09 +02:00
Jo
60f1be7c82 python3Packages.fontmake: cleanup (#561546) 2026-09-27 08:37:44 +00:00
Diogo Correia
21106257bb doc/treewide: use channels.nixos.org instead of GitHub tarballs (#567374) 2026-09-27 08:36:52 +00:00
Sefa Eyeoglu
a8d86f94a8 doc/styleguide: use sentence case
As the style guide suggests! :D

Signed-off-by: Sefa Eyeoglu <contact@scrumplex.net>
2026-09-27 10:35:35 +02:00
Marek Fajkus
e96c6cd23e elmPackages.elm-xref: Fix compatibility with elm 0.19.2 (#567372) 2026-09-27 08:32:57 +00:00
whoomee
b231de7d55 fribidi: specify meta.changelog 2026-09-27 10:31:07 +02:00
whoomee
5c51fed8c5 fribidi: add maintainer tmarkus 2026-09-27 10:31:07 +02:00
whoomee
7b9d55b627 fribidi: modernize 2026-09-27 10:31:07 +02:00
R. Ryantm
804833fc0b signalbackup-tools: 20260822 -> 20260927 2026-09-27 08:30:48 +00:00
Jo
109230e841 ffmpeg: add cpe infromation (#567368) 2026-09-27 08:30:24 +00:00
nixpkgs-ci[bot]
d56b89f6fb scopehal-apps: 0.2.2 -> 0.3 (#567308) 2026-09-27 08:28:17 +00:00
jopejoe1
804aa65519 firefox-{beta,devedition}-unwrapped: add cpe information 2026-09-27 10:27:57 +02:00
Tom
973091643e gnomeExtensions.impatience: add hideyosh1 to maintainers (#539465) 2026-09-27 08:26:04 +00:00
Sefa Eyeoglu
6b896a5a8c doc/treewide: use channels.nixos.org instead of GitHub tarballs
Signed-off-by: Sefa Eyeoglu <contact@scrumplex.net>
2026-09-27 10:21:11 +02:00
Marek Fajkus
f3f105dcd1 elmPackages.elm-xref: Fix compatibility with elm 0.19.2
Apply patch to fix build with updated elm compiler
2026-09-27 10:20:34 +02:00
Rémi NICOLE
c8dd24c256 netboxPlugins.netbox-cable-labels: init at 0.1.0 (#564653) 2026-09-27 08:20:13 +00:00
Victor Engmark
795f334f07 doc: Use more common spelling of "style guide"
See
[trend](https://trends.google.com/explore?q=styleguide%2Cstyle%2520guide&date=all&geo=Worldwide)
for one indication that the new spelling is much more common.
2026-09-27 10:17:36 +02:00
jopejoe1
e7c0ea6129 ffmpeg: add cpe information 2026-09-27 10:17:35 +02:00
Rémi NICOLE
4549a38cd2 netboxPlugins.netbox-notices: init at 1.3.0 (#564655) 2026-09-27 08:16:53 +00:00
jopejoe1
97faf364f3 davs2: add cpe information 2026-09-27 10:15:39 +02:00
whoomee
3b39b2d0da fribidi: add pango/libass in passthru.tests 2026-09-27 10:13:23 +02:00
whoomee
0866ba5e21 fribidi: 1.0.16 -> 1.0.17 2026-09-27 10:12:08 +02:00
R. Ryantm
fb8b749599 trufflehog: 3.97.5 -> 3.97.9 2026-09-27 08:10:31 +00:00
R. Ryantm
2930dd461d yoda: 2.1.2 -> 2.1.4 2026-09-27 08:08:38 +00:00
Victor Engmark
85c46e0d56 doc/readme: Format for readability 2026-09-27 10:08:36 +02:00
StepBroBD
48f36b9079 ocamlPackages.unstrctrd: 0.4 -> 0.5 (#567159) 2026-09-27 08:07:20 +00:00
R. Ryantm
0213fb9282 defuddle: 0.19.3 -> 0.19.4 2026-09-27 08:04:47 +00:00
Rémi NICOLE
f54874bc8e netboxPlugins.netbox-sqids: init at 0.2.0 (#564917) 2026-09-27 08:01:50 +00:00
Grimmauld
8137effccd nixos/account-utils, nixos/accounts-daemon: add NSS library path to services (#565369) 2026-09-27 08:01:18 +00:00
Thiago Kenji Okada
5d9dfbb05a nixos-rebuild-ng: avoid crashing when fds are closed during switch by using systemd-run --wait --verbose instead of systemd-run --pipe (#506897) 2026-09-27 08:00:55 +00:00
Benedikt Ritter
e4c3998302 maven_4: 4.0.0-rc-6 -> 4.0.0-rc-7 2026-09-27 10:00:13 +02:00
whoomee
a1a0075710 meson: add disabledTests support 2026-09-27 10:00:04 +02:00
nixpkgs-ci[bot]
8f5f1e8f8e lmstudio: 0.4.23.1 -> 0.4.25.1 (#567359) 2026-09-27 07:59:43 +00:00
Grimmauld
cdf43658dc {libapparmor,apparmor-*}: add CPE (#567224) 2026-09-27 07:58:44 +00:00
R. Ryantm
0b7aec0658 python3Packages.appium-python-client: 6.0.6 -> 6.0.7 2026-09-27 07:58:40 +00:00
Aaron Andersen
26b6de75a3 xwayland-satellite: 0.8.2 -> 0.8.3 (#566386) 2026-09-27 07:56:03 +00:00
R. Ryantm
8eb7eafe10 neocmakelsp: 0.11.1 -> 0.11.2 2026-09-27 07:55:15 +00:00
R. Ryantm
5e66c0e2b9 nest-cli: 12.0.3 -> 12.0.7 2026-09-27 07:47:43 +00:00
R. Ryantm
79e7d11cb5 vscode-extensions.dotenv.dotenv-vscode: 0.28.1 -> 1.5.7 2026-09-27 07:43:53 +00:00
Ulrik Strid
9cab9ed832 microsoft-edge, msedgedriver: refactor, add darwin support (#565662) 2026-09-27 07:38:21 +00:00
crertel
e44a874f28 lmstudio: 0.4.23.1 -> 0.4.25.1 2026-09-27 02:34:29 -05:00
Minijackson
9a08409806 netbox: 4.7.0 -> 4.7.1
Remove django-graphiql-debug-toolbar from dependencies,
as it was removed from base_requirements.txt upstream.
2026-09-27 09:30:59 +02:00
Minijackson
fda892a988 nixos/tests/netbox: enable ssh backdoor for interactive tests 2026-09-27 09:30:59 +02:00
Minijackson
c962694a08 netbox: 4.6.8 -> 4.7.0 2026-09-27 09:30:59 +02:00
Minijackson
8f5692f408 python3Packages.django-pgware: init at 1.0.0
Needed by NetBox 4.7.0
2026-09-27 09:30:59 +02:00
Thiago Kenji Okada
d3feeda056 nixos/tests/nixos-rebuild-target-host-interrupted: fix test 2026-09-27 08:30:28 +01:00
nixpkgs-ci[bot]
ae6bc0b043 yubioath-flutter: 7.4.1 -> 7.4.2 (#562164) 2026-09-27 07:25:34 +00:00
R. Ryantm
73fb6a442f python3Packages.pyhik: 0.4.6 -> 0.4.7 2026-09-27 07:22:40 +00:00
kaynetik
bbc7ddf060 hunk: 0.21.1 -> 0.22.0
Upstream moved the app into `packages/hunk`. Build and install skills
from the new paths, and replace the `paths.ts` patch with a
`$out/skills` symlink that `hunk skill path` already resolves.

Signed-off-by: kaynetik <aleksandar@nesovic.dev>
2026-09-27 09:21:46 +02:00
Marek Fajkus
02f754064d cargo-generate: 0.23.9 -> 0.25.0 (#567322) 2026-09-27 07:19:36 +00:00
R. Ryantm
80711d2a3e wavelog: 3.2.2 -> 3.2.3 2026-09-27 07:17:00 +00:00
Gaétan Lepage
a2ffba684f python3Packages.orbax-checkpoint: 0.12.5 -> 0.12.6 (#567194) 2026-09-27 07:10:55 +00:00
Sergei Volkov
c82d70bc35 julia_113: init at 1.13.1 2026-09-27 09:05:25 +02:00
nixpkgs-ci[bot]
022b28b217 keycloakPlugins.keycloak-magic-link: 0.75 -> 0.84 (#567349) 2026-09-27 07:02:23 +00:00
nixpkgs-ci[bot]
73e5a4a588 slint-tr-extractor: 1.17.1 -> 1.18.1 (#567079) 2026-09-27 07:02:21 +00:00
nixpkgs-ci[bot]
dc69892ec3 keycloakPlugins.keycloak-orgs: 0.180 -> 0.182 (#567350) 2026-09-27 07:02:19 +00:00
R. Ryantm
8a766bf2a9 tree-sitter-grammars.tree-sitter-pkl: 0.20.0-unstable-2026-03-27 -> 0.21.0-unstable-2026-09-25 2026-09-27 07:00:33 +00:00
R. Ryantm
ff1380b1d2 tree-sitter-grammars.tree-sitter-php-only: 0.24.2-unstable-2026-03-19 -> 0.25.0-unstable-2026-09-24 2026-09-27 06:59:13 +00:00
Jon Seager
5a4a887d43 tsgolint: 7.0.2001 -> 7.0.2003 (#567295) 2026-09-27 06:55:54 +00:00
R. Ryantm
fb22dca800 python3Packages.asyncmy: 0.2.14 -> 0.2.15 2026-09-27 06:51:30 +00:00
R. Ryantm
cd64f70e6b python3Packages.pysillaprism: 0.2.0 -> 0.2.1 2026-09-27 06:48:41 +00:00
R. Ryantm
961c9b6052 keycloakPlugins.keycloak-orgs: 0.180 -> 0.182 2026-09-27 06:35:34 +00:00
Audrey Dutcher
e443f5081e keycloak: fix cross-compilation (#567319) 2026-09-27 06:35:24 +00:00
R. Ryantm
d7e4059378 keycloakPlugins.keycloak-magic-link: 0.75 -> 0.84 2026-09-27 06:35:07 +00:00
R. Ryantm
dad464aff9 libretro.fceumm: 0-unstable-2026-08-22 -> 0-unstable-2026-09-26 2026-09-27 06:19:10 +00:00
nixpkgs-ci[bot]
7e5db1fdb4 Merge master into staging-nixos 2026-09-27 06:16:42 +00:00
nixpkgs-ci[bot]
1036995706 Merge staging-next into staging 2026-09-27 06:16:12 +00:00
nixpkgs-ci[bot]
70eef449a3 Merge master into staging-next 2026-09-27 06:15:38 +00:00
Arne Keller
819e16381c mpvScripts.youtube-chat: fix version (#567287) 2026-09-27 06:15:00 +00:00
R. Ryantm
a46b00347d restate: 1.7.10 -> 1.7.12 2026-09-27 06:13:22 +00:00
R. Ryantm
0d328ff88e paratest: 7.24.1 -> 7.25.0 2026-09-27 06:02:22 +00:00
Arnout Engelen
2f71ad15d4 nixos-rebuild-ng: avoid crashing when fds are closed during switch
This was previously implemented as
https://github.com/NixOS/nixpkgs/pull/463029 but that led to
unexpected side effects as documented there and in
https://github.com/NixOS/nixpkgs/pull/498801.
A more ambitious approach is
https://github.com/NixOS/nixpkgs/pull/503032

This approach is a smaller delta, simpler and safer

Fixes #462179
2026-09-27 07:00:38 +01:00
Thiago Kenji Okada
c6336bc564 bitbake-setup: init at 2.19.0 (#553184) 2026-09-27 05:52:56 +00:00
Thiago Kenji Okada
ed2c1d44c1 mons: fix version, switch to hash (#567281) 2026-09-27 05:51:38 +00:00
R. Ryantm
3e2d8109ae cargo-guppy: 0.18.0 -> 0.19.1 2026-09-27 05:50:24 +00:00
Pol Dellaiera
455253b443 secretspec: 0.21.0 -> 0.21.1 (#567302) 2026-09-27 05:49:55 +00:00
Pol Dellaiera
98d335265e leviculum: 0.8.1 -> 0.9.0 (#567329) 2026-09-27 05:36:17 +00:00
Yohann Boniface
751afbbfdd chatzone-desktop: fix URL handling (#566976) 2026-09-27 05:28:17 +00:00
R. Ryantm
322628153e essh: 0.4.0 -> 0.4.1 2026-09-27 05:27:41 +00:00
R. Ryantm
6bcb10007f feh: 3.13 -> 3.13.1 2026-09-27 05:24:12 +00:00
Yohann Boniface
de8e00bb4f minc_widgets: fix version, modernize (#567262) 2026-09-27 05:23:00 +00:00
Yohann Boniface
f3d41cfc78 mdctags: fix version, modernize (#567260) 2026-09-27 05:21:59 +00:00
Ethan Carter Edwards
a53d27da92 newflasher: modernize
Signed-off-by: Ethan Carter Edwards <ethan@ethancedwards.com>
2026-09-27 01:01:49 -04:00
nixpkgs-ci[bot]
5476e0b0a3 catt: 0.13.2 -> 0.13.3 (#567297) 2026-09-27 04:59:47 +00:00
R. Ryantm
946ae981c1 wrangler: 4.132.0 -> 4.141.0 2026-09-27 04:49:51 +00:00
R. Ryantm
f0ec4e25ab home-assistant-custom-lovelace-modules.light-entity-card: 6.4.0 -> 6.4.1 2026-09-27 04:47:03 +00:00
nixpkgs-ci[bot]
af0a030d8c newflasher: 60 -> 61 (#567164) 2026-09-27 04:33:00 +00:00
LunNova
066cb831a4 rocmPackages.llvm.llvm: backport patches to support arm64e.x1 support in base llvm (#567075) 2026-09-27 04:26:13 +00:00
R. Ryantm
5e2401a372 python3Packages.types-mysqlclient: 2.2.0.20260508 -> 2.3.0.20260923 2026-09-27 04:25:48 +00:00
R. Ryantm
01522328ba vscode-extensions.leanprover.lean4: 0.0.239 -> 0.0.240 2026-09-27 04:24:18 +00:00
R. Ryantm
9b32ccc790 pybugz: 0.14 -> 0.15 2026-09-27 04:18:59 +00:00
nixpkgs-ci[bot]
70f5216da3 mprisence: 1.8.5 -> 1.8.8 (#567131) 2026-09-27 04:11:28 +00:00
R. Ryantm
461821773f appium-inspector: 2026.7.1 -> 2026.9.2 2026-09-27 04:11:18 +00:00
zowoq
6fa4e5c186 terraform-providers.launchdarkly_launchdarkly: 3.1.5 -> 3.1.6 (#567327) 2026-09-27 04:05:44 +00:00
nixpkgs-ci[bot]
4e88045b27 Merge master into staging-nixos 2026-09-27 04:03:04 +00:00
nixpkgs-ci[bot]
2c07ff3592 Merge staging-next into staging 2026-09-27 04:02:34 +00:00
nixpkgs-ci[bot]
7b01a6b4b6 Merge master into staging-next 2026-09-27 04:02:03 +00:00
Sebastián Mancilla
103348c6ac libff: fix header installation with CMake 4.3+ (#559966) 2026-09-27 03:52:04 +00:00
Michael Daniels
da1f7a1117 ci/github-script: convert various to TypeScript (#567205) 2026-09-27 03:45:59 +00:00
R. Ryantm
8c833ef1db leviculum: 0.8.1 -> 0.9.0 2026-09-27 03:45:15 +00:00
Masum Reza
9b5f1e1d6d limine-full: 12.9.0 -> 12.9.1 (#567316) 2026-09-27 03:44:41 +00:00
Sebastián Mancilla
8d5d270900 cheat: 4.5.0 -> 5.1.0 (#521325) 2026-09-27 03:42:02 +00:00
Adam C. Stephens
f70d1ee0ff omp: 18.2.11 -> 18.3.3 (#567323) 2026-09-27 03:35:13 +00:00
R. Ryantm
3f63f6db45 terraform-providers.launchdarkly_launchdarkly: 3.1.5 -> 3.1.6 2026-09-27 03:29:13 +00:00
Sebastián Mancilla
5335d4d186 sacad: 2.8.3 -> 3.0.1 (#539975) 2026-09-27 03:28:49 +00:00
Sebastián Mancilla
63531214ad mycli: 1.44.2 -> 2.20.0 (#522107) 2026-09-27 03:12:30 +00:00
Sebastián Mancilla
d79cfc3e13 proton-cli: 2.2.3 -> 3.4.0 (#553470) 2026-09-27 02:58:31 +00:00
Sebastián Mancilla
62294804c4 libinklevel: 0.9.4 -> 0.9.7 (#552514) 2026-09-27 02:52:02 +00:00
R. Ryantm
465dfea5af cargo-generate: 0.23.9 -> 0.25.0 2026-09-27 02:49:01 +00:00
Adam C. Stephens
b6d2175d99 omp: 18.2.11 -> 18.3.3
Changelog: https://github.com/can1357/oh-my-pi/releases/tag/v18.3.3
2026-09-26 22:46:38 -04:00
Audrey Dutcher
26d249985e keycloak: fix cross-compilation 2026-09-26 19:37:06 -07:00
nixpkgs-ci[bot]
4c42ed05bb stashcat: 6.52.0 -> 6.54.1 (#567018) 2026-09-27 02:35:19 +00:00
R. Ryantm
ce1eaf2515 sgt-puzzles: 20260912.ea09098 -> 20260923.616da16 2026-09-27 02:19:24 +00:00
Bobby Rong
09e95147eb Cinnamon updates 2026-09-26 (#567037) 2026-09-27 02:17:54 +00:00
R. Ryantm
45f06483c5 limine-full: 12.9.0 -> 12.9.1 2026-09-27 02:00:15 +00:00
zowoq
c3a2a89dc2 nixos/kexec: add maintainer 2026-09-27 11:50:15 +10:00
zowoq
da0c95f456 kexec-tools: add maintainer 2026-09-27 11:45:04 +10:00
zowoq
e38e60d715 ci/OWNERS, maintainers/team-list: remove maintainer from buildbot (#539788) 2026-09-27 01:15:18 +00:00
R. Ryantm
12e98d5c1a scopehal-apps: 0.2.2 -> 0.3 2026-09-27 01:03:34 +00:00
Victor Fuentes
6f4cf54e07 glib: watch XDG state profiles for application changes
Make glib patch watch $XDG_STATE_HOME/nix/profiles for appinfo changes in
addition to /nix/var/nix/profiles and /nix/var/nix/profiles/system/sw/share.

Without this change glib will not detect changes after nix profile install
or home-manager switch if they target ~/.local/state/nix/profiles.
2026-09-26 18:02:25 -07:00
Victor Fuentes
0658011fdb gnome-shell: refresh icons after profile switches
GNOME checks for icon changes based on directory modification time.
Since Nix hardcodes modification time to 1, GNOME never detects when icons are changed,
leading to missing icons in the application menu on newly installed programs.

To fix we now also invalidate icon cache on device and inode changes.
2026-09-26 17:57:22 -07:00
coolcuber
fcbfd23ce7 muso: fix version, enable structuredAttrs 2026-09-26 20:45:51 -04:00
Domen Kožar
a690c58565 secretspec: 0.21.0 -> 0.21.1
Changelog: https://github.com/cachix/secretspec/blob/v0.21.1/CHANGELOG.md
Release: https://github.com/cachix/secretspec/releases/tag/v0.21.1

The published crate now ships every test fixture, so drop the sparse
checkout of the release tag. The external provider ancestor walk tests
no longer depend on host ownership, so stop skipping them.

Assisted-by: Claude Code (Claude Opus 5.5)
2026-09-27 02:45:30 +02:00
R. Ryantm
af50d4dc13 kubectl: 1.37.0 -> 1.37.1 2026-09-27 00:39:23 +00:00
R. Ryantm
7ae0cb845d clinfo: 3.0.25.02.14 -> 3.1.26.09.26 2026-09-27 00:36:48 +00:00
nixpkgs-ci[bot]
73638b8d97 Merge master into staging-nixos 2026-09-27 00:29:40 +00:00
R. Ryantm
135d297e6e catt: 0.13.2 -> 0.13.3 2026-09-27 00:29:11 +00:00
nixpkgs-ci[bot]
9ba77512d2 Merge staging-next into staging 2026-09-27 00:29:10 +00:00
nixpkgs-ci[bot]
565188e4b7 Merge master into staging-next 2026-09-27 00:28:39 +00:00
Joseph LaFreniere
02a875bea9 tsgolint: 7.0.2001 -> 7.0.2003
https://github.com/oxc-project/tsgolint/releases/tag/v7.0.2003
2026-09-26 19:25:57 -05:00
R. Ryantm
2053eff1c1 stump: 0.1.7 -> 0.1.10 2026-09-27 00:18:25 +00:00
Otavio Salvador
09b5d3436b whisrs: init at 0.1.27
Assisted-by: Claude Code (claude-opus-5)
2026-09-26 21:13:32 -03:00
R. Ryantm
806180c187 libkrun: 1.19.0 -> 1.19.5 2026-09-27 00:09:47 +00:00
Nadir Ishiguro
b89ad69f06 pcloud: 2.2.1 -> 2.3.0
Upstream release notes:

> 2.3.0(23/09/2026)
> This version brings pCloud's document editing feature, available in the context (right-click) menu for premium and business users. It also introduces a new way to manage items that failed to upload or download, by allowing you to take actions for the specific item.
> Heads-up: File manager restart will be required for the document editing option to appear in the right-click menu.
2026-09-27 02:08:23 +02:00
dotlambda
51db3848d0 python3Packages.tesla-protocol: 2.0.0 -> 3.0.0 (#567219) 2026-09-27 00:06:51 +00:00
coolcuber
941cca3c74 mpvScripts.youtube-chat: fix version 2026-09-26 20:05:13 -04:00
R. Ryantm
bfdc173730 dorion: 6.13.1 -> 6.13.2 2026-09-26 23:57:08 +00:00
R. Ryantm
6e7ba58dec shelter: 0-unstable-2026-09-06 -> 0-unstable-2026-09-16 2026-09-26 23:46:37 +00:00
coolcuber
5b1ba3ec45 mons: fix version, switch to hash 2026-09-26 19:45:34 -04:00
Yt
9dc197bee4 meilisearch: 1.53.2 -> 1.54.0 (#567270) 2026-09-26 23:35:40 +00:00
coolcuber
ef99886013 mmh: fix version; enable strictDeps, structuredAttrs 2026-09-26 19:11:59 -04:00
R. Ryantm
3361d2bf32 python3Packages.jellyfin-apiclient-python: 1.18.0 -> 1.19.0 2026-09-26 23:08:57 +00:00
R. Ryantm
19519f9f3c meilisearch: 1.53.2 -> 1.54.0 2026-09-26 23:01:26 +00:00
Eric Rodrigues Pires
de79fb1cd7 trimal: fix homepage 2026-09-26 19:58:28 -03:00
Eric Rodrigues Pires
c1939dc1c0 tre: fix homepage 2026-09-26 19:58:28 -03:00
Eric Rodrigues Pires
81f75338fc sphinx-fortran: fix homepage 2026-09-26 19:58:28 -03:00
Eric Rodrigues Pires
93274b9ddb proxytunnel: fix homepage 2026-09-26 19:58:28 -03:00
Eric Rodrigues Pires
406d53422e proj-datumgrid: fix homepage 2026-09-26 19:58:28 -03:00
Eric Rodrigues Pires
018142060d mozillavpn: fix homepage 2026-09-26 19:58:28 -03:00
Eric Rodrigues Pires
5008f843ed luaPackages.vicious: fix homepage 2026-09-26 19:58:27 -03:00
Eric Rodrigues Pires
ab9a3d08a7 keycard-cli: fix homepage 2026-09-26 19:55:55 -03:00
Eric Rodrigues Pires
9bc04e053c kiln: fix homepage 2026-09-26 19:55:55 -03:00
Eric Rodrigues Pires
e8eed3a47f kuzu: fix homepage 2026-09-26 19:55:55 -03:00
Eric Rodrigues Pires
0ae3ef4d82 ladspaPlugins: fix homepage 2026-09-26 19:55:55 -03:00
Eric Rodrigues Pires
c34d7f8b6f xpra: fix homepage and remove downloadPage 2026-09-26 19:55:55 -03:00
Eric Rodrigues Pires
525c847f7f lcab: fix homepage 2026-09-26 19:55:55 -03:00
Eric Rodrigues Pires
f97f8bc46f ldmud: fix homepage 2026-09-26 19:55:55 -03:00
Eric Rodrigues Pires
8b9bfa6ddb libcint: fix homepage 2026-09-26 19:55:55 -03:00
Eric Rodrigues Pires
525c5ec9e8 libfm: fix homepage 2026-09-26 19:55:55 -03:00
Eric Rodrigues Pires
afd8e49614 pcmanfm: fix homepage 2026-09-26 19:55:55 -03:00
Eric Rodrigues Pires
0ad1a1ff0d liblogging: fix homepage 2026-09-26 19:55:55 -03:00
Eric Rodrigues Pires
849a1ca67b libsieve: fix homepage 2026-09-26 19:55:55 -03:00
Eric Rodrigues Pires
9f66be416a lklug-sinhala: fix homepage 2026-09-26 19:55:55 -03:00
Eric Rodrigues Pires
8a4709eb1f luaPackages.cosmo: fix homepage 2026-09-26 19:55:47 -03:00
Eric Rodrigues Pires
b842c76aa6 loxodo: fix homepage 2026-09-26 19:55:47 -03:00
Eric Rodrigues Pires
3b98ca6860 luaPackages.ljsyscall: fix homepage 2026-09-26 19:55:45 -03:00
coolcuber
9404b59d84 minc_widgets: fix version, modernize 2026-09-26 18:40:09 -04:00
penelope zhong
b0e48c1969 gnomeExtensions.impatience: add hideyosh1 as maintainer 2026-09-26 17:27:36 -05:00
penelope zhong
d4405d55de maintainers: add hideyosh1 2026-09-26 17:27:36 -05:00
coolcuber
b489b8cafc mdctags: fix version, modernize 2026-09-26 18:24:59 -04:00
Sergei Volkov
104561095c julia: add __structuredAttrs = true;
required for adding new package julia_113
2026-09-26 23:53:40 +02:00
Sergei Volkov
7327a6a0ce julia_113-bin: init at 1.13.1 2026-09-26 23:53:35 +02:00
coolcuber
785b85d8a2 jackline: fix version 2026-09-26 17:47:38 -04:00
coolcuber
d9107ea2c8 jack-autoconnect: fix version, modernize 2026-09-26 17:41:22 -04:00
Dhananjay Balan
32f949cbb9 pgcli: 4.6.0 -> 4.7.1 2026-09-26 23:39:11 +02:00
R. Ryantm
80b73605fe vscode-extensions.divyanshuagrawal.competitive-programming-helper: 2026.9.1789051951 -> 2026.9.1789578855 2026-09-26 21:32:24 +00:00
Martin Weinelt
f3492d9296 [staging-next] afflib: fix build with gcc 16 (#566315) 2026-09-26 21:20:24 +00:00
Martin Weinelt
ae2bb2d507 [staging-next] libofx: fix build with gcc 16 (#566314) 2026-09-26 21:20:20 +00:00
Grayson Tinker
fd18652856 iana-etc: mark as supported on all platforms 2026-09-26 15:04:59 -06:00
nixpkgs-ci[bot]
65ba6d0bc0 unifont: 17.0.05 -> 18.0.01 (#567201) 2026-09-26 20:44:00 +00:00
Rafael Ieda
143592c313 microsoft-edge: refactor, add darwin support 2026-09-26 17:34:10 -03:00
Rafael Ieda
670ddeed25 msedgedriver: refactor, add darwin support 2026-09-26 17:34:10 -03:00
Sandro
311e1b0faa paperless-ngx: 3.1.3 -> 3.2.1 (#566339) 2026-09-26 20:33:46 +00:00
Sandro Jäckel
4dfb033345 nixos/nix: move nix.nixPath into nix.settings.nix-path
This removes some confusion when setting nix.settings.nix-path to a custom value,
disabling channels and ending up with an empty NIX_PATH.
This is important since nix 2.24 fixed NIX_PATH not overwriting the
nix-path setting.
2026-09-26 22:16:09 +02:00
Diogo Correia
7cc1fd5e16 immich: prevent node-gyp .pyc unreproducible files
Disable writing python bytecode since those files contain timestamps,
causing unreproducible builds.

There are still other causes of unreproducibility in this package, but
this is a step in the right direction.

See #566878
2026-09-26 21:12:15 +01:00
Martin Weinelt
b73ee9f069 [staging-next] lixPackageSets.lix_2_94.lix: backport patch to always include sys/syscall.h (#566583) 2026-09-26 20:10:41 +00:00
Martin Weinelt
544eb13571 python3Packages.django: fix patch application
On master 6.1 was merged and it didn't require the patch any longer, so
it was moved from 6.x to 6.0.
2026-09-26 21:47:27 +02:00
Joshua Peek
71fa691f40 macos-defaults: 0.2.0 -> 0.3.0 2026-09-26 12:39:48 -07:00
AlexAntonik
a7d8a12d72 python3Packages.pure-magic-rs: fix license
Signed-off-by: AlexAntonik <antonikavv@gmail.com>
2026-09-26 22:26:59 +03:00
R. Ryantm
97fe25891d protonup-rs: 0.15.0 -> 0.15.1 2026-09-26 19:26:42 +00:00
Grimmauld
3d8bcf1c41 {libapparmor,apparmor-*}: add CPE 2026-09-26 21:25:58 +02:00
R. Ryantm
d44f692511 sarasa-gothic: 1.0.41 -> 1.0.42 2026-09-26 19:07:54 +00:00
Luflosi
726f5db117 python3Packages.rebiber: init at 1.3.0
https://github.com/yuchenlin/rebiber
2026-09-26 20:57:58 +02:00
Sandro Jäckel
050004990a home-assistant-custom-lovelace-modules.tankerkoenig-card: 1.8.2 -> 1.9.0
Diff: https://github.com/timmaurice/lovelace-tankerkoenig-card/compare/1.8.2...1.9.0

Changelog: https://github.com/timmaurice/lovelace-tankerkoenig-card/releases/tag/1.9.0
2026-09-26 20:56:13 +02:00
Eric Rodrigues Pires
8e67c7d2a3 ocamlPackages.sosa: fix homepage 2026-09-26 15:39:59 -03:00
Eric Rodrigues Pires
371397ae4c ocamlPackages.ocurl: fix homepage 2026-09-26 15:39:58 -03:00
R. Ryantm
bf6d9e9a57 python3Packages.tesla-protocol: 2.0.0 -> 3.0.0 2026-09-26 18:38:35 +00:00
Luflosi
ce00c9e1ae python3Packages.tsv: init at 1.2
https://github.com/adamnovak/tsv
2026-09-26 20:36:17 +02:00
nixpkgs-ci[bot]
6f1ff1ac54 Merge master into staging-nixos 2026-09-26 18:11:24 +00:00
nixpkgs-ci[bot]
4230018f6a Merge staging-next into staging 2026-09-26 18:10:51 +00:00
nixpkgs-ci[bot]
f2b3ac2ee7 Merge master into staging-next 2026-09-26 18:10:21 +00:00
Aiden Schembri
7a1e0f8969 discord: move to pkgs/by-name 2026-09-26 19:51:24 +02:00
Luke Granger-Brown
df662bdbf8 isponsorblocktv: fix with async-cache 2.x 2026-09-26 18:47:01 +01:00
Sizhe Zhao
0790a027a9 nixosTests.pocket-id: fix postgresql test
Assisted-by: Pi coding agent (gpt-5.6-sol)
2026-09-27 01:41:06 +08:00
Dee Anzorge
8b3361688d iaito: remove breakpointHook 2026-09-26 19:36:52 +02:00
Jost Alemann
14f3918529 kew: 4.3.6 -> 4.3.8
Changelog: https://codeberg.org/ravachol/kew/releases/tag/v4.3.8
Diff: https://codeberg.org/ravachol/kew/compare/v4.3.6...v4.3.8
2026-09-26 19:28:18 +02:00
Michael Daniels
32675f4b92 ci/github-script: convert various to TypeScript 2026-09-26 12:48:43 -04:00
Jo
2087f61a54 libopus: switch to fetchFromGitLab and fetch models separately (#556975) 2026-09-26 16:43:31 +00:00
Luflosi
a7c694d3d8 proj: Fix compatibility issue with mapnik
Without this change, mapnik fails to compile with the following strange error message:
```
CMake Error in CMakeLists.txt:
  No known features for C compiler

  ""

  version .
```
2026-09-26 18:20:28 +02:00
R. Ryantm
f88952e486 unifont: 17.0.05 -> 18.0.01 2026-09-26 15:55:48 +00:00
Gaetan Lepage
3f7d49579d python3Packages.orbax-checkpoint: 0.12.5 -> 0.12.6
Diff: https://github.com/google/orbax/compare/v0.12.5...v0.12.6

Changelog: https://github.com/google/orbax/blob/v0.12.6/checkpoint/CHANGELOG.md
2026-09-26 15:52:07 +00:00
R. Ryantm
7e6cdfebf7 mochi: 26.8.2 -> 26.9.2 2026-09-26 15:40:29 +00:00
R. Ryantm
4c7d183e82 todoist-cli: 5.3.6 -> 5.4.2 2026-09-26 15:36:15 +00:00
R. Ryantm
990a620715 aiken: 1.1.23 -> 1.1.24 2026-09-26 15:11:17 +00:00
Sean Buckley
ee0b669c8f brave{,-origin}: 1.95.104 -> 1.96.59
https://community.brave.app/t/release-channel-1-96-59/658731
2026-09-26 11:04:28 -04:00
R. Ryantm
9a5e044663 boilr: 1.9.6 -> 1.10.1 2026-09-26 15:01:18 +00:00
LorenzBischof
2f3ec9c471 umap: 3.7.3 -> 3.8.1
Assisted-by: Claude Code (Claude Opus 5)
2026-09-26 16:34:57 +02:00
Anund
0043340350 rocmPackages.llvm.llvm: backport patches to support arm64e_x1
PR #564039 introduced support for arm64e_x1 in base llvm. The support
required changes introduced in 22.1.0 not otherwise present in amd fork
of llvm based on 22.0.0. Backport additional patches to get allow the
patch to cleanly apply.
2026-09-27 00:15:30 +10:00
R. Ryantm
cc074fd446 git-town: 24.0.0 -> 24.1.0 2026-09-26 14:09:11 +00:00
wrench-exile-legacy
57e9bc9f54 maintainers: update wrench-exile-legacy 2026-09-26 15:01:28 +01:00
R. Ryantm
72c9531286 inspircd: 4.12.0 -> 4.12.1 2026-09-26 13:58:50 +00:00
R. Ryantm
e7a7525289 newflasher: 60 -> 61 2026-09-26 13:34:24 +00:00
R. Ryantm
242dcea3a9 ocamlPackages.unstrctrd: 0.4 -> 0.5 2026-09-26 13:24:53 +00:00
R. Ryantm
94ab58a194 folo: 1.13.0 -> 1.14.0 2026-09-26 12:54:28 +00:00
R. Ryantm
f6db2f36a2 markdownlint-cli2: 0.23.2 -> 0.23.3 2026-09-26 12:41:37 +00:00
nixpkgs-ci[bot]
47399f9b65 Merge master into staging-nixos 2026-09-26 12:13:11 +00:00
nixpkgs-ci[bot]
741e2dba5a Merge staging-next into staging 2026-09-26 12:12:40 +00:00
nixpkgs-ci[bot]
caa0ccbe11 Merge master into staging-next 2026-09-26 12:12:11 +00:00
Eric Rodrigues Pires
12ae23e533 rnm: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
1e2d73b1a9 ruri: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
7a7c6b0121 scipopt-gcg: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
4699ae7c36 seamly2d: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
db2802cebf selinux-python: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
a42f9c74cb selinux-sandbox: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
c260400540 sequelpro: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
4cfecdc2ec shc: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
8bd5de3c9d sigal: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
43b02513c1 signify: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
cf422adbfb soundfont-fluid: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
e1aefb6829 source-han-code-jp: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
634a55fadb spatial-shell: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
f3f379d458 ssdeep: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
cc13425f74 swh_lv2: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
87c8c61efe swift-quit: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
2c3f99d637 sympa: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
1a54bb30d8 t-rex: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
42366c9f1e tbox: fix homepage 2026-09-26 08:53:35 -03:00
Eric Rodrigues Pires
50694c5037 tcl: fix homepage 2026-09-26 08:53:34 -03:00
Eric Rodrigues Pires
68b8fd1445 tk: fix homepage 2026-09-26 08:52:54 -03:00
Eric Rodrigues Pires
bc78ca7beb lxsession: fix homepage 2026-09-26 07:21:15 -03:00
Eric Rodrigues Pires
946c51de52 meli: fix homepage 2026-09-26 07:21:14 -03:00
Eric Rodrigues Pires
175461cb6c ne: fix homepage 2026-09-26 07:21:14 -03:00
Eric Rodrigues Pires
b8442e5a70 mrsh: fix homepage 2026-09-26 07:21:14 -03:00
Eric Rodrigues Pires
f43d6963bb mps: fix homepage 2026-09-26 07:21:14 -03:00
R. Ryantm
f2e66a13d9 python3Packages.pycaption: 2.3.9 -> 2.3.10 2026-09-26 10:17:36 +00:00
R. Ryantm
f0de1bd980 mprisence: 1.8.5 -> 1.8.8 2026-09-26 10:06:46 +00:00
Jo
1fbf0f11ba ffado: 2.4.9 -> 2.5.0, switch to expat, remove glibmm dep (#559517) 2026-09-26 09:59:11 +00:00
Jo
88fa96498d ffmpeg: add optional support for mpeg-h decoding (#547782) 2026-09-26 09:40:54 +00:00
Jo
05db684ddb ffmpeg: add opencolorio support (#549273) 2026-09-26 09:40:47 +00:00
Jo
00c7c3381b ffmpeg: add cairo support (#547846) 2026-09-26 09:40:22 +00:00
Sergei Volkov
57d85e1387 julia_112: fix build w/ glibc-2.44 2026-09-26 11:20:11 +02:00
Sergei Volkov
f8d1733076 julia_111: fix build w/ glibc-2.44 2026-09-26 11:18:48 +02:00
Sergei Volkov
de64ab35f9 julia_110: fix build w/ glibc-2.44 2026-09-26 11:18:35 +02:00
Sefa Eyeoglu
79ca8b28e0 python3Packages.hatchling: 1.31.0 -> 1.32.0 (#554653) 2026-09-26 08:29:39 +00:00
R. Ryantm
b3749ca1e8 fromager: 0.95.0 -> 0.97.0 2026-09-26 08:21:24 +00:00
R. Ryantm
f0c93b6811 libretro.flycast: 0-unstable-2026-09-15 -> 0-unstable-2026-09-26 2026-09-26 08:17:21 +00:00
R. Ryantm
833acbe176 blackfire: 2026.9.0 -> 2026.9.1 2026-09-26 07:53:41 +00:00
R. Ryantm
de37ec1138 slint-tr-extractor: 1.17.1 -> 1.18.1 2026-09-26 07:27:09 +00:00
R. Ryantm
66ed1c3013 libretro.bsnes: 0-unstable-2026-09-04 -> 0-unstable-2026-09-19 2026-09-26 06:40:25 +00:00
nixpkgs-ci[bot]
f762d41f18 Merge master into staging-nixos 2026-09-26 06:15:49 +00:00
nixpkgs-ci[bot]
2b54e3f649 Merge staging-next into staging 2026-09-26 06:15:16 +00:00
nixpkgs-ci[bot]
d8983dda49 Merge master into staging-next 2026-09-26 06:14:39 +00:00
R. Ryantm
34972af4bd ddccontrol-db: 20260915 -> 20260922 2026-09-26 06:14:02 +00:00
Vladimír Čunát
59e609ef7e [staging-next] ghostscript: 10.07.1 -> 10.08.0 (#566918) 2026-09-26 05:15:40 +00:00
Katsumi Takeuchi
f9e4b130e6 intel-oneapi-toolkit: add recutita as maintainer 2026-09-26 13:56:44 +09:00
R. Ryantm
1464b11d5c python3Packages.graphemeu: 0.10.0 -> 0.11.0 2026-09-26 03:41:36 +00:00
Bobby Rong
308f4366d2 pix: 3.4.10 -> 3.4.11
https://github.com/linuxmint/pix/compare/3.4.10...3.4.11
2026-09-26 10:23:05 +08:00
Bobby Rong
73c648c62d xreader: 4.6.7 -> 4.6.9
https://github.com/linuxmint/xreader/compare/4.6.7...4.6.9

Fixes CVE-2026-19772.
2026-09-26 10:22:53 +08:00
Bobby Rong
472e9e61c4 xviewer: 3.4.16 -> 3.4.17
https://github.com/linuxmint/xviewer/compare/3.4.16...3.4.17
2026-09-26 10:22:53 +08:00
Bobby Rong
237afb11b7 timeshift: 25.12.4 -> 26.09.0
https://github.com/linuxmint/timeshift/compare/25.12.4...26.09.0
2026-09-26 10:17:43 +08:00
R. Ryantm
5124126497 miller: 6.21.0 -> 6.22.0 2026-09-26 01:58:25 +00:00
R. Ryantm
b5baf21591 python3Packages.denon-rs232: 4.2.2 -> 4.2.3 2026-09-26 01:51:56 +00:00
R. Ryantm
f8c5feea6b python3Packages.yaspin: 3.5.0 -> 3.5.1 2026-09-26 01:47:37 +00:00
R. Ryantm
abd011a941 hebcal: 5.15.0 -> 5.16.0 2026-09-26 01:25:51 +00:00
Michael Daniels
3e4de0bf72 python3Packages.tzdata: 2026.3 -> 2026.4 (#563404) 2026-09-26 00:58:10 +00:00
R. Ryantm
ef401924ff pycharm: 2026.2.0.1 -> 2026.2.3 2026-09-26 00:53:30 +00:00
R. Ryantm
5c5a16aec3 stashcat: 6.52.0 -> 6.54.1 2026-09-26 00:47:19 +00:00
nixpkgs-ci[bot]
00e98d9670 Merge master into staging-nixos 2026-09-26 00:43:03 +00:00
nixpkgs-ci[bot]
18ae82e73e Merge staging-next into staging 2026-09-26 00:42:32 +00:00
nixpkgs-ci[bot]
f76546e358 Merge master into staging-next 2026-09-26 00:42:01 +00:00
R. Ryantm
11809c2ecb await: 2.7.0 -> 2.8.0 2026-09-26 00:26:04 +00:00
nixpkgs-ci[bot]
8f9764a5bb Merge master into staging-nixos 2026-09-26 00:25:10 +00:00
nixpkgs-ci[bot]
157c5e989f Merge staging-next into staging 2026-09-26 00:24:38 +00:00
nixpkgs-ci[bot]
68ebbe78c9 Merge master into staging-next 2026-09-26 00:24:09 +00:00
Jan Solanti
26a4e338bd wpa_supplicant: re-add erroneously dropped patch
Rebased version of the patch taken from https://gitlab.archlinux.org/archlinux/packaging/packages/wpa_supplicant/-/blob/main/0008-Revert-Mark-authorization-completed-on-driver-indica.patch
2026-09-26 03:16:45 +03:00
Xesxen
2bbe417828 microcode-intel: 20260812 -> 20260925 2026-09-26 01:40:41 +02:00
Jared Biel
eb2d9129bd php84: 8.4.25 -> 8.4.26 2026-09-25 18:07:18 -05:00
Jared Biel
4df552d563 php82: 8.2.33 -> 8.2.34 2026-09-25 18:06:44 -05:00
Jared Biel
71445f2a5c php83: 8.3.33 -> 8.3.35 2026-09-25 18:05:48 -05:00
Eric Rodrigues Pires
d35c124368 libre-baskerville: fix homepage 2026-09-25 19:32:42 -03:00
Eric Rodrigues Pires
525cc50c78 libre-caslon: fix homepages 2026-09-25 19:32:42 -03:00
Eric Rodrigues Pires
f2ee23a017 klog: fix homepage 2026-09-25 19:32:42 -03:00
Eric Rodrigues Pires
76f0259ba9 dosis: fix homepage 2026-09-25 19:32:42 -03:00
Eric Rodrigues Pires
6de8488188 cubicsdr: fix homepage 2026-09-25 19:32:42 -03:00
Eric Rodrigues Pires
5f2cf844f5 cabin: fix homepage 2026-09-25 19:32:42 -03:00
Eric Rodrigues Pires
08ee34cfc5 brutalmaze: fix homepage 2026-09-25 19:32:42 -03:00
Eric Rodrigues Pires
31ca842746 bossa: fix homepage 2026-09-25 19:32:42 -03:00
Eric Rodrigues Pires
9fbfc8e618 audiality2: fix homepage 2026-09-25 19:32:42 -03:00
Eric Rodrigues Pires
0dc1943093 argus: fix homepage 2026-09-25 19:32:42 -03:00
Eric Rodrigues Pires
10cdd1f7fc argus-clients: fix homepage 2026-09-25 19:32:42 -03:00
Eric Rodrigues Pires
7e1f7e6130 adminirevo: fix homepage 2026-09-25 19:32:42 -03:00
Eric Rodrigues Pires
9d13d00cec analog: fix homepage 2026-09-25 19:32:42 -03:00
Jess Sullivan
cb8dac22c3 unnaturalscrollwheels: 1.4.0 -> 1.4.2
Picks up the macOS 26 sleep/wake freeze and dashboard crash fix
(tagged 1.4.1, which has no release page) and the 1.4.2 Apple Events
entitlement removal and DMG signing fix.

Changelog: https://github.com/ther0n/UnnaturalScrollWheels/releases/tag/1.4.2
Diff: https://github.com/ther0n/UnnaturalScrollWheels/compare/1.4.0...1.4.2
2026-09-25 18:23:49 -04:00
Eric Rodrigues Pires
de19cf1dcd perlPackages.Yancy: fix homepage 2026-09-25 19:13:45 -03:00
Eric Rodrigues Pires
e52ece6330 perlPackages.TemplateToolkit: fix homepage 2026-09-25 19:13:45 -03:00
Eric Rodrigues Pires
9fb179473a perlPackages.CatalystRuntime: fix homepage 2026-09-25 19:13:44 -03:00
Eric Rodrigues Pires
c373408053 perlPackages.CatalystDevel: fix homepage 2026-09-25 19:13:44 -03:00
Eric Rodrigues Pires
1c10ebde0d perlPackages.Moose: fix homepage 2026-09-25 19:13:44 -03:00
Eric Rodrigues Pires
89aadce41a perlPackages.ExporterDeclare: fix homepage 2026-09-25 19:13:44 -03:00
Eric Rodrigues Pires
c754f9557d perlPackages.FennecLite: fix homepage 2026-09-25 19:13:44 -03:00
Eric Rodrigues Pires
dcaf78e94a perlPackages.Imager: fix homepage 2026-09-25 19:13:44 -03:00
Eric Rodrigues Pires
bfcfd51f05 perlPackages.perlldap: fix homepage 2026-09-25 19:13:44 -03:00
Eric Rodrigues Pires
35567f8089 perlPackages.PerlCritic: fix homepage 2026-09-25 19:13:44 -03:00
Eric Rodrigues Pires
ebf2f3212c perlPackages.TestRunCmdLine: fix homepage 2026-09-25 19:13:44 -03:00
Eric Rodrigues Pires
5e4a1e75cd perlPackages.strictures: fix homepage 2026-09-25 19:13:44 -03:00
R. Ryantm
af6605e6df grafanaPlugins.victoriametrics-metrics-datasource: 0.25.2 -> 0.26.1 2026-09-25 22:07:18 +00:00
Eric Rodrigues Pires
6bf0faee0e ocamlPackages.apron: fix homepage 2026-09-25 19:05:33 -03:00
Eric Rodrigues Pires
89c172bdb6 ocamlPackages.piqi: fix homepage 2026-09-25 19:05:33 -03:00
Eric Rodrigues Pires
3c81ed8ddc ocamlPackages.piqi-ocaml: fix homepage 2026-09-25 19:05:33 -03:00
Eric Rodrigues Pires
12ea6e9423 ocamlPackages.sawja: fix homepage 2026-09-25 19:05:33 -03:00
Eric Rodrigues Pires
31a3582f9e ocamlPackages.ssl: fix homepage 2026-09-25 19:05:33 -03:00
Eric Rodrigues Pires
95cb4741ca ocamlPackages.xml-light: fix homepage 2026-09-25 19:05:33 -03:00
Eric Rodrigues Pires
ea09ee74b3 ocamlPackages.zmq: fix homepage 2026-09-25 19:05:33 -03:00
Martin Weinelt
db80c7a5bb jemalloc: 5.3.1 -> 5.4.0 (#566529) 2026-09-25 22:02:36 +00:00
R. Ryantm
fb9f61bf1d phpExtensions.blackfire: 2026.9.0 -> 2026.9.2 2026-09-25 22:02:15 +00:00
R. Ryantm
a387f1e5ba rbspy: 0.51.0 -> 0.53.0 2026-09-25 21:48:58 +00:00
Alexander Rezvov
1166e171ba chatzone-desktop: fix URL handling
Register the chatzone URL scheme alongside the existing mattermost scheme.
Pass URLs to the application with the %U desktop entry field code so links
opened through the desktop handler reach Chatzone.

Assisted-by: OpenAI Codex (GPT-6)
2026-09-26 00:31:33 +03:00
nixpkgs-ci[bot]
18a12247d3 libsecret: switch to gnutls (#563817) 2026-09-25 20:53:44 +00:00
R. Ryantm
099e907200 python3Packages.jh2: 5.0.13 -> 5.0.15 2026-09-25 20:29:09 +00:00
R. Ryantm
05df1ea314 xpra: 6.5.3 -> 6.5.4 2026-09-25 20:14:37 +00:00
ShouviT
c5494648d9 marktext: 0.17.0-unstable-2025-11-19 -> 0.19.1
fix pnpm/electron-builder packaging
2026-09-25 19:04:35 +00:00
nixpkgs-ci[bot]
86ad3d4fa4 Merge staging-next into staging 2026-09-25 18:11:52 +00:00
nixpkgs-ci[bot]
29dea26ec5 Merge master into staging-next 2026-09-25 18:11:16 +00:00
MithicSpirit
c24ac651a4 xwayland-satellite: 0.8.2 -> 0.8.3
https://github.com/Supreeeme/xwayland-satellite/releases/tag/v0.8.3
2026-09-25 13:50:55 -04:00
MithicSpirit
9bafacb7b2 xwayland-satellite: add mithicspirit as maintainer 2026-09-25 13:50:37 -04:00
FliegendeWurst
8fe8bd33e4 ghostscript: 10.07.1 -> 10.08.0
https://ghostscript.readthedocs.io/en/gs10.08.0/News.html
(cherry picked from commit e909f2a01d)
2026-09-25 11:58:32 -05:00
Sefa Eyeoglu
5e2fc041a4 dejavu-fonts: enable strictDeps, enable structuredAttrs (#563235) 2026-09-25 16:27:56 +00:00
Arne Keller
8e52499c98 libdeflate: 1.25 -> 1.26 (#562653) 2026-09-25 16:08:47 +00:00
R. Ryantm
29fa973b02 livekit-cli: 2.18.6 -> 2.18.8 2026-09-25 16:05:55 +00:00
R. Ryantm
4626bf6409 freescout: 1.8.235 -> 1.8.241 2026-09-25 16:05:44 +00:00
Markus Kowalewski
b6eeaa6f90 hwloc: 2.14.0 -> 2.15.0 (#566368) 2026-09-25 15:45:55 +00:00
Nick Cao
add458b2a4 alt-tab-macos: 11.4.3 -> 11.7.1 (#565925) 2026-09-25 14:46:59 +00:00
Arne Keller
62bd5ff526 bash: 5.3p15 -> 5.3p20 (#564188) 2026-09-25 14:01:53 +00:00
R. Ryantm
38f9af3886 soju: 0.11.0 -> 0.11.1 2026-09-25 13:43:29 +00:00
Lukas Epple
041e9cb7a3 utf8proc: 2.11.3 -> 2.12.0 (#566771) 2026-09-25 13:38:55 +00:00
David Pesticcio
28d56e13da doublecmd: fix lua support 2026-09-25 14:29:11 +01:00
Sandro
61a111f011 mastodon: 4.6.8 -> 4.7.2 (#554800) 2026-09-25 13:23:56 +00:00
Jan Tojnar
bfa92fa6f4 speechd: replace systemd dependency with systemdLibs (#554459) 2026-09-25 12:45:38 +00:00
nixpkgs-ci[bot]
9a48805c48 Merge staging-next into staging 2026-09-25 12:14:36 +00:00
nixpkgs-ci[bot]
6b6effb678 Merge master into staging-next 2026-09-25 12:14:03 +00:00
nixpkgs-ci[bot]
85df3ffdd4 Merge staging-next into staging 2026-09-25 11:47:42 +00:00
nixpkgs-ci[bot]
4a1c5dbf27 Merge master into staging-next 2026-09-25 11:47:11 +00:00
K900
9e79d2e5e0 Merge remote-tracking branch 'origin/master' into staging-next 2026-09-25 14:46:25 +03:00
nixpkgs-ci[bot]
f2ee868a9a Merge staging-next into staging 2026-09-25 11:44:42 +00:00
R. Ryantm
f0249a67f0 trealla: 3.10.3 -> 3.11.4 2026-09-25 11:20:20 +00:00
Ryan Omasta
eabb98b070 uhd: 4.10.0.0 -> 4.11.0.0
https://github.com/EttusResearch/uhd/releases/tag/v4.11.0.0
Diff: https://github.com/EttusResearch/uhd/compare/v4.10.0.0...v4.11.0.0
2026-09-25 04:43:18 -06:00
K900
cbe97427be rdma-core: fix up list order 2026-09-25 13:38:21 +03:00
K900
b6c8064e13 libhwy: unconditionalize patch 2026-09-25 13:38:11 +03:00
K900
21e5cb56d0 openvino: fix build on aarch64/GCC16 2026-09-25 13:30:37 +03:00
jopejoe1
5521645b2c python3Packahes.fontmake: adopt 2026-09-25 12:24:38 +02:00
jopejoe1
8859f5089e python3Packages.fontmake: clean up depencies 2026-09-25 12:24:38 +02:00
R. Ryantm
f0fe644ce1 utf8proc: 2.11.3 -> 2.12.0 2026-09-25 09:07:16 +00:00
nixpkgs-ci[bot]
3f9f124aa7 ghostscript: 10.07.1 -> 10.08.0 (#566416) 2026-09-25 07:28:15 +00:00
R. Ryantm
226c7e8b52 prl-tools: 27.0.1-58670 -> 27.0.2-58673 2026-09-25 06:20:25 +00:00
nixpkgs-ci[bot]
3752a4417b Merge staging-next into staging 2026-09-25 06:16:50 +00:00
nixpkgs-ci[bot]
98fe6aa185 Merge master into staging-next 2026-09-25 06:16:15 +00:00
Vladimír Čunát
610986fa74 clippy: separateDebugInfo only when not using 32 bit buildPlatform (#565303) 2026-09-25 05:36:08 +00:00
Bjørn Forsman
77e8b0fc4d [staging-next] libfaketime: fix build on darwin (#566671) 2026-09-25 04:44:49 +00:00
Pol Dellaiera
fd8fb4d585 [staging-next] modest: fix build with gcc 16 (#566679) 2026-09-25 04:36:29 +00:00
R. Ryantm
1e383f71a0 trezor-suite: 26.8.2 -> 26.9.2 2026-09-25 02:53:32 +00:00
Florian Franzen
a43e841f9a python3Packages.untokenize: fix build with Python 3.14 2026-09-25 04:30:49 +02:00
nixpkgs-ci[bot]
d6b3e6987d Merge staging-next into staging 2026-09-25 00:25:41 +00:00
nixpkgs-ci[bot]
180ad544ca Merge master into staging-next 2026-09-25 00:25:09 +00:00
whispers
2c4ed6d542 modest: fix build with gcc 16
failing due to unused variables and the better analysis provided in gcc
16. upstream seems very dead and unused variables *definitely* do not
seem worth patching, so let's just unconditionalize the existing
directives.
2026-09-24 19:47:43 -04:00
zowoq
fd28be2645 librist: fix darwin build (#566662) 2026-09-24 23:43:59 +00:00
zowoq
f73469d7ff [staging-next] simple-dftd3: fix build with gfortran 16 (#566309) 2026-09-24 23:43:42 +00:00
zowoq
9d33af67d5 [staging-next] dftd4: fix build with gfortran 16 (#566301) 2026-09-24 23:43:36 +00:00
zowoq
5565ce1af6 [staging-next] octomap: fix build with gcc 16 (#566300) 2026-09-24 23:43:33 +00:00
whispers
c468091956 libfaketime: fix build on darwin
another patch which doesn't apply on the older version that darwin is
on, compared to non-darwin platforms. these platform-specific versions
are extremely cursed. hopefully we can upgrade and unify soon.
2026-09-24 19:03:42 -04:00
R. Ryantm
10fb10c90c streamlink: 8.6.0 -> 8.6.1 2026-09-24 22:43:32 +00:00
Randy Eckenrode
00f1966b12 swiftPackages.{llvmPackages.libclang,swift-foundation}: fixes for staging-next breakage (#566620) 2026-09-24 22:39:15 +00:00
Martin Weinelt
94715d7aad python3Packages.psycopg: 3.3.5 -> 3.3.6 (#566638) 2026-09-24 22:29:58 +00:00
Martin Weinelt
a3bd483c99 python3Packages.psycopg: 3.3.5 -> 3.3.6
https://github.com/psycopg/psycopg/blob/3.3.6/docs/news.rst#current-release
2026-09-25 00:23:28 +02:00
zowoq
db264f2d39 librist: fix darwin build
https://hydra.nixos.org/build/346613734/step/6/log
2026-09-25 08:03:14 +10:00
Michael Daniels
4f9739eee3 dtc: unbreak on Darwin 2026-09-24 17:45:11 -04:00
R. Ryantm
80c94051d1 opa-envoy-plugin: 1.20.2-envoy -> 1.21.0-envoy 2026-09-24 20:50:09 +00:00
Martin Weinelt
09b4359c16 python3Packages.sqlalchemy: 2.0.51 -> 2.0.54 (#566634) 2026-09-24 20:46:34 +00:00
Anish Pallati
38220de882 postgresqlPackages.pgroonga: add anish as maintainer
Signed-off-by: Anish Pallati <i@anish.land>
2026-09-24 16:39:23 -04:00
Anish Pallati
73a1f269c3 postgresqlPackages.pgroonga: 4.0.5 -> 4.0.9
Signed-off-by: Anish Pallati <i@anish.land>
2026-09-24 16:39:23 -04:00
Martin Weinelt
4262cf9882 python3Packages.sqlalchemy: 2.0.51 -> 2.0.54
https://github.com/sqlalchemy/sqlalchemy/releases/tag/rel_2_0_54
2026-09-24 22:32:31 +02:00
Randy Eckenrode
847a2695a5 swiftPackages.swift-foundation: add imports needed after Glibc upgrade 2026-09-24 16:17:19 -04:00
Randy Eckenrode
4414b128b8 swiftPackages.llvmPackages.libclang: disable separate debug output
The separate debug info is huge (8+ GiB), which prevents Swift from
building on Hydra.
2026-09-24 16:17:19 -04:00
Anish Pallati
56b893cf5f groonga: add anish as maintainer
Signed-off-by: Anish Pallati <i@anish.land>
2026-09-24 16:13:41 -04:00
Anish Pallati
01ab9375cd groonga: modernize
Signed-off-by: Anish Pallati <i@anish.land>
2026-09-24 16:13:40 -04:00
Anish Pallati
24d2b721cc groonga: build stem token filter
Signed-off-by: Anish Pallati <i@anish.land>
2026-09-24 16:13:40 -04:00
Anish Pallati
652a1106de groonga: fix plugin and data install paths
Signed-off-by: Anish Pallati <i@anish.land>
2026-09-24 16:13:40 -04:00
Anish Pallati
9aa47de919 groonga: 16.1.0 -> 16.1.1
Signed-off-by: Anish Pallati <i@anish.land>
2026-09-24 16:13:40 -04:00
StepBroBD
360ffd4da4 ocaml: 5.5.0 → 5.5.1 (#566387) 2026-09-24 19:59:51 +00:00
Kerstin Humm
0c1762b45d mastodon: 4.6.8 -> 4.7.2
Changelog: https://github.com/mastodon/mastodon/releases/tag/v4.7.0
Changelog: https://github.com/mastodon/mastodon/releases/tag/v4.7.1
Changelog: https://github.com/mastodon/mastodon/releases/tag/v4.7.2
Diff: https://github.com/mastodon/mastodon/compare/v4.6.8...v4.7.2
2026-09-24 20:56:58 +02:00
nixpkgs-ci[bot]
f9c51a1640 Merge staging-next into staging 2026-09-24 18:12:15 +00:00
nixpkgs-ci[bot]
68cf20aeb9 Merge master into staging-next 2026-09-24 18:11:40 +00:00
Ben Siraphob
d67f40d544 minimal-bootstrap: don't keep build compiler by unnecessary RPATH for static-only case (#565248) 2026-09-24 17:57:05 +00:00
whispers
b33695fa51 lixPackageSets.lix_2_94.lix: backport patch to always include sys/syscall.h
failing build logs: https://hydra.nixos.org/build/346618614/log
2026-09-24 13:14:21 -04:00
Jared Biel
b3151ec883 php85: 8.5.10 -> 8.5.11 2026-09-24 11:32:19 -05:00
Arne Keller
df86a64381 [staging-next] libctemplate: fix build with gcc 16 (#566394) 2026-09-24 15:24:10 +00:00
Vladislav Grechannik
3bf5a0f631 element-web: 1.12.28 -> 1.12.29
Diff: https://github.com/element-hq/element-web/compare/v1.12.28...v1.12.29

Changelog: https://github.com/element-hq/element-web/blob/v1.12.29/CHANGELOG.md
2026-09-24 17:09:18 +02:00
Vladislav Grechannik
e0cf42a68a element-desktop: 1.12.28 -> 1.12.29
Diff: https://github.com/element-hq/element-web/compare/v1.12.28...v1.12.29

Changelog: https://github.com/element-hq/element-web/blob/v1.12.29/CHANGELOG.md
2026-09-24 16:59:41 +02:00
K900
f8b3e0beb8 libhwy: nixfmt 2026-09-24 17:51:02 +03:00
nixpkgs-ci[bot]
43a3e4c9af libpfm: 4.13.0 -> 4.14.1 (#566367) 2026-09-24 14:41:54 +00:00
K900
ef3f747b96 libhwy: backport GCC 16/aarch64 build fix 2026-09-24 17:39:23 +03:00
Martin Weinelt
dcccfa9039 jemalloc: 5.3.1 -> 5.4.0
https://github.com/jemalloc/jemalloc/compare/5.3.1...5.4.0
2026-09-24 16:17:59 +02:00
Domen Kožar
022d6b7afd libsecretspec-resolver: init at 0.21.0
Package the C11 IPC client separately from the embedded Rust-backed ABI. Use yyjson, run upstream C tests, and validate the 1.0.0 pkg-config ABI version.

https://github.com/cachix/secretspec/releases/tag/v0.21.0

Assisted-by: OpenAI Codex CLI 0.155.1 (gpt-6-sol)
Assisted-by: OpenAI Codex (GPT-6)
2026-09-24 15:34:55 +02:00
Martin Weinelt
b03df3c731 sudo: fix CVE-2026-96512 (#566451) 2026-09-24 12:59:06 +00:00
ProxyVT
50beab5ec1 ariang-native: init at 1.3.14
https://github.com/mayswind/AriaNg-Native/releases/tag/1.3.14
2026-09-24 15:55:59 +03:00
João Santos Reis
1d90cb709c aws-crt-cpp: 0.34.3 -> 0.43.6 2026-09-24 13:37:53 +01:00
João Santos Reis
cf240c5379 aws-c-sdkutils: 0.2.4 -> 1.0.0 2026-09-24 13:37:51 +01:00
João Santos Reis
a5a7fc8911 aws-c-mqtt: 0.13.3 -> 1.0.0 2026-09-24 13:37:50 +01:00
João Santos Reis
9f55b64c42 aws-c-s3: 0.8.7 -> 1.1.2 2026-09-24 13:37:49 +01:00
João Santos Reis
49146d4ab0 aws-c-event-stream: 0.7.0 -> 1.0.0 2026-09-24 13:37:48 +01:00
João Santos Reis
ba2f51c7dc aws-checksums: 0.2.7 -> 1.0.0 2026-09-24 13:37:47 +01:00
João Santos Reis
13d0fa0f05 aws-c-auth: 0.9.1 -> 1.0.0 2026-09-24 13:37:46 +01:00
João Santos Reis
24bf228407 aws-c-http: 0.11.0 -> 1.0.0 2026-09-24 13:37:45 +01:00
João Santos Reis
37bb5cc2c5 aws-c-io: 0.27.2 -> 1.0.0 2026-09-24 13:37:44 +01:00
João Santos Reis
c152cf477e aws-c-compression: 0.3.1 -> 1.0.0 2026-09-24 13:37:43 +01:00
João Santos Reis
d4f968884c aws-c-cal: 0.9.2 -> 1.0.0 2026-09-24 13:37:42 +01:00
João Santos Reis
68edea920b aws-c-common: 0.12.4 -> 1.0.0 2026-09-24 13:37:41 +01:00
K900
5f51aa724c rdma-core: disable man pages on i686
This avoids pandoc and the horrible i686 GHC bootstrap chain.
2026-09-24 15:15:00 +03:00
nixpkgs-ci[bot]
deb975ca42 Merge staging-next into staging 2026-09-24 12:14:17 +00:00
nixpkgs-ci[bot]
cb6de40acd Merge master into staging-next 2026-09-24 12:13:48 +00:00
Doron Behar
acd8291c82 python3Packages.numpy: 2.5.2 -> 2.5.3 (#565799) 2026-09-24 12:00:56 +00:00
K900
88742742cf ast-grep: 0.45.1 -> 0.45.3, skip crashing test 2026-09-24 14:25:34 +03:00
K900
8c79562ded arrow-cpp: fix build 2026-09-24 14:11:27 +03:00
Sandro Jäckel
a2c8553b8c python3Packages.django-oauth-toolkit: pin pytest-django 2026-09-24 12:56:19 +02:00
Anish Pallati
3cd64f8ce9 postgresqlPackages.tsja: enable strictDeps and __structuredAttrs
Signed-off-by: Anish Pallati <i@anish.land>
2026-09-24 06:10:46 -04:00
Anish Pallati
eeafdcf8ff buildPgrxExtension: enable __structuredAttrs
Signed-off-by: Anish Pallati <i@anish.land>
2026-09-24 06:10:46 -04:00
Anish Pallati
ca68cfa5d0 postgresqlBuildExtension: enable __structuredAttrs
Signed-off-by: Anish Pallati <i@anish.land>
2026-09-24 06:10:45 -04:00
Sandro Jäckel
61ca019b98 python3Packages.django-vtasks: 3.1.0 -> 3.2.0
Diff: https://gitlab.com/glitchtip/django-vtasks/-/compare/v3.1.0...3.2.0

Changelog: https://gitlab.com/glitchtip/django-vtasks/-/releases/v3.2.0
2026-09-24 11:46:21 +02:00
Sandro Jäckel
ead03a0e51 python3Packages.django-valkey: pin pytest-django 2026-09-24 11:46:20 +02:00
Sandro Jäckel
cbe7aa8aca python3Packages.pytest-django_4_12: init at 4.12.0
The 4.13.0/4.14.0 updates have breaking changes many applications need
to adjust their test suite around.
2026-09-24 11:46:20 +02:00
Ryan Hendrickson
ce287a157d sudo: fix CVE-2026-96512 2026-09-24 05:41:03 -04:00
Vladimír Čunát
d063a7a600 [staging-next] onnxruntime: fix build with gcc 16 (#566340) 2026-09-24 09:08:48 +00:00
Vladimír Čunát
7038f59f63 darwin.ICU: ensure that check phase uses C++17 with GCC 16 (#566365) 2026-09-24 09:00:02 +00:00
Vladimír Čunát
47d82011cf [staging-next] _7zz: make array-bounds non-fatal for gcc 16 (#551961) 2026-09-24 08:58:21 +00:00
FliegendeWurst
e909f2a01d ghostscript: 10.07.1 -> 10.08.0
https://ghostscript.readthedocs.io/en/gs10.08.0/News.html
2026-09-24 10:03:50 +02:00
Aleksi Hannula
1257758291 minimal-bootstrap.libiberty: init at 16.2.0 2026-09-24 09:39:42 +03:00
Aleksi Hannula
0dd62f7a21 minimal-bootstrap.libbacktrace: init at 16.2.0 2026-09-24 09:39:42 +03:00
Aleksi Hannula
78fc51f896 minimal-bootstrap.lib{gmp,mpc,mpfr}: build with GCC 10
In a previous PR, I mistakenly added them as compiled with gcc-latest.
However, we want to link gcc-latest against these packages.
2026-09-24 09:39:42 +03:00
Aleksi Hannula
804b8a84fa minimal-bootstrap.gcc10: Use wrapper 2026-09-24 09:39:42 +03:00
Aleksi Hannula
1f0dd24d5e minimal-bootstrap: Configurable dynamic linker and static-libgcc in GCC wrapper
The configuration can be automated once proper cross-compilation
infrastructure is added.
2026-09-24 09:39:41 +03:00
Aleksi Hannula
5820092cde minimal-bootstrap.gcc*: Add GCC wrapper test 2026-09-24 09:39:41 +03:00
Aleksi Hannula
65056060c2 minimal-bootstrap.gcc10: Unify lib and lib64 2026-09-24 09:39:41 +03:00
K900
acd757ca78 tg_owt: 0-unstable-2026-08-03 -> 0-unstable-2026-09-23
Fixes build with GCC 16
2026-09-24 09:37:56 +03:00
nixpkgs-ci[bot]
c9f8a79ae6 Merge staging-next into staging 2026-09-24 06:16:44 +00:00
nixpkgs-ci[bot]
b80dc4626f Merge master into staging-next 2026-09-24 06:16:13 +00:00
Anish Pallati
9d5173db31 nixosTests.postgresql.wal2json: fix broken test
Signed-off-by: Anish Pallati <i@anish.land>
2026-09-24 01:27:33 -04:00
Anish Pallati
3703849be5 postgresqlPackages.pg_squeeze: fix broken test
Signed-off-by: Anish Pallati <i@anish.land>
2026-09-24 01:21:38 -04:00
whispers
befb599323 libctemplate: fix build with gcc 16
fetch 5aa5a00e74
from upstream to fix the build with gcc 16, as it defaults to C++20 and
triggers this failure.
2026-09-24 00:58:34 -04:00
Domen Kožar
665bc767c3 libsecretspec: rename secretspec-ffi and update to 0.21.0
Follow the upstream native library rename, update cargo-c targets and pkg-config tests, and retain secretspec-ffi as a package alias. Document the native consumer migration in the 26.11 release notes.

https://github.com/cachix/secretspec/releases/tag/v0.21.0

Assisted-by: OpenAI Codex CLI 0.155.1 (gpt-6-sol)
2026-09-24 06:33:10 +02:00
Vincent Laporte
413a7e8d2e ocaml: 5.5.0 → 5.5.1 2026-09-24 06:13:30 +02:00
crertel
fab8bd8cf9 supercollider-with-plugins: fix plugin discovery
Assisted-by: Codex (GPT-6)
2026-09-23 21:38:36 -05:00
R. Ryantm
43b940b7f9 hwloc: 2.14.0 -> 2.15.0 2026-09-24 00:56:41 +00:00
R. Ryantm
71960067f6 libpfm: 4.13.0 -> 4.14.1 2026-09-24 00:52:01 +00:00
nixpkgs-ci[bot]
16b3da48f4 Merge staging-next into staging 2026-09-24 00:24:27 +00:00
nixpkgs-ci[bot]
ac6d0781b3 Merge master into staging-next 2026-09-24 00:23:53 +00:00
Randy Eckenrode
19f5caf5b8 darwin.ICU: ensure that check phase uses C++17 with GCC 16
Even though ICU uses C++17 to build the main library, it doesn’t use it
to build its tests even though it needs it there too.
2026-09-23 20:19:23 -04:00
kyehn
9021890b04 mycli: 1.44.2 -> 2.20.0 2026-09-24 00:12:05 +00:00
kyehn
80398a84a2 python3Packages.clickdc: init at 0.1.1 2026-09-24 00:10:52 +00:00
gregory langlais
e20afc048e paq: add gregl83 as maintainer 2026-09-23 16:19:28 -07:00
gregory langlais
bd8ef45bbe maintainers: add gregl83 2026-09-23 16:19:24 -07:00
Sandro Jäckel
d35cf6bf04 paperless-ngx: 3.1.3 -> 3.2.1
Changelog: https://github.com/paperless-ngx/paperless-ngx/releases/tag/v3.2.0
Changelog: https://github.com/paperless-ngx/paperless-ngx/releases/tag/v3.2.1
Diff: https://github.com/paperless-ngx/paperless-ngx/compare/v3.1.3...v3.2.1
2026-09-24 01:15:47 +02:00
Sandro Jäckel
d414ec5c0a python3Packages.whoosh-compat: init at 0.3.0 2026-09-24 01:15:46 +02:00
Sandro Jäckel
4b11cb9798 python3Packages.tika-client: 0.11.0 -> 1.0.0
Changelog: https://github.com/stumpylog/tika-client/releases/tag/1.0.0
Diff: https://github.com/stumpylog/tika-client/compare/0.11.0...1.0.0
2026-09-24 01:15:44 +02:00
Sandro Jäckel
c91a3c98b3 python3Packages.pytest-django: 4.12.0 -> 4.14.0
Changelog: https://github.com/pytest-dev/pytest-django/blob/v4.14.0/docs/changelog.rst
2026-09-24 01:15:42 +02:00
Sandro Jäckel
b7dc0c64b3 python3Packages.gotenberg-client: 0.14.0 -> 1.0.0
Changelog: https://github.com/stumpylog/gotenberg-client/releases/tag/1.0.0
Diff: https://github.com/stumpylog/gotenberg-client/compare/0.14.0...1.0.0
2026-09-24 01:15:40 +02:00
whispers
d4f7712743 onnxruntime: fix build with gcc 16
GCC 16 implemented P0952R2, which changes the output of libstdc++'s
std::generate_canonical. Some of onnxruntime('s tests) rely on this old
behavior, so we restore the old behavior with the provided macro. Based
on a fix suggested by upstream.
2026-09-23 17:39:36 -04:00
whispers
d9efac4aa6 afflib: fix build with gcc 16
libafflib.so fails to link due to undefined references when using GCC 16.
2026-09-23 16:35:41 -04:00
whispers
0ceab93737 libofx: fix build with gcc 16
C++20 changes the signature of std::allocator::allocate. We vendor a
patch from an approved PR to fix this.
2026-09-23 16:24:19 -04:00
whispers
d84fecd622 simple-dftd3: fix build with gfortran 16
set_model_ghost_index was not declared as part of the public api,
leading to link errors with gfortran 16.

we would submit this contribution upstream, but they disallow
contributions under pseudonyms, which is a dealbreaker for us. if
someone else wants to, they are welcome to.
2026-09-23 16:16:06 -04:00
whispers
9dfa02e055 dftd4: fix build with gfortran 16
get_numerical_hessian was not declared as part of the public API,
leading to link errors with gfortran 16.
2026-09-23 15:46:26 -04:00
whispers
bd0c483e8d octomap: fix build with gcc 16
d7e54ca1c4
didn't make it into the 1.10.1 release, so this mention is still there.
it's gone on `devel`.

reverts part of 02dfb7e346.
2026-09-23 15:39:51 -04:00
K900
8c5535ccbe Merge remote-tracking branch 'origin/master' into staging-next 2026-09-23 22:10:24 +03:00
dish
683d24b5cf ytmdesktop: fix 2026-09-23 14:44:17 -04:00
dish
5decb4dc33 Merge remote-tracking branch 'upstream/master' into staging-next 2026-09-23 14:43:01 -04:00
nixpkgs-ci[bot]
b3556016d7 Merge staging-next into staging 2026-09-23 18:12:51 +00:00
K900
8f4e237d1e [staging-next] apache-orc: explicitly specify C++17 for abseil-cpp (#545413) 2026-09-23 16:48:31 +00:00
Peder Bergebakken Sundt
f2fa49e0b4 python3Packages.unidiff: 1.0.0 -> 1.0.1 (#564287) 2026-09-23 14:34:45 +00:00
Peder Bergebakken Sundt
4be519d2eb guileImportsCheckHook: init and convert various (#562657) 2026-09-23 13:10:39 +00:00
Francesco Gazzetta
12be4dc500 tclPackages.rl_json: use tclRequiresCheck 2026-09-23 14:53:08 +02:00
Francesco Gazzetta
fee414494c tcl.tclRequiresCheckHook: refer to tclsh by absolute path
Without this, tcl has to be put in nativeBuildInputs or the hook fails.
2026-09-23 14:52:29 +02:00
Bobby Rong
371994986d spidermonkey_140: 140.14.0 -> 140.16.0 (#562862) 2026-09-23 12:50:27 +00:00
whispers
004c7af167 gcc13: 13.4.0 -> 13.5.0
https://sourceware.org/pipermail/gcc/2026-September/248876.html
2026-09-23 08:39:10 -04:00
R. Ryantm
ec69a11809 spidermonkey_140: 140.14.0 -> 140.16.0 2026-09-23 12:30:01 +00:00
nixpkgs-ci[bot]
39c31fb32f Merge staging-next into staging 2026-09-23 12:14:37 +00:00
nixpkgs-ci[bot]
f01d304834 Merge master into staging-next 2026-09-23 12:14:01 +00:00
éclairevoyant
c1c2d69eb1 alt-tab-macos: 11.4.3 -> 11.7.1 2026-09-23 07:49:26 -04:00
whispers
81a876d818 _7zz: make array-bounds non-fatal for gcc 16
GCC 16 fails due to what is ostensibly an out-of-bounds read, but it is
introduced by GCC's own optimizations; building with -O0 or -fno-inline
does not trigger a failure. Possibly related GCC bug:
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=122197

example build failure: https://hydra.nixos.org/build/339161854/log
2026-09-23 07:31:00 -04:00
whispers
edadff5d41 apache-orc: explicitly specify C++17 for abseil-cpp
abseil exposes different interfaces depending on what is available in
`std` in a given C++ standard. gcc 16 defaults to C++20, thus causing
the default abseil-cpp to expose a different interface than the one
apache-orc (built with C++17) expects. this leads to a
great deal of "error: 'partial_ordering' has not been declared in 'std'"
and similar originating from abseil's types/compare.h. thus, we
explicitly override abseil to specify the desired C++ standard. this
happens through protobuf as abseil-cpp is in its propagatedBuildInputs.
2026-09-23 07:03:36 -04:00
Jonas Heinrich
2d7a50d7b1 stalwart_0_16: 0.16.22 -> 0.16.23 2026-09-23 12:44:33 +02:00
Jonas Heinrich
7bf182434f stalwart_0_16.spam-filter: 3.0.1 -> 3.0.2 2026-09-23 12:44:24 +02:00
Jonas Heinrich
00cec4ce53 stalwart_0_16.webui: 1.0.10 -> 1.0.11 2026-09-23 12:44:15 +02:00
R. Ryantm
601187e09c libvlc: 3.0.23-2 -> 3.0.24 2026-09-23 09:18:10 +00:00
nixpkgs-ci[bot]
23669631b0 Merge staging-next into staging 2026-09-23 09:08:29 +00:00
K900
c8e07dbf29 Merge remote-tracking branch 'origin/master' into staging-next 2026-09-23 12:07:12 +03:00
nixpkgs-ci[bot]
a7bcbad6fc Merge staging-next into staging 2026-09-23 09:04:42 +00:00
R. Ryantm
913b6c23f4 graphify: 0.9.61 -> 0.9.66 2026-09-23 08:12:21 +00:00
Vladimír Čunát
5eb6bca452 Merge branch 'staging' into staging-next 2026-09-23 08:58:19 +02:00
Vladimír Čunát
91a6c86270 multiple-outputs.sh: Fix propagatedBuildOutputs and structuredAttrs (#553979) 2026-09-23 06:46:51 +00:00
Vladimír Čunát
d036ae7c8c libaom: 3.12.1 -> 3.14.0 (#521697) 2026-09-23 06:41:44 +00:00
Vladimír Čunát
99db7938f5 libaom: fixup outputs in *.cmake
Now libheif builds for me with this atop nixpkgs master.
2026-09-23 08:34:41 +02:00
Vladimír Čunát
18aa80589a xdg-dbus-proxy: 0.1.7 -> 0.1.8 (#551476) 2026-09-23 06:27:21 +00:00
nixpkgs-ci[bot]
3fe38cd422 Merge staging-next into staging 2026-09-23 06:16:27 +00:00
nixpkgs-ci[bot]
bc8a4a0bce Merge master into staging-next 2026-09-23 06:15:59 +00:00
Vladimír Čunát
0f1e6334ca thrift: 0.22.0 -> 0.24.0 (#514296) 2026-09-23 06:10:48 +00:00
Vladimír Čunát
db3a3c0e87 glibc: 2.42-84 -> 2.44-25 (#557451) 2026-09-23 05:31:03 +00:00
Vladimír Čunát
b311f651df meson: 1.12.0 -> 1.12.1 (#566033) 2026-09-23 04:21:25 +00:00
R. Ryantm
5fc9e6f089 wine-staging: 11.16 -> 11.18 2026-09-23 03:08:17 +00:00
nixpkgs-ci[bot]
30c38cd0fd Merge staging-next into staging 2026-09-23 00:23:50 +00:00
nixpkgs-ci[bot]
4a5b5ca7a5 Merge master into staging-next 2026-09-23 00:23:21 +00:00
nixpkgs-ci[bot]
412594867b openexr: 3.4.15 -> 3.5.0 (#565776) 2026-09-22 23:18:45 +00:00
whispers
45d94985cd meson: 1.12.0 -> 1.12.1
https://github.com/mesonbuild/meson/compare/1.12.0...1.12.1
https://github.com/mesonbuild/meson/milestone/139
2026-09-22 19:05:09 -04:00
Martin Weinelt
c5c6708aea nss: 3.128 -> 3.129 (#563453) 2026-09-22 22:26:57 +00:00
Michael Daniels
59615fcc9b less: 704 -> 710 (#564373) 2026-09-22 21:24:20 +00:00
dmkhitaryan
00a5e0d24d yacreader: 10.0.0 -> 10.3.1 2026-09-23 01:16:16 +04:00
nixpkgs-ci[bot]
05100b0144 libheif: 1.23.4 -> 1.23.5 (#565908) 2026-09-22 21:03:58 +00:00
Antonis Kotronakis
e2497c3a52 nixos/beszel-agent: enable zfs monitoring support 2026-09-23 00:02:31 +03:00
Shawn8901
e705852165 epson-escpr2: 1.2.37 -> 1.2.42 2026-09-22 21:38:18 +02:00
Shawn8901
87dd924db8 epson-escpr2: drop update script and clear user agent for fetchurl
Epson seems to have started blocking download tools like curl & wget,
see https://aur.archlinux.org/packages/epson-inkjet-printer-escpr2#comment-1067163
2026-09-22 21:36:00 +02:00
R. Ryantm
36d55ca837 mattermostLatest: 11.10.2 -> 11.11.0 2026-09-22 18:41:39 +00:00
nixpkgs-ci[bot]
11d0bd7aac Merge staging-next into staging 2026-09-22 18:12:32 +00:00
nixpkgs-ci[bot]
9a6118ccdd Merge master into staging-next 2026-09-22 18:11:56 +00:00
Ethan Carter Edwards
3564c9c95b doc/guileImportsCheckHook: init hook docs in manual
Signed-off-by: Ethan Carter Edwards <ethan@ethancedwards.com>
2026-09-22 13:44:34 -04:00
Ethan Carter Edwards
419deb3220 guile-commonmark: use guileImportsCheckHook
Signed-off-by: Ethan Carter Edwards <ethan@ethancedwards.com>
2026-09-22 13:44:33 -04:00
Ethan Carter Edwards
b1436e0634 guile-json: use guileImportsCheckHook
Converted to a structuredAttrs consumer

Signed-off-by: Ethan Carter Edwards <ethan@ethancedwards.com>
2026-09-22 13:44:33 -04:00
Ethan Carter Edwards
e80f238f98 guile-git: use guileImportsCheckHook
Signed-off-by: Ethan Carter Edwards <ethan@ethancedwards.com>
2026-09-22 13:44:32 -04:00
Ethan Carter Edwards
aa633dff01 guile*: cleanup, propagate guileImportsCheckHook
Removing coverageAnalysis was discussed on Matrix with xokdvium.
It isn't used anymore.

Signed-off-by: Ethan Carter Edwards <ethan@ethancedwards.com>
2026-09-22 13:44:32 -04:00
Ethan Carter Edwards
abecc61150 guileImportsCheckHook: init
This hook should function similar to how pythonImportsCheck functions in
buildPythonApplication or buildPythonPackage.

Signed-off-by: Ethan Carter Edwards <ethan@ethancedwards.com>
2026-09-22 13:44:32 -04:00
Thomas Bemme
c47c6eafcb librewolf-unwrapped: 156.0-1 -> 156.0.1-1 2026-09-22 18:07:49 +02:00
Vladimír Čunát
fb971edc63 libheif: 1.23.4 -> 1.23.5
https://github.com/strukturag/libheif/releases/tag/v1.23.5
2026-09-22 18:00:14 +02:00
Francesco Gazzetta
18229a2de6 tcl,tk: set mainProgram (#565607) 2026-09-22 15:30:59 +00:00
Francesco Gazzetta
80593a46eb tcl.tclRequiresCheckHook: move tcl code from heredoc to a separate file (#562547) 2026-09-22 15:04:31 +00:00
Vladimír Čunát
68cebc3848 [staging] gnupg: update freepg patches to source-2.4.9-freepg-1 (#562774) 2026-09-22 14:59:50 +00:00
K900
63368e65a2 expat: 2.8.4 -> 2.8.5 (#565868) 2026-09-22 14:34:20 +00:00
Adam C. Stephens
6dd5adf4e7 mobilizon: drop unnecessary cmake dependency
fast_html already defines this in override.
mix hook changes allowed cmake hook changes to run, which fail because it's unneeded.
2026-09-22 10:23:50 -04:00
Adam C. Stephens
5cfa15f65b beam hooks: add targeted auxiliary hook opt-outs
Assisted-By: OpenAI Codex GPT-6 Astra
2026-09-22 10:23:50 -04:00
Adam C. Stephens
eb7233903a beamPackages.mixBuildDirHook: skip empty library paths and unmatched globs 2026-09-22 10:23:50 -04:00
Adam C. Stephens
e79e45b0ce beamPackages.mixRelease: move fixup to mixReleaseSetupHook
Assisted-By: OpenAI Codex GPT-6 Astra
2026-09-22 10:23:50 -04:00
Adam C. Stephens
2ff9ee32fb beamPackages.mixRelease: extract mixDepsCompileHook 2026-09-22 10:23:50 -04:00
Adam C. Stephens
16f22d7599 beamPackages.mixRelease: extract mixNixDepsSetupHook 2026-09-22 10:23:50 -04:00
K900
b2e5a7c32e expat: 2.8.4 -> 2.8.5 2026-09-22 17:22:26 +03:00
Vladimír Čunát
2aef6e14b5 libaom: 3.14.1 -> 3.15.0
https://aomedia.googlesource.com/aom/+/refs/tags/v3.15.0
Fixes: CVE-2026-56209 CVE-2026-13906
2026-09-22 16:20:28 +02:00
Vladimír Čunát
e951f968cf Unbound: 1.26.0 -> 1.26.1 (#564725) 2026-09-22 14:14:49 +00:00
Amadeus Mader
e7cbd8815e nixos/nebula: move tunless test to existing test 2026-09-22 15:41:19 +02:00
nixpkgs-ci[bot]
6eeb94e60f Merge staging-next into staging 2026-09-22 12:13:53 +00:00
nixpkgs-ci[bot]
4faa76a1b3 Merge master into staging-next 2026-09-22 12:13:21 +00:00
Alexis Hildebrandt
4a80decdc3 remind: 06.02.10 -> 06.03.04 2026-09-22 13:59:58 +02:00
Alexis Hildebrandt
1b46221907 remind: Replace gitUpdate with custom update script 2026-09-22 13:59:48 +02:00
Vladimír Čunát
64a75b0ee2 poppler: 26.06.0 -> 26.09.0 (#548228) 2026-09-22 11:58:42 +00:00
Doron Behar
395b9dc4a7 utf8cpp: 4.2.0 -> 4.2.1 (#565324) 2026-09-22 09:04:43 +00:00
Doron Behar
93cff4293a openmpi: fix hash (#565506) 2026-09-22 09:04:07 +00:00
Vladimír Čunát
33fe94c98d memcached: 1.6.42 -> 1.6.45 (#538111) 2026-09-22 08:38:50 +00:00
R. Ryantm
9e15d22f16 libpcap: 1.10.6 -> 1.10.7
Taken from history of PR #560539
2026-09-22 10:33:09 +02:00
R. Ryantm
302fc0370d openexr: 3.4.15 -> 3.5.0 2026-09-22 08:27:55 +00:00
Vladimír Čunát
7915e43d2e cups: patch CVE-2026-87875 and CVE-2026-87876 (#563047) 2026-09-22 08:25:14 +00:00
Vladimír Čunát
15f3405d02 gcc: 15 -> 16 (#537781) 2026-09-22 08:04:16 +00:00
nixpkgs-ci[bot]
9ea0129e94 Merge staging-next into staging 2026-09-22 06:16:12 +00:00
nixpkgs-ci[bot]
054ea70695 Merge master into staging-next 2026-09-22 06:15:41 +00:00
Adam C. Stephens
556f308bb5 beamPackages.mixRelease: extract mixFodDepsSetupHook 2026-09-21 23:02:37 -04:00
Adam C. Stephens
71cfdbc359 beamPackages.mixRelease: use writableTmpDirAsHomeHook 2026-09-21 23:02:36 -04:00
Adam C. Stephens
ab47a5d584 beamPackages.mixRelease: extract mixReleaseSetupHook
Assisted-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-21 23:02:35 -04:00
Adam C. Stephens
44323b5dcd beamPackages.mixRelease: extract mixEscriptSetupHook
Assisted-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-21 23:02:33 -04:00
Will Fancher
13eb807de6 systemd: 261.2 -> 261.3 (#565130) 2026-09-22 01:28:58 +00:00
nixpkgs-ci[bot]
9ffbab3cc1 Merge staging-next into staging 2026-09-22 00:25:06 +00:00
nixpkgs-ci[bot]
3e9f9df37d Merge master into staging-next 2026-09-22 00:24:35 +00:00
Emily
ee3490eb46 gn: 0-unstable-2026-07-23 -> 0-unstable-2026-08-14 (#564454) 2026-09-21 22:43:18 +00:00
Martin Weinelt
c6bd42decc frigate: 0.17.2 -> 0.18.0 (#541441) 2026-09-21 20:35:03 +00:00
Martin Weinelt
61d7bf9e97 openvino: build cpu plugin on aarch64-linux
We need to substitute the gcc-ar and gcc-ranlib path as otherwise the
build scripts for ARM ComputeLibrary are finding the wrong ar/ranlib
executables which breaks at link time.
2026-09-21 22:03:21 +02:00
Martin Weinelt
182e420ecc python3Packages.filterpy: fix scipy 1.12 deprecation warnings 2026-09-21 22:03:20 +02:00
Martin Weinelt
b453b6ed6c nixos/frigate: harden runtime execution environment 2026-09-21 22:03:20 +02:00
Martin Weinelt
aa1b83e8ea frigate: extract models into models attribute tree
This creates dedicated attributes per model and exposes a `model` and a
optionally a `labelmap` attribute where useful. The idea is to collect
model build plans to make them easily accessible and referencable in your
configurations.

The explicit idea is not to cache on cache.nixos.org, because they are
usually readily availalbe as FODs or just require light conversions that
everyone should be able to handle on their own machine or build pipeline.

This now also packages the converted ssdlite mobilnet v2 model for
OpenVINO based setups, though I would recommend looking into YOLO models
at this time.
2026-09-21 22:03:20 +02:00
Martin Weinelt
71deb719ea frigate: 0.17.2 -> 0.18.0 2026-09-21 22:03:19 +02:00
Pavol Rusnak
922797b5e0 python3Packages.libusb1: 3.3.1 -> 3.4.0 (#565601) 2026-09-21 19:18:11 +00:00
nixpkgs-ci[bot]
9d857ecf8a Merge staging-next into staging 2026-09-21 18:11:25 +00:00
nixpkgs-ci[bot]
6713268fd8 Merge master into staging-next 2026-09-21 18:10:54 +00:00
Martin Weinelt
9a01c06e97 python3Packages.django_5: skip flaky test (#565609) 2026-09-21 17:26:36 +00:00
Martin Weinelt
b3f4f11e7e python3Packages.django_5: skip flaky test
The test checks performance and easily fails under cpu pressure.
2026-09-21 19:18:51 +02:00
Francesco Gazzetta
7382f70aa3 tk: set mainProgram 2026-09-21 19:11:23 +02:00
Francesco Gazzetta
e102e2a10b tcl: set mainProgram 2026-09-21 19:11:06 +02:00
rnhmjoj
85dcfcc36f python3Packages.libusb1: 3.3.1 -> 3.4.0 2026-09-21 18:15:45 +02:00
sempiternal-aurora
7d32cab9b4 gnucobol: enable __structuredAttrs 2026-09-21 17:48:46 +02:00
sempiternal-aurora
009b2db5bb multiple-outputs.sh: fix with structuredAttrs
The variable `propagatedBuildOutputs` was only allowed to be a string,
so when `__structuredAttrs = true` was set, it was incorrectly detected,
especially for empty arrays. Refactor the code to allow it to be either
an array or string.

Closes: #323126
2026-09-21 17:48:46 +02:00
Ryan Burns
6d0a1ae720 srtp: 2.8.0 -> 2.8.1 (#565458) 2026-09-21 15:24:45 +00:00
Will Fancher
c3c2644b50 nixos/tests/systemd-shutdown: Test pre-exitrd shutdown scripts 2026-09-21 11:13:57 -04:00
Will Fancher
5931105883 nixos/test-driver: Add timeout to wait_for_shutdown 2026-09-21 11:13:28 -04:00
Francesco Gazzetta
af9977e4c5 tcl.tclRequiresCheckHook: move tcl code from heredoc to a separate file
A heredoc piped into tclsh makes tclsh run in interactive mode, which
keeps running regardless of errors. This required us to `catch` the
error and `exit` manually. By using a standalone script we avoid this
hack and the error gets automatically printed out.

With a standalone file we also get better editor support.
2026-09-21 15:40:49 +02:00
Ilan Joselevich
c3d9063e08 nginxModules.otel: init at 0.1.2
Assisted-by: Claude:claude-fable-5-1
2026-09-21 14:56:41 +02:00
Ilan Joselevich
dba0cf96a9 opentelemetry-cpp: expose opentelemetry-proto in passthru
Assisted-by: Claude:claude-fable-5-1
2026-09-21 14:49:31 +02:00
Ilan Joselevich
315b3cde54 nginx: let modules override the nginx derivation
A module that brings cmake needs dontUseCmakeConfigure set on nginx,
which the existing per-module attributes can't express.

Assisted-by: Claude:claude-fable-5-1
2026-09-21 14:49:16 +02:00
Ilan Joselevich
bf651830a9 nginx: let modules provide nativeBuildInputs
Some modules run their own build system from their config script and
need build tools in the nginx build.

Assisted-by: Claude:claude-fable-5-1
2026-09-21 14:48:14 +02:00
nixpkgs-ci[bot]
a64560e505 Merge staging-next into staging 2026-09-21 12:14:05 +00:00
nixpkgs-ci[bot]
5a11e87acc Merge master into staging-next 2026-09-21 12:13:34 +00:00
Markus Kowalewski
a7da5b25d1 openmpi: fix hash 2026-09-21 13:16:00 +02:00
Amadeus Mader
a2fbe4fa45 nixos/nebula: fix inverted tun.device length assertion
Resolves #565467.

Assisted-by: OpenCode (kimi-k3)
2026-09-21 12:54:00 +02:00
Anders Kaseorg
e9258a46a0 zulip: 5.13.1 → 5.13.2
Signed-off-by: Anders Kaseorg <andersk@mit.edu>
2026-09-21 03:19:52 -07:00
nixpkgs-ci[bot]
3a69921b0a azurite: 3.35.0 -> 3.37.0 (#558594) 2026-09-21 10:00:58 +00:00
R. Ryantm
526ece09f4 srtp: 2.8.0 -> 2.8.1 2026-09-21 08:33:47 +00:00
Thomas Butter
b05968103a subnetcalc: 2.6.6 -> 2.7.5 2026-09-21 07:28:38 +00:00
nixpkgs-ci[bot]
bf644a7888 Merge staging-next into staging 2026-09-21 06:21:24 +00:00
nixpkgs-ci[bot]
906569520b Merge master into staging-next 2026-09-21 06:20:53 +00:00
Sigmanificient
4ef493125b various: inline meta.homepage in src url 2026-09-21 04:25:01 +02:00
Ryan Hendrickson
e33cf59dea haskell.compiler: apply LLVM split sections fix unconditionally (#556637) 2026-09-21 00:26:53 +00:00
nixpkgs-ci[bot]
e583ea4a3b Merge master into staging-next 2026-09-21 00:26:53 +00:00
Ryan Hendrickson
4a3bdbb942 gtk4: backport Wayland session cleanup null check (#544742) 2026-09-21 00:24:16 +00:00
nixpkgs-ci[bot]
b7ab04901e Merge staging-next into staging 2026-09-21 00:27:24 +00:00
Randy Eckenrode
29698dbb12 swift.swiftArch, swift.swiftOs: fix the eval (#565323) 2026-09-20 23:38:59 +00:00
Skye Soss
29616af295 nixos/accounts-daemon: add nss module path to service
The accounts-daemon service looks up user accounts, so it needs access
to the NSS shared libraries.
2026-09-20 18:03:20 -05:00
Skye Soss
2db5041958 nixos/account-utils: add nss module path to pwaccessd
The pwaccessd service looks up passwords with getspent, which the nscd
socket protocol does not handle.
2026-09-20 18:01:47 -05:00
Sergei Trofimovich
3c034ce443 utf8cpp: 4.2.0 -> 4.2.1
Changes: https://github.com/nemtrif/utfcpp/releases/tag/v4.2.1
2026-09-20 21:00:45 +01:00
Sergei Trofimovich
bb0f35f8a0 swift.swiftArch, swift.swiftOs: fix the eval
Without the chnage the eval fails as:

    $ nix eval 'nixpkgs/staging#swift.swiftArch'
    error:
       … in the left operand of the update (//) operator
         at «github:NixOS/nixpkgs/9cfde996e4f874e9b58a0e9efb5193d565b6daf3»/lib/derivations.nix:265:8:
          264|     drv
          265|     // mapAttrs (_: lib.warn msg) drvToWrap
             |        ^
          266|     // (

       … while calling the 'mapAttrs' builtin
         at «github:NixOS/nixpkgs/9cfde996e4f874e9b58a0e9efb5193d565b6daf3»/lib/derivations.nix:265:8:
          264|     drv
          265|     // mapAttrs (_: lib.warn msg) drvToWrap
             |        ^
          266|     // (

       (stack trace truncated; use '--show-trace' to show the full, detailed trace)

       error: expected a set but found a string: "x86_64"
2026-09-20 20:47:59 +01:00
Ben Siraphob
0a4346fbea minimal-bootstrap: separate musl tools from runtime (#565293) 2026-09-20 19:40:47 +00:00
matthewcroughan
69b1bbcc1c clippy: separateDebugInfo only when not using 32 bit buildPlatform
There are issues with memory allocation on 32 bit buildPlatforms that are resolved by not using this option
2026-09-20 19:51:38 +01:00
nixpkgs-ci[bot]
9cfde996e4 Merge staging-next into staging 2026-09-20 18:10:45 +00:00
Ben Siraphob
005d5f2d18 minimal-bootstrap: header installation should not retain build-time bash and sed 2026-09-20 11:10:27 -07:00
Ben Siraphob
db3241d439 minimal-bootstrap: separate musl tools from runtime 2026-09-20 11:10:27 -07:00
nixpkgs-ci[bot]
294444c6b3 Merge master into staging-next 2026-09-20 18:10:14 +00:00
dramforever
83a31a3822 stdenv-bootstrap-tools: Fix lib*_asneeded problem on gcc16
GCC 16 added and starts using -latomic_asneeded and -lgcc_s_asneeded to
pull in the corresponding libraries as if --as-needed. Add these linker
scripts.

After fixing this, gcc in turn wants libatomic, so reuse the existing
line copying it for riscv, and use it for all platforms.

See https://gcc.gnu.org/bugzilla/show_bug.cgi?id=123650 for why this was
added.

(cherry picked from commit cd01953447)
2026-09-20 11:13:42 -04:00
whispers
a1eee2b35c gcc: 15 -> 16
changes: https://gcc.gnu.org/gcc-16/changes.html
porting guide: https://gcc.gnu.org/gcc-16/porting_to.html
2026-09-20 11:13:41 -04:00
whispers
4632343d62 minimal-bootstrap.gcc-glibc: 15.3.0 -> 16.2.0
https://gcc.gnu.org/gcc-16/changes.html
2026-09-20 11:13:39 -04:00
whispers
188f6b434a minimal-bootstrap.gcc-latest: 15.3.0 -> 16.2.0
https://gcc.gnu.org/gcc-16/changes.html
2026-09-20 11:13:37 -04:00
Ben Siraphob
5bdfec15ed minimal-bootstrap: don't keep build compiler by unnecessary RPATH for static-only case 2026-09-20 07:20:25 -07:00
Doron Behar
05f5a3586f file: add self as co-maintainer, add test, use versionCheckHook (#565106) 2026-09-20 14:10:30 +00:00
nixpkgs-ci[bot]
e21d7705d5 Merge staging-next into staging 2026-09-20 12:12:39 +00:00
nixpkgs-ci[bot]
79dca5c171 Merge master into staging-next 2026-09-20 12:12:07 +00:00
Stefan Frijters
3593228682 rustc: fix unpatched shebangs (#564735) 2026-09-20 10:07:05 +00:00
Jonas Heinrich
3e78b1bdde euro-office-desktopeditors: init at 9.3.1-dev.1 2026-09-20 11:03:17 +02:00
Rafael Ieda
32f1472e0e gradm: mark as broken on aarch64-linux (last successful Hydra build 2018) 2026-09-20 03:32:09 -03:00
nixpkgs-ci[bot]
8da4489bc8 Merge staging-next into staging 2026-09-20 06:14:26 +00:00
nixpkgs-ci[bot]
bb7535f586 Merge master into staging-next 2026-09-20 06:13:57 +00:00
Thomas Butter
705d6da161 kubernetes-polaris: 10.1.7 -> 10.2.5 2026-09-20 05:20:06 +00:00
Will Fancher
2bae9f4d18 systemd: 261.2 -> 261.3 2026-09-20 00:18:02 -04:00
Michael Daniels
93fd013de3 file: use versionCheckHook 2026-09-19 22:15:58 -04:00
Michael Daniels
b41e03e2d5 file: always run tests 2026-09-19 22:15:17 -04:00
Michael Daniels
780932049b file: add musl build to passthru.tests 2026-09-19 22:15:15 -04:00
Martin Weinelt
fc5a4e2b58 [staging] onetbb: fix nullptr deref in hwloc probe (#565075) 2026-09-20 01:46:14 +00:00
zowoq
21ff5242f3 mimalloc: 3.4.5 -> 3.5.3 (#557848) 2026-09-20 01:14:00 +00:00
nixpkgs-ci[bot]
9dc31ff839 Merge staging-next into staging 2026-09-20 00:27:50 +00:00
nixpkgs-ci[bot]
0e14e38a34 Merge master into staging-next 2026-09-20 00:27:14 +00:00
Martin Weinelt
e19b7d221a onetbb: fix nullptr deref in hwloc probe
This fixes OpenVINO CPU plugin initialization in the Nix sandbox.
2026-09-20 01:52:01 +02:00
R. Ryantm
dabf496cd0 mimalloc: 3.4.5 -> 3.5.3 2026-09-19 23:03:53 +00:00
R. Ryantm
5886ee1551 python3Packages.pyinstaller: 6.22.2 -> 6.22.3 2026-09-19 21:24:04 +00:00
Lukas Epple
6819cbce30 python3Packages.defcon: migrate to pyproject (#560844) 2026-09-19 19:26:49 +00:00
Michael Daniels
ebb9ee0fef file: add mdaniels5757 as co-maintainer 2026-09-19 14:15:39 -04:00
nixpkgs-ci[bot]
65cffdd771 Merge staging-next into staging 2026-09-19 18:10:18 +00:00
nixpkgs-ci[bot]
f8a29a4f3c Merge master into staging-next 2026-09-19 18:09:48 +00:00
Stefan Frijters
7675d2397a libsigcxx*: add explicit version suffix to attr, enable structuredAttrs and strictDeps, move to pkgs/by-name (#560126) 2026-09-19 17:28:52 +00:00
Antoine du Hamel
1a75fb7d3d nodejs: use shared simdutf only on versions that do not force-use the… (#564657) 2026-09-19 16:51:58 +00:00
Vladimír Čunát
e50b783f78 ibus: fix crashes with latest gtk (#562818) 2026-09-19 15:37:56 +00:00
R. Ryantm
bee24f10cb easyrsa: 3.2.6 -> 3.2.7 2026-09-19 15:00:34 +00:00
Maximilian Bosch
91c3fb7d5a zutty: mark as broken
Failing Hydra build: https://hydra.nixos.org/build/344291345
No upstream fix available.
2026-09-19 16:44:03 +02:00
Maximilian Bosch
85f87c51d6 electron_42: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344146127

Electron 43+ have a Chromium codebase that is new enough to contain the
patch in question.
2026-09-19 16:44:03 +02:00
Maximilian Bosch
12773d25e7 linux_6_1: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344163800

The full commit[1] doesn't apply on 6.1, so I ported the only relevant
portion to it.

Backport is currently pending[2] (as I've noticed after hand-rolling
this patch), so for now we're only applying what we actually need.

[1] https://lore.kernel.org/r/20251206092825.1471385-1-mikhail.v.gavrilov@gmail.com
[2] https://lore.kernel.org/all/2026051315-engorge-agreed-39cb@gregkh/
2026-09-19 16:44:03 +02:00
Maximilian Bosch
256511bd01 clickhouse: fix build w/ glibc-2.44
`struct open_how` is actually defined now, even though the value is set
to false.

Failing Hydra build: https://hydra.nixos.org/build/344143757
2026-09-19 16:44:03 +02:00
Maximilian Bosch
ee3cffdbb7 guacamole-server: 1.6.0-unstable-2025-06-29 -> 1.6.0-unstable-2026-08-16
Fixes build w/ glibc-2.44.

Failing Hydra build: https://hydra.nixos.org/build/344150990
2026-09-19 16:44:03 +02:00
Maximilian Bosch
19863a81d5 mimic: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344168963
2026-09-19 16:44:02 +02:00
Maximilian Bosch
f5757270ac papi: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344174835/log
2026-09-19 16:44:02 +02:00
Maximilian Bosch
6e4c64d6de liquidwar: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344166064
2026-09-19 16:44:02 +02:00
Maximilian Bosch
b9cbf8617f orbuculum: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344174435
2026-09-19 16:44:02 +02:00
Maximilian Bosch
c3ff0d0313 fnc: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344147213
2026-09-19 16:44:02 +02:00
Maximilian Bosch
b4cd20c95b openvas-scanner: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344174370
2026-09-19 16:44:01 +02:00
Maximilian Bosch
26da0e8d57 odp-dpdk: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344173889
2026-09-19 16:44:01 +02:00
Maximilian Bosch
0560882502 alsa-scarlett-gui: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344140166
2026-09-19 16:44:01 +02:00
Maximilian Bosch
743f1ebcdd helix.tree-sitter-grammars.tree-sitter-perl: fix build w/ glibc-2.44
`bsearch` being a macro causes a syntax error on compilation. I'm
letting the maintainers do an upgrade, for now we remove the custom
bsearch implementation and let it use the glibc-provided one.

Failing Hydra build: https://hydra.nixos.org/build/344158900/step/91/log
2026-09-19 16:44:01 +02:00
Maximilian Bosch
ada787547f picolibc: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344179652
2026-09-19 16:44:01 +02:00
Maximilian Bosch
09d8101a4f pspp: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344181613
2026-09-19 16:44:00 +02:00
Maximilian Bosch
bae8a721d9 ulfius: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344467071
2026-09-19 16:44:00 +02:00
Maximilian Bosch
01aced593b j: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344160462
2026-09-19 16:44:00 +02:00
Maximilian Bosch
3e6711e178 ats2: fix build w/ glibc-2.42
Failing Hydra build: https://hydra.nixos.org/build/344140882

`bsearch` is a macro now, so the `extern`-definition leads to a syntax
error. Not going to find out how to use sourceforge to send that though 🤷
2026-09-19 16:44:00 +02:00
Maximilian Bosch
9e2084eb15 xfstests: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344216601
2026-09-19 16:44:00 +02:00
Maximilian Bosch
bc0eb86a1a open-vm-tools: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344174037

This package builds fine on the base of this branch, so it's somehow
related to the glibc change, I'm just not understanding how.

Anyways, the issue is that `g_free` is a macro in glib (NOT glibc) and
was expanded in here leading to a syntax error. Removing this line
entirely fixes the issue for us.
2026-09-19 16:43:59 +02:00
Maximilian Bosch
0706a24d11 mitscheme: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344290710

_POSIX_C_SOURCE is defined in an already imported glibc header. Since
that's used to enable newer C extensions and the code is still building
fine, we're just removing the definition from the package's source-code.
2026-09-19 16:43:59 +02:00
Maximilian Bosch
03a5c683bf mysql-shell_{8,9}: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344169786
2026-09-19 16:43:59 +02:00
Maximilian Bosch
8929e07ea1 pesign: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344178917
2026-09-19 16:43:59 +02:00
Maximilian Bosch
ceec2dc3b9 hexcurse: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344158921
2026-09-19 16:43:59 +02:00
Maximilian Bosch
9266a746c1 xbps: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344216369
2026-09-19 16:43:58 +02:00
Maximilian Bosch
9a4883041b virt-viewer: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344467073
2026-09-19 16:43:58 +02:00
Maximilian Bosch
744a98d733 odyssey: fix build w/ glibc-2.44 2026-09-19 16:43:58 +02:00
Maximilian Bosch
f2926847c4 livegrep: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344166092
2026-09-19 16:43:58 +02:00
Maximilian Bosch
a71a62a7b0 zookeeper_mt: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344217319
2026-09-19 16:43:58 +02:00
Maximilian Bosch
e3d7bc3b83 ctx: drop
Unmaintained and not updated in three years. Also doesn't build with
latest glibc anymore.

Failing Hydra build: https://hydra.nixos.org/build/344144642
2026-09-19 16:43:57 +02:00
Maximilian Bosch
ba0ad70bd4 ntp: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344170903
2026-09-19 16:43:57 +02:00
Maximilian Bosch
48484b56c7 tuxpaint: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344213768

While the same patch is also upstream[1], I didn't really get how to
extract .patch files from sourceforge, so I used the Gentoo vendored
patch instead, contents are the same.

[1] 6271edecec/
2026-09-19 16:43:57 +02:00
Maximilian Bosch
d097fa8774 odhcp6c: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344173898
2026-09-19 16:43:57 +02:00
Maximilian Bosch
d288e330d6 ipv6calc: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344160376
2026-09-19 16:43:57 +02:00
Maximilian Bosch
1eff3c1301 thunderbird-140: mark as broken
Failing Hydra build: https://hydra.nixos.org/build/344212797

Same issue as with Firefox 140 esr and likely equally painful to fix,
however the new ESR 153 is out already and it's an ESR for 5 out of 12
weeks when 140 is likely being put EOL[1].

[1] https://support.mozilla.org/en-US/kb/thunderbird-esr
2026-09-19 16:43:56 +02:00
Maximilian Bosch
315030e076 vg: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344214471
2026-09-19 16:43:56 +02:00
Maximilian Bosch
705c45b212 libmongocrypt: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344162914
2026-09-19 16:43:56 +02:00
Maximilian Bosch
c6497b9e94 bees: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344141697
2026-09-19 16:43:56 +02:00
Maximilian Bosch
8594a5e0d8 firefox-esr-140: mark as broken
Failing Hydra build: https://hydra.nixos.org/build/344146962

Fixing that is a can of worms:

* There's a patch for the original compiler error[1], however the source
  hashes in the source-tree must be updated manually since that's a
  one-line JSON and that part of the patch doesn't apply.

* Only to discover that there's subsequent breakage.

Given that this is EOL by the end of month[2], fixing that doesn't seem
like well-invested time to me.

[1] https://bugzilla.mozilla.org/show_bug.cgi?id=2030493
[2] https://endoflife.date/firefox
2026-09-19 16:43:56 +02:00
Maximilian Bosch
e563ad1ecd surge-xt: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344209629
2026-09-19 16:43:55 +02:00
Maximilian Bosch
cd8332cd80 pacemaker: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344174583
2026-09-19 16:43:55 +02:00
Maximilian Bosch
758a42843e x16-emulator: fix build w/ glibc-2.44 2026-09-19 16:43:55 +02:00
Maximilian Bosch
137f6183e1 orcania: fix build w/ glibc-2.44
ChangeLog: https://hydra.nixos.org/build/344174427
2026-09-19 16:43:55 +02:00
Maximilian Bosch
c90629a831 ocf-resource-agents: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344173775
2026-09-19 16:43:55 +02:00
Maximilian Bosch
e78e07e061 futility: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344147650
2026-09-19 16:43:54 +02:00
Maximilian Bosch
b50f76ac40 spice-vdagent: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344209099
2026-09-19 16:43:54 +02:00
Maximilian Bosch
75cda6b87d fyi: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344147678
2026-09-19 16:43:54 +02:00
Maximilian Bosch
5f33626ac6 diod: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344145191
2026-09-19 16:43:54 +02:00
Maximilian Bosch
2b9386ea43 beanstalkd: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344141671
2026-09-19 16:43:54 +02:00
Maximilian Bosch
e82ce26603 ngn-k: drop
Upstream's readme claims:

> this k implementation is no longer supported

Failing Hydra build: https://hydra.nixos.org/build/344170285
2026-09-19 16:43:54 +02:00
Maximilian Bosch
cb312659e0 vboot-utils: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344214375
2026-09-19 16:43:53 +02:00
Maximilian Bosch
d80776b6f1 loudmouth: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344166707
2026-09-19 16:43:53 +02:00
Maximilian Bosch
815ed5f9a7 cdecl: mark as broken
Failing Hydra build: https://hydra.nixos.org/build/344142755
2026-09-19 16:43:53 +02:00
Maximilian Bosch
f6b4893f16 urweb: fix build w/ glibc-2.44
ChangeLog: https://hydra.nixos.org/build/344214226
2026-09-19 16:43:53 +02:00
Maximilian Bosch
852dab931e convimg: mark as broken
Failing Hydra build: https://hydra.nixos.org/build/344144152

The culprit is in a 10 years old git submodule 🫠
2026-09-19 16:43:53 +02:00
Maximilian Bosch
58dc9df41c libbladeRF: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344162454
2026-09-19 16:43:52 +02:00
Maximilian Bosch
6d1f6ca228 links2: mark as broken
Failing Hydra build: https://hydra.nixos.org/build/344163770

Code-golfing to do

    if (strchr(cast_const_char ud, POST_CHAR)) *strchr(cast_const_char ud, POST_CHAR) = 0;

means we can't workaround the failure with
-Wno-error=discarded-qualifiers like we did for every other package.

Also, upstream doesn't use any forge, so I'm not going to bother
patching this 🤷
2026-09-19 16:43:52 +02:00
Maximilian Bosch
a065432188 criu: fix build w/ glibc-2.44
ChangeLog: https://hydra.nixos.org/build/344144517
2026-09-19 16:43:52 +02:00
Maximilian Bosch
6d10055041 cowsql: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344144419
2026-09-19 16:43:52 +02:00
Maximilian Bosch
829921e643 dragmap: drop
Failing Hydra build: https://hydra.nixos.org/build/344145730

Repo is archived as well.
2026-09-19 16:43:52 +02:00
Maximilian Bosch
ac80cd0e95 trurl: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344213650
2026-09-19 16:43:51 +02:00
Maximilian Bosch
2036e92086 mir_2_15: mark as broken
It's deeply questionable that this exists in the first place, this
release is three years old now.

For the sake of not ripping out a full desktop environment[1], I'm leaving
it in for now.

Failing Hydra build: https://hydra.nixos.org/build/344169110

[1] Lomiri and the build fails with `pkgs.mir`
2026-09-19 16:43:51 +02:00
Maximilian Bosch
80c900a82e libbpf_0: drop
Doesn't build with glibc 2.44 and hasn't seen a release in four years.
Suricata builds fine with pkgs.libbpf.
2026-09-19 16:43:51 +02:00
Maximilian Bosch
52724515a3 termpaint: fix build w/ glibc-2.44
ChangeLog: https://hydra.nixos.org/build/344210222
2026-09-19 16:43:51 +02:00
Maximilian Bosch
ce4117f12e ucode: fix build w/ glibc-2.44
Also apply two more bugfixes to correctly apply the patch fixing the
issue.

Failing Hydra build: https://hydra.nixos.org/build/344213888
2026-09-19 16:43:50 +02:00
Maximilian Bosch
facdfe4dab target-isns: fix build w/ glibc-2.44
ChangeLog: https://hydra.nixos.org/build/344209981
2026-09-19 16:43:50 +02:00
Maximilian Bosch
4b4ab89855 tayga: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344210014
2026-09-19 16:43:50 +02:00
Maximilian Bosch
342e877fdd aerospike: fix build w/ glibc-2.44
Failing Hydra build: https://hydra.nixos.org/build/344139672
2026-09-19 16:43:50 +02:00
Maximilian Bosch
67bbac951c libfaketime: fix build w/ glibc-2.44
Failing Hydra Build: https://hydra.nixos.org/build/344162647

I'm aware that there's a 0.9.13 containing this patch, but given the
fallout according to the comment, i.e.

> 0.9.10 break dict-db-wiktionary and quartus-prime-lite on linux,
> and 0.9.11 break everything on darwin

I'm not going to look into this and pick the easy route for now, i.e.
fixing the fallout of glibc which is what I'm here for.
2026-09-19 16:43:50 +02:00
Maximilian Bosch
1e23b1be78 glibc: 2.42-84 -> 2.44-25
Announcements:
* https://inbox.sourceware.org/libc-announce/13932477.uLZWGnKmhe@pinacolada/T/#u
* https://inbox.sourceware.org/libc-announce/teaVXxrfQH2qv0xBul7sXg@gentoo.org/T/#u

Closes #502924
2026-09-19 16:43:49 +02:00
Maximilian Bosch
31bb833ca2 python3Packages.mypy: fix build w/ glibc-2.44
Otherwiwse a bunch of tests break with
"warning: ‘_POSIX_C_SOURCE’ redefined".

Apparently this now happens, if software doesn't adhere to the rule of
`Python.h` having to be included first[1]. The applied patch focuses on
Python 3.15 support, but also happens to fix that.

[1] https://bugzilla.redhat.com/show_bug.cgi?id=2416110
2026-09-19 16:43:49 +02:00
Maximilian Bosch
9c912cb797 sane-backends: fix build w/ glibc-2.44
Co-authored-by: Philip Taron <philip.taron@gmail.com>
2026-09-19 16:43:49 +02:00
Maximilian Bosch
53c393eb11 ldb: fix build w/ glibc-2.44
Co-authored-by: Philip Taron <philip.taron@gmail.com>
2026-09-19 16:43:49 +02:00
Maximilian Bosch
abc74b463f efivar: fix build w/ glibc-2.44 2026-09-19 16:43:49 +02:00
Maximilian Bosch
efa476934e kvmtool: fix build w/ glibc-2.44 2026-09-19 16:43:48 +02:00
Maximilian Bosch
1a0a983791 krb5: fix build w/ glibc-2.44
Co-authored-by: Philip Taron <philip.taron@gmail.com>
2026-09-19 16:43:48 +02:00
Maximilian Bosch
db8336f9f1 librist: fix build w/ glibc-2.44
Co-authored-by: Philip Taron <philip.taron@gmail.com>
2026-09-19 16:43:48 +02:00
Maximilian Bosch
00b73f9854 dtc: fix build w/ glibc-2.44
Co-authored-by: Philip Taron <philip.taron@gmail.com>
2026-09-19 16:43:48 +02:00
Maximilian Bosch
03290f6370 grub2: fix build w/ glibc-2.44
Co-authored-by: Philip Taron <philip.taron@gmail.com>
2026-09-19 16:43:48 +02:00
Maximilian Bosch
9149e326c5 minimal-bootstrap.glibc-headers: 2.42 -> 2.44 2026-09-19 16:43:47 +02:00
Nico Felbinger
12e424e1f6 netboxPlugins.netbox-sqids: init at 0.2.0 2026-09-19 15:18:33 +02:00
Thomas Butter
5d5b93d56b cheat: 4.5.0 -> 5.1.0 2026-09-19 12:59:28 +00:00
nixpkgs-ci[bot]
1fa0257af6 pahole: 1.31 -> 1.32 (#564776) 2026-09-19 12:29:35 +00:00
nixpkgs-ci[bot]
147cfbe222 Merge staging-next into staging 2026-09-19 12:13:07 +00:00
nixpkgs-ci[bot]
a04c5001c0 Merge master into staging-next 2026-09-19 12:12:38 +00:00
Xesxen
102ab2b793 unbound: 1.26.0 -> 1.26.1 2026-09-19 12:34:31 +02:00
Rachala Raj
2370c1b281 bibata-caelestia: init at 0-unstable-2026-09-05
Assisted-by: Antigravity (Gemini 3.8 Flash)
2026-09-19 13:33:40 +05:30
nixpkgs-ci[bot]
e7d03f4564 Merge staging-next into staging 2026-09-19 06:14:33 +00:00
nixpkgs-ci[bot]
3879c6a694 Merge master into staging-next 2026-09-19 06:14:04 +00:00
R. Ryantm
b8fa6d27a5 pahole: 1.31 -> 1.32 2026-09-19 03:52:35 +00:00
nixpkgs-ci[bot]
0b6ffb4835 Merge staging-next into staging 2026-09-19 02:13:26 +00:00
nixpkgs-ci[bot]
080f58f21b Merge master into staging-next 2026-09-19 02:12:56 +00:00
nixpkgs-ci[bot]
0961751e87 Merge staging-next into staging 2026-09-19 00:24:19 +00:00
nixpkgs-ci[bot]
f77f951d9f Merge master into staging-next 2026-09-19 00:23:48 +00:00
Stefan Frijters
81c20cfd8c rustc: fix unpatched shebangs 2026-09-19 00:30:17 +02:00
Elias Khanzada
906ded2f2e gnome-mahjongg: enable tests
Assisted-by: Claude Code (model: Claude Opus 5, claude-opus-5)
2026-09-18 14:01:32 -07:00
Elias Khanzada
cd8b8156e0 gnome-mahjongg: 49.1.1 -> 51.0
Assisted-by: Claude Code (model: Claude Opus 5, claude-opus-5)
2026-09-18 13:59:11 -07:00
Stefan Frijters
970588e7e0 gtk-doc: fix unpatched shebang, modernize (#564567) 2026-09-18 20:23:18 +00:00
nixpkgs-ci[bot]
87a62769b7 Merge staging-next into staging 2026-09-18 18:11:13 +00:00
nixpkgs-ci[bot]
a5a4067a98 Merge master into staging-next 2026-09-18 18:10:40 +00:00
Nico Felbinger
e972c5f42e netboxPlugins.netbox-notices: init at 1.3.0 2026-09-18 19:24:19 +02:00
Nico Felbinger
a042edd23a netboxPlugins.netbox-cable-labels: init at 0.1.0 2026-09-18 19:23:49 +02:00
Antoine du Hamel
eaed4506c4 nodejs: use shared simdutf only on versions that do not force-use the vendored one 2026-09-18 18:54:14 +02:00
R. Ryantm
fc4fa266db python3Packages.xml-marshaller: 1.0.2 -> 1.0.3 2026-09-18 16:01:28 +00:00
Grimmauld
e48e4af429 ffado: libxmlxx3 -> expat, remove glibmm 2026-09-18 17:40:50 +02:00
Grimmauld
ee8cfe4f57 ffado: 2.4.9 -> 2.5.0 2026-09-18 17:40:21 +02:00
R. Ryantm
f71af341cd python3Packages.pytapo: 3.4.18 -> 3.4.19 2026-09-18 15:29:17 +00:00
Maximilian Bosch
55b4fee88a minimal-bootstrap: glibc 2.42 -> 2.44 2026-09-18 16:30:08 +02:00
Stefan Frijters
4d1bee9f38 tclPackages.expect{,_5}: fix unpatched shebangs for bash scripts (#564577) 2026-09-18 13:26:42 +00:00
Stefan Frijters
72bbb59dc9 tclPackages.expect_5: modernize
We don't need explicit strictDeps, mkTclDerivation takes care of that.
2026-09-18 14:42:49 +02:00
Stefan Frijters
8291cd3378 tclModules.expect_5: fix unpatched bash scripts 2026-09-18 14:38:37 +02:00
Stefan Frijters
060acb0434 tclModules.expect: fix unpatched bash scripts 2026-09-18 14:38:34 +02:00
Stefan Frijters
26c3ff7b21 gtk-doc: modernize
Explicit strictDeps is not needed, this is set by buildPythonApplication.
2026-09-18 14:15:05 +02:00
Stefan Frijters
a244bf2117 gtk-doc: patch interpreter line for gtkdocize 2026-09-18 14:15:01 +02:00
nixpkgs-ci[bot]
bd369297a6 Merge staging-next into staging 2026-09-18 12:13:47 +00:00
nixpkgs-ci[bot]
8489ccd0d0 Merge master into staging-next 2026-09-18 12:13:13 +00:00
Randy Eckenrode
5e98dfece6 apple-sdk_27: init at 27.0 (#564039) 2026-09-18 10:43:55 +00:00
kirillrdy
061a79e319 protobuf: 36.1 -> 36.2 (#564481) 2026-09-18 09:50:55 +00:00
Gaetan Lepage
913b78ec5c protobuf: 36.1 -> 36.2
Diff: https://github.com/protocolbuffers/protobuf/compare/v36.1...v36.2

Changelog: https://github.com/protocolbuffers/protobuf/releases/tag/v36.2
2026-09-18 09:35:26 +00:00
Stefan Frijters
4de1b5aaa8 texinfo: update file path for 7.3 (#564283) 2026-09-18 08:59:28 +00:00
Stefan Frijters
0322005c1d tzdata: fix unpatched shebang (#564219) 2026-09-18 08:59:06 +00:00
Stefan Frijters
7762aa429c llvmPackages.clang-tools: use bash for wrapper (#563394) 2026-09-18 08:57:37 +00:00
Yt
3475f3c012 python3Packages.httpcore2: fix riscv64-linux build (#560527) 2026-09-18 08:14:32 +00:00
sempiternal-aurora
927856c7c3 apple-sdk: add tests for different versions 2026-09-18 09:11:24 +02:00
sempiternal-aurora
041da8cd78 apple-sdk_27: init at 27.0 2026-09-18 09:11:24 +02:00
sempiternal-aurora
4b9403aca7 apple-sdk_{14,15,26}: remove callPackage to by-name in all-packages
A nice to do clean-up that brings things into a style I've done before.
Does cause the sdks to be built with an earlier stage, but otherwise
doesn't seem to cause any breakages.
2026-09-18 09:11:24 +02:00
sempiternal-aurora
bbf0d88475 llvmPackages.llvm: add support for arm64e.x1 subtype
Apple added a new CPU subtype with the macOS 27 sdk, which describes
CPUs with extra pointer authentication features. The apple A20 and M6
chips have this subtype, and code in the new macOS 27 sdk needs the
compiler toolchain to be able to handle these architectures, so that it
can be linked against.
2026-09-18 09:11:22 +02:00
R. Ryantm
e434096805 gn: 0-unstable-2026-07-23 -> 0-unstable-2026-08-14 2026-09-18 06:31:02 +00:00
nixpkgs-ci[bot]
c184c86b77 Merge staging-next into staging 2026-09-18 06:16:01 +00:00
nixpkgs-ci[bot]
b6fdaa44f8 Merge master into staging-next 2026-09-18 06:15:29 +00:00
@mjones
494e2dd289 util-linux: do not run unnecessary autoreconf (#562148) 2026-09-18 04:15:48 +00:00
Austin Horstman
7b6bd159cc makeBinaryWrapper: ignore prefix/suffix empty segment check for LUA_PATH/LUA_CPATH (#564274) 2026-09-18 02:38:54 +00:00
nixpkgs-ci[bot]
dd0a641804 Merge staging-next into staging 2026-09-18 00:24:51 +00:00
nixpkgs-ci[bot]
ef215a382d Merge master into staging-next 2026-09-18 00:24:10 +00:00
Michael Daniels
fb0f7b5e70 less: 704 -> 710
Changelog: https://www.greenwoodsoftware.com/less/news.710.html
2026-09-17 19:14:08 -04:00
Thomas Mühlbacher
5bf21ff317 llvmPackages.clang-tools: add test for clang-tidy
While the wrapper's bash script was broken, clang-tidy would have failed
to check a project with an include such as assert.h because it wouldn't
have been able to find that header file.
2026-09-17 20:28:32 +02:00
Thomas Mühlbacher
c37c7bbcdb llvmPackages.clang-tools: use correct shell shebang
This wrapper is factually a bash script and should therefore use the
correct shebang instead of relying on the leniency of the bash POSIX
mode.
2026-09-17 20:28:32 +02:00
Thomas Mühlbacher
247f4425b9 llvmPackages.clang-tools: ensure wrapper uses bash
The wrapper script relies on features only available with bash, namely
arithmetic evaluation as in `while (( $# )); do`. So let's ensure that
the shebang is patched to use bash. (bash's POSIX `sh` evaluates this as
intended.)

A minimal reproducer with a project that generally ought to pass
clang-tidy checking may look like so:

```nix
{
  pkgs ? import <nixpkgs> { },
}:
pkgs.fwupd.overrideAttrs (
  final: prev: {
    nativeBuildInputs = prev.nativeBuildInputs ++ [ pkgs.clang-tools ];
    preCheck = ''
      ninja clang-tidy
    '';
  }
)
```

Before, you may see many errors about missing headers and some lines
that suspiciously look like bash errors.

```
fwupd> >>> /nix/store/gf6qdh329rc8lbby710r9rzhwqkkgv3h-clang-tools-21.1.8/bin/clang-tidy --use-color -quiet -p /build/source/build /build/source/plugins/uf2/fu-self-test.c
fwupd> /nix/store/gf6qdh329rc8lbby710r9rzhwqkkgv3h-clang-tools-21.1.8/bin/clang-tidy: line 5: 129: not found
fwupd> /nix/store/gf6qdh329rc8lbby710r9rzhwqkkgv3h-clang-tools-21.1.8/bin/clang-tidy: line 23: 129: not found
fwupd> 276 warnings and 1 error generated.
fwupd> Error while processing /build/source/plugins/uf2/fu-self-test.c.
fwupd> /nix/store/dm7fg33sqnjxkwdpirnnbnx7wyi89m82-glib-2.88.3-dev/include/glib-2.0/glib/gtypes.h:41:10: error: 'time.h' file not found [clang-diagnostic-error]
fwupd>    41 | #include <time.h>
fwupd>       |          ^~~~~~~~
```

With this change, these clang-tidy errors no longer appear.
2026-09-17 20:15:07 +02:00
nixpkgs-ci[bot]
152f4985fc Merge staging-next into staging 2026-09-17 18:11:25 +00:00
nixpkgs-ci[bot]
ba9b3359a7 Merge master into staging-next 2026-09-17 18:10:58 +00:00
Peder Bergebakken Sundt
7eb70d9acd python3Packages.unidiff: 1.0.0 -> 1.0.1
Changelog: https://github.com/matiasb/python-unidiff/raw/v1.0.1/HISTORY
2026-09-17 18:57:41 +02:00
Adam C. Stephens
95437efd1d openssl: downgrade default to 3.5 LTS (#564262) 2026-09-17 16:36:40 +00:00
Stefan Frijters
1cb8cf0cd5 texinfo: update file path for 7.3
The whole tp directory was renamed to tta in
https://cgit.git.savannah.gnu.org/cgit/texinfo.git/commit/?h=release/7.3&id=c692ff501fe7c346f548a9e61ecd13bb0ab5a3b7
2026-09-17 18:32:08 +02:00
Thomas Gerbet
d3c88870e9 makeBinaryWrapper: ignore prefix/suffix empty segment check for LUA_PATH/LUA_CPATH
These are not an issue with Lua, we can allowlist them.

This should resolve the neovim build issue reported in https://github.com/NixOS/nixpkgs/pull/548442#issuecomment-5709248256
2026-09-17 16:14:26 +00:00
Adam C. Stephens
edee310e8f openssl: downgrade default to 3.5 LTS
3.6.x will go out of support in November before branch off.
I suggest this is a simpler change than trying to bring all of the
tree up to 4.x. It's likely that some packages may need to manually
specify such.
2026-09-17 11:30:20 -04:00
Stefan Frijters
ef4cbb9d84 tzdata: fix unpatched shebang
Regression after setting strictDeps = true;
2026-09-17 16:00:47 +02:00
nixpkgs-ci[bot]
c8649eaf2d Merge master into staging-next 2026-09-17 12:13:47 +00:00
K900
dae954bbdf pipewire: 1.6.8 -> 1.6.9 (#564190) 2026-09-17 12:12:47 +00:00
nixpkgs-ci[bot]
3b65b53073 Merge staging-next into staging 2026-09-17 12:14:18 +00:00
Marie Ramlow
0693729d34 chunkfs: port to fuse 3 2026-09-17 14:04:50 +02:00
K900
cd205bf477 pipewire: 1.6.8 -> 1.6.9
Diff: https://gitlab.freedesktop.org/pipewire/pipewire/-/compare/1.6.8...1.6.9

Changelog: https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.9
2026-09-17 14:55:58 +03:00
kataokatsuki
802aba3710 bash: 5.3p15 -> 5.3p20 2026-09-17 20:48:15 +09:00
Leonard Sheng Sheng Lee
34e29fbe99 px0: init at 0.1.4
Package `px0`, a fast, ultra-light, remote-first IDE for instant
code navigation and review in the browser. Built from source using
`buildGoModule`; pure Go with no CGO or external dependencies.

Signed-off-by: Leonard Sheng Sheng Lee <305414+sheeeng@users.noreply.github.com>
2026-09-17 12:03:02 +02:00
Marie Ramlow
7089858463 masterpdfeditor: use archive.org as a fallback 2026-09-17 09:58:06 +02:00
nixpkgs-ci[bot]
c496893b23 Merge staging-next into staging 2026-09-17 06:16:42 +00:00
nixpkgs-ci[bot]
fc3d38ef07 Merge master into staging-next 2026-09-17 06:16:13 +00:00
nixpkgs-ci[bot]
f6001f38f7 Merge staging-next into staging 2026-09-17 06:01:31 +00:00
nixpkgs-ci[bot]
f5d1035747 Merge master into staging-next 2026-09-17 06:00:59 +00:00
R. Ryantm
fc60e89bb9 python3Packages.python-gammu: 3.2.4 -> 3.5.0 2026-09-17 04:34:41 +00:00
Michael Daniels
ce4ff022d5 Merge remote-tracking branch 'upstream/staging-next' into staging 2026-09-16 22:29:47 -04:00
Tristan Ross
61b71b7fea libimobiledevice: drop unused libgcrypt dependency, modernize (#563848) 2026-09-17 02:16:44 +00:00
Michael Daniels
2b8a77bf80 nixVersions.nixComponents*.nix-store: fix compat with meson 1.12
Was broken by 7851563c0b
2026-09-16 21:57:01 -04:00
nixpkgs-ci[bot]
ff0f454fa6 Merge master into staging-next 2026-09-17 00:23:56 +00:00
Peder Bergebakken Sundt
cb43c2bf6b python3Packages.dask: 2026.7.1 -> 2026.8.0 (#558699) 2026-09-16 21:35:51 +00:00
Gaetan Lepage
6d8ee00de2 python3Packages.dask-ml: cleanup, fix 2026-09-16 21:03:47 +00:00
Gaetan Lepage
13ec1d2a1a python3Packages.dask-glm: 0.3.2 -> 0.4.0
Diff: https://github.com/dask/dask-glm/compare/0.3.2...0.4.0

Changelog: https://github.com/dask/dask-glm/releases/tag/0.4.0
2026-09-16 21:03:42 +00:00
Gaetan Lepage
06ff6a54d3 python3Packages.distributed: 2026.7.1 -> 2026.8.0
Diff: https://github.com/dask/distributed/compare/2026.7.1...2026.8.0

Changelog: https://github.com/dask/distributed/releases/tag/2026.8.0
2026-09-16 21:03:38 +00:00
Gaetan Lepage
a201dbdc72 python3Packages.dask: 2026.7.1 -> 2026.8.0
Diff: https://github.com/dask/dask/compare/2026.7.1...2026.8.0

Changelog: https://docs.dask.org/en/latest/changelog.html
2026-09-16 21:03:32 +00:00
Randy Eckenrode
f467180b4c swift: 5.10.1 -> 6.2.4 (#557896) 2026-09-16 20:15:53 +00:00
Doron Behar
a9162e9e0b python3Packages.matplotlib: 3.11.1 -> 3.11.2
Changelog: https://github.com/matplotlib/matplotlib/releases/tag/v3.11.2
2026-09-16 22:21:42 +03:00
Doron Behar
1dd6a474b1 python3Packages.numpy: 2.5.2 -> 2.5.3
Diff: https://github.com/numpy/numpy/compare/v2.5.2...v2.5.3

Changelog: https://github.com/numpy/numpy/releases/tag/v2.5.3
2026-09-16 22:21:28 +03:00
nixpkgs-ci[bot]
5faab3a1b7 Merge master into staging-next 2026-09-16 18:11:05 +00:00
Doron Behar
1ab7013aee zlib: use default configure script on windows (#428871) 2026-09-16 15:28:28 +00:00
teutat3s
f83b24d5df Merge branch 'staging-next' into staging 2026-09-16 16:25:08 +02:00
Ramses
df370ba756 dconf: modernize (#530541) 2026-09-16 13:36:31 +00:00
nixpkgs-ci[bot]
71bb675326 Merge master into staging-next 2026-09-16 12:14:08 +00:00
Ramses
e3e78cbb3c gdk-pixbuf: 2.44.7 -> 2.44.8 (#556525) 2026-09-16 11:47:11 +00:00
Arne Keller
ee9d6faf80 ada: enable structuredAttrs, strictDeps, and split outputs (#561058) 2026-09-16 11:45:32 +00:00
夜坂雅
6bb6dcae52 libimobiledevice: drop unused libgcrypt dependency, modernize 2026-09-16 18:31:40 +08:00
liberodark
b063b8f9b2 nixos/rundeck: fix module for rundeck 6.x 2026-09-16 12:26:01 +02:00
misuzu
5e48062abd spandsp: fix url and patch UB on ppc64be (#499147) 2026-09-16 09:42:35 +00:00
Grimmauld
47dd164970 libsecret: switch to gnutls
- libgcrypt being based on gnupg codebase has had a few "interesting" security incidents recently
- libsecret exposes `gnutls` as alternative crypto backend [1]
  - all tests still pass
  - only the implementation of `service_decode_aes_secret` is affected
    - this is not an exported symbol
  - this reduces closure size (gnutls is in the closure anyways, libgcrypt would be on-top after recent changes)
  - this reduces attack surface (gnutls is in the closure anyways, libgcrypt would be additional attack surface)
- after recent changes, libsecret is currently the largest consumer of libgcrypt

[1] a5cd57f103/meson.build (L40-58)
2026-09-16 10:30:01 +02:00
Grimmauld
d278faec92 libmicrohttpd: drop libgcrypt (#563739) 2026-09-16 07:38:52 +00:00
Grimmauld
d263f2c84f tpm2-tss: drop unused libgcrypt dependency (#563733) 2026-09-16 07:29:01 +00:00
nixpkgs-ci[bot]
0f1fd70371 Merge master into staging-next 2026-09-16 06:15:52 +00:00
Randy Eckenrode
3c1176569d teams/swift: add reckenrode 2026-09-15 23:09:15 -04:00
Randy Eckenrode
3a5030e356 doc/rl-2611: add Swift 6.2 2026-09-15 23:08:49 -04:00
Randy Eckenrode
be9fc82101 doc: update Swift documentation for the new packaging 2026-09-15 23:08:49 -04:00
Randy Eckenrode
bfd7c65db3 doc/stdenv/platform-notes: add note about missing macro libraries 2026-09-15 23:08:49 -04:00
Randy Eckenrode
aadf094af6 swiftPackages_ng: rename to swiftPackages 2026-09-15 23:08:49 -04:00
Randy Eckenrode
424cefcdb5 swiftPackages: delete Swift 5.10.1 package set
The old package set will be replaced with the Swift 6.2 package set.
Going forward, it is expected that updates will be done in that package
set since it is hoped that another rewrite will not be required.
2026-09-15 23:08:49 -04:00
Randy Eckenrode
447ed2aef2 swiftPackages_ng: warn on use of deprecated aliases 2026-09-15 23:08:49 -04:00
Randy Eckenrode
b34706c1cf swiftPackages_ng.swift: warn on use of deprecated aliases 2026-09-15 23:08:49 -04:00
Randy Eckenrode
282292d48e xcodes: remove obsolete Swift constructs
The new Swift packaging no longer requires using a custom stdenv.
2026-09-15 23:08:48 -04:00
Randy Eckenrode
8264809510 xcodegen: remove obsolete Swift constructs
The new Swift packaging no longer requires using a custom stdenv.
2026-09-15 23:08:48 -04:00
Randy Eckenrode
ddcccf79ca vzvm: remove obsolete Swift constructs
The new Swift packaging no longer requires using a custom stdenv.
2026-09-15 23:08:48 -04:00
Randy Eckenrode
a62b12e78d swipeaerospace: remove obsolete Swift constructs
The new Swift packaging no longer requires using a custom stdenv.
2026-09-15 23:08:48 -04:00
Randy Eckenrode
61ef2bbc09 swipeaerospace: drop settings window patch
Swift 6.2 uses the 26.x SDK, which has the required APIs, making the
patch no longer necessary.
2026-09-15 23:08:48 -04:00
Randy Eckenrode
1bd6df7300 swipeaerospace: update for new Swift packaging
- Manually specify the path to BlueSocket. The new Swift packaging no
  longer wraps `swift`. Normally, the build system would handle this,
  but the SwipeAeroSpace packaging builds things manually; and
- Move modules and libraries to the standard locations (lib/swift/macosx
  and lib, respectively). The latter helps ld-wrapper find the dylib
  when linking BlueSocket.
2026-09-15 23:08:48 -04:00
Randy Eckenrode
08ca3e0147 stats: remove obsolete Swift constructs
The new Swift packaging no longer requires using a custom stdenv.
2026-09-15 23:08:48 -04:00
Randy Eckenrode
83b68a56b5 smc-fuzzer: remove unused swiftPackage argument 2026-09-15 23:08:48 -04:00
Randy Eckenrode
ebcc3c55bf rectangle: remove obsolete Swift constructs
The new Swift packaging no longer requires using a custom stdenv.
2026-09-15 23:08:48 -04:00
Randy Eckenrode
f5b380c3f4 protoc-gen-swift: remove obsolete Swift constructs
- The new Swift packaging no longer requires using a custom stdenv; and
- It also no longer requires special handling of libdispatch or manually
  adding Foundation to `buildInputs`. Both are bundled in the toolchain.
2026-09-15 23:08:48 -04:00
Randy Eckenrode
7bb47adab9 pam-watchid: remove obsolete Swift constructs
The new Swift packaging no longer requires using a custom stdenv.
2026-09-15 23:08:47 -04:00
Randy Eckenrode
6ae3279a89 mpv-unwrapped: remove obsolete Swift constructs
- The Swift stdlib is now a seperate package, and there is a hook to fix
  up references to the toolchain to point to the stdlib. It should no
  longer be necessary to manually specify the path to the stdlib; and
- Support for `NIX_SWIFTFLAGS_COMPILE` has been dropped from the new Swift
  packaging.
2026-09-15 23:08:47 -04:00
Randy Eckenrode
c82350cedd mask: include Swift support 2026-09-15 23:08:47 -04:00
Randy Eckenrode
09181faedc ethernet-connection-status: remove obsolete Swift constructs 2026-09-15 23:08:47 -04:00
Randy Eckenrode
33b37373bb dotnet/wrapper.nix: remove obsolete Swift constructs
The new Swift packaging no longer requires using a custom stdenv.
2026-09-15 23:08:47 -04:00
Randy Eckenrode
f10061fbb2 dotnet/source/vmr.nix: remove obsolete Swift constructs
The new Swift packaging no longer requires using a custom stdenv.
2026-09-15 23:08:47 -04:00
Randy Eckenrode
7d50bf1b32 dockutil: remove obsolete Swift constructs
The new Swift packaging no longer requires using a custom stdenv.
2026-09-15 23:08:47 -04:00
Randy Eckenrode
be04f95ba2 dark-mode-notify: remove obsolete Swift constructs
The new Swift packaging no longer requires using a custom stdenv.
2026-09-15 23:08:47 -04:00
Randy Eckenrode
ae64a01a39 cgtcalc: enable tests on non-Darwin 2026-09-15 23:08:46 -04:00
Randy Eckenrode
567d6acb6a cgtcalc: remove obsolete Swift constructs
The new Swift packaging includes XCTest in the toolchain.
2026-09-15 23:08:46 -04:00
Randy Eckenrode
06552da921 autokbisw: remove obsolete Swift constructs
The new Swift packaging no longer requires using a custom stdenv.
2026-09-15 23:08:46 -04:00
Randy Eckenrode
18bb266cd8 alt-tab-macos: remove obsolete Swift constructs
The new Swift packaging no longer requires using a custom stdenv.
2026-09-15 23:08:46 -04:00
Randy Eckenrode
4026f234bf alt-tab-macos: drop Swift 5.10.1 compatibility workarounds 2026-09-15 23:08:46 -04:00
Randy Eckenrode
b74a4c6ff6 alt-tab-macos: fix compatibility building with the 26.x SDK
It’s not clear how upstream is able to build this using an upstream
toolchain, but the header for this API in our SDK has marked it
obsolete. This causes the build to fail even though it won’t be used on
our default deployment target. Fortunately, that means the offending
static method can just be deleted.
2026-09-15 23:08:46 -04:00
Randy Eckenrode
6c20eef73b airdrop-cli: remove obsolete Swift constructs
The new Swift packaging no longer requires using a custom stdenv.
2026-09-15 23:08:46 -04:00
Randy Eckenrode
485fbb2716 age-plugin-se: remove obsolete Swift constructs
- The new Swift packaging no longer requires using a custom stdenv; and
- It no longer requires handling of libdispatch. It’s bundled in the
  toolchain.
2026-09-15 23:08:46 -04:00
Randy Eckenrode
0c5005508e age-plugin-se: switch to fetchSwiftPMDeps
The way age-plugin-se attempts to vendor Swift Crypto doesn’t work on
Linux after switching to Swift 6.2.4. Using fetchSwiftPMDeps does work,
so just use it. This simplifies the dependency vendoring logic.
2026-09-15 23:08:46 -04:00
Randy Eckenrode
5c0c265307 fetchSwiftPMDeps: add to the top-level 2026-09-15 23:08:46 -04:00
Randy Eckenrode
4fe30679ab swift: 5.10.1 -> 6.2.4
https://www.swift.org/blog/announcing-swift-6/
https://www.swift.org/blog/swift-6.1-released/
https://www.swift.org/blog/swift-6.2-released/

Switch the top-level Swift implementation to use the new packaging,
which also upgrades the version from 5.10.1 to 6.2.4.
2026-09-15 23:08:45 -04:00
Randy Eckenrode
0333d2c6f7 sentry-cli: disable SwiftPM install phase
sentry-cli expects to rely on the install phase defined in its
`Makefile`.
2026-09-15 23:08:45 -04:00
Randy Eckenrode
d0be72e769 protoc-gen-swift: include submodules for building with Swift 6
swift-protobuf uses a different `Package.swift` when building with
Swift 6. This one requires several submodules. These will be vendored in
later versions of swift-protobuf, but the one currently packages
requires them to be fetched.
2026-09-15 23:08:45 -04:00
Randy Eckenrode
cb6636d66d handy: improve compatibility when using the 26.x SDK
The Swift 6.2 packaging propagates the 26.x SDK, which will cause handy
to fail to build due to required macros being unavailable.
2026-09-15 23:08:45 -04:00
Randy Eckenrode
6043f3856f dark-mode-notify: disable SwiftPM install phase
dark-mode-notify expects to rely on the install phase defined in its
`Makefile`.
2026-09-15 23:08:45 -04:00
Randy Eckenrode
8eb27d94e7 apple-sdk: rely on our Swift stdlib package for stdlib stubs and modules 2026-09-15 23:08:45 -04:00
Randy Eckenrode
fdccfa8b36 airdrop-cli: disable SwiftPM install phase
airdrop-cli expects to rely on the install phase defined in its
`Makefile`.
2026-09-15 23:08:45 -04:00
Randy Eckenrode
abd5659830 age-plugin-se: disable SwiftPM install phase
age-plugin-se expects to rely on the install phase defined in its
`Makefile`.
2026-09-15 23:08:45 -04:00
Randy Eckenrode
f5d5cdf9e7 swiftPackages_ng: add compatibility aliases for old package names 2026-09-15 23:08:45 -04:00
Randy Eckenrode
a1ba3b7654 swiftPackages_ng.swift: add passthru properties for compatibility 2026-09-15 23:08:44 -04:00
Randy Eckenrode
e7b6ee399e swiftPackages_ng.swiftly: init at 1.1.3
While not especially useful in Nixpkgs, users may want to install static
SDKs and toolchains using it.
2026-09-15 23:08:44 -04:00
Randy Eckenrode
f82fc8a209 swiftPackages_ng.swift-format: init at 6.2.4 2026-09-15 23:08:44 -04:00
Randy Eckenrode
4914173e34 swiftPackages_ng.swift-docc: init at 6.2.4 2026-09-15 23:08:44 -04:00
Randy Eckenrode
6c12143ea5 swiftPackages.swift-docc-render: init at 6.2.4-unstable-2025-09-16
We have to use an unstable version for compatibility with Node.js 22.
Otherwise, it requires Node.js 20, which has been removed from Nixpkgs.
2026-09-15 23:08:44 -04:00
Randy Eckenrode
f7277f2572 swiftPackages_ng.sourcekit-lsp: init at 6.2.4 2026-09-15 23:08:44 -04:00
Randy Eckenrode
3a44ae2ba8 swiftPackages_ng.swift: add tests
- Port over cxx-interop-test from the Swift 5.10.1 implementation and
  also add support for testing using Swift from C++;
- Add tests for the repl and scripting;
- Add tests for features that impact macOS such as Swift Differentiation
  (dropped from macOS 26.4) and Foundation Macros; and
- Add tests for Swift Testing to confirm it works.
2026-09-15 23:08:44 -04:00
Randy Eckenrode
3afe5aec32 swiftPackages_ng.swiftpm2nix: port to swiftpmUnpackHook
swiftpm2nix includes everything (and a bit more, which can be ignored)
needed by `swiftpm2UnpackHook` to unpack and setup dependencies. This
allows swiftpm2nix to use the edit-based vendoring method and
automatically gain any improvements made to that hook
2026-09-15 23:08:44 -04:00
Randy Eckenrode
da05dc18ce swiftPackages_ng.swiftpm: propagate swiftpmHook
Ideally, packages would opt into hook behavior by including the hook
explicitly, but that would be a significantly breaking change. At least
for now, propagate the hook for compatibility.
2026-09-15 23:08:44 -04:00
Randy Eckenrode
e2408a3532 swiftPackages_ng.swiftpmHook: init at 6.2.4
This hook is similar to the SwiftPM 5.10.1 hook already in Nixpkgs
except it also includes an install phase.
2026-09-15 23:08:44 -04:00
Randy Eckenrode
deff8c1492 swiftPackages_ng.swiftpmUnpackHook: init at 6.2.4
Sets up the Swift package with its dependencies “vendored” from the FOD
created by `fetchSwiftPMDeps`. Because SwiftPM does not support
vendoring dependencies natively, this hook instead sets them up as if
they are being “edited”, which causes SwiftPM to use what has been
copied or symlinked into the top-level `Packages` folder of the build.
2026-09-15 23:08:43 -04:00
Randy Eckenrode
8e806474c4 swiftPackages_ng.fetchSwiftPMDeps: init
`fetchSwiftPMDeps` is an alternative to `swiftpm2nix` that uses a FOD,
which should greatly simplify packaging Swift dependencies.
2026-09-15 23:08:43 -04:00
Randy Eckenrode
860cbce30d swiftPackages_ng.swiftpm: init at 6.2.4 2026-09-15 23:08:43 -04:00
Randy Eckenrode
884c04f8ed swiftPackages_ng.swift-build: init at 6.2.4 2026-09-15 23:08:43 -04:00
Randy Eckenrode
272e07e6ee swiftPackages_ng.swift-system: init at 1.8.1 2026-09-15 23:08:43 -04:00
Randy Eckenrode
20370b91b6 swiftPackages_ng.swift-certificates: init at 1.19.4 2026-09-15 23:08:43 -04:00
Randy Eckenrode
5c233bad7c swiftPackages_ng.swift-crypto: init at 4.5.1 2026-09-15 23:08:43 -04:00
Randy Eckenrode
a0ee52630e swiftPackages_ng.swift-asn1: init at 1.7.1 2026-09-15 23:08:43 -04:00
Randy Eckenrode
0f4a90941a swiftPackages_ng.swift: include testing libraries in the toolchain 2026-09-15 23:08:43 -04:00
Randy Eckenrode
c1ab40a70a swiftPackages_ng.swift-testing: init at 6.2.4 2026-09-15 23:08:43 -04:00
Randy Eckenrode
8cdee6caa0 swiftPackages_ng.swift-corelibs-xctest: init at 6.2.4 2026-09-15 23:08:42 -04:00
Randy Eckenrode
eef51f196c swiftPackages_ng.swift: enable the REPL
LLDB needs to be symlinked into the toolchain for the REPL to work. It
needs to be able to find both the Swift shared libraries and modules.
2026-09-15 23:08:42 -04:00
Randy Eckenrode
34bbd8c8a9 swiftPackages_ng.llvmPackages.lldb: support Swift and the REPL
Unlike the other LLVM packages used by Swift, LLDB requires several
changes and patching to work and function with Swift in Nixpkgs.
2026-09-15 23:08:42 -04:00
Randy Eckenrode
b842ad4d1f swiftPackages_ng.swiftc: add static output for LLDB
The Swift REPL depends on a highly modified version of LLDB included in
the Swift fork of LLVM. This build of LLDB depends on a number of
internal headers and static libraries from the Swift compiler build. We
don’t want to include these in the dev outputs because they would
unnecessarily increase its size when building Swift programs. Instead,
copy them to a separate output that LLDB will use when building.
2026-09-15 23:08:42 -04:00
Randy Eckenrode
e904858c8d swiftPackages_ng.swiftc: init stage 2 at 6.2.4
The stage 2 compiler is the full compiler with LTO optimizations and all
features enabled. It is linked against the separate stdlib.
2026-09-15 23:08:42 -04:00
Randy Eckenrode
4eba26cb25 swiftPackages_ng.swift: include the stdlib in the toolchain 2026-09-15 23:08:42 -04:00
Randy Eckenrode
fc73c0ba79 swiftPackages_ng.stdlib: init at 6.2.4
The Swift stdlib is normally built with the compiler, but we build it
separately to keep the closure size down of Swift-using programs and to
support cross-compilation in the future.
2026-09-15 23:08:42 -04:00
Randy Eckenrode
ed25aa9d7c swiftPackages_ng.swift: include the Swift compiler driver in the toolchain 2026-09-15 23:08:42 -04:00
Randy Eckenrode
3645468866 swiftPackages_ng.swift-driver: init at 6.2.4 2026-09-15 23:08:42 -04:00
Randy Eckenrode
e4bafb0eae swiftPackages_ng.swift-tools-support-core: init at 6.2.4 2026-09-15 23:08:41 -04:00
Randy Eckenrode
9d6002a9a1 swiftPackages_ng.swift-llbuild: init at 6.2.4 2026-09-15 23:08:41 -04:00
Randy Eckenrode
a4330ce7ce swiftPackages_ng.swift-argument-parser: init at 1.8.2 2026-09-15 23:08:41 -04:00
Randy Eckenrode
69368615c4 swiftPackages_ng.swift: include Foundation in the toolchain 2026-09-15 23:08:41 -04:00
Randy Eckenrode
57fbb23103 swiftPackages_ng.swift-corelibs-foundation: init at 6.2.4 2026-09-15 23:08:41 -04:00
Randy Eckenrode
4bfeb0192b swiftPackages_ng.swift-foundation: init at 6.2.4 2026-09-15 23:08:41 -04:00
Randy Eckenrode
5e2ebf6050 swiftPackages_ng.swift-foundation-icu: init at 6.2.4
The upstream package vendors Apple’s ICU fork, but we already build it
as `darwin.ICU`. This package just provides the needed CMake files to
allow it to work with the rest of the Swift build process.
2026-09-15 23:08:41 -04:00
Randy Eckenrode
602696312b swiftPackages_ng.swift-collections: init at 1.6.0 2026-09-15 23:08:41 -04:00
Randy Eckenrode
06be068d16 swiftPackages_ng.swift: correctly propagate libdispatch
The Swift overlay for libdispatch does not include the non-Swift shared
libraries. These need to be included in the toolchain in addition to the
Swift overlay and its module.
2026-09-15 23:08:41 -04:00
Randy Eckenrode
f0edcf6f72 swiftPackages_ng.swift-corelibs-libdispatch: build the Swift overlay 2026-09-15 23:08:41 -04:00
Randy Eckenrode
ba32eefdc8 swiftPackages_ng.swift-minimal: init
Every package in the Swift package set uses the Swift toolchain to
build, but obviously they can’t use a toolchain that includes
themselves. That would result in circular dependencies.

Note: This is a private helper. Packages outside of the Swift package
set should always use the full Swift toolchain when building.
2026-09-15 23:08:40 -04:00
Randy Eckenrode
246541b9f7 swiftPackages_ng.swift: propagate 26.x SDK when macros are supported 2026-09-15 23:08:40 -04:00
Randy Eckenrode
40e846c2b0 swiftPackages_ng.swift: init stage 1 at 6.2.4
The stage 1 compiler supports macros, which are needed by the 26.x SDK
and to build Swift Foundation on Linux.
2026-09-15 23:08:40 -04:00
Randy Eckenrode
ce1a8b6683 swiftPackages_ng: add bootstrap helper
The Swift bootstrap process requires building the Swift compiler several
times. Upstream Swift does this all in the the Swift build process, but
we want to manage it with Nix instead. Doing it in Nix gives us more
control over what it links against and will allow the stdlib to built
separate from the compiler. It will also allow us to take the Swift 6.2
compiler and use it to bootstrap future versions of Swift.

Additionally, the build crashes in `swift-frontend` on Darwin when using
the bootstrapping mode, so it can’t be used anyway. Fortunately, the C++
compiler does work after some patching. It’s brittle, but it can build
everything needed to build a more functional Swift bootstrap compiler.
2026-09-15 23:08:40 -04:00
Randy Eckenrode
e04335ea4a swiftPackages_ng.swift-syntax: init at 6.2.4 2026-09-15 23:08:40 -04:00
Randy Eckenrode
cbda3182f1 swiftPackages_ng.swift: init
The Swift compiler expects to find the stdlib, its modules, etc relative
to its location. Building everything together in one derivation would be
a terrible idea because it would take a very long time to build and
require rebuilding things unnecessarily during the bootstrap.
Fortunately, we can symlink most of what Swift expects together.

Collectively, the contents of this package is called a toolchain. One
should think of it as similar to the toolchains offered on swift.org
except that it’s bootstrapped from source and is part of Nixpkgs.
2026-09-15 23:08:40 -04:00
Randy Eckenrode
0dfc837eb4 swiftPackages_ng.swiftc: init stage 0 at 6.2.4
The stage 0 Swift compiler is the legacy, C++-based compiler. Its
primary purpose is to build a Swift-based compiler that can be used to
build the stdlib and final Swift compiler. It’s buggy, but there are
patches to work around its limitations.
2026-09-15 23:08:40 -04:00
Randy Eckenrode
3b1f177f71 swiftPackages_ng: add private libtool helper package
Many Swift packages on Darwin require using its `libtool` to link
libraries. The upstream LLVM version is compatible enough for our needs,
so we use that one instead of the one from cctools, which should help
with future work to enable Linux to Darwin cross-compilation.
2026-09-15 23:08:40 -04:00
Randy Eckenrode
f15734cf54 swiftPackages_ng: add private alias for upstream LLVM
While Swift requires its own fork for libclang and libLLVM, it can work
with upstream LLVM tools. When possible, we want to use them. This alias
facilitates that. The name was chosen to avoid clashing with the name of
the Swift LLVM fork’s package set.
2026-09-15 23:08:40 -04:00
Randy Eckenrode
cf5da7e5b8 swiftPackages_ng.swift-corelibs-libdispatch: init at 6.2.4
This could probably be done as a drop-in replacement for the existing
`swiftPackages.Dispatch` package, but it’s easier to keep it separate.
One key change from this package is that the Swift overlay uses the same
shared libraries as the non-Swift build of the package, which makes
bootstrapping easier because everything can link the same libdispatch.
2026-09-15 23:08:40 -04:00
Randy Eckenrode
b2f39c4a7e swiftPackages_ng.swift-cmark: init at 0.8.0
Swift requires its own fork of cmark. It doesn’t need a Swift compiler,
so it can be introduced separately from the commit that adds it.
2026-09-15 23:08:39 -04:00
Randy Eckenrode
3c3b7f1cbf swiftPackages_ng.llvmPackages: init at 17.0.0
Swift requires using Apple’s fork of LLVM. The fork contains APIs that
have not been upstreamed into LLVM and may never be upstreamed. It also
contains changes required to support compling Swift. LLDB in particular
has been modified heavily to depend on Swift compiler internals.
2026-09-15 23:08:39 -04:00
Randy Eckenrode
cf87abba34 swiftPackages.swift_release: init at 6.2.4
The Swift toolchain contains libraries and tools that are versioned
together. Building a toolchain containing mixed versions of these is not
supported by upstream and may not even build at all. However, we want to
build these separately when possible, so introduce `swift_release` and
`swift_sources` to capture this toolchain requirement.

Note that there is an exception to this versioning scheme. The Swift
toolchain depends on packages that are developed independently of the
toolchain (such as Swift Argument Parser and Swift Collections). These
can (and will be) updated independently of the toolchain.
2026-09-15 23:08:39 -04:00
Randy Eckenrode
f26a0bb1eb swiftPackages_ng: init package set
Establish a parallel package set while the new Swift packaging is set
up. The primary purpose is to allow packages to be added incrementally
while still allowing `git bisect` to work. Otherwise, `swift` would be
broken until this series was done (or it would have to be a single,
large commit). This approach seems like the least bad one.
2026-09-15 23:08:39 -04:00
Randy Eckenrode
5776a35d7a darwin.ICU: add Linux as a supported platform
Swift Foundation uses a vendored copy of Apple’s ICU fork in the
implementation of `FoundationInternationalization`. Instead of
maintaining yet another build of ICU, update our existing packaging to
build on Linux to faclitate devendoring swift-corelibs-icu.
2026-09-15 23:08:39 -04:00
Randy Eckenrode
a9955997b6 lib.systems.elaborate: add Swift platform
Move the definition of the Swift arch, platform, and triple out of the
Swift compiler derivation; which should make it easier to handle
target-specific differences once Swift cross-compilation is supported.
2026-09-15 23:08:39 -04:00
夜坂雅
b755abea8f libmicrohttpd: drop libgcrypt 2026-09-16 08:28:26 +08:00
nixpkgs-ci[bot]
341d5ab264 Merge master into staging-next 2026-09-16 00:23:46 +00:00
whispers
78643f203e tpm2-tss: drop unused libgcrypt dependency
this was removed back in July 2020 with ebfe77b41e.
diffoscoping the outputs yields no differences besides self-references
in store paths.
2026-09-15 18:53:47 -04:00
éclairevoyant
5a4b81602a blender: enable strictDeps, __structuredAttrs 2026-09-15 15:00:23 -04:00
éclairevoyant
c7d13c681c blender-oneapi: init at 5.2.1
Co-authored-by: Sittymin <mail@sittymin.top>
2026-09-15 15:00:23 -04:00
nixpkgs-ci[bot]
14d9dae8f6 Merge staging-next into staging 2026-09-15 18:10:47 +00:00
nixpkgs-ci[bot]
3550cbd8a9 Merge master into staging-next 2026-09-15 18:10:16 +00:00
Alexandre Esteves
48f5c78ce8 haskellPackages: clean up darwin overrides 2026-09-15 18:35:56 +01:00
Alexandre Esteves
7b1e626a2b haskellPackages: fix a lot of failures under darwin sandbox 2026-09-15 18:35:56 +01:00
Sandro
a860bffebf cryptsetup: 2.8.7 -> 2.8.8 (#561112) 2026-09-15 16:25:01 +00:00
Adam C. Stephens
17ccf5930b libgcrypt: 1.12.2 -> 1.12.4 (#557517) 2026-09-15 16:20:21 +00:00
Cosima Neidahl
c034850abb rust-bindgen: compare platforms with systems.equals (#561492) 2026-09-15 15:54:10 +00:00
Thomas Gerbet
d07e114765 makeBinaryWrapper: reject prefix/suffix with an empty path segment (#548442) 2026-09-15 15:16:58 +00:00
Grimmauld
c7b5584c8a libnice: 0.1.23 -> 0.1.24 (#561344) 2026-09-15 15:06:28 +00:00
marcg
35e6d50e25 pdf2image: patch remaining poppler_path defaults
The existing substituteInPlace was not matching all instances where the
`poppler_path` argument appeared.

This affects the signatures of `pdfinfo_from_path`,
`pdfinfo_from_bytes`, `_get_command_path` and `_get_poppler_version`.
2026-09-15 17:30:30 +03:00
Sandro
44778ad15e go_1_26: 1.26.7 -> 1.26.8 (#559669) 2026-09-15 13:42:12 +00:00
nixpkgs-ci[bot]
cd47c2a902 Merge staging-next into staging 2026-09-15 12:13:38 +00:00
nixpkgs-ci[bot]
40bfd164c3 Merge master into staging-next 2026-09-15 12:13:08 +00:00
whoomee
2ba30f5255 libnice: enable tests 2026-09-15 14:11:34 +02:00
Doron Behar
7c4f236b90 mpi: 5.0.10 -> 5.0.11 (#562579) 2026-09-15 08:45:16 +00:00
Bjørn Forsman
d831d24247 liburcu: 0.15.6 -> 0.15.7 (#563348) 2026-09-15 08:22:22 +00:00
Bjørn Forsman
5b00ace03f liburcu: enable strictDeps, enable structuredAttrs (#563379) 2026-09-15 08:21:46 +00:00
ajs124
2ad7222239 nss: 3.128 -> 3.129
https://github.com/mozilla/nss/blob/master/doc/src/releases/nss_3_129.md
2026-09-15 09:36:45 +02:00
nixpkgs-ci[bot]
a6f96b0ea1 Merge staging-next into staging 2026-09-15 06:16:25 +00:00
nixpkgs-ci[bot]
4b300207d9 Merge master into staging-next 2026-09-15 06:15:48 +00:00
LunNova
b024c87e93 lndir: 1.0.5 -> 1.0.6 (#554051) 2026-09-15 02:49:01 +00:00
LunNova
c777c4a106 libmicrohttpd: 1.0.6 -> 1.0.10 (#554471) 2026-09-15 02:48:49 +00:00
Michael Daniels
063989a01c python3Packages.tzdata: 2026.3 -> 2026.4
Changelog: https://github.com/python/tzdata/blob/2026.4/NEWS.md
2026-09-14 21:19:42 -04:00
nixpkgs-ci[bot]
6a87f493de Merge staging-next into staging 2026-09-15 00:25:53 +00:00
nixpkgs-ci[bot]
a9a6d9769e Merge master into staging-next 2026-09-15 00:25:21 +00:00
Stefan Frijters
857ac80f17 liburcu: enable structuredAttrs 2026-09-15 02:03:00 +02:00
Stefan Frijters
844baee10f liburcu: enable strictDeps 2026-09-15 02:02:45 +02:00
Sergei Trofimovich
015a221101 liburcu: 0.15.6 -> 0.15.7
Changes: https://raw.githubusercontent.com/urcu/userspace-rcu/v0.15.7/ChangeLog
2026-09-14 22:45:29 +01:00
Michael Daniels
523b127f7f dtc: 1.7.2 -> 1.8.1 (#562969) 2026-09-14 21:12:57 +00:00
Michael Daniels
1344a818f6 various: fix hashes 2026-09-14 17:09:04 -04:00
nixpkgs-ci[bot]
a258ec4c55 Merge staging-next into staging 2026-09-14 18:10:55 +00:00
nixpkgs-ci[bot]
3a54b20725 Merge master into staging-next 2026-09-14 18:10:24 +00:00
Colin
52db7cb20a python3Packages.inline-snapshot: skip documentation tests (#560020) 2026-09-14 17:00:18 +00:00
Grimmauld
f3eff0d268 libcap_ng: 0.9.5 -> 0.9.6 (#563204) 2026-09-14 14:31:22 +00:00
Stefan Frijters
8407989025 db{4,5,6}: enable strictDeps, enable structuredAttrs (#557330) 2026-09-14 14:30:12 +00:00
Stefan Frijters
d883b3e838 dejavu-fonts: enable strictDeps, enable structuredAttrs 2026-09-14 16:29:38 +02:00
Stefan Frijters
6fcf365873 libpaper: enable strictDeps, enable structuredAttrs (#561054) 2026-09-14 14:13:04 +00:00
Stefan Frijters
c85a6b25b6 imath: enable strictDeps, enable structuredAttrs, modernize (#558324) 2026-09-14 14:12:54 +00:00
Stefan Frijters
002113f64d jbig2dec: enable strictDeps, enable structuredAttrs (#558323) 2026-09-14 14:12:44 +00:00
Stefan Frijters
902db911f7 luit: enable structuredAttrs (#563187) 2026-09-14 14:07:07 +00:00
Stefan Frijters
21e285a65f boehmgc: enable strictDeps, use tag (#557020) 2026-09-14 13:46:25 +00:00
Sandro
491f3db39f lame: 3.100 -> 4.0 (#549371) 2026-09-14 12:38:24 +00:00
nixpkgs-ci[bot]
2a99b27bd9 Merge staging-next into staging 2026-09-14 12:14:46 +00:00
nixpkgs-ci[bot]
e97b635f47 Merge master into staging-next 2026-09-14 12:14:18 +00:00
Stefan Frijters
b6f5fd41d4 nixos/librenms: use structuredAttrs instead of passAsFile 2026-09-14 14:13:20 +02:00
Michael Daniels
09f46cd8f7 git: fix interpreter paths in contrib scripts (#553198) 2026-09-14 12:07:49 +00:00
teutat3s
9f3ff79769 electron: fix update script, electron_43: update (#561844) 2026-09-14 11:40:53 +00:00
Grimmauld
8eb0079666 Revert "libcap_ng: disable tests on static"
This reverts commit 18219b32ad.
2026-09-14 13:37:04 +02:00
Grimmauld
b19adca688 libcap_ng: 0.9.5 -> 0.9.6 2026-09-14 13:36:15 +02:00
Sandro Jäckel
33790f6c2f moonshine: 0.16.0 -> 0.16.1
Diff: https://github.com/hgaiser/moonshine/compare/v0.16.0...v0.16.1

Changelog: https://github.com/hgaiser/moonshine/releases/tag/v0.16.1
2026-09-14 13:02:36 +02:00
liberodark
21cce0b93d nixos/glpi-agent: fix cpu and memory reporting in inventory 2026-09-14 11:56:29 +02:00
Antoine du Hamel
da8353e689 apache-orc: fix build (#563013) 2026-09-14 08:22:23 +00:00
nixpkgs-ci[bot]
0d533caa25 Merge staging-next into staging 2026-09-14 06:20:52 +00:00
nixpkgs-ci[bot]
83e8c37160 Merge master into staging-next 2026-09-14 06:20:22 +00:00
R. Ryantm
6b2cd20dee python3Packages.mail-parser: 4.5.0 -> 4.6.5 2026-09-14 04:24:05 +00:00
Michael Daniels
5fc894118b dtc: 1.7.2 -> 1.8.1
Diff: https://github.com/dgibson/dtc/compare/v1.7.2...v1.8.1
2026-09-13 21:23:45 -04:00
nixpkgs-ci[bot]
1582e30993 Merge staging-next into staging 2026-09-14 00:27:24 +00:00
nixpkgs-ci[bot]
0ada4117ca Merge master into staging-next 2026-09-14 00:26:54 +00:00
Robert Schütz
721870b2a6 cups: patch CVE-2026-87875 and CVE-2026-87876 2026-09-13 17:24:30 -07:00
Antoine du Hamel
e99a883255 apache-orc: fix build 2026-09-13 23:39:20 +02:00
Luna Nova
2d7031a82a bcc: remove refs to LLVM static libs that bloated closure by 2G 2026-09-13 13:49:37 -07:00
Stig Palmquist
ff4e29c8ac gnupg: update freepg patches to source-2.4.9-freepg-1
Assisted-by: Claude Code (Claude Fable 5.1)
2026-09-13 22:37:55 +02:00
nixpkgs-ci[bot]
f81f3a8561 Merge staging-next into staging 2026-09-13 18:50:44 +00:00
nixpkgs-ci[bot]
421336fd3e Merge master into staging-next 2026-09-13 18:48:00 +00:00
Michael Daniels
ae94a54779 Merge remote-tracking branch 'upstream/staging-next' into staging 2026-09-13 14:44:51 -04:00
nixpkgs-ci[bot]
6312385d3f Merge master into staging-next 2026-09-13 18:10:02 +00:00
ajs124
10a679b628 tzdata: 2026c -> 2026d (#562483) 2026-09-13 15:31:51 +00:00
Aaron Andersen
1daabc4111 ppp: replace systemd dependency with systemdLibs (#554457) 2026-09-13 14:58:14 +00:00
Aaron Andersen
989f6e0e0b networkmanager: replace systemd dependency with systemdMinimal (#554453) 2026-09-13 14:57:47 +00:00
Aaron Andersen
f8841a2925 modemmanager: replace systemd dependency with systemdLibs (#554460) 2026-09-13 14:57:14 +00:00
Aaron Andersen
16144cc92b pulseaudio: replace systemd dependency with systemdLibs (#561419) 2026-09-13 14:55:26 +00:00
Hythera
57c499f656 scribus: fix build with poppler 26.07.0 2026-09-13 16:27:23 +02:00
Hythera
4077f6f4f3 inkscape: fix build with poppler 26.07.0 2026-09-13 16:27:23 +02:00
Hythera
6e699d9302 poppler: 26.06.0 -> 26.09.0
changelog: https://gitlab.freedesktop.org/poppler/poppler/-/raw/poppler-26.09.0/NEWS

diff: https://gitlab.freedesktop.org/poppler/poppler/-/compare/poppler-26.06.0...poppler-26.09.0
2026-09-13 16:27:04 +02:00
Marcus Ramberg
59cce71f7e perlPackages.AuthenSASL: 2.1900 -> 2.2100 (#560920) 2026-09-13 14:05:37 +00:00
nixpkgs-ci[bot]
a34b8e1953 Merge master into staging-next 2026-09-13 12:12:16 +00:00
Wolfgang Walther
60945fb736 unixodbcDrivers.psql: 18.00.0002 -> 18.00.0003 (#562064) 2026-09-13 09:59:09 +00:00
Tom Hunze
2fbdf98fbc ibus: fix crashes with latest gtk
GTK issue: https://gitlab.gnome.org/GNOME/gtk/-/work_items/8341
Upstream PR: https://github.com/ibus/ibus/pull/2929
2026-09-13 10:15:40 +02:00
Harinn
b58a721234 python3Packages.defcon: modernize 2026-09-13 14:01:16 +07:00
Harinn
52487795df python3Packages.defcon: migrate to pyproject
As part of https://github.com/NixOS/nixpkgs/issues/515974
2026-09-13 14:01:16 +07:00
nixpkgs-ci[bot]
b0ff850fc0 Merge master into staging-next 2026-09-13 06:18:04 +00:00
nixpkgs-ci[bot]
78bb6139a2 Merge master into staging-next 2026-09-13 00:27:09 +00:00
Sandro
3464499993 libvpx: 1.16.0 -> 1.17.0 (#556585) 2026-09-12 20:20:04 +00:00
Winter
80979dc81f rust: enable strictDeps / structuredAttrs in its build infrastructure (#559899) 2026-09-12 20:06:21 +00:00
Stefan Frijters
70f533105e luit: enable structuredAttrs 2026-09-12 21:40:26 +02:00
LunNova
9bb742e252 srt: enable strictDeps, enable structuredAttrs, modernize (#558318) 2026-09-12 18:28:59 +00:00
nixpkgs-ci[bot]
f170819950 Merge master into staging-next 2026-09-12 18:09:41 +00:00
R. Ryantm
ad8f04ff84 libdeflate: 1.25 -> 1.26 2026-09-12 17:41:54 +00:00
dotlambda
3d78ead5d5 python3Packages.pyjwt: 2.13.0 -> 2.14.0 (#562328) 2026-09-12 15:41:12 +00:00
Michael Daniels
9436a21007 protobuf: add proto output to fix protobufc build (#562223) 2026-09-12 14:08:30 +00:00
Ben Siraphob
ee62012a92 phonon: disable experimental library to fix build with newer clang
The experimental library is an unstable upstream API and should not be exposed by distribution builds. Disabling it also avoids the newer-Clang build failure on Darwin.

Assisted-by: Pi (OpenAI Codex GPT-5.6-sol)
2026-09-12 05:55:14 -07:00
R. Ryantm
6d7da008fe mpi: 5.0.10 -> 5.0.11 2026-09-12 12:34:32 +00:00
nixpkgs-ci[bot]
cf489720f6 Merge master into staging-next 2026-09-12 12:11:37 +00:00
nixpkgs-ci[bot]
73d3951f2e Merge master into staging-next 2026-09-12 06:13:47 +00:00
ajs124
387081f737 tzdata: 2026c -> 2026d
https://lists.iana.org/hyperkitty/list/tz-announce@iana.org/thread/L4IGHJRBUQR53F7RTEHM5IS7ZMBR3YXP/
2026-09-12 08:10:21 +02:00
Randy Eckenrode
4276ad9330 lldb: backport export trie fixes to LLDB 22 and older (#560288) 2026-09-12 00:55:20 +00:00
nixpkgs-ci[bot]
a4ccc8d0d6 Merge master into staging-next 2026-09-12 00:23:25 +00:00
Nick Cao
06ee12b968 protobuf: fix typo in pkgConfigModules (#562204) 2026-09-11 18:55:35 +00:00
nixpkgs-ci[bot]
d400b12e47 Merge master into staging-next 2026-09-11 18:10:14 +00:00
Robert Schütz
409bbcafb7 python3Packages.pyjwt: use finalAttrs 2026-09-11 09:57:12 -07:00
Robert Schütz
70a62b6872 python3Packages.pyjwt: 2.13.0 -> 2.14.0
Diff: https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0

Changelog: https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst
2026-09-11 08:51:50 -07:00
whispers
ae02526138 libgcrypt: 1.12.2 -> 1.12.4
https://lists.gnu.org/archive/html/info-gnu/2026-08/msg00007.html
https://lists.gnu.org/archive/html/info-gnu/2026-09/msg00002.html
2026-09-11 09:17:33 -04:00
Antoine du Hamel
ef2080c04e nghttp3: 1.16.0 -> 1.17.0 (#542067) 2026-09-11 12:21:15 +00:00
Fabian Affolter
753ec2f3b6 python3Packages.gitpython: 3.1.58 -> 3.1.62
Diff: https://github.com/gitpython-developers/GitPython/compare/3.1.58...3.1.62

Changelog: https://github.com/gitpython-developers/GitPython/blob/3.1.62/doc/source/changes.rst
2026-09-11 14:03:46 +02:00
K900
8596db6bc8 qt6.qtdeclarative: backport change recommended by KDE (#562228) 2026-09-11 10:13:31 +00:00
K900
d9d2e944dc qt6.qtdeclarative: backport change recommended by KDE 2026-09-11 13:07:17 +03:00
Antoine du Hamel
31e7b77199 protobuf: add proto output to fix protobufc build 2026-09-11 11:45:52 +02:00
teutat3s
723f7f655b electron: fix update script
https://github.com/NixOS/nixpkgs/pull/555729 changed yarn hashes but
didn't apply the changes to the electron update script.
2026-09-11 11:11:09 +02:00
Markus Kowalewski
9944c84aed rdma-core: 64.0 -> 65.0 (#561851) 2026-09-11 08:27:40 +00:00
Antoine du Hamel
9e8378652d protobuf: fix typo in pkgConfigModules 2026-09-11 09:59:04 +02:00
Vladimír Čunát
5febd09562 gstreamer: 1.28.6 -> 1.28.7 (#561359) 2026-09-11 07:16:31 +00:00
Vladimír Čunát
874e3b2cf7 xz: 5.8.3 -> 5.8.4 (#561722) 2026-09-11 07:13:56 +00:00
Vladimír Čunát
7c08908394 libheif: 1.23.3 -> 1.23.4 (#561053) 2026-09-11 07:12:11 +00:00
R. Ryantm
dc457e1ad8 yubioath-flutter: 7.4.1 -> 7.4.2 2026-09-11 06:21:11 +00:00
whispers
b1a505fe96 util-linux: do not run unnecessary autoreconf
since #402852 (and made unconditional in
41205c0e6c), we run autoreconf for
util-linux. this is because we needed to patch configure.ac. this is no
longer the case, as the patch for which we did this was accepted
upstream and we've had it since v2.42:
https://lore.kernel.org/util-linux/20250501075806.88759-1-hi@alyssa.is/.
accordingly, we can now remove this

if we still want to autoreconf for some reason, despite it not being
needed, we should at least unpin automake116x, as we have no reason to
require an old automake anymore.
2026-09-11 00:55:14 -04:00
R. Ryantm
913c7c9d08 unixodbcDrivers.psql: 18.00.0002 -> 18.00.0003 2026-09-11 01:16:42 +00:00
Randy Eckenrode
53b813b166 lldb: backport export trie fixes to LLDB 22 and older
Older versions of LLDB crash on macOS 27 when starting a debugging
session on macOS 27 due to a stack overflow in `ParseExportTries`.

The fixes from LLVM 23 can’t be cherry-picked due to other changes. They
have been manually backported and squashed into a single patch.
2026-09-10 20:51:32 -04:00
Michael Daniels
86b171da65 Revert "meson: don't set postPatch at all if not using PyPy"
This reverts commit ef3d7e646a.
2026-09-10 19:26:18 -04:00
Grimmauld
6d2ce9dc6b orc: 0.4.42 -> 0.4.44 (#557688) 2026-09-10 20:50:49 +00:00
whoomee
0667451352 orc: specify meta.identifiers.cpeParts 2026-09-10 21:41:07 +02:00
whoomee
075f08ee5b orc: refactor mesonFlags 2026-09-10 21:41:07 +02:00
whoomee
f95cc368a1 orc: re-enable buildDevDoc 2026-09-10 21:41:07 +02:00
whoomee
87a9c3a077 orc: specify and test meta.pkgConfigModules 2026-09-10 21:41:07 +02:00
whoomee
f6f7fa5fb7 orc: set updateScript 2026-09-10 21:41:07 +02:00
whoomee
3113b9085a orc: 0.4.42 -> 0.4.44 2026-09-10 21:41:07 +02:00
Tom Hunze
562727f5bf libsigcxx_2_0: modernize 2026-09-10 20:17:51 +02:00
Tom Hunze
2af6f8803a libsigcxx_{2,3}_0: move to pkgs/by-name 2026-09-10 20:17:49 +02:00
Tom Hunze
b0c699eea1 libsigcxx_3_0: enable structuredAttrs and strictDeps 2026-09-10 20:17:48 +02:00
Tom Hunze
07387e61cb libsigcxx_2_0: enable structuredAttrs and strictDeps 2026-09-10 20:17:47 +02:00
Tom Hunze
11900e5fb9 libsigcxx30: rename to libsigcxx_3_0
That's more consistent with other GNOME-related package attributes with
explicit ABI version suffixes.
2026-09-10 20:17:46 +02:00
Tom Hunze
ae25eb7f83 libsigcxx: rename to libsigcxx_2_0
Having the older ABI version as the default seems odd, so drop the
unsuffixed version similar to webkitgtk and as discussed in [1].

[1] https://github.com/NixOS/nixpkgs/pull/543345#issuecomment-5199018730
2026-09-10 20:17:45 +02:00
Sandro
1a5e3f739a nixosTests.installed-tests.gjs: fix build (#557190) 2026-09-10 13:37:04 +00:00
rewine
bf95a36adb simdutf: 9.1.0 -> 9.1.1 (#561319) 2026-09-10 12:38:29 +00:00
Sergei Volkov
2606fefd61 julia-bin: add strictDeps = true and __structuredAttrs = true
required by CI for adding new julia_113-bin package
2026-09-10 14:33:38 +02:00
Stefan Frijters
44d4b38a94 go: enable strictDeps, structuredAttrs for bootstrap, use stdenvNoCC (#559867) 2026-09-10 10:13:10 +00:00
R. Ryantm
6d4f039414 rdma-core: 64.0 -> 65.0 2026-09-10 08:52:03 +00:00
Masum Reza
a75253b6ce bcachefs-tools: remove RISC-V bindgen workaround (#561500) 2026-09-10 05:58:24 +00:00
Michael Daniels
33942a2e77 meson: 1.10.2 -> 1.12.0, modernize (#548621) 2026-09-09 22:22:12 +00:00
Michael Daniels
1fbebaa13c glibmm*: add explicit version suffix to attr, enable structuredAttrs and strictDeps (#559692) 2026-09-09 22:14:49 +00:00
Sergei Trofimovich
49054352ce xz: 5.8.3 -> 5.8.4
Changes: https://github.com/tukaani-project/xz/releases/tag/v5.8.4
2026-09-09 21:38:11 +01:00
nixpkgs-ci[bot]
cb9b0c0b77 bitfocus-companion: 4.3.4 -> 5.0.5 (#560954) 2026-09-09 16:31:19 +00:00
jopejoe1
d04a605371 python3Packages.fontmake: use finalAttrs 2026-09-09 11:45:48 +02:00
R. Ryantm
0fbaab0484 qgis: 4.2.1 -> 4.2.2 2026-09-09 07:39:54 +00:00
nixpkgs-ci[bot]
8c5a2e3922 Merge staging-next into staging 2026-09-09 06:15:57 +00:00
Jamie Magee
9cd092bab4 bcachefs-tools: remove RISC-V bindgen workaround 2026-09-08 22:03:40 -07:00
Jamie Magee
e86865624d rust-bindgen: compare platforms with systems.equals 2026-09-08 20:19:55 -07:00
Michael Daniels
a5de2edf4b cmake: 4.4.2 -> 4.4.3 (#560301) 2026-09-09 00:38:40 +00:00
nixpkgs-ci[bot]
895225db0a Merge staging-next into staging 2026-09-09 00:25:39 +00:00
Antoine du Hamel
c3af716c01 nodejs_24: 24.20.0 -> 24.21.0 (#561432) 2026-09-08 22:14:47 +00:00
Antoine du Hamel
e1459ab0f2 nodejs_24: 24.20.0 -> 24.21.0 2026-09-08 23:52:48 +02:00
Tyce Herrman
6cf20e6351 lix: add tyceherrman as maintainer
Assisted-by: Codex (gpt-5.6-sol)
2026-09-08 16:58:02 -04:00
Tyce Herrman
53819b8cb0 lix: add update script for 2.95 releases
Extract version, source, and Cargo definitions consistently for 2.94,
2.95, and the development snapshot. Keep scope construction, patches,
and aliases in default.nix.

Isolate the 2.95 updater in its release file so replacing a shared Cargo
hash cannot modify the development snapshot. Restrict automated updates
to the 2.95 release series.

Assisted-by: Codex (gpt-5.6-sol)
Assisted-by: Codex (GPT-6)
2026-09-08 16:58:01 -04:00
Tyce Herrman
495e968f9f lix: 2.95.2 -> 2.95.3
Assisted-by: Codex (gpt-5.6-sol)
Assisted-by: Codex (GPT-6)
2026-09-08 16:58:00 -04:00
Aaron Andersen
9ae024d506 pulseaudio: replace systemd dependency with systemdLibs 2026-09-08 16:52:30 -04:00
Markus Kowalewski
3e0695468c ucc: 1.8.0 -> 1.9.0 (#561369) 2026-09-08 20:32:08 +00:00
nixpkgs-ci[bot]
e98e6f357c Merge staging-next into staging 2026-09-08 20:34:05 +00:00
Antoine du Hamel
e1dbe60fcb protobuf: add meta.pkgConfigModules, split outputs (#560607) 2026-09-08 19:36:15 +00:00
Tom Hunze
5be4a69984 glibmm_2_68: enable structuredAttrs and strictDeps 2026-09-08 21:34:38 +02:00
Tom Hunze
0b8536ce92 glibmm_2_4: enable structuredAttrs and strictDeps 2026-09-08 21:34:37 +02:00
Tom Hunze
c0e8f0697b glibmm: rename to glibmm_2_4
Having the older ABI version as the default seems odd and the different
glibmm packages appear to be fundamentally incompatible, so drop the
unsuffixed version similar to webkitgtk and as discussed in [1].

[1] https://github.com/NixOS/nixpkgs/pull/543345#issuecomment-5199018730
2026-09-08 21:34:33 +02:00
Sandro Jäckel
8db8147600 nixos/paperless: allow overwriting exporter settings without mkForce 2026-09-08 21:07:41 +02:00
Sandro Jäckel
a8018b043e nixos/engelsystem: do not require mkForce ot overwrite default pm.* settings 2026-09-08 21:03:54 +02:00
R. Ryantm
594199fa6d ucc: 1.8.0 -> 1.9.0 2026-09-08 18:43:03 +00:00
whoomee
d3aad09b0f gstreamer: 1.28.6 -> 1.28.7 2026-09-08 20:23:50 +02:00
nixpkgs-ci[bot]
667251099c Merge staging-next into staging 2026-09-08 18:11:42 +00:00
whoomee
c504504011 libnice: 0.1.23 -> 0.1.24 2026-09-08 18:40:48 +02:00
Weijia Wang
2906d09f24 simdutf: 9.1.0 -> 9.1.1 2026-09-08 18:12:55 +02:00
Stefan Frijters
3f9ac46801 libmad: enable strictDeps, enable structuredAttrs, modernize (#561069) 2026-09-08 15:11:16 +00:00
nixpkgs-ci[bot]
a5cf0fec59 Merge staging-next into staging 2026-09-08 12:14:31 +00:00
Dan Xin
abcf354eba changedetection-io: qualify Playwright container image 2026-09-08 18:03:47 +08:00
Colin
8b478022c0 rust-bindgen: pass target triple when cross-compiling (#558886) 2026-09-08 07:20:23 +00:00
nixpkgs-ci[bot]
f60c533f50 libsoup_3: enable strictDeps, enable structuredAttrs, modernize (#561067) 2026-09-08 06:44:20 +00:00
rewine
a5b02745d1 simdutf: split in multiple outputs (#561070) 2026-09-08 02:47:56 +00:00
R. Ryantm
24e4fd5341 cryptsetup: 2.8.7 -> 2.8.8 2026-09-08 01:02:28 +00:00
nixpkgs-ci[bot]
93bc9015b0 Merge staging-next into staging 2026-09-08 00:25:33 +00:00
Antoine du Hamel
9f452abaef simdjson: split in multiple outputs (#561068) 2026-09-07 22:59:53 +00:00
Antoine du Hamel
6c3c849e11 simdutf: split in multiple outputs 2026-09-08 00:51:38 +02:00
Stefan Frijters
437e4699e0 libmad: enable structuredAttrs 2026-09-08 00:48:41 +02:00
Antoine du Hamel
c34953c17f simdjson: split in multiple outputs 2026-09-08 00:48:15 +02:00
Stefan Frijters
a086377e58 libmad: enable strictDeps 2026-09-08 00:48:13 +02:00
Stefan Frijters
bd30f1ebbf libsoup_3: modernize 2026-09-08 00:41:58 +02:00
Stefan Frijters
171d4b6f98 libsoup_3: enable structuredAttrs 2026-09-08 00:41:48 +02:00
Stefan Frijters
59391f774d libsoup_3: enable strictDeps 2026-09-08 00:41:20 +02:00
Antoine du Hamel
6fb5cdb9a3 ada: split in two outputs 2026-09-08 00:09:58 +02:00
Antoine du Hamel
1b3d9fa3af ada: enable strictDeps 2026-09-08 00:09:58 +02:00
Antoine du Hamel
b76aeb3d38 ada: enable structuredAttrs 2026-09-08 00:09:49 +02:00
Stefan Frijters
f7bb6dd755 libpaper: enable structuredAttrs 2026-09-08 00:00:20 +02:00
Stefan Frijters
6d5884d31c libpaper: enable strictDeps 2026-09-08 00:00:05 +02:00
Sergei Trofimovich
be981eb018 libheif: 1.23.3 -> 1.23.4
Changes: https://github.com/strukturag/libheif/releases/tag/v1.23.4
2026-09-07 22:56:22 +01:00
dotlambda
561e33fa9a catch2_3: 3.15.3 -> 3.16.0 (#557906) 2026-09-07 20:57:12 +00:00
dotlambda
f55420bb42 gpgme: 2.1.2 -> 2.2.0 (#558649) 2026-09-07 20:05:18 +00:00
Cosima Neidahl
988efea9a3 python3Packages.appnope: 0.1.4 -> 1.0.0 (#557883) 2026-09-07 18:41:45 +00:00
nixpkgs-ci[bot]
7ed8d225d3 Merge staging-next into staging 2026-09-07 18:11:10 +00:00
nixpkgs-ci[bot]
8f01c55eb6 Merge staging-next into staging 2026-09-07 17:16:39 +00:00
Tiebe Groosman
73714887c9 bitfocus-companion: 4.3.4 -> 5.0.5 2026-09-07 19:00:00 +02:00
sh0uv1
55c902a0a0 perlPackages.AuthenSASL: 2.1900 -> 2.2100 2026-09-07 15:40:57 +00:00
Michael Daniels
9bdf09b40d meson: respect NIX_BUILD_CORES in tests 2026-09-07 10:43:59 -04:00
Michael Daniels
fdb2910f21 meson: use --replace-fail, lib.getExe' 2026-09-07 10:43:59 -04:00
Michael Daniels
ef3d7e646a meson: don't set postPatch at all if not using PyPy
I prefer this formatting, I think.
2026-09-07 10:43:59 -04:00
Michael Daniels
52048f3175 meson: set optional-dependencies 2026-09-07 10:43:59 -04:00
Michael Daniels
e39541fd76 meson: combine installShellCompletion calls 2026-09-07 10:43:58 -04:00
Michael Daniels
a3b310ec27 meson: set __structuredAttrs = true 2026-09-07 10:43:58 -04:00
Michael Daniels
57c2cd9c5f meson: use writableTmpDirAsHomeHook 2026-09-07 10:43:58 -04:00
Michael Daniels
e375bc6272 meson: set pyproject = true 2026-09-07 10:43:58 -04:00
Michael Daniels
a5d4caecd5 meson: use finalAttrs 2026-09-07 10:43:46 -04:00
Sandro
6aec222ae9 yarn-berry: 4.14.1 -> 4.18.0 (#555729) 2026-09-07 13:55:22 +00:00
nixpkgs-ci[bot]
d84ca0a63a Merge staging-next into staging 2026-09-07 12:14:22 +00:00
Martin Weinelt
c8cb97df0b python3Packages.psycopg: 3.3.4 -> 3.3.5 (#560729) 2026-09-07 11:53:22 +00:00
Stefan Frijters
97b6bd89d6 python3Packages.dirty-equals: fix tests, modernize (#545428) 2026-09-07 11:47:28 +00:00
Martin Weinelt
77ad8ec37e python3Packages.psycopg: 3.3.4 -> 3.3.5
https://github.com/psycopg/psycopg/blob/3.3.5/docs/news.rst#current-release
2026-09-07 13:42:08 +02:00
Harinn
cc9d7e21b4 python3Packages.crcmod: modernize 2026-09-07 18:39:16 +07:00
Harinn
5c2f79b803 python3Packages.crcmod: migrate to pyproject
As part of https://github.com/NixOS/nixpkgs/issues/515974
2026-09-07 18:39:16 +07:00
Dimitar Nestorov
d251914e23 yarn-berry_4: 4.14.1 -> 4.18.0 2026-09-07 14:11:57 +03:00
Dimitar Nestorov
8f7ca3386c yarn-berry: add lockfileVersion 2026-09-07 10:18:47 +03:00
nixpkgs-ci[bot]
d825874f52 Merge staging-next into staging 2026-09-07 06:20:27 +00:00
Michael Daniels
003cd78447 meson: 1.10.2 -> 1.12.0 2026-09-06 22:38:11 -04:00
nixpkgs-ci[bot]
8d729f45a9 Merge staging-next into staging 2026-09-07 00:27:25 +00:00
Antoine du Hamel
dc3cf5062f protobuf: add meta.pkgConfigModules 2026-09-07 00:25:28 +02:00
K900
3df3d22a78 Merge remote-tracking branch 'origin/staging-next' into staging 2026-09-06 21:14:57 +03:00
Michael Daniels
95e3ac8836 Revert "unixodbcDrivers.mariadb: 3.2.6 -> 3.2.8, adopt" (#560612) 2026-09-06 17:40:47 +00:00
Antoine du Hamel
41d426db5b protobuf: use separate outputs 2026-09-06 19:11:41 +02:00
Stefan Frijters
dcaa8f4370 libidn2: enable strictDeps, structuredAttrs for non-bootstrap build, modernize (#558336) 2026-09-06 15:42:24 +00:00
Stefan Frijters
ebd2073a2e iana-etc: enable strictDeps, enable structuredAttrs, modernize (#559869) 2026-09-06 15:41:01 +00:00
Stefan Frijters
88bd0f2d61 simdjson: enable strictDeps, enable structuredAttrs (#558316) 2026-09-06 15:40:44 +00:00
nixpkgs-ci[bot]
cb710b720c nodejs deps: enable structuredAttrs, strictDeps, and multiple outputs (#560569) 2026-09-06 14:51:29 +00:00
Antoine du Hamel
bda34026b7 uvwasi: enable structuredAttrs, strictDeps, and multiple outputs 2026-09-06 16:31:00 +02:00
Antoine du Hamel
303384d3a0 nbytes: enable structuredAttrs, strictDeps, and multiple outputs 2026-09-06 16:30:59 +02:00
Antoine du Hamel
fb3f389bc7 merve: enable structuredAttrs, strictDeps, and multiple outputs 2026-09-06 16:30:57 +02:00
Michael Daniels
311a15ebb5 Revert "unixodbcDrivers.mariadb: 3.2.6 -> 3.2.8, adopt" 2026-09-06 10:24:07 -04:00
Gaétan Lepage
583ee25c96 abseil-cpp: 20260107.1 -> 20260817.0 (#559122) 2026-09-06 12:51:00 +00:00
liberodark
a03d7c5196 python3Packages.httpcore2: fix riscv64-linux build 2026-09-06 14:32:40 +02:00
nixpkgs-ci[bot]
c9196da4ac Merge staging-next into staging 2026-09-06 12:12:19 +00:00
Ihar Hrachyshka
4cc41c63ec go: drop GO111MODULE (#560250) 2026-09-06 10:36:44 +00:00
Arne Keller
9bafdc01bb swig: fix cross-compilation (#544392) 2026-09-06 10:34:44 +00:00
Yt
090f51b888 grpc: 1.83.0 -> 1.83.1 (#560468) 2026-09-06 09:43:33 +00:00
scraptux
93880b986b python3Packages.grpcio-tools: 1.83.0 -> 1.83.1 2026-09-06 10:38:19 +02:00
scraptux
35678e2de5 python3Packages.grpcio-testing: 1.83.0 -> 1.83.1 2026-09-06 10:38:16 +02:00
scraptux
17b9bc2c15 python3Packages.grpcio-status: 1.83.0 -> 1.83.1 2026-09-06 10:38:14 +02:00
scraptux
37869fcefa python3Packages.grpcio-reflection: 1.83.0 -> 1.83.1 2026-09-06 10:38:12 +02:00
scraptux
f6254e7328 python3Packages.grpcio-health-checking: 1.83.0 -> 1.83.1 2026-09-06 10:38:10 +02:00
scraptux
2bbce9fb11 python3Packages.grpcio-channelz: 1.83.0 -> 1.83.1 2026-09-06 10:38:08 +02:00
scraptux
201de3c140 python3Packages.grpcio: 1.83.0 -> 1.83.1 2026-09-06 10:38:07 +02:00
scraptux
7f3ed9c6ac grpc: 1.83.0 -> 1.83.1 2026-09-06 10:38:04 +02:00
nixpkgs-ci[bot]
87bbf878ad Merge staging-next into staging 2026-09-06 06:14:22 +00:00
Michael Daniels
6ef62b1961 unixodbcDrivers.mariadb: 3.2.6 -> 3.2.8, adopt (#508355) 2026-09-06 01:29:11 +00:00
Hythera
11737cb0a4 unixodbcDrivers.mariadb: add hythera as maintainer 2026-09-05 21:17:06 -04:00
Hythera
d0c819d62c unixodbcDrivers.mariadb: modernize 2026-09-05 21:17:05 -04:00
Hythera
0ce7459b96 unixodbcDrivers.mariadb: 3.2.6 -> 3.2.9
changelog: https://mariadb.com/docs/release-notes/connectors/odbc/3.2/3.2.9

diff: https://github.com/mariadb-corporation/mariadb-connector-odbc/compare/3.2.6...3.2.9
2026-09-05 21:17:05 -04:00
Michael Daniels
05473b9ce0 shared-mime-info: 2.4 -> 2.5.1 (#537027) 2026-09-06 01:15:23 +00:00
nixpkgs-ci[bot]
8a37da22c5 Merge staging-next into staging 2026-09-06 00:28:00 +00:00
Michael Daniels
2d83a9af4a libqrtr-glib: 1.2.2 -> 1.4.0 (#531104) 2026-09-06 00:17:09 +00:00
R. Ryantm
2b1762a54f python3Packages.google-cloud-dlp: 3.38.0 -> 3.39.0 2026-09-06 00:01:15 +00:00
Hythera
7315bec432 shared-mime-info: 2.4 -> 2.5.1
changelog: https://gitlab.freedesktop.org/xdg/shared-mime-info/-/blob/2.5.1/NEWS

diff: https://gitlab.freedesktop.org/xdg/shared-mime-info/-/compare/2.4...2.5.1
2026-09-06 01:17:09 +02:00
Stefan Frijters
0683ad8c01 go: use stdenvNoCC for bootstrap 2026-09-05 23:29:33 +02:00
Stefan Frijters
e5a1f49564 go: enable structuredAttrs for bootstrap 2026-09-05 23:29:32 +02:00
Stefan Frijters
da685c6c16 go: enable strictDeps for bootstrap 2026-09-05 23:29:32 +02:00
Sandro Jäckel
cc13c84a76 nixos/mjolnir: add support for using native encryption 2026-09-05 22:21:50 +02:00
Michael Daniels
e49d7187f7 libmysofa: enable tests (#560238) 2026-09-05 20:18:46 +00:00
Sandro Jäckel
6c1cf8bb4f mjolnir: 1.9.2 -> 1.12.1 2026-09-05 22:09:47 +02:00
Sandro Jäckel
84f7cb0e63 matrix-sdk-crypto-nodejs: 0.4.0-beta.1 -> 0.6.6
Diff: https://github.com/matrix-org/matrix-rust-sdk-crypto-nodejs/compare/v0.4.0-beta.1...v0.6.6

Changelog: https://github.com/matrix-org/matrix-rust-sdk-crypto-nodejs/blob/main/CHANGELOG.md
2026-09-05 22:09:47 +02:00
Michael Daniels
39632953ba cmake: 4.4.2 -> 4.4.3
Changelog: https://cmake.org/cmake/help/v4.4/release/4.4.html
Diff: https://github.com/Kitware/CMake/compare/v4.4.2...v4.4.3
2026-09-05 16:05:36 -04:00
Michael Daniels
704f32146a libmysofa: enable tests 2026-09-05 14:59:09 -04:00
Sandro Jäckel
9a1444ff8a go: drop GO111MODULE
This defaults to on since go 1.16, see https://go.dev/ref/mod#mod-commands
2026-09-05 18:07:22 +02:00
Roman
5b7e9c9fa2 doc/rl-2611: note the proton-cli breaking changes
Assisted-by: pi 0.85.0 (Anthropic claude-opus-5)
2026-09-05 18:06:26 +02:00
Roman
d8aad67d98 proton-cli: update description and homepage
The description leads with what the program is for and ends on the
property that sets it apart, in the one-sentence form the manual asks
for. The homepage is the documentation site upstream publishes.

Assisted-by: pi 0.85.0 (Anthropic claude-opus-5)
2026-09-05 17:53:03 +02:00
Roman
898ffc9c30 proton-cli: 2.2.3 -> 3.4.0
The command is now `proton`, with `proton-cli` kept as a second name, so
`subPackages`, `mainProgram` and the completions move with it.

Human verification is solved in the user's own browser, so upstream
deleted the embedded CAPTCHA webview, the script that built it and its
`webview_go` dependency. The build tag, that script, the vendor-fetch
override that kept it out, pkg-config, wrapGAppsHook3 and the GTK stack
go with them, leaving a plain pure-Go build: 843.8 MiB -> 57.7 MiB.

3.0.0 reworks the command line: `--output` is the response format on
every command, no secret is accepted as a flag value, and several
subcommands moved. The release note carries the breaks.

https://github.com/roman-16/proton-cli/blob/main/CHANGELOG.md

Assisted-by: pi 0.85.0 (Anthropic claude-opus-5)
2026-09-05 17:52:59 +02:00
VykosMolt
82a791baa5 pcsclite: fix pcsc-spy interpreter
Patch pcsc-spy with the host Python after moving it to dev. The automatic dev-output hook uses the build path, leaving /usr/bin/python3 unchanged with strictDeps.

Add an execution test for pcsc-spy --help.

Fixes #557676

Assisted-by: Codex (GPT-6 Astra)
2026-09-05 13:09:05 +02:00
hakan-demirli
00588fd903 python3Packages.inline-snapshot: skip documentation tests 2026-09-05 00:35:22 +02:00
Emilio López
85ccec0a1f libff: fix header installation with CMake 4.3+
CMake 4.3 (commit 4e7e6928cb, "install: Fix bugs around empty
directories") changed install(DIRECTORY "" ...): the empty string used to
silently expand to the current source directory, and is now a no-op that
creates the destination directory but installs nothing into it. libff
uses that form for its headers, so since the cmake 4.3.4 bump the
package ships an empty include/libff and dependents such as hevm fail
to compile with:

  fatal error: libff/algebra/fields/bigint.hpp: No such file or directory

Replace the empty string with "./" so the header tree is installed again.

See https://gitlab.kitware.com/cmake/cmake/-/issues/27568

Assisted-by: Claude Code (Claude Fable 5.1)
2026-09-04 14:23:34 -03:00
Stefan Frijters
4cbf08b937 rustc: enable strictDeps 2026-09-04 15:33:32 +02:00
Stefan Frijters
05283c8449 cargo: enable structuredAttrs 2026-09-04 15:33:00 +02:00
Stefan Frijters
6749ed78c9 cargo-auditable-cargo-wrapper: enable strictDeps, enable structuredAttrs 2026-09-04 15:32:29 +02:00
Stefan Frijters
e9c36d6b0f cargo: enable strictDeps, enabled structuredAttrs for binary derivation 2026-09-04 15:31:18 +02:00
Stefan Frijters
d1c11f1d55 rustc: enable strictDeps, enable structuredAttrs for binary derivation 2026-09-04 15:30:27 +02:00
Stefan Frijters
5975da64bb rustc: enable structuredAttrs in wrapper 2026-09-04 15:28:11 +02:00
Stefan Frijters
0b1d179e29 rustPlatform.fetchCargoVendor: enable strictDeps, enable structuredAttrs 2026-09-04 15:27:04 +02:00
Stefan Frijters
0da45eb98e iana-etc: enable structuredAttrs, use finalAttrs, use hash 2026-09-04 13:55:23 +02:00
Stefan Frijters
11c8783464 iana-etc: enable strictDeps 2026-09-04 13:55:23 +02:00
whispers
54c6f0648c go_1_26: 1.26.7 -> 1.26.8
changelog: https://go.dev/doc/devel/release#go1.26.minor
diff: https://github.com/golang/go/compare/go1.26.7...go1.26.8
2026-09-03 18:05:17 -04:00
Gaetan Lepage
2ad46cfb95 abseil-cpp: 20260107.1 -> 20260817.0
Diff:
https://github.com/abseil/abseil-cpp/compare/20260107.1...20260817.0

Changelogs:
- https://github.com/abseil/abseil-cpp/releases/tag/20260526.0
- https://github.com/abseil/abseil-cpp/releases/tag/20260817.0
2026-09-02 12:36:50 +00:00
R. Ryantm
d4a13a495e openlibm: 0.8.7 -> 0.8.8 2026-09-02 12:34:23 +00:00
Fabian Affolter
09c32059eb python3Packages.pyrate-limiter: migrate to finalAttrs 2026-09-02 09:06:31 +02:00
R. Ryantm
d3bac142d1 python3Packages.pyrate-limiter: 4.4.0 -> 4.5.0 2026-09-02 06:33:32 +00:00
Robert Schütz
1163f773c6 gpgmepp: 2.1.0 -> 2.2.0
Changelog: https://dev.gnupg.org/source/gpgmepp/browse/master/NEWS;gpgmepp-2.2.0?as=remarkup
2026-09-01 15:03:01 -07:00
Jamie Magee
44869a3612 rust-bindgen: pass target triple when cross-compiling 2026-09-01 14:11:27 -07:00
R. Ryantm
9f4d3355dc liblouis: 3.38.0 -> 3.39.0 2026-09-01 17:25:05 +00:00
R. Ryantm
2cb2ee32e5 libfastjson: 1.2304.0 -> 1.2609.0 2026-09-01 17:21:40 +00:00
chemonke
3e8bce5d58 python3Packages.selfies: init at 2.2.0
Co-authored-by: Ross George <mrrosspgeorge@gmail.com>
2026-09-01 16:19:10 +02:00
R. Ryantm
34902c088f python3Packages.pyvips: 3.1.1 -> 3.2.0 2026-09-01 11:05:09 +00:00
chemonke
f7210faefa maintainers: add chemonke 2026-09-01 11:39:39 +02:00
R. Ryantm
380b627719 python3Packages.pywikibot: 11.6.0 -> 11.7.0 2026-09-01 05:13:11 +00:00
Robert Schütz
7fa51063df gpgme: 2.1.2 -> 2.2.0
Changelog: https://github.com/gpg/gpgme/blob/gpgme-2.2.0/NEWS
2026-08-31 19:46:46 -07:00
R. Ryantm
aaef923e34 azurite: 3.35.0 -> 3.37.0 2026-08-31 22:04:05 +00:00
R. Ryantm
457a58c29b netmaker: 1.6.0 -> 1.7.0 2026-08-31 21:13:46 +00:00
Sergei Trofimovich
9bbb6926e1 imlib2: 1.12.6 -> 1.12.7
Changes: https://www.mail-archive.com/enlightenment-devel@lists.sourceforge.net/msg117685.html
2026-08-31 21:51:51 +01:00
Roman
1bf24d8815 proton-cli: don't run the built binary when cross-compiling
The completions are generated by running the binary that was just
built, which the build machine cannot do when it is not the host
platform. stdenv already disables the install check on exactly this
condition; postInstall was the one place ignoring it.

Assisted-by: pi 0.84.2 (Anthropic claude-opus-5)
2026-08-31 22:31:33 +02:00
Stefan Frijters
6fd9290118 libidn2: modernize non-bootstrap build, fix comment 2026-08-31 12:06:57 +02:00
Stefan Frijters
971823d346 libidn2: enable strictDeps and structuredAttrs for non-bootstrap build 2026-08-31 12:06:49 +02:00
Stefan Frijters
a1c497ad0e srt: enable structuredAttrs, use tag/hash 2026-08-31 11:40:36 +02:00
Stefan Frijters
f3dedf6799 srt: enable strictDeps 2026-08-31 11:40:34 +02:00
Stefan Frijters
fd5f39bb5c simdjson: enable structuredAttrs 2026-08-31 11:37:57 +02:00
Stefan Frijters
849f0cc989 simdjson: enable strictDeps 2026-08-31 11:37:56 +02:00
Stefan Frijters
dceabcb721 jbig2dec: enable structuredAttrs 2026-08-31 11:36:57 +02:00
Stefan Frijters
7e51d02b33 jbig2dec: enable strictDeps 2026-08-31 11:36:56 +02:00
Stefan Frijters
93a0568e38 imath: enable structuredAttrs, use tag 2026-08-31 11:36:30 +02:00
Stefan Frijters
c55bf541fe imath: enable strictDeps 2026-08-31 11:35:31 +02:00
OPNA2608
7adb46d173 python3Packages.appnope: 0.1.4 -> 1.0.0 2026-08-30 21:10:33 +02:00
Robert Schütz
d801a11a6b catch2_3: use finalAttrs 2026-08-29 21:51:49 -07:00
Robert Schütz
cb288385c4 catch2_3: 3.15.3 -> 3.16.0
Diff: https://github.com/catchorg/Catch2/compare/v3.15.3...v3.16.0

Changelog: https://github.com/catchorg/Catch2/blob/v3.16.0/docs/release-notes.md
2026-08-29 21:50:05 -07:00
Tom Hunze
107da3649c nixosTests.installed-tests.gjs: fix build
These tests require cairo and xlib typelibs.

Hydra: https://hydra.nixos.org/build/343716867
2026-08-28 12:17:56 +02:00
Stefan Frijters
bcff0884c7 db{4,5,6}: enable structuredAttrs 2026-08-28 11:39:02 +02:00
Stefan Frijters
191d65e9b0 db{4,5,6}: enable strictDeps 2026-08-28 11:38:44 +02:00
jopejoe1
16dfea4ec2 lib.licenses: drop gfl in favor of lppl13c 2026-08-27 20:21:20 +02:00
Stefan Frijters
3117f84f1d boehmgc: enable strictDeps, use tag 2026-08-27 13:10:10 +02:00
jopejoe1
9f39f06d61 libopus: switch to fetchFromGitLab and fetch models separately 2026-08-27 11:02:38 +02:00
liberodark
43bb5f368b haskell.compiler: apply LLVM split sections fix unconditionally 2026-08-27 10:46:34 +02:00
R. Ryantm
17a75aa77d libvpx: 1.16.0 -> 1.17.0 2026-08-26 00:45:19 +00:00
Sergei Trofimovich
77e8072674 gdk-pixbuf: 2.44.7 -> 2.44.8
Changes: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/compare/2.44.7...2.44.8
2026-08-25 21:34:09 +01:00
benaryorg
08eff661f2 ceph.tests: comprehensive output
This will make the output much more verbose, but also show the actual errors in the test output if there are any.

Signed-off-by: benaryorg <binary@benary.org>
2026-08-25 07:47:19 +00:00
benaryorg
635b673496 ceph.tests: fixes for 20.2.4 2026-08-25 07:47:19 +00:00
benaryorg
593dd64de2 ceph.tests: osd creation via ceph-volume
Signed-off-by: benaryorg <binary@benary.org>
2026-08-25 07:37:44 +00:00
benaryorg
0fdef1d59a ceph.tests: cleanup of deprecated tests
The old tests should be completely superseded by the new ones at this point.
I left in the *ceph-single-node-bluestore* test because covering single node setups might be beneficial, even if it duplicates a lot of the code.
However we should be able to trim down the single node code quite a bit, basically if RADOS works then we should be able to assume everything else works too, as long as the multi-node tests pass.

Signed-off-by: benaryorg <binary@benary.org>
2026-08-25 07:37:44 +00:00
benaryorg
edf461ab8b ceph.tests: dashboard test in multi-node setup
Signed-off-by: benaryorg <binary@benary.org>
2026-08-25 07:37:44 +00:00
benaryorg
2888c1ab83 ceph.tests: latest linux kernel
This is required for the tests to pass since the `aes256k` cipher (the secure one) is only available since version 7.0.

Signed-off-by: benaryorg <binary@benary.org>
2026-08-25 07:37:43 +00:00
Niklas Hambüchen
23fb8b42d4 rl: Mention recommended Ceph vulnerability key rotation 2026-08-25 04:11:00 +00:00
Niklas Hambüchen
d611102d5d ceph: 20.2.3 -> 20.2.4 2026-08-25 04:10:59 +00:00
Oleksandr Usov
1e8e68e5a9 git: fix interpreter paths in contrib scripts 2026-08-24 20:13:00 +01:00
jopejoe1
037be2d137 darwin.shell_cmds: update license
Ran `scancode` through the source code to find those
2026-08-21 18:01:56 +02:00
jopejoe1
344273fedf darwin.basic_cmds: set license to bsd3
Found no refrence to `ISC` in the source code
2026-08-21 15:45:58 +02:00
Adam Dinwoodie
b9cba33d74 python3Packages.hatchling: 1.31.0 -> 1.32.0
Changelog: https://github.com/pypa/hatch/releases/tag/hatchling-v1.32.0

This includes adding tomlkit as a dependency.
2026-08-21 11:21:09 +01:00
Adam Dinwoodie
96217f333c python3Packages.{poetry-core,tomlkit}: disable checks
To avoid bootstrap issues caused by packages required when running the
checks, skip the check phase as part of building poetcy-core and
tomlkit.  To avoid losing the benefit of those checks, add them back in
outside the dependency chain within `passthru.tests`.
2026-08-21 11:21:05 +01:00
R. Ryantm
4a2ac39b4f colloid-cursors: 2025-07-19 -> 2026-08-10 2026-08-21 02:46:45 +00:00
R. Ryantm
e93035fc75 sdrangel: 7.27.1 -> 7.27.2 2026-08-20 11:25:04 +00:00
Adam Dinwoodie
f3b3e9a8d2 python3Packages.{poetry-core,tomlkit}: use finalAttrs
Minor refactoring of these two Python packages to use `finalAttrs` rather
than `rec` for self-references.  This also permits the package
definitions to reference other attributes found in `finalAttrs`, notably
`finalAttrs.finalPackage`.
2026-08-20 12:22:27 +01:00
Sergei Trofimovich
5f16fc985c libmicrohttpd: 1.0.6 -> 1.0.10 2026-08-19 22:01:58 +01:00
Aaron Andersen
b25306b0d4 ppp: replace systemd dependency with systemdLibs 2026-08-19 16:30:04 -04:00
seth
785ec6b49a zlib: use default configure script on windows
This avoids the pitfalls of win32/Makefile.gcc (which prevents building
on compilers other than gcc without patching and has non-standard
installation behavior) and fixes cross compilation for ucrtAarch64

Putting the DLL's in `$out/bin` was given the approval of:

John Ericson <John.Ericson@Obsidian.Systems>
2026-08-19 17:50:14 +03:00
Doron Behar
51044d203a zlib: remove not needed anymore lld linker workaround
Tested that with this change the packages
`pkgsCross.x86_64-{freebsd,openbsd}.zlib` build from an `x86_64-linux`
build platform, and that their hashes actually are changed due to this.
2026-08-19 17:49:34 +03:00
R. Ryantm
ec82f03086 simplebluez: 0.11.0 -> 1.1.0 2026-08-19 01:48:51 +00:00
Aaron Andersen
66b6f41fd3 networkmanager: replace systemd dependency with systemdMinimal 2026-08-18 20:41:35 -04:00
Aaron Andersen
58d084bdd2 modemmanager: replace systemd dependency with systemdLibs 2026-08-18 20:34:56 -04:00
Aaron Andersen
43c642606d speechd: add withSystem option 2026-08-18 20:04:32 -04:00
Aaron Andersen
3f37524554 speechd: replace systemd dependency with systemdLibs 2026-08-18 20:03:14 -04:00
Sergei Trofimovich
17e5e45040 lndir: 1.0.5 -> 1.0.6
Changes: https://www.mail-archive.com/xorg-announce@lists.x.org/msg01945.html
2026-08-18 21:28:58 +01:00
R. Ryantm
6c020e42a4 process-compose: 1.120.0 -> 1.122.0 2026-08-18 02:27:56 +00:00
Aaron Jheng
0a9281fd8d lame: 3.100 -> 4.0 2026-08-17 08:35:43 +08:00
R. Ryantm
d33eaecdad librice: 0.3.0 -> 0.4.3 2026-08-16 14:26:00 +02:00
Otavio Salvador
0503d597da bitbake-setup: init at 2.19.0
bitbake-setup is the OpenEmbedded utility that creates a BitBake build
environment from a published configuration. It bundles the BitBake `bb`
library, so it needs no other Python packages.

Upstream publishes a wheel only. The Git repository has no build files
at the 2.19.0 tag: `packaging-pypi/bitbake-setup/` came later, and it
assembles the distribution with a script instead of a plain source tree.
The wheel is therefore the only released source.

`nix-update` cannot read the version from the `files.pythonhosted.org`
wheel URL, so the update script passes a `mirror://pypi` URL instead.

The tool runs `git` to fetch the configuration registry and the layers,
so the wrapper adds `git` to PATH.

Assisted-by: Claude Code (claude-opus-5)
2026-08-15 22:52:52 -03:00
DCsunset
a1b9c3cbdd python3Packages.scienceplots: 2.1.1 -> 2.2.2 2026-08-14 19:38:22 +00:00
KangaZero
6936a1272e libinklevel: 0.9.4 -> 0.9.7
Added `libxml2` to `buildInputs`; this was required since `0.9.5`
2026-08-14 13:35:22 +09:00
R. Ryantm
1e6f018531 python3Packages.proton-core: 0.7.0 -> 0.7.4 2026-08-13 06:10:23 +00:00
R. Ryantm
e59c1c0c42 xdg-dbus-proxy: 0.1.7 -> 0.1.8 2026-08-11 12:22:42 +00:00
jopejoe1
521ffc36c2 ffmpeg: add opencolorio support 2026-08-06 22:41:12 +02:00
jopejoe1
1d92aad267 ffmpeg: add optional support for mpeg-h decoding 2026-08-04 21:59:41 +02:00
jopejoe1
274a0a2361 ffmpeg: add cairo support 2026-08-04 21:58:03 +02:00
crumblingMizzle
6d980c2264 swig: fix cross-compilation 2026-08-03 18:33:25 -04:00
Thomas Gerbet
d2cbb4ba81 makeBinaryWrapper: reject prefix/suffix with an empty path segment
Preferred to reject explictly the value instead of silently sanitizing
it. It's closer to what we do for the invalid env name and it will allow
us to spot derivation that were impacted by the issue that has not yet
been fixed.
2026-08-02 17:01:28 +02:00
R. Ryantm
60a3f8ab66 python3Packages.azure-mgmt-privatedns: 1.2.0 -> 2.0.0 2026-08-01 08:53:18 +00:00
jopejoe1
416daa9b53 mpeghdec: init at 4.0.1 2026-07-31 16:46:20 +02:00
jopejoe1
c92f29ee31 mmtisobmff: init at 1.0.4 2026-07-31 16:46:20 +02:00
jopejoe1
c4787fe946 ilo: init at 2.0.2 2026-07-31 16:40:36 +02:00
Stefan Frijters
ed5ca467b9 python3Packages.dirty-equals: enable structuredAttrs, use finalAttrs 2026-07-25 01:39:55 +02:00
Stefan Frijters
7eb51f62c7 python3Packages.dirty-equals: fix tests
The tests were not actually enabled with overrideAttrs instead
of overridePythonAttrs.

Enabling them exposed a failure.
2026-07-25 01:39:51 +02:00
Ben Brown
340d0ca38e python3Packages.detect-secrets: disable tests for optional dependencies 2026-07-23 15:51:03 +01:00
bitbloxhub
5d03ccc350 gtk4: backport Wayland session cleanup null check 2026-07-23 00:40:56 +00:00
Felix Buehler
d07cc49cdc nixos/fedimintd: map vhost via lib.mkDefault 2026-07-22 00:04:20 +02:00
SandaruKasa
c5898aaf41 libaom: strictDeps, __structuredAttrs 2026-07-18 20:50:44 +03:00
SandaruKasa
a090aae6c1 libaom: 3.12.1 -> 3.14.1
Changelog: https://aomedia.googlesource.com/aom/+/refs/tags/v3.14.1/CHANGELOG
2026-07-18 20:46:55 +03:00
Diogo Correia
bd3f7f4429 nixos/tests/flaresolverr: fetch local webpage
This ensures that the browser is started and working.
2026-07-18 14:48:59 +01:00
OPNA2608
57f55719d4 cc-wrapper: Default-disable AltiVec with powerpc64-linux LLVM
GCC is very conservative about enabling AltiVec. The default target has it disabled, and it requires either:

- picking a CPU target that is generic POWER7 or higher, or is a specific CPU model that had AltiVec, or
- using -maltivec to opt into it

LLVM default-enables AltiVec, and has it marked as supported on CPUs that historically lacked it.

Inconsistency aside, this leads to issues when building things with Clang that do not expect just AltiVec to be enabled, like webkitgtk.

To make things more consistent, if no gcc.cpu is configured, pass -mno-altivec to Clang.
2026-07-15 22:47:56 +02:00
R. Ryantm
77e36bcb9d thrift: 0.22.0 -> 0.24.0 2026-07-15 17:47:14 +00:00
R. Ryantm
54c1571722 nghttp3: 1.16.0 -> 1.17.0 2026-07-15 04:27:21 +00:00
R. Ryantm
9c06a6653d memcached: 1.6.42 -> 1.6.45 2026-07-12 06:27:58 +00:00
David Mkhitaryan
5151482e19 sacad: 2.8.3 -> 3.0.1 2026-07-09 16:31:25 +04:00
zowoq
44dc047ef5 maintainers/team-list: remove maintainer from buildbot 2026-07-09 12:02:47 +10:00
zowoq
b0b3191811 ci/OWNERS: remove maintainer from buildbot 2026-07-09 12:02:47 +10:00
Felix Stupp
8c75f138ff nixos/adguardhome: add tests ensuring logging to syslog works 2026-06-16 00:38:06 +00:00
Felix Stupp
6ac56136e5 nixos/adguardhome: allow AF_UNIX when log.file=="syslog" 2026-06-16 00:25:37 +00:00
Hythera
a734897cbe libqrtr-glib: 1.2.2 -> 1.4.0
diff: https://gitlab.freedesktop.org/mobile-broadband/libqrtr-glib/-/compare/1.2.2...1.4.0
2026-06-12 20:25:53 +02:00
Sandro
51a9e8c3db nixos/installer: fix defaultText rendering as plain string 2026-06-11 17:24:36 +02:00
SandaruKasa
69e163e571 dconf: strictDeps & __structuredAttrs
`nix store make-content-addressed` gives the same output
before and after this change
2026-06-11 02:13:04 +03:00
SandaruKasa
7edc8b4006 dconf: add man output
out: 104K -> 92K
man: 0K -> 12K
2026-06-11 02:12:03 +03:00
codgician
34edde092d perlPackages.XMLTwig: 3.52 -> 3.54 2026-05-27 13:49:48 +08:00
Amaan Qureshi
c4d7c303d3 spandsp: disable lpc10_tests on ppc64
The LPC-10 test checks decoded audio against a reference WAV generated
on x86. On POWER, small float rounding differences in the encoder
accumulate over hundreds of frames and eventually produce different
output, even though the codec itself works correctly.
2026-03-12 06:03:13 -04:00
Amaan Qureshi
7dbd6409f8 spandsp: fix bit_operations_tests UB on ppc64be 2026-03-12 00:52:39 -04:00
Amaan Qureshi
10a4220c8a spandsp: fix dead source URL, add mirror 2026-03-12 00:44:19 -04:00
Gutyina Gergő
bba8b3a2a9 cisco-packet-tracer_9: add mime files
This fixes the system not recognizing file types like .pkt and not
opening them with packet tracer.
2026-03-03 12:27:36 +01:00
1554 changed files with 35452 additions and 36627 deletions

View File

@@ -130,7 +130,7 @@ jobs:
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
with:
script: |
const { default: checkCommitMessages } = await import('${{ github.workspace }}/trusted/ci/github-script/lint-commits.js')
const { default: checkCommitMessages } = await import('${{ github.workspace }}/trusted/ci/github-script/lint-commits.ts')
await checkCommitMessages({
github,

View File

@@ -38,8 +38,8 @@ jobs:
TARGET_SHA: ${{ inputs.targetSha }}
with:
script: |
const { classify } = await import('${{ github.workspace }}/ci/github-script/supportedBranches.js')
const { default: supportedSystems } = await import('${{ github.workspace }}/ci/github-script/supportedSystems.js')
const { classify } = await import('${{ github.workspace }}/ci/github-script/supportedBranches.ts')
const { default: supportedSystems } = await import('${{ github.workspace }}/ci/github-script/supportedSystems.ts')
const baseBranch = (
context.payload.merge_group?.base_ref ??

View File

@@ -64,8 +64,8 @@ jobs:
'.github/workflows/test.yml',
'ci/github-script/package.json',
'ci/github-script/package-lock.json',
'ci/github-script/supportedBranches.js',
'ci/github-script/supportedSystems.js',
'ci/github-script/supportedBranches.ts',
'ci/github-script/supportedSystems.ts',
'ci/pinned.json',
'pkgs/top-level/release-supported-systems.json',
].includes(file))) core.setOutput('merge-group', true)
@@ -82,8 +82,8 @@ jobs:
'ci/github-script/bot.js',
'ci/github-script/check-target-branch.ts',
'ci/github-script/commits.ts',
'ci/github-script/get-pr-commit-details.js',
'ci/github-script/lint-commits.js',
'ci/github-script/get-pr-commit-details.ts',
'ci/github-script/lint-commits.ts',
'ci/github-script/manual-file-edits.ts',
'ci/github-script/merge.js',
'ci/github-script/package.json',
@@ -91,9 +91,9 @@ jobs:
'ci/github-script/prepare.js',
'ci/github-script/reminders.ts',
'ci/github-script/reviewers.js',
'ci/github-script/reviews.js',
'ci/github-script/supportedBranches.js',
'ci/github-script/supportedSystems.js',
'ci/github-script/reviews.ts',
'ci/github-script/supportedBranches.ts',
'ci/github-script/supportedSystems.ts',
'ci/github-script/withRateLimit.js',
'ci/pinned.json',
'pkgs/top-level/release-supported-systems.json',

View File

@@ -444,9 +444,9 @@ nixos/tests/forgejo.nix @adamcstephens @bendlas @christoph-heiss @
/doc/hooks/zig.section.md @RossComputerGuy
# Buildbot
nixos/modules/services/continuous-integration/buildbot @Mic92 @zowoq
nixos/tests/buildbot.nix @Mic92 @zowoq
pkgs/development/tools/continuous-integration/buildbot @Mic92 @zowoq
nixos/modules/services/continuous-integration/buildbot @Mic92
nixos/tests/buildbot.nix @Mic92
pkgs/development/tools/continuous-integration/buildbot @Mic92
# Pretix
pkgs/by-name/pr/pretix/ @mweinelt

View File

@@ -104,7 +104,7 @@ For the purposes of CI, branches in the NixOS/nixpkgs repository are classified
Some branches also have a version component, which is either `unstable` or `YY.MM`.
`ci/github-script/supportedBranches.js` is a script imported by CI to classify the base and head branches of a Pull Request.
`ci/github-script/supportedBranches.ts` is a script imported by CI to classify the base and head branches of a Pull Request.
This classification will then be used to skip certain jobs.
This script can also be run locally to print basic test cases.

View File

@@ -4,7 +4,7 @@ import path from 'node:path'
import { DefaultArtifactClient } from '@actions/artifact'
import { handleMerge } from './merge.js'
import { handleReviewers } from './reviewers.js'
import { classify } from './supportedBranches.js'
import { classify } from './supportedBranches.ts'
import withRateLimit from './withRateLimit.js'
export default async ({ github, context, core, dry }) => {

View File

@@ -1,4 +1,4 @@
import { classify, split } from './supportedBranches.js'
import { classify, split } from './supportedBranches.ts'
type TargetBranchPolicyFacts = {
base: string

View File

@@ -6,8 +6,8 @@ import {
evaluateTargetBranchPolicy,
getTargetBranchPolicy,
} from './check-target-branch-policy.ts'
import { dismissReviews, postReview } from './reviews.js'
import { split } from './supportedBranches.js'
import { dismissReviews, postReview } from './reviews.ts'
import { split } from './supportedBranches.ts'
// TODO: should this be combined with the branch checks in prepare.js?
// They do seem quite similar, but this needs to run after eval,

View File

@@ -2,8 +2,8 @@ import { execFileSync } from 'node:child_process'
import type * as actionsCore from '@actions/core'
import type { context as actionsContext } from '@actions/github'
import type { GitHub } from '@actions/github/lib/utils'
import { dismissReviews, postReview } from './reviews.js'
import { classify } from './supportedBranches.js'
import { dismissReviews, postReview } from './reviews.ts'
import { classify } from './supportedBranches.ts'
import withRateLimit from './withRateLimit.js'
const dirname = import.meta.dirname

View File

@@ -3,26 +3,23 @@ import { promisify } from 'node:util'
const execFile = promisify(nodeExecFile)
/**
* @typedef {{
* subject: string,
* sha: string,
* author: { name: string, email: string },
* committer: { name: string, email: string}
* changedPaths: string[],
* changedPathSegments: Set<string>,
* }} Commit
*/
export type Commit = {
subject: string
sha: string
author: { name: string; email: string }
committer: { name: string; email: string }
changedPaths: string[]
changedPathSegments: Set<string>
}
/**
* @param {{
* args: string[]
* core: typeof import('@actions/core'),
* quiet?: boolean,
* repoPath?: string,
* }} RunGitProps
*/
async function runGit({ args, repoPath, core, quiet }) {
interface RunGitProps {
args: string[]
core: typeof import('@actions/core')
quiet?: boolean
repoPath?: string
}
async function runGit({ args, repoPath, core, quiet }: RunGitProps) {
if (repoPath) {
args = ['-C', repoPath, ...args]
}
@@ -34,21 +31,29 @@ async function runGit({ args, repoPath, core, quiet }) {
return await execFile('git', args)
}
interface GetCommitMessagesForPRProps {
core: typeof import('@actions/core')
pr: Awaited<
ReturnType<
InstanceType<
typeof import('@actions/github/lib/utils').GitHub
>['rest']['pulls']['get']
>
>['data']
repoPath?: string
}
/**
* Gets the SHA, subject and changed files for each commit in the given PR.
*
* Don't use GitHub API at all: the "list commits on PR" endpoint has a limit
* of 250 commits and doesn't return the changed files.
*
* @param {{
* core: typeof import('@actions/core'),
* pr: Awaited<ReturnType<InstanceType<typeof import('@actions/github/lib/utils').GitHub>["rest"]["pulls"]["get"]>>["data"]
* repoPath?: string,
* }} GetCommitMessagesForPRProps
*
* @returns {Promise<Commit[]>}
*/
export async function getCommitDetailsForPR({ core, pr, repoPath }) {
export async function getCommitDetailsForPR({
core,
pr,
repoPath,
}: GetCommitMessagesForPRProps): Promise<Commit[]> {
await runGit({
args: ['fetch', `--depth=1`, 'origin', pr.base.sha],
repoPath,

View File

@@ -1,17 +1,23 @@
import { getCommitDetailsForPR } from './get-pr-commit-details.js'
import { classify } from './supportedBranches.js'
import { type Commit, getCommitDetailsForPR } from './get-pr-commit-details.ts'
import { classify } from './supportedBranches.ts'
/** @typedef {import('./get-pr-commit-details.js').Commit} Commit */
type GitHub = InstanceType<typeof import('@actions/github/lib/utils').GitHub>
type Context = typeof import('@actions/github').context
type Core = typeof import('@actions/core')
/**
* @param {{
* github: InstanceType<typeof import('@actions/github/lib/utils').GitHub>,
* context: typeof import('@actions/github').context,
* core: typeof import('@actions/core'),
* repoPath?: string,
* }} LintCommitsProps
*/
export default async function lintCommits({ github, context, core, repoPath }) {
interface LintCommitsProps {
github: GitHub
context: Context
core: Core
repoPath?: string
}
export default async function lintCommits({
github,
context,
core,
repoPath,
}: LintCommitsProps) {
// This check should only be run when we have the pull_request context.
const pull_number = context.payload.pull_request?.number
if (!pull_number) {
@@ -53,13 +59,15 @@ export default async function lintCommits({ github, context, core, repoPath }) {
await checkCommitMetadata({ commits, core })
}
/**
* @param {{
* commits: Commit[],
* core: typeof import('@actions/core'),
* }} CheckCommitMessagesProps
*/
async function checkCommitMessages({ commits, core }) {
interface CheckCommitMessagesProps {
commits: Commit[]
core: Core
}
async function checkCommitMessages({
commits,
core,
}: CheckCommitMessagesProps) {
const failures = new Set()
const conventionalCommitTypes = [
@@ -80,10 +88,13 @@ async function checkCommitMessages({ commits, core }) {
]
/**
* @param {string[]} types e.g. ["fix", "feat"]
* @param {string?} sha commit hash
* @param types e.g. ["fix", "feat"]
* @param sha commit hash
*/
function makeConventionalCommitRegex(types, sha = null) {
function makeConventionalCommitRegex(
types: string[],
sha: string | null = null,
) {
core.info(
`${
sha
@@ -166,17 +177,15 @@ async function checkCommitMessages({ commits, core }) {
}
}
/**
* @param {{
* commits: Commit[],
* core: typeof import('@actions/core'),
* }} CheckGitFieldsProps
*/
async function checkCommitMetadata({ commits, core }) {
interface CheckGitFieldsProps {
commits: Commit[]
core: Core
}
async function checkCommitMetadata({ commits, core }: CheckGitFieldsProps) {
const failures = new Set()
/** @type {(s: string) => boolean} */
const isEmail = (s) => /^.+@.*$/.test(s)
const isEmail = (s: string) => /^.+@.*$/.test(s)
for (const commit of commits) {
if (!commit.author.name) {

View File

@@ -1,6 +1,6 @@
import { getCommitDetailsForPR } from './get-pr-commit-details.js'
import { dismissReviews, postReview } from './reviews.js'
import { classify } from './supportedBranches.js'
import { getCommitDetailsForPR } from './get-pr-commit-details.ts'
import { dismissReviews, postReview } from './reviews.ts'
import { classify } from './supportedBranches.ts'
export default async function checkManualFileEdits({
github,

View File

@@ -1,5 +1,5 @@
// @ts-nocheck
import { classify } from './supportedBranches.js'
import { classify } from './supportedBranches.ts'
function runChecklist({
committers,

View File

@@ -1,7 +1,7 @@
// @ts-nocheck
import { dismissReviews, postReview } from './reviews.js'
import { classify } from './supportedBranches.js'
import supportedSystems from './supportedSystems.js'
import { dismissReviews, postReview } from './reviews.ts'
import { classify } from './supportedBranches.ts'
import supportedSystems from './supportedSystems.ts'
const reviewKey = 'prepare'
@@ -66,7 +66,7 @@ export default async ({ github, context, core, dry }) => {
// commits between that base and head is the real base. We can query for this via GitHub's
// REST API. There can be multiple candidates for the real base with the same number of
// commits. In this case we pick the "best" candidate by a fixed ordering of branches,
// as defined in ci/github-script/supportedBranches.js.
// as defined in ci/github-script/supportedBranches.ts.
//
// These requests take a while, when comparing against the wrong release - they need
// to look at way more than 10k commits in that case. Thus, we try to minimize the

View File

@@ -3,9 +3,9 @@ import path from 'node:path'
import type * as actionsCore from '@actions/core'
import type { context as actionsContext } from '@actions/github'
import type { GitHub } from '@actions/github/lib/utils'
import { getCommitDetailsForPR } from './get-pr-commit-details.js'
import { dismissReviews, postReview } from './reviews.js'
import { classify } from './supportedBranches.js'
import { getCommitDetailsForPR } from './get-pr-commit-details.ts'
import { dismissReviews, postReview } from './reviews.ts'
import { classify } from './supportedBranches.ts'
/**
* Reminders to post as a non-blocking review when a pull request touches

View File

@@ -1,6 +1,6 @@
Thanks for contributing to the documentation
Make sure you follow the [documentation styleguide](https://github.com/NixOS/nixpkgs/blob/master/doc/styleguide.md), most notably:
Make sure you follow the [documentation style guide](https://github.com/NixOS/nixpkgs/blob/master/doc/styleguide.md), most notably:
- Show, don't tell: lead with a minimal working example; explanation follows the code.
- No meta-commentary: don't write "This section explains how to…", just do it.

View File

@@ -13,30 +13,28 @@ const reviewUsers = [
'manual-edit',
]
/**
* @typedef {InstanceType<typeof import('@actions/github/lib/utils').GitHub>} GitHub
* @typedef {typeof import('@actions/github').context} Context
*
* @typedef {Awaited<ReturnType<GitHub['rest']['pulls']['listReviews']>>['data'][number]} Review
* @typedef {Review & { user: NonNullable<Review['user']> }} ReviewWithNonNullUser
*/
type GitHub = InstanceType<typeof import('@actions/github/lib/utils').GitHub>
type Context = typeof import('@actions/github').context
type Review = Awaited<
ReturnType<GitHub['rest']['pulls']['listReviews']>
>['data'][number]
type ReviewWithNonNullUser = Review & { user: NonNullable<Review['user']> }
interface DismissReviewsProps {
github: GitHub
context: Context
core: typeof import('@actions/core')
dry: boolean
reviewKey?: string
}
/**
* @param {{
* github: GitHub,
* context: Context,
* core: typeof import('@actions/core'),
* dry: boolean,
* reviewKey?: string,
* }} DismissReviewsProps
*/
export async function dismissReviews({
github,
context,
core,
dry,
reviewKey,
}) {
}: DismissReviewsProps) {
const pull_number = context.payload.pull_request?.number
if (!pull_number) {
core.warning('dismissReviews called outside of pull_request context')
@@ -47,23 +45,29 @@ export async function dismissReviews({
return
}
const allReviews = await github.paginate(github.rest.pulls.listReviews, {
...context.repo,
pull_number,
})
const allReviews: Review[] = await github.paginate(
github.rest.pulls.listReviews,
{
...context.repo,
pull_number,
},
)
const reviews = /** @type {ReviewWithNonNullUser[]} */ (
allReviews.filter(
const reviews = allReviews
.filter((review): review is ReviewWithNonNullUser => !!review.user)
.filter(
(review) =>
review.user &&
review.state !== 'DISMISSED' &&
review.user.login.endsWith('[bot]') &&
reviewUsers.some((substr) => review.user?.login.includes(substr)),
)
)
const reviewsByUser = reviews.reduce(
(prev, curr) => {
if (!curr.user) {
return prev
}
if (!(curr.user.login in prev)) {
prev[curr.user.login] = []
}
@@ -72,7 +76,7 @@ export async function dismissReviews({
return prev
},
/** @type {Record<string, ReviewWithNonNullUser[]> } */ ({}),
{} as Record<string, ReviewWithNonNullUser[]>,
)
const commentRegex = new RegExp(
@@ -86,8 +90,8 @@ export async function dismissReviews({
)
let reviewsToMinimize = reviews
const /** @type {ReviewWithNonNullUser[]} */ reviewsToDismiss = []
const /** @type {ReviewWithNonNullUser[]} */ reviewsToResolve = []
const reviewsToDismiss: ReviewWithNonNullUser[] = []
const reviewsToResolve: ReviewWithNonNullUser[] = []
if (reviewKey && reviews.every((review) => commentRegex.test(review.body))) {
reviewsToMinimize = reviews.filter((review) =>
@@ -165,17 +169,16 @@ export async function dismissReviews({
])
}
/**
* @param {{
* github: GitHub,
* context: Context,
* core: typeof import('@actions/core'),
* dry: boolean,
* body: string,
* event: keyof typeof eventToState,
* reviewKey: string,
* }} PostReviewProps
*/
interface PostReviewProps {
github: GitHub
context: Context
core: typeof import('@actions/core')
dry: boolean
body: string
event: keyof typeof eventToState
reviewKey: string
}
export async function postReview({
github,
context,
@@ -184,7 +187,7 @@ export async function postReview({
body,
event = 'REQUEST_CHANGES',
reviewKey,
}) {
}: PostReviewProps) {
const pull_number = context.payload.pull_request?.number
if (!pull_number) {
core.warning('postReview called outside of pull_request context')
@@ -210,8 +213,7 @@ export async function postReview({
reviewUsers.some((substr) => review.user?.login.includes(substr)),
)
/** @type {null | Review} */
let pendingReview
let pendingReview: null | Review
const matchingReviews = reviews.filter((review) =>
reviewKeyRegex.test(review.body),
)

View File

@@ -101,7 +101,7 @@ program
.argument('<repo>', 'Name of the GitHub repository to run on (Example: nixpkgs)')
.argument('<pr>', 'Number of the Pull Request to run on')
.action(async (owner, repo, pr, options) => {
const checkCommitMessages = (await import('./lint-commits.js')).default
const checkCommitMessages = (await import('./lint-commits.ts')).default
await run(checkCommitMessages, owner, repo, pr, options)
})

View File

@@ -2,11 +2,12 @@
/*
#!nix-shell -i node -p nodejs
*/
// @ts-nocheck
import { resolve } from 'node:path'
import { fileURLToPath } from 'node:url'
const typeConfig = {
type BranchType = 'channel' | 'development' | 'primary' | 'secondary'
const typeConfig: Record<string, BranchType[]> = {
master: ['development', 'primary'],
release: ['development', 'primary'],
staging: ['development', 'secondary'],
@@ -19,7 +20,7 @@ const typeConfig = {
// "order" ranks the development branches by how likely they are the intended base branch
// when they are an otherwise equally good fit according to ci/github-script/prepare.js.
const orderConfig = {
const orderConfig: Record<string, number> = {
master: 0,
release: 1,
staging: 2,
@@ -28,15 +29,30 @@ const orderConfig = {
'staging-next': 4,
}
function split(branch) {
return {
...branch.match(
/(?<prefix>.+?)(-(?<version>\d{2}\.\d{2}|unstable)(?:-(?<suffix>.*))?)?$/,
).groups,
}
type Digit = 0 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9
type Version = `${Digit}${Digit}.${Digit}${Digit}` | 'unstable'
interface SplitResult {
prefix: string
version: Version
suffix?: string
}
function classify(branch) {
function split(branch: string) {
const groups = branch.match(
/(?<prefix>.+?)(-(?<version>\d{2}\.\d{2}|unstable)(?:-(?<suffix>.*))?)?$/,
)!.groups!
return groups as unknown as SplitResult
}
interface BranchClassification {
branch: string
order: number
stable: boolean
type: BranchType[]
version: Version
}
function classify(branch: string): BranchClassification {
const { prefix, version } = split(branch)
return {
branch,
@@ -55,7 +71,7 @@ if (
fileURLToPath(import.meta.url) === resolve(process.argv[1])
) {
console.log('split(branch)')
function testSplit(branch) {
function testSplit(branch: string) {
console.log(branch, split(branch))
}
testSplit('master')
@@ -72,7 +88,7 @@ if (
console.log('')
console.log('classify(branch)')
function testClassify(branch) {
function testClassify(branch: string) {
console.log(branch, classify(branch))
}
testClassify('master')

View File

@@ -1,11 +0,0 @@
// @ts-nocheck
export default async ({ github, context, targetSha }) => {
const { content, encoding } = (
await github.rest.repos.getContent({
...context.repo,
path: 'pkgs/top-level/release-supported-systems.json',
ref: targetSha,
})
).data
return JSON.parse(Buffer.from(content, encoding).toString())
}

View File

@@ -0,0 +1,30 @@
interface SupportedSystemsProps {
github: InstanceType<typeof import('@actions/github/lib/utils').GitHub>
context: typeof import('@actions/github').context
targetSha: string
}
export default async ({
github,
context,
targetSha,
}: SupportedSystemsProps) => {
const contentObject = (
await github.rest.repos.getContent({
...context.repo,
path: 'pkgs/top-level/release-supported-systems.json',
ref: targetSha,
})
).data
if ('type' in contentObject && contentObject.type === 'file') {
const { content, encoding } = contentObject
return JSON.parse(
Buffer.from(content, encoding as BufferEncoding).toString(),
)
} else {
throw new Error(
'Fetched pkgs/top-level/release-supported-systems.json is not a file',
)
}
}

View File

@@ -7,19 +7,26 @@ This directory houses the source files for the Nixpkgs manual.
> We are actively restructuring our documentation to be more beginner friendly.
>
When writing new docs use **Progressive Disclosure**
When writing new docs use **Progressive Disclosure:**
Start simple, pick up beginners.
Use **examples** first to show how to get something done. Keep **Explanation** lean.
- Start simple, pick up beginners.
- Use **examples** first to show how to get something done.
- Keep **explanation** lean.
Use our [styleguide](./styleguide.md) for more in depth guidance on writing good documentation.
Use our [style guide](./styleguide.md) for more in depth guidance on writing good documentation.
Documentation about Nixpkgs belongs here, this includes 'getting-started'-guides and 'onboarding-guides' for *using* Nixpkgs and the language frameworks it ships.
Documentation about Nixpkgs belongs here.
This includes getting started guides and onboarding guides for *using* Nixpkgs and the language frameworks it ships.
Write **guides** task-first: lead with a working example, then explain in prose.
Write **reference** as the specification of functions and attributes.
We are actively working to generate reference documentation from the [doc-comments](https://github.com/NixOS/rfcs/blob/master/rfcs/0145-doc-strings.md) present in code, which also lets you view it locally with `:doc` in `nix repl`.
We are actively working to generate reference documentation from the [doc-comments](https://github.com/NixOS/rfcs/blob/master/rfcs/0145-doc-strings.md) present in code, which also lets you view it locally with the `:doc` command in `nix repl`, e.g.:
```
nix-repl> :l <nixpkgs>
nix-repl> :doc lib.mapAttrsToList
```
See [Document structure](#document-structure) for a structural template.
@@ -42,23 +49,23 @@ If the build succeeds, the manual will be in `./result/share/doc/nixpkgs/manual.
### Development environment
To reduce repetition, consider using tools from the provided development environment:
Load it from the Nixpkgs documentation directory with
To reduce repetition, consider using tools from the documentation development environment:
```ShellSession
$ cd /path/to/nixpkgs/doc
$ nix-shell
```
To load the development utilities automatically when entering that directory, [set up `nix-direnv`](https://nix.dev/guides/recipes/direnv).
To load the documentation development environment automatically when entering that directory:
Make sure that your local files aren't added to Git history by adding the following lines to `.git/info/exclude` at the root of the Nixpkgs repository:
1. Install [`nix-direnv`](https://search.nixos.org/packages?channel=unstable&query=nix-direnv#show=nix-direnv)
1. Set up direnv in the documentation directory:
```
/**/.envrc
/**/.direnv
```
```ShellSession
$ cd doc
$ echo "use nix" > .envrc
$ direnv allow
```
#### Live preview
@@ -133,14 +140,12 @@ A few markups for other kinds of literals are also available:
- `` {env}`XDG_DATA_DIRS` ``
- `` {file}`/etc/passwd` ``
- `` {option}`networking.useDHCP` ``
- `` {var}`/etc/passwd` ``
- `` {var}`pkgs` ``
The values will be formatted as inline `<code>` elements.
These literal kinds are used mostly in NixOS option documentation.
This syntax is taken from [MyST](https://myst-parser.readthedocs.io/en/latest/syntax/syntax.html#roles-an-in-line-extension-point).
Though, the feature originates from [reStructuredText](https://www.sphinx-doc.org/en/master/usage/restructuredtext/roles.html#role-manpage) with slightly different syntax.
They are handled by `myst_role` defined per renderer. <!-- reverse references in code -->
#### Admonitions
Set off from the text to bring attention to something.
@@ -163,7 +168,7 @@ The following are supported:
- `example`
Example admonitions require a title to work.
If you don't provide one, the manual won't be built.
If you don't provide one, the manual won't build.
```markdown
::: {.example #ex-showing-an-example}
@@ -179,11 +184,11 @@ Text for the example.
For defining a group of terms:
```markdown
pear
: green or yellow bulbous fruit
Pear
: Green or yellow bulbous fruit
watermelon
: green fruit with red flesh
Watermelon
: Green fruit with red flesh
```
## Commit conventions
@@ -215,7 +220,7 @@ When needed, each convention explains why it exists, so you can make a decision
Note that these conventions are about the **structure** of the manual (and its source files), not about the content that goes in it.
You, as the writer of documentation, are still in charge of its content.
**For prose style, see the [documentation styleguide](./styleguide.md).**
**For prose style, see the [documentation style guide](./styleguide.md).**
### Document structure
@@ -285,7 +290,7 @@ When changing existing content, update formatting if possible, but avoid excessi
### Examples first
Put examples before detailed explanations (see the [styleguide](./styleguide.md) for the rationale).
Put examples before detailed explanations (see the [style guide](./styleguide.md) for the rationale).
Use this structure for each documented item:

View File

@@ -5,7 +5,7 @@ Create a `shell.nix` with the following:
```nix
# shell.nix
let
nixpkgs = fetchTarball "https://github.com/NixOS/nixpkgs/archive/nixos-unstable.tar.gz";
nixpkgs = fetchTarball "https://channels.nixos.org/nixos-unstable/nixexprs.tar.zst";
pkgs = import nixpkgs { };
in
pkgs.mkShell {
@@ -25,7 +25,7 @@ nix-shell
This activates your `shell.nix` and you should see:
```sh
unpacking 'https://github.com/NixOS/nixpkgs/archive/nixos-unstable.tar.gz' into the Git cache...
unpacking 'https://channels.nixos.org/nixos-unstable/nixexprs.tar.zst' into the Git cache...
Welcome in your nix shell
```

View File

@@ -53,7 +53,7 @@ Pin Nixpkgs and call the package from `default.nix`:
```nix
# default.nix
let
nixpkgs = fetchTarball "https://github.com/NixOS/nixpkgs/archive/nixos-unstable.tar.gz";
nixpkgs = fetchTarball "https://channels.nixos.org/nixos-unstable/nixexprs.tar.zst";
pkgs = import nixpkgs { };
in
pkgs.callPackage ./package.nix { }

View File

@@ -3,7 +3,7 @@
This hook defaults a variety of environment variables known
to control thread counts to 1. Many of these otherwise default
to `$(nproc)`, which causes massive overloads on build machines
if nix build jobs and build cores are already tuned to fully utilize
if nix build jobs and build cores are already tuned to fully use
compute capacity of a builder without additional parallelism.
Currently sets the following environment variables:

View File

@@ -0,0 +1,28 @@
# `guileImportsCheckHook` {#guileImportsCheckHook}
This hook checks if a guile package can be imported. The hook is automatically
propagated by `guile`, so using it is as simple as:
```nix
{
lib,
stdenv,
guile,
# ...
}:
stdenv.mkDerivation (finalAttrs: {
# ...
nativeBuildInputs = [ guile ];
guileImportsCheck = [
"package"
];
# ...
})
```
The `guileImportsCheckHook` package can also included manually in
`nativeBuildInputs` if one desires.

View File

@@ -92,3 +92,10 @@ Meson setup hook.
- `prefixKey`
- `enableParallelBuilding`
- `enableParallelChecking`
- `disabledTests`
#### `disabledTests` {#meson-disabled-tests}
Specifies a list of tests to skip in `mesonCheckPhase`.
You can optionally specify a subproject using a colon prefix, e.g. `subproject:test_name`.
Meson will pick up the main project name as a default if no subproject is specified.

View File

@@ -5,7 +5,7 @@
COSMIC (Computer Operating System Main Interface Components) is a desktop environment developed by
System76, primarily for the Pop!_OS Linux distribution. Applications in the COSMIC ecosystem are
written in Rust and use libcosmic, which builds on the Iced GUI framework. This section explains
how to properly package and integrate COSMIC applications within Nix.
how to package and integrate COSMIC applications within Nix.
### libcosmicAppHook {#ssec-cosmic-libcosmic-app-hook}
@@ -17,7 +17,7 @@ and wrapping applications based on libcosmic. It handles many common requirement
- Managing Vergen environment variables for build-time information
- Setting up Rust linker flags for specific libraries
To use the hook, simply add it to your package's `nativeBuildInputs`:
Add the hook to your package's `nativeBuildInputs`:
```nix
{
@@ -61,8 +61,9 @@ rustPlatform.buildRustPackage {
}
```
Note that `cosmic-settings` is a separate application and not a part of the libcosmic settings
system itself. It's included by default in `libcosmicAppHook` only to provide these fallback theme
> [!Note]
> `cosmic-settings` is a separate application and not a part of the libcosmic settings
> system itself. It's included by default in `libcosmicAppHook` only to provide these fallback theme
settings.
### Icons {#ssec-cosmic-icons}

View File

@@ -63,7 +63,7 @@ For instance, `sqlite-lua` needs `g:sqlite_clib_path` to be set to work. Nixpkgs
- `wrapperArgs`: Extra arguments forwarded to the `makeWrapper` call.
- `wrapRc`: Nix, not being able to write in your `$HOME`, loads the
generated Neovim configuration via the `$VIMINIT` environment variable, i.e. : `export VIMINIT='lua dofile("/nix/store/…-init.lua")'`. This has side effects like preventing Neovim from sourcing your `init.lua` in `$XDG_CONFIG_HOME/nvim` (see bullet 7 of [`:help startup`](https://neovim.io/doc/user/starting.html#startup) in Neovim). Disable it if you want to generate your own wrapper. You can still reuse the generated vimscript init code via `neovim.passthru.initRc`.
- `plugins`: A list of plugins to add to the wrapper.
- `plugins`: A list of plugins to add to the wrapper. If a plugin is not available in nixpkgs, you can [package it yourself](#what-if-your-favourite-vim-plugin-isnt-already-packaged).
- `extraLuaPackages`: A function passed on to `lua.withPackages`.
- `extraPython3Packages`: A function passed on to `python3.withPackages`.
- `withPython3`, `withNodeJs`, `withRuby`, `withPerl` control when to enable neovim

View File

@@ -11,47 +11,86 @@ nix-shell -p swift --run 'swiftc -' <<< 'print("Hello world!")'
The `swift` package also provides the `swift` command, with some caveats:
- Swift Package Manager (SwiftPM) is packaged separately as `swiftpm`. If you
need functionality like `swift build`, `swift run`, `swift test`, you must
also add the `swiftpm` package to your closure.
- On Darwin, the `swift repl` command requires an Xcode installation. This is
because it uses the system LLDB debugserver, which has special entitlements.
- Swift Package Manager (SwiftPM) is packaged separately as `swiftpm`.
If you need functionality like `swift build`, `swift run`, `swift test`, you must also add the `swiftpm` package to your closure.
- On Darwin, the `swift repl` command requires an Xcode installation.
This is because it uses the system LLDB debugserver, which has special entitlements.
## Module search paths {#ssec-swift-module-search-paths}
Like other toolchains in Nixpkgs, the Swift compiler executables are wrapped
to help Swift find your application's dependencies in the Nix store. These
wrappers scan the `buildInputs` of your package derivation for specific
directories where Swift modules are placed by convention, and automatically
add those directories to the Swift compiler search paths.
The Swift compiler executables are patched to find the C and C++ standard libraries associated with its target platform, but they are not wrapped.
They will not find your application’s dependencies automatically in the Nix store.
Your build system is expected to handle this for you.
Swift follows different conventions depending on the platform. The wrappers
look for the following directories:
SwiftPM provides a hook that scans the `buildInputs` of your package derivation for specific directories where the Swift modules are placed by convention.
These directories are added automatically to `swiftpmFlags` when the hook runs.
Swift in Nixpkgs follows a few conventions when installing dependencies:
- On Darwin platforms: `lib/swift/macosx`
(If not targeting macOS, replace `macosx` with the Xcode platform name.)
- On other platforms: `lib/swift/linux/x86_64`
(Where `linux` and `x86_64` are from lowercase `uname -sm`.)
- For convenience, Nixpkgs also adds `lib/swift` to the search path.
This can save a bit of work packaging Swift modules, because many Nix builds
will produce output for just one target anyway.
- Libraries (both shared and static) are installed to `lib`.
This differs from upstream packaging, but it matches how other langauges are packaged in Nixpkgs.
This allows Swift packages to take advantage of existing tooling that expects libraries to be installed in this standard location.
- Modules are installed to `lib/swift/<platform>` where `<platform>` is the Swift platform for your host platform (e.g., `lib/swift/macosx` or `lib/swift/linux`).
Note that Linux modules may be installed in a directory specific to the target architecture(e.g., `lib/swift/linux/x86_64`), but this is uncommon.
Upstream Swift appears to be moving away from this convention.
## Core libraries {#ssec-swift-core-libraries}
In addition to the standard library, the Swift toolchain contains some
additional 'core libraries' that, on Apple platforms, are normally distributed
as part of the OS or Xcode. These are packaged separately in Nixpkgs and can
be found (for use in `buildInputs`) as:
The `swift` package contains a complete toolchain with the Swift stdlib, Dispatch, Foundation, XCTest, and Swift Testing.
These packages do not need to be added to `buildInputs` when packaging applications.
The Swift compiler will find them automatically in the `swift` toolchain.
- `swiftPackages.Dispatch`
- `swiftPackages.Foundation`
- `swiftPackages.XCTest`
If you do need to use these packages outside of the Swift toolchain, they are available in the following packages:
- `swiftPackages.stdlib` contains the Swift stdlib and backdeployment dylibs.
- `swiftPackages.swift-corelibs-libdispatch` contains the Dispatch framework.
- `swiftPackages.swift-corelibs-foundation` contains the Foundation framework.
- `swiftPackages.swift-corelibs-xctest` and `swiftPackages.swift-testing` contain the XCTest and Swift Testing frameworks respectively.
Note: On Darwin, the Swift stdlib has been removed from the SDK.
The Swift toolchain contains the stubs and modules required to build Swift applications with the following exceptions:
- Swift Differentiation is shipped as a dylib in Nixpkgs because it is no longer shipped with the OS (as of macOS 26.4).
This allows packages using Swift Differentiation to work regardless of OS version.
- The Span back-deployment dylib is shipped with the stdlib.
- This is expected because back-deployment dylibs are normally shipped with the toolchain.
- FoundationMacros is built and shipped as a dylib in `swiftPackages.swift-foundation` and included in the toolchain.
Macros are actually compiler plugins executed at build time.
Without this, FoundationMacros would not work on Darwin.
## Packaging with SwiftPM {#ssec-swift-packaging-with-swiftpm}
Nixpkgs includes a small helper `swiftpm2nix` that can fetch your SwiftPM
dependencies for you, when you need to write a Nix expression to package your
application.
Nixpkgs includes two ways to package dependencies for Swift applications: `fetchSwiftPMDeps` and `swiftpm2nix`.
While `swiftpm2nix` is not deprecated, using `fetchSwiftPMDeps` is preferred because it is easier to use and does not (usually) require shipping extra files with your package.
### Packaging with `fetchSwiftPMDeps` {#ssec-swift-packaging-with-fetch-swiftpm-deps}
Swift provides a fetcher that will download all of your dependencies based on the `Package.resolved` shipped by your package.
If your package does not ship one, you will have to generate it yourself and provide it with your package.
Otherwise, set `swiftpmDeps` as follows:
```nix
{
swiftpmDeps = fetchSwiftPMDeps {
inherit src;
hash = "sha256-1KfyrQXE1HaO9WsuskzgiiEZxM/oelp40Jwzr8xJEL4=";
};
}
```
The `src` attribute is required as is the `hash`.
The first time you build your package, you will need to set `hash` to an empty value by using `lib.fakeHash` to get the hash for your dependencies.
The following optional attributes can also be used:
- `name`: Sets the name of the vendored dependencies fixed-output derivation.
You can also use `pname` and `version` to set the `name`.
This is often easier because you can inherit them from `finalAttrs`.
- `sourceRoot`: Sets the path where `Package.swift` and `Package.resolved` can be found if they are not in their default, top-level location.
- `patches`: Can be used to apply patches to your project before the dependencies are vendored.
This is useful to update `Package.swift` or `Package.resolved`.
- `postPatch`: Can be used to perform extra steps after patching.
You can copy a custom `Package.resolved` in `postPatch`.
### Packaging with `swiftpm2nix` {#ssec-swift-packaging-with-swiftpm2nix}
The first step is to run the generator:
@@ -65,8 +104,8 @@ swift package resolve
swiftpm2nix
```
This produces some files in a directory `nix`, which will be part of your Nix
expression. The next step is to write that expression:
This produces some files in a directory `nix`, which will be part of your Nix expression.
The next step is to write that expression:
```nix
{
@@ -126,45 +165,13 @@ stdenv.mkDerivation (finalAttrs: {
})
```
### Custom build flags {#ssec-swiftpm-custom-build-flags}
#### Patching dependencies {#ssec-swiftpm-patching-dependencies}
If you'd like to build a different configuration than `release`:
In some cases, it may be necessary to patch a SwiftPM dependency.
SwiftPM dependencies are located in `.build/checkouts`, but the `swiftpm2nix` helper provides these as symlinks to read-only `/nix/store` paths.
To patch them, we need to make them writable.
```nix
{ swiftpmBuildConfig = "debug"; }
```
It is also possible to provide additional flags to `swift build`:
```nix
{ swiftpmFlags = [ "--disable-dead-strip" ]; }
```
The default `buildPhase` already passes `-j` for parallel building.
If these two customization options are insufficient, provide your own
`buildPhase` that invokes `swift build`.
### Running tests {#ssec-swiftpm-running-tests}
Including `swiftpm` in your `nativeBuildInputs` also provides a default
`checkPhase`, but it must be enabled with:
```nix
{ doCheck = true; }
```
This essentially runs: `swift test -c release`
### Patching dependencies {#ssec-swiftpm-patching-dependencies}
In some cases, it may be necessary to patch a SwiftPM dependency. SwiftPM
dependencies are located in `.build/checkouts`, but the `swiftpm2nix` helper
provides these as symlinks to read-only `/nix/store` paths. To patch
them, we need to make them writable.
A special function `swiftpmMakeMutable` is available to replace the symlink
with a writable copy:
A special function `swiftpmMakeMutable` is available to replace the symlink with a writable copy:
```nix
{
@@ -183,21 +190,76 @@ with a writable copy:
}
```
### Custom build flags {#ssec-swiftpm-custom-build-flags}
If you'd like to build a different configuration than `release`:
```nix
{ swiftpmBuildConfig = "debug"; }
```
It is also possible to provide additional flags to `swift build`:
```nix
{ swiftpmFlags = [ "--disable-dead-strip" ]; }
```
The default `buildPhase` already passes `-j` for parallel building.
If these two customization options are insufficient, provide your own `buildPhase` that invokes `swift build`.
### Running tests {#ssec-swiftpm-running-tests}
Including `swiftpm` in your `nativeBuildInputs` also provides a default `checkPhase`, but it must be enabled with:
```nix
{ doCheck = true; }
```
This essentially runs: `swift test -c release`
### Installing packages {#ssec-swiftpm-install-phase}
SwiftPM provides a default install phase that installs any products specified in your package’s `Package.swift`.
If your package does not specify any products, which is not uncommon, you will have to manually install them to `out`.
To disable the SwiftPM install phase, include the following in your derivation:
```nix
{ dontUseSwiftpmInstall = true; }
```
## Hooks {#ssec-swift-hooks}
Swift provides the following hooks to automate builds and unpack dependencies:
- `swiftpmHook`: Propagated by `swiftpm`.
Also propagates `swiftpmUnpackHook`.
Provides build, install, and check phases. It also adds any dependencies found in `buildInputs` to `swiftpmFlags`.
- `swiftpmUnpackHook`: Sets up `workspace-state.json` and links vendored dependencies to the top-level `Packages` directory in the build environment.
Swift also provides a hook with the toolchain to replace rpath references to the toolchain with references to the stdlib package.
This hook is used automatically by the `swift` package.
This avoids pulling the entire toolchain into the closure of your package.
## Considerations for custom build tools {#ssec-swift-considerations-for-custom-build-tools}
### Linking the standard library {#ssec-swift-linking-the-standard-library}
The `swift` package has a separate `lib` output containing just the Swift
standard library, to prevent Swift applications needing a dependency on the
full Swift compiler at runtime. Linking with the Nixpkgs Swift toolchain
already ensures binaries correctly reference the `lib` output.
The Swift stdlib is packaged separately as `swiftPackages.stdlib`.
The shared and static libraries are installed to `lib`.
Most tooling in Nixpkgs should find them automatically when linking.
The stdlib provides a hook to change any rpaths pointing to the toolchain to point to the stdlib instead.
Sometimes, Swift is used only to compile part of a mixed codebase, and the
link step is manual. Custom build tools often locate the standard library
relative to the `swift` compiler executable, and while the result will work,
when this path ends up in the binary, it will have the Swift compiler as an
unintended dependency.
The stdlib modules are installed to `lib/swift/<platform>` in the `dev` output of the stdlib package.
These are symlinked together into the `swift` toolchain.
If your build tools locate the modules relative to the `swift` compiler executable, it should do the right thing automatically.
In this case, you should investigate how your build process discovers the
standard library, and override the path. The correct path will be something
like: `"${swift.swift.lib}/${swift.swiftModuleSubdir}"`
### Accessing properties of the Swift platform {#ssec-swift-platform-properties}
The architecture, platform, and triple used by Swift is available as attributes on the build/host/targetPlatform for the `stdenv`.
- `stdenv.<platform>.swift.platform`: The Swift platform (e.g., `macosx` for macOS, `linux` for Linux, etc).
- `stdenv.<platform>.swift.arch`: The Swift architecture (e.g., `arm64` for Darwin or `aarch64` for Linux, `x86_64`, etc).
- `stdenv.<platform>.swift.triple`: The triple used by Swift.
This is the same as `stdenv.<platform>.config` except on Darwin.
On Darwin, it uses the OS name instead of `darwin` and includes the deployment target (e.g., `arm64-apple-macosx14.0`).

View File

@@ -364,6 +364,9 @@
{
"file": "hooks/gnome.section.md"
},
{
"file": "hooks/guileImportsCheckHook.section.md"
},
{
"file": "hooks/haredo.section.md"
},

View File

@@ -164,6 +164,9 @@
"ghc-deprecation-policy": [
"index.html#ghc-deprecation-policy"
],
"guileImportsCheckHook": [
"index.html#guileImportsCheckHook"
],
"how-channels-work": [
"index.html#how-channels-work"
],
@@ -1981,6 +1984,9 @@
"sec-darwin-troubleshooting-xcodebuild-absolute-paths": [
"index.html#sec-darwin-troubleshooting-xcodebuild-absolute-paths"
],
"sec-darwin-missing-macros": [
"index.html#sec-darwin-missing-macros"
],
"sec-darwin-troubleshooting-libiconv": [
"index.html#sec-darwin-troubleshooting-libiconv"
],
@@ -2978,6 +2984,9 @@
"meson-honored-variables": [
"index.html#meson-honored-variables"
],
"meson-disabled-tests": [
"index.html#meson-disabled-tests"
],
"setup-hook-mpi-check": [
"index.html#setup-hook-mpi-check"
],
@@ -4593,14 +4602,26 @@
"ssec-swift-packaging-with-swiftpm": [
"index.html#ssec-swift-packaging-with-swiftpm"
],
"ssec-swift-packaging-with-fetch-swiftpm-deps": [
"index.html#ssec-swift-packaging-with-fetch-swiftpm-deps"
],
"ssec-swift-packaging-with-swiftpm2nix": [
"index.html#ssec-swift-packaging-with-swiftpm2nix"
],
"ssec-swiftpm-patching-dependencies": [
"index.html#ssec-swiftpm-patching-dependencies"
],
"ssec-swiftpm-custom-build-flags": [
"index.html#ssec-swiftpm-custom-build-flags"
],
"ssec-swiftpm-running-tests": [
"index.html#ssec-swiftpm-running-tests"
],
"ssec-swiftpm-patching-dependencies": [
"index.html#ssec-swiftpm-patching-dependencies"
"ssec-swiftpm-install-phase": [
"index.html#ssec-swiftpm-install-phase"
],
"ssec-swift-hooks": [
"index.html#ssec-swift-hooks"
],
"ssec-swift-considerations-for-custom-build-tools": [
"index.html#ssec-swift-considerations-for-custom-build-tools"
@@ -4608,6 +4629,9 @@
"ssec-swift-linking-the-standard-library": [
"index.html#ssec-swift-linking-the-standard-library"
],
"ssec-swift-platform-properties": [
"index.html#ssec-swift-platform-properties"
],
"sec-language-tcl": [
"index.html#sec-language-tcl"
],

View File

@@ -16,6 +16,8 @@
+nixpkgs.url = "https://channels.nixos.org/nixos-26.05/nixexprs.tar.zst";
```
- GCC has been updated from GCC 15 to GCC 16. This introduces some backwards-incompatible changes. Refer to the [upstream porting guide](https://gcc.gnu.org/gcc-16/porting_to.html) for details.
- Emacs has been updated to 31.
This introduces some backwards‐incompatible changes; see the NEWS for details.
NEWS can be viewed from Emacs by typing `C-h n`, or by clicking `Help->Emacs News` from the menu bar.
@@ -36,6 +38,10 @@
- `zabbix.<package>` now defaults to version 7.4. If you want to keep using Zabbix 6.0, use `pkgs.zabbix60.<package>`.
Note that Zabbix 6.0 is in limited support, and will be deprecated on February 28, 2027. Consider upgrading.
- `zabbix-agent2-plugin-postgresql` is now moved to `zabbix{60,70,74}.plugins.postgresql`.
- Official Zabbix plugins (ember-plus, mongodb, and mssql) have been added under `zabbix{60,70,74}.plugins.<plugin>`.
- `perlPackages.NetOAuth` has been updated from 0.28 to 0.33.
Callers that verify messages must now set `allowed_signature_methods` per message or configure `@Net::OAuth::ALLOWED_SIGNATURE_METHODS`; `verify` otherwise throws an exception.
See the [upstream changelog](https://metacpan.org/dist/Net-OAuth/changes) for details.
@@ -117,6 +123,9 @@
- `himalaya` has been updated from `v1.2.0` to `v2.0.0`, which introduces breaking changes. See the [release notes](https://github.com/pimalaya/himalaya/releases/tag/v2.0.0) and the [migration guide](https://github.com/pimalaya/himalaya/blob/master/MIGRATION.md).
- `proton-cli` has been updated from `2.2.3` to `3.4.0`, and installs its command as `proton`, with `proton-cli` kept beside it as a symlink.
`3.0.0` reworked the command line - `--output` is now the response format, secrets are no longer accepted as flag values, and several subcommands moved - so scripts need a review against the [upstream changelog](https://github.com/roman-16/proton-cli/blob/main/CHANGELOG.md).
- `tengine` has been removed as it has seen seriously delayed responses to security vulnerabilities.
- `jellyfin` has been upgraded to major version 12, which contains breaking changes. See the [upstream blog post](https://jellyfin.org/posts/jellyfin-release-12.0) for more information on how to safely upgrade.
@@ -171,6 +180,8 @@
- `replaceVarsWith` now enables `strictDeps` and `__structuredAttrs` and passing these attributes to the function is no longer allowed.
By extension, `replaceVars` now also enables `strictDeps` and `__structuredAttrs`.
- `nginx` / `nginxStable` is now built without the `rtmp` nginx module by default. You can enable it again using `nginx.override { modules = [ pkgs.nginxModules.rtmp ]; }`
- `buildFHSEnvChroot` has been removed after deprecation in 23.05.
- `leafnode` has been removed, as it was an unmaintained alpha-release of leafnode 2 and has a dependency on the EOL PRCE-library. Consider using `leafnode1` instead, which is still maintained.
@@ -193,6 +204,11 @@
- `librest` providing 0.7 ABI was removed. `librest_1_0` providing 1.0 ABI was renamed to `librest` and `librest_1_0` was kept as an alias.
- `secretspec-ffi` has been renamed to `libsecretspec` and updated to 0.21.0.
The old package attribute remains an alias, but native consumers must rebuild
against the new `libsecretspec` library and pkg-config module. The separate
`libsecretspec-resolver` package provides a C client for `secretspec serve`.
- `luaPackages.lrexlib-pcre` has been removed as part of the process to fully migrate from the end-of-life PRCE library to PCRE2. `luaPackages.lrexlib-pcre2` and multiple other versions of lrexlib can be used instead.
- `hostapd` was upgraded to version 2.12+, which moves move supported, basic, and beacon transmission rate configuration to be at BSS level instead of per-radio for all BSSs. Refer to the [upstream example config](https://git.w1.fi/cgit/hostap/plain/hostapd/hostapd.conf) for details.
@@ -225,6 +241,16 @@
- `nim-2_0` & `nim-2_2` and respective aliases have been removed; please migrate to `nim` or `nim-unwrapped` (nim 2.2.10).
- `domoticz` has been updated from `2024.7` to `2026.x`, breaking third party applications and scripts using the old RType calls. Review the [release notes](https://github.com/domoticz/domoticz/blob/2026.2/History.txt#L398) for more information.
- `swift` is no longer wrapped.
The `NIX_SWIFTFLAGS_COMPILE` variable is no longer supported.
If you need to pass custom flags to the Swift compiler, you must add them via your package’s build system.
The default target version used by `swiftc` on Darwin is the operating system major version.
This value may be overridden by the build system (e.g., SwiftPM defaults to 10.13 instead).
See the Swift documentation in Nixpkgs for details.
- `swiftpm` is no longer wrapped to include Git to fetch dependencies.
Users with Git-based dependencies will need to add `git` to their dev shells or include it in their environment if they weren’t already.
- `vimacs` has been removed, as it has not been maintained in 10 years and was built for an old version of vim (6.0).
- The deprecated `appimageTools.extractType1`, `appimageTools.extractType2`, and `appimageTools.wrapType1` aliases now emit warnings. Use `appimageTools.extract` and `appimageTools.wrapType2` instead.
@@ -261,18 +287,27 @@
- `nextpnr` introduced support for the nexus and gatemate architectures. Building support for each individual architecture can be configured using the package parameters.
- `mastodon` has been updated to 4.7. The [4.7.0 release notes](https://github.com/mastodon/mastodon/releases/tag/v4.7.0) mention some unusually long running migrations.
- Emacs loads the `early-default` library after `early-init.el`.
Users can add `early-init.el` via `emacs.pkgs.withPackages`
by packaging `early-init.el` into a library named `early-default`.
To prevent loading the `early-default` library,
set `inhibit-early-default-init` in `early-init.el`.
- Ceph has a vulnerability in old generated CephX keys.
The project recommends to rotate old keys.
This is a manual process, see https://ceph.io/en/news/blog/2026/v20-2-4-v19-2-6-combo-released
- `services.ceph` enabled the generation of Ceph log files at `/var/log/ceph/`.
They were missing before because Ceph omitted logs when this directory was missing.
Ceph logs can grow large, so you may want to configure rotation of these logs.
- Firefox wrapper now accepts an optional `appDataDir` argument, which sets `MOZ_APP_DATA` to relocate Firefox application data. This is especially useful on macOS 27 and later, where wrapped Firefox applications may be denied access to profiles in traditional application data directory.
- Swift has been upgraded to Swift 6.2.4 from Swift 5.10.1.
The Swift packaging has been rewritten.
## Nixpkgs Library {#sec-nixpkgs-release-26.11-lib}
<!-- To avoid merge conflicts, consider adding your item at an arbitrary place in the list instead. -->

View File

@@ -121,7 +121,8 @@ Generally, only the last SDK release for a major version is packaged.
|---------------|-------------|------------------------------|
| 15.0–15.4 | 14.4 | `apple-sdk_14` / `apple-sdk` |
| 16.0 | 15.0 | `apple-sdk_15` |
| 26.0+ | 26.0+ | `apple-sdk_26`, etc |
| 26.0 | 26.0 | `apple-sdk_26` |
| 27.0+ | 27.0+ | `apple-sdk_27`, etc |
#### Darwin Default SDK versions {#sec-darwin-troubleshooting-darwin-defaults}
@@ -192,6 +193,13 @@ stdenv.mkDerivation {
}
```
### Macro library not available {#sec-darwin-missing-macros}
Some frameworks provide macros that are only shipped with Xcode.
For example, the AppleIntelligence framework, Swift Data, and SwiftUI (as of the 27.0 SDK).
A non-free package making these available will be added at a later date.
Until then, they are unfortunately not available in Nixpkgs.
#### How to use libiconv on Darwin {#sec-darwin-troubleshooting-libiconv}
The libiconv package is included in the SDK by default along with libresolv and libsbuf.

View File

@@ -1,4 +1,4 @@
# Styleguide
# Style guide
Use this page as a reference and style guide for our internal and external documentation.
@@ -22,7 +22,7 @@ Write for someone who knows a great deal — up to but not including this projec
If specific knowledge is required, mention it at the start of the page.
### Show, Don't Tell
### Show, don't tell
The fastest path to understanding is a working example.
People learn by doing, not by reading about doing.
@@ -34,7 +34,7 @@ People learn by doing, not by reading about doing.
- Cover edge cases or variations
- Link to further information instead of including it
### Grammar and Style
### Grammar and style
**Sentence structure:**
@@ -54,7 +54,7 @@ Users care about *detecting hardware*, not *the tool that does it*.
> This command detects your hardware and saves the configuration.
### Content Organization
### Content organization
Lead with value. State what the reader will accomplish before explaining how.
@@ -83,21 +83,23 @@ Use **progressive disclosure**. Introduce concepts only when needed.
3. Explain concepts if needed
4. Provide advanced options separately or link to the reference
### No Meta-commentary
### No meta-commentary
Don't describe what the documentation does. Just do it.
**Don't:**
> This section explains how to configure networking.
> The following guide walks you through setting up a web server.
**Do:**
> Configure networking by setting:
> Set up a web server:
### Code Examples
### Code examples
**Keep examples focused:**
@@ -130,7 +132,7 @@ Paste code examples directly and without further alteration.
}
```
### Lead with Practical Examples
### Lead with practical examples
Don't front-load theory. Readers want to accomplish something first, then understand why it works.
@@ -166,7 +168,7 @@ Users learn the NixOS module system by seeing patterns first.
- Link deeper concepts instead of inlining them
- Link to `nix.dev` for optional learning
### General Rules
### General rules
- Abbreviate keys like `ssh-ed25519 AAAAC3NzaC…`
- Abbreviate IP addresses like `192.168.XXX.XXX`
@@ -200,7 +202,7 @@ Use sentence case. A reader scanning only headings should understand the page.
> Configure networking
> Add a user to the system
### Imperative Mood, Voice, and Person
### Imperative mood, voice, and person
Use imperative mood for instructions. Address the reader as "you", not "the user". Use active voice; in other words, make the subject do the action.
@@ -230,7 +232,7 @@ Use present tense for descriptions. Future tense makes documentation feel tentat
> This creates a new folder.
> Running this command installs the package.
### Be Confident
### Be confident
State facts. Don't hedge with "should," "might," "typically," or "usually" unless the behavior genuinely varies.
@@ -244,7 +246,7 @@ State facts. Don't hedge with "should," "might," "typically," or "usually" unles
> This creates the configuration file.
> The service starts automatically.
### Avoid Nominalizations
### Avoid nominalizations
A nominalization is a verb turned into a noun, often by adding *-tion*, *-meant*, or *-ance* (e.g. "explanation", "selection"). The fix: find the hidden verb and use it directly.
@@ -258,7 +260,7 @@ A nominalization is a verb turned into a noun, often by adding *-tion*, *-meant*
> Select from the list.
> Explain the error.
### Plain Words
### Plain words
Technical precision for technical terms; plain language for everything else.
@@ -270,7 +272,7 @@ Technical precision for technical terms; plain language for everything else.
- "set up" not "establish"
- "find out" not "ascertain"
### Filler Words and Weak Phrases
### Filler words and weak phrases
Cut words and phrases that add length without meaning.
@@ -296,7 +298,7 @@ Delete on sight:
Every word must earn its place.
### Writing Procedures
### Writing procedures
One instruction per sentence. Don't pack multiple actions into one sentence.
@@ -320,7 +322,7 @@ Don't bury the negative. Key limitations should be prominent, not a footnote aft
> This service does not support multiple instances.
### Consistent Terminology
### Consistent terminology
Pick a term and stick to it. Don't swap synonyms to avoid repetition. In technical documentation, repetition is clarity.
@@ -359,7 +361,7 @@ Only link when the destination is directly relevant, not for generic background
> See `[database schema](url)` for the full table structure.
### UI Language
### UI language
Match UI element names exactly: wording, casing, and spacing (even if a label seems oddly worded).

View File

@@ -22,7 +22,7 @@ import <nixpkgs> {
}
```
Note that we set `linker` to `lld`. This is because LLVM has its own linker, called "lld". By setting it, we utilize Clang and lld within this new instance of Nixpkgs. There is a shorthand method for building everything with LLVM: `pkgsLLVM`. This is easier to use with `nix-build` (or `nix build`):
Note that we set `linker` to `lld`. This is because LLVM has its own linker, called "lld". By setting it, we use Clang and lld within this new instance of Nixpkgs. There is a shorthand method for building everything with LLVM: `pkgsLLVM`. This is easier to use with `nix-build` (or `nix build`):
```bash
nix-build -A pkgsLLVM.hello

View File

@@ -105,27 +105,48 @@ There are several ways to tweak how Nix handles a package which has been marked
$ export NIXPKGS_ALLOW_UNFREE=1
```
- It is possible to permanently allow individual unfree packages, while still blocking unfree packages by default using the `allowUnfreePredicate` configuration option in the user configuration file.
This option is a function which accepts a package as a parameter, and returns a boolean. The following example configuration accepts a package and always returns false:
```nix
{ allowUnfreePredicate = (pkg: false); }
```
For a more useful example, try the following. This configuration only allows unfree packages named roon-server and Visual Studio Code:
- To allow specific unfree packages, add their names to your Nixpkgs configuration file:
```nix
{
allowUnfreePredicate =
pkg:
builtins.elem (lib.getName pkg) [
"roon-server"
"vscode"
];
allowUnfreePackages = [
"fence"
"roon-server"
"vscode"
];
}
```
`allowUnfreePackages` permits the listed unfree packages.
In NixOS modules, lists set through `nixpkgs.config.allowUnfreePackages` merge additively across modules. This allows you to declare your unfree exceptions in the same modules that triggered them.
To allow unfree packages programmatically:
```nix
{ lib, ... }:
{
allowUnfreePredicate = pkg: lib.hasPrefix "roon" (lib.getName pkg);
}
```
This permits packages such as `roon-bridge` and `roon-server`.
To combine the list and predicate, set both options:
```nix
{ lib, ... }:
{
allowUnfreePackages = [
"fence"
"vscode"
];
allowUnfreePredicate = pkg: lib.hasPrefix "roon" (lib.getName pkg);
}
```
This permits unfree packages that match either option.
- It is also possible to allow and block licenses that are specifically acceptable or not acceptable, using `allowlistedLicenses` and `blocklistedLicenses`, respectively.
The following example configuration allowlists the licenses `amd` and `wtfpl`:

View File

@@ -703,11 +703,6 @@ lib.mapAttrs mkLicense (
url = "https://www.schristiancollins.com/generaluser.php"; # license included in sources
};
gfl = {
fullName = "GUST Font License";
url = "https://www.gust.org.pl/projects/e-foundry/licenses/GUST-FONT-LICENSE.txt";
};
gfsl = {
fullName = "GUST Font Source License";
url = "https://www.gust.org.pl/projects/e-foundry/licenses/GUST-FONT-SOURCE-LICENSE.txt";

View File

@@ -1595,17 +1595,76 @@ let
*/
mkDefinition = args@{ file, value, ... }: args // { _type = "definition"; };
/**
Labels a definition with a priority.
See the documentation of `filterOverrides` for the interpretation of the priority value.
Nesting this function usually leads to an invalid definition.
`mkDefault`, `mkOptionDefault`, and `mkForce` partially apply `mkOverride` with common priorities used in the NixOS module system.
# Inputs
`priority`
: A numeric value representing the precedence.
See the documentation of `filterOverrides` for the interpretation of this value.
`content`
: The definition to be labeled with a given priority.
# Examples
:::{.example}
## `lib.modules.mkOverride` usage example
```nix
mkOverride 1000 "hello, world!"
=> { _type = "override"; content = "hello, world!"; priority = 1000; }
```
```nix
(lib.evalModules {
modules = [
{ options.foo = lib.mkOption { }; }
{ config.foo = lib.mkOverride 20 1; }
{ config.foo = lib.mkOverride 10 2; }
];
}).config
=> { foo = 2; }
```
:::
*/
mkOverride = priority: content: {
_type = "override";
inherit priority content;
};
mkOptionDefault = mkOverride 1500; # priority of option defaults
mkDefault = mkOverride 1000; # used in config sections of non-user modules to set a default
/**
Labels a definition with the priority of option declaration defaults.
*/
mkOptionDefault = mkOverride 1500;
/**
Labels a definition with the priority used in config sections of non-user modules to set a default.
*/
mkDefault = mkOverride 1000;
defaultOverridePriority = 100;
mkImageMediaOverride = mkOverride 60; # image media profiles can be derived by inclusion into host config, hence needing to override host config, but do allow user to mkForce
/**
Labels a definition with the priority used in image media profiles.
Image media profiles can be derived by inclusion into host config, hence needing to override host config, but do allow users to `mkForce`.
*/
mkImageMediaOverride = mkOverride 60;
/**
Labels a definition with a high priority (low value).
*/
mkForce = mkOverride 50;
mkVMOverride = mkOverride 10; # used by ‘nixos-rebuild build-vm’
/**
Labels a definition with used by {command}`nixos-rebuild build-vm`.
*/
mkVMOverride = mkOverride 10;
mkFixStrictness = warn "lib.mkFixStrictness has no effect and will be removed. It returns its argument unmodified, so you can just remove any calls." id;

View File

@@ -719,6 +719,26 @@ let
else
null;
};
swift = {
arch = final.uname.processor;
platform =
if final.isMacOS then
"macosx"
else if final.isiOS then
"iphoneos"
else if final.isLinux then
"linux"
else if final.isWindows then
"windows"
else
null;
triple =
if final.isDarwin then
# FIXME: Can this be done a better way?
"${final.swift.arch}-${final.parsed.vendor.name}-${final.swift.platform}${final.darwinMinVersion}"
else
final.config;
};
};
in
# Platforms elaborated by pre-26.11 Nixpkgs will include the `linux-kernel` attr,

View File

@@ -445,8 +445,7 @@
"id": 4020424,
"maintainers": {
"Mic92": 96200,
"kalbasit": 87115,
"katexochen": 49727155
"kalbasit": 87115
},
"members": {
"mfrw": 4929861,

View File

@@ -251,7 +251,7 @@
};
_365tuwe = {
name = "Uwe Schlifkowitz";
email = "supertuwe@gmail.com";
email = "uwe.schlifkowitz@secunet.com";
github = "365tuwe";
githubId = 10263091;
};
@@ -460,6 +460,7 @@
name = "aaravrav";
github = "aaravrav";
githubId = 37036762;
matrix = "@hepara:matrix.org";
};
aarnphm = {
email = "contact@aarnphm.xyz";
@@ -5090,6 +5091,12 @@
githubId = 1689801;
name = "Mikhail Chekan";
};
chemonke = {
email = "nixpkgs@chemonke.ch";
github = "chemonke";
githubId = 183837749;
name = "Curdin Bosshart";
};
chen = {
email = "i@cuichen.cc";
github = "cu1ch3n";
@@ -10805,6 +10812,12 @@
githubId = 273582;
name = "greg";
};
gregl83 = {
email = "general+nixpkgs@gregorylanglais.com";
github = "gregl83";
githubId = 1258023;
name = "gregory langlais";
};
gregshuflin = {
email = "greg@everdayimshuflin.com";
github = "neunenak";
@@ -11513,6 +11526,13 @@
githubId = 58676303;
name = "hhydraa";
};
hideyosh1 = {
email = "penelope.zhong@proton.me";
keys = [ { fingerprint = "01E9 0D3E 815F 84CA 1003 E7D7 2F75 2D18 C2C1 7AF8"; } ];
name = "Penelope Zhong";
github = "hideyosh1";
githubId = 64223175;
};
higebu = {
name = "Yuya Kusakabe";
email = "yuya.kusakabe@gmail.com";
@@ -12143,6 +12163,12 @@
githubId = 71074737;
name = "Simon Wick";
};
ilovelinux = {
email = "nix+nixpkgs@ilovelinux.dev";
github = "ilovelinux";
githubId = 9268789;
name = "Antonio Spadaro";
};
ilya-epifanov = {
email = "mail@ilya.network";
github = "ilya-epifanov";
@@ -12637,6 +12663,12 @@
github = "j0hax";
githubId = 3802620;
};
j0schu = {
name = "Jonas";
email = "Joschu2015@t-online.de";
github = "J0schu";
githubId = 56407950;
};
j0xaf = {
email = "j0xaf@j0xaf.de";
name = "Jörn Gersdorf";
@@ -14087,6 +14119,12 @@
github = "jooooscha";
githubId = 57965027;
};
joseg313 = {
name = "Jose Garcia";
email = "501jag3@gmail.com";
github = "joseg313";
githubId = 215610619;
};
josephschmitt = {
name = "Joseph Schmitt";
email = "dev@joe.sh";
@@ -20094,6 +20132,12 @@
githubId = 52401682;
name = "myul";
};
Myxogastria0808 = {
email = "r.rstudio.c@gmail.com";
github = "Myxogastria0808";
githubId = 78744619;
name = "Yuki Osada";
};
myypo = {
email = "nikirsmcgl@gmail.com";
github = "myypo";
@@ -28978,6 +29022,13 @@
github = "thelissimus";
githubId = 70096720;
};
thelolcoder2007 = {
name = "thelolcoder2007";
github = "thelolcoder2007";
githubId = 52106896;
matrix = "@erents:dapperepoging.nl";
keys = [ { fingerprint = "E374 815F C754 462B 1C34 3562 FDC3 99DE 8F7E 200B"; } ];
};
themadbit = {
name = "Mark Tanui";
email = "marktanui75@gmail.com";
@@ -31571,10 +31622,10 @@
];
};
wrench-exile-legacy = {
email = "user@wrench-exile-legacy.site";
email = "hello@wrenchd.dev";
github = "wrench-exile-legacy";
githubId = 280737824;
name = "wrench";
name = "wrenchd";
};
wrmilling = {
name = "Winston R. Milling";

View File

@@ -108,7 +108,6 @@ with lib.maintainers;
members = [
lopsided98
mic92
zowoq
];
scope = "Maintain Buildbot CI framework";
shortName = "Buildbot";
@@ -751,6 +750,7 @@ with lib.maintainers;
swift = {
members = [
reckenrode
samasaur
stephank
];

View File

@@ -302,9 +302,11 @@
- `chatgpt` has been retargeted to OpenAI's new ChatGPT desktop app, while the previous app has been renamed to `chatgpt-classic`.
- NetBox was updated to `>= 4.6.8`. Have a look at the breaking changes
of the [4.6 release](https://github.com/netbox-community/netbox/releases/tag/v4.6.0),
make the required changes to your database, if needed, then upgrade by setting `services.netbox.package = pkgs.netbox_4_6;` in your configuration.
- NetBox was updated to `>= 4.7.0`. Have a look at the breaking changes
of the [4.6 release](https://github.com/netbox-community/netbox/releases/tag/v4.6.0)
and the [4.7 release](https://github.com/netbox-community/netbox/releases/tag/v4.7.0),
make the required changes to your configuration and database, if needed,
before you upgrade to NixOS 26.11.
- The COSMIC desktop module now enables by default `system76-power` and `system76-scheduler` following upstream recommended packages. The previous power managment service can be enabled back by setting `services.power-profiles-daemon.enable = true`.
@@ -356,6 +358,8 @@
- `boot.loader.systemd-boot` gained support for [Automatic Boot Assessment](https://systemd.io/AUTOMATIC_BOOT_ASSESSMENT/) via the new [`boot.loader.systemd-boot.bootCounting`](#opt-boot.loader.systemd-boot.bootCounting.enable) options, allowing automatic detection of and recovery from bad NixOS generations. As part of this change, boot loader entries on the ESP/XBOOTLDR partition are now named `nixos-<content-hash>.conf` instead of `nixos-generation-<n>.conf`; existing entries are migrated automatically on the next `nixos-rebuild boot`/`switch`.
- The Wordpress module now supports auto database migrations using wp-cli, which gets triggered after every package version update.
- `services.nginx` gained a [`lua`](#opt-services.nginx.lua.enable) option to enable Lua scripting via OpenResty's lua-nginx-module on a stock nginx, configuring `lua_package_path`/`lua_package_cpath` from the packages listed in [`services.nginx.lua.extraPackages`](#opt-services.nginx.lua.extraPackages). Use this to add Lua to a regular nginx; for the full OpenResty platform (libraries that rely on its bundled lualib, such as `lua-resty-openidc`), set `services.nginx.package` to `pkgs.openresty` instead — the option configures the Lua search path for it too.
- `services.nginx.virtualHosts.<name>.locations.<name>` gained a new `useGrpcErrorPages` option. If enabled, it sets up error pages that are valid gRPC messages. This is useful if you proxy gRPC and want to emit errors from nginx, for example when adding authentication on top.

View File

@@ -335,7 +335,7 @@ class BaseMachine(ABC):
...
@abstractmethod
def wait_for_shutdown(self) -> None:
def wait_for_shutdown(self, timeout: dt.timedelta | None = None) -> None:
"""Wait for the machine to power off. This does *not* initiate a shutdown;
that's usually done via `shutdown()`.
"""
@@ -1061,7 +1061,7 @@ class QemuMachine(BaseMachine):
break
self.send_console(char.decode())
def wait_for_shutdown(self) -> None:
def wait_for_shutdown(self, timeout: dt.timedelta | None = None) -> None:
"""
Wait for the VM to power off. This does *not* initiate a shutdown;
that's usually done via `shutdown()`.
@@ -1072,7 +1072,9 @@ class QemuMachine(BaseMachine):
with self.nested("waiting for the VM to power off"):
sys.stdout.flush()
assert self.process
self.process.wait()
self.process.wait(
timeout=timeout.total_seconds() if timeout is not None else None
)
self.pid = None
self.booted = False
@@ -1903,7 +1905,7 @@ class NspawnMachine(BaseMachine):
self.systemctl("poweroff")
self.wait_for_shutdown()
def wait_for_shutdown(self) -> None:
def wait_for_shutdown(self, timeout: dt.timedelta | None = None) -> None:
"""
Wait for the container to power off. This does *not* initiate a shutdown;
that's usually done via `shutdown()`.
@@ -1912,7 +1914,9 @@ class NspawnMachine(BaseMachine):
return
with self.nested("waiting for the container to power off"):
self.process.wait()
self.process.wait(
timeout=timeout.total_seconds() if timeout is not None else None
)
self.process = None

View File

@@ -42,7 +42,7 @@ in
};
};
nixPath = mkOption {
settings.nix-path = mkOption {
type = types.listOf types.str;
default =
if cfg.channel.enable then
@@ -80,8 +80,11 @@ in
};
};
config = mkIf cfg.enable {
imports = [
(lib.mkRenamedOptionModule [ "nix" "nixPath" ] [ "nix" "settings" "nix-path" ])
];
config = mkIf cfg.enable {
environment.extraInit = mkIf cfg.channel.enable ''
if [ -e "$HOME/.nix-defexpr/channels" ]; then
export NIX_PATH="$HOME/.nix-defexpr/channels''${NIX_PATH:+:$NIX_PATH}"
@@ -95,7 +98,7 @@ in
# NIX_PATH has a non-empty default according to Nix docs, so we don't unset
# it when empty.
environment.sessionVariables = {
NIX_PATH = cfg.nixPath;
NIX_PATH = cfg.settings.nix-path;
};
systemd.tmpfiles.rules = lib.mkIf cfg.channel.enable [

View File

@@ -72,6 +72,20 @@ $ nixos-version --configuration-revision
aa314ebd1592f6cdd53cb5bba8bcae97d9323de8
.Ed
.
.It Fl -kernel-version
Show the kernel version, e.g.
.Bd -literal -offset indent
$ nixos-version --kernel-version
7.2.5
.Ed
.
.It Fl -specialisations
Show specialisations, separated by spaces, if available, e.g.
.Bd -literal -offset indent
$ nixos-version --specialisations
foo bar
.Ed
.
.It Fl -json
Print a JSON representation of the versions of NixOS and the top-level
configuration flake.

View File

@@ -20,8 +20,23 @@ case "$1" in
fi
echo "@configurationRevision@"
;;
--kernel-version)
if [[ "@kernelVersion@" =~ "@" ]]; then
echo "$0: kernel version is unknown" >&2
exit 1
fi
echo "@kernelVersion@"
;;
--specialisations)
specialisations=@specialisations@
if [[ -z "$specialisations" ]]; then
echo "$0: no specialisations found" >&2
exit 1
fi
printf '%s\n' "$specialisations"
;;
--json)
cat <<EOF
cat <<'EOF'
@json@
EOF
;;

View File

@@ -53,13 +53,27 @@ let
nixos-version = makeProg {
name = "nixos-version";
src = ./nixos-version.sh;
replacements = {
replacements = rec {
inherit (pkgs) runtimeShell;
inherit (config.system.nixos) version codeName revision;
inherit (config.system) configurationRevision;
kernelVersion =
if config.boot.kernel.enable then
# modDirVersion returns 6.18.54-xanmod1 instead of 6.18.54
config.boot.kernelPackages.kernel.modDirVersion or config.boot.kernelPackages.kernel.version
else
null;
specialisations = lib.escapeShellArg (
lib.concatStringsSep " " (lib.attrNames config.specialisation)
);
json = builtins.toJSON (
{
nixosVersion = config.system.nixos.version;
specialisations = lib.attrNames config.specialisation;
}
// lib.optionalAttrs (kernelVersion != null) {
inherit kernelVersion;
}
// lib.optionalAttrs (config.system.nixos.revision != null) {
nixpkgsRevision = config.system.nixos.revision;
@@ -292,7 +306,7 @@ in
{
options.system.tools.${name}.enable = lib.mkEnableOption "${name} script" // {
default = config.nix.enable && !config.system.disableInstallerTools;
defaultText = "config.nix.enable && !config.system.disableInstallerTools";
defaultText = lib.literalExpression "config.nix.enable && !config.system.disableInstallerTools";
};
config = lib.mkIf config.system.tools.${name}.enable {

View File

@@ -102,7 +102,7 @@ in
# because we would need some kind of evil shim taking the *calling* flake's self path,
# perhaps, to ever make that work (in order to know where the Nix expr for the system came
# from and how to call it).
nix.nixPath = lib.mkDefault (
nix.settings.nix-path = lib.mkDefault (
[ "nixpkgs=flake:nixpkgs" ]
++ lib.optional config.nix.channel.enable "/nix/var/nix/profiles/per-user/root/channels"
);

View File

@@ -1258,7 +1258,6 @@
./services/networking/gnunet.nix
./services/networking/go-autoconfig.nix
./services/networking/go-camo.nix
./services/networking/go-neb.nix
./services/networking/go-shadowsocks2.nix
./services/networking/gobgpd.nix
./services/networking/godns.nix

View File

@@ -33,7 +33,13 @@ in
config = lib.mkIf cfg.enable (
lib.mkMerge [
{
environment.systemPackages = [ cfg.package ];
environment.systemPackages = [
cfg.package
];
# Needed to add the freedesktop sound theme
# It's only a runtime dependency for noctalia, so it's not made a package dependency.
xdg.sounds.enable = true;
systemd.user.services.noctalia = lib.mkIf cfg.systemd.enable {
description = "Noctalia Wayland desktop shell";

View File

@@ -486,6 +486,10 @@ in
See https://www.isc.org/blogs/isc-dhcp-eol/ for details.
Please switch to a different implementation like kea or dnsmasq.
'')
(lib.mkRemovedOptionModule [ "services" "go-neb" ] ''
The Go-NEB project was discontinued by Matrix.org and archived in June
2023. Use matrix-hookshot or another maintained Matrix bot instead.
'')
(mkRemovedOptionModule [ "services" "gsignond" ] ''
The corresponding package was unmaintained, abandoned upstream, used outdated library and thus removed from nixpkgs.
'')

View File

@@ -51,7 +51,10 @@ in
sockets.pwupdd.wantedBy = lib.optional config.users.mutableUsers "sockets.target"; # immutable users do not need password updating
sockets.newidmapd.wantedBy = [ "sockets.target" ];
services."pwupdd@".environment.PWUPDD_OPTS = lib.escapeShellArgs cfg.extraArgs;
services."pwaccessd".environment.PWACCESSD_OPTS = lib.escapeShellArgs cfg.extraArgs;
services."pwaccessd".environment = {
LD_LIBRARY_PATH = config.system.nssModules.path;
PWACCESSD_OPTS = lib.escapeShellArgs cfg.extraArgs;
};
};
environment.systemPackages = [ cfg.package ];

View File

@@ -48,6 +48,7 @@
# Accounts daemon looks for dbus interfaces in $XDG_DATA_DIRS/accountsservice
environment.XDG_DATA_DIRS = "${config.system.path}/share";
environment.LD_LIBRARY_PATH = config.system.nssModules.path;
}
(

View File

@@ -20,11 +20,16 @@ let
rawHomeserverUrl = cfg.homeserverUrl;
pantalaimon = {
inherit (cfg.pantalaimon) username;
use = cfg.pantalaimon.enable;
}
// lib.optionalAttrs cfg.pantalaimon.enable {
inherit (cfg.pantalaimon) username;
password = "@PANTALAIMON_PASSWORD@"; # will be replaced in "generateConfig"
};
encryption = {
inherit (cfg.settings.encryption) username;
password = "@ENCRYPTION_PASSWORD@"; # will be replaced in "generateConfig"
};
};
moduleConfigFile = pkgs.writeText "module-config.yaml" (
@@ -72,6 +77,9 @@ let
${lib.optionalString (cfg.pantalaimon.passwordFile != null) ''
${pkgs.replace-secret}/bin/replace-secret '@PANTALAIMON_PASSWORD@' '${cfg.pantalaimon.passwordFile}' ${cfg.dataPath}/config/default.yaml
''}
${lib.optionalString (cfg.encryption.passwordFile != null) ''
${pkgs.replace-secret}/bin/replace-secret '@ENCRYPTION_PASSWORD@' '${cfg.encryption.passwordFile}' ${cfg.dataPath}/config/default.yaml
''}
''
);
in
@@ -98,6 +106,14 @@ in
'';
};
encryption.passwordFile = lib.mkOption {
type = with lib.types; nullOr path;
default = null;
description = ''
File containing the matrix password for the `mjolnir` user.
'';
};
pantalaimon = lib.mkOption {
description = ''
`pantalaimon` options (enables E2E Encryption support).
@@ -186,17 +202,22 @@ in
config = lib.mkIf config.services.mjolnir.enable {
assertions = [
{
assertion = !(cfg.settings.encryption.use && cfg.encryption.passwordFile == null);
message = "encryption.passwordFile must be specified when native encryption is used.";
}
{
assertion = !(cfg.pantalaimon.enable && cfg.pantalaimon.passwordFile == null);
message = "Specify pantalaimon.passwordFile";
message = "pantalaimon.passwordFile must be specified when pantalaimon is enabled.";
}
{
assertion = !(cfg.pantalaimon.enable && cfg.accessTokenFile != null);
message = "Do not specify accessTokenFile when using pantalaimon";
assertion = cfg.accessTokenFile == null -> cfg.pantalaimon.enable || cfg.settings.encryption.use;
message = "Do not specify accessTokenFile when using native encryption or pantalaimon";
}
{
assertion = !(!cfg.pantalaimon.enable && cfg.accessTokenFile == null);
message = "Specify accessTokenFile when not using pantalaimon";
assertion =
!(!cfg.pantalaimon.enable && !cfg.settings.encryption.use && cfg.accessTokenFile == null);
message = "Specify accessTokenFile when not using pantalaimon or native encryption.";
}
];

View File

@@ -38,12 +38,8 @@ let
PAPERLESS_REDIS = "unix://${redisServer.unixSocket}";
}
// lib.optionalAttrs (cfg.settings.PAPERLESS_AI_ENABLED or true) {
NLTK_DATA = cfg.package.nltkDataDir;
TIKTOKEN_CACHE_DIR = cfg.package.tiktokenCacheDir;
}
// lib.optionalAttrs (cfg.settings.PAPERLESS_ENABLE_NLTK or true) {
PAPERLESS_NLTK_DIR = cfg.package.nltkDataDir;
}
// lib.optionalAttrs (cfg.openMPThreadingWorkaround) {
OMP_NUM_THREADS = "1";
}
@@ -717,7 +713,9 @@ in
"d '${cfg.exporter.directory}' - ${cfg.user} ${config.users.users.${cfg.user}.group} - -"
];
services.paperless.exporter.settings = options.services.paperless.exporter.settings.default;
services.paperless.exporter.settings = lib.mapAttrs (
_: v: lib.mkDefault v
) options.services.paperless.exporter.settings.default;
systemd.services.paperless-exporter = {
startAt = lib.defaultTo [ ] cfg.exporter.onCalendar;

View File

@@ -6,6 +6,76 @@
}:
let
cfg = config.services.beszel.agent;
hasVideoDriver = driver: builtins.elem driver config.services.xserver.videoDrivers;
# Collector names must match `isValidCollectorSource` in upstream's agent/gpu.go.
# macmon and powermetrics are macOS-only and omitted here.
gpuCollectors = {
# read sysfs directly, need no package or device access
"amd_sysfs" = { };
"intel_sysfs" = { };
"intel_gpu_top" = {
package = lib.getBin pkgs.intel-gpu-tools;
deviceAllow = [ "char-drm rw" ];
capabilities = [ "CAP_PERFMON" ];
# perf_event_open is in @debug, not @system-service
systemCalls = [ "perf_event_open" ];
};
"nvidia-smi" = {
package = lib.getBin config.hardware.nvidia.package;
deviceAllow = [ "char-nvidia* rw" ];
};
"nvml" = {
deviceAllow = [ "char-nvidia* rw" ];
};
"nvtop" = {
package = lib.getBin pkgs.nvtopPackages.full;
deviceAllow = [
"char-nvidia* rw"
"char-drm rw"
];
};
"rocm-smi" = {
package = lib.getBin pkgs.rocmPackages.rocm-smi;
deviceAllow = [
"char-drm rw"
"char-kfd rw"
];
};
};
activeCollectors = lib.optionals (!cfg.environment.SKIP_GPU) cfg.environment.GPU_COLLECTOR;
collectorAttrs =
attr: lib.unique (lib.concatMap (name: gpuCollectors.${name}.${attr} or [ ]) activeCollectors);
gpuPackages = map (name: gpuCollectors.${name}.package) (
lib.filter (name: gpuCollectors.${name} ? package) activeCollectors
);
gpuNeedsDevices = collectorAttrs "deviceAllow" != [ ];
# capabilities granted under PrivateUsers are void on the host, see
# systemd.exec(5), so these collectors also need the user namespace disabled
gpuNeedsCapabilities = collectorAttrs "capabilities" != [ ];
# Any explicit DeviceAllow turns DevicePolicy=auto into an allow-list, so the GPU
# devices are omitted when smartmon relies on full /dev access.
deviceAllowList =
lib.optionals (cfg.smartmon.enable && cfg.smartmon.deviceAllow != [ ]) (
map (device: "${device} r") cfg.smartmon.deviceAllow
)
++ lib.optionals (!cfg.smartmon.enable || cfg.smartmon.deviceAllow != [ ]) (
collectorAttrs "deviceAllow" ++ lib.optionals config.boot.zfs.enabled [ "/dev/zfs rw" ]
);
serviceCapabilities =
lib.optionals cfg.smartmon.enable [
"CAP_SYS_RAWIO"
"CAP_SYS_ADMIN"
]
++ collectorAttrs "capabilities";
in
{
meta.maintainers = with lib.maintainers; [
@@ -60,6 +130,45 @@ in
Enabling this option will skip systemd tracking and its setup in NixOS.
'';
};
SKIP_GPU = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
Whether to disable GPU monitoring.
Enabling this option will skip GPU tracking.
'';
};
GPU_COLLECTOR = lib.mkOption {
# upstream takes a comma-separated string, which used to be passed through as is
type =
with lib.types;
coercedTo str (value: map lib.trim (lib.splitString "," value)) (
listOf (enum (lib.attrNames gpuCollectors))
);
default =
lib.optionals (hasVideoDriver "nvidia") [ "nvidia-smi" ]
++ lib.optionals (hasVideoDriver "amdgpu") [ "amd_sysfs" ]
++ lib.optionals (hasVideoDriver "intel") [ "intel_sysfs" ];
defaultText = lib.literalMD ''
derived from {option}`services.xserver.videoDrivers`
'';
example = [
"nvidia-smi"
"intel_gpu_top"
];
description = ''
GPU collectors to use, in priority order. Overrides the agent's
auto-detection; the packages needed by the selected collectors are added
to the service path. If empty, the agent auto-detects available
collectors. `rocm-smi` is deprecated upstream in favour of `amd_sysfs`,
and `intel_gpu_top` is not used on the xe driver, where `intel_sysfs` is
preferred.
Access to GPU device nodes is only granted for the collectors listed
here, so a collector provided through
{option}`services.beszel.agent.extraPath` has to be listed as well.
'';
};
};
};
default = { };
@@ -129,22 +238,22 @@ in
wants = [ "network-online.target" ];
after = [ "network-online.target" ];
# drop empty lists so an unset GPU_COLLECTOR keeps upstream auto-detection
environment = lib.mapAttrs (
_: value: if lib.isBool value then (lib.boolToString value) else value
) (cfg.environment // { DATA_DIR = cfg.dataDir; });
_: value:
if lib.isBool value then
(lib.boolToString value)
else if lib.isList value then
lib.concatStringsSep "," value
else
value
) (lib.filterAttrs (_: value: value != [ ]) (cfg.environment // { DATA_DIR = cfg.dataDir; }));
path =
cfg.extraPath
++ lib.optionals cfg.smartmon.enable [ cfg.smartmon.package ]
++ lib.optionals (builtins.elem "nvidia" config.services.xserver.videoDrivers) [
(lib.getBin config.hardware.nvidia.package)
]
++ lib.optionals (builtins.elem "amdgpu" config.services.xserver.videoDrivers) [
(lib.getBin pkgs.rocmPackages.rocm-smi)
]
++ lib.optionals (builtins.elem "intel" config.services.xserver.videoDrivers) [
(lib.getBin pkgs.intel-gpu-tools)
];
++ lib.optionals config.boot.zfs.enabled [ config.boot.zfs.package ]
++ gpuPackages;
serviceConfig = {
ExecStart = ''
@@ -165,26 +274,22 @@ in
DynamicUser = true;
User = "beszel-agent";
# Capabilities needed for SMART monitoring
AmbientCapabilities = lib.mkIf cfg.smartmon.enable [
"CAP_SYS_RAWIO"
"CAP_SYS_ADMIN"
];
CapabilityBoundingSet = lib.mkIf cfg.smartmon.enable [
"CAP_SYS_RAWIO"
"CAP_SYS_ADMIN"
];
# Capabilities needed for SMART monitoring and GPU performance counters
AmbientCapabilities = serviceCapabilities;
CapabilityBoundingSet = serviceCapabilities;
# Device access for SMART monitoring
DeviceAllow = lib.mkIf (cfg.smartmon.enable && cfg.smartmon.deviceAllow != [ ]) (
map (device: "${device} r") cfg.smartmon.deviceAllow
);
DeviceAllow = lib.mkIf (deviceAllowList != [ ]) deviceAllowList;
LockPersonality = true;
NoNewPrivileges = !cfg.smartmon.enable;
PrivateDevices = !cfg.smartmon.enable;
PrivateDevices = !cfg.smartmon.enable && !gpuNeedsDevices;
PrivateTmp = true;
PrivateUsers = !cfg.smartmon.enable && !cfg.environment.SKIP_SYSTEMD;
# zfs commands fail inside a user namespace since zfs 2.2, see syncoid.nix
PrivateUsers =
!cfg.smartmon.enable
&& !config.boot.zfs.enabled
&& !cfg.environment.SKIP_SYSTEMD
&& !gpuNeedsCapabilities;
ProtectClock = true;
ProtectControlGroups = "strict";
ProtectHome = "read-only";
@@ -199,7 +304,7 @@ in
RestrictSUIDSGID = true;
SystemCallArchitectures = "native";
SystemCallErrorNumber = "EPERM";
SystemCallFilter = [ "@system-service" ];
SystemCallFilter = [ "@system-service" ] ++ collectorAttrs "systemCalls";
Type = "simple";
UMask = 27;
};

View File

@@ -95,8 +95,8 @@ in
DynamicUser = true;
StateDirectory = "glpi-agent";
CapabilityBoundingSet = [ "CAP_SYS_ADMIN" ];
AmbientCapabilities = [ "CAP_SYS_ADMIN" ];
CapabilityBoundingSet = [ "CAP_DAC_READ_SEARCH" ];
AmbientCapabilities = [ "CAP_DAC_READ_SEARCH" ];
LimitCORE = 0;
LimitNOFILE = 65535;
@@ -104,7 +104,7 @@ in
MemorySwapMax = 0;
MemoryZSwapMax = 0;
PrivateTmp = true;
ProcSubset = "pid";
ProcSubset = "all";
ProtectClock = true;
ProtectControlGroups = true;
ProtectHome = true;

View File

@@ -32,10 +32,14 @@ let
inherit (package) phpPackage;
phpOptions = toKeyValue cfg.phpOptions;
preferLocalBuild = true;
passAsFile = [ "phpOptions" ];
strictDeps = true;
__structuredAttrs = true;
}
''
cat $phpPackage/etc/php.ini $phpOptionsPath > $out
(
cat $phpPackage/etc/php.ini
printf "%s" "$phpOptions"
) > $out
'';
artisanWrapper = pkgs.writeShellScriptBin "librenms-artisan" ''

View File

@@ -240,6 +240,8 @@ in
"AF_INET"
"AF_INET6"
]
# AF_UNIX to be able to connect to e.g. /dev/log
++ lib.optionals (cfg.settings.log.file or "" == "syslog") [ "AF_UNIX" ]
++ lib.optionals cfg.allowDHCP [ "AF_PACKET" ];
RestrictNamespaces = true;
RestrictRealtime = true;

View File

@@ -13,7 +13,6 @@ let
mkEnableOption
mkIf
mkOption
mkOverride
mkPackageOption
nameValuePair
recursiveUpdate
@@ -351,13 +350,11 @@ in
fedimintdName: cfg:
(nameValuePair cfg.nginx.fqdn (
lib.mkMerge [
cfg.nginx.config
(lib.mapAttrsRecursive (_: lib.mkDefault) cfg.nginx.config)
{
# Note: we want by default to enable OpenSSL, but it seems anything 100 and above is
# overridden by default value from vhost-options.nix
enableACME = mkOverride 99 true;
forceSSL = mkOverride 99 true;
enableACME = true;
forceSSL = true;
locations.${cfg.nginx.path_ws} = {
proxyPass = "http://127.0.0.1:${toString cfg.api_ws.port}/";
proxyWebsockets = true;

View File

@@ -1,10 +0,0 @@
{ lib, ... }:
{
imports = [
(lib.mkRemovedOptionModule [ "services" "go-neb" ] ''
The Go-NEB project was discontinued by Matrix.org and archived in June
2023. Use matrix-hookshot or another maintained Matrix bot instead.
'')
];
}

View File

@@ -292,7 +292,7 @@ in
assertions = lib.mapAttrsToList (netName: netCfg: {
# IFNAMSIZ caps network device names to 16 chars (including NULL terminator).
# Without this check, users might end up with a truncated interface name.
assertion = !netCfg.tun.disable && builtins.stringLength netCfg.tun.device <= 15;
assertion = netCfg.tun.disable || builtins.stringLength netCfg.tun.device <= 15;
message = ''
Network device names can't be longer than 15 chars.
`config.services.nebula.networks.${netName}.tun.device` is set to "${netCfg.tun.device}" which is above the limit.

View File

@@ -405,7 +405,9 @@ in
extraConfig = nginxAuthRequest + ''
types {
video/mp4 mp4;
image/jpeg jpg;
image/jpeg jpg jpeg;
image/png png;
image/webp webp;
}
expires 7d;
@@ -493,19 +495,6 @@ in
}
'';
};
# frontend uses this to fetch the version
"/api/go2rtc/api" = {
proxyPass = "http://frigate-go2rtc/api";
recommendedProxySettings = true;
extraConfig =
nginxAuthRequest
+ nginxProxySettings
+ ''
limit_except GET {
deny all;
}
'';
};
# integrationn uses this to add webrtc candidate
"/api/go2rtc/webrtc" = {
proxyPass = "http://frigate-go2rtc/api/webrtc";
@@ -541,6 +530,7 @@ in
expires off;
proxy_cache frigate_api_cache;
proxy_cache_key "$scheme$proxy_host$request_uri|$role|$groups|$user";
proxy_cache_lock on;
proxy_cache_use_stale updating;
proxy_cache_valid 200 5s;
@@ -563,6 +553,13 @@ in
${nginxProxySettings}
}
location /api/logout {
auth_request off;
rewrite ^/api(/.*)$ $1 break;
proxy_pass http://frigate-api;
${nginxProxySettings}
}
location /api/auth/first_time_login {
auth_request off;
limit_except GET {
@@ -747,7 +744,6 @@ in
]
++ optionals (!stdenv.hostPlatform.isAarch64) [
# not available on aarch64-linux
intel-gpu-tools
rocmPackages.rocminfo
];
serviceConfig = {
@@ -775,11 +771,10 @@ in
Group = "frigate";
SupplementaryGroups = [ "render" ] ++ optionals withCoral [ "coral" ];
AmbientCapabilities = optionals (elem cfg.vaapiDriver [
"i965"
"iHD"
]) [ "CAP_PERFMON" ]; # for intel_gpu_top
# No capabilities
CapabilityBoundingSet = [ "" ];
# Allow delegating access
UMask = "0027";
StateDirectory = "frigate";
@@ -797,9 +792,53 @@ in
# Sockets/IPC
RuntimeDirectory = "frigate";
RemoveIPC = true;
# Reduce visible process scope to cgroup
ProtectProc = "invisible";
# Allow wide /proc inspection, e.g. for cpuinfo
ProcSubset = "all";
# Protect various system locations/interfaces
ProtectControlGroups = true;
ProtectHome = true;
ProtectHostname = true;
ProtectKernelLogs = true;
ProtectKernelModules = true;
ProtectKernelTunables = true;
ProtectSystem = "strict";
# No JIT compilation
MemoryDenyWriteExecute = true;
# No ABI personality changes
LockPersonality = true;
# Only IP/Unix sockets
RestrictAddressFamilies = [
"AF_INET"
"AF_INET6"
"AF_UNIX"
];
# Deny namespace creation
RestrictNamespaces = true;
# No privilege escalation
NoNewPrivileges = true;
RestrictSUIDSGID = true;
# No realtime schedulign
RestrictRealtime = true;
# Restrict allowed syscalls
SystemCallFilter = [
"@system-service"
"~@privileged"
];
SystemCallArchitectures = "native";
SystemCallErrorNumber = "EPERM";
};
};

View File

@@ -202,7 +202,7 @@ in
(mkIf cfg.playwrightSupport {
changedetection-io-playwright = {
image = "browserless/chrome";
image = "docker.io/browserless/chrome";
environment = {
SCREEN_WIDTH = "1920";
SCREEN_HEIGHT = "1024";

View File

@@ -116,7 +116,7 @@ in
services.phpfpm.pools.engelsystem = {
user = "engelsystem";
settings = {
settings = lib.mapAttrs (_: v: lib.mkDefault v) {
"listen.owner" = config.services.nginx.user;
"pm" = "dynamic";
"pm.max_children" = 32;

View File

@@ -43,7 +43,7 @@ in
type = types.submodule { freeformType = types.attrsOf (types.nullOr types.str); };
defaultText = lib.literalExpression ''
{
HBOX_STORAGE_CONN_STRING = "file:///var/lib/homebox";
HBOX_STORAGE_CONN_STRING = "file:///var/lib/homebox?no_tmp_dir=1";
HBOX_STORAGE_PREFIX_PATH = "data";
HBOX_DATABASE_DRIVER = "sqlite3";
HBOX_DATABASE_SQLITE_PATH = "/var/lib/homebox/data/homebox.db?_pragma=busy_timeout=999&_pragma=journal_mode=WAL&_fk=1";
@@ -51,7 +51,6 @@ in
HBOX_OPTIONS_GITHUB_RELEASE_CHECK = "false";
HBOX_MODE = "production";
HOME = "/var/lib/homebox";
TMPDIR = "/var/lib/homebox/tmp";
}
'';
description = ''
@@ -125,7 +124,9 @@ in
services.homebox.settings = lib.mkMerge [
(lib.mapAttrs (_: mkDefault) {
HBOX_STORAGE_CONN_STRING = "file:///var/lib/homebox";
# We cannot use a tempdir as homebox wants to rename the file, which does not work across filesystem boundaries
# also see: https://github.com/google/go-cloud/issues/3294 and https://pkg.go.dev/gocloud.dev/blob/fileblob#URLOpener
HBOX_STORAGE_CONN_STRING = "file:///var/lib/homebox?no_tmp_dir=1";
HBOX_STORAGE_PREFIX_PATH = "data";
HBOX_DATABASE_DRIVER = "sqlite3";
HBOX_DATABASE_SQLITE_PATH = "/var/lib/homebox/data/homebox.db?_pragma=busy_timeout=999&_pragma=journal_mode=WAL&_fk=1";
@@ -134,10 +135,8 @@ in
HBOX_MODE = "production";
# Fix this startup issue:
# failed to create modcache index dir: mkdir /var/empty/.cache: read-only file system
# TODO: remove once https://github.com/golang/tools/commit/03cb4551c662c0e078502fe5f317ca4114b89cd8 is available
HOME = "/var/lib/homebox";
# Fix uploading/saving attachments/images:
# [...] rename /tmp/ced4804c80b1ed1f6e88060f6d829db421e6dbf3a189715265900b5d6b0243ed.1889b3d16ab36e22.tmp /var/lib/homebox/data/5f42f81b-e9ad-4495-b6a6-9e9f704db30e/documents/ced4804c80b1ed1f6e88060f6d829db421e6dbf3a189715265900b5d6b0243ed: invalid cross-device link" [...]
TMPDIR = "/var/lib/homebox/tmp";
})
(mkIf cfg.database.createLocally {

View File

@@ -434,10 +434,10 @@ in
package = lib.mkOption {
type = types.package;
default =
if lib.versionAtLeast config.system.stateVersion "26.11" then pkgs.netbox_4_6 else pkgs.netbox_4_5;
if lib.versionAtLeast config.system.stateVersion "26.11" then pkgs.netbox_4_7 else pkgs.netbox_4_5;
defaultText = lib.literalExpression ''
if lib.versionAtLeast config.system.stateVersion "26.11" then
pkgs.netbox_4_6
pkgs.netbox_4_7
else
pkgs.netbox_4_5;
'';
@@ -563,6 +563,15 @@ in
config = lib.mkIf cfg.enable (
lib.mkMerge [
{
assertions = [
{
assertion =
cfg.postgresql.createLocally
-> lib.versionAtLeast config.services.postgresql.finalPackage.version "15";
message = "NetBox requires PostgreSQL >= 15. Please read the NixOS manual to upgrade your PostgreSQL version.";
}
];
services.netbox.plugins = lib.mkIf enableLDAP (ps: [ ps.django-auth-ldap ]);
services.redis.servers.netbox.enable = cfg.redis.createLocally;
@@ -733,26 +742,6 @@ in
PrivateTmp = true;
};
};
netbox-housekeeping = defaultUnitConfig // {
description = "NetBox housekeeping job";
wantedBy = [ "multi-user.target" ];
after = [
"network-online.target"
"netbox.service"
];
wants = [ "network-online.target" ];
serviceConfig = defaultServiceConfig // {
Type = "oneshot";
ExecStart = toString [
(lib.getExe finalPackage)
"housekeeping"
];
};
};
};
systemd.timers.netbox-housekeeping = {

View File

@@ -12,6 +12,13 @@ let
scheme = if cfg.ssl.enable then "https" else "http";
configFile = settingsFormat.generate "rundeck-config.properties" cfg.settings;
jaasLoginModuleClass =
if lib.versionAtLeast cfg.package.version "6" then
"org.rundeck.jaas.PropertyFileLoginModule"
else
"org.eclipse.jetty.jaas.spi.PropertyFileLoginModule";
frameworkFile = settingsFormat.generate "framework.properties" cfg.frameworkSettings;
realmFile = pkgs.writeText "realm.properties" ''
@@ -133,7 +140,43 @@ in
aclPolicies = lib.mkOption {
type = lib.types.attrsOf lib.types.str;
default = { };
default = {
"admin.aclpolicy" = ''
description: Admin, all access.
context:
project: '.*'
for:
resource:
- allow: '*'
adhoc:
- allow: '*'
job:
- allow: '*'
node:
- allow: '*'
runner:
- allow: '*'
by:
group: admin
---
description: Admin, all access.
context:
application: 'rundeck'
for:
resource:
- allow: '*'
project:
- allow: '*'
project_acl:
- allow: '*'
storage:
- allow: '*'
by:
group: admin
'';
};
description = "ACL policies for Rundeck, where the attribute name is the filename and the value is the policy content";
example = lib.literalExpression ''
{
@@ -493,9 +536,9 @@ in
group = cfg.group;
text = ''
RDpropertyfilelogin {
org.eclipse.jetty.jaas.spi.PropertyFileLoginModule required
${jaasLoginModuleClass} required
debug="true"
file="/etc/rundeck/realm.properties";
file="${cfg.configDir}/realm.properties";
};
'';
};
@@ -631,9 +674,7 @@ in
replaceSecret "@SERVER_UUID@" "${cfg.dataDir}/.uuid" "${cfg.configDir}/framework.properties"
)}
if [ -f ${cfg.dataDir}/etc/framework.properties ]; then
install -m 0640 ${cfg.configDir}/framework.properties ${cfg.dataDir}/etc/framework.properties
fi
install -C -m 0640 ${cfg.configDir}/framework.properties ${cfg.dataDir}/etc/framework.properties
${lib.concatStringsSep "\n" (
lib.mapAttrsToList (

View File

@@ -555,7 +555,33 @@ in
before = [ "phpfpm-wordpress-${hostName}.service" ];
after = optional cfg.database.createLocally "mysql.service";
script = secretsScript (stateDir hostName);
serviceConfig = {
Type = "oneshot";
User = user;
Group = webserver.group;
};
})
) eachSite)
(mapAttrs' (
hostName: cfg:
(nameValuePair "wordpress-migrate-database-${hostName}" {
wantedBy = [ "multi-user.target" ];
after = [
"phpfpm-wordpress-${hostName}.service"
]
++ optional cfg.database.createLocally "mysql.service";
script = ''
# Auto migrate database after version update
versionFile="${stateDir hostName}/src-version"
version=$(cat "$versionFile" 2>/dev/null || echo 0)
if [[ $version != 0 && $version != ${cfg.package.version} ]]; then
echo "Executing database migration"
${lib.getExe pkgs.wp-cli} --path="${cfg.finalPackage}/share/wordpress" \
--skip-plugins --skip-themes core update-db
fi
echo ${cfg.package.version} > "$versionFile"
'';
serviceConfig = {
Type = "oneshot";
User = user;

View File

@@ -9,6 +9,10 @@ let
cfg = config.boot.kexec;
in
{
meta = {
inherit (pkgs.kexec-tools.meta) maintainers;
};
options.boot.kexec = {
enable = lib.mkEnableOption "kexec" // {
default = lib.meta.availableOn pkgs.stdenv.hostPlatform pkgs.kexec-tools;

View File

@@ -22,6 +22,14 @@
};
};
syslogConf = {
services.adguardhome = {
enable = true;
settings.log.file = "syslog";
};
};
declarativeConf = {
services.adguardhome = {
enable = true;
@@ -127,6 +135,12 @@
schemaVersionBefore23.wait_for_unit("adguardhome.service")
schemaVersionBefore23.wait_for_open_port(3000)
with subtest("Logging to syslog test"):
# AdGuard is expected to fail when it cannot connect to syslog
# hence its sufficient to look whether the service starts at all
syslogConf.wait_for_unit("adguardhome.service")
syslogConf.wait_for_open_port(3000)
with subtest("Declarative config test, DNS will be reachable"):
declarativeConf.wait_for_unit("adguardhome.service")
declarativeConf.wait_for_open_port(53)

View File

@@ -402,22 +402,10 @@ in
ceph-multi-node-bluestore-cephfs = runTestOn [ "aarch64-linux" "x86_64-linux" ] (
import ./ceph-multi-node-bluestore.nix { withCephfs = true; }
);
ceph-multi-node-deprecated-filestore = runTestOn [
"aarch64-linux"
"x86_64-linux"
] ./ceph-multi-node-deprecated-filestore.nix;
ceph-single-node-bluestore = runTestOn [
"aarch64-linux"
"x86_64-linux"
] ./ceph-single-node-bluestore.nix;
ceph-single-node-bluestore-dmcrypt = runTestOn [
"aarch64-linux"
"x86_64-linux"
] ./ceph-single-node-bluestore-dmcrypt.nix;
ceph-single-node-deprecated-filestore = runTestOn [
"aarch64-linux"
"x86_64-linux"
] ./ceph-single-node-deprecated-filestore.nix;
certmgr = import ./certmgr.nix { inherit pkgs runTest; };
cfssl = runTestOn [ "aarch64-linux" "x86_64-linux" ] ./cfssl.nix;
cgit = runTest ./cgit.nix;
@@ -659,10 +647,6 @@ in
imports = [ ./firefox.nix ];
_module.args.firefoxPackage = pkgs.firefox;
};
firefox-beta = runTest {
imports = [ ./firefox.nix ];
_module.args.firefoxPackage = pkgs.firefox-beta;
};
firefox-devedition = runTest {
imports = [ ./firefox.nix ];
_module.args.firefoxPackage = pkgs.firefox-devedition;
@@ -672,10 +656,6 @@ in
imports = [ ./firefox.nix ];
_module.args.firefoxPackage = pkgs.firefox-esr;
};
firefox-esr-140 = runTest {
imports = [ ./firefox.nix ];
_module.args.firefoxPackage = pkgs.firefox-esr-140;
};
firefox-esr-153 = runTest {
imports = [ ./firefox.nix ];
_module.args.firefoxPackage = pkgs.firefox-esr-153;
@@ -1282,6 +1262,7 @@ in
nginx-modsecurity = runTest ./nginx-modsecurity.nix;
nginx-moreheaders = runTest ./nginx-moreheaders.nix;
nginx-njs = runTest ./nginx-njs.nix;
nginx-otel = runTest ./nginx-otel.nix;
nginx-proxyprotocol = runTest ./nginx-proxyprotocol/default.nix;
nginx-pubhtml = runTest ./nginx-pubhtml.nix;
nginx-redirectcode = runTest ./nginx-redirectcode.nix;
@@ -1322,6 +1303,9 @@ in
nixos-rebuild-target-host = runTest {
imports = [ ./nixos-rebuild-target-host.nix ];
};
nixos-rebuild-target-host-interrupted = runTest {
imports = [ ./nixos-rebuild-target-host-interrupted.nix ];
};
nixpkgs = pkgs.callPackage ../modules/misc/nixpkgs/test.nix { inherit evalMinimalConfig; };
nixpkgs-config-allow-unfree =
pkgs.callPackage ../modules/misc/nixpkgs/test-nixpkgs-config-allow-unfree.nix

View File

@@ -59,6 +59,50 @@
openFirewall = true;
};
};
# Only inspected by the test script, never activated: the VM has no GPU,
# but the generated units can still be checked.
specialisation."gpu-sysfs".configuration = {
services.beszel.agent = {
enable = true;
environment.GPU_COLLECTOR = [ "amd_sysfs" ];
};
};
specialisation."gpu-devices".configuration = {
services.beszel.agent = {
enable = true;
environment.GPU_COLLECTOR = [ "intel_gpu_top" ];
};
};
specialisation."gpu-smartmon".configuration = {
services.beszel.agent = {
enable = true;
# upstream's comma-separated form is accepted as well
environment.GPU_COLLECTOR = "intel_gpu_top";
smartmon = {
enable = true;
deviceAllow = [ "/dev/nvme0" ];
};
};
};
specialisation."zfs".configuration = {
networking.hostId = "8425e349";
boot.supportedFilesystems = [ "zfs" ];
services.beszel.agent.enable = true;
};
specialisation."gpu-skipped".configuration = {
services.beszel.agent = {
enable = true;
environment = {
SKIP_GPU = true;
GPU_COLLECTOR = [ "intel_gpu_top" ];
};
};
};
};
};
@@ -67,6 +111,13 @@
let
hubCfg = nodes.hubHost.services.beszel.hub;
agentCfg = nodes.agentHost.specialisation."agent".configuration.services.beszel.agent;
# /run/current-system points at the "agent" specialisation after the switch,
# so the units are read from the store directly.
gpuUnit =
name:
"${
nodes.agentHost.specialisation.${name}.configuration.system.build.toplevel
}/etc/systemd/system/beszel-agent.service";
in
''
import json
@@ -115,5 +166,41 @@
agentHost.wait_for_unit("beszel-agent.service")
agentHost.wait_until_succeeds("journalctl -eu beszel-agent --grep 'SSH connection established'")
agentHost.wait_until_succeeds(f'curl -H \'Authorization: {user["token"]}\' -f ${agentCfg.environment.HUB_URL}/api/collections/systems/records | jq -e \'.items[].status == "up"\' ')
with subtest("Agent stays sandboxed without a GPU"):
agentHost.succeed("systemctl show beszel-agent -p PrivateDevices --value | grep -qx yes")
agentHost.succeed("systemctl show beszel-agent -p PrivateUsers --value | grep -qx yes")
with subtest("GPU collectors shape the unit"):
# sysfs-only collector keeps the sandbox
sysfs = agentHost.succeed("cat ${gpuUnit "gpu-sysfs"}")
assert "PrivateDevices=true" in sysfs, sysfs
assert "PrivateUsers=true" in sysfs, sysfs
assert "intel-gpu-tools" not in sysfs, sysfs
# device-based collector gets its devices as an allow-list, and
# CAP_PERFMON/perf_event_open with the user namespace disabled
devices = agentHost.succeed("cat ${gpuUnit "gpu-devices"}")
assert "PrivateDevices=false" in devices, devices
assert "PrivateUsers=false" in devices, devices
assert "DeviceAllow=char-drm rw" in devices, devices
assert "CAP_PERFMON" in devices, devices
assert "perf_event_open" in devices, devices
# GPU devices must survive smartmon's DeviceAllow list
smartmon = agentHost.succeed("cat ${gpuUnit "gpu-smartmon"}")
assert "DeviceAllow=/dev/nvme0 r" in smartmon, smartmon
assert "DeviceAllow=char-drm rw" in smartmon, smartmon
# zfs only gets /dev/zfs, but needs the host user namespace
zfs = agentHost.succeed("cat ${gpuUnit "zfs"}")
assert "PrivateDevices=true" in zfs, zfs
assert "DeviceAllow=/dev/zfs rw" in zfs, zfs
assert "PrivateUsers=false" in zfs, zfs
# SKIP_GPU wins over an explicitly configured collector
skipped = agentHost.succeed("cat ${gpuUnit "gpu-skipped"}")
assert "PrivateDevices=true" in skipped, skipped
assert "intel-gpu-tools" not in skipped, skipped
'';
}

View File

@@ -25,19 +25,16 @@ let
osd0 = {
name = "0";
ip = "192.168.1.2";
key = "AQBCEJNa3s8nHRAANvdsr93KqzBznuIWm2gOGg==";
uuid = "55ba2294-3e24-478f-bee0-9dca4c231dd9";
};
osd1 = {
name = "1";
ip = "192.168.1.3";
key = "AQBEEJNac00kExAAXEgy943BGyOpVH1LLlHafQ==";
uuid = "5e97a838-85b6-43b0-8950-cb56d554d1e5";
};
osd2 = {
name = "2";
ip = "192.168.1.4";
key = "AQAdyhZeIaUlARAAGRoidDAmS6Vkp546UFEf5w==";
uuid = "ea999274-13d0-4dd5-9af9-ad25a324f72f";
};
# Client that mounts CephFS using the in-kernel client.
@@ -58,6 +55,14 @@ let
monHost = cfg.monA.ip;
monInitialMembers = cfg.monA.name;
};
extraConfig = {
log_to_syslog = "false";
log_to_file = "false";
log_to_stderr = "true";
debug_rocksdb = "1/5";
debug_mgr = "1/5";
mon_host = "v2:${cfg.monA.ip}:3300 v1:${cfg.monA.ip}:6789";
};
}
// daemonConfig;
@@ -81,6 +86,7 @@ let
bash
sudo
ceph
cryptsetup
netcat
];
@@ -145,6 +151,11 @@ let
enable = true;
daemons = [ cfg.monA.name ];
};
# TODO: move this to a separate machine
rgw = {
enable = true;
daemons = [ cfg.monA.name ];
};
}
# The MDS daemon (which provides CephFS) is only configured in the CephFS
# variant of this test.
@@ -209,6 +220,11 @@ let
vlans = [ 1 ];
};
# Ceph 20.2.4 introduced the aes256k cipher for authentication.
# Linux started supporting these in kernel version 7.0.
# Remove this line at the earliest convenience (i.e. when tests are run by 7.0 or higher by default).
boot.kernelPackages = pkgs.linuxPackages_latest;
networking = networkConfig;
environment.systemPackages = with pkgs; [
@@ -285,6 +301,8 @@ let
# Based on the "manual deployment" approach from:
# https://docs.ceph.com/en/tentacle/install/manual-deployment/
baseScript = ''
import json
start_all()
monA.wait_for_unit("network.target")
@@ -297,14 +315,15 @@ let
"sudo -u ceph ceph-authtool --create-keyring /tmp/ceph.mon.keyring --gen-key -n mon. --cap mon 'allow *'",
"sudo -u ceph ceph-authtool --create-keyring /etc/ceph/ceph.client.admin.keyring --gen-key -n client.admin --cap mon 'allow *' --cap osd 'allow *' --cap mds 'allow *' --cap mgr 'allow *'",
"sudo -u ceph ceph-authtool /tmp/ceph.mon.keyring --import-keyring /etc/ceph/ceph.client.admin.keyring",
"monmaptool --create --add ${cfg.monA.name} ${cfg.monA.ip} --fsid ${cfg.clusterId} /tmp/monmap",
# Creating the mon with v2 (and a legacy v1) address right away removes the need for running `enable-msgr2` later on.
# It is also makes the test more consistent by fixing the address to a known value instead of letting it derive the address.
"monmaptool --create --addv ${cfg.monA.name} '[v2:${cfg.monA.ip}:3300,v1:${cfg.monA.ip}:6789]' --auth-allowed-ciphers aes256k --auth-preferred-cipher aes256k --auth-service-cipher aes256k --fsid ${cfg.clusterId} /tmp/monmap",
"sudo -u ceph ceph-mon --mkfs -i ${cfg.monA.name} --monmap /tmp/monmap --keyring /tmp/ceph.mon.keyring",
"sudo -u ceph mkdir -p /var/lib/ceph/mgr/ceph-${cfg.monA.name}/",
"sudo -u ceph touch /var/lib/ceph/mon/ceph-${cfg.monA.name}/done",
"systemctl start ceph-mon-${cfg.monA.name}",
)
monA.wait_for_unit("ceph-mon-${cfg.monA.name}")
monA.succeed("ceph mon enable-msgr2")
monA.succeed("ceph config set mon auth_allow_insecure_global_id_reclaim false")
# Can't check ceph status until a mon is up
@@ -320,59 +339,63 @@ let
monA.wait_until_succeeds("ceph -s | grep 'quorum ${cfg.monA.name}'")
monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'")
# Send the admin keyring to the OSD machines.
monA.succeed("cp /etc/ceph/ceph.client.admin.keyring /tmp/shared")
osd0.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph")
osd1.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph")
osd2.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph")
# Send the bootstrap-osd keyring to the OSD machines.
monA.succeed("ceph auth get client.bootstrap-osd -o /etc/ceph/ceph.client.bootstrap-osd.keyring")
monA.succeed("cp /etc/ceph/ceph.client.bootstrap-osd.keyring /tmp/shared")
# Bootstrap the BlueStore OSDs.
osd0.succeed(
"mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd0.name}",
"echo bluestore > /var/lib/ceph/osd/ceph-${cfg.osd0.name}/type",
"ln -sf /dev/vdb /var/lib/ceph/osd/ceph-${cfg.osd0.name}/block",
"ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd0.name}/keyring --name osd.${cfg.osd0.name} --add-key ${cfg.osd0.key}",
'echo \'{"cephx_secret": "${cfg.osd0.key}"}\' | ceph osd new ${cfg.osd0.uuid} -i -',
)
osd1.succeed(
"mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd1.name}",
"echo bluestore > /var/lib/ceph/osd/ceph-${cfg.osd1.name}/type",
"ln -sf /dev/vdb /var/lib/ceph/osd/ceph-${cfg.osd1.name}/block",
"ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd1.name}/keyring --name osd.${cfg.osd1.name} --add-key ${cfg.osd1.key}",
'echo \'{"cephx_secret": "${cfg.osd1.key}"}\' | ceph osd new ${cfg.osd1.uuid} -i -',
)
osd2.succeed(
"mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd2.name}",
"echo bluestore > /var/lib/ceph/osd/ceph-${cfg.osd2.name}/type",
"ln -sf /dev/vdb /var/lib/ceph/osd/ceph-${cfg.osd2.name}/block",
"ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd2.name}/keyring --name osd.${cfg.osd2.name} --add-key ${cfg.osd2.key}",
'echo \'{"cephx_secret": "${cfg.osd2.key}"}\' | ceph osd new ${cfg.osd2.uuid} -i -',
)
#
# The steps for this are roughly the same for all OSDs:
# 1. get the bootstrap-osd keyring
# 2. prepare the osd via ceph-volume lvm, the second line contains the OSD specific configuration
# 3. deactivate it to unmount the tmpfs
# 4. activate it without a tmpfs for persistent data
# 5. sync, so the osd has at least one consistent state saved
# 6. start it
# We `sync` so that the config survives the forced crashes below.
# osd.0: plain
osd0.succeed(
"ceph-osd -i ${cfg.osd0.name} --mkfs --osd-uuid ${cfg.osd0.uuid}",
"chown -R ceph:ceph /var/lib/ceph/osd",
"mkdir -p /var/lib/ceph/bootstrap-osd",
"cp /tmp/shared/ceph.client.bootstrap-osd.keyring /var/lib/ceph/bootstrap-osd/ceph.keyring",
"ceph-volume lvm prepare --objectstore bluestore --no-systemd --osd-id ${cfg.osd0.name} --osd-fsid ${cfg.osd0.uuid} "
"--data /dev/vdb",
"ceph-volume lvm deactivate ${cfg.osd0.name} ${cfg.osd0.uuid}",
"ceph-volume lvm activate --no-tmpfs --no-systemd ${cfg.osd0.name} ${cfg.osd0.uuid}",
"sync",
"systemctl start ceph-osd-${cfg.osd0.name}",
)
# osd.1: plain
osd1.succeed(
"ceph-osd -i ${cfg.osd1.name} --mkfs --osd-uuid ${cfg.osd1.uuid}",
"chown -R ceph:ceph /var/lib/ceph/osd",
"mkdir -p /var/lib/ceph/bootstrap-osd",
"cp /tmp/shared/ceph.client.bootstrap-osd.keyring /var/lib/ceph/bootstrap-osd/ceph.keyring",
"ceph-volume lvm prepare --objectstore bluestore --no-systemd --osd-id ${cfg.osd1.name} --osd-fsid ${cfg.osd1.uuid} "
"--data /dev/vdb --dmcrypt",
"ceph-volume lvm deactivate ${cfg.osd1.name} ${cfg.osd1.uuid}",
"ceph-volume lvm activate --no-tmpfs --no-systemd ${cfg.osd1.name} ${cfg.osd1.uuid}",
"sync",
"systemctl start ceph-osd-${cfg.osd1.name}",
)
# osd.2: plain
osd2.succeed(
"ceph-osd -i ${cfg.osd2.name} --mkfs --osd-uuid ${cfg.osd2.uuid}",
"chown -R ceph:ceph /var/lib/ceph/osd",
"mkdir -p /var/lib/ceph/bootstrap-osd",
"cp /tmp/shared/ceph.client.bootstrap-osd.keyring /var/lib/ceph/bootstrap-osd/ceph.keyring",
"ceph-volume lvm prepare --objectstore bluestore --no-systemd --osd-fsid ${cfg.osd2.uuid} --osd-id ${cfg.osd2.name} "
"--data /dev/vdb",
"ceph-volume lvm deactivate ${cfg.osd2.name} ${cfg.osd2.uuid}",
"ceph-volume lvm activate --no-tmpfs --no-systemd ${cfg.osd2.name} ${cfg.osd2.uuid}",
"sync",
"systemctl start ceph-osd-${cfg.osd2.name}",
)
monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'")
monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'")
monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'")
monA.succeed(
# Autoscaling will cause PGs to be peering, causing the tests to become flakey.
"ceph osd pool set noautoscale",
"ceph osd pool create multi-node-test 32 32",
"ceph osd pool ls | grep 'multi-node-test'",
@@ -389,6 +412,7 @@ let
"ceph osd pool ls | grep 'multi-node-other-test'",
)
monA.succeed("ceph osd pool set multi-node-other-test size 2")
# TODO: actually write to the pool using rados directly
monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'")
monA.wait_until_succeeds("! ceph -s | grep -e 'unknown' -e 'pgs inactive'")
monA.fail(
@@ -396,23 +420,100 @@ let
"ceph osd pool delete multi-node-other-test multi-node-other-test --yes-i-really-really-mean-it",
)
# Bootstrap RGW
monA.succeed(
"sudo -u ceph mkdir -p /var/lib/ceph/radosgw/ceph-${cfg.monA.name}",
"ceph auth get-or-create client.${cfg.monA.name} osd 'allow rwx' mon 'allow rw' > /var/lib/ceph/radosgw/ceph-${cfg.monA.name}/keyring",
"chown ceph:ceph /var/lib/ceph/radosgw/ceph-${cfg.monA.name}/keyring",
"systemctl start ceph-rgw-${cfg.monA.name}",
)
monA.wait_for_unit("ceph-rgw-${cfg.monA.name}")
monA.wait_for_open_port(7480)
# Enable the dashboard and recheck health
monA.succeed(
"ceph mgr module enable dashboard",
"ceph config set mgr mgr/dashboard/ssl false",
# default is 8080 but it's better to be explicit
"ceph config set mgr mgr/dashboard/server_port 8080",
)
# The dashboard does not listen on localhost:
# `server_addr` defaults to the wildcard address, but the dashboard module
# resolves that to the active mgr's own IP and binds only to it,
# so loopback is never bound.
# See https://github.com/ceph/ceph/blob/v20.2.2/src/pybind/mgr/dashboard/module.py#L213-L214
# Therefore address the dashboard via the mgr's IP instead of localhost.
dashboard = "http://${cfg.monA.ip}:8080"
monA.wait_for_open_port(8080, addr="${cfg.monA.ip}")
monA.wait_until_succeeds(f"curl -s --fail {dashboard}")
monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'")
# Initialize dashboard creds.
# In a the query below, we test the Dashboard's `/api/rgw/daemon`,
# which needs that the dashboard can talk to RGW.
# `set-rgw-credentials` needs a running RGW daemon.
monA.succeed(
"echo 'foo bar baz qux' > /tmp/dashboard_pw",
"ceph dashboard ac-user-create admin -i /tmp/dashboard_pw administrator",
"ceph dashboard set-rgw-credentials",
"sync",
)
# Get dashboard auth token
auth_payload = json.dumps({"username": "admin", "password": "foo bar baz qux"})
auth_response = json.loads(monA.succeed(
f"curl --fail -s -X POST -H 'Accept: application/vnd.ceph.api.v1.0+json' -H 'Content-Type: application/json' -d '{auth_payload}' {dashboard}/api/auth",
))
token = auth_response["token"]
# Check cluster health via dashboard API
health = json.loads(monA.succeed(
f"curl --fail -s -H 'Accept: application/vnd.ceph.api.v1.0+json' -H 'Authorization: Bearer {token}' {dashboard}/api/health/minimal",
))
assert health["health"]["status"] == "HEALTH_OK"
# List daemons via REST API.
# This also requires a running RGW daemon, as it asserts on the first one.
rgw_daemons = json.loads(monA.succeed(
f"curl --fail -s -H 'Accept: application/vnd.ceph.api.v1.0+json' -H 'Authorization: Bearer {token}' {dashboard}/api/rgw/daemon",
))
assert rgw_daemons[0]["id"] == "${cfg.monA.name}"
# Shut down ceph on all machines in a very unpolite way
monA.crash()
osd0.crash()
osd1.crash()
osd2.crash()
# Start it up
# Start the mon first and mark the OSDs as down.
# Since the heartbeats are pretty high by default, the OSDs would otherwise be marked as up still.
# However we do not want to lower the heartbeats since this might cause flakey tests.
monA.start()
monA.wait_for_unit("ceph-mon-${cfg.monA.name}")
monA.wait_until_succeeds("ceph osd down all")
# Then start the OSDs as normal.
osd0.start()
osd1.start()
osd2.start()
monA.start()
# Ensure they are all up.
osd0.wait_for_unit("network.target")
osd1.wait_for_unit("network.target")
osd2.wait_for_unit("network.target")
# Ensure the cluster comes back up again.
# FIXME: dmcrypt OSDs currently do not work out of the box.
# For a potential long-term fix see: https://github.com/NixOS/nixpkgs/pull/512912#discussion_r3140295546
osd1.succeed(
"ceph-volume lvm activate --no-tmpfs --no-systemd ${cfg.osd1.name} ${cfg.osd1.uuid}",
"systemctl start ceph-osd-${cfg.osd1.name}",
)
# Test the cluster state thoroughly.
monA.wait_until_succeeds("ceph -s | grep 'mon: 1 daemons'")
monA.wait_until_succeeds("ceph -s | grep 'quorum ${cfg.monA.name}'")
monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'")
monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'")
monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'")
monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'")
# Verify the recovery.
@@ -444,45 +545,50 @@ let
# Create a CephFS.
monA.succeed(
"ceph osd pool create cephfs-data 32 32",
"ceph osd pool create cephfs-metadata 32 32",
"ceph fs new cephfs cephfs-metadata cephfs-data",
"ceph fs volume create testing",
"ceph osd pool set cephfs.testing.data pg_num 32",
"ceph osd pool set cephfs.testing.meta pg_num 32",
)
# Wait for the MDS to claim the filesystem and become active.
monA.wait_until_succeeds("ceph fs status cephfs | grep -e 'active'", timeout=60)
monA.wait_until_succeeds("ceph fs status testing | grep -e 'active'", timeout=60)
# Distribute the admin keyring (and a plain secret file for the kernel
# client) to both client machines, so that they can authenticate.
# Create a subvolume, issue credentials, then distribute those credentials.
monA.succeed(
"cp /etc/ceph/ceph.client.admin.keyring /tmp/shared",
"ceph-authtool -p /etc/ceph/ceph.client.admin.keyring > /tmp/shared/admin.secret",
"ceph fs subvolumegroup create testing group",
"ceph fs subvolume create testing subvolume --group_name group",
"ceph fs subvolume authorize testing subvolume kclient group",
"ceph fs subvolume authorize testing subvolume fuseclient group",
"ceph auth get client.kclient -o /tmp/shared/ceph.client.kclient.keyring",
"ceph auth get client.fuseclient -o /tmp/shared/ceph.client.fuseclient.keyring",
)
kclient.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph")
fuseclient.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph")
kclient.succeed("cp /tmp/shared/admin.secret /etc/ceph/admin.secret")
kclient.succeed("cp /tmp/shared/ceph.client.kclient.keyring /etc/ceph")
fuseclient.succeed("cp /tmp/shared/ceph.client.fuseclient.keyring /etc/ceph")
# Get the volume path generated by Ceph.
volume_path = monA.succeed("ceph fs subvolume getpath testing subvolume group | tee /dev/stderr").strip()
# Mount CephFS on the kernel client.
# We force the messenger v2 protocol via "ms_mode=secure"; the cluster
# has msgr2 enabled (see "ceph mon enable-msgr2" above) and the legacy v1
# has msgr2 enabled (the monmap is created with a v2 address above) and the legacy v1
# protocol apparently does not reconnect reliably after the servers are restarted.
# The msgr2 monitor listens on port 3300 (instead of legacy v1 port 6789),
# so we have to point the device string at that port explicitly.
# `recover_session=clean` makes the kernel client automatically reconnect
# (discarding its stale session) after the whole cluster has been down,
# which would otherwise leave the mount blocklisted and hanging forever.
# which would otherwise leave the mount blocklisted and hanging.
# Real CephFS use may not prefer hanging `recover_session=clean`, and
# prefer manual de-blocklisting to avoid any failed OS syscalls,
# but for this test, discarding stale sessions is good enough.
kclient.succeed("mkdir -p /mnt/cephfs")
kclient.wait_until_succeeds(
"mount -t ceph ${cfg.monA.ip}:3300:/ /mnt/cephfs -o name=admin,secretfile=/etc/ceph/admin.secret,ms_mode=secure,recover_session=clean"
f"mount -t ceph kclient@.testing={volume_path} /mnt/cephfs -o ms_mode=secure,recover_session=clean"
)
kclient.succeed("mountpoint /mnt/cephfs")
# Mount CephFS on the FUSE client using ceph-fuse.
fuseclient.succeed("mkdir -p /mnt/cephfs")
fuseclient.wait_until_succeeds(
"ceph-fuse --id admin -m ${cfg.monA.ip}:6789 /mnt/cephfs"
f"ceph-fuse --id fuseclient -m ${cfg.monA.ip}:3300 -r {volume_path} /mnt/cephfs"
)
fuseclient.succeed("mountpoint /mnt/cephfs")
@@ -510,24 +616,40 @@ let
osd1.crash()
osd2.crash()
# Start it up
# Start the mon first and mark the OSDs as down.
# Since the heartbeats are pretty high by default, the OSDs would otherwise be marked as up still.
# However we do not want to lower the heartbeats since this might cause flakey tests.
monA.start()
monA.wait_for_unit("ceph-mon-${cfg.monA.name}")
monA.wait_until_succeeds("ceph osd down all")
# Then start the OSDs as normal.
osd0.start()
osd1.start()
osd2.start()
monA.start()
# Ensure they are all up.
osd0.wait_for_unit("network.target")
osd1.wait_for_unit("network.target")
osd2.wait_for_unit("network.target")
# FIXME: dmcrypt OSDs currently do not work out of the box.
# For a potential long-term fix see: https://github.com/NixOS/nixpkgs/pull/512912#discussion_r3140295546
osd1.succeed(
"ceph-volume lvm activate --no-tmpfs --no-systemd ${cfg.osd1.name} ${cfg.osd1.uuid}",
"systemctl start ceph-osd-${cfg.osd1.name}",
)
# Ensure the cluster comes back up again.
# See the note above on why this uses `wait_until_succeeds`.
monA.wait_until_succeeds("ceph -s | grep 'mon: 1 daemons'")
monA.wait_until_succeeds("ceph -s | grep 'quorum ${cfg.monA.name}'")
monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'")
monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'")
monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'")
monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'", timeout=60)
# Ensure the MDS/CephFS comes back up again, too.
monA.wait_for_unit("ceph-mds-${cfg.monA.name}")
monA.wait_until_succeeds("ceph fs status cephfs | grep -e 'active'", timeout=60)
monA.wait_until_succeeds("ceph fs status testing | grep -e 'active'", timeout=60)
monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'")
# The clients kept running across the outage, so their CephFS mounts

View File

@@ -1,291 +0,0 @@
# Tests the legacy FileStore OSD backend.
{ lib, ... }:
let
cfg = {
clusterId = "066ae264-2a5d-4729-8001-6ad265f50b03";
monA = {
name = "a";
ip = "192.168.1.1";
};
osd0 = {
name = "0";
ip = "192.168.1.2";
key = "AQBCEJNa3s8nHRAANvdsr93KqzBznuIWm2gOGg==";
uuid = "55ba2294-3e24-478f-bee0-9dca4c231dd9";
};
osd1 = {
name = "1";
ip = "192.168.1.3";
key = "AQBEEJNac00kExAAXEgy943BGyOpVH1LLlHafQ==";
uuid = "5e97a838-85b6-43b0-8950-cb56d554d1e5";
};
osd2 = {
name = "2";
ip = "192.168.1.4";
key = "AQAdyhZeIaUlARAAGRoidDAmS6Vkp546UFEf5w==";
uuid = "ea999274-13d0-4dd5-9af9-ad25a324f72f";
};
};
generateCephConfig =
{ daemonConfig }:
{
enable = true;
global = {
fsid = cfg.clusterId;
monHost = cfg.monA.ip;
monInitialMembers = cfg.monA.name;
};
}
// daemonConfig;
generateHost =
{ cephConfig, networkConfig }:
{ pkgs, ... }:
{
virtualisation = {
emptyDiskImages = [ 20480 ];
vlans = [ 1 ];
};
networking = networkConfig;
environment.systemPackages = with pkgs; [
bash
sudo
ceph
xfsprogs
netcat
];
boot.kernelModules = [ "xfs" ];
services.ceph = cephConfig;
};
networkMonA = {
dhcpcd.enable = false;
interfaces.eth1.ipv4.addresses = lib.mkOverride 0 [
{
address = cfg.monA.ip;
prefixLength = 24;
}
];
firewall = {
allowedTCPPorts = [
6789
3300
];
allowedTCPPortRanges = [
{
from = 6800;
to = 7300;
}
];
};
};
cephConfigMonA = generateCephConfig {
daemonConfig = {
mon = {
enable = true;
daemons = [ cfg.monA.name ];
};
mgr = {
enable = true;
daemons = [ cfg.monA.name ];
};
};
};
networkOsd = osd: {
dhcpcd.enable = false;
interfaces.eth1.ipv4.addresses = lib.mkOverride 0 [
{
address = osd.ip;
prefixLength = 24;
}
];
firewall = {
allowedTCPPortRanges = [
{
from = 6800;
to = 7300;
}
];
};
};
cephConfigOsd =
osd:
generateCephConfig {
daemonConfig = {
osd = {
enable = true;
daemons = [ osd.name ];
};
};
};
# Following deployment is based on the manual deployment described here:
# https://docs.ceph.com/docs/master/install/manual-deployment/
# For other ways to deploy a ceph cluster, look at the documentation at
# https://docs.ceph.com/docs/master/
testscript =
{ ... }:
''
start_all()
monA.wait_for_unit("network.target")
osd0.wait_for_unit("network.target")
osd1.wait_for_unit("network.target")
osd2.wait_for_unit("network.target")
# Bootstrap ceph-mon daemon
monA.succeed(
"sudo -u ceph ceph-authtool --create-keyring /tmp/ceph.mon.keyring --gen-key -n mon. --cap mon 'allow *'",
"sudo -u ceph ceph-authtool --create-keyring /etc/ceph/ceph.client.admin.keyring --gen-key -n client.admin --cap mon 'allow *' --cap osd 'allow *' --cap mds 'allow *' --cap mgr 'allow *'",
"sudo -u ceph ceph-authtool /tmp/ceph.mon.keyring --import-keyring /etc/ceph/ceph.client.admin.keyring",
"monmaptool --create --add ${cfg.monA.name} ${cfg.monA.ip} --fsid ${cfg.clusterId} /tmp/monmap",
"sudo -u ceph ceph-mon --mkfs -i ${cfg.monA.name} --monmap /tmp/monmap --keyring /tmp/ceph.mon.keyring",
"sudo -u ceph mkdir -p /var/lib/ceph/mgr/ceph-${cfg.monA.name}/",
"sudo -u ceph touch /var/lib/ceph/mon/ceph-${cfg.monA.name}/done",
"systemctl start ceph-mon-${cfg.monA.name}",
)
monA.wait_for_unit("ceph-mon-${cfg.monA.name}")
monA.succeed("ceph mon enable-msgr2")
monA.succeed("ceph config set mon auth_allow_insecure_global_id_reclaim false")
# Can't check ceph status until a mon is up
monA.succeed("ceph -s | grep 'mon: 1 daemons'")
# Start the ceph-mgr daemon, it has no deps and hardly any setup
monA.succeed(
"ceph auth get-or-create mgr.${cfg.monA.name} mon 'allow profile mgr' osd 'allow *' mds 'allow *' > /var/lib/ceph/mgr/ceph-${cfg.monA.name}/keyring",
"sync", # to ensure shell redirection above is durable
"systemctl start ceph-mgr-${cfg.monA.name}",
)
monA.wait_for_unit("ceph-mgr-a")
monA.wait_until_succeeds("ceph -s | grep 'quorum ${cfg.monA.name}'")
monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'")
# Send the admin keyring to the OSD machines
monA.succeed("cp /etc/ceph/ceph.client.admin.keyring /tmp/shared")
osd0.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph")
osd1.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph")
osd2.succeed("cp /tmp/shared/ceph.client.admin.keyring /etc/ceph")
# Bootstrap OSDs
osd0.succeed(
"mkfs.xfs /dev/vdb",
"mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd0.name}",
"mount /dev/vdb /var/lib/ceph/osd/ceph-${cfg.osd0.name}",
"ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd0.name}/keyring --name osd.${cfg.osd0.name} --add-key ${cfg.osd0.key}",
'echo \'{"cephx_secret": "${cfg.osd0.key}"}\' | ceph osd new ${cfg.osd0.uuid} -i -',
)
osd1.succeed(
"mkfs.xfs /dev/vdb",
"mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd1.name}",
"mount /dev/vdb /var/lib/ceph/osd/ceph-${cfg.osd1.name}",
"ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd1.name}/keyring --name osd.${cfg.osd1.name} --add-key ${cfg.osd1.key}",
'echo \'{"cephx_secret": "${cfg.osd1.key}"}\' | ceph osd new ${cfg.osd1.uuid} -i -',
)
osd2.succeed(
"mkfs.xfs /dev/vdb",
"mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd2.name}",
"mount /dev/vdb /var/lib/ceph/osd/ceph-${cfg.osd2.name}",
"ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd2.name}/keyring --name osd.${cfg.osd2.name} --add-key ${cfg.osd2.key}",
'echo \'{"cephx_secret": "${cfg.osd2.key}"}\' | ceph osd new ${cfg.osd2.uuid} -i -',
)
# We `sync` so that the config survives the forced crashes below.
osd0.succeed(
"ceph-osd -i ${cfg.osd0.name} --mkfs --osd-uuid ${cfg.osd0.uuid}",
"chown -R ceph:ceph /var/lib/ceph/osd",
"sync",
"systemctl start ceph-osd-${cfg.osd0.name}",
)
osd1.succeed(
"ceph-osd -i ${cfg.osd1.name} --mkfs --osd-uuid ${cfg.osd1.uuid}",
"chown -R ceph:ceph /var/lib/ceph/osd",
"sync",
"systemctl start ceph-osd-${cfg.osd1.name}",
)
osd2.succeed(
"ceph-osd -i ${cfg.osd2.name} --mkfs --osd-uuid ${cfg.osd2.uuid}",
"chown -R ceph:ceph /var/lib/ceph/osd",
"sync",
"systemctl start ceph-osd-${cfg.osd2.name}",
)
monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'")
monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'")
monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'")
monA.succeed(
"ceph osd pool create multi-node-test 32 32",
"ceph osd pool ls | grep 'multi-node-test'",
# We need to enable an application on the pool, otherwise it will
# stay unhealthy in state POOL_APP_NOT_ENABLED.
# Creating a CephFS would do this automatically, but we haven't done that here.
# See: https://docs.ceph.com/en/reef/rados/operations/pools/#associating-a-pool-with-an-application
# We use the custom application name "nixos-test" for this.
"ceph osd pool application enable multi-node-test nixos-test",
"ceph osd pool rename multi-node-test multi-node-other-test",
"ceph osd pool ls | grep 'multi-node-other-test'",
)
monA.wait_until_succeeds("ceph -s | grep '2 pools, 33 pgs'")
monA.succeed("ceph osd pool set multi-node-other-test size 2")
monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'")
monA.wait_until_succeeds("ceph -s | grep '33 active+clean'")
monA.fail(
"ceph osd pool ls | grep 'multi-node-test'",
"ceph osd pool delete multi-node-other-test multi-node-other-test --yes-i-really-really-mean-it",
)
# Shut down ceph on all machines in a very unpolite way
monA.crash()
osd0.crash()
osd1.crash()
osd2.crash()
# Start it up
osd0.start()
osd1.start()
osd2.start()
monA.start()
# Ensure the cluster comes back up again
monA.succeed("ceph -s | grep 'mon: 1 daemons'")
monA.wait_until_succeeds("ceph -s | grep 'quorum ${cfg.monA.name}'")
monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'")
monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'")
monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'")
'';
in
{
name = "basic-multi-node-ceph-cluster-deprecated-filestore";
meta = with lib.maintainers; {
maintainers = [ lejonet ];
};
nodes = {
monA = generateHost {
cephConfig = cephConfigMonA;
networkConfig = networkMonA;
};
osd0 = generateHost {
cephConfig = cephConfigOsd cfg.osd0;
networkConfig = networkOsd cfg.osd0;
};
osd1 = generateHost {
cephConfig = cephConfigOsd cfg.osd1;
networkConfig = networkOsd cfg.osd1;
};
osd2 = generateHost {
cephConfig = cephConfigOsd cfg.osd2;
networkConfig = networkOsd cfg.osd2;
};
};
testScript = testscript;
}

View File

@@ -1,269 +0,0 @@
{ lib, ... }:
let
# the single node ipv6 address
ip = "2001:db8:ffff::";
# the global ceph cluster id
cluster = "54465b37-b9d8-4539-a1f9-dd33c75ee45a";
# the fsids of OSDs
osd-fsid-map = {
"0" = "1c1b7ea9-06bf-4d30-9a01-37ac3a0254aa";
"1" = "bd5a6f49-69d5-428c-ac25-a99f0c44375c";
"2" = "c90de6c7-86c6-41da-9694-e794096dfc5c";
};
in
{
name = "basic-single-node-ceph-cluster-bluestore-dmcrypt";
meta.maintainers = with lib.maintainers; [
benaryorg
nh2
];
nodes.ceph =
{
lib,
pkgs,
config,
...
}:
{
# disks for bluestore
virtualisation.emptyDiskImages = [
20480
20480
20480
];
# networking setup (no external connectivity required, only local IPv6)
networking.useDHCP = false;
systemd.network = {
enable = true;
wait-online.extraArgs = [
"-i"
"lo"
];
networks = {
"40-loopback" = {
enable = true;
name = "lo";
DHCP = "no";
addresses = [ { Address = "${ip}/128"; } ];
};
};
};
# do not start the ceph target by default so we can format the disks first
systemd.targets.ceph.wantedBy = lib.mkForce [ ];
# add the packages to systemPackages so the testscript doesn't run into any unexpected issues
# this shouldn't be required on production systems which have their required packages in the unit paths only
# but it helps in case one needs to actually run the tooling anyway
environment.systemPackages = with pkgs; [
ceph
cryptsetup
lvm2
];
services.ceph = {
enable = true;
client.enable = true;
extraConfig = {
public_addr = ip;
cluster_addr = ip;
# ipv6
ms_bind_ipv4 = "false";
ms_bind_ipv6 = "true";
# msgr2 settings
ms_cluster_mode = "secure";
ms_service_mode = "secure";
ms_client_mode = "secure";
ms_mon_cluster_mode = "secure";
ms_mon_service_mode = "secure";
ms_mon_client_mode = "secure";
# less default modules, cuts down on memory and startup time in the tests
mgr_initial_modules = "";
# distribute by OSD, not by host, as per https://docs.ceph.com/en/reef/cephadm/install/#single-host
osd_crush_chooseleaf_type = "0";
};
client.extraConfig."mon.0" = {
host = "ceph";
mon_addr = "v2:[${ip}]:3300";
public_addr = "v2:[${ip}]:3300";
};
global = {
fsid = cluster;
clusterNetwork = "${ip}/64";
publicNetwork = "${ip}/64";
monInitialMembers = "0";
};
mon = {
enable = true;
daemons = [ "0" ];
};
osd = {
enable = true;
daemons = builtins.attrNames osd-fsid-map;
};
mgr = {
enable = true;
daemons = [ "ceph" ];
};
};
systemd.services =
let
osd-name = id: "ceph-osd-${id}";
osd-pre-start = id: [
"!${config.services.ceph.osd.package.out}/bin/ceph-volume lvm activate --bluestore ${id} ${osd-fsid-map.${id}} --no-systemd"
"${config.services.ceph.osd.package.lib}/libexec/ceph/ceph-osd-prestart.sh --id ${id} --cluster ${config.services.ceph.global.clusterName}"
];
osd-post-stop = id: [
"!${config.services.ceph.osd.package.out}/bin/ceph-volume lvm deactivate ${id}"
];
map-osd = id: {
name = osd-name id;
value = {
serviceConfig.ExecStartPre = lib.mkForce (osd-pre-start id);
serviceConfig.ExecStopPost = osd-post-stop id;
unitConfig.ConditionPathExists = lib.mkForce [ ];
unitConfig.StartLimitBurst = lib.mkForce 4;
path = with pkgs; [
util-linux
lvm2
cryptsetup
];
};
};
in
lib.pipe config.services.ceph.osd.daemons [
(map map-osd)
builtins.listToAttrs
];
};
testScript = ''
start_all()
ceph.wait_for_unit("default.target")
# Bootstrap ceph-mon daemon
ceph.succeed(
"mkdir -p /var/lib/ceph/bootstrap-osd",
"ceph-authtool --create-keyring /tmp/ceph.mon.keyring --gen-key -n mon. --cap mon 'allow *'",
"ceph-authtool --create-keyring /etc/ceph/ceph.client.admin.keyring --gen-key -n client.admin --cap mon 'allow *' --cap osd 'allow *' --cap mds 'allow *' --cap mgr 'allow *'",
"ceph-authtool --create-keyring /var/lib/ceph/bootstrap-osd/ceph.keyring --gen-key -n client.bootstrap-osd --cap mon 'profile bootstrap-osd' --cap mgr 'allow r'",
"ceph-authtool /tmp/ceph.mon.keyring --import-keyring /etc/ceph/ceph.client.admin.keyring",
"ceph-authtool /tmp/ceph.mon.keyring --import-keyring /var/lib/ceph/bootstrap-osd/ceph.keyring",
"monmaptool --create --fsid ${cluster} --addv 0 'v2:[${ip}]:3300/0' --clobber /tmp/ceph.initial-monmap",
"mkdir -p /var/lib/ceph/mon/ceph-0",
"ceph-mon --mkfs -i 0 --monmap /tmp/ceph.initial-monmap --keyring /tmp/ceph.mon.keyring",
"chown ceph:ceph -R /tmp/ceph.mon.keyring /var/lib/ceph",
"systemctl start ceph-mon-0.service",
)
ceph.wait_for_unit("ceph-mon-0.service")
# should the mon not start or bind for some reason this gives us a better error message than the config commands running into a timeout
ceph.wait_for_open_port(3300, "${ip}")
ceph.succeed(
# required for HEALTH_OK
"ceph config set mon auth_allow_insecure_global_id_reclaim false",
# IPv6
"ceph config set global ms_bind_ipv4 false",
"ceph config set global ms_bind_ipv6 true",
# the new (secure) protocol
"ceph config set global ms_bind_msgr1 false",
"ceph config set global ms_bind_msgr2 true",
# just a small little thing
"ceph config set mon mon_compact_on_start true",
)
# Can't check ceph status until a mon is up
ceph.succeed("ceph -s | grep 'mon: 1 daemons'")
# Bootstrap OSDs (do this before starting the mgr because cryptsetup and the mgr both eat a lot of memory)
ceph.succeed(
# this will automatically do what's required for LVM, cryptsetup, and stores all the data in Ceph's internal databases
"ceph-volume lvm prepare --bluestore --data /dev/vdb --dmcrypt --no-systemd --osd-id 0 --osd-fsid ${osd-fsid-map."0"}",
"ceph-volume lvm prepare --bluestore --data /dev/vdc --dmcrypt --no-systemd --osd-id 1 --osd-fsid ${osd-fsid-map."1"}",
"ceph-volume lvm prepare --bluestore --data /dev/vdd --dmcrypt --no-systemd --osd-id 2 --osd-fsid ${osd-fsid-map."2"}",
"sudo ceph-volume lvm deactivate 0",
"sudo ceph-volume lvm deactivate 1",
"sudo ceph-volume lvm deactivate 2",
"chown -R ceph:ceph /var/lib/ceph",
)
# Start OSDs (again, argon2id eats memory, so this happens before starting the mgr)
ceph.succeed(
"systemctl start ceph-osd-0.service",
"systemctl start ceph-osd-1.service",
"systemctl start ceph-osd-2.service",
)
ceph.wait_until_succeeds("ceph -s | grep 'quorum 0'")
ceph.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'")
# Start the ceph-mgr daemon, after copying in the keyring
ceph.succeed(
"mkdir -p /var/lib/ceph/mgr/ceph-ceph/",
"ceph auth get-or-create -o /var/lib/ceph/mgr/ceph-ceph/keyring mgr.ceph mon 'allow profile mgr' osd 'allow *' mds 'allow *'",
"chown -R ceph:ceph /var/lib/ceph/mgr/ceph-ceph/",
"systemctl start ceph-mgr-ceph.service",
)
ceph.wait_for_unit("ceph-mgr-ceph")
ceph.wait_until_succeeds("ceph -s | grep 'quorum 0'")
ceph.wait_until_succeeds("ceph -s | grep 'mgr: ceph(active,'")
ceph.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'")
ceph.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'")
# test the actual storage
ceph.succeed(
"ceph osd pool create single-node-test 32 32",
"ceph osd pool ls | grep 'single-node-test'",
# We need to enable an application on the pool, otherwise it will
# stay unhealthy in state POOL_APP_NOT_ENABLED.
# Creating a CephFS would do this automatically, but we haven't done that here.
# See: https://docs.ceph.com/en/reef/rados/operations/pools/#associating-a-pool-with-an-application
# We use the custom application name "nixos-test" for this.
"ceph osd pool application enable single-node-test nixos-test",
"ceph osd pool rename single-node-test single-node-other-test",
"ceph osd pool ls | grep 'single-node-other-test'",
)
ceph.wait_until_succeeds("ceph -s | grep '2 pools, 33 pgs'")
ceph.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'")
ceph.wait_until_succeeds("ceph -s | grep '33 active+clean'")
ceph.fail(
# the old pool should be gone
"ceph osd pool ls | grep 'multi-node-test'",
# deleting the pool should fail without setting mon_allow_pool_delete
"ceph osd pool delete single-node-other-test single-node-other-test --yes-i-really-really-mean-it",
)
# rebooting gets rid of any potential tmpfs mounts or device-mapper devices
ceph.shutdown()
ceph.start()
ceph.wait_for_unit("default.target")
# Start it up (again OSDs first due to memory constraints of cryptsetup and mgr)
ceph.systemctl("start ceph-mon-0.service")
ceph.wait_for_unit("ceph-mon-0")
ceph.systemctl("start ceph-osd-0.service")
ceph.wait_for_unit("ceph-osd-0")
ceph.systemctl("start ceph-osd-1.service")
ceph.wait_for_unit("ceph-osd-1")
ceph.systemctl("start ceph-osd-2.service")
ceph.wait_for_unit("ceph-osd-2")
ceph.systemctl("start ceph-mgr-ceph.service")
ceph.wait_for_unit("ceph-mgr-ceph")
# Ensure the cluster comes back up again
ceph.succeed("ceph -s | grep 'mon: 1 daemons'")
ceph.wait_until_succeeds("ceph -s | grep 'quorum 0'")
ceph.wait_until_succeeds("ceph osd stat | grep -E '3 osds: 3 up[^,]*, 3 in'")
ceph.wait_until_succeeds("ceph -s | grep 'mgr: ceph(active,'")
ceph.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'")
'';
}

View File

@@ -9,17 +9,14 @@ let
};
osd0 = {
name = "0";
key = "AQBCEJNa3s8nHRAANvdsr93KqzBznuIWm2gOGg==";
uuid = "55ba2294-3e24-478f-bee0-9dca4c231dd9";
};
osd1 = {
name = "1";
key = "AQBEEJNac00kExAAXEgy943BGyOpVH1LLlHafQ==";
uuid = "5e97a838-85b6-43b0-8950-cb56d554d1e5";
};
osd2 = {
name = "2";
key = "AQAdyhZeIaUlARAAGRoidDAmS6Vkp546UFEf5w==";
uuid = "ea999274-13d0-4dd5-9af9-ad25a324f72f";
};
};
@@ -51,6 +48,11 @@ let
vlans = [ 1 ];
};
# Ceph 20.2.4 introduced the aes256k cipher for authentication.
# Linux started supporting these in kernel version 7.0.
# Remove this line at the earliest convenience (i.e. when tests are run by 7.0 or higher by default).
boot.kernelPackages = pkgs.linuxPackages_latest;
networking = networkConfig;
environment.systemPackages = with pkgs; [
@@ -115,13 +117,18 @@ let
"sudo -u ceph ceph-authtool --create-keyring /tmp/ceph.mon.keyring --gen-key -n mon. --cap mon 'allow *'",
"sudo -u ceph ceph-authtool --create-keyring /etc/ceph/ceph.client.admin.keyring --gen-key -n client.admin --cap mon 'allow *' --cap osd 'allow *' --cap mds 'allow *' --cap mgr 'allow *'",
"sudo -u ceph ceph-authtool /tmp/ceph.mon.keyring --import-keyring /etc/ceph/ceph.client.admin.keyring",
"monmaptool --create --add ${cfg.monA.name} ${cfg.monA.ip} --fsid ${cfg.clusterId} /tmp/monmap",
# Create the monmap with both a msgr2 (v2) and a legacy (v1) address.
# Using plain `--add` yields a v1-only monmap, which leaves the cluster
# in HEALTH_WARN with MON_MSGR2_NOT_ENABLED. Running `ceph mon
# enable-msgr2` afterwards is not enough: it rewrites the monmap (a
# subsequent `ceph mon dump` does show the v2 address), but the health
# check keeps reporting the mon as v1-only indefinitely.
"monmaptool --create --addv ${cfg.monA.name} '[v2:${cfg.monA.ip}:3300,v1:${cfg.monA.ip}:6789]' --fsid ${cfg.clusterId} /tmp/monmap",
"sudo -u ceph ceph-mon --mkfs -i ${cfg.monA.name} --monmap /tmp/monmap --keyring /tmp/ceph.mon.keyring",
"sudo -u ceph touch /var/lib/ceph/mon/ceph-${cfg.monA.name}/done",
"systemctl start ceph-mon-${cfg.monA.name}",
)
monA.wait_for_unit("ceph-mon-${cfg.monA.name}")
monA.succeed("ceph mon enable-msgr2")
monA.succeed("ceph config set mon auth_allow_insecure_global_id_reclaim false")
# Can't check ceph status until a mon is up
@@ -148,14 +155,24 @@ let
"mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd2.name}",
"echo bluestore > /var/lib/ceph/osd/ceph-${cfg.osd2.name}/type",
"ln -sf /dev/vdd /var/lib/ceph/osd/ceph-${cfg.osd2.name}/block",
"ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd0.name}/keyring --name osd.${cfg.osd0.name} --add-key ${cfg.osd0.key}",
"ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd1.name}/keyring --name osd.${cfg.osd1.name} --add-key ${cfg.osd1.key}",
"ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd2.name}/keyring --name osd.${cfg.osd2.name} --add-key ${cfg.osd2.key}",
'echo \'{"cephx_secret": "${cfg.osd0.key}"}\' | ceph osd new ${cfg.osd0.uuid} -i -',
'echo \'{"cephx_secret": "${cfg.osd1.key}"}\' | ceph osd new ${cfg.osd1.uuid} -i -',
'echo \'{"cephx_secret": "${cfg.osd2.key}"}\' | ceph osd new ${cfg.osd2.uuid} -i -',
"ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd0.name}/keyring --name osd.${cfg.osd0.name} --gen-key",
"ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd1.name}/keyring --name osd.${cfg.osd1.name} --gen-key",
"ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd2.name}/keyring --name osd.${cfg.osd2.name} --gen-key",
)
# Register the OSDs with the generated keys read back from their keyrings.
for osd_name, osd_uuid in [
("${cfg.osd0.name}", "${cfg.osd0.uuid}"),
("${cfg.osd1.name}", "${cfg.osd1.uuid}"),
("${cfg.osd2.name}", "${cfg.osd2.uuid}"),
]:
key = monA.succeed(
f"ceph-authtool --print-key /var/lib/ceph/osd/ceph-{osd_name}/keyring --name osd.{osd_name}"
).strip()
monA.succeed(
f"echo '{{\"cephx_secret\": \"{key}\"}}' | ceph osd new {osd_uuid} -i -"
)
# Initialize the OSDs with regular filestore
monA.succeed(
"ceph-osd -i ${cfg.osd0.name} --mkfs --osd-uuid ${cfg.osd0.uuid}",

View File

@@ -1,249 +0,0 @@
{ lib, ... }:
let
cfg = {
clusterId = "066ae264-2a5d-4729-8001-6ad265f50b03";
monA = {
name = "a";
ip = "192.168.1.1";
};
osd0 = {
name = "0";
key = "AQBCEJNa3s8nHRAANvdsr93KqzBznuIWm2gOGg==";
uuid = "55ba2294-3e24-478f-bee0-9dca4c231dd9";
};
osd1 = {
name = "1";
key = "AQBEEJNac00kExAAXEgy943BGyOpVH1LLlHafQ==";
uuid = "5e97a838-85b6-43b0-8950-cb56d554d1e5";
};
osd2 = {
name = "2";
key = "AQAdyhZeIaUlARAAGRoidDAmS6Vkp546UFEf5w==";
uuid = "ea999274-13d0-4dd5-9af9-ad25a324f72f";
};
};
generateCephConfig =
{ daemonConfig }:
{
enable = true;
global = {
fsid = cfg.clusterId;
monHost = cfg.monA.ip;
monInitialMembers = cfg.monA.name;
};
}
// daemonConfig;
generateHost =
{
cephConfig,
networkConfig,
}:
{ pkgs, ... }:
{
virtualisation = {
memorySize = 2048;
emptyDiskImages = [
20480
20480
20480
];
vlans = [ 1 ];
};
networking = networkConfig;
environment.systemPackages = with pkgs; [
bash
sudo
ceph
xfsprogs
];
boot.kernelModules = [ "xfs" ];
services.ceph = cephConfig;
};
networkMonA = {
dhcpcd.enable = false;
interfaces.eth1.ipv4.addresses = lib.mkOverride 0 [
{
address = cfg.monA.ip;
prefixLength = 24;
}
];
};
cephConfigMonA = generateCephConfig {
daemonConfig = {
mon = {
enable = true;
daemons = [ cfg.monA.name ];
};
mgr = {
enable = true;
daemons = [ cfg.monA.name ];
};
osd = {
enable = true;
daemons = [
cfg.osd0.name
cfg.osd1.name
cfg.osd2.name
];
};
rgw = {
enable = true;
daemons = [ cfg.monA.name ];
};
};
};
# Following deployment is based on the manual deployment described here:
# https://docs.ceph.com/docs/master/install/manual-deployment/
# For other ways to deploy a ceph cluster, look at the documentation at
# https://docs.ceph.com/docs/master/
testScript = ''
start_all()
monA.wait_for_unit("network.target")
# Bootstrap ceph-mon daemon
monA.succeed(
"sudo -u ceph ceph-authtool --create-keyring /tmp/ceph.mon.keyring --gen-key -n mon. --cap mon 'allow *'",
"sudo -u ceph ceph-authtool --create-keyring /etc/ceph/ceph.client.admin.keyring --gen-key -n client.admin --cap mon 'allow *' --cap osd 'allow *' --cap mds 'allow *' --cap mgr 'allow *'",
"sudo -u ceph ceph-authtool /tmp/ceph.mon.keyring --import-keyring /etc/ceph/ceph.client.admin.keyring",
"monmaptool --create --add ${cfg.monA.name} ${cfg.monA.ip} --fsid ${cfg.clusterId} /tmp/monmap",
"sudo -u ceph ceph-mon --mkfs -i ${cfg.monA.name} --monmap /tmp/monmap --keyring /tmp/ceph.mon.keyring",
"sudo -u ceph touch /var/lib/ceph/mon/ceph-${cfg.monA.name}/done",
"systemctl start ceph-mon-${cfg.monA.name}",
)
monA.wait_for_unit("ceph-mon-${cfg.monA.name}")
monA.succeed("ceph mon enable-msgr2")
monA.succeed("ceph config set mon auth_allow_insecure_global_id_reclaim false")
# Can't check ceph status until a mon is up
monA.succeed("ceph -s | grep 'mon: 1 daemons'")
# Start the ceph-mgr daemon, after copying in the keyring
monA.succeed(
"sudo -u ceph mkdir -p /var/lib/ceph/mgr/ceph-${cfg.monA.name}/",
"ceph auth get-or-create mgr.${cfg.monA.name} mon 'allow profile mgr' osd 'allow *' mds 'allow *' > /var/lib/ceph/mgr/ceph-${cfg.monA.name}/keyring",
"systemctl start ceph-mgr-${cfg.monA.name}",
)
monA.wait_for_unit("ceph-mgr-a")
monA.wait_until_succeeds("ceph -s | grep 'quorum ${cfg.monA.name}'")
monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'")
# Bootstrap OSDs
monA.succeed(
"mkfs.xfs /dev/vdb",
"mkfs.xfs /dev/vdc",
"mkfs.xfs /dev/vdd",
"mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd0.name}",
"mount /dev/vdb /var/lib/ceph/osd/ceph-${cfg.osd0.name}",
"mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd1.name}",
"mount /dev/vdc /var/lib/ceph/osd/ceph-${cfg.osd1.name}",
"mkdir -p /var/lib/ceph/osd/ceph-${cfg.osd2.name}",
"mount /dev/vdd /var/lib/ceph/osd/ceph-${cfg.osd2.name}",
"ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd0.name}/keyring --name osd.${cfg.osd0.name} --add-key ${cfg.osd0.key}",
"ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd1.name}/keyring --name osd.${cfg.osd1.name} --add-key ${cfg.osd1.key}",
"ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${cfg.osd2.name}/keyring --name osd.${cfg.osd2.name} --add-key ${cfg.osd2.key}",
'echo \'{"cephx_secret": "${cfg.osd0.key}"}\' | ceph osd new ${cfg.osd0.uuid} -i -',
'echo \'{"cephx_secret": "${cfg.osd1.key}"}\' | ceph osd new ${cfg.osd1.uuid} -i -',
'echo \'{"cephx_secret": "${cfg.osd2.key}"}\' | ceph osd new ${cfg.osd2.uuid} -i -',
)
# Initialize the OSDs with regular filestore
monA.succeed(
"ceph-osd -i ${cfg.osd0.name} --mkfs --osd-uuid ${cfg.osd0.uuid}",
"ceph-osd -i ${cfg.osd1.name} --mkfs --osd-uuid ${cfg.osd1.uuid}",
"ceph-osd -i ${cfg.osd2.name} --mkfs --osd-uuid ${cfg.osd2.uuid}",
"chown -R ceph:ceph /var/lib/ceph/osd",
"systemctl start ceph-osd-${cfg.osd0.name}",
"systemctl start ceph-osd-${cfg.osd1.name}",
"systemctl start ceph-osd-${cfg.osd2.name}",
)
monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'")
monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'")
monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'")
monA.succeed(
"ceph osd pool create single-node-test 32 32",
"ceph osd pool ls | grep 'single-node-test'",
# We need to enable an application on the pool, otherwise it will
# stay unhealthy in state POOL_APP_NOT_ENABLED.
# Creating a CephFS would do this automatically, but we haven't done that here.
# See: https://docs.ceph.com/en/reef/rados/operations/pools/#associating-a-pool-with-an-application
# We use the custom application name "nixos-test" for this.
"ceph osd pool application enable single-node-test nixos-test",
"ceph osd pool rename single-node-test single-node-other-test",
"ceph osd pool ls | grep 'single-node-other-test'",
)
monA.wait_until_succeeds("ceph -s | grep '2 pools, 33 pgs'")
monA.succeed(
"ceph osd getcrushmap -o crush",
"crushtool -d crush -o decrushed",
"sed 's/step chooseleaf firstn 0 type host/step chooseleaf firstn 0 type osd/' decrushed > modcrush",
"crushtool -c modcrush -o recrushed",
"ceph osd setcrushmap -i recrushed",
"ceph osd pool set single-node-other-test size 2",
)
monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'")
monA.wait_until_succeeds("ceph -s | grep '33 active+clean'")
monA.fail(
"ceph osd pool ls | grep 'multi-node-test'",
"ceph osd pool delete single-node-other-test single-node-other-test --yes-i-really-really-mean-it",
)
# Bootstrap RGW
monA.succeed(
"sudo -u ceph mkdir -p /var/lib/ceph/radosgw/ceph-${cfg.monA.name}",
"ceph auth get-or-create client.${cfg.monA.name} osd 'allow rwx' mon 'allow rw' > /var/lib/ceph/radosgw/ceph-${cfg.monA.name}/keyring",
"chown ceph:ceph /var/lib/ceph/radosgw/ceph-${cfg.monA.name}/keyring",
"systemctl start ceph-rgw-${cfg.monA.name}",
)
monA.wait_for_unit("ceph-rgw-${cfg.monA.name}")
monA.wait_for_open_port(7480)
# Shut down ceph by stopping ceph.target.
monA.succeed("systemctl stop ceph.target")
# Start it up
monA.succeed("systemctl start ceph.target")
monA.wait_for_unit("ceph-mon-${cfg.monA.name}")
monA.wait_for_unit("ceph-mgr-${cfg.monA.name}")
monA.wait_for_unit("ceph-osd-${cfg.osd0.name}")
monA.wait_for_unit("ceph-osd-${cfg.osd1.name}")
monA.wait_for_unit("ceph-osd-${cfg.osd2.name}")
monA.wait_for_unit("ceph-rgw-${cfg.monA.name}")
# Ensure the cluster comes back up again
monA.succeed("ceph -s | grep 'mon: 1 daemons'")
monA.wait_until_succeeds("ceph -s | grep 'quorum ${cfg.monA.name}'")
monA.wait_until_succeeds("ceph osd stat | grep -e '3 osds: 3 up[^,]*, 3 in'")
monA.wait_until_succeeds("ceph -s | grep 'mgr: ${cfg.monA.name}(active,'")
monA.wait_until_succeeds("ceph -s | grep 'HEALTH_OK'")
'';
in
{
name = "basic-single-node-ceph-cluster-deprecated-filestore";
meta = with lib.maintainers; {
maintainers = [
lejonet
johanot
];
};
nodes = {
monA = generateHost {
cephConfig = cephConfigMonA;
networkConfig = networkMonA;
};
};
inherit testScript;
}

View File

@@ -10,11 +10,30 @@
enable = true;
port = 8888;
};
services.nginx = {
enable = true;
virtualHosts.localhost = {
locations."/" = {
return = "200 'hello world'";
extraConfig = ''
default_type text/plain;
'';
};
};
};
};
testScript = ''
testScript = /* python */ ''
import json
machine.wait_for_unit("flaresolverr.service")
machine.wait_for_open_port(8888)
machine.succeed("curl --fail http://localhost:8888/")
res = machine.succeed("""curl --fail http://localhost:8888/v1 -X POST --json '{ "cmd": "request.get", "url": "http://localhost/", "maxTimeout": 10000 }'""")
res = json.loads(res)
response = res["solution"]["response"]
assert "hello world" in response, f"Could not find 'hello world' in response: {response}"
'';
}

View File

@@ -77,5 +77,7 @@
# wait for a recording to appear
machine.wait_for_file("/var/cache/frigate/test@*.mp4")
machine.log(machine.execute("systemd-analyze security frigate.service | grep -v ✓")[1])
'';
}

View File

@@ -14,6 +14,8 @@ in
services.homebox = {
enable = true;
settings.HBOX_WEB_PORT = port;
settings.HBOX_OPTIONS_ALLOW_REGISTRATION = "true";
settings.HBOX_LOG_LEVEL = "trace";
};
};
@@ -50,6 +52,7 @@ in
in
self;
testScript = ''
import json
def test_homebox(node):
node.wait_for_unit("homebox.service")
node.wait_for_open_port(${port})
@@ -57,6 +60,29 @@ in
node.succeed("curl --fail -X GET 'http://localhost:${port}/'")
out = node.succeed("curl --fail 'http://localhost:${port}/api/v1/status'")
assert '"health":true' in out
node.succeed("curl --request POST --fail 'http://localhost:${port}/api/v1/users/register' \
--data '{\"email\":\"a@b.c\",\"name\":\"test\",\"password\":\"password\"}' \
")
login = node.succeed("curl --request POST --fail 'http://localhost:${port}/api/v1/users/login' \
--data-urlencode 'password=password' \
--data-urlencode 'username=a@b.c' \
")
login_data = json.loads(login)
token = login_data["token"]
locations = node.succeed(f"curl --request GET --fail 'http://localhost:${port}/api/v1/entities?isLocation=true' \
--header 'Authorization: {token}' \
")
location_id = json.loads(locations)["items"][0]["id"]
item = node.succeed(f"curl --request POST --fail 'http://localhost:${port}/api/v1/entities' \
--header 'Authorization: {token}' \
--data '{{\"name\":\"testitem\",\"parentId\":\"{location_id}\"}}' \
")
item_id = json.loads(item)["id"]
node.succeed(f"curl --request POST --fail 'http://localhost:${port}/api/v1/entities/{item_id}/attachments' \
--header 'Authorization: {token}' \
--form 'file=test;type=text/plain;filename=test.txt' \
--form name=test.txt \
")
test_homebox(simple)
simple.send_monitor_command("quit")

View File

@@ -2,7 +2,7 @@
{
name = "kexec";
meta = with lib.maintainers; {
maintainers = [
maintainers = pkgs.kexec-tools.meta.maintainers ++ [
flokli
lassulus
];

View File

@@ -1,11 +1,11 @@
{
lib,
pkgs,
...
}:
{
name = "music-assistant";
meta.maintainers = with lib.maintainers; [ hexa ];
meta = { inherit (pkgs.music-assistant.meta) maintainers; };
containers.machine = {
services.music-assistant = {

View File

@@ -1,6 +1,9 @@
{ pkgs, lib, ... }:
{
pkgs,
lib,
...
}:
let
# We'll need to be able to trade cert files between nodes via scp.
inherit (import ../ssh-keys.nix pkgs)
snakeOilPrivateKey
@@ -44,13 +47,11 @@ let
}
extraConfig
];
in
{
name = "nebula";
nodes = {
lighthouse =
{ ... }@args:
makeNebulaNode args "lighthouse" {
@@ -97,6 +98,24 @@ in
};
};
};
# A lighthouse can run without a tun interface, no device name = skip length check pr 565501
services.nebula.networks.tunless = {
ca = "/etc/nebula/ca.crt";
cert = "/etc/nebula/lighthouse.crt";
key = "/etc/nebula/lighthouse.key";
isLighthouse = true;
listen = {
host = "0.0.0.0";
port = 4243;
};
tun = {
disable = true;
device = "nebula.tunless-too-long";
};
user = "nebula-smoke";
group = "nebula-smoke";
};
};
allowAny =
@@ -265,12 +284,10 @@ in
};
};
};
};
testScript =
let
setUpPrivateKey = name: ''
${name}.start()
${name}.succeed(
@@ -379,6 +396,11 @@ in
lighthouse.wait_until_succeeds("ping -c1 -W1 10.0.100.1", timeout=10)
lighthouse.wait_until_succeeds("ping -c1 -W1 2001:db8::1", timeout=10)
# The tunless network starts without a tun device despite its (deliberately over-long) configured device name. pr 565501
lighthouse.wait_for_unit("nebula@tunless.service")
lighthouse.wait_until_succeeds("ss -lun | grep -q ':4243'", timeout=10)
lighthouse.fail("ip link show nebula.tunless-too-long")
# Start all the machines to be set up
allowAny.start()
allowFromLighthouse.start()

View File

@@ -0,0 +1,56 @@
{
name = "nginx-otel";
nodes.machine =
{ pkgs, ... }:
{
services.opentelemetry-collector = {
enable = true;
settings = {
receivers.otlp.protocols.grpc.endpoint = "127.0.0.1:4317";
exporters.debug.verbosity = "detailed";
service.pipelines.traces = {
receivers = [ "otlp" ];
exporters = [ "debug" ];
};
};
};
services.nginx = {
enable = true;
additionalModules = [ pkgs.nginxModules.otel ];
commonHttpConfig = ''
otel_exporter {
endpoint localhost:4317;
}
otel_service_name "nginx-test";
otel_trace on;
'';
virtualHosts."localhost".locations."/".extraConfig = ''
otel_trace_context propagate;
otel_span_name "handle";
return 200 "otel-ok";
'';
};
};
testScript =
{ nodes, ... }:
let
cfg = nodes.machine.services.nginx;
in
''
machine.wait_for_unit("opentelemetry-collector")
machine.wait_for_open_port(4317)
machine.wait_for_unit("nginx")
machine.wait_for_open_port(80)
machine.succeed("test -e ${cfg.package}/modules/ngx_otel_module.so")
machine.succeed("grep -F ngx_otel_module.so ${cfg.package}/etc/nginx/dynamic-modules.conf")
response = machine.wait_until_succeeds("curl -fsS http://127.0.0.1/")
t.assertIn("otel-ok", response)
machine.wait_until_succeeds("journalctl -u opentelemetry-collector --grep 'service.name: Str\\(nginx-test\\)'")
machine.wait_until_succeeds("journalctl -u opentelemetry-collector --grep 'Name +: handle'")
'';
}

View File

@@ -12,10 +12,12 @@ in
{
virtualisation.writableStore = true;
system.extraDependencies = [ (pkgs.runCommand "deps" { } "mkdir $out").inputDerivation ];
nix.nixPath = [ "nixpkgs=${../../..}" ];
nix.settings.substituters = lib.mkForce [ ];
nix.settings.system-features = [ "supported-feature" ];
nix.settings.experimental-features = [ "nix-command" ];
nix.settings = {
experimental-features = [ "nix-command" ];
nix-path = [ "nixpkgs=${../../..}" ];
substituters = lib.mkForce [ ];
system-features = [ "supported-feature" ];
};
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
programs.nix-required-mounts.enable = true;
programs.nix-required-mounts.allowedPatterns.supported-feature = {

View File

@@ -0,0 +1,236 @@
{ hostPkgs, ... }:
# This test recreates a remote deployment scenario where the connection
# between deployer and target is closed during the deployment - in this
# case because the connection goes over a 'reverse ssh' tunnel service
# that has changes that are being deployed.
# This is not seamless (the deployer doesn't get to see the logs after
# the disconnect), but is a lot better than the old behaviour, where
# the switch was aborted and the connection never restored.
{
name = "nixos-rebuild-target-host-interrupted";
# TODO: remove overlay from nixos/modules/profiles/installation-device.nix
# make it a _small package instead, then remove pkgsReadOnly = false;.
node.pkgsReadOnly = false;
# disabled by default. See all-tests.nix / tag(no-nix-by-default)
defaults.nix.enable = true;
nodes = {
deployer =
{
nodes,
lib,
pkgs,
...
}:
let
inherit (import ./ssh-keys.nix pkgs) snakeOilPrivateKey snakeOilPublicKey;
in
{
imports = [
../modules/profiles/installation-device.nix
];
nix.settings = {
substituters = lib.mkForce [ ];
hashed-mirrors = null;
connect-timeout = 1;
};
system.includeBuildDependencies = true;
virtualisation = {
cores = 2;
memorySize = 3072;
};
services.openssh.enable = true;
users.users.root.openssh.authorizedKeys.keys = [ nodes.target.system.build.publicKey ];
system.build.privateKey = snakeOilPrivateKey;
system.build.publicKey = snakeOilPublicKey;
system.switch.enable = true;
services.getty.autologinUser = lib.mkForce "root";
};
target =
{
nodes,
lib,
pkgs,
...
}:
let
inherit (import ./ssh-keys.nix pkgs) snakeOilPrivateKey snakeOilPublicKey;
targetConfig = {
documentation.enable = false;
services.openssh.enable = true;
system.build.privateKey = snakeOilPrivateKey;
system.build.publicKey = snakeOilPublicKey;
users.users.root.openssh.authorizedKeys.keys = [ nodes.deployer.system.build.publicKey ];
users.users.alice.openssh.authorizedKeys.keys = [ nodes.deployer.system.build.publicKey ];
users.users.bob.openssh.authorizedKeys.keys = [ nodes.deployer.system.build.publicKey ];
users.users.alice.extraGroups = [ "wheel" ];
users.users.bob.extraGroups = [ "wheel" ];
# Disable sudo for root to ensure sudo isn't called without `--sudo`
security.sudo.extraRules = lib.mkForce [
{
groups = [ "wheel" ];
commands = [ { command = "ALL"; } ];
}
{
users = [ "alice" ];
commands = [
{
command = "ALL";
options = [ "NOPASSWD" ];
}
];
}
];
nix.settings.trusted-users = [ "@wheel" ];
environment.etc."autossh-identity.key" = {
source = nodes.target.system.build.privateKey;
mode = "0600";
};
services.autossh-ng.sessions.will-be-interrupted-by-rebuild = {
user = "root";
destination = "deployer";
extraArguments = "-R2222:localhost:22 -i/etc/autossh-identity.key";
hostKeyChecking = false;
};
# Faster retry to avoid slow test
systemd.services.autossh-ng-will-be-interrupted-by-rebuild.serviceConfig.RestartSec =
lib.mkForce "1s";
};
in
{
imports = [ ./common/user-account.nix ];
config = lib.mkMerge [
targetConfig
{
system.build = {
inherit targetConfig;
};
system.switch.enable = true;
networking.hostName = "target";
}
];
};
};
testScript =
{ nodes, ... }:
let
sshConfig = builtins.toFile "ssh.conf" ''
UserKnownHostsFile=/dev/null
StrictHostKeyChecking=no
'';
targetConfigJSON = hostPkgs.writeText "target-configuration.json" (
builtins.toJSON nodes.target.system.build.targetConfig
);
targetNetworkJSON = hostPkgs.writeText "target-network.json" (
builtins.toJSON nodes.target.system.build.networkConfig
);
configFile =
hostname:
hostPkgs.writeText "configuration.nix" # nix
''
{ lib, pkgs, modulesPath, ... }: {
imports = [
(modulesPath + "/virtualisation/qemu-vm.nix")
(modulesPath + "/virtualisation/guest-networking-options.nix")
(modulesPath + "/testing/test-instrumentation.nix")
(modulesPath + "/../tests/common/user-account.nix")
(lib.modules.importJSON ./target-configuration.json)
(lib.modules.importJSON ./target-network.json)
./hardware-configuration.nix
];
boot.loader.grub = {
enable = true;
device = "/dev/vda";
forceInstall = true;
};
# We're changing the '-E' parameter to the new hostname here,
# not because we care about the logs, but because we want to
# force the scenario where the connection is broken during the
# deployment (because the autossh-ng service is stopped and
# started):
services.autossh-ng.sessions.will-be-interrupted-by-rebuild.extraArguments = "-R2222:localhost:22 -i/etc/autossh-identity.key -E ${hostname}";
# this will be asserted to validate the switch happened:
networking.hostName = "${hostname}";
}
'';
in
# python
''
start_all()
target.wait_for_open_port(22)
deployer.wait_until_succeeds("ping -c1 target")
deployer.succeed("install -Dm 600 ${nodes.deployer.system.build.privateKey} ~root/.ssh/id_ecdsa")
deployer.succeed("install ${sshConfig} ~root/.ssh/config")
target.succeed("nixos-generate-config")
deployer.succeed("scp alice@target:/etc/nixos/hardware-configuration.nix /root/hardware-configuration.nix")
target.wait_for_unit("autossh-ng-will-be-interrupted-by-rebuild.service")
deployer.copy_from_host("${configFile "config-1-deployed"}", "/root/configuration-1.nix")
deployer.copy_from_host("${configFile "config-2-deployed"}", "/root/configuration-2.nix")
deployer.copy_from_host("${targetNetworkJSON}", "/root/target-network.json")
deployer.copy_from_host("${targetConfigJSON}", "/root/target-configuration.json")
with subtest("Deploy to alice@target via reverse ssh"):
deployer.wait_for_unit("multi-user.target")
# Uses TTY/send_chars instead of deployer.succeed to set NIX_SSHOPTS
deployer.send_chars("NIX_SSHOPTS=\"-p 2222\" nixos-rebuild switch -I nixos-config=/root/configuration-1.nix --target-host alice@localhost --sudo\n")
# the connection breaks, but the 'switch' should now continue in the background:
deployer.wait_until_tty_matches("1", "error: while running command with remote sudo")
def deployed(last_try: bool) -> bool:
target_hostname = deployer.succeed("ssh alice@target cat /etc/hostname", timeout=20).rstrip()
if last_try:
print(f"Still seeing hostname {target_hostname}")
return target_hostname == "config-1-deployed"
retry(deployed)
with subtest("Deploy to bob@target via reverse ssh with password-based sudo"):
deployer.wait_for_unit("multi-user.target")
# Uses TTY/send_chars instead of deployer.succeed to set NIX_SSHOPTS and for ask-sudo-password
deployer.send_chars("""NIX_SSHOPTS="-p 2222" nixos-rebuild switch -I nixos-config=/root/configuration-2.nix --target-host bob@localhost --ask-sudo-password; printf '%s\\n' "$?" > /tmp/bob-rebuild-status\n""")
deployer.wait_until_tty_matches("1", "password for bob")
deployer.send_chars("${nodes.target.users.users.bob.password}\n")
# the connection breaks, but the 'switch' should now continue in the background:
deployer.wait_for_file("/tmp/bob-rebuild-status")
status = deployer.succeed("cat /tmp/bob-rebuild-status").strip()
assert status != "0", "Expected the interrupted SSH deployment to report failure"
def deployed(last_try: bool) -> bool:
target_hostname = deployer.succeed("ssh alice@target cat /etc/hostname", timeout=20).rstrip()
if last_try:
print(f"Still seeing hostname {target_hostname}")
return target_hostname == "config-2-deployed"
retry(deployed)
'';
}

View File

@@ -36,13 +36,18 @@ in
enable = true;
settings = {
PORT = 10001;
DB_CONNECTION_STRING = "host=/run/postgresql user=${username} database=${username}";
DB_CONNECTION_STRING = "postgresql:///${username}?host=/run/postgresql";
};
credentials = {
inherit ENCRYPTION_KEY;
};
};
systemd.services.pocket-id = {
after = [ "postgresql.target" ];
requires = [ "postgresql.target" ];
};
services.postgresql = {
enable = true;
ensureUsers = [

View File

@@ -22,6 +22,7 @@ let
wal_level = "logical";
max_replication_slots = "10";
max_wal_senders = "10";
output_plugin_libraries = "wal2json";
};
};
};

View File

@@ -90,7 +90,6 @@ import ./make-test-python.nix (
# test server
machine.succeed("${qgisPackage}/bin/qgis_mapserver --version | grep 'QGIS ${qgisPackage.version}'")
machine.succeed("curl --head http://localhost | grep 'Server:.*${qgisPackage.version}'")
machine.succeed("curl http://localhost/index.json | grep 'Landing page as JSON'")
'';
}

View File

@@ -12,6 +12,13 @@
group = "rundeck";
};
environment.etc."rundeck-tokens.properties" = {
text = "testadmin: nixostesttoken,admin";
mode = "0400";
user = "rundeck";
group = "rundeck";
};
services.rundeck = {
enable = true;
serverHostname = "rundeck";
@@ -20,6 +27,7 @@
serverPort = 4441;
database.type = "h2";
openFirewall = true;
frameworkSettings."rundeck.tokens.file" = "/etc/rundeck-tokens.properties";
};
environment.systemPackages = with pkgs; [
@@ -32,17 +40,8 @@
testScript = ''
start_all()
def login_and_verify_api(machine, host, port, user, password, timeout=300):
"""Authenticate via Rundeck form login and verify API access."""
machine.wait_until_succeeds(
f"curl -s -c /tmp/cookies -L"
f" -d 'j_username={user}&j_password={password}'"
f" http://{host}:{port}/j_security_check -o /dev/null"
f" && curl -s -b /tmp/cookies -H 'Accept: application/json'"
f" http://{host}:{port}/api/26/system/info"
f" | jq -e '.system.rundeck.version'",
timeout=timeout,
)
api = "http://rundeck:4441/api/26"
token = "-H 'X-Rundeck-Auth-Token: nixostesttoken' -H 'Accept: application/json'"
def properties(machine, path):
return machine.succeed(f"cat {path}").replace("\\", "").replace(" = ", "=")
@@ -90,21 +89,32 @@
"[ \"$(stat -c %U /etc/rundeck/realm.properties)\" = rundeck ]"
)
with subtest("API authentication via form login"):
login_and_verify_api(rundeck, "rundeck", 4441, "testadmin", "testpassword")
with subtest("Form login accepts realm credentials"):
rundeck.wait_until_succeeds(
"curl -s -o /dev/null -w '%{url_effective}' -c /tmp/login-cookies -L"
" -d 'j_username=testadmin&j_password=testpassword'"
" http://rundeck:4441/j_security_check"
" | grep -qvE 'error|login'",
timeout=300,
)
with subtest("API authentication via static token"):
rundeck.wait_until_succeeds(
f"curl -s {token} {api}/system/info"
" | jq -e '.system.rundeck.version'",
timeout=300,
)
rundeck.succeed(
"curl -s -b /tmp/cookies -X POST"
" -H 'Accept: application/json'"
f"curl -s {token} -X POST"
" -H 'Content-Type: application/json'"
" -d '{\"name\":\"test-project\",\"config\":{}}'"
" http://rundeck:4441/api/26/projects"
f" {api}/projects"
" | jq -e '.name == \"test-project\"'"
)
rundeck.succeed(
"curl -s -b /tmp/cookies -H 'Accept: application/json'"
" http://rundeck:4441/api/26/projects"
f"curl -s {token} {api}/projects"
" | jq -e 'any(.[]; .name == \"test-project\")'"
)
'';

View File

@@ -1,148 +1,197 @@
{ lib, pkgs, ... }:
let
genNodeId =
name:
pkgs.runCommand "syncthing-test-certs-${name}" { } ''
mkdir -p $out
${pkgs.syncthing}/bin/syncthing generate --home=$out
${pkgs.libxml2}/bin/xmllint --xpath 'string(configuration/device/@id)' $out/config.xml > $out/id
'';
idA = genNodeId "a";
idB = genNodeId "b";
idC = genNodeId "c";
testPassword = "it's a secret";
in
{
name = "syncthing";
meta.maintainers = with pkgs.lib.maintainers; [ zarelit ];
nodeNames = [
"a"
"b"
"c"
];
nodeDirs = lib.genAttrs nodeNames (n: ./test-nodes + "/${n}");
nodeData = lib.mapAttrs (n: v: {
cert = "${v}/cert.pem";
key = "${v}/key.pem";
id = lib.fileContents (v + "/id");
}) nodeDirs;
nodes = {
a =
{ config, ... }:
{
environment.etc.bar-encryption-password.text = testPassword;
services.syncthing = {
enable = true;
openDefaultPorts = true;
cert = "${idA}/cert.pem";
key = "${idA}/key.pem";
guiAddress = "unix:///run/syncthing/syncthing.sock";
settings = {
devices.b.id = lib.fileContents "${idB}/id";
devices.c.id = lib.fileContents "${idC}/id";
folders.foo = {
path = "/var/lib/syncthing/foo";
devices = [ "b" ];
};
folders.bar = {
path = "/var/lib/syncthing/bar";
devices = [
{
name = "c";
encryptionPasswordFile = "/etc/${config.environment.etc.bar-encryption-password.target}";
}
];
};
folders.baz = {
path = "/var/lib/syncthing/baz";
devices = [
"b"
"c"
];
ignorePatterns = [ ];
};
folders."foo bar" = {
path = "/var/lib/syncthing/foo-bar";
devices = [
"b"
];
};
};
};
};
b =
{ config, ... }:
{
environment.etc.bar-encryption-password.text = testPassword;
services.syncthing = {
enable = true;
openDefaultPorts = true;
cert = "${idB}/cert.pem";
key = "${idB}/key.pem";
settings = {
devices.a.id = lib.fileContents "${idA}/id";
devices.c.id = lib.fileContents "${idC}/id";
folders.foo = {
path = "/var/lib/syncthing/foo";
devices = [ "a" ];
};
folders.bar = {
path = "/var/lib/syncthing/bar";
devices = [
{
name = "c";
encryptionPasswordFile = "/etc/${config.environment.etc.bar-encryption-password.target}";
}
];
};
folders.baz = {
path = "/var/lib/syncthing/baz";
devices = [
"a"
"c"
];
ignorePatterns = [
"notB"
];
};
# Test how we handle white spaces in folder IDs
folders."foo bar" = {
path = "/var/lib/syncthing/foo-bar";
devices = [
"a"
];
ignorePatterns = [
"notB"
# Just test that an apostrophe doesn't break the curl config
# commands. See: https://github.com/NixOS/nixpkgs/issues/554744
"apostrophe'"
];
};
};
};
};
c = {
services.syncthing = {
enable = true;
openDefaultPorts = true;
cert = "${idC}/cert.pem";
key = "${idC}/key.pem";
settings = {
devices.a.id = lib.fileContents "${idA}/id";
devices.b.id = lib.fileContents "${idB}/id";
folders.bar = {
path = "/var/lib/syncthing/bar";
devices = [
"a"
"b"
];
type = "receiveencrypted";
};
folders.baz = {
path = "/var/lib/syncthing/baz";
devices = [
"a"
"b"
];
ignorePatterns = [
"notC"
];
};
};
};
testPassword = "it's a secret";
commonNodeConfigModule = {
services.syncthing = {
enable = true;
openDefaultPorts = true;
settings.devices = lib.mapAttrs (n: v: { inherit (v) id; }) nodeData;
};
};
nodeConfigModules = {
a = {
services.syncthing = {
inherit (nodeData.a) cert key;
guiAddress = "unix:///run/syncthing/syncthing.sock";
};
};
b = {
services.syncthing = { inherit (nodeData.b) cert key; };
};
c = {
services.syncthing = { inherit (nodeData.c) cert key; };
};
};
nodeFolderConfigModules = [
# "foo" is a folder that is synchronised only between nodes a and b.
rec {
a = {
services.syncthing.settings.folders.foo = {
path = "/var/lib/syncthing/foo";
devices = [
"a"
"b"
];
};
};
b = a;
c = { };
}
# "bar" is synchronised between a and c, and between b and c, but c only
# gets an encrypted copy, and a and b never synchronise directly to each
# other.
rec {
a =
{ config, ... }:
{
environment.etc.bar-encryption-password.text = testPassword;
services.syncthing.settings.folders.bar = {
path = "/var/lib/syncthing/bar";
devices = [
{
name = "c";
encryptionPasswordFile = "/etc/${config.environment.etc.bar-encryption-password.target}";
}
];
};
};
b = a;
c = {
services.syncthing.settings.folders.bar = {
path = "/var/lib/syncthing/bar";
devices = [
"a"
"b"
];
type = "receiveencrypted";
};
};
}
# "baz" is synchronised between all three nodes, but has filters on b and c
# that mean they shouldn't receive certain files.
{
a = {
services.syncthing.settings.folders.baz = {
path = "/var/lib/syncthing/baz";
devices = [
"b"
"c"
];
ignorePatterns = [ ];
};
};
b = {
services.syncthing.settings.folders.baz = {
path = "/var/lib/syncthing/baz";
devices = [
"a"
"c"
];
ignorePatterns = [
"notB"
# Just test that an apostrophe doesn't break the curl config
# commands. See: https://github.com/NixOS/nixpkgs/issues/554744
"apostrophe'"
];
};
};
c = {
services.syncthing.settings.folders.baz = {
path = "/var/lib/syncthing/baz";
devices = [
"a"
"b"
];
ignorePatterns = [ "notC" ];
};
};
}
# "foo bar" tests handling whitespace in folder IDs.
{
a = {
services.syncthing.settings.folders."foo bar" = {
path = "/var/lib/syncthing/foo-bar";
devices = [ "b" ];
};
};
b = {
services.syncthing.settings.folders."foo bar" = {
path = "/var/lib/syncthing/foo-bar";
devices = [ "a" ];
ignorePatterns = [ "notB" ];
};
};
c = { };
}
];
in
{
name = "syncthing-folders";
meta.maintainers = with pkgs.lib.maintainers; [ zarelit ];
# Run from the root of the nixpkgs repository with
#
# nix-build -A nixosTests.syncthing-folders.genNodeData &&
# ./result/bin/genNodeData.sh
#
# This generates new keys, certificates, and overall Syncthing config, and
# updates the certificate and key files and the ID file extracted from the
# overall Syncthing config file.
passthru.genNodeData = pkgs.writeShellApplication {
name = "genNodeData.sh";
runtimeInputs = with pkgs; [
syncthing
libxml2
];
text = ''
rm -r nixos/tests/syncthing/test-nodes
mkdir nixos/tests/syncthing/test-nodes
cd nixos/tests/syncthing/test-nodes
for d in ${lib.escapeShellArgs nodeNames}; do
mkdir -- "$d"
syncthing generate --home="$d"
xmllint --xpath 'string(configuration/device/@id)' "$d"/config.xml >"$d"/id
rm -f -- "$d"/.syncthing.tmp.* "$d"/config.xml
done
'';
};
nodes = lib.genAttrs nodeNames (n: {
imports = [
commonNodeConfigModule
nodeConfigModules."${n}"
]
++ map (builtins.getAttr n) nodeFolderConfigModules;
});
testScript = ''
start_all()

View File

@@ -1,6 +1,6 @@
{ lib, pkgs, ... }:
{
name = "syncthing";
name = "syncthing-no-settings";
meta.maintainers = with pkgs.lib.maintainers; [ chkno ];
nodes = {

View File

@@ -0,0 +1,11 @@
-----BEGIN CERTIFICATE-----
MIIBoDCCAVKgAwIBAgIJAJ7l/z0JF6aOMAUGAytlcDBKMRIwEAYDVQQKEwlTeW5j
dGhpbmcxIDAeBgNVBAsTF0F1dG9tYXRpY2FsbHkgR2VuZXJhdGVkMRIwEAYDVQQD
EwlzeW5jdGhpbmcwHhcNMjYwNDAyMDAwMDAwWhcNNDYwMzI4MDAwMDAwWjBKMRIw
EAYDVQQKEwlTeW5jdGhpbmcxIDAeBgNVBAsTF0F1dG9tYXRpY2FsbHkgR2VuZXJh
dGVkMRIwEAYDVQQDEwlzeW5jdGhpbmcwKjAFBgMrZXADIQBCsJ1O6QrxxFP/YKKj
WAjdZp07AiTIIC0/p/mHGbmyraNVMFMwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQW
MBQGCCsGAQUFBwMBBggrBgEFBQcDAjAMBgNVHRMBAf8EAjAAMBQGA1UdEQQNMAuC
CXN5bmN0aGluZzAFBgMrZXADQQBqGFXpwvEoAc7N6mT9evXI3++STiTE6Lu3Z2z3
ecp5vU3fS5U+b0fO4BEUrNoaDdXurfOal6+LoydAnJcFamwN
-----END CERTIFICATE-----

View File

@@ -0,0 +1 @@
F2ACIUG-FML5RHY-ATV55ZN-5KGVUIV-RWFG3Y6-QPLTKZB-NWUZAGD-7QRCWAP

View File

@@ -0,0 +1,3 @@
-----BEGIN PRIVATE KEY-----
MC4CAQAwBQYDK2VwBCIEIE2ls259KcQgtizG7hwP3aBhlYBNuPJwSBG8d4uVBFOh
-----END PRIVATE KEY-----

View File

@@ -0,0 +1,11 @@
-----BEGIN CERTIFICATE-----
MIIBnzCCAVGgAwIBAgIIKyLKAcqLWn4wBQYDK2VwMEoxEjAQBgNVBAoTCVN5bmN0
aGluZzEgMB4GA1UECxMXQXV0b21hdGljYWxseSBHZW5lcmF0ZWQxEjAQBgNVBAMT
CXN5bmN0aGluZzAeFw0yNjA0MDIwMDAwMDBaFw00NjAzMjgwMDAwMDBaMEoxEjAQ
BgNVBAoTCVN5bmN0aGluZzEgMB4GA1UECxMXQXV0b21hdGljYWxseSBHZW5lcmF0
ZWQxEjAQBgNVBAMTCXN5bmN0aGluZzAqMAUGAytlcAMhABoahydRmwpbCII6mz9i
E8FeGH7YdHqgMeAmLiFZu2wMo1UwUzAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYw
FAYIKwYBBQUHAwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQCMAAwFAYDVR0RBA0wC4IJ
c3luY3RoaW5nMAUGAytlcANBADFVKB2vF16j0gc/h71x3vUi042FbmXTPk9kMb2O
9O0NnWSoMuOGPFDEoHWBFuUuixQ/3cw45zw+fea28m95gQo=
-----END CERTIFICATE-----

View File

@@ -0,0 +1 @@
LOB4D2H-OYG64QZ-NDX43LJ-NYR4HQU-BRNXCNI-ERACWFP-OVURLBI-63MR5QP

Some files were not shown because too many files have changed in this diff Show More