Compare commits

...

36 Commits

Author SHA1 Message Date
nixpkgs-ci[bot]
9c081a1eb6 Merge master into staging-nixos 2026-09-29 18:13:19 +00:00
Connor Baker
3a3470d694 cudaPackages.buildRedistHook: remove fixupPropagatedBuildOutputsForMultipleOutputs fix (#568318) 2026-09-29 17:48:43 +00:00
Marc Jakobi
4f2108965f luajit_openresty: add riscv64 support (#567986) 2026-09-29 17:46:24 +00:00
nixpkgs-ci[bot]
8c8166b43b wesnoth-devel: 1.19.24 -> 1.19.28 (#568190) 2026-09-29 17:21:32 +00:00
Jörg Thalheim
308a676716 nix-fast-build: 2.0.3 -> 2.0.4 (#568306) 2026-09-29 17:06:45 +00:00
misuzu
48bfc8e60a python3Packages.argos-translate-files: fix license (#568255) 2026-09-29 17:06:13 +00:00
dotlambda
66634b008d immich: 3.2.2 -> 3.2.4 (#567983) 2026-09-29 16:54:41 +00:00
Gaetan Lepage
65fe9eae2b cudaPackages.buildRedistHook: remove fixupPropagatedBuildOutputsForMultipleOutputs fix 2026-09-29 16:35:15 +00:00
Gaétan Lepage
0942ff1a32 vimPlugins.direnv-nvim: init at 0-unstable-2026-06-28 (#568313) 2026-09-29 16:28:53 +00:00
nixpkgs-ci[bot]
c60add55c1 deno: 2.9.6 -> 2.9.7 (#566848) 2026-09-29 16:27:22 +00:00
Marie Ramlow
72f14508e3 vimPlugins.direnv-nvim: init at 0-unstable-2026-06-28
https://github.com/NotAShelf/direnv.nvim
2026-09-29 18:12:23 +02:00
Gaetan Lepage
0c6fcccb3e nix-fast-build: 2.0.3 -> 2.0.4
Diff: https://github.com/Mic92/nix-fast-build/compare/2.0.3...2.0.4

Changelog: https://github.com/Mic92/nix-fast-build/releases/tag/2.0.4
2026-09-29 17:54:52 +02:00
AlexAntonik
f08680045c python3Packages.argos-translate-files: fix license
Signed-off-by: AlexAntonik <antonikavv@gmail.com>
2026-09-29 16:17:57 +03:00
nixpkgs-ci[bot]
11dac38567 Merge master into staging-nixos 2026-09-29 12:15:56 +00:00
Rafael Ieda
85981abf4a wesnoth-devel: 1.19.24 -> 1.19.28 2026-09-29 06:20:29 -03:00
nixpkgs-ci[bot]
975fc7be2c Merge master into staging-nixos 2026-09-29 06:17:28 +00:00
liberodark
ea8f81c9f4 luajit_openresty: fix luaAttr for the lua package set 2026-09-29 02:48:27 +02:00
nixpkgs-ci[bot]
2d10c403da Merge master into staging-nixos 2026-09-29 00:27:10 +00:00
liberodark
7c0bdd0e0b luajit: use luajit_openresty on riscv64 2026-09-29 02:23:15 +02:00
liberodark
a38c886f62 luajit_openresty: add riscv64 support 2026-09-29 02:23:01 +02:00
liberodark
b768821e77 luajit_openresty: 2.1-20260724 -> 2.1-20260824 2026-09-29 02:21:35 +02:00
nixpkgs-ci[bot]
42f8625814 libslirp: 4.9.3 -> 4.9.5 (#556763) 2026-09-28 19:34:24 +00:00
Robert Schütz
3e586911e3 immich: 3.2.2 -> 3.2.4
Diff: https://github.com/immich-app/immich/compare/v3.2.2...v3.2.4

Changelog: https://github.com/immich-app/immich/releases/tag/v3.2.4
2026-09-28 12:12:31 -07:00
nixpkgs-ci[bot]
b64bf322e6 Merge master into staging-nixos 2026-09-28 18:13:54 +00:00
LunNova
60cf12cd8b nixos/wrappers: enforce target executable is ELF (#567913) 2026-09-28 16:00:35 +00:00
Grimmauld
1be4b4866d nixos/wrappers: enforce target executable is ELF
This *will* break some things, such as `nixosTests.espanso`.
This is intended: Loading bash, python or perl scripts via SUID or extensive capabilities is dangerous.
PERL5LIB, PYTHONPATH or BASH_ENV make these things trivial LPE primitives.

The mime types being matched include both static, non-static and pie ELFs.
This should be fine until we somehow get yet another type of magic and associated mime type.
2026-09-28 17:32:15 +02:00
nixpkgs-ci[bot]
f8400c7fd3 Merge master into staging-nixos 2026-09-28 12:16:46 +00:00
Gaétan Lepage
10eda59563 ruff: 0.16.8 -> 0.16.9 (#566710) 2026-09-28 07:46:16 +00:00
nixpkgs-ci[bot]
66fbb71c65 Merge master into staging-nixos 2026-09-28 06:23:21 +00:00
K900
1b34b12008 nixos/rpcbind: declare rpc user unconditionally to break recursion (#540058) 2026-09-28 05:25:36 +00:00
nixpkgs-ci[bot]
d8af1c703b Merge master into staging-nixos 2026-09-28 00:29:32 +00:00
R. Ryantm
2601e5fc56 libslirp: 4.9.3 -> 4.9.5 2026-09-26 21:47:02 +00:00
R. Ryantm
32199a9e54 deno: 2.9.6 -> 2.9.7 2026-09-25 11:50:27 +00:00
Jost Alemann
6b47e6f6e4 ruff: 0.16.8 -> 0.16.9
Changelog: https://github.com/astral-sh/ruff/releases/tag/0.16.9
Diff: https://github.com/astral-sh/ruff/compare/0.16.8...0.16.9
2026-09-25 06:36:40 +02:00
Nikolaos Karaolidis
90c69965db nixos/rpcbind: drop with lib
Signed-off-by: Nikolaos Karaolidis <nick@karaolidis.com>
2026-09-13 12:53:40 +01:00
Nikolaos Karaolidis
c1b5f25b6b nixos/rpcbind: declare rpc user unconditionally to break recursion
rpcbind defined its rpc user inside config = mkIf cfg.enable {...}, making the presence of the rpc key in config.users.users depend on services.rpcbind.enable. Since users.users is an attrsOf submodule, reading one user's attribute forces the whole key set, forcing that guard, which nfs.nix derives from boot.supportedFilesystems <- config.fileSystems. A fileSystems entry referencing a user (home/uid/gid) therefore closed an infinite-recursion loop, i.e. you couldn't write fileSystems."${config.users.users.me.home}/data".

Fixes #24570.

Signed-off-by: Nikolaos Karaolidis <nick@karaolidis.com>
2026-09-13 12:53:40 +01:00
15 changed files with 141 additions and 70 deletions

View File

@@ -361,16 +361,19 @@ in
###### wrappers consistency checks
system.checks = lib.singleton (
pkgs.runCommandLocal "ensure-all-wrappers-paths-exist"
pkgs.runCommandLocal "ensure-wrapper-integrity"
{
nativeBuildInputs = [ pkgs.libcap-text-verifier ];
nativeBuildInputs = [
pkgs.libcap-text-verifier
pkgs.file
];
preferLocalBuild = true;
}
''
# make sure we produce output
mkdir -p $out
echo -n "Checking that Nix store paths of all wrapped programs exist... "
echo -n "Checking that Nix store paths of all wrapped programs exist and are ELF executables... "
${lib.toShellVar "wrappers" (lib.mapAttrs (n: v: v.source) wrappers)}
for name in "''${!wrappers[@]}"; do
path="''${wrappers[$name]}"
@@ -382,6 +385,15 @@ in
test -t 1 && echo -ne '\033[0m'
exit 1
fi
magic=$(file --mime --brief --dereference "$path")
if ! [[ "$magic" =~ application/x-executable || "$magic" =~ application/x-pie-executable ]]; then
test -t 1 && echo -ne '\033[1;31m'
echo "FAIL"
echo "The target executable $path is not an ELF! This is a security risk."
echo "Script wrappers (e.g. bash or python) are commonly susceptible to dangerous env var injections."
test -t 1 && echo -ne '\033[0m'
exit 1
fi
done
echo "OK"

View File

@@ -5,8 +5,6 @@
...
}:
with lib;
{
###### interface
@@ -15,8 +13,8 @@ with lib;
services.rpcbind = {
enable = mkOption {
type = types.bool;
enable = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
Whether to enable `rpcbind`, an ONC RPC directory service
@@ -32,29 +30,34 @@ with lib;
###### implementation
config = mkIf config.services.rpcbind.enable {
environment.systemPackages = [ pkgs.rpcbind ];
config = lib.mkMerge [
(lib.mkIf config.services.rpcbind.enable {
environment.systemPackages = [ pkgs.rpcbind ];
systemd.packages = [ pkgs.rpcbind ];
systemd.packages = [ pkgs.rpcbind ];
systemd.services.rpcbind = {
wantedBy = [ "multi-user.target" ];
# rpcbind performs a check for /var/run/rpcbind.lock at startup
# and will crash if /var/run isn't present. In the stock NixOS
# var.conf tmpfiles configuration file, /var/run is symlinked to
# /run, so rpcbind can enter a race condition in which /var/run
# isn't symlinked yet but tries to interact with the path, so
# controlling the order explicitly here ensures that rpcbind can
# start successfully. The `wants` instead of `requires` should
# avoid creating a strict/brittle dependency.
wants = [ "systemd-tmpfiles-setup.service" ];
after = [ "systemd-tmpfiles-setup.service" ];
};
systemd.services.rpcbind = {
wantedBy = [ "multi-user.target" ];
# rpcbind performs a check for /var/run/rpcbind.lock at startup
# and will crash if /var/run isn't present. In the stock NixOS
# var.conf tmpfiles configuration file, /var/run is symlinked to
# /run, so rpcbind can enter a race condition in which /var/run
# isn't symlinked yet but tries to interact with the path, so
# controlling the order explicitly here ensures that rpcbind can
# start successfully. The `wants` instead of `requires` should
# avoid creating a strict/brittle dependency.
wants = [ "systemd-tmpfiles-setup.service" ];
after = [ "systemd-tmpfiles-setup.service" ];
};
})
users.users.rpc = {
group = "nogroup";
uid = config.ids.uids.rpc;
};
};
{
users.users.rpc = {
enable = config.services.rpcbind.enable;
group = "nogroup";
uid = config.ids.uids.rpc;
};
}
];
}

View File

@@ -5334,6 +5334,20 @@ final: prev: {
meta.hydraPlatforms = [ ];
};
direnv-nvim = buildVimPlugin {
pname = "direnv.nvim";
version = "0-unstable-2026-06-28";
src = fetchFromGitHub {
owner = "NotAShelf";
repo = "direnv.nvim";
rev = "9258f9f10c4c729d8296fce0e3ecb12543daad06";
hash = "sha256-b5PpmkYWaDGLNcu+36tRR5ycATHYBjs9WrV8/jfmooQ=";
};
meta.homepage = "https://github.com/NotAShelf/direnv.nvim/";
meta.license = getLicenseFromSpdxId "MPL-2.0";
meta.hydraPlatforms = [ ];
};
direnv-vim = buildVimPlugin {
pname = "direnv.vim";
version = "0-unstable-2023-12-02";

View File

@@ -379,6 +379,7 @@ https://github.com/barrettruth/diffs.nvim/,,
https://github.com/dlyongemallo/diffview-plus.nvim/,,
https://github.com/sindrets/diffview.nvim/,,
https://github.com/elihunter173/dirbuf.nvim/,,
https://github.com/NotAShelf/direnv.nvim/,,
https://github.com/direnv/direnv.vim/,,
https://github.com/chipsenkbeil/distant.nvim/,,
https://github.com/doki-theme/doki-theme-vim/,,

View File

@@ -36,7 +36,7 @@ let
in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "deno";
version = "2.9.6";
version = "2.9.7";
__structuredAttrs = true;
@@ -51,10 +51,10 @@ rustPlatform.buildRustPackage (finalAttrs: {
repo = "deno";
tag = "v${finalAttrs.version}";
fetchSubmodules = true; # required for tests
hash = "sha256-4X7IfQk9NJizhZKqH2EuDnSfk8axkKFyiZEv1FOfWTM=";
hash = "sha256-GOhud8uXlsDdyAN84WscakxK2qCFTEYSUwR5Wt2QPAs=";
};
cargoHash = "sha256-EKRC+wqIos9O0GHaxjmb/ghyzV6oCi1qwhO2tjszWR4=";
cargoHash = "sha256-VSWkdTJiSX8O3+Kpu7RKnydxB3OcbwG9+NJCvLdFl68=";
patches = [
./patches/0002-tests-replace-hardcoded-paths.patch

View File

@@ -110,7 +110,7 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "immich";
version = "3.2.2";
version = "3.2.4";
__structuredAttrs = true;
strictDeps = true;
@@ -119,7 +119,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "immich-app";
repo = "immich";
tag = "v${finalAttrs.version}";
hash = "sha256-napG+EMZbbbeq7R8FtnuDsDwdpxItkwTVWztnw07DfA=";
hash = "sha256-/wWep6A/ryocuGMOElcD1lOEwT6tJDdwa5HAcCZUXSs=";
};
pnpmDeps = fetchPnpmDeps {

View File

@@ -10,14 +10,14 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libslirp";
version = "4.9.3";
version = "4.9.5";
src = fetchFromGitLab {
domain = "gitlab.freedesktop.org";
owner = "slirp";
repo = "libslirp";
tag = "v${finalAttrs.version}";
hash = "sha256-Spr3dO5ehuUlzx3EnJi8najANWOirwQcTsWTVRVXYuY=";
hash = "sha256-iWu3/Klsm8e9MH147BJhn9Vqyneq5ROqPvll1cnieL0=";
};
separateDebugInfo = true;

View File

@@ -9,7 +9,7 @@
python3Packages.buildPythonApplication (finalAttrs: {
pname = "nix-fast-build";
version = "2.0.3";
version = "2.0.4";
pyproject = true;
__structuredAttrs = true;
@@ -17,7 +17,7 @@ python3Packages.buildPythonApplication (finalAttrs: {
owner = "Mic92";
repo = "nix-fast-build";
tag = finalAttrs.version;
hash = "sha256-L4HfADUq4Imq1LnvmjBPFBEAZAIKD9Pnj6ExRkVqHC4=";
hash = "sha256-sc/NZIHkRhgyAzK8Xn6G++vGrl/Uf7QHh+J5fnZ/o4s=";
};
build-system = [ python3Packages.setuptools ];

View File

@@ -16,7 +16,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "ruff";
version = "0.16.8";
version = "0.16.9";
__structuredAttrs = true;
@@ -24,12 +24,12 @@ rustPlatform.buildRustPackage (finalAttrs: {
owner = "astral-sh";
repo = "ruff";
tag = finalAttrs.version;
hash = "sha256-vfyEulokZqx5VyQA3jlKhQhgr/flLIGHcgC7CeegGl0=";
hash = "sha256-gxQXIlle9LGs1HcPiJn7KW0p21xsr62/FGypyqEfnSI=";
};
cargoBuildFlags = [ "--package=ruff" ];
cargoHash = "sha256-aX9Vu1egtvloe9dspXHR0Amc0mEuWG67EAOQU2b3oM0=";
cargoHash = "sha256-5ZolzeBEj6dolhObhWS/jMyB7KJPRSIbN0+zcG+0AGY=";
nativeBuildInputs = [ installShellFiles ];

View File

@@ -10,6 +10,9 @@
SDL2_net,
makeBinaryWrapper,
SDL2_ttf,
sdl3,
sdl3-image,
sdl3-mixer,
pango,
gettext,
boost186,
@@ -22,12 +25,30 @@
lua5_4,
curl,
nix-update-script,
versionCheckHook,
enableDevel ? false,
}:
let
boost = boost186;
suffix = lib.optionalString enableDevel "-devel";
sdl =
if enableDevel then
[
sdl3
sdl3-image
sdl3-mixer
]
else
[
SDL2
SDL2_image
SDL2_mixer
SDL2_net
SDL2_ttf
];
# wesnoth requires lua built with c++, see https://github.com/wesnoth/wesnoth/pull/8234
lua = lua5_4.override {
postConfigure = ''
@@ -38,7 +59,7 @@ in
stdenv.mkDerivation (finalAttrs: {
pname = "wesnoth${suffix}";
version = if enableDevel then "1.19.24" else "1.18.8";
version = if enableDevel then "1.19.28" else "1.18.8";
src = fetchFromGitHub {
owner = "wesnoth";
@@ -46,11 +67,17 @@ stdenv.mkDerivation (finalAttrs: {
tag = finalAttrs.version;
hash =
if enableDevel then
"sha256-q6gdzHDPkG/RqpJxIHqWsxD0n8dzKajDhAT49bjmq78="
"sha256-5S2kgqn+HZIPguQP+FYaK79Cvx0IRnmcGSeWPQflt/g="
else
"sha256-Tgp3y120j5nqoBrDo7D9C0FcVO3TH5lf+/SoCjR+ikc=";
};
strictDeps = true;
doInstallCheck = true;
nativeInstallCheckInputs = [ versionCheckHook ];
versionCheckProgram = "${placeholder "out"}/bin/wesnothd${suffix}";
nativeBuildInputs = [
cmake
pkg-config
@@ -58,11 +85,6 @@ stdenv.mkDerivation (finalAttrs: {
++ lib.optionals stdenv.hostPlatform.isDarwin [ makeBinaryWrapper ];
buildInputs = [
SDL2
SDL2_image
SDL2_mixer
SDL2_net
SDL2_ttf
pango
gettext
boost
@@ -74,7 +96,8 @@ stdenv.mkDerivation (finalAttrs: {
icu
lua
curl
];
]
++ sdl;
cmakeFlags = [
(lib.cmakeBool "ENABLE_SYSTEM_LUA" true)

View File

@@ -24,9 +24,6 @@ buildRedistHookRegistration() {
postInstallCheckHooks+=(checkCudaNonEmptyOutputs)
nixLog "added checkCudaNonEmptyOutputs to postInstallCheckHooks"
preFixupHooks+=(fixupPropagatedBuildOutputsForMultipleOutputs)
nixLog "added fixupPropagatedBuildOutputsForMultipleOutputs to preFixupHooks"
postFixupHooks+=(fixupCudaPropagatedBuildOutputsToOut)
nixLog "added fixupCudaPropagatedBuildOutputsToOut to postFixupHooks"
@@ -193,16 +190,6 @@ checkCudaHasStubsIffIncludeRemoveStubsFromRunpathHook() {
return 0
}
# TODO(@connorbaker): https://github.com/NixOS/nixpkgs/issues/323126.
# _multioutPropagateDev() currently expects a space-separated string rather than an array.
# NOTE: Because _multioutPropagateDev is a postFixup hook, we correct it in preFixup.
fixupPropagatedBuildOutputsForMultipleOutputs() {
nixLog "converting propagatedBuildOutputs to a space-separated string"
# shellcheck disable=SC2124
export propagatedBuildOutputs="${propagatedBuildOutputs[@]}"
return 0
}
# The multiple outputs setup hook only propagates build outputs to dev.
# We want to propagate them to out as well, in case the user interpolates
# the package into a string -- in such a case, the dev output is not selected
@@ -217,7 +204,7 @@ fixupCudaPropagatedBuildOutputsToOut() {
mkdir -p "${out:?}/nix-support"
# NOTE: We must use printWords to ensure the output is a single line.
for output in $propagatedBuildOutputs; do
for output in "${propagatedBuildOutputs[@]}"; do
# Propagate the other components to the out output
nixLog "adding ${!output:?} to propagatedBuildInputs of ${out:?}"
printWords "${!output:?}" >>"${out:?}/nix-support/propagated-build-inputs"

View File

@@ -4,6 +4,8 @@
lib,
callPackage,
fetchFromGitHub,
fetchpatch2,
applyPatches,
makeBinaryWrapper,
}:
@@ -199,6 +201,13 @@ rec {
luajit_openresty = import ../luajit/openresty.nix {
self = luajit_openresty;
inherit callPackage fetchFromGitHub passthruFun;
inherit
callPackage
fetchFromGitHub
fetchpatch2
applyPatches
stdenv
passthruFun
;
};
}

View File

@@ -2,23 +2,45 @@
self,
callPackage,
fetchFromGitHub,
fetchpatch2,
applyPatches,
stdenv,
passthruFun,
}:
callPackage ./default.nix rec {
version = "2.1-20260724";
let
version = "2.1-20260824";
src = fetchFromGitHub {
owner = "openresty";
repo = "luajit2";
rev = "v${version}";
hash = "sha256-cvy9FgHWFuacCFl7/conLwNuMgaol1LnIUiqcnXy9H8=";
tag = "v${version}";
hash = "sha256-IynlDQOyjCr1C3qibLg3OJ9Qd/Rb5jzjy30ETKdKvFM=";
};
# upstream LuaJIT has no riscv64.
# port submitted at https://github.com/openresty/luajit2/pull/236 same as Debian
srcWithRiscv64Port = applyPatches {
inherit src;
patches = [
(fetchpatch2 {
url = "https://github.com/openresty/luajit2/compare/v2.1-20260824...ce14aff834d8d62220fc730a16042c52451f41cc.diff";
hash = "sha256-VHDTUr7PWpthmhO3BokCbdL1cricAnX6BjZGTi1wr3Q=";
})
];
};
in
callPackage ./default.nix {
inherit version;
# default luaAttr would be luajit_2_1, the wrong interpreter for the lua package set
luaAttr = "luajit_openresty";
src = if stdenv.hostPlatform.isRiscV64 then srcWithRiscv64Port else src;
extraMeta = {
badPlatforms = [
"loongarch64-linux" # See https://github.com/LuaJIT/LuaJIT/issues/1278
"riscv64-linux" # See https://github.com/LuaJIT/LuaJIT/issues/628
# 64-bit POWER (LE and BE, either ELF ABI version on the latter) *is* supported, but ELFv1 powerpc64-linux has an
# issue with memory allocation
# https://github.com/openresty/luajit2/issues/258

View File

@@ -62,7 +62,7 @@ buildPythonPackage (finalAttrs: {
meta = {
description = "Translate files using Argos Translate";
homepage = "https://www.argosopentech.com";
license = lib.licenses.mit;
license = lib.licenses.agpl3Only;
maintainers = with lib.maintainers; [ misuzu ];
};
})

View File

@@ -4395,7 +4395,7 @@ with pkgs;
luaPackages = lua52Packages;
luajit = luajit_2_1;
luajit = if stdenv.hostPlatform.isRiscV64 then luajit_openresty else luajit_2_1;
luarocks = luaPackages.luarocks;
luarocks-nix = luaPackages.luarocks-nix;