mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-07-22 16:41:08 +00:00
Compare commits
767 Commits
nixpkgs-un
...
python-upd
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
49233162d6 | ||
|
|
8d040b1444 | ||
|
|
97913a3458 | ||
|
|
275f91ca1a | ||
|
|
e63b4d964a | ||
|
|
f4a8de6d8f | ||
|
|
9b29620658 | ||
|
|
8e2a675d8a | ||
|
|
3c1cb4721b | ||
|
|
b99ab211db | ||
|
|
16ceb917c7 | ||
|
|
e53ce32d8b | ||
|
|
1719162d82 | ||
|
|
a4cb2a936f | ||
|
|
66aab15e2d | ||
|
|
2ac7325c92 | ||
|
|
1e690d63d6 | ||
|
|
3df278795e | ||
|
|
b41d6b8723 | ||
|
|
934118b04a | ||
|
|
adbf39fe2a | ||
|
|
5f8a3d3cfa | ||
|
|
6214bad005 | ||
|
|
f6730c976a | ||
|
|
5452ef2f30 | ||
|
|
0cd71c5451 | ||
|
|
a8d1537873 | ||
|
|
7f225f2eed | ||
|
|
9694d18e84 | ||
|
|
441a2bb609 | ||
|
|
30e115e64e | ||
|
|
b2aa5ba615 | ||
|
|
471df6a509 | ||
|
|
6029273d3b | ||
|
|
638d68d5a5 | ||
|
|
5c10f4aa27 | ||
|
|
6ac2df8f6e | ||
|
|
945270e826 | ||
|
|
eb94779507 | ||
|
|
c931704246 | ||
|
|
8716c6e323 | ||
|
|
4fcd1ced68 | ||
|
|
ac60a9e360 | ||
|
|
0084934a15 | ||
|
|
96e85f3113 | ||
|
|
b1e4cc5d5d | ||
|
|
82fcdfd0ed | ||
|
|
d0df1312b7 | ||
|
|
99577502f3 | ||
|
|
e6891530cb | ||
|
|
e355d4f5c8 | ||
|
|
5e287811bc | ||
|
|
f3758ad44b | ||
|
|
3c9cf64035 | ||
|
|
0fef0ae6d5 | ||
|
|
6305d59f7c | ||
|
|
5c915e98e1 | ||
|
|
f72db6bf68 | ||
|
|
183931a1cf | ||
|
|
032cfaf859 | ||
|
|
3099bd3f22 | ||
|
|
260901e23f | ||
|
|
4a69532a6a | ||
|
|
c59b05508f | ||
|
|
2f27e7cf49 | ||
|
|
daa95195dd | ||
|
|
e3cc9a21be | ||
|
|
a1004378f3 | ||
|
|
29a8467310 | ||
|
|
bdf0a1733e | ||
|
|
087259bf03 | ||
|
|
9fb21b00b3 | ||
|
|
1d9a30906e | ||
|
|
913358ad67 | ||
|
|
8be19173ac | ||
|
|
fea45e5e9d | ||
|
|
414804f09c | ||
|
|
b724b726ed | ||
|
|
f8046a7640 | ||
|
|
1617865302 | ||
|
|
f280d9d1cd | ||
|
|
3bae8e878b | ||
|
|
129b1367f8 | ||
|
|
062e14e2f9 | ||
|
|
8634347d56 | ||
|
|
05a5c121eb | ||
|
|
e5ffb383ad | ||
|
|
31280770c2 | ||
|
|
18a55b8b13 | ||
|
|
1aeafa7c2a | ||
|
|
97ee6f39d2 | ||
|
|
e1a93c635e | ||
|
|
f2c7688610 | ||
|
|
fdff3b6d4d | ||
|
|
27e116834f | ||
|
|
fd69fdf179 | ||
|
|
f255048fff | ||
|
|
4db081fc19 | ||
|
|
bf61433489 | ||
|
|
59e265f076 | ||
|
|
ff01b0ce8f | ||
|
|
a1a9610557 | ||
|
|
7a3a6fbe55 | ||
|
|
78e52eaa11 | ||
|
|
c3f499a147 | ||
|
|
4c8fd327c8 | ||
|
|
6dfafd45f1 | ||
|
|
3ac558ba01 | ||
|
|
7dea139c94 | ||
|
|
d4d92c3e4e | ||
|
|
d5625ae386 | ||
|
|
f4ef9ca361 | ||
|
|
c39085348a | ||
|
|
eb7bf502a4 | ||
|
|
1ab5df5a17 | ||
|
|
ff412bb903 | ||
|
|
f912b7dbae | ||
|
|
9a0e9275e1 | ||
|
|
c25423f923 | ||
|
|
83d09388b7 | ||
|
|
45f05953c9 | ||
|
|
eed26fc194 | ||
|
|
3584432b67 | ||
|
|
e8406537df | ||
|
|
d0009d11b7 | ||
|
|
6e0998bb4e | ||
|
|
87c268fc45 | ||
|
|
365e5afe04 | ||
|
|
1b85c31bee | ||
|
|
be8b0dcb21 | ||
|
|
d82a5ed8a6 | ||
|
|
3b7959dde1 | ||
|
|
49db97d68e | ||
|
|
399698a71d | ||
|
|
c180da6ef4 | ||
|
|
e6b4355be9 | ||
|
|
70d3fbbf13 | ||
|
|
5c3b5092c3 | ||
|
|
639ae4bbed | ||
|
|
ab91d20a3f | ||
|
|
33a66960bf | ||
|
|
4ae3f9e414 | ||
|
|
8e5758bfd8 | ||
|
|
1a3743bb01 | ||
|
|
fbc0ee9a4a | ||
|
|
1553d3f053 | ||
|
|
26fbafc2e0 | ||
|
|
7bea3e0117 | ||
|
|
c63f8c3fba | ||
|
|
d7ff4a66cb | ||
|
|
b884e4d9e1 | ||
|
|
5e77eb9e8c | ||
|
|
f8b4066712 | ||
|
|
d5622e4aef | ||
|
|
f4d6b45e70 | ||
|
|
16d16ffaa4 | ||
|
|
c7bf188dd1 | ||
|
|
c5707a1404 | ||
|
|
65c5a6dac2 | ||
|
|
e5b95b099e | ||
|
|
f3b474941c | ||
|
|
0fa0f446a0 | ||
|
|
800fcf581f | ||
|
|
888be46e0c | ||
|
|
2570484320 | ||
|
|
3bc2fe7a82 | ||
|
|
6f5550a62f | ||
|
|
eb12f6fa9d | ||
|
|
17749f1b0c | ||
|
|
a1cf8c2c2b | ||
|
|
d1b1476ff9 | ||
|
|
5597b685ed | ||
|
|
b80687fa42 | ||
|
|
5300c0dff9 | ||
|
|
cff500b2e9 | ||
|
|
2193364af5 | ||
|
|
d090076291 | ||
|
|
445c41eb98 | ||
|
|
6cfc5963a4 | ||
|
|
352c949523 | ||
|
|
b535dcab38 | ||
|
|
7a8213f821 | ||
|
|
aafa42d435 | ||
|
|
446ce057f7 | ||
|
|
595830ce19 | ||
|
|
a5f0b8e102 | ||
|
|
549010907c | ||
|
|
044a30626e | ||
|
|
d6260de378 | ||
|
|
c5fb3802aa | ||
|
|
9db553de22 | ||
|
|
9fdea88be8 | ||
|
|
7f9efc3f8d | ||
|
|
81e0ccd699 | ||
|
|
870f81ae6d | ||
|
|
b9124d07fa | ||
|
|
6900a124d9 | ||
|
|
69745b3092 | ||
|
|
cad7f57ac3 | ||
|
|
287173ee8b | ||
|
|
2ca11409ea | ||
|
|
5fc427e664 | ||
|
|
953bc491e5 | ||
|
|
2bd3200bbc | ||
|
|
bff1f2f8a4 | ||
|
|
8f5a762c16 | ||
|
|
a07bb7f59d | ||
|
|
5fde7450ea | ||
|
|
0e01138454 | ||
|
|
279d557d56 | ||
|
|
c02cec4fdb | ||
|
|
9e1be8d8a9 | ||
|
|
abbd981247 | ||
|
|
3adee824b2 | ||
|
|
94e8ddc11b | ||
|
|
3b388808ec | ||
|
|
7fdd7a0a43 | ||
|
|
fd6525fe22 | ||
|
|
ae050500c1 | ||
|
|
a9ad64d20d | ||
|
|
d5ca3483a1 | ||
|
|
8fc3e41843 | ||
|
|
0a85a6492c | ||
|
|
37980b0853 | ||
|
|
d500778e43 | ||
|
|
405945874a | ||
|
|
bec0bc967a | ||
|
|
62ea94c201 | ||
|
|
7b4a9f3904 | ||
|
|
eb937eca77 | ||
|
|
01dbc3ec9b | ||
|
|
e8a32a1aa0 | ||
|
|
0dc1e39e1b | ||
|
|
059ed5a40c | ||
|
|
f6db60842c | ||
|
|
00f4abe087 | ||
|
|
ecd8f32bcd | ||
|
|
46bfe83cc1 | ||
|
|
427f83bc1b | ||
|
|
d75a3fa17d | ||
|
|
7b607fe865 | ||
|
|
b825552128 | ||
|
|
32d47ec38b | ||
|
|
9183b77c29 | ||
|
|
ff3f2270db | ||
|
|
b64e13cf97 | ||
|
|
7cdd4e1ae4 | ||
|
|
2d5bca4cdf | ||
|
|
7601ab6805 | ||
|
|
6ee364839b | ||
|
|
d7069577cd | ||
|
|
e84a374a8f | ||
|
|
59e6f2bdee | ||
|
|
852f189b34 | ||
|
|
5ef7f171a3 | ||
|
|
2ca3d7c2a4 | ||
|
|
1a3cfcf0d5 | ||
|
|
31b1ff3caa | ||
|
|
e122fee939 | ||
|
|
eea0997336 | ||
|
|
4169bd4063 | ||
|
|
a83d51c090 | ||
|
|
f93d88c669 | ||
|
|
4c3441695b | ||
|
|
179cf95b7f | ||
|
|
d50e412820 | ||
|
|
12861f9d1a | ||
|
|
fad84e9e63 | ||
|
|
bdf4e6eb22 | ||
|
|
89a064cb9f | ||
|
|
f13e65b178 | ||
|
|
23c6c7a44e | ||
|
|
b9f721365c | ||
|
|
8ff3c728ac | ||
|
|
2721ed0cd7 | ||
|
|
0c096610cd | ||
|
|
869aa0441e | ||
|
|
49dd1c8b21 | ||
|
|
bc21b349f4 | ||
|
|
62a0b7a2c5 | ||
|
|
a4c734219b | ||
|
|
0edbb73c37 | ||
|
|
2217bb11c4 | ||
|
|
86d506c6f4 | ||
|
|
0088e3ccaa | ||
|
|
de7a47fbf9 | ||
|
|
196c4e88db | ||
|
|
5472decf44 | ||
|
|
98c95806a0 | ||
|
|
83a0bb7cea | ||
|
|
8f148d93f6 | ||
|
|
96f8f609c4 | ||
|
|
ce64f07dd2 | ||
|
|
60f84450ab | ||
|
|
d3291efa1c | ||
|
|
ef130ba3c3 | ||
|
|
f97c842f38 | ||
|
|
a27367ce58 | ||
|
|
a9b7ff9f68 | ||
|
|
a0f770b1e0 | ||
|
|
20160a6d5c | ||
|
|
0473ed3fb0 | ||
|
|
3f606b755e | ||
|
|
44e6d12e3c | ||
|
|
b7084b6128 | ||
|
|
4e42583459 | ||
|
|
9aa9153c4a | ||
|
|
c45ba81144 | ||
|
|
a4b4576c67 | ||
|
|
3b4518e8a2 | ||
|
|
526efa52e2 | ||
|
|
587b72ad3e | ||
|
|
36b0eb0dca | ||
|
|
c7eab28550 | ||
|
|
187095757b | ||
|
|
efb3726b52 | ||
|
|
c8a5d64e0e | ||
|
|
023d279213 | ||
|
|
ce689d6a4d | ||
|
|
59ae93215f | ||
|
|
5a147b95c6 | ||
|
|
fe8a2e36c3 | ||
|
|
d3b1a00a33 | ||
|
|
fa57ef5bd3 | ||
|
|
7b1cb1ff89 | ||
|
|
3b4d9199ed | ||
|
|
1ad21ce2a7 | ||
|
|
8e0a391de6 | ||
|
|
4bf23e1e86 | ||
|
|
860a66f2d5 | ||
|
|
4c5e19c3be | ||
|
|
6b87ca95d4 | ||
|
|
449ea564cd | ||
|
|
243cd8239c | ||
|
|
6304b10b43 | ||
|
|
ab2c12891d | ||
|
|
e4903f0456 | ||
|
|
747f448ad1 | ||
|
|
649daf9a5e | ||
|
|
218994223a | ||
|
|
f7ef479aef | ||
|
|
6cbdc11793 | ||
|
|
9a3c020d18 | ||
|
|
fbf6873ec8 | ||
|
|
967e3c2164 | ||
|
|
bb507abce1 | ||
|
|
2078e14914 | ||
|
|
2a0fe99286 | ||
|
|
94ff2f02a4 | ||
|
|
7d44dc49ab | ||
|
|
05180ba482 | ||
|
|
b01149720f | ||
|
|
ef2d4cd63a | ||
|
|
a187cae4ae | ||
|
|
f86c4d8b29 | ||
|
|
d0e90fac00 | ||
|
|
85ea91b158 | ||
|
|
fcd9d5b20b | ||
|
|
4e26cb7489 | ||
|
|
b74f0ab33c | ||
|
|
e45f55ed67 | ||
|
|
bed497736d | ||
|
|
b1c249ab19 | ||
|
|
3433cdf533 | ||
|
|
5e54e68ffe | ||
|
|
56bb2cc56a | ||
|
|
c02559f1f0 | ||
|
|
c181c999d9 | ||
|
|
5e53adb250 | ||
|
|
05aec69820 | ||
|
|
1c231e4ab1 | ||
|
|
eb0dbe6935 | ||
|
|
54eb644221 | ||
|
|
0f9a3c53a3 | ||
|
|
282593c507 | ||
|
|
790756f505 | ||
|
|
95b1a21908 | ||
|
|
b249ced44a | ||
|
|
1488f541dc | ||
|
|
c282797b16 | ||
|
|
5fdb3bc2f4 | ||
|
|
b96ed4d602 | ||
|
|
1d05796574 | ||
|
|
8a597f5ae6 | ||
|
|
5d0c21d222 | ||
|
|
bdd297d0ff | ||
|
|
8fe06cd8ba | ||
|
|
c8ce539c62 | ||
|
|
ac819cafd0 | ||
|
|
c2191b114b | ||
|
|
b5b4b56795 | ||
|
|
6b7ce51244 | ||
|
|
d3ef1479a9 | ||
|
|
5bffa343a1 | ||
|
|
c1f7c0ec1d | ||
|
|
49abeb2ebc | ||
|
|
b71eecfbbe | ||
|
|
2b69b6b928 | ||
|
|
fdf6502eb3 | ||
|
|
ad865d0009 | ||
|
|
eca8a86b7a | ||
|
|
6e22635a6f | ||
|
|
0eb9fc4c11 | ||
|
|
2a5eb18dbf | ||
|
|
e68c39840e | ||
|
|
b0b09e5b61 | ||
|
|
84d051dfe8 | ||
|
|
ecdd169da0 | ||
|
|
2b92585264 | ||
|
|
b0b1fcd402 | ||
|
|
672778a273 | ||
|
|
b076d257c0 | ||
|
|
dbe230e5f7 | ||
|
|
38f72584a7 | ||
|
|
10f52e1ff0 | ||
|
|
4d1475e1ce | ||
|
|
dc3e183262 | ||
|
|
1297b0e3ea | ||
|
|
4cf7f131b7 | ||
|
|
dc9b2d36d5 | ||
|
|
f43e09c13b | ||
|
|
6dd6e9ec1a | ||
|
|
38af1bb8e4 | ||
|
|
576e53b263 | ||
|
|
5c560639cc | ||
|
|
09ffbef1de | ||
|
|
cb157f07f9 | ||
|
|
842f062743 | ||
|
|
2248791fc5 | ||
|
|
3ba12cd3e4 | ||
|
|
6552955c76 | ||
|
|
e5a478dc03 | ||
|
|
75395c0592 | ||
|
|
6f4a56db8e | ||
|
|
4f5c0a4447 | ||
|
|
2736b2e922 | ||
|
|
d4b703e784 | ||
|
|
34af3065e5 | ||
|
|
46488a9344 | ||
|
|
7c0a098ada | ||
|
|
5c418480fb | ||
|
|
ba7c0447e4 | ||
|
|
715961232d | ||
|
|
b99e56874c | ||
|
|
84b47fef2f | ||
|
|
d4856b14c2 | ||
|
|
64c320b8d2 | ||
|
|
efa4c69a95 | ||
|
|
5acdac6455 | ||
|
|
5c2746b34c | ||
|
|
7991a73099 | ||
|
|
694bc89ebc | ||
|
|
be1222f4f6 | ||
|
|
e1b40f5381 | ||
|
|
00766a5d4f | ||
|
|
691f9d4a8a | ||
|
|
8ca5e47471 | ||
|
|
1f07ef191f | ||
|
|
5f2bcd2a01 | ||
|
|
a8ea58d366 | ||
|
|
61ac5736f4 | ||
|
|
a372dc5edb | ||
|
|
b29ec61921 | ||
|
|
e6bf6e9fdc | ||
|
|
434bdf3e31 | ||
|
|
a3d3227668 | ||
|
|
16294a2525 | ||
|
|
152201b5f8 | ||
|
|
6d8fcd0ed4 | ||
|
|
db5d42a1fb | ||
|
|
f6229cee1b | ||
|
|
40abd3e2cb | ||
|
|
34f55ec38c | ||
|
|
d8f24a5dd0 | ||
|
|
00278dcc75 | ||
|
|
4ec747bd48 | ||
|
|
388a73241c | ||
|
|
0763df0110 | ||
|
|
cc89337b56 | ||
|
|
fe92563706 | ||
|
|
12efcad243 | ||
|
|
4bc8a3b4ac | ||
|
|
66086b79ba | ||
|
|
94d27db015 | ||
|
|
2538c000a6 | ||
|
|
3a4ada4f4d | ||
|
|
f0c9c59635 | ||
|
|
a55f8f39bf | ||
|
|
a16de1dccf | ||
|
|
5f0ee84259 | ||
|
|
fb290d5d24 | ||
|
|
9650af3a29 | ||
|
|
b973eed9ea | ||
|
|
c2e63d6bcb | ||
|
|
889ea4c031 | ||
|
|
978b351bf7 | ||
|
|
72dcf41a6f | ||
|
|
528e62cee4 | ||
|
|
f4b20637d7 | ||
|
|
fd360c4429 | ||
|
|
701ebd45f1 | ||
|
|
f121b630ae | ||
|
|
2a50b443b5 | ||
|
|
20f348252a | ||
|
|
ab4ae03bc7 | ||
|
|
0fdd6cabaa | ||
|
|
ac36e0ac03 | ||
|
|
9f1baceb91 | ||
|
|
8121751fd4 | ||
|
|
3f0f7cef47 | ||
|
|
a1c6e43548 | ||
|
|
38911fbe61 | ||
|
|
51adff44f6 | ||
|
|
757cb598d7 | ||
|
|
d7951b35db | ||
|
|
b5e21ce95d | ||
|
|
bb997bc7d7 | ||
|
|
1995f3e0bb | ||
|
|
2bb7a68648 | ||
|
|
52573cc0e7 | ||
|
|
4087f5d72d | ||
|
|
9e255a89dd | ||
|
|
eb8b88ae6b | ||
|
|
596866e0a8 | ||
|
|
0130888692 | ||
|
|
46bac7fdab | ||
|
|
6c3967b670 | ||
|
|
c9cf113518 | ||
|
|
a4c7bb7c2d | ||
|
|
ca7c1b884a | ||
|
|
70feff9540 | ||
|
|
20382e39ad | ||
|
|
d43850d6ed | ||
|
|
b21d0c8739 | ||
|
|
0ab3722264 | ||
|
|
6ac3a34121 | ||
|
|
b72cbb85d8 | ||
|
|
4752f97962 | ||
|
|
006c7936a2 | ||
|
|
02be72a9e5 | ||
|
|
33db82a7fb | ||
|
|
ddab585265 | ||
|
|
ab52c90582 | ||
|
|
58fccdd72d | ||
|
|
efa0af5a81 | ||
|
|
e64d912def | ||
|
|
13b1951166 | ||
|
|
d07523fb0f | ||
|
|
7350dc17b2 | ||
|
|
338d7b777a | ||
|
|
5285fba241 | ||
|
|
bf0b785901 | ||
|
|
1e7d467566 | ||
|
|
41c8b60446 | ||
|
|
b989afae40 | ||
|
|
6f45cf3b46 | ||
|
|
97b993b6de | ||
|
|
eb8d97ca2d | ||
|
|
2460cec5c9 | ||
|
|
4fca7cee9b | ||
|
|
0dafa129ec | ||
|
|
75344375d5 | ||
|
|
d7e253a814 | ||
|
|
8f026f4d4f | ||
|
|
46ab45db9e | ||
|
|
d1e40d5bca | ||
|
|
03b8f6d6d2 | ||
|
|
0e60258826 | ||
|
|
8e7420ee4a | ||
|
|
172a7c1da7 | ||
|
|
0a09558e36 | ||
|
|
4f9c25ce13 | ||
|
|
b7511a628d | ||
|
|
1eb5929281 | ||
|
|
26317899f1 | ||
|
|
82c2d18f05 | ||
|
|
47f7109d73 | ||
|
|
e923a383a2 | ||
|
|
af10cefe2e | ||
|
|
c9bccd97ca | ||
|
|
efc0e2338c | ||
|
|
b699a21608 | ||
|
|
22ab7ac180 | ||
|
|
40d7bc5a60 | ||
|
|
0c409ea618 | ||
|
|
1b2bc271ce | ||
|
|
3ef896f1e6 | ||
|
|
79d1bc837b | ||
|
|
dc3fc077f4 | ||
|
|
4d9499f3a3 | ||
|
|
f8219af848 | ||
|
|
f5332861db | ||
|
|
154f4693b9 | ||
|
|
47331eb8bb | ||
|
|
bd08be1bd2 | ||
|
|
6f7345c8a6 | ||
|
|
3ab262f723 | ||
|
|
a2904ce42c | ||
|
|
206fd6070d | ||
|
|
ff663716f7 | ||
|
|
3cddb329e8 | ||
|
|
c4b827fa89 | ||
|
|
16b27381f0 | ||
|
|
19fef913d7 | ||
|
|
d15b45bb33 | ||
|
|
b70af925f2 | ||
|
|
d857df2041 | ||
|
|
c4e2dc82fa | ||
|
|
74ebbfaf0b | ||
|
|
a6735426ca | ||
|
|
18f68151ec | ||
|
|
cea24fefd1 | ||
|
|
9fb8d43cff | ||
|
|
15e6b0bad9 | ||
|
|
f30659ca7c | ||
|
|
17e6e533cc | ||
|
|
8746d3caee | ||
|
|
8ad0c2a646 | ||
|
|
b90a446f81 | ||
|
|
754bb1790e | ||
|
|
95512c9829 | ||
|
|
d6f4cb7151 | ||
|
|
5985f54958 | ||
|
|
08c17b3d48 | ||
|
|
da8e7ca876 | ||
|
|
fc6e831527 | ||
|
|
c106989163 | ||
|
|
38e13031b5 | ||
|
|
690eb2f7b3 | ||
|
|
dac44d4a95 | ||
|
|
a95886ca2f | ||
|
|
ad560d3c16 | ||
|
|
2e8b48cd62 | ||
|
|
83c911be36 | ||
|
|
a40ca2a795 | ||
|
|
af92041495 | ||
|
|
c8369558a8 | ||
|
|
b9d7f2b1a0 | ||
|
|
3e4be31224 | ||
|
|
d0a2b56b4f | ||
|
|
e085df16b3 | ||
|
|
9784a83e6e | ||
|
|
76fd246bc5 | ||
|
|
b9a46241e4 | ||
|
|
443edeffde | ||
|
|
dd405da7eb | ||
|
|
40cb04dfa0 | ||
|
|
5178946d54 | ||
|
|
c5423a5587 | ||
|
|
c516683a6a | ||
|
|
b71ffc69fd | ||
|
|
4fadb90a41 | ||
|
|
a7a6bd99a2 | ||
|
|
4c551237f8 | ||
|
|
12425f1be9 | ||
|
|
0559b83f73 | ||
|
|
a2d18d7dea | ||
|
|
d1e81cb2d5 | ||
|
|
8e58d07c4c | ||
|
|
2555c86506 | ||
|
|
490c011ce3 | ||
|
|
8515b91b88 | ||
|
|
620dc9f455 | ||
|
|
6c27ebc956 | ||
|
|
b494a67c17 | ||
|
|
b7b9f65c48 | ||
|
|
f23e8ad032 | ||
|
|
782207ca52 | ||
|
|
92ff23e587 | ||
|
|
b2635b4976 | ||
|
|
0005075f86 | ||
|
|
c57c87c729 | ||
|
|
89cdf1a803 | ||
|
|
5c62da7ead | ||
|
|
827631d242 | ||
|
|
0c20c79236 | ||
|
|
0d19ffd8ad | ||
|
|
f1921ed922 | ||
|
|
8ee90271be | ||
|
|
a74c47e5d1 | ||
|
|
b71417e791 | ||
|
|
4236c602ca | ||
|
|
785ed9f0c0 | ||
|
|
61bf491213 | ||
|
|
df62a84d7e | ||
|
|
3e9573a974 | ||
|
|
eb58007af7 | ||
|
|
977b9e5271 | ||
|
|
4ddd9cf248 | ||
|
|
c057afbc4d | ||
|
|
9788ceafce | ||
|
|
5499574b39 | ||
|
|
d0c0d01afc | ||
|
|
135034ac71 | ||
|
|
67e5f7660c | ||
|
|
f6a9db5a5b | ||
|
|
a8f768361e | ||
|
|
1aaeceaa79 | ||
|
|
194322d2a3 | ||
|
|
b13e34b8d9 | ||
|
|
ef5e576fc2 | ||
|
|
c6983d7c79 | ||
|
|
a7f82d501c | ||
|
|
38c44143d7 | ||
|
|
01eb57cba2 | ||
|
|
1021330c20 | ||
|
|
22eda77d98 | ||
|
|
eeff68cc68 | ||
|
|
964949b656 | ||
|
|
2a7a7b11e8 | ||
|
|
f2c880e5b1 | ||
|
|
ba13cc996e | ||
|
|
329a50f3f0 | ||
|
|
7ea4c90475 | ||
|
|
ede972bd9e | ||
|
|
c3b03cd3dd | ||
|
|
86a2720d85 | ||
|
|
2a90ef803f | ||
|
|
15d080f250 | ||
|
|
91916cd915 | ||
|
|
9714f07c1f | ||
|
|
9f6e938e3b | ||
|
|
cb7ec1e718 | ||
|
|
703a55ddf4 | ||
|
|
55e369901a | ||
|
|
09614c7c7d | ||
|
|
504f6c9307 | ||
|
|
b545bebf42 | ||
|
|
2ff3dd5224 | ||
|
|
57f78a87b5 | ||
|
|
931ac3bead | ||
|
|
321652d161 | ||
|
|
aac123ef69 | ||
|
|
fd5878533a | ||
|
|
cba47cf5e8 | ||
|
|
f9e1063171 | ||
|
|
2c9c1c82ef | ||
|
|
5fa3ac888c | ||
|
|
813c10f1d6 | ||
|
|
559ec51b02 | ||
|
|
e197a90da7 | ||
|
|
81fbb6a0c3 | ||
|
|
523a4dc418 | ||
|
|
ff85c2b93b | ||
|
|
2d80d64878 | ||
|
|
745f12467c | ||
|
|
0150e1894f | ||
|
|
0fc90c3e06 | ||
|
|
09c2f24013 | ||
|
|
bf6855be79 | ||
|
|
341ec4198d | ||
|
|
c81dbffc4f | ||
|
|
3cb487b5a9 | ||
|
|
4f7994e44a | ||
|
|
f52e868a2e | ||
|
|
e837217263 | ||
|
|
cf414a6ba8 | ||
|
|
19d080de23 | ||
|
|
126bd3b578 | ||
|
|
8eb3c82575 | ||
|
|
e749b0a6c7 | ||
|
|
4564ed7a76 | ||
|
|
8eba8a5341 | ||
|
|
3d38015f90 | ||
|
|
bd17e51cde | ||
|
|
8748d67aac | ||
|
|
f337efba64 |
2
.github/workflows/build.yml
vendored
2
.github/workflows/build.yml
vendored
@@ -59,7 +59,7 @@ jobs:
|
||||
merged-as-untrusted-at: ${{ inputs.mergedSha }}
|
||||
target-as-trusted-at: ${{ inputs.targetSha }}
|
||||
|
||||
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
- uses: cachix/install-nix-action@a49548c11d9846ad46ecc0115273879b045f001c # v31.10.7
|
||||
with:
|
||||
# Sandbox is disabled on MacOS by default.
|
||||
extra_nix_config: sandbox = true
|
||||
|
||||
2
.github/workflows/check.yml
vendored
2
.github/workflows/check.yml
vendored
@@ -147,7 +147,7 @@ jobs:
|
||||
merged-as-untrusted-at: ${{ inputs.mergedSha }}
|
||||
target-as-trusted-at: ${{ inputs.targetSha }}
|
||||
|
||||
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
- uses: cachix/install-nix-action@a49548c11d9846ad46ecc0115273879b045f001c # v31.10.7
|
||||
|
||||
- uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17
|
||||
continue-on-error: true
|
||||
|
||||
8
.github/workflows/eval.yml
vendored
8
.github/workflows/eval.yml
vendored
@@ -139,7 +139,7 @@ jobs:
|
||||
core.info(`Found pinned.json commit: ${ciPinBumpCommit}`)
|
||||
|
||||
- name: Install Nix
|
||||
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
uses: cachix/install-nix-action@a49548c11d9846ad46ecc0115273879b045f001c # v31.10.7
|
||||
|
||||
- name: Load supported versions
|
||||
id: versions
|
||||
@@ -187,7 +187,7 @@ jobs:
|
||||
target-as-trusted-at: ${{ inputs.targetSha }}
|
||||
|
||||
- name: Install Nix
|
||||
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
uses: cachix/install-nix-action@a49548c11d9846ad46ecc0115273879b045f001c # v31.10.7
|
||||
|
||||
- uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17
|
||||
continue-on-error: true
|
||||
@@ -277,7 +277,7 @@ jobs:
|
||||
merge-multiple: true
|
||||
|
||||
- name: Install Nix
|
||||
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
uses: cachix/install-nix-action@a49548c11d9846ad46ecc0115273879b045f001c # v31.10.7
|
||||
|
||||
- name: Combine all output paths and eval stats
|
||||
run: |
|
||||
@@ -486,7 +486,7 @@ jobs:
|
||||
merged-as-untrusted-at: ${{ inputs.mergedSha }}
|
||||
|
||||
- name: Install Nix
|
||||
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
uses: cachix/install-nix-action@a49548c11d9846ad46ecc0115273879b045f001c # v31.10.7
|
||||
|
||||
- name: Ensure flake outputs on all systems still evaluate
|
||||
run: nix flake check --all-systems --no-build './nixpkgs/untrusted?shallow=1'
|
||||
|
||||
6
.github/workflows/lint.yml
vendored
6
.github/workflows/lint.yml
vendored
@@ -35,7 +35,7 @@ jobs:
|
||||
with:
|
||||
merged-as-untrusted-at: ${{ inputs.mergedSha }}
|
||||
|
||||
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
- uses: cachix/install-nix-action@a49548c11d9846ad46ecc0115273879b045f001c # v31.10.7
|
||||
|
||||
# TODO: Figure out how to best enable caching for the treefmt job. Cachix won't work well,
|
||||
# because the cache would be invalidated on every commit - treefmt checks every file.
|
||||
@@ -70,7 +70,7 @@ jobs:
|
||||
with:
|
||||
merged-as-untrusted-at: ${{ inputs.mergedSha }}
|
||||
|
||||
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
- uses: cachix/install-nix-action@a49548c11d9846ad46ecc0115273879b045f001c # v31.10.7
|
||||
|
||||
- uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17
|
||||
continue-on-error: true
|
||||
@@ -100,7 +100,7 @@ jobs:
|
||||
merged-as-untrusted-at: ${{ inputs.mergedSha }}
|
||||
target-as-trusted-at: ${{ inputs.targetSha }}
|
||||
|
||||
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
- uses: cachix/install-nix-action@a49548c11d9846ad46ecc0115273879b045f001c # v31.10.7
|
||||
|
||||
- uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17
|
||||
continue-on-error: true
|
||||
|
||||
@@ -41,7 +41,7 @@
|
||||
/lib/meta.nix @alyssais @NixOS/stdenv @llakala
|
||||
/lib/meta-types.nix @infinisil @adisbladis @NixOS/stdenv @llakala
|
||||
/lib/source-types.nix @alyssais @NixOS/stdenv @llakala
|
||||
/lib/systems @alyssais @NixOS/stdenv
|
||||
/lib/systems @alyssais @NixOS/stdenv @llakala
|
||||
## Libraries / Module system
|
||||
/lib/modules.nix @infinisil @roberth @hsjobeki @llakala
|
||||
/lib/types.nix @infinisil @roberth @hsjobeki @llakala
|
||||
@@ -260,7 +260,7 @@ pkgs/development/python-modules/buildcatrust/ @ajs124 @lukegb @mweinelt
|
||||
/pkgs/applications/editors/jetbrains @leona-ya @theCapypara
|
||||
|
||||
# Licenses
|
||||
/lib/licenses @alyssais @emilazy @jopejoe1
|
||||
/lib/licenses @alyssais @emilazy @jopejoe1 @llakala
|
||||
|
||||
# Qt
|
||||
/pkgs/development/libraries/qt-5 @K900 @NickCao @SuperSandro2000
|
||||
|
||||
@@ -395,13 +395,6 @@ module.exports = async ({ github, context, core, dry }) => {
|
||||
pull_number,
|
||||
per_page: 100,
|
||||
})
|
||||
|
||||
// label llm-assisted PRs accordingly
|
||||
const assistedByPattern = /Assisted-by: (?!nix-init)/i
|
||||
evalLabels['llm-assisted'] = prCommits.some((c) =>
|
||||
assistedByPattern.test(c.commit.message),
|
||||
)
|
||||
|
||||
const commitSubjects = prCommits.map(
|
||||
(c) => c.commit.message.split('\n')[0],
|
||||
)
|
||||
|
||||
@@ -143,4 +143,3 @@ lib.extendMkDerivation {
|
||||
});
|
||||
}
|
||||
```
|
||||
:::
|
||||
|
||||
@@ -165,7 +165,7 @@ They are useful for creating files from Nix expressions, and are all implemented
|
||||
Each of these functions will cause a derivation to be produced.
|
||||
When you coerce the result of each of these functions to a string with [string interpolation](https://nixos.org/manual/nix/stable/language/string-interpolation) or [`toString`](https://nixos.org/manual/nix/stable/language/builtins#builtins-toString), it will evaluate to the [store path](https://nixos.org/manual/nix/stable/store/store-path) of this derivation.
|
||||
|
||||
::: {.note}
|
||||
:::: {.note}
|
||||
Some of these functions will put the resulting files within a directory inside the [derivation output](https://nixos.org/manual/nix/stable/language/derivations#attr-outputs).
|
||||
If you need to refer to the resulting files somewhere else in a Nix expression, append their path to the derivation's store path.
|
||||
|
||||
@@ -190,7 +190,7 @@ writeShellScript "evaluate-my-file.sh" ''
|
||||
cat ${my-file}/share/my-file
|
||||
''
|
||||
```
|
||||
:::
|
||||
::::
|
||||
|
||||
### `makeDesktopItem` {#trivial-builder-makeDesktopItem}
|
||||
|
||||
|
||||
24
doc/hooks/check-phase-thread-limit-hook.section.md
Normal file
24
doc/hooks/check-phase-thread-limit-hook.section.md
Normal file
@@ -0,0 +1,24 @@
|
||||
# checkPhaseThreadLimitHook {#setup-hook-check-phase-thread-limit}
|
||||
|
||||
This hook defaults a variety of environment variables known
|
||||
to control thread counts to 1. Many of these otherwise default
|
||||
to `$(nproc)`, which causes massive overloads on build machines
|
||||
if nix build jobs and build cores are already tuned to fully utilize
|
||||
compute capacity of a builder without additional parallelism.
|
||||
|
||||
Currently sets the following environment variables:
|
||||
- [`OMP_NUM_THREADS`](https://www.openmp.org/spec-html/5.0/openmpse50.html)
|
||||
- [`OPENBLAS_NUM_THREADS`](https://github.com/OpenMathLib/OpenBLAS/blob/e7b45174355edec1f04de1cabcf5ca6a98ea7fbc/USAGE.md#how-can-i-use-openblas-in-multi-threaded-applications)
|
||||
- [`MKL_NUM_THREADS`](https://www.intel.com/content/www/us/en/docs/onemkl/developer-guide-linux/2023-0/mkl-domain-num-threads.html)
|
||||
- [`BLIS_NUM_THREADS`](https://github.com/flame/blis/blob/b8b75b4e19459f5d618b57aa814ca38b1d82eb82/docs/Multithreading.md#specifying-multithreading)
|
||||
- `VECLIB_MAXIMUM_THREADS`: Only affects darwin, see [`man 7 Accelerate`](https://manp.gs/mac/7/Accelerate)
|
||||
- [`NUMBA_NUM_THREADS`](https://numba.readthedocs.io/en/stable/reference/envvars.html#threading-control)
|
||||
- [`NUMEXPR_NUM_THREADS`](https://numexpr.readthedocs.io/en/latest/user_guide.html#threadpool-configuration)
|
||||
|
||||
The `NIX_CHECK_PHASE_DEFAULT_NUM_THREADS` environment variable
|
||||
can be used to override the default thread count limit.
|
||||
`dontLimitCheckPhaseThreads = true;` can be used to disable
|
||||
thread limiting on an individual package.
|
||||
|
||||
This hook will not attempt to override already existing
|
||||
definitions for thread count environment variables.
|
||||
@@ -13,6 +13,7 @@ aws-c-common.section.md
|
||||
bmake.section.md
|
||||
breakpoint.section.md
|
||||
cernlib.section.md
|
||||
check-phase-thread-limit-hook.section.md
|
||||
cmake.section.md
|
||||
desktop-file-utils.section.md
|
||||
gdk-pixbuf.section.md
|
||||
@@ -34,7 +35,6 @@ nodejs-install-manuals.section.md
|
||||
npm-build-hook.section.md
|
||||
npm-config-hook.section.md
|
||||
npm-install-hook.section.md
|
||||
openmp-check-hook.section.md
|
||||
patch-rc-path-hooks.section.md
|
||||
perl.section.md
|
||||
pkg-config.section.md
|
||||
|
||||
@@ -1,10 +0,0 @@
|
||||
# openmpCheckPhaseHook {#setup-hook-omp-check}
|
||||
|
||||
|
||||
This hook can be used to setup a check phase that
|
||||
requires running a OpenMP application. It mostly
|
||||
serves to limit `OMP_NUM_THREADS` to avoid overloading
|
||||
build machines.
|
||||
|
||||
This hook will not attempt to override an already existing
|
||||
definition of `OMP_NUM_THREADS` in the environment.
|
||||
@@ -59,7 +59,7 @@ The recommended way of defining a derivation for a Rocq library, is to use the `
|
||||
* `releaseRev` (optional, defaults to `(v: v)`), provides a default mapping from release names to revision hashes/branch names/tags,
|
||||
* `releaseArtifact` (optional, defaults to `(v: null)`), provides a default mapping from release names to artifact names (only works for github artifact for now),
|
||||
* `displayVersion` (optional), provides a way to alter the computation of `name` from `pname`, by explaining how to display version numbers,
|
||||
* `namePrefix` (optional, defaults to `[ "rocq" ]`), provides a way to alter the computation of `name` from `pname`, by explaining which dependencies must occur in `name`,
|
||||
* `namePrefix` (optional, defaults to `[ "rocq-core" ]`), provides a way to alter the computation of `name` from `pname`, by explaining which dependencies must occur in `name`,
|
||||
* `nativeBuildInputs` (optional), is a list of executables that are required to build the current derivation, in addition to the default ones (namely `which`, `dune` and `ocaml` depending on whether `useDune`, `useDuneifVersion` and `mlPlugin` are set).
|
||||
* `extraNativeBuildInputs` (optional, deprecated), an additional list of derivation to add to `nativeBuildInputs`,
|
||||
* `overrideNativeBuildInputs` (optional) replaces the default list of derivation to which `nativeBuildInputs` and `extraNativeBuildInputs` adds extra elements,
|
||||
|
||||
@@ -32,21 +32,6 @@ There is a TeX Live packaging that lives entirely under attribute `texlive`.
|
||||
)
|
||||
```
|
||||
|
||||
- Packages can be overriden by passing a new package with the same `pname` to `.withPackages`. For instance, the following replaces Asymptote with the version from Nixpkgs, which is usually more up to date:
|
||||
```nix
|
||||
texliveMedium.withPackages (ps: [ asymptote ])
|
||||
```
|
||||
|
||||
- To exclude a package from a collection, use an empty override as below:
|
||||
```nix
|
||||
texliveBasic.withPackages (
|
||||
ps: with ps; [
|
||||
collection-bibtexextra
|
||||
{ pname = "bib2gls"; }
|
||||
]
|
||||
)
|
||||
```
|
||||
|
||||
- To add the documentation for all packages in the environment, use
|
||||
```nix
|
||||
texliveSmall.overrideAttrs { withDocs = true; }
|
||||
|
||||
@@ -2920,7 +2920,8 @@
|
||||
"setup-hook-mpi-check": [
|
||||
"index.html#setup-hook-mpi-check"
|
||||
],
|
||||
"setup-hook-omp-check": [
|
||||
"setup-hook-check-phase-thread-limit": [
|
||||
"index.html#setup-hook-check-phase-thread-limit",
|
||||
"index.html#setup-hook-omp-check"
|
||||
],
|
||||
"ninja": [
|
||||
|
||||
@@ -31,6 +31,9 @@
|
||||
By the time of this release, Homebrew will offer only limited [Tier 3](https://docs.brew.sh/Support-Tiers#tier-3) support for the platform, but MacPorts will likely continue to support it for a long time.
|
||||
We also recommend users consider installing NixOS, which should continue to run on essentially all Intel Macs, especially after Apple stops security support for macOS 26 in 2028.
|
||||
|
||||
- `bundlerApp` now sets `__structuredAttrs = true` for its result package.
|
||||
Out-of-tree packages passing `postBuild` to `bundlerApp` should examine if their `postBuild` commands are compatible with structured attributes.
|
||||
|
||||
- `databricks-cli` has been updated from `0.290.2` to `1.x.x`, the first major release. OAuth tokens for interactive logins (`auth_type = databricks-cli`) are now stored in the OS-native secure store by default (Secret Service on Linux) instead of `~/.databricks/token-cache.json`; cached tokens from older versions are not migrated, so run `databricks auth login` once per profile after upgrading. To keep the previous file-backed storage, set `DATABRICKS_AUTH_STORAGE=plaintext` or add `auth_storage = plaintext` under `[__settings__]` in `~/.databrickscfg`. Additionally, the `vector_search_endpoints` DABs resource renamed `min_qps` to `target_qps` (and the `vector-search-endpoints` command renamed `--min-qps` to `--target-qps`). See the [upstream changelog](https://github.com/databricks/cli/blob/main/CHANGELOG.md) for details.
|
||||
|
||||
- `hurl` has been updated to `8.x.x` which has some breaking changes. See [upstream changelog](https://github.com/Orange-OpenSource/hurl/releases/tag/8.0.0) for details.
|
||||
@@ -42,14 +45,10 @@
|
||||
|
||||
- `python3Packages.django-health-check` has been updated to major version 4. See its [migration guide](https://codingjoe.dev/django-health-check/migrate-to-v4/) and [changelog](https://github.com/codingjoe/django-health-check/releases/tag/4.0.0) for breaking changes.
|
||||
|
||||
- `jmtpfs` has been removed due to lack of maintenance and fuse3 support.
|
||||
|
||||
- `libgdata` has been removed, as it was archived upstream and relied on the insecure libsoup 2.4.
|
||||
|
||||
- `mcphost` has been removed, as it was archived upstream and declared unmaintained.
|
||||
|
||||
- `fflogs` has been removed because it was no longer functional. Users should switch to `archon-lite`.
|
||||
|
||||
- `services.mysql` now sets `root@localhost` authentication to `auth_socket` when used with `mysql` or `percona-server`.
|
||||
Existing deployments will also be adjusted if possible. See the [security advisory GHSA-6qxx-6rg8-c4p8](https://github.com/NixOS/nixpkgs/security/advisories/GHSA-6qxx-6rg8-c4p8) for more information.
|
||||
|
||||
@@ -148,7 +147,8 @@
|
||||
|
||||
### Breaking changes {#sec-nixpkgs-release-26.11-lib-breaking}
|
||||
|
||||
- `fittrackee` 1.0.0 now requires postgres with postgis. The [upgrade guide](https://docs.fittrackee.org/en/upgrading-to-1.0.0.html) has steps to prepare for this upgrade.
|
||||
- Create the first release note entry in this section!
|
||||
|
||||
|
||||
### Deprecations {#sec-nixpkgs-release-26.11-lib-deprecations}
|
||||
|
||||
|
||||
@@ -156,7 +156,8 @@ body {
|
||||
}
|
||||
|
||||
a {
|
||||
text-decoration: underline;
|
||||
text-decoration: none;
|
||||
border-bottom: 1px solid;
|
||||
color: var(--link-color);
|
||||
}
|
||||
|
||||
@@ -479,8 +480,6 @@ div.appendix .variablelist .term {
|
||||
nav.toc-sidebar {
|
||||
height: 100%;
|
||||
padding: 0 1rem 2rem;
|
||||
background-color: var(--background);
|
||||
color: var(--main-text-color);
|
||||
}
|
||||
|
||||
/* menu button, shown on mobile, hidden on desktop */
|
||||
@@ -522,59 +521,6 @@ nav.toc-sidebar li {
|
||||
|
||||
nav.toc-sidebar summary {
|
||||
cursor: pointer;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
list-style: none;
|
||||
}
|
||||
|
||||
nav.toc-sidebar summary::before {
|
||||
content: "▸";
|
||||
flex: none;
|
||||
font-size: 0.75em;
|
||||
}
|
||||
nav.toc-sidebar details[open] > summary::before {
|
||||
content: "▾";
|
||||
}
|
||||
|
||||
nav.toc-sidebar a {
|
||||
display: block;
|
||||
width: 100%;
|
||||
padding: 3px 8px;
|
||||
border-left: 3px solid transparent;
|
||||
border-radius: 3px;
|
||||
color: inherit;
|
||||
transition:
|
||||
background-color 120ms ease,
|
||||
border-color 120ms ease;
|
||||
}
|
||||
nav.toc-sidebar a:hover {
|
||||
background-color: #f2f2f2 !important;
|
||||
}
|
||||
|
||||
nav.toc-sidebar a.active {
|
||||
background-color: #d8d8d8;
|
||||
border-left-color: #444;
|
||||
font-weight: 600;
|
||||
}
|
||||
nav.toc-sidebar a.active-trail {
|
||||
border-left-color: #bbb;
|
||||
background-color: #e8e8e8;
|
||||
}
|
||||
|
||||
@media (prefers-color-scheme: dark) {
|
||||
nav.toc-sidebar a:hover {
|
||||
/* hover should win over scroll selectors despite beeing less specific */
|
||||
background-color: #606060 !important;
|
||||
}
|
||||
nav.toc-sidebar a.active {
|
||||
background-color: #373737;
|
||||
border-left-color: #eee;
|
||||
font-weight: 600;
|
||||
}
|
||||
nav.toc-sidebar a.active-trail {
|
||||
border-left-color: #eee;
|
||||
background-color: #323232;
|
||||
}
|
||||
}
|
||||
|
||||
@media screen and (min-width: 768px) {
|
||||
@@ -607,6 +553,7 @@ nav.toc-sidebar a.active-trail {
|
||||
max-height: none;
|
||||
overflow-y: auto;
|
||||
border: none;
|
||||
border-right: 0.0625rem solid #d8d8d8;
|
||||
}
|
||||
|
||||
/* Hide the toggle button on desktop */
|
||||
|
||||
@@ -1,16 +1,16 @@
|
||||
# Platform Support {#chap-platform-support}
|
||||
|
||||
Packages receive varying degrees of support, both in terms of maintainer and security team attention and available computation resources for continuous integration (CI). We have 7 defined tiers denoting how well supported each platform is.
|
||||
Packages receive varying degrees of support, both in terms of maintainer attention and available computation resources for continuous integration (CI). We have 7 defined tiers denoting how well supported each platform is.
|
||||
|
||||
## Tiers {#sec-platform-tiers}
|
||||
|
||||
### Tier 1 {#sec-platform-tier1}
|
||||
|
||||
[Tier 1](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-1) platforms receive the highest level of support where problems can block updates, security fixes are treated with urgency, platform-specific patches are freely applied, and most packages are expected to work.
|
||||
[Tier 1](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-1) platforms receive the highest level of support where problems can block updates, platform-specific patches are freely applied, and most packages are expected to work.
|
||||
|
||||
### Tier 2 {#sec-platform-tier2}
|
||||
|
||||
[Tier 2](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-2) platforms are expected to remain functional and secure with updates, receive platform-specific patches as needed, and have many packages built by Hydra with full ofBorg support.
|
||||
[Tier 2](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-2) platforms are expected to remain functional with updates, receive platform-specific patches as needed, and have many packages built by Hydra with full ofBorg support.
|
||||
|
||||
### Tier 3 {#sec-platform-tier3}
|
||||
|
||||
@@ -22,25 +22,25 @@ Platform Tiers [4 through 7](https://github.com/NixOS/rfcs/blob/master/rfcs/0046
|
||||
|
||||
## Breakdown {#sec-platform-breakdown}
|
||||
|
||||
| Triple | Support Tier | Channel Blockers | Hydra Support | Security Support | Ofborg Support | Bootstrap Tarballs | Cross Compiling Support |
|
||||
|---------------------------------------|------------------------------------------------------------------------------------------------|------------------|---------------|------------------|----------------|--------------------|-------------------------|
|
||||
| `x86_64-unknown-linux-gnu` | [Tier 1](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-1) | Many | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
|
||||
| `aarch64-unknown-linux-gnu` | [Tier 2](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-2) | Some | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
|
||||
| `x86_64-unknown-linux-musl` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | Limited | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `aarch64-unknown-linux-musl` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | Limited | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `x86_64-unknown-unknown-freebsd` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `arm64-apple-darwin` | [Tier 2](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-2) | Some | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
|
||||
| `i686-unknown-linux-gnu` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | Limited | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `riscv32-unknown-linux-gnu` | [Tier 4](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-4) | None | ❌ | ❌ | ❌ | ❌ | ✔️ |
|
||||
| `riscv64-unknown-linux-gnu` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `loongarch64-unknown-linux-gnu` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `armv6l-unknown-linux-gnueabihf` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `armv6l-unknown-linux-musleabihf` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `armv7l-unknown-linux-gnueabihf` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `armv5tel-unknown-linux-gnueabi` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `mips64el-unknown-linux-gnuabi64` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `mips64el-unknown-linux-gnuabin32` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `mipsel-unknown-linux-gnu` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `powerpc64-unknown-linux-gnuabielfv2` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `powerpc64le-unknown-linux-gnu` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `s390x-unknown-linux-gnu` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| Triple | Support Tier | Channel Blockers | Hydra Support | Ofborg Support | Bootstrap Tarballs | Cross Compiling Support |
|
||||
| ------------------------------------- | ------------ | ---------------- | ------------- | -------------- | ------------------ | ----------------------- |
|
||||
| `x86_64-unknown-linux-gnu` | [Tier 1](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-1) | Many | ✔️ | ✔️ | ✔️ | ✔️ |
|
||||
| `aarch64-unknown-linux-gnu` | [Tier 2](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-2) | Some | ✔️ | ✔️ | ✔️ | ✔️ |
|
||||
| `x86_64-unknown-linux-musl` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | Limited | ❌ | ✔️ | ✔️ |
|
||||
| `aarch64-unknown-linux-musl` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | Limited | ❌ | ✔️ | ✔️ |
|
||||
| `x86_64-unknown-unknown-freebsd` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `arm64-apple-darwin` | [Tier 2](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-2) | Some | ✔️ | ✔️ | ✔️ | ❌ |
|
||||
| `i686-unknown-linux-gnu` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | Limited | ❌ | ✔️ | ✔️ |
|
||||
| `riscv32-unknown-linux-gnu` | [Tier 4](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-4) | None | ❌ | ❌ | ❌ | ✔️ |
|
||||
| `riscv64-unknown-linux-gnu` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `loongarch64-unknown-linux-gnu` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `armv6l-unknown-linux-gnueabihf` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `armv6l-unknown-linux-musleabihf` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `armv7l-unknown-linux-gnueabihf` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `armv5tel-unknown-linux-gnueabi` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `mips64el-unknown-linux-gnuabi64` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `mips64el-unknown-linux-gnuabin32` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `mipsel-unknown-linux-gnu` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `powerpc64-unknown-linux-gnuabielfv2` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `powerpc64le-unknown-linux-gnu` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ✔️ | ✔️ |
|
||||
| `s390x-unknown-linux-gnu` | [Tier 3](https://github.com/NixOS/rfcs/blob/master/rfcs/0046-platform-support-tiers.md#tier-3) | None | ❌ | ❌ | ✔️ | ✔️ |
|
||||
|
||||
@@ -1140,7 +1140,7 @@ rec {
|
||||
|
||||
For a function that gives you control over what counts as a leaf, see `mapAttrsRecursiveCond`.
|
||||
|
||||
::: {.example #map-attrs-recursive-example}
|
||||
:::{#map-attrs-recursive-example .example}
|
||||
# Map over leaf attributes
|
||||
|
||||
```nix
|
||||
@@ -1165,7 +1165,7 @@ rec {
|
||||
If the predicate returns false, `mapAttrsRecursiveCond` does not recurse, but instead applies the mapping function.
|
||||
If the predicate returns true, it does recurse, and does not apply the mapping function.
|
||||
|
||||
::: {.example #map-attrs-recursive-cond-example}
|
||||
:::{#map-attrs-recursive-cond-example .example}
|
||||
# Map over an leaf attributes defined by a condition
|
||||
|
||||
Map derivations to their `name` attribute.
|
||||
|
||||
@@ -564,7 +564,7 @@ rec {
|
||||
|
||||
# Examples
|
||||
|
||||
:::{.example #ex-makeScope}
|
||||
:::{#ex-makeScope .example}
|
||||
# Create an interdependent package set on top of `pkgs`
|
||||
|
||||
The functions in `foo.nix` and `bar.nix` can depend on each other, in the sense that `foo.nix` can contain a function that expects `bar` as an attribute in its argument.
|
||||
@@ -593,7 +593,7 @@ rec {
|
||||
```
|
||||
:::
|
||||
|
||||
:::{.example #ex-makeScope-callPackage}
|
||||
:::{#ex-makeScope-callPackage .example}
|
||||
# Using `callPackage` from a scope
|
||||
|
||||
```nix
|
||||
|
||||
@@ -310,11 +310,6 @@ lib.mapAttrs mkLicense (
|
||||
redistributable = true;
|
||||
};
|
||||
|
||||
buddy = {
|
||||
spdxId = "Buddy";
|
||||
fullName = "Buddy License";
|
||||
};
|
||||
|
||||
bzip2 = {
|
||||
spdxId = "bzip2-1.0.6";
|
||||
fullName = "bzip2 and libbzip2 License v1.0.6";
|
||||
@@ -387,13 +382,6 @@ lib.mapAttrs mkLicense (
|
||||
free = false;
|
||||
};
|
||||
|
||||
cc-by-nc-30-igo = {
|
||||
# Currently does not have a spdxID will get one in the future https://github.com/spdx/license-list-XML/issues/2845
|
||||
# spdxId = "CC-BY-NC-3.0-IGO";
|
||||
fullName = "Creative Commons Attribution Non Commercial 3.0 IGO";
|
||||
free = false;
|
||||
};
|
||||
|
||||
cc-by-nc-40 = {
|
||||
spdxId = "CC-BY-NC-4.0";
|
||||
fullName = "Creative Commons Attribution Non Commercial 4.0 International";
|
||||
@@ -938,11 +926,6 @@ lib.mapAttrs mkLicense (
|
||||
free = false;
|
||||
};
|
||||
|
||||
jpl-image = {
|
||||
fullName = "JPL Image Use Policy";
|
||||
spdxId = "JPL-image";
|
||||
};
|
||||
|
||||
knuth = {
|
||||
fullName = "Knuth CTAN License";
|
||||
spdxId = "Knuth-CTAN";
|
||||
@@ -1628,11 +1611,6 @@ lib.mapAttrs mkLicense (
|
||||
url = "https://fedoraproject.org/wiki/Licensing:Wadalab?rd=Licensing/Wadalab";
|
||||
};
|
||||
|
||||
wordnet = {
|
||||
spdxId = "WordNet";
|
||||
fullName = "WordNet License";
|
||||
};
|
||||
|
||||
wtfpl = {
|
||||
spdxId = "WTFPL";
|
||||
fullName = "Do What The F*ck You Want To Public License";
|
||||
|
||||
@@ -1289,12 +1289,6 @@
|
||||
name = "Alexandru Tocar";
|
||||
keys = [ { fingerprint = "B617 DD24 3AB0 2E3F 2E67 DBFD 1305 2A85 D7A4 2AA4"; } ];
|
||||
};
|
||||
AlexAntonik = {
|
||||
email = "antonikavv@gmail.com";
|
||||
github = "AlexAntonik";
|
||||
githubId = 55547934;
|
||||
name = "Alex Antonik";
|
||||
};
|
||||
alexarice = {
|
||||
email = "alexrice999@hotmail.co.uk";
|
||||
github = "alexarice";
|
||||
@@ -1495,12 +1489,6 @@
|
||||
githubId = 60479013;
|
||||
name = "Alma Cemerlic";
|
||||
};
|
||||
aln730 = {
|
||||
email = "arnsg730@proton.me";
|
||||
github = "aln730";
|
||||
githubId = 94751172;
|
||||
name = "AGawas";
|
||||
};
|
||||
Alper-Celik = {
|
||||
email = "alper@alper-celik.dev";
|
||||
name = "Alper Çelik";
|
||||
@@ -1641,6 +1629,12 @@
|
||||
githubId = 382798;
|
||||
name = "amfl";
|
||||
};
|
||||
amiddelk = {
|
||||
email = "amiddelk@gmail.com";
|
||||
github = "amiddelk";
|
||||
githubId = 1358320;
|
||||
name = "Arie Middelkoop";
|
||||
};
|
||||
aminechikhaoui = {
|
||||
email = "amine.chikhaoui91@gmail.com";
|
||||
github = "AmineChikhaoui";
|
||||
@@ -1954,12 +1948,6 @@
|
||||
githubId = 51257127;
|
||||
name = "anntnzrb";
|
||||
};
|
||||
anntoin = {
|
||||
email = "anntoin@gmail.com";
|
||||
github = "Anntoin";
|
||||
githubId = 3289027;
|
||||
name = "Anntóin Wilkinson";
|
||||
};
|
||||
anoa = {
|
||||
matrix = "@andrewm:amorgan.xyz";
|
||||
email = "andrew@amorgan.xyz";
|
||||
@@ -2019,12 +2007,6 @@
|
||||
githubId = 14838767;
|
||||
name = "Jacopo Scannella";
|
||||
};
|
||||
antoineco = {
|
||||
email = "hello@acotten.com";
|
||||
github = "antoineco";
|
||||
githubId = 3299086;
|
||||
name = "Antoine Cotten";
|
||||
};
|
||||
anton-4 = {
|
||||
name = "Anton";
|
||||
github = "Anton-4";
|
||||
@@ -4450,12 +4432,6 @@
|
||||
{ fingerprint = "8916 F727 734E 77AB 437F A33A 19AB 76F5 CEE1 1392"; }
|
||||
];
|
||||
};
|
||||
caguiclajmg = {
|
||||
email = "jmg.caguicla@guarandoo.me";
|
||||
github = "caguiclajmg";
|
||||
githubId = 32662060;
|
||||
name = "John Mark Gabriel Caguicla";
|
||||
};
|
||||
CaiqueFigueiredo = {
|
||||
email = "public@caiquefigueiredo.me";
|
||||
github = "caiquefigueiredo";
|
||||
@@ -4755,6 +4731,12 @@
|
||||
githubId = 52760912;
|
||||
name = "Cameron Brown";
|
||||
};
|
||||
ccellado = {
|
||||
email = "annplague@gmail.com";
|
||||
github = "ccellado";
|
||||
githubId = 44584960;
|
||||
name = "Denis Khalmatov";
|
||||
};
|
||||
ccicnce113424 = {
|
||||
email = "ccicnce113424@gmail.com";
|
||||
matrix = "@ccicnce113424:matrix.org";
|
||||
@@ -5625,11 +5607,6 @@
|
||||
githubId = 5953003;
|
||||
name = "Connor Nelson";
|
||||
};
|
||||
conny = {
|
||||
github = "ConstantConstantin";
|
||||
githubId = 162139822;
|
||||
name = "Constantin-Paul Hertel";
|
||||
};
|
||||
conradmearns = {
|
||||
email = "conradmearns+github@pm.me";
|
||||
github = "ConradMearns";
|
||||
@@ -6386,12 +6363,6 @@
|
||||
github = "David-Kopczynski";
|
||||
githubId = 53194670;
|
||||
};
|
||||
David-Moody = {
|
||||
name = "David Moody";
|
||||
email = "david.moody@scot.me.uk";
|
||||
github = "David-Moody";
|
||||
githubId = 63956662;
|
||||
};
|
||||
david-sawatzke = {
|
||||
email = "d-nix@sawatzke.dev";
|
||||
github = "david-sawatzke";
|
||||
@@ -6826,13 +6797,6 @@
|
||||
githubId = 77843198;
|
||||
name = "Vasilis Manetas";
|
||||
};
|
||||
Deric-W = {
|
||||
email = "robo-eric@gmx.de";
|
||||
github = "Deric-W";
|
||||
githubId = 42873573;
|
||||
name = "Eric Wolf";
|
||||
keys = [ { fingerprint = "ADAA B6F3 A955 5589 D66C CE61 80D2 DA42 8A4A 537F"; } ];
|
||||
};
|
||||
DerickEddington = {
|
||||
email = "derick.eddington@pm.me";
|
||||
github = "DerickEddington";
|
||||
@@ -9143,12 +9107,6 @@
|
||||
githubId = 41450706;
|
||||
name = "fin-w";
|
||||
};
|
||||
fiona = {
|
||||
email = "mail@fiona.hamburg";
|
||||
github = "Fiona42069";
|
||||
githubId = 260108682;
|
||||
name = "fiona";
|
||||
};
|
||||
fionera = {
|
||||
email = "nix@fionera.de";
|
||||
github = "fionera";
|
||||
@@ -11522,13 +11480,6 @@
|
||||
githubId = 72767437;
|
||||
name = "Ian Holloway";
|
||||
};
|
||||
iank = {
|
||||
email = "iank@iank.org";
|
||||
github = "iank";
|
||||
githubId = 109598;
|
||||
name = "Ian Kilgore";
|
||||
keys = [ { fingerprint = "21F7 244E 095F 619E 8E3E 1EB4 9F3A 4AAB 4D90 D879"; } ];
|
||||
};
|
||||
ianliu = {
|
||||
email = "ian.liu88@gmail.com";
|
||||
github = "ianliu";
|
||||
@@ -11982,12 +11933,6 @@
|
||||
githubId = 16307070;
|
||||
name = "iosmanthus";
|
||||
};
|
||||
ipetkov = {
|
||||
name = "Ivan Petkov";
|
||||
github = "ipetkov";
|
||||
githubId = 1638690;
|
||||
email = "nixpkgs@ipetkov.dev";
|
||||
};
|
||||
ipsavitsky = {
|
||||
email = "ipsavitsky234@gmail.com";
|
||||
github = "ipsavitsky";
|
||||
@@ -12556,12 +12501,6 @@
|
||||
github = "JaviMerino";
|
||||
githubId = 44926;
|
||||
};
|
||||
jayadeep-km-sonarsource = {
|
||||
email = "jayadeep.kinavoormadam@sonarsource.com";
|
||||
name = "Jayadeep Kinavoor Madam";
|
||||
github = "jayadeep-km-sonarsource";
|
||||
githubId = 156662663;
|
||||
};
|
||||
jayesh-bhoot = {
|
||||
name = "Jayesh Bhoot";
|
||||
email = "jb@jayeshbhoot.com";
|
||||
@@ -14439,12 +14378,6 @@
|
||||
github = "keller00";
|
||||
githubId = 8452750;
|
||||
};
|
||||
kenis1108 = {
|
||||
email = "1836362346@qq.com";
|
||||
github = "kenis1108";
|
||||
githubId = 45393183;
|
||||
name = "kenis";
|
||||
};
|
||||
kenran = {
|
||||
email = "johannes.maier@mailbox.org";
|
||||
github = "kenranunderscore";
|
||||
@@ -16467,11 +16400,6 @@
|
||||
githubId = 83420438;
|
||||
name = "Lewis";
|
||||
};
|
||||
lubsch = {
|
||||
github = "lubsch";
|
||||
githubId = 33580245;
|
||||
name = "Benjamin Lohmar";
|
||||
};
|
||||
luc65r = {
|
||||
email = "lucas@ransan.fr";
|
||||
github = "luc65r";
|
||||
@@ -16684,6 +16612,12 @@
|
||||
githubId = 10746692;
|
||||
name = "Leopold Luley";
|
||||
};
|
||||
lumi = {
|
||||
email = "lumi@pew.im";
|
||||
github = "lumi-me-not";
|
||||
githubId = 26020062;
|
||||
name = "lumi";
|
||||
};
|
||||
luminarleaf = {
|
||||
github = "LuminarLeaf";
|
||||
githubId = 80571430;
|
||||
@@ -20193,12 +20127,6 @@
|
||||
github = "nigelgbanks";
|
||||
githubId = 487373;
|
||||
};
|
||||
nightconcept = {
|
||||
email = "dark@nightconcept.net";
|
||||
github = "nightconcept";
|
||||
githubId = 486025;
|
||||
name = "Danny Solivan";
|
||||
};
|
||||
nikhilmaddirala = {
|
||||
name = "Nikhil Maddirala";
|
||||
github = "nikhilmaddirala";
|
||||
@@ -20788,9 +20716,8 @@
|
||||
github = "numinit";
|
||||
githubId = 369111;
|
||||
keys = [
|
||||
# SSH, per-machine yubikey ecdsa-sk keys
|
||||
# SSH
|
||||
{ fingerprint = "XX/0lMz82MpucPqf0KG+5EJoozzNRi8i/t59byD2kNo"; }
|
||||
{ fingerprint = "dye2C1N4RQaf+8ht5Ipd52BbnnuwBtdXxocPzk8b2mw"; }
|
||||
# GPG, >=2025, stays in one place
|
||||
{ fingerprint = "FD28 F9C9 81C5 D78E 56E8 8311 5C3E B94D 198F 1491"; }
|
||||
# GPG, >=2025, travels with me
|
||||
@@ -21268,6 +21195,12 @@
|
||||
githubId = 19862;
|
||||
name = "KJ Ørbekk";
|
||||
};
|
||||
orbitz = {
|
||||
email = "mmatalka@gmail.com";
|
||||
github = "orbitz";
|
||||
githubId = 75299;
|
||||
name = "Malcolm Matalka";
|
||||
};
|
||||
orhun = {
|
||||
email = "orhunparmaksiz@gmail.com";
|
||||
github = "orhun";
|
||||
@@ -22086,12 +22019,6 @@
|
||||
githubId = 421510;
|
||||
name = "Noé Rubinstein";
|
||||
};
|
||||
phluxjr = {
|
||||
email = "phluxjr@phluxjr.net";
|
||||
github = "phluxjr";
|
||||
githubId = 185956030;
|
||||
name = "phluxjr";
|
||||
};
|
||||
pho = {
|
||||
email = "phofin@gmail.com";
|
||||
github = "pho";
|
||||
@@ -26035,12 +25962,6 @@
|
||||
name = "Nikolay Korotkiy";
|
||||
keys = [ { fingerprint = "ADF4 C13D 0E36 1240 BD01 9B51 D1DE 6D7F 6936 63A5"; } ];
|
||||
};
|
||||
silicalet = {
|
||||
name = "Mr. why";
|
||||
email = "silicalet@outlook.com";
|
||||
github = "silicalet";
|
||||
githubId = 188071249;
|
||||
};
|
||||
silky = {
|
||||
name = "Noon van der Silk";
|
||||
email = "noonsilk+nixpkgs@gmail.com";
|
||||
@@ -26711,6 +26632,12 @@
|
||||
github = "spreetin";
|
||||
githubId = 7392173;
|
||||
};
|
||||
sprock = {
|
||||
email = "rmason@mun.ca";
|
||||
github = "sprock";
|
||||
githubId = 6391601;
|
||||
name = "Roger Mason";
|
||||
};
|
||||
sputn1ck = {
|
||||
email = "kon@kon.ninja";
|
||||
github = "sputn1ck";
|
||||
@@ -27285,13 +27212,6 @@
|
||||
githubId = 36695359;
|
||||
name = "Vasyl Solovei";
|
||||
};
|
||||
swaggeroo = {
|
||||
email = "swaggerooo@pm.me";
|
||||
github = "swaggeroo";
|
||||
githubId = 57057662;
|
||||
name = "Swaggeroo";
|
||||
keys = [ { fingerprint = "D221 99EC 4FFF EF4D F29D 2435 5208 74E7 3291 4E0B"; } ];
|
||||
};
|
||||
swarren83 = {
|
||||
email = "shawn.w.warren@gmail.com";
|
||||
github = "swarren83";
|
||||
@@ -29789,6 +29709,12 @@
|
||||
githubId = 20145996;
|
||||
name = "Victor Fuentes";
|
||||
};
|
||||
vlstill = {
|
||||
email = "xstill@fi.muni.cz";
|
||||
github = "vlstill";
|
||||
githubId = 4070422;
|
||||
name = "Vladimír Štill";
|
||||
};
|
||||
vmandela = {
|
||||
email = "venkat.mandela@gmail.com";
|
||||
github = "vmandela";
|
||||
@@ -31150,13 +31076,6 @@
|
||||
{ fingerprint = "D2A8 A906 ACA7 B6D6 575E 9A2F 3A49 5054 6EA6 9E5C"; }
|
||||
];
|
||||
};
|
||||
yoquec = {
|
||||
email = "alvaro.viejo@yoquec.com";
|
||||
github = "yoquec";
|
||||
githubId = 59575696;
|
||||
name = "Alvaro Viejo";
|
||||
matrix = "@yoquec.com:matrix.org";
|
||||
};
|
||||
yorickvp = {
|
||||
email = "yorickvanpelt@gmail.com";
|
||||
matrix = "@yorickvp:matrix.org";
|
||||
|
||||
@@ -8,7 +8,6 @@ binaryheap,,,,,,vcunat
|
||||
bit32,,,,,5.1,lblasc
|
||||
busted,,,,,,
|
||||
busted-htest,,,,,,mrcjkb
|
||||
canola.nvim,,,,,,saadndm
|
||||
cassowary,,,,,,alerque
|
||||
cldr,,,,,,alerque
|
||||
commons.nvim,,,,,5.1,mrcjkb
|
||||
|
||||
|
@@ -307,7 +307,7 @@ async def commit_changes(
|
||||
commit_message = "{attrPath}: {oldVersion} -> {newVersion}".format(**change)
|
||||
if "commitMessage" in change:
|
||||
commit_message = change["commitMessage"]
|
||||
if "commitBody" in change:
|
||||
elif "commitBody" in change:
|
||||
commit_message = commit_message + "\n\n" + change["commitBody"]
|
||||
await check_subprocess_output(
|
||||
"git",
|
||||
|
||||
@@ -717,15 +717,6 @@ with lib.maintainers;
|
||||
github = "security-review";
|
||||
};
|
||||
|
||||
stardust-xr = {
|
||||
members = [
|
||||
pandapip1
|
||||
technobaboo
|
||||
];
|
||||
scope = "Maintain Stardust XR packages";
|
||||
shortName = "StardustXR";
|
||||
};
|
||||
|
||||
stdenv = {
|
||||
enableFeatureFreezePing = true;
|
||||
github = "stdenv";
|
||||
|
||||
@@ -41,6 +41,5 @@ and non-critical by adding `options = [ "nofail" ];`.
|
||||
```{=include=} sections
|
||||
luks-file-systems.section.md
|
||||
sshfs-file-systems.section.md
|
||||
nfs-file-systems.section.md
|
||||
overlayfs.section.md
|
||||
```
|
||||
|
||||
@@ -1,52 +0,0 @@
|
||||
# NFS File Systems {#sec-nfs-file-systems}
|
||||
|
||||
[NFS][nfs] (Network File System) allows you to mount directories from remote machines over the network.
|
||||
|
||||
[nfs]: https://en.wikipedia.org/wiki/Network_File_System
|
||||
[nfs-man]: https://man7.org/linux/man-pages/man5/nfs.5.html
|
||||
|
||||
To mount NFS filesystems persistently, use the `fileSystems` option:
|
||||
|
||||
```nix
|
||||
{
|
||||
fileSystems."/mnt/data" = {
|
||||
device = "server.example.com:/export/data";
|
||||
fsType = "nfs";
|
||||
};
|
||||
}
|
||||
```
|
||||
|
||||
## Automounting {#sec-nfs-automount}
|
||||
|
||||
To have NFS filesystems mounted on-demand instead of at boot, add the `noauto` and `x-systemd.automount` options:
|
||||
|
||||
```nix
|
||||
{
|
||||
fileSystems."/mnt/data" = {
|
||||
device = "server.example.com:/export/data";
|
||||
fsType = "nfs";
|
||||
options = [
|
||||
"noauto"
|
||||
"x-systemd.automount"
|
||||
];
|
||||
};
|
||||
}
|
||||
```
|
||||
|
||||
## Ad-hoc Mounting {#sec-nfs-adhoc}
|
||||
|
||||
To mount NFS filesystems ad-hoc using the `mount` command, enable NFS and required RPC services:
|
||||
|
||||
```nix
|
||||
{
|
||||
boot.supportedFilesystems = [ "nfs" ];
|
||||
}
|
||||
```
|
||||
|
||||
Then you can mount filesystems manually:
|
||||
|
||||
```shell
|
||||
$ sudo mount -t nfs server.example.com:/export/data /mnt/data
|
||||
```
|
||||
|
||||
For more information on NFS mount options, see the [nfs(5) man page][nfs-man].
|
||||
@@ -47,7 +47,7 @@ The first steps to all these are the same:
|
||||
|
||||
Where `<version>` corresponds to the latest version available on [channels.nixos.org](https://channels.nixos.org/).
|
||||
|
||||
You must run `$ nix-channel --update` for the channel change to take effect.
|
||||
You may want to throw in a `nix-channel --update` for good measure.
|
||||
|
||||
1. Install the NixOS installation tools:
|
||||
|
||||
|
||||
@@ -619,15 +619,6 @@
|
||||
"sec-luks-file-systems-fido2-systemd": [
|
||||
"index.html#sec-luks-file-systems-fido2-systemd"
|
||||
],
|
||||
"sec-nfs-file-systems": [
|
||||
"index.html#sec-nfs-file-systems"
|
||||
],
|
||||
"sec-nfs-automount": [
|
||||
"index.html#sec-nfs-automount"
|
||||
],
|
||||
"sec-nfs-adhoc": [
|
||||
"index.html#sec-nfs-adhoc"
|
||||
],
|
||||
"sec-sshfs-file-systems": [
|
||||
"index.html#sec-sshfs-file-systems"
|
||||
],
|
||||
|
||||
@@ -99,8 +99,6 @@
|
||||
|
||||
- `services.plantuml-server.packages.jetty` now supports `jetty_12`, it no longer supports `jetty_11`.
|
||||
|
||||
- `services.komodo-periphery` has been updated to support version 2.0.0. Some options have been renamed to match the new configuration structure; compatibility aliases are provided for the renamed options. The `passkeys` and `outbound.onboardingKey` options have been removed; use `passkeyFiles`, `auth.privateKey`/`auth.corePublicKeys`, or `outbound.onboardingKeyFile` instead. New outbound mode configuration is available under `outbound.*`.
|
||||
|
||||
## Other Notable Changes {#sec-release-26.11-notable-changes}
|
||||
|
||||
<!-- To avoid merge conflicts, consider adding your item at an arbitrary place in the list instead. -->
|
||||
@@ -144,8 +142,6 @@
|
||||
|
||||
- The `newuidmap` and `newgidmap` security wrappers are now installed with `cap_setuid`/`cap_setgid` file capabilities instead of the setuid-root bit, matching shadow's `--with-fcaps` install mode and other major distributions. Rootless containers (podman, docker-rootless, unprivileged user namespaces) are unaffected. The only behavioural change is that mapping host uid 0 via `/etc/subuid` (which NixOS never configures by default) additionally requires `cap_setfcap`; users who explicitly grant uid 0 in a subuid range can restore the previous behaviour with `security.wrappers.newuidmap.capabilities = lib.mkForce "cap_setuid,cap_setfcap+ep";`.
|
||||
|
||||
- The `authelia` module now uses systemd's `LoadCredential` to load all files defined in `secrets`. As such, these files no longer need to be readable by the authelia user and group: they can for example be set to be only readable by the root user.
|
||||
|
||||
- `zoneminder` has been updated to 1.38.x release. See [upstream release note](https://github.com/ZoneMinder/zoneminder/releases/tag/1.38.0). While database migration should happen automatically, it's recommended that you make a backup of the database before upgrading your system.
|
||||
|
||||
- The latest available version of Nextcloud is v34 (available as `pkgs.nextcloud34`). The installation logic is as follows:
|
||||
|
||||
@@ -625,7 +625,7 @@ rec {
|
||||
|
||||
listenStreams = mkOption {
|
||||
default = [ ];
|
||||
type = types.listOf (types.coercedTo types.port toString types.str);
|
||||
type = types.listOf types.str;
|
||||
example = [
|
||||
"0.0.0.0:993"
|
||||
"/run/my-socket"
|
||||
|
||||
@@ -1861,7 +1861,6 @@
|
||||
./services/web-servers/nginx/tailscale-auth.nix
|
||||
./services/web-servers/phpfpm/default.nix
|
||||
./services/web-servers/pomerium.nix
|
||||
./services/web-servers/rustfs.nix
|
||||
./services/web-servers/rustus.nix
|
||||
./services/web-servers/send.nix
|
||||
./services/web-servers/stargazer.nix
|
||||
|
||||
@@ -511,7 +511,7 @@ in
|
||||
services.simplesamlphp has been vulnerable and unmaintained in nixpkgs.
|
||||
'')
|
||||
(mkRemovedOptionModule [ "security" "pam" "enableEcryptfs" ] ''
|
||||
security.pam.enableEcryptfs was removed since it was unmaintained in nixpkgs.
|
||||
security.pam.enableFscrypt was removed since it was unmaintained in nixpkgs.
|
||||
'')
|
||||
(mkRemovedOptionModule [ "security" "rngd" ] ''
|
||||
rngd is not necessary for any device that the kernel recognises
|
||||
|
||||
@@ -1832,6 +1832,11 @@ let
|
||||
else
|
||||
config.users.motdFile;
|
||||
|
||||
makePAMService = name: service: {
|
||||
name = "pam.d/${name}";
|
||||
value.source = pkgs.writeText "${name}.pam" service.text;
|
||||
};
|
||||
|
||||
optionalSudoConfigForSSHAgentAuth =
|
||||
lib.optionalString (config.security.pam.sshAgentAuth.enable || config.security.pam.rssh.enable)
|
||||
''
|
||||
@@ -2643,26 +2648,7 @@ in
|
||||
};
|
||||
};
|
||||
|
||||
environment.etc =
|
||||
let
|
||||
# Write all pam config in a single derivation for performance
|
||||
pamd =
|
||||
pkgs.runCommand "pam.d"
|
||||
{
|
||||
__structuredAttrs = true;
|
||||
services = lib.mapAttrs (_: svc: svc.text) enabledServices;
|
||||
}
|
||||
''
|
||||
mkdir $out
|
||||
for i in "''${!services[@]}"; do
|
||||
printf '%s' "''${services[$i]}" > "$out/$i"
|
||||
done
|
||||
'';
|
||||
in
|
||||
lib.mapAttrs' (name: service: {
|
||||
name = "pam.d/${name}";
|
||||
value.source = "${pamd}/${name}";
|
||||
}) enabledServices;
|
||||
environment.etc = lib.mapAttrs' makePAMService enabledServices;
|
||||
|
||||
systemd =
|
||||
lib.mkIf (lib.any (service: service.lastlog.enable) (lib.attrValues config.security.pam.services))
|
||||
|
||||
@@ -8,65 +8,41 @@ let
|
||||
cfg = config.services.komodo-periphery;
|
||||
settingsFormat = pkgs.formats.toml { };
|
||||
|
||||
actualRepoDir = if cfg.repoDir != null then cfg.repoDir else "${cfg.rootDirectory}/repos";
|
||||
actualStackDir = if cfg.stackDir != null then cfg.stackDir else "${cfg.rootDirectory}/stacks";
|
||||
actualBuildDir = if cfg.buildDir != null then cfg.buildDir else "${cfg.rootDirectory}/builds";
|
||||
|
||||
genFinalSettings =
|
||||
let
|
||||
actualServerEnabled =
|
||||
if cfg.inbound.serverEnabled != null then
|
||||
cfg.inbound.serverEnabled
|
||||
else
|
||||
(cfg.outbound.coreAddress == "");
|
||||
|
||||
hasAnyPrivateKey = cfg.auth.privateKey != "";
|
||||
|
||||
baseSettings = {
|
||||
default_terminal_command = cfg.defaultTerminalCommand;
|
||||
disable_terminals = cfg.disableTerminals;
|
||||
disable_container_terminals = cfg.disableContainerTerminals;
|
||||
|
||||
stats_polling_rate = cfg.statsPollingRate;
|
||||
container_stats_polling_rate = cfg.containerStatsPollingRate;
|
||||
legacy_compose_cli = cfg.legacyComposeCli;
|
||||
|
||||
include_disk_mounts = cfg.includeDiskMounts;
|
||||
exclude_disk_mounts = cfg.excludeDiskMounts;
|
||||
|
||||
# When a private key is explicitly configured, it's passed via env var.
|
||||
# Otherwise, use the default file path so Periphery auto-generates a key.
|
||||
private_key = if !hasAnyPrivateKey then "file:${cfg.rootDirectory}/keys/periphery.key" else "";
|
||||
core_public_keys = [ ];
|
||||
passkeys = [ ];
|
||||
|
||||
server_enabled = actualServerEnabled;
|
||||
port = cfg.inbound.port;
|
||||
bind_ip = cfg.inbound.bindIp;
|
||||
allowed_ips = cfg.inbound.allowedIps;
|
||||
ssl_enabled = cfg.inbound.ssl.enable;
|
||||
port = cfg.port;
|
||||
bind_ip = cfg.bindIp;
|
||||
root_directory = cfg.rootDirectory;
|
||||
repo_dir = "${cfg.rootDirectory}/repos";
|
||||
stack_dir = "${cfg.rootDirectory}/stacks";
|
||||
ssl_enabled = cfg.ssl.enable;
|
||||
}
|
||||
// {
|
||||
core_address = cfg.outbound.coreAddress;
|
||||
connect_as = cfg.outbound.connectAs;
|
||||
onboarding_key = "";
|
||||
// lib.optionalAttrs cfg.ssl.enable {
|
||||
ssl_key_file = cfg.ssl.keyFile;
|
||||
ssl_cert_file = cfg.ssl.certFile;
|
||||
}
|
||||
// {
|
||||
logging = {
|
||||
level = cfg.logging.level;
|
||||
stdio = cfg.logging.stdio;
|
||||
opentelemetry_service_name = cfg.logging.opentelemetryServiceName;
|
||||
opentelemetry_scope_name = cfg.logging.opentelemetryScopeName;
|
||||
pretty = cfg.logging.pretty;
|
||||
}
|
||||
// lib.optionalAttrs (cfg.logging.otlpEndpoint != "") {
|
||||
otlp_endpoint = cfg.logging.otlpEndpoint;
|
||||
};
|
||||
pretty_startup_config = cfg.prettyStartupConfig;
|
||||
allowed_ips = cfg.allowedIps;
|
||||
passkeys = cfg.passkeys;
|
||||
disable_terminals = cfg.disableTerminals;
|
||||
disable_container_exec = cfg.disableContainerExec;
|
||||
stats_polling_rate = cfg.statsPollingRate;
|
||||
container_stats_polling_rate = cfg.containerStatsPollingRate;
|
||||
legacy_compose_cli = cfg.legacyComposeCli;
|
||||
include_disk_mounts = cfg.includeDiskMounts;
|
||||
exclude_disk_mounts = cfg.excludeDiskMounts;
|
||||
}
|
||||
// cfg.extraSettings;
|
||||
in
|
||||
lib.filterAttrsRecursive (_: v: v != null && v != { } && v != [ ] && v != "") baseSettings;
|
||||
lib.filterAttrsRecursive (_: v: v != null && v != { } && v != [ ]) baseSettings;
|
||||
|
||||
configFile =
|
||||
if cfg.configFile == null then
|
||||
@@ -75,125 +51,62 @@ let
|
||||
cfg.configFile;
|
||||
in
|
||||
{
|
||||
imports = with lib; [
|
||||
(mkRenamedOptionModule
|
||||
[ "services" "komodo-periphery" "port" ]
|
||||
[ "services" "komodo-periphery" "inbound" "port" ]
|
||||
)
|
||||
(mkRenamedOptionModule
|
||||
[ "services" "komodo-periphery" "bindIp" ]
|
||||
[ "services" "komodo-periphery" "inbound" "bindIp" ]
|
||||
)
|
||||
(mkRenamedOptionModule
|
||||
[ "services" "komodo-periphery" "allowedIps" ]
|
||||
[ "services" "komodo-periphery" "inbound" "allowedIps" ]
|
||||
)
|
||||
(mkRenamedOptionModule
|
||||
[ "services" "komodo-periphery" "ssl" "enable" ]
|
||||
[ "services" "komodo-periphery" "inbound" "ssl" "enable" ]
|
||||
)
|
||||
(mkRenamedOptionModule
|
||||
[ "services" "komodo-periphery" "ssl" "keyFile" ]
|
||||
[ "services" "komodo-periphery" "inbound" "ssl" "keyFile" ]
|
||||
)
|
||||
(mkRenamedOptionModule
|
||||
[ "services" "komodo-periphery" "ssl" "certFile" ]
|
||||
[ "services" "komodo-periphery" "inbound" "ssl" "certFile" ]
|
||||
)
|
||||
(mkRenamedOptionModule
|
||||
[ "services" "komodo-periphery" "serverEnabled" ]
|
||||
[ "services" "komodo-periphery" "inbound" "serverEnabled" ]
|
||||
)
|
||||
(mkRenamedOptionModule
|
||||
[ "services" "komodo-periphery" "disableContainerExec" ]
|
||||
[ "services" "komodo-periphery" "disableContainerTerminals" ]
|
||||
)
|
||||
(mkRemovedOptionModule [ "services" "komodo-periphery" "passkeys" ]
|
||||
"services.komodo-periphery.passkeys has been removed. Use passkeyFiles for v1.X compatibility, or migrate to auth.privateKey and auth.corePublicKeys (v2.0+)."
|
||||
)
|
||||
(mkRemovedOptionModule [ "services" "komodo-periphery" "outbound" "onboardingKey" ]
|
||||
"services.komodo-periphery.outbound.onboardingKey has been removed. Use outbound.onboardingKeyFile instead for better security."
|
||||
)
|
||||
];
|
||||
|
||||
options.services.komodo-periphery = {
|
||||
enable = lib.mkEnableOption "Periphery, a multi-server Docker and Git deployment agent by Komodo";
|
||||
|
||||
package = lib.mkPackageOption pkgs "komodo" { };
|
||||
|
||||
dockerHost = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.str;
|
||||
default = null;
|
||||
description = ''
|
||||
Docker host socket URI to use for container operations.
|
||||
If null, uses the default Docker socket and automatically enables Docker.
|
||||
Set this to use alternative container runtimes like Podman or remote Docker hosts.
|
||||
'';
|
||||
example = lib.literalExpression ''
|
||||
# Podman rootless
|
||||
"unix:///run/user/1000/podman/podman.sock"
|
||||
|
||||
# Podman rootful
|
||||
"unix:///run/podman/podman.sock"
|
||||
|
||||
# Remote Docker
|
||||
"tcp://192.168.1.100:2375"
|
||||
'';
|
||||
};
|
||||
|
||||
configFile = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.path;
|
||||
default = null;
|
||||
description = ''
|
||||
Path to the Periphery configuration file.
|
||||
|
||||
- If `null` (default), a configuration file will be automatically generated
|
||||
from the module options (recommended for most users).
|
||||
- If set to a path, that file will be used directly as the configuration file.
|
||||
- You can also use `pkgs.writeText` to write configuration inline in your NixOS configuration.
|
||||
|
||||
When using a custom config file, all other module options (except `package`, `user`, `group`,
|
||||
`environment`, and `environmentFile`) will be ignored.
|
||||
'';
|
||||
description = "Path to the periphery configuration file. If null, a configuration file will be generated from the module options.";
|
||||
example = lib.literalExpression ''
|
||||
# Option 1: Use an existing config file
|
||||
"/etc/komodo/periphery.toml"
|
||||
|
||||
# Option 2: Write config inline using pkgs.writeText
|
||||
pkgs.writeText "periphery.toml" '''
|
||||
root_directory = "/var/lib/komodo-periphery"
|
||||
|
||||
logging.level = "info"
|
||||
logging.stdio = "standard"
|
||||
port = 8120
|
||||
bind_ip = "[::]"
|
||||
ssl_enabled = true
|
||||
[logging]
|
||||
level = "info"
|
||||
'''
|
||||
'';
|
||||
};
|
||||
|
||||
port = lib.mkOption {
|
||||
type = lib.types.port;
|
||||
default = 8120;
|
||||
description = "Port for the Periphery agent to listen on.";
|
||||
};
|
||||
|
||||
bindIp = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "[::]";
|
||||
description = "IP address to bind to.";
|
||||
};
|
||||
|
||||
rootDirectory = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
default = "/var/lib/komodo-periphery";
|
||||
description = "Root directory for Komodo Periphery data.";
|
||||
};
|
||||
|
||||
repoDir = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.path;
|
||||
default = null;
|
||||
defaultText = lib.literalExpression ''"''${config.services.komodo-periphery.rootDirectory}/repos"'';
|
||||
description = "Directory for Komodo Periphery to manage repos. If null, defaults to `\${rootDirectory}/repos`.";
|
||||
};
|
||||
ssl = {
|
||||
enable = lib.mkEnableOption "SSL/TLS support" // {
|
||||
default = true;
|
||||
};
|
||||
|
||||
stackDir = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.path;
|
||||
default = null;
|
||||
defaultText = lib.literalExpression ''"''${config.services.komodo-periphery.rootDirectory}/stacks"'';
|
||||
description = "Directory for Komodo Periphery to manage stacks. If null, defaults to `\${rootDirectory}/stacks`.";
|
||||
};
|
||||
keyFile = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
default = "${cfg.rootDirectory}/ssl/key.pem";
|
||||
defaultText = lib.literalExpression ''"''${config.services.komodo-periphery.rootDirectory}/ssl/key.pem"'';
|
||||
description = "Path to SSL key file.";
|
||||
};
|
||||
|
||||
buildDir = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.path;
|
||||
default = null;
|
||||
defaultText = lib.literalExpression ''"''${config.services.komodo-periphery.rootDirectory}/builds"'';
|
||||
description = "Directory for Komodo Periphery to manage builds. If null, defaults to `\${rootDirectory}/builds`.";
|
||||
certFile = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
default = "${cfg.rootDirectory}/ssl/cert.pem";
|
||||
defaultText = lib.literalExpression ''"''${config.services.komodo-periphery.rootDirectory}/ssl/cert.pem"'';
|
||||
description = "Path to SSL certificate file.";
|
||||
};
|
||||
};
|
||||
|
||||
logging = {
|
||||
@@ -226,41 +139,26 @@ in
|
||||
description = "OpenTelemetry OTLP endpoint for traces.";
|
||||
example = "http://localhost:4317";
|
||||
};
|
||||
|
||||
opentelemetryServiceName = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "Periphery";
|
||||
description = "(v2.0+) OpenTelemetry service name attached to telemetry.";
|
||||
};
|
||||
|
||||
opentelemetryScopeName = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "Komodo";
|
||||
description = "(v2.0+) OpenTelemetry scope name attached to telemetry.";
|
||||
};
|
||||
|
||||
pretty = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "(v2.0+) Enable human-readable logging (multi-line).";
|
||||
};
|
||||
};
|
||||
|
||||
prettyStartupConfig = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "(v2.0+) Enable human-readable startup config log (multi-line).";
|
||||
allowedIps = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
description = "IP addresses or subnets allowed to call the periphery API. Empty list allows all.";
|
||||
example = [
|
||||
"::ffff:12.34.56.78"
|
||||
"10.0.10.0/24"
|
||||
];
|
||||
};
|
||||
|
||||
passkeyFiles = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.path;
|
||||
default = null;
|
||||
passkeys = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
description = ''
|
||||
Path to file containing passkeys (v1.X compatibility).
|
||||
This will be passed via `PERIPHERY_PASSKEYS_FILE` environment variable.
|
||||
Consider migrating to the new v2.0+ authentication mechanism.
|
||||
Passkeys required to access the periphery API.
|
||||
WARNING: These will be stored in the Nix store in plain text!
|
||||
'';
|
||||
example = "/run/secrets/komodo-passkey";
|
||||
example = [ "your-secure-passkey" ];
|
||||
};
|
||||
|
||||
extraSettings = lib.mkOption {
|
||||
@@ -272,23 +170,16 @@ in
|
||||
};
|
||||
};
|
||||
|
||||
defaultTerminalCommand = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "bash";
|
||||
description = "(v2.0+) Default terminal command used to initialize the shell.";
|
||||
example = "zsh";
|
||||
};
|
||||
|
||||
disableTerminals = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "Disable remote shell access through Periphery.";
|
||||
};
|
||||
|
||||
disableContainerTerminals = lib.mkOption {
|
||||
disableContainerExec = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "(v2.0+) Disable remote container shell access through Periphery.";
|
||||
description = "Disable remote container shell access through Periphery.";
|
||||
};
|
||||
|
||||
statsPollingRate = lib.mkOption {
|
||||
@@ -331,147 +222,6 @@ in
|
||||
];
|
||||
};
|
||||
|
||||
auth = {
|
||||
privateKey = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "";
|
||||
description = ''
|
||||
(v2.0+) Private key used with the Noise handshake.
|
||||
|
||||
Use `file:/path/to/file` prefix to load from a file. If the file doesn't exist,
|
||||
Periphery will generate and write a new key to the path.
|
||||
|
||||
If empty, defaults to `file:''${rootDirectory}/keys/periphery.key`.
|
||||
'';
|
||||
example = lib.literalExpression ''
|
||||
# Reference a secret file
|
||||
"file:''${config.age.secrets.komodo-private-key.path}"
|
||||
|
||||
# Or direct path
|
||||
"file:/run/secrets/komodo-private-key"
|
||||
'';
|
||||
};
|
||||
|
||||
corePublicKeys = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
description = ''
|
||||
(v2.0+) Accepted public keys to allow Core(s) to connect.
|
||||
Accepts Spki base64 DER directly or can reference files using `file:/path/to/core.pub` prefix.
|
||||
You can mix direct keys and file references.
|
||||
|
||||
For better security, use the `file:` prefix to reference secret files.
|
||||
'';
|
||||
example = lib.literalExpression ''
|
||||
[
|
||||
# Direct key value
|
||||
"MCowBQYDK2VuAyEATZgrjGHeF0KJUe0+n77+qAWOg3YzEzXOmQWaRgO3OGQ="
|
||||
# Reference secret files
|
||||
"file:''${config.age.secrets.komodo-core1-pub.path}"
|
||||
"file:''${config.age.secrets.komodo-core2-pub.path}"
|
||||
]
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
inbound = {
|
||||
serverEnabled = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.bool;
|
||||
default = null;
|
||||
description = ''
|
||||
Enable the inbound connection server for Core -> Periphery connections.
|
||||
If null, defaults to false when `outbound.coreAddress` is defined, otherwise true.
|
||||
'';
|
||||
};
|
||||
|
||||
port = lib.mkOption {
|
||||
type = lib.types.port;
|
||||
default = 8120;
|
||||
description = "Port for the inbound Periphery server to listen on.";
|
||||
};
|
||||
|
||||
bindIp = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "[::]";
|
||||
description = ''
|
||||
IP address the periphery server will bind to.
|
||||
The default allows external IPv4 and IPv6 connections.
|
||||
'';
|
||||
};
|
||||
|
||||
allowedIps = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
description = ''
|
||||
Limit the IP addresses which can connect to Periphery.
|
||||
Supports IPv4/IPv6 addresses and subnets.
|
||||
Empty list allows all connections.
|
||||
'';
|
||||
example = [
|
||||
"::ffff:12.34.56.78"
|
||||
"10.0.10.0/24"
|
||||
];
|
||||
};
|
||||
|
||||
ssl = {
|
||||
enable = lib.mkEnableOption "(v2.0+) SSL/TLS support for inbound connections" // {
|
||||
default = true;
|
||||
};
|
||||
|
||||
keyFile = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
default = "${cfg.rootDirectory}/ssl/key.pem";
|
||||
defaultText = lib.literalExpression ''"''${config.services.komodo-periphery.rootDirectory}/ssl/key.pem"'';
|
||||
description = ''
|
||||
Path to SSL key file.
|
||||
If the file doesn't exist and SSL is enabled, self-signed keys will be generated using openssl.
|
||||
'';
|
||||
};
|
||||
|
||||
certFile = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
default = "${cfg.rootDirectory}/ssl/cert.pem";
|
||||
defaultText = lib.literalExpression ''"''${config.services.komodo-periphery.rootDirectory}/ssl/cert.pem"'';
|
||||
description = ''
|
||||
Path to SSL certificate file.
|
||||
If the file doesn't exist and SSL is enabled, self-signed certificate will be generated using openssl.
|
||||
'';
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
outbound = {
|
||||
coreAddress = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "";
|
||||
description = ''
|
||||
(v2.0+) The address of Komodo Core. Must be reachable from this host.
|
||||
If provided, Periphery will operate in outbound mode.
|
||||
'';
|
||||
example = "demo.komo.do";
|
||||
};
|
||||
|
||||
connectAs = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "";
|
||||
description = ''
|
||||
(v2.0+) The Server this Periphery agent should connect as.
|
||||
Must match an existing Server name or id.
|
||||
'';
|
||||
example = "server-name";
|
||||
};
|
||||
|
||||
onboardingKeyFile = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.path;
|
||||
default = null;
|
||||
description = ''
|
||||
(v2.0+) Path to file containing the onboarding key.
|
||||
This will be passed via `PERIPHERY_ONBOARDING_KEY_FILE` environment variable.
|
||||
'';
|
||||
example = lib.literalExpression ''"''${config.age.secrets.komodo-onboarding.path}"'';
|
||||
};
|
||||
};
|
||||
|
||||
user = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "komodo-periphery";
|
||||
@@ -503,14 +253,14 @@ in
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
virtualisation.docker.enable = lib.mkDefault (cfg.dockerHost == null);
|
||||
virtualisation.docker.enable = true;
|
||||
|
||||
users.users.${cfg.user} = lib.mkIf (cfg.user == "komodo-periphery") {
|
||||
isSystemUser = true;
|
||||
group = cfg.group;
|
||||
description = "Komodo Periphery service user";
|
||||
home = cfg.rootDirectory;
|
||||
extraGroups = lib.optional (cfg.dockerHost == null) "docker";
|
||||
extraGroups = [ "docker" ];
|
||||
};
|
||||
|
||||
users.groups.${cfg.group} = lib.mkIf (cfg.group == "komodo-periphery") { };
|
||||
@@ -521,26 +271,16 @@ in
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
"${actualRepoDir}".d = {
|
||||
"${cfg.rootDirectory}/repos".d = {
|
||||
mode = "0755";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
"${actualStackDir}".d = {
|
||||
"${cfg.rootDirectory}/stacks".d = {
|
||||
mode = "0755";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
"${actualBuildDir}".d = {
|
||||
mode = "0755";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
"${cfg.rootDirectory}/keys".d = {
|
||||
mode = "0700";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
"${cfg.rootDirectory}/ssl".d = {
|
||||
mode = "0700";
|
||||
user = cfg.user;
|
||||
@@ -552,63 +292,35 @@ in
|
||||
description = "Komodo Periphery - Multi-server Docker and Git deployment agent";
|
||||
after = [
|
||||
"network-online.target"
|
||||
]
|
||||
++ lib.optional (cfg.dockerHost == null) "docker.service";
|
||||
"docker.service"
|
||||
];
|
||||
wants = [
|
||||
"network-online.target"
|
||||
]
|
||||
++ lib.optional (cfg.dockerHost == null) "docker.service";
|
||||
"docker.service"
|
||||
];
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
|
||||
serviceConfig = {
|
||||
Type = "simple";
|
||||
User = cfg.user;
|
||||
Group = cfg.group;
|
||||
SupplementaryGroups = lib.mkIf (cfg.dockerHost == null) [ "docker" ];
|
||||
SupplementaryGroups = [ "docker" ];
|
||||
Restart = "on-failure";
|
||||
RestartSec = "10s";
|
||||
WorkingDirectory = cfg.rootDirectory;
|
||||
|
||||
ExecStart = lib.escapeShellArgs [
|
||||
(lib.getExe' cfg.package "periphery")
|
||||
"${lib.getExe' cfg.package "periphery"}"
|
||||
"--config-path"
|
||||
configFile
|
||||
(if cfg.configFile != null then cfg.configFile else configFile)
|
||||
];
|
||||
|
||||
Environment = lib.mapAttrsToList (name: value: "${name}=${value}") (
|
||||
lib.optionalAttrs (cfg.configFile == null) {
|
||||
PERIPHERY_ROOT_DIRECTORY = cfg.rootDirectory;
|
||||
PERIPHERY_REPO_DIR = actualRepoDir;
|
||||
PERIPHERY_STACK_DIR = actualStackDir;
|
||||
PERIPHERY_BUILD_DIR = actualBuildDir;
|
||||
cfg.environment
|
||||
// lib.optionalAttrs (!cfg.disableTerminals) {
|
||||
PATH = "/run/current-system/sw/bin:/run/wrappers/bin";
|
||||
}
|
||||
// lib.optionalAttrs (cfg.configFile == null && cfg.inbound.ssl.enable) {
|
||||
PERIPHERY_SSL_KEY_FILE = cfg.inbound.ssl.keyFile;
|
||||
PERIPHERY_SSL_CERT_FILE = cfg.inbound.ssl.certFile;
|
||||
}
|
||||
// lib.optionalAttrs (cfg.dockerHost != null) {
|
||||
DOCKER_HOST = cfg.dockerHost;
|
||||
}
|
||||
// lib.optionalAttrs (cfg.passkeyFiles != null) {
|
||||
PERIPHERY_PASSKEYS_FILE = cfg.passkeyFiles;
|
||||
}
|
||||
// lib.optionalAttrs (cfg.auth.privateKey != "") {
|
||||
PERIPHERY_PRIVATE_KEY = cfg.auth.privateKey;
|
||||
}
|
||||
// lib.optionalAttrs (cfg.auth.corePublicKeys != [ ]) {
|
||||
PERIPHERY_CORE_PUBLIC_KEYS = lib.concatStringsSep "," cfg.auth.corePublicKeys;
|
||||
}
|
||||
// lib.optionalAttrs (cfg.outbound.onboardingKeyFile != null) {
|
||||
PERIPHERY_ONBOARDING_KEY_FILE = cfg.outbound.onboardingKeyFile;
|
||||
}
|
||||
// cfg.environment
|
||||
);
|
||||
|
||||
ExecSearchPath = lib.mkIf (!cfg.disableTerminals) [
|
||||
"/run/current-system/sw/bin"
|
||||
"/run/wrappers/bin"
|
||||
];
|
||||
|
||||
EnvironmentFile = lib.mkIf (cfg.environmentFile != null) cfg.environmentFile;
|
||||
|
||||
StateDirectory = "komodo-periphery";
|
||||
@@ -617,7 +329,7 @@ in
|
||||
NoNewPrivileges = true;
|
||||
PrivateTmp = true;
|
||||
ProtectSystem = "full";
|
||||
ProtectHome = "read-only";
|
||||
ProtectHome = true;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
@@ -40,6 +40,7 @@ in
|
||||
config = lib.mkIf cfg.enable {
|
||||
environment.systemPackages = with pkgs; [
|
||||
seatd
|
||||
sdnotify-wrapper
|
||||
];
|
||||
users.groups.seat = lib.mkIf (cfg.group == "seat") { };
|
||||
|
||||
@@ -54,7 +55,7 @@ in
|
||||
Type = "notify";
|
||||
NotifyAccess = "all";
|
||||
SyslogIdentifier = "seatd";
|
||||
ExecStart = "${lib.getExe' pkgs.s6 "s6-notify-socket-from-fd"} ${pkgs.seatd.bin}/bin/seatd -n 1 -u ${cfg.user} -g ${cfg.group} -l ${cfg.logLevel}";
|
||||
ExecStart = "${pkgs.sdnotify-wrapper}/bin/sdnotify-wrapper ${pkgs.seatd.bin}/bin/seatd -n 1 -u ${cfg.user} -g ${cfg.group} -l ${cfg.logLevel}";
|
||||
RestartSec = 1;
|
||||
Restart = "always";
|
||||
};
|
||||
|
||||
@@ -58,17 +58,17 @@ stdenv.mkDerivation {
|
||||
dontConfigure = true;
|
||||
|
||||
buildPhase = ''
|
||||
TARGET_DIR="$out/tmp"
|
||||
TARGET_DIR="$out/etc/opt/brother/scanner/brscan5"
|
||||
mkdir -p "$TARGET_DIR"
|
||||
cp -rp "./models" "$TARGET_DIR"
|
||||
cp -rp "./brscan5.ini" "$TARGET_DIR"
|
||||
cp -rp "./brsanenetdevice.cfg" "$TARGET_DIR"
|
||||
export NIX_REDIRECTS="/etc/opt/brother/scanner/brscan5/=$TARGET_DIR/"
|
||||
printf '${addAllNetDev netDevices}\n'
|
||||
${addAllNetDev netDevices}
|
||||
|
||||
mkdir -p "$out/etc/opt/brother/scanner/brscan5"
|
||||
mv -T "$TARGET_DIR" "$out/etc/opt/brother/scanner/brscan5"
|
||||
export NIX_REDIRECTS="/etc/opt/brother/scanner/brscan5/=$TARGET_DIR/"
|
||||
|
||||
printf '${addAllNetDev netDevices}\n'
|
||||
|
||||
${addAllNetDev netDevices}
|
||||
'';
|
||||
|
||||
dontInstall = true;
|
||||
|
||||
@@ -57,7 +57,7 @@ in
|
||||
default = { };
|
||||
description = ''
|
||||
Configuration options for the Stalwart server.
|
||||
See <https://stalw.art/docs/configuration> for available options.
|
||||
See <https://stalw.art/docs/category/configuration> for available options.
|
||||
|
||||
By default, the module is configured to store everything locally.
|
||||
'';
|
||||
|
||||
@@ -22,23 +22,17 @@ in
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
environment = {
|
||||
# systemd-localed looks into 00-keyboard.conf
|
||||
# systemd-localed does not like if Option values are ""
|
||||
etc."X11/xorg.conf.d/00-keyboard.conf".text =
|
||||
let
|
||||
optionLine =
|
||||
name: value: lib.optionalString (value != null && value != "") ''Option "${name}" "${value}"'';
|
||||
in
|
||||
''
|
||||
Section "InputClass"
|
||||
Identifier "Keyboard catchall"
|
||||
MatchIsKeyboard "on"
|
||||
${optionLine "XkbModel" xcfg.xkb.model}
|
||||
${optionLine "XkbLayout" xcfg.xkb.layout}
|
||||
${optionLine "XkbOptions" xcfg.xkb.options}
|
||||
${optionLine "XkbVariant" xcfg.xkb.variant}
|
||||
EndSection
|
||||
'';
|
||||
# localectl looks into 00-keyboard.conf
|
||||
etc."X11/xorg.conf.d/00-keyboard.conf".text = ''
|
||||
Section "InputClass"
|
||||
Identifier "Keyboard catchall"
|
||||
MatchIsKeyboard "on"
|
||||
Option "XkbModel" "${xcfg.xkb.model}"
|
||||
Option "XkbLayout" "${xcfg.xkb.layout}"
|
||||
Option "XkbOptions" "${xcfg.xkb.options}"
|
||||
Option "XkbVariant" "${xcfg.xkb.variant}"
|
||||
EndSection
|
||||
'';
|
||||
systemPackages = with pkgs; [
|
||||
nixos-icons # needed for gnome and pantheon about dialog, nixos-manual and maybe more
|
||||
xdg-utils
|
||||
|
||||
@@ -460,7 +460,7 @@ in
|
||||
Group = cfg.group;
|
||||
TimeoutSec = "300";
|
||||
WorkingDirectory = "${cfg.package}/share/redmine";
|
||||
ExecStart = "${bundle} exec rails server -u webrick -e production -b ${toString cfg.address} -p ${toString cfg.port}";
|
||||
ExecStart = "${bundle} exec rails server -u webrick -e production -b ${toString cfg.address} -p ${toString cfg.port} -P '${cfg.stateDir}/redmine.pid'";
|
||||
RuntimeDirectory = "redmine";
|
||||
RuntimeDirectoryMode = "0750";
|
||||
AmbientCapabilities = "";
|
||||
|
||||
@@ -94,8 +94,8 @@ in
|
||||
serviceConfig = {
|
||||
ExecStart = ''
|
||||
${pkgs.prometheus-imap-mailstat-exporter}/bin/imap-mailstat-exporter \
|
||||
--config.file="${createConfigFile cfg.accounts}" \
|
||||
${optionalString cfg.oldestUnseenDate "--oldestunseen.feature"} \
|
||||
-config ${createConfigFile cfg.accounts} \
|
||||
${optionalString cfg.oldestUnseenDate "-oldestunseendate"} \
|
||||
${concatStringsSep " \\\n " cfg.extraFlags}
|
||||
'';
|
||||
};
|
||||
|
||||
@@ -102,7 +102,7 @@ in
|
||||
${lib.getExe pkgs.envsubst} \
|
||||
-i ${configuration} \
|
||||
-o ${configFilePath}
|
||||
umask "$old_umask"
|
||||
umask $old_umask
|
||||
'';
|
||||
|
||||
serviceConfig = {
|
||||
|
||||
@@ -6,32 +6,17 @@
|
||||
}:
|
||||
let
|
||||
cfg = config.services.vnstat;
|
||||
settingsFormat = pkgs.formats.keyValue { };
|
||||
in
|
||||
{
|
||||
options.services.vnstat = {
|
||||
enable = lib.mkEnableOption "update of network usage statistics via vnstatd";
|
||||
package = lib.mkPackageOption pkgs "vnstat" { };
|
||||
settings = lib.mkOption {
|
||||
type = lib.types.submodule { freeformType = settingsFormat.type; };
|
||||
default = { };
|
||||
description = ''
|
||||
Configuration for vnstat. Refer to
|
||||
[https://humdi.net/vnstat/man/vnstat.conf.html]
|
||||
or {manpage}`vnstat.conf(5)` for more information.
|
||||
'';
|
||||
example = {
|
||||
AlwaysAddNewInterfaces = 1;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
|
||||
environment.systemPackages = [ cfg.package ];
|
||||
|
||||
environment.etc."vnstat.conf".source = settingsFormat.generate "vnstat.conf" cfg.settings;
|
||||
|
||||
users = {
|
||||
groups.vnstatd = { };
|
||||
|
||||
@@ -74,8 +59,4 @@ in
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
meta = {
|
||||
maintainers = with lib.maintainers; [ hmenke ];
|
||||
};
|
||||
}
|
||||
|
||||
@@ -132,7 +132,7 @@ in
|
||||
description = "socket for fast remote file copy program daemon";
|
||||
conflicts = [ "rsync.service" ];
|
||||
|
||||
listenStreams = [ cfg.port ];
|
||||
listenStreams = [ (toString cfg.port) ];
|
||||
socketConfig.Accept = true;
|
||||
|
||||
wantedBy = [ "sockets.target" ];
|
||||
|
||||
@@ -44,7 +44,7 @@ in
|
||||
settings = mkOption {
|
||||
description = ''
|
||||
Headplane configuration options. Generates a YAML config file.
|
||||
See <https://github.com/tale/headplane/blob/main/config.example.yaml>.
|
||||
See: https://github.com/tale/headplane/blob/main/config.example.yaml
|
||||
'';
|
||||
type = types.submodule {
|
||||
options = {
|
||||
@@ -129,16 +129,6 @@ in
|
||||
headscale = mkOption {
|
||||
type = types.submodule {
|
||||
options = {
|
||||
api_key_path = mkOption {
|
||||
type = types.nullOr types.path;
|
||||
default = null;
|
||||
description = ''
|
||||
Path to a file containing a Headscale API key.
|
||||
This is required for OIDC authentication aswell for the Headplane agent.
|
||||
'';
|
||||
example = lib.literalExpression "config.sops.secrets.headplane_pre_authkey.path";
|
||||
};
|
||||
|
||||
url = mkOption {
|
||||
type = types.str;
|
||||
default = "http://127.0.0.1:${toString config.services.headscale.port}";
|
||||
@@ -221,6 +211,15 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
pre_authkey_path = mkOption {
|
||||
type = types.nullOr types.path;
|
||||
default = null;
|
||||
description = ''
|
||||
Path to a file containing a Headscale pre-auth key for the agent.
|
||||
'';
|
||||
example = lib.literalExpression "config.sops.secrets.headplane_pre_authkey.path";
|
||||
};
|
||||
|
||||
executable_path = mkOption {
|
||||
type = types.path;
|
||||
readOnly = true;
|
||||
@@ -238,14 +237,20 @@ in
|
||||
};
|
||||
|
||||
cache_ttl = mkOption {
|
||||
type = types.ints.positive;
|
||||
default = 180000;
|
||||
type = types.nullOr types.int;
|
||||
default = null;
|
||||
description = ''
|
||||
How long to cache agent information (in milliseconds).
|
||||
If you want data to update faster, reduce the TTL, but this will increase the frequency of requests to Headscale.
|
||||
Deprecated cache TTL for the agent. This option is accepted
|
||||
by Headplane 0.6.2 but has no effect.
|
||||
'';
|
||||
};
|
||||
|
||||
cache_path = mkOption {
|
||||
type = types.path;
|
||||
default = "/var/lib/headplane/agent_cache.json";
|
||||
description = "The path to store the agent's cache.";
|
||||
};
|
||||
|
||||
work_dir = mkOption {
|
||||
type = types.path;
|
||||
default = "/var/lib/headplane/agent";
|
||||
@@ -320,6 +325,16 @@ in
|
||||
example = lib.literalExpression "config.sops.secrets.oidc_client_secret.path";
|
||||
};
|
||||
|
||||
headscale_api_key_path = mkOption {
|
||||
type = types.nullOr types.path;
|
||||
default = null;
|
||||
description = ''
|
||||
Path to a file containing the Headscale API key.
|
||||
Required for OIDC authentication.
|
||||
'';
|
||||
example = lib.literalExpression "config.sops.secrets.headscale_api_key.path";
|
||||
};
|
||||
|
||||
disable_api_key_login = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
@@ -351,6 +366,25 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
redirect_uri = mkOption {
|
||||
type = types.nullOr types.str;
|
||||
default = null;
|
||||
description = ''
|
||||
Deprecated OIDC redirect URI. Use services.headplane.settings.server.base_url
|
||||
instead; Headplane derives the callback URL from it.
|
||||
'';
|
||||
example = "https://headplane.example.com/admin/oidc/callback";
|
||||
};
|
||||
|
||||
strict_validation = mkOption {
|
||||
type = types.nullOr types.bool;
|
||||
default = null;
|
||||
description = ''
|
||||
Deprecated OIDC validation setting. This option is accepted
|
||||
by Headplane 0.6.2 but has no effect.
|
||||
'';
|
||||
};
|
||||
|
||||
profile_picture_source = mkOption {
|
||||
type = types.enum [
|
||||
"oidc"
|
||||
@@ -395,6 +429,16 @@ in
|
||||
description = "Custom userinfo endpoint URL.";
|
||||
example = "https://provider.example.com/userinfo";
|
||||
};
|
||||
|
||||
user_storage_file = mkOption {
|
||||
type = types.nullOr types.path;
|
||||
default = null;
|
||||
description = ''
|
||||
Deprecated path to the pre-0.6.2 JSON user database.
|
||||
Headplane uses this once to migrate users into its internal database.
|
||||
'';
|
||||
example = "/var/lib/headplane/users.json";
|
||||
};
|
||||
};
|
||||
}
|
||||
);
|
||||
@@ -408,6 +452,33 @@ in
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
warnings =
|
||||
lib.optionals (cfg.settings.oidc != null && cfg.settings.oidc.redirect_uri != null) [
|
||||
''
|
||||
services.headplane.settings.oidc.redirect_uri is deprecated by Headplane 0.6.2.
|
||||
Use services.headplane.settings.server.base_url instead; Headplane derives
|
||||
the OIDC callback URL from it.
|
||||
''
|
||||
]
|
||||
++ lib.optionals (cfg.settings.oidc != null && cfg.settings.oidc.strict_validation != null) [
|
||||
''
|
||||
services.headplane.settings.oidc.strict_validation is deprecated and has no effect
|
||||
in Headplane 0.6.2.
|
||||
''
|
||||
]
|
||||
++ lib.optionals (cfg.settings.oidc != null && cfg.settings.oidc.user_storage_file != null) [
|
||||
''
|
||||
services.headplane.settings.oidc.user_storage_file is deprecated. Headplane 0.6.2
|
||||
uses it only to migrate the pre-0.6.2 JSON user database into the internal database.
|
||||
''
|
||||
]
|
||||
++ lib.optionals (agentSettings != null && agentSettings.cache_ttl != null) [
|
||||
''
|
||||
services.headplane.settings.integration.agent.cache_ttl is deprecated and has no
|
||||
effect in Headplane 0.6.2.
|
||||
''
|
||||
];
|
||||
|
||||
assertions = [
|
||||
{
|
||||
assertion = config.services.headscale.enable;
|
||||
@@ -431,25 +502,26 @@ in
|
||||
'';
|
||||
}
|
||||
{
|
||||
assertion = cfg.settings.oidc == null || cfg.settings.headscale.api_key_path != null;
|
||||
assertion = cfg.settings.oidc == null || cfg.settings.oidc.headscale_api_key_path != null;
|
||||
message = ''
|
||||
services.headplane.settings.headscale.api_key_path must be set
|
||||
when services.headplane.settings.oidc is non-null.
|
||||
Headplane's OIDC flow requires a Headscale API key to mint sessions.
|
||||
services.headplane.settings.oidc.headscale_api_key_path must be set
|
||||
when services.headplane.settings.oidc is non-null. Headplane's OIDC
|
||||
flow requires a Headscale API key to mint sessions.
|
||||
'';
|
||||
}
|
||||
{
|
||||
assertion =
|
||||
agentSettings == null || !agentSettings.enabled || cfg.settings.headscale.api_key_path != null;
|
||||
agentSettings == null || !agentSettings.enabled || agentSettings.pre_authkey_path != null;
|
||||
message = ''
|
||||
services.headplane.settings.headscale.api_key_path must be set when the agent is enabled.
|
||||
services.headplane.settings.integration.agent.pre_authkey_path must be set
|
||||
when the agent is enabled.
|
||||
'';
|
||||
}
|
||||
];
|
||||
|
||||
environment = {
|
||||
systemPackages = [ cfg.package ];
|
||||
etc."headplane/config.yaml".source = settingsFile;
|
||||
etc."headplane/config.yaml".source = "${settingsFile}";
|
||||
};
|
||||
|
||||
systemd.services.headplane = {
|
||||
@@ -462,7 +534,6 @@ in
|
||||
config.systemd.services.headscale.name
|
||||
];
|
||||
requires = [ config.systemd.services.headscale.name ];
|
||||
restartTriggers = [ settingsFile ];
|
||||
|
||||
environment = {
|
||||
HEADPLANE_DEBUG_LOG = toString cfg.debug;
|
||||
|
||||
@@ -93,8 +93,8 @@ in
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
|
||||
warnings = mkIf (!config.systemd.network.enable) [
|
||||
"services.networkd-dispatcher will not execute any scripts unless networkd is enabled, either via `systemd.network.enable` or via `networking.useNetworkd`."
|
||||
warnings = mkIf (!config.networking.useNetworkd) [
|
||||
"services.networkd-dispatcher will not execute any scripts unless networking.useNetworkd is enabled."
|
||||
];
|
||||
|
||||
systemd = {
|
||||
|
||||
@@ -232,10 +232,6 @@ in
|
||||
"openssh"
|
||||
"banner"
|
||||
] "Use services.openssh.settings.Banner instead.")
|
||||
(lib.mkRenamedOptionModule
|
||||
[ "services" "openssh" "moduliFile" ]
|
||||
[ "services" "openssh" "settings" "ModuliFile" ]
|
||||
)
|
||||
];
|
||||
|
||||
###### interface
|
||||
@@ -733,14 +729,6 @@ in
|
||||
'';
|
||||
example = "/etc/ssh/banner";
|
||||
};
|
||||
ModuliFile = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
default = "${config.services.openssh.package}/etc/ssh/moduli";
|
||||
defaultText = lib.literalExpression ''"''${config.services.openssh.package}/etc/ssh/moduli"'';
|
||||
description = ''
|
||||
Specifies the {manpage}`moduli(5)` file to use for Diffie-Hellman key exchange.
|
||||
'';
|
||||
};
|
||||
};
|
||||
}
|
||||
);
|
||||
@@ -752,6 +740,16 @@ in
|
||||
description = "Verbatim contents of {file}`sshd_config`.";
|
||||
};
|
||||
|
||||
moduliFile = lib.mkOption {
|
||||
example = "/etc/my-local-ssh-moduli;";
|
||||
type = lib.types.path;
|
||||
description = ''
|
||||
Path to `moduli` file to install in
|
||||
`/etc/ssh/moduli`. If this option is unset, then
|
||||
the `moduli` file shipped with OpenSSH will be used.
|
||||
'';
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
users.users = lib.mkOption {
|
||||
@@ -772,12 +770,14 @@ in
|
||||
};
|
||||
users.groups.sshd = { };
|
||||
|
||||
services.openssh.moduliFile = lib.mkDefault "${cfg.package}/etc/ssh/moduli";
|
||||
services.openssh.sftpServerExecutable = lib.mkDefault "${cfg.package}/libexec/sftp-server";
|
||||
|
||||
environment.etc =
|
||||
authKeysFiles
|
||||
// authPrincipalsFiles
|
||||
// {
|
||||
"ssh/moduli".source = cfg.moduliFile;
|
||||
"ssh/sshd_config".source = sshconf;
|
||||
};
|
||||
|
||||
|
||||
@@ -268,6 +268,15 @@ let
|
||||
};
|
||||
};
|
||||
|
||||
writeOidcJwksConfigFile =
|
||||
oidcIssuerPrivateKeyFile:
|
||||
pkgs.writeText "oidc-jwks.yaml" ''
|
||||
identity_providers:
|
||||
oidc:
|
||||
jwks:
|
||||
- key: {{ secret "${oidcIssuerPrivateKeyFile}" | mindent 10 "|" | msquote }}
|
||||
'';
|
||||
|
||||
# Remove an attribute in a nested set
|
||||
# https://discourse.nixos.org/t/modify-an-attrset-in-nix/29919/5
|
||||
removeAttrByPath =
|
||||
@@ -353,12 +362,7 @@ in
|
||||
execCommand = "${instance.package}/bin/authelia";
|
||||
configFile = format.generate "config.yml" cleanedSettings;
|
||||
oidcJwksConfigFile = lib.optional (instance.secrets.oidcIssuerPrivateKeyFile != null) (
|
||||
pkgs.writeText "oidc-jwks.yaml" ''
|
||||
identity_providers:
|
||||
oidc:
|
||||
jwks:
|
||||
- key: {{ mustEnv "CREDENTIALS_DIRECTORY" | printf "%s/oidcIssuerPrivateKeyFile" | secret | mindent 10 "|" | msquote }}
|
||||
''
|
||||
writeOidcJwksConfigFile instance.secrets.oidcIssuerPrivateKeyFile
|
||||
);
|
||||
configArg = "--config ${
|
||||
builtins.concatStringsSep "," (
|
||||
@@ -369,25 +373,21 @@ in
|
||||
]
|
||||
)
|
||||
}";
|
||||
# Mapping between the Authelia env variables and the secret keys defined in the module
|
||||
envSecretsMap = {
|
||||
AUTHELIA_IDENTITY_VALIDATION_RESET_PASSWORD_JWT_SECRET_FILE = "jwtSecretFile";
|
||||
AUTHELIA_STORAGE_ENCRYPTION_KEY_FILE = "storageEncryptionKeyFile";
|
||||
AUTHELIA_SESSION_SECRET_FILE = "sessionSecretFile";
|
||||
AUTHELIA_IDENTITY_PROVIDERS_OIDC_HMAC_SECRET_FILE = "oidcHmacSecretFile";
|
||||
};
|
||||
nonNullEnvSecretsMap = lib.filterAttrs (_: v: instance.secrets.${v} != null) envSecretsMap;
|
||||
in
|
||||
{
|
||||
description = "Authelia authentication and authorization server";
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
after = [ "network-online.target" ]; # Checks SMTP notifier creds during startup
|
||||
wants = [ "network-online.target" ];
|
||||
environment = {
|
||||
X_AUTHELIA_CONFIG_FILTERS = lib.mkIf (oidcJwksConfigFile != [ ]) "template";
|
||||
}
|
||||
// lib.mapAttrs (_: v: "%d/${v}") nonNullEnvSecretsMap
|
||||
// instance.environmentVariables;
|
||||
environment =
|
||||
(lib.filterAttrs (_: v: v != null) {
|
||||
X_AUTHELIA_CONFIG_FILTERS = lib.mkIf (oidcJwksConfigFile != [ ]) "template";
|
||||
AUTHELIA_IDENTITY_VALIDATION_RESET_PASSWORD_JWT_SECRET_FILE = instance.secrets.jwtSecretFile;
|
||||
AUTHELIA_STORAGE_ENCRYPTION_KEY_FILE = instance.secrets.storageEncryptionKeyFile;
|
||||
AUTHELIA_SESSION_SECRET_FILE = instance.secrets.sessionSecretFile;
|
||||
AUTHELIA_IDENTITY_PROVIDERS_OIDC_HMAC_SECRET_FILE = instance.secrets.oidcHmacSecretFile;
|
||||
})
|
||||
// instance.environmentVariables;
|
||||
|
||||
preStart = "${execCommand} ${configArg} validate-config";
|
||||
serviceConfig = {
|
||||
@@ -399,12 +399,6 @@ in
|
||||
StateDirectory = autheliaName instance.name;
|
||||
StateDirectoryMode = "0700";
|
||||
|
||||
LoadCredential =
|
||||
lib.optional (
|
||||
instance.secrets.oidcIssuerPrivateKeyFile != null
|
||||
) "oidcIssuerPrivateKeyFile:${instance.secrets.oidcIssuerPrivateKeyFile}"
|
||||
++ lib.mapAttrsToList (_: v: "${v}:${instance.secrets.${v}}") nonNullEnvSecretsMap;
|
||||
|
||||
# Security options:
|
||||
AmbientCapabilities = "";
|
||||
CapabilityBoundingSet = "";
|
||||
|
||||
@@ -86,7 +86,7 @@ in
|
||||
The primary motivation for this is an immutable `/etc`, where we cannot
|
||||
write the files directly to `/etc`.
|
||||
|
||||
However this can also serve other use cases, e.g. when `/etc` is on a `tmpfs`.
|
||||
However this an also serve other use cases, e.g. when `/etc` is on a `tmpfs`.
|
||||
'';
|
||||
};
|
||||
|
||||
|
||||
@@ -149,6 +149,13 @@ in
|
||||
|
||||
protocol.encryption.set = allow_incoming,try_outgoing,enable_retry
|
||||
|
||||
# Limits for file handle resources, this is optimized for
|
||||
# an `ulimit` of 1024 (a common default). You MUST leave
|
||||
# a ceiling of handles reserved for rTorrent's internal needs!
|
||||
network.http.max_open.set = 50
|
||||
network.max_open_files.set = 600
|
||||
network.max_open_sockets.set = 3000
|
||||
|
||||
# Memory resource usage (increase if you have a large number of items loaded,
|
||||
# and/or the available resources to spend)
|
||||
pieces.memory.max.set = 1800M
|
||||
@@ -162,14 +169,15 @@ in
|
||||
execute.nothrow = sh, -c, (cat, "echo >", (session.path), "rtorrent.pid", " ", (system.pid))
|
||||
|
||||
# Other operational settings (check & adapt)
|
||||
encoding.add = utf8
|
||||
system.umask.set = 0027
|
||||
system.cwd.set = (cfg.basedir)
|
||||
network.http.dns_cache_timeout.set = 25
|
||||
schedule = monitor_diskspace, 15, 60, ((close_low_diskspace, 1000M))
|
||||
schedule2 = monitor_diskspace, 15, 60, ((close_low_diskspace, 1000M))
|
||||
|
||||
# Watch directories (add more as you like, but use unique schedule names)
|
||||
#schedule = watch_start, 10, 10, ((load.start, (cat, (cfg.watch), "start/*.torrent")))
|
||||
#schedule = watch_load, 11, 10, ((load.normal, (cat, (cfg.watch), "load/*.torrent")))
|
||||
#schedule2 = watch_start, 10, 10, ((load.start, (cat, (cfg.watch), "start/*.torrent")))
|
||||
#schedule2 = watch_load, 11, 10, ((load.normal, (cat, (cfg.watch), "load/*.torrent")))
|
||||
|
||||
# Logging:
|
||||
# Levels = critical error warn notice info debug
|
||||
@@ -210,10 +218,6 @@ in
|
||||
RuntimeDirectory = "rtorrent";
|
||||
RuntimeDirectoryMode = 750;
|
||||
|
||||
# rtorrent derives socket limits from this value since 0.16.15; see table in
|
||||
# https://github.com/rakshasa/rtorrent/wiki/Socket-Manager-and-Resource-Allocation
|
||||
LimitNOFILE = lib.mkDefault 16384;
|
||||
|
||||
CapabilityBoundingSet = [ "" ];
|
||||
LockPersonality = true;
|
||||
NoNewPrivileges = true;
|
||||
|
||||
@@ -169,25 +169,11 @@ in
|
||||
enable = true;
|
||||
virtualHosts."${cfg.virtualHost.domain}".extraConfig = ''
|
||||
root * ${cfg.package}
|
||||
encode zstd gzip
|
||||
|
||||
@immutable path /resources/*
|
||||
header @immutable Cache-Control "public, max-age=31536000, immutable"
|
||||
|
||||
@html not path /resources/*
|
||||
header @html Cache-Control "no-store"
|
||||
|
||||
header {
|
||||
-ETag
|
||||
-Last-Modified
|
||||
}
|
||||
|
||||
file_server
|
||||
handle_path /assets/config.yml {
|
||||
root * ${configFile}
|
||||
file_server
|
||||
}
|
||||
|
||||
file_server
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
@@ -134,40 +134,6 @@ in
|
||||
Type = "simple";
|
||||
Restart = "on-failure";
|
||||
RestartSec = 3;
|
||||
|
||||
# systemd hardening, based on jellyfin (also .NET) but stricter
|
||||
CapabilityBoundingSet = [ "" ];
|
||||
DevicePolicy = "closed";
|
||||
LockPersonality = true;
|
||||
NoNewPrivileges = true;
|
||||
PrivateDevices = true;
|
||||
PrivateUsers = true;
|
||||
ProcSubset = "pid";
|
||||
ProtectClock = true;
|
||||
ProtectControlGroups = !config.boot.isContainer;
|
||||
ProtectHome = true;
|
||||
ProtectHostname = true;
|
||||
ProtectKernelLogs = true;
|
||||
ProtectKernelModules = !config.boot.isContainer;
|
||||
ProtectKernelTunables = !config.boot.isContainer;
|
||||
ProtectProc = "invisible";
|
||||
ProtectSystem = "strict";
|
||||
# no AF_NETLINK here since there's no network connection monitoring
|
||||
RestrictAddressFamilies = [
|
||||
"AF_INET"
|
||||
"AF_INET6"
|
||||
"AF_UNIX"
|
||||
];
|
||||
RestrictNamespaces = !config.boot.isContainer;
|
||||
RestrictRealtime = true;
|
||||
RestrictSUIDSGID = true;
|
||||
SystemCallArchitectures = "native";
|
||||
SystemCallErrorNumber = "EPERM";
|
||||
SystemCallFilter = [
|
||||
"@system-service"
|
||||
"~@privileged"
|
||||
];
|
||||
UMask = "0077";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
@@ -34,7 +34,7 @@ in
|
||||
host = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "127.0.0.1";
|
||||
description = "The IP to host on. Use 0.0.0.0 to expose on all network adapters.";
|
||||
description = "The IP to host on. Use 0.0.0.0 to expose on all adapters.";
|
||||
};
|
||||
|
||||
port = lib.mkOption {
|
||||
@@ -46,22 +46,13 @@ in
|
||||
disable_auth = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = ''
|
||||
Disable HTTP token authentication with requests.
|
||||
WARNING: This will make your instance vulnerable! Only turn this on if you are ONLY connecting from localhost.
|
||||
'';
|
||||
};
|
||||
|
||||
disable_fetch_requests = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "Disable fetching external content in response to requests, such as images from URLs.";
|
||||
description = "Disable HTTP token authentication. WARNING: Vulnerable if exposed.";
|
||||
};
|
||||
|
||||
api_servers = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ "OAI" ];
|
||||
description = "Select API servers to enable. Possible values: OAI, Kobold.";
|
||||
description = "Select API servers to enable. Options: OAI, Kobold.";
|
||||
};
|
||||
};
|
||||
|
||||
@@ -75,18 +66,7 @@ in
|
||||
log_requests = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "Enable request logging. NOTE: Only use this for debugging!";
|
||||
};
|
||||
|
||||
log_chat_completion_requests = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = ''
|
||||
Write every /v1/chat/completions request to logs/debug/ as JSON.
|
||||
PRIVACY WARNING: Enabling this creates a comprehensive request log, including the
|
||||
full message history and generation parameters. API keys are redacted, but prompts
|
||||
and user-provided content are preserved for bug-report reproduction.
|
||||
'';
|
||||
description = "Enable request logging. Only use for debug.";
|
||||
};
|
||||
};
|
||||
|
||||
@@ -131,94 +111,35 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
inline_model_loading = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = ''
|
||||
Allow direct loading of models from a completion or chat completion request.
|
||||
This method of loading is strict by default; enable dummy models to add
|
||||
exceptions for invalid model names.
|
||||
'';
|
||||
};
|
||||
|
||||
model_name = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.str;
|
||||
default = null;
|
||||
description = ''
|
||||
An initial model to load. Make sure the model is located in the model directory!
|
||||
REQUIRED: This must be filled out to load a model on startup.
|
||||
'';
|
||||
description = "The initial model to load on startup. Must exist in model_dir.";
|
||||
example = "Qwen3_5-9B";
|
||||
};
|
||||
|
||||
max_seq_len = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.int;
|
||||
default = null;
|
||||
description = ''
|
||||
Max sequence length (default: min(max_position_embeddings, cache_size)).
|
||||
Set to -1 to fetch from the model's config.json.
|
||||
'';
|
||||
description = "Max sequence length. Set null to use model defaults.";
|
||||
};
|
||||
|
||||
cache_mode = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "FP16";
|
||||
description = ''
|
||||
Enable different cache modes for VRAM savings.
|
||||
Specify the pair k_bits,v_bits where k_bits and v_bits are integers from 2-8 (e.g. '8,8').
|
||||
The legacy values 'FP16', 'Q8', 'Q6', 'Q4' are also accepted.
|
||||
'';
|
||||
};
|
||||
|
||||
tensor_parallel = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = ''
|
||||
Load model with tensor parallelism.
|
||||
Falls back to autosplit if GPU split isn't provided. This ignores the gpu_split_auto value.
|
||||
'';
|
||||
description = "Cache mode for VRAM savings. ExLlamaV2: FP16, Q8, Q6, Q4. ExLlamaV3: specific pair string (e.g., '8,8').";
|
||||
};
|
||||
|
||||
gpu_split_auto = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = true;
|
||||
description = "Automatically allocate resources to GPUs. Not parsed for single GPU users.";
|
||||
description = "Automatically allocate resources to GPUs.";
|
||||
};
|
||||
|
||||
dummy_model_names = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ "gpt-3.5-turbo" ];
|
||||
description = ''
|
||||
A list of fake model names that are sent via the /v1/models endpoint.
|
||||
Also used as bypasses for strict mode if inline_model_loading is true.
|
||||
'';
|
||||
};
|
||||
|
||||
vision = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "Enables vision support if the model supports it.";
|
||||
};
|
||||
|
||||
reasoning = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = ''
|
||||
Enable reasoning parser.
|
||||
Do NOT enable this if the model is not a reasoning model (e.g. deepseek-r1 series).
|
||||
'';
|
||||
};
|
||||
|
||||
reasoning_start_token = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "<think>";
|
||||
description = "The start token for reasoning content.";
|
||||
};
|
||||
|
||||
reasoning_end_token = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "</think>";
|
||||
description = "The end token for reasoning content.";
|
||||
description = "List of fake model names sent via the /v1/models endpoint.";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
@@ -1,151 +0,0 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.services.rustfs;
|
||||
in
|
||||
{
|
||||
meta.maintainers = with lib.maintainers; [
|
||||
marcel
|
||||
];
|
||||
|
||||
options.services.rustfs = {
|
||||
enable = lib.mkEnableOption "RustFS Object Storage Server";
|
||||
|
||||
package = lib.mkPackageOption pkgs "rustfs" { };
|
||||
|
||||
user = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "rustfs";
|
||||
description = "The user RustFS should run as.";
|
||||
};
|
||||
|
||||
group = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "rustfs";
|
||||
description = "The group RustFS should run as.";
|
||||
};
|
||||
|
||||
settings = lib.mkOption {
|
||||
default = { };
|
||||
description = ''
|
||||
Options for RustFS configuration. Refer to
|
||||
<https://docs.rustfs.com/installation/linux/single-node-single-disk.html#_5-configure-environment-variables>
|
||||
for details on supported values.
|
||||
'';
|
||||
example = lib.literalExpression ''
|
||||
{
|
||||
RUSTFS_CONSOLE_ENABLE = "true";
|
||||
RUSTFS_VOLUMES = "/mnt/rustfs";
|
||||
}
|
||||
'';
|
||||
type = lib.types.submodule {
|
||||
freeformType = lib.types.attrsOf (
|
||||
lib.types.oneOf [
|
||||
lib.types.str
|
||||
lib.types.int
|
||||
]
|
||||
);
|
||||
options = {
|
||||
RUSTFS_VOLUMES = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
default = "/var/lib/rustfs";
|
||||
description = "The directory where RustFS stores it's data.";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
environmentFile = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
description = "Path to environment file containing secrets like RUSTFS_ACCESS_KEY or RUSTFS_SECRET_KEY.";
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
assertions = [
|
||||
{
|
||||
assertion = !(cfg.settings ? RUSTFS_ACCESS_KEY);
|
||||
message = "RUSTFS_ACCESS_KEY must not be set in services.rustfs.settings. Use environmentFile instead.";
|
||||
}
|
||||
{
|
||||
assertion = !(cfg.settings ? RUSTFS_SECRET_KEY);
|
||||
message = "RUSTFS_SECRET_KEY must not be set in services.rustfs.settings. Use environmentFile instead.";
|
||||
}
|
||||
];
|
||||
|
||||
systemd = {
|
||||
tmpfiles.settings."10-rustfs".${cfg.settings.RUSTFS_VOLUMES}.d = {
|
||||
inherit (cfg) user group;
|
||||
};
|
||||
|
||||
# https://docs.rustfs.com/installation/linux/single-node-single-disk.html#_6-configure-system-service
|
||||
services.rustfs = {
|
||||
description = "RustFS Object Storage Server";
|
||||
documentation = [ "https://rustfs.com/docs/" ];
|
||||
|
||||
after = [ "network-online.target" ];
|
||||
wants = [ "network-online.target" ];
|
||||
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
|
||||
environment = cfg.settings;
|
||||
|
||||
preStart = ''
|
||||
if [ -z "$RUSTFS_ACCESS_KEY" ] || [ -z "$RUSTFS_SECRET_KEY" ]; then
|
||||
echo "RustFS uses well-known default values for RUSTFS_ACCESS_KEY and RUSTFS_SECRET_KEY,"
|
||||
echo "please configure them using services.rustfs.environmentFile."
|
||||
exit 1
|
||||
fi
|
||||
'';
|
||||
|
||||
serviceConfig = {
|
||||
Type = "notify";
|
||||
NotifyAccess = "main";
|
||||
User = cfg.user;
|
||||
Group = cfg.group;
|
||||
|
||||
EnvironmentFile = cfg.environmentFile;
|
||||
ExecStart = lib.getExe cfg.package;
|
||||
|
||||
LimitNOFILE = 1048576;
|
||||
LimitNPROC = 32768;
|
||||
TasksMax = "infinity";
|
||||
|
||||
Restart = "always";
|
||||
RestartSec = "10s";
|
||||
|
||||
OOMScoreAdjust = "-1000";
|
||||
SendSIGKILL = false;
|
||||
|
||||
TimeoutStartSec = "30s";
|
||||
TimeoutStopSec = "30s";
|
||||
|
||||
NoNewPrivileges = true;
|
||||
|
||||
ProtectHome = true;
|
||||
PrivateTmp = true;
|
||||
PrivateDevices = true;
|
||||
ProtectClock = true;
|
||||
ProtectKernelTunables = true;
|
||||
ProtectKernelModules = true;
|
||||
ProtectControlGroups = true;
|
||||
RestrictSUIDSGID = true;
|
||||
RestrictRealtime = true;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
users = {
|
||||
users.${cfg.user} = {
|
||||
isSystemUser = true;
|
||||
inherit (cfg) group;
|
||||
};
|
||||
groups.${cfg.group} = { };
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -68,7 +68,7 @@ let
|
||||
|
||||
configFile = pkgs.writeText "plymouthd.conf" ''
|
||||
[Daemon]
|
||||
ShowDelay=${toString cfg.showDelay}
|
||||
ShowDelay=0
|
||||
DeviceTimeout=8
|
||||
Theme=${cfg.theme}
|
||||
${cfg.extraConfig}
|
||||
@@ -166,15 +166,6 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
showDelay = mkOption {
|
||||
type = types.numbers.nonnegative;
|
||||
default = 0;
|
||||
example = 0.5;
|
||||
description = ''
|
||||
Time (in seconds) to delay the splash screen.
|
||||
'';
|
||||
};
|
||||
|
||||
extraConfig = mkOption {
|
||||
type = types.lines;
|
||||
default = "";
|
||||
|
||||
@@ -27,8 +27,6 @@ in
|
||||
"${cfg.package}/lib/udev/fido_id"
|
||||
"${cfg.package}/lib/cryptsetup/libcryptsetup-token-systemd-fido2.so"
|
||||
"${pkgs.libfido2}/lib/libfido2.so.1"
|
||||
# dlopened by the libpcsclite.so.1 shim, invisible to make-initrd-ng
|
||||
"${lib.getLib pkgs.pcsclite}/lib/libpcsclite_real.so.1"
|
||||
];
|
||||
};
|
||||
}
|
||||
|
||||
@@ -45,7 +45,6 @@
|
||||
"systemd-tpm2-setup.service"
|
||||
"systemd-pcrextend.socket"
|
||||
"systemd-pcrextend@.service"
|
||||
"systemd-pcrlogin@.service"
|
||||
];
|
||||
}
|
||||
)
|
||||
|
||||
@@ -201,7 +201,7 @@ rec {
|
||||
(onFullSupported "nixos.tests.printing-socket")
|
||||
(onFullSupported "nixos.tests.proxy")
|
||||
(onFullSupported "nixos.tests.sddm.default")
|
||||
(onFullSupported "nixos.tests.shadow.login")
|
||||
(onFullSupported "nixos.tests.shadow")
|
||||
(onFullSupported "nixos.tests.simple-container")
|
||||
(onFullSupported "nixos.tests.simple-vm")
|
||||
(onFullSupported "nixos.tests.sway")
|
||||
|
||||
@@ -1512,7 +1512,6 @@ in
|
||||
rtkit = runTest ./rtkit.nix;
|
||||
rtorrent = runTest ./rtorrent.nix;
|
||||
rush = runTest ./rush.nix;
|
||||
rustfs = runTest ./rustfs.nix;
|
||||
rustical = runTest ./web-apps/rustical.nix;
|
||||
rustls-libssl = runTest ./rustls-libssl.nix;
|
||||
rxe = runTest ./rxe.nix;
|
||||
@@ -1540,7 +1539,7 @@ in
|
||||
sftpgo = runTest ./sftpgo.nix;
|
||||
sfxr-qt = runTest ./sfxr-qt.nix;
|
||||
sgt-puzzles = runTest ./sgt-puzzles.nix;
|
||||
shadow = import ./shadow { inherit runTest; };
|
||||
shadow = runTest ./shadow.nix;
|
||||
shadowsocks = handleTest ./shadowsocks { };
|
||||
shadps4 = runTest ./shadps4.nix;
|
||||
sharkey = runTest ./web-apps/sharkey.nix;
|
||||
@@ -1586,8 +1585,6 @@ in
|
||||
sssd-ldap = handleTestOn [ "x86_64-linux" "aarch64-linux" ] ./sssd-ldap.nix { };
|
||||
sssd-legacy-config = handleTestOn [ "x86_64-linux" "aarch64-linux" ] ./sssd-legacy-config.nix { };
|
||||
stalwart = runTest ./stalwart/stalwart.nix;
|
||||
stardust-xr-atmosphere = runTest ./stardust-xr/atmosphere.nix;
|
||||
stardust-xr-flatland = runTest ./stardust-xr/flatland.nix;
|
||||
stargazer = runTest ./web-servers/stargazer.nix;
|
||||
starship = runTest ./starship.nix;
|
||||
startx = import ./startx.nix { inherit pkgs runTest; };
|
||||
@@ -1687,7 +1684,6 @@ in
|
||||
systemd-journal = runTest ./systemd-journal.nix;
|
||||
systemd-journal-gateway = runTest ./systemd-journal-gateway.nix;
|
||||
systemd-journal-upload = runTest ./systemd-journal-upload.nix;
|
||||
systemd-localed = runTest ./systemd-localed.nix;
|
||||
systemd-lock-handler = runTestOn [ "aarch64-linux" "x86_64-linux" ] ./systemd-lock-handler.nix;
|
||||
systemd-machinectl = runTest ./systemd-machinectl.nix;
|
||||
systemd-misc = runTest ./systemd-misc.nix;
|
||||
@@ -1846,7 +1842,6 @@ in
|
||||
};
|
||||
virtualbox = handleTestOn [ "x86_64-linux" ] ./virtualbox.nix { };
|
||||
vm-variant = handleTest ./vm-variant.nix { };
|
||||
vnstat = runTest ./vnstat.nix;
|
||||
vscode-remote-ssh = handleTestOn [ "x86_64-linux" ] ./vscode-remote-ssh.nix { };
|
||||
vscodium = import ./vscodium.nix { inherit runTest; };
|
||||
vsftpd = runTest ./vsftpd.nix;
|
||||
|
||||
@@ -28,10 +28,12 @@
|
||||
# This is purely for testing purposes!
|
||||
environment.etc."authelia/storageEncryptionKeyFile" = {
|
||||
mode = "0400";
|
||||
user = "authelia-testing";
|
||||
text = "you_must_generate_a_random_string_of_more_than_twenty_chars_and_configure_this";
|
||||
};
|
||||
environment.etc."authelia/jwtSecretFile" = {
|
||||
mode = "0400";
|
||||
user = "authelia-testing";
|
||||
text = "a_very_important_secret";
|
||||
};
|
||||
environment.etc."authelia/users_database.yml" = {
|
||||
|
||||
@@ -102,6 +102,7 @@ in
|
||||
from selenium.webdriver.firefox.options import Options
|
||||
from selenium.webdriver.support.ui import WebDriverWait
|
||||
from selenium.webdriver.support import expected_conditions as EC
|
||||
from time import sleep
|
||||
|
||||
|
||||
def log(msg):
|
||||
@@ -128,7 +129,7 @@ in
|
||||
wait.until(EC.presence_of_element_located((by, query)))
|
||||
|
||||
|
||||
def wait_title_contains(title, timeout=30):
|
||||
def wait_title_contains(title, timeout=10):
|
||||
wait = WebDriverWait(driver, timeout)
|
||||
wait.until(EC.title_contains(title))
|
||||
|
||||
@@ -137,6 +138,11 @@ in
|
||||
return driver.find_element(by, query)
|
||||
|
||||
|
||||
def set_value(elem, value):
|
||||
script = 'arguments[0].value = arguments[1]'
|
||||
return driver.execute_script(script, elem, value)
|
||||
|
||||
|
||||
log("Waiting for the homepage to load")
|
||||
|
||||
# cockpit sets initial title as hostname
|
||||
@@ -145,45 +151,36 @@ in
|
||||
|
||||
log("Homepage loaded!")
|
||||
|
||||
# Prefer send_keys over setting .value via JS: Cockpit's login
|
||||
# form (and PatternFly widgets) do not always react to the latter.
|
||||
log("Filling out username")
|
||||
login_input = find_element(By.CSS_SELECTOR, 'input#login-user-input')
|
||||
login_input.clear()
|
||||
login_input.send_keys("${user}")
|
||||
set_value(login_input, "${user}")
|
||||
|
||||
log("Filling out password")
|
||||
password_input = find_element(
|
||||
By.CSS_SELECTOR, 'input#login-password-input'
|
||||
)
|
||||
password_input.clear()
|
||||
password_input.send_keys("${password}")
|
||||
password_input = find_element(By.CSS_SELECTOR, 'input#login-password-input')
|
||||
set_value(password_input, "${password}")
|
||||
|
||||
log("Submitting credentials for login")
|
||||
driver.find_element(By.CSS_SELECTOR, 'button#login-button').click()
|
||||
|
||||
# driver.implicitly_wait(1)
|
||||
# driver.get("https://server:7890/system")
|
||||
|
||||
log("Waiting dashboard to load")
|
||||
wait_title_contains("${user}@server")
|
||||
|
||||
log("Waiting for the frontend to initialize")
|
||||
sleep(1)
|
||||
|
||||
log("Looking for that banner that tells about limited access")
|
||||
wait_elem(By.CSS_SELECTOR, 'iframe.container-frame', timeout=30)
|
||||
container_iframe = find_element(
|
||||
By.CSS_SELECTOR, 'iframe.container-frame'
|
||||
)
|
||||
container_iframe = find_element(By.CSS_SELECTOR, 'iframe.container-frame')
|
||||
driver.switch_to.frame(container_iframe)
|
||||
# Wait for the overview iframe to render the limited-access alert.
|
||||
# Fixed sleeps were flaky after Cockpit 364 (slower SPA init).
|
||||
phrase = "Web console is running in limited access mode"
|
||||
WebDriverWait(driver, 30).until(
|
||||
lambda d: phrase in d.page_source
|
||||
)
|
||||
|
||||
assert "Web console is running in limited access mode" in driver.page_source
|
||||
|
||||
log("Clicking the sudo button")
|
||||
# Button label is "Turn on administrative access"
|
||||
for button in driver.find_elements(By.TAG_NAME, "button"):
|
||||
if 'admin' in button.text.casefold():
|
||||
if 'admin' in button.text:
|
||||
button.click()
|
||||
break
|
||||
driver.switch_to.default_content()
|
||||
|
||||
log("Checking that /nonexistent is not a thing")
|
||||
@@ -192,17 +189,13 @@ in
|
||||
|
||||
log("Checking plugin path")
|
||||
driver.get("https://server:7890/hello-test")
|
||||
wait_elem(By.CSS_SELECTOR, 'iframe.container-frame', timeout=30)
|
||||
sleep(2)
|
||||
for iframe in driver.find_elements(By.TAG_NAME, "iframe"):
|
||||
if "hello-test" in (iframe.get_attribute("src") or ""):
|
||||
driver.switch_to.frame(iframe)
|
||||
break
|
||||
output = find_element(By.ID, "output")
|
||||
WebDriverWait(driver, 30).until(
|
||||
lambda d: "SUCCESS: Hello, world!" in output.text
|
||||
or output.text.startswith("FAILED:")
|
||||
)
|
||||
text = output.text
|
||||
text = driver.find_element(By.ID, "output").text
|
||||
sleep(1)
|
||||
assert "SUCCESS: Hello, world!" in text, f"Plugin failed: {text}"
|
||||
|
||||
driver.close()
|
||||
@@ -222,10 +215,8 @@ in
|
||||
|
||||
server.wait_for_unit("sockets.target")
|
||||
server.wait_for_open_port(7890)
|
||||
# Port open is not enough: cockpit-ws may still be finishing startup.
|
||||
server.wait_until_succeeds("curl -k https://127.0.0.1:7890 -o /dev/null")
|
||||
|
||||
client.wait_until_succeeds("curl -k https://server:7890 -o /dev/stderr")
|
||||
client.succeed("curl -k https://server:7890 -o /dev/stderr")
|
||||
print(client.succeed("whoami"))
|
||||
client.succeed('PYTHONUNBUFFERED=1 selenium-script')
|
||||
'';
|
||||
|
||||
@@ -1,39 +0,0 @@
|
||||
{
|
||||
lib,
|
||||
pkgs,
|
||||
config,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
imports = [
|
||||
./user-account.nix
|
||||
./x11.nix
|
||||
];
|
||||
test-support.displayManager.auto.user = "alice";
|
||||
systemd.user.targets.xdg-desktop-autostart = {
|
||||
wantedBy = [ "graphical-session.target" ];
|
||||
after = [ "graphical-session.target" ];
|
||||
};
|
||||
|
||||
hardware.graphics.enable = true;
|
||||
|
||||
services.monado = {
|
||||
enable = true;
|
||||
defaultRuntime = true;
|
||||
forceDefaultRuntime = true;
|
||||
};
|
||||
systemd.user.services.monado = {
|
||||
requires = [ "graphical-session.target" ];
|
||||
environment = {
|
||||
# Stop Monado from probing for any hardware
|
||||
SIMULATED_ENABLE = "1";
|
||||
SIMULATED_LEFT = "simple";
|
||||
SIMULATED_RIGHT = "simple";
|
||||
# Run as X11 client rather than using direct mode
|
||||
XRT_COMPOSITOR_FORCE_XCB = "1";
|
||||
# And run fullscreen so that we can hide the DE
|
||||
XRT_COMPOSITOR_XCB_FULLSCREEN = "1";
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -12,8 +12,8 @@ in
|
||||
meta = with pkgs.lib.maintainers; {
|
||||
maintainers = [
|
||||
equirosa
|
||||
SuperSandro2000
|
||||
ryan4yin
|
||||
kaynetik
|
||||
];
|
||||
};
|
||||
|
||||
|
||||
@@ -5,63 +5,22 @@
|
||||
maintainers = with lib.maintainers; [ channinghe ];
|
||||
};
|
||||
|
||||
nodes = {
|
||||
periphery =
|
||||
{ ... }:
|
||||
{
|
||||
virtualisation.docker.enable = true;
|
||||
services.komodo-periphery = {
|
||||
enable = true;
|
||||
inbound.bindIp = "127.0.0.1";
|
||||
inbound.port = 8120;
|
||||
inbound.ssl.enable = false;
|
||||
inbound.serverEnabled = true;
|
||||
disableTerminals = true;
|
||||
disableContainerTerminals = true;
|
||||
statsPollingRate = "10-sec";
|
||||
containerStatsPollingRate = "1-min";
|
||||
logging.level = "debug";
|
||||
extraSettings = {
|
||||
secrets.TEST_SECRET = "test-value";
|
||||
};
|
||||
auth.privateKey = "file:/var/lib/komodo-periphery/keys/test.key";
|
||||
auth.corePublicKeys = [ "MCowBQYDK2VuAyEATZgrjGHeF0KJUe0+n77+qAWOg3YzEzXOmQWaRgO3OGQ=" ];
|
||||
};
|
||||
nodes.machine =
|
||||
{ config, pkgs, ... }:
|
||||
{
|
||||
virtualisation.docker.enable = true;
|
||||
services.komodo-periphery = {
|
||||
enable = true;
|
||||
bindIp = "127.0.0.1";
|
||||
port = 8120;
|
||||
ssl.enable = false;
|
||||
passkeys = [ "test-passkey" ];
|
||||
};
|
||||
|
||||
peripheryOutbound =
|
||||
{ ... }:
|
||||
{
|
||||
virtualisation.docker.enable = true;
|
||||
services.komodo-periphery = {
|
||||
enable = true;
|
||||
inbound.ssl.enable = false;
|
||||
logging.level = "debug";
|
||||
outbound.coreAddress = "core.invalid";
|
||||
outbound.connectAs = "test-server";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
testScript = ''
|
||||
start_all()
|
||||
|
||||
with subtest("Inbound periphery starts and serves /version"):
|
||||
periphery.wait_for_unit("komodo-periphery.service")
|
||||
periphery.wait_for_open_port(8120)
|
||||
periphery.succeed("curl -fsS --max-time 10 http://127.0.0.1:8120/version")
|
||||
|
||||
with subtest("Periphery creates managed directories"):
|
||||
periphery.succeed("test -d /var/lib/komodo-periphery")
|
||||
periphery.succeed("test -d /var/lib/komodo-periphery/repos")
|
||||
periphery.succeed("test -d /var/lib/komodo-periphery/stacks")
|
||||
periphery.succeed("test -d /var/lib/komodo-periphery/builds")
|
||||
periphery.succeed("test -d /var/lib/komodo-periphery/keys")
|
||||
periphery.succeed("test -d /var/lib/komodo-periphery/ssl")
|
||||
|
||||
with subtest("Outbound periphery stays active despite unreachable core"):
|
||||
peripheryOutbound.wait_for_unit("komodo-periphery.service")
|
||||
peripheryOutbound.sleep(15)
|
||||
peripheryOutbound.succeed("systemctl is-active komodo-periphery")
|
||||
machine.wait_for_unit("komodo-periphery.service")
|
||||
machine.wait_for_open_port(8120)
|
||||
machine.succeed("systemctl status komodo-periphery.service")
|
||||
'';
|
||||
}
|
||||
|
||||
@@ -3,57 +3,47 @@
|
||||
name = "monado";
|
||||
|
||||
nodes.machine =
|
||||
{
|
||||
lib,
|
||||
pkgs,
|
||||
config,
|
||||
...
|
||||
}:
|
||||
{ pkgs, ... }:
|
||||
|
||||
{
|
||||
imports = [ ./common/openxr.nix ];
|
||||
|
||||
systemd.user.services.print-openxr-info = {
|
||||
wantedBy = [ "xdg-desktop-autostart.target" ];
|
||||
requires = [ "monado.service" ];
|
||||
script = lib.getExe' pkgs.openxr-loader "openxr_runtime_list";
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
};
|
||||
hardware.graphics.enable = true;
|
||||
users.users.alice = {
|
||||
isNormalUser = true;
|
||||
uid = 1000;
|
||||
};
|
||||
|
||||
systemd.user.services.xrgears = {
|
||||
wantedBy = [ "xdg-desktop-autostart.target" ];
|
||||
requires = [ "monado.service" ];
|
||||
script = lib.getExe pkgs.xrgears;
|
||||
services.monado = {
|
||||
enable = true;
|
||||
defaultRuntime = true;
|
||||
|
||||
forceDefaultRuntime = true;
|
||||
};
|
||||
# Stop Monado from probing for any hardware
|
||||
systemd.user.services.monado.environment.SIMULATED_ENABLE = "1";
|
||||
|
||||
environment.systemPackages = with pkgs; [ openxr-loader ];
|
||||
};
|
||||
|
||||
testScript =
|
||||
{ nodes, ... }:
|
||||
let
|
||||
userId = toString nodes.machine.users.users.alice.uid;
|
||||
runtimePath = "/run/user/${userId}";
|
||||
in
|
||||
''
|
||||
with subtest("Ensure X11 starts"):
|
||||
start_all()
|
||||
machine.succeed("loginctl enable-linger alice")
|
||||
machine.wait_for_x()
|
||||
# for defaultRuntime
|
||||
machine.succeed("stat /etc/xdg/openxr/1/active_runtime.json")
|
||||
|
||||
with subtest("Ensure default runtime present"):
|
||||
machine.succeed("stat /etc/xdg/openxr/1/active_runtime.json")
|
||||
machine.succeed("loginctl enable-linger alice")
|
||||
machine.wait_for_unit("user@${userId}.service")
|
||||
|
||||
with subtest("Ensure forced runtime present"):
|
||||
# Monado needs to be started to create the forced runtime file
|
||||
machine.systemctl("start monado.service", "alice")
|
||||
machine.wait_for_unit("monado.service", "alice")
|
||||
machine.succeed("stat /home/alice/.config/openxr/1/active_runtime.json")
|
||||
machine.wait_for_unit("monado.socket", "alice")
|
||||
machine.systemctl("start monado.service", "alice")
|
||||
machine.wait_for_unit("monado.service", "alice")
|
||||
|
||||
with subtest("Ensure openxr_runtime_list can find runtime"):
|
||||
machine.wait_for_unit("print-openxr-info.service", "alice")
|
||||
# for forceDefaultRuntime
|
||||
machine.succeed("stat /home/alice/.config/openxr/1/active_runtime.json")
|
||||
|
||||
with subtest("Ensure xrgears launches"):
|
||||
machine.wait_for_unit("xrgears.service", "alice")
|
||||
# TODO: 10 seconds should be long enough for anything, but this is theoretically flaky
|
||||
machine.sleep(10)
|
||||
machine.screenshot("screen")
|
||||
machine.succeed("su -- alice -c env XDG_RUNTIME_DIR=${runtimePath} openxr_runtime_list")
|
||||
'';
|
||||
}
|
||||
|
||||
@@ -23,6 +23,7 @@
|
||||
environment.systemPackages = with pkgs; [
|
||||
usbutils
|
||||
glib
|
||||
jmtpfs
|
||||
tree
|
||||
];
|
||||
services.gvfs.enable = true;
|
||||
@@ -87,6 +88,22 @@
|
||||
${unmountAllMtpDevices}
|
||||
'';
|
||||
};
|
||||
jmtpfs = {
|
||||
# jmtpfsTest:
|
||||
# 1. Mounts the device on a dir named `phone` using jmtpfs
|
||||
# 2. Puts the current Nixpkgs libmtp version into a file
|
||||
# 3. Checks for corruption with `diff`
|
||||
# 4. Prints the directory tree
|
||||
jmtpfsTest = pkgs.writeScript "jmtpfsTest.sh" ''
|
||||
set -e
|
||||
mkdir phone
|
||||
jmtpfs phone
|
||||
echo "${pkgs.libmtp.version}" > phone/tmp/testFile
|
||||
echo "${pkgs.libmtp.version}" > testFile
|
||||
diff phone/tmp/testFile testFile
|
||||
tree phone
|
||||
'';
|
||||
};
|
||||
in
|
||||
# Using >&2 allows the results of the scripts to be printed to the terminal
|
||||
# when building this test with Nix. Scripts would otherwise complete
|
||||
@@ -96,5 +113,6 @@
|
||||
client.wait_for_unit("multi-user.target")
|
||||
client.wait_for_unit("dbus.service")
|
||||
client.succeed("${gvfs.gvfsTest} >&2")
|
||||
client.succeed("${jmtpfs.jmtpfsTest} >&2")
|
||||
'';
|
||||
}
|
||||
|
||||
@@ -4,6 +4,7 @@
|
||||
|
||||
meta = {
|
||||
maintainers = with lib.maintainers; [ jmbaur ];
|
||||
broken = pkgs.stdenv.hostPlatform.isAarch64;
|
||||
};
|
||||
|
||||
nodes.machine =
|
||||
@@ -16,8 +17,7 @@
|
||||
uboot = ubootQemuAarch64.overrideAttrs (old: {
|
||||
postPatch = (old.postPatch or "") + ''
|
||||
substituteInPlace board/emulation/qemu-arm/qemu-arm.env \
|
||||
--replace-fail "kernel_addr_r=0x40400000" "kernel_addr_r=0x50000000" \
|
||||
--replace-fail "ramdisk_addr_r=0x44000000" "ramdisk_addr_r=0x58000000"
|
||||
--replace-fail "ramdisk_addr_r=0x44000000" "ramdisk_addr_r=0x46000000"
|
||||
'';
|
||||
});
|
||||
|
||||
@@ -53,7 +53,6 @@
|
||||
|
||||
# VM boots up via qfw
|
||||
boot.loader.grub.enable = false;
|
||||
boot.kernelModules = [ "optee" ];
|
||||
|
||||
services.tee-supplicant = {
|
||||
enable = true;
|
||||
|
||||
@@ -1,69 +0,0 @@
|
||||
{ pkgs, ... }:
|
||||
|
||||
let
|
||||
accessKey = "BKIKJAA5BMMU2RHO6IBB";
|
||||
secretKey = "V7f1CwQqAcwo80UEIJEjc5gVQUSSx5ohQ9GSrr12";
|
||||
|
||||
rustfsPythonScript =
|
||||
pkgs.writers.writePython3 "rustfs-test" { libraries = with pkgs.python3Packages; [ minio ]; }
|
||||
/* python */ ''
|
||||
import io
|
||||
import os
|
||||
from minio import Minio
|
||||
|
||||
minioClient = Minio(
|
||||
'localhost:9000',
|
||||
access_key='${accessKey}',
|
||||
secret_key='${secretKey}',
|
||||
secure=False
|
||||
)
|
||||
sio = io.BytesIO()
|
||||
sio.write(b'Test from Python')
|
||||
sio.seek(0, os.SEEK_END)
|
||||
sio_len = sio.tell()
|
||||
sio.seek(0)
|
||||
minioClient.put_object(
|
||||
'test-bucket',
|
||||
'test.txt',
|
||||
sio,
|
||||
sio_len,
|
||||
content_type='text/plain'
|
||||
)
|
||||
'';
|
||||
|
||||
in
|
||||
{
|
||||
name = "rustfs";
|
||||
meta = with pkgs.lib.maintainers; {
|
||||
maintainers = [
|
||||
marcel
|
||||
];
|
||||
};
|
||||
|
||||
containers.machine =
|
||||
{ pkgs, ... }:
|
||||
{
|
||||
services.rustfs = {
|
||||
enable = true;
|
||||
environmentFile = builtins.toString (
|
||||
pkgs.writeText "rustfs-secrets.env" ''
|
||||
RUSTFS_ACCESS_KEY=${accessKey}
|
||||
RUSTFS_SECRET_KEY=${secretKey}
|
||||
''
|
||||
);
|
||||
};
|
||||
|
||||
environment.systemPackages = with pkgs; [ minio-client ];
|
||||
};
|
||||
|
||||
testScript = /* python */ ''
|
||||
machine.wait_for_unit("rustfs.service")
|
||||
|
||||
machine.succeed("mc alias set rustfs http://localhost:9000 ${accessKey} ${secretKey} --api s3v4")
|
||||
machine.succeed("mc mb rustfs/test-bucket")
|
||||
machine.succeed("${rustfsPythonScript}")
|
||||
assert "test-bucket" in machine.succeed("mc ls rustfs")
|
||||
assert "Test from Python" in machine.succeed("mc cat rustfs/test-bucket/test.txt")
|
||||
machine.succeed("mc rb --force rustfs/test-bucket")
|
||||
'';
|
||||
}
|
||||
@@ -1,5 +0,0 @@
|
||||
{ runTest }:
|
||||
{
|
||||
login = runTest ./login.nix;
|
||||
system = runTest ./system.nix;
|
||||
}
|
||||
@@ -1,147 +0,0 @@
|
||||
{ pkgs, ... }:
|
||||
let
|
||||
# Create a Python environment for the controller with all necessary test framework dependencies
|
||||
controllerPython = pkgs.python3.withPackages (ps: [
|
||||
ps.flaky
|
||||
ps.jc
|
||||
ps.pytest
|
||||
ps.pytest-mh
|
||||
ps.pytest-ticket
|
||||
]);
|
||||
|
||||
shadowHostName = "shadowhost";
|
||||
in
|
||||
{
|
||||
name = "shadow-system-tests";
|
||||
|
||||
meta.maintainers = with pkgs.lib.maintainers; [ joaosreis ];
|
||||
|
||||
nodes = {
|
||||
# The target host: runs sshd, has shadow and other test dependencies installed, mutable users, and some specific settings to match the expectations of the test suite
|
||||
shadowhost =
|
||||
{ pkgs, ... }:
|
||||
{
|
||||
networking.hostName = shadowHostName;
|
||||
services.openssh = {
|
||||
enable = true;
|
||||
settings = {
|
||||
PermitRootLogin = "yes";
|
||||
PasswordAuthentication = false;
|
||||
};
|
||||
};
|
||||
|
||||
users.mutableUsers = true;
|
||||
|
||||
environment.systemPackages = with pkgs; [
|
||||
shadow
|
||||
expect
|
||||
];
|
||||
|
||||
users.defaultUserShell = "/bin/sh";
|
||||
|
||||
security.loginDefs.settings = {
|
||||
PASS_MAX_DAYS = 99999;
|
||||
PASS_MIN_DAYS = 0;
|
||||
PASS_WARN_AGE = 7;
|
||||
USERGROUPS_ENAB = "yes";
|
||||
CREATE_HOME = "yes";
|
||||
UID_MIN = 1001;
|
||||
GID_MIN = 1001;
|
||||
};
|
||||
|
||||
security.pam.services = {
|
||||
newusers.text = ''
|
||||
auth required pam_permit.so
|
||||
account required pam_permit.so
|
||||
password required pam_permit.so
|
||||
session required pam_permit.so
|
||||
'';
|
||||
};
|
||||
|
||||
services.envfs.enable = true;
|
||||
};
|
||||
|
||||
# The controller: runs pytest-mh against the shadow host
|
||||
controller =
|
||||
{ pkgs, ... }:
|
||||
{
|
||||
environment.systemPackages = [
|
||||
controllerPython
|
||||
pkgs.openssh
|
||||
];
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
testScript = ''
|
||||
import textwrap
|
||||
|
||||
start_all()
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# 1. Generate an SSH keypair on the controller and authorise it
|
||||
# on the shadow host
|
||||
# ------------------------------------------------------------------
|
||||
controller.succeed("mkdir -p /root/.ssh && chmod 700 /root/.ssh")
|
||||
controller.succeed(
|
||||
"ssh-keygen -t ed25519 -N \'\' -f /root/.ssh/id_ed25519 2>&1"
|
||||
)
|
||||
pub_key = controller.succeed("cat /root/.ssh/id_ed25519.pub").strip()
|
||||
|
||||
# Inject the generated public key into the shadow host at runtime
|
||||
shadowhost.succeed("mkdir -p /root/.ssh && chmod 700 /root/.ssh")
|
||||
shadowhost.succeed(
|
||||
f"echo '{pub_key}' >> /root/.ssh/authorized_keys && "
|
||||
"chmod 600 /root/.ssh/authorized_keys"
|
||||
)
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# 2. Make sure the shadow host has a writable /etc/login.defs,
|
||||
# since the test framework expects to be able to write to it.
|
||||
# ------------------------------------------------------------------
|
||||
shadowhost.succeed(
|
||||
"cp --remove-destination $(readlink -f /etc/login.defs) /etc/login.defs && "
|
||||
"chmod 644 /etc/login.defs"
|
||||
)
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# 3. Copy the upstream test suite onto the controller
|
||||
# ------------------------------------------------------------------
|
||||
controller.succeed(
|
||||
"cp -r ${pkgs.shadow.passthru.testFramework} /root/shadow-tests && "
|
||||
"chmod -R u+w /root/shadow-tests"
|
||||
)
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# 4. Write the mhc.yaml topology config
|
||||
# This tells pytest-mh where the shadow host is and which role
|
||||
# it plays. The hostname must match the NixOS node name.
|
||||
# ------------------------------------------------------------------
|
||||
controller.succeed(textwrap.dedent("""
|
||||
cat > /root/shadow-tests/mhc.yaml << 'EOF'
|
||||
domains:
|
||||
- id: shadow
|
||||
hosts:
|
||||
- hostname: ${shadowHostName}
|
||||
role: shadow
|
||||
ssh:
|
||||
user: root
|
||||
private_key: /root/.ssh/id_ed25519
|
||||
EOF
|
||||
"""))
|
||||
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# 5. Run the upstream pytest-mh test suite from the controller
|
||||
# ------------------------------------------------------------------
|
||||
shadowhost.wait_for_unit("sshd.service")
|
||||
# gpasswd tests are disabled, since they rely on specific behavior of the gpasswd command that is not applicable to NixOS
|
||||
controller.succeed(
|
||||
"cd /root/shadow-tests && "
|
||||
"${controllerPython}/bin/pytest "
|
||||
"--mh-config=mhc.yaml "
|
||||
"--deselect=tests/test_gpasswd.py "
|
||||
"-v tests/"
|
||||
)
|
||||
'';
|
||||
}
|
||||
@@ -1,54 +0,0 @@
|
||||
{ ... }:
|
||||
{
|
||||
name = "stardust-xr-atmosphere";
|
||||
|
||||
# Doesn't understand @polling_condition
|
||||
skipTypeCheck = true;
|
||||
|
||||
nodes.machine =
|
||||
{
|
||||
lib,
|
||||
pkgs,
|
||||
config,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
imports = [ ./common.nix ];
|
||||
|
||||
virtualisation.memorySize = 4096;
|
||||
|
||||
systemd.user.services.stardust-xr-atmosphere = {
|
||||
wantedBy = [ "xdg-desktop-autostart.target" ];
|
||||
requires = [ "stardust-xr-server.service" ];
|
||||
after = [ "stardust-xr-server.service" ];
|
||||
script = ''
|
||||
set -eufx pipefail
|
||||
${lib.getExe pkgs.stardust-xr-atmosphere} install ${pkgs.stardust-xr-atmosphere}/share/atmosphere/default_envs/the_grid
|
||||
${lib.getExe pkgs.stardust-xr-atmosphere} set-default the_grid
|
||||
${lib.getExe pkgs.stardust-xr-atmosphere} show
|
||||
'';
|
||||
environment.RUST_BACKTRACE = "full";
|
||||
};
|
||||
};
|
||||
|
||||
testScript =
|
||||
{ nodes, ... }:
|
||||
''
|
||||
@polling_condition()
|
||||
def atmosphere_running():
|
||||
machine.wait_for_unit("stardust-xr-atmosphere.service", "alice")
|
||||
|
||||
with subtest("Ensure X11 starts"):
|
||||
start_all()
|
||||
machine.succeed("loginctl enable-linger alice")
|
||||
machine.wait_for_x()
|
||||
|
||||
with subtest("Ensure system works"):
|
||||
with atmosphere_running:
|
||||
# TODO(@Pandapip1): 20 seconds should be long enough for anything, but this is theoretically flaky
|
||||
# Adding systemd notify support to stardust-xr-atmosphere should resolve this
|
||||
machine.sleep(20)
|
||||
machine.screenshot("screen")
|
||||
'';
|
||||
}
|
||||
@@ -1,23 +0,0 @@
|
||||
{
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
imports = [ ../common/openxr.nix ];
|
||||
|
||||
# TODO(@Pandapip1): For the time being, Stardust doesn't like controllers rather than hand tracking
|
||||
services.monado.enable = lib.mkForce false;
|
||||
|
||||
systemd.user.services.stardust-xr-server = {
|
||||
wantedBy = [ "xdg-desktop-autostart.target" ];
|
||||
# requires = [ "monado.service" ];
|
||||
serviceConfig = {
|
||||
Type = "notify";
|
||||
NotifyAccess = "all";
|
||||
ExecStart = "${lib.getExe pkgs.stardust-xr-server} -e ${pkgs.writeShellScript "notifyReady" "systemd-notify --ready"}";
|
||||
};
|
||||
environment.RUST_BACKTRACE = "full";
|
||||
};
|
||||
}
|
||||
@@ -1,57 +0,0 @@
|
||||
{ ... }:
|
||||
{
|
||||
name = "stardust-xr-flatland";
|
||||
|
||||
# Doesn't understand @polling_condition
|
||||
skipTypeCheck = true;
|
||||
|
||||
nodes.machine =
|
||||
{
|
||||
lib,
|
||||
pkgs,
|
||||
config,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
imports = [ ./common.nix ];
|
||||
|
||||
systemd.user.services.stardust-xr-flatland = {
|
||||
wantedBy = [ "xdg-desktop-autostart.target" ];
|
||||
requires = [ "stardust-xr-server.service" ];
|
||||
after = [ "stardust-xr-server.service" ];
|
||||
script = lib.getExe pkgs.stardust-xr-flatland;
|
||||
environment.RUST_BACKTRACE = "full";
|
||||
};
|
||||
|
||||
systemd.user.services.test-wayland-app = {
|
||||
wantedBy = [ "xdg-desktop-autostart.target" ];
|
||||
requires = [ "stardust-xr-flatland.service" ];
|
||||
after = [ "stardust-xr-flatland.service" ];
|
||||
script = lib.getExe pkgs.wayland-colorbar;
|
||||
environment = {
|
||||
DISPLAY = "";
|
||||
WAYLAND_DISPLAY = "wayland-0";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
testScript =
|
||||
{ nodes, ... }:
|
||||
''
|
||||
@polling_condition()
|
||||
def wayland_client_running():
|
||||
machine.wait_for_unit("test-wayland-app.service", "alice")
|
||||
|
||||
with subtest("Ensure X11 starts"):
|
||||
start_all()
|
||||
machine.succeed("loginctl enable-linger alice")
|
||||
machine.wait_for_x()
|
||||
|
||||
with subtest("Ensure system works"):
|
||||
with wayland_client_running:
|
||||
# TODO: 20 seconds should be long enough for anything, but this is theoretically flaky
|
||||
machine.sleep(20)
|
||||
machine.screenshot("screen")
|
||||
'';
|
||||
}
|
||||
@@ -1,23 +0,0 @@
|
||||
{ lib, ... }:
|
||||
{
|
||||
name = "systemd-localed";
|
||||
meta.maintainers = [ lib.maintainers.haansn08 ];
|
||||
|
||||
nodes.machine = { ... }: {
|
||||
# we don't use services.xserver.enable because some window managers like
|
||||
# niri rely on systemd-localed for the keyboard layout:
|
||||
# https://niri-wm.github.io/niri/Configuration%3A-Input.html#layout
|
||||
services.graphical-desktop.enable = true;
|
||||
|
||||
services.xserver.xkb.layout = "jp";
|
||||
};
|
||||
|
||||
testScript = ''
|
||||
machine.start()
|
||||
machine.wait_for_unit("default.target")
|
||||
machine.wait_for_unit("dbus.socket")
|
||||
|
||||
status, stdout = machine.execute("localectl")
|
||||
t.assertIn("X11 Layout: jp", stdout)
|
||||
'';
|
||||
}
|
||||
@@ -1,26 +0,0 @@
|
||||
{ lib, ... }:
|
||||
{
|
||||
name = "vnstat";
|
||||
meta.maintainers = with lib.maintainers; [ hmenke ];
|
||||
|
||||
containers.machine = {
|
||||
services.vnstat = {
|
||||
enable = true;
|
||||
settings = {
|
||||
AlwaysAddNewInterfaces = 1;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
testScript = ''
|
||||
start_all()
|
||||
|
||||
machine.wait_for_unit("vnstat.service")
|
||||
|
||||
machine.succeed("vnstat --iflist")
|
||||
machine.fail("vnstat -i dummy0")
|
||||
machine.succeed("ip link add dummy0 type dummy")
|
||||
machine.succeed("ip link set dummy0 up")
|
||||
machine.wait_until_succeeds("vnstat -i dummy0", timeout=10)
|
||||
'';
|
||||
}
|
||||
@@ -1,21 +1,10 @@
|
||||
{
|
||||
lib,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
apiKeyFile = "/tmp/immich-api.key";
|
||||
customInterval = 5;
|
||||
user = "alice";
|
||||
in
|
||||
{
|
||||
name = "immichframe";
|
||||
|
||||
meta.maintainers = with lib.maintainers; [
|
||||
numinit
|
||||
jfly
|
||||
];
|
||||
|
||||
enableOCR = true;
|
||||
|
||||
nodes.machine =
|
||||
@@ -26,22 +15,11 @@ in
|
||||
...
|
||||
}:
|
||||
{
|
||||
imports = [
|
||||
../common/user-account.nix
|
||||
../common/x11.nix
|
||||
];
|
||||
imports = [ ../common/x11.nix ];
|
||||
|
||||
# When setting memory to 2500 I got "Kernel panic - not syncing: Out of
|
||||
# When setting this to 2500 I got "Kernel panic - not syncing: Out of
|
||||
# memory: compulsory panic_on_oom is enabled".
|
||||
# Setting cores to 1 (the default) also makes immich take a long time to start up.
|
||||
# If this breaks, keep synced with the immich test.
|
||||
virtualisation = {
|
||||
memorySize = 4096;
|
||||
cores = 2;
|
||||
};
|
||||
hardware.graphics.enable = true;
|
||||
environment.variables.XAUTHORITY = "/home/${user}/.Xauthority";
|
||||
test-support.displayManager.auto.user = user;
|
||||
virtualisation.memorySize = 3000;
|
||||
|
||||
environment.systemPackages = with pkgs; [
|
||||
imagemagick
|
||||
@@ -91,7 +69,6 @@ in
|
||||
|
||||
custom_interval = ${toString customInterval}
|
||||
|
||||
machine.wait_for_x()
|
||||
machine.wait_for_unit("immich-server.service")
|
||||
machine.wait_for_open_port(2283)
|
||||
|
||||
@@ -156,7 +133,11 @@ in
|
||||
assert len(assets) == 2, assets
|
||||
|
||||
# Wait for a photo to be displayed.
|
||||
machine.execute("su - ${user} -c 'firefox --kiosk http://localhost:8002' >&2 & disown")
|
||||
machine.wait_for_x()
|
||||
machine.execute("xterm -e 'firefox --kiosk http://localhost:8002' >&2 &")
|
||||
machine.wait_for_window("immichFrame")
|
||||
_, active_window = machine.execute("xdotool getactivewindow")
|
||||
machine.succeed(f"xdotool windowsize {quote(active_window.strip())} 100% 100%")
|
||||
machine.wait_for_text('reproduce this moment')
|
||||
machine.wait_for_text('with NixOS tests')
|
||||
machine.screenshot("screen")
|
||||
|
||||
@@ -51,9 +51,7 @@ pythonPackages.buildPythonApplication (finalAttrs: {
|
||||
pygobject3
|
||||
pykka
|
||||
requests
|
||||
# Provides pkg_resources required by Mopidy 3 and affected extensions.
|
||||
# Remove when updating to Mopidy 4.
|
||||
setuptools_80
|
||||
setuptools
|
||||
tornado
|
||||
]
|
||||
++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ dbus-python ];
|
||||
|
||||
@@ -11,7 +11,7 @@
|
||||
libpulseaudio,
|
||||
withCoreAudio ? stdenv.hostPlatform.isDarwin,
|
||||
withJack ? stdenv.hostPlatform.isUnix,
|
||||
libjack2,
|
||||
jack,
|
||||
withConplay ? !stdenv.hostPlatform.isWindows,
|
||||
perl,
|
||||
writeScript,
|
||||
@@ -21,11 +21,11 @@ assert withConplay -> !libOnly;
|
||||
|
||||
stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "${lib.optionalString libOnly "lib"}mpg123";
|
||||
version = "1.33.5";
|
||||
version = "1.33.6";
|
||||
|
||||
src = fetchurl {
|
||||
url = "mirror://sourceforge/mpg123/mpg123-${finalAttrs.version}.tar.bz2";
|
||||
hash = "sha256-DX68jaCv88o4PIxrWmrb5ALuW7JWaFuMVJnzpzn51t0=";
|
||||
hash = "sha256-kpp8GLpmK4knrtTeIprZroqytIBt0PMLkBE+sbTiGVo=";
|
||||
};
|
||||
|
||||
outputs = [
|
||||
@@ -45,7 +45,7 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
++ lib.optionals withPulse [ libpulseaudio ]
|
||||
++ lib.optionals withCoreAudio [
|
||||
]
|
||||
++ lib.optionals withJack [ libjack2 ]
|
||||
++ lib.optionals withJack [ jack ]
|
||||
);
|
||||
|
||||
configureFlags =
|
||||
@@ -21,14 +21,14 @@ let
|
||||
url = "https://edgedl.me.gvt1.com/android/studio/ide-zips/2026.1.1.10/android-studio-quail1-patch2-linux.tar.gz";
|
||||
};
|
||||
betaVersion = {
|
||||
version = "2026.1.3.5"; # "Android Studio Quail 3 | 2026.1.3 RC 1"
|
||||
sha256Hash = "sha256-P8YoUnG4YtCOPkbHLFBHfteZg8cJJeXuDgty+kmgbSw=";
|
||||
url = "https://edgedl.me.gvt1.com/android/studio/ide-zips/2026.1.3.5/android-studio-quail3-rc1-linux.tar.gz";
|
||||
version = "2026.1.2.9"; # "Android Studio Quail 2 | 2026.1.2 RC 2"
|
||||
sha256Hash = "sha256-QzNhbE8Ryv0VGQY/VzhJhqeS0c6rrUpgXXVOoBV+NHE=";
|
||||
url = "https://edgedl.me.gvt1.com/android/studio/ide-zips/2026.1.2.9/android-studio-quail2-rc2-linux.tar.gz";
|
||||
};
|
||||
latestVersion = {
|
||||
version = "2026.1.4.1"; # "Android Studio Quail 4 | 2026.1.4 Canary 1"
|
||||
sha256Hash = "sha256-ynHUoMDsTNgKKRAU948k37ktAIlIm9A+md8KyVBTjl4=";
|
||||
url = "https://edgedl.me.gvt1.com/android/studio/ide-zips/2026.1.4.1/android-studio-quail4-canary1-linux.tar.gz";
|
||||
version = "2026.1.3.3"; # "Android Studio Quail 3 | 2026.1.3 Canary 3"
|
||||
sha256Hash = "sha256-C8rbR+0iGNzsr7HtiNiFw++ZG9/t00/c1Ozr9ngssPs=";
|
||||
url = "https://edgedl.me.gvt1.com/android/studio/ide-zips/2026.1.3.3/android-studio-quail3-canary3-linux.tar.gz";
|
||||
};
|
||||
in
|
||||
{
|
||||
|
||||
@@ -47,6 +47,7 @@ melpaBuild (finalAttrs: {
|
||||
platforms = [
|
||||
"aarch64-darwin"
|
||||
"aarch64-linux"
|
||||
"x86_64-darwin"
|
||||
"x86_64-linux"
|
||||
"x86_64-windows"
|
||||
];
|
||||
|
||||
@@ -28,6 +28,10 @@ let
|
||||
url = "https://download.jetbrains.com/cpp/CLion-2026.1.4-aarch64.tar.gz";
|
||||
hash = "sha256-I6IKQng4lNtRlQIq08K5bueqgKI/q1awX4EuRnyAnOk=";
|
||||
};
|
||||
x86_64-darwin = {
|
||||
url = "https://download.jetbrains.com/cpp/CLion-2026.1.4.dmg";
|
||||
hash = "sha256-AJt+K1zv4eyjdzubUeFGwB9mqzvOeb3ffA2k0MajPBs=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://download.jetbrains.com/cpp/CLion-2026.1.4-aarch64.dmg";
|
||||
hash = "sha256-i3stX7dyRgSOJkFTMD9/hkw6e2mGNqn13S7X/vJ66RQ=";
|
||||
|
||||
@@ -19,6 +19,10 @@ let
|
||||
url = "https://download.jetbrains.com/datagrip/datagrip-2026.1.3-aarch64.tar.gz";
|
||||
hash = "sha256-G+tinD/+qM5HVR4u2E0cNXtdVsbwgK8/PdZ3ic6hf4M=";
|
||||
};
|
||||
x86_64-darwin = {
|
||||
url = "https://download.jetbrains.com/datagrip/datagrip-2026.1.3.dmg";
|
||||
hash = "sha256-vW2LEonl0D9S0VxbeJX4jRrwhELGBwlOXwiHslvh06E=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://download.jetbrains.com/datagrip/datagrip-2026.1.3-aarch64.dmg";
|
||||
hash = "sha256-Kyt3fYPXzwTVxPFVKd+atiHWb/i7gjGahz1MJ4iXxy8=";
|
||||
|
||||
@@ -21,6 +21,10 @@ let
|
||||
url = "https://download.jetbrains.com/python/dataspell-2026.1.2-aarch64.tar.gz";
|
||||
hash = "sha256-SSmIPF0pDMolxeXL21UaHMbZdtYbChWVxTKZOsPhH+I=";
|
||||
};
|
||||
x86_64-darwin = {
|
||||
url = "https://download.jetbrains.com/python/dataspell-2026.1.2.dmg";
|
||||
hash = "sha256-2qzwzGMYuy1qEuTprxwNa5gOPgCZq2MadSKN8FT8w8c=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://download.jetbrains.com/python/dataspell-2026.1.2-aarch64.dmg";
|
||||
hash = "sha256-MGWufS0nlswdqhACNQWtlXJwfPiYw8wUx7olIxPS15k=";
|
||||
|
||||
@@ -19,6 +19,10 @@ let
|
||||
url = "https://download.jetbrains.com/idea/gateway/JetBrainsGateway-2026.1.3-aarch64.tar.gz";
|
||||
hash = "sha256-CSe04BBo4jS1cIhu4NfZqaSHMaNue2eFUPa+1gOxuoo=";
|
||||
};
|
||||
x86_64-darwin = {
|
||||
url = "https://download.jetbrains.com/idea/gateway/JetBrainsGateway-2026.1.3.dmg";
|
||||
hash = "sha256-WKwIP19y5EKO98JgEm468ofaRp/JO5z8lqNhtpsH4tY=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://download.jetbrains.com/idea/gateway/JetBrainsGateway-2026.1.3-aarch64.dmg";
|
||||
hash = "sha256-AHY/lY0ARkW0VoSgy0t7LLNXA965PLooWBSWxBKBV5M=";
|
||||
|
||||
@@ -19,6 +19,10 @@ let
|
||||
url = "https://download.jetbrains.com/go/goland-2026.1.4-aarch64.tar.gz";
|
||||
hash = "sha256-7s98kY08aKjdRGQLDkffeVhgj1FWurLmTTYmtb5Qx6c=";
|
||||
};
|
||||
x86_64-darwin = {
|
||||
url = "https://download.jetbrains.com/go/goland-2026.1.4.dmg";
|
||||
hash = "sha256-RbvcLpLVyeL4B1DJ2/9Ub/6Cz6fJGXMPCHsJ705GsAo=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://download.jetbrains.com/go/goland-2026.1.4-aarch64.dmg";
|
||||
hash = "sha256-y7mEke0z0MvQs+kMtrmrq7EeAtJUbgo6sGZrOB0MraM=";
|
||||
|
||||
@@ -22,6 +22,10 @@ let
|
||||
url = "https://download.jetbrains.com/idea/ideaIU-2026.1.4-aarch64.tar.gz";
|
||||
hash = "sha256-MDZFuLrUxcCIc0Zhi4QhgKPeU7Pgs9oJ/FxQH1n3gBM=";
|
||||
};
|
||||
x86_64-darwin = {
|
||||
url = "https://download.jetbrains.com/idea/ideaIU-2026.1.4.dmg";
|
||||
hash = "sha256-8K+LiewiINP4S9eqV0kGWtfy2Ff/zvBwX89iX7mYZ78=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://download.jetbrains.com/idea/ideaIU-2026.1.4-aarch64.dmg";
|
||||
hash = "sha256-XIBK/+Lxaz9dX+Lxl7HXsl+Z3Z7GBzSuDxNssb/4A2s=";
|
||||
|
||||
@@ -19,6 +19,10 @@ let
|
||||
url = "https://download.jetbrains.com/mps/2025.3/MPS-2025.3.tar.gz";
|
||||
hash = "sha256-xAI+UrTheCTWHSdoI4YZvhTlrlc121M+OVFkfzd7a3k=";
|
||||
};
|
||||
x86_64-darwin = {
|
||||
url = "https://download.jetbrains.com/mps/2025.3/MPS-2025.3-macos.dmg";
|
||||
hash = "sha256-whYAjKkF79mrknHflZnvOOy2bLosYUguelZDSuPt3uY=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://download.jetbrains.com/mps/2025.3/MPS-2025.3-macos-aarch64.dmg";
|
||||
hash = "sha256-3HnEHOhRRI9IYjBhc5FO7h5j4jBBDtZTVkmO/S1fBEQ=";
|
||||
|
||||
@@ -19,6 +19,10 @@ let
|
||||
url = "https://download.jetbrains.com/webide/PhpStorm-2026.1.4-aarch64.tar.gz";
|
||||
hash = "sha256-T9q3/nxv/AA6y7CHWtOhUibR7bnKN8OZmfN3NWYTsIQ=";
|
||||
};
|
||||
x86_64-darwin = {
|
||||
url = "https://download.jetbrains.com/webide/PhpStorm-2026.1.4.dmg";
|
||||
hash = "sha256-W7EwYu7S3hs1564tXq8H1Uok/Gwx/8QJO4brUGOfFY4=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://download.jetbrains.com/webide/PhpStorm-2026.1.4-aarch64.dmg";
|
||||
hash = "sha256-XGcfEWHHeLugvkT/WlQDsVRN33F46b1PCNhINQitqSY=";
|
||||
|
||||
@@ -20,6 +20,10 @@ let
|
||||
url = "https://download.jetbrains.com/python/pycharm-2026.1.4-aarch64.tar.gz";
|
||||
hash = "sha256-71FbYpN0seJ5k/yZA7aoXgU4W/N1BhjtKl7W7Hic9UE=";
|
||||
};
|
||||
x86_64-darwin = {
|
||||
url = "https://download.jetbrains.com/python/pycharm-2026.1.4.dmg";
|
||||
hash = "sha256-Q5hTcYoNUzmAxwcsXJNS4medQjFKWc/Sgkybt4PQPfg=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://download.jetbrains.com/python/pycharm-2026.1.4-aarch64.dmg";
|
||||
hash = "sha256-qxSgp8r4S0KXjCCTIoAiEZFCn3uBE/0pWLLA6td0Fq0=";
|
||||
|
||||
@@ -31,6 +31,10 @@ let
|
||||
url = "https://download.jetbrains.com/rider/JetBrains.Rider-2026.1.4-aarch64.tar.gz";
|
||||
hash = "sha256-GXmyBrqxUpwK4djjwllvK+pnfktDrDHpLJKoe4D2xFo=";
|
||||
};
|
||||
x86_64-darwin = {
|
||||
url = "https://download.jetbrains.com/rider/JetBrains.Rider-2026.1.4.dmg";
|
||||
hash = "sha256-GfQ5WpKunJ+JhE1VcArm3UxZ5udCbfnS1Kw3D4gZorA=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://download.jetbrains.com/rider/JetBrains.Rider-2026.1.4-aarch64.dmg";
|
||||
hash = "sha256-cfwT22BN1jzKZzrZHMQqYFJPGuRwta/sqoOJOp+PfBE=";
|
||||
|
||||
@@ -19,6 +19,10 @@ let
|
||||
url = "https://download.jetbrains.com/ruby/RubyMine-2026.1.4-aarch64.tar.gz";
|
||||
hash = "sha256-oSu19pkGVWt31vWBdAffSZsu4QzsUznVbUSwDy98nug=";
|
||||
};
|
||||
x86_64-darwin = {
|
||||
url = "https://download.jetbrains.com/ruby/RubyMine-2026.1.4.dmg";
|
||||
hash = "sha256-BLo2weIJK8gQAcMtAiETM7FMdhw9aoFIGh5Yqjv3k7s=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://download.jetbrains.com/ruby/RubyMine-2026.1.4-aarch64.dmg";
|
||||
hash = "sha256-4wEnwcPRtwp0wxePUMiLow6sMxirwndRMdmJL8LBh9k=";
|
||||
|
||||
@@ -25,6 +25,10 @@ let
|
||||
url = "https://download.jetbrains.com/rustrover/RustRover-2026.1.4-aarch64.tar.gz";
|
||||
hash = "sha256-KpF3jCnLKCEeEXkBdB8ZsPPqP9FOVRTwRV/FQLKyh1Q=";
|
||||
};
|
||||
x86_64-darwin = {
|
||||
url = "https://download.jetbrains.com/rustrover/RustRover-2026.1.4.dmg";
|
||||
hash = "sha256-2BwgAD0xF9IxRJh+gW4vLzBW13rFQSzQPbEwdmQGvLU=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://download.jetbrains.com/rustrover/RustRover-2026.1.4-aarch64.dmg";
|
||||
hash = "sha256-Hly4NBv9mg/RMmxCM6m9w5eS/CQ7ycxp7V2VQZwyGQE=";
|
||||
|
||||
@@ -19,6 +19,10 @@ let
|
||||
url = "https://download.jetbrains.com/webstorm/WebStorm-2026.1.4-aarch64.tar.gz";
|
||||
hash = "sha256-f9KenMq1gtldzpBraSBwOb/186WQwh1ps5Ypj5JoOU0=";
|
||||
};
|
||||
x86_64-darwin = {
|
||||
url = "https://download.jetbrains.com/webstorm/WebStorm-2026.1.4.dmg";
|
||||
hash = "sha256-SGdo6WYMCcCBuZUjvURcMTbJUqhZ4MzFlSLg6Zjr84I=";
|
||||
};
|
||||
aarch64-darwin = {
|
||||
url = "https://download.jetbrains.com/webstorm/WebStorm-2026.1.4-aarch64.dmg";
|
||||
hash = "sha256-ZYen6Ew0GYbBAmuGCDACPBsygxZ6sT787o6gqF9DJzw=";
|
||||
|
||||
@@ -78,5 +78,7 @@ Any comments or other manual changes between these markers will be removed when
|
||||
- on `aarch64-linux`:
|
||||
- from source build
|
||||
- see if build (binary or source) works without expat
|
||||
- on `x86_64-darwin`:
|
||||
- from source build
|
||||
- on `aarch64-darwin`:
|
||||
- from source build
|
||||
|
||||
@@ -3,7 +3,7 @@ import os
|
||||
import dataclasses
|
||||
from pathlib import Path
|
||||
|
||||
SUPPORTED_SYSTEMS = ["x86_64-linux", "aarch64-linux", "aarch64-darwin"]
|
||||
SUPPORTED_SYSTEMS = ["x86_64-linux", "aarch64-linux", "x86_64-darwin", "aarch64-darwin"]
|
||||
|
||||
|
||||
def find_nixpkgs(current_path: Path) -> Path:
|
||||
|
||||
@@ -4,6 +4,7 @@
|
||||
"urls": {
|
||||
"x86_64-linux": "https://download.jetbrains.com/cpp/CLion-{version}.tar.gz",
|
||||
"aarch64-linux": "https://download.jetbrains.com/cpp/CLion-{version}-aarch64.tar.gz",
|
||||
"x86_64-darwin": "https://download.jetbrains.com/cpp/CLion-{version}.dmg",
|
||||
"aarch64-darwin": "https://download.jetbrains.com/cpp/CLion-{version}-aarch64.dmg"
|
||||
}
|
||||
},
|
||||
@@ -12,6 +13,7 @@
|
||||
"urls": {
|
||||
"x86_64-linux": "https://download.jetbrains.com/datagrip/datagrip-{version}.tar.gz",
|
||||
"aarch64-linux": "https://download.jetbrains.com/datagrip/datagrip-{version}-aarch64.tar.gz",
|
||||
"x86_64-darwin": "https://download.jetbrains.com/datagrip/datagrip-{version}.dmg",
|
||||
"aarch64-darwin": "https://download.jetbrains.com/datagrip/datagrip-{version}-aarch64.dmg"
|
||||
}
|
||||
},
|
||||
@@ -20,6 +22,7 @@
|
||||
"urls": {
|
||||
"x86_64-linux": "https://download.jetbrains.com/python/dataspell-{version}.tar.gz",
|
||||
"aarch64-linux": "https://download.jetbrains.com/python/dataspell-{version}-aarch64.tar.gz",
|
||||
"x86_64-darwin": "https://download.jetbrains.com/python/dataspell-{version}.dmg",
|
||||
"aarch64-darwin": "https://download.jetbrains.com/python/dataspell-{version}-aarch64.dmg"
|
||||
}
|
||||
},
|
||||
@@ -28,6 +31,7 @@
|
||||
"urls": {
|
||||
"x86_64-linux": "https://download.jetbrains.com/idea/gateway/JetBrainsGateway-{version}.tar.gz",
|
||||
"aarch64-linux": "https://download.jetbrains.com/idea/gateway/JetBrainsGateway-{version}-aarch64.tar.gz",
|
||||
"x86_64-darwin": "https://download.jetbrains.com/idea/gateway/JetBrainsGateway-{version}.dmg",
|
||||
"aarch64-darwin": "https://download.jetbrains.com/idea/gateway/JetBrainsGateway-{version}-aarch64.dmg"
|
||||
}
|
||||
},
|
||||
@@ -36,6 +40,7 @@
|
||||
"urls": {
|
||||
"x86_64-linux": "https://download.jetbrains.com/go/goland-{version}.tar.gz",
|
||||
"aarch64-linux": "https://download.jetbrains.com/go/goland-{version}-aarch64.tar.gz",
|
||||
"x86_64-darwin": "https://download.jetbrains.com/go/goland-{version}.dmg",
|
||||
"aarch64-darwin": "https://download.jetbrains.com/go/goland-{version}-aarch64.dmg"
|
||||
}
|
||||
},
|
||||
@@ -44,6 +49,7 @@
|
||||
"urls": {
|
||||
"x86_64-linux": "https://download.jetbrains.com/idea/ideaIU-{version}.tar.gz",
|
||||
"aarch64-linux": "https://download.jetbrains.com/idea/ideaIU-{version}-aarch64.tar.gz",
|
||||
"x86_64-darwin": "https://download.jetbrains.com/idea/ideaIU-{version}.dmg",
|
||||
"aarch64-darwin": "https://download.jetbrains.com/idea/ideaIU-{version}-aarch64.dmg"
|
||||
}
|
||||
},
|
||||
@@ -56,6 +62,7 @@
|
||||
"urls": {
|
||||
"x86_64-linux": "https://download.jetbrains.com/mps/{versionMajorMinor}/MPS-{version}.tar.gz",
|
||||
"aarch64-linux": "https://download.jetbrains.com/mps/{versionMajorMinor}/MPS-{version}.tar.gz",
|
||||
"x86_64-darwin": "https://download.jetbrains.com/mps/{versionMajorMinor}/MPS-{version}-macos.dmg",
|
||||
"aarch64-darwin": "https://download.jetbrains.com/mps/{versionMajorMinor}/MPS-{version}-macos-aarch64.dmg"
|
||||
}
|
||||
},
|
||||
@@ -64,6 +71,7 @@
|
||||
"urls": {
|
||||
"x86_64-linux": "https://download.jetbrains.com/webide/PhpStorm-{version}.tar.gz",
|
||||
"aarch64-linux": "https://download.jetbrains.com/webide/PhpStorm-{version}-aarch64.tar.gz",
|
||||
"x86_64-darwin": "https://download.jetbrains.com/webide/PhpStorm-{version}.dmg",
|
||||
"aarch64-darwin": "https://download.jetbrains.com/webide/PhpStorm-{version}-aarch64.dmg"
|
||||
}
|
||||
},
|
||||
@@ -72,6 +80,7 @@
|
||||
"urls": {
|
||||
"x86_64-linux": "https://download.jetbrains.com/python/pycharm-{version}.tar.gz",
|
||||
"aarch64-linux": "https://download.jetbrains.com/python/pycharm-{version}-aarch64.tar.gz",
|
||||
"x86_64-darwin": "https://download.jetbrains.com/python/pycharm-{version}.dmg",
|
||||
"aarch64-darwin": "https://download.jetbrains.com/python/pycharm-{version}-aarch64.dmg"
|
||||
}
|
||||
},
|
||||
@@ -84,6 +93,7 @@
|
||||
"urls": {
|
||||
"x86_64-linux": "https://download.jetbrains.com/rider/JetBrains.Rider-{version}.tar.gz",
|
||||
"aarch64-linux": "https://download.jetbrains.com/rider/JetBrains.Rider-{version}-aarch64.tar.gz",
|
||||
"x86_64-darwin": "https://download.jetbrains.com/rider/JetBrains.Rider-{version}.dmg",
|
||||
"aarch64-darwin": "https://download.jetbrains.com/rider/JetBrains.Rider-{version}-aarch64.dmg"
|
||||
}
|
||||
},
|
||||
@@ -92,6 +102,7 @@
|
||||
"urls": {
|
||||
"x86_64-linux": "https://download.jetbrains.com/ruby/RubyMine-{version}.tar.gz",
|
||||
"aarch64-linux": "https://download.jetbrains.com/ruby/RubyMine-{version}-aarch64.tar.gz",
|
||||
"x86_64-darwin": "https://download.jetbrains.com/ruby/RubyMine-{version}.dmg",
|
||||
"aarch64-darwin": "https://download.jetbrains.com/ruby/RubyMine-{version}-aarch64.dmg"
|
||||
}
|
||||
},
|
||||
@@ -100,6 +111,7 @@
|
||||
"urls": {
|
||||
"x86_64-linux": "https://download.jetbrains.com/rustrover/RustRover-{version}.tar.gz",
|
||||
"aarch64-linux": "https://download.jetbrains.com/rustrover/RustRover-{version}-aarch64.tar.gz",
|
||||
"x86_64-darwin": "https://download.jetbrains.com/rustrover/RustRover-{version}.dmg",
|
||||
"aarch64-darwin": "https://download.jetbrains.com/rustrover/RustRover-{version}-aarch64.dmg"
|
||||
}
|
||||
},
|
||||
@@ -108,6 +120,7 @@
|
||||
"urls": {
|
||||
"x86_64-linux": "https://download.jetbrains.com/webstorm/WebStorm-{version}.tar.gz",
|
||||
"aarch64-linux": "https://download.jetbrains.com/webstorm/WebStorm-{version}-aarch64.tar.gz",
|
||||
"x86_64-darwin": "https://download.jetbrains.com/webstorm/WebStorm-{version}.dmg",
|
||||
"aarch64-darwin": "https://download.jetbrains.com/webstorm/WebStorm-{version}-aarch64.dmg"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
# nix run --impure --expr 'with import <nixpkgs> {}; jupyter-console.withSingleKernel clojupyter.definition'
|
||||
|
||||
# Jupyter notebook:
|
||||
# nix shell --impure --expr 'with import <nixpkgs> {}; [ (jupyter.override { definitions.clojure = clojupyter.definition; }) ]' -c jupyter-notebook
|
||||
# nix run --impure --expr 'with import <nixpkgs> {}; jupyter.override { definitions.clojure = clojupyter.definition; }'
|
||||
|
||||
let
|
||||
cljdeps = import ./deps.nix { inherit pkgs; };
|
||||
|
||||
@@ -12,7 +12,7 @@
|
||||
# nix run --impure --expr 'with import <nixpkgs> {}; jupyter-console.withSingleKernel octave-kernel.definition'
|
||||
|
||||
# Jupyter notebook:
|
||||
# nix shell --impure --expr 'with import <nixpkgs> {}; [ (jupyter.override { definitions.octave = octave-kernel.definition; }) ]' -c jupyter-notebook
|
||||
# nix run --impure --expr 'with import <nixpkgs> {}; jupyter.override { definitions.octave = octave-kernel.definition; }'
|
||||
|
||||
let
|
||||
kernel = callPackage ./kernel.nix {
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
# nix run --impure --expr 'with import <nixpkgs> {}; jupyter-console.withSingleKernel wolfram-for-jupyter-kernel.definition'
|
||||
|
||||
# Jupyter notebook:
|
||||
# nix shell --impure --expr 'with import <nixpkgs> {}; [ (jupyter.override { definitions.wolfram = wolfram-for-jupyter-kernel.definition; }) ]' -c jupyter-notebook
|
||||
# nix run --impure --expr 'with import <nixpkgs> {}; jupyter.override { definitions.wolfram = wolfram-for-jupyter-kernel.definition; }'
|
||||
|
||||
let
|
||||
kernel = callPackage ./kernel.nix { };
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
stdenv,
|
||||
}:
|
||||
rec {
|
||||
version = "9.2.0541";
|
||||
version = "9.2.0782";
|
||||
|
||||
outputs = [
|
||||
"out"
|
||||
@@ -15,7 +15,7 @@ rec {
|
||||
owner = "vim";
|
||||
repo = "vim";
|
||||
rev = "v${version}";
|
||||
hash = "sha256-M2vdIAM3P2MZdcMvFX/3/fixliTosR06nvPIX7NXFNo=";
|
||||
hash = "sha256-D4IyDgl1JdmumDzO0uMg2LhoSnFUeqhcMJ6ImC17wzs=";
|
||||
};
|
||||
|
||||
enableParallelBuilding = true;
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user