Compare commits

..

258 Commits

Author SHA1 Message Date
sterni
ea31f133da haskell.packages.microhs.time: 1.16 -> 1.16.0.1
(To fix evaluation.)
2026-07-25 11:36:16 +02:00
nixpkgs-ci[bot]
5a5cd26432 Merge a016e17772 into haskell-updates 2026-07-25 00:37:35 +00:00
Lukas Epple
d47687c04d [haskell-updates] haskellPackages: stackage Nightly 2026-07-13 -> Nightly 2026-07-24 (#545393) 2026-07-24 21:53:13 +00:00
sterni
08f0950a50 haskell.packages.microhs.haskeline: 0.8.4.1 -> 0.8.5.0
(To fix evaluation.)
2026-07-24 23:35:24 +02:00
sterni
f4c6e009f9 haskellPackages.yesod-test: avoid infinite recursion 2026-07-24 23:28:15 +02:00
sterni
a1beaf2803 haskellPackages.no-recursion: drop obsolete override 2026-07-24 23:25:28 +02:00
sterni
3594aefa35 haskellPackages: stackage Nightly 2026-07-13 -> Nightly 2026-07-24
all-cabal-hashes: 2026-07-15T08:37:28Z -> 2026-07-24T18:50:05Z

(generated by maintainers/scripts/haskell/update-package-set.sh)
2026-07-24 22:05:31 +02:00
Lukas Epple
3b19ff96a1 [haskell-updates] haskell.packages.ghc9125: 9.12.4.20260614 -> 9.12.4.20260713 (#544619) 2026-07-24 20:01:07 +00:00
nixpkgs-ci[bot]
19573606e8 Merge e220185ff6 into haskell-updates 2026-07-24 00:34:22 +00:00
nixpkgs-ci[bot]
7632f2c418 Merge 6e369fe949 into haskell-updates 2026-07-23 00:36:30 +00:00
sterni
b393efc343 haskell.packages.ghc9125: 9.12.4.20260614 -> 9.12.4.20260713
rc2 -> rc3
2026-07-22 19:32:38 +02:00
nixpkgs-ci[bot]
eef2380c20 Merge dde6423243 into haskell-updates 2026-07-22 00:34:47 +00:00
nixpkgs-ci[bot]
e3c24ee8db Merge c91334b372 into haskell-updates 2026-07-21 00:36:50 +00:00
Malte Ott
116208d9cf haskellPackages.hie-bios: restrict to 0.19 (#543505) 2026-07-20 15:54:18 +00:00
nixpkgs-ci[bot]
a332844436 Merge cbf17f2c3c into haskell-updates 2026-07-20 00:39:47 +00:00
Alexandre Esteves
86ed8342de haskellPackages: regenerate package set based on current config 2026-07-19 13:45:57 +01:00
Alexandre Esteves
31f495afe9 haskellPackages.hie-bios: restrict to 0.19 2026-07-19 13:45:49 +01:00
nixpkgs-ci[bot]
da941382a6 Merge 2a83e50fab into haskell-updates 2026-07-19 00:37:23 +00:00
Wolfgang Walther
920b50911d [haskell-updates] haskellPackages: stackage Nightly 2026-06-26 -> Nightly 2026-07-13 (#543047) 2026-07-18 06:01:42 +00:00
Wolfgang Walther
43159787fd haskellPackages.rerefined: allow QuickCheck 2.16 (#536459) 2026-07-18 06:01:28 +00:00
nixpkgs-ci[bot]
a603053a30 Merge b5d95a3fd3 into haskell-updates 2026-07-18 00:34:07 +00:00
Wolfgang Walther
5865c4be2c haskellPackages.postgres-websockets: update jailbreak 2026-07-17 22:39:16 +02:00
Wolfgang Walther
b72ec6bdee haskellPackages.no-recursion: warn for obsolete override
A fix has been merged upstream, but not released, yet - so adding the
warning to pick that up automatically on the next bump.
2026-07-17 22:39:08 +02:00
Wolfgang Walther
c818fb7e53 haskellPackages: drop various obsolete overrides after hackage bump 2026-07-17 22:39:04 +02:00
Wolfgang Walther
88daa4b688 haskellPackages: regenerate hackage-packages.nix 2026-07-17 22:33:28 +02:00
Wolfgang Walther
d82c0d269e haskellPackages.mlkem: disable tests 2026-07-17 22:33:26 +02:00
Wolfgang Walther
0b6b59708c haskellPackages: stackage Nightly 2026-06-26 -> Nightly 2026-07-13
all-cabal-hashes: 2026-06-26T06:10:51Z -> 2026-07-15T08:37:28Z

(generated by maintainers/scripts/haskell/update-package-set.sh)
2026-07-17 22:33:25 +02:00
Wolfgang Walther
9220258efb haskellPackages.mlkem: unmark broken
This package is still effectively broken at this stage, but the next
bump to stackage will add mlkem as a dependency of tls, which is in the
dependency chain of cabal2nix itself.

The same bump will update crypton and thus make mlkem build - but we
can't mark it unbroken, when cabal2nix-unstable fails to run because one
of its dependencies is marked broken...
2026-07-17 22:09:38 +02:00
nixpkgs-ci[bot]
a8560ee995 Merge 3caf6c92ce into haskell-updates 2026-07-17 00:36:58 +00:00
nixpkgs-ci[bot]
cfdc80cdd7 Merge 8288eae5a4 into haskell-updates 2026-07-16 00:35:07 +00:00
Wolfgang Walther
523ffbe971 haskellPackages.rapid: patch bounds (#541874) 2026-07-15 06:41:29 +00:00
nixpkgs-ci[bot]
3aed88a715 Merge 2c726dc782 into haskell-updates 2026-07-15 00:30:56 +00:00
Alexandre Esteves
1c3465fcb7 haskellPackages: regenerate package set based on current config 2026-07-14 17:57:03 +01:00
Alexandre Esteves
54112f9a6b haskellPackages.rapid: patch bounds 2026-07-14 17:56:50 +01:00
nixpkgs-ci[bot]
92cbc9ca81 Merge d95279435c into haskell-updates 2026-07-14 00:33:37 +00:00
nixpkgs-ci[bot]
6a3c990a99 Merge 310b8cc6a5 into haskell-updates 2026-07-13 00:38:09 +00:00
nixpkgs-ci[bot]
39ee207b1d Merge dd93798a29 into haskell-updates 2026-07-12 00:38:11 +00:00
nixpkgs-ci[bot]
d64edb78f9 Merge ffc7f8ce99 into haskell-updates 2026-07-11 00:36:01 +00:00
nixpkgs-ci[bot]
54726cb9e3 Merge 0e6ff04fc5 into haskell-updates 2026-07-10 00:42:12 +00:00
nixpkgs-ci[bot]
b7659cdb62 Merge 8ab1ccd1c1 into haskell-updates 2026-07-09 00:41:01 +00:00
nixpkgs-ci[bot]
bcf85400c4 Merge bd3c09ca2a into haskell-updates 2026-07-08 00:36:49 +00:00
nixpkgs-ci[bot]
e3927c07f7 Merge 60f3895575 into haskell-updates 2026-07-07 00:43:55 +00:00
nixpkgs-ci[bot]
8486e8a7b3 Merge fbdfe58264 into haskell-updates 2026-07-06 00:43:34 +00:00
nixpkgs-ci[bot]
4f0970401a Merge 7d5d19274b into haskell-updates 2026-07-05 00:43:51 +00:00
nixpkgs-ci[bot]
9959ce2f44 Merge f91cfe02f8 into haskell-updates 2026-07-04 00:40:56 +00:00
nixpkgs-ci[bot]
3f085fe61c Merge 9778ed5674 into haskell-updates 2026-07-03 00:42:09 +00:00
Wolfgang Walther
f61423d87c haskellPackages.lambdabot: remove ncfavier as maintainer (#537887) 2026-07-02 19:57:54 +00:00
Naïm Camille Favier
4aeebf57da haskellPackages.lambdabot: remove ncfavier as maintainer 2026-07-02 19:38:32 +02:00
Wolfgang Walther
4c7647a6d3 haskell.packages.ghc{96,98}.haskell-language-server: fix build (#537724) 2026-07-02 10:10:33 +00:00
Wolfgang Walther
afda14f1d4 dhall-lsp-server: fix build with lsp 2.8 2026-07-02 10:31:48 +02:00
Wolfgang Walther
e9af2ed4be haskellPackages.no-recursion: jailbreak 2026-07-02 10:23:39 +02:00
Wolfgang Walther
2735e861f0 haskell.packages.ghc{96,98}.haskell-language-server: fix build
Jailbreaks are due to optparse-applicative.
2026-07-02 10:07:26 +02:00
Wolfgang Walther
92ca07b6a5 haskellPackages.threadscope: jailbreak 2026-07-02 09:48:12 +02:00
Wolfgang Walther
e82d6b924f haskellPackages.taskwarrior: jailbreak 2026-07-02 09:43:24 +02:00
Wolfgang Walther
94aa8f8960 haskellPackages.shh{,-extras}: jailbreak 2026-07-02 09:41:11 +02:00
Wolfgang Walther
75496eb67a haskellPackages.eventlog2html: jailbreak 2026-07-02 09:36:13 +02:00
Wolfgang Walther
9c55dbeccf [haskell-updates] stack: patch for semaphore-compat >= 2.0 (#534567) 2026-07-02 07:25:00 +00:00
Wolfgang Walther
cef090d1ab haskellPackages.optics: pick patches that make test suite pass with 9.12 (#536009) 2026-07-02 07:19:43 +00:00
sterni
4132fb9736 haskellPackages.optics: pick patches that make test suite pass with 9.12
I'm not 100% clear whether there is still some kind of GHC regression
involved here, but I think we can pick these patches from upstream's
development branch. Also GHC upstream is aware of these (original)
failures with 9.12.5-rc2.
2026-07-02 09:13:52 +02:00
Wolfgang Walther
98c655c09a haskellPackages.*: compile a few test suites with threaded runtime (#537144) 2026-07-02 07:06:56 +00:00
nixpkgs-ci[bot]
3f49232af6 Merge 8037b1aab1 into haskell-updates 2026-07-02 00:50:41 +00:00
nixpkgs-ci[bot]
7100632254 Merge 5bb269961b into haskell-updates 2026-07-01 00:56:02 +00:00
Alexandre Esteves
b078be0041 haskellPackages.*: compile a few test suites with threaded runtime 2026-07-01 01:01:33 +01:00
nixpkgs-ci[bot]
92779d4478 Merge 3b1d058d00 into haskell-updates 2026-06-30 00:53:14 +00:00
sterni
070e7a021f haskellPackages.futhark-manifest: use version requested by futhark-0.26.3 2026-06-29 23:56:40 +02:00
Wolfgang Walther
71b5964ed6 haskellPackages.{yaya*}: allow doctest 0.25 (#536739) 2026-06-29 18:04:32 +00:00
Wolfgang Walther
00a35c51c7 haskellPackages.{yaya*}: allow doctest 0.25 2026-06-29 19:55:06 +02:00
Wolfgang Walther
dbd129b241 haskellPackages.graphviz: allow QuickCheck 2.16 (#536737) 2026-06-29 17:54:14 +00:00
Wolfgang Walther
26066e1e2b haskellPackages.graphviz: allow QuickCheck 2.16 2026-06-29 19:28:59 +02:00
nixpkgs-ci[bot]
60f1d07046 Merge 2df5d1313a into haskell-updates 2026-06-29 00:55:22 +00:00
Wolfgang Walther
a5e06de0c4 haskellPackages.servant-{auth-client,auth-docs,auth-server,swagger}: jailbreak (#536456) 2026-06-28 22:21:46 +00:00
Wolfgang Walther
8833922b3e haskellPackages.rerefined: allow QuickCheck 2.16 2026-06-28 23:57:31 +02:00
Wolfgang Walther
d0e8fdd1bd haskellPackages.servant-{auth-client,auth-docs,auth-server,swagger}: jailbreak 2026-06-28 23:39:46 +02:00
sterni
9122c84035 git-annex: delete unused patch file 2026-06-28 16:15:35 +02:00
sterni
f479cbacab stack: apply patches for semaphore-compat >= 2.0
Apply patches from https://github.com/commercialhaskell/stack/pull/6935
allowing us to build stack with GHC 9.12.5-rc2 (but no other GHC version).
Patch for the change log is not included (due to likely conflict problems),
but other documentation included with stack is updated.

We also apply an unrelated bug fix, so we don't need to rebase the patches.
2026-06-28 16:12:15 +02:00
sterni
f87fabdc91 stack: drop released patch 2026-06-28 16:11:51 +02:00
sterni
f94cecf640 haskell.packages.ghc910.stack: remove compat code
Ideally, we won't use this going forward and just build stack with GHC 9.12
2026-06-28 15:45:51 +02:00
Wolfgang Walther
fc0932307c pkgsStatic.haskell.packages.native-bignum.ghc948.postgrest: fix build
Removes a dependency which had long been replaced upstream, but the
expression is still generated from the outdated hackage package.

The GHC 9.4.8 static variant is still used upstream, but we will be able
to remove it from the release set on PostgREST's next release.
2026-06-28 10:47:04 +02:00
Wolfgang Walther
ffbec19b05 haskellPackages.git-annex: update hash 2026-06-28 10:32:42 +02:00
nixpkgs-ci[bot]
435e7264b6 Merge bdd995eaee into haskell-updates 2026-06-28 00:54:07 +00:00
sternenseemann
480f0726e7 [haskell-updates] haskellPackages: stackage Nightly 2026-06-20 -> Nightly 2026-06-26 (#534748) 2026-06-27 11:29:35 +00:00
nixpkgs-ci[bot]
4d0ae93287 Merge 538087c016 into haskell-updates 2026-06-27 00:52:07 +00:00
sternenseemann
81ef0ce73b haskellPackages.wai-app-file-cgi: pin to < 3.2.0 for mighttpd2 (#535246) 2026-06-26 11:13:45 +00:00
sterni
24211dd381 haskellPackages.wai-app-file-cgi: pin to < 3.2.0 for mighttpd2
Requires picking a compat patch from 3.2.1 for http-types-0.12.5.
2026-06-26 13:04:54 +02:00
sterni
8b99224c3e haskellPackages.statistics: drop obsolete override 2026-06-26 10:48:10 +02:00
sterni
d56383f426 haskellPackages: stackage Nightly 2026-06-20 -> Nightly 2026-06-26
all-cabal-hashes: 2026-06-20T12:32:58Z -> 2026-06-26T06:10:51Z

(generated by maintainers/scripts/haskell/update-package-set.sh)
2026-06-26 10:48:10 +02:00
nixpkgs-ci[bot]
2836c4b1f4 Merge 19e056881c into haskell-updates 2026-06-26 00:54:38 +00:00
Wolfgang Walther
16a3b0c7d9 [haskell-updates] git-annex: unbreak (#534543) 2026-06-25 08:31:42 +00:00
Wolfgang Walther
7db16b7a40 top-level/release-haskell.nix: use ghc 9.12 in versioned jobs (#534745) 2026-06-25 07:55:36 +00:00
nixpkgs-ci[bot]
85b5c86354 Merge 19a053f28c into haskell-updates 2026-06-25 00:53:29 +00:00
nixpkgs-ci[bot]
3f6c25ad80 Merge dd4c7b49b6 into haskell-updates 2026-06-24 00:48:36 +00:00
sterni
a8988fede0 top-level/release-haskell.nix: drop ghc9125 exclusions
These packages need to work in the default package set anyways!
2026-06-23 23:36:56 +02:00
sterni
68f69e8b05 top-level/release-haskell.nix: prefer ghc9125 over ghc9123 2026-06-23 23:36:56 +02:00
Robert Hensing
9bbb567bb9 haskellPackages.hercules-ci-optparse-applicative: 0.19.0.0-fork-0 -> 0.19.0.0-fork-1 2026-06-23 17:11:40 +02:00
sterni
5f8a3af9eb haskellPackages.git-annex: patch for http-types >= 0.12.5 2026-06-23 12:55:31 +02:00
sterni
b25e3e8489 git-annex: update sha256 for 10.20260601 2026-06-23 12:55:31 +02:00
sterni
a220c38f46 haskellPackages.cabal2nix-unstable: 2026-03-30 -> 2026-06-23
This makes sure the libmagic dependency of haskellPackages.magic
is resolved correctly again.
2026-06-23 12:55:25 +02:00
sterni
fdbcfd8b47 haskellPackages.statistics: allow doctest >= 0.25 2026-06-23 10:17:49 +02:00
sterni
eff6c0e60e darcs: patch incompatibilities with Stackage Nightly and Cabal 3.14 2026-06-23 10:17:49 +02:00
nixpkgs-ci[bot]
5a03008b47 Merge 691bc285bc into haskell-updates 2026-06-23 00:52:15 +00:00
nixpkgs-ci[bot]
6dd4da168b Merge 6e7f01b46b into haskell-updates 2026-06-22 00:59:28 +00:00
Alexandre Esteves
4cbc2251c7 haskellPackages.haskell-language-server: fix or bump deps (#525752) 2026-06-22 00:38:49 +00:00
Alexandre Esteves
a8233a24e1 haskellPackages: regenerate package set based on current config 2026-06-21 23:04:56 +01:00
Alexandre Esteves
da4f3989f0 haskellPackages.haskell-language-server: add myself as maintainer including deps 2026-06-21 22:44:59 +01:00
Alexandre Esteves
e0497b3d10 haskellPackages: drop obsolete package upgrades 2026-06-21 22:44:07 +01:00
Alexandre Esteves
a49c815e3d haskellPackages: regenerate package set based on current config 2026-06-21 22:43:24 +01:00
Alexandre Esteves
f213d6af36 haskellPackages.haskell-language-server: unrestrict deps 2026-06-21 22:30:23 +01:00
Alexandre Esteves
aba749b3bb haskellPackages.stylish-haskell: patch bound 2026-06-21 22:30:07 +01:00
Wolfgang Walther
e64658550c cabal-install: patch for compatibility with semaphore-compat-2.0.0 (#531658) 2026-06-21 09:11:29 +00:00
Wolfgang Walther
07d2edc929 haskellPackages.gitit: drop obsolete overrides 2026-06-21 10:47:07 +02:00
nixpkgs-ci[bot]
b52ea84a40 Merge dccba7b9f2 into haskell-updates 2026-06-21 00:59:34 +00:00
sterni
f394a62a65 cabal-install: patch for compatibility with semaphore-compat-2.0.0
This is necessary pending a release of cabal-install-3.18 (and Cabal-3.18).
Since the patch for Cabal changes the public API, I've chosen to only
apply it inside the cabal-install overlay for now.
2026-06-21 02:39:54 +02:00
sternenseemann
ad66699b02 [haskell-updates] haskellPackages: stackage Nightly 2026-06-09 -> Nightly 2026-06-16 (#530271) 2026-06-21 00:30:46 +00:00
sterni
084d450fa7 haskell.packages.ghc9125: 9.12.4.20260606 -> 9.12.4.20260614 2026-06-20 19:18:03 +02:00
Wolfgang Walther
ec138222f7 haskellPackages.postgres-websockets: jailbreak (wai-app-static) 2026-06-20 19:18:03 +02:00
sterni
5a13f175d1 haskellPackages.hakyll-filestore: drop obsolete override 2026-06-20 19:18:03 +02:00
Wolfgang Walther
117625921f haskellPackages.hw-prim: drop obsolete jailbreak 2026-06-20 19:18:03 +02:00
Wolfgang Walther
2c44031fe0 haskellPackages.vector: drop obsolete jailbreak 2026-06-20 19:18:03 +02:00
sterni
d34ba4d817 haskellPackages: stackage Nightly 2026-06-09 -> Nightly 2026-06-20
all-cabal-hashes: 2026-06-09T15:28:54Z -> 2026-06-20T12:32:58Z

(generated by maintainers/scripts/haskell/update-package-set.sh)
2026-06-20 19:18:02 +02:00
nixpkgs-ci[bot]
e34ce374a1 Merge 6c91888634 into haskell-updates 2026-06-20 00:54:18 +00:00
nixpkgs-ci[bot]
a00be59a94 Merge f7df78e77a into haskell-updates 2026-06-19 01:03:53 +00:00
nixpkgs-ci[bot]
ab20ff9b2f Merge a0fe7a7f2e into haskell-updates 2026-06-18 00:58:39 +00:00
nixpkgs-ci[bot]
995d34a153 Merge 8cf9f7fff1 into haskell-updates 2026-06-17 00:58:42 +00:00
Wolfgang Walther
9208b19946 haskellPackages.{rvar,QuickCheck-safe}: fix build (#531374) 2026-06-16 20:14:29 +00:00
nixpkgs-ci[bot]
9029909ba3 Merge 5a21d1bfee into haskell-updates 2026-06-16 01:04:21 +00:00
nixpkgs-ci[bot]
b82be3afe6 Merge 635f366cf9 into haskell-updates 2026-06-15 00:59:45 +00:00
Naïm Camille Favier
248b70dc3b haskellPackages.QuickCheck-safe: allow build with QuickCheck 2.16 2026-06-14 16:11:41 +02:00
Naïm Camille Favier
0baca65faa haskellPackages.{rvar,random-fu}: fix build 2026-06-14 16:11:11 +02:00
nixpkgs-ci[bot]
b1528a1baf Merge a18d24ff2b into haskell-updates 2026-06-14 00:57:26 +00:00
Wolfgang Walther
200316c491 haskellPackages/fused-effects: jailbreak because of too tight hedgedoc dep (#531331) 2026-06-13 12:49:06 +00:00
mangoiv
3c4f10205c haskellPackages/fused-effects: jailbreak because of too tight hedgedog dep 2026-06-13 14:03:44 +02:00
Wolfgang Walther
827c840fb1 haskellPackages.validation: pin to 1.1.5 (#530365) 2026-06-13 11:43:41 +00:00
Allen Du
095f6729ca haskellPackages.validation: pin to 1.1.5 2026-06-13 10:17:35 +02:00
Wolfgang Walther
1352e67378 haskellPackages: regenerate hackage-packages.nix 2026-06-13 10:17:11 +02:00
nixpkgs-ci[bot]
0814616eaf Merge 08740d8811 into haskell-updates 2026-06-13 00:57:33 +00:00
nixpkgs-ci[bot]
f70431ea67 Merge 20c18080b0 into haskell-updates 2026-06-12 00:58:47 +00:00
sterni
8383c3f904 haskellPackages.hakyll-filestore: allow hakyll >= 4.17 2026-06-11 22:38:23 +02:00
nixpkgs-ci[bot]
cac8c10692 Merge d9c4084332 into haskell-updates 2026-06-11 00:55:35 +00:00
Wolfgang Walther
739281cf7a haskellPackages.yesod-middleware-csp: jailbreak & unbreak (#529859) 2026-06-10 09:49:07 +00:00
Michael Schneider
ef5a2561e3 haskellPackages.yesod-middleware-csp: 1.2.0 -> 1.3.0 2026-06-10 16:40:50 +07:00
sterni
a5f1afdf0f haskellPackages.pandoc: drop patch applied by upstream 2026-06-10 06:40:59 +02:00
sternenseemann
cbe86ed815 [haskell-updates] haskellPackages: stackage Nightly 2026-05-27 -> Nightly 2026-06-07 (#529097) 2026-06-09 16:33:20 +00:00
Wolfgang Walther
5617c0ba47 haskellPackages: stackage Nightly 2026-05-27 -> Nightly 2026-06-09
all-cabal-hashes: 2026-05-28T09:17:22Z -> 2026-06-09T15:28:54Z

(generated by maintainers/scripts/haskell/update-package-set.sh)

Co-authored-by: sterni <sternenseemann@systemli.org>
2026-06-09 18:08:40 +02:00
sternenseemann
caf8327196 git-annex: build against filepath-bytestring instead of file-io (#527916) 2026-06-09 15:35:27 +00:00
sternenseemann
89b9cdcbba haskellPackages.{bitwise,psqueues,xz}: drop override (#525905) 2026-06-09 15:33:55 +00:00
sternenseemann
3c3354afa3 haskell.packages.ghc912: 9.12.3 -> 9.12.4.20260606 (#529900) 2026-06-09 15:11:44 +00:00
sterni
8cc9c34bcb haskell.packages.ghc9{4,6}.semaphore-compat: 1.0.0 -> 2.0.0
This matches GHC 9.12.5.
2026-06-09 15:49:31 +02:00
sterni
8c3d964e79 haskell.packages.ghc912: 9.12.3 -> 9.12.4.20260606 2026-06-09 13:54:57 +02:00
nixpkgs-ci[bot]
cadaf97e4e Merge 3438114c15 into haskell-updates 2026-06-09 00:50:54 +00:00
nixpkgs-ci[bot]
593c21a56a Merge f77c3e23e5 into haskell-updates 2026-06-08 00:57:17 +00:00
Wolfgang Walther
6306c15610 elmPackages.elm-format: jailbreak (#529072) 2026-06-07 10:03:20 +00:00
Marek Fajkus
884892c2c1 elmPackages.elm-format: jailbreak 2026-06-07 11:40:59 +02:00
nixpkgs-ci[bot]
627dd785ad Merge 38d9adc8ca into haskell-updates 2026-06-07 00:56:22 +00:00
nixpkgs-ci[bot]
180157dfa4 Merge b99e1dabec into haskell-updates 2026-06-06 00:52:21 +00:00
Wolfgang Walther
0d1190abf7 haskellPackages.duckdb-simple: jailbreak (#528095) 2026-06-05 20:49:03 +00:00
nixpkgs-ci[bot]
c24d964453 Merge fcfb4d2c1c into haskell-updates 2026-06-05 00:55:21 +00:00
Allen Du
9ec4c8e1b6 haskellPackages.duckdb-simple: jailbreak
too strict bounds on QuickCheck <2.16
2026-06-04 15:30:54 -04:00
sternenseemann
b32a192bcf mkjson: disable doctests and switch to Codeberg (#527977) 2026-06-04 14:05:55 +00:00
Troels Henriksen
338f88c94a mkjson: disable doctests and switch to Codeberg 2026-06-04 15:43:27 +02:00
sternenseemann
a262ae9474 haskellPackages.servant-mutlipart-core: jailbreak (#527963) 2026-06-04 12:56:45 +00:00
sterni
9f367b9af0 haskellPackages.hakyll-alectryon: allow hakyll 4.17 2026-06-04 14:50:03 +02:00
sterni
9227423f57 haskellPackages.hakyll-images: drop obsolete override
Test suite was fixed in 1.3.1
2026-06-04 14:48:33 +02:00
sorki
79b85a6061 haskellPackages.servant-mutlipart-core: jailbreak
Pending issue / PR
https://github.com/haskell-servant/servant-multipart/issues/76
https://github.com/haskell-servant/servant-multipart/pull/77
2026-06-04 14:47:10 +02:00
sterni
07837352f5 git-annex: build against filepath-bytestring instead of file-io
Unfortunately, file-io >= 0.2 is required which conflicts with the core
package shipped with GHC.
2026-06-04 12:51:17 +02:00
sterni
422b020e60 git-annex: update sha256 for 10.20260525 2026-06-04 12:50:48 +02:00
nixpkgs-ci[bot]
d58b43bad8 Merge 0cc225cd89 into haskell-updates 2026-06-04 01:02:38 +00:00
nixpkgs-ci[bot]
e4e45c45d7 Merge 52383c55bc into haskell-updates 2026-06-03 01:03:22 +00:00
Wolfgang Walther
a0811c1859 haskellPackages.dataframe: unpin from 0.3.3.6 (#526717) 2026-06-02 06:42:04 +00:00
nixpkgs-ci[bot]
41dec8b399 Merge e7713b176c into haskell-updates 2026-06-02 00:57:41 +00:00
Ai-Ya-Ya
4b9529d490 haskellPackages.pinch: jailbreak
bump already merged upstream, awaiting new Hackage release
2026-06-01 23:59:36 +00:00
Ai-Ya-Ya
eca559367a haskellPackages.dataframe: unpin from 0.3.3.6
later version of dataframe removed dependency on random-1.3 so safe to
unpin
2026-06-01 18:48:15 +00:00
Wolfgang Walther
d217b14de6 haskellPackages.haskell-ci: 0.18.1 -> 0.19.20260331 (#525918) 2026-06-01 17:41:44 +00:00
nixpkgs-ci[bot]
5aafdde3a0 Merge 501880c9da into haskell-updates 2026-06-01 00:54:54 +00:00
nixpkgs-ci[bot]
9eb68607ef Merge 78058c8132 into haskell-updates 2026-05-31 00:54:34 +00:00
sterni
430963bdf1 haskellPackages.haskell-ci: 0.18.1 -> 0.19.20260331
This plus a bunch of workarounds fixes the build of haskell-ci with
Stackage Nightly.
2026-05-30 13:03:39 +02:00
Wolfgang Walther
4ca20a7582 haskellPackages.xz: drop override
Fixed in a new revision on the latest hackage bump.
2026-05-30 12:31:51 +02:00
Wolfgang Walther
39ad1cb021 haskellPackages.psqueues: drop override
Fixed in a new revision on the latest hackage bump.
2026-05-30 12:30:57 +02:00
Wolfgang Walther
6ad984ce3d haskellPackages.bitwise: drop override
Fixed in a new revision on the latest hackage bump.
2026-05-30 12:30:31 +02:00
sternenseemann
8b0587a6d1 haskellPackages.pdftotext: fix build (#525219) 2026-05-30 10:17:08 +00:00
sterni
668847dd15 haskellPackages.hoogle: unpin
This pin should _not_ have survived this long!
2026-05-30 11:42:25 +02:00
Wolfgang Walther
40f0c70593 postgrest: fix build (#524050) 2026-05-30 08:48:06 +00:00
nixpkgs-ci[bot]
265fda252f Merge ce8325fa0e into haskell-updates 2026-05-30 00:50:33 +00:00
sterni
e1eeed9ea6 release-haskell.nix: test haddock-{api,library} on GHC < 9.12
At least where possible.
2026-05-29 12:45:02 +02:00
sterni
d3928686c3 haskell.packages.ghc96.haddock-api: ignore overly strict bounds 2026-05-29 12:45:02 +02:00
sterni
fb629a8712 haskell.packages.ghc94.haddock-{api,library}: provide matching versions
GHC >= 9.12 ships these libraries as a core package, so we need to manually
pick them for older package sets. Given that they depend on the ghc library,
they actually need to match.

The broken flag on haddock-api is pretty much bogus now, as it isn't
even built as part of the main package set anymore (but with ghc as a
core pkg), but haskell.packages.ghc9{8,10}.haddock-api need to be marked
as broken since no releases compatible with GHC 9.10 or 9.8 have been
made to Hackage.
2026-05-29 12:44:22 +02:00
sterni
1fa9545db7 haskell.packages.ghc94.file-io: don't try to provide
file-io depends on unix >= 2.8 which isn't included with GHC 9.4, so we
can't properly build file-io in this package set (without making it
inconsist). Our best shot at making packages “just work” is hoping the
use Cabal conditionals to depend on file-io, so file-io doesn't actually
wind up being necessary for GHC 9.4.

If file-io is absolutely necessary, manual package specific intervention
will be necessary either way.
2026-05-29 12:42:44 +02:00
sterni
7b203a8cdf haskell.packages.ghc9{0,4,6}.semaphore-compat: keep using 1.0.0
semaphore-compat 2.0.0 has just been released, but no GHC ships it as
a core package yet, so using 1.0.0 for GHC <9.8 makes more sense as it
matches Stackage Nightly.
2026-05-29 12:42:43 +02:00
sternenseemann
3080e495c5 haskellPackages.amazonka: fix build (#525212) 2026-05-29 09:53:03 +00:00
nixpkgs-ci[bot]
41a68a1180 Merge 7b97a86791 into haskell-updates 2026-05-29 00:53:02 +00:00
Marc Scholten
2c84961290 haskellPackages.pdftotext: fix build 2026-05-28 17:35:29 +01:00
Marc Scholten
eb378a86bf haskellPackages.amazonka: fix build 2026-05-28 15:59:22 +01:00
sternenseemann
b8880df8ac haskell.packages.ghc902Binary: fix evaluation of package set (#496292) 2026-05-28 10:49:59 +00:00
sternenseemann
79a87d6750 haskell.packages.ghc902Binary: fix evaluation of package set
These attributes need to be present, so that callPackage doesn't fail
with an unrecoverable error on some members of the package set. This
is not necessary for any package Hydra builds, but helps for listing/
inspecting the package set.
2026-05-28 12:40:26 +02:00
sternenseemann
61b9e0b5f4 haskell.packages.microhs: fix eval after bump to nightly (#522940) 2026-05-28 10:28:38 +00:00
sternenseemann
2cb1137ad8 [haskell-updates] haskellPackages: stackage Nightly 2026-05-16 -> Nightly 2026-05-27 (#525157) 2026-05-28 10:24:12 +00:00
sterni
dc341cc322 haskell.packages.microhs: fix eval after bump to nightly 2026-05-28 12:23:16 +02:00
sternenseemann
7ef227eef6 haskellPackages.ghc-typelits-natnormalise: fix tests (#524100) 2026-05-28 10:17:40 +00:00
sterni
df2259de34 haskellPackages.os-string_2_0_10: drop obsolete jailbreak 2026-05-28 12:12:18 +02:00
sterni
fbfe792c92 haskellPackages: stackage Nightly 2026-05-16 -> Nightly 2026-05-27
all-cabal-hashes: 2026-05-16T18:12:46Z -> 2026-05-28T09:17:22Z

(generated by maintainers/scripts/haskell/update-package-set.sh)
2026-05-28 12:07:57 +02:00
nixpkgs-ci[bot]
18c743b5c9 Merge 8be06063cd into haskell-updates 2026-05-28 00:46:19 +00:00
Marc Scholten
1912d24658 haskellPackages.ghc-typelits-natnormalise: fix tests
Tests spawn ghc with -fplugin and need the package's in-place package database in NIX_GHC_PACKAGE_PATH_FOR_TEST.

Put the override in configuration-nix.nix so it applies across GHC package sets.

Assisted-by: OpenAI Codex (GPT-5)
2026-05-27 10:42:28 +01:00
nixpkgs-ci[bot]
8b3bed966a Merge c0523a4c8f into haskell-updates 2026-05-27 00:51:00 +00:00
nixpkgs-ci[bot]
8ca5572327 Merge 0a6619d2fd into haskell-updates 2026-05-26 01:34:21 +00:00
nixpkgs-ci[bot]
f1cd3a542b Merge 3ab9d06032 into haskell-updates 2026-05-26 00:48:54 +00:00
Wolfgang Walther
28ea7d3e94 postgrest: fix build
text-builder-dev 0.3.10 needs lawful-conversions < 0.2.

postgrest itself still depends on the older insert-ordered-containers <
0.3, but swagger2 - despite trying to provide a "compat" layer - fails
to build with that, so we pin both of them.
2026-05-25 16:51:13 +02:00
nixpkgs-ci[bot]
015d2be85f Merge 7e18ec5706 into haskell-updates 2026-05-25 14:15:27 +00:00
nixpkgs-ci[bot]
dcd5f66215 Merge 68d9bb691b into haskell-updates 2026-05-25 00:50:42 +00:00
nixpkgs-ci[bot]
c990defdc1 Merge 89afca31a7 into haskell-updates 2026-05-24 00:49:43 +00:00
nixpkgs-ci[bot]
ef80ea96c0 Merge ee4a6d835b into haskell-updates 2026-05-23 00:48:26 +00:00
nixpkgs-ci[bot]
70b3bb6148 Merge 90b4a6bcd3 into haskell-updates 2026-05-22 00:49:41 +00:00
Michael Daniels
9f87b41bbc Merge commit '8d0a7d4c0437cc1e5349d3dabde379c5e2a66305' into haskell-updates 2026-05-21 17:04:36 -04:00
Michael Daniels
9eab5d0982 Merge commit '4e39fb70d8cff0e9ffb89217d731c9b82af6473e' into haskell-updates 2026-05-19 21:10:08 -04:00
Wolfgang Walther
31b3654bd0 haskellPackages: various jailbreaks for QuickCheck 2.16 (#521243) 2026-05-18 09:51:21 +00:00
Wolfgang Walther
fd7118d37f haskell.packages.ghc{94,96,98}.os-string: allow QuickCheck 2.16 2026-05-18 11:42:42 +02:00
Wolfgang Walther
3f0c2996b0 haskellPackages.test-framework: run tests 2026-05-18 11:42:41 +02:00
Wolfgang Walther
58545c6507 haskellPackages.finite-typelits: allow QuickCheck 2.16 2026-05-18 11:42:06 +02:00
Wolfgang Walther
bd20e4d544 haskellPackages.binary-instances: allow QuickCheck 2.16 2026-05-18 11:38:35 +02:00
Wolfgang Walther
40fdae7a02 haskellPackages.proto-lens-arbitrary: update comment 2026-05-18 11:38:34 +02:00
Wolfgang Walther
4dfddc5e2d haskellPackages.hw-prim: update comment 2026-05-18 11:38:33 +02:00
Wolfgang Walther
a42cf3de47 haskellPackages.Unique: update comment 2026-05-18 11:38:32 +02:00
Wolfgang Walther
98472212df haskellPackages.hspec-core: update comment
Upstream issue is resolved, QuickCheck comment outdated - but when I try
to enable the tests, I get infinite recursion.
2026-05-18 11:38:31 +02:00
Wolfgang Walther
1166f6d5fe haskellPackages.xz: update comment 2026-05-18 11:38:30 +02:00
Wolfgang Walther
3100f81d11 haskellPackages.hgmp: drop jailbreak & unbreak
Builds fine for me.
2026-05-18 11:38:30 +02:00
Wolfgang Walther
cfae19b0e2 haskellPackages.io-sim: run tests 2026-05-18 11:38:29 +02:00
Wolfgang Walther
4c79be7954 haskellPackages.hedgehog-classes: allow hedgehog 1.6 2026-05-18 11:38:28 +02:00
Wolfgang Walther
a5d168008d haskellPackages.algebraic-graphs: allow QuickCheck 2.16 2026-05-18 11:38:27 +02:00
Wolfgang Walther
8960ba3747 haskellPackages.lzma: allow QuickCheck 2.16 2026-05-18 11:38:26 +02:00
Wolfgang Walther
4bac4c007b haskellPackages.bitwise: allow QuickCheck 2.16 2026-05-18 11:38:24 +02:00
Wolfgang Walther
449e33902d haskellPackages.fgl: allow QuickCheck 2.16 2026-05-18 11:38:24 +02:00
Wolfgang Walther
cfb525e8c7 haskellPackages.uuid: allow QuickCheck 2.16 2026-05-18 11:38:23 +02:00
Wolfgang Walther
90e108c717 haskellPackages.nix-derivation: allow QuickCheck 2.16 2026-05-18 11:38:22 +02:00
Wolfgang Walther
a9c7731b36 haskellPackages.http-api-data: allow QuickCheck 2.16 2026-05-18 11:38:21 +02:00
Wolfgang Walther
0e972a63ef haskellPackages.psqueues: allow QuickCheck 2.16 2026-05-18 11:38:19 +02:00
Wolfgang Walther
db6cdf8674 haskellPackages.{attoparsec,optparse-applicative,vecotr}: add upstream issue for QuickCheck 2.16 2026-05-18 11:38:18 +02:00
Wolfgang Walther
83742b85ed haskellPackages.criterion: drop patch
Already applied.
2026-05-18 11:36:57 +02:00
Wolfgang Walther
7fe7f911c5 haskellPackages.algebraic-graphs: drop patch
Already applied upstream.
2026-05-18 10:20:46 +02:00
Wolfgang Walther
379b9966b6 haskellPackages.pandoc: drop patches
These are already applied after the update.
2026-05-18 10:20:45 +02:00
Michael Daniels
8e147a7423 Merge commit 'c45cb29917167adb9ef5912b4bd93692cd19073e' into haskell-updates 2026-05-17 20:57:31 -04:00
sterni
e78b52efb2 haskell.packages.ghc914: drop obsolete package upgrades
We use these version by default now.
2026-05-17 15:51:05 +02:00
sternenseemann
9db26c0d78 maintainers/haskell/eval-pkg-sets.sh: add script for checking eval (#510902) 2026-05-17 13:14:33 +00:00
Wolfgang Walther
44c90f8b11 haskell.compiler.ghc{96,98,…}: drop obsolete workaround on darwin (#520191) 2026-05-17 12:41:08 +00:00
Wolfgang Walther
6ae08b4b8c haskellPackages.hpc-codecov: run obsolete override
The upstream issue has been resolved.
2026-05-17 14:38:47 +02:00
Wolfgang Walther
e71086f1ad haskellPackages: stackage LTS 24.38 -> Nightly 2026-05-16 / ghc: 9.10 -> 9.12 (#521235) 2026-05-17 12:20:08 +00:00
Wolfgang Walther
a9a7b4af3b haskellPackages.ihp{,-*}: remove overrides
hasql had been updated in the Stackage bump to Nightly, so we can just
unmark all of these at the top-level.
2026-05-17 14:08:10 +02:00
Wolfgang Walther
6e6ee420cc haskell.packages.ghc910.stack: fix eval 2026-05-17 14:05:11 +02:00
Wolfgang Walther
4f5821131d haskell.packages.ghc910.ghc-exactprint: pin 1.10
This was previously pinned via Stackage, but the update to Nightly
bumped the default to 1.12, which matches GHC 9.12.
2026-05-17 14:05:10 +02:00
Wolfgang Walther
7c90da01b9 haskellPackages: stackage LTS 24.38 -> Nightly 2026-05-16
all-cabal-hashes: 2026-04-24T19:35:23Z -> 2026-05-16T18:12:46Z

(generated by maintainers/scripts/haskell/update-package-set.sh)

Includes all manual changes required to eval and run cabal2nix-unstable
on this branch.
2026-05-17 13:57:57 +02:00
Wolfgang Walther
87258e4b4c maintainers/scripts/haskell/update-stackage: switch to Nightly
Switching to Nightly to start the upgrade process to GHC 9.12. We'll
eventually switch back to LTS once Stackage 25 is released.

Needs to be a separate commit, otherwise the script itself won't run.
2026-05-17 12:27:13 +02:00
Wolfgang Walther
07855b2421 ghc: 9.10 -> 9.12
Changing the default version of GHC ahead of switching to Stackage
Nightly in the next commits.
2026-05-17 12:27:07 +02:00
Wolfgang Walther
0ec79f0885 haskellPackages: regenerate hackage-packages
Generated by maintainers/scripts/haskell/regenerate-hackage-packages.sh
2026-05-17 11:58:18 +02:00
sterni
9adad48243 haskell.compiler.ghc{96,98,…}: drop obsolete workaround on darwin
The hadrian bindist configure script checks for the environment
variables we already set since https://gitlab.haskell.org/ghc/ghc/-/merge_requests/11649
This change has been backported to 9.6.2 and 9.8.2, so all hadrian
built GHCs we package are fixed.
2026-05-17 11:30:40 +02:00
Wolfgang Walther
2e0690adfb Merge commit 'f9710d15003bad7a6ed5f1c14229164fac2f1458' into haskell-updates 2026-05-17 10:48:26 +02:00
Wolfgang Walther
e9724bc92f git-annex: remove tasty workaround (#520973) 2026-05-17 08:37:33 +00:00
sterni
3b2f54505e git-annex: parallelize test suite
Uses git-annex custom mechanism which deals global state correctly
2026-05-16 17:20:08 +02:00
sterni
5498d6a4fe git-annex: remove tasty workaround
Has been fixed upstream
2026-05-16 17:19:28 +02:00
sternenseemann
b0f9043b9f haskell.compiler.ghcHEAD: 9.15.20260322 -> 10.1.20260513 (#520202) 2026-05-16 10:05:13 +00:00
sterni
fcd62a690f haskell.compiler.ghcHEAD: 9.15.20260322 -> 10.1.20260513 2026-05-14 22:11:54 +02:00
sternenseemann
fe8e3efa4f maintainers/haskell/eval-pkg-sets.sh: add script for checking eval
This checks the eval of all package sets, even those neither CI nor
Hydra will evaluate (completely).
2026-04-19 23:17:45 +02:00
314 changed files with 31144 additions and 35648 deletions

View File

@@ -211,7 +211,7 @@ nixos/modules/installer/tools/nix-fallback-paths.nix @Artturin @Ericson2314 @lo
/pkgs/development/perl-modules @stigtsp @marcusramberg
# R
/pkgs/by-name/r/R @jbedo
/pkgs/applications/science/math/R @jbedo
/pkgs/development/r-modules @jbedo
# Rust

View File

@@ -12,19 +12,6 @@
"revision": "7525d999cd850b9a488817abc89c75dc733acf17",
"url": "https://github.com/NixOS/nixpkgs/archive/7525d999cd850b9a488817abc89c75dc733acf17.tar.gz",
"hash": "sha256-4IHyyLgLBdKefkljdKod4IMn023pQiDXAWJA187cmdY="
},
"nixpkgs-26.05-darwin": {
"type": "Git",
"repository": {
"type": "GitHub",
"owner": "NixOS",
"repo": "nixpkgs"
},
"branch": "nixpkgs-26.05-darwin",
"submodules": false,
"revision": "51fe96f9107566e6b8eeb7fc4ba696c01e548b04",
"url": "https://github.com/NixOS/nixpkgs/archive/51fe96f9107566e6b8eeb7fc4ba696c01e548b04.tar.gz",
"hash": "sha256-yj0LPLnsmYoLmA3FGANjeTEwej0/DHjZBXWnDQDUuIs="
}
},
"version": 8

View File

@@ -28,7 +28,7 @@ However, [those were unified early 2020](https://github.com/NixOS/nixpkgs/pull/8
```nix
{ appimageTools, fetchurl }:
appimageTools.wrapType2 {
let
pname = "nuclear";
version = "0.6.30";
@@ -36,7 +36,8 @@ appimageTools.wrapType2 {
url = "https://github.com/nukeop/nuclear/releases/download/v${version}/nuclear-v${version}.AppImage";
hash = "sha256-he1uGC1M/nFcKpMM9JKY4oeexJcnzV0ZRxhTjtJz6xw=";
};
}
in
appimageTools.wrapType2 { inherit pname version src; }
```
:::
@@ -55,7 +56,7 @@ There are a few ways to learn which dependencies an application needs:
```nix
{ appimageTools, fetchurl }:
appimageTools.wrapType2 {
let
pname = "irccloud";
version = "0.16.0";
@@ -63,7 +64,9 @@ appimageTools.wrapType2 {
url = "https://github.com/irccloud/irccloud-desktop/releases/download/v${version}/IRCCloud-${version}-linux-x86_64.AppImage";
hash = "sha256-/hMPvYdnVB1XjKgU2v47HnVvW4+uC3rhRjbucqin4iI=";
};
in
appimageTools.wrapType2 {
inherit pname version src;
extraPkgs = pkgs: [ pkgs.at-spi2-core ];
}
```
@@ -85,12 +88,12 @@ However, [those were unified early 2020](https://github.com/NixOS/nixpkgs/pull/8
# Extracting an AppImage to install extra files
`wrapType2` automatically extracts the AppImage for you and makes it available via the `contents` attribute.
Note how `finalAttrs.contents` is used in `extraInstallCommands` to install additional files that were extracted from the AppImage.
This example was adapted from a real package in Nixpkgs to show how `extract` is usually used in combination with `wrapType2`.
Note how `appimageContents` is used in `extraInstallCommands` to install additional files that were extracted from the AppImage.
```nix
{ appimageTools, fetchurl }:
appimageTools.wrapType2 (finalAttrs: {
let
pname = "irccloud";
version = "0.16.0";
@@ -99,24 +102,27 @@ appimageTools.wrapType2 (finalAttrs: {
hash = "sha256-/hMPvYdnVB1XjKgU2v47HnVvW4+uC3rhRjbucqin4iI=";
};
appimageContents = appimageTools.extract { inherit pname version src; };
in
appimageTools.wrapType2 {
inherit pname version src;
extraPkgs = pkgs: [ pkgs.at-spi2-core ];
extraInstallCommands = ''
mv $out/bin/irccloud-${version} $out/bin/irccloud
install -m 444 -D ${finalAttrs.contents}/irccloud.desktop $out/share/applications/irccloud.desktop
install -m 444 -D ${finalAttrs.contents}/usr/share/icons/hicolor/512x512/apps/irccloud.png \
install -m 444 -D ${appimageContents}/irccloud.desktop $out/share/applications/irccloud.desktop
install -m 444 -D ${appimageContents}/usr/share/icons/hicolor/512x512/apps/irccloud.png \
$out/share/icons/hicolor/512x512/apps/irccloud.png
substituteInPlace $out/share/applications/irccloud.desktop \
--replace-fail 'Exec=AppRun' 'Exec=irccloud'
'';
})
}
```
:::
`appimageTools` also exposes the `extract` function should you need to do it manually, requiring `pname`, `version`, and `src` arguments (`src` being the AppImage file to extract).
The arguments passed to `extract` can also contain a `postExtract` attribute, which allows you to execute additional commands after the files are extracted from the AppImage.
The argument passed to `extract` can also contain a `postExtract` attribute, which allows you to execute additional commands after the files are extracted from the AppImage.
`postExtract` must be a string with commands to run.
:::{.warning}
@@ -132,7 +138,7 @@ This is a rewrite of [](#ex-extracting-appimage) to use `postExtract` and `wrapA
```nix
{ appimageTools, fetchurl }:
appimageTools.wrapAppImage (finalAttrs: {
let
pname = "irccloud";
version = "0.16.0";
@@ -141,22 +147,30 @@ appimageTools.wrapAppImage (finalAttrs: {
hash = "sha256-/hMPvYdnVB1XjKgU2v47HnVvW4+uC3rhRjbucqin4iI=";
};
contents = appimageTools.extract {
inherit (finalAttrs) pname version src;
appimageContents = appimageTools.extract {
inherit pname version src;
postExtract = ''
substituteInPlace $out/irccloud.desktop --replace-fail 'Exec=AppRun' 'Exec=irccloud'
'';
};
in
appimageTools.wrapAppImage {
inherit pname version;
src = appimageContents;
extraPkgs = pkgs: [ pkgs.at-spi2-core ];
extraInstallCommands = ''
mv $out/bin/irccloud-${version} $out/bin/irccloud
install -m 444 -D ${finalAttrs.contents}/irccloud.desktop $out/share/applications/irccloud.desktop
install -m 444 -D ${finalAttrs.contents}/usr/share/icons/hicolor/512x512/apps/irccloud.png \
install -m 444 -D ${appimageContents}/irccloud.desktop $out/share/applications/irccloud.desktop
install -m 444 -D ${appimageContents}/usr/share/icons/hicolor/512x512/apps/irccloud.png \
$out/share/icons/hicolor/512x512/apps/irccloud.png
'';
})
# specify src archive for nix-update
passthru.src = src;
}
```
:::

View File

@@ -741,7 +741,7 @@ Notable attributes:
Compliance suite for [modular service](https://nixos.org/manual/nixos/unstable/#modular-services) integrations.
Tests that a service manager integration correctly handles the portable modular services contract: `process.argv`, sub-services, assertions, and warnings.
Tests that a service manager integration correctly handles the portable modular services contract: `process.argv`, `process.environment` (including `null` values that unset a variable), sub-services, assertions, and warnings.
### Return value {#tester-modularServiceCompliance-return}

View File

@@ -129,8 +129,6 @@
- `super-productivity` has been updated. The binary has been renamed from `super-productivity` to `superproductivity`. A symlink from the old name is provided for backward compatibility.
- `buildFHSEnv`, `appimageTools.wrapAppImage`, and `appimageTools.wrapType2` now support the `finalAttrs` pattern. When using `wrapAppImage`, it is now recommended to pass the extracted AppImage to the `contents` attribute (instead of `src`), to avoid shadowing `src`. Passing the extracted contents to `src` is now deprecated and will be removed in a future release.
- Package-URL (PURL, https://github.com/package-url/purl-spec) metadata identifier has been added for `fetchgit`, `fetchpypi` and `fetchFromGithub` fetchers.
`mkDerivation` has been adjusted to reuse this information.
Package-URLs allow reliably identifying and locating software packages.

View File

@@ -199,8 +199,7 @@
&& system != "riscv64-linux"
# Exclude x86_64-freebsd because "Package go-1.22.12-freebsd-amd64-bootstrap in /nix/store/0yw40qnrar3lvc5hax5n49abl57apjbn-source/pkgs/development/compilers/go/binary.nix:50 is not available on the requested hostPlatform"
&& system != "x86_64-freebsd"
# TODO: revert to importing fmt.pkg directly from ./ci when support for 26.05 ends
) (forAllSystems (system: (import ./shell.nix { inherit system; }).formatter));
) (forAllSystems (system: (import ./ci { inherit system; }).fmt.pkg));
/**
A nested structure of [packages](https://nix.dev/manual/nix/latest/glossary#package-attribute-set) and other values.

View File

@@ -1259,11 +1259,6 @@ lib.mapAttrs mkLicense (
fullName = "SIL Open Font License 1.1";
};
ogluk30 = {
spdxId = "OGL-UK-3.0";
fullName = "Open Government Licence v3.0";
};
oml = {
spdxId = "OML";
fullName = "Open Market License";
@@ -1426,8 +1421,9 @@ lib.mapAttrs mkLicense (
};
stk = {
spdxId = "MIT-STK";
fullName = "MIT-STK License";
shortName = "stk";
fullName = "Synthesis Tool Kit 4.3";
url = "https://github.com/thestk/stk/blob/master/LICENSE";
};
sudo = {

View File

@@ -70,6 +70,26 @@ in
Command used for reloading in the underlying service manager to reload.
'';
};
environment = lib.mkOption {
type = types.lazyAttrsOf (
types.nullOr (types.coercedTo (types.either types.path types.package) (x: "${x}") types.str)
);
default = { };
example = lib.literalExpression ''{ FOO = "bar"; PATH = null; }'';
description = ''
Environment variables passed verbatim to the service process by the
service manager. Entries set to `null` actively unset the variable
before the process starts -- backends without native unset support use
a wrapper (e.g. `execline`'s `unexport`) so the variable is absent
even when the service manager or a backend-specific override would
otherwise supply it.
Values appear in the rendered unit and may be world-readable. For
secrets, use a backend-specific mechanism such as
`systemd.service.serviceConfig.EnvironmentFile`.
'';
};
};
notificationProtocol = mkOption {

View File

@@ -48,6 +48,10 @@ let
(dummyPkg "cowsay.sh")
"world"
];
environment = {
FOO = "bar";
DROPPED = null;
};
};
};
service3 = {
@@ -110,6 +114,7 @@ let
"/usr/bin/echo"
"hello"
];
environment = { };
};
services = { };
assertions = [
@@ -128,6 +133,10 @@ let
"${dummyPkg "cowsay.sh"}"
"world"
];
environment = {
FOO = "bar";
DROPPED = null;
};
};
services = { };
assertions = [ ];
@@ -136,6 +145,7 @@ let
service3 = {
process = {
argv = [ "/bin/false" ];
environment = { };
};
services.exclacow = {
process = {
@@ -143,6 +153,7 @@ let
"${dummyPkg "cowsay-ng"}/bin/cowsay"
"!"
];
environment = { };
};
services = { };
assertions = [

View File

@@ -1173,12 +1173,6 @@
}
];
};
albfsg = {
name = "Alberto Francisco Solaz García";
github = "albfsg";
githubId = 227897008;
email = "albfsg@proton.me";
};
alch-emi = {
email = "emi@alchemi.dev";
github = "Alch-Emi";
@@ -7339,13 +7333,6 @@
githubId = 39825;
name = "Dominik Honnef";
};
donottellmetonottellyou = {
name = "Jade Masker";
email = "donottellmetonottellyou@gmail.com";
github = "donottellmetonottellyou";
githubId = 115233539;
keys = [ { fingerprint = "5C8B 7128 4AB3 000D 4AC6 6234 9B81 35A2 4A75 CB86"; } ];
};
donovanglover = {
github = "donovanglover";
githubId = 2374245;
@@ -12966,6 +12953,11 @@
name = "Jez Cope";
keys = [ { fingerprint = "D9DA 3E47 E8BD 377D A317 B3D0 9E42 CE07 1C45 59D1"; } ];
};
jf-uu = {
github = "jf-uu";
githubId = 181011550;
name = "jf-uu";
};
jfchevrette = {
email = "jfchevrette@gmail.com";
github = "jfchevrette";
@@ -13582,12 +13574,6 @@
name = "Jonas Wunderlich";
matrix = "@matrix:03j.de";
};
jonascarpay = {
name = "Jonas Carpay";
email = "jonascarpay@gmail.com";
github = "jonascarpay";
githubId = 3593851;
};
jonasfranke = {
name = "Jonas Franke";
email = "info@jonasfranke.xyz";
@@ -18875,11 +18861,6 @@
githubId = 45770;
name = "Mitsuhiro Nakamura";
};
MNThomson = {
github = "MNThomson";
githubId = 73045936;
name = "Max Thomson";
};
moaxcp = {
email = "moaxcp@gmail.com";
github = "moaxcp";
@@ -20294,12 +20275,6 @@
github = "niklaskorz";
githubId = 590517;
};
niklasravnsborg = {
name = "Niklas Ravnsborg";
github = "niklasravnsborg";
githubId = 6717303;
keys = [ { fingerprint = "0C90 DD8A 0EE9 93DF 8D58 7AF9 8360 E6C5 8AE8 F3ED"; } ];
};
niklasthorild = {
name = "Niklas Thorild";
email = "niklas@thorild.se";
@@ -23333,13 +23308,6 @@
github = "DaRacci";
githubId = 90304606;
};
rachalaraj = {
name = "Rachala Raj Kumar";
email = "rachaalaraj@gmail.com";
matrix = "@rachalaraj:matrix.org";
github = "rachalaraj";
githubId = 124191100;
};
RadxaYuntian = {
# This is the work account for @MakiseKurisu
name = "ZHANG Yuntian";
@@ -29397,11 +29365,6 @@
github = "UnsolvedCypher";
githubId = 3170853;
};
untio11 = {
name = "Robin Kneepkens";
github = "untio11";
githubId = 14060658;
};
uralbash = {
email = "root@uralbash.ru";
github = "uralbash";

View File

@@ -0,0 +1,39 @@
#!/usr/bin/env nix-shell
#!nix-shell -i bash
#!nix-shell -p jq git
# shellcheck shell=bash
#
# Usage: eval-pkg-sets.sh [extra flags for nix-* commands ...]
#
# Must be executed in a git checkout of Nixpkgs.
set -euo pipefail
NIXPKGS="$(git rev-parse --show-toplevel)"
PKGSETS="$(nix-env --readonly-mode --json --drv-path -f "$NIXPKGS" -qaP -A haskell.compiler "$@" \
| jq -r 'to_entries | unique_by(.value.drvPath) .[] .key | sub("^haskell.compiler";"haskell.packages")')"
trap 'exit 1' SIGINT SIGTERM
set +e
badsets=""
for set in $PKGSETS; do
# Confirm an equivalent package set to haskell.compiler.$entry exists and is usable
if ! nix-instantiate --readonly-mode -A "$set.ghc" "$@" > /dev/null 2>&1; then
echo "Skipping $set... ($set.ghc does not evaluate)"
else
echo "Evaluating $set..."
if ! nix-env --readonly-mode -f "$NIXPKGS" -qaP --drv-path -A "$set" "$@" > /dev/null; then
badsets+="$set "
fi
fi
done
if [ -n "$badsets" ]; then
echo "Found potential eval issues in the following sets:" >&2
# shellcheck disable=SC2086
printf '%s\n' $badsets
exit 1
fi

View File

@@ -33,7 +33,7 @@ fi
# Stackage solver to use, LTS or Nightly
# (should be capitalized like the display name)
SOLVER=LTS
SOLVER=Nightly
# Stackage solver verson, if any. Use latest if empty
VERSION=
TMP_TEMPLATE=update-stackage.XXXXXXX
@@ -105,6 +105,7 @@ sed -r \
-e '/ hledger-ui /d' \
-e '/ hledger-web /d' \
-e '/ spacecookie /d' \
-e '/ hnix-store-core /d' \
< "${tmpfile_new}" >> $stackage_config
# Explanations:
# cabal2nix, distribution-nixpkgs, jailbreak-cabal, language-nix: These are our packages and we know what we are doing.

View File

@@ -152,7 +152,16 @@ let
};
systemdServiceOptions = buildPackages.nixosOptionsDoc {
inherit (evalModules { modules = [ ../../modules/system/service/systemd/service.nix ]; }) options;
inherit
(evalModules {
modules = [
(modules.importApply ../../modules/system/service/systemd/service.nix {
pkgs = throw "nixos docs / systemdServiceOptions: Do not reference pkgs in docs";
})
];
})
options
;
# TODO: filter out options that are not systemd-specific, maybe also change option prefix to just `service-opt-`?
inherit revision warningsAreErrors;
transformOptions =

View File

@@ -129,7 +129,7 @@
- [nvme-rs](https://github.com/liberodark/nvme-rs), NVMe monitoring [services.nvme-rs](#opt-services.nvme-rs.enable).
- [Overseerr](https://overseerr.dev), a request management and media discovery tool for the Plex ecosystem. Available as {option}`opt-services.overseerr.enable`.
- [Overseerr](https://overseerr.dev), a request management and media discovery tool for the Plex ecosystem. Available as [services.overseerr](#opt-services.overseerr.enable).
- [PairDrop](https://github.com/schlagmichdoch/pairdrop), a peer-to-peer file transfer web app. Available as [services.pairdrop](#opt-services.pairdrop.enable).

View File

@@ -84,7 +84,7 @@
- [PdfDing](https://www.pdfding.com/), manage, view and edit your PDFs seamlessly on all your devices wherever you are. Available as [services.pdfding](#opt-services.pdfding.enable).
- [mangowc](https://github.com/DreamMaoMao/mangowc), a lightweight and feature-rich Wayland compositor based on dwl. Available as [programs.mangowc](#opt-programs.mango.enable).
- [mangowc](https://github.com/DreamMaoMao/mangowc), a lightweight and feature-rich Wayland compositor based on dwl. Available as [programs.mangowc](#opt-programs.mangowc.enable).
- [reaction](https://reaction.ppom.me/), a daemon that scans program outputs for repeated patterns, and takes action. A common usage is to scan ssh and webserver logs, and to ban hosts that cause multiple authentication errors. A modern alternative to fail2ban. Available as [services.reaction](#opt-services.reaction.enable).

View File

@@ -89,9 +89,9 @@
- Apache Kafka has dropped support for ZooKeeper mode. The `apacheKafka_3_9` and `apacheKafka_4_0` packages have been removed, as every remaining packaged version is KRaft-only. The `services.apache-kafka.zookeeper` option (previously an alias for `services.apache-kafka.settings."zookeeper.connect"`) has been removed; migrate your cluster to [KRaft](#module-services-apache-kafka-kraft) mode instead.
- `virtualisation.containers.registries.block` / `insecure` / `search` were deprecated,
- `virtualisation.registries.block` / `insecure` / `search` were deprecated,
because they mapped to the deprecated V1 `registries.conf` format.
See the new option {option}`virtualisation.containers.registries.settings`
See the new option {option}`virtualisation.registries.settings`
and [containers-registries.conf(5)](https://github.com/containers/image/blob/main/docs/containers-registries.conf.5.md)
to migrate to the new configuration format.
@@ -113,8 +113,6 @@
- `services.komodo-periphery` has been updated to support version 2.0.0. Some options have been renamed to match the new configuration structure; compatibility aliases are provided for the renamed options. The `passkeys` and `outbound.onboardingKey` options have been removed; use `passkeyFiles`, `auth.privateKey`/`auth.corePublicKeys`, or `outbound.onboardingKeyFile` instead. New outbound mode configuration is available under `outbound.*`.
- Package `overseerr` has been removed as the `overseerr` and `jellyseerr` projects were merged under `seerr`.
## Other Notable Changes {#sec-release-26.11-notable-changes}
<!-- To avoid merge conflicts, consider adding your item at an arbitrary place in the list instead. -->
@@ -142,8 +140,6 @@
- `security.run0.persistentAuth` options have been added to support persistent Authentication of session. Timeout configurable via `security.polkit.settings.Polkitd.ExpirationSeconds`.
- [`virtualisation.qemu.firmware.enable`](#opt-virtualisation.qemu.firmware.enable) has been added to install QEMU firmware descriptors to {file}`/etc/qemu/firmware`, making the corresponding firmware images discoverable by tools such as `systemd-vmspawn`. By default this exposes the firmware bundled with QEMU. Further firmware can be added via [`virtualisation.qemu.firmware.packages`](#opt-virtualisation.qemu.firmware.packages), for example the new `OVMF-amdsev` and `OVMF-inteltdx` packages, which provide UEFI firmware for AMD SEV-SNP and Intel TDX confidential VMs.
- `boot.loader.systemd-boot` gained support for [Automatic Boot Assessment](https://systemd.io/AUTOMATIC_BOOT_ASSESSMENT/) via the new [`boot.loader.systemd-boot.bootCounting`](#opt-boot.loader.systemd-boot.bootCounting.enable) options, allowing automatic detection of and recovery from bad NixOS generations. As part of this change, boot loader entries on the ESP/XBOOTLDR partition are now named `nixos-<content-hash>.conf` instead of `nixos-generation-<n>.conf`; existing entries are migrated automatically on the next `nixos-rebuild boot`/`switch`.
- `services.nginx` gained a [`lua`](#opt-services.nginx.lua.enable) option to enable Lua scripting via OpenResty's lua-nginx-module on a stock nginx, configuring `lua_package_path`/`lua_package_cpath` from the packages listed in [`services.nginx.lua.extraPackages`](#opt-services.nginx.lua.extraPackages). Use this to add Lua to a regular nginx; for the full OpenResty platform (libraries that rely on its bundled lualib, such as `lua-resty-openidc`), set `services.nginx.package` to `pkgs.openresty` instead — the option configures the Lua search path for it too.

View File

@@ -355,7 +355,7 @@
./programs/wayland/hyprland.nix
./programs/wayland/hyprlock.nix
./programs/wayland/labwc.nix
./programs/wayland/mango.nix
./programs/wayland/mangowc.nix
./programs/wayland/miracle-wm.nix
./programs/wayland/niri.nix
./programs/wayland/pinnacle.nix
@@ -938,6 +938,7 @@
./services/misc/open-webui.nix
./services/misc/orthanc.nix
./services/misc/osrm.nix
./services/misc/overseerr.nix
./services/misc/owncast.nix
./services/misc/packagekit.nix
./services/misc/paisa.nix
@@ -2051,7 +2052,6 @@
./virtualisation/openvswitch.nix
./virtualisation/parallels-guest.nix
./virtualisation/podman/default.nix
./virtualisation/qemu-firmware.nix
./virtualisation/qemu-guest-agent.nix
./virtualisation/rosetta.nix
./virtualisation/spice-usb-redirection.nix

View File

@@ -14,93 +14,56 @@ in
Miriway, a Mir based Wayland compositor. You can manually launch Miriway by
executing "exec miriway" on a TTY, or launch it from a display manager. Copy
/etc/xdg/xdg-miriway/miriway-shell.config to ~/.config/miriway-shell.config
and /etc/xdg/xdg-miriway/miriway-shell.settings to ~/.config/miriway-shell.settings
to modify the system-wide configuration on a per-user basis. See <https://github.com/Miriway/Miriway>,
and "miriway --help" for more information'';
config = lib.mkOption {
description = ''
Contents of system-wide miriway-shell.config. See Miriway's configuration documentation for details.
'';
type = lib.types.lines;
default = ''
x11-window-title=Miriway (Mir-on-X)
idle-timeout=600
ctrl-alt=t:miriway-terminal # Default "terminal emulator finder"
shell-component=dbus-update-activation-environment --systemd DISPLAY WAYLAND_DISPLAY
meta=Left:@dock-left
meta=Right:@dock-right
meta=Space:@toggle-maximized
meta=Home:@workspace-begin
meta=End:@workspace-end
meta=Page_Up:@workspace-up
meta=Page_Down:@workspace-down
ctrl-alt=BackSpace:@exit
'';
example = ''
idle-timeout=300
ctrl-alt=t:weston-terminal
add-wayland-extensions=all
shell-components=dbus-update-activation-environment --systemd DISPLAY WAYLAND_DISPLAY
shell-component=waybar
shell-component=wbg Pictures/wallpaper
'';
};
settings = lib.mkOption {
shell-meta=a:synapse
meta=Left:@dock-left
meta=Right:@dock-right
meta=Space:@toggle-maximized
meta=Home:@workspace-begin
meta=End:@workspace-end
meta=Page_Up:@workspace-up
meta=Page_Down:@workspace-down
ctrl-alt=BackSpace:@exit
'';
description = ''
Contents of system-wide miriway-shell.settings. See Miriway's configuration documentation for details.
'';
type = lib.types.lines;
default = ''
command_ctrl_alt=t:miriway-terminal # Default "terminal emulator finder"
command_meta=Left:@dock-left
command_meta=Right:@dock-right
command_meta=Space:@toggle-maximized
command_meta=Home:@workspace-begin
command_meta=End:@workspace-end
command_meta=Page_Up:@workspace-up
command_meta=Page_Down:@workspace-down
command_ctrl_alt=BackSpace:@exit
'';
example = ''
command_ctrl_alt=t:weston-terminal
command_shell_meta=a:synapse
command_meta=Left:@dock-left
command_meta=Right:@dock-right
command_meta=Space:@toggle-maximized
command_meta=Home:@workspace-begin
command_meta=End:@workspace-end
command_meta=Page_Up:@workspace-up
command_meta=Page_Down:@workspace-down
command_ctrl_alt=BackSpace:@exit
Miriway's config. This will be installed system-wide.
The default will install the miriway package's barebones example config.
'';
};
};
config = lib.mkIf cfg.enable {
warnings =
let
optionsNoLongerInConfig = [
"ctrl-alt"
"meta"
"shell-ctrl-alt"
"shell-meta"
"shell-plain"
"command_ctrl_alt"
"command_meta"
"command_shell_ctrl_alt"
"command_shell_meta"
"command_plain"
];
in
# Added 2026-07-17
lib.optional
(builtins.foldl' (
acc: option: acc || (lib.strings.hasInfix "${option}=" cfg.config)
) false optionsNoLongerInConfig)
''
Since Miriway 26.06, configuration options got partially renamed and split across different files.
A new option `programs.miriway.settings` got introduced for options that belong into miriway-shell.settings
instead of miriway-shell.config.
You appear to have one of the following options in `programs.miriway.config` that should now go into
`programs.miriway.settings`, and may need to be renamed:
${lib.strings.concatStringsSep ", " optionsNoLongerInConfig}
'';
environment = {
systemPackages = with pkgs; [
miriway
@@ -108,7 +71,6 @@ in
];
etc = {
"xdg/xdg-miriway/miriway-shell.config".text = cfg.config;
"xdg/xdg-miriway/miriway-shell.settings".text = cfg.settings;
};
};

View File

@@ -6,22 +6,18 @@
}:
let
cfg = config.programs.mango;
cfg = config.programs.mangowc;
in
{
options.programs.mango = {
enable = lib.mkEnableOption "Mango, a Wayland compositor based on dwl and scenefx";
options.programs.mangowc = {
enable = lib.mkEnableOption "MangoWC, a Wayland compositor based on dwl and scenefx";
package = lib.mkPackageOption pkgs "mango" {
default = [ "mango" ];
example = "pkgs.mango.override { enableXWayland = false; }";
package = lib.mkPackageOption pkgs "mangowc" {
default = [ "mangowc" ];
example = "pkgs.mangowc.override { enableXWayland = false; }";
};
};
imports = [
(lib.mkRenamedOptionModule [ "programs" "mangowc" ] [ "programs" "mango" ])
];
config = lib.mkIf cfg.enable {
environment.systemPackages = [ cfg.package ];

View File

@@ -539,13 +539,6 @@ in
(mkRemovedOptionModule [ "services" "xserver" "cmt" ] ''
services.xserver.cmt has been removed as it was broken and unmaintained upstream
'')
(mkRemovedOptionModule
[
"services"
"overseerr"
]
"`services.overseerr` has been replaced by `services.seerr` as the project has been merged with Jellyseerr under Seerr."
)
# Do NOT add any option renames here, see top of the file
];
}

View File

@@ -242,9 +242,7 @@ let
"elkm1"
"elv"
"enocean"
"homeassistant_connect_zbt2"
"homeassistant_hardware"
"homeassistant_sky_connect"
"homeassistant_yellow"
"firmata"
"flexit"

View File

@@ -0,0 +1,89 @@
{
config,
pkgs,
lib,
...
}:
let
cfg = config.services.overseerr;
in
{
meta.maintainers = [ lib.maintainers.jf-uu ];
options.services.overseerr = {
enable = lib.mkEnableOption "Overseerr, a request management and media discovery tool for the Plex ecosystem";
package = lib.mkPackageOption pkgs "overseerr" { };
openFirewall = lib.mkOption {
type = lib.types.bool;
default = false;
description = "Open a port in the firewall for the Overseerr web interface.";
};
port = lib.mkOption {
type = lib.types.port;
default = 5055;
description = "The port which the Overseerr web UI should listen on.";
};
};
config = lib.mkIf cfg.enable {
systemd.services.overseerr = {
description = "Request management and media discovery tool for the Plex ecosystem";
after = [ "network.target" ];
wantedBy = [ "multi-user.target" ];
environment = {
CONFIG_DIRECTORY = "/var/lib/overseerr";
PORT = toString cfg.port;
};
serviceConfig = {
CapabilityBoundingSet = "";
DynamicUser = true;
ExecStart = lib.getExe cfg.package;
LockPersonality = true;
NoNewPrivileges = true;
PrivateDevices = true;
PrivateIPC = true;
PrivateMounts = true;
PrivateTmp = true;
PrivateUsers = true;
ProcSubset = "pid";
ProtectClock = true;
ProtectControlGroups = true;
ProtectHome = true;
ProtectHostname = true;
ProtectKernelLogs = true;
ProtectKernelModules = true;
ProtectKernelTunables = true;
ProtectProc = "invisible";
ProtectSystem = "strict";
RemoveIPC = true;
Restart = "on-failure";
RestrictAddressFamilies = [
"AF_INET"
"AF_INET6"
"AF_UNIX"
];
RestrictNamespaces = true;
RestrictRealtime = true;
RestrictSUIDSGID = true;
StateDirectory = "overseerr";
StateDirectoryMode = "0700";
SystemCallArchitectures = "native";
SystemCallErrorNumber = "EPERM";
SystemCallFilter = [
"@system-service"
"~@privileged"
"~@resources"
];
Type = "exec";
};
};
networking.firewall = lib.mkIf cfg.openFirewall {
allowedTCPPorts = [ cfg.port ];
};
};
}

View File

@@ -988,9 +988,8 @@ in
systemd.services.nsd = {
description = "NSD authoritative only domain name service";
after = [ "network-online.target" ];
after = [ "network.target" ];
wantedBy = [ "multi-user.target" ];
wants = [ "network-online.target" ];
startLimitBurst = 4;
startLimitIntervalSec = 5 * 60; # 5 mins

View File

@@ -115,7 +115,7 @@ in
default = true;
description = ''
Whether unbound should resolve local queries (i.e. add 127.0.0.1 to
/etc/resolv.conf and set name servers to localhost respectively).
/etc/resolv.conf).
'';
};
@@ -276,7 +276,6 @@ in
resolvconf = {
useLocalResolver = mkDefault true;
};
nameservers = lib.mkBefore ([ "127.0.0.1" ] ++ (optional config.networking.enableIPv6 "::1"));
};
environment.etc."unbound/unbound.conf".source = confFile;

View File

@@ -36,14 +36,8 @@ let
userbornConfigJson = pkgs.writeText "userborn.json" (builtins.toJSON userbornConfig);
userbornStaticFiles =
pkgs.runCommand "static-userborn"
{
nativeBuildInputs = [ cfg.package ];
}
''
mkdir -p $out
userborn ${userbornConfigJson} $out
'';
pkgs.runCommand "static-userborn" { }
"mkdir -p $out; ${lib.getExe cfg.package} ${userbornConfigJson} $out";
previousConfigPath = "/var/lib/userborn/previous-userborn.json";
immutableEtc = config.system.etc.overlay.enable && !config.system.etc.overlay.mutable;

View File

@@ -1,3 +1,9 @@
# Non-module arguments
# These are separate from the module arguments to avoid implicit dependencies.
# This makes service modules self-contained, allowing mixing of Nixpkgs versions.
{ pkgs }:
# The module
{
lib,
config,
@@ -92,6 +98,11 @@ in
to prevent systemd substitution. Set this option explicitly to enable
systemd's substitution features.
When {option}`process.environment` contains keys set to `null`, the default
is automatically prefixed with `unexport KEY` invocations (from
`pkgs.execline`) so those variables are unset before the process starts,
regardless of what `Environment=` or inherited environment supplies.
To extend {option}`process.argv` with systemd specifiers, you can append
to the escaped arguments:
@@ -109,8 +120,19 @@ in
for available specifiers like `%n`, `%i`, `%t`.
'';
type = types.str;
default = config.systemd.lib.escapeSystemdExecArgs config.process.argv;
defaultText = lib.literalExpression "config.systemd.lib.escapeSystemdExecArgs config.process.argv";
default =
let
nullEnvKeys = lib.attrNames (lib.filterAttrs (_: v: v == null) config.process.environment);
in
if nullEnvKeys == [ ] then
config.systemd.lib.escapeSystemdExecArgs config.process.argv
else
lib.concatMapStringsSep " " (
k: "${escapeSystemdExecArg "${pkgs.execline}/bin/unexport"} ${escapeSystemdExecArg k}"
) nullEnvKeys
+ " "
+ config.systemd.lib.escapeSystemdExecArgs config.process.argv;
defaultText = lib.literalMD "The escaped `process.argv`, prefixed with `\"unexport\" \"KEY\"` (from `pkgs.execline`) for each key in `process.environment` set to `null`.";
};
systemd.mainExecReload = mkOption {
@@ -187,7 +209,7 @@ in
types.submoduleWith {
class = "service";
modules = [
./service.nix
(lib.modules.importApply ./service.nix { inherit pkgs; })
];
specialArgs = {
inherit systemdPackage;
@@ -207,6 +229,9 @@ in
systemd.services."" = {
# TODO description;
wantedBy = lib.mkDefault [ "multi-user.target" ];
environment = lib.mapAttrs (_: lib.mkDefault) (
lib.filterAttrs (_: v: v != null) config.process.environment
);
serviceConfig = {
ExecReload = config.systemd.mainExecReload;
Type = lib.mkDefault (if config.notificationProtocol.systemd then "notify" else "simple");

View File

@@ -63,7 +63,7 @@ let
modularServiceConfiguration = portable-lib.configure {
serviceManagerPkgs = pkgs;
extraRootModules = [
./service.nix
(lib.modules.importApply ./service.nix { inherit pkgs; })
./config-data-path.nix
];
extraRootSpecialArgs = {

View File

@@ -76,6 +76,40 @@ let
};
};
# Test that `process.environment` becomes `Environment=` entries on the unit,
# that null values are dropped from `Environment=` and wrapped with unexport
# in `ExecStart`.
system.services.envvars = {
process = {
argv = [ hello' ];
environment = {
FOO = "bar";
BAZ = "qux";
DROPPED = null;
};
};
};
# Test that an explicit `systemd.service.environment` override wins over
# the portable default produced by `process.environment`.
system.services.envvars-override = {
process = {
argv = [ hello' ];
environment.FOO = "from-process";
};
systemd.service.environment.FOO = "from-systemd";
};
# Test that `process.environment` `null` unsets via wrapper even when the
# systemd layer sets the same key (true unset, not just "skip setting").
system.services.envvars-unset = {
process = {
argv = [ hello' ];
environment.FOO = null;
};
systemd.service.environment.FOO = "leaked";
};
# Test extending process.argv with systemd specifiers
system.services.argv-extended =
{ config, ... }:
@@ -137,6 +171,22 @@ runCommand "test-modular-service-systemd-units"
# The base command should be escaped ($1 -> $$1, m%n -> m%%n), but the appended --systemd-unit %n should not be
grep -F 'ExecStart="${hello}/bin/hello" "--greeting" "Fun $$1 fact, remainder is often expressed as m%%n" --systemd-unit %n' ${toplevel}/etc/systemd/system/argv-extended.service >/dev/null
# process.environment becomes Environment= entries; null values are dropped
# from Environment= and wrapped with unexport in ExecStart.
grep -F 'Environment="FOO=bar"' ${toplevel}/etc/systemd/system/envvars.service >/dev/null
grep -F 'Environment="BAZ=qux"' ${toplevel}/etc/systemd/system/envvars.service >/dev/null
! grep -F 'Environment=.*DROPPED' ${toplevel}/etc/systemd/system/envvars.service
grep 'ExecStart=.*unexport.*DROPPED' ${toplevel}/etc/systemd/system/envvars.service >/dev/null
# systemd.service.environment override wins over process.environment.
grep -F 'Environment="FOO=from-systemd"' ${toplevel}/etc/systemd/system/envvars-override.service >/dev/null
! grep -F 'FOO=from-process' ${toplevel}/etc/systemd/system/envvars-override.service
# process.environment null uses unexport wrapper for true unset, even when
# the systemd layer has an Environment= entry for the same key.
grep -F 'Environment="FOO=leaked"' ${toplevel}/etc/systemd/system/envvars-unset.service >/dev/null
grep 'ExecStart=.*unexport.*FOO' ${toplevel}/etc/systemd/system/envvars-unset.service >/dev/null
[[ ! -e ${toplevel}/etc/systemd/system/foo.socket ]]
[[ ! -e ${toplevel}/etc/systemd/system/bar.socket ]]
[[ ! -e ${toplevel}/etc/systemd/system/bar-db.socket ]]

View File

@@ -69,7 +69,7 @@ in
config = lib.mkIf (cfg.enable) {
environment.systemPackages = [ cfg.package ];
# we also want these mounts in virtual machines.
fileSystems = if config.virtualisation.qemu ? package then lib.mkVMOverride mounts else mounts;
fileSystems = if config.virtualisation ? qemu then lib.mkVMOverride mounts else mounts;
# We no longer need those when using envfs
system.activationScripts.usrbinenv = lib.mkForce "";

View File

@@ -196,7 +196,7 @@ in
# that do not specify any nodes, or an empty attr set as nodes) will not
# have the QEMU module loaded and thuse these options can't and should not
# be set.
virtualisation = lib.optionalAttrs (options ? virtualisation.qemu.package) {
virtualisation = lib.optionalAttrs (options ? virtualisation.qemu) {
qemu = {
# NOTE: optionalAttrs
# test-instrumentation.nix appears to be used without qemu-vm.nix, so

View File

@@ -1,50 +0,0 @@
{
config,
lib,
pkgs,
...
}:
let
cfg = config.virtualisation.qemu.firmware;
in
{
options.virtualisation.qemu.firmware = {
enable = lib.mkEnableOption "QEMU firmware descriptors in {file}`/etc/qemu/firmware`";
packages = lib.mkOption {
type = lib.types.listOf lib.types.package;
default = [ pkgs.qemu ];
defaultText = lib.literalExpression "[ pkgs.qemu ]";
example = lib.literalExpression "[ pkgs.qemu pkgs.OVMF-amdsev.fd ]";
description = ''
Packages providing QEMU firmware descriptors under
{file}`share/qemu/firmware`, following the QEMU firmware interop
convention (see {file}`docs/interop/firmware.json` in the QEMU
source tree). The descriptors are merged and linked to
{file}`/etc/qemu/firmware`, where tools like
{command}`systemd-vmspawn` discover the firmware available for
running virtual machines.
The default exposes the descriptors of the firmware images
bundled with QEMU. Note that setting this option replaces the
default, so include `pkgs.qemu` when adding further firmware.
'';
};
};
config = lib.mkIf cfg.enable {
environment.etc."qemu/firmware".source =
let
merged = pkgs.buildEnv {
name = "qemu-firmware-descriptors";
paths = cfg.packages;
pathsToLink = [ "/share/qemu/firmware" ];
};
in
"${merged}/share/qemu/firmware";
};
meta.maintainers = [ lib.maintainers.katexochen ];
}

View File

@@ -1303,6 +1303,7 @@ in
osrm-backend = runTest ./osrm-backend.nix;
outline = runTest ./outline.nix;
overlayfs = runTest ./overlayfs.nix;
overseerr = runTest ./overseerr.nix;
owi = runTest ./owi.nix;
owncast = runTest ./owncast.nix;
oxidized = handleTest ./oxidized.nix { };
@@ -1448,7 +1449,6 @@ in
pykms = runTest ./pykms.nix;
qbittorrent = runTest ./qbittorrent.nix;
qboot = runTestOn [ "x86_64-linux" "i686-linux" ] ./qboot.nix;
qemu-firmware = runTestOn [ "x86_64-linux" ] ./qemu-firmware.nix;
qemu-vm-external-disk-image = runTest ./qemu-vm-external-disk-image.nix;
qemu-vm-restrictnetwork = handleTest ./qemu-vm-restrictnetwork.nix { };
qemu-vm-store = runTest ./qemu-vm-store.nix;

View File

@@ -33,12 +33,13 @@
add-wayland-extensions=all
enable-x11=
ctrl-alt=t:foot --maximized
ctrl-alt=a:env WINIT_UNIX_BACKEND=x11 WAYLAND_DISPLAY= alacritty --option window.startup_mode=\"maximized\"
shell-component=dbus-update-activation-environment --systemd DISPLAY WAYLAND_DISPLAY
shell-component=foot --maximized
'';
settings = ''
command_ctrl_alt=t:foot --maximized
command_ctrl_alt=a:env WINIT_UNIX_BACKEND=x11 WAYLAND_DISPLAY= alacritty --option window.startup_mode=\"maximized\"
'';
};
environment = {
@@ -58,9 +59,8 @@
etc."xdg/foot/foot.ini".source = (pkgs.formats.ini { }).generate "foot.ini" {
main = {
font = "inconsolata:size=16";
initial-color-theme = "light";
};
colors-light = rec {
colors = rec {
foreground = "000000";
background = "ffffff";
regular2 = foreground;

20
nixos/tests/overseerr.nix Normal file
View File

@@ -0,0 +1,20 @@
{ lib, pkgs, ... }:
{
name = "overseerr";
meta.maintainers = with lib.maintainers; [ jf-uu ];
nodes.machine =
{ pkgs, ... }:
{
environment.systemPackages = [ pkgs.jq ];
services.overseerr.enable = true;
};
testScript = ''
machine.wait_for_unit("overseerr.service")
machine.wait_for_open_port(5055)
version = machine.succeed("curl --fail http://localhost:5055/api/v1/status | jq --raw-output .version").rstrip("\n")
assert version == "${pkgs.overseerr.version}", f"expected version to be ${pkgs.overseerr.version}, got {version}"
'';
}

View File

@@ -1,41 +0,0 @@
{ lib, ... }:
{
name = "qemu-firmware";
meta.maintainers = [ lib.maintainers.katexochen ];
nodes.machine =
{ pkgs, ... }:
{
virtualisation.qemu.firmware = {
enable = true;
packages = [
pkgs.qemu
pkgs.OVMF-amdsev.fd
pkgs.OVMF-inteltdx.fd
];
};
environment.systemPackages = [ pkgs.jq ];
};
testScript = ''
machine.wait_for_unit("multi-user.target")
with subtest("descriptors are merged into /etc/qemu/firmware"):
machine.succeed("test -e /etc/qemu/firmware/60-edk2-x86_64.json")
machine.succeed("test -e /etc/qemu/firmware/61-edk2-ovmf-x64-amdsev.json")
machine.succeed("test -e /etc/qemu/firmware/61-edk2-ovmf-x64-inteltdx.json")
with subtest("descriptors reference existing firmware images"):
machine.succeed(
"jq -er '.mapping | .filename // .executable.filename' "
+ "/etc/qemu/firmware/*.json | xargs stat --"
)
with subtest("systemd-vmspawn discovers the descriptors"):
listed = machine.succeed("systemd-vmspawn --firmware=list")
assert "61-edk2-ovmf-x64-amdsev.json" in listed
assert "61-edk2-ovmf-x64-inteltdx.json" in listed
assert "60-edk2-x86_64.json" in listed
'';
}

View File

@@ -91,9 +91,6 @@ let
click_when_unobstructed((By.XPATH, "//a[contains(., 'Skip to web app')]"))
# Skip the tour on first login
click_when_unobstructed((By.XPATH, "//button[contains(., 'Skip')]"))
click_when_unobstructed((By.XPATH, "//button[contains(., 'New item')]"))
driver.find_element(By.XPATH, '//input[@formcontrolname="name"]').send_keys(

View File

@@ -1,19 +0,0 @@
{
lib,
b4,
melpaBuild,
}:
melpaBuild {
pname = "b4-review-mode";
inherit (b4) version;
src = b4.src-misc;
sourceRoot = "${b4.src-misc.name}/misc/emacs";
meta = {
description = "Emacs major mode with highlighting for the b4 review reply editor";
homepage = "https://git.kernel.org/pub/scm/utils/b4/b4.git/about";
license = lib.licenses.gpl2Only;
maintainers = with lib.maintainers; [ fzakaria ];
};
}

View File

@@ -6,26 +6,22 @@
magit,
transient,
with-editor,
consult,
plz,
}:
melpaBuild {
pname = "majutsu";
version = "0.6.0-unstable-2026-07-23";
version = "0.6.0-unstable-2026-07-09";
src = fetchFromGitHub {
owner = "0WD0";
repo = "majutsu";
rev = "8eaf8cb4db2f0737d0a131ef8b61ce6393660369";
hash = "sha256-QqvzRfqWa4Ql7bpuShqHmXzXJCu1VU8ObnImiK7ZyvE=";
rev = "59aff9b93eac575fbccc1f4ab2d48d048e0ead9b";
hash = "sha256-GJ62hsHgLEFIY0ghij0VPFt1jMUGRKhI2eCroBjkxtc=";
};
packageRequires = [
magit
transient
with-editor
consult
plz
];
passthru.updateScript = nix-update-script { extraArgs = [ "--version=branch=main" ]; };

View File

@@ -1,19 +0,0 @@
{
lib,
vimUtils,
b4,
}:
vimUtils.buildVimPlugin {
pname = "b4-review-vim";
inherit (b4) version;
src = b4.src-misc;
sourceRoot = "${b4.src-misc.name}/misc/vim";
meta = {
description = "Vim syntax highlighting for the b4 review reply editor";
homepage = "https://git.kernel.org/pub/scm/utils/b4/b4.git/about";
license = lib.licenses.gpl2Only;
maintainers = with lib.maintainers; [ fzakaria ];
};
}

View File

@@ -74,9 +74,6 @@ let
];
env = {
# Build zlob for a portable CPU baseline (https://github.com/dmtrKovalenko/fff/issues/705)
CI = "1";
OPENSSL_NO_VENDOR = true;
# Allow undefined symbols on Darwin - they will be provided by Neovim's LuaJIT runtime

View File

@@ -21,22 +21,22 @@ vscode-utils.buildVscodeMarketplaceExtension (finalAttrs: {
sources = {
"x86_64-linux" = {
arch = "linux-x64";
hash = "sha256-Z/tQ+KV+3MdbknA/1kmiIpVfOsUM8NUu+0iHlPVbYV0=";
hash = "sha256-Y6MXjJBmhMzuQMwhkPLHK/vtciTdjsGvkEblH3ofju0=";
};
"aarch64-linux" = {
arch = "linux-arm64";
hash = "sha256-d2GjWr0FHOoORI5KRdwUQvcFfBB8xV6j9wj5OS9VL9o=";
hash = "sha256-8VvDtb+8SoLTRC7pXwH40amRurxTQgCmhdi0u7e5AfU=";
};
"aarch64-darwin" = {
arch = "darwin-arm64";
hash = "sha256-dlfGTxf2EoiNb0g9uqwjTNW8fi2d1tzubGdIDyp4xTw=";
hash = "sha256-bqjEgsjY+zyG1g/KtkRNxAlazIpc+HwGWvsMQNnPI2M=";
};
};
in
{
name = "claude-code";
publisher = "anthropic";
version = "2.1.219";
version = "2.1.218";
}
// sources.${stdenvNoCC.hostPlatform.system}
or (throw "Unsupported system ${stdenvNoCC.hostPlatform.system}");

View File

@@ -10,8 +10,8 @@ vscode-utils.buildVscodeMarketplaceExtension {
mktplcRef = {
publisher = "oxc";
name = "oxc-vscode";
version = "1.59.0";
hash = "sha256-avfW91oF8PGCoDYocC744wpQ3zE8fv5582n55Ugb8k8=";
version = "1.58.0";
hash = "sha256-30dFeguNbY8WM3fLym6aUMkHYH5wA5scSNn04Ukbj9U=";
};
nativeBuildInputs = [

View File

@@ -5,13 +5,13 @@
}:
mkLibretroCore {
core = "mednafen-vb";
version = "0-unstable-2026-07-22";
version = "0-unstable-2026-06-14";
src = fetchFromGitHub {
owner = "libretro";
repo = "beetle-vb-libretro";
rev = "7cc663e9044459b3dab1790bdce8f48dc7358ed6";
hash = "sha256-ntw8SXzyu0PTDQgaLmT5Wy172A8TI3JLN6A5WQ2T/OI=";
rev = "38e7a0ec9ac7079ca1c1e3dd9aaf5b56f527efca";
hash = "sha256-+57qsfH2wygKdD66yauzKD9XDf01q4LeiWdIeYbVUmc=";
};
makefile = "Makefile";

View File

@@ -20,13 +20,13 @@
}:
mkLibretroCore {
core = "dolphin";
version = "0-unstable-2026-07-23";
version = "0-unstable-2026-07-12";
src = fetchFromGitHub {
owner = "libretro";
repo = "dolphin";
rev = "c6b869102f6b9f450f0a9878330d00484754879d";
hash = "sha256-7sImbA1uzpwGovo4+5bK9SJpIDIvdB5FhN2IuxVaiQ8=";
rev = "0b766a68cc835775b3216500bb9af2f5d4602b12";
hash = "sha256-JaUiDc4/vEWjEXe6H9+i6pft2DTsl5my5wyFmtbjdR0=";
fetchSubmodules = true;
};

View File

@@ -7,13 +7,13 @@
}:
mkLibretroCore {
core = "melonds";
version = "0-unstable-2026-07-19";
version = "0-unstable-2026-06-25";
src = fetchFromGitHub {
owner = "libretro";
repo = "melonds";
rev = "66b5d2634cd0a79030562811e6e05f5532f800ba";
hash = "sha256-nQvnXoB8UeaSr6QfYwn18Y18KyLyWvcv/Q3L3SHvaNU=";
rev = "c9550d18923fe86a5ad9faa159399b55c12b47f1";
hash = "sha256-xvBdt/TMxZOrC//DLHRWRMqIibt7dNsfLM/FeMTRA60=";
};
extraBuildInputs = [

View File

@@ -5,13 +5,13 @@
}:
mkLibretroCore {
core = "picodrive";
version = "0-unstable-2026-07-23";
version = "0-unstable-2026-04-02";
src = fetchFromGitHub {
owner = "libretro";
repo = "picodrive";
rev = "78a662e3135871a6c657d5e61900f6704152e594";
hash = "sha256-3+x1ILIUq+/nwfUGXweNIq3PFTAaP56/6G+dX4dEZ/Y=";
rev = "f0d4a0118a9733a1f10bce5a4ac772c474f9300d";
hash = "sha256-q584bnqIbKoXSCRHUAcqSJAIhholnXfbphvLVcbm57o=";
fetchSubmodules = true;
};

View File

@@ -1,37 +0,0 @@
{ callPackage }:
let
flavorData = {
browser = {
optStem = "brave";
fileStem = "brave-browser";
appIdStem = "com.brave.Browser";
darwinStem = "Brave Browser";
changelogFile = "CHANGELOG_DESKTOP.md";
homepage = "https://brave.com/";
innerBinary = "brave";
};
origin = {
optStem = "brave-origin";
fileStem = "brave-origin";
appIdStem = "com.brave.Origin";
darwinStem = "Brave Origin";
changelogFile = "CHANGELOG_DESKTOP_ORIGIN.md";
homepage = "https://brave.com/origin/";
innerBinary = "brave";
};
};
mkBrave =
release:
let
pkg = import release;
fd = flavorData.${pkg.flavor or "browser"};
in
callPackage ./make-brave.nix { } (pkg // fd);
in
{
brave = mkBrave ./packages/brave.nix;
brave-origin = mkBrave ./packages/brave-origin.nix;
}

View File

@@ -1,21 +0,0 @@
# Expression generated by update.sh; do not edit it by hand!
rec {
pname = "brave-origin";
version = "1.92.144";
flavor = "origin";
archives = {
aarch64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin_${version}_arm64.deb";
hash = "sha256-zqjpiBMogYhtuEhIlPlK8J2j9hzfd1M8RYlT/c74Na8=";
};
x86_64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin_${version}_amd64.deb";
hash = "sha256-KF5WXF7GJPLCcEQyASEVfNrYyFJRXBSyWVPPAZPCa/E=";
};
aarch64-darwin = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin-v${version}-darwin-arm64.zip";
hash = "sha256-kkP8cBRnC34+SjC9EvkpKcDYP3cxW7sdJgni0+zXwbk=";
};
};
}

View File

@@ -1,20 +0,0 @@
# Expression generated by update.sh; do not edit it by hand!
rec {
pname = "brave";
version = "1.92.144";
archives = {
aarch64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_arm64.deb";
hash = "sha256-Z9uUJRaMx+P35oXtvAnjHyOQOXt8mW5oyyEtnD754x8=";
};
x86_64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_amd64.deb";
hash = "sha256-no/KD+3EB6CqvVWEmDB/8k2rv1wau469FBXMNWN7z6k=";
};
aarch64-darwin = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-v${version}-darwin-arm64.zip";
hash = "sha256-YidWCVGP36wn1goAulSbVrKFoHI1NA/pLtfPjIXBO48=";
};
};
}

View File

@@ -1,100 +0,0 @@
#!/usr/bin/env nix-shell
#!nix-shell -i bash -p curl nix jq
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" &>/dev/null && pwd)"
VERSIONS_URL="https://versions.brave.com/latest/brave-versions.json"
sri_hash() {
nix-hash --to-sri --type sha256 "$(nix-prefetch-url --type sha256 "$1")"
}
find_release_with_asset() {
local versionsJson="$1" channel="$2" template="$3"
local match
match="$(
jq -c --arg channel "$channel" --arg tmpl "$template" '
[.[]
| select(.channel == $channel)
| . as $r
| select(
$r.github.assets
| map(.name)
| any(. == ($tmpl | gsub("\\$\\{version\\}"; $r.name)))
)
]
| sort_by(.published)
| last
' <<<"$versionsJson"
)"
if [[ "$match" != "null" ]]; then
printf '%s' "$match"
return 0
fi
echo "update.sh: no ${channel} release with asset matching '${template}' found" >&2
return 1
}
emit_archive_entry() {
local releaseJson="$1" version="$2" template="$3" platform="$4"
local name="${template//\$\{version\}/$version}"
local url
url="$(
jq -r --arg n "$name" '
.github.assets[]
| select(.name == $n)
| .download_url
' <<<"$releaseJson"
)"
if [[ -z "$url" ]]; then
return 0
fi
local hash
hash="$(sri_hash "$url")"
local nixUrl="${url//${version}/\$\{version\}}"
cat <<EOF
${platform} = {
url = "${nixUrl}";
hash = "${hash}";
};
EOF
}
write_package_nix() {
local pname="$1" releaseJson="$2" debStem="$3" darwinStem="$4"
local version
version="$(jq -r '.name' <<<"$releaseJson")"
echo "=> ${pname}: ${version}" >&2
local flavorLine=""
if [[ "$pname" == brave-origin || "$pname" == brave-origin-* ]]; then
flavorLine=' flavor = "origin";'
fi
local outFile="${SCRIPT_DIR}/packages/${pname}.nix"
{
echo '# Expression generated by update.sh; do not edit it by hand!'
echo 'rec {'
echo " pname = \"${pname}\";"
echo " version = \"${version}\";"
[[ -n "$flavorLine" ]] && echo "$flavorLine"
echo ''
echo ' archives = {'
emit_archive_entry "$releaseJson" "$version" "${debStem}_\${version}_arm64.deb" "aarch64-linux"
emit_archive_entry "$releaseJson" "$version" "${debStem}_\${version}_amd64.deb" "x86_64-linux"
emit_archive_entry "$releaseJson" "$version" "${darwinStem}-v\${version}-darwin-arm64.zip" "aarch64-darwin"
echo ' };'
echo '}'
} > "$outFile"
}
versionsJson="$(curl --fail -s "$VERSIONS_URL")"
entries=(
"brave brave-browser brave"
"brave-origin brave-origin brave-origin"
)
for entry in "${entries[@]}"; do
read -r pname debStem darwinStem <<<"$entry"
releaseJson="$(find_release_with_asset "$versionsJson" "release" "${debStem}_\${version}_amd64.deb")"
write_package_nix "$pname" "$releaseJson" "$debStem" "$darwinStem"
done

View File

@@ -91,6 +91,7 @@
cupsSupport ? true,
cups ? null,
proprietaryCodecs ? true,
pulseSupport ? false,
libpulseaudio ? null,
ungoogled ? false,
ungoogled-chromium,
@@ -393,9 +394,7 @@ let
libgcrypt
cups
]
++ [
libpulseaudio
];
++ lib.optional pulseSupport libpulseaudio;
buildInputs = [
]
@@ -456,9 +455,7 @@ let
libgcrypt
cups
]
++ [
libpulseaudio
];
++ lib.optional pulseSupport libpulseaudio;
patches = [
./patches/cross-compile.patch
@@ -971,7 +968,7 @@ let
use_vaapi = false;
use_v4l2_codec = true;
}
// {
// lib.optionalAttrs pulseSupport {
use_pulseaudio = true;
link_pulseaudio = true;
}

View File

@@ -32,6 +32,7 @@
enableWideVine ? false,
ungoogled ? false, # Whether to build chromium or ungoogled-chromium
cupsSupport ? true,
pulseSupport ? config.pulseaudio or stdenv.hostPlatform.isLinux,
commandLineArgs ? "",
pkgsBuildBuild,
pkgs,
@@ -75,6 +76,7 @@ let
inherit
proprietaryCodecs
cupsSupport
pulseSupport
ungoogled
;
gnChromium = buildPackages.gn.override upstream-info.deps.gn;

View File

@@ -535,11 +535,11 @@
"vendorHash": null
},
"hashicorp_azurerm": {
"hash": "sha256-M8Kq0lVbPtob2g8j8k4OJenAz8f5jjSobf192TrpSEg=",
"hash": "sha256-XJmSVCX6rigPD4oi0S4qUyvgvR5SkCHZV2rMAqsmIIo=",
"homepage": "https://registry.terraform.io/providers/hashicorp/azurerm",
"owner": "hashicorp",
"repo": "terraform-provider-azurerm",
"rev": "v4.81.0",
"rev": "v4.79.0",
"spdx": "MPL-2.0",
"vendorHash": null
},

View File

@@ -13,6 +13,7 @@
gst_all_1,
gtk2,
gtk2-x11,
gtkspell2,
intltool,
lib,
libice,
@@ -93,6 +94,7 @@ let
]
++ lib.optionals stdenv.hostPlatform.isLinux [
gtk2
gtkspell2
farstream
]
++ lib.optional stdenv.hostPlatform.isDarwin gtk2-x11;
@@ -124,14 +126,16 @@ let
"--disable-nm"
"--disable-tcl"
"--disable-gevolution"
"--disable-gtkspell"
]
++ lib.optionals withCyrus_sasl [ "--enable-cyrus-sasl=yes" ]
++ lib.optionals withGnutls [
"--enable-gnutls=yes"
"--enable-nss=no"
]
++ lib.optionals stdenv.hostPlatform.isDarwin [ "--disable-vv" ]
++ lib.optionals stdenv.hostPlatform.isDarwin [
"--disable-gtkspell"
"--disable-vv"
]
++ lib.optionals stdenv.cc.isClang [ "CFLAGS=-Wno-error=int-conversion" ];
enableParallelBuilding = true;

View File

@@ -32,7 +32,7 @@
lapack,
curl,
tzdata,
withRecommendedPackages ? false,
withRecommendedPackages ? true,
enableStrictBarrier ? false,
enableMemoryProfiling ? false,
# R as of writing does not support outputting both .so and .a files; it outputs:
@@ -45,7 +45,7 @@ assert (!blas.isILP64) && (!lapack.isILP64);
stdenv.mkDerivation (finalAttrs: {
pname = "R";
version = "4.6.1";
version = "4.6.0";
src =
let
@@ -53,7 +53,7 @@ stdenv.mkDerivation (finalAttrs: {
in
fetchurl {
url = "https://cran.r-project.org/src/base/R-${lib.versions.major version}/${pname}-${version}.tar.gz";
hash = "sha256-TabmHSwKrF8UoufkMstfzCae/oPaQpMFC6fwPf9OLPQ=";
hash = "sha256-uNybRUNmDHtZa4eTjfUyOUNQNgl2Un00QijuDtEuRew=";
};
outputs = [

View File

@@ -97,82 +97,6 @@ let
buildPrefix = "Build/*/*";
isQemuPlatform = builtins.elem projectDscPath [
"OvmfPkg/OvmfPkgX64.dsc"
"ArmVirtPkg/ArmVirtQemu.dsc"
"OvmfPkg/RiscVVirt/RiscVVirtQemu.dsc"
"OvmfPkg/LoongArchVirt/LoongArchVirtQemu.dsc"
];
# QEMU firmware interop descriptors to install, keyed by file name.
# Add an attribute to ship an additional descriptor.
qemuDescriptors =
let
description = "${fwPrefix} UEFI firmware for ${cpuName}${lib.optionalString secureBoot " with Secure Boot"}";
flashMapping = varsFile: {
device = "flash";
mode = "split";
executable = {
filename = "${placeholder "fd"}/FV/${fwPrefix}_CODE.fd";
format = "raw";
};
nvram-template = {
filename = "${placeholder "fd"}/FV/${varsFile}";
format = "raw";
};
};
common = {
interface-types = [ "uefi" ];
targets = [
{
architecture = cpuName;
machines =
{
x86_64 =
if systemManagementModeRequired then
[ "pc-q35-*" ]
else
[
"pc-i440fx-*"
"pc-q35-*"
];
aarch64 = [ "virt-*" ];
riscv64 = [ "virt*" ];
loongarch64 = [ "virt*" ];
}
.${cpuName} or [ ];
}
];
features =
lib.optionals stdenv.hostPlatform.isx86 [
"acpi-s3"
"amd-sev"
]
++ lib.optionals (stdenv.hostPlatform.isx86 && !systemManagementModeRequired) [ "amd-sev-es" ]
++ lib.optionals secureBoot [ "secure-boot" ]
++ lib.optionals systemManagementModeRequired [ "requires-smm" ]
++ lib.optionals (stdenv.hostPlatform.isx86 && !debug) [ "verbose-dynamic" ];
tags = [ ];
};
in
lib.optionalAttrs isQemuPlatform (
{
"50-edk2-${cpuName}${lib.optionalString secureBoot "-sb"}.json" = common // {
inherit description;
mapping = flashMapping "${fwPrefix}_VARS.fd";
};
}
// lib.optionalAttrs msVarsTemplate {
"40-edk2-${cpuName}${lib.optionalString secureBoot "-sb"}-enrolled.json" = common // {
description = "${description}, Microsoft keys enrolled";
mapping = flashMapping "${fwPrefix}_VARS.ms.fd";
features = common.features ++ [ "enrolled-keys" ];
};
}
);
in
assert msVarsTemplate -> fdSize4MB;
@@ -318,17 +242,7 @@ edk2.mkDerivation projectDscPath (finalAttrs: {
mkdir -vp $fd/AAVMF
ln -s $fd/FV/AAVMF_CODE.fd $fd/AAVMF/QEMU_EFI-pflash.raw
ln -s $fd/FV/AAVMF_VARS.fd $fd/AAVMF/vars-template-pflash.raw
''
+ lib.optionalString (qemuDescriptors != { }) ''
mkdir -vp $fd/share/qemu/firmware
''
+ lib.concatStrings (
lib.mapAttrsToList (name: descriptor: ''
python3 -m json.tool > $fd/share/qemu/firmware/${name} <<'EOF'
${builtins.toJSON descriptor}
EOF
'') qemuDescriptors
);
'';
dontPatchELF = true;

View File

@@ -143,27 +143,6 @@ let
hash = mobyHash;
};
extraMobyPath = lib.optionals stdenv.hostPlatform.isLinux (
lib.makeBinPath [
iproute2
iptables
e2fsprogs
xz
xfsprogs
procps
util-linuxMinimal
gitMinimal
]
);
extraMobyUserPath = lib.optionals (stdenv.hostPlatform.isLinux && !clientOnly) (
lib.makeBinPath [
rootlesskit
slirp4netns
fuse-overlayfs
]
);
moby = buildGoModule (
lib.optionalAttrs stdenv.hostPlatform.isLinux {
pname = "moby";
@@ -191,6 +170,27 @@ let
++ lib.optionals withSystemd [ systemd ]
++ lib.optionals withSeccomp [ libseccomp ];
extraPath = lib.optionals stdenv.hostPlatform.isLinux (
lib.makeBinPath [
iproute2
iptables
e2fsprogs
xz
xfsprogs
procps
util-linuxMinimal
gitMinimal
]
);
extraUserPath = lib.optionals (stdenv.hostPlatform.isLinux && !clientOnly) (
lib.makeBinPath [
rootlesskit
slirp4netns
fuse-overlayfs
]
);
postPatch = ''
patchShebangs hack/make.sh hack/make/
''
@@ -218,9 +218,7 @@ let
install -Dm755 ./bundles/dynbinary-daemon/docker-proxy $out/libexec/docker/docker-proxy
makeWrapper $out/libexec/docker/dockerd $out/bin/dockerd \
--prefix PATH : "$out/libexec/docker${
lib.optionalString (extraMobyPath != "") ":${extraMobyPath}"
}"
--prefix PATH : "$out/libexec/docker:$extraPath"
ln -s ${docker-containerd}/bin/containerd $out/libexec/docker/containerd
ln -s ${docker-containerd}/bin/containerd-shim${lib.optionalString (lib.versionAtLeast version "29.0.0") "-runc-v2"} $out/libexec/docker/containerd-shim${lib.optionalString (lib.versionAtLeast version "29.0.0") "-runc-v2"}
@@ -235,9 +233,7 @@ let
# rootless Docker
install -Dm755 ./contrib/dockerd-rootless.sh $out/libexec/docker/dockerd-rootless.sh
makeWrapper $out/libexec/docker/dockerd-rootless.sh $out/bin/dockerd-rootless \
--prefix PATH : "$out/libexec/docker${
lib.optionalString (extraMobyPath != "") ":${extraMobyPath}"
}${lib.optionalString (extraMobyUserPath != "") ":${extraMobyUserPath}"}"
--prefix PATH : "$out/libexec/docker:$extraPath:$extraUserPath"
runHook postInstall
'';
@@ -339,7 +335,7 @@ let
install -Dm755 ./build/docker $out/libexec/docker/docker
makeWrapper $out/libexec/docker/docker $out/bin/docker \
--prefix PATH : "$out/libexec/docker" \
--prefix PATH : "$out/libexec/docker:$extraPath" \
--prefix DOCKER_CLI_PLUGIN_DIRS : "${dockerCliPluginsDirs}"
''
+ lib.optionalString (!clientOnly) ''

View File

@@ -8,13 +8,13 @@
}:
mkHyprlandPlugin (finalAttrs: {
pluginName = "hy3";
version = "0.56.0.1";
version = "0.55.0";
src = fetchFromGitHub {
owner = "outfoxxed";
repo = "hy3";
tag = "hl${finalAttrs.version}";
hash = "sha256-iK0vERuy5aXisDXm/bzcJP0dgaIot5MLPoVG62DjqO4=";
hash = "sha256-P3wwiIfqo89evW7xzI+wOI/qM1WPZBiiSmGNtBmYeVk=";
};
nativeBuildInputs = [ cmake ];

View File

@@ -7,13 +7,13 @@
mkHyprlandPlugin (finalAttrs: {
pluginName = "hypr-darkwindow";
version = "0.56.0";
version = "0.55.4";
src = fetchFromGitHub {
owner = "micha4w";
repo = "Hypr-DarkWindow";
tag = "v${finalAttrs.version}";
hash = "sha256-2upGTy7IRhrhxf+5VPjzrua8ebOtED6i8kSN8ka+ffg=";
hash = "sha256-91l5TD46OMfvmhd1WqWxm42cEnjR1yAj2Qk/73mr3ks=";
};
installPhase = ''

View File

@@ -8,18 +8,16 @@
pv,
squashfsTools,
buildFHSEnv,
replaceVarsWith,
runtimeShell,
runCommand,
pkgs,
}:
rec {
appimage-exec = replaceVarsWith {
appimage-exec = pkgs.replaceVarsWith {
src = ./appimage-exec.sh;
isExecutable = true;
dir = "bin";
replacements = {
inherit runtimeShell;
inherit (pkgs) runtimeShell;
path = lib.makeBinPath [
bash
binutils-unwrapped
@@ -44,7 +42,7 @@ rec {
assert
name == null
|| throw "The `name` argument is deprecated. Use `pname` and `version` instead to construct the name.";
runCommand "${pname}-${version}-extracted"
pkgs.runCommand "${pname}-${version}-extracted"
{
nativeBuildInputs = [ appimage-exec ];
strictDeps = true;
@@ -59,55 +57,60 @@ rec {
extractType2 = extract;
wrapType1 = wrapType2;
wrapAppImage = lib.extendMkDerivation {
constructDrv = buildFHSEnv;
excludeDrvArgNames = [ "extraPkgs" ];
extendDrvArgs =
finalAttrs:
prev@{
contents ? prev.src,
extraPkgs ? pkgs: [ ],
meta ? { },
...
}:
wrapAppImage =
args@{
src,
extraPkgs ? pkgs: [ ],
meta ? { },
...
}:
buildFHSEnv (
defaultFhsEnvArgs
// {
targetPkgs = pkgs: [ appimage-exec ] ++ defaultFhsEnvArgs.targetPkgs pkgs ++ extraPkgs pkgs;
runScript = "appimage-exec.sh -w ${finalAttrs.contents or prev.src} --";
runScript = "appimage-exec.sh -w ${src} --";
meta = {
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
}
// meta;
};
};
}
// (removeAttrs args (builtins.attrNames (builtins.functionArgs wrapAppImage)))
);
wrapType2 = lib.extendMkDerivation {
constructDrv = wrapAppImage;
extendDrvArgs = finalAttrs: args: {
contents = extract (
lib.filterAttrs (
key: value:
builtins.elem key [
"pname"
"version"
"src"
wrapType2 =
args@{
src,
extraPkgs ? pkgs: [ ],
...
}:
wrapAppImage (
args
// {
inherit extraPkgs;
src = extract (
lib.filterAttrs (
key: value:
builtins.elem key [
"pname"
"version"
"src"
]
) args
);
# passthru src to make nix-update work
# hack to keep the origin position (unsafeGetAttrPos)
passthru =
lib.pipe args [
lib.attrNames
(lib.remove "src")
(removeAttrs args)
]
) finalAttrs
);
# passthru src to make nix-update work
# hack to keep the origin position (unsafeGetAttrPos)
passthru =
lib.pipe finalAttrs [
lib.attrNames
(lib.remove "src")
(removeAttrs finalAttrs)
]
// args.passthru or { };
};
};
// args.passthru or { };
}
);
defaultFhsEnvArgs = {
# Most of the packages were taken from the Steam chroot

View File

@@ -1,7 +1,6 @@
{
lib,
stdenv,
stdenvNoCC,
callPackage,
runCommandLocal,
writeShellScript,
@@ -12,6 +11,30 @@
bubblewrap,
}:
{
pname ? throw "You must provide either `name` or `pname`",
version ? throw "You must provide either `name` or `version`",
name ? "${pname}-${version}",
runScript ? "bash",
nativeBuildInputs ? [ ],
extraInstallCommands ? "",
executableName ? args.pname or name,
meta ? { },
passthru ? { },
extraPreBwrapCmds ? "",
extraBwrapArgs ? [ ],
unshareUser ? false,
unshareIpc ? false,
unsharePid ? false,
unshareNet ? false,
unshareUts ? false,
unshareCgroup ? false,
privateTmp ? false,
chdirToPwd ? true,
dieWithParent ? true,
...
}@args:
# NOTE:
# `pname` and `version` will throw if they were not provided.
# Use `name` instead of directly evaluating `pname` or `version`.
@@ -19,358 +42,338 @@
# If you need `pname` or `version` specifically, use `args` instead:
# e.g. `args.pname or ...`.
lib.makeOverridable (
lib.extendMkDerivation {
constructDrv = stdenvNoCC.mkDerivation;
excludeDrvArgNames = [
"multiPkgs"
"targetPkgs"
let
inherit (lib)
concatLines
concatStringsSep
escapeShellArgs
filter
optionalString
splitString
;
inherit (lib.attrsets) removeAttrs;
# The splicing code does not handle `pkgsi686Linux` well, so we have to be
# explicit about which package set it's coming from.
inherit (pkgsHostTarget) pkgsi686Linux;
# we don't know which have been supplied, and want to avoid defaulting missing attrs to null. Passed into runCommandLocal
nameAttrs = lib.filterAttrs (
key: value:
builtins.elem key [
"name"
"pname"
"version"
]
) args;
buildFHSEnv = callPackage ./buildFHSEnv.nix { };
fhsenv = buildFHSEnv (
removeAttrs args [
"runScript"
];
extendDrvArgs =
finalAttrs:
"extraInstallCommands"
"meta"
"passthru"
"extraPreBwrapCmds"
"extraBwrapArgs"
"dieWithParent"
"unshareUser"
"unshareCgroup"
"unshareUts"
"unshareNet"
"unsharePid"
"unshareIpc"
"privateTmp"
]
);
etcBindEntries =
let
files = [
# NixOS Compatibility
"static"
"nix" # mainly for nixVersions.git users, but also for access to nix/netrc
# Shells
"shells"
"bashrc"
"zshenv"
"zshrc"
"zinputrc"
"zprofile"
# Users, Groups, NSS
"passwd"
"group"
"shadow"
"hosts"
"resolv.conf"
"nsswitch.conf"
# User profiles
"profiles"
# Sudo & Su
"login.defs"
"sudoers"
"sudoers.d"
# Time
"localtime"
"zoneinfo"
# Other Core Stuff
"machine-id"
"os-release"
# PAM
"pam.d"
# Fonts
"fonts"
# ALSA
"alsa"
"asound.conf"
# SSL
"ssl/certs"
"ca-certificates"
"pki"
# Custom dconf profiles
"dconf"
];
in
map (path: "/etc/${path}") files;
# Here's the problem case:
# - we need to run bash to run the init script
# - LD_PRELOAD may be set to another dynamic library, requiring us to discover its dependencies
# - oops! ldconfig is part of the init script, and it hasn't run yet
# - everything explodes
#
# In particular, this happens with fhsenvs in fhsenvs, e.g. when running
# a wrapped game from Steam.
#
# So, instead of doing that, we build a tiny static (important!) shim
# that executes ldconfig in a completely clean environment to generate
# the initial cache, and then execs into the "real" init, which is the
# first time we see anything dynamically linked at all.
#
# Also, the real init is placed strategically at /init, so we don't
# have to recompile this every time.
containerInit =
runCommandCC "container-init"
{
pname ? throw "You must provide either `name` or `pname`",
version ? throw "You must provide either `name` or `version`",
name ? "${pname}-${version}",
runScript ? "bash",
executableName ? args.pname or name,
meta ? { },
passthru ? { },
unshareUser ? false,
unshareIpc ? false,
unsharePid ? false,
unshareNet ? false,
unshareUts ? false,
unshareCgroup ? false,
privateTmp ? false,
chdirToPwd ? true,
dieWithParent ? true,
...
}@args:
let
inherit (lib)
concatLines
concatStringsSep
escapeShellArgs
filter
optionalString
splitString
removeAttrs
;
buildInputs = [ stdenv.cc.libc.static or null ];
}
''
$CXX -static -s -o $out ${./container-init.cc}
'';
# The splicing code does not handle `pkgsi686Linux` well, so we have to be
# explicit about which package set it's coming from.
inherit (pkgsHostTarget) pkgsi686Linux;
realInit =
run:
writeShellScript "${name}-init" ''
source /etc/profile
exec ${run} "$@"
'';
buildFHSEnv = callPackage ./buildFHSEnv.nix { };
indentLines = str: concatLines (map (s: " " + s) (filter (s: s != "") (splitString "\n" str)));
bwrapCmd =
{
initArgs ? "",
}:
''
ignored=(/nix /dev /proc /etc ${optionalString privateTmp "/tmp"})
ro_mounts=()
symlinks=()
etc_ignored=()
fhsenv = buildFHSEnv (
removeAttrs args [
"runScript"
"extraInstallCommands"
"meta"
"passthru"
"extraPreBwrapCmds"
"extraBwrapArgs"
"dieWithParent"
"unshareUser"
"unshareCgroup"
"unshareUts"
"unshareNet"
"unsharePid"
"unshareIpc"
"privateTmp"
]
);
${extraPreBwrapCmds}
etcBindEntries =
let
files = [
# NixOS Compatibility
"static"
"nix" # mainly for nixVersions.git users, but also for access to nix/netrc
# Shells
"shells"
"bashrc"
"zshenv"
"zshrc"
"zinputrc"
"zprofile"
# Users, Groups, NSS
"passwd"
"group"
"shadow"
"hosts"
"resolv.conf"
"nsswitch.conf"
# User profiles
"profiles"
# Sudo & Su
"login.defs"
"sudoers"
"sudoers.d"
# Time
"localtime"
"zoneinfo"
# Other Core Stuff
"machine-id"
"os-release"
# PAM
"pam.d"
# Fonts
"fonts"
# ALSA
"alsa"
"asound.conf"
# SSL
"ssl/certs"
"ca-certificates"
"pki"
# Custom dconf profiles
"dconf"
];
in
map (path: "/etc/${path}") files;
# loop through all entries of root in the fhs environment, except its /etc.
for i in ${fhsenv}/*; do
path="/''${i##*/}"
if [[ $path == '/etc' ]]; then
:
elif [[ -L $i ]]; then
symlinks+=(--symlink "$(${coreutils}/bin/readlink "$i")" "$path")
ignored+=("$path")
else
ro_mounts+=(--ro-bind "$i" "$path")
ignored+=("$path")
fi
done
# Here's the problem case:
# - we need to run bash to run the init script
# - LD_PRELOAD may be set to another dynamic library, requiring us to discover its dependencies
# - oops! ldconfig is part of the init script, and it hasn't run yet
# - everything explodes
#
# In particular, this happens with fhsenvs in fhsenvs, e.g. when running
# a wrapped game from Steam.
#
# So, instead of doing that, we build a tiny static (important!) shim
# that executes ldconfig in a completely clean environment to generate
# the initial cache, and then execs into the "real" init, which is the
# first time we see anything dynamically linked at all.
#
# Also, the real init is placed strategically at /init, so we don't
# have to recompile this every time.
containerInit =
runCommandCC "container-init"
# loop through the entries of /etc in the fhs environment.
if [[ -d ${fhsenv}/etc ]]; then
for i in ${fhsenv}/etc/*; do
path="/''${i##*/}"
# NOTE: we're binding /etc/fonts and /etc/ssl/certs from the host so we
# don't want to override it with a path from the FHS environment.
if [[ $path == '/fonts' || $path == '/ssl' ]]; then
continue
fi
if [[ -L $i ]]; then
symlinks+=(--symlink "$i" "/etc$path")
else
ro_mounts+=(--ro-bind "$i" "/etc$path")
fi
etc_ignored+=("/etc$path")
done
fi
# propagate /etc from the actual host if nested
if [[ -e /.host-etc ]]; then
ro_mounts+=(--ro-bind /.host-etc /.host-etc)
else
ro_mounts+=(--ro-bind /etc /.host-etc)
fi
declare -A etc_ignored_set
for ign in "''${etc_ignored[@]}"; do
etc_ignored_set[$ign]=1
done
# link selected etc entries from the actual root
for i in ${escapeShellArgs etcBindEntries}; do
if [[ -n "''${etc_ignored_set[$i]:-}" ]]; then
continue
fi
if [[ -e $i ]]; then
symlinks+=(--symlink "/.host-etc/''${i#/etc/}" "$i")
fi
done
declare -A ignored_set
for ign in "''${ignored[@]}"; do
ignored_set[$ign]=1
done
declare -a auto_mounts
# loop through all directories in the root
for dir in /*; do
# if it is a directory and not already provided by the FHS env or
# explicitly ignored, bind-mount it into the chroot. Use exact match
# via associative array because regex substring matching incorrectly
# skips prefixes (e.g. /sb would match /sbin and never get mounted,
# breaking --chdir when CWD is on a custom mount like /sb/project).
# https://github.com/NixOS/nixpkgs/issues/241151
if [[ -d "$dir" ]] && [[ -z "''${ignored_set[$dir]:-}" ]]; then
# add it to the mount list
auto_mounts+=(--bind "$dir" "$dir")
fi
done
declare -a x11_args
# Always mount a tmpfs on /tmp/.X11-unix
# Rationale: https://github.com/flatpak/flatpak/blob/be2de97e862e5ca223da40a895e54e7bf24dbfb9/common/flatpak-run.c#L277
x11_args+=(--tmpfs /tmp/.X11-unix)
# Try to guess X socket path. This doesn't cover _everything_, but it covers some things.
if [[ "$DISPLAY" == *:* ]]; then
# recover display number from $DISPLAY formatted [host]:num[.screen]
display_nr=''${DISPLAY/#*:} # strip host
display_nr=''${display_nr/%.*} # strip screen
local_socket=/tmp/.X11-unix/X$display_nr
x11_args+=(--ro-bind-try "$local_socket" "$local_socket")
fi
${optionalString privateTmp ''
# sddm places XAUTHORITY in /tmp
if [[ "$XAUTHORITY" == /tmp/* ]]; then
x11_args+=(--ro-bind-try "$XAUTHORITY" "$XAUTHORITY")
fi
# dbus-run-session puts the socket in /tmp
IFS=";" read -ra addrs <<<"$DBUS_SESSION_BUS_ADDRESS"
for addr in "''${addrs[@]}"; do
[[ "$addr" == unix:* ]] || continue
IFS="," read -ra parts <<<"''${addr#unix:}"
for part in "''${parts[@]}"; do
printf -v part '%s' "''${part//\\/\\\\}"
printf -v part '%b' "''${part//%/\\x}"
[[ "$part" == path=/tmp/* ]] || continue
x11_args+=(--ro-bind-try "''${part#path=}" "''${part#path=}")
done
done
''}
cmd=(
${bubblewrap}/bin/bwrap
--dev-bind /dev /dev
--proc /proc
${optionalString chdirToPwd ''--chdir "$(pwd)"''}
${optionalString unshareUser "--unshare-user"}
${optionalString unshareIpc "--unshare-ipc"}
${optionalString unsharePid "--unshare-pid"}
${optionalString unshareNet "--unshare-net"}
${optionalString unshareUts "--unshare-uts"}
${optionalString unshareCgroup "--unshare-cgroup"}
${optionalString dieWithParent "--die-with-parent"}
--bind /nix /nix
${optionalString privateTmp "--tmpfs /tmp"}
# Our glibc will look for the cache in its own path in `/nix/store`.
# As such, we need a cache to exist there, because pressure-vessel
# depends on the existence of an ld cache. However, adding one
# globally proved to be a bad idea (see #100655), the solution we
# settled on being mounting one via bwrap.
# Also, the cache needs to go to both 32 and 64 bit glibcs, for games
# of both architectures to work.
--tmpfs ${glibc}/etc \
--tmpfs /etc \
--symlink /etc/ld.so.conf ${glibc}/etc/ld.so.conf \
--symlink /etc/ld.so.cache ${glibc}/etc/ld.so.cache \
--ro-bind ${glibc}/etc/rpc ${glibc}/etc/rpc \
--remount-ro ${glibc}/etc \
--symlink ${realInit runScript} /init \
''
+ optionalString fhsenv.isMultiBuild (indentLines ''
--tmpfs ${pkgsi686Linux.glibc}/etc \
--symlink /etc/ld.so.conf ${pkgsi686Linux.glibc}/etc/ld.so.conf \
--symlink /etc/ld.so.cache ${pkgsi686Linux.glibc}/etc/ld.so.cache \
--ro-bind ${pkgsi686Linux.glibc}/etc/rpc ${pkgsi686Linux.glibc}/etc/rpc \
--remount-ro ${pkgsi686Linux.glibc}/etc \
'')
+ ''
"''${ro_mounts[@]}"
"''${symlinks[@]}"
"''${auto_mounts[@]}"
"''${x11_args[@]}"
${concatStringsSep "\n " extraBwrapArgs}
${containerInit} ${initArgs}
)
exec "''${cmd[@]}"
'';
bin = writeShellScript "${name}-bwrap" (bwrapCmd {
initArgs = ''"$@"'';
});
in
runCommandLocal name
(
nameAttrs
// {
inherit nativeBuildInputs;
__structuredAttrs = true;
passthru = passthru // {
env =
runCommandLocal "${name}-shell-env"
{
buildInputs = [ stdenv.cc.libc.static or null ];
shellHook = bwrapCmd { };
}
''
$CXX -static -s -o $out ${./container-init.cc}
echo >&2 ""
echo >&2 "*** User chroot 'env' attributes are intended for interactive nix-shell sessions, not for building! ***"
echo >&2 ""
exit 1
'';
realInit =
run:
writeShellScript "${name}-init" ''
source /etc/profile
exec ${run} "$@"
'';
indentLines = str: concatLines (map (s: " " + s) (filter (s: s != "") (splitString "\n" str)));
bwrapCmd =
{
initArgs ? "",
}:
''
ignored=(/nix /dev /proc /etc ${optionalString privateTmp "/tmp"})
ro_mounts=()
symlinks=()
etc_ignored=()
${finalAttrs.extraPreBwrapCmds or ""}
# loop through all entries of root in the fhs environment, except its /etc.
for i in ${fhsenv}/*; do
path="/''${i##*/}"
if [[ $path == '/etc' ]]; then
:
elif [[ -L $i ]]; then
symlinks+=(--symlink "$(${coreutils}/bin/readlink "$i")" "$path")
ignored+=("$path")
else
ro_mounts+=(--ro-bind "$i" "$path")
ignored+=("$path")
fi
done
# loop through the entries of /etc in the fhs environment.
if [[ -d ${fhsenv}/etc ]]; then
for i in ${fhsenv}/etc/*; do
path="/''${i##*/}"
# NOTE: we're binding /etc/fonts and /etc/ssl/certs from the host so we
# don't want to override it with a path from the FHS environment.
if [[ $path == '/fonts' || $path == '/ssl' ]]; then
continue
fi
if [[ -L $i ]]; then
symlinks+=(--symlink "$i" "/etc$path")
else
ro_mounts+=(--ro-bind "$i" "/etc$path")
fi
etc_ignored+=("/etc$path")
done
fi
# propagate /etc from the actual host if nested
if [[ -e /.host-etc ]]; then
ro_mounts+=(--ro-bind /.host-etc /.host-etc)
else
ro_mounts+=(--ro-bind /etc /.host-etc)
fi
declare -A etc_ignored_set
for ign in "''${etc_ignored[@]}"; do
etc_ignored_set[$ign]=1
done
# link selected etc entries from the actual root
for i in ${escapeShellArgs etcBindEntries}; do
if [[ -n "''${etc_ignored_set[$i]:-}" ]]; then
continue
fi
if [[ -e $i ]]; then
symlinks+=(--symlink "/.host-etc/''${i#/etc/}" "$i")
fi
done
declare -A ignored_set
for ign in "''${ignored[@]}"; do
ignored_set[$ign]=1
done
declare -a auto_mounts
# loop through all directories in the root
for dir in /*; do
# if it is a directory and not already provided by the FHS env or
# explicitly ignored, bind-mount it into the chroot. Use exact match
# via associative array because regex substring matching incorrectly
# skips prefixes (e.g. /sb would match /sbin and never get mounted,
# breaking --chdir when CWD is on a custom mount like /sb/project).
# https://github.com/NixOS/nixpkgs/issues/241151
if [[ -d "$dir" ]] && [[ -z "''${ignored_set[$dir]:-}" ]]; then
# add it to the mount list
auto_mounts+=(--bind "$dir" "$dir")
fi
done
declare -a x11_args
# Always mount a tmpfs on /tmp/.X11-unix
# Rationale: https://github.com/flatpak/flatpak/blob/be2de97e862e5ca223da40a895e54e7bf24dbfb9/common/flatpak-run.c#L277
x11_args+=(--tmpfs /tmp/.X11-unix)
# Try to guess X socket path. This doesn't cover _everything_, but it covers some things.
if [[ "$DISPLAY" == *:* ]]; then
# recover display number from $DISPLAY formatted [host]:num[.screen]
display_nr=''${DISPLAY/#*:} # strip host
display_nr=''${display_nr/%.*} # strip screen
local_socket=/tmp/.X11-unix/X$display_nr
x11_args+=(--ro-bind-try "$local_socket" "$local_socket")
fi
${optionalString privateTmp ''
# sddm places XAUTHORITY in /tmp
if [[ "$XAUTHORITY" == /tmp/* ]]; then
x11_args+=(--ro-bind-try "$XAUTHORITY" "$XAUTHORITY")
fi
# dbus-run-session puts the socket in /tmp
IFS=";" read -ra addrs <<<"$DBUS_SESSION_BUS_ADDRESS"
for addr in "''${addrs[@]}"; do
[[ "$addr" == unix:* ]] || continue
IFS="," read -ra parts <<<"''${addr#unix:}"
for part in "''${parts[@]}"; do
printf -v part '%s' "''${part//\\/\\\\}"
printf -v part '%b' "''${part//%/\\x}"
[[ "$part" == path=/tmp/* ]] || continue
x11_args+=(--ro-bind-try "''${part#path=}" "''${part#path=}")
done
done
''}
cmd=(
${bubblewrap}/bin/bwrap
--dev-bind /dev /dev
--proc /proc
${optionalString chdirToPwd ''--chdir "$(pwd)"''}
${optionalString unshareUser "--unshare-user"}
${optionalString unshareIpc "--unshare-ipc"}
${optionalString unsharePid "--unshare-pid"}
${optionalString unshareNet "--unshare-net"}
${optionalString unshareUts "--unshare-uts"}
${optionalString unshareCgroup "--unshare-cgroup"}
${optionalString dieWithParent "--die-with-parent"}
--bind /nix /nix
${optionalString privateTmp "--tmpfs /tmp"}
# Our glibc will look for the cache in its own path in `/nix/store`.
# As such, we need a cache to exist there, because pressure-vessel
# depends on the existence of an ld cache. However, adding one
# globally proved to be a bad idea (see #100655), the solution we
# settled on being mounting one via bwrap.
# Also, the cache needs to go to both 32 and 64 bit glibcs, for games
# of both architectures to work.
--tmpfs ${glibc}/etc \
--tmpfs /etc \
--symlink /etc/ld.so.conf ${glibc}/etc/ld.so.conf \
--symlink /etc/ld.so.cache ${glibc}/etc/ld.so.cache \
--ro-bind ${glibc}/etc/rpc ${glibc}/etc/rpc \
--remount-ro ${glibc}/etc \
--symlink ${realInit runScript} /init \
''
+ optionalString fhsenv.isMultiBuild (indentLines ''
--tmpfs ${pkgsi686Linux.glibc}/etc \
--symlink /etc/ld.so.conf ${pkgsi686Linux.glibc}/etc/ld.so.conf \
--symlink /etc/ld.so.cache ${pkgsi686Linux.glibc}/etc/ld.so.cache \
--ro-bind ${pkgsi686Linux.glibc}/etc/rpc ${pkgsi686Linux.glibc}/etc/rpc \
--remount-ro ${pkgsi686Linux.glibc}/etc \
'')
+ ''
"''${ro_mounts[@]}"
"''${symlinks[@]}"
"''${auto_mounts[@]}"
"''${x11_args[@]}"
${concatStringsSep "\n " (finalAttrs.extraBwrapArgs or [ ])}
${containerInit} ${initArgs}
)
exec "''${cmd[@]}"
'';
bin = writeShellScript "${name}-bwrap" (bwrapCmd {
initArgs = ''"$@"'';
});
in
{
buildCommand = ''
mkdir -p $out/bin
ln -s ${bin} $out/bin/${executableName}
${finalAttrs.extraInstallCommands or ""}
'';
__structuredAttrs = true;
strictDeps = true;
enableParallelBuilding = true;
preferLocalBuild = true;
allowSubstitutes = false;
passthru = passthru // {
env =
runCommandLocal "${name}-shell-env"
{
shellHook = bwrapCmd { };
}
''
echo >&2 ""
echo >&2 "*** User chroot 'env' attributes are intended for interactive nix-shell sessions, not for building! ***"
echo >&2 ""
exit 1
'';
inherit args fhsenv;
};
meta = {
mainProgram = executableName;
}
// meta;
inherit args fhsenv;
};
}
)
meta = {
mainProgram = executableName;
}
// meta;
}
)
''
mkdir -p $out/bin
ln -s ${bin} $out/bin/${executableName}
${extraInstallCommands}
''

View File

@@ -29,6 +29,10 @@ let
services = {
svc = {
process.argv = [ "${coreutils}/bin/true" ];
process.environment = {
FOO = "bar";
DROPPED = null;
};
assertions = [
{
assertion = true;
@@ -70,6 +74,19 @@ let
expected = [ "${coreutils}/bin/true" ];
};
# A set environment variable round-trips through process.environment.
testProcessEnvironment = {
expr = c.process.environment.FOO;
expected = "bar";
};
# A null environment variable is preserved as null (unset request),
# rather than coerced to a string or dropped from the attrset.
testProcessEnvironmentNull = {
expr = c.process.environment.DROPPED;
expected = null;
};
testAssertions = {
expr = lib.elem {
assertion = true;
@@ -186,6 +203,9 @@ let
mkdir -p "$dir"
echo "$$" > "$dir/pid"
printf '%s\n' "$@" > "$dir/args"
# Record the process's own environment as received from the service
# manager (NUL-delimited, as the kernel stores it).
"${coreutils}/bin/cat" "/proc/$$/environ" > "$dir/environ"
exec "${coreutils}/bin/sleep" infinity
'';
@@ -238,6 +258,31 @@ let
|| { echo "${id}: expected arg ${lib.escapeShellArg arg} not found"; cat "${sharedDir}/${id}/args"; exit 1; }
'') expectedArgs;
/**
Shell snippet: assert that the service's recorded environment contains
each `present` entry (an exact `KEY=value` string) and contains no
variable named in `absent`.
*/
checkEnv =
id:
{
present ? [ ],
absent ? [ ],
}:
''
# The recorded environ is NUL-delimited; render one entry per line.
tr '\0' '\n' < "${sharedDir}/${id}/environ" > "${sharedDir}/${id}/environ.lines"
''
+ lib.concatMapStrings (entry: ''
grep -qxF -- ${lib.escapeShellArg entry} "${sharedDir}/${id}/environ.lines" \
|| { echo "${id}: expected env ${lib.escapeShellArg entry} not found"; cat "${sharedDir}/${id}/environ.lines"; exit 1; }
'') present
+ lib.concatMapStrings (key: ''
if grep -qE ${lib.escapeShellArg "^${key}="} "${sharedDir}/${id}/environ.lines"; then
echo "${id}: env variable ${lib.escapeShellArg key} should be unset"; exit 1
fi
'') absent;
mkTestScript =
name: text:
lib.getExe (writeShellApplication {
@@ -330,6 +375,24 @@ in
);
};
environment = mkTest {
name = "${namePrefix}-environment";
services.test = {
process.argv = mkArgv "env" [ ];
process.environment = {
FOO = "bar";
DROPPED = null;
};
};
testExe = mkTestScript "environment" (
waitAndCheck "env" [ ]
+ checkEnv "env" {
present = [ "FOO=bar" ];
absent = [ "DROPPED" ];
}
);
};
sub-services = mkTest {
name = "${namePrefix}-sub-services";
services.a = {

View File

@@ -15,11 +15,12 @@
stdenv.mkDerivation (finalAttrs: {
pname = "algol68g";
version = "3.12.3";
version = "3.12.2";
src = fetchurl {
url = "https://algol68genie.nl/algol68g-${finalAttrs.version}.tar.gz";
hash = "sha256-TS5m+Byi+5j4jiOuQbR159QERfNJsQiGNngtoyC9IrE=";
# Uses archive.org because the original site removes older versions.
url = "https://web.archive.org/web/20260515052918/https://algol68genie.nl/algol68g-3.12.2.tar.gz";
hash = "sha256-4fiubqpgoH3YOlCg1bJHQ3kOayKNulW3CYbOK1awE7k";
};
outputs = [
@@ -47,8 +48,8 @@ stdenv.mkDerivation (finalAttrs: {
postInstall =
let
pdfdoc = fetchurl {
url = "https://algol68genie.nl/learning-algol-68-genie.pdf";
hash = "sha256-BrVjYXd5sknV0+UCRgQMf0H3QMzMQcLhytEEuiTGkLE=";
url = "https://web.archive.org/web/20260503174213/https://algol68genie.nl/learning-algol-68-genie.pdf";
hash = "sha256-eLMRf3XcAkr/Dmk7ieRe62x76VcCj+2QltHH7YtL15s=";
};
in
lib.optionalString withPDFDoc ''

View File

@@ -12,16 +12,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "alistral";
version = "0.6.8";
version = "0.6.7";
src = fetchFromGitHub {
owner = "RustyNova016";
repo = "Alistral";
tag = "v${finalAttrs.version}";
hash = "sha256-NDWQl2Gq4Q0OMMCrHQhybInaJRjY3Fxe3GXrGb32MMY=";
hash = "sha256-XsN4UyIXkd0YVtO/q9EcFP/sBYkH9leISmbJZ93ef6E=";
};
cargoHash = "sha256-QxTmjtntp5zy7UijRn0hF3DyOOl3dIpZjPSASCuHaEk=";
cargoHash = "sha256-KFNFioZ/5moC5FNXw+hA+NrPjsqu+3V8A5mtZ4FZUHw=";
buildNoDefaultFeatures = true;
# Would be cleaner with an "--all-features" option

View File

@@ -9,6 +9,7 @@
let
opencv4WithGtk = python3Packages.opencv4.override {
enableGtk2 = true; # For GTK2 support
enableGtk3 = true; # For GTK3 support
};
in

View File

@@ -6,7 +6,7 @@
rustPlatform.buildRustPackage {
pname = "as-tree";
version = "0.12.0-unstable-2021-03-09";
version = "unstable-2021-03-09";
src = fetchFromGitHub {
owner = "jez";

View File

@@ -12,16 +12,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "aube";
version = "1.32.0";
version = "1.29.1";
src = fetchFromGitHub {
owner = "jdx";
repo = "aube";
tag = "v${finalAttrs.version}";
hash = "sha256-0BnaxRk6+KY4AGZ31lis0zxc9uWp3OrxCgp9SgOrqNI=";
hash = "sha256-87r9qltKUhjnYG9O484OUzKFiO8Xoge9VZ13l6RgrdA=";
};
cargoHash = "sha256-vYbbnEpVWG6kjnycl1kk3D+lXuzTzOKuilA0ImBHYAI=";
cargoHash = "sha256-Cy5Ea/rF2IJ5WppKKI7E1toy9N+bQEArVW9o2pHzBMc=";
nativeBuildInputs = [ cmake ]; # libz-ng-sys
@@ -36,7 +36,6 @@ rustPlatform.buildRustPackage (finalAttrs: {
checkFlags = [
# failed on x86_64-linux
"--skip=concurrency::tests::floor_and_ceiling_inclusive"
"--skip=http::ticket_cache::tests::max_per_host_evicts_oldest"
"--skip=http::ticket_cache::tests::invalidate_removes_all_for_host"
# require network access

View File

@@ -7,16 +7,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "automatic-timezoned";
version = "2.0.149";
version = "2.0.143";
src = fetchFromGitHub {
owner = "maxbrunet";
repo = "automatic-timezoned";
rev = "v${finalAttrs.version}";
sha256 = "sha256-FQ4SJcHkdNJcZOncY0BHg+CwnUcyszzfYPCUhWZHhi0=";
sha256 = "sha256-bbdhvQ9THiBRf1rLExXQiwlrkgZBFZlaV2CUszDmwo4=";
};
cargoHash = "sha256-4+gNtQrlaDrSCUFEIByFUQnITSkF9Mo9bq6Ug9d7t1w=";
cargoHash = "sha256-J7h1hVp8wK6UlkstcLCq4uMKJ9ZyLwGR75tcxpWnHT8=";
nativeInstallCheckInputs = [ versionCheckHook ];

View File

@@ -1,82 +0,0 @@
{
lib,
stdenv,
fetchzip,
autoPatchelfHook,
azure-cli,
makeWrapper,
}:
let
version = "3.0.0-beta.10";
srcs = {
x86_64-linux = {
url = "https://github.com/microsoft/mcp/releases/download/Azure.Mcp.Server-${version}/Azure.Mcp.Server-linux-x64-native.zip";
hash = "sha256-2wrpyTVunT54dYD1ascVDRTW2AN5NpoV+q3UUt5dQSg=";
};
aarch64-linux = {
url = "https://github.com/microsoft/mcp/releases/download/Azure.Mcp.Server-${version}/Azure.Mcp.Server-linux-arm64.zip";
hash = "sha256-K1QRpj5/RzZx2mrmtnB5lGX9CoaAC+pRVGqqHtXWncY=";
};
x86_64-darwin = {
url = "https://github.com/microsoft/mcp/releases/download/Azure.Mcp.Server-${version}/Azure.Mcp.Server-osx-x64.zip";
hash = "sha256-ebT6sipbA7IdGx98kF/8GLpHL1fVSVqnmL4rEwsa43k=";
};
aarch64-darwin = {
url = "https://github.com/microsoft/mcp/releases/download/Azure.Mcp.Server-${version}/Azure.Mcp.Server-osx-arm64.zip";
hash = "sha256-33rg+fnIB/VJZbVKTP7b8829BbcDnfnaYFMOyPLFzEw=";
};
};
unavailable = throw "azure-mcp package is not available for this platform.";
src = fetchzip {
inherit (srcs.${stdenv.hostPlatform.system} or unavailable) url hash;
stripRoot = false;
};
in
stdenv.mkDerivation {
pname = "azure-mcp";
inherit version src;
strictDeps = true;
__structuredAttrs = true;
nativeBuildInputs = [
makeWrapper
]
++ lib.optionals stdenv.hostPlatform.isLinux [ autoPatchelfHook ];
buildInputs = lib.optionals stdenv.hostPlatform.isLinux [
stdenv.cc.cc.lib
];
dontConfigure = true;
dontBuild = true;
installPhase = ''
runHook preInstall
install -Dm755 ./azmcp $out/bin/azure-mcp
wrapProgram $out/bin/azure-mcp \
--prefix PATH : ${lib.makeBinPath [ azure-cli ]}
runHook postInstall
'';
meta = {
description = "Model Context Protocol server for Azure services";
longDescription = ''
The Azure MCP Server implements the Model Context Protocol (MCP)
specification to create a seamless connection between AI agents and
Azure services. It provides 321+ tools for interacting with Azure
resources including storage, compute, databases, and more.
'';
homepage = "https://github.com/microsoft/mcp";
changelog = "https://github.com/microsoft/mcp/blob/Azure.Mcp.Server-${version}/servers/Azure.Mcp.Server/CHANGELOG.md";
license = lib.licenses.mit;
sourceProvenance = [ lib.sourceTypes.binaryNativeCode ];
platforms = lib.attrNames srcs;
mainProgram = "azure-mcp";
maintainers = with lib.maintainers; [ sheeeng ];
};
}

View File

@@ -2,7 +2,6 @@
lib,
python3Packages,
fetchPypi,
fetchgit,
patatt,
}:
@@ -32,15 +31,6 @@ python3Packages.buildPythonApplication (finalAttrs: {
textual
];
passthru = {
src-misc = fetchgit {
url = "https://git.kernel.org/pub/scm/utils/b4/b4.git";
rev = "v${finalAttrs.version}";
hash = "sha256-NjYL3RKQpjDkU98qbXyl/cvLTJYVAfIowm8E2Rg8AgI=";
fetchSubmodules = false;
};
};
meta = {
homepage = "https://git.kernel.org/pub/scm/utils/b4/b4.git/about";
license = lib.licenses.gpl2Only;

View File

@@ -20,13 +20,13 @@ let
in
buildBazelPackage rec {
pname = "bant";
version = "0.3.3";
version = "0.3.0";
src = fetchFromGitHub {
owner = "hzeller";
repo = "bant";
rev = "v${version}";
hash = "sha256-6c403+DK1tcQxC16FKEtdhnJEA9LJl8H8Usnw08FBnA=";
hash = "sha256-T/BQRYCFAHkaGi5T485I9vbr3g7PzgIEHC27w6mg/3A=";
};
bazelFlags = [

View File

@@ -6,16 +6,16 @@
buildGoModule (finalAttrs: {
pname = "bazel-remote";
version = "2.6.2";
version = "2.6.1";
src = fetchFromGitHub {
owner = "buchgr";
repo = "bazel-remote";
rev = "v${finalAttrs.version}";
hash = "sha256-wE0l1tBtj44l1Eamd4wCHzjnPhT7W5yZ5MkTA5cOUrg=";
hash = "sha256-9vPaTm/HTJ3ftlFg+AkcwXX7xyhmGTgKL3PXhtUHRDk=";
};
vendorHash = "sha256-DGyGQLEAwy79ibWGxAWa7gmaXTajcW3jqGJou2Wnykc=";
vendorHash = "sha256-uh8ST1AQ8OsFMfXly23TMMcheNmhb1MknmPMjB76GIQ=";
subPackages = [ "." ];

View File

@@ -8,17 +8,17 @@
buildGoModule (finalAttrs: {
pname = "bento";
version = "1.19.0";
version = "1.18.1";
src = fetchFromGitHub {
owner = "warpstreamlabs";
repo = "bento";
tag = "v${finalAttrs.version}";
hash = "sha256-3ZISLZzh8FYAE9riZ5Ya5h3LhwzHK4a5jJl8jeHiNoA=";
hash = "sha256-KIlCHOAHShOwrxO9F414PQ07+SzCWhpo8auhyjkuNZA=";
};
proxyVendor = true;
vendorHash = "sha256-h9bH5aewbDAuOVAps3TMihjCITFiBT/bbqNJCUT0NN8=";
vendorHash = "sha256-uzB98AiJKw9TCbKSdQDiztfw7nIT0mVt80JALAPp2Aw=";
subPackages = [
"cmd/bento"

View File

@@ -1,8 +1,8 @@
# Generated by ./update.sh
# Generated by ./update.sh - do not update manually!
{
version = "1.10.4";
deb-hash = "sha256-rOFbiuEbeO2qZntUhO+LNhwX6XlvWRU9v0HIAjyHwd8=";
sig-hash = "sha256-3fAGauXHA8S+XIuHeOIFxp7TsXd1LdqFg8hpWIU4P7k=";
version = "1.10.3";
deb-hash = "sha256-kzLtadq8gfX6j9XU3PD5kNV43wLDoICPlXdJqULkAWE=";
sig-hash = "sha256-+51j+SBp7buukop1T4Gz0YDUga6540BVxDRoU2YE3pY=";
key-E222AA02-hash = "sha256-Ue/UmS6F440/ybEEIAR+pdPEIksAt6QSMN6G5TZVWzc=";
key-4A133008-hash = "sha256-UijG3DkJNNTakVJd2wl30mDepa27n6R/Xxfl4sjt0sk=";
key-387C8307-hash = "sha256-PrRYZLT0xv82dUscOBgQGKNf6zwzWUDhriAffZbNpmI=";

View File

@@ -14,13 +14,13 @@
buildNpmPackage (finalAttrs: {
pname = "bitwarden-cli";
version = "2026.7.0";
version = "2026.6.0";
src = fetchFromGitHub {
owner = "bitwarden";
repo = "clients";
tag = "cli-v${finalAttrs.version}";
hash = "sha256-8PYjRa1lhs53FCfqPBqH9712X1ek02wbkI+kW5tkepE=";
hash = "sha256-JIIis3wW0cU33ovRQfJi3HlB2YdLZ5IPvueq1dGFbas=";
};
postPatch = ''
@@ -31,7 +31,7 @@ buildNpmPackage (finalAttrs: {
nodejs = nodejs_22;
npmDepsFetcherVersion = 2;
npmDepsHash = "sha256-WRxlvkgWboO0ukUHgjC5CrfgfwnmUfDXI4r5dx9CKww=";
npmDepsHash = "sha256-sXFSjQw9iM5Ye03BX+ZzpDfeAyLTJoG/k46NiI3O8+A=";
nativeBuildInputs = lib.optionals stdenv.hostPlatform.isDarwin [
perl

View File

@@ -31,10 +31,8 @@ stdenv.mkDerivation (finalAttrs: {
'';
nativeBuildInputs = [
gobject-introspection
meson
ninja
python3
wrapGAppsNoGuiHook
];
@@ -88,8 +86,6 @@ stdenv.mkDerivation (finalAttrs: {
};
};
strictDeps = true;
meta = {
description = "Markup language for GTK user interface files";
mainProgram = "blueprint-compiler";

View File

@@ -12,16 +12,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "bottom";
version = "0.14.6";
version = "0.14.4";
src = fetchFromGitHub {
owner = "ClementTsang";
repo = "bottom";
tag = finalAttrs.version;
hash = "sha256-52aUYfFm72nSG7bAlwa18kMu13i+c4myl2QfaA2YZmw=";
hash = "sha256-axzZEviUVosXo5XzQB32A2+sUdiLzEtjZg52Z6hp4lM=";
};
cargoHash = "sha256-N+dfYORAdWAg5qUrFEgXbiRtYJpcvV1AcbLR5WiD0QI=";
cargoHash = "sha256-RUFlv95VoRhfHeIXWFWWtbwn71uJnEYoi2NozU4ybK8=";
nativeBuildInputs = [
autoAddDriverRunpath

View File

@@ -49,20 +49,26 @@
coreutils,
libxcb,
zlib,
# Darwin dependencies
unzip,
makeWrapper,
# command line arguments which are always set e.g "--disable-gpu"
commandLineArgs ? "",
# Necessary for USB audio devices.
pulseSupport ? stdenv.hostPlatform.isLinux,
libpulseaudio,
# For GPU acceleration support on Wayland (without the lib it doesn't seem to work)
libGL,
# For video acceleration via VA-API (--enable-features=AcceleratedVideoDecodeLinuxGL,AcceleratedVideoEncoder)
libvaSupport ? stdenv.hostPlatform.isLinux,
libva,
enableVideoAcceleration ? libvaSupport,
# For Vulkan support (--enable-features=Vulkan); disabled by default as it seems to break VA-API
vulkanSupport ? false,
addDriverRunpath,
@@ -72,22 +78,8 @@
{
pname,
version,
# Map from Nix system strings ("x86_64-linux", "aarch64-darwin", ...) to
# the corresponding upstream `{ url, hash }` record. Encoding the per-system
# sources as data rather than positional arguments lets channel-specific
# package.nix files drop platforms that upstream hasn't published yet.
archives,
# Upstream product flavor: "browser" (the regular Brave) or "origin" (the
# stripped-down Brave Origin).
flavor ? "browser",
# Flavor-specific paths supplied by the caller (default.nix).
optStem,
fileStem,
appIdStem,
darwinStem,
changelogFile,
homepage,
innerBinary,
hash,
url,
}:
let
@@ -102,19 +94,6 @@ let
escapeShellArg
;
# /opt/brave.com/<optName>/
optName = optStem;
# Basename used for .desktop, gnome-control-center xml and icon files.
fileBase = fileStem;
# Secondary .desktop app-id.
appId = appIdStem;
# Upstream shell wrapper inside /opt.
innerWrapper = fileStem;
# macOS .app bundle name (inside the zip).
darwinApp = darwinStem;
# Upstream Exec= target in .desktop files (replaced with our wrapper).
upstreamBin = "brave-${flavor}-stable";
deps = [
alsa-lib
at-spi2-atk
@@ -177,19 +156,13 @@ let
] # disable automatic updates
# The feature disable is needed for VAAPI to work correctly: https://github.com/brave/brave-browser/issues/20935
++ optionals enableVideoAcceleration [ "UseChromeOSDirectVideoDecoder" ];
archive =
assert lib.assertMsg (builtins.hasAttr stdenv.hostPlatform.system archives)
"${pname} is not available for ${stdenv.hostPlatform.system}";
archives.${stdenv.hostPlatform.system};
in
stdenv.mkDerivation {
inherit pname version;
__structuredAttrs = true;
strictDeps = true;
src = fetchurl { inherit (archive) url hash; };
src = fetchurl {
inherit url hash;
};
dontConfigure = true;
dontBuild = true;
@@ -228,27 +201,27 @@ stdenv.mkDerivation {
cp -R usr/share $out
cp -R opt/ $out/opt
export BINARYWRAPPER=$out/opt/brave.com/${optName}/${innerWrapper}
export BINARYWRAPPER=$out/opt/brave.com/brave/brave-browser
# Fix path to bash in $BINARYWRAPPER
substituteInPlace $BINARYWRAPPER \
--replace-fail /bin/bash ${stdenv.shell} \
--replace-fail 'CHROME_WRAPPER' 'WRAPPER'
ln -sf $BINARYWRAPPER $out/bin/${pname}
ln -sf $BINARYWRAPPER $out/bin/brave
for exe in $out/opt/brave.com/${optName}/{${innerBinary},chrome_crashpad_handler}; do
for exe in $out/opt/brave.com/brave/{brave,chrome_crashpad_handler}; do
patchelf \
--set-interpreter "$(cat $NIX_CC/nix-support/dynamic-linker)" \
--set-rpath "${rpath}" $exe
done
# Fix paths
substituteInPlace $out/share/applications/{${fileBase},${appId}}.desktop \
--replace-fail /usr/bin/${upstreamBin} $out/bin/${pname}
substituteInPlace $out/share/gnome-control-center/default-apps/${fileBase}.xml \
substituteInPlace $out/share/applications/{brave-browser,com.brave.Browser}.desktop \
--replace-fail /usr/bin/brave-browser-stable $out/bin/brave
substituteInPlace $out/share/gnome-control-center/default-apps/brave-browser.xml \
--replace-fail /opt/brave.com $out/opt/brave.com
substituteInPlace $out/opt/brave.com/${optName}/default-app-block \
substituteInPlace $out/opt/brave.com/brave/default-app-block \
--replace-fail /opt/brave.com $out/opt/brave.com
# Correct icons location
@@ -256,13 +229,13 @@ stdenv.mkDerivation {
for icon in ''${icon_sizes[*]}
do
mkdir -p $out/share/icons/hicolor/''${icon}x''${icon}/apps
ln -s $out/opt/brave.com/${optName}/product_logo_''${icon}.png $out/share/icons/hicolor/''${icon}x''${icon}/apps/${fileBase}.png
mkdir -p $out/share/icons/hicolor/$icon\x$icon/apps
ln -s $out/opt/brave.com/brave/product_logo_$icon.png $out/share/icons/hicolor/$icon\x$icon/apps/brave-browser.png
done
# Replace xdg-settings and xdg-mime
ln -sf ${xdg-utils}/bin/xdg-settings $out/opt/brave.com/${optName}/xdg-settings
ln -sf ${xdg-utils}/bin/xdg-mime $out/opt/brave.com/${optName}/xdg-mime
ln -sf ${xdg-utils}/bin/xdg-settings $out/opt/brave.com/brave/xdg-settings
ln -sf ${xdg-utils}/bin/xdg-mime $out/opt/brave.com/brave/xdg-mime
runHook postInstall
''
@@ -271,9 +244,9 @@ stdenv.mkDerivation {
mkdir -p $out/{Applications,bin}
cp -r . "$out/Applications/${darwinApp}.app"
cp -r . "$out/Applications/Brave Browser.app"
makeWrapper "$out/Applications/${darwinApp}.app/Contents/MacOS/${darwinApp}" $out/bin/${pname}
makeWrapper "$out/Applications/Brave Browser.app/Contents/MacOS/Brave Browser" $out/bin/brave
runHook postInstall
'';
@@ -306,33 +279,22 @@ stdenv.mkDerivation {
installCheckPhase = ''
# Bypass upstream wrapper which suppresses errors
$out/opt/brave.com/${optName}/brave --version
$out/opt/brave.com/brave/brave --version
'';
passthru.updateScript = ./update.sh;
meta = {
homepage = homepage;
description =
"Privacy-oriented browser for Desktop and Laptop computers"
+ lib.optionalString (flavor == "origin") " (Origin variant)";
homepage = "https://brave.com/";
description = "Privacy-oriented browser for Desktop and Laptop computers";
changelog =
"https://github.com/brave/brave-browser/blob/master/${changelogFile}#"
"https://github.com/brave/brave-browser/blob/master/CHANGELOG_DESKTOP.md#"
+ lib.replaceStrings [ "." ] [ "" ] version;
longDescription =
if flavor == "origin" then
''
Brave Origin is a stripped-down variant of the Brave browser that
removes most non-privacy features (rewards, wallet, AI, etc.) while
keeping the core privacy, adblock and Chromium-based browsing
experience.
''
else
''
Brave browser blocks the ads and trackers that slow you down,
chew up your bandwidth, and invade your privacy. Brave lets you
contribute to your favorite creators automatically.
'';
longDescription = ''
Brave browser blocks the ads and trackers that slow you down,
chew up your bandwidth, and invade your privacy. Brave lets you
contribute to your favorite creators automatically.
'';
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
license = lib.licenses.mpl20;
maintainers = with lib.maintainers; [
@@ -340,9 +302,12 @@ stdenv.mkDerivation {
jefflabonte
nasirhm
buckley310
rachalaraj
];
platforms = builtins.attrNames archives;
mainProgram = if flavor == "origin" then "brave-origin" else "brave";
platforms = [
"aarch64-linux"
"x86_64-linux"
"aarch64-darwin"
];
mainProgram = "brave";
};
}

View File

@@ -0,0 +1,35 @@
# Expression generated by update.sh; do not edit it by hand!
{ stdenv, callPackage, ... }@args:
let
pname = "brave";
version = "1.92.143";
allArchives = {
aarch64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_arm64.deb";
hash = "sha256-IHBJm9uow2d/X4Z9e117aGdP1Y+3R1ApWu40sPtdbr8=";
};
x86_64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_amd64.deb";
hash = "sha256-jaxNneurduBiw3jho5Fp7gXnBfSpLB5hlE06i/JK+ic=";
};
aarch64-darwin = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-v${version}-darwin-arm64.zip";
hash = "sha256-EvfZgO8FAijof1Ml6gqSOyRndL8KYFdT0MNmVmuxAnU=";
};
};
archive =
if builtins.hasAttr stdenv.system allArchives then
allArchives.${stdenv.system}
else
throw "Unsupported platform.";
in
callPackage ./make-brave.nix (removeAttrs args [ "callPackage" ]) (
archive
// {
inherit pname version;
}
)

48
pkgs/by-name/br/brave/update.sh Executable file
View File

@@ -0,0 +1,48 @@
#!/usr/bin/env nix-shell
#!nix-shell -i bash -p curl gnused nix jq
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" &>/dev/null && pwd)"
latestVersion="$(curl --fail -s ${GITHUB_TOKEN:+-u ":$GITHUB_TOKEN"} "https://api.github.com/repos/brave/brave-browser/releases/latest" | jq -r '.tag_name' | sed 's/^v//')"
hashAarch64="$(nix-hash --to-sri --type sha256 "$(nix-prefetch-url --type sha256 "https://github.com/brave/brave-browser/releases/download/v${latestVersion}/brave-browser_${latestVersion}_arm64.deb")")"
hashAmd64="$(nix-hash --to-sri --type sha256 "$(nix-prefetch-url --type sha256 "https://github.com/brave/brave-browser/releases/download/v${latestVersion}/brave-browser_${latestVersion}_amd64.deb")")"
hashAarch64Darwin="$(nix-hash --to-sri --type sha256 "$(nix-prefetch-url --type sha256 "https://github.com/brave/brave-browser/releases/download/v${latestVersion}/brave-v${latestVersion}-darwin-arm64.zip")")"
cat > $SCRIPT_DIR/package.nix << EOF
# Expression generated by update.sh; do not edit it by hand!
{ stdenv, callPackage, ... }@args:
let
pname = "brave";
version = "${latestVersion}";
allArchives = {
aarch64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v\${version}/brave-browser_\${version}_arm64.deb";
hash = "${hashAarch64}";
};
x86_64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v\${version}/brave-browser_\${version}_amd64.deb";
hash = "${hashAmd64}";
};
aarch64-darwin = {
url = "https://github.com/brave/brave-browser/releases/download/v\${version}/brave-v\${version}-darwin-arm64.zip";
hash = "${hashAarch64Darwin}";
};
};
archive =
if builtins.hasAttr stdenv.system allArchives then
allArchives.\${stdenv.system}
else
throw "Unsupported platform.";
in
callPackage ./make-brave.nix (removeAttrs args [ "callPackage" ]) (
archive
// {
inherit pname version;
}
)
EOF

View File

@@ -21,13 +21,13 @@
buildNpmPackage rec {
pname = "bruno";
version = "4.0.0";
version = "3.5.2";
src = fetchFromGitHub {
owner = "usebruno";
repo = "bruno";
tag = "v${version}";
hash = "sha256-M4oNx3nSe8hSAtZMVyXIW0qQIQkaOeQgpPsfjmmJ30E=";
hash = "sha256-Lll/ywDkHv0xvLk8iiBEySek7A3dBmfO4V/q2xaNtBQ=";
postFetch = ''
${lib.getExe npm-lockfile-fix} $out/package-lock.json
@@ -36,7 +36,7 @@ buildNpmPackage rec {
nodejs = nodejs_22;
npmDepsHash = "sha256-Jrlpztg1JxuPaLD4O9elOaU1eFH3dmr6oWwi4Ch9Zv8=";
npmDepsHash = "sha256-4VsSXiHj/INCu4ryZ+JxPbfDpsgIb5eYvOUYz+gbKEE=";
npmFlags = [ "--legacy-peer-deps" ];
nativeBuildInputs = [
@@ -77,10 +77,6 @@ buildNpmPackage rec {
# fix version reported in sidebar and about page
${jq}/bin/jq '.version |= "${version}"' packages/bruno-electron/package.json | ${moreutils}/bin/sponge packages/bruno-electron/package.json
${jq}/bin/jq '.version |= "${version}"' packages/bruno-app/package.json | ${moreutils}/bin/sponge packages/bruno-app/package.json
# disable remote image download to prevent network calls to comply with build sandboxing
substituteInPlace packages/bruno-app/plugins/remote-images/loader.cjs \
--replace-fail 'const urls = findRemoteImageUrls(source, domains);' 'const urls = [];'
'';
postConfigure = ''

View File

@@ -13,7 +13,7 @@
clutter-gtk,
gst_all_1,
glib,
gtk3,
gtk2,
libgsf,
libxml2,
fluidsynth,
@@ -52,7 +52,7 @@ stdenv.mkDerivation {
gst_all_1.gst-plugins-base
gst_all_1.gst-plugins-good
glib
gtk3
gtk2
libgsf
libxml2
# optional packages

View File

@@ -11,16 +11,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cargo-binstall";
version = "1.21.1";
version = "1.21.0";
src = fetchFromGitHub {
owner = "cargo-bins";
repo = "cargo-binstall";
tag = "v${finalAttrs.version}";
hash = "sha256-7YXdKK6P6LSf/DGDL6jroR3VVqAD4uGUOGJS/dZbcvw=";
hash = "sha256-6msYAVCN1i2srA4DquqcdJxUrJP1jub34c/a/4RbWCg=";
};
cargoHash = "sha256-iUYTFtx0KBi4qgJNyuIAGcTCbS4KMyBbTIgR3nDiNAI=";
cargoHash = "sha256-r9iGWxrLlD83QtvZuWXIxjI2S0RO1GNwOed531FVvJk=";
nativeBuildInputs = [
pkg-config

View File

@@ -8,15 +8,15 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cargo-shear";
version = "1.13.3";
version = "1.13.2";
src = fetchCrate {
pname = "cargo-shear";
version = finalAttrs.version;
hash = "sha256-Qaq3nBZZR0biG5kVL15zhI8GwLEWBNzgeD3rHeZZOeU=";
hash = "sha256-69OwhT4vc4xwvuVxZ0C7F/Us01TsuYJnnTKT6PHsOF8=";
};
cargoHash = "sha256-3YMdOCCK+rVx0XZfBqiMAw+aep1TBU5Ok6//c433h4o=";
cargoHash = "sha256-x0lZ8E/P9IaPSdzUo2O3t5qR2I3959So9uaAm4PBM4E=";
env = {
# https://github.com/Boshen/cargo-shear/blob/v1.6.2/src/lib.rs#L51-L54

View File

@@ -8,45 +8,40 @@
apple-sdk_15,
libiconv,
versionCheckHook,
nix-update,
writeShellApplication,
curl,
nix-update-script,
runCommand,
jq,
}:
let
# ccusage embeds the LiteLLM model-pricing table at build time instead of
# downloading it (the Nix sandbox has no network). Upstream pins the exact
# data revision via its flake.lock and points CCUSAGE_PRICING_JSON_PATH at it;
# we mirror that revision here so the build is offline, reproducible, and
# byte-identical to what upstream ships.
#
# Both values below are kept in sync with the package version by
# passthru.updateScript — do not edit them by hand.
litellmPricingRev = "49ca04d8c3ddea336237ce6f3082dbc26d19e944";
litellmPricingHash = "sha256-rkUyugxdoD7WlPN//6BQpl4OJQuBbc20db7gt7exqpc=";
# ccusage embeds the LiteLLM model-pricing table at build time. Its build
# script otherwise downloads this file from the network, which fails in the
# sandbox. Upstream pins the data via a flake input and points
# CCUSAGE_PRICING_JSON_PATH at it; mirror that exact revision here so the
# build is offline and reproducible (see package.nix + flake.lock in the
# upstream repo at tag v20.0.6). Bump this revision together with the package
# version; nix-update only refreshes the src and cargo hashes.
litellmPricing = fetchurl {
url = "https://raw.githubusercontent.com/BerriAI/litellm/${litellmPricingRev}/model_prices_and_context_window.json";
hash = litellmPricingHash;
url = "https://raw.githubusercontent.com/BerriAI/litellm/f27df8d516802ce4c1b32973992154fe83b851cf/model_prices_and_context_window.json";
hash = "sha256-zJa6H2EwP9s+hMVs78Y+hwo4UX1dHRtvX5J3MdGh5aI=";
};
in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "ccusage";
version = "20.0.17";
version = "20.0.6";
src = fetchFromGitHub {
owner = "ccusage";
repo = "ccusage";
tag = "v${finalAttrs.version}";
hash = "sha256-486iLPRqQVRnKVbVT93D08RTRzd6/h503ckB//24nho=";
hash = "sha256-uf/FlPprxx4jh74YwjmYMtoIHpTkKrWTLetbNoYiFv4=";
};
# The Cargo workspace lives in rust/, not at the repo root.
cargoRoot = "rust";
buildAndTestSubdir = "rust";
cargoHash = "sha256-23l/BCCGcZ1i5mFBC6Q+FE7sQRHnPLbU4QoQe7TfoiQ=";
cargoHash = "sha256-izA2Gs5nPmt0zn6/e1xM80vyyQHYKGEUDpUFRpyFiB8=";
__structuredAttrs = true;
strictDeps = true;
@@ -77,40 +72,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
doInstallCheck = true;
passthru = {
# Plain nix-update only refreshes version + src/cargo hashes; it can't know
# about the LiteLLM pricing pin above. This wrapper bumps the package as
# usual, then reads the litellm revision that ccusage locks at the new tag
# and rewrites litellmPricingRev/litellmPricingHash to match, so automated
# (r-ryantm) bumps stay complete instead of shipping stale pricing data.
updateScript = lib.getExe (writeShellApplication {
name = "ccusage-update";
runtimeInputs = [
curl
jq
nix-update
];
text = ''
set -euo pipefail
attr="''${UPDATE_NIX_ATTR_PATH:-ccusage}"
nix-update "$attr"
version=$(nix-instantiate --eval --raw -A "$attr.version")
rev=$(curl --fail --silent --show-error --location \
"https://raw.githubusercontent.com/ccusage/ccusage/v''${version}/flake.lock" \
| jq --raw-output '.nodes.litellm.locked.rev')
hash=$(nix-prefetch-url --type sha256 \
"https://raw.githubusercontent.com/BerriAI/litellm/''${rev}/model_prices_and_context_window.json" \
| xargs nix --extra-experimental-features nix-command hash convert --hash-algo sha256 --to sri)
file=$(nix-instantiate --eval --raw -A "$attr.meta.position" | sed -re 's/:[0-9]+$//')
sed -i \
-e "s|litellmPricingRev = \"[0-9a-f]*\"|litellmPricingRev = \"''${rev}\"|" \
-e "s|litellmPricingHash = \"sha256-[^\"]*\"|litellmPricingHash = \"''${hash}\"|" \
"$file"
'';
});
updateScript = nix-update-script { };
tests = {
# With no agent data on disk, ccusage must still emit a valid, empty JSON

View File

@@ -1,47 +1,47 @@
{
"version": "2.1.219",
"commit": "7006c4c3acac98e554d3997baeda6a7fa4d1ff7c",
"buildDate": "2026-07-24T03:34:26Z",
"version": "2.1.218",
"commit": "bce61b433bc397ce68686368abd12f545b0a013a",
"buildDate": "2026-07-22T18:42:19Z",
"platforms": {
"darwin-arm64": {
"binary": "claude",
"checksum": "a8e806faaefac53c7a0f26523d8a45c60dbef3407b14ef990c75765d08febc82",
"size": 256908272
"checksum": "71abaff59312c9a9b6a1d818365048b42e4e95cc521a823660eded3e0880d9b7",
"size": 255069680
},
"darwin-x64": {
"binary": "claude",
"checksum": "03be9f988ed88391b4a5f08e4c5dc317ce2fffa4a9dc66c01106326e7698ee76",
"size": 266381200
"checksum": "9862b74a083e8a4ed572f99cbd4895185e0dd5a0a601affb0fb8e43d8d1f40e6",
"size": 264548368
},
"linux-arm64": {
"binary": "claude",
"checksum": "1f834b322ba9d1291cc7ffeff16a6795a59145bda279dbd59cd7ecebc7b7f15a",
"size": 271825824
"checksum": "295fd30481bd03b38450fdec2a6e25bb6472c2074f04b0c4a566cd5988f230bf",
"size": 269990816
},
"linux-x64": {
"binary": "claude",
"checksum": "22cfd6f5b3061c0391ba84e9cf8c9deaa37783aac18b004d42ec061e98f00691",
"size": 275004400
"checksum": "e12071751a9336b8af1012c103358ff04ac18f9aaff4a738cff7ba5cdfaf63f2",
"size": 273177584
},
"linux-arm64-musl": {
"binary": "claude",
"checksum": "22b2c2e0f41ab0b7c7b8845be9c49fe6f27e4c344aab1bd174bdf84a4e6b0570",
"size": 265074024
"checksum": "efcaae48f8f537a0e9a47b4317a5f8c184706c99ddd8ca0a9a21391e2a766ef8",
"size": 263239016
},
"linux-x64-musl": {
"binary": "claude",
"checksum": "487008769dd69599adb779205b6b371de27b4245f0ad2ad70f15baf4eac5f81e",
"size": 269627984
"checksum": "62986293277153f5db97404cf7e3e96de136f02c28f79ccd5c7bc99766224db4",
"size": 267801168
},
"win32-x64": {
"binary": "claude.exe",
"checksum": "10f4c1f85b07f3cf6b8fff930fd26ecd475bd146a378acfafa559a6db9d89637",
"size": 265714848
"checksum": "81fcf59bb7abb558aedc6f2361f4723b3d757d28e799962d88b18b4520df66ca",
"size": 263931552
},
"win32-arm64": {
"binary": "claude.exe",
"checksum": "6a1db10161b93e81ac55537feeae8a299f0bf67601c1c0f2016e79c850302baa",
"size": 260090016
"checksum": "a7959fd87feb9557d56f4e5752f7ed1ddf405f3bea91b2571bf93af636efd193",
"size": 258307232
}
},
"sdkCompat": {
@@ -68,8 +68,7 @@
"0.3.208",
"0.3.209",
"0.3.215",
"0.3.217",
"0.3.218"
"0.3.217"
],
"harnessSchema": 1
}

View File

@@ -16,11 +16,11 @@
socat,
versionCheckHook,
writableTmpDirAsHomeHook,
manifest ? lib.importJSON ./manifest.json,
}:
let
stdenv = stdenvNoCC;
baseUrl = "https://downloads.claude.ai/claude-code-releases";
manifest = lib.importJSON ./manifest.json;
platformKey = "${stdenv.hostPlatform.node.platform}-${stdenv.hostPlatform.node.arch}";
platformManifestEntry = manifest.platforms.${platformKey};
in

View File

@@ -9,13 +9,13 @@
buildGoModule (finalAttrs: {
pname = "cloudflared";
version = "2026.7.3";
version = "2026.7.2";
src = fetchFromGitHub {
owner = "cloudflare";
repo = "cloudflared";
tag = finalAttrs.version;
hash = "sha256-hIDx9Nd7CKlM0vCKqkVHxBMj4QzvnnsYYMjhzOqcECU=";
hash = "sha256-fuJfvm5c63koMl46sJmZOiWuNKpOwH17MD20XD7q6s0=";
};
vendorHash = null;

View File

@@ -11,17 +11,17 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "communique";
version = "1.2.3";
version = "1.2.1";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "jdx";
repo = "communique";
tag = "v${finalAttrs.version}";
hash = "sha256-F7m6PxPOuQlZFIVYBUl650JsaZVJJmC1c+6jMgmGgc8=";
hash = "sha256-lQN6LViO3Ta6eCbU6j76OFN95R6A0hP3Pfc38KrHDng=";
};
cargoHash = "sha256-KyGbkVNi2rHTJfIeeq6nVFDhkWmaKh/IZ6xiVxPaXWQ=";
cargoHash = "sha256-RJzjpDhxpi7Zmzw9kl48yq6//zTYOeJ+SrgAfqq/tl4=";
nativeCheckInputs = [
cacert

View File

@@ -24,13 +24,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "cubeb";
version = "0-unstable-2026-07-25";
version = "0-unstable-2026-07-16";
src = fetchFromGitHub {
owner = "mozilla";
repo = "cubeb";
rev = "ef47ae581df7c2f76058d554b3edde17f9ee7cba";
hash = "sha256-vGTB0xsIv89ua9tltdjkxLChVvTKra4kxaWCxszG3x0=";
rev = "0942f635f78049fc8af24939effed255ae0d0044";
hash = "sha256-RQqmrRXRABsNDjGztsLLjsZlZFBEeAAc/ysoDj6CT1A=";
};
outputs = [

View File

@@ -8,11 +8,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "cutemaze";
version = "1.3.7";
version = "1.3.6";
src = fetchurl {
url = "https://gottcode.org/cutemaze/cutemaze-${finalAttrs.version}.tar.bz2";
hash = "sha256-iaT55oVw5j3ttAiWW5y6QlQDsoUKRppDtNSLKUBNr2E=";
hash = "sha256-Fl/fsKB04Kn4HwkNlpcuR3wTJFfn1gGgRGTwRUNDawY=";
};
nativeBuildInputs = [

View File

@@ -56,7 +56,7 @@ let
davinci = (
stdenv.mkDerivation rec {
pname = "davinci-resolve${lib.optionalString studioVariant "-studio"}";
version = "21.0.3";
version = "21.0.1";
nativeBuildInputs = [
appimageTools.appimage-exec
@@ -78,9 +78,9 @@ let
outputHashAlgo = "sha256";
outputHash =
if studioVariant then
"sha256-pEJF+FQlBngEi5YlKq/pFNCzBiQgqjQrTnfrlKEEi6s="
"sha256-8JN3ptd8jcacxHihZHXuhdkyambUsnFIj+AruvpztKI="
else
"sha256-3SymaLm3ibyk8yOWcUS9fOfnKEmgVA5XXc5tls27qfo=";
"sha256-ioAqvqHjwFX1ec6fDoxg2VUZy1moYoGx/aEewDuN1+g=";
impureEnvVars = lib.fetchers.proxyImpureEnvVars;

View File

@@ -19,7 +19,7 @@
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "dbeaver-bin";
version = "26.1.3";
version = "26.1.1";
src =
let
@@ -31,9 +31,9 @@ stdenvNoCC.mkDerivation (finalAttrs: {
aarch64-darwin = "macos-aarch64.dmg";
};
hash = selectSystem {
x86_64-linux = "sha256-cPRmReV6F+pCkrbF7d1m+bQjOaJCCFndNSThMWPGrsY=";
aarch64-linux = "sha256-bT1bCKzeiAMJbPa6I6fqQq7OrbkKhgDYAUEKuURHP5g=";
aarch64-darwin = "sha256-NYX651gUpEDh2O720ZKl7fUTYLFKpTJzyC/YnN4Vnys=";
x86_64-linux = "sha256-atbQ00lq589FlNem85NgzTKGyhTRpFII8OSfVfYQuD0=";
aarch64-linux = "sha256-Sde0q31hXMqX2oxfhgj5EcpeUYYFZJy61usaJVpZkLM=";
aarch64-darwin = "sha256-PwuFwEE+aBEG/ykwNrEBl20yfrade8BdUUHdLJGBkwc=";
};
in
fetchurl {

View File

@@ -33,7 +33,7 @@ let
in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "deno";
version = "2.9.4";
version = "2.9.3";
__structuredAttrs = true;
@@ -47,10 +47,10 @@ rustPlatform.buildRustPackage (finalAttrs: {
repo = "deno";
tag = "v${finalAttrs.version}";
fetchSubmodules = true; # required for tests
hash = "sha256-ivch++yGRUyWtox/5QqomC4DlTvMBxK+gIcN9/7tt5E=";
hash = "sha256-XMHlWK+lhyn1KO1CSxcuM3KzTjYviVrRw+FUL74bBPc=";
};
cargoHash = "sha256-ynbHLZXkPPYpsC4dCu6jA6x8ftiTHWZ/uxzdbUcUaa0=";
cargoHash = "sha256-WZxyoD9WMnaLyD3/86R90KWC+9OA15fIMw8SjmovNHA=";
patches = [
./patches/0002-tests-replace-hardcoded-paths.patch
@@ -211,8 +211,6 @@ rustPlatform.buildRustPackage (finalAttrs: {
++ lib.optionals stdenv.hostPlatform.isLinux [
# Wants to access /etc/resolv.conf: https://github.com/hickory-dns/hickory-dns/issues/2959
"--skip=tests::test_userspace_resolver"
# We don't have a tmp dir with sticky bit during build
"--skip=util::temp::test::test_ensure_secure_temp_parent_rejects_non_sticky_writable_dir"
];
__darwinAllowLocalNetworking = true;

View File

@@ -1,16 +0,0 @@
Submodule build contains modified content
diff --git a/build/config/compiler/BUILD.gn b/build/config/compiler/BUILD.gn
index 11ddb4916..0bd001600 100644
--- a/build/config/compiler/BUILD.gn
+++ b/build/config/compiler/BUILD.gn
@@ -2827,10 +2827,6 @@ config("split_dwarf") {
# thinlto requires -gsplit-dwarf in ldflags.
if (use_thin_lto && !is_apple) {
ldflags = split_dwarf_flags
- } else {
- # .dwo files are generated when ThinLTO is not used.
- c_additional_outputs =
- [ "{{target_out_dir}}/{{label_name}}/{{source_name_part}}.dwo" ]
}
}

View File

@@ -71,27 +71,26 @@ let
in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "rusty-v8";
version = "150.2.0";
version = "149.4.0";
src = fetchFromGitHub {
owner = "denoland";
repo = "rusty_v8";
tag = "v${finalAttrs.version}";
fetchSubmodules = true;
hash = "sha256-Iwgc08bUHR4OiwqopJua6fkQYMOdC5k9TgoCmZQrWIw=";
hash = "sha256-n4dKtki9ov0lWBeLmMDI4Tpk8zQ8YYSf04QW6DTYisY=";
};
patches = [
./librusty_v8_no_downloads.patch
./llvm22.patch
./gn_inputs_fix.patch
./c_additional_outputs.patch
]
++ lib.optionals stdenv.targetPlatform.isDarwin [
./librusty_v8-darwin-fix-__rust_no_alloc_shim_is_unstable_v2.patch
];
cargoHash = "sha256-M65ODvL+o3njO3SdbJaCvgRupoguCGCIoYY/dYiJPng=";
cargoHash = "sha256-bGqg/6sfBaF/JpObgXyP4Mh+4P9zfuzd454m4wjluGw=";
nativeBuildInputs = [
llvmPackages.clang

View File

@@ -8,17 +8,15 @@
buildGoModule (finalAttrs: {
pname = "diffyml";
version = "1.7.1";
version = "1.7.0";
__structuredAttrs = true;
__darwinAllowLocalNetworking = true;
src = fetchFromGitHub {
owner = "szhekpisov";
repo = "diffyml";
tag = "v${finalAttrs.version}";
hash = "sha256-bfFerbjpwQuTCnGKfqUj3ydf1xBdNoP+qH7UTmtZvTk=";
hash = "sha256-DIKHvFY/eW3CAF/ojW+D737vFCcZk0peRrSb8I/an9Q=";
};
vendorHash = "sha256-QE/EwVzMqUO24ZAl0WBibGx6x0kNo1AUTZtfnQvX50k=";

View File

@@ -20,13 +20,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "diodon";
version = "1.14.0";
version = "1.13.0";
src = fetchFromGitHub {
owner = "diodon-dev";
repo = "diodon";
tag = finalAttrs.version;
hash = "sha256-lcDJe9uJeDPtVBwh3QzQdRX4/exOl6gLStpQxLiT10M=";
hash = "sha256-VCJANasrGmC0jIy8JNNURvmgpL/SLOaVsKo7Pf+X8DQ=";
};
strictDeps = true;

Some files were not shown because too many files have changed in this diff Show More