staging-nixos merge for 2025-10-15 (#452239)
This commit is contained in:
@@ -219,6 +219,10 @@ let
|
||||
replaceDefaultConfig "11-lcdfilter-default.conf" "11-lcdfilter-${cfg.subpixel.lcdfilter}.conf"
|
||||
)}
|
||||
|
||||
${lib.optionalString cfg.allowBitmaps ''
|
||||
rm -f $dst/70-no-bitmaps-except-emoji.conf
|
||||
''}
|
||||
|
||||
# 00-nixos-cache.conf
|
||||
ln -s ${cacheConf} $dst/00-nixos-cache.conf
|
||||
|
||||
|
||||
@@ -32,12 +32,8 @@
|
||||
boot.kexec.enable = lib.mkDefault false;
|
||||
# Relies on bash scripts
|
||||
powerManagement.enable = lib.mkDefault false;
|
||||
# Has some bash inside
|
||||
systemd.shutdownRamfs.enable = lib.mkDefault false;
|
||||
# Relies on the gzip command which depends on bash
|
||||
services.logrotate.enable = lib.mkDefault false;
|
||||
# Service relies on bash scripts
|
||||
services.timesyncd.enable = lib.mkDefault false;
|
||||
|
||||
# Check that the system does not contain a Nix store path that contains the
|
||||
# string "bash".
|
||||
|
||||
@@ -17,6 +17,7 @@ in
|
||||
enable = lib.mkEnableOption "pivoting back to an initramfs for shutdown" // {
|
||||
default = true;
|
||||
};
|
||||
|
||||
contents = lib.mkOption {
|
||||
description = "Set of files that have to be linked into the shutdown ramfs";
|
||||
example = lib.literalExpression ''
|
||||
@@ -34,6 +35,22 @@ in
|
||||
type = utils.systemdUtils.types.initrdStorePath;
|
||||
default = [ ];
|
||||
};
|
||||
|
||||
shell.enable = lib.mkEnableOption "" // {
|
||||
default = config.environment.shell.enable;
|
||||
internal = true;
|
||||
description = ''
|
||||
Whether to enable a shell in the shutdown ramfs.
|
||||
|
||||
In contrast to `environment.shell.enable`, this option actually
|
||||
strictly disables all shells in the shutdown ramfs because they're not
|
||||
copied into it anymore. Paths that use a shell (e.g. via the `script`
|
||||
option), will break if this option is set.
|
||||
|
||||
Only set this option if you're sure that you can recover from potential
|
||||
issues.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
@@ -43,9 +60,11 @@ in
|
||||
"/etc/os-release".source = config.environment.etc.os-release.source;
|
||||
};
|
||||
systemd.shutdownRamfs.storePaths = [
|
||||
pkgs.runtimeShell
|
||||
"${pkgs.coreutils}/bin"
|
||||
]
|
||||
++ lib.optionals cfg.shell.enable [
|
||||
pkgs.runtimeShell
|
||||
]
|
||||
++ map (c: builtins.removeAttrs c [ "text" ]) (builtins.attrValues cfg.contents);
|
||||
|
||||
systemd.mounts = [
|
||||
@@ -71,9 +90,21 @@ in
|
||||
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
ExecStart = "${pkgs.makeInitrdNGTool}/bin/make-initrd-ng ${ramfsContents} /run/initramfs";
|
||||
|
||||
# Sandboxing
|
||||
ProtectSystem = "strict";
|
||||
ReadWritePaths = "/run/initramfs";
|
||||
ExecStart = "${pkgs.makeInitrdNGTool}/bin/make-initrd-ng ${ramfsContents} /run/initramfs";
|
||||
ProtectHome = true;
|
||||
ProtectHostname = true;
|
||||
ProtectClock = true;
|
||||
ProtectKernelTunables = true;
|
||||
ProtectKernelModules = true;
|
||||
ProtectKernelLogs = true;
|
||||
ProtectControlGroups = true;
|
||||
PrivateNetwork = true;
|
||||
LockPersonality = true;
|
||||
MemoryDenyWriteExecute = true;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
@@ -19,6 +19,7 @@
|
||||
# work.
|
||||
environment.binsh = lib.mkForce null;
|
||||
boot.initrd.systemd.shell.enable = false;
|
||||
systemd.shutdownRamfs.shell.enable = false;
|
||||
|
||||
# This ensures that we only have the store paths of our closure in the
|
||||
# in the guest. This is necessary so we can grep in the store.
|
||||
@@ -31,6 +32,7 @@
|
||||
environment.systemPackages = [
|
||||
pkgs.coreutils
|
||||
pkgs.gnugrep
|
||||
pkgs.findutils
|
||||
];
|
||||
|
||||
# Unset the regex because the tests instrumentation needs bash.
|
||||
@@ -43,6 +45,12 @@
|
||||
with subtest("/bin/sh doesn't exist"):
|
||||
machine.fail("stat /bin/sh")
|
||||
|
||||
with subtest("shutdown ramfs is bashless"):
|
||||
machine.systemctl("start generate-shutdown-ramfs.service")
|
||||
shutdown_ramfs_bash_paths = machine.succeed("find /run/initramfs -type d,f -name '*bash*'")
|
||||
print(shutdown_ramfs_bash_paths)
|
||||
t.assertNotIn("bash", shutdown_ramfs_bash_paths)
|
||||
|
||||
bash_store_paths = machine.succeed("ls /nix/store | grep bash || true")
|
||||
print(bash_store_paths)
|
||||
'';
|
||||
|
||||
@@ -575,6 +575,7 @@ in
|
||||
fluent-bit = runTest ./fluent-bit.nix;
|
||||
fluentd = runTest ./fluentd.nix;
|
||||
fluidd = runTest ./fluidd.nix;
|
||||
fontconfig-bitmap-fonts = runTest ./fontconfig-bitmap-fonts.nix;
|
||||
fontconfig-default-fonts = runTest ./fontconfig-default-fonts.nix;
|
||||
forgejo = import ./forgejo.nix {
|
||||
inherit runTest;
|
||||
|
||||
@@ -0,0 +1,17 @@
|
||||
{ lib, ... }:
|
||||
{
|
||||
name = "fontconfig-bitmap-fonts";
|
||||
|
||||
nodes.machine =
|
||||
{ config, pkgs, ... }:
|
||||
{
|
||||
fonts.packages = [
|
||||
pkgs.terminus_font
|
||||
];
|
||||
fonts.fontconfig.allowBitmaps = true;
|
||||
};
|
||||
|
||||
testScript = ''
|
||||
machine.succeed("fc-list | grep Terminus")
|
||||
'';
|
||||
}
|
||||
@@ -52,10 +52,7 @@ in
|
||||
|
||||
## 1. Patches relevant on every platform ####################################
|
||||
|
||||
[ ]
|
||||
# Pass the path to a C++ compiler directly in the Makefile.in
|
||||
++ optional (!lib.systems.equals targetPlatform hostPlatform) ./libstdc++-target.patch
|
||||
++ optionals noSysDirs (
|
||||
optionals noSysDirs (
|
||||
[
|
||||
# Do not try looking for binaries and libraries in /lib and /usr/lib
|
||||
./gcc-12-no-sys-dirs.patch
|
||||
|
||||
@@ -1,32 +0,0 @@
|
||||
Patch to make the target libraries 'configure' scripts find the proper CPP.
|
||||
I noticed that building the mingw32 cross compiler.
|
||||
Looking at the build script for mingw in archlinux, I think that only nixos
|
||||
needs this patch. I don't know why.
|
||||
diff --git a/Makefile.in b/Makefile.in
|
||||
index 93f66b6..d691917 100644
|
||||
--- a/Makefile.in
|
||||
+++ b/Makefile.in
|
||||
@@ -266,6 +266,7 @@ BASE_TARGET_EXPORTS = \
|
||||
AR="$(AR_FOR_TARGET)"; export AR; \
|
||||
AS="$(COMPILER_AS_FOR_TARGET)"; export AS; \
|
||||
CC="$(CC_FOR_TARGET) $(XGCC_FLAGS_FOR_TARGET) $$TFLAGS"; export CC; \
|
||||
+ CPP="$(CC_FOR_TARGET) $(XGCC_FLAGS_FOR_TARGET) $$TFLAGS -E"; export CC; \
|
||||
CFLAGS="$(CFLAGS_FOR_TARGET)"; export CFLAGS; \
|
||||
CONFIG_SHELL="$(SHELL)"; export CONFIG_SHELL; \
|
||||
CPPFLAGS="$(CPPFLAGS_FOR_TARGET)"; export CPPFLAGS; \
|
||||
@@ -291,11 +292,13 @@ BASE_TARGET_EXPORTS = \
|
||||
RAW_CXX_TARGET_EXPORTS = \
|
||||
$(BASE_TARGET_EXPORTS) \
|
||||
CXX_FOR_TARGET="$(RAW_CXX_FOR_TARGET)"; export CXX_FOR_TARGET; \
|
||||
- CXX="$(RAW_CXX_FOR_TARGET) $(XGCC_FLAGS_FOR_TARGET) $$TFLAGS"; export CXX;
|
||||
+ CXX="$(RAW_CXX_FOR_TARGET) $(XGCC_FLAGS_FOR_TARGET) $$TFLAGS"; export CXX; \
|
||||
+ CXXCPP="$(RAW_CXX_FOR_TARGET) $(XGCC_FLAGS_FOR_TARGET) $$TFLAGS -E"; export CXX;
|
||||
|
||||
NORMAL_TARGET_EXPORTS = \
|
||||
$(BASE_TARGET_EXPORTS) \
|
||||
- CXX="$(CXX_FOR_TARGET) $(XGCC_FLAGS_FOR_TARGET) $$TFLAGS"; export CXX;
|
||||
+ CXX="$(CXX_FOR_TARGET) $(XGCC_FLAGS_FOR_TARGET) $$TFLAGS"; export CXX; \
|
||||
+ CXXCPP="$(CXX_FOR_TARGET) $(XGCC_FLAGS_FOR_TARGET) $$TFLAGS -E"; export CXX;
|
||||
|
||||
# Where to find GMP
|
||||
HOST_GMPLIBS = @gmplibs@
|
||||
@@ -550,7 +550,7 @@ let
|
||||
DRM_AMD_ISP = whenAtLeast "6.11" yes;
|
||||
|
||||
# Enable new firmware (and by extension NVK) for compatible hardware on Nouveau
|
||||
DRM_NOUVEAU_GSP_DEFAULT = whenAtLeast "6.8" yes;
|
||||
DRM_NOUVEAU_GSP_DEFAULT = whenBetween "6.8" "6.18" yes;
|
||||
|
||||
# Enable Nouveau shared virtual memory (used by OpenCL)
|
||||
DEVICE_PRIVATE = whenHasDevicePrivate yes;
|
||||
@@ -568,6 +568,11 @@ let
|
||||
# Intel GVT-g graphics virtualization supports 64-bit only
|
||||
DRM_I915_GVT = yes;
|
||||
DRM_I915_GVT_KVMGT = module;
|
||||
# Enable Hyper-V guest stuff
|
||||
HYPERV = lib.mkMerge [
|
||||
(whenOlder "6.18" module)
|
||||
(whenAtLeast "6.18" yes)
|
||||
];
|
||||
# Enable Hyper-V Synthetic DRM Driver
|
||||
DRM_HYPERV = whenAtLeast "5.14" module;
|
||||
# And disable the legacy framebuffer driver when we have the new one
|
||||
@@ -683,8 +688,8 @@ let
|
||||
EXT2_FS_POSIX_ACL = yes;
|
||||
EXT2_FS_SECURITY = yes;
|
||||
|
||||
EXT3_FS_POSIX_ACL = yes;
|
||||
EXT3_FS_SECURITY = yes;
|
||||
EXT3_FS_POSIX_ACL = option yes;
|
||||
EXT3_FS_SECURITY = option yes;
|
||||
|
||||
EXT4_FS_POSIX_ACL = yes;
|
||||
EXT4_FS_SECURITY = yes;
|
||||
@@ -1020,7 +1025,7 @@ let
|
||||
ZRAM_DEF_COMP_ZSTD = whenAtLeast "5.11" yes;
|
||||
ZSWAP = option yes;
|
||||
ZSWAP_COMPRESSOR_DEFAULT_ZSTD = whenAtLeast "5.7" (lib.mkOptionDefault yes);
|
||||
ZPOOL = yes;
|
||||
ZPOOL = whenOlder "6.18" yes;
|
||||
ZSMALLOC = option yes;
|
||||
};
|
||||
|
||||
@@ -1085,6 +1090,8 @@ let
|
||||
HID_BATTERY_STRENGTH = yes;
|
||||
# enabled by default in x86_64 but not arm64, so we do that here
|
||||
HIDRAW = yes;
|
||||
# 6.18-rc1 fails to link otherwise, at least on aarch64
|
||||
HID_HAPTIC = whenAtLeast "6.18" yes;
|
||||
|
||||
# Enable loading HID fixups as eBPF from userspace
|
||||
HID_BPF = whenAtLeast "6.3" (whenPlatformHasEBPFJit yes);
|
||||
|
||||
@@ -1,12 +1,12 @@
|
||||
{
|
||||
"testing": {
|
||||
"version": "6.17-rc7",
|
||||
"hash": "sha256:11bjz14ncfbnz3h9a4vk71av664xrx1kh28i22w7yg6g46hifq65",
|
||||
"version": "6.18-rc1",
|
||||
"hash": "sha256:1warfcvr86as1rcls3g5f9i4az6xqabjwmf6jxlx9dk2l523sl1l",
|
||||
"lts": false
|
||||
},
|
||||
"6.1": {
|
||||
"version": "6.1.155",
|
||||
"hash": "sha256:0wsw99h2jsrcx9fff59nqjx66l40vywj8qi3j6yvqpq8xsp8g4y2",
|
||||
"version": "6.1.156",
|
||||
"hash": "sha256:13i2l04pmba7dksz2p5kwxgr5bydc5lp7284d4wfsnjf425i9fyl",
|
||||
"lts": true
|
||||
},
|
||||
"5.15": {
|
||||
@@ -25,13 +25,13 @@
|
||||
"lts": true
|
||||
},
|
||||
"6.6": {
|
||||
"version": "6.6.111",
|
||||
"hash": "sha256:1is6nrm5x54bw8zn8l5akp8ign185i19biks442yynfn63hp1i04",
|
||||
"version": "6.6.112",
|
||||
"hash": "sha256:08la2f8w5w2x0l9nmvzsmbwa951xyshhvdhwwhfyjmka66zr4zbc",
|
||||
"lts": true
|
||||
},
|
||||
"6.12": {
|
||||
"version": "6.12.52",
|
||||
"hash": "sha256:1ccyd9h9i3xia1gqq0mggis5yv04c9ys44xp707wfcm0f3v0r1dl",
|
||||
"version": "6.12.53",
|
||||
"hash": "sha256:1df0sahirxsby2imsbi04vcn2bimskl4l2r19v7sywz6ran0fdb6",
|
||||
"lts": true
|
||||
},
|
||||
"6.16": {
|
||||
@@ -40,8 +40,8 @@
|
||||
"lts": false
|
||||
},
|
||||
"6.17": {
|
||||
"version": "6.17.2",
|
||||
"hash": "sha256:0zzmcjkmxmcn45y20g8hz7dxs355rmczp9k8vjwc3xb5a03cpszx",
|
||||
"version": "6.17.3",
|
||||
"hash": "sha256:16cld01iwn6hhayxh6f0z71rph0z3p3m4bsd49szddd5v0cqdk1y",
|
||||
"lts": false
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user