Merge staging-next into staging

This commit is contained in:
nixpkgs-ci[bot]
2026-02-16 10:40:28 +00:00
committed by GitHub
65 changed files with 788 additions and 408 deletions
+11
View File
@@ -11111,6 +11111,12 @@
githubId = 7481521;
name = "Balázs Lengyel";
};
ilai-deutel = {
github = "ilai-deutel";
githubId = 10098207;
name = "Ilaï Deutel";
keys = [ { fingerprint = "1025 8841 8FF7 E165 6964 90A2 06E8 A973 4948 08A2"; } ];
};
ilarvne = {
email = "ilarvne@proton.me";
github = "ilarvne";
@@ -14433,6 +14439,11 @@
githubId = 629430;
keys = [ { fingerprint = "2843 750C B1AB E256 94BE 40E2 D843 D30B 42CA 0E2D"; } ];
};
kulczwoj = {
name = "Wojciech Kulczycki";
github = "kulczwoj";
githubId = 58049191;
};
KunyaKud = {
name = "KunyaKud";
email = "wafuu@posteo.net";
+30 -6
View File
@@ -62,6 +62,19 @@ in
config = lib.mkIf cfg.enable {
warnings = lib.optional (cfg.powerUpCommands != "") ''
powerManagement.powerUpCommands is deprecated due to it having unclear ordering semantics.
It will be removed in NixOS 26.11.
It is recommended to create an explicit systemd oneshot service instead,
that is pulled in at the right time during the boot process.
See https://www.freedesktop.org/software/systemd/man/latest/systemd.special.html
for more information on possible targets that can be used for this.
If you also want to run this service upon waking up from resume, the recommended
method to do so is described here:
https://www.freedesktop.org/software/systemd/man/latest/systemd.special.html#sleep.target
'';
systemd.targets.post-resume = {
description = "Post-Resume Actions";
requires = [ "post-resume.service" ];
@@ -81,14 +94,25 @@ in
serviceConfig.Type = "oneshot";
};
systemd.services.post-boot = {
description = "Post-boot Actions";
# It's not well defined at what point in the bootup sequence this should run
# we should eventually just remove this.
wantedBy = [ "multi-user.target" ];
restartIfChanged = false;
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
};
script = ''
${cfg.powerUpCommands}
'';
};
systemd.services.post-resume = {
description = "Post-Resume Actions";
after = [
"suspend.target"
"hibernate.target"
"hybrid-sleep.target"
"suspend-then-hibernate.target"
];
# Pulled in by post-resume.service above
after = [ "sleep.target" ];
script = ''
/run/current-system/systemd/bin/systemctl try-restart --no-block post-resume.target
${cfg.resumeCommands}
@@ -742,6 +742,8 @@ in
};
systemd = {
generatorPath = [ cfg.package ];
sockets.sshd = lib.mkIf cfg.startWhenNeeded {
description = "SSH Socket";
wantedBy = [ "sockets.target" ];
@@ -58,10 +58,6 @@ in
assertion = config.boot.postBootCommands == "";
message = "nixos-init cannot be used with boot.postBootCommands";
}
{
assertion = config.powerManagement.powerUpCommands == "";
message = "nixos-init cannot be used with powerManagement.powerUpCommands";
}
];
})
];
-1
View File
@@ -30,7 +30,6 @@ let
);
postBootCommands = pkgs.writeText "local-cmds" ''
${config.boot.postBootCommands}
${config.powerManagement.powerUpCommands}
'';
};
};
+41 -6
View File
@@ -233,6 +233,8 @@ let
proxy_env = config.networking.proxy.envVars;
json = pkgs.formats.json { };
in
{
@@ -356,6 +358,28 @@ in
'';
};
generatorEnvironment = mkOption {
type = types.attrsOf types.str;
default = { };
example = {
MY_VAR = "my-value";
};
description = ''
Environment variables for systemd generators.
The `PATH` environment variable is populated via `systemd.generatorPath`.
'';
};
generatorPath = mkOption {
type = types.listOf types.package;
default = [ ];
example = lib.literalExpression "[ pkgs.hello ]";
description = ''
Packages added to the `PATH` environment variable of all systemd generators.
'';
};
shutdown = mkOption {
type = types.attrsOf types.path;
default = { };
@@ -636,6 +660,12 @@ in
"systemd/user-preset/00-nixos.preset".text = ''
ignore *
'';
"systemd/generator-environment.json".source =
json.generate "systemd-generator-environment.json" cfg.generatorEnvironment;
"systemd/system-environment-generators/env-generator".source =
"${config.system.nixos-init.package}/bin/env-generator";
};
services.dbus.enable = true;
@@ -683,12 +713,7 @@ in
systemd.managerEnvironment = {
# Doesn't contain systemd itself - everything works so it seems to use the compiled-in value for its tools
# util-linux is needed for the main fsck utility wrapping the fs-specific ones
PATH = lib.makeBinPath (
config.system.fsPackages
++ [ cfg.package.util-linux ]
# systemd-ssh-generator needs sshd in PATH
++ lib.optional config.services.openssh.enable config.services.openssh.package
);
PATH = lib.makeBinPath (config.system.fsPackages ++ [ cfg.package.util-linux ]);
LOCALE_ARCHIVE = "/run/current-system/sw/lib/locale/locale-archive";
TZDIR = "/etc/zoneinfo";
# If SYSTEMD_UNIT_PATH ends with an empty component (":"), the usual unit load path will be appended to the contents of the variable
@@ -704,6 +729,16 @@ in
DefaultIPAccounting = lib.mkDefault true;
};
# These are needed for systemd-fstab-generator to schedule systemd-fsck@
# units.
systemd.generatorPath = config.system.fsPackages ++ [
cfg.package.util-linux
];
systemd.generatorEnvironment = {
PATH = lib.makeBinPath cfg.generatorPath;
};
system.requiredKernelConfig = map config.lib.kernelConfig.isEnabled [
"DEVTMPFS"
"CGROUPS"
@@ -92,6 +92,7 @@ let
# Declare root explicitly to avoid shellcheck warnings, it comes from the env
declare root
mkdir -p "$root/usr/bin"
mkdir -p "$root/etc" "$root/var/lib"
chmod 0755 "$root/etc" "$root/var/lib"
mkdir -p "$root/var/lib/private" "$root/root" /run/nixos-containers
+2 -3
View File
@@ -19,8 +19,6 @@ in
nodes.machine =
{ pkgs, ... }:
{
imports = lib.optionals (!systemdStage1) [ ./common/auto-format-root-device.nix ];
virtualisation = {
emptyDiskImages = [ 512 ];
useBootLoader = true;
@@ -30,7 +28,6 @@ in
# the new root device is /dev/vdb
# an empty 512MiB drive, containing no Nix store.
mountHostNixStore = true;
fileSystems."/".autoFormat = lib.mkIf systemdStage1 true;
};
boot.loader.systemd-boot.enable = true;
@@ -90,6 +87,8 @@ in
# Create encrypted volume
machine.wait_for_unit("multi-user.target")
machine.succeed("echo "" | cryptsetup luksFormat /dev/vdb --batch-mode")
machine.succeed("echo "" | cryptsetup luksOpen /dev/vdb cryptroot")
machine.succeed("mkfs.ext4 /dev/mapper/cryptroot")
machine.succeed("bootctl set-default nixos-generation-1-specialisation-boot-luks-wrong-keyfile.conf")
machine.succeed("sync")
machine.crash()
+5 -1
View File
@@ -5,7 +5,6 @@
nodes.machine =
{ pkgs, ... }:
{
imports = [ ./common/auto-format-root-device.nix ];
# Use systemd-boot
virtualisation = {
@@ -48,7 +47,12 @@
# Create encrypted volume
machine.wait_for_unit("multi-user.target")
machine.succeed("echo -n supersecret | cryptsetup luksFormat -q --iter-time=1 /dev/vdb -")
machine.succeed("echo -n supersecret | cryptsetup luksOpen -q /dev/vdb cryptroot")
machine.succeed("mkfs.ext4 /dev/mapper/cryptroot")
machine.succeed("echo -n supersecret | cryptsetup luksFormat -q --iter-time=1 /dev/vdc -")
machine.succeed("echo -n supersecret | cryptsetup luksOpen -q /dev/vdc cryptroot2")
machine.succeed("mkfs.ext4 /dev/mapper/cryptroot2")
# Boot from the encrypted disk
machine.succeed("bootctl set-default nixos-generation-1-specialisation-boot-luks.conf")
+5 -7
View File
@@ -1,6 +1,8 @@
{ lib, ... }:
let
name = "continuwuity";
user = "alice";
pass = "my-secret-password";
in
{
inherit name;
@@ -12,8 +14,7 @@ in
settings.global = {
server_name = name;
address = [ "0.0.0.0" ];
allow_registration = true;
yes_i_am_very_very_sure_i_want_an_open_registration_server_prone_to_abuse = true;
admin_execute = [ "users create ${user} ${pass}" ];
};
extraEnvironment.RUST_BACKTRACE = "yes";
};
@@ -30,13 +31,10 @@ in
async def main() -> None:
# Connect to continuwuity
client = nio.AsyncClient("http://continuwuity:6167", "alice")
# Register as user alice
response = await client.register("alice", "my-secret-password")
client = nio.AsyncClient("http://continuwuity:6167", "${user}")
# Log in as user alice
response = await client.login("my-secret-password")
response = await client.login("${pass}")
# Create a new room
response = await client.room_create(federate=False)
+2 -1
View File
@@ -38,7 +38,6 @@ in
};
};
virtualisation.rootDevice = "/dev/mapper/cryptroot";
virtualisation.fileSystems."/".autoFormat = true;
boot.initrd.secrets."/etc/cryptroot.key" = keyfile;
};
};
@@ -47,6 +46,8 @@ in
# Create encrypted volume
machine.wait_for_unit("multi-user.target")
machine.succeed("cryptsetup luksFormat -q --iter-time=1 -d ${keyfile} /dev/vdb")
machine.succeed("cryptsetup luksOpen --key-file ${keyfile} /dev/vdb cryptroot")
machine.succeed("mkfs.ext4 /dev/mapper/cryptroot")
# Boot from the encrypted disk
machine.succeed("bootctl set-default nixos-generation-1-specialisation-boot-luks.conf")
+4 -1
View File
@@ -31,7 +31,6 @@
cryptroot2.device = "/dev/vdc";
};
virtualisation.rootDevice = "/dev/mapper/cryptroot";
virtualisation.fileSystems."/".autoFormat = true;
# test mounting device unlocked in initrd after switching root
virtualisation.fileSystems."/cryptroot2".device = "/dev/mapper/cryptroot2";
};
@@ -40,7 +39,11 @@
testScript = ''
# Create encrypted volume
machine.wait_for_unit("multi-user.target")
machine.succeed("echo -n supersecret | cryptsetup luksFormat -q --iter-time=1 /dev/vdb -")
machine.succeed("echo -n supersecret | cryptsetup luksOpen -q /dev/vdb cryptroot")
machine.succeed("mkfs.ext4 /dev/mapper/cryptroot")
machine.succeed("echo -n supersecret | cryptsetup luksFormat -q --iter-time=1 /dev/vdc -")
machine.succeed("echo -n supersecret | cryptsetup luksOpen -q /dev/vdc cryptroot2")
machine.succeed("mkfs.ext4 /dev/mapper/cryptroot2")
+2 -1
View File
@@ -32,7 +32,6 @@
};
};
virtualisation.rootDevice = "/dev/mapper/cryptroot";
virtualisation.fileSystems."/".autoFormat = true;
};
};
@@ -40,6 +39,8 @@
# Create encrypted volume
machine.wait_for_unit("multi-user.target")
machine.succeed("echo -n supersecret | cryptsetup luksFormat -q --iter-time=1 /dev/vdb -")
machine.succeed("echo -n supersecret | cryptsetup luksOpen -q /dev/vdb cryptroot")
machine.succeed("mkfs.ext4 /dev/mapper/cryptroot")
machine.succeed("PASSWORD=supersecret SYSTEMD_LOG_LEVEL=debug systemd-cryptenroll --tpm2-pcrs= --tpm2-device=auto /dev/vdb |& systemd-cat")
# Boot from the encrypted disk
+4 -1
View File
@@ -79,9 +79,12 @@ in
};
testScript = ''
# Create encrypted volume
machine.wait_for_unit("multi-user.target")
machine.succeed("echo -n ${passphrase} | cryptsetup luksFormat -q --iter-time=1 /dev/vdb -")
machine.succeed("echo -n ${passphrase} | cryptsetup luksOpen -q /dev/vdb cryptroot")
machine.succeed("mkfs.ext4 /dev/mapper/cryptroot")
machine.succeed("echo -n ${passphrase} | cryptsetup luksFormat -q --iter-time=1 /dev/vdc -")
machine.succeed("echo -n ${passphrase} | cryptsetup luksOpen -q /dev/vdc cryptroot2")
machine.succeed("mkfs.ext4 /dev/mapper/cryptroot2")
+5
View File
@@ -19,6 +19,7 @@ in
nodes = {
virthost = {
environment.systemPackages = [ pkgs.jq ];
services.openssh = {
enable = true;
settings.PermitRootLogin = "prohibit-password";
@@ -48,6 +49,10 @@ in
virthost.succeed("cp '${snakeOilEd25519PrivateKey}' ~/.ssh/id_ed25519")
virthost.succeed("chmod 600 ~/.ssh/id_ed25519")
with subtest("Check the environment generator"):
print(virthost.succeed("jq '.' /etc/systemd/generator-environment.json"))
print(virthost.succeed("/etc/systemd/system-environment-generators/env-generator"))
with subtest("ssh into a container with AF_UNIX"):
virthost.wait_for_unit("container@guest.service")
virthost.wait_until_succeeds("ssh -i ~/.ssh/id_ed25519 unix/run/systemd/nspawn/unix-export/guest/ssh echo meow | grep meow")
@@ -0,0 +1,21 @@
{
lib,
vscode-utils,
}:
vscode-utils.buildVscodeMarketplaceExtension {
mktplcRef = {
name = "packaging";
publisher = "claui";
version = "0.2.5";
hash = "sha256-WGs00Q1oa8Nz9dpKn3iZSjrhR0VKUwJWPGdm+wWtoxs=";
};
meta = {
changelog = "https://github.com/claui/vscode-packaging/releases";
description = "Visual Studio Code extension for PKGBUILDs in the Arch User Repository (AUR)";
downloadPage = "https://marketplace.visualstudio.com/items?itemName=claui.packaging";
homepage = "https://github.com/claui/vscode-packaging";
license = lib.licenses.asl20;
maintainers = with lib.maintainers; [ ilai-deutel ];
};
}
@@ -989,6 +989,8 @@ let
};
};
claui.packaging = callPackage ./claui.packaging { };
cmschuetz12.wal = buildVscodeMarketplaceExtension {
mktplcRef = {
name = "wal";
@@ -2516,6 +2518,8 @@ let
};
};
jjk.jjk = callPackage ./jjk.jjk { };
jkillian.custom-local-formatters = buildVscodeMarketplaceExtension {
mktplcRef = {
publisher = "jkillian";
@@ -0,0 +1,21 @@
{
lib,
vscode-utils,
}:
vscode-utils.buildVscodeMarketplaceExtension {
mktplcRef = {
name = "jjk";
publisher = "jjk";
version = "0.8.1";
hash = "sha256-2JUn6wkWgZKZzhitQy6v9R/rCNLrt7DBtt59707hp6c=";
};
meta = {
changelog = "https://github.com/keanemind/jjk/releases";
description = "Visual Studio Code extension for the Jujutsu (jj) version control system";
downloadPage = "https://marketplace.visualstudio.com/items?itemName=jjk.jjk";
homepage = "https://github.com/keanemind/jjk";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [ ilai-deutel ];
};
}
@@ -7,8 +7,8 @@ vscode-utils.buildVscodeMarketplaceExtension {
mktplcRef = {
publisher = "sourcegraph";
name = "amp";
version = "0.0.1770596843";
hash = "sha256-FLajygfJM+EPOXSU7g5I7Yo1YU7zYvTuw2cfY3B17BE=";
version = "0.0.1771217285";
hash = "sha256-eTvkYFir8ZNNjWCaQ20WiJe/pJ8Gbtqvx74dq9S9Llw=";
};
meta = {
@@ -5,13 +5,13 @@
}:
mkLibretroCore {
core = "fbneo";
version = "0-unstable-2026-02-08";
version = "0-unstable-2026-02-15";
src = fetchFromGitHub {
owner = "libretro";
repo = "fbneo";
rev = "e21e3f3c40eb4422b93b8984ef46fe04cdaee9db";
hash = "sha256-7hZ2TJwHtgyHd+CZahazXZnKhfNpWZqfev9jtTHlmag=";
rev = "946de34101cd59701d66a8d2ec38394a6057740f";
hash = "sha256-Alzl84MAkSAr8CkqursthVc1eWn7McsNangjxFAaAQA=";
};
makefile = "Makefile";
@@ -48,6 +48,7 @@ let
apparmorRules = apparmorRulesFromClosure { name = "transmission-daemon"; } (
[
crc32c
curl
libdeflate
libevent
@@ -136,11 +136,11 @@ stdenv.mkDerivation (finalAttrs: {
+ lib.optionalString nixosTestRunner "-for-vm-tests"
+ lib.optionalString toolsOnly "-utils"
+ lib.optionalString userOnly "-user";
version = "10.2.0";
version = "10.2.1";
src = fetchurl {
url = "https://download.qemu.org/qemu-${finalAttrs.version}.tar.xz";
hash = "sha256-njCtG4ufe0RjABWC0aspfznPzOpdCFQMDKbWZyeFiDo=";
hash = "sha256-o3F0d9jiyE1jC//7wg9s0yk+tFqh5trG0MwnaJmRyeE=";
};
depsBuildBuild = [
@@ -267,50 +267,6 @@ stdenv.mkDerivation (finalAttrs: {
sha256 = "sha256-oC+bRjEHixv1QEFO9XAm4HHOwoiT+NkhknKGPydnZ5E=";
revert = true;
})
# Implement termios2 (TCGETS2 etc) for glibc 2.42 compatibility. Should be in the next release.
# https://gitlab.com/qemu-project/qemu/-/issues/3065
# https://lore.kernel.org/qemu-devel/20260103153239.15787-1-dilfridge@gentoo.org/t/#u
(fetchpatch {
name = "0001-Add-termios2-support-to-linux-user.patch";
url = "https://gitlab.com/qemu-project/qemu/-/commit/e9a8a10e84c1bf6e2e8be000e4dd5c83ba0d8470.patch";
hash = "sha256-Zc+ZjiSug3uT/F7+mmoYc2VXqw2MV6UubYqB+pr2dNY=";
})
(fetchpatch {
name = "0002-Add-termios2-support-to-alpha-target.patch";
url = "https://gitlab.com/qemu-project/qemu/-/commit/8d8c6aeee8599a099e49ec4411f3d1e087ae40ad.patch";
hash = "sha256-5e5vUp9nr96ZmVA98W/ETReLbkofayysJXlx1Ck9gDs=";
})
(fetchpatch {
name = "0003-Add-termios2-support-to-hppa-target.patch";
url = "https://gitlab.com/qemu-project/qemu/-/commit/edc741710acedd61011f937967b960d154794258.patch";
hash = "sha256-nls6eTOB06eqACjQ/r1sQvb9YaYmrpJcegsDGqKAOaI=";
})
(fetchpatch {
name = "0004-Add-termios2-support-to-mips-target.patch";
url = "https://gitlab.com/qemu-project/qemu/-/commit/edf9184f4feb691b0f70dc544443db2380891598.patch";
hash = "sha256-GrBhyMq2QiCc+WlUwaB9j4G8vB3ipxJRV5Hvyab/5Fk=";
})
(fetchpatch {
name = "0005-Add-termios2-support-to-sh4-target.patch";
url = "https://gitlab.com/qemu-project/qemu/-/commit/afbe0ff81c29d674b9c18a588bcaab34ddcb8a7b.patch";
hash = "sha256-h+9eC6H8/GJ85Lt1Y0ggdJbbgTIvDfIJkPQfX/FgO4c=";
})
(fetchpatch {
name = "0006-Add-termios2-support-to-sparc-target.patch";
url = "https://gitlab.com/qemu-project/qemu/-/commit/947b971cad90375040f399899909a3f1f32b483f.patch";
hash = "sha256-/JvF25aSR2mBSvkpqupDySMJYZI+lv7L0YwhqiaDk3A=";
})
(fetchpatch {
name = "0007-linux-user-Add-missing-termios-baud-rates.patch";
url = "https://gitlab.com/qemu-project/qemu/-/commit/4f22fcb5c67f40a36e6654f6cfaee23f9f9e93d1.patch";
hash = "sha256-CM81yL0/i+fmQe8qzemre13N3A74J1HIC7ilCbb7ESQ=";
})
(fetchpatch {
name = "0008-linux-user-fixup-termios2-related-things-on-PowerPC.patch";
url = "https://gitlab.com/qemu-project/qemu/-/commit/d68f0e2e906939bef076d0cd52f902d433c8c3da.patch";
hash = "sha256-vF47CKqg0wBBOUkHeJ3hv3nUHCftl2OwD3Nh0dL1PNk=";
})
]
++ lib.optional nixosTestRunner ./force-uid0-on-9p.patch;
+36 -31
View File
@@ -16,7 +16,6 @@ in
pkgsBuildHost,
makeInitrdNGTool,
binutils,
runCommand,
# Name of the derivation (not of the resulting file!)
name ? "initrd",
@@ -74,47 +73,53 @@ in
_compressorMeta.ubootName
or (throw "Unrecognised compressor ${_compressorName}, please specify uInitrdCompression"),
}:
runCommand name
{
compress = "${_compressorExecutable} ${lib.escapeShellArgs _compressorArgsReal}";
passthru = {
compressorExecutableFunction = _compressorFunction;
compressorArgs = _compressorArgsReal;
};
stdenvNoCC.mkDerivation (finalAttrs: {
__structuredAttrs = true;
inherit
extension
makeUInitrd
uInitrdArch
prepend
;
${if makeUInitrd then "uInitrdCompression" else null} = uInitrdCompression;
# the initrd will be self-contained so we can drop references
# to the closure that was used to build it
unsafeDiscardReferences.out = true;
passAsFile = [ "contents" ];
contents = builtins.toJSON contents;
inherit
name
extension
makeUInitrd
uInitrdArch
prepend
;
${if makeUInitrd then "uInitrdCompression" else null} = uInitrdCompression;
nativeBuildInputs = [
makeInitrdNGTool
cpio
]
++ lib.optional makeUInitrd ubootTools;
}
''
compress = "${_compressorExecutable} ${lib.escapeShellArgs _compressorArgsReal}";
contentsJSON = builtins.toJSON contents;
nativeBuildInputs = [
makeInitrdNGTool
cpio
]
++ lib.optional makeUInitrd ubootTools;
buildCommand = ''
mkdir -p ./root/{run,tmp,var/empty}
ln -s ../run ./root/var/run
make-initrd-ng "$contentsPath" ./root
make-initrd-ng <(echo "$contentsJSON") ./root
mkdir "$out"
(cd root && find . -exec touch -h -d '@1' '{}' +)
for PREP in $prepend; do
for PREP in ''${prepend[@]}; do
cat $PREP >> $out/initrd
done
(cd root && find . -print0 | sort -z | cpio --quiet -o -H newc -R +0:+0 --reproducible --null | eval -- $compress >> "$out/initrd")
if [ -n "$makeUInitrd" ]; then
mkimage -A "$uInitrdArch" -O linux -T ramdisk -C "$uInitrdCompression" -d "$out/initrd" $out/initrd.img
# Compatibility symlink
ln -sf "initrd.img" "$out/initrd"
mkimage -A "$uInitrdArch" -O linux -T ramdisk -C "$uInitrdCompression" -d "$out/initrd" $out/initrd.img
# Compatibility symlink
ln -sf "initrd.img" "$out/initrd"
else
ln -s "initrd" "$out/initrd$extension"
ln -s "initrd" "$out/initrd$extension"
fi
''
'';
passthru = {
compressorExecutableFunction = _compressorFunction;
compressorArgs = _compressorArgsReal;
};
})
+35 -33
View File
@@ -81,42 +81,44 @@ in
_compressorMeta.ubootName
or (throw "Unrecognised compressor ${_compressorName}, please specify uInitrdCompression"),
}:
stdenvNoCC.mkDerivation (
rec {
inherit
name
makeUInitrd
extension
uInitrdArch
prepend
;
stdenvNoCC.mkDerivation (finalAttrs: {
__structuredAttrs = true;
builder = ./make-initrd.sh;
# the initrd will be self-contained so we can drop references
# to the closure that was used to build it
unsafeDiscardReferences.out = true;
nativeBuildInputs = [
cpio
]
++ lib.optional makeUInitrd ubootTools;
inherit
name
extension
makeUInitrd
uInitrdArch
prepend
;
${if makeUInitrd then "uInitrdCompression" else null} = uInitrdCompression;
compress = "${_compressorExecutable} ${lib.escapeShellArgs _compressorArgsReal}";
builder = ./make-initrd.sh;
# Pass the function through, for reuse in append-initrd-secrets. The
# function is used instead of the string, in order to support
# cross-compilation (append-initrd-secrets running on a different
# architecture than what the main initramfs is built on).
passthru = {
compressorExecutableFunction = _compressorFunction;
compressorArgs = _compressorArgsReal;
};
nativeBuildInputs = [
cpio
]
++ lib.optional makeUInitrd ubootTools;
# !!! should use XML.
objects = map (x: x.object) contents;
symlinks = map (x: x.symlink) contents;
suffices = map (x: if x ? suffix then x.suffix else "none") contents;
compress = "${_compressorExecutable} ${lib.escapeShellArgs _compressorArgsReal}";
closureInfo = "${pkgsBuildHost.closureInfo { rootPaths = objects; }}";
}
// lib.optionalAttrs makeUInitrd {
uInitrdCompression = uInitrdCompression;
}
)
# !!! should use XML.
objects = map (x: x.object) contents;
symlinks = map (x: x.symlink) contents;
suffices = map (x: if x ? suffix then x.suffix else "none") contents;
closureInfo = "${pkgsBuildHost.closureInfo { rootPaths = finalAttrs.objects; }}";
# Pass the function through, for reuse in append-initrd-secrets. The
# function is used instead of the string, in order to support
# cross-compilation (append-initrd-secrets running on a different
# architecture than what the main initramfs is built on).
passthru = {
compressorExecutableFunction = _compressorFunction;
compressorArgs = _compressorArgsReal;
};
})
+12 -16
View File
@@ -1,9 +1,5 @@
set -o pipefail
objects=($objects)
symlinks=($symlinks)
suffices=($suffices)
mkdir root
# Needed for splash_helper, which gets run before init.
@@ -12,14 +8,14 @@ mkdir root/sys
mkdir root/proc
for ((n = 0; n < ${#objects[*]}; n++)); do
object=${objects[$n]}
symlink=${symlinks[$n]}
suffix=${suffices[$n]}
if test "$suffix" = none; then suffix=; fi
for ((n = 0; n < ${#objects[@]}; n++)); do
object=${objects[n]}
symlink=${symlinks[n]}
suffix=${suffices[n]}
if test "$suffix" = none; then suffix=; fi
mkdir -p $(dirname root/$symlink)
ln -s $object$suffix root/$symlink
mkdir -p $(dirname root/$symlink)
ln -s $object$suffix root/$symlink
done
@@ -34,16 +30,16 @@ storePaths="$(cat $closureInfo/store-paths)"
# Put the closure in a gzipped cpio archive.
mkdir -p $out
for PREP in $prepend; do
for PREP in ${prepend[@]}; do
cat $PREP >> $out/initrd
done
(cd root && find * .[^.*] -exec touch -h -d '@1' '{}' +)
(cd root && find * .[^.*] -print0 | sort -z | cpio --quiet -o -H newc -R +0:+0 --reproducible --null | eval -- $compress >> "$out/initrd")
if [ -n "$makeUInitrd" ]; then
mkimage -A "$uInitrdArch" -O linux -T ramdisk -C "$uInitrdCompression" -d "$out/initrd" $out/initrd.img
# Compatibility symlink
ln -sf "initrd.img" "$out/initrd"
mkimage -A "$uInitrdArch" -O linux -T ramdisk -C "$uInitrdCompression" -d "$out/initrd" $out/initrd.img
# Compatibility symlink
ln -sf "initrd.img" "$out/initrd"
else
ln -s "initrd" "$out/initrd$extension"
ln -s "initrd" "$out/initrd$extension"
fi
+2 -2
View File
@@ -12,13 +12,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "andi";
version = "0.14";
version = "1.15";
src = fetchFromGitHub {
owner = "evolbioinf";
repo = "andi";
tag = "v${finalAttrs.version}";
hash = "sha256-tjQ9exFyqu/xnbUGpF6k0kE5C1D93kISjRErwHfjW9E=";
hash = "sha256-199CjhOdC0BnNyhhTSn/DWmqn/0vSziV+aW2shE1Vuo=";
};
nativeBuildInputs = [
@@ -9,6 +9,7 @@
glib,
libsecret,
webkitgtk_4_1,
imagemagick,
}:
stdenv.mkDerivation (finalAttrs: {
@@ -45,6 +46,7 @@ stdenv.mkDerivation (finalAttrs: {
nativeBuildInputs = [
makeWrapper
autoPatchelfHook
imagemagick
];
installPhase = ''
@@ -70,7 +72,8 @@ stdenv.mkDerivation (finalAttrs: {
]
} \
--run "mkdir -p /tmp/SWT-GDBusServer"
install -D icon.xpm "$out/share/pixmaps/apache-directory-studio.xpm"
mkdir -p $out/share/icons/hicolor/48x48/apps
magick icon.xpm $out/share/icons/hicolor/48x48/apps/apache-directory-studio.png
install -D -t "$out/share/applications" ${finalAttrs.desktopItem}/share/applications/*
'';
@@ -1,12 +1,12 @@
{
lib,
stdenv,
buildGo124Module,
buildGoModule,
fetchFromGitHub,
go-task,
}:
buildGo124Module rec {
buildGoModule rec {
pname = "arduino-create-agent";
version = "1.7.0";
@@ -21,6 +21,10 @@ buildGo124Module rec {
./updater.patch
];
excludedPackages = [
"design"
];
vendorHash = "sha256-Nrw7l3nV1sMVWs1HECQJYohKiD0gPvWQOLD7eohEd1A=";
ldflags = [
@@ -213,9 +213,9 @@
containerapp = mkAzExtension rec {
pname = "containerapp";
version = "1.3.0b1";
version = "1.3.0b2";
url = "https://azcliprod.blob.core.windows.net/cli-extensions/containerapp-${version}-py2.py3-none-any.whl";
hash = "sha256-gEFo2qBqQ19SSIMx1BWPoc19xv7lCUkuZMSUz9qPqrE=";
hash = "sha256-Br/cfKFTkqcjGRCXAbHqfwTe4g49F3zbj/tzp/O+giI=";
description = "Microsoft Azure Command-Line Tools Containerapp Extension";
propagatedBuildInputs = with python3Packages; [
docker
+2 -2
View File
@@ -8,13 +8,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "capstone";
version = "5.0.6";
version = "5.0.7";
src = fetchFromGitHub {
owner = "capstone-engine";
repo = "capstone";
rev = finalAttrs.version;
hash = "sha256-ovIvsxVq+/q5UUMzP4WpxzaE0898uayNc1g2Coignnc=";
hash = "sha256-+6QReHZK+iIXspizy6Kvk7cj016HOKgiaKSaP4h7mao=";
};
cmakeFlags = [
+3 -3
View File
@@ -6,16 +6,16 @@
buildGoModule (finalAttrs: {
pname = "chisel";
version = "1.11.3";
version = "1.11.4";
src = fetchFromGitHub {
owner = "jpillora";
repo = "chisel";
tag = "v${finalAttrs.version}";
hash = "sha256-JrDRcp0gImG/5b/BC0KWM2IqJrS2mzO+ZX6kbTtQYlM=";
hash = "sha256-g0UjjzH22ri/tYMO8HDQ6zjis9z6ojRsQJIP5AGhjfM=";
};
vendorHash = "sha256-2H+YHqYE1xm+7qDG3jfFpwS9FbYkbwJ6uso2At2BZcU=";
vendorHash = "sha256-hqHd+62csVjHY2oAvi5fwlI0LbjR/LSDg6b1SMwe8Fw=";
ldflags = [
"-s"
+2 -2
View File
@@ -7,13 +7,13 @@
buildGoModule (finalAttrs: {
pname = "codecrafters-cli";
version = "46";
version = "47";
src = fetchFromGitHub {
owner = "codecrafters-io";
repo = "cli";
tag = "v${finalAttrs.version}";
hash = "sha256-XG85j9iay0+bQIoUeCrvO+rCch9ONXRAtoXjXI2Rt9s=";
hash = "sha256-X0pQouy/XHZMkPwBab2FsjjPhLrWIRglMJOTl/hzkcI=";
# A shortened git commit hash is part of the version output, and is
# needed at build time. Use the `.git` directory to retrieve the
# commit SHA, and remove the directory afterwards since it is not needed
+5 -5
View File
@@ -8,16 +8,16 @@
}:
let
openShiftVersion = "4.20.5";
openShiftVersion = "4.21.0";
okdVersion = "4.20.0-okd-scos.11";
microshiftVersion = "4.20.0";
microshiftVersion = "4.21.0";
writeKey = "$(MODULEPATH)/pkg/crc/segment.WriteKey=cvpHsNcmGCJqVzf6YxrSnVlwFSAZaYtp";
gitCommit = "ae41f68e34a463bfb6a72dc06c51f2b809c99724";
gitHash = "sha256-O8O3O+RoBieOdsAqLAomZ2lPIHEta6j2yhNOfXwtrVA=";
gitCommit = "275f36851d44a1dba8407f960f763b546ba8fc32";
gitHash = "sha256-M622rTWsz35EVmMm/EyIAYbRFFBvpXYjcNp4HrcFl3o=";
in
buildGoModule (finalAttrs: {
pname = "crc";
version = "2.57.0";
version = "2.58.0";
src = fetchFromGitHub {
owner = "crc-org";
+3 -3
View File
@@ -11,16 +11,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "gitlogue";
version = "0.7.0";
version = "0.8.0";
src = fetchFromGitHub {
owner = "unhappychoice";
repo = "gitlogue";
tag = "v${finalAttrs.version}";
hash = "sha256-mZ2A6274Ujpo5rTewFaMUslZhLCKJ2iw43J8X3vuBBI=";
hash = "sha256-T9QhPWT6w6Ezdl33mPb24UB38ApZdY/JlFMWYJZw+gA=";
};
cargoHash = "sha256-MueaRVomOiQsPSOnHpB/k9a8fNpKpFRilAXgIkVxZ94=";
cargoHash = "sha256-7MQOf/BQ5dDR7iIOKjyKah7CJuZN4OZm+CcHso7FecI=";
nativeBuildInputs = [ pkg-config ];
+3 -3
View File
@@ -8,16 +8,16 @@
buildGoModule (finalAttrs: {
pname = "grafanactl";
version = "0.1.8";
version = "0.1.9";
src = fetchFromGitHub {
owner = "grafana";
repo = "grafanactl";
tag = "v${finalAttrs.version}";
hash = "sha256-UaltfA3O9IkcWXCnxe0pOhYm3//5YZEvhVi3emCy1mM=";
hash = "sha256-TJoTxVKfG2mfV05pkAxUJR7NKZbD9VIqRW4H8lyP2As=";
};
vendorHash = "sha256-wIp05nwc4MICkNFoEAjOd4kjs1RE7RpINcdYzIdq4YY=";
vendorHash = "sha256-zEE4iaZJBneYgo6avCOTG7tWZ88NDskPTYiCMb8pRR4=";
ldflags = [
"-X main.version=v${finalAttrs.version}"
+3 -3
View File
@@ -7,18 +7,18 @@
buildGoModule (finalAttrs: {
pname = "lakectl";
version = "1.65.2";
version = "1.77.0";
src = fetchFromGitHub {
owner = "treeverse";
repo = "lakeFS";
tag = "v${finalAttrs.version}";
hash = "sha256-X7cjNa9PQFUuvCN8/i8p9kqsvHqc3IGFWL++Mj0KdfY=";
hash = "sha256-PGOCDWyocj91po7vL6IOwUGNzWERv0rwEAYp6LK2E30=";
};
subPackages = [ "cmd/lakectl" ];
proxyVendor = true;
vendorHash = "sha256-JEAVAXWscq/u+ABvYThlWkpaVRQd2e2gtmYoLDjVx/s=";
vendorHash = "sha256-a37Cv7Wcf74hscMxVvZ7g6zZgBTqz/0wmSNamExM/Tc=";
ldflags = [
"-s"
@@ -72,17 +72,17 @@ let
in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "matrix-continuwuity";
version = "0.5.4";
version = "0.5.5";
src = fetchFromGitea {
domain = "forgejo.ellis.link";
owner = "continuwuation";
repo = "continuwuity";
tag = "v${finalAttrs.version}";
hash = "sha256-E2BJh0ynzUm3gHJXM0qKIgTyEEMD02PG+uPPdr/MKaQ=";
hash = "sha256-mEdhnyzuW2fTP/dBpJE6EnvTH2fbQXOOwZgjJ1trQmU=";
};
cargoHash = "sha256-yPQxEZwMQv7HqlQzQxwGrUzZOL21cfNymkNdkOA4GIk=";
cargoHash = "sha256-giG4SZNh7uV7PIeHv0npfkgYi6lWn55YktKHOF7HGyM=";
nativeBuildInputs = [
pkg-config
+1
View File
@@ -48,6 +48,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
"initrd-init"
"find-etc"
"resolve-in-root"
"env-generator"
];
postInstall = ''
@@ -0,0 +1,53 @@
use std::{
collections::HashMap,
fs,
io::{self, Write},
};
use anyhow::{Context, Result};
use serde::Deserialize;
const CONFIG_PATH: &str = "/etc/systemd/generator-environment.json";
const KMSG_PATH: &str = "/dev/kmsg";
#[derive(Deserialize)]
struct Config(HashMap<String, String>);
/// Implementation for the entrypoint of the `env-generator` binary.
///
/// Reads the JSON config for the systemd generator environment and prints it in KEY=VALUE format
/// to stdout. This makes the configured environment variables available for all systemd
/// generators.
fn env_generator_impl() -> Result<()> {
let content = fs::read(CONFIG_PATH).with_context(|| format!("Failed to read {CONFIG_PATH}"))?;
let config: Config = serde_json::from_slice(&content).context("Failed to parse config")?;
let mut buffer = Vec::new();
for (key, value) in config.0 {
writeln!(&mut buffer, "{key}=\"{value}\"").context("Failed to write to buffer")?;
}
let stdout = io::stdout();
let mut locked = stdout.lock();
locked
.write_all(&buffer)
.context("Failed to write to stdout")?;
Ok(())
}
/// Entrypoint for the `env-generator` binary.
///
/// Generators cannot use normal logging but have to write to /dev/kmsg.
///
/// The return value is just here so that we can use the `main.rs` entrypoint for this binary.
/// Errors returned from this function will not be logged and thus are meaningless.
pub fn env_generator() -> Result<()> {
if let Err(err) = env_generator_impl() {
// Sometimes we do not have /dev/kmsg, e.g. inside a container
if let Ok(mut kmsg) = fs::OpenOptions::new().write(true).open(KMSG_PATH) {
let _ = write!(kmsg, "<3>env-generator: {err:#}");
}
}
Ok(())
}
+2
View File
@@ -1,5 +1,6 @@
mod activate;
mod config;
mod env_generator;
mod find_etc;
mod fs;
mod init;
@@ -14,6 +15,7 @@ use anyhow::{Context, Result, bail};
pub use crate::{
activate::activate,
env_generator::env_generator,
find_etc::find_etc,
init::init,
initrd_init::initrd_init,
+2 -1
View File
@@ -2,7 +2,7 @@ use std::{env, io::Write, process::ExitCode};
use log::Level;
use nixos_init::{find_etc, initrd_init, resolve_in_root};
use nixos_init::{env_generator, find_etc, initrd_init, resolve_in_root};
fn main() -> ExitCode {
let arg0 = env::args()
@@ -15,6 +15,7 @@ fn main() -> ExitCode {
"find-etc" => find_etc,
"resolve-in-root" => resolve_in_root,
"initrd-init" => initrd_init,
"env-generator" => env_generator,
_ => {
log::error!("Command {arg0} unknown");
return ExitCode::FAILURE;
@@ -308,6 +308,14 @@ It must be one of the following:
option, it is possible to build non-flake NixOS configurations even if
the current NixOS systems uses flakes.
*--diff*
show the diff between the system closure in /run/current-system
and the newly built system closure.
(avaliable for actions: build, boot, test, switch)
This is similar to running:
"nix store diff-closures /run/current-system result" after build
In addition, *nixos-rebuild* accepts following options from nix commands that
the tool calls:
@@ -197,6 +197,12 @@ def get_parser() -> tuple[argparse.ArgumentParser, dict[str, argparse.ArgumentPa
help="Selects an image variant to build from the "
"config.system.build.images attribute of the given configuration",
)
main_parser.add_argument(
"--diff",
action="store_true",
help="prints out the diff between the current system "
"and the newly built one using nix store diff-closures"
)
main_parser.add_argument("action", choices=Action.values(), nargs="?")
return main_parser, sub_parsers
@@ -259,6 +265,20 @@ def parse_args(
if args.no_build_nix:
parser_warn("--no-build-nix is deprecated, we do not build nix anymore")
if args.diff and args.action not in (
# case for calling build_and_activate_system
# except excluding DRY_BUILD and DRY_ACTIVATE,
# in which --diff is uniquely a no-op
Action.SWITCH.value,
Action.BOOT.value,
Action.TEST.value,
Action.BUILD.value,
Action.BUILD_IMAGE.value,
Action.BUILD_VM.value,
Action.BUILD_VM_WITH_BOOTLOADER.value,
):
parser_warn(f"--diff is a no-op with '{args.action}'")
if args.action == Action.EDIT.value and (args.file or args.attr):
parser.error("--file and --attr are not supported with 'edit'")
@@ -1,3 +1,4 @@
import sys
import json
import logging
import os
@@ -537,6 +538,25 @@ def list_generations(profile: Profile) -> list[GenerationJson]:
reverse=True,
)
def diff_closures(current_config: Path, new_config: Path, target_host: Remote | None = None):
print(
f"<<< {current_config}\n"
f">>> {new_config}",
file=sys.stderr
)
run_wrapper(
[
"nix",
*FLAKE_FLAGS,
"store",
"diff-closures",
current_config,
new_config,
],
remote=target_host,
stdout=sys.stderr
)
def repl(build_attr: BuildAttr, nix_flags: Args | None = None) -> None:
run_args = ["nix", "repl", "--file", build_attr.path]
@@ -321,6 +321,13 @@ def build_and_activate_system(
grouped_nix_args=grouped_nix_args,
)
current_config = Path("/run/current-system")
if args.diff:
if current_config.exists():
nix.diff_closures(current_config=current_config.readlink(), new_config=path_to_config, target_host=target_host)
else:
logger.warning(f"missing '{str(current_config)}', skipping configuration diff...")
_activate_system(
path_to_config=path_to_config,
action=action,
@@ -1,3 +1,4 @@
import sys
import textwrap
import uuid
from pathlib import Path
@@ -550,6 +551,29 @@ def test_list_generations(mock_get_generations: Mock, tmp_path: Path) -> None:
]
@patch(get_qualified_name(n.run_wrapper, n), autospec=True)
def test_diff_closures(mock_run: Mock) -> None:
assert n.diff_closures(
Path("/run/current-system"),
Path("/nix/var/nix/profiles/system"),
None
) == None
mock_run.assert_called_with(
[
"nix",
"--extra-experimental-features",
"nix-command flakes",
"store",
"diff-closures",
Path("/run/current-system"),
Path("/nix/var/nix/profiles/system"),
],
remote=None,
stdout=sys.stderr
)
@patch(get_qualified_name(n.run_wrapper, n), autospec=True)
def test_repl(mock_run: Mock) -> None:
n.repl(m.BuildAttr("<nixpkgs/nixos>", None), {"nix_flag": True})
+3 -3
View File
@@ -10,16 +10,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "nono";
version = "0.4.1";
version = "0.5.0";
src = fetchFromGitHub {
owner = "always-further";
repo = "nono";
tag = "v${finalAttrs.version}";
hash = "sha256-siZK9ELU5RsX2Dc1T8LpOFNVR0Qo3xJ2LfIrqb6abSk=";
hash = "sha256-32PiM84dwZ3dPIAIak1DL3iencguXCzehFCDsulDyhI=";
};
cargoHash = "sha256-3xuZMXX9YTHY4HsFuOdzbykqOVH/PWuFyLhPbl7baqY=";
cargoHash = "sha256-nE0vVBThXnqo8VnFCkOyqhpZZ40MIkXSqUoJUZcDVhE=";
nativeBuildInputs = [
pkg-config
+89
View File
@@ -0,0 +1,89 @@
{
lib,
stdenv,
requireFile,
bubblewrap,
fakeroot,
unixtools,
cudaSupport,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "pixinsight";
version = "1.9.3-20250402";
src = requireFile {
name = "PI-linux-x64-${finalAttrs.version}-c.tar.xz";
url = "http://pixinsight.com";
hash = "sha256-MOAWH64A13vVLeNiBC9nO78P0ELmXXHR5ilh5uUhWhs=";
};
nativeBuildInputs = [
bubblewrap
fakeroot
unixtools.script
];
sourceRoot = ".";
# Patch installer binary with correct interpreter and rpath
postPatch = ''
patchelf ./installer \
--set-interpreter "$(cat $NIX_CC/nix-support/dynamic-linker)" \
--set-rpath ${lib.getLib stdenv.cc.cc}/lib
'';
dontConfigure = true;
dontBuild = true;
installPhase = ''
runHook preInstall
# Prepare output directories
mkdir -p $out/opt
mkdir -p $out/share/{applications,mime/packages}
for i in 16 24 32 48 64 128 256 512; do
mkdir -p $out/share/icons/hicolor/"$i"x"$i"/apps
done
mkdir -p $out/share/icons/hicolor/scalable/apps
# Install using proper bind-mounts
bwrap \
--bind /build /build \
--bind $out/opt /opt \
--bind /nix /nix \
--dev /dev \
fakeroot script -ec "./installer \
--yes \
--install-desktop-dir=$out/share/applications \
--install-mime-dir=$out/share/mime \
--install-icons-dir=$out/share/icons/hicolor \
--no-bin-launcher"
''
+ lib.optionalString cudaSupport ''
# Remove bundled libtensorflow-cpu files
rm -f $out/opt/PixInsight/bin/lib/libtensorflow*
''
+ ''
runHook postInstall
'';
postFixup = ''
# Patch desktop entry for downstream compatibility
substituteInPlace $out/share/applications/PixInsight.desktop \
--replace-fail "Exec=/opt/PixInsight/bin/PixInsight.sh" "Exec=pixinsight"
'';
meta = {
description = "Scientific image processing program for astrophotography";
homepage = "https://pixinsight.com/";
license = lib.licenses.unfree;
maintainers = with lib.maintainers; [
sheepforce
kulczwoj
];
platforms = [ "x86_64-linux" ];
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
hydraPlatforms = [ ];
};
})
@@ -0,0 +1,56 @@
{
lib,
stdenv,
fetchurl,
autoPatchelfHook,
cudaPackages,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "libtensorflow-gpu";
version = "2.18.1";
src = fetchurl {
url = "https://storage.googleapis.com/tensorflow/versions/${finalAttrs.version}/${finalAttrs.pname}-linux-x86_64.tar.gz";
hash = "sha256-9k7DA53E/hh9zzMhX0D6BZOZWwOoiNEi/tdYHONIFeU=";
};
nativeBuildInputs = [
autoPatchelfHook
];
buildInputs = with cudaPackages; [
cudatoolkit
cudnn
];
sourceRoot = ".";
# Unpack tarball to subdir, preventing copying `env-vars` to $out in `installPhase`
preUnpack = ''
mkdir source
cd source
'';
dontPatch = true;
dontConfigure = true;
dontBuild = true;
installPhase = ''
runHook preInstall
mkdir -p $out
cp -pr --reflink=auto -- . $out
runHook postInstall
'';
meta = {
description = "Computation using data flow graphs for scalable machine learning";
homepage = "http://tensorflow.org";
license = lib.licenses.asl20;
maintainers = with lib.maintainers; [ kulczwoj ];
platforms = [ "x86_64-linux" ];
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
};
})
+157 -166
View File
@@ -1,182 +1,173 @@
{
stdenv,
lib,
requireFile,
autoPatchelfHook,
unixtools,
fakeroot,
mailcap,
libGL,
libpulseaudio,
alsa-lib,
nss,
gd,
gst_all_1,
nspr,
expat,
fontconfig,
dbus,
glib,
zlib,
openssl,
libdrm,
cups,
avahi-compat,
libidn2,
libdeflate,
brotli,
libxkbcommon,
libxcb,
libxtst,
libxrandr,
libxfixes,
libxext,
libxdamage,
libxcomposite,
libx11,
xrandr,
libxkbfile,
wayland,
libudev0-shim,
bubblewrap,
libjpeg8,
gdk-pixbuf,
gtk3,
pango,
callPackage,
buildFHSEnv,
cudaPackages,
config,
cudaSupport ? config.cudaSupport,
# Provide support for built-in self-updates and plugin management
#
# PixInsight installs updates and plugins in its main installation location,
# which is incompatible with running it from immutable Nix store.
#
# `true`:
# - configure mutable copy of PixInsight installation under
# `~/.local/share/pixinsight`, and run PixInsight using it
# - whenever immutable installation changes, on launch clear and reinstall
# mutable files to keep synced with Nix store
# - `PixInsightUpdater` is fully functional
#
# `false`:
# - run PixInsight using immutable installation from Nix store
# - `PixInsightUpdater` returns `Read-only file system` error on update
# installation attempt
#
# Enabled by default, as this is part of core functionality, expected from upstream
enableUpdates ? true,
}:
let
meta = {
description = "Scientific image processing program for astrophotography";
homepage = "https://pixinsight.com/";
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
license = lib.licenses.unfree;
platforms = [ "x86_64-linux" ];
maintainers = [ lib.maintainers.sheepforce ];
hydraPlatforms = [ ];
mainProgram = "PixInsight";
};
pixinsight = callPackage ./. { inherit cudaSupport; };
pname = "pixinsight";
version = "1.9.3-20250402";
# For CUDA support (PixInsight ships with `libtensorflow-cpu`)
#
# PixInsight uses C API `libtensorflow`, which differs from library shipped
# with `tensorflow-bin`: in particular it contains `VERS_1.0` embedded.
# Variants from `tensorflow-bin` don't embed it and are rejected as
# incompatible, when PixInsight installs plugins to its internal runtime
# environment and loads their dependencies.
libtensorflow-gpu = callPackage ./libtensorflow-gpu.nix { };
installPkg = stdenv.mkDerivation (finalAttrs: {
inherit meta pname version;
deployPath = "$HOME/.local/share/pixinsight";
storePathFile = "${deployPath}/opt/PixInsight/.store-path";
in
buildFHSEnv {
inherit (pixinsight) pname version;
src = requireFile rec {
name = "PI-linux-x64-${finalAttrs.version}-c.tar.xz";
url = "https://pixinsight.com/";
hash = "sha256-MOAWH64A13vVLeNiBC9nO78P0ELmXXHR5ilh5uUhWhs=";
message = ''
PixInsight is available from ${url} and requires a commercial (or trial) license.
After a license has been obtained, PixInsight can be downloaded from the software distribution
(choose Linux 64bit).
The PixInsight tarball must be added to the nix-store, i.e. via
nix-prefetch-url --type sha256 file:///path/to/${name}
'';
};
sourceRoot = ".";
targetPkgs =
pkgs:
(with pkgs; [
expat
glib
zlib
udev
dbus
nspr
nss
openssl
nativeBuildInputs = [
unixtools.script
fakeroot
mailcap
libudev0-shim
bubblewrap
alsa-lib
libxkbcommon
libGL
libdrm
qt6Packages.qtbase
gtk3
fontconfig
libjpeg8
gd
libssh2
libpsl
libidn2
brotli
libdeflate
avahi-compat
cups
libx11
libxcomposite
libxdamage
libxext
libxfixes
libxinerama
libxrandr
libxrender
libxtst
libsm
libice
libxcb
libxkbfile
libxcb-util
libxcb-image
libxcb-keysyms
libxcb-render-util
libxcb-wm
# libxcb-cursor # Bundled by PixInsight
])
++ lib.optionals cudaSupport (
[
libtensorflow-gpu
]
++ (with pkgs.cudaPackages; [
cudatoolkit
cudnn
])
);
extraInstallCommands = ''
# Provide second binary matching upstream CLI command (`PixInsight`)
ln -s $out/bin/{pixinsight,PixInsight}
# Provide desktop integration files
ln -s {${pixinsight},$out}/share
'';
# Prepare mutable opt/ for self-update and plugin support
# Clear and redeploy whenever `pixinsight` store path changes
extraPreBwrapCmds = lib.optionalString enableUpdates ''
set -e
read -r DEPLOYED_PATH < "${storePathFile}" 2>/dev/null || DEPLOYED_PATH=""
if [ "$DEPLOYED_PATH" != "${pixinsight}" ]; then
echo "pixinsight: new PixInsight installation detected"
echo "pixinsight: deploying ${pixinsight}/opt/PixInsight to ${deployPath}/opt/PixInsight..."
mkdir -p "${deployPath}"/opt
rm -rf "${deployPath}"/opt/PixInsight
cp -R ${pixinsight}/opt/PixInsight "${deployPath}"/opt
chmod -R u+w "${deployPath}"/opt/PixInsight
echo "${pixinsight}" > "${storePathFile}"
echo "pixinsight: deployed successfully"
fi
'';
extraBwrapArgs =
lib.optionals enableUpdates [
# Bind-mount mutable opt/ to /opt
''--bind "${deployPath}"/opt /opt''
]
++ lib.optionals (!enableUpdates) [
# Bind-mount immutable opt/ to /opt
''--ro-bind "${pixinsight}"/opt /opt''
];
postPatch = ''
patchelf ./installer \
--set-interpreter "$(cat $NIX_CC/nix-support/dynamic-linker)" \
--set-rpath ${lib.getLib stdenv.cc.cc}/lib
'';
profile = lib.optionalString cudaSupport ''
export XLA_FLAGS=--xla_gpu_cuda_data_dir=${cudaPackages.cudatoolkit}
'';
dontConfigure = true;
dontBuild = true;
runScript = "/opt/PixInsight/bin/PixInsight.sh";
installPhase = ''
runHook preInstall
mkdir -p $out/bin $out/opt/PixInsight $out/share/{applications,mime/packages,icons/hicolor}
bwrap --bind /build /build --bind $out/opt /opt --bind /nix /nix --dev /dev fakeroot script -ec "./installer \
--yes \
--install-desktop-dir=$out/share/applications \
--install-mime-dir=$out/share/mime \
--install-icons-dir=$out/share/icons/hicolor \
--no-bin-launcher \
--no-remove"
rm -rf $out/opt/PixInsight-old-0
ln -s $out/opt/PixInsight/bin/PixInsight $out/bin/.
ln -s $out/opt/PixInsight/bin/lib $out/lib
runHook postInstall
'';
});
runPkg = buildFHSEnv {
inherit meta pname version;
targetPkgs =
pkgs:
[
# PI itself
installPkg
# runtime deps
mailcap
libudev0-shim
(lib.getLib stdenv.cc.cc)
stdenv.cc
libGL
libpulseaudio
alsa-lib
nss
gd
gst_all_1.gstreamer
gst_all_1.gst-plugins-base
nspr
expat
fontconfig
dbus
glib
zlib
openssl
libdrm
wayland
cups
avahi-compat
libjpeg8
gdk-pixbuf
gtk3
pango
libidn2
libdeflate
brotli
libxkbcommon
libxcb
libx11
libxdamage
xrandr
libxtst
libxcomposite
libxext
libxfixes
libxrandr
libxkbfile
];
profile = ''
export QT_QPA_PLATFORM_PLUGIN_PATH=/opt/PixInsight/bin/lib/qt-plugins/platforms
export QT_PLUGIN_PATH=/opt/PixInsight/bin/lib/qt-plugins
export LD_LIBRARY_PATH=${libudev0-shim}/lib
'';
runScript = "${installPkg}/bin/PixInsight";
passthru = {
inherit libtensorflow-gpu;
unwrapped = pixinsight;
};
in
runPkg
inherit (pixinsight.meta)
description
homepage
license
maintainers
platforms
sourceProvenance
hydraPlatforms
;
}
+2 -2
View File
@@ -25,13 +25,13 @@
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "readest";
version = "0.9.99";
version = "0.9.100";
src = fetchFromGitHub {
owner = "readest";
repo = "readest";
tag = "v${finalAttrs.version}";
hash = "sha256-Fcil35siaGrooW8+R2WrZaR5qHPJXIYOU/Au1YKlb2M=";
hash = "sha256-GsIOMfNqjcdtVRZ0XwCkxpQoIonivLJVT4GmZyB86M0=";
fetchSubmodules = true;
};
+2 -2
View File
@@ -7,13 +7,13 @@
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "rime-wanxiang";
version = "14.6.10";
version = "14.7.0";
src = fetchFromGitHub {
owner = "amzxyz";
repo = "rime_wanxiang";
tag = "v" + finalAttrs.version;
hash = "sha256-GpR5G1vLExRIFcHYMgjmvO/6ZZrFr8EbWtaQIBrveA0=";
hash = "sha256-c4Wx0TJPNTMN6wqJCc9Nk76rc/0Tul/Hu6Kj8cZ75BI=";
};
installPhase = ''
+3 -3
View File
@@ -16,18 +16,18 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "ruff";
version = "0.15.0";
version = "0.15.1";
src = fetchFromGitHub {
owner = "astral-sh";
repo = "ruff";
tag = finalAttrs.version;
hash = "sha256-Q3xujVNv5i3mgdsjnvgTiPoKmK9aeSgz+2IoVrNur4k=";
hash = "sha256-Bj4ATRVYrKqigISNiDvgjUw4MLMwfgdID8MqaiVxz0g=";
};
cargoBuildFlags = [ "--package=ruff" ];
cargoHash = "sha256-JMMDOANg+nqrCoxiuIXTcdqm7UZ61pIJwUTJB20TjUM=";
cargoHash = "sha256-IF60aGv56Kh+wDYyN7XzLBywepvAxv2HMqSOz+Su2b4=";
nativeBuildInputs = [ installShellFiles ];
+2 -2
View File
@@ -9,7 +9,7 @@
let
baseName = "scalafmt";
version = "3.10.6";
version = "3.10.7";
deps = stdenv.mkDerivation {
name = "${baseName}-deps-${version}";
buildCommand = ''
@@ -19,7 +19,7 @@ let
cp $(< deps) $out/share/java/
'';
outputHashMode = "recursive";
outputHash = "sha256-ZSVatzkY+6oiVL4MPf3oyFZiTYaXQ0PNfYvS3O/kU+A=";
outputHash = "sha256-egN5P6jH/xvWm/5TXE/QyIyLdJqu8YQwkfIA40geRXs=";
};
in
stdenv.mkDerivation {
+2 -2
View File
@@ -11,11 +11,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "strace";
version = "6.18";
version = "6.19";
src = fetchurl {
url = "https://strace.io/files/${finalAttrs.version}/strace-${finalAttrs.version}.tar.xz";
hash = "sha256-CtXcupc6aed5ZQ7xyzNbEu5gcW/HMmYJiVvTPm0qcyU=";
hash = "sha256-4HbIUe7AlySG7IQhZP3FRUf50Xq9PRRJ3osSD10pkUM=";
};
separateDebugInfo = true;
@@ -1,23 +1,23 @@
{
version = "1.24.2";
version = "1.25.1";
x86_64-linux = {
url = "https://download.sysdig.com/scanning/bin/sysdig-cli-scanner/1.24.2/linux/amd64/sysdig-cli-scanner";
hash = "sha256-HrkgmdIEgq5fBttZCO2Y0LcgitmTylwBjEUCA0MvqDs=";
url = "https://download.sysdig.com/scanning/bin/sysdig-cli-scanner/1.25.1/linux/amd64/sysdig-cli-scanner";
hash = "sha256-Qg00JIeYpGPcgd9jlbyfOrklWVrseMMLwv5hw87RP/0=";
};
aarch64-linux = {
url = "https://download.sysdig.com/scanning/bin/sysdig-cli-scanner/1.24.2/linux/arm64/sysdig-cli-scanner";
hash = "sha256-AsyM2scsKtQqFygZbrhXQkz1dE7PX1+nT1+gkmfmZcs=";
url = "https://download.sysdig.com/scanning/bin/sysdig-cli-scanner/1.25.1/linux/arm64/sysdig-cli-scanner";
hash = "sha256-GBoNTdSod/IOfsCzYCqU9DLzj2LEjXUwig6gjMbCrYs=";
};
x86_64-darwin = {
url = "https://download.sysdig.com/scanning/bin/sysdig-cli-scanner/1.24.2/darwin/amd64/sysdig-cli-scanner";
hash = "sha256-zCS8X3wLKwowlDhNamXN04hhHy6/SNaq3rFu6oOjbBg=";
url = "https://download.sysdig.com/scanning/bin/sysdig-cli-scanner/1.25.1/darwin/amd64/sysdig-cli-scanner";
hash = "sha256-MtCtWY3/dIIzL3f4IyZzHQPXNuR+OQFR318jQNO5r78=";
};
aarch64-darwin = {
url = "https://download.sysdig.com/scanning/bin/sysdig-cli-scanner/1.24.2/darwin/arm64/sysdig-cli-scanner";
hash = "sha256-+KjOhNRGIXl+B0k8rnQNtbYphKqxvuSHz/R31mOHapY=";
url = "https://download.sysdig.com/scanning/bin/sysdig-cli-scanner/1.25.1/darwin/arm64/sysdig-cli-scanner";
hash = "sha256-vjbpPx8swNwuhperEnDP9sQe+Q1vJU4ZfvLloE2gbh4=";
};
}
+3 -3
View File
@@ -12,16 +12,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "usage";
version = "2.11.0";
version = "2.16.2";
src = fetchFromGitHub {
owner = "jdx";
repo = "usage";
tag = "v${finalAttrs.version}";
hash = "sha256-AFfI843y1fKdw2f4alz7WoeMQR2IPWDJ3SofCCMJVpQ=";
hash = "sha256-1vcJKCtDZtbL0cRAEQ6MgWlESRpOchi6uYMyZi0U9zM=";
};
cargoHash = "sha256-WC/q9yd1XJT/EtC9ES5fw6j45gyRo3k2eNEDwGmvDWo=";
cargoHash = "sha256-rhx09WclXiZtPGsmBCG9ShfWgo7YFKFSPHQpqy9wbtE=";
postPatch = ''
substituteInPlace ./examples/*.sh \
+3 -3
View File
@@ -11,16 +11,16 @@
buildGoModule (finalAttrs: {
pname = "yq-go";
version = "4.52.2";
version = "4.52.4";
src = fetchFromGitHub {
owner = "mikefarah";
repo = "yq";
tag = "v${finalAttrs.version}";
hash = "sha256-AWWSuMrAwv+J8PK/VXyYDwJGSdv2F0/pvNRouK4slM0=";
hash = "sha256-vbvqjcov0ceFeQ81tIaXHbAFjrJ2dCkRfkw/MA0qCr4=";
};
vendorHash = "sha256-rl7AhOJKjVRyfcu7uofniSYJMjBkaO+kCqLRmz2MsiE=";
vendorHash = "sha256-WQDuMVBlmomxdaMQ/nVNki8o++dPdwDSj6jQqbsQNQw=";
nativeBuildInputs = lib.optionals (stdenv.buildPlatform.canExecute stdenv.hostPlatform) [
installShellFiles
+6 -1
View File
@@ -196,7 +196,12 @@ rustPlatform.buildRustPackage (finalAttrs: {
# Some crates define extra types or enum values in test configuration which then lead
# to type checking errors in other crates unless this feature is enabled.
checkFeatures = [ "visual-tests" ];
# gpui/runtime_shaders is required on darwin for the same reason as buildFeatures above:
# without it, build.rs invokes the proprietary Metal shader compiler.
checkFeatures = [
"visual-tests"
]
++ finalAttrs.buildFeatures;
env = {
ALLOW_MISSING_LICENSES = true;
@@ -283,6 +283,14 @@
hash = "sha256-Vr5wkiSE1S5e+cJ8pWUvG9KFpxtmvQ8wAy08ElGNp5E=";
})
]
# Fix subword division regression in 9.12.3 https://gitlab.haskell.org/ghc/ghc/-/merge_requests/15264
++ lib.optionals (version == "9.12.3") [
(fetchpatch {
name = "ghc-9.12.3-fix-subword-division.patch";
url = "https://gitlab.haskell.org/ghc/ghc/-/commit/65370007e2d9f1976fbcfbb514917fb111117148.patch";
hash = "sha256-GMnD0StBTRynl2Lels1L0u1bo7HscLGPUAv+rTJ98QQ=";
})
]
# Fixes stack overrun in rts which crashes an process whenever
# freeHaskellFunPtr is called with nixpkgs' hardening flags.
# https://gitlab.haskell.org/ghc/ghc/-/issues/25485 krank:ignore-line
+3 -3
View File
@@ -28,9 +28,9 @@ let
"21.1.8".officialRelease.sha256 = "sha256-pgd8g9Yfvp7abjCCKSmIn1smAROjqtfZaJkaUkBSKW0=";
"22.1.0-rc3".officialRelease.sha256 = "sha256-vGG7lDdDFW427lS384Bl7Pt9QFgK1XVxLmtm878xmxU=";
"23.0.0-git".gitRelease = {
rev = "dc152f0d2d085dcfb7542d0e71e19ebfa1aa3794";
rev-version = "23.0.0-unstable-2026-02-01";
sha256 = "sha256-F0NXNZLTlMnZlWuAqpoBxrr1DCavQz00WdobKbuwarU=";
rev = "23374f95ed1362cfcabcb1a1a95bc81fc58b70b9";
rev-version = "23.0.0-unstable-2026-02-15";
sha256 = "sha256-CbB+5bFRwbz/k7USBD+h3d0FFGMt58lW7lG3tyeEEyQ=";
};
}
// llvmVersions;
@@ -12,7 +12,7 @@
buildPythonPackage (finalAttrs: {
pname = "specfile";
version = "0.39.0";
version = "0.39.1";
pyproject = true;
src = fetchFromGitHub {
@@ -23,7 +23,7 @@ buildPythonPackage (finalAttrs: {
# export-subst prevents reproducibility
rm "$out/.git_archival.txt"
'';
hash = "sha256-apGGUVBFNRknQvyBCVZerw0/MctWDTDcz4y/7tRp46s=";
hash = "sha256-z9HGnBLdtJ4uzm1DJFD0QN/DZNTdBbZcPx/kefCYnkc=";
};
build-system = [
@@ -15,14 +15,14 @@
buildPythonPackage rec {
pname = "ubelt";
version = "1.4.0";
version = "1.4.1";
pyproject = true;
src = fetchFromGitHub {
owner = "Erotemic";
repo = "ubelt";
tag = "v${version}";
hash = "sha256-9f22hNi/YrxAVoEOGojdziogUN/YNCrpUuOfib9nqfQ=";
hash = "sha256-iEKwJaOWiotyGcz1orc8z3Iqq5Va7p639ebStOA1bCo=";
};
nativeBuildInputs = [
@@ -20,23 +20,23 @@
"lts": true
},
"6.6": {
"version": "6.6.124",
"hash": "sha256:0kkri7y9g5c7hylwsdc2wq2drhniay171nnccr533qlvisgzpbm7",
"version": "6.6.125",
"hash": "sha256:0g88r1v5q0m1n1ii2f16awc8w9m471m6hqx7r5whad4a8dpkpqwf",
"lts": true
},
"6.12": {
"version": "6.12.70",
"hash": "sha256:1w1flq4phr3i51c85bz8d9a8cg780vn7dr29y4j4izyfv33wwk4v",
"version": "6.12.72",
"hash": "sha256:0ybijkw2zadhlg49r0wvnvy3s2czj5jnb149cz8ybvzvp90qgxdi",
"lts": true
},
"6.18": {
"version": "6.18.10",
"hash": "sha256:1plfwknqh5831kjq6f2yxcm4lqvp68a6kvcfnbxa5ba12wb7glyn",
"version": "6.18.11",
"hash": "sha256:1xrsc7s3kh7mipfs0v33n97gfi55ll83x4hxvwi969qh8293ibrq",
"lts": false
},
"6.19": {
"version": "6.19",
"hash": "sha256:0mqka8ii7bvmx9hvfjdiyva9ib0j7m390gxhh8gki3qb4nl7jc1h",
"version": "6.19.1",
"hash": "sha256:1vlki73j7m2khjl39hq4fy42qql9als18nmnjg00a8yklhqzb0qb",
"lts": false
}
}
@@ -8,13 +8,13 @@
postgresqlBuildExtension (finalAttrs: {
pname = "plpgsql-check";
version = "2.8.8";
version = "2.8.9";
src = fetchFromGitHub {
owner = "okbob";
repo = "plpgsql_check";
tag = "v${finalAttrs.version}";
hash = "sha256-jAcQ5gUWjyw4A+pJWKf06EayY/UKeSzlNmnTD4mV/c4=";
hash = "sha256-SqL+Rw1ICeTj2b5bfW+awOf0Kk4SrsvfC6HF6XNe6+I=";
};
passthru.tests.extension = postgresqlTestExtension {