diff --git a/nixos/doc/manual/release-notes/rl-2611.section.md b/nixos/doc/manual/release-notes/rl-2611.section.md
index 5e4bea763284..a36490122096 100644
--- a/nixos/doc/manual/release-notes/rl-2611.section.md
+++ b/nixos/doc/manual/release-notes/rl-2611.section.md
@@ -30,6 +30,8 @@
- Python 2 has been removed from the top-level package set, as it is long past end-of-life. The `python2`, `python27`, `python2Full`, `python27Full`, `python2Packages`, and `python27Packages` attributes, along with the legacy `python`, `pythonFull`, and `pythonPackages` aliases, now throw an error directing you to `python3`. The `isPy2` and `isPy27` package flags have been removed accordingly. The only remaining Python 2 interpreter is vendored inside the `resholve` package for its `oil` dependency and is not exposed for general use.
+- `security.polkit.enablePkexecWrapper` has been introduced, making the `pkexec` setuid wrapper opt-in.
+
- `systemd.user.extraConfig` has been removed in favor of the structured [](#opt-systemd.user.settings.Manager) option. Use `systemd.user.settings.Manager` to set any `systemd-user.conf(5)` option directly. For example, replace `systemd.user.extraConfig = "DefaultTimeoutStartSec=60";` with `systemd.user.settings.Manager.DefaultTimeoutStartSec = 60;`.
- `services.timesyncd.extraConfig` has been removed in favor of the structured [](#opt-services.timesyncd.settings.Time) option. Use `services.timesyncd.settings.Time` to set any `timesyncd.conf(5)` option directly. For example, replace `services.timesyncd.extraConfig = "PollIntervalMaxSec=180";` with `services.timesyncd.settings.Time.PollIntervalMaxSec = 180;`.
diff --git a/nixos/modules/config/fonts/fontconfig.nix b/nixos/modules/config/fonts/fontconfig.nix
index 62214cacc101..16b22841ac14 100644
--- a/nixos/modules/config/fonts/fontconfig.nix
+++ b/nixos/modules/config/fonts/fontconfig.nix
@@ -127,6 +127,38 @@ let
'';
+ # user defined font aliases
+ # priority 53
+ aliases =
+ let
+ mkFontBlock =
+ key: fonts:
+ lib.optionalString ((builtins.length fonts) > 0) ''
+ <${key}>
+ ${lib.concatMapStrings (font: "${font}") fonts}
+ ${key}>
+ '';
+
+ mkAliasBlock = family: opts: ''
+
+ ${family}
+ ${mkFontBlock "prefer" opts.prefer}
+ ${mkFontBlock "accept" opts.accept}
+ ${mkFontBlock "default" opts.default}
+
+ '';
+ in
+ pkgs.writeText "fc-53-user-aliases.conf" ''
+
+
+
+
+
+ ${lib.concatStrings (lib.mapAttrsToList mkAliasBlock cfg.aliases)}
+
+
+ '';
+
# bitmap font options
# priority 53
rejectBitmaps = pkgs.writeText "fc-53-no-bitmaps.conf" ''
@@ -245,6 +277,9 @@ let
# 53-no-bitmaps.conf
ln -s ${rejectBitmaps} $dst/53-no-bitmaps.conf
+ # 53-user-aliases.conf
+ ln -s ${aliases} $dst/53-user-aliases.conf
+
${lib.optionalString (!cfg.allowType1) ''
# 53-nixos-reject-type1.conf
ln -s ${rejectType1} $dst/53-nixos-reject-type1.conf
@@ -522,6 +557,69 @@ in
description = "Use embedded bitmaps in fonts like Calibri.";
};
+ aliases = lib.mkOption {
+ type = lib.types.attrsOf (
+ lib.types.submodule {
+ options = {
+ binding = lib.mkOption {
+ type = lib.types.enum [
+ "same"
+ "weak"
+ "strong"
+ ];
+ default = "same";
+ description = ''
+ Binding precedence for this font family. See
+ fontconfig "Font Matching" section for details.
+ '';
+ };
+
+ prefer = lib.mkOption {
+ type = lib.types.listOf lib.types.str;
+ default = [ ];
+ description = ''
+ Fonts whose glyphs are chosen preferentially prior
+ to fonts which match the alias family.
+ '';
+ };
+
+ accept = lib.mkOption {
+ type = lib.types.listOf lib.types.str;
+ default = [ ];
+ description = ''
+ Fonts that are chosen if none of the preferred
+ fonts, nor the alias family could provide the
+ desired glyph.
+ '';
+ };
+
+ default = lib.mkOption {
+ type = lib.types.listOf lib.types.str;
+ default = [ ];
+ description = ''
+ Last chance fallback fonts which are chosen by
+ default if none of the other options could
+ provide the desired glyph.
+ '';
+ };
+ };
+ }
+ );
+ default = { };
+ example = lib.literalExpression ''
+ {
+ # use FreeSans for Greek symbols missing in Helvetica
+ "Helvetica" = {
+ default = [ "FreeSans" ];
+ };
+ };
+ '';
+ description = ''
+ Font aliases that can substitute preferential fonts,
+ or specify custom fallback fonts.
+ '';
+ };
+
};
};
@@ -557,6 +655,9 @@ in
# 52-nixos-default-fonts.conf
r ${defaultFontsConf},
+ # 53-user-aliases.conf
+ r ${aliases},
+
# 53-no-bitmaps.conf
r ${rejectBitmaps},
diff --git a/nixos/modules/installer/cd-dvd/installation-cd-graphical-calamares.nix b/nixos/modules/installer/cd-dvd/installation-cd-graphical-calamares.nix
index 097a4eca51d5..59e050fe2846 100644
--- a/nixos/modules/installer/cd-dvd/installation-cd-graphical-calamares.nix
+++ b/nixos/modules/installer/cd-dvd/installation-cd-graphical-calamares.nix
@@ -11,6 +11,9 @@ in
{
imports = [ ./installation-cd-graphical-base.nix ];
+ # required for calamares
+ security.polkit.enablePkexecWrapper = true;
+
# required for kpmcore to work correctly
programs.partition-manager.enable = true;
diff --git a/nixos/modules/installer/tools/tools.nix b/nixos/modules/installer/tools/tools.nix
index 8fd268ee0d2d..23a0bebe388c 100644
--- a/nixos/modules/installer/tools/tools.nix
+++ b/nixos/modules/installer/tools/tools.nix
@@ -330,7 +330,7 @@ in
'';
config = lib.mkIf config.system.tools.nixos-rebuild.enableRun0Elevation {
- security.polkit.enable = lib.mkDefault true;
+ security.run0.enable = lib.mkDefault true;
environment.systemPackages = [ pkgs.polkit-stdin-agent ];
};
}
diff --git a/nixos/modules/programs/gamemode.nix b/nixos/modules/programs/gamemode.nix
index 834ae6f54a1d..3e568f9a68aa 100644
--- a/nixos/modules/programs/gamemode.nix
+++ b/nixos/modules/programs/gamemode.nix
@@ -60,7 +60,10 @@ in
};
security = {
- polkit.enable = true;
+ polkit = {
+ enable = true;
+ enablePkexecWrapper = lib.mkDefault true;
+ };
wrappers = lib.mkIf cfg.enableRenice {
gamemoded = {
owner = "root";
diff --git a/nixos/modules/programs/throne.nix b/nixos/modules/programs/throne.nix
index 2023055892dd..a64178c77757 100644
--- a/nixos/modules/programs/throne.nix
+++ b/nixos/modules/programs/throne.nix
@@ -64,32 +64,36 @@ in
# 3. Put ThroneCore into a systemd service, and let polkit check service name.
# This is the most secure and convenient way but requires heavy modification
# to Throne source code. Would be good to let upstream support that eventually.
- security.polkit.extraConfig =
- lib.mkIf (cfg.tunMode.enable && (!cfg.tunMode.setuid) && config.services.resolved.enable)
- ''
- polkit.addRule(function(action, subject) {
- const allowedActionIds = [
- "org.freedesktop.resolve1.revert",
- "org.freedesktop.resolve1.set-domains",
- "org.freedesktop.resolve1.set-default-route",
- "org.freedesktop.resolve1.set-dns-servers"
- ];
+ security.polkit = {
+ enable = true;
+ enablePkexecWrapper = lib.mkDefault true;
+ extraConfig =
+ lib.mkIf (cfg.tunMode.enable && (!cfg.tunMode.setuid) && config.services.resolved.enable)
+ ''
+ polkit.addRule(function(action, subject) {
+ const allowedActionIds = [
+ "org.freedesktop.resolve1.revert",
+ "org.freedesktop.resolve1.set-domains",
+ "org.freedesktop.resolve1.set-default-route",
+ "org.freedesktop.resolve1.set-dns-servers"
+ ];
- if (allowedActionIds.indexOf(action.id) !== -1) {
- try {
- var parentPid = polkit.spawn(["${lib.getExe' pkgs.procps "ps"}", "-o", "ppid=", subject.pid]).trim();
- var parentCap = polkit.spawn(["${lib.getExe' pkgs.libcap "getpcaps"}", parentPid]).trim();
- if (parentCap.includes("cap_net_admin") && parentCap.includes("cap_net_raw")) {
- return polkit.Result.YES;
- } else {
+ if (allowedActionIds.indexOf(action.id) !== -1) {
+ try {
+ var parentPid = polkit.spawn(["${lib.getExe' pkgs.procps "ps"}", "-o", "ppid=", subject.pid]).trim();
+ var parentCap = polkit.spawn(["${lib.getExe' pkgs.libcap "getpcaps"}", parentPid]).trim();
+ if (parentCap.includes("cap_net_admin") && parentCap.includes("cap_net_raw")) {
+ return polkit.Result.YES;
+ } else {
+ return polkit.Result.NOT_HANDLED;
+ }
+ } catch (e) {
return polkit.Result.NOT_HANDLED;
}
- } catch (e) {
- return polkit.Result.NOT_HANDLED;
}
- }
- })
- '';
+ })
+ '';
+ };
};
meta.maintainers = with lib.maintainers; [ aleksana ];
diff --git a/nixos/modules/security/polkit.nix b/nixos/modules/security/polkit.nix
index c2bbe706529f..6ea840d4ccf3 100644
--- a/nixos/modules/security/polkit.nix
+++ b/nixos/modules/security/polkit.nix
@@ -6,27 +6,52 @@
}:
let
- cfg = config.security.polkit;
+ inherit (lib)
+ mkEnableOption
+ mkOption
+ mkIf
+ mkPackageOption
+ mkRemovedOptionModule
+ types
+ ;
+ cfg = config.security.polkit;
in
{
+ imports = [
+ (mkRemovedOptionModule [ "security" "polkit" "debug" ] "Use security.polkit.extraArgs instead")
+ ];
- options = {
+ options.security.polkit = {
+ enable = mkEnableOption "polkit";
- security.polkit.enable = lib.mkEnableOption "polkit";
+ enablePkexecWrapper = mkEnableOption "the setuid pkexec wrapper";
- security.polkit.package = lib.mkPackageOption pkgs "polkit" { };
+ package = mkPackageOption pkgs "polkit" { };
- security.polkit.debug = lib.mkEnableOption "debug logs from polkit. This is required in order to see log messages from rule definitions";
+ extraArgs = mkOption {
+ type = types.listOf types.str;
+ default = [
+ "--no-debug"
+ "--log-level=notice"
+ ];
+ description = ''
+ List of arguments to pass to the polkitd executable.
- security.polkit.extraConfig = lib.mkOption {
- type = lib.types.lines;
+ ::: {.note}
+ To see debug logs you need to negate the default `--no-debug` setting.
+ :::
+ '';
+ };
+
+ extraConfig = mkOption {
+ type = types.lines;
default = "";
example = ''
/* Log authorization checks. */
polkit.addRule(function(action, subject) {
- // Make sure to set { security.polkit.debug = true; } in configuration.nix
+ // Make sure to negate --no-debug in services.polkit.extraArgs: { security.polkit.extraArgs = [ "--log-level=notice" ]; }
polkit.log("user " + subject.user + " is attempting action " + action.id + " from PID " + subject.pid);
});
@@ -41,8 +66,8 @@ in
'';
};
- security.polkit.adminIdentities = lib.mkOption {
- type = lib.types.listOf lib.types.str;
+ adminIdentities = mkOption {
+ type = with types; listOf str;
default = [ "unix-group:wheel" ];
example = [
"unix-user:alice"
@@ -58,25 +83,34 @@ in
};
- config = lib.mkIf cfg.enable {
+ config = mkIf cfg.enable {
environment.systemPackages = [
cfg.package.bin
cfg.package.out
];
+ services.dbus.packages = [ cfg.package.out ];
+
systemd.packages = [ cfg.package.out ];
- systemd.services.polkit.serviceConfig.ExecStart = [
- ""
- "${cfg.package.out}/lib/polkit-1/polkitd ${lib.optionalString (!cfg.debug) "--no-debug"}"
- ];
-
- systemd.services.polkit.restartTriggers = [ config.system.path ];
- systemd.services.polkit.reloadTriggers = [
- config.environment.etc."polkit-1/rules.d/10-nixos.rules".source
- ];
- systemd.services.polkit.stopIfChanged = false;
+ systemd.services.polkit = {
+ restartTriggers = [ config.system.path ];
+ reloadTriggers = [
+ config.environment.etc."polkit-1/rules.d/10-nixos.rules".source
+ ];
+ serviceConfig.ExecStart = [
+ # nuke default ExecStart
+ ""
+ # provide our own instead
+ (toString (
+ [
+ "${lib.getLib cfg.package}/lib/polkit-1/polkitd"
+ ]
+ ++ cfg.extraArgs
+ ))
+ ];
+ };
systemd.sockets."polkit-agent-helper".wantedBy = [ "sockets.target" ];
@@ -89,7 +123,7 @@ in
# The upstream unit uses PrivateDevices=yes and ProtectHome=yes,
# which prevents PAM modules from accessing hardware (e.g. FIDO
# tokens via /dev/hidraw*) or reading key files from home directories.
- (lib.mkIf config.security.pam.u2f.enable {
+ (mkIf config.security.pam.u2f.enable {
# Override upstream PrivateDevices=yes to allow access to /dev/hidraw*
PrivateDevices = false;
DeviceAllow = [
@@ -100,7 +134,7 @@ in
# ~/.config/Yubico/u2f_keys (the default key file location)
ProtectHome = "read-only";
})
- (lib.mkIf config.security.pam.zfs.enable {
+ (mkIf config.security.pam.zfs.enable {
PrivateDevices = false;
DeviceAllow = [
"/dev/zfs rw"
@@ -120,23 +154,16 @@ in
${cfg.extraConfig}
''; # TODO: validation on compilation (at least against typos)
- services.dbus.packages = [ cfg.package.out ];
-
security.pam.services.polkit-1 = { };
security.wrappers.pkexec = {
+ enable = cfg.enablePkexecWrapper;
setuid = true;
owner = "root";
group = "root";
- source = "${cfg.package.bin}/bin/pkexec";
+ source = lib.getExe' cfg.package "pkexec";
};
- systemd.tmpfiles.rules = [
- # Probably no more needed, clean up
- "R /var/lib/polkit-1"
- "R /var/lib/PolicyKit"
- ];
-
users.users.polkituser = {
description = "PolKit daemon";
uid = config.ids.uids.polkituser;
diff --git a/nixos/modules/security/run0.nix b/nixos/modules/security/run0.nix
index 22296a76c95e..6aa7f9ad3155 100644
--- a/nixos/modules/security/run0.nix
+++ b/nixos/modules/security/run0.nix
@@ -6,6 +6,13 @@
}:
let
+ inherit (lib)
+ mkEnableOption
+ mkIf
+ mkMerge
+ mkOption
+ ;
+
cfg = config.security.run0;
sudoAlias = pkgs.writeShellScriptBin "sudo" ''
@@ -18,7 +25,9 @@ let
in
{
options.security.run0 = {
- wheelNeedsPassword = lib.mkOption {
+ enable = mkEnableOption "support for run0";
+
+ wheelNeedsPassword = mkOption {
type = lib.types.bool;
default = true;
description = ''
@@ -27,26 +36,45 @@ in
'';
};
- enableSudoAlias = lib.mkEnableOption "make {command}`sudo` an alias to {command}`run0`.";
+ enableSudoAlias = mkEnableOption "make {command}`sudo` an alias to {command}`run0`.";
};
- config = {
- assertions = [
- {
- assertion =
- cfg.enableSudoAlias -> (!config.security.sudo.enable && !config.security.sudo-rs.enable);
- message = "`security.run0.enableSudoAlias` cannot be enabled if `security.sudo` or `security.sudo-rs` are enabled.";
- }
- ];
-
- security.polkit.extraConfig = lib.mkIf (!cfg.wheelNeedsPassword) ''
- polkit.addRule(function(action, subject) {
- if (action.id == "org.freedesktop.systemd1.manage-units" && subject.isInGroup("wheel")) {
- return polkit.Result.YES;
+ config = mkMerge [
+ {
+ # Late introduction of the enable toggle, this should help during migration.
+ # TODO: Remove after 26.11 release
+ assertions = [
+ {
+ assertion = !cfg.wheelNeedsPassword -> cfg.enable;
+ message = "`security.run0.enable` is currently disabled, but is required for the `security.run0.wheelNeedsPassword` option to take effect";
}
- });
- '';
+ {
+ assertion = cfg.enableSudoAlias -> cfg.enable;
+ message = "`security.run0.enableSudoAlias` depends on `security.run0.enable`, which is disabled.";
+ }
+ ];
+ }
+ (mkIf cfg.enable {
+ assertions = [
+ {
+ assertion =
+ cfg.enableSudoAlias -> (!config.security.sudo.enable && !config.security.sudo-rs.enable);
+ message = "`security.run0.enableSudoAlias` cannot be enabled if `security.sudo` or `security.sudo-rs` are enabled.";
+ }
+ ];
- environment.systemPackages = lib.optional cfg.enableSudoAlias sudoAlias;
- };
+ security.polkit = {
+ enable = true;
+ extraConfig = mkIf (!cfg.wheelNeedsPassword) ''
+ polkit.addRule(function(action, subject) {
+ if (action.id == "org.freedesktop.systemd1.manage-units" && subject.isInGroup("wheel")) {
+ return polkit.Result.YES;
+ }
+ });
+ '';
+ };
+
+ environment.systemPackages = lib.optional cfg.enableSudoAlias sudoAlias;
+ })
+ ];
}
diff --git a/nixos/modules/services/desktop-managers/budgie.nix b/nixos/modules/services/desktop-managers/budgie.nix
index 29bdb469d7f1..807d6b019b72 100644
--- a/nixos/modules/services/desktop-managers/budgie.nix
+++ b/nixos/modules/services/desktop-managers/budgie.nix
@@ -243,6 +243,8 @@ in
# Required by Budgie's Polkit Dialog.
security.polkit.enable = mkDefault true;
+ # Required by Budige's Control Center and Desktop
+ security.polkit.enablePkexecWrapper = mkDefault true;
# Required by Budgie Panel plugins and/or Budgie Control Center panels.
networking.networkmanager.enable = mkDefault true; # for BCC's Network panel.
diff --git a/nixos/modules/services/desktop-managers/cosmic.nix b/nixos/modules/services/desktop-managers/cosmic.nix
index c780a5164922..3d367f01defe 100644
--- a/nixos/modules/services/desktop-managers/cosmic.nix
+++ b/nixos/modules/services/desktop-managers/cosmic.nix
@@ -146,7 +146,10 @@ in
environment.sessionVariables.X11_EXTRA_RULES_XML = "${config.services.xserver.xkb.dir}/rules/base.extras.xml";
programs.dconf.enable = true;
programs.dconf.packages = [ pkgs.cosmic-session ];
- security.polkit.enable = true;
+ security.polkit = {
+ enable = true;
+ enablePkexecWrapper = lib.mkDefault true;
+ };
security.rtkit.enable = true;
services.accounts-daemon.enable = true;
services.displayManager.sessionPackages = [ pkgs.cosmic-session ];
diff --git a/nixos/modules/services/desktop-managers/gnome.nix b/nixos/modules/services/desktop-managers/gnome.nix
index 3747a491098f..1d850f1f26e5 100644
--- a/nixos/modules/services/desktop-managers/gnome.nix
+++ b/nixos/modules/services/desktop-managers/gnome.nix
@@ -325,7 +325,11 @@ in
i18n.inputMethod.enable = mkDefault true;
i18n.inputMethod.type = mkDefault "ibus";
programs.dconf.enable = true;
- security.polkit.enable = true;
+ security.polkit = {
+ enable = true;
+ # Required by gnome-initial-setup, gnome-system-monitor, gvfs for admin://
+ enablePkexecWrapper = lib.mkDefault true;
+ };
security.rtkit.enable = mkDefault true;
services.accounts-daemon.enable = true;
services.dleyna.enable = mkDefault true;
diff --git a/nixos/modules/services/desktops/gnome/gnome-remote-desktop.nix b/nixos/modules/services/desktops/gnome/gnome-remote-desktop.nix
index 958fbb546dc3..eaa9399862a4 100644
--- a/nixos/modules/services/desktops/gnome/gnome-remote-desktop.nix
+++ b/nixos/modules/services/desktops/gnome/gnome-remote-desktop.nix
@@ -22,6 +22,10 @@
config = lib.mkIf config.services.gnome.gnome-remote-desktop.enable {
services.pipewire.enable = true;
services.dbus.packages = [ pkgs.gnome-remote-desktop ];
+ security.polkit = {
+ enable = true;
+ enablePkexecWrapper = lib.mkDefault true;
+ };
environment.systemPackages = [ pkgs.gnome-remote-desktop ];
diff --git a/nixos/modules/services/hardware/tuned.nix b/nixos/modules/services/hardware/tuned.nix
index 65a857f4fde8..f399dc55c306 100644
--- a/nixos/modules/services/hardware/tuned.nix
+++ b/nixos/modules/services/hardware/tuned.nix
@@ -246,7 +246,10 @@ in
systemPackages = [ cfg.package ];
};
- security.polkit.enable = lib.mkDefault true;
+ security.polkit = {
+ enable = lib.mkDefault true;
+ enablePkexecWrapper = lib.mkDefault true;
+ };
services = {
dbus.packages = [ cfg.package ];
diff --git a/nixos/modules/services/x11/desktop-managers/cinnamon.nix b/nixos/modules/services/x11/desktop-managers/cinnamon.nix
index a91fa045aa7a..738aaa000a79 100644
--- a/nixos/modules/services/x11/desktop-managers/cinnamon.nix
+++ b/nixos/modules/services/x11/desktop-managers/cinnamon.nix
@@ -111,7 +111,10 @@ in
services.blueman.enable = mkDefault (notExcluded pkgs.blueman);
services.hardware.bolt.enable = mkDefault (notExcluded pkgs.bolt);
hardware.bluetooth.enable = mkDefault true;
- security.polkit.enable = true;
+ security.polkit = {
+ enable = true;
+ enablePkexecWrapper = lib.mkDefault true;
+ };
services.accounts-daemon.enable = true;
services.system-config-printer.enable = (mkIf config.services.printing.enable (mkDefault true));
services.dbus.packages = with pkgs; [
diff --git a/nixos/modules/services/x11/desktop-managers/xfce.nix b/nixos/modules/services/x11/desktop-managers/xfce.nix
index 2d53eb58f287..3dcc5431e7c8 100644
--- a/nixos/modules/services/x11/desktop-managers/xfce.nix
+++ b/nixos/modules/services/x11/desktop-managers/xfce.nix
@@ -220,7 +220,10 @@ in
# Enable helpful DBus services.
services.udisks2.enable = true;
- security.polkit.enable = true;
+ security.polkit = {
+ enable = true;
+ enablePkexecWrapper = lib.mkDefault true;
+ };
services.accounts-daemon.enable = true;
services.upower.enable = config.powerManagement.enable;
services.gnome.glib-networking.enable = true;
diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix
index 3ea6c4f25598..93ec2703c3e5 100644
--- a/nixos/tests/all-tests.nix
+++ b/nixos/tests/all-tests.nix
@@ -1700,6 +1700,7 @@ in
tiddlywiki = runTest ./tiddlywiki.nix;
tigervnc = handleTest ./tigervnc.nix { };
tika = runTest ./tika.nix;
+ timekpr = runTest ./timekpr.nix;
timezone = runTest ./timezone.nix;
timidity = handleTestOn [ "aarch64-linux" "x86_64-linux" ] ./timidity { };
tinc = handleTest ./tinc { };
diff --git a/nixos/tests/lomiri.nix b/nixos/tests/lomiri.nix
index 5dc43286c0f3..61893abe91a1 100644
--- a/nixos/tests/lomiri.nix
+++ b/nixos/tests/lomiri.nix
@@ -669,7 +669,7 @@ in
# Doing this here, since we need an in-session shell & separately starting a terminal again wastes time
with subtest("polkit agent works"):
- machine.send_chars("pkexec touch /tmp/polkit-test\n")
+ machine.send_chars("run0 touch /tmp/polkit-test\n")
# There's an authentication notification here that gains focus, but we struggle with OCRing it
# Just hope that it's up after a short wait
machine.sleep(10)
diff --git a/nixos/tests/rtkit.nix b/nixos/tests/rtkit.nix
index 74bf69e02a83..295fd36a1391 100644
--- a/nixos/tests/rtkit.nix
+++ b/nixos/tests/rtkit.nix
@@ -55,7 +55,7 @@
# Provide a little logging of polkit checks - otherwise it's
# impossible to know what's going on.
- security.polkit.debug = true;
+ security.polkit.extraArgs = [ "--log-level=notice" ];
security.polkit.extraConfig = ''
polkit.addRule(function(action, subject) {
const ns = "org.freedesktop.RealtimeKit1.";
diff --git a/nixos/tests/timekpr.nix b/nixos/tests/timekpr.nix
index 1ae793d8f70e..9f832d2b62dd 100644
--- a/nixos/tests/timekpr.nix
+++ b/nixos/tests/timekpr.nix
@@ -1,13 +1,15 @@
-{ pkgs, lib, ... }:
+{
+ lib,
+ ...
+}:
+
{
name = "timekpr";
meta.maintainers = [ lib.maintainers.atry ];
- nodes.machine =
- { pkgs, lib, ... }:
- {
- services.timekpr.enable = true;
- };
+ containers.machine = {
+ services.timekpr.enable = true;
+ };
testScript = ''
start_all()
diff --git a/pkgs/by-name/ni/nixos-firewall-tool/package.nix b/pkgs/by-name/ni/nixos-firewall-tool/package.nix
index f0245905a902..08cf7b138c8a 100644
--- a/pkgs/by-name/ni/nixos-firewall-tool/package.nix
+++ b/pkgs/by-name/ni/nixos-firewall-tool/package.nix
@@ -7,8 +7,8 @@
}:
stdenvNoCC.mkDerivation {
- name = "nixos-firewall-tool";
-
+ pname = "nixos-firewall-tool";
+ version = lib.trivial.release;
src = builtins.filterSource (name: _: !(lib.hasSuffix ".nix" name)) ./.;
strictDeps = true;
diff --git a/pkgs/by-name/qe/qemu/package.nix b/pkgs/by-name/qe/qemu/package.nix
index dea71a96bd84..34d22a285da4 100644
--- a/pkgs/by-name/qe/qemu/package.nix
+++ b/pkgs/by-name/qe/qemu/package.nix
@@ -140,11 +140,11 @@ stdenv.mkDerivation (finalAttrs: {
+ lib.optionalString nixosTestRunner "-for-vm-tests"
+ lib.optionalString toolsOnly "-utils"
+ lib.optionalString userOnly "-user";
- version = "11.0.0";
+ version = "11.0.1";
src = fetchurl {
url = "https://download.qemu.org/qemu-${finalAttrs.version}.tar.xz";
- hash = "sha256-wEyjYBJlPzLRHGdNNwz1KnEOfT8Ywti2PkkyBSpIVNY=";
+ hash = "sha256-DSNfWCAnjZFKMVXsJ6+OQljWl+qJKJVXCAfWnAy4zWQ=";
};
depsBuildBuild = [
diff --git a/pkgs/by-name/ru/ruff/package.nix b/pkgs/by-name/ru/ruff/package.nix
index 8566e5251408..8aa8f51b8273 100644
--- a/pkgs/by-name/ru/ruff/package.nix
+++ b/pkgs/by-name/ru/ruff/package.nix
@@ -16,7 +16,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "ruff";
- version = "0.15.16";
+ version = "0.15.17";
__structuredAttrs = true;
@@ -24,12 +24,12 @@ rustPlatform.buildRustPackage (finalAttrs: {
owner = "astral-sh";
repo = "ruff";
tag = finalAttrs.version;
- hash = "sha256-krmHCLijp+D4gBjKV9cdicPob4ry5I6QwB3MUz0z7zA=";
+ hash = "sha256-+UsKRBe+lp/LdsmK/W11wCt2RypEryA5eBPb01OKCJw=";
};
cargoBuildFlags = [ "--package=ruff" ];
- cargoHash = "sha256-d2iV7iWf7lVhj1Bbaxxk5Zao4KK3oC7whppRvk0erzA=";
+ cargoHash = "sha256-y1sKf+KXya/K+WUiIE357U6DXh/d+AQgj0SQIi1gpUw=";
nativeBuildInputs = [ installShellFiles ];
diff --git a/pkgs/by-name/ty/ty/package.nix b/pkgs/by-name/ty/ty/package.nix
index c1a1f061bebe..41db756b4492 100644
--- a/pkgs/by-name/ty/ty/package.nix
+++ b/pkgs/by-name/ty/ty/package.nix
@@ -17,7 +17,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "ty";
- version = "0.0.46";
+ version = "0.0.49";
__structuredAttrs = true;
src = fetchFromGitHub {
@@ -25,7 +25,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
repo = "ty";
tag = finalAttrs.version;
fetchSubmodules = true;
- hash = "sha256-IZgQduqsQU8wMu0yW3SYypEzAJ0gmDObTJ75xG88xbA=";
+ hash = "sha256-IKeoskueujGYFjhUd3V7iwKwZjFZqG3OYfe36S6J2aw=";
};
# For Darwin platforms, remove the integration test for file notifications,
@@ -39,7 +39,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
cargoBuildFlags = [ "--package=ty" ];
- cargoHash = "sha256-rSvaYddm5n1qtPRHfY6du0aA1t2TsIqzTPnHQ9NHMP8=";
+ cargoHash = "sha256-y1sKf+KXya/K+WUiIE357U6DXh/d+AQgj0SQIi1gpUw=";
nativeBuildInputs = [ installShellFiles ];
buildInputs = [ rust-jemalloc-sys ];
diff --git a/pkgs/os-specific/linux/kernel/common-config.nix b/pkgs/os-specific/linux/kernel/common-config.nix
index f89fa487bfe2..91bea44bf1a7 100644
--- a/pkgs/os-specific/linux/kernel/common-config.nix
+++ b/pkgs/os-specific/linux/kernel/common-config.nix
@@ -1420,13 +1420,10 @@ let
DRM_AMDGPU_USERPTR = yes;
# We want to prefer PREEMPT_LAZY when available, and fall back on PREEMPT_VOLUNTARY.
- # It just so happens that kconfig asks for PREEMPT_LAZY first, so doing it like this
- # does what we want.
- # FIXME: This is stupid and bad.
- # See: https://github.com/torvalds/linux/commit/7dadeaa6e851e7d67733f3e24fc53ee107781d0f
+ # The version cutoff is arbitrary, the real cutoff is somewhere around 6.13 depending on target.
PREEMPT = no;
- PREEMPT_LAZY = option yes;
- PREEMPT_VOLUNTARY = option yes;
+ PREEMPT_LAZY = whenAtLeast "6.18" yes;
+ PREEMPT_VOLUNTARY = whenOlder "6.18" yes;
X86_AMD_PLATFORM_DEVICE = lib.mkIf stdenv.hostPlatform.isx86 yes;
X86_PLATFORM_DRIVERS_DELL = lib.mkIf stdenv.hostPlatform.isx86 (whenAtLeast "5.12" yes);
diff --git a/pkgs/os-specific/linux/kernel/generate-config.pl b/pkgs/os-specific/linux/kernel/generate-config.pl
index 57d3ab739cb6..18d1f2150562 100644
--- a/pkgs/os-specific/linux/kernel/generate-config.pl
+++ b/pkgs/os-specific/linux/kernel/generate-config.pl
@@ -100,7 +100,13 @@ sub runConfig {
elsif ($line =~ /choice\[(.*)\]: ###$/) {
my $answer = "";
foreach my $name (keys %choices) {
- $answer = $choices{$name} if ($answers{$name} || "") eq "y";
+ if (($answers{$name} || "") eq "y") {
+ if ($answer eq "") {
+ $answer = $choices{$name};
+ } else {
+ die "conflicting answers!"
+ }
+ }
}
print STDERR "CHOICE: $1, ANSWER: $answer\n" if $debug;
print OUT "$answer\n" if $1 =~ /-/;
diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json
index a44bc74bacac..43db58a4181e 100644
--- a/pkgs/os-specific/linux/kernel/kernels-org.json
+++ b/pkgs/os-specific/linux/kernel/kernels-org.json
@@ -38,5 +38,10 @@
"version": "7.0.12",
"hash": "sha256:1nk5lans9qg1avmmcwyadfps43d3hyjz9a5gjyvsc77w3sjckvap",
"lts": false
+ },
+ "7.1": {
+ "version": "7.1",
+ "hash": "sha256:18344l5fv3hgsqjrjr3dgg96lll7f294qq11lg40sydygxwl87v9",
+ "lts": false
}
}
diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix
index fdcfe380b116..dac97a477fa5 100644
--- a/pkgs/top-level/aliases.nix
+++ b/pkgs/top-level/aliases.nix
@@ -1277,6 +1277,7 @@ mapAliases {
linux_6_18 = linuxKernel.kernels.linux_6_18;
linux_6_19 = linuxKernel.kernels.linux_6_19;
linux_7_0 = linuxKernel.kernels.linux_7_0;
+ linux_7_1 = linuxKernel.kernels.linux_7_1;
linux_ham = throw "linux_ham has been removed in favour of the standard kernel packages"; # Added 2025-06-24
linux_hardened = throw "linux_hardened has been removed due to lack of maintenance"; # Added 2026-03-18
linux_latest-libre = throw "linux_latest_libre has been removed due to lack of maintenance"; # Added 2025-10-01
@@ -1312,6 +1313,7 @@ mapAliases {
linuxPackages_6_18 = linuxKernel.packages.linux_6_18;
linuxPackages_6_19 = linuxKernel.packages.linux_6_19;
linuxPackages_7_0 = linuxKernel.packages.linux_7_0;
+ linuxPackages_7_1 = linuxKernel.packages.linux_7_1;
linuxPackages_ham = throw "linux_ham has been removed in favour of the standard kernel packages"; # Added 2025-06-24
linuxPackages_hardened = throw "linuxPackages_hardened has been removed due to lack of maintenance"; # Added 2026-03-18
linuxPackages_latest-libre = throw "linux_latest_libre has been removed due to lack of maintenance"; # Added 2025-10-01
diff --git a/pkgs/top-level/linux-kernels.nix b/pkgs/top-level/linux-kernels.nix
index ddf456a49931..ccd896e616ee 100644
--- a/pkgs/top-level/linux-kernels.nix
+++ b/pkgs/top-level/linux-kernels.nix
@@ -100,6 +100,14 @@ in
];
};
+ linux_7_1 = callPackage ../os-specific/linux/kernel/mainline.nix {
+ branch = "7.1";
+ kernelPatches = [
+ kernelPatches.bridge_stp_helper
+ kernelPatches.request_key_helper
+ ];
+ };
+
linux_testing =
let
testing = callPackage ../os-specific/linux/kernel/mainline.nix {
@@ -667,6 +675,7 @@ in
linux_6_12 = recurseIntoAttrs (packagesFor kernels.linux_6_12);
linux_6_18 = recurseIntoAttrs (packagesFor kernels.linux_6_18);
linux_7_0 = recurseIntoAttrs (packagesFor kernels.linux_7_0);
+ linux_7_1 = recurseIntoAttrs (packagesFor kernels.linux_7_1);
}
// lib.optionalAttrs config.allowAliases {
linux_4_19 = throw "linux 4.19 was removed because it will reach its end of life within 24.11"; # Added 2024-09-21
@@ -735,7 +744,7 @@ in
packageAliases = {
linux_default = packages.linux_6_18;
# Update this when adding the newest kernel major version!
- linux_latest = packages.linux_7_0;
+ linux_latest = packages.linux_7_1;
}
// lib.optionalAttrs config.allowAliases {
linux_mptcp = throw "'linux_mptcp' has been moved to https://github.com/teto/mptcp-flake";