diff --git a/nixos/doc/manual/from_md/release-notes/rl-2205.section.xml b/nixos/doc/manual/from_md/release-notes/rl-2205.section.xml
index 89b23678454c..d97a27002158 100644
--- a/nixos/doc/manual/from_md/release-notes/rl-2205.section.xml
+++ b/nixos/doc/manual/from_md/release-notes/rl-2205.section.xml
@@ -1666,9 +1666,20 @@
- services.logrotate.enable now defaults to
- true if any rotate path has been defined, and some paths have
- been added by default.
+ services.logrotate.enable
+ now defaults to true if any rotate path has been defined, and
+ some paths have been added by default.
+
+
+
+
+ The logrotate module also has been updated to freeform syntax:
+ services.logrotate.paths
+ and
+ services.logrotate.extraConfig
+ will work, but issue deprecation warnings and
+ services.logrotate.settings
+ should now be used instead.
diff --git a/nixos/doc/manual/release-notes/rl-2205.section.md b/nixos/doc/manual/release-notes/rl-2205.section.md
index 4918d8460b58..4d099bf7572e 100644
--- a/nixos/doc/manual/release-notes/rl-2205.section.md
+++ b/nixos/doc/manual/release-notes/rl-2205.section.md
@@ -582,8 +582,11 @@ In addition to numerous new and upgraded packages, this release has the followin
- `services.mattermost.plugins` has been added to allow the declarative installation of Mattermost plugins.
Plugins are automatically repackaged using autoPatchelf.
-- `services.logrotate.enable` now defaults to true if any rotate path has
+- [services.logrotate.enable](#opt-services.logrotate.enable) now defaults to true if any rotate path has
been defined, and some paths have been added by default.
+- The logrotate module also has been updated to freeform syntax: [services.logrotate.paths](#opt-services.logrotate.paths)
+ and [services.logrotate.extraConfig](#opt-services.logrotate.extraConfig) will work, but issue deprecation
+ warnings and [services.logrotate.settings](#opt-services.logrotate.settings) should now be used instead.
- The `zrepl` package has been updated from 0.4.0 to 0.5:
diff --git a/nixos/modules/services/logging/logrotate.nix b/nixos/modules/services/logging/logrotate.nix
index 082cf92ff4ef..332a2a597edc 100644
--- a/nixos/modules/services/logging/logrotate.nix
+++ b/nixos/modules/services/logging/logrotate.nix
@@ -5,7 +5,10 @@ with lib;
let
cfg = config.services.logrotate;
- pathOpts = { name, ... }: {
+ # deprecated legacy compat settings
+ # these options will be removed before 22.11 in the following PR:
+ # https://github.com/NixOS/nixpkgs/pull/164169
+ pathOpts = { name, ... }: {
options = {
enable = mkOption {
type = types.bool;
@@ -86,23 +89,113 @@ let
config.name = name;
};
- mkConf = pathOpts: ''
- # generated by NixOS using the `services.logrotate.paths.${pathOpts.name}` attribute set
- ${concatMapStringsSep " " (path: ''"${path}"'') (toList pathOpts.path)} {
- ${optionalString (pathOpts.user != null || pathOpts.group != null) "su ${pathOpts.user} ${pathOpts.group}"}
- ${pathOpts.frequency}
- rotate ${toString pathOpts.keep}
- ${pathOpts.extraConfig}
- }
- '';
-
- paths = sortProperties (attrValues (filterAttrs (_: pathOpts: pathOpts.enable) cfg.paths));
- configFile = pkgs.writeText "logrotate.conf" (
- concatStringsSep "\n" (
- [ "missingok" "notifempty" cfg.extraConfig ] ++ (map mkConf paths)
- )
+ generateLine = n: v:
+ if builtins.elem n [ "files" "priority" "enable" "global" ] || v == null then null
+ else if builtins.elem n [ "extraConfig" "frequency" ] then "${v}\n"
+ else if builtins.elem n [ "firstaction" "lastaction" "prerotate" "postrotate" "preremove" ]
+ then "${n}\n ${v}\n endscript\n"
+ else if isInt v then "${n} ${toString v}\n"
+ else if v == true then "${n}\n"
+ else if v == false then "no${n}\n"
+ else "${n} ${v}\n";
+ generateSection = indent: settings: concatStringsSep (fixedWidthString indent " " "") (
+ filter (x: x != null) (mapAttrsToList generateLine settings)
);
+ # generateSection includes a final newline hence weird closing brace
+ mkConf = settings:
+ if settings.global or false then generateSection 0 settings
+ else ''
+ ${concatMapStringsSep "\n" (files: ''"${files}"'') (toList settings.files)} {
+ ${generateSection 2 settings}}
+ '';
+
+ # below two mapPaths are compat functions
+ mapPathOptToSetting = n: v:
+ if n == "keep" then nameValuePair "rotate" v
+ else if n == "path" then nameValuePair "files" v
+ else nameValuePair n v;
+
+ mapPathsToSettings = path: pathOpts:
+ nameValuePair path (
+ filterAttrs (n: v: ! builtins.elem n [ "user" "group" "name" ] && v != "") (
+ (mapAttrs' mapPathOptToSetting pathOpts) //
+ {
+ su =
+ if pathOpts.user != null
+ then "${pathOpts.user} ${pathOpts.group}"
+ else null;
+ }
+ )
+ );
+
+ settings = sortProperties (attrValues (filterAttrs (_: settings: settings.enable) (
+ foldAttrs recursiveUpdate { } [
+ {
+ header = {
+ enable = true;
+ missingok = true;
+ notifempty = true;
+ frequency = "weekly";
+ rotate = 4;
+ };
+ # compat section
+ extraConfig = {
+ enable = (cfg.extraConfig != "");
+ global = true;
+ extraConfig = cfg.extraConfig;
+ priority = 101;
+ };
+ }
+ (mapAttrs' mapPathsToSettings cfg.paths)
+ cfg.settings
+ { header = { global = true; priority = 100; }; }
+ ]
+ )));
+ configFile = pkgs.writeTextFile {
+ name = "logrotate.conf";
+ text = concatStringsSep "\n" (
+ map mkConf settings
+ );
+ checkPhase = optionalString cfg.checkConfig ''
+ # logrotate --debug also checks that users specified in config
+ # file exist, but we only have sandboxed users here so brown these
+ # out. according to man page that means su, create and createolddir.
+ # files required to exist also won't be present, so missingok is forced.
+ user=$(${pkgs.coreutils}/bin/id -un)
+ group=$(${pkgs.coreutils}/bin/id -gn)
+ sed -e "s/\bsu\s.*/su $user $group/" \
+ -e "s/\b\(create\s\+[0-9]*\s*\|createolddir\s\+[0-9]*\s\+\).*/\1$user $group/" \
+ -e "1imissingok" -e "s/\bnomissingok\b//" \
+ $out > /tmp/logrotate.conf
+ # Since this makes for very verbose builds only show real error.
+ # There is no way to control log level, but logrotate hardcodes
+ # 'error:' at common log level, so we can use grep, taking care
+ # to keep error codes
+ set -o pipefail
+ if ! ${pkgs.logrotate}/sbin/logrotate --debug /tmp/logrotate.conf 2>&1 \
+ | ( ! grep "error:" ) > /tmp/logrotate-error; then
+ echo "Logrotate configuration check failed."
+ echo "The failing configuration (after adjustments to pass tests in sandbox) was:"
+ printf "%s\n" "-------"
+ cat /tmp/logrotate.conf
+ printf "%s\n" "-------"
+ echo "The error reported by logrotate was as follow:"
+ printf "%s\n" "-------"
+ cat /tmp/logrotate-error
+ printf "%s\n" "-------"
+ echo "You can disable this check with services.logrotate.checkConfig = false,"
+ echo "but if you think it should work please report this failure along with"
+ echo "the config file being tested!"
+ false
+ fi
+ '';
+ };
+
+ mailOption =
+ if foldr (n: a: a || n ? mail) false (attrValues cfg.settings)
+ then "--mail=${pkgs.mailutils}/bin/mail"
+ else "";
in
{
imports = [
@@ -112,17 +205,121 @@ in
options = {
services.logrotate = {
enable = mkEnableOption "the logrotate systemd service" // {
- default = foldr (n: a: a || n.enable) false (attrValues cfg.paths);
- defaultText = literalExpression "cfg.paths != {}";
+ default = foldr (n: a: a || n.enable) false (attrValues cfg.settings);
+ defaultText = literalExpression "cfg.settings != {}";
};
+ settings = mkOption {
+ default = { };
+ description = ''
+ logrotate freeform settings: each attribute here will define its own section,
+ ordered by priority, which can either define files to rotate with their settings
+ or settings common to all further files settings.
+ Refer to for details.
+ '';
+ type = types.attrsOf (types.submodule ({ name, ... }: {
+ freeformType = with types; attrsOf (nullOr (oneOf [ int bool str ]));
+
+ options = {
+ enable = mkEnableOption "setting individual kill switch" // {
+ default = true;
+ };
+
+ global = mkOption {
+ type = types.bool;
+ default = false;
+ description = ''
+ Whether this setting is a global option or not: set to have these
+ settings apply to all files settings with a higher priority.
+ '';
+ };
+ files = mkOption {
+ type = with types; either str (listOf str);
+ default = name;
+ defaultText = ''
+ The attrset name if not specified
+ '';
+ description = ''
+ Single or list of files for which rules are defined.
+ The files are quoted with double-quotes in logrotate configuration,
+ so globs and spaces are supported.
+ Note this setting is ignored if globals is true.
+ '';
+ };
+
+ frequency = mkOption {
+ type = types.nullOr types.str;
+ default = null;
+ description = ''
+ How often to rotate the logs. Defaults to previously set global setting,
+ which itself defauts to weekly.
+ '';
+ };
+
+ priority = mkOption {
+ type = types.int;
+ default = 1000;
+ description = ''
+ Order of this logrotate block in relation to the others. The semantics are
+ the same as with `lib.mkOrder`. Smaller values are inserted first.
+ '';
+ };
+ };
+
+ }));
+ };
+
+ configFile = mkOption {
+ type = types.path;
+ default = configFile;
+ defaultText = ''
+ A configuration file automatically generated by NixOS.
+ '';
+ description = ''
+ Override the configuration file used by MySQL. By default,
+ NixOS generates one automatically from .
+ '';
+ example = literalExpression ''
+ pkgs.writeText "logrotate.conf" '''
+ missingok
+ "/var/log/*.log" {
+ rotate 4
+ weekly
+ }
+ ''';
+ '';
+ };
+
+ checkConfig = mkOption {
+ type = types.bool;
+ default = true;
+ description = ''
+ Whether the config should be checked at build time.
+
+ Some options are not checkable at build time because of the build sandbox:
+ for example, the test does not know about existing files and system users are
+ not known.
+ These limitations mean we must adjust the file for tests (missingok is forced
+ and users are replaced by dummy users), so tests are complemented by a
+ logrotate-checkconf service that is enabled by default.
+ This extra check can be disabled by disabling it at the systemd level with the
+ option.
+
+ Conversely there are still things that might make this check fail incorrectly
+ (e.g. a file path where we don't have access to intermediate directories):
+ in this case you can disable the failing check with this option.
+ '';
+ };
+
+ # deprecated legacy compat settings
paths = mkOption {
type = with types; attrsOf (submodule pathOpts);
- default = {};
+ default = { };
description = ''
Attribute set of paths to rotate. The order each block appears in the generated configuration file
can be controlled by the priority option
using the same semantics as `lib.mkOrder`. Smaller values have a greater priority.
+ This setting has been deprecated in favor of logrotate settings.
'';
example = literalExpression ''
{
@@ -151,19 +348,37 @@ in
description = ''
Extra contents to append to the logrotate configuration file. Refer to
for details.
+ This setting has been deprecated in favor of
+ logrotate settings.
'';
};
};
};
config = mkIf cfg.enable {
- assertions = mapAttrsToList (name: pathOpts:
- { assertion = (pathOpts.user != null) == (pathOpts.group != null);
- message = ''
- If either of `services.logrotate.paths.${name}.user` or `services.logrotate.paths.${name}.group` are specified then *both* must be specified.
- '';
- }
- ) cfg.paths;
+ assertions =
+ mapAttrsToList
+ (name: pathOpts:
+ {
+ assertion = (pathOpts.user != null) == (pathOpts.group != null);
+ message = ''
+ If either of `services.logrotate.paths.${name}.user` or `services.logrotate.paths.${name}.group` are specified then *both* must be specified.
+ '';
+ })
+ cfg.paths;
+
+ warnings =
+ (mapAttrsToList
+ (name: pathOpts: ''
+ Using config.services.logrotate.paths.${name} is deprecated and will become unsupported in a future release.
+ Please use services.logrotate.settings instead.
+ '')
+ cfg.paths
+ ) ++
+ (optional (cfg.extraConfig != "") ''
+ Using config.services.logrotate.extraConfig is deprecated and will become unsupported in a future release.
+ Please use services.logrotate.settings with globals=true instead.
+ '');
systemd.services.logrotate = {
description = "Logrotate Service";
@@ -172,7 +387,16 @@ in
serviceConfig = {
Restart = "no";
User = "root";
- ExecStart = "${pkgs.logrotate}/sbin/logrotate ${configFile}";
+ ExecStart = "${pkgs.logrotate}/sbin/logrotate ${mailOption} ${cfg.configFile}";
+ };
+ };
+ systemd.services.logrotate-checkconf = {
+ description = "Logrotate configuration check";
+ wantedBy = [ "multi-user.target" ];
+ serviceConfig = {
+ Type = "oneshot";
+ RemainAfterExit = true;
+ ExecStart = "${pkgs.logrotate}/sbin/logrotate --debug ${cfg.configFile}";
};
};
};
diff --git a/nixos/modules/services/misc/gitlab.nix b/nixos/modules/services/misc/gitlab.nix
index e48444f71612..488c3be7b653 100644
--- a/nixos/modules/services/misc/gitlab.nix
+++ b/nixos/modules/services/misc/gitlab.nix
@@ -848,10 +848,7 @@ in {
extraConfig = mkOption {
type = types.lines;
- default = ''
- copytruncate
- compress
- '';
+ default = "";
description = ''
Extra logrotate config options for this path. Refer to
for details.
@@ -977,13 +974,14 @@ in {
# Enable rotation of log files
services.logrotate = {
enable = cfg.logrotate.enable;
- paths = {
+ settings = {
gitlab = {
- path = "${cfg.statePath}/log/*.log";
- user = cfg.user;
- group = cfg.group;
+ files = "${cfg.statePath}/log/*.log";
+ su = "${cfg.user} ${cfg.group}";
frequency = cfg.logrotate.frequency;
- keep = cfg.logrotate.keep;
+ rotate = cfg.logrotate.keep;
+ copytruncate = true;
+ compress = true;
extraConfig = cfg.logrotate.extraConfig;
};
};
diff --git a/nixos/modules/services/networking/lxd-image-server.nix b/nixos/modules/services/networking/lxd-image-server.nix
index b119ba8acf63..d326626eed44 100644
--- a/nixos/modules/services/networking/lxd-image-server.nix
+++ b/nixos/modules/services/networking/lxd-image-server.nix
@@ -51,18 +51,14 @@ in
environment.etc."lxd-image-server/config.toml".source = format.generate "config.toml" cfg.settings;
- services.logrotate.paths.lxd-image-server = {
- path = "/var/log/lxd-image-server/lxd-image-server.log";
+ services.logrotate.settings.lxd-image-server = {
+ files = "/var/log/lxd-image-server/lxd-image-server.log";
frequency = "daily";
- keep = 21;
- extraConfig = ''
- create 755 lxd-image-server ${cfg.group}
- missingok
- compress
- delaycompress
- copytruncate
- notifempty
- '';
+ rotate = 21;
+ create = "755 lxd-image-server ${cfg.group}";
+ compress = true;
+ delaycompress = true;
+ copytruncate = true;
};
systemd.tmpfiles.rules = [
diff --git a/nixos/modules/services/networking/syncplay.nix b/nixos/modules/services/networking/syncplay.nix
index b6faf2d3f772..c17426ecced7 100644
--- a/nixos/modules/services/networking/syncplay.nix
+++ b/nixos/modules/services/networking/syncplay.nix
@@ -61,6 +61,15 @@ in
Group to use when running Syncplay.
'';
};
+
+ passwordFile = mkOption {
+ type = types.nullOr types.path;
+ default = null;
+ description = ''
+ Path to the file that contains the server password. If
+ null, the server doesn't require a password.
+ '';
+ };
};
};
@@ -71,10 +80,17 @@ in
after = [ "network-online.target" ];
serviceConfig = {
- ExecStart = "${pkgs.syncplay}/bin/syncplay-server ${escapeShellArgs cmdArgs}";
User = cfg.user;
Group = cfg.group;
+ LoadCredential = lib.mkIf (cfg.passwordFile != null) "password:${cfg.passwordFile}";
};
+
+ script = ''
+ ${lib.optionalString (cfg.passwordFile != null) ''
+ export SYNCPLAY_PASSWORD=$(cat "''${CREDENTIALS_DIRECTORY}/password")
+ ''}
+ exec ${pkgs.syncplay}/bin/syncplay-server ${escapeShellArgs cmdArgs}
+ '';
};
};
}
diff --git a/nixos/modules/services/web-servers/apache-httpd/default.nix b/nixos/modules/services/web-servers/apache-httpd/default.nix
index d817ff6019a3..3099705acbe2 100644
--- a/nixos/modules/services/web-servers/apache-httpd/default.nix
+++ b/nixos/modules/services/web-servers/apache-httpd/default.nix
@@ -710,20 +710,15 @@ in
services.logrotate = optionalAttrs (cfg.logFormat != "none") {
enable = mkDefault true;
- paths.httpd = {
- path = "${cfg.logDir}/*.log";
- user = cfg.user;
- group = cfg.group;
+ settings.httpd = {
+ files = "${cfg.logDir}/*.log";
+ su = "${cfg.user} ${cfg.group}";
frequency = "daily";
- keep = 28;
- extraConfig = ''
- sharedscripts
- compress
- delaycompress
- postrotate
- systemctl reload httpd.service > /dev/null 2>/dev/null || true
- endscript
- '';
+ rotate = 28;
+ sharedscripts = true;
+ compress = true;
+ delaycompress = true;
+ postrotate = "systemctl reload httpd.service > /dev/null 2>/dev/null || true";
};
};
diff --git a/nixos/modules/services/web-servers/nginx/default.nix b/nixos/modules/services/web-servers/nginx/default.nix
index e046c28dd6bb..7caaf5611cc0 100644
--- a/nixos/modules/services/web-servers/nginx/default.nix
+++ b/nixos/modules/services/web-servers/nginx/default.nix
@@ -989,17 +989,14 @@ in
nginx.gid = config.ids.gids.nginx;
};
- services.logrotate.paths.nginx = mapAttrs (_: mkDefault) {
- path = "/var/log/nginx/*.log";
+ services.logrotate.settings.nginx = mapAttrs (_: mkDefault) {
+ files = "/var/log/nginx/*.log";
frequency = "weekly";
- keep = 26;
- extraConfig = ''
- compress
- delaycompress
- postrotate
- [ ! -f /var/run/nginx/nginx.pid ] || kill -USR1 `cat /var/run/nginx/nginx.pid`
- endscript
- '';
+ su = "${cfg.user} ${cfg.group}";
+ rotate = 26;
+ compress = true;
+ delaycompress = true;
+ postrotate = "[ ! -f /var/run/nginx/nginx.pid ] || kill -USR1 `cat /var/run/nginx/nginx.pid`";
};
};
}
diff --git a/nixos/modules/system/boot/systemd.nix b/nixos/modules/system/boot/systemd.nix
index 297a80d4681b..f69c5d3d5a64 100644
--- a/nixos/modules/system/boot/systemd.nix
+++ b/nixos/modules/system/boot/systemd.nix
@@ -612,22 +612,18 @@ in
boot.kernelParams = optional (!cfg.enableUnifiedCgroupHierarchy) "systemd.unified_cgroup_hierarchy=0";
- services.logrotate.paths = {
+ services.logrotate.settings = {
"/var/log/btmp" = mapAttrs (_: mkDefault) {
frequency = "monthly";
- keep = 1;
- extraConfig = ''
- create 0660 root ${config.users.groups.utmp.name}
- minsize 1M
- '';
+ rotate = 1;
+ create = "0660 root ${config.users.groups.utmp.name}";
+ minsize = "1M";
};
"/var/log/wtmp" = mapAttrs (_: mkDefault) {
frequency = "monthly";
- keep = 1;
- extraConfig = ''
- create 0664 root ${config.users.groups.utmp.name}
- minsize 1M
- '';
+ rotate = 1;
+ create = "0664 root ${config.users.groups.utmp.name}";
+ minsize = "1M";
};
};
};
diff --git a/nixos/modules/virtualisation/azure-agent.nix b/nixos/modules/virtualisation/azure-agent.nix
index bd8c7f8c1eea..e2425b44eac4 100644
--- a/nixos/modules/virtualisation/azure-agent.nix
+++ b/nixos/modules/virtualisation/azure-agent.nix
@@ -146,15 +146,11 @@ in
services.logrotate = {
enable = true;
- extraConfig = ''
- /var/log/waagent.log {
- compress
- monthly
- rotate 6
- notifempty
- missingok
- }
- '';
+ settings."/var/log/waagent.log" = {
+ compress = true;
+ frequency = "monthly";
+ rotate = 6;
+ };
};
systemd.targets.provisioned = {
diff --git a/nixos/tests/logrotate.nix b/nixos/tests/logrotate.nix
index 7e3046c94272..b0685f3af9ff 100644
--- a/nixos/tests/logrotate.nix
+++ b/nixos/tests/logrotate.nix
@@ -1,26 +1,105 @@
# Test logrotate service works and is enabled by default
-import ./make-test-python.nix ({ pkgs, ...} : rec {
+let
+ importTest = { ... }: {
+ services.logrotate.settings.import = {
+ olddir = false;
+ };
+ };
+
+in
+
+import ./make-test-python.nix ({ pkgs, ... }: rec {
name = "logrotate";
meta = with pkgs.lib.maintainers; {
maintainers = [ martinetd ];
};
- # default machine
- nodes.machine = { ... }: {
+ nodes = {
+ defaultMachine = { ... }: { };
+ failingMachine = { ... }: {
+ services.logrotate.configFile = pkgs.writeText "logrotate.conf" ''
+ # self-written config file
+ su notarealuser notagroupeither
+ '';
+ };
+ machine = { config, ... }: {
+ imports = [ importTest ];
+
+ services.logrotate.settings = {
+ # remove default frequency header and add another
+ header = {
+ frequency = null;
+ delaycompress = true;
+ };
+ # extra global setting... affecting nothing
+ last_line = {
+ global = true;
+ priority = 2000;
+ shred = true;
+ };
+ # using mail somewhere should add --mail to logrotate invokation
+ sendmail = {
+ mail = "user@domain.tld";
+ };
+ # postrotate should be suffixed by 'endscript'
+ postrotate = {
+ postrotate = "touch /dev/null";
+ };
+ # check checkConfig works as expected: there is nothing to check here
+ # except that the file build passes
+ checkConf = {
+ su = "root utmp";
+ createolddir = "0750 root utmp";
+ create = "root utmp";
+ "create " = "0750 root utmp";
+ };
+ # multiple paths should be aggregated
+ multipath = {
+ files = [ "file1" "file2" ];
+ };
+ # overriding imported path should keep existing attributes
+ # (e.g. olddir is still set)
+ import = {
+ notifempty = true;
+ };
+ };
+ # extraConfig compatibility - should be added to top level, early.
+ services.logrotate.extraConfig = ''
+ nomail
+ '';
+ # paths compatibility
+ services.logrotate.paths = {
+ compat_path = {
+ path = "compat_test_path";
+ };
+ # user/group should be grouped as 'su user group'
+ compat_user = {
+ user = config.users.users.root.name;
+ group = "root";
+ };
+ # extraConfig in path should be added to block
+ compat_extraConfig = {
+ extraConfig = "dateext";
+ };
+ # keep -> rotate
+ compat_keep = {
+ keep = 1;
+ };
+ };
+ };
};
testScript =
''
with subtest("whether logrotate works"):
- machine.succeed(
- # we must rotate once first to create logrotate stamp
- "systemctl start logrotate.service")
+ # we must rotate once first to create logrotate stamp
+ defaultMachine.succeed("systemctl start logrotate.service")
# we need to wait for console text once here to
# clear console buffer up to this point for next wait
- machine.wait_for_console_text('logrotate.service: Deactivated successfully')
+ defaultMachine.wait_for_console_text('logrotate.service: Deactivated successfully')
- machine.succeed(
+ defaultMachine.succeed(
# wtmp is present in default config.
"rm -f /var/log/wtmp*",
# we need to give it at least 1MB
@@ -28,10 +107,46 @@ import ./make-test-python.nix ({ pkgs, ...} : rec {
# move into the future and check rotation.
"date -s 'now + 1 month + 1 day'")
- machine.wait_for_console_text('logrotate.service: Deactivated successfully')
- machine.succeed(
+ defaultMachine.wait_for_console_text('logrotate.service: Deactivated successfully')
+ defaultMachine.succeed(
# check rotate worked
"[ -e /var/log/wtmp.1 ]",
)
+ with subtest("default config does not have mail"):
+ defaultMachine.fail("systemctl cat logrotate.service | grep -- --mail")
+ with subtest("using mails adds mail option"):
+ machine.succeed("systemctl cat logrotate.service | grep -- --mail")
+ with subtest("check generated config matches expectation"):
+ machine.succeed(
+ # copy conf to /tmp/logrotate.conf for easy grep
+ "conf=$(systemctl cat logrotate | grep -oE '/nix/store[^ ]*logrotate.conf'); cp $conf /tmp/logrotate.conf",
+ "! grep weekly /tmp/logrotate.conf",
+ "grep -E '^delaycompress' /tmp/logrotate.conf",
+ "tail -n 1 /tmp/logrotate.conf | grep shred",
+ "sed -ne '/\"sendmail\" {/,/}/p' /tmp/logrotate.conf | grep 'mail user@domain.tld'",
+ "sed -ne '/\"postrotate\" {/,/}/p' /tmp/logrotate.conf | grep endscript",
+ "grep '\"file1\"\n\"file2\" {' /tmp/logrotate.conf",
+ "sed -ne '/\"import\" {/,/}/p' /tmp/logrotate.conf | grep noolddir",
+ "sed -ne '1,/^\"/p' /tmp/logrotate.conf | grep nomail",
+ "grep '\"compat_test_path\" {' /tmp/logrotate.conf",
+ "sed -ne '/\"compat_user\" {/,/}/p' /tmp/logrotate.conf | grep 'su root root'",
+ "sed -ne '/\"compat_extraConfig\" {/,/}/p' /tmp/logrotate.conf | grep dateext",
+ "[[ $(sed -ne '/\"compat_keep\" {/,/}/p' /tmp/logrotate.conf | grep -w rotate) = \" rotate 1\" ]]",
+ "! sed -ne '/\"compat_keep\" {/,/}/p' /tmp/logrotate.conf | grep -w keep",
+ )
+ # also check configFile option
+ failingMachine.succeed(
+ "conf=$(systemctl cat logrotate | grep -oE '/nix/store[^ ]*logrotate.conf'); cp $conf /tmp/logrotate.conf",
+ "grep 'self-written config' /tmp/logrotate.conf",
+ )
+ with subtest("Check logrotate-checkconf service"):
+ machine.wait_for_unit("logrotate-checkconf.service")
+ # wait_for_unit also asserts for success, so wait for
+ # parent target instead and check manually.
+ failingMachine.wait_for_unit("multi-user.target")
+ info = failingMachine.get_unit_info("logrotate-checkconf.service")
+ if info["ActiveState"] != "failed":
+ raise Exception('logrotate-checkconf.service was not failed')
+
'';
})
diff --git a/pkgs/applications/editors/poke/default.nix b/pkgs/applications/editors/poke/default.nix
index e05008613910..c2ade207d609 100644
--- a/pkgs/applications/editors/poke/default.nix
+++ b/pkgs/applications/editors/poke/default.nix
@@ -22,11 +22,11 @@ let
isCross = stdenv.hostPlatform != stdenv.buildPlatform;
in stdenv.mkDerivation rec {
pname = "poke";
- version = "2.1";
+ version = "2.2";
src = fetchurl {
url = "mirror://gnu/${pname}/${pname}-${version}.tar.gz";
- sha256 = "sha256-zVKObBu8VAw7YpwrTza3hLMKAmsAWji5koNCJZlEJnA=";
+ sha256 = "sha256-xF6k5xpRohhTZzhcAc65dZbsW3EDOGm+xKYLHLciWQM=";
};
outputs = [ "out" "dev" "info" "lib" "man" ];
diff --git a/pkgs/applications/misc/p2pool/default.nix b/pkgs/applications/misc/p2pool/default.nix
index f888d162fc44..cb0b53e887b2 100644
--- a/pkgs/applications/misc/p2pool/default.nix
+++ b/pkgs/applications/misc/p2pool/default.nix
@@ -14,13 +14,13 @@
stdenv.mkDerivation rec {
pname = "p2pool";
- version = "1.8";
+ version = "1.9";
src = fetchFromGitHub {
owner = "SChernykh";
repo = "p2pool";
rev = "v${version}";
- sha256 = "sha256-cQd3dtih7C+pEmkvlrsYTJtQWBVVMiFbtNQUM0Ck3tg=";
+ sha256 = "sha256-nqJ0F99QjrpwXHRPxZ7kLCYA9VJWGH2ahcr/MBQrhyY=";
fetchSubmodules = true;
};
diff --git a/pkgs/applications/networking/browsers/brave/default.nix b/pkgs/applications/networking/browsers/brave/default.nix
index 65627a490d10..7c0006f745c6 100644
--- a/pkgs/applications/networking/browsers/brave/default.nix
+++ b/pkgs/applications/networking/browsers/brave/default.nix
@@ -91,11 +91,11 @@ in
stdenv.mkDerivation rec {
pname = "brave";
- version = "1.36.122";
+ version = "1.37.109";
src = fetchurl {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_amd64.deb";
- sha256 = "aBHoEu1egRPMpeUBgRl2V5J3op1Ju+CvprG14dIWc8M=";
+ sha256 = "fL3vuCqUnzq38JD0bzM/DxLVb5P31iChbMVY2eax9RE=";
};
dontConfigure = true;
diff --git a/pkgs/applications/virtualization/podman-tui/default.nix b/pkgs/applications/virtualization/podman-tui/default.nix
index 7a8ed6fed284..17272acd86eb 100644
--- a/pkgs/applications/virtualization/podman-tui/default.nix
+++ b/pkgs/applications/virtualization/podman-tui/default.nix
@@ -11,13 +11,13 @@
}:
buildGoModule rec {
pname = "podman-tui";
- version = "0.2.0";
+ version = "0.3.0";
src = fetchFromGitHub {
owner = "containers";
repo = "podman-tui";
rev = "v${version}";
- sha256 = "sha256-y5bFr31CQ4JES6tjvThyy7qmoKFC59uwtDMG5r+r8K4=";
+ sha256 = "sha256-1WbDmnKyFosp4Kz9QINr3lOR/wD0UW2QZf7nAAaoClM=";
};
vendorSha256 = null;
diff --git a/pkgs/development/compilers/ocaml/4.14.nix b/pkgs/development/compilers/ocaml/4.14.nix
index 558a1491ca7f..216620d67d60 100644
--- a/pkgs/development/compilers/ocaml/4.14.nix
+++ b/pkgs/development/compilers/ocaml/4.14.nix
@@ -1,9 +1,6 @@
import ./generic.nix {
major_version = "4";
minor_version = "14";
- patch_version = "0-rc2";
- src = fetchTarball {
- url = "https://caml.inria.fr/pub/distrib/ocaml-4.14/ocaml-4.14.0~rc2.tar.xz";
- sha256 = "sha256:0ch8nyfk2mzwhmlxb434cyamp7n14zxhwsq1h8033g629kw50kb0";
- };
+ patch_version = "0";
+ sha256 = "sha256:0axcc7c23pf4qinz4vxgkba6pwziwbp9i2ydwzar7x9zlp6diarn";
}
diff --git a/pkgs/development/compilers/vala/default.nix b/pkgs/development/compilers/vala/default.nix
index 230f6ee19a20..8013f283c708 100644
--- a/pkgs/development/compilers/vala/default.nix
+++ b/pkgs/development/compilers/vala/default.nix
@@ -90,8 +90,8 @@ let
in rec {
vala_0_48 = generic {
- version = "0.48.23";
- sha256 = "sha256-3jzIWNmV4HR0IZ4lo+Hw7ZmAcNLiBtOjE9Q3ml93oGo=";
+ version = "0.48.24";
+ sha256 = "NknvhFc7aGX8NHBkDuYDcgCZ65FbOfqtGbdJjeGn3yQ=";
};
vala_0_54 = generic {
diff --git a/pkgs/development/libraries/gnome-online-accounts/default.nix b/pkgs/development/libraries/gnome-online-accounts/default.nix
index f58e87b2f7e6..1fed0b470691 100644
--- a/pkgs/development/libraries/gnome-online-accounts/default.nix
+++ b/pkgs/development/libraries/gnome-online-accounts/default.nix
@@ -30,7 +30,7 @@
stdenv.mkDerivation rec {
pname = "gnome-online-accounts";
- version = "3.43.1";
+ version = "3.44.0";
# https://gitlab.gnome.org/GNOME/gnome-online-accounts/issues/87
src = fetchFromGitLab {
@@ -38,7 +38,7 @@ stdenv.mkDerivation rec {
owner = "GNOME";
repo = "gnome-online-accounts";
rev = version;
- sha256 = "sha256-Dpq5bQwU0ZAxmEllpbLnS1Jz3F0rxtFMKZcIvAteObU=";
+ sha256 = "sha256-8dp3cizyQVHegDxX9G6iGLW5g44audn431hCPMS/KlA=";
};
outputs = [ "out" "man" "dev" "devdoc" ];
diff --git a/pkgs/development/python-modules/apycula/default.nix b/pkgs/development/python-modules/apycula/default.nix
index e84e3eb301b5..d8bb92e0d3bc 100644
--- a/pkgs/development/python-modules/apycula/default.nix
+++ b/pkgs/development/python-modules/apycula/default.nix
@@ -12,7 +12,7 @@
buildPythonPackage rec {
pname = "apycula";
- version = "0.2";
+ version = "0.3";
format = "setuptools";
disabled = pythonOlder "3.8";
@@ -20,7 +20,7 @@ buildPythonPackage rec {
src = fetchPypi {
inherit version;
pname = "Apycula";
- hash = "sha256-xvr/NDAjCjhpImzNlCOcI4x5dIAefJ1TnUgoBhgdhPA=";
+ hash = "sha256-Ncecrn5fQW0iAgrE3P7GZTx8E1TiFqiDMhZQSPrDvdk=";
};
nativeBuildInputs = [
diff --git a/pkgs/servers/dante/default.nix b/pkgs/servers/dante/default.nix
index 1ed03f0e3d5a..12ba281d811c 100644
--- a/pkgs/servers/dante/default.nix
+++ b/pkgs/servers/dante/default.nix
@@ -1,4 +1,4 @@
-{ lib, stdenv, fetchurl, pam, libkrb5, cyrus_sasl, miniupnpc }:
+{ lib, stdenv, fetchurl, fetchpatch, pam, libkrb5, cyrus_sasl, miniupnpc, autoreconfHook }:
stdenv.mkDerivation rec {
pname = "dante";
@@ -9,6 +9,7 @@ stdenv.mkDerivation rec {
sha256 = "0pbahkj43rx7rmv2x40mf5p3g3x9d6i2sz7pzglarf54w5ghd2j1";
};
+ nativeBuildInputs = lib.optional stdenv.hostPlatform.isMips64 autoreconfHook;
buildInputs = [ pam libkrb5 cyrus_sasl miniupnpc ];
configureFlags = if !stdenv.isDarwin
@@ -17,6 +18,13 @@ stdenv.mkDerivation rec {
dontAddDisableDepTrack = stdenv.isDarwin;
+ patches = lib.optional stdenv.hostPlatform.isMips64 [
+ (fetchpatch {
+ name = "0002-osdep-m4-Remove-getaddrinfo-too-low-checks.patch";
+ url = "https://raw.githubusercontent.com/buildroot/buildroot/master/package/dante/0002-osdep-m4-Remove-getaddrinfo-too-low-checks.patch";
+ sha256 = "sha256-e+qF8lB5tkiA7RlJ+tX5O6KxQrQp33RSPdP1TxU961Y=";
+ }) ];
+
meta = with lib; {
description = "A circuit-level SOCKS client/server that can be used to provide convenient and secure network connectivity";
homepage = "https://www.inet.no/dante/";
diff --git a/pkgs/servers/web-apps/mediawiki/default.nix b/pkgs/servers/web-apps/mediawiki/default.nix
index 650b27a7f554..2339c170f166 100644
--- a/pkgs/servers/web-apps/mediawiki/default.nix
+++ b/pkgs/servers/web-apps/mediawiki/default.nix
@@ -2,11 +2,11 @@
stdenv.mkDerivation rec {
pname = "mediawiki";
- version = "1.37.1";
+ version = "1.37.2";
src = with lib; fetchurl {
url = "https://releases.wikimedia.org/mediawiki/${versions.majorMinor version}/${pname}-${version}.tar.gz";
- sha256 = "sha256-U0NuktwwrbFLZ5fYE50gaWpUYVJfOKN1yD5DXPBC4uc=";
+ sha256 = "sha256-WD8HS8r87BfaUBQqVvW7/eXDNml31h2RLX5W/Mo72hs=";
};
prePatch = ''
diff --git a/pkgs/shells/zsh/oh-my-zsh/default.nix b/pkgs/shells/zsh/oh-my-zsh/default.nix
index 851d5b08ff36..082472b9cd39 100644
--- a/pkgs/shells/zsh/oh-my-zsh/default.nix
+++ b/pkgs/shells/zsh/oh-my-zsh/default.nix
@@ -5,15 +5,15 @@
, git, nix, nixfmt, jq, coreutils, gnused, curl, cacert }:
stdenv.mkDerivation rec {
- version = "2022-03-29";
+ version = "2022-03-31";
pname = "oh-my-zsh";
- rev = "93435bff4947ca0855d4d8ecc4786877578f0dd3";
+ rev = "53863e7b3ff0c2e2816e90dab3d870adebdf49c7";
src = fetchFromGitHub {
inherit rev;
owner = "ohmyzsh";
repo = "ohmyzsh";
- sha256 = "w9DU2eTf8fID/xDhkJYVPuvYbVIXE9GKW8pycKZ9jVA=";
+ sha256 = "TQOGSAzcJfcUNTzUcCI5tTlAKD1JYtH9CiPnfHZaA9E=";
};
installPhase = ''
diff --git a/pkgs/tools/security/spectre-meltdown-checker/default.nix b/pkgs/tools/security/spectre-meltdown-checker/default.nix
index 49aa4a2a4ca5..cf85ed9310a1 100644
--- a/pkgs/tools/security/spectre-meltdown-checker/default.nix
+++ b/pkgs/tools/security/spectre-meltdown-checker/default.nix
@@ -2,13 +2,13 @@
stdenv.mkDerivation rec {
pname = "spectre-meltdown-checker";
- version = "0.44";
+ version = "0.45";
src = fetchFromGitHub {
owner = "speed47";
repo = "spectre-meltdown-checker";
rev = "v${version}";
- sha256 = "1b47wlc52jnp2d5c7kbqnxmlm4g3cfbv25q30llv5mlmzs6d7bam";
+ sha256 = "sha256-yGrsiPBux4YeiQ3BL2fnne5P55R/sQZ4FwzSkE6BqPc=";
};
prePatch = ''
diff --git a/pkgs/tools/system/logrotate/default.nix b/pkgs/tools/system/logrotate/default.nix
index f0ce08383359..4c9536cd7cf4 100644
--- a/pkgs/tools/system/logrotate/default.nix
+++ b/pkgs/tools/system/logrotate/default.nix
@@ -1,5 +1,4 @@
{ lib, stdenv, fetchFromGitHub, gzip, popt, autoreconfHook
-, mailutils ? null
, aclSupport ? true, acl
, nixosTests
}:
@@ -19,8 +18,6 @@ stdenv.mkDerivation rec {
configureFlags = [
"--with-compress-command=${gzip}/bin/gzip"
"--with-uncompress-command=${gzip}/bin/gunzip"
- ] ++ lib.optionals (mailutils != null) [
- "--with-default-mail-command=${mailutils}/bin/mail"
];
nativeBuildInputs = [ autoreconfHook ];
diff --git a/pkgs/top-level/ocaml-packages.nix b/pkgs/top-level/ocaml-packages.nix
index 9b2183f63581..6e38e07ff3b6 100644
--- a/pkgs/top-level/ocaml-packages.nix
+++ b/pkgs/top-level/ocaml-packages.nix
@@ -1578,7 +1578,7 @@ in let inherit (pkgs) callPackage; in rec
ocamlPackages_4_14 = mkOcamlPackages (callPackage ../development/compilers/ocaml/4.14.nix { });
- ocamlPackages_latest = ocamlPackages_4_13;
+ ocamlPackages_latest = ocamlPackages_4_14;
ocamlPackages = ocamlPackages_4_13;
}