From deaf61dab10a18898bc38065ae760bbfd20240e2 Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:18:11 -0400 Subject: [PATCH 01/37] linux: 4.14.281 -> 4.14.282 --- pkgs/os-specific/linux/kernel/linux-4.14.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-4.14.nix b/pkgs/os-specific/linux/kernel/linux-4.14.nix index bfed578429ef..4ee7bae77633 100644 --- a/pkgs/os-specific/linux/kernel/linux-4.14.nix +++ b/pkgs/os-specific/linux/kernel/linux-4.14.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "4.14.281"; + version = "4.14.282"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = if (modDirVersionArg == null) then concatStringsSep "." (take 3 (splitVersion "${version}.0")) else modDirVersionArg; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v4.x/linux-${version}.tar.xz"; - sha256 = "0pivb1m2cwqnlm8bhd4ccnlq9pwp2r5lmn77gp91k6vbjv3gkqis"; + sha256 = "18sp2qvk8dkjrlxwf4d470282m9wyvhajvyys9vs94rh1i3whdv6"; }; } // (args.argsOverride or {})) From c6c98c48b4bb91ad3998b291e79ea1d9110138a0 Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:18:13 -0400 Subject: [PATCH 02/37] linux: 4.19.245 -> 4.19.246 --- pkgs/os-specific/linux/kernel/linux-4.19.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-4.19.nix b/pkgs/os-specific/linux/kernel/linux-4.19.nix index 606fe18413fe..2c34b151031a 100644 --- a/pkgs/os-specific/linux/kernel/linux-4.19.nix +++ b/pkgs/os-specific/linux/kernel/linux-4.19.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "4.19.245"; + version = "4.19.246"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = if (modDirVersionArg == null) then concatStringsSep "." (take 3 (splitVersion "${version}.0")) else modDirVersionArg; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v4.x/linux-${version}.tar.xz"; - sha256 = "1s58qci6xhmss12glzkqk41kp60pqmzh4d84kyz4m4nf4xhdvzcr"; + sha256 = "0fmsglkvdgdmrkm53vyi9d4hvdl4py9qn1z0mni224n96rd2zb80"; }; } // (args.argsOverride or {})) From 2ac8909c8b5c7d7e0c19b84e2a8bc703ef5674a2 Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:18:16 -0400 Subject: [PATCH 03/37] linux: 4.9.316 -> 4.9.317 --- pkgs/os-specific/linux/kernel/linux-4.9.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-4.9.nix b/pkgs/os-specific/linux/kernel/linux-4.9.nix index 93570b9b5c0e..e55a187208f1 100644 --- a/pkgs/os-specific/linux/kernel/linux-4.9.nix +++ b/pkgs/os-specific/linux/kernel/linux-4.9.nix @@ -1,12 +1,12 @@ { buildPackages, fetchurl, perl, buildLinux, nixosTests, stdenv, ... } @ args: buildLinux (args // rec { - version = "4.9.316"; + version = "4.9.317"; extraMeta.branch = "4.9"; extraMeta.broken = stdenv.isAarch64; src = fetchurl { url = "mirror://kernel/linux/kernel/v4.x/linux-${version}.tar.xz"; - sha256 = "05yd7djm6dcxv3vaylhmj3p0yml421azv8qabmhv4ric1f99idjp"; + sha256 = "06qdqcplslnp1ncaqvp5yjr294rz3x4qrxnv522v76awj6dkd8vy"; }; } // (args.argsOverride or {})) From a7757d8a946c36a3eab8b340cf3155c71ca1df21 Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:18:18 -0400 Subject: [PATCH 04/37] linux: 5.10.118 -> 5.10.121 --- pkgs/os-specific/linux/kernel/linux-5.10.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-5.10.nix b/pkgs/os-specific/linux/kernel/linux-5.10.nix index aa4a489692d9..5b28b814c00a 100644 --- a/pkgs/os-specific/linux/kernel/linux-5.10.nix +++ b/pkgs/os-specific/linux/kernel/linux-5.10.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "5.10.118"; + version = "5.10.121"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = if (modDirVersionArg == null) then concatStringsSep "." (take 3 (splitVersion "${version}.0")) else modDirVersionArg; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v5.x/linux-${version}.tar.xz"; - sha256 = "0jqbzvgbvaldwwarvg27mcv2kfcgmfw72zpy4h4sp5d1hzqj1q65"; + sha256 = "1iljaaiwqg30rqb9zxrxc4l1p56q75jf0zvsrmn67z2a12sffi4h"; }; } // (args.argsOverride or {})) From 19d986621529a9cbb8bd9d39a96efea53df99d7d Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:18:20 -0400 Subject: [PATCH 05/37] linux: 5.15.43 -> 5.15.46 --- pkgs/os-specific/linux/kernel/linux-5.15.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-5.15.nix b/pkgs/os-specific/linux/kernel/linux-5.15.nix index 5c559fc86645..af9deb63c34b 100644 --- a/pkgs/os-specific/linux/kernel/linux-5.15.nix +++ b/pkgs/os-specific/linux/kernel/linux-5.15.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "5.15.43"; + version = "5.15.46"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = if (modDirVersionArg == null) then concatStringsSep "." (take 3 (splitVersion "${version}.0")) else modDirVersionArg; @@ -15,6 +15,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v5.x/linux-${version}.tar.xz"; - sha256 = "04hwaykdjdqhcdk1pr6p4kkyw6h3z6ig4qpsra2klxsqklx92jq6"; + sha256 = "0srp0wypl24gf5yz91mpk1c2kllabq6wvby1wqrrbdwvfx35figb"; }; } // (args.argsOverride or { })) From 363c71ff3cb469f90a4dce78e01eabbe53076d09 Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:18:22 -0400 Subject: [PATCH 06/37] linux: 5.17.11 -> 5.17.14 --- pkgs/os-specific/linux/kernel/linux-5.17.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-5.17.nix b/pkgs/os-specific/linux/kernel/linux-5.17.nix index 19e521432fde..b4eea2a18c9e 100644 --- a/pkgs/os-specific/linux/kernel/linux-5.17.nix +++ b/pkgs/os-specific/linux/kernel/linux-5.17.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "5.17.11"; + version = "5.17.14"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = if (modDirVersionArg == null) then concatStringsSep "." (take 3 (splitVersion "${version}.0")) else modDirVersionArg; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v5.x/linux-${version}.tar.xz"; - sha256 = "0c8vz02lbfm0zkgsr1gvdp8bzxz255dk863pnakw6d77z9bfc22p"; + sha256 = "0r2skbgxzw42cn29mr7i9w7fczzxhc1lx3xvri44ljjyfdqn7r0b"; }; } // (args.argsOverride or { })) From 260e08a6e64631a6c04ed6807caf6a96007ee8fb Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:18:25 -0400 Subject: [PATCH 07/37] linux: 5.18 -> 5.18.3 --- pkgs/os-specific/linux/kernel/linux-5.18.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-5.18.nix b/pkgs/os-specific/linux/kernel/linux-5.18.nix index b81f2479cb43..a4d889b3e919 100644 --- a/pkgs/os-specific/linux/kernel/linux-5.18.nix +++ b/pkgs/os-specific/linux/kernel/linux-5.18.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "5.18"; + version = "5.18.3"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = if (modDirVersionArg == null) then concatStringsSep "." (take 3 (splitVersion "${version}.0")) else modDirVersionArg; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v5.x/linux-${version}.tar.xz"; - sha256 = "1vjwhl4s8qxfg1aabn8xnpjza3qzrjcp5450h9qpjvl999lg3wsi"; + sha256 = "1sngy576db1zl2284kd0j8ds4biln0q98wnywirzsg3c0w2v8367"; }; } // (args.argsOverride or { })) From 45a098de80741473ce865f8c091d828a629fd33f Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:18:26 -0400 Subject: [PATCH 08/37] linux: 5.4.196 -> 5.4.197 --- pkgs/os-specific/linux/kernel/linux-5.4.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-5.4.nix b/pkgs/os-specific/linux/kernel/linux-5.4.nix index b2d9a81d0f8b..0fa70aaa0869 100644 --- a/pkgs/os-specific/linux/kernel/linux-5.4.nix +++ b/pkgs/os-specific/linux/kernel/linux-5.4.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "5.4.196"; + version = "5.4.197"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = if (modDirVersionArg == null) then concatStringsSep "." (take 3 (splitVersion "${version}.0")) else modDirVersionArg; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v5.x/linux-${version}.tar.xz"; - sha256 = "1x5irgki792f21hm5146xary0260cl9r475kvw8vm9w32vyx18ig"; + sha256 = "1a1nzrx873vwlpm018l6rk19yh59badvwsknw3chbkbhzjrigbf2"; }; } // (args.argsOverride or {})) From e457a67642a0460f13b7b64749361d444a0e2d2d Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:18:32 -0400 Subject: [PATCH 09/37] linux-rt_5_10: 5.10.115-rt67 -> 5.10.120-rt70 --- pkgs/os-specific/linux/kernel/linux-rt-5.10.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-rt-5.10.nix b/pkgs/os-specific/linux/kernel/linux-rt-5.10.nix index b4f80d11380f..cd182803ec0e 100644 --- a/pkgs/os-specific/linux/kernel/linux-rt-5.10.nix +++ b/pkgs/os-specific/linux/kernel/linux-rt-5.10.nix @@ -6,7 +6,7 @@ , ... } @ args: let - version = "5.10.115-rt67"; # updated by ./update-rt.sh + version = "5.10.120-rt70"; # updated by ./update-rt.sh branch = lib.versions.majorMinor version; kversion = builtins.elemAt (lib.splitString "-" version) 0; in buildLinux (args // { @@ -18,14 +18,14 @@ in buildLinux (args // { src = fetchurl { url = "mirror://kernel/linux/kernel/v5.x/linux-${kversion}.tar.xz"; - sha256 = "0w9gwizyqjgsj93dqqvlh6bqkmpzjajhj09319nqncc95yrigr7m"; + sha256 = "12qfgmzif2dy3kj4rqrnlx1if87c4fjmnya1bqpwx3hm0ih7ayjv"; }; kernelPatches = let rt-patch = { name = "rt"; patch = fetchurl { url = "mirror://kernel/linux/kernel/projects/rt/${branch}/older/patch-${version}.patch.xz"; - sha256 = "16igpdqq8nqzf98pkrs9v692d1r1fpnwrh3qxrkja0fgzswdwc0j"; + sha256 = "0l0fp7bqfj11qcq3dqd5lv468z1hha0y774dfiliv97lx7gq34m9"; }; }; in [ rt-patch ] ++ kernelPatches; From 87e0009cd59f73d2f00c481a255b81d80a20e082 Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:18:50 -0400 Subject: [PATCH 10/37] linux_latest-libre: 18738 -> 18777 --- pkgs/os-specific/linux/kernel/linux-libre.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-libre.nix b/pkgs/os-specific/linux/kernel/linux-libre.nix index 971847a895ac..159584f607ff 100644 --- a/pkgs/os-specific/linux/kernel/linux-libre.nix +++ b/pkgs/os-specific/linux/kernel/linux-libre.nix @@ -1,8 +1,8 @@ { stdenv, lib, fetchsvn, linux , scripts ? fetchsvn { url = "https://www.fsfla.org/svn/fsfla/software/linux-libre/releases/branches/"; - rev = "18738"; - sha256 = "024iw4352h8b1kbbimqgid95h868swiw45wn91sjkpmwr612v6kd"; + rev = "18777"; + sha256 = "0ycg799pdi3rarkdgrrxcfjl15n8i24d9zc54xhg79wpgxcv39n3"; } , ... }: From 67a664c575335508a2f7afc65dbe78151ad1a244 Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:19:14 -0400 Subject: [PATCH 11/37] linux/hardened/patches/4.14: 4.14.281-hardened1 -> 4.14.282-hardened1 --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index b6485a32851c..f4338016be2e 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -2,12 +2,12 @@ "4.14": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-4.14.281-hardened1.patch", - "sha256": "1i70qrv9dfpp0szl2m6icrnzpgw1r21nr4b6bbpdf1gmq22y9gf1", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/4.14.281-hardened1/linux-hardened-4.14.281-hardened1.patch" + "name": "linux-hardened-4.14.282-hardened1.patch", + "sha256": "0f7av5llr1ccx0k6z2p2spaqk4jfaw9555gf59303zgxsvakavmi", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/4.14.282-hardened1/linux-hardened-4.14.282-hardened1.patch" }, - "sha256": "0pivb1m2cwqnlm8bhd4ccnlq9pwp2r5lmn77gp91k6vbjv3gkqis", - "version": "4.14.281" + "sha256": "18sp2qvk8dkjrlxwf4d470282m9wyvhajvyys9vs94rh1i3whdv6", + "version": "4.14.282" }, "4.19": { "patch": { From 1c31d9666e4ad96f06111997870cd43875bf1dc3 Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:19:16 -0400 Subject: [PATCH 12/37] linux/hardened/patches/4.19: 4.19.245-hardened1 -> 4.19.246-hardened1 --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index f4338016be2e..a74a58e09e97 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -12,12 +12,12 @@ "4.19": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-4.19.245-hardened1.patch", - "sha256": "181bsz4zzw1hmk3l0cxrgfxlf1z5gy86bxrnwxh08n3j35biywf2", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/4.19.245-hardened1/linux-hardened-4.19.245-hardened1.patch" + "name": "linux-hardened-4.19.246-hardened1.patch", + "sha256": "00827r0hiiia95z4nwvbqi1jxj5bzh8hna3d4p08gj2pvq5rwvxk", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/4.19.246-hardened1/linux-hardened-4.19.246-hardened1.patch" }, - "sha256": "1s58qci6xhmss12glzkqk41kp60pqmzh4d84kyz4m4nf4xhdvzcr", - "version": "4.19.245" + "sha256": "0fmsglkvdgdmrkm53vyi9d4hvdl4py9qn1z0mni224n96rd2zb80", + "version": "4.19.246" }, "5.10": { "patch": { From 858741e87213845fdb74b87ec50d5fd002ff18ce Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:19:18 -0400 Subject: [PATCH 13/37] linux/hardened/patches/5.10: 5.10.118-hardened1 -> 5.10.121-hardened1 --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index a74a58e09e97..c0df03213414 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -22,12 +22,12 @@ "5.10": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-5.10.118-hardened1.patch", - "sha256": "0kn33lzb92p80rvy3jzkhnv5izr8h082x400s6ihxp1sqdal0fb7", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/5.10.118-hardened1/linux-hardened-5.10.118-hardened1.patch" + "name": "linux-hardened-5.10.121-hardened1.patch", + "sha256": "1a7mvfnm15ci81129mpvh3gn6w75bq0i1ydv02zyngk9cz5mgjc1", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/5.10.121-hardened1/linux-hardened-5.10.121-hardened1.patch" }, - "sha256": "0jqbzvgbvaldwwarvg27mcv2kfcgmfw72zpy4h4sp5d1hzqj1q65", - "version": "5.10.118" + "sha256": "1iljaaiwqg30rqb9zxrxc4l1p56q75jf0zvsrmn67z2a12sffi4h", + "version": "5.10.121" }, "5.15": { "patch": { From de36193dee5973147419a5819498f973f2fc6c40 Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:19:21 -0400 Subject: [PATCH 14/37] linux/hardened/patches/5.15: 5.15.43-hardened1 -> 5.15.46-hardened1 --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index c0df03213414..44f19fe246f4 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -32,12 +32,12 @@ "5.15": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-5.15.43-hardened1.patch", - "sha256": "03ilpzhr01567aaadwwk3qdnh9hlm427ihyrr59dwlwsfcqy2fd9", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/5.15.43-hardened1/linux-hardened-5.15.43-hardened1.patch" + "name": "linux-hardened-5.15.46-hardened1.patch", + "sha256": "1ndvrr98mn40705dsfkyda9ny5r273bl9f6n1xb5ndx34j396wrh", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/5.15.46-hardened1/linux-hardened-5.15.46-hardened1.patch" }, - "sha256": "04hwaykdjdqhcdk1pr6p4kkyw6h3z6ig4qpsra2klxsqklx92jq6", - "version": "5.15.43" + "sha256": "0srp0wypl24gf5yz91mpk1c2kllabq6wvby1wqrrbdwvfx35figb", + "version": "5.15.46" }, "5.17": { "patch": { From f61e9f4a536c0b0afacd2eace7317f32b33ab778 Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:19:23 -0400 Subject: [PATCH 15/37] linux/hardened/patches/5.17: 5.17.11-hardened1 -> 5.17.14-hardened1 --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index 44f19fe246f4..6d0ba9664720 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -42,12 +42,12 @@ "5.17": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-5.17.11-hardened1.patch", - "sha256": "01l4k1j23ckkifjxwaq9lcfp7ynpasyn5f7nqsff6xx2wcg0qyxf", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/5.17.11-hardened1/linux-hardened-5.17.11-hardened1.patch" + "name": "linux-hardened-5.17.14-hardened1.patch", + "sha256": "017dq8ngg3mxnfffjkf1knkzii8hsf1gsi65zla34n7kjyajlchq", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/5.17.14-hardened1/linux-hardened-5.17.14-hardened1.patch" }, - "sha256": "0c8vz02lbfm0zkgsr1gvdp8bzxz255dk863pnakw6d77z9bfc22p", - "version": "5.17.11" + "sha256": "0r2skbgxzw42cn29mr7i9w7fczzxhc1lx3xvri44ljjyfdqn7r0b", + "version": "5.17.14" }, "5.4": { "patch": { From a2c6e4372a49bd5d6e2e5ddf2e181ad6a258597c Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:19:25 -0400 Subject: [PATCH 16/37] linux/hardened/patches/5.18: init at 5.18.3-hardened1 --- nixos/tests/kernel-generic.nix | 1 + pkgs/os-specific/linux/kernel/hardened/patches.json | 10 ++++++++++ pkgs/top-level/all-packages.nix | 2 ++ pkgs/top-level/linux-kernels.nix | 2 ++ 4 files changed, 15 insertions(+) diff --git a/nixos/tests/kernel-generic.nix b/nixos/tests/kernel-generic.nix index 1e60198abdd0..5e6682d1045d 100644 --- a/nixos/tests/kernel-generic.nix +++ b/nixos/tests/kernel-generic.nix @@ -31,6 +31,7 @@ let linux_5_10_hardened linux_5_15_hardened linux_5_17_hardened + linux_5_18_hardened linux_testing; }; diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index 6d0ba9664720..94d3c35de3b0 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -49,6 +49,16 @@ "sha256": "0r2skbgxzw42cn29mr7i9w7fczzxhc1lx3xvri44ljjyfdqn7r0b", "version": "5.17.14" }, + "5.18": { + "patch": { + "extra": "-hardened1", + "name": "linux-hardened-5.18.3-hardened1.patch", + "sha256": "1kfnknpw2g39j7gqy6mqjmkaxkmdigx617rz2vpqvjxddfv59764", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/5.18.3-hardened1/linux-hardened-5.18.3-hardened1.patch" + }, + "sha256": "1sngy576db1zl2284kd0j8ds4biln0q98wnywirzsg3c0w2v8367", + "version": "5.18.3" + }, "5.4": { "patch": { "extra": "-hardened1", diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 899a1823ed86..f629729e4d70 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -23294,6 +23294,8 @@ with pkgs; linux_5_15_hardened = linuxKernel.kernels.linux_5_15_hardened; linuxPackages_5_17_hardened = linuxKernel.packages.linux_5_17_hardened; linux_5_17_hardened = linuxKernel.kernels.linux_5_17_hardened; + linuxPackages_5_18_hardened = linuxKernel.packages.linux_5_18_hardened; + linux_5_18_hardened = linuxKernel.kernels.linux_5_18_hardened; # Hardkernel (Odroid) kernels. linuxPackages_hardkernel_latest = linuxKernel.packageAliases.linux_hardkernel_latest; diff --git a/pkgs/top-level/linux-kernels.nix b/pkgs/top-level/linux-kernels.nix index 2f53fc73874e..b635eb01fd7a 100644 --- a/pkgs/top-level/linux-kernels.nix +++ b/pkgs/top-level/linux-kernels.nix @@ -244,6 +244,7 @@ in { linux_5_10_hardened = hardenedKernelFor kernels.linux_5_10 { }; linux_5_15_hardened = hardenedKernelFor kernels.linux_5_15 { }; linux_5_17_hardened = hardenedKernelFor kernels.linux_5_17 { }; + linux_5_18_hardened = hardenedKernelFor kernels.linux_5_18 { }; })); /* Linux kernel modules are inherently tied to a specific kernel. So @@ -551,6 +552,7 @@ in { linux_5_10_hardened = recurseIntoAttrs (hardenedPackagesFor kernels.linux_5_10 { }); linux_5_15_hardened = recurseIntoAttrs (hardenedPackagesFor kernels.linux_5_15 { }); linux_5_17_hardened = recurseIntoAttrs (hardenedPackagesFor kernels.linux_5_17 { }); + linux_5_18_hardened = recurseIntoAttrs (hardenedPackagesFor kernels.linux_5_18 { }); linux_zen = recurseIntoAttrs (packagesFor kernels.linux_zen); linux_lqx = recurseIntoAttrs (packagesFor kernels.linux_lqx); From 5dc09cd84f4456c6d3ce3b601a0c91c15dbccc33 Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Fri, 10 Jun 2022 14:19:27 -0400 Subject: [PATCH 17/37] linux/hardened/patches/5.4: 5.4.196-hardened1 -> 5.4.197-hardened1 --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index 94d3c35de3b0..7f2ee97406ee 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -62,11 +62,11 @@ "5.4": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-5.4.196-hardened1.patch", - "sha256": "11q9sadncbz84yhsai7xdbrgmcbghj0hc1lqc45767v1f3snmpyi", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/5.4.196-hardened1/linux-hardened-5.4.196-hardened1.patch" + "name": "linux-hardened-5.4.197-hardened1.patch", + "sha256": "0kqfviyx5aigadm051y9xkbyscnn9f92zwqxkjkxhpn0y684i7n5", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/5.4.197-hardened1/linux-hardened-5.4.197-hardened1.patch" }, - "sha256": "1x5irgki792f21hm5146xary0260cl9r475kvw8vm9w32vyx18ig", - "version": "5.4.196" + "sha256": "1a1nzrx873vwlpm018l6rk19yh59badvwsknw3chbkbhzjrigbf2", + "version": "5.4.197" } } From 547ea4a972f64bb1cc4922eb0f2069715da631b1 Mon Sep 17 00:00:00 2001 From: Andreas Date: Sat, 11 Jun 2022 11:43:44 +0200 Subject: [PATCH 18/37] maintainers: add hamburger1984 --- maintainers/maintainer-list.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index 441d2a634758..9d16a254ca89 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -4969,6 +4969,12 @@ githubId = 1498782; name = "Jesse Haber-Kucharsky"; }; + hamburger1984 = { + email = "hamburger1984@gmail.com"; + github = "hamburger1984"; + githubId = 438976; + name = "Andreas Krohn"; + }; hamhut1066 = { email = "github@hamhut1066.com"; github = "moredhel"; From 514bd27e9210b732ca191695445eb43083e18fe2 Mon Sep 17 00:00:00 2001 From: rnhmjoj Date: Sat, 11 Jun 2022 16:00:13 +0200 Subject: [PATCH 19/37] libreswan: 4.6 -> 4.7 --- pkgs/tools/networking/libreswan/default.nix | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/networking/libreswan/default.nix b/pkgs/tools/networking/libreswan/default.nix index 4df0471bbd8d..7c500d509258 100644 --- a/pkgs/tools/networking/libreswan/default.nix +++ b/pkgs/tools/networking/libreswan/default.nix @@ -43,11 +43,11 @@ in stdenv.mkDerivation rec { pname = "libreswan"; - version = "4.6"; + version = "4.7"; src = fetchurl { url = "https://download.libreswan.org/${pname}-${version}.tar.gz"; - sha256 = "1zsnsfx18pf5dy1p4jva2sfl0bdfx5y9ls54f9bp70m64r46yf96"; + sha256 = "0i7wyfgkaq6kcfhh1yshb1v7q42n3zvdkhq10f3ks1h075xk7mnx"; }; strictDeps = true; @@ -112,6 +112,7 @@ stdenv.mkDerivation rec { "INITSYSTEM=systemd" "UNITDIR=$(out)/etc/systemd/system/" "TMPFILESDIR=$(out)/lib/tmpfiles.d/" + "LINUX_VARIANT=nixos" ]; # Hack to make install work From d574ec79cb8ed92bda77204f0a3cd6e313ac56e6 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 11 Jun 2022 14:06:24 +0000 Subject: [PATCH 20/37] python310Packages.entrypoint2: 1.0 -> 1.1 --- pkgs/development/python-modules/entrypoint2/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/entrypoint2/default.nix b/pkgs/development/python-modules/entrypoint2/default.nix index 4fd464d483f3..fcd23d0a0c75 100644 --- a/pkgs/development/python-modules/entrypoint2/default.nix +++ b/pkgs/development/python-modules/entrypoint2/default.nix @@ -2,11 +2,11 @@ buildPythonPackage rec { pname = "entrypoint2"; - version = "1.0"; + version = "1.1"; src = fetchPypi { inherit pname version; - sha256 = "sha256-Z+kG9q2VjYP0i07ewo192CZw6SYZiPa0prY6vJ+zvlY="; + sha256 = "sha256-/At/57IazatHpYWrlAfKflxPlstoiFddtrDOuR8OEFo="; }; pythonImportsCheck = [ "entrypoint2" ]; From 39a56c7696aee49ef0c6cf4747cc44097db79b84 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Na=C3=AFm=20Favier?= Date: Sat, 11 Jun 2022 23:22:03 +0200 Subject: [PATCH 21/37] nixos/security/wrappers: use an assertion for the existence check A simpler implementation of 7d8b303e3fd76ccf58cfe26348e889def3663546 that uses an assertion instead of a derivation. `pathHasContext` seems a bit better than `hasPrefix storeDir` because it avoids a string comparison, and catches nonsense like `"foo${pkgs.hello}bar"`. --- nixos/modules/security/wrappers/default.nix | 40 +++++---------------- 1 file changed, 9 insertions(+), 31 deletions(-) diff --git a/nixos/modules/security/wrappers/default.nix b/nixos/modules/security/wrappers/default.nix index 169ef7442626..ec4fe33b8f1d 100644 --- a/nixos/modules/security/wrappers/default.nix +++ b/nixos/modules/security/wrappers/default.nix @@ -202,15 +202,21 @@ in ###### implementation config = { - assertions = lib.mapAttrsToList - (name: opts: + assertions = lib.concatLists (lib.mapAttrsToList + (name: opts: [ { assertion = opts.setuid || opts.setgid -> opts.capabilities == ""; message = '' The security.wrappers.${name} wrapper is not valid: setuid/setgid and capabilities are mutually exclusive. ''; } - ) wrappers; + { assertion = lib.pathHasContext (toString opts.source) -> lib.pathExists opts.source; + message = '' + The security.wrappers.${name} wrapper is not valid: + the source store path '${opts.source}' does not exist. + ''; + } + ]) wrappers); security.wrappers = let @@ -273,33 +279,5 @@ in ln --symbolic "$wrapperDir" "${wrapperDir}" fi ''; - - ###### wrappers consistency checks - system.extraDependencies = lib.singleton (pkgs.runCommandLocal - "ensure-all-wrappers-paths-exist" { } - '' - # make sure we produce output - mkdir -p $out - - echo -n "Checking that Nix store paths of all wrapped programs exist... " - - declare -A wrappers - ${lib.concatStringsSep "\n" (lib.mapAttrsToList (n: v: - "wrappers['${n}']='${v.source}'") wrappers)} - - for name in "''${!wrappers[@]}"; do - path="''${wrappers[$name]}" - if [[ "$path" =~ /nix/store ]] && [ ! -e "$path" ]; then - test -t 1 && echo -ne '\033[1;31m' - echo "FAIL" - echo "The path $path does not exist!" - echo 'Please, check the value of `security.wrappers."'$name'".source`.' - test -t 1 && echo -ne '\033[0m' - exit 1 - fi - done - - echo "OK" - ''); }; } From 9d84f435e351dfe89f5e7b1c7ca6f4cdb3fe06aa Mon Sep 17 00:00:00 2001 From: Artturin Date: Sun, 12 Jun 2022 04:15:04 +0300 Subject: [PATCH 22/37] nixVersions.nix_2_9: pull patch to add missing git-dir flags --- pkgs/tools/package-management/nix/default.nix | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/pkgs/tools/package-management/nix/default.nix b/pkgs/tools/package-management/nix/default.nix index 47c442cc8da0..c46d2319df41 100644 --- a/pkgs/tools/package-management/nix/default.nix +++ b/pkgs/tools/package-management/nix/default.nix @@ -89,6 +89,14 @@ in lib.makeExtensible (self: { nix_2_9 = common { version = "2.9.1"; sha256 = "sha256-qNL3lQPBsnStkru3j1ajN/H+knXI+X3dku8/dBfSw3g="; + patches = [ + # add missing --git-dir flags + # remove once 2.9.2 is out + (fetchpatch { + url = "https://github.com/NixOS/nix/commit/1a994cc35b33dcfd484e7a96be0e76e23bfb9029.patch"; + sha256 = "sha256-7rDlqWRSVPijbvrTm4P+YykbMWyJryorXqGLEgg8/Wo="; + }) + ]; }; stable = self.nix_2_9; From 8ae485e75b352cd11bba96bc20d7e65913178054 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sun, 12 Jun 2022 11:34:53 +0200 Subject: [PATCH 23/37] python310Packages.entrypoint2: add format --- .../python-modules/entrypoint2/default.nix | 24 +++++++++++++++---- 1 file changed, 20 insertions(+), 4 deletions(-) diff --git a/pkgs/development/python-modules/entrypoint2/default.nix b/pkgs/development/python-modules/entrypoint2/default.nix index fcd23d0a0c75..e2146f3a5a62 100644 --- a/pkgs/development/python-modules/entrypoint2/default.nix +++ b/pkgs/development/python-modules/entrypoint2/default.nix @@ -1,17 +1,33 @@ -{ lib, buildPythonPackage, fetchPypi, EasyProcess, path, pytestCheckHook }: +{ lib +, buildPythonPackage +, fetchPypi +, EasyProcess +, path +, pytestCheckHook +, pythonOlder +}: buildPythonPackage rec { pname = "entrypoint2"; version = "1.1"; + format = "setuptools"; + + disabled = pythonOlder "3.7"; src = fetchPypi { inherit pname version; - sha256 = "sha256-/At/57IazatHpYWrlAfKflxPlstoiFddtrDOuR8OEFo="; + hash = "sha256-/At/57IazatHpYWrlAfKflxPlstoiFddtrDOuR8OEFo="; }; - pythonImportsCheck = [ "entrypoint2" ]; + checkInputs = [ + EasyProcess + path + pytestCheckHook + ]; - checkInputs = [ EasyProcess path pytestCheckHook ]; + pythonImportsCheck = [ + "entrypoint2" + ]; meta = with lib; { description = "Easy to use command-line interface for python modules"; From 65666128992f73018e4cad71a7e96813f2031b19 Mon Sep 17 00:00:00 2001 From: Michael Weiss Date: Sat, 11 Jun 2022 11:56:32 +0200 Subject: [PATCH 24/37] sshfs: 3.7.2 -> 3.7.3 https://github.com/libfuse/sshfs/releases/tag/sshfs-3.7.3: > This is the last release from the current maintainer. SSHFS is now no > longer maintained or developed. Github issue tracking and pull > requests have therefore been disabled. The mailing list (see below) is > still available for use. > > If you would like to take over this project, you are welcome to do so. > Please fork it and develop the fork for a while. Once there has been 6 > months of reasonable activity, please contact Nikolaus@rath.org and > I'll be happy to give you ownership of this repository or replace with > a pointer to the fork. --- pkgs/tools/filesystems/sshfs-fuse/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/filesystems/sshfs-fuse/default.nix b/pkgs/tools/filesystems/sshfs-fuse/default.nix index 879199347bd1..2f11bb0047ad 100644 --- a/pkgs/tools/filesystems/sshfs-fuse/default.nix +++ b/pkgs/tools/filesystems/sshfs-fuse/default.nix @@ -22,7 +22,7 @@ in if stdenv.isDarwin then } else mkSSHFS { - version = "3.7.2"; - sha256 = "0i0ycgwdxja8313hlkrlwrl85a4ykkyqddgg484jkr4rnr7ylk8w"; + version = "3.7.3"; + sha256 = "0s2hilqixjmv4y8n67zaq374sgnbscp95lgz5ignp69g3p1vmhwz"; platforms = lib.platforms.linux; } From 1785ce8db1d7458f11788158263288fb2f94d40e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 12 Jun 2022 11:20:23 +0000 Subject: [PATCH 25/37] python310Packages.browser-cookie3: 0.14.2 -> 0.14.3 --- pkgs/development/python-modules/browser-cookie3/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/browser-cookie3/default.nix b/pkgs/development/python-modules/browser-cookie3/default.nix index a8b5d4e01441..3fce6a7473b3 100644 --- a/pkgs/development/python-modules/browser-cookie3/default.nix +++ b/pkgs/development/python-modules/browser-cookie3/default.nix @@ -12,14 +12,14 @@ buildPythonPackage rec { pname = "browser-cookie3"; - version = "0.14.2"; + version = "0.14.3"; format = "setuptools"; disabled = pythonOlder "3.7"; src = fetchPypi { inherit pname version; - hash = "sha256-YR5NcDmbLlnhxcDuyM6hjjuL/Ozw79ytbCF4/nmSZmQ="; + hash = "sha256-Ch8ho4T3R9qwQiaP+n5Q21x62Ip3ibtqDJIDnobbh5c="; }; propagatedBuildInputs = [ From 67512331eb8317dd07982f39486f1f071ac0d3a1 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sun, 12 Jun 2022 14:10:09 +0200 Subject: [PATCH 26/37] python310Packages.kml2geojson: init at 5.1.0 --- .../python-modules/kml2geojson/default.nix | 46 +++++++++++++++++++ pkgs/top-level/python-packages.nix | 2 + 2 files changed, 48 insertions(+) create mode 100644 pkgs/development/python-modules/kml2geojson/default.nix diff --git a/pkgs/development/python-modules/kml2geojson/default.nix b/pkgs/development/python-modules/kml2geojson/default.nix new file mode 100644 index 000000000000..6ceb71a9e5be --- /dev/null +++ b/pkgs/development/python-modules/kml2geojson/default.nix @@ -0,0 +1,46 @@ +{ lib +, buildPythonPackage +, poetry-core +, fetchFromGitHub +, pytestCheckHook +, pythonOlder +, click +}: + +buildPythonPackage rec { + pname = "kml2geojson"; + version = "5.1.0"; + format = "pyproject"; + + disabled = pythonOlder "3.8"; + + src = fetchFromGitHub { + owner = "mrcagney"; + repo = pname; + rev = version; + hash = "sha256-iJEcXpvy+Y3MkxAF2Q1Tkcx8GxUVjeVzv6gl134zdiI="; + }; + + nativeBuildInputs = [ + poetry-core + ]; + + propagatedBuildInputs = [ + click + ]; + + checkInputs = [ + pytestCheckHook + ]; + + pythonImportsCheck = [ + "kml2geojson" + ]; + + meta = with lib; { + description = "Library to convert KML to GeoJSON"; + homepage = "https://github.com/mrcagney/kml2geojson"; + license = licenses.mit; + maintainers = with maintainers; [ fab ]; + }; +} diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index 6fd6fcae0409..39dfd257c4db 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -4743,6 +4743,8 @@ in { kmapper = callPackage ../development/python-modules/kmapper { }; + kml2geojson = callPackage ../development/python-modules/kml2geojson { }; + kmsxx = toPythonModule (pkgs.kmsxx.override { withPython = true; }); From 218093d36a5846643a5fb8ba5abfcdec6d00de4c Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sun, 12 Jun 2022 14:26:05 +0200 Subject: [PATCH 27/37] python310Packages.wktutils: init at 1.1.4 --- .../python-modules/wktutils/default.nix | 66 +++++++++++++++++++ pkgs/top-level/python-packages.nix | 2 + 2 files changed, 68 insertions(+) create mode 100644 pkgs/development/python-modules/wktutils/default.nix diff --git a/pkgs/development/python-modules/wktutils/default.nix b/pkgs/development/python-modules/wktutils/default.nix new file mode 100644 index 000000000000..a8cd9eb21019 --- /dev/null +++ b/pkgs/development/python-modules/wktutils/default.nix @@ -0,0 +1,66 @@ +{ lib +, buildPythonPackage +, dateparser +, defusedxml +, fetchFromGitHub +, fiona +, geomet +, geopandas +, kml2geojson +, pyshp +, pythonOlder +, pyyaml +, regex +, requests +, shapely +, scikit-learn +}: + +buildPythonPackage rec { + pname = "wktutils"; + version = "1.1.4"; + format = "setuptools"; + + disabled = pythonOlder "3.7"; + + src = fetchFromGitHub { + owner = "asfadmin"; + repo = "Discovery-WKTUtils"; + rev = "refs/tags/v${version}"; + hash = "sha256-/gcMnZ+wWflbvLlyfIaEoSYaLrsosMyD60ei/5Iis6E="; + }; + + propagatedBuildInputs = [ + dateparser + defusedxml + fiona + geomet + geopandas + kml2geojson + pyshp + pyyaml + regex + requests + shapely + scikit-learn + ]; + + postPatch = '' + substituteInPlace setup.py \ + --replace "sklearn" "scikit-learn" + ''; + + # Module doesn't have tests + doCheck = false; + + pythonImportsCheck = [ + "WKTUtils" + ]; + + meta = with lib; { + description = "Collection of tools for handling WKTs"; + homepage = "https://github.com/asfadmin/Discovery-WKTUtils"; + license = licenses.bsd3; + maintainers = with maintainers; [ fab ]; + }; +} diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index 39dfd257c4db..3bd0f219fef8 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -11200,6 +11200,8 @@ in { winsspi = callPackage ../development/python-modules/winsspi { }; + wktutils = callPackage ../development/python-modules/wktutils { }; + wled = callPackage ../development/python-modules/wled { }; woob = callPackage ../development/python-modules/woob { }; From bf580b0edebbd6d862749e545a740a33eb358169 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sun, 12 Jun 2022 14:51:13 +0200 Subject: [PATCH 28/37] python310Packages.asf-search: 3.0.6 -> 3.2.2 - enable tests - adjust inpuuuts --- .../python-modules/asf-search/default.nix | 52 ++++++++++++++++--- 1 file changed, 44 insertions(+), 8 deletions(-) diff --git a/pkgs/development/python-modules/asf-search/default.nix b/pkgs/development/python-modules/asf-search/default.nix index b868b5f13628..7ac0bae903a6 100644 --- a/pkgs/development/python-modules/asf-search/default.nix +++ b/pkgs/development/python-modules/asf-search/default.nix @@ -1,21 +1,57 @@ -{ lib, buildPythonPackage, fetchFromGitHub, pytz, shapely, importlib-metadata, requests, python-dateutil }: +{ lib +, buildPythonPackage +, dateparser +, fetchFromGitHub +, importlib-metadata +, numpy +, pytestCheckHook +, python-dateutil +, pythonOlder +, pytz +, requests +, requests-mock +, shapely +, wktutils +}: buildPythonPackage rec { - pname = "asf_search"; - version = "3.0.6"; + pname = "asf-search"; + version = "3.2.2"; + format = "setuptools"; + + disabled = pythonOlder "3.7"; src = fetchFromGitHub { owner = "asfadmin"; repo = "Discovery-asf_search"; - rev = "v${version}"; - sha256 = "1jzah2l1db1p2mv59w9qf0x3a9hk6s5rzy0jnp2smsddvyxfwcyn"; + rev = "refs/tags/v${version}"; + hash = "sha256-9fJp4P2cD11ppU80Av/aJOcqpaBwuYgdWWBTMo/HCeo="; }; - propagatedBuildInputs = [ pytz shapely importlib-metadata requests python-dateutil ]; + propagatedBuildInputs = [ + dateparser + importlib-metadata + numpy + python-dateutil + pytz + requests + shapely + wktutils + ]; - doCheck = false; + checkInputs = [ + pytestCheckHook + requests-mock + ]; - pythonImportsCheck = [ "asf_search" ]; + postPatch = '' + substituteInPlace setup.py \ + --replace "WKTUtils==" "WKTUtils>=" + ''; + + pythonImportsCheck = [ + "asf_search" + ]; meta = with lib; { description = "Python wrapper for the ASF SearchAPI"; From 85a49d0af879a7aecd7a01ea00a06cde5f38e936 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 12 Jun 2022 12:59:20 +0000 Subject: [PATCH 29/37] python310Packages.plugwise: 0.19.0 -> 0.19.1 --- pkgs/development/python-modules/plugwise/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/plugwise/default.nix b/pkgs/development/python-modules/plugwise/default.nix index b8900b0f5506..e6f09947905d 100644 --- a/pkgs/development/python-modules/plugwise/default.nix +++ b/pkgs/development/python-modules/plugwise/default.nix @@ -21,7 +21,7 @@ buildPythonPackage rec { pname = "plugwise"; - version = "0.19.0"; + version = "0.19.1"; format = "setuptools"; disabled = pythonOlder "3.7"; @@ -30,7 +30,7 @@ buildPythonPackage rec { owner = pname; repo = "python-plugwise"; rev = "refs/tags/v${version}"; - sha256 = "sha256-ST7eC7IXW47b1AlX25ubUPTi6Hkcjd+7L0tzht3fz9s="; + sha256 = "sha256-eytv61aTGL6rTLHfZD9Tsl9FycdExo+TGsVBCNu1fIo="; }; propagatedBuildInputs = [ From 1b9baceff43bff11ca97dd1a89e6fc52e83c9058 Mon Sep 17 00:00:00 2001 From: misuzu Date: Wed, 8 Jun 2022 17:13:37 +0300 Subject: [PATCH 30/37] python3Packages.uvloop: disable problematic test on armv7l too --- pkgs/development/python-modules/uvloop/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/development/python-modules/uvloop/default.nix b/pkgs/development/python-modules/uvloop/default.nix index b4b75dbb1941..ec7f3e47ca73 100644 --- a/pkgs/development/python-modules/uvloop/default.nix +++ b/pkgs/development/python-modules/uvloop/default.nix @@ -46,7 +46,7 @@ buildPythonPackage rec { "--assert=plain" "--strict" "--tb=native" - ] ++ lib.optionals (stdenv.isAarch64) [ + ] ++ lib.optionals (stdenv.isAarch32 || stdenv.isAarch64) [ # test gets stuck in epoll_pwait on hydras aarch64 builders # https://github.com/MagicStack/uvloop/issues/412 "--deselect" "tests/test_tcp.py::Test_AIO_TCPSSL::test_remote_shutdown_receives_trailing_data" From dd63da9494c30dc7d13c16f6fe58673746592511 Mon Sep 17 00:00:00 2001 From: Andreas Date: Fri, 10 Jun 2022 16:41:37 +0200 Subject: [PATCH 31/37] hwatch: init at 0.3.6 --- pkgs/tools/misc/hwatch/default.nix | 33 ++++++++++++++++++++++++++++++ pkgs/top-level/all-packages.nix | 2 ++ 2 files changed, 35 insertions(+) create mode 100644 pkgs/tools/misc/hwatch/default.nix diff --git a/pkgs/tools/misc/hwatch/default.nix b/pkgs/tools/misc/hwatch/default.nix new file mode 100644 index 000000000000..259297eb494f --- /dev/null +++ b/pkgs/tools/misc/hwatch/default.nix @@ -0,0 +1,33 @@ +{ lib, stdenv, fetchFromGitHub, fetchpatch, rustPlatform }: + +rustPlatform.buildRustPackage rec { + pname = "hwatch"; + version = "0.3.6"; + + src = fetchFromGitHub { + owner = "blacknon"; + repo = pname; + # prefix, because just "0.3.6' causes the download to silently fail: + # $ curl -v https://github.com/blacknon/hwatch/archive/0.3.6.tar.gz + # ... + # < HTTP/2 300 + # ... + # the given path has multiple possibilities: #, # + rev = "refs/tags/${version}"; + sha256 = "sha256-uaAgA6DWwYVT9mQh55onW+qxIC2i9GVuimctTJpUgfA="; + }; + + cargoSha256 = "sha256-Xt3Z6ax3Y45KZhTYMBr/Rfx1o+ZAoPYj51SN5hnrXQM="; + + meta = with lib; { + homepage = "https://github.com/blackmon/hwatch"; + description= "Modern alternative to the watch command"; + longDescription = '' + A modern alternative to the watch command, records the differences in + execution results and can check this differences at after. + ''; + license = licenses.mit; + maintainers = with maintainers; [ hamburger1984 ]; + platforms = platforms.linux; + }; +} diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 899a1823ed86..628115f43923 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -400,6 +400,8 @@ with pkgs; gpick = callPackage ../tools/misc/gpick { }; + hwatch = callPackage ../tools/misc/hwatch { }; + hobbes = callPackage ../development/tools/hobbes { stdenv = gcc10StdenvCompat; }; html5validator = python3Packages.callPackage ../applications/misc/html5validator { }; From 324df04b67cf92017138a13737e7500e67060eb0 Mon Sep 17 00:00:00 2001 From: misuzu Date: Fri, 10 Jun 2022 20:47:44 +0300 Subject: [PATCH 32/37] linuxPackages: use 5_10 kernel on 32-bit platforms 5_15 fails to build with `Failed to parse base BTF 'vmlinux': -22` on i686 and armv7l. --- pkgs/top-level/linux-kernels.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/top-level/linux-kernels.nix b/pkgs/top-level/linux-kernels.nix index 2f53fc73874e..d4cf80e36466 100644 --- a/pkgs/top-level/linux-kernels.nix +++ b/pkgs/top-level/linux-kernels.nix @@ -565,7 +565,7 @@ in { }); packageAliases = { - linux_default = if stdenv.hostPlatform.isi686 then packages.linux_5_10 else packages.linux_5_15; + linux_default = if stdenv.hostPlatform.is32bit then packages.linux_5_10 else packages.linux_5_15; # Update this when adding the newest kernel major version! linux_latest = packages.linux_5_18; linux_mptcp = packages.linux_mptcp_95; From f78374bfa5f0535f80dc5b0c8bf62072661381c4 Mon Sep 17 00:00:00 2001 From: misuzu Date: Sun, 12 Jun 2022 16:46:14 +0300 Subject: [PATCH 33/37] python3Packages.afdko: skip broken test on armv7l (#177400) --- pkgs/development/python-modules/afdko/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/afdko/default.nix b/pkgs/development/python-modules/afdko/default.nix index c9cbd16fc0a6..613ee89f276e 100644 --- a/pkgs/development/python-modules/afdko/default.nix +++ b/pkgs/development/python-modules/afdko/default.nix @@ -81,8 +81,8 @@ buildPythonPackage rec { "test_filename_without_dir" "test_overwrite" "test_options" - ] ++ lib.optionals (stdenv.hostPlatform.isAarch64 || stdenv.hostPlatform.isRiscV) [ - # aarch64-only (?) failure, unknown reason so far + ] ++ lib.optionals (stdenv.hostPlatform.isAarch32 || stdenv.hostPlatform.isAarch64 || stdenv.hostPlatform.isRiscV) [ + # unknown reason so far # https://github.com/adobe-type-tools/afdko/issues/1425 "test_spec" ] ++ lib.optionals (stdenv.hostPlatform.isi686) [ From e17c1d5a52f1397bdecc2e0dc8d094aa081cbb1d Mon Sep 17 00:00:00 2001 From: Aaron Andersen Date: Sun, 5 Jun 2022 08:44:41 -0400 Subject: [PATCH 34/37] kodi.packages.urllib3: 1.26.4+matrix.1 -> 1.26.8+matrix.1 --- .../video/kodi/addons/urllib3/default.nix | 20 +++++++++++-------- 1 file changed, 12 insertions(+), 8 deletions(-) diff --git a/pkgs/applications/video/kodi/addons/urllib3/default.nix b/pkgs/applications/video/kodi/addons/urllib3/default.nix index de0fbb997654..a8365f5f68d7 100644 --- a/pkgs/applications/video/kodi/addons/urllib3/default.nix +++ b/pkgs/applications/video/kodi/addons/urllib3/default.nix @@ -1,19 +1,23 @@ -{ lib, buildKodiAddon, fetchzip, addonUpdateScript }: +{ lib, buildKodiAddon, fetchFromGitHub, addonUpdateScript }: + buildKodiAddon rec { pname = "urllib3"; namespace = "script.module.urllib3"; - version = "1.26.4+matrix.1"; + version = "1.26.8+matrix.1"; - src = fetchzip { - url = "https://mirrors.kodi.tv/addons/matrix/${namespace}/${namespace}-${version}.zip"; - sha256 = "1d2k6gbsnhdadcl1xc7igz4m71z2fcnpln5ppfjv455cmkk110vf"; + # temporarily fetching from a PR because of CVE-2021-33503 + # see https://github.com/xbmc/repo-scripts/pull/2193 for details + src = fetchFromGitHub { + owner = "xbmc"; + repo = "repo-scripts"; + rev = "f0bfacab4732e33c5669bedd1a86319fa9e38338"; + sha256 = "sha256-UEMLrIvuuPARGHMsz6dOZrOuHIYVSpi0gBy2lK1Y2sk="; }; + sourceRoot = "source/script.module.urllib3"; + passthru = { pythonPath = "lib"; - updateScript = addonUpdateScript { - attrPath = "kodi.packages.urllib3"; - }; }; meta = with lib; { From 099059530967f724cad3227716e53f5b57c393b3 Mon Sep 17 00:00:00 2001 From: Peter Hoeg Date: Sat, 11 Jun 2022 09:01:21 +0800 Subject: [PATCH 35/37] rtl8821cu: 2022-03-08 -> 2022-05-07 --- pkgs/os-specific/linux/rtl8821cu/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/os-specific/linux/rtl8821cu/default.nix b/pkgs/os-specific/linux/rtl8821cu/default.nix index a3d767d2ee67..3af4fee9eda2 100644 --- a/pkgs/os-specific/linux/rtl8821cu/default.nix +++ b/pkgs/os-specific/linux/rtl8821cu/default.nix @@ -2,13 +2,13 @@ stdenv.mkDerivation rec { pname = "rtl8821cu"; - version = "${kernel.version}-unstable-2022-03-08"; + version = "${kernel.version}-unstable-2022-05-07"; src = fetchFromGitHub { owner = "morrownr"; repo = "8821cu-20210118"; - rev = "4bdd7c8668562e43564cd5d786055633e591ad4d"; - sha256 = "sha256-dfvDpjsra/nHwIGywOkZICTEP/Ex7ooH4zzkXqAaDkI="; + rev = "e3cf788e1dddaba3273190755ce424f93fe593e4"; + hash = "sha256-VUZU/oFSaxewy/BF/2k4OssAi4AWSWweqXYZPHmsQvY="; }; hardeningDisable = [ "pic" ]; From 24a46503dfe430dd3ad9fad1ac88da1de21436da Mon Sep 17 00:00:00 2001 From: Simon Schoeters Date: Sun, 12 Jun 2022 16:18:46 +0200 Subject: [PATCH 36/37] bluewalker: 0.3.0 -> 0.3.1 --- pkgs/tools/bluetooth/bluewalker/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/bluetooth/bluewalker/default.nix b/pkgs/tools/bluetooth/bluewalker/default.nix index 06241b1436ae..ed2a5796444e 100644 --- a/pkgs/tools/bluetooth/bluewalker/default.nix +++ b/pkgs/tools/bluetooth/bluewalker/default.nix @@ -2,13 +2,13 @@ buildGoModule rec { pname = "bluewalker"; - version = "0.3.0"; + version = "0.3.1"; src = fetchFromGitLab { owner = "jtaimisto"; repo = pname; rev = "v${version}"; - sha256 = "sha256-spuJRiNiaBV4EsetUq8vUfR6ejUNZxLhVzS3AZZyrrQ="; + sha256 = "sha256-wAzBlCczsLfHboGYIsyN7dGwz52CMw+L3XQ0njfLVR0="; }; vendorSha256 = "189qs6vmx63vwsjmc4qgf1y8xjsi7x6l1f5c3kd8j8jnagl26z4h"; From fd2a89b98330f4a06636ef19f34716d68ea7fe71 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sun, 12 Jun 2022 17:07:36 +0200 Subject: [PATCH 37/37] nixos/wpa_supplicant: don't log that wpa_supplicant.conf is ignored with `allowAuxiliaryImperativeNetworks = true` The warning is wrong with `allowAuxiliaryImperativeNetworks`[1] being set to `true` because both files are included in this case with `-c` and `-I`. [1] https://nixos.org/manual/nixos/stable/options.html#opt-networking.wireless.allowAuxiliaryImperativeNetworks --- nixos/modules/services/networking/wpa_supplicant.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nixos/modules/services/networking/wpa_supplicant.nix b/nixos/modules/services/networking/wpa_supplicant.nix index c2e1d37e28bf..5a7975ae1782 100644 --- a/nixos/modules/services/networking/wpa_supplicant.nix +++ b/nixos/modules/services/networking/wpa_supplicant.nix @@ -114,7 +114,7 @@ let script = '' - ${optionalString configIsGenerated '' + ${optionalString (configIsGenerated && !cfg.allowAuxiliaryImperativeNetworks) '' if [ -f /etc/wpa_supplicant.conf ]; then echo >&2 "<3>/etc/wpa_supplicant.conf present but ignored. Generated ${configFile} is used instead." fi