From 87b499adc0ed2ce9a79e2085d87202cb66420983 Mon Sep 17 00:00:00 2001 From: figsoda Date: Tue, 10 Jan 2023 11:28:12 -0500 Subject: [PATCH 01/11] selene: 0.23.1 -> 0.24.0 Diff: https://github.com/kampfkarren/selene/compare/0.23.1...0.24.0 Changelog: https://github.com/kampfkarren/selene/blob/0.24.0/CHANGELOG.md --- pkgs/development/tools/selene/default.nix | 19 ++++--------------- 1 file changed, 4 insertions(+), 15 deletions(-) diff --git a/pkgs/development/tools/selene/default.nix b/pkgs/development/tools/selene/default.nix index 5ca33613c96d..238bf9938425 100644 --- a/pkgs/development/tools/selene/default.nix +++ b/pkgs/development/tools/selene/default.nix @@ -1,7 +1,6 @@ { lib , rustPlatform , fetchFromGitHub -, fetchpatch , robloxSupport ? true , pkg-config , openssl @@ -11,26 +10,16 @@ rustPlatform.buildRustPackage rec { pname = "selene"; - version = "0.23.1"; + version = "0.24.0"; src = fetchFromGitHub { owner = "kampfkarren"; repo = pname; rev = version; - sha256 = "sha256-gD49OzhpO059wawA+PJc8SIYQ23965LF21zqIfj62Y4="; + sha256 = "sha256-tw9OLdXhqxgqROub0P/+nd4LQGNw3QDxlCyyf8ogRQM="; }; - cargoSha256 = "sha256-oekqM/Jvh0z6O6iJhSi7Ph5gsF5Fssr5ItKpmyozhPk="; - - patches = [ - # fix broken test - # https://github.com/kampfkarren/selene/pull/471 - (fetchpatch { - name = "fix-test-roblox-incorrect-roact-usage.patch"; - url = "https://github.com/kampfkarren/selene/commit/f4abf9f3fb639b372fe4ac47449f8a1e455c28a5.patch"; - sha256 = "sha256-nk7HGygXXu91cqiRZBA/sLBlaJLkNg90C2NX8Kr1WGA="; - }) - ]; + cargoSha256 = "sha256-5/xAX8BhB81cB7x2Pe/MKCV0Fi76ZcO6XHFQxTVIuLA="; nativeBuildInputs = lib.optionals robloxSupport [ pkg-config @@ -38,7 +27,7 @@ rustPlatform.buildRustPackage rec { buildInputs = lib.optionals robloxSupport [ openssl - ] ++ lib.optional (robloxSupport && stdenv.isDarwin) [ + ] ++ lib.optionals (robloxSupport && stdenv.isDarwin) [ darwin.apple_sdk.frameworks.Security ]; From 8f3de3efd4e06d6ad9a787e65ca90f577df25a6a Mon Sep 17 00:00:00 2001 From: figsoda Date: Tue, 10 Jan 2023 16:28:19 -0500 Subject: [PATCH 02/11] topiary: unstable-2022-12-02 -> unstable-2023-01-10 Diff: https://github.com/tweag/topiary/compare/ae861a30097bd6297f553eb0ea2597f86f16d156...c36d4a2253f337e1a28d497826a84754b8d833f6 --- pkgs/development/tools/misc/topiary/default.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/development/tools/misc/topiary/default.nix b/pkgs/development/tools/misc/topiary/default.nix index 9a9529bfb5b4..06f75284b5cf 100644 --- a/pkgs/development/tools/misc/topiary/default.nix +++ b/pkgs/development/tools/misc/topiary/default.nix @@ -2,16 +2,16 @@ rustPlatform.buildRustPackage rec { pname = "topiary"; - version = "unstable-2022-12-02"; + version = "unstable-2023-01-10"; src = fetchFromGitHub { owner = "tweag"; repo = pname; - rev = "ae861a30097bd6297f553eb0ea2597f86f16d156"; - sha256 = "sha256-WVrl+LxWSbHkbFGbkUhmw4Klwg6CzfnLAz8F0mF0kb8="; + rev = "c36d4a2253f337e1a28d497826a84754b8d833f6"; + sha256 = "sha256-0uqDuEpL9JCXzD7sQ3PDv4N1KtCSkoMoD5i402uIfas="; }; - cargoSha256 = "sha256-qoCOcYp1NYz/YhIBP6AkCCudVLpqhztRehc2xZoYp9A="; + cargoSha256 = "sha256-PvMjLC133rlsPrgyESuVHIf2TPCtgGQQULCQvBTIJ20="; postInstall = '' install -Dm444 languages/* -t $out/share/languages From 5bba17c9aadf916cf3d81fb0c85307406c72289e Mon Sep 17 00:00:00 2001 From: Michael Weiss Date: Tue, 10 Jan 2023 23:00:06 +0100 Subject: [PATCH 03/11] chromium: 108.0.5359.124 -> 109.0.5414.74 https://chromereleases.googleblog.com/2023/01/stable-channel-update-for-desktop.html This update includes 17 security fixes. CVEs: CVE-2023-0128 CVE-2023-0129 CVE-2023-0130 CVE-2023-0131 CVE-2023-0132 CVE-2023-0133 CVE-2023-0134 CVE-2023-0135 CVE-2023-0136 CVE-2023-0137 CVE-2023-0138 CVE-2023-0139 CVE-2023-0140 CVE-2023-0141 --- .../browsers/chromium/upstream-info.json | 20 +++++++++---------- 1 file changed, 10 insertions(+), 10 deletions(-) diff --git a/pkgs/applications/networking/browsers/chromium/upstream-info.json b/pkgs/applications/networking/browsers/chromium/upstream-info.json index 05a65260e96d..d64eea22c831 100644 --- a/pkgs/applications/networking/browsers/chromium/upstream-info.json +++ b/pkgs/applications/networking/browsers/chromium/upstream-info.json @@ -1,21 +1,21 @@ { "stable": { - "version": "108.0.5359.124", - "sha256": "0x9ac6m4xdccjdrk2bmq4y7bhfpgf2dv0q7lsbbsa50vlv1gm3fl", - "sha256bin64": "00c11svz9dzkg57484jg7c558l0jz8jbgi5zyjs1w7xp24vpnnpg", + "version": "109.0.5414.74", + "sha256": "0pcfaj3n3rjk4va9g0ajlsv1719kdhqcnjdd4piinqxb4qy27vgd", + "sha256bin64": "1qfp9li90p2d6asy60v12h7r4025l01yf3dzcdyihvr0la3bhdrx", "deps": { "gn": { - "version": "2022-10-05", + "version": "2022-11-10", "url": "https://gn.googlesource.com/gn", - "rev": "b9c6c19be95a3863e02f00f1fe403b2502e345b6", - "sha256": "1rhadb6qk867jafr85x2m3asis3jv7x06blhmad2d296p26d5w6x" + "rev": "1c4151ff5c1d6fbf7fa800b8d4bb34d3abc03a41", + "sha256": "02621c9nqpr4pwcapy31x36l5kbyd0vdgd0wdaxj5p8hrxk67d6b" } }, "chromedriver": { - "version": "108.0.5359.71", - "sha256_linux": "0lxmzmjpy4j5k3hx7wxdbbk87fr883a6323r9fj5nmylb230i3p4", - "sha256_darwin": "14kl58qlxkfq7hipg717nwawzcx7qzg77v322ikgrvqi03f0saci", - "sha256_darwin_aarch64": "08rbp1dqv1xvy1w9jsip3140frbifzblgrn6i9xr612hxysxhap6" + "version": "109.0.5414.25", + "sha256_linux": "1gybh9nyc2j96ics1898qkrn1aajb2gpjb8l6b2p0hs24iqhjilg", + "sha256_darwin": "1w3sz9sxjkir2wwkzjx870qq04xzf9z7b59m953w33mkfm6zvz71", + "sha256_darwin_aarch64": "1qfg22glac44y5pdzscm2yr6wjnhm7p7pkiadblky27fp13dpyv0" } }, "beta": { From 138ffdeab989dcd0640f1e3b204e9cad8821c914 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 11 Jan 2023 14:37:57 +0000 Subject: [PATCH 04/11] python310Packages.google-cloud-monitoring: 2.12.0 -> 2.14.0 --- .../python-modules/google-cloud-monitoring/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/google-cloud-monitoring/default.nix b/pkgs/development/python-modules/google-cloud-monitoring/default.nix index f4e381ace9df..0254ca532859 100644 --- a/pkgs/development/python-modules/google-cloud-monitoring/default.nix +++ b/pkgs/development/python-modules/google-cloud-monitoring/default.nix @@ -14,14 +14,14 @@ buildPythonPackage rec { pname = "google-cloud-monitoring"; - version = "2.12.0"; + version = "2.14.0"; format = "setuptools"; disabled = pythonOlder "3.7"; src = fetchPypi { inherit pname version; - hash = "sha256-J0I8P+5BQq1igzKEGtccv66KxPTrzmPErtpx3ornk24="; + hash = "sha256-Fn21kQVBPjZk9pvsLO2W0vLalbXk3mSOKKn/uieudaY="; }; propagatedBuildInputs = [ From 1729975ffc93affec069edb099a3127e7759e19a Mon Sep 17 00:00:00 2001 From: Alyssa Ross Date: Wed, 11 Jan 2023 00:43:44 +0000 Subject: [PATCH 05/11] gawk: disable PIE PIE is incompatible with gawk's new persistent memory feature. This fixes pkgsMusl.gawk. Fixes: 3fba3bf53f2 ("gawk: 5.1.1 -> 5.2.1") Fixes: https://github.com/NixOS/nixpkgs/pull/210124 --- pkgs/tools/text/gawk/default.nix | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/text/gawk/default.nix b/pkgs/tools/text/gawk/default.nix index f07da96aa48b..a85e91b1a0c1 100644 --- a/pkgs/tools/text/gawk/default.nix +++ b/pkgs/tools/text/gawk/default.nix @@ -16,7 +16,7 @@ assert (doCheck && stdenv.isLinux) -> glibcLocales != null; -stdenv.mkDerivation rec { +stdenv.mkDerivation (rec { pname = "gawk" + lib.optionalString interactive "-interactive"; version = "5.2.1"; @@ -83,4 +83,8 @@ stdenv.mkDerivation rec { platforms = platforms.unix ++ platforms.windows; maintainers = [ ]; }; -} +} // lib.optionalAttrs stdenv.hostPlatform.isMusl { + # PIE is incompatible with the "persistent malloc" ("pma") feature. + # FIXME: make unconditional in staging (added to avoid rebuilds in staging-next) + hardeningDisable = [ "pie" ]; +}) From fbedeabf198c5e17e8779d3ae06234c91bee7de1 Mon Sep 17 00:00:00 2001 From: Michael Adler Date: Wed, 11 Jan 2023 14:00:53 +0100 Subject: [PATCH 06/11] mtdutils: enable parallel building --- pkgs/tools/filesystems/mtdutils/default.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/tools/filesystems/mtdutils/default.nix b/pkgs/tools/filesystems/mtdutils/default.nix index 86ca59c8fce9..ceb0c4e175e6 100644 --- a/pkgs/tools/filesystems/mtdutils/default.nix +++ b/pkgs/tools/filesystems/mtdutils/default.nix @@ -13,6 +13,8 @@ stdenv.mkDerivation rec { nativeBuildInputs = [ autoreconfHook pkg-config ] ++ lib.optional doCheck cmocka; buildInputs = [ acl libuuid lzo zlib zstd ]; + enableParallelBuilding = true; + configureFlags = with lib; [ (enableFeature doCheck "unit-tests") (enableFeature doCheck "tests") From a5c2a37896e822565d7563c56e8b2e1b05f5c620 Mon Sep 17 00:00:00 2001 From: Michael Adler Date: Wed, 11 Jan 2023 14:01:03 +0100 Subject: [PATCH 07/11] mtdutils: add dev output This contains headers and static libs. --- pkgs/tools/filesystems/mtdutils/default.nix | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/pkgs/tools/filesystems/mtdutils/default.nix b/pkgs/tools/filesystems/mtdutils/default.nix index ceb0c4e175e6..f6a1e0a5c56c 100644 --- a/pkgs/tools/filesystems/mtdutils/default.nix +++ b/pkgs/tools/filesystems/mtdutils/default.nix @@ -22,6 +22,14 @@ stdenv.mkDerivation rec { doCheck = stdenv.hostPlatform == stdenv.buildPlatform; + outputs = [ "out" "dev" ]; + + postInstall = '' + mkdir -p $dev/lib + mv *.a $dev/lib/ + mv include $dev/ + ''; + meta = with lib; { description = "Tools for MTD filesystems"; downloadPage = "https://git.infradead.org/mtd-utils.git"; From 0b90e548b5aabea90f01437467467bc73dc61bf1 Mon Sep 17 00:00:00 2001 From: Adam Joseph Date: Sun, 9 Oct 2022 15:25:46 -0700 Subject: [PATCH 08/11] lib/meta(availableOn): handle missing meta and empty meta.platform --- lib/meta.nix | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/lib/meta.nix b/lib/meta.nix index 893c671b04fa..8f4e7e2c7bf7 100644 --- a/lib/meta.nix +++ b/lib/meta.nix @@ -92,12 +92,15 @@ rec { A package is available on a platform if both - 1. One of `meta.platforms` pattern matches the given platform. + 1. One of `meta.platforms` pattern matches the given + platform, or `meta.platforms` is not present. 2. None of `meta.badPlatforms` pattern matches the given platform. */ availableOn = platform: pkg: - lib.any (platformMatch platform) pkg.meta.platforms && + if !(pkg?meta) then true else + (!(pkg.meta ? platforms) || + lib.any (platformMatch platform) pkg.meta.platforms) && lib.all (elem: !platformMatch platform elem) (pkg.meta.badPlatforms or []); /* Get the corresponding attribute in lib.licenses From 098c6b0becdbf0226b359c69fbfa4911b35a77d9 Mon Sep 17 00:00:00 2001 From: Adam Joseph Date: Sun, 9 Oct 2022 15:26:14 -0700 Subject: [PATCH 09/11] check-meta(hasUnsupportedPlatform): use lib.meta.availableOn `hasUnsupportedPlatform` was not updated with #37395, so it does not understand attrsets in `meta.[bad]platforms`. In particular, attrsets in `meta.badPlatforms` will "fail open" and be ignored. Let's use `lib.meta.availableOn` instead of duplicating its logic. Thanks to @alyssais for [noticing][1]. [1][https://github.com/NixOS/nixpkgs/pull/194148#discussion_r990817610] Co-authored-by: sternenseemann --- lib/meta.nix | 4 +--- pkgs/stdenv/generic/check-meta.nix | 7 +++---- 2 files changed, 4 insertions(+), 7 deletions(-) diff --git a/lib/meta.nix b/lib/meta.nix index 8f4e7e2c7bf7..62894aeb316b 100644 --- a/lib/meta.nix +++ b/lib/meta.nix @@ -98,9 +98,7 @@ rec { 2. None of `meta.badPlatforms` pattern matches the given platform. */ availableOn = platform: pkg: - if !(pkg?meta) then true else - (!(pkg.meta ? platforms) || - lib.any (platformMatch platform) pkg.meta.platforms) && + ((!pkg?meta.platforms) || lib.any (platformMatch platform) pkg.meta.platforms) && lib.all (elem: !platformMatch platform elem) (pkg.meta.badPlatforms or []); /* Get the corresponding attribute in lib.licenses diff --git a/pkgs/stdenv/generic/check-meta.nix b/pkgs/stdenv/generic/check-meta.nix index da2e9b135f2e..751e19d1681a 100644 --- a/pkgs/stdenv/generic/check-meta.nix +++ b/pkgs/stdenv/generic/check-meta.nix @@ -57,9 +57,8 @@ let isMarkedBroken = attrs: attrs.meta.broken or false; - hasUnsupportedPlatform = attrs: - (!lib.lists.elem hostPlatform.system (attrs.meta.platforms or lib.platforms.all) || - lib.lists.elem hostPlatform.system (attrs.meta.badPlatforms or [])); + hasUnsupportedPlatform = + pkg: !(lib.meta.availableOn hostPlatform pkg); isMarkedInsecure = attrs: (attrs.meta.knownVulnerabilities or []) != []; @@ -272,7 +271,7 @@ let sourceProvenance = listOf lib.types.attrs; maintainers = listOf (attrsOf anything); # TODO use the maintainer type from lib/tests/maintainer-module.nix priority = int; - platforms = listOf str; + platforms = listOf (either str (attrsOf anything)); # see lib.meta.platformMatch hydraPlatforms = listOf str; broken = bool; unfree = bool; From e091693f131b3e23ff8debf943f1606e79ca1232 Mon Sep 17 00:00:00 2001 From: Rick van Schijndel Date: Wed, 11 Jan 2023 21:06:22 +0100 Subject: [PATCH 10/11] cargo: fix cross-compilation by adding missing zlib dependency Previously it was failing with: Compiling cargo v0.67.1 (/build/rustc-1.66.1-src/src/tools/cargo) error: linking with `/nix/store/gcc-wrapper-11.3.0/bin/cc` failed: exit status: 1 | = note: /nix/store/binutils-2.39/bin/ld: skipping incompatible /nix/store/zlib-aarch64-unknown-linux-gnu-1.2.13/lib/libz.so when searching for -lz /nix/store/binutils-2.39/bin/ld: cannot find -lz: No such file or directory /nix/store/binutils-2.39/bin/ld: skipping incompatible /nix/store/zlib-aarch64-unknown-linux-gnu-1.2.13/lib/libz.so when searching for -lz collect2: error: ld returned 1 exit status --- pkgs/development/compilers/rust/cargo.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/development/compilers/rust/cargo.nix b/pkgs/development/compilers/rust/cargo.nix index 291a64f2210c..9b10767e5bff 100644 --- a/pkgs/development/compilers/rust/cargo.nix +++ b/pkgs/development/compilers/rust/cargo.nix @@ -26,6 +26,7 @@ rustPlatform.buildRustPackage { nativeBuildInputs = [ pkg-config cmake installShellFiles makeWrapper (lib.getDev pkgsHostHost.curl) + zlib ]; buildInputs = [ cacert file curl python3 openssl zlib ] ++ lib.optionals stdenv.isDarwin [ CoreFoundation Security ]; From dcf630c172df2a9ecaa47c77f868211e61ae8e52 Mon Sep 17 00:00:00 2001 From: K900 Date: Wed, 11 Jan 2023 23:24:12 +0300 Subject: [PATCH 11/11] mesa: 22.3.2 -> 22.3.3 --- pkgs/development/libraries/mesa/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/mesa/default.nix b/pkgs/development/libraries/mesa/default.nix index ea290ed03317..c853c172d240 100644 --- a/pkgs/development/libraries/mesa/default.nix +++ b/pkgs/development/libraries/mesa/default.nix @@ -41,7 +41,7 @@ with lib; let # Release calendar: https://www.mesa3d.org/release-calendar.html # Release frequency: https://www.mesa3d.org/releasing.html#schedule - version = "22.3.2"; + version = "22.3.3"; branch = versions.major version; withLibdrm = lib.meta.availableOn stdenv.hostPlatform libdrm; @@ -64,7 +64,7 @@ self = stdenv.mkDerivation { "ftp://ftp.freedesktop.org/pub/mesa/${version}/mesa-${version}.tar.xz" "ftp://ftp.freedesktop.org/pub/mesa/older-versions/${branch}.x/${version}/mesa-${version}.tar.xz" ]; - sha256 = "c15df758a8795f53e57f2a228eb4593c22b16dffd9b38f83901f76cd9533140b"; + sha256 = "sha256-vteZeIvyvZ7wedl82OCTSL9TywhoGFeOQHc7KxeBKSI="; }; # TODO: