diff --git a/ci/OWNERS b/ci/OWNERS index 3c93cc9a1f39..3d6eb0a38b27 100644 --- a/ci/OWNERS +++ b/ci/OWNERS @@ -361,7 +361,8 @@ pkgs/development/python-modules/buildcatrust/ @ajs124 @lukegb @mweinelt /pkgs/development/lua-modules @NixOS/lua # Neovim -/pkgs/applications/editors/neovim @NixOS/neovim +/pkgs/applications/editors/neovim @NixOS/neovim +/doc/languages-frameworks/neovim.section.md @NixOS/neovim # VimPlugins /pkgs/applications/editors/vim/plugins @NixOS/neovim diff --git a/doc/languages-frameworks/neovim.section.md b/doc/languages-frameworks/neovim.section.md index e0c22d8ccba5..78e9bf714013 100644 --- a/doc/languages-frameworks/neovim.section.md +++ b/doc/languages-frameworks/neovim.section.md @@ -25,7 +25,7 @@ neovim.override { withRuby = false; configure = { customRC = '' - # here your custom viml configuration goes! + " here your custom viml configuration goes! ''; packages.myVimPackage = with pkgs.vimPlugins; { # See examples below on how to use custom packages. @@ -47,7 +47,7 @@ neovim-qt.override { neovim = neovim.override { configure = { customRC = '' - # your custom viml configuration + " your custom viml configuration ''; }; }; @@ -64,11 +64,14 @@ For instance, `sqlite-lua` needs `g:sqlite_clib_path` to be set to work. Nixpkgs - `wrapRc`: Nix, not being able to write in your `$HOME`, loads the generated Neovim configuration via the `$VIMINIT` environment variable, i.e. : `export VIMINIT='lua dofile("/nix/store/…-init.lua")'`. This has side effects like preventing Neovim from sourcing your `init.lua` in `$XDG_CONFIG_HOME/nvim` (see bullet 7 of [`:help startup`](https://neovim.io/doc/user/starting.html#startup) in Neovim). Disable it if you want to generate your own wrapper. You can still reuse the generated vimscript init code via `neovim.passthru.initRc`. - `plugins`: A list of plugins to add to the wrapper. -- `extraLuaPackages`: A function passed on to `lua.withPackages` -- `withPython3`, `withNodeJs`, `withRuby` control when to enable neovim +- `extraLuaPackages`: A function passed on to `lua.withPackages`. +- `extraPython3Packages`: A function passed on to `python3.withPackages`. +- `withPython3`, `withNodeJs`, `withRuby`, `withPerl` control when to enable neovim providers (see `:h provider`). +- `vimAlias` and `viAlias` control whether to symlink the `vim` and `vi` binaries to `nvim` respectively. +- `extraName` is a string appended to the package name and derivation name. -``` +```nix wrapNeovimUnstable neovim-unwrapped { autoconfigure = true; autowrapRuntimeDeps = true; @@ -80,7 +83,8 @@ wrapNeovimUnstable neovim-unwrapped { vim.opt.colorcolumn = { 100 } vim.opt.termguicolors = true ''; - # plugins accepts a list of either plugins or { plugin = ...; config = ..vimscript.. }; + # plugins accepts a list of either plugins or attribute sets containing: + # { plugin = ...; config = ...; type = "viml"|"lua"; } (type defaults to "viml") plugins = with vimPlugins; [ { plugin = vim-obsession; @@ -88,7 +92,19 @@ wrapNeovimUnstable neovim-unwrapped { map $ Obsession ''; } - (nvim-treesitter.withPlugins (p: [ p.nix p.python ])) + { + plugin = grug-far-nvim; + type = "lua"; + config = '' + require('grug-far').setup({ + startInInsertMode = false, + }) + ''; + } + (nvim-treesitter.withPlugins (p: [ + p.nix + p.python + ])) hex-nvim ]; extraLuaPackages = lp: [ lp.mpack ]; @@ -98,12 +114,12 @@ wrapNeovimUnstable neovim-unwrapped { } ``` -You can explore the configuration with`nix repl` to discover these options and +You can explore the configuration with `nix repl` to discover these options and override them. For instance: ```nix -neovim.overrideAttrs (oldAttrs: { +neovim.override { autowrapRuntimeDeps = false; -}) +} ``` ## Specificities for some plugins {#neovim-plugin-specificities} diff --git a/maintainers/README.md b/maintainers/README.md index 4c3e5cff9c2a..4959e6aa5892 100644 --- a/maintainers/README.md +++ b/maintainers/README.md @@ -160,7 +160,7 @@ Once approved, the team will have the right privileges to be pinged and requeste > [!TIP] > The team name should be as short as possible; because it is nested under the maintainers group, no -maintainers suffix is needed. -After the first [weekly team sync](../.github/workflows/team-sync.yml) with the new team, it's then also possible to link it to the entry in `team-list.nix` by setting its `github` field to the GitHub team name. +After the first [weekly team sync](../.github/workflows/teams.yml) with the new team, it's then also possible to link it to the entry in `team-list.nix` by setting its `github` field to the GitHub team name. # Maintainer scripts diff --git a/nixos/lib/test-driver/default.nix b/nixos/lib/test-driver/default.nix index f92e7981c55d..efc7d8fa9a85 100644 --- a/nixos/lib/test-driver/default.nix +++ b/nixos/lib/test-driver/default.nix @@ -19,8 +19,6 @@ netpbm, vhost-device-vsock, nixosTests, - qemu_pkg ? qemu_test, - qemu_test, setuptools, socat, systemd, @@ -58,7 +56,6 @@ buildPythonApplication { propagatedBuildInputs = [ coreutils netpbm - qemu_pkg socat util-linux vde2 diff --git a/nixos/lib/test-driver/src/test_driver/machine/__init__.py b/nixos/lib/test-driver/src/test_driver/machine/__init__.py index 76c1100f5e12..c5c051ce1cc5 100644 --- a/nixos/lib/test-driver/src/test_driver/machine/__init__.py +++ b/nixos/lib/test-driver/src/test_driver/machine/__init__.py @@ -1730,6 +1730,7 @@ class NspawnMachine(BaseMachine): self.process = subprocess.Popen( [self.start_command], + cwd=self.state_dir, env={ "RUN_NSPAWN_ROOT_DIR": str(self.state_dir), "RUN_NSPAWN_SHARED_DIR": str(self.shared_dir), diff --git a/nixos/lib/testing/driver.nix b/nixos/lib/testing/driver.nix index 7a4c7e31a0e1..c15578f4fbfc 100644 --- a/nixos/lib/testing/driver.nix +++ b/nixos/lib/testing/driver.nix @@ -20,7 +20,6 @@ let # the respective qemu version and with or without ocr support testDriver = config.pythonTestDriverPackage.override { inherit (config) enableOCR extraPythonPackages; - qemu_pkg = config.qemu.package; enableNspawn = config.containers != { }; }; diff --git a/nixos/modules/services/hardware/udev.nix b/nixos/modules/services/hardware/udev.nix index 1299a5115a5f..1f28286b059d 100644 --- a/nixos/modules/services/hardware/udev.nix +++ b/nixos/modules/services/hardware/udev.nix @@ -461,10 +461,17 @@ in "${config.boot.initrd.systemd.package}/lib/systemd/systemd-udevd" "${config.boot.initrd.systemd.package}/lib/udev/ata_id" "${config.boot.initrd.systemd.package}/lib/udev/cdrom_id" - "${config.boot.initrd.systemd.package}/lib/udev/dmi_memory_id" "${config.boot.initrd.systemd.package}/lib/udev/scsi_id" "${config.boot.initrd.systemd.package}/lib/udev/rules.d" ] + ++ lib.optional ( + # https://github.com/systemd/systemd/blob/v259/meson.build#L1529-L1530 + pkgs.stdenv.hostPlatform.isx86 + || pkgs.stdenv.hostPlatform.isAarch + || pkgs.stdenv.hostPlatform.isLoongArch64 + || pkgs.stdenv.hostPlatform.isMips + || pkgs.stdenv.hostPlatform.isRiscV64 + ) "${config.boot.initrd.systemd.package}/lib/udev/dmi_memory_id" ++ map (x: "${x}/bin") config.boot.initrd.services.udev.binPackages; # Generate the udev rules for the initrd diff --git a/nixos/modules/services/mail/dovecot.nix b/nixos/modules/services/mail/dovecot.nix index 2c00b3ee6529..48b0795c53c1 100644 --- a/nixos/modules/services/mail/dovecot.nix +++ b/nixos/modules/services/mail/dovecot.nix @@ -7,7 +7,6 @@ let inherit (lib) - all attrsToList concatMapStringsSep concatStringsSep @@ -19,7 +18,6 @@ let isBool isDerivation isInt - isList isPath isString listToAttrs @@ -98,53 +96,67 @@ let i: n: v: "${i}${toString n} = ${v}"; - formatKeyValue = - indent: n: v: - if (v == null) then - "" - else if isInt v then - toOption indent n (toString v) + isPrimitive = v: !isAttrs v || isDerivation v; + + formatPrimitive = + v: + if isInt v then + toString v else if isBool v then - toOption indent n (yesOrNo v) + yesOrNo v else if isString v then - toOption indent n v - else if isList v then - if all isString v then - toOption indent n (concatStringsSep " " v) - else - map (formatKeyValue indent n) v + v else if isPath v || isDerivation v then # paths -> copy to store # derivations -> just use output path instead of looping over the attrs - toOption indent n "${v}" - else if isAttrs v && v ? _section then - let - sectionType = v._section.type; - sectionName = v._section.name; - sectionTitle = concatStringsSep " " ( - filter (s: s != null) [ - sectionType - sectionName - ] - ); - in - concatStringsSep "\n" ( - [ - "${indent}${sectionTitle} {" - ] - ++ (mapAttrsToList (formatKeyValue "${indent} ") (removeAttrs v [ "_section" ])) - ++ [ "${indent}}" ] - ) - else if isAttrs v then - concatStringsSep "\n" ( - [ - "${indent}${n} {" - ] - ++ (mapAttrsToList (formatKeyValue "${indent} ") v) - ++ [ "${indent}}" ] - ) + "${v}" else - throw (traceSeq v "services.dovecot2.settings: unexpected type"); + throw (traceSeq v "services.dovecot2.settings: unexpected primitive type"); + + formatSection = + indent: n: v: + let + sectionTitle = + if v ? _section then + concatStringsSep " " ( + filter (s: s != null) [ + v._section.type + v._section.name + ] + ) + else + n; + inner = removeAttrs v [ "_section" ]; + in + concatStringsSep "\n" ( + [ "${indent}${sectionTitle} {" ] + ++ flatten (mapAttrsToList (primitiveLinesFor "${indent} ") inner) + ++ flatten (mapAttrsToList (sectionLinesFor "${indent} ") inner) + ++ [ "${indent}}" ] + ); + + # emit lines for a k=v pair only when the value is a primitive + primitiveLinesFor = + indent: n: v: + let + primitives = filter isPrimitive (flatten [ v ]); + hasOnlySections = primitives == [ ] && v != [ ]; + in + # Only emit an empty list if the original entry was also an empty list. + # This is so that values like k = [{ ... }] will not produce an output + # here, but k = [] will, even though they result in the same + # primitives = []. + optional (!hasOnlySections && v != null) ( + toOption indent n (concatMapStringsSep " " formatPrimitive primitives) + ); + + # emit lines for a k=v pair only when the value is *not* a primitive + sectionLinesFor = + indent: n: v: + let + sections = filter (e: !isPrimitive e) (flatten [ v ]); + in + map (e: formatSection indent n e) sections; doveConf = let @@ -156,10 +168,13 @@ let ]; in concatStringsSep "\n" ( - optional (configVersion != null) (formatKeyValue "" "dovecot_config_version" configVersion) - ++ optional (storageVersion != null) (formatKeyValue "" "dovecot_storage_version" storageVersion) + optionals (configVersion != null) (primitiveLinesFor "" "dovecot_config_version" configVersion) + ++ optionals (storageVersion != null) ( + primitiveLinesFor "" "dovecot_storage_version" storageVersion + ) ++ optionals (cfg.includeFiles != [ ]) (map (f: "!include ${f}") cfg.includeFiles) - ++ flatten (mapAttrsToList (formatKeyValue "") remainingSettings) + ++ flatten (mapAttrsToList (primitiveLinesFor "") remainingSettings) + ++ flatten (mapAttrsToList (sectionLinesFor "") remainingSettings) ); isPre24 = versionOlder cfg.package.version "2.4"; diff --git a/nixos/modules/services/network-filesystems/kubo.nix b/nixos/modules/services/network-filesystems/kubo.nix index 4e676b80a1aa..9c08028a0842 100644 --- a/nixos/modules/services/network-filesystems/kubo.nix +++ b/nixos/modules/services/network-filesystems/kubo.nix @@ -334,7 +334,7 @@ in programs.fuse = { enable = lib.mkIf cfg.autoMount true; - userAllowOther = lib.mkIf cfg.settings.Mounts.fuseAllowOther true; + userAllowOther = lib.mkIf cfg.settings.Mounts.FuseAllowOther true; }; users.users = lib.mkIf (cfg.user == "ipfs") { diff --git a/nixos/modules/services/web-apps/tabbyapi.nix b/nixos/modules/services/web-apps/tabbyapi.nix index 0340e69775a7..bd937b0d5685 100644 --- a/nixos/modules/services/web-apps/tabbyapi.nix +++ b/nixos/modules/services/web-apps/tabbyapi.nix @@ -167,6 +167,13 @@ in wantedBy = [ "multi-user.target" ]; description = "TabbyAPI - OAI compatible server for Exllama"; + # Triton & huggingface downloader need writable cache folders + environment = { + HOME = "/var/lib/tabbyapi"; + XDG_CACHE_HOME = "/var/lib/tabbyapi/.cache"; + TRITON_CACHE_DIR = "/tmp/triton"; + }; + serviceConfig = { ExecStart = "${lib.getExe cfg.package} --config=${configFile}"; Restart = "on-failure"; diff --git a/nixos/modules/system/boot/networkd.nix b/nixos/modules/system/boot/networkd.nix index 2b14caac86fa..4a22d6585eb9 100644 --- a/nixos/modules/system/boot/networkd.nix +++ b/nixos/modules/system/boot/networkd.nix @@ -4231,8 +4231,10 @@ let "systemd-networkd-wait-online@.service" "systemd-networkd.service" "systemd-networkd.socket" - "systemd-networkd-persistent-storage.service" + "systemd-networkd-resolve-hook.socket" "systemd-networkd-varlink-metrics.socket" + "systemd-networkd-varlink.socket" + "systemd-networkd-persistent-storage.service" ]; systemd.sockets.systemd-networkd-varlink-metrics.wantedBy = [ "sockets.target" ]; @@ -4314,6 +4316,9 @@ let systemd.additionalUpstreamUnits = [ "systemd-networkd-wait-online.service" "systemd-networkd.service" + "systemd-networkd-resolve-hook.socket" + "systemd-networkd-varlink-metrics.socket" + "systemd-networkd-varlink.socket" "systemd-networkd.socket" "systemd-network-generator.service" "network-online.target" diff --git a/nixos/modules/system/boot/resolved.nix b/nixos/modules/system/boot/resolved.nix index da2b57285a76..6760dab044e9 100644 --- a/nixos/modules/system/boot/resolved.nix +++ b/nixos/modules/system/boot/resolved.nix @@ -185,7 +185,11 @@ in # added with order 501 to allow modules to go before with mkBefore system.nssDatabases.hosts = (mkOrder 501 [ "resolve [!UNAVAIL=return]" ]); - systemd.additionalUpstreamSystemUnits = [ "systemd-resolved.service" ]; + systemd.additionalUpstreamSystemUnits = [ + "systemd-resolved.service" + "systemd-resolved-monitor.socket" + "systemd-resolved-varlink.socket" + ]; systemd.services.systemd-resolved = { wantedBy = [ "sysinit.target" ]; @@ -248,7 +252,12 @@ in tmpfiles.settings.systemd-resolved-stub."/etc/resolv.conf".L.argument = "/run/systemd/resolve/stub-resolv.conf"; - additionalUpstreamUnits = [ "systemd-resolved.service" ]; + additionalUpstreamUnits = [ + "systemd-resolved.service" + "systemd-resolved-monitor.socket" + "systemd-resolved-varlink.socket" + ]; + users.systemd-resolve = { }; groups.systemd-resolve = { }; storePaths = [ "${config.boot.initrd.systemd.package}/lib/systemd/systemd-resolved" ]; diff --git a/nixos/modules/system/boot/systemd.nix b/nixos/modules/system/boot/systemd.nix index 75b4143d6810..acfb213b98e0 100644 --- a/nixos/modules/system/boot/systemd.nix +++ b/nixos/modules/system/boot/systemd.nix @@ -65,6 +65,7 @@ let # Udev. "systemd-udevd-control.socket" "systemd-udevd-kernel.socket" + "systemd-udevd-varlink.socket" "systemd-udevd.service" ] ++ (optional (!config.boot.isContainer) "systemd-udev-trigger.service") @@ -157,6 +158,8 @@ let "systemd-ask-password-wall.service" # Varlink APIs + "systemd-ask-password@.service" + "systemd-ask-password.socket" ] ++ lib.optionals cfg.package.withBootloader [ "systemd-bootctl@.service" @@ -178,11 +181,13 @@ let ] ++ optionals cfg.package.withImportd [ "systemd-importd.service" + "systemd-importd.socket" ] ++ optionals cfg.package.withMachined [ "machine.slice" "machines.target" "systemd-machined.service" + "systemd-machined.socket" ] ++ optionals cfg.package.withNspawn [ "systemd-nspawn@.service" @@ -191,6 +196,9 @@ let # Misc. "systemd-sysctl.service" "systemd-machine-id-commit.service" + + "systemd-mute-console@.service" + "systemd-mute-console.socket" ] ++ optionals cfg.package.withTimedated [ "dbus-org.freedesktop.timedate1.service" @@ -209,6 +217,11 @@ let "dbus-org.freedesktop.portable1.service" "systemd-portabled.service" ] + ++ optionals cfg.package.withRepart [ + # Varlink APIs + "systemd-repart@.service" + "systemd-repart.socket" + ] ++ [ "systemd-exit.service" "systemd-update-done.service" @@ -221,6 +234,8 @@ let "factory-reset.target" "systemd-factory-reset-request.service" "systemd-factory-reset-reboot.service" + "systemd-factory-reset@.service" + "systemd-factory-reset.socket" ] ++ cfg.additionalUpstreamSystemUnits; diff --git a/nixos/modules/system/boot/systemd/repart.nix b/nixos/modules/system/boot/systemd/repart.nix index fce8e417991d..2126464c5250 100644 --- a/nixos/modules/system/boot/systemd/repart.nix +++ b/nixos/modules/system/boot/systemd/repart.nix @@ -157,6 +157,12 @@ in boot.initrd.systemd = lib.mkIf initrdCfg.enable { additionalUpstreamUnits = [ "systemd-repart.service" + # Varlink APIs + # NOTE: compared to stage 2 where the IPC is enabled in the global location, initrd + # might be optimized to keep away the repart binary. + # As a result, we enable repart IPC in the initrd only if repart is enabled in the initrd. + "systemd-repart.socket" + "systemd-repart@.service" ]; storePaths = [ diff --git a/nixos/modules/system/boot/systemd/tmpfiles.nix b/nixos/modules/system/boot/systemd/tmpfiles.nix index c606ff1ac50b..631a02645d9b 100644 --- a/nixos/modules/system/boot/systemd/tmpfiles.nix +++ b/nixos/modules/system/boot/systemd/tmpfiles.nix @@ -317,6 +317,7 @@ in mkdir -p $out/lib/tmpfiles.d cd $out/lib/tmpfiles.d + ln -s "${systemd}/example/tmpfiles.d/credstore.conf" ln -s "${systemd}/example/tmpfiles.d/home.conf" ln -s "${systemd}/example/tmpfiles.d/journal-nocow.conf" ln -s "${systemd}/example/tmpfiles.d/portables.conf" diff --git a/nixos/modules/system/boot/systemd/tpm2.nix b/nixos/modules/system/boot/systemd/tpm2.nix index 2703d60428f1..de0f72e5a543 100644 --- a/nixos/modules/system/boot/systemd/tpm2.nix +++ b/nixos/modules/system/boot/systemd/tpm2.nix @@ -43,6 +43,8 @@ "tpm2.target" "systemd-tpm2-setup-early.service" "systemd-tpm2-setup.service" + "systemd-pcrextend.socket" + "systemd-pcrextend@.service" ]; } ) @@ -69,6 +71,8 @@ boot.initrd.systemd.additionalUpstreamUnits = [ "tpm2.target" "systemd-tpm2-setup-early.service" + "systemd-pcrextend.socket" + "systemd-pcrextend@.service" ]; boot.initrd.availableKernelModules = [ @@ -81,6 +85,7 @@ pkgs.tpm2-tss "${cfg.package}/lib/systemd/systemd-tpm2-setup" "${cfg.package}/lib/systemd/system-generators/systemd-tpm2-generator" + "${cfg.package}/lib/systemd/systemd-pcrextend" ]; } ) @@ -89,7 +94,9 @@ cfg = config.boot.initrd.systemd; in lib.mkIf (cfg.enable && cfg.tpm2.enable && cfg.tpm2.pcrphases.enable) { - boot.initrd.systemd.additionalUpstreamUnits = [ "systemd-pcrphase-initrd.service" ]; + boot.initrd.systemd.additionalUpstreamUnits = [ + "systemd-pcrphase-initrd.service" + ]; boot.initrd.systemd.services.systemd-pcrphase-initrd.wantedBy = [ "initrd.target" ]; boot.initrd.systemd.storePaths = [ "${cfg.package}/lib/systemd/systemd-pcrextend" ]; } diff --git a/nixos/modules/virtualisation/credentials-options.nix b/nixos/modules/virtualisation/credentials-options.nix new file mode 100644 index 000000000000..3345f6933784 --- /dev/null +++ b/nixos/modules/virtualisation/credentials-options.nix @@ -0,0 +1,63 @@ +{ lib, pkgs, ... }: +{ + options.virtualisation.credentials = lib.mkOption { + description = '' + Credentials to pass to the VM or container using systemd's credential system. + + See {manpage}`systemd.exec(5)`, {manpage}`systemd-creds(1)` and https://systemd.io/CREDENTIALS/ for more + information about systemd credentials. + ''; + default = { }; + example = lib.literalExpression '' + { + database-password = { + text = "my-secret-password"; + }; + ssl-cert = { + source = "./cert.pem"; + }; + binary-key = { + source = "./private.der"; + }; + } + ''; + type = lib.types.attrsOf ( + lib.types.submodule ( + { + name, + options, + config, + ... + }: + { + options = { + source = lib.mkOption { + type = lib.types.nullOr (lib.types.pathWith { }); + default = null; + description = '' + Source file on the host containing the credential data. + ''; + }; + text = lib.mkOption { + default = null; + type = lib.types.nullOr lib.types.str; + description = '' + Text content of the credential. + + For binary data or when the credential content should come from + an existing file, use `source` instead. + + ::: {.warning} + The text here is stored in the host's nix store as a file. + ::: + ''; + }; + }; + config.source = lib.mkIf (config.text != null) ( + lib.mkDerivedConfig options.text (pkgs.writeText name) + ); + } + ) + ); + }; +} diff --git a/nixos/modules/virtualisation/nspawn-container/default.nix b/nixos/modules/virtualisation/nspawn-container/default.nix index 9100b580768b..82a06929e925 100644 --- a/nixos/modules/virtualisation/nspawn-container/default.nix +++ b/nixos/modules/virtualisation/nspawn-container/default.nix @@ -21,6 +21,10 @@ let cfg = config.virtualisation; in { + imports = [ + ../credentials-options.nix + ]; + options = { virtualisation.cmdline = lib.mkOption { @@ -131,7 +135,8 @@ in # Send a READY=1 notification to a socket when the container is fully booted. "--notify-ready=yes" - ]; + ] + ++ lib.mapAttrsToList (name: cred: "--load-credential=${name}:${cred.source}") cfg.credentials; system.build.nspawn = let diff --git a/nixos/modules/virtualisation/qemu-vm.nix b/nixos/modules/virtualisation/qemu-vm.nix index d99a491b8579..59645757575f 100644 --- a/nixos/modules/virtualisation/qemu-vm.nix +++ b/nixos/modules/virtualisation/qemu-vm.nix @@ -399,6 +399,7 @@ in imports = [ ../profiles/qemu-guest.nix ./disk-size-option.nix + ./credentials-options.nix (mkRenamedOptionModule [ "virtualisation" @@ -1126,81 +1127,20 @@ in }; virtualisation.credentials = mkOption { - description = '' - Credentials to pass to the VM using systemd's credential system. - - See {manpage}`systemd.exec(5)` , {manpage}`systemd-creds(1)` and https://systemd.io/CREDENTIALS/ for more - information about systemd credentials. - ''; - default = { }; - example = { - database-password = { - text = "my-secret-password"; - }; - ssl-cert = { - source = "./cert.pem"; - }; - binary-key = { - mechanism = "fw_cfg"; - source = "./private.der"; - }; - config-file = { - mechanism = "smbios"; - text = '' - [database] - host=localhost - port=5432 - ''; - }; - }; type = types.attrsOf ( - lib.types.submodule ( - { - name, - options, - config, - ... - }: - { - options = { - mechanism = lib.mkOption { - type = lib.types.enum [ - "fw_cfg" - "smbios" - ]; - default = if pkgs.stdenv.hostPlatform.isx86 then "smbios" else "fw_cfg"; - defaultText = lib.literalExpression ''if pkgs.stdenv.hostPlatform.isx86 then "smbios" else "fw_cfg"''; - description = '' - The mechanism used to pass the credential to the VM. - ''; - }; - source = lib.mkOption { - type = lib.types.nullOr (lib.types.pathWith { }); - default = null; - description = '' - Source file on the host containing the credential data. - ''; - }; - text = lib.mkOption { - default = null; - type = lib.types.nullOr lib.types.str; - description = '' - Text content of the credential. - - For binary data or when the credential content should come from - an existing file, use `source` instead. - - ::: {.warning} - The text here is stored in the host's nix store as a file. - ::: - ''; - }; - }; - config.source = lib.mkIf (config.text != null) ( - lib.mkDerivedConfig options.text (pkgs.writeText name) - ); - } - ) + lib.types.submodule { + options.mechanism = lib.mkOption { + type = lib.types.enum [ + "fw_cfg" + "smbios" + ]; + default = if pkgs.stdenv.hostPlatform.isx86 then "smbios" else "fw_cfg"; + defaultText = lib.literalExpression ''if pkgs.stdenv.hostPlatform.isx86 then "smbios" else "fw_cfg"''; + description = '' + The mechanism used to pass the credential to the VM. + ''; + }; + } ); }; diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index 7899bc60480d..fc4c96312a9e 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -448,6 +448,14 @@ in }; coturn = runTest ./coturn.nix; couchdb = runTest ./couchdb.nix; + credentials-fwcfg = runTest { + imports = [ ./credentials.nix ]; + _module.args.mechanism = "fw_cfg"; + }; + credentials-smbios = runTestOn [ "x86_64-linux" ] { + imports = [ ./credentials.nix ]; + _module.args.mechanism = "smbios"; + }; cri-o = runTestOn [ "aarch64-linux" "x86_64-linux" ] ./cri-o.nix; croc = runTest ./croc.nix; cross-seed = runTest ./cross-seed.nix; @@ -1425,14 +1433,6 @@ in pykms = runTest ./pykms.nix; qbittorrent = runTest ./qbittorrent.nix; qboot = runTestOn [ "x86_64-linux" "i686-linux" ] ./qboot.nix; - qemu-vm-credentials-fwcfg = runTest { - imports = [ ./qemu-vm-credentials.nix ]; - _module.args.mechanism = "fw_cfg"; - }; - qemu-vm-credentials-smbios = runTestOn [ "x86_64-linux" ] { - imports = [ ./qemu-vm-credentials.nix ]; - _module.args.mechanism = "smbios"; - }; qemu-vm-external-disk-image = runTest ./qemu-vm-external-disk-image.nix; qemu-vm-restrictnetwork = handleTest ./qemu-vm-restrictnetwork.nix { }; qemu-vm-store = runTest ./qemu-vm-store.nix; @@ -1715,6 +1715,7 @@ in systemd-user-settings = runTest ./systemd-user-settings.nix; systemd-user-tmpfiles-rules = runTest ./systemd-user-tmpfiles-rules.nix; systemd-userdbd = runTest ./systemd-userdbd.nix; + systemd-varlink = runTest ./systemd-varlink.nix; systemtap = handleTest ./systemtap.nix { }; szurubooru = handleTest ./szurubooru.nix { }; taler = handleTest ./taler { }; diff --git a/nixos/tests/boot.nix b/nixos/tests/boot.nix index d1ac1a8769fe..a59f94b94edf 100644 --- a/nixos/tests/boot.nix +++ b/nixos/tests/boot.nix @@ -207,7 +207,7 @@ in import os # Create a mutable linked image backed by the read-only SD image - if os.system("qemu-img create -f qcow2 -F raw -b ${sdImage} ${mutableImage}") != 0: + if os.system("${pkgs.qemu}/bin/qemu-img create -f qcow2 -F raw -b ${sdImage} ${mutableImage}") != 0: raise RuntimeError("Could not create mutable linked image") machine = create_machine("${startCommand}") diff --git a/nixos/tests/common/ec2.nix b/nixos/tests/common/ec2.nix index 864afc63cb8b..f28e094d455b 100644 --- a/nixos/tests/common/ec2.nix +++ b/nixos/tests/common/ec2.nix @@ -51,9 +51,11 @@ in ) os.makedirs(image_dir, mode=0o700, exist_ok=True) disk_image = os.path.join(image_dir, "machine.qcow2") + QEMU_BIN = "${pkgs.qemu}" + QEMU_IMG = f"{QEMU_BIN}/bin/qemu-img" subprocess.check_call( [ - "qemu-img", + QEMU_IMG, "create", "-f", "qcow2", @@ -64,7 +66,7 @@ in disk_image, ] ) - subprocess.check_call(["qemu-img", "resize", disk_image, "10G"]) + subprocess.check_call([QEMU_IMG, "resize", disk_image, "10G"]) # Note: we use net=169.0.0.0/8 rather than # net=169.254.0.0/16 to prevent dhcpcd from getting horribly @@ -74,7 +76,7 @@ in # turn off the DHCP server, but qemu does not have an option # to do that. start_command = ( - "qemu-kvm -m 1024" + f"{QEMU_BIN}/bin/qemu-kvm -m 1024" + " -device virtio-net-pci,netdev=vlan0" + " -netdev 'user,id=vlan0,net=169.0.0.0/8,guestfwd=tcp:169.254.169.254:80-cmd:${getExe imdsServer} ${metaData}'" + f" -drive file={disk_image},if=virtio,werror=report" diff --git a/nixos/tests/credentials.nix b/nixos/tests/credentials.nix new file mode 100644 index 000000000000..7984ffd03593 --- /dev/null +++ b/nixos/tests/credentials.nix @@ -0,0 +1,106 @@ +{ + lib, + pkgs, + mechanism, + ... +}: + +let + secret = '' + foo + bar + baz + ''; + secret-file = "bar"; + + common-credentials = { + secret-default-mechanism = { + text = "default-mechanism"; + }; + secret-file-nix-store = { + source = pkgs.writeText "secret-file-nix-store" secret-file; + }; + secret-file-host = { + source = "./secret-file-host"; + }; + secret-file-host-binary = { + source = "./secret-file-host-binary"; + }; + }; +in + +{ + name = "credentials-${mechanism}"; + + meta.maintainers = with lib.maintainers; [ arianvp ]; + + # No VM<->container traffic in this test; credentials are static. + requiredFeatures.devnet = lib.mkForce false; + + nodes.vm = { + virtualisation.credentials = common-credentials // { + secret = { + inherit mechanism; + text = secret; + }; + }; + }; + + containers.container = { + virtualisation.credentials = common-credentials // { + secret = { + text = secret; + }; + }; + }; + + testScript = '' + import base64 + + secret_file_host = "baz" + # Binary data with null bytes, high bytes, and other problematic characters. + secret_file_host_binary = bytes([ + 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, + 0x08, 0x09, 0x0A, 0x0B, 0x0C, 0x0D, 0x0E, 0x0F, + 0xDE, 0xAD, 0xBE, 0xEF, + 0xFF, 0xFE, 0xFD, 0xFC, + 0x00, 0x00, 0x00, 0x00, + 0x80, 0x81, 0x82, 0x83, + ]) + + def assert_credentials(m): + with open(m.state_dir / "secret-file-host", "w") as f: + f.write(secret_file_host) + with open(m.state_dir / "secret-file-host-binary", "wb") as f2: + f2.write(secret_file_host_binary) + + t.assertEqual( + m.succeed("systemd-creds --system cat secret").strip(), + "foo\nbar\nbaz", + ) + t.assertEqual( + m.succeed("systemd-creds --system cat secret-default-mechanism").strip(), + "default-mechanism", + ) + t.assertEqual( + m.succeed("systemd-creds --system cat secret-file-nix-store").strip(), + "${secret-file}", + ) + t.assertEqual( + m.succeed("systemd-creds --system cat secret-file-host").strip(), + secret_file_host, + ) + result = m.succeed( + "systemd-creds --system cat secret-file-host-binary --transcode=base64" + ).strip() + expected = base64.b64encode(secret_file_host_binary).decode("ascii") + t.assertEqual( + result, + expected, + f"Binary credential mismatch: got {result}, expected {expected}", + ) + + assert_credentials(vm) + assert_credentials(container) + ''; +} diff --git a/nixos/tests/ec2-image.nix b/nixos/tests/ec2-image.nix index b54b153bd52e..df07d14b8ba7 100644 --- a/nixos/tests/ec2-image.nix +++ b/nixos/tests/ec2-image.nix @@ -88,294 +88,298 @@ in }; }; - testScript = '' - import os - import re - import subprocess - import tempfile + testScript = + { nodes, ... }: + '' + import os + import re + import subprocess + import tempfile - # Instance Metadata Service (IMDSv2 with 1.0 metadata version) - # TODO: Use 'latest' metadata version instead of '1.0' - # TODO: [Test matrix] also test providing the host key through IMDS - # - i.e. a test module argument to select between writing or reading the host key - def create_ec2_metadata_dir(temp_dir, client_pubkey): - """Create fake EC2 metadata directory structure with mock data""" - metadata_dir = os.path.join(temp_dir.name, "ec2-metadata") + # Instance Metadata Service (IMDSv2 with 1.0 metadata version) + # TODO: Use 'latest' metadata version instead of '1.0' + # TODO: [Test matrix] also test providing the host key through IMDS + # - i.e. a test module argument to select between writing or reading the host key + def create_ec2_metadata_dir(temp_dir, client_pubkey): + """Create fake EC2 metadata directory structure with mock data""" + metadata_dir = os.path.join(temp_dir.name, "ec2-metadata") - # Create directory structure - os.makedirs(os.path.join(metadata_dir, "1.0", "meta-data", "public-keys", "0"), exist_ok=True) - os.makedirs(os.path.join(metadata_dir, "latest", "api"), exist_ok=True) + # Create directory structure + os.makedirs(os.path.join(metadata_dir, "1.0", "meta-data", "public-keys", "0"), exist_ok=True) + os.makedirs(os.path.join(metadata_dir, "latest", "api"), exist_ok=True) - # Metadata version 1.0 endpoints (what fetch-ec2-metadata.sh actually fetches) - with open(os.path.join(metadata_dir, "1.0", "meta-data", "hostname"), "w") as f: - f.write("test-instance") - with open(os.path.join(metadata_dir, "1.0", "meta-data", "ami-manifest-path"), "w") as f: - f.write("(test)") - with open(os.path.join(metadata_dir, "1.0", "meta-data", "instance-id"), "w") as f: - f.write("i-1234567890abcdef0") - with open(os.path.join(metadata_dir, "1.0", "user-data"), "w") as f: - f.write("") - with open(os.path.join(metadata_dir, "1.0", "meta-data", "public-keys", "0", "openssh-key"), "w") as f: - f.write(client_pubkey) + # Metadata version 1.0 endpoints (what fetch-ec2-metadata.sh actually fetches) + with open(os.path.join(metadata_dir, "1.0", "meta-data", "hostname"), "w") as f: + f.write("test-instance") + with open(os.path.join(metadata_dir, "1.0", "meta-data", "ami-manifest-path"), "w") as f: + f.write("(test)") + with open(os.path.join(metadata_dir, "1.0", "meta-data", "instance-id"), "w") as f: + f.write("i-1234567890abcdef0") + with open(os.path.join(metadata_dir, "1.0", "user-data"), "w") as f: + f.write("") + with open(os.path.join(metadata_dir, "1.0", "meta-data", "public-keys", "0", "openssh-key"), "w") as f: + f.write(client_pubkey) - # IMDSv2 token endpoint - return a fake token - with open(os.path.join(metadata_dir, "latest", "api", "token"), "w") as f: - f.write("test-token-12345") + # IMDSv2 token endpoint - return a fake token + with open(os.path.join(metadata_dir, "latest", "api", "token"), "w") as f: + f.write("test-token-12345") - return metadata_dir + return metadata_dir - def generate_client_ssh_key(): - """Generate SSH key pair on VM host for client authentication""" - # Use temporary directory for key generation - import tempfile - with tempfile.TemporaryDirectory() as key_dir: - private_key = os.path.join(key_dir, "id_ed25519") - public_key = os.path.join(key_dir, "id_ed25519.pub") + def generate_client_ssh_key(): + """Generate SSH key pair on VM host for client authentication""" + # Use temporary directory for key generation + import tempfile + with tempfile.TemporaryDirectory() as key_dir: + private_key = os.path.join(key_dir, "id_ed25519") + public_key = os.path.join(key_dir, "id_ed25519.pub") - # Generate key pair using host SSH tools - ret = os.system(f"${hostPkgs.openssh}/bin/ssh-keygen -t ed25519 -f {private_key} -N \"\"") - if ret != 0: - raise Exception("Failed to generate SSH key pair") + # Generate key pair using host SSH tools + ret = os.system(f"${hostPkgs.openssh}/bin/ssh-keygen -t ed25519 -f {private_key} -N \"\"") + if ret != 0: + raise Exception("Failed to generate SSH key pair") - # Read the generated public key - with open(public_key, "r") as f: - client_pubkey = f.read().strip() + # Read the generated public key + with open(public_key, "r") as f: + client_pubkey = f.read().strip() - # Read the private key - with open(private_key, "r") as f: - client_private_key = f.read() + # Read the private key + with open(private_key, "r") as f: + client_private_key = f.read() - return client_pubkey, client_private_key + return client_pubkey, client_private_key - def setup_client_ssh_key(client, client_private_key): - """Install the pre-generated SSH private key on client""" - client.succeed("mkdir -p /root/.ssh") - client.succeed(f"cat > /root/.ssh/id_ed25519 << 'EOF'\n{client_private_key}\nEOF") - client.succeed("chmod 600 /root/.ssh/id_ed25519") + def setup_client_ssh_key(client, client_private_key): + """Install the pre-generated SSH private key on client""" + client.succeed("mkdir -p /root/.ssh") + client.succeed(f"cat > /root/.ssh/id_ed25519 << 'EOF'\n{client_private_key}\nEOF") + client.succeed("chmod 600 /root/.ssh/id_ed25519") - def setup_machine(temp_dir, client_pubkey): - """Initialize EC2 machine with disk image, metadata server, and networking""" - # Set up disk image - image_dir = os.path.join( - os.environ.get("TMPDIR", tempfile.gettempdir()), "tmp", "vm-state-machine" - ) - os.makedirs(image_dir, mode=0o700, exist_ok=True) - disk_image = os.path.join(image_dir, "machine.qcow2") - subprocess.check_call([ - "qemu-img", "create", "-f", "qcow2", "-F", "qcow2", - "-o", "backing_file=${image}", disk_image - ]) - subprocess.check_call(["qemu-img", "resize", disk_image, "10G"]) + def setup_machine(temp_dir, client_pubkey): + """Initialize EC2 machine with disk image, metadata server, and networking""" + # Set up disk image + image_dir = os.path.join( + os.environ.get("TMPDIR", tempfile.gettempdir()), "tmp", "vm-state-machine" + ) + os.makedirs(image_dir, mode=0o700, exist_ok=True) + disk_image = os.path.join(image_dir, "machine.qcow2") + QEMU = "${nodes.machine.virtualisation.qemu.package}" + QEMU_IMG = f"{QEMU}/bin/qemu-img" + subprocess.check_call([ + QEMU_IMG, "create", "-f", "qcow2", "-F", "qcow2", + "-o", "backing_file=${image}", disk_image + ]) + subprocess.check_call([QEMU_IMG, "resize", disk_image, "10G"]) - # Create fake EC2 metadata in temporary directory with client's public key - metadata_dir = create_ec2_metadata_dir(temp_dir, client_pubkey) + # Create fake EC2 metadata in temporary directory with client's public key + metadata_dir = create_ec2_metadata_dir(temp_dir, client_pubkey) - # Add both VLAN networking (matching test framework) and EC2 metadata server - vlan_net = ( - " -device virtio-net-pci,netdev=vlan1,mac=52:54:00:12:01:02" - + ' -netdev vde,id=vlan1,sock="$QEMU_VDE_SOCKET_1"' - ) - metadata_net = ( - " -device virtio-net-pci,netdev=ec2meta" - + f" -netdev 'user,id=ec2meta,net=169.0.0.0/8,guestfwd=tcp:169.254.169.254:80-cmd:${lib.getExe imdsServer} {metadata_dir}'" - ) + # Add both VLAN networking (matching test framework) and EC2 metadata server + vlan_net = ( + " -device virtio-net-pci,netdev=vlan1,mac=52:54:00:12:01:02" + + ' -netdev vde,id=vlan1,sock="$QEMU_VDE_SOCKET_1"' + ) + metadata_net = ( + " -device virtio-net-pci,netdev=ec2meta" + + f" -netdev 'user,id=ec2meta,net=169.0.0.0/8,guestfwd=tcp:169.254.169.254:80-cmd:${lib.getExe imdsServer} {metadata_dir}'" + ) - start_command = ( - "qemu-kvm -m 1024" - + f" -drive file={disk_image},if=virtio,werror=report" - + vlan_net - + metadata_net - + " $QEMU_OPTS" - ) + start_command = ( + f"{QEMU}/bin/qemu-kvm -m 1024" + + f" -drive file={disk_image},if=virtio,werror=report" + + vlan_net + + metadata_net + + " $QEMU_OPTS" + ) - return create_machine(start_command), metadata_dir + return create_machine(start_command), metadata_dir - def test_userdata_decompression(machine, user_data_path, compressed_data, format_name): - """Test that compressed user-data is decompressed by fetch-ec2-metadata""" - test_marker = f"{format_name}-decompression-test" - with open(user_data_path, "wb") as f: - f.write(compressed_data) - machine.succeed("systemctl reset-failed fetch-ec2-metadata; systemctl restart fetch-ec2-metadata") - result = machine.succeed("cat /etc/ec2-metadata/user-data") - assert test_marker in result, f"Expected '{test_marker}' in decompressed {format_name} content, got: {result}" - journal = machine.succeed("journalctl -u fetch-ec2-metadata --no-pager -b") - assert "decompressing:" in journal, f"Expected decompression log in journal for {format_name}" + def test_userdata_decompression(machine, user_data_path, compressed_data, format_name): + """Test that compressed user-data is decompressed by fetch-ec2-metadata""" + test_marker = f"{format_name}-decompression-test" + with open(user_data_path, "wb") as f: + f.write(compressed_data) + machine.succeed("systemctl reset-failed fetch-ec2-metadata; systemctl restart fetch-ec2-metadata") + result = machine.succeed("cat /etc/ec2-metadata/user-data") + assert test_marker in result, f"Expected '{test_marker}' in decompressed {format_name} content, got: {result}" + journal = machine.succeed("journalctl -u fetch-ec2-metadata --no-pager -b") + assert "decompressing:" in journal, f"Expected decompression log in journal for {format_name}" - # Create temporary directory for metadata (scoped for cleanup) - temp_dir = tempfile.TemporaryDirectory() + # Create temporary directory for metadata (scoped for cleanup) + temp_dir = tempfile.TemporaryDirectory() - # Start client first (but don't wait for it to boot) - client.start() + # Start client first (but don't wait for it to boot) + client.start() - # Generate SSH key pair on VM host before starting machine - client_pubkey, client_private_key = generate_client_ssh_key() + # Generate SSH key pair on VM host before starting machine + client_pubkey, client_private_key = generate_client_ssh_key() - # Set up machine with client's public key in metadata service - machine, metadata_dir = setup_machine(temp_dir, client_pubkey) - user_data_path = os.path.join(metadata_dir, "1.0", "user-data") + # Set up machine with client's public key in metadata service + machine, metadata_dir = setup_machine(temp_dir, client_pubkey) + user_data_path = os.path.join(metadata_dir, "1.0", "user-data") - try: - machine.start() + try: + machine.start() - # Wait for services to be ready - machine.wait_for_unit("sshd.service") - machine.wait_for_unit("print-host-key.service") - machine.wait_for_unit("apply-ec2-data.service") + # Wait for services to be ready + machine.wait_for_unit("sshd.service") + machine.wait_for_unit("print-host-key.service") + machine.wait_for_unit("apply-ec2-data.service") - # Extract shared variables outside subtests - machine_ip = "${config.nodes.machine.networking.primaryIPAddress}" + # Extract shared variables outside subtests + machine_ip = "${config.nodes.machine.networking.primaryIPAddress}" - with subtest("EC2 metadata service connectivity"): - # Obtain an IMDSv2 token, then use it to fetch metadata - imds_token = machine.succeed( - "curl -sf -X PUT -H 'X-aws-ec2-metadata-token-ttl-seconds: 600'" - " http://169.254.169.254/latest/api/token" - ).strip() - assert imds_token, "Failed to obtain IMDSv2 token" - hostname_response = machine.succeed( - f"curl -sf -H 'X-aws-ec2-metadata-token: {imds_token}'" - " http://169.254.169.254/1.0/meta-data/hostname" - ) - assert "test-instance" in hostname_response, f"Expected 'test-instance', got: {hostname_response}" + with subtest("EC2 metadata service connectivity"): + # Obtain an IMDSv2 token, then use it to fetch metadata + imds_token = machine.succeed( + "curl -sf -X PUT -H 'X-aws-ec2-metadata-token-ttl-seconds: 600'" + " http://169.254.169.254/latest/api/token" + ).strip() + assert imds_token, "Failed to obtain IMDSv2 token" + hostname_response = machine.succeed( + f"curl -sf -H 'X-aws-ec2-metadata-token: {imds_token}'" + " http://169.254.169.254/1.0/meta-data/hostname" + ) + assert "test-instance" in hostname_response, f"Expected 'test-instance', got: {hostname_response}" - with subtest("SSH host key extraction from console"): - console_log = machine.get_console_log() - assert "-----BEGIN SSH HOST KEY FINGERPRINTS-----" in console_log - assert "-----END SSH HOST KEY FINGERPRINTS-----" in console_log - assert "-----BEGIN SSH HOST KEY KEYS-----" in console_log - assert "-----END SSH HOST KEY KEYS-----" in console_log + with subtest("SSH host key extraction from console"): + console_log = machine.get_console_log() + assert "-----BEGIN SSH HOST KEY FINGERPRINTS-----" in console_log + assert "-----END SSH HOST KEY FINGERPRINTS-----" in console_log + assert "-----BEGIN SSH HOST KEY KEYS-----" in console_log + assert "-----END SSH HOST KEY KEYS-----" in console_log - keys_pattern = r"-----BEGIN SSH HOST KEY KEYS-----(.*?)-----END SSH HOST KEY KEYS-----" - keys_match = re.search(keys_pattern, console_log, re.DOTALL) - assert keys_match, "Could not find SSH host keys section" - keys_content = keys_match.group(1).strip() - assert "ssh-" in keys_content, "SSH keys should contain ssh- prefix" + keys_pattern = r"-----BEGIN SSH HOST KEY KEYS-----(.*?)-----END SSH HOST KEY KEYS-----" + keys_match = re.search(keys_pattern, console_log, re.DOTALL) + assert keys_match, "Could not find SSH host keys section" + keys_content = keys_match.group(1).strip() + assert "ssh-" in keys_content, "SSH keys should contain ssh- prefix" - with subtest("Network connectivity"): - client.succeed(f"ping -c 1 {machine_ip}") + with subtest("Network connectivity"): + client.succeed(f"ping -c 1 {machine_ip}") - with subtest("SSH connectivity with strict host key checking"): - # Install the pre-generated private key on client - setup_client_ssh_key(client, client_private_key) + with subtest("SSH connectivity with strict host key checking"): + # Install the pre-generated private key on client + setup_client_ssh_key(client, client_private_key) - # Get console log and extract host keys - console_log = machine.get_console_log() - keys_pattern = r"-----BEGIN SSH HOST KEY KEYS-----(.*?)-----END SSH HOST KEY KEYS-----" - keys_match = re.search(keys_pattern, console_log, re.DOTALL) - assert keys_match, "Could not find SSH host keys section" + # Get console log and extract host keys + console_log = machine.get_console_log() + keys_pattern = r"-----BEGIN SSH HOST KEY KEYS-----(.*?)-----END SSH HOST KEY KEYS-----" + keys_match = re.search(keys_pattern, console_log, re.DOTALL) + assert keys_match, "Could not find SSH host keys section" - # Create known_hosts file from console-extracted host keys - keys_content = keys_match.group(1).strip() - known_hosts_entries = [] - for line in keys_content.split('\n'): - if line.strip() and line.startswith('ssh-'): - known_hosts_entries.append(f"{machine_ip} {line.strip()}") + # Create known_hosts file from console-extracted host keys + keys_content = keys_match.group(1).strip() + known_hosts_entries = [] + for line in keys_content.split('\n'): + if line.strip() and line.startswith('ssh-'): + known_hosts_entries.append(f"{machine_ip} {line.strip()}") - assert known_hosts_entries, "No SSH host keys found for known_hosts generation" + assert known_hosts_entries, "No SSH host keys found for known_hosts generation" - known_hosts_content = '\n'.join(known_hosts_entries) - client.succeed(f"cat > /root/.ssh/known_hosts << 'EOF'\n{known_hosts_content}\nEOF") + known_hosts_content = '\n'.join(known_hosts_entries) + client.succeed(f"cat > /root/.ssh/known_hosts << 'EOF'\n{known_hosts_content}\nEOF") - # Test SSH connectivity with strict host key checking - ssh_result = client.succeed(f"ssh -o ConnectTimeout=60 -o BatchMode=yes -i /root/.ssh/id_ed25519 root@{machine_ip} 'echo Hello from $(hostname)'") - assert "Hello from test-instance" in ssh_result, f"Unexpected SSH result: {ssh_result}" + # Test SSH connectivity with strict host key checking + ssh_result = client.succeed(f"ssh -o ConnectTimeout=60 -o BatchMode=yes -i /root/.ssh/id_ed25519 root@{machine_ip} 'echo Hello from $(hostname)'") + assert "Hello from test-instance" in ssh_result, f"Unexpected SSH result: {ssh_result}" - with subtest("Basic EC2 functionality"): - machine.succeed("findmnt / -o SIZE -n | grep -E '[0-9]+G'") + with subtest("Basic EC2 functionality"): + machine.succeed("findmnt / -o SIZE -n | grep -E '[0-9]+G'") - with subtest("Decompression of gzip-compressed user-data"): - import gzip as gzip_mod - test_data = b"#!/bin/bash\necho gzip-decompression-test\n" - test_userdata_decompression(machine, user_data_path, gzip_mod.compress(test_data), "gzip") + with subtest("Decompression of gzip-compressed user-data"): + import gzip as gzip_mod + test_data = b"#!/bin/bash\necho gzip-decompression-test\n" + test_userdata_decompression(machine, user_data_path, gzip_mod.compress(test_data), "gzip") - with subtest("Decompression of bzip2-compressed user-data"): - import bz2 - test_data = b"#!/bin/bash\necho bzip2-decompression-test\n" - test_userdata_decompression(machine, user_data_path, bz2.compress(test_data), "bzip2") + with subtest("Decompression of bzip2-compressed user-data"): + import bz2 + test_data = b"#!/bin/bash\necho bzip2-decompression-test\n" + test_userdata_decompression(machine, user_data_path, bz2.compress(test_data), "bzip2") - with subtest("Decompression of xz-compressed user-data"): - import lzma - test_data = b"#!/bin/bash\necho xz-decompression-test\n" - test_userdata_decompression(machine, user_data_path, lzma.compress(test_data), "xz") + with subtest("Decompression of xz-compressed user-data"): + import lzma + test_data = b"#!/bin/bash\necho xz-decompression-test\n" + test_userdata_decompression(machine, user_data_path, lzma.compress(test_data), "xz") - with subtest("Decompression of zstd-compressed user-data"): - test_data = b"#!/bin/bash\necho zstd-decompression-test\n" - proc = subprocess.run( - ["${hostPkgs.zstd}/bin/zstd", "-c"], - input=test_data, capture_output=True, check=True, - ) - test_userdata_decompression(machine, user_data_path, proc.stdout, "zstd") + with subtest("Decompression of zstd-compressed user-data"): + test_data = b"#!/bin/bash\necho zstd-decompression-test\n" + proc = subprocess.run( + ["${hostPkgs.zstd}/bin/zstd", "-c"], + input=test_data, capture_output=True, check=True, + ) + test_userdata_decompression(machine, user_data_path, proc.stdout, "zstd") - with subtest("Decompression of lzip-compressed user-data"): - test_data = b"#!/bin/bash\necho lzip-decompression-test\n" - proc = subprocess.run( - ["${hostPkgs.lzip}/bin/lzip", "-c"], - input=test_data, capture_output=True, check=True, - ) - test_userdata_decompression(machine, user_data_path, proc.stdout, "lzip") + with subtest("Decompression of lzip-compressed user-data"): + test_data = b"#!/bin/bash\necho lzip-decompression-test\n" + proc = subprocess.run( + ["${hostPkgs.lzip}/bin/lzip", "-c"], + input=test_data, capture_output=True, check=True, + ) + test_userdata_decompression(machine, user_data_path, proc.stdout, "lzip") - with subtest("IPv6 IMDS fallback"): - # Save hostname fetched via IPv4 for later comparison - original_hostname = machine.succeed("cat /etc/ec2-metadata/hostname").strip() + with subtest("IPv6 IMDS fallback"): + # Save hostname fetched via IPv4 for later comparison + original_hostname = machine.succeed("cat /etc/ec2-metadata/hostname").strip() - # Assign the EC2 IPv6 IMDS address to loopback - machine.succeed("ip -6 addr add fd00:ec2::254/128 dev lo") + # Assign the EC2 IPv6 IMDS address to loopback + machine.succeed("ip -6 addr add fd00:ec2::254/128 dev lo") - # Create metadata directory structure for the IPv6 endpoint - machine.succeed( - "mkdir -p /tmp/ipv6-metadata/1.0/meta-data/public-keys/0" - " && mkdir -p /tmp/ipv6-metadata/latest/api" - " && cp /etc/ec2-metadata/hostname /tmp/ipv6-metadata/1.0/meta-data/hostname" - " && cp /etc/ec2-metadata/ami-manifest-path /tmp/ipv6-metadata/1.0/meta-data/ami-manifest-path" - " && echo i-1234567890abcdef0 > /tmp/ipv6-metadata/1.0/meta-data/instance-id" - " && echo ipv6-test-token > /tmp/ipv6-metadata/latest/api/token" - " && touch /tmp/ipv6-metadata/1.0/user-data" - ) - machine.execute( - "test -f /etc/ec2-metadata/public-keys-0-openssh-key" - " && cp /etc/ec2-metadata/public-keys-0-openssh-key" - " /tmp/ipv6-metadata/1.0/meta-data/public-keys/0/openssh-key" - ) + # Create metadata directory structure for the IPv6 endpoint + machine.succeed( + "mkdir -p /tmp/ipv6-metadata/1.0/meta-data/public-keys/0" + " && mkdir -p /tmp/ipv6-metadata/latest/api" + " && cp /etc/ec2-metadata/hostname /tmp/ipv6-metadata/1.0/meta-data/hostname" + " && cp /etc/ec2-metadata/ami-manifest-path /tmp/ipv6-metadata/1.0/meta-data/ami-manifest-path" + " && echo i-1234567890abcdef0 > /tmp/ipv6-metadata/1.0/meta-data/instance-id" + " && echo ipv6-test-token > /tmp/ipv6-metadata/latest/api/token" + " && touch /tmp/ipv6-metadata/1.0/user-data" + ) + machine.execute( + "test -f /etc/ec2-metadata/public-keys-0-openssh-key" + " && cp /etc/ec2-metadata/public-keys-0-openssh-key" + " /tmp/ipv6-metadata/1.0/meta-data/public-keys/0/openssh-key" + ) - # Serve metadata on the IPv6 IMDS address via socat + imds-server (inetd-style) - machine.succeed( - "systemd-run --unit=ipv6-imds --" - " socat TCP6-LISTEN:80,bind=[fd00:ec2::254],fork,reuseaddr" - " SYSTEM:'${lib.getExe imdsServer} /tmp/ipv6-metadata'" - ) + # Serve metadata on the IPv6 IMDS address via socat + imds-server (inetd-style) + machine.succeed( + "systemd-run --unit=ipv6-imds --" + " socat TCP6-LISTEN:80,bind=[fd00:ec2::254],fork,reuseaddr" + " SYSTEM:'${lib.getExe imdsServer} /tmp/ipv6-metadata'" + ) - # Wait for IPv6 IMDS to become reachable (token endpoint doesn't require auth) - machine.wait_until_succeeds( - "curl -sf -X PUT -H 'X-aws-ec2-metadata-token-ttl-seconds: 600'" - " http://[fd00:ec2::254]/latest/api/token" - ) + # Wait for IPv6 IMDS to become reachable (token endpoint doesn't require auth) + machine.wait_until_succeeds( + "curl -sf -X PUT -H 'X-aws-ec2-metadata-token-ttl-seconds: 600'" + " http://[fd00:ec2::254]/latest/api/token" + ) - # Block IPv4 IMDS to force fallback to IPv6 - machine.succeed( - "iptables -I OUTPUT -d 169.254.169.254 -p tcp --dport 80 -j REJECT" - ) + # Block IPv4 IMDS to force fallback to IPv6 + machine.succeed( + "iptables -I OUTPUT -d 169.254.169.254 -p tcp --dport 80 -j REJECT" + ) - # Verify IPv4 IMDS is now unreachable - machine.fail( - "curl -sf --connect-timeout 2 http://169.254.169.254/1.0/meta-data/hostname" - ) + # Verify IPv4 IMDS is now unreachable + machine.fail( + "curl -sf --connect-timeout 2 http://169.254.169.254/1.0/meta-data/hostname" + ) - # Clear fetched metadata and re-run the fetcher - machine.succeed("rm -f /etc/ec2-metadata/*") - machine.succeed("systemctl restart fetch-ec2-metadata") + # Clear fetched metadata and re-run the fetcher + machine.succeed("rm -f /etc/ec2-metadata/*") + machine.succeed("systemctl restart fetch-ec2-metadata") - # Verify metadata was successfully re-fetched via IPv6 - hostname = machine.succeed("cat /etc/ec2-metadata/hostname").strip() - assert hostname == original_hostname, f"Expected '{original_hostname}', got '{hostname}'" + # Verify metadata was successfully re-fetched via IPv6 + hostname = machine.succeed("cat /etc/ec2-metadata/hostname").strip() + assert hostname == original_hostname, f"Expected '{original_hostname}', got '{hostname}'" - # Clean up: restore IPv4 IMDS access - machine.succeed( - "iptables -D OUTPUT -d 169.254.169.254 -p tcp --dport 80 -j REJECT" - ) - machine.succeed("systemctl stop ipv6-imds") + # Clean up: restore IPv4 IMDS access + machine.succeed( + "iptables -D OUTPUT -d 169.254.169.254 -p tcp --dport 80 -j REJECT" + ) + machine.succeed("systemctl stop ipv6-imds") - finally: - machine.shutdown() - temp_dir.cleanup() - ''; + finally: + machine.shutdown() + temp_dir.cleanup() + ''; } diff --git a/nixos/tests/qemu-vm-credentials.nix b/nixos/tests/qemu-vm-credentials.nix deleted file mode 100644 index 9ee2d270d8f0..000000000000 --- a/nixos/tests/qemu-vm-credentials.nix +++ /dev/null @@ -1,83 +0,0 @@ -{ - lib, - pkgs, - mechanism, - ... -}: - -let - secret = '' - foo - bar - baz - ''; - secret-file = "bar"; -in - -{ - name = "qemu-vm-credentials-${mechanism}"; - - meta.maintainers = with lib.maintainers; [ arianvp ]; - - nodes = { - machine = { - virtualisation.credentials = { - secret = { - inherit mechanism; - text = secret; - }; - secret-default-mechanism = { - text = "default-mechanism"; - }; - secret-file-nix-store = { - inherit mechanism; - source = pkgs.writeText "secret-file-nix-store" secret-file; - }; - secret-file-host = { - inherit mechanism; - source = "./secret-file-host"; - }; - secret-file-host-binary = { - inherit mechanism; - source = "./secret-file-host-binary"; - }; - }; - }; - }; - - testScript = '' - import base64 - secret_file_host = "baz" - # Binary data with null bytes, high bytes, and all sorts of problematic characters - secret_file_host_binary = bytes([ - 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, # null and control chars - 0x08, 0x09, 0x0A, 0x0B, 0x0C, 0x0D, 0x0E, 0x0F, - 0xDE, 0xAD, 0xBE, 0xEF, # classic binary pattern - 0xFF, 0xFE, 0xFD, 0xFC, # high bytes - 0x00, 0x00, 0x00, 0x00, # multiple nulls - 0x80, 0x81, 0x82, 0x83, # more high bytes - ]) - - with open(machine.state_dir / "secret-file-host", "w") as f: - f.write(secret_file_host) - with open(machine.state_dir / "secret-file-host-binary", "wb") as f2: - f2.write(secret_file_host_binary) - - - # Test text credential - t.assertEqual(machine.succeed("systemd-creds --system cat secret").strip(), "foo\nbar\nbaz") - - t.assertEqual(machine.succeed("systemd-creds --system cat secret-default-mechanism").strip(), "default-mechanism") - - # Test credential from nix store - t.assertEqual(machine.succeed("systemd-creds --system cat secret-file-nix-store").strip(), "${secret-file}") - - # Test credential from host file - t.assertEqual(machine.succeed("systemd-creds --system cat secret-file-host").strip(), secret_file_host) - - # Test binary credential - verify exact binary content - result = machine.succeed("systemd-creds --system cat secret-file-host-binary --transcode=base64").strip() - expected = base64.b64encode(secret_file_host_binary).decode('ascii') - t.assertEqual(result, expected, f"Binary credential mismatch: got {result}, expected {expected}") - ''; -} diff --git a/nixos/tests/systemd-initrd-simple.nix b/nixos/tests/systemd-initrd-simple.nix index 191a23abb2e4..b02616e1b772 100644 --- a/nixos/tests/systemd-initrd-simple.nix +++ b/nixos/tests/systemd-initrd-simple.nix @@ -1,15 +1,15 @@ +{ pkgs, ... }: { name = "systemd-initrd-simple"; - nodes.machine = - { pkgs, ... }: - { - testing.initrdBackdoor = true; - boot.initrd.systemd.enable = true; - virtualisation.fileSystems."/".autoResize = true; - }; + nodes.machine = { + testing.initrdBackdoor = true; + boot.initrd.systemd.enable = true; + virtualisation.fileSystems."/".autoResize = true; + }; testScript = + { nodes, ... }: # python '' import subprocess @@ -43,7 +43,7 @@ oldAvail = machine.succeed("df --output=avail / | sed 1d") machine.shutdown() - subprocess.check_call(["qemu-img", "resize", "vm-state-machine/machine.qcow2", "+1G"]) + subprocess.check_call(["${nodes.machine.virtualisation.qemu.package}/bin/qemu-img", "resize", "vm-state-machine/machine.qcow2", "+1G"]) machine.start() machine.switch_root() diff --git a/nixos/tests/systemd-varlink.nix b/nixos/tests/systemd-varlink.nix new file mode 100644 index 000000000000..df5d7cbb73a3 --- /dev/null +++ b/nixos/tests/systemd-varlink.nix @@ -0,0 +1,46 @@ +{ lib, ... }: +{ + name = "systemd-varlink"; + meta.maintainers = [ lib.maintainers.raitobezarius ]; + nodes.machine = + { config, pkgs, ... }: + { + networking.useNetworkd = true; + services.resolved.enable = true; + systemd.network.enable = true; + }; + testScript = '' + def list_interfaces(intf_path: str) -> list[str]: + return machine.succeed(f"varlinkctl list-interfaces {intf_path}").split('\n') + + expected_reg_sd_interfaces = [ + ("BootControl", "bootctl"), + ("Credentials", "creds"), + ("Hostname", "hostnamed"), + ("JournalAccess", "journald"), + ("Import", "importd"), + ("Machine", "machined"), + ("Resolve", "resolved-varlink"), + ("Resolve.Monitor", "resolved-monitor"), + ("Udev", "udevd-varlink"), + ("MuteConsole", "mute-console"), + ("FactoryReset", "factory-reset"), + ("AskPassword", "ask-password"), + ("Network", "networkd-varlink"), + ("Repart", "repart"), + ] + expected_priv_sd_interfaces = [ + ("Login", None), # systemd-logind-varlink.socket exist but is not necessary. + ] + expected_interfaces = [ + (f"io.systemd.{intf}", f"systemd-{socket_name}", f"/run/varlink/registry/io.systemd.{intf}") for intf, socket_name in expected_reg_sd_interfaces + ] + [ + (f"io.systemd.{intf}", f"systemd-{socket_name}" if socket_name is not None else None, f"/run/systemd/io.systemd.{intf}") for intf, socket_name in expected_priv_sd_interfaces + ] + + for intf, socket_name, intf_path in expected_interfaces: + if socket_name is not None: + machine.wait_for_unit(f"{socket_name}.socket") + assert intf in list_interfaces(intf_path), f"Interface '{intf}' not found in the Varlink registry" + ''; +} diff --git a/nixos/tests/systemd.nix b/nixos/tests/systemd.nix index 8cca68465802..b04b288e8939 100644 --- a/nixos/tests/systemd.nix +++ b/nixos/tests/systemd.nix @@ -38,21 +38,23 @@ services.journald.extraConfig = "Storage=volatile"; test-support.displayManager.auto.user = "alice"; - systemd.shutdown.test = pkgs.writeScript "test.shutdown" '' - #!${pkgs.runtimeShell} - PATH=${ - lib.makeBinPath ( - with pkgs; - [ - util-linux - coreutils - ] - ) - } - mount -t 9p shared -o trans=virtio,version=9p2000.L /tmp/shared - touch /tmp/shared/shutdown-test - umount /tmp/shared - ''; + systemd.shutdownRamfs.contents."/etc/systemd/system-shutdown/test".source = + pkgs.writeShellScript "test.shutdown" '' + PATH=${ + lib.makeBinPath ( + with pkgs; + [ + util-linux + coreutils + ] + ) + } + mkdir -p /tmp/shared + mount -t 9p shared -o trans=virtio,version=9p2000.L /tmp/shared + touch /tmp/shared/shutdown-test + umount /tmp/shared + ''; + systemd.shutdownRamfs.storePaths = [ "${pkgs.util-linux}/bin" ]; systemd.services.oncalendar-test = { description = "calendar test"; @@ -147,7 +149,7 @@ subprocess.check_call( [ - "qemu-img", + "${nodes.machine.virtualisation.qemu.package}/bin/qemu-img", "convert", "-O", "raw", diff --git a/pkgs/applications/editors/neovim/tests/default.nix b/pkgs/applications/editors/neovim/tests/default.nix index 5bc2730da87b..c17957ffbe3a 100644 --- a/pkgs/applications/editors/neovim/tests/default.nix +++ b/pkgs/applications/editors/neovim/tests/default.nix @@ -204,23 +204,23 @@ pkgs.lib.recurseIntoAttrs rec { ${nvim_with_plug}/bin/nvim -V3log.txt -i NONE -c 'color base16-tomorrow-night' +quit! -e ''; - nvim_with_autoconfigure = pkgs.neovim.overrideAttrs { - plugins = [ - vimPlugins.unicode-vim - vimPlugins.fzf-hoogle-vim - ]; + nvim_with_autoconfigure = pkgs.neovim.override { + configure = { + packages.myPlugins.start = [ + vimPlugins.unicode-vim + vimPlugins.fzf-hoogle-vim + ]; + }; autoconfigure = true; - # legacy wrapper sets it to false - wrapRc = true; }; - nvim_with_runtimeDeps = pkgs.neovim.overrideAttrs { - plugins = [ - pkgs.vimPlugins.hex-nvim - ]; + nvim_with_runtimeDeps = pkgs.neovim.override { + configure = { + packages.myPlugins.start = [ + pkgs.vimPlugins.hex-nvim + ]; + }; autowrapRuntimeDeps = true; - # legacy wrapper sets it to false - wrapRc = true; }; nvim_with_ftplugin = diff --git a/pkgs/applications/editors/vscode/generic.nix b/pkgs/applications/editors/vscode/generic.nix index de93186c3db1..752ff76bf682 100644 --- a/pkgs/applications/editors/vscode/generic.nix +++ b/pkgs/applications/editors/vscode/generic.nix @@ -249,6 +249,9 @@ stdenv.mkDerivation ( }) ]; + strictDeps = true; + __structuredAttrs = true; + buildInputs = [ libsecret ] diff --git a/pkgs/applications/networking/cluster/terraform-providers/providers.json b/pkgs/applications/networking/cluster/terraform-providers/providers.json index dcc45bb855cc..1a49fccc3bbc 100644 --- a/pkgs/applications/networking/cluster/terraform-providers/providers.json +++ b/pkgs/applications/networking/cluster/terraform-providers/providers.json @@ -209,13 +209,13 @@ "vendorHash": "sha256-rCWeetM6nhNb1I1PmB66E5K1ku9ODRqN87MU9y6W/dc=" }, "cloudflare_cloudflare": { - "hash": "sha256-y3GAU5wLLETSrmYqGZs2I0qg8jnGcu32Xt/UHGS1NTA=", + "hash": "sha256-SHEK/NJrs1ZkyDc8jSnb39dT/wX7ixSsHc//cwhTfz8=", "homepage": "https://registry.terraform.io/providers/cloudflare/cloudflare", "owner": "cloudflare", "repo": "terraform-provider-cloudflare", - "rev": "v5.20.0", + "rev": "v5.21.1", "spdx": "Apache-2.0", - "vendorHash": "sha256-LGibxg94dOiMfNynQfBoxQ6zR8A7xDfGNTujmEJcu14=" + "vendorHash": "sha256-YLgIcohvOYBVt/GOkiqxdJVThhcphG2l8Lha1MwU9L4=" }, "cloudfoundry-community_cloudfoundry": { "hash": "sha256-1nYncJLVU/f9WD6Quh9IieIXgixPzbPk4zbtI1zmf9g=", diff --git a/pkgs/build-support/build-nim-package.nix b/pkgs/build-support/build-nim-package.nix index 1e8489212cd6..ade88ea9d3db 100644 --- a/pkgs/build-support/build-nim-package.nix +++ b/pkgs/build-support/build-nim-package.nix @@ -15,6 +15,7 @@ let baseAttrs = { strictDeps = true; enableParallelBuilding = true; + __structuredAttrs = true; doCheck = true; configurePhase = '' runHook preConfigure diff --git a/pkgs/by-name/at/attic-client/package.nix b/pkgs/by-name/at/attic-client/package.nix index 51fa7cbe75da..5a23514ca537 100644 --- a/pkgs/by-name/at/attic-client/package.nix +++ b/pkgs/by-name/at/attic-client/package.nix @@ -21,13 +21,13 @@ in rustPlatform.buildRustPackage { pname = "attic"; - version = "0-unstable-2026-06-14"; + version = "0-unstable-2026-06-26"; src = fetchFromGitHub { owner = "zhaofengli"; repo = "attic"; - rev = "6b22d76ca351c5a07a5e5a60b95bc23320f7e791"; - hash = "sha256-sboz+gG8z0KX+q0kkvLloNcogXYLwiY5iw2xwN36rFo="; + rev = "b7c905657cb81b8ec9c26b0d9f53aa2e4f231810"; + hash = "sha256-//gQFVLVFhwHyI9yrpPqX0MQJGYqS6nE/iLV872K+PU="; }; nativeBuildInputs = [ @@ -38,7 +38,7 @@ rustPlatform.buildRustPackage { buildInputs = lib.optional needNixInclude nix ++ [ boost ]; cargoBuildFlags = lib.concatMapStrings (c: "-p ${c} ") crates; - cargoHash = "sha256-LqE4jOIasxIG4DAhgZJMlTSyt/a900QR06wBFtRNRO8="; + cargoHash = "sha256-fYWRlgP3uwntULe6o2MC1yB/ea2x+27m1Op7o2wUd+U="; env = { ATTIC_DISTRIBUTOR = "nixpkgs"; diff --git a/pkgs/by-name/au/auto-editor/package.nix b/pkgs/by-name/au/auto-editor/package.nix index 2d66a987d949..e260967f09ce 100644 --- a/pkgs/by-name/au/auto-editor/package.nix +++ b/pkgs/by-name/au/auto-editor/package.nix @@ -54,6 +54,8 @@ buildNimPackage rec { # buildNimPackage hack substituteInPlace ae.nimble \ --replace-fail '"main=auto-editor"' '"main"' + + mv tests/unit.nim tests/tunit.nim # buildNimPackage expects tests to start with t ''; nativeCheckInputs = [ @@ -64,7 +66,7 @@ buildNimPackage rec { checkPhase = '' runHook preCheck - eval "nim r --nimcache:$NIX_BUILD_TOP/nimcache $nimFlags $src/tests/unit.nim" + nim_builder --phase:check substituteInPlace tests/test.py \ --replace-fail '"./auto-editor"' "\"$out/bin/main\"" diff --git a/pkgs/by-name/bl/blesh/package.nix b/pkgs/by-name/bl/blesh/package.nix index c9e3b727dbf4..74fba950d70b 100644 --- a/pkgs/by-name/bl/blesh/package.nix +++ b/pkgs/by-name/bl/blesh/package.nix @@ -10,14 +10,14 @@ stdenvNoCC.mkDerivation (finalAttrs: { pname = "blesh"; - version = "0.4.0-devel3-unstable-2026-06-21"; + version = "0.4.0-devel3-unstable-2026-06-27"; src = fetchFromGitHub { owner = "akinomyoga"; repo = "ble.sh"; - rev = "6cffa910eccce252fa391875c7c03c94fb6f1b09"; + rev = "5d39ebe6db67a46de4195f8ce8186e34cd2618d1"; fetchSubmodules = true; - hash = "sha256-CUIHfK1m00p6rBBNp/XqXifeRcG7BKpkdF7kl4+2tZY="; + hash = "sha256-12aSZl0qx0CwaIq/U77pCFz9Ij2CrzhojQuBngc7oag="; }; nativeBuildInputs = [ @@ -28,10 +28,6 @@ stdenvNoCC.mkDerivation (finalAttrs: { # Fix the cache invalidation not working; see # https://github.com/NixOS/nixpkgs/pull/521218#issuecomment-4641313131 ./fix-cache-invalidation.patch - # ble.sh reaches a runtime-dir fallback under the install base when the - # others are unusable (always on WSL); see - # https://github.com/NixOS/nixpkgs/pull/521218#issuecomment-4686973408 - ./skip-readonly-runtime-dir.patch ]; # ble.sh embeds the commit id, normally read from .git, which fetchFromGitHub omits. @@ -41,6 +37,10 @@ stdenvNoCC.mkDerivation (finalAttrs: { "BLE_GIT_BRANCH=master" ]; + postPatch = '' + patchShebangs --build make_command.sh make + ''; + doCheck = true; # auto-detection runs `make -n check` without makeFlags, which fails without BLE_GIT_COMMIT_ID checkTarget = "check"; diff --git a/pkgs/by-name/bl/blesh/skip-readonly-runtime-dir.patch b/pkgs/by-name/bl/blesh/skip-readonly-runtime-dir.patch deleted file mode 100644 index e03f56fc2646..000000000000 --- a/pkgs/by-name/bl/blesh/skip-readonly-runtime-dir.patch +++ /dev/null @@ -1,10 +0,0 @@ ---- a/ble.pp -+++ b/ble.pp -@@ -1934,6 +1934,7 @@ - function ble/base/initialize-runtime-directory/.base { - local tmp_dir=$_ble_base/run - if [[ ! -d $tmp_dir ]]; then -+ [[ -w $_ble_base ]] || return 1 - ble/bin/mkdir -p "$tmp_dir" || return 1 - ble/bin/chmod a+rwxt "$tmp_dir" || return 1 - fi diff --git a/pkgs/by-name/ca/cai/package.nix b/pkgs/by-name/ca/cai/package.nix new file mode 100644 index 000000000000..2bc457a2ccfd --- /dev/null +++ b/pkgs/by-name/ca/cai/package.nix @@ -0,0 +1,131 @@ +{ + lib, + python3Packages, + fetchFromGitHub, + nix-update-script, + writableTmpDirAsHomeHook, +}: + +python3Packages.buildPythonApplication (finalAttrs: { + pname = "cai"; + version = "1.1.5-unstable-2026-06-05"; + pyproject = true; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "aliasrobotics"; + repo = "cai"; + rev = "1c79507140845d0c57455e3b623e489680fd80e8"; + hash = "sha256-LcU9GoUulpeAaaBZr2Mg/C+UmjZ74UL+SGqdB0P9JtA="; + }; + + pythonRemoveDeps = [ + "cryptography" + "dotenv" + "openinference-instrumentation-openai" + "pypdf2" + ]; + + pythonRelaxDeps = [ "openai" ]; + + build-system = with python3Packages; [ hatchling ]; + + dependencies = with python3Packages; [ + cryptography + curl-cffi + dnspython + docker + fastapi + flask + folium + graphviz + griffe + litellm + mako + matplotlib + mcp + mkdocs + mkdocs-material + nest-asyncio + networkx + numpy + numpy + openai + openinference-instrumentation-openai + pandas + paramiko + prompt-toolkit + pydantic + pypdf + python-dotenv + questionary + requests + rich + textual + trafilatura + types-requests + typing-extensions + wasabi + websockets + ]; + + nativeInstallCheckInputs = with python3Packages; [ + inline-snapshot + litellm + pytest-asyncio + pytestCheckHook + writableTmpDirAsHomeHook + ]; + + pythonImportsCheck = [ "cai" ]; + + disabledTestPaths = [ + # Exclude examples + "examples/" + # API key is required + "tests/agents/test_agent_inference.py" + "tests/agents/test_agent_one_tool.py" + "tests/agents/test_blue_teamer_gctr.py" + "tests/api/test_api.py" + "tests/cli/test_cli_headless_cancellation.py" + "tests/commands/" + "tests/integration/" + "tests/refusals/" + "tests/test_unified_pattern.py" + "tools/tpm_test.py" + # openai 2.x API changes + "tests/cli/test_cli_streaming.py" + "tests/core/test_openai_chatcompletions.py" + "tests/core/test_openai_chatcompletions_stream.py" + "tests/mcp/test_runner_calls_mcp.py" + "tests/tracing/test_agent_tracing.py" + "tests/tracing/test_responses_tracing.py" + "tests/tracing/test_tracing.py" + "tests/tracing/test_tracing_errors.py" + "tests/tracing/test_tracing_errors_streamed.py" + "tests/voice/test_workflow.py" + # Missing symbols (version mismatch) + "tests/core/test_auto_compact.py" + "tests/core/test_context_optimization.py" + # Probing the live interpreter outside sandbox + "tests/continuous_ops/test_wizard_worker_python_bin.py" + # Tests requires live CTF infrastructure + "tests/ctfs/test_ctf.py" + # Other error + "tests/test_cli_print_deduplication.py" + "tests/tools/test_output_tool.py" + "tests/util/test_wait_hints_compact.py" + ]; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "Framework for AI Security"; + homepage = "https://github.com/aliasrobotics/cai"; + changelog = "https://github.com/aliasrobotics/cai/releases/tag/${finalAttrs.src.rev}"; + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ fab ]; + mainProgram = "cai"; + }; +}) diff --git a/pkgs/by-name/ca/cargo-show-asm/package.nix b/pkgs/by-name/ca/cargo-show-asm/package.nix index 5714316129c1..039fa3861b06 100644 --- a/pkgs/by-name/ca/cargo-show-asm/package.nix +++ b/pkgs/by-name/ca/cargo-show-asm/package.nix @@ -10,14 +10,14 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "cargo-show-asm"; - version = "0.2.59"; + version = "0.2.62"; src = fetchCrate { inherit (finalAttrs) pname version; - hash = "sha256-5RNfokTD86OFGzWRUyY29+d5P3sWWHmzGCGdIkzIK/g="; + hash = "sha256-gR1+Daz3EY6HtijWqbaCg6nD2B8gi6EYMYFspW39nlw="; }; - cargoHash = "sha256-EcnxozYMjxFHwLpeYwh5dP18+1tiPsY6uQBie3SCg18="; + cargoHash = "sha256-QpitYFYRkzntVW15PJimVIX6AaIU+qVY7g3Y88GnKkA="; nativeBuildInputs = [ installShellFiles diff --git a/pkgs/by-name/co/context7-mcp/package.nix b/pkgs/by-name/co/context7-mcp/package.nix index d8b7f7dde62e..bc565e2e546b 100644 --- a/pkgs/by-name/co/context7-mcp/package.nix +++ b/pkgs/by-name/co/context7-mcp/package.nix @@ -18,13 +18,13 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "context7-mcp"; - version = "3.2.1"; + version = "3.2.2"; src = fetchFromGitHub { owner = "upstash"; repo = "context7"; tag = "${tag-prefix}@${finalAttrs.version}"; - hash = "sha256-Gf3GnVOceAMzsc1SYGQVriDzDD/dQYSoBSrCuQ5M4UI="; + hash = "sha256-v3zKMnZsc0gWVAdgZwFTskWcFVlOU6sG2i+qDwjx+dw="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/co/copilot-language-server/package.nix b/pkgs/by-name/co/copilot-language-server/package.nix index 0ec6ac776fb1..cadc8f9ad0cc 100644 --- a/pkgs/by-name/co/copilot-language-server/package.nix +++ b/pkgs/by-name/co/copilot-language-server/package.nix @@ -10,11 +10,11 @@ }: stdenvNoCC.mkDerivation (finalAttrs: { pname = "copilot-language-server"; - version = "1.509.0"; + version = "1.513.0"; src = fetchzip { url = "https://github.com/github/copilot-language-server-release/releases/download/${finalAttrs.version}/copilot-language-server-js-${finalAttrs.version}.zip"; - hash = "sha256-PY4pr9FHKHSJjNctq7bGlsZ1yvDM6IqbmfobI1WsDP0="; + hash = "sha256-wVibxZjUW6BX4YhdYlyE0/zp0fst2H/XmmqZLqxGXH8="; stripRoot = false; }; diff --git a/pkgs/by-name/db/dbeaver-bin/package.nix b/pkgs/by-name/db/dbeaver-bin/package.nix index c68ca12af343..cb4cf4679e46 100644 --- a/pkgs/by-name/db/dbeaver-bin/package.nix +++ b/pkgs/by-name/db/dbeaver-bin/package.nix @@ -19,7 +19,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { pname = "dbeaver-bin"; - version = "26.1.0"; + version = "26.1.1"; src = let @@ -32,10 +32,10 @@ stdenvNoCC.mkDerivation (finalAttrs: { aarch64-darwin = "macos-aarch64.dmg"; }; hash = selectSystem { - x86_64-linux = "sha256-zAkHddh5xm9SHMV6OcJpl2A3+lS4GMJDbZ/+zg/5PzE="; - aarch64-linux = "sha256-0Tv45N+nZ2lRgn/Lo5HpPjuGigI0X2CJIIV96UO0bs8="; - x86_64-darwin = "sha256-INfXvR9FJZcruC8KeRtc0SIHUUHc0p3jjDNk4eBk7Lo="; - aarch64-darwin = "sha256-s+NQ5hp3NiQpJ/b3mp7Fdjh5rEmf1UnSz/Ai5Z43qEg="; + x86_64-linux = "sha256-atbQ00lq589FlNem85NgzTKGyhTRpFII8OSfVfYQuD0="; + aarch64-linux = "sha256-Sde0q31hXMqX2oxfhgj5EcpeUYYFZJy61usaJVpZkLM="; + x86_64-darwin = "sha256-EmTHuzEc4beM52hC2T7poZ1SOKa9kO2Rp3NnctlsBYo="; + aarch64-darwin = "sha256-PwuFwEE+aBEG/ykwNrEBl20yfrade8BdUUHdLJGBkwc="; }; in fetchurl { diff --git a/pkgs/by-name/dd/ddhx/package.nix b/pkgs/by-name/dd/ddhx/package.nix index e69826b472ed..033080c49167 100644 --- a/pkgs/by-name/dd/ddhx/package.nix +++ b/pkgs/by-name/dd/ddhx/package.nix @@ -5,13 +5,13 @@ }: buildDubPackage (finalAttrs: { pname = "ddhx"; - version = "0.9.3"; + version = "0.10.0"; src = fetchFromGitHub { owner = "dd86k"; repo = "ddhx"; tag = "v${finalAttrs.version}"; - hash = "sha256-7sXXkn/B9iN8Iq4X/Rj7BufdHKDBS1aG3pXcInG+UaI="; + hash = "sha256-1dbY7xUOpwihrppuB+tyHuV2b12E4Yv2J69LXULxmg0="; }; dubLock = ./dub-lock.json; diff --git a/pkgs/by-name/de/defuddle/package.nix b/pkgs/by-name/de/defuddle/package.nix index 16b78498174a..94131aac3c11 100644 --- a/pkgs/by-name/de/defuddle/package.nix +++ b/pkgs/by-name/de/defuddle/package.nix @@ -7,16 +7,16 @@ buildNpmPackage rec { pname = "defuddle"; - version = "0.18.1"; + version = "0.19.1"; src = fetchFromGitHub { owner = "kepano"; repo = "defuddle"; tag = version; - hash = "sha256-e/+eigIzpP0g+ZqTeyZnF6mloaY6UeKcMWfqryCcLbM="; + hash = "sha256-Fn203XKjZ2qbM1o0zs6mgxCdjWLOwz9Na+s1WSQG9XM="; }; - npmDepsHash = "sha256-1NFwhYEGTKpjzCdK/eHK0TWtOEpn67FA+B3QZ11w1Rs="; + npmDepsHash = "sha256-quqWhbcaSNj4Bk++4N4LYq3Y8U5nQqnwc+MqU0LLgso="; # jsdom is both a peerDependency and devDependency; pruning # devDependencies removes it, but the CLI needs it at runtime. diff --git a/pkgs/by-name/de/devin-desktop/info.json b/pkgs/by-name/de/devin-desktop/info.json new file mode 100644 index 000000000000..5c45c061197d --- /dev/null +++ b/pkgs/by-name/de/devin-desktop/info.json @@ -0,0 +1,14 @@ +{ + "aarch64-darwin": { + "version": "3.3.18", + "vscodeVersion": "1.110.1", + "url": "https://windsurf-stable.codeiumdata.com/darwin-arm64/stable/16737566f57f3b53bde136375fe0544eca12fac4/Devin-darwin-arm64-3.3.18.zip", + "sha256": "7ac789baa5d818b09f6a62315d34b55dde02b0a409a22903d0228a819ea734e7" + }, + "x86_64-linux": { + "version": "3.3.18", + "vscodeVersion": "1.110.1", + "url": "https://windsurf-stable.codeiumdata.com/linux-x64/stable/16737566f57f3b53bde136375fe0544eca12fac4/Devin-linux-x64-3.3.18.tar.gz", + "sha256": "05c7fa988c324a1633038ebe90e217d17a7f188197a5070f397460864ef41292" + } +} diff --git a/pkgs/by-name/wi/windsurf/package.nix b/pkgs/by-name/de/devin-desktop/package.nix similarity index 73% rename from pkgs/by-name/wi/windsurf/package.nix rename to pkgs/by-name/de/devin-desktop/package.nix index 6f5e6c97c769..d33b5d803dbf 100644 --- a/pkgs/by-name/wi/windsurf/package.nix +++ b/pkgs/by-name/de/devin-desktop/package.nix @@ -16,15 +16,16 @@ buildVscode { inherit commandLineArgs useVSCodeRipgrep; inherit (info) version vscodeVersion; - pname = "windsurf"; - executableName = "windsurf"; - longName = "Windsurf"; - shortName = "windsurf"; - libraryName = "windsurf"; - iconName = "windsurf"; + pname = "devin-desktop"; - sourceRoot = if stdenv.hostPlatform.isDarwin then "Windsurf.app" else "Windsurf"; + executableName = "devin-desktop"; + longName = "devin-desktop"; + shortName = "devin-desktop"; + libraryName = "devin-desktop"; + iconName = "devin-desktop"; + + sourceRoot = if stdenv.hostPlatform.isDarwin then "Devin.app" else "Devin"; src = fetchurl { inherit (info) url sha256; }; @@ -41,9 +42,9 @@ buildVscode { description = "Agentic IDE powered by AI Flow paradigm"; longDescription = '' The first agentic IDE, and then some. - The Windsurf Editor is where the work of developers and AI truly flow together, allowing for a coding experience that feels like literal magic. + Devin Desktop is where the work of developers and AI truly flow together, allowing for a coding experience that feels like literal magic. ''; - homepage = "https://codeium.com/windsurf"; + homepage = "https://devin.ai/desktop"; license = lib.licenses.unfree; maintainers = with lib.maintainers; [ sarahec @@ -51,7 +52,6 @@ buildVscode { ]; platforms = [ "aarch64-darwin" - "x86_64-darwin" "x86_64-linux" ]; sourceProvenance = [ lib.sourceTypes.binaryBytecode ]; diff --git a/pkgs/by-name/wi/windsurf/update/.gitignore b/pkgs/by-name/de/devin-desktop/update/.gitignore similarity index 100% rename from pkgs/by-name/wi/windsurf/update/.gitignore rename to pkgs/by-name/de/devin-desktop/update/.gitignore diff --git a/pkgs/by-name/wi/windsurf/update/package.json b/pkgs/by-name/de/devin-desktop/update/package.json similarity index 100% rename from pkgs/by-name/wi/windsurf/update/package.json rename to pkgs/by-name/de/devin-desktop/update/package.json diff --git a/pkgs/by-name/wi/windsurf/update/tsconfig.json b/pkgs/by-name/de/devin-desktop/update/tsconfig.json similarity index 100% rename from pkgs/by-name/wi/windsurf/update/tsconfig.json rename to pkgs/by-name/de/devin-desktop/update/tsconfig.json diff --git a/pkgs/by-name/wi/windsurf/update/update.mts b/pkgs/by-name/de/devin-desktop/update/update.mts similarity index 84% rename from pkgs/by-name/wi/windsurf/update/update.mts rename to pkgs/by-name/de/devin-desktop/update/update.mts index 64fad0bbd59f..f10048bfdbd4 100755 --- a/pkgs/by-name/wi/windsurf/update/update.mts +++ b/pkgs/by-name/de/devin-desktop/update/update.mts @@ -17,7 +17,7 @@ interface LatestInfo { readonly productVersion: string; } -const platforms = ["aarch64-darwin", "x86_64-darwin", "x86_64-linux"] as const; +const platforms = ["aarch64-darwin", "x86_64-linux"] as const; type Platform = (typeof platforms)[number]; type InfoMap = Record< Platform, @@ -29,7 +29,7 @@ type InfoMap = Record< } >; -async function getInfo(targetSystem: "darwin-arm64" | "darwin-x64" | "linux-x64") { +async function getInfo(targetSystem: "darwin-arm64" | "linux-x64") { const url = `https://windsurf-stable.codeium.com/api/update/${targetSystem}/stable/latest` as const; @@ -57,7 +57,6 @@ async function main() { const info: InfoMap = { "aarch64-darwin": await getInfo("darwin-arm64"), - "x86_64-darwin": await getInfo("darwin-x64"), "x86_64-linux": await getInfo("linux-x64"), }; if (JSON.stringify(oldInfo) === JSON.stringify(info)) { @@ -66,7 +65,7 @@ async function main() { } for (const platform of platforms) { console.log( - `[update] Updating Windsurf ${platform} ${oldInfo[platform].version} -> ${info[platform].version}`, + `[update] Updating Devin Desktop ${platform} ${oldInfo[platform].version} -> ${info[platform].version}`, ); } await fsPromises.writeFile( @@ -74,7 +73,7 @@ async function main() { JSON.stringify(info, null, 2) + "\n", "utf-8", ); - console.log("[update] Updating Windsurf complete"); + console.log("[update] Updating Devin Desktop complete"); } if (process.argv[1] === __filename) { diff --git a/pkgs/by-name/di/dioxus-cli/package.nix b/pkgs/by-name/di/dioxus-cli/package.nix index cdafe17af58f..ce34b458922b 100644 --- a/pkgs/by-name/di/dioxus-cli/package.nix +++ b/pkgs/by-name/di/dioxus-cli/package.nix @@ -9,7 +9,7 @@ installShellFiles, makeWrapper, esbuild, - wasm-bindgen-cli_0_2_118, + wasm-bindgen-cli_0_2_126, testers, dioxus-cli, withTelemetry ? false, @@ -81,7 +81,7 @@ rustPlatform.buildRustPackage (finalAttrs: { --suffix PATH : ${ lib.makeBinPath [ esbuild - wasm-bindgen-cli_0_2_118 + wasm-bindgen-cli_0_2_126 ] } ''; diff --git a/pkgs/by-name/fe/feishin/package.nix b/pkgs/by-name/fe/feishin/package.nix index 4e2f82063d42..f8a1a7ee214c 100644 --- a/pkgs/by-name/fe/feishin/package.nix +++ b/pkgs/by-name/fe/feishin/package.nix @@ -8,7 +8,7 @@ mpv-unwrapped, fetchPnpmDeps, pnpmConfigHook, - pnpm_10_29_2, + pnpm_10, darwin, actool, copyDesktopItems, @@ -42,7 +42,7 @@ buildNpmPackage { version src ; - pnpm = pnpm_10_29_2; + pnpm = pnpm_10; fetcherVersion = 3; hash = "sha256-zNOGJ24G0xcgsGK4DmbBm7d1PHTp7IJS+RTALGRtfDg="; }; @@ -50,7 +50,7 @@ buildNpmPackage { env.ELECTRON_SKIP_BINARY_DOWNLOAD = "1"; nativeBuildInputs = [ - pnpm_10_29_2 + pnpm_10 ] ++ lib.optionals (stdenv.hostPlatform.isLinux) [ copyDesktopItems ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ diff --git a/pkgs/by-name/gl/glab/package.nix b/pkgs/by-name/gl/glab/package.nix index 366d896bbacc..57f5b58c450f 100644 --- a/pkgs/by-name/gl/glab/package.nix +++ b/pkgs/by-name/gl/glab/package.nix @@ -13,13 +13,13 @@ buildGoModule (finalAttrs: { pname = "glab"; - version = "1.101.0"; + version = "1.105.0"; src = fetchFromGitLab { owner = "gitlab-org"; repo = "cli"; tag = "v${finalAttrs.version}"; - hash = "sha256-K8QL9Ff5FHmiXyBEdsUE8kwhSF0camSFh08LbfJb3wo="; + hash = "sha256-MKb46PHgm+jfHGf2rEh0o7ghtb6JR4UE3Mam9z+2gw8="; leaveDotGit = true; postFetch = '' cd "$out" @@ -28,7 +28,7 @@ buildGoModule (finalAttrs: { ''; }; - vendorHash = "sha256-u1zvzMrQGyTVcl/lnIGK3dfisxGYRa2LGpDMBDq6rJk="; + vendorHash = "sha256-aFrTCqvxVaiEJFKa4zY0kFW1P6QDDD4UG5x+yHK6vZ8="; ldflags = [ "-s" diff --git a/pkgs/by-name/im/immich-go/package.nix b/pkgs/by-name/im/immich-go/package.nix index bb2900f0ab30..9dc8babd6be0 100644 --- a/pkgs/by-name/im/immich-go/package.nix +++ b/pkgs/by-name/im/immich-go/package.nix @@ -9,13 +9,13 @@ }: buildGoModule (finalAttrs: { pname = "immich-go"; - version = "0.31.0"; + version = "0.32.0"; src = fetchFromGitHub { owner = "simulot"; repo = "immich-go"; tag = "v${finalAttrs.version}"; - hash = "sha256-u+laNZ0/UncwH+3Ylk7g40DB99dAbQRrBNOVk80FrMc="; + hash = "sha256-bMbLMlLZpzFP7Zh9kqWzEELt3MdOR8HMkH0gTU8qD9U="; # Inspired by: https://github.com/NixOS/nixpkgs/blob/f2d7a289c5a5ece8521dd082b81ac7e4a57c2c5c/pkgs/applications/graphics/pdfcpu/default.nix#L20-L32 # The intention here is to write the information into files in the `src`'s @@ -32,7 +32,7 @@ buildGoModule (finalAttrs: { ''; }; - vendorHash = "sha256-C6IQ6g5vdGqv8mzdTzLicZqP5lh3l2uNH2gIZELNAHg="; + vendorHash = "sha256-BwrP+eG+XPcTAbSKhJk0BOrfBlNeLHEeRhq49ZkQhwY="; # options used by upstream: # https://github.com/simulot/immich-go/blob/v0.25.0/.goreleaser.yaml diff --git a/pkgs/by-name/ki/kiro/package.nix b/pkgs/by-name/ki/kiro/package.nix index 9c6e7361eebc..60d81bd99c69 100644 --- a/pkgs/by-name/ki/kiro/package.nix +++ b/pkgs/by-name/ki/kiro/package.nix @@ -5,6 +5,7 @@ fetchurl, extraCommandLineArgs ? "", useVSCodeRipgrep ? stdenv.hostPlatform.isDarwin, + _7zz, }: let @@ -31,7 +32,16 @@ in url = sources.url; hash = sources.hash; }; - sourceRoot = "Kiro"; + + # Kiro.dmg is APFS formatted, unpack with 7zz + extraNativeBuildInputs = lib.optionals stdenv.hostPlatform.isDarwin [ _7zz ]; + + sourceRoot = if stdenv.hostPlatform.isDarwin then "Kiro.app" else "Kiro"; + + sourceExecutableName = if stdenv.hostPlatform.isDarwin then "code" else "kiro"; + + dontFixup = stdenv.hostPlatform.isDarwin; + patchVSCodePath = true; tests = { }; diff --git a/pkgs/by-name/li/linyaps-box/package.nix b/pkgs/by-name/li/linyaps-box/package.nix index d4d11afd0e63..2bda17485993 100644 --- a/pkgs/by-name/li/linyaps-box/package.nix +++ b/pkgs/by-name/li/linyaps-box/package.nix @@ -13,13 +13,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "linyaps-box"; - version = "2.2.0"; + version = "2.2.1"; src = fetchFromGitHub { owner = "OpenAtom-Linyaps"; repo = "linyaps-box"; rev = finalAttrs.version; - hash = "sha256-s17BI5nftQFrDZQVKBJjQYSOJHDPlkA2VLG4Hd61xSY="; + hash = "sha256-KULNPztaDeO6Dih98KcnawMz2rDjQd6AYT9FgAADhIg="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/lu/lunar-client/package.nix b/pkgs/by-name/lu/lunar-client/package.nix index ecf1bb7599e9..7714186e91c0 100644 --- a/pkgs/by-name/lu/lunar-client/package.nix +++ b/pkgs/by-name/lu/lunar-client/package.nix @@ -7,11 +7,11 @@ appimageTools.wrapType2 rec { pname = "lunarclient"; - version = "3.7.6"; + version = "3.7.9"; src = fetchurl { url = "https://launcherupdates.lunarclientcdn.com/Lunar%20Client-${version}-ow.AppImage"; - hash = "sha512-+xC7hvpQfmXkZ+FndNAWIxgfWjodfdcCrHmPe5XqEC+3cBkT6KpOxvuw7o0qAebxo6VNN5tKuAPfibfZfeH+RQ=="; + hash = "sha512-7rVPN/CmnaA91mnNQkuK4/pmPtHeLvsLeuzBlEBbRT2RrYtSxF3eEnHiFndlMzmRor8FWuFITz43QFPgFVMJpQ=="; }; nativeBuildInputs = [ makeWrapper ]; diff --git a/pkgs/by-name/ma/manifold/package.nix b/pkgs/by-name/ma/manifold/package.nix index 80557bb78436..59537390f21a 100644 --- a/pkgs/by-name/ma/manifold/package.nix +++ b/pkgs/by-name/ma/manifold/package.nix @@ -11,13 +11,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "manifold"; - version = "3.5.1"; + version = "3.5.2"; src = fetchFromGitHub { owner = "elalish"; repo = "manifold"; tag = "v${finalAttrs.version}"; - hash = "sha256-ZsTGokNpWDT0EgA3VaU/aMh8WtUygIqcSxzLikeyQ9c="; + hash = "sha256-jzVIQ90H90szzZSUWvqgBB+5UMgZ9I/uYhYJbexCifk="; }; nativeBuildInputs = [ cmake ]; diff --git a/pkgs/by-name/ma/matcha/package.nix b/pkgs/by-name/ma/matcha/package.nix index 04720b6bd494..47c8b2744f6c 100644 --- a/pkgs/by-name/ma/matcha/package.nix +++ b/pkgs/by-name/ma/matcha/package.nix @@ -14,16 +14,16 @@ buildGoLatestModule (finalAttrs: { __structuredAttrs = true; pname = "matcha"; - version = "0.40.1"; + version = "0.43.0"; src = fetchFromGitHub { owner = "floatpane"; repo = "matcha"; tag = "v${finalAttrs.version}"; - hash = "sha256-4GbuiFFHQ14O+S2TtWiP1UWg3h6J9Cys6A8k5+0Ww/I="; + hash = "sha256-x+k1/k7pwJ0MW0t31ieaOkbP8LtqDSmHOBrNEGA0K6Q="; }; - vendorHash = "sha256-TFc7e7gNtFNiCJHARngWSBKGqGhH7PiX48VkU9kD9Bs="; + vendorHash = "sha256-5smWIw8ofG61ugHxFbmQ9r9vcxi098/UmxUE15lx4wE="; proxyVendor = true; nativeBuildInputs = lib.optionals stdenv.hostPlatform.isLinux [ diff --git a/pkgs/by-name/mg/mgmt/package.nix b/pkgs/by-name/mg/mgmt/package.nix index 6a4611a5918e..3928b2ed0c49 100644 --- a/pkgs/by-name/mg/mgmt/package.nix +++ b/pkgs/by-name/mg/mgmt/package.nix @@ -12,16 +12,16 @@ }: buildGoModule (finalAttrs: { pname = "mgmt"; - version = "1.0.2"; + version = "1.1.0"; src = fetchFromGitHub { owner = "purpleidea"; repo = "mgmt"; tag = finalAttrs.version; - hash = "sha256-nLk497gGrZ664VG9/yV6tqTtwAsN8EmuAEh5Vmq95hQ="; + hash = "sha256-jVFIVlytDvfTrAzWkX+pedAq/AcLrCDFtLPx0Wc+XjM="; }; - vendorHash = "sha256-w4j9cJwW2tnjXSnd3w3v81TwHI8tGYiImjG3LZ+Pjuc="; + vendorHash = "sha256-mMRAlqySy6dpRG86p0BHSpYn2gzE8N4sZ3qHiyuttBA="; proxyVendor = true; diff --git a/pkgs/by-name/mo/mongodb-ce/package.nix b/pkgs/by-name/mo/mongodb-ce/package.nix index 4fb2618f35b5..5a7fe772b5e5 100644 --- a/pkgs/by-name/mo/mongodb-ce/package.nix +++ b/pkgs/by-name/mo/mongodb-ce/package.nix @@ -17,7 +17,9 @@ stdenv.mkDerivation (finalAttrs: { pname = "mongodb-ce"; - version = "8.2.7"; + version = "8.2.11"; + __structuredAttrs = true; + strictDeps = true; src = finalAttrs.passthru.sources.${stdenv.hostPlatform.system} @@ -49,23 +51,28 @@ stdenv.mkDerivation (finalAttrs: { nativeInstallCheckInputs = [ versionCheckHook ]; versionCheckProgram = "${placeholder "out"}/bin/mongod"; + # Apple's LibreSSL tries to read this while running `mongod --version` + sandboxProfile = lib.optionalString stdenv.hostPlatform.isDarwin '' + (allow file-read* (literal "/private/etc/ssl/openssl.cnf")) + ''; + passthru = { sources = { "x86_64-linux" = fetchurl { url = "https://fastdl.mongodb.org/linux/mongodb-linux-x86_64-ubuntu2404-${finalAttrs.version}.tgz"; - hash = "sha256-GYyWeVSoRXgrlQqx7R2chxH3+5S4ewbTefWJR9S2Frs="; + hash = "sha256-sqFkZ19eYZHQFwVX2zwaKaYXisvoqN25+8DFbyGU2H4="; }; "aarch64-linux" = fetchurl { url = "https://fastdl.mongodb.org/linux/mongodb-linux-aarch64-ubuntu2404-${finalAttrs.version}.tgz"; - hash = "sha256-HTErVesWEWDjheedELdDOwlMrDvhV3JdVGtV3RuSeBI="; + hash = "sha256-5AX8pb1jInbQTuE0RqpqqcRXon6wKwdvoDCNDF70krE="; }; "x86_64-darwin" = fetchurl { url = "https://fastdl.mongodb.org/osx/mongodb-macos-x86_64-${finalAttrs.version}.tgz"; - hash = "sha256-DeD/v+NP2b8BTReV80+Lz0O9t6e3O9+52sJmTK5NtVY="; + hash = "sha256-BLIFrmToU8tFHdjAD+0q827cyeDHoYiXwtsds6e7NMA="; }; "aarch64-darwin" = fetchurl { url = "https://fastdl.mongodb.org/osx/mongodb-macos-arm64-${finalAttrs.version}.tgz"; - hash = "sha256-d8uulXczpq7ZEDmDsbb3o9kaZJ1IYzZ6MkgBLkNU4Mo="; + hash = "sha256-M3/x/d2rVKUmIZBQ9hVuT6W9ajZy/Ut5+8aDeXF+HwY="; }; }; updateScript = diff --git a/pkgs/by-name/n8/n8n/package.nix b/pkgs/by-name/n8/n8n/package.nix index 0e91e2fd604c..11e0fa4396a9 100644 --- a/pkgs/by-name/n8/n8n/package.nix +++ b/pkgs/by-name/n8/n8n/package.nix @@ -26,20 +26,20 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "n8n"; - version = "2.25.7"; + version = "2.27.4"; src = fetchFromGitHub { owner = "n8n-io"; repo = "n8n"; tag = "n8n@${finalAttrs.version}"; - hash = "sha256-V8CqEzCw4DcLPCao4HRXrJXFeID2+Ef8fNW1xd1b8Vs="; + hash = "sha256-Z8oAetoSJLTCO7UO+DrlSDFAIjLSLND9bQzrcLz0hYg="; }; pnpmDeps = fetchPnpmDeps { inherit (finalAttrs) pname version src; pnpm = pnpm_10; fetcherVersion = 3; - hash = "sha256-JS4OY6CmihsbJRyPszSlNUEViFKfLm2vu+G2upIoLW8="; + hash = "sha256-xTZlv8YZC8u9pzD/WroduyO2MVtRvZ7ajKTphsHfObs="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/na/nano/package.nix b/pkgs/by-name/na/nano/package.nix index e4a2d0b1ea96..2e68584027ee 100644 --- a/pkgs/by-name/na/nano/package.nix +++ b/pkgs/by-name/na/nano/package.nix @@ -31,11 +31,11 @@ let in stdenv.mkDerivation rec { pname = "nano"; - version = "9.0"; + version = "9.1"; src = fetchurl { - url = "mirror://gnu/nano/${pname}-${version}.tar.xz"; - hash = "sha256-nzhDdLSWEQoltzrVpf67OEeDxuMYizcGP2d6yQgBP94="; + url = "mirror://gnu/nano/nano-${version}.tar.xz"; + hash = "sha256-X0d2QnTLdTI0nOCqIOwQ8ejoUabp+j62aBLEPRltsEI="; }; nativeBuildInputs = [ texinfo ] ++ lib.optional enableNls gettext; diff --git a/pkgs/by-name/oh/oh-my-posh/package.nix b/pkgs/by-name/oh/oh-my-posh/package.nix index c068bd32779e..93fbf33e6a40 100644 --- a/pkgs/by-name/oh/oh-my-posh/package.nix +++ b/pkgs/by-name/oh/oh-my-posh/package.nix @@ -6,16 +6,16 @@ }: buildGoModule (finalAttrs: { pname = "oh-my-posh"; - version = "29.18.0"; + version = "29.19.0"; src = fetchFromGitHub { owner = "jandedobbeleer"; repo = "oh-my-posh"; tag = "v${finalAttrs.version}"; - hash = "sha256-A01LX+UvPlnQy/GoRoLVIBl8TrIB6XGjvpr3fCB5Jsg="; + hash = "sha256-KhE0JWOY9j4rSmVZOmUxC9pQbjSpISph+6RyntlryFs="; }; - vendorHash = "sha256-cuVkJjaeLBECeEBPSB1hyRcBs4AhXkG4br0ehjZ0pjI="; + vendorHash = "sha256-SI2FjnRlWSsS9Uju8R+FW6/IpqewXsiOwKXfueZ7KPY="; sourceRoot = "${finalAttrs.src.name}/src"; diff --git a/pkgs/by-name/pr/protoc-gen-grpc-java/data.nix b/pkgs/by-name/pr/protoc-gen-grpc-java/data.nix index 0274f88a3c0a..694bd75a468d 100644 --- a/pkgs/by-name/pr/protoc-gen-grpc-java/data.nix +++ b/pkgs/by-name/pr/protoc-gen-grpc-java/data.nix @@ -1,14 +1,14 @@ { - version = "1.81.0"; + version = "1.82.1"; hashes = { - linux-aarch_64 = "sha256-BhO92wlj0L3M8H4CGuB4NRZkjN9zPuFM/E2NAkn6d1o="; - linux-ppcle_64 = "sha256-Y1YC+C/AxdYiB7gcaerVhE383+8rPOiEI8+r/BxkeXk="; - linux-s390_64 = "sha256-cVjZl+ju8e+yroYOttrgIBGSBWDPw1jz1dOLdr58Bmc="; - linux-x86_32 = "sha256-I10buzyicR0aVI3BKDvtly6NwfjSP2hLOD1eY5NJFZc="; - linux-x86_64 = "sha256-T3WWxgoTdSS1TysR2Vb6IA8/6XZ43hzd2CfRCVQlD30="; - osx-aarch_64 = "sha256-c359UvEa+J85KV6KFOXMuUWCYmyB5VkTfmLfj8J81qQ="; - osx-x86_64 = "sha256-c359UvEa+J85KV6KFOXMuUWCYmyB5VkTfmLfj8J81qQ="; - windows-x86_32 = "sha256-mMRY0dLrPpLcQUeK5GqeOrBFqlghBC7FgqqoRWHdjYs="; - windows-x86_64 = "sha256-18mnbuYxoqnQLYHPWC2m2+TW5pJmX/O2OkQLG5xyND0="; + linux-aarch_64 = "sha256-VTDKjBMzFj5CocdqK1EEIOBsdTIckXMrNGOlRyByCc8="; + linux-ppcle_64 = "sha256-/NCzmrhbTDaYhJBntW6n6yA5tvtsvdVldMlK7WfV6RY="; + linux-s390_64 = "sha256-Bk83rw8iGsniyNcivgQRjx/GOWB0kv4Wo01b4YTG0Pk="; + linux-x86_32 = "sha256-Ai7h2w1ZGWlS/tAdiT/dpd6wt3VM4rpPiQuv5rDbfCY="; + linux-x86_64 = "sha256-OnXRqIuP5E9KHVy48ixz+PzI1WOu2QV/9epISyLNry8="; + osx-aarch_64 = "sha256-hm3WySlSQu/J5rg8pWlpOStcPnODqn1b7pKL1N5CkSQ="; + osx-x86_64 = "sha256-hm3WySlSQu/J5rg8pWlpOStcPnODqn1b7pKL1N5CkSQ="; + windows-x86_32 = "sha256-CWZAubE98Aftf7Mjd2caROxsWSxS+JQGf4YB+FEwiwo="; + windows-x86_64 = "sha256-XmhjMhJ/djRizOkSh+i7PtZn2RL9jVV5PcBkgwpYw0o="; }; } diff --git a/pkgs/by-name/qu/qui/package.nix b/pkgs/by-name/qu/qui/package.nix index 4d24190dc46a..f5a749d4ff0c 100644 --- a/pkgs/by-name/qu/qui/package.nix +++ b/pkgs/by-name/qu/qui/package.nix @@ -14,12 +14,12 @@ }: buildGo126Module (finalAttrs: { pname = "qui"; - version = "1.20.0"; + version = "1.21.0"; src = fetchFromGitHub { owner = "autobrr"; repo = "qui"; tag = "v${finalAttrs.version}"; - hash = "sha256-h1OIz+4oVuHg7bKWSKgkEwouX1oJKJmOC1VI+nrPwmI="; + hash = "sha256-3LExp17AGxZjAXXF0GoiTW7I1wluZf3uoZnXNF6WNYg="; }; qui-web = stdenvNoCC.mkDerivation (finalAttrs': { @@ -44,7 +44,7 @@ buildGo126Module (finalAttrs: { ; pnpm = pnpm_11; fetcherVersion = 4; - hash = "sha256-nSlW06//r/olVgSBgHc8LGWWfNXewAF5cZXfoZemC+w="; + hash = "sha256-53bj1QlfihIyKsQK5o3FsA9qWZJrNPWEJ441UK9nWR0="; }; postBuild = '' @@ -56,7 +56,7 @@ buildGo126Module (finalAttrs: { ''; }); - vendorHash = "sha256-4HQOoBDjV3Pt4O/KMu8c3aeUB5evceIdlAnsixO1Pjs="; + vendorHash = "sha256-n+CCRQk46j/ljAfFap3mgwxs4JF9Qr/TLqZILghgbU4="; preBuild = '' cp -r ${finalAttrs.qui-web}/* web/dist diff --git a/pkgs/by-name/re/repomix/package.nix b/pkgs/by-name/re/repomix/package.nix index 19b16ae59f8b..89edde64d8b5 100644 --- a/pkgs/by-name/re/repomix/package.nix +++ b/pkgs/by-name/re/repomix/package.nix @@ -8,16 +8,16 @@ buildNpmPackage rec { pname = "repomix"; - version = "1.14.0"; + version = "1.15.0"; src = fetchFromGitHub { owner = "yamadashy"; repo = "repomix"; tag = "v${version}"; - hash = "sha256-xvRCblm7WRvxFBjsxe3AjvLt8AvL4Q9F6SQuOv39ADA="; + hash = "sha256-M96q1oJ2ipDMfeos5P0FBbngjStC86qBlQcRFXitkt4="; }; - npmDepsHash = "sha256-Pw2/w0rn5UloUqPZrze2l1Qi7JEdAXxlpPm7dxEHzWU="; + npmDepsHash = "sha256-3AP+mMFipVUfO7vLY7ZjaJ8FG4uwpxC2+jYtaHz49YI="; nativeInstallCheckInputs = [ versionCheckHook ]; doInstallCheck = true; diff --git a/pkgs/by-name/re/reticulum-group-chat/package.nix b/pkgs/by-name/re/reticulum-group-chat/package.nix new file mode 100644 index 000000000000..862703889ab1 --- /dev/null +++ b/pkgs/by-name/re/reticulum-group-chat/package.nix @@ -0,0 +1,39 @@ +{ + lib, + buildGoModule, + fetchFromGitHub, + versionCheckHook, + nix-update-script, +}: + +buildGoModule (finalAttrs: { + pname = "reticulum-group-chat"; + version = "1.11.0"; + __structuredAttrs = true; + __darwinAllowLocalNetworking = true; + + src = fetchFromGitHub { + owner = "thatSFguy"; + repo = "reticulum-group-chat"; + tag = "v${finalAttrs.version}"; + hash = "sha256-LWHYIKnkEPrlDIEruP2ctuMQGnrL1uofOWAsZ4E5guw="; + }; + + vendorHash = "sha256-qMmEi7OYv2xzYOoeBWQ0omeIrcTyhxylw2qvv9kd9dk="; + + ldflags = [ "-s" ]; + + doInstallCheck = true; + nativeInstallCheckInputs = [ versionCheckHook ]; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "Pure-Go LXMF group-chat hub for the Reticulum network — a single static binary that relays many-to-many encrypted text chat over LoRa, TCP/IP, and mixed meshes. No Python, no third-party RNS library"; + homepage = "https://github.com/thatSFguy/reticulum-group-chat"; + changelog = "https://github.com/thatSFguy/reticulum-group-chat/releases/tag/${finalAttrs.src.tag}"; + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ drupol ]; + mainProgram = "fwdsvc"; + }; +}) diff --git a/pkgs/by-name/ru/ruff/package.nix b/pkgs/by-name/ru/ruff/package.nix index ca5d02475508..56982ab4db18 100644 --- a/pkgs/by-name/ru/ruff/package.nix +++ b/pkgs/by-name/ru/ruff/package.nix @@ -16,7 +16,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "ruff"; - version = "0.15.18"; + version = "0.15.20"; __structuredAttrs = true; @@ -24,12 +24,12 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "astral-sh"; repo = "ruff"; tag = finalAttrs.version; - hash = "sha256-DH00tENXdCdNcGPXPGzZsU3RVYQ0VBe1QLvbgEg/G6k="; + hash = "sha256-8PFMGKG15kWBpG4YXg37940WtSe/e5pQDqIe3iJRh5A="; }; cargoBuildFlags = [ "--package=ruff" ]; - cargoHash = "sha256-RmK14NMPbhoRVLwIF5GXdGQg2AnMH20JGx7XF4HO+wY="; + cargoHash = "sha256-Bf6nsUnNMYapP0YN0SBkTPoP1czmj35tPwN1awyKhUw="; nativeBuildInputs = [ installShellFiles ]; diff --git a/pkgs/by-name/sh/shiru/package.nix b/pkgs/by-name/sh/shiru/package.nix index c14c5a89bcb4..74532831db34 100644 --- a/pkgs/by-name/sh/shiru/package.nix +++ b/pkgs/by-name/sh/shiru/package.nix @@ -65,7 +65,12 @@ stdenv.mkDerivation (finalAttrs: { ./node_modules/.bin/electron-builder --dir \ --c.electronDist=electron-dist \ - --c.electronVersion=${electron.version} + --c.electronVersion=${electron.version} \ + ${lib.optionalString stdenv.hostPlatform.isDarwin '' + --c.npmRebuild=false \ + --c.mac.identity=null \ + --c.mac.notarize=false \ + ''} runHook postBuild ''; @@ -73,6 +78,8 @@ stdenv.mkDerivation (finalAttrs: { installPhase = '' runHook preInstall + '' + + lib.optionalString (!stdenv.hostPlatform.isDarwin) '' mkdir -p "$out/share/lib/shiru" cp -r dist/*-unpacked/{locales,resources{,.pak}} "$out/share/lib/shiru" @@ -82,7 +89,18 @@ stdenv.mkDerivation (finalAttrs: { --add-flags "$out/share/lib/shiru/resources/app.asar" \ --prefix LD_LIBRARY_PATH : "${lib.makeLibraryPath [ stdenv.cc.cc.lib ]}" \ --inherit-argv0 + '' + + lib.optionalString stdenv.hostPlatform.isDarwin '' + mkdir -p "$out/Applications" + cp -r dist/mac*/Shiru.app "$out/Applications/" + mkdir -p "$out/bin" + makeWrapper \ + "$out/Applications/Shiru.app/Contents/MacOS/Shiru" \ + "$out/bin/shiru" \ + --set-default ELECTRON_IS_DEV 0 + '' + + '' runHook postInstall ''; @@ -116,7 +134,10 @@ stdenv.mkDerivation (finalAttrs: { maintainers = with lib.maintainers; [ naomieow ]; - platforms = [ "x86_64-linux" ]; + platforms = [ + "x86_64-linux" + "aarch64-darwin" + ]; mainProgram = "shiru"; }; }) diff --git a/pkgs/by-name/si/sif/package.nix b/pkgs/by-name/si/sif/package.nix index 0b33852a7892..8808910e606a 100644 --- a/pkgs/by-name/si/sif/package.nix +++ b/pkgs/by-name/si/sif/package.nix @@ -8,16 +8,16 @@ buildGoModule (finalAttrs: { pname = "sif"; - version = "0-unstable-2026-06-11"; + version = "0-unstable-2026-06-23"; src = fetchFromGitHub { owner = "vmfunc"; repo = "sif"; - rev = "d62919523abfecd06e07ba6528b15e9861bd747c"; - hash = "sha256-T/HIvcXG3OpSK7xhZpYnCWv4KsRn0bnLhyouPjgwUoE="; + rev = "39b333320eab64f22392b2494a7cd18462d42b29"; + hash = "sha256-1WdjmCxhd37gkb/HbgUfFZkcFumCMDQKAyG5nvfGAMU="; }; - vendorHash = "sha256-rOAubGbeDPl0LJovksKRfYJmUvU6hmx3Ht12M7eLiOA="; + vendorHash = "sha256-R47Qz5tty+qvJKcWYMGZKYyRvpxN+mOdudT+cpUCT4s="; subPackages = [ "cmd/sif" ]; diff --git a/pkgs/by-name/sn/snekim/package.nix b/pkgs/by-name/sn/snekim/package.nix index 8deefd7515d2..73a375ebc484 100644 --- a/pkgs/by-name/sn/snekim/package.nix +++ b/pkgs/by-name/sn/snekim/package.nix @@ -15,7 +15,6 @@ buildNimPackage (finalAttrs: { hash = "sha256-Qgvq4CkGvNppYFpITCCifOHtVQYRQJPEK3rTJXQkTvI="; }; - strictDeps = true; lockFile = ./lock.json; nimFlags = [ "-d:nimraylib_now_shared" ]; diff --git a/pkgs/by-name/sy/syft/package.nix b/pkgs/by-name/sy/syft/package.nix index f666eaa9dee8..c90ae32ded47 100644 --- a/pkgs/by-name/sy/syft/package.nix +++ b/pkgs/by-name/sy/syft/package.nix @@ -8,13 +8,13 @@ buildGoModule (finalAttrs: { pname = "syft"; - version = "1.45.1"; + version = "1.46.0"; src = fetchFromGitHub { owner = "anchore"; repo = "syft"; tag = "v${finalAttrs.version}"; - hash = "sha256-JYMauarf2GB6ZJXB5pDZAcYZFJXWqEkULF3KIE8WvJQ="; + hash = "sha256-gjVfsJQoE//u0i6lVQCEF2dSUvoepIOaqqCazOUgSwI="; # populate values that require us to use git. By doing this in postFetch we # can delete .git afterwards and maintain better reproducibility of the src. leaveDotGit = true; @@ -29,7 +29,7 @@ buildGoModule (finalAttrs: { # hash mismatch with darwin proxyVendor = true; - vendorHash = "sha256-KjbxAhjIb8h4F6kXfa38qUwWloK/3Rh6YU8G7rMIOtw="; + vendorHash = "sha256-t4L+Q82ohwBEXVh1Yy7OOrNhinnAXzOHO7mmFJQUZYM="; nativeBuildInputs = [ installShellFiles ]; diff --git a/pkgs/by-name/ta/tabbyapi/package.nix b/pkgs/by-name/ta/tabbyapi/package.nix index d4027e187c8d..cac9ebfe2c59 100644 --- a/pkgs/by-name/ta/tabbyapi/package.nix +++ b/pkgs/by-name/ta/tabbyapi/package.nix @@ -7,14 +7,14 @@ }: python3Packages.buildPythonApplication { pname = "tabbyapi"; - version = "0-unstable-2026-06-13"; + version = "0-unstable-2026-06-27"; pyproject = true; src = fetchFromGitHub { owner = "theroyallab"; repo = "tabbyAPI"; - rev = "54850882315d509c984f9fe07fb8f5d04a0b4ba9"; - hash = "sha256-rIpI3pCJtfU1AEHBwQCIwuOh4c14N/z8VlX0hdxOC60="; + rev = "3cf468c28362c28be1c8fc731ce1ccaf7b2206d0"; + hash = "sha256-s97YFyij2/oYlClmV2laDrCkkoK4uVZgRsn5WwftLag="; }; build-system = with python3Packages; [ diff --git a/pkgs/by-name/te/telemt/package.nix b/pkgs/by-name/te/telemt/package.nix index b47d915d88a7..4f0a6495e014 100644 --- a/pkgs/by-name/te/telemt/package.nix +++ b/pkgs/by-name/te/telemt/package.nix @@ -5,16 +5,16 @@ }: rustPlatform.buildRustPackage rec { pname = "telemt"; - version = "3.4.18"; + version = "3.4.19"; src = fetchFromGitHub { owner = "telemt"; repo = "telemt"; tag = version; - hash = "sha256-++EO+gkr6q+y8e0uwYyD04cFGyhwS2DW4JON4LOx0s0="; + hash = "sha256-3Vpz61/mEQ43zOEUtUBQw16D/LBvWymreJp4q1uDydM="; }; - cargoHash = "sha256-n25cjncocDv5gNftqv4TO0HRCoZEakiGzfLZqvT1ya4="; + cargoHash = "sha256-uQVL4k+/6L2vUTWbpTC9RvWQHC84P5fuCSrBLtoDdz8="; checkFlags = [ # flaky: races between MiddleClientWriterCancelled and TrafficBudgetWaitCancelled observation paths diff --git a/pkgs/by-name/te/textlint/package.nix b/pkgs/by-name/te/textlint/package.nix index ddb43b9e6b20..5d18f749d5b4 100644 --- a/pkgs/by-name/te/textlint/package.nix +++ b/pkgs/by-name/te/textlint/package.nix @@ -4,7 +4,7 @@ fetchFromGitHub, makeWrapper, nodejs-slim, - pnpm_9, + pnpm_10, fetchPnpmDeps, pnpmConfigHook, versionCheckHook, @@ -29,13 +29,13 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "textlint"; - version = "15.2.1"; + version = "15.7.1"; src = fetchFromGitHub { owner = "textlint"; repo = "textlint"; tag = "v${finalAttrs.version}"; - hash = "sha256-xjtmYz+O+Sn697OrBkPddv1Ma5UsOkO5v4SGlhsaYWA="; + hash = "sha256-Dt0AprnI/ixezMwU6JG6WhfJTU1xTRu2M4xwbY4uOko="; }; patches = [ @@ -57,16 +57,16 @@ stdenv.mkDerivation (finalAttrs: { src patches ; - pnpm = pnpm_9; - fetcherVersion = 3; - hash = "sha256-TYMhAcmfWHbj/0yLNYiJXWd1GiYb+zqBLj2/83cGbzg="; + pnpm = pnpm_10; + fetcherVersion = 4; + hash = "sha256-dWcLm8cTo8LC6IqMEe1zDxVJ7ioytKigEwYna6hiO8A="; }; nativeBuildInputs = [ makeWrapper nodejs-slim pnpmConfigHook - pnpm_9 + pnpm_10 ]; buildPhase = '' diff --git a/pkgs/by-name/te/textlint/remove-overrides.patch b/pkgs/by-name/te/textlint/remove-overrides.patch index 0d6737107c0e..8fa5d4108d09 100644 --- a/pkgs/by-name/te/textlint/remove-overrides.patch +++ b/pkgs/by-name/te/textlint/remove-overrides.patch @@ -1,10 +1,10 @@ diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml -index 1f0e8f8b..68a9c06a 100644 +index 9ee6370f6..552beed1b 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml -@@ -4,9 +4,6 @@ settings: - autoInstallPeers: true - excludeLinksFromLockfile: false +@@ -295,9 +295,6 @@ catalogs: + specifier: ^3.25.76 + version: 3.25.76 -overrides: - '@textlint/ast-node-types': workspace:* @@ -12,3 +12,15 @@ index 1f0e8f8b..68a9c06a 100644 importers: .: +diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml +index 300a519e0..bf41d5370 100644 +--- a/pnpm-workspace.yaml ++++ b/pnpm-workspace.yaml +@@ -130,7 +130,5 @@ minimumReleaseAgeExclude: + # Force all @textlint/ast-node-types references to use the workspace version + # This prevents version conflicts where some packages might reference old versions (e.g., 13.4.1) + # that cause TypeScript type incompatibility errors in monorepo +-overrides: +- "@textlint/ast-node-types": "workspace:*" + # https://pnpm.io/settings#verifydepsbeforerun + verifyDepsBeforeRun: "install" diff --git a/pkgs/by-name/ty/ty/package.nix b/pkgs/by-name/ty/ty/package.nix index 48a4dbae05f2..187daf164c61 100644 --- a/pkgs/by-name/ty/ty/package.nix +++ b/pkgs/by-name/ty/ty/package.nix @@ -17,7 +17,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "ty"; - version = "0.0.52"; + version = "0.0.54"; __structuredAttrs = true; src = fetchFromGitHub { @@ -25,7 +25,7 @@ rustPlatform.buildRustPackage (finalAttrs: { repo = "ty"; tag = finalAttrs.version; fetchSubmodules = true; - hash = "sha256-p9fTzQ4DYvnwrtLdpSTekBV4ZbR1KETR8dfsbp8CDpo="; + hash = "sha256-hbVH0dCUHkWKD9IG/CYhYI4TfLgpk++tPOkCD36eVSg="; }; # For Darwin platforms, remove the integration test for file notifications, @@ -39,7 +39,7 @@ rustPlatform.buildRustPackage (finalAttrs: { cargoBuildFlags = [ "--package=ty" ]; - cargoHash = "sha256-NUIdYOeyRsR/ZQueEXshYdWTnSeQiRjZRRi2ag8Dm48="; + cargoHash = "sha256-Bf6nsUnNMYapP0YN0SBkTPoP1czmj35tPwN1awyKhUw="; nativeBuildInputs = [ installShellFiles ]; buildInputs = [ rust-jemalloc-sys ]; diff --git a/pkgs/by-name/wa/wasm-bindgen-cli_0_2_126/package.nix b/pkgs/by-name/wa/wasm-bindgen-cli_0_2_126/package.nix new file mode 100644 index 000000000000..f4cb05a610d2 --- /dev/null +++ b/pkgs/by-name/wa/wasm-bindgen-cli_0_2_126/package.nix @@ -0,0 +1,19 @@ +{ + buildWasmBindgenCli, + fetchCrate, + rustPlatform, +}: + +buildWasmBindgenCli rec { + src = fetchCrate { + pname = "wasm-bindgen-cli"; + version = "0.2.126"; + hash = "sha256-H6Is3fiZVxZCfOMWK5dWMSrtn50VGv0sfdnsT+cTtyk="; + }; + + cargoDeps = rustPlatform.fetchCargoVendor { + inherit src; + inherit (src) pname version; + hash = "sha256-VucqkXbCi4qtQzY/HrXiDnbSURsagPsdNVMn1Tw3UiY="; + }; +} diff --git a/pkgs/by-name/wa/waydroid-helper/package.nix b/pkgs/by-name/wa/waydroid-helper/package.nix index 828e9caf19c9..089e1f37332b 100644 --- a/pkgs/by-name/wa/waydroid-helper/package.nix +++ b/pkgs/by-name/wa/waydroid-helper/package.nix @@ -21,6 +21,7 @@ libxml2, systemd, unzip, + vte-gtk4, nix-update-script, fetchpatch, }: @@ -83,6 +84,7 @@ python3Packages.buildPythonApplication { libadwaita libxml2 systemd + vte-gtk4 ]; dontUseCmakeConfigure = true; diff --git a/pkgs/by-name/wi/windsurf/info.json b/pkgs/by-name/wi/windsurf/info.json deleted file mode 100644 index 52ac71b50298..000000000000 --- a/pkgs/by-name/wi/windsurf/info.json +++ /dev/null @@ -1,20 +0,0 @@ -{ - "aarch64-darwin": { - "version": "2.3.9", - "vscodeVersion": "1.110.1", - "url": "https://windsurf-stable.codeiumdata.com/darwin-arm64/stable/a5d3f1ff990cabc0e8001cce6642bdb7ad429e73/Windsurf-darwin-arm64-2.3.9.zip", - "sha256": "35b11cd7307588fa11d4ec4690c2a5da8639e37659d68939e3a1dd46d9a105e3" - }, - "x86_64-darwin": { - "version": "2.3.9", - "vscodeVersion": "1.110.1", - "url": "https://windsurf-stable.codeiumdata.com/darwin-x64/stable/a5d3f1ff990cabc0e8001cce6642bdb7ad429e73/Windsurf-darwin-x64-2.3.9.zip", - "sha256": "63a515c68f322653b901f1472184ca688102f9b8c0b598dec590eb648ead4211" - }, - "x86_64-linux": { - "version": "2.3.9", - "vscodeVersion": "1.110.1", - "url": "https://windsurf-stable.codeiumdata.com/linux-x64/stable/a5d3f1ff990cabc0e8001cce6642bdb7ad429e73/Windsurf-linux-x64-2.3.9.tar.gz", - "sha256": "874024744cd853b7c350fe514be19b0060fac39586253c3b7602d6869473eadc" - } -} diff --git a/pkgs/by-name/wo/workcraft/package.nix b/pkgs/by-name/wo/workcraft/package.nix index 6012fabf47eb..fea071c44337 100644 --- a/pkgs/by-name/wo/workcraft/package.nix +++ b/pkgs/by-name/wo/workcraft/package.nix @@ -8,11 +8,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "workcraft"; - version = "3.5.4"; + version = "3.5.5"; src = fetchurl { url = "https://github.com/workcraft/workcraft/releases/download/v${finalAttrs.version}/workcraft-v${finalAttrs.version}-linux.tar.gz"; - hash = "sha256-+G4Z9GfyfdBL3qb8RqtmRPq6wC6et4P3S6Owy/L5sSU="; + hash = "sha256-zpuwNwVu9iH7JSHsSyGt3gl6swOHa2b9uDC8Ck2Mtno="; }; nativeBuildInputs = [ makeWrapper ]; diff --git a/pkgs/by-name/ya/yazi/plugins/toggle-pane/default.nix b/pkgs/by-name/ya/yazi/plugins/toggle-pane/default.nix index 939c16325536..8322d78c35ef 100644 --- a/pkgs/by-name/ya/yazi/plugins/toggle-pane/default.nix +++ b/pkgs/by-name/ya/yazi/plugins/toggle-pane/default.nix @@ -5,13 +5,13 @@ }: mkYaziPlugin { pname = "toggle-pane.yazi"; - version = "0-unstable-2026-05-07"; + version = "0-unstable-2026-06-26"; src = fetchFromGitHub { owner = "yazi-rs"; repo = "plugins"; - rev = "4ffa48f33465c22cce48c5d506295a3eb27c1979"; - hash = "sha256-wr5QL493A175dRjYSyYpMMJax1RKWaZ3jAdFdL3XXTw="; + rev = "39aaf6dc77e546fe7f7836f102a6c57f96d15365"; + hash = "sha256-rl8EA8aymVQU1296IVsEZ2WR9xBxQTYBK+VUCic/K3k="; }; meta = { diff --git a/pkgs/development/lua-modules/generated-packages.nix b/pkgs/development/lua-modules/generated-packages.nix index 5214f3d71956..04dcae0d69c8 100644 --- a/pkgs/development/lua-modules/generated-packages.nix +++ b/pkgs/development/lua-modules/generated-packages.nix @@ -1040,15 +1040,15 @@ final: prev: { }: buildLuarocksPackage { pname = "fzf-lua"; - version = "0.0.2658-1"; + version = "0.0.2661-1"; knownRockspec = (fetchurl { - url = "mirror://luarocks/fzf-lua-0.0.2658-1.rockspec"; - sha256 = "1dibv791x3yvw4ib56661r4g1v0lmfbwssj0x0jbwsjwnrnqis14"; + url = "mirror://luarocks/fzf-lua-0.0.2661-1.rockspec"; + sha256 = "0gw3q50zxawk81bnaxpj9n9n6fvv9qmyykvnxlha33bz0wvc13cq"; }).outPath; src = fetchzip { - url = "https://github.com/ibhagwan/fzf-lua/archive/267f5db2aa2202b9f6cc7a50783f0ccd2121766c.zip"; - sha256 = "1a4yy3wj0xq0jyrx8qnj6i29v5c8vvi52sbrk8112xy66qlysmm8"; + url = "https://github.com/ibhagwan/fzf-lua/archive/b6f0392fe1645973c795b5bbbd8d6db466a5a25a.zip"; + sha256 = "17mr5nnsx86isk8zqknpc172hpg86nxvmplcwwnk67qg1y8a8jwa"; }; disabled = luaOlder "5.1"; @@ -1137,15 +1137,15 @@ final: prev: { }: buildLuarocksPackage { pname = "grug-far.nvim"; - version = "1.6.71-1"; + version = "1.6.72-1"; knownRockspec = (fetchurl { - url = "mirror://luarocks/grug-far.nvim-1.6.71-1.rockspec"; - sha256 = "1gvwjg617qimb8i737hvdr423py7ry8c0lsna9chpxaks3j0cf4n"; + url = "mirror://luarocks/grug-far.nvim-1.6.72-1.rockspec"; + sha256 = "1ky24vksn0wvv058pvv03r163ba07s8b051mwi99qna2y77js2ds"; }).outPath; src = fetchzip { - url = "https://github.com/MagicDuck/grug-far.nvim/archive/c995bbacf8229dc096ec1c3d60f8531059c86c1b.zip"; - sha256 = "15wv6hvkiqi0rdg59y7dgaz7g6nz3141fdmkdggrc1h8aadky9zr"; + url = "https://github.com/MagicDuck/grug-far.nvim/archive/c69859c1d5427ab5fc7ed12380ab521b4e336691.zip"; + sha256 = "0yp64zp64zk5skf3blx359dmchy9wwfv4nf30hhdagvm8phbkkpx"; }; disabled = luaOlder "5.1"; @@ -1322,15 +1322,15 @@ final: prev: { }: buildLuarocksPackage { pname = "kulala.nvim"; - version = "6.15.3-1"; + version = "6.17.0-1"; knownRockspec = (fetchurl { - url = "mirror://luarocks/kulala.nvim-6.15.3-1.rockspec"; - sha256 = "00ghq3ph0vykphhiilj2k8643hdm5glz3h9iwpnsbahpgwpwppzy"; + url = "mirror://luarocks/kulala.nvim-6.17.0-1.rockspec"; + sha256 = "1m2i088p9gdkvh2s1pgzwq7j2wi2n97k2qdwggi5g22c20ph9370"; }).outPath; src = fetchzip { - url = "https://github.com/mistweaverco/kulala.nvim/archive/v6.15.3.zip"; - sha256 = "1friyckh8bxsixsql1r3h1ljfr3a13w061hnw5z7rj92inyx5536"; + url = "https://github.com/mistweaverco/kulala.nvim/archive/v6.17.0.zip"; + sha256 = "03iilwmi10v6d849nxi47rgfg65qzir4h7h28iw2ga3l3f33h2gy"; }; disabled = luaOlder "5.1"; @@ -4712,21 +4712,21 @@ final: prev: { }: buildLuarocksPackage { pname = "mini.test"; - version = "0.17.0-1"; + version = "0.18.0-1"; knownRockspec = (fetchurl { - url = "mirror://luarocks/mini.test-0.17.0-1.rockspec"; - sha256 = "0k9qvizfb3if0r20zid8had91ckkfy061lznvmi4r9hyy421dwfw"; + url = "mirror://luarocks/mini.test-0.18.0-1.rockspec"; + sha256 = "0k0pdp5qalfhcmdaqi0mz3s0p7rwq88bjcs6b7s5z80rqrhji67k"; }).outPath; src = fetchzip { - url = "https://github.com/echasnovski/mini.test/archive/v0.17.0.zip"; - sha256 = "0hffg59cn8dlhnjnkcfs9vannf10n2j33lna2d8zbaxajxaa8jks"; + url = "https://github.com/nvim-mini/mini.test/archive/v0.18.0.zip"; + sha256 = "1q1qy3f0mxrqx96gq4q3h4w2qip40lqkyd9vs65zc76wj9wx37hw"; }; disabled = luaOlder "5.1"; meta = { - homepage = "https://github.com/echasnovski/mini.test"; + homepage = "https://github.com/nvim-mini/mini.test"; license = lib.licenses.mit; description = "Test neovim plugins. Part of the mini.nvim suite."; }; @@ -5937,7 +5937,6 @@ final: prev: { buildLuarocksPackage, fetchFromGitHub, fetchurl, - inspect, ltreesitter, lua-cjson, luafilesystem, @@ -5947,22 +5946,21 @@ final: prev: { }: buildLuarocksPackage { pname = "teal-language-server"; - version = "0.1.3-1"; + version = "0.1.4-1"; knownRockspec = (fetchurl { - url = "mirror://luarocks/teal-language-server-0.1.3-1.rockspec"; - sha256 = "1mqg294rgzcfbfam0qdab3z93j7gsx250hs9f271337gqki34848"; + url = "mirror://luarocks/teal-language-server-0.1.4-1.rockspec"; + sha256 = "0hgjlpyc90r3m4n4y6k8vjf5cdkv1q5b1mrfc31pssrhfwplq5hq"; }).outPath; src = fetchFromGitHub { owner = "teal-language"; repo = "teal-language-server"; - tag = "0.1.3"; - hash = "sha256-XuHm6AbcBmv0fyQjlJlBMWqJlGYoveW7BEEN+axMRhw="; + tag = "0.1.4"; + hash = "sha256-5SdKjE690zxLAl2Kwcy2Bk49KUrpkYBPviK+mrQnMec="; }; propagatedBuildInputs = [ argparse - inspect ltreesitter lua-cjson luafilesystem @@ -6034,8 +6032,8 @@ final: prev: { src = fetchFromGitHub { owner = "nvim-telescope"; repo = "telescope.nvim"; - rev = "9377230aa5305d9e9aca4ed8dadf1070fb4aa9fc"; - hash = "sha256-iFHYx+5Rf3ol7CjVLjqVu+VNjdGfeC8V8nS/1THO+cQ="; + rev = "427b576c16792edad01a92b89721d923c19ad60f"; + hash = "sha256-/GycCrepwDer0UvBN/f84pJUSvNp+ZfTIUPv0psl+IQ="; }; disabled = lua.luaversion != "5.1"; diff --git a/pkgs/development/lua-modules/overrides.nix b/pkgs/development/lua-modules/overrides.nix index 6819850eef40..0bbadc0ac269 100644 --- a/pkgs/development/lua-modules/overrides.nix +++ b/pkgs/development/lua-modules/overrides.nix @@ -1178,9 +1178,9 @@ in ''; postConfigure = (old.postConfigure or "") + '' substituteInPlace ''${rockspecFilename} \ - --replace-fail '"ltreesitter == 0.1.0",' '"ltreesitter >= 0.2.0",' \ - --replace-fail '"luv == 1.51.0",' '"luv >= 1.51.0",' \ - --replace-fail '"tl == 0.24.5",' '"tl >= 0.24.5",' + --replace-fail '"ltreesitter == 0.3.0",' '"ltreesitter >= 0.3.0",' \ + --replace-fail '"luv == 1.52.1",' '"luv >= 1.52.1",' \ + --replace-fail '"tl == 0.24.8",' '"tl >= 0.24.8",' ''; }); diff --git a/pkgs/development/python-modules/alibabacloud-ram20150501/default.nix b/pkgs/development/python-modules/alibabacloud-ram20150501/default.nix index ffa802f1a398..16d4c217e2f8 100644 --- a/pkgs/development/python-modules/alibabacloud-ram20150501/default.nix +++ b/pkgs/development/python-modules/alibabacloud-ram20150501/default.nix @@ -11,7 +11,7 @@ buildPythonPackage (finalAttrs: { pname = "alibabacloud-ram20150501"; - version = "1.2.0"; + version = "1.2.1"; pyproject = true; __structuredAttrs = true; @@ -19,7 +19,7 @@ buildPythonPackage (finalAttrs: { src = fetchPypi { pname = "alibabacloud_ram20150501"; inherit (finalAttrs) version; - hash = "sha256-YlNRPIiAdp9P1bNv7d2zYqnKYorZrpwFwO6s9fvJW0I="; + hash = "sha256-dzFVfjw5oPAVm59dEMksDeZZXCf0VT3EWeA8zZpMIqU="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/flash-linear-attention/default.nix b/pkgs/development/python-modules/flash-linear-attention/default.nix index 9cce12efe716..14fd32763b38 100644 --- a/pkgs/development/python-modules/flash-linear-attention/default.nix +++ b/pkgs/development/python-modules/flash-linear-attention/default.nix @@ -21,7 +21,7 @@ buildPythonPackage (finalAttrs: { pname = "flash-linear-attention"; - version = "0.5.0"; + version = "0.5.1"; pyproject = true; disabled = pythonOlder "3.10"; @@ -30,7 +30,7 @@ buildPythonPackage (finalAttrs: { owner = "fla-org"; repo = "flash-linear-attention"; tag = "v${finalAttrs.version}"; - hash = "sha256-g66yGHaBwEyjb+of76tKTtV/7as/2xQuqcjbGs4E3rU="; + hash = "sha256-vxNbZ+FkxJh2E0TF09Z7ghkm8eas7Q96heeSXwgV4uU="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/google-cloud-vpc-access/default.nix b/pkgs/development/python-modules/google-cloud-vpc-access/default.nix index 7eadd4c1912e..3a9b138595d6 100644 --- a/pkgs/development/python-modules/google-cloud-vpc-access/default.nix +++ b/pkgs/development/python-modules/google-cloud-vpc-access/default.nix @@ -14,13 +14,13 @@ buildPythonPackage (finalAttrs: { pname = "google-cloud-vpc-access"; - version = "1.16.0"; + version = "1.17.0"; pyproject = true; src = fetchPypi { pname = "google_cloud_vpc_access"; inherit (finalAttrs) version; - hash = "sha256-cVJ8Ok3K1dKGuTsBhDJUqhYEimNTEqOjfVSTqxke0NQ="; + hash = "sha256-c5HvaQIykWRNAuDSBhv72kHZs8qgMY8cyvn5N7mahY4="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/google-cloud-webrisk/default.nix b/pkgs/development/python-modules/google-cloud-webrisk/default.nix index e99b9f90c206..b1bd9f39a93e 100644 --- a/pkgs/development/python-modules/google-cloud-webrisk/default.nix +++ b/pkgs/development/python-modules/google-cloud-webrisk/default.nix @@ -14,13 +14,13 @@ buildPythonPackage (finalAttrs: { pname = "google-cloud-webrisk"; - version = "1.21.0"; + version = "1.22.0"; pyproject = true; src = fetchPypi { pname = "google_cloud_webrisk"; inherit (finalAttrs) version; - hash = "sha256-/PcV2opz3zaGerJk6rCOQNwZbxV2FqY/3BLMNQzO8Pc="; + hash = "sha256-OjJcQDXpbtq4RB8Cev6UgCqvDByOXmoJ306oFlQtryQ="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/google-cloud-workflows/default.nix b/pkgs/development/python-modules/google-cloud-workflows/default.nix index 8c8ac097930f..5c147f3c176b 100644 --- a/pkgs/development/python-modules/google-cloud-workflows/default.nix +++ b/pkgs/development/python-modules/google-cloud-workflows/default.nix @@ -13,13 +13,13 @@ buildPythonPackage (finalAttrs: { pname = "google-cloud-workflows"; - version = "1.22.0"; + version = "1.23.0"; pyproject = true; src = fetchPypi { pname = "google_cloud_workflows"; inherit (finalAttrs) version; - hash = "sha256-9+uHMI2CPzwNWcn9Kci7ze+Oi5E4MhgHTIMf2Sfr4y0="; + hash = "sha256-vo4IpdE0GG2834Z8BbFZrYrH3jtkJbIb76q39PJY1Kg="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/govee-ble/default.nix b/pkgs/development/python-modules/govee-ble/default.nix index 5831629f8e20..0277781145fd 100644 --- a/pkgs/development/python-modules/govee-ble/default.nix +++ b/pkgs/development/python-modules/govee-ble/default.nix @@ -13,14 +13,14 @@ buildPythonPackage (finalAttrs: { pname = "govee-ble"; - version = "1.2.0"; + version = "1.4.0"; pyproject = true; src = fetchFromGitHub { owner = "Bluetooth-Devices"; repo = "govee-ble"; tag = "v${finalAttrs.version}"; - hash = "sha256-+qzSNwV+2h75LVly7kZaaulKQp5Hp0N8k05BauN1TXo="; + hash = "sha256-Y1iSU6G/+0qSLgFQNKeCuhpVv6mJYXivk0wNGNMBd6U="; }; build-system = [ poetry-core ]; diff --git a/pkgs/development/python-modules/iamdata/default.nix b/pkgs/development/python-modules/iamdata/default.nix index 0a749b9892d9..6bedcafffc37 100644 --- a/pkgs/development/python-modules/iamdata/default.nix +++ b/pkgs/development/python-modules/iamdata/default.nix @@ -8,14 +8,14 @@ buildPythonPackage (finalAttrs: { pname = "iamdata"; - version = "0.1.202606261"; + version = "0.1.202606271"; pyproject = true; src = fetchFromGitHub { owner = "cloud-copilot"; repo = "iam-data-python"; tag = "v${finalAttrs.version}"; - hash = "sha256-gxtJMcDyez94n1JVc0KZo2ygtskcPgudSLdUzgfCJjw="; + hash = "sha256-EdU6fcNXufK/GK7tz43+SDox/Cms4uVT5DEzyIv93OQ="; }; __darwinAllowLocalNetworking = true; diff --git a/pkgs/development/python-modules/microsoft-kiota-abstractions/default.nix b/pkgs/development/python-modules/microsoft-kiota-abstractions/default.nix index 88930abfb5e8..c2f1d0baa7f1 100644 --- a/pkgs/development/python-modules/microsoft-kiota-abstractions/default.nix +++ b/pkgs/development/python-modules/microsoft-kiota-abstractions/default.nix @@ -2,31 +2,31 @@ lib, buildPythonPackage, fetchFromGitHub, - poetry-core, + flit-core, + gitUpdater, opentelemetry-api, opentelemetry-sdk, pytest-asyncio, pytest-mock, pytestCheckHook, std-uritemplate, - gitUpdater, }: buildPythonPackage (finalAttrs: { pname = "microsoft-kiota-abstractions"; - version = "1.10.3"; + version = "1.11.6"; pyproject = true; src = fetchFromGitHub { owner = "microsoft"; repo = "kiota-python"; tag = "microsoft-kiota-abstractions-v${finalAttrs.version}"; - hash = "sha256-r0u+erTSKBWzLV7VfwWUYh7lyJS1hDh5A0Tzk3pFzo4="; + hash = "sha256-hhYQsNcy+jVVmKiDuB1nGpx+aA7toM6WDFoU5Vnu5Vs="; }; sourceRoot = "${finalAttrs.src.name}/packages/abstractions/"; - build-system = [ poetry-core ]; + build-system = [ flit-core ]; dependencies = [ opentelemetry-api diff --git a/pkgs/development/python-modules/microsoft-kiota-authentication-azure/default.nix b/pkgs/development/python-modules/microsoft-kiota-authentication-azure/default.nix index 6205839229ba..0fa9c9743652 100644 --- a/pkgs/development/python-modules/microsoft-kiota-authentication-azure/default.nix +++ b/pkgs/development/python-modules/microsoft-kiota-authentication-azure/default.nix @@ -4,7 +4,7 @@ azure-core, buildPythonPackage, fetchFromGitHub, - poetry-core, + flit-core, microsoft-kiota-abstractions, opentelemetry-api, opentelemetry-sdk, @@ -16,19 +16,19 @@ buildPythonPackage (finalAttrs: { pname = "microsoft-kiota-authentication-azure"; - version = "1.10.3"; + version = "1.11.6"; pyproject = true; src = fetchFromGitHub { owner = "microsoft"; repo = "kiota-python"; tag = "microsoft-kiota-authentication-azure-v${finalAttrs.version}"; - hash = "sha256-r0u+erTSKBWzLV7VfwWUYh7lyJS1hDh5A0Tzk3pFzo4="; + hash = "sha256-hhYQsNcy+jVVmKiDuB1nGpx+aA7toM6WDFoU5Vnu5Vs="; }; sourceRoot = "${finalAttrs.src.name}/packages/authentication/azure/"; - build-system = [ poetry-core ]; + build-system = [ flit-core ]; dependencies = [ aiohttp diff --git a/pkgs/development/python-modules/microsoft-kiota-http/default.nix b/pkgs/development/python-modules/microsoft-kiota-http/default.nix index 245d7935a741..128abade58b3 100644 --- a/pkgs/development/python-modules/microsoft-kiota-http/default.nix +++ b/pkgs/development/python-modules/microsoft-kiota-http/default.nix @@ -2,7 +2,7 @@ lib, buildPythonPackage, fetchFromGitHub, - poetry-core, + flit-core, httpx, microsoft-kiota-abstractions, opentelemetry-api, @@ -16,19 +16,19 @@ buildPythonPackage (finalAttrs: { pname = "microsoft-kiota-http"; - version = "1.10.3"; + version = "1.11.6"; pyproject = true; src = fetchFromGitHub { owner = "microsoft"; repo = "kiota-python"; tag = "microsoft-kiota-http-v${finalAttrs.version}"; - hash = "sha256-r0u+erTSKBWzLV7VfwWUYh7lyJS1hDh5A0Tzk3pFzo4="; + hash = "sha256-hhYQsNcy+jVVmKiDuB1nGpx+aA7toM6WDFoU5Vnu5Vs="; }; sourceRoot = "${finalAttrs.src.name}/packages/http/httpx/"; - build-system = [ poetry-core ]; + build-system = [ flit-core ]; dependencies = [ httpx diff --git a/pkgs/development/python-modules/microsoft-kiota-serialization-json/default.nix b/pkgs/development/python-modules/microsoft-kiota-serialization-json/default.nix index d0b08a6286d5..ca39e6a8824f 100644 --- a/pkgs/development/python-modules/microsoft-kiota-serialization-json/default.nix +++ b/pkgs/development/python-modules/microsoft-kiota-serialization-json/default.nix @@ -2,7 +2,7 @@ lib, buildPythonPackage, fetchFromGitHub, - poetry-core, + flit-core, microsoft-kiota-abstractions, pendulum, pytest-asyncio, @@ -13,19 +13,19 @@ buildPythonPackage (finalAttrs: { pname = "microsoft-kiota-serialization-json"; - version = "1.10.3"; + version = "1.11.6"; pyproject = true; src = fetchFromGitHub { owner = "microsoft"; repo = "kiota-python"; tag = "microsoft-kiota-serialization-json-v${finalAttrs.version}"; - hash = "sha256-r0u+erTSKBWzLV7VfwWUYh7lyJS1hDh5A0Tzk3pFzo4="; + hash = "sha256-hhYQsNcy+jVVmKiDuB1nGpx+aA7toM6WDFoU5Vnu5Vs="; }; sourceRoot = "${finalAttrs.src.name}/packages/serialization/json/"; - build-system = [ poetry-core ]; + build-system = [ flit-core ]; dependencies = [ microsoft-kiota-abstractions diff --git a/pkgs/development/python-modules/microsoft-kiota-serialization-multipart/default.nix b/pkgs/development/python-modules/microsoft-kiota-serialization-multipart/default.nix index 5cd49138df9e..1b081aa9a210 100644 --- a/pkgs/development/python-modules/microsoft-kiota-serialization-multipart/default.nix +++ b/pkgs/development/python-modules/microsoft-kiota-serialization-multipart/default.nix @@ -2,7 +2,7 @@ lib, buildPythonPackage, fetchFromGitHub, - poetry-core, + flit-core, microsoft-kiota-abstractions, microsoft-kiota-serialization-json, pytest-asyncio, @@ -13,19 +13,19 @@ buildPythonPackage rec { pname = "microsoft-kiota-serialization-multipart"; - version = "1.10.3"; + version = "1.11.6"; pyproject = true; src = fetchFromGitHub { owner = "microsoft"; repo = "kiota-python"; tag = "microsoft-kiota-serialization-multipart-v${version}"; - hash = "sha256-r0u+erTSKBWzLV7VfwWUYh7lyJS1hDh5A0Tzk3pFzo4="; + hash = "sha256-hhYQsNcy+jVVmKiDuB1nGpx+aA7toM6WDFoU5Vnu5Vs="; }; sourceRoot = "${src.name}/packages/serialization/multipart/"; - build-system = [ poetry-core ]; + build-system = [ flit-core ]; dependencies = [ microsoft-kiota-abstractions ]; diff --git a/pkgs/development/python-modules/microsoft-kiota-serialization-text/default.nix b/pkgs/development/python-modules/microsoft-kiota-serialization-text/default.nix index 800a324d4bc8..bae91e5e83ec 100644 --- a/pkgs/development/python-modules/microsoft-kiota-serialization-text/default.nix +++ b/pkgs/development/python-modules/microsoft-kiota-serialization-text/default.nix @@ -2,7 +2,7 @@ lib, buildPythonPackage, fetchFromGitHub, - poetry-core, + flit-core, microsoft-kiota-abstractions, pytest-asyncio, pytest-mock, @@ -13,19 +13,19 @@ buildPythonPackage rec { pname = "microsoft-kiota-serialization-text"; - version = "1.10.3"; + version = "1.11.6"; pyproject = true; src = fetchFromGitHub { owner = "microsoft"; repo = "kiota-python"; tag = "microsoft-kiota-serialization-text-v${version}"; - hash = "sha256-r0u+erTSKBWzLV7VfwWUYh7lyJS1hDh5A0Tzk3pFzo4="; + hash = "sha256-hhYQsNcy+jVVmKiDuB1nGpx+aA7toM6WDFoU5Vnu5Vs="; }; sourceRoot = "${src.name}/packages/serialization/text/"; - build-system = [ poetry-core ]; + build-system = [ flit-core ]; dependencies = [ microsoft-kiota-abstractions diff --git a/pkgs/development/python-modules/openinference-instrumentation-claude-agent-sdk/default.nix b/pkgs/development/python-modules/openinference-instrumentation-claude-agent-sdk/default.nix new file mode 100644 index 000000000000..e65aeb508cb3 --- /dev/null +++ b/pkgs/development/python-modules/openinference-instrumentation-claude-agent-sdk/default.nix @@ -0,0 +1,74 @@ +{ + lib, + buildPythonPackage, + claude-agent-sdk, + fetchFromGitHub, + hatchling, + nix-update-script, + openinference-instrumentation, + openinference-semantic-conventions, + opentelemetry-api, + opentelemetry-instrumentation, + opentelemetry-semantic-conventions, + pytest-asyncio, + pytest-timeout, + pytestCheckHook, + pyyaml, + sniffio, + typing-extensions, + wrapt, +}: + +buildPythonPackage (finalAttrs: { + pname = "openinference-instrumentation-claude-agent-sdk"; + version = "0.1.6"; + pyproject = true; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "Arize-ai"; + repo = "openinference"; + tag = "python-openinference-instrumentation-claude-agent-sdk-v${finalAttrs.version}"; + hash = "sha256-wmwqmN/rN521TaXVZfkaRzHPVhANSgKaBVc4rhXgIII="; + }; + + sourceRoot = "${finalAttrs.src.name}/python/instrumentation/${finalAttrs.pname}"; + + build-system = [ hatchling ]; + + dependencies = [ + opentelemetry-api + opentelemetry-instrumentation + opentelemetry-semantic-conventions + openinference-semantic-conventions + openinference-instrumentation + typing-extensions + wrapt + ]; + + optional-dependencies = { + instruments = [ claude-agent-sdk ]; + }; + + nativeCheckInputs = [ + pytest-asyncio + pytest-timeout + pytestCheckHook + pyyaml + sniffio + ] + ++ lib.flatten (builtins.attrValues finalAttrs.passthru.optional-dependencies); + + pythonImportsCheck = [ "openinference.instrumentation.claude_agent_sdk" ]; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "OpenInference Claude Agent SDK Instrumentation"; + homepage = "https://github.com/Arize-ai/openinference"; + changelog = "https://github.com/Arize-ai/openinference/releases/tag/${finalAttrs.src.tag}"; + license = lib.licenses.asl20; + maintainers = with lib.maintainers; [ fab ]; + }; +}) diff --git a/pkgs/development/python-modules/openinference-instrumentation-openai/default.nix b/pkgs/development/python-modules/openinference-instrumentation-openai/default.nix new file mode 100644 index 000000000000..31a804841153 --- /dev/null +++ b/pkgs/development/python-modules/openinference-instrumentation-openai/default.nix @@ -0,0 +1,84 @@ +{ + lib, + buildPythonPackage, + fetchFromGitHub, + hatchling, + httpx, + nix-update-script, + openai, + openinference-instrumentation, + openinference-semantic-conventions, + opentelemetry-api, + opentelemetry-instrumentation-httpx, + opentelemetry-instrumentation, + opentelemetry-semantic-conventions, + pytest-asyncio, + pytest-vcr, + pytestCheckHook, + respx, + typing-extensions, + wrapt, +}: + +buildPythonPackage (finalAttrs: { + pname = "openinference-instrumentation-openai"; + version = "0.1.52"; + pyproject = true; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "Arize-ai"; + repo = "openinference"; + tag = "python-openinference-instrumentation-openai-v${finalAttrs.version}"; + hash = "sha256-wmwqmN/rN521TaXVZfkaRzHPVhANSgKaBVc4rhXgIII="; + }; + + sourceRoot = "${finalAttrs.src.name}/python/instrumentation/${finalAttrs.pname}"; + + build-system = [ hatchling ]; + + dependencies = [ + opentelemetry-api + opentelemetry-instrumentation + opentelemetry-semantic-conventions + openinference-semantic-conventions + openinference-instrumentation + typing-extensions + wrapt + ]; + + optional-dependencies = { + instruments = [ openai ]; + }; + + nativeCheckInputs = [ + httpx + opentelemetry-instrumentation-httpx + pytest-asyncio + pytest-vcr + pytestCheckHook + respx + ] + ++ lib.flatten (builtins.attrValues finalAttrs.passthru.optional-dependencies); + + pythonImportsCheck = [ "openinference.instrumentation.openai" ]; + + disabledTests = [ + # Tests want to connect to OpenAI's API + "test_cached_tokens" + "test_input_value" + "test_openai" + "test_tool_calls" + ]; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "OpenInference OpenAI SDK Instrumentation"; + homepage = "https://github.com/Arize-ai/openinference"; + changelog = "https://github.com/Arize-ai/openinference/releases/tag/${finalAttrs.src.tag}"; + license = lib.licenses.asl20; + maintainers = with lib.maintainers; [ fab ]; + }; +}) diff --git a/pkgs/development/python-modules/openinference-instrumentation/default.nix b/pkgs/development/python-modules/openinference-instrumentation/default.nix new file mode 100644 index 000000000000..6c2e2fbf3a3b --- /dev/null +++ b/pkgs/development/python-modules/openinference-instrumentation/default.nix @@ -0,0 +1,69 @@ +{ + lib, + buildPythonPackage, + fetchFromGitHub, + hatchling, + jsonschema, + nix-update-script, + openai, + openinference-semantic-conventions, + opentelemetry-api, + opentelemetry-sdk, + pytest-asyncio, + pytest-vcr, + pytestCheckHook, + typing-extensions, + wrapt, +}: + +buildPythonPackage (finalAttrs: { + pname = "openinference-instrumentation"; + version = "0.1.53"; + pyproject = true; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "Arize-ai"; + repo = "openinference"; + tag = "python-openinference-instrumentation-v${finalAttrs.version}"; + hash = "sha256-1FzAiO3Vxt2o9YCzwPfHOn4hwvOLDt9Luv3zQTJ6J2Q="; + }; + + sourceRoot = "${finalAttrs.src.name}/python/${finalAttrs.pname}"; + + build-system = [ hatchling ]; + + dependencies = [ + opentelemetry-api + opentelemetry-sdk + openinference-semantic-conventions + typing-extensions + wrapt + ]; + + nativeCheckInputs = [ + jsonschema + openai + pytest-asyncio + pytest-vcr + pytestCheckHook + ]; + + pythonImportsCheck = [ "openinference.instrumentation" ]; + + disabledTests = [ + # Tests want to connect to OpenAI's API + "TestTracerLLMDecorator" + ]; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "OpenTelemetry Instrumentation for AI Observability"; + homepage = "https://github.com/Arize-ai/openinference"; + changelog = "https://github.com/Arize-ai/openinference/releases/tag/${finalAttrs.src.tag}"; + license = lib.licenses.asl20; + maintainers = with lib.maintainers; [ fab ]; + }; +}) diff --git a/pkgs/development/python-modules/openinference-semantic-conventions/default.nix b/pkgs/development/python-modules/openinference-semantic-conventions/default.nix new file mode 100644 index 000000000000..a7a129cc1cc3 --- /dev/null +++ b/pkgs/development/python-modules/openinference-semantic-conventions/default.nix @@ -0,0 +1,45 @@ +{ + lib, + buildPythonPackage, + fetchFromGitHub, + hatchling, + nix-update-script, + pytest-asyncio, + pytestCheckHook, +}: + +buildPythonPackage (finalAttrs: { + pname = "openinference-semantic-conventions"; + version = "0.1.30"; + pyproject = true; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "Arize-ai"; + repo = "openinference"; + tag = "python-openinference-semantic-conventions-v${finalAttrs.version}"; + hash = "sha256-MkgajZknHOw4/qra6uZ99rtpiylpHhOj8tDfLGUSU74="; + }; + + sourceRoot = "${finalAttrs.src.name}/python/${finalAttrs.pname}"; + + build-system = [ hatchling ]; + + nativeCheckInputs = [ + pytest-asyncio + pytestCheckHook + ]; + + pythonImportsCheck = [ "openinference.semconv" ]; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "OpenTelemetry Semantic Conventions for AI Observability"; + homepage = "https://github.com/Arize-ai/openinference"; + changelog = "https://github.com/Arize-ai/openinference/releases/tag/${finalAttrs.src.tag}"; + license = lib.licenses.asl20; + maintainers = with lib.maintainers; [ fab ]; + }; +}) diff --git a/pkgs/development/python-modules/opentelemetry-instrumentation-httpx/default.nix b/pkgs/development/python-modules/opentelemetry-instrumentation-httpx/default.nix index 4fe687d399dd..4cf08c1aa584 100644 --- a/pkgs/development/python-modules/opentelemetry-instrumentation-httpx/default.nix +++ b/pkgs/development/python-modules/opentelemetry-instrumentation-httpx/default.nix @@ -1,4 +1,5 @@ { + lib, buildPythonPackage, hatchling, httpx, @@ -6,7 +7,9 @@ opentelemetry-instrumentation, opentelemetry-util-http, opentelemetry-test-utils, + opentelemetry-semantic-conventions, pytestCheckHook, + pythonOlder, respx, }: @@ -23,6 +26,7 @@ buildPythonPackage { httpx opentelemetry-api opentelemetry-instrumentation + opentelemetry-semantic-conventions opentelemetry-util-http ]; @@ -32,6 +36,8 @@ buildPythonPackage { respx ]; + doCheck = pythonOlder "3.14"; + pythonImportsCheck = [ "opentelemetry.instrumentation.httpx" ]; meta = opentelemetry-instrumentation.meta // { diff --git a/pkgs/development/python-modules/opentelemetry-instrumentation/default.nix b/pkgs/development/python-modules/opentelemetry-instrumentation/default.nix index 5bceaef09814..9bb8ba599c2e 100644 --- a/pkgs/development/python-modules/opentelemetry-instrumentation/default.nix +++ b/pkgs/development/python-modules/opentelemetry-instrumentation/default.nix @@ -10,7 +10,7 @@ wrapt, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "opentelemetry-instrumentation"; version = "0.61b0"; pyproject = true; @@ -19,11 +19,11 @@ buildPythonPackage rec { src = fetchFromGitHub { owner = "open-telemetry"; repo = "opentelemetry-python-contrib"; - tag = "v${version}"; + tag = "v${finalAttrs.version}"; hash = "sha256-DT13gcYPNYXBPnf622WsA16C+7sabJfOshDquHn06Ok="; }; - sourceRoot = "${src.name}/opentelemetry-instrumentation"; + sourceRoot = "${finalAttrs.src.name}/opentelemetry-instrumentation"; build-system = [ hatchling ]; @@ -53,8 +53,8 @@ buildPythonPackage rec { meta = { description = "Instrumentation Tools & Auto Instrumentation for OpenTelemetry Python"; homepage = "https://github.com/open-telemetry/opentelemetry-python-contrib/tree/main/opentelemetry-instrumentation"; - changelog = "https://github.com/open-telemetry/opentelemetry-python-contrib/releases/tag/v${version}"; + changelog = "https://github.com/open-telemetry/opentelemetry-python-contrib/releases/tag/v${finalAttrs.src.tag}"; license = lib.licenses.asl20; maintainers = [ lib.maintainers.natsukium ]; }; -} +}) diff --git a/pkgs/development/python-modules/pybase62/default.nix b/pkgs/development/python-modules/pybase62/default.nix index eb0128481761..3b9cc45ed37b 100644 --- a/pkgs/development/python-modules/pybase62/default.nix +++ b/pkgs/development/python-modules/pybase62/default.nix @@ -9,7 +9,7 @@ buildPythonPackage (finalAttrs: { pname = "pybase62"; - version = "0.5.0"; + version = "1.0.0"; pyproject = true; __structuredAttrs = true; @@ -17,7 +17,7 @@ buildPythonPackage (finalAttrs: { src = fetchFromGitHub { owner = "suminb"; repo = "base62"; - tag = finalAttrs.version; + tag = "v${finalAttrs.version}"; hash = "sha256-/H16MT3mKCdXItoeOn1LWTHlgWmtwJdQHUaCp18eMz0="; }; @@ -32,7 +32,7 @@ buildPythonPackage (finalAttrs: { meta = { description = "Module for base62 encoding"; homepage = "https://github.com/suminb/base62"; - changelog = "https://github.com/suminb/base62/releases/tag/${finalAttrs.src.tag}"; + changelog = "https://github.com/suminb/base62/releases/tag/v${finalAttrs.src.tag}"; license = lib.licenses.bsd2WithViews; maintainers = with lib.maintainers; [ fab ]; }; diff --git a/pkgs/development/python-modules/python-smarttub/default.nix b/pkgs/development/python-modules/python-smarttub/default.nix index 4bca217d6b6f..f705b32a1940 100644 --- a/pkgs/development/python-modules/python-smarttub/default.nix +++ b/pkgs/development/python-modules/python-smarttub/default.nix @@ -13,16 +13,16 @@ python-dateutil, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "python-smarttub"; - version = "0.0.47"; + version = "0.0.48"; pyproject = true; src = fetchFromGitHub { owner = "mdz"; repo = "python-smarttub"; - tag = "v${version}"; - hash = "sha256-jKNXViqyRFPeHmoUGL9BGUUcVTQ1w3uJy7J8OlFikPw="; + tag = "v${finalAttrs.version}"; + hash = "sha256-+iaRZO4jPpVnE8Tj8SwjMUXS3xB7vd/ztRYNE2B48Ro="; }; build-system = [ @@ -48,8 +48,8 @@ buildPythonPackage rec { meta = { description = "Python API for SmartTub enabled hot tubs"; homepage = "https://github.com/mdz/python-smarttub"; - changelog = "https://github.com/mdz/python-smarttub/releases/tag/v${version}"; + changelog = "https://github.com/mdz/python-smarttub/releases/tag/${finalAttrs.src.tag}"; license = lib.licenses.mit; maintainers = with lib.maintainers; [ fab ]; }; -} +}) diff --git a/pkgs/development/python-modules/switchbot-api/default.nix b/pkgs/development/python-modules/switchbot-api/default.nix index 9839f490ee1c..deeab9eb65f6 100644 --- a/pkgs/development/python-modules/switchbot-api/default.nix +++ b/pkgs/development/python-modules/switchbot-api/default.nix @@ -15,14 +15,14 @@ buildPythonPackage (finalAttrs: { pname = "switchbot-api"; - version = "2.11.1"; + version = "2.12.0"; pyproject = true; src = fetchFromGitHub { owner = "SeraphicCorp"; repo = "py-switchbot-api"; tag = "v${finalAttrs.version}"; - hash = "sha256-xgfFpylMS8Xs3erM7vuJKun6fYOtJ6kfXgBVSkejbJI="; + hash = "sha256-mvGWuj+YpAqMg8dpICMwkY73vVwrvF6Klld2h2q1Mig="; }; build-system = [ poetry-core ]; diff --git a/pkgs/os-specific/linux/busybox/default.nix b/pkgs/os-specific/linux/busybox/default.nix index d155c1064676..20a76523092a 100644 --- a/pkgs/os-specific/linux/busybox/default.nix +++ b/pkgs/os-specific/linux/busybox/default.nix @@ -99,6 +99,13 @@ stdenv.mkDerivation (finalAttrs: { excludes = [ "networking/httpd_ratelimit_cgi.c" ]; # New since release. hash = "sha256-Msm9sDZrVx7ofunnvnTS73SPKUUpR3Tv5xZ/wBd+rts="; }) + # tar: only strip unsafe components from hardlinks, not symlinks + # fix issue introduced by the previous patch (CVE-2026-26157_CVE-2026-26158.patch) + (fetchpatch { + name = "CVE-2026-26157_CVE-2026-26158-2.patch"; + url = "https://github.com/vda-linux/busybox_mirror/commit/599f5dd8fac390c18b79cba4c14c334957605dae.patch"; + hash = "sha256-go/KHSsuMSm21nC0yvKEtAQs8Jnjjqdcs5i8RWBGwT4="; + }) # syslogd: fix writing to local log file # https://lists.busybox.net/pipermail/busybox/2024-October/090969.html (fetchpatch { @@ -263,12 +270,6 @@ stdenv.mkDerivation (finalAttrs: { # Relies on suid/guid bits skip-testcase cpio.tests "cpio restores suid/sgid bits" - # Weird failures, looks related to our sandbox - skip-testcase tar.tests "tar does not extract into symlinks" - skip-testcase tar.tests "tar -k does not extract into symlinks" - skip-testcase tar.tests "tar Symlink attack: create symlink and then write through it" - skip-testcase tar.tests "tar Symlinks and hardlinks coexist" - popd ''; }); diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index 54ff5434cfe3..1850e03a312b 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -30,18 +30,18 @@ "lts": true }, "6.18": { - "version": "6.18.36", - "hash": "sha256:0kn4r43lnd5nb5c298b30030qyaxv05s7k40n9si1j3iyk4qdazv", + "version": "6.18.37", + "hash": "sha256:0maj2ap1m09bxl6a3g9wc65h9sdr6y8rwc5qcqlbavb4wq0d4g58", "lts": true }, "7.0": { - "version": "7.0.13", - "hash": "sha256:04wrz38ldls7pv1yxa1m7p2hqn1731l93xnz93fs7b0nyz8fv09w", + "version": "7.0.14", + "hash": "sha256:160ggaq9rh50a39gz02fpia8maq85bwxhqlwsc03yafjhjvrk6fy", "lts": false }, "7.1": { - "version": "7.1.1", - "hash": "sha256:0z8x6wafxzc5vkim9jh8wpycdkk9y5bpxgsirmdpyznw84szl5aj", + "version": "7.1.2", + "hash": "sha256:0gw8nnq6nix9xk2dhb1jwmhnqjayrn3bn2akzg4lgqkvfa9qq69p", "lts": false } } diff --git a/pkgs/os-specific/linux/systemd/default.nix b/pkgs/os-specific/linux/systemd/default.nix index 39ce581ae5b7..4652d2cf8d11 100644 --- a/pkgs/os-specific/linux/systemd/default.nix +++ b/pkgs/os-specific/linux/systemd/default.nix @@ -701,6 +701,7 @@ stdenv.mkDerivation (finalAttrs: { withMachined withNetworkd withNspawn + withRepart withPortabled withSysupdate withTimedated diff --git a/pkgs/servers/home-assistant/custom-components/powercalc/package.nix b/pkgs/servers/home-assistant/custom-components/powercalc/package.nix index eadef67ec1b0..a294f47c40b8 100644 --- a/pkgs/servers/home-assistant/custom-components/powercalc/package.nix +++ b/pkgs/servers/home-assistant/custom-components/powercalc/package.nix @@ -17,13 +17,13 @@ buildHomeAssistantComponent rec { owner = "bramstroker"; domain = "powercalc"; - version = "1.21.0"; + version = "1.21.2"; src = fetchFromGitHub { inherit owner; repo = "homeassistant-powercalc"; tag = "v${version}"; - hash = "sha256-XVLemGYPuArcwek6zEZW/MS79sUWL2qbeUSTNarsZ8I="; + hash = "sha256-D8gFEhitQjryZLLcP2ZsXNqWLvPyayuoYGq5C0B2D5w="; }; dependencies = [ numpy ]; diff --git a/pkgs/servers/home-assistant/custom-lovelace-modules/material-you-utilities/package.nix b/pkgs/servers/home-assistant/custom-lovelace-modules/material-you-utilities/package.nix index 0e886d89926d..af26077a697e 100644 --- a/pkgs/servers/home-assistant/custom-lovelace-modules/material-you-utilities/package.nix +++ b/pkgs/servers/home-assistant/custom-lovelace-modules/material-you-utilities/package.nix @@ -6,16 +6,16 @@ buildNpmPackage rec { pname = "material-you-utilities"; - version = "2.1.15"; + version = "2.1.16"; src = fetchFromGitHub { owner = "Nerwyn"; repo = "material-you-utilities"; tag = version; - hash = "sha256-fqs2+OEBOJDO3Y3QO7+R93TCNg+FooZVgilTxcDcNjo="; + hash = "sha256-s8VVV2KmiJ3auQPRwVRWHonYlVWkExC3quRANfW295U="; }; - npmDepsHash = "sha256-1Cv90vnfhAY+XaiN523APShl6al/RkFbcVUiNayg+FE="; + npmDepsHash = "sha256-D18gwO8zO7lKbaRhj+QaeGzkE7zqXc3KGvz9am4rrFY="; installPhase = '' runHook preInstall diff --git a/pkgs/servers/sql/postgresql/ext/age.nix b/pkgs/servers/sql/postgresql/ext/age.nix index 15000ef02c33..eb91916748ca 100644 --- a/pkgs/servers/sql/postgresql/ext/age.nix +++ b/pkgs/servers/sql/postgresql/ext/age.nix @@ -16,7 +16,6 @@ let "16" = "sha256-iukdi2c3CukGvjuTojybFFAZBlAw8GEfzFPr2qJuwTA="; "15" = "sha256-webZWgWZGnSoXwTpk816tjbtHV1UIlXkogpBDAEL4gM="; "14" = "sha256-jZXhcYBubpjIJ8M5JHXKV5f6VK/2BkypH3P7nLxZz3E="; - "13" = "sha256-HR6nnWt/V2a0rD5eHHUsFIZ1y7lmvLz36URt9pPJnCw="; }; in postgresqlBuildExtension (finalAttrs: { diff --git a/pkgs/servers/sql/postgresql/ext/pg_hint_plan.nix b/pkgs/servers/sql/postgresql/ext/pg_hint_plan.nix index 9e3cc3bd3fc1..6795b16692da 100644 --- a/pkgs/servers/sql/postgresql/ext/pg_hint_plan.nix +++ b/pkgs/servers/sql/postgresql/ext/pg_hint_plan.nix @@ -27,10 +27,6 @@ let version = "1.4.4"; hash = "sha256-8rJ4Ck0Axf9zKhOXaJ4EA/M783YZRLuWx+GMGccadVo="; }; - "13" = { - version = "1.3.11"; - hash = "sha256-XTxCw1Uj6rVLcXJuHoT3RkEhdKVLGjOdR7rhFI8YJas="; - }; }; source = diff --git a/pkgs/servers/sql/postgresql/ext/pg_safeupdate.nix b/pkgs/servers/sql/postgresql/ext/pg_safeupdate.nix index 7b9249ad64b1..81de98b98bbc 100644 --- a/pkgs/servers/sql/postgresql/ext/pg_safeupdate.nix +++ b/pkgs/servers/sql/postgresql/ext/pg_safeupdate.nix @@ -5,59 +5,23 @@ postgresqlBuildExtension, }: -let - sources = { - "13" = { - version = "1.4"; - hash = "sha256-1cyvVEC9MQGMr7Tg6EUbsVBrMc8ahdFS3+CmDkmAq4Y="; - }; - "14" = { - version = "1.5"; - hash = "sha256-RRSpkWLFuif+6RCncnsb1NnjKnIIRY9KgebKkjCN5cs="; - }; - "15" = { - version = "1.5"; - hash = "sha256-RRSpkWLFuif+6RCncnsb1NnjKnIIRY9KgebKkjCN5cs="; - }; - "16" = { - version = "1.5"; - hash = "sha256-RRSpkWLFuif+6RCncnsb1NnjKnIIRY9KgebKkjCN5cs="; - }; - "17" = { - version = "1.5"; - hash = "sha256-RRSpkWLFuif+6RCncnsb1NnjKnIIRY9KgebKkjCN5cs="; - }; - "18" = { - version = "1.5"; - hash = "sha256-RRSpkWLFuif+6RCncnsb1NnjKnIIRY9KgebKkjCN5cs="; - }; - }; - - source = - sources."${lib.versions.major postgresql.version}" or { - version = ""; - hash = throw "pg_safeupdate: version specification for pg ${postgresql.version} missing."; - }; -in - -postgresqlBuildExtension { +postgresqlBuildExtension (finalAttrs: { pname = "pg-safeupdate"; - inherit (source) version; + version = "1.6"; src = fetchFromGitHub { owner = "eradman"; repo = "pg-safeupdate"; - tag = source.version; - inherit (source) hash; + tag = finalAttrs.version; + hash = "sha256-xky2tlb0EoKzyIYftVr7/2BYLdinhxHjXiVO3lR57MM="; }; meta = { - broken = !builtins.elem (lib.versions.major postgresql.version) (builtins.attrNames sources); description = "Simple extension to PostgreSQL that requires criteria for UPDATE and DELETE"; homepage = "https://github.com/eradman/pg-safeupdate"; - changelog = "https://github.com/eradman/pg-safeupdate/raw/${source.version}/NEWS"; + changelog = "https://github.com/eradman/pg-safeupdate/raw/${finalAttrs.version}/NEWS"; platforms = postgresql.meta.platforms; maintainers = with lib.maintainers; [ wolfgangwalther ]; license = lib.licenses.postgresql; }; -} +}) diff --git a/pkgs/servers/sql/postgresql/ext/pgaudit.nix b/pkgs/servers/sql/postgresql/ext/pgaudit.nix index 454fe1200ac5..af7763fd4ead 100644 --- a/pkgs/servers/sql/postgresql/ext/pgaudit.nix +++ b/pkgs/servers/sql/postgresql/ext/pgaudit.nix @@ -9,7 +9,10 @@ let sources = { - # v18: No upstream ticket, yet (2025-07-07) + "18" = { + version = "18.0"; + hash = "sha256-+1YKJxMFkok7MsYeA9GRkc2FLxuBGRLpC+JzdK/xqoM="; + }; "17" = { version = "17.1"; hash = "sha256-9St/ESPiFq2NiPKqbwHLwkIyATKUkOGxFcUrWgT+Iqo="; @@ -26,10 +29,6 @@ let version = "1.6.3"; hash = "sha256-KgLidJHjUK9BTp6ffmGUj1chcwIe6IzlcadRpGCfNdM="; }; - "13" = { - version = "1.5.3"; - hash = "sha256-IU4Clec3DkKWT7+kw0VtQNybt94i7M2rSSgJG/XdcRs="; - }; }; source = diff --git a/pkgs/servers/web-apps/lemmy/pin.json b/pkgs/servers/web-apps/lemmy/pin.json index d419fa5b0c1e..b7e07bc4303b 100644 --- a/pkgs/servers/web-apps/lemmy/pin.json +++ b/pkgs/servers/web-apps/lemmy/pin.json @@ -4,5 +4,5 @@ "serverHash": "sha256-JcJV1dEWlFsbv9eH2yQMGYEZEFB/Pe1xtL1UNtKI6c4=", "serverCargoHash": "sha256-cwmz8Gf7T1IsCRyxo3ap+byX+Aj7+iCTHmZ/IeMN2no=", "uiHash": "sha256-67OMwzOGl+dMX5YNPPBG/QwKOVerkSa7ICbrQl4YBp4=", - "uiPNPMDepsHash": "sha256-T7vHfeewwT8fCH6AM6u2GFRkd+KWsp4lKj5I7I+yJAo=" + "uiPNPMDepsHash": "sha256-50IUUymGyaCAeMnWbYJlBytcULr9lvuY9kLVSEqHGL0=" } diff --git a/pkgs/servers/web-apps/lemmy/ui.nix b/pkgs/servers/web-apps/lemmy/ui.nix index 787000960efe..b44e20f314b4 100644 --- a/pkgs/servers/web-apps/lemmy/ui.nix +++ b/pkgs/servers/web-apps/lemmy/ui.nix @@ -3,7 +3,7 @@ stdenvNoCC, libsass, nodejs, - pnpm_9, + pnpm_11, fetchPnpmDeps, pnpmConfigHook, fetchFromGitHub, @@ -31,7 +31,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { nativeBuildInputs = [ nodejs pnpmConfigHook - pnpm_9 + pnpm_11 ]; buildInputs = [ @@ -42,8 +42,8 @@ stdenvNoCC.mkDerivation (finalAttrs: { extraBuildInputs = [ libsass ]; pnpmDeps = fetchPnpmDeps { inherit (finalAttrs) pname version src; - pnpm = pnpm_9; - fetcherVersion = 3; + pnpm = pnpm_11; + fetcherVersion = 4; hash = pinData.uiPNPMDepsHash; }; diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index c5866b7f22e9..171fbaccca1c 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -2351,6 +2351,7 @@ mapAliases { wifi-password = throw "'wifi-password' has been removed as it was unmaintained upstream"; # Added 2025-08-29 win-pvdrivers = throw "'win-pvdrivers' has been removed as it was subject to the Xen build machine compromise (XSN-01) and has open security vulnerabilities (XSA-468)"; # Added 2025-08-29 win-virtio = throw "'win-virtio' has been renamed to/replaced by 'virtio-win'"; # Converted to throw 2025-10-27 + windsurf = warnAlias "'windsurf' has been rebranded and replaced as 'devin-desktop'" devin-desktop; wineWayland = throw "'wineWayland' has been renamed to/replaced by 'wine-wayland'"; # Converted to throw 2025-10-27 wineWowPackages = warnAlias diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index fd0bae89108b..ebfbc1038f37 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -196,7 +196,6 @@ with pkgs; inherit (nix-update) nix-update-script; nixos-test-driver = pkgs.python3Packages.callPackage ../../nixos/lib/test-driver { - qemu_pkg = pkgs.qemu; imagemagick_light = pkgs.imagemagick_light.override { inherit (pkgs) libtiff; }; tesseract4 = pkgs.tesseract4.override { enableLanguages = [ "eng" ]; }; # We want `pkgs.systemd`, *not* `python3Packages.system`. diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index c7527717d04c..152f9b53cfee 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -2886,6 +2886,13 @@ with self; url = "mirror://cpan/authors/id/D/DA/DAVIDO/Bytes-Random-Secure-0.29.tar.gz"; hash = "sha256-U7vTOeahHvygfGGaYVx8GIpouyvoSaHLfvw91Nmuha4="; }; + patches = [ + (fetchpatch { + name = "CVE-2026-11625.patch"; + url = "https://security.metacpan.org/patches/B/Bytes-Random-Secure/0.29/CVE-2026-11625-r1.patch"; + hash = "sha256-EDPFvFjqGtN5/TiJlarqKMrtH6kEQD6rOA7B2moBkiA="; + }) + ]; propagatedBuildInputs = [ CryptRandomSeed MathRandomISAAC @@ -2907,6 +2914,17 @@ with self; url = "mirror://cpan/authors/id/D/DA/DAVIDO/Bytes-Random-Secure-Tiny-1.011.tar.gz"; hash = "sha256-A9lntfgoRpCRN9WrmYSsVwrBCkQB4MYC89IgjEZayYI="; }; + patches = [ + (fetchpatch { + name = "CVE-2026-11702.patch"; + url = "https://security.metacpan.org/patches/B/Bytes-Random-Secure-Tiny/1.011/CVE-2026-11702-r1.patch"; + hash = "sha256-81wvVdtQsF5YeRhjAeaOFa7aE1cgdCni+G28LA7ZLqM="; + }) + ]; + preCheck = '' + # Remove test that CVE patch breaks: "Attempt to access disallowed key '_rng' in a restricted hash" + rm t/35-mrie-cover.t + ''; meta = { description = "Tiny Perl extension to generate cryptographically-secure random bytes"; license = with lib.licenses; [ diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index f4c5310f86f3..8f90a996d573 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -11965,6 +11965,22 @@ self: super: with self; { } ); + openinference-instrumentation = + callPackage ../development/python-modules/openinference-instrumentation + { }; + + openinference-instrumentation-claude-agent-sdk = + callPackage ../development/python-modules/openinference-instrumentation-claude-agent-sdk + { }; + + openinference-instrumentation-openai = + callPackage ../development/python-modules/openinference-instrumentation-openai + { }; + + openinference-semantic-conventions = + callPackage ../development/python-modules/openinference-semantic-conventions + { }; + openmm = toPythonModule ( pkgs.openmm.override { python3Packages = self;