Commit Graph

51395 Commits

Author SHA1 Message Date
chn
4ae892f647 Merge remote-tracking branch 'upstream/nixos-25.05' into nixos-25.05 2025-09-16 21:07:10 +08:00
Robert Schütz
b7338ccd18 nixos/nextcloud: remove X-XSS-Protection
see https://github.com/nextcloud/server/pull/53476

(cherry picked from commit 06c99c29c9)
2025-09-13 14:21:44 -04:00
Wolfgang Walther
1c19667f3c nixos/all-tests: keep-sorted
(cherry picked from commit 4d055c69f7)
2025-09-13 14:42:22 +02:00
Philip Taron
10be3a533f [Backport 25.05] teleport_18: init at 18.1.1; teleport_16: 16.5.13 -> 16.5.15; teleport_17: 17.5.4 -> 17.7.3; teleport_18: 18.1.1 -> 18.2.0 (#441311) 2025-09-11 20:05:19 +02:00
Kerstin Humm
d6326ce0bf nixos/canaille: remove HTTP header X-XSS-Protection
Addresses https://github.com/NixOS/nixpkgs/issues/438800

(cherry picked from commit 301e5cca9c)
2025-09-09 21:20:33 +00:00
JuliusFreudenberger
21037c0b4c teleport_18: init at 18.1.1
(cherry picked from commit f073e6214c)
2025-09-08 22:21:19 +02:00
Maximilian Bosch
7d7d436071 Merge: [Backport release-25.05] nixos/nextcloud: Pass OC_PASS and NC_PASS environment variables to nextcloud-occ (#440004) 2025-09-08 07:45:33 +02:00
Wael Nasreddine
88469b5caa [Backport release-25.05] ncps: Update the module for ncps v0.3.0 (#440346) 2025-09-06 12:44:04 -07:00
nixpkgs-ci[bot]
078e17c0be [Backport release-25.05] nixos/kerberos_server: add extraKDCArgs option (#440187)
nixos/kerberos_server: add extraKDCArgs option

(cherry picked from commit b3af89dd38)

Co-authored-by: Katalin Rebhan <me@dblsaiko.net>
2025-09-06 13:55:31 +02:00
Philip Taron
a474ab79b3 [Backport release-25.05] nixVersions.nix_2_28: 2.28.4 -> 2.28.5 (#440074) 2025-09-06 12:26:22 +02:00
Wael Nasreddine
bb7c2bf89f ncps: Add support for the --cache-temp-path flag
(cherry picked from commit 414c23facc)
2025-09-05 07:20:36 +00:00
Wael Nasreddine
258e3e3bac ncps: Add support for the --prometheus-enabled flag
(cherry picked from commit a0817f37f2)
2025-09-05 07:20:35 +00:00
Maximilian Bosch
11f50618c3 Merge: [25.05] linux_6_15: remove, zfs: 2.3.3 -> 2.3.4, linux_6_12_hardened: v6.12.34-hardened1 -> v6.12.43-hardened1 (#438965) 2025-09-04 13:00:14 +02:00
Philip Taron
98f7229a73 nixVersions.nix_2_28: 2.28.4 -> 2.28.5
Diff: https://github.com/NixOS/nix/compare/refs/tags/2.28.4...refs/tags/2.28.5

No changelog found; this brings backported changes from June through August to the stable Nix for Nixpkgs.

(cherry picked from commit a75061e577)
2025-09-04 07:20:46 +00:00
provokateurin
9a0dee2e9c nixos/nextcloud: Pass OC_PASS and NC_PASS environment variables to nextcloud-occ
(cherry picked from commit ba24e7fa23)
2025-09-03 22:36:44 +00:00
dish
70a4352089 [Backport release-25.05] nixos/grocy: don't set X-XSS-Protection anymore (#439543) 2025-09-03 12:47:39 -04:00
Robert Helgesson
908dbaf1e7 nixos/grav: remove X-XSS-Protection
See <https://github.com/NixOS/nixpkgs/issues/438800>.

(cherry picked from commit 90c505624b)
2025-09-02 23:25:35 +02:00
Robert Helgesson
4b5e614d94 nixos/grav: use PHP 8.3
The stable version of Grav is not compatible with later versions of
PHP.

(cherry picked from commit 22617bd181)
2025-09-02 23:25:35 +02:00
Peder Bergebakken Sundt
2c7eb6abdd [Backport release-25.05] warp-plus: 1.2.5 -> 1.2.6-unstable-2025-08-13 (#439417) 2025-09-02 23:17:42 +02:00
dish
d9cfae021d [Backport release-25.05] nixos/grafana: don't set X-XSS-Protection anymore (#439325) 2025-09-02 15:09:29 -04:00
dish
8574caa202 [Backport release-25.05] nixos/kanboard: remove X-XSS-Protection (#439324) 2025-09-02 15:08:11 -04:00
Picnoir
fb92a140f2 nixos/tests/pleroma: rm x-xss-protection
See https://github.com/NixOS/nixpkgs/issues/438800

(cherry picked from commit f2edbb6a16)
2025-09-02 13:04:41 +00:00
Diogo Correia
c85c6554aa nixos/grocy: don't set X-XSS-Protection anymore
Part of #438800.

The OWASP recommentation[1] is:

> The X-XSS-Protection header has been deprecated by modern browsers
> and its use can introduce additional security issues on the client
> side. As such, it is recommended to set the header as X-XSS-Protection: 0
> in order to disable the XSS Auditor, and not allow it to take the default
> behavior of the browser handling the response. Please use
> Content-Security-Policy instead.

[1] https://owasp.org/www-project-secure-headers/#x-xss-protection

(cherry picked from commit c129255508)
2025-09-02 13:03:41 +00:00
Diogo Correia
d8c2bd99a8 {nixos/,}grocy: add diogotcorreia as maintainer
(cherry picked from commit 80f6d36543)
2025-09-02 13:03:41 +00:00
Pavel Sobolev
b2e397ff89 treewide: remove paveloom as maintainer
(cherry picked from commit f685a22664)
2025-09-02 09:58:37 +05:30
Morgan Jones
cf39b1d157 [Backport release-25.05] mattermost: charset fixes (#439044) 2025-09-01 22:52:42 +00:00
Maximilian Bosch
27d2e27300 nixos/grafana: don't set X-XSS-Protection anymore
Part of #438800.

The OWASP recommentation[1] is:

> The X-XSS-Protection header has been deprecated by modern browsers
> and its use can introduce additional security issues on the client
> side. As such, it is recommended to set the header as X-XSS-Protection: 0
> in order to disable the XSS Auditor, and not allow it to take the default
> behavior of the browser handling the response. Please use
> Content-Security-Policy instead.

Hence, we turn this off, diverging from the upstream defaults here. An
upstream issue has been opened[2].

[1] https://owasp.org/www-project-secure-headers/#x-xss-protection
[2] https://github.com/grafana/grafana/issues/110369

(cherry picked from commit 409107d2f5)
2025-09-01 20:52:12 +00:00
Zexin Yuan
4398ea964b nixos/kanboard: remove X-XSS-Protection
(cherry picked from commit 47fcf23026)
2025-09-01 20:51:01 +00:00
Defelo
120cf68ade nixos/glitchtip: add stateDir option
(cherry picked from commit 6ef10ab044)
2025-09-01 15:54:37 +00:00
Defelo
0cdcf4e6fb nixos/glitchtip: fix sourcemap uploads
(cherry picked from commit 95968f2f73)
2025-09-01 15:54:37 +00:00
Defelo
9978b14017 nixos/tests/glitchtip: test sourcemap uploads
(cherry picked from commit e9de9b50ce)
2025-09-01 15:54:37 +00:00
Defelo
ad0f2f28ec nixos/radicle: add httpd.aliases option
(cherry picked from commit 8b4862c608)
2025-09-01 14:47:38 +00:00
Adam C. Stephens
67d07b7e23 [release-25.05] openvswitch: 3.5.1 -> 3.5.2 (#438904) 2025-09-01 09:47:54 -04:00
Alyssa Ross
5266a6d938 nixos/public-inbox: fix inboxdir option
This wasn't consistently used — sometimes the default value was
hardcoded.

(cherry picked from commit 0fdcb36005)
2025-09-01 15:44:38 +02:00
Adam C. Stephens
03a9484617 nixos/tests/openvswitch: improve ping check resiliency 2025-09-01 09:32:09 -04:00
Morgan Jones
e15890c3fe nixos/mattermost: remove fallback charset for MySQL
This was causing issues on newer versions of MariaDB (breaking
NixOS tests) like:

```
Error 1064 (42000): You have an error in your SQL syntax;
check the manual that corresponds to your MariaDB server version
for the right syntax to use near '%2Cutf8' at line 1
```

Since this is simply a fallback character set and all supported versions
of MariaDB support utf8mb4, delete the fallback.

This change should be fully compatible with existing deployments.

(cherry picked from commit 6cc8a8cdb5)
2025-09-01 02:19:40 +00:00
Martin Weinelt
f36fdd634d postfix-tlspol: 1.8.15 -> 1.8.16
https://github.com/Zuplu/postfix-tlspol/releases/tag/v1.8.16
(cherry picked from commit 609cad27ad)
2025-08-31 14:22:08 +00:00
Maximilian Bosch
7a9baae4e7 linux_6_15: remove
EOL upstream.

We only have one hardened kernel at the moment now because
LTS == latest available. This situation would've also happened before
the cleanup since 6.13/6.14 were removed in June already[1].

[1] 23b573705d

(cherry picked from commit 510532e9ae)
2025-08-31 15:34:01 +02:00
Sefa Eyeoglu
b70e23a3bb nixos/postgresql-backup: add pgdumpAllOptions
Signed-off-by: Sefa Eyeoglu <contact@scrumplex.net>
(cherry picked from commit 82d2631e1c)
2025-08-30 12:53:14 +00:00
Sandro Jäckel
3edda9e8f3 nixos/postgresql-backup: do not enable assertions when module is disabled
(cherry picked from commit d7fbdf54e1)
2025-08-30 12:27:11 +00:00
Maximilian Bosch
73120866fa teams/flyingcircus: remove ma27 from members
By the end of the month, I'll leave Flying Circus. Thanks a lot for the
journey together <3

The rootless-test for podman is something I decided to keep since I'm
using parts of the features covered in there myself.

(cherry picked from commit 201cb3e519)
2025-08-28 17:15:18 +00:00
Wolfgang Walther
7bc8d63262 [25.05] Backport of #413251 (#435593) 2025-08-26 15:46:28 +00:00
Maximilian Bosch
e3f9723c15 Merge: [Backport release-25.05] Fix: Correct podman systemd service name (#432866) 2025-08-25 12:27:48 +02:00
Vladimír Čunát
6570ceeb3c thunderbird: 141.0 -> 142.0, drop firefox 128 (#435442) 2025-08-25 10:33:02 +02:00
Wolfgang Walther
44d6b48a5f postgresql.tests.postgresql.postgresql-backup-all: fix random dump
The new `\restrict` migitation creates random keys in the dump file by
default, which breaks a before/after test for the backup module. By
making the restrict key reproducible, the test passes again.

(cherry picked from commit 87e1134406)
2025-08-24 09:09:39 +00:00
Martin Weinelt
db43745348 firefox-esr-128-unwrapped: drop
(cherry picked from commit 5cdd66b7df)
2025-08-23 13:38:04 +02:00
Adam C. Stephens
e6ad556248 [Backport release-25.05] nixos/vector: add graceful shutdown limit option; nixos/vector: add option to disable the configuration validation (#428623) 2025-08-22 14:34:15 -04:00
Brendan Taylor
55ce6a8344 nixos/borgmatic: do not use pg_dumpall when a format is set (#413251)
(cherry picked from commit d0be8ff242)
2025-08-21 18:09:04 +02:00
Willy
9971d819cb nixosTests.prometheus-exporters.smokeping: fix test after 0.10.0
prometheus-smokeping-prober was updated to 0.10.0 in #396980
which introduced a new label `tos` in its metrics.
add it to the failing tests to make them match
the expected metric (and pass) again

you could argue that the tests are a bit too greedy with the way
they match metrics, but I actually like it that way

(cherry picked from commit 2103ba2688)
2025-08-21 14:03:55 +00:00
Jonas Heinrich
a0c2500457 nixos/invoiceplane: Update patch
(cherry picked from commit aa06ffc4c3)
2025-08-20 14:49:48 +00:00