Commit Graph

809284 Commits

Author SHA1 Message Date
Fernando Rodrigues
fbc146f31e xen: patch with XSA-472
Mutiple vulnerabilities in the Viridian interface

There are multiple issues related to the handling and accessing of guest
memory pages in the viridian code:

 1. A NULL pointer dereference in the updating of the reference TSC area.
    This is CVE-2025-27466.

 2. A NULL pointer dereference by assuming the SIM page is mapped when
    a synthetic timer message has to be delivered.  This is
    CVE-2025-58142.

 3. A race in the mapping of the reference TSC page, where a guest can
    get Xen to free a page while still present in the guest physical to
    machine (p2m) page tables.  This is CVE-2025-58143.

Signed-off-by: Fernando Rodrigues <alpha@sigmasquadron.net>

(cherry picked from commit 2648215258)
Signed-off-by: Fernando Rodrigues <alpha@sigmasquadron.net>
2025-09-09 22:59:06 +10:00
Wolfgang Walther
6e362e9a38 [Backport release-25.05] build(deps): bump cachix/install-nix-action from 31.5.2 to 31.6.0 (#439462) 2025-09-02 08:36:23 +00:00
dependabot[bot]
f8ecf8cc37 build(deps): bump cachix/install-nix-action from 31.5.2 to 31.6.0
Bumps [cachix/install-nix-action](https://github.com/cachix/install-nix-action) from 31.5.2 to 31.6.0.
- [Release notes](https://github.com/cachix/install-nix-action/releases)
- [Changelog](https://github.com/cachix/install-nix-action/blob/master/RELEASE.md)
- [Commits](fc6e360bed...56a7bb7b56)

---
updated-dependencies:
- dependency-name: cachix/install-nix-action
  dependency-version: 31.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
(cherry picked from commit df934c4327)
2025-09-02 08:33:34 +00:00
Wolfgang Walther
e6d15a202b [Backport release-25.05] maintainers: require GitHub handle (enforce via CI) (#439453) 2025-09-02 08:16:03 +00:00
Wolfgang Walther
2f2221f44c maintainers: require GitHub handle
At the scale of Nixpkgs, actively maintaining a package is only possible
with integration into CI. To be able to be pinged for review requests,
the maintainer must have a GitHub handle, which:
- Leads to an invitation to the NixOS org, which comes with additional
privileges.
- Allows to request the maintainer for review as a member of this org.
- Automatically requests the maintainer for review in CI.

Currently, the GitHub handle is not strictly enforced. This leads to
some new maintainers accidentally forgetting to set these. We can avoid
these mistakes and enforce them via CI.

(cherry picked from commit 568b19f656)
2025-09-02 08:10:32 +00:00
Wolfgang Walther
c47551083b maintainers: drop gm6k (#439452) 2025-09-02 08:08:20 +00:00
Wolfgang Walther
589c0e4105 [Backport release-25.05] maintainers.tomkoid: add github (#439450) 2025-09-02 08:02:48 +00:00
Fernando Rodrigues
10b2d601a6 maintainers: drop gm6k
Although this maintainer has responded to requests for maintainance and
is active in Nixpkgs, the new data collection requirements introduced in
https://github.com/NixOS/nixpkgs/pull/437085 have been a privacy
concern for this maintainer, who has stated (https://github.com/NixOS/nixpkgs/pull/437082#issuecomment-3243483517)
that they do not wish for their data to be added to the maintainer list.

For this reason, there is no other recourse than to remove this
maintainer's information from newer revisions of Nixpkgs, as their
maintainer entry is now non-compliant with Nixpkgs' latest policies.
Once more, this removal is NOT due to the usual inactivity reasons, but
for specific privacy concerns expressed by the maintainer being removed.

Signed-off-by: Fernando Rodrigues <alpha@sigmasquadron.net>

(cherry picked from commit 81d1a3a2ae)
Signed-off-by: Fernando Rodrigues <alpha@sigmasquadron.net>
2025-09-02 17:59:01 +10:00
Wolfgang Walther
b32051328d maintainers: add github/githubId for tomkoid
(cherry picked from commit 03e63ed0d9)
2025-09-02 07:57:38 +00:00
Ulrik Strid
eee3c7ba25 [Backport release-25.05] microsoft-edge: 139.0.3405.111 -> 139.0.3405.125 (#439226) 2025-09-02 08:13:31 +02:00
Morgan Jones
71bb0ea41d [Backport release-25.05] lmstudio: 0.3.23.3 -> 0.3.24.6 (#439361) 2025-09-02 05:39:27 +00:00
Morgan Jones
be4bb2dcce [Backport release-25.05] easyrsa: 3.2.3 -> 3.2.4 (#439363) 2025-09-02 05:38:37 +00:00
rewine
e9a4417f6c [Backport release-25.05] vivaldi: 7.5.3735.64 -> 7.5.3735.66 (#439421) 2025-09-02 13:16:04 +08:00
R. Ryantm
46d32b9380 vivaldi: 7.5.3735.64 -> 7.5.3735.66
(cherry picked from commit 1b017fbf5c)
2025-09-02 05:09:17 +00:00
Morgan Jones
cf39b1d157 [Backport release-25.05] mattermost: charset fixes (#439044) 2025-09-01 22:52:42 +00:00
R. Ryantm
f4b2746db8 easyrsa: 3.2.3 -> 3.2.4
(cherry picked from commit 7082943360)
2025-09-01 22:52:01 +00:00
crertel
d81145a0f8 lmstudio: 0.3.23.3 -> 0.3.24.6
(cherry picked from commit a29f313962)
2025-09-01 22:47:46 +00:00
Felix Bargfeldt
6bc6c63ca0 [Backport release-25.05] chhoto-url: 6.3.0 -> 6.3.1 (#439356) 2025-09-02 00:35:03 +02:00
Defelo
8531d35134 chhoto-url: 6.3.0 -> 6.3.1
Changelog: https://github.com/SinTan1729/chhoto-url/releases/tag/6.3.1
Diff: https://github.com/SinTan1729/chhoto-url/compare/6.3.0...6.3.1
(cherry picked from commit 71701ca8a5)
2025-09-01 22:15:48 +00:00
Vincent Laporte
5a534679b0 jasmin-compiler: 2025.06.0 → 2025.06.1
(cherry picked from commit de2fd96686)
2025-09-01 21:27:33 +02:00
Wolfgang Walther
7c815e513a [25.05] postgrest: 13.0.0 -> 13.0.6 (#439281) 2025-09-01 19:14:55 +00:00
Wolfgang Walther
0420b329f6 postgrest: 13.0.5 -> 13.0.6
Release Notes:
https://github.com/PostgREST/postgrest/releases/tag/v13.0.6

(cherry picked from commit 8b3d840ac8)
2025-09-01 20:07:33 +02:00
Wolfgang Walther
cbe4381a2c postgrest: 13.0.4 -> 13.0.5
Release Notes:
https://github.com/PostgREST/postgrest/releases/tag/v13.0.5

(cherry picked from commit 826d9716e2)
2025-09-01 20:07:16 +02:00
Wolfgang Walther
1bb90a21db haskellPackages.postgrest: 13.0.0 -> 13.0.4
Just fixes some regressions in v13.

Changelog:
https://github.com/PostgREST/postgrest/blob/v13.0.4/CHANGELOG.md
(cherry picked from commit ffcada9749)
2025-09-01 20:07:13 +02:00
Franz Pletz
7b936b6c80 [Backport release-25.05] librewolf-bin-unwrapped: 142.0.1 -> 142.0.1-1 (#439257) 2025-09-01 19:33:33 +02:00
Dominic Wrege
317667d7b5 librewolf-bin-unwrapped: 142.0.1 -> 142.0.1-1
(cherry picked from commit 27cada1157)
2025-09-01 17:05:10 +00:00
Wolfgang Walther
a4bad3269f [Backport release-25.05] ci/eval/compare: handle missing packages (#439250) 2025-09-01 16:37:40 +00:00
Wolfgang Walther
4198e557f3 ci/eval/compare: handle missing packages
Not all packages that are reported as changed will actually exist on the
platform that the maintainers are colleted on.

This is the case for some attributes that are only available on Darwin
or explicitly set to `null` on Linux. By filtering out packages without
maintainers, these are ignored - and we should potentially get a small
performance improvement as well.

(cherry picked from commit f2ca5796de)
2025-09-01 16:24:43 +00:00
Felix Bargfeldt
c4b3f85ffb [Backport release-25.05] nixos/glitchtip: fix sourcemap uploads, add stateDir option (#439241) 2025-09-01 18:22:03 +02:00
Defelo
120cf68ade nixos/glitchtip: add stateDir option
(cherry picked from commit 6ef10ab044)
2025-09-01 15:54:37 +00:00
Defelo
0cdcf4e6fb nixos/glitchtip: fix sourcemap uploads
(cherry picked from commit 95968f2f73)
2025-09-01 15:54:37 +00:00
Defelo
9978b14017 nixos/tests/glitchtip: test sourcemap uploads
(cherry picked from commit e9de9b50ce)
2025-09-01 15:54:37 +00:00
dish
6b07f6504a [Backport release-25.05] komikku: 1.85.0 -> 1.86.0 (#438047) 2025-09-01 11:02:05 -04:00
dish
f0ac2a2be9 [Backport release-25.05] flyctl: 0.3.171 -> 0.3.172 (#439032) 2025-09-01 11:01:03 -04:00
dish
ba5f55507f [Backport release-25.05] virt-manager: 5.0.0 -> 5.1.0 (#439216) 2025-09-01 10:59:37 -04:00
Louis Bailleau
6e4ada68f2 microsoft-edge: 139.0.3405.111 -> 139.0.3405.125
(cherry picked from commit 2b9f4f9b62)
2025-09-01 14:56:40 +00:00
Felix Bargfeldt
26abce87ea [Backport release-25.05] nixos/radicle: add httpd.aliases option (#439220) 2025-09-01 16:55:35 +02:00
dish
fb159a8980 [Backport release-25.05] bakelite: 0.4.2-unstable-2023-05-30 -> 0.4.2-unstable-2024-08-02 (#439162) 2025-09-01 10:54:44 -04:00
Defelo
ad0f2f28ec nixos/radicle: add httpd.aliases option
(cherry picked from commit 8b4862c608)
2025-09-01 14:47:38 +00:00
R. Ryantm
b6fe120508 virt-manager: 5.0.0 -> 5.1.0
(cherry picked from commit 4096fb30d9)
2025-09-01 14:38:10 +00:00
Nick Cao
b413895be0 [Backport release-25.05] nightfox-gtk-theme: 0-unstable-2025-07-21 -> 0-unstable-2025-08-21 (#438717) 2025-09-01 10:33:14 -04:00
Tristan Ross
17096cea47 llvmPackages_git: 22.0.0-unstable-2025-08-24 -> 22.0.0-unstable-2025-08-31
(cherry picked from commit 0c186805ac)
2025-09-01 16:13:17 +02:00
Tristan Ross
10265dc092 llvmPackages_git: 22.0.0-unstable-2025-08-17 -> 22.0.0-unstable-2025-08-24
(cherry picked from commit 2e8a2ab9e3)
2025-09-01 15:48:19 +02:00
Adam C. Stephens
67d07b7e23 [release-25.05] openvswitch: 3.5.1 -> 3.5.2 (#438904) 2025-09-01 09:47:54 -04:00
Alyssa Ross
5266a6d938 nixos/public-inbox: fix inboxdir option
This wasn't consistently used — sometimes the default value was
hardcoded.

(cherry picked from commit 0fdcb36005)
2025-09-01 15:44:38 +02:00
Adam C. Stephens
03a9484617 nixos/tests/openvswitch: improve ping check resiliency 2025-09-01 09:32:09 -04:00
R. Ryantm
368188fa00 bakelite: 0.4.2-unstable-2023-05-30 -> 0.4.2-unstable-2024-08-02
(cherry picked from commit 00aba33680)
2025-09-01 12:20:30 +00:00
jopejoe1
89c774777f [Backport release-25.05] discord-ptb: 0.0.156 -> 0.0.158 (#439125) 2025-09-01 13:33:35 +02:00
Azat Bahawi
fac4eed671 [Backport release-25.05] qolibri: move to by-name, switch to Qt6 (#439084) 2025-09-01 14:23:11 +03:00
Wolfgang Walther
e7100b5ddb [Backport release-25.05] ci/eval/compare: ping maintainers of removed packages (#439133) 2025-09-01 10:32:09 +00:00