Compare commits

...

4691 Commits

Author SHA1 Message Date
Vladimír Čunát
50fc86b75d haskellPackages.hs-mesos: throw properly
Until now it dependended on `pkgs.mesos` alias which just throws.
But with `allowAliases = false` that was a hard error
and blocked channel (since we changed the indexing scripts).
2023-04-27 14:53:20 +02:00
Dmitry Kalinkin
abd6db5708 texlive.texinfo: fix hash (#227358)
(cherry picked from commit 9a55a26ea7)
2023-04-21 16:34:24 -04:00
Martin Weinelt
0874168639 Merge pull request #206382 from NixOS/backport-206193-to-release-22.05 2023-01-01 14:35:27 +01:00
Martin Weinelt
df90b9dd7d Merge pull request #205034 from LeSuisse/22.05-vscodium-1.73.1.22314 2023-01-01 14:35:15 +01:00
Martin Weinelt
6d67d2ba0d Merge pull request #205038 from LeSuisse/22.05-vscode-1.73.1 2023-01-01 14:35:01 +01:00
Martin Weinelt
95b0a33f46 Merge pull request #207955 from NixOS/backport-207864-to-release-22.05 2023-01-01 14:34:47 +01:00
Naïm Favier
3ab6d81fc6 Merge pull request #208607 from NixOS/backport-199425-to-release-22.05 2023-01-01 13:19:32 +01:00
Mikilio
0fae6636c9 nixos/nixos-enter: add full path for systemd-tmpfiles
(cherry picked from commit b6c367162c)
2023-01-01 11:31:42 +00:00
Robert Scott
5353b10bd9 Merge pull request #208423 from NixOS/backport-207278-to-release-22.05
[Backport release-22.05] pacparser: 1.3.7 -> 1.4.0
2022-12-31 15:40:26 +00:00
Kerstin
1b62419388 Merge pull request #208503 from NixOS/backport-208419-to-release-22.05
[Backport release-22.05] imagemagick: 7.1.0-55 -> 7.1.0-56
2022-12-31 16:11:37 +01:00
R. Ryantm
7ba9600777 imagemagick: 7.1.0-55 -> 7.1.0-56
(cherry picked from commit 21c2734135)
2022-12-31 14:18:28 +00:00
Naïm Favier
0c5a734cde Merge pull request #207310 from NixOS/backport-207264-to-release-22.05 2022-12-31 00:06:39 +01:00
Thomas Gerbet
b3ff252954 pacparser: 1.3.7 -> 1.4.0
Fixes CVE-2019-25078 (and possibly other security related issues without CVE ID).

https://github.com/manugarg/pacparser/releases/tag/v1.4.0
https://github.com/manugarg/pacparser/releases/tag/v1.3.9
https://github.com/manugarg/pacparser/releases/tag/v1.3.8
(cherry picked from commit d6e3f5491b)
2022-12-30 22:57:32 +00:00
Thomas Gerbet
88eaf4a29b Merge pull request #208134 from NixOS/backport-208014-to-release-22.05
[Backport release-22.05] trafficserver: 9.1.3 -> 9.1.4
2022-12-29 18:30:22 +01:00
Martin Weinelt
50d60fd23f Merge pull request #207589 from NixOS/staging-next-22.05 2022-12-28 21:22:23 +01:00
Thomas Gerbet
7bd3d09fe5 trafficserver: 9.1.3 -> 9.1.4
Fixes CVE-2022-32749 and CVE-2022-40743.

https://raw.githubusercontent.com/apache/trafficserver/9.1.x/CHANGELOG-9.1.4
(cherry picked from commit ede90bb8e1)
2022-12-28 17:59:58 +00:00
Bjørn Forsman
038cb1e929 nixos/borgbackup: fix ~/.cache, ~/.config ownership
Invoke `install` separately for each directory to get ownership right --
i.e. not always owned by root. When owned by root, user sessions break
as no user processes are allowed to create directores there. On normal
systems the directories already exist, but in clean environments / NixOS
test VMs, the bug shows.

Before:
  $ namei -l /home/user1/.cache/borg
  f: /home/user1/.cache/borg
  drwxr-xr-x root  root  /
  drwxr-xr-x root  root  home
  drwx------ user1 users user1
  drwxr-xr-x root  root  .cache
  drwxr-xr-x user1 users borg

After:
  $ namei -l /home/user1/.cache/borg
  f: /home/user1/.cache/borg
  drwxr-xr-x root  root  /
  drwxr-xr-x root  root  home
  drwx------ user1 users user1
  drwxr-xr-x user1 users .cache
  drwxr-xr-x user1 users borg
(cherry picked from commit ab5e4f74ef366643de6c309084004bc48c5599c4)
2022-12-28 15:02:33 +01:00
Thomas Gerbet
d3beb2b1c9 Merge pull request #205560 from risicle/ris-traefik-CVE-2022-41717-r22.05
[22.05] traefik: add patch for CVE-2022-41717
2022-12-28 10:39:46 +01:00
Martin Weinelt
f9dd1bae4c webkitgtk: 2.38.2 -> 2.38.3
https://webkitgtk.org/2022/12/22/webkitgtk2.38.3-released.html
https://webkitgtk.org/security/WSA-2022-0011.html

Fixes: CVE-2022-42852, CVE-2022-42856, CVE-2022-42867, CVE-2022-46692,
       CVE-2022-46698, CVE-2022-46699, CVE-2022-46700
(cherry picked from commit 5880a6a2c8)
2022-12-27 11:07:06 +00:00
github-actions[bot]
9a27139c97 Merge release-22.05 into staging-next-22.05 2022-12-27 00:15:02 +00:00
Robert Scott
2b1c2c3e55 qemu: add patches for CVE-2022-4172 & CVE-2022-4144
(cherry picked from commit 84ea2f024f)
2022-12-26 17:27:45 +01:00
Vladimír Čunát
d56c437625 Merge #207827: systemd: 250.8 -> 250.9
...into staging-next-22.05
2022-12-26 16:59:13 +01:00
Дамјан Георгиевски
79decf8ea0 systemd: 250.8 -> 250.9
https://github.com/systemd/systemd-stable/compare/v250.8...v250.9

also fixes an security issue with systemd-coredump:
https://www.openwall.com/lists/oss-security/2022/12/21/3

250.9 added optional support for `libqrencode.so.3` too, so handle that
too.
2022-12-26 13:52:01 +01:00
Martin Weinelt
bb16922dd6 Merge pull request #205068 from NixOS/backport-204902-to-staging-22.05 2022-12-24 17:27:36 +01:00
Martin Weinelt
f327458235 Merge pull request #206597 from risicle/ris-sqlite-CVE-2022-46908-r22.05 2022-12-24 17:26:41 +01:00
Martin Weinelt
a57a032067 Merge pull request #207165 from mweinelt/22.05/curl-7.87.0-fixes 2022-12-24 10:47:05 +01:00
github-actions[bot]
a60f9bdddc Merge staging-next-22.05 into staging-22.05 2022-12-24 00:13:37 +00:00
github-actions[bot]
fe7ab74a86 Merge release-22.05 into staging-next-22.05 2022-12-24 00:13:04 +00:00
Florian Klink
79e63f30ed Merge pull request #198060 from toonn/backport-196593-to-release-22.05
[22.05] Wire desktop Bump
2022-12-23 17:46:18 +01:00
Maximilian Bosch
01d56beb40 Merge pull request #207407 from Ma27/22.05-linux-kernel-updates
[22.05] Linux kernel updates 2022-12-23
2022-12-23 13:33:04 +01:00
Maximilian Bosch
974b017712 Merge pull request #207275 from NixOS/backport-207044-to-release-22.05
[Backport release-22.05] matrix-synapse: 1.73.0 -> 1.74.0
2022-12-23 13:32:17 +01:00
Maximilian Bosch
e2911d0220 linux/hardened/patches/6.0: 6.0.13-hardened1 -> 6.0.15-hardened1
(cherry picked from commit 1ecc5414ce)
2022-12-23 11:54:28 +01:00
Maximilian Bosch
c4fb1ab519 linux/hardened/patches/5.4: 5.4.227-hardened1 -> 5.4.228-hardened1
(cherry picked from commit 7a3b851089)
2022-12-23 11:54:28 +01:00
Maximilian Bosch
48b4d16644 linux/hardened/patches/5.15: 5.15.83-hardened1 -> 5.15.85-hardened1
(cherry picked from commit afc5e7cc9a)
2022-12-23 11:54:27 +01:00
Maximilian Bosch
9b393d4bf0 linux/hardened/patches/5.10: 5.10.159-hardened1 -> 5.10.161-hardened1
(cherry picked from commit d3e0241c4d)
2022-12-23 11:54:27 +01:00
Maximilian Bosch
825a7bab04 linux: 6.0.13 -> 6.0.15
(cherry picked from commit f6f17ce513)
2022-12-23 11:54:14 +01:00
Maximilian Bosch
be74df04bb linux: 5.4.227 -> 5.4.228
(cherry picked from commit 734f672b67)
2022-12-23 11:54:14 +01:00
Maximilian Bosch
8f926809fa linux: 5.15.83 -> 5.15.85
(cherry picked from commit a464cfcb36)
2022-12-23 11:54:13 +01:00
Maximilian Bosch
8fa5798ab9 linux: 5.10.159 -> 5.10.161
(cherry picked from commit 600ca141de)
2022-12-23 11:54:13 +01:00
Martin Weinelt
99a62471c8 Merge pull request #207173 from NixOS/backport-207151-to-staging-22.05 2022-12-23 01:44:54 +01:00
github-actions[bot]
09e8ec316a Merge staging-next-22.05 into staging-22.05 2022-12-23 00:15:40 +00:00
github-actions[bot]
6dba551b79 Merge release-22.05 into staging-next-22.05 2022-12-23 00:14:56 +00:00
Thomas Gerbet
060cbf6ee4 libvncserver: 0.9.13 -> 0.9.14
Fixes CVE-2020-29260.

https://github.com/LibVNC/libvncserver/releases/tag/LibVNCServer-0.9.14
(cherry picked from commit 0dc0b93db1)
2022-12-22 18:31:40 +00:00
Sumner Evans
e3edd9afcb matrix-synapse: 1.73.0 -> 1.74.0
Signed-off-by: Sumner Evans <me@sumnerevans.com>
(cherry picked from commit c5e381b6c2)
2022-12-22 15:19:36 +00:00
Thomas Gerbet
5cfefb9600 Merge pull request #206836 from NixOS/backport-205676-to-release-22.05
[Backport release-22.05] pjsip: add patch for CVE-2022-31031
2022-12-22 12:43:43 +01:00
github-actions[bot]
4038c67928 Merge staging-next-22.05 into staging-22.05 2022-12-22 00:15:26 +00:00
github-actions[bot]
f929109d9e Merge release-22.05 into staging-next-22.05 2022-12-22 00:14:49 +00:00
Martin Weinelt
40283dc971 libksba: 1.6.2 -> 1.6.3
https://gnupg.org/blog/20221017-pepe-left-the-ksba.html

Fixes: CVE-2022-3515
(cherry picked from commit bae75df20e)
2022-12-21 23:40:15 +00:00
Martin Weinelt
85a5572ca4 curl: backport 7.87.0 security fixes
https://curl.se/docs/CVE-2022-43551.html
https://curl.se/docs/CVE-2022-43552.html

Fixes: CVE-2022-43551, CVE-2022-43552
2022-12-21 23:36:16 +01:00
Martin Weinelt
e844c1687e Merge pull request #207055 from mweinelt/22.05/ovs 2022-12-21 15:26:21 +01:00
github-actions[bot]
2b64f7acc3 Merge staging-next-22.05 into staging-22.05 2022-12-21 00:14:37 +00:00
github-actions[bot]
4dce0a051e Merge release-22.05 into staging-next-22.05 2022-12-21 00:13:57 +00:00
Martin Weinelt
e7f4ba87d5 Merge pull request #207046 from risicle/ris-redmine-4.2.9-r22.05 2022-12-21 00:02:09 +01:00
Martin Weinelt
d0b452290c openvswitch-lts: Mark known vulnerable
https://www.openwall.com/lists/oss-security/2022/12/20/2
2022-12-20 23:51:46 +01:00
Martin Weinelt
dc0b71be6b openvswitch: 2.17.0 -> 2.17.5
Fixes LLDP underflow issue while parsing malformed Auto Attach TLVs.

https://www.openvswitch.org/releases/NEWS-2.17.1.txt
https://www.openvswitch.org/releases/NEWS-2.17.2.txt
https://www.openvswitch.org/releases/NEWS-2.17.3.txt
https://www.openvswitch.org/releases/NEWS-2.17.4.txt
https://www.openvswitch.org/releases/NEWS-2.17.5.txt
2022-12-20 23:51:42 +01:00
Robert Scott
77ac4a848e redmine: 4.2.8 -> 4.2.9
(cherry picked from commit 59fb0606d1)
2022-12-20 21:41:48 +00:00
Felix Singer
4325b72aaa redmine: 4.2.7 -> 4.2.8
(cherry picked from commit 32a43582e7)
2022-12-20 21:41:22 +00:00
Martin Weinelt
3dc2ae30bb Merge pull request #206134 from NixOS/backport-206123-to-release-22.05
[Backport release-22.05] librewolf: 107.0.1-2 -> 108.0-1
2022-12-20 20:57:02 +01:00
Robert Schütz
2772a171db imagemagick: 7.1.0-54 -> 7.1.0-55
Diff: https://github.com/ImageMagick/ImageMagick/compare/7.1.0-54...7.1.0-55
(cherry picked from commit d0be85dd11)
2022-12-20 07:22:02 -08:00
github-actions[bot]
70bb1cd0a5 Merge staging-next-22.05 into staging-22.05 2022-12-20 00:15:13 +00:00
github-actions[bot]
cc6c51b5e9 Merge release-22.05 into staging-next-22.05 2022-12-20 00:14:37 +00:00
Franz Pletz
bfb04388d4 Merge pull request #206714 from NixOS/backport-206514-to-release-22.05
[Backport release-22.05] [Backport release-22.11] mbedtls: 2.28.1 -> 2.28.2
2022-12-19 12:03:08 +01:00
Robert Scott
4621893969 pjsip: add patch for CVE-2022-31031
(cherry picked from commit 54f22d3d27)
2022-12-19 10:40:28 +00:00
Vladimír Čunát
fe8835ca45 Merge #206385: thunderbird*: 102.5.1 -> 102.6.0
...into release-22.05
2022-12-19 09:55:05 +01:00
github-actions[bot]
a8617f401f Merge staging-next-22.05 into staging-22.05 2022-12-19 00:14:29 +00:00
github-actions[bot]
efe041a5ce Merge release-22.05 into staging-next-22.05 2022-12-19 00:13:48 +00:00
Raphael Robatsch
6504f1d973 mbedtls: 2.28.1 -> 2.28.2
Changelog: https://github.com/Mbed-TLS/mbedtls/blob/mbedtls-2.28.2/ChangeLog

(cherry picked from commit aac46d7460)
(cherry picked from commit cceb746099)
2022-12-18 15:14:59 +00:00
Martin Weinelt
e398530d85 Merge pull request #206515 from NixOS/backport-206443-to-release-22.05 2022-12-18 01:31:14 +01:00
github-actions[bot]
94c637724e Merge staging-next-22.05 into staging-22.05 2022-12-18 00:15:21 +00:00
github-actions[bot]
838ab6b78b Merge release-22.05 into staging-next-22.05 2022-12-18 00:14:50 +00:00
Robert Scott
afe2adcc97 sqlite: add patch for CVE-2022-46908
(cherry picked from commit a7a2489afd)
2022-12-17 19:34:14 +00:00
Michael Weiss
ed5c42ecc8 Merge pull request #206536 from primeos/ungoogled-chromium-backport-oldstable
[22.05] ungoogled-chromium: 108.0.5359.99 -> 108.0.5359.125
2022-12-17 19:21:52 +01:00
Michael Weiss
67c12bfc46 Merge pull request #206534 from NixOS/backport-206306-to-release-22.05
[Backport release-22.05] chromium: 108.0.5359.98 -> 108.0.5359.124
2022-12-17 16:18:12 +01:00
Michael Weiss
df62601675 chromium: 108.0.5359.98 -> 108.0.5359.124
https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop_13.html

This update includes 8 security fixes.

CVEs:
CVE-2022-4436 CVE-2022-4437 CVE-2022-4438 CVE-2022-4439 CVE-2022-4440

(cherry picked from commit 4d78fa3a59)
2022-12-17 13:17:00 +00:00
Michael Adler
382146ff9f ungoogled-chromium: 108.0.5359.99 -> 108.0.5359.125
(cherry picked from commit 9adfad5eaa)
2022-12-17 14:14:51 +01:00
Michael Weiss
32a617c239 Merge pull request #205204 from NixOS/backport-205117-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 108.0.5359.95 -> 108.0.5359.99
2022-12-17 14:11:38 +01:00
R. Ryantm
c9186c4f20 firefox-unwrapped: 108.0 -> 108.0.1
(cherry picked from commit dbf1e1161a)
2022-12-17 10:34:00 +00:00
Maximilian Bosch
d513b448cc Merge pull request #206498 from Ma27/22.05-linux-kernel-updates
[22.05] Linux kernel updates 2022-12-16
2022-12-17 11:12:34 +01:00
Robert Schütz
3e89320211 nixopsUnstable: mark certifi insecure
(cherry picked from commit 218122fa5c)
2022-12-17 01:46:57 -08:00
Robert Schütz
91f5eb9de1 nixops: mark certifi insecure
(cherry picked from commit 7825e0f1ef)
2022-12-17 01:46:57 -08:00
Maximilian Bosch
2450eda7d3 linux: 4.9.335 -> 4.9.336 2022-12-17 09:21:07 +01:00
Maximilian Bosch
c816514a1a linux/hardened/patches/6.0: 6.0.11-hardened1 -> 6.0.13-hardened1
(cherry picked from commit 9a1c480917)
2022-12-17 09:20:32 +01:00
Maximilian Bosch
8acc0c1b02 linux/hardened/patches/5.4: 5.4.225-hardened1 -> 5.4.227-hardened1
(cherry picked from commit b346fc8005)
2022-12-17 09:20:19 +01:00
Maximilian Bosch
0c4a36f004 linux/hardened/patches/5.15: 5.15.81-hardened1 -> 5.15.83-hardened1
(cherry picked from commit 9ceaa23872)
2022-12-17 09:20:17 +01:00
Maximilian Bosch
38c5c2bbe4 linux/hardened/patches/5.10: 5.10.157-hardened1 -> 5.10.159-hardened1
(cherry picked from commit 2d3cabe51f)
2022-12-17 09:19:31 +01:00
Maximilian Bosch
51a65228b9 linux/hardened/patches/4.19: 4.19.267-hardened1 -> 4.19.269-hardened1
(cherry picked from commit 4a9708ac03)
2022-12-17 09:18:26 +01:00
Maximilian Bosch
74fd9c4523 linux/hardened/patches/4.14: 4.14.300-hardened1 -> 4.14.302-hardened1
(cherry picked from commit 168c60bbe8)
2022-12-17 09:18:25 +01:00
Maximilian Bosch
4e323bf38a linux-rt_5_10: 5.10.153-rt76 -> 5.10.158-rt77
(cherry picked from commit 0fd3622bbc)
2022-12-17 09:18:25 +01:00
Maximilian Bosch
4467889b67 linux: 6.0.12 -> 6.0.13
(cherry picked from commit f3e1ec7eda)
2022-12-17 09:18:25 +01:00
Maximilian Bosch
14fda51bc7 linux: 5.4.226 -> 5.4.227
(cherry picked from commit e084dd9bff)
2022-12-17 09:18:24 +01:00
Maximilian Bosch
c918aca9b3 linux: 5.15.82 -> 5.15.83
(cherry picked from commit 0d9e47d655)
2022-12-17 09:18:24 +01:00
Maximilian Bosch
98550be63a linux: 5.10.158 -> 5.10.159
(cherry picked from commit 7b15da8941)
2022-12-17 09:18:24 +01:00
Maximilian Bosch
69bcdb1997 linux: 4.19.268 -> 4.19.269
(cherry picked from commit 1103904492)
2022-12-17 09:18:24 +01:00
Maximilian Bosch
ebd11b9ce2 linux: 4.14.301 -> 4.14.302
(cherry picked from commit 1d12ad41d1)
2022-12-17 09:18:24 +01:00
Vladimír Čunát
337c1ba6e4 thunderbird*: 102.5.1 -> 102.6.0
https://www.thunderbird.net/en-US/thunderbird/102.6.0/releasenotes/
(cherry picked from commit 3a4c97caa0)
2022-12-16 11:33:26 +00:00
Rouven Czerwinski
6b9fa29b13 xwayland: 22.1.5 -> 22.1.6
Changelog: https://lists.x.org/archives/xorg-announce/2022-December/003304.html
(cherry picked from commit 6a2f790f7a)
2022-12-16 11:11:11 +00:00
github-actions[bot]
517ea88ed2 Merge staging-next-22.05 into staging-22.05 2022-12-16 00:15:38 +00:00
github-actions[bot]
fd357708cd Merge release-22.05 into staging-next-22.05 2022-12-16 00:15:01 +00:00
Martin Weinelt
0461a51242 Merge pull request #206219 from vcunat/p/firefox-22.05 2022-12-15 12:38:24 +01:00
Vladimír Čunát
8e27fbf278 firefox: fix build by using newer rustc
FF 108 needs at least 1.63
https://hydra.nixos.org/build/201985872/nixlog/1/tail
2022-12-15 11:27:34 +01:00
Vladimír Čunát
730f38f455 rustPackages_1_64: backport from nixpkgs 22.11
I just copied the parts of nix expressions from 22.11.
2022-12-15 11:27:34 +01:00
ajs124
6cb8f6312d nss_latest: 3.85 -> 3.86
https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/NqCkaX216zY/m/QAUPTaBWCgAJ
(cherry picked from commit c13ed541db)
2022-12-15 11:27:34 +01:00
ajs124
0b82253944 nss_latest: 3.84 -> 3.85
https://github.com/nss-dev/nss/blob/master/doc/rst/releases/nss_3_85.rst
(cherry picked from commit 9930d35129)
Firefox 108 needs nss >= 3.85
2022-12-15 11:27:34 +01:00
Vladimír Čunát
053a71db7a Merge #206207: openssl_3: patch CVE-2022-3996
...into release-22.05
2022-12-15 10:46:25 +01:00
ajs124
3aa399e2f0 openssl_3: patch CVE-2022-3996
https://www.openssl.org/news/secadv/20221213.txt
(cherry picked from commit fa8c56b8c7)
2022-12-15 09:11:07 +00:00
Martin Weinelt
edff532d4f Merge pull request #205391 from helsinki-systems/bkp/22.05/nss_latest_cacert 2022-12-15 02:05:03 +01:00
github-actions[bot]
35f4ddf2eb Merge staging-next-22.05 into staging-22.05 2022-12-15 00:15:52 +00:00
github-actions[bot]
86d926f453 Merge release-22.05 into staging-next-22.05 2022-12-15 00:15:18 +00:00
Martin Weinelt
9264e62367 Merge pull request #205991 from mweinelt/22.05/firefox-108.0 2022-12-14 22:30:26 +01:00
squalus
a5d5057d9a librewolf: 107.0.1-2 -> 108.0-1
(cherry picked from commit 5046b3bd1a)
2022-12-14 21:26:37 +00:00
Kerstin
e5ce59ad29 Merge pull request #205962 from NixOS/backport-205897-to-release-22.05
[Backport release-22.05] imagemagick: 7.1.0-53 -> 7.1.0-54
2022-12-14 18:54:58 +01:00
Martin Weinelt
5cb48ea3c1 Merge pull request #205997 from NixOS/backport-201525-to-release-22.05 2022-12-14 02:11:21 +01:00
R. Ryantm
de69a39b5b firefox-beta-bin-unwrapped: 107.0b9 -> 108.0b9
(cherry picked from commit b4adc07d7d)
2022-12-14 01:08:27 +00:00
Martin Weinelt
3c3bb8ccaa Merge pull request #205993 from NixOS/backport-201526-to-release-22.05 2022-12-14 02:00:52 +01:00
R. Ryantm
84ea6618d4 firefox-devedition-bin-unwrapped: 107.0b9 -> 108.0b9
(cherry picked from commit f4e5563053)
2022-12-14 00:54:06 +00:00
Martin Weinelt
c4b58082cc firefox-esr-unwrapped: 102.5.0esr -> 102.6.0esr
https://www.mozilla.org/en-US/firefox/102.6.0/releasenotes/
(cherry picked from commit 7673d5110f)
2022-12-14 01:50:43 +01:00
Vladimír Čunát
29ef5e70e6 firefox*: 107.0.1 -> 108.0
https://www.mozilla.org/en-US/firefox/108.0/releasenotes/

./build/cargo-link uses /usr/bin/env shebang and thus needs patching.

(cherry picked from commit 85f91f3f47)
2022-12-14 01:49:20 +01:00
Martin Weinelt
296c54d29e Merge pull request #205857 from mweinelt/22.05/wolfssl-5.5.3 2022-12-14 01:48:51 +01:00
github-actions[bot]
36dc91c3fc Merge staging-next-22.05 into staging-22.05 2022-12-14 00:16:16 +00:00
github-actions[bot]
e8ff2570b5 Merge release-22.05 into staging-next-22.05 2022-12-14 00:15:37 +00:00
Maximilian Bosch
9642297fc6 Merge pull request #205972 from Ma27/22.05-element-backport
[22.05] element-{web,desktop}: 1.11.15 -> 1.11.16
2022-12-13 23:25:40 +01:00
Maximilian Bosch
42a73d6f35 element-{web,desktop}: 1.11.15 -> 1.11.16
Backport of 8e832b78fd to 22.05.

ChangeLog web: https://github.com/vector-im/element-web/releases/tag/v1.11.16
ChangeLog desktop: https://github.com/vector-im/element-desktop/releases/tag/v1.11.16
2022-12-13 22:21:01 +01:00
R. Ryantm
b34c349339 imagemagick: 7.1.0-53 -> 7.1.0-54
(cherry picked from commit 980cc45e15)
2022-12-13 20:40:48 +00:00
Maximilian Bosch
0bb3e99c86 Merge pull request #205781 from NixOS/backport-205754-to-release-22.05
[Backport release-22.05] wiki-js: 2.5.292 -> 2.5.294
2022-12-13 12:46:41 +01:00
Jack Kelly
392094add3 wolfssl: fix hash
The previous hash corresponded to wolfssl-5.5.2, but it looks like
everyone was getting cache hits on the built outputs and nobody
noticed.

(cherry picked from commit 9adcaceb2c)
2022-12-13 01:00:09 +01:00
Fabian Affolter
f272e6b8a0 wolfssl: 5.5.2 -> 5.5.3
https://github.com/wolfSSL/wolfssl/blob/master/ChangeLog.md#wolfssl-release-553-nov-2-2022
(cherry picked from commit f1f41c5da7)
2022-12-13 01:00:05 +01:00
Vladimír Čunát
bfee11f41c python311: revert asyncio changes done in 3.11.1
Almost same as in the parent commit.

(cherry picked from commit 1a5af95367)
2022-12-12 15:41:15 +01:00
Vladimír Čunát
3241c34a2e python310: revert asyncio changes done in 3.10.9
They brought significant regressions.  Upstream is now discussing
what to do, but we still want the security fixes from 3.10.9.

(cherry picked from commit 9ee1d16c36)
2022-12-12 15:41:09 +01:00
Maximilian Bosch
b06da061e1 wiki-js: 2.5.292 -> 2.5.294
ChangeLog: https://github.com/requarks/wiki/releases/tag/v2.5.293
ChangeLog: https://github.com/requarks/wiki/releases/tag/v2.5.294
(cherry picked from commit 132ac65001)
2022-12-12 14:18:52 +00:00
github-actions[bot]
c8d2e24856 Merge staging-next-22.05 into staging-22.05 2022-12-11 00:17:02 +00:00
github-actions[bot]
1b16b20c8a Merge release-22.05 into staging-next-22.05 2022-12-11 00:16:29 +00:00
Robert Scott
9e934ddbf9 traefik: add patch for CVE-2022-41717 2022-12-10 20:14:19 +00:00
Robert Schütz
7b9eeb856c poetry: mark insecure
The version of cleo in poetry.lock (1.0.0a5) is vulnerable to
CVE-2022-42966.

(cherry picked from commit d1bdaa9a99)
2022-12-10 11:30:05 -08:00
Bjørn Forsman
085fde3706 nextcloud-client: 3.6.2 -> 3.6.4
(cherry picked from commit b5169b276b)
2022-12-10 16:02:35 +01:00
Pavol Rusnak
d6ed087396 Merge pull request #205460 from NixOS/backport-205425-to-release-22.05
[Backport release-22.05] procyon: 0.6-prerelease -> 0.6.0
2022-12-10 14:30:09 +01:00
Pavol Rusnak
0e93aea9f4 procyon: 0.6-prerelease -> 0.6.0
(cherry picked from commit 66e349bad1)
2022-12-10 13:05:15 +00:00
Robert Scott
ca02b52f93 Merge pull request #205281 from Ma27/discourse-backport
[22.05] discourse: 2.9.0.beta10 -> 2.9.0.beta14
2022-12-10 12:27:24 +00:00
ajs124
4f752ec80f cacert: 3.83 -> 3.86
https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/NqCkaX216zY/m/QAUPTaBWCgAJ
(cherry picked from commit e5212aaa67)
2022-12-10 01:51:47 +01:00
ajs124
7d0d27a2cd nss_latest: 3.85 -> 3.86
https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/NqCkaX216zY/m/QAUPTaBWCgAJ
(cherry picked from commit c13ed541db)
2022-12-10 01:51:42 +01:00
ajs124
3d7cd16983 nss_latest: 3.84 -> 3.85
https://github.com/nss-dev/nss/blob/master/doc/rst/releases/nss_3_85.rst
(cherry picked from commit 9930d35129)
2022-12-10 01:51:38 +01:00
github-actions[bot]
49a39ce23f Merge staging-next-22.05 into staging-22.05 2022-12-10 00:15:25 +00:00
github-actions[bot]
3cc30c7d12 Merge release-22.05 into staging-next-22.05 2022-12-10 00:14:48 +00:00
Robert Scott
850c27142a Merge pull request #205075 from NixOS/backport-204876-to-release-22.05
[Backport release-22.05] ssm-agent: apply patch for CVE-2022-29527
2022-12-09 22:32:23 +00:00
Maximilian Bosch
439cc33f41 Merge pull request #205173 from NixOS/backport-205155-to-release-22.05
[Backport release-22.05] linuxKernel.kernels: update
2022-12-09 13:15:40 +01:00
Maximilian Bosch
0f7939b489 discourse: 2.9.0.beta10 -> 2.9.0.beta14
Backport of #204251.
Fixes CVE-2022-41921, CVE-2022-41944, CVE-2022-46150, CVE-2022-46159.
2022-12-09 11:42:28 +01:00
Maximilian Bosch
3d9b38f945 linux: 4.9.334 -> 4.9.335 2022-12-09 11:23:53 +01:00
Thomas Gerbet
3b0e6df4db Merge pull request #204326 from NixOS/backport-204300-to-release-22.05
[Backport release-22.05] pgadmin4: apply patch for CVE-2022-4223
2022-12-09 10:30:15 +01:00
github-actions[bot]
bf3df7dd80 Merge staging-next-22.05 into staging-22.05 2022-12-09 00:16:29 +00:00
github-actions[bot]
62fabc31c7 Merge release-22.05 into staging-next-22.05 2022-12-09 00:15:53 +00:00
Robert Scott
ee6eb95d9b Merge pull request #205077 from NixOS/backport-205045-to-release-22.05
[Backport release-22.05] imagemagick6: 6.9.12-26 -> 6.9.12-68
2022-12-09 00:13:50 +00:00
Anderson Torres
cfd18fb759 Merge pull request #205195 from LeSuisse/22.05-vlc-3.0.18
[22.05] vlc: 3.0.17.3 -> 3.0.18
2022-12-08 20:40:57 -03:00
Michael Adler
282aa31073 ungoogled-chromium: 108.0.5359.95 -> 108.0.5359.99
(cherry picked from commit 3f7c8b2b96)
2022-12-08 22:35:47 +00:00
Michael Weiss
99ec06122f Merge pull request #205053 from NixOS/backport-205041-to-release-22.05
[Backport release-22.05] chromium: 108.0.5359.94 -> 108.0.5359.98
2022-12-08 23:27:38 +01:00
Mustafa Çalışkan
96d9e2d768 vlc: 3.0.17.3 -> 3.0.18
(cherry picked from commit 795fc63682)
2022-12-08 23:12:48 +01:00
Mustafa Çalışkan
251308828d live555: 2022.07.14 -> 2022.12.01
(cherry picked from commit 99269923c6)
2022-12-08 23:12:48 +01:00
R. Ryantm
427c6c21ed live555: 2022.06.16 -> 2022.07.14
(cherry picked from commit 860ecbc98a)
2022-12-08 23:12:48 +01:00
misuzu
0a80131579 live555: 2022.02.07 -> 2022.06.16
(cherry picked from commit 4c031799bf)
2022-12-08 23:12:48 +01:00
Robert Scott
00f209ad8c Merge pull request #204991 from NixOS/backport-204548-to-release-22.05
[Backport release-22.05] libredwg: 0.12.4 -> 0.12.5
2022-12-08 21:55:03 +00:00
Bernardo Meurer
18a1c13fc3 linux: 6.0.11 -> 6.0.12
(cherry picked from commit 02a7f67cf0)
2022-12-08 20:01:44 +00:00
Bernardo Meurer
801209d89d linux: 5.4.225 -> 5.4.226
(cherry picked from commit 2d1651b612)
2022-12-08 20:01:44 +00:00
Bernardo Meurer
6ea3d9deef linux: 5.15.81 -> 5.15.82
(cherry picked from commit 6b0253df6a)
2022-12-08 20:01:44 +00:00
Bernardo Meurer
2dd08ee3a9 linux: 5.10.157 -> 5.10.158
(cherry picked from commit 1c008e6a66)
2022-12-08 20:01:43 +00:00
Bernardo Meurer
bc9949c986 linux: 4.19.267 -> 4.19.268
(cherry picked from commit 1a3bd52a0b)
2022-12-08 20:01:43 +00:00
Bernardo Meurer
cd53e8f53e linux: 4.14.300 -> 4.14.301
(cherry picked from commit ee48569ebf)
2022-12-08 20:01:43 +00:00
Thomas Gerbet
df2f5ffc30 imagemagick6: 6.9.12-26 -> 6.9.12-68
Fixes CVE-2022-1114, CVE-2022-1115, CVE-2022-3213, CVE-2022-32545, CVE-2022-32546 and CVE-2022-32547.

91af8aa460/ChangeLog.md
(cherry picked from commit a1f5263a86)
2022-12-08 00:36:02 +00:00
Thomas Gerbet
b144a27d00 ssm-agent: apply patch for CVE-2022-29527
(cherry picked from commit 2145ef28e2)
2022-12-08 00:34:33 +00:00
github-actions[bot]
3225270e91 Merge staging-next-22.05 into staging-22.05 2022-12-08 00:15:15 +00:00
github-actions[bot]
5ec9779950 Merge release-22.05 into staging-next-22.05 2022-12-08 00:14:41 +00:00
Martin Weinelt
7a454cc61a python310: 3.10.8 -> 3.10.9
https://docs.python.org/release/3.10.9/whatsnew/changelog.html
https://pythoninsider.blogspot.com/2022/12/python-3111-3109-3916-3816-3716-and.html

Fixes: CVE-2022-37454, CVE-2022-45061, CVE-2022-42919
(cherry picked from commit e824b21ba7)
2022-12-08 00:04:50 +00:00
Martin Weinelt
fa77536c51 python39: 3.9.15 -> 3.9.16
https://docs.python.org/release/3.9.16/whatsnew/changelog.html
https://pythoninsider.blogspot.com/2022/12/python-3111-3109-3916-3816-3716-and.html

Fixes: CVE-2022-37454, CVE-2022-42919, CVE-2022-45061, CVE-2015-20107
(cherry picked from commit 2fce48831c)
2022-12-08 00:04:50 +00:00
Michael Weiss
5ed8e2d604 chromium: 108.0.5359.94 -> 108.0.5359.98
https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop_7.html
(cherry picked from commit efb623debc)
2022-12-07 22:40:09 +00:00
Robert Scott
37382756db libredwg: unmark broken on darwin 2022-12-07 22:12:43 +00:00
nixpkgs-upkeep-bot
93459deb8a vscode: 1.73.0 -> 1.73.1
(cherry picked from commit 3c603ddf32)
2022-12-07 21:44:02 +01:00
nixpkgs-upkeep-bot
99a8e825a7 vscode: 1.72.2 -> 1.73.0
(cherry picked from commit a5c98493ef)
2022-12-07 21:44:02 +01:00
Winter
f881644bd0 vscode: don't fixup on darwin
Editing the `code` binary within the app bundle causes the bundle's signature to be invalidated, which prevents launching starting with macOS Ventura, because VS Code is notarized.

See https://eclecticlight.co/2022/06/17/app-security-changes-coming-in-ventura/ for more information.

(cherry picked from commit b29b81e458)
2022-12-07 21:44:02 +01:00
Adam Stephens
1242b8778e vscode: 1.72.1 -> 1.72.2
(cherry picked from commit f185aa12ab)
2022-12-07 21:44:01 +01:00
Adam Stephens
7e978da8b9 vscode: 1.71.2 -> 1.72.1
(cherry picked from commit da2258f912)
2022-12-07 21:44:01 +01:00
nixpkgs-upkeep-bot
bf6630380b vscode: 1.71.0 -> 1.71.2
(cherry picked from commit 2c3f33fd7e)
2022-12-07 21:44:01 +01:00
nixpkgs-upkeep-bot
6cbbda6901 vscode: 1.70.2 -> 1.71.0
(cherry picked from commit 1aa2c58f44)
2022-12-07 21:44:01 +01:00
nixpkgs-upkeep-bot
3d459868f8 vscode: 1.70.1 -> 1.70.2
(cherry picked from commit 5e24229488)
2022-12-07 21:44:01 +01:00
nixpkgs-upkeep-bot
8e737a7f11 vscode: 1.70.0 -> 1.70.1
(cherry picked from commit 08bd25a37a)
2022-12-07 21:44:00 +01:00
nixpkgs-upkeep-bot
f252708682 vscode: 1.69.2 -> 1.70.0
(cherry picked from commit 2c6b87b861)
2022-12-07 21:44:00 +01:00
R. Ryantm
dd2f077921 vscodium: 1.73.0.22306 -> 1.73.1.22314
(cherry picked from commit 9edba069ad)
2022-12-07 21:21:35 +01:00
R. Ryantm
2cfb5dd521 vscodium: 1.72.2.22289 -> 1.73.0.22306
(cherry picked from commit ee33796d9a)
2022-12-07 21:21:35 +01:00
R. Ryantm
40b2698c56 vscodium: 1.72.2.22286 -> 1.72.2.22289
(cherry picked from commit 28c21c140a)
2022-12-07 21:21:35 +01:00
R. Ryantm
0d262c2fe9 vscodium: 1.72.1.22284 -> 1.72.2.22286
(cherry picked from commit ffca0e9113)
2022-12-07 21:21:34 +01:00
R. Ryantm
fa77719d16 vscodium: 1.71.2.22258 -> 1.72.1.22284
(cherry picked from commit ae24d583ae)
2022-12-07 21:21:34 +01:00
nixpkgs-upkeep-bot
020d1f1e30 vscodium: 1.71.0.22245 -> 1.71.2.22258
(cherry picked from commit 9f1c7ec9b2)
2022-12-07 21:21:34 +01:00
nixpkgs-upkeep-bot
65c7d78841 vscodium: 1.70.2.22230 -> 1.71.0.22245
(cherry picked from commit 98d1746cac)
2022-12-07 21:21:34 +01:00
nixpkgs-upkeep-bot
c0c6c2b403 vscodium: 1.70.1.22228 -> 1.70.2.22230
(cherry picked from commit 0bffbf1d33)
2022-12-07 21:21:34 +01:00
nixpkgs-upkeep-bot
7c304aa2df vscodium: 1.70.1 -> 1.70.1.22228
(cherry picked from commit ab2905f473)
2022-12-07 21:21:33 +01:00
nixpkgs-upkeep-bot
a8dbb8d484 vscodium: 1.70.0 -> 1.70.1
(cherry picked from commit 9eb7edfef9)
2022-12-07 21:21:33 +01:00
Anderson Torres
009093a2e1 Merge pull request #204345 from NixOS/backport-204336-to-release-22.05
[Backport release-22.05] palemoon: 31.4.0 -> 31.4.1.1
2022-12-07 15:55:46 -03:00
Martin Weinelt
2a8b780db9 Merge pull request #205006 from NixOS/backport-204893-to-release-22.05 2022-12-07 16:56:48 +01:00
Martin Weinelt
ce0650787a python38: 3.11.0 -> 3.11.1
https://www.python.org/downloads/release/python-3111/
https://docs.python.org/release/3.11.1/whatsnew/changelog.html#python-3-11-1
https://pythoninsider.blogspot.com/2022/12/python-3111-3109-3916-3816-3716-and.html

Fixes: CVE-2022-45061
(cherry picked from commit f1433e66f9)
2022-12-07 15:22:27 +00:00
Martin Weinelt
3840a8233e python38: 3.8.15 -> 3.8.16
https://www.python.org/downloads/release/python-3816/
https://pythoninsider.blogspot.com/2022/12/python-3111-3109-3916-3816-3716-and.html

Fixes: CVE-2022-37454, CVE-2022-45061, CVE-2015-20107
(cherry picked from commit 71c4a3a0b1)
2022-12-07 15:22:27 +00:00
Martin Weinelt
16d247e56a python37: 3.7.15 -> 3.7.16
https://www.python.org/downloads/release/python-3716/
https://pythoninsider.blogspot.com/2022/12/python-3111-3109-3916-3816-3716-and.html

Fixes: CVE-2022-37454, CVE-2022-45061, CVE-2015-20107
(cherry picked from commit 10bab2150c)
2022-12-07 15:22:27 +00:00
Linus Heckemann
c06590856d Merge pull request #204972 from NixOS/backport-204795-to-staging-22.05
[Backport staging-22.05] cacert: Distrust TrustCor root certificates
2022-12-07 15:34:38 +01:00
Robert Scott
44f3b7e2a6 python3Packages.libredwg: fix build on darwin
(cherry picked from commit c0e332492f)
2022-12-07 14:00:28 +00:00
Robert Scott
b8f03470df libredwg: 0.12.4 -> 0.12.5
(cherry picked from commit a4966eecb9)
2022-12-07 14:00:28 +00:00
Martin Weinelt
57d63521e7 cacert: Distrust TrustCor root certificates
Mozilla set "Distrust After" for the three TrustCor Root CAs¹, so new
certificates issued would not be trusted after 2022/11/30, while older
enduser certificates would continue working until they expire. This is a
fine-grained policy option available to consumers of the NSS library,
such as Firefox or Thunderbird.

For Linux systems we generally export the Mozilla trust store into our
own CA bundle that ultimately lacks that metadata, because there is no
standardized way to parse it in the first place.

That means that as long as Mozilla keeps the certificate in their CA
program, even with time-based "Distrust" configured, we would keep
trusting it fully². That is completely unreasonable and that is why we
reject these CAs here for all users of nixpkgs.

The TrustCor CAs were primarily used to sign certificates for dynamic
hosts for domains provided through no-ip.com, so we expect the fallout
from this to be minimal.

[1] https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/oxX69KFvsm4/m/yLohoVqtCgAJ
[2] https://utcc.utoronto.ca/~cks/space/blog/linux/CARootStoreTrustProblem

(cherry picked from commit 2e7853293d)
2022-12-07 10:45:32 +00:00
Vladimír Čunát
fc3dcc9c90 Merge #204522: thunderbird*: 102.5.0 -> 102.5.1
...into release-22.05
2022-12-07 10:24:32 +01:00
Martin Weinelt
ef3b3fbc6e Merge pull request #204555 from NixOS/backport-204532-to-release-22.05 2022-12-07 01:20:04 +01:00
Jörg Thalheim
e719707385 signal-desktop: 6.0.0 -> 6.0.1
Changelog: https://github.com/signalapp/Signal-Desktop/releases/tag/v6.0.1
(cherry picked from commit cb7184812c)
2022-12-07 01:18:05 +01:00
github-actions[bot]
57fecb2425 Merge release-22.05 into staging-next-22.05 2022-12-07 00:15:20 +00:00
github-actions[bot]
d881cf9fd6 [Backport release-22.05] androidenv: use emulator from the path that makes it find qemu (#204849) 2022-12-06 22:49:02 +01:00
Kerstin
1d94ea96c6 Merge pull request #204796 from NixOS/backport-204735-to-release-22.05
[Backport release-22.05] imagemagick: 7.1.0-52 -> 7.1.0-53
2022-12-06 22:30:55 +01:00
Martin Weinelt
de8021c00a Merge pull request #204827 from NixOS/backport-204817-to-release-22.05 2022-12-06 21:56:06 +01:00
Sumner Evans
edbb1c4a67 matrix-synapse: 1.72.0 -> 1.73.0
Signed-off-by: Sumner Evans <me@sumnerevans.com>
(cherry picked from commit 33b48c1b65)
2022-12-06 17:19:55 +00:00
R. Ryantm
0720398756 imagemagick: 7.1.0-52 -> 7.1.0-53
(cherry picked from commit faef21d3db)
2022-12-06 15:21:57 +00:00
Martin Weinelt
fd9a112a97 Merge remote-tracking branch 'origin/staging-next-22.05' into staging-22.05 2022-12-06 01:25:10 +01:00
github-actions[bot]
539eb36607 Merge release-22.05 into staging-next-22.05 2022-12-06 00:14:21 +00:00
Jörg Thalheim
7e72265b08 Merge pull request #204580 from NixOS/backport-203827-to-release-22.05
[Backport release-22.05] signal-desktop: 5.63.1 -> 6.0.0
2022-12-05 14:47:58 +01:00
kilianar
01906c3647 signal-desktop: 5.63.1 -> 6.0.0
https://github.com/signalapp/Signal-Desktop/releases/tag/v6.0.0
(cherry picked from commit 79d95a065c)
2022-12-05 02:33:54 +00:00
Martin Weinelt
f9eb186457 Merge remote-tracking branch 'origin/staging-next-22.05' into staging-22.05 2022-12-05 01:34:06 +01:00
github-actions[bot]
2fa391558b Merge release-22.05 into staging-next-22.05 2022-12-05 00:15:26 +00:00
squalus
257237e9b3 librewolf: 107.0-1 -> 107.0.1-2
(cherry picked from commit 04a55b4bcb)
2022-12-04 23:42:08 +00:00
Vladimír Čunát
8f06a50e5f thunderbird*: 102.5.0 -> 102.5.1
https://www.thunderbird.net/en-US/thunderbird/102.5.1/releasenotes/
(cherry picked from commit 43760b400a)
2022-12-04 19:47:47 +00:00
Martin Weinelt
7187c12972 Merge pull request #204288 from mweinelt/22.05/botan2-CVE-2022-43705 2022-12-04 17:01:55 +01:00
Maximilian Bosch
12626191ea Merge pull request #204452 from Ma27/element-22.05
[22.05] element-{web,desktop}: 1.11.14 -> 1.11.15
2022-12-04 15:38:17 +01:00
Michael Weiss
1bc3dfc740 Merge pull request #204444 from NixOS/backport-204365-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 108.0.5359.72 -> 108.0.5359.95
2022-12-04 13:43:50 +01:00
Michael Weiss
f109793a76 Merge pull request #204442 from NixOS/backport-204364-to-release-22.05
[Backport release-22.05] chromium: 108.0.5359.71 -> 108.0.5359.94
2022-12-04 13:43:26 +01:00
Maximilian Bosch
332937f2c8 element-{web,desktop}: 1.11.14 -> 1.11.15
Backport of 13f3fdd8b3 (#204351) to 22.05.

ChangeLog web: https://github.com/vector-im/element-web/releases/tag/v1.11.15
ChangeLog desktop: https://github.com/vector-im/element-desktop/releases/tag/v1.11.15
2022-12-04 11:51:22 +01:00
Michael Weiss
30ebc3783a ungoogled-chromium: 108.0.5359.72 -> 108.0.5359.95
(cherry picked from commit d23b4148e7)
2022-12-04 10:30:53 +00:00
Michael Weiss
2e0d7ad9e6 chromium: 108.0.5359.71 -> 108.0.5359.94
https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop.html

This update includes 1 security fix. Google is aware that an exploit for
CVE-2022-4262 exists in the wild.

CVEs:
CVE-2022-4262

(cherry picked from commit 66bdeac7cb)
2022-12-04 10:30:37 +00:00
Naïm Favier
ed418392a6 Merge pull request #204313 from ncfavier/vim-nix-installer-22.05 2022-12-04 10:33:34 +01:00
Martin Weinelt
8d1434abac Merge remote-tracking branch 'origin/staging-next-22.05' into staging-22.05 2022-12-04 01:32:17 +01:00
github-actions[bot]
c3ddbada86 Merge release-22.05 into staging-next-22.05 2022-12-04 00:15:20 +00:00
Robert Scott
aac972f178 Merge pull request #204329 from LeSuisse/22.05-iterm2-3.4.18
[22.05] iterm2: 3.4.15 -> 3.4.18
2022-12-03 23:28:54 +00:00
Martin Weinelt
d47d9a6a29 Merge pull request #204339 from LeSuisse/capnproto-0.9.2 2022-12-03 22:23:24 +01:00
OPNA2608
d805236f13 palemoon: 31.4.0 -> 31.4.1.1
(cherry picked from commit 1795beca40)
2022-12-03 20:17:05 +00:00
Thomas Gerbet
50893f0310 capnproto: 0.9.1 -> 0.9.2
Fixes CVE-2022-46149.

b2fdf71399/security-advisories/2022-11-30-0-pointer-list-bounds.md
2022-12-03 20:20:30 +01:00
Thomas Gerbet
1525c32494 iterm2: 3.4.17 -> 3.4.18
Fixes CVE-2022-45872.

Changelog:
```
- Change DECRQSS response to patch a security
  hole.
- Fix crash when dragging a tab out of a window.
- Improve crash reporting to include Objective-C
  exceptions, which Apple broke.
```

(cherry picked from commit a9b1810350)
2022-12-03 19:23:04 +01:00
Tim Kleinschmidt
defc446ba3 iterm2: 3.4.15 -> 3.4.17
https://iterm2.com/downloads/stable/iTerm2-3_4_16.changelog
https://iterm2.com/downloads/stable/iTerm2-3_4_17.changelog
(cherry picked from commit da3c876cdd)
2022-12-03 19:22:59 +01:00
Thomas Gerbet
c4180714df pgadmin4: apply patch for CVE-2022-4223
Version 6.16 [0] seems quite large in term of changes so I preferred to only backport
the security fix.

[0] https://www.pgadmin.org/docs/pgadmin4/development/release_notes_6_16.html

(cherry picked from commit 30fbe9255f)
2022-12-03 18:00:18 +00:00
Maximilian Bosch
6c66ef16d1 nixos/profiles/base: install vim w/nix-syntax plugin
Considering that you most likely edit Nix code in the installer, that
seems like a useful thing.

The size of the ISO I got from

    nix-build nixos/release.nix -A iso_minimal.x86_64-linux

is still at 877M.

(cherry picked from commit 0b5a0cbc69)
2022-12-03 17:09:31 +01:00
Mario Rodas
e09913998d Merge pull request #204298 from NixOS/backport-204129-to-release-22.05
[Backport release-22.05] brave: 1.43.89 -> 1.46.133
2022-12-03 11:08:29 -05:00
Sean Buckley
c38218a9ba brave: 1.43.89 -> 1.46.133
https://community.brave.com/t/release-channel-1-46-133/449943

(cherry picked from commit 048211eec2)
2022-12-03 15:15:48 +00:00
Martin Weinelt
b2cd103556 botan2: Fix CVE-2022-43705
Backports security patches and regression tests. A complete fix would
require an API change that is scheduled for the 3.0 release, which is
out of scope.

https://github.com/randombit/botan/security/advisories/GHSA-4v9w-qvcq-6q7w

Fixes: CVE-2022-43705
2022-12-03 14:37:34 +01:00
Vladimír Čunát
979d4ea288 Merge #203265: Linux kernel updates 2022-11-27 and -12-02
...into release-22.05
2022-12-03 14:03:10 +01:00
Martin Weinelt
156859c400 Merge pull request #204280 from NixOS/backport-204185-to-release-22.05 2022-12-03 14:02:55 +01:00
Robert Scott
1e32590973 lepton: add CVE-2022-4104 to knownVulnerabilities
(cherry picked from commit 259c543e7f)
2022-12-03 13:02:14 +00:00
K900
0581b0b006 linux: set X86_AMD_PSTATE=y instead of =m
(cherry picked from commit b9a4991020)
2022-12-03 13:23:33 +01:00
K900
62e946b788 linux/hardened/patches/6.0: 6.0.8-hardened1 -> 6.0.10-hardened1
(cherry picked from commit aea291b018)
2022-12-03 13:23:05 +01:00
K900
182e712391 linux/hardened/patches/5.15: 5.15.79-hardened1 -> 5.15.80-hardened1
(cherry picked from commit 30d0f12f77)
2022-12-03 13:23:04 +01:00
K900
df6a743ae2 linux_latest-libre: 18996 -> 19001
(cherry picked from commit aea7b200b2)
2022-12-03 13:23:03 +01:00
K900
304e450521 linux: 6.0.10 -> 6.0.11
(cherry picked from commit c355d94275)
2022-12-03 13:23:01 +01:00
K900
f2d4a9bb69 linux: 5.15.80 -> 5.15.81
(cherry picked from commit 8f5ddf07cb)
2022-12-03 13:23:00 +01:00
K900
9d0ad218e9 linux: 5.10.156 -> 5.10.157
(cherry picked from commit d779e43f22)
2022-12-03 13:22:54 +01:00
Ryan Lahfa
a35e0d56f2 Merge pull request #204264 from NixOS/backport-204184-to-release-22.05
[Backport release-22.05] mbedtls: 2.28.0 -> 2.28.1
2022-12-03 12:55:01 +01:00
Thomas Gerbet
54b537c809 mbedtls: 2.28.0 -> 2.28.1
Fixes CVE-2022-35409.

https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.1
https://mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories/mbedtls-security-advisory-2022-07/
(cherry picked from commit 3b0a78f9fe)
2022-12-03 11:53:57 +00:00
Michael Weiss
d6d5a5e772 Merge pull request #204150 from NixOS/backport-204117-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 107.0.5304.122 -> 108.0.5359.72
2022-12-03 12:01:03 +01:00
github-actions[bot]
d7c2139504 Merge staging-next-22.05 into staging-22.05 2022-12-03 00:14:24 +00:00
github-actions[bot]
e0bb0a4f76 Merge release-22.05 into staging-next-22.05 2022-12-03 00:13:48 +00:00
Robert Scott
5d7d1d5f74 Merge pull request #203817 from risicle/ris-mujs-CVE-2022-44789-r22.05
[22.05] mujs: add patch for CVE-2022-44789
2022-12-02 19:27:21 +00:00
Michael Weiss
4c43973e35 ungoogled-chromium: 107.0.5304.122 -> 108.0.5359.72
(cherry picked from commit 74949d9c40)
2022-12-02 17:35:10 +00:00
github-actions[bot]
226ff078b7 Merge staging-next-22.05 into staging-22.05 2022-12-02 00:16:22 +00:00
github-actions[bot]
c900973f45 Merge release-22.05 into staging-next-22.05 2022-12-02 00:15:33 +00:00
Robert Scott
faf60907d8 mujs: add patch for unannounced stack overflow 2022-12-01 21:30:03 +00:00
Ryan Lahfa
60d042d7e3 Merge pull request #203950 from NixOS/backport-203668-to-release-22.05
[Backport release-22.05] postgresql_jdbc: 42.5.0 -> 42.5.1
2022-12-01 21:23:01 +01:00
Yaya
97e88a936c gitlab: 15.4.4 -> 15.4.6 (#203978)
https://about.gitlab.com/releases/2022/11/30/security-release-gitlab-15-6-1-released

Fixes CVE-2022-4206
Fixes CVE-2022-3820
Fixes CVE-2022-4205
Fixes CVE-2022-3902
Fixes CVE-2022-4054
Fixes CVE-2022-3572
Fixes CVE-2022-3482
Fixes CVE-2022-4255
Fixes CVE-2022-3478
Fixes CVE-2022-4201
2022-12-01 19:42:44 +01:00
Thomas Gerbet
30449783cd postgresql_jdbc: 42.5.0 -> 42.5.1
Fixes CVE-2022-41946.

https://github.com/pgjdbc/pgjdbc/blob/REL42.5.1/CHANGELOG.md
(cherry picked from commit ee36d11868)
2022-12-01 16:12:32 +00:00
Mario Rodas
af4d0d532f Merge pull request #202269 from risicle/ris-tensorflow-2.8.4-r22.05
[22.05] python3Packages.tensorflow: 2.8.1 -> 2.8.4, python3Packages.tensorflow-bin: 2.8.1 -> 2.8.4
2022-11-30 21:20:51 -05:00
Mario Rodas
172d160a83 Merge pull request #203831 from NixOS/backport-203729-to-release-22.05
[Backport release-22.05] chromium: 107.0.5304.121 -> 108.0.5359.71
2022-11-30 20:56:17 -05:00
Naïm Favier
a6d669c3fb Merge pull request #203833 from NixOS/backport-203595-to-release-22.05 2022-12-01 01:28:13 +01:00
github-actions[bot]
c0aa36dd1b Merge staging-next-22.05 into staging-22.05 2022-12-01 00:18:33 +00:00
github-actions[bot]
fb9e0bf834 Merge release-22.05 into staging-next-22.05 2022-12-01 00:17:57 +00:00
Naïm Favier
c25384f9a8 nixos/nix-daemon: allow registry paths to be... paths
Currently paths are handled by `types.package`, whose semantics are a
bit of a mess. In particular, it converts path values to derivations
using `toDerivation`, which will lead to problems when flake `outPath`s
become paths in https://github.com/NixOS/nix/pull/6530.

This change makes the "incompatible changes" section in the above PR
obsolete: `nix.registry.nixpkgs.flake = nixpkgs;` works as expected (the
flake is copied to the store).

(cherry picked from commit bcb5f0decc)
2022-12-01 00:09:06 +00:00
Michael Weiss
62df51e959 chromium: 107.0.5304.121 -> 108.0.5359.71
https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_29.html

This update includes 28 security fixes.

CVEs:
CVE-2022-4174 CVE-2022-4175 CVE-2022-4176 CVE-2022-4177 CVE-2022-4178
CVE-2022-4179 CVE-2022-4180 CVE-2022-4181 CVE-2022-4182 CVE-2022-4183
CVE-2022-4184 CVE-2022-4185 CVE-2022-4186 CVE-2022-4187 CVE-2022-4188
CVE-2022-4189 CVE-2022-4190 CVE-2022-4191 CVE-2022-4192 CVE-2022-4193
CVE-2022-4194 CVE-2022-4195

(cherry picked from commit 3609aedb1e)
2022-12-01 00:05:48 +00:00
Michael Weiss
2bce644feb Merge pull request #203809 from primeos/chromium-backport
[22.05] Prepare for backporting Chromium M108
2022-11-30 23:45:39 +01:00
Robert Scott
fd03298cd3 mujs: add patch for CVE-2022-44789 2022-11-30 22:32:45 +00:00
Michael Weiss
ed306b1b78 chromiumBeta: 108.0.5359.48 -> 108.0.5359.71 (#203681)
* chromiumBeta: 108.0.5359.48 -> 108.0.5359.62

* chromiumBeta: 108.0.5359.62 -> 108.0.5359.71

(cherry picked from commit ed4a7faf43)
2022-11-30 22:48:52 +01:00
Michael Weiss
61bf3c965d chromiumBeta: Fix the build
We do already set `system_wayland_scanner_path` to
`"${wayland}/bin/wayland-scanner"` but apparently wayland-scanner wasn't
required (anymore?) as wayland-scanner is only in the `bin` output (I have a
few ideas what could've changed but didn't bother to check as it isn't worth
the time as long as it works now).

This fixes the following build error:
```
ninja: error: '../../../../../../../../nix/store/l3y9k2x7cqzcjj9s18z7la9xqsjq6r52-wayland-1.21.0/bin/wayland-scanner', needed by 'gen/components/exo/wayland/protocol/aura-shell-protocol.c', missing and no known rule to make it
```

(cherry picked from commit 4024dedc4d)
2022-11-30 22:48:51 +01:00
Michael Weiss
65374cb518 chromiumBeta: Fix the configuration phase
Upstream switched use_system_libwayland to false [0] and
system_wayland_scanner_path will now only be declared if
use_system_wayland_scanner is set to true (it defaults to
use_system_libwayland) [1].

In Nixpkgs, we usually try to set use_system_* to true (i.e., we favor
system libraries over bundled/vendored ones) but in the case of Chromium
this can become difficult to maintain so we might eventually drop
`use_system_libwayland = true` again (IIRC this only caused one
incompatibility in the past though: b6b51374fc7; and f9d9864cb6 will
become relevant again when we build with the bundled libwayland).

[0]: b33bdfe265
[1]: 272220cefa

(cherry picked from commit 9d05d42f4d)
2022-11-30 22:48:51 +01:00
Michael Weiss
935bd00e35 chromiumDev: 109.0.5410.0 -> 109.0.5414.10
(cherry picked from commit 6492d64628)
2022-11-30 22:48:51 +01:00
Michael Weiss
caa0724537 chromiumBeta: 108.0.5359.40 -> 108.0.5359.48
(cherry picked from commit f2b994a384)
2022-11-30 22:48:50 +01:00
Michael Weiss
cfd882b6e4 chromiumDev: 109.0.5396.2 -> 109.0.5410.0
(cherry picked from commit ec860f905d)
2022-11-30 22:48:50 +01:00
Michael Weiss
14b1a6c99a chromiumBeta: 108.0.5359.30 -> 108.0.5359.40
(cherry picked from commit 81b2f56045)
2022-11-30 22:48:50 +01:00
Michael Weiss
ba5bf92c18 nixos/tests/chromium: Re-enable the chrome://gpu test for M107
I need to fix copying the chrome://gpu content to the clipboard (Ctrl+a doesn't
work anymore so we have to click the button) but we can at least test the font
rendering for now.

(cherry picked from commit 673f7d025b)
2022-11-30 22:48:50 +01:00
Michael Weiss
cd11a9e32e chromiumDev: 109.0.5384.0 -> 109.0.5396.2
(cherry picked from commit fe2fe7c588)
2022-11-30 22:48:49 +01:00
Michael Weiss
802eb722c3 chromiumBeta: 108.0.5359.22 -> 108.0.5359.30
(cherry picked from commit f432eecba7)
2022-11-30 22:48:49 +01:00
Michael Weiss
77383d9041 chromiumBeta: 107.0.5304.68 -> 108.0.5359.22
(cherry picked from commit 5fa41df499)
2022-11-30 22:48:49 +01:00
Michael Weiss
7e09fab0a7 chromiumDev: 108.0.5359.19 -> 109.0.5384.0
(cherry picked from commit 1e999fae15)
2022-11-30 22:48:48 +01:00
Michael Weiss
42e61a7ee6 chromiumDev: 108.0.5359.10 -> 108.0.5359.19
(cherry picked from commit 3a2c2fbc24)
2022-11-30 22:48:48 +01:00
Michael Weiss
776e54e90d chromiumBeta: 107.0.5304.62 -> 107.0.5304.68
(cherry picked from commit e07577d52d)
2022-11-30 22:48:48 +01:00
github-actions[bot]
244485c8b6 Merge staging-next-22.05 into staging-22.05 2022-11-30 00:16:56 +00:00
github-actions[bot]
2b400b9699 Merge release-22.05 into staging-next-22.05 2022-11-30 00:16:22 +00:00
Mario Rodas
0244e143dc Merge pull request #203599 from NixOS/backport-203579-to-release-22.05
[Backport release-22.05] firefox-{,bin-}unwrapped: 107.0 -> 107.0.1
2022-11-29 18:34:44 -05:00
Martin Weinelt
9f9c9d646b firefox-bin-unwrapped: 107.0 -> 107.0.1
https://www.mozilla.org/en-US/firefox/107.0.1/releasenotes/
(cherry picked from commit 5834fbb994)
2022-11-29 13:45:38 +00:00
Martin Weinelt
f6016a6159 firefox-unwrapped: 107.0 -> 107.0.1
https://www.mozilla.org/en-US/firefox/107.0.1/releasenotes/
(cherry picked from commit 83c75c0f43)
2022-11-29 13:45:38 +00:00
github-actions[bot]
f1c2092e68 Merge staging-next-22.05 into staging-22.05 2022-11-29 00:17:07 +00:00
github-actions[bot]
b5c517c233 Merge release-22.05 into staging-next-22.05 2022-11-29 00:16:31 +00:00
Anderson Torres
f214b8c945 Merge pull request #203461 from NixOS/backport-203119-to-release-22.05
[Backport release-22.05] palemoon: 31.3.1 -> 31.4.0
2022-11-28 20:15:08 -03:00
OPNA2608
308d03032f palemoon: 31.3.1 -> 31.4.0
(cherry picked from commit be825b650a)
2022-11-28 14:46:54 +00:00
Thiago Kenji Okada
cc7ae74d40 Merge pull request #203133 from NixOS/backport-203110-to-release-22.05
[Backport release-22.05] shellhub-agent: 0.10.4 -> 0.10.8
2022-11-28 08:55:51 +00:00
github-actions[bot]
78088a7479 Merge staging-next-22.05 into staging-22.05 2022-11-28 00:15:50 +00:00
github-actions[bot]
08f30ca1f0 Merge release-22.05 into staging-next-22.05 2022-11-28 00:15:20 +00:00
Robert Scott
5acc438f33 Merge pull request #203165 from NixOS/backport-200798-to-release-22.05
[Backport release-22.05] drogon: 1.8.1 -> 1.8.2
2022-11-28 00:14:58 +00:00
Sandro
07ad858a50 Merge pull request #202016 from NixOS/backport-201261-to-release-22.05 2022-11-28 00:04:59 +01:00
Martin Weinelt
56514fb03d Merge pull request #203325 from LeSuisse/22.05-dropbear-CVE-2021-36369 2022-11-27 20:41:25 +01:00
Thomas Gerbet
2e0b6e678c dropbear: apply patch for CVE-2021-36369 2022-11-27 20:01:38 +01:00
Vladimír Čunát
88462ff548 Merge #203319: upx: apply patch for CVE-2021-20285
...into release-22.05
2022-11-27 19:52:43 +01:00
Thomas Gerbet
ca9e17753f upx: apply patch for CVE-2021-20285
Did not bump to 4.0.0 yet because the 4.0.0 release is affected by CVE-2021-30500 and CVE-2021-30501.
The patch for CVE-2021-30500 does not apply cleanly on top of 4.0.0.

(cherry picked from commit e43e91a2a2)
2022-11-27 18:41:43 +00:00
Maximilian Bosch
3c8286fb65 linux: 4.9.333 -> 4.9.334 2022-11-27 15:14:17 +01:00
Maximilian Bosch
f9adb9c703 linux/hardened/patches/5.4: 5.4.224-hardened1 -> 5.4.225-hardened1
(cherry picked from commit 91e2b58a76)
2022-11-27 14:13:07 +00:00
Maximilian Bosch
6f17718072 linux/hardened/patches/5.15: 5.15.78-hardened1 -> 5.15.79-hardened1
(cherry picked from commit 04ba9d8ded)
2022-11-27 14:13:07 +00:00
Maximilian Bosch
cd84dbb32a linux/hardened/patches/5.10: 5.10.154-hardened1 -> 5.10.156-hardened1
(cherry picked from commit 5c01fb2677)
2022-11-27 14:13:07 +00:00
Maximilian Bosch
b4e054e877 linux/hardened/patches/4.19: 4.19.265-hardened1 -> 4.19.267-hardened1
(cherry picked from commit a3ef6bef2a)
2022-11-27 14:13:07 +00:00
Maximilian Bosch
45ce93ad00 linux/hardened/patches/4.14: 4.14.299-hardened1 -> 4.14.300-hardened1
(cherry picked from commit dee4d9f013)
2022-11-27 14:13:07 +00:00
Maximilian Bosch
72dbf38202 linux_latest-libre: 18978 -> 18996
(cherry picked from commit 7b2c616756)
2022-11-27 14:13:07 +00:00
Maximilian Bosch
7be2c91486 linux: 6.0.9 -> 6.0.10
(cherry picked from commit 6861146537)
2022-11-27 14:13:07 +00:00
Maximilian Bosch
0dff111ce4 linux: 5.4.224 -> 5.4.225
(cherry picked from commit 08eebaf5d9)
2022-11-27 14:13:07 +00:00
Maximilian Bosch
ecb105ea51 linux: 5.15.79 -> 5.15.80
(cherry picked from commit 9f5b441bf4)
2022-11-27 14:13:07 +00:00
Maximilian Bosch
239e9c08de linux: 5.10.155 -> 5.10.156
(cherry picked from commit 42edd9f2e9)
2022-11-27 14:13:07 +00:00
Maximilian Bosch
6bfc34d74a linux: 4.19.265 -> 4.19.267
(cherry picked from commit e3db9b3f05)
2022-11-27 14:13:07 +00:00
Maximilian Bosch
8d4c7e351d linux: 4.14.299 -> 4.14.300
(cherry picked from commit 2d7d63b452)
2022-11-27 14:13:07 +00:00
Michael Weiss
fecf05d486 Merge pull request #202936 from NixOS/backport-202869-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 107.0.5304.110 -> 107.0.5304.122
2022-11-27 12:02:05 +01:00
Martin Weinelt
4d3afa8043 Merge pull request #203169 from mweinelt/22.05/ntfs3g-security
[22.05] ntfs3g: Patch arbitrary code execution
2022-11-27 11:48:09 +01:00
Martin Weinelt
3da1b548e6 Merge pull request #203160 from mweinelt/22.05/moodle-3.11.11
[22.05] moodle: 3.11.6 -> 3.11.11
2022-11-27 11:12:53 +01:00
Martin Weinelt
6649e08812 Merge pull request #199848 from risicle/ris-batik-1.16-r22.05 2022-11-27 02:50:02 +01:00
Martin Weinelt
a1fad5f46e Merge pull request #201829 from risicle/ris-fluentd-CVE-2022-39379.r22.05 2022-11-27 02:49:37 +01:00
Martin Weinelt
1c9ac74ebf Merge pull request #202062 from risicle/ris-pillow-CVE-2022-45198-r22.05 2022-11-27 02:45:09 +01:00
Martin Weinelt
06e1283324 ntfs3g: Patch arbitrary code execution
Fixes: CVE-2022-40284
2022-11-27 02:38:50 +01:00
R. Ryantm
acac5492d1 drogon: 1.8.1 -> 1.8.2
(cherry picked from commit d46a86208a)
2022-11-27 01:36:24 +00:00
Martin Weinelt
816af9f07a moodle: 3.11.6 -> 3.11.11
https://moodledev.io/general/releases/3.11/3.11.7
https://moodledev.io/general/releases/3.11/3.11.8
https://moodledev.io/general/releases/3.11/3.11.9
https://moodledev.io/general/releases/3.11/3.11.10
https://moodledev.io/general/releases/3.11/3.11.11

Fixes: CVE-2022-30596, CVE-2022-30597, CVE-2022-30598, CVE-2022-30599,
       CVE-2022-30600, CVE-2022-35649, CVE-2022-35650, CVE-2022-35651,
       CVE-2022-35652, CVE-2022-35653, CVE-2022-0323, CVE-2022-2986,
       CVE-2022-40208, CVE-2022-40313, CVE-2022-40314, CVE-2022-40315,
       CVE-2022-40316, CVE-2021-23414, CVE-2022-45149, CVE-2022-45150,
       CVE-2022-45151, CVE-2022-45152
2022-11-27 02:18:06 +01:00
github-actions[bot]
c301c8e062 Merge staging-next-22.05 into staging-22.05 2022-11-27 00:17:46 +00:00
github-actions[bot]
b986ed0696 Merge release-22.05 into staging-next-22.05 2022-11-27 00:17:13 +00:00
Otavio Salvador
2cbf445bf8 shellhub-agent: 0.10.4 -> 0.10.8
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit 03bf773416)
2022-11-26 21:52:16 +00:00
Thiago Kenji Okada
446cc74ab9 Merge pull request #202940 from Enzime/backport-tailscale-to-release-22.05
[Backport release-22.05] tailscale: 1.24.2 -> 1.32.3
2022-11-26 19:16:39 +00:00
Robert Scott
365fa63ad6 Merge pull request #202600 from risicle/ris-libtiff-CVE-2022-3970-r22.05
[22.05] libtiff: add patch for CVE-2022-3970
2022-11-26 13:08:48 +00:00
github-actions[bot]
9db232b3e6 Merge staging-next-22.05 into staging-22.05 2022-11-26 00:15:10 +00:00
github-actions[bot]
286944e613 Merge release-22.05 into staging-next-22.05 2022-11-26 00:14:37 +00:00
Michael Hoang
84d6c9ff70 tailscale: 1.24.2 -> 1.32.3 2022-11-26 10:40:32 +11:00
Michael Adler
14c16fcbbb ungoogled-chromium: 107.0.5304.110 -> 107.0.5304.122
(cherry picked from commit 9fa2f1bf3e)
2022-11-25 23:32:58 +00:00
Michael Weiss
695b351525 Merge pull request #202916 from NixOS/backport-202742-to-release-22.05
[Backport release-22.05] chromium: 107.0.5304.110 -> 107.0.5304.121
2022-11-26 00:25:39 +01:00
Michael Weiss
cf32aa958c chromium: 107.0.5304.110 -> 107.0.5304.121
https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html

This update includes 1 security fix. Google is aware that an exploit for
CVE-2022-4135 exists in the wild.

CVEs:
CVE-2022-4135

(cherry picked from commit dbea32f981)
2022-11-25 21:24:47 +00:00
Pavol Rusnak
c91ed90bf7 Merge pull request #189750 from NixOS/backport-188571-to-release-22.05
[Backport release-22.05] btcpayserver: 1.6.9 -> 1.6.10
2022-11-25 19:40:56 +01:00
Thiago Kenji Okada
0faaf0a9bb Merge pull request #202789 from NixOS/backport-196923-to-release-22.05
[Backport release-22.05] xwayland: 22.1.3 -> 22.1.5
2022-11-25 12:14:02 +00:00
Rouven Czerwinski
2ab0349211 xwayland: 22.1.3 -> 22.1.5
Package bump:
- Grabs are now deactivated on Xwayland, leaving them to the compositor
- Memleak and length-check fixes for xkb
- Fix for kinetic scrolling
- Delayed wl_surface destruction to fix a race

(cherry picked from commit 152ed82e8f)
2022-11-25 07:21:55 +00:00
github-actions[bot]
da8367f38a Merge staging-next-22.05 into staging-22.05 2022-11-25 00:15:59 +00:00
github-actions[bot]
e627d4267f Merge release-22.05 into staging-next-22.05 2022-11-25 00:15:26 +00:00
Thiago Kenji Okada
d4556b01cd Merge pull request #202272 from Enzime/backport-181797-to-release-22.05
[Backport release-22.05] go_1_19: init at 1.19
2022-11-24 18:55:15 +00:00
Thiago Kenji Okada
a16a27cd6d Merge pull request #202669 from NixOS/backport-202589-to-release-22.05
[Backport release-22.05] tor-browser-bundle-bin: 11.5.7 -> 11.5.8
2022-11-24 17:56:31 +00:00
Nicolas Benes
60b075ec10 tor-browser-bundle-bin: 11.5.7 -> 11.5.8
https://blog.torproject.org/new-release-tor-browser-1158/
(cherry picked from commit c99cfce6ad)
2022-11-24 12:37:43 +00:00
Robert Scott
68ba2f4099 Merge pull request #202593 from panicgh/backport-202171-to-release-22.05
[Backport release-22.05] cfitsio: 4.1.0 -> 4.2.0
2022-11-24 00:31:16 +00:00
github-actions[bot]
edae11b9ad Merge staging-next-22.05 into staging-22.05 2022-11-24 00:16:44 +00:00
github-actions[bot]
f090fcd284 Merge release-22.05 into staging-next-22.05 2022-11-24 00:16:08 +00:00
Robert Scott
de6654afed libtiff: add patch for CVE-2022-3970
(cherry picked from commit 9a4cba4233)
2022-11-23 21:51:48 +00:00
R. Ryantm
af2b7e0d99 cfitsio: 4.1.0 -> 4.2.0
(cherry picked from commit f8eea40283)
2022-11-23 22:02:23 +01:00
Maximilian Bosch
95f824c9eb Merge pull request #202402 from NixOS/backport-202362-to-release-22.05
[Backport release-22.05] matrix-synapse: 1.71.0 -> 1.72.0
2022-11-23 20:45:31 +01:00
Ninjatrappeur
8f1da28577 Merge pull request #202544 from NixOS/backport-202491-to-release-22.05 2022-11-23 16:41:32 +01:00
Félix Baylac-Jacqué
647ebf83e6 nixosTests/prosody[-mysql]: fix tests TLS setup
The tests TLS setup was bogus: the xmpp-send-message script was trying
to connect to the server through a bogus domain name. Injecting the
right one.

I'm a bit confused about that one. I know for sure this NixOS test
succeeded last time I checked it, but the TLS conf is bogus for sure.
I assume the slixmpp SNI validation was a bit too loose and was
tightened at some point.

(cherry picked from commit 8040c468ed)
2022-11-23 15:25:35 +00:00
Félix Baylac-Jacqué
c60ec520ae nixosTests/prosody: add timeout
The xmpp-sendmessage the slixmpp-powered python script tend to timeout
and block the nixos channels.

Adding a signal-based timeout making sure that whatever happens, the
script won't run for more than 2 minutes. That should be pleinty
enough time to finish regardless of the runner specs. As a data point,
it runs in about 10 secs on my desktop machine.

(cherry picked from commit 501d684de8)
2022-11-23 15:25:35 +00:00
Pavol Rusnak
f10cdcf31d Merge pull request #202484 from NixOS/backport-202463-to-release-22.05
[Backport release-22.05] python3Packages.monero: 1.0.1 -> 1.1.1
2022-11-23 10:48:38 +01:00
gp2112
707b07a439 python3Packages.monero: 1.0.1 -> 1.1.1
(cherry picked from commit 443f5eb97f)
2022-11-23 09:19:15 +00:00
Pavol Rusnak
61514f2306 Merge pull request #202393 from prusnak/i2pd-22.05
[backport 22.05] i2pd: 2.41.0 -> 2.44.0
2022-11-23 10:10:36 +01:00
Vladimír Čunát
0a3da52c89 Merge #202023: staging-next-22.05 - iteration 15
...into release-22.05
2022-11-23 08:25:20 +01:00
github-actions[bot]
13573c668b Merge staging-next-22.05 into staging-22.05 2022-11-23 00:16:29 +00:00
github-actions[bot]
0ff79bc937 Merge release-22.05 into staging-next-22.05 2022-11-23 00:15:56 +00:00
Shea Levy
56ca700cea Merge pull request #202324 from shlevy/zotero-6.0.18-22.05
zotero: 6.0.4 -> 6.0.18
2022-11-22 16:23:31 -05:00
Robert Scott
6eb6b9a5bb Merge pull request #201257 from mweinelt/22.05/twisted
[22.05] python3Packages.twisted: Resolve host header injection vulnerability
2022-11-22 20:43:39 +00:00
Sumner Evans
27a01b3470 matrix-synapse: 1.71.0 -> 1.72.0
Signed-off-by: Sumner Evans <me@sumnerevans.com>
(cherry picked from commit 6ac16c2697)
2022-11-22 19:49:18 +00:00
R. Ryantm
85d4ebd525 i2pd: 2.43.0 -> 2.44.0
(cherry picked from commit 57f2bb494d)
2022-11-22 20:12:26 +01:00
Sandro Jäckel
8046afc4ea i2pd: remove unecessary ? null from inputs
(cherry picked from commit 64abd830b4)
2022-11-22 20:12:22 +01:00
R. Ryantm
9233a24a78 i2pd: 2.42.1 -> 2.43.0
(cherry picked from commit a5923a7139)
2022-11-22 20:12:16 +01:00
R. Ryantm
a492a6d15f i2pd: 2.41.0 -> 2.42.1
(cherry picked from commit df94e3fdce)
2022-11-22 20:12:10 +01:00
Mario Rodas
7f53c76b85 Merge pull request #202177 from NixOS/backport-201354-to-release-22.05
[Backport release-22.05] nixos/mastodon: fix emoji import
2022-11-22 08:15:06 -05:00
Shea Levy
b63aa9ad4f zotero: 6.0.4 -> 6.0.18 2022-11-22 04:31:28 -05:00
Robert Scott
d5b06b2fad python3Packages.tensorflow-bin: 2.8.1 -> 2.8.4 2022-11-22 00:49:18 +00:00
Robert Scott
33ff7ee960 python3Packages.tensorflow: 2.8.1 -> 2.8.4 2022-11-22 00:49:18 +00:00
github-actions[bot]
409dac7694 Merge staging-next-22.05 into staging-22.05 2022-11-22 00:17:36 +00:00
github-actions[bot]
891ea11465 Merge release-22.05 into staging-next-22.05 2022-11-22 00:17:05 +00:00
zowoq
f3e5ad171c go_1_19: init at 1.19
(cherry picked from commit 32f980605e)
2022-11-22 11:13:10 +11:00
Maximilian Bosch
41001c708d Merge pull request #191704 from NixOS/backport-190121-to-release-22.05
[Backport release-22.05] mautrix-signal: `--prefix` instead of `--set` PATH
2022-11-22 00:31:35 +01:00
Maximilian Bosch
3028b35b7c Merge pull request #202259 from NixOS/backport-202045-to-release-22.05
[Backport release-22.05] wiki-js: 2.5.291 -> 2.5.292
2022-11-22 00:06:19 +01:00
Maximilian Bosch
1651d9ac3a Merge pull request #202255 from NixOS/backport-201483-to-release-22.05
[Backport release-22.05] mautrix-whatsapp: 0.7.1 -> 0.7.2
2022-11-21 23:53:16 +01:00
R. Ryantm
ca076fbc8c wiki-js: 2.5.291 -> 2.5.292
(cherry picked from commit 69dd2ae6fa)
2022-11-21 22:49:04 +00:00
Luflosi
c8ec11e07e mautrix-whatsapp: 0.7.1 -> 0.7.2
https://github.com/mautrix/whatsapp/releases/tag/v0.7.2
(cherry picked from commit ed0a8c9553)
2022-11-21 22:30:29 +00:00
Janne Heß
5652d8a32e Merge pull request #202202 from NixOS/backport-202054-to-release-22.05
[Backport release-22.05] nixos/tests/acme/server: regenerate certs
2022-11-21 18:57:30 +01:00
ajs124
6449f9d13a nixos/tests/acme/server: regenerate certs
expired today

(cherry picked from commit 626e8b67fa)
2022-11-21 15:31:56 +00:00
Izorkin
16924866ff nixos/mastodon: fix emoji import
(cherry picked from commit fc30443c06eb79bd19399c1a0491631310cde38a)
2022-11-21 10:49:23 +00:00
github-actions[bot]
6e26175406 Merge staging-next-22.05 into staging-22.05 2022-11-21 00:16:23 +00:00
github-actions[bot]
c5df4c9876 Merge release-22.05 into staging-next-22.05 2022-11-21 00:15:40 +00:00
Jörg Thalheim
cf63ade6f7 Merge pull request #202065 from lheckemann/backport-freerdp
Backport freerdp
2022-11-20 23:44:18 +01:00
Robert Scott
4f441f3d03 python3Packages.pillow: add patch for CVE-2022-45198, test for CVE-2022-45199
resurrect mechanism from 20.09 (17a715465b)
to fetch binary parts of patches needed for tests.
2022-11-20 17:33:09 +00:00
R. Ryantm
dacbf4ce79 freerdp: 2.8.1 -> 2.9.0
(cherry picked from commit c2e17b7e5e)
2022-11-20 17:29:07 +01:00
R. Ryantm
c9ede65639 freerdpUnstable: 2.8.0 -> 2.8.1
(cherry picked from commit fa90ccd7de)
2022-11-20 17:29:06 +01:00
R. Ryantm
3e0b3d21a3 freerdp: 2.7.0 -> 2.8.0
(cherry picked from commit 053fb00690)
2022-11-20 17:28:50 +01:00
Vladimír Čunát
f8b062bc4f Merge branch 'staging-22.05' into staging-next-22.05 2022-11-20 09:41:08 +01:00
Martin Weinelt
75ce3d93c3 python3Packages.pytz-deprecation-shim: Disable tests
Tests are flaky and upstream doesn't care, and neither do we.

(cherry picked from commit 9b11f79c37)
The package is a frequent pain on mass rebuilds, so it's worth picking.
2022-11-20 09:17:45 +01:00
Nicolas Benes
d8e7655a19 cups-kyocera: fix source URL
(cherry picked from commit 79059c9505)
2022-11-20 06:22:54 +00:00
Martin Weinelt
b68a6a27ad Merge pull request #201777 from NixOS/backport-201762-to-release-22.05 2022-11-20 02:44:28 +01:00
Robert Scott
ef11394219 fluentd: add patch for CVE-2022-39379 2022-11-19 00:29:37 +00:00
github-actions[bot]
71173e3ef3 Merge staging-next-22.05 into staging-22.05 2022-11-19 00:15:51 +00:00
github-actions[bot]
8560a6b5b5 Merge release-22.05 into staging-next-22.05 2022-11-19 00:15:21 +00:00
Martin Weinelt
cff261c923 thunderbird-bin-unwrapped: 102.4.1 -> 102.5.0
https://www.thunderbird.net/en-US/thunderbird/102.5.0/releasenotes/
https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird102.5

Fixes: CVE-2022-45403, CVE-2022-45404, CVE-2022-45405, CVE-2022-45406,
       CVE-2022-45408, CVE-2022-45409, CVE-2022-45410, CVE-2022-45411,
       CVE-2022-45412, CVE-2022-45416, CVE-2022-45418, CVE-2022-45420,
       CVE-2022-45421
(cherry picked from commit 1afe1b2b00)
2022-11-18 15:16:57 +00:00
Martin Weinelt
df6382e9bb thunderbird-unwrapped: 102.4.1 -> 102.5.0
https://www.thunderbird.net/en-US/thunderbird/102.5.0/releasenotes/
https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird102.5

Fixes: CVE-2022-45403, CVE-2022-45404, CVE-2022-45405, CVE-2022-45406,
       CVE-2022-45408, CVE-2022-45409, CVE-2022-45410, CVE-2022-45411,
       CVE-2022-45412, CVE-2022-45416, CVE-2022-45418, CVE-2022-45420,
       CVE-2022-45421
(cherry picked from commit 2018e786a3)
2022-11-18 15:16:57 +00:00
Mario Rodas
f42a45c015 Merge pull request #201621 from NixOS/backport-199127-to-release-22.05
[Backport release-22.05] freetube: 0.17.1 -> 0.18.0
2022-11-18 05:14:58 -05:00
Mario Rodas
0d432d2a2d Merge pull request #201157 from iFreilicht/backport-200716-to-release-22.05
Backport 22.05: tfsec: fix broken info links and version string
2022-11-18 03:22:10 -05:00
Mario Rodas
d82119ab7d Merge pull request #201471 from blitz/onedrive-update
[Backport release-22.05] onedrive: 2.4.17 -> 2.4.21
2022-11-18 03:21:21 -05:00
github-actions[bot]
7a39326b26 Merge staging-next-22.05 into staging-22.05 2022-11-18 00:17:03 +00:00
github-actions[bot]
7103287794 Merge release-22.05 into staging-next-22.05 2022-11-18 00:16:32 +00:00
Martin Weinelt
8cc081471e Merge pull request #201669 from NixOS/backport-201665-to-release-22.05 2022-11-17 21:57:34 +01:00
Vladimír Čunát
a5655955dd librewolf: drop upstreamed patch
This partially reverts commit 61598203a4.
After update to 107 the patch is already in the src.

(cherry picked from commit bcb0994006)
2022-11-17 19:47:51 +00:00
Maximilian Bosch
6d73a47410 Merge pull request #201608 from NixOS/backport-201559-to-release-22.05
[Backport release-22.05] linuxKernel.kernels: updates
2022-11-17 15:25:48 +01:00
Felix Uhl
21ad71c9d3 tfsec: fix broken info links and version string
Fixes #200710. The version string must be prefixed with a v, otherwise
links to information about the findings from tfsec will 404.

(cherry picked from commit c14697d803)
2022-11-17 14:34:57 +01:00
Bobby Rong
80664d4f55 Merge pull request #201466 from NixOS/backport-201449-to-release-22.05
[Backport release-22.05] signal-desktop: 5.63.0 -> 5.63.1
2022-11-17 20:21:11 +08:00
alyaeanyx
aabef0793c freetube: 0.17.1 -> 0.18.0
(cherry picked from commit 99e0091cae)
2022-11-17 12:05:55 +00:00
Bernardo Meurer
764718cd85 linux: 6.0.8 -> 6.0.9
(cherry picked from commit 4dabd9c39b)
2022-11-17 08:51:06 +00:00
Bernardo Meurer
4faa1fed99 linux: 5.15.78 -> 5.15.79
(cherry picked from commit 63adc7fafe)
2022-11-17 08:51:06 +00:00
Bernardo Meurer
9d89e24f76 linux: 5.10.154 -> 5.10.155
(cherry picked from commit bd9a5606b4)
2022-11-17 08:51:06 +00:00
github-actions[bot]
eec0f9397e Merge staging-next-22.05 into staging-22.05 2022-11-17 00:16:39 +00:00
github-actions[bot]
8851636e4a Merge release-22.05 into staging-next-22.05 2022-11-17 00:16:02 +00:00
Florian Klink
08fa9bfe6d Merge pull request #201546 from gdamjan/update-systemd
systemd: 250.7 -> 250.8
2022-11-16 22:03:25 +00:00
Дамјан Георгиевски
316bd1e9b8 systemd: 250.7 -> 250.8
no changelog, just a list of commits:
https://github.com/systemd/systemd-stable/compare/v250.7...v250.8
2022-11-16 21:11:36 +01:00
Kerstin Humm
6474d93e00 mastodon: 3.5.3 -> 3.5.5 2022-11-16 11:41:31 +01:00
Filippo Berto
b80171c8e3 onedrive: 2.4.20 -> 2.4.21
(cherry picked from commit ec70a388c5)
2022-11-16 09:55:47 +01:00
R. Ryantm
02ac70b439 onedrive: 2.4.20 -> 2.4.21
(cherry picked from commit 177911fa86)
2022-11-16 09:55:41 +01:00
Ryan Horiguchi
f4a56b6dd8 onedrive: 2.4.19 -> 2.14.20
(cherry picked from commit 3934afb8b1)
2022-11-16 09:55:34 +01:00
Ryan Horiguchi
53e027946e onedrive: 2.4.17 -> 2.14.19
(cherry picked from commit a6ed92b044)
2022-11-16 09:55:27 +01:00
Eduardo Quiros
54f129c408 signal-desktop: 5.63.0 -> 5.63.1
(cherry picked from commit 29dd883f5d)
2022-11-16 08:43:44 +00:00
Bobby Rong
ce5e927055 Merge pull request #201447 from bobby285271/xfce
[22.05] xfce.xfce4-settings: 4.16.2 -> 4.16.5
2022-11-16 13:26:36 +08:00
José Romildo
81161679cc xfce.xfce4-settings: 4.16.4 -> 4.16.5
(cherry picked from commit f478baba65)
2022-11-16 12:40:03 +08:00
José Romildo
cebef9abe8 xfce.xfce4-settings: 4.16.3 -> 4.16.4
(cherry picked from commit 5f6c4fc156)
2022-11-16 12:38:58 +08:00
José Romildo
da67f4501b xfce.xfce4-settings: 4.16.2 -> 4.16.3
(cherry picked from commit 87c1d847d2)
2022-11-16 12:38:49 +08:00
github-actions[bot]
dac95fb64a Merge staging-next-22.05 into staging-22.05 2022-11-16 00:16:25 +00:00
github-actions[bot]
5659d34338 Merge release-22.05 into staging-next-22.05 2022-11-16 00:15:49 +00:00
Martin Weinelt
06f69949ee Merge pull request #201360 from squalus/librewolf-2205 2022-11-16 00:18:46 +01:00
Vladimír Čunát
814f8f3363 Merge #200361: staging-next-22.05 - iteration 14
...into release-22.05
2022-11-15 21:13:44 +01:00
squalus
a73bdcda29 librewolf: 106.0.3-1 -> 107.0-1
(cherry picked from commit 9a2f7b878c)
2022-11-15 11:23:59 -08:00
Robert Scott
02ac89b8e8 Merge pull request #201244 from risicle/ris-nomad-1.2.14-1.3.7-r22.05
[22.05] nomad_1_3: 1.3.1 -> 1.3.7, nomad_1_2: 1.2.8 -> 1.2.14
2022-11-15 19:19:58 +00:00
Mauricio Collares
bc7ab5c20e Merge pull request #191348 from collares/sage-bigints
[staging-next-22.05] sage: override python limit on int<->str conversions
2022-11-15 16:17:11 -03:00
Martin Weinelt
9fa4dba86d Merge pull request #201301 from mweinelt/22.05/firefox-107 2022-11-15 19:30:00 +01:00
Mauricio Collares
551a4ab37c sage: override python limit on int<->str conversions 2022-11-15 15:29:10 -03:00
Jonas Heinrich
d6a2830661 python310Packages.howdoi: disable failing test
(cherry picked from commit c0c767ee26)
2022-11-15 19:00:32 +01:00
Maximilian Bosch
778369ef9d privacyidea: fix build
Just a small test error, workaround applied from upstream/master.

(cherry picked from commit 1c7728df2a)
https://hydra.nixos.org/build/198491099
2022-11-15 18:59:03 +01:00
figsoda
2b37d567bb Merge pull request #201341 from NixOS/backport-201337-to-release-22.05
[Backport release-22.05] protonvpn-gui: add meta.mainProgram
2022-11-15 12:03:15 -05:00
wyndon
17d7640fc6 protonvpn-gui: add meta.mainProgram
(cherry picked from commit 845038dc31)
2022-11-15 16:45:48 +00:00
Martin Weinelt
90ac6ad7d6 Merge pull request #201258 from NixOS/backport-201252-to-release-22.05 2022-11-15 13:25:07 +01:00
Vladimír Čunát
c75a869832 Merge branch 'release-22.05' into staging-next-22.05 2022-11-15 12:54:34 +01:00
Jonas Heinrich
0c63ae8b3e python3*Packages.xdis: Fix build
(cherry picked from commit fc6b3c45d5)
But vcunat added more versions, even some future ones.
2022-11-15 12:52:34 +01:00
Martin Weinelt
ffe6fbbf64 python3Packages.amazon-ion: 0.9.2 -> 0.9.3
(cherry picked from commit bfb51b91f1)

The .2 and .3 update fix recent regression during build (tests),
and the announcements for seem pretty non-breaking:
https://github.com/amzn/ion-python/releases
2022-11-15 12:34:27 +01:00
Vladimír Čunát
1cf911d88e Merge #199833: jami-*: backport pjsip CVE fix for jami
...into release-22.05
2022-11-15 12:25:30 +01:00
Martin Weinelt
e985822e77 python3Packages.amazon-ion: 0.9.1 -> 0.9.2
(cherry picked from commit fc76fdd0f3)
2022-11-15 12:14:48 +01:00
Martin Weinelt
4707b6abbd firefox-esr-102-unwrapped: 102.4.0esr -> 102.5.0esr
https://www.mozilla.org/en-US/firefox/102.5.0/releasenotes/
(cherry picked from commit 22dafab650)
2022-11-15 10:44:53 +01:00
Martin Weinelt
14a3d53e86 firefox-bin-unwrapped: 106.0.5 -> 107.0
https://www.mozilla.org/en-US/firefox/107.0/releasenotes/
(cherry picked from commit 28b268d34b)
2022-11-15 10:27:04 +01:00
Martin Weinelt
4c6fbb4fbe firefox{,-bin}, thunderbird{,-bin}: Set meta.changelog
(cherry picked from commit 8ec89ef1b5)
2022-11-15 10:27:00 +01:00
R. Ryantm
279916cb2c firefox-unwrapped: 106.0.5 -> 107.0
https://www.mozilla.org/en-US/firefox/107.0/releasenotes/
(cherry picked from commit f3a8bb1ec8)
2022-11-15 10:26:56 +01:00
Robert Scott
30ebc6e348 python3Packages.twisted: add some key reverse dependencies to passthru.tests
(cherry picked from commit 06737d2879)
2022-11-15 07:47:06 +01:00
github-actions[bot]
f0a846bae0 Merge staging-next-22.05 into staging-22.05 2022-11-15 00:16:16 +00:00
github-actions[bot]
c3b4013ea3 Merge release-22.05 into staging-next-22.05 2022-11-15 00:15:41 +00:00
Martin Weinelt
40c75b3424 python3Packages.slixmpp: 1.8.2 -> 1.8.3
Slixmpp versions before 1.8.3 would not validate a certificate hostname
due to a very relaxed SSL context, that did not validate certificates at
all.

Fixes: CVE-2022-45197
(cherry picked from commit 775b15cabb)
2022-11-14 23:03:34 +00:00
Martin Weinelt
b078e560c0 python3Packages.twisted: Resolve host header injection vulnerability
https://github.com/advisories/GHSA-vg46-2rrj-3647

Fixes: CVE-2022-39348
2022-11-15 00:00:29 +01:00
techknowlogick
fc5e1f8193 nomad_1_3: 1.3.6 -> 1.3.7
(cherry picked from commit da75f81be8)
2022-11-14 21:28:11 +00:00
techknowlogick
a6bffb6e44 nomad_1_3: 1.3.5 -> 1.3.6
(cherry picked from commit 19b7aae977)
2022-11-14 21:27:10 +00:00
techknowlogick
7896a3d821 nomad_1_3: 1.3.4 -> 1.3.5
(cherry picked from commit f10333f64b)
2022-11-14 21:26:29 +00:00
zowoq
1c36b5afad nomad_1_3: 1.3.3 -> 1.3.4
https://github.com/hashicorp/nomad/releases/tag/v1.3.4

(cherry picked from commit b483c822f8,
which also bumped to go 1.19, but we don't have that so left
at 1.18)
2022-11-14 21:25:33 +00:00
Astro
a321338d2a nomad_1_3: 1.3.2 -> 1.3.3
(cherry picked from commit 07730a7b49)
2022-11-14 21:22:25 +00:00
Pavol Rusnak
16f4e04658 Merge pull request #201234 from NixOS/backport-201221-to-release-22.05
[Backport release-22.05] tor: 0.4.7.10 -> 0.4.7.11
2022-11-14 22:00:37 +01:00
Pavol Rusnak
08c2dd25fe tor: 0.4.7.10 -> 0.4.7.11
(cherry picked from commit 7c3fb5774e)
2022-11-14 20:29:44 +00:00
techknowlogick
ef74f0d471 nomad_1_3: 1.3.1 -> 1.3.2
(cherry picked from commit d39b1faa01)
2022-11-14 20:09:20 +00:00
techknowlogick
ee6d417f75 nomad_1_2: 1.2.13 -> 1.2.14
(cherry picked from commit ee5d39648e)
2022-11-14 19:58:47 +00:00
techknowlogick
542f79b8c9 nomad_1_2: 1.2.12 -> 1.2.13
(cherry picked from commit 53518d5d5e)
2022-11-14 19:57:38 +00:00
techknowlogick
7a8fcb2254 nomad_1_2: 1.2.11 -> 1.2.12
(cherry picked from commit 55d613752a)
2022-11-14 19:56:36 +00:00
Robert Scott
1ebdc20232 nomad_1_2: 1.2.9 -> 1.2.11
https://github.com/hashicorp/nomad/releases/tag/v1.2.10
https://github.com/hashicorp/nomad/releases/tag/v1.2.11

(cherry picked from commit 7374e6644a,
which bumped to go 1.19, but we don't have that so have bumped to
1.18)
2022-11-14 19:55:12 +00:00
techknowlogick
06eede8542 nomad_1_2: 1.2.8 -> 1.2.9
(cherry picked from commit 8da1e102f6)
2022-11-14 19:39:14 +00:00
Alexander Bantyev
7fdf329049 Merge pull request #196643 from NixOS/backport-196626-to-release-22.05
[Backport release-22.05] pleroma: fix captcha
2022-11-14 22:30:47 +04:00
Bjørn Forsman
29d9eb59c0 joplin-desktop: make Icon= more bitrot resistant
Replace Icon=<nix_store_path_to_icon> with Icon=<icon_name> so that the
desktop file doesn't break when placed in ~/.config/autostart and after
a system upgrade + garbage collect cycle.

(cherry picked from commit 3aeb452f3f2f590944a7281519daa9e223cdd7a2)
2022-11-14 14:12:57 +01:00
Maximilian Bosch
1a5f7e6a83 Merge pull request #201066 from risicle/ris-grafana-8.5.15-r22.05
[22.05] grafana: 8.5.14 -> 8.5.15
2022-11-14 10:59:48 +01:00
github-actions[bot]
ddbaf02f0d Merge staging-next-22.05 into staging-22.05 2022-11-14 00:16:19 +00:00
github-actions[bot]
6a37063823 Merge release-22.05 into staging-next-22.05 2022-11-14 00:15:37 +00:00
Robert Scott
505cc35f64 grafana: 8.5.14 -> 8.5.15 2022-11-13 20:08:30 +00:00
Mario Rodas
664b342ce0 Merge pull request #200925 from NixOS/backport-178685-to-release-22.05
[Backport release-22.05] teamspeak_server: 3.13.6 -> 3.13.7
2022-11-13 07:52:53 -05:00
Martin Weinelt
98714dc3b2 Merge pull request #198092 from rhendric/backport-196724-to-release-22.05 2022-11-13 11:54:59 +01:00
Martin Weinelt
315dfb7b4c mitmproxy: disable failing test
(cherry picked from commit 79e7f22154)
2022-11-13 10:00:17 +01:00
Vladimír Čunát
836f4c9ec2 pubs: drop the last test
Order of authors within the single entry differs; not sure why
and not sure why this isn't an issue on nixpkgs master.
Either way, at a quick glance it doesn't seem relevant to the test.
2022-11-13 09:56:49 +01:00
Robert Schütz
7275aa928c pubs: fix tests
(cherry picked from commit 8c036c75ca)
2022-11-13 09:50:06 +01:00
Theodore Ni
ca43481f23 python310Packages.loguru: fix failing tests
Pulls in a patch from upstream that fixes test failing on Python 3.10.6
and greater.

(cherry picked from commit b518a7d877)
We now got the issue, probably with backporting minor python3 updates:
https://hydra.nixos.org/build/198002739
2022-11-13 09:43:44 +01:00
R. Ryantm
b28e8482f2 firefox-beta-bin-unwrapped: 107.0b5 -> 107.0b9
(cherry picked from commit eb4bcdcc69)
2022-11-12 23:42:03 -05:00
R. Ryantm
88a0ef10a5 firefox-beta-bin-unwrapped: 106.0b9 -> 107.0b5
(cherry picked from commit a4c60438d3)
2022-11-12 23:42:03 -05:00
R. Ryantm
29b3de0188 firefox-beta-bin-unwrapped: 106.0b7 -> 106.0b9
(cherry picked from commit a2bf9b4cf0)
2022-11-12 23:42:03 -05:00
R. Ryantm
8221e6b988 firefox-beta-bin-unwrapped: 106.0b5 -> 106.0b7
(cherry picked from commit fad386bad1)
2022-11-12 23:42:03 -05:00
R. Ryantm
4afe888688 firefox-beta-bin-unwrapped: 106.0b2 -> 106.0b5
(cherry picked from commit 3d215f75b8)
2022-11-12 23:42:03 -05:00
Mario Rodas
eac99848df Merge pull request #200945 from Ma27/backport-redis-cve-2022-3647
[22.05] redis: patch for CVE-2022-3647
2022-11-12 21:39:04 -05:00
github-actions[bot]
92cb369afd Merge staging-next-22.05 into staging-22.05 2022-11-13 00:15:54 +00:00
github-actions[bot]
06a7c271c0 Merge release-22.05 into staging-next-22.05 2022-11-13 00:15:18 +00:00
Maximilian Bosch
6c302ef625 redis: patch for CVE-2022-3647
https://nvd.nist.gov/vuln/detail/CVE-2022-3647
(cherry picked from commit c1135fc57d)
2022-11-12 22:45:17 +01:00
Martin Weinelt
7f3180ec16 Merge pull request #200882 from risicle/ris-libtiff-cves-202210-r22.05 2022-11-12 20:41:27 +01:00
Sandro
c5091eec68 Merge pull request #200469 from xentec/backport-22.05-hedgedoc
[22.05] hedgedoc: 1.9.4 -> 1.9.6
2022-11-12 20:36:05 +01:00
Johannes Schleifenbaum
e89574d29c teamspeak_server: 3.13.6 -> 3.13.7
(cherry picked from commit dda1d60ac6)
2022-11-12 19:14:24 +00:00
R. Ryantm
dbe42aa01f firefox-devedition-bin-unwrapped: 107.0b5 -> 107.0b9
(cherry picked from commit ff51d7e4f4)
2022-11-12 13:49:36 -05:00
Robert Scott
d27b1b9e87 libtiff: add patches for CVE-2022-3626, CVE-2022-3627, CVE-2022-3597, CVE-2022-3598 & CVE-2022-3570 2022-11-12 16:22:22 +00:00
Martin Weinelt
208943d643 python3Packages.pyfakefs: 4.6.2 -> 4.6.3
(cherry picked from commit b226724c85)

The changelog since 4.5.6 doesn't sound risky to me:
https://github.com/pytest-dev/pyfakefs/blob/v4.6.3/CHANGES.md
and this fixes its tests which regressed probably with
minor python update.
2022-11-12 08:36:49 +01:00
Martin Weinelt
d7e9a62e45 python3Packages.pyfakefs: 4.5.6 -> 4.6.2
(cherry picked from commit baa63060b3)
2022-11-12 08:33:32 +01:00
Mario Rodas
386382253e Merge pull request #200702 from NixOS/backport-200698-to-release-22.05
[Backport release-22.05] yt-dlp: 2022.10.4 -> 2022.11.11
2022-11-11 20:47:16 -05:00
github-actions[bot]
f72d2125dc Merge staging-next-22.05 into staging-22.05 2022-11-12 00:16:50 +00:00
github-actions[bot]
72d7f3a56c Merge release-22.05 into staging-next-22.05 2022-11-12 00:16:18 +00:00
Martin Weinelt
b8af0ecc31 Merge pull request #198164 from NixOS/backport-197806-to-staging-22.05 2022-11-11 23:57:26 +01:00
Florian Klink
2cd47b0444 Merge pull request #200383 from gdamjan/update-systemd
[staging-22.05] systemd: 250.4 -> 250.7
2022-11-11 19:27:04 +00:00
Pavol Rusnak
cb8d3fe07d Merge pull request #200731 from NixOS/backport-200728-to-release-22.05 2022-11-11 18:55:30 +01:00
Pavol Rusnak
011eadcdfa trezor-suite: fix build
(cherry picked from commit 4035b2a9ac)
2022-11-11 17:46:41 +00:00
Mario Rodas
3ea15be37f yt-dlp: 2022.10.4 -> 2022.11.11
https://github.com/yt-dlp/yt-dlp/releases/tag/2022.11.11
(cherry picked from commit c74255c7bf)
2022-11-11 14:10:21 +00:00
Maximilian Bosch
41b8fae7ac Merge pull request #200700 from NixOS/backport-200695-to-release-22.05
[Backport release-22.05] jhead: patches for CVE-2022-41751
2022-11-11 14:51:25 +01:00
Maximilian Bosch
60d8e20c31 Merge pull request #200694 from NixOS/backport-200589-to-release-22.05
[Backport release-22.05] linuxKernel.kernels: updates
2022-11-11 14:50:54 +01:00
Maximilian Bosch
69cad8dcbd jhead: patches for CVE-2022-41751
See https://nvd.nist.gov/vuln/detail/CVE-2022-41751
Also relevant: https://github.com/Matthias-Wandel/jhead/issues/60

(cherry picked from commit 709f4ce70cc1fe4401adcaaf8ed4833c86779386)
2022-11-11 13:25:28 +00:00
Maximilian Bosch
b5b1210448 linux: 4.9.332 -> 4.9.333 2022-11-11 14:23:58 +01:00
Bernardo Meurer
af31703b91 linux/hardened/patches/6.0: 6.0.7-hardened1 -> 6.0.8-hardened1
(cherry picked from commit d2eb86ec6a)
2022-11-11 12:44:11 +00:00
Bernardo Meurer
bd1928ff38 linux/hardened/patches/5.4: 5.4.223-hardened1 -> 5.4.224-hardened1
(cherry picked from commit 21c40dd71f)
2022-11-11 12:44:11 +00:00
Bernardo Meurer
b03e0716de linux/hardened/patches/5.15: 5.15.77-hardened1 -> 5.15.78-hardened1
(cherry picked from commit 31c39d33a9)
2022-11-11 12:44:11 +00:00
Bernardo Meurer
68d4560e00 linux/hardened/patches/5.10: 5.10.153-hardened1 -> 5.10.154-hardened1
(cherry picked from commit 6578c8d52e)
2022-11-11 12:44:11 +00:00
Bernardo Meurer
e70476e4ea linux/hardened/patches/4.19: 4.19.264-hardened1 -> 4.19.265-hardened1
(cherry picked from commit cf1bb7a52e)
2022-11-11 12:44:11 +00:00
Bernardo Meurer
a0817e577f linux/hardened/patches/4.14: 4.14.298-hardened1 -> 4.14.299-hardened1
(cherry picked from commit fb82780f97)
2022-11-11 12:44:11 +00:00
Bernardo Meurer
303a44e871 linux-rt_5_4: 5.4.209-rt77 -> 5.4.221-rt79
(cherry picked from commit f9286fe0e9)
2022-11-11 12:44:11 +00:00
Bernardo Meurer
3ca598303a linux-rt_5_10: 5.10.152-rt75 -> 5.10.153-rt76
(cherry picked from commit 79c0a328d1)
2022-11-11 12:44:11 +00:00
Bernardo Meurer
7d0f96263d linux: 6.0.7 -> 6.0.8
(cherry picked from commit e3f6163c00)
2022-11-11 12:44:11 +00:00
Bernardo Meurer
24bd2f2158 linux: 5.4.223 -> 5.4.224
(cherry picked from commit 8a9366d61c)
2022-11-11 12:44:11 +00:00
Bernardo Meurer
a5c3d07348 linux: 5.15.77 -> 5.15.78
(cherry picked from commit 164aecb6ca)
2022-11-11 12:44:11 +00:00
Bernardo Meurer
0864f48361 linux: 5.10.153 -> 5.10.154
(cherry picked from commit c22e3c9840)
2022-11-11 12:44:10 +00:00
Bernardo Meurer
5b36193567 linux: 4.19.264 -> 4.19.265
(cherry picked from commit fa300b747e)
2022-11-11 12:44:10 +00:00
Bernardo Meurer
4a07f1102c linux: 4.14.298 -> 4.14.299
(cherry picked from commit 9553d38c5e)
2022-11-11 12:44:10 +00:00
Maximilian Bosch
37e9b04dd2 Merge pull request #200533 from Ma27/backport-element
[22.05] element-{web,desktop}: 1.11.13 -> 1.11.14
2022-11-11 11:47:38 +01:00
Martin Weinelt
42ad3b9bdf Merge pull request #200630 from helsinki-systems/upd/samba4-22.05 2022-11-11 03:27:26 +01:00
ajs124
e69865e9e5 samba4: 4.15.9 -> 4.15.11
fixes CVE-2022-3592 and CVE-2022-3437
2022-11-11 03:05:29 +01:00
github-actions[bot]
597b1b3c9b Merge staging-next-22.05 into staging-22.05 2022-11-11 00:18:05 +00:00
github-actions[bot]
5ab90f7710 Merge release-22.05 into staging-next-22.05 2022-11-11 00:17:32 +00:00
Michael Weiss
c859830e4c Merge pull request #200541 from NixOS/backport-200445-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 107.0.5304.88 -> 107.0.5304.110
2022-11-10 23:24:00 +01:00
Michael Weiss
bd790b39aa Merge pull request #200540 from NixOS/backport-200444-to-release-22.05
[Backport release-22.05] chromium: 107.0.5304.87 -> 107.0.5304.110
2022-11-10 23:23:28 +01:00
Bjørn Forsman
58f933e321 nextcloud-client: 3.6.1 -> 3.6.2
(cherry picked from commit aba5969b74)
2022-11-10 20:23:55 +01:00
ajs124
d283698611 Merge pull request #200309 from helsinki-systems/upd/varnish-2205
[22.05] varnish: updates
2022-11-10 20:22:48 +01:00
Anderson Torres
25d4fa1831 Merge pull request #200562 from NixOS/backport-200267-to-release-22.05
[Backport release-22.05] palemoon: 31.3.0.1 -> 31.3.1
2022-11-10 16:13:23 -03:00
OPNA2608
482668c860 palemoon: 31.3.0.1 -> 31.3.1
(cherry picked from commit 4854f55666)
2022-11-10 17:35:01 +00:00
Michael Weiss
cc6ff6a144 ungoogled-chromium: 107.0.5304.88 -> 107.0.5304.110
(cherry picked from commit 6477a3bdc3)
2022-11-10 14:31:20 +00:00
Michael Weiss
67325df37d chromium: 107.0.5304.87 -> 107.0.5304.110
https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop.html

This update includes 10 security fixes.

CVEs:
CVE-2022-3885 CVE-2022-3886 CVE-2022-3887 CVE-2022-3888 CVE-2022-3889
CVE-2022-3890

(cherry picked from commit cc136d85d9)
2022-11-10 14:28:32 +00:00
Maximilian Bosch
0b745d8350 element-{web,desktop}: 1.11.13 -> 1.11.14
ChangeLog web: https://github.com/vector-im/element-web/releases/tag/v1.11.14
ChangeLog desktop: https://github.com/vector-im/element-desktop/releases/tag/v1.11.14

Backport of 1eb380d489 (#200301).
2022-11-10 14:35:38 +01:00
Maximilian Bosch
2e68d26162 Merge pull request #200376 from NixOS/backport-200347-to-release-22.05
[Backport release-22.05] wiki-js: 2.5.290 -> 2.5.291
2022-11-10 08:52:12 +01:00
Pol Dellaiera
b90e1fd526 hedgedoc: 1.9.5 -> 1.9.6
(cherry picked from commit e8805267fe)
2022-11-10 04:15:35 +01:00
Pol Dellaiera
4cb45dd7e5 hedgedoc: 1.9.4 -> 1.9.5
(cherry picked from commit 31b3bf55fc)
2022-11-10 04:15:27 +01:00
github-actions[bot]
20896f29fb Merge staging-next-22.05 into staging-22.05 2022-11-10 00:17:30 +00:00
github-actions[bot]
72e3c25522 Merge release-22.05 into staging-next-22.05 2022-11-10 00:16:59 +00:00
John Ericson
d0e1dd63a4 Merge pull request #200432 from NixOS/backport-200431-to-release-22.05
[Backport release-22.05] build-support/rust/lib: Add `toTargetFamily`
2022-11-09 16:58:26 -05:00
John Ericson
0c47c96d1c build-support/rust/lib: Add toTargetFamily
Taken from https://github.com/kolloch/crate2nix/pull/255/files, it
belongs in Nixpkgs not crate2nix.

I have been using that P.R. for a few months without incident.

(cherry picked from commit e94d54dd86)
2022-11-09 21:24:04 +00:00
Vladimír Čunát
172ea8bce9 python3Packages.ipython: patch test after python update
(cherry picked from commit fad9786825)
2022-11-09 19:42:40 +01:00
Martin Weinelt
2fae15a0a6 python3Packages.astor: disabled failing test
and prune the list of tests from working ones.

(cherry picked from commit 6a851472f2)
2022-11-09 19:30:28 +01:00
Anderson Torres
fa84271556 Merge pull request #200393 from NixOS/backport-200365-to-release-22.05
[Backport release-22.05] byacc: 20220128 -> 20221106
2022-11-09 15:00:43 -03:00
AndersonTorres
1b282f6252 byacc: 20220128 -> 20221106
Also, add AndersonTorres as maintainer.

(cherry picked from commit 684b0f278a)
2022-11-09 14:58:28 +00:00
Дамјан Георгиевски
71efd09c07 systemd: 250.4 -> 250.7
removed the pull/22174.patch`, it has been backported in v250,
see https://github.com/systemd/systemd-stable/pull/195

src/test/test-load-fragment.c got some `/bin/echo` invocations in
9727b9ee7b
2022-11-09 14:58:26 +01:00
Maximilian Bosch
a2396bec08 wiki-js: 2.5.290 -> 2.5.291
ChangeLog: https://github.com/requarks/wiki/releases/tag/v2.5.291
(cherry picked from commit 28691b90fb)
2022-11-09 12:43:27 +00:00
Maximilian Bosch
2d4a8b20b1 Merge pull request #200246 from NixOS/backport-200211-to-release-22.05
[Backport release-22.05] matrix-synapse: 1.70.1 -> 1.71.0
2022-11-09 13:38:15 +01:00
linsui
eb8acbbcf9 [22.05] Backport pjsip CVE fix for jami 2022-11-09 18:41:31 +08:00
Vladimír Čunát
2ba8cf13df Merge branch 'staging-22.05' into staging-next-22.05 2022-11-09 11:17:19 +01:00
Vladimír Čunát
76b45a1bf3 Merge #199790: python3Packages.jupyter_core: patch CVE-2022-39286
...into staging-22.05
2022-11-09 11:15:58 +01:00
Vladimír Čunát
155629501c Merge #200359: python39: 3.9.13 -> 3.9.15
...into staging-22.05
2022-11-09 11:10:27 +01:00
Martin Weinelt
5939449db7 python39: 3.9.14 -> 3.9.15
http://docs.python.org/release/3.9.15/whatsnew/changelog.html
(cherry picked from commit 997b80d632)
2022-11-09 11:01:37 +01:00
Martin Weinelt
c19d9d996f python39: 3.9.13 -> 3.9.14
https://docs.python.org/3.9/whatsnew/changelog.html#python-3-9-14-final
https://pythoninsider.blogspot.com/2022/09/python-releases-3107-3914-3814-and-3714.html

Fixes: CVE-2020-10735
(cherry picked from commit 34182bc865)
2022-11-09 11:01:32 +01:00
Vladimír Čunát
92c74cd22c Merge #198246: python3X: backport all old releases
...into staging-22.05
2022-11-09 10:56:20 +01:00
Vladimír Čunát
c0ca8d71fa Merge #200311: python310Packages.mpmath: fix CVE-2021-29063
...into staging-22.05
2022-11-09 10:51:36 +01:00
Vladimír Čunát
fe08792c9c Merge branch 'release-22.05' into staging-22.05 2022-11-09 10:51:22 +01:00
Vladimír Čunát
42e11fb96e Merge #194085: nixos/fail2ban: improve module documentation
...into release-22.05
2022-11-09 10:44:04 +01:00
Vladimír Čunát
25587d4684 Merge #198154: pjsip: add patches for CVE-2022-39269 & CVE-2022-39244
...into release-22.05
2022-11-09 10:35:22 +01:00
Vladimír Čunát
dd2f51d121 Merge #199715: expat: 2.4.9 -> 2.5.0
...into staging-22.05
2022-11-09 10:26:17 +01:00
Vladimír Čunát
75753c9d3d Merge #198698: tzdata: 2022e -> 2022f
...into staging-22.05
2022-11-09 10:24:23 +01:00
Theodore Ni
0515dbd07d tzdata: fix build on darwin
Version 2022f doesn't build on Darwin because its detection of whether
getrandom is available doesn't work. This has been fixed upstream, and
we can pull in the patches.

(cherry picked from commit dd3624849e)
2022-11-09 07:55:12 +01:00
Aaron Andersen
211cdffac5 Merge pull request #200280 from veehaitch/github-runner-22.05-aanderse
github-runner: add `aanderse` as maintainer
2022-11-08 20:18:45 -05:00
Robert Schütz
c8ab7e5712 python310Packages.mpmath: fix CVE-2021-29063
(cherry picked from commit 7e5832d003)
2022-11-09 00:59:51 +00:00
ajs124
fbced147ed varnish71: 7.1.1 -> 7.1.2
https://github.com/varnishcache/varnish-cache/blob/7.1/doc/changes.rst#varnish-cache-712-2022-11-08
2022-11-09 01:43:53 +01:00
ajs124
617e6874bc varnish60: 6.0.10 -> 6.0.11
https://github.com/varnishcache/varnish-cache/blob/6.0/doc/changes.rst#varnish-cache-6011-2022-11-08
(cherry picked from commit f9c4148be7)
2022-11-09 01:42:36 +01:00
Aaron Andersen
4a80c4be8e Merge pull request #200283 from newAM/github-runner-22.05
[release-22.05] github-runner: 2.296.2 -> 2.299.1
2022-11-08 19:41:44 -05:00
github-actions[bot]
455d547698 Merge staging-next-22.05 into staging-22.05 2022-11-09 00:17:16 +00:00
github-actions[bot]
3c54fe0265 Merge release-22.05 into staging-next-22.05 2022-11-09 00:16:40 +00:00
Alex Martens
58a023bef7 github-runner: 2.296.2 -> 2.299.1 2022-11-08 14:23:08 -08:00
Vincent Haupert
a8f30b0cac github-runner: add aanderse as maintainer 2022-11-08 23:15:25 +01:00
Sumner Evans
c9e2d0af8d matrix-synapse: 1.70.1 -> 1.71.0
Signed-off-by: Sumner Evans <me@sumnerevans.com>
(cherry picked from commit ccd94ad132)
2022-11-08 19:42:42 +00:00
Kerstin
ececb1504b Merge pull request #200232 from NixOS/backport-200099-to-release-22.05
[Backport release-22.05] imagemagick: 7.1.0-51 -> 7.1.0-52
2022-11-08 20:06:06 +01:00
R. Ryantm
dcf4a244f0 imagemagick: 7.1.0-51 -> 7.1.0-52
(cherry picked from commit 55ba51375bf8a26304464126a1c406bd8ee04bb8)
2022-11-08 18:23:43 +00:00
R. Ryantm
4732f29ae5 imagemagick: 7.1.0-48 -> 7.1.0-51
(cherry picked from commit 4d9e748454)
2022-11-08 10:17:51 -08:00
Maximilian Bosch
df2bcbbd1c Merge pull request #199754 from Ma27/backport-5.19-removal
[22.05] linuxKernel.kernels.linux_5_19: drop
2022-11-08 16:39:28 +01:00
Vladimír Čunát
52c2134edf Merge #199676: pixman: patch CVE-2022-44638
...into staging-22.05
2022-11-08 11:36:51 +01:00
Martin Weinelt
67bcb74195 Merge pull request #200165 from NixOS/backport-200102-to-release-22.05 2022-11-08 09:38:08 +01:00
Martin Weinelt
89af1062fe buildMozillaMach: add curl into crashreporter rpath
Firefox has been crashy during the 106 cycle on my laptop, so I saw the
crashreporter more often than not. In the terminal spew I found

> Failed to open curl lib from binary, use libcurl.so instead

and the GUI told me submitting the report had failed. Not great if you
actually except to have your bugs fixed at some point.

(cherry picked from commit 6acfc788cc)
2022-11-08 08:22:38 +00:00
squalus
4686b37b67 librewolf: 106.0.1-1 -> 106.0.3-1
(cherry picked from commit f7ef72305d)
2022-11-07 23:05:31 -05:00
Robert Scott
85aef4bfef python3Packages.jupyter_core: add patch for CVE-2022-39286 2022-11-08 00:47:05 +00:00
Robert Scott
692acead1b python3Packages.nbconvert: add patch to fix tests against jupyter_core 4.11.2 2022-11-08 00:46:59 +00:00
github-actions[bot]
4d480e3b1e Merge staging-next-22.05 into staging-22.05 2022-11-08 00:18:08 +00:00
github-actions[bot]
e1c7990132 Merge release-22.05 into staging-next-22.05 2022-11-08 00:17:27 +00:00
Vladimír Čunát
8d467eecf4 Merge #199129: openssl_3: enable KTLS only on Linux
...into release-22.05
2022-11-07 19:12:07 +01:00
Anderson Torres
ebf65554b1 Merge pull request #198513 from raindev/backport-netatalk-segfault-fix
[22.05] netatalk: FreeBSD patchset 3.1.13_3, critical fix
2022-11-07 08:45:06 -03:00
Nicolas Benes
10d120b590 tor-browser-bundle-bin: 11.5.6 -> 11.5.7
(cherry picked from commit 337e89b7d4c843cb2928940bc3f38fb00b4e9164)
2022-11-07 10:53:58 +01:00
github-actions[bot]
e44085953f Merge staging-next-22.05 into staging-22.05 2022-11-07 00:16:47 +00:00
github-actions[bot]
0aa087c59b Merge release-22.05 into staging-next-22.05 2022-11-07 00:16:14 +00:00
Martin Weinelt
771e95dcf4 Merge pull request #199714 from maxeaubrey/22.05_webkitgtk_2.38.2 2022-11-06 22:52:46 +01:00
Jörg Thalheim
455fb17a15 Merge pull request #199877 from NixOS/backport-199770-to-release-22.05
[Backport release-22.05] nixos options markdown: fix html escaping
2022-11-06 21:39:42 +01:00
Domen Kožar
2e5980c63a nixos options markdown: fix html escaping
\<foo\> will often be displayed like \<foo>, for example by mkdocs.

I've tested a number of markdown renderers and they render html escape
sequences fine.

(cherry picked from commit e190302018)
2022-11-06 18:14:42 +00:00
R. Ryantm
92eb434a1e batik: 1.15 -> 1.16
(cherry picked from commit fc7a1f33c9)
2022-11-06 12:12:37 +00:00
R. Ryantm
67da1cea0d batik: 1.14 -> 1.15
(cherry picked from commit 0b0cef2915)
2022-11-06 12:12:01 +00:00
Maximilian Bosch
987a9764e3 Merge pull request #199697 from LeSuisse/wireshark-3.6.9-22.05
[22.05] wireshark: 3.6.5 -> 3.6.9
2022-11-06 11:33:42 +01:00
Maximilian Bosch
9a9cea1a8d Merge pull request #199717 from NixOS/backport-199009-to-staging-22.05
[Backport staging-22.05] openssl_1_1: 1.1.1q -> 1.1.1s
2022-11-06 11:31:27 +01:00
Maximilian Bosch
e62972371b Merge pull request #199748 from Ma27/backport-element
[22.05] element-{web,desktop}: 1.11.10 -> 1.11.13
2022-11-06 11:25:53 +01:00
Vladimír Čunát
45f1f5a856 Merge #199743: rrsync: change perl script to python script
...into release-22.05
2022-11-06 09:45:44 +01:00
Anderson Torres
5a24e144ff Merge pull request #199756 from NixOS/backport-199726-to-release-22.05
[Backport release-22.05] timg: apply patch for CVE-2022-43151
2022-11-05 21:47:13 -03:00
github-actions[bot]
4b074315f0 Merge staging-next-22.05 into staging-22.05 2022-11-06 00:18:10 +00:00
github-actions[bot]
b604ecf2b3 Merge release-22.05 into staging-next-22.05 2022-11-06 00:17:38 +00:00
Pavol Rusnak
baf5a515aa Merge pull request #199787 from NixOS/backport-199782-to-release-22.05
[Backport release-22.05] trezor-suite: 22.8.2 -> 22.10.3
2022-11-06 01:14:03 +01:00
Pavol Rusnak
f6733db5fd trezor-suite: 22.8.2 -> 22.10.3
(cherry picked from commit 836f31e104)
2022-11-06 00:13:39 +00:00
Maximilian Bosch
6ef69dc2c6 Merge pull request #197258 from NixOS/backport-197203-to-release-22.05
[Backport release-22.05] packer: 1.8.2 -> 1.8.3
2022-11-05 23:01:51 +01:00
Maximilian Bosch
f3e08c6059 Merge pull request #199389 from helsinki-systems/upd/php74
[22.05] php74: 7.4.32 -> 7.4.33
2022-11-05 23:01:10 +01:00
Maximilian Bosch
25d23d7100 Merge pull request #199502 from NixOS/backport-198781-to-release-22.05
[Backport release-22.05] strace: 5.19 -> 6.0
2022-11-05 23:00:49 +01:00
Mario Rodas
ae5b803af7 Merge pull request #199760 from NixOS/backport-199724-to-release-22.05
[Backport release-22.05] tomcat: 9.0.53 -> 9.0.68, 10.0.11 -> 10.0.27
2022-11-05 16:25:49 -05:00
Thomas Gerbet
a7cebceb95 tomcat: 9.0.53 -> 9.0.68, 10.0.11 -> 10.0.27
Fixes CVE-2021-42340, CVE-2021-43980, CVE-2022-23181, CVE-2022-29885, CVE-2022-34305 and CVE-2022-42252.

https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.68_(markt)
https://tomcat.apache.org/tomcat-10.0-doc/changelog.html#Tomcat_10.0.27_(markt)
(cherry picked from commit 7f29a5746a)
2022-11-05 20:15:49 +00:00
Thomas Gerbet
8619ea329f timg: apply patch for CVE-2022-43151
https://github.com/hzeller/timg/issues/92
(cherry picked from commit bbb8622275)
2022-11-05 19:51:25 +00:00
Bernardo Meurer
c15fe8cb3b linuxKernel.kernels.linux_5_19: drop
The 5.19.x series has reached EOL, and is no longer supported upstream.

(cherry picked from commit 8cc5d8e32a)
2022-11-05 20:43:57 +01:00
Maximilian Bosch
db4054fdba Merge pull request #199739 from NixOS/backport-199523-to-release-22.05
[Backport release-22.05] linuxKernel.kernels: updates
2022-11-05 20:32:51 +01:00
Maximilian Bosch
72e6057f34 Merge pull request #199740 from NixOS/backport-198132-to-release-22.05
[Backport release-22.05] privacyidea: 3.7.3 -> 3.7.4
2022-11-05 20:19:39 +01:00
Maximilian Bosch
42c2fc7f10 element-{web,desktop}: 1.11.10 -> 1.11.13
ChangeLogs:
* https://github.com/vector-im/element-web/releases/tag/v1.11.11
* https://github.com/vector-im/element-web/releases/tag/v1.11.12
* https://github.com/vector-im/element-web/releases/tag/v1.11.13

Porting #199745, #198146 to stable.
2022-11-05 20:12:35 +01:00
Further
24cff15316 rrsync: clean unused part
(cherry picked from commit c19c7d96c5)
2022-11-05 18:58:30 +00:00
Further
00d1455561 rrsync: fixed python3 and add braceexpand module
(cherry picked from commit 9d7d8c11eb)
2022-11-05 18:58:30 +00:00
Further
349cf2ea3a rrsync: change per script to python script
(cherry picked from commit a91cea12b1)
2022-11-05 18:58:30 +00:00
Mario Rodas
ab5be3536a Merge pull request #199588 from risicle/ris-libpulsar-2.9.3-r22.05
[22.05] libpulsar: 2.9.1 -> 2.9.3
2022-11-05 13:41:21 -05:00
Maximilian Bosch
5fc4b1b279 privacyidea: 3.7.3 -> 3.7.4
ChangeLog: https://github.com/privacyidea/privacyidea/releases/tag/v3.7.4
(cherry picked from commit f8fcc169f8)
2022-11-05 18:39:38 +00:00
Bernardo Meurer
efca25b437 linux/hardened/patches/6.0: 6.0.6-hardened1 -> 6.0.7-hardened1
(cherry picked from commit dab266f371)
2022-11-05 18:37:02 +00:00
Bernardo Meurer
70ad422953 linux/hardened/patches/5.4: 5.4.221-hardened1 -> 5.4.223-hardened1
(cherry picked from commit 451e251ea4)
2022-11-05 18:37:02 +00:00
Bernardo Meurer
7679d52436 linux/hardened/patches/5.15: 5.15.76-hardened1 -> 5.15.77-hardened1
(cherry picked from commit 525ee05190)
2022-11-05 18:37:01 +00:00
Bernardo Meurer
ca72758906 linux/hardened/patches/5.10: 5.10.152-hardened1 -> 5.10.153-hardened1
(cherry picked from commit 7791bbd54b)
2022-11-05 18:37:01 +00:00
Bernardo Meurer
34f9cd91fd linux/hardened/patches/4.19: 4.19.262-hardened1 -> 4.19.264-hardened1
(cherry picked from commit a2ddd1ac1a)
2022-11-05 18:37:01 +00:00
Bernardo Meurer
ce343ebdf2 linux/hardened/patches/4.14: 4.14.296-hardened1 -> 4.14.298-hardened1
(cherry picked from commit b674b426d4)
2022-11-05 18:37:01 +00:00
Bernardo Meurer
a6782cecf0 linux_latest-libre: 18950 -> 18978
(cherry picked from commit b43ea99326)
2022-11-05 18:37:01 +00:00
Bernardo Meurer
39b826d6cc linux: 6.0.6 -> 6.0.7
(cherry picked from commit 8bb699516f)
2022-11-05 18:37:01 +00:00
Bernardo Meurer
518471ca7d linux: 5.4.221 -> 5.4.223
(cherry picked from commit b44d44e951)
2022-11-05 18:37:01 +00:00
Bernardo Meurer
9324ef495b linux: 5.15.76 -> 5.15.77
(cherry picked from commit b0c196f148)
2022-11-05 18:37:01 +00:00
Bernardo Meurer
4ec8ea2f75 linux: 5.10.152 -> 5.10.153
(cherry picked from commit ff99944b11)
2022-11-05 18:37:01 +00:00
Bernardo Meurer
f9a99b3464 linux: 4.9.331 -> 4.9.332
(cherry picked from commit e328685098)
2022-11-05 18:37:01 +00:00
Bernardo Meurer
ea91f78de6 linux: 4.19.262 -> 4.19.264
(cherry picked from commit 267d467ecd)
2022-11-05 18:37:01 +00:00
Bernardo Meurer
1b213039d3 linux: 4.14.296 -> 4.14.298
(cherry picked from commit 282901a050)
2022-11-05 18:37:01 +00:00
Maximilian Bosch
b210cec07b Merge pull request #199722 from NixOS/backport-199345-to-release-22.05
[Backport release-22.05] nextcloud: 24.0.6 -> 24.0.7, 25.0.0 -> 25.0.1
2022-11-05 17:42:35 +01:00
Maximilian Bosch
549b04c474 nextcloud25: 25.0.0 -> 25.0.1
(cherry picked from commit 126d3848ce)
2022-11-05 16:26:04 +00:00
Maximilian Bosch
6aa6234abf nextcloud24: 24.0.6 -> 24.0.7
(cherry picked from commit d2fad4bebd)
2022-11-05 16:26:04 +00:00
Maximilian Bosch
27a9295277 nixos/nextcloud: fix upgrade warning
(cherry picked from commit ad21c759d4)
2022-11-05 16:26:04 +00:00
Vladimír Čunát
fddf4b1926 openssl_1_1: drop a long unused patch
(cherry picked from commit 6aa0c5e918)
2022-11-05 16:07:00 +00:00
Vladimír Čunát
36191cbd06 openssl_1_1: 1.1.1q -> 1.1.1s
I believe this double version jump includes no security fixes.

(cherry picked from commit 32ebb91f4b)
2022-11-05 16:07:00 +00:00
Thomas Gerbet
b946c6e710 expat: 2.4.9 -> 2.5.0
Fixes CVE-2022-43680

https://github.com/libexpat/libexpat/blob/R_2_5_0/expat/Changes
(cherry picked from commit a12a0047d0)
2022-11-05 16:00:10 +00:00
Martin Weinelt
113d70c103 webkitgtk: 2.38.1 -> 2.38.2
https://webkitgtk.org/2022/11/04/webkitgtk2.38.2-released.html
https://webkitgtk.org/security/WSA-2022-0010.html

Fixes: CVE-2022-32888, CVE-2022-32923, CVE-2022-42799, CVE-2022-42823
       CVE-2022-42824
(cherry picked from commit 12c069cd35)
2022-11-05 15:52:15 +01:00
Jan Tojnar
df6651b7cd webkitgtk: 2.38.0 → 2.38.1
https://webkitgtk.org/2022/10/20/webkitgtk2.38.1-released.html
https://github.com/WebKit/WebKit/compare/webkitgtk-2.38.0...webkitgtk-2.38.1

Changelog-Reviewed-By: Jan Tojnar <jtojnar@gmail.com>
(cherry picked from commit 4e8b341ade)
2022-11-05 15:51:53 +01:00
Jan Tojnar
8c4ec7ac05 webkitgtk: 2.37.90 → 2.38.0
https://webkitgtk.org/2022/09/16/webkitgtk2.38.0-released.html
https://github.com/WebKit/WebKit/compare/webkitgtk-2.37.90...webkitgtk-2.38.0
https://webkitgtk.org/security/WSA-2022-0009.html

Fixes:
CVE-2022-32886
CVE-2022-32891
CVE-2022-32912

Changelog-Reviewed-By: Jan Tojnar <jtojnar@gmail.com>
(cherry picked from commit 225103487a)
2022-11-05 15:51:47 +01:00
Jan Tojnar
2f32fb8daa webkitgtk: Display ABI version in name
To make it easier to distinguish which versions are in the closure.

(cherry picked from commit 57e596a865)
2022-11-05 15:51:41 +01:00
Jan Tojnar
154b185b3c webkitgtk: 2.37.1 → 2.37.90
https://webkitgtk.org/2022/08/19/webkitgtk2.37.90-released.html
https://github.com/WebKit/WebKit/compare/webkitgtk-2.37.1...webkitgtk-2.37.90

Changelog-Reviewed-By: Jan Tojnar <jtojnar@gmail.com>
(cherry picked from commit ccc127b3da)
2022-11-05 15:51:35 +01:00
Jan Tojnar
0971994c4a webkitgtk: 2.36.7 → 2.37.1
https://webkitgtk.org/2022/07/12/webkitgtk2.37.1-released.html

Changelog-Reviewed-By: Jan Tojnar <jtojnar@gmail.com>
(cherry picked from commit f5d6f8b560)
2022-11-05 15:51:30 +01:00
Martin Weinelt
a32a8fd775 Merge pull request #198730 from risicle/ris-curl-CVEs-202210-r22.05 2022-11-05 14:12:15 +01:00
Martin Weinelt
f09ad462c5 Merge pull request #199192 from LeSuisse/quictls-3.0.7-22.05 2022-11-05 14:08:23 +01:00
Martin Weinelt
30567d8168 Merge pull request #199696 from NixOS/backport-199673-to-release-22.05 2022-11-05 14:04:05 +01:00
Martin Weinelt
135e26a7b9 firefox-bin-unwrapped: 106.0.3 -> 106.0.5
https://www.mozilla.org/en-US/firefox/106.0.4/releasenotes/
https://www.mozilla.org/en-US/firefox/106.0.5/releasenotes/
(cherry picked from commit 69d5c86471)
2022-11-05 13:01:03 +00:00
Thomas Gerbet
d9647f0eeb [22.05] wireshark: 3.6.5 -> 3.6.9
Fixes CVE-2022-3725 and CVE-2022-3190.
https://www.wireshark.org/security/wnpa-sec-2022-07.html
https://www.wireshark.org/security/wnpa-sec-2022-06

https://www.wireshark.org/docs/relnotes/wireshark-3.6.9.html
https://www.wireshark.org/docs/relnotes/wireshark-3.6.8.html
https://www.wireshark.org/docs/relnotes/wireshark-3.6.7.html
https://www.wireshark.org/docs/relnotes/wireshark-3.6.6.html
2022-11-05 13:50:04 +01:00
Martin Weinelt
6da07c16fe Merge pull request #199509 from NixOS/backport-199306-to-release-22.05 2022-11-05 13:44:23 +01:00
Martin Weinelt
01293d1886 pixman: Apply fix for integer overflow in pixman_sample_floor_y
https://gitlab.freedesktop.org/pixman/pixman/-/issues/63

Fixes: CVE-2022-44638
2022-11-05 11:45:45 +01:00
R. Ryantm
e94d83857f firefox-unwrapped: 106.0.4 -> 106.0.5
(cherry picked from commit c01fdc7455)
2022-11-05 11:29:39 +01:00
github-actions[bot]
c75ad7584a Merge staging-next-22.05 into staging-22.05 2022-11-05 00:17:14 +00:00
github-actions[bot]
90a217f67f Merge release-22.05 into staging-next-22.05 2022-11-05 00:16:32 +00:00
Mario Rodas
bcdd40cd4a Merge pull request #199573 from NixOS/backport-198558-to-release-22.05
[Backport release-22.05] wolfssl: 5.5.1 -> 5.5.2
2022-11-04 19:08:07 -05:00
Robert Scott
be98ef07fb libpulsar: 2.9.1 -> 2.9.3 2022-11-04 23:02:57 +00:00
Thomas Gerbet
8a35775451 wolfssl: 5.5.1 -> 5.5.2
https://github.com/wolfSSL/wolfssl/releases/tag/v5.5.2-stable
Also includes a fix for CVE-2022-42905, the build option needed
for the vulnerability does not seem to be enabled in the derivation.

(cherry picked from commit 7e8b8cee64)
2022-11-04 21:17:07 +00:00
Jörg Thalheim
6f96f23bd5 Merge pull request #199528 from davidak/backport-175128-to-release-22.05
[22.05] nixos/doc: improve install instructions
2022-11-04 19:24:41 +01:00
davidak
892def4ab5 nixos/doc: improve install instructions
- Update download URLs
- Replace "USB stick"/"USB Drive" with "USB flash drive" as that seem more correct

  https://en.wikipedia.org/wiki/USB_flash_drive
  https://elementary.io/docs/installation#choose-operating-system

- Don't mention CD as easiest option anymore,
  as all modern systems should be able to boot from USB,
  but many don't have a CD drive. Burning CDs is also usually wasteful as you
  can't burn them again.
- Remove link to NixOS Wiki (Making_the_installation_media) as it is not needed
- Add Etcher and USBImager as graphical tools to create install drive
- Make dd command consistent and use block size of 4 MB for faster flashing
- More consistent text
- Add instructions for "Booting from the install medium"

  Inspired by 9a91b0f495/docs/installation.md (booting-from-the-install-drive-booting-from-the-installation-medium-clear-float-2)

- Add instructions for "Graphical Installation"
- Restructure headings and anchors for "Manual Installation"
- Adding legacy anchors for "Manual Installation" to not break links

(cherry picked from commit f701bd5986)

Co-authored-by: j-k <dev@j-k.io>
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
Co-authored-by: Robert Schütz <github@dotlambda.de>
Co-authored-by: Jörg Thalheim <Mic92@users.noreply.github.com>
Co-authored-by: Thiago Kenji Okada <thiagokokada@gmail.com>
2022-11-04 15:54:21 +01:00
Jan Tojnar
024981ee60 nixos/doc/manual/md-to-db.sh: Add support for <kbd> element
(cherry picked from commit fa285355ee)
2022-11-04 15:17:54 +01:00
github-actions[bot]
1404483f45 vscode-extensions.streetsidesoftware.code-spell-checker: 2.10.1 -> 2.11.0
(cherry picked from commit 423a5c72fd)

Co-authored-by: datafoo <34766150+datafoo@users.noreply.github.com>
2022-11-04 20:15:21 +08:00
Mario Rodas
1a623978be Merge pull request #199256 from NixOS/backport-197360-to-release-22.05
[Backport release-22.05] gitlab: 15.4.2 -> 15.4.4
2022-11-04 06:54:23 -05:00
R. Ryantm
6ef1237d48 firefox-unwrapped: 106.0.3 -> 106.0.4
(cherry picked from commit 82e5d263b9)
2022-11-04 11:47:12 +00:00
Maximilian Bosch
77f7b482de strace: 5.19 -> 6.0
ChangeLog: https://github.com/strace/strace/releases/tag/v6.0
(cherry picked from commit 77670a2003)
2022-11-04 11:11:34 +00:00
Bobby Rong
bf8564890d Merge pull request #199439 from NixOS/backport-199402-to-release-22.05
[Backport release-22.05] signal-desktop: 5.62.0 -> 5.63.0
2022-11-04 16:21:53 +08:00
kilianar
db8b58a2e2 signal-desktop: 5.62.0 -> 5.63.0
https://github.com/signalapp/Signal-Desktop/releases/tag/v5.63.0
(cherry picked from commit f6d5568862)
2022-11-04 01:16:42 +00:00
github-actions[bot]
34a4d3cebc Merge staging-next-22.05 into staging-22.05 2022-11-04 00:17:55 +00:00
github-actions[bot]
fca2f7a62d Merge release-22.05 into staging-next-22.05 2022-11-04 00:17:25 +00:00
Sandro Jäckel
30ae46ffd7 netatalk: cleanup, format
(cherry picked from commit 5814c516f3)
2022-11-03 23:50:08 +01:00
ajs124
84abfc038e php74: 7.4.32 -> 7.4.33
fixes CVE-2022-31630 and CVE-2022-37454
2022-11-03 20:33:26 +01:00
Pierre Bourdon
5d3976195b Merge pull request #199365 from NixOS/backport-199334-to-release-22.05
[Backport release-22.05] sudo: apply patch for CVE-2022-43995
2022-11-03 16:59:21 +01:00
Thomas Gerbet
8812389a12 sudo: apply patch for CVE-2022-43995
bd209b9f16
(cherry picked from commit 86c8848f78)
2022-11-03 15:31:38 +00:00
github-actions[bot]
3ac18d4d7e Merge staging-next-22.05 into staging-22.05 2022-11-03 00:17:57 +00:00
github-actions[bot]
27b77b33fe Merge release-22.05 into staging-next-22.05 2022-11-03 00:17:02 +00:00
M. A
6827170713 gitlab: 15.4.2 -> 15.4.4
https://about.gitlab.com/releases/2022/11/02/security-release-gitlab-15-5-2-released/

Fixes CVE-2022-3767
Fixes CVE-2022-3265
Fixes CVE-2022-3483
Fixes CVE-2022-3818
Fixes CVE-2022-3726
Fixes CVE-2022-2251
Fixes CVE-2022-3486
Fixes CVE-2022-3793
Fixes CVE-2022-3413
Fixes CVE-2022-2761
Fixes CVE-2022-3819
Fixes CVE-2022-3280
Fixes CVE-2022-3706

(cherry picked from commit faaf43c36a)
2022-11-02 23:30:48 +00:00
Domen Kožar
4f09cfce9c Merge pull request #199213 from yayayayaka/fix-cachix-doc
[22.05] nixos/cachix-watch-store: Remove lib.mdDoc
2022-11-02 20:29:59 +00:00
M. A
f5dbbd78de nixos/cachix-watch-store: Remove lib.mdDoc
https://github.com/NixOS/nixpkgs/pull/199193#issuecomment-1301178688
2022-11-02 20:23:24 +00:00
Domen Kožar
3e01e01ee3 Merge pull request #199193 from NixOS/backport-199182-to-release-22.05
[Backport release-22.05] nixos/cachix-watch-store: fix missing reference to the module
2022-11-02 17:11:09 +00:00
Jean-François Roche
281f5ece2c nixos/cachix-watch-store: fix missing reference to the module
I forgot to add the module to the list when I have added the module (dc529302fe)

(cherry picked from commit 7506fbd7f4)
2022-11-02 16:58:44 +00:00
Thomas Gerbet
38217d7761 quictls: only set enable-ktls flag on Linux
(cherry picked from commit 09685474e9)
2022-11-02 17:51:06 +01:00
Thomas Gerbet
f43ed35409 quictls: 3.0.5+quick_unstable-2022-07.05 -> 3.0.7+quic1
Fixes CVE-2022-3786 and CVE-2022-3602.
See eeca5969b3 and 70ca403dc2.

(cherry picked from commit bbae16baa9)
2022-11-02 17:50:53 +01:00
Izorkin
7a1bcca2fe quictls: disable ct feature in static mode
cherry picked from commit cc60c24909

(cherry picked from commit 4f99d8e708)
2022-11-02 17:50:21 +01:00
Izorkin
e7d28b8bde quictls: specify the ABI explicitly on mips64
cherry picked from commit 77d6781cdc

(cherry picked from commit 94ffbb4fdf)
2022-11-02 17:50:02 +01:00
Izorkin
af7e41948a quictls: 3.0.3+quick_unstable-2022-05.04 -> 3.0.5+quick_unstable-2022-07.05
(cherry picked from commit 1ed8ae38c9)
2022-11-02 17:49:50 +01:00
Yorick
3390a2b135 Merge pull request #199141 from NixOS/backport-190915-to-release-22.05
[Backport release-22.05] linuxPackages.wireguard: 1.0.20211208 -> 1.0.20220627, fix cross
2022-11-02 12:45:34 +01:00
Yorick van Pelt
e6c042701b linuxPackages_5_4.wireguard: fix cross build
(cherry picked from commit 941367cba5)
2022-11-02 10:33:15 +00:00
Yorick van Pelt
74fcf28fc6 linuxPackages.wireguard: 1.0.20211208 -> 1.0.20220627
(cherry picked from commit 32cfc505c6)
2022-11-02 10:33:15 +00:00
Vladimír Čunát
5263aa4296 openssl_3: enable KTLS only on Linux
This fixes build on *-darwin.

(cherry picked from commit 70ca403dc2)
2022-11-02 10:01:39 +01:00
github-actions[bot]
fe5cbaed13 Merge staging-next-22.05 into staging-22.05 2022-11-02 00:17:18 +00:00
github-actions[bot]
1b40bff7bf Merge release-22.05 into staging-next-22.05 2022-11-02 00:16:47 +00:00
Maximilian Bosch
c9a1090e19 Merge pull request #198815 from NixOS/backport-198777-to-release-22.05
[Backport release-22.05] linuxKernel.kernels: updates
2022-11-01 19:28:03 +01:00
Pavol Rusnak
dc858036fe Merge pull request #199010 from NixOS/backport-199002-to-release-22.05
[Backport release-22.05] lnd: 0.15.2-beta -> 0.15.4-beta
2022-11-01 18:10:59 +01:00
Pavol Rusnak
8e386793ab lnd: 0.15.2-beta -> 0.15.4-beta
(cherry picked from commit 991a5ca464)
2022-11-01 17:10:07 +00:00
Vladimír Čunát
b3a8f7ed26 Merge #199001: openssl: 3.0.5 -> 3.0.7
...into release-22.05
2022-11-01 17:04:19 +01:00
Martin Weinelt
cb2730af77 openssl: 3.0.5 -> 3.0.7
Fixes: CVE-2022-3786, CVE-2022-3602
Co-Authored-By: Andreas Schrägle <git@ajs124.de>
(cherry picked from commit eeca5969b3)
2022-11-01 15:53:50 +00:00
superherointj
0745bcae6f linuxPackages.lttng-modules: mark broken for 5.10
(cherry picked from commit f175291ce8)
2022-11-01 14:01:13 +01:00
R. Ryantm
53c5da3e97 lttng-tools: 2.13.7 -> 2.13.8
(cherry picked from commit c7186043a0)
2022-11-01 14:01:13 +01:00
fortuneteller2k
add404a3b1 linuxPackages.lttng-modules: 2.13.2 -> 2.13.4
(cherry picked from commit 282052f1dd)
2022-11-01 14:01:13 +01:00
R. Ryantm
c33d18cd6c lttng-tools: 2.13.4 -> 2.13.7
(cherry picked from commit 57aa33c58c)
2022-11-01 14:01:13 +01:00
FliegendeWurst
fa7dc24af9 v4l2loopback: unstable-2021-07-13 -> unstable-2022-08-05
(cherry picked from commit d07edf7bc0f81fbdd5f1a4d61d1f7005a18541d4)
2022-11-01 13:37:32 +01:00
Vladimír Čunát
1cf00ea3e8 Merge #197803: qemu: add patch for CVE-2022-3165
into release-22.05
2022-11-01 11:39:58 +01:00
Bjørn Forsman
072487244b skypeforlinux: remove nix store path references in desktop files
Because desktop files can be copied to $HOME/.config/autostart, and
eventually the Nix store paths they reference will be garbage collected
and break.

(cherry picked from commit 0870c0251249ecb765d413c3819819b80cedf686)
2022-11-01 11:05:06 +01:00
Bjørn Forsman
94fe73e1f2 xpra: fix application icon location
This makes the icon visible in desktop environments. (Tested in GNOME).

(cherry picked from commit d5b195d21f68cb1a2d9b7b1c6554cea467005da7)
2022-11-01 10:42:25 +01:00
github-actions[bot]
0ff4c4b477 Merge staging-next-22.05 into staging-22.05 2022-11-01 00:19:57 +00:00
github-actions[bot]
30fb0d2927 Merge release-22.05 into staging-next-22.05 2022-11-01 00:19:23 +00:00
Martin Weinelt
1b4722674c Merge pull request #198780 from NixOS/backport-198737-to-release-22.05 2022-10-31 23:14:26 +01:00
Christian Kögler
df655cda57 Merge pull request #198218 from NixOS/backport-198134-to-release-22.05
[Backport release-22.05] thunderbird-{,bin-}unwrapped: 102.4.0 -> 102.4.1
2022-10-31 22:01:25 +01:00
Bernardo Meurer
a959893b79 linux/hardened/patches/6.0: 6.0.5-hardened1 -> 6.0.6-hardened1
(cherry picked from commit e86a2ff7fe)
2022-10-31 17:58:59 +00:00
Bernardo Meurer
0bf0ea5aea linux/hardened/patches/5.4: 5.4.220-hardened1 -> 5.4.221-hardened1
(cherry picked from commit 0b4bc71ea2)
2022-10-31 17:58:59 +00:00
Bernardo Meurer
42802f403e linux/hardened/patches/5.15: 5.15.75-hardened1 -> 5.15.76-hardened1
(cherry picked from commit 3b2de1b5dd)
2022-10-31 17:58:59 +00:00
Bernardo Meurer
10ad4cdc68 linux/hardened/patches/5.10: 5.10.150-hardened1 -> 5.10.152-hardened1
(cherry picked from commit 615205d5b4)
2022-10-31 17:58:59 +00:00
Bernardo Meurer
abcf394313 linux-rt_5_10: 5.10.145-rt74 -> 5.10.152-rt75
(cherry picked from commit 5bcbe8ecd1)
2022-10-31 17:58:59 +00:00
Bernardo Meurer
c429ad5792 linux: 6.0.5 -> 6.0.6
(cherry picked from commit be14fb9e5c)
2022-10-31 17:58:59 +00:00
Bernardo Meurer
2a54070046 linux: 5.4.220 -> 5.4.221
(cherry picked from commit 41633ab784)
2022-10-31 17:58:59 +00:00
Bernardo Meurer
59557c5dc4 linux: 5.15.75 -> 5.15.76
(cherry picked from commit ac745085d8)
2022-10-31 17:58:59 +00:00
Bernardo Meurer
d427a4ab72 linux: 5.10.150 -> 5.10.152
(cherry picked from commit 33da8f9642)
2022-10-31 17:58:59 +00:00
Cabia Rangris
ddb57cae7c Merge pull request #198778 from NixOS/backport-197968-to-release-22.05
[Backport release-22.05] pythonPackages.dbus-next: Ignore tcp_connection_with_forwarding test
2022-10-31 20:46:38 +04:00
Maximilian Bosch
7b3e0905ab Merge pull request #198782 from NixOS/backport-198618-to-release-22.05
[Backport release-22.05] wiki-js: 2.5.289 -> 2.5.290
2022-10-31 15:05:43 +01:00
R. Ryantm
39c6ca7863 wiki-js: 2.5.289 -> 2.5.290
(cherry picked from commit 2575f0fc36)
2022-10-31 13:06:22 +00:00
Martin Weinelt
e43db1722d firefox-bin-unwrapped: 106.0.2 -> 106.0.3
https://www.mozilla.org/en-US/firefox/106.0.3/releasenotes/
(cherry picked from commit 71d12f6934)
2022-10-31 12:09:38 +00:00
Martin Weinelt
ff49d0f21c firefox-unwrapped: 106.0.2 -> 106.0.3
https://www.mozilla.org/en-US/firefox/106.0.3/releasenotes/
(cherry picked from commit 0fad4307e8)
2022-10-31 12:09:38 +00:00
Vladimir Serov
eac1f414eb pythonPackages.dbus-next: Ignore tcp_connection_with_forwarding test
Fixes #197408

Co-authored-by: @SFrijters
(cherry picked from commit 78c370aed7)
2022-10-31 12:01:39 +00:00
Robin Gloster
550e699382 Merge pull request #197514 from Ma27/backport-nextcloud25-nonbreaking
[22.05] nextcloud25: init (non-breaking)
2022-10-31 12:00:28 +00:00
Maximilian Bosch
2aede80d80 Merge pull request #198760 from NixOS/backport-192130-to-release-22.05
[Backport release-22.05] atlassian-confluence: 7.18.1 -> 7.19.1
2022-10-31 10:41:32 +01:00
Maximilian Bosch
6fb8185010 Merge pull request #198763 from NixOS/backport-198279-to-release-22.05
[Backport release-22.05] matrix-synapse: 1.70.0 -> 1.70.1
2022-10-31 10:41:18 +01:00
Maximilian Bosch
4d325bcf10 matrix-synapse: 1.70.0 -> 1.70.1
ChangeLog: https://github.com/matrix-org/synapse/releases/tag/v1.70.1
(cherry picked from commit 9173f1c5b4)
2022-10-31 09:07:42 +00:00
techknowlogick
e26aa5e6fa atlassian-confluence: 7.18.1 -> 7.19.1
(cherry picked from commit b8ac53c772)
2022-10-31 08:51:58 +00:00
Vladimír Čunát
c94d6447ca python3Packages.dateparser: fix tests on 31st day
Our patch from PR #189312 wasn't complete; let's take the upstream one.
I tested on 31st that it really passes now.

(cherry picked from commit e85bc94c9d)
2022-10-31 07:43:41 +01:00
github-actions[bot]
44acd11772 Merge staging-next-22.05 into staging-22.05 2022-10-31 00:18:32 +00:00
github-actions[bot]
383b9f1c48 Merge release-22.05 into staging-next-22.05 2022-10-31 00:18:03 +00:00
sternenseemann
d2a6211fd8 go-font: avoid .gitignore and .gitattributes in output
These were previously left over in $out, as they weren't matched by
`$out/*`.

(cherry picked from commit 81f7902be45055c9272b606e4ddb532cb0ef3420)
2022-10-31 00:54:10 +01:00
Robert Scott
f306f51be2 curl: add patches for multiple CVEs
CVE-2022-35252
CVE-2022-32221
CVE-2022-42915
CVE-2022-42916

switching to binary patching mode to allow the test for
CVE-2022-35252 to apply its line-endings correctly
2022-10-30 22:55:27 +00:00
Michael Weiss
06bd61e4b9 Merge pull request #198703 from NixOS/backport-198679-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 107.0.5304.68 -> 107.0.5304.88
2022-10-30 23:06:47 +01:00
Michael Weiss
ed11c0bd75 Merge pull request #198702 from NixOS/backport-198677-to-release-22.05
[Backport release-22.05] chromium: 107.0.5304.68 -> 107.0.5304.87
2022-10-30 23:05:57 +01:00
Michael Weiss
78056e081b ungoogled-chromium: 107.0.5304.68 -> 107.0.5304.88
(cherry picked from commit 0590d6d01c)
2022-10-30 18:58:55 +00:00
Michael Weiss
f06575c59b chromium: 107.0.5304.68 -> 107.0.5304.87
https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_27.html

This update includes 1 security fix. Google is aware of reports that an exploit
for CVE-2022-3723 exists in the wild.

CVEs:
CVE-2022-3723

(cherry picked from commit 1cd6b2c7f4)
2022-10-30 18:58:44 +00:00
ajs124
292b8bba6a tzdata: 2022e -> 2022f
https://mm.icann.org/pipermail/tz-announce/2022-October/000075.html
(cherry picked from commit 7d5f5e1f2a)
2022-10-30 18:39:53 +00:00
Martin Weinelt
7de7ddf239 Merge pull request #197618 from risicle/ris-traefik-CVE-2022-39271-r22.05 2022-10-30 16:31:58 +01:00
Nicolas Benes
26eb67abc9 tor-browser-bundle-bin: 11.5.5 -> 11.5.6
https://blog.torproject.org/new-release-tor-browser-1156/
(cherry picked from commit 9d8d995f52)
2022-10-30 11:32:45 +01:00
Bobby Rong
6440d13df2 Merge pull request #198577 from NixOS/backport-198477-to-release-22.05
[Backport release-22.05] cinnamon.cinnamon-common: unbreak cinnamon2d session
2022-10-30 09:05:51 +08:00
Bobby Rong
d753e510dc cinnamon.cinnamon-common: unbreak cinnamon2d session
(cherry picked from commit 8b44356e1f)
2022-10-30 00:46:37 +00:00
github-actions[bot]
26738b2a1d Merge staging-next-22.05 into staging-22.05 2022-10-30 00:19:21 +00:00
github-actions[bot]
df156bff30 Merge release-22.05 into staging-next-22.05 2022-10-30 00:18:42 +00:00
ajs124
15093c384e Merge pull request #198491 from NixOS/backport-198406-to-release-22.05
[Backport release-22.05] php: bump to 8.0.25 and 8.1.12
2022-10-30 01:17:24 +02:00
Pavel Shirshov
f63011683f netatalk: FreeBSD patchset 3.1.13_3, critical fix
(cherry picked from commit d1ecca0178)
2022-10-29 21:06:15 +02:00
Pol Dellaiera
47cf69b8c3 php81: 8.1.11 -> 8.1.12
(cherry picked from commit f8cd3d8b2b)
2022-10-29 16:27:08 +00:00
Pol Dellaiera
3d153b4c67 php80: 8.0.24 -> 8.0.25
(cherry picked from commit 305a0e8e65)
2022-10-29 16:27:08 +00:00
Berk D. Demir
b62e0c1523 go-font: 2017-03-30 -> 2.010
(cherry picked from commit a589016c5fcb21869fa1f7ce5c76f66c350b7f0b)
2022-10-29 15:56:35 +02:00
github-actions[bot]
7b431afb36 Merge staging-next-22.05 into staging-22.05 2022-10-29 00:15:10 +00:00
github-actions[bot]
f7eb6ad5f4 Merge release-22.05 into staging-next-22.05 2022-10-29 00:14:35 +00:00
Robert Scott
d837e1cbbe pjsip: add patches for CVE-2022-39269 & CVE-2022-39244
(cherry picked from commit 91a37f5d6d)
2022-10-28 20:36:42 +01:00
Mario Rodas
040c6d8374 Merge pull request #193393 from NixOS/backport-193036-to-release-22.05
[Backport release-22.05] drogon: 1.8.0 -> 1.8.1
2022-10-28 07:53:35 -05:00
Martin Weinelt
1c6678572a python38: 3.8.14 -> 3.8.15
http://docs.python.org/release/3.8.15/whatsnew/changelog.html
(cherry picked from commit 8444183652)
2022-10-28 11:55:07 +02:00
Martin Weinelt
3512a9c8ef python38: 3.8.13 -> 3.8.14
https://pythoninsider.blogspot.com/2022/09/python-releases-3107-3914-3814-and-3714.html

Fixes: CVE-2020-10735
(cherry picked from commit d1633b506b)
2022-10-28 11:54:59 +02:00
Martin Weinelt
7d51de150c python37: 3.7.14 -> 3.7.15
https://docs.python.org/release/3.7.15/whatsnew/changelog.html
(cherry picked from commit 87761da934)
2022-10-28 11:53:49 +02:00
Martin Weinelt
816b65bb51 python37: 3.7.13 -> 3.7.14
https://pythoninsider.blogspot.com/2022/09/python-releases-3107-3914-3814-and-3714.html

Fixes: CVE-2020-10735
(cherry picked from commit 0f91504e47)
2022-10-28 11:53:40 +02:00
Martin Weinelt
0901b8548d python310: 3.10.7 -> 3.10.8
https://docs.python.org/release/3.10.8/whatsnew/changelog.html
(cherry picked from commit a88ce6dc0b)
2022-10-28 11:52:04 +02:00
Martin Weinelt
3f4db8ae2b python310: 3.10.6 -> 3.10.7
https://docs.python.org/3.10/whatsnew/changelog.html\#python-3-10-7-final
https://pythoninsider.blogspot.com/2022/09/python-releases-3107-3914-3814-and-3714.html

Fixes: CVE-2020-10735
(cherry picked from commit 6b6a8fe7c0)
2022-10-28 11:51:26 +02:00
Martin Weinelt
8b21bc71bd python310: 3.10.5 -> 3.10.6
https://docs.python.org/3.10/whatsnew/changelog.html#python-3-10-6-final
https://pythoninsider.blogspot.com/2022/08/python-3106-is-available.html
https://www.python.org/downloads/release/python-3106/
(cherry picked from commit b4ba441d7c)
2022-10-28 11:51:06 +02:00
Martin Weinelt
5452dd0fff python310: 3.10.4 -> 3.10.5
https://docs.python.org/release/3.10.5/whatsnew/changelog.html#python-3-10-5-final
(cherry picked from commit 08615ec689)
2022-10-28 11:50:54 +02:00
Martin Weinelt
66ee690f6a python311: 3.11.0-rc2 -> 3.11.0
https://www.python.org/downloads/release/python-3110/
https://discuss.python.org/t/python-3-11-0-final-is-now-available/20291
(cherry picked from commit 4932ed92a4)
2022-10-28 11:49:13 +02:00
Martin Weinelt
1e4d4f521a python311: 3.11.0rc1 -> 3.11.0rc2
https://docs.python.org/3.11/whatsnew/changelog.html#python-3-11-0-release-candidate-2
(cherry picked from commit 1a1cd4b6cd)
2022-10-28 11:49:13 +02:00
Martin Weinelt
a8915694b1 python311: 3.11.0b5 -> 3.11.0rc1
https://docs.python.org/3.11/whatsnew/changelog.html#python-3-11-0-beta-5
(cherry picked from commit 7363ab9ebb)
2022-10-28 11:49:13 +02:00
Martin Weinelt
58a9b8f019 python311: 3.11.0b4 -> 3.11.0b5
https://pythoninsider.blogspot.com/2022/07/python-3110b5-is-now-available.html
https://www.python.org/downloads/release/python-3110b5/
(cherry picked from commit afda166636)
2022-10-28 11:49:13 +02:00
Martin Weinelt
1e3aef7e49 python311: 3.11.0b3 -> 3.11.0b4
https://www.python.org/downloads/release/python-3110b4/
https://pythoninsider.blogspot.com/2022/07/python-3110b4-is-now-available.html
(cherry picked from commit 802ec5de4b)
2022-10-28 11:49:13 +02:00
Martin Weinelt
c8fa0280cb python311: 3.11.0b1 -> 3.11.0b3
https://www.python.org/downloads/release/python-3110b2/
https://pythoninsider.blogspot.com/2022/05/python-3110b2-is-now-available.html

With updated darwin-libutil.patch provided by Randy Eckenrode.

Co-Authored-By: Randy Eckenrode <randy@largeandhighquality.com>
(cherry picked from commit a5c5302ddd)
2022-10-28 11:49:12 +02:00
Martin Weinelt
57ac426ce6 python311: 3.11.0a7 -> 3.11.0b1
https://www.python.org/downloads/release/python-3110b1/
https://blog.python.org/2022/05/python-3110b1-is-now-available.html
(cherry picked from commit 85dfb11907)
2022-10-28 11:49:12 +02:00
Maximilian Bosch
7269939a5d Merge pull request #198216 from NixOS/backport-198151-to-release-22.05
[Backport release-22.05] matrix-synapse: 1.69.0 -> 1.70.0
2022-10-28 08:54:57 +02:00
Maximilian Bosch
5e5a7a8310 Merge pull request #198215 from NixOS/backport-198189-to-release-22.05
[Backport release-22.05] matrix-synapse: remove setuptools_rust from runtime dependencies
2022-10-28 08:54:23 +02:00
Nicolas Benes
90981d7695 thunderbird-unwrapped: 102.4.0 -> 102.4.1
https://www.thunderbird.net/en-US/thunderbird/102.4.1/releasenotes/
(cherry picked from commit 724330fa1c)
2022-10-28 06:44:43 +00:00
Nicolas Benes
7d45b77151 thunderbird-bin-unwrapped: 102.4.0 -> 102.4.1
https://www.thunderbird.net/en-US/thunderbird/102.4.1/releasenotes/
(cherry picked from commit 26f3f406a6)
2022-10-28 06:44:43 +00:00
Maximilian Bosch
546928c8a8 matrix-synapse: 1.69.0 -> 1.70.0
ChangeLog: https://github.com/matrix-org/synapse/releases/tag/v1.70.0
(cherry picked from commit 1161a6f63e)
2022-10-28 06:31:48 +00:00
Nick Cao
031aabe5f8 matrix-synapse: remove setuptools_rust from runtime dependencies
(cherry picked from commit a7a59fe459)
2022-10-28 06:28:16 +00:00
Maximilian Bosch
a0cecd35bd Merge pull request #198063 from NixOS/backport-197944-to-release-22.05
[Backport release-22.05] linuxKernel.kernels: update
2022-10-28 08:22:55 +02:00
Maximilian Bosch
0513bfbf31 Merge pull request #196905 from NixOS/backport-196686-to-release-22.05
[Backport release-22.05] matrix-synapse: 1.68.0 -> 1.69.0
2022-10-28 08:22:29 +02:00
Mario Rodas
170f54b653 Merge pull request #198157 from NixOS/backport-198069-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 106.0.5249.119 -> 107.0.5304.68
2022-10-28 00:24:49 -05:00
Mario Rodas
08c9d962cf Merge pull request #198156 from NixOS/backport-197799-to-release-22.05
[Backport release-22.05] chromium: 106.0.5249.119 -> 107.0.5304.68
2022-10-28 00:24:06 -05:00
github-actions[bot]
2038a8344a Merge staging-next-22.05 into staging-22.05 2022-10-28 00:18:21 +00:00
github-actions[bot]
cdee24e682 Merge release-22.05 into staging-next-22.05 2022-10-28 00:17:46 +00:00
Martin Weinelt
ad6fff63d2 nss: 3.79.1 -> 3.79.2
https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/dbVxfMyXEyE
(cherry picked from commit be990edc4a)
2022-10-27 23:13:16 +00:00
Michael Weiss
69bc31664d fixup! ungoogled-chromium: 106.0.5249.119 -> 107.0.5304.68
(cherry picked from commit 3f9c609e1918e360e5dc2da21151240575a531bd)
2022-10-27 22:05:31 +00:00
Michael Adler
052f9c95be ungoogled-chromium: 106.0.5249.119 -> 107.0.5304.68
(cherry picked from commit 8b6f333ce247886454ab80bae236e156948431ef)
2022-10-27 22:05:31 +00:00
Michael Weiss
40aef9b526 chromium: 106.0.5249.119 -> 107.0.5304.68
https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_25.html

This update includes 14 security fixes.

CVEs:
CVE-2022-3652 CVE-2022-3653 CVE-2022-3654 CVE-2022-3655 CVE-2022-3656
CVE-2022-3657 CVE-2022-3658 CVE-2022-3659 CVE-2022-3660 CVE-2022-3661

(cherry picked from commit c9dad8d543)
2022-10-27 22:05:20 +00:00
Michael Weiss
86a34577e2 Merge pull request #198105 from primeos/chromium-backport
[22.05] Prepare for backporting Chromium M107
2022-10-27 23:57:05 +02:00
Michael Weiss
a235773c3b chromiumBeta: Fix the build
The build argument `use_system_libwayland_server` was set to `false`
since M107 [0]. This will cause `libwayland` to be built which does in
turn pull in `libffi` ("//build/config/linux/libffi") [1].

Alternatively, we should be able to fix the libffi dependency by setting
`use_system_libffi = true` (recently added, see [2]) and adding `libffi`
to the build inputs.

[0]: b9cd6d6767
[1]: https://source.chromium.org/chromium/chromium/src/+/refs/tags/107.0.5304.62:third_party/wayland/BUILD.gn
[2]: cf3ee09f08

(cherry picked from commit f9d9864cb6)
2022-10-27 20:04:50 +02:00
Michael Weiss
a99734e532 chromium{Beta,Dev}: Fix the configuration phase
Setting `clang_base_path` [0] does skip [1] a clang version check [2]
that would fail in our case:
```
configuring
ERROR at //build/config/compiler/BUILD.gn:1314:22: Script returned non-zero exit code.
    clang_revision = exec_script("//tools/clang/scripts/update.py",
                     ^----------
Current dir: /tmp/nix-build-chromium-unwrapped-107.0.5304.29.drv-0/chromium-107.0.5304.29/out/Release/
Command: python3 /tmp/nix-build-chromium-unwrapped-107.0.5304.29.drv-0/chromium-107.0.5304.29/tools/clang/scripts/update.py --print-revision --verify-version=16.0.0
Returned 1 and printed out:

The expected clang version is llvmorg-16-init-4609-g025a5b22-2 but the actual version is
Did you run "gclient sync"?

See //build/config/BUILDCONFIG.gn:329:3: which caused the file to be included.
  "//build/config/compiler:afdo",
  ^-----------------------------
error: builder for '/nix/store/02riyhzvrgn2vaab29d3gipxzkx6nb44-chromium-unwrapped-107.0.5304.29.drv' failed with exit code 1
```

I also chose to disable the Qt support for now. The Qt support is
enabled by default on Linux [3] but we need to add the required
dependencies first to fix the build (and my current priority is to get a
basic build working for the security critical stable channel update):
```
configuring
ERROR at //build/config/linux/pkg_config.gni:104:17: Script returned non-zero exit code.
    pkgresult = exec_script(pkg_config_script, args, "value")
                ^----------
Current dir: /tmp/nix-build-chromium-unwrapped-107.0.5304.62.drv-0/chromium-107.0.5304.62/out/Release/
Command: python3 /tmp/nix-build-chromium-unwrapped-107.0.5304.62.drv-0/chromium-107.0.5304.62/build/config/linux/pkg-config.py Qt5Core Qt5Widgets
Returned 1.
stderr:

Package Qt5Core was not found in the pkg-config search path.
Perhaps you should add the directory containing `Qt5Core.pc'
to the PKG_CONFIG_PATH environment variable
No package 'Qt5Core' found
Package Qt5Widgets was not found in the pkg-config search path.
Perhaps you should add the directory containing `Qt5Widgets.pc'
to the PKG_CONFIG_PATH environment variable
No package 'Qt5Widgets' found
Could not run pkg-config.

See //ui/qt/BUILD.gn:13:1: whence it was called.
pkg_config("qt5_config") {
^-------------------------
See //ui/linux/BUILD.gn:54:15: which caused the file to be included.
    deps += [ "//ui/qt" ]
              ^--------
error: builder for '/nix/store/3zzddkh74cnhvq6nql32y9pnbvzf2jv9-chromium-unwrapped-107.0.5304.62.drv' failed with exit code 1
```

[0]: https://source.chromium.org/chromium/chromium/src/+/refs/tags/107.0.5304.62:docs/clang.md
[1]: https://source.chromium.org/chromium/chromium/src/+/refs/tags/107.0.5304.62:build/config/compiler/BUILD.gn;l=1306
[2]: https://source.chromium.org/chromium/chromium/src/+/refs/tags/107.0.5304.62:tools/clang/scripts/update.py;l=358
[3]: https://source.chromium.org/chromium/chromium/src/+/refs/tags/107.0.5304.62:ui/qt/qt.gni;l=8

(cherry picked from commit f709a74fa3)
2022-10-27 20:04:50 +02:00
Michael Weiss
cade954f87 nixos/tests/chromium: Disable a failing test for M107+
I haven't had time to look into this yet but it looks like opening chrome://gpu
doesn't work anymore without proper GPU rendering (we use software rendering
due to the virtualisation).
According to the console output the new window never opens (at least with
Google Chrome - I couldn't test it with Chromium yet due to the failing builds
for M107 and M108):
```
(finished: sending keys ‘chrome://gpu
‘, in 0.14 seconds)
machine: waiting for a window to appear
machine: must succeed: xwininfo -root -tree | sed 's/.*0x[0-9a-f]* \"\([^\"]*\)\".*/\1/; t; d'
(finished: must succeed: xwininfo -root -tree | sed 's/.*0x[0-9a-f]* \"\([^\"]*\)\".*/\1/; t; d', in 0.05 seconds)
machine # Error: eglChooseConfig returned zero configs
machine #     at Create (../../third_party/dawn/src/dawn/native/opengl/ContextEGL.cpp:53)
machine #
machine: must succeed: xwininfo -root -tree | sed 's/.*0x[0-9a-f]* \"\([^\"]*\)\".*/\1/; t; d'
machine # WARNING: lavapipe is not a conformant vulkan implementation, testing use only.
(finished: must succeed: xwininfo -root -tree | sed 's/.*0x[0-9a-f]* \"\([^\"]*\)\".*/\1/; t; d', in 0.06 seconds)
machine: must succeed: xwininfo -root -tree | sed 's/.*0x[0-9a-f]* \"\([^\"]*\)\".*/\1/; t; d'
(finished: must succeed: xwininfo -root -tree | sed 's/.*0x[0-9a-f]* \"\([^\"]*\)\".*/\1/; t; d', in 0.09 seconds)
[...]
```

(cherry picked from commit 5389fbe783)
2022-10-27 20:04:49 +02:00
Michael Weiss
5a253ce2b1 nixos/tests/chromium: Fix the tests for Google Chrome
The meta attribute "timeout" is only set for Chromium (might still be required
due to the long build duration). The Google Chrome tests were failing with:

    error: attribute 'timeout' missing

According to nixos/lib/testing/meta.nix "null values are filtered out by
`meta`" so `timeout = chromiumPkg.meta.timeout or null` might be fine as
well.

(cherry picked from commit 0fa4d17725)
2022-10-27 20:04:49 +02:00
Michael Weiss
009b1b585c chromiumDev: 108.0.5355.0 -> 108.0.5359.10
(cherry picked from commit 7910d3db26)
2022-10-27 20:04:49 +02:00
Michael Weiss
2f2bf4b3bd chromiumBeta: 107.0.5304.36 -> 107.0.5304.62
(cherry picked from commit 0db31aa5aa)
2022-10-27 20:04:49 +02:00
Michael Weiss
aff18b9caa chromiumDev: 108.0.5343.2 -> 108.0.5355.0
(cherry picked from commit 53f7c7150e)
2022-10-27 20:04:48 +02:00
Michael Weiss
03423166be chromiumBeta: 107.0.5304.29 -> 107.0.5304.36
(cherry picked from commit 282eb843e0)
2022-10-27 20:04:48 +02:00
Michael Weiss
2decca237a chromiumDev: 108.0.5327.0 -> 108.0.5343.2
(cherry picked from commit 6ea106f4d8)
2022-10-27 20:04:48 +02:00
Michael Weiss
705cd60044 chromiumBeta: 107.0.5304.18 -> 107.0.5304.29
(cherry picked from commit 979047f732)
2022-10-27 20:04:47 +02:00
Michael Weiss
38511b14b6 chromiumDev: 107.0.5304.10 -> 108.0.5327.0
(cherry picked from commit ec50f7a5c3)
2022-10-27 20:04:47 +02:00
Michael Weiss
471b429876 chromiumBeta: 106.0.5249.61 -> 107.0.5304.18
(cherry picked from commit d88384313a)
2022-10-27 20:04:47 +02:00
R. Ryantm
78b6bf089b firefox-devedition-bin-unwrapped: 106.0b9 -> 107.0b5
(cherry picked from commit 0d93ef82bb)
2022-10-27 13:28:11 -04:00
R. Ryantm
8df2f368f2 firefox-devedition-bin-unwrapped: 106.0b7 -> 106.0b9
(cherry picked from commit 234ae8cfbb)
2022-10-27 13:28:10 -04:00
R. Ryantm
13400242e2 firefox-devedition-bin-unwrapped: 106.0b5 -> 106.0b7
(cherry picked from commit f33230dc4c)
2022-10-27 13:28:10 -04:00
R. Ryantm
370726c212 firefox-devedition-bin-unwrapped: 106.0b3 -> 106.0b5
(cherry picked from commit 9dfac8fef4)
2022-10-27 13:28:10 -04:00
ajs124
fabec68ab2 Merge pull request #197964 from risicle/ris-mysql-8.0.31-r22.05
[22.05] mysql80: 8.0.29 -> 8.0.31
2022-10-27 17:31:29 +02:00
Bernardo Meurer
a6c5a290a9 linux/hardened/patches/6.0: init at 6.0.5-hardened1
(cherry picked from commit 1faf7ac12b)
2022-10-27 12:38:09 +00:00
Bernardo Meurer
2ae336bc3c linux/hardened/patches/5.4: 5.4.218-hardened1 -> 5.4.220-hardened1
(cherry picked from commit 9496752a40)
2022-10-27 12:38:09 +00:00
Bernardo Meurer
3b5c8f083f linux/hardened/patches/5.19: 5.19.16-hardened1 -> 5.19.17-hardened1
(cherry picked from commit 27fe39ca92)
2022-10-27 12:38:09 +00:00
Bernardo Meurer
fa182fed59 linux/hardened/patches/5.15: 5.15.74-hardened1 -> 5.15.75-hardened1
(cherry picked from commit 6dce5b8937)
2022-10-27 12:38:09 +00:00
Bernardo Meurer
c5e609a86d linux/hardened/patches/5.10: 5.10.148-hardened1 -> 5.10.150-hardened1
(cherry picked from commit 9c5400268b)
2022-10-27 12:38:09 +00:00
Bernardo Meurer
58fe2eb639 linux/hardened/patches/4.19: 4.19.261-hardened1 -> 4.19.262-hardened1
(cherry picked from commit 9f0f5c89b3)
2022-10-27 12:38:09 +00:00
Bernardo Meurer
68b86691f0 linux/hardened/patches/4.14: 4.14.295-hardened1 -> 4.14.296-hardened1
(cherry picked from commit 49dcb766af)
2022-10-27 12:38:09 +00:00
Bernardo Meurer
f4c7155631 linux: 6.0.3 -> 6.0.5
(cherry picked from commit 46f6e6f4f1)
2022-10-27 12:38:09 +00:00
Bernardo Meurer
a8ea5b0f99 linux: 5.4.219 -> 5.4.220
(cherry picked from commit d6401ccea7)
2022-10-27 12:38:09 +00:00
Bernardo Meurer
05906d70c0 linux: 5.19.16 -> 5.19.17
(cherry picked from commit 62742edeb9)
2022-10-27 12:38:09 +00:00
Bernardo Meurer
6720a5a68d linux: 5.15.74 -> 5.15.75
(cherry picked from commit 992d8263aa)
2022-10-27 12:38:09 +00:00
Bernardo Meurer
52da2a41e5 linux: 5.10.149 -> 5.10.150
(cherry picked from commit 2fd2030e1e)
2022-10-27 12:38:09 +00:00
Bernardo Meurer
3eb2bf76c4 linux: 4.9.330 -> 4.9.331
(cherry picked from commit ec3c885adf)
2022-10-27 12:38:09 +00:00
Bernardo Meurer
c8edc4cf45 linux: 4.19.261 -> 4.19.262
(cherry picked from commit 31af94e98d)
2022-10-27 12:38:09 +00:00
Bernardo Meurer
756a8e8dc3 linux: 4.14.295 -> 4.14.296
(cherry picked from commit d423ef2ff9)
2022-10-27 12:38:08 +00:00
toonn
7226f5956f wire-desktop: mac 3.27.2944 -> 3.29.4477
(cherry picked from commit aa3e6347fc)
2022-10-27 14:16:41 +02:00
toonn
85c60318a4 wire-desktop: linux 3.27.2944 -> 3.29.2997
(cherry picked from commit 46142236d9)
2022-10-27 14:16:07 +02:00
Vladimír Čunát
c132d0837d Merge #198013: librewolf: fix build on aarch64-linux by upstream patch
...into release-22.05
2022-10-27 12:51:15 +02:00
Vladimír Čunát
63ebe68354 Merge #197034: thunderbird*: 102.3.3 -> 102.4.0
...into release-22.05
2022-10-27 09:03:02 +02:00
Vladimír Čunát
3be030cee0 librewolf: fix build on aarch64-linux by upstream patch
https://hydra.nixos.org/build/196437728
Same as c08efaf08 for firefox.

Cleanup of the nix expression was needed; the previous patch file
didn't even exist (anymore?)

(cherry picked from commit 61598203a4)
2022-10-27 06:23:23 +00:00
Nicolas Benes
2f5687d697 tor-browser-bundle-bin: 11.5.4 -> 11.5.5
https://blog.torproject.org/new-release-tor-browser-1155/
(cherry picked from commit f0f665ec3e)
2022-10-27 01:02:03 -04:00
Michael Weiss
4479e24f2f ungoogled-chromium: 106.0.5249.103 -> 106.0.5249.119
(cherry picked from commit 10e5fa68de)
2022-10-26 21:26:09 -04:00
github-actions[bot]
63bda071dc Merge staging-next-22.05 into staging-22.05 2022-10-27 00:17:48 +00:00
github-actions[bot]
abdd2a2623 Merge release-22.05 into staging-next-22.05 2022-10-27 00:17:14 +00:00
Martin Weinelt
ae221f0a10 Merge pull request #197591 from NixOS/backport-188184-to-staging-22.05 2022-10-27 01:51:29 +02:00
Martin Weinelt
25e653e3e7 Merge pull request #196305 from winterqt/update-hedgedoc-22.05 2022-10-27 01:46:50 +02:00
Martin Weinelt
c7472f8d15 Merge pull request #197918 from mweinelt/22.05/firefox-106.0.2 2022-10-27 01:25:03 +02:00
Kerstin
0a773b4ddf Merge pull request #197924 from NixOS/backport-197893-to-release-22.05
[Backport release-22.05] nixos/mastodon: fix start services
2022-10-26 22:21:48 +02:00
Robert Scott
090e7710f2 mysql80: 8.0.30 -> 8.0.31
(cherry picked from commit 23511ff5b6)
2022-10-26 21:03:11 +01:00
tirex
bd4b39a2ed mysql: 8.0.29 -> 8.0.30
(cherry picked from commit f3e806edf4)
2022-10-26 21:02:56 +01:00
Robert Scott
ce503e6e92 Merge pull request #197625 from risicle/ris--rabbitmq-server-3.9.18-r22.05
[22.05] rabbitmq-server: 3.9.14 -> 3.9.18
2022-10-26 19:08:27 +01:00
figsoda
35f0125e9e Merge pull request #194743 from NixOS/backport-194739-to-release-22.05
[Backport release-22.05] vscode-extensions.elixir-lsp.vscode-elixir-ls: 0.8.0 -> 0.11.0
2022-10-26 12:41:18 -04:00
Izorkin
ac1dbc02f3 nixos/mastodon: fix start services
(cherry picked from commit e6e7bbb62c4b09ccff4a0f173e92f4bad5b58e55)
2022-10-26 15:18:19 +00:00
Martin Weinelt
96968acbf2 firefox-bin-unwrapped: 106.0.1 -> 106.0.2
https://www.mozilla.org/en-US/firefox/106.0.2/releasenotes/
(cherry picked from commit 591441af02)
2022-10-26 16:53:18 +02:00
Martin Weinelt
0685b55d45 firefox-unwrapped: 106.0.1 -> 106.0.2
https://www.mozilla.org/en-US/firefox/106.0.2/releasenotes/
(cherry picked from commit bd66d2fe38)
2022-10-26 16:53:14 +02:00
adisbladis
cd787f111b Merge pull request #197832 from adisbladis/backport-22_05-flit-scm-init
[22.05] python3Packages.flit-scm: init at 1.7.0
2022-10-26 22:07:17 +13:00
Vladimír Čunát
e6e675cafe Merge #197057: staging-next-22.05 - iteration 13
...into release-22.05
2022-10-26 08:55:23 +02:00
Phillip Cloud
4f27e44bee python3Packages.flit-scm: init at 1.7.0
(cherry picked from commit 9f8a55aee5)
2022-10-26 18:00:54 +13:00
Robert Scott
0ffd63d303 qemu: add patch for CVE-2022-3165
(cherry picked from commit ceee8090d1)
2022-10-25 22:46:22 +01:00
github-actions[bot]
1dd5dfe133 Merge staging-next-22.05 into staging-22.05 2022-10-25 00:25:42 +00:00
github-actions[bot]
6e24e8b05c Merge release-22.05 into staging-next-22.05 2022-10-25 00:25:06 +00:00
Yuka
e0db156cfb pkgsMusl.libtasn1: fix build (#191043)
Patch borrowed from alpine to work around a specific test failure with musl libc
Upstream is patching this test in their own CI because that CI is using alpine and thus musl
06e7433c4e (diff-037ea159eb0a7cb0ac23b851e66bee30fb838ee8d0d99fa331a1ba65283d37f7R293)

(cherry picked from commit 8614d1dd20)
2022-10-25 00:19:02 +01:00
Robert Scott
befdb03d38 rabbitmq-server: 3.9.14 -> 3.9.18 2022-10-24 23:01:59 +01:00
Robert Scott
533490ea44 traefik: add patch for CVE-2022-39271 2022-10-24 21:29:40 +01:00
R. Ryantm
59149684e6 libtasn1: 4.18.0 -> 4.19.0
(cherry picked from commit 1acad4d826)
2022-10-24 16:59:01 +00:00
squalus
6107f97012 librewolf: 105.0.1-1 -> 106.0.1-1
(cherry picked from commit 6c47447c74)
2022-10-24 07:26:56 -04:00
Maximilian Bosch
fc53d6e62b Merge pull request #197516 from Ma27/backport-element
[22.05] element-{web,desktop}: 1.11.8 -> 1.11.10
2022-10-24 12:27:14 +02:00
Maximilian Bosch
8e5e961e14 element-{web,desktop}: 1.11.8 -> 1.11.10
ChangeLog: https://github.com/vector-im/element-web/releases/tag/v1.11.10
  & https://github.com/vector-im/element-web/releases/tag/v1.11.9

Corresponding `master` change: 6302d8f806
(#195709).
2022-10-24 10:59:11 +02:00
Maximilian Bosch
94323f6ac5 nextcloud25: init
This is a non-breaking change because the default version installed by
`services.nextcloud` remains `pkgs.nextcloud24`, but it gives users a
chance to upgrade to v25 on 22.05.

I also left `pkgs.nextcloud23` in here because it will only be dropped
in 2022-12 which is also the EOL of 22.05.

The corresponding change in `master` is at
40b7f52b8f from PR #197386.
2022-10-24 10:50:11 +02:00
Anderson Torres
6b8ce46f34 Merge pull request #197441 from NixOS/backport-194003-to-release-22.05
[Backport release-22.05] palemoon: 31.2.0.1 -> 31.3.0.1
2022-10-24 00:32:29 -03:00
github-actions[bot]
da51441b33 Merge staging-next-22.05 into staging-22.05 2022-10-24 00:23:22 +00:00
github-actions[bot]
5113707601 Merge release-22.05 into staging-next-22.05 2022-10-24 00:22:47 +00:00
OPNA2608
ab45de0499 palemoon: Further drop parallelism
It's still not stable on OfBorg.

(cherry picked from commit 2001f8d1ac)
2022-10-23 22:17:06 +00:00
OPNA2608
b42eedba4a palemoon: 31.2.0.1 -> 31.3.0.1
(cherry picked from commit 2666172816)
2022-10-23 22:17:06 +00:00
Robert Scott
98f8316449 Merge pull request #197049 from helsinki-systems/upd/nginx-22.05
[22.05]: nginx updates
2022-10-23 18:48:24 +01:00
Robert Scott
2acc2a998a Merge pull request #197251 from NixOS/backport-197196-to-staging-22.05
[Backport staging-22.05] libde265: 1.0.8 -> 1.0.9
2022-10-23 16:42:13 +01:00
Michele Guerini Rocco
8b38543f0a Merge pull request #197250 from NixOS/backport-196911-to-release-22.05
[Backport release-22.05] qt5.qtwebengine: 5.15.8 -> 5.15.11
2022-10-23 15:25:28 +02:00
Robert Scott
5f07f285ce Merge pull request #197272 from NixOS/backport-197192-to-staging-22.05
[Backport staging-22.05] faad2: 2.10.0 -> 2.10.1
2022-10-23 14:03:08 +01:00
Maximilian Bosch
471d92178b Merge pull request #197214 from NixOS/backport-197189-to-release-22.05
[Backport release-22.05] linux-kernel updates
2022-10-23 14:29:21 +02:00
Artturi
f911559414 Merge pull request #197266 from Artturin/backport-197248-to-release-22.05
[backport release-22.05] discord: add a script to disable breaking updates
2022-10-23 04:21:39 +03:00
Mario Rodas
2fc3c0ee1d Merge pull request #197261 from NixOS/backport-190772-to-release-22.05
[Backport release-22.05] nixos/syncthing: remove exit code 2 from exit status success
2022-10-22 19:52:12 -05:00
github-actions[bot]
ac0ff2bec3 Merge staging-next-22.05 into staging-22.05 2022-10-23 00:24:07 +00:00
github-actions[bot]
242a46f2ef Merge release-22.05 into staging-next-22.05 2022-10-23 00:23:37 +00:00
Thomas Gerbet
49cdad8623 faad2: 2.10.0 -> 2.10.1
Fixes CVE-2021-32273, CVE-2021-32274, CVE-2021-32276, CVE-2021-32277 and CVE-2021-32278.
https://github.com/knik0/faad2/releases/tag/2.10.1

(cherry picked from commit 0780634426)
2022-10-22 21:16:58 +00:00
Artturin
2d762b9201 discord: add a script to disable breaking updates
(cherry picked from commit c223efc36b39e4b88a5ac4f79dcb95881ed58d18)
2022-10-22 23:08:05 +03:00
Christian Kögler
8855b8336d nixos/syncthing: remove exit code 2 from exit status success
Fix #181713

(cherry picked from commit 89dcb1d31dd7e572d0c4cf208315123342856136)
2022-10-22 19:38:25 +00:00
Maxine Aubrey
c236def976 packer: 1.8.2 -> 1.8.3
(cherry picked from commit 969f5df9e5)
2022-10-22 19:04:10 +00:00
Thomas Gerbet
6c61113546 libde265: 1.0.8 -> 1.0.9
Fixes CVE-2021-36409, CVE-2021-35452, CVE-2021-36408, CVE-2021-36410 and CVE-2021-36411.
https://github.com/strukturag/libde265/releases/tag/v1.0.9

(cherry picked from commit 3c03948545)
2022-10-22 17:44:07 +00:00
Kazutoshi Noguchi
3987a4ea48 qt5.qtwebengine: 5.15.8 -> 5.15.11
(cherry picked from commit bf677a72e8)
2022-10-22 17:38:06 +00:00
Robert Scott
257cd998f5 Merge pull request #197115 from NixOS/backport-195335-to-release-22.05
[Backport release-22.05] sylpheed: apply patch for CVE-2021-37746
2022-10-22 17:40:12 +01:00
Robert Scott
1c21dea522 Merge pull request #193954 from NixOS/backport-192146-to-release-22.05
[Backport release-22.05] frr: add patch for CVE-2022-37032
2022-10-22 15:48:57 +01:00
Bernardo Meurer
3e2d910a5b linux/hardened/patches/5.4: 5.4.217-hardened2 -> 5.4.218-hardened1
(cherry picked from commit 59efe413b2)
2022-10-22 12:17:22 +00:00
Bernardo Meurer
3ebfb68783 linux/hardened/patches/5.19: 5.19.15-hardened2 -> 5.19.16-hardened1
(cherry picked from commit b0f1947ea8)
2022-10-22 12:17:21 +00:00
Bernardo Meurer
63082b2c41 linux/hardened/patches/5.15: 5.15.73-hardened3 -> 5.15.74-hardened1
(cherry picked from commit e164607345)
2022-10-22 12:17:21 +00:00
Bernardo Meurer
484e114728 linux/hardened/patches/5.10: 5.10.147-hardened2 -> 5.10.148-hardened1
(cherry picked from commit 0292ed799d)
2022-10-22 12:17:21 +00:00
Bernardo Meurer
3b6e8f2657 linux: 6.0.2 -> 6.0.3
(cherry picked from commit 1f7e118c3f)
2022-10-22 12:17:21 +00:00
Bernardo Meurer
ced2c3a006 linux: 5.4.218 -> 5.4.219
(cherry picked from commit 558536850f)
2022-10-22 12:17:21 +00:00
Bernardo Meurer
9470e57de6 linux: 5.10.148 -> 5.10.149
(cherry picked from commit 98428f66c8)
2022-10-22 12:17:21 +00:00
Artturi
3933d8bb91 Merge pull request #197146 from NixOS/backport-197141-to-release-22.05
[Backport release-22.05] discord: 0.0.20 -> 0.0.21
2022-10-22 04:14:33 +03:00
Anna Kudriavtsev
532b00afe9 discord: 0.0.20 -> 0.0.21
(cherry picked from commit 32566159ea)
2022-10-22 01:00:07 +00:00
github-actions[bot]
368a88c6a2 Merge staging-next-22.05 into staging-22.05 2022-10-22 00:21:26 +00:00
github-actions[bot]
c4e71464cb Merge release-22.05 into staging-next-22.05 2022-10-22 00:20:56 +00:00
Martin Weinelt
7a0b1f3b95 Merge pull request #197124 from mweinelt/22.05/firefox-106.0.1 2022-10-22 01:12:09 +02:00
Martin Weinelt
29ae303671 firefox-bin-unwrapped: 106.0 -> 106.0.1
https://www.mozilla.org/en-US/firefox/106.0.1/releasenotes/
(cherry picked from commit 87fa015d32)
2022-10-21 23:42:26 +02:00
Martin Weinelt
f368c01276 firefox-unwrapped: 106.0 -> 106.0.1
https://www.mozilla.org/en-US/firefox/106.0.1/releasenotes/
(cherry picked from commit 1f6b6f02e9)
2022-10-21 23:42:23 +02:00
Yorick van Pelt
d2dfeb16fd sylpheed: apply patch for CVE-2021-37746
(cherry picked from commit fc7ca788a3)
2022-10-21 20:31:42 +00:00
Bobby Rong
e90270087b Merge pull request #196972 from NixOS/backport-196959-to-release-22.05
[Backport release-22.05] shellhub-agent: 0.10.3 -> 0.10.4
2022-10-21 20:44:39 +08:00
Vladimír Čunát
ac20a8605b Merge #197061: vault-medusa: Add myself as maintainer
...into release-22.05
2022-10-21 13:15:17 +02:00
Jonas Heinrich
c50f51e701 vault-medusa: Add myself as maintainer
(cherry picked from commit 9eb6f65782a4165badc4c217d53a5cbe76c37a72)
2022-10-21 11:14:51 +00:00
Vladimír Čunát
d52297c4bd Merge #188000: rpm: 4.17.0 -> 4.17.1
...into release-22.05
2022-10-21 12:56:23 +02:00
Vladimír Čunát
ba1237ff8a Merge #194468: vault-medusa: init at 0.3.5
...into release-22.05
2022-10-21 12:50:54 +02:00
Vladimír Čunát
c087c823f1 Merge #194574: opcr-policy: init at 0.1.42
...into release-22.05
2022-10-21 12:49:29 +02:00
Vladimír Čunát
8a8ae17664 Merge branch 'staging-22.05' into staging-next-22.05 2022-10-21 12:44:04 +02:00
Vladimír Čunát
c4e36d818c Merge #194729: hydrus: 495 -> 501
...into release-22.05
2022-10-21 12:41:49 +02:00
Vladimír Čunát
8c0c9c61aa Merge #189996: less: 600 -> 608
...into staging-22.05
2022-10-21 12:31:17 +02:00
Vladimír Čunát
22eb0a8795 Merge #186923: libbluray: fix various java related issues
...into staging-22.05
2022-10-21 12:27:19 +02:00
Vladimír Čunát
11041f555b Merge #195996: libopenmpt: 0.6.4 -> 0.6.6
...into staging-22.05
2022-10-21 12:10:32 +02:00
Izorkin
6e9b2d6062 nginxQuic: 3550b00d9dc8 -> 3be953161026
(cherry picked from commit 9d676cb01d)
2022-10-21 11:48:03 +02:00
Izorkin
06a9c87f71 nginxQuic: 8d0753760546 -> 3550b00d9dc8
(cherry picked from commit a09d4826e1)
2022-10-21 11:48:01 +02:00
Izorkin
197651064b nginxMainline: 1.23.1 -> 1.23.2
(cherry picked from commit a9cbc65ad0)
2022-10-21 11:47:02 +02:00
Izorkin
11139690f0 nginxMainline: 1.23.0 -> 1.23.1
(cherry picked from commit ba7d7192f5)
2022-10-21 11:46:58 +02:00
Izorkin
1a0c0c9599 nginxStable: 1.22.0 -> 1.22.1
(cherry picked from commit 2392241c0b)
2022-10-21 11:46:10 +02:00
Nicolas Benes
7dc9195202 thunderbird-bin-unwrapped: 102.3.3 -> 102.4.0
https://www.thunderbird.net/en-US/thunderbird/102.4.0/releasenotes/
(cherry picked from commit 1a3a18aa79)
2022-10-21 07:56:57 +00:00
Nicolas Benes
e247dcda89 thunderbird-unwrapped: 102.3.3 -> 102.4.0
https://www.thunderbird.net/en-US/thunderbird/102.4.0/releasenotes/
(cherry picked from commit 0df09a4a45)
2022-10-21 07:56:57 +00:00
Anderson Torres
22b999f0e6 Merge pull request #197002 from NixOS/backport-196988-to-release-22.05
[Backport release-22.05] shapelib: add patch for CVE-2022-0699
2022-10-21 00:05:22 -03:00
Robert Scott
1df9e06e29 shapelib: add patch for CVE-2022-0699
(cherry picked from commit 2c2cb5d497)
2022-10-21 01:17:52 +00:00
github-actions[bot]
36aab1ed39 Merge staging-next-22.05 into staging-22.05 2022-10-21 00:20:49 +00:00
github-actions[bot]
de52ad0d76 Merge release-22.05 into staging-next-22.05 2022-10-21 00:20:21 +00:00
R. Ryantm
2db13054d2 shellhub-agent: 0.10.3 -> 0.10.4
(cherry picked from commit 818e7c689f)
2022-10-20 20:26:49 +00:00
Linus Heckemann
277121e05c Merge pull request #196668 from NixOS/backport-196283-to-release-22.05
[Backport release-22.05] libowfat: fix build with glibc 2.34
2022-10-20 21:57:10 +02:00
Vladimír Čunát
d2fc243b29 Merge #196465: thunderbird*: 102.3.2 -> 102.3.3
...into release-22.05
2022-10-20 18:16:32 +02:00
Sandro
861de04467 Merge pull request #196721 from Minion3665/backport-196624-dependencies-to-2205 2022-10-20 14:07:04 +02:00
Nick Cao
f595a35ebf matrix-synapse: 1.68.0 -> 1.69.0
(cherry picked from commit 7c0cf03e64)
2022-10-20 09:57:41 +00:00
Skyler Grey
eb58a0d3a7 multimc: suggest prismlauncher as an alternative
- Previously PolyMC was the suggested alternative
- This commit replaces that with prismlauncher, as PolyMC is no longer
  secure
2022-10-20 09:01:04 +01:00
Franz Pletz
44fc3cb097 Merge pull request #196580 from NixOS/backport-183206-to-release-22.05
[Backport release-22.05] clamav: 0.105.0 -> 0.105.1
2022-10-20 08:58:58 +02:00
github-actions[bot]
555fc2ce67 Merge staging-next-22.05 into staging-22.05 2022-10-20 00:22:44 +00:00
github-actions[bot]
2868077cdc Merge release-22.05 into staging-next-22.05 2022-10-20 00:22:13 +00:00
Skyler Grey
15d4e09dee release-notes-2205: suggest using prismlauncher
- Previously PolyMC was the suggested replacement for MultiMC
- As PolyMC is marked as insecure and prismlauncher is a replacement,
  this commit suggests using it instead
2022-10-19 22:38:26 +01:00
Skyler Grey
0398dd769f prismlauncher: init at 5.0 2022-10-19 22:38:22 +01:00
Pogobanane
451c1a3e32 nextcloud-client: 3.6.0 -> 3.6.1
(cherry picked from commit 3937c0c474)
2022-10-19 23:33:36 +02:00
Skyler Grey
f9b1cf5ddd maintainers: add minion3665 2022-10-19 09:09:52 +01:00
Sefa Eyeoglu
476bff3f96 tomlplusplus: init at 3.2.0
Signed-off-by: Sefa Eyeoglu <contact@scrumplex.net>
2022-10-19 09:09:52 +01:00
Sefa Eyeoglu
da17dc4d5d maintainers: add Scrumplex
Signed-off-by: Sefa Eyeoglu <contact@scrumplex.net>
Signed-off-by: Skyler Grey <skyler3665@gmail.com>
2022-10-19 09:09:49 +01:00
Robin Gloster
c5203abb13 Merge pull request #196655 from NixOS/backport-194767-to-release-22.05
[Backport release-22.05] gitlab: 15.4.1 -> 15.4.2
2022-10-19 07:23:05 +00:00
github-actions[bot]
aa27d711db Merge staging-next-22.05 into staging-22.05 2022-10-19 00:21:53 +00:00
github-actions[bot]
d3ee448f36 Merge release-22.05 into staging-next-22.05 2022-10-19 00:21:17 +00:00
Linus Heckemann
07fff3c535 libowfat: fix build with glibc 2.34
(cherry picked from commit 077faae467)
2022-10-19 00:02:39 +00:00
Martin Weinelt
b29e6c7218 Merge pull request #196618 from mweinelt/22.05/firefox-106 2022-10-19 01:16:57 +02:00
Yaya
adcb7c9066 gitlab: 15.4.1 -> 15.4.2
https://about.gitlab.com/releases/2022/10/03/gitlab-15-4-2-released/
(cherry picked from commit 878167fc8f1e6585e2fae7446d92e416789e2810)
2022-10-18 21:41:55 +00:00
misuzu
8abcd7def7 pleroma: fix captcha
(cherry picked from commit bc47164f29ef724a3ff71d504b39870ccc087abc)
2022-10-18 20:03:52 +00:00
Martin Weinelt
98d58dea9e dump_syms: 1.0.1 -> 2.0.0
https://github.com/mozilla/dump_syms/releases/tag/v2.0.0
(cherry picked from commit d77432260a)
2022-10-18 21:13:03 +02:00
Vladimír Čunát
2eda1ee43e firefox: fix build on aarch64-linux by upstream patch
(cherry picked from commit c08efaf08b)
2022-10-18 18:05:51 +02:00
Martin Weinelt
177853386f firefox-esr-102-unwrapped: 102.3.0esr -> 102.4.0esr
https://www.mozilla.org/en-US/firefox/102.4.0/releasenotes/
(cherry picked from commit 43c3a9fdf6)
2022-10-18 18:05:35 +02:00
Martin Weinelt
aa4a8d0785 firefox-bin-unwrapped: 105.0.3 -> 106.0
https://www.mozilla.org/en-US/firefox/106.0/releasenotes/
(cherry picked from commit 31de446787)
2022-10-18 18:04:42 +02:00
Martin Weinelt
4776eb37f0 firefox-unwrapped: 105.0.3 -> 106.0
https://www.mozilla.org/en-US/firefox/106.0/releasenotes/
(cherry picked from commit 5ac348c7f3)
2022-10-18 18:04:38 +02:00
Domen Kožar
9d0f0163b2 Merge pull request #196558 from NixOS/backport-196417-to-release-22.05
[Backport release-22.05] nixos: add cachix watch-store service
2022-10-18 13:58:04 +01:00
Bobby Rong
5b6b181638 Merge pull request #194723 from datafoo/backport-193938-to-release-22.05
Backport 193938 to release 22.05
2022-10-18 20:45:53 +08:00
R. Ryantm
d53da18c24 clamav: 0.105.0 -> 0.105.1
(cherry picked from commit cf04b73efc)
2022-10-18 12:05:54 +00:00
Jean-François Roche
9319859389 nixos: add cachix watch-store service
Self hosted CI push built packages asynchronously to cachix using a service.

Based on @Mic92 [code](https://github.com/cachix/cachix/issues/370#issuecomment-817081937)

(cherry picked from commit dc529302fe)
2022-10-18 08:57:58 +00:00
Sandro
47edaa313f Merge pull request #196481 from NixOS/backport-196476-to-release-22.05 2022-10-18 03:29:30 +02:00
github-actions[bot]
e75b3108d3 Merge staging-next-22.05 into staging-22.05 2022-10-18 00:22:42 +00:00
github-actions[bot]
e028921480 Merge release-22.05 into staging-next-22.05 2022-10-18 00:22:02 +00:00
Tris Emmy Wilson
a772595d2b polymc: mark knownVulnerabilities OVE-20221017-0001
see #196460, https://xeiaso.net/blog/OVE-20221017-0001

(cherry picked from commit 9d27de8105)
2022-10-17 22:13:32 +00:00
Martin Weinelt
27fdffd0ce thunderbird-bin-unwrapped: 102.3.2 -> 102.3.3
https://www.thunderbird.net/en-US/thunderbird/102.3.3/releasenotes/
(cherry picked from commit bff138f49d)
2022-10-17 21:01:18 +00:00
Martin Weinelt
788b4c595a thunderbird-unwrapped: 102.3.2 -> 102.3.3
https://www.thunderbird.net/en-US/thunderbird/102.3.3/releasenotes/
(cherry picked from commit 99034b201c)
2022-10-17 21:01:18 +00:00
Vladimír Čunát
1a94c97706 libksba: 1.6.0 -> 1.6.2
Close #192215

Noteworthy changes in version 1.6.2 (2022-10-07) [C22/A14/R2]
------------------------------------------------
 * Fix integer overflow in the CRL parser.  [rK4b7d9cd4a0]
 Release-info: https://dev.gnupg.org/T6230

Noteworthy changes in version 1.6.1 (2022-09-16) [C22/A14/R1]
------------------------------------------------
 * Allow an OCSP server not to return the sent nonce.  [rK24992a4a7a]
 Release-info: https://dev.gnupg.org/T6210

(cherry picked from commit 8ec485f514)
2022-10-17 19:59:24 +02:00
Bobby Rong
1935dd8fda Merge pull request #196340 from NixOS/backport-195780-to-release-22.05
[Backport release-22.05] tor-browser-bundle-bin: 11.5.2 -> 11.5.4
2022-10-17 21:56:39 +08:00
Maximilian Bosch
82a2921aab Merge pull request #196319 from NixOS/backport-196306-to-release-22.05
[Backport release-22.05] mautrix-whatsapp: 0.7.0 -> 0.7.1
2022-10-17 10:19:54 +02:00
Nicolas Benes
321d61df57 tor-browser-bundle-bin: add mirror for old versions
The normal source download mirrors usually contain only the latest (or a
few latest) release. Building a derivation for an old version can
therefore sometimes fail, if the source tar file was removed from the
mirror in the meantime.

A mirror containing even the old TBB release files is added to fix this
issue.

(cherry picked from commit d941434947)
2022-10-17 02:42:17 +00:00
Nicolas Benes
9ec8fd9439 tor-browser-bundle-bin: 11.5.2 -> 11.5.4
(cherry picked from commit d4027145f9)
2022-10-17 02:42:17 +00:00
Bobby Rong
05648fddf2 Merge pull request #196285 from bobby285271/cinnamon-stable
[22.05] cinnamon.cinnamon-common: many fixes
2022-10-17 10:05:29 +08:00
github-actions[bot]
faca36aee8 Merge staging-next-22.05 into staging-22.05 2022-10-17 00:22:08 +00:00
github-actions[bot]
524f89b7a3 Merge release-22.05 into staging-next-22.05 2022-10-17 00:21:39 +00:00
Dmitry Kalinkin
2667ea140e python3Packages.pytest-randomly: change hash after 25bafc8f1d 2022-10-16 18:03:33 -04:00
Maximilian Bosch
98d785956c mautrix-whatsapp: 0.7.0 -> 0.7.1
ChangeLog: https://github.com/mautrix/whatsapp/releases/tag/v0.7.1
(cherry picked from commit 487c3ebf7e)
2022-10-16 21:09:45 +00:00
Christian Kögler
bf82ac1f93 Merge pull request #196276 from NixOS/backport-196103-to-release-22.05
[Backport release-22.05] freeswitch: 1.10.7 -> 1.10.8
2022-10-16 20:13:00 +02:00
Maximilian Bosch
50a8eb8338 Merge pull request #196166 from risicle/ris-grafana-8.5.14-r22.05
[22.05] grafana: 8.5.13 -> 8.5.14
2022-10-16 20:04:04 +02:00
Sandro Jäckel
92c9d6a02c hedgedoc: refactor to fix editor crashing, replace inactive maintainer with myself
(cherry picked from commit 1653d2e3e2)
2022-10-16 13:26:17 -04:00
Sandro Jäckel
58abd5a8c8 yarn2nix: change yarnFlags to append by default
The main usecase for this variable is to append --production to yarn
which now got a whole lot easier because you no longer need to repeat
the defaults.

(cherry picked from commit 9bbc053f1a)
2022-10-16 13:25:38 -04:00
Pol Dellaiera
3de2496e60 hedgedoc: 1.9.0 -> 1.9.4 (#178129)
(cherry picked from commit a174de16ed)
2022-10-16 13:21:54 -04:00
Bobby Rong
20f0a287ee maintainers: add bobby285271 to cinnamon maintainer
(cherry picked from commit 957b36c74f)
2022-10-16 22:23:13 +08:00
Bobby Rong
f73c9bd568 cinnamon.cinnamon-common: Fix locking from menu
Closes #194612

(cherry picked from commit 8e2afcd868)
2022-10-16 22:21:55 +08:00
Bobby Rong
1bc7436db1 cinnamon.cinnamon-common: Fix upload-system-info path
(cherry picked from commit 6d36e7b057)
2022-10-16 22:21:42 +08:00
Bobby Rong
8ec26bcfa5 cinnamon.cinnamon-common: ensure xapp is available for cinnamon-desktop-editor
Closes #129946
Closes #177041

(cherry picked from commit d00b39e174)
2022-10-16 22:20:05 +08:00
Bobby Rong
438c357a78 cinnamon.cinnamon-common: ensure caribou is in XDG_DATA_DIRS
Some of its layout files are required for constructing a keyboard model.

Closes #101881

(cherry picked from commit 3de049f71d)
2022-10-16 22:19:31 +08:00
Bobby Rong
13f636225e cinnamon.cinnamon-common: fix msgfmt path for Spices.py
Closes #168924

(cherry picked from commit a29ca0ec20)
2022-10-16 22:19:11 +08:00
misuzu
d484d39c5a freeswitch: 1.10.7 -> 1.10.8
(cherry picked from commit 4a9250a8b2)
2022-10-16 13:39:32 +00:00
misuzu
a49a987f0b libks: 1.7.0 -> 1.8.0
(cherry picked from commit 7d1d10dccf)
2022-10-16 13:39:32 +00:00
Bobby Rong
8de8b98839 Merge pull request #196106 from NixOS/backport-192077-to-release-22.05
[Backport release-22.05] freeswitch: Fix build error
2022-10-16 21:31:03 +08:00
Robert Scott
3605fd3096 Merge pull request #192494 from NixOS/backport-192127-to-release-22.05
[Backport release-22.05] tinyproxy: add patch for CVE-2022-40468
2022-10-16 13:24:34 +01:00
github-actions[bot]
9f2b692dea Merge staging-next-22.05 into staging-22.05 2022-10-16 00:22:35 +00:00
github-actions[bot]
54513c6c79 Merge release-22.05 into staging-next-22.05 2022-10-16 00:22:03 +00:00
K900
945a85cb7e Merge pull request #196109 from NixOS/backport-196094-to-release-22.05
[Backport release-22.05] Kernel updates for 2022-10-15
2022-10-16 00:54:10 +03:00
Robert Scott
ffc1736ae9 Merge pull request #195789 from yorickvP/backport-195331-to-staging-22.05
[Backport staging-22.05] avahi: add patch for CVE-2021-3468
2022-10-15 21:54:39 +01:00
Robert Scott
be44bf672c Merge pull request #196155 from NixOS/backport-196107-to-release-22.05
[Backport release-22.05] libosip: 5.3.0 -> 5.3.1
2022-10-15 18:51:24 +01:00
Robert Scott
e3048f62c1 grafana: 8.5.13 -> 8.5.14 2022-10-15 18:04:13 +01:00
Thomas Gerbet
70f9e7738c libosip: 5.3.0 -> 5.3.1
Fixes CVE-2022-41550
https://git.savannah.gnu.org/cgit/osip.git/commit/?id=103d28ad799436b8a53fd8671428b25b0c08b8a0

(cherry picked from commit f909502274)
2022-10-15 15:41:13 +00:00
Vladimír Čunát
5d9a9b3e6c Merge #196127: nixosTests.vscodium: fix .wayland test
...into release-22.05
Fix by allowing more expressions to satisfy save file dialog.
2022-10-15 14:00:55 +02:00
Patrick Hilhorst
0e736b0a10 nixosTests.vscodium: allow more expressions to satisfy save file dialog
Previously was not clearing due to OCR glitch, should be more robust now. Also commented out the 'quit', which was also failing.

(cherry picked from commit 1bb6ca7fe1)
2022-10-15 11:48:02 +00:00
K900
9ccaecaa3a linux/hardened/patches/5.4: 5.4.215-hardened1 -> 5.4.217-hardened2
(cherry picked from commit c9fa012f1b)
2022-10-15 09:39:12 +00:00
K900
6c76c9150d linux/hardened/patches/5.19: 5.19.12-hardened1 -> 5.19.15-hardened2
(cherry picked from commit 529e4e43cd)
2022-10-15 09:39:12 +00:00
K900
041d88263b linux/hardened/patches/5.15: 5.15.71-hardened1 -> 5.15.73-hardened3
(cherry picked from commit 1fe114699f)
2022-10-15 09:39:12 +00:00
K900
f9e4ea5086 linux/hardened/patches/5.10: 5.10.146-hardened1 -> 5.10.147-hardened2
(cherry picked from commit ac118a1d1b)
2022-10-15 09:39:12 +00:00
K900
54dcce8b0a linux/hardened/patches/4.19: 4.19.260-hardened1 -> 4.19.261-hardened1
(cherry picked from commit 6d5f9ea638)
2022-10-15 09:39:12 +00:00
K900
bfe82b1864 linux: 6.0 -> 6.0.2
(cherry picked from commit 7523167eda)
2022-10-15 09:39:12 +00:00
K900
10e290a257 linux: 5.4.216 -> 5.4.218
(cherry picked from commit 202379fa9c)
2022-10-15 09:39:12 +00:00
K900
eb7d55cf44 linux: 5.19.14 -> 5.19.16
(cherry picked from commit e3bf36cdd3)
2022-10-15 09:39:11 +00:00
K900
db67352114 linux: 5.15.72 -> 5.15.74
(cherry picked from commit 6981bd8fda)
2022-10-15 09:39:11 +00:00
K900
59a06ab559 linux: 5.10.147 -> 5.10.148
(cherry picked from commit 9702319ec1)
2022-10-15 09:39:11 +00:00
Jonas Heinrich
66e79da594 freeswitch: Fix build error
(cherry picked from commit 58ba283555)
2022-10-15 08:47:47 +00:00
Mario Rodas
5e2a45820c Merge pull request #195733 from NixOS/backport-195208-to-staging-22.05
[Backport staging-22.05] wavpack: 5.4.0 -> 5.5.0
2022-10-14 23:06:17 -05:00
Mario Rodas
d3974c99a5 Merge pull request #196072 from NixOS/backport-195860-to-release-22.05
[Backport release-22.05] postgresql_jdbc: 42.2.20 -> 42.5.0
2022-10-14 20:53:33 -05:00
Mario Rodas
b40641ff31 Merge pull request #195238 from NixOS/backport-195203-to-release-22.05
[Backport release-22.05] yaws: 2.0.6 -> 2.1.1
2022-10-14 20:40:04 -05:00
Mario Rodas
7e9b727595 Merge pull request #195381 from datafoo/backport-194718-to-release-22.05
[22.05] backport #194718
2022-10-14 20:36:31 -05:00
Mario Rodas
e034ff650c Merge pull request #195396 from NixOS/backport-195336-to-release-22.05
[Backport release-22.05] plib: patch for CVE-2021-38714
2022-10-14 20:28:48 -05:00
Mario Rodas
38bf991622 Merge pull request #195718 from primeos/chromium-backport
[22.05] chromium: 106.0.5249.103 -> 106.0.5249.119
2022-10-14 20:01:19 -05:00
Thomas Gerbet
b69e4249b9 postgresql_jdbc: 42.2.20 -> 42.5.0
Fixes CVE-2022-31197 and CVE-2022-21724.

https://jdbc.postgresql.org/changelogs/2021-10-18-42.3.0-release/
https://jdbc.postgresql.org/changelogs/2022-06-09-42.4.0-release/
https://jdbc.postgresql.org/changelogs/2022-08-03-42.4.1-release/
https://jdbc.postgresql.org/changelogs/2022-08-17-42.4.2-release/
https://jdbc.postgresql.org/changelogs/2022-08-24-42.5.0-release/
(cherry picked from commit 6def56c5e7)
2022-10-15 00:43:05 +00:00
Anderson Torres
2a1f35032a Merge pull request #195959 from NixOS/backport-195890-to-release-22.05
[Backport release-22.05] mgba: 0.9.3 -> 0.10.0
2022-10-14 21:24:58 -03:00
github-actions[bot]
fb9ba43230 Merge staging-next-22.05 into staging-22.05 2022-10-15 00:21:24 +00:00
github-actions[bot]
994e4a915e Merge release-22.05 into staging-next-22.05 2022-10-15 00:20:45 +00:00
Sandro
588d57d82f Merge pull request #188552 from NixOS/backport-188373-to-release-22.05 2022-10-14 22:08:37 +02:00
ajs124
78a37aa630 Merge pull request #195875 from mweinelt/22.05/nss-3.84
[22.05] nss_latest: 3.82 -> 3.84
2022-10-14 18:11:43 +02:00
R. Ryantm
40a7b25bf6 libopenmpt: 0.6.5 -> 0.6.6
(cherry picked from commit ff3dd66849)
2022-10-14 17:26:46 +02:00
OPNA2608
3037c4b1dd libopenmpt: 0.6.4 -> 0.6.5
(cherry picked from commit 4db470acb6)
2022-10-14 17:26:42 +02:00
AndersonTorres
f8a7ad7b68 mgba: 0.9.3 -> 0.10.0
Now with lua scripting engine!

(cherry picked from commit 875ba8ecdb)
2022-10-14 10:57:47 +00:00
github-actions[bot]
3f7be4a4d2 Merge staging-next-22.05 into staging-22.05 2022-10-14 00:22:53 +00:00
github-actions[bot]
54b7615b6a Merge release-22.05 into staging-next-22.05 2022-10-14 00:22:23 +00:00
Martin Weinelt
a34dcc2eda nss: 3.83 -> 3.84
https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/uV-FYp6SUr8/m/M5TvBj0eAQAJ
(cherry picked from commit 989e8d8568)
2022-10-14 02:07:32 +02:00
Martin Weinelt
142217e1d0 nss_latest: 3.82 -> 3.83
https://github.com/nss-dev/nss/blob/master/doc/rst/releases/nss_3_83.rst
(cherry picked from commit 61b5db3336)
2022-10-14 02:07:27 +02:00
Robert Scott
3e3ef781ea Merge pull request #195791 from yorickvP/backport-195217-to-release-22.05
[Backport release-22.05] libmicrohttpd_0_70: mark as insecure
2022-10-13 23:55:21 +01:00
Robert Scott
57e0d95061 Merge pull request #195788 from yorickvP/backport-195329-to-release-22.05
[Backport release-22.05] lua: 5.4.3 -> 5.4.4
2022-10-13 23:53:54 +01:00
Martin Weinelt
a23076f923 Merge pull request #195848 from helsinki-systems/upd/tzdata2205 2022-10-13 22:45:59 +02:00
ajs124
b8960073f3 tzdata: 2022d -> 2022e
https://mm.icann.org/pipermail/tz-announce/2022-October/000074.html
(cherry picked from commit 8a2b098a1b)
2022-10-13 21:34:40 +02:00
ajs124
7a44afc412 tzdata: 2022c -> 2022d
https://mm.icann.org/pipermail/tz-announce/2022-September/000073.html
(cherry picked from commit ee73d3a942)
2022-10-13 21:34:35 +02:00
zowoq
bd08df0fc8 tzdata: 2022b -> 2022c
https://mm.icann.org/pipermail/tz-announce/2022-August/000072.html
(cherry picked from commit 913ea47f6b)
2022-10-13 21:34:32 +02:00
Yorick van Pelt
4fb69ef2dc libmicrohttpd_0_9_70: mark as insecure
(cherry picked from commit 4902637cc2)
2022-10-13 12:22:22 +02:00
Yorick van Pelt
577f6d1471 proxysql: switch libmicrohttpd from 0.9.70 to 0.9.69
0.9.70 is vulnerable to CVE-2021-3466, but 0.9.69 is fine.
proxysql is not yet compatible with 0.9.71

(cherry picked from commit a9cd13546b)
2022-10-13 12:22:22 +02:00
Yorick van Pelt
04fb7f4104 libmicrohttpd_0_9_69: init at 0.9.69
(cherry picked from commit fe2d699e41)
2022-10-13 12:22:22 +02:00
Yorick van Pelt
bb67c02a85 xmr-stak: switch libmicrohttpd to 0.9.71
(cherry picked from commit 342e281624)
2022-10-13 12:22:22 +02:00
Yorick van Pelt
9387120854 osmscout-server: move libmicrohttpd to 0.9.71
(cherry picked from commit 4beb9675e3)
2022-10-13 12:15:22 +02:00
Yorick van Pelt
04013acc61 elfutils: move libmicrohttpd to 0.9.71
(cherry picked from commit e907371b61)
2022-10-13 12:15:22 +02:00
Yorick van Pelt
4a7bf1fce1 avahi: add patch for CVE-2021-3468
(cherry picked from commit 039e1a05f5)
2022-10-13 12:10:52 +02:00
Yorick van Pelt
f1326b1383 lua: 5.4.3 -> 5.4.4
CVE-2021-44647, CVE-2021-44964, CVE-2021-43519

(cherry picked from commit 5af1ad13f6)
2022-10-13 12:04:41 +02:00
github-actions[bot]
87879053f2 Merge staging-next-22.05 into staging-22.05 2022-10-13 00:21:29 +00:00
github-actions[bot]
9e597b54df Merge release-22.05 into staging-next-22.05 2022-10-13 00:20:53 +00:00
Martin Weinelt
e06bd4b64b Merge pull request #194836 from risicle/ris-strongswan-CVE-2022-40617-r22.05 2022-10-13 00:18:39 +02:00
Yorick van Pelt
d0f7899b23 wavpack: 5.4.0 -> 5.5.0
CVE-2021-44269

(cherry picked from commit 27738d46f7)
2022-10-12 22:07:36 +00:00
Robert Scott
f313706e0c Merge pull request #191885 from LeSuisse/cosign-22.05-1.12.0
[22.05] cosign: 1.8.0 -> 1.12.0
2022-10-12 22:50:31 +01:00
Michael Weiss
d3aa7a9ea6 chromium: 106.0.5249.103 -> 106.0.5249.119
https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_11.html

This update includes 6 security fixes.

CVEs:
CVE-2022-3445 CVE-2022-3446 CVE-2022-3447 CVE-2022-3448 CVE-2022-3449
CVE-2022-3450

(cherry picked from commit c8d4492a8d)
2022-10-12 22:19:52 +02:00
Michael Weiss
b4ac947407 Merge pull request #195561 from NixOS/backport-195405-to-release-22.05
[Backport release-22.05] chromium: 106.0.5249.91 -> 106.0.5249.103
2022-10-12 22:18:31 +02:00
Anderson Torres
9234f5a17e Merge pull request #195672 from NixOS/backport-195379-to-release-22.05
[Backport release-22.05] parlatype: restore, 2.1 -> 3.1
2022-10-12 14:37:45 -03:00
Alexander Shpilkin
0ec9204ab6 parlatype: sort dependencies and reformat
(cherry picked from commit 16ead09b5e)
2022-10-12 14:58:11 +00:00
Alexander Shpilkin
56651c23da parlatype: 2.1 -> 3.1
(cherry picked from commit 0aa7db6030)
2022-10-12 14:58:11 +00:00
Alexander Shpilkin
47aba9bc76 parlatype: disable pocketsphinx integration
(cherry picked from commit 81738843e9)
2022-10-12 14:58:11 +00:00
Alexander Shpilkin
da6a5c8297 Revert "parlatype: remove"
This reverts commit 3d957ef33b.

(cherry picked from commit 8a4c373216)
2022-10-12 14:58:11 +00:00
Domen Kožar
5575eda7ce Merge pull request #195648 from NixOS/backport-194170-to-release-22.05
[Backport release-22.05] zoom-us: 5.11.{9.10046,10.4400} -> 5.12.0.{11129,4682}
2022-10-12 14:56:14 +02:00
Keshav Kini
9ee9dc18cd zoom-us: 5.11.{9.10046,10.4400} -> 5.12.0.{11129,4682}
(cherry picked from commit a4d7d4b000)
2022-10-12 09:17:59 +00:00
zowoq
145e0eeac7 go_1_18: 1.18.6 -> 1.18.7
(cherry picked from commit b0d7504e82)
2022-10-11 21:37:56 -04:00
github-actions[bot]
0b816197d9 Merge staging-next-22.05 into staging-22.05 2022-10-12 00:24:05 +00:00
github-actions[bot]
28696797ed Merge release-22.05 into staging-next-22.05 2022-10-12 00:23:35 +00:00
Lassulus
cded5ae4df Merge pull request #195574 from NixOS/backport-195557-to-release-22.05 2022-10-11 22:37:38 +02:00
lassulus
3c8bd8789b writers.writeJS: pass arguments to script
(cherry picked from commit 85a36f9146)
2022-10-11 19:56:00 +00:00
Michael Weiss
3c8c4ca82a chromium: 106.0.5249.91 -> 106.0.5249.103
https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop.html
(cherry picked from commit 420363e3ce)
2022-10-11 18:56:17 +00:00
Michael Weiss
e4fe389762 Merge pull request #195408 from NixOS/backport-195326-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 106.0.5249.91 -> 106.0.5249.103
2022-10-11 20:52:19 +02:00
Vladimír Čunát
0b20bf89e0 Merge #195187: thunderbird*: 102.3.1 -> 102.3.2
...into release-22.05
2022-10-11 07:39:29 +02:00
Zhaofeng Li
1062dd854b steam: Add extraArgs to prepend arguments to Steam
The steam launcher script in SteamOS 3 always prepends `-steamdeck`
to ensure the correct client version is used. This argument enables
us to replicate the setup in NixOS.

(cherry picked from commit 39ead096544fe7faa202a66b5a6041a872e8f505)
2022-10-10 21:49:12 -04:00
Martin Weinelt
d4c3f3ce09 Merge pull request #192203 from NixOS/backport-192099-to-release-22.05 2022-10-11 03:20:55 +02:00
github-actions[bot]
0e719a50a5 Merge staging-next-22.05 into staging-22.05 2022-10-11 00:21:50 +00:00
github-actions[bot]
075846a4c0 Merge release-22.05 into staging-next-22.05 2022-10-11 00:21:18 +00:00
Michael Adler
e56135bd85 ungoogled-chromium: 106.0.5249.91 -> 106.0.5249.103
(cherry picked from commit 00a62633db)
2022-10-10 20:03:11 +00:00
Yorick van Pelt
2684aabee9 plib: patch for CVE-2021-38714
(cherry picked from commit b2f0054dd0)
2022-10-10 18:50:04 +00:00
x10an14
903e05d87b vscode-extensions.streetsidesoftware.code-spell-checker: 2.1.7 -> 2.10.1
(cherry picked from commit 3241ef22f9)
2022-10-10 17:40:33 +02:00
datafoo
c9cf266998 vscode-extensions.dbaeumer.vscode-eslint: 2.2.2 -> 2.2.6
(cherry picked from commit 04cfb30407)
2022-10-10 17:32:57 +02:00
datafoo
96f4f537b3 vscode-extensions.stkb.rewrap: 1.16.1 -> 1.16.3
(cherry picked from commit 64f0a698a5)
2022-10-10 17:32:57 +02:00
datafoo
4bdb8d73db vscode-extensions.naumovs.color-highlight: 2.5.0 -> 2.6.0
(cherry picked from commit 31111502eb)
2022-10-10 17:32:57 +02:00
datafoo
71ac13e339 vscode-extensions.esbenp.prettier-vscode: 9.5.0 -> 9.9.0
(cherry picked from commit 57c921763a)
2022-10-10 17:32:48 +02:00
datafoo
8b4e1d7453 vscode-extensions.davidanson.vscode-markdownlint: 0.47.0 -> 0.48.1
(cherry picked from commit 1a30a70fb3)
2022-10-10 17:28:09 +02:00
datafoo
009540add1 vscode-extensions.apollographql.vscode-apollo: 1.19.9 -> 1.19.11
(cherry picked from commit 04d4d8d2e6)
2022-10-10 17:28:09 +02:00
Sandro
e179d1e57a Merge pull request #194372 from NixOS/backport-193165-to-release-22.05 2022-10-10 13:38:52 +02:00
Pavol Rusnak
c769a39f04 Merge pull request #195358 from prusnak/lnd-22.05
lnd: 0.14.3-beta -> 0.15.2-beta
2022-10-10 12:59:27 +02:00
Pavol Rusnak
9a7206dfab Merge pull request #195353 from NixOS/backport-195339-to-release-22.05
[Backport release-22.05] eclair: 0.6.2 -> 0.7.0-patch-disconnect
2022-10-10 12:58:26 +02:00
Otto Sabart
96372fbc1c lnd: 0.15.1-beta -> 0.15.2-beta
(cherry picked from commit d74b3668e7)
2022-10-10 12:53:00 +02:00
Pavol Rusnak
ffe9ce2564 lnd: 0.15.0-beta -> 0.15.1-beta
(cherry picked from commit 61621f5b7e)
2022-10-10 12:52:54 +02:00
Pavol Rusnak
3e35027ae6 lnd: 0.14.3-beta -> 0.15.0-beta
(cherry picked from commit 54c19e2408)
2022-10-10 12:52:48 +02:00
Yorick van Pelt
6a7e78495f eclair: 0.6.2 -> 0.7.0-patch-disconnect
(cherry picked from commit e622de224e)
2022-10-10 10:48:04 +00:00
Martin Weinelt
931300f961 Merge pull request #195284 from NixOS/backport-195264-to-staging-22.05 2022-10-10 03:15:56 +02:00
github-actions[bot]
7c76c2a372 Merge staging-next-22.05 into staging-22.05 2022-10-10 00:21:03 +00:00
github-actions[bot]
c1207bd11e Merge release-22.05 into staging-next-22.05 2022-10-10 00:20:17 +00:00
Martin Weinelt
47f5668ee7 dbus: 1.14.0 -> 1.14.4
https://gitlab.freedesktop.org/dbus/dbus/-/blob/dbus-1.14.4/NEWS

Fixes: CVE-2022-42010, CVE-2022-42011, CVE-2022-42012
(cherry picked from commit bdb347b42c)
2022-10-09 21:21:28 +00:00
Vladimír Čunát
ecdafdc9f0 Merge #195247: arrow-cpp: Fix build on emulated x86_64-darwin
...into release-22.05
2022-10-09 20:43:06 +02:00
K900
98fc76182b Merge pull request #195069 from vcunat/p/linux-6.0_22.05
[Backport release-22.05] linux_6_0: init at 6.0
2022-10-09 21:28:51 +03:00
Robert Scott
0fc2b4f7ac Merge pull request #195257 from NixOS/backport-195249-to-release-22.05
[Backport release-22.05] exiv2: drop a test on darwin, really now
2022-10-09 18:56:24 +01:00
Vladimír Čunát
9af2cdce10 exiv2: drop a test on darwin, really now
I did this wrong in 9927b2f2c3.  `-f` invites typos.

(cherry picked from commit 6471cff5dd)
2022-10-09 17:05:31 +00:00
Michael Weiss
0897bc93e3 Merge pull request #195220 from NixOS/backport-195092-to-release-22.05
[Backport release-22.05] chromedriver: fix darwin aarch64
2022-10-09 18:59:04 +02:00
Andrew Marshall
24e36bebeb arrow-cpp: Fix building x86_64-darwin on aarch_64-darwin
When building x86_64-darwin emulated via Rosetta on aarch64-darwin, all
tests would fail with

> Illegal instruction: 4

this resolves that by never using Jemalloc on Darwin, since even though
`isAarch64` is false, it might “really” be aarch64-darwin.

(cherry picked from commit 9764c81130034e9e01efd458560ce2cd95ed7519)
2022-10-09 16:06:38 +00:00
Robert Scott
9282141c8b Merge pull request #195237 from NixOS/backport-195191-to-release-22.05
[Backport release-22.05] exiv2: drop a test on darwin
2022-10-09 16:18:14 +01:00
Yorick van Pelt
35336a0635 yaws: 2.0.6 -> 2.1.1
(cherry picked from commit cc1dbce261)
2022-10-09 14:44:14 +00:00
Thomas Gerbet
fde3553bff cosign: build with Go 1.18 2022-10-09 16:40:52 +02:00
R. Ryantm
5e728491b9 cosign: 1.11.1 -> 1.12.0
(cherry picked from commit f5357321ba)
2022-10-09 16:40:52 +02:00
Thomas Gerbet
8b3ce5a49b cosign: 1.11.0 -> 1.11.1
https://github.com/sigstore/cosign/releases/tag/v1.11.1
(cherry picked from commit f9cd86edd5)
2022-10-09 16:40:52 +02:00
R. Ryantm
6e62007038 cosign: 1.10.1 -> 1.11.0
(cherry picked from commit c7f4385e84)
2022-10-09 16:40:52 +02:00
Thomas Gerbet
643240adc4 cosign: 1.10.0 -> 1.10.1
https://github.com/sigstore/cosign/releases/tag/v1.10.1

Includes a fix for CVE-2022-35929
https://github.com/sigstore/cosign/security/advisories/GHSA-vjxv-45g9-9296

(cherry picked from commit 958dd9a8c7)
2022-10-09 16:40:52 +02:00
Thomas Gerbet
ccc96b2e89 cosign: 1.9.0 -> 1.10.0
`cosigned` is no more part of the cosign repository and it has been moved
into a `sigstore/policy-controller` repository. A new package should probably
be created to replace it.

https://github.com/sigstore/cosign/releases/tag/v1.10.0
(cherry picked from commit 595932cd2b)
2022-10-09 16:40:51 +02:00
Thomas Gerbet
14a91dbdef cosign: 1.8.0 -> 1.9.0
Release notes:
https://github.com/sigstore/cosign/releases/tag/v1.9.0

(cherry picked from commit 85ac5d8c9b)
2022-10-09 16:40:51 +02:00
Vladimír Čunát
7bffc2bc2e exiv2: drop a test on darwin
It's often an issue; no idea why:
https://hydra.nixos.org/job/nixpkgs/nixpkgs-22.05-darwin/exiv2.aarch64-darwin
though for x86 it seems to have started after compiling via rosetta:
https://hydra.nixos.org/build/192631598

Note that exiv2 blocks the darwin-tested job.

(cherry picked from commit 9927b2f2c3)
2022-10-09 14:21:19 +00:00
Robert Scott
6a5a3bbf4a Merge pull request #194999 from risicle/ris-go-1-18-apple-sdk-11-r22.05
[22.05] go_1_18: Use apple_sdk_11_0.callPackage
2022-10-09 15:01:52 +01:00
Konstantin Alekseev
d5ade8400e chromedriver: fix darwin aarch64
(cherry picked from commit c02b06d612)
2022-10-09 11:18:05 +00:00
Vladimír Čunát
322d32f23e thunderbird-bin: 102.3.1 -> 102.3.2
https://www.thunderbird.net/en-US/thunderbird/102.3.2/releasenotes/
(cherry picked from commit e35e3836c5)
2022-10-09 06:49:50 +00:00
Vladimír Čunát
9968f2b6e9 thunderbird: 102.3.1 -> 102.3.2
https://www.thunderbird.net/en-US/thunderbird/102.3.2/releasenotes/
(cherry picked from commit d25c4975cf)
2022-10-09 06:49:50 +00:00
Thomas Gerbet
b3783bcfb8 spark_3_2: 3.2.1 -> 3.2.2
https://spark.apache.org/releases/spark-release-3-2-2.html

Fixes CVE-2022-33891.

(cherry picked from commit 24407ae3e7)
2022-10-08 21:32:38 -04:00
github-actions[bot]
34e8a2661e Merge staging-next-22.05 into staging-22.05 2022-10-09 00:20:49 +00:00
github-actions[bot]
f66dd4a579 Merge release-22.05 into staging-next-22.05 2022-10-09 00:20:06 +00:00
Robert Scott
8e799ffd2c Merge pull request #195139 from NixOS/backport-195070-to-release-22.05
[Backport release-22.05] nixosTests.spark: give `worker` node 2G of memory
2022-10-08 23:00:04 +01:00
Robert Scott
fcefb44de4 nixosTests.spark: give worker node 2G of memory
test currently failing due to OOM

(cherry picked from commit 68138bfb28)
2022-10-08 21:37:30 +00:00
Vladimír Čunát
8fb05e8f75 Merge #194284: staging-next-22.05 - iteration 12
...into release-22.05
2022-10-08 21:17:28 +02:00
Martin Weinelt
868a3294b9 Merge pull request #195094 from NixOS/backport-195017-to-release-22.05 2022-10-08 16:38:44 +02:00
Martin Weinelt
23a1edbce0 firefox-bin-unwrapped: 105.0.2 -> 105.0.3
https://www.mozilla.org/en-US/firefox/105.0.3/releasenotes/
(cherry picked from commit 5b97db5b4a)
2022-10-08 13:16:28 +00:00
Martin Weinelt
c1b3e8773a firefox-unwrapped: 105.0.2 -> 105.0.3
https://www.mozilla.org/en-US/firefox/105.0.3/releasenotes/
(cherry picked from commit 5255c541a6)
2022-10-08 13:16:28 +00:00
K900
9ea7b836dd perf: fix build with kernel 6.0
(cherry picked from commit dbf1d73cd1)
2022-10-08 11:58:15 +02:00
K900
d69f348215 linux/6.0: init
(cherry picked from commit 0faffb5531)
2022-10-08 11:54:07 +02:00
Jörg Thalheim
1a9935bf90 Merge pull request #195050 from LeSuisse/22.05-libdwarf-mark-vuln-CVE-2022-39170
libdwarf: mark vulnerable to CVE-2022-39170
2022-10-08 10:03:45 +02:00
Thomas Gerbet
1008f95809 libdwarf: mark vulnerable to CVE-2022-39170 2022-10-08 09:39:34 +02:00
Bobby Rong
9bacaca48a Merge pull request #195027 from NixOS/backport-194722-to-release-22.05
[Backport release-22.05] signal-desktop: 5.61.1 -> 5.62.0
2022-10-08 14:41:44 +08:00
kilianar
38d5de3cd8 signal-desktop: 5.61.1 -> 5.62.0
https://github.com/signalapp/Signal-Desktop/releases/tag/v5.62.0
(cherry picked from commit 5ccd68f9c0)
2022-10-08 03:43:50 +00:00
Bobby Rong
2eca8b6349 Merge pull request #195025 from NixOS/backport-193599-to-release-22.05
[Backport release-22.05] signal-desktop: 5.61.0 -> 5.61.1
2022-10-08 11:33:20 +08:00
kilianar
2b546a23fc signal-desktop: 5.61.0 -> 5.61.1
https://github.com/signalapp/Signal-Desktop/releases/tag/v5.61.1
(cherry picked from commit 0b87d79621)
2022-10-08 02:34:52 +00:00
github-actions[bot]
4d818984ad Merge staging-next-22.05 into staging-22.05 2022-10-08 00:20:24 +00:00
github-actions[bot]
17decaf263 Merge release-22.05 into staging-next-22.05 2022-10-08 00:19:48 +00:00
toonn
4af479b298 go_1_18: Use apple_sdk_11_0.callPackage
Go 1.18 requires a newer SDK than the one we build from sources. As a
workaround we're making use of the SDK we're using for aarch64-darwin.
This means Go 1.18 will not work on any Darwin systems that don't have
forwards-compatible SDK versions with the particular package in
question. We might need to mark Go packages broken based on the macOS
version rather than just the platform and architecture.

Until we find a better solution, Go packages will need to make sure to
get all their (Darwin) system dependencies from the `apple_sdk_11_0`,
this includes dependencies of build tools like `xcbuild`.

For convenience `darwin.apple_sdk_11_0` has a `callPackage` attribute
which provides the correct `stdenv` and `xcbuild` attributes as
arguments. This function can be expanded to substitute other necessary
arguments when they come up.

(cherry picked from commit 00336e25bd)
2022-10-07 23:27:52 +01:00
Robert Scott
00120309a3 Merge pull request #194145 from reckenrode/apple_sdk_11_0-backport
[backport release-22.05] apple_sdk_11_0: make available for use on x86_64-darwin
2022-10-07 22:55:35 +01:00
Martin Weinelt
9ecc270f02 Merge pull request #194641 from NixOS/backport-191101-to-release-22.05 2022-10-07 10:40:27 +02:00
Michele Guerini Rocco
a4f6ec1cf0 Merge pull request #194787 from NixOS/backport-194655-to-release-22.05
[Backport release-22.05] libreswan: 4.7 -> 4.8
2022-10-07 08:45:22 +02:00
Winter
7db3a9e6ab jemalloc: fix building emulated x86_64-darwin on aarch64-darwin
(cherry picked from commit f97ed85bae from PR #193638)
It won't build on Hydra now; this should fix that.
https://hydra.nixos.org/build/193545147
2022-10-07 04:40:30 +02:00
zowoq
0567824639 rustc: fix building emulated x86_64-darwin with jemalloc on aarch64-darwin
Co-authored-by: Randy Eckenrode <randy@largeandhighquality.com>
Co-authored-by: Uri Baghin <uri@canva.com>
Co-authored-by: Winter <winter@winter.cafe>

(cherry picked from commit 0be05bd970 in PR #193403)
It won't build on Hydra now; this should fix that.
https://hydra.nixos.org/build/193561576
2022-10-07 04:37:15 +02:00
github-actions[bot]
b34d0b0a01 Merge staging-next-22.05 into staging-22.05 2022-10-07 00:24:46 +00:00
github-actions[bot]
7325f18825 Merge release-22.05 into staging-next-22.05 2022-10-07 00:24:11 +00:00
Robert Scott
2f516fbf27 strongswan: add patch for CVE-2022-40617 2022-10-06 21:03:43 +01:00
Martin Weinelt
ca025d52b5 Merge pull request #194764 from NixOS/backport-194660-to-release-22.05 2022-10-06 21:59:15 +02:00
rnhmjoj
31fc502b12 libreswan: 4.7 -> 4.8
Note: this also fixes DNSSEC support, which was enabled but not working
due to the (most likely) missing DNS root file.

(cherry picked from commit f288df00cb)
2022-10-06 18:39:34 +00:00
Bernardo Meurer
7128ccee58 Merge pull request #194777 from zhaofengli/mesa-radv-overrides-22.05 2022-10-06 15:25:39 -03:00
Bernardo Meurer
986c54971b Merge pull request #194773 from NixOS/backport-194761-to-release-22.05 2022-10-06 15:25:35 -03:00
Maximilian Bosch
370b42a605 Merge pull request #194745 from Ma27/backport-kernel-updates
[22.05] Linux kernel updates 2022-10-06
2022-10-06 19:21:45 +02:00
Zhaofeng Li
8f84bf6ff6 mesa: Install radv override configs into $out
Without this, the per-game radv overrides aren't applied.
2022-10-06 11:09:40 -06:00
Yaya
d173fee8ae nextcloud: 23.0.9 -> 23.0.10, 24.0.5 -> 24.0.6
https://nextcloud.com/changelog/#latest23
https://nextcloud.com/changelog/#latest24
(cherry picked from commit 5234adeffe)
2022-10-06 16:39:13 +00:00
Martin Weinelt
1979c732ad dhcp: 4.4.3 -> 4.4.3-P1
https://downloads.isc.org/isc/dhcp/4.4.3-P1/dhcp-4.4.3-P1-RELNOTES
https://www.openwall.com/lists/oss-security/2022/10/05/1

Fixes: CVE-2022-2928, CVE-2022-2929
(cherry picked from commit f340a34482)
2022-10-06 15:04:17 +00:00
Wout Mertens
ed9b904c5e Merge pull request #194755 from NixOS/backport-183028-to-release-22.05
[Backport release-22.05] nixos/restic: add 'backups.package' option to override the restic package
2022-10-06 16:20:44 +02:00
github-actions[bot]
4224eb717f nixos/restic: use postStop for backupCleanupCommand (#194756)
That way the `backupCleanupCommand` can also run when the backup service
failed for some reason.

Fixes: #182089.
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit 7e8e00d656)

Co-authored-by: Otavio Salvador <otavio@ossystems.com.br>
2022-10-06 16:10:52 +02:00
Winter
6ed53485c6 Update nixos/tests/restic.nix
(cherry picked from commit d87db50c5e65beed3010db62e491391fdc2827a8)
2022-10-06 14:04:00 +00:00
Winter
88dc88b113 Update nixos/modules/services/backup/restic.nix
(cherry picked from commit dfa3f7e414bea889a09ed033ef7cef30741d255e)
2022-10-06 14:04:00 +00:00
Alan Strohm
7a2fe0893e nixos/restic: add 'backups.package' option to override the restic package.
Fixes #176314

Also allows for using a wrapped version of restic with special
capabilities as described in the [restic
docs](https://restic.readthedocs.io/en/latest/080_examples.html#backing-up-your-system-without-running-restic-as-root)

(cherry picked from commit ef1561847a747a450c8f4d046e9c28f0bbb44ef6)
2022-10-06 14:04:00 +00:00
datafoo
aa74349265 vscode-extensions.elixir-lsp.vscode-elixir-ls: 0.8.0 -> 0.11.0
(cherry picked from commit f947cfaa1d)
2022-10-06 11:09:54 +00:00
Thiago Kenji Okada
f6059b06c2 Merge pull request #194728 from NixOS/backport-188428-to-release-22.05
[Backport release-22.05] vscode-extensions.jakebecker.elixir-ls: 0.9.0 -> 0.11.0
2022-10-06 11:56:15 +01:00
Maximilian Bosch
cb5fd3fd36 linux/hardened/patches/5.4: 5.4.214-hardened1 -> 5.4.215-hardened1
(cherry picked from commit 287084ca5b)
2022-10-06 11:49:37 +02:00
Maximilian Bosch
a6ff9a26c2 linux/hardened/patches/5.19: 5.19.11-hardened1 -> 5.19.12-hardened1
(cherry picked from commit 5ececd27af)
2022-10-06 11:49:37 +02:00
Maximilian Bosch
867fc5e144 linux/hardened/patches/5.15: 5.15.70-hardened1 -> 5.15.71-hardened1
(cherry picked from commit 650325d345)
2022-10-06 11:49:37 +02:00
Maximilian Bosch
9d52788d26 linux/hardened/patches/5.10: 5.10.145-hardened1 -> 5.10.146-hardened1
(cherry picked from commit e10301dd2a)
2022-10-06 11:49:36 +02:00
Maximilian Bosch
a9c1d06e94 linux/hardened/patches/4.19: 4.19.259-hardened1 -> 4.19.260-hardened1
(cherry picked from commit 9ba817f60b)
2022-10-06 11:49:36 +02:00
Maximilian Bosch
bd0e7d597d linux/hardened/patches/4.14: 4.14.294-hardened1 -> 4.14.295-hardened1
(cherry picked from commit 6a9fb21418)
2022-10-06 11:49:36 +02:00
Maximilian Bosch
5991c7669e linux_latest-libre: 18916 -> 18950
(cherry picked from commit 1db3d28892)
2022-10-06 11:49:36 +02:00
Maximilian Bosch
c4eb8460b3 linux: 5.4.215 -> 5.4.216
(cherry picked from commit a8ad1882c1)
2022-10-06 11:49:35 +02:00
Maximilian Bosch
b09a3bb9f5 linux: 5.15.71 -> 5.15.72
(cherry picked from commit addb39984d)
2022-10-06 11:49:35 +02:00
Maximilian Bosch
904adb408a linux: 5.10.146 -> 5.10.147
(cherry picked from commit 6ea285206d)
2022-10-06 11:49:35 +02:00
Maximilian Bosch
01e820a5d7 linux: 4.19.260 -> 4.19.261
(cherry picked from commit d7920e2ded)
2022-10-06 11:49:35 +02:00
superherointj
43625ea7e7 vscode-extensions.jakebecker.elixir-ls: 0.9.0 -> 0.11.0
(cherry picked from commit 582533460829800f04016a7363b46b5d94e25a3d)
2022-10-06 08:53:52 +00:00
Daniel Olsen
d02f0a5f1d hydrus: 495 -> 501 2022-10-06 10:43:33 +02:00
Mario Rodas
102eac5212 Merge pull request #194650 from NixOS/backport-194632-to-release-22.05
[Backport release-22.05] chromium: 106.0.5249.61 -> 106.0.5249.91
2022-10-05 23:06:06 -05:00
github-actions[bot]
519a6f1ffc Merge staging-next-22.05 into staging-22.05 2022-10-06 00:21:56 +00:00
github-actions[bot]
dfc2bc3c44 Merge release-22.05 into staging-next-22.05 2022-10-06 00:21:22 +00:00
Michele Guerini Rocco
aef5547ea8 Merge pull request #194635 from rnhmjoj/pr-monero-back
[22.05] monero-{cli,gui}: 0.18.1.1 -> 0.18.1.2
2022-10-05 23:35:02 +02:00
Michael Weiss
b73813be24 chromium: 106.0.5249.61 -> 106.0.5249.91
https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_30.html

This update includes 3 security fixes.

CVEs:
CVE-2022-3370 CVE-2022-3373

(cherry picked from commit ff92f35b83)
2022-10-05 21:06:09 +00:00
Michael Weiss
223f4d34b2 chromedriver: Disable on aarch64-darwin
chromedriver_mac64_m1.zip is currently not available anymore and I do not have time to look into it:
path is '/nix/store/zhz7hrk94dc0dn7a42czhd1nz9142826-chromedriver_mac64.zip'
nix-prefetch-url https://chromedriver.storage.googleapis.com/106.0.5249.61/chromedriver_mac64_m1.zip
error: unable to download 'https://chromedriver.storage.googleapis.com/106.0.5249.61/chromedriver_mac64_m1.zip': HTTP error 404

       response body:

       <?xml version='1.0' encoding='UTF-8'?><Error><Code>NoSuchKey</Code><Message>The specified key does not exist.</Message><Details>No such object: chromedriver/106.0.5249.61/chromedriver_mac64_m1.zip</Details></Error>

(cherry picked from commit 3d50284bb2)
2022-10-05 21:06:09 +00:00
Michael Weiss
e4de735bd3 Merge pull request #194633 from NixOS/backport-194239-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 106.0.5249.62 -> 106.0.5249.91
2022-10-05 23:00:54 +02:00
R. Ryantm
12e5182dfc python310Packages.jwcrypto: 1.3.1 -> 1.4.2
(cherry picked from commit a9133913e4)
2022-10-05 20:26:06 +00:00
Robert Scott
01e470355e Merge pull request #193986 from risicle/ris-wolfssl-5.5.1-r22.05
[22.05] wolfssl: 5.3.0 -> 5.5.1
2022-10-05 21:04:21 +01:00
Michael Adler
21c7309246 ungoogled-chromium: 106.0.5249.62 -> 106.0.5249.91
(cherry picked from commit d1c2066afb)
2022-10-05 18:28:20 +00:00
R. Ryantm
3d992d5749 monero-gui: 0.18.1.1 -> 0.18.1.2
(cherry picked from commit 65bc1cda0f)
2022-10-05 20:28:18 +02:00
R. Ryantm
b5221436ee monero-cli: 0.18.1.1 -> 0.18.1.2
(cherry picked from commit 463e3d3b32)
2022-10-05 20:28:10 +02:00
Vladimír Čunát
ccd6a79b83 Merge #194625: linux: 5.19.12 -> 5.19.14
...into release-22.05
2022-10-05 19:21:07 +02:00
Vladimír Čunát
268fa5e3ba linux_5_19: 5.19.13 -> 5.19.14
(cherry picked from commit 35955e360c)
2022-10-05 17:19:37 +00:00
Kylie McClain
8c9dfb4cf4 linux: 5.19.12 -> 5.19.13
(cherry picked from commit c736ed13b2)
2022-10-05 17:19:37 +00:00
Martin Weinelt
c8ad27fe6d Merge pull request #194477 from mweinelt/22.05/django-4.0.8 2022-10-05 16:37:54 +02:00
Jake Hill
fb64a00d28 opcr-policy: init at 0.1.42
(cherry picked from commit 14bb4ee9b7)
2022-10-05 10:51:30 +00:00
Jake Hill
b604cd027d maintainers: add naphta
(cherry picked from commit 3646a7561f)
2022-10-05 10:51:30 +00:00
Martin Weinelt
78342239aa Merge pull request #194522 from NixOS/backport-194471-to-release-22.05 2022-10-05 05:13:37 +02:00
Mario Rodas
ccf5510a8d Merge pull request #194384 from NixOS/backport-194369-to-release-22.05
[Backport release-22.05] yt-dlp: 2022.9.1 -> 2022.10.4
2022-10-04 22:13:07 -05:00
Franz Pletz
a6ca6dc4bc Merge pull request #194427 from NixOS/backport-194405-to-release-22.05
[Backport release-22.05] zfs: 2.1.5 → 2.1.6
2022-10-05 04:32:36 +02:00
Martin Weinelt
bff3ff018a python3Packages.django_3: 3.2.15 -> 3.2.16
https://docs.djangoproject.com/en/3.2/releases/3.2.16/
https://www.djangoproject.com/weblog/2022/oct/04/security-releases/

Fixes: CVE-2022-41323
(cherry picked from commit b1dca5596e)
2022-10-05 03:28:04 +02:00
Martin Weinelt
dc11432a95 Merge pull request #194526 from NixOS/backport-194523-to-release-22.05 2022-10-05 03:04:18 +02:00
Martin Weinelt
4ddd552f64 usbimager: Fix filechooser dialog
Closes: #193985
(cherry picked from commit e338844d90)
2022-10-05 01:00:05 +00:00
Martin Weinelt
02363087dd firefox-bin-unwrapped: 105.0.1 -> 105.0.2
https://www.mozilla.org/en-US/firefox/105.0.2/releasenotes/
(cherry picked from commit 766196550b)
2022-10-05 00:30:00 +00:00
Martin Weinelt
285c5bccef firefox-unwrapped: 105.0.1 -> 105.0.2
https://www.mozilla.org/en-US/firefox/105.0.2/releasenotes/
(cherry picked from commit a12dd80a49)
2022-10-05 00:30:00 +00:00
github-actions[bot]
d81eddf840 Merge staging-next-22.05 into staging-22.05 2022-10-05 00:22:07 +00:00
github-actions[bot]
f5cb9e222d Merge release-22.05 into staging-next-22.05 2022-10-05 00:21:35 +00:00
Martin Weinelt
360052c3d3 python3Packages.django_4: patch in zoneinfo directory
Closes: #187388
(cherry picked from commit f36d79dcb7)
2022-10-04 21:55:36 +02:00
Martin Weinelt
36218e9c88 python3Packages.django_4: 4.0.7 -> 4.0.8
https://docs.djangoproject.com/en/4.0/releases/4.0.8/
https://www.djangoproject.com/weblog/2022/oct/04/security-releases/

Fixes: CVE-2022-41323
2022-10-04 21:55:04 +02:00
Bruno Paulin
d81efb7885 vault-medusa: init at 0.3.5
(cherry picked from commit 390fc0a8f3)
2022-10-04 19:21:34 +00:00
Jörg Thalheim
d8e86666ac zfs: 2.1.5 → 2.1.6
(cherry picked from commit 5bae92a715)
2022-10-04 14:05:30 +00:00
Frederik Rietdijk
fe76645aaf "buildPython*: store dist (wheel/sdist) in dist output
Most packages were fixed on python-unstable.

This reverts commit 0a4898c21a.

Note that the hook is NOT added by default so we don't change
behaviour on a stable branch.

(cherry picked from commit 86ab83260f)
2022-10-04 13:43:32 +02:00
Frederik Rietdijk
f31d978ee3 onnnxruntime, python3Packages.onnxruntime: improve packaging
The Python bindings to onnxruntime were added by me in #193188.

Adding Python support this way is not a good way. Here a wheel was
created (which is fine) and installed in a python output. The
propagated-build-inputs file is put in the dev output. That's fine,
except that stdenv.mkDerivation does not automatically add dev when
python is included, because other outputs are only added when no
output is explicitly selected. This means that when you want to use
these bindings in another Python package, pip will complain it cannot
find the dependencies of the bindings.

In this PR, the onnxruntime derivation outputs a wheel in the dist output.
Then, in python-packages.nix we have a separate onnxruntime package
which installs the bindings.

The Python bindings have quite some dependencies which, depending on
your use case, are not required. Thus the dependency relax hook is
used to remove some of these dependencies.

Note there is also an issue with protobuf versions. The onnxruntime
bindings require an older protobuf and Python protobuf which we
cannot offer. Thus protobuf is also removed as Python dependency.

(cherry picked from commit 34d1d336ad)
2022-10-04 13:43:32 +02:00
Mario Rodas
3a4305233e yt-dlp: 2022.9.1 -> 2022.10.4
https://github.com/yt-dlp/yt-dlp/releases/tag/2022.10.04
(cherry picked from commit be3f2e8554)
2022-10-04 09:49:11 +00:00
Philipp Middendorf
4048eeb6c7 crystfel-headless: fix wrapProgram dependency
(cherry picked from commit f893f28019)
2022-10-04 08:52:02 +00:00
github-actions[bot]
cdd545ac76 Merge staging-next-22.05 into staging-22.05 2022-10-04 00:22:31 +00:00
github-actions[bot]
e931ff4e74 Merge release-22.05 into staging-next-22.05 2022-10-04 00:22:00 +00:00
Robert Scott
574f4f298c vault-bin: 1.10.5 -> 1.10.6 2022-10-03 17:15:10 -04:00
Robert Scott
723ea19cc1 vault: 1.10.5 -> 1.10.6 2022-10-03 17:15:10 -04:00
Vladimír Čunát
5761686744 Merge branch 'staging-22.05' into staging-next-22.05 2022-10-03 22:09:36 +02:00
Vladimír Čunát
f937ae9217 Merge #194231: nss: 3.68.4 -> 3.79.1
...into staging-22.05
2022-10-03 22:08:33 +02:00
Vladimír Čunát
293603025c Merge #194055: dnsmasq: add patch for CVE-2022-0934
...into staging-22.05
2022-10-03 22:05:53 +02:00
Domen Kožar
ea70247475 Merge pull request #192742 from NixOS/22.05-piperwire
[22.05] pipewire backports
2022-10-03 18:15:40 +02:00
Vladimír Čunát
0ed6ed080c Merge #191317: glibc locales: fix on cross endian
...into staging-22.05
2022-10-03 17:42:55 +02:00
Martin Weinelt
b68543734c nss: 3.68.4 -> 3.79.1
The 3.68.4 release was the last of the 3.68 ESR series and 3.79 is the
new ESR series.

https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_79.html
https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_79_1.html
(cherry picked from commit d1e2a371f0)
2022-10-03 14:34:30 +00:00
maxine
81a3237b64 Merge pull request #194191 from vcunat/p/docker-22.05 2022-10-03 11:51:48 +02:00
Vladimír Čunát
0adc445063 docker: fix build by using go 1.18
Broken probably since update in 749fbb8 (PR #193197)
2022-10-03 10:11:32 +02:00
Vincent Laporte
21d04197e1 gajim: 1.4.7 → 1.5.1
(cherry picked from commit 61be216937,
with nbxmpp override added)
2022-10-03 08:01:08 +02:00
Randy Eckenrode
1378de64a8 apple_sdk_11_0: provide SDK-specific callPackage
(cherry picked from commit 9659c7a)
2022-10-02 21:32:19 -04:00
Randy Eckenrode
0310f2fa16 apple_sdk_11_0: expose 11.0 sdk stdenv as an attribute
(cherry picked from commit 4741402)
2022-10-02 21:31:54 -04:00
Randy Eckenrode
82f309e924 apple_sdk_11_0: fix build on x86_64-darwin and expose as attribute
(cherry picked from commit d8f7177)
2022-10-02 21:30:26 -04:00
github-actions[bot]
a959ce466f Merge staging-next-22.05 into staging-22.05 2022-10-03 00:20:43 +00:00
github-actions[bot]
68ce87bbe4 Merge release-22.05 into staging-next-22.05 2022-10-03 00:20:14 +00:00
Robert Scott
038b71b753 Merge pull request #194124 from LeSuisse/mediawiki-1.37.6-22.05
[22.05] mediawiki: 1.37.4 -> 1.37.6
2022-10-03 00:35:58 +01:00
Robert Scott
6577871f2e Merge pull request #194091 from NixOS/backport-194046-to-release-22.05
[Backport release-22.05] darkhttpd: 1.13 -> 1.14
2022-10-03 00:35:13 +01:00
Thomas Gerbet
9454d1c249 mediawiki: 1.37.4 -> 1.37.6
Fixes CVE-2022-41767, CVE-2022-41765 and CVE-2022-41767.

https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/SPYFDCGZE7KJNO73ET7QVSUXMHXVRFTE/
https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/thread/DMQKMFSH4K7KLBXWZTDBGI2PWLLHJHJZ/
2022-10-03 00:39:09 +02:00
Robert Scott
09c1b4e8a8 Merge pull request #193952 from NixOS/backport-193408-to-release-22.05
[Backport release-22.05] apacheKafka: 2.8.1 -> 2.8.2
2022-10-02 22:28:15 +01:00
Robert Scott
2a57890da5 Merge pull request #193951 from NixOS/backport-192740-to-release-22.05
[Backport release-22.05] mysql57: 5.7.37 -> 5.7.39
2022-10-02 17:30:05 +01:00
Thomas Gerbet
cddc3cb996 darkhttpd: 1.13 -> 1.14
https://github.com/emikulic/darkhttpd/releases/tag/v1.14

Fixes CVE-2020-25691.

(cherry picked from commit 573ee6b58c)
2022-10-02 15:35:45 +00:00
Solene Rapenne
52a85302d7 nixos/fail2ban: improve module documentation
(cherry picked from commit 605a588ea6)
2022-10-02 15:15:17 +00:00
Bobby Rong
814644ab7b Merge pull request #193433 from NixOS/backport-193380-to-release-22.05
[Backport release-22.05] signal-desktop: 5.60.0 -> 5.61.0
2022-10-02 21:40:04 +08:00
Robert Scott
67c6c43685 dnsmasq: add patch for CVE-2022-0934 2022-10-02 12:20:52 +01:00
Yorick van Pelt
82b6e4dedc libcamera: unstable-2022-09-03 -> unstable-2022-09-15
(cherry picked from commit fa44ead700)
Signed-off-by: Domen Kožar <domen@dev.si>
(cherry picked from commit 29a89385c30c13d8cebaad1404ee1035c28e62d9)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-10-02 12:04:00 +01:00
K900
58b60c961a libcamera: unstable-2022-07-15 -> unstable-2022-09-03
(cherry picked from commit 851e74a2f1)
Signed-off-by: Domen Kožar <domen@dev.si>
(cherry picked from commit 2b8f5d631b5c0a8448526f2b74947397d6dc30a7)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-10-02 12:03:56 +01:00
Martin Weinelt
6a1be2f69e libcamera: 2022-01-03 -> 2022-07-15
Fixes the documentation build with sphinx 5.0

(cherry picked from commit b4e278209f)
Signed-off-by: Domen Kožar <domen@dev.si>
(cherry picked from commit 385e3646da5fdb3b22d6ac13944fb40bb1331b33)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-10-02 12:03:50 +01:00
K900
6b844875c8 pipewire: 0.3.57 -> 0.3.58
(cherry picked from commit 48bf1dd780)
Signed-off-by: Domen Kožar <domen@dev.si>
(cherry picked from commit 1bc120c7088d2dcc12221d383d6fc92205f0262c)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-10-02 12:03:45 +01:00
K900
4c1b72b2c5 pipewire: 0.3.56 -> 0.3.57
(cherry picked from commit 092f4eb681)
Signed-off-by: Domen Kožar <domen@dev.si>
(cherry picked from commit 7f4c844d6b010704f83a61f6cb0aaa43c28e1ab1)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-10-02 12:03:35 +01:00
Fredrik Bergroth
164f94bbea wireplumber: backport a fix for bluetooth rescan loops
(cherry picked from commit cd07396027)
Signed-off-by: Domen Kožar <domen@dev.si>
(cherry picked from commit 0852e9fa32faf7e5d798bcf71977169a28b30d77)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-10-02 12:03:30 +01:00
K900
c937817dac pipewire: 0.3.55 -> 0.3.56
(cherry picked from commit bbe8931b36)
Signed-off-by: Domen Kožar <domen@dev.si>
(cherry picked from commit 1accc46f5b9b1e1d38df480ddcf3585d737c161a)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-10-02 12:03:23 +01:00
K900
3d36cae07f pipewire: import upstream-recommended crash fix patch
(cherry picked from commit 4145580102)
Signed-off-by: Domen Kožar <domen@dev.si>
(cherry picked from commit 8a142a1d8828e5d42f7f37f3c79a4cc169572866)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-10-02 12:03:19 +01:00
K900
405fb5a356 pipewire: 0.3.54 -> 0.3.55, fix pw-v4l2
(cherry picked from commit 11c43f0a13)
Signed-off-by: Domen Kožar <domen@dev.si>
(cherry picked from commit 817d1cef58a10ca55256a84c8bb630496867da91)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-10-02 12:03:14 +01:00
K900
a43fcc00cf wireplumber: backport a fix for no sound in VMs
(cherry picked from commit 41c194565f)
Signed-off-by: Domen Kožar <domen@dev.si>
(cherry picked from commit a75535a641e9e97f7389e66a411cc2c5a600d4f5)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-10-02 12:03:09 +01:00
Jan Solanti
461d9e3ecf pipewire: 0.3.53 -> 0.3.54
(cherry picked from commit 844f03a9dd)
Signed-off-by: Domen Kožar <domen@dev.si>
(cherry picked from commit 07f5f0a6e583a2e38870a41c6b477607312f346b)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-10-02 12:03:04 +01:00
Jan Solanti
62ff7392ff pipewire: 0.3.52 -> 0.3.53
(cherry picked from commit a11073eef8)
Signed-off-by: Domen Kožar <domen@dev.si>
(cherry picked from commit c2e167863de519165b6dd33ca6333f0ab4875739)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-10-02 12:02:59 +01:00
K900
ca31abf214 wireplumber: 0.4.10 -> 0.4.11
(cherry picked from commit 75ec318b80)
Signed-off-by: Domen Kožar <domen@dev.si>
(cherry picked from commit af1387db3bfcabd0ade71237195513d5f3f98238)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-10-02 12:02:50 +01:00
Vincent Bernat
fc345604bc pipewire: 0.3.51 -> 0.3.52
New LC3plus codec is not enabled as it is not packaged in nixpkgs. The
source is available from ETSI as a [ZIP file][].

[ZIP file]: https://www.etsi.org/deliver/etsi_ts/103600_103699/103634/01.03.01_60/ts_103634v010301p0.zip

(cherry picked from commit 11a818b768)
(cherry picked from commit 9d181d384c9a56ca346bc95b7ec7f680b83538c3)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-10-02 12:02:42 +01:00
Christian Kampka
c1d4445550 pipewire: add option to disable systemd support
(cherry picked from commit 50b21c666f)
Signed-off-by: Domen Kožar <domen@dev.si>
(cherry picked from commit ca3f8ed2c461c10d1240b0a742912e2316d53cdf)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-10-02 12:02:29 +01:00
maxine
749fbb8ce0 Merge pull request #193197 from NixOS/backport-190489-to-release-22.05
[Backport release-22.05] docker: 20.10.17 -> 20.10.18
2022-10-02 12:30:27 +02:00
Maximilian Bosch
d077310acc Merge pull request #193958 from NixOS/backport-193561-to-release-22.05
[Backport release-22.05] Linux kernel updates 2022-09-29
2022-10-02 08:01:34 +02:00
Bobby Rong
62d362b597 Merge pull request #194013 from NixOS/backport-192967-to-release-22.05
[Backport release-22.05] iio-sensor-proxy: update homepage
2022-10-02 09:33:05 +08:00
Weathercold
d39b7af419 iio-sensor-proxy: update homepage
The github repo is archived, change to gitlab.

(cherry picked from commit be28a3a7f7)
2022-10-02 01:21:05 +00:00
github-actions[bot]
790da4fc9c Merge staging-next-22.05 into staging-22.05 2022-10-02 00:23:00 +00:00
github-actions[bot]
c048831bbb Merge release-22.05 into staging-next-22.05 2022-10-02 00:22:32 +00:00
adisbladis
07ee4f771e Merge pull request #193992 from AndersonTorres/BACKPORT-2205
[Backport 22.05] Merge pull request #191769 from osama-re/melpa-fetchers-v2
2022-10-02 12:00:45 +13:00
Anderson Torres
7497d607ea Merge pull request #191769 from osama-re/melpa-fetchers-v2
emacs: fix emacs packages with new fetchers
2022-10-01 19:31:52 -03:00
Robert Scott
173a0601a5 wolfssl: 5.5.0 -> 5.5.1
(cherry picked from commit d70ab7b97e)
2022-10-01 22:49:14 +01:00
Thomas Gerbet
6cbac86e91 wolfssl: 5.4.0 -> 5.5.0
https://github.com/wolfSSL/wolfssl/releases/tag/v5.5.0-stable
Fixes CVE-2022-38152 and CVE-2022-38153.

(cherry picked from commit 736ad733a8)
2022-10-01 22:49:13 +01:00
Fabian Affolter
6e8bc4f3a6 wolfssl: 5.3.0 -> 5.4.0
CVE-2020-12966: https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1013
CVE-2021-46744: https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1033
(cherry picked from commit c56b9f8bad)
2022-10-01 22:49:06 +01:00
Robert Scott
56ee6d1924 Merge pull request #193955 from NixOS/backport-193766-to-release-22.05
[Backport release-22.05] discourse: 2.9.0.beta9 -> 2.9.0.beta10
2022-10-01 22:30:31 +01:00
Maximilian Bosch
84bb85f12d linux/hardened/patches/5.4: 5.4.212-hardened1 -> 5.4.214-hardened1
(cherry picked from commit e1663a8c95)
2022-10-01 18:33:44 +00:00
Maximilian Bosch
a8aeca85a7 linux/hardened/patches/5.19: 5.19.8-hardened2 -> 5.19.11-hardened1
(cherry picked from commit b0e81ef64f)
2022-10-01 18:33:44 +00:00
Maximilian Bosch
08e45dda44 linux/hardened/patches/5.15: 5.15.67-hardened1 -> 5.15.70-hardened1
(cherry picked from commit 815763c425)
2022-10-01 18:33:44 +00:00
Maximilian Bosch
0cb59351cc linux/hardened/patches/5.10: 5.10.142-hardened1 -> 5.10.145-hardened1
(cherry picked from commit d1973863ae)
2022-10-01 18:33:44 +00:00
Maximilian Bosch
025e906c45 linux/hardened/patches/4.19: 4.19.257-hardened1 -> 4.19.259-hardened1
(cherry picked from commit 017d461dba)
2022-10-01 18:33:43 +00:00
Maximilian Bosch
d4707ec763 linux/hardened/patches/4.14: 4.14.292-hardened1 -> 4.14.294-hardened1
(cherry picked from commit 2ba1ad5ec6)
2022-10-01 18:33:43 +00:00
Maximilian Bosch
c2f7d26264 linux-rt_5_10: 5.10.140-rt73 -> 5.10.145-rt74
(cherry picked from commit 6b330d1541)
2022-10-01 18:33:43 +00:00
Maximilian Bosch
8bf5c52cac linux: 5.4.214 -> 5.4.215
(cherry picked from commit a5c28a9c5e)
2022-10-01 18:33:43 +00:00
Maximilian Bosch
ff8b4aaf30 linux: 5.19.11 -> 5.19.12
(cherry picked from commit 66b26bf7a4)
2022-10-01 18:33:43 +00:00
Maximilian Bosch
5210952f83 linux: 5.15.70 -> 5.15.71
(cherry picked from commit 5ac099eb6f)
2022-10-01 18:33:43 +00:00
Maximilian Bosch
7847a440d3 linux: 5.10.145 -> 5.10.146
(cherry picked from commit ec62edf17e)
2022-10-01 18:33:43 +00:00
Maximilian Bosch
91192e535f linux: 4.9.329 -> 4.9.330
(cherry picked from commit 8e60fc74fc)
2022-10-01 18:33:43 +00:00
Maximilian Bosch
84ca72609d linux: 4.19.259 -> 4.19.260
(cherry picked from commit f0a698ea9f)
2022-10-01 18:33:43 +00:00
Maximilian Bosch
b6dde6613b linux: 4.14.294 -> 4.14.295
(cherry picked from commit fa19b5af63)
2022-10-01 18:33:43 +00:00
Robert Scott
7204b6d3ad Merge pull request #193950 from NixOS/backport-192915-to-release-22.05
[Backport release-22.05] wasm3: add many knownVulnerabilities
2022-10-01 18:48:21 +01:00
Ryan Mulligan
390b27244c discourse: 2.9.0.beta9 -> 2.9.0.beta10
(cherry picked from commit 3005b8858e)
2022-10-01 17:42:36 +00:00
Robert Scott
40a5c796cf frr: add patch for CVE-2022-37032
(cherry picked from commit 118179f32a)
2022-10-01 17:35:00 +00:00
Robert Scott
7c37be6567 apacheKafka: 2.8.1 -> 2.8.2
(cherry picked from commit 2226cca1ed)
2022-10-01 17:32:23 +00:00
Thomas Gerbet
ddc10d4318 mysql57: 5.7.37 -> 5.7.39
Fixes CVE-2022-21417, CVE-2022-21427, CVE-2022-21451, CVE-2022-21444 and CVE-2022-21460
See https://www.oracle.com/security-alerts/cpuapr2022.html#AppendixMSQL

Changelogs:
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-39.html
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-38.html
(cherry picked from commit 06c9198cbf)
2022-10-01 17:31:16 +00:00
Robert Scott
115e5c9f96 wasm3: add many knownVulnerabilities
(cherry picked from commit 25dbfa36fd)
2022-10-01 17:30:54 +00:00
Elis Hirwing
8595fb1d7a Merge pull request #193721 from helsinki-systems/backport-193653-to-release-22.05
[22.05] php: 8.0.23 -> 8.0.24, 8.1.10 -> 8.1.11, 7.4.30 -> 7.4.32
2022-10-01 17:14:35 +02:00
Guillaume Girol
ff6543e3e2 Merge pull request #193916 from NixOS/backport-193897-to-release-22.05
[Backport release-22.05] python3Packages.matrix-nio: 0.19.0 -> 0.20.0
2022-10-01 15:12:22 +00:00
Robert Scott
ae00f4b112 pantalaimon: 0.10.4 -> 0.10.5
(cherry picked from commit 92ea9b65d8)
2022-10-01 14:47:32 +00:00
Robert Scott
9c9c1b3554 python3Packages.matrix-nio: 0.19.0 -> 0.20.0
(cherry picked from commit f3cf5a0912)
2022-10-01 14:47:32 +00:00
Vladimír Čunát
79caff6214 Merge #193118: libbpf 0.7.0 -> 0.8.1, bpftrace: 0.14.1 -> 0.15.0
...into staging-22.05
2022-10-01 16:05:52 +02:00
Robert Scott
01f549f581 Merge pull request #193367 from mweinelt/22.05/protobuf-3.19.5
[staging-22.05] protobuf3_19: 3.19.4 -> 3.19.5
2022-10-01 14:24:10 +01:00
Martin Weinelt
a04352e7d8 Merge pull request #193747 from mweinelt/22.05/squid 2022-10-01 14:37:15 +02:00
Martin Weinelt
adeda8b9b9 squid: enable parallel building
(cherry picked from commit c1ec1f33b6)
2022-10-01 14:06:38 +02:00
Martin Weinelt
41b9c7c14a squid: Address security advisories 2022.1 and 2022.2
Fixes: CVE-2022-41317, CVE-2022-41318
2022-10-01 14:06:20 +02:00
R. Ryantm
9cac458502 shellhub-agent: 0.10.2 -> 0.10.3
(cherry picked from commit 6e213b6243)
2022-10-01 11:20:36 +08:00
Robert Scott
c7c45d325f erlangR22: mark with knownVulnerabilities CVE-2022-37026
(cherry picked from commit 21a72508a65e9d64ae146b423ffb973c1597143e)
2022-10-01 11:07:15 +09:00
Robert Scott
233729cdb4 erlangR21: mark with knownVulnerabilities CVE-2022-37026
(cherry picked from commit 2f600e3f8224c0f9650ad6ded79b0b2f54d57e6a)
2022-10-01 11:07:15 +09:00
Robert Scott
38644f709f erlangR23: 23.3.4.10 -> 23.3.4.17
(cherry picked from commit 6d7fb709aa8ebad45578d48ac2a86f7308cb7e1d)
2022-10-01 11:07:15 +09:00
Robert Scott
9e1287b510 erlangR24: 24.2 -> 24.3.4.5
(cherry picked from commit 4afe51e57155cd49d2fc6d988ac7ebad0cad0172)
2022-10-01 11:07:15 +09:00
github-actions[bot]
c5f1086e9c Merge staging-next-22.05 into staging-22.05 2022-10-01 00:24:48 +00:00
github-actions[bot]
eb3e2e738b Merge release-22.05 into staging-next-22.05 2022-10-01 00:24:15 +00:00
superherointj
8d1918bb4b Merge pull request #193749 from NixOS/backport-193549-to-release-22.05
[Backport release-22.05] librewolf: 105.0-1 -> 105.0.1-1
2022-09-30 15:09:25 -03:00
squalus
beef6dd6e9 librewolf: 105.0-1 -> 105.0.1-1
(cherry picked from commit 2fa99053a6)
2022-09-30 17:49:07 +00:00
superherointj
6d1bf99be1 Merge pull request #192480 from NixOS/backport-192464-to-release-22.05
[Backport release-22.05] librewolf: 104.0-1 -> 105.0-1
2022-09-30 14:42:12 -03:00
Vladimír Čunát
3c549a8eb4 Merge #193557: thunderbird*: 102.3.0 -> 102.3.1
...into release-22.05
2022-09-30 18:17:23 +02:00
ajs124
7598627dc6 php74: 7.4.30 -> 7.4.32
not a backport because master does not have php74 anymore
2022-09-30 16:40:53 +02:00
Pol Dellaiera
1ef3169437 php81: 8.1.10 -> 8.1.11
(cherry picked from commit 51ada90c64)
2022-09-30 16:28:40 +02:00
Pol Dellaiera
92ebcfc7a6 php80: 8.0.23 -> 8.0.24
(cherry picked from commit 0d87d2232a)
2022-09-30 16:28:26 +02:00
github-actions[bot]
b22e7be3c4 Merge staging-next-22.05 into staging-22.05 2022-09-30 00:26:32 +00:00
github-actions[bot]
5f85b22709 Merge release-22.05 into staging-next-22.05 2022-09-30 00:26:02 +00:00
Martin Weinelt
c9389643ae Merge pull request #193592 from NixOS/backport-193582-to-release-22.05 2022-09-30 00:45:21 +02:00
Yaya
303cb7cea0 gitlab: 15.4.0 -> 15.4.1
https://about.gitlab.com/releases/2022/09/29/security-release-gitlab-15-4-1-released/

Fixes CVE-2022-3283 CVE-2022-3060 CVE-2022-2904 CVE-2022-3018
      CVE-2022-3291 CVE-2022-3067 CVE-2022-2882 CVE-2022-3066
      CVE-2022-3286 CVE-2022-3285 CVE-2022-3330 CVE-2022-3351
      CVE-2022-3288 CVE-2022-3293 CVE-2022-3279 CVE-2022-3325
      CVE-2022-31107

(cherry picked from commit 6609c223b0)
2022-09-29 22:10:53 +00:00
Michael Weiss
ec8c0ee845 Merge pull request #193411 from NixOS/backport-193391-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 105.0.5195.127 -> 106.0.5249.62
2022-09-29 22:01:22 +02:00
Vladimír Čunát
6a408308b7 thunderbird-bin: 102.3.0 -> 102.3.1
(cherry picked from commit eeb1287c06)
2022-09-29 18:04:41 +00:00
Vladimír Čunát
bddb2ae319 thunderbird: 102.3.0 -> 102.3.1
(cherry picked from commit 95f0a5d608)
2022-09-29 18:04:41 +00:00
Frederik Rietdijk
13cbe534eb Merge pull request #193472 from FRidh/electron 2022-09-29 10:03:53 +02:00
Mihai Fufezan
83caa0c7fb electron_20: 20.1.0 -> 20.1.3 2022-09-29 09:50:00 +02:00
Mihai Fufezan
058b1a41f0 electron_20: 20.0.1 -> 20.1.0 2022-09-29 09:50:00 +02:00
Mihai Fufezan
7bb88a3084 electron_20: init at 20.0.1 2022-09-29 09:49:58 +02:00
Martin Weinelt
1b814a1346 Merge pull request #193438 from mweinelt/22.05/nheko 2022-09-29 03:55:36 +02:00
Martin Weinelt
650dad69cc Merge pull request #193442 from mweinelt/22.05/schildichat 2022-09-29 03:34:39 +02:00
R. Ryantm
ffae8a136e mtxclient: 0.8.0 -> 0.8.2
(cherry picked from commit f123e6324a)
2022-09-29 03:30:23 +02:00
Philipp
5a7e3dd5c8 mtxclient: 0.7.0 -> 0.8.0
(cherry picked from commit cb608633e8)
2022-09-29 03:30:19 +02:00
Martin Weinelt
9e648a8389 Merge pull request #193439 from mweinelt/22.05/cinny 2022-09-29 03:29:06 +02:00
Martin Weinelt
c3f46edbb9 schildichat-{desktop,web}: 1.11.4-sc.1 -> 1.11.8-sc.1
https://github.com/SchildiChat/schildichat-desktop/releases/tag/v1.11.8-sc.1

Fixes: CVE-2022-39249, CVE-2022-39250, CVE-2022-39251, CVE-2022-39236
(cherry picked from commit 64b6dd1215)
2022-09-29 03:26:39 +02:00
Yureka
fbdf0904e5 schildichat-{web,desktop}: 1.10.12-sc.1 -> 1.11.4-sc.1
(cherry picked from commit 5676f32cd6)
2022-09-29 03:26:26 +02:00
Ashish SHUKLA
43b4f45e66 cinny: 2.2.0 -> 2.2.2
(cherry picked from commit c7c8cfba6a)
2022-09-29 03:15:31 +02:00
Ashish SHUKLA
be92e0cd91 cinny: 2.1.3 -> 2.2.0
(cherry picked from commit b1745d3da3)
2022-09-29 03:15:27 +02:00
Ashish SHUKLA
440b8d25c4 cinny: 2.1.2 -> 2.1.3
(cherry picked from commit f79fa14789)
2022-09-29 03:15:23 +02:00
R. Ryantm
3994068efd cinny: 2.1.1 -> 2.1.2
(cherry picked from commit 2db29e2df5)
2022-09-29 03:15:18 +02:00
Ashish SHUKLA
506c787845 cinny: 2.0.4 -> 2.1.1
(cherry picked from commit f51f722597)
2022-09-29 03:15:15 +02:00
Ashish SHUKLA
66387e361d cinny: 2.0.3 -> 2.0.4
(cherry picked from commit 8fb4658bc2)
2022-09-29 03:15:12 +02:00
Philipp
1b46d111e1 nheko: 0.10.1-1 -> 0.10.2
(cherry picked from commit 12d03efffd)
2022-09-29 03:13:12 +02:00
Azat Bahawi
5614fb780b nheko: 0.10.0 -> 0.10.1-1
Fixes a build failure https://hydra.nixos.org/build/190031815

(cherry picked from commit 8676f60f1f)
2022-09-29 03:13:09 +02:00
Philipp
1d023a08f4 nheko: 0.9.3 -> 0.10.0
(cherry picked from commit a3aef504aa)
2022-09-29 03:13:05 +02:00
kilianar
ac4a9b251a signal-desktop: 5.60.0 -> 5.61.0
https://github.com/signalapp/Signal-Desktop/releases/tag/v5.61.0
(cherry picked from commit 5b3a96474c)
2022-09-29 00:53:00 +00:00
github-actions[bot]
3aebd9f9af Merge staging-next-22.05 into staging-22.05 2022-09-29 00:24:00 +00:00
github-actions[bot]
9962ccd32f Merge release-22.05 into staging-next-22.05 2022-09-29 00:23:29 +00:00
Wout Mertens
40eb0ecba1 restic: 0.13.1 -> 0.14.0 (#193324)
(cherry picked from commit 5c7f600e67)

Co-authored-by: Norbert Melzer <timmelzer@gmail.com>
2022-09-29 00:11:48 +02:00
Michael Weiss
60b0a92cbd ungoogled-chromium: 105.0.5195.127 -> 106.0.5249.62
(cherry picked from commit 851375d6e9)
2022-09-28 22:06:34 +00:00
Michael Weiss
dd12dff736 Merge pull request #193392 from NixOS/backport-193224-to-release-22.05
[Backport release-22.05] chromium: 105.0.5195.125 -> 106.0.5249.61
2022-09-28 23:59:09 +02:00
Michael Weiss
5934001ff7 Merge pull request #193389 from primeos/chromium-backport
[22.05] chromium: Backport the beta and dev channel updates
2022-09-28 22:33:48 +02:00
R. Ryantm
895a3209a5 drogon: 1.8.0 -> 1.8.1
(cherry picked from commit f7e74df256)
2022-09-28 20:26:53 +00:00
Michael Weiss
2a884b79fe chromium: 105.0.5195.125 -> 106.0.5249.61
https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_27.html

This update includes 20 security fixes.

CVEs:
CVE-2022-3304 CVE-2022-3201 CVE-2022-3305 CVE-2022-3306 CVE-2022-3307
CVE-2022-3308 CVE-2022-3309 CVE-2022-3310 CVE-2022-3311 CVE-2022-3312
CVE-2022-3313 CVE-2022-3314 CVE-2022-3315 CVE-2022-3316 CVE-2022-3317
CVE-2022-3318

(cherry picked from commit 22efe771f8)
2022-09-28 20:18:08 +00:00
Michael Weiss
9dce85855f chromiumDev: 107.0.5300.0 -> 107.0.5304.10
(cherry picked from commit f0b04d6fed)
2022-09-28 22:07:40 +02:00
Michael Weiss
676ffd2f88 chromiumBeta: 106.0.5249.51 -> 106.0.5249.61
(cherry picked from commit 8af33e21dd)
2022-09-28 22:07:40 +02:00
Michael Weiss
e8dbdc86a0 chromiumBeta: 106.0.5249.40 -> 106.0.5249.51
(cherry picked from commit b9c0438331)
2022-09-28 22:07:39 +02:00
Michael Weiss
1cc42fdf3b chromiumDev: 107.0.5286.2 -> 107.0.5300.0
(cherry picked from commit b7e5d303be)
2022-09-28 22:07:39 +02:00
Michael Weiss
351f07c1d4 chromiumBeta: 106.0.5249.30 -> 106.0.5249.40
(cherry picked from commit bf2d2a7fbb)
2022-09-28 22:07:39 +02:00
Michael Weiss
905d8eb492 chromiumDev: 106.0.5249.21 -> 107.0.5286.2
(cherry picked from commit aaacde1009)
2022-09-28 22:07:38 +02:00
Michael Weiss
d1d2f218d9 chromiumBeta: 106.0.5249.21 -> 106.0.5249.30
(cherry picked from commit 2f761d4a48)
2022-09-28 22:07:38 +02:00
Michael Weiss
fd90924308 chromiumBeta: 105.0.5195.52 -> 106.0.5249.21
(cherry picked from commit 83ada3da7a)
2022-09-28 22:07:38 +02:00
Michael Weiss
e5257b1729 chromiumDev: 106.0.5249.12 -> 106.0.5249.21
(cherry picked from commit f408eee926)
2022-09-28 22:07:37 +02:00
maralorn
b5b04186d2 Merge pull request #193358 from mweinelt/22.05/element
[22.05] element-{web,desktop}: 1.11.5 -> 1.11.8
2022-09-28 20:20:31 +02:00
Martin Weinelt
24750f7dbb element-{desktop,web}: 1.11.7 -> 1.11.8
https://github.com/vector-im/element-web/releases/tag/v1.11.8
(cherry picked from commit ff964e2de0)
2022-09-28 20:06:34 +02:00
Frederik Rietdijk
9bcd37245f python3Packages.skl2onnx: init at 1.13 2022-09-28 10:16:09 -07:00
Frederik Rietdijk
ee8ed3ea11 python3Packages.onnxconverter-common: init at 1.12.2 2022-09-28 10:16:09 -07:00
Frederik Rietdijk
209c8a2a0a onnxruntime: remove oneDNN support and change maintainer
oneDNN version in 22.05 is too old I think.
2022-09-28 10:16:09 -07:00
Frederik Rietdijk
1fce764e71 onnxruntime: add Python support 2022-09-28 10:16:09 -07:00
Christian Kögler
5e755fc8ed onnxruntime: 1.10.0 -> 1.12.1 2022-09-28 10:16:09 -07:00
Brian McKenna
e93bf1d337 onnxruntime: init at 1.10.0 (resurrected) 2022-09-28 10:16:09 -07:00
Martin Weinelt
0621122787 protobuf3_19: 3.19.4 -> 3.19.5
https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-8gq9-2x98-w8hf

Fixes: CVE-2022-1941
(cherry picked from commit c9b98fe8b1)
2022-09-28 19:12:46 +02:00
Philipp
27ab93500a element-{web,desktop}: 1.11.5 -> 1.11.7
(cherry picked from commit 11ec6f92e7)
2022-09-28 18:24:12 +02:00
Martin Weinelt
566dc66533 Merge pull request #192912 from risicle/ris-tensorflow-2.8.1-r22.05 2022-09-28 17:53:10 +02:00
Martin Weinelt
0c97cb06a5 Merge pull request #192622 from mweinelt/22.05/mozilla 2022-09-28 03:31:05 +02:00
Martin Weinelt
ba61f07bc8 Merge pull request #193103 from risicle/ris-joblib-CVE-2022-21797-r22.05 2022-09-28 03:10:25 +02:00
github-actions[bot]
e08312fa0c Merge staging-next-22.05 into staging-22.05 2022-09-28 00:24:29 +00:00
github-actions[bot]
f5922dbc09 Merge release-22.05 into staging-next-22.05 2022-09-28 00:23:53 +00:00
Martin Weinelt
6ba7ee6a88 Merge pull request #193226 from NixOS/backport-193200-to-release-22.05 2022-09-28 01:42:08 +02:00
Dominique Martinet
bad4d76dac linux-kernel config: disable DEBUG_INFO_REDUCED
Linux's aarch64 defconfig has been updated in 5.13 to enable "reduced"
debug infos (upstream commit ed938a4bfc58 ("arm64: defconfig: Use
DEBUG_INFO_REDUCED"), but that commits locks DEBUG_INFO_BTF as noticed
in #175467

This disables it back which should fix bpftrace usage of BTF not working
on newer kernels.

(cherry picked from commit 47f9f04788)
2022-09-27 23:39:52 +01:00
Robert Scott
09ce503f60 Merge pull request #192965 from risicle/ris-bind-9.18.7-r22.05
[22.05] bind: 9.18.3 -> 9.18.7
2022-09-27 21:10:25 +01:00
Domen Kožar
ed5e29234a Merge pull request #193185 from domenkozar/22.05-cachix-bump
[22.05] cachix: 0.8.1 -> 1.0.1
2022-09-27 21:35:34 +02:00
ajs124
9ce5466e6e Merge pull request #192294 from helsinki-systems/upd/mariadb-22.05
[22.05] mariadb: patch release
2022-09-27 21:08:06 +02:00
R. Ryantm
e008387065 python310Packages.matrix-common: 1.2.1 -> 1.3.0
(cherry picked from commit 5acccf3677)
2022-09-27 20:58:23 +02:00
Martin Weinelt
653a8e02dd matrix-synapse: 1.67.0 -> 1.68.0
https://github.com/matrix-org/synapse/releases/tag/v1.68.0

Uses poetry-core to build the package. Drops setuptools-rust from
runtime dependencies, because they are checked at startup, which breaks
because we do a clear separation of concerns.

Fixes a misconception about the tests, that were until now always run
against the source module. This breaks with the introduction of the rust
components, because they're not available in the source module.

Adds missing pre and post hooks to checkPhase.

(cherry picked from commit 326b8f7d8f)
2022-09-27 18:47:24 +00:00
Franz Pletz
3cb9969a5d Merge pull request #193204 from NixOS/backport-193150-to-release-22.05
[Backport release-22.05] minetest: 5.6.0 -> 5.6.1, cleanup, add fgaz to maintainers
2022-09-27 19:35:28 +02:00
Francesco Gazzetta
d20156aa17 minetest: update outdated broken expression
(cherry picked from commit 8c6f018766)
2022-09-27 16:25:15 +00:00
Francesco Gazzetta
0b627ad0ee minetest: add fgaz to maintainers
(cherry picked from commit 2819931e41)
2022-09-27 16:25:15 +00:00
Francesco Gazzetta
0858520bb3 minetest: 5.6.0 -> 5.6.1
(cherry picked from commit aee300a6b5)
2022-09-27 16:25:14 +00:00
Francesco Gazzetta
251c1b9b5d irrlichtmt: 1.9.0mt7 -> 1.9.0mt8
(cherry picked from commit 7a84b04ced)
2022-09-27 16:25:14 +00:00
Sandro Jäckel
d1375ba912 docker: 20.10.17 -> 20.10.18
(cherry picked from commit 7d0ad48142)
2022-09-27 15:11:49 +00:00
Domen Kožar
38e441d51a cachix: 0.8.1 -> 1.0.1 2022-09-27 14:46:35 +01:00
Bobby Rong
131c0c31db Merge pull request #193153 from NixOS/backport-193141-to-release-22.05
[Backport release-22.05] pantheon.gala: Fix multitasking view allocation assertions
2022-09-27 18:25:31 +08:00
R. Ryantm
ea94201a0c libbpf: 0.8.0 -> 0.8.1
(cherry picked from commit ce7e118975)
2022-09-27 11:05:27 +01:00
Bobby Rong
08540c1a9e pantheon.gala: Fix multitasking view allocation assertions
(cherry picked from commit 1c66e61450)
2022-09-27 08:22:47 +00:00
github-actions[bot]
e90f24e320 Merge staging-next-22.05 into staging-22.05 2022-09-27 00:22:45 +00:00
github-actions[bot]
f8d3fae304 Merge release-22.05 into staging-next-22.05 2022-09-27 00:22:15 +00:00
Dominique Martinet
145a05a368 libbpf: 0.7.0 -> 0.8.0
(cherry picked from commit 9f75123e00)
2022-09-27 01:03:00 +01:00
Dominique Martinet
417231687f bpftrace: 0.14.1 -> 0.15.0
(cherry picked from commit d8b840a60f)
2022-09-27 01:02:42 +01:00
Martin Weinelt
82379884b2 Merge pull request #193023 from NixOS/backport-193022-to-release-22.05 2022-09-27 00:34:26 +02:00
Robert Scott
8e77006ad9 python3Packages.joblib: add patch for CVE-2022-21797 2022-09-26 22:51:15 +01:00
Maximilian Bosch
2840797852 Merge pull request #193048 from NixOS/backport-193014-to-release-22.05
[Backport release-22.05] Kernel updates 2022-09-26
2022-09-26 17:54:50 +02:00
Maximilian Bosch
fcb3da934e linux: 5.4.213 -> 5.4.214
(cherry picked from commit f5634aec0d)
2022-09-26 15:10:59 +00:00
Maximilian Bosch
efec0204c0 linux: 5.19.9 -> 5.19.11
(cherry picked from commit e33dff4d6c)
2022-09-26 15:10:59 +00:00
Maximilian Bosch
22fe27720c linux: 5.15.68 -> 5.15.70
(cherry picked from commit 2a6848c41f)
2022-09-26 15:10:59 +00:00
Maximilian Bosch
e650026101 linux: 5.10.143 -> 5.10.145
(cherry picked from commit 658cf99cfd)
2022-09-26 15:10:59 +00:00
Maximilian Bosch
791c1d43a1 linux: 4.9.328 -> 4.9.329
(cherry picked from commit 56eac8d627)
2022-09-26 15:10:59 +00:00
Maximilian Bosch
8d108d312c linux: 4.19.258 -> 4.19.259
(cherry picked from commit 6d6910f87d)
2022-09-26 15:10:58 +00:00
Maximilian Bosch
7f44406dae linux: 4.14.293 -> 4.14.294
(cherry picked from commit 047d538aea)
2022-09-26 15:10:58 +00:00
Thiago Kenji Okada
36e8641bb6 Merge pull request #193034 from NixOS/backport-191846-to-release-22.05
[Backport release-22.05] shellhub-agent: 0.10.1 -> 0.10.2
2022-09-26 15:55:45 +01:00
Jörg Thalheim
00f877f492 Merge pull request #193035 from NixOS/backport-192245-to-release-22.05
[Backport release-22.05] cider: 1.4.1.1680 -> 1.5.6
2022-09-26 16:16:17 +02:00
Pogobanane
f8e121e3ca cider: 1.4.1.1680 -> 1.5.6
(cherry picked from commit 49f8e6388c)
2022-09-26 14:01:12 +00:00
Otavio Salvador
b8aaee3179 shellhub-agent: 0.10.1 -> 0.10.2
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit f175cb1d8a)
2022-09-26 13:40:27 +00:00
Thiago Kenji Okada
a453f1a8e6 Merge pull request #191710 from NixOS/backport-190962-to-release-22.05
[Backport release-22.05] shellhub-agent: 0.9.6 -> 0.10.1
2022-09-26 13:51:37 +01:00
Martin Weinelt
eafb1c82a8 matrix-appservice-irc: 0.35.0 -> 0.35.1
https://github.com/matrix-org/matrix-appservice-irc/releases/tag/0.35.1

Fixes an SQL injection vulnerability through room ids when using the
PostgreSQL backend.

(cherry picked from commit cc8cb2ee8e)
2022-09-26 12:13:33 +00:00
Vladimír Čunát
b542cc75fa Merge #192564: staging-next-22.05 - iteration 11
...into release-22.05

We have basically no `*-darwin` binaries.  We'd have to wait for several
more days (at least), and I wouldn't be happy about delaying security
fixes for `*-linux` just because of that.

So let's "skip" this iteration for darwin.  It has a separate channel,
so those users shouldn't be significantly affected by this merge.
2022-09-26 09:55:28 +02:00
pacien
058d97782e godot-export-templates: strip export template file
Stripping reduces the template size from around 500MB to 40MB for Linux.
This is added explicitly here because mkDerivation does not automatically
strip binaries in the template directory.

This also impacts the size of the exported games and programs.
For example, here are the size of the `oh-my-git` package using this
template, without and with stripping:

```
❯ du -sh result*/
375M	result-oh-my-git-without-strip/
45M	result-oh-my-git-with-strip/
```

GitHub: closes https://github.com/NixOS/nixpkgs/issues/170470
(cherry picked from commit cb2e69963b670d6f66287a6a511b89f207bde32a)
2022-09-25 22:14:45 -04:00
github-actions[bot]
691c835be3 Merge staging-next-22.05 into staging-22.05 2022-09-26 00:20:02 +00:00
github-actions[bot]
cfcceccc04 Merge release-22.05 into staging-next-22.05 2022-09-26 00:19:13 +00:00
R. Ryantm
be25f29776 bind: 9.18.6 -> 9.18.7
(cherry picked from commit a6fe6e968b)
2022-09-25 23:13:24 +01:00
R. Ryantm
c584e8abdb bind: 9.18.5 -> 9.18.6
(cherry picked from commit 89d680fa2b)
2022-09-25 23:13:01 +01:00
R. Ryantm
abba4c1b5e bind: 9.18.4 -> 9.18.5
(cherry picked from commit 79d65a8851)
2022-09-25 23:12:43 +01:00
Robert Schütz
13da002eef bind: 9.18.3 -> 9.18.4
https://downloads.isc.org/isc/bind9/9.18.4/doc/arm/html/notes.html
(cherry picked from commit 2847e6e691)
2022-09-25 23:12:21 +01:00
Robert Scott
d0d890621d python3Packages.tensorflow-bin: 2.8.0 -> 2.8.1 2022-09-25 17:39:30 +01:00
Robert Scott
bd73627df1 python3Packages.tensorflow: 2.8.0 -> 2.8.1 2022-09-25 17:38:49 +01:00
Martin Weinelt
72783a2d0d Merge pull request #192858 from gador/backport-octoprint-1.8.3-22.05 2022-09-25 14:12:58 +02:00
Florian Brandes
30b404ddaf octoprint: fix build issue with flask-limiter dependency
Signed-off-by: Florian Brandes <florian.brandes@posteo.de>
2022-09-25 14:08:53 +02:00
Florian Brandes
9f50384cf1 octoprint: 1.8.1 -> 1.8.3
fixes several security issues
See https://github.com/OctoPrint/OctoPrint/releases/tag/1.8.3

Signed-off-by: Florian Brandes <florian.brandes@posteo.de>
(cherry picked from commit e8c0a78f47)
2022-09-25 13:56:48 +02:00
Martin Weinelt
e94f0e87cf Merge pull request #192862 from NixOS/backport-187701-to-staging-22.05 2022-09-25 12:59:50 +02:00
Kim Lindberger
d88db8f1f5 Merge pull request #192794 from NixOS/backport-192423-to-release-22.05
[Backport release-22.05] gitlab: 15.3.3 -> 15.4.0
2022-09-25 11:15:16 +02:00
Ivan Kozik
0b8395c247 gzip: build and install zless which went missing in gzip-1.12
Fixes https://github.com/NixOS/nixpkgs/issues/187697

(cherry picked from commit 23e5407bd4)
2022-09-25 08:20:44 +00:00
Vladimír Čunát
496dfb82bf python3Packages.pyhanko-certvalidator: drop an expired test
(cherry picked from commit b81cbeceef)
2022-09-25 09:13:11 +02:00
github-actions[bot]
c61d6c4671 Merge staging-next-22.05 into staging-22.05 2022-09-25 00:18:22 +00:00
github-actions[bot]
79b9b02ac2 Merge release-22.05 into staging-next-22.05 2022-09-25 00:17:43 +00:00
Robert Scott
aee4db5b9e Merge pull request #192788 from risicle/ris-tinygltf-CVE-2022-3008-r22.05
[22.05] tinygltf: add patch for CVE-2022-3008
2022-09-25 00:56:59 +01:00
Robert Scott
83fa8084d1 Merge pull request #192717 from LeSuisse/22.05-consul-1.12.5
[22.05] consul: 1.12.1 -> 1.12.5
2022-09-24 21:33:13 +01:00
Mario Rodas
d4f610684c Merge pull request #192789 from tpwrules/fix-intel-ocl
[22.05] intel-ocl: add web archive link since other links 404
2022-09-24 14:35:15 -05:00
Yaya
8262b5336f gitlab: 15.3.3 -> 15.4.0
https://gitlab.com/gitlab-org/gitlab/-/raw/v15.4.0-ee/CHANGELOG.md
(cherry picked from commit 4e1ac07bd9)
2022-09-24 17:07:12 +00:00
Sumner Evans
4a5d9dab51 intel-ocl: add web archive link since other links 404
Signed-off-by: Sumner Evans <me@sumnerevans.com>
(cherry picked from commit 00fe47bc0e)
2022-09-24 11:51:37 -05:00
Robert Scott
0dd5b1983c tinygltf: add patch for CVE-2022-3008 2022-09-24 17:46:30 +01:00
Mario Rodas
893b6b9f6c Merge pull request #192758 from NixOS/backport-192460-to-release-22.05
[Backport release-22.05] redis: 7.0.4 -> 7.0.5
2022-09-24 09:24:27 -05:00
ajs124
b57da5e7ca redis: 7.0.4 -> 7.0.5
Fixes CVE-2022-35951

Release notes: https://github.com/redis/redis/releases/tag/7.0.5

(cherry picked from commit d699b10068)
2022-09-24 11:55:14 +00:00
Thomas Gerbet
400ca85b20 consul: 1.12.1 -> 1.12.5
Fixes CVE-2021-41803.

Changelogs:
https://github.com/hashicorp/consul/releases/tag/v1.12.5
https://github.com/hashicorp/consul/releases/tag/v1.12.4
https://github.com/hashicorp/consul/releases/tag/v1.12.3
https://github.com/hashicorp/consul/releases/tag/v1.12.2
2022-09-24 09:20:35 +02:00
Mario Rodas
41064d1c9d Merge pull request #192699 from marsam/22.05-update-nodejs
[22.05] nodejs: 14.20.0 -> 14.20.1, 16.16.0 -> 16.17.1, 18.7.0 -> 18.9.1
2022-09-24 00:55:05 -05:00
Luke Granger-Brown
309faedb83 Merge pull request #192678 from NixOS/backport-192519-to-release-22.05
[Backport release-22.05] obs-studio-plugins.obs-pipewire-audio-capture: 1.0.4 -> 1.0.5
2022-09-24 02:12:55 +01:00
R. Ryantm
c07ec62ddf obs-studio-plugins.obs-pipewire-audio-capture: 1.0.4 -> 1.0.5
(cherry picked from commit d00cce907d)
2022-09-24 00:41:45 +00:00
github-actions[bot]
1b4eca6eaf Merge staging-next-22.05 into staging-22.05 2022-09-24 00:19:39 +00:00
github-actions[bot]
c1be9d2d9b Merge release-22.05 into staging-next-22.05 2022-09-24 00:19:01 +00:00
Martin Weinelt
1aac6bab2a firefox-devedition-bin-unwrapped: 105.0b9 -> 106.0b3
(cherry picked from commit 57db102e99)
2022-09-23 15:53:09 +02:00
Martin Weinelt
71564f23aa firefox-beta-bin-unwrapped: 105.0b9 -> 106.0b2
(cherry picked from commit ea401a6ad3)
2022-09-23 15:53:06 +02:00
Martin Weinelt
41dcf7ca22 firefox-bin-unwrapped: 105.0 -> 105.0.1
https://www.mozilla.org/en-US/firefox/105.0.1/releasenotes/
(cherry picked from commit bee18da2fe)
2022-09-23 15:53:03 +02:00
Martin Weinelt
b621a184d1 firefox-unwrapped: 105.0 -> 105.0.1
https://www.mozilla.org/en-US/firefox/105.0.1/releasenotes/
(cherry picked from commit ec248bd566)
2022-09-23 15:52:58 +02:00
Michele Guerini Rocco
7e27b838cd Merge pull request #192597 from rnhmjoj/pr-monero-back
monero-{cli,gui}: 0.18.1.0 -> 0.18.1.1
2022-09-23 15:32:28 +02:00
R. Ryantm
2d659baf60 monero-gui: 0.18.1.0 -> 0.18.1.1
(cherry picked from commit 2bd070cbac)
2022-09-23 10:18:07 +02:00
R. Ryantm
cce5dfdf84 monero-cli: 0.18.1.0 -> 0.18.1.1
(cherry picked from commit 85e38189c2)
2022-09-23 10:18:01 +02:00
Vladimír Čunát
e9bd3d0616 Merge #192224: knot-resolver: 5.5.0 -> 5.5.3
...into release-22.05
2022-09-23 07:47:01 +02:00
Vladimír Čunát
92626510b6 Merge branch 'staging-22.05' into staging-next-22.05 2022-09-23 07:40:26 +02:00
Vladimír Čunát
0a9a49a932 Merge #192278: unbound: fix CVE-2022-3204
...into staging-22.05
2022-09-23 07:37:37 +02:00
Mario Rodas
99c9c28c50 nodejs-18_x: 18.9.0 -> 18.9.1
https://github.com/nodejs/node/releases/tag/v18.9.1
(cherry picked from commit 4c7bfc6000)
2022-09-23 04:20:00 +00:00
github-actions[bot]
bb89ad5bef Merge staging-next-22.05 into staging-22.05 2022-09-23 00:19:14 +00:00
github-actions[bot]
ce14e67e95 Merge release-22.05 into staging-next-22.05 2022-09-23 00:18:39 +00:00
Robert Scott
b11d6bafbe tinyproxy: add patch for CVE-2022-40468
(cherry picked from commit 32f4104b66)
2022-09-22 22:24:50 +00:00
squalus
2a3fadb0d3 librewolf: 104.0-1 -> 105.0-1
(cherry picked from commit b0517e5db9)
2022-09-22 20:45:52 +00:00
Christian Kögler
4e10ae831a Merge pull request #192448 from NixOS/backport-192304-to-release-22.05
[Backport release-22.05] signal-desktop: 5.59.0 -> 5.60.0
2022-09-22 21:58:54 +02:00
Maximilian Bosch
f6fd9dfa51 Merge pull request #192408 from Ma27/grafana-security-backport
[22.05] grafana: 8.5.11 -> 8.5.13, fix CVE-2022-35957 & CVE-2022-36062
2022-09-22 21:21:41 +02:00
Martin Weinelt
d27844e020 Merge pull request #192407 from NixOS/backport-192013-to-release-22.05 2022-09-22 18:59:00 +02:00
Martin Weinelt
2881041a82 Merge pull request #192327 from NixOS/backport-192221-to-release-22.05 2022-09-22 18:55:03 +02:00
Martin Weinelt
3c5f04f903 Merge pull request #192339 from NixOS/backport-192141-to-staging-22.05 2022-09-22 18:54:45 +02:00
Eduardo Quiros
32daa3dfb0 signal-desktop: 5.59.0 -> 5.60.0
(cherry picked from commit 2c030b2e9e276e34596355accc9db171fbc026a9)
2022-09-22 15:46:09 +00:00
R. Ryantm
d4d466b210 wiki-js: 2.5.288 -> 2.5.289
(cherry picked from commit c15ada5b91)
2022-09-22 10:52:45 -04:00
Maximilian Bosch
bcc68429a5 Merge pull request #191909 from NixOS/backport-191871-to-release-22.05
[Backport release-22.05] wiki-js: 2.5.287 -> 2.5.288
2022-09-22 16:00:39 +02:00
Vladimír Čunát
e390ffa732 knot-resolver: 5.5.2 -> 5.5.3
CVE-2022-40188 and also the patches were included in the release.
https://gitlab.nic.cz/knot/knot-resolver/-/tags/v5.5.3

(cherry picked from commit 14384cf3ca)
2022-09-22 14:04:37 +02:00
Vladimír Čunát
683a4658bb knot-resolver: run more tests also on *-darwin
The tests need patching a bit, until the next release.
These tests would e.g. discover that kresd didn't work at all
until the patch in the parent commit.

(cherry picked from commit 6ffee2b5d0)
2022-09-22 14:04:37 +02:00
Vladimír Čunát
6e37410a1d knot-resolver: patch library loading for darwin
Apparently until now it could never start up on x86_64-darwin :-/

(cherry picked from commit 6d2168c73c)
2022-09-22 14:04:37 +02:00
Vladimír Čunát
f90ef90489 knot-resolver: 5.5.1 -> 5.5.2
https://gitlab.nic.cz/knot/knot-resolver/-/tags/v5.5.2
(cherry picked from commit 55a29891d4)
2022-09-22 14:04:37 +02:00
Vladimír Čunát
5399d182a7 knot-resolver: 5.5.0 -> 5.5.1
https://gitlab.nic.cz/knot/knot-resolver/-/tags/v5.5.1
(cherry picked from commit bac638e75b)
2022-09-22 14:04:37 +02:00
Anderson Torres
a5e514e6b7 Merge pull request #191689 from risicle/ris-rizin-CVEs-22.05
[22.05] rizin: add patches for multiple CVEs
2022-09-22 08:38:06 -03:00
superherointj
bd118201b8 Merge pull request #192406 from NixOS/backport-191670-to-release-22.05
[Backport release-22.05] linux/hardened: fix update script and build for 5.19
2022-09-22 07:58:42 -03:00
Maximilian Bosch
72db63adaf grafana: 8.5.11 -> 8.5.13, fix CVE-2022-35957 & CVE-2022-36062
ChangeLog: https://github.com/grafana/grafana/releases/tag/v8.5.13
2022-09-22 11:37:40 +02:00
Markus S. Wamser
7617989b17 teams: 1.5.00.10453 -> 1.5.00.23861 (linux), 1.5.00.22362 (darwin)
(cherry picked from commit f0c3d89c03)
2022-09-22 09:19:24 +00:00
Maximilian Bosch
83a6e43507 linux/hardened/5.19: fix build
The options GCC_PLUGIN_RANDSTRUCT{,_PERFORMANCE} have been renamed to
`RANDSTRUCT_*` in 595b893e2087de306d0781795fb8ec47873596a6 since CLang
is about to support this as well and thus the options had to be
generalized.

Also, the file that is used to generate the seed has changed, only the
reference to the file in the patch was changed on adding Linux 5.19[1]

[1] b4d0cb4497

(cherry picked from commit dd6727e7b8)
2022-09-22 09:11:48 +00:00
Maximilian Bosch
d5d408c6e2 nixos/kernel-generic: build linux_5_19_hardened
(cherry picked from commit 073f7b179c)
2022-09-22 09:11:48 +00:00
Maximilian Bosch
681729f23b linux-hardened: fix update script
We now have releases called `v5.19.x-hardened2` so make sure that the
update script doesn't stumble upon this.

(cherry picked from commit 80228b73e9)
2022-09-22 09:11:47 +00:00
Maximilian Bosch
67abe3e9fe linux/hardened/patches/5.19: 5.19.8-hardened1 -> 5.19.8-hardened2
(cherry picked from commit c2d301f7af)
2022-09-22 09:11:47 +00:00
Maximilian Bosch
94cf7cc0c8 linux_latest-libre: 18911 -> 18916
(cherry picked from commit b3dc6e35e0)
2022-09-22 09:11:47 +00:00
github-actions[bot]
346557835e Merge staging-next-22.05 into staging-22.05 2022-09-22 00:17:59 +00:00
github-actions[bot]
846dc6f8f4 Merge release-22.05 into staging-next-22.05 2022-09-22 00:17:20 +00:00
Robert Scott
5deff50dff expat: 2.4.8 -> 2.4.9
(cherry picked from commit 880fa3ec19)
2022-09-22 00:11:30 +00:00
Martin Weinelt
aab77df33a Merge pull request #188643 from risicle/ris-mod-wsgi-CVE-2022-2255-r22.05 2022-09-22 01:13:38 +02:00
Vladimír Čunát
a6502c83b1 thunderbird-bin: 102.2.2 -> 102.3.0
https://www.thunderbird.net/en-US/thunderbird/102.3.0/releasenotes/
(cherry picked from commit 88cb8dd07d)
2022-09-21 23:11:01 +00:00
Martin Weinelt
dd949f16f4 Merge pull request #192248 from NixOS/backport-192204-to-release-22.05 2022-09-22 01:10:42 +02:00
R. Ryantm
a0d6c6d8ed lighttpd: 1.4.66 -> 1.4.67
(cherry picked from commit 1ca49a3cf4b68431c59d90d5ecce2299f8f07fa3)
2022-09-22 01:09:21 +02:00
Martin Weinelt
77c3102f98 Merge pull request #192094 from NixOS/backport-192088-to-release-22.05 2022-09-22 01:08:05 +02:00
Martin Weinelt
34be77a9ca Merge pull request #192214 from NixOS/backport-192202-to-release-22.05 2022-09-22 01:07:51 +02:00
ajs124
9cf2fb373c mariadb_106: 10.6.9 -> 10.6.10
https://mariadb.com/kb/en/mariadb-10610-release-notes/
(cherry picked from commit 1b8755548c)
2022-09-21 21:50:56 +02:00
ajs124
465771ac3b mariadb_107: 10.7.5 -> 10.7.6
https://mariadb.com/kb/en/mariadb-1076-release-notes/
(cherry picked from commit 0f1042dec1)
2022-09-21 21:50:56 +02:00
ajs124
e42a58a6e9 mariadb_108: 10.8.4 -> 10.8.5
https://mariadb.com/kb/en/mariadb-1085-release-notes/
(cherry picked from commit d563e5c1e0)
2022-09-21 21:50:55 +02:00
ajs124
d2e3ba3562 unbound: fix CVE-2022-3204 2022-09-21 20:05:02 +02:00
Martin Weinelt
8ca615e239 Merge pull request #192275 from NixOS/backport-192272-to-release-22.05 2022-09-21 18:55:48 +02:00
rnhmjoj
dd0ed2d131 pdns-recursor: 4.7.2 -> 4.7.3
(cherry picked from commit 7cc305fa59)
2022-09-21 16:48:54 +00:00
R. Ryantm
d4f905ad84 thunderbird-unwrapped: 102.2.2 -> 102.3.0
(cherry picked from commit 44d3703d62)
2022-09-21 13:42:47 +00:00
Martin Weinelt
9bdbbaa634 Merge pull request #192093 from mweinelt/22.05/firefox 2022-09-21 13:47:20 +02:00
R. Ryantm
3f1c09dfa6 thunderbird-91-unwrapped: 91.13.0 -> 91.13.1
(cherry picked from commit 28830d30e6)
2022-09-21 08:50:48 +00:00
WilliButz
9d9aca3988 weechatScripts.wee-slack: 2.8.0 -> 2.9.0
https://github.com/wee-slack/wee-slack/releases/tag/v2.9.0
(cherry picked from commit 514fecc96d)
2022-09-21 08:00:58 +00:00
github-actions[bot]
d3c0e88255 Merge staging-next-22.05 into staging-22.05 2022-09-21 00:19:33 +00:00
github-actions[bot]
15bc1d2ab9 Merge release-22.05 into staging-next-22.05 2022-09-21 00:18:56 +00:00
Robert Scott
cafad185b7 Merge pull request #191955 from risicle/ris-cmark-gfm-0.29.0.gfm.6-r22.05
[22.05] cmark-gfm: 0.29.0.gfm.3 -> 0.29.0.gfm.6
2022-09-20 21:51:58 +01:00
Kerstin
0820d9c779 Merge pull request #191368 from erictapen/22.05/kanidm
[release-22.05] nixos/kanidm: Add cacerts path to unixd service
2022-09-20 22:36:07 +02:00
Martin Weinelt
7c48aa5fbf buildMozillaMach: use rust 1.61 2022-09-20 21:48:40 +02:00
Robert Scott
7d93a50743 Merge pull request #191408 from risicle/ris-libtiff-CVE-2022-2953-r22.05
[22.05] libtiff: add patch for CVE-2022-2953
2022-09-20 19:15:23 +01:00
Vladimír Čunát
298742b2b8 firefox-bin: 104.0.2 -> 105.0
https://www.mozilla.org/en-US/firefox/105.0/releasenotes/
(cherry picked from commit 07e9c317b4)
2022-09-20 15:38:54 +00:00
Martin Weinelt
1c265e17a8 firefox-esr-102-unwrapped: 102.2.0esr -> 102.3.0esr
https://www.mozilla.org/en-US/firefox/102.3.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-41/

Fixes: CVE-2022-40959, CVE-2022-40960, CVE-2022-40958, CVE-2022-40956
       CVE-2022-40957, CVE-2022-40962
(cherry picked from commit f559d89cd0)
2022-09-20 17:34:10 +02:00
Martin Weinelt
9d17d1b810 firefox-unwrapped: 104.0.2 -> 105.0
https://www.mozilla.org/en-US/firefox/105.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-40

Fixes: CVE-2022-40959, CVE-2022-40960, CVE-2022-40958, CVE-2022-40961,
       CVE-2022-40956, CVE-2022-40957, CVE-2022-40962
(cherry picked from commit 11b3d69652)
2022-09-20 17:33:26 +02:00
Bobby Rong
e64df9c5c8 Merge pull request #192038 from NixOS/backport-192033-to-release-22.05
[Backport release-22.05] srain: fix homepage
2022-09-20 02:09:51 -06:00
Shengyu Zhang
cf8fcef85e srain: fix homepage
See also https://srain.silverrainz.me/blog/migrate-domain.html

(cherry picked from commit 198dd79a4a)
2022-09-20 07:59:50 +00:00
Martin Weinelt
85914bac0b Merge pull request #191728 from mweinelt/mark-firefox-91-vulnerable 2022-09-20 03:56:05 +02:00
github-actions[bot]
fa4466565d Merge staging-next-22.05 into staging-22.05 2022-09-20 00:21:42 +00:00
github-actions[bot]
852cf2cd97 Merge release-22.05 into staging-next-22.05 2022-09-20 00:21:09 +00:00
Shea Levy
6dd5255fc4 Merge branch 'backport-191383-to-release-22.05' of https://github.com/SDAChess/nixpkgs into release-22.05 2022-09-19 16:00:52 -04:00
squalus
b09b20fd0f librewolf: 103.0-3 -> 104.0-1
(cherry picked from commit eb3cea96da)
2022-09-19 12:48:52 -04:00
Robert Scott
db67252e2a cmark-gfm: 0.29.0.gfm.5 -> 0.29.0.gfm.6
(cherry picked from commit 626445f1c7)
2022-09-19 17:33:48 +01:00
R. Ryantm
32c245781b cmark-gfm: 0.29.0.gfm.4 -> 0.29.0.gfm.5
(cherry picked from commit 8fb82d80fe)
2022-09-19 17:33:38 +01:00
R. Ryantm
1006660c0d cmark-gfm: 0.29.0.gfm.3 -> 0.29.0.gfm.4
(cherry picked from commit 55ac327102)
2022-09-19 17:33:23 +01:00
Martin Weinelt
57cd752861 Merge pull request #191929 from NixOS/backport-181002-to-release-22.05 2022-09-19 18:19:31 +02:00
Martin Weinelt
151ea1305d gwenhyfar: 5.6.0 -> 5.9.0
(cherry picked from commit 77af6669db)
2022-09-19 14:17:01 +00:00
Martin Weinelt
86cab4e24a libchipcard: 5.0.4 -> 5.1.6
(cherry picked from commit 81804181d1)
2022-09-19 14:17:01 +00:00
Martin Weinelt
e5e2d53f64 aqbanking: 6.3.0 -> 6.5.0
(cherry picked from commit 1e68a02e4a)
2022-09-19 14:17:00 +00:00
Maximilian Bosch
fe46048ab9 Merge pull request #191905 from Ma27/pi-backport
[22.05] privacyidea: 3.7.2 -> 3.7.3
2022-09-19 16:01:21 +02:00
R. Ryantm
b4fe6a4953 wiki-js: 2.5.287 -> 2.5.288
(cherry picked from commit c5be74c769)
2022-09-19 12:06:23 +00:00
Maximilian Bosch
20dc478985 Merge pull request #191774 from NixOS/backport-191672-to-release-22.05
[Backport release-22.05] linux: remove 5.18
2022-09-19 13:41:13 +02:00
Maximilian Bosch
e1280cc86d privacyidea: 3.7.2 -> 3.7.3, fix build
ChangeLog: https://github.com/privacyidea/privacyidea/blob/v3.7.3/Changelog
Failing Hydra build: https://hydra.nixos.org/build/190981743

* Disable tests of `werkzeug` since a lot of it is now failing with
  `unclosed file handle` (partly just randomly) which is an indicator
  for a broken test-suite. Dependency updates that would help us to get
  rid of this hackery are apparently in progress upstream[1].

* Disable checkPhase for `Mako` since it now requires `lingua` as
  `checkInput`, but it'd require `click>8`, however we use v7 here for
  the older flask. To avoid even more dependency chaos, I decided to
  just turn off the tests here.

* Update disabled tests for `privacyidea` itself: a few tests are either
  removed or succeeding now (perhaps because we now set `$HOME` now for
  tests ;-) ). Documented on the remaining tests why they can't work in
  a `nix-build`.

[1] https://github.com/privacyidea/privacyidea/issues/2876

(cherry picked from commit f1fa5f1eb4)
2022-09-19 13:40:34 +02:00
github-actions[bot]
76ebeccdf5 Merge staging-next-22.05 into staging-22.05 2022-09-19 00:17:04 +00:00
github-actions[bot]
a2e3393184 Merge release-22.05 into staging-next-22.05 2022-09-19 00:16:25 +00:00
Robert Scott
2fb7501320 Merge pull request #191111 from NixOS/backport-191081-to-release-22.05
[Backport release-22.05] routinator: 0.11.2 -> 0.11.3
2022-09-18 20:03:34 +01:00
Robert Scott
4504569602 Merge pull request #191493 from NixOS/backport-191485-to-release-22.05
[Backport release-22.05] python3Packages.reportlab: Ignore special casing for m1 macs
2022-09-18 19:21:03 +01:00
Luke Granger-Brown
b9d5fa527a Merge pull request #191756 from NixOS/backport-191410-to-staging-22.05
[Backport staging-22.05] cacert: 3.80 -> 3.83
2022-09-18 16:37:51 +01:00
Christian Kögler
494fcbbe85 Merge pull request #190810 from NixOS/backport-184534-to-release-22.05
[Backport release-22.05] qbittorrent: 4.4.3 -> 4.4.3.1
2022-09-18 14:04:02 +02:00
Maximilian Bosch
3d952140f0 linux: remove 5.18
This is long overdue, the last release was almost a month ago, on 21st
Aug 2022[1].

[1] https://lwn.net/Articles/905532/

(cherry picked from commit a2969b43bb)
2022-09-18 10:14:23 +00:00
Christian Kögler
b47d4447dc Merge pull request #191762 from Ma27/element-backport
[22.05] element-{web,desktop}: 1.11.4 -> 1.11.5
2022-09-18 11:43:32 +02:00
Maximilian Bosch
163971a2f3 element-{web,desktop}: 1.11.4 -> 1.11.5
Port of #191690 (59f8ea7f96) to stable.
2022-09-18 11:07:26 +02:00
Martin Weinelt
a60b2f3620 cacert: 3.80 -> 3.83
- Bug 1785297 - Add two SECOM root certificates to NSS
- Bug 1787075 - Add two DigitalSign root certificates to NSS
- Bug 1778412 - Remove Camerfirma Global Chambersign Root from NSS

(cherry picked from commit 2c9b58573f)
2022-09-18 08:54:24 +00:00
Martin Weinelt
d84f54d645 firefox-esr-91-unwrapped: mark vulnerable 2022-09-18 03:52:48 +02:00
github-actions[bot]
164e911f76 Merge staging-next-22.05 into staging-22.05 2022-09-18 00:17:46 +00:00
github-actions[bot]
f7f16c9794 Merge release-22.05 into staging-next-22.05 2022-09-18 00:17:04 +00:00
Otavio Salvador
cf92109fe8 shellhub-agent: 0.9.6 -> 0.10.1
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit 2bf2f4583a)
2022-09-17 21:43:55 +00:00
Niklas Hambüchen
f38a2fc8ad mautrix-signal: Use --prefix instead of --set in wrapper.
Otherwise, options like `systemd.services.<name>.path` have no effect.

An example for this being necessary is to add `ffmpeg` to the path of
a service running `mautrix-signal` in order to decode audio messages.

In general, package wrappers should not make environment variables like
PATH or PYTHONPATH non-overridable.

(cherry picked from commit 162d4bf69f)
2022-09-17 20:03:29 +00:00
Maximilian Bosch
17989edb05 Merge pull request #191657 from NixOS/backport-191364-to-release-22.05
[Backport release-22.05] linux: 5.19.8 -> 5.19.9
2022-09-17 18:59:54 +02:00
Maximilian Bosch
88fd427cb9 Merge pull request #191682 from NixOS/backport-190431-to-release-22.05
[Backport release-22.05] wiki-js: 2.5.286 -> 2.5.287
2022-09-17 18:57:54 +02:00
Simon Scatton
0edc2e466c Merge branch 'release-22.05' into backport-191383-to-release-22.05 2022-09-17 18:46:57 +02:00
Lily Ritter
dac2ff1a6a discord: 0.0.19 -> 0.0.20
(cherry picked from commit 3fcf17c348)
2022-09-17 18:38:45 +02:00
Maximilian Bosch
0e9ae6a24b nixos/wiki-js: pin nodejs to v16
v18 is not supported, see https://docs.requarks.io/install/requirements#nodejs

(cherry picked from commit 6b6bb7cdd3)
2022-09-17 16:25:51 +00:00
R. Ryantm
821da9aa64 wiki-js: 2.5.286 -> 2.5.287
(cherry picked from commit 3cac015a69)
2022-09-17 16:25:51 +00:00
Maximilian Bosch
71e4e76cfb Merge pull request #190752 from yayayayaka/nextcloud-2022-09-11
[Backport release-22.05] nextcloud: nextcloud23: 23.0.8 -> 23.0.9, nextcloud24: 24.0.4 -> 24.0.5
2022-09-17 17:52:27 +02:00
Maximilian Bosch
3ce88f1f17 Merge pull request #191621 from NixOS/backport-191542-to-release-22.05
[Backport release-22.05] mautrix-whatsapp: 0.6.1 -> 0.7.0
2022-09-17 17:37:20 +02:00
Maximilian Bosch
26bff0c842 mautrix-whatsapp: build w/Go 1.18
As stated in the release notes, this is necessary now.
2022-09-17 17:14:38 +02:00
Mario Rodas
2b721ab914 Merge pull request #191567 from NixOS/backport-191162-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 105.0.5195.102 -> 105.0.5195.127
2022-09-17 09:11:02 -05:00
Mario Rodas
a8b32682bc Merge pull request #191566 from NixOS/backport-191161-to-release-22.05
[Backport release-22.05] chromium: 105.0.5195.102 -> 105.0.5195.125
2022-09-17 09:10:39 -05:00
Robert Scott
b7ef7a6742 rizin: add patches for multiple CVEs
CVE-2022-36039
CVE-2022-36040
CVE-2022-36041
CVE-2022-36043
CVE-2022-36044

CVE-2022-36042 doesn't appear to affect 0.3.4
2022-09-17 15:01:02 +01:00
Anderson Torres
852f1b7c84 Merge pull request #191660 from NixOS/backport-191577-to-release-22.05
[Backport release-22.05] ftgl: drop an impure -dylib_file on darwin
2022-09-17 10:36:02 -03:00
Dmitry Kalinkin
0e814c68bf ftgl: drop an impure -dylib_file on darwin
The build may outright fail because of this on recent macOS:

ftgl> clang-11: error: no such file or directory: '/System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGL.dylib'

(cherry picked from commit 795fbbf5cc)
2022-09-17 13:32:35 +00:00
superherointj
7e90aa11de linux_latest-libre: 18904 -> 18911
(cherry picked from commit 558d9998a7)
2022-09-17 13:23:34 +00:00
superherointj
d4f0cadf71 linux: 5.4.212 -> 5.4.213
(cherry picked from commit 18a8634d15)
2022-09-17 13:23:34 +00:00
superherointj
8cf426e441 linux: 5.19.8 -> 5.19.9
(cherry picked from commit 9f80f6bfa9)
2022-09-17 13:23:34 +00:00
superherointj
5602188c4a linux: 5.15.67 -> 5.15.68
(cherry picked from commit 087dde20eb)
2022-09-17 13:23:34 +00:00
superherointj
28aa969049 linux: 5.10.142 -> 5.10.143
(cherry picked from commit 2875584458)
2022-09-17 13:23:34 +00:00
superherointj
410217827f linux: 4.9.327 -> 4.9.328
(cherry picked from commit ba9e102d79)
2022-09-17 13:23:34 +00:00
superherointj
019463b123 linux: 4.19.257 -> 4.19.258
(cherry picked from commit d233f0c847)
2022-09-17 13:23:34 +00:00
superherointj
144d043139 linux: 4.14.292 -> 4.14.293
(cherry picked from commit e78ad2c848)
2022-09-17 13:23:34 +00:00
Shea Levy
7686dcfe8c Merge branch 'scope-lite' into release-22.05 2022-09-17 06:41:55 -04:00
Shea Levy
f21492b413 stduuid: init at 1.2.2
(cherry picked from commit c29a6a6416)
2022-09-17 06:22:01 -04:00
Charlotte Van Petegem
f862b9d38c mautrix-whatsapp: 0.6.1 -> 0.7.0
https://github.com/mautrix/whatsapp/releases/tag/v0.7.0
(cherry picked from commit 0727ac8a48)
2022-09-17 07:53:49 +00:00
Maximilian Bosch
802c1ab0a4 Merge pull request #191250 from NixOS/backport-191150-to-release-22.05
[Backport release-22.05] matrix-synapse: 1.66.0 -> 1.67.0
2022-09-17 09:37:51 +02:00
github-actions[bot]
1c0d8b4e7e Merge staging-next-22.05 into staging-22.05 2022-09-17 00:17:11 +00:00
github-actions[bot]
0e569cfd1f Merge release-22.05 into staging-next-22.05 2022-09-17 00:16:36 +00:00
Michael Weiss
be64df0d94 ungoogled-chromium: 105.0.5195.102 -> 105.0.5195.127
(cherry picked from commit 782b9c8adf)
2022-09-16 21:53:40 +00:00
Michael Weiss
a51785eef5 chromium: 105.0.5195.102 -> 105.0.5195.125
(cherry picked from commit f3cd1ff30f)
2022-09-16 21:52:53 +00:00
Martin Weinelt
92e73bf492 python3Packages.reportlab: ignore special casing for m1 macs
(cherry picked from commit 05beb70eb2)
2022-09-16 23:01:07 +02:00
Ryan Mulligan
9147c410a7 Merge pull request #191544 from NixOS/backport-186331-to-release-22.05
[Backport release-22.05] discourse.plugins.discourse-bbcode-color: init
2022-09-16 13:43:06 -07:00
Sandro
4b3db16502 Merge pull request #190854 from NixOS/backport-190136-to-release-22.05 2022-09-16 22:34:18 +02:00
Ryan Mulligan
e637a62327 discourse.plugins.discourse-bbcode-color: init
(cherry picked from commit 3d332125a4)
2022-09-16 19:34:34 +00:00
Robert Scott
d14ba56038 Merge pull request #191316 from NixOS/backport-190582-to-staging-22.05
[Backport staging-22.05] python3Packages.oauthlib: 3.2.0 -> 3.2.1
2022-09-16 20:01:50 +01:00
Janne Heß
312c0f7f37 Merge pull request #190840 from helsinki-systems/upd/icinga2
[22.05] icinga2: 2.13.3 -> 2.13.5
2022-09-16 14:24:36 +02:00
Vladimír Čunát
cdd98ddbef Merge #190891: staging-next-22.05 - iteration 10
...into release-22.05
2022-09-16 11:06:29 +02:00
Vladimír Čunát
0dfa3b283a Merge #191088: kanboard: fix source hash
...into release-22.05
2022-09-16 09:56:39 +02:00
github-actions[bot]
d4addd81e8 Merge staging-next-22.05 into staging-22.05 2022-09-16 00:19:54 +00:00
github-actions[bot]
8b84f31e91 Merge release-22.05 into staging-next-22.05 2022-09-16 00:19:12 +00:00
Robert Scott
92faab7ce9 libtiff: add patch for CVE-2022-2953
some manual adjustement required, hence not pulling from upstream
2022-09-15 22:10:10 +01:00
Robert Scott
7ebfa16ca3 Merge pull request #190996 from NixOS/backport-190849-to-release-22.05
[Backport release-22.05] samba: 4.15.5 -> 4.15.9
2022-09-15 20:26:49 +01:00
Christian Kögler
e2c95e0384 Merge pull request #191326 from NixOS/backport-191273-to-release-22.05
[Backport release-22.05] signal-desktop: 5.58.0 -> 5.59.0
2022-09-15 21:02:23 +02:00
Tako Marks
3a26ffa308 nixos/kanidm: Add unixd test
Test makes sure unixd is able to run and is able to query the server.

(cherry picked from commit fb3f7d70b4)
2022-09-15 20:31:54 +02:00
Tako Marks
e34c4f85cb nixos/kanidm: Bind mount cacert path in unixd service
In order to be able to use the unixd service with the `verify_ca` and
`verify_hostnames` set to `true` it needs to be able to read the
certificate store. This change bind mounts the cacert paths for the
unixd service.

(cherry picked from commit 3df41451e3)
2022-09-15 20:31:53 +02:00
Martin Weinelt
994cffd997 nixos/tests/kanidm: Update recover_account commandline
The username is now passed directly as an argument.

(cherry picked from commit 9ac9449a0a)
2022-09-15 20:31:53 +02:00
Martin Weinelt
1e0c426c15 kanidm: 1.1.0-alpha.8 -> 1.1.0-alpha.9
https://github.com/kanidm/kanidm/releases/tag/v1.1.0-alpha.9

Uses a concrete rev, because it relies on additional commits from the
release branch that provide build fixes.

(cherry picked from commit b6f5b81920)
2022-09-15 20:31:53 +02:00
Sandro
178fea1414 Merge pull request #191324 from pogobanane/backport-190155-to-release-22.05 2022-09-15 14:25:35 +02:00
Eduardo Quiros
9cbc58a547 signal-desktop: 5.58.0 -> 5.59.0
(cherry picked from commit 0eef6fb7d5)
2022-09-15 12:18:32 +00:00
Kerstin
4157473f92 Merge pull request #191269 from NixOS/backport-191265-to-release-22.05
[Backport release-22.05] python3Packages.img2pdf: apply patch to fix tests
2022-09-15 14:08:16 +02:00
R. RyanTM
7a45719861 nextcloud-client: 3.5.4 -> 3.6.0 (#190155)
Co-authored-by: Doron Behar <doron.behar@gmail.com>
2022-09-15 13:38:36 +02:00
Minijackson
474af68226 nixos/i18n: use glibcLocales from the host packages
The locale-archive is dependent on the endianness of the host system

(cherry picked from commit 09df3d5515)
2022-09-15 11:11:10 +00:00
Minijackson
d3d5fcb69a glibcLocales: follow host platform endianness
(cherry picked from commit 81c37edce4)
2022-09-15 11:11:10 +00:00
Robert Scott
ab9ba21f5d python3Packages.oauthlib: 3.2.0 -> 3.2.1
(cherry picked from commit 9aed7b7cbb)
2022-09-15 11:10:27 +00:00
Martin Weinelt
75519e7a8b python3Packages.img2pdf: apply patch to fix tests
(cherry picked from commit 5e05ec3352)
2022-09-15 04:18:54 +00:00
Anderson Torres
01ec6cc8e9 Merge pull request #189939 from leungbk/emacs-backport-pgtk
[22.05] emacs: use withPgtk option more
2022-09-14 23:32:16 -03:00
Brian Leung
bea03ac862 emacs: avoid installing gsettings-desktop-schemas on Darwin
(cherry-picked from commit 499921d643)
2022-09-14 18:34:58 -07:00
Brian Leung
ab550b3360 emacs: use withPgtk option more
(cherry-picked from commit 6d0e82f11a)

- do not require X when withPgtk is true
- make default settings and boolean logic consistent with withPgtk setting
2022-09-14 18:32:17 -07:00
github-actions[bot]
2e504c4d18 Merge staging-next-22.05 into staging-22.05 2022-09-15 00:17:30 +00:00
github-actions[bot]
b5c04e2eed Merge release-22.05 into staging-next-22.05 2022-09-15 00:16:55 +00:00
Nick Cao
26a7d2d4fb matrix-synapse: 1.66.0 -> 1.67.0
(cherry picked from commit 65cefcd588)
2022-09-15 00:15:26 +00:00
John Ericson
b13abb7427 Merge pull request #191193 from NixOS/backport-175871-to-staging-22.05
[Backport staging-22.05] buildRubyGem: fix bundix cross
2022-09-14 10:45:42 -04:00
Artturin
2dcdb9cc3a buildRubyGem: inherit libobjc from darwin
(cherry picked from commit 6b8ce2acdf)
2022-09-14 14:07:28 +00:00
Artturin
26372312f7 buildRubyGem: fix bundix cross
allows building bundix but most ruby gems still fail with

```
++ gem install --local --force --http-proxy http://nodtd.invalid --ignore-dependencies --install-dir /nix/store/...-ruby-aarch64-unknown-linux-gnu2.7.6-nio4r-2.5.8-aarch64-unknown-linux-gnu/lib/ruby/gems/2.7.0
--build-root / --backtrace --no-env-shebang -N /nix/store/...-nio4r-2.5.8.gem --
/nix/store/...-ruby-aarch64-unknown-linux-gnu-2.7.6/bin/gem: line 8: require: command not found
/nix/store/...-ruby-aarch64-unknown-linux-gnu-2.7.6/bin/gem: line 9: require: command not found
/nix/store/...-ruby-aarch64-unknown-linux-gnu-2.7.6/bin/gem: line 10: require: command not found
/nix/store/...-ruby-aarch64-unknown-linux-gnu-2.7.6/bin/gem: line 12: required_version: command not found
/nix/store/...-ruby-aarch64-unknown-linux-gnu-2.7.6/bin/gem: line 14: unless: command not found
/nix/store/...-ruby-aarch64-unknown-linux-gnu-2.7.6/bin/gem: line 15: abort: command not found
/nix/store/...-ruby-aarch64-unknown-linux-gnu-2.7.6/bin/gem: line 16: end: command not found
/nix/store/...-ruby-aarch64-unknown-linux-gnu-2.7.6/bin/gem: line 18: args: command not found
/nix/store/...-ruby-aarch64-unknown-linux-gnu-2.7.6/bin/gem: line 20: begin: command not found
/nix/store/...-ruby-aarch64-unknown-linux-gnu-2.7.6/bin/gem: line 21: Gem::GemRunner.new.run: command not found
/nix/store/...-ruby-aarch64-unknown-linux-gnu-2.7.6/bin/gem: line 22: rescue: command not found
/nix/store/...-ruby-aarch64-unknown-linux-gnu-2.7.6/bin/gem: line 23: exit: e.exit_code: numeric argument required
```

(cherry picked from commit a720bc44c2)
2022-09-14 14:07:28 +00:00
Domen Kožar
a083302d81 Merge pull request #191181 from domenkozar/22.05-datadog-agent-fixes
22.05 datadog agent fixes
2022-09-14 13:19:54 +01:00
sohalt
a0bb296cf7 datadog-agent: 7.36.0 -> 7.38.1
(cherry picked from commit fab8a905ab)
2022-09-14 13:03:28 +01:00
sohalt
ee3ff7232f datadog-integrations-core: 7.30.1 -> 7.38.0
(cherry picked from commit 39165f2938)
2022-09-14 13:02:52 +01:00
sohalt
daff3c7091 datadog: fix python integration
(cherry picked from commit 6f0654817a)
2022-09-14 13:02:44 +01:00
github-actions[bot]
2ea3dcc261 Merge staging-next-22.05 into staging-22.05 2022-09-14 00:19:11 +00:00
github-actions[bot]
aefe9583b6 Merge release-22.05 into staging-next-22.05 2022-09-14 00:18:25 +00:00
0x4A6F
5386926771 routinator: 0.11.2 -> 0.11.3
(cherry picked from commit 7704c81e12)
2022-09-13 20:41:56 +00:00
Raito Bezarius
154fcea7c7 kanboard: fix source hash 2022-09-13 18:47:32 +02:00
Kerstin
19bb831cc2 Merge pull request #191064 from NixOS/backport-190986-to-release-22.05
[Backport release-22.05] imagemagick: 7.1.0-47 -> 7.1.0-48
2022-09-13 17:46:37 +02:00
Martin Weinelt
7206e13352 Merge pull request #191074 from NixOS/backport-191065-to-release-22.05 2022-09-13 17:26:59 +02:00
Martin Weinelt
ca63839550 matrix-appservice-irc: 0.34.1 -> 0.35.0
Fetches, injects and patchelfs the rust native crypto bindings for the
two most prominent targets.

(cherry picked from commit 24d15603ad)
2022-09-13 14:46:29 +00:00
R. Ryantm
2a93502234 imagemagick: 7.1.0-47 -> 7.1.0-48
(cherry picked from commit c23686e115)
2022-09-13 12:17:46 +00:00
Gabriel Ebner
d86a4619b7 Merge pull request #191039 from NixOS/backport-191035-to-release-22.05
[Backport release-22.05] elan: 1.4.1 -> 1.4.2
2022-09-13 13:08:11 +02:00
kilianar
1a1b6829da signal-desktop: 5.57.0 -> 5.58.0
https://github.com/signalapp/Signal-Desktop/releases/tag/v5.58.0
(cherry picked from commit 315d77643c)
2022-09-13 18:41:06 +08:00
Gabriel Ebner
f0ff9e6e47 elan: 1.4.1 -> 1.4.2
(cherry picked from commit 38aa976494)
2022-09-13 09:24:12 +00:00
Vladimír Čunát
09d8647fa9 Merge #190698: thunderbird*: 102.2.1 -> 102.2.2
...into release-22.05
2022-09-13 08:52:47 +02:00
Nguyễn Gia Phong
ccafeb2aff dendrite: 0.9.4 -> 0.9.8
(cherry picked from commit 99e71eee21)
2022-09-12 23:28:23 -04:00
Martin Weinelt
7dfb6b46dd Merge pull request #190994 from NixOS/backport-190970-to-staging-22.05 2022-09-13 03:30:29 +02:00
Robert Scott
eb95062481 samba: 4.15.5 -> 4.15.9
(cherry picked from commit 755e7195b2)
2022-09-13 00:25:23 +00:00
github-actions[bot]
1719ceb67a Merge staging-next-22.05 into staging-22.05 2022-09-13 00:18:00 +00:00
github-actions[bot]
cfbf8ca0af Merge release-22.05 into staging-next-22.05 2022-09-13 00:17:18 +00:00
Martin Weinelt
0728bec3ec nspr: 4.34.1 -> 4.35
NSPR 4.35 contains the following changes:
- fixes for building with clang
- use the number of online processors for the
  PR_GetNumberOfProcessors() API on some platforms
- fix build on mips+musl libc
- Add support for the LoongArch 64-bit architecture

For details, please refer to the list of related bugs:
https://bugzilla.mozilla.org/buglist.cgi?resolution=FIXED&query_format=advanced&product=NSPR&target_milestone=4.35

(cherry picked from commit f878b25632)
2022-09-13 00:10:21 +00:00
Shane Sveller
10f3841d4c elixir_1_14: init at 1.14.0
https://elixir-lang.org/blog/2022/09/01/elixir-v1-14-0-released/
https://hexdocs.pm/elixir/1.14.0/changelog.html
2022-09-12 18:38:25 -04:00
Robert Scott
b03b0add65 Merge pull request #190827 from NixOS/backport-190778-to-release-22.05
[Backport release-22.05] trafficserver: 9.1.2 -> 9.1.3
2022-09-12 21:26:09 +01:00
Domen Kožar
45e3ff758e Update nixos/modules/services/system/cachix-agent/default.nix
Co-authored-by: pennae <82953136+pennae@users.noreply.github.com>
2022-09-12 16:31:13 +02:00
Domen Kožar
05f3344177 Update nixos/modules/services/system/cachix-agent/default.nix
Co-authored-by: pennae <82953136+pennae@users.noreply.github.com>
2022-09-12 16:31:13 +02:00
Domen Kožar
3fe263d370 cachix-agent: add host option
(cherry picked from commit fbc23b491a)
2022-09-12 16:31:13 +02:00
Martin Weinelt
131346ee0f Merge pull request #190923 from NixOS/backport-190836-to-release-22.05 2022-09-12 15:25:00 +02:00
Martin Weinelt
b3bee08092 Merge pull request #190922 from NixOS/backport-190888-to-release-22.05 2022-09-12 14:51:35 +02:00
Erik Arvstedt
1d16361fe8 paperless: use imagemagickBig
`imagemagickBig` has `gs` support. This fixes a warning during
thumbnail generation (`convert: no images defined`).
The type of thumbnails that are generated is unchanged.

(cherry picked from commit a611c674c2)
2022-09-12 12:15:51 +00:00
Erik Arvstedt
8a53f6da32 paperless: fix array formatting
(cherry picked from commit e3be4ad2f0)
2022-09-12 12:15:50 +00:00
Erik Arvstedt
3c6ea972c5 nixos/paperless: use python from pkg for gunicorn
This ensures that a compatible `gunicorn` is used when `pkg` is
overridden.

(cherry picked from commit fdead18e9e)
2022-09-12 12:10:47 +00:00
Vladimír Čunát
e44571fa66 Merge branch 'release-22.05' into staging-next-22.05 2022-09-12 09:43:22 +02:00
Vladimír Čunát
ae530e2cd8 Merge branch 'staging-22.05' into staging-next-22.05 2022-09-12 09:43:05 +02:00
Vladimír Čunát
bf014cad81 Merge #190633: kernel: 2022-09-09 updates
...into release-22.05
2022-09-12 09:29:23 +02:00
Vladimír Čunát
2977fb03c1 Merge #190584: python3Packages.Mako: 1.2.0 -> 1.2.2
...into staging-22.05
2022-09-12 09:24:08 +02:00
Vladimír Čunát
81cf1eab08 Merge #190324: python3Packages.nose: fix cross-compiling
...into staging-22.05
2022-09-12 09:21:53 +02:00
Vladimír Čunát
937daa821f Merge #190858: liblqr1: fix compilation on x86_64_darwin
...into release-22.05
2022-09-12 07:13:08 +02:00
github-actions[bot]
d757247ea6 Merge staging-next-22.05 into staging-22.05 2022-09-12 00:16:32 +00:00
github-actions[bot]
1fa0a42afa Merge release-22.05 into staging-next-22.05 2022-09-12 00:16:00 +00:00
Sheldon Neuberger
c6664eda2f liblqr: fix compilation on x86_64_darwin
Add AppKit dependency, fixes error: "ld: file not found:
/System/Library/Frameworks/AppKit.framework/Versions/C/AppKit for
architecture x86_64".

(cherry picked from commit 62020a5be1a4adde90f4599178d39ef41e652134)
2022-09-11 23:27:21 +00:00
Markus S. Wamser
dedd71b121 xmind: 8-update8 -> 8-update9
Previous URL was no longer available.
GTK and JRE dependencies required fixing.

Closes #122916

(cherry picked from commit 51f9cbc44e)
2022-09-11 22:24:07 +00:00
Janne Heß
5c7f84b783 icinga2: 2.13.3 -> 2.13.5 2022-09-11 22:19:31 +02:00
Robert Scott
847ca7a0e3 trafficserver: 9.1.2 -> 9.1.3
(cherry picked from commit 618883d37c)
2022-09-11 19:00:48 +00:00
R. Ryantm
f66ae7bf05 qbittorrent: 4.4.3 -> 4.4.3.1
(cherry picked from commit 7f3e30173afc7dbbb5929e13482a61e749da890a)
2022-09-11 16:55:17 +00:00
Domen Kožar
68dfacf253 Merge pull request #186539 from NixOS/backport-186338-to-release-22.05
[Backport release-22.05] python310Packages.python-fsutil: Unmark broken on Darwin
2022-09-11 16:54:23 +01:00
Domen Kožar
be5d8d456f Merge pull request #190802 from NixOS/backport-190792-to-release-22.05
[22.05] cachix-agent: fix a typo
2022-09-11 16:51:55 +01:00
Domen Kožar
d239c364df cachix-agent: fix a typo
(cherry picked from commit 3f7ba12868)
2022-09-11 15:46:38 +00:00
Maximilian Bosch
281f9cdec6 nixos/nextcloud: fix a deprecation warning in the tests using redis
(cherry picked from commit f72099e0cd)
2022-09-11 08:01:51 +00:00
Maximilian Bosch
a0243bf618 nextcloud: drop password regeneration behavior
While updating to 23.0.9/24.0.5[1], it was discovered that Nextcloud
silently changes db passwords in some cases (in case of MySQL in **all**
now).

This is inherently incompatible with our module. Further context is
provided in the patch file attached to this commit.

[1] https://github.com/NixOS/nixpkgs/pull/190646, see comments below

(cherry picked from commit 958914fab2)
2022-09-11 07:57:12 +00:00
Maximilian Bosch
69ba435080 nextcloud24: 24.0.4 -> 24.0.5
ChangeLog: https://nextcloud.com/changelog/#24-0-5
(cherry picked from commit 1801529961)
2022-09-11 07:56:59 +00:00
Maximilian Bosch
0773518f95 nextcloud23: 23.0.8 -> 23.0.9
ChangeLog: https://nextcloud.com/changelog/#23-0-9
(cherry picked from commit 0e3e28fef0)
2022-09-11 07:56:37 +00:00
Mario Rodas
3b46a31bc1 Merge pull request #190102 from NixOS/backport-190038-to-staging-22.05
[Backport staging-22.05] go_1_18: 1.18.5 -> 1.18.6
2022-09-11 00:44:43 -05:00
Christian Kögler
dd1f4d9824 Merge pull request #190460 from NixOS/backport-190372-to-release-22.05
[Backport release-22.05] github-runner: 2.296.1 -> 2.296.2
2022-09-11 07:38:58 +02:00
Luke Granger-Brown
2efd048150 Merge pull request #190586 from NixOS/backport-189586-to-staging-22.05
[Backport staging-22.05] inetutils: add patch for CVE-2022-39028
2022-09-11 04:24:35 +01:00
1sixth
e6f053b607 qbittorrent: 4.4.2 -> 4.4.3
(cherry picked from commit 4f1a81505f)
2022-09-10 22:42:05 -04:00
Pierre Bourdon
7d90258501 redmine: 4.2.5 -> 4.2.7
(cherry picked from commit 9800628109)
2022-09-10 22:35:25 -04:00
Pierre Bourdon
7c3e548f8a redmine: add nixos test to passthru.tests
(cherry picked from commit 9c642006bd)
2022-09-10 22:35:25 -04:00
Pierre Bourdon
e27e7983f9 redmine: support arch-dependent gem dependencies in update.sh
Method inspired by the update script for `discourse` in nixpkgs.

(cherry picked from commit ec13e46dd1)
2022-09-10 22:35:25 -04:00
Martin Weinelt
78bdf29722 Merge pull request #190723 from risicle/ris-yara-4.2.3-r22.05 2022-09-11 03:43:55 +02:00
github-actions[bot]
29707b94c0 Merge staging-next-22.05 into staging-22.05 2022-09-11 00:16:53 +00:00
github-actions[bot]
3d0f6f058b Merge release-22.05 into staging-next-22.05 2022-09-11 00:16:10 +00:00
Pavol Rusnak
15f892f3b7 Merge pull request #190705 from NixOS/backport-190647-to-release-22.05
[Backport release-22.05] tor: 0.4.7.8 -> 0.4.7.10
2022-09-11 00:51:13 +02:00
Martin Weinelt
39503ad3c7 Merge pull request #190726 from NixOS/backport-190278-to-release-22.05 2022-09-11 00:46:08 +02:00
Martin Weinelt
1488de70f7 Merge pull request #190725 from NixOS/backport-190277-to-release-22.05 2022-09-11 00:45:57 +02:00
R. Ryantm
e9c9c53022 firefox-devedition-bin-unwrapped: 105.0b7 -> 105.0b9
(cherry picked from commit 8362f85e80)
2022-09-10 22:38:41 +00:00
R. Ryantm
524821264d firefox-beta-bin-unwrapped: 105.0b7 -> 105.0b9
(cherry picked from commit 60d0494fe8)
2022-09-10 22:38:12 +00:00
Fabian Affolter
8afde9defe python310Packages.yara-python: 4.2.0 -> 4.2.3
(cherry picked from commit 640409c4d6)
2022-09-10 23:12:25 +01:00
Fabian Affolter
c1433df20d yara: 4.2.2 -> 4.2.3
(cherry picked from commit 5816d32249)
2022-09-10 23:11:48 +01:00
Fabian Affolter
072eef0206 yara: 4.2.1 -> 4.2.2
(cherry picked from commit 9687676754)
2022-09-10 23:11:30 +01:00
R. Ryantm
2defb051af tor: 0.4.7.8 -> 0.4.7.10
(cherry picked from commit ae490fc65ae15b44c5bd09905f24350446b5870c)
2022-09-10 18:00:59 +00:00
Vladimír Čunát
dfcd0b55de thunderbird-bin: 102.2.1 -> 102.2.2
https://www.thunderbird.net/en-US/thunderbird/102.2.2/releasenotes/
(cherry picked from commit 5fe60b2fe5)
2022-09-10 16:11:42 +00:00
Vladimír Čunát
c57b18f428 thunderbird: 102.2.1 -> 102.2.2
https://www.thunderbird.net/en-US/thunderbird/102.2.2/releasenotes/
(cherry picked from commit d487adc4ea)
2022-09-10 16:11:42 +00:00
Benjamin Hipple
15493135c0 Merge pull request #190678 from NixOS/backport-190663-to-release-22.05
[Backport release-22.05] fava: 1.22.2 -> 1.22.3
2022-09-10 11:44:36 -04:00
Thomas Gerbet
376b55df24 fava: 1.22.2 -> 1.22.3
Fixes CVE-2022-2589.
https://github.com/beancount/fava/compare/v1.22.2...v1.22.3

(cherry picked from commit 06e4f6fd65)
2022-09-10 13:16:10 +00:00
Bernardo Meurer
74a002d893 linux/hardened/patches/5.4: 5.4.211-hardened1 -> 5.4.212-hardened1
(cherry picked from commit 1f1aca42d0)
2022-09-10 06:10:09 +00:00
Bernardo Meurer
1f62ca6a19 linux/hardened/patches/5.19: 5.19.6-hardened1 -> 5.19.8-hardened1
(cherry picked from commit 722d9d0d00)
2022-09-10 06:10:09 +00:00
Bernardo Meurer
940ee6cf64 linux/hardened/patches/5.15: 5.15.64-hardened1 -> 5.15.67-hardened1
(cherry picked from commit fa2034286c)
2022-09-10 06:10:09 +00:00
Bernardo Meurer
d929f91930 linux/hardened/patches/5.10: 5.10.140-hardened1 -> 5.10.142-hardened1
(cherry picked from commit d1f6bac7c0)
2022-09-10 06:10:09 +00:00
Bernardo Meurer
1a25927307 linux/hardened/patches/4.19: 4.19.256-hardened1 -> 4.19.257-hardened1
(cherry picked from commit a43178b658)
2022-09-10 06:10:08 +00:00
Bernardo Meurer
42812b1a27 linux/hardened/patches/4.14: 4.14.291-hardened1 -> 4.14.292-hardened1
(cherry picked from commit ec9ecabc95)
2022-09-10 06:10:08 +00:00
Bernardo Meurer
9a7a82b899 linux_latest-libre: 18885 -> 18904
(cherry picked from commit afcc2dafdf)
2022-09-10 06:10:08 +00:00
Bernardo Meurer
1c9d737375 linux-rt_5_10: 5.10.131-rt72 -> 5.10.140-rt73
(cherry picked from commit c000edba79)
2022-09-10 06:10:08 +00:00
Bernardo Meurer
243fff335b linux: 5.4.211 -> 5.4.212
(cherry picked from commit a38d853569)
2022-09-10 06:10:08 +00:00
Bernardo Meurer
9c57971f94 linux: 5.19.6 -> 5.19.8
(cherry picked from commit 2f0101f380)
2022-09-10 06:10:08 +00:00
Bernardo Meurer
bac9b3b323 linux: 5.15.64 -> 5.15.67
(cherry picked from commit cece1283c9)
2022-09-10 06:10:08 +00:00
Bernardo Meurer
d425bdac8b linux: 5.10.140 -> 5.10.142
(cherry picked from commit 2919da7f54)
2022-09-10 06:10:08 +00:00
Bernardo Meurer
ea60cc3699 linux: 4.9.326 -> 4.9.327
(cherry picked from commit 52851d8857)
2022-09-10 06:10:08 +00:00
Bernardo Meurer
b9a8d85edb linux: 4.19.256 -> 4.19.257
(cherry picked from commit 802f5b4771)
2022-09-10 06:10:08 +00:00
Bernardo Meurer
a43f29caf9 linux: 4.14.291 -> 4.14.292
(cherry picked from commit 787baf2459)
2022-09-10 06:10:08 +00:00
github-actions[bot]
b22216e0db Merge staging-next-22.05 into staging-22.05 2022-09-10 00:18:05 +00:00
github-actions[bot]
a39c2c1ca5 Merge release-22.05 into staging-next-22.05 2022-09-10 00:17:21 +00:00
Robert Scott
9241e888d5 inetutils: add patch for CVE-2022-39028
(cherry picked from commit 72d2cd3208)
2022-09-09 23:56:31 +00:00
Robert Scott
34c6af02c9 python3Packages.Mako: 1.2.1 -> 1.2.2
(cherry picked from commit 520042472c)
2022-09-10 00:30:45 +01:00
Jonas Heinrich
8385cf3066 python310Packages.Mako: Add missing check dependency
(cherry picked from commit 2a4169019e)
2022-09-10 00:30:45 +01:00
Jonas Heinrich
2d726a29b4 python310Packages.lingua: init at 4.15.0
(cherry picked from commit 7b7fe29819)
2022-09-10 00:30:44 +01:00
Martin Weinelt
12b6f0d99c python3Packages.Mako: 1.2.0 -> 1.2.1
(cherry picked from commit 54bac49f21)
2022-09-10 00:26:57 +01:00
github-actions[bot]
45b56b5321 gitlab: 15.3.2 -> 15.3.3 (#190480)
https://about.gitlab.com/releases/2022/09/05/gitlab-15-3-3-released/
(cherry picked from commit cd830c5a33b919b69ee3ba0b3b8b09ecbbba020f)

Co-authored-by: Yaya <mak@nyantec.com>
2022-09-09 18:04:15 +02:00
Alex Martens
839a96b547 github-runner: 2.296.1 -> 2.296.2
(cherry picked from commit 482b0ce810)
2022-09-09 09:10:15 +00:00
Yorick van Pelt
5d5223aee9 python3Packages.nose: fix cross-compiling
(cherry picked from commit 27ff1af1cb)
2022-09-08 12:24:08 +00:00
Mario Rodas
e4c4c2d9c1 nodejs-18_x: 18.8.0 -> 18.9.0
https://github.com/nodejs/node/releases/tag/v18.9.0
(cherry picked from commit 53af2c93ce)
2022-09-08 04:20:00 +00:00
github-actions[bot]
8c14c73df2 Merge staging-next-22.05 into staging-22.05 2022-09-08 00:19:07 +00:00
github-actions[bot]
ca4f21e07a Merge release-22.05 into staging-next-22.05 2022-09-08 00:18:24 +00:00
Jonas Heinrich
c7bad05cd7 Merge pull request #190097 from michaeladler/backport-189455-to-release-22.05
brave: 1.42.88 -> 1.43.89
2022-09-07 20:50:20 +02:00
Vladimír Čunát
8d5f0960e7 Merge #189625: firefox-esr*: 91 -> 102 (into release-22.05) 2022-09-07 14:42:27 +02:00
Vladimír Čunát
8f435f5a4c Merge #189627: thunderbird*: 91 -> 102 (into release-22.05) 2022-09-07 14:40:09 +02:00
Franz Pletz
e9c0bf4314 Merge pull request #190115 from NixOS/backport-189932-to-release-22.05
[Backport release-22.05] klibc: fix KLIBCARCH=riscv64
2022-09-07 14:03:45 +02:00
Astro
b35dbc389a klibc: fix KLIBCARCH=riscv64
(cherry picked from commit 694fc2fffe)
2022-09-07 10:56:46 +00:00
zowoq
2aec372cdc go_1_18: 1.18.5 -> 1.18.6
(cherry picked from commit 08837acea8e5d655b5720d7c882d9172b2b28f14)
2022-09-07 07:44:12 +00:00
Michael Adler
06c8f7c3ed brave: 1.42.88 -> 1.43.89
(cherry picked from commit b5dbb07543)
2022-09-07 07:53:00 +02:00
github-actions[bot]
9743c0b07d Merge staging-next-22.05 into staging-22.05 2022-09-07 00:15:46 +00:00
github-actions[bot]
3f1eb203e8 Merge release-22.05 into staging-next-22.05 2022-09-07 00:15:12 +00:00
superherointj
5aeb3fb419 Merge pull request #190003 from moduon/k3s-1.23.10+k3s1
k3s: 1.23.6+k3s1 -> 1.23.10+k3s1
2022-09-06 16:58:19 -03:00
Artturi
a2c10a7a38 Merge pull request #190032 from NixOS/backport-189961-to-release-22.05 2022-09-06 22:16:05 +03:00
Zhaofeng Li
617c1a577a steam: Disable udev-based joystick discovery for SDL2
Fixes #101281.

(cherry picked from commit b84625ee73)
2022-09-06 17:27:32 +00:00
Martin Weinelt
a05e902112 Merge pull request #189903 from NixOS/backport-189881-to-release-22.05 2022-09-06 18:26:00 +02:00
Jairo Llopis
8a5f38937d k3s: 1.23.6+k3s1 -> 1.23.10+k3s1
Proposing directly to release-22.05 because master already is on 1.24.x.

@moduon MT-1075
2022-09-06 13:43:46 +01:00
ash
694761d594 less: 600 -> 608
Back on a recommended/non-beta version.

http://greenwoodsoftware.com/less/news.608.html
(cherry picked from commit b61fb50dde)
2022-09-06 12:09:18 +00:00
Bobby Rong
d2f66009e5 Merge pull request #189719 from sersorrel/backport-189610-to-release-22.05
[22.05] xivlauncher: 1.0.0.9 -> 1.0.1.0
2022-09-06 11:31:09 +08:00
Bobby Rong
7abf71a40b Merge pull request #189861 from NixOS/backport-154860-to-release-22.05
[Backport release-22.05] findup: init at 1.0
2022-09-06 11:26:54 +08:00
Martin Weinelt
a925e4ddee Merge pull request #189933 from NixOS/backport-188803-to-release-22.05 2022-09-06 03:12:06 +02:00
Ivar Scholten
c33ffee5e6 nodejs-18_x: fix cross compilation to aarch64-linux
This adds a patch reverting https://github.com/nodejs/node/pull/43200 because it breaks
cross compilation to aarch64-linux. Gcc would not recognize the
`-msign-return-address=all` flag causing compilation to fail.

(cherry picked from commit 71b85973dd)
2022-09-06 02:57:08 +02:00
github-actions[bot]
6ed1c2e8ee Merge staging-next-22.05 into staging-22.05 2022-09-06 00:16:37 +00:00
github-actions[bot]
d3763d80d6 Merge release-22.05 into staging-next-22.05 2022-09-06 00:15:55 +00:00
Robert Scott
17ef0b9479 python3Packages.markdown2: add patch for xss issue SNYK-PYTHON-MARKDOWN2-2606985
(cherry picked from commit c64ca0283b)
2022-09-05 23:54:56 +00:00
Robert Scott
f0b8e5f428 python3Packages.markdown2: 2.4.1 -> 2.4.3
(cherry picked from commit 7f0b3c288f)
2022-09-05 23:54:56 +00:00
Robert Scott
047d50513c python3Packages.markdown2: fix tests to actually run
(cherry picked from commit 26501c5268)
2022-09-05 23:54:56 +00:00
Martin Weinelt
f955b60d31 firefox-devedition-bin-unwrapped: 105.0b4 -> 105.0b7
(cherry picked from commit 18b89d7c1e)
2022-09-05 20:20:23 +00:00
Martin Weinelt
a31d570560 firefox-beta-bin-unwrapped: 105.0b4 -> 105.0b7
(cherry picked from commit 40e7fcaf28)
2022-09-05 20:20:23 +00:00
Martin Weinelt
f7604b85a0 firefox-bin-unwrapped: 104.0.1 -> 104.0.2
https://www.mozilla.org/en-US/firefox/104.0.2/releasenotes/
(cherry picked from commit 5e03faff77)
2022-09-05 20:20:23 +00:00
Martin Weinelt
12d3513f8d firefox-unwrapped: 104.0.1 -> 104.0.2
https://www.mozilla.org/en-US/firefox/104.0.2/releasenotes/
(cherry picked from commit c9a750458f)
2022-09-05 20:20:23 +00:00
hiljusti
e0c0da0f3a findup: init at 1.0
(cherry picked from commit f78e768d49)
2022-09-05 14:26:09 +00:00
Martin Weinelt
2dd5d3707c Merge pull request #189856 from NixOS/backport-189852-to-release-22.05 2022-09-05 15:45:19 +02:00
Erik Arvstedt
25e107b443 paperless: move PYTHONPATH definition to module
`paperless-ngx.pythonPath` was incomplete due to the missing paperless-ngx
source, so it had to be amended in the service.
Instead of amending it, define it entirely in the service.

This allows an override of `paperless-ngx.propagatedBuildInputs` to be reflected
in the service's PYTHONPATH.

(cherry picked from commit 783f8f16c1)
2022-09-05 15:43:34 +02:00
Erik Arvstedt
0de8039907 nixos/paperless: extract variable pkg
(cherry picked from commit 310b9fe58d)
2022-09-05 13:31:52 +00:00
Jan Tojnar
d39035792e gnome.sushi: Fix video previews
GStreamer was missing gtksink element.

Fixes: https://github.com/NixOS/nixpkgs/issues/182542
(cherry picked from commit 09e38a1d8a8c034ec8be0fc2fd1b22139855a66d)
2022-09-05 07:53:46 +02:00
github-actions[bot]
2c145eac69 Merge staging-next-22.05 into staging-22.05 2022-09-05 00:19:10 +00:00
github-actions[bot]
6a5ffa97c2 Merge release-22.05 into staging-next-22.05 2022-09-05 00:18:28 +00:00
Martin Weinelt
50c62eeda9 Merge pull request #189731 from mweinelt/22.05/papercuts 2022-09-04 20:26:40 +02:00
Guillaume Girol
687478dcf9 Merge pull request #187902 from ereslibre/backport-wasmtime-0-39-1
wasmtime: backport to release-22.05
2022-09-04 18:11:40 +00:00
R. Ryantm
bce0890777 btcpayserver: 1.6.9 -> 1.6.10
(cherry picked from commit 4ae959e949)
2022-09-04 17:36:07 +00:00
Martin Weinelt
f39ae5f8cc nixos/paperless: Restrict CAP_NET_BIND_SERVICE
Handing CAP_NET_BIND_SERVICE to the `paperless-web.service` only makes
sense when it actually wants to bind to a port < 1024. Don't hand it out
if that is not the case.

(cherry picked from commit f98011803e)
2022-09-04 16:41:24 +02:00
Martin Weinelt
243024303e paperless: Expose python environment in passthru
This allows adding more python dependencies through overrides.

(cherry picked from commit 73e10d9d5a)
2022-09-04 16:41:11 +02:00
Martin Weinelt
69e2c9fa84 nixos/paperless: Add pgsql via unix socket example
Finding out how to connect paperless to a PostgreSQL database via unix
sockets and peer authentication took me a few minutes, so leaving a hint
in the extraConfig example seems like a good idea to me.

Also remove unnecessary use of literalExpression for attribute set, it
is only required for complex values like functions or values that depend
on other values or packages.

(cherry picked from commit 2d257f8101)
2022-09-04 16:40:20 +02:00
Martin Weinelt
285f7393e3 nixos/paperless: Allow mbind syscall in paperless-web.services
After uploading a document through the webinterface I started seeing
it killed through the SYSBUS signal. Inspecting the call trace led me to
liblapack's memory allocator, that uses the mbind syscall on Linux.

(cherry picked from commit 94f00041f0)
2022-09-04 16:40:14 +02:00
ash
111bb01927 xivlauncher: add sersorrel to maintainers
(cherry picked from commit ebafad7e76)
2022-09-04 14:12:12 +01:00
ash
b06fb8a17a xivlauncher: 1.0.0.9 -> 1.0.1.0
(cherry picked from commit 92354582dd)
2022-09-04 12:50:55 +01:00
Christian Kögler
b5e7357fa6 Merge pull request #189361 from NixOS/backport-180149-to-release-22.05
[Backport release-22.05] nixos/gitlab: fix registry.issuer setting
2022-09-04 12:53:05 +02:00
Rafael Fernández López
fbbd4e310b wasmtime: disable tests on x86_64-darwin
Remove tests on x86_64-darwin to avoid specific false errors due to
the way Hydra runners are set up for this architecture.

On this platform, on Hydra runners we see: `SIMD support requires
SSE3, SSSE3, SSE4.1, and SSE4.2 on x86_64.` present in all failing
tests.

Thus, do not run tests on this platform to avoid false reports of this
derivation being broken, because Hydra runners are set up in a way
that this CPU features are not available.

An example of automation marking this derivation as broken because the
Hydra runs were reporting failures: 03bc571744.

(cherry picked from commit 9c59fd919f)
2022-09-04 11:39:25 +02:00
Thomas Gerbet
7bfb89a490 wasmtime: 0.38.0 -> 0.39.1
https://github.com/bytecodealliance/wasmtime/blob/v0.39.1/RELEASES.md

Fixes CVE-2022-31146 and CVE-2022-31169.

(cherry picked from commit 03119abf6b)
2022-09-04 11:39:17 +02:00
Rafael Fernández López
9b2080da37 wasmtime: 0.37.0 -> 0.38.0
(cherry picked from commit d4ed4c52e1)
2022-09-04 11:39:07 +02:00
Rafael Fernández López
ccf0b5488d wasmtime: remove unneeded dependencies
Also, add `ereslibre` as a maintainer

(cherry picked from commit 7042b2fd9c)
2022-09-04 11:38:57 +02:00
superherointj
f3d1f91481 Merge pull request #186904 from NixOS/backport-185833-to-release-22.05
[Backport release-22.05] opentrack: 2.1.3 → 2022.3.0
2022-09-04 05:02:19 -03:00
github-actions[bot]
e43e068fb5 Merge staging-next-22.05 into staging-22.05 2022-09-04 00:16:47 +00:00
github-actions[bot]
2557956405 Merge release-22.05 into staging-next-22.05 2022-09-04 00:16:12 +00:00
Vladimír Čunát
f4ef4dbd6e thunderbird*: 91 -> 102
The upstream support of 91 branch is already ending around now,
so let's switch the default.
2022-09-03 18:45:17 +02:00
Martin Weinelt
e52f995282 firefox-esr{,-unwrapped,-wayland}: 91 -> 102
The 91 release tree has a planned end of life in 2022/09 and the 102
tree is its successor.

Includes some reordering that makes more sense to me.

(cherry picked from commit 5dfa9b0ee9)
2022-09-03 16:34:50 +00:00
Martin Weinelt
013e8d86d9 Merge pull request #189502 from NixOS/backport-189492-to-release-22.05 2022-09-03 18:15:33 +02:00
Michael Weiss
33e7c8706e Merge pull request #189604 from NixOS/backport-189592-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 105.0.5195.54 -> 105.0.5195.102
2022-09-03 17:16:51 +02:00
Michael Weiss
38665e38f4 ungoogled-chromium: 105.0.5195.54 -> 105.0.5195.102
(cherry picked from commit 82d8999e04)
2022-09-03 13:34:35 +00:00
Michele Guerini Rocco
a69918f60e Merge pull request #186792 from rnhmjoj/pr-monero-back
[22.05] monero-{cli,gui}: 0.17.3.2 -> 0.18.1.0
2022-09-03 11:23:25 +02:00
Michael Weiss
c49f566944 Merge pull request #189524 from primeos/chromium-backport
[22.05] chromium: 104.0.5112.101 -> 105.0.5195.102 + ungoogled-chromium
2022-09-03 10:53:13 +02:00
Jonas Heinrich
3bd415994d Merge pull request #189239 from Ma27/element-web-update-22.05
[22.05] element-{web,desktop}: 1.11.0 -> 1.11.4, fix CVE-2022-36059 & CVE-2022-36060
2022-09-03 09:24:16 +02:00
Jörg Thalheim
556a6d9a89 rustup: also patch binaries in libexec
fixes https://github.com/NixOS/nixpkgs/issues/186052

(cherry picked from commit 56a690d7fb)
2022-09-03 06:17:58 +00:00
adisbladis
0214a7c3e3 Merge pull request #189545 from NixOS/backport-187968-to-release-22.05
[Backport release-22.05] emacs: Enable xinput2 on version 29 and newer
2022-09-03 17:58:00 +12:00
adisbladis
29f1ae3a49 emacs: Enable xinput2 on version 29 and newer
(cherry picked from commit ca25a9c7b2)
2022-09-03 03:46:21 +00:00
adisbladis
17707baee4 emacs: Simplify patchelf invocation when building with lucid
(cherry picked from commit 73c90badf3)
2022-09-03 03:46:21 +00:00
github-actions[bot]
7752a6685e Merge staging-next-22.05 into staging-22.05 2022-09-03 00:14:59 +00:00
github-actions[bot]
008ef98387 Merge release-22.05 into staging-next-22.05 2022-09-03 00:14:25 +00:00
Michael Weiss
92ef1e231e ungoogled-chromium: 104.0.5112.102 -> 105.0.5195.54
(cherry picked from commit f9e02fa945)
2022-09-03 01:18:10 +02:00
Michael Weiss
6d7507be62 chromium: 105.0.5195.52 -> 105.0.5195.102
https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop.html

This update includes 1 security fix. Google is aware of reports that an exploit
for CVE-2022-3075 exists in the wild.

CVEs:
CVE-2022-3075

(cherry picked from commit ac10e9551d)
2022-09-03 01:18:10 +02:00
Michael Weiss
2ccae06c29 chromium: Fix the build
The build was failing with the following error:
```
[18950/51180] SOLINK ./libvk_swiftshader.sotls_transport_interface/dtls_transport_interface.omputils.o[K.otch.oos.oKx/unbundle:default)fault)ault)
FAILED: libvk_swiftshader.so libvk_swiftshader.so.TOC
python3 "../../build/toolchain/gcc_solink_wrapper.py" --readelf="readelf" --nm="nm"  --sofile="./libvk_swiftshader.so" --tocfile="./libvk_swiftshader.so.TOC" --output="./libvk_swiftshader.so" -- clang++ -shared -Wl,-soname="libvk_swiftshader.so" -Wl,-Bsymbolic -Wl,--version-script=../../third_party/swiftshader/src/Vulkan/vk_swiftshader.lds -fuse-ld=lld -Wl,--fatal-warnings -Wl,--build-id=sha1 -fPIC -Wl,-z,noexecstack -Wl,-z,relro -Wl,-z,now -Wl,--icf=all -Wl,--color-diagnostics -Wl,-mllvm,-instcombine-lower-dbg-declare=0 -flto=thin -Wl,--thinlto-jobs=all -Wl,--thinlto-cache-dir=thinlto-cache -Wl,--thinlto-cache-policy=cache_size=10\%:cache_size_bytes=40g:cache_size_files=100000 -Wl,-mllvm,-import-instr-limit=30 -fwhole-program-vtables -Wl,--no-call-graph-profile-sort -m64 -no-canonical-prefixes -Wl,-O2 -Wl,--gc-sections -rdynamic -Wl,-z,defs -Wl,--as-needed -nostdlib++ -Wl,--lto-O0 -fsanitize=cfi-vcall -fsanitize=cfi-icall -o "./libvk_swiftshader.so" @"./libvk_swiftshader.so.rsp"
ld.lld: error: unable to find library -l:libffi_pic.a
clang++: error: linker command failed with exit code 1 (use -v to see invocation)
```

This turned out to be a regression from b6b51374fc. That change was
bad/undesirable in the first place and I only applied it to quickly fix
another build error caused by incompatible wayland-protocols header
files from a newer system version (Chromium bundles version 1.21 while
we already package 1.26).

The better fix for that wayland-protocols build issue is to pull in a
patch that is already used/tested by the Arch package [0] and seems to
originate from [1] (not sure if that patch was formally submitted yet).

Alternatives to that patch would be to (we should probably first try the
first approach if need be):
1) Build with wayland-protocols 1.21 from the system (by overriding the
   Nixpkgs package).
2) Dynamically link against libffi by patching [2] to use the other
   branch (`default_toolchain == "//build/toolchain/cros:target"`).

Some additional details can be found in the GitHub PR [3].
Huge thanks to Lorenz Brun for his great analysis that enabled me to fix
the build so that we can finally merge the update to Chromium M105
(which contains many important security fixes!).

[0]: a353833a5a
[1]: https://bugs.chromium.org/p/angleproject/issues/detail?id=7582#c1
[2]: https://source.chromium.org/chromium/chromium/src/+/refs/tags/105.0.5195.52:build/config/linux/libffi/BUILD.gn
[3]: https://github.com/NixOS/nixpkgs/pull/189033

Co-Authored-By: Lorenz Brun <lorenz@brun.one>
(cherry picked from commit d932886d6e)
2022-09-03 01:18:09 +02:00
Michael Weiss
c61ec9e788 chromium: 104.0.5112.101 -> 105.0.5195.52
https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_30.html

This update includes 24 security fixes.

CVEs:
CVE-2022-3038 CVE-2022-3039 CVE-2022-3040 CVE-2022-3041 CVE-2022-3042
CVE-2022-3043 CVE-2022-3044 CVE-2022-3045 CVE-2022-3046 CVE-2022-3047
CVE-2022-3048 CVE-2022-3049 CVE-2022-3050 CVE-2022-3051 CVE-2022-3052
CVE-2022-3053 CVE-2022-3054 CVE-2022-3055 CVE-2022-3056 CVE-2022-3057
CVE-2022-3058

(cherry picked from commit 360844281a)
2022-09-03 01:18:09 +02:00
Michael Weiss
0b1090e62e Merge pull request #189520 from primeos/chromium-backport
[22.05] Prepare for backporting Chromium M105
2022-09-03 01:16:19 +02:00
Stefan Radziuk
369c727760 chromium: add commandLineArgs after wayland flags (#189371)
(cherry picked from commit d32eae0f23)
2022-09-03 00:51:01 +02:00
Stefan Radziuk
dfa1f11a34 google-chrome: add commandLineArgs after wayland flags (#189199)
(cherry picked from commit 1be806f07f)
2022-09-03 00:51:01 +02:00
Michael Weiss
1bc63f680d chromiumDev: 106.0.5245.0 -> 106.0.5249.12
(cherry picked from commit 50e7538f3e)
2022-09-03 00:51:01 +02:00
Michael Weiss
5006760920 chromiumBeta: Fix errors due to incompatible Wayland headers
This "fixes" errors like these:
```
FAILED: obj/third_party/angle/angle_gpu_info_util/SystemInfo_vulkan.o
[...]
In file included from ../../third_party/wayland/src/src/wayland-client.h:40:
/nix/store/an42rhwn6ck2nix6caikrr4rvizknjhh-wayland-1.21.0-dev/include/wayland-client-protocol.h:1040:13: error: use of undeclared identifier 'wl_proxy_marshal_flags'
        callback = wl_proxy_marshal_flags((struct wl_proxy *) wl_display,
                   ^
[...]
/nix/store/an42rhwn6ck2nix6caikrr4rvizknjhh-wayland-1.21.0-dev/include/wayland-client-protocol.h:1392:87: error: use of undeclared identifier 'WL_MARSHAL_FLAG_DESTROY'
                         WL_SHM_POOL_DESTROY, NULL, wl_proxy_get_version((struct wl_proxy *) wl_shm_pool), WL_MARSHAL_FLAG_DESTROY);
                                                                                                           ^
[...]
fatal error: too many errors emitted, stopping now [-ferror-limit=]
```

At least for now (until Chromium updates their bundled Wayland version) it
seems best to use the bundled headers/versions to avoid version incompatibility
issues (we should hopefully be able to drop use_system_wayland_scanner though).

(cherry picked from commit b6b51374fc)
2022-09-03 00:51:01 +02:00
Michael Weiss
679c505d8e chromiumBeta: 105.0.5195.37 -> 105.0.5195.52
(cherry picked from commit a5cb5ba44a)
2022-09-03 00:51:00 +02:00
Michael Weiss
1076de3f5b chromiumDev: 106.0.5231.2 -> 106.0.5245.0
(cherry picked from commit 872ca61379)
2022-09-03 00:51:00 +02:00
Michael Weiss
11ad494717 chromiumBeta: 105.0.5195.28 -> 105.0.5195.37
(cherry picked from commit d0bbad1246)
2022-09-03 00:51:00 +02:00
Michael Weiss
935a287eba chromiumDev: 106.0.5216.6 -> 106.0.5231.2
(cherry picked from commit 0e03ad366a)
2022-09-03 00:50:59 +02:00
Michael Weiss
c312ffb328 chromiumBeta: 105.0.5195.19 -> 105.0.5195.28
(cherry picked from commit 61063f3276)
2022-09-03 00:50:59 +02:00
Michael Weiss
6e54d818bc chromiumDev: 105.0.5195.19 -> 106.0.5216.6
(cherry picked from commit 22eae24df0)
2022-09-03 00:50:59 +02:00
Michael Weiss
456bc2e564 chromiumBeta: 104.0.5112.79 -> 105.0.5195.19
(cherry picked from commit a43bf95ad0)
2022-09-03 00:50:58 +02:00
Michael Weiss
f1b1c741af chromiumDev: 105.0.5195.10 -> 105.0.5195.19
(cherry picked from commit 201eb18f4d)
2022-09-03 00:50:58 +02:00
Michael Weiss
5beb4da537 chromiumBeta: 104.0.5112.65 -> 104.0.5112.79
(cherry picked from commit 8ce54794cc)
2022-09-03 00:50:58 +02:00
Michael Weiss
6b02cc42e6 chromiumDev: 105.0.5191.2 -> 105.0.5195.10
(cherry picked from commit b746ec7446)
2022-09-03 00:50:57 +02:00
Michael Weiss
267aaa09bc chromiumBeta: 104.0.5112.57 -> 104.0.5112.65
(cherry picked from commit 5af5104501)
2022-09-03 00:50:57 +02:00
Michael Weiss
0cd8b8ec71 chromiumDev: 105.0.5176.3 -> 105.0.5191.2
(cherry picked from commit 92bb481cd7)
2022-09-03 00:50:57 +02:00
Michael Weiss
fff867de58 chromiumBeta: 104.0.5112.48 -> 104.0.5112.57
(cherry picked from commit 9e393ee5dd)
2022-09-03 00:50:56 +02:00
Michael Weiss
7fbe0334a1 chromiumDev: 105.0.5148.2 -> 105.0.5176.3
(cherry picked from commit ddf49ce022)
2022-09-03 00:50:56 +02:00
Michael Weiss
3f192407b0 chromiumBeta: 104.0.5112.39 -> 104.0.5112.48
(cherry picked from commit 41a5ec97d5)
2022-09-03 00:50:56 +02:00
Michael Weiss
bf11ada791 chromiumBeta: 104.0.5112.29 -> 104.0.5112.39
(cherry picked from commit 8d73ee9187)
2022-09-03 00:50:55 +02:00
Michael Weiss
1014181914 chromiumDev: 104.0.5112.20 -> 105.0.5148.2
(cherry picked from commit 924540c6c7)
2022-09-03 00:50:55 +02:00
Michael Weiss
181dcc0097 chromiumBeta: 104.0.5112.20 -> 104.0.5112.29
(cherry picked from commit b19cb885f3)
2022-09-03 00:50:55 +02:00
Michael Weiss
8c0adb83e8 chromiumDev: 104.0.5112.12 -> 104.0.5112.20
(cherry picked from commit 4a4f0cc411)
2022-09-03 00:50:54 +02:00
Michael Weiss
8c0e24082c chromiumBeta: 103.0.5060.53 -> 104.0.5112.20
(cherry picked from commit 57a56ee3d5)
2022-09-03 00:50:54 +02:00
George Shammas
c4bd479532 chromium: improve kerberos support
(cherry picked from commit acef4bfe61)
2022-09-03 00:26:58 +02:00
Vladimír Čunát
61e74be21b thunderbird*: 102.2.1 -> 102.2.2
https://www.thunderbird.net/en-US/thunderbird/102.2.1/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-38/
(cherry picked from commit 935aa2d5fd)
2022-09-02 19:49:57 +00:00
kilianar
253ccce6af signal-desktop: 5.56.0 -> 5.57.0
https://github.com/signalapp/Signal-Desktop/releases/tag/v5.57.0
(cherry picked from commit 1ac9fea548)
2022-09-02 17:48:53 +02:00
Timothy DeHerrera
3dbcc95224 Merge pull request #189467 from NixOS/backport-187478-to-release-22.05
[Backport release-22.05] gamescope: 3.11.33-jupiter-3.3-2 -> 3.11.39
2022-09-02 08:34:12 -06:00
Timothy DeHerrera
7524eee28e gamescope: 3.11.33-jupiter-3.3-2 -> 3.11.39
(cherry picked from commit a8b135297c4926cc98d60eac40e6c5f0233c52cb)
2022-09-02 14:27:09 +00:00
Timothy DeHerrera
d549290eee libliftoff: 0.2.0 -> 0.3.0
(cherry picked from commit 508b6b66575af5161755a9abbbf207a8edda562a)
2022-09-02 14:27:09 +00:00
Bobby Rong
3321eea12a Merge pull request #189121 from NixOS/backport-189085-to-release-22.05
[Backport release-22.05] tor-browser-bundle-bin: 11.5.1 -> 11.5.2
2022-09-02 20:00:21 +08:00
Michele Guerini Rocco
d0a57b9205 Merge pull request #189413 from NixOS/backport-189374-to-release-22.05
[Backport release-22.05] pdns-recursor: 4.7.1 -> 4.7.2
2022-09-02 10:28:54 +02:00
R. Ryantm
e5dea85646 pdns-recursor: 4.7.1 -> 4.7.2
(cherry picked from commit bd1c1724d1)
2022-09-02 08:12:13 +00:00
Vladimír Čunát
67e4507814 Merge #189097: staging-next-22.05 - iteration9 2022-09-02 08:22:40 +02:00
Vladimír Čunát
2168f9454c sqlite-replication: fixup build after d915be48c6
It *might* have some vulnerabilities, though.
It seems to be quite an old version.
2022-09-02 08:21:20 +02:00
github-actions[bot]
7314bae423 Merge staging-next-22.05 into staging-22.05 2022-09-02 00:16:03 +00:00
github-actions[bot]
77becd89dc Merge release-22.05 into staging-next-22.05 2022-09-02 00:15:21 +00:00
Mario Rodas
f4160d8a7b Merge pull request #189279 from NixOS/backport-189262-to-release-22.05
[Backport release-22.05] yt-dlp: 2022.8.19 -> 2022.9.1
2022-09-01 18:08:54 -05:00
WilliButz
f4c64b6d1c nixos/gitlab: fix registry.issuer setting
Prior to this change, the configuration value for
`services.gitlab.registry.issuer` was only referenced by the
docker-registry configuration and in the `gitlab-registry-cert` service
while the gitlab config used the hard-coded value "gitlab-issuer".

(cherry picked from commit e2a322b3cd)
2022-09-01 22:21:37 +00:00
Pavol Rusnak
c0a4213bfe Merge pull request #189348 from NixOS/backport-189302-to-release-22.05
[Backport release-22.05] trezor-suite: 22.3.2 -> 22.8.2
2022-09-01 23:02:07 +02:00
matthewcroughan
4b883b17c4 trezor-suite: 22.3.2 -> 22.8.2
(cherry picked from commit ed5bd9d73d)
2022-09-01 20:44:58 +00:00
Martin Weinelt
612d4e9152 Merge pull request #189315 from NixOS/backport-189312-to-release-22.05 2022-09-01 20:52:42 +02:00
Martin Weinelt
806c505b8a python3Packages.dateparser: patch flaky test
The dateparser module has a test that works with the current day of the
month and uses it in June 2020. This breaks everytime we build the
package on the 31st of a month, because June only has 30 days.

```
❯ cal 6 2020
      Juni 2020
Mo Di Mi Do Fr Sa So
 1  2  3  4  5  6  7
 8  9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30
```

https://github.com/scrapinghub/dateparser/issues/1053
(cherry picked from commit 0cece84ef3)
2022-09-01 17:48:53 +00:00
adisbladis
907f78efd7 Merge pull request #189283 from adisbladis/hatch-fancy-pypi-readme-backport
[Backport release-22.05] python310Packages.hatch-fancy-pypi-readme: init at 22.3.0
2022-09-02 03:34:37 +12:00
Vladimír Čunát
b687cd3b7a Merge branch 'release-22.05' into staging-next-22.05 2022-09-01 17:24:44 +02:00
Vladimír Čunát
8d33f2b085 Merge #189285: Linux Kernel update 5.19.6 date 2022-08-31
...into staging-next-22.05
2022-09-01 17:05:25 +02:00
superherointj
9d20de0edb linux/hardened/patches/5.19: 5.19.5-hardened1 -> 5.19.6-hardened1
(cherry picked from commit a37389d4fe)
2022-09-01 15:00:01 +00:00
superherointj
44125fe10e linux/hardened/patches/5.15: 5.15.63-hardened1 -> 5.15.64-hardened1
(cherry picked from commit 3c23d0194e)
2022-09-01 15:00:01 +00:00
superherointj
3aeaae51af linux/hardened/patches/5.10: 5.10.139-hardened1 -> 5.10.140-hardened1
(cherry picked from commit 7afe0b6ec7)
2022-09-01 15:00:01 +00:00
superherointj
11ba3c7466 linux: 5.19.5 -> 5.19.6
(cherry picked from commit 7210ee48ed)
2022-09-01 15:00:01 +00:00
superherointj
61543b5419 linux: 5.15.63 -> 5.15.64
(cherry picked from commit 666470c12d)
2022-09-01 15:00:01 +00:00
superherointj
958c6d8b99 linux: 5.10.139 -> 5.10.140
(cherry picked from commit 7168244a19)
2022-09-01 15:00:01 +00:00
Theodore Ni
d794db6803 python310Packages.hatch-fancy-pypi-readme: init at 22.3.0
This is depended upon by the newest python310Packages.jsonschema.

(cherry picked from commit b0beaa821e)
2022-09-02 02:53:21 +12:00
zowoq
e2dc3d8fb9 yt-dlp: 2022.8.19 -> 2022.9.1
https://github.com/yt-dlp/yt-dlp/releases/tag/2022.09.01
(cherry picked from commit eae91dafb8)
2022-09-01 14:26:30 +00:00
Maximilian Bosch
97400f8943 element-desktop: work around broken resolutions 2022-09-01 12:07:44 +02:00
Robert Scott
b82ccafb54 poppler: add patch for CVE-2022-38784
(cherry picked from commit 04ca702625)
/cc original PR #189196
2022-09-01 11:41:59 +02:00
Maximilian Bosch
5e01e0a09f element-{web,desktop}: 1.11.0 -> 1.11.4, fix CVE-2022-36059 & CVE-2022-36060
Backport of #189150, #186133.
2022-09-01 11:24:57 +02:00
Vladimír Čunát
4ffd044774 Merge #188268: linux_5_4_hardened: don't build on x86_64-linux
...into release-22.05
2022-09-01 10:05:22 +02:00
Doron Behar
374d334335 Merge pull request #188940 from kini/backport-188774-to-release-22.05 2022-09-01 05:44:43 +00:00
Christian Kögler
9ad42e7902 Merge pull request #189214 from NixOS/backport-189203-to-release-22.05
[Backport release-22.05] github-runner: 2.296.0 -> 2.296.1
2022-09-01 07:18:19 +02:00
Alex Martens
565d04e5a7 github-runner: 2.296.0 -> 2.296.1
(cherry picked from commit 550179b49d)
2022-09-01 02:36:18 +00:00
superherointj
e5be8a487d Merge pull request #189207 from NixOS/backport-189171-to-release-22.05
[Backport release-22.05] drogon: 1.7.5 -> 1.8.0
2022-08-31 22:21:23 -03:00
urlordjames
d32151d198 drogon: 1.7.5 -> 1.8.0
(cherry picked from commit ce7f162232)
2022-09-01 01:20:10 +00:00
github-actions[bot]
11f82604eb Merge staging-next-22.05 into staging-22.05 2022-09-01 00:17:07 +00:00
github-actions[bot]
47376b09d7 Merge release-22.05 into staging-next-22.05 2022-09-01 00:16:22 +00:00
Robert Scott
7d7622909a Merge pull request #189175 from NixOS/backport-189007-to-release-22.05
[Backport release-22.05] openscad: add patches for CVE-2022-0496 & CVE-2022-0497
2022-08-31 22:51:28 +01:00
Robert Scott
96a0d7f638 openscad: add patches for CVE-2022-0496 & CVE-2022-0497
(cherry picked from commit 3bfe6bfca2)
2022-08-31 20:44:37 +00:00
Christian Kögler
067d5d5b89 Merge pull request #187718 from NixOS/backport-182355-to-release-22.05
[Backport release-22.05] anki-bin: 2.1.52 -> 2.1.54
2022-08-31 21:09:52 +02:00
Maximilian Bosch
564fb6977e Merge pull request #189124 from NixOS/backport-189115-to-release-22.05
[Backport release-22.05] matrix-synapse: 1.65.0 -> 1.66.0
2022-08-31 17:52:43 +02:00
Nick Cao
00880b83c5 matrix-synapse: 1.65.0 -> 1.66.0
(cherry picked from commit eeefc8f733)
2022-08-31 15:14:19 +00:00
Nicolas Benes
ecf962fddd tor-browser-bundle-bin: 11.5.1 -> 11.5.2
(cherry picked from commit 9895ba4b77)
2022-08-31 14:36:58 +00:00
Maximilian Bosch
7346c9f08a Merge pull request #189040 from delroth/grafana-cve-2022-31176-22.05
[22.05] grafana, grafana-image-renderer: bump for CVE-2022-31176
2022-08-31 13:32:15 +02:00
Jörg Thalheim
05e39014e9 Merge pull request #189093 from Mic92/nearcore-backport
[release-22.05] nearcore: 1.27.0 -> 1.28.1
2022-08-31 12:01:06 +01:00
Vladimír Čunát
d5f435b411 Merge branch 'staging-22.05' into staging-next-22.05 2022-08-31 12:13:10 +02:00
Vladimír Čunát
838e102f80 Merge #188936: linux kernel update 2022-08-29
...into staging-22.05
2022-08-31 12:10:58 +02:00
Vladimír Čunát
850a974a67 Merge #189032: webkitgtk: 2.36.5 -> 2.36.7
...into staging-22.05
2022-08-31 12:09:48 +02:00
Jörg Thalheim
087e65d47d nearcore: 1.28.0 -> 1.28.1
(cherry picked from commit 4f805873ff)
2022-08-31 11:57:00 +02:00
Jörg Thalheim
c8e4e2b4ef nearcore: 1.27.0 -> 1.28.0
(cherry picked from commit f97bbb81129555db2a4596bc29922aa02f5b9f74)
2022-08-31 11:57:00 +02:00
Malte Brandy
e33722b5bb haskell.packages.ghc924.hiedb: dontCheck
(cherry picked from commit 3ca851a1d1)
2022-08-31 11:50:43 +02:00
Yaya
4080979819 gitlab: 15.3.1 -> 15.3.2
https://about.gitlab.com/releases/2022/08/30/critical-security-release-gitlab-15-3-2-released/

Resolves CVE-2022-2992 CVE-2022-2865 CVE-2022-2527
         CVE-2022-2592 CVE-2022-2533 CVE-2022-2455
         CVE-2022-2428 CVE-2022-2908 CVE-2022-2630
         CVE-2022-2931 CVE-2022-2907 CVE-2022-3031

(cherry picked from commit 0cacf01164c368ba68e9de23a00592d15de8332c)
2022-08-30 20:31:40 -04:00
github-actions[bot]
954b70c4a1 Merge staging-next-22.05 into staging-22.05 2022-08-31 00:19:57 +00:00
github-actions[bot]
ec0c5b3376 Merge release-22.05 into staging-next-22.05 2022-08-31 00:19:20 +00:00
Pierre Bourdon
fa939aa785 grafana: 8.5.9 -> 8.5.11 (CVE-2022-31176) 2022-08-31 02:16:22 +02:00
Pierre Bourdon
d8f80a07c6 grafana-image-renderer: 3.4.0 -> 3.6.1 (CVE-2022-31176)
(cherry picked from commit d4ada97520)
2022-08-31 01:50:24 +02:00
Martin Weinelt
20b8998f32 webkitgtk: 2.36.6 -> 2.36.7
https://webkitgtk.org/2022/08/24/webkitgtk2.36.7-released.html
https://webkitgtk.org/security/WSA-2022-0008.html

Fixes: CVE-2022-32893
(cherry picked from commit cb40cdf49a)
2022-08-31 01:32:43 +02:00
Simon Bruder
98a5d37401 webkitgtk: 2.36.5 -> 2.36.6
Fixes #185219.

(cherry picked from commit 12d647d5c8)
2022-08-30 23:06:29 +00:00
Martin Weinelt
a28adc36c2 Merge pull request #188952 from NixOS/backport-188889-to-release-22.05 2022-08-30 15:09:39 +02:00
Marek Mahut
2fd83cff1e Merge pull request #188534 from 1000101/ipfs-cluster
[Backport release-22.05] ipfs-cluster: 1.0.0 -> 1.0.2
2022-08-30 13:55:34 +02:00
Martin Weinelt
2a38783b00 firefox-devedition-bin-unwrapped: 104.0b10 -> 105.0b4
(cherry picked from commit 27c45326b5)
2022-08-30 11:37:51 +00:00
Martin Weinelt
769eb89005 firefox-beta-bin-unwrapped: 104.0b9 -> 105.0b4
(cherry picked from commit 0437543dc5)
2022-08-30 11:37:51 +00:00
Martin Weinelt
ff8361d186 firefox-bin-unwrapped: 104.0 -> 104.0.1
https://www.mozilla.org/en-US/firefox/104.0.1/releasenotes/
(cherry picked from commit 0955d646f5)
2022-08-30 11:37:51 +00:00
Martin Weinelt
64f3eefc91 firefox-unwrapped: 104.0 -> 104.0.1
https://www.mozilla.org/en-US/firefox/104.0.1/releasenotes/
(cherry picked from commit 66124effe6)
2022-08-30 11:37:51 +00:00
Keshav Kini
2e789f323e zoom-us: 5.11.{1.8356,3.3882} -> 5.11.{9.10046,10.4400}
(cherry picked from commit 7aabe71f78)
2022-08-30 01:46:27 -07:00
superherointj
3bc5920e30 linux/hardened/patches/5.4: 5.4.210-hardened1 -> 5.4.211-hardened1
(cherry picked from commit 8720e91143)
2022-08-30 08:03:00 +00:00
superherointj
9c532ab338 linux/hardened/patches/5.19: init at 5.19.5-hardened1
(cherry picked from commit 6c64bc1513)
2022-08-30 08:03:00 +00:00
superherointj
2d02836164 linux/hardened/patches/5.15: 5.15.62-hardened1 -> 5.15.63-hardened1
(cherry picked from commit 9c52217141)
2022-08-30 08:03:00 +00:00
superherointj
db7fb4659b linux/hardened/patches/5.10: 5.10.137-hardened1 -> 5.10.139-hardened1
(cherry picked from commit 18e3f842ec)
2022-08-30 08:03:00 +00:00
superherointj
0c8ae54351 linux/hardened/patches/4.19: 4.19.255-hardened1 -> 4.19.256-hardened1
(cherry picked from commit c963a9fd67)
2022-08-30 08:03:00 +00:00
superherointj
6cbb917f59 linux/hardened/patches/4.14: 4.14.290-hardened1 -> 4.14.291-hardened1
(cherry picked from commit 3235fcb17d)
2022-08-30 08:03:00 +00:00
superherointj
097516ed59 linux: 5.19.4 -> 5.19.5
(cherry picked from commit bb0eb96d45)
2022-08-30 08:03:00 +00:00
superherointj
ca8176f664 linux: 5.10.138 -> 5.10.139
(cherry picked from commit 0d7868b45f)
2022-08-30 08:02:59 +00:00
Bobby Rong
f4924a0a1f Merge pull request #188791 from NixOS/backport-187213-to-release-22.05
[Backport release-22.05] signal-desktop: 5.54.0 -> 5.56.0
2022-08-30 10:07:28 +08:00
github-actions[bot]
b58685ebe7 Merge staging-next-22.05 into staging-22.05 2022-08-30 00:18:43 +00:00
github-actions[bot]
2099a6f71d Merge release-22.05 into staging-next-22.05 2022-08-30 00:18:07 +00:00
Doron Behar
cc634d9aa0 Merge pull request #188819 from NixOS/backport-188734-to-release-22.05 2022-08-29 18:48:36 +03:00
Mauricio Collares
6a4785177d zoom-us: fix virtual backgrounds
(cherry picked from commit d7f61154c3)
2022-08-29 15:11:41 +00:00
Eduardo Quiros
7eea8cfca4 signal-desktop: 5.54.0 -> 5.56.0
(cherry picked from commit 9646f307a2)
2022-08-29 08:58:59 +00:00
Robert Scott
8771f639c5 qemu: add patch for CVE-2020-14394
(cherry picked from commit 42a7627f09313cdddd61c01f0fe33a804ddb111c)
2022-08-29 02:29:14 -04:00
Robert Scott
9532af010c qemu: add patches for CVE-2022-0216
(cherry picked from commit 481765892f01ff46881157391694cd91d65a98b3)
2022-08-29 02:29:14 -04:00
github-actions[bot]
ce572090f7 Merge staging-next-22.05 into staging-22.05 2022-08-29 00:16:55 +00:00
github-actions[bot]
ffc16f47a2 Merge release-22.05 into staging-next-22.05 2022-08-29 00:16:15 +00:00
Sandro
1ddd992fa0 Merge pull request #188599 from necessarily-equal/update-to-unvanquished-0.53.1-on-22.05 2022-08-28 23:45:50 +02:00
Kerstin
6f3cca9878 Merge pull request #188683 from NixOS/backport-188674-to-release-22.05
[Backport release-22.05] imagemagick: 7.1.0-46 -> 7.1.0-47
2022-08-28 22:39:19 +02:00
R. Ryantm
7f7f3de7d7 imagemagick: 7.1.0-46 -> 7.1.0-47
(cherry picked from commit 5ba8f7cc88)
2022-08-28 19:20:00 +00:00
Robert Scott
16236dd7e3 Merge pull request #188623 from NixOS/backport-161288-to-release-22.05
[Backport release-22.05] pngpaste: init at 0.2.3
2022-08-28 16:29:51 +01:00
Robert Scott
7d777d4dc4 apacheHttpdPackages.mod_wsgi: add patch for CVE-2022-2255 2022-08-28 16:16:42 +01:00
Charlie Moog
a4361eab74 github-runner: fix package layout, script patches, default state dir
(cherry picked from commit 9fd2b544ac7795464f5b1d9bacbe3cf12465dc16)
2022-08-28 11:11:22 -04:00
Vladimír Čunát
a32ab5433f Merge #186794: libwebp: 1.2.3 -> 1.2.4 (into staging-22.05) 2022-08-28 16:09:19 +02:00
superherointj
8a4d7c473c Merge pull request #188635 from NixOS/backport-188294-to-release-22.05
[Backport release-22.05] vscode-extensions.svelte.svelte-vscode: 105.3.0 -> 105.21.0
2022-08-28 10:43:53 -03:00
Fabian Hauser
3ae7ce6518 vscode-extensions.svelte.svelte-vscode: 105.3.0 -> 105.21.0
(cherry picked from commit bd56129fba)
2022-08-28 13:40:52 +00:00
Sam Willcocks
2cabcacc41 pngpaste: init at 0.2.3
(cherry picked from commit cbe518b293)
2022-08-28 12:49:57 +00:00
Sam Willcocks
0bc85c6eaa maintainers: add samw
(cherry picked from commit 1f7bdfdc20)
2022-08-28 12:49:57 +00:00
Martin Weinelt
b5554e1747 Merge pull request #185581 from risicle/ris-sanic-CVE-2022-35920-r22.05 2022-08-28 14:39:21 +02:00
Antoine Fontaine
29993c09b0 unvanquished: 0.52.1 -> 0.53.1
Release notes:
0.53.0 https://unvanquished.net/unvanquished-0-53-beta-what-a-milestone/
0.53.1 https://unvanquished.net/unvanquished-0-53-1-and-launcher-0-2-0-quick-fix-and-dark-magic/
2022-08-28 12:11:02 +02:00
Christian Kögler
198d8fbc27 Merge pull request #188214 from NixOS/backport-181469-to-release-22.05
[Backport release-22.05] djvulibre: move librsvg to nativeBuildInputs
2022-08-28 07:11:46 +02:00
Bobby Rong
290dbaacc1 Merge pull request #188502 from NixOS/backport-188236-to-release-22.05
[Backport release-22.05] bambootracker: 0.5.1 -> 0.5.2
2022-08-28 11:18:25 +08:00
Théo Zimmermann
318598952d obsidian: upgrade dependency as requested by upstream
See https://forum.obsidian.md/t/update-popup-on-latest-version/40810/4.

(cherry picked from commit 6f92f05f53)
2022-08-28 02:00:22 +00:00
github-actions[bot]
0be341e8ac Merge staging-next-22.05 into staging-22.05 2022-08-28 00:19:26 +00:00
github-actions[bot]
b01cbda69b Merge release-22.05 into staging-next-22.05 2022-08-28 00:18:53 +00:00
Luflosi
d4ab16668f ipfs-cluster: 1.0.1 -> 1.0.2
https://github.com/ipfs-cluster/ipfs-cluster/releases/tag/v1.0.2

The project was moved from the "ipfs" to the the "ipfs-cluster" Github organization.

Also update the homepage URL, since the old one now redirects to the new one.
2022-08-27 21:58:13 +02:00
Luflosi
d5006774b0 ipfs-cluster: 1.0.0 -> 1.0.1
https://github.com/ipfs/ipfs-cluster/releases/tag/v1.0.1
2022-08-27 21:58:04 +02:00
Martin Weinelt
0ba2543f8c borgbackup: move manpages into man output
By creating the man output the multiple-outputs hook will automatically
move manpages in the correct path into it.

(cherry picked from commit 237f49730588ac7dbd2606b776d3841b741f9f95)
2022-08-27 12:19:23 -04:00
kilianar
05951a56c2 borgbackup: 1.2.1 -> 1.2.2
https://github.com/borgbackup/borg/releases/tag/1.2.2
(cherry picked from commit 5f609ee951f4414badf850c3fa0bfbb2b8979fec)
2022-08-27 12:19:23 -04:00
Winter
0252a6ee4c dendrite: disable tests 2022-08-27 12:17:02 -04:00
Winter
2dad972810 dendrite: 0.8.5 -> 0.9.4 2022-08-27 12:17:02 -04:00
OPNA2608
5a49b39459 bambootracker: 0.5.1 -> 0.5.2
(cherry picked from commit 9d417df2e5)
2022-08-27 13:22:56 +00:00
Sofi
6cb1065d6e nixos/minecraft-server: optimize world generation inside test
Due to how complex minecraft world generation has gotten in recent
years, it now can take several minutes to complete the first generation
of a world seed, even on relatively new and powerful hardware.

We are testing if a minecraft server can run inside of a nix enviroment,
and not so much about stress testing the CI.

Test running before this change:

> (finished: waiting for TCP port 43000, in 118.49 seconds)

Test running with this change:

> (finished: waiting for TCP port 43000, in 27.88 seconds)

Choice of using `level-type` and `generate-structures` was made as they
support almost every version of minecraft. These two also make it
extremely clear what it does, compared to the more complex
`generator-settings` and all its toggles.

(cherry picked from commit aed32f226430b51deaf53e4d64be153539795b77)
2022-08-27 00:16:11 -04:00
Alyssa Ross
f488d00234 Revert "rsync: Work around upstream cross-compilation issue"
This reverts commit 49edde0905.

Our packaged rsync version now contains the fix.

(cherry picked from commit bf0aa68088)
2022-08-26 23:24:53 -04:00
Maximilian Bosch
30b4361026 rsync: re-add enableCopyDevicesPatch, warn that it's obsolete 2022-08-26 23:24:53 -04:00
Maximilian Bosch
d915be48c6 sqlite: patch CVE-2022-35737 2022-08-26 23:24:53 -04:00
Maximilian Bosch
28e2f31bd6 vim: 9.0.0115 -> 9.0.0244
Fixes CVE-2022-2816, CVE-2022-2817, CVE-2022-2819, CVE-2022-2845,
CVE-2022-2849, CVE-2022-2862, CVE-2022-2874, CVE-2022-2889.

(cherry picked from commit 18b4b87e0fb9032feca86ccfc8caceb094121157)
2022-08-26 23:24:53 -04:00
Maximilian Bosch
c0e6fc7e45 libtiff: patch CVE-2022-{2867,2868,2869} 2022-08-26 23:24:53 -04:00
Maximilian Bosch
596c06d7b0 minio: patch CVE-2022-35919 2022-08-26 23:24:53 -04:00
Ivan Kozik
15b48fe3ba rsync: 3.2.4 -> 3.2.5
This release fixes CVE-2022-29154:
https://download.samba.org/pub/rsync/NEWS#3.2.5

Remove enableCopyDevicesPatch because --copy-devices was included in rsync 3.2.4:
https://download.samba.org/pub/rsync/NEWS#3.2.4:~:text=Added%20the%20%2D%2Dcopy%2Ddevices%20option

(cherry picked from commit 457e267206)
2022-08-26 23:24:53 -04:00
Sandro Jäckel
a14a0f0299 rsync: adopt, greatly simplify package
(cherry picked from commit 9e1c94057c)
2022-08-26 23:24:53 -04:00
Thomas Gerbet
0b0657d43a rsync: 3.2.3 -> 3.2.4
https://download.samba.org/pub/rsync/NEWS#3.2.4
(cherry picked from commit 3de6800173)
2022-08-26 23:24:53 -04:00
Sandro Jäckel
d945c63e8c go_1_18: 1.18.2 -> 1.18.5
(cherry picked from commit 6e7fb72f0f)
(cherry picked from commit e4f3664e62)
(cherry picked from commit eba5f13c08)

Fixes CVE-2022-1705, CVE-2022-32148, CVE-2022-30631, CVE-2022-30633,
CVE-2022-28131, CVE-2022-30635, CVE-2022-30632, CVE-2022-30630, CVE-2022-1962
2022-08-26 23:24:53 -04:00
Sandro Jäckel
8030f694c2 go_1_17: 1.17.10 -> 1.17.13
(cherry picked from commit 47016de7ef)
(cherry picked from commit 6b6a73f53e)
(cherry picked from commit 8fb01fab4f)

Fixes CVE-2022-1705, CVE-2022-32148, CVE-2022-30631, CVE-2022-30633,
CVE-2022-28131, CVE-2022-30635, CVE-2022-30632, CVE-2022-30630, CVE-2022-1962
2022-08-26 23:24:53 -04:00
github-actions[bot]
089e7f462d Merge staging-next-22.05 into staging-22.05 2022-08-27 00:15:54 +00:00
github-actions[bot]
f397ec60f6 Merge release-22.05 into staging-next-22.05 2022-08-27 00:15:14 +00:00
Aaron Andersen
5d52b4e4fb Merge pull request #188414 from NixOS/backport-188117-to-release-22.05
[Backport release-22.05] github-runner: 2.295.0 -> 2.296.0
2022-08-26 14:34:06 -04:00
Alex Martens
76562a0a9c github-runner: 2.295.0 -> 2.296.0
(cherry picked from commit 0806ee7ed5)
2022-08-26 18:16:58 +00:00
Julian Stecklina
4ad364d69e evolution: 3.44.3 -> 3.44.4
(cherry picked from commit 0414c7e074)
2022-08-26 20:00:38 +02:00
Julian Stecklina
b9b953d1f9 evolution-ews: 3.44.3 -> 3.44.4
(cherry picked from commit cc1ecf44d8)
2022-08-26 20:00:38 +02:00
Julian Stecklina
6d0a16ccd6 gnome.evolution-data-server: 3.44.3 -> 3.44.4
(cherry picked from commit a2f98e5914)
2022-08-26 20:00:38 +02:00
Martin Weinelt
a3297de559 Merge pull request #188406 from NixOS/backport-176491-to-release-22.05 2022-08-26 19:18:35 +02:00
Martin Weinelt
329595e491 borgbackup: set meta.mainProgram
(cherry picked from commit 1ff3b6b146fe15e8926028c407e91c03950f5e0d)
2022-08-26 15:48:50 +00:00
Martin Weinelt
444f19b965 borgbackup: 1.2.0 -> 1.2.1
https://github.com/borgbackup/borg/releases/tag/1.2.1
(cherry picked from commit e5b63cd9249f59d4e69ce0fb94517d569a2811a7)
2022-08-26 15:48:50 +00:00
Bobby Rong
f11e12ac6a Merge pull request #188394 from NixOS/backport-188029-to-release-22.05
[Backport release-22.05] changelogger: 0.5.2 -> 0.5.3
2022-08-26 21:27:12 +08:00
Tom Siewert
7da1674570 changelogger: 0.5.2 -> 0.5.3
(cherry picked from commit ec124cda59)
2022-08-26 12:56:08 +00:00
Maximilian Bosch
52e38c8cd6 Merge pull request #188386 from NixOS/backport-188335-to-release-22.05
[Backport release-22.05] Linux kernel updates 2022-08-25
2022-08-26 14:04:53 +02:00
superherointj
f3f2e4122a linux_latest-libre: 18880 -> 18885
(cherry picked from commit fe76cced40)
2022-08-26 11:11:30 +00:00
superherointj
8c90c72b0c linux: 5.4.210 -> 5.4.211
(cherry picked from commit 645ad87d82)
2022-08-26 11:11:30 +00:00
superherointj
87c7fcd29c linux: 5.19.3 -> 5.19.4
(cherry picked from commit fc04b42545)
2022-08-26 11:11:30 +00:00
superherointj
e4f1b306d2 linux: 5.15.62 -> 5.15.63
(cherry picked from commit fba0a26dd8)
2022-08-26 11:11:30 +00:00
superherointj
3d420ba829 linux: 5.10.137 -> 5.10.138
(cherry picked from commit 20009a7b14)
2022-08-26 11:11:30 +00:00
superherointj
d3ab527e62 linux: 4.9.325 -> 4.9.326
(cherry picked from commit 105b6f1baf)
2022-08-26 11:11:29 +00:00
superherointj
395df46aa0 linux: 4.19.255 -> 4.19.256
(cherry picked from commit bb50933572)
2022-08-26 11:11:29 +00:00
superherointj
c40d2edc33 linux: 4.14.290 -> 4.14.291
(cherry picked from commit e37f235e3a)
2022-08-26 11:11:29 +00:00
piegames
d0171edc7f Merge pull request #176032: gnomeExtensions.freon: fix patch for v48
[Backport release-22.05] gnomeExtensions.freon: fix patch for v48, simplify
2022-08-26 10:37:20 +02:00
Maximilian Bosch
24fa2dcd92 Merge pull request #188374 from NixOS/backport-188355-to-release-22.05
[Backport release-22.05] tig: 2.5.6 -> 2.5.7
2022-08-26 10:27:14 +02:00
Matthias Beyer
fe7dd7398e tig: 2.5.6 -> 2.5.7
Signed-off-by: Matthias Beyer <mail@beyermatthias.de>
(cherry picked from commit 219fd334e0)
2022-08-26 08:12:11 +00:00
maxine [they]
e43d2e2fdc Merge pull request #188195 from blitz/gnome-42-updates
[22.05] Backport Gnome 42 Updates
2022-08-26 09:50:10 +02:00
superherointj
5545afa395 Merge pull request #188349 from NixOS/backport-188317-to-release-22.05
[Backport release-22.05] rar: 6.11 -> 6.12
2022-08-26 01:00:48 -03:00
Anthony Roussel
82de573970 rar: 6.11 -> 6.12
(cherry picked from commit f39c54608a)
2022-08-26 03:35:28 +00:00
github-actions[bot]
3498f75038 Merge staging-next-22.05 into staging-22.05 2022-08-26 00:16:48 +00:00
github-actions[bot]
b6a3c27418 Merge release-22.05 into staging-next-22.05 2022-08-26 00:16:09 +00:00
Mario Rodas
058de38185 Merge pull request #188172 from NixOS/backport-186030-to-release-22.05
[Backport release-22.05] podman: 4.1.1 -> 4.2.0
2022-08-25 06:46:05 -05:00
Mario Rodas
2cfe38a780 Merge pull request #187923 from NixOS/backport-182958-to-release-22.05
[Backport release-22.05] postgresqlPackages.timescaledb: 2.7.0 -> 2.7.2
2022-08-25 06:44:47 -05:00
Martin Weinelt
d1e54d3cb0 Merge pull request #188276 from NixOS/backport-183283-to-release-22.05 2022-08-25 12:28:40 +02:00
Sandro
9b4eeddef3 lib/systems/inspect.nix: add isAarch
(cherry picked from commit c6b0b4d0b1157979322b9a08da9433d5f3b2dfec)
2022-08-25 10:11:43 +00:00
Martin Weinelt
46859851fc open-vm-tools: 12.0.5 -> 12.1.0
https://www.vmware.com/security/advisories/VMSA-2022-0024.html
https://www.openwall.com/lists/oss-security/2022/08/23/3

Fixes: CVE-2022-31676
(cherry picked from commit 59d86c1e1b60938b87a947e15aa3c1fa3f35d883)
2022-08-25 17:02:01 +08:00
Vladimír Čunát
e1601e505c linux_5_4_hardened: don't build on x86_64-linux anymore
5.4 hasn't configured successfully on x86_64-linux for months.
People don't seem to care, but the 5.4 packages clutter failure lists
on Hydra + tools.
https://hydra.nixos.org/job/nixpkgs/trunk/linux_5_4_hardened.x86_64-linux/all

Perhaps surprisingly, it works on aarch64-linux and also on older kernels.

(cherry picked from commit 55812d7b48)
2022-08-25 08:04:59 +00:00
Mario Rodas
5f17353d51 Merge pull request #180808 from NixOS/backport-180612-to-release-22.05
[Backport release-22.05] elmPackages.nodejs: 14.19.3 -> 14.20.0
2022-08-25 00:24:00 -05:00
Mario Rodas
dd8eb78bf9 nodejs-18_x: 18.7.0 -> 18.8.0
https://github.com/nodejs/node/releases/tag/v18.8.0
(cherry picked from commit dd845813db)
2022-08-25 04:20:00 +00:00
Mario Rodas
59573f302e nodejs-16_x: 16.17.0 -> 16.17.1
https://github.com/nodejs/node/releases/tag/v16.17.1
(cherry picked from commit 5b647c67af)
2022-09-23 04:20:00 +00:00
github-actions[bot]
de27c6f2b5 Merge staging-next-22.05 into staging-22.05 2022-08-25 00:17:02 +00:00
github-actions[bot]
2c8a7a516e Merge release-22.05 into staging-next-22.05 2022-08-25 00:16:22 +00:00
Alyssa Ross
5997562e84 djvulibre: enable parallel building
Tested at -j48.

(cherry picked from commit 2b5b344788)
2022-08-24 19:27:24 +00:00
Alyssa Ross
69d442ffc1 djvulibre: move librsvg to nativeBuildInputs
librsvg is only at build time, for generating icons with
rsvg-convert.  Previously, when cross compiling, rsvg-convert wouldn't
be found, and icon generation would be disabled.

(cherry picked from commit 75d86f0e79)
2022-08-24 19:27:23 +00:00
Jan Tojnar
7af7f8932d deja-dup: 43.3 → 43.4
https://gitlab.gnome.org/World/deja-dup/-/compare/43.3...43.4
(cherry picked from commit e2d48d0ece)
2022-08-24 19:26:56 +03:00
Jan Tojnar
87b3bdcbdb geocode-glib: 3.26.2 → 3.26.3
https://gitlab.gnome.org/GNOME/geocode-glib/-/compare/3.26.2...3.26.3

- Add support for linking against libsoup 3 (incompatible ABI).
- Format the expression.
- Register installed tests (currently broken).

(cherry picked from commit fb2877c36f)
2022-08-24 19:26:42 +03:00
Jan Tojnar
2c8115cdc2 pitivi: 2021.05 → 2022.06
https://gitlab.gnome.org/GNOME/pitivi/-/compare/2021.05.0...2022.06.0

- Add librosa for beat detection
- Also remove some dependencies that have long been unneeded.

(cherry picked from commit e13726c80e)
2022-08-24 19:26:23 +03:00
Jan Tojnar
ccd9a18f7f rhythmbox: 3.4.5 → 3.4.6
https://gitlab.gnome.org/GNOME/rhythmbox/-/compare/v3.4.5...v3.4.6

- Build script now compiles schemas automatically.
- Add some initial test dependencies.

(cherry picked from commit c6217958d0)
2022-08-24 19:26:15 +03:00
Jan Tojnar
0af95e15ba orca: 42.1 → 42.2
https://gitlab.gnome.org/GNOME/orca/-/compare/ORCA_42_1...ORCA_42_2
(cherry picked from commit dbb3c8d6a7)
2022-08-24 19:26:07 +03:00
Jan Tojnar
8d0d962d5e gnome.sushi: 41.2 → 42.0
https://gitlab.gnome.org/GNOME/sushi/-/compare/41.2...42.0
(cherry picked from commit ac47a22add)
2022-08-24 19:25:58 +03:00
Jan Tojnar
f73bd9de4c gnome.gnome-maps: 42.2 → 42.3
https://gitlab.gnome.org/GNOME/gnome-maps/-/compare/v42.2...v42.3
(cherry picked from commit 679a373a81)
2022-08-24 19:25:44 +03:00
Jan Tojnar
840948e565 gnome.gnome-calculator: 42.1 → 42.2
https://gitlab.gnome.org/GNOME/gnome-calculator/-/compare/42.1...42.2
(cherry picked from commit 6654f95010)
2022-08-24 19:25:36 +03:00
Jan Tojnar
3d31eed1d5 gnome.gnome-boxes: 42.1 → 42.2
https://gitlab.gnome.org/GNOME/gnome-boxes/-/compare/42.1...42.2

Tarball no longer contains gtk-frdp subproject and it is going to be dropped in the future:
https://gitlab.gnome.org/GNOME/gnome-boxes/-/merge_requests/532

(cherry picked from commit 5e2d29c7f2)
2022-08-24 19:25:24 +03:00
Jan Tojnar
b45fd8f834 evolution: 3.44.2 → 3.44.3
https://gitlab.gnome.org/GNOME/evolution/-/compare/3.44.2...3.44.3
(cherry picked from commit bd9e9f512d)
2022-08-24 19:25:13 +03:00
Jan Tojnar
2b5bd4f25e evolution-data-server: 3.44.2 → 3.44.3
https://gitlab.gnome.org/GNOME/evolution-data-server/-/compare/3.44.2...3.44.3
(cherry picked from commit d87a011c1e)
2022-08-24 19:24:44 +03:00
Jan Tojnar
95917d1b68 evolution-ews: 3.44.2 → 3.44.3
https://gitlab.gnome.org/GNOME/evolution-ews/-/compare/3.44.2...3.44.3
(cherry picked from commit e88d37389c)
2022-08-24 19:23:56 +03:00
R. Ryantm
034fead67e evolution-ews: 3.44.1 -> 3.44.2
(cherry picked from commit e8327b0384)
2022-08-24 19:23:44 +03:00
Martin Weinelt
294ef54a1e Merge pull request #188179 from NixOS/backport-174744-to-release-22.05 2022-08-24 17:04:38 +02:00
Martin Weinelt
67ff642ac4 Merge pull request #177046 from NixOS/backport-175985-to-release-22.05 2022-08-24 17:00:38 +02:00
Jeremy Kolb
282441604c remove unused fetchpatch
(cherry picked from commit 8daaf8e398f356513147fec989e6222ea842fd8b)
2022-08-24 14:10:40 +00:00
Jeremy Kolb
b86fd48670 open-vm-tools: 12.0.0 -> 12.0.5
(cherry picked from commit e3548876c046c2cc27bb274e0d68ada85ac10aa8)
2022-08-24 14:10:40 +00:00
zowoq
950df825b6 podman: 4.1.1 -> 4.2.0
https://github.com/containers/podman/releases/tag/v4.2.0
(cherry picked from commit fa0c0bcb38)
2022-08-24 13:07:38 +00:00
Martin Weinelt
eddb3c5f8b Merge pull request #188155 from NixOS/backport-188134-to-release-22.05 2022-08-24 14:32:00 +02:00
Vladimír Čunát
d3c1deb36b thunderbird-91: 91.12.0 -> 91.13.0
https://www.thunderbird.net/en-US/thunderbird/91.13.0/releasenotes/
(cherry picked from commit 95bc085056fef8e644e79b8956c3adec38d843f8)
2022-08-24 10:39:59 +00:00
Maximilian Bosch
fd1e5261eb Merge pull request #188142 from NixOS/backport-188027-to-release-22.05
[Backport release-22.05] Linux kernel updates 2022-08-23
2022-08-24 11:37:58 +02:00
Maximilian Bosch
0398d2f56d linux/hardened/patches/5.18: 5.18.17-hardened1 -> 5.18.19-hardened1
(cherry picked from commit c8322d761e)
2022-08-24 08:44:50 +00:00
Maximilian Bosch
022f7dfe1b linux/hardened/patches/5.15: 5.15.60-hardened1 -> 5.15.62-hardened1
(cherry picked from commit 59d8bb65af)
2022-08-24 08:44:50 +00:00
Maximilian Bosch
626a7b2b85 linux/hardened/patches/5.10: 5.10.136-hardened1 -> 5.10.137-hardened1
(cherry picked from commit 92020eb821)
2022-08-24 08:44:50 +00:00
Maximilian Bosch
ba3df988fd linux_latest-libre: 18837 -> 18880
(cherry picked from commit 44ff12b6d9)
2022-08-24 08:44:50 +00:00
Maximilian Bosch
e96994b3b3 linux: 5.19.2 -> 5.19.3
(cherry picked from commit 76ffc68429)
2022-08-24 08:44:50 +00:00
Maximilian Bosch
9e04dccaf5 linux: 5.18.18 -> 5.18.19
(cherry picked from commit b0a84e1b65)
2022-08-24 08:44:50 +00:00
Maximilian Bosch
cfc26d35a1 linux: 5.15.61 -> 5.15.62
(cherry picked from commit 7ca490c3d2)
2022-08-24 08:44:50 +00:00
Maximilian Bosch
2363e8e7c3 linux: 5.10.136 -> 5.10.137
(cherry picked from commit 0858a9a4dd)
2022-08-24 08:44:50 +00:00
Emery Hemingway
a5c89f496b getdns, stubby: update 1.7.0 -> 1.7.2, 0.4.0 -> 0.4.2
https://getdnsapi.net/releases/getdns-1-7-1-rc-1/
(cherry picked from commit db8fd3ec97c55c337c4752c1c0f710f65106e258)
2022-08-23 21:43:21 -05:00
github-actions[bot]
9320824bf9 Merge staging-next-22.05 into staging-22.05 2022-08-24 00:16:21 +00:00
github-actions[bot]
0a5c91edc3 Merge release-22.05 into staging-next-22.05 2022-08-24 00:15:41 +00:00
Vladimír Čunát
e984b74927 Merge #188036: gcc12: 12.1.0 -> 12.2.0 (into release-22.05) 2022-08-23 23:08:23 +02:00
Lorenz Brun
281a61e915 gutenprint: fix CUPS backend
The CUPS backend was not built since gutenprint requires libusb1, not 0.1 (at least since ~2014).
With this change CUPS detects printers relying on the pure gutenprint backend (like some dye sublimation printers).

(cherry picked from commit c413232fc8)
2022-08-23 22:55:03 +02:00
Vladimír Čunát
77483ebdfa thunderbird*: 102.1.2 -> 102.2.0
https://www.thunderbird.net/en-US/thunderbird/102.2.0/releasenotes/
(cherry picked from commit dc178ae28e)
2022-08-23 22:19:22 +02:00
Nicolas Benes
9452bd5085 pulseview: 0.4.1 -> 0.4.2
(cherry picked from commit d8f986d902)
2022-08-23 22:12:27 +02:00
Nicolas Benes
e796be1a97 sigrok-firmware-fx2lafw: init at 0.1.7
Cross-compile the firmware files instead of downloading the binaries.
Bump 0.1.6 -> 0.1.7.

(cherry picked from commit bc36ea147b)

Manually removed `meta.sourceProvenance`, which is not yet supported in
release-22.05.
2022-08-23 22:12:27 +02:00
Nicolas Benes
3861872a3b libsigrok: 0.5.1 -> 0.5.2
* bump version
* enable hidapi: add support for many serial devices, such as digital
  multimeters and data loggers
* enable ieee1284 and bluetooth support on Linux
* install udev rules

(cherry picked from commit 0b0c92af76)
2022-08-23 22:12:27 +02:00
Nicolas Benes
617fb5e745 collectd: unpin libsigrok
The pinning of `libsigrok` was introduced in 300e495101 for
`collectd-5.5.1`. It is now at 5.12.0 and the pinning seems outdated.

(cherry picked from commit fcc47aec15)
2022-08-23 22:12:27 +02:00
Nicolas Benes
4aa0a95895 maintainers: add panicgh
(cherry picked from commit 4320bb9229)
2022-08-23 22:12:27 +02:00
Bernardo Meurer
580d1ea22a Merge pull request #188050 from mweinelt/22.05/firefox
[22.05]  firefox{,-bin}-unwrapped: 103.0.2 -> 104.0; firefox-esr-102-unwrapped: 102.1.0esr -> 102.2.0esr; firefox-91-esr-unwrapped: 91.12.0esr -> 91.13.0esr; firefox-beta-bin-unwrapped: 104.0b7 -> 104.b09; firefox-devedition-bin-unwrapped: 104.0b7 -> 104.b10
2022-08-23 13:56:23 -03:00
Martin Weinelt
92673635c6 firefox-devedition-bin-unwrapped: 104.0b7 -> 104.b10
(cherry picked from commit 02cb054cf4)
2022-08-23 18:22:18 +02:00
Martin Weinelt
68dc3cb1b0 firefox-beta-bin-unwrapped: 104.0b7 -> 104.b09
(cherry picked from commit e07f2519b9)
2022-08-23 18:22:18 +02:00
Martin Weinelt
1ac689b3cb firefox-esr-102-unwrapped: 102.1.0esr -> 102.2.0esr
https://www.mozilla.org/en-US/firefox/102.2.0/releasenotes/

Fixes: CVE-2022-38472, CVE-2022-38473, CVE-2022-38476, CVE-2022-38477,
       CVE-2022-38478
(cherry picked from commit 1c98a4b64b)
2022-08-23 18:22:17 +02:00
Martin Weinelt
3e0afdd943 firefox-esr-91-unwrapped: 91.12.0esr -> 91.13.0esr
https://www.mozilla.org/en-US/firefox/91.13.0/releasenotes/

Fixes: CVE-2022-38472, CVE-2022-38473, CVE-2022-38478
(cherry picked from commit d50d54a0fe)
2022-08-23 18:22:17 +02:00
Martin Weinelt
8f565e491b firefox-bin-unwrapped: 103.0.2 -> 104.0
https://www.mozilla.org/en-US/firefox/104.0/releasenotes/

Fixes: CVE-2022-38472, CVE-2022-38473, CVE-2022-38474, CVE-2022-38475,
       CVE-2022-38477, CVE-2022-38478
(cherry picked from commit 77d59491fe)
2022-08-23 18:22:16 +02:00
Martin Weinelt
61c3835199 firefox-unwrapped: 103.0.2 -> 104.0
https://www.mozilla.org/en-US/firefox/104.0/releasenotes/

Fixes: CVE-2022-38472, CVE-2022-38473, CVE-2022-38474, CVE-2022-38475,
       CVE-2022-38477, CVE-2022-38478
(cherry picked from commit 097a473056)
2022-08-23 18:22:15 +02:00
Maximilian Bosch
22b6dc7dbd Merge pull request #188031 from sersorrel/mistune-0.8-is-ok-actually
[22.05] Revert "python3Packages.mistune_0_8: mark knownVulnerabilities CVE-2022-34749"
2022-08-23 17:17:58 +02:00
Sergei Trofimovich
3be693ee0c gcc12: 12.1.0 -> 12.2.0
Co-authored-by: Robert Scott <github@humanleg.org.uk>
(cherry picked from commit 657075f9fa)
2022-08-23 14:35:12 +00:00
Vladimír Čunát
b9fd420fa5 Merge #187517: staging-next-22.05 - iteration 8 2022-08-23 15:42:56 +02:00
ash
34030414dd Revert "python3Packages.mistune_0_8: mark knownVulnerabilities CVE-2022-34749"
This reverts commit db8c23037a.

Mistune 0.8.4 is not vulnerable to CVE-2022-34749, only 2.0.x versions
of Mistune are.
2022-08-23 14:16:23 +01:00
ajs124
e096c9ccd6 Merge pull request #188008 from NixOS/backport-184433-to-release-22.05
[Backport release-22.05] pdns-recursor: 4.7.0 -> 4.7.1
2022-08-23 15:13:08 +02:00
Pavol Rusnak
3525df95cd Merge pull request #188017 from NixOS/backport-187448-to-release-22.05
[Backport release-22.05] btcpayserver: 1.6.6 -> 1.6.9
2022-08-23 15:09:10 +02:00
nixbitcoin
897480c9f0 btcpayserver: 1.6.6 -> 1.6.9
(cherry picked from commit 2aac29e292)
2022-08-23 12:31:46 +00:00
R. Ryantm
fb60de3e5a pdns-recursor: 4.7.0 -> 4.7.1
(cherry picked from commit 2907074047)
2022-08-23 11:52:25 +00:00
Domen Kožar
cd6e29f41f Merge pull request #187898 from domenkozar/22.05-ghc-9.2.4
[22.05] ghc 9.2.4
2022-08-23 13:37:09 +02:00
Martin Weinelt
25bf4d421f rpm: 4.17.0 -> 4.17.1
https://rpm.org/wiki/Releases/4.17.1.html

Fixes: CVE-2021-3521
(cherry picked from commit f4d11afb67)
2022-08-23 10:52:11 +00:00
github-actions[bot]
1329dd030e gitlab: 15.2.2 -> 15.3.1 (#187984)
(cherry picked from commit 255311b3adceefa5035af9588863ac886fc0610a)

Co-authored-by: Winter <winter@winter.cafe>
2022-08-23 12:32:06 +02:00
Vladimír Čunát
06ac9cdfe4 Merge #187740: thunderbird*-102: 102.0.3 -> 102.1.2
...into release-22.05
2022-08-23 07:50:39 +02:00
Bernardo Meurer
1df6238154 kernel: only enable PINCTRL_AMD on 5.19+
(cherry picked from commit 7e901eeae0)
2022-08-23 09:51:11 +08:00
Peter Hoeg
dc3bdeacf2 kernel: fix touchpads on AMD laptops
(cherry picked from commit f7c980599e)
2022-08-23 09:51:11 +08:00
Bobby Rong
0e78cdd168 Merge pull request #187879 from NixOS/backport-187789-to-release-22.05
[Backport release-22.05] shellhub-agent: 0.9.5 -> 0.9.6
2022-08-23 09:16:18 +08:00
github-actions[bot]
c04c6709e1 Merge staging-next-22.05 into staging-22.05 2022-08-23 00:18:01 +00:00
github-actions[bot]
f934ed5d5e Merge release-22.05 into staging-next-22.05 2022-08-23 00:17:21 +00:00
Martin Weinelt
cc8fb88ea4 Merge pull request #187937 from NixOS/backport-187307-to-release-22.05 2022-08-23 01:59:10 +02:00
Martin Weinelt
c5f4d2c43a Merge pull request #187930 from NixOS/backport-187357-to-staging-22.05 2022-08-23 01:39:59 +02:00
Martin Weinelt
e9ee8fe5c7 nss_latest: 3.81 -> 3.82
https://github.com/nss-dev/nss/blob/master/doc/rst/releases/nss_3_82.rst
(cherry picked from commit 1393dba610)
2022-08-22 23:38:58 +00:00
Martin Weinelt
40007f53eb nss: migrate manual patching into postPatch
(cherry picked from commit 0badc2389a)
2022-08-22 23:07:17 +00:00
Martin Weinelt
59081b1618 nss: Drop ckpem patch
It's usefulness is not clear to us maintainers.

(cherry picked from commit df214678dc)
2022-08-22 23:07:17 +00:00
Martin Weinelt
14d0bff3fe nss: Drop nss-pem patchset
The patch url went 404 and other distros¹ have discarded it as well in
favor of packaging nss-pem²

[1] https://gitweb.gentoo.org/repo/gentoo.git/commit/dev-libs/nss?id=5eca3e02c87163b3c541cdee893830d201abfb86
[2] https://github.com/kdudka/nss-pem

(cherry picked from commit 7f01443ef1)
2022-08-22 23:07:17 +00:00
Maximilian Bosch
775db1a30d Merge pull request #187911 from NixOS/backport-187500-to-release-22.05
[Backport release-22.05] wiki-js: 2.5.285 -> 2.5.286
2022-08-23 00:10:31 +02:00
Mario Rodas
0018a967a5 postgresqlPackages.timescaledb: 2.7.0 -> 2.7.2
https://github.com/timescale/timescaledb/releases/tag/2.7.1
https://github.com/timescale/timescaledb/releases/tag/2.7.2
(cherry picked from commit 6e6a515607)
2022-08-22 21:48:18 +00:00
R. Ryantm
156e009163 wiki-js: 2.5.285 -> 2.5.286
(cherry picked from commit 8f0df21eb3)
2022-08-22 18:55:12 +00:00
Gabriel Ebner
52527082ea Merge pull request #187903 from NixOS/backport-187896-to-release-22.05
[Backport release-22.05] elan: overwrite llvm-ar with stdenv ar
2022-08-22 19:04:38 +02:00
Gabriel Ebner
de6fd52217 elan: overwrite llvm-ar with stdenv ar
(cherry picked from commit e99329eb02)
2022-08-22 16:48:56 +00:00
Domen Kožar
a8aa7cc0ca ghc: add 9.2.4 2022-08-22 17:49:46 +02:00
R. Ryantm
8032ed26f3 shellhub-agent: 0.9.5 -> 0.9.6
(cherry picked from commit 8546d723f3)
2022-08-22 14:06:01 +00:00
Vladimír Čunát
01acec67cd python3Packages.exchangelib: patch tests after tzdata update
(cherry picked from commit e9d5d4d7dc)
2022-08-22 08:41:29 +02:00
Christian Kögler
4aae6a9e43 Merge pull request #184571 from NixOS/backport-182744-to-release-22.05
[Backport release-22.05] owncast: Fix statedirectory issue after upgrade
2022-08-22 08:38:46 +02:00
Christian Kögler
a8a1a8be4b Merge pull request #187761 from NixOS/backport-181349-to-release-22.05
[Backport release-22.05] bpftrace/bpftool: libelf -> elfutils dependency update
2022-08-22 08:30:37 +02:00
Vladimír Čunát
6542027984 python3Packages.orjson: skip a problematic test
For nixpkgs master we updated instead in PR #186580
2022-08-22 08:18:39 +02:00
Peter Hoeg
491c37ad3a nixos/https-dns-proxy: add OpenDNS support
(cherry picked from commit 28116cfd9b)
2022-08-22 13:07:49 +08:00
Peter Hoeg
075d19f8a0 https-dns-proxy: 2021-03-29 -> 2022-05-05
(cherry picked from commit f0ec7d7698)
2022-08-22 13:07:49 +08:00
github-actions[bot]
83fd12544a Merge staging-next-22.05 into staging-22.05 2022-08-22 00:16:43 +00:00
github-actions[bot]
ffea40b6f9 Merge release-22.05 into staging-next-22.05 2022-08-22 00:16:09 +00:00
Dominique Martinet
44e7286b89 bpftool: replace libelf with elfutils
libelf is no longer maintained, use elfutils' libelf instead

(cherry picked from commit d6d039148d)
2022-08-21 15:52:48 +00:00
Dominique Martinet
bf2eab466b bpftrace: remove libelf extraneous dependency
elfutils provides a libelf, we don't need it twice

(cherry picked from commit 3762c001fa)
2022-08-21 15:52:48 +00:00
Anderson Torres
23534df34c Merge pull request #187734 from NixOS/backport-187661-to-release-22.05
[Backport release-22.05] libpkgconf: 1.9.2 -> 1.9.3
2022-08-21 12:11:18 -03:00
Anderson Torres
d4a6a67c32 Merge pull request #187735 from NixOS/backport-187642-to-release-22.05
[Backport release-22.05]  berry: patch the version in the configure script
2022-08-21 12:11:00 -03:00
Vladimír Čunát
eb450b6920 thunderbird*-102: 102.0.3 -> 102.1.2
https://www.thunderbird.net/en-US/thunderbird/102.1.0/releasenotes/
https://www.thunderbird.net/en-US/thunderbird/102.1.1/releasenotes/
https://www.thunderbird.net/en-US/thunderbird/102.1.2/releasenotes/

On nixpkgs master this is in commit f4e93a3ded / PR #187428
2022-08-21 15:01:41 +02:00
Vladimír Čunát
7ab4ab7f59 thunderbird-bin-102: fix alias
It was incorrectly pointing to thunderbird-bin-91.
2022-08-21 14:57:32 +02:00
Norbert Melzer
e73dc31025 berry: patch the version in the configure script
This fixes how berry internalizes its own version. By default a static 0.1.7 is
and overriden if a `.git` folder does exist. In that case `git describe` is used
and the version parsed out of it.

This PR unconditionally patches the version in the configure file as that appears
to be easier and more idiomatic than a "fake git".

(cherry picked from commit b283467401)
2022-08-21 12:14:03 +00:00
R. Ryantm
4930338860 libpkgconf: 1.9.2 -> 1.9.3
(cherry picked from commit 755c8f230a)
2022-08-21 12:13:52 +00:00
Izumi Raine
45ede4ab78 anki-bin: 2.1.52 -> 2.1.54
(cherry picked from commit cc18e3ce0e)
2022-08-21 10:53:38 +00:00
Christian Kögler
2cb8ab06d9 Merge pull request #185932 from NixOS/backport-185153-to-release-22.05
[Backport release-22.05] nixos/nixos-containers: Fix ineffective warning
2022-08-21 08:51:12 +02:00
Christian Kögler
1df0808e2f Merge pull request #186773 from NixOS/backport-186587-to-release-22.05
[Backport release-22.05] nixos/mirakurun: set the LOGO_DATA_DIR_PATH environment variable
2022-08-21 08:40:47 +02:00
Christian Kögler
b00612cc2b Merge pull request #187396 from NixOS/backport-186982-to-release-22.05
[Backport release-22.05] newsflash: fix adding xdg-open to PATH
2022-08-21 08:30:54 +02:00
github-actions[bot]
f8338a9247 Merge staging-next-22.05 into staging-22.05 2022-08-21 00:16:11 +00:00
github-actions[bot]
290e684a24 Merge release-22.05 into staging-next-22.05 2022-08-21 00:15:30 +00:00
superherointj
9a91318fff Merge pull request #187610 from NixOS/backport-187299-to-release-22.05
[Backport release-22.05] nixos/minio: fix startup issue
2022-08-20 12:24:25 -03:00
superherointj
3bdf879a5b nixos/minio: fix startup issue
(cherry picked from commit 89f527384b)
2022-08-20 15:19:45 +00:00
Dmitry Kalinkin
5dc15c15c7 pythia: add fixDarwinDylibNames
Library not loaded: @rpath/libpythia8.dylib

(cherry picked from commit 91e8f10dbd)
2022-08-20 11:12:52 -04:00
Martin Weinelt
739a96f246 Merge pull request #187537 from risicle/ris-streamlit-CVE-2022-35918-r22.05 2022-08-20 12:48:06 +02:00
Mario Rodas
a1eac15fe8 Merge pull request #187424 from NixOS/backport-187376-to-release-22.05
[Backport release-22.05] yt-dlp: 2022.8.14 -> 2022.8.19
2022-08-20 01:08:29 -05:00
Robert Scott
8b839e5760 streamlit: add patch for CVE-2022-35918 2022-08-20 02:17:58 +01:00
github-actions[bot]
30d66c9cf5 Merge staging-next-22.05 into staging-22.05 2022-08-20 00:14:27 +00:00
github-actions[bot]
6cc0a74567 Merge release-22.05 into staging-next-22.05 2022-08-20 00:13:53 +00:00
Vladimír Čunát
ff8b618852 Merge branch 'staging-22.05' into staging-next-22.05 2022-08-19 23:46:41 +02:00
Vladimír Čunát
60a1f8abe1 Merge #187404: Kernels for 2022-08-17 (into staging-22.05) 2022-08-19 23:45:22 +02:00
Vladimír Čunát
3be38cc733 mid2key: trivial fixup after commit e0476d93fe
It seems like noone cares, but getting it back seems easy.

(cherry picked from commit 2ae3c22cd0)
2022-08-19 22:22:44 +02:00
Vladimír Čunát
29b1be1470 Merge #186080: gst_all_1: 1.20.1 -> 1.20.3 (security)
...into staging-22.05
2022-08-19 20:12:37 +02:00
Vladimír Čunát
644b92f9c0 Merge #184579: unbound: fix CVE-2022-30698 and CVE-2022-30699
...into staging-22.05
2022-08-19 20:09:12 +02:00
Vladimír Čunát
00e376e3f3 Merge #187393: gcc12: apply working patch for darwin-aarch64
...into release-22.05
2022-08-19 18:29:13 +02:00
Martin Weinelt
c8e459ac45 Merge pull request #187445 from NixOS/backport-187383-to-release-22.05 2022-08-19 16:00:49 +02:00
Zhaofeng Li
990955a71e colmena: 0.3.0 -> 0.3.1
(cherry picked from commit 02de659303)
2022-08-19 13:04:53 +00:00
zowoq
c70980fec5 yt-dlp: 2022.8.14 -> 2022.8.19
https://github.com/yt-dlp/yt-dlp/releases/tag/2022.08.19
(cherry picked from commit 2d52abcbef)
2022-08-19 10:00:15 +00:00
K900
004401db7d linux/hardened/patches/5.4: 5.4.208-hardened1 -> 5.4.210-hardened1
(cherry picked from commit 4789b92366)
2022-08-19 07:53:41 +00:00
K900
007b1b1e8e linux: 5.19.1 -> 5.19.2
(cherry picked from commit 7413d509cd)
2022-08-19 07:53:41 +00:00
K900
bffbb6064d linux: 5.18.17 -> 5.18.18
(cherry picked from commit 636c6b3fad)
2022-08-19 07:53:41 +00:00
K900
2979783bec linux: 5.15.60 -> 5.15.61
(cherry picked from commit 7aeb316e7e)
2022-08-19 07:53:41 +00:00
Kira Bruneau
827b9dfc86 newsflash: fix adding xdg-open to PATH
(cherry picked from commit cd7ccff1f3)
2022-08-19 06:53:02 +00:00
Theodore Ni
123f7f28de gcc12: apply working patch for darwin-aarch64
(cherry picked from commit 74b420b612)
2022-08-19 06:46:55 +00:00
github-actions[bot]
a238e82fb5 Merge staging-next-22.05 into staging-22.05 2022-08-19 00:16:43 +00:00
github-actions[bot]
590ecfeeb9 Merge release-22.05 into staging-next-22.05 2022-08-19 00:16:08 +00:00
John Ericson
d7a4a9397f Merge pull request #187355 from obsidiansystems/fix-compiler-rt-armvl-patch-22.05
[Backport release-22.05]: llvmPackages_14.compiler-rt: fix aarch32 patch
2022-08-18 18:40:18 -04:00
John Ericson
462d76cc7b llvmPackages_14.compiler-rt: fix aarch32 patch
This is just the same fix we did for LLVM 13 in
265ba73a78 applied to LLVM 14.

(cherry picked from commit d6636a5de6)
2022-08-18 22:10:45 +00:00
Sandro
63cd5fe801 Merge pull request #187167 from NixOS/backport-184877-to-release-22.05 2022-08-18 23:27:24 +02:00
ajs124
4304f4dbd6 Merge pull request #187160 from NixOS/backport-186867-to-release-22.05
[Backport release-22.05] mariadb: 10.8.4, 10.7.5, 10.6.9, 10.5.17 and 10.4.26
2022-08-18 22:10:49 +02:00
Ryan Mulligan
9b9f4bb4e1 Merge pull request #187082 from NixOS/backport-185820-to-release-22.05
[Backport release-22.05] discourse: 2.9.0.beta4 -> 2.9.0.beta9
2022-08-18 10:07:47 -07:00
Michael Weiss
ae266625e8 chromium: 104.0.5112.79 -> 104.0.5112.101
https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_16.html

This update includes 11 security fixes. Google is aware that an exploit
for CVE-2022-2856 exists in the wild.

CVEs:
CVE-2022-2852 CVE-2022-2854 CVE-2022-2855 CVE-2022-2857 CVE-2022-2858
CVE-2022-2853 CVE-2022-2856 CVE-2022-2859 CVE-2022-2860 CVE-2022-2861

(cherry picked from commit 5369167b7d)
2022-08-18 15:39:44 +00:00
Kerstin
f023fc50b9 Merge pull request #187287 from NixOS/backport-187235-to-release-22.05
[Backport release-22.05] imagemagick: 7.1.0-45 -> 7.1.0-46
2022-08-18 16:16:03 +02:00
Robert Schütz
5cbe6c5635 imagemagick: 7.1.0-45 -> 7.1.0-46
(cherry picked from commit 86f9d4bdcd)
2022-08-18 13:46:55 +00:00
Kira Bruneau
d16bbfd781 Merge pull request #187124 from kira-bruneau/python3Packages.debugpy
[Backport release-22.05] python3Packages.debugpy: 1.6.0 → 1.6.3
2022-08-18 09:14:34 -04:00
Kira Bruneau
cec7368718 Merge pull request #187130 from NixOS/backport-184781-to-release-22.05
[Backport release-22.05] linuxPackages.xpadneo: 0.9.1 -> 0.9.4
2022-08-18 09:12:15 -04:00
Michael Weiss
31d0b26bb3 Merge pull request #187242 from NixOS/backport-187228-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 104.0.5112.81 -> 104.0.5112.102
2022-08-18 14:19:38 +02:00
Michael Adler
279048961f ungoogled-chromium: 104.0.5112.81 -> 104.0.5112.102
(cherry picked from commit d2a0defa04)
2022-08-18 08:50:11 +00:00
Kira Bruneau
890fdd28ed Merge pull request #187206 from NixOS/backport-185159-to-release-22.05
[Backport release-22.05] zynaddsubfx: 3.0.5 → 3.0.6
2022-08-17 23:30:47 -04:00
Kira Bruneau
6b909b61a7 zynaddsubfx: 3.0.5 → 3.0.6
(cherry picked from commit 1c395dbabe)
2022-08-18 02:31:28 +00:00
Kira Bruneau
66aca63550 zynaddsubfx: disable PortChecker test when building with lashSupport
(cherry picked from commit fbaac3ad4f)
2022-08-18 02:31:28 +00:00
Kira Bruneau
f1abe6edf7 zynaddsubfx: use for loop to set rpath for vst libraries
(cherry picked from commit 6c3be14afe)
2022-08-18 02:31:28 +00:00
Kira Bruneau
49d61a91f8 zynaddsubfx: separate doc output
(cherry picked from commit 5b44e6010d)
2022-08-18 02:31:28 +00:00
Kira Bruneau
0c7396edba zynaddsubfx: use Zyn-Fusion logo for zest build
Derived from https://raw.githubusercontent.com/mruby-zest/mruby-zest/ea4894620bf80ae59593b5d404b950d436a91e6c/example/ZynLogo.qml

(cherry picked from commit dc0a907d87)
2022-08-18 02:31:27 +00:00
Kira Bruneau
e32657d65d Merge pull request #187141 from NixOS/backport-176110-to-release-22.05
[Backport release-22.05] zynaddsubfx: pull upstream fix for -fno-common (mruby-zest)
2022-08-17 22:24:18 -04:00
github-actions[bot]
1afe0177d7 Merge staging-next-22.05 into staging-22.05 2022-08-18 00:15:40 +00:00
github-actions[bot]
4731a86feb Merge release-22.05 into staging-next-22.05 2022-08-18 00:15:00 +00:00
R. Ryantm
3f08b7dd6b nextcloud-client: 3.5.3 -> 3.5.4
(cherry picked from commit e53c311042)
2022-08-17 20:44:12 +00:00
ajs124
4364d2021b mariadb_108: 10.8.3 -> 10.8.4
https://mariadb.com/kb/en/mariadb-1084-release-notes/

Fixes:
- CVE-2022-32082
- CVE-2022-32089
- CVE-2022-32081
- CVE-2018-25032
- CVE-2022-32091
- CVE-2022-32084

(cherry picked from commit e710cd5106)
2022-08-17 19:16:07 +00:00
ajs124
70bf742012 mariadb_107: 10.7.4 -> 10.7.5
https://mariadb.com/kb/en/mariadb-1075-release-notes/

Fixes:
- CVE-2022-32082
- CVE-2022-32089
- CVE-2022-32081
- CVE-2018-25032
- CVE-2022-32091
- CVE-2022-32084

(cherry picked from commit 4131e59c77)
2022-08-17 19:16:07 +00:00
ajs124
9ea0c9a790 mariadb_106: 10.6.8 -> 10.6.9
https://mariadb.com/kb/en/mariadb-1069-release-notes/

Fixes:
- CVE-2022-32082
- CVE-2022-32089
- CVE-2022-32081
- CVE-2018-25032
- CVE-2022-32091
- CVE-2022-32084

(cherry picked from commit c7aba71f1c)
2022-08-17 19:16:07 +00:00
ajs124
dad1b1909a mariadb_105: 10.5.16 -> 10.5.17
https://mariadb.com/kb/en/mariadb-10517-release-notes/

Fixes:
- CVE-2022-32082
- CVE-2022-32089
- CVE-2022-32081
- CVE-2018-25032
- CVE-2022-32091
- CVE-2022-32084

(cherry picked from commit aeb72f7668)
2022-08-17 19:16:07 +00:00
ajs124
380a303bd8 mariadb_104: 10.4.25 -> 10.4.26
https://mariadb.com/kb/en/mariadb-10426-release-notes/

Fixes:
- CVE-2022-32089
- CVE-2022-32081
- CVE-2018-25032
- CVE-2022-32091
- CVE-2022-32084

(cherry picked from commit 7ea9e62df1)
2022-08-17 19:16:07 +00:00
ajs124
ea6332c906 mariadb: sha256 -> hash
(cherry picked from commit 9c6f7712a2)
2022-08-17 19:16:07 +00:00
Sergei Trofimovich
a10998848d zynaddsubfx: pull upstream fix for -fno-common (mruby-zest)
Without the change internal dependency mruby-zest fails to build on
-fno-common toolchain as:

    ld: libmruby.a(nvg_context.o):mruby-nanovg/src/nvg_context.c:217: multiple definition of
      `mrb_nvg_context_type'; libmruby.a(gem.o):mruby-widget-lib/src/gem.c:293: first defined here

(cherry picked from commit 338484a75e)
2022-08-17 15:47:06 +00:00
Kira Bruneau
a55a7db823 Merge pull request #187129 from NixOS/backport-174377-to-release-22.05
[Backport release-22.05] ccache: 4.6 -> 4.6.1
2022-08-17 11:11:23 -04:00
Kira Bruneau
e96e4c8463 Merge pull request #187128 from NixOS/backport-184121-to-release-22.05
[Backport release-22.05] vkBasalt: 0.3.2.5 -> 0.3.2.6
2022-08-17 11:11:02 -04:00
Kira Bruneau
e114d6e0cd nixos/xpadneo: don't disable ertm on kernel 5.12 or later
The [v0.9.2 changelog](https://github.com/atar-axis/xpadneo/releases/tag/v0.9.2)
mentions that ERTM should no longer be unconditionally disabled on
kernels later than 5.12.

(cherry picked from commit bda6036d2e)
2022-08-17 11:05:35 -04:00
Kira Bruneau
95eec93bdb linuxPackages.xpadneo: fix license
(cherry picked from commit 600b36b117)
2022-08-17 14:53:46 +00:00
R. Ryantm
83d33f9279 linuxPackages.xpadneo: 0.9.1 -> 0.9.4
(cherry picked from commit dcbe29d119)
2022-08-17 14:53:46 +00:00
R. Ryantm
3a98132fb5 ccache: 4.6 -> 4.6.1
(cherry picked from commit 6a92588264)
2022-08-17 14:50:36 +00:00
R. Ryantm
8675f6ceb6 vkBasalt: 0.3.2.5 -> 0.3.2.6
(cherry picked from commit 4b971c83e6)
2022-08-17 14:50:07 +00:00
Christian Kögler
8ba3961583 Merge pull request #187015 from NixOS/backport-182299-to-release-22.05
[Backport release-22.05] mpd: fix 0.23.8 on darwin
2022-08-17 16:49:13 +02:00
Kira Bruneau
fc201e4182 python3Packages.debugpy: 1.6.2 → 1.6.3
(cherry picked from commit ce9849054cc0bc6fbe13e5da6d4b310cc60f9404)
2022-08-17 09:52:57 -04:00
Kira Bruneau
2c3201aba3 python3Packages.debugpy: 1.6.0 → 1.6.2
(cherry picked from commit 8d750db596)
2022-08-17 09:52:02 -04:00
Kira Bruneau
b255b29ac7 python3Packages.debugpy: remove unnecessary arch specifiers
(cherry picked from commit 512d30b8a0)
2022-08-17 09:50:22 -04:00
Maximilian Bosch
9a1fde0e0c Merge pull request #187090 from NixOS/backport-186685-to-release-22.05
[Backport release-22.05] prometheus-openldap-exporter: 2.2.1 -> 2.2.2
2022-08-17 12:10:42 +02:00
Maximilian Bosch
8ddb3a9a9f Merge pull request #187091 from NixOS/backport-187014-to-release-22.05
[Backport release-22.05] mautrix-whatsapp: 0.6.0 -> 0.6.1
2022-08-17 11:58:33 +02:00
Charlotte Van Petegem
efeb8e291d mautrix-whatsapp: 0.6.0 -> 0.6.1
(cherry picked from commit c62bab4a92)
2022-08-17 09:49:12 +00:00
R. Ryantm
aa47fb8a08 prometheus-openldap-exporter: 2.2.1 -> 2.2.2
(cherry picked from commit b0de490314)
2022-08-17 09:48:17 +00:00
Maximilian Bosch
7bc65bf653 Merge pull request #187087 from NixOS/backport-187074-to-release-22.05
[Backport release-22.05] matrix-synapse: 1.64.0 -> 1.65.0
2022-08-17 11:42:55 +02:00
R. Ryantm
9c78a6a0ae matrix-synapse: 1.64.0 -> 1.65.0
(cherry picked from commit f4eec8f9ae)
2022-08-17 09:21:58 +00:00
Maximilian Bosch
4841fff1d7 Merge pull request #187079 from NixOS/backport-186988-to-release-22.05
[Backport release-22.05] linuxKernel.kernels: updates
2022-08-17 11:17:07 +02:00
talyz
f541b6e191 discourse: Update plugins
(cherry picked from commit a3cc1609cd)
2022-08-17 08:46:42 +00:00
talyz
89e3503f93 discourse: Filter out :require_name option when creating the Gemfile
:require_name is internal to Discourse and Bundler throws an error
when it's passed through to the Gemfile.

(cherry picked from commit f34bc06abc)
2022-08-17 08:46:42 +00:00
talyz
002b764d73 discourse: 2.9.0.beta4 -> 2.9.0.beta9
Co-authored-by: Tobias Stenzel <ts@flyingcircus.io>
(cherry picked from commit 7feea0d062)
2022-08-17 08:46:41 +00:00
Bernardo Meurer
5090645850 linux_testing: 5.19-rc -> 6.0-rc1
(cherry picked from commit 676abbfc9b)
2022-08-17 08:31:41 +00:00
Bernardo Meurer
a4774b65ab linux/hardened/patches/5.18: 5.18.15-hardened1 -> 5.18.17-hardened1
(cherry picked from commit 6023139cd8)
2022-08-17 08:31:41 +00:00
Bernardo Meurer
b8230254e0 linux/hardened/patches/5.15: 5.15.58-hardened1 -> 5.15.60-hardened1
(cherry picked from commit 49123a639f)
2022-08-17 08:31:40 +00:00
Bernardo Meurer
a481a4e2aa linux/hardened/patches/5.10: 5.10.134-hardened1 -> 5.10.136-hardened1
(cherry picked from commit b251c3d591)
2022-08-17 08:31:40 +00:00
Bernardo Meurer
871105ce05 linux/hardened/patches/4.19: 4.19.254-hardened1 -> 4.19.255-hardened1
(cherry picked from commit 151120cee0)
2022-08-17 08:31:40 +00:00
Bernardo Meurer
630eafa56d linux-rt_5_4: 5.4.193-rt74 -> 5.4.209-rt77
(cherry picked from commit edfc88a7d3)
2022-08-17 08:31:40 +00:00
Bernardo Meurer
3920a4e881 linux: 5.4.209 -> 5.4.210
(cherry picked from commit cf81560d25)
2022-08-17 08:31:40 +00:00
Bernardo Meurer
1cda7fcc5d linux: 5.19 -> 5.19.1
(cherry picked from commit 6221871a7d)
2022-08-17 08:31:40 +00:00
Bernardo Meurer
b77caf4e53 linux: 5.18.16 -> 5.18.17
(cherry picked from commit 36c83a7be6)
2022-08-17 08:31:40 +00:00
Bernardo Meurer
faab7547e2 linux: 5.15.59 -> 5.15.60
(cherry picked from commit 17173d1781)
2022-08-17 08:31:40 +00:00
Bernardo Meurer
71d9c7619a linux: 5.10.135 -> 5.10.136
(cherry picked from commit d58cbe4865)
2022-08-17 08:31:40 +00:00
Bernardo Meurer
b12014e4cf linux: 4.19.254 -> 4.19.255
(cherry picked from commit dc78e9719c)
2022-08-17 08:31:40 +00:00
Anderson Torres
eddfa420ec Merge pull request #187040 from NixOS/backport-186949-to-release-22.05
[Backport release-22.05] free42: 3.0.13 -> 3.0.14
2022-08-17 00:33:50 -03:00
Anderson Torres
8fb8c15748 Merge pull request #187037 from NixOS/backport-185531-to-release-22.05
[Backport release-22.05] libpkgconf: 1.8.0 -> 1.9.2
2022-08-16 21:38:58 -03:00
github-actions[bot]
d0c4ddd63e Merge staging-next-22.05 into staging-22.05 2022-08-17 00:15:13 +00:00
github-actions[bot]
9ac08ed478 Merge release-22.05 into staging-next-22.05 2022-08-17 00:14:34 +00:00
R. Ryantm
0db91993e1 free42: 3.0.13 -> 3.0.14
(cherry picked from commit bcbfdd3e0b)
2022-08-16 23:51:02 +00:00
R. Ryantm
92ec9a918e libpkgconf: 1.8.0 -> 1.9.2
(cherry picked from commit 4d3bce525c)
2022-08-16 23:40:46 +00:00
Lassulus
342fa101f4 Merge pull request #187013 from NixOS/backport-186842-to-release-22.05 2022-08-16 22:55:13 +02:00
Yestin L. Harrison
7fed2963d6 mpd: fix 0.23.8 on darwin
- 0.23.8 includes c975d8b943
- said change fixes deprecation warnings introduced in the 12.0 sdk, using definitions from the 12.0 sdk
- nixpkgs uses 10.12 and 11.0, neither of which are the 12.0 sdk
- this will gracefully degrade into a no-op when that changes

(cherry picked from commit 19b2875ec62a4215319a280f59a1d10a7e983489)
2022-08-16 18:56:01 +00:00
lassulus
c2c9069809 archivebox: use hash instead of sha256
(cherry picked from commit f5a02eb84e)
2022-08-16 18:42:59 +00:00
Matthias Thym
a82127cea6 pywinrm: remove optional insecure dependency (kerberos)
(cherry picked from commit 6bc5810d7c)
2022-08-16 16:54:03 +02:00
Mario Rodas
4cd98424c3 Merge pull request #186934 from NixOS/backport-182022-to-release-22.05
[Backport release-22.05] duplicity: 0.8.20 -> 0.8.23
2022-08-16 08:39:47 -05:00
Thiago Kenji Okada
0205a2d868 Merge pull request #186951 from NixOS/backport-186943-to-release-22.05
[Backport release-22.05] devito: unstable-2022-04-22 -> 4.7.1
2022-08-16 13:37:24 +01:00
Átila Saraiva
8a015d2c0e devito: unstable-2022-04-22 -> 4.7.1
(cherry picked from commit 97552f0fbc)
2022-08-16 12:29:22 +00:00
StephenWithPH
2043739123 duplicity: 0.8.20 -> 0.8.23
(cherry picked from commit f2187ade75)
2022-08-16 10:49:34 +00:00
Gauvain 'GovanifY' Roussel-Tarbouriech
39efddea38 libbluray: fix build failure on 1.3.1 with java
Backported from an upstream patch

(cherry picked from commit 785ca266b6)
2022-08-16 09:48:22 +00:00
Gauvain 'GovanifY' Roussel-Tarbouriech
2c6c3122b2 libbluray: fix broken BDJ patch
(cherry picked from commit 938ea3de88)
2022-08-16 09:48:22 +00:00
Bobby Rong
2ac1913235 Merge pull request #186905 from NixOS/backport-186879-to-release-22.05
[Backport release-22.05] pantheon.switchboard-plug-pantheon-shell: 6.2.0 -> 6.3.0
2022-08-16 16:05:52 +08:00
Bobby Rong
0332fa98b7 pantheon.switchboard-plug-pantheon-shell: 6.2.0 -> 6.3.0
(cherry picked from commit 2f2c8966d3)
2022-08-16 07:12:14 +00:00
Francesco Zanini
76f6ba152a opentrack: 2.1.3 → 2022.3.0
Fixes #185520

(cherry picked from commit f38a47d64a)
2022-08-16 06:47:37 +00:00
Lassulus
1c423bf130 Merge pull request #182514 from NixOS/backport-182343-to-release-22.05
[Backport release-22.05] fzf: 0.30.0 -> 0.31.0
2022-08-16 08:23:27 +02:00
nixpkgs-upkeep-bot
1d585ebcc0 vscodium: 1.69.2 -> 1.70.0
(cherry picked from commit 1b95ba3c9c)
2022-08-16 02:13:30 -04:00
Jörg Thalheim
f7fbbcc9ac syncoid: handle syncing dataset without a parent
(cherry picked from commit 2c3f6055fb)
2022-08-16 02:03:03 -04:00
Danielle Hutzley
43626f1d63 minetest: 5.5.1 -> 5.6.0
(cherry picked from commit 5bf982e2f4c4ecc194230212d51011c78897c7b8)
2022-08-16 01:57:35 -04:00
Yaya
42ca6231ff nextcloud: 23.0.7 -> 23.0.8, 24.0.3 -> 24.0.4
https://nextcloud.com/changelog/#latest23
https://nextcloud.com/changelog/#latest24
(cherry picked from commit 333c145d41)
2022-08-16 01:57:02 -04:00
Brian Leung
fd66e704c1 universal-ctags: 5.9.20220710.0 -> 5.9.20220814.0
(cherry picked from commit a948fb2737)
2022-08-16 01:55:42 -04:00
Francesco Gazzetta
f60692c176 xprintidle: 0.2.4 -> 0.2.5
(cherry picked from commit 67272ce268)
2022-08-16 01:55:17 -04:00
Jörg Thalheim
09ec15134a Merge pull request #186890 from NixOS/backport-171562-to-release-22.05
[Backport release-22.05] nixos/doc/installation: fix alignment of created partitions
2022-08-16 05:26:52 +01:00
Mario Rodas
ecfa14a4de nodejs-16_x: 16.16.0 -> 16.17.0
https://github.com/nodejs/node/releases/tag/v16.17.0
(cherry picked from commit 6e2536f1b0)
2022-08-16 04:20:00 +00:00
Mario Rodas
e2a62687e9 nodejs-14_x: 14.20.0 -> 14.20.1
https://github.com/nodejs/node/releases/tag/v14.20.1
(cherry picked from commit 8b89d8d5bd)
2022-09-23 04:20:00 +00:00
Jörg Thalheim
fc2e9cf08b nixos/doc/installation: fix alignment of created partitions
$ parted /dev/nvme1n1 -- mkpart primary linux-swap -8GiB 100%
Warning: The resulting partition is not properly aligned for best performance: 3108850352s % 2048s != 0s
Ignore/Cancel?
Information: You may need to update /etc/fstab.

When using GB than parted seems to round up itself.

(cherry picked from commit f18befaaf4)
2022-08-16 04:10:44 +00:00
github-actions[bot]
68eea912ce Merge staging-next-22.05 into staging-22.05 2022-08-16 00:17:07 +00:00
github-actions[bot]
22eb5eb461 Merge release-22.05 into staging-next-22.05 2022-08-16 00:16:29 +00:00
Kira Bruneau
50b6709b40 Merge pull request #186855 from NixOS/backport-185016-to-release-22.05
[Backport release-22.05] mangohud: statically link spdlog
2022-08-15 18:02:54 -04:00
Kira Bruneau
0740bdaa9f mangohud: statically link spdlog
Works around bug in pressure-vessel where it wasn't including
necessary vulkan layer dependencies defined through DT_RUNPATH in the
sandbox.

https://github.com/ValveSoftware/steam-runtime/issues/511
(cherry picked from commit 2d6481a4fd)
2022-08-15 21:42:38 +00:00
Kira Bruneau
158a0a176f Merge pull request #186846 from NixOS/backport-182378-to-release-22.05
[Backport release-22.05] mangohud: Build mangoapp and mangohudctl for gamescope integration
2022-08-15 17:37:01 -04:00
Zhaofeng Li
0df91aa122 mangohud: Build mangoapp and mangohudctl for gamescope integration
(cherry picked from commit 3705020d97)
2022-08-15 17:28:35 -04:00
Kira Bruneau
77de5e5255 Merge pull request #186040 from kira-bruneau/backport-185848-to-release-22.05
[Backport release-22.05] electron: use wrapper instead of symlink for bin on darwin
2022-08-15 16:15:46 -04:00
Maximilian Bosch
3d47bbaa26 Merge pull request #186699 from NixOS/backport-186637-to-release-22.05
[Backport release-22.05] strace: 5.18 -> 5.19
2022-08-15 18:36:06 +02:00
Timothy DeHerrera
4cdfea1ce2 Merge pull request #186808 from NixOS/backport-186100-to-release-22.05
[Backport release-22.05] gamescope: rename libseat to seatd
2022-08-15 10:30:17 -06:00
superherointj
15edd9ac4a gamescope: rename libseat to seatd
(cherry picked from commit 8dd1594d04)
2022-08-15 15:58:53 +00:00
Timothy DeHerrera
b5f7027ce1 Merge pull request #186347 from NixOS/backport-181788-to-release-22.05
[Backport release-22.05] gamescope: init at 3.11.33-jupiter-3.3-2
2022-08-15 09:53:11 -06:00
tpdcl
363b6a1ee4 FAHClient: 7.6.13 -> 7.6.21 (#186780) 2022-08-15 17:41:49 +02:00
Christian Kögler
66fc0fecaa Merge pull request #182632 from NixOS/backport-174926-to-release-22.05
[Backport release-22.05] xwayland: 22.1.1 -> 22.1.3
2022-08-15 14:20:35 +02:00
ajs124
2e6f1475b5 libwebp: 1.2.3 -> 1.2.4
(cherry picked from commit e3d4450eff)
2022-08-15 12:15:44 +00:00
Pavol Rusnak
c4f583a769 monero: 0.17.3.2 -> 0.18.1.0
(cherry picked from commit 0ec615c46b)
2022-08-15 12:34:49 +02:00
Pavol Rusnak
b9548f04d2 monero-gui: 0.17.3.2 -> 0.18.1.0
(cherry picked from commit 749e42f16d)
2022-08-15 12:34:49 +02:00
Stanisław Pitucha
befc42d68a randomx: 1.1.9 -> 1.1.10
(cherry picked from commit bb202ec721)
2022-08-15 12:34:48 +02:00
R. Ryantm
31543a7448 hidapi: 0.11.2 -> 0.12.0
(cherry picked from commit 20749fc886)
2022-08-15 12:34:48 +02:00
Randy Eckenrode
71a1890ff1 apple_sdk_11_0: fix build on x86_64-darwin and expose as attribute
(cherry picked from commit d8f71776ff)
2022-08-15 12:34:48 +02:00
Randy Eckenrode
67e4141c06 apple_sdk_11_0: provide SDK-specific callPackage
(cherry picked from commit 9659c7abce)
2022-08-15 12:34:48 +02:00
Randy Eckenrode
ecf787f692 apple_sdk_11_0: expose 11.0 sdk stdenv as an attribute
(cherry picked from commit 4741402d54)
2022-08-15 12:34:48 +02:00
midchildan
bc37ac72d4 nixos/mirakurun: set the LOGO_DATA_DIR_PATH environment variable
(cherry picked from commit 664b01f082)
2022-08-15 09:46:23 +00:00
Bobby Rong
5cc1c4438a Merge pull request #186556 from NixOS/backport-186523-to-release-22.05
[Backport release-22.05] shellhub-agent: 0.9.4 -> 0.9.5
2022-08-15 16:07:12 +08:00
Bobby Rong
cfabaa15e9 Merge pull request #186374 from NixOS/backport-186271-to-release-22.05
[Backport release-22.05] pantheon.elementary-terminal: 6.0.2 -> 6.1.0
2022-08-15 09:05:16 +08:00
github-actions[bot]
5bd8ed8489 Merge staging-next-22.05 into staging-22.05 2022-08-15 00:15:26 +00:00
github-actions[bot]
f9f20ee123 Merge release-22.05 into staging-next-22.05 2022-08-15 00:14:47 +00:00
Mario Rodas
b648a98b17 Merge pull request #186730 from NixOS/backport-186727-to-release-22.05
[Backport release-22.05] yt-dlp: 2022.8.8 -> 2022.8.14
2022-08-14 18:23:13 -05:00
maxine [they]
9d1700a328 Merge pull request #186732 from NixOS/backport-186534-to-release-22.05 2022-08-15 01:22:06 +02:00
R. Ryantm
b274d589de glib-networking: 2.72.1 -> 2.72.2
(cherry picked from commit 431d982fa9)
2022-08-14 23:13:28 +00:00
zowoq
ec69cf36b2 yt-dlp: 2022.8.8 -> 2022.8.14
https://github.com/yt-dlp/yt-dlp/releases/tag/2022.08.14
(cherry picked from commit 48f5dbcd38)
2022-08-14 23:01:00 +00:00
Sergei Trofimovich
677306263b strace: 5.18 -> 5.19
While at it added trivial updater.
Changes: https://github.com/strace/strace/releases/tag/v5.19

(cherry picked from commit e3f61ba992)
2022-08-14 19:31:57 +00:00
maxine [they]
879121648f Merge pull request #186670 from NixOS/backport-186524-to-release-22.05 2022-08-14 18:59:38 +02:00
R. Ryantm
804845809c gnome.eog: 42.2 -> 42.3
(cherry picked from commit 60e834b276090dba97b09a9b70e17b89cd14e6f4)
2022-08-14 14:46:46 +00:00
Martin Weinelt
e1b180fc45 Merge pull request #186620 from NixOS/backport-176088-to-release-22.05 2022-08-14 13:15:52 +02:00
maxine [they]
f6dda99bf9 Merge pull request #186619 from NixOS/backport-186528-to-release-22.05 2022-08-14 13:11:17 +02:00
maxine [they]
f8a9293e44 Merge pull request #186615 from NixOS/backport-186533-to-release-22.05 2022-08-14 12:44:38 +02:00
maxine [they]
ecb8da8651 Merge pull request #186618 from NixOS/backport-186530-to-release-22.05 2022-08-14 12:44:19 +02:00
maxine [they]
854765e22e Merge pull request #186617 from NixOS/backport-186532-to-release-22.05 2022-08-14 12:44:09 +02:00
maxine [they]
9ac0a6130f Merge pull request #186613 from NixOS/backport-186537-to-release-22.05
[Backport release-22.05] gnome.mutter: 42.3 -> 42.4
2022-08-14 12:34:26 +02:00
maxine [they]
a7ce82d8c0 Merge pull request #186614 from NixOS/backport-186535-to-release-22.05
[Backport release-22.05] gnome.tali: 40.7 -> 40.8
2022-08-14 12:33:54 +02:00
Florian Amsallem
6c83b76c25 python3Packages.django_4: fix geos_gdal patch syntax error
(cherry picked from commit 43f65db139)
2022-08-14 10:33:34 +00:00
R. Ryantm
b1c18863a1 gnome.gedit: 42.1 -> 42.2
(cherry picked from commit 911de5b6eb)
2022-08-14 10:27:30 +00:00
R. Ryantm
64093864f3 gnome.gnome-software: 42.3 -> 42.4
(cherry picked from commit 03d7498f4e)
2022-08-14 10:26:22 +00:00
R. Ryantm
0e643bff1f gnome.gnome-remote-desktop: 42.3 -> 42.4
(cherry picked from commit 5935f45f1a)
2022-08-14 10:26:13 +00:00
R. Ryantm
1fa4dc487b gnome.gnome-shell: 42.3.1 -> 42.4
(cherry picked from commit 2ecfd05765)
2022-08-14 10:25:29 +00:00
R. Ryantm
1ac1254ef8 gnome.tali: 40.7 -> 40.8
(cherry picked from commit 9be26ce643)
2022-08-14 10:24:06 +00:00
R. Ryantm
b4ccef4703 gnome.mutter: 42.3 -> 42.4
(cherry picked from commit fd7947723e)
2022-08-14 10:23:40 +00:00
R. Ryantm
f39c6d996d shellhub-agent: 0.9.4 -> 0.9.5
(cherry picked from commit f2ee0cc465)
2022-08-14 02:30:47 +00:00
github-actions[bot]
cbfbda1a77 Merge staging-next-22.05 into staging-22.05 2022-08-14 00:15:40 +00:00
github-actions[bot]
524ededbe2 Merge release-22.05 into staging-next-22.05 2022-08-14 00:15:00 +00:00
Theodore Ni
218b302514 python310Packages.python-fsutil: Unmark broken on Darwin
At least on my aarch64 Darwin machine, python-fsutil builds fine.

(cherry picked from commit 56554b73b5)
2022-08-13 23:15:24 +00:00
ajs124
44f4952910 tzdata: 2022a -> 2022b
https://mm.icann.org/pipermail/tz-announce/2022-August/000071.html
(cherry picked from commit 15323f2c050c46a6a81230442a0388c59aefdb1d)
2022-08-13 20:51:45 +02:00
Mario Rodas
70b6236f3c Merge pull request #186465 from NixOS/backport-185064-to-release-22.05
[Backport release-22.05] hydrus: 493 -> 495
2022-08-13 12:16:36 -05:00
Mario Rodas
8a80b0cf89 Merge pull request #184900 from NixOS/backport-182705-to-release-22.05
[Backport release-22.05] samtools: Fix cross-compilation
2022-08-13 12:03:56 -05:00
Daniel Olsen
d0b60a6f39 hydrus: 494 -> 495
(cherry picked from commit 28f39c389f)
2022-08-13 17:00:28 +00:00
Daniel Olsen
e728d4728e hydrus: 493 -> 494
(cherry picked from commit 0d565a3e85)
2022-08-13 17:00:28 +00:00
Mario Rodas
4628a79ea5 Merge pull request #186460 from NixOS/backport-186164-to-release-22.05
[Backport release-22.05] zeronet-conservancy: 0.7.6 -> 0.7.7
2022-08-13 11:48:07 -05:00
Francesco Gazzetta
aa5a0dcaec zeronet-conservancy: 0.7.6 -> 0.7.7
(cherry picked from commit b0461c474e)
2022-08-13 16:06:52 +00:00
John Ericson
d816f474aa Merge pull request #186457 from NixOS/backport-156241-to-release-22.05
[Backport release-22.05] mpvacious: remove hack for multi-file script loading
2022-08-13 12:00:17 -04:00
Ken Micklas
eb139be584 mpvacious: remove hack for multi-file script loading
(cherry picked from commit 90bfb6dc4b)
2022-08-13 14:59:56 +00:00
Vladimír Čunát
f5108bc3a7 Merge #185759: staging-next-22.05 - iteration 7
...into release-22.05
2022-08-13 16:13:43 +02:00
Mario Rodas
ea9e6b4023 Merge pull request #186406 from NixOS/backport-186170-to-staging-22.05
[Backport staging-22.05] postgresql: 10.21 -> 10.22, 11.16 -> 11.17, 12.11 -> 12.12, 13.7 -> 13.8, 14.4 -> 14.5
2022-08-13 04:10:10 -05:00
ajs124
2fa17d42cf postgresql_10: 10.21 -> 10.22
fixes CVE-2022-2625

(cherry picked from commit 6d980c0d8b)
2022-08-13 08:34:27 +00:00
ajs124
5599a03662 postgresql_11: 11.16 -> 11.17
fixes CVE-2022-2625

(cherry picked from commit d1213d3dc8)
2022-08-13 08:34:27 +00:00
ajs124
c57a102764 postgresql_12: 12.11 -> 12.12
fixes CVE-2022-2625

(cherry picked from commit 2793fbe755)
2022-08-13 08:34:27 +00:00
ajs124
9acfa36ebc postgresql_13: 13.7 -> 13.8
fixes CVE-2022-2625

(cherry picked from commit 4059636757)
2022-08-13 08:34:27 +00:00
ajs124
4118a01de4 postgresql_14: 14.4 -> 14.5
fixes CVE-2022-2625

(cherry picked from commit c9aa86be11)
2022-08-13 08:34:27 +00:00
ajs124
6fac2a303f postgresql: sha256 -> hash
(cherry picked from commit 993dde135f)
2022-08-13 08:34:26 +00:00
QuantMint
15e66dc65d steamPackages.steam-runtime: 0.20211102.0 -> 0.20220601.1
(cherry picked from commit 7e2760130b)
2022-08-12 22:53:48 -07:00
Mario Rodas
a977252b40 Merge pull request #186370 from NixOS/backport-186219-to-release-22.05
[Backport release-22.05] freetube: 0.17.0 -> 0.17.1
2022-08-12 22:35:37 -05:00
Bobby Rong
768025a4dd pantheon.elementary-terminal: 6.0.2 -> 6.1.0
(cherry picked from commit 5965f1b44c)
2022-08-13 03:31:16 +00:00
alyaeanyx
345c6c6110 freetube: 0.17.0 -> 0.17.1
(cherry picked from commit 9951ffc06e)
2022-08-13 02:43:35 +00:00
github-actions[bot]
d4b023a1b8 Merge staging-next-22.05 into staging-22.05 2022-08-13 00:16:18 +00:00
github-actions[bot]
b7c9e8774d Merge release-22.05 into staging-next-22.05 2022-08-13 00:15:41 +00:00
maxine [they]
8619c55eff Merge pull request #186357 from NixOS/backport-186341-to-release-22.05
[Backport release-22.05] networkmanager: 1.38.2 -> 1.38.4
2022-08-13 01:27:02 +02:00
Maxine Aubrey
a8e87e5ef2 networkmanager: 1.38.2 -> 1.38.4
(cherry picked from commit 824ac98299)
2022-08-12 23:20:32 +00:00
ash lea
d1baddcef8 steam: fix opengl inside pressure-vessel
(cherry picked from commit 7df47f56882c6e0ba64063a7cac9f4a9e4c5af6e)
2022-08-12 15:34:01 -07:00
Timothy DeHerrera
fa005d50ae gamescope init at 3.11.33-jupiter-3.3-2
(cherry picked from commit a3f954f991)
2022-08-12 21:52:56 +00:00
Winter
6ddd2d34e3 gitlab: 15.1.4 -> 15.2.2
(cherry picked from commit 58bb8ab012)
2022-08-12 12:15:36 -04:00
Winter
5c8dd46337 bundlerEnv: allow copying additional paths alongside config files
(cherry picked from commit 8fb9c2cdd7)
2022-08-12 12:15:36 -04:00
Martin Weinelt
5c211b47ae Merge pull request #186303 from NixOS/revert-186222-backport-168465-to-release-22.05 2022-08-12 17:26:45 +02:00
Janne Heß
41f0eea1b7 Revert "nixos/tautulli: add option to open firewall"
This reverts commit c1c3328fe2.
2022-08-12 17:24:02 +02:00
Janne Heß
5846c487c1 Revert "Update nixos/modules/services/misc/tautulli.nix"
This reverts commit abf2fa272e.
2022-08-12 17:24:02 +02:00
Doron Behar
387379ad23 Merge pull request #186125 from doronbehar/pkg/texlab 2022-08-12 15:02:51 +03:00
Fabián Heredia Montiel
95625a75e1 python3Packages.uvloop: disable hanging test
(cherry picked from commit c49c7a9495)
https://hydra.nixos.org/build/186919437
2022-08-12 13:51:52 +02:00
Fabián Heredia Montiel
bea3745150 python3Packages.eventlet: disable failing test
(cherry picked from commit ea345cd9bc)
https://hydra.nixos.org/build/186881917
2022-08-12 13:46:27 +02:00
Mario Rodas
1979221662 Merge pull request #186136 from 1000101/update-nodejs-18_x
[22.05] nodejs-18_x: 18.2.0 -> 18.7.0
2022-08-12 05:57:35 -05:00
Martin Weinelt
9beaca2d01 Merge pull request #186202 from mweinelt/22.05/automat-dont-depend-on-m2r 2022-08-12 12:21:11 +02:00
Vincent Haupert
25e7481fd5 github-runner: 2.294.0 -> 2.295.0
(cherry picked from commit 2d1f0f363d7bb972669eb9f20da6cbb6e6e3bcbc)
2022-08-12 00:25:46 -04:00
Jeroen Simonetti
90969ce99a nixos/routedns: init
Signed-off-by: Jeroen Simonetti <jeroen@simonetti.nl>
(cherry picked from commit 829167bd27)
2022-08-11 23:25:56 -04:00
Jeroen Simonetti
3b9f41fd40 routedns: init at 0.1.5
Signed-off-by: Jeroen Simonetti <jeroen@simonetti.nl>
(cherry picked from commit 766a719557)
2022-08-11 23:25:56 -04:00
Jeroen Simonetti
4ea1beea75 maintainers: add jsimonetti
Signed-off-by: Jeroen Simonetti <jeroen@simonetti.nl>
(cherry picked from commit 88e182b3bf)
2022-08-11 23:25:56 -04:00
Winter
abf2fa272e Update nixos/modules/services/misc/tautulli.nix
(cherry picked from commit d120dd0a0f213650cea1f99296ba8e5dde429879)
2022-08-11 23:15:03 -04:00
Ryan Horiguchi
c1c3328fe2 nixos/tautulli: add option to open firewall
(cherry picked from commit 690f7cba87e2a021544553e1f467690fe4e2f11c)
2022-08-11 23:15:03 -04:00
github-actions[bot]
5894d2dda9 Merge staging-next-22.05 into staging-22.05 2022-08-12 00:14:32 +00:00
github-actions[bot]
52d9f294f6 Merge release-22.05 into staging-next-22.05 2022-08-12 00:13:50 +00:00
Robert Schütz
7fb285336d python310Packages.automat: don't depend on m2r
The latter depends on an outdated, vulnerable version of mistune.

(cherry picked from commit d3462c92f9)
2022-08-12 02:13:40 +02:00
Sandro Jäckel
752713749d python310Packages.automat: adopt, run tests
(cherry picked from commit 6596ccf447)
2022-08-12 02:13:36 +02:00
Robert Scott
e9b6b5de5c Merge pull request #186149 from NixOS/backport-184209-to-release-22.05
[Backport release-22.05] python3Packages.mistune_0_8: mark `knownVulnerabilities` for CVE-2022-34749
2022-08-11 21:20:27 +01:00
Robert Scott
9a8c5583ed python3Packages.mistune_0_8: mark knownVulnerabilities CVE-2022-34749
(cherry picked from commit db8c23037a)
2022-08-11 19:26:57 +00:00
Anderson Torres
036c1a8eff Merge pull request #186122 from NixOS/backport-185922-to-release-22.05
[Backport release-22.05] freecad: 0.20 -> 0.20.1
2022-08-11 15:55:52 -03:00
1000101
f4f855497d nodejs-18_x: 18.2.0 -> 18.7.0 2022-08-11 19:32:02 +02:00
Kira Bruneau
bd3d4db025 texlab: fix cross-compilation 2022-08-11 19:53:05 +03:00
Kira Bruneau
0256474766 texlab: 4.2.0 → 4.2.1 2022-08-11 19:53:05 +03:00
Kira Bruneau
d15d97487e texlab: 4.0.0 → 4.2.0 (#181149) 2022-08-11 19:53:04 +03:00
Kira Bruneau
bb270ee85c texlab: remove unused dylib of human_name 2022-08-11 19:53:04 +03:00
Doron Behar
ed0699f671 texlab: 3.3.2 -> 4.0.0 2022-08-11 19:53:04 +03:00
R. Ryantm
789dcc1984 freecad: 0.20 -> 0.20.1
(cherry picked from commit 0b390c407c)
2022-08-11 16:40:22 +00:00
Domen Kožar
aafac0d8b4 Merge pull request #186117 from domenkozar/22.05-flaky-hls-rename-plugin
[22.05] haskellPackages.hls-rename-plugin: flaky tests
2022-08-11 11:24:19 -05:00
Anderson Torres
0c686344a6 Merge pull request #186113 from NixOS/backport-184945-to-release-22.05
[Backport release-22.05] libnbd: 1.12.2 -> 1.14.0
2022-08-11 13:06:50 -03:00
Domen Kožar
4d74ca91b3 haskellPackages.hls-rename-plugin: flaky tests 2022-08-11 11:02:13 -05:00
R. Ryantm
8b5b1581e3 libnbd: 1.12.2 -> 1.14.0
(cherry picked from commit 6b189c307a)
2022-08-11 15:27:41 +00:00
Anderson Torres
57919e45dd Merge pull request #186105 from NixOS/backport-185977-to-release-22.05
[Backport release-22.05] tllist: 1.0.5 -> 1.1.0
2022-08-11 12:18:46 -03:00
Kerstin
e6ca293039 Merge pull request #185066 from erictapen/22.05/mixxx
[Backport release-22.05] mixxx: 2.3.2 -> 2.3.3
2022-08-11 16:51:09 +02:00
Lassulus
87b0f3cb0c Merge pull request #186097 from NixOS/backport-174301-to-release-22.05
[Backport release-22.05] nixos-generators: 1.5.0 -> 1.6.0
2022-08-11 16:45:14 +03:00
AndersonTorres
b5a98bc851 tllist: 1.0.5 -> 1.1.0
(cherry picked from commit 29c163731e)
2022-08-11 13:22:53 +00:00
ajs124
d298f199f8 Merge pull request #186095 from NixOS/backport-186046-to-release-22.05 2022-08-11 15:17:55 +02:00
lassulus
45effad668 nixos-generators: 1.5.0 -> 1.6.0
(cherry picked from commit b79667a20d)
2022-08-11 12:31:10 +00:00
R. Ryantm
2f7f49e82b jenkins: 2.346.2 -> 2.346.3
(cherry picked from commit ec5bd8b169)
2022-08-11 12:19:39 +00:00
Kira Bruneau
b64bc65dcb micropad: remove special case for electron on darwin
(cherry picked from commit 263b0365db)
2022-08-11 07:40:33 -04:00
Kira Bruneau
666ad6481b schildichat-desktop: remove special case for electron on darwin
(cherry picked from commit 6877e896fc)
2022-08-11 07:40:32 -04:00
Kira Bruneau
ed7a3086db element-desktop: remove special case for electron on darwin
(cherry picked from commit 2c035ca89f)
2022-08-11 07:40:31 -04:00
Kira Bruneau
d497eb5af3 deltachat-desktop: remove special case for electron on darwin
(cherry picked from commit 45a58291de)
2022-08-11 07:40:09 -04:00
Kira Bruneau
bdd4d8f08a electron: use wrapper instead of symlink for bin on darwin
electron fails to run through a symlink:

```
GPU process isn't usable. Goodbye.
```

(cherry picked from commit 4c476e1c70)
2022-08-11 07:39:35 -04:00
R. Ryantm
45c9736ed6 lighttpd: 1.4.65 -> 1.4.66
(cherry picked from commit a03f2967868b8ac590bf7d9a214ae358f59c689f)
2022-08-11 12:50:38 +02:00
Christian Albrecht
762185acf2 gst_all_1: 1.20.1 -> 1.20.3, fix CVE-2022-(192[0-5]|2122)
Vulnerabilities:
 - 7.8 https://nvd.nist.gov/vuln/detail/CVE-2022-1920
 - 7.8 https://nvd.nist.gov/vuln/detail/CVE-2022-1921
 - 7.8 https://nvd.nist.gov/vuln/detail/CVE-2022-1922
 - 7.8 https://nvd.nist.gov/vuln/detail/CVE-2022-1923
 - 7.8 https://nvd.nist.gov/vuln/detail/CVE-2022-1924
 - 7.8 https://nvd.nist.gov/vuln/detail/CVE-2022-1925
 - 7.8 https://nvd.nist.gov/vuln/detail/CVE-2022-2122

https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/1224
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/1225
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/1226
2022-08-11 12:34:28 +02:00
x10an14
b946a106c1 discord: 0.0.18 -> 0.0.19
As of this commit date, v0.0.18 won't let you start up - the auto-check
for available updates aborts application startup.

(cherry picked from commit 1f2b951a1f68ae56986aa3831f0889615aa7ebaf)
2022-08-10 23:17:37 -04:00
Luflosi
be6c42ea91 apfsprogs: unstable-2022-02-23 -> unstable-2022-07-21
(cherry picked from commit c4dc43a8fa)
2022-08-10 22:23:30 -04:00
Martin Weinelt
d27a7b1849 microcode-intel: 20220510 -> 20220809
https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20220809
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00657.html

Fixes: CVE-2022-21233
(cherry picked from commit 8bfd38f610)
2022-08-10 22:19:24 -04:00
Nick Cao
3b1eb8e453 knot-dns: 3.1.8 -> 3.1.9
(cherry picked from commit bfd99a4fec)
2022-08-10 22:18:16 -04:00
github-actions[bot]
6f6174b8cd Merge staging-next-22.05 into staging-22.05 2022-08-11 00:16:47 +00:00
github-actions[bot]
be57068b28 Merge release-22.05 into staging-next-22.05 2022-08-11 00:16:08 +00:00
Martin Weinelt
e47cb3e7b3 Merge pull request #185950 from helsinki-systems/bkp/22.05/varnish 2022-08-11 00:14:45 +02:00
ajs124
8410d49d36 varnish: add myself as maintainer
and remove fpletz, which removed himself on master in c092a502df

(cherry picked from commit cdbf0d5d67)
2022-08-10 19:45:43 +02:00
ajs124
6536ebc2ae varnish71: 7.1.0 -> 7.1.1
https://varnish-cache.org/security/VSV00009.html#vsv00009
(cherry picked from commit 1b6c66d38c)
2022-08-10 19:45:25 +02:00
ajs124
6548b10afc varnish: sha256 -> hash
(cherry picked from commit 56a3a71d36)
2022-08-10 19:45:21 +02:00
kilianar
f7bf1c8f79 signal-desktop: 5.53.0 -> 5.54.0
https://github.com/signalapp/Signal-Desktop/releases/tag/v5.54.0
(cherry picked from commit f7d6f6f54c)
2022-08-10 12:59:29 -04:00
Martin Puppe
48b37dd39d nixos/nixos-containers: Fix ineffective warning
A warning regarding enabling NixOS containers and
virtualisation.containers at the same time with state versions < 22.05
had been added in commit 3c49151f15. But
this warning had accidentally been defined in the wrong place, and the
warning has therefore not actually been in effect. This commit fixes
that.

(cherry picked from commit 82c64d154b)
2022-08-10 15:29:39 +00:00
Robin Gloster
b6d9987f26 Merge pull request #185873 from mayflower/vim-security-backport
[22.05] vim: 8.2.5172 -> 9.0.0115, fix CVE-2022-25{22,71,8{0,1},98}
2022-08-10 14:55:14 +02:00
Robin Gloster
b73b03a511 Merge pull request #185867 from mayflower/git-security-update-2205
[22.05] git: 2.36.0 -> 2.36.2, fix CVE-2022-29187
2022-08-10 14:53:40 +02:00
Martin Weinelt
e4c9d950a3 Merge pull request #185851 from NixOS/backport-185722-to-release-22.05 2022-08-10 10:30:54 +02:00
Maximilian Bosch
52b416ab5a vim: 8.2.5172 -> 9.0.0115, fix CVE-2022-25{22,71,8{0,1},98}
Security advisories:
* https://nvd.nist.gov/vuln/detail/CVE-2022-2522
* https://nvd.nist.gov/vuln/detail/CVE-2022-2571
* https://nvd.nist.gov/vuln/detail/CVE-2022-2580
* https://nvd.nist.gov/vuln/detail/CVE-2022-2581
* https://nvd.nist.gov/vuln/detail/CVE-2022-2598

I'm well-aware that this sounds like quite a big change, but:

* Each commit is a new release and a concept like release branches
  doesn't exist, so we cannot expect this to be fixed for 8.x.

* The commit which is tagged as 9.0.0000[1] isn't a breaking change, but
  states:

  >  release version 9.0
  >
  > Problem:    About time to release Vim 9.0.
  > Solution:   Update the version number everywhere.

  In other words, the big changes happened before. In fact, 8.2.5172 is
  the commit right before 9.0 and because 9.0 isn't a breaking commit,
  but only contains a changed release note, we technically have vim9
  already on 22.05.

[1] eb49041875
2022-08-10 10:23:04 +02:00
Bernardo Meurer
19d490f11c nixos/geoclue2: wait for network to be up when wifi provider is enabled
(cherry picked from commit ee0b8a7eaa)
2022-08-10 02:58:21 -04:00
Maximilian Bosch
3cce6754e2 git: 2.36.0 -> 2.36.2, fix CVE-2022-29187
Advisory:
* https://github.com/git/git/security/advisories/GHSA-j342-m5hw-rr3v
* https://nvd.nist.gov/vuln/detail/CVE-2022-29187

Release notes:
* https://lwn.net/ml/git/xmqqczgqmv0f.fsf%40gitster.g/ (2.36.1)
* https://lwn.net/ml/git/xmqqv8s2fefi.fsf%40gitster.g/ (2.36.2 and
  related releases)

Our `master`-branch is not affected by this since we already have
`git-2.37.1` there since dd6f2768b1.

Since Nix uses `--git-dir` now for all `git -C` calls in libfetchers,
the entire `.git`-dir detection code-path which originally caused the
series of CVEs is never reached and thus this change is not expected to
break Nix (also, 2.37 with equivalent changes is already on `master` for
a while).
2022-08-10 08:53:11 +02:00
Mario Rodas
1a149dc7c2 Merge pull request #185859 from NixOS/backport-184003-to-release-22.05
[Backport release-22.05] peertube: 4.2.1 -> 4.2.2
2022-08-09 22:29:45 -05:00
Izorkin
13fbbc92cc nixos/peertube: fix start service
(cherry picked from commit 0b98d77ff5)
2022-08-10 02:53:10 +00:00
Izorkin
ae6664f06c peertube: 4.2.1 -> 4.2.2
(cherry picked from commit 4344950312)
2022-08-10 02:53:10 +00:00
Mario Rodas
3f3fa048af Merge pull request #185821 from NixOS/backport-185732-to-release-22.05
[Backport release-22.05] yt-dlp: 2022.07.18 -> 2022.8.8
2022-08-09 21:48:09 -05:00
github-actions[bot]
6bf43d6f40 Merge staging-next-22.05 into staging-22.05 2022-08-10 00:14:28 +00:00
github-actions[bot]
6828b4b90d Merge release-22.05 into staging-next-22.05 2022-08-10 00:13:50 +00:00
Martin Weinelt
78462af13e firefox-devedition-bin-unwrapped: 104.0b4 -> 104.0b7
(cherry picked from commit 780343cc77)
2022-08-09 23:06:35 +00:00
Martin Weinelt
1cc3a56d54 firefox-beta-bin-unwrapped: 104.0b4 -> 104.0b7
(cherry picked from commit 59b3d2738b)
2022-08-09 23:06:34 +00:00
Martin Weinelt
7bb328eb72 firefox-bin-unwrapped: 103.0.1 -> 103.0.2
https://www.mozilla.org/en-US/firefox/103.0.2/releasenotes/
(cherry picked from commit 39b4f0994e)
2022-08-09 23:06:34 +00:00
Martin Weinelt
c62637b8c2 firefox-unwrapped: 103.0.1 -> 103.0.2
https://www.mozilla.org/en-US/firefox/103.0.2/releasenotes/
(cherry picked from commit 52aef90bc6)
2022-08-09 23:06:34 +00:00
Robin Gloster
d64eb5961d Merge pull request #185780 from mayflower/patch-libtirpc-cve-2022-46828
[22.05] libtirpc: apply patch for CVE-2021-46828
2022-08-10 00:06:25 +02:00
zowoq
6e9ad8368f yt-dlp: 2022.07.18 -> 2022.8.8
https://github.com/yt-dlp/yt-dlp/releases/tag/2022.08.08
(cherry picked from commit 2c84638d2b)
2022-08-09 18:29:52 +00:00
Maximilian Bosch
a3048d29cd libtirpc: apply patch for CVE-2021-46828
https://nvd.nist.gov/vuln/detail/CVE-2021-46828
2022-08-09 15:05:34 +02:00
Lassulus
490f6174c0 Merge pull request #185487 from NixOS/backport-179328-to-release-22.05
[Backport release-22.05] exim: 4.95 -> 4.96
2022-08-09 11:17:16 +03:00
Vladimír Čunát
4d54b3e29d Merge branch 'staging-22.05' into staging-next-22.05 2022-08-09 09:57:45 +02:00
Sergei Trofimovich
7a1f899207 Merge #185394: cairo: pull upstream fix for grayscale aliasing bug
(cherry picked from commit 6206494db6)
2022-08-09 09:52:33 +02:00
Vladimír Čunát
b5982242b0 Merge #185754: zlib: add fixed patch for CVE-2022-37434
...into staging-22.05
2022-08-09 09:23:27 +02:00
Vladimír Čunát
80ed09fe79 gnutls: patch CVE-2022-2509 2022-08-09 09:22:33 +02:00
Winter
34ec472210 zlib: add fixed patch for CVE-2022-37434
(cherry picked from commit d56d587e85)
2022-08-09 07:17:56 +00:00
Winter
fe877f069c zlib: remove superfluous patch files
(cherry picked from commit 5323fa886e)
2022-08-09 07:17:56 +00:00
John Ericson
3d13a54bf3 Merge pull request #185687 from NixOS/backport-182187-to-release-22.05
[Backport release-22.05] newlib-nano: Set same flags as regular newlib in cc-wrapper/gcc config
2022-08-08 21:48:25 -04:00
github-actions[bot]
810dbc4a75 Merge staging-next-22.05 into staging-22.05 2022-08-09 00:16:29 +00:00
github-actions[bot]
0140a2f05c Merge release-22.05 into staging-next-22.05 2022-08-09 00:15:51 +00:00
adisbladis
2c989c271f gcc: Set --with-newlib when using newlib-nano
(cherry picked from commit facbbae4b7)
2022-08-08 17:50:27 +00:00
adisbladis
b323542ca7 cc-wrapper: Set correct hardening_unsupported_flags for newlib-nano
(cherry picked from commit d5fb429c7d)
2022-08-08 17:50:26 +00:00
M. A
8f7cfe275b nixos/snipe-it: Add private_uploads to tmpfiles
Through testing Snipe-IT's backup feature I discovered that it expects
the `${dataDir}/storage/private_uploads` folder to be present.

(cherry picked from commit 7ba51f359a1bf2cbe9a870579ed9e58caa7f8c48)
2022-08-08 11:30:13 -04:00
Thiago Kenji Okada
6ca8bc35c7 Merge pull request #184199 from risicle/ris-obsidian-0.15.9-r22.05
[22.05] obsidian: 0.14.6 -> 0.15.9
2022-08-08 12:44:50 +01:00
Pavol Rusnak
ffd12e3589 Merge pull request #185654 from prusnak/btcpayserver-22.05
[22.05] btcpayserver: 1.5.1 -> 1.6.6
2022-08-08 12:48:23 +02:00
Erik Arvstedt
89cf6fc710 btcpayserver: 1.6.1 -> 1.6.6
(cherry picked from commit 6716c682c8)
2022-08-08 12:19:08 +02:00
Erik Arvstedt
17c460148a nbxplorer: 2.3.28 -> 2.3.33
(cherry picked from commit aecf8393c5)
2022-08-08 12:19:03 +02:00
Pavol Rusnak
e5b74d5ea4 btcpayserver: enable build on darwin
(cherry picked from commit 79aebd3e05)
2022-08-08 12:18:46 +02:00
Erik Arvstedt
a5bd91724e btcpayserver: 1.5.4 -> 1.6.1
(cherry picked from commit b45e4a004e)
2022-08-08 12:18:42 +02:00
Erik Arvstedt
2d3eef2dbe nbxplorer: 2.3.26 -> 2.3.28
(cherry picked from commit 43b37c60c0)
2022-08-08 12:18:38 +02:00
Pavol Rusnak
0bb2b2a7d9 btcpayserver: 1.5.3 -> 1.5.4
(cherry picked from commit 9253fc4a56)
2022-08-08 12:18:24 +02:00
Erik Arvstedt
867fbfa85f btcpayserver: 1.5.1 -> 1.5.3
(cherry picked from commit 2e0c027ee3)
2022-08-08 12:18:13 +02:00
Erik Arvstedt
f338423a79 nbxplorer: 2.3.20 -> 2.3.26
(cherry picked from commit 1a9df1136a)
2022-08-08 12:18:00 +02:00
github-actions[bot]
658706fc7b Merge staging-next-22.05 into staging-22.05 2022-08-08 00:14:00 +00:00
github-actions[bot]
b612bdc038 Merge release-22.05 into staging-next-22.05 2022-08-08 00:13:23 +00:00
Felix Schröter
92fe622fdf etebase-server: 0.8.3 -> 0.9.1
(cherry picked from commit 3dd79ce65d)
2022-08-07 17:30:14 -04:00
Kira Bruneau
c1bb4bfeb0 mangohud: 0.6.7-1 → 0.6.8
(cherry picked from commit 8677058a83)
2022-08-07 17:27:18 -04:00
Robert Scott
7eb1ae2b4a python3Packages.sanic: add patch for CVE-2022-35920 2022-08-07 19:10:49 +01:00
Robert Scott
f1c5c8dfc8 Merge pull request #185421 from risicle/ris-libtiff-CVE-2022-34526-r22.05
[22.05] libtiff: add patch for CVE-2022-34526
2022-08-07 11:42:18 +01:00
Bobby Rong
3c8a5fa9a6 Merge pull request #185130 from NixOS/backport-185062-to-release-22.05
[Backport release-22.05] signal-desktop: 5.52.0 -> 5.53.0
2022-08-07 16:11:37 +08:00
illustris
0228346f7b nixos/release: add proxmox LXC and VMA
(cherry picked from commit 0c0ea441e7a1fbbbccd1fdfbf998932fa14d75ac)
2022-08-06 21:41:32 -04:00
illustris
a27d90282c nixos/proxmox-image: use qemu 6.2 for building VMA
(cherry picked from commit 148b6da2a785371127eb52f0c37bd3421ce5db6c)
2022-08-06 21:41:32 -04:00
Franz Pletz
43f63ea591 Merge pull request #185292 from NixOS/backport-184348-to-release-22.05 2022-08-07 03:22:10 +02:00
github-actions[bot]
83ceaf1523 Merge staging-next-22.05 into staging-22.05 2022-08-07 00:17:45 +00:00
github-actions[bot]
2fd2d0fca8 Merge release-22.05 into staging-next-22.05 2022-08-07 00:16:55 +00:00
Robert Scott
22838ffbf4 Merge pull request #185491 from NixOS/backport-185432-to-release-22.05
[Backport release-22.05] gpac: mark with several `knownVulnerabilities`
2022-08-06 23:47:22 +01:00
Robert Scott
290eb1c46d gpac: mark with several knownVulnerabilities
(cherry picked from commit f5d6209b00)
2022-08-06 22:36:11 +00:00
ajs124
2624205929 exim: 4.95 -> 4.96
https://lists.exim.org/lurker/message/20220625.141825.d6de6074.en.html
(cherry picked from commit 65b8af2a7f)
2022-08-06 21:49:14 +00:00
ajs124
ea1bf40b07 php81: 8.1.8 -> 8.1.9
https://www.php.net/ChangeLog-8.php#8.1.9
(cherry picked from commit da6ccfbab2)
2022-08-06 12:01:47 -04:00
ajs124
1b1ecfe111 php80: 8.0.21 -> 8.0.22
https://www.php.net/ChangeLog-8.php#8.0.22
(cherry picked from commit 2b483c62db)
2022-08-06 12:01:47 -04:00
Vladimír Čunát
1e37265b92 nifi: switch src to a working and stable URL
The previous one apparently only works for the last release.

(cherry picked from commit 9f43cb3752)
2022-08-06 15:41:54 +02:00
Robert Scott
eda1176877 libtiff: add patch for CVE-2022-34526
(cherry picked from commit 19c5c57e72)
2022-08-06 14:06:42 +01:00
Robert Scott
b966358263 SDL: add patch for CVE-2022-34568
(cherry picked from commit eda5ea847ddf7f8cf70a1e45d15ae1805da232a3)
2022-08-06 03:11:29 -04:00
Sandro
72f492e275 Update pkgs/os-specific/linux/bbswitch/default.nix
(cherry picked from commit 7ee214f8e36e00b2122f5051299adf1b6dfec1ef)
2022-08-06 02:53:53 -04:00
Zane van Iperen
aadbfbc65e linuxPackages.bbswitch: 0.8 -> unstable-2021-11-29
Switch to the development branch, as it's basically stable at
this point, and pinch Arch's 5.18 compat patch.

Also remove existing patches:
- PR 102 was rejected upstream, the actual issue is
  https://github.com/Bumblebee-Project/bbswitch/issues/112,
  and can be worked around via acpi_osi=Linux
- PR 196 is applied upstream.

(cherry picked from commit e1c59eaf85139abf379954d52340a25570ab09d3)
2022-08-06 02:53:53 -04:00
Michael Adler
d96e79fce8 ungoogled-chromium: 103.0.5060.134 -> 104.0.5112.81
(cherry picked from commit 1ad5e92e8d)
2022-08-06 02:46:51 -04:00
K900
4f262f4f64 python3Packages.poetry: 1.1.12 -> 1.1.14
(cherry picked from commit 0a5a747b65)
2022-08-05 20:06:07 -07:00
github-actions[bot]
f3aeda303e Merge staging-next-22.05 into staging-22.05 2022-08-06 00:15:24 +00:00
github-actions[bot]
e305ef0254 Merge release-22.05 into staging-next-22.05 2022-08-06 00:14:40 +00:00
Martin Weinelt
e7868c6b0b Merge pull request #184549 from NixOS/backport-179728-to-staging-22.05 2022-08-06 00:26:59 +02:00
Martin Weinelt
e103e00810 Merge pull request #185296 from NixOS/backport-185213-to-staging-22.05 2022-08-06 00:22:35 +02:00
Robert Scott
50c4fbbeb0 Merge pull request #185304 from NixOS/backport-185195-to-release-22.05
[Backport release-22.05] ferdi: Note CVE-2022-32320 in knownVulnerabilities
2022-08-05 23:20:13 +01:00
Stig Palmquist
60b88134af ferdi: Note CVE-2022-32320 in knownVulnerabilities
(cherry picked from commit ae36fbe7f9)
2022-08-05 21:14:08 +00:00
Dmitry Kalinkin
1e0fb22489 clhep: init at 2.4.5.3 (#185264)
(cherry picked from commit 8d10015d3a)
2022-08-05 16:46:03 -04:00
Martin Weinelt
43ce4ac122 nspr: 4.34 -> 4.34.1
(cherry picked from commit 83daa6a316)
2022-08-05 20:27:52 +00:00
Aidan Gauland
6790917c8a minetest: Patch executable paths
(cherry picked from commit 53b1553a3f)
2022-08-05 19:48:10 +00:00
Aidan Gauland
08bda390aa irrlichtmt: 1.9.0mt4 -> 1.9.0mt5
(cherry picked from commit 3bc3c5a5f0)
2022-08-05 19:48:09 +00:00
Aidan Gauland
d72f224700 minetest: 5.5.0 -> 5.5.1
(cherry picked from commit 3a6dd06688)
2022-08-05 19:48:09 +00:00
Michael Weiss
14f6494789 Merge pull request #185122 from NixOS/backport-185052-to-release-22.05
[Backport release-22.05] chromium: 103.0.5060.134 -> 104.0.5112.79
2022-08-05 20:24:55 +02:00
Vladimír Čunát
2ed5b6b0f5 Merge #184513: staging-next-22.05 - iteration 6
... into release-22.05
2022-08-05 08:42:30 +02:00
github-actions[bot]
d74ac00a90 Merge staging-next-22.05 into staging-22.05 2022-08-05 00:17:25 +00:00
github-actions[bot]
23aff49aef Merge release-22.05 into staging-next-22.05 2022-08-05 00:16:45 +00:00
Anderson Torres
a770ce7331 Merge pull request #185163 from NixOS/backport-185131-to-release-22.05
[Backport release-22.05] palemoon: 31.1.1 -> 31.2.0.1
2022-08-04 20:39:10 -03:00
OPNA2608
09cd41711b palemoon: 31.1.1 -> 31.2.0.1
(cherry picked from commit f1b4bba5ac)
2022-08-04 23:09:14 +00:00
Winter
b095fe5050 Merge pull request #185155 from NixOS/backport-183369-to-release-22.05 2022-08-04 17:30:33 -04:00
Luflosi
ecd3f31037 linuxPackages.apfs: unstable-2022-02-03 -> unstable-2022-07-24
(cherry picked from commit d49fc40e4a)
2022-08-04 21:13:18 +00:00
Winter
2bba1180a1 Merge pull request #178590 from leungbk/backport-kitty-0.25.2 2022-08-04 16:28:11 -04:00
K900
508b95a49c zeroc-ice: skip failing test
(cherry picked from commit 62cc9ad726)
It's expired test certificate(s).
2022-08-04 22:27:20 +02:00
Anderson Torres
36b9f3d40b Merge pull request #184028 from NixOS/backport-183754-to-release-22.05
[Backport release-22.05] primecount: 7.3 -> 7.4
2022-08-04 13:12:06 -03:00
Thiago Kenji Okada
ec39957f79 Merge pull request #185135 from NixOS/backport-184846-to-release-22.05
[Backport release-22.05] opentabletdriver: add buildInputs
2022-08-04 13:54:29 +01:00
Thiago Kenji Okada
193925b8b9 opentabletdriver: add buildInputs
Should fix issue: #184652

(cherry picked from commit f15b4a5b05)
2022-08-04 12:39:29 +00:00
K900
b63c863c80 Merge pull request #185134 from NixOS/backport-143885-to-release-22.05
[Backport release-22.05] profiles/all-hardware.nix: add reset-raspberry for USB on RPi 4
2022-08-04 15:34:38 +03:00
Ratchanan Srirattanamet
1d6a3aaf5f profiles/all-hardware.nix: add reset-raspberry for USB on RPi 4
This is needed for USB to work on RPi 4. Kernel's defconfig demoted the
module from built-in to module in 5.14. See [1].

[1] https://lore.kernel.org/linux-arm-kernel/ab43364b-55cc-08e6-a647-6e50a1743f03@gmail.com/

(cherry picked from commit 2140fed726)
2022-08-04 12:33:52 +00:00
kilianar
aabec38f75 signal-desktop: 5.52.0 -> 5.53.0
https://github.com/signalapp/Signal-Desktop/releases/tag/v5.53.0
(cherry picked from commit c69eeb2c49)
2022-08-04 12:02:55 +00:00
Michael Weiss
ef9bbd280b chromium: 103.0.5060.134 -> 104.0.5112.79
https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop.html

This update includes 27 security fixes.

CVEs:
CVE-2022-2603 CVE-2022-2604 CVE-2022-2605 CVE-2022-2606 CVE-2022-2607
CVE-2022-2608 CVE-2022-2609 CVE-2022-2610 CVE-2022-2611 CVE-2022-2612
CVE-2022-2613 CVE-2022-2614 CVE-2022-2615 CVE-2022-2616 CVE-2022-2617
CVE-2022-2618 CVE-2022-2619 CVE-2022-2620 CVE-2022-2621 CVE-2022-2622
CVE-2022-2623 CVE-2022-2624

(cherry picked from commit 17f9f662f8)
2022-08-04 10:48:47 +00:00
Kerstin
6c32b75a33 Merge pull request #185114 from dotlambda/imagemagick-7.1.0-45
[22.05] imagemagick: 7.1.0-44 -> 7.1.0-45
2022-08-04 11:14:54 +02:00
Vladimír Čunát
01bcf5ec79 Merge #179982: thunderbird*-102: init at 102.0
...into release-22.05
2022-08-04 11:02:46 +02:00
Alyssa Ross
a8190e7c60 imagemagick: rename 7.0.nix to default.nix
"7.0.nix" doesn't make any sense, because it contains version
7.1.0-39.  imagemagick6 is barely used and can probably be removed
soon, so I think it makes sense to let 7.x have the default.nix path.

(cherry picked from commit 7ac2cf8e83)
2022-08-04 08:54:37 +00:00
Robert Schütz
b84c7a772a imagemagick: 7.1.0-44 -> 7.1.0-45
(cherry picked from commit 305eb886a3)
2022-08-04 08:44:38 +00:00
Martin Weinelt
1599c40272 Merge pull request #185074 from NixOS/backport-184995-to-staging-22.05 2022-08-04 10:39:34 +02:00
K900
33cebc2110 Merge pull request #185106 from NixOS/backport-184812-to-release-22.05
[Backport release-22.05] linux: actually fix split BTFs
2022-08-04 11:05:01 +03:00
K900
8fb7f8d575 Merge pull request #185107 from NixOS/backport-185093-to-release-22.05
[Backport release-22.05] Kernel updates for 2022-08-03
2022-08-04 11:04:47 +03:00
K900
2727284d39 linux/hardened/patches/5.4: 5.4.206-hardened1 -> 5.4.208-hardened1
(cherry picked from commit f23ac4035c)
2022-08-04 08:04:13 +00:00
K900
ec13eaa562 linux/hardened/patches/5.18: 5.18.12-hardened1 -> 5.18.15-hardened1
(cherry picked from commit 86bccf10b9)
2022-08-04 08:04:13 +00:00
K900
511d362705 linux/hardened/patches/5.15: 5.15.55-hardened1 -> 5.15.58-hardened1
(cherry picked from commit e9c8925f98)
2022-08-04 08:04:13 +00:00
K900
b12f3bf2e8 linux/hardened/patches/5.10: 5.10.131-hardened1 -> 5.10.134-hardened1
(cherry picked from commit fca28ee089)
2022-08-04 08:04:12 +00:00
K900
eaa3d22676 linux/hardened/patches/4.19: 4.19.252-hardened1 -> 4.19.254-hardened1
(cherry picked from commit b588944c55)
2022-08-04 08:04:12 +00:00
K900
7e129db304 linux/hardened/patches/4.14: 4.14.288-hardened1 -> 4.14.290-hardened1
(cherry picked from commit 941b70fb70)
2022-08-04 08:04:12 +00:00
K900
47234c5972 linux_latest-libre: 18825 -> 18837
(cherry picked from commit e4be613a8b)
2022-08-04 08:04:12 +00:00
K900
6632ed6f58 linux: 5.4.208 -> 5.4.209
(cherry picked from commit 6f5368cff9)
2022-08-04 08:04:12 +00:00
K900
f7ba043945 linux: 5.18.15 -> 5.18.16
(cherry picked from commit f437246542)
2022-08-04 08:04:12 +00:00
K900
2459b69595 linux: 5.15.58 -> 5.15.59
(cherry picked from commit b7b3e0bd51)
2022-08-04 08:04:12 +00:00
K900
e15eeecba2 linux: 5.10.134 -> 5.10.135
(cherry picked from commit 20249152ce)
2022-08-04 08:04:12 +00:00
K900
d35ec07b89 linux: provide pahole when configuring
The kernel checks the version of pahole at configuration time to know
if it supports features like split BTFs. If pahole doesn't exist,
all of that gets disabled in the config file, so the kernel ends up
built without split BTFs, despite having a working pahole for the actual
build.

(cherry picked from commit 6cd9a388df)
2022-08-04 08:03:52 +00:00
Vladimír Čunát
f92f7078b8 thunderbird: 102.0.2 -> 102.0.3
https://www.thunderbird.net/en-US/thunderbird/102.0.3/releasenotes/
(cherry picked from commit 7d84ef8ad9)
2022-08-04 10:02:58 +02:00
Nick Cao
466ba959e5 thunderbird-unwrapped: 102.0.1 -> 102.0.2
(cherry picked from commit 2c596146f6)
2022-08-04 10:02:49 +02:00
Vladimír Čunát
ab60687d7a thunderbird: 102.0 -> 102.0.1
https://www.thunderbird.net/en-US/thunderbird/102.0.1/releasenotes/
(cherry picked from commit b68ae07939)
2022-08-04 10:02:20 +02:00
Vladimír Čunát
c00ab01bd4 Merge #184611: thunderbird-91: 91.11.0 -> 91.12.0
...into release-22.05
2022-08-04 09:49:04 +02:00
github-actions[bot]
71f0605803 Merge staging-next-22.05 into staging-22.05 2022-08-04 00:15:22 +00:00
github-actions[bot]
9e2adc8a07 Merge release-22.05 into staging-next-22.05 2022-08-04 00:14:37 +00:00
Martin Weinelt
41e104e61b python3Packages.django_3: 3.2.14 -> 3.2.15
https://www.djangoproject.com/weblog/2022/aug/03/security-releases/

Fixes: CVE-2022-36359
(cherry picked from commit ae26091d37)
2022-08-03 23:37:29 +00:00
R. Ryantm
dd0dce34e9 mixxx: 2.3.2 -> 2.3.3
(cherry picked from commit 42a4a46441)
2022-08-03 23:51:07 +02:00
Thiago Kenji Okada
a620cb32fe Merge pull request #185043 from NixOS/backport-182372-to-release-22.05
[Backport release-22.05] xanmod-kernels: update and init tt
2022-08-03 21:21:15 +01:00
fortuneteller2k
6a8516a143 xanmod-kernels: move kernelPatches to xanmodKernels
(cherry picked from commit b3d53dee19)
2022-08-03 18:16:49 +00:00
fortuneteller2k
547d599424 linux_xanmod_tt: init at 5.15.54
(cherry picked from commit 9459bcdc13)
2022-08-03 18:16:49 +00:00
fortuneteller2k
ee9030c8bd xanmod-kernels: set suffix to a default value
(cherry picked from commit d726818c37)
2022-08-03 18:16:49 +00:00
fortuneteller2k
8e8feca52d linux_xanmod_latest: 5.18.10 -> 5.18.11
(cherry picked from commit b0cfccd50a)
2022-08-03 18:16:49 +00:00
fortuneteller2k
e2e88d14b4 linux_xanmod: 5.15.53 -> 5.15.54
(cherry picked from commit ac93fd3177)
2022-08-03 18:16:49 +00:00
fortuneteller2k
8aced39e55 xanmod-kernels: remove explicit WERROR=n
(cherry picked from commit e5d17fcc91)
2022-08-03 18:16:49 +00:00
fortuneteller2k
a4f42d8c2e linux_xanmod: rename stable to lts
(cherry picked from commit 9d0769d4e7)
2022-08-03 18:16:49 +00:00
Winter
66ff02607f Merge pull request #185042 from NixOS/backport-185018-to-release-22.05 2022-08-03 14:11:22 -04:00
Kira Bruneau
1034283a4c poke: fix aarch64-darwin build
jiegec discovered that the reason the aarch64-darwin build was failing
was because pre-generated configure script failed to detect the macOS
version.

With this change we'll just ignore the pre-generated configure script,
and build it ourself with autoreconf.

(cherry picked from commit 952c5269b3)
2022-08-03 17:45:47 +00:00
Kira Bruneau
75d5832997 Merge pull request #185041 from NixOS/backport-183873-to-release-22.05
[Backport release-22.05] poke: mark aarch64-darwin as broken instead of a bad platform
2022-08-03 13:39:58 -04:00
Kira Bruneau
29e4fae74c poke: mark aarch64-darwin as broken instead of a bad platform
(cherry picked from commit f42dbbdfe2)
2022-08-03 17:38:35 +00:00
Martin Weinelt
478f3cbc84 Merge pull request #184996 from NixOS/backport-184993-to-release-22.05 2022-08-03 13:41:04 +02:00
Martin Weinelt
2f20395d25 python3Packages.django_4: 4.0.6 -> 4.0.7
https://www.djangoproject.com/weblog/2022/aug/03/security-releases/

Fixes: CVE-2022-36359
(cherry picked from commit 8e4e1caf65)
2022-08-03 11:26:27 +00:00
tirex
58d9afc5dc linux_5_19: add missing package alias
There are missing aliases for this package.

(cherry picked from commit 0121451d2efc65b8d660bbcb6d03b4bfd5d24e76)
2022-08-03 08:56:30 +00:00
Alyssa Ross
e4b111f5be linux_latest: 5.18.15 -> 5.19
(cherry picked from commit bbbebf95242f33dd930f4b9d2983b8d9b531db3c)
2022-08-03 08:39:34 +00:00
Kira Bruneau
c55096e021 Merge pull request #174822 from NixOS/backport-173795-to-release-22.05
[Backport release-22.05] mangohud: 0.6.5 -> 0.6.7-1
2022-08-02 22:33:29 -04:00
github-actions[bot]
2a7effa802 Merge staging-next-22.05 into staging-22.05 2022-08-03 00:17:42 +00:00
github-actions[bot]
64fb6c750f Merge release-22.05 into staging-next-22.05 2022-08-03 00:16:43 +00:00
Anderson Torres
4a2e2ae280 Merge pull request #184904 from NixOS/backport-184316-to-release-22.05
[Backport release-22.05] ltris: 1.2.4 -> 1.2.5
2022-08-02 19:09:26 -03:00
Shane Sveller
b0343f8b7c erlang: 25.0.2 -> 25.0.3
https://www.erlang.org/patches/otp-25.0.3
(cherry picked from commit 3a6483f5ebd7ef59c85c5ed15c9a81e31d844521)
2022-08-02 23:42:05 +02:00
Shane Sveller
7daf2a4e1f erlang: 25.0 -> 25.0.2
https://www.erlang.org/patches/otp-25.0.1
https://www.erlang.org/patches/otp-25.0.2
(cherry picked from commit ddcc8217dcd4989f6af9b66375d9f3c739f4c974)
2022-08-02 23:42:05 +02:00
Winter
54e80a521f Merge pull request #184893 from NixOS/backport-184845-to-release-22.05 2022-08-02 17:41:45 -04:00
R. Ryantm
dab2d8c6ad ltris: 1.2.4 -> 1.2.5
(cherry picked from commit e17f70ef42)
2022-08-02 21:38:36 +00:00
Anderson Torres
a5fe330b9e Merge pull request #184899 from NixOS/backport-184342-to-release-22.05
[Backport release-22.05] lpairs2: 2.1 -> 2.2
2022-08-02 18:31:53 -03:00
Luis Pedro Coelho
ec24d988f6 samtools: Fix cross-compilation
Tests require bgzip which comes from the htslib package.

This did not cause problems prior to
41485e7337 as tests were not run in
cross-compilation.

(cherry picked from commit 5877d8e072)
2022-08-02 21:26:01 +00:00
R. Ryantm
433e7391d0 lpairs2: 2.1 -> 2.2
(cherry picked from commit 8f6d9b45fb)
2022-08-02 21:25:37 +00:00
Anderson Torres
eff0460f14 Merge pull request #184879 from NixOS/backport-184674-to-release-22.05
[Backport release-22.05] sakura: 3.8.4 -> 3.8.5
2022-08-02 18:18:37 -03:00
Anderson Torres
5b7fa73de2 Merge pull request #184880 from NixOS/backport-184745-to-release-22.05
[Backport release-22.05] xa: 2.3.12 -> 2.3.13
2022-08-02 18:18:21 -03:00
Anderson Torres
1d6168605f Merge pull request #184883 from NixOS/backport-184773-to-release-22.05
[Backport release-22.05] yabasic: 2.90.1 -> 2.90.2
2022-08-02 18:18:07 -03:00
Anderson Torres
58f143e1c2 Merge pull request #184884 from NixOS/backport-184766-to-release-22.05
[Backport release-22.05] zchunk: 1.2.0 -> 1.2.2
2022-08-02 18:17:45 -03:00
Michael Auchter
dce0b5d026 nixos/soju: add defaults and assertions for TLS
Enabling soju without providing a value for tlsCertificate currently
results in:

  error: The option `services.soju.tlsCertificate' is used but not
  defined.

Since tlsCertificate is intended to be optional, set default to null.

Additionally, add assertions to ensure that both tlsCertificate and
tlsCertificateKey are either set or unset.

(cherry picked from commit 5c0e18a6bb)
2022-08-02 20:59:38 +00:00
R. Ryantm
091e563cac zchunk: 1.2.0 -> 1.2.2
(cherry picked from commit 740b518320)
2022-08-02 19:31:21 +00:00
R. Ryantm
7d4924c221 yabasic: 2.90.1 -> 2.90.2
(cherry picked from commit 7c8629447b)
2022-08-02 19:28:57 +00:00
R. Ryantm
c49a24b811 xa: 2.3.12 -> 2.3.13
(cherry picked from commit eea38ee715)
2022-08-02 19:27:25 +00:00
R. Ryantm
eb6515c619 sakura: 3.8.4 -> 3.8.5
(cherry picked from commit 6702078739)
2022-08-02 19:26:45 +00:00
Anderson Torres
684db6b544 Merge pull request #184661 from NixOS/backport-184162-to-release-22.05
[Backport release-22.05] zxing-cpp: 1.2.0 -> 1.4.0
2022-08-02 16:21:09 -03:00
Anderson Torres
64d07a6286 Merge pull request #184660 from NixOS/backport-184260-to-release-22.05
[Backport release-22.05] lbreakouthd: 1.0.9 -> 1.0.10
2022-08-02 16:20:39 -03:00
Winter
f4a568cf13 Merge pull request #184859 from NixOS/backport-184838-to-release-22.05 2022-08-02 14:49:09 -04:00
Sumner Evans
728df4438c matrix-synapse: 1.63.1 -> 1.64.0
Signed-off-by: Sumner Evans <me@sumnerevans.com>
(cherry picked from commit 463fe0db3d)
2022-08-02 17:41:59 +00:00
Kerstin
1d1cac1426 Merge pull request #184855 from dotlambda/imagemagick-7.1.0-44
[22.05] imagemagick: 7.1.0-43 -> 7.1.0-44
2022-08-02 19:23:12 +02:00
Robert Schütz
c1f7fa8a3d imagemagick: 7.1.0-43 -> 7.1.0-44
(cherry picked from commit 25a8587508)
2022-08-02 16:49:23 +00:00
kilianar
1ef0f17f8e syncthing: 1.20.3 -> 1.20.4
https://github.com/syncthing/syncthing/releases/tag/v1.20.4
(cherry picked from commit 515d6cff4af6311b2e9cd3a22e5f2db94c760ff0)
2022-08-02 16:05:15 +02:00
Bjørn Forsman
6968c9465a syncthing: also link nixosTests.syncthing in passthru.tests
Before this change it linked syncthing-init and syncthing-relay but was
missing the main syncthing test itself.

(cherry picked from commit b5900c1bb9d980935eb236c7209590c87715ee0e)
2022-08-02 16:04:34 +02:00
John Ericson
a9f66ae640 Merge pull request #184814 from NixOS/backport-184620-to-release-22.05
[Backport release-22.05] buildRustCrate: Add support for standard library deps
2022-08-02 08:56:52 -04:00
Alyssa Ross
0bee6c25c2 linuxPackages.apfs: mark broken on 5.19
(cherry picked from commit 116f3443115e958c26c6d0ae6517cebee2566d48)
2022-08-02 12:52:32 +00:00
John Ericson
5aef865cef buildRustCrate: Add support for standard library deps
We are replicating one mechanism behind `-Z build-std`.

There isn't yet crate2nix support for this, but one can (and I do) add
the missing stdlib deps (for this feature to pick up) with overrides.

(cherry picked from commit cc29693a09)
2022-08-02 12:34:44 +00:00
alyaeanyx
53303b9087 freetube: 0.16.0 -> 0.17.0
(cherry picked from commit 3c2a83612955daa0e2457f1c58caab461300756f)
2022-08-02 14:16:13 +02:00
Winter
276c780851 Merge pull request #184774 from NixOS/backport-184238-to-release-22.05 2022-08-02 04:45:59 -04:00
R. Ryantm
d5a7d719e9 hut: 0.1.0 -> 0.2.0
(cherry picked from commit 43e64074f2)
2022-08-02 08:29:13 +00:00
Winter
77587a2d5a Merge pull request #184759 from NixOS/backport-180750-to-release-22.05 2022-08-02 03:48:15 -04:00
Roman Volosatovs
7747d334da kernel: port randstruct patch to 5.19
Signed-off-by: Roman Volosatovs <roman@profian.com>
Signed-off-by: Roman Volosatovs <rvolosatovs@riseup.net>
(cherry picked from commit 5a9ed0ff2c156863627fca64deb6df9bfba98718)
2022-08-02 07:17:04 +00:00
matthewcroughan
35dabbc317 linux_testing: 5.15-rc6 -> 5.19-rc5
(cherry picked from commit 20efc11d74971c2b83ea877446e83dcf24e4d3ff)
2022-08-02 07:17:04 +00:00
Winter
8d558c0811 Merge pull request #184712 from NixOS/backport-184475-to-release-22.05 2022-08-02 00:25:51 -04:00
R. Ryantm
9e6cffdb0c psi-plus: 1.5.1618 -> 1.5.1633
(cherry picked from commit f9d4fb6a95)
2022-08-02 03:49:24 +00:00
R. Ryantm
dd68bb484d zxing-cpp: 1.2.0 -> 1.4.0
(cherry picked from commit 1953e425a9)
2022-08-02 00:22:47 +00:00
R. Ryantm
e2920f2349 lbreakouthd: 1.0.9 -> 1.0.10
(cherry picked from commit 8a1f471e85)
2022-08-02 00:22:13 +00:00
github-actions[bot]
6c85b2ea07 Merge staging-next-22.05 into staging-22.05 2022-08-02 00:16:25 +00:00
Anderson Torres
5e92e966e1 Merge pull request #184221 from NixOS/backport-184056-to-release-22.05
[Backport release-22.05] stella: 6.6 -> 6.7
2022-08-01 21:16:21 -03:00
github-actions[bot]
b30c363b32 Merge release-22.05 into staging-next-22.05 2022-08-02 00:15:47 +00:00
Anderson Torres
aff9d971bc Merge pull request #184222 from NixOS/backport-184048-to-release-22.05
[Backport release-22.05] ares: 128 -> 129
2022-08-01 21:13:35 -03:00
Benjamin Hipple
bb75b4bd7b Merge pull request #184345 from risicle/ris-fava-1.22.2.r22.05
[22.05] fava: 1.21 -> 1.22.2
2022-08-01 20:07:15 -04:00
Winter
760d3360f7 Merge pull request #184631 from NixOS/backport-184399-to-release-22.05 2022-08-01 18:22:53 -04:00
Winter
564384fab3 Merge pull request #184632 from NixOS/backport-184623-to-release-22.05
[Backport release-22.05] securefs: compile with clang
2022-08-01 18:21:10 -04:00
ajs124
5e718d78c1 python3.pkgs.pyunbound: inherit patches from unbound 2022-08-02 00:10:38 +02:00
Robert Scott
0840fd623a Merge pull request #184240 from risicle/ris-vault-1.10.5-r22.05
[22.05] vault, vault-bin: 1.10.3 -> 1.10.5
2022-08-01 23:02:00 +01:00
ajs124
8b90408201 Merge pull request #184558 from helsinki-systems/bkp/22.05/libwebp 2022-08-01 23:51:19 +02:00
Sylvain Fankhauser
d9cba9061f securefs: compile with clang
securefs always exits with an "invalid password" error when compiled with
the latest GCC version. Upstream confirmed the fix is to build with
clang:
https://github.com/netheril96/securefs/issues/124#issuecomment-962618957

(cherry picked from commit a87cd27054)
2022-08-01 21:12:38 +00:00
R. Ryantm
391f6b13d2 net-snmp: 5.9.1 -> 5.9.3
(cherry picked from commit 25985fa375)
2022-08-01 20:46:54 +00:00
ajs124
408c3e3049 unbound: fix CVE-2022-30698 and CVE-2022-30699 2022-08-01 21:53:54 +02:00
Robert Schütz
c45ab4b6a5 python310Packages.mat2: 0.12.4 -> 0.13.0
fixes CVE-2022-35410

https://0xacab.org/jvoisin/mat2/-/blob/0.13.0/CHANGELOG.md
(cherry picked from commit 97f2bc8b06)
2022-08-01 19:52:31 +00:00
Vladimír Čunát
7d2bee020a thunderbird-91: 91.11.0 -> 91.12.0
https://www.thunderbird.net/en-US/thunderbird/91.12.0/releasenotes/
(cherry picked from commit 3cdefadeaf)
2022-08-01 17:40:23 +00:00
John Ericson
a9afb6a008 Merge pull request #184601 from NixOS/backport-184596-to-release-22.05
[Backport release-22.05] compiler-rt: Fix "bare metal" case boolean logic
2022-08-01 13:24:37 -04:00
John Ericson
c820cd8cee compiler-rt: Fix "bare metal" case boolean logic
It is possible to both be bare metal and have a libc (newlib).

This libc doesn't provide very much --- not enough for CMake to think
the C toolchain works. We therefore adjust our logic so we hit the "bare
metal" case with or without libc.

The "use LLVM" bootstrap is intentionally not affected.

(cherry picked from commit bf39e32272)
2022-08-01 16:51:26 +00:00
Martin Weinelt
1cab649bc0 Merge pull request #184574 from NixOS/backport-184548-to-release-22.05 2022-08-01 18:43:06 +02:00
Martin Weinelt
c55d3940f3 firefox-devedition-bin-unwrapped: 103.0b9 -> 104.0b4
(cherry picked from commit 15118244b5)
2022-08-01 15:05:22 +00:00
Martin Weinelt
2932004c05 firefox-beta-bin-unwrapped: 103.0b9 -> 104.0b4
(cherry picked from commit e5b199029a)
2022-08-01 15:05:22 +00:00
Martin Weinelt
73174df87f firefox-bin-unwrapped: 103.0 -> 103.0.1
https://www.mozilla.org/en-US/firefox/103.0.1/releasenotes/
(cherry picked from commit cbe3f7a141)
2022-08-01 15:05:22 +00:00
Martin Weinelt
8ba7833270 firefox-unwrapped: 103.0 -> 103.0.1
https://www.mozilla.org/en-US/firefox/103.0.1/releasenotes/
(cherry picked from commit a03cc9a933)
2022-08-01 15:05:22 +00:00
Peder Bergebakken Sundt
a1822d1e29 owncast: Fix statedirectory issue after upgrade
The entrypoint script would ensure a symlink to
the nix store exists in the state directory.
The script would fail when trying to overwrite an
existing symlink.

Steps to trigger the issue:

* Install owncast
* Upgrade owncast
* Garbage collect the store
* Upgrade owncast

I chose not to use the -f option in `ln`, as this is
more explicit.

(cherry picked from commit ac2d6bef04)
2022-08-01 14:30:48 +00:00
R. Ryantm
d213bd21d8 libwebp: 1.2.2 -> 1.2.3
(cherry picked from commit 964ee6f55f)
2022-08-01 14:54:19 +02:00
ajs124
2697a8cd48 libwebp: 1.2.1 -> 1.2.2
also clean up and take up maintainership

(cherry picked from commit 51619a501f)
2022-08-01 14:54:16 +02:00
squalus
c4e5eee372 python310Packages.setuptools-scm: fix cross compile of dependents
Packages depending on setuptools-scm need the setuptools module at
build time. Add setuptools to the propagatedBuildInputs so this is
guaranteed. This fixes cross compile of the dependent packages.

(cherry picked from commit 77e6eda9b2)
2022-08-01 11:05:08 +00:00
Vladimír Čunát
35adedc166 Merge branch 'staging-22.05' into staging-next-22.05 2022-08-01 10:50:32 +02:00
Vladimír Čunát
e43cf17484 Merge #182384: wolfssl: add patches for CVE-2022-34293
... and encrypted memory improvements (into release-22.05)
2022-08-01 10:33:52 +02:00
Vladimír Čunát
c088812c56 Merge #182395: openldap: load client config from /etc
...not the nix store (into staging-22.05)
2022-08-01 10:29:32 +02:00
Vladimír Čunát
efbd56edf6 Merge #182521: perlPackages.LWP: 6.49 -> 6.67, fix cross build
...into staging-22.05
2022-08-01 10:27:17 +02:00
Vladimír Čunát
34fb71c153 Merge #182244: kexec-tools: fix build with elfv2 abi on ppc64be
...into staging-22.05
2022-08-01 10:27:17 +02:00
Vladimír Čunát
6c285681cb Merge #182242: llvm14: Skip broken tests on riscv
...into staging-22.05
2022-08-01 10:27:17 +02:00
Winter
13ddb2c617 Merge pull request #184407 from NixOS/backport-182113-to-release-22.05 2022-07-31 23:31:53 -04:00
Andrew Marshall
2b1fb09dc7 mlc: 3.9 -> 3.9a
The previous version is also now unavailable, and the URL appears to
have been changed.

(cherry picked from commit 59dca5cc57)
2022-08-01 03:10:04 +00:00
github-actions[bot]
f8ee2e37aa Merge staging-next-22.05 into staging-22.05 2022-08-01 00:17:10 +00:00
github-actions[bot]
99e0953d65 Merge release-22.05 into staging-next-22.05 2022-08-01 00:16:36 +00:00
Robert Scott
9e26f12815 fava: 1.22.1 -> 1.22.2
(cherry picked from commit cc95d8a722)
2022-07-31 22:06:47 +01:00
Vladyslav M
6631511775 fava: 1.21 -> 1.22.1
(cherry picked from commit a1bf8ce827)
2022-07-31 22:06:32 +01:00
Robert Scott
4b754b24d0 vault: 1.10.3 -> 1.10.5 2022-07-31 15:36:13 +01:00
Vincent Laporte
8b7ba20e59 gajim: 1.4.6 → 1.4.7
(cherry picked from commit 628574adb5)
2022-07-31 16:22:26 +02:00
AndersonTorres
65912f3432 ares: 128 -> 129
(cherry picked from commit dd91058dd6)
2022-07-31 13:43:33 +00:00
R. Ryantm
ab4789bf07 stella: 6.6 -> 6.7
(cherry picked from commit a5c0e67ed4)
2022-07-31 13:42:32 +00:00
Robert Scott
01df1f7bb1 vault-bin: 1.10.3 -> 1.10.5 2022-07-31 14:13:18 +01:00
Jörg Thalheim
14f1cb285d Merge pull request #184202 from NixOS/backport-178873-to-release-22.05
[Backport release-22.05] Fix broken seafile
2022-07-31 12:59:20 +01:00
greizgh
cd32e3cd88 seahub: build python path from overridden python
Co-authored-by: Robert Schütz <github@dotlambda.de>
(cherry picked from commit 070ce98dda)
2022-07-31 11:28:14 +00:00
Greizgh
5dca084c3a seahub: add passthru.tests
(cherry picked from commit c2d6628ae9)
2022-07-31 11:28:14 +00:00
Greizgh
39e986eea8 nixos/seafile: version 9.0x compatibility
(cherry picked from commit dd8386c453)
2022-07-31 11:28:14 +00:00
Greizgh
cbc319287a seahub: 8.0.8 -> 9.0.6
(cherry picked from commit 8d6df4d032)
2022-07-31 11:28:14 +00:00
Greizgh
f5aa239f22 seafile-server: 8.0.8 -> 9.0.6
(cherry picked from commit bc9ec95b36)
2022-07-31 11:28:13 +00:00
R. Ryantm
a2d9eda683 obsidian: 0.14.15 -> 0.15.9
(cherry picked from commit d49fe72888)
2022-07-31 12:04:12 +01:00
Átila Saraiva
feb9a2c7c0 obsidian: 0.14.6 -> 0.14.15
(cherry picked from commit 56d2f848b1)
2022-07-31 12:03:56 +01:00
K900
ede02b4ccb Merge pull request #184164 from NixOS/backport-183600-to-release-22.05
[Backport release-22.05] nixos-rebuild: always set flakeFlags
2022-07-31 10:46:18 +03:00
K900
1880ae56b0 nixos-rebuild: always set flakeFlags
Otherwise a rebuild can fail when a flake is autodetected
in /etc/nixos/flake.nix and the system doesn't have flakes
globally enabled.

(cherry picked from commit 28dae620b2)
2022-07-31 07:42:22 +00:00
Robert Scott
720249407b python3Packages.mistune_2_0: 2.0.2 -> 2.0.4
(cherry picked from commit 0a9621088aecdc0fc6c7a0afaacb8cf2bb69d108)
2022-07-30 20:56:56 -07:00
Martin Weinelt
a26a6f4529 python3Packages.untangle: 1.1.1 -> 1.2.1
addressing CVE-2022-31471 & CVE-2022-33977

(cherry picked from commit 769dd92446)
2022-07-30 17:51:11 -07:00
github-actions[bot]
9e4e152d3c Merge staging-next-22.05 into staging-22.05 2022-07-31 00:16:19 +00:00
github-actions[bot]
7a84b512a9 Merge release-22.05 into staging-next-22.05 2022-07-31 00:15:38 +00:00
Anderson Torres
620181da88 Merge pull request #184040 from NixOS/backport-183993-to-release-22.05
[Backport release-22.05] dxa: 0.1.4 -> 0.1.5
2022-07-30 18:21:40 -03:00
R. Ryantm
3c2a15eee9 dxa: 0.1.4 -> 0.1.5
(cherry picked from commit b62eadf3b1)
2022-07-30 21:03:49 +00:00
Anderson Torres
783f4c4877 Merge pull request #183875 from NixOS/backport-183867-to-release-22.05
[Backport release-22.05] openmsx: 17.0 -> 18.0
2022-07-30 17:59:10 -03:00
Anderson Torres
0016868194 Merge pull request #184029 from NixOS/backport-184001-to-release-22.05
[Backport release-22.05] free42: 3.0.9 -> 3.0.13
2022-07-30 17:44:27 -03:00
R. Ryantm
fc813058f6 free42: 3.0.9 -> 3.0.13
(cherry picked from commit cc8cefb0a8)
2022-07-30 19:20:21 +00:00
R. Ryantm
da32f1444a primecount: 7.3 -> 7.4
(cherry picked from commit faa6e41b2a)
2022-07-30 19:06:19 +00:00
Anderson Torres
b19560aa61 Merge pull request #184018 from NixOS/backport-183756-to-release-22.05
[Backport release-22.05] primesieve: 7.9 -> 8.0
2022-07-30 15:41:04 -03:00
R. Ryantm
b579350a39 primesieve: 7.9 -> 8.0
(cherry picked from commit 344c2740e1)
2022-07-30 18:18:18 +00:00
Anderson Torres
48e7602692 Merge pull request #184016 from NixOS/backport-183638-to-release-22.05
[Backport release-22.05] gftp: 2.8.0b -> 2.9.1b
2022-07-30 15:11:33 -03:00
Winter
c46209cae6 Merge pull request #182733 from risicle/ris-ujson-CVE-2022-31117-r22.05 2022-07-30 13:32:02 -04:00
Winter
ccda0794f7 Merge pull request #182708 from risicle/ris-lxml-CVE-2022-2309.r22.05 2022-07-30 13:24:31 -04:00
R. Ryantm
404a3558ed gftp: 2.8.0b -> 2.9.1b
(cherry picked from commit 958280f0d5)
2022-07-30 17:23:14 +00:00
Anderson Torres
e65fe777d9 Merge pull request #183872 from NixOS/backport-183739-to-release-22.05
[Backport release-22.05] ppsspp: 1.12.3 -> 1.13.1
2022-07-30 14:17:27 -03:00
John Ericson
d5f1a5126b Merge pull request #183968 from obsidiansystems/add-newer-ipfs-backport
[22.05] ipfs_0_14: Init
2022-07-30 11:27:37 -04:00
John Ericson
5a38ac6d37 ipfs_0_14: Init
On stable we just add new versions, rather than making potentially
breaking bumps.

See 6109ba4f30 for prior art of this.
2022-07-30 10:04:08 -04:00
Luflosi
bf089d447f ipfs: use passthru for repoVersion
The `repoVersion` is only used outside the derivation and not for the build of IPFS itsef. This is exactly the use-case `passthru` was meant for.
It allows updating the `repoVersion` without rebuilding IPFS. This may come in handy if someone forgets to update it and it needs to be updated later.

(cherry picked from commit 7ff7f66643)
2022-07-30 09:49:16 -04:00
R. Ryantm
dcf5d9fed9 oauth2-proxy: 7.2.1 -> 7.3.0
(cherry picked from commit 3bc35e7dafdbed8e7d4cdceaa0e953b544868c24)
2022-07-30 14:54:25 +02:00
Pavol Rusnak
e0607132c7 Merge pull request #183957 from NixOS/backport-183951-to-release-22.05 2022-07-30 14:14:53 +02:00
Pavol Rusnak
46c2543e9e bitcoin: fix broken build on aarch64-darwin
fixes #179474
follow-up to #179795

(cherry picked from commit bd95ace2d3)
2022-07-30 11:53:16 +00:00
Winter
1e5d0fbd82 Merge pull request #183876 from NixOS/backport-182937-to-release-22.05 2022-07-30 00:05:55 -04:00
Winter
2c96788430 Merge pull request #183881 from NixOS/backport-183165-to-release-22.05 2022-07-30 00:05:11 -04:00
Daniel Olsen
4edb7ce2e2 hydrus: 492 -> 493
(cherry picked from commit 5c2c276f6f)
2022-07-30 03:23:44 +00:00
Kira Bruneau
11fc4a7fc1 poke: mark aarch64-darwin as a bad platform
Jitter fails to compile on aarch64-darwin:

Undefined symbols for architecture arm64:
  "_jitter_print_context_kind_destroy", referenced from:
      _jitter_print_libtextstyle_finalize in libjitter-libtextstyle.a(jitter-print-libtextstyle.o)
  "_jitter_print_context_kind_make_trivial", referenced from:
      _jitter_print_libtextstyle_initialize in libjitter-libtextstyle.a(jitter-print-libtextstyle.o)
  "_jitter_print_context_make", referenced from:
      _jitter_print_context_make_libtextstyle in libjitter-libtextstyle.a(jitter-print-libtextstyle.o)
     (maybe you meant: _jitter_print_context_make_libtextstyle)
  "_ostream_flush", referenced from:
      _jitter_print_context_libtextstyle_flush in libjitter-libtextstyle.a(jitter-print-libtextstyle.o)
  "_ostream_write_mem", referenced from:
      _jitter_print_context_libtextstyle_print_chars in libjitter-libtextstyle.a(jitter-print-libtextstyle.o)
  "_styled_ostream_begin_use_class", referenced from:
      _jitter_print_context_libtextstyle_begin_decoration in libjitter-libtextstyle.a(jitter-print-libtextstyle.o)
  "_styled_ostream_end_use_class", referenced from:
      _jitter_print_context_libtextstyle_end_decoration in libjitter-libtextstyle.a(jitter-print-libtextstyle.o)
  "_styled_ostream_set_hyperlink", referenced from:
      _jitter_print_context_libtextstyle_begin_decoration in libjitter-libtextstyle.a(jitter-print-libtextstyle.o)
      _jitter_print_context_libtextstyle_end_decoration in libjitter-libtextstyle.a(jitter-print-libtextstyle.o)
ld: symbol(s) not found for architecture arm64

(cherry picked from commit 9f5b96a9e1)
2022-07-30 03:07:55 +00:00
Kira Bruneau
f40c8a1739 poke: fix cross-compilation
(cherry picked from commit c360ada54c)
2022-07-30 03:07:55 +00:00
Kira Bruneau
31d811d1b5 poke: only wrap poke-gui with TCLLIBPATH
(cherry picked from commit c843822729)
2022-07-30 03:07:55 +00:00
Kira Bruneau
574c988455 poke: fix guiSupport
(cherry picked from commit c027d1a8f2)
2022-07-30 03:07:55 +00:00
Kira Bruneau
539569b7c0 poke: move share/vim from $lib to $out
(cherry picked from commit 45f46d31a6)
2022-07-30 03:07:55 +00:00
R. Ryantm
78aa8bdf18 poke: 2.3 -> 2.4
(cherry picked from commit 6810e93f13)
2022-07-30 03:07:55 +00:00
AndersonTorres
5d324bb273 openmsx: 17.0 -> 18.0
(cherry picked from commit 3cd1540510)
2022-07-30 02:56:21 +00:00
R. Ryantm
ce2a7ffee3 ppsspp: 1.12.3 -> 1.13.1
(cherry picked from commit d98b8a4942)
2022-07-30 02:38:56 +00:00
Anderson Torres
6b95192bc6 Merge pull request #183869 from NixOS/backport-183581-to-release-22.05
[Backport release-22.05] _4th: 3.64.0 -> 3.64.1
2022-07-29 23:32:05 -03:00
Anderson Torres
e0581b9e42 Merge pull request #183868 from NixOS/backport-183650-to-release-22.05
[Backport release-22.05] jwasm: 2.14 -> 2.15
2022-07-29 23:31:27 -03:00
R. Ryantm
658d69d2ea _4th: 3.64.0 -> 3.64.1
(cherry picked from commit 9a1aa7d8ae)
2022-07-30 01:55:16 +00:00
R. Ryantm
bf8b695653 jwasm: 2.14 -> 2.15
(cherry picked from commit 5960a2d1b4)
2022-07-30 01:54:42 +00:00
Winter
38c98c2d8c Merge pull request #183863 from NixOS/backport-183209-to-release-22.05 2022-07-29 20:49:08 -04:00
AndersonTorres
e80275f018 fvwm3: nixos module
(cherry picked from commit bef8e4df1d)
2022-07-30 00:16:04 +00:00
AndersonTorres
f86672c6c0 fvwm3: init at 1.0.4
(cherry picked from commit cd43f8b8bd)
2022-07-30 00:16:04 +00:00
AndersonTorres
cf8765dddb fvwm: rename nixos module to fvwm2
(cherry picked from commit 2617a00699)
2022-07-30 00:16:04 +00:00
AndersonTorres
54927be032 fvwm: move-rename to fvwm2
In order to introduce fvwm3, since 2.6.x is now in maintenance mode, with the
new development occurring in a new repository.

(cherry picked from commit 439696441e)
2022-07-30 00:16:04 +00:00
github-actions[bot]
0a71e1f64b Merge staging-next-22.05 into staging-22.05 2022-07-30 00:14:49 +00:00
github-actions[bot]
f8b8c5ca69 Merge release-22.05 into staging-next-22.05 2022-07-30 00:14:04 +00:00
Maximilian Bosch
876ae82835 Merge pull request #183824 from NixOS/backport-183741-to-release-22.05
[Backport release-22.05] Linux kernel updates 2022-07-29
2022-07-30 00:45:56 +02:00
Maximilian Bosch
dc1cb12765 linux: 5.4.207 -> 5.4.208
(cherry picked from commit d060a1191b)
2022-07-29 21:45:48 +00:00
Maximilian Bosch
0165ea659d linux: 5.18.13 -> 5.18.15
(cherry picked from commit 37f0f42f70)
2022-07-29 21:45:48 +00:00
Maximilian Bosch
c8cee1200a linux: 5.15.56 -> 5.15.58
(cherry picked from commit 8beec3e69a)
2022-07-29 21:45:48 +00:00
Maximilian Bosch
e126a0f720 linux: 5.10.132 -> 5.10.134
(cherry picked from commit 40b001eee2)
2022-07-29 21:45:47 +00:00
Maximilian Bosch
925a608db9 linux: 4.9.324 -> 4.9.325
(cherry picked from commit 32da3390ab)
2022-07-29 21:45:47 +00:00
Maximilian Bosch
840ae19c84 linux: 4.19.253 -> 4.19.254
(cherry picked from commit 310ce04485)
2022-07-29 21:45:47 +00:00
Maximilian Bosch
f69257a580 linux: 4.14.289 -> 4.14.290
(cherry picked from commit be408ef5bb)
2022-07-29 21:45:47 +00:00
Ilan Joselevich
86b53cbfae nextcloud-client: 3.5.2 -> 3.5.3
(cherry picked from commit acd0c51b1c)
2022-07-29 23:42:03 +02:00
Eduardo Quiros
8b37a0da38 signal-desktop: 5.50.0 -> 5.52.0
(cherry picked from commit e91ae12d88)
2022-07-29 23:27:35 +02:00
Robert Scott
975b388b43 Merge pull request #182859 from mayflower/qemu-backport-CVE-2022-35414
[22.05] qemu: fix CVE-2022-35414
2022-07-29 21:56:04 +01:00
Winter
e8bc4c190a Merge pull request #183749 from squalus/librewolf-22.05
[Backport release-22.05] librewolf: 102.0-2 -> 103.0-3
2022-07-29 14:29:20 -04:00
squalus
c5ac8bcf44 librewolf: 102.0-2 -> 103.0-3
(cherry picked from commit 4042f5e34b)
2022-07-29 10:51:42 -07:00
Robin Gloster
066281f640 qemu: fix CVE-2022-35414
(cherry picked from commit b2d221795b)
2022-07-29 19:18:31 +02:00
Winter
b3dc49bbce Merge pull request #183704 from NixOS/backport-183075-to-release-22.05
[Backport release-22.05] tutanota-desktop: 3.95.4 -> 3.98.15
2022-07-29 12:24:09 -04:00
kilianar
7408411377 tutanota-desktop: 3.95.4 -> 3.98.15
https://github.com/tutao/tutanota/releases/tag/tutanota-desktop-release-3.98.15
(cherry picked from commit 28cc677b26)
2022-07-29 14:53:43 +00:00
github-actions[bot]
47fbbcef60 Merge staging-next-22.05 into staging-22.05 2022-07-29 00:14:57 +00:00
github-actions[bot]
2c3561414b Merge release-22.05 into staging-next-22.05 2022-07-29 00:14:22 +00:00
Winter
9370544d84 Merge pull request #183506 from NixOS/backport-183404-to-release-22.05
[Backport release-22.05] gitlab: 15.1.2 -> 15.1.4
2022-07-28 19:49:45 -04:00
Winter
643383bf4f Merge pull request #183503 from NixOS/backport-183486-to-release-22.05
[Backport release-22.05] webkitgtk: 2.36.4 → 2.36.5
2022-07-28 19:03:23 -04:00
Robert Scott
0f9845e204 Merge pull request #182675 from NixOS/backport-182578-to-release-22.05
[Backport release-22.05] lua5_4: add patch for CVE-2022-33099
2022-07-28 23:51:04 +01:00
Winter
adb3c70a80 gitlab: 15.1.2 -> 15.1.4
(cherry picked from commit 09521268ef18a84d5b34fdea3ee3806834d41645)
2022-07-28 22:39:12 +00:00
Jan Tojnar
e034dd1f9a webkitgtk: 2.36.4 → 2.36.5
https://webkitgtk.org/2022/07/28/webkitgtk2.36.5-released.html
https://webkitgtk.org/security/WSA-2022-0007.html
(cherry picked from commit 5c3edc267f2019a1c1c0bf789a6edf04c011ebca)
2022-07-28 22:12:15 +00:00
Winter
6e58354889 Merge pull request #183279 from NixOS/backport-178933-to-release-22.05
[Backport release-22.05] heisenbridge: 1.13.0 -> 1.13.1
2022-07-28 13:33:05 -04:00
Winter
b80b8d22b3 Merge pull request #183277 from NixOS/backport-182940-to-release-22.05
[Backport release-22.05] fetchnextcloudapp: name -> pname
2022-07-28 11:52:55 -04:00
Domen Kožar
8a2f2d0f5a Merge pull request #183350 from domenkozar/22.05-cachix-bump
[22.05] cachix bump
2022-07-28 10:06:12 -05:00
Domen Kožar
11d10caa50 cachix: 0.8.0 -> 0.8.1 2022-07-28 09:41:54 -05:00
Adam Joseph
4ec615c044 gpsd: delete useless line
(cherry picked from commit 789e6f13153dfddaf73da7f75d70c376d0665040)
2022-07-28 16:11:43 +02:00
Adam Joseph
e4c38af18a gpsd: unbreak the build for guiSupport=false
The `rm $out/bin/xgps*` command fails because that file is not there in the first place.  Let's change it to `rm -f $out/bin/xgps*` so we can build with `guiSupport=false`.

(cherry picked from commit f6772839add744bde626ef0d1544a3ceaaf8a925)
2022-07-28 16:11:43 +02:00
R. Ryantm
8c24b0c7b1 heisenbridge: 1.13.0 -> 1.13.1
(cherry picked from commit d08919a511)
2022-07-28 11:25:11 +00:00
ajs124
393f84986c fetchnextcloudapp: name -> pname
this way name and the storepath contain the version, which can be useful
sometimes

(cherry picked from commit 0ce971e5d2)
2022-07-28 10:52:34 +00:00
Winter
174e938d59 Merge pull request #183021 from NixOS/backport-182827-to-release-22.05
[Backport release-22.05] binutils: fix the kernel build for PowerPC
2022-07-28 01:18:59 -04:00
Winter
646b187a9b Merge pull request #183146 from NixOS/backport-182844-to-release-22.05
[Backport release-22.05] nix.perl-bindings: fix build on aarch64-darwin
2022-07-28 01:10:37 -04:00
Winter
43074a8152 Merge pull request #183185 from NixOS/backport-183025-to-release-22.05
[Backport release-22.05] vscode, vscodium: 1.69.1 -> 1.69.2
2022-07-27 23:40:49 -04:00
Bill Ewanick
41d0efabbe vscodium: 1.69.1 -> 1.69.2
(cherry picked from commit 91a156d2c3)
2022-07-28 02:52:02 +00:00
Bill Ewanick
bf71813799 vscode: 1.69.1 -> 1.69.2
(cherry picked from commit bad8f550a7)
2022-07-28 02:52:02 +00:00
Winter
615358979e Merge pull request #183179 from NixOS/backport-182657-to-release-22.05
[Backport release-22.05] mktorrent: specify platforms
2022-07-27 22:30:02 -04:00
Winter
0b384c1fce mktorrent: add winter as maintainer
(cherry picked from commit 93e4d695fe)
2022-07-28 02:16:00 +00:00
Winter
b4dbf0044f mktorrent: specify platforms
(cherry picked from commit e5efc4779d)
2022-07-28 02:16:00 +00:00
Winter
00ed43c4ed mktorrent: formatting
(cherry picked from commit 3f99d1b6b6)
2022-07-28 02:15:59 +00:00
Winter
eb8d5e223b Merge pull request #183134 from NixOS/backport-183117-to-release-22.05
[Backport release-22.05] tor-browser-bundle-bin: 11.5 -> 11.5.1
2022-07-27 21:22:22 -04:00
github-actions[bot]
786fc04a5e Merge staging-next-22.05 into staging-22.05 2022-07-28 00:17:43 +00:00
github-actions[bot]
2bc43e1a18 Merge release-22.05 into staging-next-22.05 2022-07-28 00:17:05 +00:00
Artturi
eb45994f6c Merge pull request #183153 from NixOS/backport-182851-to-staging-22.05 2022-07-28 01:00:07 +03:00
Artturin
f2790ac9b7 SDL2: restore udev support by default on linux
it was disabled seemingly by accident in 8abc1cccfb

(cherry picked from commit 47c3a3e440)
2022-07-27 21:33:00 +00:00
Rick van Schijndel
76e54678eb Merge pull request #182633 from fleimgruber/backport_jabref_5_6
[Backport release-22.05] JabRef: 5.5 -> 5.6
2022-07-27 23:29:17 +02:00
misuzu
3668cba582 nix.perl-bindings: fix build on aarch64-darwin
(cherry picked from commit ecd7a89a7b)
2022-07-27 20:59:26 +00:00
Bjørn Forsman
0e98c0a41c lighttpd: link nixosTests.lighttpd to passthru.tests
Ref. https://nixos.org/manual/nixpkgs/unstable/#ssec-nixos-tests-linking

(cherry picked from commit c699f1a1d087a7e56a30152df9ea5b6baacac817)
2022-07-27 22:24:12 +02:00
Bjørn Forsman
9c6b8542c3 nixos: add lighttpd test
(cherry picked from commit 21ded95a35fb51ddd3335adad7145871f3b3f1b1)
2022-07-27 22:24:12 +02:00
Nicolas Benes
43ad82e046 tor-browser-bundle-bin: 11.5 -> 11.5.1
(cherry picked from commit fadcd7cbd1)
2022-07-27 19:09:46 +00:00
Sandro
209f4cbede Merge pull request #183059 from NixOS/backport-182765-to-release-22.05 2022-07-27 20:45:07 +02:00
Vladimír Čunát
110cb3e742 Merge #183121: zen-kernels: retire myself as a maintainer
...into release-22.05
2022-07-27 19:58:20 +02:00
Dmitriy
2296150de9 zen-kernels: retire myself as a maintainer
(cherry picked from commit 1909ee2df3)
2022-07-27 17:36:38 +00:00
Timothy DeHerrera
557786ef63 Merge pull request #183101 from NixOS/backport-181674-to-release-22.05
[Backport release-22.05] nvidia: improve robustness of udev rules
2022-07-27 06:53:33 -07:00
Timothy DeHerrera
7f11c49d3c nvidia: improve robustness of udev rules
fixes #165719

(cherry picked from commit 371db36e56)
2022-07-27 13:36:43 +00:00
Bobby Rong
86a2640727 Merge pull request #181376 from NixOS/backport-181369-to-release-22.05
[Backport release-22.05] vmware-horizon-client: use legacy UI
2022-07-27 21:03:18 +08:00
Bobby Rong
b155e6abcc Merge pull request #182709 from NixOS/backport-182573-to-release-22.05
[Backport release-22.05] benthos: init at 4.3.0
2022-07-27 20:30:47 +08:00
Bobby Rong
de0db9ca74 Merge pull request #182926 from NixOS/backport-181737-to-release-22.05
[Backport release-22.05] zen-kernels: retire myself as a maintainer
2022-07-27 20:28:19 +08:00
Vladimír Čunát
b375e20785 Merge #183090: kanboard: fix source hash (into release-22.05) 2022-07-27 13:18:25 +02:00
Vladimír Čunát
885ff51860 kanboard: fix source hash
When auto-updating in commit 258a05b427, both bots succeeded,
but a couple days later on Hydra the hash always differed already.
https://github.com/NixOS/nixpkgs/pull/159913
https://hydra.nixos.org/build/167559708

I assume that the upstream modified their tag soon after release.

(cherry picked from commit 3173592f44)
2022-07-27 10:54:00 +00:00
Mario Rodas
d9536b9b1e Merge #182640: nodejs-16_x: 16.15.0 -> 16.16.0
(cherry picked from commit ca9423b7f6)
Let's do this directly; it seemed better to skip over the pixman
commit for now, as this has security fixes and is much cheaper.
2022-07-27 10:56:36 +02:00
Craftman7
a4e601607d sentry-cli: 1.74.3 -> 2.5.0
(cherry picked from commit c37f48149d)
2022-07-27 04:50:21 +00:00
github-actions[bot]
95049cf6bc Merge staging-next-22.05 into staging-22.05 2022-07-27 00:17:38 +00:00
github-actions[bot]
b485b5f0e0 Merge release-22.05 into staging-next-22.05 2022-07-27 00:17:02 +00:00
Minijackson
2396fa296a binutils: fix the kernel build for PowerPC
(cherry picked from commit 5d05bbed74)
2022-07-26 21:26:43 +00:00
Martin Weinelt
aab3441eb6 Merge pull request #182975 from mweinelt/22.05/mozilla 2022-07-26 21:17:55 +02:00
Martin Weinelt
f81210b353 firefox-beta-bin-unwrapped: 103.0b1 -> 103.0b9
(cherry picked from commit 9483f20d10)
2022-07-26 15:55:49 +02:00
Martin Weinelt
8685d620c7 firefox-devediton-bin-unwrapped: 103.0b1 -> 103.0b9
(cherry picked from commit d4c6c0f252)
2022-07-26 15:55:49 +02:00
Martin Weinelt
7f07354aaa spidermonkey_91: 91.11.0 -> 91.12.0
(cherry picked from commit d361a9f90a)
2022-07-26 15:55:48 +02:00
Martin Weinelt
316d816778 firefox-esr-91-unwrapped: 91.11.0esr -> 91.12.0esr
https://www.mozilla.org/en-US/firefox/91.12.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-29/

Fixes: CVE-2022-36319, CVE-2022-36318
(cherry picked from commit aafd5020fa)
2022-07-26 15:55:48 +02:00
Martin Weinelt
650e9589bb firefox-esr-102-unwrapped: 102.0.1esr -> 102.1.0esr
https://www.mozilla.org/en-US/firefox/102.1.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-30/

Fixes: CVE-2022-36319, CVE-2022-36318, CVE-2022-36314, CVE-2022-2505
(cherry picked from commit a2c4eb714d)
2022-07-26 15:55:47 +02:00
Martin Weinelt
6772a8f7bb firefox-bin-unwrapped: 102.0.1 -> 103.0
https://www.mozilla.org/en-US/firefox/103.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-28/

Fixes: CVE-2022-36319, CVE-2022-36317, CVE-2022-36318, CVE-2022-36314,
       CVE-2022-36315, CVE-2022-36316, CVE-2022-36320, CVE-2022-2505
(cherry picked from commit 8e3066f49f)
2022-07-26 15:55:47 +02:00
Martin Weinelt
1192e2a4e8 firefox-unwrapped: 102.0.1 -> 103.0
https://www.mozilla.org/en-US/firefox/103.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-28/

Fixes: CVE-2022-36319, CVE-2022-36317, CVE-2022-36318, CVE-2022-36314,
       CVE-2022-36315, CVE-2022-36316, CVE-2022-36320, CVE-2022-2505
(cherry picked from commit a168249ddc)
2022-07-26 15:55:46 +02:00
Martin Weinelt
f2c6940a97 rust-cbindgen: 0.24.2 -> 0.24.3
https://github.com/eqrion/cbindgen/releases/tag/v0.24.3
(cherry picked from commit 49f69d1988)
2022-07-26 15:55:46 +02:00
Martin Weinelt
f5eeb7e957 rust-cbindgen: 0.23.0 -> 0.24.2
https://github.com/eqrion/cbindgen/releases/tag/v0.24.0
https://github.com/eqrion/cbindgen/releases/tag/v0.24.1
https://github.com/eqrion/cbindgen/releases/tag/v0.24.2
(cherry picked from commit 1a3ff178aa)
2022-07-26 15:55:45 +02:00
Atemu
d2111ede50 zen-kernels: retire myself as a maintainer
I don't use either anymore

(cherry picked from commit ff2e597e9a)
2022-07-26 06:58:37 +00:00
Bjørn Forsman
d3c953af9a lighttpd: 1.4.64 -> 1.4.65
And remove already merged patch.

Changelog: https://www.lighttpd.net/2022/6/7/1.4.65/
(cherry picked from commit d73a8cc6c46331dc0f0ae9b7f163fc42a0708a7e)
2022-07-26 07:43:45 +02:00
Winter
003fd7c074 Merge pull request #182908 from NixOS/backport-182661-to-release-22.05
[Backport release-22.05] bpf-linker: init at 0.9.4
2022-07-25 23:32:42 -04:00
Louis Bettens
bd7c228082 chia: mark as insecure
(cherry picked from commit 6808d5e09d)
2022-07-25 23:24:06 -04:00
Nick Cao
e8ce420ed4 bpf-linker: init at 0.9.4
(cherry picked from commit a67bbc7465)
2022-07-26 02:52:38 +00:00
Franz Pletz
4408ce0f62 Merge pull request #182902 from PedroHLC/backport-182703-to-release-22.05 2022-07-26 04:06:46 +02:00
Yaya
9aaebf5e20 nextcloud: 23.0.6 -> 23.0.7
https://nextcloud.com/changelog/#latest23
(cherry picked from commit 74afc0e0d0474c809c7c3ae902d2298843e6f1de)
2022-07-26 04:03:30 +02:00
PedroHLC ☭
4376c0dcc3 linux_lqx: 5.18.14-lqx1 -> 5.18.14-lqx2
(cherry picked from commit 30c47f202a)
2022-07-25 21:56:23 -03:00
PedroHLC ☭
d9a9d1df9d linux_lqx: 5.18.13-lqx1 -> 5.18.14-lqx1
(cherry picked from commit 6f8b42bb02)
2022-07-25 21:56:12 -03:00
PedroHLC ☭
438e7034c9 linux_zen: 5.18.13-zen1 -> 5.18.14-zen1
(cherry picked from commit a829e713d4)
2022-07-25 21:56:05 -03:00
PedroHLC ☭
c0ab326ad7 zen-kernels: 5.18.12 -> 5.18.13
(cherry picked from commit 2913507a7a)
2022-07-25 21:55:27 -03:00
github-actions[bot]
5c380f0466 Merge staging-next-22.05 into staging-22.05 2022-07-26 00:15:56 +00:00
github-actions[bot]
d1fb552511 Merge release-22.05 into staging-next-22.05 2022-07-26 00:15:12 +00:00
Winter
85f964b438 Merge pull request #182895 from NixOS/backport-182888-to-release-22.05
[Backport release-22.05] gitaly: fix ldflags
2022-07-25 20:13:56 -04:00
Mario Rodas
77eff0aa10 Merge pull request #182892 from NixOS/backport-182821-to-release-22.05
[Backport release-22.05] python310Packages.scrapy: 2.6.1 -> 2.6.2
2022-07-25 19:10:15 -05:00
zowoq
723070cffe gitaly: fix ldflags
should be a list

(cherry picked from commit 6e0e1f6dd0)
2022-07-26 00:03:49 +00:00
Mario Rodas
daa3edb71f python310Packages.scrapy: 2.6.1 -> 2.6.2
https://github.com/scrapy/scrapy/releases/tag/2.6.2
(cherry picked from commit d12b988d6d)
2022-07-25 23:39:32 +00:00
Winter
b5e425c574 Merge pull request #182874 from NixOS/backport-180148-to-release-22.05
[Backport release-22.05] nixos/nginx: fix broken listenAddresses example
2022-07-25 18:59:47 -04:00
Martin Weinelt
7f19c2542c Merge pull request #182872 from NixOS/backport-179397-to-release-22.05 2022-07-26 00:05:31 +02:00
Luflosi
483ce2b4e8 nixos/nginx: fix broken listenAddresses example
When using the example without the square brackets, nginx fails to start:
```
nginx-pre-start: nginx: [emerg] invalid port in "::1:80" of the "listen" directive in /nix/store/xyz-nginx.conf:29
nginx-pre-start: nginx: configuration file /nix/store/xyz-nginx.conf test failed
```

(cherry picked from commit 320e4dbcc3)
2022-07-25 21:52:09 +00:00
Martin Weinelt
da7494ee4c Merge pull request #182870 from NixOS/backport-179398-to-release-22.05 2022-07-25 23:47:51 +02:00
R. Ryantm
9f9a28d24d firefox-beta-bin-unwrapped: 102.0b9 -> 103.0b1
(cherry picked from commit 4e000b4b6a)
2022-07-25 21:42:37 +00:00
R. Ryantm
9c6f028d7e firefox-devedition-bin-unwrapped: 102.0b9 -> 103.0b1
(cherry picked from commit 8dc489545d)
2022-07-25 21:37:50 +00:00
github-actions[bot]
f0fa012b64 python3Packages.uproot: fix runtime "No module named 'pkg_resources'" (#182830)
(cherry picked from commit 4385533655)

Co-authored-by: Dmitry Kalinkin <dmitry.kalinkin@gmail.com>
2022-07-25 15:32:51 -04:00
ajs124
755f05ce51 Merge pull request #178598 from NixOS/backport-174014-to-release-22.05 2022-07-25 20:49:18 +02:00
Dmitry Kalinkin
990914c467 python3Packages.awkward: fix runtime "No module named 'setuptools'"
(cherry picked from commit b4bb913e9712c89fac144dc866403b84898c6c3a)
2022-07-25 18:52:37 +02:00
Bjørn Forsman
1d63a2242d nixos/jenkins-job-builder: set serviceConfig.Type = "oneshot"
This change allows detecting configuration errors during
switch-to-configuration instead of them being reported asynchronously
*after* switch-to-configuration has exited.

(And update the NixOS test accordingly.)

(cherry picked from commit d7d3f5bd4166bae492cf8d4867d57461e65b2cc9)
2022-07-25 10:16:52 +02:00
Winter
01304725d4 Merge pull request #182729 from NixOS/backport-182654-to-release-22.05
[Backport release-22.05] tere: init at 1.1.0
2022-07-25 00:09:03 -04:00
Anderson Torres
9940968e2d Merge pull request #182746 from NixOS/backport-180252-to-release-22.05
[Backport release-22.05] trackma: fix bug with qt build
2022-07-25 00:20:45 -03:00
Anderson Torres
9b64c02ad8 Merge pull request #182747 from NixOS/backport-180565-to-release-22.05
[Backport release-22.05] anime-downloader: fix bug with qt build
2022-07-25 00:20:34 -03:00
github-actions[bot]
ee46b3b47d Merge staging-next-22.05 into staging-22.05 2022-07-25 00:15:34 +00:00
github-actions[bot]
ee305597a4 Merge release-22.05 into staging-next-22.05 2022-07-25 00:14:51 +00:00
WeebSorceress
b6ec706428 anime-downloader: fix bug with qt build
(cherry picked from commit 1ba2a7f398)
2022-07-24 23:56:49 +00:00
WeebSorceress
df8af0c58a trackma: fix bug with qt option
(cherry picked from commit ad36639f47)
2022-07-24 23:54:51 +00:00
Mario Rodas
d5fbd6d546 Merge pull request #182740 from NixOS/backport-181021-to-release-22.05
[Backport release-22.05] Add `bash` to netdata service path
2022-07-24 17:14:55 -05:00
Melvyn
1a37707fd6 Add bash to netdata service path
The `bash` binary is needed for running some plugins, notably the alarm notify plugins. If the binary isn't in the path, alarms notifications aren't sent and the netdata error log instead contains `/usr/bin/env: 'bash': No such file or directory`.

(cherry picked from commit ef6d6d4c4a)
2022-07-24 21:17:22 +00:00
Mario Rodas
ca9423b7f6 Merge pull request #182640 from risicle/ris-nodejs-16.16.0-r22.05
[22.05] nodejs-16_x: 16.15.0 -> 16.16.0
2022-07-24 15:10:50 -05:00
Robert Scott
cfa3b35bc3 python3Packages.ujson: add patch for CVE-2022-31117 2022-07-24 20:19:33 +01:00
Producer Matt
e942c20f90 tere: init at 1.1.0
A failing test was keeping it from building. I [confirmed with the
dev](https://github.com/mgunyho/tere/issues/44) it's known and ignored
so I commented it out with a patch.

This app isn't that useful until some [shell hooks have been
added.](https://github.com/mgunyho/tere#setup) So I hope to add a config
option to home-manager such as:

```nix
programs.tere = {
  enabled = true;
  useBashIntegration = true;
  useFishIntegration = true;
};
```

(cherry picked from commit bf182e4dec)
2022-07-24 18:24:19 +00:00
Producer Matt
cc787369bf maintainers: add ProducerMatt
(cherry picked from commit 83322150b0)
2022-07-24 18:24:19 +00:00
Anderson Torres
d1ca40ea76 Merge pull request #182715 from NixOS/backport-180581-to-release-22.05
[Backport release-22.05] palemoon: 31.1.0 -> 31.1.1
2022-07-24 14:10:07 -03:00
OPNA2608
5cdff167e7 palemoon: Further limit build cores count
Still not consistent with 32. Let's try upstream's job count for releases.

(cherry picked from commit 2cc04ccafe)
2022-07-24 16:31:42 +00:00
OPNA2608
5cca8c79aa palemoon: 31.1.0 -> 31.1.1
(cherry picked from commit b17f522053)
2022-07-24 16:31:42 +00:00
Mark Sagi-Kazar
2523da09a5 benthos: init at 4.3.0
Signed-off-by: Mark Sagi-Kazar <mark.sagikazar@gmail.com>
(cherry picked from commit b1d98133c0)
2022-07-24 15:52:53 +00:00
Robert Scott
61d0affbef python3Packages.lxml: add patch for CVE-2022-2309 2022-07-24 16:46:53 +01:00
Robert Scott
5edc66d410 lua5_4: add patch for CVE-2022-33099
(cherry picked from commit dd107ca580)
2022-07-24 08:40:06 +00:00
fleimgruber
f1251371e8 no source provenance attrs 2022-07-24 10:23:38 +02:00
Bobby Rong
d4f600ec45 Merge pull request #182653 from NixOS/backport-182603-to-release-22.05
[Backport release-22.05] railway: init at 1.8.3
2022-07-24 15:21:03 +08:00
Winter
2e14bc76ab Merge pull request #182475 from NixOS/backport-182166-to-release-22.05
[Backport release-22.05] eget: init at 1.1.0
2022-07-23 23:46:33 -04:00
Craftman7
c0bcb4430b railway: init at 1.8.3
(cherry picked from commit 60a93661ca)
2022-07-24 03:06:20 +00:00
Craftman7
7ca3af9c35 maintainers: add Crafter
(cherry picked from commit 780ac58567)
2022-07-24 03:06:20 +00:00
Mario Rodas
30b3752ea4 Merge pull request #182639 from NixOS/backport-181682-to-release-22.05
[Backport release-22.05] vscode, vscodium: 1.68.1 -> 1.69.1
2022-07-23 19:57:46 -05:00
Josh Robson Chase
053c0a54bf innernet: only package systemd units for linux
(cherry picked from commit 6b9080d336)
2022-07-23 20:52:41 -04:00
Josh Robson Chase
1cbe5a79b3 innernet: package systemd units
(cherry picked from commit 31c82b62ff)
2022-07-23 20:52:41 -04:00
github-actions[bot]
e3ca56e9d7 Merge staging-next-22.05 into staging-22.05 2022-07-24 00:18:27 +00:00
github-actions[bot]
eaf72491bc Merge release-22.05 into staging-next-22.05 2022-07-24 00:17:45 +00:00
Mario Rodas
0ac605310d Merge pull request #182398 from NixOS/backport-182302-to-release-22.05
[Backport release-22.05] minio: 2022-05-08T23-50-31Z -> 2022-07-17T15-43-14Z
2022-07-23 19:10:04 -05:00
Mario Rodas
bdc175b70c nodejs-16_x: 16.15.0 -> 16.16.0
https://github.com/nodejs/node/releases/tag/v16.15.1
https://github.com/nodejs/node/releases/tag/v16.16.0
(cherry picked from commit 37580d6187)
2022-07-24 00:45:18 +01:00
Robert Scott
7b95eb3eb7 Merge pull request #182637 from bjornfor/backport-grails
[22.05] grails: 5.1.7 -> 5.1.9
2022-07-23 23:35:48 +01:00
Bobby Rong
11acadbfd8 vscodium: 1.68.1 -> 1.69.1
(cherry picked from commit 81c37cf5f2)
2022-07-23 22:22:50 +00:00
Bobby Rong
b280801f4c vscode: 1.68.1 -> 1.69.1
(cherry picked from commit 2d8b3b67ee)
2022-07-23 22:22:50 +00:00
Robert Scott
99c46c5bb5 grails: 5.1.7 -> 5.1.9
addressing CVE-2022-35912

https://nvd.nist.gov/vuln/detail/CVE-2022-35912
(cherry picked from commit 10e96b76b3)
2022-07-23 23:13:49 +02:00
R. Ryantm
254afed787 grails: 5.1.6 -> 5.1.7
(cherry picked from commit 675d89b8bccbdd2b6a52ef8742fa0a6f27748993)
2022-07-23 23:11:38 +02:00
Winter
322f8c512d Merge pull request #182624 from NixOS/backport-182596-to-release-22.05
[Backport release-22.05] bambootracker: 0.5.0 -> 0.5.1
2022-07-23 17:06:49 -04:00
Sandro
81f1dcb034 Apply suggestions from code review
(cherry picked from commit 5061ccd1c2bee119b6896e0ef2a59ddd498b6a61)
2022-07-23 19:26:50 +00:00
Rouven Czerwinski
fcfd8d8788 xwayland: 22.1.1 -> 22.1.3
Version bump:
22.1.3:
- fix two XKB security vulnerabilities
22.1.2:
- fix an invalid pointer access in drm_lease_handle_device
- Add and set RANDR emulation

(cherry picked from commit 21a1bff4638b812d74c9bb125b57ed2b1d2f27c4)
2022-07-23 19:26:50 +00:00
linsui
5ba4dff09c JabRef: 5.5 -> 5.6
(cherry picked from commit 2df7e18699)
2022-07-23 21:07:29 +02:00
Winter
33eaead204 Merge pull request #182564 from NixOS/backport-182534-to-release-22.05
[Backport release-22.05] rainloop-{community,standard}: patch CVE-2022-29360
2022-07-23 14:44:52 -04:00
OPNA2608
4cdcc3e2ad bambootracker: 0.5.0 -> 0.5.1
(cherry picked from commit 0beea3a05a)
2022-07-23 18:36:02 +00:00
Mario Rodas
16fc9ce3f9 Merge pull request #182597 from NixOS/backport-182579-to-release-22.05
[Backport release-22.05] carla: 2.4.3 -> 2.5.0
2022-07-23 11:22:49 -05:00
Minijackson
406170dc07 carla: 2.4.3 -> 2.5.0
(cherry picked from commit 69036df904)
2022-07-23 15:59:41 +00:00
Stig
8b7ef76dad Merge pull request #182515 from risicle/ris-mediawiki-1.37.4-r22.05
[22.05] mediawiki: 1.37.2 -> 1.37.4
2022-07-23 17:20:45 +02:00
Lassulus
faf1a8b467 Merge pull request #182582 from NixOS/backport-182570-to-release-22.05 2022-07-23 16:13:48 +02:00
Bjørn Forsman
b841640f23 nixos/syncthing: don't leak the secret API key in process listings
(cherry picked from commit 65399c4742)
2022-07-23 13:48:05 +00:00
Bobby Rong
4d128b0264 Merge pull request #182192 from NixOS/backport-181580-to-release-22.05
[Backport release-22.05] ptcollab: 0.6.1.0 -> 0.6.1.1
2022-07-23 19:27:30 +08:00
Peder Bergebakken Sundt
00cd208c40 rainloop-{community,standard}: patch CVE-2022-29360
(cherry picked from commit d23282a2f5)
2022-07-23 11:10:07 +00:00
github-actions[bot]
e557268a0e Merge staging-next-22.05 into staging-22.05 2022-07-23 00:16:47 +00:00
github-actions[bot]
01e3cd0948 Merge release-22.05 into staging-next-22.05 2022-07-23 00:16:06 +00:00
Stig Palmquist
875fcd5940 [22.05] perlPackages.LWP: keep HTTPDaemon in propagatedBuildInputs
LWP was updated and changed to work around a cross compilation
regression caused by a HTTPDaemon security update, this caused another
regression where derivations expecting LWP to propagate HTTPDaemon
failed.

This commit keeps HTTPDaemon in propagatedBuildInputs for host builds as
some derivations like SOAPLite, Tirex and possibly more expect LWP to
propagate it. But not for cross builds since they are not able to build
HTTPDaemon.
2022-07-23 02:12:03 +02:00
Stig Palmquist
faa44ec33b perlPackages.LWP: 6.49 -> 6.67
Moves test dependencies to `checkInputs` to avoid pulling in
HTTP::Daemon, which is now a test requirement, if we're cross compiling
as HTTP::Daemon doesn't build with perl-cross miniperl.

(cherry picked from commit a98d434e5e)
2022-07-23 01:56:04 +02:00
Robert Scott
b3f0680e94 mediawiki: 1.37.2 -> 1.37.4 2022-07-22 23:44:04 +01:00
kilianar
1249b49b2d fzf: 0.30.0 -> 0.31.0
https://github.com/junegunn/fzf/releases/tag/0.31.0
(cherry picked from commit ab6b6091d0a124eb94038fc5fdff566ee09d2663)
2022-07-22 22:27:58 +00:00
Maximilian Bosch
4c92479d4d Merge pull request #182509 from NixOS/backport-182458-to-release-22.05
[Backport release-22.05] Linux kernel updates 2022-07-22
2022-07-23 00:11:08 +02:00
Maximilian Bosch
15964066a0 Merge pull request #182307 from NixOS/backport-181755-to-release-22.05
[Backport release-22.05] epson-escpr2: 1.1.48 -> 1.1.49
2022-07-22 23:57:40 +02:00
Maximilian Bosch
41c0f32885 linux/hardened/patches/5.4: 5.4.205-hardened1 -> 5.4.206-hardened1
(cherry picked from commit 7a3f99fa70)
2022-07-22 21:44:57 +00:00
Maximilian Bosch
24676a09bc linux/hardened/patches/5.18: 5.18.11-hardened1 -> 5.18.12-hardened1
(cherry picked from commit 5d94d1543d)
2022-07-22 21:44:57 +00:00
Maximilian Bosch
a1f4b8ed80 linux/hardened/patches/5.15: 5.15.54-hardened1 -> 5.15.55-hardened1
(cherry picked from commit fec96c5435)
2022-07-22 21:44:57 +00:00
Maximilian Bosch
7d22d331e3 linux/hardened/patches/5.10: 5.10.130-hardened1 -> 5.10.131-hardened1
(cherry picked from commit cef3263da6)
2022-07-22 21:44:56 +00:00
Maximilian Bosch
25bc9ea5a5 linux: 5.4.206 -> 5.4.207
(cherry picked from commit 61fa750911)
2022-07-22 21:44:56 +00:00
Maximilian Bosch
686dc4f4e5 linux: 5.18.12 -> 5.18.13
(cherry picked from commit a368cce1a5)
2022-07-22 21:44:56 +00:00
Maximilian Bosch
d87b46727f linux: 5.15.55 -> 5.15.56
(cherry picked from commit 98215a7f78)
2022-07-22 21:44:56 +00:00
Maximilian Bosch
9b1ec9a510 linux: 5.10.131 -> 5.10.132
(cherry picked from commit d91bda3b83)
2022-07-22 21:44:56 +00:00
Maximilian Bosch
0404d2cf87 linux: 4.9.323 -> 4.9.324
(cherry picked from commit 225a653b7d)
2022-07-22 21:44:56 +00:00
Maximilian Bosch
ee221a0473 linux: 4.19.252 -> 4.19.253
(cherry picked from commit ae6aa45e31)
2022-07-22 21:44:56 +00:00
Maximilian Bosch
63dbdb57a3 linux: 4.14.288 -> 4.14.289
(cherry picked from commit 9e6fcd6f07)
2022-07-22 21:44:56 +00:00
Bobby Rong
e3583ad6e5 Merge pull request #182474 from NixOS/backport-182272-to-release-22.05
[Backport release-22.05] hydrus: 491 -> 492
2022-07-22 22:31:24 +08:00
Sandro
6923ca30eb Update pkgs/tools/misc/eget/default.nix
(cherry picked from commit e79d61aacfe725e5c5869289ae98c952f563a2fb)
2022-07-22 14:27:38 +00:00
zendo
fbba190486 Update platforms
(cherry picked from commit 949be961772464ec98babd9aba9c57aaac2de14a)
2022-07-22 14:27:38 +00:00
zendo
bedeb961ee eget: init at 1.1.0
(cherry picked from commit 803f097882f2235dfb2714fd8829d0d052c8de04)
2022-07-22 14:27:38 +00:00
Bobby Rong
9124646ccb Merge pull request #181927 from Elinvention/backport179459
[Backport release-22.05] obs-studio-plugins.obs-pipewire-audio-capture: init at 1.0.4 (#179459)
2022-07-22 22:14:50 +08:00
Bobby Rong
a4958e035b Merge pull request #182086 from NixOS/backport-181945-to-release-22.05
[Backport release-22.05] shellhub-agent: 0.9.3 -> 0.9.4
2022-07-22 22:09:12 +08:00
Daniel Olsen
73a771410d hydrus: 491 -> 492
(cherry picked from commit bed33cb4a5)
2022-07-22 14:04:32 +00:00
Bobby Rong
80dc2f6e75 Merge pull request #182461 from NixOS/backport-182441-to-release-22.05
[Backport release-22.05] services/web-apps/lemmy.nix: Remove space that causes a type error
2022-07-22 21:48:50 +08:00
Maximilian Bosch
57d833cdde Merge pull request #182455 from NixOS/backport-182267-to-release-22.05
[Backport release-22.05] nixos/confluence: store crowd SSO password securely
2022-07-22 15:37:22 +02:00
Maximilian Bosch
4845d6f664 Merge pull request #182146 from obsidiansystems/22.05-rust-1.61
[Backport release-22.05] rust 1.61.0: Init
2022-07-22 15:34:57 +02:00
Ilan Joselevich
ec9a91a225 services/web-apps/lemmy.nix: Remove space that causes a type error
(cherry picked from commit d0617a58e2)
2022-07-22 12:37:54 +00:00
Maximilian Bosch
d135d798c6 Merge pull request #181140 from NixOS/backport-174162-to-release-22.05
[Backport release-22.05] waybar: 0.9.12 -> 0.9.13
2022-07-22 14:23:32 +02:00
Maximilian Bosch
0af0674ce6 nixos/confluence: store crowd SSO password securely
Basically the same as the JIRA change[1], but I figured that we can
actually implement that in a backwards compatible manner.

[1] https://github.com/NixOS/nixpkgs/pull/181715

(cherry picked from commit 258060c37d)
2022-07-22 11:17:47 +00:00
Martin Weinelt
099cb1a04e Merge pull request #182396 from NixOS/backport-182341-to-release-22.05 2022-07-22 10:50:15 +02:00
Winter
4149c3d018 Merge pull request #182420 from NixOS/backport-182402-to-release-22.05
[Backport release-22.05] sshs: 3.2.0 -> 3.3.0
2022-07-22 01:15:32 -04:00
github-actions[bot]
c6de8d2f4e [Backport release-22.05] dart: 2.17.0 -> 2.17.3 (#182425)
(cherry picked from commit 2d37278463)

Co-authored-by: nanashi0x74 <rian.lindenberger@gmail.com>
2022-07-22 01:13:28 -04:00
Michal
f125b232d9 sshs: 3.2.0 -> 3.3.0
(cherry picked from commit 91f9185dfb)
2022-07-22 03:58:40 +00:00
github-actions[bot]
7e6c25edcd Merge staging-next-22.05 into staging-22.05 2022-07-22 00:17:09 +00:00
github-actions[bot]
3d27438ef3 Merge release-22.05 into staging-next-22.05 2022-07-22 00:16:25 +00:00
kilianar
103c8bad7b minio: 2022-05-08T23-50-31Z -> 2022-07-17T15-43-14Z
https://github.com/minio/minio/releases/tag/RELEASE.2022-07-17T15-43-14Z

fixes CVE-2022-31028

(cherry picked from commit 4bf0af2efd)
2022-07-21 22:55:13 +00:00
ajs124
de2777bee9 nss_latest: 3.80 -> 3.81
https://github.com/nss-dev/nss/blob/master/doc/rst/releases/nss_3_81.rst
(cherry picked from commit 20ada9a6c7)
2022-07-21 22:47:32 +00:00
Dan Callaghan
a32bf49fdb openldap: load client config from /etc, not the nix store
We want Openldap clients to load /etc/ldap.conf at runtime, not
${pkgs.openldap}/etc/ldap.conf which is always a sample config.

Pass sysconfdir=/etc at compile time, so that /etc/krb5.conf is embedded
in the library as the path of its config file.

Pass sysconfdir=${out}/etc at install time, so that the sample configs
and schema files are correctly included in the build output.

This hack works because the Makefiles are not smart enough to notice
that the sysconfdir variable has changed across invocations -- because
nobody ever writes their Makefiles to be that smart. :-)

Fixes #181937.

(cherry picked from commit be2175dc94)
2022-07-21 22:34:25 +00:00
markuskowa
18c787c386 Merge pull request #182243 from NixOS/backport-182181-to-staging-22.05
[Backport staging-22.05] pixman: Limit threads
2022-07-21 21:42:20 +02:00
github-actions[bot]
84fc544332 [Backport release-22.05] nixos/minecraft-server: let server shutdown cleanly (#182369)
(cherry picked from commit e2b34f0f11)

Co-authored-by: Sofi <sofi+git@mailbox.org>
2022-07-21 15:30:58 -04:00
Winter
2772bcbf48 Merge pull request #182346 from NixOS/backport-181745-to-release-22.05
[Backport release-22.05] pivy: 0.6.6 -> 0.6.7
2022-07-21 14:58:38 -04:00
Winter
92b6199e93 Merge pull request #182305 from LibreCybernetics/backport-metals
[22.05] metals: 0.11.5 → 0.11.7
2022-07-21 14:55:27 -04:00
Winter
d847e53386 Merge pull request #182335 from Leixb/backport-rustdesk-1.1.9
[22.05] rustdesk: 1.1.8 -> 1.1.9, fix
2022-07-21 14:54:32 -04:00
Vladimír Čunát
70e3e0ee80 Merge #181922: staging-next-22.05 into release-22.05 2022-07-21 19:00:17 +02:00
Michael Alan Dorman
e783357d37 pivy: 0.6.6 -> 0.6.7
When attempting to do certain operations in FreeCAD, I ran into this
error:

    12:24:32  Traceback (most recent call last):
    12:24:32    File "/nix/store/y43dl4mv61lvzpdvwpwpsazj6b3ii87l-freecad-0.20/Mod/Image/ImageTools/_CommandImageScaling.py", line 181, in getmousepoint
    12:24:32      event = event_cb.getEvent()
    12:24:32    File "/nix/store/dq8yly6isjzq6imm0i0qjxkang5rcq84-python3.10-pivy-0.6.6/lib/python3.10/site-packages/pivy/coin.py", line 49384, in getEvent
    12:24:32      return _coin.SoEventCallback_getEvent(self)
    12:24:32  SystemError: <built-in function SoEventCallback_getEvent> returned a result with an exception set
    12:24:33  <class 'SystemError'>
    12:24:33  SystemError: PY_SSIZE_T_CLEAN macro must be defined for '#' formats
    12:24:33
    The above exception was the direct cause of the following exception:

This macro was defined in
2f049c1920,
well after 0.6.6 was released, implying that FreeCAD depends on 0.6.7.

(cherry picked from commit d5642e3491)
2022-07-21 15:11:55 +00:00
marius david
ab10a971ae rustdesk: 1.1.8 -> 1.1.9, fix
(cherry picked from commit 6bca1a6416)
2022-07-21 14:29:35 +02:00
ajs124
c93e5ab157 Merge pull request #182190 from NixOS/backport-179358-to-release-22.05 2022-07-21 14:26:34 +02:00
Shawn8901
a77d5572aa epson-escpr2: 1.1.48 -> 1.1.49
(cherry picked from commit 0c0befe2c3)
2022-07-21 06:39:27 +00:00
Maximilian Bosch
a51600cb04 Merge pull request #182246 from NixOS/backport-182239-to-release-22.05
[Backport release-22.05] atlassian-crowd: 4.4.0 -> 5.0.1
2022-07-21 08:27:26 +02:00
Maximilian Bosch
28f414e662 Merge pull request #182276 from NixOS/backport-182025-to-release-22.05
[Backport release-22.05] nextcloud24: 24.0.2 -> 24.0.3
2022-07-21 08:26:42 +02:00
Kevin Rauscher
468695595f metals: remove client specific wrappers
(cherry picked from commit f49a09b5a2)
2022-07-21 01:24:19 -05:00
Kevin Rauscher
9a330e0640 metals: 0.11.6 -> 0.11.7
(cherry picked from commit e84435878c)
2022-07-21 01:24:19 -05:00
Filipe Regadas
8f48f7c416 metals: 0.11.5 -> 0.11.6
(cherry picked from commit 5604839404)
2022-07-21 01:24:19 -05:00
Winter
b7a15e40c8 Merge pull request #182171 from NixOS/backport-182038-to-release-22.05
[Backport release-22.05] dssp: init at 4.0.5
2022-07-20 23:21:23 -04:00
Winter
38eaa0d591 Merge pull request #182297 from NixOS/backport-182294-to-release-22.05
[Backport release-22.05] ffmpeg: add platforms
2022-07-20 23:10:56 -04:00
zowoq
a8a9eb8b49 ffmpeg: add platforms
(cherry picked from commit 643bc7dd2315a038cd609f55a63f9eb220c7e7db)
2022-07-21 02:49:08 +00:00
Winter
c6eb556bb6 Merge pull request #182291 from NixOS/backport-138255-to-release-22.05
[Backport release-22.05] mafft: init at 7.487
2022-07-20 22:47:42 -04:00
natsukium
52e3ccfaec mafft: 7.487 -> 7.490
(cherry picked from commit 0524e8856b)
2022-07-21 01:55:07 +00:00
natsukium
513072d23f mafft: init at 7.487
(cherry picked from commit ff76ac9156)
2022-07-21 01:55:07 +00:00
natsukium
7dc8a855ad maintainers: Add natsukium
(cherry picked from commit bdf68ddb6a)
2022-07-21 01:55:07 +00:00
Winter
f8494e324d Merge pull request #182161 from NixOS/backport-180881-to-release-22.05
[Backport release-22.05] awscli2: 2.7.9 -> 2.7.14
2022-07-20 21:48:32 -04:00
github-actions[bot]
c3faa504b2 Merge staging-next-22.05 into staging-22.05 2022-07-21 00:15:52 +00:00
github-actions[bot]
c079f5d6db Merge release-22.05 into staging-next-22.05 2022-07-21 00:15:11 +00:00
Winter
d2ff0167ce Merge pull request #182265 from NixOS/backport-182248-to-release-22.05
[Backport release-22.05] chromium: 103.0.5060.114 -> 103.0.5060.134
2022-07-20 18:25:31 -04:00
Winter
b0543c27ba Merge pull request #182007 from winterqt/backport-181660-to-release-22.05
[Backport release-22.05] libuiohook: init at 1.2.2
2022-07-20 18:24:04 -04:00
Bernardo Meurer
729d3ce1c6 nextcloud24: 24.0.2 -> 24.0.3
(cherry picked from commit aea4ab4fd7)
2022-07-20 22:13:48 +00:00
Maximilian Bosch
318541290f Merge pull request #182200 from NixOS/backport-182095-to-release-22.05
[Backport release-22.05] matrix-synapse: 1.62.0 -> 1.63.1
2022-07-21 00:12:03 +02:00
Maximilian Bosch
b6468f8204 Merge pull request #182271 from NixOS/backport-181816-to-release-22.05
[Backport release-22.05] mautrix-whatsapp: 0.5.0 -> 0.6.0
2022-07-21 00:07:37 +02:00
Charlotte Van Petegem
01d01b6bf7 mautrix-whatsapp: 0.5.0 -> 0.6.0
https://github.com/mautrix/whatsapp/releases/tag/v0.6.0
(cherry picked from commit 670457fbdc)
2022-07-20 21:47:25 +00:00
Sumner Evans
2ebf5ccf16 matrix-synapse: 1.63.0 -> 1.63.1
Signed-off-by: Sumner Evans <me@sumnerevans.com>
(cherry picked from commit f4b02d9b1b)
2022-07-20 23:44:28 +02:00
Michael Weiss
178b028ffb chromium: 103.0.5060.114 -> 103.0.5060.134
https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop_19.html

This update includes 11 security fixes.

CVEs:
CVE-2022-2477 CVE-2022-2478 CVE-2022-2479 CVE-2022-2480 CVE-2022-2481
CVE-2022-2163

(cherry picked from commit 247f871b4d)
2022-07-20 20:52:41 +00:00
Michael Weiss
b7299003b0 Merge pull request #182249 from NixOS/backport-182205-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 103.0.5060.114 -> 103.0.5060.134
2022-07-20 22:48:42 +02:00
Michael Adler
7862ff5334 ungoogled-chromium: 103.0.5060.114 -> 103.0.5060.134
(cherry picked from commit ed0793c2d4)
2022-07-20 19:43:34 +00:00
Robin Gloster
3707f4a073 atlassian-crowd: 4.4.0 -> 5.0.1
CVE-2022-26136, CVE-2022-26137

(cherry picked from commit 161e4838fd)
2022-07-20 19:33:37 +00:00
Ryan Burns
5690a5d96f kexec-tools: fix build with elfv2 abi on ppc64be
(cherry picked from commit 10d615c89d)
2022-07-20 19:08:31 +00:00
Christian Kögler
e2b024c13d pixman: Limit threads
(cherry picked from commit 719e350414)
2022-07-20 19:04:57 +00:00
Luiz Ribeiro
0908ec663f llvm14: Skip broken tests on riscv
(cherry picked from commit c743308438)
2022-07-20 19:02:07 +00:00
Winter
2bee7df806 Merge pull request #182230 from NixOS/backport-182228-to-release-22.05
[Backport release-22.05] buildGoModules: don't add kalbasit as maintainer to every go package
2022-07-20 13:05:47 -04:00
Winter
e8441cdc8a Merge pull request #182224 from NixOS/backport-182169-to-release-22.05
[Backport release-22.05] setserial: fix cross compilation
2022-07-20 12:52:38 -04:00
Sandro Jäckel
b7f0c941c4 buildGoModules: don't add kalbasit as maintainer to every go package
(cherry picked from commit 20e17c8cd4)
2022-07-20 16:51:50 +00:00
Winter
96d127077e Merge pull request #182174 from NixOS/backport-181962-to-release-22.05
[Backport release-22.05] elfcat: 0.1.7 -> 0.1.8
2022-07-20 12:19:49 -04:00
Adam Joseph
1f0f810fa4 setserial: fix cross compilation
The setserial derivation uses nroff at compile time, so groff should
be in nativeBuildInputs rather than buildInputs.

(cherry picked from commit cb78371557)
2022-07-20 16:19:45 +00:00
Bobby Rong
26fe7618c7 Merge pull request #181901 from NixOS/backport-180959-to-release-22.05
[Backport release-22.05] sshs init at 3.2.0
2022-07-20 20:57:38 +08:00
Sumner Evans
157606dc28 matrix-synapse: 1.62.0 -> 1.63.0
Signed-off-by: Sumner Evans <me@sumnerevans.com>
(cherry picked from commit b11ce38b27)
2022-07-20 11:59:26 +00:00
R. Ryantm
0d64b49371 ptcollab: 0.6.1.0 -> 0.6.1.1
(cherry picked from commit 419b730533)
2022-07-20 10:17:22 +00:00
ajs124
99d0f07d75 nixos/tests/jitsi-meet: remove grep for successfull health check
afaict, it doesn't log this anymore after https://github.com/jitsi/jitsi-videobridge/pull/1188

(cherry picked from commit 729764a32d)
2022-07-20 09:55:56 +00:00
ajs124
611e25c061 nixos/jitsi-meet: move prosodyctl calls into prosody preStart
(cherry picked from commit aea940da63)
2022-07-20 09:55:56 +00:00
ajs124
c71d718251 jitsi-meet: 1.0.6155 -> 1.0.6260
(cherry picked from commit bf4912f399)
2022-07-20 09:55:56 +00:00
ajs124
b895cbfbd6 jitsi-videobridge: 2.1-595-g3637fda4 -> 2.2-9-g8cded16e
(cherry picked from commit bc9c51b90e)
2022-07-20 09:55:56 +00:00
ajs124
f1876eb1bb jicofo: 1.0-832 -> 1.0-900
(cherry picked from commit cbbdf1bf7b)
2022-07-20 09:55:56 +00:00
ajs124
7d77f7a688 jitsi-meet-prosody: 1.0.5675 -> 1.0.6260
(cherry picked from commit ecb36a7a6f)
2022-07-20 09:55:56 +00:00
fortuneteller2k
27d48fbaf6 elfcat: 0.1.7 -> 0.1.8
(cherry picked from commit 18677c2e7d)
2022-07-20 05:50:39 +00:00
John Ericson
5ba1290abe Merge pull request #182147 from NixOS/backport-182031-to-release-22.05
[Backport release-22.05] build-support/rust/lib: make arch and os functions respect target JSON
2022-07-20 01:31:46 -04:00
Winter
68d9e69ba9 Merge pull request #182162 from NixOS/backport-176447-to-release-22.05
[Backport release-22.05] aws-sso-cli: init at 1.9.2
2022-07-20 01:21:33 -04:00
natsukium
541a471414 dssp: init at 4.0.5
(cherry picked from commit cf0dc604a6)
2022-07-20 05:11:31 +00:00
natsukium
fb0414a693 libcifpp: init at 4.2.0
(cherry picked from commit a8a4cdb76d)
2022-07-20 05:11:31 +00:00
Winter
5a606bb49b Merge pull request #182084 from NixOS/backport-181928-to-release-22.05
[Backport release-22.05] domination: 1.2.4 -> 1.2.5
2022-07-20 01:01:46 -04:00
Morgan Helton
1581b30f1f aws-sso-cli: init at 1.9.2
(cherry picked from commit 8a56b32c66)
2022-07-20 02:50:38 +00:00
Morgan Helton
667c209241 maintainers: add devusb
(cherry picked from commit d4f419a110)
2022-07-20 02:50:37 +00:00
Morgan Helton
7c8395108b awscli2: add devusb to maintainers
(cherry picked from commit d4ec3b4b0e)
2022-07-20 02:36:25 +00:00
Morgan Helton
ba0f35d502 awscli2: 2.7.9 -> 2.7.14
(cherry picked from commit d7dc8c6b6c)
2022-07-20 02:36:25 +00:00
github-actions[bot]
4f2633b197 Merge staging-next-22.05 into staging-22.05 2022-07-20 00:16:02 +00:00
github-actions[bot]
73dd9743c2 Merge release-22.05 into staging-next-22.05 2022-07-20 00:15:18 +00:00
Mario Rodas
08d1e151e4 Merge pull request #181930 from NixOS/backport-181897-to-release-22.05
[Backport release-22.05] yt-dlp: 2022.6.29 -> 2022.07.18
2022-07-19 19:02:21 -05:00
John Ericson
b49c1ce29f build-support/rust/lib: make arch and os functions respect target JSON
(cherry picked from commit 39811b1da9)
2022-07-19 23:03:25 +00:00
Luka Blašković
2c7d266b88 rust 1.61.0: Init
(Based on commit 55c8e27290)
2022-07-19 18:38:32 -04:00
Martin Weinelt
e732e1fdbf Merge pull request #182060 from stigtsp/package/redis-7.0.4-update-22.05 2022-07-19 15:32:15 +02:00
Bobby Rong
df1dcf1b89 Merge pull request #181615 from NixOS/backport-178644-to-release-22.05
[Backport release-22.05] hydrus: 488d -> 491
2022-07-19 20:17:54 +08:00
Otavio Salvador
fd9c64a6e6 shellhub-agent: 0.9.3 -> 0.9.4
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit 088df050d8)
2022-07-19 12:00:12 +00:00
Francesco Gazzetta
793de46faf domination: 1.2.4 -> 1.2.5
(cherry picked from commit 6a58d58582f56ab52206924353fbeb1ec5226630)
2022-07-19 11:46:10 +00:00
Bobby Rong
3a2d6e8c92 Merge pull request #182074 from NixOS/backport-182042-to-release-22.05
[Backport release-22.05] platformio: unset broken on aarch64
2022-07-19 19:19:25 +08:00
Enno Richter
5d246a01e6 platformio: unset broken on aarch64
(cherry picked from commit 6b5849cb4f60daf47a62ca41f49029e1b1e84760)
2022-07-19 09:46:14 +00:00
Stig
008f63ba1d Merge pull request #181957 from NixOS/backport-181949-to-release-22.05
[Backport release-22.05] rt: 5.0.2 -> 5.0.3
2022-07-19 09:32:09 +02:00
Mario Rodas
8f133cba5e redis: 7.0.3 -> 7.0.4
https://github.com/redis/redis/releases/tag/7.0.4
(cherry picked from commit 48b7d7fc38)
2022-07-19 09:09:50 +02:00
Mario Rodas
c577ad0e91 redis: 7.0.2 -> 7.0.3
https://github.com/redis/redis/releases/tag/7.0.3
(cherry picked from commit 1238884090)
2022-07-19 09:09:50 +02:00
Mario Rodas
8f7cd85e7a redis: 7.0.0 -> 7.0.2
https://github.com/redis/redis/releases/tag/7.0.1
https://github.com/redis/redis/releases/tag/7.0.2
(cherry picked from commit b661c34a10)
2022-07-19 09:09:50 +02:00
github-actions[bot]
fa63d87c1f Merge staging-next-22.05 into staging-22.05 2022-07-19 00:17:35 +00:00
github-actions[bot]
538c58526c Merge release-22.05 into staging-next-22.05 2022-07-19 00:16:50 +00:00
Andrew Morgan
6467db1205 libuiohook: init at 1.2.2
(cherry picked from commit 4f82bcc822)
2022-07-18 16:15:17 -04:00
Andrew Morgan
390eed99f9 maintainers: add anoa
(cherry picked from commit 28778e05a0)
2022-07-18 16:14:39 -04:00
Thiago Kenji Okada
c35cc3546f Merge pull request #181968 from NixOS/backport-181733-to-release-22.05
[Backport release-22.05] zen-kernels: linux_lqx, linux_zen: 5.18.11 -> 5.18.12
2022-07-18 18:56:20 +01:00
PedroHLC ☭
9f9116a847 zen-kernels: 5.18.11 -> 5.18.12
(cherry picked from commit 6c36b381db)
2022-07-18 16:01:50 +00:00
ajs124
e1c8f24ae3 rt: 5.0.2 -> 5.0.3
fixes CVE-2022-25802, CVE-2022-25803 and CVE-2020-11022 (in rt)

For all changes see https://github.com/bestpractical/rt/releases/tag/rt-5.0.3

(cherry picked from commit c286a8f8c2)
2022-07-18 14:18:23 +00:00
7c6f434c
0c46150c9c Merge pull request #181903 from NixOS/backport-181192-to-release-22.05
[Backport release-22.05] gajim: 1.4.3 → 1.4.6
2022-07-18 14:15:52 +00:00
Mario Rodas
4222467cb9 yt-dlp: 2022.6.29 -> 2022.07.18
https://github.com/yt-dlp/yt-dlp/releases/tag/2022.07.18
(cherry picked from commit 1be882bca9)
2022-07-18 10:22:08 +00:00
Elia Argentieri
e3e80151a2 obs-studio-plugins.obs-pipewire-audio-capture: init at 1.0.3 (#179459)
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit 22cc20eba8)
2022-07-18 11:36:32 +02:00
Vladimír Čunát
7391594091 Merge branch 'staging-22.05' into staging-next-22.05 2022-07-18 10:38:21 +02:00
Vladimír Čunát
3eb3df0dfb Merge #181218: aws-iam-authenticator: 0.5.7 -> 0.5.9
...into release-22.05
2022-07-18 10:37:09 +02:00
Vladimír Čunát
012354bc86 Merge #181729: linux: enable MODULE_ALLOW_BTF_MISMATCH
...into staging-22.05
2022-07-18 10:35:33 +02:00
Vladimír Čunát
824e37a89a Merge #181808: xorg.xorgserver: patch two CVEs
...into staging-22.05
2022-07-18 10:32:01 +02:00
Vladimír Čunát
ab2ac7650a Merge #181839: go*: fix pkgsCross.raspberryPi.pkgsBuildHost.go*
...into staging-22.05
2022-07-18 10:27:17 +02:00
Vladimír Čunát
c16d93b60c Merge #181767: perlPackages.HTTPDaemon: 6.01 -> 6.14
... and patch for CVE-2022-3108 (into staging-22.05)
2022-07-18 10:24:39 +02:00
Vladimír Čunát
ea9ff78ed3 Merge #181734: python3Packages.setuptools: add distutils patch
... to support cross-compilation (into staging-22.05)
2022-07-18 10:17:58 +02:00
Rick van Schijndel
6726628860 Merge pull request #181895 from NixOS/backport-181885-to-staging-22.05
[Backport staging-22.05] libdecor: add missing dep egl (fix cross-compile)
2022-07-18 09:54:14 +02:00
Rick van Schijndel
a872489c96 Merge pull request #181876 from pacien/pkgs-lib-cross-2205
[22.05] pkgs-lib: fix JSON, YAML and TOML cross-compilation
2022-07-18 09:11:11 +02:00
Vincent Laporte
ec87bf6390 gajim: 1.4.3 → 1.4.6
(cherry picked from commit fa748c2e5d)
2022-07-18 04:52:35 +00:00
Michal
a7fa1e8c5f sshs: init at 3.2.0
(cherry picked from commit 190a8c326c)
2022-07-18 04:43:36 +00:00
Michal
13a733bc1c maintainers: add ihatethefrench
(cherry picked from commit 602e9830e9)
2022-07-18 04:43:35 +00:00
Mario Rodas
fc5eb3025b Merge pull request #181886 from winterqt/backport-181644-to-release-22.05
[Backport release-22.05] mdbook: 0.4.18 -> 0.4.20
2022-07-17 19:33:31 -05:00
github-actions[bot]
bb73fd4409 Merge staging-next-22.05 into staging-22.05 2022-07-18 00:14:28 +00:00
github-actions[bot]
d7adcceace Merge release-22.05 into staging-next-22.05 2022-07-18 00:13:50 +00:00
pacien
e5b3ab3b84 libdecor: add missing dep egl (fix cross-compile)
This adds a missing runtime dependency necessary when cross-compiling,
solving the following error:

> Run-time dependency egl found: NO (tried pkgconfig)
> demo/meson.build:7:0: ERROR: Dependency "egl" not found, tried pkgconfig

(cherry picked from commit 036ed9b9f1)
2022-07-17 23:24:26 +00:00
Sandro Jäckel
4b863e5f3d mdbook: add nix to passthru.tests
(cherry picked from commit 5dba101517)
2022-07-17 16:11:03 -04:00
Sandro Jäckel
1b23f10311 mdbook: 0.4.18 -> 0.4.20
(cherry picked from commit 233fa91f75)
2022-07-17 16:10:49 -04:00
Ben Wolsieffer
2ea4fbbc9c pkgs-lib: fix JSON, YAML and TOML cross-compilation
Splicing of nativeBuildInputs doesn't work unless callPackage is used, so
the generators were attempting to use host platform tools at build time.

(cherry picked from commit 14b01120c1)
2022-07-17 21:12:56 +02:00
Maximilian Bosch
4c288839a3 Merge pull request #181695 from Ma27/backport-element
[22.05] element-{web,desktop}: 1.10.15 -> 1.11.0
2022-07-17 20:32:29 +02:00
Bjørn Forsman
cccc62fe97 nixos/jenkins-job-builder: create secret file with umask 0077
IOW, don't make it world readable.

(cherry picked from commit 837ba2d4070b160a8360f5df2adba937b3f9e3a7)
2022-07-17 15:48:49 +02:00
amesgen
fb02b1f4a9 sigal: add setuptools to deps
(cherry picked from commit b622a65477)
2022-07-17 15:38:00 +02:00
Artturin
2f4286aa46 go_1_17: fix pkgsCross.raspberryPi.pkgsBuildHost.go_1_17
/nix/store/lyl6nysc3i3aqhj6shizjgj0ibnf1pvg-glibc-2.34-210/lib/libpthread.so: file not recognized: file format not recognized

(cherry picked from commit addc94bee790e62f695742ea8668fdaceb720b41)
2022-07-17 12:40:38 +00:00
Artturin
58f967a775 go_1_18: fix pkgsCross.raspberryPi.pkgsBuildHost.go_1_18
/nix/store/lyl6nysc3i3aqhj6shizjgj0ibnf1pvg-glibc-2.34-210/lib/libpthread.so: file not recognized: file format not recognized

(cherry picked from commit 6e4a11f457ef699741606fb0e143fa4854a13382)
2022-07-17 12:40:38 +00:00
Artturin
2900d63acf go_1_17: fix pkgsCross.raspberryPi.pkgsBuildHost.go_1_17
/nix/store/lyl6nysc3i3aqhj6shizjgj0ibnf1pvg-glibc-2.34-210/lib/libpthread.so: file not recognized: file format not recognized

it appears that those aren't needed anymore since go builds

they were added in PR 23122, i don't know why

(cherry picked from commit 42720944630c80ce8218c32d41e49f88b1019ea8)
2022-07-17 12:40:38 +00:00
Artturin
dd78fb756b go_1_18: fix pkgsCross.raspberryPi.pkgsBuildHost.go_1_18
/nix/store/lyl6nysc3i3aqhj6shizjgj0ibnf1pvg-glibc-2.34-210/lib/libpthread.so: file not recognized: file format not recognized

it appears that those aren't needed anymore since go builds

they were added in PR 23122, i don't know why

(cherry picked from commit 5d4da876dee491499a4e7d8838b9b550e248aa32)
2022-07-17 12:40:38 +00:00
Bobby Rong
5947eb12f0 Merge pull request #181833 from NixOS/backport-181789-to-release-22.05
[Backport release-22.05] pantheon.elementary-files: fix crash when removing bookmark
2022-07-17 20:32:34 +08:00
Thiago Kenji Okada
884e8851d1 Merge pull request #181836 from NixOS/backport-179691-to-release-22.05
[Backport release-22.05] linux_xanmod: bump stable and edge to latest version
2022-07-17 13:19:11 +01:00
Phillip Cloud
dfdcb11bec linux_xanmod: remove LRNG option
(cherry picked from commit 100c1bcc11)
2022-07-17 11:30:39 +00:00
Phillip Cloud
55ba92838f linux_xanmod_latest: 5.18.1 -> 5.18.10
(cherry picked from commit bc799b3222)
2022-07-17 11:30:39 +00:00
Phillip Cloud
73dce5b995 linux_xanmod: 5.15.43 -> 5.15.53
(cherry picked from commit 3087ec9f21)
2022-07-17 11:30:39 +00:00
Thiago Kenji Okada
c565288bc8 Merge pull request #181771 from NixOS/backport-175917-to-release-22.05
[Backport release-22.05] linuxKernels.kernels.linux_xanmod: 5.15.40 -> 5.15.43
2022-07-17 12:25:05 +01:00
Bobby Rong
d3705c1944 pantheon.elementary-files: fix crash when removing bookmark
(cherry picked from commit 475016947e)
2022-07-17 10:33:42 +00:00
Alyssa Ross
dcd9ce1a06 imagemagick: fix version
imagemagick.passthru.tests tests that the Nixpkgs version for
imagemagick matches the one produced by magick --version, so the
recent upgrade that changed the dash to a dot broke the test.

Fixes: 3a4ea08942 ("imagemagick: 7.1.0-39 -> 7.1.0.43")
(cherry picked from commit c82890e2e2)
2022-07-17 09:41:24 +02:00
Vladimír Čunát
27457e7081 xorg.xorgserver: patch two CVEs
https://lists.x.org/archives/xorg/2022-July/061035.html
(cherry picked from commit 98137b4db1)
2022-07-17 06:31:40 +00:00
Mario Rodas
4e329926df Merge pull request #181681 from NixOS/backport-181489-to-release-22.05
[Backport release-22.05] shellhub-agent: 0.9.2 -> 0.9.3
2022-07-16 22:42:35 -05:00
github-actions[bot]
af172fd6c7 Merge staging-next-22.05 into staging-22.05 2022-07-17 00:15:19 +00:00
github-actions[bot]
a54a013a34 Merge release-22.05 into staging-next-22.05 2022-07-17 00:14:46 +00:00
github-actions[bot]
d9a169d56d [Backport release-22.05] steam/fhsenv.nix: Add libindicator-gtk2 and libdbusmenu-gtk2 (#181766)
* steam/fhsenv.nix: Add libindicator-gtk2 and libdbusmenu-gtk2

Fixes steam tray icon showing up but not being interactable

(cherry picked from commit 07f87860f530406a3a1bb581ca9c8712b9d89cc1)

* Update pkgs/games/steam/fhsenv.nix

(cherry picked from commit b924df32660bfae1a6d31b4f683a6b33bed0c6a2)

Co-authored-by: Luna Nova <git@lunnova.dev>
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
2022-07-16 19:05:55 -04:00
Phillip Cloud
842f0722a3 linuxKernels.kernels.linux_xanmod: don't set -Werror by default
Co-authored-by: fortune <lythe1107@gmail.com>
(cherry picked from commit 58b3f66931)
2022-07-16 22:28:13 +00:00
Phillip Cloud
d2a52c0272 linuxKernels.kernels.linux_xanmod: apply patch from review
(cherry picked from commit 83171a1dba)
2022-07-16 22:28:13 +00:00
Phillip Cloud
c6f8eb8c5a linuxKernels.kernels.linux_xanmod: import helpers
Co-authored-by: fortune <lythe1107@gmail.com>
(cherry picked from commit d688ec7d80)
2022-07-16 22:28:13 +00:00
Phillip Cloud
772158e43a linuxKernels.kernels.linux_xanmod: adjust config for 5.18
(cherry picked from commit ecaaba491d)
2022-07-16 22:28:13 +00:00
Phillip Cloud
780404e505 linuxKernel.kernels.linux_xanmod_latest: 5.17.8 -> 5.18.1
(cherry picked from commit 61b37a0a20)
2022-07-16 22:28:13 +00:00
Phillip Cloud
02ddda06c7 linuxKernels.kernels.linux_xanmod: 5.15.40 -> 5.15.43
(cherry picked from commit 3fd61ac55e)
2022-07-16 22:28:13 +00:00
Mauricio Collares
90929245c7 python3Packages.jupyterlab_server: create temp home for tests
(cherry picked from commit cd414d016b)
2022-07-17 00:24:40 +02:00
Stig Palmquist
6308561c52 perlPackages.HTTPDaemon: Patch for CVE-2022-3108
Adds 3 patches from upstream:

- 331d5c1d1f
- e84475de51
- 8dc5269d59

(cherry picked from commit b47afc347d)
2022-07-16 21:45:05 +00:00
Stig Palmquist
3edf750956 perlPackages.HTTPDaemon: 6.01 -> 6.14
(cherry picked from commit c1fe33bc63)
2022-07-16 21:45:05 +00:00
github-actions[bot]
d04cc00824 [Backport release-22.05] jack-autoconnect: init at unstable-2021-02-01 (#181763)
* jack-autoconnect: init at unstable-2021-02-01

Applied `nixfmt` against the added module.

(cherry picked from commit 9087bbde376dced533f02d4b7c925bf931d750dc)

* Update pkgs/applications/audio/jack-autoconnect/default.nix

(cherry picked from commit a211a787b0e241b1687fb92eb6ee413ed13cb28b)

Co-authored-by: Viacheslav Lotsmanov <lotsmanov89@gmail.com>
Co-authored-by: Winter <winter@winter.cafe>
2022-07-16 17:27:46 -04:00
Robert Scott
9e94c6ed47 wolfssl: add patches for CVE-2022-34293 & encrypted memory improvements
these are the actionable security issues announced with 5.4.0
2022-07-16 21:58:52 +01:00
Maximilian Bosch
aeb21e4ec9 Merge pull request #181732 from NixOS/backport-181718-to-release-22.05
[Backport release-22.05] Kernel updates - week of 2022-07-16
2022-07-16 19:08:14 +02:00
Ben Wolsieffer
9eb9a9904c python3Packages.setuptools: add distutils patch to support cross-compilation
This is mostly the same patch applied to stdlib distutils, except rebased
and reworked a bit. This fixes cross-compilation of Python packages with
C extension modules now that setuptools uses bundled distutils.

(cherry picked from commit 2294dace6a)
2022-07-16 14:13:01 +00:00
K900
bdceae6a31 linux-rt_5_10: 5.10.120-rt70 -> 5.10.131-rt72
(cherry picked from commit 191beef260)
2022-07-16 14:00:15 +00:00
K900
30d7e878fa linux: 5.4.205 -> 5.4.206
(cherry picked from commit 00ec9cf112)
2022-07-16 14:00:15 +00:00
K900
f1d2b9f460 linux: 5.18.11 -> 5.18.12
(cherry picked from commit 70ce5e51c7)
2022-07-16 14:00:15 +00:00
K900
9bc7d713de linux: 5.15.54 -> 5.15.55
(cherry picked from commit aa6f361841)
2022-07-16 14:00:15 +00:00
K900
ee1dc7e232 linux: 5.10.130 -> 5.10.131
(cherry picked from commit d6f057760a)
2022-07-16 14:00:15 +00:00
Kerstin Humm
c4ab2eacea imagemagick: 7.1.0-39 -> 7.1.0.43
(cherry picked from commit 3a4ea08942)
2022-07-16 13:55:39 +00:00
K900
9734ad6101 linux: enable MODULE_ALLOW_BTF_MISMATCH
Right now it looks like the BTFs are not reproducible between different builds
of the same kernel, and the kernel will refuse to load modules if the BTF
doesn't match. This can cause some interesting side effects when Nix
uses different substituters for different parts of the kernel.

This is far from ideal, and we _really_ should figure out how to actually
make the BTF building consistently reproducible, but that seems more
complicated, so maybe we should do this to get affected systems booting.

See also: https://lore.kernel.org/bpf/YfK18x%2FXrYL4Vw8o@syu-laptop/ ,
where the openSUSE people ran into similar issues.

(cherry picked from commit 4e02bb4922)
2022-07-16 13:31:03 +00:00
Bjørn Forsman
f70d741c7f nixos/tests/jenkins: improve jenkins-job-builder subtest
Rely on services.jenkins-job-builder to reload the configuration instead
of doing that manually in the test.

(If this had been implemented already, it would have caught the bug
fixed by the parent commit, that services.jenkins-job-builder failed to
reload jenkins config from disk.)

(cherry picked from commit 67800cde8fc778d231ef063d11f1a1e3e9b3fbfb)
2022-07-16 15:22:26 +02:00
Bjørn Forsman
84f7c860c7 nixos/jenkins-job-builder: fix jenkins authentication
The current authentication code is broken against newer jenkins:

  jenkins-job-builder-start[1257]: Asking Jenkins to reload config
  jenkins-start[789]: 2022-07-12 14:34:31.148+0000 [id=17]        WARNING hudson.security.csrf.CrumbFilter#doFilter: Found invalid crumb 31e96e52938b51f099a61df9505a4427cb9dca7e35192216755659032a4151df. If you are calling this URL with a script, please use the API Token instead. More information: https://www.jenkins.io/redirect/crumb-cannot-be-used-for-script
  jenkins-start[789]: 2022-07-12 14:34:31.160+0000 [id=17]        WARNING hudson.security.csrf.CrumbFilter#doFilter: No valid crumb was included in request for /reload by admin. Returning 403.
  jenkins-job-builder-start[1357]: curl: (22) The requested URL returned error: 403

Fix it by using `jenkins-cli` instead of messing with `curl`.

This rewrite also prevents leaking the password in process listings. (We
could probably do it without `replace-secret`, assuming `printf` is a
shell built-in, but this implementation should be safe even with shells
not having a built-in `printf`.)

Ref https://github.com/NixOS/nixpkgs/issues/156400.

(cherry picked from commit 7a01213aa78b6de475de0b3a00d0ae71279816e6)
2022-07-16 15:22:26 +02:00
Nicolas Benes
8c81147af4 tor-browser-bundle-bin: 11.0.15 -> 11.5
(cherry picked from commit f3da5ec1ada2dbc98b85dd289375606b12eea393)
2022-07-16 15:20:09 +02:00
Pavol Rusnak
ee41d3117f electron: fix headers location
see https://www.electronjs.org/blog/s3-bucket-change for more info

(cherry picked from commit d2184ac868)
2022-07-16 15:03:45 +02:00
Maximilian Bosch
d7c7f26538 electron: don't update default version on 22.05 2022-07-16 15:02:59 +02:00
M. A
2a757d1d84 nixos/gitlab: Bump git to 2.35.4
Resolves CVE-2022-29187

(cherry picked from commit 61e3490c1c)
2022-07-16 14:59:13 +02:00
Artturi
07a2e6a4e3 Merge pull request #181687 from NixOS/backport-181429-to-release-22.05
[Backport release-22.05] universal-ctags: 5.9.20220529.0 -> 5.9.20220710.0
2022-07-16 14:55:22 +03:00
Maximilian Bosch
ff5b119ee0 Merge pull request #181697 from NixOS/backport-181640-to-release-22.05
[Backport release-22.05] Linux kernel updates 2022-07-15
2022-07-16 09:46:45 +02:00
Maximilian Bosch
1b250e0b8a linux/hardened/patches/5.4: 5.4.203-hardened1 -> 5.4.205-hardened1
(cherry picked from commit b78bde7fc3)
2022-07-16 06:59:03 +00:00
Maximilian Bosch
4b789d87e6 linux/hardened/patches/5.18: 5.18.8-hardened1 -> 5.18.11-hardened1
(cherry picked from commit 5b934a0f91)
2022-07-16 06:59:02 +00:00
Maximilian Bosch
36aaa15479 linux/hardened/patches/5.15: 5.15.52-hardened1 -> 5.15.54-hardened1
(cherry picked from commit 79cc0324b3)
2022-07-16 06:59:02 +00:00
Maximilian Bosch
f0f078a524 linux/hardened/patches/5.10: 5.10.128-hardened1 -> 5.10.130-hardened1
(cherry picked from commit 56fa7c6a9c)
2022-07-16 06:59:02 +00:00
Maximilian Bosch
6410018f63 linux/hardened/patches/4.19: 4.19.250-hardened1 -> 4.19.252-hardened1
(cherry picked from commit ab4a2a7a47)
2022-07-16 06:59:02 +00:00
Maximilian Bosch
aee3a7f227 linux/hardened/patches/4.14: 4.14.286-hardened1 -> 4.14.288-hardened1
(cherry picked from commit 542ea83d58)
2022-07-16 06:59:02 +00:00
Maximilian Bosch
3dd24b6fa6 linux_latest-libre: 18798 -> 18825
(cherry picked from commit f544b56c74)
2022-07-16 06:59:02 +00:00
Maximilian Bosch
23d1558232 linux: 5.4.204 -> 5.4.205
(cherry picked from commit e21d1188e0)
2022-07-16 06:59:02 +00:00
Maximilian Bosch
b001efc85c linux: 5.18.10 -> 5.18.11
(cherry picked from commit d9ffcdf0d6)
2022-07-16 06:59:02 +00:00
Maximilian Bosch
6fb2a58c38 linux: 5.15.53 -> 5.15.54
(cherry picked from commit 4806df0be2)
2022-07-16 06:59:02 +00:00
Maximilian Bosch
04c0545865 linux: 5.10.129 -> 5.10.130
(cherry picked from commit 027ae2cc48)
2022-07-16 06:59:02 +00:00
Maximilian Bosch
595ca1eeab linux: 4.9.322 -> 4.9.323
(cherry picked from commit 1a21d7ebe2)
2022-07-16 06:59:02 +00:00
Maximilian Bosch
6f231b343e linux: 4.19.251 -> 4.19.252
(cherry picked from commit a97667c44b)
2022-07-16 06:59:02 +00:00
Maximilian Bosch
4cad32ba3d linux: 4.14.287 -> 4.14.288
(cherry picked from commit 556fc7f473)
2022-07-16 06:59:02 +00:00
Maximilian Bosch
f1126f1827 element-desktop: use electron_19 2022-07-16 08:49:52 +02:00
Pavol Rusnak
959a9893d9 electron_19: init at 19.0.7
(cherry picked from commit 715b7691f2)
2022-07-16 07:50:08 +02:00
Maximilian Bosch
3a67858a53 Merge pull request #181643 from NixOS/backport-181320-to-release-22.05
[Backport release-22.05] tig: 2.5.5 -> 2.5.6
2022-07-16 07:29:05 +02:00
Maximilian Bosch
af6b143fca Merge pull request #181591 from whentze/grafana-8.5.9
[22.05] grafana: 8.5.6 -> 8.5.9
2022-07-16 07:28:48 +02:00
Winter
fc9508122e Merge pull request #181671 from NixOS/backport-179990-to-release-22.05
[Backport release-22.05] renpy: init at 8.0.0
2022-07-16 01:12:20 -04:00
Brian Leung
a3fbbedd5b universal-ctags: 5.9.20220529.0 -> 5.9.20220710.0
(cherry picked from commit 449f7bc6af)
2022-07-16 04:13:07 +00:00
Otavio Salvador
651665ae68 shellhub-agent: 0.9.2 -> 0.9.3
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit dbd58ee84f)
2022-07-16 03:05:06 +00:00
夜坂雅
d0b939e6ec pygame_sdl2: Sync version with Ren'Py version
(cherry picked from commit 551cd8fa3d)
2022-07-16 02:11:05 +00:00
夜坂雅
f71824d149 renpy: init at 8.0.0
(cherry picked from commit b151a79d10)
2022-07-16 02:11:05 +00:00
夜坂雅
ca4a9e8234 maintainers: add shadowrz
(cherry picked from commit 7de963e9a3)
2022-07-16 02:11:05 +00:00
github-actions[bot]
afd506c219 Merge staging-next-22.05 into staging-22.05 2022-07-16 00:16:11 +00:00
github-actions[bot]
29a912dc13 Merge release-22.05 into staging-next-22.05 2022-07-16 00:15:36 +00:00
Martin Weinelt
7f1fcb618f Merge pull request #181655 from NixOS/backport-181645-to-release-22.05 2022-07-16 01:06:24 +02:00
Ilan Joselevich
386fef8bb6 mpd: 0.23.7 -> 0.23.8
(cherry picked from commit d7af7b160a)
2022-07-15 22:56:58 +00:00
schnusch
cb834ca718 remote-touchpad: 1.2.0 -> 1.2.1
(cherry picked from commit a3eca010b0)
2022-07-16 00:07:39 +02:00
Maximilian Bosch
7cb6e3cc3a Merge pull request #181641 from NixOS/backport-181283-to-release-22.05
[Backport release-22.05] gitea: 1.16.8 -> 1.16.9
2022-07-16 00:07:12 +02:00
Maximilian Bosch
156bcd44f3 element-{web,desktop}: 1.10.15 -> 1.11.0
ChangeLog desktop: https://github.com/vector-im/element-desktop/releases/tag/v1.11.0
ChangeLog web: https://github.com/vector-im/element-web/releases/tag/v1.11.0

Backport of #180273
2022-07-16 00:04:12 +02:00
Matthias Beyer
0c27175795 tig: 2.5.5 -> 2.5.6
Signed-off-by: Matthias Beyer <mail@beyermatthias.de>
(cherry picked from commit faa5c30d5a15b548231b44a225b05513a433a674)
2022-07-15 21:42:52 +00:00
kilianar
eea6c10a67 gitea: 1.16.8 -> 1.16.9
(cherry picked from commit f8d9ca3703)
2022-07-15 21:39:58 +00:00
Winter
ccb91069ab Merge pull request #181617 from NixOS/backport-181306-to-release-22.05
[Backport release-22.05] caddy: 2.5.1 -> 2.5.2
2022-07-15 15:15:40 -04:00
techknowlogick
4d76573b75 caddy: 2.5.1 -> 2.5.2
(cherry picked from commit 10646f5e07)
2022-07-15 17:17:28 +00:00
Daniel Olsen
45f3616ea4 hydrus: 490 -> 491
(cherry picked from commit cec2f72095)
2022-07-15 16:48:20 +00:00
Daniel Olsen
729f05fb1f hydrus: 489 -> 490
(cherry picked from commit 250157ab54)
2022-07-15 16:48:20 +00:00
Daniel Olsen
0c06b48a39 hydrus: unpin python version
(cherry picked from commit 76562ec8d9)
2022-07-15 16:48:20 +00:00
Daniel Olsen
bb9abb0e20 hydrus: 488d -> 489
(cherry picked from commit eab2d27e22)
2022-07-15 16:48:20 +00:00
Wanja Hentze
84c51c23ea grafana: 8.5.6 -> 8.5.9
Announcement and security advisory: https://grafana.com/blog/2022/07/14/grafana-v9-0-3-8-5-9-8-4-10-and-8-3-10-released-with-high-severity-security-fix/
2022-07-15 12:13:10 +02:00
R. Ryantm
549d82bdd4 jenkins: 2.346.1 -> 2.346.2
(cherry picked from commit dc9211b4ead1a894d6e2a27c900931bc3e503bac)
2022-07-15 11:17:08 +02:00
github-actions[bot]
a996eb7bcf Merge staging-next-22.05 into staging-22.05 2022-07-15 00:17:07 +00:00
github-actions[bot]
451165e369 Merge release-22.05 into staging-next-22.05 2022-07-15 00:16:30 +00:00
Martin Weinelt
c06d5fa9c6 Merge pull request #181468 from NixOS/backport-181312-to-release-22.05 2022-07-14 18:12:15 +02:00
Jörg Thalheim
af54b6145c Merge pull request #181447 from NixOS/backport-181438-to-release-22.05
[Backport release-22.05] signal-desktop: 5.49.0 -> 5.50.0
2022-07-14 15:19:28 +02:00
Thiago Kenji Okada
6688df296a Merge pull request #181285 from NixOS/backport-181215-to-release-22.05
[Backport release-22.05] zen-kernels: linux_zen, linux_lqx: 5.18.10 -> 5.18.11
2022-07-14 14:09:05 +01:00
R. Ryantm
e4423a304b firefox-esr-102-unwrapped: 102.0esr -> 102.0.1esr
(cherry picked from commit 0b91cc0961)
2022-07-14 11:38:50 +00:00
kilianar
27a74be826 signal-desktop: 5.49.0 -> 5.50.0
(cherry picked from commit 28010c8de4)
2022-07-14 07:41:56 +00:00
github-actions[bot]
d705901920 Merge staging-next-22.05 into staging-22.05 2022-07-14 00:17:05 +00:00
github-actions[bot]
de3673d999 Merge release-22.05 into staging-next-22.05 2022-07-14 00:16:13 +00:00
Domen Kožar
8fa57a6538 Merge pull request #181378 from domenkozar/cachix-agent-22.05-backports
[22.05] Cachix backports
2022-07-13 14:47:26 -05:00
Domen Kožar
e97b836f99 cachix-agent: allow restarts now that deployments are subprocesses
(cherry picked from commit c46a3dc50a)
2022-07-13 12:34:19 -05:00
Domen Kožar
627eebdb87 cachix: 0.7.0 -> 0.8.0 2022-07-13 12:33:09 -05:00
Sean Buckley
1c66a6ea70 vmware-horizon-client: use legacy UI
(cherry picked from commit 3e5fba739b)
2022-07-13 16:18:34 +00:00
Vladimír Čunát
365e1b3a85 Merge #180752: staging-next-22.05 - iteration 4 2022-07-13 08:30:03 +02:00
R. Ryantm
be3e39a6ce python310Packages.pip-tools: 6.6.1 -> 6.6.2
(cherry picked from commit 0cfd23c34e)
It's needed after the pip update:
https://github.com/jazzband/pip-tools/releases/tag/6.6.2
2022-07-13 08:29:11 +02:00
Fabian Affolter
9b55b79aba python3Packages.tweepy: add missing input
(cherry picked from commit 86138531bc)
Now it wouldn't build otherwise.
2022-07-13 08:11:05 +02:00
Bobby Rong
15968d3de8 Merge pull request #181249 from NixOS/backport-181179-to-release-22.05
[Backport release-22.05] pantheon.wingpanel-indicator-notifications: 6.0.5 -> 6.0.6
2022-07-13 10:24:07 +08:00
github-actions[bot]
c8b99ea226 Merge staging-next-22.05 into staging-22.05 2022-07-13 00:17:35 +00:00
github-actions[bot]
57d7519c5b Merge release-22.05 into staging-next-22.05 2022-07-13 00:16:57 +00:00
Winter
c944d18cbd Merge pull request #179463 from NixOS/backport-166340-to-release-22.05
[Backport release-22.05] nixos/ipfs: Only set ReadWritePaths when hardened
2022-07-12 19:01:31 -04:00
PedroHLC ☭
c582a15e83 zen-kernels: add pedrohlc as maintainer
(cherry picked from commit c2fa5569a0)
2022-07-12 22:05:04 +00:00
PedroHLC ☭
e5405c75f2 linux_lqx: 5.18.10-lqx1 -> 5.18.11-lqx1
(cherry picked from commit c1f94c40df)
2022-07-12 22:05:04 +00:00
PedroHLC ☭
96c1e3ce47 linux_zen: 5.18.10-zen1 -> 5.18.11-zen1
(cherry picked from commit 2c994cf1c7)
2022-07-12 22:05:04 +00:00
Bjørn Forsman
46178c610b nixos/ddclient: don't leak password in process listings
...by using `replace-secret` instead of `sed` when injecting the
password into the ddclient config file. (Verified with `execsnoop`.)

Ref https://github.com/NixOS/nixpkgs/issues/156400.

(cherry picked from commit e0f2f7f9ea)
2022-07-12 23:38:39 +02:00
Elis Hirwing
4aceab3cad Merge pull request #180862 from helsinki-systems/upd/php2205
[22.05] php8*: 8.0.20 -> 8.0.21, 8.1.7 -> 8.1.8
2022-07-12 21:39:31 +02:00
github-actions[bot]
b4f4f87b7e gitlab: 15.1.1 -> 15.1.2 (#180799)
https://about.gitlab.com/releases/2022/07/04/gitlab-15-1-2-released/
(cherry picked from commit 7d50755b21b5e1ad8740a02ce138874ed8f88bf7)

Co-authored-by: M. A <mak@nyantec.com>
2022-07-12 21:00:53 +02:00
Artturi
5f4323a9ee Merge pull request #181240 from NixOS/backport-180253-to-release-22.05
[Backport release-22.05] fprintd-tod: fix build
2022-07-12 19:55:50 +03:00
Bobby Rong
28e3682caf pantheon.wingpanel-indicator-notifications: 6.0.5 -> 6.0.6
(cherry picked from commit 3003cd353a)
2022-07-12 16:51:05 +00:00
Henri Menke
f402c6f7b2 fprintd-tod: fix build
(cherry picked from commit f4710680af)
2022-07-12 14:39:12 +00:00
R. Ryantm
a081c9e90e aws-iam-authenticator: 0.5.7 -> 0.5.9
(cherry picked from commit 47955687cc)
2022-07-12 12:24:37 +00:00
adisbladis
b8720c8492 Merge pull request #180866 from NixOS/backport-180843-to-release-22.05
[Backport release-22.05] poetry2nix: 1.30.0 -> 1.31.0
2022-07-12 19:44:20 +08:00
Linus Heckemann
302de15ce7 Merge pull request #181125 from whentze/bump-pcre2
[22.05] pcre2: 10.39 -> 10.40
2022-07-12 09:22:43 +02:00
Aaron Andersen
60e774ff2c Merge pull request #181172 from NixOS/backport-180014-to-release-22.05
[Backport release-22.05] kodi.packages.invidious: init at 0.1.0+matrix.1
2022-07-12 02:54:31 +02:00
Aaron Andersen
13e224687c kodi.packages.invidious: init at 0.1.0+matrix.1
(cherry picked from commit 01bbab739b)
2022-07-12 00:37:43 +00:00
github-actions[bot]
8051a692d6 Merge staging-next-22.05 into staging-22.05 2022-07-12 00:14:59 +00:00
github-actions[bot]
039117feec Merge release-22.05 into staging-next-22.05 2022-07-12 00:14:20 +00:00
Robert Scott
fc151a26a9 Merge pull request #181138 from NixOS/backport-180083-to-staging-22.05
[Backport staging-22.05] hdf5: 1.12.1 -> 1.12.2
2022-07-11 23:16:27 +01:00
Robert Scott
f204a18d7b Merge pull request #181137 from NixOS/backport-180085-to-release-22.05
[Backport release-22.05] hdf5_1_10: 1.10.6 -> 1.10.9
2022-07-11 22:11:32 +01:00
Minijackson
a8c50d44b6 waybar: 0.9.12 -> 0.9.13
added upower support, enabled by default

(cherry picked from commit ffe324d8bd)
2022-07-11 17:53:19 +00:00
Rick van Schijndel
c18625a02a Merge pull request #181006 from NixOS/backport-180924-to-release-22.05
[Backport release-22.05] untrunc-anthwlock: fix build on darwin and ensure optimized builds
2022-07-11 19:21:55 +02:00
Jiajie Chen
08e2dff6b0 hdf5: 1.12.1 -> 1.12.2
The bin-mv.patch is applied upstream.

(cherry picked from commit 8a84ef7972)
2022-07-11 17:09:17 +00:00
Jiajie Chen
563e7d183d hdf5_1_10: 1.10.6 -> 1.10.9
pythonPackages.tables is updated, the version pin is removed.

The bin-mv.patch is applied upstream.

(cherry picked from commit b3aee32add)
2022-07-11 17:04:40 +00:00
Vladimír Čunát
965d2156a8 Merge branch 'release-22.05' into staging-22.05 2022-07-11 18:20:20 +02:00
Wanja Hentze
7efc2530d0 pcre2: 10.39 -> 10.40
backporting from unstable because it fixes the following criticial CVEs:
https://nvd.nist.gov/vuln/detail/CVE-2022-1586
https://nvd.nist.gov/vuln/detail/CVE-2022-1587
2022-07-11 17:29:07 +02:00
K900
ca337cf2e7 Merge pull request #180744 from whentze/bump-vim
[22.05] vim: 8.2.4816 -> 8.2.5172
2022-07-11 16:33:31 +03:00
Martin Weinelt
06ad005bf1 python3Packages.homeconnect: propagate six
(cherry picked from commit e5b1832b36)
2022-07-11 10:59:21 +02:00
Martin Weinelt
32f37befb7 python3Packages.globus-sdk: fix tests
(cherry picked from commit a4b86d4e75)
2022-07-11 10:59:05 +02:00
Martin Weinelt
f981c44e29 python3Packages.flickrapi: propagate six
(cherry picked from commit b6f6f1f7d5)
2022-07-11 10:58:16 +02:00
github-actions[bot]
4ef226f573 Merge staging-next-22.05 into staging-22.05 2022-07-11 00:14:16 +00:00
github-actions[bot]
c6c427f341 Merge release-22.05 into staging-next-22.05 2022-07-11 00:13:45 +00:00
Mario Rodas
1b69bbdd35 Merge pull request #181007 from NixOS/backport-180922-to-release-22.05
[Backport release-22.05] dotenv-linter: fix build on darwin
2022-07-10 18:53:49 -05:00
Guillaume Girol
5b7ef5b51e Merge pull request #180880 from NixOS/backport-178266-to-release-22.05
[Backport release-22.05] powerdns-admin: 0.2.4 -> 0.3.0
2022-07-10 20:02:24 +00:00
Sebastián Mancilla
b0ddef229a dotenv-linter: fix build on darwin
Add missing Security framework as input.

(cherry picked from commit bc776c4d36)
2022-07-10 18:13:27 +00:00
Sebastián Mancilla
da92159e33 untrunc-anthwlock: refactor build
Use buildPhase to make clear that we need two invocations of 'make' with
different targets.

Also set IS_RELEASE to 1 to ensure an optimized build is created instead
of a debug build (see Makefile).

(cherry picked from commit 3239a05357)
2022-07-10 18:10:49 +00:00
Sebastián Mancilla
a132219e18 untrunc-anthwlock: mark as unbroken on darwin
Fixed by c39770ecc5 (libui: fix typo when installing libs on darwin,
2022-07-09).

(cherry picked from commit cf88ead89d)
2022-07-10 18:10:49 +00:00
Sebastián Mancilla
636862dd5c libui: fix typo when installing libs on darwin
(cherry picked from commit c39770ecc5)
2022-07-10 18:10:49 +00:00
Maximilian Bosch
cf034a867e Merge pull request #180998 from NixOS/backport-180580-to-release-22.05
[Backport release-22.05] roundcube: 1.5.2 -> 1.5.3
2022-07-10 20:00:24 +02:00
Maximilian Bosch
55ce662d5d Merge pull request #180282 from NixOS/backport-180265-to-release-22.05
[Backport release-22.05] privacyidea: 3.7.1 -> 3.7.2
2022-07-10 20:00:08 +02:00
Rick van Schijndel
a21362dd5e Merge pull request #180981 from NixOS/backport-180925-to-release-22.05
[Backport release-22.05] coan: fix build on darwin
2022-07-10 19:30:39 +02:00
Rick van Schijndel
6594fb14de Merge pull request #180982 from NixOS/backport-180928-to-release-22.05
[Backport release-22.05] boofuzz: fix build on darwin
2022-07-10 19:30:01 +02:00
Maximilian Bosch
35a2f6b731 roundcube: 1.5.2 -> 1.5.3
ChangeLog: https://github.com/roundcube/roundcubemail/releases/tag/1.5.3
(cherry picked from commit b1cb8f33f7)
2022-07-10 16:56:28 +00:00
Bobby Rong
3d35b30882 Merge pull request #180553 from NixOS/backport-151005-to-release-22.05
[Backport release-22.05] nixos/gnome: make it possible to remove core packages
2022-07-10 23:47:48 +08:00
Sebastián Mancilla
a44ff9f0f7 boofuzz: fix build on darwin
Disable tests that need network access.

(cherry picked from commit ed2b320176)
2022-07-10 11:54:05 +00:00
Sebastián Mancilla
4cddfa32f8 coan: fix build on darwin
The configure script was failing because the `-std=c++11` flag was used
when trying to compile C.

Set the flag with CXXFLAGS instead.

(cherry picked from commit f170b3aebc)
2022-07-10 11:51:32 +00:00
Martin Weinelt
22ea849b5f Merge pull request #180956 from NixOS/backport-180842-to-release-22.05 2022-07-10 13:02:01 +02:00
Michael Weiss
3e385d0f5b Merge pull request #180961 from NixOS/backport-180901-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 103.0.5060.53 -> 103.0.5060.114
2022-07-10 12:33:41 +02:00
Michael Weiss
b7b2f56f93 ungoogled-chromium: 103.0.5060.53 -> 103.0.5060.114
(cherry picked from commit 70896ec871)
2022-07-10 10:16:42 +00:00
Michael Weiss
a8b2826ab8 Merge pull request #180902 from NixOS/backport-180897-to-release-22.05
[Backport release-22.05] chromium: 103.0.5060.53 -> 103.0.5060.114
2022-07-10 12:08:19 +02:00
Martin Weinelt
3b7df45b3c python3Packages.cmd2: don't require vim for tests
It causes a huge rebuild chain when updating vim, that affects, among
others qemu and ceph.

(cherry picked from commit b3dfc58a53dbe0352305b450c0ac2e2c1aa7e4a1)
2022-07-10 10:06:56 +00:00
github-actions[bot]
78a2a6ae19 bun: init at 0.1.1
(cherry picked from commit 63a859c835)
2022-07-10 16:34:52 +08:00
github-actions[bot]
0132f9486b Merge staging-next-22.05 into staging-22.05 2022-07-10 00:17:24 +00:00
github-actions[bot]
41986df330 Merge release-22.05 into staging-next-22.05 2022-07-10 00:16:45 +00:00
Michael Weiss
c92d78b333 chromium: 103.0.5060.53 -> 103.0.5060.114
https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop.html

This update includes 4 security fixes. Google is aware that an exploit
for CVE-2022-2294 exists in the wild.

CVEs:
CVE-2022-2294 CVE-2022-2295 CVE-2022-2296

Note: This update was delayed due to crbug.com/1341418.
(cherry picked from commit 5039fc4ec0)
2022-07-09 22:43:26 +00:00
Robert Scott
0ad6eae049 Merge pull request #180729 from whentze/feature/patch-dpkg
[22.05] dpkg: 1.20.9ubuntu2 -> 1.20.9ubuntu2.2
2022-07-09 21:48:35 +01:00
Robert Scott
7399dda8da Merge pull request #180291 from mweinelt/22.05/libdwarf
[22.05] libdwarf: mark known vulnerable
2022-07-09 20:05:15 +01:00
Artturi
f8ce7caf17 Merge pull request #180850 from NixOS/backport-180778-to-release-22.05
[Backport release-22.05] logrotate: fix config check without sandbox
2022-07-09 21:16:07 +03:00
Thiago Kenji Okada
72b83a8932 Merge pull request #180847 from NixOS/backport-180773-to-release-22.05
[Backport release-22.05] zen-kernels: linux_lqx, linux_zen: 5.18.9 -> 5.18.10
2022-07-09 18:52:16 +01:00
Flakebi
519e689d1b powerdns-admin: 0.2.4 -> 0.3.0
(cherry picked from commit abbdfc25d1)
2022-07-09 17:37:13 +00:00
adisbladis
52c739c4a2 poetry2nix: 1.30.0 -> 1.31.0
(cherry picked from commit 076be10524)
2022-07-09 15:25:30 +00:00
ajs124
f6013ca4c6 php81: 8.1.7 -> 8.1.8
Fixes CVE-2022-31627

https://www.php.net/ChangeLog-8.php#8.1.8
(cherry picked from commit e416f8806d)
2022-07-09 16:35:31 +02:00
ajs124
daa96baea2 php80: 8.0.20 -> 8.0.21
https://www.php.net/ChangeLog-8.php#8.0.21
(cherry picked from commit b429bc2508)
2022-07-09 16:35:31 +02:00
ajs124
c0cc8bd7d5 php: sha256 -> hash
(cherry picked from commit 3020f0014c)
2022-07-09 16:35:28 +02:00
Martin Weinelt
22f774e61f home-assistant: relax PyJWT constraint 2022-07-09 16:07:47 +02:00
Bobby Rong
873bb402ba Merge pull request #180707 from NixOS/backport-180610-to-release-22.05
[Backport release-22.05] signal-desktop: 5.48.0 -> 5.49.0
2022-07-09 07:53:59 -06:00
Dominique Martinet
17147f553b logrotate: fix config check without sandbox
make logrotate not try to write to /var/lib/logrotate.status by
using an alternate path.

Also avoid /tmp and use build CWD

Fixes #180734

(cherry picked from commit fd701a9cd1)
2022-07-09 12:26:48 +00:00
PedroHLC ☭
e40f9c0260 zen-kernels: linux_lqx, linux_zen: 5.18.9 -> 5.18.10
(cherry picked from commit 541dc61858)
2022-07-09 11:54:43 +00:00
Robert Scott
febe67fb0f Merge pull request #180795 from NixOS/backport-180526-to-release-22.05
[Backport release-22.05] pdnsd: fix build
2022-07-09 12:39:28 +01:00
maxine [they]
e23d19890c Merge pull request #180830 from NixOS/backport-180804-to-release-22.05 2022-07-09 11:37:04 +02:00
R. Ryantm
53b048a653 epiphany: 42.2 -> 42.3
(cherry picked from commit fa6cc5d952f33befbd8727de8ff1e10c83cbda34)
2022-07-09 09:25:53 +00:00
Doron Behar
25980c1b91 Merge pull request #180738 from NixOS/backport-178587-to-release-22.05 2022-07-09 12:25:42 +03:00
Elis Hirwing
8c6a480d4d Merge pull request #180739 from whentze/bump-php
[22.05] php: 7.4.29 -> 7.4.30, 8.0.19 -> 8.0.20, 8.1.6 -> 8.1.7
2022-07-09 09:00:15 +02:00
R. Ryantm
d9af12f1e9 elmPackages.nodejs: 14.19.3 -> 14.20.0
(cherry picked from commit f62dd75433)
2022-07-09 05:37:53 +00:00
Rick van Schijndel
2603253f1b Merge pull request #180743 from NixOS/backport-180605-to-release-22.05
[Backport release-22.05] starlark: Patch tests to unbreak on aarch64
2022-07-09 03:04:55 +02:00
maxine [they]
6bfc6d7b07 Merge pull request #180723 from NixOS/backport-180623-to-release-22.05
[Backport release-22.05] gnome.gnome-bluetooth: 42.1 -> 42.2
2022-07-09 02:37:22 +02:00
maxine [they]
31c5b967d1 Merge pull request #180618 from NixOS/backport-180490-to-release-22.05
[Backport release-22.05] xdg-desktop-portal-gnome: 42.1 -> 42.3
2022-07-09 02:36:59 +02:00
github-actions[bot]
5187173be2 Merge staging-next-22.05 into staging-22.05 2022-07-09 00:13:37 +00:00
github-actions[bot]
18acf48bf9 Merge release-22.05 into staging-next-22.05 2022-07-09 00:13:00 +00:00
ajs124
0d998debdd pdnsd: fix build
(cherry picked from commit d61e62804a)
2022-07-08 23:44:39 +00:00
Maximilian Bosch
2708fb3afb Merge pull request #180769 from NixOS/backport-180584-to-release-22.05
[Backport release-22.05] Linux kernel updates 2022-07-07
2022-07-08 23:55:13 +02:00
Maximilian Bosch
2b5f596225 linux/hardened/patches/5.4: 5.4.202-hardened1 -> 5.4.203-hardened1
(cherry picked from commit cc7d3f9228)
2022-07-08 21:00:15 +00:00
Maximilian Bosch
45139b5aa2 linux/hardened/patches/5.15: 5.15.51-hardened1 -> 5.15.52-hardened1
(cherry picked from commit 287f104a15)
2022-07-08 21:00:15 +00:00
Maximilian Bosch
2e56cb472e linux/hardened/patches/5.10: 5.10.127-hardened1 -> 5.10.128-hardened1
(cherry picked from commit b01bc117d4)
2022-07-08 21:00:15 +00:00
Maximilian Bosch
1aaf21b83f linux/hardened/patches/4.19: 4.19.249-hardened1 -> 4.19.250-hardened1
(cherry picked from commit b4fb4a07cf)
2022-07-08 21:00:15 +00:00
Maximilian Bosch
e88598c205 linux/hardened/patches/4.14: 4.14.285-hardened1 -> 4.14.286-hardened1
(cherry picked from commit 50815fdf17)
2022-07-08 21:00:15 +00:00
Maximilian Bosch
415a0c21b6 linux: 5.4.203 -> 5.4.204
(cherry picked from commit 4a5a4a0ff2)
2022-07-08 21:00:15 +00:00
Maximilian Bosch
24cb8b34b0 linux: 5.18.9 -> 5.18.10
(cherry picked from commit 525e5cd3b3)
2022-07-08 21:00:15 +00:00
Maximilian Bosch
6a6ec0dcfe linux: 5.15.52 -> 5.15.53
(cherry picked from commit 7361080635)
2022-07-08 21:00:15 +00:00
Maximilian Bosch
b733a131a6 linux: 5.10.128 -> 5.10.129
(cherry picked from commit 8e9ad03cbf)
2022-07-08 21:00:14 +00:00
Maximilian Bosch
4b68980d09 linux: 4.9.321 -> 4.9.322
(cherry picked from commit eb59a193b9)
2022-07-08 21:00:14 +00:00
Maximilian Bosch
bfadccc950 linux: 4.19.250 -> 4.19.251
(cherry picked from commit 83b4ead7e1)
2022-07-08 21:00:14 +00:00
Maximilian Bosch
7d78a0da3a linux: 4.14.286 -> 4.14.287
(cherry picked from commit f0238d6098)
2022-07-08 21:00:14 +00:00
Vladimír Čunát
aac73d5433 Merge branch 'staging-22.05' into staging-next-22.05 2022-07-08 20:22:26 +02:00
Vladimír Čunát
118322574f Merge #176768: opencv4: disable hdf5 for cross-compilation
...into staging-22.05
2022-07-08 20:21:18 +02:00
Wanja Hentze
263f66ee2a vim: 8.2.4816 -> 8.2.5172
Fixes the following CVEs:
https://nvd.nist.gov/vuln/detail/CVE-2022-1927
https://nvd.nist.gov/vuln/detail/CVE-2022-2207
https://nvd.nist.gov/vuln/detail/CVE-2022-2210
https://nvd.nist.gov/vuln/detail/CVE-2022-2175
https://nvd.nist.gov/vuln/detail/CVE-2022-1616
https://nvd.nist.gov/vuln/detail/CVE-2022-1619
https://nvd.nist.gov/vuln/detail/CVE-2022-1621
https://nvd.nist.gov/vuln/detail/CVE-2022-1629
https://nvd.nist.gov/vuln/detail/CVE-2022-1720
https://nvd.nist.gov/vuln/detail/CVE-2022-1733
https://nvd.nist.gov/vuln/detail/CVE-2022-1735
https://nvd.nist.gov/vuln/detail/CVE-2022-1769
https://nvd.nist.gov/vuln/detail/CVE-2022-1785
https://nvd.nist.gov/vuln/detail/CVE-2022-1796
https://nvd.nist.gov/vuln/detail/CVE-2022-1851
https://nvd.nist.gov/vuln/detail/CVE-2022-1886
https://nvd.nist.gov/vuln/detail/CVE-2022-1898
https://nvd.nist.gov/vuln/detail/CVE-2022-1942
https://nvd.nist.gov/vuln/detail/CVE-2022-2124
https://nvd.nist.gov/vuln/detail/CVE-2022-2125
https://nvd.nist.gov/vuln/detail/CVE-2022-2126
https://nvd.nist.gov/vuln/detail/CVE-2022-2129
https://nvd.nist.gov/vuln/detail/CVE-2022-2182
https://nvd.nist.gov/vuln/detail/CVE-2022-2183
https://nvd.nist.gov/vuln/detail/CVE-2022-2206
https://nvd.nist.gov/vuln/detail/CVE-2022-1620
https://nvd.nist.gov/vuln/detail/CVE-2022-1674
https://nvd.nist.gov/vuln/detail/CVE-2022-1771
https://nvd.nist.gov/vuln/detail/CVE-2022-2208

Changes: https://github.com/vim/vim/compare/v8.2.4816...v8.2.5172
2022-07-08 19:34:34 +02:00
Wanja Hentze
e4ac560076 php81: 8.1.6 -> 8.1.7
Fixes https://nvd.nist.gov/vuln/detail/CVE-2022-31625 and https://nvd.nist.gov/vuln/detail/CVE-2022-31626.
Changelog: https://www.php.net/ChangeLog-8.php#8.1.7
2022-07-08 18:33:02 +02:00
Wanja Hentze
ac5ca66a98 php80: 8.0.19 -> 8.0.20
Fixes https://nvd.nist.gov/vuln/detail/CVE-2022-31625 and https://nvd.nist.gov/vuln/detail/CVE-2022-31626.
Changelog: https://www.php.net/ChangeLog-8.php#8.0.20
2022-07-08 18:32:22 +02:00
Wanja Hentze
f8520376f3 php74: 7.4.29 -> 7.4.30
Fixes https://nvd.nist.gov/vuln/detail/CVE-2022-31625 and https://nvd.nist.gov/vuln/detail/CVE-2022-31626.
Changelog: https://www.php.net/ChangeLog-7.php#7.4.30
2022-07-08 18:31:48 +02:00
Berk D. Demir
cdc1441e7b starlark: Patch tests to unbreak on aarch64
Pull in the patch from the submitted pull request to upstream to fix the
unit test data that doesn't tolerate floating point approximation.

- Unbreaks aarch64-linux
- Fixes the build for aarch64-darwin

(cherry picked from commit 699a374e8a)
2022-07-08 16:30:50 +00:00
Yuri A. Martinez Falcão
940cdbde1a zoom.us: 5.10.{4,6} -> 5.11.1
Added pipewire to dependencies for wayland support.
Make update script suitable for multiple systems

(cherry picked from commit 21074029d391634904d2f47c6a33170d214005a6)
2022-07-08 16:06:43 +00:00
Doron Behar
71d7a4c037 Merge pull request #180735 from NixOS/backport-174281-to-release-22.05 2022-07-08 19:00:39 +03:00
Sebastian Reuße
255616ada4 zoom-us: 5.10.4.2845 -> 5.10.6.3192 on x86_64-linux
Fixes #174147

(cherry picked from commit 1b27e162e5)
2022-07-08 15:23:40 +00:00
Vladimír Čunát
4d35bc1b6a Merge #178761: networkmanager: Apply several fixes for OWE
...into staging-22.05
2022-07-08 17:20:36 +02:00
Vladimír Čunát
5a8165ed7d Merge #180399: ffmpeg: 4.4.1 -> 4.4.2 (into staging-22.05) 2022-07-08 17:16:25 +02:00
Vladimír Čunát
4ad5d0fa2c Merge #179805: libopenmpt: 0.6.3 -> 0.6.4
...into staging-22.05
2022-07-08 17:14:32 +02:00
Vladimír Čunát
fc090bb495 Merge #179343: cacert, nss_latest: * -> 3.80
...into staging-22.05
2022-07-08 17:12:20 +02:00
Vladimír Čunát
39d851a3a6 Merge #178766: python310Packages.pip: 22.0.4 -> 22.1.2
...into staging-22.05
2022-07-08 17:10:42 +02:00
Wanja Hentze
a0dd21418a dpkg: 1.20.9ubuntu2 -> 1.20.9ubuntu2.2
Fixes https://nvd.nist.gov/vuln/detail/CVE-2022-1664
See also https://ubuntu.com/security/notices/USN-5446-1

Changelog: https://changelogs.ubuntu.com/changelogs/pool/main/d/dpkg/dpkg_1.20.9ubuntu2.2/changelog
2022-07-08 16:44:17 +02:00
R. Ryantm
f0baa7ce76 gnome.gnome-bluetooth: 42.1 -> 42.2
(cherry picked from commit 09ee324674af3b89c72467894ad2e968ca292c63)
2022-07-08 14:30:47 +00:00
Eduardo Quiros
5edcbe8b0a signal-desktop: 5.48.0 -> 5.49.0
(cherry picked from commit 0fd868d030)
2022-07-08 12:12:34 +00:00
Martin Weinelt
428e122b00 Merge pull request #180695 from NixOS/backport-180690-to-release-22.05 2022-07-08 14:11:56 +02:00
Martin Weinelt
7f76ded560 mpd: 0.23.6 -> 0.23.7
https://musicpd.org/news/2022/05/mpd-0-23-7-released/
(cherry picked from commit cdcc2b1c61)
2022-07-08 11:28:12 +00:00
Stig
d91b582c6c Merge pull request #180339 from stigtsp/backport/gnupg-2.3.6-and-patches
[Backport staging-22.05] gnupg:  2.3.4 -> 2.3.6, patches for CVE-2022-34903 and compressed sigs, gpgme: fix test
2022-07-08 12:23:31 +02:00
Vladimír Čunát
f69b7bbcda python3.pkgs.gpgme: fix a test
This is a python counterpart of commit db6b3e0a5ec77; /cc PR #180336

(cherry picked from commit add0201f35)
2022-07-08 11:54:20 +02:00
Vladimír Čunát
7f46dd7c3c fixup! gpgme: fix a test after disallowing compressed signatures
(cherry picked from commit 1fc760419d)
2022-07-08 11:32:37 +02:00
Vladimír Čunát
c9c9f2a260 gpgme: fix a test after disallowing compressed signatures
/cc PR #180336

I'm not entirely sure about this, as I couldn't spend much time, but
it seemed plausible that the patch caused a different kind of errors
in this tested case - though it's possible I messed the test up.
Either way, the tests seem to pass now, unblocking the CVE fixes ;-)

(cherry picked from commit db6b3e0a5e)
2022-07-08 11:32:37 +02:00
Martin Weinelt
6c53d0359d Merge pull request #180361 from mweinelt/22.05/openssl 2022-07-08 10:14:12 +02:00
Bobby Rong
12a974e4b4 Merge pull request #180579 from NixOS/backport-180568-to-release-22.05
[Backport release-22.05] anime-downloader: fix missing runtime dependencies
2022-07-08 13:32:00 +08:00
Bobby Rong
1d09c1d769 xdg-desktop-portal-gnome: 42.1 → 42.3
https://gitlab.gnome.org/GNOME/xdg-desktop-portal-gnome/-/compare/42.1...42.3
(cherry picked from commit 06189dc2f4)
2022-07-08 04:03:09 +00:00
github-actions[bot]
3f6f45e62c Merge staging-next-22.05 into staging-22.05 2022-07-08 00:16:44 +00:00
github-actions[bot]
bc9bac5851 Merge release-22.05 into staging-next-22.05 2022-07-08 00:16:07 +00:00
Dmitry Kalinkin
6e35c43019 blender: fix on darwin
(cherry picked from commit 007c4341fe)
2022-07-07 18:28:20 -04:00
Maximilian Bosch
e0b3cdac0d Merge pull request #180563 from NixOS/backport-180092-to-release-22.05
[Backport release-22.05] Linux kernel updates 2022-07-04
2022-07-07 23:17:25 +02:00
WeebSorceress
ad4214325c anime-downloader: fix missing runtime dependencies
(cherry picked from commit e3f26208bc)
2022-07-07 20:42:30 +00:00
Domen Kožar
4f115cb0eb Merge pull request #180564 from NixOS/backport-180165-to-release-22.05
[Backport release-22.05] virtualbox: update patch linux-5.18 -> linux-5.19
2022-07-07 14:35:27 -05:00
Yarny0
882ba8a2ab virtualbox: update patch linux-5.18 -> linux-5.19
Some history:

The linux kernel v5.18-rc contains the commit

> commit 6e8ec2552c7d13991148e551e3325a624d73fac6
> Author: Jason A. Donenfeld <Jason@zx2c4.com>
> Date:   2022-01-16 14:23:10 +0100
>
>     random: use computational hash for entropy extraction
> [...]

which modifies the kernels random number generator.

This change broke VirtualBox 6.1.34 in several ways:
It causes random crashes and filesystem corruption in the guest
(at least on some host CPU models).
More details can be found in the
corresponding ticket in the VirtualBox bug tracker:
https://www.virtualbox.org/ticket/20914

That ticket also contains a patch "vbox-linux-5.18.patch"
for VirtualBox that fixes the problem,
at least for kernels 5.18 and (hopefully) above.
This patch got added to nixpkgs' VirtualBox build recipe with
9c8132494f .

Meanwhile, the kernel patch got backported to LTS kernels.
As the VirtualBox patch contains several `#if RTLNX_VER_MIN(5,18,0)`
clauses to apply the fix,
it can't heal VirtualBox on LTS kernel versions.
The result is that VirtualBox is still broken if used
with linux kernels 5.10 and 5.15
(currenly the default kernel in nixpkgs).

Luckily, VirtualBox developers updated the patch
(now named "vbox-linux-5.19.patch") to not only fix the
problem for the upcoming 5.19 kernel, but also address
backport releases.

The commit at hand replaces "vbox-linux-5.18.patch"
with the new "vbox-linux-5.19.patch",
fixing VirtualBox for LTS kernel releases.

(cherry picked from commit 0ad873b44b)
2022-07-07 18:55:09 +00:00
Domen Kožar
6dce23a6fd Merge pull request #177413 from NixOS/backport-175507-to-release-22.05
[Backport release-22.05] virtualbox: 6.1.30 -> 6.1.34
2022-07-07 13:50:16 -05:00
Maximilian Bosch
1cc82c116d linux: 5.4.202 -> 5.4.203
(cherry picked from commit 111751879d)
2022-07-07 18:38:18 +00:00
Maximilian Bosch
b3634de030 linux: 5.18.8 -> 5.18.9
(cherry picked from commit 39a8cebc2b)
2022-07-07 18:38:17 +00:00
Maximilian Bosch
0ca6abb1a0 linux: 5.15.51 -> 5.15.52
(cherry picked from commit edd230fbc4)
2022-07-07 18:38:17 +00:00
Maximilian Bosch
ff07b59612 linux: 5.10.127 -> 5.10.128
(cherry picked from commit 1e01358524)
2022-07-07 18:38:17 +00:00
Maximilian Bosch
0a51e044da linux: 4.9.320 -> 4.9.321
(cherry picked from commit 734b6f6d30)
2022-07-07 18:38:17 +00:00
Maximilian Bosch
da8dfb3944 linux: 4.19.249 -> 4.19.250
(cherry picked from commit 67b230bd08)
2022-07-07 18:38:17 +00:00
Maximilian Bosch
63b9f2a6bb linux: 4.14.285 -> 4.14.286
(cherry picked from commit a9b933df1c)
2022-07-07 18:38:17 +00:00
Maximilian Bosch
522afca14a Merge pull request #180559 from NixOS/backport-179702-to-release-22.05
[Backport release-22.05] Assorted kernel updates for 2022-06-29
2022-07-07 20:31:36 +02:00
K900
5049610a2c linux/hardened/patches/5.4: 5.4.201-hardened1 -> 5.4.202-hardened1
(cherry picked from commit f8b452f127)
2022-07-07 18:03:16 +00:00
K900
7ada5a9fcc linux/hardened/patches/5.18: 5.18.7-hardened1 -> 5.18.8-hardened1
(cherry picked from commit 87f3f3ab17)
2022-07-07 18:03:16 +00:00
K900
482dc99c58 linux/hardened/patches/5.15: 5.15.50-hardened1 -> 5.15.51-hardened1
(cherry picked from commit 362d5a564f)
2022-07-07 18:03:16 +00:00
K900
051ca1ffe9 linux/hardened/patches/5.10: 5.10.125-hardened1 -> 5.10.127-hardened1
(cherry picked from commit 0228189916)
2022-07-07 18:03:16 +00:00
K900
645325832e linux: 5.4.201 -> 5.4.202
(cherry picked from commit 7b061f8eb6)
2022-07-07 18:03:16 +00:00
K900
fcce9cae1a linux: 5.18.7 -> 5.18.8
(cherry picked from commit 7c4567e0d4)
2022-07-07 18:03:16 +00:00
K900
0719a2e501 linux: 5.15.50 -> 5.15.51
(cherry picked from commit 5a52c81969)
2022-07-07 18:03:16 +00:00
K900
89bf538650 linux: 5.10.126 -> 5.10.127
(cherry picked from commit 6ed6ef2ea1)
2022-07-07 18:03:16 +00:00
Ryan Horiguchi
980bf31c74 nixos/gnome: make it possible to remove core packages
Co-Authored-By: Jan Tojnar <jtojnar@gmail.com>
(cherry picked from commit 42ceb20d29)
2022-07-07 16:52:17 +00:00
Jan Tojnar
b63469629c nixos/gnome: Move sessionPath to core-shell group
This will allow people to disable these packages.

(cherry picked from commit ca23e42105)
2022-07-07 16:52:17 +00:00
Jan Tojnar
5a2d44da57 nixos/gnome: drop hicolor-icon-theme
It is already installed by xdg.icons.enable.

Let’s also enable that option explicitly to prevent users from accidentally
disabling it since GNOME will be severely broken without it.

(cherry picked from commit 016b99dce6)
2022-07-07 16:52:17 +00:00
Jan Tojnar
612ad7d968 nixos/xdg/icons: Install hicolor-icon-theme
While the package contains no icons, it includes an `index.theme` file
describing directories where toolkits should look for icons installed by apps.

(cherry picked from commit 7f0ce26bbd)
2022-07-07 16:52:17 +00:00
Jan Tojnar
c70632ce2e nixos/gnome: drop shared-mime-info
It is already installed by xdg.mime.enable.

Let’s also enable that option explicitly to prevent users from accidentally
disabling it since GNOME will be severely broken without it.

(cherry picked from commit aad39fe41a)
2022-07-07 16:52:17 +00:00
ajs124
999466f7e0 Merge pull request #180519 from NixOS/backport-179055-to-release-22.05 2022-07-07 17:56:18 +02:00
Georg Haas
3e718d0b32 wireshark: 3.6.3 -> 3.6.5
Changelogs:
 - https://www.wireshark.org/docs/relnotes/wireshark-3.6.4.html
 - https://www.wireshark.org/docs/relnotes/wireshark-3.6.5.html
(cherry picked from commit 086468ce4e09508eb2105d42be3b80cfc7cf4b37)
2022-07-07 17:24:34 +02:00
Maximilian Bosch
41434bb1ae Merge pull request #180126 from NixOS/backport-178858-to-release-22.05
[Backport release-22.05] nixos/matrix-synapse: update docs
2022-07-07 15:17:36 +02:00
Izorkin
ebaa94966a nginx: build with pcre
Pcre2 is not currently supported by nginx lua module.

(cherry picked from commit bc6a464c32)
2022-07-07 13:12:46 +00:00
Izorkin
5fcb50d720 nixos/tests: small update nginx-http3 test
(cherry picked from commit f169a1af97)
2022-07-07 13:12:46 +00:00
Izorkin
8061f7b691 nginxModules.moreheaders: v0.33 -> unstable-2022-06-21
(cherry picked from commit ccff32fa91)
2022-07-07 13:12:46 +00:00
Izorkin
ceb7a49722 nginxQuic: 5b1011b5702b -> 8d0753760546
(cherry picked from commit ec443943f5)
2022-07-07 13:12:45 +00:00
Izorkin
d5b329ea86 nginxMainline: 1.22.0 -> 1.23.0
(cherry picked from commit 7a8c541412)
2022-07-07 13:12:45 +00:00
Martin Weinelt
d2e341a2fd Merge pull request #180514 from mweinelt/22.05/openssl_3 2022-07-07 15:04:00 +02:00
Martin Weinelt
479cdc7c0f openssl_1_1: 1.1.1p -> 1.1.1q
https://www.openssl.org/news/secadv/20220705.txt

Fixes: CVE-2022-2097
(cherry picked from commit 82da6eb46d)
2022-07-07 14:44:00 +02:00
Martin Weinelt
582c29857b openssl_3: 3.0.4 -> 3.0.5
https://www.openssl.org/news/secadv/20220705.txt

We already acted on the first public disclosure, so this release removes
the previous patch and upgrades to the release including the fix.

Related: CVE-2022-2274
Fixes: CVE-2022-2097
(cherry picked from commit 1dbf7b45e2)
2022-07-07 14:42:33 +02:00
Alyssa Ross
c9b9ad0a1d openssl_3: rename from openssl_3_0
With their new versioning scheme, OpenSSL have committed[1] to API and
ABI compatibility for the whole 3.x.x release series, so we shouldn't
be overly specific in our attribute name.

[1]: https://www.openssl.org/blog/blog/2018/11/28/version/

(cherry picked from commit fd6a8fb894)
2022-07-07 14:42:28 +02:00
github-actions[bot]
a2bbab359f stgit: mark as unbroken on darwin (#180414)
Marked as broken by 37c633f7ae (treewide: pkgs/applications: mark
broken for darwin, 2022-05-28) probably by mistake. It builds and works
just fine.

(cherry picked from commit bdae2919d2)

Co-authored-by: Sebastián Mancilla <smancill@smancill.dev>
2022-07-06 20:16:44 -04:00
github-actions[bot]
d817bb9005 Merge staging-next-22.05 into staging-22.05 2022-07-07 00:16:30 +00:00
github-actions[bot]
58378f1bc6 Merge release-22.05 into staging-next-22.05 2022-07-07 00:15:52 +00:00
Martin Weinelt
83a3744f56 Merge pull request #180367 from NixOS/backport-180230-to-release-22.05 2022-07-07 01:43:32 +02:00
Martin Weinelt
c803abff21 Merge pull request #180408 from NixOS/backport-180403-to-release-22.05 2022-07-07 00:30:24 +02:00
Martin Weinelt
ef8307cae0 python3Packages.ldap: 3.4.0 -> 3.4.2
https://github.com/python-ldap/python-ldap/releases/tag/python-ldap-3.4.2
(cherry picked from commit c3f498f8c0)
2022-07-06 22:10:14 +00:00
superherointj
df8298ecc7 Merge pull request #180406 from WeebSorceress/backport-179942-to-release-22.05
[Backport release-22.05] adl: init at 3.0.1
2022-07-06 19:05:16 -03:00
WeebSorceress
a75edb3551 adl: init at 3.0.1
(cherry picked from commit a885d43d61)
2022-07-06 18:56:03 -03:00
Thomas Tuegel
1be2083e6d Merge pull request #180379 from NixOS/backport-179871-to-release-22.05
[Backport release-22.05] hplip: 3.21.12 -> 3.22.6
2022-07-06 16:52:41 -05:00
ajs124
080e7e5bc3 ffmpeg: 4.4.1 -> 4.4.2
d61977cbe4:/Changelog#l4

fixes CVE-2022-1475

(cherry picked from commit fea398ab65)
2022-07-06 21:09:15 +00:00
ajs124
a52fe94f98 Merge pull request #180376 from NixOS/backport-180351-to-release-22.05
[Backport release-22.05] dovecot: fix CVE-2022-30550
2022-07-06 21:33:02 +02:00
Claudio Bley
a3817c0174 hplip: 3.21.12 -> 3.22.6
* add patch from Debian which removes closed-source binary blobs from the
  package and fixes the build on aarch64-linux

* add patch that reverts calls of `strcpy` replaced with `snprintf`

Fixes #162141.

(cherry picked from commit 3ed1328b9b)
2022-07-06 19:11:59 +00:00
ajs124
5199528c0a dovecot: fix CVE-2022-30550
(cherry picked from commit 6870d49fea)
2022-07-06 18:33:42 +00:00
Jan Tojnar
b47cc81d95 webkitgtk: 2.36.3 → 2.36.4
https://webkitgtk.org/2022/07/05/webkitgtk2.36.4-released.html
https://webkitgtk.org/security/WSA-2022-0006.html
(cherry picked from commit a238ca2853)
2022-07-06 16:43:40 +00:00
Martin Weinelt
5754b3bf61 Merge pull request #180255 from squalus/librewolf-backport
[22.05] librewolf: 100.0-3 -> 102.0-2
2022-07-06 18:34:35 +02:00
squalus
9dd88fe103 librewolf: 100.0-3 -> 102.0-2
(cherry picked from commit 55c5a83c4c)
2022-07-06 09:11:55 -07:00
Arthur Gautier
316b762afd qemu-utils: ensure we cut off qemu dependency
(cherry picked from commit 312d91f14d33f08a296c744e495f61529ba77268)
2022-07-06 16:07:58 +00:00
Arthur Gautier
c6f977ecac qemu-utils: remove qemu dependency
qemu-utils was pulling qemu which is a 900MB dependency. By removing
reference to it (unneeded), we're saving space on our deployments.
qemu-utils is a dependency of cloud-utils

(cherry picked from commit a0153f4964c1c021f858ae7d5173cc4f5db23e41)
2022-07-06 16:07:58 +00:00
Bobby Rong
745b897230 Merge pull request #180334 from NixOS/backport-179939-to-release-22.05
[Backport release-22.05] frece: init at 1.0.6
2022-07-06 21:58:51 +08:00
superherointj
7d569cc4f6 hcloud: add fish to shell autocompletion
(cherry picked from commit c6f4b24770571ad9847ef858fb3384a3b1ecdf10)
2022-07-06 09:50:24 -03:00
Tom Siewert
7d26e3adcb hcloud: 1.29.5 -> 1.30.0
(cherry picked from commit e085e49dfc8807692c325b4b501612cc0943ca45)
2022-07-06 09:50:24 -03:00
Stig Palmquist
850753d1b5 gnupg: add patch disallowing compressed signatures and certificates
https://seclists.org/oss-sec/2022/q3/9
https://seclists.org/oss-sec/2022/q3/27
(cherry picked from commit 22e81f39ac)
2022-07-06 14:46:51 +02:00
Stig Palmquist
c7f30df180 gnupg: Add patch for CVE-2022-34903
https://www.openwall.com/lists/oss-security/2022/06/30/1
https://dev.gnupg.org/T6027
(cherry picked from commit 3d0e70ae2a)
2022-07-06 14:46:51 +02:00
Stig Palmquist
3352a7915b gnupg: 2.3.4 -> 2.3.6
(cherry picked from commit 1b2929cd91)
2022-07-06 14:46:51 +02:00
WeebSorceress
265554f0db frece: init at 1.0.6
(cherry picked from commit de0d0a2fb0)
2022-07-06 12:02:07 +00:00
github-actions[bot]
7e472328dc Merge staging-next-22.05 into staging-22.05 2022-07-06 00:16:09 +00:00
github-actions[bot]
961d8013ac Merge release-22.05 into staging-next-22.05 2022-07-06 00:15:36 +00:00
Martin Weinelt
6bc866f5bd libdwarf: mark known vulnerable
Related: #177227
2022-07-06 01:01:14 +02:00
Thiago Kenji Okada
299dbf37b0 Merge pull request #180275 from PedroHLC/backport-180264-to-release-22.05
[Backport release-22.05] zen-kernels: 5.17.7 -> 5.18.9
2022-07-05 23:52:40 +01:00
Martin Weinelt
791d9c01e3 Merge pull request #180285 from NixOS/backport-180272-to-release-22.05
[Backport release-22.05] firefox-unwrapped: 102.0 -> 102.0.1; firefox-bin-unwrapped: 102.0 -> 102.0.1
2022-07-06 00:15:48 +02:00
Martin Weinelt
6aee7d35ec firefox-bin-unwrapped: 102.0 -> 102.0.1
https://www.mozilla.org/en-US/firefox/102.0.1/releasenotes/
(cherry picked from commit 838e78a8a6)
2022-07-05 21:54:49 +00:00
Martin Weinelt
f8f1bdfd14 firefox-unwrapped: 102.0 -> 102.0.1
https://www.mozilla.org/en-US/firefox/102.0.1/releasenotes/
(cherry picked from commit e3e78bb409)
2022-07-05 21:54:49 +00:00
Sergei Trofimovich
199369b5b9 linux: disable WERROR by default
gcc update frequently breaks most recent kernel releases due to blanket -Werror
flag. Let's avoid -Werror in a default build to ease kernel and gcc maintenance.

(cherry picked from commit fea73bfd63)
2022-07-05 18:17:42 -03:00
Maximilian Bosch
cb5433561f nixos/privacyidea: pin python to 3.9
Otherwise `pi-manage` doesn't work inside the Python env (which is 3.10
whereas privacyidea requires 3.9).

Failing Hydra build: https://hydra.nixos.org/build/182734928

(cherry picked from commit 000d72eb7f)
2022-07-05 20:53:47 +00:00
Maximilian Bosch
0a0426ec77 privacyidea: 3.7.1 -> 3.7.2
ChangeLog: https://github.com/privacyidea/privacyidea/releases/tag/v3.7.2
(cherry picked from commit 1360dd9d71)
2022-07-05 20:53:47 +00:00
Maximilian Bosch
ba4f5eaa68 Merge pull request #180259 from NixOS/backport-180241-to-release-22.05
[Backport release-22.05] matrix-synapse: 1.61.1 -> 1.62.0
2022-07-05 22:37:01 +02:00
PedroHLC ☭
64f74edff0 zen-kernels: 5.18.7 -> 5.18.9
(cherry picked from commit cbc4d51711)
2022-07-05 16:24:11 -03:00
Dmitriy
bcb69e328f linux_zen: 5.18.5-zen1 -> 5.18.7-zen1
(cherry picked from commit 9da7308bb7)
2022-07-05 16:24:11 -03:00
Dmitriy
9eee280e28 linux_lqx: 5.15.16-lqx2 -> 5.18.7-lqx1
(cherry picked from commit adf52ecefe)
2022-07-05 16:24:11 -03:00
Dmitriy
893e54b008 linux_lqx, linux_zen: add update script
(cherry picked from commit 66c8475a8f)
2022-07-05 16:24:11 -03:00
Dmitriy
ede447e282 linux_lqx, linux_zen: refactor to unify
Unify linux_zen and linux_lqx -> zen-kernels

(cherry picked from commit 40674f0d7f)
2022-07-05 16:24:11 -03:00
InternetUnexplorer
67aa004802 linux_zen: 5.18.1-zen1 -> 5.18.5-zen1
(cherry picked from commit 089d7e3941)
2022-07-05 16:24:11 -03:00
InternetUnexplorer
dbcb7e4b18 linux_zen: 5.18.0-zen1 -> 5.18.1-zen1
This also disables WERROR, which is necessary until #175433 reaches
master (which disables it for all kernels).

(cherry picked from commit c240539dba)
2022-07-05 16:24:11 -03:00
André Vitor de Lima Matos
bcdb5e7072 linuxKernel.kernels.linux_zen: 5.17.7-zen1 -> 5.18.0-zen1
(cherry picked from commit 208fd4f173)
2022-07-05 16:24:11 -03:00
André Vitor de Lima Matos
98f03dfc5a kernel/update-zen.sh: add support to .0 patch versions
(cherry picked from commit 3c4e372c3f)
2022-07-05 16:24:11 -03:00
Sumner Evans
fb5e6a7172 matrix-synapse: 1.61.1 -> 1.62.0
Signed-off-by: Sumner Evans <me@sumnerevans.com>
(cherry picked from commit 8c5079ef3e)
2022-07-05 17:21:20 +00:00
Sumner Evans
dc4b931cdb matrix-common: 1.1.0 -> 1.2.1
Signed-off-by: Sumner Evans <me@sumnerevans.com>
(cherry picked from commit 5139952bef)
2022-07-05 17:21:20 +00:00
Robert Hensing
155bfc120e Merge pull request #178573 from NixOS/backport-174460-to-release-22.05
[Backport release-22.05] make-options-doc: Support Nix-provided declaration links
2022-07-05 19:16:29 +02:00
R. Ryantm
e5c61c7b10 diffoscope: 216 -> 217
(cherry picked from commit be558f02e5)
2022-07-05 19:13:45 +02:00
R. Ryantm
1861a7b2ba diffoscope: 215 -> 216
(cherry picked from commit 4e38070d6a)
2022-07-05 19:13:45 +02:00
R. Ryantm
bdf8a77b88 diffoscope: 214 -> 215
(cherry picked from commit 89d005bbb7)
2022-07-05 19:13:45 +02:00
R. Ryantm
028ecf4eb2 diffoscope: 213 -> 214
(cherry picked from commit 54e5a04e8c)
2022-07-05 19:13:45 +02:00
sternenseemann
262870c75a Revert "llvmPackages: do not include static archives when shared…"
Reverts #162607 / 1748887ff2.

Reason for revert: This change caused llvm-config{,-native} to be unable
to find static archives bundled with LLVM, as has been [reported]. Ever
since #152944 using moveToOutput in LLVM is _evil_ because llvm-config
obtains it knowledge about the installation locations from the CMake
configure step.

Consequently a change like #162607 will need to be implemented by making
LLVM itself install the static archives to the correct location or by
adding yet another patch which updates llvm-config's knowledge of the
location. The latter is not desireable in my opinion, though, since it
is just asking for this sort of trouble: Before #152944 we had an
outputs.patch that did this sort of things which broke spectacularly in
edge cases.

Fixes #148117.

[reported]: https://github.com/NixOS/nixpkgs/issues/148117#issuecomment-1158245576

(cherry picked from commit a2ed5b214d397cab7ce737dc1b1959bbd6a81419)
2022-07-05 16:08:20 +02:00
kilianar
9e96b1562d syncthing: 1.20.2 -> 1.20.3
https://github.com/syncthing/syncthing/releases/tag/v1.20.3
(cherry picked from commit 6fd9b1f9cdbb09e68fefa5e74802c529f80fe6bb)
2022-07-05 15:32:44 +02:00
kilianar
0bc59833c3 syncthing: 1.20.1 -> 1.20.2
(cherry picked from commit e2fd174261)
2022-07-05 15:00:46 +02:00
maxine [they]
8b8117d826 Merge pull request #180215 from NixOS/backport-180200-to-release-22.05
[Backport release-22.05] gnome.polari: 42.0 -> 42.1
2022-07-05 14:43:30 +02:00
maxine [they]
2751379027 Merge pull request #180216 from NixOS/backport-180196-to-release-22.05
[Backport release-22.05] gnome.gnome-shell-extensions: 42.2 -> 42.3
2022-07-05 14:43:17 +02:00
maxine [they]
f21c1bbe9d Merge pull request #180214 from NixOS/backport-180195-to-release-22.05
[Backport release-22.05] gnome.gnome-shell: 42.2 -> 42.3.1
2022-07-05 14:42:58 +02:00
maxine [they]
fb655a6517 Merge pull request #180213 from NixOS/backport-180199-to-release-22.05
[Backport release-22.05] gnome.mutter: 42.2 -> 42.3
2022-07-05 14:42:48 +02:00
Bobby Rong
d1075c8c92 Merge pull request #180117 from NixOS/backport-180064-to-release-22.05
[Backport release-22.05] Pantheon 7 updates 2022-07-03
2022-07-05 20:02:39 +08:00
R. Ryantm
a0dfdf923e gnome.gnome-shell-extensions: 42.2 -> 42.3
(cherry picked from commit 042db7e16c)
2022-07-05 10:19:06 +00:00
R. Ryantm
29e35462d3 gnome.polari: 42.0 -> 42.1
(cherry picked from commit 95325c1793)
2022-07-05 10:18:42 +00:00
R. Ryantm
998d4d6a16 gnome.gnome-shell: 42.2 -> 42.3.1
(cherry picked from commit 1468b339d0)
2022-07-05 10:18:41 +00:00
R. Ryantm
f4164d3547 gnome.mutter: 42.2 -> 42.3
(cherry picked from commit 95ffdc6b73)
2022-07-05 10:18:36 +00:00
Martin Weinelt
e91e9a5e6e Merge pull request #180021 from risicle/ris-curl-CVEs-2022-07-r22.05 2022-07-05 12:11:35 +02:00
Martin Weinelt
edcc3eedd6 Merge pull request #180185 from NixOS/backport-180105-to-staging-22.05 2022-07-05 12:09:41 +02:00
Ilan Joselevich
6a9fcf917c nextcloud-client: 3.5.1 -> 3.5.2
(cherry picked from commit c0758c18949c63c3f9b9f4360c92c3c776d8fcb5)
2022-07-05 11:25:58 +02:00
Maximilian Bosch
e8bf875c0f Merge pull request #180141 from NixOS/backport-179171-to-release-22.05
[Backport release-22.05] epson-escpr2: 1.1.46 -> 1.1.48
2022-07-05 11:07:45 +02:00
Maximilian Bosch
c2f79d00f8 Merge pull request #179373 from NixOS/backport-179237-to-release-22.05
[Backport release-22.05] wiki-js: 2.5.284 -> 2.5.285
2022-07-05 11:07:31 +02:00
Martin Weinelt
07eb0ab6d7 python3Packages.django_3: 3.2.13 -> 3.2.14
https://www.djangoproject.com/weblog/2022/jul/04/security-releases/
https://docs.djangoproject.com/en/dev/releases/3.2.14/

Fixes: CVE-2022-34265
(cherry picked from commit 8f3b6c83d9)
2022-07-05 01:41:24 +00:00
Martin Weinelt
b8d6d72867 python3Packages.django_4: 4.0.5 -> 4.0.6
https://www.djangoproject.com/weblog/2022/jul/04/security-releases/
https://docs.djangoproject.com/en/dev/releases/4.0.6/

Fixes: CVE-2022-34265
(cherry picked from commit 3086451764)
2022-07-05 01:41:24 +00:00
github-actions[bot]
555cbdc66d Merge staging-next-22.05 into staging-22.05 2022-07-05 00:14:00 +00:00
github-actions[bot]
9403e116ec Merge release-22.05 into staging-next-22.05 2022-07-05 00:13:23 +00:00
WilliButz
cc16da2c92 Merge pull request #180143 from NixOS/backport-170947-to-release-22.05
[Backport release-22.05] nixos/gitlab: fix gitlab-registry-cert path condition
2022-07-04 19:29:36 +02:00
Tobias Stenzel
38561390bd nixos/gitlab: fix gitlab-registry-cert path condition
`ConditionPathExists` belongs in the [Unit] section, not [Service].
The unit now properly checks if the cert file already
exists before activating so certs will not be overwritten anymore.

(cherry picked from commit 0c4f8e78b5)
2022-07-04 16:44:56 +00:00
Shawn8901
cc840e906e epson-escpr2: 1.1.46 -> 1.1.48
(cherry picked from commit fa0f161ef7)
2022-07-04 16:31:31 +00:00
Nicolas Benes
b9cac54ba7 tor-browser-bundle-bin: 11.0.14 -> 11.0.15
(cherry picked from commit b6805190a2)
2022-07-04 18:08:22 +02:00
Maximilian Bosch
e8d4797728 Merge pull request #178348 from NixOS/backport-177935-to-release-22.05
[Backport release-22.05] nixos/prometheus-postfix-exporter: fixes for systemd integration
2022-07-04 17:10:10 +02:00
Maximilian Bosch
bcb83a9cc8 nixos/matrix-synapse: update docs
* Update attribute names in code examples (* -> settings.*).
* Use `nix-shell -p` rather than `nix run` because the example won't
  work with the current default Nix.
* Update config values for `element-web`.
* Fix link to `element-web` security considerations.
* Make the synapse expression even smaller and use callout-lists to
  explain the code.
* Document how to correctly deploy the shared registration secret.

[1] https://spec.matrix.org/latest/client-server-api/#getwell-knownmatrixclient

(cherry picked from commit 899a37d190)
2022-07-04 15:01:25 +00:00
Bobby Rong
edaee6c8d8 Merge pull request #180101 from NixOS/backport-179989-to-release-22.05
[Backport release-22.05] sigi: 3.4.0 -> 3.4.2
2022-07-04 21:48:06 +08:00
Bobby Rong
40f723cb54 Merge pull request #180116 from NixOS/backport-179347-to-release-22.05
[Backport release-22.05] kdigger: 1.2.0 -> 1.2.1
2022-07-04 21:47:22 +08:00
Bobby Rong
8f75281021 pantheon.granite7: fix large height bug for MessageDialog
(cherry picked from commit 6841314b45)
2022-07-04 13:42:01 +00:00
Bobby Rong
77dbd7717b pantheon.gala: fix initial alt-tab switcher indicator visibility
(cherry picked from commit 513b8a9d2b)
2022-07-04 13:42:01 +00:00
Bobby Rong
52f8e5e484 pantheon.wingpanel-indicator-notifications: 6.0.4 -> 6.0.5
(cherry picked from commit ba48a66dec)
2022-07-04 13:42:01 +00:00
Bobby Rong
4e09144f38 pantheon.switchboard-plug-wacom: 1.0.0 -> 1.0.1
(cherry picked from commit fcd299ab70)
2022-07-04 13:42:01 +00:00
06kellyjac
b5546b96c1 kdigger: 1.2.0 -> 1.2.1
(cherry picked from commit 383ee3c194)
2022-07-04 13:26:04 +00:00
Jörg Thalheim
655e6d8fc5 Merge pull request #180003 from NixOS/backport-179784-to-release-22.05
[Backport release-22.05] signal-desktop: 5.47.0 -> 5.48.0
2022-07-04 14:27:17 +02:00
Jörg Thalheim
814851ed80 Merge pull request #180002 from NixOS/backport-179723-to-release-22.05
[Backport release-22.05] signal-desktop: revert “Allow overriding the spell checker language”
2022-07-04 14:27:02 +02:00
maxine [they]
483b06d875 Merge pull request #180110 from NixOS/backport-180076-to-release-22.05
[Backport release-22.05] gnome.gnome-remote-desktop: 42.2 -> 42.3
2022-07-04 13:58:16 +02:00
R. Ryantm
3f04afbe92 gnome.gnome-remote-desktop: 42.2 -> 42.3
(cherry picked from commit 19c31e6b87086271790f8619acc3ac24d5d81352)
2022-07-04 11:42:06 +00:00
Maximilian Bosch
5bd221a9d7 Merge pull request #180104 from NixOS/backport-180097-to-release-22.05
[Backport release-22.05] atlassian-jira: 8.22.2 -> 8.22.4
2022-07-04 13:11:15 +02:00
WilliButz
d95d417ffd atlassian-jira: 8.22.2 -> 8.22.4
includes fix for CVE-2022-26135

https://confluence.atlassian.com/jira/jira-server-security-advisory-29nd-june-2022-1142430667.html
https://confluence.atlassian.com/jirasoftware/issues-resolved-in-8-22-4-1141486890.html
(cherry picked from commit 50dff7c678)
2022-07-04 10:46:59 +00:00
hiljusti
0a242ce1f8 sigi: 3.4.0 -> 3.4.2
(cherry picked from commit b4cbc03186)
2022-07-04 10:26:20 +00:00
github-actions[bot]
88d37c6285 Merge staging-next-22.05 into staging-22.05 2022-07-04 00:18:12 +00:00
github-actions[bot]
2591f40196 Merge release-22.05 into staging-next-22.05 2022-07-04 00:17:34 +00:00
Robert Scott
2bac6216d0 curl: add patches for multiple CVEs
CVE-2022-32205
CVE-2022-32206
CVE-2022-32207
CVE-2022-32208
2022-07-03 16:54:35 +01:00
ajs124
71d047ba0b offlineimap: remove optional insecure kerberos dependency
was marked insecure in c8dbbe5c32
because of https://github.com/apple/ccs-pykerberos/issues/31

(cherry picked from commit 5fec5ebf37)
2022-07-03 14:21:30 +00:00
Robert Schütz
21d5606285 python310Packages.vyper: mark insecure
(cherry picked from commit 587c686926)
2022-07-03 14:21:30 +00:00
Robert Schütz
adc3d56021 python310Packages.waitress: 2.1.1 -> 2.1.2
https://github.com/Pylons/waitress/blob/v2.1.2/HISTORY.txt

fixes CVE-2022-31015

(cherry picked from commit 701b918dc3)
2022-07-03 14:21:30 +00:00
Robert Schütz
52f4f8bcd0 python310Packages.rencode: 1.0.6 -> unstable-2021-08-10
fixes CVE-2021-40839

(cherry picked from commit 2447fc09ec)
2022-07-03 14:21:30 +00:00
Robert Schütz
80554b6ab7 python310Packages.pypdf2: 1.26.0 -> 1.28.4
https://github.com/py-pdf/PyPDF2/blob/1.28.4/CHANGELOG

fixes CVE-2022-24859

(cherry picked from commit a1b860e67a)
2022-07-03 14:21:30 +00:00
Robert Schütz
b05807667d python310Packages.notebook: 6.4.10 -> 6.4.12
fixes CVE-2022-29238

(cherry picked from commit 7b3c3d6ced)
2022-07-03 14:21:30 +00:00
Robert Schütz
92fb16d76c python310Packages.kerberos: mark insecure
(cherry picked from commit c8dbbe5c32)
2022-07-03 14:21:30 +00:00
Robert Schütz
3e2668d511 python310Packages.jupyter_server: 1.11.2 -> 1.17.1
https://github.com/jupyter-server/jupyter_server/blob/v1.17.1/CHANGELOG.md

fixes CVE-2022-24757 and CVE-2022-29241

(cherry picked from commit b9f50b7803)
2022-07-03 14:21:30 +00:00
Robert Schütz
d7ded9821f python310Packages.jupyterhub: 1.3.0 -> 1.5.0
https://github.com/jupyterhub/jupyterhub/blob/1.5.0/docs/source/changelog.md

fixes CVE-2021-41247

(cherry picked from commit af1bf5dc71)
2022-07-03 14:21:30 +00:00
Robert Schütz
b48ed52cc4 python310Packages.flower: mark insecure
(cherry picked from commit cb8ab777b8)
2022-07-03 14:21:30 +00:00
Robert Schütz
e72989c323 python310Packages.flask-caching: 1.10.1 -> 1.11.1
(cherry picked from commit be19a33c51)
2022-07-03 14:21:30 +00:00
Robert Schütz
f4e54d4647 python310Packages.cookiecutter: 1.7.3 -> 2.1.1
fixes CVE-2022-24065

(cherry picked from commit 68ead458d3)
2022-07-03 14:21:30 +00:00
Robert Schütz
72efc40141 python310Packages.beaker: mark insecure
(cherry picked from commit 12fb03569f)
2022-07-03 14:21:30 +00:00
Artturi
4eb80b0867 Merge pull request #176339 from amjoseph-nixpkgs/pr/backport/174691
[Backport release-22.05] arm-trusted-firmware: unfree only if hdcp.bin used
2022-07-03 16:25:12 +03:00
maxine [they]
a8df415af2 Merge pull request #180004 from NixOS/backport-179975-to-release-22.05 2022-07-03 14:31:22 +02:00
Bobby Rong
88256e9829 Merge pull request #179967 from bobby285271/pantheon-stable
[22.05] Pantheon 6.1 updates 2022-07-02
2022-07-03 20:21:23 +08:00
Bobby Rong
3bdba7fc60 Merge pull request #179997 from NixOS/backport-179988-to-release-22.05
[Backport release-22.05] pantheon.switchboard-plug-pantheon-shell: 6.1.0 -> 6.2.0
2022-07-03 20:21:02 +08:00
Bobby Rong
876f561009 Merge pull request #179996 from NixOS/backport-179987-to-release-22.05
[Backport release-22.05] pantheon.switchboard-plug-network: 2.4.2 -> 2.4.3
2022-07-03 20:20:51 +08:00
R. Ryantm
94311bb01b gtk4: 4.6.5 -> 4.6.6
(cherry picked from commit f797cceab2dccde19d2a86f3e0f09af9506861a1)
2022-07-03 12:20:17 +00:00
kilianar
66eb568b21 signal-desktop: 5.47.0 -> 5.48.0
https://github.com/signalapp/Signal-Desktop/releases/tag/v5.48.0
(cherry picked from commit 1fc2aa773b)
2022-07-03 12:18:54 +00:00
Andrew Kvalheim
e67b541a3a signal-desktop: revert "Allow overriding the spell checker language (#44456)"
This reverts commit 9ef1406a99.

Signal Desktop removed this functionality when changing spell checkers:

  - signalapp/Signal-Desktop@6a517e4ef9
  - signalapp/Signal-Desktop@4a8f5db0a4

(cherry picked from commit cb7ddc7f34)
2022-07-03 12:18:18 +00:00
Sandro
4d67f272f1 Merge pull request #179787 from NixOS/backport-179264-to-release-22.05
[Backport release-22.05] signal-desktop: fix missing tray icon
2022-07-03 14:13:50 +02:00
R. Ryantm
c92bed68c0 pantheon.switchboard-plug-pantheon-shell: 6.1.0 -> 6.2.0
(cherry picked from commit eccf2df672)
2022-07-03 11:22:30 +00:00
R. Ryantm
67719d6e65 pantheon.switchboard-plug-network: 2.4.2 -> 2.4.3
(cherry picked from commit 867a0b9c69)
2022-07-03 11:19:54 +00:00
Maximilian Bosch
261d8d497a Merge pull request #179547 from NixOS/backport-179477-to-release-22.05
[Backport release-22.05] Linux kernel updates 2022-06-28
2022-07-03 11:37:02 +02:00
Fabian Affolter
88c794b291 Merge pull request #179524 from NixOS/backport-179453-to-release-22.05
[Backport release-22.05] python310Packages.niapy: init at 2.0.2
2022-07-03 10:42:16 +02:00
Vladimír Čunát
ccd1222a22 thunderbird*: default to 91 branch for now 2022-07-03 10:39:06 +02:00
Nick Cao
bddb567111 thunderbirdPackages: make thunderbird an alias to thunderbird-102
(cherry picked from commit d5720b7be7)
2022-07-03 08:20:47 +00:00
Nick Cao
b991c7fd00 thunderbird*: 91.11.0 -> 102.0
(cherry picked from commit a5cb45329e)
2022-07-03 08:20:46 +00:00
Bobby Rong
f93ef1c775 pantheon.elementary-camera: backport two fixes from 6.2.0
On master, elementary-camera has been updated to 6.1.0 in 63c45ddaf8 and 6.2.0 in a173b861ff.
2022-07-03 09:54:26 +08:00
Bobby Rong
3fa4c98f68 pantheon.elementary-files: 6.1.3 -> 6.1.4
(cherry picked from commit 07428e9c2f)
2022-07-03 09:29:37 +08:00
github-actions[bot]
727146c28e Merge staging-next-22.05 into staging-22.05 2022-07-03 00:18:06 +00:00
github-actions[bot]
88dcc8373c Merge release-22.05 into staging-next-22.05 2022-07-03 00:17:34 +00:00
Anderson Torres
18038cee44 Merge pull request #179916 from NixOS/backport-179907-to-release-22.05
[Backport release-22.05] freecad: fix crash when selecting color of a solid
2022-07-02 14:22:41 -03:00
Anderson Torres
b53c02d3fc Merge pull request #179917 from NixOS/backport-179715-to-release-22.05
[Backport release-22.05] trackma: init at 0.8.4
2022-07-02 14:20:46 -03:00
WeebSorceress
52762ed532 trackma: init at 0.8.4
(cherry picked from commit a2403ed37f)
2022-07-02 15:25:41 +00:00
Juraj Hercek
8b9c0113c6 freecad: fix crash when selecting color of a solid
FreeCAD crashes when user wants to select color of a solid with
following console message (long lines wrapped):

    $ nix run nixpkgs#freecad
    FreeCAD 0.20, Libs: 0.20RUnknown
    © Juergen Riegel, Werner Mayer, Yorik van Havre and others 2001-2022
    FreeCAD is free and open-source software licensed under the terms of
    LGPL2+ license.
    FreeCAD wouldn't be possible without FreeCAD community.
      #####                 ####  ###   ####
      #                    #      # #   #   #
      #     ##  #### ####  #     #   #  #   #
      ####  # # #  # #  #  #     #####  #   #
      #     #   #### ####  #    #     # #   #
      #     #   #    #     #    #     # #   #  ##  ##  ##
      #     #   #### ####   ### #     # ####   ##  ##  ##

    (freecad:19737): GLib-GIO-ERROR **: 14:33:02.511: Settings schema
    'org.gtk.Settings.ColorChooser' is not installed
    fish: Job 1, 'nix run nixpkgs#freecad' terminated by signal SIGTRAP
    (Trace or breakpoint trap)

This patch adds hooks for GApps to relevant places in order to make
FreeCAD finding the Color Chooser dialog schema effectively preventing
crash from happening.

(cherry picked from commit 269b500073)
2022-07-02 15:14:59 +00:00
Alyssa Ross
09c32b0bda rustc: mark broken for dynamic Musl target
(cherry picked from commit 9e103d03dcd3db6b26ea67da04a9fc1c62aa0787)
2022-07-02 09:29:00 +00:00
Vladimír Čunát
f04e77d490 Merge #179251: staging-next-22.05 - iteration 3 2022-07-02 11:24:54 +02:00
Vladimír Čunát
a95caee27f Merge #179882: thrift: fix expired certs in tests
(cherry picked from commit 36888aa839)
2022-07-02 11:14:40 +02:00
maxine [they]
e966a51973 Merge pull request #179875 from NixOS/backport-179774-to-staging-22.05 2022-07-02 10:59:00 +02:00
maxine [they]
f04dfc76b1 Merge pull request #179876 from NixOS/backport-179768-to-release-22.05 2022-07-02 10:58:46 +02:00
maxine [they]
c8d6eb287c Merge pull request #179877 from NixOS/backport-179770-to-release-22.05 2022-07-02 10:58:34 +02:00
maxine [they]
35a6df9ef7 Merge pull request #179878 from NixOS/backport-179766-to-staging-22.05 2022-07-02 10:58:18 +02:00
maxine [they]
8bf0ab6690 Merge pull request #179879 from NixOS/backport-179667-to-release-22.05 2022-07-02 10:58:07 +02:00
R. Ryantm
306ef57905 glib-networking: 2.72.0 -> 2.72.1
(cherry picked from commit 4bb2fdfaab7111afc7d8c4c8235acf8dbf742c35)
2022-07-02 08:45:59 +00:00
R. Ryantm
3cfa5fd10c glib: 2.72.2 -> 2.72.3
(cherry picked from commit 9839f23cbdb85b69cc70b0f59079996fc6bbc3f3)
2022-07-02 08:44:44 +00:00
R. Ryantm
97c5c853c1 gnome.gnome-software: 42.2 -> 42.3
(cherry picked from commit 22379a971cf22f8596ce2b97d7df5f9b32db3f17)
2022-07-02 08:44:11 +00:00
R. Ryantm
e9fd2a0928 gnome.gnome-control-center: 42.2 -> 42.3
(cherry picked from commit 7ef5f770c5a464e5396a2d9af3b55a6ee116a187)
2022-07-02 08:44:09 +00:00
R. Ryantm
2371b71b3c libsoup_3: 3.0.6 -> 3.0.7
(cherry picked from commit 611212aab44cc5101f5036e7de4c40b493246632)
2022-07-02 08:43:22 +00:00
Bobby Rong
0257ea0eca Merge pull request #179771 from NixOS/backport-179653-to-release-22.05
[Backport release-22.05] pantheon.switchboard-plug-printers: 2.1.10 -> 2.2.0
2022-07-02 16:13:22 +08:00
Bobby Rong
2b27e4f8e9 Merge pull request #179791 from NixOS/backport-179779-to-release-22.05
[Backport release-22.05] pantheon.wingpanel-indicator-network: 2.3.2 -> 2.3.3
2022-07-02 16:12:27 +08:00
7c6f434c
35582f557e Merge pull request #179818 from NixOS/backport-178895-to-release-22.05
[Backport release-22.05] sage: depend on python3Packages.notebook
2022-07-02 06:10:43 +00:00
github-actions[bot]
0802ca2b80 Merge staging-next-22.05 into staging-22.05 2022-07-02 00:17:21 +00:00
github-actions[bot]
a87b236280 Merge release-22.05 into staging-next-22.05 2022-07-02 00:16:45 +00:00
Martin Weinelt
f5a6d714ea Merge pull request #179840 from NixOS/backport-179810-to-release-22.05 2022-07-01 23:51:17 +02:00
Johan Thomsen
68587fd736 prometheus: add flag for dns plugin, enable by default
(cherry picked from commit 3ea552b399058817c1e593beddff1b6758e21571)
2022-07-01 23:10:14 +02:00
Yaya
a6cb6ea559 gitlab: 15.1.0 -> 15.1.1
https://about.gitlab.com/releases/2022/06/30/critical-security-release-gitlab-15-1-1-released/

Fixes CVE-2022-2185 CVE-2022-2235 CVE-2022-2230 CVE-2022-2229
      CVE-2022-1983 CVE-2022-1963 CVE-2022-2228 CVE-2022-1981
      CVE-2022-2243 CVE-2022-2244 CVE-2022-1954 CVE-2022-2270
      CVE-2022-2250 CVE-2022-1999 CVE-2022-2281 CVE-2022-2227

(cherry picked from commit 53cf316b691c520cd53aa65d7c3be5c08c0bd5c7)
2022-07-01 20:25:49 +00:00
Mauricio Collares
df0b37d1f7 sage: depend on python3Packages.notebook
(cherry picked from commit f025b2340b)
2022-07-01 16:49:43 +00:00
Domen Kožar
e4e484c84f Merge pull request #179625 from NixOS/backport-175170-to-release-22.05
[Backport release-22.05] haskell.compiler: ghc922 -> ghc923
2022-07-01 09:46:52 -05:00
Domen Kožar
8005c5b112 ghc: add 9.2.3 2022-07-01 09:30:18 -05:00
R. Ryantm
b97b4dd38e libopenmpt: 0.6.3 -> 0.6.4
(cherry picked from commit 7edd294d1d92584622ab019553b47e03b220769c)
2022-07-01 14:12:43 +00:00
Pavol Rusnak
915f5a5b3c Merge pull request #179799 from NixOS/backport-179795-to-release-22.05
[Backport release-22.05] bitcoin: fix broken build on aarch64-darwin
2022-07-01 14:50:28 +02:00
Pavol Rusnak
3b967b49be bitcoin: fix broken build on aarch64-darwin
by disabling stackprotector which kills the tests

(cherry picked from commit 28385978bc)
2022-07-01 12:49:24 +00:00
Robert Hensing
83693f62aa Merge pull request #179785 from NixOS/backport-178365-to-release-22.05
[Backport release-22.05] lib.formats.keyValue: init
2022-07-01 12:49:15 +02:00
R. Ryantm
a96e8e492e pantheon.wingpanel-indicator-network: 2.3.2 -> 2.3.3
(cherry picked from commit d20dd11968)
2022-07-01 10:24:15 +00:00
teutat3s
280b1aa637 signal-desktop: fix missing tray icon
Fixes: #178892
(cherry picked from commit c22a517b752dd7e8c059c5f92b9cc467d246c5d6)
2022-07-01 09:58:16 +00:00
Francesco Gazzetta
5f85d74552 formats.keyValue: add tests
(cherry picked from commit 0d2842a435)
2022-07-01 09:36:43 +00:00
Francesco Gazzetta
b5fa8e479b lib.formats.keyValue: init
(cherry picked from commit 3ff9245301)
2022-07-01 09:36:43 +00:00
Bobby Rong
d66e753605 pantheon.switchboard-plug-printers: 2.1.10 -> 2.2.0
(cherry picked from commit 133573bd5b)
2022-07-01 04:49:36 +00:00
Robert Schütz
adc1ed6c83 communi: 3.5.0 -> 3.6.0
(cherry picked from commit e47f1d2527)
2022-07-01 01:08:03 +00:00
github-actions[bot]
19119dffc9 Merge staging-next-22.05 into staging-22.05 2022-07-01 00:17:35 +00:00
github-actions[bot]
e6ec584e25 Merge release-22.05 into staging-next-22.05 2022-07-01 00:16:56 +00:00
Alyssa Ross
961ddd2f29 pkgsStatic.jansson: fix build
Fixes: 938f2ce101 ("jansson: enable shared library installation")
(cherry picked from commit 50c258cc1b05fda9d1f9222ddbaa71c3cbd68977)
2022-06-30 23:56:18 +00:00
Alyssa Ross
f59ca01aab pkgsMusl.libical: fix build by disabling tests
We can't support running tests on Musl until TZDIR support is added.

(cherry picked from commit 264d232312ca38ae54f701afa25254ea8e0adfa5)
2022-06-30 23:55:23 +00:00
Thiago Kenji Okada
ac55f5fa8c Merge pull request #179393 from colin-arnott-xero/awscli2-backport
[22.05] awscli2: 2.5.6 -> 2.7.9
2022-06-30 23:20:22 +01:00
ckie
05734e66dd Merge pull request #178897 from bdd/release-22.05
[22.05] runitor: 0.9.2 -> 0.10.1
2022-06-30 22:28:22 +03:00
Domen Kožar
e1029c6170 Merge pull request #179720 from domenkozar/backport-cachix-agent-verbose-22.05
[backport 22.05] cachix-agent: expose verbose option
2022-06-30 10:57:48 -05:00
Domen Kožar
728605f042 cachix-agent: expose verbose option
(cherry picked from commit 989565d676)
2022-06-30 10:27:14 -05:00
ajs124
23c5f25ee6 Merge pull request #176123 from NixOS/backport-176101-to-release-22.05
[Backport release-22.05] wpscan: 3.8.20 → 3.8.22
2022-06-30 17:05:39 +02:00
Bobby Rong
dbb62c34bb Merge pull request #178188 from NixOS/backport-177174-to-release-22.05
[Backport release-22.05] zeronet-conservancy: 0.7.5 -> 0.7.6, add nixos test
2022-06-30 19:50:41 +08:00
Bobby Rong
8b3f617345 Merge pull request #179617 from NixOS/backport-179018-to-release-22.05
[Backport release-22.05] qbe: unstable-2022-04-11 -> 1.0
2022-06-30 19:16:40 +08:00
Bobby Rong
78630792ee Merge pull request #179677 from NixOS/backport-179450-to-release-22.05
[Backport release-22.05] Add changelogger package
2022-06-30 19:14:10 +08:00
Alyssa Ross
9de9ed1106 libv4l: fix build for non-glibc platforms
argp is a Glibc-specific feature.

(cherry picked from commit bfd4a0bc82f010c93a0e1d29e3eac4f9ee81de58)
2022-06-30 09:25:39 +00:00
markuskowa
2b1f886e43 Merge pull request #179629 from NixOS/backport-179495-to-release-22.05
[Backport release-22.05] pdfstudio / pdfstudioviewer: 2021.1.3 -> 2021.2.0
2022-06-30 10:43:05 +02:00
Tom Siewert
e8d2bfdaca changelogger: init at 0.5.2
(cherry picked from commit b607d51a88)
2022-06-30 06:32:33 +00:00
Tom Siewert
945246e2e7 nixos/maintainers: add tomsiewert
(cherry picked from commit 2c1f26572f)
2022-06-30 06:32:33 +00:00
github-actions[bot]
eb14bfa099 Merge staging-next-22.05 into staging-22.05 2022-06-30 00:15:59 +00:00
github-actions[bot]
fb0416a5b8 Merge release-22.05 into staging-next-22.05 2022-06-30 00:15:26 +00:00
Domen Kožar
7fb2acd492 Merge pull request #179638 from NixOS/backport-179634-to-release-22.05
[Backport release-22.05] cachix-agent: properly handle not restarting the service
2022-06-29 18:54:56 -05:00
Anderson Torres
c0fd789727 Merge pull request #179592 from NixOS/backport-178898-to-release-22.05
[Backport release-22.05] pixelorama: init at 0.10.1
2022-06-29 20:44:19 -03:00
Domen Kožar
67c515d88b cachix-agent: properly handle not restarting the service
(cherry picked from commit c7b135ac8e)
2022-06-29 22:51:03 +00:00
Philipp Woelfel
66d2e2c33e pdfstudio / pdfstudioviewer: 2021.1.3 -> 2021.2.0
(cherry picked from commit f136e63c1b)
2022-06-29 21:48:44 +00:00
Francesco Gazzetta
d48001366e qbe: unstable-2022-04-11 -> 1.0
(cherry picked from commit 7fa4799766)
2022-06-29 20:45:17 +00:00
Felix Schröter
61824942d4 pixelorama: init at 0.10.1
(cherry picked from commit 53c202dc53)
2022-06-29 17:18:07 +00:00
Thiago Kenji Okada
93950edf01 Merge pull request #179572 from NixOS/backport-179265-to-release-22.05
[Backport release-22.05] unrar: 6.1.6 -> 6.1.7
2022-06-29 17:23:23 +01:00
Robert Schütz
8cc4e592a1 unrar: 6.1.6 -> 6.1.7
(cherry picked from commit 2b9bd14ba9)
2022-06-29 13:44:28 +00:00
Martin Weinelt
be6da3774d Merge pull request #179503 from NixOS/backport-179480-to-release-22.05 2022-06-29 13:07:21 +02:00
Maximilian Bosch
f82866fc65 linux/hardened/patches/5.4: 5.4.200-hardened1 -> 5.4.201-hardened1
(cherry picked from commit 7d58f625e2)
2022-06-29 08:51:40 +00:00
Maximilian Bosch
a21f647865 linux/hardened/patches/5.18: 5.18.6-hardened1 -> 5.18.7-hardened1
(cherry picked from commit 57d38001ad)
2022-06-29 08:51:40 +00:00
Maximilian Bosch
02503a21eb linux/hardened/patches/5.15: 5.15.49-hardened1 -> 5.15.50-hardened1
(cherry picked from commit d7973cd502)
2022-06-29 08:51:40 +00:00
Maximilian Bosch
419389c1a7 linux/hardened/patches/5.10: 5.10.124-hardened1 -> 5.10.125-hardened1
(cherry picked from commit 3cf33ad016)
2022-06-29 08:51:40 +00:00
Maximilian Bosch
68976a61a8 linux/hardened/patches/4.19: 4.19.248-hardened1 -> 4.19.249-hardened1
(cherry picked from commit 14479c95a2)
2022-06-29 08:51:40 +00:00
Maximilian Bosch
6396303ddf linux/hardened/patches/4.14: 4.14.284-hardened1 -> 4.14.285-hardened1
(cherry picked from commit 299b49b539)
2022-06-29 08:51:39 +00:00
Maximilian Bosch
d608f7fa39 linux: 5.4.200 -> 5.4.201
(cherry picked from commit dfc38c7baa)
2022-06-29 08:51:39 +00:00
Maximilian Bosch
306d82d357 linux: 5.18.6 -> 5.18.7
(cherry picked from commit a13afa2d90)
2022-06-29 08:51:39 +00:00
Maximilian Bosch
9665798289 linux: 5.15.49 -> 5.15.50
(cherry picked from commit 17996e10f9)
2022-06-29 08:51:39 +00:00
Maximilian Bosch
171e9b6b1a linux: 5.10.124 -> 5.10.126
(cherry picked from commit 48f604ef69)
2022-06-29 08:51:39 +00:00
Maximilian Bosch
f783b17069 linux: 4.9.319 -> 4.9.320
(cherry picked from commit 21c39a0969)
2022-06-29 08:51:39 +00:00
Maximilian Bosch
bc81326d0d linux: 4.19.248 -> 4.19.249
(cherry picked from commit 34fe04da8e)
2022-06-29 08:51:39 +00:00
Maximilian Bosch
55841367ec linux: 4.14.284 -> 4.14.285
(cherry picked from commit 2b50639f43)
2022-06-29 08:51:39 +00:00
Mario Rodas
5e2ca9f15b Merge pull request #179523 from NixOS/backport-179520-to-release-22.05
[Backport release-22.05] yt-dlp: 2022.6.22.1 -> 2022.6.29
2022-06-29 02:34:36 -05:00
Fabian Affolter
41b14bae0a python310Packages.niapy: init at 2.0.2
(cherry picked from commit ae4623b296)
2022-06-29 07:14:45 +00:00
zowoq
c774aa420c yt-dlp: 2022.6.22.1 -> 2022.6.29
https://github.com/yt-dlp/yt-dlp/releases/tag/2022.06.29
(cherry picked from commit 910a91e05c)
2022-06-29 06:43:56 +00:00
Martin Weinelt
394262ca64 Merge pull request #179367 from mweinelt/22.05/mozilla 2022-06-29 03:02:05 +02:00
Vladimír Čunát
94cbbfed27 thunderbird-bin: 91.10.0 -> 91.11.0
https://www.thunderbird.net/en-US/thunderbird/91.11.0/releasenotes/
(cherry picked from commit 2ca9969237)
2022-06-29 00:18:00 +00:00
Vladimír Čunát
1a1d38ef4b thunderbird: 91.10.0 -> 91.11.0
https://www.thunderbird.net/en-US/thunderbird/91.11.0/releasenotes/
(cherry picked from commit caeb46375d)
2022-06-29 00:18:00 +00:00
github-actions[bot]
a8127f1814 Merge staging-next-22.05 into staging-22.05 2022-06-29 00:15:43 +00:00
github-actions[bot]
e33c6966df Merge release-22.05 into staging-next-22.05 2022-06-29 00:15:00 +00:00
Max
754b9ff77e nixos/tests/ipfs: Simplify FUSE test
Co-authored-by: Luflosi <Luflosi@users.noreply.github.com>
(cherry picked from commit 664dab9574)
2022-06-28 17:01:02 +00:00
Max
85aca560fe nixos/ipfs: test FUSE mount
(cherry picked from commit 699e389f83)
2022-06-28 17:01:02 +00:00
Max
a849652e30 nixos/ipfs: Only set ReadWritePaths when hardened
Co-authored-by: Luflosi <Luflosi@users.noreply.github.com>
(cherry picked from commit 72d6d73e37)
2022-06-28 17:01:01 +00:00
Martin Weinelt
babb041b71 Merge pull request #179448 from NixOS/backport-179447-to-release-22.05 2022-06-28 18:28:13 +02:00
Maximilian Bosch
e119cc9499 matrix-synapse: 1.61.0 -> 1.61.1
ChangeLog: https://github.com/matrix-org/synapse/releases/tag/v1.61.1
(cherry picked from commit 89d1b48eb5)
2022-06-28 14:58:38 +00:00
R. Ryantm
7de6d47c6a jenkins: 2.332.3 -> 2.346.1
(cherry picked from commit 369740a281)
2022-06-28 16:35:19 +02:00
Robert Hensing
e41e56e817 Merge pull request #179427 from NixOS/backport-174176-to-release-22.05
[Backport release-22.05] haskellPackages: Add buildFromCabalSdist (faster, tested)
2022-06-28 15:05:55 +02:00
Robert Hensing
0600591b73 pkgs.tests.haskell.cabalSdist: Avoid IFD
(cherry picked from commit 392fba1132)
2022-06-28 08:11:37 +00:00
Robert Hensing
f6911ed5e1 haskellPackages: Add buildFromCabalSdist (faster, tested)
(cherry picked from commit cf5e2d5103)
2022-06-28 08:11:37 +00:00
Luke Worth
2bd1a2604b awscli2: 2.7.8 -> 2.7.9
(cherry picked from commit a25847ddaa)
2022-06-28 00:19:55 +00:00
Luke Worth
b15485ffda awscli2: fix python dependency versions
(cherry picked from commit e47202775f)
2022-06-28 00:19:50 +00:00
Bryan A. S
95878b7bb4 awscli2: 2.7.3 -> 2.7.8
(cherry picked from commit a58388770e)
2022-06-28 00:19:44 +00:00
Bryan A. S
9f8393dff0 awscli2: 2.5.6 -> 2.7.3
- upgrade package

- test overrides

- add myself as maintainer

(cherry picked from commit 43e661da40)
2022-06-28 00:19:36 +00:00
github-actions[bot]
9e64750af8 Merge staging-next-22.05 into staging-22.05 2022-06-28 00:17:46 +00:00
github-actions[bot]
a5a85e612b Merge release-22.05 into staging-next-22.05 2022-06-28 00:17:12 +00:00
Robert Schütz
bb82c715e4 conan: 1.47.0 -> 1.49.0
(cherry picked from commit fe8a3f1ff8)

Reason: conan-1.47 is affected by CVE-2022-29217, via old pinned pyjwt,
upgrading conan allows using newer, unaffected pyjwt.
2022-06-27 15:06:49 -07:00
Sandro Jäckel
59dbe711de python310Packages.pyjwt: 2.3.0 -> 2.4.0
(cherry picked from commit a02ab4d6ae)

Reason: pyjwt-2.4.0 is not affected by CVE-2022-29217.
2022-06-27 15:06:49 -07:00
Bjørn Forsman
389babbdd4 Revert "python310Packages.pyjwt: fix CVE-2022-29217"
This reverts commit 764759283d.

The next commit will upgrade to pyjwt-2.4, which is not affected by the
CVE.
2022-06-27 15:06:49 -07:00
Maximilian Bosch
5427667e2d wiki-js: 2.5.284 -> 2.5.285
ChangeLog: https://github.com/requarks/wiki/releases/tag/v2.5.285
(cherry picked from commit 137e9a6316)
2022-06-27 20:05:59 +00:00
Martin Weinelt
133fdc6d62 spidermonkey_91: 91.10.0 -> 91.11.0
(cherry picked from commit d3d7ea1ace)
2022-06-27 21:35:20 +02:00
Martin Weinelt
8716f4349b firefox-beta-bin-unwrapped: 102.0b5 -> 102.0b9
(cherry picked from commit 71c17fd17f)
2022-06-27 21:35:19 +02:00
Martin Weinelt
69dcd3d791 firefox-devedition-unwrapped: 102.0b6 -> 102.0b9
(cherry picked from commit 46f9c89390)
2022-06-27 21:35:18 +02:00
R. Ryantm
27d6a8a37f firefox-devedition-bin-unwrapped: 102.0b5 -> 102.0b6
(cherry picked from commit 3cd8c2f457)
2022-06-27 21:35:17 +02:00
Martin Weinelt
71e855844c firefox-esr-91-unwrapped: 91.10.0esr -> 91.11.0esr
https://www.mozilla.org/en-US/firefox/91.11.0/releasenotes/
(cherry picked from commit ddc17118f0)
2022-06-27 21:35:16 +02:00
Martin Weinelt
32b0554add firefox-esr-102-unwrapped: init at 102.0esr
https://www.mozilla.org/en-US/firefox/102.0/releasenotes/
(cherry picked from commit 1832364599)
2022-06-27 21:35:15 +02:00
Martin Weinelt
f39a701d50 firefox-bin-unwrapped: 101.0.1 -> 102.0
https://www.mozilla.org/en-US/firefox/102.0/releasenotes/
(cherry picked from commit 32b18b77bd)
2022-06-27 21:35:14 +02:00
Martin Weinelt
155b2e6685 firefox-unwrapped: 101.0.1 -> 102.0
https://www.mozilla.org/en-US/firefox/102.0/releasenotes/
(cherry picked from commit 736555d08f)
2022-06-27 21:35:10 +02:00
ajs124
6e8e204a54 cacert: 3.77 -> 3.80
(cherry picked from commit 04be37dead)
2022-06-27 13:59:15 +00:00
ajs124
5e11276cc8 nss_latest: 3.79 -> 3.80
https://github.com/nss-dev/nss/blob/master/doc/rst/releases/nss_3_80.rst
(cherry picked from commit 2999d0186f)
2022-06-27 13:59:15 +00:00
Martin Weinelt
62de360d75 Merge pull request #179325 from NixOS/backport-178809-to-release-22.05
[Backport release-22.05] nss_latest: 3.79 -> 3.80
2022-06-27 15:09:18 +02:00
06kellyjac
e0d71e288b busybox: patch CVE-2022-30065
https://nvd.nist.gov/vuln/detail/CVE-2022-30065
(cherry picked from commit 44e9c8ce2e37ff9effc07199b0b60c6af22dfd61)
2022-06-27 11:50:54 +00:00
ajs124
b257b15ebc nss_latest: 3.79 -> 3.80
https://github.com/nss-dev/nss/blob/master/doc/rst/releases/nss_3_80.rst
(cherry picked from commit 0bd02d1963)
2022-06-27 11:38:13 +00:00
Florian Klink
621a3f9aaf Merge pull request #178830 from Madouura/release/zfs
[Backport release-22.05] zfs: 2.1.4 -> 2.1.5
2022-06-27 10:12:26 +07:00
github-actions[bot]
07b4c9e797 Merge staging-next-22.05 into staging-22.05 2022-06-27 00:16:28 +00:00
github-actions[bot]
1de15d789d Merge release-22.05 into staging-next-22.05 2022-06-27 00:15:57 +00:00
Mario Rodas
ce07108125 Merge pull request #179116 from NixOS/backport-179052-to-release-22.05
[Backport release-22.05] peertube: 4.2.0 -> 4.2.1
2022-06-26 16:34:51 -05:00
Vladimír Čunát
54780bc6e4 Merge branch 'staging-22.05' into staging-next-22.05 2022-06-26 22:49:21 +02:00
Lassulus
cd90e773ea Merge pull request #179217 from NixOS/backport-179168-to-release-22.05
[Backport release-22.05] Revert "nixos/hedgedoc: Do not set StateDirectory to an absolute path"
2022-06-26 19:49:46 +02:00
Yaya
16dd6b905d Revert "nixos/hedgedoc: Do not set StateDirectory to an absolute path"
(cherry picked from commit 57617daaff)
2022-06-26 17:11:16 +00:00
Lassulus
9d9bc0e9f1 Merge pull request #179202 from NixOS/backport-179198-to-release-22.05
[Backport release-22.05] extra-container: 0.8 -> 0.10
2022-06-26 18:23:00 +02:00
Erik Arvstedt
b761627947 extra-container: 0.8 -> 0.10
(cherry picked from commit ca12710b06)
2022-06-26 15:52:47 +00:00
Thiago Kenji Okada
c0c86bc4c7 Merge pull request #179185 from NixOS/backport-179175-to-release-22.05
[Backport release-22.05] nixos/fontconfig: add fonts.fontconfig.hinting.style option
2022-06-26 13:12:07 +01:00
Thiago Kenji Okada
47421ff4e6 nixos/fontconfig: add fonts.fontconfig.hinting.style option
(cherry picked from commit 659096dd89)
2022-06-26 11:59:08 +00:00
Bernardo Meurer
4a155658a7 Merge pull request #179106 from NixOS/backport-178486-to-release-22.05
[Backport release-22.05] octoprint.python.pkgs.stlviewer: fix build
2022-06-25 21:57:20 -07:00
github-actions[bot]
bfc6088781 Merge staging-next-22.05 into staging-22.05 2022-06-26 00:17:36 +00:00
github-actions[bot]
b216a1c56d Merge release-22.05 into staging-next-22.05 2022-06-26 00:17:05 +00:00
Martin Weinelt
72a1f16707 Merge pull request #179031 from NixOS/backport-178917-to-release-22.05 2022-06-26 01:24:58 +02:00
Martin Weinelt
6a1b85f83f Merge pull request #178890 from NixOS/backport-177679-to-release-22.05 2022-06-26 01:09:07 +02:00
Martin Weinelt
b3413c7e08 Merge pull request #178980 from NixOS/backport-178797-to-release-22.05 2022-06-26 01:08:15 +02:00
Izorkin
dbf69f2f47 peertube: 4.2.0 -> 4.2.1
(cherry picked from commit b200beb196)
2022-06-25 22:57:14 +00:00
Felix Buehler
dd4d402f7d octoprint.python.pkgs.stlviewer: fix build
(cherry picked from commit 3e5042d4ff)
2022-06-25 22:06:50 +00:00
M. A
ae1a623f1d gitlab: 15.0.2 -> 15.1.0
https://about.gitlab.com/releases/2022/06/22/gitlab-15-1-released/
(cherry picked from commit 8ae568df326a860aaec1b8af0da8069770831fd3)
2022-06-25 23:29:36 +02:00
talyz
20a2143749 nixos/gitlab: Use Git 2.35.x to work around git bug
Git 2.36.1 seemingly contains a commit-graph related bug which is
easily triggered through GitLab, so let's downgrade it to 2.35.x until
this issue is solved. See
https://gitlab.com/gitlab-org/gitlab/-/issues/360783#note_992870101.

(cherry picked from commit f94d14899d70150abcf2823e243524397b0c1806)
2022-06-25 23:29:11 +02:00
Kim Lindberger
5ec2af9f48 Merge pull request #179033 from NixOS/backport-178703-to-release-22.05
[Backport release-22.05] nomachine-client: 7.9.2 -> 7.10.1
2022-06-25 19:07:22 +02:00
talyz
2b204dd582 nomachine-client: 7.9.2 -> 7.10.1
(cherry picked from commit 9e57dde15b)
2022-06-25 15:23:52 +00:00
R. Ryantm
ea404b57fd apko: 0.3.3 -> 0.4.0
(cherry picked from commit eeb3e707ff)
2022-06-25 15:22:57 +00:00
Thiago Kenji Okada
9f832703fc runitor: remove unnecessary input 2022-06-25 16:03:56 +01:00
kilianar
eef56552bd signal-desktop: 5.46.0 -> 5.47.0
(cherry picked from commit 956560470b)
2022-06-25 10:29:02 +00:00
Mario Rodas
7a1700745c Merge pull request #178763 from NixOS/backport-178609-to-release-22.05
[Backport release-22.05] packer: 1.8.1 -> 1.8.2
2022-06-24 21:24:06 -05:00
github-actions[bot]
a41e9792bb Merge staging-next-22.05 into staging-22.05 2022-06-25 00:15:26 +00:00
github-actions[bot]
3b9e4c45af Merge release-22.05 into staging-next-22.05 2022-06-25 00:14:55 +00:00
Berk D. Demir
6902545bde runitor: 0.9.2 -> 0.10.1
- New functionality
- No breaking changes
- Requires Go 1.18

0.9.2  -> 0.10.0
(cherry picked from commit ca0e288de3)

0.10.0 -> 0.10.1
(cherry picked from commit 1f9c7f3393)
2022-06-24 21:22:34 +00:00
Francesco Gazzetta
5465f42fef vengi-tools: 0.0.18 -> 0.0.20
(cherry picked from commit 5e52fdf6f6)
2022-06-24 19:32:46 +00:00
Vladimír Čunát
9417c06976 Merge #178682: thunderbird*: 91.9.1 -> 91.10.0
...into release-22.05
2022-06-24 18:11:22 +02:00
Martin Weinelt
5bc6c48038 Merge pull request #178871 from NixOS/backport-178865-to-release-22.05 2022-06-24 16:15:48 +02:00
Martin Weinelt
99da275fce python3Packages.django-prometheus: fix 2.2.0 update
(cherry picked from commit 67cd38b519)
2022-06-24 14:05:13 +00:00
Bobby Rong
414e29d739 Merge pull request #178849 from NixOS/backport-178362-to-release-22.05
[Backport release-22.05] gnonograms: 2.0.0 -> 2.1.2
2022-06-24 19:28:03 +08:00
Bobby Rong
2cf81883be Merge pull request #178757 from NixOS/backport-178648-to-release-22.05
[Backport release-22.05] github-runner: 2.293.0 -> 2.294.0
2022-06-24 18:30:21 +08:00
Francesco Gazzetta
ab5209df3a gnonograms: 2.0.0 -> 2.1.2
(cherry picked from commit 0b7337095a)
2022-06-24 08:50:10 +00:00
Madoura
5ba1aa2b0d release-notes: move zfs update from 22.11 to 22.05
(cherry picked from commit 93b55ffb00)
2022-06-24 03:08:08 -05:00
Lassulus
8c8d8e9bc6 Merge pull request #178799 from NixOS/backport-175287-to-release-22.05
[Backport release-22.05] rss-glx: fix build
2022-06-24 08:59:40 +02:00
Jörg Thalheim
c07754e400 Merge pull request #178680 from NixOS/backport-178586-to-release-22.05
[Backport release-22.05] nearcore: 1.26.1 -> 1.27.0
2022-06-24 07:57:30 +01:00
Mario Rodas
0b185e3ceb Merge pull request #178827 from NixOS/backport-174471-to-release-22.05
[Backport release-22.05] chafa: 1.8.0 -> 1.10.3
2022-06-24 01:29:21 -05:00
Mario Rodas
3aa2752ec5 Merge pull request #178677 from NixOS/backport-177764-to-release-22.05
[Backport release-22.05] peertube: 4.1.1 -> 4.2.0
2022-06-24 00:35:06 -05:00
Madoura
c0ab5fcb33 zfs: 2.1.4 -> 2.1.5
(cherry picked from commit 8cfcee74b1)
2022-06-24 00:08:39 -05:00
Bobby Rong
23b4a3506c Merge pull request #176894 from NixOS/backport-176880-to-release-22.05
[Backport release-22.05] nixos/ibus: fix services.dbus.package
2022-06-24 12:39:11 +08:00
Bobby Rong
fb5e1f7e54 Merge pull request #176698 from NixOS/backport-170063-to-release-22.05
[Backport release-22.05] prusa-slicer: use patched wxWidgets
2022-06-24 12:36:33 +08:00
Bobby Rong
136d1f620e Merge pull request #176488 from NixOS/backport-176326-to-release-22.05
[Backport release-22.05] mill: 0.10.3 → 0.10.4
2022-06-24 12:26:38 +08:00
R. Ryantm
e4d6859b52 chafa: 1.8.0 -> 1.10.3
(cherry picked from commit 24bb1b1c9a)
2022-06-24 04:13:44 +00:00
Bobby Rong
08e00ab738 Merge pull request #174326 from NixOS/backport-174274-to-release-22.05
[Backport release-22.05] octoprint: 1.8.0 -> 1.8.1
2022-06-24 12:00:37 +08:00
Anderson Torres
cf7ea1fadb Merge pull request #178752 from NixOS/backport-178259-to-release-22.05
[Backport release-22.05] freecad: 0.19.2 -> 0.20
2022-06-23 21:55:25 -03:00
github-actions[bot]
8680873b35 Merge staging-next-22.05 into staging-22.05 2022-06-24 00:15:15 +00:00
github-actions[bot]
fac1f86e46 Merge release-22.05 into staging-next-22.05 2022-06-24 00:14:40 +00:00
Eelco Dolstra
822504c5ca Merge pull request #178765 from NixOS/backport-178755-to-staging-22.05
[Backport staging-22.05] Fix pkgsStatic.libzip
2022-06-24 00:37:37 +02:00
Michael Weiss
eed42b33ca Merge pull request #178789 from NixOS/backport-178645-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 102.0.5005.115 -> 103.0.5060.53
2022-06-23 23:25:13 +02:00
Azat Bahawi
c47cd973b6 rss-glx: fix build
(cherry picked from commit 8b501a1089)
2022-06-23 21:13:53 +00:00
Maximilian Bosch
158a9eba0e Merge pull request #178745 from NixOS/backport-178709-to-release-22.05
[Backport release-22.05] Linux kernel updates 2022-06-23
2022-06-23 21:56:10 +02:00
Michael Weiss
5acbf8169b ungoogled-chromium: 102.0.5005.115 -> 103.0.5060.53
(cherry picked from commit dd9c01a9af)
2022-06-23 19:50:56 +00:00
Shea Levy
ccf8bdf726 Merge pull request #178769 from NixOS/backport-178731-to-release-22.05
[Backport release-22.05] Fix isabelle on darwin
2022-06-23 14:01:46 -04:00
Shea Levy
9c7f0f1f1e isabelle: Fix build on darwin
(cherry picked from commit c4f2260cdb)
2022-06-23 17:46:08 +00:00
Shea Levy
070775d3b2 z3_4_4_0: Fix build on darwin.
(cherry picked from commit 4d781f329d)
2022-06-23 17:46:08 +00:00
Shea Levy
02fb5dc242 gcc49: Fix build on darwin
(cherry picked from commit 8e6206f9c9)
2022-06-23 17:46:08 +00:00
06kellyjac
303a685e08 python310Packages.pip: 22.0.4 -> 22.1.2
(cherry picked from commit 6e20d752b6)
2022-06-23 17:08:55 +00:00
Eelco Dolstra
0d9095e4c7 libzip: Fix static build
Don't build the regression tests because they don't build with
pkgsStatic and are not executed anyway.

(cherry picked from commit b97f46c807)
2022-06-23 17:07:16 +00:00
techknowlogick
b35a6c8679 packer: 1.8.1 -> 1.8.2
(cherry picked from commit 7440b6aa3eb58e9167220b51d69e9509101f9816)
2022-06-23 16:43:14 +00:00
Martin Weinelt
1a35bcca26 networkmanager: Apply several fixes for OWE
The patches have already landed on main and are considered for
backporting to 1.38.x.

https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/1259
(cherry picked from commit 010c4593c7)
2022-06-23 16:24:40 +00:00
Alex Martens
8235086f3d github-runner: 2.293.0 -> 2.294.0
(cherry picked from commit 30820de671)
2022-06-23 16:10:14 +00:00
Nicolas Benes
2aafdfa554 freecad: 0.19.2 -> 0.20
(cherry picked from commit 7ca0fb42c6057ea2ab436c88608e942e49a027e4)
2022-06-23 15:33:50 +00:00
Maximilian Bosch
3e6c6662dc linux_testing_bcachefs: mark as broken
Doesn't build with Linux 5.18, but we have to remove 5.17 now because
it's EOL.

(cherry picked from commit 7ff7153c22)
2022-06-23 15:13:12 +00:00
Maximilian Bosch
67e6855213 linux_5_17: remove
(cherry picked from commit f0e3e98377)
2022-06-23 15:13:12 +00:00
Maximilian Bosch
a5ffbf1cc4 linux/hardened/patches/5.4: 5.4.198-hardened1 -> 5.4.200-hardened1
(cherry picked from commit 1d833f1783)
2022-06-23 15:13:12 +00:00
Maximilian Bosch
02ec3702bf linux/hardened/patches/5.18: 5.18.3-hardened1 -> 5.18.6-hardened1
(cherry picked from commit 80caa72602)
2022-06-23 15:13:12 +00:00
Maximilian Bosch
9dcd1c83f4 linux/hardened/patches/5.15: 5.15.47-hardened1 -> 5.15.49-hardened1
(cherry picked from commit 14ad08aee4)
2022-06-23 15:13:12 +00:00
Maximilian Bosch
5ca61cfc57 linux/hardened/patches/5.10: 5.10.122-hardened1 -> 5.10.124-hardened1
(cherry picked from commit 500dff12fe)
2022-06-23 15:13:12 +00:00
Maximilian Bosch
10200a828a linux/hardened/patches/4.19: 4.19.247-hardened1 -> 4.19.248-hardened1
(cherry picked from commit d450bf294a)
2022-06-23 15:13:12 +00:00
Maximilian Bosch
fed2039371 linux/hardened/patches/4.14: 4.14.283-hardened1 -> 4.14.284-hardened1
(cherry picked from commit 0fc1333d75)
2022-06-23 15:13:12 +00:00
Maximilian Bosch
d22112274e linux_latest-libre: 18777 -> 18798
(cherry picked from commit efdcc5f6a8)
2022-06-23 15:13:12 +00:00
Maximilian Bosch
3fdbe25ed2 linux: 5.4.198 -> 5.4.200
(cherry picked from commit 4051ac2d8e)
2022-06-23 15:13:12 +00:00
Maximilian Bosch
394bc05864 linux: 5.18.4 -> 5.18.6
(cherry picked from commit a266f7808b)
2022-06-23 15:13:12 +00:00
Maximilian Bosch
e94429d9b5 linux: 5.15.47 -> 5.15.49
(cherry picked from commit ca439ff6a6)
2022-06-23 15:13:12 +00:00
Maximilian Bosch
e05ee3941b linux: 5.10.122 -> 5.10.124
(cherry picked from commit 66e572d984)
2022-06-23 15:13:12 +00:00
Maximilian Bosch
ae8d8cb97d linux: 4.9.318 -> 4.9.319
(cherry picked from commit 34952774df)
2022-06-23 15:13:12 +00:00
Maximilian Bosch
60f8d1fe07 linux: 4.19.247 -> 4.19.248
(cherry picked from commit 2341a8672d)
2022-06-23 15:13:11 +00:00
Maximilian Bosch
d574e600a0 linux: 4.14.283 -> 4.14.284
(cherry picked from commit d7c1e34aa0)
2022-06-23 15:13:11 +00:00
Lassulus
0bdc2d2e9d Merge pull request #178635 from NixOS/backport-178462-to-staging-22.05 2022-06-23 16:06:37 +02:00
Bobby Rong
b824c03c89 Merge pull request #178618 from NixOS/backport-177673-to-release-22.05
[Backport release-22.05] discord-sh: init at unstable-2022-05-19
2022-06-23 19:24:08 +08:00
Bobby Rong
d2572960b9 Merge pull request #178619 from NixOS/backport-172373-to-release-22.05
[Backport release-22.05] tinystatus: init at unstable-2021-07-09
2022-06-23 19:23:36 +08:00
Martin Weinelt
ecea31c4f1 thunderbird-bin-unwrapped: 91.9.1 -> 91.10.0
https://www.thunderbird.net/en-US/thunderbird/91.10.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-22/

Fixes: CVE-2022-31736, CVE-2022-31737, CVE-2022-31738, CVE-2022-31739,
       CVE-2022-31740, CVE-2022-31741, CVE-2022-1834, CVE-2022-31742,
       CVE-2022-31747
(cherry picked from commit ef49524ebb)
2022-06-23 05:50:20 +00:00
Martin Weinelt
ae16c7fd64 thunderbird-unwrapped: 91.9.1 -> 91.10.0
https://www.thunderbird.net/en-US/thunderbird/91.10.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-22/

Fixes: CVE-2022-31736, CVE-2022-31737, CVE-2022-31738, CVE-2022-31739,
       CVE-2022-31740, CVE-2022-31741, CVE-2022-1834, CVE-2022-31742,
       CVE-2022-31747
(cherry picked from commit 3a0fa6aabe)
2022-06-23 05:50:20 +00:00
Jörg Thalheim
96250714c8 nearcore: 1.26.1 -> 1.27.0
(cherry picked from commit a4ec26f670)
2022-06-23 05:30:16 +00:00
Bobby Rong
58a0bb2433 Merge pull request #178663 from NixOS/backport-178524-to-release-22.05
[Backport release-22.05] gnome.aisleriot: update source sha256
2022-06-23 13:27:07 +08:00
Izorkin
0a5f4cce20 peertube: 4.1.1 -> 4.2.0
(cherry picked from commit 3b48948616)
2022-06-23 04:56:39 +00:00
Mario Rodas
f52ebe1bf0 Merge pull request #178033 from MrTarantoga/backport-177021-to-release-22.05
[Backport release-22.05]  RStudio: 1.4.1717 -> 2022.02.3+492
2022-06-22 21:57:48 -05:00
R. Ryantm
4e82d3dc07 gnome.aisleriot: update source sha256
Upstream re-tagged 3.22.23 and 3.22.24:

- https://gitlab.gnome.org/GNOME/aisleriot/-/issues/937

A direct comparison:

- 3.22.23: 730f7feb48..9c89b68662
- 3.22.24: 21a6d3c8e6..b9cd13873b

The following commits are no longer presented on 3.22.24:

- 9c89b68662...c18c1797d4
- e4e55fd282...730f7feb48
- 7ed4c8c9a3...21a6d3c8e6

The following commits are no longer part of 3.22.23 but still part of 3.22.24:

- 301fa2700d...78c53b7aea

(cherry picked from commit 2573b8bcc5)
2022-06-23 01:57:44 +00:00
Shea Levy
39f63ea704 Merge pull request #178636 from NixOS/backport-178627-to-release-22.05
[Backport release-22.05] veriT: Fix build on macos
2022-06-22 20:46:35 -04:00
Robert Schütz
80beb79660 python310Packages.bottle: 0.12.19 -> 0.12.21
fixes CVE-2022-31799

(cherry picked from commit a4afd6aa1e)
2022-06-23 00:42:57 +00:00
github-actions[bot]
a2629b7bda Merge staging-next-22.05 into staging-22.05 2022-06-23 00:14:37 +00:00
github-actions[bot]
3f93db832f Merge release-22.05 into staging-next-22.05 2022-06-23 00:13:58 +00:00
Michael Weiss
290b2d3f24 Merge pull request #178503 from NixOS/backport-178489-to-release-22.05
[Backport release-22.05] chromium: 102.0.5005.115 -> 103.0.5060.53
2022-06-23 00:04:23 +02:00
Robert Schütz
bd12dea783 prs: 0.3.2 -> 0.3.4
https://gitlab.com/timvisee/prs/-/blob/v0.3.4/CHANGELOG.md

fixes: CVE-2020-36205, CVE-2021-45707
(cherry picked from commit c777fbbf5d)
2022-06-22 21:09:14 +00:00
ajs124
cbff2daf56 Merge pull request #178602 from NixOS/backport-174022-to-release-22.05
[Backport release-22.05] panotools: 2.9.20 -> 2.9.21
2022-06-22 22:54:58 +02:00
ajs124
8e7c9d24d2 Merge pull request #178595 from NixOS/backport-178403-to-release-22.05
[Backport release-22.05] rt: 5.0.1 -> 5.0.2
2022-06-22 22:54:21 +02:00
Hernan Rajchert
44e23e4c20 veriT: Fix build on macos
(cherry picked from commit ef22f5fd93)
2022-06-22 20:53:05 +00:00
Martin Weinelt
0a7e76c141 openssl_3_0: 3.0.3 -> 3.0.4
Fixes additional sanitization issues in the c_rehash script.

https://mta.openssl.org/pipermail/openssl-announce/2022-June/000227.html

Fixes: CVE-2022-2068
(cherry picked from commit deb8ef1162)
2022-06-22 20:53:00 +00:00
Martin Weinelt
591e1fd446 openssl_1_1: 1.1.1o -> 1.1.1p
Fixes additional sanitization issues in the c_rehash script.

https://mta.openssl.org/pipermail/openssl-announce/2022-June/000226.html

Fixes: CVE-2022-2068
(cherry picked from commit 0c21382922)
2022-06-22 20:53:00 +00:00
Pascal Bach
2ac30140a6 Merge pull request #178577 from NixOS/backport-178404-to-release-22.05
[Backport release-22.05] nextcloud: 23.0.5 -> 23.0.6, 24.0.1 -> 24.0.2
2022-06-22 22:07:45 +02:00
matthewcroughan
05c65cd364 tinystatus: init at unstable-2021-07-09
Co-authored-by: j-k <dev@j-k.io>

Co-authored-by: ckie <25263210+ckiee@users.noreply.github.com>
(cherry picked from commit 294742618e)
2022-06-22 19:23:09 +00:00
matthewcroughan
27630a8f03 discord-sh: init at unstable-2022-05-19
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit b96b41d2a8)
2022-06-22 19:22:31 +00:00
Lassulus
389f6cd659 Merge pull request #178607 from NixOS/backport-177077-to-release-22.05
[Backport release-22.05] nixos/bitlbee: allow writing to configDir
2022-06-22 21:14:31 +02:00
Lassulus
13ef8a5a36 Merge pull request #178604 from NixOS/backport-178314-to-release-22.05
[Backport release-22.05] ergochat: 2.9.1 -> 2.10.0
2022-06-22 21:13:44 +02:00
Lassulus
df5f5c74df Merge pull request #178608 from NixOS/backport-177536-to-release-22.05
[Backport release-22.05] nixos/hedgedoc: Do not set StateDirectory to an absolute path
2022-06-22 21:05:39 +02:00
Vladimír Čunát
d3c76e453b Merge #177716: staging-next-22.05 - iteration 2 2022-06-22 19:45:15 +02:00
M. A
4bab5cf047 nixos/hedgedoc: Do not set StateDirectory to an absolute path
Commit 8109d8a set the `StateDirectory=` option of the systemd service
configuration to the value of `cfg.workDir` which is wrong, according
to dasJ [1]. This commit resolves this issue by stripping the
`/var/lib/` prefix from `cfg.workDir`.

[1] https://github.com/NixOS/nixpkgs/pull/172824#issuecomment-1130350412

(cherry picked from commit becff58579)
2022-06-22 17:36:16 +00:00
lassulus
06943de3ec nixos/bitlbee: allow writing to configDir
(cherry picked from commit a12e525410)
2022-06-22 17:35:04 +00:00
lassulus
9cc44356e2 ergochat: 2.9.1 -> 2.10.0
(cherry picked from commit 7e68dc4d9b)
2022-06-22 17:18:04 +00:00
Thomas Gerbet
605a3a2ec2 panotools: 2.9.20 -> 2.9.21
Fixes CVE-2021-33293

https://sourceforge.net/projects/panotools/files/libpano13/libpano13-2.9.21/
(cherry picked from commit c3182eace3)
2022-06-22 17:09:36 +00:00
Thomas Gerbet
a9fb7fe7c4 metabase: 0.42.1 -> 0.43.1
Fixes CVE-2022-24853, CVE-2022-24854 and CVE-2022-24855

https://github.com/metabase/metabase/releases/tag/v0.43.1
https://github.com/metabase/metabase/releases/tag/v0.43.0
(cherry picked from commit fa22eab4c1)
2022-06-22 16:41:45 +00:00
Gary Wan
c2b72f939a rt: 5.0.1 -> 5.0.2
(cherry picked from commit 5301f37392)
2022-06-22 16:34:30 +00:00
Brian Leung
c00acc6747 kitty: 0.25.1 -> 0.25.2
(cherry picked from commit 6bd65099b6)
2022-06-22 09:03:58 -07:00
adisbladis
21321a6381 Merge pull request #178580 from NixOS/backport-178458-to-release-22.05
[Backport release-22.05] crun: Don't use hard-coded /usr/bin paths
2022-06-22 23:16:19 +08:00
adisbladis
09fc2817de crun: Don't use hard-coded /usr/bin paths
The paths to newuidmap & newgidmap are currently hard-coded in the binary.

(cherry picked from commit e53c4b9205)
2022-06-22 14:38:09 +00:00
Robbert Gurdeep Singh
9bc5774891 nextcloud: 23.0.5 -> 23.0.6, 24.0.1 -> 24.0.2
(cherry picked from commit 376dfe8766)
2022-06-22 14:22:04 +00:00
Robert Hensing
795336437d doc: Fix config options reference file links
(cherry picked from commit 11b33fcdcc)
2022-06-22 13:53:56 +00:00
Robert Hensing
6798ade2ab make-options-doc: Support Nix-provided declaration links
Previously, the location logic was hardcoded, supporting only
Nixpkgs and NixOps properly, leaving other uses of the module
system without good location support.

(cherry picked from commit cee66a8cd5)
2022-06-22 13:53:56 +00:00
Lassulus
614ee6782d Merge pull request #175975 from NixOS/backport-173664-to-release-22.05
[Backport release-22.05] nixos/peertube: use redis.servers
2022-06-22 14:46:58 +02:00
Sandro
bd82e26c07 Merge pull request #175757 from NixOS/backport-175243-to-release-22.05 2022-06-22 14:37:13 +02:00
Mario Rodas
0cf5e39f02 Merge pull request #178556 from NixOS/backport-178516-to-release-22.05
[Backport release-22.05] yt-dlp: 2022.05.18 -> 2022.6.22.1
2022-06-22 06:05:12 -05:00
zowoq
b461bd584d yt-dlp: 2022.05.18 -> 2022.6.22.1
https://github.com/yt-dlp/yt-dlp/releases/tag/2022.06.22
https://github.com/yt-dlp/yt-dlp/releases/tag/2022.06.22.1
(cherry picked from commit cbbc9759b6)
2022-06-22 10:51:28 +00:00
github-actions[bot]
00fdf0263f Merge staging-next-22.05 into staging-22.05 2022-06-22 00:17:46 +00:00
github-actions[bot]
6a76de3c7d Merge release-22.05 into staging-next-22.05 2022-06-22 00:17:13 +00:00
Martin Weinelt
f91f4c0fb6 Merge pull request #178495 from NixOS/backport-178487-to-release-22.05 2022-06-21 23:59:51 +02:00
Michael Weiss
732182247e chromium: 102.0.5005.115 -> 103.0.5060.53
https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html

This update includes 14 security fixes.

CVEs:
CVE-2022-2156 CVE-2022-2157 CVE-2022-2158 CVE-2022-2160 CVE-2022-2161
CVE-2022-2162 CVE-2022-2163 CVE-2022-2164 CVE-2022-2165

(cherry picked from commit de0f40f35b)
2022-06-21 21:48:16 +00:00
Michael Weiss
00a8a2bf1d Merge pull request #178490 from primeos/chromium-backport
[22.05] Prepare for backporting Chromium M103
2022-06-21 23:42:33 +02:00
Flakebi
7e87f78f0d salt: 3004.1 -> 3004.2
(cherry picked from commit c3cecf09fa)
2022-06-21 21:35:09 +00:00
Michael Weiss
7ca43ee102 chromiumDev: 104.0.5110.0 -> 104.0.5112.12
(cherry picked from commit b14fe90066)
2022-06-21 23:14:51 +02:00
Michael Weiss
ac331bfa2e chromiumBeta: 103.0.5060.42 -> 103.0.5060.53
(cherry picked from commit 4cda286925)
2022-06-21 23:14:50 +02:00
Michael Weiss
78dddd8504 chromiumDev: 104.0.5098.0 -> 104.0.5110.0
(cherry picked from commit b8190f93d5)
2022-06-21 23:14:50 +02:00
Michael Weiss
9248bfa199 chromiumBeta: 103.0.5060.33 -> 103.0.5060.42
(cherry picked from commit a4471b3a97)
2022-06-21 23:14:50 +02:00
Michael Weiss
3c16b78905 chromiumDev: 104.0.5083.0 -> 104.0.5098.0
(cherry picked from commit 83a028528c)
2022-06-21 23:14:49 +02:00
Michael Weiss
496afda7b4 chromiumBeta: 103.0.5060.24 -> 103.0.5060.33
(cherry picked from commit 2272153e49)
2022-06-21 23:14:49 +02:00
Michael Weiss
8f5a83170d chromiumDev: 103.0.5060.24 -> 104.0.5083.0
(cherry picked from commit 4f8cc4ba80)
2022-06-21 23:14:49 +02:00
Michael Weiss
ff02616d85 chromiumBeta: 102.0.5005.61 -> 103.0.5060.24
(cherry picked from commit 542dc1b5cd)
2022-06-21 23:14:49 +02:00
Michael Weiss
f1a49923a1 chromiumDev: 103.0.5060.13 -> 103.0.5060.24
(cherry picked from commit 44107eea55)
2022-06-21 23:14:48 +02:00
Michael Weiss
b079f0c39d chromiumDev: 103.0.5056.0 -> 103.0.5060.13
(cherry picked from commit f52ca60fd6)
2022-06-21 23:14:48 +02:00
Michael Weiss
95fc0b8010 chromiumBeta: 102.0.5005.49 -> 102.0.5005.61
(cherry picked from commit ba943bd907)
2022-06-21 23:14:48 +02:00
maxine [they]
eeb00a798b Merge pull request #178480 from NixOS/backport-178396-to-release-22.05 2022-06-21 22:04:36 +02:00
R. Ryantm
30d1a900b1 gnome.aisleriot: 3.22.23 -> 3.22.24
(cherry picked from commit 126c231c96619711cb3d4c978ce8769e4916a54e)
2022-06-21 20:02:53 +00:00
Pavol Rusnak
a9f6d7c87a Merge pull request #178466 from NixOS/backport-178443-to-release-22.05 2022-06-21 20:47:04 +02:00
Robert Hensing
ecef29b94b Merge pull request #177587 from NixOS/backport-176385-to-release-22.05
[Backport release-22.05] stdenv/adapters.nix: Fix for overlay style arguments
2022-06-21 19:00:59 +02:00
Pavol Rusnak
03dea20f59 eclipse.plugins.bytecode-outline: 2.5.0.201711011753-5a57fdf -> 1.0.1.202006062100
fix dead upstream urls, replace with new upstream

plugin has lower version because the versioning has been
restarted when the plugin namespace was changed from de.loskutov.BytecodeOutline
to org.eclipse.jdt.bcoview

(cherry picked from commit a40cc0e399)
2022-06-21 16:24:24 +00:00
Pavol Rusnak
bde79a8921 eclipse.plugins.anyedittools: 2.7.1.201709201439 -> 2.7.2.202006062100
fix dead upstream urls, replace with new upstream

(cherry picked from commit 1367f89a73)
2022-06-21 16:24:24 +00:00
Thiago Kenji Okada
bb5ff13d3e Merge pull request #178432 from NixOS/backport-176331-to-release-22.05
[Backport release-22.05] anime-downloader: init at 5.0.14
2022-06-21 16:57:45 +01:00
Robert Hensing
ec51c253bd Merge pull request #178435 from NixOS/backport-176324-to-release-22.05
[Backport release-22.05] doc/builders/images/dockertools: improve shadowSetup example
2022-06-21 14:42:29 +02:00
Maximilian Bosch
04d790825c Merge pull request #178001 from NixOS/backport-177993-to-release-22.05
[Backport release-22.05] mautrix-whatsapp: 0.4.0 -> 0.5.0
2022-06-21 14:31:47 +02:00
Mirco Bauer
086ddfabba doc/builders/images/dockertools: improve shadowSetup example
The example snippet will fail with this error as it is not self contained and
assumes `shadowSetup` was given:

    $ nix-build docker-image.nix
    error: undefined variable 'shadowSetup' at docker-image.nix:20:7

Instead use the full reference to `shadowSetup` in the example so it will work
as stated.

(cherry picked from commit ac66ff97ed)
2022-06-21 12:29:56 +00:00
WeebSorceress
68c0875cc5 anime-downloader: init at 5.0.14
(cherry picked from commit 41b5af8b65)
2022-06-21 12:05:35 +00:00
maxine [they]
9203724333 Merge pull request #178416 from NixOS/backport-177784-to-release-22.05
[Backport release-22.05] terraform: 1.2.2 -> 1.2.3
2022-06-21 11:10:40 +02:00
techknowlogick
afad2ad6e9 terraform: 1.2.2 -> 1.2.3
(cherry picked from commit 63055de8b7)
2022-06-21 09:01:42 +00:00
Robert Schütz
4b4a0539e1 archivebox: mark insecure
Django 3.1 has reached the end of extended support and all
vulnerabilities listed on [1] as affecting Django 3.2 should be assumed
to also affect Django 3.1.

[1]: https://www.djangoproject.com/weblog/2022/apr/11/security-releases/

(cherry picked from commit 067314d87f)
2022-06-21 06:02:16 +00:00
Robert Schütz
87c4c082c6 archivebox: update Django to 3.1.14
(cherry picked from commit aedd39d869)
2022-06-21 06:02:16 +00:00
github-actions[bot]
5d280f2ea2 Merge staging-next-22.05 into staging-22.05 2022-06-21 00:19:11 +00:00
github-actions[bot]
d7b1038227 Merge release-22.05 into staging-next-22.05 2022-06-21 00:18:38 +00:00
Kerstin
324f26c617 Merge pull request #178372 from NixOS/backport-178356-to-release-22.05
[Backport release-22.05] imagemagick: 7.1.0-37 -> 7.1.0-39
2022-06-21 01:01:51 +02:00
maralorn
f0bb7af8ad Merge pull request #178072 from NixOS/backport-178025-to-release-22.05
[Backport release-22.05] mailmanPackages.hyperkitty: fix build
2022-06-21 00:29:32 +02:00
Robert Schütz
950b0574fc imagemagick: 7.1.0-37 -> 7.1.0-39
(cherry picked from commit 7978240546)
2022-06-20 21:42:16 +00:00
Wout Mertens
12b804909f Merge pull request #178203 from NixOS/backport-178182-to-release-22.05
[Backport release-22.05] netdata: 1.34.1 -> 1.35.1
2022-06-20 22:52:11 +02:00
OPNA2608
71739af235 dmd: Fix grep in test after gdb bump
(cherry picked from commit 1ff67969b5)
2022-06-20 19:42:46 +02:00
Maximilian Bosch
487689b35d nixos/prometheus-postfix-exporter: fixes for systemd integration
* Allow the service to read from the journal w/systemd.enable
* Ensure that the service is started after postfix.service

(cherry picked from commit 1f9375b92e8236b4881f080e3b43d8db8db2dc68)
2022-06-20 17:37:00 +00:00
Pavol Rusnak
65a9d22c91 boost: use jfrog mirror instead of bintray
See https://www.boost.org/users/news/boost_has_moved_downloads_to_jfr.html
for more info

(cherry picked from commit f806c5114c0385242e4e35e0f29cd87dd0127315)
2022-06-20 19:28:13 +02:00
Maximilian Bosch
c67f5e4e20 strace: 5.17 -> 5.18
ChangeLog: https://github.com/strace/strace/releases/tag/v5.18
(cherry picked from commit a62e864c81)
2022-06-20 19:11:32 +02:00
David Reiss
44b7a871b1 nixos/pipewire: fix wireplumber with system-wide
(cherry picked from commit 33163bd0ef)
2022-06-20 19:08:47 +02:00
Patryk Wychowaniec
bc3470c382 clang-tools: provide many versions
(cherry picked from commit 7d817da1214236142c2ef505dfe3ac54bb128496)
2022-06-20 18:44:54 +02:00
Patryk Wychowaniec
d93a5bd155 clang-tools: don't hardcode list of tools
Currently clang-tools' derivation uses a hardcoded list of names to
distinguish between what's a compiler-like binary and what's a tool-like
binary (so that e.g. clang-tidy is included in the derivation, but
clang-13 - not).

Because Clang's tools follow a common naming convention
(clang-somethingsomething), I think it's easier if we just used a simple
regular expression in place of the hardcoded list.

(cherry picked from commit 706be2b272906963ec8fc75d717c11e220f1ba74)
2022-06-20 18:44:54 +02:00
Pavol Rusnak
095de0a1d3 Merge pull request #178330 from NixOS/backport-178235-to-release-22.05
[Backport release-22.05] jbake: 2.6.5 -> 2.6.7
2022-06-20 16:41:11 +02:00
Pavol Rusnak
6e8504748d Merge pull request #178331 from NixOS/backport-178236-to-release-22.05
[Backport release-22.05] ipe: 7.2.23 -> 7.2.24
2022-06-20 16:40:59 +02:00
Pavol Rusnak
259e79d764 Merge pull request #178329 from NixOS/backport-178272-to-release-22.05
[Backport release-22.05] asciidoctorj: 2.4.2 -> 2.5.4
2022-06-20 16:34:07 +02:00
Pavol Rusnak
269dd1ea6a ipe: 7.2.23 -> 7.2.24
(cherry picked from commit 41e6f56844)
2022-06-20 14:06:28 +00:00
Pavol Rusnak
2990bf771e jbake: 2.6.5 -> 2.6.7
(cherry picked from commit 4a178259ef)
2022-06-20 13:59:16 +00:00
Pascal Wittmann
f1603cb4db asciidoctorj: 2.4.2 -> 2.5.4
also addresses issue  #111896

(cherry picked from commit ed05243918)
2022-06-20 13:59:05 +00:00
Tobias Mayer
d423c0ce15 pkgsStatic.libunwind: fix build
(cherry picked from commit 596af32a582d81bf1731bc68940d914b322de3f8)
2022-06-20 12:47:28 +00:00
Bobby Rong
81254dd69a Merge pull request #178227 from kfollesdal/backport-177180-to-release-22.05
[Backport release-22.05] github-runner: 2.292.0 -> 2.293.0
2022-06-20 19:57:05 +08:00
Bobby Rong
a3a3af1df0 Merge pull request #178067 from NixOS/backport-177868-to-release-22.05
[Backport release-22.05] kdigger: init at 1.2.0
2022-06-20 12:47:46 +08:00
Bobby Rong
ded815c602 Merge pull request #177806 from NixOS/backport-177777-to-release-22.05
[Backport release-22.05] chain-bench: init at 0.0.2
2022-06-20 12:45:16 +08:00
github-actions[bot]
cf38dc9b47 Merge staging-next-22.05 into staging-22.05 2022-06-20 00:14:52 +00:00
github-actions[bot]
80b56f0ae2 Merge release-22.05 into staging-next-22.05 2022-06-20 00:14:15 +00:00
Mario Rodas
e6a15f517e Merge pull request #177026 from NixOS/backport-176898-to-release-22.05
[Backport release-22.05] poppler: 22.04.0 -> 22.06.0
2022-06-19 18:36:19 -05:00
Pavol Rusnak
e7902110a0 Merge pull request #178268 from NixOS/backport-178223-to-release-22.05 2022-06-19 21:34:52 +02:00
Robert Scott
cc0322f1fb Merge pull request #178230 from DeterminateSystems/liblouis-backport
[22.05] liblouis: apply patch for CVE-2022-26981
2022-06-19 20:07:58 +01:00
Pavol Rusnak
b7bd07ef8d tor: 0.4.7.7 -> 0.4.7.8
(cherry picked from commit e339c5a041)
2022-06-19 19:02:36 +00:00
Pascal Wittmann
5afb1b7dcf Merge pull request #178079 from NixOS/backport-178075-to-release-22.05
[Backport release-22.05] groovy: 3.0.7 -> 3.0.11
2022-06-19 14:50:53 +02:00
Eduard Bachmakov
171ae67908 strawberry: 1.0.4 -> 1.0.5
(cherry picked from commit 4c082bffac10e2b40a0d066843e8d3f71b5b8e2f)
2022-06-19 20:08:31 +08:00
Vladimír Čunát
3b0a83ac96 Merge #178220: unclutter-xfixes: fix cross-compilation
...into release-22.05
2022-06-19 12:07:47 +02:00
Alex Martens
e647b32309 github-runner: 2.292.0 -> 2.293.0
(cherry picked from commit 0df74af7a9)
2022-06-19 12:02:04 +02:00
Brian McKenna
5d3d42e067 unclutter-xfixes: fix cross-compilation
(cherry picked from commit a9bb8e4c98)
2022-06-19 09:21:05 +00:00
Vladimír Čunát
40624dd841 Merge #176751: ntfs3g: 2021.8.22 -> 2022.5.17
...into staging-next-22.05
2022-06-19 11:12:39 +02:00
Bobby Rong
c768396750 Merge pull request #178205 from NixOS/backport-178089-to-release-22.05
[Backport release-22.05] pantheon.elementary-files: 6.1.2 -> 6.1.3
2022-06-19 16:37:55 +08:00
Vladimír Čunát
474a25746a Revert #177937: graalvmXX-ce: use a patched version of zlib
This reverts commit 313331adfd, reversing
changes made to 091f72367a.
This is a backport of PR #178209; see there for more information, etc.
2022-06-19 09:00:45 +02:00
Bobby Rong
13ccaac700 pantheon.elementary-files: 6.1.2 -> 6.1.3
(cherry picked from commit 3e550d5cd2)
2022-06-19 05:12:23 +00:00
Izorkin
cc6a0436b5 netdata: 1.34.1 -> 1.35.1
(cherry picked from commit 095ed30363)
2022-06-19 04:47:51 +00:00
github-actions[bot]
34ad63fc64 Merge staging-next-22.05 into staging-22.05 2022-06-19 00:16:26 +00:00
github-actions[bot]
a7f8fa4dc0 Merge release-22.05 into staging-next-22.05 2022-06-19 00:15:49 +00:00
Francesco Gazzetta
8e590f22b5 zeronet-conservancy: add nixos test
(cherry picked from commit 3cfdd35ff6)
2022-06-18 23:39:33 +00:00
Francesco Gazzetta
5c3a4baf39 zeronet-conservancy: 0.7.5 -> 0.7.6
(cherry picked from commit 67eb7a1d55)
2022-06-18 23:39:33 +00:00
Robert Scott
57622cb817 Merge pull request #178030 from NixOS/backport-177812-to-release-22.05
[Backport release-22.05] python3Packages.pytorch: unbreak on Darwin
2022-06-18 21:43:07 +01:00
sternenseemann
4b1707c38e lowdown: 0.11.1 -> 1.0.0
Only minor changes:
edca6ce6d5/versions.xml (L1352-L1358)

(cherry picked from commit 5253f82b7bec521671409b39d7469efdc98e48a3)
2022-06-18 21:17:56 +02:00
Victor Fuentes
02257c62a2 calamares-nixos-extensions: 0.3.8 -> 0.3.10
(cherry picked from commit d5e616a3f4)
2022-06-18 20:54:17 +02:00
Victor Fuentes
a17a3845ad installation-cd: prevent gnome from sleeping
(cherry picked from commit 54fcba5b3b)
2022-06-18 20:54:17 +02:00
Victor Fuentes
bd8749bcc1 calamares: increase default verbosity
(cherry picked from commit 4b863a0256)
2022-06-18 20:54:17 +02:00
Victor Fuentes
91e813ba57 calamares: 3.2.57 -> 3.2.59
(cherry picked from commit c50f620c33)
2022-06-18 20:54:17 +02:00
Mario Rodas
7874a5a16e Merge pull request #177551 from ionutnechita/yandex-browser-nix-22.05
yandex-browser: 22.1.3.907-1 -> 22.5.0.1879-1
2022-06-18 10:42:11 -05:00
Bobby Rong
a95c91386f Merge pull request #178055 from NixOS/backport-178018-to-release-22.05
[Backport release-22.05] conftest: 0.32.0 -> 0.32.1
2022-06-18 22:48:16 +08:00
Bobby Rong
fb69287e50 Merge pull request #176682 from NixOS/backport-174138-to-release-22.05
[Backport release-22.05] github-runner: 2.291.1 -> 2.292.0
2022-06-18 22:30:06 +08:00
Bobby Rong
fc81c98348 Merge pull request #178063 from NixOS/backport-177950-to-release-22.05
[Backport release-22.05] vscodium: 1.68.0 -> 1.68.1
2022-06-18 22:22:05 +08:00
Bobby Rong
63860754fb Merge pull request #177985 from NixOS/backport-177959-to-release-22.05
[Backport release-22.05] signal-desktop: 5.45.1 -> 5.46.0
2022-06-18 22:16:17 +08:00
github-actions[bot]
f87de21d11 postgresql: 14.3 -> 14.4 (#177968)
(cherry picked from commit 124d0f2f8d420a6b5104dc2e944aac3ee793a921)

Co-authored-by: timothy <git@timothyklim.com>
2022-06-18 08:57:41 -05:00
maxine [they]
f91561da56 Merge pull request #177942 from NixOS/backport-177932-to-release-22.05
[Backport release-22.05] networkmanager: 1.38.0 -> 1.38.2
2022-06-18 11:07:36 +02:00
maxine [they]
4f66d1dd69 Merge pull request #178066 from NixOS/backport-177818-to-release-22.05
[Backport release-22.05] vscode: 1.68.0 -> 1.68.1
2022-06-18 11:07:30 +02:00
Daniel Løvbrøtte Olsen
2f361cb7e7 hydrus: 483 -> 488d (#177770)
Backport of:

- hydrus: 483 -> 484 (95191d4f61)
- hydrus: 484 -> 487 (dcfeb8a826)
- hydrus: 487 -> 488d (4ac196b95e)
2022-06-18 16:27:05 +08:00
Vladimír Čunát
fa233d368e Merge #177671: staging docs: explain that purple arrows are manual
...into release-22.05
2022-06-18 09:17:39 +02:00
Anderson Torres
dd54c73a7e Merge pull request #178074 from NixOS/backport-178028-to-release-22.05
[Backport release-22.05] Fix CHM format support in Calibre
2022-06-17 23:32:11 -03:00
github-actions[bot]
543f25cc77 Merge staging-next-22.05 into staging-22.05 2022-06-18 00:18:18 +00:00
github-actions[bot]
a9e6bcc244 Merge release-22.05 into staging-next-22.05 2022-06-18 00:17:40 +00:00
jacobtolar
721e822a1f groovy: 3.0.7 -> 3.0.11
(cherry picked from commit e449ba23ba)
2022-06-17 22:41:06 +00:00
Alexander Shpilkin
10ebb731ee calibre: fix chm processing dependency
(cherry picked from commit 7d883da22a)
2022-06-17 21:24:21 +00:00
Alexander Shpilkin
354b2a0b68 pythonPackages.pychm,python3Packages.pychm: init at 0.8.6
(cherry picked from commit a07a608342)
2022-06-17 21:24:21 +00:00
Kerstin
525b696376 Merge pull request #178060 from NixOS/backport-178009-to-release-22.05
[Backport release-22.05] gollum: 5.2.3 -> 5.3.0
2022-06-17 23:14:57 +02:00
Maximilian Bosch
50d63d1664 mailmanPackages.hyperkitty: fix build
Closes #177470

(cherry picked from commit e768893052)
2022-06-17 21:00:03 +00:00
06kellyjac
e5366801dc kdigger: init at 1.2.0
(cherry picked from commit 34c91d44c8)
2022-06-17 20:15:20 +00:00
nixpkgs-upkeep-bot
5a9a5c545f vscode: 1.68.0 -> 1.68.1
(cherry picked from commit 58b2655b4c)
2022-06-17 20:06:28 +00:00
nixpkgs-upkeep-bot
04574484d8 vscodium: 1.68.0 -> 1.68.1
(cherry picked from commit 1a0d8eebd7)
2022-06-17 19:43:08 +00:00
Benno Bielmeier
8926e9d73e gollum: fix shebang in bin/gollum
In the v5.3.0 release of gollum, the shebang in `bin/gollum` changed,
breaking the package build:
https://github.com/gollum/gollum/compare/v5.2.3..v5.3.0#diff-0108eafd2bcdf5151e078efec0119e63431569fca19b46660c9b8d9b7cdd6cf5R1

(cherry picked from commit d0af7c06ac)
2022-06-17 19:14:44 +00:00
Benno Bielmeier
902a25219a nixos/gollum: add option local-time
This feature was introduced in gollum v5.3.0

(cherry picked from commit be0e2db8b9)
2022-06-17 19:14:44 +00:00
Benno Bielmeier
fab1014ef3 nixos/gollum: improve description of user-icons option
(cherry picked from commit 9434ac0963)
2022-06-17 19:14:44 +00:00
Benno Bielmeier
79f48e6beb gollum: 5.2.3 → 5.3.0
(cherry picked from commit bed5ba3529)
2022-06-17 19:14:44 +00:00
Shea Levy
10065cfbfc linuxPackages.system76-io: 1.0.1 -> 1.0.2
(cherry picked from commit bce0ac2d35)
2022-06-17 19:09:17 +00:00
06kellyjac
b389f332ae conftest: 0.32.0 -> 0.32.1
(cherry picked from commit acddbacee4)
2022-06-17 18:29:48 +00:00
Anderson Torres
a15df1c131 Merge pull request #177996 from NixOS/backport-177567-to-release-22.05
[Backport release-22.05] palemoon: Limit build cores count
2022-06-17 13:33:14 -03:00
Goetz
d022c708c4 Fix not FHS paths
Create explicit nix path replacement of hard coded FHS paths for pandoc and nodejs.

(cherry picked from commit f4c5c86fbbe264d67e4eb416add0a7eee17d3f49)
2022-06-17 16:55:33 +02:00
Goetz
8b26bbf69a Remove Quarto patch
Follow review in
https://github.com/NixOS/nixpkgs/pull/177021#pullrequestreview-1007625773

(cherry picked from commit c758d73537a0eb256f5b069dbd3200cef75c3b76)
2022-06-17 16:55:17 +02:00
Goetz
4dcdd9b9bc RStudio: 1.4.1717 -> 2022.02.3+492
The old version does not compile with gcc11. Also the used nixos-22.05
libraries (R interpreter) have changed their interfaces that have to be
also patched. Updating RStudio is usefull.

(cherry picked from commit bbfc6883de78c44c1d59221668e4e6b396377389)
2022-06-17 16:52:54 +02:00
Malo Bourgon
a4fa94965a python3Packages.pytorch: unbreak on Darwin
* Add missing `buildInputs`.
* Enable Grand Central Dispatch support for `aarch64-darwin`.
* Remove `postFixup` steps for .dylib files that aren't present.

(cherry picked from commit c1d5efbee20eaf5a2748dbb5e08eaf304b7b3f34)
2022-06-17 14:40:25 +00:00
Maximilian Bosch
f919a40e54 Merge pull request #177990 from Ma27/backport-element
[22.05] element-{web,desktop}: 1.10.14 -> 1.10.15
2022-06-17 14:47:44 +02:00
Charlotte Van Petegem
c7c2ff3fc8 mautrix-whatsapp: 0.4.0 -> 0.5.0
https://github.com/mautrix/whatsapp/releases/tag/v0.5.0
(cherry picked from commit ab8b3a1c07)
2022-06-17 09:47:49 +00:00
adisbladis
d17a56d90e Merge pull request #177945 from NixOS/backport-177888-to-release-22.05
[Backport release-22.05] python3: fix wrong platform libs when cross-compiling
2022-06-17 17:04:48 +08:00
OPNA2608
527e23dde7 palemoon: Limit build cores count
Building with too many cores may be the cause of the build flakiness with OfBorg.
Upstream says <=32 cores should work fine, let's see if this helps.
https://forum.palemoon.org/viewtopic.php?f=5&t=28480

(cherry picked from commit 222fe563b9)
2022-06-17 08:42:24 +00:00
Maximilian Bosch
26f77c9cf7 element-{web,desktop}: 1.10.14 -> 1.10.15
ChangeLog web: https://github.com/vector-im/element-web/releases/tag/v1.10.15
ChangeLog desktop: https://github.com/vector-im/element-desktop/releases/tag/v1.10.15
2022-06-17 09:58:53 +02:00
Maximilian Bosch
0dc2b8cd11 Merge pull request #177943 from NixOS/backport-177867-to-release-22.05
[Backport release-22.05] Linux kernel updates 2022-06-16
2022-06-17 09:53:05 +02:00
Eduardo Quiros
ed4228ceee signal-desktop: 5.45.1 -> 5.46.0
(cherry picked from commit 523bed764c)
2022-06-17 07:28:18 +00:00
Anderson Torres
d76f540d9c Merge pull request #177974 from NixOS/backport-177928-to-staging-22.05
[Backport staging-22.05] uclibc-ng: 1.0.38 -> 1.0.41
2022-06-17 02:25:10 -03:00
AndersonTorres
4357e19eca uclibc-ng: 1.0.38 -> 1.0.41
Also
- Add AndersonTorres as maintainer
- Set badPlatforms to aarch64 (because it does not exist on the source tree of
  uclibc-ng

(cherry picked from commit 949579633d)
2022-06-17 05:10:42 +00:00
AndersonTorres
49a797a31a Move uclibc to uclibc-ng
In order to keep coherence between upstream project's name.

Also, aliasing it to the older names uclibc and uclibcCross.

(cherry picked from commit e418cc4298)
2022-06-17 05:10:42 +00:00
AndersonTorres
b529cc8dff Cosmetical: 80-char fill the opening paragraph of all-packages.nix
(cherry picked from commit 2ee6526b2a)
2022-06-17 05:10:41 +00:00
Mario Rodas
585cd33667 Merge pull request #177956 from NixOS/backport-177063-to-staging-22.05
[Backport staging-22.05] jansson: enable shared library installation
2022-06-16 23:22:07 -05:00
github-actions[bot]
42e1eb80c6 Merge staging-next-22.05 into staging-22.05 2022-06-17 00:14:56 +00:00
github-actions[bot]
350745ab72 Merge release-22.05 into staging-next-22.05 2022-06-17 00:14:22 +00:00
Maximilian Bosch
87d9c84817 Merge pull request #175179 from NixOS/backport-175165-to-release-22.05
[Backport release-22.05] nixos/nextcloud: Fix broken config file
2022-06-17 01:18:56 +02:00
Thiago Kenji Okada
313331adfd Merge pull request #177937 from NixOS/backport-177865-to-release-22.05
[Backport release-22.05] graalvmXX-ce: use a patched version of zlib
2022-06-16 23:57:02 +01:00
Artturin
8eca77048d python3: fix wrong platform libs when cross-compiling
see https://github.com/NixOS/nixpkgs/pull/169475#issuecomment-1129517328

patch by adisbladis

Co-authored-by: adisbladis <adisbladis@gmail.com>
(cherry picked from commit 843b988680)
2022-06-16 22:33:29 +00:00
Maximilian Bosch
f649e16704 linux/hardened/patches/5.4: 5.4.197-hardened1 -> 5.4.198-hardened1
(cherry picked from commit fb273f2144)
2022-06-16 22:28:07 +00:00
Maximilian Bosch
88a0136f69 linux/hardened/patches/5.17: 5.17.14-hardened1 -> 5.17.15-hardened1
(cherry picked from commit 96aa98b34e)
2022-06-16 22:28:07 +00:00
Maximilian Bosch
6bfdb41e73 linux/hardened/patches/5.15: 5.15.46-hardened1 -> 5.15.47-hardened1
(cherry picked from commit b728110e62)
2022-06-16 22:28:07 +00:00
Maximilian Bosch
d8c152db08 linux/hardened/patches/5.10: 5.10.121-hardened1 -> 5.10.122-hardened1
(cherry picked from commit 638b826560)
2022-06-16 22:28:07 +00:00
Maximilian Bosch
efba3d1342 linux/hardened/patches/4.19: 4.19.246-hardened1 -> 4.19.247-hardened1
(cherry picked from commit 2f5d73c7c8)
2022-06-16 22:28:07 +00:00
Maximilian Bosch
b822cca8bb linux/hardened/patches/4.14: 4.14.282-hardened1 -> 4.14.283-hardened1
(cherry picked from commit f66c3eec69)
2022-06-16 22:28:07 +00:00
Maximilian Bosch
f616afaabd linux: 5.4.197 -> 5.4.198
(cherry picked from commit 47f2c949b1)
2022-06-16 22:28:07 +00:00
Maximilian Bosch
a415091c5c linux: 5.18.3 -> 5.18.4
(cherry picked from commit c06fe392cf)
2022-06-16 22:28:07 +00:00
Maximilian Bosch
9d7625ac97 linux: 5.17.14 -> 5.17.15
(cherry picked from commit e58ad1f6c8)
2022-06-16 22:28:06 +00:00
Maximilian Bosch
ffed955bca linux: 5.15.46 -> 5.15.47
(cherry picked from commit 66f0feca14)
2022-06-16 22:28:06 +00:00
Maximilian Bosch
07149c1a36 linux: 5.10.121 -> 5.10.122
(cherry picked from commit 2aabaf7e8a)
2022-06-16 22:28:06 +00:00
Maximilian Bosch
76fc882e48 linux: 4.9.317 -> 4.9.318
(cherry picked from commit 685043bbe9)
2022-06-16 22:28:06 +00:00
Maximilian Bosch
435237e566 linux: 4.19.246 -> 4.19.247
(cherry picked from commit de6b615add)
2022-06-16 22:28:06 +00:00
Maximilian Bosch
27e5a20237 linux: 4.14.282 -> 4.14.283
(cherry picked from commit 783c3d65ef)
2022-06-16 22:28:06 +00:00
Maxine Aubrey
9a9042bfbf networkmanager: 1.38.0 -> 1.38.2
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/compare/1.38.0...1.38.2
(cherry picked from commit e8f62e992d)
2022-06-16 22:20:58 +00:00
Thiago Kenji Okada
d6a81a748a graalvmXX-ce: use a patched version of zlib
The previous releases of zlib were not sensitive to incorrect CRC
inputs with bits set above the low 32. Some programs were depended on
this behavior, including GraalVM. So this commit backports a patch from
`zlib` develop that brings back the old behavior. This will probably
be included in the next release of zlib.

Before:

```
$ rm -rf ~/.babashka
$ bb -e "(babashka.pods/load-pod 'clj-kondo/clj-kondo \"2022.05.31\")"
Downloading pod clj-kondo/clj-kondo (2022.05.31)
----- Error --------------------------------------------------------------------
Type:     java.util.zip.ZipException
Message:  invalid entry CRC (expected 0x269cdf2c but got 0x13b86fd8)
Location: <expr>:1:1

----- Context ------------------------------------------------------------------
1: (babashka.pods/load-pod 'clj-kondo/clj-kondo "2022.05.31")
   ^--- invalid entry CRC (expected 0x269cdf2c but got 0x13b86fd8)

----- Stack trace --------------------------------------------------------------
babashka.pods.impl.resolver/unzip             - <built-in>
babashka.pods.impl.resolver/resolve/fn--30674 - <built-in>
clojure.core/mapv/fn--8535                    - <built-in>
clojure.core.protocols/fn--8244               - <built-in>
clojure.core.protocols/fn--8204/G--8199--8213 - <built-in>
... (run with --debug to see elided elements)
babashka.pods.sci/load-pod/fn--30887          - <built-in>
babashka.pods.sci/load-pod                    - <built-in>
clojure.core/apply                            - <built-in>
babashka.impl.pods/load-pod                   - <built-in>
user                                          - <expr>:1:1
```

After:

```
$ rm -rf ~/.babashka
$ ./result/bin/bb -e "(babashka.pods/load-pod 'clj-kondo/clj-kondo \"2022.05.31\")"
Downloading pod clj-kondo/clj-kondo (2022.05.31)
Successfully installed pod clj-kondo/clj-kondo (2022.05.31)
```

The issue should affect other programs using GraalVM, but this was the
test that I had at hand.

(cherry picked from commit b2f19ab3b5)
2022-06-16 21:52:43 +00:00
Maximilian Bosch
091f72367a Merge pull request #177905 from Ma27/backport-grafana
[22.05] grafana: 8.5.5 -> 8.5.6
2022-06-16 23:40:20 +02:00
Michele Guerini Rocco
760ed64f23 Merge pull request #177907 from NixOS/backport-177283-to-release-22.05
[Backport release-22.05] pdns-recursor: 4.6.2 -> 4.7.0
2022-06-16 19:45:42 +02:00
rnhmjoj
9fb4d4874b pdns-recursor: 4.6.2 -> 4.7.0
(cherry picked from commit b0b2bad541)
2022-06-16 17:28:57 +00:00
Maximilian Bosch
be6bb5e5d3 grafana: 8.5.5 -> 8.5.6
ChangeLog: https://github.com/grafana/grafana/releases/tag/v8.5.6
2022-06-16 19:16:22 +02:00
Shea Levy
bc8d413097 linuxPackages.system76-io: Fix building on newer kernels.
See https://github.com/pop-os/system76-io-dkms/issues/7

(cherry picked from commit 76a936228a)
2022-06-16 16:10:22 +00:00
7c6f434c
9d6fe078d8 Merge pull request #177481 from NixOS/backport-176934-to-release-22.05
[Backport release-22.05] apache-jena: 4.4.0 -> 4.5.0
2022-06-16 15:34:46 +00:00
Michele Guerini Rocco
46d8bd8799 Merge pull request #177787 from NixOS/backport-177299-to-release-22.05
[Backport release-22.05] mkvtoolnix: 67.0.0 -> 68.0.0
2022-06-16 15:13:20 +02:00
Maximilian Bosch
5c54a4ff0d Merge pull request #177869 from NixOS/backport-177714-to-release-22.05
[Backport release-22.05] matrix-synapse: 1.60.0 -> 1.61.0
2022-06-16 14:53:38 +02:00
Maximilian Bosch
299638a85c Merge pull request #177377 from vcunat/p/nixUnstable-22.05
[22.05] nixUnstable: switch to the latest release
2022-06-16 13:43:23 +02:00
Bobby Rong
ff99261d8a Merge pull request #177756 from NixOS/backport-177680-to-release-22.05
[Backport release-22.05] ft2-clone: 1.54 -> 1.55
2022-06-16 19:28:49 +08:00
Nick Cao
f3b2cf835e matrix-synapse: 1.60.0 -> 1.61.0
(cherry picked from commit 402807041a)
2022-06-16 11:20:16 +00:00
Artturin
f27eb9dba1 nixVersions.nix_2_9: pull patch to add missing git-dir flags
(cherry picked from commit 9d84f435e3)
2022-06-16 13:19:21 +02:00
Maximilian Bosch
b0cde25a2e Merge pull request #177652 from NixOS/backport-177635-to-release-22.05
[Backport release-22.05] rnix-lsp: 0.2.4 -> 0.2.5
2022-06-16 12:55:30 +02:00
Vincent Laporte
713b7b0404 ocamlPackages.wasm: 1.1.1 → 2.0.0
(cherry picked from commit 6c36c16a81b03f73a4ab91a83588a05b72341b54)
2022-06-16 11:54:32 +02:00
Linus Heckemann
a4f5b169f1 liblouis: apply patch for CVE-2022-26981
Fixes: CVE-2022-26981

Refs:
https://github.com/liblouis/liblouis/pull/1185
https://github.com/advisories/GHSA-xrp8-mw8v-p6mq
https://nvd.nist.gov/vuln/detail/CVE-2022-26981
2022-06-16 09:35:57 +02:00
Bobby Rong
6f637542ed Merge pull request #177841 from NixOS/backport-177710-to-release-22.05
[Backport release-22.05] Pantheon 7 updates 2022-06-14
2022-06-16 14:06:23 +08:00
Bobby Rong
53625a5a91 pantheon.elementary-settings-daemon: add updateScript
(cherry picked from commit 099300771f)
2022-06-16 05:13:51 +00:00
Bobby Rong
42035d4f46 pantheon.elementary-notifications: add updateScript
(cherry picked from commit 859f3ff664)
2022-06-16 05:13:50 +00:00
Bobby Rong
39f94f1f9f pantheon.switchboard: 6.0.1 -> 6.0.2
(cherry picked from commit 0747c65922)
2022-06-16 05:13:50 +00:00
Bobby Rong
edfe3cca16 pantheon.elementary-tasks: 6.2.0 -> 6.3.0
(cherry picked from commit afbe75751b)
2022-06-16 05:13:50 +00:00
Mario Rodas
e1d121b97d Merge pull request #177814 from NixOS/backport-177800-to-release-22.05
[Backport release-22.05] podman: 4.1.0 -> 4.1.1
2022-06-16 00:10:17 -05:00
Bobby Rong
c17564a54b Merge pull request #177766 from NixOS/backport-177111-to-release-22.05
[Backport release-22.05] vscodium: 1.67.2 -> 1.68.0
2022-06-16 13:06:11 +08:00
github-actions[bot]
8fe1854bc6 Merge staging-next-22.05 into staging-22.05 2022-06-16 00:15:09 +00:00
github-actions[bot]
40122c0c76 Merge release-22.05 into staging-next-22.05 2022-06-16 00:14:34 +00:00
Jakub Kozłowski
d2708877ff Merge pull request #177815 from NixOS/backport-177661-to-release-22.05 2022-06-16 01:58:51 +02:00
Jakub Kozłowski
891d2bdc0b scala-cli: 0.1.7 -> 0.1.8
(cherry picked from commit 6b0f4f603c)
2022-06-15 23:42:53 +00:00
Jakub Kozłowski
4cbeb21f16 Merge pull request #177803 from NixOS/backport-176651-to-release-22.05 2022-06-16 01:37:36 +02:00
zowoq
803e6c05ee podman: 4.1.0 -> 4.1.1
https://github.com/containers/podman/releases/tag/v4.1.1
(cherry picked from commit 75d21e7131)
2022-06-15 23:28:01 +00:00
06kellyjac
6eacd249e6 chain-bench: init at 0.0.2
(cherry picked from commit 2205b90699)
2022-06-15 22:32:06 +00:00
Jakub Kozłowski
761b737550 scala-cli: 0.1.6 -> 0.1.7
(cherry picked from commit 22f30538f2)
2022-06-15 21:44:58 +00:00
maxine [they]
8b3c33e320 Merge pull request #177797 from NixOS/backport-177706-to-release-22.05
[Backport release-22.05] gnome.gnome-calendar: 42.1 -> 42.2
2022-06-15 22:23:19 +02:00
maxine [they]
0826b52e77 Merge pull request #177795 from NixOS/backport-177593-to-release-22.05
[Backport release-22.05] gnome.ghex: 42.2 -> 42.3
2022-06-15 22:23:07 +02:00
maxine [they]
f6d96b0139 Merge pull request #177796 from NixOS/backport-177473-to-release-22.05
[Backport release-22.05] gtksourceview5: 5.4.1 -> 5.4.2
2022-06-15 22:22:58 +02:00
maxine [they]
ea6f565720 Merge pull request #177794 from NixOS/backport-177469-to-release-22.05
[Backport release-22.05] gnome-text-editor: 42.1 -> 42.2
2022-06-15 22:22:43 +02:00
R. Ryantm
c385762fbc gnome.gnome-calendar: 42.1 -> 42.2
(cherry picked from commit 9896d3e929)
2022-06-15 20:17:12 +00:00
R. Ryantm
7bc04740c7 gtksourceview5: 5.4.1 -> 5.4.2
(cherry picked from commit 3b95894025)
2022-06-15 20:16:42 +00:00
R. Ryantm
0f96caf132 gnome.ghex: 42.2 -> 42.3
(cherry picked from commit 3c25c57c81)
2022-06-15 20:16:00 +00:00
R. Ryantm
09319c570a gnome-text-editor: 42.1 -> 42.2
(cherry picked from commit 434130e202)
2022-06-15 20:15:51 +00:00
Rick van Schijndel
9e74ccc250 Merge pull request #176243 from NixOS/backport-175460-to-release-22.05
[Backport release-22.05] deadbeef-statusnotifier-plugin: fix libdbusmenu dependency
2022-06-15 21:01:23 +02:00
rnhmjoj
99236dc3f9 mkvtoolnix: 67.0.0 -> 68.0.0
(cherry picked from commit 9a41cd6236)
2022-06-15 19:01:13 +00:00
Rick van Schijndel
21d6cc8f9c Merge pull request #176277 from NixOS/backport-176000-to-release-22.05
[Backport release-22.05] dotnet: mark dotnet unbroken on Darwin
2022-06-15 21:00:23 +02:00
Rick van Schijndel
c13277c2aa Merge pull request #177097 from NixOS/backport-176672-to-staging-22.05
[Backport staging-22.05] libusb1: 1.0.25 -> 1.0.26
2022-06-15 20:41:28 +02:00
Rick van Schijndel
6bc0ef47d1 Merge pull request #177226 from NixOS/backport-177220-to-release-22.05
[Backport release-22.05] fwupd: 1.8.0 -> 1.8.1
2022-06-15 20:38:54 +02:00
Maximilian Bosch
a77972308d Merge pull request #177569 from Ma27/backport-element
[22.05] element-{web,desktop}: 1.10.13 -> 1.10.14
2022-06-15 20:28:40 +02:00
nixpkgs-upkeep-bot
c9c05870f5 vscodium: 1.67.2 -> 1.68.0
(cherry picked from commit fae6144d7d)
2022-06-15 14:19:40 +00:00
Francesco Gazzetta
aab59afec1 ft2-clone: 1.54 -> 1.55
(cherry picked from commit cc3fa0d787)
2022-06-15 12:54:09 +00:00
adisbladis
8b538fcb32 Merge pull request #177723 from NixOS/backport-177709-to-release-22.05
[Backport release-22.05] go-ethereum: 1.10.17 -> 1.10.18
2022-06-15 15:30:32 +08:00
Francois-Rene Rideau
8da987d804 go-ethereum: 1.10.17 -> 1.10.18
(cherry picked from commit c841addd75)
2022-06-15 07:12:42 +00:00
Vladimír Čunát
db3e55d015 Merge branch 'staging-22.05' into staging-next-22.05 2022-06-15 07:37:28 +02:00
toonn
ba1d937917 cacert: Drop python3Minimal
This PR, https://github.com/NixOS/nixpkgs/pull/176291, started building
`cacert` with `python3Minimal` to work around an infinite recursion
problem with the `mailcap` build.

This causes problems now because `buildcatrust` requires the `_scproxy`
module and that's not built for `python3Minimal` on Darwin. This causes
many transitive failures. Simply building `cacert` with `python3` seems
to work fine.

The `mailcap` expression has since been altered and this infinite
recursion issue doesn't reappear.

(cherry picked from commit 1e1539c281)
(effectively a revert of 526a0b8047)
2022-06-15 07:35:18 +02:00
ajs124
598e9baf7d dovecot: 2.3.19 -> 2.3.19.1
(cherry picked from commit 7aaf277a47)
2022-06-15 00:37:10 +00:00
Anderson Torres
76c036451d Merge pull request #177574 from OPNA2608/backport/palemoon_31.1.0
[22.05] palemoon: 31.0.0 -> 31.1.0
2022-06-14 21:30:30 -03:00
github-actions[bot]
67bd35a279 Merge staging-next-22.05 into staging-22.05 2022-06-15 00:17:14 +00:00
github-actions[bot]
08bfe7fea8 Merge release-22.05 into staging-next-22.05 2022-06-15 00:16:37 +00:00
José Romildo Malaquias
4f1d3ca7ec Merge pull request #177676 from NixOS/backport-176703-to-release-22.05
[Backport release-22.05] matcha-gtk-theme: 2021-12-25 -> 2022-06-07
2022-06-14 19:57:37 -03:00
José Romildo
a02bbf01ec matcha-gtk-theme: 2021-12-25 -> 2022-06-07
(cherry picked from commit 025ddc1ec3e247c7e488177153b2c8157ebe5521)
2022-06-14 20:35:16 +00:00
José Romildo
ad1a452814 matcha-gtk-theme: add update script
(cherry picked from commit 647c7bc2f29ac4f91fef510342e16956d33f1361)
2022-06-14 20:35:16 +00:00
José Romildo
95264632ae matcha-gtk-theme: reformat nix expression
(cherry picked from commit f88c65a5db54b9553cb6c3452093d1d194da06ea)
2022-06-14 20:35:16 +00:00
Sandro
5aca9964ec Merge pull request #176777 from DarkOnion0/drawio-backport-22.05
[22.05] drawio: 18.1.3 -> 19.0.2
2022-06-14 22:32:49 +02:00
Adam Joseph
807db9e5e8 submitting-changes.chapter.md: avoid being specific
There is some doubt as to exactly how to enumerate all the merges from
one branch to another reliably.  In the meantime, let's be a little
more vague.

(cherry picked from commit 50217b01dd)
2022-06-14 17:43:45 +00:00
Adam Joseph
463675efd7 submitting-changes.chapter.md: explain that purple arrows are manual
The documentation for this diagram explains that the blue arrows are
automatic processes which happen every six hours.  There is no
explanation about how the purple arrows happen or how often.

As a new contributor to nixpkgs, I incorrectly assumed that the purple
arrows were also automatic processes (they aren't), which left me sort
of confused about what the whole scheme was accomplishing.

Recently I went through the github history to see how often these
events happen, and realized that the purple arrows are (a) triggered
manually by a nixpkgs project member and (b) happen much, much, much
less frequently than every six hours.

Now everything makes a lot more sense.  I suggest the wording change
in this commit, or something similar, to save future contributors the
same confusion that I experienced.

(cherry picked from commit 94c0e08808)
2022-06-14 17:43:45 +00:00
Maximilian Bosch
d7b4ced4b6 rnix-lsp: 0.2.4 -> 0.2.5
ChangeLog: https://github.com/nix-community/rnix-lsp/blob/v0.2.5/CHANGELOG.md#v025---2022-06-14
(cherry picked from commit 6813740dc7)
2022-06-14 14:54:23 +00:00
Martin Weinelt
9ff91ce2e4 Merge pull request #177625 from NixOS/backport-177583-to-release-22.05 2022-06-14 11:49:30 +02:00
Nicolas Benes
fdaefd3ea2 tor-browser-bundle-bin: 11.0.13 -> 11.0.14
(cherry picked from commit de77c035c4)
2022-06-14 09:37:15 +00:00
Aaron Andersen
0eb0b72a28 Merge pull request #177455 from NixOS/backport-176976-to-release-22.05
[Backport release-22.05] hydroxide: 0.2.21 -> 0.2.23
2022-06-13 20:58:02 -04:00
Aaron Andersen
828de64c8a Merge pull request #177456 from NixOS/backport-177321-to-release-22.05
[Backport release-22.05] mpd: fix socket activation
2022-06-13 20:57:35 -04:00
github-actions[bot]
5003aa1583 Merge staging-next-22.05 into staging-22.05 2022-06-14 00:17:28 +00:00
github-actions[bot]
e090dbb264 Merge release-22.05 into staging-next-22.05 2022-06-14 00:16:38 +00:00
Robert Hensing
347f458bbb stdenv/adapters.nix: Fix for overlay style arguments
(cherry picked from commit dd770cc211)
2022-06-14 00:04:45 +00:00
R. Ryantm
5afd4c9683 palemoon: 31.0.0 -> 31.1.0 2022-06-13 23:45:10 +02:00
Maximilian Bosch
1f2b6e8bb7 element-{web,desktop}: 1.10.13 -> 1.10.14
ChangeLog desktop: https://github.com/vector-im/element-desktop/releases/tag/v1.10.14
ChangeLog web: https://github.com/vector-im/element-web/releases/tag/v1.10.14
2022-06-13 23:36:09 +02:00
Ionut Nechita
ebcf4a9761 yandex-browser: 22.1.3.907-1 -> 22.5.0.1879-1
Signed-off-by: Ionut Nechita <ionut_n2001@yahoo.com>
Change-Id: I70fd2e794ce0bc209678646e692b10177d7a7b34
2022-06-13 20:37:37 +03:00
github-actions[bot]
041ac28bb5 nixos/openldap: fix systemd rejecting notification (#177520)
On one of the two machines I have running openldap, openldap failed to start due to a "timeout". Increasing the allowed startup delay didn't help.

I noticed the following in logs:
```
openldap.service: Got notification message from PID 5224, but reception only permitted for main PID 5223
```

It turns out that on this machine at least, openldap apparently sends the notification from a non-main process, which means that we need this NotifyAccess setting for systemd to record that it successfully started. Without it, after 30 seconds systemd kills the process because it didn't receive the sd_notify call.

Somehow the other machine I have on nixos running ldap works fine even without this, but I could not figure out what changes the behavior.

Given that AFAIU NotifyAccess still restricts to "from the cgroup of the service", I think this change should be safe.

(cherry picked from commit bd0fe743953ede63f1921403446d78c0ce43a65f)

Co-authored-by: Léo Gaspard <leo@gaspard.io>
2022-06-13 15:58:31 +02:00
Thomas Gerbet
2524e4f964 apache-jena: 4.4.0 -> 4.5.0
Fixes CVE-2022-28890.
https://www.mail-archive.com/users@jena.apache.org/msg19632.html

(cherry picked from commit 1d90386271)
2022-06-13 07:41:34 +00:00
Maximilian Bosch
a119e218ad Merge pull request #177464 from NixOS/backport-177442-to-release-22.05
[Backport release-22.05] grafana: 8.5.3 -> 8.5.5
2022-06-13 06:58:26 +02:00
Maximilian Bosch
86cdd67f54 Merge pull request #177467 from NixOS/backport-177430-to-release-22.05
[Backport release-22.05] nixos/prometheus-wireguard-exporter: fix broken options
2022-06-13 06:57:58 +02:00
Maximilian Bosch
2c2ff470e6 Merge pull request #177466 from NixOS/backport-177434-to-release-22.05
[Backport release-22.05] wiki-js: 2.5.283 -> 2.5.284
2022-06-13 06:57:23 +02:00
Maximilian Bosch
71d350cdae Merge pull request #177427 from NixOS/backport-177216-to-release-22.05
[Backport release-22.05] Linux kernel updates 2022-06-10
2022-06-13 06:50:29 +02:00
Maximilian Bosch
177585e063 nixos/prometheus-wireguard-exporter: fix broken options
This is apparently a breaking change in a patch-level release[1] where
it's now necessary to specify values for each CLI argument.

[1] https://github.com/MindFlavor/prometheus_wireguard_exporter/releases/tag/3.6.1

(cherry picked from commit e03d41fb6b)
2022-06-13 04:19:17 +00:00
Maximilian Bosch
5a01011e27 wiki-js: 2.5.283 -> 2.5.284
ChangeLog: https://github.com/requarks/wiki/releases/tag/v2.5.284
(cherry picked from commit 186ba212b5)
2022-06-13 04:18:25 +00:00
Maximilian Bosch
b0e21410e1 grafana: 8.5.3 -> 8.5.5
ChangeLogs:
* https://github.com/grafana/grafana/releases/tag/v8.5.4
* https://github.com/grafana/grafana/releases/tag/v8.5.5

(cherry picked from commit df0b326d75)
2022-06-13 04:10:33 +00:00
Peter Hoeg
a6879b20ec strawberry: 1.0.3 -> 1.0.4
(cherry picked from commit 4a2d1f7840)
2022-06-13 10:54:55 +08:00
rnhmjoj
9b2957ee4b mpd: fix socket activation
Apparently since systemd v250 a `ListenStream` in an override file won't
override the unit, but will be appended to a list of socket addresses.
The socket unit fails if two or more addresses have the same port,
probably because two systemd processes try to listen to it at once.
The solution is to add an empty `ListenStream=` to reset all previous
definitions.

Fix #175478.

(cherry picked from commit 7149c5cb60)
2022-06-13 02:31:58 +00:00
Aaron Andersen
4040a70b35 hydroxide: 0.2.21 -> 0.2.23
(cherry picked from commit b8c87def65)
2022-06-13 02:18:57 +00:00
github-actions[bot]
4460c25b13 Merge staging-next-22.05 into staging-22.05 2022-06-13 00:16:47 +00:00
github-actions[bot]
9707fd7776 Merge release-22.05 into staging-next-22.05 2022-06-13 00:16:11 +00:00
Aaron Andersen
fbba5047a4 kodi.packages.urllib3: 1.26.4+matrix.1 -> 1.26.8+matrix.1
(cherry picked from commit e17c1d5a52)
2022-06-12 22:57:49 +00:00
Andrew Marshall
7f019156b9 linux/hardened/patches/5.4: 5.4.196-hardened1 -> 5.4.197-hardened1
(cherry picked from commit 5dc09cd84f)
2022-06-12 17:57:51 +00:00
Andrew Marshall
9709714bf0 linux/hardened/patches/5.18: init at 5.18.3-hardened1
(cherry picked from commit a2c6e4372a)
2022-06-12 17:57:51 +00:00
Andrew Marshall
a6c5222595 linux/hardened/patches/5.17: 5.17.11-hardened1 -> 5.17.14-hardened1
(cherry picked from commit f61e9f4a53)
2022-06-12 17:57:51 +00:00
Andrew Marshall
319d57dd35 linux/hardened/patches/5.15: 5.15.43-hardened1 -> 5.15.46-hardened1
(cherry picked from commit de36193dee)
2022-06-12 17:57:51 +00:00
Andrew Marshall
093c4dc5df linux/hardened/patches/5.10: 5.10.118-hardened1 -> 5.10.121-hardened1
(cherry picked from commit 858741e872)
2022-06-12 17:57:51 +00:00
Andrew Marshall
de65dcfa50 linux/hardened/patches/4.19: 4.19.245-hardened1 -> 4.19.246-hardened1
(cherry picked from commit 1c31d9666e)
2022-06-12 17:57:51 +00:00
Andrew Marshall
988d77b725 linux/hardened/patches/4.14: 4.14.281-hardened1 -> 4.14.282-hardened1
(cherry picked from commit 67a664c575)
2022-06-12 17:57:51 +00:00
Andrew Marshall
ffa93401e4 linux_latest-libre: 18738 -> 18777
(cherry picked from commit 87e0009cd5)
2022-06-12 17:57:51 +00:00
Andrew Marshall
71d444f092 linux-rt_5_10: 5.10.115-rt67 -> 5.10.120-rt70
(cherry picked from commit e457a67642)
2022-06-12 17:57:51 +00:00
Andrew Marshall
8814d2ec8c linux: 5.4.196 -> 5.4.197
(cherry picked from commit 45a098de80)
2022-06-12 17:57:50 +00:00
Andrew Marshall
fd944442e9 linux: 5.18 -> 5.18.3
(cherry picked from commit 260e08a6e6)
2022-06-12 17:57:50 +00:00
Andrew Marshall
efb6eb853e linux: 5.17.11 -> 5.17.14
(cherry picked from commit 363c71ff3c)
2022-06-12 17:57:50 +00:00
Andrew Marshall
7cd1ca3528 linux: 5.15.43 -> 5.15.46
(cherry picked from commit 19d9866215)
2022-06-12 17:57:50 +00:00
Andrew Marshall
d5dd641de2 linux: 5.10.118 -> 5.10.121
(cherry picked from commit a7757d8a94)
2022-06-12 17:57:50 +00:00
Andrew Marshall
eda208b154 linux: 4.9.316 -> 4.9.317
(cherry picked from commit 2ac8909c8b)
2022-06-12 17:57:50 +00:00
Andrew Marshall
df3e7ccc7f linux: 4.19.245 -> 4.19.246
(cherry picked from commit c6c98c48b4)
2022-06-12 17:57:50 +00:00
Andrew Marshall
826924de96 linux: 4.14.281 -> 4.14.282
(cherry picked from commit deaf61dab1)
2022-06-12 17:57:50 +00:00
Maximilian Bosch
0965c895dc Merge pull request #177418 from NixOS/backport-177415-to-release-22.05
[Backport release-22.05] nixos/wpa_supplicant: don't log that wpa_supplicant.conf is ignored with `allowAuxiliaryImperativeNetworks = true`
2022-06-12 18:17:39 +02:00
Michele Guerini Rocco
e0a70ea804 Merge pull request #177417 from NixOS/backport-177293-to-release-22.05
[Backport release-22.05] libreswan: 4.6 -> 4.7
2022-06-12 18:09:48 +02:00
Maximilian Bosch
5b2ce294d3 nixos/wpa_supplicant: don't log that wpa_supplicant.conf is ignored with allowAuxiliaryImperativeNetworks = true
The warning is wrong with `allowAuxiliaryImperativeNetworks`[1] being
set to `true` because both files are included in this case with `-c` and
`-I`.

[1] https://nixos.org/manual/nixos/stable/options.html#opt-networking.wireless.allowAuxiliaryImperativeNetworks

(cherry picked from commit fd2a89b983)
2022-06-12 15:56:27 +00:00
rnhmjoj
611dae9203 libreswan: 4.6 -> 4.7
(cherry picked from commit 514bd27e92)
2022-06-12 15:51:16 +00:00
André Silva
5a59b5c182 virtualbox: 6.1.30 -> 6.1.34
(cherry picked from commit 9c8132494f)
2022-06-12 15:04:22 +00:00
Vladimír Čunát
88fcb74829 Merge #177395: metrics job: schedule on a dedicated machine
...into release-22.05
2022-06-12 14:35:15 +02:00
Vladimír Čunát
0e415414ce Revert "metrics job: schedule on any machine, for now"
(cherry picked from commit e8c87f0946)
2022-06-12 12:31:35 +00:00
Michael Weiss
36b5ff86a5 Merge pull request #177388 from primeos/chromium-backport
[Backport release-22.05] ungoogled-chromium: 102.0.5005.61 -> 102.0.5005.115
2022-06-12 13:50:01 +02:00
Michael Weiss
05be2f7387 ungoogled-chromium: 102.0.5005.61 -> 102.0.5005.115
(cherry picked from commit 69c4953f4b)
2022-06-12 13:25:49 +02:00
Michael Weiss
8612bc1a7f Merge pull request #174702 from NixOS/backport-174623-to-release-22.05
[Backport release-22.05] ungoogled-chromium: 101.0.4951.64 -> 102.0.5005.61
2022-06-12 13:24:57 +02:00
José Romildo Malaquias
a9a29c17c8 Merge pull request #177352 from NixOS/backport-177340-to-release-22.05
[Backport release-22.05] xfce.exo: 4.16.3 -> 4.16.4
2022-06-12 08:20:16 -03:00
Thiago Kenji Okada
ecba40c457 Merge pull request #177382 from NixOS/backport-177325-to-release-22.05
[Backport release-22.05] distrobox: 1.3.0 -> 1.3.1
2022-06-12 11:46:23 +01:00
Átila Saraiva
e1e6bd3259 distrobox: 1.3.0 -> 1.3.1
(cherry picked from commit 501ec23c49)
2022-06-12 10:31:38 +00:00
maxine [they]
f645fde237 Merge pull request #177267 from NixOS/backport-177250-to-staging-22.05 2022-06-12 11:53:02 +02:00
maxine [they]
ae190db8c6 Merge pull request #177266 from NixOS/backport-177247-to-release-22.05 2022-06-12 11:52:43 +02:00
Vladimír Čunát
0436580cf1 nixUnstable: switch to the latest release
On master we did this in f888642ec6 in PR #175603,
but on stable nixpkgs we surely don't want to advance nixStable.
2022-06-12 10:48:53 +02:00
zowoq
13f2106bf8 nixVersions.nix_2_9: 2.9.0 -> 2.9.1
(cherry picked from commit 54e6551ba4)
2022-06-12 10:44:49 +02:00
Artturin
a95318ac87 nixVersions.nix_2_9: init at 2.9.0
(cherry picked from commit f0c3fe4091)
2022-06-12 10:44:20 +02:00
José Romildo
65e95d4811 xfce.exo: 4.16.3 -> 4.16.4
Fixes: CVE-2022-32278
(cherry picked from commit 46f92ca4da)
2022-06-12 00:48:25 +00:00
Martin Weinelt
1f8d88087a Merge pull request #177316 from dotlambda/CVE-2022-29217 2022-06-12 02:41:31 +02:00
github-actions[bot]
41868703b9 Merge staging-next-22.05 into staging-22.05 2022-06-12 00:16:03 +00:00
github-actions[bot]
80cfd38681 Merge release-22.05 into staging-next-22.05 2022-06-12 00:15:22 +00:00
Martin Weinelt
f867e81b60 Merge pull request #177224 from NixOS/backport-176986-to-release-22.05 2022-06-12 02:00:18 +02:00
Michele Guerini Rocco
ff5740471b Merge pull request #177332 from NixOS/backport-177298-to-release-22.05
[Backport release-22.05] mutt: 2.2.4 -> 2.2.5
2022-06-12 00:05:16 +02:00
rnhmjoj
362bb4babc mutt: 2.2.4 -> 2.2.5
(cherry picked from commit e0dc568e25)
2022-06-11 20:54:05 +00:00
Rick van Schijndel
10116a7724 Merge pull request #177317 from NixOS/backport-176786-to-release-22.05
[Backport release-22.05] sbsigntool: 0.9.1 -> 0.9.4
2022-06-11 20:08:04 +02:00
Henri Menke
4e2b152b7f sbsigntool: add hmenke as maintainer
(cherry picked from commit 53b3ad5398)
2022-06-11 17:45:39 +00:00
Henri Menke
c5c459ca53 sbsigntool: 0.9.1 -> 0.9.4
(cherry picked from commit aa8115c447)
2022-06-11 17:45:38 +00:00
Robert Schütz
764759283d python310Packages.pyjwt: fix CVE-2022-29217 2022-06-11 17:30:42 +00:00
Bobby Rong
d3551b986a Merge pull request #177242 from NixOS/backport-177230-to-release-22.05
[Backport release-22.05] signal-desktop: 5.45.0 -> 5.45.1
2022-06-11 22:27:34 +08:00
Patrick Jackson
fd459d0d1f transmission-remote-gtk: 1.4.1 -> 1.5.1
(cherry picked from commit 9ea251b6c15b1e80b04d51d5da4c493c9f65588b)
2022-06-11 08:27:30 -05:00
R. Ryantm
5b6adce72c librsvg: 2.54.3 -> 2.54.4
(cherry picked from commit 2a97fea3bfe41b03aef1c44f45bd60bf3662e2dd)
2022-06-11 09:24:54 +00:00
R. Ryantm
41166a602b gspell: 1.10.0 -> 1.11.1
(cherry picked from commit 17bb5120e9bdbc580342530a082f77ce11a3b8cf)
2022-06-11 09:20:38 +00:00
7c6f434c
dab6df5138 Merge pull request #177257 from NixOS/backport-177114-to-release-22.05
[Backport release-22.05] speed-dreams: 2.2.2 -> 2.2.3
2022-06-11 08:35:03 +00:00
7c6f434c
123a212a09 Merge pull request #176841 from NixOS/backport-176732-to-release-22.05
[Backport release-22.05] gajim: 1.4.2 → 1.4.3
2022-06-11 08:34:55 +00:00
7c6f434c
601d67acc0 Merge pull request #175465 from NixOS/backport-174448-to-release-22.05
[Backport release-22.05] nginxStable: 1.20.2 -> 1.22.0
2022-06-11 08:34:45 +00:00
Astro
00c97aa8da speed-dreams: 2.2.2 -> 2.2.3
(cherry picked from commit 90f443a17b)
2022-06-11 07:22:50 +00:00
Eduardo Quiros
1c54a1b5bb signal-desktop: 5.45.0 -> 5.45.1
(cherry picked from commit 2f7a870a4c)
2022-06-11 02:24:36 +00:00
Anderson Torres
cc5a426ba3 Merge pull request #177236 from NixOS/backport-177120-to-release-22.05
[Backport release-22.05] refind: Fix possible NULL dereference
2022-06-10 23:13:13 -03:00
Samuel Dionne-Riel
4afa2c4818 refind: Fix possible NULL dereference
This was observed with U-Boot.

See the upstream change.

 - https://sourceforge.net/p/refind/code/merge-requests/45/

(cherry picked from commit eb900ded42)
2022-06-11 00:20:47 +00:00
github-actions[bot]
a2a72d6fc3 Merge staging-next-22.05 into staging-22.05 2022-06-11 00:16:30 +00:00
github-actions[bot]
30189940ae Merge release-22.05 into staging-next-22.05 2022-06-11 00:15:54 +00:00
Mario Rodas
396dae873d Merge pull request #177211 from NixOS/backport-177204-to-release-22.05
[Backport release-22.05] chromium: 102.0.5005.61 -> 102.0.5005.115
2022-06-10 19:15:26 -05:00
maxine [they]
20bdb91aac Merge pull request #177221 from NixOS/backport-177218-to-release-22.05 2022-06-11 00:48:42 +02:00
Maxine Aubrey
25b51afd96 fwupd: 1.8.0 -> 1.8.1
- https://github.com/fwupd/fwupd/releases/tag/1.8.1

(cherry picked from commit a58c728d5f)
2022-06-10 22:37:53 +00:00
Maxine Aubrey
39e1db0c73 libxmlb: 0.3.8 -> 0.3.9
(cherry picked from commit 110b8ad1ef)
2022-06-10 22:37:53 +00:00
Martin Weinelt
8e36b49554 firefox-devedition-bin-unwrapped: 102.0b1 -> 102.0b5
(cherry picked from commit 26ca0d1901ae0a7f55406d34c413281f8ea0ee68)
2022-06-10 22:26:26 +00:00
Martin Weinelt
cd6504a26f firefox-beta-bin-unwrapped: 102.0b1 -> 102.0b5
(cherry picked from commit 439a7369aea23ec6eb6d70121480a62b8bb1a74c)
2022-06-10 22:26:26 +00:00
Martin Weinelt
32571f542c firefox-bin-unwrapped: 101.0 -> 101.0.1
https://www.mozilla.org/en-US/firefox/101.0.1/releasenotes/
(cherry picked from commit d373d1b66bf68ae6c20ee22a8afd03bbb714d0da)
2022-06-10 22:26:26 +00:00
R. Ryantm
70874fe932 firefox-unwrapped: 101.0 -> 101.0.1
https://www.mozilla.org/en-US/firefox/101.0.1/releasenotes/
(cherry picked from commit 3a852683aa3365f5628cc4435249da394dba50cd)
2022-06-10 22:26:26 +00:00
Maxine Aubrey
fd60d3b1fc docker: 20.10.16 -> 20.10.17
- https://github.com/moby/moby/releases/tag/v20.10.17
- https://github.com/containerd/containerd/releases/tag/v1.6.6
- https://github.com/docker/cli/releases/tag/v20.10.17
- https://github.com/opencontainers/runc/releases/tag/v1.1.2

(cherry picked from commit c0a672b343)
2022-06-10 22:17:25 +00:00
maxine [they]
f63c1101c1 Merge pull request #177176 from NixOS/backport-177112-to-release-22.05
[Backport release-22.05] vscode: 1.67.2 -> 1.68.0
2022-06-10 23:58:39 +02:00
maxine [they]
3c7e7c2e32 Merge pull request #177187 from NixOS/backport-177075-to-release-22.05
[Backport release-22.05] GNOME updates
2022-06-10 23:58:28 +02:00
Michael Weiss
b105122fb2 chromium: 102.0.5005.61 -> 102.0.5005.115
https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop.html

This update includes 7 security fixes.

CVEs:
CVE-2022-2007 CVE-2022-2008 CVE-2022-2010 CVE-2022-2011

(cherry picked from commit 41c362c9d1)
2022-06-10 20:26:25 +00:00
Artturi
7655f0df7d Merge pull request #177195 from NixOS/backport-177184-to-release-22.05 2022-06-10 21:32:25 +03:00
Artturin
b52cb419e3 nixVersions.unstable: pre20220530 -> pre20220610
(cherry picked from commit 676d99ff21)
2022-06-10 17:34:49 +00:00
Martin Weinelt
2739a9c64e Merge pull request #177186 from NixOS/backport-177181-to-release-22.05 2022-06-10 17:20:16 +02:00
Aaron Andersen
4c6ef982da Merge pull request #177076 from NixOS/backport-174959-to-release-22.05
[Backport release-22.05] nixos/openconnect: add autoStart option
2022-06-10 11:17:28 -04:00
Artturi
781512b342 Merge pull request #177119 from NixOS/backport-175177-to-release-22.05 2022-06-10 17:56:35 +03:00
Jan Tojnar
d810838cae tracker-miners: 3.3.0 → 3.3.1
https://gitlab.gnome.org/GNOME/tracker-miners/-/compare/3.3.0...3.3.1
(cherry picked from commit 3f896ec0592a26df81502afabd1c88ec8b76c9dd)
2022-06-10 14:45:40 +00:00
Jan Tojnar
35043a0e5b tepl: 6.0.1 → 6.0.2
https://gitlab.gnome.org/swilmet/tepl/-/compare/6.0.1...6.0.2
(cherry picked from commit d38eed08f08dd2372e7a577e89deca917668fb6b)
2022-06-10 14:45:40 +00:00
Jan Tojnar
0b68ef5982 networkmanagerapplet: 1.26.0 → 1.28.0
https://gitlab.gnome.org/GNOME/network-manager-applet/-/compare/1.26.0...1.28.0
(cherry picked from commit 5b6038016ee14d158006ec2f91a27a10850f41c5)
2022-06-10 14:45:39 +00:00
Jan Tojnar
051509aa63 gupnp-av: 0.14.0 → 0.14.1
https://gitlab.gnome.org/GNOME/gupnp-av/-/compare/gupnp-av-0.14.0...gupnp-av-0.14.1
(cherry picked from commit 2746ab80ca76741f8af15a4327f30a74aab83c4d)
2022-06-10 14:45:39 +00:00
Jan Tojnar
aecbc57d04 gnome-desktop: 42.1 → 42.2
https://gitlab.gnome.org/GNOME/gnome-desktop/-/compare/42.1...42.2
(cherry picked from commit 4553fcbd6e69f156d8fdcfa85026d1138cafc114)
2022-06-10 14:45:39 +00:00
Jan Tojnar
f636c554f7 gnome.gnome-bluetooth: 42.0 → 42.1
https://gitlab.gnome.org/GNOME/gnome-bluetooth/-/compare/42.0...42.1
(cherry picked from commit d87676e33e2f596cb89356969747665f01596e65)
2022-06-10 14:45:39 +00:00
Jan Tojnar
676f2db2ae amtk: 5.4.0 → 5.4.1
https://gitlab.gnome.org/World/amtk/-/compare/5.4.0...5.4.1
(cherry picked from commit 273f87e5a1a817a568b40f9661cb395b7038928c)
2022-06-10 14:45:39 +00:00
Fabian Affolter
5278d3fa91 apacheHttpd: 2.4.53 -> 2.4.54
https://downloads.apache.org/httpd/CHANGES_2.4.54

Fixes: CVE-2022-31813, CVE-2022-30556, CVE-2022-30522, CVE-2022-29404,
CVE-2022-28615, CVE-2022-28614, CVE-2022-28330, CVE-2022-26377

(cherry picked from commit 35c7173cf5)
2022-06-10 14:44:36 +00:00
nixpkgs-upkeep-bot
bb1d18e2e3 vscode: 1.67.2 -> 1.68.0
(cherry picked from commit df118d7a7a)
2022-06-10 13:02:51 +00:00
Bobby Rong
4b333a943b Merge pull request #177161 from NixOS/backport-177127-to-release-22.05
[Backport release-22.05] Pantheon 7 updates 2022-06-09
2022-06-10 20:47:05 +08:00
José Romildo Malaquias
6413282438 Merge pull request #177169 from NixOS/backport-176568-to-release-22.05
[Backport release-22.05] xdgmenumaker: 1.5 -> 1.6
2022-06-10 08:59:27 -03:00
José Romildo
fff47df047 xdgmenumaker: 1.5 -> 1.6
(cherry picked from commit 2a4b80a24d79cdfb0ad12986f5f0b7c18bd650b7)
2022-06-10 11:39:32 +00:00
José Romildo
1a657e328f xdgmenumaker: avoid double wrapping
(cherry picked from commit 8a24a370c348441b0c181ed89050fd31b8ed606d)
2022-06-10 11:39:31 +00:00
José Romildo
7844ff53b9 xdgmenumaker: fix license
(cherry picked from commit a8ffe753a8fc367d6a0a1067902b25571b4ff2d8)
2022-06-10 11:39:31 +00:00
José Romildo
25fb133142 xdgmenumaker: add update script
(cherry picked from commit 7be84e3f24f2106c9b68cfbd5369eead96c00258)
2022-06-10 11:39:31 +00:00
José Romildo
953f40a8b9 xdgmenumaker: format nix expression
(cherry picked from commit 7eff2eb4226e4a633c88428aeff602de6eebdb6e)
2022-06-10 11:39:31 +00:00
Bobby Rong
9bb49b913e pantheon.elementary-notifications: 6.0.1 -> 6.0.2
(cherry picked from commit 6667e3670f)
2022-06-10 11:14:59 +00:00
Bobby Rong
89f6d209ad pantheon.elementary-videos: 2.8.3 -> 2.8.4
(cherry picked from commit 22e8068097)
2022-06-10 11:14:59 +00:00
Martin Weinelt
8b66e3f2eb Merge pull request #177138 from NixOS/backport-176561-to-release-22.05
[Backport release-22.05] pipewire: create home directory for the pipewire user when running systemwide
2022-06-10 09:46:28 +02:00
K900
523e6da729 pipewire: create home directory for the pipewire user when running systemwide
wireplumber wants to store state there

(cherry picked from commit 955d1a6dde)
2022-06-10 07:30:51 +00:00
John Ericson
e8cf67daca Merge pull request #177086 from NixOS/backport-176925-to-release-22.05
[Backport release-22.05] llvmPackages_14: Fix remaining broken gnu-install-dirs patches
2022-06-09 22:40:26 -04:00
Alexander Bantyev
e2bb4ac359 yafaray-core: stdenv -> gcc10Stdenv
(cherry picked from commit 8a6dbc8b7d)
2022-06-10 02:27:36 +00:00
Alexander Bantyev
bf55b6e57d xqilla: stdenv -> gcc10Stdenv
(cherry picked from commit da31172e10)
2022-06-10 02:27:36 +00:00
Alexander Bantyev
fbbba9d932 xc3sprog: stdenv -> gcc10Stdenv
(cherry picked from commit a5739070a0)
2022-06-10 02:27:35 +00:00
Alexander Bantyev
1f5020ad41 wxcam: stdenv -> gcc10Stdenv
(cherry picked from commit 1461ead834)
2022-06-10 02:27:35 +00:00
Alexander Bantyev
a144ddf991 webrtc-audio-processing_1: stdenv -> gcc10Stdenv
(cherry picked from commit 1affead2e6)
2022-06-10 02:27:35 +00:00
Alexander Bantyev
50f6f6a658 uri: stdenv -> gcc10Stdenv
(cherry picked from commit 4281581f32)
2022-06-10 02:27:35 +00:00
Alexander Bantyev
05cd94742d ucg: stdenv -> gcc10Stdenv
(cherry picked from commit 101927cc46)
2022-06-10 02:27:35 +00:00
Alexander Bantyev
bea0a97588 tracebox: stdenv -> gcc10Stdenv
(cherry picked from commit 17cca50520)
2022-06-10 02:27:35 +00:00
Alexander Bantyev
b4c8a1cf10 tiscamera: stdenv -> gcc10Stdenv
(cherry picked from commit bb1a8a87a6)
2022-06-10 02:27:35 +00:00
Alexander Bantyev
ef7790a218 textadept11: stdenv -> gcc10Stdenv
(cherry picked from commit 7bd4ef2835)
2022-06-10 02:27:34 +00:00
Alexander Bantyev
05f528f3cd swiftshader: stdenv -> gcc10Stdenv
(cherry picked from commit fe9163bac7)
2022-06-10 02:27:34 +00:00
Alexander Bantyev
39e4f16c13 swfmill: stdenv -> gcc10Stdenv
(cherry picked from commit 8c379ef34f)
2022-06-10 02:27:34 +00:00
Alexander Bantyev
472eb16a5d stuntrally: stdenv -> gcc10Stdenv
(cherry picked from commit 70e3e0d839)
2022-06-10 02:27:34 +00:00
Alexander Bantyev
e57538106c strelka: stdenv -> gcc10Stdenv
(cherry picked from commit 38a3766228)
2022-06-10 02:27:34 +00:00
Alexander Bantyev
3df111400d spring: stdenv -> gcc10Stdenv
(cherry picked from commit c526e73ea2)
2022-06-10 02:27:34 +00:00
Alexander Bantyev
d2dd6aa729 sonic-lineup: stdenv -> gcc10Stdenv
(cherry picked from commit b9af2b5afd)
2022-06-10 02:27:34 +00:00
Alexander Bantyev
fe705dabd0 rss-glx: stdenv -> gcc10Stdenv
(cherry picked from commit 91ef8a2d4e)
2022-06-10 02:27:34 +00:00
Alexander Bantyev
71f9a7eba3 pktgen: stdenv -> gcc10Stdenv
(cherry picked from commit 8297eeacda)
2022-06-10 02:27:33 +00:00
Alexander Bantyev
de90857f39 pianobooster: stdenv -> gcc10Stdenv
(cherry picked from commit 533171bfff)
2022-06-10 02:27:33 +00:00
Alexander Bantyev
43dcb64aac percona-xtrabackup_8_0: stdenv -> gcc10Stdenv
(cherry picked from commit 0655723b23)
2022-06-10 02:27:33 +00:00
Alexander Bantyev
b57aecc742 percona-xtrabackup_2_4: stdenv -> gcc10Stdenv
(cherry picked from commit 5785f8321c)
2022-06-10 02:27:33 +00:00
Alexander Bantyev
2ea483c077 percona-server56: stdenv -> gcc10Stdenv
(cherry picked from commit cbdb85b743)
2022-06-10 02:27:33 +00:00
Alexander Bantyev
cac2078730 oxen: stdenv -> gcc10Stdenv
(cherry picked from commit 32e76212c5)
2022-06-10 02:27:33 +00:00
Alexander Bantyev
fe01fa2cdb openvino: stdenv -> gcc10Stdenv
(cherry picked from commit edd13b5528)
2022-06-10 02:27:33 +00:00
Alexander Bantyev
cc0ea7710c opendbx: stdenv -> gcc10Stdenv
(cherry picked from commit 28bcbe1ac8)
2022-06-10 02:27:33 +00:00
Alexander Bantyev
7a073fa2a9 openclonk: stdenv -> gcc10Stdenv
(cherry picked from commit e86878e1b1)
2022-06-10 02:27:32 +00:00
Alexander Bantyev
beb5d0c7f3 olive-editor: stdenv -> gcc10Stdenv
(cherry picked from commit 5ec76e1cd6)
2022-06-10 02:27:32 +00:00
Alexander Bantyev
dafe9b4eee obliv-c: stdenv -> gcc10Stdenv
(cherry picked from commit 2be028e943)
2022-06-10 02:27:32 +00:00
Alexander Bantyev
413b850dbf non: stdenv -> gcc10Stdenv
(cherry picked from commit 15b44bab79)
2022-06-10 02:27:32 +00:00
Alexander Bantyev
a3b5a1fe0b nano-wallet: stdenv -> gcc10Stdenv
(cherry picked from commit 3eac0002ec)
2022-06-10 02:27:31 +00:00
Alexander Bantyev
a0b805e42b mrustc-bootstrap: stdenv -> gcc10Stdenv
(cherry picked from commit 41e537a585)
2022-06-10 02:27:31 +00:00
Alexander Bantyev
0fec5225b4 mps: stdenv -> gcc10Stdenv
(cherry picked from commit c27f7b1b00)
2022-06-10 02:27:31 +00:00
Alexander Bantyev
2223fa4343 mkcue: stdenv -> gcc10Stdenv
(cherry picked from commit 33851c466f)
2022-06-10 02:27:31 +00:00
Alexander Bantyev
c5fc385bfa mitscheme: stdenv -> gcc10Stdenv
(cherry picked from commit 7976cdf59e)
2022-06-10 02:27:31 +00:00
Alexander Bantyev
9709d9041f miniaudicle: stdenv -> gcc10Stdenv
(cherry picked from commit 43494af5eb)
2022-06-10 02:27:31 +00:00
Alexander Bantyev
965e804eed mars: stdenv -> gcc10Stdenv
(cherry picked from commit b31af490cd)
2022-06-10 02:27:31 +00:00
Alexander Bantyev
e31c0bae34 loki: stdenv -> gcc10Stdenv
(cherry picked from commit e374625845)
2022-06-10 02:27:30 +00:00
Alexander Bantyev
5aa020b0f5 libdynd: stdenv -> gcc10Stdenv
(cherry picked from commit 14a2dec50d)
2022-06-10 02:27:30 +00:00
Alexander Bantyev
753f6b396d jigdo: stdenv -> gcc10Stdenv
(cherry picked from commit 872f42247b)
2022-06-10 02:27:30 +00:00
Alexander Bantyev
ea01390e5e isrcsubmit: stdenv -> gcc10Stdenv
(cherry picked from commit fcb1fbf5fc)
2022-06-10 02:27:30 +00:00
Alexander Bantyev
22924a9f96 iqueue: stdenv -> gcc10Stdenv
(cherry picked from commit daa692e42c)
2022-06-10 02:27:30 +00:00
Alexander Bantyev
d089be3ff4 idsk: stdenv -> gcc10Stdenv
(cherry picked from commit 0590c39ffa)
2022-06-10 02:27:30 +00:00
Alexander Bantyev
265e6817b4 hobbes: stdenv -> gcc10Stdenv
(cherry picked from commit 591dc2fdd2)
2022-06-10 02:27:30 +00:00
Alexander Bantyev
e1cff75832 gsmlib: stdenv -> gcc10Stdenv
(cherry picked from commit 8dc4d73477)
2022-06-10 02:27:30 +00:00
Alexander Bantyev
d16bf92b1d gosmore: stdenv -> gcc10Stdenv
(cherry picked from commit 0e05668dc3)
2022-06-10 02:27:29 +00:00
Alexander Bantyev
cc657df8a8 getdp: stdenv -> gcc10Stdenv
(cherry picked from commit 9f22d631eb)
2022-06-10 02:27:29 +00:00
Alexander Bantyev
7ae5a1bb8d gebaar-libinput: stdenv -> gcc10Stdenv
(cherry picked from commit feb6162f83)
2022-06-10 02:27:29 +00:00
Alexander Bantyev
45a55199cb gammy: stdenv -> gcc10Stdenv
(cherry picked from commit 5d8e2a71f1)
2022-06-10 02:27:29 +00:00
Alexander Bantyev
8372726fc4 flwrap: stdenv -> gcc10Stdenv
(cherry picked from commit 77aab56ca4)
2022-06-10 02:27:29 +00:00
Alexander Bantyev
aa365454d9 fluxus: stdenv -> gcc10Stdenv
(cherry picked from commit 5e081aeaa1)
2022-06-10 02:27:29 +00:00
Alexander Bantyev
bda56985cf ericw-tools: stdenv -> gcc10Stdenv
(cherry picked from commit 5b12d3a807)
2022-06-10 02:27:29 +00:00
Alexander Bantyev
601a30a915 dxx-rebirth: stdenv -> gcc10Stdenv
(cherry picked from commit fd26c9493b)
2022-06-10 02:27:29 +00:00
Alexander Bantyev
6453f10948 dl-poly-classic-mpi: stdenv -> gcc10Stdenv
(cherry picked from commit 9882ffead4)
2022-06-10 02:27:28 +00:00
Alexander Bantyev
e8ba7bd1e4 djv: stdenv -> gcc10Stdenv
(cherry picked from commit a484f4f331)
2022-06-10 02:27:28 +00:00
Alexander Bantyev
30d5e7ec3e diopser: stdenv -> gcc10Stdenv
(cherry picked from commit 30d4616997)
2022-06-10 02:27:28 +00:00
Alexander Bantyev
8c1830e5d5 cxxtools: stdenv -> gcc10Stdenv
(cherry picked from commit e46b811478)
2022-06-10 02:27:28 +00:00
Alexander Bantyev
7e1e22358f clingcon: stdenv -> gcc10Stdenv
(cherry picked from commit c6af26acfc)
2022-06-10 02:27:28 +00:00
cab
a8e6921eb2 pkgs: added gcc10StdenvCompat
Many packages got broken by gcc10 -> 11 switch. This makes overriding
broken libraries a bit easier.

(cherry picked from commit 8bdc1401a2)
2022-06-10 02:27:28 +00:00
Martin Weinelt
bc105fd1ca Merge pull request #177108 from NixOS/backport-177053-to-staging-22.05 2022-06-10 02:38:33 +02:00
github-actions[bot]
f29e1f50dd Merge staging-next-22.05 into staging-22.05 2022-06-10 00:16:00 +00:00
github-actions[bot]
77bf3c4a73 Merge release-22.05 into staging-next-22.05 2022-06-10 00:15:20 +00:00
Raito Bezarius
1725dfbd7f zlib: backport upstream fix on CRC validation
Starting zlib 1.2.12, CRC validation has became stricter.
This broke Keycloak ≥ 17 in certain situations, for details, see:

- https://github.com/keycloak/keycloak/issues/11316 ;
- https://github.com/NixOS/nixpkgs/issues/170539

This patch makes the CRC validation comprehensive with respect to older
or already existing checksums out there.

(cherry picked from commit 8335c46632)
2022-06-09 23:46:52 +00:00
ckie
f961520b1f Merge pull request #176411 from NixOS/backport-173408-to-release-22.05
[Backport release-22.05] vivaldi-widevine: hash update for upstream zip
2022-06-10 01:08:59 +03:00
Henri Menke
e5584bc53d libusb1: 1.0.25 -> 1.0.26
(cherry picked from commit 7f8d28e99b)
2022-06-09 21:45:52 +00:00
Jörg Thalheim
7aabede5f6 Merge pull request #177082 from NixOS/backport-177069-to-release-22.05
[Backport release-22.05] golangci-lint: only mark broken for x86_64 on darwin
2022-06-09 21:27:40 +01:00
John Ericson
a6e0f3aaa7 llvmPackages_14: Fix remaining broken gnu-install-dirs patches
(cherry picked from commit 942da65b07)
2022-06-09 20:26:32 +00:00
Malo Bourgon
928fc3bf56 golangci-lint: only mark broken for x86_64 on darwin
(cherry picked from commit 55a127751d)
2022-06-09 19:48:59 +00:00
Moritz Böhme
7c7f6d7d74 nixos/openconnect: add autoStart option
(cherry picked from commit 106bfcaf8a)
2022-06-09 19:03:45 +00:00
Domen Kožar
ce7d4c4e95 Merge pull request #177059 from domenkozar/cachix-agent-fix-user-22.05
[release-22.05] cachix-agent: set USER to please cachix
2022-06-09 13:57:34 -05:00
Domen Kožar
3c45db325a Merge pull request #177057 from NixOS/backport-176974-to-release-22.05
[Backport release-22.05] nix: patch curl netrc regression
2022-06-09 13:57:21 -05:00
Sergei Trofimovich
abfd8d94c2 jansson: enable shared library installation
Without shared libraries metworkmanager fails to build:

    $ nix build -f. networkmanager -L
    ...
    networkmanager> meson.build:269:2: ERROR: Assert failed: Unable to determine Jansson SONAME

(cherry picked from commit 938f2ce101)
2022-06-09 18:49:11 +01:00
Guillaume Girol
4348fc64bf Merge pull request #176345 from NixOS/backport-176294-to-release-22.05
[Backport release-22.05] gstreamer plugins good: fix qt support
2022-06-09 17:47:52 +00:00
Domen Kožar
4dc549819a cachix-agent: set USER to please cachix
(cherry picked from commit f38fd46992)
2022-06-09 17:32:45 +01:00
Domen Kožar
28bb699584 check that password is not blank
Co-authored-by: Robert Hensing <roberth@users.noreply.github.com>
(cherry picked from commit 85f2a13ee3)
2022-06-09 16:19:13 +00:00
Domen Kožar
dd94e0df79 nix: patch curl netrc regression
https://github.com/curl/curl/issues/8653
(cherry picked from commit 7434c16611)
2022-06-09 16:19:13 +00:00
Fabian Affolter
2119531de6 Merge pull request #177017 from sgiroux-spwr/backport-174952-to-release-22.05
[22.05] python310Packages.bravado-core: disable failing tests
2022-06-09 17:38:05 +02:00
Jeremy Kolb
7cf936ba73 open-vm-tools: fix shared folders
(cherry picked from commit 12d74e3abf)
2022-06-09 15:14:10 +00:00
Thiago Kenji Okada
41f240fe87 Merge pull request #177030 from NixOS/backport-176821-to-release-22.05
[Backport release-22.05] fx_cast: 0.1.2 -> 0.2.0
2022-06-09 14:35:11 +01:00
PedroHLC ☭
c068aa6975 fx_cast: 0.1.2 -> 0.2.0
Reviews:

- Just makes the error message a bit nicer. (kevincox)

Co-authored-by: Kevin Cox <kevincox@kevincox.ca>
(cherry picked from commit 6850695d67)
2022-06-09 13:20:53 +00:00
Doron Behar
df60447f02 Merge pull request #176988 from NixOS/backport-175658-to-release-22.05 2022-06-09 16:12:02 +03:00
Janne Heß
b6b76ff53e Merge pull request #176960 from NixOS/backport-176907-to-release-22.05
[Backport release-22.05] firejail: patches for CVE-2022-31214
2022-06-09 15:06:02 +02:00
Mauricio Collares
49e4273716 poppler: 22.04.0 -> 22.06.0
(cherry picked from commit cb93c3b900)
2022-06-09 13:01:55 +00:00
Bobby Rong
eea6ffb684 Merge pull request #176906 from NixOS/backport-176569-to-release-22.05
[Backport release-22.05] appflowy: 0.0.3 -> 0.0.4
2022-06-09 20:57:38 +08:00
sgiroux-spwr
38dbda117a python310Packages.bravado-core: disable failing tests
(cherry picked from commit 44011a0502)
2022-06-09 11:32:09 +00:00
Vincent Laporte
139f46487a ocamlPackages.menhir: 20211128 → 20220210
(cherry picked from commit c3609799ebc4c4139d81dd17d962b2fe018e6291)
2022-06-09 11:08:44 +02:00
Vincent Laporte
801180e44a liquidsoap: pin menhir dependency
(cherry picked from commit 1d68645ab06ce9db40f86ed239e315ad63fdd0b9)
2022-06-09 11:08:44 +02:00
Vincent Laporte
a3a025385a alt-ergo: ensure compatibility with Menhir ≥ 20211215
(cherry picked from commit 2bf692b604d3dced3d1a18a0bd91dbe26f7ba2a1)
2022-06-09 11:08:44 +02:00
Vincent Laporte
23e09b1789 oacmlPackages.toml: make compatible with menhir ≥ 20211215
(cherry picked from commit e98a1c948a5522252feea167ff1533c25dbba576)
2022-06-09 11:08:44 +02:00
Vincent Laporte
c791eaec13 oacmlPackages.odate: make compatible with menhir ≥ 20211215
(cherry picked from commit 3b024fd6722e914cb98d78f30a43091e24f20b2e)
2022-06-09 11:08:44 +02:00
Thiago Kenji Okada
91ec188c8a Merge pull request #177004 from NixOS/backport-176987-to-release-22.05
[Backport release-22.05] fluxcd: 0.31.0 -> 0.31.1
2022-06-09 09:49:57 +01:00
R. Ryantm
20ae280652 fluxcd: 0.31.0 -> 0.31.1
(cherry picked from commit 2f0426187c)
2022-06-09 08:33:42 +00:00
Janne Heß
c3f4ada930 Merge pull request #176920 from NixOS/backport-175655-to-release-22.05
[Backport release-22.05] ec2-amis: add release 22.05
2022-06-09 10:33:41 +02:00
Arnout Engelen
ea7f796287 Merge pull request #176472 from NixOS/backport-175954-to-release-22.05
[Backport release-22.05] opensnitch-ui: fix events table and notifications
2022-06-09 09:30:38 +02:00
Vladimír Čunát
e5556c75ac Merge #176992: python3Packages.black: disable all tests on aarch64-linux
...into release-22.05
2022-06-09 09:13:10 +02:00
Vladimír Čunát
502b36599c python3Packages.black: disable all tests on aarch64-linux
For now at least.  I'm tired of this channel-blocking chase:
https://github.com/NixOS/nixpkgs/pull/176991#issuecomment-1150736907

(cherry picked from commit 9ed9ea16af)
2022-06-09 09:04:21 +02:00
Vladimír Čunát
0ce449519c python3Packages.black: disable another test on aarch64-linux
Basically the same as commit 3fcf9f18dd.
https://hydra.nixos.org/build/179644263

(cherry picked from commit f954e8acd7)
2022-06-09 06:33:15 +00:00
Bernardo Meurer
272c9ec408 beets: fix external plugins in pluginOverrides
(cherry picked from commit 4845c93713)
2022-06-09 05:04:18 +00:00
adisbladis
2a6acf223f poetry2nix: 1.29.1 -> 1.30.0
(cherry picked from commit 213d9cfba1)
2022-06-08 18:28:58 -07:00
github-actions[bot]
929a607ab7 Merge staging-next-22.05 into staging-22.05 2022-06-09 00:15:38 +00:00
github-actions[bot]
333a226ab6 Merge release-22.05 into staging-next-22.05 2022-06-09 00:15:03 +00:00
Stig Palmquist
58b0e70f6b firejail: patches for CVE-2022-31214
https://seclists.org/oss-sec/2022/q2/188
(cherry picked from commit b31db15de0)
2022-06-08 22:26:11 +00:00
ckie
578757aec2 Merge pull request #176957 from NixOS/backport-176937-to-release-22.05
[Backport release-22.05] discord: 0.0.17 -> 0.0.18
2022-06-09 01:00:07 +03:00
Ayman El Didi
62d07231d2 discord: 0.0.17 -> 0.0.18
(cherry picked from commit 808aad6cee)
2022-06-08 21:32:09 +00:00
Klemens Nanni
13f96c0674 keepassxc: Wrap once
Using Qt *and* GTK means both wrapper hooks kick in, so avoid automatic
GTK wrapping and merge arguments into Qt ones as usual.

Duplicate wrapping must be avoided as it breaks the program's basename,
e.g. `argv[0]` ends up with ".keepassxc-wrapped" rather than
"keepassxc" as basename.

This fixes all three ELF executables (there is `-cli` and `-proxy`).

(cherry picked from commit 0b497c5c57a042ec19e07c7594acd8a5b3f85bd1)
2022-06-08 23:23:39 +02:00
Fabian Affolter
38f3e4049f Merge pull request #176858 from NixOS/backport-176604-to-release-22.05
[Backport release-22.05] cloud-init: fix missing pyserial dependency
2022-06-08 21:55:17 +02:00
Pierre Roux
81123ec567 coq_8_16: init at 8.16+rc1
(cherry picked from commit d84d0a8231ae89afbc6ca9f7e5e1a100d13310e9)
2022-06-08 20:36:58 +02:00
Sebastien Bourdeauducq
0a2e00bc78 hydra: create runcommand-logs directory
(cherry picked from commit aa15c27bcc81578d093649ab33ad1abba1d4ed68)
2022-06-08 11:28:31 -07:00
Vincent Laporte
5264e1e775 ocamlPackages.cooltt: unstable-2021-05-25 → unstable-2022-04-28
(cherry picked from commit 5b1670d41decb70208999230cbc3ccde0f9e0718)
2022-06-08 20:07:41 +02:00
Vincent Laporte
dbfe9c1646 ocamlPackages.yuujinchou: init at 2.0.0
(cherry picked from commit 9ddee86492c6a97d366c5ff05da9bd4a74ed1153)
2022-06-08 20:07:41 +02:00
Vincent Laporte
3986d3e583 ocamlPackages.bwd: init at 2.0.0
(cherry picked from commit 3460ac5c74e2d8483502db1dde5344544fafb1d5)
2022-06-08 20:07:41 +02:00
AmineChikhaoui
1c763e09cf ec2-amis: add release 22.05
(cherry picked from commit 3909226544)
2022-06-08 15:44:33 +00:00
DarkOnion0
007f188f9e appflowy: 0.0.3 -> 0.0.4
(cherry picked from commit 0106c4b159)
2022-06-08 13:56:59 +00:00
Bobby Rong
7e7798cd82 Merge pull request #176897 from NixOS/backport-175578-to-release-22.05
[Backport release-22.05] CONTRIBUTING.md: use 22.05 as target branch for backports
2022-06-08 21:16:53 +08:00
Markus S. Wamser
91fcce8d06 CONTRIBUTING.md: use 22.05 as target branch for backports
(cherry picked from commit 924b27e479)
2022-06-08 13:07:58 +00:00
linj
d5c354ce5e nixos/ibus: fix services.dbus.package
(cherry picked from commit bbf947dbd860dd959688dd3d323fc0c10a14dad1)
2022-06-08 12:43:51 +00:00
Jules Aguillon
f745b8d677 ocamlPackages.cmdliner_1_0: Update license
License changed on version 1.0.0 from bsd3 to isc.

(cherry picked from commit bcbbbea82e)
2022-06-08 13:04:41 +02:00
Jules Aguillon
ffd6285801 ocamlformat: 0.20.1 -> 0.21.0
The cmdliner dependency changed.
Update older version to use cmdliner_1_0 explicitly to be ready when it
changes.

(cherry picked from commit 29750d369c)
2022-06-08 13:04:41 +02:00
Jules Aguillon
3d35c9ebec ocamlPackages.cmdliner_1_1: init at 1.1.1
Add the latest version of cmdliner. This release broke many packages and
have more constraining dependencies so the previous version cannot be
removed from nixpkgs for now.

The previous version is still available as ocamlPackages.cmdliner_1_0
and ocamlPackages.cmdliner points to it for now.

(cherry picked from commit 5a61d18997)
2022-06-08 13:04:41 +02:00
Robert Hensing
328b3188f1 Merge pull request #176873 from NixOS/backport-176558-to-release-22.05
[Backport release-22.05] nixos/nix-daemon: set LimitNOFILE to infinity
2022-06-08 12:20:34 +02:00
Artturin
d1dea16cf8 nixos/nix-daemon: set LimitNOFILE to 1048576
fixes 'too many open files'

(cherry picked from commit c8f5b17a98)
2022-06-08 10:07:56 +00:00
Jan Tojnar
3ce27780ae deja-dup: 43.2 → 43.3
Now requires desktop file installation for adding Google & Microsoft accounts
to register URI handler – running in nix-shell not sufficient for initial authentication.

https://gitlab.gnome.org/World/deja-dup/-/compare/43.2...43.3

Fixes: https://github.com/NixOS/nixpkgs/issues/173780
(cherry picked from commit 56e4006b111ada81f51b5b906ff6d50e1e373ff1)
2022-06-08 17:38:58 +08:00
Vincent Laporte
0421607bad qarte: 4.15.1 → 4.17.1
(cherry picked from commit a6494aad0bddfb46e3d5ac6be37408bdbdbea3e0)
2022-06-08 10:48:01 +02:00
Eliza
60eee107fa mujmap: 0.1.1 -> 0.2.0 (#176833)
(cherry picked from commit a93aa04c4cfb5f44d4bda3a3bb3ee47d2fea180b)
2022-06-08 10:09:25 +02:00
teutat3s
deb8c7da8a cloud-init: fix missing pyserial dependency
and check for all required imports as per requirements.txt

While debugging missing metadata in the cloud-init boot local phase
in a NixOS VM on SmartOS, the following error was observed:
SystemError: Unable to open /dev/ttyS1
Adding the missing pyserial dependency fixes the above error and
cloud-init metadata detection now works in NixOS VMs on SmartOS

(cherry picked from commit cf594d1f6e)
2022-06-08 07:53:19 +00:00
Vladimír Čunát
986a0d0d8e Merge #176402: staging-next-22.05 - iteration 1
aarch64-darwin has still many binaries to build, but I'd rather
merge already, and the darwin channel can catch up later.
2022-06-08 07:41:19 +02:00
André Vitor de Lima Matos
c2ceee505a loki-lib: compile with c++11
(cherry picked from commit 4b6301d656)
It wouldn't build otherwise.
2022-06-08 07:30:11 +02:00
Vincent Laporte
047fa3ed1d gajim: 1.4.2 → 1.4.3
(cherry picked from commit ae9f904eb2)
2022-06-08 05:20:41 +00:00
github-actions[bot]
f15870d1b2 Merge staging-next-22.05 into staging-22.05 2022-06-08 00:15:04 +00:00
github-actions[bot]
77ff00ed88 Merge release-22.05 into staging-next-22.05 2022-06-08 00:14:28 +00:00
github-actions[bot]
93109b6d79 python3Packages.validphys2: add missing dependencies (#176818)
Those are needed for the report generation.

(cherry picked from commit fa1d382bd6)
2022-06-07 18:39:35 -04:00
adisbladis
2465176f04 rmfuse: Re-lock dependencies
So Pillow is bumped https://pillow.readthedocs.io/en/stable/releasenotes/9.1.1.html.

Closes #175600

(cherry picked from commit 4537ba53c0)
2022-06-07 14:42:45 -07:00
Rick van Schijndel
ed9eb4d122 Merge pull request #176778 from NixOS/backport-176374-to-staging-22.05
[Backport staging-22.05] portaudio: fix cross compilation
2022-06-07 21:19:18 +02:00
Nick Cao
33fbbd440c portaudio: set strictDeps
(cherry picked from commit a0aeec7e43)
2022-06-07 18:21:11 +00:00
Nick Cao
75e43102af portaudio: fix cross compilation
(cherry picked from commit e5cb006914)
2022-06-07 18:21:11 +00:00
DarkOnion0
adc9804e82 drawio: 18.1.3 -> 19.0.2 2022-06-07 20:15:37 +02:00
Rick van Schijndel
a215825528 opencv4: disable hdf5 for cross-compilation
This gets us as far as building opencv, but it doesn't completely build yet

(cherry picked from commit aa9f72b92b)
2022-06-07 17:28:24 +00:00
Rick van Schijndel
11e805f993 Merge pull request #176665 from NixOS/backport-176494-to-release-22.05
[Backport release-22.05] jpegexiforient: fix cross-compilation
2022-06-07 19:17:45 +02:00
Robert Schütz
304e2d02b6 python2Packages.pyjwt: mark insecure
(cherry picked from commit 007ffa6069)
2022-06-07 09:59:50 -07:00
Robert Schütz
6e4b2fd7d7 nixops: mark insecure
(cherry picked from commit e174b463e7)
2022-06-07 09:59:50 -07:00
Robert Schütz
3e0f5acc6e python2Packages.urllib3: mark insecure
(cherry picked from commit ac4fc73abc)
2022-06-07 09:58:49 -07:00
Pierre Bourdon
33c340469f ntfs3g: 2021.8.22 -> 2022.5.17
This is unfortunately more complex than a simple version bump because
upstream has not released a dist tarball for this release. This commit
switches to using the github source and running autoreconf ourselves.

Along the way, stop randomly patching sources and Makefiles and instead
switch to upstreamable alternatives. The two (small) build system
patches have been sent upstream, see tuxera/ntfs-3g#39.

(cherry picked from commit 58d2ebb283)
2022-06-07 16:49:29 +00:00
Artturi
ae39e1e3b6 Merge pull request #176646 from NixOS/backport-176291-to-staging-22.05 2022-06-07 18:55:34 +03:00
maxine [they]
fd5a117f09 Merge pull request #176490 from NixOS/backport-175790-to-release-22.05
[Backport release-22.05] libadwaita: 1.1.1 -> 1.1.2
2022-06-07 17:38:10 +02:00
Jakub Kozłowski
daa78e40e9 Merge pull request #176652 from NixOS/backport-175496-to-release-22.05 2022-06-07 14:33:25 +02:00
André-Patrick Bubel
9a839960ad prusa-slicer: use patched wxWidgets
With the upstream wxWidgets version prusa-slicer crashes under certain
circumstances (https://github.com/NixOS/nixpkgs/issues/168358)

Prusa3D provides a patched version of wxWidgets, fixing this and other issues.

The 'wxGTK31-gtk3-override' option provides a way to specify the
wxWidgets package, e.g. so that `super-slicer` can use its own version.

(cherry picked from commit f9e2c5443c)
2022-06-07 11:47:20 +00:00
Vincent Laporte
4974116c6f coq: 8.15.1 → 8.15.2
(cherry picked from commit 3e1ea09b77688b3739fb79391b05518e0b0097e8)
2022-06-07 11:56:45 +02:00
Vincent Laporte
be395ed2c9 compcert: add support for Coq 8.15.2
(cherry picked from commit 4831380bd3a513ccaffce433d7b39df9b030ba46)
2022-06-07 11:56:45 +02:00
Vincent Laporte
e13c9688ae coqPackages.VST: fix build with Coq 8.15.2
(cherry picked from commit 996c8bf8b742fdef99ee9a919f94678c422e2a4c)
2022-06-07 11:56:45 +02:00
Thiago Kenji Okada
484b9212d9 Merge pull request #176686 from NixOS/backport-176660-to-release-22.05
[Backport release-22.05] fluxcd: 0.30.2 -> 0.31.0
2022-06-07 10:43:01 +01:00
R. Ryantm
ba83087f6f fluxcd: 0.30.2 -> 0.31.0
(cherry picked from commit 17b53760f6)
2022-06-07 09:26:44 +00:00
Alex Martens
df8a72b1f2 github-runner: 2.291.1 -> 2.292.0
(cherry picked from commit 36fbecf109)
2022-06-07 08:58:45 +00:00
Mario Rodas
605730650f Merge pull request #176663 from NixOS/backport-176302-to-staging-22.05
[Backport staging-22.05] jansson: 2.13.1 -> 2.14
2022-06-07 00:47:39 -05:00
Brian McKenna
ee4e811231 jpegexiforient: fix cross-compilation
(cherry picked from commit 535900e91d)
2022-06-07 05:31:31 +00:00
Mario Rodas
31d40705e8 jansson: add marsam to maintainers
(cherry picked from commit 2b6596c426)
2022-06-07 05:13:51 +00:00
Mario Rodas
a648088048 jansson: 2.13.1 -> 2.14
https://github.com/akheron/jansson/raw/v2.14/CHANGES
(cherry picked from commit 9ac2a6f064)
2022-06-07 05:13:51 +00:00
Anderson Torres
51ec056092 Merge pull request #176639 from NixOS/backport-176629-to-release-22.05
[Backport release-22.05] gitlab: 15.0.1 -> 15.0.2
2022-06-06 23:11:06 -03:00
Jakub Kozłowski
2db7bc424f scala-cli: 0.1.5 -> 0.1.6
(cherry picked from commit bab6e29256)
2022-06-07 02:08:45 +00:00
Jakub Kozłowski
906dfcba52 scala-cli: add updater
(cherry picked from commit 567b83ebbd)
2022-06-07 02:08:45 +00:00
Artturin
61bde9b861 mailcap: fix build
and prevent future inf rec issues

(cherry picked from commit 80f9a78c01)
2022-06-07 00:43:04 +00:00
Sandro Jäckel
526a0b8047 cacert: use buildcatrust build with python3Minimal
to avoid inifinite recursion with mailcap

Co-authored-by: Artturi <Artturin@artturin.com>
(cherry picked from commit 81c57a8407)
2022-06-07 00:43:04 +00:00
Anderson Torres
a45d53b958 Merge pull request #176641 from NixOS/backport-173939-to-release-22.05
[Backport release-22.05] tauon: 7.1.3 -> 7.2.1
2022-06-06 21:34:32 -03:00
github-actions[bot]
5d5436c42b Merge staging-next-22.05 into staging-22.05 2022-06-07 00:14:22 +00:00
github-actions[bot]
b7b67cd93f Merge release-22.05 into staging-next-22.05 2022-06-07 00:13:18 +00:00
Jan Solanti
5257ffbd0d tauon: 7.1.3 -> 7.2.1
(cherry picked from commit 2be636a8c3)
2022-06-07 00:01:50 +00:00
José Romildo Malaquias
782443388e Merge pull request #176637 from NixOS/backport-175309-to-release-22.05
[Backport release-22.05] jwm: 2.4.1 -> 2.4.2
2022-06-06 20:46:51 -03:00
Yaya
0f5afc8b3a gitlab: 15.0.1 -> 15.0.2
https://about.gitlab.com/releases/2022/06/06/gitlab-15-0-2-released/
(cherry picked from commit b1e63fdb4073bfee8833902ce43293b256a88adb)
2022-06-06 23:11:24 +00:00
José Romildo
33052fc8e0 jwm: reformat
(cherry picked from commit 02aa3bff8c)
2022-06-06 22:39:37 +00:00
José Romildo
83c1b05332 jwm: add update script
(cherry picked from commit ea4692000b)
2022-06-06 22:39:37 +00:00
José Romildo
c703258873 jwm: 2.4.1 -> 2.4.2
(cherry picked from commit 889c8592d5)
2022-06-06 22:39:37 +00:00
Thiago Kenji Okada
fa5a81c651 Merge pull request #176615 from NixOS/backport-176582-to-release-22.05
[Backport release-22.05] htop-vim: unstable-2021-10-11 -> unstable-2022-05-24
2022-06-06 23:29:57 +01:00
Thiago Kenji Okada
83cdcb59de htop-vim: unstable-2021-10-11 -> unstable-2022-05-24
(cherry picked from commit 475b010143)
2022-06-06 20:05:26 +00:00
github-actions[bot]
f05e7d39a4 [Backport release-22.05] pySmartDL: init at 1.3.4 (#176579)
Co-authored-by: WeebSorceress <hello@weebsorceress.anonaddy.me>
2022-06-06 20:37:50 +02:00
github-actions[bot]
34fb2fe9d2 [Backport release-22.05] cfscrape: init at 2.1.1 (#176583)
Co-authored-by: WeebSorceress <hello@weebsorceress.anonaddy.me>
2022-06-06 20:37:37 +02:00
Martin Weinelt
eb0e60c666 Merge pull request #176562 from NixOS/backport-176290-to-staging-22.05 2022-06-06 18:38:48 +02:00
Janne Heß
4ec9ae5800 openldap: Fix some issues by applying patches
These patches are from the 2.6 support branch and will hence make it
into 2.6.3 at a later point. At this point however, I cannot use slapd
as a syncrepl slave because it segfaults on startup. This also fixes
parallel build.

(cherry picked from commit b32df807ea)
2022-06-06 15:36:32 +00:00
Rick van Schijndel
9acc2a130b Merge pull request #176363 from doronbehar/release/fix-eval
python3.pkgs.manticore: mark as broken only once
2022-06-06 13:43:39 +02:00
Vladimír Čunát
a34761e758 Merge #176512: python3Packages.black: disable test on aarch64-linux
...into staging-next-22.05
2022-06-06 08:31:41 +02:00
Martin Weinelt
dbef7d2abb python3Packages.black: disable test on aarch64-linux
This test reproducibly triggers the max open files limit on our
aarch64 hydra builders. Disable it for now to make tests work again but
this can't be the final solution.

https://hydra.nixos.org/build/179001754
(cherry picked from commit 3fcf9f18dd)
2022-06-06 06:19:19 +00:00
Robert Schütz
c3d24a1a1b libadwaita: 1.1.1 -> 1.1.2
https://gitlab.gnome.org/GNOME/libadwaita/-/blob/1.1.2/NEWS
(cherry picked from commit c2cc778be6)
2022-06-06 01:02:12 +00:00
Fabián Heredia Montiel
6cd795ae32 mill: 0.10.3 → 0.10.4
https://github.com/com-lihaoyi/mill/releases/tag/0.10.4
(cherry picked from commit ceb01c3d48)
2022-06-06 00:41:56 +00:00
github-actions[bot]
cf19ffbfe6 Merge staging-next-22.05 into staging-22.05 2022-06-06 00:14:24 +00:00
github-actions[bot]
991b652b2d Merge release-22.05 into staging-next-22.05 2022-06-06 00:13:43 +00:00
Kerstin
b5243a0c09 Merge pull request #176469 from NixOS/backport-176415-to-release-22.05
[Backport release-22.05] imagemagick: 7.1.0-36 -> 7.1.0-37
2022-06-05 23:28:51 +02:00
Ram Kromberg
d00911b913 opensnitch-ui: fix events table and notifications
(cherry picked from commit c49b3af8b4)
2022-06-05 20:48:55 +00:00
Ram Kromberg
fff418b182 pyasn: add missing databases
(cherry picked from commit 9644cda0a0)
2022-06-05 20:48:54 +00:00
Robert Schütz
33736f6dbb imagemagick: 7.1.0-36 -> 7.1.0-37
(cherry picked from commit 2badffbd99)
2022-06-05 20:27:20 +00:00
zimbatm
14876f0dab exiftool: fix mainProgram
By default `lib.getExe` and `nix run` assume there is a binary at
"$out/bin/$pname" unless "meta.mainProgram" is specified. Since the
pname here is "perl5.34.1-Image-ExifTool", pass the "meta.mainProgram".

(cherry picked from commit e58688ff18dfcdd452968005e7944c74d3a1acc7)
2022-06-05 20:38:02 +02:00
Paul S
3c7761046e vivaldi-widevine: switch to fetchzip
hopefully it makes the hash not change sometimes

(cherry picked from commit 208a03de93)
2022-06-05 16:04:29 +00:00
Thiago Kenji Okada
ca2629644d Merge pull request #176365 from NixOS/backport-175226-to-release-22.05
[Backport release-22.05] argocd: 2.3.3 -> 2.3.4
2022-06-05 16:28:57 +01:00
Vladimír Čunát
b7374e31f7 Merge branch 'staging-22.05' into staging-next-22.05 2022-06-05 16:40:57 +02:00
legendofmiracles
e56f11391a Merge pull request #176395 from NixOS/backport-176333-to-release-22.05
[Backport release-22.05] noisetorch: 0.11.5 -> 0.12.0
2022-06-05 07:28:54 -06:00
Denbeigh Stevens
5ef70710e2 noisetorch: 0.11.5 -> 0.12.0
(cherry picked from commit 74ed89f243)
2022-06-05 13:11:52 +00:00
Thiago Kenji Okada
db3d15f685 Merge pull request #176388 from thiagokokada/remove-duplicate-meta.broken
[release-22.05]  python3Packages.manticore: remove duplicate meta.broken
2022-06-05 13:48:13 +01:00
Thiago Kenji Okada
045c345362 python3Packages.manticore: remove duplicate meta.broken 2022-06-05 13:28:44 +01:00
Bryan A. S
f0a7f2ef8b argocd: 2.3.3 -> 2.3.4
- bump version

- add ldflag kubectlVersion, this introduces a new thing to change when upgrading this package

(cherry picked from commit 5f45f1cd28)
2022-06-05 10:41:37 +00:00
Doron Behar
9094beb054 python3.pkgs.manticore: mark as broken only once
Fix ofborg's evaluation on the release-22.05 branch. It's hard to blame
anyone for causing this evaluation error. Both commits
43072cd017 and
c5b2704fcd created the `meta.broken`
attribute. The diff of both commits doesn't indicate either had the
other `broken` attribute written.
2022-06-05 13:28:50 +03:00
Brian Leung
3e7031b70f universal-ctags: set meta.mainProgram
(cherry picked from commit 58fabf558b)
2022-06-05 12:15:41 +02:00
Brian Leung
ccbf17612d universal-ctags: 5.9.20220220.0 -> 5.9.20220529.0
(cherry picked from commit 06f3bb21cd)
2022-06-05 12:15:41 +02:00
Vladimír Čunát
6cc0f84bce Merge #176347: qt6: remove all references to aliases
...into release-22.05
2022-06-05 10:56:06 +02:00
Nick Cao
f3d83a1899 qt6: remove all references to aliases
(cherry picked from commit 3688fe70f4)
2022-06-05 08:55:20 +00:00
Vladimír Čunát
320587101c Merge #175974: airgeddon: init at 11.01 (into release-22.05) 2022-06-05 10:46:18 +02:00
Vladimír Čunát
7a0303bf04 Merge #175271: seatd: 0.6.4 -> 0.7.0 (into release-22.05) 2022-06-05 10:44:19 +02:00
Guillaume Girol
eb3a8dfa83 gstreamer plugins good: fix qt support
(cherry picked from commit 985adfdd50)
2022-06-05 08:42:34 +00:00
Vladimír Čunát
f5bb8b9125 Merge #174753: Revert "noto-fonts-cjk: switch back to variable font"
...into release-22.05
2022-06-05 10:42:33 +02:00
Vladimír Čunát
6d39682788 Merge #175568: python310Packages.pyramid_jinja2: disable failing tests
...into release-22.05
2022-06-05 10:38:37 +02:00
Vladimír Čunát
0de9fe258d Merge #175124: mars: fix build (into release-22.05) 2022-06-05 10:34:49 +02:00
Vladimír Čunát
020e766043 Merge #174260: python39Packages.manticore: relax crytic-compile constraint
...into release-22.05
2022-06-05 10:32:06 +02:00
Vladimír Čunát
61a805b39f Merge #174981: release-notes: don't encourage copying secrets to the store
...into release-22.05
2022-06-05 10:32:05 +02:00
Vladimír Čunát
f8bb16e043 Merge #174536: tracee: init at 0.7.0 (into release-22.05) 2022-06-05 10:32:04 +02:00
Vladimír Čunát
8ba4df74b9 Merge #174179: qt6: init at 6.3.0 (into release-22.05) 2022-06-05 10:32:03 +02:00
Bobby Rong
77b71d313e Merge pull request #176174 from NixOS/backport-176165-to-release-22.05
[Backport release-22.05] signal-desktop: 5.44.1 -> 5.45.0
2022-06-05 16:20:50 +08:00
Vladimír Čunát
5a8d61f439 Merge #174166: lingua-franca: 0.1.0-alpha -> 0.1.0-beta
...into release-22.05
2022-06-05 10:01:44 +02:00
Vladimír Čunát
873f89e5aa Merge #175326: zlog: patch CVE-2021-43521 (into release-22.05) 2022-06-05 09:59:44 +02:00
Vladimír Čunát
80ac87d376 Merge #175581: lua5_{2,4}: add patch for CVE-2022-28805
...into staging-22.05
2022-06-05 09:52:30 +02:00
Vladimír Čunát
0fb2c31456 Merge #175156: mesa: 22.0.2 -> 22.0.4 (into staging-22.05) 2022-06-05 09:47:03 +02:00
Vladimír Čunát
8826b362e1 Merge #175107: cups: 2.4.1 -> 2.4.2 (into staging-22.05) 2022-06-05 09:45:35 +02:00
Vladimír Čunát
765d5c88ba Merge #174979: gtk3: 3.24.33-2022-03-11 → 3.24.34
...into staging-22.05
2022-06-05 09:41:24 +02:00
Adam Joseph
f7c1aa6a22 arm-trusted-firmware: unfree only if hdcp.bin used; otherwise delete it
The `unfreeIncludeHDCPBlob` parameter was introduced as a result of
this reviewer request:

  https://github.com/NixOS/nixpkgs/issues/148890#issuecomment-1032002903

The default value `unfreeIncludeHDCPBlob?true` causes a change in the
`meta.license` field for all of the subpackages within
`pkgs/misc/arm-trusted-firmware/`, and results in them needing
`NIXPKGS_ALLOW_NONFREE=1`.

For non-Rockchip platforms the file hdcp.bin does not get included in
the output; the blob is for a Synopsys HDCP core that is currently
used only by Rockchip (although other companies could license it from
Synopsys in the future). Therefore on non-Rockchip we can delete
hdcp.bin before building instead of changing the license. This
preserves the ability to build them without NIXPKGS_ALLOW_NONFREE=1.

Let's do that.

Deleting hdcp.bin ensures that we won't be caught by surprise if some
future non-Rockchip Arm CPU licenses the same Synopsys HDCP core that
Rockchip is using.

Use easier-to-follow names for controlling the blob
inclusion/exclusion.  Also, if the blob is believed to be unnecessary,
delete it beforehand so we will know if we were wrong about that belief.

Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit 8485bfc9bf)
2022-06-04 23:46:56 -07:00
FliegendeWurst
dcfb7d8aa2 marp: add known vulnerability
Co-Authored-By: Jan Tojnar <jtojnar@gmail.com>
2022-06-05 06:31:15 +02:00
Mario Rodas
7387dd9eb6 Merge pull request #176111 from NixOS/backport-174035-to-release-22.05
[Backport release-22.05] ocamlPackages.sedlex: 2.4 → 2.5
2022-06-04 22:33:38 -05:00
github-actions[bot]
6b2b18c755 Merge staging-next-22.05 into staging-22.05 2022-06-05 00:17:19 +00:00
github-actions[bot]
61ccf9f2c6 Merge release-22.05 into staging-next-22.05 2022-06-05 00:16:44 +00:00
Artturi
d6cb04299c Merge pull request #176236 from NixOS/backport-176177-to-release-22.05 2022-06-04 23:07:00 +03:00
Smaug123
e0b17fd48c Mark dotnet unbroken
(cherry picked from commit 699fe4c869)
2022-06-04 18:50:15 +00:00
maxine [they]
d9794b04bf Merge pull request #176231 from NixOS/backport-176183-to-release-22.05
[Backport release-22.05] gnome.rygel: 0.40.3 -> 0.40.4
2022-06-04 18:40:07 +02:00
maxine [they]
191942953a Merge pull request #176232 from NixOS/backport-176178-to-release-22.05
[Backport release-22.05] evolution: 3.44.1 -> 3.44.2
2022-06-04 18:39:55 +02:00
Evgeny Kurnevsky
57da584e6f deadbeef-statusnotifier-plugin: fix libdbusmenu dependency
(cherry picked from commit f630ac5f2d)
2022-06-04 13:30:58 +00:00
ckie
fe540a2bf6 Merge pull request #175979 from ckiee/backport-175607-to-release-22.05-2
[Backport release-22.05] matrix-synapse: 1.59.1 -> 1.60.0
2022-06-04 15:30:08 +03:00
Artturin
cfc4d0255f font-awesome,mplus-fonts: fix build
(cherry picked from commit c5b06df6a4)
2022-06-04 12:04:43 +00:00
Robin Gloster
2de8b2cb8b Merge pull request #176234 from NixOS/backport-176220-to-release-22.05
[Backport release-22.05] atlassian-confluence: 7.17.1 -> 7.18.1
2022-06-04 14:01:03 +02:00
Martin Weinelt
3a42342c86 atlassian-confluence: 7.17.1 -> 7.18.1
(cherry picked from commit 4f250bc45a)
2022-06-04 12:00:17 +00:00
R. Ryantm
21087863f7 evolution: 3.44.1 -> 3.44.2
(cherry picked from commit 32022909005fbc0a5b3c57eef98fcec404b915d0)
2022-06-04 11:50:39 +00:00
R. Ryantm
4148cf1160 gnome.rygel: 0.40.3 -> 0.40.4
(cherry picked from commit 676e0e7efc2a8bebc190cff2f0f669dd9715950d)
2022-06-04 11:50:29 +00:00
Rick van Schijndel
a18fa2eb5a Merge pull request #175320 from NixOS/backport-174140-to-staging-22.05
[Backport staging-22.05] Revert "xorg.xorgserver: 1.20.13 -> 21.1.3"
2022-06-04 13:42:09 +02:00
maxine [they]
d7e7254a5e Merge pull request #175594 from NixOS/backport-175575-to-release-22.05
[Backport release-22.05] gtk4: 4.6.4 -> 4.6.5
2022-06-04 13:41:17 +02:00
maxine [they]
027d7a8b8c Merge pull request #174700 from NixOS/backport-174436-to-staging-22.05
[Backport staging-22.05] librsvg: 2.54.1 -> 2.54.3
2022-06-04 13:40:45 +02:00
maxine [they]
a695e0e150 Merge pull request #175782 from NixOS/backport-175722-to-release-22.05
[Backport release-22.05] webkitgtk: 2.36.2 -> 2.36.3
2022-06-04 13:40:16 +02:00
maxine [they]
8c7df9aefa Merge pull request #175596 from NixOS/backport-175561-to-staging-22.05
[Backport staging-22.05] glib: 2.72.1 -> 2.72.2
2022-06-04 13:40:08 +02:00
maxine [they]
e1ad60aded Merge pull request #176155 from NixOS/backport-176106-to-release-22.05
[Backport release-22.05] gnome-firmware: 42.1 -> 42.2
2022-06-04 13:39:36 +02:00
Mario Rodas
9fb2fc288a Merge pull request #175697 from NixOS/backport-175665-to-release-22.05
[Backport release-22.05] ledger: fix Python 3.10 module build
2022-06-04 06:02:51 -05:00
Martin Weinelt
122449b028 Merge pull request #176223 from NixOS/backport-175836-to-release-22.05 2022-06-04 13:02:37 +02:00
Lara
e6e9127a56 gitlab: 15.0.0 -> 15.0.1
https://about.gitlab.com/releases/2022/06/01/critical-security-release-gitlab-15-0-1-released/

Fixes: CVE-2022-1680, CVE-2022-1940, CVE-2022-1948, CVE-2022-1935,
       CVE-2022-1936, CVE-2022-1944, CVE-2022-1821, CVE-2022-1783
(cherry picked from commit e2293f8b903bd429d5aac0602160ca7b24cae446)
2022-06-04 10:41:31 +00:00
Eduardo Quiros
3e044ceecc signal-desktop: 5.44.1 -> 5.45.0
(cherry picked from commit 1a931f6eca)
2022-06-04 02:07:50 +00:00
github-actions[bot]
b9ca77a266 Merge staging-next-22.05 into staging-22.05 2022-06-04 00:15:18 +00:00
github-actions[bot]
f6b813dd6f Merge release-22.05 into staging-next-22.05 2022-06-04 00:14:42 +00:00
Bobby Rong
90c12d4986 gnome-firmware: 42.1 → 42.2
https://gitlab.gnome.org/World/gnome-firmware/-/compare/42.1...42.2
(cherry picked from commit d1f54d60aa)
2022-06-03 21:44:13 +00:00
Bobby Rong
eecb986bad gnome-firmware: add update script
(cherry picked from commit 5f36ed3f87)
2022-06-03 21:44:13 +00:00
Thiago Kenji Okada
7a20c208aa Merge pull request #176129 from NixOS/backport-175965-to-release-22.05
[Backport release-22.05] Add new restic options for NixOS module
2022-06-03 18:04:27 +01:00
maxine [they]
81c8e47da2 Merge pull request #174890 from NixOS/backport-174855-to-release-22.05
[Backport release-22.05] gnome.gvfs: 1.50.1 -> 1.50.2
2022-06-03 17:30:37 +02:00
maxine [they]
e98de5749f Merge pull request #175101 from NixOS/backport-175071-to-release-22.05
[Backport release-22.05] gnome.nautilus: 42.1.1 -> 42.2
2022-06-03 17:30:10 +02:00
maxine [they]
b7284342f3 Merge pull request #175721 from NixOS/backport-175686-to-release-22.05
[Backport release-22.05] gnome.gnome-settings-daemon: 42.1 -> 42.2
2022-06-03 17:29:59 +02:00
maxine [they]
9e679ae85b Merge pull request #175103 from NixOS/backport-175060-to-release-22.05
[Backport release-22.05] evolution-data-server: 3.44.1 -> 3.44.2
2022-06-03 17:29:41 +02:00
maxine [they]
fb8c5bab75 Merge pull request #175461 from NixOS/backport-175428-to-release-22.05
[Backport release-22.05] gnome.mutter: 42.1 -> 42.2
2022-06-03 17:29:16 +02:00
maxine [they]
80d04fece5 Merge pull request #175462 from NixOS/backport-175424-to-release-22.05
[Backport release-22.05] gnome.gnome-shell: 42.1 -> 42.2
2022-06-03 17:29:03 +02:00
Otavio Salvador
7ba0bb440c nixos/restic: add backup{Prepare,Cleanup}Command options
The backupPrepareCommand and backupCleanupCommand options offer a way to
run a script to prepare for backup and then cleanup it once finish.

Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit d9e3b1fafe)
2022-06-03 15:25:20 +00:00
Otavio Salvador
925b07e7b5 nixos/restic: add new repositoryFile option
Allow providing the repository as a file, useful when we don't want it
being stored in the Git repository as plain text.

Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit deae887c5a)
2022-06-03 15:25:20 +00:00
Otavio Salvador
c3701b64c8 nixos/restic: reformat
Apply nixpkgs-fmt on file prior doing changes.

Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit 082a4184ec)
2022-06-03 15:25:20 +00:00
Jan Tojnar
73e97ed8ea wpscan: 3.8.20 → 3.8.22
(cherry picked from commit c2608d3ea0)
2022-06-03 14:23:03 +00:00
Vincent Laporte
fed87a5975 ocamlPackages.sedlex: 2.4 → 2.5
(cherry picked from commit 138f2534513cc0449d9524773476f9fa0aad2431)
2022-06-03 13:48:25 +00:00
Vincent Laporte
7e78ab82a5 ocamlPackages: rename sedlex_2 into sedlex
(cherry picked from commit 4d795dc1b289cf05f2c5304f4514b4a419c94e63)
2022-06-03 13:48:25 +00:00
Vincent Laporte
135cf7fca6 ocamlPackages.sedlex: remove at 1.99.5
(cherry picked from commit 3668b3613b14d9862e90481cf7800ccba6d1fdfe)
2022-06-03 13:48:25 +00:00
maxine [they]
d06103277d Merge pull request #176076 from NixOS/backport-175916-to-release-22.05
[Backport release-22.05] _1password-gui: 8.7.0 -> 8.7.1
2022-06-03 12:37:51 +02:00
Thiago Kenji Okada
0d91f83af7 Merge pull request #176083 from NixOS/backport-173859-to-release-22.05
[Backport release-22.05] nvidia_x11: 390.147 → 390.151, 470.103.01 → 470.129.06, 510.68.02 → 515.48.07
2022-06-03 11:14:50 +01:00
Kiskae
0129fd2ff1 nvidia_x11: 390.147 → 390.151, 470.103.01 → 470.129.06, 510.68.02 → 515.48.07, beta → 515.43.04
(cherry picked from commit 51c38fa317)
2022-06-03 09:40:50 +00:00
Maxine Aubrey
8faa89d548 _1password-gui-beta: 8.8.0-11.BETA -> 8.8.0-119.BETA
(cherry picked from commit 2841a2876e)
2022-06-03 08:49:46 +00:00
Maxine Aubrey
ad6ea4717c _1password-gui: 8.7.0 -> 8.7.1
https://releases.1password.com/linux/8.7/#1password-for-linux-8.7.1
(cherry picked from commit e00c71926f)
2022-06-03 08:49:46 +00:00
Luke Granger-Brown
86afb0abd3 Merge pull request #176062 from NixOS/backport-175955-to-release-22.05
[Backport release-22.05] mercurial: 6.1.2 -> 6.1.3
2022-06-03 08:35:25 +01:00
techknowlogick
befd1c342a mercurial: add techknowlogick as maintainer
(cherry picked from commit ca19b56a93)
2022-06-03 06:50:04 +00:00
techknowlogick
bda438292e mercurial: 6.1.2 -> 6.1.3
(cherry picked from commit 98bc447a8a)
2022-06-03 06:50:04 +00:00
Justinas Stankevicius
008944edc2 gnomeExtensions.freon: fix patch for v48, simplify
(cherry picked from commit c0e56baaba)
2022-06-03 02:13:37 +00:00
Martin Weinelt
0f4c659650 Merge pull request #176023 from NixOS/backport-176021-to-release-22.05 2022-06-03 02:21:32 +02:00
Martin Weinelt
9c8395c017 python3Packages.coloredlogs: update hash
This didn't happen when the package was updated to 15.0.1 in #128965.

(cherry picked from commit e8d83130fb)
2022-06-03 00:19:46 +00:00
github-actions[bot]
c230316b8c Merge staging-next-22.05 into staging-22.05 2022-06-03 00:14:43 +00:00
github-actions[bot]
1a98982ac5 Merge release-22.05 into staging-next-22.05 2022-06-03 00:14:07 +00:00
Rick van Schijndel
498aaed2d9 Merge pull request #175977 from NixOS/backport-175865-to-release-22.05
[Backport release-22.05] mono: fix build on Darwin
2022-06-02 21:39:19 +02:00
Rick van Schijndel
b2ea3c9919 Merge pull request #175978 from NixOS/backport-175668-to-release-22.05
[Backport release-22.05] libspnav: fix cross-compilation
2022-06-02 21:32:00 +02:00
Adam Joseph
e3218853e0 libspnav: fix cross-compilation
Prior to this commit, pkgsCross.foo.libspnav would fail with something
like:

```
/nix/store/...-bash-5.1-p16/bin/bash: line 1: ar: command not found
```

Let's fix that by passing `AR=` in `makeFlags`.

(cherry picked from commit 96ac705f1b)
2022-06-02 18:47:07 +00:00
Robin Townsend
a650a723f8 matrix-synapse: Warn about state_group_edges changes in release notes
(cherry picked from commit d0eda68f5b)
2022-06-02 21:47:02 +03:00
Randy Eckenrode
4b8672d138 mono: fix broken mono4 build on Darwin
(cherry picked from commit 9ce157afc8)
2022-06-02 18:44:32 +00:00
Randy Eckenrode
b0f807d761 mono: be more precise in flagging broken builds
(cherry picked from commit 1622a6cdeb)
2022-06-02 18:44:32 +00:00
Robin Townsend
27398dd894 matrix-synapse: 1.59.1 -> 1.60.0
https://github.com/matrix-org/synapse/releases/tag/v1.60.0
(cherry picked from commit bb5f5eadf4)
2022-06-02 21:41:30 +03:00
Izorkin
74d1c336ae nixos/peertube: use redis.servers
(cherry picked from commit 0b1340f57b)
2022-06-02 18:31:20 +00:00
PedroHLC ☭
471ab8e5a0 airgeddon: init at 11.01
(cherry picked from commit 1e5b8da09d)
2022-06-02 18:26:06 +00:00
PedroHLC ☭
5776ccd20a Add @PedroHLC to maintainer-list
(cherry picked from commit df38903e79)
2022-06-02 18:26:06 +00:00
Rick van Schijndel
549a2d57ff Merge pull request #175890 from NixOS/backport-175647-to-release-22.05
[Backport release-22.05] gstreamer-good: support cross-compilation
2022-06-02 20:20:05 +02:00
José Romildo Malaquias
9d150ec144 Merge pull request #175038 from NixOS/backport-173655-to-release-22.05
[Backport release-22.05] libsForQt5.qtstyleplugin-kvantum: 1.0.1 -> 1.0.2
2022-06-02 14:30:15 -03:00
Vladimír Čunát
20f8d917cf gtk3: fixup build on *-darwin
(cherry picked from commit 161315c4de)
2022-06-02 23:05:13 +08:00
Bobby Rong
40e2b1ae05 Merge pull request #175374 from NixOS/backport-175368-to-release-22.05
[Backport release-22.05] signal-desktop: 5.43.0 -> 5.44.1
2022-06-02 22:56:33 +08:00
Sergei Trofimovich
7ce62f25fb ghc: use CXX=c++, not CXX=cxx
Otherwise attempt to build ghcHEAD from local checkout fails as:

    $ nix build -L --impure --expr 'with import ~/nm {}; haskell.compiler.ghcHEAD.overrideAttrs (oa: { src = ./.; patches = []; nativeBuildInputs = oa.nativeBuildInputs ++ [ git ]; })' --keep-failed
    ...
    ghc> checking C++ standard library flavour... ./configure: line 11487: /nix/store/r7r10qvsqlnvbzjkjinvscjlahqbxifl-gcc-wrapper-11.3.0/bin/cxx: No such file or directory

I think 'cxx' is not provided by stdenv.

(cherry picked from commit 849d47a928)
2022-06-02 11:23:57 +02:00
Rick van Schijndel
827b45cdb3 gst_all_1.gst-plugins-good: support cross-compilation
Enabling strictDeps verified by diffing with diffoscope.

(cherry picked from commit 43edcbfc73)
2022-06-02 05:21:48 +00:00
Rick van Schijndel
dcc5de94d9 libshout: ensure pkg-config file is generated when cross-compiling
(cherry picked from commit ed59f12ad5)
2022-06-02 05:21:48 +00:00
github-actions[bot]
4ba17cf0dd Merge staging-next-22.05 into staging-22.05 2022-06-02 00:19:07 +00:00
github-actions[bot]
2fc3ec89db Merge release-22.05 into staging-next-22.05 2022-06-02 00:18:33 +00:00
Martin Weinelt
791a85bb26 Merge pull request #175864 from NixOS/backport-175648-to-staging-22.05 2022-06-02 01:04:29 +02:00
ajs124
be1a4866b5 nss: sha256 -> hash
(cherry picked from commit 309bfdf2e2)
2022-06-01 22:47:00 +00:00
ajs124
7686e5a458 nss_latest: 3.78 -> 3.79
https://github.com/nss-dev/nss/blob/master/doc/rst/releases/nss_3_79.rst
(cherry picked from commit ae1f1709b7)
2022-06-01 22:47:00 +00:00
ajs124
20d0439be8 nss_esr: 3.68.3 -> 3.68.4
https://github.com/nss-dev/nss/blob/master/doc/rst/releases/nss_3_68_4.rst
(cherry picked from commit bf5c00fc75)
2022-06-01 22:46:59 +00:00
Martin Weinelt
9ff65cb28c Merge pull request #175861 from NixOS/backport-175855-to-release-22.05 2022-06-02 00:33:53 +02:00
Martin Weinelt
09d8bd180f python3Packages.django_4: 4.0.4 -> 4.0.5
https://docs.djangoproject.com/en/4.0/releases/4.0.5/
(cherry picked from commit 0a9a6fa6e2)
2022-06-01 22:24:23 +00:00
Ben Siraphob
51af43c68c Merge pull request #175744 from NixOS/backport-164779-to-release-22.05 2022-06-01 21:40:52 +00:00
piegames
46e420c9a3 Merge pull request #175664 from NixOS/backport-175535-to-release-22.05 2022-06-01 23:19:03 +02:00
Robert Scott
e15a101bc0 Merge pull request #175709 from NixOS/backport-175700-to-release-22.05
[Backport release-22.05] cvc4: fix build on darwin
2022-06-01 21:56:17 +01:00
Martin Weinelt
afd5b59fa9 Merge pull request #175761 from NixOS/backport-175729-to-release-22.05 2022-06-01 22:36:39 +02:00
Martin Weinelt
7880462d80 Merge pull request #175832 from NixOS/backport-175766-to-release-22.05 2022-06-01 22:36:18 +02:00
Martin Weinelt
a4dbc8c6f8 zigbeem2mqtt: 1.25.1 -> 1.25.2
https://github.com/Koenkk/zigbee2mqtt/releases/tag/1.25.2
(cherry picked from commit 4164876cd0)
2022-06-01 20:22:58 +00:00
Jacek Galowicz
a2b856c920 Merge pull request #175756 from NixOS/backport-175660-to-release-22.05
[Backport release-22.05] duplicity: use pydrive2 to fix Google Drive backup problems
2022-06-01 21:39:42 +02:00
maxine [they]
97bbad1c65 Merge pull request #175797 from NixOS/backport-175784-to-release-22.05 2022-06-01 20:41:39 +02:00
Maxine Aubrey
cdf66769ff terraform: 1.2.1 -> 1.2.2
https://github.com/hashicorp/terraform/releases/tag/v1.2.2
(cherry picked from commit f8aaaf68f7)
2022-06-01 18:26:19 +00:00
Jörg Thalheim
233a3beb55 Merge pull request #175794 from Mic92/fix-manual
[22.05] manual: fix build
2022-06-01 19:25:18 +01:00
Jörg Thalheim
940d55567e manual: fix build 2022-06-01 20:18:10 +02:00
sternenseemann
f3d3ec4f35 python3Packages.afdko: 3.8.1 -> 3.8.3
https://github.com/adobe-type-tools/afdko/blob/3.8.3/NEWS.md#383-released-2022-05-09
(cherry picked from commit 2cdbcc203a)
2022-06-01 19:07:32 +02:00
sternenseemann
e97790e39e python3Packages.tqdm: 4.63.1 -> 4.64.0
Only additions, no changes: https://github.com/tqdm/tqdm/releases/tag/v4.64.0

(cherry picked from commit fd30fff773)
2022-06-01 19:07:32 +02:00
sternenseemann
ceabfeaf80 antlr4_9: 4.9.2 -> 4.9.3
(cherry picked from commit ddd16ea9f1)
2022-06-01 19:07:32 +02:00
Martin Weinelt
84c17569f5 webkitgtk: 2.36.2 -> 2.36.3
https://webkitgtk.org/2022/05/28/webkitgtk2.36.3-released.html
https://webkitgtk.org/security/WSA-2022-0005.html

Fixes: CVE-2022-26700, CVE-2022-26709, CVE-2022-26717, CVE-2022-26716,
       CVE-2022-26719, CVE-2022-30293, CVE-2022-30294
(cherry picked from commit 5e92d30497c662a40432e3c9d5e3a8f866fdb57c)
2022-06-01 16:54:51 +00:00
Linus Heckemann
96e11107b5 jellyfin: fix permissions on state directory
Previously, all configuration and state data was accessible to all
users on the system running jellyfin. This included user passwords in
the Jellyfin database, as well as credentials for LDAP if configured.
The exact set of accessible data depends on system configuration.

Thanks to Sofie Finnes Øvrelid for reporting this issue.

Fixes: CVE-2022-32198

Co-Authored-By: Martin Weinelt <hexa@darmstadt.ccc.de>
(cherry picked from commit 7eab23d517)
2022-06-01 15:25:51 +00:00
Brian Leung
d556093191 kitty: 0.25.0 -> 0.25.1
(cherry picked from commit b22c2113df)
2022-06-01 15:00:43 +00:00
Fabian Affolter
3642b3cdf5 python310Packages.sdds: disable on older Python releases
(cherry picked from commit 3a15f05927)
2022-06-01 10:51:14 -04:00
R. Ryantm
631756fefa python310Packages.sdds: 0.2.1 -> 0.3.0
(cherry picked from commit 7b3aa7abd6)
2022-06-01 10:51:14 -04:00
Julian Stecklina
e682507e9c duplicity: use pydrive2 to fix gdrive backup problems
pydrive is abandoned and has unfixed issues. In particular, Deja Dup
backups (which uses duplicity as backend) to Google Drive fail with

 Giving up after 5 attempts. RedirectMissingLocation: Redirected but
 the response is missing a Location: header.

More context and pointers are available in the Deja Dup bug tracker:
https://gitlab.gnome.org/World/deja-dup/-/issues/202#note_1306216

(cherry picked from commit a571caaf73)
2022-06-01 14:49:47 +00:00
7c6f434c
b39f966df6 Merge pull request #175712 from NixOS/backport-175160-to-release-22.05
[Backport release-22.05] libreoffice: add update script and 7.2.5 -> 7.3.3 take two
2022-06-01 13:53:15 +00:00
Mauricio Collares
464063d3ef lean2: 2017-07-22 -> 2018-10-01, unbreak
(cherry picked from commit 8fdfe10bcf)
2022-06-01 13:17:31 +00:00
Martin Weinelt
8fb5575e00 Merge pull request #175728 from NixOS/backport-175611-to-release-22.05 2022-06-01 12:34:09 +02:00
Matthias Treydte
f6e9f22877 nixos/systemd-boot: fix systemd-boot-builder refusing to update
Handling of the string length condition in should_update
was broken, as evident with the log message

> leaving systemd-boot 246 in place (250.4 is not newer)

Discussion with @mweinelt came to the conclusion
that Python's "<" operator already does what we need,
so the should_update function can be dropped.

Fixes a30de3b849

(cherry picked from commit ff24f484af)
2022-06-01 10:27:07 +00:00
R. Ryantm
44ce883099 gnome.gnome-settings-daemon: 42.1 -> 42.2
(cherry picked from commit 3822259f73c2ebfea98bb78ba86f5bbf8435b8de)
2022-06-01 09:41:35 +00:00
Thibault Gagnaux
1f29859f4d libreoffice: run the update-script's side-effect at runtime instead of eval
time

(cherry picked from commit d7ccd36aa0)
2022-06-01 08:43:30 +00:00
Thibault Gagnaux
63526524c0 libreoffice: add impure functions comment
(cherry picked from commit 4c23cbcc15)
2022-06-01 08:43:30 +00:00
Thibault Gagnaux
f5b2b6fab3 libreoffice: rename libreoffice -> libreoffice-bin
(cherry picked from commit fe949d64ef)
2022-06-01 08:43:30 +00:00
Thibault Gagnaux
64a8888734 libreoffice: pass explicit file to update-source-version function and
fix import typo

(cherry picked from commit 56ce01eca3)
2022-06-01 08:43:30 +00:00
Thibault Gagnaux
caff1d97af libreoffice: add darwin to meta platforms and extract to common.nix
As a result, the darwin derivations will show up on
https://search.nixos.org/packages.

(cherry picked from commit 8315cf274b)
2022-06-01 08:43:30 +00:00
Thibault Gagnaux
c69a4ae5a8 Revert "libreoffice: move darwin to separate libreoffice-darwin package"
Introducing a new name for each complex darwin derivation does not
scale.

This reverts commit b207ef980751b2dfe2f222fbd7dbc854f9bd90bf.

(cherry picked from commit b9a5485aa5)
2022-06-01 08:43:30 +00:00
Thibault Gagnaux
8db21d1368 libreoffice: move darwin to separate libreoffice-darwin package
The linux and darwin derivations are completely different. Therefore, it
makes more sense to treat them as two separate, independent derivations.

(cherry picked from commit d4dd3f5f7e)
2022-06-01 08:43:30 +00:00
Thibault Gagnaux
6fa63ae9ed libreoffice: add integration test and use lib.fakeSha256
(cherry picked from commit 2fb0615a66)
2022-06-01 08:43:30 +00:00
tricktron
8cfd8dd66c libreoffice: apply suggestions from code review
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit d679ccc970)
2022-06-01 08:43:30 +00:00
Thibault Gagnaux
d621ea13cf libreoffice: 7.2.5 -> 7.3.3
(cherry picked from commit ccfd4255bb)
2022-06-01 08:43:30 +00:00
Thibault Gagnaux
98d67ed484 libreoffice: general darwin improvements
- throw error if platform is not supported
- fix wrong pre/postInstallPhase hook -> pre/postInstall
- switch to stdenvNoCC because we don't build anything
- run all phases by default
- wrap binary using `open -na $out/Applications/${appName} --args "$@"`

(cherry picked from commit ed52a44934)
2022-06-01 08:43:29 +00:00
Thibault Gagnaux
2b89c6403a libreoffice: refactor and document version reset workaround
(cherry picked from commit 9f80b6d8fe)
2022-06-01 08:43:29 +00:00
Thibault Gagnaux
f6df89ca46 libreoffice: add update-script for darwin
(cherry picked from commit 8395d7a4d3)
2022-06-01 08:43:29 +00:00
Ben Siraphob
03aeb6c8da Merge pull request #175705 from NixOS/backport-175619-to-release-22.05
[Backport release-22.05] python3Packages.awscrt: fix darwin build
2022-06-01 08:16:32 +00:00
Ben Siraphob
d0a23aa650 cvc4: fix build on darwin
Dependency on cln is optional

(cherry picked from commit 583a2312e4)
2022-06-01 08:14:57 +00:00
github-actions[bot]
5322a131fd terraform: 1.2.0 -> 1.2.1 (#175701)
https://github.com/hashicorp/terraform/releases/tag/v1.2.1
(cherry picked from commit 504b23488738ab2e0e74d9b8e449170b1d51bc8a)

Co-authored-by: zowoq <59103226+zowoq@users.noreply.github.com>
2022-06-01 09:36:35 +02:00
Konstantin Alekseev
d01cce0281 python3Packages.awscrt: fix darwin build
(cherry picked from commit 21dc93570f)
2022-06-01 07:31:29 +00:00
Ben Siraphob
d1b4563ec1 Merge pull request #175049 from NixOS/backport-175027-to-release-22.05 2022-06-01 06:40:41 +00:00
Randy Eckenrode
b25331cdab ledger: fix Python 3.10 module build
The current default boost (1.77) doesn’t work with Python 3.10, so use
1.79 instead.

(cherry picked from commit d4964be44c)
2022-06-01 06:21:44 +00:00
Bobby Rong
aac61c6fdb Merge pull request #175669 from NixOS/backport-175609-to-release-22.05
[Backport release-22.05] gnome-obfuscate: 0.0.4 -> 0.0.7
2022-06-01 12:38:17 +08:00
Francesco Gazzetta
cbe70d0025 gnome-obfuscate: 0.0.4 -> 0.0.7
(cherry picked from commit e0903ce6aa)
2022-06-01 00:24:35 +00:00
github-actions[bot]
69a15d85be Merge staging-next-22.05 into staging-22.05 2022-06-01 00:17:32 +00:00
github-actions[bot]
ceb66e98c3 Merge release-22.05 into staging-next-22.05 2022-06-01 00:16:50 +00:00
Martin Weinelt
c584fbd349 Merge pull request #175663 from dotlambda/pyfuse3-cythonize
[22.05] python310Packages.pyfuse3: cythonize before building
2022-06-01 02:14:00 +02:00
Artturi
e9e3d09dc6 Merge pull request #175652 from NixOS/backport-175606-to-release-22.05 2022-06-01 03:10:34 +03:00
Martin Weinelt
62d77318a9 Merge pull request #175286 from risicle/ris-cherry-pick-174152 2022-06-01 01:55:24 +02:00
piegames
e5b332e450 magic-wormhole-rs: Add alias wormhole-rs
(cherry picked from commit 5b314280b0)
2022-05-31 23:28:50 +00:00
Robert Schütz
ecab8dec3b python310Packages.pyfuse3: cythonize before building
(cherry picked from commit a3859b796f)
2022-05-31 23:11:35 +00:00
Paul Tötterman
4f7a0e1d40 cloudflared: isn't broken after all
Flaky tests resulted in broken status. Rebuilt fine.

(cherry picked from commit 05135c973d)
2022-05-31 22:27:34 +00:00
Robert Schütz
3a5821bc4d Merge pull request #175645 from NixOS/backport-175546-to-release-22.05
[Backport release-22.05] imagemagick: 7.1.0-35 -> 7.1.0-36
2022-05-31 14:54:32 -07:00
Robert Scott
4c47879e47 Merge pull request #175643 from NixOS/backport-175628-to-release-22.05
[Backport release-22.05] Fix: make pyarrow buildable on darwin
2022-05-31 22:39:36 +01:00
Robert Schütz
2fac192a98 imagemagick: 7.1.0-35 -> 7.1.0-36
(cherry picked from commit bd1d3d243a)
2022-05-31 21:24:09 +00:00
Nikola Knezevic
4a2bbf59c8 Fix: make pyarrow buildable on darwin
This change disables several tests that fail on darwin due to requiring
localhost networking. In addition, it bumps up the number of open file
descriptors to allow test_pandas.py/TestConvertMisc tests to pass.

(cherry picked from commit f0e0734f61)
2022-05-31 21:23:10 +00:00
piegames
7a5d3c6e82 Merge pull request #175526 from NixOS/backport-174626-to-release-22.05 2022-05-31 22:01:34 +02:00
Jörg Thalheim
a1685b2293 Merge pull request #175629 from Mic92/big-docs-backport
Backport missing changelog updates from master
2022-05-31 20:35:12 +01:00
Robert Scott
14c7ba01cf Merge pull request #175542 from NixOS/backport-175528-to-release-22.05
[Backport release-22.05] python3Packages.celery: unmark as broken
2022-05-31 20:18:35 +01:00
Jörg Thalheim
5feb16e7a4 release-notes: link to all nix versions
(cherry picked from commit b8f31e9e3b)
2022-05-31 20:31:17 +02:00
Jörg Thalheim
f263400ed1 doc: rework notable changes 2022-05-31 20:31:17 +02:00
Jörg Thalheim
cd0b034230 doc: sort service list
(cherry picked from commit 5936d939ce)
2022-05-31 20:31:17 +02:00
Jörg Thalheim
42c62fc672 nixos/timetagger: drop non-evaluating service files
The file was not included in the module list and also does not evaluate.

(cherry picked from commit 9ae4a910e4)
2022-05-31 20:31:16 +02:00
Jörg Thalheim
976fe7f785 doc: add missing new services to release-notes
(cherry picked from commit 78f5129aa6)
2022-05-31 20:31:16 +02:00
Robert Schütz
c7693c932c libspotify: remove
As of May 16, 2022, Spotify no longer supports libspotify.
https://developer.spotify.com/community/news/2022/04/12/libspotify-sunset/

(cherry picked from commit 1f402eec78)
2022-05-31 10:21:40 -07:00
Robert Schütz
306caa2d8a clementineUnfree: remove
(cherry picked from commit 70c42db535)
2022-05-31 10:21:40 -07:00
Robert Schütz
7e8a615282 python3Packages.pyspotify: remove
(cherry picked from commit 645f612c40)
2022-05-31 10:21:40 -07:00
Robert Schütz
57eb5bcb03 mopidy-spotify: remove
(cherry picked from commit eaf436cc25)
2022-05-31 10:21:40 -07:00
Robert Schütz
da1906a951 mopidy-spotify-tunigo: remove
(cherry picked from commit e0ea4b52f0)
2022-05-31 10:21:40 -07:00
Martin Weinelt
084d9e819b Merge pull request #175617 from NixOS/backport-175514-to-release-22.05 2022-05-31 18:36:34 +02:00
Martin Weinelt
c3d7f2d9f4 firefox-devedition-bin-unwrapped: 101.0b9 -> 102.0b1
(cherry picked from commit ab1dd069c7)
2022-05-31 15:39:40 +00:00
Martin Weinelt
d027c44dc1 firefox-beta-bin-unwrapped: 101.0b9 -> 102.0b1
(cherry picked from commit 172e3144ab)
2022-05-31 15:39:40 +00:00
Martin Weinelt
cf82bac10c spidermonkey_91: 91.9.1 -> 91.10.0
(cherry picked from commit 78ffb8f7ae)
2022-05-31 15:39:40 +00:00
Martin Weinelt
b7a0b7ddc1 firefox-esr-91-unwrapped: 91.9.1esr -> 91.10.0esr
https://www.mozilla.org/en-US/firefox/91.10.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-21/

Fixes: CVE-2022-31736, CVE-2022-31737, CVE-2022-31738, CVE-2022-31739,
       CVE-2022-31740, CVE-2022-31741, CVE-2022-31742, CVE-2022-31747
(cherry picked from commit f89d5a7f2c)
2022-05-31 15:39:40 +00:00
Martin Weinelt
ba71f5b07c firefox-bin-unwrapped: 100.0.2- -> 101.0
https://www.mozilla.org/en-US/firefox/101.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-20/

Fixes: CVE-2022-31736, CVE-2022-31737, CVE-2022-31738, CVE-2022-31739,
       CVE-2022-31740, CVE-2022-31741, CVE-2022-31742, CVE-2022-31743,
       CVE-2022-31744, CVE-2022-31745, CVE-2022-1919, CVE-2022-31747,
       CVE-2022-31748
(cherry picked from commit 8353459d92)
2022-05-31 15:39:40 +00:00
Martin Weinelt
ba1a850d8f firefox-unwrapped: 100.0.2- -> 101.0
https://www.mozilla.org/en-US/firefox/101.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-20/

Fixes: CVE-2022-31736, CVE-2022-31737, CVE-2022-31738, CVE-2022-31739,
       CVE-2022-31740, CVE-2022-31741, CVE-2022-31742, CVE-2022-31743,
       CVE-2022-31744, CVE-2022-31745, CVE-2022-1919, CVE-2022-31747,
       CVE-2022-31748
(cherry picked from commit 332711833d)
2022-05-31 15:39:40 +00:00
maxine [they]
c7a8b604b4 Merge pull request #175464 from NixOS/backport-175411-to-release-22.05
[Backport release-22.05] gnome.gnome-remote-desktop: 42.1.1 -> 42.2
2022-05-31 17:32:39 +02:00
maxine [they]
ba485ec041 Merge pull request #175468 from NixOS/backport-175425-to-release-22.05
[Backport release-22.05] gnome.gnome-shell-extensions: 42.1 -> 42.2
2022-05-31 17:32:25 +02:00
maxine [they]
b726afec42 Merge pull request #175614 from NixOS/backport-175564-to-release-22.05
[Backport release-22.05] gnome.gnome-software: 42.1 -> 42.2
2022-05-31 17:32:03 +02:00
maxine [they]
d22fa0dea4 Merge pull request #175597 from NixOS/backport-175563-to-release-22.05
[Backport release-22.05] gnome.gnome-boxes: 42.0.1 -> 42.1
2022-05-31 17:31:51 +02:00
R. Ryantm
c3bd4a53e0 gnome.gnome-software: 42.1 -> 42.2
(cherry picked from commit e70ebbd0bf)
2022-05-31 15:26:12 +00:00
Alexander Foremny
08950a6e29 glirc: unbreak via downgrade to 2.38
glirc 2.39 does not compile against any set of released packages and is
unlikely to be fixed without a subsequent release
(https://github.com/glguy/irc-core/issues/99).

Cherry-picked from commit 0bbe2a7fc9df0aaccb77c908bb5ae82b5c9adde2.
2022-05-31 15:59:17 +02:00
R. Ryantm
ba6bb6b195 gnome.gnome-boxes: 42.0.1 -> 42.1
(cherry picked from commit 0aa4485e407710177ec627830ede88c9f3f35318)
2022-05-31 11:45:03 +00:00
R. Ryantm
6690e2776b glib: 2.72.1 -> 2.72.2
(cherry picked from commit 83f683bfa294dd4fe0c28c06ec70526f10ff0f70)
2022-05-31 11:43:59 +00:00
Bobby Rong
23a5fe2453 Merge pull request #175588 from NixOS/backport-175273-to-release-22.05
[Backport release-22.05] drawio: 18.0.6 -> 18.1.3
2022-05-31 19:28:06 +08:00
Bobby Rong
11ef1fa017 Merge pull request #175590 from NixOS/backport-175572-to-release-22.05
[Backport release-22.05] release-notes: fix typo
2022-05-31 19:23:46 +08:00
R. Ryantm
a0e8eef590 gtk4: 4.6.4 -> 4.6.5
(cherry picked from commit c616e5cb13b162693879b23a628a2001c0d17617)
2022-05-31 11:22:31 +00:00
github-actions[bot]
fcd1e36f02 .github/PULL_REQUEST_TEMPLATE.md: 21.11 -> 22.05
(cherry picked from commit 2c74606664)

Co-authored-by: Markus S. Wamser <github-dev@mail2013.wamser.eu>
2022-05-31 19:21:03 +08:00
Markus S. Wamser
2ec6dd8400 release-notes: fix typo
(cherry picked from commit 32e26d2627)
2022-05-31 11:06:35 +00:00
DarkOnion0
35972b1772 drawio: 18.0.6 -> 18.1.3
(cherry picked from commit 48210371c1)
2022-05-31 10:49:18 +00:00
ajs124
5241b80217 Merge pull request #175562 from NixOS/backport-175522-to-release-22.05
[Backport release-22.05] python3.pkgs.pyfuse3: fix broken mark
2022-05-31 12:42:49 +02:00
Jörg Thalheim
2fa57ed190 Merge pull request #175574 from NixOS/backport-175571-to-release-22.05
[Backport release-22.05] nearcore: 1.26.0 -> 1.26.1 [security update]
2022-05-31 10:12:00 +01:00
Robin Gloster
b34c389a48 lua5_4: fix CVE-2022-28805
(cherry picked from commit 5a7d0b6b34)
2022-05-31 09:08:56 +00:00
Robin Gloster
980d1262a0 lua5_2: add patch for CVE-2022-28805
Derived from 1f3c6f4534

(cherry picked from commit 04d41ba8cc)
2022-05-31 09:08:56 +00:00
Wout Mertens
925cb60007 Merge pull request #175580 from NixOS/backport-174290-to-release-22.05
[Backport release-22.05] netdata: 1.33.1 -> 1.34.1
2022-05-31 11:00:26 +02:00
markuskowa
a476bcffdc Merge pull request #175490 from NixOS/backport-175283-to-release-22.05
[Backport release-22.05] openmpi: 4.1.3 -> 4.1.4
2022-05-31 10:32:44 +02:00
Izorkin
12fcbe7c93 netdata: 1.33.1 -> 1.34.1
(cherry picked from commit 2ab4d2f39e)
2022-05-31 08:27:17 +00:00
Izorkin
21ddf44a11 netdata: go.d.plugin: 0.31.0 -> 0.32.3
(cherry picked from commit a77280ef85)
2022-05-31 08:27:16 +00:00
Jörg Thalheim
cdf89a7f56 nearcore: 1.26.0 -> 1.26.1
(cherry picked from commit 97bdb3c645)
2022-05-31 07:56:00 +00:00
Fabian Affolter
804a6d1c63 python310Packages.pyramid_jinja2: disable failing tests
- switch to pytestCheckHook
- disable on older Python releases

(cherry picked from commit c9098ff0bb)
2022-05-31 07:15:43 +00:00
Janne Heß
9b5e34626f README: 21.11 -> 22.05
I kind of forgot that when I did the release...

(cherry picked from commit cfaec958cc)
2022-05-31 08:36:52 +02:00
ajs124
8de3426450 python3.pkgs.pyfuse3: fix broken mark
(cherry picked from commit 51b506f8de)
2022-05-31 06:16:28 +00:00
Artturi
27ba51ca76 Merge pull request #175543 from NixOS/backport-175492-to-release-22.05 2022-05-31 03:34:22 +03:00
github-actions[bot]
479bb88767 Merge staging-next-22.05 into staging-22.05 2022-05-31 00:15:41 +00:00
github-actions[bot]
a8d4a5d85f Merge release-22.05 into staging-next-22.05 2022-05-31 00:14:58 +00:00
Artturin
c26f16dacf nixVersions.unstable: pre20220512 -> pre20220530
(cherry picked from commit 963e1c79dc)
2022-05-31 00:09:20 +00:00
Robert Scott
0ec5b05673 python3Packages.celery: unmark as broken
mistakenly marked broken due to a spurious hydra failure

(cherry picked from commit 67dffc3000)
2022-05-30 23:46:16 +00:00
Robert Scott
a27f49a449 python3Packages.celery: skip hydra-failing tests on darwin
these tests cause darwin hydra to hit open file limits

(cherry picked from commit 71c7efa387)
2022-05-30 23:46:16 +00:00
Robert Scott
7c1e79e294 Merge pull request #175533 from NixOS/backport-175161-to-release-22.05
[Backport release-22.05] python3Packages.uamqp: use openssl on darwin-aarch64
2022-05-30 23:09:25 +01:00
Robert Scott
9895371137 Merge pull request #175529 from NixOS/backport-175127-to-release-22.05
[Backport release-22.05] libnatspec: fix build on darwin
2022-05-30 23:07:19 +01:00
Robert Scott
b6927692f1 python3Packages.uamqp: use openssl on darwin-aarch64
azure's libraries aren't happy enough with our macos sdk on aarch64
to let us use applessl

(cherry picked from commit 6f7557f8c6)
2022-05-30 21:59:26 +00:00
Robert Scott
cc7b00bf1b libnatspec: unmark broken on darwin
(cherry picked from commit 012021659f)
2022-05-30 21:52:26 +00:00
Robert Scott
27fbb13768 libnatspec: fix build on darwin
broken in 3c12e95ad1 when parentheses
were removed, changing the semantics.

add libiconv universally to avoid such mixups.

(cherry picked from commit 8e113240bb)
2022-05-30 21:52:26 +00:00
Vladyslav M
5f38cae56d magic-wormhole-rs: 0.3.0 -> 0.5.0
(cherry picked from commit a655844561)
2022-05-30 21:41:32 +00:00
Artturi
fbba8a2fe7 Merge pull request #174954 from NixOS/backport-172391-to-release-22.05
[Backport release-22.05] stdenv: warn about use of stdenv.glibc
2022-05-30 23:43:53 +03:00
github-actions[bot]
7a26484ee7 [Backport release-22.05] fix font fallout from extraPostFetch -> postFetch (#175516)
* gdouros-fonts: fix build

some hashes were changed since ods files are now installed

(cherry picked from commit fce460deb2e89b27b0d67b0b5971f6ff8f7e48f6)

* camingo-code: fix build

contents not changed

(cherry picked from commit 2996a4db1b5600e02b08e0d7995ff87e67f0ecd0)

* hannom: fix build

(cherry picked from commit 1966820dcf1b5ec91078e51fb8cc336533b689ef)

* helvetica-neue-lt-std: fix build

perms changed so the hash changed too

(cherry picked from commit 7a35874fc7511472363b4517491a660224dc8c80)

* liberastika: fix build

hash changed due to no doc dir anymore

(cherry picked from commit 23bf61ff69be5ec2c513c61fd5448efe72f0bce8)

* kochi-substitute-naga10: fix build

(cherry picked from commit 437c8b8ab4059f52d906323611c05d5f2ab9be4d)

* xkcd-font: use a simpler method to remove unneeded files

(cherry picked from commit 134f0109742cf9ed541cefa9e58c69b9fd21925c)

* fonts: also remove hidden files

(cherry picked from commit 0b9c64625335c7e1c4c3b7d7bab34aaf706d9ed4)

Co-authored-by: Artturin <Artturin@artturin.com>
2022-05-30 23:42:01 +03:00
Thiago Kenji Okada
1915503140 Merge pull request #175509 from NixOS/backport-175466-to-release-22.05
[Backport release-22.05] sway-launcher-desktop: 1.5.4 -> 1.6.0
2022-05-30 20:28:18 +01:00
linj
bd1c3e774b nixos/dendrite: add an option loadCredential
systemd-247 provides a mechanism called LoadCredential for secrets and
it is better than environment file. See the section of Environment=
in the manual of systemd.exec for more information.

Some options in config.yaml need values to be strings, which currently
can be used with environmentFile but not loadCredential. But it's
possible to use loadCredential for those options, e.g. we can
substitute their values in ExecStart, but not in ExecStartPre due to
[1].

[1]: https://github.com/systemd/systemd/issues/19604

(cherry picked from commit 37792e5766)
2022-05-30 12:21:52 -07:00
PedroHLC ☭
316dce136c sway-launcher-desktop: 1.5.4 -> 1.6.0
(cherry picked from commit bd78e1ac1e)
2022-05-30 19:04:56 +00:00
Janne Heß
ce6aa13369 Release 22.05
(cherry picked from commit cbaacfb8df)
2022-05-30 20:51:36 +02:00
Thiago Kenji Okada
2c1f2cc193 Merge pull request #175441 from NixOS/backport-175211-to-release-22.05
[Backport release-22.05] liblouis: fix darwin build with patch
2022-05-30 18:04:50 +01:00
Thiago Kenji Okada
b0aae9a820 Merge pull request #175481 from NixOS/backport-173349-to-release-22.05
[Backport release-22.05] python310Packages.robotframework: 5.0 -> 5.0.1
2022-05-30 18:03:47 +01:00
Markus Kowalewski
4804131e6e openmpi: 4.1.3 -> 4.1.4
(cherry picked from commit cf21f98217)
2022-05-30 15:30:05 +00:00
Janne Heß
a634c8f6c1 Merge pull request #175482 from NixOS/backport-175480-to-release-22.05
[Backport release-22.05] libportal/libqalculate: Unbreak
2022-05-30 16:21:43 +02:00
Janne Heß
6494478c35 libportal/libqalculate: Unbreak
This blocks release because the tested jobset depends on these
indirectly.

(cherry picked from commit cd0956e5d8)
2022-05-30 14:16:41 +00:00
R. Ryantm
9b7dd0976e python310Packages.robotframework: 5.0 -> 5.0.1
(cherry picked from commit e5cb66e9f97e522d7028815a4f58ea8ee52d974f)
2022-05-30 13:53:43 +00:00
Maximilian Bosch
e44c82bfec Merge pull request #175168 from NixOS/backport-175024-to-release-22.05
[Backport release-22.05] wiki-js: 2.5.282 -> 2.5.283
2022-05-30 15:52:01 +02:00
Yorick van Pelt
e0fa35aeeb asterisk: 16.25.1 -> 16.26.1, 18.11.1 -> 18.12.1, 19.3.1 -> 19.4.1
(cherry picked from commit 5d62b7f79f)
2022-05-30 12:46:57 +00:00
Yorick van Pelt
99633af7af asterisk: update updateScript to include python deps
(cherry picked from commit 237b5838d3)
2022-05-30 12:46:57 +00:00
Janne Heß
64c18203e2 Merge pull request #175472 from helsinki-systems/feat/mark-broken
[22.05] treewide: mark broken packages as broken
2022-05-30 14:46:33 +02:00
Rick van Schijndel
658fd8317a robomachine: mark broken
(cherry picked from commit 26243136fe)
2022-05-30 14:20:07 +02:00
Rick van Schijndel
43072cd017 treewide: pkgs/development/python-modules: mark broken for aarch64-linux
(cherry picked from commit afbb0f6ff4)
2022-05-30 14:20:06 +02:00
Rick van Schijndel
a8cd66256f mps: mark broken
(cherry picked from commit 7da0ca2e25)
2022-05-30 14:19:33 +02:00
Rick van Schijndel
cdea6a07de swift: mark broken
(cherry picked from commit cd19a0e7b4)
2022-05-30 14:19:33 +02:00
Rick van Schijndel
f078cea543 treewide: pkgs/development: mark broken for aarch64-linux
(cherry picked from commit 11ee22d797)
2022-05-30 14:19:32 +02:00
Rick van Schijndel
ff7cd38205 treewide: pkgs/applications: mark broken for aarch64-linux
(cherry picked from commit 433701147a)
2022-05-30 14:19:24 +02:00
Rick van Schijndel
2a7b9a3fcb treewide: mark broken for darwin
(cherry picked from commit 010f6ee30d)
2022-05-30 14:19:21 +02:00
Rick van Schijndel
95a3b63e81 luaPackages.luxio: mark broken for darwin
(cherry picked from commit 82ccbc08de)
2022-05-30 14:19:04 +02:00
Rick van Schijndel
184877600b treewide: pkgs/desktops: mark broken for darwin
(cherry picked from commit 7a68548822)
2022-05-30 14:19:04 +02:00
Rick van Schijndel
1ea48d9664 treewide: pkgs/servers/sql: mark 2 psql extension broken
(cherry picked from commit 033d5579c2)
2022-05-30 14:19:04 +02:00
Rick van Schijndel
b29dbdf474 treewide: pkgs/servers: mark broken for darwin
(cherry picked from commit 879d278253)
2022-05-30 14:19:04 +02:00
Rick van Schijndel
d911a85d84 speedcrunch: mark broken on darwin
(cherry picked from commit a0dd8198cd)
2022-05-30 14:19:04 +02:00
Rick van Schijndel
5874279f95 tippecanoe: mark broken on darwin as well
(cherry picked from commit c312ae98a1)
2022-05-30 14:19:03 +02:00
Rick van Schijndel
744167bc9e blender: mark broken on all darwins
(cherry picked from commit 117ee3af2a)
2022-05-30 14:19:03 +02:00
Rick van Schijndel
8d86a47ea1 libresprite: mark broken on darwin
(cherry picked from commit da846421fc)
2022-05-30 14:19:03 +02:00
Rick van Schijndel
da3b873b79 pqrs: mark broken
(cherry picked from commit edde4da42e)
2022-05-30 14:19:03 +02:00
Rick van Schijndel
b516917c56 treewide: pkgs/development: mark broken for darwin
(cherry picked from commit 03bc571744)
2022-05-30 14:19:03 +02:00
Rick van Schijndel
86baa2411e treewide: pkgs/development/libraries: mark broken for darwin
(cherry picked from commit 7d58a30286)
2022-05-30 14:19:02 +02:00
Rick van Schijndel
3644535053 treewide: pkgs/development/python-modules: mark broken for darwin
(cherry picked from commit 65db3b17a8)
2022-05-30 14:19:02 +02:00
Rick van Schijndel
11af55b8b3 treewide: pkgs/development/tools: mark broken for darwin
(cherry picked from commit 13e0d33703)
2022-05-30 14:19:02 +02:00
Rick van Schijndel
e315d48b2b treewide: pkgs/development/compilers: mark broken for darwin
(cherry picked from commit 0b45cae8a3)
2022-05-30 14:19:02 +02:00
Rick van Schijndel
941826b663 treewide: pkgs/applications: mark broken for darwin
(cherry picked from commit 37c633f7ae)
2022-05-30 14:19:01 +02:00
Rick van Schijndel
90c49a6acd treewide: pkgs/games: mark broken for darwin
(cherry picked from commit f97a7e634f)
2022-05-30 14:19:01 +02:00
Rick van Schijndel
4de437620a treewide: pkgs/tools: mark broken for darwin
All packages that were failing on x86_64-darwin are marked broken.
I'm assuming here that these are also broken on aarch64-darwin.

(cherry picked from commit cd3c25616d)
2022-05-30 14:19:01 +02:00
Rick van Schijndel
0c269335a9 ccl: mark broken on x86_64-darwin
(cherry picked from commit 6d9a33741e)
2022-05-30 14:19:01 +02:00
Rick van Schijndel
0dc1602b92 cataclysm-dda-git: mark broken on x86_64-darwin
(cherry picked from commit 941458e0b9)
2022-05-30 14:19:01 +02:00
Rick van Schijndel
779dcac6fc cargo-modules: mark broken on x86_64-darwin
(cherry picked from commit 2542b4d60e)
2022-05-30 14:19:00 +02:00
Rick van Schijndel
96e8c48c1f cargo-deb: mark broken on x86_64-darwin
(cherry picked from commit ed7599305f)
2022-05-30 14:19:00 +02:00
Rick van Schijndel
ce94f5ee41 cardinal: mark broken on darwin
(cherry picked from commit dd6e61fa54)
2022-05-30 14:19:00 +02:00
Rick van Schijndel
1dd5dabfc9 bupstash: mark broken on x86_64-darwin
Related to https://github.com/NixOS/nixpkgs/issues/101229

(cherry picked from commit c3fa68c928)
2022-05-30 14:19:00 +02:00
Rick van Schijndel
6ebd1794aa bullet-roboschool: mark broken on x86_64-darwin
(cherry picked from commit bc286911d8)
2022-05-30 14:19:00 +02:00
Rick van Schijndel
4304f69306 bsnes-hd: mark broken on x86_64-darwin
(cherry picked from commit d898e26892)
2022-05-30 14:18:59 +02:00
Rick van Schijndel
3f8c71eff2 boofuzz: mark broken on x86_64-darwin
(cherry picked from commit 1f88f6a2c0)
2022-05-30 14:18:59 +02:00
Rick van Schijndel
41b16eb3b5 boinc: mark broken for aarch64
(cherry picked from commit 90869787c5)
2022-05-30 14:18:59 +02:00
Rick van Schijndel
528ab12cb7 blender: mark broken on x86_64-darwin
(cherry picked from commit 53d8d81656)
2022-05-30 14:18:59 +02:00
Rick van Schijndel
3893752d12 bigloo: mark broken on x86_64 Darwin
(cherry picked from commit 8152b170e2)
2022-05-30 14:18:59 +02:00
Rick van Schijndel
2eaf7db352 binwalk: mark broken on x86_64-darwin
Probably some issues with signatures.
Disabling this test may or may not also help.

(cherry picked from commit ce7a64713e)
2022-05-30 14:18:58 +02:00
Rick van Schijndel
667e5d3a64 bakelite: only supports linux
(cherry picked from commit 5d8ec2adc1)
2022-05-30 14:18:58 +02:00
Rick van Schijndel
cc1e49cf6a awless: mark broken for aarch64-linux
Unclear if this ever worked.

asm: InitTextSym double init for .Syscall
panic: invalid use of LSym - NewFuncInfo with Extra of type *obj.FuncInfo

goroutine 1 [running]:
cmd/internal/obj.(*LSym).NewFuncInfo(0x400015e100)
        /nix/store/9nqp0vlgakl12c6irdn3qvicqsvc2zl8-go-1.17.10/share/go/src/cmd/internal/obj/link.go:496 +0x134
cmd/internal/obj.(*Link).InitTextSym(0x400017c000, 0x400015e100, 0x4)
        /nix/store/9nqp0vlgakl12c6irdn3qvicqsvc2zl8-go-1.17.10/share/go/src/cmd/internal/obj/plist.go:153 +0x10c
cmd/asm/internal/asm.(*Parser).asmText(0x400013fe60, {0x400013fd00, 0x3, 0x3})
        /nix/store/9nqp0vlgakl12c6irdn3qvicqsvc2zl8-go-1.17.10/share/go/src/cmd/asm/internal/asm/asm.go:180 +0x4f0
cmd/asm/internal/asm.(*Parser).pseudo(0x400013fe60, {0x4000130460, 0x4}, {0x400013fd00, 0x3, 0x3})
        /nix/store/9nqp0vlgakl12c6irdn3qvicqsvc2zl8-go-1.17.10/share/go/src/cmd/asm/internal/asm/parse.go:297 +0x7c
cmd/asm/internal/asm.(*Parser).Parse(0x400013fe60)
        /nix/store/9nqp0vlgakl12c6irdn3qvicqsvc2zl8-go-1.17.10/share/go/src/cmd/asm/internal/asm/parse.go:105 +0xcc
main.main()
        /nix/store/9nqp0vlgakl12c6irdn3qvicqsvc2zl8-go-1.17.10/share/go/src/cmd/asm/main.go:91 +0x814

(cherry picked from commit 223184228c)
2022-05-30 14:18:58 +02:00
Rick van Schijndel
277a046219 aspino: mark broken for x86_64 Darwin
Been broken for a few years already too.

(cherry picked from commit 5e1adacaf0)
2022-05-30 14:18:58 +02:00
Rick van Schijndel
92315bf58b alttpr-opentracker: only enable on x86_64-linux
It was failing to build on aarch64-linux with:

Executing dotnetConfigureHook
  Determining projects to restore...
  Restored /build/source/OpenTracker.UnitTests/OpenTracker.UnitTests.csproj (in 35.07 sec).
  Restored /build/source/OpenTracker.Models/OpenTracker.Models.csproj (in 520 ms).
  Restored /build/source/OpenTracker.Utils/OpenTracker.Utils.csproj (in 48 ms).
/build/source/OpenTracker/OpenTracker.csproj : error NU1101: Unable to find package Microsoft.NETCore.App.Host.linux-arm64. No packages exist with this id in source(s): /nix/store/x82zwgmqdbp4xykx1nkrjin8hicm8jld-opentracker-1.8.2-nuget-source/lib [/build/source/OpenTracker.sln]
  Failed to restore /build/source/OpenTracker/OpenTracker.csproj (in 12.45 sec).
  Restored /build/source/Avalonia.ThemeManager/Avalonia.ThemeManager.csproj (in 56 ms).

(cherry picked from commit b465f1a92f)
2022-05-30 14:18:58 +02:00
Rick van Schijndel
e0206b48ca adwaita-qt: mark broken on Darwin since it doesn't build with qt514
Darwin is still using qt514 instead of qt515.

(cherry picked from commit 70c66de145)
2022-05-30 14:18:57 +02:00
Rick van Schijndel
f18b0b125a CHOWTapeModel: mark broken on aarch64
(cherry picked from commit 859aa7da13)
2022-05-30 14:18:57 +02:00
R. Ryantm
1028ade8c5 gnome.gnome-shell-extensions: 42.1 -> 42.2
(cherry picked from commit 46d725e9f55c549a3996b495b080d04c9ca615a7)
2022-05-30 11:49:20 +00:00
ajs124
70fda42f22 nixos/nginx: fix SystemCallFilter for openresty
(cherry picked from commit 30186896ee)
2022-05-30 11:39:47 +00:00
ajs124
3a8981f184 nginxQuic: update
(cherry picked from commit c26e3354a7)
2022-05-30 11:39:47 +00:00
ajs124
488f5502e6 nginx(Stable|Mainline|Quic): use pcre2
(cherry picked from commit b484952330)
2022-05-30 11:39:47 +00:00
ajs124
c0a40d4492 nginxMainline: 1.21.6 -> 1.22.0
(cherry picked from commit 893214cd0e)
2022-05-30 11:39:47 +00:00
ajs124
8667d76449 nginxStable: 1.20.2 -> 1.22.0
(cherry picked from commit 14ef375cf0)
2022-05-30 11:39:47 +00:00
R. Ryantm
3928d564c4 gnome.gnome-remote-desktop: 42.1.1 -> 42.2
(cherry picked from commit e5d3c056a09fa13797747d420821f1897041464d)
2022-05-30 11:28:07 +00:00
R. Ryantm
25c33ba764 gnome.gnome-shell: 42.1 -> 42.2
(cherry picked from commit e2bcaeb9e01a014003e3aced4629c7031ccdbaea)
2022-05-30 11:23:28 +00:00
R. Ryantm
c28f8796e4 gnome.mutter: 42.1 -> 42.2
(cherry picked from commit 02cbede60caf22aa14e9d81158799ecf21980a6b)
2022-05-30 11:23:27 +00:00
Janne Heß
bc7824cc01 Merge pull request #175458 from NixOS/backport-175445-to-release-22.05
[Backport release-22.05] nixos/vmware-guest: Remove the video driver
2022-05-30 12:56:26 +02:00
Janne Heß
ecc36827c6 nixos/vmware-guest: Remove the video driver
This breaks isos since https://github.com/NixOS/nixpkgs/pull/172668
because vmware is enabled there. @K900 tested this and confirmed that
the GPU acceleration still works.

(cherry picked from commit 5157246aa4)
2022-05-30 10:37:15 +00:00
7c6f434c
be5e3632be Merge pull request #175434 from NixOS/backport-175426-to-release-22.05
[Backport release-22.05] gajim: 1.4.1 → 1.4.2
2022-05-30 07:48:35 +00:00
Robert Scott
44aa4d1566 liblouis: fix darwin build with patch
(cherry picked from commit 327af2f90f)
2022-05-30 07:15:15 +00:00
Vincent Laporte
362889b5c2 gajim: 1.4.1 → 1.4.2
(cherry picked from commit 1593316a21)
2022-05-30 06:29:45 +00:00
github-actions[bot]
f728c8605b Merge staging-next-22.05 into staging-22.05 2022-05-30 00:18:03 +00:00
github-actions[bot]
c2ae4dc17f Merge release-22.05 into staging-next-22.05 2022-05-30 00:17:24 +00:00
Robert Scott
7f7e833e0b Merge pull request #175373 from NixOS/backport-175357-to-release-22.05
[Backport release-22.05] python3Packages.cnvkit: 0.9.7 -> 0.9.9, skip broken test
2022-05-30 00:22:50 +01:00
Robert Scott
2830ce4133 Merge pull request #175371 from NixOS/backport-175336-to-release-22.05
[Backport release-22.05] python3Packages.pomegranate: 0.13.5 -> 0.14.8
2022-05-30 00:17:17 +01:00
Eduardo Quiros
1b17250fcc signal-desktop: 5.43.0 -> 5.44.1
(cherry picked from commit 8e4ca49414)
2022-05-29 23:14:39 +00:00
Robert Scott
d20913a939 python3Packages.cnvkit: 0.9.7 -> 0.9.9, skip broken test
(cherry picked from commit 798d9f9f3b)
2022-05-29 23:11:56 +00:00
Robert Scott
7ac55c542a python3Packages.pomegranate: 0.13.5 -> 0.14.8
(cherry picked from commit 17003648fe)
2022-05-29 22:52:35 +00:00
Bjørn Forsman
10c86be5af genimage: 9 -> 15
It still doesn't install any documenation, the README now has .rst file
extension.

(cherry picked from commit 42b247f7e7eb9fcbd6830d7669da778e053c0d2e)
2022-05-29 23:26:35 +02:00
Martin Weinelt
49de89df1a Merge pull request #175338 from NixOS/backport-175095-to-release-22.05 2022-05-29 23:14:57 +02:00
sternenseemann
66160e08c4 fcft: 3.1.1 -> 3.1.2
https://codeberg.org/dnkl/fcft/releases/tag/3.1.2
(cherry picked from commit ebfcc109b2bf1430881e063900e20e19460853b0)
2022-05-29 23:12:36 +02:00
maxine [they]
6ee6788cb0 Merge pull request #175277 from NixOS/backport-175236-to-release-22.05
[Backport release-22.05] gnome.gnome-terminal: 3.44.0 -> 3.44.1
2022-05-29 22:49:44 +02:00
maxine [they]
23d2d93e19 Merge pull request #175276 from NixOS/backport-175230-to-release-22.05
[Backport release-22.05] gnome.aisleriot: 3.22.22 -> 3.22.23
2022-05-29 22:49:41 +02:00
Janne Heß
889c107a29 Merge pull request #174967 from NixOS/backport-174734-to-release-22.05
[Backport release-22.05] release: Slightly adjust release-critical packages
2022-05-29 21:34:05 +02:00
Janne Heß
6ffcbe6bc8 Merge pull request #174980 from NixOS/backport-174639-to-release-22.05
[Backport release-22.05] nixos/version: add trailing newline to os-release
2022-05-29 21:33:21 +02:00
Janne Heß
e495381dad Merge pull request #175190 from NixOS/backport-174795-to-release-22.05
[Backport release-22.05] openmoji-black,openmoji-color: fix hanging builds
2022-05-29 21:29:18 +02:00
Martin Weinelt
5d4a350660 nixos/doc/rl-2205: add slapd argon2 module rename hint
(cherry picked from commit 173fdcb251)
2022-05-29 18:54:06 +00:00
Artturin
7797c7ece5 glibc_multi: match output ordering of glibc
glibc has an exception in that 'out' is the default output instead of 'bin'

it should be matched here for consistency

(cherry picked from commit 513b7f1010)
2022-05-29 21:00:45 +03:00
Thiago Kenji Okada
388410bd28 Merge pull request #175329 from NixOS/backport-175302-to-release-22.05
[Backport release-22.05] distrobox: 1.2.15 -> 1.3.0
2022-05-29 18:58:00 +01:00
AtilaSaraiva
ee30f081ef distrobox: 1.2.15 -> 1.3.0
(cherry picked from commit 4330af7dd8)
2022-05-29 17:38:02 +00:00
Thomas Gerbet
61ef2043df zlog: fixes CVE-2021-43521
(cherry picked from commit a0a5f90ef2)
2022-05-29 16:55:43 +00:00
Vladimír Čunát
d09c03736d xorg.xorgserver: 1.20.13 -> 1.20.14
https://lists.x.org/archives/xorg-announce/2021-December/003124.html
(cherry picked from commit 1e65cb9c88)
2022-05-29 15:57:58 +00:00
Vladimír Čunát
b7c264c175 Revert "xorg.xorgserver: 1.20.13 -> 21.1.3"
This reverts commit 3312352596.
Fixes #170856: issues of some users.

(cherry picked from commit 43b7c9611c)
2022-05-29 15:57:58 +00:00
Robert Scott
489b52c6b7 Merge pull request #175318 from NixOS/backport-174522-to-release-22.05
[Backport release-22.05] python39Packages.graspologic: mark as broken
2022-05-29 16:51:43 +01:00
Fabian Affolter
0a553b0ace python39Packages.graspologic: mark as broken
(cherry picked from commit 9102b1cc65)
2022-05-29 15:32:23 +00:00
Fabian Affolter
45e24683bd python310Packages.numba: 0.55.1 -> 0.55.2
(cherry picked from commit 9b3553d1c4)
2022-05-29 14:49:57 +01:00
Fabian Affolter
e78bf71ff6 python310Packages.arviz: 0.12.0 -> 0.12.1
(cherry picked from commit cd22937423)
2022-05-29 14:49:57 +01:00
Fabian Affolter
fcfac6de24 python39Packages.umap-learn: disable flaky test
(cherry picked from commit c18e7de036)
2022-05-29 14:49:56 +01:00
Fabian Affolter
2d36fd535b python310Packages.datashader: 0.13.0 -> 0.14.0
(cherry picked from commit 7f38d0a148)
2022-05-29 14:49:56 +01:00
Fabian Affolter
9262314b78 python310Packages.pynndescent: 0.5.6 -> 0.5.7
(cherry picked from commit 5af41eba18)
2022-05-29 14:49:55 +01:00
Fabian Affolter
5f059fd0b4 python310Packages.aeppl: init at 0.0.31
(cherry picked from commit 91824e3192)
2022-05-29 14:49:54 +01:00
Fabian Affolter
0d8196ee9a python310Packages.numdifftools: init at 0.9.40
(cherry picked from commit 0fb3b8bddf)
2022-05-29 14:49:54 +01:00
Fabian Affolter
4d805f77c3 python310Packages.persim: disable failing tests on Python 3.10
(cherry picked from commit d69a2ffcea)
2022-05-29 14:49:53 +01:00
Fabian Affolter
2be4ab1b3b python39Packages.aesara: 2.5.3 -> 2.6.6
(cherry picked from commit b7874eee05)
2022-05-29 14:49:53 +01:00
Fabian Affolter
784c856be6 python310Packages.numba: update disable
(cherry picked from commit 2e32938d54)
2022-05-29 14:49:52 +01:00
Fabian Affolter
d70947e152 python39Packages.numba-scipy: update stale substituteInPlace
(cherry picked from commit 8278f5c3b0)
2022-05-29 14:49:51 +01:00
Fabian Affolter
d276d7f8aa python39Packages.numpyro: remove whitespace
(cherry picked from commit 2675b0e23d)
2022-05-29 14:49:17 +01:00
Fabian Affolter
1d14a5934c python310Packages.pymc3: 3.11.5 -> unstable-2022-05-23
(cherry picked from commit e55dfef920)
2022-05-29 14:49:16 +01:00
Fabian Affolter
e1a31e8893 python39Packages.arviz: refactor
(cherry picked from commit 97b7f3bc1a)
2022-05-29 14:49:16 +01:00
Fabian Affolter
099564e9f7 python39Packages.numpyro: init at 0.9.2
(cherry picked from commit 68f5159e30)
2022-05-29 14:49:15 +01:00
Fabian Affolter
e747bd3b23 python39Packages.xarray-einstats: init at 0.2.2
(cherry picked from commit a7f104763d)
2022-05-29 14:49:14 +01:00
Fabian Affolter
fc7643fea4 python310Packages.pyro-ppl: move extras dependencies
(cherry picked from commit 9da2f48064)
2022-05-29 14:49:14 +01:00
Bobby Rong
ec8c383af7 Merge pull request #175229 from NixOS/backport-175112-to-release-22.05
[Backport release-22.05] snowflake: 2.0.1 -> 2.2.0
2022-05-29 21:17:26 +08:00
Thiago Kenji Okada
db78278ff2 Merge pull request #175280 from NixOS/backport-175221-to-release-22.05
[Backport release-22.05] argocd-autopilot: 0.3.5 -> 0.3.7
2022-05-29 12:06:52 +01:00
Bryan A. S
2e263afbd0 argocd-autopilot: 0.3.5 -> 0.3.7
- bump version

- fix typo in ldflags to make sure default manifests url works

(cherry picked from commit 063471168d)
2022-05-29 10:39:01 +00:00
Robert Scott
4dcce2e40a Merge pull request #175144 from NixOS/backport-173327-to-staging-22.05
[Backport staging-22.05] libtiff: add patches for CVE-2022-1354 & CVE-2022-1355
2022-05-29 11:31:01 +01:00
Rick van Schijndel
2a64cd672b Merge pull request #175263 from NixOS/backport-174762-to-release-22.05
[Backport release-22.05] u-boot: embiggen RPi kernel allocation again, again
2022-05-29 12:19:19 +02:00
R. Ryantm
623b1681a6 gnome.gnome-terminal: 3.44.0 -> 3.44.1
(cherry picked from commit 87fd72101b)
2022-05-29 10:12:29 +00:00
R. Ryantm
49d24ce4d8 gnome.aisleriot: 3.22.22 -> 3.22.23
(cherry picked from commit 9344541ff2)
2022-05-29 10:11:14 +00:00
Rouven Czerwinski
eb03e084e3 seatd: 0.6.4 -> 0.7.0
Package bump to 0.7.0. The most important change for NixOS is a polling
bug fix for the logind backend. Previously sway would receive the DRM FD
pause event only after the DRM FD was unpaused, this is fixed in this
release.

Signed-off-by: Rouven Czerwinski <rouven@czerwinskis.de>
(cherry picked from commit a16d56e7b4)
2022-05-29 09:35:29 +00:00
maxine [they]
82d155a8ef Merge pull request #175237 from NixOS/backport-175233-to-release-22.05 2022-05-29 11:12:44 +02:00
maxine [they]
88215e69ae Merge pull request #175234 from NixOS/backport-175231-to-release-22.05 2022-05-29 11:12:31 +02:00
Vladimír Čunát
d21a6faf85 Merge #174340: e2fsprogs: apply patch unconditionally
...into release-22.05
2022-05-29 10:45:19 +02:00
K900
d42735f21b u-boot: embiggen RPi kernel allocation again, again
(cherry picked from commit ff391e0f0d)
2022-05-29 07:47:42 +00:00
R. Ryantm
cd7af3091d gnome.gnome-maps: 42.1 -> 42.2
(cherry picked from commit d64d4c8fcc)
2022-05-29 04:19:49 +00:00
Robert Schütz
ca7b592395 python310Packages.ocrmypdf: fix build on Darwin
With enabled sandbox we get
    PermissionError: [Errno 1] Operation not permitted
when calling os.nice().

(cherry picked from commit 65450988a5)
2022-05-28 21:18:52 -07:00
Robert Schütz
fb9306521f python310Packages.pikepdf: fix build on aarch64-darwin
(cherry picked from commit f0eb6d2059)
2022-05-28 21:18:52 -07:00
R. Ryantm
361309a694 gnome.eog: 42.1 -> 42.2
(cherry picked from commit 213cac429f)
2022-05-29 04:06:08 +00:00
Robert Schütz
6daced223a python310Packages.miniaudio: fix build on Darwin
(cherry picked from commit 57436c50ee)
2022-05-28 20:45:53 -07:00
Yaya
a87c409c9d snowflake: 2.0.1 -> 2.2.0
(cherry picked from commit 45109ffcb8)
2022-05-29 03:30:01 +00:00
Bobby Rong
fc206e3522 Merge pull request #175036 from NixOS/backport-173947-to-release-22.05
[Backport release-22.05] vkdisplayinfo: init at 0.1
2022-05-29 11:27:18 +08:00
Mario Rodas
1ae0feedfb Merge pull request #175213 from NixOS/backport-173501-to-release-22.05
[Backport release-22.05] mysql: 8.0.28 -> 8.0.29
2022-05-28 20:44:21 -05:00
github-actions[bot]
a444ab8121 Merge staging-next-22.05 into staging-22.05 2022-05-29 00:16:54 +00:00
github-actions[bot]
db8fe7158b Merge release-22.05 into staging-next-22.05 2022-05-29 00:16:14 +00:00
Aaron Jheng
47e85c3a34 mysql: 8.0.28 -> 8.0.29
(cherry picked from commit 0ce4fec785)
2022-05-29 00:12:17 +00:00
Martin Weinelt
53d60246da Merge pull request #175115 from NixOS/backport-172849-to-release-22.05 2022-05-29 01:59:45 +02:00
Robert Scott
3ef0aa0806 Merge pull request #175184 from NixOS/backport-174997-to-release-22.05
[Backport release-22.05] python3Packages.aioftp: skip pasv-mode test on darwin
2022-05-29 00:34:23 +01:00
Martin Weinelt
9d86c39445 Merge pull request #175201 from NixOS/backport-175028-to-staging-22.05
[Backport staging-22.05] openldap: make extraContribModules actually overrideable
2022-05-29 01:11:17 +02:00
Thiago Kenji Okada
d4efa1d822 Merge pull request #175203 from NixOS/backport-174897-to-release-22.05
[Backport release-22.05] each: 0.1.3 -> 0.2.0
2022-05-28 23:18:50 +01:00
Rick van Schijndel
8e5e8a366b Merge pull request #175181 from NixOS/backport-173198-to-release-22.05
[Backport release-22.05] nlohmann_json: 3.10.2 -> 3.10.5
2022-05-28 23:42:54 +02:00
R. Ryantm
7327559ad1 each: 0.1.3 -> 0.2.0
(cherry picked from commit 635d185f91)
2022-05-28 21:41:11 +00:00
Rick van Schijndel
38c57eb610 Merge pull request #175176 from NixOS/backport-173132-to-release-22.05
[Backport release-22.05] sigi: 3.3.0 -> 3.4.0
2022-05-28 23:23:47 +02:00
sternenseemann
f15e18b12d openldap: make extraContribModules actually overrideable
By using the build environment instead of relying on rec, using
overrideAttrs to change the value of extraContribModules will actually
have an effect.

(cherry picked from commit bf5acbc122)
2022-05-28 21:21:53 +00:00
Francesco Gazzetta
fa71687b27 openmoji-black,openmoji-color: fix hanging builds
...by downgrading fontforge.

Fixes https://github.com/NixOS/nixpkgs/issues/167869

(cherry picked from commit 6ee6794c8c)
2022-05-28 20:17:21 +00:00
Niklas Hambüchen
96d30fd819 Merge pull request #175164 from NixOS/backport-173370-to-release-22.05
[Backport release-22.05] turbovnc: 2.2.7 -> 3.0, unvendor libs
2022-05-28 21:58:09 +02:00
Robert Scott
53544f8d64 python3Packages.aioftp: skip pasv-mode test on darwin
(cherry picked from commit cd07879440)
2022-05-28 19:42:15 +00:00
Markus S. Wamser
cfc4f9536a nlohmann_json: 3.10.2 -> 3.10.5
(cherry picked from commit 1dfba65a22)
2022-05-28 19:29:36 +00:00
Aleksandar Topuzović
3d573b3f00 nixos/nextcloud: Fix broken config file
(cherry picked from commit fd86efb8c2)
2022-05-28 19:15:29 +00:00
hiljusti
921f8b4bd6 sigi: 3.3.0 -> 3.4.0
(cherry picked from commit 96467f286f)
2022-05-28 18:59:47 +00:00
Maximilian Bosch
515f7e95a6 wiki-js: 2.5.282 -> 2.5.283
ChangeLog: https://github.com/requarks/wiki/releases/tag/v2.5.283
(cherry picked from commit 9b11851ccf)
2022-05-28 18:24:20 +00:00
R. Ryantm
f1f0c4c1ac avrdudess: 2.13 -> 2.14
(cherry picked from commit 84ebb9b9f6a1668dabd9a7bf7e814671f115f465)
2022-05-28 19:58:52 +02:00
Markus S. Wamser
d3c1f66ebb turbovnc: 2.2.7 -> 3.0, unvendor libs
(cherry picked from commit 891df4eec9)
2022-05-28 17:58:52 +00:00
Gabriel Ebner
f01602e62a Merge pull request #175155 from NixOS/backport-175139-to-release-22.05
[Backport release-22.05] linuxPackages.digimend: unstable-2019-06-18 -> 10
2022-05-28 19:02:30 +02:00
Mario Rodas
db69d106a5 Merge pull request #174963 from NixOS/backport-174937-to-release-22.05
[Backport release-22.05] plantuml: 1.2022.3 -> 1.2022.5
2022-05-28 11:30:10 -05:00
Michael Weiss
313c5a9274 mesa: 22.0.3 -> 22.0.4
(cherry picked from commit b3fa0c3f86)
2022-05-28 18:09:00 +02:00
Michael Weiss
63c1814f99 mesa: 22.0.2 -> 22.0.3
(cherry picked from commit 44c5652c19)
2022-05-28 18:08:54 +02:00
Gabriel Ebner
ff48f1faa1 linuxPackages.digimend: unstable-2019-06-18 -> 10
(cherry picked from commit ddf273588e)
2022-05-28 16:08:50 +00:00
Artturi
1328a1b0e8 Merge pull request #175054 from NixOS/backport-170545-to-release-22.05
[Backport release-22.05] kitty: 0.24.4 -> 0.25.0
2022-05-28 18:46:02 +03:00
Bjørn Forsman
61bd5ce6a8 pulseview: hotfix build
libsForQt514 uses a custom stdenv that cause breakage when mixed with
boost built with normal stdenv. Fix it by building boost with the same
stdenv as libsForQt514.

This is a dirty fix compared to https://github.com/NixOS/nixpkgs/pull/171380,
but without mass rebuilds.

(cherry picked from commit 8d5481d01c)
2022-05-28 17:30:14 +02:00
José Romildo Malaquias
13209ddf33 Merge pull request #175141 from NixOS/backport-174931-to-release-22.05
[Backport release-22.05] xfce: move legacy aliases outside the scope of xfce
2022-05-28 12:22:08 -03:00
Robert Scott
36ce478716 libtiff: add patches for CVE-2022-1354 & CVE-2022-1355
(cherry picked from commit 8d8b43cb3c)
2022-05-28 15:08:27 +00:00
José Romildo
4e63ae1e0f xfce: move legacy aliases outside the scope of xfce
(cherry picked from commit 52beb63f4e)
2022-05-28 15:00:27 +00:00
José Romildo Malaquias
7429d1dec3 Merge pull request #175113 from NixOS/backport-174277-to-release-22.05
[Backport release-22.05] xfce: convert old aliases to throws, and remove old throws
2022-05-28 11:55:02 -03:00
José Romildo Malaquias
5870c4f0fb Merge pull request #175131 from NixOS/backport-174197-to-release-22.05
[Backport release-22.05] xfce.xfce4-terminal: 1.0.3 -> 1.0.4
2022-05-28 11:52:49 -03:00
Jörg Thalheim
812751d57f Merge pull request #175043 from NixOS/backport-174776-to-release-22.05
[Backport release-22.05] xkcd-font: fix build
2022-05-28 15:35:29 +01:00
Jörg Thalheim
aada3dbffd Merge pull request #175120 from NixOS/backport-175108-to-release-22.05
[Backport release-22.05] docs: document using labels for backporting in CONTRIBUTING.md
2022-05-28 15:33:08 +01:00
Bobby Rong
f00aef2d38 Merge pull request #174588 from NixOS/backport-169312-to-release-22.05
[Backport release-22.05] apko: init at 0.3.3
2022-05-28 22:11:31 +08:00
José Romildo
730e258412 xfce.xfce4-terminal: 1.0.3 -> 1.0.4
(cherry picked from commit e4dad6d606)
2022-05-28 13:58:20 +00:00
Azat Bahawi
33a2724525 mars: fix build
Bumps the revision and fixes https://hydra.nixos.org/build/178082390
Mark the version as "unstable" because the latest official version does
not build and there are no new releases.

(cherry picked from commit f35a5e2479)
2022-05-28 13:03:06 +00:00
Arnout Engelen
49db510d94 CONTRIBUTING.md: document using labels for backporting
(cherry picked from commit d73290c6dd)
2022-05-28 12:36:25 +00:00
Robert Scott
95d85ef635 Merge pull request #175116 from NixOS/backport-175039-to-release-22.05
[Backport release-22.05] clingcon: fix build
2022-05-28 13:21:44 +01:00
Azat Bahawi
817e0854f7 clingcon: fix build
Fix build https://hydra.nixos.org/build/178237905

(cherry picked from commit aa8447dd0c)
2022-05-28 11:45:54 +00:00
maxine [they]
812ec6fbca Merge pull request #175102 from NixOS/backport-175067-to-release-22.05 2022-05-28 13:38:03 +02:00
Matthias Treydte
fd46fd58f2 nixos/systemd-boot: fix systemd-boot-builder dowgrade to fail
Since, 4ddc78818e systemd-boot-builder
is broken in two ways:

  * if no systemd-boot is currently installed *and* the NIXOS_INSTALL_BOOTLOADER
    env variable is not set, it will try to run "bootctl update", which will fail
  * if the currently installed systemd-boot version is newer than the version
    we're about to install, it will also try to run "bootctl update", which will fail

This patch changes the behaviour,

  * for the first case to still fail, but not even bother to try running
    "bootctl update" and instead erroring out with an exception
  * for the second case to leave the newer version in place, restoring
    the pre - 4ddc78818e behaviour

To do the proper version check a new "should_update" helper function was introduced,
mimicing the compare_product C function from bootctl. If the following systemd
issue gets resolved, we would have a nice way to get rid of this function:

> https://github.com/systemd/systemd/issues/23450

This change allows to again switch to a different NixOS configuration which contains
an older systemd-boot.

Co-authored-by: Martin Weinelt <mweinelt@users.noreply.github.com>
(cherry picked from commit a30de3b849)
2022-05-28 11:29:14 +00:00
José Romildo
f52be30c02 xfce: convert old aliases to throws, and remove old throws
(cherry picked from commit 886d8b7ecf)
2022-05-28 11:21:28 +00:00
Thomas Gerbet
fee9a02002 cups: 2.4.1 -> 2.4.2
Fixes CVE-2022-26691.
https://github.com/OpenPrinting/cups/releases/tag/v2.4.2

(cherry picked from commit c590c23f49)
2022-05-28 10:53:31 +00:00
Janne Heß
d1086907f5 Merge pull request #174961 from NixOS/backport-174722-to-release-22.05
[Backport release-22.05] perl*Packages: Fix all packages
2022-05-28 12:29:49 +02:00
R. Ryantm
55821cbc13 evolution-data-server: 3.44.1 -> 3.44.2
(cherry picked from commit fc70d4257477682e6036d591a3ec8a41d74baa2c)
2022-05-28 10:13:37 +00:00
R. Ryantm
92d6058128 gnome.gnome-control-center: 42.1 -> 42.2
(cherry picked from commit 2fe8fe3ec62e96a448af087c20afab508c793aee)
2022-05-28 10:12:53 +00:00
R. Ryantm
ae4b739a8d gnome.nautilus: 42.1.1 -> 42.2
(cherry picked from commit 4615c41a73f1dbc867501a62c07e36e50b834942)
2022-05-28 10:11:27 +00:00
José Romildo Malaquias
714c4cce49 Merge pull request #175025 from NixOS/backport-173031-to-release-22.05
[Backport release-22.05] lxqt.libqtxdg: 3.9.0 -> 3.9.1
2022-05-28 06:54:05 -03:00
Bobby Rong
1127044143 Merge pull request #175085 from NixOS/backport-175059-to-release-22.05
[Backport release-22.05] pantheon.elementary-feedback: 6.1.0 -> 6.1.1
2022-05-28 17:10:15 +08:00
maxine [they]
69fd269a46 Merge pull request #175073 from NixOS/backport-175065-to-release-22.05
[Backport release-22.05] gnome.gnome-calculator: 42.0 -> 42.1
2022-05-28 11:08:27 +02:00
maxine [they]
1cf16ebae9 Merge pull request #175078 from NixOS/backport-175074-to-release-22.05
[Backport release-22.05] _1password: fix hashes
2022-05-28 11:05:21 +02:00
Michele Guerini Rocco
a840724b0c Merge pull request #175037 from NixOS/backport-174757-to-release-22.05
[Backport release-22.05] qutebrowser: 2.5.0 -> 2.5.1
2022-05-28 10:47:02 +02:00
Bobby Rong
fa127ed2cf pantheon.elementary-feedback: load metadata from correct location
(cherry picked from commit 874fb627c4)
2022-05-28 08:33:41 +00:00
Bobby Rong
3df1b42267 pantheon.elementary-feedback: 6.1.0 -> 6.1.1
(cherry picked from commit e741166e62)
2022-05-28 08:33:40 +00:00
Jörg Thalheim
8160ad8247 Merge pull request #175081 from NixOS/backport-152437-to-release-22.05
[Backport release-22.05] picoscope: fix sources
2022-05-28 09:02:38 +01:00
Jörg Thalheim
1e4ab9e339 picoscope: fix sources
(cherry picked from commit a3a93502f1)
2022-05-28 07:44:15 +00:00
Mario Rodas
971ad1c5b5 _1password: fix hashes
The latest version bump only updated the hash for x86_64-linux.

(cherry picked from commit dab999d541)
2022-05-28 07:34:14 +00:00
Jörg Thalheim
9af86f3121 Merge pull request #174944 from NixOS/backport-174680-to-release-22.05
[Backport release-22.05] nix-ld: disable build on non-linux platforms
2022-05-28 08:30:27 +01:00
Wael Nasreddine
08be99ada5 Merge pull request #175076 from NixOS/backport-175026-to-release-22.05 2022-05-28 00:21:08 -07:00
Maximilian Bosch
b1426df893 packer: 1.8.0 -> 1.8.1
ChangeLog: https://github.com/hashicorp/packer/blob/v1.8.1/CHANGELOG.md#181-may-27-2022
(cherry picked from commit 125e0b9f5c)
2022-05-28 06:52:50 +00:00
R. Ryantm
a883bac308 gnome.gnome-calculator: 42.0 -> 42.1
(cherry picked from commit cdcf234ef3)
2022-05-28 05:02:56 +00:00
Malo Bourgon
9f7197cff3 kitty: 0.24.4 -> 0.25.0
(cherry picked from commit 41d4a16961)
2022-05-28 01:27:13 +00:00
Robert Scott
8105e30643 Revert "cln: fix build on darwin"
(cherry picked from commit bc0d3c4b47)
2022-05-28 00:21:40 +00:00
Robert Schütz
71be98ead1 ostinato: fix desktop file
(cherry picked from commit dcd7915d17)
2022-05-27 17:16:49 -07:00
github-actions[bot]
22600329b9 Merge staging-next-22.05 into staging-22.05 2022-05-28 00:16:44 +00:00
github-actions[bot]
341ea1c678 Merge release-22.05 into staging-next-22.05 2022-05-28 00:16:08 +00:00
midchildan
01895ff5df xkcd-font: add comment
(cherry picked from commit 05e4997ae97743d7fa096134d620aff4290ab7c8)
2022-05-27 23:30:12 +00:00
midchildan
72727d16fe xkcd-font: remove dotfiles from output
(cherry picked from commit 736905b7e8f52c32683a17259e17a31bd5c8f285)
2022-05-27 23:30:12 +00:00
midchildan
6bf9570279 xkcd-font: fix build
(cherry picked from commit ef97620b668a5c8d1ac7fee56be7feab9c5e53cf)
2022-05-27 23:30:12 +00:00
José Romildo
a85b8bde1c libsForQt5.qtstyleplugin-kvantum: add update script
(cherry picked from commit 6238d2fe76)
2022-05-27 23:20:52 +00:00
José Romildo
a7a00cab7b libsForQt5.qtstyleplugin-kvantum: 1.0.1 -> 1.0.2
(cherry picked from commit c1aec2157f)
2022-05-27 23:20:51 +00:00
Robert Schütz
b4d2bc6726 qutebrowser: 2.5.0 -> 2.5.1
https://github.com/qutebrowser/qutebrowser/releases/tag/v2.5.1
(cherry picked from commit 2be2461a98)
2022-05-27 22:58:16 +00:00
Luna Nova
75a28d908b vkdisplayinfo: init at 0.1
https://github.com/ChristophHaag/vkdisplayinfo

Apply suggestions from @SuperSandro2000's code review

Co-authored-by: Sandro <sandro.jaeckel@gmail.com>

Don't use pipefail

(cherry picked from commit 108dea5cda)
2022-05-27 22:55:15 +00:00
José Romildo
894508e63b lxqt.lxqt-session: 1.1.0 -> 1.1.1
(cherry picked from commit 1c884fb5bd)
2022-05-27 22:32:43 +00:00
José Romildo
b5b02698f6 lxqt.qtxdg-tools: init at 3.9.1
(cherry picked from commit 6a69317900)
2022-05-27 22:32:42 +00:00
José Romildo
976a934df5 lxqt.libqtxdg: 3.9.0 -> 3.9.1
(cherry picked from commit 3ab2cf2279)
2022-05-27 22:32:42 +00:00
Niklas Hambüchen
33f78039b4 Merge pull request #174983 from NixOS/backport-174669-to-release-22.05
[Backport release-22.05] consul: 1.12.0 -> 1.12.1
2022-05-27 22:32:06 +02:00
Robert Scott
c5e45824da Merge pull request #174973 from NixOS/backport-174817-to-release-22.05
[Backport release-22.05] curl: deduplicate definition of `passthru.tests`
2022-05-27 20:30:24 +01:00
Robert Scott
f344c2bb1a Merge pull request #174976 from NixOS/backport-174820-to-release-22.05
[Backport release-22.05] python3Packages.nitime: disable test test_FilterAnalyzer
2022-05-27 20:30:10 +01:00
Robert Scott
3e89701b6f Merge pull request #174972 from NixOS/backport-174818-to-release-22.05
[Backport release-22.05] gecode_3: fix on darwin using same patch as gecode_6
2022-05-27 20:29:30 +01:00
techknowlogick
201b09125f consul: 1.12.0 -> 1.12.1
(cherry picked from commit 933a7b06bc)
2022-05-27 17:44:34 +00:00
Guillaume Girol
09e3091aae release-notes: don't encourage people to copy secrets to the store
(cherry picked from commit 2fdd23c154)
2022-05-27 17:40:49 +00:00
Matthew Toohey
c3aa32bed0 nixos/version: add trailing newline to os-release
(cherry picked from commit e41c423b01)
2022-05-27 17:34:48 +00:00
Jan Tojnar
97aa87451d gtk3: 3.24.33-2022-03-11 → 3.24.34
9d1d2f0a66...3.24.34
(cherry picked from commit 4e323c2ae12b3801b502d86b2af7b72365c9792e)
2022-05-27 17:33:25 +00:00
Robert Scott
aaf38814a7 python3Packages.nitime: disable test test_FilterAnalyzer
fails on all platforms after scipy 1.8.0 bump

(cherry picked from commit f01cef9982)
2022-05-27 17:16:15 +00:00
Robert Scott
889b6d813b curl: deduplicate definition of passthru.tests
(cherry picked from commit e9a0f109e5)
2022-05-27 16:59:21 +00:00
Robert Scott
fc72e35403 gecode_3: fix on darwin using same patch as gecode_6
(cherry picked from commit dd41e3832a)
2022-05-27 16:58:28 +00:00
Janne Heß
6e466b727d release: Slightly adjust release-critical packages
Removing Python 2 because it's EOL and most packages don't use it
anymore.
Also replace thunderbird with firefox because more people use it and it
feels better maintained in general

(cherry picked from commit 24bd72fd83)
2022-05-27 16:29:15 +00:00
Thomas Gerbet
44c1444338 plantuml: 1.2022.3 -> 1.2022.5
Fixes CVE-2022-1231.
https://plantuml.com/en/changes

(cherry picked from commit b6e3591669)
2022-05-27 15:53:55 +00:00
Janne Heß
c7bcba0389 perl*Packages: Fix all packages
This is mostly done by disabling the tests or the entire package on
Darwin

(cherry picked from commit 2997839463)
2022-05-27 15:39:24 +00:00
Artturin
09250ba91f treewide: change some glibc to stdenv.cc.libc
(cherry picked from commit c1fffdfffb)
2022-05-27 15:01:55 +00:00
Artturin
75e79f63d4 treewide: stdenv.glibc -> glibc
(cherry picked from commit 0c4d65b21e)
2022-05-27 15:01:55 +00:00
Artturin
e2457ce8bb stdenv: warn about use of stdenv.glibc
TODO was added in
119920faa6

(cherry picked from commit a05b581783)
2022-05-27 15:01:54 +00:00
Rick van Schijndel
7ec4e53390 Merge pull request #174602 from NixOS/backport-174222-to-release-22.05
[Backport release-22.05] linuxPackages.rtw88: 2021-04-19 to 2022-05-08, removed broken mark.
2022-05-27 16:07:22 +02:00
Jörg Thalheim
1f0b10ae8b nix-ld: disable build on non-linux platforms
(cherry picked from commit fcb339e294)
2022-05-27 13:57:09 +00:00
Kerstin Humm
7bb3e009c1 mastodon: 3.5.2 -> 3.5.3
(cherry picked from commit db795b8f2b7c6d315f50acba15c0491b4f0f1907)
2022-05-27 14:50:30 +02:00
maxine [they]
779e2f50f8 Merge pull request #174902 from NixOS/backport-174794-to-release-22.05
[Backport release-22.05] kind: 0.11.1 -> 0.14.0
2022-05-27 12:39:42 +02:00
Maxine Aubrey
9ffa7a7abb kind: 0.11.1 -> 0.14.0
- https://github.com/kubernetes-sigs/kind/releases/tag/v0.12.0
- https://github.com/kubernetes-sigs/kind/releases/tag/v0.13.0
- https://github.com/kubernetes-sigs/kind/releases/tag/v0.14.0

Changes:
- update/fix nixos specific kernel module path patch
- change build options to match upstream
- pin major go version to match upstream

(cherry picked from commit 5b062820b6)
2022-05-27 10:38:20 +00:00
maxine [they]
dddcef9ef7 Merge pull request #174549 from NixOS/backport-174524-to-release-22.05
[Backport release-22.05] coredns: 1.9.1 -> 1.9.2
2022-05-27 12:23:27 +02:00
maxine [they]
86631674f3 Merge pull request #174889 from NixOS/backport-174851-to-release-22.05
[Backport release-22.05] gnome.gnome-initial-setup: 42.1.1 -> 42.2
2022-05-27 12:17:31 +02:00
maxine [they]
31a0fe22f4 Merge pull request #174882 from NixOS/backport-174848-to-release-22.05
[Backport release-22.05] gnome.gedit: 42.0 -> 42.1
2022-05-27 12:17:17 +02:00
R. Ryantm
81d6245a61 gnome.gvfs: 1.50.1 -> 1.50.2
(cherry picked from commit c92255f7551a7156048a78ab2ca6df2a72701df3)
2022-05-27 08:47:16 +00:00
R. Ryantm
27d041e617 gnome.gnome-initial-setup: 42.1.1 -> 42.2
(cherry picked from commit c49b38e057f2e5127011683e85f357e1034d1204)
2022-05-27 08:44:26 +00:00
Timo Kaufmann
41d80aaff9 Merge pull request #174785 from NixOS/backport-174139-to-release-22.05
[Backport release-22.05] sage: fix passthru.kernelspec regression
2022-05-27 10:38:43 +02:00
R. Ryantm
a76201ad78 gnome.gedit: 42.0 -> 42.1
(cherry picked from commit c7acf6a4ac)
2022-05-27 07:54:53 +00:00
Maximilian Bosch
e7dbbc76e7 Merge pull request #174813 from NixOS/backport-174773-to-release-22.05
[Backport release-22.05] Linux kernel updates 2022-05-25
2022-05-27 07:56:02 +02:00
Kerstin Humm
308d79072c python3Packages.python-louvain: fix test karate
Also add pandas, scipy to checkInputs

(cherry picked from commit 22f3d34c93)
2022-05-27 04:39:54 +02:00
R. Ryantm
357ab17bb7 vorta: 0.8.4 -> 0.8.6
(cherry picked from commit a64bf22230)
2022-05-26 17:55:37 -07:00
github-actions[bot]
f95bd09ce8 Merge staging-next-22.05 into staging-22.05 2022-05-27 00:16:42 +00:00
github-actions[bot]
ee323a7bc5 Merge release-22.05 into staging-next-22.05 2022-05-27 00:16:07 +00:00
Atemu
1cf2f5ba35 mangohud: 0.6.5 -> 0.6.7-1
Updated patches and added new dependency on spdlog

(cherry picked from commit ad241745c3)
2022-05-27 00:13:34 +00:00
Maximilian Bosch
0102a71727 linux/hardened/patches/5.4: 5.4.195-hardened1 -> 5.4.196-hardened1
(cherry picked from commit 75f4c62775)
2022-05-26 22:52:40 +00:00
Maximilian Bosch
54ad2d59b7 linux/hardened/patches/5.17: 5.17.9-hardened1 -> 5.17.11-hardened1
(cherry picked from commit ec4b2a871d)
2022-05-26 22:52:40 +00:00
Maximilian Bosch
70426590f0 linux/hardened/patches/5.15: 5.15.41-hardened1 -> 5.15.43-hardened1
(cherry picked from commit e97b03a780)
2022-05-26 22:52:40 +00:00
Maximilian Bosch
27b7a0686f linux/hardened/patches/5.10: 5.10.117-hardened1 -> 5.10.118-hardened1
(cherry picked from commit d8d0dd929e)
2022-05-26 22:52:40 +00:00
Maximilian Bosch
921fbe2c57 linux/hardened/patches/4.19: 4.19.244-hardened1 -> 4.19.245-hardened1
(cherry picked from commit 63192641bb)
2022-05-26 22:52:40 +00:00
Maximilian Bosch
65395800a0 linux/hardened/patches/4.14: 4.14.280-hardened1 -> 4.14.281-hardened1
(cherry picked from commit 08daee172e)
2022-05-26 22:52:40 +00:00
Maximilian Bosch
9c6daf44c5 linux: 5.4.195 -> 5.4.196
(cherry picked from commit d505557a29)
2022-05-26 22:52:40 +00:00
Maximilian Bosch
488dabf121 linux: 5.17.9 -> 5.17.11
(cherry picked from commit c57d757e1b)
2022-05-26 22:52:40 +00:00
Maximilian Bosch
b95e3c00d4 linux: 5.15.41 -> 5.15.43
(cherry picked from commit bc0db57d53)
2022-05-26 22:52:39 +00:00
Maximilian Bosch
bbfd3b5093 linux: 5.10.117 -> 5.10.118
(cherry picked from commit ec5629f3f2)
2022-05-26 22:52:39 +00:00
Maximilian Bosch
0de9fe65fb linux: 4.9.315 -> 4.9.316
(cherry picked from commit 110b58f77e)
2022-05-26 22:52:39 +00:00
Maximilian Bosch
d979074177 linux: 4.19.244 -> 4.19.245
(cherry picked from commit b5c4a60bbe)
2022-05-26 22:52:39 +00:00
Maximilian Bosch
3fa5c1831f linux: 4.14.280 -> 4.14.281
(cherry picked from commit f2e1f34e4c)
2022-05-26 22:52:39 +00:00
Martin Weinelt
6477b12bae python3Packages.sanic: disable some tests again
Apparently those tests still need to be disabled.

(cherry picked from commit b79448d4ee)
2022-05-26 15:17:01 -07:00
Robert Schütz
b00c255692 python310Packages.uvicorn: 0.17.5 -> 0.17.6
https://github.com/encode/uvicorn/releases/tag/0.17.6
(cherry picked from commit 58667dbd53)
2022-05-26 15:17:01 -07:00
sternenseemann
6eeedcd742 Merge pull request #174798 from NixOS/backport-174777-to-release-22.05
[Backport release-22.05] gajim: fix plugin support
2022-05-26 23:40:40 +02:00
Robert Schütz
88e092f22c python3Packages.pykeepass: 4.0.1 -> 4.0.2
https://github.com/libkeepass/pykeepass/blob/v4.0.2/CHANGELOG.rst
(cherry picked from commit 09cce3f3e2)
2022-05-26 14:16:59 -07:00
Robert Scott
fbfe922658 Merge pull request #174779 from NixOS/backport-174617-to-release-22.05
[Backport release-22.05] python3Packages.pot: fix build on darwin
2022-05-26 22:04:13 +01:00
sternenseemann
79d2667dd0 gajim: update download page
(cherry picked from commit 9559ad77585c546221a2072ec1e315300d6a43f7)
2022-05-26 20:45:13 +00:00
sternenseemann
5dc61208df gajim: add dependency on gssapi
Not sure what this is necessary for precisely, but Gajim would complain
about missing it on startup.

(cherry picked from commit 65cc6305ee0ebb5ff7ce295c2075b659e3021bb9)
2022-05-26 20:45:13 +00:00
sternenseemann
b904d062b2 gajim: don't vendor old plugin_installer
With 1.4.0 the plugin_installer was added to the main Gajim source tree,
so we no longer need to fetch the plugins repository.

(cherry picked from commit f63c5a45c2010583c83d181bd8eba4b3745460e0)
2022-05-26 20:45:13 +00:00
Manuel Bärenz
6848cb6bfc scribus: Rename scribus{,Unstable} -> scribus{_1_4,}
(cherry picked from commit 28c8201955118249aa466260d3016869ad9f98c0)
2022-05-26 21:29:30 +02:00
Mauricio Collares
325eb23722 sage: fix passthru.kernelspec regression
(cherry picked from commit 8711501e96)
2022-05-26 19:11:07 +00:00
Martin Weinelt
7212933299 Merge pull request #174768 from NixOS/backport-174716-to-release-22.05 2022-05-26 20:23:13 +02:00
Martin Weinelt
fd840b999a Merge pull request #174766 from NixOS/backport-174718-to-release-22.05 2022-05-26 20:22:02 +02:00
Robert Scott
64a0e6fe03 python3Packages.pot: fix build on darwin
(cherry picked from commit 0cdff58b3f)
2022-05-26 18:19:39 +00:00
Robert Scott
ae77c60007 Merge pull request #174631 from NixOS/backport-174618-to-release-22.05
[Backport release-22.05] coredns: fix tests on darwin
2022-05-26 19:15:26 +01:00
Martin Weinelt
53bc420a99 Merge pull request #174769 from NixOS/backport-174756-to-staging-22.05 2022-05-26 19:39:10 +02:00
ajs124
df6a46b865 nspr: add hexa to maintainers
Co-authored-by: Martin Weinelt <mweinelt@users.noreply.github.com>
(cherry picked from commit e71288ffe5)
2022-05-26 17:37:40 +00:00
ajs124
5faf8c49f7 nspr: 4.33 -> 4.34
(cherry picked from commit a7be0f278d)
2022-05-26 17:37:40 +00:00
Martin Weinelt
8f2211f0c6 python3Packages.sanic-auth: disable failing test
(cherry picked from commit 664bd428bd)
2022-05-26 17:37:26 +00:00
Martin Weinelt
6dfa1d5a2c python3Packages.elastic-apm: fix tests with sanic>=22.3.0
(cherry picked from commit 39e8b8b42f)
2022-05-26 17:37:25 +00:00
Martin Weinelt
7ea428e9a1 python3Packages.sanic: 21.12.1 -> 22.3.2
(cherry picked from commit c95ab3cc25)
2022-05-26 17:37:25 +00:00
Martin Weinelt
4ef9f03873 python3Packages.sanic-resting: 0.8.2 -> 22.3.0
(cherry picked from commit 1fda638640)
2022-05-26 17:37:25 +00:00
Martin Weinelt
9893de5cfd python3Packages.sanic-routing: 0.7.2 -> 22.3.0
(cherry picked from commit 17273c5fcf)
2022-05-26 17:37:25 +00:00
Martin Weinelt
4b71257186 python3Packages.sentry-sdk: stop testing integrations
They're fragile and break on most dependency upgrades and the upstream
is too slow to catch up in a reasonable timeframe.

Also implement optional-depdencies passthru attr set and clean up unused
dependencies.

(cherry picked from commit df64a670ae)
2022-05-26 17:19:34 +00:00
Kai Wohlfahrt
787b1647a9 python3Packages.aiohttp: remove trustme test dependency on aarch64-darwin
This is an optional test dependency dependency is no longer needed, and
makes the package unbuildable on aarch64-darwin, as it transitively
depends on pyopenssl, which is marked broken.

(cherry picked from commit df1f9ecd9b)
2022-05-26 08:19:38 -07:00
midchildan
aa9efbf1ff noto-fonts-cjk: Revert "switch back to variable font"
This reverts commit 32c0743a20.

Fixes #171976. Some non-free packages happend to include the problematic
version of Harfbuzz that made the variable Noto CJK to not render.
2022-05-27 00:19:08 +09:00
Martin Weinelt
67cdf5099c Merge pull request #174743 from NixOS/backport-174717-to-release-22.05 2022-05-26 16:46:56 +02:00
Martin Weinelt
e409cfe8e9 python3Packages.lomond: disable tornado_4 tests on python3.10
And organize a makeover for the package.

(cherry picked from commit 9c295d34e1)
2022-05-26 14:27:50 +00:00
Martin Weinelt
b1671eaf7f Merge pull request #174739 from NixOS/backport-174719-to-release-22.05 2022-05-26 16:09:15 +02:00
Martin Weinelt
88fc18d34a python3Packages.pyfronius: add patch for python310 compat
(cherry picked from commit 27d3429a3f)
2022-05-26 14:04:44 +00:00
maxine [they]
300811fa8f Merge pull request #174699 from NixOS/backport-174064-to-release-22.05
[Backport release-22.05] golangci-lint: 1.45.2 -> 1.46.2
2022-05-26 15:54:27 +02:00
Martin Weinelt
ca7506ce15 Merge pull request #174723 from NixOS/backport-169430-to-release-22.05 2022-05-26 14:30:56 +02:00
Fabian Möller
718104684b breitbandmessung: don't use bundled electron
(cherry picked from commit 92e2e3b3f4)
2022-05-26 12:27:17 +00:00
Gabriel Ebner
dcc69df9cb Merge pull request #174704 from NixOS/backport-174624-to-release-22.05
[Backport release-22.05] elinks: disable perl support on darwin
2022-05-26 13:19:45 +02:00
Robert Scott
d96ad18485 elinks: disable perl support on darwin
currently causes a header mixup with LIST_HEAD macros

(cherry picked from commit 9b103fac08)
2022-05-26 09:59:13 +00:00
Michael Weiss
fab8a5d15d ungoogled-chromium: 101.0.4951.64 -> 102.0.5005.61
(cherry picked from commit 6226fc5cf0)
2022-05-26 09:57:04 +00:00
Michael Weiss
282ea22a18 Merge pull request #174449 from NixOS/backport-174338-to-release-22.05
[Backport release-22.05] chromium: 101.0.4951.64 -> 102.0.5005.61
2022-05-26 11:49:31 +02:00
R. Ryantm
0b6b10340a librsvg: 2.54.1 -> 2.54.3
(cherry picked from commit 2bab6e81ef9f067f101f7f3b6578199541d756ad)
2022-05-26 09:41:14 +00:00
Jan Tojnar
84070c8154 Remove myself from maintainers
Done with `sed -i -E '/^\s+jtojnar\s*$/d;s/ @?jtojnar//g' (rg ' jtojnar|^\s+jtojnar\s*$' -l -g '!maintainers/maintainer-list.nix')`.
(Always check the `rg` result beforehand to avoid corruption.)
2022-05-26 11:30:50 +02:00
Zane van Iperen
28bdfbef5b golangci-lint: 1.45.2 -> 1.46.2
(cherry picked from commit 4a029b2477)
2022-05-26 09:30:49 +00:00
maxine [they]
34f12f5e45 Merge pull request #174561 from NixOS/backport-174102-to-release-22.05
[Backport release-22.05] GNOME updates
2022-05-26 11:00:30 +02:00
adisbladis
192c0dcfc7 Merge pull request #174693 from NixOS/backport-174689-to-release-22.05
[Backport release-22.05] compressFirmwareXz: fix with empty lib/firmware
2022-05-26 16:58:37 +08:00
Alyssa Ross
6fd97eadd7 compressFirmwareXz: fix with empty lib/firmware
Fixes: 8aa8e0ce7f ("nixos/udev: compress all firmware if supported")
(cherry picked from commit 76405e3077)
2022-05-26 08:07:05 +00:00
Jörg Thalheim
99acd989ad Merge pull request #174622 from NixOS/backport-174491-to-release-22.05
[Backport release-22.05] ghidra-bin: 10.1.1 -> 10.1.4
2022-05-26 07:15:59 +01:00
adisbladis
aebc7fd7e2 Merge pull request #174661 from NixOS/backport-174178-to-release-22.05
[Backport release-22.05] emacsPackages.melpaBuild: Update package-build, avoid monkey-patch
2022-05-26 13:55:22 +08:00
Tad Fisher
c8bb3de96e emacsPackages.melpaBuild: Update package-build, avoid monkey-patch
(cherry picked from commit b4e4982e6c)
2022-05-26 02:53:28 +00:00
github-actions[bot]
fe2a9a8801 Merge staging-next-22.05 into staging-22.05 2022-05-26 00:16:33 +00:00
github-actions[bot]
59169e05ec Merge release-22.05 into staging-next-22.05 2022-05-26 00:15:58 +00:00
Robert Scott
794428305f coredns: fix tests on darwin
(cherry picked from commit e9c36e2d76)
2022-05-25 23:26:10 +00:00
Martin Weinelt
e3a8165d29 Merge pull request #174625 from NixOS/backport-174285-to-release-22.05 2022-05-26 01:20:35 +02:00
Tobias Mayer
01ad3873a6 pkgsStatic.python3: fix build
GCC does not come with a `libgcc_eh.a` for the target platform if
it was built without `--enable-shared`. That flag was removed with
c6dd11ca39, meaning we should no longer
attempt to link against that lib.

(cherry picked from commit 1e447d7898)
2022-05-25 22:39:57 +00:00
sintemal
511b94b525 ghidra-bin: 10.1.1 -> 10.1.4
(cherry picked from commit d079f3654d)
2022-05-25 22:21:58 +00:00
Alyssa Ross
55636a152d linuxPackages.openafs: mark broken on Linux 5.18
(cherry picked from commit d7446ec4678e97e7f80023d1e6a788d3c4894a2b)
2022-05-25 22:21:48 +00:00
Alyssa Ross
a2a6e71985 linuxPackages.vmware: mark broken on Linux 5.18
(cherry picked from commit f68830545150a8e1c63ca9c88d7893c8f4ade611)
2022-05-25 22:21:48 +00:00
Alyssa Ross
3c23c47c69 linuxPackages.virtualbox: mark broken on Linux 5.18
(cherry picked from commit 11ab41731c0d2f5c24947b1bc85661f6c8e36f6e)
2022-05-25 22:21:48 +00:00
Alyssa Ross
b3d8309c8a linuxPackages.rtl88xxau-aircrack: mark broken on Linux 5.18
(cherry picked from commit 90b308ddf8594478d5510e75efd4a09536b4248c)
2022-05-25 22:21:48 +00:00
Alyssa Ross
46e171dba1 linuxPackages.rtl8821ce: mark broken on Linux 5.18
(cherry picked from commit de2fc99ca6ab983a7bf8be070071d14b31cd3b84)
2022-05-25 22:21:48 +00:00
Alyssa Ross
ccec3f70c2 linuxPackages.rtl8192eu: mark broken on Linux 5.18
(cherry picked from commit 044f1204c7f5b6d7281d8a14d5e6fbd3a01bb060)
2022-05-25 22:21:48 +00:00
Alyssa Ross
778388bdff linuxPackages.nvidiabl: mark broken on Linux 5.18
(cherry picked from commit c49453790213fa0851ba3179b81f11253d26ca0b)
2022-05-25 22:21:48 +00:00
Alyssa Ross
7348038c72 linuxPackages.lttng-modules: mark broken on Linux 5.18
(cherry picked from commit 87fd0b8f5e35aafed79e67fd84116c1ae72db0d1)
2022-05-25 22:21:48 +00:00
Alyssa Ross
2dba8c3408 linuxPackages.kvmfr: mark broken on Linux 5.18
(cherry picked from commit 4f8a58791b1ed3214fe78481a27adad65d441011)
2022-05-25 22:21:48 +00:00
Alyssa Ross
c1e01debe7 linuxPackages.kvdo: mark broken on Linux 5.17+
(cherry picked from commit 9da14eb0a6919d4a24b8051a30933c9b2efdac78)
2022-05-25 22:21:48 +00:00
Alyssa Ross
7436afa22d linuxPackages.intel-speed-select: mark broken on Linux 5.18
(cherry picked from commit e34fb41128168f771dbfffa4cd8927869dd9cc44)
2022-05-25 22:21:48 +00:00
Alyssa Ross
f83ace1305 linuxPackages.facetimehd: mark broken on Linux 5.18
(cherry picked from commit cd6418bfe124c8feb54a523ebdf49b81b8e06a43)
2022-05-25 22:21:48 +00:00
Alyssa Ross
a274814c07 linuxPackages.dpdk: mark broken on Linux 5.18
(cherry picked from commit 5dfffe13e7fd211d0a6bd86c68c40e6337d04692)
2022-05-25 22:21:48 +00:00
Alyssa Ross
0042f455d1 linuxPackages.dpdk-kmods: mark broken on Linux 5.18
(cherry picked from commit ffbb348e7b9cab746f4fd3d205e34f8837e419cb)
2022-05-25 22:21:48 +00:00
Alyssa Ross
09a0b5f4d4 linuxPackages.dddvb: mark broken on Linux 5.18
(cherry picked from commit 2e82459fdc56b67e639019964b17d3be1e7c6ee3)
2022-05-25 22:21:48 +00:00
Alyssa Ross
79e93660fe linuxPackages.bbswitch: mark broken on Linux 5.18
(cherry picked from commit 48d76730a3c0f570e05559ba118a565fa3b1e7a0)
2022-05-25 22:21:48 +00:00
Alyssa Ross
410c3f046b linuxPackages.akvcam: mark broken on Linux 5.18
(cherry picked from commit cac2231057d35b9524336aec511693f16c7d5057)
2022-05-25 22:21:48 +00:00
Alyssa Ross
aac57c30ea linuxPackages.vendor-reset: enable parallel building
Tested at -j48.

(cherry picked from commit 9dab6bc07744790f5ca081fd9af07db1547bfaf5)
2022-05-25 22:21:32 +00:00
Alyssa Ross
113012804c linuxPackages.vendor-reset: patch for Linux 5.18
(cherry picked from commit d851e2f78a2c270e0f8ba1954cd884830796c8d0)
2022-05-25 22:21:32 +00:00
Alyssa Ross
520108641b cgiserver: init at 1.0.0
(cherry picked from commit b97e0d1cbc4c07934c4162502c637824818b58f0)
2022-05-25 22:20:57 +00:00
Alyssa Ross
f922a077d8 linux_latest: 5.17.9 -> 5.18
NSFD_V3 is now always enabled, and enabling debug info now requires
selecting a DWARF version instead of just setting DEBUG_INFO=y.

(cherry picked from commit fa7ae8876f)
2022-05-25 22:19:57 +00:00
Alyssa Ross
f6b9994e2e linuxPackages.pktgen: 21.11.0 -> 22.04.1
21.11.0 didn't build with our version of DPDK.

(cherry picked from commit 9278a76d82dd8ee4f9c4207b288ee391352fb149)
2022-05-25 22:18:51 +00:00
Alyssa Ross
8aa0aa9c7d linuxPackages.netatop: fix build with Linux 5.18
With 5.18, implicit fallthrough is an error, and netatop hasn't caught
up yet.

(cherry picked from commit 197e9ba286917cf32ed85efa117a14285b21a998)
2022-05-25 22:18:02 +00:00
Robert Scott
2224599890 Merge pull request #174614 from NixOS/backport-174581-to-release-22.05
[Backport release-22.05] python310Packages.pot: 0.8.1.0 -> 0.8.2
2022-05-25 22:20:00 +01:00
Robert Scott
64b479425b Merge pull request #174428 from NixOS/backport-174322-to-release-22.05
[Backport release-22.05] python310Packages.tokenizers: unstable-2021-08-13 -> 0.12.1
2022-05-25 22:15:47 +01:00
Fabian Affolter
c7f4660ac8 python310Packages.pot: 0.8.1.0 -> 0.8.2
(cherry picked from commit b7de85745c04526625d2874aee4c968654f0bd67)
2022-05-25 21:03:15 +00:00
AtilaSaraiva
daf6ceeebc linuxPackages.rtw88: removing upper version limit for the broken mark
(cherry picked from commit 032a4229f40010531c34f0e61aff84ba4c7a8261)
2022-05-25 20:26:27 +00:00
AtilaSaraiva
f57bf57c8d linuxPackages.rtw88: 2021-04-19 to 2022-05-08
added myself to the maintainers

(cherry picked from commit 71749fd81da723a2737c91e2cffe491e6c82c1d1)
2022-05-25 20:26:27 +00:00
Pascal Bach
d76be3882c Merge pull request #174311 from NixOS/backport-174280-to-release-22.05
[Backport release-22.05] element-{web,desktop}: 1.10.12 -> 1.10.13
2022-05-25 21:40:37 +02:00
Martin Weinelt
86fe1a808a Merge pull request #174589 from NixOS/backport-174535-to-release-22.05 2022-05-25 21:17:52 +02:00
Martin Weinelt
56f9e5d35e dump_syms: 1.0.0 -> 1.0.1
https://github.com/mozilla/dump_syms/releases/tag/v1.0.1
(cherry picked from commit d3564429d5)
2022-05-25 19:16:37 +00:00
06kellyjac
2dbb13690e apko: init at 0.3.3
(cherry picked from commit dcf4c8e7b9)
2022-05-25 19:11:45 +00:00
Martin Weinelt
6efc186e60 Merge pull request #174575 from NixOS/backport-174565-to-release-22.05 2022-05-25 20:45:06 +02:00
Alvar Penning
186c857daa logrotate: 3.19.0 -> 3.20.1
Fixes CVE-2022-1348.

- https://github.com/logrotate/logrotate/releases/tag/3.20.0
- https://github.com/logrotate/logrotate/releases/tag/3.20.1

(cherry picked from commit 0e006cd850)
2022-05-25 18:23:47 +00:00
Jan Tojnar
e5f47298b7 gnome.gnome-keyring: 40.0 → 42.1
https://gitlab.gnome.org/GNOME/gnome-keyring/-/compare/40.0...42.1

The systemd-activation support does not appear to me to be ready yet: https://gitlab.gnome.org/GNOME/gnome-keyring/-/merge_requests/35

(cherry picked from commit 2d6c441042)
2022-05-25 17:32:11 +00:00
Jan Tojnar
a412d05a3b seahorse: fix missing icons
Recent `wrapGAppsHook` change stopped `gcr` from being added to `XDG_DATA_DIRS`:
b1e73fa2e0
But gcr installs icons expected by Seahorse to the hicolor theme so we need to add it back.

Also drop adwaita-icon-theme since whether it will be used depends on user’s environment.

(cherry picked from commit e3e91f0c33)
2022-05-25 17:32:11 +00:00
Jan Tojnar
3090468d02 gupnp-tools: 0.10.2 → 0.10.3
https://gitlab.gnome.org/GNOME/gupnp-tools/-/compare/gupnp-tools-0.10.2...gupnp-tools-0.10.3
(cherry picked from commit 9925507b45)
2022-05-25 17:32:11 +00:00
Jan Tojnar
d3abf842f6 evince: 42.2 → 42.3
https://gitlab.gnome.org/GNOME/evince/-/compare/42.2...42.3
(cherry picked from commit e337e4ea5f)
2022-05-25 17:32:11 +00:00
Jan Tojnar
c7d2d933e3 shotwell: 0.30.15 → 0.30.16
https://gitlab.gnome.org/GNOME/shotwell/-/compare/shotwell-0.30.15...shotwell-0.30.16
(cherry picked from commit 2f87de7b08)
2022-05-25 17:32:11 +00:00
Jan Tojnar
e0aa1f1cd5 orca: 42.0 → 42.1
https://gitlab.gnome.org/GNOME/orca/-/compare/ORCA_42_0...ORCA_42_1
(cherry picked from commit 275b2f85ec)
2022-05-25 17:32:11 +00:00
Jan Tojnar
21e08a43f0 gnome.seahorse: 41.0 → 42.0
https://gitlab.gnome.org/GNOME/seahorse/-/compare/41.0...42.0
(cherry picked from commit b5d942b84f)
2022-05-25 17:32:10 +00:00
maxine [they]
0b9b835599 Merge pull request #174554 from NixOS/backport-174546-to-release-22.05 2022-05-25 19:06:33 +02:00
Maxine Aubrey
cc85ac23b9 docker: 20.10.15 -> 20.10.16
- https://docs.docker.com/engine/release-notes/#201016
- https://github.com/docker/cli/releases/tag/v20.10.16
- https://github.com/moby/moby/releases/tag/v20.10.16

(cherry picked from commit f21fb9441f)
2022-05-25 17:01:25 +00:00
R. Ryantm
44b21b7984 coredns: 1.9.1 -> 1.9.2
(cherry picked from commit ff7d60fdcf)
2022-05-25 16:47:37 +00:00
maxine [they]
50b9bcc9a4 Merge pull request #174544 from NixOS/backport-174488-to-release-22.05
[Backport release-22.05] docker-credential-gcr: 2.1.2 -> 2.1.4
2022-05-25 18:25:57 +02:00
R. Ryantm
e55bd861a9 docker-credential-gcr: 2.1.2 -> 2.1.4
(cherry picked from commit 3740bcad45)
2022-05-25 16:24:35 +00:00
maxine [they]
84026ed10c Merge pull request #174542 from NixOS/backport-174085-to-release-22.05
[Backport release-22.05] slack: 4.25.1 -> 4.26.1
2022-05-25 18:24:14 +02:00
maxine [they]
1f0988a53f Merge pull request #174543 from NixOS/backport-174392-to-release-22.05
[Backport release-22.05] _1password: 2.2.0 -> 2.3.1
2022-05-25 18:24:04 +02:00
R. Ryantm
db4d79857a _1password: 2.2.0 -> 2.3.1
(cherry picked from commit 85ff3bfe63)
2022-05-25 16:22:45 +00:00
nanashi0x74
0700863107 slack:4.25.1 -> 4.26.1
(cherry picked from commit 3d409bffca8e693fd74ad396705155be94d30bbf)
2022-05-25 16:22:38 +00:00
maxine [they]
30482fab2d Merge pull request #174541 from NixOS/backport-174486-to-release-22.05
[Backport release-22.05] docker-compose_2: 2.5.0 -> 2.5.1
2022-05-25 18:22:15 +02:00
R. Ryantm
f1dc426351 docker-compose_2: 2.5.0 -> 2.5.1
(cherry picked from commit dc51978b78)
2022-05-25 16:21:55 +00:00
06kellyjac
7a96cc6b2c tracee: add manual nixosTest for integration testing
(cherry picked from commit c68803fe31)
2022-05-25 16:41:33 +01:00
06kellyjac
e5aaa1f2f4 tracee: init at 0.7.0
(cherry picked from commit e2917e019b)
2022-05-25 16:41:24 +01:00
Michael Weiss
8d1d1dff92 chromium: 101.0.4951.64 -> 102.0.5005.61
https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html

This update includes 32 security fixes.

CVEs:
CVE-2022-1853 CVE-2022-1854 CVE-2022-1855 CVE-2022-1856 CVE-2022-1857
CVE-2022-1858 CVE-2022-1859 CVE-2022-1860 CVE-2022-1861 CVE-2022-1862
CVE-2022-1863 CVE-2022-1864 CVE-2022-1865 CVE-2022-1866 CVE-2022-1867
CVE-2022-1868 CVE-2022-1869 CVE-2022-1870 CVE-2022-1871 CVE-2022-1872
CVE-2022-1873 CVE-2022-1874 CVE-2022-1875 CVE-2022-1876

(cherry picked from commit e48814a245)
2022-05-25 09:15:11 +00:00
Martin Weinelt
4332560513 Merge pull request #174440 from NixOS/backport-174396-to-release-22.05 2022-05-25 10:11:48 +02:00
R. Ryantm
2cd013ed83 esphome: 2022.5.0 -> 2022.5.1
(cherry picked from commit bd88e1b38b)
2022-05-25 07:58:48 +00:00
Fabian Affolter
04ce374a07 python310Packages.tokenizers: add Security for darwin
(cherry picked from commit 73aa9f07ee)
2022-05-25 06:56:35 +00:00
Fabian Affolter
692f2abe16 python310Packages.tokenizers: unstable-2021-08-13 -> 0.12.1
(cherry picked from commit b95fefe360)
2022-05-25 06:56:35 +00:00
Mario Rodas
0c3bf3a5c3 Merge pull request #174421 from NixOS/backport-174267-to-release-22.05
[Backport release-22.05] postgresqlPackages.timescaledb: 2.6.1 -> 2.7.0
2022-05-25 01:43:11 -05:00
1000101
6652336fc8 postgresqlPackages.timescaledb: 2.6.1 -> 2.7.0
(cherry picked from commit 06eee30956)
2022-05-25 06:24:59 +00:00
Bobby Rong
08cea6f6cc Merge pull request #174263 from NixOS/backport-174220-to-release-22.05
[Backport release-22.05] pantheon.gala: save/restore easing on workspace switch
2022-05-25 12:01:32 +08:00
github-actions[bot]
80d81fd611 Merge staging-next-22.05 into staging-22.05 2022-05-25 00:18:27 +00:00
github-actions[bot]
1774dcc1ca Merge release-22.05 into staging-next-22.05 2022-05-25 00:17:36 +00:00
Robert Scott
851a423898 Merge pull request #174211 from NixOS/backport-173679-to-release-22.05
[Backport release-22.05] moarvm: fix build on darwin
2022-05-25 00:16:43 +01:00
Robert Scott
4d12927134 Merge pull request #174336 from NixOS/backport-174327-to-release-22.05
[Backport release-22.05] python310Packages.pyhocon: disable failing tests
2022-05-25 00:09:06 +01:00
Vladimír Čunát
81bb75b6ef e2fsprogs: apply patch unconditionally
Commit 49d0a5afd mistakenly inverted when to apply the patch.
Maybe it's not needed anymore, as pkgsMusl.e2fsprogs succeeded for me
even without it, but it looks harmless and better not have it inversed.
This way we also don't cause a mass rebuild :-)

(cherry picked from commit f008987704)
2022-05-24 22:47:53 +00:00
Fabian Affolter
a3349543b0 python310Packages.pyhocon: disable failing tests
(cherry picked from commit 76014d394e)
2022-05-24 22:32:24 +00:00
Martin Weinelt
3455859476 Merge pull request #174335 from NixOS/backport-171679-to-release-22.05 2022-05-25 00:23:49 +02:00
Martin Weinelt
ec44a901de Merge pull request #174333 from NixOS/backport-174329-to-release-22.05
[Backport release-22.05] powerdns-admin: fix build
2022-05-25 00:23:13 +02:00
Sebastian Neubauer
5ae3ced1e5 directx-shader-compiler: 1.6.2106 -> 1.6.2112
The glibc update broke compiling dxc. Update and fix compilation.

- Use ninja because it's faster and fixes compilation (uhm, yes, no idea
  why)
- Remove the comment about using submodules only for .git, they are
  actually used for SPIR-V
- The way default CMake flags are passed changed
- Add myself as maintainer

(cherry picked from commit 7655d19fc2)
2022-05-24 22:22:54 +00:00
Robert Scott
648b182a89 Merge pull request #174254 from NixOS/backport-174144-to-release-22.05
[Backport release-22.05] python310Packages.mlflow: 1.25.1 -> 1.26.0
2022-05-24 23:22:23 +01:00
Flakebi
cd575e1d5c powerdns-admin: fix build
Pin jsonschema to 3.2.0 because bravado-core is incompatible with 4.0.
Also fix the dnspython pin.

(cherry picked from commit efec13e550)
2022-05-24 22:18:28 +00:00
Florian Brandes
2a95d707e0 octoprint: 1.8.0 -> 1.8.1
Signed-off-by: Florian Brandes <florian.brandes@posteo.de>
(cherry picked from commit d08975af50)
2022-05-24 21:41:27 +00:00
Robert Scott
16ad3208e3 Merge pull request #174319 from NixOS/backport-174307-to-release-22.05
[Backport release-22.05] python310Packages.sumtypes: 0.1a5 -> 0.1a6
2022-05-24 22:35:53 +01:00
Robert Scott
8afb7a9534 Merge pull request #174317 from NixOS/backport-174296-to-release-22.05
[Backport release-22.05] python310Packages.qiskit-aer: disable failing test
2022-05-24 22:31:52 +01:00
Robert Scott
48f65c327a Merge pull request #174318 from NixOS/backport-174304-to-release-22.05
[Backport release-22.05] python39Packages.tensorly: disable failing test
2022-05-24 22:29:18 +01:00
Martin Weinelt
b823f47a93 Merge pull request #174320 from NixOS/backport-174312-to-release-22.05 2022-05-24 23:12:35 +02:00
Martin Weinelt
ef406f904d Merge pull request #174314 from NixOS/backport-174249-to-release-22.05
[Backport release-22.05] tor-browser-bundle-bin: 11.0.11 -> 11.0.13
2022-05-24 23:09:34 +02:00
Martin Weinelt
961e143b58 dump_syms: unstable-2022-05-05 -> 1.0.0
https://github.com/mozilla/dump_syms/releases/tag/v1.0.0
(cherry picked from commit 183bd9e940)
2022-05-24 21:09:18 +00:00
Fabian Affolter
4b9e6cba12 python310Packages.sumtypes: 0.1a5 -> 0.1a6
(cherry picked from commit bf30415f27)
2022-05-24 21:00:57 +00:00
Fabian Affolter
51810a0fe3 python39Packages.tensorly: disable failing test
(cherry picked from commit 0bee571d1b)
2022-05-24 21:00:45 +00:00
Fabian Affolter
eae67d0842 python310Packages.qiskit-aer: disable failing test
(cherry picked from commit 7acf1bd715)
2022-05-24 21:00:32 +00:00
FliegendeWurst
379a610966 tor-browser-bundle-bin: 11.0.11 -> 11.0.13
(cherry picked from commit 5c801dd601)
2022-05-24 20:36:17 +00:00
Sumner Evans
c695bcc79b element-{web,desktop}: 1.10.12 -> 1.10.13
(cherry picked from commit 402e5fe40d)
2022-05-24 20:24:10 +00:00
Martin Weinelt
d7cba8862e Merge pull request #174303 from NixOS/backport-174111-to-release-22.05
[Backport release-22.05] linuxPackages.nvidiabl: use a better homepage
2022-05-24 21:13:34 +02:00
Alyssa Ross
91c1c5f493 linuxPackages.nvidiabl: use a better homepage
It makes more sense to point this to the fork that we're using, rather
than the upstream.

(cherry picked from commit 062d21eead)
2022-05-24 19:05:48 +00:00
Robert Scott
339d0fc23d Merge pull request #174300 from NixOS/backport-174175-to-release-22.05
[Backport release-22.05] python3Packages.pyzbar: fix for darwin
2022-05-24 20:00:22 +01:00
Robert Scott
b87b64e349 python3Packages.pyzbar: fix for darwin
(cherry picked from commit a7de2cdcac)
2022-05-24 18:27:20 +00:00
Martin Weinelt
7f99bde23d Merge pull request #174298 from NixOS/backport-173738-to-release-22.05
[Backport release-22.05] buildMozillaMach: add support for MLS
2022-05-24 20:21:05 +02:00
Martin Weinelt
32bd8a47d8 buildMozillaMach: set geo.provider.network.url for new profiles.
Use Mozilla Location Service as geolocation provider for new profiles,
since our Google API key does not seem to work for geolocation at this
time.

Related: https://github.com/NixOS/nixpkgs/issues/173758
(cherry picked from commit 2d97db7873)
2022-05-24 18:14:22 +00:00
Martin Weinelt
a42e4414ac buildMozillaMach: Clean up Google API key configuration
Use a proper filename that and add the URL where information about
requesting API keys can be found.

(cherry picked from commit 0750e47a4d)
2022-05-24 18:14:22 +00:00
Martin Weinelt
8698dd394a buildMozillaMach: add support for MLS
We have received our very own API key for Mozilla Location Services and
have been recognized as a Public Interest Project, implying a rate limit
of 100k daily requests¹, which should be sufficient for our population.

N.B: This key belongs to the NixOS project, please don't use ours, but
instead request your own.

[1] https://location.services.mozilla.com/terms

(cherry picked from commit 1ba9dfbd97)
2022-05-24 18:14:22 +00:00
Martin Weinelt
3e8bf7fdeb Merge pull request #174161 from NixOS/backport-174005-to-staging-22.05 2022-05-24 20:07:31 +02:00
Rick van Schijndel
75560c4747 Merge pull request #174293 from NixOS/backport-174048-to-release-22.05
[Backport release-22.05] praat: fix cross-compilation
2022-05-24 20:01:15 +02:00
Rick van Schijndel
1715955fcb praat: fix cross-compilation
(cherry picked from commit 55b1550473)
2022-05-24 17:20:04 +00:00
Maximilian Bosch
6c97721a01 Merge pull request #174181 from NixOS/backport-174145-to-release-22.05
[Backport release-22.05] nixos/nextcloud: use PHP 8 avoiding broken 2FA app
2022-05-24 14:26:36 +02:00
Bobby Rong
df8cde54fa pantheon.gala: save/restore easing on workspace switch
(cherry picked from commit 7d48c204ef)
2022-05-24 10:32:10 +00:00
Fabian Affolter
c5b2704fcd python39Packages.manticore: mark as broken on darwin
(cherry picked from commit 36ea50ffe5)
2022-05-24 09:52:31 +00:00
Fabian Affolter
173a99a56a python39Packages.manticore: relax crytic-compile constraint
(cherry picked from commit fd04417531)
2022-05-24 09:52:31 +00:00
Fabian Affolter
046df58fe2 python310Packages.mlflow: 1.25.1 -> 1.26.0
(cherry picked from commit 00004be60e)
2022-05-24 08:38:11 +00:00
Thiago Kenji Okada
9f80fc22c1 Merge pull request #174240 from NixOS/backport-174129-to-release-22.05
[Backport release-22.05] adtool: mark broken
2022-05-24 08:07:46 +01:00
Martin Weinelt
78f9b41ee9 adtool: mark broken
Broke when updating OpenLDAP>2.5 and has not seen a change since 2017,
which is at this point 5y in the past.

I think it's safe to say that this tool deserves to being marked broken.

(cherry picked from commit d2fa18e744522f9823fde46ee9f9548de71bf231)
2022-05-24 06:38:57 +00:00
Wael Nasreddine
fb0003cd0b Merge pull request #174231 from NixOS/backport-174224-to-release-22.05 2022-05-23 22:09:55 -07:00
Bobby Rong
61b4e52c1e Merge pull request #174234 from NixOS/backport-174217-to-release-22.05
[Backport release-22.05] pantheon.elementary-mail: 6.4.0 -> 7.0.0
2022-05-24 13:02:55 +08:00
Bobby Rong
1a81be4d38 pantheon.elementary-mail: 6.4.0 -> 7.0.0
(cherry picked from commit 7e72954cad)
2022-05-24 04:48:39 +00:00
Wael M. Nasreddine
fc5baa5ec2 onlykey: 5.3.3 -> 5.3.4
(cherry picked from commit 0094dccde8)
2022-05-24 04:46:06 +00:00
Wael M. Nasreddine
f7390567fa onlykey-agent: 1.1.11 -> 1.1.13
(cherry picked from commit 9ba84fb7f7)
2022-05-24 04:46:06 +00:00
Wael M. Nasreddine
6901609eb9 onlykey-cli: 1.2.5 -> 1.2.9
(cherry picked from commit ca32037807)
2022-05-24 04:46:06 +00:00
Bobby Rong
b80531b35c Merge pull request #174216 from NixOS/backport-174112-to-release-22.05
[Backport release-22.05] pantheon-tweaks: 1.0.3 -> 1.0.4
2022-05-24 09:05:21 +08:00
Bobby Rong
d263bdfdbb pantheon-tweaks: 1.0.3 -> 1.0.4
(cherry picked from commit f60bb29734)
2022-05-24 00:41:28 +00:00
github-actions[bot]
8fcc66975c Merge staging-next-22.05 into staging-22.05 2022-05-24 00:16:41 +00:00
github-actions[bot]
915facf67d Merge release-22.05 into staging-next-22.05 2022-05-24 00:16:08 +00:00
Robert Scott
5c018ddd2e moarvm: add patch fixing build of bundled mimalloc on darwin
same patch as introduced to our own mimalloc in
9ba8bda313

(cherry picked from commit 7d56d31d82)
2022-05-24 00:14:18 +00:00
Robert Scott
b313d272ea Merge pull request #174196 from NixOS/backport-174084-to-release-22.05
[Backport release-22.05] python3Packages.aspy-refactor-imports: fix url and darwin test failure
2022-05-23 23:11:48 +01:00
Martin Weinelt
93eac359fd Merge pull request #174188 from NixOS/backport-174182-to-release-22.05
[Backport release-22.05] wallabag: 2.4.3 -> 2.5.0
2022-05-24 00:06:32 +02:00
Florian Brandes
bd96db064f python3Packages.aspy-refactor-imports: fix url and darwin test failure
Signed-off-by: Florian Brandes <florian.brandes@posteo.de>
(cherry picked from commit 2f4da397f0)
2022-05-23 22:04:25 +00:00
Robert Scott
642205175f Merge pull request #174191 from NixOS/backport-174148-to-release-22.05
[Backport release-22.05] s3bro: remove use_2to3
2022-05-23 22:57:10 +01:00
Fabian Affolter
ab405d8791 s3bro: remove use_2to3
(cherry picked from commit aa608e458c)
2022-05-23 21:34:39 +00:00
Martin Weinelt
54bd8d1f4d wallabag: 2.4.3 -> 2.5.0
https://github.com/wallabag/wallabag/releases/tag/2.5.0
(cherry picked from commit da56374a49)
2022-05-23 21:23:37 +00:00
Sergei Trofimovich
d44ca35d48 Merge pull request #174186 from NixOS/backport-172734-to-staging-22.05
[Backport staging-22.05] ncurses: 6.3 -> 6.3-p20220507
2022-05-23 21:07:37 +00:00
Sergei Trofimovich
4b8d27912f ncurses: 6.3 -> 6.3-p20220507
The main reason to pick intermediate patchset is to pull upstream
fix for CVE-2022-29458.

Changes: https://github.com/mirror/ncurses/blob/master/NEWS (since 6.3 release)
(cherry picked from commit be09e32117)
2022-05-23 20:46:18 +00:00
Antoine Martin
576b037f78 nixos/nextcloud: use PHP 8 avoiding broken 2FA app
(cherry picked from commit f3f0b60006)
2022-05-23 20:21:26 +00:00
Nick Cao
4cb5527a44 tdesktop: 3.6.0 -> 3.7.3
(cherry picked from commit 33775ec9a2)
2022-05-23 20:16:57 +00:00
milahu
8cbf8c9669 qt6: init at 6.3.0
(cherry picked from commit 5baa20d7c8)
2022-05-23 20:16:57 +00:00
Vladimír Čunát
c489a129b6 Merge #174177: glibc: apply patch to unbreak gnat6
...into staging-22.05
2022-05-23 22:15:12 +02:00
Sergei Trofimovich
4c4379be56 glibc: apply pending PR29162 to unbreak gnat6
commit e938c0274 "Don't add access size hints to fortifiable functions"
converted a few '__attr_access ((...))' into '__fortified_attr_access (...)'
calls.

But one of conversions had double parentheses of '__fortified_attr_access (...)'.

Noticed as a gnat6 build failure:

    /<<NIX>>-glibc-2.34-210-dev/include/bits/string_fortified.h:110:50: error: macro "__fortified_attr_access" requires 3 arguments, but only 1 given

The change fixes parentheses.

(cherry picked from commit 3c211fb591)
2022-05-23 20:06:12 +00:00
revol-xut
3a21a46ed1 lingua-franca: 0.1.0 -> 0.2.0
(cherry picked from commit 2c54c0602d)
2022-05-23 19:09:41 +00:00
Martin Weinelt
448c3da013 python39: 3.9.12 -> 3.9.13
https://www.python.org/downloads/release/python-3913/
https://blog.python.org/2022/05/python-3913-is-now-available.html
(cherry picked from commit 761ecd1061)
2022-05-23 18:16:05 +00:00
Janne Heß
7ae60dd706 22.05 beta release 2022-05-23 20:00:45 +02:00
2121 changed files with 55858 additions and 41765 deletions

View File

@@ -22,7 +22,7 @@ For new packages please briefly describe the package or provide a link to its ho
- made sure NixOS tests are [linked](https://nixos.org/manual/nixpkgs/unstable/#ssec-nixos-tests-linking) to the relevant packages
- [ ] Tested compilation of all packages that depend on this change using `nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD"`. Note: all changes have to be committed, also see [nixpkgs-review usage](https://github.com/Mic92/nixpkgs-review#usage)
- [ ] Tested basic functionality of all binary files (usually in `./result/bin/`)
- [22.05 Release Notes (or backporting 21.11 Release notes)](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#generating-2205-release-notes)
- [22.11 Release Notes (or backporting 22.05 Release notes)](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#generating-2211-release-notes)
- [ ] (Package updates) Added a release notes entry if the change is major or breaking
- [ ] (Module updates) Added a release notes entry if the change is significant
- [ ] (Module addition) Added a release notes entry if adding a new NixOS module

View File

@@ -97,11 +97,17 @@ git push origin $(git branch --show-current) --force-with-lease
Follow these steps to backport a change into a release branch in compliance with the [commit policy](https://nixos.org/nixpkgs/manual/#submitting-changes-stable-release-branches).
You can add a label such as `backport release-22.05` to a PR, so that merging it will
automatically create a backport (via [a GitHub Action](.github/workflows/backport.yml)).
This also works for PR's that have already been merged, and might take a couple of minutes to trigger.
You can also create the backport manually:
1. Take note of the commits in which the change was introduced into `master` branch.
2. Check out the target _release branch_, e.g. `release-21.11`. Do not use a _channel branch_ like `nixos-21.11` or `nixpkgs-21.11-darwin`.
2. Check out the target _release branch_, e.g. `release-22.05`. Do not use a _channel branch_ like `nixos-22.05` or `nixpkgs-22.05-darwin`.
3. Create a branch for your change, e.g. `git checkout -b backport`.
4. When the reason to backport is not obvious from the original commit message, use `git cherry-pick -xe <original commit>` and add a reason. Otherwise use `git cherry-pick -x <original commit>`. That's fine for minor version updates that only include security and bug fixes, commits that fixes an otherwise broken package or similar. Please also ensure the commits exists on the master branch; in the case of squashed or rebased merges, the commit hash will change and the new commits can be found in the merge message at the bottom of the master pull request.
5. Push to GitHub and open a backport pull request. Make sure to select the release branch (e.g. `release-21.11`) as the target branch of the pull request, and link to the pull request in which the original change was comitted to `master`. The pull request title should be the commit title with the release version as prefix, e.g. `[21.11]`.
5. Push to GitHub and open a backport pull request. Make sure to select the release branch (e.g. `release-22.05`) as the target branch of the pull request, and link to the pull request in which the original change was comitted to `master`. The pull request title should be the commit title with the release version as prefix, e.g. `[22.05]`.
6. When the backport pull request is merged and you have the necessary privileges you can also replace the label `9.needs: port to stable` with `8.has: port to stable` on the original pull request. This way maintainers can keep track of missing backports easier.
## Criteria for Backporting changes
@@ -113,17 +119,15 @@ Anything that does not cause user or downstream dependency regressions can be ba
- Services which require a client to be up-to-date regardless. (E.g. `spotify`, `steam`, or `discord`)
- Security critical applications (E.g. `firefox`)
## Generating 22.05 Release Notes
(This section also applies to backporting 21.11 release notes: substitute "rl-2205" for "rl-2111".)
## Generating 22.11 Release Notes
Documentation in nixpkgs is transitioning to a markdown-centric workflow. Release notes now require a translation step to convert from markdown to a compatible docbook document.
Steps for updating 22.05 Release notes:
Steps for updating 22.11 Release notes:
1. Edit `nixos/doc/manual/release-notes/rl-2205.section.md` with the desired changes
2. Run `./nixos/doc/manual/md-to-db.sh` to render `nixos/doc/manual/from_md/release-notes/rl-2205.section.xml`
3. Include changes to `rl-2205.section.md` and `rl-2205.section.xml` in the same commit.
1. Edit `nixos/doc/manual/release-notes/rl-2211.section.md` with the desired changes
2. Run `./nixos/doc/manual/md-to-db.sh` to render `nixos/doc/manual/from_md/release-notes/rl-2211.section.xml`
3. Include changes to `rl-2211.section.md` and `rl-2211.section.xml` in the same commit.
## Reviewing contributions

View File

@@ -51,9 +51,9 @@ Nixpkgs and NixOS are built and tested by our continuous integration
system, [Hydra](https://hydra.nixos.org/).
* [Continuous package builds for unstable/master](https://hydra.nixos.org/jobset/nixos/trunk-combined)
* [Continuous package builds for the NixOS 21.11 release](https://hydra.nixos.org/jobset/nixos/release-21.11)
* [Continuous package builds for the NixOS 22.05 release](https://hydra.nixos.org/jobset/nixos/release-22.05)
* [Tests for unstable/master](https://hydra.nixos.org/job/nixos/trunk-combined/tested#tabs-constituents)
* [Tests for the NixOS 21.11 release](https://hydra.nixos.org/job/nixos/release-21.11/tested#tabs-constituents)
* [Tests for the NixOS 22.05 release](https://hydra.nixos.org/job/nixos/release-22.05/tested#tabs-constituents)
Artifacts successfully built with Hydra are published to cache at
https://cache.nixos.org/. When successful build and test criteria are

View File

@@ -0,0 +1,11 @@
--[[
Converts some HTML elements commonly used in Markdown to corresponding DocBook elements.
]]
function RawInline(elem)
if elem.format == 'html' and elem.text == '<kbd>' then
return pandoc.RawInline('docbook', '<keycap>')
elseif elem.format == 'html' and elem.text == '</kbd>' then
return pandoc.RawInline('docbook', '</keycap>')
end
end

View File

@@ -302,7 +302,7 @@ buildImage {
runAsRoot = ''
#!${pkgs.runtimeShell}
${shadowSetup}
${pkgs.dockerTools.shadowSetup}
groupadd -r redis
useradd -r -g redis redis
mkdir /data

View File

@@ -227,7 +227,7 @@ digraph {
}
```
[This GitHub Action](https://github.com/NixOS/nixpkgs/blob/master/.github/workflows/periodic-merge-6h.yml) brings changes from `master` to `staging-next` and from `staging-next` to `staging` every 6 hours.
[This GitHub Action](https://github.com/NixOS/nixpkgs/blob/master/.github/workflows/periodic-merge-6h.yml) brings changes from `master` to `staging-next` and from `staging-next` to `staging` every 6 hours; these are the blue arrows in the diagram above. The purple arrows in the diagram above are done manually and much less frequently. You can get an idea of how often these merges occur by looking at the git history.
### Master branch {#submitting-changes-master-branch}

View File

@@ -1,5 +1,8 @@
{ pkgs ? (import ../.. {}), nixpkgs ? { }}:
let
inherit (pkgs) lib;
inherit (lib) hasPrefix removePrefix;
locationsXml = import ./lib-function-locations.nix { inherit pkgs nixpkgs; };
functionDocs = import ./lib-function-docs.nix { inherit locationsXml pkgs; };
version = pkgs.lib.version;
@@ -29,6 +32,18 @@ let
optionsDoc = pkgs.nixosOptionsDoc {
inherit (pkgs.lib.evalModules { modules = [ ../../pkgs/top-level/config.nix ]; }) options;
documentType = "none";
transformOptions = opt:
opt // {
declarations =
map
(decl:
if hasPrefix (toString ../..) (toString decl)
then
let subpath = removePrefix "/" (removePrefix (toString ../..) (toString decl));
in { url = "https://github.com/NixOS/nixpkgs/blob/master/${subpath}"; name = subpath; }
else decl)
opt.declarations;
};
};
in pkgs.runCommand "doc-support" {}

View File

@@ -77,7 +77,7 @@ There is a special handling of the `debug` output, described at [](#stdenv-separ
A commonly adopted convention in `nixpkgs` is that executables provided by the package are contained within its first output. This convention allows the dependent packages to reference the executables provided by packages in a uniform manner. For instance, provided with the knowledge that the `perl` package contains a `perl` executable it can be referenced as `${pkgs.perl}/bin/perl` within a Nix derivation that needs to execute a Perl script.
The `glibc` package is a deliberate single exception to the “binaries first” convention. The `glibc` has `libs` as its first output allowing the libraries provided by `glibc` to be referenced directly (e.g. `${stdenv.glibc}/lib/ld-linux-x86-64.so.2`). The executables provided by `glibc` can be accessed via its `bin` attribute (e.g. `${stdenv.glibc.bin}/bin/ldd`).
The `glibc` package is a deliberate single exception to the “binaries first” convention. The `glibc` has `libs` as its first output allowing the libraries provided by `glibc` to be referenced directly (e.g. `${glibc}/lib/ld-linux-x86-64.so.2`). The executables provided by `glibc` can be accessed via its `bin` attribute (e.g. `${lib.getBin stdenv.cc.libc}/bin/ldd`).
The reason for why `glibc` deviates from the convention is because referencing a library provided by `glibc` is a very common operation among Nix packages. For instance, third-party executables packaged by Nix are typically patched and relinked with the relevant version of `glibc` libraries from Nix packages (please see the documentation on [patchelf](https://github.com/NixOS/patchelf) for more details).

View File

@@ -17,6 +17,7 @@ rec {
isx86 = { cpu = { family = "x86"; }; };
isAarch32 = { cpu = { family = "arm"; bits = 32; }; };
isAarch64 = { cpu = { family = "arm"; bits = 64; }; };
isAarch = { cpu = { family = "arm"; }; };
isMips = { cpu = { family = "mips"; }; };
isMips32 = { cpu = { family = "mips"; bits = 32; }; };
isMips64 = { cpu = { family = "mips"; bits = 64; }; };

View File

@@ -856,6 +856,13 @@
githubId = 661909;
name = "Antonio Nuno Monteiro";
};
anoa = {
matrix = "@andrewm:amorgan.xyz";
email = "andrew@amorgan.xyz";
github = "anoadragon453";
githubId = 1342360;
name = "Andrew Morgan";
};
anpryl = {
email = "anpryl@gmail.com";
github = "anpryl";
@@ -2588,6 +2595,12 @@
fingerprint = "8026 D24A A966 BF9C D3CD CB3C 08FB 2BFC 470E 75B4";
}];
};
Crafter = {
email = "crafter@crafter.rocks";
github = "Craftzman7";
githubId = 70068692;
name = "Crafter";
};
craigem = {
email = "craige@mcwhirter.io";
github = "craigem";
@@ -2742,6 +2755,16 @@
githubId = 16895361;
name = "Deniz Alp Durmaz";
};
DAlperin = {
email = "git@dov.dev";
github = "DAlperin";
githubId = 16063713;
name = "Dov Alperin";
keys = [{
longkeyid = "rsa3072/0x7F2C07B91B52BB61";
fingerprint = "4EED 5096 B925 86FA 1101 6673 7F2C 07B9 1B52 BB61";
}];
};
DamienCassou = {
email = "damien@cassou.me";
github = "DamienCassou";
@@ -3093,6 +3116,12 @@
githubId = 17111639;
name = "Devin Singh";
};
devusb = {
email = "mhelton@devusb.us";
github = "devusb";
githubId = 4951663;
name = "Morgan Helton";
};
dezgeg = {
email = "tuomas.tynkkynen@iki.fi";
github = "dezgeg";
@@ -3699,6 +3728,12 @@
githubId = 1897147;
name = "Elijah Caine";
};
Elinvention = {
email = "elia@elinvention.ovh";
github = "Elinvention";
githubId = 5737945;
name = "Elia Argentieri";
};
elitak = {
email = "elitak@gmail.com";
github = "elitak";
@@ -5391,6 +5426,13 @@
githubId = 40234257;
name = "ilkecan bozdogan";
};
ihatethefrench = {
email = "michal@tar.black";
matrix = "@michal:tar.black";
github = "ihatethefrench";
githubId = 30374463;
name = "Michal S.";
};
illegalprime = {
email = "themichaeleden@gmail.com";
github = "illegalprime";
@@ -6326,6 +6368,13 @@
github = "jsierles";
githubId = 82;
};
jsimonetti = {
email = "jeroen+nixpkgs@simonetti.nl";
matrix = "@jeroen:simonetti.nl";
name = "Jeroen Simonetti";
github = "jsimonetti";
githubId = 5478838;
};
jtcoolen = {
email = "jtcoolen@pm.me";
name = "Julien Coolen";
@@ -8424,6 +8473,17 @@
fingerprint = "3196 83D3 9A1B 4DE1 3DC2 51FD FEA8 88C9 F5D6 4F62";
}];
};
minion3665 = {
name = "Skyler Grey";
email = "skyler3665@gmail.com";
matrix = "@minion3665:matrix.org";
github = "Minion3665";
githubId = 34243578;
keys = [{
longkeyid = "rsa4096/0x1AFD10256B3C714D";
fingerprint = "D520 AC8D 7C96 9212 5B2B BD3A 1AFD 1025 6B3C 714D";
}];
};
mir06 = {
email = "armin.leuprecht@uni-graz.at";
github = "mir06";
@@ -8914,6 +8974,12 @@
githubId = 1222539;
name = "Roman Naumann";
};
naphta = {
email = "naphta@noreply.github.com";
github = "naphta";
githubId = 6709831;
name = "Jake Hill";
};
nasirhm = {
email = "nasirhussainm14@gmail.com";
github = "nasirhm";
@@ -8946,6 +9012,16 @@
githubId = 818502;
name = "Nathan Yong";
};
natsukium = {
email = "nixpkgs@natsukium.com";
github = "natsukium";
githubId = 25083790;
name = "Tomoya Otabi";
keys = [{
longkeyid = "ed25519/0x9EA45A31DB994C53";
fingerprint = "3D14 6004 004C F882 D519 6CD4 9EA4 5A31 DB99 4C53";
}];
};
natto1784 = {
email = "natto@weirdnatto.in";
github = "natto1784";
@@ -9713,6 +9789,12 @@
githubId = 1788628;
name = "pandaman";
};
panicgh = {
email = "nbenes.gh@xandea.de";
github = "panicgh";
githubId = 79252025;
name = "Nicolas Benes";
};
paperdigits = {
email = "mica@silentumbrella.com";
github = "paperdigits";
@@ -9820,6 +9902,12 @@
githubId = 8641;
name = "Pierre Carrier";
};
pedrohlc = {
email = "root@pedrohlc.com";
github = "PedroHLC";
githubId = 1368952;
name = "Pedro Lara Campos";
};
penguwin = {
email = "penguwin@penguwin.eu";
github = "penguwin";
@@ -10244,6 +10332,12 @@
}
];
};
ProducerMatt = {
name = "Matthew Pherigo";
email = "ProducerMatt42@gmail.com";
github = "ProducerMatt";
githubId = 58014742;
};
Profpatsch = {
email = "mail@profpatsch.de";
github = "Profpatsch";
@@ -11232,6 +11326,12 @@
githubId = 107703;
name = "Samuel Rivas";
};
samw = {
email = "sam@wlcx.cc";
github = "wlcx";
githubId = 3065381;
name = "Sam Willcocks";
};
samyak = {
name = "Samyak Sarnayak";
email = "samyak201@gmail.com";
@@ -11383,6 +11483,17 @@
githubId = 3598650;
name = "Fritz Otlinghaus";
};
Scrumplex = {
name = "Sefa Eyeoglu";
email = "contact@scrumplex.net";
matrix = "@Scrumplex:duckhub.io";
github = "Scrumplex";
githubId = 11587657;
keys = [{
longkeyid = "rsa2048/0xC10411294912A422";
fingerprint = "AF1F B107 E188 CB97 9A94 FD7F C104 1129 4912 A422";
}];
};
scubed2 = {
email = "scubed2@gmail.com";
github = "scubed2";
@@ -11524,6 +11635,13 @@
githubId = 543055;
name = "Shadaj Laddad";
};
shadowrz = {
email = "shadowrz+nixpkgs@disroot.org";
matrix = "@ShadowRZ:matrixim.cc";
github = "ShadowRZ";
githubId = 23130178;
name = "";
};
shahrukh330 = {
email = "shahrukh330@gmail.com";
github = "shahrukh330";
@@ -12904,6 +13022,13 @@
githubId = 6740669;
name = "Tom Smeets";
};
tomsiewert = {
email = "tom@siewert.io";
matrix = "@tom:frickel.earth";
github = "tomsiewert";
githubId = 8794235;
name = "Tom Siewert";
};
toonn = {
email = "nixpkgs@toonn.io";
matrix = "@toonn:matrix.org";
@@ -13553,6 +13678,17 @@
email = "kirill.wedens@gmail.com";
name = "wedens";
};
WeebSorceress = {
name = "WeebSorceress";
email = "hello@weebsorceress.anonaddy.me";
matrix = "@weebsorceress:matrix.org";
github = "WeebSorceress";
githubId = 106774777;
keys = [{
longkeyid = "rsa4096/0x7F57344317F0FA43";
fingerprint = "659A 9BC3 F904 EC24 1461 2EFE 7F57 3443 17F0 FA43";
}];
};
wegank = {
name = "Weijia Wang";
email = "contact@weijia.wang";

View File

@@ -61,7 +61,7 @@ for bin in $(find $binaryDist -executable -type f) :; do
uniq;
)
if test "$names" = "glibc"; then names="stdenv.glibc"; fi
if test "$names" = "glibc"; then names="glibc"; fi
if echo $names | grep -c "gcc" &> /dev/null; then names="stdenv.cc.cc"; fi
if test $lib != $libPath; then

View File

@@ -93,6 +93,7 @@ with lib.maintainers; {
cinnamon = {
members = [
bobby285271
mkg20001
];
scope = "Maintain Cinnamon desktop environment and applications made by the LinuxMint team.";
@@ -223,7 +224,7 @@ with lib.maintainers; {
};
freedesktop = {
members = [ jtojnar ];
members = [ ];
scope = "Maintain Freedesktop.org packages for graphical desktop.";
shortName = "freedesktop.org packaging";
};
@@ -258,7 +259,6 @@ with lib.maintainers; {
members = [
bobby285271
hedning
jtojnar
dasj19
maxeaubrey
];

View File

@@ -1,35 +1,135 @@
<section xmlns="http://docbook.org/ns/docbook" xmlns:xlink="http://www.w3.org/1999/xlink" xml:id="sec-booting-from-usb">
<title>Booting from a USB Drive</title>
<title>Booting from a USB flash drive</title>
<para>
For systems without CD drive, the NixOS live CD can be booted from a
USB stick. You can use the <literal>dd</literal> utility to write
the image: <literal>dd if=path-to-image of=/dev/sdX</literal>. Be
careful about specifying the correct drive; you can use the
<literal>lsblk</literal> command to get a list of block devices.
The image has to be written verbatim to the USB flash drive for it
to be bootable on UEFI and BIOS systems. Here are the recommended
tools to do that.
</para>
<note>
<title>On macOS</title>
<section xml:id="sec-booting-from-usb-graphical">
<title>Creating bootable USB flash drive with a graphical
tool</title>
<para>
Etcher is a popular and user-friendly tool. It works on Linux,
Windows and macOS.
</para>
<para>
Download it from
<link xlink:href="https://www.balena.io/etcher/">balena.io</link>,
start the program, select the downloaded NixOS ISO, then select
the USB flash drive and flash it.
</para>
<warning>
<para>
Etcher reports errors and usage statistics by default, which can
be disabled in the settings.
</para>
</warning>
<para>
An alternative is
<link xlink:href="https://bztsrc.gitlab.io/usbimager">USBImager</link>,
which is very simple and does not connect to the internet.
Download the version with write-only (wo) interface for your
system. Start the program, select the image, select the USB flash
drive and click <quote>Write</quote>.
</para>
</section>
<section xml:id="sec-booting-from-usb-linux">
<title>Creating bootable USB flash drive from a Terminal on
Linux</title>
<orderedlist numeration="arabic" spacing="compact">
<listitem>
<para>
Plug in the USB flash drive.
</para>
</listitem>
<listitem>
<para>
Find the corresponding device with <literal>lsblk</literal>.
You can distinguish them by their size.
</para>
</listitem>
<listitem>
<para>
Make sure all partitions on the device are properly unmounted.
Replace <literal>sdX</literal> with your device (e.g.
<literal>sdb</literal>).
</para>
</listitem>
</orderedlist>
<programlisting>
$ diskutil list
[..]
/dev/diskN (external, physical):
#: TYPE NAME SIZE IDENTIFIER
[..]
$ diskutil unmountDisk diskN
Unmount of all volumes on diskN was successful
$ sudo dd if=nix.iso of=/dev/rdiskN bs=1M
sudo umount /dev/sdX*
</programlisting>
<orderedlist numeration="arabic" spacing="compact">
<listitem override="4">
<para>
Then use the <literal>dd</literal> utility to write the image
to the USB flash drive.
</para>
</listitem>
</orderedlist>
<programlisting>
sudo dd if=&lt;path-to-image&gt; of=/dev/sdX bs=4M conv=fsync
</programlisting>
</section>
<section xml:id="sec-booting-from-usb-macos">
<title>Creating bootable USB flash drive from a Terminal on
macOS</title>
<orderedlist numeration="arabic" spacing="compact">
<listitem>
<para>
Plug in the USB flash drive.
</para>
</listitem>
<listitem>
<para>
Find the corresponding device with
<literal>diskutil list</literal>. You can distinguish them by
their size.
</para>
</listitem>
<listitem>
<para>
Make sure all partitions on the device are properly unmounted.
Replace <literal>diskX</literal> with your device (e.g.
<literal>disk1</literal>).
</para>
</listitem>
</orderedlist>
<programlisting>
diskutil unmountDisk diskX
</programlisting>
<orderedlist numeration="arabic" spacing="compact">
<listitem override="4">
<para>
Then use the <literal>dd</literal> utility to write the image
to the USB flash drive.
</para>
</listitem>
</orderedlist>
<programlisting>
sudo dd if=&lt;path-to-image&gt; of=/dev/rdiskX bs=4m
</programlisting>
<para>
Using the 'raw' <literal>rdiskN</literal> device instead of
<literal>diskN</literal> completes in minutes instead of hours.
After <literal>dd</literal> completes, a GUI dialog &quot;The disk
you inserted was not readable by this computer&quot; will pop up,
which can be ignored.
</para>
</note>
<para>
The <literal>dd</literal> utility will write the image verbatim to
the drive, making it the recommended option for both UEFI and
non-UEFI installations.
</para>
<note>
<para>
Using the 'raw' <literal>rdiskX</literal> device instead of
<literal>diskX</literal> with dd completes in minutes instead of
hours.
</para>
</note>
<orderedlist numeration="arabic" spacing="compact">
<listitem override="5">
<para>
Eject the disk when it is finished.
</para>
</listitem>
</orderedlist>
<programlisting>
diskutil eject /dev/diskX
</programlisting>
</section>
</section>

File diff suppressed because it is too large Load Diff

View File

@@ -2,16 +2,15 @@
<title>Obtaining NixOS</title>
<para>
NixOS ISO images can be downloaded from the
<link xlink:href="https://nixos.org/nixos/download.html">NixOS
download page</link>. There are a number of installation options. If
you happen to have an optical drive and a spare CD, burning the
image to CD and booting from that is probably the easiest option.
Most people will need to prepare a USB stick to boot from.
<xref linkend="sec-booting-from-usb" /> describes the preferred
method to prepare a USB stick. A number of alternative methods are
presented in the
<link xlink:href="https://nixos.wiki/wiki/NixOS_Installation_Guide#Making_the_installation_media">NixOS
Wiki</link>.
<link xlink:href="https://nixos.org/download.html#nixos-iso">NixOS
download page</link>. Follow the instructions in
<xref linkend="sec-booting-from-usb" /> to create a bootable USB
flash drive.
</para>
<para>
If you have a very old system that cant boot from USB, you can burn
the image to an empty CD. NixOS might not work very well on such
systems.
</para>
<para>
As an alternative to installing NixOS yourself, you can get a
@@ -23,16 +22,16 @@
Using virtual appliances in Open Virtualization Format (OVF)
that can be imported into VirtualBox. These are available from
the
<link xlink:href="https://nixos.org/nixos/download.html">NixOS
<link xlink:href="https://nixos.org/download.html#nixos-virtualbox">NixOS
download page</link>.
</para>
</listitem>
<listitem>
<para>
Using AMIs for Amazons EC2. To find one for your region and
instance type, please refer to the
<link xlink:href="https://github.com/NixOS/nixpkgs/blob/master/nixos/modules/virtualisation/ec2-amis.nix">list
of most recent AMIs</link>.
Using AMIs for Amazons EC2. To find one for your region, please
refer to the
<link xlink:href="https://nixos.org/download.html#nixos-amazon">download
page</link>.
</para>
</listitem>
<listitem>

View File

@@ -12,7 +12,7 @@
<listitem>
<para>
<emphasis>Stable channels</emphasis>, such as
<link xlink:href="https://nixos.org/channels/nixos-21.11"><literal>nixos-21.11</literal></link>.
<link xlink:href="https://nixos.org/channels/nixos-22.05"><literal>nixos-22.05</literal></link>.
These only get conservative bug fixes and package upgrades. For
instance, a channel update may cause the Linux kernel on your
system to be upgraded from 4.19.34 to 4.19.38 (a minor bug fix),
@@ -33,7 +33,7 @@
<listitem>
<para>
<emphasis>Small channels</emphasis>, such as
<link xlink:href="https://nixos.org/channels/nixos-21.11-small"><literal>nixos-21.11-small</literal></link>
<link xlink:href="https://nixos.org/channels/nixos-22.05-small"><literal>nixos-22.05-small</literal></link>
or
<link xlink:href="https://nixos.org/channels/nixos-unstable-small"><literal>nixos-unstable-small</literal></link>.
These are identical to the stable and unstable channels
@@ -60,8 +60,8 @@
<para>
When you first install NixOS, youre automatically subscribed to the
NixOS channel that corresponds to your installation source. For
instance, if you installed from a 21.11 ISO, you will be subscribed
to the <literal>nixos-21.11</literal> channel. To see which NixOS
instance, if you installed from a 22.05 ISO, you will be subscribed
to the <literal>nixos-22.05</literal> channel. To see which NixOS
channel youre subscribed to, run the following as root:
</para>
<programlisting>
@@ -76,17 +76,17 @@ nixos https://nixos.org/channels/nixos-unstable
</programlisting>
<para>
(Be sure to include the <literal>nixos</literal> parameter at the
end.) For instance, to use the NixOS 21.11 stable channel:
end.) For instance, to use the NixOS 22.05 stable channel:
</para>
<programlisting>
# nix-channel --add https://nixos.org/channels/nixos-21.11 nixos
# nix-channel --add https://nixos.org/channels/nixos-22.05 nixos
</programlisting>
<para>
If you have a server, you may want to use the <quote>small</quote>
channel instead:
</para>
<programlisting>
# nix-channel --add https://nixos.org/channels/nixos-21.11-small nixos
# nix-channel --add https://nixos.org/channels/nixos-22.05-small nixos
</programlisting>
<para>
And if you want to live on the bleeding edge:
@@ -146,7 +146,7 @@ system.autoUpgrade.allowReboot = true;
also specify a channel explicitly, e.g.
</para>
<programlisting language="bash">
system.autoUpgrade.channel = https://nixos.org/channels/nixos-21.11;
system.autoUpgrade.channel = https://nixos.org/channels/nixos-22.05;
</programlisting>
</section>
</chapter>

File diff suppressed because it is too large Load Diff

View File

@@ -1,31 +1,72 @@
# Booting from a USB Drive {#sec-booting-from-usb}
# Booting from a USB flash drive {#sec-booting-from-usb}
For systems without CD drive, the NixOS live CD can be booted from a USB
stick. You can use the `dd` utility to write the image:
`dd if=path-to-image of=/dev/sdX`. Be careful about specifying the correct
drive; you can use the `lsblk` command to get a list of block devices.
The image has to be written verbatim to the USB flash drive for it to be
bootable on UEFI and BIOS systems. Here are the recommended tools to do that.
::: {.note}
::: {.title}
On macOS
## Creating bootable USB flash drive with a graphical tool {#sec-booting-from-usb-graphical}
Etcher is a popular and user-friendly tool. It works on Linux, Windows and macOS.
Download it from [balena.io](https://www.balena.io/etcher/), start the program,
select the downloaded NixOS ISO, then select the USB flash drive and flash it.
::: {.warning}
Etcher reports errors and usage statistics by default, which can be disabled in
the settings.
:::
```ShellSession
$ diskutil list
[..]
/dev/diskN (external, physical):
#: TYPE NAME SIZE IDENTIFIER
[..]
$ diskutil unmountDisk diskN
Unmount of all volumes on diskN was successful
$ sudo dd if=nix.iso of=/dev/rdiskN bs=1M
```
An alternative is [USBImager](https://bztsrc.gitlab.io/usbimager),
which is very simple and does not connect to the internet. Download the version
with write-only (wo) interface for your system. Start the program,
select the image, select the USB flash drive and click "Write".
Using the \'raw\' `rdiskN` device instead of `diskN` completes in
minutes instead of hours. After `dd` completes, a GUI dialog \"The disk
you inserted was not readable by this computer\" will pop up, which can
be ignored.
:::
## Creating bootable USB flash drive from a Terminal on Linux {#sec-booting-from-usb-linux}
The `dd` utility will write the image verbatim to the drive, making it
the recommended option for both UEFI and non-UEFI installations.
1. Plug in the USB flash drive.
2. Find the corresponding device with `lsblk`. You can distinguish them by
their size.
3. Make sure all partitions on the device are properly unmounted. Replace `sdX`
with your device (e.g. `sdb`).
```ShellSession
sudo umount /dev/sdX*
```
4. Then use the `dd` utility to write the image to the USB flash drive.
```ShellSession
sudo dd if=<path-to-image> of=/dev/sdX bs=4M conv=fsync
```
## Creating bootable USB flash drive from a Terminal on macOS {#sec-booting-from-usb-macos}
1. Plug in the USB flash drive.
2. Find the corresponding device with `diskutil list`. You can distinguish them
by their size.
3. Make sure all partitions on the device are properly unmounted. Replace `diskX`
with your device (e.g. `disk1`).
```ShellSession
diskutil unmountDisk diskX
```
4. Then use the `dd` utility to write the image to the USB flash drive.
```ShellSession
sudo dd if=<path-to-image> of=/dev/rdiskX bs=4m
```
After `dd` completes, a GUI dialog \"The disk
you inserted was not readable by this computer\" will pop up, which can
be ignored.
::: {.note}
Using the \'raw\' `rdiskX` device instead of `diskX` with dd completes in
minutes instead of hours.
:::
5. Eject the disk when it is finished.
```ShellSession
diskutil eject /dev/diskX
```

View File

@@ -1,30 +1,143 @@
# Installing NixOS {#sec-installation}
## Booting the system {#sec-installation-booting}
## Booting from the install medium {#sec-installation-booting}
To begin the installation, you have to boot your computer from the install drive.
1. Plug in the install drive. Then turn on or restart your computer.
2. Open the boot menu by pressing the appropriate key, which is usually shown
on the display on early boot.
Select the USB flash drive (the option usually contains the word "USB").
If you choose the incorrect drive, your computer will likely continue to
boot as normal. In that case restart your computer and pick a
different drive.
::: {.note}
The key to open the boot menu is different across computer brands and even
models. It can be <kbd>F12</kbd>, but also <kbd>F1</kbd>,
<kbd>F9</kbd>, <kbd>F10</kbd>, <kbd>Enter</kbd>, <kbd>Del</kbd>,
<kbd>Esc</kbd> or another function key. If you are unsure and don't see
it on the early boot screen, you can search online for your computers
brand, model followed by "boot from usb".
The computer might not even have that feature, so you have to go into the
BIOS/UEFI settings to change the boot order. Again, search online for
details about your specific computer model.
For Apple computers with Intel processors press and hold the <kbd>⌥</kbd>
(Option or Alt) key until you see the boot menu. On Apple silicon press
and hold the power button.
:::
::: {.note}
If your computer supports both BIOS and UEFI boot, choose the UEFI option.
:::
::: {.note}
If you use a CD for the installation, the computer will probably boot from
it automatically. If not, choose the option containing the word "CD" from
the boot menu.
:::
3. Shortly after selecting the appropriate boot drive, you should be
presented with a menu with different installer options. Leave the default
and wait (or press <kbd>Enter</kbd> to speed up).
4. The graphical images will start their corresponding desktop environment
and the graphical installer, which can take some time. The minimal images
will boot to a command line. You have to follow the instructions in
[](#sec-installation-manual) there.
## Graphical Installation {#sec-installation-graphical}
The graphical installer is recommended for desktop users and will guide you
through the installation.
1. In the "Welcome" screen, you can select the language of the Installer and
the installed system.
::: {.tip}
Leaving the language as "American English" will make it easier to search for
error messages in a search engine or to report an issue.
:::
2. Next you should choose your location to have the timezone set correctly.
You can actually click on the map!
::: {.note}
The installer will use an online service to guess your location based on
your public IP address.
:::
3. Then you can select the keyboard layout. The default keyboard model should
work well with most desktop keyboards. If you have a special keyboard or
notebook, your model might be in the list. Select the language you are most
comfortable typing in.
4. On the "Users" screen, you have to type in your display name, login name
and password. You can also enable an option to automatically login to the
desktop.
5. Then you have the option to choose a desktop environment. If you want to
create a custom setup with a window manager, you can select "No desktop".
::: {.tip}
If you don't have a favorite desktop and don't know which one to choose,
you can stick to either GNOME or Plasma. They have a quite different
design, so you should choose whichever you like better.
They are both popular choices and well tested on NixOS.
:::
6. You have the option to allow unfree software in the next screen.
7. The easiest option in the "Partitioning" screen is "Erase disk", which will
delete all data from the selected disk and install the system on it.
Also select "Swap (with Hibernation)" in the dropdown below it.
You have the option to encrypt the whole disk with LUKS.
::: {.note}
At the top left you see if the Installer was booted with BIOS or UEFI. If
you know your system supports UEFI and it shows "BIOS", reboot with the
correct option.
:::
::: {.warning}
Make sure you have selected the correct disk at the top and that no
valuable data is still on the disk! It will be deleted when
formatting the disk.
:::
8. Check the choices you made in the "Summary" and click "Install".
::: {.note}
The installation takes about 15 minutes. The time varies based on the
selected desktop environment, internet connection speed and disk write speed.
:::
9. When the install is complete, remove the USB flash drive and
reboot into your new system!
## Manual Installation {#sec-installation-manual}
NixOS can be installed on BIOS or UEFI systems. The procedure for a UEFI
installation is by and large the same as a BIOS installation. The
differences are mentioned in the steps that follow.
installation is broadly the same as for a BIOS installation. The differences
are mentioned in the following steps.
The installation media can be burned to a CD, or now more commonly,
"burned" to a USB drive (see [](#sec-booting-from-usb)).
The NixOS manual is available by running `nixos-help` in the command line
or from the application menu in the desktop environment.
The installation media contains a basic NixOS installation. When it's
finished booting, it should have detected most of your hardware.
The NixOS manual is available by running `nixos-help`.
To have access to the command line on the graphical images, open
Terminal (GNOME) or Konsole (Plasma) from the application menu.
You are logged-in automatically as `nixos`. The `nixos` user account has
an empty password so you can use `sudo` without a password:
```ShellSession
$ sudo -i
```
If you downloaded the graphical ISO image, you can run `systemctl
start display-manager` to start the desktop environment. If you want
to continue on the terminal, you can use `loadkeys` to switch to your
preferred keyboard layout. (We even provide neo2 via `loadkeys de
neo`!)
You can use `loadkeys` to switch to your preferred keyboard layout.
(We even provide neo2 via `loadkeys de neo`!)
If the text is too small to be legible, try `setfont ter-v32n` to
increase the font size.
@@ -33,7 +146,8 @@ To install over a serial port connect with `115200n8` (e.g.
`picocom -b 115200 /dev/ttyUSB0`). When the bootloader lists boot
entries, select the serial console boot entry.
### Networking in the installer {#sec-installation-booting-networking}
### Networking in the installer {#sec-installation-manual-networking}
[]{#sec-installation-booting-networking} <!-- legacy anchor -->
The boot process should have brought up networking (check `ip
a`). Networking is necessary for the installer, since it will
@@ -100,7 +214,8 @@ placed by mounting the image on a different machine). Alternatively you
must set a password for either `root` or `nixos` with `passwd` to be
able to login.
## Partitioning and formatting {#sec-installation-partitioning}
### Partitioning and formatting {#sec-installation-manual-partitioning}
[]{#sec-installation-partitioning} <!-- legacy anchor -->
The NixOS installer doesn't do any partitioning or formatting, so you
need to do that yourself.
@@ -112,7 +227,8 @@ below use `parted`, but also provides `fdisk`, `gdisk`, `cfdisk`, and
The recommended partition scheme differs depending if the computer uses
*Legacy Boot* or *UEFI*.
### UEFI (GPT) {#sec-installation-partitioning-UEFI}
#### UEFI (GPT) {#sec-installation-manual-partitioning-UEFI}
[]{#sec-installation-partitioning-UEFI} <!-- legacy anchor -->
Here\'s an example partition scheme for UEFI, using `/dev/sda` as the
device.
@@ -133,14 +249,14 @@ update /etc/fstab.
which will be used by the boot partition.
```ShellSession
# parted /dev/sda -- mkpart primary 512MiB -8GiB
# parted /dev/sda -- mkpart primary 512MB -8GB
```
3. Next, add a *swap* partition. The size required will vary according
to needs, here a 8GiB one is created.
to needs, here a 8GB one is created.
```ShellSession
# parted /dev/sda -- mkpart primary linux-swap -8GiB 100%
# parted /dev/sda -- mkpart primary linux-swap -8GB 100%
```
::: {.note}
@@ -153,14 +269,15 @@ update /etc/fstab.
reserved 512MiB at the start of the disk.
```ShellSession
# parted /dev/sda -- mkpart ESP fat32 1MiB 512MiB
# parted /dev/sda -- mkpart ESP fat32 1MB 512MB
# parted /dev/sda -- set 3 esp on
```
Once complete, you can follow with
[](#sec-installation-partitioning-formatting).
[](#sec-installation-manual-partitioning-formatting).
### Legacy Boot (MBR) {#sec-installation-partitioning-MBR}
#### Legacy Boot (MBR) {#sec-installation-manual-partitioning-MBR}
[]{#sec-installation-partitioning-MBR} <!-- legacy anchor -->
Here\'s an example partition scheme for Legacy Boot, using `/dev/sda` as
the device.
@@ -180,14 +297,14 @@ update /etc/fstab.
end part, where the swap will live.
```ShellSession
# parted /dev/sda -- mkpart primary 1MiB -8GiB
# parted /dev/sda -- mkpart primary 1MB -8GB
```
3. Finally, add a *swap* partition. The size required will vary
according to needs, here a 8GiB one is created.
```ShellSession
# parted /dev/sda -- mkpart primary linux-swap -8GiB 100%
# parted /dev/sda -- mkpart primary linux-swap -8GB 100%
```
::: {.note}
@@ -196,9 +313,10 @@ update /etc/fstab.
:::
Once complete, you can follow with
[](#sec-installation-partitioning-formatting).
[](#sec-installation-manual-partitioning-formatting).
### Formatting {#sec-installation-partitioning-formatting}
#### Formatting {#sec-installation-manual-partitioning-formatting}
[]{#sec-installation-partitioning-formatting} <!-- legacy anchor -->
Use the following commands:
@@ -233,7 +351,8 @@ Use the following commands:
- For creating software RAID devices, use `mdadm`.
## Installing {#sec-installation-installing}
### Installing {#sec-installation-manual-installing}
[]{#sec-installation-installing} <!-- legacy anchor -->
1. Mount the target file system on which NixOS should be installed on
`/mnt`, e.g.
@@ -394,7 +513,8 @@ Use the following commands:
You may also want to install some software. This will be covered in
[](#sec-package-management).
## Installation summary {#sec-installation-summary}
### Installation summary {#sec-installation-manual-summary}
[]{#sec-installation-summary} <!-- legacy anchor -->
To summarise, [Example: Commands for Installing NixOS on `/dev/sda`](#ex-install-sequence)
shows a typical sequence of commands for installing NixOS on an empty hard

View File

@@ -1,24 +1,21 @@
# Obtaining NixOS {#sec-obtaining}
NixOS ISO images can be downloaded from the [NixOS download
page](https://nixos.org/nixos/download.html). There are a number of
installation options. If you happen to have an optical drive and a spare
CD, burning the image to CD and booting from that is probably the
easiest option. Most people will need to prepare a USB stick to boot
from. [](#sec-booting-from-usb) describes the preferred method to
prepare a USB stick. A number of alternative methods are presented in
the [NixOS Wiki](https://nixos.wiki/wiki/NixOS_Installation_Guide#Making_the_installation_media).
page](https://nixos.org/download.html#nixos-iso). Follow the instructions in
[](#sec-booting-from-usb) to create a bootable USB flash drive.
If you have a very old system that can't boot from USB, you can burn the image
to an empty CD. NixOS might not work very well on such systems.
As an alternative to installing NixOS yourself, you can get a running
NixOS system through several other means:
- Using virtual appliances in Open Virtualization Format (OVF) that
can be imported into VirtualBox. These are available from the [NixOS
download page](https://nixos.org/nixos/download.html).
download page](https://nixos.org/download.html#nixos-virtualbox).
- Using AMIs for Amazon's EC2. To find one for your region and
instance type, please refer to the [list of most recent
AMIs](https://github.com/NixOS/nixpkgs/blob/master/nixos/modules/virtualisation/ec2-amis.nix).
- Using AMIs for Amazon's EC2. To find one for your region, please refer
to the [download page](https://nixos.org/download.html#nixos-amazon).
- Using NixOps, the NixOS-based cloud deployment tool, which allows
you to provision VirtualBox and EC2 NixOS instances from declarative

View File

@@ -6,7 +6,7 @@ expressions and associated binaries. The NixOS channels are updated
automatically from NixOS's Git repository after certain tests have
passed and all packages have been built. These channels are:
- *Stable channels*, such as [`nixos-21.11`](https://nixos.org/channels/nixos-21.11).
- *Stable channels*, such as [`nixos-22.05`](https://nixos.org/channels/nixos-22.05).
These only get conservative bug fixes and package upgrades. For
instance, a channel update may cause the Linux kernel on your system
to be upgraded from 4.19.34 to 4.19.38 (a minor bug fix), but not
@@ -19,7 +19,7 @@ passed and all packages have been built. These channels are:
radical changes between channel updates. It's not recommended for
production systems.
- *Small channels*, such as [`nixos-21.11-small`](https://nixos.org/channels/nixos-21.11-small)
- *Small channels*, such as [`nixos-22.05-small`](https://nixos.org/channels/nixos-22.05-small)
or [`nixos-unstable-small`](https://nixos.org/channels/nixos-unstable-small).
These are identical to the stable and unstable channels described above,
except that they contain fewer binary packages. This means they get updated
@@ -38,8 +38,8 @@ newest supported stable release.
When you first install NixOS, you're automatically subscribed to the
NixOS channel that corresponds to your installation source. For
instance, if you installed from a 21.11 ISO, you will be subscribed to
the `nixos-21.11` channel. To see which NixOS channel you're subscribed
instance, if you installed from a 22.05 ISO, you will be subscribed to
the `nixos-22.05` channel. To see which NixOS channel you're subscribed
to, run the following as root:
```ShellSession
@@ -54,16 +54,16 @@ To switch to a different NixOS channel, do
```
(Be sure to include the `nixos` parameter at the end.) For instance, to
use the NixOS 21.11 stable channel:
use the NixOS 22.05 stable channel:
```ShellSession
# nix-channel --add https://nixos.org/channels/nixos-21.11 nixos
# nix-channel --add https://nixos.org/channels/nixos-22.05 nixos
```
If you have a server, you may want to use the "small" channel instead:
```ShellSession
# nix-channel --add https://nixos.org/channels/nixos-21.11-small nixos
# nix-channel --add https://nixos.org/channels/nixos-22.05-small nixos
```
And if you want to live on the bleeding edge:
@@ -114,5 +114,5 @@ the new generation contains a different kernel, initrd or kernel
modules. You can also specify a channel explicitly, e.g.
```nix
system.autoUpgrade.channel = https://nixos.org/channels/nixos-21.11;
system.autoUpgrade.channel = https://nixos.org/channels/nixos-22.05;
```

View File

@@ -19,6 +19,7 @@ pandoc_flags=(
"--lua-filter=$DIR/../../../doc/build-aux/pandoc-filters/myst-reader/roles.lua"
"--lua-filter=$DIR/../../../doc/build-aux/pandoc-filters/link-unix-man-references.lua"
"--lua-filter=$DIR/../../../doc/build-aux/pandoc-filters/docbook-writer/rst-roles.lua"
"--lua-filter=$DIR/../../../doc/build-aux/pandoc-filters/docbook-writer/html-elements.lua"
"--lua-filter=$DIR/../../../doc/build-aux/pandoc-filters/docbook-writer/labelless-link-is-xref.lua"
-f "commonmark${pandoc_commonmark_enabled_extensions}+smart"
-t docbook

View File

@@ -1,4 +1,4 @@
# Release 22.05 (“Quokka”, 2022.05/??) {#sec-release-22.05}
# Release 22.05 (“Quokka”, 2022.05/30) {#sec-release-22.05}
- Support is planned until the end of December 2022, handing over to 22.11.
@@ -6,61 +6,59 @@
In addition to numerous new and upgraded packages, this release has the following highlights:
- The `firefox` browser on `x86_64-linux` is now making use of
profile-guided optimization resulting in a much more responsive
browsing experience.
- Nix has been updated from 2.3 to 2.8. This mainly brings experimental support
for Flakes, but also marks the `nix` command as experimental which now has to
be enabled via the configuration explicitly. For more information and
instructions for upgrades, see the
relase notes for [nix-2.4](https://nixos.org/manual/nix/stable/release-notes/rl-2.4.html),
[nix-2.5](https://nixos.org/manual/nix/stable/release-notes/rl-2.5.html),
[nix-2.6](https://nixos.org/manual/nix/stable/release-notes/rl-2.6.html),
[nix-2.7](https://nixos.org/manual/nix/stable/release-notes/rl-2.7.html) and
[nix-2.8](https://nixos.org/manual/nix/stable/release-notes/rl-2.8.html)
- `security.acme.defaults` has been added to simplify configuring
settings for many certificates at once. This also opens up the
the option to use DNS-01 validation when using `enableACME` on
web server virtual hosts (e.g. `services.nginx.virtualHosts.*.enableACME`).
- The `firefox` browser on `x86_64-linux` now makes use of profile-guided
optimisation, resulting in a much more responsive browsing experience.
- GNOME has been upgraded to 42. Please take a look at their [Release Notes](https://release.gnome.org/42/) for details. Notably, it replaces gedit with GNOME Text Editor, GNOME Terminal with GNOME Console (formerly Kings Cross), and GNOME Screenshot with a tool built into the Shell.
- GNOME has been upgraded to 42. Please take a look at their [Release
Notes](https://release.gnome.org/42/) for details. In particular, it replaces
gedit with GNOME Text Editor, GNOME Terminal with GNOME Console (formerly
King's Cross) and GNOME Screenshot by a tool integrated into the Shell.
- `stdenv.mkDerivation` now supports a self-referencing `finalAttrs:` parameter
containing the final `mkDerivation` arguments including overrides.
`drv.overrideAttrs` now supports two parameters `finalAttrs: previousAttrs:`.
This allows packaging configuration to be overridden in a consistent manner by
providing an alternative to `rec {}` syntax.
Additionally, `passthru` can now reference `finalAttrs.finalPackage` containing
the final package, including attributes such as the output paths and
`overrideAttrs`.
New language integrations can be simplified by overriding a "prototype"
package containing the language-specific logic. This removes the need for a
extra layer of overriding for the "generic builder" arguments, thus removing a
usability problem and source of error.
- PHP 8.1 is now available
- Mattermost has been updated to extended support release 6.3, as the previously packaged extended support release 5.37 is [reaching its end of life](https://docs.mattermost.com/upgrade/extended-support-release.html).
Migrations may take a while, see the [changelog](https://docs.mattermost.com/install/self-managed-changelog.html#release-v6-3-extended-support-release)
and [important upgrade notes](https://docs.mattermost.com/upgrade/important-upgrade-notes.html).
- PHP 8.1 is now available.
- systemd services can now set [systemd.services.\<name\>.reloadTriggers](#opt-systemd.services) instead of `reloadIfChanged` for a more granular distinction between reloads and restarts.
- Systemd has been upgraded to the version 250.
- Pulseaudio has been upgraded to version 15.0 and now optionally [supports additional Bluetooth audio codecs](https://www.freedesktop.org/wiki/Software/PulseAudio/Notes/15.0/#supportforldacandaptxbluetoothcodecsplussbcxqsbcwithhigher-qualityparameters) like aptX or LDAC, with codec switching support being available in `pavucontrol`. This feature is disabled by default but can be enabled by using `hardware.pulseaudio.package = pkgs.pulseaudioFull;`.
Existing 3rd party modules that provided similar functionality, like `pulseaudio-modules-bt` or `pulseaudio-hsphfpd` are deprecated and have been removed.
- Pulseaudio has been updated to version 15.0 and now optionally
[supports additional Bluetooth audio codecs](https://www.freedesktop.org/wiki/Software/PulseAudio/Notes/15.0/#supportforldacandaptxbluetoothcodecsplussbcxqsbcwithhigher-qualityparameters)
such as aptX or LDAC, with codec switching available in `pavucontrol`. This
feature is disabled by default, but can be enabled with the option
`hardware.pulseaudio.package = pkgs.pulseaudioFull;`. Existing third-party
modules that offered similar functions, such as `pulseaudio-modules-bt` or
`pulseaudio-hsphfpd`, are obsolete and have been removed.
- PostgreSQL now defaults to major version 14.
- The new [`postgresqlTestHook`](https://nixos.org/manual/nixpkgs/stable/#sec-postgresqlTestHook) runs a PostgreSQL server for the duration of package checks.
- [`kops`](https://kops.sigs.k8s.io) defaults to 1.22.4, which will enable [Instance Metadata Service Version 2](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-metadata-service.html) and require tokens on new clusters with Kubernetes 1.22. This will increase security by default, but may break some types of workloads. See the [release notes](https://kops.sigs.k8s.io/releases/1.22-notes/) for details.
- Module authors can use `mkRenamedOptionModuleWith` to automate the deprecation cycle without annoying out-of-tree module authors and their users.
- The default GHC version has been updated from 8.10.7 to 9.0.2. `pkgs.haskellPackages` and `pkgs.ghc` will now use this version by default.
- The GNOME and Plasma installation CDs now use `pkgs.calamares` and `pkgs.calamares-nixos-extensions` to allow users to easily install and set up NixOS with a GUI.
- `security.acme.defaults` has been added to simplify the configuration of
settings for many certificates at once. This also opens up the option to use
DNS-01 validation when using `enableACME` web server virtual hosts (e.g.
`services.nginx.virtualHosts.*.enableACME`).
## New Services {#sec-release-22.05-new-services}
- [1password](https://1password.com/), command-lines and graphic interface for 1Password. Available as [programs._1password](#opt-programs._1password.enable) and [programs._1password-gui](#opt-programs._1password.enable).
- [aesmd](https://github.com/intel/linux-sgx#install-the-intelr-sgx-psw), the Intel SGX Architectural Enclave Service Manager. Available as [services.aesmd](#opt-services.aesmd.enable).
- [agate](https://github.com/mbrubeck/agate), a very simple server for the Gemini hypertext protocol. Available as [services.agate](#opt-services.agate.enable).
- [rootless Docker](https://docs.docker.com/engine/security/rootless/), a `systemd --user` Docker service which runs without root permissions. Available as [virtualisation.docker.rootless.enable](options.html#opt-virtualisation.docker.rootless.enable).
- [matrix-conduit](https://conduit.rs/), a simple, fast and reliable chat server powered by matrix. Available as [services.matrix-conduit](option.html#opt-services.matrix-conduit.enable).
@@ -71,79 +69,115 @@ In addition to numerous new and upgraded packages, this release has the followin
- [apfs](https://github.com/linux-apfs/linux-apfs-rw), a kernel module for mounting the Apple File System (APFS).
- [FRRouting](https://frrouting.org/), a popular suite of Internet routing protocol daemons (BGP, BFD, OSPF, IS-IS, VRRP and others). Available as [services.frr](#opt-services.frr.babel.enable)
- [ArchiSteamFarm](https://github.com/JustArchiNET/ArchiSteamFarm), a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Available as [services.archisteamfarm](#opt-services.archisteamfarm.enable).
- [heisenbridge](https://github.com/hifi/heisenbridge), a bouncer-style Matrix IRC bridge. Available as [services.heisenbridge](options.html#opt-services.heisenbridge.enable).
- [BaGet](https://loic-sharma.github.io/BaGet/), a lightweight NuGet and symbol server. Available at [services.baget](#opt-services.baget.enable).
- [snowflake-proxy](https://snowflake.torproject.org/), a system to defeat internet censorship. Available as [services.snowflake-proxy](options.html#opt-services.snowflake-proxy.enable).
- [blocky](https://0xerr0r.github.io/blocky/), fast and lightweight DNS proxy as ad-blocker for local network with many features. Available as [services.blocky](#opt-services.blocky.enable).
- [r53-ddns](https://github.com/fleaz/r53-ddns), a small tool to run your own DDNS service via AWS Route53. Available as [services.r53-ddns](options.html#opt-services.r53-ddns.enable).
- [cloudflare-dyndns](https://github.com/kissgyorgy/cloudflare-dyndns), CloudFlare Dynamic DNS client. Available as [services.cloudflare-dyndns](#opt-services.cloudflare-dyndns.enable).
- [ergochat](https://ergo.chat), a modern IRC with IRCv3 features. Available as [services.ergochat](options.html#opt-services.ergochat.enable).
- [Corosync](https://corosync.github.io/corosync/) and [Pacemaker](https://clusterlabs.org/pacemaker/), A open-source high availability resource manager. Available as [services.corosync](#opt-services.corosync.enable) and [services.pacemaker](#opt-services.pacemaker.enable).
- [Snipe-IT](https://snipeitapp.com), a free open source IT asset/license management system. Available as [services.snipe-it](options.html#opt-services.snipe-it.enable).
- [create_ap](https://github.com/lakinduakash/linux-wifi-hotspot), a module for creating wifi hotspots using the program linux-wifi-hotspot. Available as [services.create_ap](#opt-services.create_ap.enable).
- [PowerDNS-Admin](https://github.com/ngoduykhanh/PowerDNS-Admin), a web interface for the PowerDNS server. Available at [services.powerdns-admin](options.html#opt-services.powerdns-admin.enable).
- [Envoy](https://www.envoyproxy.io/), a high-performance reverse proxy. Available as [services.envoy](#opt-services.envoy.enable).
- [pgadmin4](https://github.com/postgres/pgadmin4), an admin interface for the PostgreSQL database. Available at [services.pgadmin](options.html#opt-services.pgadmin.enable).
- [ergochat](https://ergo.chat), a modern IRC with IRCv3 features. Available as [services.ergochat](#opt-services.ergochat.enable).
- [input-remapper](https://github.com/sezanzeb/input-remapper), an easy to use tool to change the mapping of your input device buttons. Available at [services.input-remapper](options.html#opt-services.input-remapper.enable).
- [ethercalc](https://github.com/audreyt/ethercalc), an online collaborative spreadsheet. Available as [services.ethercalc](#opt-services.ethercalc.enable).
- [InvoicePlane](https://invoiceplane.com), web application for managing and creating invoices. Available at [services.invoiceplane](options.html#opt-services.invoiceplane.enable).
- [filebeat](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-overview.html), a lightweight shipper for forwarding and centralizing log data. Available as [services.filebeat](#opt-services.filebeat.enable).
- [maddy](https://maddy.email), a composable all-in-one mail server. Available as [services.maddy](options.html#opt-services.maddy.enable).
- [FRRouting](https://frrouting.org/), a popular suite of Internet routing protocol daemons (BGP, BFD, OSPF, IS-IS, VRRP and others). Available as [services.frr](#opt-services.frr.babel.enable).
- [K40-Whisperer](https://www.scorchworks.com/K40whisperer/k40whisperer.html), a program to control cheap Chinese laser cutters. Available as [programs.k40-whisperer.enable](options.html#opt-programs.k4-whisperer.enable). Users must add themselves to the `k40` group to be able to access the device.
- [Grafana Mimir](https://grafana.com/oss/mimir/), an open source, horizontally scalable, highly available, multi-tenant, long-term storage for Prometheus. Available as [services.mimir](#opt-services.mimir.enable).
- [mozillavpn](https://github.com/mozilla-mobile/mozilla-vpn-client), the client for the [Mozilla VPN](https://vpn.mozilla.org/) service. Available as [services.mozillavpn](options.html#opt-services.mozillavpn).
- [Haste](https://hastebin.com/about.md), a pastebin written in node.js. Available as [services.haste](#opt-services.haste-server.enable).
- [mtr-exporter](https://github.com/mgumz/mtr-exporter), a Prometheus exporter for mtr metrics. Available as [services.mtr-exporter](options.html#opt-services.mtr-exporter.enable).
- [headscale](https://github.com/juanfont/headscale), an Open Source implementation of the [Tailscale](https://tailscale.io) Control Server. Available as [services.headscale](#opt-services.headscale.enable).
- [prometheus-pve-exporter](https://github.com/prometheus-pve/prometheus-pve-exporter), a tool that exposes information from the Proxmox VE API for use by Prometheus. Available as [services.prometheus.exporters.pve](options.html#opt-services.prometheus.exporters.pve).
- [heisenbridge](https://github.com/hifi/heisenbridge), a bouncer-style Matrix IRC bridge. Available as [services.heisenbridge](#opt-services.heisenbridge.enable).
- [netbox](https://github.com/netbox-community/netbox), infrastructure resource modeling (IRM) tool. Available as [services.netbox](options.html#opt-services.netbox.enable).
- [https-dns-proxy](https://github.com/aarond10/https_dns_proxy), DNS to DNS over HTTPS (DoH) proxy. Available as [services.https-dns-proxy](#opt-services.https-dns-proxy.enable).
- [input-remapper](https://github.com/sezanzeb/input-remapper), an easy to use tool to change the mapping of your input device buttons. Available at [services.input-remapper](#opt-services.input-remapper.enable).
- [InvoicePlane](https://invoiceplane.com), web application for managing and creating invoices. Available at [services.invoiceplane](#opt-services.invoiceplane.sites._name_.enable).
- [k3b](https://userbase.kde.org/K3b), the KDE disk burning application. Available as [programs.k3b](#opt-programs.k3b.enable).
- [K40-Whisperer](https://www.scorchworks.com/K40whisperer/k40whisperer.html), a program to control cheap Chinese laser cutters. Available as [programs.k40-whisperer.enable](#opt-programs.k40-whisperer.enable). Users must add themselves to the `k40` group to be able to access the device.
- [kanidm](https://kanidm.github.io/kanidm/stable/), an identity management server written in Rust. Available as [services.kanidm](#opt-services.kanidm.enableServer)
- [maddy](https://maddy.email), a composable all-in-one mail server. Available as [services.maddy](#opt-services.maddy.enable).
- [Maddy](https://maddy.email/), a free an open source mail server. Availabe as [services.maddy](#opt-services.maddy.enable).
- [matrix-conduit](https://conduit.rs/), a simple, fast and reliable chat server powered by matrix. Available as [services.matrix-conduit](option.html#opt-services.matrix-conduit.enable).
- [Moosefs](https://moosefs.com), fault tolerant petabyte distributed file system. Available as [moosefs](#opt-services.moosefs.master.enable).
- [mozillavpn](https://github.com/mozilla-mobile/mozilla-vpn-client), the client for the [Mozilla VPN](https://vpn.mozilla.org/) service. Available as [services.mozillavpn](#opt-services.mozillavpn.enable).
- [mtr-exporter](https://github.com/mgumz/mtr-exporter), a Prometheus exporter for mtr metrics. Available as [services.mtr-exporter](#opt-services.mtr-exporter.enable).
- [nbd](https://nbd.sourceforge.io/), a Network Block Device server. Available as [services.nbd](#opt-services.nbd.server.enable).
- [netbox](https://github.com/netbox-community/netbox), infrastructure resource modeling (IRM) tool. Available as [services.netbox](#opt-services.netbox.enable).
- [nethoscope](https://github.com/vvilhonen/nethoscope), listen to your network traffic. Available as [programs.nethoscope](#opt-programs.nethoscope.enable).
- [nifi](https://nifi.apache.org), an easy to use, powerful, and reliable system to process and distribute data. Available as [services.nifi](#opt-services.nifi.enable).
- [nix-ld](https://github.com/Mic92/nix-ld), Run unpatched dynamic binaries on NixOS. Available as [programs.nix-ld](#opt-programs.nix-ld.enable).
- [NNCP](http://www.nncpgo.org), NNCP (Node to Node copy) utilities and configuration, Available as [programs.nncp](#opt-programs.nncp.enable).
- [pgadmin4](https://github.com/postgres/pgadmin4), an admin interface for the PostgreSQL database. Available at [services.pgadmin](#opt-services.pgadmin.enable).
- [PowerDNS-Admin](https://github.com/ngoduykhanh/PowerDNS-Admin), a web interface for the PowerDNS server. Available at [services.powerdns-admin](#opt-services.powerdns-admin.enable).
- [prometheus-pve-exporter](https://github.com/prometheus-pve/prometheus-pve-exporter), a tool that exposes information from the Proxmox VE API for use by Prometheus. Available as [services.prometheus.exporters.pve](#opt-services.prometheus.exporters.pve.enable).
- [prosody-filer](https://github.com/ThomasLeister/prosody-filer), a server for handling XMPP HTTP Upload requests. Available at [services.prosody-filer](#opt-services.prosody-filer.enable).
- [Public Inbox](https://public-inbox.org), an "archives first" approach to mailing lists. Available as [services.public-inbox](#opt-services.public-inbox.enable).
- [r53-ddns](https://github.com/fleaz/r53-ddns), a small tool to run your own DDNS service via AWS Route53. Available as [services.r53-ddns](#opt-services.r53-ddns.enable).
- [rmfakecloud](https://ddvk.github.io/rmfakecloud/), a clone of the cloud sync the remarkable tablet. Available as [services.rmfakecloud](#opt-services.rmfakecloud.enable).
- [rootless Docker](https://docs.docker.com/engine/security/rootless/), a `systemd --user` Docker service which runs without root permissions. Available as [virtualisation.docker.rootless.enable](options.html#opt-virtualisation.docker.rootless.enable).
- [rstudio-server](https://www.rstudio.com/products/rstudio/#rstudio-server), a browser-based version of the RStudio IDE for the R programming language. Available as [services.rstudio-server](#opt-services.rstudio-server.enable).
- [rtsp-simple-server](https://github.com/aler9/rtsp-simple-server), ready-to-use RTSP / RTMP / HLS server and proxy that allows to read, publish and proxy video and audio streams. Available as [services.rtsp-simple-server](#opt-services.rtsp-simple-server.enable).
- [Snipe-IT](https://snipeitapp.com), a free open source IT asset/license management system. Available as [services.snipe-it](#opt-services.snipe-it.enable).
- [snowflake-proxy](https://snowflake.torproject.org/), a system to defeat internet censorship. Available as [services.snowflake-proxy](#opt-services.snowflake-proxy.enable).
- [sslmate-agent](https://sslmate.com/), a daemon for managing SSL/TLS certificates on a server. Available as [services.sslmate-agent](services.sslmate-agent.enable).
- [starship](https://starship.rs), a minimal, blazing-fast, and infinitely customizable prompt for any shell. Available at [programs.startship](#opt-programs.starship.enable).
- [systembus-notify](https://github.com/rfjakob/systembus-notify), allow system level notifications to reach the users. Available as [services.systembus-notify](opt-services.systembus-notify.enable). Please keep in mind that this service should only be enabled on machines with fully trusted users, as any local user is able to DoS user sessions by spamming notifications.
- [teleport](https://goteleport.com), allows engineers and security professionals to unify access for SSH servers, Kubernetes clusters, web applications, and databases across all environments. Available at [services.teleport](#opt-services.teleport.enable).
- [tetrd](https://tetrd.app), share your internet connection from your device to your PC and vice versa through a USB cable. Available at [services.tetrd](#opt-services.tetrd.enable).
- [uptermd](https://upterm.dev), an open-source solution for sharing terminal sessions instantly over the public internet via secure tunnels. Available at [services.uptermd](#opt-services.uptermd.enable).
- [agate](https://github.com/mbrubeck/agate), a very simple server for the Gemini hypertext protocol. Available as [services.agate](options.html#opt-services.agate.enable).
- [usbrelayd](https://github.com/darrylb123/usbrelay), an USB Relay MQTT daemon. Available as [services.usbrelayd](#opt-services.usbrelayd.enable).
- [ArchiSteamFarm](https://github.com/JustArchiNET/ArchiSteamFarm), a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Available as [services.archisteamfarm](options.html#opt-services.archisteamfarm.enable).
- [webdav-server-rs](https://github.com/miquels/webdav-server-rs), Webdav server in rust. Available as [services.webdav-server-rs](#opt-services.webdav-server-rs.enable).
- [teleport](https://goteleport.com), allows engineers and security professionals to unify access for SSH servers, Kubernetes clusters, web applications, and databases across all environments. Available at [services.teleport](#opt-services.teleport.enable).
- [wg-netmanager](https://github.com/gin66/wg_netmanager), the Wireguard network manager. Available as [services.wg-netmanager](#opt-services.wg-netmanager.enable).
- [BaGet](https://loic-sharma.github.io/BaGet/), a lightweight NuGet and symbol server. Available at [services.baget](#opt-services.baget.enable).
- [moosefs](https://moosefs.com), fault tolerant petabyte distributed file system.
Available as [moosefs](#opt-services.moosefs.client.enable).
- [prosody-filer](https://github.com/ThomasLeister/prosody-filer), a server for handling XMPP HTTP Upload requests. Available at [services.prosody-filer](#opt-services.prosody-filer.enable).
- [systembus-notify](https://github.com/rfjakob/systembus-notify), allow system level notifications to reach the users. Available as [services.systembus-notify](opt-services.systembus-notify.enable). Please keep in mind that this service should only be enabled on machines with fully trusted users, as any local user is able to DoS user sessions by spamming notifications.
- [ethercalc](https://github.com/audreyt/ethercalc), an online collaborative
spreadsheet. Available as [services.ethercalc](options.html#opt-services.ethercalc.enable).
- [nbd](https://nbd.sourceforge.io/), a Network Block Device server. Available as [services.nbd](options.html#opt-services.nbd.server.enable).
- [nix-ld](https://github.com/Mic92/nix-ld), Run unpatched dynamic binaries on NixOS. Available as [programs.nix-ld](options.html#opt-programs.nix-ld.enable).
- [timetagger](https://timetagger.app), an open source time-tracker with an intuitive user experience and powerful reporting. [services.timetagger](options.html#opt-services.timetagger.enable).
- [rstudio-server](https://www.rstudio.com/products/rstudio/#rstudio-server), a browser-based version of the RStudio IDE for the R programming language. Available as [services.rstudio-server](options.html#opt-services.rstudio-server.enable).
- [headscale](https://github.com/juanfont/headscale), an Open Source implementation of the [Tailscale](https://tailscale.io) Control Server. Available as [services.headscale](options.html#opt-services.headscale.enable)
- [create_ap](https://github.com/lakinduakash/linux-wifi-hotspot), a module for creating wifi hotspots using the program linux-wifi-hotspot. Available as [services.create_ap](options.html#opt-services.create_ap.enable).
- [blocky](https://0xerr0r.github.io/blocky/), fast and lightweight DNS proxy as ad-blocker for local network with many features.
- [pacemaker](https://clusterlabs.org/pacemaker/) cluster resource manager
- [nifi](https://nifi.apache.org), an easy to use, powerful, and reliable system to process and distribute data. Available as [services.nifi](options.html#opt-services.nifi.enable).
- [kanidm](https://kanidm.github.io/kanidm/stable/), an identity management server written in Rust.
- [Zammad](https://zammad.org/), a web-based, open source user support/ticketing solution. Available as [services.zammad](#opt-services.zammad.enable).
<!-- To avoid merge conflicts, consider adding your item at an arbitrary place in the list instead. -->
@@ -169,7 +203,7 @@ In addition to numerous new and upgraded packages, this release has the followin
- The update of the haskell package set brings with it a new version of the `xmonad`
module, which will break your configuration if you use `launch` as entrypoint. The
example code the corresponding nixos module was adjusted, you way want to have a look at it.
example code the corresponding nixos module was adjusted, you may want to have a look at it.
- The `home-assistant` module now requires users that don't want their
configuration to be managed declaratively to set
@@ -250,6 +284,8 @@ In addition to numerous new and upgraded packages, this release has the followin
- `openldap` (and therefore the slapd LDAP server) were updated to version 2.6.2. The project introduced backwards-incompatible changes, namely the removal of the bdb, hdb, ndb, and shell backends in slapd. Therefore before updating, dump your database `slapcat -n 1` in LDIF format, and reimport it after updating your `services.openldap.settings`, which represents your `cn=config`.
Additionally with 2.5 the argon2 module was included in the standard distrubtion and renamed from `pw-argon2` to `argon2`. Remember to update your `olcModuleLoad` entry in `cn=config`.
- `openssh` has been update to 8.9p1, changing the FIDO security key middleware interface.
- `git` no longer hardcodes the path to openssh' ssh binary to reduce the amount of rebuilds. If you are using git with ssh remotes and do not have a ssh binary in your enviroment consider adding `openssh` to it or switching to `gitFull`.
@@ -368,13 +404,13 @@ In addition to numerous new and upgraded packages, this release has the followin
};
extraConfigFiles = [
/run/keys/matrix-synapse/secrets.yaml
"/run/keys/matrix-synapse/secrets.yaml"
];
};
}
```
The secrets in your original config should be migrated into a YAML file that is included via `extraConfigFiles`.
The secrets in your original config should be migrated into a YAML file that is included via `extraConfigFiles`. The filename must be quoted to prevent nix from copying it to the (world readable) store.
Additionally a few option defaults have been synced up with upstream default values, for example the `max_upload_size` grew from `10M` to `50M`. For the same reason, the default
`media_store_path` was changed from `${dataDir}/media` to `${dataDir}/media_store` if `system.stateVersion` is at least `22.05`. Files will need to be manually moved to the new
@@ -551,7 +587,15 @@ In addition to numerous new and upgraded packages, this release has the followin
- The `miller` package has been upgraded from 5.10.3 to [6.2.0](https://github.com/johnkerl/miller/releases/tag/v6.2.0). See [What's new in Miller 6](https://miller.readthedocs.io/en/latest/new-in-miller-6).
- MultiMC has been replaced with the fork PolyMC due to upstream developers being hostile to 3rd party package maintainers. PolyMC removes all MultiMC branding and is aimed at providing proper 3rd party packages like the one contained in Nixpkgs. This change affects the data folder where game instances and other save and configuration files are stored. Users with existing installations should rename `~/.local/share/multimc` to `~/.local/share/polymc`. The main config file's path has also moved from `~/.local/share/multimc/multimc.cfg` to `~/.local/share/polymc/polymc.cfg`.
- MultiMC has been replaced with the fork PrismLauncher due to upstream
developers being hostile to 3rd party package maintainers. PrismLauncher
removes all MultiMC branding and is aimed at providing proper 3rd party
packages like the one contained in Nixpkgs. This change affects the data
folder where game instances and other save and configuration files are stored.
Users with existing installations should rename `~/.local/share/multimc` to
`~/.local/share/PrismLauncher`. The main config file's path has also moved
from `~/.local/share/multimc/multimc.cfg` to
`~/.local/share/PrismLauncher/prismlauncher.cfg`.
- `systemd-nspawn@.service` settings have been reverted to the default systemd behaviour. User namespaces are now activated by default. If you want to keep running nspawn containers without user namespaces you need to set `systemd.nspawn.<name>.execConfig.PrivateUsers = false`
@@ -705,6 +749,13 @@ In addition to numerous new and upgraded packages, this release has the followin
- The configuration portion of the `nix-daemon` module has been reworked and exposed as [nix.settings](options.html#opt-nix-settings):
* Legacy options have been mapped to the corresponding options under under [nix.settings](options.html#opt-nix.settings) and will be deprecated when NixOS 21.11 reaches end of life.
* [nix.buildMachines.publicHostKey](options.html#opt-nix.buildMachines.publicHostKey) has been added.
- [`kops`](https://kops.sigs.k8s.io) defaults to 1.23.2, which will enable [Instance Metadata Service Version 2](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-metadata-service.html) and require tokens on new clusters with Kubernetes >= 1.22. This will increase security by default, but may break some types of workloads. The default behaviour for `spec.kubeDNS.nodeLocalDNS.forwardToKubeDNS` has changed from `true` to `false`. Cilium now has `disable-cnp-status-updates: true` by default. Set this to false if you rely on the CiliumNetworkPolicy status fields. Support for Kubernetes 1.17, the Lyft CNI, Weave CNI on Kubernetes >= 1.23, CentOS 7 and 8, Debian 9, RHEL 7, and Ubuntu 16.05 (Xenial) has been removed. See the [1.22 release notes](https://kops.sigs.k8s.io/releases/1.22-notes/) and [1.23 release notes](https://kops.sigs.k8s.io/releases/1.23-notes/) for more details, including other significant changes.
- Mattermost has been upgraded to extended support version 6.3 as the previously
packaged extended support version 5.37 is [reaching end of life](https://docs.mattermost.com/upgrade/extended-support-release.html).
Migration may take some time, see the [changelog](https://docs.mattermost.com/install/self-managed-changelog.html#release-v6-3-extended-support-release)
and [important upgrade notes](https://docs.mattermost.com/upgrade/important-upgrade-notes.html).
- The `writers.writePyPy2`/`writers.writePyPy3` and corresponding `writers.writePyPy2Bin`/`writers.writePyPy3Bin` convenience functions to create executable Python 2/3 scripts using the PyPy interpreter were added.
@@ -730,6 +781,17 @@ In addition to numerous new and upgraded packages, this release has the followin
redis-cli save
cp /var/lib/redis/dump.rdb "/var/lib/redis-mastodon/dump.rdb"
```
- Peertube now uses services.redis.servers to start a new redis server, instead of using a global redis server.
This improves compatibility with other services that use redis.
Redis database is used for storage only cache and job queue. More information can be found here - [Peertube architecture](https://docs.joinpeertube.org/contribute-architecture).
If you do want to save the redis database, you can use the following commands before upgrade OS:
```bash
redis-cli save
sudo mkdir /var/lib/redis-peertube
sudo cp /var/lib/redis/dump.rdb /var/lib/redis-peertube/dump.rdb
```
- If you are using Wayland you can choose to use the Ozone Wayland support
in Chrome and several Electron apps by setting the environment variable
@@ -797,7 +859,6 @@ In addition to numerous new and upgraded packages, this release has the followin
If you are using only a window manager without a desktop manager, you need to enable
`services.xserver.desktopManager.runXdgAutostartIfNone` or using the `dex` package to make `fcitx5` work.
- A new module was added for the Envoy reverse proxy, providing the options `services.envoy.enable` and `services.envoy.settings`.
- The option `services.duplicati.dataDir` has been added to allow changing the location of duplicati's files.
@@ -843,9 +904,6 @@ In addition to numerous new and upgraded packages, this release has the followin
- The default value for `programs.spacefm.settings.graphical_su` got unset. It previously pointed to `gksu` which has been removed.
- A new module was added for the [Starship](https://starship.rs/) shell prompt,
providing the options `programs.starship.enable` and `programs.starship.settings`.
- The [Dino](https://dino.im) XMPP client was updated to 0.3, adding support for audio and video calls.
- `services.mattermost.plugins` has been added to allow the declarative installation of Mattermost plugins.
@@ -905,9 +963,13 @@ In addition to numerous new and upgraded packages, this release has the followin
- The `nss` package was split into `nss_esr` and `nss_latest`, with `nss` being an alias for `nss_esr`. This was done to ease maintenance of `nss` and dependent high-profile packages like `firefox`.
- The default `scribus` version is now 1.5, while version 1.4 is still available as `scribus_1_4` ([#172700](https://github.com/NixOS/nixpkgs/pull/172700)).
- The Nextcloud module now supports to create a Mysql database automatically
with `services.nextcloud.database.createLocally` enabled.
- Matrix Synapse now requires entries in the `state_group_edges` table to be unique, in order to prevent accidentally introducing duplicate information (for example, because a database backup was restored multiple times). If your Synapse database already has duplicate rows in this table, this could fail with an error and require manual remediation.
- The Nextcloud module now allows setting the value of the `max-age` directive of the `Strict-Transport-Security` HTTP header, which is now controlled by the `services.nextcloud.https` option, rather than `services.nginx.recommendedHttpHeaders`.
- The `spark3` package has been updated from 3.1.2 to 3.2.1 ([#160075](https://github.com/NixOS/nixpkgs/pull/160075)):
@@ -915,8 +977,6 @@ In addition to numerous new and upgraded packages, this release has the followin
- Testing has been enabled for `aarch64-linux` in addition to `x86_64-linux`.
- The `spark3` package is now usable on `aarch64-darwin` as a result of [#158613](https://github.com/NixOS/nixpkgs/pull/158613) and [#158992](https://github.com/NixOS/nixpkgs/pull/158992).
- The `programs.nncp` options were added for generating host-global NNCP configuration.
- The option `services.snapserver.openFirewall` will no longer default to
`true` starting with NixOS 22.11. Enable it explicitly if you need to control
Snapserver remotely or connect streamig clients from other hosts.
@@ -927,5 +987,24 @@ In addition to numerous new and upgraded packages, this release has the followin
or `wl*` with priority 99 (which means that it doesn't have any effect if such an interface is matched
by a `.network-`unit with a lower priority). In case of scripted networking, no behavior
was changed.
- The new [`postgresqlTestHook`](https://nixos.org/manual/nixpkgs/stable/#sec-postgresqlTestHook) runs a PostgreSQL server for the duration of package checks.
- `zfs` was updated from 2.1.4 to 2.1.5, enabling it to be used with Linux kernel 5.18.
- `stdenv.mkDerivation` now supports a self-referencing `finalAttrs:` parameter
containing the final `mkDerivation` arguments including overrides.
`drv.overrideAttrs` now supports two parameters `finalAttrs: previousAttrs:`.
This allows packaging configuration to be overridden in a consistent manner by
providing an alternative to `rec {}` syntax.
Additionally, `passthru` can now reference `finalAttrs.finalPackage` containing
the final package, including attributes such as the output paths and
`overrideAttrs`.
New language integrations can be simplified by overriding a "prototype"
package containing the language-specific logic. This removes the need for a
extra layer of overriding for the "generic builder" arguments, thus removing a
usability problem and source of error.
<!-- To avoid merge conflicts, consider adding your item at an arbitrary place in the list instead. -->

View File

@@ -3,7 +3,7 @@ import sys
options = json.load(sys.stdin)
for (name, value) in options.items():
print('##', name.replace('<', '\\<').replace('>', '\\>'))
print('##', name.replace('<', '&lt;').replace('>', '&gt;'))
print(value['description'])
print()
if 'type' in value:

View File

@@ -213,6 +213,23 @@
<xsl:template match="attr[@name = 'declarations' or @name = 'definitions']">
<simplelist>
<!--
Example:
opt.declarations = [ { name = "foo/bar.nix"; url = "https://github.com/....."; } ];
-->
<xsl:for-each select="list/attrs[attr[@name = 'name']]">
<member><filename>
<xsl:if test="attr[@name = 'url']">
<xsl:attribute name="xlink:href"><xsl:value-of select="attr[@name = 'url']/string/@value"/></xsl:attribute>
</xsl:if>
<xsl:value-of select="attr[@name = 'name']/string/@value"/>
</filename></member>
</xsl:for-each>
<!--
When the declarations/definitions are raw strings,
fall back to hardcoded location logic, specific to Nixpkgs.
-->
<xsl:for-each select="list/string">
<member><filename>
<!-- Hyperlink the filename either to the NixOS Subversion

View File

@@ -65,7 +65,7 @@ let
${fcBool cfg.hinting.autohint}
</edit>
<edit mode="append" name="hintstyle">
<const>hintslight</const>
<const>${cfg.hinting.style}</const>
</edit>
<edit mode="append" name="antialias">
${fcBool cfg.antialias}
@@ -226,7 +226,6 @@ in
(mkRenamedOptionModule [ "fonts" "fontconfig" "ultimate" "useEmbeddedBitmaps" ] [ "fonts" "fontconfig" "useEmbeddedBitmaps" ])
(mkRenamedOptionModule [ "fonts" "fontconfig" "ultimate" "forceAutohint" ] [ "fonts" "fontconfig" "forceAutohint" ])
(mkRenamedOptionModule [ "fonts" "fontconfig" "ultimate" "renderMonoTTFAsBitmap" ] [ "fonts" "fontconfig" "renderMonoTTFAsBitmap" ])
(mkRemovedOptionModule [ "fonts" "fontconfig" "hinting" "style" ] "")
(mkRemovedOptionModule [ "fonts" "fontconfig" "forceAutohint" ] "")
(mkRemovedOptionModule [ "fonts" "fontconfig" "renderMonoTTFAsBitmap" ] "")
(mkRemovedOptionModule [ "fonts" "fontconfig" "dpi" ] "Use display server-specific options")
@@ -349,6 +348,20 @@ in
fonts, but better than unhinted fonts.
'';
};
style = mkOption {
type = types.enum [ "hintnone" "hintslight" "hintmedium" "hintfull" ];
default = "hintslight";
description = ''
Hintstyle is the amount of font reshaping done to line up
to the grid.
hintslight will make the font more fuzzy to line up to the grid
but will be better in retaining font shape, while hintfull will
be a crisp font that aligns well to the pixel grid but will lose
a greater amount of font shape.
'';
};
};
includeUserConf = mkOption {

View File

@@ -10,12 +10,12 @@ with lib;
i18n = {
glibcLocales = mkOption {
type = types.path;
default = pkgs.buildPackages.glibcLocales.override {
default = pkgs.glibcLocales.override {
allLocales = any (x: x == "all") config.i18n.supportedLocales;
locales = config.i18n.supportedLocales;
};
defaultText = literalExpression ''
pkgs.buildPackages.glibcLocales.override {
pkgs.glibcLocales.override {
allLocales = any (x: x == "all") config.i18n.supportedLocales;
locales = config.i18n.supportedLocales;
}

View File

@@ -1,4 +1,4 @@
{ config, lib, ... }:
{ config, lib, pkgs, ... }:
with lib;
{
@@ -23,6 +23,12 @@ with lib;
"/share/pixmaps"
];
environment.systemPackages = [
# Empty icon theme that contains index.theme file describing directories
# where toolkits should look for icons installed by apps.
pkgs.hicolor-icon-theme
];
# libXcursor looks for cursors in XCURSOR_PATH
# it mostly follows the spec for icons
# See: https://www.x.org/releases/current/doc/man/man3/Xcursor.3.xhtml Themes

View File

@@ -361,10 +361,9 @@ in
services.udev.extraRules =
''
# Create /dev/nvidia-uvm when the nvidia-uvm module is loaded.
KERNEL=="nvidia", RUN+="${pkgs.runtimeShell} -c 'mknod -m 666 /dev/nvidiactl c 195 255'"
KERNEL=="nvidia_modeset", RUN+="${pkgs.runtimeShell} -c 'mknod -m 666 /dev/nvidia-modeset c 195 254'"
KERNEL=="card*", SUBSYSTEM=="drm", DRIVERS=="nvidia", PROGRAM="${pkgs.gnugrep}/bin/grep 'Device Minor:' /proc/driver/nvidia/gpus/%b/information", \
RUN+="${pkgs.runtimeShell} -c 'mknod -m 666 /dev/nvidia%c{3} c 195 %c{3}"
KERNEL=="nvidia", RUN+="${pkgs.runtimeShell} -c 'mknod -m 666 /dev/nvidiactl c $$(grep nvidia-frontend /proc/devices | cut -d \ -f 1) 255'"
KERNEL=="nvidia", RUN+="${pkgs.runtimeShell} -c 'for i in $$(cat /proc/driver/nvidia/gpus/*/information | grep Minor | cut -d \ -f 4); do mknod -m 666 /dev/nvidia$${i} c $$(grep nvidia-frontend /proc/devices | cut -d \ -f 1) $${i}; done'"
KERNEL=="nvidia_modeset", RUN+="${pkgs.runtimeShell} -c 'mknod -m 666 /dev/nvidia-modeset c $$(grep nvidia-frontend /proc/devices | cut -d \ -f 1) 254'"
KERNEL=="nvidia_uvm", RUN+="${pkgs.runtimeShell} -c 'mknod -m 666 /dev/nvidia-uvm c $$(grep nvidia-uvm /proc/devices | cut -d \ -f 1) 0'"
KERNEL=="nvidia_uvm", RUN+="${pkgs.runtimeShell} -c 'mknod -m 666 /dev/nvidia-uvm-tools c $$(grep nvidia-uvm /proc/devices | cut -d \ -f 1) 1'"
'' + optionalString cfg.powerManagement.finegrained ''

View File

@@ -15,7 +15,8 @@ in
# https://wiki.archlinux.org/index.php/Gamepad#Connect_Xbox_Wireless_Controller_with_Bluetooth
extraModprobeConfig =
mkIf
config.hardware.bluetooth.enable
(config.hardware.bluetooth.enable &&
(lib.versionOlder config.boot.kernelPackages.kernel.version "5.12"))
"options bluetooth disable_ertm=1";
extraModulePackages = with config.boot.kernelPackages; [ xpadneo ];

View File

@@ -67,7 +67,7 @@ in
programs.dconf.packages = [ ibusPackage ];
services.dbus.packages = [
ibusAutostart
ibusPackage
];
environment.variables = {

View File

@@ -18,7 +18,8 @@
extraGSettingsOverrides = ''
[org.gnome.shell]
welcome-dialog-last-shown-version='9999999999'
[org.gnome.desktop.session]
idle-delay=0
[org.gnome.settings-daemon.plugins.power]
sleep-inactive-ac-type='nothing'
sleep-inactive-battery-type='nothing'

View File

@@ -101,7 +101,7 @@ chroot_add_resolv_conf "$mountPoint" || echo "$0: failed to set up resolv.conf"
LOCALE_ARCHIVE="$system/sw/lib/locale/locale-archive" IN_NIXOS_ENTER=1 chroot "$mountPoint" "$system/activate" 1>&2 || true
# Create /tmp
chroot "$mountPoint" systemd-tmpfiles --create --remove --exclude-prefix=/dev 1>&2 || true
chroot "$mountPoint" "$system/sw/bin/systemd-tmpfiles" --create --remove --exclude-prefix=/dev 1>&2 || true
)
unset TMPDIR

View File

@@ -13,7 +13,7 @@ let
attrsToText = attrs:
concatStringsSep "\n" (
mapAttrsToList (n: v: ''${n}=${escapeIfNeccessary (toString v)}'') attrs
);
) + "\n";
osReleaseContents = {
NAME = "NixOS";
@@ -107,7 +107,7 @@ in
defaultChannel = mkOption {
internal = true;
type = types.str;
default = "https://nixos.org/channels/nixos-unstable";
default = "https://nixos.org/channels/nixos-22.05";
description = "Default NixOS channel to which the root user is subscribed.";
};

View File

@@ -884,6 +884,7 @@
./services/networking/redsocks.nix
./services/networking/resilio.nix
./services/networking/robustirc-bridge.nix
./services/networking/routedns.nix
./services/networking/rpcbind.nix
./services/networking/rxe.nix
./services/networking/sabnzbd.nix
@@ -999,6 +1000,7 @@
./services/security/vaultwarden/default.nix
./services/security/yubikey-agent.nix
./services/system/cachix-agent/default.nix
./services/system/cachix-watch-store.nix
./services/system/cloud-init.nix
./services/system/dbus.nix
./services/system/earlyoom.nix

View File

@@ -109,6 +109,9 @@ in
# USB drivers
"xhci-pci-renesas"
# Reset controllers
"reset-raspberrypi" # Triggers USB chip firmware load.
# Misc "weak" dependencies
"analogix-dp"
"analogix-anx6345" # For DP or eDP (e.g. integrated display)

View File

@@ -20,7 +20,13 @@
pkgs.mkpasswd # for generating password files
# Some text editors.
pkgs.vim
(pkgs.vim.customize {
name = "vim";
vimrcConfig.packages.default = {
start = [ pkgs.vimPlugins.vim-nix ];
};
vimrcConfig.customRC = "syntax on";
})
# Some networking tools.
pkgs.fuse

View File

@@ -215,6 +215,7 @@ in {
systemd.sockets.mpd = mkIf cfg.startWhenNeeded {
wantedBy = [ "sockets.target" ];
listenStreams = [
"" # Note: this is needed to override the upstream unit
(if pkgs.lib.hasPrefix "/" cfg.network.listenAddress
then cfg.network.listenAddress
else "${optionalString (cfg.network.listenAddress != "any") "${cfg.network.listenAddress}:"}${toString cfg.network.port}")

View File

@@ -139,8 +139,9 @@ let
# Ensure that the home directory already exists
# We can't assert createHome == true because that's not the case for root
cd "${config.users.users.${cfg.user}.home}"
${install} -d .config/borg
${install} -d .cache/borg
# Create each directory separately to prevent root owned parent dirs
${install} -d .config .config/borg
${install} -d .cache .cache/borg
'' + optionalString (isLocalPath cfg.repo && !cfg.removableDevice) ''
${install} -d ${escapeShellArg cfg.repo}
''));

View File

@@ -96,13 +96,22 @@ in
};
repository = mkOption {
type = types.str;
type = with types; nullOr str;
default = null;
description = ''
repository to backup to.
'';
example = "sftp:backup@192.168.1.100:/backups/${name}";
};
repositoryFile = mkOption {
type = with types; nullOr path;
default = null;
description = ''
Path to the file containing the repository location to backup to.
'';
};
paths = mkOption {
type = types.nullOr (types.listOf types.str);
default = null;
@@ -142,7 +151,7 @@ in
extraBackupArgs = mkOption {
type = types.listOf types.str;
default = [];
default = [ ];
description = ''
Extra arguments passed to restic backup.
'';
@@ -153,7 +162,7 @@ in
extraOptions = mkOption {
type = types.listOf types.str;
default = [];
default = [ ];
description = ''
Extra extended options to be passed to the restic --option flag.
'';
@@ -172,7 +181,7 @@ in
pruneOpts = mkOption {
type = types.listOf types.str;
default = [];
default = [ ];
description = ''
A list of options (--keep-* et al.) for 'restic forget
--prune', to automatically prune old snapshots. The
@@ -197,9 +206,34 @@ in
'';
example = "find /home/matt/git -type d -name .git";
};
backupPrepareCommand = mkOption {
type = with types; nullOr str;
default = null;
description = ''
A script that must run before starting the backup process.
'';
};
backupCleanupCommand = mkOption {
type = with types; nullOr str;
default = null;
description = ''
A script that must run after finishing the backup process.
'';
};
package = mkOption {
type = types.package;
default = pkgs.restic;
defaultText = literalExpression "pkgs.restic";
description = ''
Restic package to use.
'';
};
};
}));
default = {};
default = { };
example = {
localbackup = {
paths = [ "/home" ];
@@ -225,66 +259,85 @@ in
config = {
warnings = mapAttrsToList (n: v: "services.restic.backups.${n}.s3CredentialsFile is deprecated, please use services.restic.backups.${n}.environmentFile instead.") (filterAttrs (n: v: v.s3CredentialsFile != null) config.services.restic.backups);
systemd.services =
mapAttrs' (name: backup:
let
extraOptions = concatMapStrings (arg: " -o ${arg}") backup.extraOptions;
resticCmd = "${pkgs.restic}/bin/restic${extraOptions}";
filesFromTmpFile = "/run/restic-backups-${name}/includes";
backupPaths = if (backup.dynamicFilesFrom == null)
then if (backup.paths != null) then concatStringsSep " " backup.paths else ""
else "--files-from ${filesFromTmpFile}";
pruneCmd = optionals (builtins.length backup.pruneOpts > 0) [
( resticCmd + " forget --prune " + (concatStringsSep " " backup.pruneOpts) )
( resticCmd + " check" )
];
# Helper functions for rclone remotes
rcloneRemoteName = builtins.elemAt (splitString ":" backup.repository) 1;
rcloneAttrToOpt = v: "RCLONE_" + toUpper (builtins.replaceStrings [ "-" ] [ "_" ] v);
rcloneAttrToConf = v: "RCLONE_CONFIG_" + toUpper (rcloneRemoteName + "_" + v);
toRcloneVal = v: if lib.isBool v then lib.boolToString v else v;
in nameValuePair "restic-backups-${name}" ({
environment = {
RESTIC_PASSWORD_FILE = backup.passwordFile;
RESTIC_REPOSITORY = backup.repository;
} // optionalAttrs (backup.rcloneOptions != null) (mapAttrs' (name: value:
nameValuePair (rcloneAttrToOpt name) (toRcloneVal value)
) backup.rcloneOptions) // optionalAttrs (backup.rcloneConfigFile != null) {
RCLONE_CONFIG = backup.rcloneConfigFile;
} // optionalAttrs (backup.rcloneConfig != null) (mapAttrs' (name: value:
nameValuePair (rcloneAttrToConf name) (toRcloneVal value)
) backup.rcloneConfig);
path = [ pkgs.openssh ];
restartIfChanged = false;
serviceConfig = {
Type = "oneshot";
ExecStart = (optionals (backupPaths != "") [ "${resticCmd} backup --cache-dir=%C/restic-backups-${name} ${concatStringsSep " " backup.extraBackupArgs} ${backupPaths}" ])
++ pruneCmd;
User = backup.user;
RuntimeDirectory = "restic-backups-${name}";
CacheDirectory = "restic-backups-${name}";
CacheDirectoryMode = "0700";
} // optionalAttrs (backup.environmentFile != null) {
EnvironmentFile = backup.environmentFile;
};
} // optionalAttrs (backup.initialize || backup.dynamicFilesFrom != null) {
preStart = ''
${optionalString (backup.initialize) ''
${resticCmd} snapshots || ${resticCmd} init
''}
${optionalString (backup.dynamicFilesFrom != null) ''
${pkgs.writeScript "dynamicFilesFromScript" backup.dynamicFilesFrom} > ${filesFromTmpFile}
''}
'';
} // optionalAttrs (backup.dynamicFilesFrom != null) {
postStart = ''
rm ${filesFromTmpFile}
'';
})
) config.services.restic.backups;
mapAttrs'
(name: backup:
let
extraOptions = concatMapStrings (arg: " -o ${arg}") backup.extraOptions;
resticCmd = "${backup.package}/bin/restic${extraOptions}";
filesFromTmpFile = "/run/restic-backups-${name}/includes";
backupPaths =
if (backup.dynamicFilesFrom == null)
then if (backup.paths != null) then concatStringsSep " " backup.paths else ""
else "--files-from ${filesFromTmpFile}";
pruneCmd = optionals (builtins.length backup.pruneOpts > 0) [
(resticCmd + " forget --prune " + (concatStringsSep " " backup.pruneOpts))
(resticCmd + " check")
];
# Helper functions for rclone remotes
rcloneRemoteName = builtins.elemAt (splitString ":" backup.repository) 1;
rcloneAttrToOpt = v: "RCLONE_" + toUpper (builtins.replaceStrings [ "-" ] [ "_" ] v);
rcloneAttrToConf = v: "RCLONE_CONFIG_" + toUpper (rcloneRemoteName + "_" + v);
toRcloneVal = v: if lib.isBool v then lib.boolToString v else v;
in
nameValuePair "restic-backups-${name}" ({
environment = {
RESTIC_PASSWORD_FILE = backup.passwordFile;
RESTIC_REPOSITORY = backup.repository;
RESTIC_REPOSITORY_FILE = backup.repositoryFile;
} // optionalAttrs (backup.rcloneOptions != null) (mapAttrs'
(name: value:
nameValuePair (rcloneAttrToOpt name) (toRcloneVal value)
)
backup.rcloneOptions) // optionalAttrs (backup.rcloneConfigFile != null) {
RCLONE_CONFIG = backup.rcloneConfigFile;
} // optionalAttrs (backup.rcloneConfig != null) (mapAttrs'
(name: value:
nameValuePair (rcloneAttrToConf name) (toRcloneVal value)
)
backup.rcloneConfig);
path = [ pkgs.openssh ];
restartIfChanged = false;
serviceConfig = {
Type = "oneshot";
ExecStart = (optionals (backupPaths != "") [ "${resticCmd} backup --cache-dir=%C/restic-backups-${name} ${concatStringsSep " " backup.extraBackupArgs} ${backupPaths}" ])
++ pruneCmd;
User = backup.user;
RuntimeDirectory = "restic-backups-${name}";
CacheDirectory = "restic-backups-${name}";
CacheDirectoryMode = "0700";
} // optionalAttrs (backup.environmentFile != null) {
EnvironmentFile = backup.environmentFile;
};
} // optionalAttrs (backup.initialize || backup.dynamicFilesFrom != null || backup.backupPrepareCommand != null) {
preStart = ''
${optionalString (backup.backupPrepareCommand != null) ''
${pkgs.writeScript "backupPrepareCommand" backup.backupPrepareCommand}
''}
${optionalString (backup.initialize) ''
${resticCmd} snapshots || ${resticCmd} init
''}
${optionalString (backup.dynamicFilesFrom != null) ''
${pkgs.writeScript "dynamicFilesFromScript" backup.dynamicFilesFrom} > ${filesFromTmpFile}
''}
'';
} // optionalAttrs (backup.dynamicFilesFrom != null || backup.backupCleanupCommand != null) {
postStop = ''
${optionalString (backup.backupCleanupCommand != null) ''
${pkgs.writeScript "backupCleanupCommand" backup.backupCleanupCommand}
''}
${optionalString (backup.dynamicFilesFrom != null) ''
rm ${filesFromTmpFile}
''}
'';
})
)
config.services.restic.backups;
systemd.timers =
mapAttrs' (name: backup: nameValuePair "restic-backups-${name}" {
wantedBy = [ "timers.target" ];
timerConfig = backup.timerConfig;
}) config.services.restic.backups;
mapAttrs'
(name: backup: nameValuePair "restic-backups-${name}" {
wantedBy = [ "timers.target" ];
timerConfig = backup.timerConfig;
})
config.services.restic.backups;
};
}

View File

@@ -16,11 +16,11 @@ let
lib.concatMapStrings (s: if lib.isList s then "-" else s)
(builtins.split "[^a-zA-Z0-9_.\\-]+" name);
# Function to build "zfs allow" commands for the filesystems we've
# delegated permissions to. It also checks if the target dataset
# exists before delegating permissions, if it doesn't exist we
# delegate it to the parent dataset. This should solve the case of
# provisoning new datasets.
# Function to build "zfs allow" commands for the filesystems we've delegated
# permissions to. It also checks if the target dataset exists before
# delegating permissions, if it doesn't exist we delegate it to the parent
# dataset (if it exists). This should solve the case of provisoning new
# datasets.
buildAllowCommand = permissions: dataset: (
"-+${pkgs.writeShellScript "zfs-allow-${dataset}" ''
# Here we explicitly use the booted system to guarantee the stable API needed by ZFS
@@ -38,15 +38,17 @@ let
(concatStringsSep "," permissions)
dataset
]}
else
${lib.escapeShellArgs [
"/run/booted-system/sw/bin/zfs"
"allow"
cfg.user
(concatStringsSep "," permissions)
# Remove the last part of the path
(builtins.dirOf dataset)
]}
${lib.optionalString ((builtins.dirOf dataset) != ".") ''
else
${lib.escapeShellArgs [
"/run/booted-system/sw/bin/zfs"
"allow"
cfg.user
(concatStringsSep "," permissions)
# Remove the last part of the path
(builtins.dirOf dataset)
]}
''}
fi
''}"
);
@@ -67,14 +69,14 @@ let
(concatStringsSep "," permissions)
dataset
]}
${lib.escapeShellArgs [
${lib.optionalString ((builtins.dirOf dataset) != ".") (lib.escapeShellArgs [
"/run/booted-system/sw/bin/zfs"
"unallow"
cfg.user
(concatStringsSep "," permissions)
# Remove the last part of the path
(builtins.dirOf dataset)
]}
])}
''}"
);
in

View File

@@ -310,7 +310,11 @@ in
mkdir -m 0700 -p ${baseDir}/queue-runner
mkdir -m 0750 -p ${baseDir}/build-logs
chown hydra-queue-runner:hydra ${baseDir}/queue-runner ${baseDir}/build-logs
mkdir -m 0750 -p ${baseDir}/runcommand-logs
chown hydra-queue-runner.hydra \
${baseDir}/queue-runner \
${baseDir}/build-logs \
${baseDir}/runcommand-logs
${optionalString haveLocalDB ''
if ! [ -e ${baseDir}/.db-created ]; then

View File

@@ -156,12 +156,22 @@ in {
reloadScript = ''
echo "Asking Jenkins to reload config"
curl_opts="--silent --fail --show-error"
access_token=${if cfg.accessTokenFile != ""
then "$(cat '${cfg.accessTokenFile}')"
else cfg.accessToken}
jenkins_url="http://${cfg.accessUser}:$access_token@${jenkinsCfg.listenAddress}:${toString jenkinsCfg.port}${jenkinsCfg.prefix}"
crumb=$(curl $curl_opts "$jenkins_url"'/crumbIssuer/api/xml?xpath=concat(//crumbRequestField,":",//crumb)')
curl $curl_opts -X POST -H "$crumb" "$jenkins_url"/reload
access_token_file=${if cfg.accessTokenFile != ""
then cfg.accessTokenFile
else "$RUNTIME_DIRECTORY/jenkins_access_token.txt"}
if [ "${cfg.accessToken}" != "" ]; then
(umask 0077; printf "${cfg.accessToken}" >"$access_token_file")
fi
jenkins_url="http://${jenkinsCfg.listenAddress}:${toString jenkinsCfg.port}${jenkinsCfg.prefix}"
auth_file="$RUNTIME_DIRECTORY/jenkins_auth_file.txt"
trap 'rm -f "$auth_file"' EXIT
(umask 0077; printf "${cfg.accessUser}:@password_placeholder@" >"$auth_file")
"${pkgs.replace-secret}/bin/replace-secret" "@password_placeholder@" "$access_token_file" "$auth_file"
if ! "${pkgs.jenkins}/bin/jenkins-cli" -s "$jenkins_url" -auth "@$auth_file" reload-configuration; then
echo "error: failed to reload configuration"
exit 1
fi
'';
in
''
@@ -233,6 +243,7 @@ in {
done
'' + (if cfg.accessUser != "" then reloadScript else "");
serviceConfig = {
Type = "oneshot";
User = jenkinsCfg.user;
RuntimeDirectory = "jenkins-job-builder";
};

View File

@@ -312,6 +312,7 @@ in {
"-h" (lib.concatStringsSep " " cfg.urlList)
]);
Type = "notify";
NotifyAccess = "all";
PIDFile = cfg.settings.attrs.olcPidFile;
};
};

View File

@@ -216,6 +216,7 @@ in
# we can't be part of a system service, and the agent should
# be okay with the main service coming and going
wantedBy = [ "default.target" ];
after = lib.optionals cfg.enableWifi [ "network-online.target" ];
unitConfig.ConditionUser = "!@system";
serviceConfig = {
Type = "exec";

View File

@@ -91,6 +91,7 @@
"adapter.auto-port-config": {
"mode": "dsp",
"monitor": false,
"control": false,
"position": "unknown"
}
}
@@ -109,6 +110,7 @@
"adapter.auto-port-config": {
"mode": "dsp",
"monitor": false,
"control": false,
"position": "unknown"
}
}

View File

@@ -251,6 +251,8 @@ in {
] ++ lib.optional config.security.rtkit.enable "rtkit";
description = "Pipewire system service user";
isSystemUser = true;
home = "/var/lib/pipewire";
createHome = true;
};
groups.pipewire.gid = config.ids.gids.pipewire;
};

View File

@@ -37,11 +37,19 @@ in
environment.systemPackages = [ cfg.package ];
environment.etc."wireplumber/main.lua.d/80-nixos.lua" = lib.mkIf (!pwUsedForAudio) {
text = ''
text = ''
-- Pipewire is not used for audio, so prevent it from grabbing audio devices
alsa_monitor.enable = function() end
'';
};
environment.etc."wireplumber/main.lua.d/80-systemwide.lua" = lib.mkIf config.services.pipewire.systemWide {
text = ''
-- When running system-wide, these settings need to be disabled (they
-- use functions that aren't available on the system dbus).
alsa_monitor.properties["alsa.reserve"] = false
default_access.properties["enable-flatpak-portal"] = false
'';
};
systemd.packages = [ cfg.package ];
@@ -50,5 +58,10 @@ in
systemd.services.wireplumber.wantedBy = [ "pipewire.service" ];
systemd.user.services.wireplumber.wantedBy = [ "pipewire.service" ];
systemd.services.wireplumber.environment = lib.mkIf config.services.pipewire.systemWide {
# Force wireplumber to use system dbus.
DBUS_SESSION_BUS_ADDRESS = "unix:path=/run/dbus/system_bus_socket";
};
};
}

View File

@@ -22,6 +22,15 @@ let
'' + concatStringsSep "\n" (mapAttrsToList
(n: v: "${n}=${cfgToString v}") cfg.serverProperties));
stopScript = pkgs.writeShellScript "minecraft-server-stop" ''
echo stop > ${config.systemd.sockets.minecraft-server.socketConfig.ListenFIFO}
# Wait for the PID of the minecraft server to disappear before
# returning, so systemd doesn't attempt to SIGKILL it.
while kill -0 "$1" 2> /dev/null; do
sleep 1s
done
'';
# To be able to open the firewall, we need to read out port values in the
# server properties, but fall back to the defaults when those don't exist.
@@ -172,16 +181,35 @@ in {
};
users.groups.minecraft = {};
systemd.sockets.minecraft-server = {
bindsTo = [ "minecraft-server.service" ];
socketConfig = {
ListenFIFO = "/run/minecraft-server.stdin";
SocketMode = "0660";
SocketUser = "minecraft";
SocketGroup = "minecraft";
RemoveOnStop = true;
FlushPending = true;
};
};
systemd.services.minecraft-server = {
description = "Minecraft Server Service";
wantedBy = [ "multi-user.target" ];
after = [ "network.target" ];
requires = [ "minecraft-server.socket" ];
after = [ "network.target" "minecraft-server.socket" ];
serviceConfig = {
ExecStart = "${cfg.package}/bin/minecraft-server ${cfg.jvmOpts}";
ExecStop = "${stopScript} $MAINPID";
Restart = "always";
User = "minecraft";
WorkingDirectory = cfg.dataDir;
StandardInput = "socket";
StandardOutput = "journal";
StandardError = "journal";
# Hardening
CapabilityBoundingSet = [ "" ];
DeviceAllow = [ "" ];

View File

@@ -167,22 +167,23 @@ let
sed -e "s/\bsu\s.*/su $user $group/" \
-e "s/\b\(create\s\+[0-9]*\s*\|createolddir\s\+[0-9]*\s\+\).*/\1$user $group/" \
-e "1imissingok" -e "s/\bnomissingok\b//" \
$out > /tmp/logrotate.conf
$out > logrotate.conf
# Since this makes for very verbose builds only show real error.
# There is no way to control log level, but logrotate hardcodes
# 'error:' at common log level, so we can use grep, taking care
# to keep error codes
set -o pipefail
if ! ${pkgs.buildPackages.logrotate}/sbin/logrotate --debug /tmp/logrotate.conf 2>&1 \
| ( ! grep "error:" ) > /tmp/logrotate-error; then
if ! ${pkgs.buildPackages.logrotate}/sbin/logrotate -s logrotate.status \
--debug logrotate.conf 2>&1 \
| ( ! grep "error:" ) > logrotate-error; then
echo "Logrotate configuration check failed."
echo "The failing configuration (after adjustments to pass tests in sandbox) was:"
printf "%s\n" "-------"
cat /tmp/logrotate.conf
cat logrotate.conf
printf "%s\n" "-------"
echo "The error reported by logrotate was as follow:"
printf "%s\n" "-------"
cat /tmp/logrotate-error
cat logrotate-error
printf "%s\n" "-------"
echo "You can disable this check with services.logrotate.checkConfig = false,"
echo "but if you think it should work please report this failure along with"

View File

@@ -33,21 +33,26 @@
<link xlink:href="https://github.com/matrix-org/synapse#synapse-installation">
installation instructions of Synapse </link>.
<programlisting>
{ pkgs, lib, ... }:
{ pkgs, lib, config, ... }:
let
fqdn =
let
join = hostName: domain: hostName + lib.optionalString (domain != null) ".${domain}";
in join config.networking.hostName config.networking.domain;
in {
networking = {
<link linkend="opt-networking.hostName">hostName</link> = "myhostname";
<link linkend="opt-networking.domain">domain</link> = "example.org";
fqdn = "${config.networking.hostName}.${config.networking.domain}";
clientConfig = {
"m.homeserver".base_url = "https://${fqdn}";
"m.identity_server" = {};
};
<link linkend="opt-networking.firewall.allowedTCPPorts">networking.firewall.allowedTCPPorts</link> = [ 80 443 ];
serverConfig."m.server" = "${config.services.matrix-synapse.settings.server_name}:443";
mkWellKnown = data: ''
add_header Content-Type application/json;
add_header Access-Control-Allow-Origin *;
return 200 '${builtins.toJSON data}';
'';
in {
<xref linkend="opt-networking.hostName" /> = "myhostname";
<xref linkend="opt-networking.domain" /> = "example.org";
<xref linkend="opt-networking.firewall.allowedTCPPorts" /> = [ 80 443 ];
<link linkend="opt-services.postgresql.enable">services.postgresql.enable</link> = true;
<link linkend="opt-services.postgresql.initialScript">services.postgresql.initialScript</link> = pkgs.writeText "synapse-init.sql" ''
<xref linkend="opt-services.postgresql.enable" /> = true;
<xref linkend="opt-services.postgresql.initialScript" /> = pkgs.writeText "synapse-init.sql" ''
CREATE ROLE "matrix-synapse" WITH LOGIN PASSWORD 'synapse';
CREATE DATABASE "matrix-synapse" WITH OWNER "matrix-synapse"
TEMPLATE template0
@@ -57,78 +62,41 @@ in {
services.nginx = {
<link linkend="opt-services.nginx.enable">enable</link> = true;
# only recommendedProxySettings and recommendedGzipSettings are strictly required,
# but the rest make sense as well
<link linkend="opt-services.nginx.recommendedTlsSettings">recommendedTlsSettings</link> = true;
<link linkend="opt-services.nginx.recommendedOptimisation">recommendedOptimisation</link> = true;
<link linkend="opt-services.nginx.recommendedGzipSettings">recommendedGzipSettings</link> = true;
<link linkend="opt-services.nginx.recommendedProxySettings">recommendedProxySettings</link> = true;
<link linkend="opt-services.nginx.virtualHosts">virtualHosts</link> = {
# This host section can be placed on a different host than the rest,
# i.e. to delegate from the host being accessible as ${config.networking.domain}
# to another host actually running the Matrix homeserver.
"${config.networking.domain}" = {
"${config.networking.domain}" = { <co xml:id='ex-matrix-synapse-dns' />
<link linkend="opt-services.nginx.virtualHosts._name_.enableACME">enableACME</link> = true;
<link linkend="opt-services.nginx.virtualHosts._name_.forceSSL">forceSSL</link> = true;
<link linkend="opt-services.nginx.virtualHosts._name_.locations._name_.extraConfig">locations."= /.well-known/matrix/server".extraConfig</link> =
let
# use 443 instead of the default 8448 port to unite
# the client-server and server-server port for simplicity
server = { "m.server" = "${fqdn}:443"; };
in ''
add_header Content-Type application/json;
return 200 '${builtins.toJSON server}';
'';
<link linkend="opt-services.nginx.virtualHosts._name_.locations._name_.extraConfig">locations."= /.well-known/matrix/client".extraConfig</link> =
let
client = {
"m.homeserver" = { "base_url" = "https://${fqdn}"; };
"m.identity_server" = { "base_url" = "https://vector.im"; };
};
# ACAO required to allow element-web on any URL to request this json file
in ''
add_header Content-Type application/json;
add_header Access-Control-Allow-Origin *;
return 200 '${builtins.toJSON client}';
'';
<link linkend="opt-services.nginx.virtualHosts._name_.locations._name_.extraConfig">locations."= /.well-known/matrix/server".extraConfig</link> = mkWellKnown serverConfig; <co xml:id='ex-matrix-synapse-well-known-server' />
<link linkend="opt-services.nginx.virtualHosts._name_.locations._name_.extraConfig">locations."= /.well-known/matrix/client".extraConfig</link> = mkWellKnown clientConfig; <co xml:id='ex-matrix-synapse-well-known-client' />
};
# Reverse proxy for Matrix client-server and server-server communication
${fqdn} = {
"${fqdn}" = {
<link linkend="opt-services.nginx.virtualHosts._name_.enableACME">enableACME</link> = true;
<link linkend="opt-services.nginx.virtualHosts._name_.forceSSL">forceSSL</link> = true;
# Or do a redirect instead of the 404, or whatever is appropriate for you.
# But do not put a Matrix Web client here! See the Element web section below.
<link linkend="opt-services.nginx.virtualHosts._name_.locations._name_.extraConfig">locations."/".extraConfig</link> = ''
<link linkend="opt-services.nginx.virtualHosts._name_.locations._name_.extraConfig">locations."/".extraConfig</link> = '' <co xml:id='ex-matrix-synapse-rev-default' />
return 404;
'';
# forward all Matrix API calls to the synapse Matrix homeserver
locations."/_matrix" = {
<link linkend="opt-services.nginx.virtualHosts._name_.locations._name_.proxyPass">proxyPass</link> = "http://[::1]:8008"; # without a trailing /
};
<link linkend="opt-services.nginx.virtualHosts._name_.locations._name_.proxyPass">locations."/_matrix".proxyPass</link> = "http://[::1]:8008"; <co xml:id='ex-matrix-synapse-rev-proxy-pass' />
<link linkend="opt-services.nginx.virtualHosts._name_.locations._name_.proxyPass">locations."/_synapse/client".proxyPass</link> = "http://[::1]:8008"; <co xml:id='ex-matrix-synapse-rev-client' />
};
};
};
services.matrix-synapse = {
<link linkend="opt-services.matrix-synapse.enable">enable</link> = true;
<link linkend="opt-services.matrix-synapse.settings.server_name">server_name</link> = config.networking.domain;
<link linkend="opt-services.matrix-synapse.settings.listeners">listeners</link> = [
{
<link linkend="opt-services.matrix-synapse.settings.listeners._.port">port</link> = 8008;
<link linkend="opt-services.matrix-synapse.settings.server_name">settings.server_name</link> = config.networking.domain;
<link linkend="opt-services.matrix-synapse.settings.listeners">settings.listeners</link> = [
{ <link linkend="opt-services.matrix-synapse.settings.listeners._.port">port</link> = 8008;
<link linkend="opt-services.matrix-synapse.settings.listeners._.bind_addresses">bind_addresses</link> = [ "::1" ];
<link linkend="opt-services.matrix-synapse.settings.listeners._.type">type</link> = "http";
<link linkend="opt-services.matrix-synapse.settings.listeners._.tls">tls</link> = false;
<link linkend="opt-services.matrix-synapse.settings.listeners._.x_forwarded">x_forwarded</link> = true;
<link linkend="opt-services.matrix-synapse.settings.listeners._.resources">resources</link> = [ {
<link linkend="opt-services.matrix-synapse.settings.listeners._.resources._.names">names</link> = [ "client" ];
<link linkend="opt-services.matrix-synapse.settings.listeners._.resources._.names">names</link> = [ "client" "federation" ];
<link linkend="opt-services.matrix-synapse.settings.listeners._.resources._.compress">compress</link> = true;
} {
<link linkend="opt-services.matrix-synapse.settings.listeners._.resources._.names">names</link> = [ "federation" ];
<link linkend="opt-services.matrix-synapse.settings.listeners._.resources._.compress">compress</link> = false;
} ];
}
];
@@ -136,20 +104,59 @@ in {
}
</programlisting>
</para>
<para>
If the <code>A</code> and <code>AAAA</code> DNS records on
<literal>example.org</literal> do not point on the same host as the records
for <code>myhostname.example.org</code>, you can easily move the
<code>/.well-known</code> virtualHost section of the code to the host that
is serving <literal>example.org</literal>, while the rest stays on
<literal>myhostname.example.org</literal> with no other changes required.
This pattern also allows to seamlessly move the homeserver from
<literal>myhostname.example.org</literal> to
<literal>myotherhost.example.org</literal> by only changing the
<code>/.well-known</code> redirection target.
</para>
<calloutlist>
<callout arearefs='ex-matrix-synapse-dns'>
<para>
If the <code>A</code> and <code>AAAA</code> DNS records on
<literal>example.org</literal> do not point on the same host as the records
for <code>myhostname.example.org</code>, you can easily move the
<code>/.well-known</code> virtualHost section of the code to the host that
is serving <literal>example.org</literal>, while the rest stays on
<literal>myhostname.example.org</literal> with no other changes required.
This pattern also allows to seamlessly move the homeserver from
<literal>myhostname.example.org</literal> to
<literal>myotherhost.example.org</literal> by only changing the
<code>/.well-known</code> redirection target.
</para>
</callout>
<callout arearefs='ex-matrix-synapse-well-known-server'>
<para>
This section is not needed if the <link linkend="opt-services.matrix-synapse.settings.server_name">server_name</link>
of <package>matrix-synapse</package> is equal to the domain (i.e.
<literal>example.org</literal> from <literal>@foo:example.org</literal>)
and the federation port is 8448.
Further reference can be found in the <link xlink:href="https://matrix-org.github.io/synapse/latest/delegate.html">docs
about delegation</link>.
</para>
</callout>
<callout arearefs='ex-matrix-synapse-well-known-client'>
<para>
This is usually needed for homeserver discovery (from e.g. other Matrix clients).
Further reference can be found in the <link xlink:href="https://spec.matrix.org/latest/client-server-api/#getwell-knownmatrixclient">upstream docs</link>
</para>
</callout>
<callout arearefs='ex-matrix-synapse-rev-default'>
<para>
It's also possible to do a redirect here or something else, this vhost is not
needed for Matrix. It's recommended though to <emphasis>not put</emphasis> element
here, see also the <link linkend='ex-matrix-synapse-rev-default'>section about Element</link>.
</para>
</callout>
<callout arearefs='ex-matrix-synapse-rev-proxy-pass'>
<para>
Forward all Matrix API calls to the synapse Matrix homeserver. A trailing slash
<emphasis>must not</emphasis> be used here.
</para>
</callout>
<callout arearefs='ex-matrix-synapse-rev-client'>
<para>
Forward requests for e.g. SSO and password-resets.
</para>
</callout>
</calloutlist>
</section>
<section xml:id="module-services-matrix-register-users">
<title>Registering Matrix users</title>
<para>
If you want to run a server with public registration by anybody, you can
then enable <literal><link linkend="opt-services.matrix-synapse.settings.enable_registration">services.matrix-synapse.settings.enable_registration</link> =
@@ -159,7 +166,7 @@ in {
To create a new user or admin, run the following after you have set the secret
and have rebuilt NixOS:
<screen>
<prompt>$ </prompt>nix run nixpkgs.matrix-synapse
<prompt>$ </prompt>nix-shell -p matrix-synapse
<prompt>$ </prompt>register_new_matrix_user -k <replaceable>your-registration-shared-secret</replaceable> http://localhost:8008
<prompt>New user localpart: </prompt><replaceable>your-username</replaceable>
<prompt>Password:</prompt>
@@ -168,12 +175,51 @@ in {
Success!
</screen>
In the example, this would create a user with the Matrix Identifier
<literal>@your-username:example.org</literal>. Note that the registration
secret ends up in the nix store and therefore is world-readable by any user
on your machine, so it makes sense to only temporarily activate the
<link linkend="opt-services.matrix-synapse.settings.registration_shared_secret">registration_shared_secret</link>
option until a better solution for NixOS is in place.
<literal>@your-username:example.org</literal>.
<warning>
<para>
When using <xref linkend="opt-services.matrix-synapse.settings.registration_shared_secret" />, the secret
will end up in the world-readable store. Instead it's recommended to deploy the secret
in an additional file like this:
<itemizedlist>
<listitem>
<para>
Create a file with the following contents:
<programlisting>registration_shared_secret: your-very-secret-secret</programlisting>
</para>
</listitem>
<listitem>
<para>
Deploy the file with a secret-manager such as <link xlink:href="https://nixops.readthedocs.io/en/latest/overview.html#managing-keys"><option>deployment.keys</option></link>
from <citerefentry><refentrytitle>nixops</refentrytitle><manvolnum>1</manvolnum></citerefentry>
or <link xlink:href="https://github.com/Mic92/sops-nix/">sops-nix</link> to
e.g. <filename>/run/secrets/matrix-shared-secret</filename> and ensure that it's readable
by <package>matrix-synapse</package>.
</para>
</listitem>
<listitem>
<para>
Include the file like this in your configuration:
<programlisting>
{
<xref linkend="opt-services.matrix-synapse.extraConfigFiles" /> = [
"/run/secrets/matrix-shared-secret"
];
}
</programlisting>
</para>
</listitem>
</itemizedlist>
</para>
</warning>
</para>
<note>
<para>
It's also possible to user alternative authentication mechanism such as
<link xlink:href="https://github.com/matrix-org/matrix-synapse-ldap3">LDAP (via <literal>matrix-synapse-ldap3</literal>)</link>
or <link xlink:href="https://matrix-org.github.io/synapse/latest/openid.html">OpenID</link>.
</para>
</note>
</section>
<section xml:id="module-services-matrix-element-web">
<title>Element (formerly known as Riot) Web Client</title>
@@ -206,10 +252,7 @@ Success!
<link linkend="opt-services.nginx.virtualHosts._name_.root">root</link> = pkgs.element-web.override {
conf = {
default_server_config."m.homeserver" = {
"base_url" = "https://${fqdn}";
"server_name" = "${fqdn}";
};
default_server_config = clientConfig; # see `clientConfig` from the snippet above.
};
};
};
@@ -217,15 +260,17 @@ Success!
</programlisting>
</para>
<para>
Note that the Element developers do not recommend running Element and your Matrix
homeserver on the same fully-qualified domain name for security reasons. In
the example, this means that you should not reuse the
<literal>myhostname.example.org</literal> virtualHost to also serve Element,
but instead serve it on a different subdomain, like
<literal>element.example.org</literal> in the example. See the
<link xlink:href="https://github.com/vector-im/riot-web#important-security-note">Element
Important Security Notes</link> for more information on this subject.
</para>
<note>
<para>
The Element developers do not recommend running Element and your Matrix
homeserver on the same fully-qualified domain name for security reasons. In
the example, this means that you should not reuse the
<literal>myhostname.example.org</literal> virtualHost to also serve Element,
but instead serve it on a different subdomain, like
<literal>element.example.org</literal> in the example. See the
<link xlink:href="https://github.com/vector-im/element-web/tree/v1.10.0#important-security-notes">Element
Important Security Notes</link> for more information on this subject.
</para>
</note>
</section>
</chapter>

View File

@@ -74,6 +74,18 @@ in
<literal>dendrite</literal> is running.
'';
};
loadCredential = lib.mkOption {
type = lib.types.listOf lib.types.str;
default = [ ];
example = [ "private_key:/path/to/my_private_key" ];
description = ''
This can be used to pass secrets to the systemd service without adding them to
the nix store.
To use the example setting, see the example of
<option>services.dendrite.settings.global.private_key</option>.
See the LoadCredential section of systemd.exec manual for more information.
'';
};
settings = lib.mkOption {
type = lib.types.submodule {
freeformType = settingsFormat.type;
@@ -88,8 +100,10 @@ in
'';
};
private_key = lib.mkOption {
type = lib.types.path;
example = "${workingDir}/matrix_key.pem";
type = lib.types.either
lib.types.path
(lib.types.strMatching "^\\$CREDENTIALS_DIRECTORY/.+");
example = "$CREDENTIALS_DIRECTORY/private_key";
description = ''
The path to the signing private key file, used to sign
requests and events.
@@ -256,6 +270,7 @@ in
RuntimeDirectoryMode = "0700";
LimitNOFILE = 65535;
EnvironmentFile = lib.mkIf (cfg.environmentFile != null) cfg.environmentFile;
LoadCredential = cfg.loadCredential;
ExecStartPre = ''
${pkgs.envsubst}/bin/envsubst \
-i ${configurationYaml} \

View File

@@ -13,6 +13,22 @@ let
else
pkgs.postgresql_12;
# Git 2.36.1 seemingly contains a commit-graph related bug which is
# easily triggered through GitLab, so we downgrade it to 2.35.x
# until this issue is solved. See
# https://gitlab.com/gitlab-org/gitlab/-/issues/360783#note_992870101.
gitPackage =
let
version = "2.35.4";
in
pkgs.git.overrideAttrs (oldAttrs: rec {
inherit version;
src = pkgs.fetchurl {
url = "https://www.kernel.org/pub/software/scm/git/git-${version}.tar.xz";
sha256 = "sha256-mv13OdNkXggeKQkJ+47QcJ6lYmcw6Qjri1ZJ2ETCTOk=";
};
});
gitlabSocket = "${cfg.statePath}/tmp/sockets/gitlab.socket";
gitalySocket = "${cfg.statePath}/tmp/sockets/gitaly.socket";
pathUrlQuote = url: replaceStrings ["/"] ["%2F"] url;
@@ -41,7 +57,7 @@ let
prometheus_listen_addr = "localhost:9236"
[git]
bin_path = "${pkgs.git}/bin/git"
bin_path = "${gitPackage}/bin/git"
[gitaly-ruby]
dir = "${cfg.packages.gitaly.ruby}"
@@ -137,7 +153,7 @@ let
};
workhorse.secret_file = "${cfg.statePath}/.gitlab_workhorse_secret";
gitlab_kas.secret_file = "${cfg.statePath}/.gitlab_kas_secret";
git.bin_path = "git";
git.bin_path = "${gitPackage}/bin/git";
monitoring = {
ip_whitelist = [ "127.0.0.0/8" "::1/128" ];
sidekiq_exporter = {
@@ -152,7 +168,7 @@ let
port = cfg.registry.externalPort;
key = cfg.registry.keyFile;
api_url = "http://${config.services.dockerRegistry.listenAddress}:${toString config.services.dockerRegistry.port}/";
issuer = "gitlab-issuer";
issuer = cfg.registry.issuer;
};
extra = {};
uploads.storage_path = cfg.statePath;
@@ -1047,7 +1063,7 @@ in {
chown ${cfg.user}:${cfg.group} ${cfg.registry.certFile}
'';
serviceConfig = {
unitConfig = {
ConditionPathExists = "!${cfg.registry.certFile}";
};
};
@@ -1275,7 +1291,7 @@ in {
});
path = with pkgs; [
postgresqlPackage
git
gitPackage
ruby
openssh
nodejs
@@ -1306,7 +1322,7 @@ in {
path = with pkgs; [
openssh
procps # See https://gitlab.com/gitlab-org/gitaly/issues/1562
git
gitPackage
cfg.packages.gitaly.rubyEnv
cfg.packages.gitaly.rubyEnv.wrappedRuby
gzip
@@ -1351,7 +1367,7 @@ in {
partOf = [ "gitlab.target" ];
path = with pkgs; [
exiftool
git
gitPackage
gnutar
gzip
openssh
@@ -1412,7 +1428,7 @@ in {
environment = gitlabEnv;
path = with pkgs; [
postgresqlPackage
git
gitPackage
openssh
nodejs
procps

View File

@@ -47,7 +47,7 @@ in
user-icons = mkOption {
type = types.nullOr (types.enum [ "gravatar" "identicon" ]);
default = null;
description = "User icons for history view";
description = "Enable specific user icons for history view";
};
emoji = mkOption {
@@ -68,6 +68,12 @@ in
description = "Disable editing pages";
};
local-time = mkOption {
type = types.bool;
default = false;
description = "Use the browser's local timezone instead of the server's for displaying dates.";
};
branch = mkOption {
type = types.str;
default = "master";
@@ -123,6 +129,7 @@ in
${optionalString cfg.emoji "--emoji"} \
${optionalString cfg.h1-title "--h1-title"} \
${optionalString cfg.no-edit "--no-edit"} \
${optionalString cfg.local-time "--local-time"} \
${optionalString (cfg.allowUploads != null) "--allow-uploads ${cfg.allowUploads}"} \
${optionalString (cfg.user-icons != null) "--user-icons ${cfg.user-icons}"} \
${cfg.stateDir}

View File

@@ -53,7 +53,10 @@ in
User = cfg.user;
Group = cfg.group;
StateDirectory = "jellyfin";
StateDirectoryMode = "0700";
CacheDirectory = "jellyfin";
CacheDirectoryMode = "0700";
UMask = "0077";
ExecStart = "${cfg.package}/bin/jellyfin --datadir '/var/lib/${StateDirectory}' --cachedir '/var/cache/${CacheDirectory}'";
Restart = "on-failure";

View File

@@ -395,6 +395,7 @@ in
str
int
bool
path
package
]);
in
@@ -734,7 +735,7 @@ in
CPUSchedulingPolicy = cfg.daemonCPUSchedPolicy;
IOSchedulingClass = cfg.daemonIOSchedClass;
IOSchedulingPriority = cfg.daemonIOSchedPriority;
LimitNOFILE = 4096;
LimitNOFILE = 1048576;
};
restartTriggers = [ nixConf ];

View File

@@ -3,6 +3,7 @@
with lib;
let
cfg = config.services.paperless;
pkg = cfg.package;
defaultUser = "paperless";
@@ -25,7 +26,7 @@ let
setupEnv = lib.concatStringsSep "\n" (mapAttrsToList (name: val: "export ${name}=\"${val}\"") env);
in pkgs.writeShellScript "manage" ''
${setupEnv}
exec ${cfg.package}/bin/paperless-ngx "$@"
exec ${pkg}/bin/paperless-ngx "$@"
'';
# Secure the services
@@ -174,11 +175,10 @@ in
See <link xlink:href="https://paperless-ngx.readthedocs.io/en/latest/configuration.html">the documentation</link>
for available options.
'';
example = literalExpression ''
{
PAPERLESS_OCR_LANGUAGE = "deu+eng";
}
'';
example = {
PAPERLESS_OCR_LANGUAGE = "deu+eng";
PAPERLESS_DBHOST = "/run/postgresql";
};
};
user = mkOption {
@@ -212,7 +212,7 @@ in
description = "Paperless scheduler";
serviceConfig = defaultServiceConfig // {
User = cfg.user;
ExecStart = "${cfg.package}/bin/paperless-ngx qcluster";
ExecStart = "${pkg}/bin/paperless-ngx qcluster";
Restart = "on-failure";
# The `mbind` syscall is needed for running the classifier.
SystemCallFilter = defaultServiceConfig.SystemCallFilter ++ [ "mbind" ];
@@ -228,9 +228,9 @@ in
# Auto-migrate on first run or if the package has changed
versionFile="${cfg.dataDir}/src-version"
if [[ $(cat "$versionFile" 2>/dev/null) != ${cfg.package} ]]; then
${cfg.package}/bin/paperless-ngx migrate
echo ${cfg.package} > "$versionFile"
if [[ $(cat "$versionFile" 2>/dev/null) != ${pkg} ]]; then
${pkg}/bin/paperless-ngx migrate
echo ${pkg} > "$versionFile"
fi
''
+ optionalString (cfg.passwordFile != null) ''
@@ -240,7 +240,7 @@ in
superuserStateFile="${cfg.dataDir}/superuser-state"
if [[ $(cat "$superuserStateFile" 2>/dev/null) != $superuserState ]]; then
${cfg.package}/bin/paperless-ngx manage_superuser
${pkg}/bin/paperless-ngx manage_superuser
echo "$superuserState" > "$superuserStateFile"
fi
'';
@@ -265,7 +265,7 @@ in
description = "Paperless document consumer";
serviceConfig = defaultServiceConfig // {
User = cfg.user;
ExecStart = "${cfg.package}/bin/paperless-ngx document_consumer";
ExecStart = "${pkg}/bin/paperless-ngx document_consumer";
Restart = "on-failure";
};
environment = env;
@@ -280,21 +280,22 @@ in
serviceConfig = defaultServiceConfig // {
User = cfg.user;
ExecStart = ''
${pkgs.python3Packages.gunicorn}/bin/gunicorn \
-c ${cfg.package}/lib/paperless-ngx/gunicorn.conf.py paperless.asgi:application
${pkg.python.pkgs.gunicorn}/bin/gunicorn \
-c ${pkg}/lib/paperless-ngx/gunicorn.conf.py paperless.asgi:application
'';
Restart = "on-failure";
AmbientCapabilities = "CAP_NET_BIND_SERVICE";
CapabilityBoundingSet = "CAP_NET_BIND_SERVICE";
# gunicorn needs setuid
SystemCallFilter = defaultServiceConfig.SystemCallFilter ++ [ "@setuid" ];
# gunicorn needs setuid, liblapack needs mbind
SystemCallFilter = defaultServiceConfig.SystemCallFilter ++ [ "@setuid mbind" ];
# Needs to serve web page
PrivateNetwork = false;
} // lib.optionalAttrs (cfg.port < 1024) {
AmbientCapabilities = [ "CAP_NET_BIND_SERVICE" ];
CapabilityBoundingSet = [ "CAP_NET_BIND_SERVICE" ];
};
environment = env // {
PATH = mkForce cfg.package.path;
PYTHONPATH = "${cfg.package.pythonPath}:${cfg.package}/lib/paperless-ngx/src";
PATH = mkForce pkg.path;
PYTHONPATH = "${pkg.python.pkgs.makePythonPath pkg.propagatedBuildInputs}:${pkg}/lib/paperless-ngx/src";
};
# Allow the web interface to access the private /tmp directory of the server.
# This is required to support uploading files via the web interface.

View File

@@ -186,7 +186,7 @@ in {
description = "Real time performance monitoring";
after = [ "network.target" ];
wantedBy = [ "multi-user.target" ];
path = (with pkgs; [ curl gawk iproute2 which procps ])
path = (with pkgs; [ curl gawk iproute2 which procps bash ])
++ lib.optional cfg.python.enable (pkgs.python3.withPackages cfg.python.extraPackages)
++ lib.optional config.virtualisation.libvirtd.enable (config.virtualisation.libvirtd.package);
environment = {

View File

@@ -74,11 +74,13 @@ in
};
};
serviceOpts = {
after = mkIf cfg.systemd.enable [ cfg.systemd.unit ];
serviceConfig = {
DynamicUser = false;
# By default, each prometheus exporter only gets AF_INET & AF_INET6,
# but AF_UNIX is needed to read from the `showq`-socket.
RestrictAddressFamilies = [ "AF_UNIX" ];
SupplementaryGroups = mkIf cfg.systemd.enable [ "systemd-journal" ];
ExecStart = ''
${pkgs.prometheus-postfix-exporter}/bin/postfix_exporter \
--web.listen-address ${cfg.listenAddress}:${toString cfg.port} \

View File

@@ -57,9 +57,9 @@ in {
${pkgs.prometheus-wireguard-exporter}/bin/prometheus_wireguard_exporter \
-p ${toString cfg.port} \
-l ${cfg.listenAddress} \
${optionalString cfg.verbose "-v"} \
${optionalString cfg.singleSubnetPerField "-s"} \
${optionalString cfg.withRemoteIp "-r"} \
${optionalString cfg.verbose "-v true"} \
${optionalString cfg.singleSubnetPerField "-s true"} \
${optionalString cfg.withRemoteIp "-r true"} \
${optionalString (cfg.wireguardConfig != null) "-n ${escapeShellArg cfg.wireguardConfig}"}
'';
RestrictAddressFamilies = [

View File

@@ -283,7 +283,7 @@ in
User = cfg.user;
Group = cfg.group;
StateDirectory = "";
ReadWritePaths = [ "" cfg.dataDir ];
ReadWritePaths = optionals (!cfg.autoMount) [ "" cfg.dataDir ];
} // optionalAttrs (cfg.serviceFdlimit != null) { LimitNOFILE = cfg.serviceFdlimit; };
} // optionalAttrs (!cfg.startWhenNeeded) {
wantedBy = [ "default.target" ];

View File

@@ -174,6 +174,7 @@ in
serviceConfig = {
DynamicUser = true;
StateDirectory = "bitlbee";
ReadWritePaths = [ cfg.configDir ];
ExecStart = "${bitlbeePkg}/sbin/bitlbee -F -n -c ${bitlbeeConfig}";
};
};

View File

@@ -13,7 +13,7 @@ let
foreground=YES
use=${cfg.use}
login=${cfg.username}
password=${lib.optionalString (cfg.protocol == "nsupdate") "/run/${RuntimeDirectory}/ddclient.key"}
password=${if cfg.protocol == "nsupdate" then "/run/${RuntimeDirectory}/ddclient.key" else "@password_placeholder@"}
protocol=${cfg.protocol}
${lib.optionalString (cfg.script != "") "script=${cfg.script}"}
${lib.optionalString (cfg.server != "") "server=${cfg.server}"}
@@ -33,10 +33,9 @@ let
${lib.optionalString (cfg.configFile == null) (if (cfg.protocol == "nsupdate") then ''
install ${cfg.passwordFile} /run/${RuntimeDirectory}/ddclient.key
'' else if (cfg.passwordFile != null) then ''
password=$(printf "%q" "$(head -n 1 "${cfg.passwordFile}")")
sed -i "s|^password=$|password=$password|" /run/${RuntimeDirectory}/ddclient.conf
"${pkgs.replace-secret}/bin/replace-secret" "@password_placeholder@" "${cfg.passwordFile}" "/run/${RuntimeDirectory}/ddclient.conf"
'' else ''
sed -i '/^password=$/d' /run/${RuntimeDirectory}/ddclient.conf
sed -i '/^password=@password_placeholder@$/d' /run/${RuntimeDirectory}/ddclient.conf
'')}
'';

View File

@@ -20,19 +20,23 @@ let
ips = [ "9.9.9.9" "149.112.112.112" ];
url = "https://dns.quad9.net/dns-query";
};
opendns = {
ips = [ "208.67.222.222" "208.67.220.220" ];
url = "https://doh.opendns.com/dns-query";
};
custom = {
inherit (cfg.provider) ips url;
};
};
defaultProvider = "quad9";
providerCfg =
let
isCustom = cfg.provider.kind == "custom";
in
lib.concatStringsSep " " [
concatStringsSep " " [
"-b"
(concatStringsSep "," (if isCustom then cfg.provider.ips else providers."${cfg.provider.kind}".ips))
(concatStringsSep "," providers."${cfg.provider.kind}".ips)
"-r"
(if isCustom then cfg.provider.url else providers."${cfg.provider.kind}".url)
providers."${cfg.provider.kind}".url
];
in
@@ -62,14 +66,16 @@ in
The upstream provider to use or custom in case you do not trust any of
the predefined providers or just want to use your own.
The default is ${defaultProvider} and there are privacy and security trade-offs
when using any upstream provider. Please consider that before using any
of them.
The default is ${defaultProvider} and there are privacy and security
trade-offs when using any upstream provider. Please consider that
before using any of them.
If you pick a custom provider, you will need to provide the bootstrap
IP addresses as well as the resolver https URL.
Supported providers: ${concatStringsSep ", " (builtins.attrNames providers)}
If you pick the custom provider, you will need to provide the
bootstrap IP addresses as well as the resolver https URL.
'';
type = types.enum ((builtins.attrNames providers) ++ [ "custom" ]);
type = types.enum (builtins.attrNames providers);
default = defaultProvider;
};
@@ -105,14 +111,18 @@ in
config = lib.mkIf cfg.enable {
systemd.services.https-dns-proxy = {
description = "DNS to DNS over HTTPS (DoH) proxy";
requires = [ "network.target" ];
after = [ "network.target" ];
wants = [ "nss-lookup.target" ];
before = [ "nss-lookup.target" ];
wantedBy = [ "multi-user.target" ];
serviceConfig = rec {
Type = "exec";
DynamicUser = true;
ProtectHome = "tmpfs";
ExecStart = lib.concatStringsSep " " (
[
"${pkgs.https-dns-proxy}/bin/https_dns_proxy"
(lib.getExe pkgs.https-dns-proxy)
"-a ${toString cfg.address}"
"-p ${toString cfg.port}"
"-l -"

View File

@@ -9,6 +9,12 @@ let
};
interfaceOptions = {
options = {
autoStart = mkOption {
default = true;
description = "Whether this VPN connection should be started automatically.";
type = types.bool;
};
gateway = mkOption {
description = "Gateway server to connect to.";
example = "gateway.example.com";
@@ -95,7 +101,7 @@ let
description = "OpenConnect Interface - ${name}";
requires = [ "network-online.target" ];
after = [ "network.target" "network-online.target" ];
wantedBy = [ "multi-user.target" ];
wantedBy = optional icfg.autoStart "multi-user.target";
serviceConfig = {
Type = "simple";

View File

@@ -0,0 +1,84 @@
{ config
, lib
, pkgs
, ...
}:
with lib;
let
cfg = config.services.routedns;
settingsFormat = pkgs.formats.toml { };
in
{
options.services.routedns = {
enable = mkEnableOption "RouteDNS - DNS stub resolver, proxy and router";
settings = mkOption {
type = settingsFormat.type;
example = literalExpression ''
{
resolvers.cloudflare-dot = {
address = "1.1.1.1:853";
protocol = "dot";
};
groups.cloudflare-cached = {
type = "cache";
resolvers = ["cloudflare-dot"];
};
listeners.local-udp = {
address = "127.0.0.1:53";
protocol = "udp";
resolver = "cloudflare-cached";
};
listeners.local-tcp = {
address = "127.0.0.1:53";
protocol = "tcp";
resolver = "cloudflare-cached";
};
}
'';
description = ''
Configuration for RouteDNS, see <link xlink:href="https://github.com/folbricht/routedns/blob/master/doc/configuration.md"/>
for more information.
'';
};
configFile = mkOption {
default = settingsFormat.generate "routedns.toml" cfg.settings;
defaultText = "A RouteDNS configuration file automatically generated by values from services.routedns.*";
type = types.path;
example = literalExpression ''"''${pkgs.routedns}/cmd/routedns/example-config/use-case-1.toml"'';
description = "Path to RouteDNS TOML configuration file.";
};
package = mkOption {
default = pkgs.routedns;
defaultText = literalExpression "pkgs.routedns";
type = types.package;
description = "RouteDNS package to use.";
};
};
config = mkIf cfg.enable {
systemd.services.routedns = {
description = "RouteDNS - DNS stub resolver, proxy and router";
after = [ "network.target" ]; # in case a bootstrap resolver is used, this might fail a few times until the respective server is actually reachable
wantedBy = [ "multi-user.target" ];
wants = [ "network.target" ];
startLimitIntervalSec = 30;
startLimitBurst = 5;
serviceConfig = {
Restart = "on-failure";
RestartSec = "5s";
LimitNPROC = 512;
LimitNOFILE = 1048576;
DynamicUser = true;
AmbientCapabilities = "CAP_NET_BIND_SERVICE";
NoNewPrivileges = true;
ExecStart = "${getBin cfg.package}/bin/routedns -l 4 ${cfg.configFile}";
};
};
};
meta.maintainers = with maintainers; [ jsimonetti ];
}

View File

@@ -19,6 +19,8 @@ let
MEDIA_ROOT = '${seahubDir}/media/'
THUMBNAIL_ROOT = '${seahubDir}/thumbnail/'
SERVICE_URL = '${cfg.ccnetSettings.General.SERVICE_URL}'
with open('${seafRoot}/.seahubSecret') as f:
SECRET_KEY = f.readline().rstrip()
@@ -177,6 +179,7 @@ in {
after = [ "network.target" ];
wantedBy = [ "seafile.target" ];
restartTriggers = [ ccnetConf seafileConf ];
path = [ pkgs.sqlite ];
serviceConfig = securityOptions // {
User = "seafile";
Group = "seafile";
@@ -200,11 +203,11 @@ in {
if [ ! -f "${seafRoot}/server-setup" ]; then
mkdir -p ${dataDir}/library-template
mkdir -p ${ccnetDir}/{GroupMgr,misc,OrgMgr,PeerMgr}
${pkgs.sqlite}/bin/sqlite3 ${ccnetDir}/GroupMgr/groupmgr.db ".read ${cfg.seafilePackage}/share/seafile/sql/sqlite/groupmgr.sql"
${pkgs.sqlite}/bin/sqlite3 ${ccnetDir}/misc/config.db ".read ${cfg.seafilePackage}/share/seafile/sql/sqlite/config.sql"
${pkgs.sqlite}/bin/sqlite3 ${ccnetDir}/OrgMgr/orgmgr.db ".read ${cfg.seafilePackage}/share/seafile/sql/sqlite/org.sql"
${pkgs.sqlite}/bin/sqlite3 ${ccnetDir}/PeerMgr/usermgr.db ".read ${cfg.seafilePackage}/share/seafile/sql/sqlite/user.sql"
${pkgs.sqlite}/bin/sqlite3 ${dataDir}/seafile.db ".read ${cfg.seafilePackage}/share/seafile/sql/sqlite/seafile.sql"
sqlite3 ${ccnetDir}/GroupMgr/groupmgr.db ".read ${cfg.seafilePackage}/share/seafile/sql/sqlite/groupmgr.sql"
sqlite3 ${ccnetDir}/misc/config.db ".read ${cfg.seafilePackage}/share/seafile/sql/sqlite/config.sql"
sqlite3 ${ccnetDir}/OrgMgr/orgmgr.db ".read ${cfg.seafilePackage}/share/seafile/sql/sqlite/org.sql"
sqlite3 ${ccnetDir}/PeerMgr/usermgr.db ".read ${cfg.seafilePackage}/share/seafile/sql/sqlite/user.sql"
sqlite3 ${dataDir}/seafile.db ".read ${cfg.seafilePackage}/share/seafile/sql/sqlite/seafile.sql"
echo "${cfg.seafilePackage.version}-sqlite" > "${seafRoot}"/server-setup
fi
# checking for upgrades and handling them
@@ -213,7 +216,14 @@ in {
installedMinor=$(cat "${seafRoot}/server-setup" | cut -d"-" -f1 | cut -d"." -f2)
pkgMajor=$(echo "${cfg.seafilePackage.version}" | cut -d"." -f1)
pkgMinor=$(echo "${cfg.seafilePackage.version}" | cut -d"." -f2)
if [ $installedMajor != $pkgMajor ] || [ $installedMinor != $pkgMinor ]; then
if [[ $installedMajor == $pkgMajor && $installedMinor == $pkgMinor ]]; then
:
elif [[ $installedMajor == 8 && $installedMinor == 0 && $pkgMajor == 9 && $pkgMinor == 0 ]]; then
# Upgrade from 8.0 to 9.0
sqlite3 ${dataDir}/seafile.db ".read ${pkgs.seahub}/scripts/upgrade/sql/9.0.0/sqlite3/seafile.sql"
echo "${cfg.seafilePackage.version}-sqlite" > "${seafRoot}"/server-setup
else
echo "Unsupported upgrade" >&2
exit 1
fi

View File

@@ -49,12 +49,14 @@ in
tlsCertificate = mkOption {
type = types.nullOr types.path;
default = null;
example = "/var/host.cert";
description = "Path to server TLS certificate.";
};
tlsCertificateKey = mkOption {
type = types.nullOr types.path;
default = null;
example = "/var/host.key";
description = "Path to server TLS certificate key.";
};
@@ -97,6 +99,16 @@ in
###### implementation
config = mkIf cfg.enable {
assertions = [
{
assertion = (cfg.tlsCertificate != null) == (cfg.tlsCertificateKey != null);
message = ''
services.soju.tlsCertificate and services.soju.tlsCertificateKey
must both be specified to enable TLS.
'';
}
];
systemd.services.soju = {
description = "soju IRC bouncer";
wantedBy = [ "multi-user.target" ];

View File

@@ -30,15 +30,22 @@ let
updateConfig = pkgs.writers.writeDash "merge-syncthing-config" ''
set -efu
# be careful not to leak secrets in the filesystem or in process listings
umask 0077
# get the api key by parsing the config.xml
while
! api_key=$(${pkgs.libxml2}/bin/xmllint \
! ${pkgs.libxml2}/bin/xmllint \
--xpath 'string(configuration/gui/apikey)' \
${cfg.configDir}/config.xml)
${cfg.configDir}/config.xml \
>"$RUNTIME_DIRECTORY/api_key"
do sleep 1; done
(printf "X-API-Key: "; cat "$RUNTIME_DIRECTORY/api_key") >"$RUNTIME_DIRECTORY/headers"
curl() {
${pkgs.curl}/bin/curl -sSLk -H "X-API-Key: $api_key" \
${pkgs.curl}/bin/curl -sSLk -H "@$RUNTIME_DIRECTORY/headers" \
--retry 1000 --retry-delay 1 --retry-all-errors \
"$@"
}
@@ -525,6 +532,8 @@ in {
};
systemd.services = {
# upstream reference:
# https://github.com/syncthing/syncthing/blob/main/etc/linux-systemd/system/syncthing%40.service
syncthing = mkIf cfg.systemService {
description = "Syncthing service";
after = [ "network.target" ];
@@ -536,7 +545,7 @@ in {
wantedBy = [ "multi-user.target" ];
serviceConfig = {
Restart = "on-failure";
SuccessExitStatus = "2 3 4";
SuccessExitStatus = "3 4";
RestartForceExitStatus="3 4";
User = cfg.user;
Group = cfg.group;
@@ -588,6 +597,7 @@ in {
serviceConfig = {
User = cfg.user;
RemainAfterExit = true;
RuntimeDirectory = "syncthing-init";
Type = "oneshot";
ExecStart = updateConfig;
};

View File

@@ -114,7 +114,7 @@ let
script =
''
${optionalString configIsGenerated ''
${optionalString (configIsGenerated && !cfg.allowAuxiliaryImperativeNetworks) ''
if [ -f /etc/wpa_supplicant.conf ]; then
echo >&2 "<3>/etc/wpa_supplicant.conf present but ignored. Generated ${configFile} is used instead."
fi

View File

@@ -91,8 +91,9 @@ in
example = "nftables-multiport";
description = ''
Default banning action (e.g. iptables, iptables-new, iptables-multiport,
shorewall, etc) It is used to define action_* variables. Can be overridden
globally or per section within jail.local file
iptables-ipset-proto6-allports, shorewall, etc) It is used to
define action_* variables. Can be overridden globally or per
section within jail.local file
'';
};
@@ -212,10 +213,18 @@ in
filter = apache-nohome
action = iptables-multiport[name=HTTP, port="http,https"]
logpath = /var/log/httpd/error_log*
backend = auto
findtime = 600
bantime = 600
maxretry = 5
''';
dovecot = '''
# block IPs which failed to log-in
# aggressive mode add blocking for aborted connections
enabled = true
filter = dovecot[mode=aggressive]
maxretry = 3
''';
}
'';
type = types.attrsOf types.lines;

View File

@@ -248,6 +248,8 @@ in
"-/etc/localtime"
"-/etc/kanidm"
"-/etc/static/kanidm"
"-/etc/ssl"
"-/etc/static/ssl"
];
BindPaths = [
# To create the socket

View File

@@ -6,7 +6,7 @@ let
cfg = config.services.privacyidea;
opt = options.services.privacyidea;
uwsgi = pkgs.uwsgi.override { plugins = [ "python3" ]; };
uwsgi = pkgs.uwsgi.override { plugins = [ "python3" ]; python3 = pkgs.python39; };
python = uwsgi.python3;
penv = python.withPackages (const [ pkgs.privacyidea ]);
logCfg = pkgs.writeText "privacyidea-log.cfg" ''

View File

@@ -17,12 +17,24 @@ in {
defaultText = "config.networking.hostName";
};
verbose = mkOption {
type = types.bool;
description = "Enable verbose output";
default = false;
};
profile = mkOption {
type = types.nullOr types.str;
default = null;
description = "Profile name, defaults to 'system' (NixOS).";
};
host = mkOption {
type = types.nullOr types.str;
default = null;
description = "Cachix uri to use.";
};
package = mkOption {
type = types.package;
default = pkgs.cachix;
@@ -45,12 +57,22 @@ in {
after = ["network-online.target"];
path = [ config.nix.package ];
wantedBy = [ "multi-user.target" ];
# don't restart while changing
reloadIfChanged = true;
# Cachix requires $USER to be set
environment.USER = "root";
# don't stop the service if the unit disappears
unitConfig.X-StopOnRemoval = false;
serviceConfig = {
# we don't want to kill children processes as those are deployments
KillMode = "process";
Restart = "on-failure";
EnvironmentFile = cfg.credentialsFile;
ExecStart = "${cfg.package}/bin/cachix deploy agent ${cfg.name} ${if cfg.profile != null then profile else ""}";
ExecStart = ''
${cfg.package}/bin/cachix ${lib.optionalString cfg.verbose "--verbose"} ${lib.optionalString (cfg.host != null) "--host ${cfg.host}"} \
deploy agent ${cfg.name} ${if cfg.profile != null then cfg.profile else ""}
'';
};
};
};

View File

@@ -0,0 +1,87 @@
{ config, pkgs, lib, ... }:
with lib;
let
cfg = config.services.cachix-watch-store;
in
{
meta.maintainers = [ lib.maintainers.jfroche lib.maintainers.domenkozar ];
options.services.cachix-watch-store = {
enable = mkEnableOption "Cachix Watch Store: https://docs.cachix.org";
cacheName = mkOption {
type = types.str;
description = "Cachix binary cache name";
};
cachixTokenFile = mkOption {
type = types.path;
description = ''
Required file that needs to contain the cachix auth token.
'';
};
compressionLevel = mkOption {
type = types.nullOr types.int;
description = "The compression level for XZ compression (between 0 and 9)";
default = null;
};
jobs = mkOption {
type = types.nullOr types.int;
description = "Number of threads used for pushing store paths";
default = null;
};
host = mkOption {
type = types.nullOr types.str;
default = null;
description = "Cachix host to connect to";
};
verbose = mkOption {
type = types.bool;
description = "Enable verbose output";
default = false;
};
package = mkOption {
type = types.package;
default = pkgs.cachix;
defaultText = literalExpression "pkgs.cachix";
description = "Cachix Client package to use.";
};
};
config = mkIf cfg.enable {
systemd.services.cachix-watch-store-agent = {
description = "Cachix watch store Agent";
after = [ "network-online.target" ];
path = [ config.nix.package ];
wantedBy = [ "multi-user.target" ];
serviceConfig = {
# we don't want to kill children processes as those are deployments
KillMode = "process";
Restart = "on-failure";
DynamicUser = true;
LoadCredential = [
"cachix-token:${toString cfg.cachixTokenFile}"
];
};
script =
let
command = [ "${cfg.package}/bin/cachix" ]
++ (lib.optional cfg.verbose "--verbose") ++ (lib.optionals (cfg.host != null) [ "--host" cfg.host ])
++ [ "watch-store" ] ++ (lib.optionals (cfg.compressionLevel != null) [ "--compression-level" (toString cfg.compressionLevel) ])
++ (lib.optionals (cfg.jobs != null) [ "--jobs" (toString cfg.jobs) ]) ++ [ cfg.cacheName ];
in
''
export CACHIX_AUTH_TOKEN="$(<"$CREDENTIALS_DIRECTORY/cachix-token")"
${lib.escapeShellArgs command}
'';
};
};
}

View File

@@ -189,6 +189,7 @@ in
CHANNELS_CONFIG_PATH = "/etc/mirakurun/channels.yml";
SERVICES_DB_PATH = "/var/lib/mirakurun/services.json";
PROGRAMS_DB_PATH = "/var/lib/mirakurun/programs.json";
LOGO_DATA_DIR_PATH = "/var/lib/mirakurun/logos";
NODE_ENV = "production";
};

View File

@@ -8,21 +8,22 @@ let
pkg = cfg.package.override (optionalAttrs cfg.sso.enable {
enableSSO = cfg.sso.enable;
crowdProperties = ''
application.name ${cfg.sso.applicationName}
application.password ${cfg.sso.applicationPassword}
application.login.url ${cfg.sso.crowd}/console/
crowd.server.url ${cfg.sso.crowd}/services/
crowd.base.url ${cfg.sso.crowd}/
session.isauthenticated session.isauthenticated
session.tokenkey session.tokenkey
session.validationinterval ${toString cfg.sso.validationInterval}
session.lastvalidation session.lastvalidation
'';
});
crowdProperties = pkgs.writeText "crowd.properties" ''
application.name ${cfg.sso.applicationName}
application.password ${if cfg.sso.applicationPassword != null then cfg.sso.applicationPassword else "@NIXOS_CONFLUENCE_CROWD_SSO_PWD@"}
application.login.url ${cfg.sso.crowd}/console/
crowd.server.url ${cfg.sso.crowd}/services/
crowd.base.url ${cfg.sso.crowd}/
session.isauthenticated session.isauthenticated
session.tokenkey session.tokenkey
session.validationinterval ${toString cfg.sso.validationInterval}
session.lastvalidation session.lastvalidation
'';
in
{
@@ -107,10 +108,17 @@ in
};
applicationPassword = mkOption {
type = types.str;
type = types.nullOr types.str;
default = null;
description = "Application password of this Confluence instance in Crowd";
};
applicationPasswordFile = mkOption {
type = types.nullOr types.str;
default = null;
description = "Path to the application password for Crowd of Confluence.";
};
validationInterval = mkOption {
type = types.int;
default = 2;
@@ -147,6 +155,16 @@ in
group = cfg.group;
};
assertions = [
{ assertion = cfg.sso.enable -> ((cfg.sso.applicationPassword == null) != (cfg.sso.applicationPasswordFile));
message = "Please set either applicationPassword or applicationPasswordFile";
}
];
warnings = mkIf (cfg.sso.enable && cfg.sso.applicationPassword != null) [
"Using `services.confluence.sso.applicationPassword` is deprecated! Use `applicationPasswordFile` instead!"
];
users.groups.${cfg.group} = {};
systemd.tmpfiles.rules = [
@@ -173,6 +191,7 @@ in
CONF_USER = cfg.user;
JAVA_HOME = "${cfg.jrePackage}";
CATALINA_OPTS = concatStringsSep " " cfg.catalinaOptions;
JAVA_OPTS = mkIf cfg.sso.enable "-Dcrowd.properties=${cfg.home}/crowd.properties";
};
preStart = ''
@@ -183,6 +202,16 @@ in
-e 's,protocol="org.apache.coyote.http11.Http11NioProtocol",protocol="org.apache.coyote.http11.Http11NioProtocol" proxyName="${cfg.proxy.name}" proxyPort="${toString cfg.proxy.port}" scheme="${cfg.proxy.scheme}",' \
'') + ''
${pkg}/conf/server.xml.dist > ${cfg.home}/server.xml
${optionalString cfg.sso.enable ''
install -m660 ${crowdProperties} ${cfg.home}/crowd.properties
${optionalString (cfg.sso.applicationPasswordFile != null) ''
${pkgs.replace-secret}/bin/replace-secret \
'@NIXOS_CONFLUENCE_CROWD_SSO_PWD@' \
${cfg.sso.applicationPasswordFile} \
${cfg.home}/crowd.properties
''}
''}
'';
serviceConfig = {

View File

@@ -6,7 +6,7 @@ let
cfg = config.services.discourse;
opt = options.services.discourse;
# Keep in sync with https://github.com/discourse/discourse_docker/blob/master/image/base/Dockerfile#L5
# Keep in sync with https://github.com/discourse/discourse_docker/blob/main/image/base/slim.Dockerfile#L5
upstreamPostgresqlVersion = lib.getVersion pkgs.postgresql_13;
postgresqlPackage = if config.services.postgresql.enable then
@@ -604,7 +604,6 @@ in
cors_origin = "";
serve_static_assets = false;
sidekiq_workers = 5;
rtl_css = false;
connection_reaper_age = 30;
connection_reaper_interval = 30;
relative_url_root = null;
@@ -940,7 +939,6 @@ in
proxy_cache discourse;
proxy_cache_key "$scheme,$host,$request_uri";
proxy_cache_valid 200 301 302 7d;
proxy_cache_valid any 1m;
'';
};
"/message-bus/" = proxy {

View File

@@ -253,9 +253,20 @@ in
'';
};
};
systemd.services.prosody.serviceConfig = mkIf cfg.prosody.enable {
EnvironmentFile = [ "/var/lib/jitsi-meet/secrets-env" ];
SupplementaryGroups = [ "jitsi-meet" ];
systemd.services.prosody = mkIf cfg.prosody.enable {
preStart = let
videobridgeSecret = if cfg.videobridge.passwordFile != null then cfg.videobridge.passwordFile else "/var/lib/jitsi-meet/videobridge-secret";
in ''
${config.services.prosody.package}/bin/prosodyctl register focus auth.${cfg.hostName} "$(cat /var/lib/jitsi-meet/jicofo-user-secret)"
${config.services.prosody.package}/bin/prosodyctl register jvb auth.${cfg.hostName} "$(cat ${videobridgeSecret})"
${config.services.prosody.package}/bin/prosodyctl mod_roster_command subscribe focus.${cfg.hostName} focus@auth.${cfg.hostName}
${config.services.prosody.package}/bin/prosodyctl register jibri auth.${cfg.hostName} "$(cat /var/lib/jitsi-meet/jibri-auth-secret)"
${config.services.prosody.package}/bin/prosodyctl register recorder recorder.${cfg.hostName} "$(cat /var/lib/jitsi-meet/jibri-recorder-secret)"
'';
serviceConfig = {
EnvironmentFile = [ "/var/lib/jitsi-meet/secrets-env" ];
SupplementaryGroups = [ "jitsi-meet" ];
};
};
users.groups.jitsi-meet = {};
@@ -266,14 +277,12 @@ in
systemd.services.jitsi-meet-init-secrets = {
wantedBy = [ "multi-user.target" ];
before = [ "jicofo.service" "jitsi-videobridge2.service" ] ++ (optional cfg.prosody.enable "prosody.service");
path = [ config.services.prosody.package ];
serviceConfig = {
Type = "oneshot";
};
script = let
secrets = [ "jicofo-component-secret" "jicofo-user-secret" "jibri-auth-secret" "jibri-recorder-secret" ] ++ (optional (cfg.videobridge.passwordFile == null) "videobridge-secret");
videobridgeSecret = if cfg.videobridge.passwordFile != null then cfg.videobridge.passwordFile else "/var/lib/jitsi-meet/videobridge-secret";
in
''
cd /var/lib/jitsi-meet
@@ -291,12 +300,6 @@ in
chmod 640 secrets-env
''
+ optionalString cfg.prosody.enable ''
prosodyctl register focus auth.${cfg.hostName} "$(cat /var/lib/jitsi-meet/jicofo-user-secret)"
prosodyctl register jvb auth.${cfg.hostName} "$(cat ${videobridgeSecret})"
prosodyctl mod_roster_command subscribe focus.${cfg.hostName} focus@auth.${cfg.hostName}
prosodyctl register jibri auth.${cfg.hostName} "$(cat /var/lib/jitsi-meet/jibri-auth-secret)"
prosodyctl register recorder recorder.${cfg.hostName} "$(cat /var/lib/jitsi-meet/jibri-recorder-secret)"
# generate self-signed certificates
if [ ! -f /var/lib/jitsi-meet.crt ]; then
${getBin pkgs.openssl}/bin/openssl req \

View File

@@ -164,7 +164,7 @@ in
wantedBy = [ "multi-user.target" ];
after = [ "pict-rs.service " ] ++ lib.optionals cfg.settings.database.createLocally [ "lemmy-postgresql.service" ];
after = [ "pict-rs.service" ] ++ lib.optionals cfg.settings.database.createLocally [ "lemmy-postgresql.service" ];
requires = lib.optionals cfg.settings.database.createLocally [ "lemmy-postgresql.service" ];

View File

@@ -475,7 +475,6 @@ in {
} // cfgService;
after = [ "network.target" ];
wantedBy = [ "multi-user.target" ];
};
systemd.services.mastodon-init-db = lib.mkIf cfg.automaticMigrations {
@@ -500,16 +499,21 @@ in {
# System Call Filtering
SystemCallFilter = [ ("~" + lib.concatStringsSep " " (systemCallsList ++ [ "@resources" ])) "@chown" "pipe" "pipe2" ];
} // cfgService;
after = [ "mastodon-init-dirs.service" "network.target" ] ++ (if databaseActuallyCreateLocally then [ "postgresql.service" ] else []);
wantedBy = [ "multi-user.target" ];
after = [ "network.target" "mastodon-init-dirs.service" ]
++ lib.optional databaseActuallyCreateLocally "postgresql.service";
requires = [ "mastodon-init-dirs.service" ]
++ lib.optional databaseActuallyCreateLocally "postgresql.service";
};
systemd.services.mastodon-streaming = {
after = [ "network.target" ]
++ (if databaseActuallyCreateLocally then [ "postgresql.service" ] else [])
++ (if cfg.automaticMigrations then [ "mastodon-init-db.service" ] else [ "mastodon-init-dirs.service" ]);
description = "Mastodon streaming";
after = [ "network.target" "mastodon-init-dirs.service" ]
++ lib.optional databaseActuallyCreateLocally "postgresql.service"
++ lib.optional cfg.automaticMigrations "mastodon-init-db.service";
requires = [ "mastodon-init-dirs.service" ]
++ lib.optional databaseActuallyCreateLocally "postgresql.service"
++ lib.optional cfg.automaticMigrations "mastodon-init-db.service";
wantedBy = [ "multi-user.target" ];
description = "Mastodon streaming";
environment = env // (if cfg.enableUnixSocket
then { SOCKET = "/run/mastodon-streaming/streaming.socket"; }
else { PORT = toString(cfg.streamingPort); }
@@ -529,11 +533,14 @@ in {
};
systemd.services.mastodon-web = {
after = [ "network.target" ]
++ (if databaseActuallyCreateLocally then [ "postgresql.service" ] else [])
++ (if cfg.automaticMigrations then [ "mastodon-init-db.service" ] else [ "mastodon-init-dirs.service" ]);
description = "Mastodon web";
after = [ "network.target" "mastodon-init-dirs.service" ]
++ lib.optional databaseActuallyCreateLocally "postgresql.service"
++ lib.optional cfg.automaticMigrations "mastodon-init-db.service";
requires = [ "mastodon-init-dirs.service" ]
++ lib.optional databaseActuallyCreateLocally "postgresql.service"
++ lib.optional cfg.automaticMigrations "mastodon-init-db.service";
wantedBy = [ "multi-user.target" ];
description = "Mastodon web";
environment = env // (if cfg.enableUnixSocket
then { SOCKET = "/run/mastodon-web/web.socket"; }
else { PORT = toString(cfg.webPort); }
@@ -554,11 +561,14 @@ in {
};
systemd.services.mastodon-sidekiq = {
after = [ "network.target" ]
++ (if databaseActuallyCreateLocally then [ "postgresql.service" ] else [])
++ (if cfg.automaticMigrations then [ "mastodon-init-db.service" ] else [ "mastodon-init-dirs.service" ]);
description = "Mastodon sidekiq";
after = [ "network.target" "mastodon-init-dirs.service" ]
++ lib.optional databaseActuallyCreateLocally "postgresql.service"
++ lib.optional cfg.automaticMigrations "mastodon-init-db.service";
requires = [ "mastodon-init-dirs.service" ]
++ lib.optional databaseActuallyCreateLocally "postgresql.service"
++ lib.optional cfg.automaticMigrations "mastodon-init-db.service";
wantedBy = [ "multi-user.target" ];
description = "Mastodon sidekiq";
environment = env // {
PORT = toString(cfg.sidekiqPort);
DB_POOL = toString cfg.sidekiqThreads;
@@ -629,7 +639,7 @@ in {
inherit (cfg) group;
};
})
(lib.attrsets.setAttrByPath [ cfg.user "packages" ] [ cfg.package mastodonEnv ])
(lib.attrsets.setAttrByPath [ cfg.user "packages" ] [ cfg.package mastodonEnv pkgs.imagemagick ])
];
users.groups.${cfg.group}.members = lib.optional cfg.configureNginx config.services.nginx.user;

View File

@@ -153,7 +153,7 @@ in {
package = mkOption {
type = types.package;
description = "Which package to use for the Nextcloud instance.";
relatedPackages = [ "nextcloud23" "nextcloud24" ];
relatedPackages = [ "nextcloud23" "nextcloud24" "nextcloud25" ];
};
phpPackage = mkOption {
type = types.package;
@@ -568,7 +568,7 @@ in {
config = mkIf cfg.enable (mkMerge [
{ warnings = let
latest = 24;
latest = 25;
upgradeWarning = major: nixos:
''
A legacy Nextcloud install (from before NixOS ${nixos}) may be installed.
@@ -633,8 +633,13 @@ in {
services.nextcloud.phpPackage =
if versionOlder cfg.package.version "21" then pkgs.php74
else if versionOlder cfg.package.version "24" then pkgs.php80
else pkgs.php81;
# FIXME: Use PHP 8.1 with Nextcloud 24 and higher, once issues like this one are fixed:
#
# https://github.com/nextcloud/twofactor_totp/issues/1192
#
# else if versionOlder cfg.package.version "24" then pkgs.php80
# else pkgs.php81;
else pkgs.php80;
}
{ assertions = [
@@ -728,7 +733,7 @@ in {
'trusted_domains' => ${writePhpArrary ([ cfg.hostName ] ++ c.extraTrustedDomains)},
'trusted_proxies' => ${writePhpArrary (c.trustedProxies)},
${optionalString (c.defaultPhoneRegion != null) "'default_phone_region' => '${c.defaultPhoneRegion}',"}
${optionalString (nextcloudGreaterOrEqualThan "23") "'profile.enabled' => ${boolToString cfg.globalProfiles}"}
${optionalString (nextcloudGreaterOrEqualThan "23") "'profile.enabled' => ${boolToString cfg.globalProfiles},"}
${objectstoreConfig}
];
'';

View File

@@ -11,8 +11,8 @@
desktop client is packaged at <literal>pkgs.nextcloud-client</literal>.
</para>
<para>
The current default by NixOS is <package>nextcloud24</package> which is also the latest
major version available.
The current default by NixOS is <package>nextcloud24</package>. The latest version available
is <package>nextcloud25</package>.
</para>
<section xml:id="module-services-nextcloud-basic-usage">
<title>Basic usage</title>

View File

@@ -11,6 +11,7 @@ let
NODE_CONFIG_DIR = "/var/lib/peertube/config";
NODE_ENV = "production";
NODE_EXTRA_CA_CERTS = "/etc/ssl/certs/ca-certificates.crt";
NPM_CONFIG_CACHE = "/var/cache/peertube/.npm";
NPM_CONFIG_PREFIX = cfg.package;
HOME = cfg.package;
};
@@ -209,7 +210,7 @@ in {
port = lib.mkOption {
type = lib.types.nullOr lib.types.port;
default = if cfg.redis.createLocally && cfg.redis.enableUnixSocket then null else 6379;
default = if cfg.redis.createLocally && cfg.redis.enableUnixSocket then null else 31638;
defaultText = lib.literalExpression ''
if config.${opt.redis.createLocally} && config.${opt.redis.enableUnixSocket}
then null
@@ -344,7 +345,7 @@ in {
};
};
}
(lib.mkIf cfg.redis.enableUnixSocket { redis = { socket = "/run/redis/redis.sock"; }; })
(lib.mkIf cfg.redis.enableUnixSocket { redis = { socket = "/run/redis-peertube/redis.sock"; }; })
];
systemd.tmpfiles.rules = [
@@ -425,6 +426,9 @@ in {
# State directory and mode
StateDirectory = "peertube";
StateDirectoryMode = "0750";
# Cache directory and mode
CacheDirectory = "peertube";
CacheDirectoryMode = "0750";
# Access write directories
ReadWritePaths = cfg.dataDirs;
# Environment
@@ -441,13 +445,17 @@ in {
enable = true;
};
services.redis = lib.mkMerge [
services.redis.servers.peertube = lib.mkMerge [
(lib.mkIf cfg.redis.createLocally {
enable = true;
})
(lib.mkIf (cfg.redis.createLocally && !cfg.redis.enableUnixSocket) {
bind = "127.0.0.1";
port = cfg.redis.port;
})
(lib.mkIf (cfg.redis.createLocally && cfg.redis.enableUnixSocket) {
unixSocket = "/run/redis/redis.sock";
unixSocketPerm = 770;
unixSocket = "/run/redis-peertube/redis.sock";
unixSocketPerm = 660;
})
];
@@ -465,7 +473,7 @@ in {
};
})
(lib.attrsets.setAttrByPath [ cfg.user "packages" ] [ cfg.package peertubeEnv peertubeCli pkgs.ffmpeg pkgs.nodejs-16_x pkgs.yarn ])
(lib.mkIf cfg.redis.enableUnixSocket {${config.services.peertube.user}.extraGroups = [ "redis" ];})
(lib.mkIf cfg.redis.enableUnixSocket {${config.services.peertube.user}.extraGroups = [ "redis-peertube" ];})
];
users.groups = lib.optionalAttrs (cfg.group == "peertube") {

View File

@@ -472,6 +472,7 @@ in {
"d ${cfg.dataDir}/storage/framework/views 0700 ${user} ${group} - -"
"d ${cfg.dataDir}/storage/logs 0700 ${user} ${group} - -"
"d ${cfg.dataDir}/storage/uploads 0700 ${user} ${group} - -"
"d ${cfg.dataDir}/storage/private_uploads 0700 ${user} ${group} - -"
];
users = {

View File

@@ -1,80 +0,0 @@
{ config, lib, pkgs, ... }:
let
inherit (lib) mkEnableOption mkIf mkOption types literalExpression;
cfg = config.services.timetagger;
in {
options = {
services.timetagger = {
enable = mkOption {
type = types.bool;
default = false;
description = ''
Tag your time, get the insight
<note><para>
This app does not do authentication.
You must setup authentication yourself or run it in an environment where
only allowed users have access.
</para></note>
'';
};
bindAddr = mkOption {
description = "Address to bind to.";
type = types.str;
default = "127.0.0.1";
};
port = mkOption {
description = "Port to bind to.";
type = types.port;
default = 8080;
};
package = mkOption {
description = ''
Use own package for starting timetagger web application.
The ${literalExpression ''pkgs.timetagger''} package only provides a
"run.py" script for the actual package
${literalExpression ''pkgs.python3Packages.timetagger''}.
If you want to provide a "run.py" script for starting timetagger
yourself, you can do so with this option.
If you do so, the 'bindAddr' and 'port' options are ignored.
'';
default = pkgs.timetagger.override { addr = cfg.bindAddr; port = cfg.port; };
defaultText = literalExpression ''
pkgs.timetagger.override {
addr = ${cfg.bindAddr};
port = ${cfg.port};
};
'';
type = types.package;
};
};
};
config = mkIf cfg.enable {
systemd.services.timetagger = {
description = "Timetagger service";
wantedBy = [ "multi-user.target" ];
serviceConfig = {
User = "timetagger";
Group = "timetagger";
StateDirectory = "timetagger";
ExecStart = "${cfg.package}/bin/timetagger";
Restart = "on-failure";
RestartSec = 1;
};
};
};
}

View File

@@ -130,7 +130,7 @@ in {
WorkingDirectory = "/var/lib/${cfg.stateDirectoryName}";
DynamicUser = true;
PrivateTmp = true;
ExecStart = "${pkgs.nodejs}/bin/node ${pkgs.wiki-js}/server";
ExecStart = "${pkgs.nodejs-16_x}/bin/node ${pkgs.wiki-js}/server";
};
};
};

View File

@@ -102,7 +102,7 @@ in
systemd.services.minio = {
description = "Minio Object Storage";
after = [ "network.target" ];
after = [ "network-online.target" ];
wantedBy = [ "multi-user.target" ];
serviceConfig = {
ExecStart = "${cfg.package}/bin/minio server --json --address ${cfg.listenAddress} --console-address ${cfg.consoleAddress} --config-dir=${cfg.configDir} ${toString cfg.dataDir}";

View File

@@ -932,7 +932,7 @@ in
# System Call Filtering
SystemCallArchitectures = "native";
SystemCallFilter = [ "~@cpu-emulation @debug @keyring @mount @obsolete @privileged @setuid" ]
++ optionals ((cfg.package != pkgs.tengine) && (!lib.any (mod: (mod.disableIPC or false)) cfg.package.modules)) [ "~@ipc" ];
++ optionals ((cfg.package != pkgs.tengine) && (cfg.package != pkgs.openresty) && (!lib.any (mod: (mod.disableIPC or false)) cfg.package.modules)) [ "~@ipc" ];
};
};

View File

@@ -60,7 +60,7 @@ with lib;
Note: This option overrides <literal>enableIPv6</literal>
'';
default = [];
example = [ "127.0.0.1" "::1" ];
example = [ "127.0.0.1" "[::1]" ];
};
enableACME = mkOption {

View File

@@ -189,7 +189,6 @@ in
Note that this should be a last resort; patching the package is preferred (see GPaste).
'';
apply = list: list ++ [ pkgs.gnome.gnome-shell pkgs.gnome.gnome-shell-extensions ];
};
favoriteAppsOverride = mkOption {
@@ -367,6 +366,10 @@ in
services.upower.enable = config.powerManagement.enable;
services.xserver.libinput.enable = mkDefault true; # for controlling touchpad settings via gnome control center
# Explicitly enabled since GNOME will be severely broken without these.
xdg.mime.enable = true;
xdg.icons.enable = true;
xdg.portal.enable = true;
xdg.portal.extraPortals = [
pkgs.xdg-desktop-portal-gnome
@@ -400,6 +403,18 @@ in
})
(mkIf serviceCfg.core-shell.enable {
services.xserver.desktopManager.gnome.sessionPath =
let
mandatoryPackages = [
pkgs.gnome.gnome-shell
];
optionalPackages = [
pkgs.gnome.gnome-shell-extensions
];
in
mandatoryPackages
++ utils.removePackagesByName optionalPackages config.environment.gnome.excludePackages;
services.colord.enable = mkDefault true;
services.gnome.chrome-gnome-shell.enable = mkDefault true;
services.gnome.glib-networking.enable = true;
@@ -452,26 +467,31 @@ in
];
# Adapt from https://gitlab.gnome.org/GNOME/gnome-build-meta/blob/gnome-3-38/elements/core/meta-gnome-core-shell.bst
environment.systemPackages = with pkgs.gnome; [
adwaita-icon-theme
nixos-background-info
gnome-backgrounds
gnome-bluetooth
gnome-color-manager
gnome-control-center
gnome-shell
gnome-shell-extensions
gnome-themes-extra
pkgs.gnome-tour # GNOME Shell detects the .desktop file on first log-in.
pkgs.gnome-user-docs
pkgs.orca
pkgs.glib # for gsettings
pkgs.gnome-menus
pkgs.gtk3.out # for gtk-launch
pkgs.hicolor-icon-theme
pkgs.shared-mime-info # for update-mime-database
pkgs.xdg-user-dirs # Update user dirs as described in http://freedesktop.org/wiki/Software/xdg-user-dirs/
];
environment.systemPackages =
let
mandatoryPackages = with pkgs.gnome; [
gnome-shell
];
optionalPackages = with pkgs.gnome; [
adwaita-icon-theme
nixos-background-info
gnome-backgrounds
gnome-bluetooth
gnome-color-manager
gnome-control-center
gnome-shell-extensions
gnome-themes-extra
pkgs.gnome-tour # GNOME Shell detects the .desktop file on first log-in.
pkgs.gnome-user-docs
pkgs.orca
pkgs.glib # for gsettings program
pkgs.gnome-menus
pkgs.gtk3.out # for gtk-launch program
pkgs.xdg-user-dirs # Update user dirs as described in http://freedesktop.org/wiki/Software/xdg-user-dirs/
];
in
mandatoryPackages
++ utils.removePackagesByName optionalPackages config.environment.gnome.excludePackages;
})
# Adapt from https://gitlab.gnome.org/GNOME/gnome-build-meta/blob/gnome-3-38/elements/core/meta-gnome-core-utilities.bst

View File

@@ -19,7 +19,8 @@ in
./evilwm.nix
./exwm.nix
./fluxbox.nix
./fvwm.nix
./fvwm2.nix
./fvwm3.nix
./herbstluftwm.nix
./i3.nix
./jwm.nix

View File

@@ -1,41 +0,0 @@
{ config, lib, pkgs, ... }:
with lib;
let
cfg = config.services.xserver.windowManager.fvwm;
fvwm = pkgs.fvwm.override { enableGestures = cfg.gestures; };
in
{
###### interface
options = {
services.xserver.windowManager.fvwm = {
enable = mkEnableOption "Fvwm window manager";
gestures = mkOption {
default = false;
type = types.bool;
description = "Whether or not to enable libstroke for gesture support";
};
};
};
###### implementation
config = mkIf cfg.enable {
services.xserver.windowManager.session = singleton
{ name = "fvwm";
start =
''
${fvwm}/bin/fvwm &
waitPID=$!
'';
};
environment.systemPackages = [ fvwm ];
};
}

View File

@@ -0,0 +1,47 @@
{ config, lib, pkgs, ... }:
with lib;
let
cfg = config.services.xserver.windowManager.fvwm2;
fvwm2 = pkgs.fvwm2.override { enableGestures = cfg.gestures; };
in
{
imports = [
(mkRenamedOptionModule
[ "services" "xserver" "windowManager" "fvwm" ]
[ "services" "xserver" "windowManager" "fvwm2" ])
];
###### interface
options = {
services.xserver.windowManager.fvwm2 = {
enable = mkEnableOption "Fvwm2 window manager";
gestures = mkOption {
default = false;
type = types.bool;
description = "Whether or not to enable libstroke for gesture support";
};
};
};
###### implementation
config = mkIf cfg.enable {
services.xserver.windowManager.session = singleton
{ name = "fvwm2";
start =
''
${fvwm2}/bin/fvwm &
waitPID=$!
'';
};
environment.systemPackages = [ fvwm2 ];
};
}

View File

@@ -0,0 +1,35 @@
{ config, lib, pkgs, ... }:
with lib;
let
cfg = config.services.xserver.windowManager.fvwm3;
inherit (pkgs) fvwm3;
in
{
###### interface
options = {
services.xserver.windowManager.fvwm3 = {
enable = mkEnableOption "Fvwm3 window manager";
};
};
###### implementation
config = mkIf cfg.enable {
services.xserver.windowManager.session = singleton
{ name = "fvwm3";
start =
''
${fvwm3}/bin/fvwm3 &
waitPID=$!
'';
};
environment.systemPackages = [ fvwm3 ];
};
}

View File

@@ -204,7 +204,6 @@ def get_profiles() -> List[str]:
else:
return []
def main() -> None:
parser = argparse.ArgumentParser(description='Update NixOS-related systemd-boot files')
parser.add_argument('default_config', metavar='DEFAULT-CONFIG', help='The default NixOS config to boot')
@@ -244,27 +243,29 @@ def main() -> None:
subprocess.check_call(["@systemd@/bin/bootctl", "--path=@efiSysMountPoint@"] + flags + ["install"])
else:
# Update bootloader to latest if needed
systemd_version = subprocess.check_output(["@systemd@/bin/bootctl", "--version"], universal_newlines=True).split()[2]
sdboot_status = subprocess.check_output(["@systemd@/bin/bootctl", "--path=@efiSysMountPoint@", "status"], universal_newlines=True)
available_out = subprocess.check_output(["@systemd@/bin/bootctl", "--version"], universal_newlines=True).split()[2]
installed_out = subprocess.check_output(["@systemd@/bin/bootctl", "--path=@efiSysMountPoint@", "status"], universal_newlines=True)
# See status_binaries() in systemd bootctl.c for code which generates this
m = re.search("^\W+File:.*/EFI/(BOOT|systemd)/.*\.efi \(systemd-boot ([\d.]+[^)]*)\)$",
sdboot_status, re.IGNORECASE | re.MULTILINE)
installed_match = re.search(r"^\W+File:.*/EFI/(?:BOOT|systemd)/.*\.efi \(systemd-boot ([\d.]+[^)]*)\)$",
installed_out, re.IGNORECASE | re.MULTILINE)
needs_install = False
available_match = re.search(r"^\((.*)\)$", available_out)
if m is None:
print("could not find any previously installed systemd-boot, installing.")
# Let systemd-boot attempt an installation if a previous one wasn't found
needs_install = True
else:
sdboot_version = f'({m.group(2)})'
if systemd_version != sdboot_version:
print("updating systemd-boot from %s to %s" % (sdboot_version, systemd_version))
needs_install = True
if installed_match is None:
raise Exception("could not find any previously installed systemd-boot")
if needs_install:
if available_match is None:
raise Exception("could not determine systemd-boot version")
installed_version = installed_match.group(1)
available_version = available_match.group(1)
if installed_version < available_version:
print("updating systemd-boot from %s to %s" % (installed_version, available_version))
subprocess.check_call(["@systemd@/bin/bootctl", "--path=@efiSysMountPoint@", "update"])
else:
print("leaving systemd-boot %s in place (%s is not newer)" % (installed_version, available_version))
mkdir_p("@efiSysMountPoint@/efi/nixos")
mkdir_p("@efiSysMountPoint@/loader/entries")

View File

@@ -440,5 +440,53 @@ let self = {
"21.11".ap-east-1.aarch64-linux.hvm-ebs = "ami-0aa3b50a4f2822a00";
"21.11".sa-east-1.aarch64-linux.hvm-ebs = "ami-00f68eff453d3fe69";
latest = self."21.11";
# 22.05.342.a634c8f6c1f
"22.05".eu-west-1.x86_64-linux.hvm-ebs = "ami-00badba5cfa0a0c0d";
"22.05".af-south-1.x86_64-linux.hvm-ebs = "ami-0d3a6166c1ea4d7b4";
"22.05".ap-east-1.x86_64-linux.hvm-ebs = "ami-06445325c360470d8";
"22.05".ap-northeast-1.x86_64-linux.hvm-ebs = "ami-009c422293bcf3721";
"22.05".ap-northeast-2.x86_64-linux.hvm-ebs = "ami-0bfc0397525a67ed8";
"22.05".ap-northeast-3.x86_64-linux.hvm-ebs = "ami-0a1fb4d4e08a6065e";
"22.05".ap-south-1.x86_64-linux.hvm-ebs = "ami-07ad258dcc69239d2";
"22.05".ap-southeast-1.x86_64-linux.hvm-ebs = "ami-0f59f7f33cba8b1a4";
"22.05".ap-southeast-2.x86_64-linux.hvm-ebs = "ami-0d1e49fe30aec165d";
"22.05".ap-southeast-3.x86_64-linux.hvm-ebs = "ami-0f5cb24a1e3fc62dd";
"22.05".ca-central-1.x86_64-linux.hvm-ebs = "ami-0551a595ba7916462";
"22.05".eu-central-1.x86_64-linux.hvm-ebs = "ami-0702eee2e75d541d1";
"22.05".eu-north-1.x86_64-linux.hvm-ebs = "ami-0fc6838942cb7d9cb";
"22.05".eu-south-1.x86_64-linux.hvm-ebs = "ami-0df9463b8965cdb80";
"22.05".eu-west-2.x86_64-linux.hvm-ebs = "ami-08f3c1eb533a42ac1";
"22.05".eu-west-3.x86_64-linux.hvm-ebs = "ami-04b50c79dc4009c97";
"22.05".me-south-1.x86_64-linux.hvm-ebs = "ami-05c52087afab7024d";
"22.05".sa-east-1.x86_64-linux.hvm-ebs = "ami-0732aa0f0c28f281b";
"22.05".us-east-1.x86_64-linux.hvm-ebs = "ami-0223db08811f6fb2d";
"22.05".us-east-2.x86_64-linux.hvm-ebs = "ami-0a743534fa3e51b41";
"22.05".us-west-1.x86_64-linux.hvm-ebs = "ami-0d72ab697beab5ea5";
"22.05".us-west-2.x86_64-linux.hvm-ebs = "ami-034946f0c47088751";
"22.05".eu-west-1.aarch64-linux.hvm-ebs = "ami-08114069426233360";
"22.05".af-south-1.aarch64-linux.hvm-ebs = "ami-0a9b83913abd61694";
"22.05".ap-east-1.aarch64-linux.hvm-ebs = "ami-03966ad4547f532b7";
"22.05".ap-northeast-1.aarch64-linux.hvm-ebs = "ami-0eb7e152c8d5aae7d";
"22.05".ap-northeast-2.aarch64-linux.hvm-ebs = "ami-08369e00c5528762b";
"22.05".ap-northeast-3.aarch64-linux.hvm-ebs = "ami-0fa14b8d48cdd57c3";
"22.05".ap-south-1.aarch64-linux.hvm-ebs = "ami-0f2ca3b542ff0913b";
"22.05".ap-southeast-1.aarch64-linux.hvm-ebs = "ami-087def0511ef2687d";
"22.05".ap-southeast-2.aarch64-linux.hvm-ebs = "ami-0aa90985199011f04";
"22.05".ap-southeast-3.aarch64-linux.hvm-ebs = "ami-0c86c52790deefa23";
"22.05".ca-central-1.aarch64-linux.hvm-ebs = "ami-06e932cc9c20403e4";
"22.05".eu-central-1.aarch64-linux.hvm-ebs = "ami-07680df1026a9b54c";
"22.05".eu-north-1.aarch64-linux.hvm-ebs = "ami-0cbe9f2725e4de706";
"22.05".eu-south-1.aarch64-linux.hvm-ebs = "ami-01a83c3892925765f";
"22.05".eu-west-2.aarch64-linux.hvm-ebs = "ami-049024d086d039b54";
"22.05".eu-west-3.aarch64-linux.hvm-ebs = "ami-0c0ebe20ebfc635a1";
"22.05".me-south-1.aarch64-linux.hvm-ebs = "ami-0d662fcaac553e945";
"22.05".sa-east-1.aarch64-linux.hvm-ebs = "ami-0888c8f703e00fdb8";
"22.05".us-east-1.aarch64-linux.hvm-ebs = "ami-03536a13324333073";
"22.05".us-east-2.aarch64-linux.hvm-ebs = "ami-067611519fa817aaa";
"22.05".us-west-1.aarch64-linux.hvm-ebs = "ami-0f96be48071c13ab2";
"22.05".us-west-2.aarch64-linux.hvm-ebs = "ami-084bc5d777585adfb";
latest = self."22.05";
}; in self

View File

@@ -742,12 +742,6 @@ in
config = mkIf (config.boot.enableContainers) (let
warnings = flatten [
(optional (config.virtualisation.containers.enable && versionOlder config.system.stateVersion "22.05") ''
Enabling both boot.enableContainers & virtualisation.containers on system.stateVersion < 22.05 is unsupported.
'')
];
unit = {
description = "Container '%i'";
@@ -771,6 +765,11 @@ in
serviceConfig = serviceDirectives dummyConfig;
};
in {
warnings =
(optional (config.virtualisation.containers.enable && versionOlder config.system.stateVersion "22.05") ''
Enabling both boot.enableContainers & virtualisation.containers on system.stateVersion < 22.05 is unsupported.
'');
systemd.targets.multi-user.wants = [ "machines.target" ];
systemd.services = listToAttrs (filter (x: x.value != null) (

View File

@@ -127,16 +127,26 @@ with lib;
name = "proxmox-${cfg.filenameSuffix}";
postVM = let
# Build qemu with PVE's patch that adds support for the VMA format
vma = pkgs.qemu_kvm.overrideAttrs ( super: {
vma = pkgs.qemu_kvm.overrideAttrs ( super: rec {
# proxmox's VMA patch doesn't work with qemu 7.0 yet
version = "6.2.0";
src = pkgs.fetchurl {
url= "https://download.qemu.org/qemu-${version}.tar.xz";
hash = "sha256-aOFdjkWsVjJuC5pK+otJo9/oq6NIgiHQmMhGmLymW0U=";
};
patches = let
rev = "cc707c362ea5c8d832aac270d1ffa7ac66a8908f";
path = "debian/patches/pve/0025-PVE-Backup-add-vma-backup-format-code.patch";
rev = "b37b17c286da3d32945fbee8ee4fd97a418a50db";
path = "debian/patches/pve/0026-PVE-Backup-add-vma-backup-format-code.patch";
vma-patch = pkgs.fetchpatch {
url = "https://git.proxmox.com/?p=pve-qemu.git;a=blob_plain;hb=${rev};f=${path}";
sha256 = "1z467xnmfmry3pjy7p34psd5xdil9x0apnbvfz8qbj0bf9fgc8zf";
url = "https://git.proxmox.com/?p=pve-qemu.git;a=blob_plain;h=${rev};f=${path}";
hash = "sha256-siuDWDUnM9Zq0/L2Faww3ELAOUHhVIHu5RAQn6L4Atc=";
};
in super.patches ++ [ vma-patch ];
in [ vma-patch ];
buildInputs = super.buildInputs ++ [ pkgs.libuuid ];
});
in
''

View File

@@ -64,7 +64,6 @@ in
environment.etc.vmware-tools.source = "${open-vm-tools}/etc/vmware-tools/*";
services.xserver = mkIf (!cfg.headless) {
videoDrivers = mkOverride 50 [ "vmware" ];
modules = [ xf86inputvmmouse ];
config = ''

Some files were not shown because too many files have changed in this diff Show More