Compare commits

...

4480 Commits

Author SHA1 Message Date
github-actions[bot]
b45d6574bb Merge release-21.11 into staging-next-21.11 2022-07-03 00:16:16 +00:00
Anderson Torres
573603b7fd Merge pull request #179915 from NixOS/backport-179907-to-release-21.11
[Backport release-21.11] freecad: fix crash when selecting color of a solid
2022-07-02 14:22:58 -03:00
Juraj Hercek
4b747de873 freecad: fix crash when selecting color of a solid
FreeCAD crashes when user wants to select color of a solid with
following console message (long lines wrapped):

    $ nix run nixpkgs#freecad
    FreeCAD 0.20, Libs: 0.20RUnknown
    © Juergen Riegel, Werner Mayer, Yorik van Havre and others 2001-2022
    FreeCAD is free and open-source software licensed under the terms of
    LGPL2+ license.
    FreeCAD wouldn't be possible without FreeCAD community.
      #####                 ####  ###   ####
      #                    #      # #   #   #
      #     ##  #### ####  #     #   #  #   #
      ####  # # #  # #  #  #     #####  #   #
      #     #   #### ####  #    #     # #   #
      #     #   #    #     #    #     # #   #  ##  ##  ##
      #     #   #### ####   ### #     # ####   ##  ##  ##

    (freecad:19737): GLib-GIO-ERROR **: 14:33:02.511: Settings schema
    'org.gtk.Settings.ColorChooser' is not installed
    fish: Job 1, 'nix run nixpkgs#freecad' terminated by signal SIGTRAP
    (Trace or breakpoint trap)

This patch adds hooks for GApps to relevant places in order to make
FreeCAD finding the Color Chooser dialog schema effectively preventing
crash from happening.

(cherry picked from commit 269b500073)
2022-07-02 15:14:50 +00:00
github-actions[bot]
7b6ca1edc9 Merge release-21.11 into staging-next-21.11 2022-07-01 00:15:26 +00:00
Martin Weinelt
399c514226 Merge pull request #178383 from risicle/ris-liblouis-CVE-2022-26981-r21.11 2022-06-30 18:57:16 +02:00
Martin Weinelt
f57154d58d Merge pull request #179546 from Ma27/2111-linux-kernels 2022-06-30 18:56:58 +02:00
github-actions[bot]
7ad6c62005 Merge release-21.11 into staging-next-21.11 2022-06-30 00:14:01 +00:00
Maximilian Bosch
e2be983360 linux/hardened/patches/5.4: 5.4.200-hardened1 -> 5.4.201-hardened1
(cherry picked from commit 7d58f625e2)
2022-06-29 10:50:05 +02:00
Maximilian Bosch
1c16811012 linux/hardened/patches/5.15: 5.15.49-hardened1 -> 5.15.50-hardened1
(cherry picked from commit d7973cd502)
2022-06-29 10:50:04 +02:00
Maximilian Bosch
c279c125de linux/hardened/patches/5.10: 5.10.124-hardened1 -> 5.10.125-hardened1
(cherry picked from commit 3cf33ad016)
2022-06-29 10:50:04 +02:00
Maximilian Bosch
6655cad95f linux/hardened/patches/4.19: 4.19.248-hardened1 -> 4.19.249-hardened1
(cherry picked from commit 14479c95a2)
2022-06-29 10:50:04 +02:00
Maximilian Bosch
42d6366629 linux/hardened/patches/4.14: 4.14.284-hardened1 -> 4.14.285-hardened1
(cherry picked from commit 299b49b539)
2022-06-29 10:50:04 +02:00
Maximilian Bosch
cc122120cb linux: 5.4.200 -> 5.4.201
(cherry picked from commit dfc38c7baa)
2022-06-29 10:50:04 +02:00
Maximilian Bosch
bd9cb56b31 linux: 5.15.49 -> 5.15.50
(cherry picked from commit 17996e10f9)
2022-06-29 10:50:04 +02:00
Maximilian Bosch
7eae32a36f linux: 5.10.124 -> 5.10.126
(cherry picked from commit 48f604ef69)
2022-06-29 10:50:04 +02:00
Maximilian Bosch
2068a7086e linux: 4.9.319 -> 4.9.320
(cherry picked from commit 21c39a0969)
2022-06-29 10:50:04 +02:00
Maximilian Bosch
be96a43b74 linux: 4.19.248 -> 4.19.249
(cherry picked from commit 34fe04da8e)
2022-06-29 10:50:04 +02:00
Maximilian Bosch
950b2e9235 linux: 4.14.284 -> 4.14.285
(cherry picked from commit 2b50639f43)
2022-06-29 10:50:04 +02:00
Martin Weinelt
7a5ca644cc Merge pull request #179539 from Ma27/2111-fix-eval 2022-06-29 10:42:35 +02:00
Martin Weinelt
8a64a3ad64 Merge pull request #179502 from NixOS/backport-179480-to-release-21.11 2022-06-29 10:34:29 +02:00
Maximilian Bosch
48a0bb9c8e linux_latest: fix eval 2022-06-29 10:19:28 +02:00
Martin Weinelt
05ae8b5207 Merge pull request #179501 from mweinelt/21.11/nss 2022-06-29 02:24:16 +02:00
Vladimír Čunát
4e49eded35 thunderbird-bin: 91.10.0 -> 91.11.0
https://www.thunderbird.net/en-US/thunderbird/91.11.0/releasenotes/
(cherry picked from commit 2ca9969237)
2022-06-29 00:17:52 +00:00
Vladimír Čunát
bfb9d6a729 thunderbird: 91.10.0 -> 91.11.0
https://www.thunderbird.net/en-US/thunderbird/91.11.0/releasenotes/
(cherry picked from commit caeb46375d)
2022-06-29 00:17:52 +00:00
github-actions[bot]
4be813fbfd Merge release-21.11 into staging-next-21.11 2022-06-29 00:13:35 +00:00
ajs124
f844ba2947 nspr: 4.33 -> 4.34
(cherry picked from commit a7be0f278d)
2022-06-29 01:55:19 +02:00
ajs124
634eef8842 nspr: 4.32 -> 4.33
(cherry picked from commit 314d3d0396)
2022-06-29 01:55:12 +02:00
Martin Weinelt
a78388364b nss_latest: 3.78 -> 3.80 2022-06-29 01:46:04 +02:00
Martin Weinelt
4214e57ca2 Merge pull request #179370 from mweinelt/21.11/mozilla 2022-06-29 01:33:59 +02:00
Martin Weinelt
9ef376a13e Merge pull request #179464 from Ma27/backport-matrix 2022-06-28 20:49:59 +02:00
Maximilian Bosch
ac8fb2f105 matrix-synapse: 1.61.0 -> 1.61.1
ChangeLog: https://github.com/matrix-org/synapse/releases/tag/v1.61.1
(cherry picked from commit 89d1b48eb5)
2022-06-28 19:01:51 +02:00
Nick Cao
d495354e86 matrix-synapse: 1.60.0 -> 1.61.0
(cherry picked from commit 402807041a)
2022-06-28 19:01:50 +02:00
Robin Townsend
130c5f665c matrix-synapse: 1.59.1 -> 1.60.0
https://github.com/matrix-org/synapse/releases/tag/v1.60.0
(cherry picked from commit bb5f5eadf4)
2022-06-28 19:01:50 +02:00
Martin Weinelt
344f8370a0 spidermonkey_91: 91.10.0 -> 91.11.0
(cherry picked from commit d3d7ea1ace)
2022-06-27 21:47:17 +02:00
Martin Weinelt
f2481b98a0 firefox-beta-bin-unwrapped: 102.0b5 -> 102.0b9
(cherry picked from commit 71c17fd17f)
2022-06-27 21:47:16 +02:00
Martin Weinelt
9359eeda4b firefox-devedition-unwrapped: 102.0b6 -> 102.0b9
(cherry picked from commit 46f9c89390)
2022-06-27 21:47:15 +02:00
R. Ryantm
5e4c328af1 firefox-devedition-bin-unwrapped: 102.0b5 -> 102.0b6
(cherry picked from commit 3cd8c2f457)
2022-06-27 21:47:14 +02:00
Martin Weinelt
7a4afb6a72 firefox-esr-91-unwrapped: 91.10.0esr -> 91.11.0esr
https://www.mozilla.org/en-US/firefox/91.11.0/releasenotes/
(cherry picked from commit ddc17118f0)
2022-06-27 21:47:13 +02:00
Martin Weinelt
fa96b82e1a firefox-bin-unwrapped: 101.0.1 -> 102.0
https://www.mozilla.org/en-US/firefox/102.0/releasenotes/
(cherry picked from commit 32b18b77bd)
2022-06-27 21:47:12 +02:00
Martin Weinelt
04de4a283d firefox-unwrapped: 101.0.1 -> 102.0
https://www.mozilla.org/en-US/firefox/102.0/releasenotes/
(cherry picked from commit 736555d08f)
2022-06-27 21:47:11 +02:00
github-actions[bot]
81dab3819a Merge release-21.11 into staging-next-21.11 2022-06-26 00:16:04 +00:00
Martin Weinelt
46af330365 Merge pull request #178979 from NixOS/backport-178797-to-release-21.11 2022-06-26 01:08:08 +02:00
Kim Lindberger
f260f0aa5b Merge pull request #179032 from NixOS/backport-178703-to-release-21.11
[Backport release-21.11] nomachine-client: 7.9.2 -> 7.10.1
2022-06-25 19:07:54 +02:00
talyz
ee18842f4b nomachine-client: 7.9.2 -> 7.10.1
(cherry picked from commit 9e57dde15b)
2022-06-25 15:23:44 +00:00
Maximilian Bosch
f341618431 Merge pull request #178791 from Ma27/backport-kernel-updates
[21.11] Linux kernel updates 2022-06-23
2022-06-25 12:31:45 +02:00
kilianar
9a80c3597f signal-desktop: 5.46.0 -> 5.47.0
(cherry picked from commit 956560470b)
2022-06-25 10:28:51 +00:00
Vladimír Čunát
4b97ab3fd8 Merge #178681: thunderbird*: 91.9.1 -> 91.10.0
...into release-21.11
2022-06-25 10:14:01 +02:00
Mario Rodas
891016b5cf Merge pull request #173546 from NixOS/backport-173237-to-release-21.11
[Backport release-21.11] alfis: 0.7.0 -> 0.7.3
2022-06-24 21:07:31 -05:00
github-actions[bot]
e873ae23e5 Merge release-21.11 into staging-next-21.11 2022-06-25 00:13:41 +00:00
Mario Rodas
e1c9213887 Merge pull request #178826 from NixOS/backport-174471-to-release-21.11
[Backport release-21.11] chafa: 1.8.0 -> 1.10.3
2022-06-24 01:29:45 -05:00
R. Ryantm
0ae05a60e2 chafa: 1.8.0 -> 1.10.3
(cherry picked from commit 24bb1b1c9a)
2022-06-24 04:13:36 +00:00
Anderson Torres
902d91def1 Merge pull request #178751 from NixOS/backport-178259-to-release-21.11
[Backport release-21.11] freecad: 0.19.2 -> 0.20
2022-06-23 21:55:09 -03:00
github-actions[bot]
4e653bd010 Merge release-21.11 into staging-next-21.11 2022-06-24 00:13:25 +00:00
Michael Weiss
aaa5fa8420 Merge pull request #178788 from NixOS/backport-178645-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 102.0.5005.115 -> 103.0.5060.53
2022-06-23 23:24:54 +02:00
Maximilian Bosch
1c5d1e07e3 Merge pull request #178639 from NixOS/backport-178404-to-release-21.11
[Backport release-21.11] nextcloud: 23.0.5 -> 23.0.6, 24.0.1 -> 24.0.2
2022-06-23 22:26:06 +02:00
Maximilian Bosch
4e2a7023bb linux_5_17: remove
(cherry picked from commit f0e3e98377)
2022-06-23 21:55:12 +02:00
Michael Weiss
0736d6cb55 ungoogled-chromium: 102.0.5005.115 -> 103.0.5060.53
(cherry picked from commit dd9c01a9af)
2022-06-23 19:50:47 +00:00
Maximilian Bosch
a2628068d8 linux/hardened/patches/5.4: 5.4.198-hardened1 -> 5.4.200-hardened1
(cherry picked from commit 1d833f1783)
2022-06-23 21:49:01 +02:00
Maximilian Bosch
ccb0bb3bc9 linux/hardened/patches/5.15: 5.15.47-hardened1 -> 5.15.49-hardened1
(cherry picked from commit 14ad08aee4)
2022-06-23 21:48:56 +02:00
Maximilian Bosch
143a22d45a linux/hardened/patches/5.10: 5.10.122-hardened1 -> 5.10.124-hardened1
(cherry picked from commit 500dff12fe)
2022-06-23 21:48:56 +02:00
Maximilian Bosch
dbab6f4b9c linux/hardened/patches/4.19: 4.19.247-hardened1 -> 4.19.248-hardened1
(cherry picked from commit d450bf294a)
2022-06-23 21:48:56 +02:00
Maximilian Bosch
440b02e2c9 linux/hardened/patches/4.14: 4.14.283-hardened1 -> 4.14.284-hardened1
(cherry picked from commit 0fc1333d75)
2022-06-23 21:48:55 +02:00
Maximilian Bosch
c612f4d703 linux_latest-libre: 18777 -> 18798
(cherry picked from commit efdcc5f6a8)
2022-06-23 21:48:55 +02:00
Maximilian Bosch
c3ce0fce79 linux: 5.4.198 -> 5.4.200
(cherry picked from commit 4051ac2d8e)
2022-06-23 21:48:55 +02:00
Maximilian Bosch
9009b02b05 linux: 5.15.47 -> 5.15.49
(cherry picked from commit ca439ff6a6)
2022-06-23 21:48:55 +02:00
Maximilian Bosch
3e24466c4d linux: 5.10.122 -> 5.10.124
(cherry picked from commit 66e572d984)
2022-06-23 21:48:55 +02:00
Maximilian Bosch
402179aae4 linux: 4.9.318 -> 4.9.319
(cherry picked from commit 34952774df)
2022-06-23 21:48:55 +02:00
Maximilian Bosch
f2f18c6fec linux: 4.19.247 -> 4.19.248
(cherry picked from commit 2341a8672d)
2022-06-23 21:48:54 +02:00
Maximilian Bosch
6666999d96 linux: 4.14.283 -> 4.14.284
(cherry picked from commit d7c1e34aa0)
2022-06-23 21:48:54 +02:00
Nicolas Benes
6ce0d8c55c freecad: 0.19.2 -> 0.20
(cherry picked from commit 7ca0fb42c6057ea2ab436c88608e942e49a027e4)
2022-06-23 15:33:40 +00:00
Martin Weinelt
0d4ae6cb1a thunderbird-bin-unwrapped: 91.9.1 -> 91.10.0
https://www.thunderbird.net/en-US/thunderbird/91.10.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-22/

Fixes: CVE-2022-31736, CVE-2022-31737, CVE-2022-31738, CVE-2022-31739,
       CVE-2022-31740, CVE-2022-31741, CVE-2022-1834, CVE-2022-31742,
       CVE-2022-31747
(cherry picked from commit ef49524ebb)
2022-06-23 05:50:09 +00:00
Martin Weinelt
f7cc562296 thunderbird-unwrapped: 91.9.1 -> 91.10.0
https://www.thunderbird.net/en-US/thunderbird/91.10.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-22/

Fixes: CVE-2022-31736, CVE-2022-31737, CVE-2022-31738, CVE-2022-31739,
       CVE-2022-31740, CVE-2022-31741, CVE-2022-1834, CVE-2022-31742,
       CVE-2022-31747
(cherry picked from commit 3a0fa6aabe)
2022-06-23 05:50:09 +00:00
Robert Schütz
3aad50c30c python310Packages.bottle: 0.12.19 -> 0.12.21
fixes CVE-2022-31799

(cherry picked from commit a4afd6aa1e)
2022-06-23 01:00:12 +00:00
github-actions[bot]
760fe9f99a Merge release-21.11 into staging-next-21.11 2022-06-23 00:12:44 +00:00
Michael Weiss
d3a04c8e53 Merge pull request #178502 from NixOS/backport-178489-to-release-21.11
[Backport release-21.11] chromium: 102.0.5005.115 -> 103.0.5060.53
2022-06-23 00:03:50 +02:00
Robbert Gurdeep Singh
c7a0b342fa nextcloud: 23.0.5 -> 23.0.6, 24.0.1 -> 24.0.2
(cherry picked from commit 376dfe8766)
2022-06-22 21:22:53 +00:00
ajs124
ad204368c8 Merge pull request #178601 from NixOS/backport-174022-to-release-21.11
[Backport release-21.11] panotools: 2.9.20 -> 2.9.21
2022-06-22 22:54:49 +02:00
Thomas Gerbet
721e1528b1 panotools: 2.9.20 -> 2.9.21
Fixes CVE-2021-33293

https://sourceforge.net/projects/panotools/files/libpano13/libpano13-2.9.21/
(cherry picked from commit c3182eace3)
2022-06-22 17:09:26 +00:00
ajs124
6e7b3c8338 Merge pull request #174243 from LeSuisse/nbd-3.24-21.11
[21.11] nbd: 3.21 -> 3.24
2022-06-22 18:41:05 +02:00
github-actions[bot]
6b5785b02f Merge release-21.11 into staging-next-21.11 2022-06-22 00:16:03 +00:00
Michael Weiss
84ef8d0693 chromium: 102.0.5005.115 -> 103.0.5060.53
https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html

This update includes 14 security fixes.

CVEs:
CVE-2022-2156 CVE-2022-2157 CVE-2022-2158 CVE-2022-2160 CVE-2022-2161
CVE-2022-2162 CVE-2022-2163 CVE-2022-2164 CVE-2022-2165

(cherry picked from commit de0f40f35b)
2022-06-21 21:48:08 +00:00
Robert Schütz
63198c9cce imagemagick: 7.1.0-37 -> 7.1.0-39
(cherry picked from commit 7978240546)
2022-06-21 00:20:56 +00:00
Robert Scott
722e4976bc liblouis: apply patch for CVE-2022-26981
Fixes: CVE-2022-26981

Refs:
liblouis/liblouis#1185
GHSA-xrp8-mw8v-p6mq
https://nvd.nist.gov/vuln/detail/CVE-2022-26981

(cherry-pick of a4f5b169f1)
2022-06-21 00:19:23 +01:00
github-actions[bot]
a0cf507cbf Merge release-21.11 into staging-next-21.11 2022-06-20 00:12:56 +00:00
Maximilian Bosch
15463250cb Merge pull request #178017 from Ma27/backport-kernel-updates
[21.11] Linux kernel updates 2022-06-16
2022-06-19 10:41:31 +02:00
github-actions[bot]
37c8a6361f Merge release-21.11 into staging-next-21.11 2022-06-19 00:14:05 +00:00
Bobby Rong
27dffce7ea Merge pull request #173547 from NixOS/backport-173240-to-release-21.11
[Backport release-21.11] git-workspace: 0.9.0 -> 1.0.3
2022-06-18 22:32:00 +08:00
Bobby Rong
693f3d4f51 Merge pull request #178062 from NixOS/backport-177950-to-release-21.11
[Backport release-21.11] vscodium: 1.68.0 -> 1.68.1
2022-06-18 22:22:11 +08:00
Bobby Rong
6a36200296 Merge pull request #177984 from NixOS/backport-177959-to-release-21.11
[Backport release-21.11] signal-desktop: 5.45.1 -> 5.46.0
2022-06-18 22:16:32 +08:00
maxine [they]
be7173e188 Merge pull request #178065 from NixOS/backport-177818-to-release-21.11
[Backport release-21.11] vscode: 1.68.0 -> 1.68.1
2022-06-18 11:07:27 +02:00
nixpkgs-upkeep-bot
390dc73830 vscode: 1.68.0 -> 1.68.1
(cherry picked from commit 58b2655b4c)
2022-06-17 20:06:19 +00:00
nixpkgs-upkeep-bot
275a286f2b vscodium: 1.68.0 -> 1.68.1
(cherry picked from commit 1a0d8eebd7)
2022-06-17 19:42:59 +00:00
Maximilian Bosch
03ee56cad0 linux/hardened/patches/5.4: 5.4.197-hardened1 -> 5.4.198-hardened1
(cherry picked from commit fb273f2144)
2022-06-17 14:22:49 +02:00
Maximilian Bosch
ef835b4ec6 linux/hardened/patches/5.17: 5.17.14-hardened1 -> 5.17.15-hardened1
(cherry picked from commit 96aa98b34e)
2022-06-17 14:22:48 +02:00
Maximilian Bosch
1cd78ce09e linux/hardened/patches/5.15: 5.15.46-hardened1 -> 5.15.47-hardened1
(cherry picked from commit b728110e62)
2022-06-17 14:22:48 +02:00
Maximilian Bosch
2f8069d520 linux/hardened/patches/5.10: 5.10.121-hardened1 -> 5.10.122-hardened1
(cherry picked from commit 638b826560)
2022-06-17 14:22:48 +02:00
Maximilian Bosch
f567369fcc linux/hardened/patches/4.19: 4.19.246-hardened1 -> 4.19.247-hardened1
(cherry picked from commit 2f5d73c7c8)
2022-06-17 14:22:48 +02:00
Maximilian Bosch
46ccedbe97 linux/hardened/patches/4.14: 4.14.282-hardened1 -> 4.14.283-hardened1
(cherry picked from commit f66c3eec69)
2022-06-17 14:22:48 +02:00
Maximilian Bosch
a65c1b1a56 linux: 5.4.197 -> 5.4.198
(cherry picked from commit 47f2c949b1)
2022-06-17 14:22:48 +02:00
Maximilian Bosch
50f8e89541 linux: 5.17.14 -> 5.17.15
(cherry picked from commit e58ad1f6c8)
2022-06-17 14:22:48 +02:00
Maximilian Bosch
eb5b40af46 linux: 5.15.46 -> 5.15.47
(cherry picked from commit 66f0feca14)
2022-06-17 14:22:47 +02:00
Maximilian Bosch
975b92ca48 linux: 5.10.121 -> 5.10.122
(cherry picked from commit 2aabaf7e8a)
2022-06-17 14:22:47 +02:00
Maximilian Bosch
8dbed73040 linux: 4.9.317 -> 4.9.318
(cherry picked from commit 685043bbe9)
2022-06-17 14:22:47 +02:00
Maximilian Bosch
36dabdeb91 linux: 4.19.246 -> 4.19.247
(cherry picked from commit de6b615add)
2022-06-17 14:22:47 +02:00
Maximilian Bosch
da2b55ff2b linux: 4.14.282 -> 4.14.283
(cherry picked from commit 783c3d65ef)
2022-06-17 14:22:47 +02:00
Eduardo Quiros
2b32d3550a signal-desktop: 5.45.1 -> 5.46.0
(cherry picked from commit 523bed764c)
2022-06-17 07:28:09 +00:00
github-actions[bot]
f44d401400 Merge release-21.11 into staging-next-21.11 2022-06-17 00:13:09 +00:00
Maximilian Bosch
f967292126 Merge pull request #177863 from Ma27/kernel-backports-21.11
[21.11] Kernel backports (excluding 5.18)
2022-06-16 23:41:11 +02:00
Andrew Marshall
554814d84a linux/hardened/patches/5.4: 5.4.196-hardened1 -> 5.4.197-hardened1
(cherry picked from commit 5dc09cd84f)
2022-06-16 12:23:12 +02:00
Andrew Marshall
b50f7d5a61 linux/hardened/patches/5.17: 5.17.11-hardened1 -> 5.17.14-hardened1
(cherry picked from commit f61e9f4a53)
2022-06-16 12:23:12 +02:00
Andrew Marshall
510e55a832 linux/hardened/patches/5.15: 5.15.43-hardened1 -> 5.15.46-hardened1
(cherry picked from commit de36193dee)
2022-06-16 12:23:12 +02:00
Andrew Marshall
192e926ba9 linux/hardened/patches/5.10: 5.10.118-hardened1 -> 5.10.121-hardened1
(cherry picked from commit 858741e872)
2022-06-16 12:23:12 +02:00
Andrew Marshall
85c9b829bb linux/hardened/patches/4.19: 4.19.245-hardened1 -> 4.19.246-hardened1
(cherry picked from commit 1c31d9666e)
2022-06-16 12:23:12 +02:00
Andrew Marshall
8aad08100c linux/hardened/patches/4.14: 4.14.281-hardened1 -> 4.14.282-hardened1
(cherry picked from commit 67a664c575)
2022-06-16 12:23:11 +02:00
Andrew Marshall
65128d9861 linux_latest-libre: 18738 -> 18777
(cherry picked from commit 87e0009cd5)
2022-06-16 12:23:11 +02:00
Andrew Marshall
e4f71e08da linux-rt_5_10: 5.10.115-rt67 -> 5.10.120-rt70
(cherry picked from commit e457a67642)
2022-06-16 12:23:11 +02:00
Andrew Marshall
35ea12e57e linux: 5.4.196 -> 5.4.197
(cherry picked from commit 45a098de80)
2022-06-16 12:23:11 +02:00
Andrew Marshall
8745b5e52b linux: 5.17.11 -> 5.17.14
(cherry picked from commit 363c71ff3c)
2022-06-16 12:23:01 +02:00
Andrew Marshall
d5623a7322 linux: 5.15.43 -> 5.15.46
(cherry picked from commit 19d9866215)
2022-06-16 12:23:01 +02:00
Andrew Marshall
4643dbb99a linux: 5.10.118 -> 5.10.121
(cherry picked from commit a7757d8a94)
2022-06-16 12:23:01 +02:00
Andrew Marshall
8613c00ae6 linux: 4.9.316 -> 4.9.317
(cherry picked from commit 2ac8909c8b)
2022-06-16 12:23:01 +02:00
Andrew Marshall
3e6bb75e46 linux: 4.19.245 -> 4.19.246
(cherry picked from commit c6c98c48b4)
2022-06-16 12:23:00 +02:00
Andrew Marshall
5d53e36ff0 linux: 4.14.281 -> 4.14.282
(cherry picked from commit deaf61dab1)
2022-06-16 12:23:00 +02:00
Bobby Rong
b882c61856 Merge pull request #177771 from NixOS/backport-177111-to-release-21.11
[Backport release-21.11] vscodium: 1.67.2 -> 1.68.0
2022-06-16 13:05:51 +08:00
nixpkgs-upkeep-bot
28e50b5711 vscodium: 1.67.2 -> 1.68.0
(cherry picked from commit fae6144d7d)
2022-06-15 14:32:47 +00:00
github-actions[bot]
dd22f0c962 Merge release-21.11 into staging-next-21.11 2022-06-15 00:15:16 +00:00
Martin Weinelt
9227bbe431 Merge pull request #177624 from NixOS/backport-177583-to-release-21.11 2022-06-14 11:49:25 +02:00
Nicolas Benes
f8ee74f0aa tor-browser-bundle-bin: 11.0.13 -> 11.0.14
(cherry picked from commit de77c035c4)
2022-06-14 09:37:04 +00:00
Eduardo Quiros
6266af0f97 signal-desktop: 5.45.0 -> 5.45.1
(cherry picked from commit 2f7a870a4c)
2022-06-14 02:26:06 +00:00
Eduardo Quiros
14e64eafe0 signal-desktop: 5.44.1 -> 5.45.0
(cherry picked from commit 1a931f6eca)
2022-06-14 02:26:06 +00:00
Eduardo Quiros
cca38f0fc3 signal-desktop: 5.43.0 -> 5.44.1
(cherry picked from commit 8e4ca49414)
2022-06-14 02:26:06 +00:00
github-actions[bot]
ad2a9e2e17 Merge release-21.11 into staging-next-21.11 2022-06-13 00:14:55 +00:00
Aaron Andersen
2a9a64710a kodi.packages.urllib3: 1.26.4+matrix.1 -> 1.26.8+matrix.1
(cherry picked from commit e17c1d5a52)
2022-06-12 22:55:53 +00:00
Vladimír Čunát
d5fcf27f4f Merge #177394: metrics job: schedule on a dedicated machine
...into release-21.11
2022-06-12 14:33:08 +02:00
Vladimír Čunát
b990ef14f7 Revert "metrics job: schedule on any machine, for now"
(cherry picked from commit e8c87f0946)
2022-06-12 12:31:28 +00:00
Michael Weiss
29461f6bd3 Merge pull request #177381 from NixOS/backport-177330-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 102.0.5005.61 -> 102.0.5005.115
2022-06-12 13:23:48 +02:00
Michael Weiss
bc8d62a671 ungoogled-chromium: 102.0.5005.61 -> 102.0.5005.115
(cherry picked from commit 69c4953f4b)
2022-06-12 10:24:22 +00:00
Martin Weinelt
b355fc5008 Merge pull request #177223 from NixOS/backport-176986-to-release-21.11 2022-06-12 03:44:27 +02:00
github-actions[bot]
9fe8cfb39c Merge release-21.11 into staging-next-21.11 2022-06-12 00:14:01 +00:00
Mario Rodas
d9be95a45f Merge pull request #177210 from NixOS/backport-177204-to-release-21.11
[Backport release-21.11] chromium: 102.0.5005.61 -> 102.0.5005.115
2022-06-10 19:15:07 -05:00
github-actions[bot]
947d461dee Merge release-21.11 into staging-next-21.11 2022-06-11 00:14:38 +00:00
Martin Weinelt
20a78ef251 firefox-devedition-bin-unwrapped: 102.0b1 -> 102.0b5
(cherry picked from commit 26ca0d1901ae0a7f55406d34c413281f8ea0ee68)
2022-06-10 22:26:14 +00:00
Martin Weinelt
b2a41bfaeb firefox-beta-bin-unwrapped: 102.0b1 -> 102.0b5
(cherry picked from commit 439a7369aea23ec6eb6d70121480a62b8bb1a74c)
2022-06-10 22:26:14 +00:00
Martin Weinelt
1dc26bd019 firefox-bin-unwrapped: 101.0 -> 101.0.1
https://www.mozilla.org/en-US/firefox/101.0.1/releasenotes/
(cherry picked from commit d373d1b66bf68ae6c20ee22a8afd03bbb714d0da)
2022-06-10 22:26:14 +00:00
R. Ryantm
dd3dc15a1b firefox-unwrapped: 101.0 -> 101.0.1
https://www.mozilla.org/en-US/firefox/101.0.1/releasenotes/
(cherry picked from commit 3a852683aa3365f5628cc4435249da394dba50cd)
2022-06-10 22:26:14 +00:00
maxine [they]
ca6a296d57 Merge pull request #177175 from NixOS/backport-177112-to-release-21.11
[Backport release-21.11] vscode: 1.67.2 -> 1.68.0
2022-06-10 23:58:32 +02:00
Michael Weiss
2286c2b6e9 chromium: 102.0.5005.61 -> 102.0.5005.115
https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop.html

This update includes 7 security fixes.

CVEs:
CVE-2022-2007 CVE-2022-2008 CVE-2022-2010 CVE-2022-2011

(cherry picked from commit 41c362c9d1)
2022-06-10 20:26:16 +00:00
Martin Weinelt
0305e119c1 Merge pull request #177185 from NixOS/backport-177181-to-release-21.11 2022-06-10 17:10:21 +02:00
Fabian Affolter
4eea060535 apacheHttpd: 2.4.53 -> 2.4.54
https://downloads.apache.org/httpd/CHANGES_2.4.54

Fixes: CVE-2022-31813, CVE-2022-30556, CVE-2022-30522, CVE-2022-29404,
CVE-2022-28615, CVE-2022-28614, CVE-2022-28330, CVE-2022-26377

(cherry picked from commit 35c7173cf5)
2022-06-10 14:44:26 +00:00
nixpkgs-upkeep-bot
986a3db4f7 vscode: 1.67.2 -> 1.68.0
(cherry picked from commit df118d7a7a)
2022-06-10 13:02:41 +00:00
github-actions[bot]
d2ac9769ad Merge release-21.11 into staging-next-21.11 2022-06-10 00:13:53 +00:00
Robert Schütz
a7f0b0832f python2Packages.pyjwt: mark insecure
(cherry picked from commit 007ffa6069)
2022-06-09 13:48:55 -07:00
Robert Schütz
206a2bb8b0 poetry: mark insecure
The version of urllib3 in poetry.lock (1.25.11) is vulnerable to
CVE-2021-33503.
2022-06-09 13:48:26 -07:00
github-actions[bot]
f95f0e01fd Merge release-21.11 into staging-next-21.11 2022-06-09 00:13:15 +00:00
Vincent Laporte
1c06dad447 qarte: 4.15.1 → 4.17.1
(cherry picked from commit a6494aad0bddfb46e3d5ac6be37408bdbdbea3e0)
2022-06-08 23:34:09 +02:00
github-actions[bot]
4cc5905cd3 Merge release-21.11 into staging-next-21.11 2022-06-08 00:13:07 +00:00
adisbladis
4dbec24ea8 Merge pull request #176814 from dotlambda/rmfuse-0.2.3
[21.11] rmfuse: 0.2.1 -> 0.2.3
2022-06-08 06:34:58 +08:00
adisbladis
3063885846 rmfuse: Re-lock dependencies
So Pillow is bumped https://pillow.readthedocs.io/en/stable/releasenotes/9.1.1.html.

Closes #175600

(cherry picked from commit 4537ba53c0)
2022-06-07 21:32:35 +00:00
adisbladis
315ca9bed8 rmfuse: 0.2.1 -> 0.2.3
(cherry picked from commit 9ea7bd4e67)
2022-06-07 21:32:35 +00:00
Robert Schütz
1fa4894d95 python2Packages.urllib3: mark insecure
(cherry picked from commit ac4fc73abc)
2022-06-07 09:59:02 -07:00
Bobby Rong
877e24dac6 Merge pull request #176357 from NixOS/backport-168882-to-release-21.11
[Backport release-21.11] vscode: fix auto encoding detection crashing editor window
2022-06-07 12:17:33 +08:00
github-actions[bot]
743e26042d Merge release-21.11 into staging-next-21.11 2022-06-07 00:11:48 +00:00
Thiago Kenji Okada
07a8317a79 Merge pull request #176358 from LeSuisse/21.11-argocd-2.1.15
[21.11] argocd: 2.1.6 -> 2.1.15
2022-06-06 09:26:57 +01:00
Vladimír Čunát
19b68784b7 Merge #176511: python3Packages.black: disable test on aarch64-linux
...into release-21.11
2022-06-06 08:25:00 +02:00
Martin Weinelt
fd7ddfc4f5 python3Packages.black: disable test on aarch64-linux
This test reproducibly triggers the max open files limit on our
aarch64 hydra builders. Disable it for now to make tests work again but
this can't be the final solution.

https://hydra.nixos.org/build/179001754
(cherry picked from commit 3fcf9f18dd)
2022-06-06 06:19:11 +00:00
github-actions[bot]
ca74c807c1 Merge release-21.11 into staging-next-21.11 2022-06-06 00:12:17 +00:00
Kerstin
a9daf7ff20 Merge pull request #176468 from NixOS/backport-176415-to-release-21.11
[Backport release-21.11] imagemagick: 7.1.0-36 -> 7.1.0-37
2022-06-05 23:29:07 +02:00
Robert Schütz
261894c7eb imagemagick: 7.1.0-36 -> 7.1.0-37
(cherry picked from commit 2badffbd99)
2022-06-05 20:27:11 +00:00
Vladimír Čunát
5986ddf62a Merge #175627: staging-next-21.11: iteration 16 2022-06-05 16:27:03 +02:00
FliegendeWurst
2673460137 zoneminder: 1.36.10 -> 1.36.15
(cherry picked from commit 1920be67a7)
2022-06-05 13:42:04 +02:00
Thomas Gerbet
3821fa4721 argocd: 2.1.6 -> 2.1.15
Fixes CVE-2022-29165, CVE-2022-24904, CVE-2022-24905, CVE-2022-1025 and CVE-2022-24348.

https://github.com/argoproj/argo-cd/releases/tag/v2.1.15
https://github.com/argoproj/argo-cd/releases/tag/v2.1.14
https://github.com/argoproj/argo-cd/releases/tag/v2.1.13
https://github.com/argoproj/argo-cd/releases/tag/v2.1.12
https://github.com/argoproj/argo-cd/releases/tag/v2.1.11
https://github.com/argoproj/argo-cd/releases/tag/v2.1.10
https://github.com/argoproj/argo-cd/releases/tag/v2.1.9
https://github.com/argoproj/argo-cd/releases/tag/v2.1.8
https://github.com/argoproj/argo-cd/releases/tag/v2.1.7
2022-06-05 12:11:50 +02:00
Sandro Jäckel
f3621d1d0b vscode: fix auto encoding detection crashing editor window
Closes #152939

(cherry picked from commit 2ca1c98617)
2022-06-05 10:09:32 +00:00
Sandro Jäckel
ed736f7201 vscode: move asar to nativeBuildInputs
(cherry picked from commit 92fe27da60)
2022-06-05 10:09:32 +00:00
Vladimír Čunát
536caf8cc3 Merge #176350: metrics job: schedule on any machine
...into release-21.11
There will be very little development on 21.11, so the usefulness here
will be very low and I'd rather turn off the old machine.
2022-06-05 11:09:05 +02:00
Vladimír Čunát
7d9476f90a metrics job: schedule on any machine, for now
For non-time metrics it doesn't matter,
and those seem more important anyway.
So better this than nothing, for now.

(cherry picked from commit 3ea36f0f74)
2022-06-05 09:08:44 +00:00
github-actions[bot]
c2ad897e36 Merge release-21.11 into staging-next-21.11 2022-06-05 00:15:29 +00:00
Robin Gloster
2de556c4cd Merge pull request #176237 from NixOS/backport-176220-to-release-21.11
[Backport release-21.11] atlassian-confluence: 7.17.1 -> 7.18.1
2022-06-04 14:44:48 +02:00
Martin Weinelt
a11bc745b2 atlassian-confluence: 7.17.1 -> 7.18.1
(cherry picked from commit 4f250bc45a)
2022-06-04 12:16:01 +00:00
maxine [they]
ca5231d8ed Merge pull request #175781 from NixOS/backport-175722-to-release-21.11
[Backport release-21.11] webkitgtk: 2.36.2 -> 2.36.3
2022-06-04 13:40:47 +02:00
Yaya
87937d32d5 gitlab: 14.9.4 -> 14.9.5 (#175842)
https://about.gitlab.com/releases/2022/06/01/critical-security-release-gitlab-15-0-1-released/

Fixes: CVE-2022-1680, CVE-2022-1940, CVE-2022-1948, CVE-2022-1935,
       CVE-2022-1936, CVE-2022-1944, CVE-2022-1821, CVE-2022-1783.
2022-06-04 13:34:51 +02:00
Martin Weinelt
0ee15ac24e Merge pull request #176222 from NixOS/backport-169518-to-release-21.11 2022-06-04 12:59:36 +02:00
techknowlogick
c6f6edaf67 atlassian-confluence: 7.14.1 -> 7.17.1
(cherry picked from commit f202a18f60)
2022-06-04 10:34:43 +00:00
github-actions[bot]
f15f0b2f57 Merge release-21.11 into staging-next-21.11 2022-06-02 00:17:20 +00:00
Martin Weinelt
bce6d15455 Merge pull request #175760 from NixOS/backport-175729-to-release-21.11 2022-06-01 22:36:29 +02:00
Martin Weinelt
2e0d2fe6a0 webkitgtk: 2.36.2 -> 2.36.3
https://webkitgtk.org/2022/05/28/webkitgtk2.36.3-released.html
https://webkitgtk.org/security/WSA-2022-0005.html

Fixes: CVE-2022-26700, CVE-2022-26709, CVE-2022-26717, CVE-2022-26716,
       CVE-2022-26719, CVE-2022-30293, CVE-2022-30294
(cherry picked from commit 5e92d30497c662a40432e3c9d5e3a8f866fdb57c)
2022-06-01 16:54:39 +00:00
Linus Heckemann
df2c0dd42c jellyfin: fix permissions on state directory
Previously, all configuration and state data was accessible to all
users on the system running jellyfin. This included user passwords in
the Jellyfin database, as well as credentials for LDAP if configured.
The exact set of accessible data depends on system configuration.

Thanks to Sofie Finnes Øvrelid for reporting this issue.

Fixes: CVE-2022-32198

Co-Authored-By: Martin Weinelt <hexa@darmstadt.ccc.de>
(cherry picked from commit 7eab23d517)
2022-06-01 15:25:41 +00:00
github-actions[bot]
29c553102e Merge release-21.11 into staging-next-21.11 2022-06-01 00:15:41 +00:00
Martin Weinelt
5402a15b97 Merge pull request #175618 from mweinelt/21.11/mozilla 2022-06-01 00:25:50 +02:00
Robert Schütz
a24b93f1c9 imagemagick: 7.1.0-35 -> 7.1.0-36
(cherry picked from commit bd1d3d243a)
2022-05-31 15:04:32 -07:00
Martin Weinelt
3e4303df38 firefox-unwrapped: migrate common to rust 1.60 and icu71
The 101.0 build requires at least Rust 1.59 and icu 71.1.
2022-05-31 20:00:37 +02:00
Mario Rodas
2ede1b9648 icu71: init at 71.1
https://github.com/unicode-org/icu/releases/tag/release-71-1
(cherry picked from commit 8203e061ec)
2022-05-31 20:00:36 +02:00
Martin Weinelt
e1b1886310 rust-cbindgen: 0.22.0 -> 0.23.0
https://github.com/eqrion/cbindgen/releases/tag/v0.23.0
(cherry picked from commit 2165db62ee)
2022-05-31 20:00:36 +02:00
Martin Weinelt
bd669bd9fb rust-cbindgen: 0.21.0 -> 0.22.0
https://github.com/eqrion/cbindgen/releases/tag/v0.22.0
(cherry picked from commit 061d442dce)
2022-05-31 20:00:36 +02:00
R. Ryantm
2a8dfeb498 rust-cbindgen: 0.20.0 -> 0.21.0
(cherry picked from commit 0b1a35a788)
2022-05-31 20:00:36 +02:00
Vladimír Čunát
3e5d3a1f7b Merge branch 'staging-21.11' into staging-next-21.11 2022-05-31 19:42:25 +02:00
Alyssa Ross
a226a433fd rust_1_60: init
(cherry picked from commit 6d49a35080)
2022-05-31 19:00:15 +02:00
Martin Weinelt
db305f8eea firefox-devedition-bin-unwrapped: 101.0b9 -> 102.0b1
(cherry picked from commit ab1dd069c7)
2022-05-31 17:44:07 +02:00
Martin Weinelt
6a07afe855 firefox-beta-bin-unwrapped: 101.0b9 -> 102.0b1
(cherry picked from commit 172e3144ab)
2022-05-31 17:44:03 +02:00
Martin Weinelt
530d6a950f spidermonkey_91: 91.9.1 -> 91.10.0
(cherry picked from commit 78ffb8f7ae)
2022-05-31 17:43:53 +02:00
Martin Weinelt
9de0bbf9e3 firefox-esr-91-unwrapped: 91.9.1esr -> 91.10.0esr
https://www.mozilla.org/en-US/firefox/91.10.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-21/

Fixes: CVE-2022-31736, CVE-2022-31737, CVE-2022-31738, CVE-2022-31739,
       CVE-2022-31740, CVE-2022-31741, CVE-2022-31742, CVE-2022-31747
(cherry picked from commit f89d5a7f2c)
2022-05-31 17:43:42 +02:00
Martin Weinelt
913b421d70 firefox-bin-unwrapped: 100.0.2- -> 101.0
https://www.mozilla.org/en-US/firefox/101.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-20/

Fixes: CVE-2022-31736, CVE-2022-31737, CVE-2022-31738, CVE-2022-31739,
       CVE-2022-31740, CVE-2022-31741, CVE-2022-31742, CVE-2022-31743,
       CVE-2022-31744, CVE-2022-31745, CVE-2022-1919, CVE-2022-31747,
       CVE-2022-31748
(cherry picked from commit 8353459d92)
2022-05-31 17:43:02 +02:00
Martin Weinelt
30a54aec09 firefox-unwrapped: 100.0.2- -> 101.0
https://www.mozilla.org/en-US/firefox/101.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-20/

Fixes: CVE-2022-31736, CVE-2022-31737, CVE-2022-31738, CVE-2022-31739,
       CVE-2022-31740, CVE-2022-31741, CVE-2022-31742, CVE-2022-31743,
       CVE-2022-31744, CVE-2022-31745, CVE-2022-1919, CVE-2022-31747,
       CVE-2022-31748
(cherry picked from commit 332711833d)
2022-05-31 17:42:59 +02:00
Bobby Rong
ec6eaba9df Merge pull request #175587 from NixOS/backport-175273-to-release-21.11
[Backport release-21.11] drawio: 18.0.6 -> 18.1.3
2022-05-31 19:27:55 +08:00
DarkOnion0
7927314514 drawio: 18.0.6 -> 18.1.3
(cherry picked from commit 48210371c1)
2022-05-31 10:49:08 +00:00
github-actions[bot]
7c9420eef1 Merge staging-next-21.11 into staging-21.11 2022-05-31 00:14:20 +00:00
github-actions[bot]
96af382f71 Merge release-21.11 into staging-next-21.11 2022-05-31 00:13:45 +00:00
Maximilian Bosch
3994556253 Merge pull request #175167 from NixOS/backport-175024-to-release-21.11
[Backport release-21.11] wiki-js: 2.5.282 -> 2.5.283
2022-05-30 15:52:06 +02:00
Jeremy Kolb
742a1ff5b2 remove unused fetchpatch
(cherry picked from commit 8daaf8e398f356513147fec989e6222ea842fd8b)
2022-05-30 01:22:32 -07:00
Jeremy Kolb
73af32cc73 open-vm-tools: 12.0.0 -> 12.0.5
(cherry picked from commit e3548876c046c2cc27bb274e0d68ada85ac10aa8)
2022-05-30 01:22:32 -07:00
Thomas Gerbet
d89b15a9dd zlog: fixes CVE-2021-43521
(cherry picked from commit a0a5f90ef2)
2022-05-30 01:18:27 -07:00
Robin Gloster
b6075839b4 vim: 8.2.4874 -> 8.2.4975
(cherry picked from commit 2e4c67b555)
2022-05-29 23:39:44 -07:00
Robin Gloster
81ab93f8d4 vim: 8.2.4816 -> 8.2.4874
fixes:
 - 7.8 https://nvd.nist.gov/vuln/detail/CVE-2022-1619
 - 7.5 https://nvd.nist.gov/vuln/detail/CVE-2022-1620
 - 7.8 https://nvd.nist.gov/vuln/detail/CVE-2022-1621
 - 7.8 https://nvd.nist.gov/vuln/detail/CVE-2022-1629
(cherry picked from commit 6c822e25b6)
2022-05-29 23:39:44 -07:00
Robert Scott
1a5e48b6b0 Merge pull request #175143 from NixOS/backport-173327-to-staging-21.11
[Backport staging-21.11] libtiff: add patches for CVE-2022-1354 & CVE-2022-1355
2022-05-30 01:18:30 +01:00
github-actions[bot]
cf4f4ef291 Merge staging-next-21.11 into staging-21.11 2022-05-30 00:16:42 +00:00
github-actions[bot]
577d3a77b1 Merge release-21.11 into staging-next-21.11 2022-05-30 00:16:06 +00:00
Bobby Rong
cc257c49c4 Merge pull request #175228 from NixOS/backport-175112-to-release-21.11
[Backport release-21.11] snowflake: 2.0.1 -> 2.2.0
2022-05-29 21:16:49 +08:00
Rick van Schijndel
baa82d4b62 Merge pull request #175262 from NixOS/backport-174762-to-release-21.11
[Backport release-21.11] u-boot: embiggen RPi kernel allocation again, again
2022-05-29 12:19:38 +02:00
Vladimír Čunát
0ae425394d Merge #174339: e2fsprogs: apply patch unconditionally
...into release-21.11
2022-05-29 10:46:19 +02:00
K900
9fd4e05dfa u-boot: embiggen RPi kernel allocation again, again
(cherry picked from commit ff391e0f0d)
2022-05-29 07:47:32 +00:00
Yaya
b834942975 snowflake: 2.0.1 -> 2.2.0
(cherry picked from commit 45109ffcb8)
2022-05-29 03:29:52 +00:00
github-actions[bot]
f07076e7e2 Merge staging-next-21.11 into staging-21.11 2022-05-29 00:15:29 +00:00
github-actions[bot]
1a09ced822 Merge release-21.11 into staging-next-21.11 2022-05-29 00:14:47 +00:00
Rick van Schijndel
d98f1aa5df Merge pull request #175175 from NixOS/backport-173132-to-release-21.11
[Backport release-21.11] sigi: 3.3.0 -> 3.4.0
2022-05-28 23:22:41 +02:00
hiljusti
441fc9ef60 sigi: 3.3.0 -> 3.4.0
(cherry picked from commit 96467f286f)
2022-05-28 18:59:39 +00:00
Maximilian Bosch
b9d3b94272 wiki-js: 2.5.282 -> 2.5.283
ChangeLog: https://github.com/requarks/wiki/releases/tag/v2.5.283
(cherry picked from commit 9b11851ccf)
2022-05-28 18:24:10 +00:00
Robert Scott
6192483a14 libtiff: add patches for CVE-2022-1354 & CVE-2022-1355
(cherry picked from commit 8d8b43cb3c)
2022-05-28 15:08:18 +00:00
Martin Weinelt
69970cc8e2 Merge pull request #174901 from LeSuisse/cups-CVE-2022-26691-21.11 2022-05-28 12:23:15 +02:00
github-actions[bot]
9536eea4ee Merge staging-next-21.11 into staging-21.11 2022-05-28 00:15:31 +00:00
github-actions[bot]
61b0402d41 Merge release-21.11 into staging-next-21.11 2022-05-28 00:14:56 +00:00
Thomas Gerbet
3ef64f557a cups: fixes CVE-2022-26691 2022-05-27 14:38:30 +02:00
Kerstin Humm
13c15a84ff mastodon: 3.5.2 -> 3.5.3
(cherry picked from commit db795b8f2b7c6d315f50acba15c0491b4f0f1907)
2022-05-27 14:05:55 +02:00
Maximilian Bosch
370d3eef4b Merge pull request #174812 from NixOS/backport-174773-to-release-21.11
[Backport release-21.11] Linux kernel updates 2022-05-25
2022-05-27 07:56:14 +02:00
github-actions[bot]
24c8cc0064 Merge release-21.11 into staging-next-21.11 2022-05-27 00:13:47 +00:00
Maximilian Bosch
d439c00b0f linux/hardened/patches/5.4: 5.4.195-hardened1 -> 5.4.196-hardened1
(cherry picked from commit 75f4c62775)
2022-05-26 22:52:29 +00:00
Maximilian Bosch
14d7392dd3 linux/hardened/patches/5.17: 5.17.9-hardened1 -> 5.17.11-hardened1
(cherry picked from commit ec4b2a871d)
2022-05-26 22:52:28 +00:00
Maximilian Bosch
1b65838921 linux/hardened/patches/5.15: 5.15.41-hardened1 -> 5.15.43-hardened1
(cherry picked from commit e97b03a780)
2022-05-26 22:52:28 +00:00
Maximilian Bosch
bba3672fa3 linux/hardened/patches/5.10: 5.10.117-hardened1 -> 5.10.118-hardened1
(cherry picked from commit d8d0dd929e)
2022-05-26 22:52:28 +00:00
Maximilian Bosch
7686ff5d71 linux/hardened/patches/4.19: 4.19.244-hardened1 -> 4.19.245-hardened1
(cherry picked from commit 63192641bb)
2022-05-26 22:52:28 +00:00
Maximilian Bosch
0ba8ca04ee linux/hardened/patches/4.14: 4.14.280-hardened1 -> 4.14.281-hardened1
(cherry picked from commit 08daee172e)
2022-05-26 22:52:28 +00:00
Maximilian Bosch
9a99008b3e linux: 5.4.195 -> 5.4.196
(cherry picked from commit d505557a29)
2022-05-26 22:52:28 +00:00
Maximilian Bosch
ad9b5022d1 linux: 5.17.9 -> 5.17.11
(cherry picked from commit c57d757e1b)
2022-05-26 22:52:28 +00:00
Maximilian Bosch
52fba79ed4 linux: 5.15.41 -> 5.15.43
(cherry picked from commit bc0db57d53)
2022-05-26 22:52:28 +00:00
Maximilian Bosch
83a2b02b9e linux: 5.10.117 -> 5.10.118
(cherry picked from commit ec5629f3f2)
2022-05-26 22:52:28 +00:00
Maximilian Bosch
a802e8ecc8 linux: 4.9.315 -> 4.9.316
(cherry picked from commit 110b58f77e)
2022-05-26 22:52:28 +00:00
Maximilian Bosch
0c0b3a37a1 linux: 4.19.244 -> 4.19.245
(cherry picked from commit b5c4a60bbe)
2022-05-26 22:52:28 +00:00
Maximilian Bosch
b48f65909c linux: 4.14.280 -> 4.14.281
(cherry picked from commit f2e1f34e4c)
2022-05-26 22:52:28 +00:00
Michael Weiss
7c75ba3448 Merge pull request #174780 from NixOS/backport-174623-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 101.0.4951.64 -> 102.0.5005.61
2022-05-26 22:08:43 +02:00
Michael Weiss
5ec7056588 Merge pull request #174781 from NixOS/backport-174338-to-release-21.11
[Backport release-21.11] chromium: 101.0.4951.64 -> 102.0.5005.61
2022-05-26 22:08:08 +02:00
Michael Weiss
070511ab7f chromium: 101.0.4951.64 -> 102.0.5005.61
https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html

This update includes 32 security fixes.

CVEs:
CVE-2022-1853 CVE-2022-1854 CVE-2022-1855 CVE-2022-1856 CVE-2022-1857
CVE-2022-1858 CVE-2022-1859 CVE-2022-1860 CVE-2022-1861 CVE-2022-1862
CVE-2022-1863 CVE-2022-1864 CVE-2022-1865 CVE-2022-1866 CVE-2022-1867
CVE-2022-1868 CVE-2022-1869 CVE-2022-1870 CVE-2022-1871 CVE-2022-1872
CVE-2022-1873 CVE-2022-1874 CVE-2022-1875 CVE-2022-1876

(cherry picked from commit e48814a245)
2022-05-26 18:24:45 +00:00
Michael Weiss
422fd63345 ungoogled-chromium: 101.0.4951.64 -> 102.0.5005.61
(cherry picked from commit 6226fc5cf0)
2022-05-26 18:24:43 +00:00
Michael Weiss
fcfb7b85b0 Merge pull request #174703 from primeos/chromium-backport
[21.11] Prepare for backporting Chromium M102
2022-05-26 20:17:25 +02:00
ajs124
9bc0e97454 Merge pull request #174584 from oxzi/logrotate-3.20.1-21.11
[Backport release-21.11] logrotate: fix CVE-2022-1348
2022-05-26 13:48:09 +02:00
Alvar Penning
f1b847e132 logrotate: fix CVE-2022-1348 2022-05-26 12:20:30 +02:00
Michael Weiss
21a18c6b04 chromiumBeta: Fix the build
The build was failing with:
[4758/49762] ACTION //third_party/dawn/src/dawn/common:dawn_version_gen__json_tarball(//build/toolchain/linux/unbundle:default)Ke:default)ux/unbundle:default)[Kuide/optimization_guide_internals/resources/optimization_guide_internals.mojom-webui.js
FAILED: gen/third_party/dawn/dawn_version_gen.json_tarball
python3 ../../third_party/dawn/generator/dawn_version_generator.py --dawn-dir ../../third_party/dawn/ --template-dir /build/chromium-102.0.5005.49/third_party/dawn/generator/templates --jinja2-path /build/chromium-102.0.5005.49/third_party/jinja2 --output-json-tarball gen/third_party/dawn/dawn_version_gen.json_tarball --depfile gen/third_party/dawn/dawn_version_gen.json_tarball.d --expected-outputs-file gen/third_party/dawn/dawn_version_gen.expected_outputs --allowed-output-dirs-file gen/third_party/dawn/dawn_version_gen.allowed_output_dirs
Traceback (most recent call last):
[...]
FileNotFoundError: [Errno 2] No such file or directory: 'git'
[4761/49762] ACTION //third_party/blink/renderer/bindings:generate_bindings_all(//build/toolchain/linux/unbundle:default)fault)
ninja: build stopped: subcommand failed.

More details here: https://bugs.chromium.org/p/chromium/issues/detail?id=1321370

The patch doesn't apply to M102 so I had to cherry-pick it manually.

(cherry picked from commit 37a13a3d4d)
2022-05-26 11:54:45 +02:00
Michael Weiss
873fff2e1f chromiumDev: 103.0.5042.0 -> 103.0.5056.0
(cherry picked from commit e1fb27152d)
2022-05-26 11:54:45 +02:00
Michael Weiss
a5912a8e90 chromiumBeta: 102.0.5005.40 -> 102.0.5005.49
(cherry picked from commit 46a14c6a37)
2022-05-26 11:54:45 +02:00
Michael Weiss
c5679c77de chromiumDev: 103.0.5028.0 -> 103.0.5042.0
(cherry picked from commit fdeff96262)
2022-05-26 11:54:45 +02:00
Michael Weiss
7f1730aae3 chromiumBeta: 102.0.5005.27 -> 102.0.5005.40
(cherry picked from commit e1ae57055b)
2022-05-26 11:54:44 +02:00
Michael Weiss
d641d1074d chromiumBeta: Fix a compilation error
LLVM 14 doesn't support those build flags yet
(-no-opaque-pointers is the argument for -Xclang):
error: unknown argument: '-no-opaque-pointers'

Those build flags were added in the following commit:
003067c130

(cherry picked from commit 7f684c2ba0)
2022-05-26 11:54:44 +02:00
Michael Weiss
54e391808c chromiumBeta: Fix the configuration phase
This fixes the following error:
configuring
ERROR at //infra/orchestrator/BUILD.gn:38:17: Could not read file.
  pydeps_file = "//third_party/blink/tools/merge_web_test_results.pydeps"
                ^--------------------------------------------------------
I resolved this to "/build/chromium-102.0.5005.27/third_party/blink/tools/merge_web_test_results.pydeps".
See //infra/orchestrator/BUILD.gn:37:1: whence it was called.
python_library("blink_merge_web_test_results_py") {
^--------------------------------------------------
See //BUILD.gn:89:5: which caused the file to be included.
    "//infra/orchestrator:orchestrator_all",
    ^--------------------------------------

It's a known upstream issue when building from the generated tarballs:
- https://bugs.chromium.org/p/chromium/issues/detail?id=1313361
- https://chromium-review.googlesource.com/c/chromium/src/+/3457503

(cherry picked from commit 73e094bf3c)
2022-05-26 11:54:44 +02:00
Sandro Jäckel
995f834136 google-chrome: remove legacy ? null
(cherry picked from commit 60c4482872)
2022-05-26 11:54:43 +02:00
Michael Weiss
eb88ce39d1 chromiumBeta: 101.0.4951.41 -> 102.0.5005.27
(cherry picked from commit b446b38810)
2022-05-26 11:54:43 +02:00
Michael Weiss
2ffc3580ac chromiumDev: 102.0.5005.22 -> 103.0.5028.0
(cherry picked from commit 2f3629b3ab)
2022-05-26 11:54:43 +02:00
Michael Weiss
3d2dfb21af chromiumDev: 102.0.5005.12 -> 102.0.5005.22
(cherry picked from commit 9cdfc7d612)
2022-05-26 11:54:43 +02:00
Michael Weiss
f5d47e51a3 chromiumDev: Fix the patch phase
This fixes the following error during patchShebangs:
./third_party/dawn/third_party/webgpu-cts/tools/run_deno: unsupported interpreter directive "#!/usr/bin/env -S deno run --unstable --allow-read --allow-write --allow-env --allow-net=deno.land --no-check" (set dontPatchShebangs=1 and handle shebang patching yourself)

(cherry picked from commit 3e8d4d6237)
2022-05-26 11:54:42 +02:00
github-actions[bot]
74a298fc50 Merge staging-next-21.11 into staging-21.11 2022-05-26 00:15:18 +00:00
github-actions[bot]
12394ab9fa Merge release-21.11 into staging-next-21.11 2022-05-26 00:14:38 +00:00
Alyssa Ross
454c54d7b6 linuxPackages.vendor-reset: enable parallel building
Tested at -j48.

(cherry picked from commit 9dab6bc07744790f5ca081fd9af07db1547bfaf5)
2022-05-25 22:21:19 +00:00
Alyssa Ross
b5633cb915 linuxPackages.vendor-reset: patch for Linux 5.18
(cherry picked from commit d851e2f78a2c270e0f8ba1954cd884830796c8d0)
2022-05-25 22:21:19 +00:00
Alyssa Ross
244c3c00bb linuxPackages.netatop: fix build with Linux 5.18
With 5.18, implicit fallthrough is an error, and netatop hasn't caught
up yet.

(cherry picked from commit 197e9ba286917cf32ed85efa117a14285b21a998)
2022-05-25 22:17:48 +00:00
Pascal Bach
f982c55881 Merge pull request #174310 from NixOS/backport-174280-to-release-21.11
[Backport release-21.11] element-{web,desktop}: 1.10.12 -> 1.10.13
2022-05-25 21:40:34 +02:00
Doron Behar
f09dae7538 Merge pull request #174427 from wamserma/backport-173474-to-release-21.11
[21.11] zoom-us: 5.9.6.2225 -> 5.10.6.3192 (x86_64-linux)/5.10.4.6592 (darwin) (backport, security)
2022-05-25 17:39:02 +03:00
Sebastian Reuße
e0c7ffdb65 zoom-us: 5.10.4.2845 -> 5.10.6.3192 on x86_64-linux
Fixes #174147

(cherry picked from commit 1b27e162e5)
2022-05-25 08:49:37 +02:00
Thomas Nixon
742f1bdea6 zoom-us: change wrapper name to fix IPC
(cherry picked from commit fa585a07f6)
2022-05-25 08:39:42 +02:00
Will Dietz
7647f19155 zoom: add dep for udev, fix launching
(cherry picked from commit 215155b440)
2022-05-25 08:39:39 +02:00
Clemens Lutz
9c8e0d220d zoom-us: Update dependencies
(cherry picked from commit 5791f1c43f)
2022-05-25 08:39:35 +02:00
Thomas Nixon
5a2f45bcb7 zoom-us: 5.9.6.2225 -> 5.10.4.2845 on x86_64-linux
(cherry picked from commit bb17d93a56)
2022-05-25 08:39:29 +02:00
Bobby Rong
919f8a2d7d Merge pull request #174262 from NixOS/backport-174220-to-release-21.11
[Backport release-21.11] pantheon.gala: save/restore easing on workspace switch
2022-05-25 12:40:00 +08:00
github-actions[bot]
2986620de3 Merge staging-next-21.11 into staging-21.11 2022-05-25 00:16:56 +00:00
github-actions[bot]
50627c84ef Merge release-21.11 into staging-next-21.11 2022-05-25 00:16:14 +00:00
Vladimír Čunát
8a4a2c925f e2fsprogs: apply patch unconditionally
Commit 49d0a5afd mistakenly inverted when to apply the patch.
Maybe it's not needed anymore, as pkgsMusl.e2fsprogs succeeded for me
even without it, but it looks harmless and better not have it inversed.
This way we also don't cause a mass rebuild :-)

(cherry picked from commit f008987704)
2022-05-24 22:47:44 +00:00
Martin Weinelt
38a25ca6dd Merge pull request #174313 from NixOS/backport-174249-to-release-21.11
[Backport release-21.11] tor-browser-bundle-bin: 11.0.11 -> 11.0.13
2022-05-24 23:09:46 +02:00
FliegendeWurst
2a04da3432 tor-browser-bundle-bin: 11.0.11 -> 11.0.13
(cherry picked from commit 5c801dd601)
2022-05-24 20:36:08 +00:00
Sumner Evans
0ebc81a314 element-{web,desktop}: 1.10.12 -> 1.10.13
(cherry picked from commit 402e5fe40d)
2022-05-24 20:24:00 +00:00
Martin Weinelt
ad432b3fc1 Merge pull request #174302 from NixOS/backport-174111-to-release-21.11
[Backport release-21.11] linuxPackages.nvidiabl: use a better homepage
2022-05-24 21:14:50 +02:00
Alyssa Ross
690c6e8042 linuxPackages.nvidiabl: use a better homepage
It makes more sense to point this to the fork that we're using, rather
than the upstream.

(cherry picked from commit 062d21eead)
2022-05-24 19:05:30 +00:00
Vladimír Čunát
2eb86322c1 Merge #174077: staging-next-21.11: iteration 15 2022-05-24 15:36:05 +02:00
Maximilian Bosch
d6ba149dd6 Merge pull request #173415 from NixOS/backport-173185-to-release-21.11
[Backport release-21.11] linux_5_17: add hardened kernel
2022-05-24 14:27:11 +02:00
Maximilian Bosch
e6e3874cd5 Merge pull request #173878 from NixOS/backport-173762-to-release-21.11
[Backport release-21.11] nextcloud: 22.2.7 -> 22.2.8, 23.0.4 -> 23.0.5, 24.0.0 -> 24.0.1
2022-05-24 14:26:56 +02:00
Maximilian Bosch
c85c74ebc7 Merge pull request #173220 from arnottcr/php81
[21.11] php81: init at 8.1.6
2022-05-24 13:54:18 +02:00
Martin Weinelt
60d45dc86e Merge pull request #174132 from NixOS/backport-174005-to-staging-21.11 2022-05-24 13:42:05 +02:00
Bobby Rong
e486a90bcd pantheon.gala: save/restore easing on workspace switch
(cherry picked from commit 7d48c204ef)
2022-05-24 10:32:01 +00:00
Thomas Gerbet
b86a394db4 nbd: 3.21 -> 3.24
Fixes CVE-2022-26495 and CVE-2022-26496.

https://sourceforge.net/projects/nbd/files/nbd/3.24/relnotes.txt/download
https://sourceforge.net/projects/nbd/files/nbd/3.23/changelog.txt/download
https://sourceforge.net/projects/nbd/files/nbd/3.22/relnotes.txt/download

(cherry picked from commit f33ccd6ec9)
2022-05-24 08:43:04 +02:00
github-actions[bot]
cbad2f2340 Merge staging-next-21.11 into staging-21.11 2022-05-24 00:15:29 +00:00
github-actions[bot]
a700d9ec51 Merge release-21.11 into staging-next-21.11 2022-05-24 00:14:51 +00:00
Janne Heß
1c813bbdc3 Merge pull request #173982 from helsinki-systems/upd/21.11/mariadb
[21.11] mariadb_106: 10.6.7 -> 10.6.8
2022-05-23 17:17:50 +02:00
Martin Weinelt
749818e700 python39: 3.9.12 -> 3.9.13
https://www.python.org/downloads/release/python-3913/
https://blog.python.org/2022/05/python-3913-is-now-available.html
(cherry picked from commit 761ecd1061)
2022-05-23 14:49:33 +00:00
Linus Heckemann
4cfde57fa8 Merge pull request #173971 from NixOS/backport-173269-to-release-21.11
[Backport release-21.11] pjsip: 2.12 -> 2.12.1
2022-05-23 13:31:25 +02:00
Vladimír Čunát
69688a526e Merge branch 'staging-21.11' into staging-next-21.11 2022-05-23 06:29:35 +02:00
github-actions[bot]
21be6cfa64 Merge staging-next-21.11 into staging-21.11 2022-05-23 00:16:30 +00:00
github-actions[bot]
e43a6028ae Merge release-21.11 into staging-next-21.11 2022-05-23 00:15:53 +00:00
Vladimír Čunát
7415688994 Merge 173991: freetype: patch for multiple CVEs
...into staging-21.11
2022-05-22 21:06:31 +02:00
Mario Rodas
06db2e2197 Merge pull request #173958 from NixOS/backport-173685-to-release-21.11
[Backport release-21.11] vscodium: 1.67.1 -> 1.67.2
2022-05-22 09:30:24 -05:00
Mario Rodas
17ad45246a Merge pull request #173961 from NixOS/backport-173684-to-release-21.11
[Backport release-21.11] vscode: 1.67.1 -> 1.67.2
2022-05-22 09:30:01 -05:00
Thomas Tuegel
c5ee24a894 freetype: patch for multiple CVEs
Fixes:

- CVE-2022-27404
- CVE-2022-27405
- CVE-2022-27406
2022-05-22 08:38:32 -05:00
ajs124
a321df5be0 mariadb_106: 10.6.7 -> 10.6.8
(cherry picked from commit 4d0a7e4704)
2022-05-22 13:05:49 +02:00
Martin Weinelt
6741c0a7bb Merge pull request #172329 from lheckemann/twisted-backport 2022-05-22 12:18:27 +02:00
Linus Heckemann
43b0485de3 pjsip: 2.12 -> 2.12.1
Release notes: https://github.com/pjsip/pjproject/releases/tag/2.12.1

Fixes: CVE-2022-24754, CVE-2022-24763, CVE-2022-24764,
       CVE-2022-24786, CVE-2022-24792, CVE-2022-24793
(cherry picked from commit 7ac64fcbae)
2022-05-22 10:05:27 +00:00
Martin Weinelt
168061820a Merge pull request #173750 from Ma27/grafana-cve-2022-29170-21.11 2022-05-22 11:58:28 +02:00
nixpkgs-upkeep-bot
df0c673914 vscode: 1.67.1 -> 1.67.2
(cherry picked from commit d325181784)
2022-05-22 08:49:02 +00:00
nixpkgs-upkeep-bot
28918799a2 vscodium: 1.67.1 -> 1.67.2
(cherry picked from commit 9c48424780)
2022-05-22 08:38:21 +00:00
Vladimír Čunát
47b7aed6dd Merge #173879: mozilla minor updates (into release-21.11)
firefox{,-bin}: 100.0.1 -> 100.0.2
firefox-esr: 91.9.0esr -> 91.9.1esr
firefox-beta-bin: 98.0b5 -> 101.0b9
firefox-devedition-bin: 101.0b6 -> 101.0b9
thunderbird{,-bin}: 91.9.0 -> 91.9.1
spidermonkey_91: 91.9.0 -> 91.9.1
2022-05-22 09:45:01 +02:00
github-actions[bot]
58a8514ee2 Merge staging-next-21.11 into staging-21.11 2022-05-22 00:15:56 +00:00
github-actions[bot]
e5a8ccb03f Merge release-21.11 into staging-next-21.11 2022-05-22 00:15:15 +00:00
Martin Weinelt
df498c3fa0 firefox-beta-bin: 99.0b6 -> 101.0b9
(cherry picked from commit 796a7117da)
2022-05-21 13:54:14 +02:00
R. Ryantm
2f35ca269e firefox-beta-bin-unwrapped: 98.0b5 -> 99.0b6
(cherry picked from commit c4527f5bd8)
2022-05-21 13:54:10 +02:00
Martin Weinelt
782fab8ad3 spidermonkey_91: 91.9.0 -> 91.9.1
https://www.mozilla.org/en-US/security/advisories/mfsa2022-19/

Fixes: CVE-2022-1802, CVE-2022-1529
(cherry picked from commit ba2e66efd1)
2022-05-21 13:53:22 +02:00
Martin Weinelt
d196aaa24b thunderbird-bin: 91.9.0 -> 91.9.1
https://www.thunderbird.net/en-US/thunderbird/91.9.1/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-19/

Fixes: CVE-2022-1802, CVE-2022-1529
(cherry picked from commit 4d87a694e3)
2022-05-21 13:53:18 +02:00
Martin Weinelt
17d8d28d68 thunderbird: 91.9.0 -> 91.9.1
https://www.thunderbird.net/en-US/thunderbird/91.9.1/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-19/

Fixes: CVE-2022-1802, CVE-2022-1529
(cherry picked from commit 0d4f241bc9)
2022-05-21 13:53:14 +02:00
Martin Weinelt
e7e9a72c47 firefox-esr: 91.9.0esr -> 91.9.1esr
https://www.mozilla.org/en-US/firefox/91.9.1/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-19/

Fixes: CVE-2022-1802, CVE-2022-1529
(cherry picked from commit a6685a5a78)
2022-05-21 13:53:06 +02:00
Martin Weinelt
3c71cd63a3 firefox-devedition-bin-unwrapped: 101.0b6 -> 101.0b9
(cherry picked from commit b9bf854088)
2022-05-21 13:52:33 +02:00
Martin Weinelt
a637760c5c firefox-bin: 100.0.1 -> 100.0.2
https://www.mozilla.org/en-US/firefox/100.0.2/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-19/

Fixes: CVE-2022-1802, CVE-2022-1529
(cherry picked from commit 9f9dfc2fe2)
2022-05-21 13:52:27 +02:00
Martin Weinelt
b8746dcbc8 firefox: 100.0.1 -> 100.0.2
https://www.mozilla.org/en-US/firefox/100.0.2/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-19/

Fixes: CVE-2022-1802, CVE-2022-1529
(cherry picked from commit b7172d4238)
2022-05-21 13:52:24 +02:00
Yaya
3c58fe02a1 nextcloud: 22.2.7 -> 22.2.8, 23.0.4 -> 23.0.5, 24.0.0 -> 24.0.1
(cherry picked from commit d8d36fa0ed)
2022-05-21 11:47:23 +00:00
Maximilian Bosch
b5991e4971 Merge pull request #173788 from Ma27/backport-mautrix-whatsapp
[21.11] mautrix-whatsapp: 0.3.1 -> 0.4.0
2022-05-21 13:23:31 +02:00
github-actions[bot]
7d5956bf56 Merge staging-next-21.11 into staging-21.11 2022-05-21 00:15:39 +00:00
github-actions[bot]
065f8d47d7 Merge release-21.11 into staging-next-21.11 2022-05-21 00:15:04 +00:00
Martin Weinelt
cbd40c72b2 Merge pull request #173573 from jtojnar/webkitgtk-2.36.2-bp 2022-05-21 01:01:47 +02:00
Maximilian Bosch
47283b6130 Merge pull request #173760 from Ma27/backport-synapse
[21.11] matrix-synapse: 1.57.0 -> 1.59.1
2022-05-20 18:32:25 +02:00
Charlotte Van Petegem
5ce230880f mautrix-whatsapp: add myself as a maintainer
(cherry picked from commit 9d4a9f1396)
2022-05-20 18:28:29 +02:00
Charlotte Van Petegem
30205abcc3 mautrix-whatsapp: 0.3.1 -> 0.4.0
https://github.com/mautrix/whatsapp/releases/tag/v0.4.0
(cherry picked from commit 3668437702)
2022-05-20 18:28:24 +02:00
Robert Schütz
2857b73e5c imagemagick: 7.1.0-34 -> 7.1.0-35
(cherry picked from commit 6501ee65b0)
2022-05-20 08:53:48 -07:00
Sumner Evans
5645cdb8c5 matrix-synapse: 1.58.0 -> 1.59.1
(cherry picked from commit 2836ac6b83)
2022-05-20 14:15:42 +02:00
Charlotte 🦝 Delenk
ba4ab43ce2 matrix-synapse: 1.57.0 -> 1.58.0
Closes #169534

(cherry picked from commit 7f1ddd2da5)
2022-05-20 14:15:39 +02:00
Maximilian Bosch
b441d14d06 Merge pull request #173680 from NixOS/backport-173642-to-release-21.11
[Backport release-21.11] Linux kernel updates
2022-05-20 13:22:59 +02:00
Maximilian Bosch
8db1edd669 grafana: fix CVE-2022-29170
We're still using 8.4.x on 21.11 because 8.5 contained a few breaking
changes[1]. The patch for 8.5[2] was almost compatible with 8.4, but had
to be modified a bit because `New` in `http_client_provider` had a
slightly different signature:

    func New(cfg *setting.Cfg, tracer tracing.Tracer, features featuremgmt.FeatureToggles) *sdkhttpclient.Provider

on 8.4.7 vs

    func New(cfg *setting.Cfg, tracer tracing.Tracer) *sdkhttpclient.Provider

on 8.5.2.

I only had to adjust the signature in the test (because `PluginRequestValidator`
was added), but nothing else because these calls are automatically
resolved via `wire`.

[1] https://github.com/grafana/grafana/releases/tag/v8.5.0
[2] 2f75684500
2022-05-20 12:48:51 +02:00
Vincent Laporte
ab19261c41 jasmin-compiler: 21.0 → 2022.04.0
(cherry picked from commit aee00ac405)
2022-05-20 11:28:17 +02:00
github-actions[bot]
0ad77a4b40 Merge staging-next-21.11 into staging-21.11 2022-05-20 00:14:46 +00:00
github-actions[bot]
3983a9c4fa Merge release-21.11 into staging-next-21.11 2022-05-20 00:14:07 +00:00
Maximilian Bosch
18618ba38b linux/hardened/patches/5.4: 5.4.193-hardened1 -> 5.4.195-hardened1
(cherry picked from commit 82273adfcd)
2022-05-19 22:32:04 +00:00
Maximilian Bosch
995a70f455 linux/hardened/patches/5.17: 5.17.7-hardened1 -> 5.17.9-hardened1
(cherry picked from commit 5c9571087e)
2022-05-19 22:32:04 +00:00
Maximilian Bosch
cc9a164413 linux/hardened/patches/5.15: 5.15.39-hardened1 -> 5.15.41-hardened1
(cherry picked from commit 7f512f7153)
2022-05-19 22:32:04 +00:00
Maximilian Bosch
36d890f081 linux/hardened/patches/5.10: 5.10.115-hardened1 -> 5.10.117-hardened1
(cherry picked from commit 240e224783)
2022-05-19 22:32:04 +00:00
Maximilian Bosch
50c8d60f72 linux/hardened/patches/4.19: 4.19.242-hardened1 -> 4.19.244-hardened1
(cherry picked from commit 28a954cabf)
2022-05-19 22:32:04 +00:00
Maximilian Bosch
f327ca9de0 linux/hardened/patches/4.14: 4.14.278-hardened1 -> 4.14.280-hardened1
(cherry picked from commit eea0f09983)
2022-05-19 22:32:04 +00:00
Maximilian Bosch
ba85b143db linux_latest-libre: 18713 -> 18738
(cherry picked from commit 3edcbfce89)
2022-05-19 22:32:04 +00:00
Maximilian Bosch
c8019c3a13 linux-rt_5_4: 5.4.188-rt73 -> 5.4.193-rt74
(cherry picked from commit 1f98b560c8)
2022-05-19 22:32:04 +00:00
Maximilian Bosch
98d4af3ffd linux-rt_5_10: 5.10.109-rt65 -> 5.10.115-rt67
(cherry picked from commit c49791b326)
2022-05-19 22:32:03 +00:00
Maximilian Bosch
9def96eb65 linux: 5.4.193 -> 5.4.195
(cherry picked from commit d56829b5fe)
2022-05-19 22:32:03 +00:00
Maximilian Bosch
9a18d25fb1 linux: 5.17.7 -> 5.17.9
(cherry picked from commit cfb71b715e)
2022-05-19 22:32:03 +00:00
Maximilian Bosch
12083feade linux: 5.15.39 -> 5.15.41
(cherry picked from commit 8935b4d533)
2022-05-19 22:32:03 +00:00
Maximilian Bosch
266151f95e linux: 5.10.115 -> 5.10.117
(cherry picked from commit 1b81fcd678)
2022-05-19 22:32:03 +00:00
Maximilian Bosch
d97bc24d3c linux: 4.9.313 -> 4.9.315
(cherry picked from commit 4072349a31)
2022-05-19 22:32:03 +00:00
Maximilian Bosch
65558079cb linux: 4.19.242 -> 4.19.244
(cherry picked from commit a7d95e31bc)
2022-05-19 22:32:03 +00:00
Maximilian Bosch
3d6f1c7c5d linux: 4.14.278 -> 4.14.280
(cherry picked from commit 3431806dfa)
2022-05-19 22:32:03 +00:00
Maximilian Bosch
685d243d97 Merge pull request #173614 from NixOS/backport-173022-to-release-21.11
[Backport release-21.11] wiki-js: 2.5.279 -> 2.5.282
2022-05-19 17:49:14 +02:00
Maximilian Bosch
d213ff5631 wiki-js: 2.5.279 -> 2.5.282
ChangeLog: https://github.com/requarks/wiki/releases/tag/v2.5.280
ChangeLog: https://github.com/requarks/wiki/releases/tag/v2.5.281
ChangeLog: https://github.com/requarks/wiki/releases/tag/v2.5.282
(cherry picked from commit 2c0b81666d)
2022-05-19 13:06:37 +00:00
Wout Mertens
401d50df81 Merge pull request #173602 from wmertens/nodejs18-backport-21.11
nodejs: backport all including v18
2022-05-19 15:04:03 +02:00
Wout Mertens
3427ee14bc nodejs: backport all including v18 2022-05-19 15:01:19 +02:00
ajs124
8180090bad Merge pull request #173545 from NixOS/backport-172351-to-release-21.11
[Backport release-21.11] spidermonkey_91: 91.8.0 -> 91.9.0
2022-05-19 14:57:51 +02:00
Vladimír Čunát
43538dfb5d Merge #173574: python3Packages.deepdiff: skip a broken test
...into release-21.11
2022-05-19 08:57:46 +02:00
Vladimír Čunát
d4004bcff1 python3Packages.deepdiff: skip a broken test 2022-05-19 08:16:15 +02:00
Vladimír Čunát
bd161c378a Merge #173174: staging-next-21.11: iteration 14 2022-05-19 08:05:44 +02:00
Vladimír Čunát
038ce3ae62 Merge #173193: firefox* + thunderbird: minor updates
...into release-21.11

firefox{,-bin}: 100.0 -> 100.0.1
firefox-devedition: 98.0b5 -> 101.0b6
thunderbird{,bin}: 91.8.1 -> 91.9.0
2022-05-19 07:57:02 +02:00
Jan Tojnar
49a807d14f libwpe: inherit maintainers from webkitgtk
(cherry picked from commit 26d7d7b5b2a21091f506507e0bf9f79c523433c4)
2022-05-19 07:37:20 +02:00
Jan Tojnar
5c26aa860a webkitgtk: re-enable WPE_RENDERER
Build with WPE renderer is no longer tested upstream
https://bugs.webkit.org/show_bug.cgi?id=238513#c10
and that configuration is extremely buggy since 2.36.0:
https://github.com/NixOS/nixpkgs/issues/169201

Previously it was disabled in c0d053ea0e.

(cherry picked from commit 303f80a9b4748439729e590b36585f9c14555420)
2022-05-19 07:37:20 +02:00
Jan Tojnar
df2284ebbc webkitgtk: 2.36.1 → 2.36.2
https://webkitgtk.org/2022/05/18/webkitgtk2.36.2-released.html
(cherry picked from commit 191443a545ad2439dde1ef36767a5bb112f28da7)
2022-05-19 07:36:49 +02:00
R. Ryantm
93c9c28daa libwpe: 1.10.1 -> 1.12.0
(cherry picked from commit c6201cd8e42a7eb433d4dc6ca10b5300d2d78c09)
2022-05-19 07:19:01 +02:00
R. Ryantm
a15147b15b libwpe-fdo: 1.10.0 -> 1.12.0
(cherry picked from commit 5f7829d7a2a79a294c2f66be758145b258bc8b70)
2022-05-19 07:18:43 +02:00
Mario Rodas
bf38b30deb Merge pull request #173559 from NixOS/backport-173470-to-release-21.11
[Backport release-21.11] yt-dlp: 2022.04.08 -> 2022.05.18
2022-05-18 20:47:30 -05:00
Mario Rodas
d72a095150 yt-dlp: add marsam to maintainers
(cherry picked from commit 74fb021e95)
2022-05-19 01:25:12 +00:00
Mario Rodas
93f107ffdc yt-dlp: 2022.04.08 -> 2022.05.18
https://github.com/yt-dlp/yt-dlp/releases/tag/2022.05.18
(cherry picked from commit 032433e985)
2022-05-19 01:25:12 +00:00
github-actions[bot]
8b1c9b6112 Merge staging-next-21.11 into staging-21.11 2022-05-19 00:16:24 +00:00
github-actions[bot]
4917b9fd54 Merge release-21.11 into staging-next-21.11 2022-05-19 00:15:44 +00:00
misuzu
9d983e89f6 git-workspace: 0.9.0 -> 1.0.3
https://github.com/orf/git-workspace/releases/tag/v1.0.3
https://github.com/orf/git-workspace/compare/v0.9.0...v1.0.3
(cherry picked from commit 33294cea74)
2022-05-18 23:21:14 +00:00
misuzu
6116050671 alfis: 0.7.0 -> 0.7.3
https://github.com/Revertron/Alfis/releases/tag/v0.7.3
https://github.com/Revertron/Alfis/compare/v0.7.0...v0.7.3
(cherry picked from commit 27e96516f8)
2022-05-18 23:21:12 +00:00
Will
a7380e6edd spidermonkey_91: 91.8.0 -> 91.9.0
(cherry picked from commit bbb27f8eb3)
2022-05-18 23:15:20 +00:00
Bobby Rong
2d474d6a4a Merge pull request #173420 from DarkOnion0/drawio-backport
[21.11] drawio: 18.0.4 -> 18.0.6
2022-05-18 21:36:41 +08:00
Pol Dellaiera
db75a30cd4 php81: 8.1.5 -> 8.1.6
(cherry picked from commit e76ad56103)
2022-05-18 12:53:46 +00:00
Pol Dellaiera
a85054fdea php81: 8.1.4 -> 8.1.5
(cherry picked from commit 47d7d17126)
2022-05-18 12:53:46 +00:00
Pol Dellaiera
8cd90f4f3c php81: 8.1.3 -> 8.1.4
(cherry picked from commit a5911f1597)
2022-05-18 12:53:46 +00:00
Pol Dellaiera
091967c67c php81: 8.1.2 -> 8.1.3
(cherry picked from commit 96983152e7)
2022-05-18 12:53:46 +00:00
Pol Dellaiera
b447ec0d05 php81: 8.1.1 -> 8.1.2
(cherry picked from commit 6794a2c3f6)
2022-05-18 12:53:46 +00:00
Stéphan Kochen
528d3bff9a php81Extensions.tokenizer: fix build
(cherry picked from commit cf7f4c058e822ee8eeaa2120c45f04b5b460a5db)
(cherry picked from commit 2dbf96e7cc)
2022-05-18 12:53:45 +00:00
Pol Dellaiera
925a3bfbd7 php81: init at 8.1.1
(cherry picked from commit 3d3479f717)

22.05 release notes purged.
2022-05-18 12:53:45 +00:00
R. Ryantm
5d39f5fe43 php74Extensions.apcu: 5.1.20 -> 5.1.21
(cherry picked from commit 0ea3426d4d)
2022-05-18 12:53:29 +00:00
Maximilian Bosch
0c98728e74 Merge pull request #173094 from arnottcr/nextcloud-backport
[21.11] nextcloud24: init at 24.0.0
2022-05-18 13:55:08 +02:00
Artturi
1e46397e1a Merge pull request #168283 from NixOS/backport-165147-to-release-21.11
[Backport release-21.11] psi-plus: 1.5.1600 -> 1.5.1615
2022-05-18 04:54:22 +03:00
github-actions[bot]
ce6bd1964b Merge staging-next-21.11 into staging-21.11 2022-05-18 00:15:36 +00:00
github-actions[bot]
a9a50249ea Merge release-21.11 into staging-next-21.11 2022-05-18 00:14:59 +00:00
Martin Weinelt
2816fee9ce Merge pull request #173319 from mweinelt/21.11/gitea 2022-05-17 23:48:21 +02:00
DarkOnion0
a758174fd0 drawio: 18.0.4 -> 18.0.6
(cherry picked from commit 6f0d3c8ec7)
2022-05-17 18:47:47 +02:00
Izorkin
17ecf8e39c linux_5_17: add hardened kernel
(cherry picked from commit 983d2a78ac)
2022-05-17 16:04:57 +00:00
Robert Schütz
254ee2b340 imagemagick: 7.1.0-33 -> 7.1.0-34
(cherry picked from commit 74fec3925e554abee4c9d0798adfaed03f7dc52c)
2022-05-17 16:15:00 +02:00
Bobby Rong
5e9f738928 Merge pull request #173088 from bobby285271/vscode
[21.11] vscode, vscodium: 1.66.2 -> 1.67.1
2022-05-17 10:27:32 +08:00
github-actions[bot]
20b45d77bd Merge staging-next-21.11 into staging-21.11 2022-05-17 00:16:30 +00:00
github-actions[bot]
93c441888e Merge release-21.11 into staging-next-21.11 2022-05-17 00:15:56 +00:00
Martin Weinelt
6db11cf332 gitea: Escape git fetch args in repo migration
https://github.com/go-gitea/gitea/pull/19487
https://nvd.nist.gov/vuln/detail/CVE-2022-30781

Fixes: CVE-2022-30781
2022-05-17 00:31:46 +02:00
adisbladis
fbbe8ed7e0 Merge pull request #173268 from DeterminateSystems/podman
[21.11] podman: add patch for CVE-2022-27649
2022-05-16 22:21:35 +08:00
Linus Heckemann
1d2c4ceb88 podman: add patch for CVE-2022-27649
"default inheritable capabilities for linux container not empty"
https://github.com/advisories/GHSA-qvf8-p83w-v58j

Fixes: CVE-2022-27649
2022-05-16 15:12:05 +02:00
Linus Heckemann
d3fd775b83 Merge pull request #173257 from NixOS/backport-172369-to-release-21.11
[Backport release-21.11] microcodeIntel: 20220419 -> 20220510
2022-05-16 14:20:33 +02:00
Martin Weinelt
b1c69808d4 microcodeIntel: 20220419 -> 20220510
https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20220510
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00617.html

Fixes: CVE-2022-21151
(cherry picked from commit 72429cd8ea)
2022-05-16 11:54:37 +00:00
Sandro Jäckel
6bd6014e12 python310Packages.txtorcon: fix test execution, cleanup
(cherry picked from commit de3f5c2270)
2022-05-16 13:34:14 +02:00
Linus Heckemann
43b05746b1 python310Packages.txtorcon: 21.1.0 -> 22.0.0
(cherry picked from commit f63c2d1278)
2022-05-16 13:34:14 +02:00
Martin Weinelt
8a103ab70f python3Packages.twisted: 22.2.0 -> 22.4.0
(cherry picked from commit 8aaa019221)
2022-05-16 13:34:13 +02:00
ajs124
a1e9e42241 python3.pkgs.twisted: 21.7.0 -> 22.2.0
(cherry picked from commit f31c35ab3d)
2022-05-16 13:34:13 +02:00
Linus Heckemann
287aac98c2 Merge pull request #173244 from NixOS/backport-172835-to-release-21.11
[Backport release-21.11] clamav: 0.103.5 -> 0.103.6
2022-05-16 12:48:21 +02:00
Linus Heckemann
cd3a233499 clamav: 0.103.5 -> 0.103.6
Fixes a number of vulnerabilities.

https://github.com/Cisco-Talos/clamav/blob/rel/0.103/NEWS.md#01036
https://mmmds.pl/clamav/

Fixes: CVE-2022-20803, CVE-2022-20770, CVE-2022-20796, CVE-2022-20771,
       CVE-2022-20785, CVE-2022-20792
(cherry picked from commit 833884de60)
2022-05-16 08:50:25 +00:00
Artturi
c718807499 Merge pull request #169198 from NixOS/backport-168875-to-release-21.11
[Backport release-21.11] hydrus: 480 -> 481
2022-05-16 05:28:26 +03:00
Artturi
d5d86bce2a Merge pull request #169963 from NixOS/backport-160246-to-release-21.11
[Backport release-21.11] droidmote: init at 3.0.6
2022-05-16 05:27:29 +03:00
github-actions[bot]
674abd49e1 [Backport release-21.11] libde265: fix CVE-2022-1253 (#172856)
* libde265: fix CVE-2022-1253

Closes #172496

(cherry picked from commit 8699bfd2149e9122e677e08f0a46e3104a5ad290)

* Update pkgs/development/libraries/libde265/default.nix

Co-authored-by: Linus Heckemann <git@sphalerite.org>
(cherry picked from commit fe4ca85c970a7bbd1746869865040787a8e6a5ec)

* Update pkgs/development/libraries/libde265/default.nix

(cherry picked from commit 0bc6dafb12b79112a695c7027fa6c3d0f97ab917)

Co-authored-by: Sandro Jäckel <sandro.jaeckel@sap.com>
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
2022-05-16 05:20:05 +03:00
Artturi
da89398901 Merge pull request #164803 from NixOS/backport-164735-to-release-21.11
[Backport release-21.11] nixos/nixos-enter: fix resolv.conf error handling and cleanup
2022-05-16 05:17:20 +03:00
Colin Arnott
359b998f85 nextcloud24: init at 24.0.0
Added Nextcloud 23 and set it as the default Nextcloud version for the
NixOS module. Added PHP 8.1 as an option for phpPackage and default for
Nextcloud ≥ 24.

(cherry picked from commit ecd8d42397)

Backport #171736 to release-21.11. We have multiple attributes for
different majors, so this is technically a new package that can be
backported.

The defaults aren't changed, so nextcloud22 is still the default for
NixOS 21.11. We have also removed php81 references, as that has not been
backported to 21.11.
2022-05-16 01:49:34 +00:00
github-actions[bot]
2e66d3560e Merge staging-next-21.11 into staging-21.11 2022-05-16 00:17:42 +00:00
github-actions[bot]
85bbf23a75 Merge release-21.11 into staging-next-21.11 2022-05-16 00:17:09 +00:00
Martin Weinelt
9974e77449 thunderbird-bin: 91.8.1 -> 91.9.0
https://www.thunderbird.net/en-US/thunderbird/91.9.0/releasenotes/
(cherry picked from commit 440242bec3)
2022-05-15 22:29:41 +02:00
Martin Weinelt
44052c0e1a thunderbird: 91.8.1 -> 91.9.0
https://www.thunderbird.net/en-US/thunderbird/91.9.0/releasenotes/
(cherry picked from commit 79a6d4dd8e)
2022-05-15 22:29:37 +02:00
Martin Weinelt
b6f1ce2a77 firefox-devedition-bin-unwrapped: 101.0b2 -> 101.0b6
(cherry picked from commit 51ac22dd46)
2022-05-15 22:29:32 +02:00
Martin Weinelt
fb29872bde firefox-devedition-bin-unwrapped: 100.0b7 -> 101.0b2
(cherry picked from commit 3382215fd7)
2022-05-15 22:29:27 +02:00
R. Ryantm
6b92a93fbb firefox-devedition-bin-unwrapped: 100.0b6 -> 100.0b7
(cherry picked from commit 868991dbac)
2022-05-15 22:29:23 +02:00
R. Ryantm
657d3d831d firefox-devedition-bin-unwrapped: 100.0b5 -> 100.0b6
(cherry picked from commit 572d0f9997)
2022-05-15 22:29:19 +02:00
Martin Weinelt
7fc6b82cb5 firefox-devedition-bin-unwrapped: 99.0b6 -> 100.0b5
(cherry picked from commit 4a92b1e81f)
2022-05-15 22:29:11 +02:00
R. Ryantm
e30619bbfb firefox-devedition-bin-unwrapped: 98.0b5 -> 99.0b6
(cherry picked from commit ff37bc3937)
2022-05-15 22:29:06 +02:00
Martin Weinelt
ecdce12b74 firefox-bin: 100.0 -> 100.0.1
https://www.mozilla.org/en-US/firefox/100.0.1/releasenotes/
(cherry picked from commit c87b0dd59c)
2022-05-15 22:28:22 +02:00
Martin Weinelt
01b72c93de firefox: 100.0 -> 100.0.1
https://www.mozilla.org/en-US/firefox/100.0.1/releasenotes/
(cherry picked from commit 142cf31abb)
2022-05-15 22:28:18 +02:00
Jörg Thalheim
d598c2cf42 Merge pull request #173178 from DarkOnion0/drawio-backport
[21.11] drawio: 15.7.3 -> 18.0.4
2022-05-15 20:42:20 +01:00
Pavol Rusnak
a77a22e9fd Merge pull request #173176 from prusnak/backport-172961-to-release-21.11
[21.11] electron: (mostly) remove dependency on libXss.so
2022-05-15 19:59:20 +02:00
Noah Fontes
96323809b2 electron: (mostly) remove dependency on libXss.so
Electron 10, which is built from Chromium 85.0.4183.84, no longer
depends on libXScrnSaver. This was removed from Chromium upstream in
revision 782094
(https://chromium-review.googlesource.com/c/chromium/src/+/2261490),
which landed in Chromium 85.0.4182.0
(https://storage.googleapis.com/chromium-find-releases-static/aa5.html#aa5c637805cd33366f2181ed6ec54e0ed174a6f9).

This change removes the LD_PRELOAD of libXss.so.1 and simply includes
libXScrnSaver in the rpath for Electron versions prior to 10.0.0.

(cherry picked from commit f26abaa2ef)
2022-05-15 19:57:48 +02:00
DarkOnion0
a3d4de251d drawio: 15.7.3 -> 18.0.4 2022-05-15 19:47:27 +02:00
Vladimír Čunát
3b007d986c Merge branch 'staging-21.11' into staging-next-21.11 2022-05-15 19:17:38 +02:00
Vladimír Čunát
67e5b8dc81 Merge #172640: curl: patch CVE-2022-27781 & CVE-2022-27782
...into staging-21.11
2022-05-15 19:04:02 +02:00
nixpkgs-upkeep-bot
451e28045a vscodium: 1.66.2 -> 1.67.1
(cherry picked from commit 21f9e5c728)
2022-05-15 10:56:43 +08:00
mat ess
0da9433c27 vscodium: Add support for aarch64-darwin (M1)
(cherry picked from commit 2d985f3fd1)
2022-05-15 10:56:30 +08:00
nixpkgs-upkeep-bot
4a51f8f0a6 vscode: 1.67.0 -> 1.67.1
(cherry picked from commit 27cae2d5a2)
2022-05-15 10:54:49 +08:00
nixpkgs-upkeep-bot
189e2ace18 vscode: 1.66.2 -> 1.67.0
(cherry picked from commit 98ebce8e1c)
2022-05-15 10:54:13 +08:00
github-actions[bot]
348e54c7f6 Merge staging-next-21.11 into staging-21.11 2022-05-15 00:20:17 +00:00
github-actions[bot]
170ba1a184 Merge release-21.11 into staging-next-21.11 2022-05-15 00:19:44 +00:00
Niklas Hambüchen
8b3398bc75 Merge pull request #172618 from nh2/consul-1.11.5-nixos-21.11
[21.11] consul: 1.10.3 -> 1.10.10
2022-05-14 22:17:02 +02:00
Mario Rodas
6879c4f633 Merge pull request #172919 from bachp/minio-2022-05-08T23-50-31Z_21.11
[Backport release-21.11] minio: 2022-01-08T03-11-54Z -> 2022-05-08T23-50-31
2022-05-14 11:08:33 -05:00
Mario Rodas
4c560cc7ee Merge pull request #172984 from NixOS/backport-172942-to-release-21.11
[Backport release-21.11] signal-desktop: 5.42.0 -> 5.43.0
2022-05-14 07:16:10 -05:00
Maximilian Bosch
3293938416 Merge pull request #172876 from NixOS/backport-172848-to-release-21.11
[Backport release-21.11] Linux kernels 2022-05-13
2022-05-14 11:47:11 +02:00
Maximilian Bosch
dd188f4aba Merge pull request #172669 from NixOS/backport-172574-to-release-21.11
[Backport release-21.11] element-{web,desktop}: 1.10.11 -> 1.10.12
2022-05-14 11:46:59 +02:00
Eduardo Quiros
d520daa919 signal-desktop: 5.42.0 -> 5.43.0
(cherry picked from commit 7c2e6fb71e)
2022-05-14 06:10:42 +00:00
github-actions[bot]
ff9d9d3366 Merge staging-next-21.11 into staging-21.11 2022-05-14 00:19:14 +00:00
github-actions[bot]
03945797c6 Merge release-21.11 into staging-next-21.11 2022-05-14 00:18:08 +00:00
Alyssa Ross
273637c50f e2fsprogs: patch for CVE-2022-1304
Did a basic smoke test of e2fsck.

(cherry picked from commit 49d0a5afdc03a7bf276e455c1875fd571ca0711b)
2022-05-13 21:37:53 +00:00
Pascal Bach
b6c879a44c minio: 2022-03-22T02-05-10Z -> 2022-05-08T23-50-31Z 2022-05-13 22:15:32 +02:00
R. Ryantm
eca65b3bbf minio: 2022-03-17T06-34-49Z -> 2022-03-22T02-05-10Z 2022-05-13 22:15:28 +02:00
Pascal Bach
43a1a44781 minio: 2022-02-26T02-54-46Z -> 2022-03-17T06-34-49Z 2022-05-13 22:15:24 +02:00
R. Ryantm
1a384314e4 minio: 2022-02-24T22-12-01Z -> 2022-02-26T02-54-46Z 2022-05-13 22:15:20 +02:00
R. Ryantm
47793bbff3 minio: 2022-02-18T01-50-10Z -> 2022-02-24T22-12-01Z 2022-05-13 22:15:16 +02:00
R. Ryantm
27858d5d3f minio: 2022-02-16T00-35-27Z -> 2022-02-18T01-50-10Z 2022-05-13 22:15:12 +02:00
R. Ryantm
1e5d59b6c3 minio: 2022-02-12T00-51-25Z -> 2022-02-16T00-35-27Z 2022-05-13 22:15:08 +02:00
R. Ryantm
5b9bc2e81e minio: 2022-02-07T08-17-33Z -> 2022-02-12T00-51-25Z 2022-05-13 22:15:04 +02:00
R. Ryantm
dd23c7a630 minio: 2022-01-08T03-11-54Z -> 2022-02-07T08-17-33Z 2022-05-13 22:14:57 +02:00
Maximilian Bosch
0e28f06f35 linux/hardened/patches/5.4: 5.4.192-hardened1 -> 5.4.193-hardened1
(cherry picked from commit 081daee45e)
2022-05-13 15:11:12 +00:00
Maximilian Bosch
0133afb75b linux/hardened/patches/5.17: 5.17.6-hardened1 -> 5.17.7-hardened1
(cherry picked from commit 1d8fa8ef14)
2022-05-13 15:11:12 +00:00
Maximilian Bosch
a54091b21e linux/hardened/patches/5.15: 5.15.38-hardened1 -> 5.15.39-hardened1
(cherry picked from commit b644615669)
2022-05-13 15:11:12 +00:00
Maximilian Bosch
f31bc25d67 linux/hardened/patches/5.10: 5.10.114-hardened1 -> 5.10.115-hardened1
(cherry picked from commit 6abf4b2b96)
2022-05-13 15:11:12 +00:00
Maximilian Bosch
16c03e5b40 linux/hardened/patches/4.19: 4.19.241-hardened1 -> 4.19.242-hardened1
(cherry picked from commit 34ede69b72)
2022-05-13 15:11:12 +00:00
Maximilian Bosch
6fb64771fb linux/hardened/patches/4.14: 4.14.277-hardened1 -> 4.14.278-hardened1
(cherry picked from commit ab2f51774b)
2022-05-13 15:11:12 +00:00
Maximilian Bosch
c92336e3c1 linux: 5.4.192 -> 5.4.193
(cherry picked from commit 3543468280)
2022-05-13 15:11:12 +00:00
Maximilian Bosch
cf2a26cbb0 linux: 5.17.6 -> 5.17.7
(cherry picked from commit dcc82f4e65)
2022-05-13 15:11:11 +00:00
Maximilian Bosch
86679d3bd2 linux: 5.15.38 -> 5.15.39
(cherry picked from commit 2b8fcabeb6)
2022-05-13 15:11:11 +00:00
Maximilian Bosch
b76f28dfd8 linux: 5.10.114 -> 5.10.115
(cherry picked from commit 2bea336233)
2022-05-13 15:11:11 +00:00
Maximilian Bosch
5e9f8f0e77 linux: 4.9.312 -> 4.9.313
(cherry picked from commit 7885a53197)
2022-05-13 15:11:11 +00:00
Maximilian Bosch
2f148e6d29 linux: 4.19.241 -> 4.19.242
(cherry picked from commit 30efbf1352)
2022-05-13 15:11:11 +00:00
Maximilian Bosch
45c8de49ec linux: 4.14.277 -> 4.14.278
(cherry picked from commit 6956681f24)
2022-05-13 15:11:11 +00:00
Artturi
79385ae0aa Merge pull request #167042 from fleimgruber/backport_alda_2_2_0
[Backport release-21.11] alda: 2.0.6 -> 2.2.0
2022-05-13 14:48:48 +03:00
Mario Rodas
7473d31f57 Merge pull request #172797 from NixOS/backport-172781-to-staging-21.11
[Backport staging-21.11] postgresql: 10.20 -> 10.21, 11.15 -> 11.16, 12.10 -> 12.11, 13.6 -> 13.7, 14.2 -> 14.3
2022-05-12 23:29:14 -05:00
Mario Rodas
fe9d75a319 postgresql_14: 14.2 -> 14.3
https://www.postgresql.org/docs/release/14.3/
(cherry picked from commit 242c4aaf39)
2022-05-13 03:44:40 +00:00
Mario Rodas
c91da8b742 postgresql_13: 13.6 -> 13.7
https://www.postgresql.org/docs/release/13.7/
(cherry picked from commit 84e86fc9ee)
2022-05-13 03:44:40 +00:00
Mario Rodas
22d1bfa3c6 postgresql_12: 12.10 -> 12.11
https://www.postgresql.org/docs/release/12.11/
(cherry picked from commit 9d599ca124)
2022-05-13 03:44:40 +00:00
Mario Rodas
6e2394fd10 postgresql_11: 11.15 -> 11.16
https://www.postgresql.org/docs/release/11.16/
(cherry picked from commit 74707e7b12)
2022-05-13 03:44:40 +00:00
Mario Rodas
9ba0b12e01 postgresql_10: 10.20 -> 10.21
https://www.postgresql.org/docs/release/10.21/
(cherry picked from commit 5a19730b5d)
2022-05-13 03:44:40 +00:00
Mario Rodas
c75d2f857f Merge pull request #172370 from NixOS/backport-169423-to-release-21.11
[Backport release-21.11] microcodeIntel: 20220207 -> 20220419
2022-05-12 19:29:24 -05:00
github-actions[bot]
426a09b42a Merge staging-next-21.11 into staging-21.11 2022-05-13 00:17:55 +00:00
github-actions[bot]
dc402d571c Merge release-21.11 into staging-next-21.11 2022-05-13 00:17:20 +00:00
Mario Rodas
f0d5f07600 Merge pull request #172701 from NixOS/backport-172599-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 101.0.4951.54 -> 101.0.4951.64
2022-05-12 19:06:23 -05:00
Mario Rodas
900a82d7e3 Merge pull request #172703 from NixOS/backport-172612-to-release-21.11
[Backport release-21.11] brave: 1.38.111 -> 1.38.115
2022-05-12 19:06:05 -05:00
adisbladis
ee80943d4d Merge pull request #172697 from DeterminateSystems/runc
runc: fix CVE-2022-29162
2022-05-12 22:14:05 +08:00
Louis Bettens
000134d061 brave: 1.38.111 -> 1.38.115
(cherry picked from commit 47ff7333f4)
2022-05-12 13:41:11 +00:00
Michael Weiss
e705410c76 ungoogled-chromium: 101.0.4951.54 -> 101.0.4951.64
(cherry picked from commit a0f35c34e1)
2022-05-12 13:27:14 +00:00
Sandro
9bd12b717c Merge pull request #172600 from primeos/chromium-backport
[Backport release-21.11] chromium: 101.0.4951.54 -> 101.0.4951.64
2022-05-12 15:20:59 +02:00
Linus Heckemann
d828170ab1 runc: fix CVE-2022-29162
https://github.com/opencontainers/runc/security/advisories/GHSA-f3fp-gc8g-vw66

Fixes: CVE-2022-29162
2022-05-12 15:06:46 +02:00
Sumner Evans
5b61a6225e element-{web,desktop}: 1.10.11 -> 1.10.12
(cherry picked from commit 8ca6240a84)
2022-05-12 07:54:55 +00:00
Robert Scott
018e284e0c curl: add patches for CVE-2022-27781 & CVE-2022-27782 2022-05-12 01:24:07 +01:00
github-actions[bot]
59d5257f6d Merge staging-next-21.11 into staging-21.11 2022-05-12 00:16:40 +00:00
github-actions[bot]
c0e76bf74b Merge release-21.11 into staging-next-21.11 2022-05-12 00:16:09 +00:00
Niklas Hambüchen
23a8b4e92f [21.11] consul: 1.10.3 -> 1.10.10
Fixes #166623. Fixes #172481.
2022-05-12 00:24:26 +02:00
Michael Weiss
9cc8d4234e chromium: 101.0.4951.54 -> 101.0.4951.64
https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_10.html

This update includes 13 security fixes.

CVEs:
CVE-2022-1633 CVE-2022-1634 CVE-2022-1635 CVE-2022-1636 CVE-2022-1637
CVE-2022-1638 CVE-2022-1639 CVE-2022-1640 CVE-2022-1641

(cherry picked from commit 9a0ff61993)
2022-05-11 21:55:18 +02:00
Michael Weiss
051448e415 Merge pull request #171849 from NixOS/backport-171564-to-release-21.11
[Backport release-21.11] chromium: 101.0.4951.41 -> 101.0.4951.54
2022-05-11 21:54:19 +02:00
Linus Heckemann
e88ce43c86 Merge pull request #172562 from NixOS/backport-172469-to-release-21.11
[Backport release-21.11] Linux kernels 2022-05-11
2022-05-11 16:12:01 +02:00
Maximilian Bosch
8c29b1d821 linux/hardened/patches/5.4: 5.4.191-hardened1 -> 5.4.192-hardened1
(cherry picked from commit e3d598b7e8)
2022-05-11 12:10:45 +00:00
Maximilian Bosch
c2ea8affc1 linux/hardened/patches/5.17: 5.17.5-hardened1 -> 5.17.6-hardened1
(cherry picked from commit c0a5d86c98)
2022-05-11 12:10:45 +00:00
Maximilian Bosch
3b36aaaa44 linux/hardened/patches/5.15: 5.15.36-hardened1 -> 5.15.38-hardened1
(cherry picked from commit e6d741c9dd)
2022-05-11 12:10:45 +00:00
Maximilian Bosch
005e613dc6 linux/hardened/patches/5.10: 5.10.113-hardened1 -> 5.10.114-hardened1
(cherry picked from commit 1fd97805d8)
2022-05-11 12:10:45 +00:00
Maximilian Bosch
e16ef2ab7b linux/hardened/patches/4.19: 4.19.240-hardened1 -> 4.19.241-hardened1
(cherry picked from commit 0faa00ddbe)
2022-05-11 12:10:45 +00:00
Maximilian Bosch
a2370456e2 linux_latest-libre: 18688 -> 18713
(cherry picked from commit 59fe74cca3)
2022-05-11 12:10:45 +00:00
Maximilian Bosch
abc4176ae3 linux: 5.4.191 -> 5.4.192
(cherry picked from commit ee2608d3ab)
2022-05-11 12:10:45 +00:00
Maximilian Bosch
2b209da7e7 linux: 5.17.5 -> 5.17.6
(cherry picked from commit d6bd76af6e)
2022-05-11 12:10:44 +00:00
Maximilian Bosch
d1895fb65f linux: 5.15.37 -> 5.15.38
(cherry picked from commit 38496aa149)
2022-05-11 12:10:44 +00:00
Maximilian Bosch
c3a3e7397d linux: 5.10.113 -> 5.10.114
(cherry picked from commit 8869941b27)
2022-05-11 12:10:44 +00:00
Artturi
32842d319c Merge pull request #172215 from Mic92/signal-desktop-backport
[21.11] signal-desktop: 5.39.0 -> 5.42.0
2022-05-11 13:06:37 +03:00
Anderson Torres
8ff9c57701 Merge pull request #172435 from NixOS/backport-172384-to-release-21.11
[Backport release-21.11] palemoon: 29.4.6 -> 31.0.0
2022-05-11 00:55:20 -03:00
OPNA2608
e1273b235c palemoon: 29.4.6 -> 31.0.0
(cherry picked from commit 0ae3ed37c1)
2022-05-11 01:56:29 +00:00
github-actions[bot]
8b69618aaa Merge staging-next-21.11 into staging-21.11 2022-05-11 00:15:19 +00:00
github-actions[bot]
1300a6ad1a Merge release-21.11 into staging-next-21.11 2022-05-11 00:14:42 +00:00
Martin Weinelt
4e1ab2333b microcodeIntel: 20220207 -> 20220419
https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20220419
(cherry picked from commit c4664f6bf1)
2022-05-10 18:39:45 +00:00
Linus Heckemann
aa2f845096 Merge pull request #166357 from NixOS/backport-163847-to-release-21.11
[Backport release-21.11] tsm-client: 8.1.13.3 -> 8.1.14.0
2022-05-10 13:33:12 +02:00
Vladimír Čunát
b50627e93a Merge #171795: staging-next-21.11: iteration 13 - 2022-05-06 2022-05-10 11:14:51 +02:00
Artturi
5a3499e427 Merge pull request #171948 from NixOS/backport-171918-to-release-21.11
[Backport release-21.11] sigi: 3.2.1 -> 3.3.0
2022-05-10 06:29:25 +03:00
Artturi
558a621b36 Merge pull request #172036 from NixOS/backport-168608-to-release-21.11
[Backport release-21.11] alfis: 0.6.11 -> 0.7.0
2022-05-10 06:28:32 +03:00
Anderson Torres
ef982f3793 Merge pull request #172269 from NixOS/backport-172248-to-release-21.11
[Backport release-21.11] recutils: disable Clang "format" hardening
2022-05-10 00:21:17 -03:00
Artturi
a75b7acc33 Merge pull request #166026 from NixOS/backport-165766-to-release-21.11
[Backport release-21.11] crystal: remove pointless reference to crystal.lib
2022-05-10 06:12:48 +03:00
Theodore Ni
eb24cfd219 recutils: disable Clang "format" hardening
Remove the -Werror=format-security compiler option when using Clang, because
recutils does not build with it enabled.

(cherry picked from commit 3ece875b60)
2022-05-10 01:41:35 +00:00
Anderson Torres
f28c7b0c00 Merge pull request #172175 from NixOS/backport-172123-to-release-21.11
[Backport release-21.11] recutils: 1.8 -> 1.9
2022-05-09 21:45:06 -03:00
github-actions[bot]
2947466b35 Merge staging-next-21.11 into staging-21.11 2022-05-10 00:15:28 +00:00
github-actions[bot]
c4710a3f01 Merge release-21.11 into staging-next-21.11 2022-05-10 00:14:48 +00:00
Linus Heckemann
cf33704649 nextcloud-exporter: mark as vulnerable to CVE-2022-21698
See also #169928 for a PR that would fix this vulnerability; after a
brief discussion with @Ma27 we came to the conclusion that breaking
backwards compatibility silently is more of a pain than breaking
evaluation loudly. We consider the severity of this vulnerability as
relatively low, because prometheus exporters should usually not be
publicly accessible anyway, and believe that this is the best approach
to allowing people who run the exporter the choice of running the
compatible version.

Closes #169928.
2022-05-09 11:17:42 -07:00
Vincent Laporte
32d7d705c4 jasmin-compiler: init at 21.0
(cherry picked from commit 333262b5ee6dcb4cf43a1246c1ebdabab56aed81)
2022-05-09 11:11:32 -07:00
Robert Scott
862bdf3a20 traefik: add patch for CVE-2022-23632 2022-05-09 10:37:16 -07:00
Linus Heckemann
bea5455b70 Merge pull request #171296 from risicle/ris-clickhouse-21.8.15.7-r21.11
[21.11] clickhouse: 21.8.8.29 -> 21.8.15.7
2022-05-09 19:17:57 +02:00
Linus Heckemann
fed5aac0a2 Merge pull request #171052 from FliegendeWurst/zsh-5.8.1
[21.11] zsh: 5.8 -> 5.8.1
2022-05-09 19:08:44 +02:00
Linus Heckemann
b82a8db606 Merge pull request #171059 from risicle/ris-blender-2.93.8-r21.11
[21.11] blender: 2.93.5 -> 2.93.8
2022-05-09 19:07:48 +02:00
Eduardo Quiros
6485f614cf signal-desktop: 5.39.0 -> 5.42.0
(cherry picked from commit 7ffc224e4a)
2022-05-09 18:31:26 +02:00
Linus Heckemann
1f8e77dfae Merge pull request #172168 from NixOS/backport-171777-to-release-21.11
[Backport release-21.11] meshcentral: 0.9.98 -> 1.0.18
2022-05-09 16:20:15 +02:00
AndersonTorres
9a7c282f66 recutils: 1.8 -> 1.9
(cherry picked from commit ae9a9ee941)
2022-05-09 11:42:37 +00:00
R. Ryantm
0cec3ac8b1 meshcentral: 0.9.98 -> 1.0.18
(cherry picked from commit 3babc11a0f)
2022-05-09 11:17:46 +00:00
ajs124
1a9fc5b8ba Merge pull request #172110 from mweinelt/21.11/rsyslog
rsyslog: prevent heap buffer overflows in TCP receiver
2022-05-09 10:31:56 +01:00
markuskowa
e5f4ca5d0d Merge pull request #172106 from markuskowa/back-slurm
slurm: 21.08.5.1 -> 21.08.8.2
2022-05-09 09:29:13 +02:00
github-actions[bot]
5dfa67b3c4 Merge staging-next-21.11 into staging-21.11 2022-05-09 00:15:00 +00:00
github-actions[bot]
ea02ca3cd7 Merge release-21.11 into staging-next-21.11 2022-05-09 00:14:23 +00:00
Martin Weinelt
780900362a rsyslog: prevent heap buffer overflows in TCP receiver
Fixes: CVE-2022-24903
2022-05-09 01:50:30 +02:00
Markus Kowalewski
b33c0d9f1c slurm: 21.08.5.1 -> 21.08.8.2 2022-05-09 00:45:14 +02:00
Robert Schütz
bffd397ed9 imagemagick: 7.1.0-32 -> 7.1.0-33
(cherry picked from commit 2f677eae73)
2022-05-08 14:36:43 -07:00
Mario Rodas
3c5ae9be1f Merge pull request #172035 from lourkeur/update/brave
[21.11] brave: 1.38.109 -> 1.38.111
2022-05-08 09:42:57 -05:00
Martin Weinelt
f95f36c23d Merge pull request #172051 from NixOS/backport-171804-to-release-21.11
[Backport release-21.11] tor-browser-bundle-bin: 11.0.10 -> 11.0.11
2022-05-08 12:23:43 +02:00
Nicolas Benes
1c9c7cf8e8 tor-browser-bundle-bin: 11.0.10 -> 11.0.11
(cherry picked from commit 607be2704a)
2022-05-08 10:00:44 +00:00
misuzu
7c3396e114 alfis: 0.6.11 -> 0.7.0
(cherry picked from commit 1e1c29aa78)
2022-05-08 07:30:03 +00:00
R. Ryantm
f0c30e8f97 brave: 1.38.109 -> 1.38.111
(cherry picked from commit e3f9f3a1b0)
2022-05-08 09:26:41 +02:00
Artturi
a7cc19161b Merge pull request #167860 from NixOS/backport-167696-to-release-21.11
[Backport release-21.11] spidermonkey_91: 91.7.0 -> 91.8.0
2022-05-08 06:44:23 +03:00
Artturi
8e5507e6a7 Merge pull request #168610 from NixOS/backport-163722-to-release-21.11
[Backport release-21.11] alfis: 0.6.10 -> 0.6.11
2022-05-08 06:39:26 +03:00
Artturi
8fd3dc3bd3 Merge pull request #170920 from NixOS/backport-169333-to-release-21.11
[Backport release-21.11] signal-desktop: 5.38.0 -> 5.39.0
2022-05-08 06:38:09 +03:00
github-actions[bot]
1e1bf79666 Merge staging-next-21.11 into staging-21.11 2022-05-08 00:15:31 +00:00
github-actions[bot]
0bdd9757c3 Merge release-21.11 into staging-next-21.11 2022-05-08 00:14:49 +00:00
Mario Rodas
ac4d124eee Merge pull request #171567 from NixOS/backport-171495-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 101.0.4951.41 -> 101.0.4951.54
2022-05-07 13:39:45 -05:00
hiljusti
2a89839d48 sigi: 3.2.1 -> 3.3.0
(cherry picked from commit b006d76fa527379bc7f64dbe4e22c689832cc592)
2022-05-07 12:20:20 +00:00
github-actions[bot]
09e5d98703 Merge staging-next-21.11 into staging-21.11 2022-05-07 00:14:14 +00:00
github-actions[bot]
2c6d5dbe0d Merge release-21.11 into staging-next-21.11 2022-05-07 00:13:36 +00:00
Michael Weiss
ad66740447 Merge pull request #171556 from ggreif/llvm_14-21.11
[21.11] llvmPackages_14: 14.0.0rc1 -> 14.0.1
2022-05-06 21:28:33 +02:00
Michael Weiss
042c0c67f8 chromium: 101.0.4951.41 -> 101.0.4951.54
https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop.html
(cherry picked from commit 1c9f439ba2)
2022-05-06 19:22:18 +00:00
Maximilian Bosch
5656d7f92a Merge pull request #171813 from NixOS/backport-171783-to-release-21.11
[Backport release-21.11] Linux kernels 2022-05-06
2022-05-06 16:48:40 +02:00
Maximilian Bosch
b90b9b0c3b linux/hardened/patches/5.4: 5.4.190-hardened1 -> 5.4.191-hardened1
(cherry picked from commit e7675ff05d)
2022-05-06 12:10:40 +00:00
Maximilian Bosch
09893b7135 linux/hardened/patches/5.17: init at 5.17.5-hardened1
(cherry picked from commit b79d9a846b)
2022-05-06 12:10:40 +00:00
Maximilian Bosch
626a71619b linux/hardened/patches/5.15: 5.15.35-hardened1 -> 5.15.36-hardened1
(cherry picked from commit ed9d1bfe64)
2022-05-06 12:10:40 +00:00
Maximilian Bosch
f09b79d99e linux/hardened/patches/5.10: 5.10.112-hardened1 -> 5.10.113-hardened1
(cherry picked from commit bb404a9c09)
2022-05-06 12:10:40 +00:00
Maximilian Bosch
3467d5a58d linux/hardened/patches/4.19: 4.19.239-hardened1 -> 4.19.240-hardened1
(cherry picked from commit 4d43ae779d)
2022-05-06 12:10:40 +00:00
Maximilian Bosch
5f15994d9e linux/hardened/patches/4.14: 4.14.276-hardened1 -> 4.14.277-hardened1
(cherry picked from commit cb10c6f5cf)
2022-05-06 12:10:40 +00:00
Maximilian Bosch
79af0c0eef linux: 5.15.36 -> 5.15.37
(cherry picked from commit f93833182b)
2022-05-06 12:10:40 +00:00
Maximilian Bosch
9aad7f496e linux: 4.19.240 -> 4.19.241
(cherry picked from commit 4ac44ce721)
2022-05-06 12:10:40 +00:00
Martin Weinelt
8ec49a8e2c Merge pull request #171684 from NixOS/backport-171677-to-release-21.11 2022-05-06 13:20:21 +02:00
Vladimír Čunát
10c0fa1c0f Merge branch 'staging-21.11' into staging-next-21.11 2022-05-06 11:36:24 +02:00
Vladimír Čunát
f5694753ac Merge #171516: libxml2: add CVE patches (into staging-21.11) 2022-05-06 08:43:23 +02:00
github-actions[bot]
7bb83c9d8b Merge staging-next-21.11 into staging-21.11 2022-05-06 00:15:07 +00:00
github-actions[bot]
34936a2882 Merge release-21.11 into staging-next-21.11 2022-05-06 00:14:30 +00:00
Yaya
20e362cadd [Backport release-21.11] gitlab: 14.9.3 -> 14.9.4 (#171364) 2022-05-05 22:24:52 +02:00
Maximilian Bosch
a38cde9e46 Merge pull request #171696 from NixOS/backport-170994-to-release-21.11
[Backport release-21.11] wiki-js: 2.5.277 -> 2.5.279
2022-05-05 21:52:03 +02:00
Maximilian Bosch
c7932e4165 wiki-js: 2.5.277 -> 2.5.279
ChangeLog: https://github.com/requarks/wiki/releases/tag/v2.5.278
ChangeLog: https://github.com/requarks/wiki/releases/tag/v2.5.279
(cherry picked from commit e6acae6768)
2022-05-05 18:58:39 +00:00
Artturi
e04461d88e Merge pull request #170212 from hiljusti/release-21.11
Backporting #166389

This includes changes from 3.1.0 and 3.1.1.

This is fully backwards-compatible. There is one new subcommand (list-stacks) added to the CLI, all other changes are to internals, testing, and documentation.

The hiljusti/sigi#19

is complete, so testing now happens with no skips at all.

hiljusti/sigi@v3.0.3...v3.1.1
2022-05-05 20:04:06 +03:00
Martin Weinelt
a2465619ab ecdsautils: 0.4.0 -> 0.4.1
Fixes psychic papers vulnerability in signature verification.

https://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pw

Fixes: CVE-2022-24884
(cherry picked from commit 974603c931)
2022-05-05 16:48:34 +00:00
Vincent Laporte
d4191fe35c easycrypt-runtest: init at 2022.04
(cherry picked from commit 1b6d9a36ebf7fe3150628ddb660ba75e95311078)
2022-05-05 11:31:38 +02:00
Vincent Laporte
15b6c97704 easycrypt: init at 2022.04
(cherry picked from commit df6e6a8cc49980123f43ca4821befdc052fa0261)
2022-05-05 11:31:38 +02:00
Vladimír Čunát
3623de8998 Merge #171501: openssl_3_0: 3.0.2 -> 3.0.3 (into release-21.11) 2022-05-05 07:48:59 +02:00
Martin Weinelt
44df741c1d openssl_1_1: 1.1.1n -> 1.1.1o
Fixes command injection in the c_rehash script, which at the same time
is also considered obsolete and should be replaced by openssl rehash.

https://mta.openssl.org/pipermail/openssl-announce/2022-May/000224.html

Fixes: CVE-2022-1292
(cherry picked from commit a7be3b2607 from PR #171413)
2022-05-05 07:44:36 +02:00
Anderson Torres
1cad1a7622 Merge pull request #171124 from NixOS/backport-171058-to-release-21.11
[Backport release-21.11] pkgsStatic.slang: fix build
2022-05-04 22:43:19 -03:00
github-actions[bot]
b7a23b614c Merge release-21.11 into staging-next-21.11 2022-05-05 00:14:15 +00:00
Michael Weiss
745f884ea0 llvmPackages_14: 14.0.0 -> 14.0.1
(cherry picked from commit 84dbfa8f97)
2022-05-05 01:29:21 +02:00
Will Dietz
ffe301bcc4 llvmPackages_14.clang: include clang-tools-extra in src for use
Fixes #166833.

The build creates a symlink for this assuming it's present,
so be sure it's there when filtering the source for clang.

Alternatively we could use LLVM_EXTERNAL_CLANG_TOOLS_EXTRA_SOURCE_DIR.

(cherry picked from commit 075c5eb8d3)
2022-05-05 01:29:21 +02:00
Will Dietz
b4fa3f98f1 openmp: disable tests due to failures
(cherry picked from commit 2efcc3e297)
2022-05-05 01:29:20 +02:00
Will Dietz
788f98e463 openmp: drop fix-find-tool patch, set *_TOOL vars directly
(cherry picked from commit 4f3116f754)
2022-05-05 01:29:20 +02:00
Will Dietz
7b7d3aae83 openmp: tests, few failures
(cherry picked from commit 7151381aab)
2022-05-05 01:29:20 +02:00
Will Dietz
a670ba0fdf openmp: no longer broken
(cherry picked from commit 5e04d64aed)
2022-05-05 01:29:20 +02:00
Will Dietz
533112a620 openmp: new fix-find-tools patch
(cherry picked from commit 790c4f13dd)
2022-05-05 01:29:20 +02:00
Will Dietz
b1308fe86e llvmPackages_14.openmp: fix install dirs patch
(cherry picked from commit 641c2d3b7b)
2022-05-05 01:29:20 +02:00
Michael Weiss
6dcd36ccaf llvmPackages_14: 14.0.0-rc4 -> 14.0.0
(cherry picked from commit c9cfbe0899)
2022-05-05 01:29:20 +02:00
Michael Weiss
c0c4706f8a llvmPackages_14: 14.0.0-rc2 -> 14.0.0-rc4
(cherry picked from commit f0c2e46468)
2022-05-05 01:29:20 +02:00
Michael Weiss
c0f1cd5523 llvmPackages: Fix the update script
(cherry picked from commit 90d9b7c8dc)
2022-05-05 01:29:20 +02:00
Michael Weiss
2bd5978268 llvmPackages_14: 14.0.0-rc1 -> 14.0.0-rc2
(cherry picked from commit dd8169da3e)
2022-05-05 01:29:19 +02:00
Martin Weinelt
d6c49a3ff3 Merge pull request #171423 from mweinelt/21.11/firefox 2022-05-05 01:24:24 +02:00
Martin Weinelt
24bea0f3ba Merge pull request #171576 from adisbladis/hatchling-backport
[Backport release-21.11] python3.pkgs.hatchling: init
2022-05-04 23:58:48 +02:00
Ofek Lev
9a791742e6 maintainers: add ofek
(cherry picked from commit 7e49720ea1)
2022-05-05 09:15:21 +12:00
adisbladis
836da54b4c python3.pkgs.hatchling: Relax version constraints
So we don't have to backport updates to "scary" packages like tomli and packaging.
2022-05-05 08:37:40 +12:00
R. Ryantm
a385b4b4f9 python310Packages.editables: 0.2 -> 0.3
(cherry picked from commit adc727d6f8)
2022-05-05 08:31:30 +12:00
R. Ryantm
30d64714e0 python310Packages.hatchling: 0.22.0 -> 0.24.0
(cherry picked from commit 235eee5537)
2022-05-05 08:22:39 +12:00
R. Ryantm
578c5fd425 python310Packages.hatchling: 0.20.1 -> 0.22.0
(cherry picked from commit f7eb323b86)
2022-05-05 08:22:35 +12:00
Martin Weinelt
41abddc092 python3Packages.hatchling: 0.20.0 -> 0.20.1
Switches to the PyPi source per the upstream maintainers request in
https://github.com/NixOS/nixpkgs/pull/163088#issuecomment-1060748447

(cherry picked from commit 455f910e03)
2022-05-05 08:22:32 +12:00
Martin Weinelt
8f6d13d081 python3Packages.hatchling: 0.18.0 -> 0.20.0
(cherry picked from commit 16c45bb173)
2022-05-05 08:22:28 +12:00
Martin Weinelt
5c9c865e83 python3Packages.hatchling: init at 0.18.0
(cherry picked from commit ba276cf1e6)
2022-05-05 08:22:24 +12:00
Michael Adler
22ae83d663 ungoogled-chromium: 101.0.4951.41 -> 101.0.4951.54
(cherry picked from commit 29037ae616)
2022-05-04 19:02:20 +00:00
piegames
a9aa0fe64c Merge pull request #171510: [21.11] matrix-appservice-irc: update matrix-org-irc to 1.2.1 2022-05-04 18:47:50 +02:00
Vladimír Čunát
dff5496b12 Merge #171106: staging-next-21.11: iteration 12 - 2022-05-01 2022-05-04 13:05:02 +02:00
techknowlogick
43dad6aa5c mastodon: 3.5.1 -> 3.5.2
(cherry picked from commit 29a1e7c99c672e0422596e84cf385a2231362631)
2022-05-04 12:52:07 +02:00
Niklas Hambüchen
61220008cb [21.11] libxml2: Backport CVE fixes from v2.9.13 and v2.9.14
* https://nvd.nist.gov/vuln/detail/CVE-2022-29824
* https://nvd.nist.gov/vuln/detail/CVE-2022-23308

See also:

* https://github.com/NixOS/nixpkgs/pull/161071#issuecomment-1047881082
* https://github.com/NixOS/nixpkgs/pull/171461#issuecomment-1116928872
2022-05-04 10:25:17 +00:00
Martin Weinelt
49aad65245 Merge pull request #171454 from helsinki-systems/bkp/2111/cacert 2022-05-04 11:59:21 +02:00
Martin Weinelt
8882a088eb firefox-esr: 91.8.0esr -> 91.9.0esr
https://www.mozilla.org/en-US/firefox/91.9.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-17/

Fixes: CVE-2022-29914, CVE-2022-29909, CVE-2022-29916, CVE-2022-29911,
       CVE-2022-29912, CVE-2022-29917
(cherry picked from commit f6fd7e36d3)
2022-05-04 11:54:37 +02:00
Martin Weinelt
3d12893b81 firefox-bin: 99.0.1 -> 100.0
https://www.mozilla.org/en-US/firefox/100.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-16/

Fixes: CVE-2022-29914, CVE-2022-29909, CVE-2022-29911, CVE-2022-29912,
       CVE-2022-29910, CVE-2022-29915, CVE-2022-29917, CVE-2022-29918
(cherry picked from commit a1f9d3a52e)
2022-05-04 11:54:37 +02:00
Martin Weinelt
8a90a603c8 firefox: 99.0.1 -> 100.0
https://www.mozilla.org/en-US/firefox/100.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-16/

Fixes: CVE-2022-29914, CVE-2022-29909, CVE-2022-29911, CVE-2022-29912,
       CVE-2022-29910, CVE-2022-29915, CVE-2022-29917, CVE-2022-29918
(cherry picked from commit 3f2a09af84)
2022-05-04 11:54:36 +02:00
Martin Weinelt
662aa1be3e firefox: use nss_latest for firefox >=92 2022-05-04 11:54:36 +02:00
Martin Weinelt
b263d400e8 nss_latest: init at 3.78 2022-05-04 11:49:18 +02:00
Martin Weinelt
cffe01aab5 nixos/tests/matrix-appservice-irc: disable registration verification
The test would previously error out like this:

> synapse_homeserver[1155]: synapse.config._base.ConfigError: You have
> enabled open registration without any verification. This is a known
> vector for spam and abuse. If you would like to allow public
> registration, please consider adding email, captcha, or token-based
> verification. Otherwise this check can be removed by setting the
> `enable_registration_without_verification` config option to `true`.

(cherry picked from commit 1d2a0b801a)
2022-05-04 11:03:10 +02:00
Martin Weinelt
65e9232e88 matrix-appservice-irc: update matrix-org-irc to 1.2.1
https://github.com/matrix-org/node-irc/blob/master/CHANGELOG.md#121-2022-05-04
2022-05-04 10:44:49 +02:00
Vladimír Čunát
4a75a726e3 Merge #171102: thunderbird*: 91.8.0 -> 91.8.1 (into release-21.11) 2022-05-04 09:57:21 +02:00
Martin Weinelt
3fb6b02346 openssl_3_0: 3.0.2 -> 3.0.3
- The c_rehash script allows command injection (CVE-2022-1292)
- OCSP_basic_verify may incorrectly verify the response signing
  certificate (CVE-2022-1343)
- Incorrect MAC key used in the RC4-MD5 ciphersuite (CVE-2022-1434)
- Resource leakage when decoding certificates and keys (CVE-2022-1473)

https://mta.openssl.org/pipermail/openssl-announce/2022-May/000224.html

Fixes: CVE-2022-1292, CVE-2022-1343, CVE-2022-1434, CVE-2022-1473
(cherry picked from commit c62eceb91e)
2022-05-04 07:24:46 +00:00
Artturi
e979daf5d6 Merge pull request #170555 from NixOS/backport-168865-to-release-21.11
[Backport release-21.11] buildRustCrate: don't try to set CARGO_FEATURE_ variables for `dep:` features
2022-05-04 05:36:45 +03:00
github-actions[bot]
ca9919e429 Merge staging-next-21.11 into staging-21.11 2022-05-04 00:14:58 +00:00
github-actions[bot]
99e0775425 Merge release-21.11 into staging-next-21.11 2022-05-04 00:14:02 +00:00
ajs124
c11a1ea2be cacert: 3.74 -> 3.77
corresponds to 8e77380250 on master
but without the changes to update.sh
2022-05-03 22:47:13 +01:00
davidak
fd43ce017d Merge pull request #171374 from NixOS/backport-171347-to-release-21.11
[Backport release-21.11] bcachefs: 2022-04 -> 2022-05
2022-05-03 11:57:35 +02:00
Madoura
9a4093e762 bcachefs-tools: unstable-2022-04-08 -> unstable-2022-05-02
(cherry picked from commit 58d1bd206b)
2022-05-03 09:10:24 +00:00
Madoura
da75f08839 linux_testing_bcachefs: unstable-2022-04-08 -> unstable-2022-04-25
(cherry picked from commit 064da2621a)
2022-05-03 09:10:24 +00:00
github-actions[bot]
d23c7df466 Merge staging-next-21.11 into staging-21.11 2022-05-03 00:14:59 +00:00
github-actions[bot]
9eb7c3dcf1 Merge release-21.11 into staging-next-21.11 2022-05-03 00:14:25 +00:00
Robert Scott
9e49886b3d haproxy: 2.3.14 -> 2.3.18 2022-05-02 10:58:37 -07:00
Robert Scott
aabc99f35d clickhouse: 21.8.8.29 -> 21.8.15.7 2022-05-02 18:06:35 +01:00
Robert Hensing
66a2919980 Merge pull request #171012 from NixOS/backport-167665-to-release-21.11
[Backport release-21.11] `pkgs._type = "pkgs"`
2022-05-02 08:05:19 +02:00
github-actions[bot]
7ef25f8dec Merge staging-next-21.11 into staging-21.11 2022-05-02 00:14:40 +00:00
github-actions[bot]
da26ac8801 Merge release-21.11 into staging-next-21.11 2022-05-02 00:14:07 +00:00
Mario Rodas
2c701a50d7 Merge pull request #171158 from risicle/ris-redis-6.2.7-r21.11
[21.11] redis: 6.2.6 -> 6.2.7
2022-05-01 17:58:31 -05:00
Robert Scott
ed4cc5a869 Merge pull request #171150 from pborzenkov/21.11-calibre-web-0.6.18
[21.11] calibre-web: 0.6.17 -> 0.6.18
2022-05-01 22:27:52 +01:00
Guillaume Girol
ff1867232d Merge pull request #170999 from lostnet/backport-170393-to-release-21.11
[Backport release-21.11] couchdb3: 3.2.1 -> 3.2.2
2022-05-01 19:31:23 +00:00
Kerstin Humm
9f0d1b354d imagemagick: 7.1.0-31 -> 7.1.0-32
(cherry picked from commit ab3a25bc8c)
2022-05-01 19:58:03 +02:00
Robert Scott
c0a71a43d5 redis: 6.2.6 -> 6.2.7 2022-05-01 18:05:28 +01:00
Pavel Borzenkov
ca3ee276f2 calibre-web: 0.6.17 -> 0.6.18
Closes #160637

(cherry picked from commit 6f012370db)
2022-05-01 18:44:09 +02:00
Pavel Borzenkov
febbf25091 python3Packages.advocate: init at 1.0.0
(cherry picked from commit 00d630efa1)
2022-05-01 18:43:59 +02:00
Pavel Borzenkov
52a73f2897 calibre-web: relax Flask, Flask-Login and lxml requirements
(cherry picked from commit 7db7864871)
2022-05-01 18:43:49 +02:00
Alyssa Ross
322b33c621 pkgsStatic.slang: fix build
(cherry picked from commit 77249527448b889720680daa54e53481c1e30706)
2022-05-01 12:15:08 +00:00
Vladimír Čunát
a3f93b81b9 Merge branch 'staging-21.11' into staging-next-21.11 2022-05-01 10:30:40 +02:00
Vladimír Čunát
b74de186b7 Merge #171010: libopenmpt: 0.5.17 -> 0.5.18 (into staging-21.11) 2022-05-01 10:27:33 +02:00
Vladimír Čunát
052d0493a5 Merge #170537: ghostscript: CVE patches (into staging-21.11) 2022-05-01 10:25:03 +02:00
taku0
09648d513d thunderbird: 91.8.0 -> 91.8.1
(cherry picked from commit a4e41af62d)
2022-05-01 07:55:03 +00:00
taku0
809c29aafb thunderbird-bin: 91.8.0 -> 91.8.1
(cherry picked from commit c203747ba3)
2022-05-01 07:55:03 +00:00
Wael Nasreddine
e41bd3eead colima: backport from unstable (#156768)
* lima: 0.7.3 -> 0.7.4

https://github.com/lima-vm/lima/releases/tag/v0.7.4
(cherry picked from commit 70307e1674)

* lima: 0.7.4 -> 0.8.0

https://github.com/lima-vm/lima/releases/tag/v0.8.0
(cherry picked from commit 435043c924)

* colima: init at 0.2.2

`colima` is a very easy usable replacement for Docker Desktop on MacOS.

Signed-off-by: Andreas Schmid <service@aaschmid.de>
(cherry picked from commit c4dbe8fe65)

* colima: update vendorSha256

(cherry picked from commit 17b3ec07e0)

* colima: 0.2.2 -> 0.3.1

Signed-off-by: Andreas Schmid <service@aaschmid.de>
(cherry picked from commit c1d77e4dd1)

* colima: 0.3.1 -> 0.3.2

Signed-off-by: Andreas Schmid <service@aaschmid.de>
(cherry picked from commit d8062c345d)

Co-authored-by: zowoq <59103226+zowoq@users.noreply.github.com>
Co-authored-by: Andreas Schmid <service@aaschmid.de>
2022-05-01 04:29:20 +03:00
github-actions[bot]
65a4db7b6c Merge staging-next-21.11 into staging-21.11 2022-05-01 00:18:50 +00:00
github-actions[bot]
92196c81c2 Merge release-21.11 into staging-next-21.11 2022-05-01 00:18:15 +00:00
Robert Scott
fc16ff333b Merge pull request #171049 from risicle/ris-qemu-CVE-2021-4206-r21.11
[21.11] qemu: add patches for CVE-2021-4206 & CVE-2021-4207
2022-04-30 21:29:54 +01:00
Robert Scott
edcc1e3451 blender: 2.93.5 -> 2.93.8 2022-04-30 19:18:17 +01:00
Alyssa Ross
8a3a4de8d7 zsh: 5.8 -> 5.8.1
Fixes: CVE-2021-45444
(cherry picked from commit b0a871a3ec)
2022-04-30 19:53:26 +02:00
Robert Scott
3f9782abb4 qemu: add patches for CVE-2021-4206 & CVE-2021-4207 2022-04-30 13:03:45 +01:00
Martin Weinelt
a02a98daef Merge pull request #170659 from mweinelt/21.11/curl 2022-04-30 13:10:43 +02:00
Robert Hensing
aec730a0af pkgs: Add _type = "pkgs"
(cherry picked from commit ad1e2500ef)
2022-04-30 10:23:59 +00:00
OPNA2608
138f17072b libopenmpt: 0.5.17 -> 0.5.18 2022-04-30 11:54:45 +02:00
Maximilian Bosch
fd3e33d696 Merge pull request #170862 from NixOS/backport-170760-to-release-21.11
[Backport release-21.11] Linux kernels 2022-04-27
2022-04-30 11:27:15 +02:00
Maximilian Bosch
e435d0a541 Merge pull request #170998 from NixOS/backport-170701-to-release-21.11
[Backport release-21.11] element-{web,desktop}: 1.10.10 -> 1.10.11
2022-04-30 11:00:41 +02:00
Michael Weiss
11ffb19e30 Merge pull request #170806 from NixOS/backport-170798-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 100.0.4896.127 -> 101.0.4951.41
2022-04-30 10:59:18 +02:00
Sumner Evans
29daba88a7 element-{web,desktop}: 1.10.10 -> 1.10.11
(cherry picked from commit b57cd37794)
2022-04-30 08:30:29 +00:00
github-actions[bot]
cfa78c26af Merge staging-next-21.11 into staging-21.11 2022-04-30 00:15:58 +00:00
github-actions[bot]
3ae92ad78a Merge release-21.11 into staging-next-21.11 2022-04-30 00:15:27 +00:00
Martin Weinelt
14269ee3f8 Merge pull request #170949 from NixOS/backport-170778-to-release-21.11 2022-04-30 01:20:46 +02:00
Martin Weinelt
e7702d7c38 cifs-utils: fix information disclosure in logger
8acc963a2e

Fixes: CVE-2022-29869
(cherry picked from commit e121ca2c8f)
2022-04-29 22:41:16 +00:00
Martin Weinelt
637c6a4162 cifs-utils: patch buffer-overflow in ip param handling
https://www.openwall.com/lists/oss-security/2022/04/27/5
https://bugzilla.suse.com/show_bug.cgi?id=1197216
https://github.com/piastry/cifs-utils/pull/7

Fixes: CVE-2022-27239
(cherry picked from commit cb3fa089ea)
2022-04-29 22:41:16 +00:00
davidak
107e032e08 geekbench: init at 4.4.4
(cherry picked from commit 929a48cd8c0aa0747aba899492579c48a6be6dd6)
2022-04-29 14:14:01 -07:00
Will
c800d222e8 couchdb3: 3.2.1 -> 3.2.2
(cherry picked from commit 14fca0ca6f)
2022-04-29 22:19:42 +02:00
Vladimír Čunát
36c3b34c3b knot: 3.1.7 -> 3.1.8
https://gitlab.nic.cz/knot/knot-dns/-/tags/v3.1.8
(cherry picked from commit 871065de22)
2022-04-29 12:38:50 -07:00
Eduardo Quiros
71c40eb6e2 signal-desktop: 5.38.0 -> 5.39.0
(cherry picked from commit 4230a22453)
2022-04-29 15:41:31 +00:00
maxine [they]
087fb90496 Merge pull request #170900 from blitz/docker-glibc-issue
[21.11] docker: 2.10.9 -> 20.10.14 (for glibc 2.34 compatiblity!)
2022-04-29 17:32:53 +02:00
Alyssa Ross
c5a5847f14 squashfs-tools-ng: 1.1.3 -> 1.1.4
(cherry picked from commit 6c031ea098ccbc17146c9ffd3fe0da3b0a07aacb)
2022-04-29 09:11:56 -05:00
teutat3s
e6aca27c64 signal-desktop: 5.37.0 -> 5.38.0
(cherry picked from commit 038cb5a97d)
2022-04-29 09:10:26 -05:00
Jan Tojnar
5203152ac8 webkitgtk: 2.36.0 → 2.36.1
https://webkitgtk.org/2022/04/21/webkitgtk2.36.1-released.html
(cherry picked from commit 0df77cad7b9a162d803775c95aa1e78aaa4566e9)
2022-04-29 15:47:46 +02:00
Maxine Aubrey
4f66697ff4 docker: 20.10.13 -> 20.10.14
https://docs.docker.com/engine/release-notes/#201014
(cherry picked from commit ae79018c44)
2022-04-29 13:57:03 +02:00
Tomek Mańko
0d184240b1 docker: add a patch to fix Docker buildkit when using ZFS graph driver.
The patch incorporates changes merged into the upstream in this PR:
https://github.com/moby/moby/pull/43136

(cherry picked from commit 3d25f046b3)
2022-04-29 13:49:17 +02:00
Maxine Aubrey
55ed08d402 docker: 20.10.12 -> 20.10.13
https://docs.docker.com/engine/release-notes/#201013
(cherry picked from commit b73b403865)
2022-04-29 13:45:53 +02:00
Danielle Lancashire
136b8d16be docker_20_10: 20.10.9 -> 20.10.12
(cherry picked from commit 18d0fe9b69)
2022-04-29 13:39:31 +02:00
Maximilian Bosch
434e6f4a00 linux: 5.4.190 -> 5.4.191
(cherry picked from commit 156229222e)
2022-04-29 07:12:39 +00:00
Maximilian Bosch
5159008a22 linux: 5.17.4 -> 5.17.5
(cherry picked from commit 0b6256c1b8)
2022-04-29 07:12:39 +00:00
Maximilian Bosch
ac5a478a62 linux: 5.15.35 -> 5.15.36
(cherry picked from commit fd748205fa)
2022-04-29 07:12:39 +00:00
Maximilian Bosch
84b239bfed linux: 5.10.112 -> 5.10.113
(cherry picked from commit f1ad14384b)
2022-04-29 07:12:39 +00:00
Maximilian Bosch
18c7742dce linux: 4.9.311 -> 4.9.312
(cherry picked from commit cd8c3a2b1e)
2022-04-29 07:12:39 +00:00
Maximilian Bosch
6506a8acc7 linux: 4.19.239 -> 4.19.240
(cherry picked from commit f708ee02bd)
2022-04-29 07:12:39 +00:00
Maximilian Bosch
5eecadd4bf linux: 4.14.276 -> 4.14.277
(cherry picked from commit 2cd2c891f9)
2022-04-29 07:12:39 +00:00
Maximilian Bosch
837913deb2 Merge pull request #170759 from NixOS/backport-169937-to-release-21.11
[Backport release-21.11] Linux kernels 2022-04-20
2022-04-29 09:06:53 +02:00
Michael Weiss
ee416c7d38 ungoogled-chromium: 100.0.4896.127 -> 101.0.4951.41
(cherry picked from commit 3084d18e44)
2022-04-28 19:19:56 +00:00
Maximilian Bosch
520fb5e0de linux-testing-bcachefs: mark as broken for now
(cherry picked from commit 654471e600)
2022-04-28 10:10:25 +00:00
Maximilian Bosch
7a26af76e8 linux/hardened/5.4: fix build
(cherry picked from commit c381ab775a)
2022-04-28 10:10:25 +00:00
Maximilian Bosch
cb2042bf99 linux/hardened/4.19: fix build
(cherry picked from commit 90c22150c0)
2022-04-28 10:10:25 +00:00
Maximilian Bosch
f425760bfe linux/hardened/4.14: fix build
(cherry picked from commit ddf613299d)
2022-04-28 10:10:25 +00:00
Maximilian Bosch
495c783f14 linux_5_16: drop
(cherry picked from commit 5580ef0c63)
2022-04-28 10:10:25 +00:00
Maximilian Bosch
204b2097e0 linux/hardened/patches/5.4: 5.4.182-hardened1 -> 5.4.190-hardened1
(cherry picked from commit bd45f28ba1)
2022-04-28 10:10:25 +00:00
Maximilian Bosch
60172c600c linux/hardened/patches/5.15: 5.15.26-hardened1 -> 5.15.35-hardened1
(cherry picked from commit 875b52ae4e)
2022-04-28 10:10:25 +00:00
Maximilian Bosch
2a390cbabc linux/hardened/patches/5.10: 5.10.103-hardened1 -> 5.10.112-hardened1
(cherry picked from commit 63c0e3bbf7)
2022-04-28 10:10:25 +00:00
Maximilian Bosch
0c4f3074e3 linux/hardened/patches/4.19: 4.19.232-hardened1 -> 4.19.239-hardened1
(cherry picked from commit 206e53cc46)
2022-04-28 10:10:25 +00:00
Maximilian Bosch
4b9e2ab0ba linux/hardened/patches/4.14: 4.14.269-hardened1 -> 4.14.276-hardened1
(cherry picked from commit c1d59aabb1)
2022-04-28 10:10:25 +00:00
Maximilian Bosch
8656f1d981 linux-hardened: quickfix to make sure the updater is working again
(cherry picked from commit d6b6293c90)
2022-04-28 10:10:25 +00:00
Maximilian Bosch
3ba95f2544 linux_latest-libre: 18664 -> 18688
(cherry picked from commit 9ab0fece50)
2022-04-28 10:10:25 +00:00
Maximilian Bosch
57ab655d40 linux: 5.4.188 -> 5.4.190
(cherry picked from commit b0d8ca58e5)
2022-04-28 10:10:25 +00:00
Maximilian Bosch
8388df2fea linux: 5.17.3 -> 5.17.4
(cherry picked from commit 8a53f9a72a)
2022-04-28 10:10:25 +00:00
Maximilian Bosch
f57a93b09c linux: 5.15.34 -> 5.15.35
(cherry picked from commit 55f39cb81e)
2022-04-28 10:10:25 +00:00
Maximilian Bosch
a35f6f997c linux: 5.10.111 -> 5.10.112
(cherry picked from commit b7353ebce8)
2022-04-28 10:10:24 +00:00
Maximilian Bosch
0b79c8b788 linux: 4.9.310 -> 4.9.311
(cherry picked from commit 1179f98255)
2022-04-28 10:10:24 +00:00
Maximilian Bosch
34f1553525 linux: 4.19.237 -> 4.19.239
(cherry picked from commit e85cc3d40f)
2022-04-28 10:10:24 +00:00
Maximilian Bosch
8daa0da2b6 linux: 4.14.275 -> 4.14.276
(cherry picked from commit 46683073ed)
2022-04-28 10:10:24 +00:00
github-actions[bot]
e28bca2e6e Merge staging-next-21.11 into staging-21.11 2022-04-28 00:31:49 +00:00
github-actions[bot]
bc9f8123b5 Merge release-21.11 into staging-next-21.11 2022-04-28 00:26:44 +00:00
squalus
feea25c586 nixos/prometheus-nginx-exporter: fix argument syntax
Arguments were being ignored because the program expects an equals sign
to separate the argument name from the value.

Documented in https://github.com/nginxinc/nginx-prometheus-exporter/issues/153

Fixes #107541

(cherry picked from commit c3ab9e6d40)
2022-04-27 23:11:46 +02:00
Robert Scott
cae749cc46 Merge pull request #170118 from risicle/ris-qemu-CVEs-2022-04-r21.11
[21.11] qemu: add patches for CVE-2022-26353 & CVE-2022-26354
2022-04-27 21:14:49 +01:00
Martin Weinelt
0de4d52dfb curl: backport security patches from 7.83.0
https://curl.se/docs/CVE-2022-22576.html
https://curl.se/docs/CVE-2022-27774.html
https://curl.se/docs/CVE-2022-27775.html
https://curl.se/docs/CVE-2022-27776.html

Fixes: CVE-2022-22576, CVE-2022-27774, CVE-2022-27775, CVE-27776
2022-04-27 20:43:16 +02:00
André Vitor de Lima Matos
7a6a47762d mimetic: fix compilation failure with new toolchain
(backport of commit fa5f78712d)
2022-04-27 10:40:30 -05:00
Mario Rodas
269d35f704 Merge pull request #170586 from NixOS/backport-170516-to-release-21.11
[Backport release-21.11] chromium: 100.0.4896.127 -> 101.0.4951.41
2022-04-27 06:35:50 -05:00
Michael Weiss
f09c1349bf chromium: 100.0.4896.127 -> 101.0.4951.41
https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html

This update includes 30 security fixes.

CVEs:
CVE-2022-1477 CVE-2022-1478 CVE-2022-1479 CVE-2022-1480 CVE-2022-1481
CVE-2022-1482 CVE-2022-1483 CVE-2022-1484 CVE-2022-1485 CVE-2022-1486
CVE-2022-1487 CVE-2022-1488 CVE-2022-1489 CVE-2022-1490 CVE-2022-1491
CVE-2022-1492 CVE-2022-1493 CVE-2022-1494 CVE-2022-1495 CVE-2022-1496
CVE-2022-1497 CVE-2022-1498 CVE-2022-1499 CVE-2022-1500 CVE-2022-1501

(cherry picked from commit 879830d817)
2022-04-27 08:59:26 +00:00
Michael Weiss
ca071d1224 Merge pull request #170519 from primeos/chromium-backport
[21.11] Prepare for backporting Chromium M101
2022-04-27 10:55:46 +02:00
Vladimír Čunát
9e2f900c90 Merge #168975: thunderbird-bin: 91.7.0 -> 91.8.0
...into release-21.11
2022-04-27 10:38:34 +02:00
Faye Duxovni
a94a643de9 buildRustCrate: don't try to set CARGO_FEATURE_ variables for dep: features
These features are internal-only, have special characters that bash
doesn't support in variable names, and aren't normally given
environment variables by cargo as far as I can tell.

(cherry picked from commit ede639a8d63f2c6da0944cab441955ca16e9cce5)
2022-04-27 02:40:40 +00:00
github-actions[bot]
12cc215bad Merge staging-next-21.11 into staging-21.11 2022-04-27 00:16:49 +00:00
github-actions[bot]
b7a0896728 Merge release-21.11 into staging-next-21.11 2022-04-27 00:16:13 +00:00
Congee
61c46396dd tpm2-pkcs11: 1.7.0 -> 1.8.0
(cherry picked from commit d7e4753f87ceb329b86ee8da82a75ffa5b95a094)
2022-04-26 16:51:19 -07:00
Robert Scott
aade233647 ghostscript: add patches for CVE-2021-45944 & CVE-2021-45949 2022-04-26 23:58:25 +01:00
Michael Weiss
39aab3280e chromiumDev: 102.0.4997.0 -> 102.0.5005.12
(cherry picked from commit da09d908be)
2022-04-27 00:04:47 +02:00
Michael Weiss
d91222a9c3 chromiumBeta: 101.0.4951.34 -> 101.0.4951.41
(cherry picked from commit 2a60ab110d)
2022-04-27 00:04:47 +02:00
Louis Bettens
1bfaa31adf chromium: 100.0.4896.88 -> 100.0.4896.127
(cherry picked from commit a6a25ec43d)
2022-04-27 00:04:46 +02:00
Michael Weiss
84e28f3e90 chromium{Beta,Dev}: Fix a build error by disabling PGO
This fixes build errors like this:
error: Could not read profile ../../chrome/build/pgo_profiles/chrome-linux-4951-1649181099-528ef6669805f2d3db6f3ad7429cfa57a6078271.profdata: unsupported instrumentation profile format version

We already package the most recent stable LLVM version for Chromium but Google
relies on unreleased (Git) versions (thanks...). This isn't ideal but I
don't have the time to package yet another LLVM version so it'll have to
cut it for now.

See build/config/compiler/pgo/pgo.gni:
- 0 : Means that PGO is turned off.
- 1 : Used during the PGI (instrumentation) phase.
- 2 : Used during the PGO (optimization) phase.

With is_official_build the default is chrome_pgo_phase = 2.

(cherry picked from commit 15623bcb65)
2022-04-27 00:04:46 +02:00
Michael Weiss
253c5a06d4 chromiumDev: 102.0.4987.0 -> 102.0.4997.0
(cherry picked from commit 8255068a63)
2022-04-27 00:03:49 +02:00
Michael Weiss
dd0b011118 chromiumDev: 102.0.4972.0 -> 102.0.4987.0
(cherry picked from commit dbf02e3a52)
2022-04-27 00:03:49 +02:00
Michael Weiss
c178cbc0b0 chromium: get-commit-message.py: Support releases with 1 security fix
There was an out-of-band security release with only a single security fix:
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html

(cherry picked from commit 92559b7330)
2022-04-27 00:03:49 +02:00
Michael Weiss
1dd77bb3a7 chromiumBeta: 101.0.4951.15 -> 101.0.4951.26
(cherry picked from commit 073c33c3a6)
2022-04-27 00:03:48 +02:00
Michael Weiss
359d5e14e0 chromium: get-commit-message.py: Support releases with 0 security fixes
Wow, a Chrome release without any (known!) security fixes:
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_20.html

(cherry picked from commit 688d6d2435)
2022-04-27 00:03:48 +02:00
Jan Tojnar
54c5d88e4a chromium: remove unused GConf dependency
GConf has been deprecated for ages and support for it removed from Chromium a while ago:

- Removal of `use_gconf` gn build system flag:
  a28f4d062f

(cherry picked from commit e3e625ffe4)
2022-04-27 00:03:48 +02:00
Jan Tojnar
7b87f2121d chromium: remove deprecated libgnome-keyring dependency
libgnome-keyring has been deprecated for a long time.
It has been superseded by libsecret, which allows access to not only
GNOME Keyring secret manager but any other service implementing
the Secret Service D-Bus API.

In fact Chromium links against libsecret when use_glib is enabled:

https://source.chromium.org/chromium/chromium/src/+/main:components/os_crypt/BUILD.gn;l=142;drc=35be6215ec8f09e50176f36753c68f26c63d1885

And use_glib is on by default on Linux:

https://source.chromium.org/chromium/chromium/src/+/main:components/os_crypt/BUILD.gn;l=142;drc=35be6215ec8f09e50176f36753c68f26c63d1885

Unfortunately, Chromium is vendoring libsecret:

https://source.chromium.org/chromium/chromium/src/+/main:components/os_crypt/BUILD.gn;l=187;drc=35be6215ec8f09e50176f36753c68f26c63d1885

We need to disable the flag explicitly, since it is enabled by default:

https://source.chromium.org/chromium/chromium/src/+/main:components/os_crypt/features.gni;l=11;drc=35be6215ec8f09e50176f36753c68f26c63d1885
(cherry picked from commit e8c84f90ed)
2022-04-27 00:03:47 +02:00
Michael Adler
f66a7ab7b5 ungoogled-chromium: added myself as maintainer
(cherry picked from commit cd16da5867)
2022-04-27 00:03:47 +02:00
Michael Weiss
ff942c6e13 chromiumDev: 101.0.4951.15 -> 102.0.4972.0
(cherry picked from commit 2b7d401ee6)
2022-04-27 00:03:47 +02:00
Michael Weiss
5f4f88de2c chromiumBeta: 100.0.4896.60 -> 101.0.4951.15
(cherry picked from commit 773cfb0859)
2022-04-27 00:03:47 +02:00
Michael Weiss
7576dca774 chromiumDev: 101.0.4951.7 -> 101.0.4951.15
(cherry picked from commit 7cbe3d69a7)
2022-04-27 00:03:46 +02:00
Michael Weiss
16486f19ae chromiumBeta: 100.0.4896.56 -> 100.0.4896.60
(cherry picked from commit 4b9e65e066)
2022-04-27 00:03:46 +02:00
Silvan Mosberger
a3917caedf Merge pull request #170455 from NixOS/backport-169581-to-release-21.11
[Backport release-21.11] openjdk: 11.0.12+7 -> 11.0.15.+10, 17.0.1+12 -> 17.0.3.+7
2022-04-26 20:33:27 +02:00
Wanja Hentze
f9cdddc92a openjdk: 17.0.1+12 -> 17.0.3.+7
Fixes several security vulnerabilities, see https://openjdk.java.net/groups/vulnerability/advisories/2022-04-19

(cherry picked from commit aca95cc459)
2022-04-26 17:44:57 +00:00
Wanja Hentze
e9c27e475b openjdk: 11.0.12+7 -> 11.0.15.+10
Fixes several security vulnerabilities, see https://openjdk.java.net/groups/vulnerability/advisories/2022-04-19

(cherry picked from commit 33bf05f46a)
2022-04-26 17:44:56 +00:00
Robert Scott
348a900ed2 nomad_1_0: 1.0.13 -> 1.0.18
requiring a bump to go 1.16
2022-04-26 10:17:23 -07:00
X9VoiD
bd1e071b07 broadcom_sta: fix build on linux 5.17
Fix build issues when compiling against Linux 5.17

(cherry picked from commit 4e583a67876664df9ebb8b6b48708107bb6e5e71)
2022-04-26 08:07:12 -07:00
Adam Joseph
fa15ff601e evtest: update sha256 hash
Commit 6df37c9aab bumped the version of
evtest but failed to update the hash.  As a result, hosts which
already have evtest-1.33 source present will build the old version but
label it as evtest-1.34.  Hosts which lack the older source code will
fail their builds.  This commit corrects the issue.

We should think about a way to get Hydra to catch issues like this.
Maybe require that if two FODs have different hashes then they must
have different `${pname}-${version}`s?  Only for FODs, of course.

(cherry picked from commit 9a0fd1e35ea417427b70a6ebdeb2cd16da92fda4)
2022-04-26 12:54:52 +02:00
Bobby Rong
0ad9627750 Merge pull request #165864 from wh0/mime-types-url
[21.11] mime-types: unrot url
2022-04-26 18:10:19 +08:00
github-actions[bot]
2c2a526340 Merge staging-next-21.11 into staging-21.11 2022-04-26 00:15:24 +00:00
github-actions[bot]
feab0dca0d Merge release-21.11 into staging-next-21.11 2022-04-26 00:14:51 +00:00
Vladimír Čunát
3a9e0f239d Merge #170284: staging-next-21.11: iteration 11 2022-04-25 23:13:26 +02:00
Vladimír Čunát
b415dc7d7c Merge branch 'staging-21.11' into staging-next-21.11 2022-04-25 18:14:44 +02:00
Vladimír Čunát
1cc875aab6 Merge #170086: vim: 8.2.4186 -> 8.2.4816 (into staging-21.11) 2022-04-25 18:12:46 +02:00
maxine [they]
33812349fa Merge pull request #170275 from NixOS/backport-170152-to-release-21.11
[Backport release-21.11] nomad_1_1: 1.1.8 -> 1.1.12
2022-04-25 17:15:39 +02:00
Robert Scott
48e1e2ab65 nomad_1_1: 1.1.8 -> 1.1.12
(cherry picked from commit a01811ab3b)
2022-04-25 15:14:00 +00:00
hiljusti
b500d7fb36 sigi: 3.0.3 -> 3.2.1 2022-04-24 23:57:29 -07:00
github-actions[bot]
0b64905412 Merge staging-next-21.11 into staging-21.11 2022-04-25 00:14:00 +00:00
github-actions[bot]
26c8efe4ad Merge release-21.11 into staging-next-21.11 2022-04-25 00:13:26 +00:00
maxine [they]
c254b8c915 Merge pull request #167072 from pborzenkov/21.11-calibre-web-0.6.17 2022-04-24 22:06:54 +02:00
R. Ryantm
e90d4a2444 calibre-web: 0.6.16 -> 0.6.17 2022-04-24 21:45:33 +02:00
R. Ryantm
35fa15c275 calibre-web: 0.6.15 -> 0.6.16 2022-04-24 21:45:10 +02:00
R. Ryantm
0bdddc28db calibre-web: 0.6.14 -> 0.6.15 2022-04-24 21:45:10 +02:00
Fabian Affolter
199c7d2f65 calibre-web: relax lxml constraint 2022-04-24 21:44:18 +02:00
Pavel Borzenkov
6aaad73865 calibre-web: 0.6.13 -> 0.6.14 2022-04-24 21:44:05 +02:00
Robert Scott
0978170a3f qemu: add patches for CVE-2022-26353 & CVE-2022-26354 2022-04-24 19:01:06 +01:00
github-actions[bot]
bba2203c18 gitlab: 14.9.2 -> 14.9.3 (#170096)
(cherry picked from commit 5759f5a9a79095bee445af5ac23e69d3d0b46949)

Co-authored-by: Yaya <mak@nyantec.com>
2022-04-24 17:42:03 +02:00
Robert Schütz
778e2dc402 imagemagick: 7.1.0-30 -> 7.1.0-31
(cherry picked from commit 006e2faea5879acd796133bdb1dd245546b6efa1)
2022-04-24 14:47:16 +02:00
FliegendeWurst
64564e63c6 vim: 8.2.4609 -> 8.2.4816
(cherry picked from commit 0c2197472d)
2022-04-24 14:37:21 +02:00
R. Ryantm
5fb48032ea vim: 8.2.4350 -> 8.2.4609
(cherry picked from commit 71fba1fb0b)
2022-04-24 14:37:20 +02:00
R. Ryantm
04e5142071 vim: 8.2.4227 -> 8.2.4350
(cherry picked from commit a7cf36f841)
2022-04-24 14:37:19 +02:00
R. Ryantm
6d12f503f7 vim: 8.2.4186 -> 8.2.4227
(cherry picked from commit ed89447f2c)
2022-04-24 14:37:19 +02:00
Pascal Bach
7dc0826bf6 Merge pull request #170022 from helsinki-systems/fix/155336
[21.11] minio: 2021-10-27T16-29-42Z -> 2022-01-08T03-11-54Z
2022-04-24 13:38:53 +02:00
Pavol Rusnak
ada85b7a70 Merge pull request #170066 from NixOS/backport-169854-to-release-21.11
[Backport release-21.11] electron: fix rpath for executable chrome_crashpad_handler
2022-04-24 10:49:43 +02:00
Congee
ae76fc45d8 electron: fix rpath for executable chrome_crashpad_handler
chrome_crashpad_handler the crash reporter does not work if rpath is unpatched

(cherry picked from commit 97a94014f5)
2022-04-24 08:44:47 +00:00
github-actions[bot]
3139fc6e35 Merge staging-next-21.11 into staging-21.11 2022-04-24 00:15:07 +00:00
github-actions[bot]
6dbaeb8d67 Merge release-21.11 into staging-next-21.11 2022-04-24 00:14:33 +00:00
R. Ryantm
b8b1fe3791 minio: 2021-12-27T07-23-18Z -> 2022-01-08T03-11-54Z
(cherry picked from commit c45c58d7dc)
2022-04-23 22:47:20 +01:00
zowoq
021c998510 minio: update vendorSha256
(cherry picked from commit 435a8c34bd)
2022-04-23 22:47:17 +01:00
R. Ryantm
b5bddfef7d minio: 2021-12-10T23-03-39Z -> 2021-12-27T07-23-18Z
(cherry picked from commit f687526593)
2022-04-23 22:47:14 +01:00
R. Ryantm
a62a6dcfa9 minio: 2021-11-24T23-19-33Z -> 2021-12-10T23-03-39Z
(cherry picked from commit c63a60d8ca)
2022-04-23 22:47:10 +01:00
R. Ryantm
64fdc62be9 minio: 2021-10-27T16-29-42Z -> 2021-11-24T23-19-33Z
(cherry picked from commit f4f9fc8d96)
2022-04-23 22:47:07 +01:00
Átila Saraiva
9237b63d00 droidmote: init at 3.0.6
(cherry picked from commit ad605efb5f)
2022-04-23 15:39:45 +00:00
Benjamin Hipple
5fb3a17960 Merge pull request #169959 from NixOS/backport-168941-to-release-21.11
[Backport release-21.11] nginxStable: add patch for CVE-2021-3618
2022-04-23 11:33:50 -04:00
Benjamin Hipple
e3cc9ecbe8 Merge pull request #169957 from NixOS/backport-169947-to-release-21.11
[Backport release-21.11] ipmiview: 2.19.0 -> 2.20.0
2022-04-23 11:15:56 -04:00
Robert Scott
83715a8946 nginxStable: add patch for CVE-2021-3618
(cherry picked from commit 6951ba02f4)
2022-04-23 15:03:57 +00:00
Florian Brandes
940d8242cc ipmiview: 2.19.0 -> 2.20.0
Signed-off-by: Florian Brandes <florian.brandes@posteo.de>
(cherry picked from commit bcacb9b84c)
2022-04-23 14:58:41 +00:00
Vladimír Čunát
b695411852 Merge #169401: libinput: 1.19.1 → 1.19.4 (into staging-21.11) 2022-04-23 13:09:28 +02:00
Maximilian Bosch
433b4266cd Merge pull request #169912 from NixOS/backport-169640-to-release-21.11
[Backport release-21.11] nextcloud: 22.2.6 -> 22.2.7, 23.0.3 -> 23.0.4
2022-04-23 10:49:57 +02:00
Pavol Rusnak
80bbf0bfa4 Merge pull request #169913 from prusnak/electron-21.11
[21.11] electron: 15.5.2, 16.2.3
2022-04-23 10:49:42 +02:00
Anders Kaseorg
40ef873784 electron_16: 16.2.1 → 16.2.3
Signed-off-by: Anders Kaseorg <andersk@mit.edu>
(cherry picked from commit d2a5b1281c)
2022-04-23 10:37:56 +02:00
Anders Kaseorg
0dea5dd4c0 electron_15: 15.5.1 → 15.5.2
Signed-off-by: Anders Kaseorg <andersk@mit.edu>
(cherry picked from commit 163c53865c)
2022-04-23 10:37:51 +02:00
Yaya
19e99c663f nextcloud: 22.2.6 -> 22.2.7, 23.0.3 -> 23.0.4
(cherry picked from commit 7dc9954956)
2022-04-23 07:52:54 +00:00
github-actions[bot]
3919de14fc Merge staging-next-21.11 into staging-21.11 2022-04-23 00:13:44 +00:00
github-actions[bot]
fd8ec1ad4d Merge release-21.11 into staging-next-21.11 2022-04-23 00:13:06 +00:00
Rick van Schijndel
a318a09a96 Merge pull request #169827 from NixOS/backport-169054-to-release-21.11
[Backport release-21.11] firectl: 0.1.0 -> unstable-2022-03-01
2022-04-22 19:08:33 +02:00
Blake Smith
5a259008fc firectl: 0.1.0 -> 0.1.0-unstable-2022-03-01
The latest version of nixpkgs.firecracker (1.0.0) is incompatible
with version 0.1.0 of firectl. Must use latest HEAD in upstream
to pick up breaking changes in the API. See:
https://github.com/firecracker-microvm/firectl/issues/82

(cherry picked from commit 6c87c725e2)
2022-04-22 17:03:33 +00:00
davidak
0df1622bd1 Merge pull request #169701 from bobby285271/epiphany
[21.11] gnome.epiphany: 41.2 → 41.4
2022-04-22 17:15:33 +02:00
Kerstin Humm
9453194b4e imagemagick: 7.1.0-29 -> 7.1.0-30
(cherry picked from commit 1200c1c3e0)
2022-04-22 13:54:16 +02:00
Kerstin Humm
9ee9ef71f0 imagemagick: 7.1.0-26 -> 7.1.0-29
(cherry picked from commit 388d576fd1)
2022-04-22 13:54:16 +02:00
Vladimír Čunát
692729210d Merge #169338: staging-next-21.11: iteration 10 - 2022-04-19 2022-04-22 08:50:27 +02:00
Bobby Rong
aba436bc7d gnome.epiphany: 41.3 → 41.4
https://gitlab.gnome.org/GNOME/epiphany/-/compare/41.3...41.4

Fixes: CVE-2022-29536
2022-04-22 13:44:54 +08:00
Bobby Rong
3703f00ea4 gnome.epiphany: 41.2 → 41.3
https://gitlab.gnome.org/GNOME/epiphany/-/compare/41.2...41.3

(cherry picked from commit 4cc9dd266d)
2022-04-22 13:44:51 +08:00
github-actions[bot]
64dfb0099a Merge staging-next-21.11 into staging-21.11 2022-04-22 00:16:11 +00:00
github-actions[bot]
33e27a3a9e Merge release-21.11 into staging-next-21.11 2022-04-22 00:15:31 +00:00
Maximilian Bosch
f0d8b06914 grafana: 8.4.6 -> 8.4.7
ChangeLog: https://github.com/grafana/grafana/releases/tag/v8.4.7
(cherry picked from commit 12e2fb8418)
2022-04-21 12:12:01 -07:00
adisbladis
d0203b27ce Merge pull request #169495 from risicle/ris-crun-CVE-2022-27650-r21.11
[21.11] crun: add patch for CVE-2022-27650
2022-04-21 18:10:28 +07:00
Bobby Rong
8961077afb Merge pull request #169141 from bobby285271/pantheon-stable
[21.11] Pantheon 6.1 backports 2022-04-18
2022-04-21 16:32:08 +08:00
Artturi
9887f02476 Merge pull request #169476 from NixOS/backport-169365-to-release-21.11
[Backport release-21.11] chromium: Fix Wayland screen sharing
2022-04-21 03:41:32 +03:00
Bobby Rong
4e653dfd91 libinput: 1.19.3 → 1.19.4
https://lists.x.org/archives/wayland-devel/2022-April/042161.html

Fixes: CVE-2022-1215
2022-04-21 08:33:04 +08:00
github-actions[bot]
679f48a0de Merge staging-next-21.11 into staging-21.11 2022-04-21 00:16:10 +00:00
github-actions[bot]
98371df571 Merge release-21.11 into staging-next-21.11 2022-04-21 00:15:27 +00:00
Robert Scott
8531bb850b crun: add patch for CVE-2022-27650 2022-04-20 22:11:15 +01:00
Michael Weiss
ba57e30893 chromium: Fix Wayland screen sharing
Fix #167526.

(cherry picked from commit bf7968139a)
2022-04-20 19:29:05 +00:00
Stig
326ef98078 Merge pull request #169439 from NixOS/backport-169066-to-release-21.11
[Backport release-21.11] franz: 5.6.1 -> 5.9.2
2022-04-20 16:58:08 +02:00
Lassulus
c5076b5a06 Merge pull request #163319 from Izorkin/backport-fix-nginx
[Backport release-21.11] nixos/nginx: update SystemCallFilter
2022-04-20 13:57:59 +01:00
Stig Palmquist
b9f98896e7 franz: 5.6.1 -> 5.9.2
(cherry picked from commit 5799e2580d)
2022-04-20 12:54:03 +00:00
Jan Tojnar
eda888e821 libinput: fix docs build
(cherry picked from commit 818de15e48)
2022-04-20 14:27:57 +08:00
Jan Tojnar
b7877574ed libinput: add freedesktop team to maintainers
(cherry picked from commit 1e144d4d08)
2022-04-20 14:27:57 +08:00
Jan Tojnar
5e10136092 libinput: Clean up
- format with nixpkgs-fmt
- use more conventional attribute ordering
- remove non-existent file from patchShebang args
- remove unnecessary if from sphinx-build binding (Nix is lazy so we do not need to null it when not used)

(cherry picked from commit 2144f37d36)
2022-04-20 14:27:57 +08:00
R. Ryantm
bf4f4e37f5 libinput: 1.19.1 → 1.19.3
https://lists.x.org/archives/wayland-devel/2021-October/042003.html
https://lists.x.org/archives/wayland-devel/2021-December/042068.html
(cherry picked from commit 58fb597c43)
2022-04-20 14:27:25 +08:00
github-actions[bot]
10b013e2ee Merge staging-next-21.11 into staging-21.11 2022-04-20 00:15:39 +00:00
github-actions[bot]
a8f26fec11 Merge release-21.11 into staging-next-21.11 2022-04-20 00:14:59 +00:00
Maximilian Bosch
147b03fa8e Merge pull request #169211 from Ma27/mautrix-whatsapp-backport
[21.11] mautrix-whatsapp: 0.3.0 -> 0.3.1
2022-04-19 22:42:59 +02:00
Timothy DeHerrera
7fd9c90a22 Merge pull request #169344 from NixOS/backport-169334-to-release-21.11
[Backport release-21.11] matrix-synapse: 1.56.0 -> 1.57.0
2022-04-19 09:59:41 -06:00
Sumner Evans
3c5d0357fd matrix-synapse: 1.56.0 -> 1.57.0
(cherry picked from commit a6bc9e05cf)
2022-04-19 15:44:49 +00:00
Vladimír Čunát
0d7f1b3a00 Merge branch 'staging-21.11' into staging-next-21.11 2022-04-19 15:24:35 +02:00
Vladimír Čunát
6222967639 Merge #168782: re2c: add patch for CVE-2022-23901
...into staging-21.11
2022-04-19 14:59:28 +02:00
Jan Tojnar
17d83d4085 Merge pull request #169170 from blitz/evolution-no-accel-html
[21.11] evolution: disable hardware accelerated HTML rendering
2022-04-19 11:19:52 +02:00
github-actions[bot]
15d012ab52 Merge staging-next-21.11 into staging-21.11 2022-04-19 00:13:16 +00:00
github-actions[bot]
ee8a8f498c Merge release-21.11 into staging-next-21.11 2022-04-19 00:12:43 +00:00
Charlotte Van Petegem
0b742e307c mautrix-whatsapp: 0.3.0 -> 0.3.1
(cherry picked from commit aaa165b6e5)
2022-04-18 17:02:43 +02:00
R. Ryantm
ebffb8cc8c hydrus: 480 -> 481
(cherry picked from commit 6592797222)
2022-04-18 13:35:03 +00:00
Robert Scott
ac1191a866 pjsip: add patch for CVE-2022-24764
(cherry picked from commit e7e3e939a8)
2022-04-18 15:17:13 +02:00
Vladimír Čunát
775b7bafe9 Merge #169122: libarchive: add patch for CVE-2022-26280
...into staging-21.11
2022-04-18 10:41:53 +02:00
Julian Stecklina
a937a7ef30 evolution: disable hardware accelerated HTML rendering
... because this causes problems for some users. For affected people,
the email composer becomes non-functional.
2022-04-18 10:34:54 +02:00
Jan Tojnar
7b38b03d76 Merge pull request #169059 from blitz/evolution-3.42.4
[21.11] evolution 3.42.1 -> 3.42.4
2022-04-18 03:21:58 +02:00
Bobby Rong
70ff93a6ed pantheon.switchboard-plug-keyboard: 2.6.0 -> 2.7.0
(cherry picked from commit b46cbe495c)
2022-04-18 09:00:18 +08:00
Bobby Rong
42a42fd900 pantheon.elementary-notifications: 6.0.0 -> 6.0.1
(cherry picked from commit abc7fcc7d4)
2022-04-18 09:00:18 +08:00
Bobby Rong
e0be405fb2 pantheon.gala: 6.3.0 -> 6.3.1
(cherry picked from commit 53b09d3791)
2022-04-18 09:00:17 +08:00
Bobby Rong
39a4a055ba pantheon.switchboard-plug-sound: 2.3.0 -> 2.3.1
(cherry picked from commit cbaf3e7e93)
2022-04-18 08:59:21 +08:00
Bobby Rong
33f1e5e9b8 pantheon.switchboard-plug-onlineaccounts: 6.3.0 -> 6.4.0
(cherry picked from commit fc8b3dbb50)
2022-04-18 08:59:10 +08:00
Bobby Rong
f582392ca0 pantheon.switchboard-plug-about: 6.0.1 -> 6.1.0
(cherry picked from commit 4981cba909)
2022-04-18 08:58:49 +08:00
Bobby Rong
8ffe5fcf88 pantheon.elementary-code: 6.1.0 -> 6.2.0
(cherry picked from commit c1732444bf)
2022-04-18 08:58:16 +08:00
Bobby Rong
23c70eec46 pantheon.elementary-dock: run glib-compile-schemas
(cherry picked from commit 3f6e36987b)
2022-04-18 08:57:11 +08:00
Bobby Rong
b8f50e631f nixos/pantheon: enable xdg desktop integration
This prevents the embarrassing situation in https://github.com/NixOS/nixpkgs/pull/163828 from happening again.

(cherry picked from commit 65f9112d6b)
2022-04-18 08:56:05 +08:00
github-actions[bot]
ea869b571d Merge staging-next-21.11 into staging-21.11 2022-04-18 00:15:40 +00:00
github-actions[bot]
5d960354a4 Merge release-21.11 into staging-next-21.11 2022-04-18 00:14:59 +00:00
Sandro
cce0c52132 Merge pull request #168989 from chkno/backport-yt-dlp
[21.11] yt-dlp: 2022.3.8.2 → 2022.04.08
2022-04-18 01:10:55 +02:00
Robert Scott
5c7e2cb0b5 libarchive: add patches for CVE-2022-26280, OSS Fuzz issue 38764 2022-04-17 23:45:30 +01:00
Michael Weiss
1e92782fe3 Merge pull request #168980 from NixOS/backport-168971-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 100.0.4896.88 -> 100.0.4896.127
2022-04-17 22:55:26 +02:00
Julian Stecklina
9c860d2f52 evolution-ews: 3.42.1 -> 3.42.4 2022-04-17 16:45:13 +02:00
Julian Stecklina
c7dca70738 evolution: 3.42.1 -> 3.42.4 2022-04-17 16:45:13 +02:00
Julian Stecklina
2e3a145051 evolution-data-server: 3.42.3 -> 3.42.4 2022-04-17 16:45:13 +02:00
Mario Rodas
c093b038d8 Merge pull request #168903 from NixOS/backport-168855-to-release-21.11
[Backport release-21.11] brave: 1.37.113 -> 1.37.116
2022-04-17 08:31:40 -05:00
github-actions[bot]
28127d9758 Merge staging-next-21.11 into staging-21.11 2022-04-17 00:15:38 +00:00
github-actions[bot]
6c618eab64 Merge release-21.11 into staging-next-21.11 2022-04-17 00:15:01 +00:00
Scott Worley
61678f91d0 yt-dlp: 2022.3.8.2 → 2022.04.08
"The websites yt-dlp deals with are a very moving target. That means that
downloads break constantly. Because of that, updates should always be backported
to the latest stable release."

(cherry picked from commit 7833517adc)
2022-04-16 16:57:01 -07:00
Michael Weiss
ecb1f58a2b ungoogled-chromium: 100.0.4896.88 -> 100.0.4896.127
(cherry picked from commit f3bdf57f61)
2022-04-16 22:55:30 +00:00
taku0
1aa2f64722 thunderbird-bin: 91.7.0 -> 91.8.0
(cherry picked from commit 067b774e7c)
2022-04-16 21:41:45 +00:00
Louis Bettens
0a862f558d chromium: 100.0.4896.88 -> 100.0.4896.127 (#168959)
https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_14.html

This update includes 2 security fixes. Google is aware that an exploit
for CVE-2022-1364 exists in the wild.

CVEs:
CVE-2022-1364

(cherry picked from commit a6a25ec43d)
2022-04-16 23:07:41 +02:00
Kim Lindberger
61ccf659d9 Merge pull request #168949 from NixOS/backport-168705-to-release-21.11
[Backport release-21.11] discourse: 2.9.0.beta3 -> 2.9.0.beta4
2022-04-16 21:51:22 +02:00
Ryan Mulligan
d02141a716 discourse: 2.9.0.beta3 -> 2.9.0.beta4
(cherry picked from commit 8c33504431)
2022-04-16 18:13:27 +00:00
Timo Kaufmann
ca0837d2ed Merge pull request #168914 from NixOS/backport-165968-to-release-21.11
[Backport release-21.11] xprintidle: init at 0.2.4
2022-04-16 15:36:43 +02:00
Francesco Gazzetta
11fa928139 xprintidle: init at 0.2.4
(cherry picked from commit 745dd2d18b)
2022-04-16 12:10:17 +00:00
R. Ryantm
0c4f0cf720 brave: 1.37.113 -> 1.37.116
(cherry picked from commit f419f92b6d986123370c74d6ae5eb90521e89d1b)
2022-04-16 10:53:00 +00:00
Maximilian Bosch
6d857c657a Merge pull request #168898 from NixOS/backport-168754-to-release-21.11
[Backport release-21.11] element-{web,desktop}: 1.10.9 -> 1.10.10
2022-04-16 12:00:20 +02:00
Maximilian Bosch
7e3936d000 element-{web,desktop}: 1.10.9 -> 1.10.10
ChangeLog: https://github.com/vector-im/element-web/releases/tag/v1.10.10
(cherry picked from commit c30945a93f)
2022-04-16 09:36:10 +00:00
Maximilian Bosch
62535eec26 Merge pull request #168886 from Ma27/neomutt-security
[21.11] neomutt: apply patch for CVE-2022-1328
2022-04-16 11:33:28 +02:00
Maximilian Bosch
994e58f32b Merge pull request #168896 from NixOS/backport-168385-to-release-21.11
[Backport release-21.11] element{-desktop,}: 1.10.8 -> 1.10.9
2022-04-16 11:30:04 +02:00
Sumner Evans
097d21811e element{-desktop,}: 1.10.8 -> 1.10.9
(cherry picked from commit 2e7cca7690)
2022-04-16 09:12:01 +00:00
Maximilian Bosch
7c839aeb0c Merge pull request #168757 from Ma27/backport-php
[21.11] php74: 7.4.28 -> 7.4.29, php80: 8.0.17 -> 8.0.18
2022-04-16 09:18:11 +02:00
Maximilian Bosch
db1a3b7d6d neomutt: apply patch for CVE-2022-1328
This fixes a buffer overflow in NeoMutt, to quote the original
report[1]:

> Hello, In mutt_decode_uuencoded(), the line length is read from the
> untrusted uuencoded part without validation. This could result in
> including private memory in message parts, for example fragments of
> other messages, passphrases or keys in replys.

Security advistory for the corresponding CVE-2022-1328 is on GitHub[2].

Applying the entire release 20220415 is IMHO too risky because too much
has changed, but applying the patch only works fine as well here.

In NeoMutt 20220415 / Mutt 2.2.3 there's also a fix for an integer
overflow[3] of a `strlen()` for very large messages which is however not
exploitable for NeoMutt according to the upstream maintainers[4], so I
won't backport this patch as well.

Related to https://github.com/NixOS/nixpkgs/pull/168800.

[1] https://gitlab.com/muttmua/mutt/-/issues/404
[2] https://github.com/advisories/GHSA-qfrq-pp74-gpff
[3] https://gitlab.com/muttmua/mutt/-/issues/405
[4] 2bedc9762e:
2022-04-16 09:07:01 +02:00
Martin Weinelt
35e06823d1 Merge pull request #168279 from mweinelt/21.11/django 2022-04-16 03:25:56 +02:00
github-actions[bot]
05906918d2 Merge staging-next-21.11 into staging-21.11 2022-04-16 00:14:50 +00:00
github-actions[bot]
787b138f68 Merge release-21.11 into staging-next-21.11 2022-04-16 00:14:08 +00:00
Mario Rodas
1e1ea42463 Merge pull request #168729 from mweinelt/21.11/ruby
[21.11] ruby_2_7: 2.7.5 -> 2.7.6; ruby_3_0: 3.0.3 -> 3.0.4
2022-04-15 18:59:44 -05:00
Martin Weinelt
278ecd211a Merge pull request #168805 from Luflosi/backport-168330-to-release-21.11 2022-04-16 01:33:54 +02:00
Mario Rodas
042f9e2719 Merge pull request #168802 from NixOS/backport-168720-to-release-21.11
[Backport release-21.11] mruby: add patch for CVE-2022-1212
2022-04-15 11:43:45 -05:00
Robert Scott
0ded6f3ef7 mruby: add patch for CVE-2022-1212
(cherry picked from commit fbfa7ea82d)
2022-04-15 16:18:19 +00:00
Maximilian Bosch
cab8ac3450 Merge pull request #168785 from drupol/php/composer-fix-CVE-2022-24828-backport-21.11
[21.11] php.packages.composer: 2.1.9 -> 2.3.5
2022-04-15 17:56:28 +02:00
Luflosi
6595b056b4 ipfs: 0.11.0 -> 0.11.1
https://github.com/ipfs/go-ipfs/releases/tag/v0.11.1
2022-04-15 17:32:21 +02:00
Pol Dellaiera
ba7c1becd4 php74Packages.composer: 2.3.3 -> 2.3.5
https://github.com/composer/composer/releases/tag/2.3.4
https://github.com/composer/composer/releases/tag/2.3.5
https://github.com/composer/composer/security/advisories/GHSA-x7cr-6qr6-2hh6

Fixes: CVE-2022-24828
(cherry picked from commit 6f2f0aaeb7)
2022-04-15 15:33:12 +02:00
R. Ryantm
965a8cd420 php74Packages.composer: 2.2.9 -> 2.3.3
(cherry picked from commit 3aa6277c43)
2022-04-15 15:30:22 +02:00
R. Ryantm
4201e55a33 php74Packages.composer: 2.2.7 -> 2.2.9
(cherry picked from commit 8bf228ce2a)
2022-04-15 15:30:16 +02:00
R. Ryantm
7b12c5e477 php74Packages.composer: 2.2.6 -> 2.2.7
(cherry picked from commit d118f55e23)
2022-04-15 15:30:10 +02:00
R. Ryantm
6fe663d812 php74Packages.composer: 2.2.3 -> 2.2.6
(cherry picked from commit 2b225076c7)
2022-04-15 15:30:03 +02:00
R. Ryantm
c7ea4753c2 php74Packages.composer: 2.2.1 -> 2.2.3
(cherry picked from commit cb9f7cafde)
2022-04-15 15:29:55 +02:00
R. Ryantm
64637d5291 php74Packages.composer: 2.1.14 -> 2.2.1
(cherry picked from commit 5c6e813ba3)
2022-04-15 15:29:49 +02:00
R. Ryantm
c2c7c856f4 php74Packages.composer: 2.1.9 -> 2.1.14
(cherry picked from commit 0782984c05)
2022-04-15 15:29:41 +02:00
Robert Scott
63e709aea1 re2c: add patch for CVE-2022-23901 2022-04-15 13:11:14 +01:00
Maximilian Bosch
c5a2cd6245 Merge pull request #168718 from NixOS/backport-168588-to-release-21.11
[Backport release-21.11] Linux kernels 2022-04-13
2022-04-15 10:34:05 +02:00
Pol Dellaiera
1517fedf3b php80: 8.0.17 -> 8.0.18
(cherry picked from commit abb096f629)
2022-04-15 09:18:01 +02:00
Pol Dellaiera
f29408b78e php74: 7.4.28 -> 7.4.29
(cherry picked from commit ba45a559b5)
2022-04-15 09:17:42 +02:00
Martin Weinelt
c248b4a964 Merge pull request #168742 from mweinelt/21.11/brave 2022-04-15 04:46:59 +02:00
R. Ryantm
b282ab2316 brave: 1.37.109 -> 1.37.113
(cherry picked from commit 8838263f3c)
2022-04-15 04:32:15 +02:00
TredwellGit
098ffbe7b3 brave: 1.36.122 -> 1.37.109
https://github.com/brave/brave-browser/blob/master/CHANGELOG_DESKTOP.md#137109
(cherry picked from commit 82230fc6ea)
2022-04-15 04:32:01 +02:00
Martin Weinelt
3fad60c0fc Merge pull request #168389 from NixOS/backport-168377-to-staging-21.11 2022-04-15 04:17:05 +02:00
JR Boyens
33e3e8d745 ruby_3_0: 3.0.3 -> 3.0.4
https://www.ruby-lang.org/en/news/2022/04/12/ruby-3-0-4-released/

Fixes: CVE-2022-28738, CVE-2022-28739
(cherry picked from commit 3e995fbb31)
2022-04-15 02:44:12 +02:00
JR Boyens
acfa21644f ruby_2_7: 2.7.5 -> 2.7.6
https://www.ruby-lang.org/en/news/2022/04/12/ruby-2-7-6-released/

Fixes: CVE-2022-28739
(cherry picked from commit dd5210d85a)
2022-04-15 02:42:02 +02:00
github-actions[bot]
ff24bf5400 Merge staging-next-21.11 into staging-21.11 2022-04-15 00:13:50 +00:00
github-actions[bot]
32ee5c7519 Merge release-21.11 into staging-next-21.11 2022-04-15 00:13:10 +00:00
TredwellGit
0753dae9ca linux-rt_5_4: 5.4.182-rt72 -> 5.4.188-rt73
(cherry picked from commit 73a50cd17b)
2022-04-14 22:59:42 +00:00
TredwellGit
50b9d2dc0d linux: 5.17.2 -> 5.17.3
(cherry picked from commit d061104f96)
2022-04-14 22:59:42 +00:00
TredwellGit
505bedd766 linux: 5.16.19 -> 5.16.20
(cherry picked from commit e70511248b)
2022-04-14 22:59:42 +00:00
TredwellGit
a6ce20642c linux: 5.15.33 -> 5.15.34
(cherry picked from commit 34a4c9124c)
2022-04-14 22:59:42 +00:00
TredwellGit
209edf88d7 linux: 5.10.110 -> 5.10.111
(cherry picked from commit 2e87b82c83)
2022-04-14 22:59:42 +00:00
TredwellGit
8987f8607a linux: 4.9.309 -> 4.9.310
(cherry picked from commit 9415d2917c)
2022-04-14 22:59:42 +00:00
Martin Weinelt
8c50fd17f9 Merge pull request #168709 from primeos/backports/git 2022-04-15 00:56:47 +02:00
Michael Weiss
4670b4ee8b git: 2.33.2 -> 2.33.3
To address usability issues in the recent security releases
(0e6c141c9e), where each "safe" directory has to be
listed on the safe.directory configuration variables:
https://lore.kernel.org/git/xmqq1qy04iqa.fsf@gitster.g/
2022-04-14 22:57:12 +02:00
Anderson Torres
2f06b87f64 Merge pull request #168621 from NixOS/backport-168467-to-release-21.11
[Backport release-21.11] palemoon: 29.4.5.1 -> 29.4.6
2022-04-14 11:00:29 -03:00
Mario Rodas
da26d3de60 Merge pull request #168625 from NixOS/backport-168426-to-release-21.11
[Backport release-21.11] vscode: 1.66.1 -> 1.66.2
2022-04-14 08:32:54 -05:00
Maximilian Bosch
4e58e5eb67 grafana: 8.4.5 -> 8.4.6
No-op release: https://github.com/grafana/grafana/releases/tag/v8.4.6

Yes, this is actually not really needed since we only provide the OSS
version of Grafana and the CVE in question is only exploitable on
Grafana enterprise, but I decided to perform this update to test the
update script I previously implemented in 7708fccf01.

(cherry picked from commit e633d42747)
2022-04-14 14:00:56 +01:00
Mario Rodas
d001cb5dc3 Merge pull request #168624 from NixOS/backport-168449-to-release-21.11
[Backport release-21.11] vscodium: 1.66.1 -> 1.66.2
2022-04-14 07:40:15 -05:00
nixpkgs-upkeep-bot
9098ba98b8 vscode: 1.66.1 -> 1.66.2
(cherry picked from commit db770979f1)
2022-04-14 11:49:10 +00:00
nixpkgs-upkeep-bot
ee11bda9b0 vscodium: 1.66.1 -> 1.66.2
(cherry picked from commit 5acc34d95a)
2022-04-14 11:47:44 +00:00
R. Ryantm
e08cac733c palemoon: 29.4.5.1 -> 29.4.6
(cherry picked from commit 93b9c6708e)
2022-04-14 11:31:37 +00:00
Kim Lindberger
7b73f7085d Merge pull request #168602 from NixOS/backport-168459-to-release-21.11
[Backport release-21.11] nomachine-client: 7.8.2 -> 7.9.2
2022-04-14 12:36:31 +02:00
R. Ryantm
536f9ec5c3 alfis: 0.6.10 -> 0.6.11
(cherry picked from commit 2fb034ffca581f383494dfc9bbd2c6587ee9cd9e)
2022-04-14 10:15:57 +00:00
talyz
d7f7d3d61d nomachine-client: 7.8.2 -> 7.9.2
(cherry picked from commit 756d8c1d4f)
2022-04-14 08:50:40 +00:00
Michele Guerini Rocco
0e9ea4f35f Merge pull request #167142 from rnhmjoj/pr-gitea-cve
gitea: patch for CVE-2022-0905, CVE-2022-1058
2022-04-14 10:02:57 +02:00
Michele Guerini Rocco
ffe1d05e1c Merge pull request #168458 from rnhmjoj/pr-mutt-cve
mutt: patch for CVE-2022-1328
2022-04-14 10:01:47 +02:00
github-actions[bot]
e00e2b98f7 Merge staging-next-21.11 into staging-21.11 2022-04-14 00:16:20 +00:00
github-actions[bot]
1e9fefd4ea Merge release-21.11 into staging-next-21.11 2022-04-14 00:15:42 +00:00
Artturi
a62ce97f92 Merge pull request #166294 from NixOS/backport-165890-to-release-21.11
[Backport release-21.11] gotify-desktop: 1.2.0 -> 1.3.1
2022-04-14 00:03:05 +03:00
Michele Guerini Rocco
d0362111ed Merge pull request #168533 from NixOS/backport-168456-to-release-21.11
[Backport release-21.11] qutebrowser: fix userscripts directory path
2022-04-13 22:32:37 +02:00
Michael Weiss
50b504f1df Merge pull request #168416 from NixOS/backport-168410-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 100.0.4896.75 -> 100.0.4896.88
2022-04-13 22:09:01 +02:00
Michael Weiss
bd6893ac80 Merge pull request #168415 from NixOS/backport-168409-to-release-21.11
[Backport release-21.11] chromium: 100.0.4896.75 -> 100.0.4896.88
2022-04-13 22:08:41 +02:00
rnhmjoj
246be6cf64 qutebrowser: fix userscripts directory path
(cherry picked from commit 17c2ca9084)
2022-04-13 20:06:06 +00:00
Vladimír Čunát
6457ec74e1 Merge #168418: git: 2.33.1 -> 2.33.2 (into staging-21.11) 2022-04-13 20:50:20 +02:00
Vladimír Čunát
d4f138b4aa Merge #168133: libtiff: add patches for multiple CVEs
...into staging-21.11
2022-04-13 15:37:29 +02:00
Martin Weinelt
3ec9e6968f Merge pull request #168474 from NixOS/backport-168433-to-release-21.11 2022-04-13 15:31:48 +02:00
Martin Weinelt
5846e02524 subversion_1_10: 1.10.7 -> 1.10.8
https://svn.apache.org/repos/asf/subversion/tags/1.10.8/CHANGES
https://subversion.apache.org/security/CVE-2021-28544-advisory.txt
https://subversion.apache.org/security/CVE-2022-24070-advisory.txt

Fixes: CVE-2021-28544, CVE-2022-24070
(cherry picked from commit c6eee6386d)
2022-04-13 11:03:21 +00:00
Martin Weinelt
301920c929 subversion: 1.14.1 -> 1.14.2
https://svn.apache.org/repos/asf/subversion/tags/1.14.2/CHANGES
https://subversion.apache.org/security/CVE-2021-28544-advisory.txt
https://subversion.apache.org/security/CVE-2022-24070-advisory.txt

Fixes: CVE-2021-28544, CVE-2022-24070
(cherry picked from commit 8f43f3dc40)
2022-04-13 11:03:21 +00:00
rnhmjoj
ddc949accb mutt: patch for CVE-2022-1328 2022-04-13 10:35:56 +02:00
Lassulus
8604556c95 Merge pull request #166493 from dali99/stable-hydrus
[21.11] hydrus: 474 -> 480
2022-04-13 09:55:39 +02:00
Martin Weinelt
83f4403210 Merge pull request #168411 from NixOS/backport-168378-to-release-21.11 2022-04-13 02:30:05 +02:00
github-actions[bot]
8499e6bd38 Merge staging-next-21.11 into staging-21.11 2022-04-13 00:15:15 +00:00
github-actions[bot]
e2f9210c96 Merge release-21.11 into staging-next-21.11 2022-04-13 00:14:36 +00:00
Michael Weiss
0e6c141c9e git: 2.33.1 -> 2.33.2 (security, CVE-2022-24765)
https://lore.kernel.org/git/xmqqv8veb5i6.fsf@gitster.g/

https://github.com/git/git/blob/v2.33.2/Documentation/RelNotes/2.33.2.txt:
"This release merges up the fixes that appear in v2.30.3, v2.31.2 and
v2.32.1 to address the security issue CVE-2022-24765"
2022-04-13 00:12:25 +02:00
Michael Weiss
c20dd2fb3a ungoogled-chromium: 100.0.4896.75 -> 100.0.4896.88
(cherry picked from commit a67703536a)
2022-04-12 22:07:48 +00:00
Michael Weiss
a4d7659236 chromium: 100.0.4896.75 -> 100.0.4896.88
https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_11.html

This update includes 11 security fixes.

CVEs:
CVE-2022-1305 CVE-2022-1306 CVE-2022-1307 CVE-2022-1308 CVE-2022-1309
CVE-2022-1310 CVE-2022-1311 CVE-2022-1312 CVE-2022-1313 CVE-2022-1314

(cherry picked from commit d2f296b3e8)
2022-04-12 22:06:45 +00:00
Martin Weinelt
658d268e9a firefox-bin: 99.0 -> 99.0.1
https://www.mozilla.org/en-US/firefox/99.0.1/releasenotes/
(cherry picked from commit d0e5a586b1)
2022-04-12 20:30:54 +00:00
Martin Weinelt
672f42c434 firefox: 99.0 -> 99.0.1
https://www.mozilla.org/en-US/firefox/99.0.1/releasenotes/
(cherry picked from commit 07c6d44239)
2022-04-12 20:30:54 +00:00
Martin Weinelt
e241fb4eb8 python39: 3.10.3 -> 3.10.4
https://www.python.org/downloads/release/python-3104/
https://docs.python.org/release/3.10.4/whatsnew/changelog.html
(cherry picked from commit 4507b9b688f9794abed6d0aec39b067066aacd76)
2022-04-12 16:32:14 +00:00
Martin Weinelt
b70c7320c5 python39: 3.9.11 -> 3.9.12
https://www.python.org/downloads/release/python-3912/
https://docs.python.org/release/3.9.12/whatsnew/changelog.html
(cherry picked from commit 9cf9596385c915ded2a52bf22c98e9bf43cc8c92)
2022-04-12 16:32:14 +00:00
Kim Lindberger
838eefb4f9 Merge pull request #168366 from talyz/21.11-discourse-2.9.0.beta3
[21.11] discourse: 2.9.0.beta1 -> 2.9.0.beta3
2022-04-12 12:51:32 +02:00
talyz
58babd0ecc discourse.plugins: Update all plugins to their latest versions
(cherry picked from commit 9b891e6f64)
2022-04-12 10:43:37 +02:00
talyz
cacbf4561c discourse: 2.9.0.beta1 -> 2.9.0.beta3
(cherry picked from commit 04afc69a29)
2022-04-12 10:43:31 +02:00
github-actions[bot]
08d34dad01 Merge staging-next-21.11 into staging-21.11 2022-04-12 00:14:38 +00:00
github-actions[bot]
b6543aa1d0 Merge release-21.11 into staging-next-21.11 2022-04-12 00:14:00 +00:00
R. Ryantm
503aec6c4e psi-plus: 1.5.1600 -> 1.5.1615
(cherry picked from commit c3dfe39b61)
2022-04-11 15:05:57 +00:00
Martin Weinelt
27ad79784b python3Packages.django_3: 3.2.12 -> 3.2.13
https://www.djangoproject.com/weblog/2022/apr/11/security-releases/
https://docs.djangoproject.com/en/3.2/releases/3.2.13/

Fixes: CVE-2022-28346, CVE-2022-28347
(cherry picked from commit bf201810d4)
2022-04-11 14:56:06 +02:00
Robert Schütz
d43e4c0a9a python3Packages.django_3: fix pname
(cherry picked from commit 8b4354e860)
2022-04-11 14:56:02 +02:00
Martin Weinelt
3385a0a22d python3Packages.django_2: 2.2.27 -> 2.2.28
https://www.djangoproject.com/weblog/2022/apr/11/security-releases/
https://docs.djangoproject.com/en/2.2/releases/2.2.28/

Fixes: CVE-2022-28346, CVE-2022-28347
2022-04-11 14:54:29 +02:00
Maximilian Bosch
a31e3437d3 Merge pull request #168164 from NixOS/backport-168118-to-release-21.11
[Backport release-21.11] Linux kernels 2022-04-08
2022-04-11 13:08:22 +02:00
Sandro
ecedcaa473 Merge pull request #168187 from NixOS/backport-168181-to-release-21.11 2022-04-11 10:57:33 +02:00
github-actions[bot]
7437e81fc7 Merge staging-next-21.11 into staging-21.11 2022-04-11 00:14:11 +00:00
github-actions[bot]
26821e92ec Merge release-21.11 into staging-next-21.11 2022-04-11 00:13:38 +00:00
Robert Scott
93fb95449e libtiff: add some reverse dependencies to passthru.tests
(cherry picked from commit 93c5836538)
2022-04-10 23:56:41 +01:00
Sandro Jäckel
b5949ce23f pngcheck: fix meta.platforms not being flattened, remove zlib overwrite
zlib is build with static by default

(cherry picked from commit 507dc6bae6)
2022-04-10 21:11:29 +00:00
Michael Weiss
e7d63bd0d5 Merge pull request #167750 from NixOS/backport-167589-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 100.0.4896.60 -> 100.0.4896.75
2022-04-10 21:32:36 +02:00
TredwellGit
6b5478bf44 linux-rt_5_4: 5.4.182-rt71 -> 5.4.182-rt72
(cherry picked from commit 3a47fa6f0a)
2022-04-10 18:57:35 +00:00
TredwellGit
57d60e5d9f linux-rt_5_10: 5.10.106-rt64 -> 5.10.109-rt65
(cherry picked from commit 83fdd68cba)
2022-04-10 18:57:35 +00:00
TredwellGit
c538ba789f linux: 5.17.1 -> 5.17.2
(cherry picked from commit cc0d608279)
2022-04-10 18:57:35 +00:00
TredwellGit
8a35a8bd83 linux: 5.16.18 -> 5.16.19
(cherry picked from commit 89e6f752db)
2022-04-10 18:57:35 +00:00
TredwellGit
b71a754a23 linux: 5.15.32 -> 5.15.33
(cherry picked from commit 2827192c14)
2022-04-10 18:57:35 +00:00
TredwellGit
bbe55638e7 linux: 5.10.109 -> 5.10.110
(cherry picked from commit 46e8fed971)
2022-04-10 18:57:34 +00:00
TredwellGit
55fd199e68 linux: 4.14.274 -> 4.14.275
(cherry picked from commit f4a3848a68)
2022-04-10 18:57:34 +00:00
Martin Weinelt
c40d4178ca Merge pull request #168151 from NixOS/backport-158482-to-release-21.11 2022-04-10 18:31:05 +02:00
Stig Palmquist
bd21ef1159 bluez: 5.62 -> 5.63
(cherry picked from commit d0a84bf142)
2022-04-10 16:10:45 +00:00
Artturi
9a144814ac Merge pull request #165358 from NixOS/backport-163216-to-release-21.11
[Backport release-21.11] boost: unbreak build for 1.65 and 1.66
2022-04-10 16:23:19 +03:00
Mario Rodas
b15a584351 Merge pull request #167829 from NixOS/backport-167258-to-release-21.11
[Backport release-21.11] curlie: 1.6.7 -> 1.6.9
2022-04-10 08:08:28 -05:00
Robert Scott
079e176cba libtiff: add patches for multiple CVEs
CVE-2022-0891
CVE-2022-0865
CVE-2022-0924
CVE-2022-0907
CVE-2022-0909
CVE-2022-0908

(cherry picked from commit 748dfdd1f5)
2022-04-10 12:46:38 +00:00
Janne Heß
f08d5bd38e Merge pull request #155853 from domenkozar/cachix-agent-21.11
[Backport 21.11] Cachix Agent
2022-04-10 14:24:13 +02:00
Artturi
f601b6f117 Merge pull request #168117 from NixOS/backport-167784-to-staging-21.11
[Backport staging-21.11] gzip: 1.11 -> 1.12
2022-04-10 14:28:18 +03:00
Martin Weinelt
ec4202bc45 gzip: 1.11 -> 1.12
https://savannah.gnu.org/forum/forum.php?forum_id=10157
https://git.savannah.gnu.org/cgit/gzip.git/commit/?id=dc9740df61e575e8c3148b7bd3c147a81ea00c7c

Fixes: CVE-2022-1271
(cherry picked from commit c4d4de89dd)
2022-04-10 09:49:11 +00:00
github-actions[bot]
e1025de0f8 Merge staging-next-21.11 into staging-21.11 2022-04-10 00:14:39 +00:00
github-actions[bot]
b366453c4e Merge release-21.11 into staging-next-21.11 2022-04-10 00:14:08 +00:00
Martin Weinelt
db81927829 Merge pull request #167920 from NixOS/backport-166298-to-release-21.11 2022-04-10 00:05:05 +02:00
Martin Weinelt
6cf17f0e1f Merge pull request #168056 from NixOS/backport-167921-to-release-21.11 2022-04-09 23:58:56 +02:00
Nicolas Benes
b6d468e451 tor-browser-bundle-bin: 11.0.9 -> 11.0.10
(cherry picked from commit d7c3643e6e)
2022-04-09 21:30:32 +00:00
Vladimír Čunát
715dc137b0 Merge #167647: staging-next: 21.11 iteration 9 - 2022-04-07 2022-04-09 22:48:11 +02:00
Thiago Kenji Okada
28c9534203 Merge pull request #168027 from NixOS/backport-167561-to-release-21.11
[Backport release-21.11] thunderbird-unwrapped: 91.7.0 -> 91.8.0
2022-04-09 21:05:26 +01:00
R. Ryantm
793a185ef5 thunderbird-unwrapped: 91.7.0 -> 91.8.0
(cherry picked from commit 4c2a906df5)
2022-04-09 18:44:24 +00:00
rnhmjoj
71f5fb1442 gitea: patch for CVE-2022-0905, CVE-2022-1058 2022-04-09 18:26:32 +02:00
davidak
5c9771cd1b Merge pull request #168002 from NixOS/backport-167968-to-release-21.11
[Backport release-21.11] bcachefs: 2022-03 -> 2022-04
2022-04-09 18:12:35 +02:00
techknowlogick
03d836b490 mastodon: 3.5.0 -> 3.5.1
Co-authored-by: Kerstin Humm <kerstin@erictapen.name>
(cherry picked from commit 6a441683a0)
2022-04-09 17:59:36 +02:00
Kerstin Humm
c47eef1f52 mastodon.updateScript: use correct input for nix-prefetch-git, better formatting
(cherry picked from commit 15313692cd)
2022-04-09 17:59:36 +02:00
Kerstin Humm
740202217f mastodon.updateScript: use runCommand instead of mkDerivation
(cherry picked from commit daf2b0f917)
2022-04-09 17:59:36 +02:00
Robert Schütz
25a92bb3f1 python39Packages.argh: fix tests
(cherry picked from commit c3928d527c)
2022-04-09 16:29:25 +02:00
Martin Weinelt
cd0ebd48bb python3Packages.seaborn: disable flaky tests 2022-04-09 16:26:16 +02:00
Madoura
ae8c5d35b5 bcachefs-tools: unstable-2022-03-22 -> unstable-2022-04-08
(cherry picked from commit ba944d42b3)
2022-04-09 14:19:59 +00:00
Madoura
f44697b92d linux_testing_bcachefs: unstable-2022-03-21 -> unstable-2022-04-08
(cherry picked from commit 3bc830267e)
2022-04-09 14:19:59 +00:00
Ben Siraphob
1788212d94 python3Packages.graphviz: disable tests on darwin
(cherry picked from commit 1a1f78dc02)
2022-04-09 16:00:47 +02:00
Malo Bourgon
1df7fde663 python3Packages.httplib2: disable failing test on darwin
(cherry picked from commit b9ed8525d9)
2022-04-09 15:57:18 +02:00
Maximilian Bosch
27b0c39887 Merge pull request #167732 from NixOS/backport-167352-to-release-21.11
[Backport release-21.11] matrix-synapse: 1.55.2 -> 1.56.0
2022-04-09 13:36:42 +02:00
Maximilian Bosch
0ccd6076a7 Merge pull request #167975 from NixOS/backport-167924-to-release-21.11
[Backport release-21.11] wiki-js: add update script, 2.5.276 -> 2.5.277
2022-04-09 13:31:10 +02:00
Mario Rodas
c2efd71717 Merge pull request #167952 from NixOS/backport-167833-to-release-21.11
[Backport release-21.11] vscodium: 1.66.0 -> 1.66.1
2022-04-09 06:22:40 -05:00
Maximilian Bosch
931860e074 wiki-js: 2.5.276 -> 2.5.277
ChangeLog: https://github.com/requarks/wiki/releases/tag/v2.5.277
(cherry picked from commit dfc0ddaa87)
2022-04-09 09:44:58 +00:00
Maximilian Bosch
ff10e27f31 wiki-js: add update script
(cherry picked from commit 2e2aed7100)
2022-04-09 09:44:58 +00:00
Vladimír Čunát
c86185d20d Merge #162234: python3*Packages.hydra: filter Python versions
..into release-21.11
2022-04-09 09:53:09 +02:00
Linus Heckemann
4a72b83416 Merge pull request #167762 from NixOS/backport-156845-to-release-21.11
[Backport release-21.11] nextcloud: make home group-readable
2022-04-09 09:33:59 +02:00
Mario Rodas
2fcd36b9c9 Merge pull request #167954 from NixOS/backport-167790-to-release-21.11
[Backport release-21.11] vscode: 1.66.0 -> 1.66.1
2022-04-08 21:14:35 -05:00
nixpkgs-upkeep-bot
f377233369 vscode: 1.66.0 -> 1.66.1
(cherry picked from commit af9cad4c94)
2022-04-09 01:45:42 +00:00
R. Ryantm
6f923b245a vscodium: 1.66.0 -> 1.66.1
(cherry picked from commit f79ae01933)
2022-04-09 01:43:47 +00:00
Mario Rodas
f989c9a8b3 Merge pull request #166585 from NixOS/backport-166500-to-release-21.11
[Backport release-21.11] vscode: 1.65.2 -> 1.66.0
2022-04-08 20:39:52 -05:00
Mario Rodas
63843df0d8 Merge pull request #166819 from NixOS/backport-166565-to-release-21.11
[Backport release-21.11] vscodium: 1.65.2 -> 1.66.0
2022-04-08 20:38:05 -05:00
github-actions[bot]
61d539d706 Merge staging-next-21.11 into staging-21.11 2022-04-09 00:15:05 +00:00
github-actions[bot]
ebbf50a7a5 Merge release-21.11 into staging-next-21.11 2022-04-09 00:14:30 +00:00
Jan Tojnar
e2b791c31d webkitgtk: 2.34.6 → 2.36.0
https://webkitgtk.org/2022/03/21/webkitgtk2.36.0-released.html
(cherry picked from commit 7dfc1de13d05a72ba03412c29458ecbb1158b155)
2022-04-08 20:50:38 +00:00
Lassulus
f00f618072 Merge pull request #162752 from NixOS/backport-159735-to-release-21.11
[Backport release-21.11] macvim: 8.2.1719 -> 8.2.3455
2022-04-08 19:59:55 +01:00
Will
b9abad0531 spidermonkey_91: 91.7.0 -> 91.8.0
(cherry picked from commit 7979a1b294)
2022-04-08 11:34:28 +00:00
Vladimír Čunát
74d8dc719b Merge #166923: knot-dns: 3.1.6 -> 3.1.7
...into staging-next-21.11
2022-04-08 12:37:38 +02:00
Izorkin
b01a688d40 mastodon: fix indexing statuses in elasticsearch
(cherry picked from commit 6e629bf17fbee30b63f3346141b268ed369f90bc)
2022-04-08 11:53:21 +02:00
Terje Larsen
8022732de1 curlie: set and test version
(cherry picked from commit b3af29aa16)
2022-04-08 06:50:26 +00:00
Terje Larsen
745fd080a2 curlie: 1.6.7 -> 1.6.9
(cherry picked from commit a440e3ec91)
2022-04-08 06:50:26 +00:00
github-actions[bot]
c52427199c Merge staging-next-21.11 into staging-21.11 2022-04-08 00:14:57 +00:00
github-actions[bot]
5c506dfa23 Merge release-21.11 into staging-next-21.11 2022-04-08 00:14:22 +00:00
Daniel Olsen
9234852841 hydrus: 474 -> 480 2022-04-08 00:51:42 +02:00
Eduardo Quiros
29abf698b3 signal-desktop: 5.36.0 -> 5.37.0
(cherry picked from commit 2303dc0128)
2022-04-07 15:00:16 -07:00
Jörg Thalheim
0a221b22bd nextcloud: use tmpfiles to create group-readable home
users.users.*.createHome makes home only owner-readable.
This breaks nginx reading static assets from nextcloud's home,
after a nixos-rebuild that did not restart nextcloud-setup.

Closes #112639

(cherry picked from commit 956dab36a3)
2022-04-07 19:19:31 +00:00
Kim Lindberger
a261726696 Merge pull request #167748 from NixOS/backport-166602-to-release-21.11
[Backport release-21.11] keycloak: 16.1.0 -> 17.0.1
2022-04-07 21:13:37 +02:00
Michael Weiss
9cff124c76 ungoogled-chromium: 100.0.4896.60 -> 100.0.4896.75
(cherry picked from commit 15291355d8)
2022-04-07 18:06:10 +00:00
talyz
53ae7061fa keycloak: 16.1.0 -> 17.0.1
(cherry picked from commit dd2cab2b50)
2022-04-07 17:59:43 +00:00
Sumner Evans
6d4b6189e8 matrix-synapse: 1.55.2 -> 1.56.0
(cherry picked from commit 55f2b8834e)
2022-04-07 16:15:56 +00:00
Maximilian Bosch
e73b1ce8fa Merge pull request #167086 from NixOS/backport-165745-to-release-21.11
[Backport release-21.11] matrix-synapse: 1.55.0 -> 1.55.2
2022-04-07 18:11:06 +02:00
Mario Rodas
87d0fabaec Merge pull request #167706 from NixOS/backport-164802-to-release-21.11
[Backport release-21.11] tailscale: 1.22.1 -> 1.22.2
2022-04-07 10:28:58 -05:00
Ilan Joselevich
62807b4276 tailscale: 1.22.1 -> 1.22.2
(cherry picked from commit 290c5083e0)
2022-04-07 13:16:57 +00:00
Ryan Burns
1bf41a04bb cpython: remove upstreamed patch
This patch has been merged in python 3.9.7.

4b55837e7c
(cherry picked from commit 925bbece2f)
2022-04-07 11:45:28 +02:00
Markus S. Wamser
66dc8dec6b python3Packages.hydra: exclude failing Python tests/unsupported versions 2022-04-07 11:18:23 +02:00
Vladimír Čunát
e387bb3a4d Merge #165225: nixos/tests/quorum: fix by syncing from master
...into release-21.11
2022-04-07 08:44:00 +02:00
Vladimír Čunát
a9204373d7 Merge branch 'staging-21.11' into staging-next-21.11 2022-04-07 08:33:15 +02:00
Vladimír Čunát
f2fd032362 Merge #164727: nodejs: Fix setup-hook addNodePath quoting
...into staging-21.11
2022-04-07 08:20:42 +02:00
Vladimír Čunát
b906832c7d Merge #167643: zlib: fix cross-compilation (into staging-21.11) 2022-04-07 08:17:56 +02:00
Vladimír Čunát
d1b8c4da41 Merge #166955: libarchive: 3.5.2 -> 3.5.3 (into staging-21.11) 2022-04-07 08:15:14 +02:00
Rick van Schijndel
697d1c5126 zlib: fix cross-compilation not producing shared libraries
Apply patch that already has been applied upstream:
- https://github.com/madler/zlib/pull/607
- 05796d3d8d

(cherry picked from commit f091c0e80d)
2022-04-07 06:13:05 +00:00
Vladimír Čunát
ab58cb47b0 Merge #164862: libopenmpt: 0.5.11 -> 0.5.17 (into staging-21.11) 2022-04-07 08:10:01 +02:00
github-actions[bot]
d3559389b3 Merge staging-next-21.11 into staging-21.11 2022-04-07 00:14:47 +00:00
github-actions[bot]
2086534683 Merge release-21.11 into staging-next-21.11 2022-04-07 00:14:16 +00:00
Martin Weinelt
60f020d822 Merge pull request #167436 from NixOS/backport-167255-to-release-21.11 2022-04-07 00:24:05 +02:00
Michael Weiss
f19f483ea0 Merge pull request #167401 from NixOS/backport-167387-to-release-21.11
[Backport release-21.11] chromium: 100.0.4896.60 -> 100.0.4896.75
2022-04-06 22:24:00 +02:00
Martin Weinelt
d2930924d2 Merge pull request #167558 from NixOS/revert-166354-21.11/twisted 2022-04-06 19:41:40 +02:00
Bjørn Forsman
7cc6478c34 nixos/ethminer: only pull in nvidia_x11 when needed
Only people using CUDA need it.

(cherry picked from commit c1af79c69d)
2022-04-06 19:13:42 +02:00
Bjørn Forsman
11c4666306 nixos/ethminer: fix option types for maxPower, recheckInterval
Neither power nor time intervals can be negative, let's use unsigned
int.

(cherry picked from commit 25daed6ec9479543f2e2ff4d7b070bf827058f52)
2022-04-06 19:12:56 +02:00
Bjørn Forsman
8990551ead nixos/ethminer: only pull in cudatoolkit when needed
(cherry picked from commit 61c12836df14aea16d91edb06317537ab7c29847)
2022-04-06 19:12:56 +02:00
Martin Weinelt
557ae1d5cb Revert "[21.11] python3Packages.twisted: fix CVE-2022-21712" 2022-04-06 18:59:41 +02:00
Thomas Tuegel
941b4b8f04 Merge pull request #167227 from ttuegel/kate-lsp-cve
Fix CVE-2022-23853
2022-04-06 09:16:04 -05:00
Martin Weinelt
334a352481 nss: 3.76 -> 3.76.1
https://github.com/nss-dev/nss/blob/master/doc/rst/releases/nss_3_76_1.rst
2022-04-06 03:42:01 +02:00
github-actions[bot]
d3e899d617 Merge staging-next-21.11 into staging-21.11 2022-04-06 00:13:55 +00:00
github-actions[bot]
43416cb90b Merge release-21.11 into staging-next-21.11 2022-04-06 00:13:21 +00:00
ajs124
a8b40864e1 nss: 3.75 -> 3.76
https://github.com/nss-dev/nss/blob/master/doc/rst/releases/nss_3_76.rst
(cherry picked from commit 4e0daeeee4)
2022-04-06 01:26:58 +02:00
Martin Weinelt
0574639d23 firefox-bin: 98.0.2 -> 99.0
https://www.mozilla.org/en-US/firefox/99.0/releasenotes/
(cherry picked from commit d93cf53f65)
2022-04-05 23:08:00 +00:00
Martin Weinelt
d87e0065ff firefox: 91.7.1 -> 91.8.0
https://www.mozilla.org/en-US/firefox/91.8.0/releasenotes/
(cherry picked from commit 35ae0b7a1b)
2022-04-05 23:08:00 +00:00
Martin Weinelt
15d64f0d84 firefox: 98.0.2 -> 99.0
https://www.mozilla.org/en-US/firefox/99.0/releasenotes/
(cherry picked from commit e1e03e5bc2)
2022-04-05 23:08:00 +00:00
Alyssa Ross
e2279b00af busybox: fix CVE-2022-28391
(cherry picked from commit ac60e92b15)
2022-04-05 21:26:15 +00:00
Michael Weiss
9ac50e37cb chromium: 100.0.4896.60 -> 100.0.4896.75
https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop.html

This update includes 1 security fix.

CVEs:
CVE-2022-1232

(cherry picked from commit 9687fffa00)
2022-04-05 20:22:37 +00:00
Michael Weiss
3a00e0ed41 Merge pull request #166855 from NixOS/backport-166809-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 99.0.4844.84 -> 100.0.4896.60
2022-04-05 21:07:46 +02:00
Artturi
44d0ecdf27 Merge pull request #167309 from Artturin/backport-167292-to-release-21.11 2022-04-05 14:33:08 +03:00
Artturin
c784de43b7 [release-21.11] nixVersions.nix_2_7: add patch to fix #163374 2022-04-05 11:57:49 +03:00
github-actions[bot]
5159d40a0a Merge staging-next-21.11 into staging-21.11 2022-04-05 00:13:25 +00:00
github-actions[bot]
62ad2df516 Merge release-21.11 into staging-next-21.11 2022-04-05 00:12:46 +00:00
Tristan Daniël Maat
ccb90fb9e1 nvidia_x11: 495.44 -> 510.60.02
Bump the driver version to the latest stable version to fix
incompatibility with Linux 5.17.1.
2022-04-04 17:03:39 -07:00
Thomas Tuegel
bcf0de51c8 kate: 21.08.3 -> 21.12.2
This out-of-band update is necessary to fix CVE-2022-23853.
2022-04-04 15:01:00 -05:00
Thomas Tuegel
40da13660e ktexteditor: patch for CVE-2022-23853 2022-04-04 14:25:31 -05:00
Maximilian Bosch
fcc07c40a3 Merge pull request #167178 from Ma27/backport-element-web
[21.11] element-{web,desktop}: 1.10.6 -> 1.10.8
2022-04-04 15:45:08 +02:00
Sumner Evans
04a827b681 element{-desktop,}: 1.10.7 -> 1.10.8
(cherry picked from commit 1c223b6343)
2022-04-04 15:21:33 +02:00
Sumner Evans
d04685e4cc element-{desktop,}: 1.10.6 -> 1.10.7
(cherry picked from commit 72eac4c3d0)
2022-04-04 15:21:32 +02:00
github-actions[bot]
bff137d889 Merge staging-next-21.11 into staging-21.11 2022-04-04 00:14:02 +00:00
github-actions[bot]
db9c6ef9b4 Merge release-21.11 into staging-next-21.11 2022-04-04 00:13:18 +00:00
Maximilian Bosch
af0a9bc0e5 Merge pull request #166863 from NixOS/backport-166607-to-release-21.11
[Backport release-21.11] grafana: 8.4.4 -> 8.4.5
2022-04-04 00:18:29 +02:00
R. Ryantm
7c759f6223 matrix-synapse: 1.55.0 -> 1.55.2
(cherry picked from commit 2ec30e4b14)
2022-04-03 21:03:14 +00:00
Robert Scott
a59507e9a6 Merge pull request #166747 from NickCao/maddy
[21.11] maddy: 0.5.2 -> 0.5.4
2022-04-03 20:55:00 +01:00
Pavol Rusnak
14775340a5 Merge pull request #166783 from prusnak/electron-21.11
[21.11] electron_16: 16.1.0 -> 16.2.1, electron_15: 15.4.1 -> 15.5.1, electron_14: 14.2.7 -> 14.2.9
2022-04-03 17:44:22 +02:00
fleimgruber
b599e5d6c2 alda: 2.0.6 -> 2.2.0
cherry-picked from 90e831473c
2022-04-03 17:20:19 +02:00
Vladimír Čunát
0aac710801 Merge #166910: perlPackages.CompressRawZlib: doCheck = false
...into release-21.11
2022-04-03 08:04:06 +02:00
Artturi
22d49109b6 Merge pull request #164337 from NixOS/backport-163926-to-release-21.11 2022-04-03 03:58:53 +03:00
github-actions[bot]
a573b8592e Merge staging-next-21.11 into staging-21.11 2022-04-03 00:14:25 +00:00
github-actions[bot]
fcc56913fd Merge release-21.11 into staging-next-21.11 2022-04-03 00:13:47 +00:00
Artturi
a8217b4d3c Merge pull request #166904 from NixOS/backport-166901-to-release-21.11 2022-04-03 01:52:22 +03:00
Michele Guerini Rocco
0cd8c10060 Merge pull request #166971 from NixOS/backport-166889-to-release-21.11
[Backport release-21.11] qutebrowser: 2.4.0 -> 2.5.0
2022-04-02 23:46:41 +02:00
Robert Scott
d564996528 Merge pull request #166949 from illustris/backport-166770-to-release-21.11
spark: CVE-2021-38296, 3.1.2 -> 3.1.3
2022-04-02 22:06:42 +01:00
rnhmjoj
b752931aa5 qutebrowser: 2.4.0 -> 2.5.0
(cherry picked from commit c313f82a8e)
2022-04-02 20:36:09 +00:00
Anderson Torres
0a42ce7772 Merge pull request #166926 from NixOS/backport-166916-to-release-21.11
[Backport release-21.11] palemoon: 29.4.5 -> 29.4.5.1, add version test
2022-04-02 17:14:07 -03:00
illustris
a907688e23 spark: 3.1.2 -> 3.1.3
backport ff86a2f24f

Fixes: CVE-2021-38296
2022-04-03 00:09:12 +05:30
illustris
babd69ef6a spark: mark 2.4 as vulnerable
backport 8a21b4ea92
2022-04-03 00:05:08 +05:30
Robert Scott
9beae175b5 libarchive: 3.5.2 -> 3.5.3 2022-04-02 19:18:56 +01:00
Robert Scott
e96c85fe03 libarchive: add some reverse dependencies to passthru.tests
(cherry picked from commit cdf5bfff4b)
2022-04-02 19:18:56 +01:00
Robert Scott
1dd6e44b72 Merge pull request #166939 from NixOS/backport-162191-to-release-21.11
[Backport release-21.11] lrzip: 0.641 -> 0.650
2022-04-02 17:54:09 +01:00
R. Ryantm
3c66fd46e9 lrzip: 0.641 -> 0.650
(cherry picked from commit 833aa51924)
2022-04-02 16:10:31 +00:00
Robert Scott
e8f6571c42 Merge pull request #166876 from yayayayaka/gitlab-14.9.2-21.11
[Backport release-21.11] gitlab: 14.9.1 -> 14.9.2
2022-04-02 16:07:20 +01:00
OPNA2608
c49827bdab palemoon: 29.4.5 -> 29.4.5.1, add version test
(cherry picked from commit dfdab81577)
2022-04-02 13:29:34 +00:00
Vladimír Čunát
50a2ba6b88 knot-dns: 3.1.6 -> 3.1.7
This version primarily fixes incomplete implementation of
the Offline KSK signing mode in the IXFR and DDNS processing.

https://gitlab.nic.cz/knot/knot-dns/-/tags/v3.1.7
(cherry picked from commit 2a5a99c586)
2022-04-02 11:54:53 +00:00
Martin Weinelt
46967290a0 gitlab: 14.9.1 -> 14.9.2
https://about.gitlab.com/releases/2022/03/31/critical-security-release-gitlab-14-9-2-released/

Fixes: CVE-2022-1162, CVE-2022-1175, CVE-2022-1190, CVE-2022-1185,
       CVE-2022-1148, CVE-2022-1121, CVE-2022-1120, CVE-2022-1100,
       CVE-2022-1193, CVE-2022-1105, CVE-2022-1099, CVE-2022-1174,
       CVE-2022-1188, CVE-2022-0740, CVE-2022-1189, CVE-2022-1157,
       CVE-2022-1111
(cherry picked from commit 3b2051594b)
2022-04-02 11:29:51 +00:00
Kerstin Humm
11e3ff27e7 imagemagick6: remove erictapen as maintainer
I haven't looked at this package for a long time, so let's reflect that
fact in the maintainer field.

(cherry picked from commit 3881e6a5adf93c3eef01d58416628117af722037)
2022-04-02 13:16:06 +02:00
Vladimír Čunát
1d24330a01 perlPackages.CompressRawZlib: doCheck = false; for now
Failure triggered by the (security) zlib update in PR #166610.
2022-04-02 10:45:42 +02:00
Artturin
bc86aef83b intel-ocl: add http url to url list
intel sometimes decides that they dont want to use http/s
https://github.com/NixOS/nixpkgs/issues/166886

(cherry picked from commit e0b8dc8904)
2022-04-02 03:29:34 +00:00
github-actions[bot]
ea1b89158e Merge staging-next-21.11 into staging-21.11 2022-04-02 00:13:11 +00:00
github-actions[bot]
24d912fff1 Merge release-21.11 into staging-next-21.11 2022-04-02 00:12:32 +00:00
Maximilian Bosch
c67bc4d39c grafana: 8.4.4 -> 8.4.5
ChangeLog: https://github.com/grafana/grafana/releases/tag/v8.4.5
(cherry picked from commit bab7f65636)
2022-04-01 19:55:29 +00:00
Michael Adler
3c06a12a38 ungoogled-chromium: 99.0.4844.84 -> 100.0.4896.60
(cherry picked from commit e41e5e30f3)
2022-04-01 19:04:12 +00:00
Martin Weinelt
6f88260faa Merge pull request #166721 from mweinelt/21.11/mediawiki
[21.11] mediawiki: 1.36.3 -> 1.36.4
2022-04-01 18:28:46 +02:00
teutat3s
78f050b906 electron: mark versions <= 14 as EOL
(cherry picked from commit ae2990ca1b)
2022-04-01 16:50:05 +02:00
Doron Behar
6f4839cf96 Merge pull request #166805 from NixOS/backport-166798-to-release-21.11 2022-04-01 16:34:30 +03:00
nixpkgs-upkeep-bot
e63f6e1703 vscodium: 1.65.2 -> 1.66.0
(cherry picked from commit cc6775822f)
2022-04-01 13:24:50 +00:00
B4rc1
69a3b5f678 mailspring: 1.9.2 -> 1.10.2
(cherry picked from commit da1544fbf7)
2022-04-01 11:30:36 +00:00
teutat3s
452a2886fe electron_16: 16.1.0 -> 16.2.1
https://github.com/electron/electron/compare/v16.1.0...v16.2.1
(cherry picked from commit 8e9aad9883)
2022-04-01 10:11:14 +02:00
teutat3s
f590749b6a electron_15: 15.4.1 -> 15.5.1
https://github.com/electron/electron/compare/v15.4.1...v15.5.1
(cherry picked from commit 2caf14f6cc)
2022-04-01 10:11:10 +02:00
teutat3s
e92afea307 electron_14: 14.2.7 -> 14.2.9
https://github.com/electron/electron/compare/v14.2.7...v14.2.9

With the release of electron v18, v14 is now officially EOL.
Look for "End of Support for 14.x.y" in:
https://github.com/electron/electron/releases/tag/v18.0.0

(cherry picked from commit 5875fd68d6)
2022-04-01 10:11:06 +02:00
Vincent Laporte
ec4ee3bfa9 ocamlPackages.unionFind: init at 20220122
(cherry picked from commit 4ed24522f2e13dedb0d08815840c41d46a9623a5)
2022-04-01 06:55:30 +02:00
Artturi
500304311f maddy: 0.5.2 -> 0.5.4 2022-04-01 10:26:38 +08:00
github-actions[bot]
36f9461dc3 Merge staging-next-21.11 into staging-21.11 2022-04-01 00:14:58 +00:00
github-actions[bot]
b2f802abd8 Merge release-21.11 into staging-next-21.11 2022-04-01 00:14:25 +00:00
Martin Weinelt
82906cbfb8 mediawiki: 1.36.3 -> 1.36.4
https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/YJNXKPV5Z56NSUQ4G3SXPDUIZG5EQ7UR/

Fixes: CVE-2022-28202, CVE-2022-28201, CVE-2022-28203
2022-04-01 00:07:18 +02:00
Martin Weinelt
7e2165f944 Merge pull request #166610 from mweinelt/21.11-zlib 2022-03-31 23:36:17 +02:00
Kid
7411a01290 fish: disable flaky pexpect tests on aarch64-linux
(cherry picked from commit 50bc5c0f8ff6571e88cf83d9a4a6392769376a1e)
2022-03-31 14:26:39 -07:00
Kid
f034526e35 fish: 3.3.1 -> 3.4.0
(cherry picked from commit a9f0d6993ab67752d82323936fd3f6daaf00c7a7)
2022-03-31 14:26:39 -07:00
Markus S. Wamser
3e14325191 zlib: 1.2.11 -> 1.2.12 (security, CVE-2018-25032)
This version bump is the official fix for CVE-2018-25032.

Release Notes:
https://zlib.net/

(cherry picked from commit 8cd9c041b4)
2022-03-31 20:47:12 +02:00
Tom Wieczorek
439acd6987 zlib: add patches to fix CVE-2018-25032
https://nvd.nist.gov/vuln/detail/CVE-2018-25032
https://www.openwall.com/lists/oss-security/2022/03/24/1

A similar change landed in Alpine: https://git.alpinelinux.org/aports/commit/?id=361df5902aa1e81594b17f06a13e10527dfb8aed

(cherry picked from commit 1832678aee)
2022-03-31 20:45:49 +02:00
Kerstin Humm
0a58eebd8e mastodon: use correct GitHub Url
The tootsuite organization was renamed to mastodon ages ago.

(cherry picked from commit 8e36a26c591f6449c80f3bb65a6d91e5586addea)
2022-03-31 18:32:17 +02:00
Kerstin Humm
e0e26f371f nixos/mastodon: preload libjemalloc.so
Co-authored-by: Izorkin <izorkin@elven.pw>
(cherry picked from commit 192beb869a7b33914a3a432b3db1d7a196d0efe8)
2022-03-31 18:32:17 +02:00
Kerstin Humm
0d9901fdd2 mastodon: 3.4.6 -> 3.5.0
Co-authored-by: Izorkin <izorkin@elven.pw>
(cherry picked from commit a8896bca5e47c16566d35067d0c5ccd11261e685)
2022-03-31 18:32:17 +02:00
Izorkin
2798497cb9 mastodon: build nodejs modules with fetchYarnDeps
(cherry picked from commit 022df44793e8ac752dda9a81c5bba5d57d357a6b)
2022-03-31 18:32:17 +02:00
Izorkin
4b44df718a nixos/tests: add mastodon test
(cherry picked from commit 43ede7e794f1ace794311b124ee9aa6f726e7d9d)
2022-03-31 18:32:17 +02:00
Jelle Besseling
0dfea8f976 mastodon: add aarch64-linux platform
(cherry picked from commit a305410e4e)
2022-03-31 18:32:17 +02:00
nixpkgs-upkeep-bot
329d02ebf2 vscode: 1.65.2 -> 1.66.0
(cherry picked from commit 78a6f5079e)
2022-03-31 15:54:01 +00:00
Artturi
3864fef7d7 Merge pull request #166579 from NixOS/backport-162845-to-release-21.11 2022-03-31 18:21:03 +03:00
Átila Saraiva
7678aef363 oil-buku: improved syntax
(cherry picked from commit d530f3d3d22f3c0b50b7515e5bf0fc28cff62408)
2022-03-31 14:59:23 +00:00
Artturi
59a5293102 Merge pull request #162262 from NixOS/backport-160192-to-release-21.11 2022-03-31 17:52:49 +03:00
Doron Behar
44580dcaa7 Merge pull request #166464 from kini/backport-zoom-us-version-bumps 2022-03-31 09:16:35 +03:00
github-actions[bot]
40119615f4 Merge staging-next-21.11 into staging-21.11 2022-03-31 00:13:14 +00:00
github-actions[bot]
41ae0dd83e Merge release-21.11 into staging-next-21.11 2022-03-31 00:12:38 +00:00
Janne Heß
eb01c16236 nixos/manual: Update copyright years, authors, and copyright
(cherry picked from commit 0ba3874e3a)
2022-03-30 16:21:07 -07:00
Michael Weiss
a50cfca8dc Merge pull request #166314 from NixOS/backport-166300-to-release-21.11
[Backport release-21.11] chromium: 99.0.4844.84 -> 100.0.4896.60
2022-03-30 22:25:14 +02:00
Clemens Lutz
6c5e898737 zoom-us: 5.9.3.1911 -> 5.9.6.2225
(cherry picked from commit ac0dbdcb93)
2022-03-30 13:06:13 -07:00
Clemens Lutz
caddf7d637 zoom-us: 5.9.1.1380 -> 5.9.3.1911
(cherry picked from commit 940737fcf4)
2022-03-30 13:06:02 -07:00
Clemens Lutz
37d8962c90 zoom-us: 5.8.6.739 -> 5.9.1.1380
(cherry picked from commit 958754bfd5)
2022-03-30 13:05:55 -07:00
Clemens Lutz
d702c802ee zoom-us: 5.8.4.210 -> 5.8.6.739
(cherry picked from commit 371082920f)
2022-03-30 13:05:29 -07:00
Janne Heß
0d8dd60947 Merge pull request #166131 from NixOS/backport-166051-to-release-21.11
[Backport release-21.11] Linux kernels 2022-03-28
2022-03-30 20:54:07 +02:00
Martin Weinelt
b87551d579 Merge pull request #164656 from mweinelt/21.11/python39 2022-03-30 16:34:53 +02:00
ajs124
efea022d6f Merge pull request #166354 from mweinelt/21.11/twisted
[21.11] python3Packages.twisted: fix CVE-2022-21712
2022-03-30 15:57:26 +02:00
Martin Weinelt
cd2d8e8389 python3Packages.metar: disable test, remove patch
The test was fine for a day and started failing again yesterday, so we
disable it this time until upstream makes a new release with more
confidence.

(cherry picked from commit ef7564a0ac)
2022-03-30 14:40:28 +02:00
Martin Weinelt
b75a898590 python3Packages.metar: patch another failing test
https://github.com/python-metar/python-metar/issues/165
(cherry picked from commit dd3e2f9587)
2022-03-30 14:40:25 +02:00
Fabian Affolter
92206f454b python3Packages.aiojobs: 0.3.0 -> 1.0.0
(cherry picked from commit b645add4d3)
2022-03-30 14:30:52 +02:00
Martin Weinelt
56c7fa2e59 python3Packages.httpx-socks: disable tests 2022-03-30 14:27:45 +02:00
Jonathan Ringer
6e2c28d6a5 python3Packages.requests-cache: 0.9.0 -> 0.9.1
(cherry picked from commit 407981d056)
2022-03-30 14:16:26 +02:00
R. Ryantm
5189f718a2 python38Packages.requests-cache: 0.8.1 -> 0.9.0
(cherry picked from commit bcbd3725d3)
2022-03-30 14:16:07 +02:00
Vladimír Čunát
d9f92c09ce Merge #166382: knot-resolver: 5.4.4 -> 5.5.0 (into release-21.11) 2022-03-30 10:50:49 +02:00
Vladimír Čunát
cf7e268af4 knot-resolver: 5.4.4 -> 5.5.0
https://gitlab.nic.cz/knot/knot-resolver/-/tags/v5.5.0
(cherry picked from commit a1a2ae2955)
2022-03-30 08:30:56 +00:00
Jonathan Ringer
1958afec16 python3Packages.pyatv: 0.9.6 -> 0.9.7
(cherry picked from commit 796bb9552d)
2022-03-30 06:16:57 +02:00
Fabian Affolter
8343d6c239 python3Packages.pyatv: remove version pinning
(cherry picked from commit ebee4b0090)
2022-03-30 06:16:53 +02:00
Fabian Affolter
3a7060e410 python3Packages.potentials: add missing dependencies
(cherry picked from commit 85585e9d13)
2022-03-30 06:10:13 +02:00
Martin Weinelt
59825ffb7b python3Packages.ansible-runner: disable test that misses an artifact 2022-03-30 05:01:57 +02:00
Yarny0
40fd7022ed tsm-client: 8.1.13.3 -> 8.1.14.0
This update fixes a denial-of-service vulnerability.

Links to IBM's "Authorized Program Analysis Report"s
(something like release notes) for 8.1.14.x:
https://www.ibm.com/support/pages/node/6559268

README for 8.1.14.x:
https://www.ibm.com/support/pages/node/6561875

Security Bulletin:
https://www.ibm.com/support/pages/node/6562383 (CVE-2021-35517, CVE-2021-36090)

(cherry picked from commit ea84f6b9e9)
2022-03-30 02:54:47 +00:00
Martin Weinelt
ba93b1d825 Merge pull request #164134 from mweinelt/21.11-weechat-wsa-2022-1 2022-03-30 04:50:55 +02:00
Martin Weinelt
0a3f21a041 python3Packages.twisted: fix CVE-2022-21712
Twisted versions before 22.1 would leak cookie and authorization headers
when following cross-origin redirects in
`twisted.web.client.RedirectAgent` and
`twisted.web.client.BrowserLikeRedirectAgent`.

Fixes: #CVE-2022-21712
2022-03-30 04:36:08 +02:00
Jonathan Ringer
c638320358 python3Packages.scrapy: disable network test
(cherry picked from commit 0ba0d8511a)
2022-03-30 03:44:10 +02:00
github-actions[bot]
9b48bdba67 Merge staging-next-21.11 into staging-21.11 2022-03-30 00:13:08 +00:00
github-actions[bot]
b70d5edb80 Merge release-21.11 into staging-next-21.11 2022-03-30 00:12:33 +00:00
Martin Weinelt
2c4c567e90 Merge pull request #165454 from helsinki-systems/upd/21.11/tzdata 2022-03-30 01:33:00 +02:00
Jonathan Ringer
e3657d4222 python3Packages.nilearn: reduce test suite significantly
Full test suite attempts to pull down web resources
and can take 9+ hours with timeout periods

(cherry picked from commit a21c84bc75)
2022-03-30 01:15:04 +02:00
Ben Darwin
6749151567 python3Packages.nilearn: unbreak tests
Only recurse into `nilearn/`, not e.g. `examples/`,
which triggers (non-mocked) data downloads.

(cherry picked from commit fa83ed462a)
2022-03-30 01:14:59 +02:00
Martin Weinelt
b07247a380 Merge pull request #166322 from NixOS/backport-164533-to-release-21.11 2022-03-30 01:13:45 +02:00
Markus S. Wamser
a9903c6b4b python3Packages.hacking: disable only failing tests instead of test group
(cherry picked from commit b89c8bcc73)
2022-03-30 01:13:06 +02:00
Sandro Jäckel
1fd7033a44 python39Packages.hacking: disable failing lint test
(cherry picked from commit e7a0a3bb82)
2022-03-30 01:12:57 +02:00
Martin Weinelt
5b1f7769cc nixos/prometheus-exporters/kea: wait for kea
Fixes race conditions like this:

> systemd[1]: Started prometheus-kea-exporter.service.
> kea-exporter[927]: Listening on http://0.0.0.0:9547
> kea-exporter[927]: Socket at /run/kea/dhcp4.sock does not exist. Is Kea running?
> systemd[1]: prometheus-kea-exporter.service: Main process exited, code=exited, status=1/FAILURE

(cherry picked from commit 8b7ca8bdcb)
2022-03-29 22:09:22 +00:00
Michael Weiss
a599b0edf5 chromium: 99.0.4844.84 -> 100.0.4896.60
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_29.html

This update includes 28 security fixes.

CVEs:
CVE-2022-1125 CVE-2022-1127 CVE-2022-1128 CVE-2022-1129 CVE-2022-1130
CVE-2022-1131 CVE-2022-1132 CVE-2022-1133 CVE-2022-1134 CVE-2022-1135
CVE-2022-1136 CVE-2022-1137 CVE-2022-1138 CVE-2022-1139 CVE-2022-1141
CVE-2022-1142 CVE-2022-1143 CVE-2022-1144 CVE-2022-1145 CVE-2022-1146

(cherry picked from commit b647d5a49d)
2022-03-29 21:20:28 +00:00
Michael Weiss
e1cfaa50df Merge pull request #166305 from primeos/chromium-backport
[21.11] Prepare for backporting Chromium M100
2022-03-29 23:15:14 +02:00
Fabian Affolter
f85a6fa951 python3Packages.surepy: relax constraints
(cherry picked from commit 52ece396d7)
2022-03-29 22:29:27 +02:00
Fabian Affolter
5229ebff40 python3Packages.seaborn: add missing dependencies
(cherry picked from commit e822c34ff9)
2022-03-29 22:18:25 +02:00
Jonathan Ringer
0119acea31 python3Packages.aiohttp-wsgi: disable network test
(cherry picked from commit 88e9beea98)
2022-03-29 22:16:10 +02:00
Adam Joseph
c475927312 chromium: honor systemdSupport
This commit exposes that support for compilation without systemd,
controlled by the global systemdSupport argument.  This argument is
understood by many other nixpkgs expressions and can be set globally
in ~/.config/nixpkgs/config.nix.

(cherry picked from commit 5f9ce130b2)
2022-03-29 21:51:04 +02:00
Michael Weiss
b145c6c070 chromiumDev: 101.0.4947.0 -> 101.0.4951.7
(cherry picked from commit a29f5a2eb3)
2022-03-29 21:51:04 +02:00
Michael Weiss
cd9c2a713b chromiumBeta: 100.0.4896.46 -> 100.0.4896.56
(cherry picked from commit ab49a71ae0)
2022-03-29 21:51:04 +02:00
Michael Weiss
7879a26800 chromiumDev: 101.0.4929.5 -> 101.0.4947.0
(cherry picked from commit 93edc87eac)
2022-03-29 21:50:39 +02:00
Michael Weiss
ba927da77d chromiumBeta: 100.0.4896.30 -> 100.0.4896.46
(cherry picked from commit 3e7268af67)
2022-03-29 21:50:39 +02:00
Michael Weiss
2ec364e0d0 chromiumDev: 101.0.4919.0 -> 101.0.4929.5
(cherry picked from commit 7d5373b0ba)
2022-03-29 21:50:39 +02:00
Michael Weiss
381028f447 chromiumBeta: 100.0.4896.20 -> 100.0.4896.30
(cherry picked from commit 7d5e470e1f)
2022-03-29 21:50:38 +02:00
Samuel Gräfenstein
e8561d1398 ungoogled-chromium: inherit upstream's build flags
This ensures that our build flags for ungoogled-chromium will remain
up-to-date with upstream's defaults (also important for avoiding build
errors).

Co-authored-by: Michael Weiss <dev.primeos@gmail.com>
(cherry picked from commit 1122130c6f)
2022-03-29 21:50:38 +02:00
Michael Weiss
ed4e3b4634 chromiumDev: 100.0.4896.20 -> 101.0.4919.0
(cherry picked from commit e1185bdd8f)
2022-03-29 21:49:34 +02:00
Michael Weiss
825d3a5733 chromiumDev: 100.0.4896.12 -> 100.0.4896.20
(cherry picked from commit 691919bf00)
2022-03-29 21:49:33 +02:00
Michael Weiss
d646b32778 chromiumBeta: 99.0.4844.51 -> 100.0.4896.20
(cherry picked from commit 05aa1711fd)
2022-03-29 21:49:31 +02:00
R. Ryantm
e56a24d6d8 gotify-desktop: 1.2.0 -> 1.3.1
(cherry picked from commit b84f13964d)
2022-03-29 19:01:42 +00:00
Robert Hensing
9b168e5e62 Merge pull request #166148 from blaggacao/release-21.11
[21.11] nixos/default.nix: Use extendModules
2022-03-29 13:32:42 +02:00
Jörg Thalheim
2a601aafdc Merge pull request #166204 from NixOS/backport-163914-to-release-21.11
[Backport release-21.11] sops: 3.7.1 -> 3.7.2
2022-03-29 09:40:44 +01:00
R. Ryantm
3525da154c sops: 3.7.1 -> 3.7.2
(cherry picked from commit 1a05175078)
2022-03-29 08:07:57 +00:00
ajs124
5e2fbbab01 Merge pull request #165929 from NixOS/backport-163485-to-release-21.11
[Backport release-21.11] warzone2100: 4.2.6 -> 4.2.7
2022-03-29 04:53:49 +02:00
Martin Weinelt
658366ed17 home-assistant: disable test_periodic_task_entering_dst 2022-03-29 03:52:27 +02:00
github-actions[bot]
2e1e37ffcb Merge staging-next-21.11 into staging-21.11 2022-03-29 00:14:54 +00:00
github-actions[bot]
49b233f6e0 Merge release-21.11 into staging-next-21.11 2022-03-29 00:14:19 +00:00
Jonathan Ringer
60c43f56ac python3Packages.pandas: 1.3.4 -> 1.3.5
(cherry picked from commit 624676631e)
2022-03-29 01:55:14 +02:00
Fabian Affolter
9ac5d4e4fd python3Packages.pandas: disable failing test
(cherry picked from commit f6cfdc97cc)
2022-03-29 01:55:02 +02:00
Jonathan Ringer
9ef176bc07 python3Packages.pandas: 1.3.3 -> 1.3.4
(cherry picked from commit 9b1636a0ef)
2022-03-29 01:54:52 +02:00
Kranium Gikos Mendoza
a7d5bc57e8 pythonPackages.pandas: disable tests on armv7l
(cherry picked from commit 4c391b4329)
2022-03-29 01:54:47 +02:00
Frederik Rietdijk
f514f6736e python3.pkgs.pandas: remove optional dependencies
(cherry picked from commit 6dc2edb831)
2022-03-29 01:54:42 +02:00
Robert Hensing
e613eaa122 nixos/default.nix: Use extendModules
(cherry picked from commit 8fd49c116b)
2022-03-28 17:28:51 -05:00
Martin Weinelt
3d5a2e94b1 Merge pull request #166136 from Flakebi/salt-backport 2022-03-28 23:14:49 +02:00
Flakebi
12dbe33833 salt: 3003.3 -> 3003.4
Fix some CVEs: https://saltproject.io/security_announcements/salt-security-advisory-release/
2022-03-28 22:19:34 +02:00
TredwellGit
e40677399e linux: 5.4.187 -> 5.4.188
(cherry picked from commit 566270be89)
2022-03-28 19:51:56 +00:00
TredwellGit
f8b0f02e8a linux: 5.17 -> 5.17.1
(cherry picked from commit 2ddb5604db)
2022-03-28 19:51:56 +00:00
TredwellGit
070876e9eb linux: 5.16.17 -> 5.16.18
(cherry picked from commit aa374b7acb)
2022-03-28 19:51:56 +00:00
TredwellGit
90bfd297e1 linux: 5.15.31 -> 5.15.32
(cherry picked from commit 6c6a932a9e)
2022-03-28 19:51:56 +00:00
TredwellGit
93b5025e98 linux: 5.10.108 -> 5.10.109
(cherry picked from commit 2abfedc54c)
2022-03-28 19:51:56 +00:00
TredwellGit
062c442872 linux: 4.9.308 -> 4.9.309
(cherry picked from commit 61df0a1d7d)
2022-03-28 19:51:56 +00:00
TredwellGit
4700c27b15 linux: 4.19.236 -> 4.19.237
(cherry picked from commit f77a0e1934)
2022-03-28 19:51:56 +00:00
TredwellGit
b6f419614b linux: 4.14.273 -> 4.14.274
(cherry picked from commit 9ee8097b31)
2022-03-28 19:51:56 +00:00
Yaya
e4be1d981e gitlab: 14.8.4 -> 14.9.1 (#166079) 2022-03-28 21:43:27 +02:00
Martin Weinelt
efd8fa90b2 python3Packages.metar: patch another failing test
https://github.com/python-metar/python-metar/issues/165
(cherry picked from commit dd3e2f9587)
2022-03-28 21:11:43 +02:00
Alyssa Ross
beb1329860 linux_latest: 5.16.14 -> 5.17
(cherry picked from commit 58ae11758e)
2022-03-28 18:34:31 +00:00
Alyssa Ross
a4e58117f6 linuxPackages.openafs: mark broken on Linux 5.17
(cherry picked from commit 3a06e285c9)
2022-03-28 18:34:31 +00:00
Alyssa Ross
54b4af6509 linuxPackages.rtl8821ce: mark broken on Linux 5.17
(cherry picked from commit 2f9822b659)
2022-03-28 18:34:31 +00:00
Alyssa Ross
ec5e38a8ca linuxPackages.r8168: mark broken on Linux 5.17
(cherry picked from commit 6d43305b89)
2022-03-28 18:34:31 +00:00
Alyssa Ross
4ad304fad7 linuxPackages.virtualboxGuestAdditions: mark broken on Linux 5.17
This package is slightly out of date, but 6.1.32 doesn't fix 5.17
compatibility either.

(cherry picked from commit 69af0d1717)
2022-03-28 18:34:31 +00:00
Martin Weinelt
26f798237c python3Packages.metar: patch flaky test
(cherry picked from commit d1ba752c47)
2022-03-28 19:58:39 +02:00
Fabian Affolter
1f58d75184 python3Packages.metar: 1.8.0 -> 1.9.0
(cherry picked from commit 230009c20e)
2022-03-28 19:58:19 +02:00
Michele Guerini Rocco
9cc577aa46 Merge pull request #166095 from helsinki-systems/upd/pdns-recursor
[21.11] pdns-recursor: 4.5.7 -> 4.5.8
2022-03-28 18:21:26 +02:00
ajs124
367bfe8e8e pdns-recursor: 4.5.7 -> 4.5.8
corresponds to e501354c13 on master
2022-03-28 17:20:07 +02:00
Martin Weinelt
ecbb46a033 Merge pull request #166082 from mweinelt/21.11/pdns 2022-03-28 17:18:50 +02:00
Martin Weinelt
657fc6d5d8 powerdns: apply patch for ixfr validation issue
The PowerDNS version we ship on release-21.11 went EOL in january, so
there are no explicit patches for 4.3.1, however the patches for 4.4.2
apply cleanly and the tests are still passing.

https://blog.powerdns.com/2022/03/25/security-advisory-2022-01-for-powerdns-authoritative-server-4-4-2-4-5-3-4-6-0-and-powerdns-recursor-4-4-7-4-5-7-4-6-0/

Fixes: CVE-2022-27227
2022-03-28 16:10:40 +02:00
Maximilian Bosch
4ecbe23395 Merge pull request #166042 from NixOS/backport-165946-to-release-21.11
[Backport release-21.11] strace: 5.16 -> 5.17
2022-03-28 12:16:42 +02:00
Maximilian Bosch
4eb1cd4217 Merge pull request #165847 from lheckemann/nix-backport
[21.11] nix_2_7: init
2022-03-28 10:04:54 +02:00
Maximilian Bosch
f2ed26ad52 strace: 5.16 -> 5.17
ChangeLog: https://github.com/strace/strace/releases/tag/v5.17
(cherry picked from commit df69885883)
2022-03-28 06:52:01 +00:00
Peter Hoeg
963874e2db crystal: remove pointless reference to crystal.lib
(cherry picked from commit ba70ac13715900e0eb8f2f895369b9d0add5359e)
2022-03-28 01:21:07 +00:00
github-actions[bot]
d5013b6f50 Merge staging-next-21.11 into staging-21.11 2022-03-28 00:13:59 +00:00
github-actions[bot]
15127e65e5 Merge release-21.11 into staging-next-21.11 2022-03-28 00:13:24 +00:00
Michael Weiss
d6778e0b5d Merge pull request #166000 from NixOS/backport-165995-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 99.0.4844.82 -> 99.0.4844.84
2022-03-28 00:33:33 +02:00
Maximilian Bosch
f1be379865 Merge pull request #165953 from NixOS/backport-165933-to-release-21.11
[Backport release-21.11] Linux kernels 2022-03-23
2022-03-27 22:08:44 +02:00
Michael Weiss
3bbb08c750 ungoogled-chromium: 99.0.4844.82 -> 99.0.4844.84
(cherry picked from commit d037e72af9)
2022-03-27 20:08:11 +00:00
Sandro
7010ef05a3 Merge pull request #165941 from NixOS/backport-165437-to-release-21.11 2022-03-27 20:33:59 +02:00
TredwellGit
21e98b41d0 linux_latest-libre: 18635 -> 18664
(cherry picked from commit 00e6bef2a6)
2022-03-27 14:29:43 +00:00
TredwellGit
f192b5180c linux: 5.4.186 -> 5.4.187
(cherry picked from commit bc04900afa)
2022-03-27 14:29:43 +00:00
TredwellGit
c1fc377949 linux: 5.16.16 -> 5.16.17
(cherry picked from commit 0cbdca520d)
2022-03-27 14:29:43 +00:00
TredwellGit
662ac47be8 linux: 5.15.30 -> 5.15.31
(cherry picked from commit a8443f0ce4)
2022-03-27 14:29:43 +00:00
TredwellGit
9275499545 linux: 5.10.107 -> 5.10.108
(cherry picked from commit 7bfe0eec2b)
2022-03-27 14:29:43 +00:00
TredwellGit
71243ca924 linux: 4.9.307 -> 4.9.308
(cherry picked from commit 2dec7aec6d)
2022-03-27 14:29:42 +00:00
TredwellGit
6deb2857a3 linux: 4.19.235 -> 4.19.236
(cherry picked from commit 8af99c4aab)
2022-03-27 14:29:42 +00:00
TredwellGit
794d21179f linux: 4.14.272 -> 4.14.273
(cherry picked from commit da2b3f0897)
2022-03-27 14:29:42 +00:00
TredwellGit
7a3f9d626c Merge pull request #165942 from NixOS/backport-165931-to-release-21.11
[Backport release-21.11] brave: 1.36.116 -> 1.36.122
2022-03-27 12:20:10 +00:00
TredwellGit
90d3498398 brave: 1.36.116 -> 1.36.122
https://github.com/brave/brave-browser/blob/master/CHANGELOG_DESKTOP.md#136122
(cherry picked from commit 19e94fc995)
2022-03-27 12:18:05 +00:00
Markus S. Wamser
9ca4ded203 python3Packages.hacking: disable only failing tests instead of test group
(cherry picked from commit b89c8bcc73)
2022-03-27 12:16:32 +00:00
R. Ryantm
904a35f168 matio: 1.5.21 -> 1.5.22
(cherry picked from commit 43a7abb40689ed1c8b52723fc5411ef20cacee6f)
2022-03-27 12:21:18 +02:00
Francesco Gazzetta
87448049e0 warzone2100: 4.2.6 -> 4.2.7
(cherry picked from commit 997fa335c3)
2022-03-27 10:07:06 +00:00
Vladimír Čunát
9ccf045d61 Merge #165119: nixosTests.kubernetes.rbac-*: disable
...into release-21.11
2022-03-27 08:35:56 +02:00
github-actions[bot]
d085cf8e19 Merge staging-next-21.11 into staging-21.11 2022-03-27 00:14:44 +00:00
github-actions[bot]
b8a2fda0ee Merge release-21.11 into staging-next-21.11 2022-03-27 00:13:59 +00:00
Michael Weiss
dfa6cc8893 Merge pull request #165875 from NixOS/backport-165867-to-release-21.11
[Backport release-21.11] chromium: 99.0.4844.82 -> 99.0.4844.84
2022-03-26 22:32:50 +01:00
Michael Weiss
573bad0744 chromium: 99.0.4844.82 -> 99.0.4844.84
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html

This update includes 1 security fix. Google is aware that an exploit for
CVE-2022-1096 exists in the wild.

CVEs:
CVE-2022-1096

(cherry picked from commit 89704501dc)
2022-03-26 20:55:38 +00:00
w
ac1ac63f3b mime-types: unrot url 2022-03-26 11:29:16 -07:00
davidak
1f12986d80 Merge pull request #165790 from Madouura/dev/backport-bcachefs
[Backport release-21.11] bcachefs and related
2022-03-26 18:23:05 +01:00
Maximilian Bosch
7dc8b4b813 nix_2_7: init 2022-03-26 18:03:07 +01:00
Anderson Torres
6b6b8052dd Merge pull request #165835 from NixOS/backport-165703-to-release-21.11
[Backport release-21.11] palemoon: 29.4.4 -> 29.4.5
2022-03-26 09:38:39 -03:00
OPNA2608
875c908012 palemoon: 29.4.4 -> 29.4.5
(cherry picked from commit e0b1208a35)
2022-03-26 12:01:59 +00:00
Maximilian Bosch
2c3e3fdc81 Merge pull request #165716 from NixOS/backport-164876-to-release-21.11
[Backport release-21.11] Linux kernels 2022-03-19
2022-03-26 11:52:36 +01:00
Fabian Affolter
fa8db4ccf5 Merge pull request #165824 from NixOS/backport-165811-to-release-21.11
[Backport release-21.11] pythonPackages.nbxmpp: 2.0.4 → 2.0.6
2022-03-26 10:58:20 +01:00
Vincent Laporte
f3871f1dbd pythonPackages.nbxmpp: 2.0.4 → 2.0.6
(cherry picked from commit ee3bbd14f9)
2022-03-26 09:08:18 +00:00
github-actions[bot]
2d00d37b77 Merge staging-next-21.11 into staging-21.11 2022-03-26 00:13:13 +00:00
github-actions[bot]
17eefebc8d Merge release-21.11 into staging-next-21.11 2022-03-26 00:12:42 +00:00
Gregor Kleen
e80f8f4d83 zfs: 2.1.3 -> 2.1.4
(cherry picked from commit 53c1fe6b2e)
2022-03-25 16:27:21 -07:00
Charlotte 🦝 Delenk
fd59ae34a6 bcachefs-tools: 2022-03-09 -> 2022-03-22
(cherry picked from commit d278459294)
2022-03-25 16:17:11 -05:00
Charlotte 🦝 Delenk
565f3667d2 linux_testing_bcachefs: 2022-03-09 -> 2022-03-21
This should fix a bug causing kernel panics when your fs has snapshots
enabled. See:
https://lore.kernel.org/all/bc622d24-9fad-7b3-22cb-da4bf2dd32d@ewheeler.net/T/

This patch also bumps the kernel version to 5.16, as bcachefs is devel-
oping against that now.

(cherry picked from commit 158789753f)
2022-03-25 16:17:01 -05:00
Jamie McClymont
f3663942a3 bcachefs: update maintainers
As requested in https://github.com/NixOS/nixpkgs/pull/163433#issuecomment-1066169644

(cherry picked from commit 3b01bd6249)
2022-03-25 16:16:34 -05:00
Jamie McClymont
165da06e3d nixos/bcachefs: re-enable encryption in test
(cherry picked from commit 4ee9b84ec5)
2022-03-25 16:16:25 -05:00
Madoura
8b071fc6c8 nixos/tests/bcachefs: use multi-disk
(cherry picked from commit 4f7cfc8cd9)
2022-03-25 16:16:02 -05:00
Jamie McClymont
d606a05402 bcachefs-tools: enable parallel building
(cherry picked from commit 5a8602a87b)
2022-03-25 16:14:08 -05:00
Jamie McClymont
13a5c59b6e bcachefs-tools: unstable-2022-01-12 -> unstable-2022-03-09
(cherry picked from commit db181acbf8)
2022-03-25 16:14:00 -05:00
Jamie McClymont
5f07839a50 linux_testing_bcachefs: unstable-2022-01-12 -> unstable-2022-03-09
(cherry picked from commit 4f64621056)
2022-03-25 16:13:50 -05:00
Pascal Bach
d89f18a17e Merge pull request #165709 from NixOS/backport-165420-to-release-21.11
[Backport release-21.11] nextcloud: 22.2.5 -> 22.2.6, 23.0.2 -> 23.0.3
2022-03-25 11:19:37 +01:00
TredwellGit
f9dbb3768d linux-rt_5_10: 5.10.104-rt63 -> 5.10.106-rt64
(cherry picked from commit 2d1b42d216)
2022-03-25 00:15:54 +00:00
TredwellGit
d7ba27bcd5 linux: 5.4.185 -> 5.4.186
(cherry picked from commit 7c8a33bbcf)
2022-03-25 00:15:54 +00:00
TredwellGit
0b2a76d00a linux: 5.16.15 -> 5.16.16
(cherry picked from commit e5f91ad134)
2022-03-25 00:15:54 +00:00
TredwellGit
65e7664282 linux: 5.15.29 -> 5.15.30
(cherry picked from commit 32f1dca656)
2022-03-25 00:15:54 +00:00
TredwellGit
ddbb1d0d4a linux: 5.10.106 -> 5.10.107
(cherry picked from commit 76cfedbe28)
2022-03-25 00:15:54 +00:00
github-actions[bot]
c3dcd229f8 Merge staging-next-21.11 into staging-21.11 2022-03-25 00:13:32 +00:00
github-actions[bot]
def120e62d Merge release-21.11 into staging-next-21.11 2022-03-25 00:13:00 +00:00
Will Dietz
3e201ab3de [21.11] ldns: 1.7.1 -> 1.8.1 (security, backport) (#165121)
* ldns: 1.7.1 -> 1.8.0

(cherry picked from commit 5677e477d3)

* ldns: 1.8.0 -> 1.8.1

(cherry picked from commit 84c77b4620)

Co-authored-by: Martin Weinelt <hexa@darmstadt.ccc.de>
Co-authored-by: R. Ryantm <ryantm-bot@ryantm.com>
2022-03-24 18:12:59 -05:00
Yaya
665b51e68d nextcloud: 22.2.5 -> 22.2.6, 23.0.2 -> 23.0.3
(cherry picked from commit f578662398)
2022-03-24 22:56:41 +00:00
Maximilian Bosch
aca8c45191 Merge pull request #164569 from Ma27/backport-4.4-removal
[21.11] Linux 4.4 removal
2022-03-24 23:53:10 +01:00
Maximilian Bosch
a0eb776019 Merge pull request #165312 from NixOS/backport-165296-to-release-21.11
[Backport release-21.11] matrix-synapse: 1.54.0 -> 1.55.0
2022-03-24 22:47:00 +01:00
ajs124
cd49b5348c linuxKernel.packages.linux_4_4: drop
(cherry picked from commit 64067cd3c5)
2022-03-24 22:38:58 +01:00
Pavol Rusnak
13815873be Merge pull request #164559 from prusnak/electron-21.11
[21.11] Update Electron
2022-03-24 19:15:28 +01:00
Jörg Thalheim
f2aa493e61 Merge pull request #165575 from NixOS/backport-165548-to-release-21.11
[Backport release-21.11] signal-desktop: 5.35.0 -> 5.36.0
2022-03-24 08:16:58 +00:00
asrar
412eb35981 alloy: add alloy 6
Backport of a18ceb4215 but excluded the alloy4 removal.
2022-03-24 16:04:13 +08:00
Eduardo Quiros
69fbab6bc1 signal-desktop: 5.35.0 -> 5.36.0
(cherry picked from commit 73faeff43e)
2022-03-24 08:04:10 +00:00
github-actions[bot]
85c3e0daf3 Merge staging-next-21.11 into staging-21.11 2022-03-24 00:12:55 +00:00
github-actions[bot]
f487a5ba5c Merge release-21.11 into staging-next-21.11 2022-03-24 00:12:22 +00:00
Pascal Bach
2808809047 Merge pull request #165314 from NixOS/backport-165131-to-release-21.11
[Backport release-21.11] youtube-dl: update youtube.com download throttling patch
2022-03-23 23:58:32 +01:00
Martin Weinelt
7a12a0df58 Merge pull request #165377 from mweinelt/21.11/firefox 2022-03-23 23:33:18 +01:00
Michael Weiss
5f7eedeb61 Merge pull request #165160 from NixOS/backport-165080-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 99.0.4844.74 -> 99.0.4844.82
2022-03-23 23:11:58 +01:00
Michael Weiss
f3844ac47d Merge pull request #165166 from NixOS/backport-165156-to-release-21.11
[Backport release-21.11] chromium: 99.0.4844.74 -> 99.0.4844.82
2022-03-23 23:09:28 +01:00
ajs124
085fb0adbb Merge pull request #165487 from helsinki-systems/backport-164576-to-release-21.11
[21.11] php80: 8.0.16 -> 8.0.17
2022-03-23 20:55:51 +01:00
Pol Dellaiera
b0559e0333 php80: 8.0.16 -> 8.0.17
(cherry picked from commit 1e395cf2e8)
2022-03-23 20:06:07 +01:00
github-actions[bot]
e78d5aae40 keycloak: wrap all the shell scripts (#165478)
Most of these just need JAVA_HOME, but a few assume that java is in PATH

(cherry picked from commit 1449c4e28dc1e6f3a3e1b5683fff4fcbe0c4b0e7)

Co-authored-by: Benjamin Staffin <benley@gmail.com>
2022-03-23 15:01:22 -04:00
Dmitry Kalinkin
a429ffb261 tzdata: fix for darwin sandbox
(cherry picked from commit ccdaaa0788)
2022-03-23 16:51:17 +01:00
Nicolas Benes
54c89ecc12 tzdata: 2021e -> 2022a
(cherry picked from commit 1dad933e18)
2022-03-23 16:18:45 +01:00
Sergei Trofimovich
a111a49a5a tzdata: 2021c -> 2021e (#151446)
(cherry picked from commit f394545b13)
2022-03-23 16:18:41 +01:00
Martin Weinelt
adcc6f5d61 firefox: set consistent remoting name
With Firefox 98.0 the remoting name now depends on the update channel
(mozbz#1752418), which resulted in a weird app_id/wmclass of
`firefox-default`, which broke window association in GNOME and likely
other desktops.

Fixes: #165107
(cherry picked from commit 3ec7f8d487)
2022-03-23 06:35:28 +01:00
Martin Weinelt
a78f0967a9 firefox-bin: 98.0.1 -> 98.0.2
https://www.mozilla.org/en-US/firefox/98.0.2/releasenotes/
(cherry picked from commit 16129972c0)
2022-03-23 06:33:00 +01:00
Martin Weinelt
22fc29d191 firefox: 98.0.1 -> 98.0.2
https://www.mozilla.org/en-US/firefox/98.0.2/releasenotes/
(cherry picked from commit 06518a4991)
2022-03-23 06:32:57 +01:00
Sandro
2ba605d00d Update pkgs/development/libraries/boost/generic.nix
(cherry picked from commit 45adfd577c2fd36e0723968e9e9a448326f2698a)
2022-03-23 02:56:30 +00:00
Markus Wamser
43ca8e8cc3 Format pkgs/development/libraries/boost/generic.nix
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit 53434214801652d93448605dbfefc4bef88d7b33)
2022-03-23 02:56:30 +00:00
Markus S. Wamser
cbfe2fc89b boost: suppress GCC warnings on older versions
(cherry picked from commit c742a5c5375494e85d733c2dd692946998b93479)
2022-03-23 02:56:30 +00:00
github-actions[bot]
fd0c8c871b Merge staging-next-21.11 into staging-21.11 2022-03-23 00:14:01 +00:00
github-actions[bot]
524b7efc01 Merge release-21.11 into staging-next-21.11 2022-03-23 00:13:17 +00:00
Artturi
d2caa93775 Merge pull request #165340 from NixOS/backport-165333-to-release-21.11
[Backport release-21.11] plasma-systemmonitor: add required dependencies
2022-03-23 01:41:49 +02:00
Artturin
fa80524e17 plasma-systemmonitor: add required dependencies
(cherry picked from commit 44d602cc8f)
2022-03-22 23:20:17 +00:00
davidak
707131a51e Merge pull request #165338 from NixOS/backport-165288-to-release-21.11
[Backport release-21.11] isso: 0.12.5 -> 0.12.6.1
2022-03-22 23:41:12 +01:00
Francesco Gazzetta
efb4f3ffab isso: 0.12.5 -> 0.12.6.1
(cherry picked from commit de096b7c83)
2022-03-22 22:11:47 +00:00
Maciej Krüger
f3f1c832e8 Merge pull request #165319 from samuelgrf/yt-dlp-backport-21.11 2022-03-22 21:49:17 +01:00
Sandro Jäckel
f9b4fdbcdb yt-dlp: 2022.2.4 -> 2022.3.8.2, remove hlsEncrypt option, add SuperSandro200 as maintainer
The hlsEncrypt option was removed because it didn't work.

Co-authored-by: Samuel Gräfenstein <s@muel.gr>
2022-03-22 20:39:31 +01:00
Martin Weinelt
1a55a8b0da Merge pull request #164598 from wamserma/openvpn-256-release 2022-03-22 20:17:12 +01:00
zowoq
8dc6e60042 yt-dlp: 2022.2.3 -> 2022.2.4
https://github.com/yt-dlp/yt-dlp/releases/tag/2022.02.04
2022-03-22 20:08:45 +01:00
zowoq
f48dcc5636 yt-dlp: 2022.1.21 -> 2022.2.3
https://github.com/yt-dlp/yt-dlp/releases/tag/2022.02.03
2022-03-22 20:07:58 +01:00
Mauricio Collares
118515deea youtube-dl: update youtube.com download throttling patch
(cherry picked from commit 6c2b751933)
2022-03-22 19:01:19 +00:00
Sumner Evans
0f3bf90535 matrix-synapse: 1.54.0 -> 1.55.0
(cherry picked from commit 9e53370359)
2022-03-22 18:51:25 +00:00
Nicolas Benes
cd6e8501e9 tor-browser-bundle-bin: 11.0.7 -> 11.0.9
(cherry picked from commit 9bffd90af8)
2022-03-22 08:49:21 -07:00
Markus S. Wamser
dfaf1d9541 nixos/tests/quorum: fix by syncing from master, format with alejandra 2022-03-22 08:56:16 +01:00
github-actions[bot]
720db7f2ad Merge staging-next-21.11 into staging-21.11 2022-03-22 00:15:05 +00:00
github-actions[bot]
ed54099ab7 Merge release-21.11 into staging-next-21.11 2022-03-22 00:14:30 +00:00
Jure Varlec
31aa631dbc linuxPackages.rtl88x2bu: switch to the new, maintained repo
The new repo has the same maintainer and is the continuation of the repo
used prior to this commit.

Closes #147053

(cherry picked from commit 31077c9148)
2022-03-21 15:39:15 -07:00
Franz Pletz
6a395040ca libressl: 3.4.2 -> 3.4.3
Fixes CVE-2022-0778.

(cherry picked from commit c201e773c6)
2022-03-21 15:27:58 -07:00
Izorkin
974dc8e0ca libressl: 3.4.1 -> 3.4.2
(cherry picked from commit fac05cccc5)
2022-03-21 15:27:58 -07:00
R. Ryantm
613927b1f2 wasm-pack: 0.10.1 -> 0.10.2
(cherry picked from commit 2b45ece87b)
2022-03-21 15:27:58 -07:00
Robert Scott
64c77a4a22 libressl_3_2: add patch for CVE-2022-0778 2022-03-21 15:27:58 -07:00
Ruud van Asseldonk
d7b634db27 squashfsTools: 4.5 -> 4.5.1
The patch that was previously fetched from GitHub is now part of the
4.5.1 release, and is no longer needed. Furthermore, 4.5.1 introduces
some new scripts to build manpages, and some new build inputs are
required to make that work.

This also rebases the Darwin patch. I don't have a Mac so I can't test
this personally. There was one conflict:

diff --cc squashfs-tools/read_xattrs.c
index 2067f80,b28c3a0..0000000
--- a/squashfs-tools/read_xattrs.c
+++ b/squashfs-tools/read_xattrs.c
@@@ -36,9 -38,7 +38,7 @@@
  #include "xattr.h"
  #include "error.h"

- #include <stdlib.h>
-
 -extern int read_fs_bytes(int, long long, int, void *);
 +extern int read_fs_bytes(int, long long, long long, void *);
  extern int read_block(int, long long, long long *, int, void *);

  static struct hash_entry {

Resolved by updating the signature from int to long long.

(cherry picked from commit ed81545df5)
2022-03-21 15:01:42 -07:00
Robert Scott
ff71169bc4 Merge pull request #164480 from NixOS/backport-164102-to-release-21.11
[Backport release-21.11] apacheHttpd: 2.4.52 -> 2.4.53
2022-03-21 22:00:10 +00:00
Izorkin
d7ee02de18 nixos/tests/peertube: add check peertube cli
(cherry picked from commit a822d0c075)
2022-03-21 14:56:14 -07:00
Izorkin
dab1193562 peertube: 4.1.0 -> 4.1.1
(cherry picked from commit b9c5e1e81a)
2022-03-21 14:56:14 -07:00
hiljusti
49f62325a5 sigi: 3.0.0 -> 3.0.2 2022-03-21 14:51:12 -07:00
techknowlogick
ab6846894a streamlink: 3.1.1 -> 3.2.0
(cherry picked from commit b0439f0bd2)
2022-03-21 14:49:23 -07:00
Martin Weinelt
ae24e825db Merge pull request #165122 from robintown/backport-bpf-unpriv 2022-03-21 22:20:46 +01:00
Michael Weiss
ce6837d010 chromium: 99.0.4844.74 -> 99.0.4844.82
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_20.html
(cherry picked from commit b073d7c10c)
2022-03-21 20:26:04 +00:00
Michael Adler
c6f9f0a20b ungoogled-chromium: 99.0.4844.74 -> 99.0.4844.82
(cherry picked from commit 6d6543e27e)
2022-03-21 19:47:59 +00:00
github-actions[bot]
9eb4e563db nixos/oauth2_proxy: add missing oidc providers (#165000)
- Add adfs and keycloak-oidc providrs
- Sort the list alphabetically

(cherry picked from commit eef56691e374ae4de2c6f3f51feb5c9be895d932)

Co-authored-by: Benjamin Staffin <benley@gmail.com>
2022-03-21 14:38:28 -04:00
Robin Townsend
15dcbc9f79 linux: Enable BPF_UNPRIV_DEFAULT_OFF in 5.15
(cherry picked from commit 3132fcfec3)
2022-03-21 13:07:03 -04:00
Markus S. Wamser
8b488c55a4 nixos/tests/kubernetes: disable rbac.singlenode.test, disable rbac.multinode.test 2022-03-21 16:06:36 +01:00
Alyssa Ross
8441cb8a1f linuxPackages.lttng-modules: 2.13.1 -> 2.13.2
Fixes the build with Linux 5.17.

(cherry picked from commit b3476cce426a4c98488aac3b7d58a32cb82461f1)
2022-03-21 09:22:34 +00:00
github-actions[bot]
a7d49424dd Merge staging-next-21.11 into staging-21.11 2022-03-21 00:13:40 +00:00
github-actions[bot]
8d31cfa489 Merge release-21.11 into staging-next-21.11 2022-03-21 00:13:04 +00:00
Robert Scott
01e87b327a Merge pull request #164966 from wamserma/backport-164804-to-release-21.11
[21.11] wordpress: 5.8.3 -> 5.8.4 (security)
2022-03-20 23:56:23 +00:00
R. Ryantm
fabcb8ee56 cawbird: 1.4.2 -> 1.5
(cherry picked from commit 9b2abc03b2)
2022-03-20 11:09:06 -07:00
Dylan Simon
24dea22304 libwebp: update source hash 2022-03-20 10:58:22 -07:00
Mario Rodas
2eba621001 Merge pull request #164286 from leo60228/backport-tailscale-1.22.1
[21.11] tailscale: 1.20.1 -> 1.22.1
2022-03-20 09:01:06 -05:00
github-actions[bot]
a44485a966 gitlab: 14.8.2 -> 14.8.4 (#164963)
(cherry picked from commit ff554e9fde6e2de056c2ee2b6127f65dfafb0578)

Co-authored-by: Yaya <mak@nyantec.com>
2022-03-20 13:43:44 +01:00
P. R. d. O
a38cc57e95 wordpress: 5.8.3 -> 5.8.4 (security)
Release Notes:
https://wordpress.org/support/wordpress-version/version-5-8-4/#maintenance-updates

(corresponding to f7563d8295)
2022-03-20 13:21:41 +01:00
Markus S. Wamser
936429d6ef openvpn: 2.5.2 -> 2.5.6, 2.4.11 -> 2.4.12 (security, CVE-2022-0547)
Release Notes:
https://github.com/OpenVPN/openvpn/blob/release/2.5/Changes.rst
https://github.com/OpenVPN/openvpn/blob/release/2.4/Changes.rst#version-2412

Fixes: CVE-2022-0547
(cherry picked from commit 448d02ec22)
2022-03-20 12:59:32 +01:00
Maëlys Bras de fer
71c72d612f sdboot-builder: fix crash in exception handling
(cherry picked from commit 529b09a729)
2022-03-20 11:23:32 +01:00
github-actions[bot]
7a03b5df39 Merge staging-next-21.11 into staging-21.11 2022-03-20 00:13:41 +00:00
github-actions[bot]
c8e3264681 Merge release-21.11 into staging-next-21.11 2022-03-20 00:13:09 +00:00
Martin Weinelt
351ffe8621 python3Packages.mypy: relax typed_ast constraint
(cherry picked from commit 8088701061)
2022-03-20 00:59:25 +01:00
Jonathan Ringer
0323abde50 python3Packages.xdist: disable flakey test
(cherry picked from commit 5d63bf250e)
2022-03-20 00:09:00 +01:00
Martin Weinelt
54c22a8bce python3Packages.typed-ast: 1.4.3 -> 1.5.0
(cherry picked from commit ce410eb2e2)
2022-03-20 00:02:49 +01:00
Mario Rodas
f4b037df88 python39Packages.scrapy: 2.5.1 -> 2.6.1
- https://github.com/scrapy/scrapy/releases/tag/2.6.0
- https://github.com/scrapy/scrapy/releases/tag/2.6.1

(cherry picked from commit 759449de75)
2022-03-19 13:33:37 -07:00
Mario Rodas
5600a12976 Merge pull request #164635 from NixOS/backport-164542-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 99.0.4844.51 -> 99.0.4844.74
2022-03-19 14:07:27 -05:00
Mario Rodas
99f926f4a0 Merge pull request #164877 from NixOS/backport-164874-to-release-21.11
[Backport release-21.11] nodejs: 12.22.10 -> 12.22.11, 14.19.0 -> 14.19.1, 16.14.0 -> 16.14.2, 17.5.0 -> 17.7.2
2022-03-19 13:49:27 -05:00
Mario Rodas
fb0c4a4117 nodejs-17_x: 17.5.0 -> 17.7.2
- https://github.com/nodejs/node/releases/tag/v17.6.0
- https://github.com/nodejs/node/releases/tag/v17.7.0
- https://github.com/nodejs/node/releases/tag/v17.7.1
- https://github.com/nodejs/node/releases/tag/v17.7.2

(cherry picked from commit 4265aaa6a0)
2022-03-19 17:57:15 +00:00
Mario Rodas
1bbd049cc1 nodejs-16_x: 16.14.0 -> 16.14.2
- https://github.com/nodejs/node/releases/tag/v16.14.1
- https://github.com/nodejs/node/releases/tag/v16.14.2

(cherry picked from commit 9516465000)
2022-03-19 17:57:15 +00:00
Mario Rodas
67e54f3123 nodejs-14_x: 14.19.0 -> 14.19.1
https://github.com/nodejs/node/releases/tag/v14.19.1
(cherry picked from commit 53f4763fd1)
2022-03-19 17:57:15 +00:00
Mario Rodas
7ceebeb3c5 nodejs-12_x: 12.22.10 -> 12.22.11
https://github.com/nodejs/node/releases/tag/v12.22.11
(cherry picked from commit 527afbfeed)
2022-03-19 17:57:15 +00:00
Mario Rodas
f37ff173d9 Merge pull request #163245 from nicknovitski/backport-159668-to-release-21.11
Backport 159668 to release 21.11
2022-03-19 11:50:49 -05:00
OPNA2608
8d6a498183 libopenmpt: 0.5.11 -> 0.5.17 2022-03-19 15:26:39 +01:00
Stig
86cef3e117 Merge pull request #164658 from risicle/ris-net-ssleay-macos-monterey-r21.11
[21.11] perlPackages.NetSSLeay: add patch fixing build on macos monterey
2022-03-19 15:01:18 +01:00
Ben Wolsieffer
66796ab0e1 nixos/nixos-enter: cleanup resolv.conf handling
(cherry picked from commit 69cff425e6)
2022-03-19 01:13:20 +00:00
Ben Wolsieffer
cb15b200e5 nixos/nixos-enter: fix resolv.conf error handling
(cherry picked from commit 1ee3d9477b)
2022-03-19 01:13:20 +00:00
github-actions[bot]
90d1ef6330 Merge staging-next-21.11 into staging-21.11 2022-03-19 00:12:13 +00:00
github-actions[bot]
cfbb9ba8b0 Merge release-21.11 into staging-next-21.11 2022-03-19 00:11:44 +00:00
Maximilian Bosch
60779b2fde grafana: 8.4.3 -> 8.4.4
ChangeLog: https://github.com/grafana/grafana/releases/tag/v8.4.4
(cherry picked from commit bee12c4c5e)
2022-03-18 10:31:36 -07:00
R. Ryantm
0a8e768277 pirate-get: 0.4.1 -> 0.4.2
(cherry picked from commit e04ef19ff1)
2022-03-18 09:26:45 -07:00
Silvan Mosberger
dcce69b636 nodejs: Fix setup-hook addNodePath quoting
The argument to addNodePath previously wasn't being quoted, leading to
problems when the argument contains characters interpreted specially by
bash

(cherry picked from commit e975c56501)
2022-03-18 15:53:10 +00:00
github-actions[bot]
95988ff1c3 Merge staging-next-21.11 into staging-21.11 2022-03-18 00:13:13 +00:00
github-actions[bot]
47db7ca223 Merge release-21.11 into staging-next-21.11 2022-03-18 00:12:42 +00:00
Martin Weinelt
e150617d31 python310: 3.10.2 -> 3.10.3
https://www.python.org/downloads/release/python-3103/
(cherry picked from commit 5117b2ee8c)
2022-03-18 01:06:55 +01:00
Frederik Rietdijk
5d98664edf python310: 3.10.1 -> 3.10.2
(cherry picked from commit 8dabcce399)
2022-03-18 01:06:29 +01:00
Martin Weinelt
926dd21d76 python310: 3.10.0 -> 3.10.1
(cherry picked from commit 76488857ab)
2022-03-18 01:06:17 +01:00
Martin Weinelt
cf4c666e1c python39: 3.9.10 -> 3.9.11
https://www.python.org/downloads/release/python-3911/
(cherry picked from commit 88deb06a96)
2022-03-18 01:06:00 +01:00
Frederik Rietdijk
d4b75c6125 python39: 3.9.9 -> 3.9.10
(cherry picked from commit 0ffdadc271)
2022-03-18 01:05:55 +01:00
Martin Weinelt
b3dbb94440 python39: 3.9.8 -> 3.9.9
(cherry picked from commit 9512291195)
2022-03-18 01:05:48 +01:00
Martin Weinelt
7f017f1741 python39: 3.9.6 -> 3.9.8
(cherry picked from commit abb6f3efe8)
2022-03-18 01:05:45 +01:00
Martin Weinelt
6044ee594d Merge pull request #164540 from NixOS/backport-164487-to-staging-21.11 2022-03-18 00:46:02 +01:00
Robert Scott
7c8f58ec41 perlPackages.NetSSLeay: add patch fixing build on macos monterey 2022-03-17 23:07:21 +00:00
Michael Adler
34d24c6fc7 ungoogled-chromium: 99.0.4844.51 -> 99.0.4844.74
(cherry picked from commit 7156c46f23)
2022-03-17 20:32:13 +00:00
Michael Weiss
e864fb6110 Merge pull request #164484 from NixOS/backport-164467-to-release-21.11
[Backport release-21.11] chromium: 99.0.4844.51 -> 99.0.4844.74
2022-03-17 21:24:38 +01:00
Martin Weinelt
2c645230e7 bind: 9.16.25 -> 9.16.27
https://downloads.isc.org/isc/bind9/9.16.27/RELEASE-NOTES-bind-9.16.27.html

Fixes: CVE-2021-25220, CVE-2022-0396
2022-03-17 08:52:00 -07:00
Maximilian Bosch
34bcd7c1ea Merge pull request #164553 from Ma27/backport-mautrix-whatsapp
[21.11] mautrix-whatsapp: 0.2.4 -> 0.3.0
2022-03-17 16:09:36 +01:00
TredwellGit
363a7711e0 electron_16: 16.0.10 -> 16.1.0
https://github.com/electron/electron/releases/tag/v16.1.0
(cherry picked from commit 4884f58b7f)
2022-03-17 09:51:27 +01:00
TredwellGit
c605426305 electron_15: 15.4.0 -> 15.4.1
https://github.com/electron/electron/releases/tag/v15.4.1
(cherry picked from commit 1a025227da)
2022-03-17 09:51:09 +01:00
TredwellGit
2604fe94bf electron_14: 14.2.6 -> 14.2.7
https://github.com/electron/electron/releases/tag/v14.2.7
(cherry picked from commit a12aeae118)
2022-03-17 09:51:05 +01:00
Charlotte Van Petegem
23bcc94a43 mautrix-whatsapp: 0.2.4 -> 0.3.0
(cherry picked from commit 6eaadbe4c3)
2022-03-17 09:26:57 +01:00
Martin Weinelt
0b802a8915 python37: 3.7.12 -> 3.7.13
https://www.python.org/downloads/release/python-3713/
(cherry picked from commit 10d1026a1ccd4cf4d4cac5a4922b567ddb9c2a8e)
2022-03-17 06:43:02 +00:00
Martin Weinelt
ae14772c12 python38: 3.8.12 -> 3.8.13
https://www.python.org/downloads/release/python-3813/
(cherry picked from commit 1d03fe5448720d34c9eb7a8ce5774442701d8f4a)
2022-03-17 06:43:02 +00:00
TredwellGit
2c66a7a6e0 Merge pull request #164513 from NixOS/backport-164498-to-release-21.11
[Backport release-21.11] brave: 1.36.112 -> 1.36.116
2022-03-17 04:12:11 +00:00
github-actions[bot]
d2be0e90a1 Merge staging-next-21.11 into staging-21.11 2022-03-17 00:14:07 +00:00
github-actions[bot]
62722e43b1 Merge release-21.11 into staging-next-21.11 2022-03-17 00:13:33 +00:00
TredwellGit
45c6038dfa Merge pull request #164496 from NixOS/backport-164456-to-release-21.11
[Backport release-21.11] Linux kernels 2022-03-16
2022-03-16 23:29:27 +00:00
TredwellGit
04e06dfcc8 brave: 1.36.112 -> 1.36.116
https://github.com/brave/brave-browser/blob/master/CHANGELOG_DESKTOP.md#136116
(cherry picked from commit 6004e84b8b)
2022-03-16 23:18:38 +00:00
TredwellGit
d3a6dc9247 linux_latest-libre: 18627 -> 18635
(cherry picked from commit 39e2856eb6)
2022-03-16 21:04:27 +00:00
TredwellGit
db7fda07e9 linux: 5.4.184 -> 5.4.185
(cherry picked from commit ae3bcac97a)
2022-03-16 21:04:27 +00:00
TredwellGit
1beb3ac701 linux: 5.16.14 -> 5.16.15
(cherry picked from commit 79699f61a2)
2022-03-16 21:04:27 +00:00
TredwellGit
6116b6b75f linux: 5.15.28 -> 5.15.29
(cherry picked from commit 6ddf7b574c)
2022-03-16 21:04:26 +00:00
TredwellGit
936982d328 linux: 5.10.105 -> 5.10.106
(cherry picked from commit 48b578d278)
2022-03-16 21:04:26 +00:00
TredwellGit
6d4c9b1913 linux: 4.9.306 -> 4.9.307
(cherry picked from commit 7ea40efa4d)
2022-03-16 21:04:26 +00:00
TredwellGit
fdee8a83e5 linux: 4.19.234 -> 4.19.235
(cherry picked from commit 111be9fee3)
2022-03-16 21:04:26 +00:00
TredwellGit
b0ac55d449 linux: 4.14.271 -> 4.14.272
(cherry picked from commit 19fe4b6872)
2022-03-16 21:04:26 +00:00
TredwellGit
e6bbf82898 Merge pull request #164459 from NixOS/backport-163723-to-release-21.11
[Backport release-21.11] brave: 1.36.111 -> 1.36.112
2022-03-16 21:02:57 +00:00
Michael Weiss
dacb16be39 chromium: 99.0.4844.51 -> 99.0.4844.74
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_15.html

This update includes 11 security fixes.

CVEs:
CVE-2022-0971 CVE-2022-0972 CVE-2022-0973 CVE-2022-0974 CVE-2022-0975
CVE-2022-0976 CVE-2022-0977 CVE-2022-0978 CVE-2022-0979 CVE-2022-0980

(cherry picked from commit d1f0959dbc)
2022-03-16 19:58:48 +00:00
Martin Weinelt
165cec176d apacheHttpd: 2.4.52 -> 2.4.53
https://downloads.apache.org/httpd/CHANGES_2.4.53

Migrating to pcre2 was recommended in the release notes, since pcre 8.x
is over 20 years old and has now reached its end of life.

Fixes: CVE-2022-23943, CVE-2022-22721, CVE-2022-22720, CVE-2022-22719
(cherry picked from commit 6bf3336975)
2022-03-16 19:37:40 +00:00
R. Ryantm
8065930025 brave: 1.36.111 -> 1.36.112
(cherry picked from commit 5975271884)
2022-03-16 17:13:22 +00:00
Sander van der Burg
e39ef87d05 Merge pull request #164322 from NixOS/backport-164300-to-release-21.11
[Backport release-21.11] Bump DisnixOS version and apply compatibility fixes
2022-03-16 09:19:26 +01:00
Bobby Rong
3604670c03 Merge pull request #163965 from NixOS/backport-163636-to-release-21.11
[Backport release-21.11] vscode: 1.65.1 -> 1.65.2
2022-03-16 15:19:29 +08:00
Jan Tojnar
9cbe73c221 udisks2: Add freedesktop team to maintainers
(cherry picked from commit c0bd9a8b46)
2022-03-16 00:22:51 +00:00
Jan Tojnar
2733c701b1 udisks2: correct patch
This was forgotten during https://github.com/NixOS/nixpkgs/pull/147606

(cherry picked from commit 39f7bd4d69)
2022-03-16 00:22:51 +00:00
github-actions[bot]
417347eec3 Merge staging-next-21.11 into staging-21.11 2022-03-16 00:12:47 +00:00
github-actions[bot]
adfbc4b19c Merge release-21.11 into staging-next-21.11 2022-03-16 00:12:14 +00:00
Sander van der Burg
e2d0740dfc DisnixWebService: compile with OpenJDK8 to retain compatibility with Tomcat 9.x
(cherry picked from commit 4206a9bbba)
2022-03-15 21:21:17 +00:00
Sander van der Burg
bcdca2c55d disnixos: 0.9.2 -> 0.9.3
(cherry picked from commit 216e5571b1)
2022-03-15 21:21:17 +00:00
Sander van der Burg
9d1dc365b6 dysnomia: replace deprecated mysql reference by mariadb
(cherry picked from commit 253ab0296c)
2022-03-15 21:21:16 +00:00
Vladimír Čunát
81f5b97a32 Merge branch 'staging-21.11' into release-21.11
It's very simple change, so let's utilize the fact
that we're rebuilding due to openssl already.
2022-03-15 20:30:39 +01:00
Vladimír Čunát
6f75731bce Merge #164303: openssl*: 1.1.1m -> 1.1.1.n; 3.0.1 -> 3.0.2
...into release-21.11.  High-severity security fixes.
2022-03-15 20:26:45 +01:00
Martin Weinelt
987dd131ff openssl_1_1: 1.1.1m -> 1.1.1n
https://github.com/openssl/openssl/blob/OpenSSL_1_1_1n/CHANGES#L10

Fixes: CVE-2022-0778
(cherry picked from commit 72bb369245)
2022-03-15 20:22:53 +01:00
Martin Weinelt
0ae4e052dc openssl_3_0: 3.0.1 -> 3.0.2
https://github.com/openssl/openssl/blob/openssl-3.0.2/CHANGES.md#changes-between-301-and-302-15-mar-2022

Fixes: CVE-2022-0778
(cherry picked from commit 384a708e6d)
2022-03-15 20:22:50 +01:00
leo60228
52c24b939c tailscale: 1.20.1 -> 1.22.1
Squashed from the following commits:
* tailscale: 1.20.1 -> 1.20.2 (cherry picked from commit
  356869f27d)
* tailscale: 1.20.2 -> 1.20.3 (cherry picked from commit
  8804d87bd3)
* tailscale: 1.20.3 -> 1.20.4 (cherry picked from commit
  8184cdaf46)
* tailscale: 1.20.4 -> 1.22.0 (cherry picked from commit
  280aca1dfb)
* tailscale: 1.22.0 -> 1.22.1 (cherry picked from commit
  a1d44190e9)
2022-03-15 12:15:49 -04:00
Maximilian Bosch
2aca05b38a Merge pull request #164250 from NixOS/backport-164108-to-release-21.11
[Backport release-21.11] wiki-js: 2.5.274 -> 2.5.276
2022-03-15 12:17:27 +01:00
Maximilian Bosch
77e62b8756 wiki-js: 2.5.274 -> 2.5.276
ChangeLog:
* https://github.com/Requarks/wiki/releases/tag/v2.5.275
* https://github.com/Requarks/wiki/releases/tag/v2.5.276

(cherry picked from commit 024abf923b)
2022-03-15 10:52:23 +00:00
Francesco Gazzetta
17bb305adf nheko: 0.9.1 -> 0.9.2
(cherry picked from commit a892724898)
(integrating 7e2fbbfb24 as well)
2022-03-14 22:10:37 -07:00
Sandro
decd6b8527 Update pkgs/applications/virtualization/open-vm-tools/default.nix
(cherry picked from commit 435a197faa52844b1d101c12f1be6214ac8a729f)
2022-03-14 22:05:22 -07:00
Jeremy Kolb
1e717094e1 open-vm-tools: 11.3.5 -> 12.0.0
Switches to fuse3 and applies a patch for array out of bounds

See https://github.com/vmware/open-vm-tools/blob/master/ReleaseNotes.md

(cherry picked from commit ff614973c5889f4308e92d39a8c2f70626d0ec5a)
2022-03-14 22:05:22 -07:00
nixpkgs-upkeep-bot
a3b33742d5 vscodium: 1.65.1 -> 1.65.2
(cherry picked from commit f03b1a937e)
2022-03-14 22:04:08 -07:00
Martin Weinelt
1b930979f1 Merge pull request #164173 from risicle/ris-nats-streaming-server-CVE-2022-26652-r21.11 2022-03-15 02:27:44 +01:00
github-actions[bot]
6972eefd8c Merge staging-next-21.11 into staging-21.11 2022-03-15 00:13:07 +00:00
github-actions[bot]
b03928b82c Merge release-21.11 into staging-next-21.11 2022-03-15 00:12:35 +00:00
Sandro
0a60e89aa1 Merge pull request #163984 from NixOS/backport-155261-to-staging-21.11 2022-03-14 23:40:34 +01:00
Robert Scott
732c0bdf5f nats-streaming-server: add patch for CVE-2022-26652 2022-03-14 22:02:40 +00:00
Martin Weinelt
64fc73bd74 Merge pull request #164137 from NixOS/backport-164126-to-release-21.11 2022-03-14 19:35:37 +01:00
Martin Weinelt
ad9290d902 Merge pull request #164138 from NixOS/backport-164056-to-release-21.11 2022-03-14 19:35:18 +01:00
Jörg Thalheim
6d0a757a89 Merge pull request #164031 from Mic92/nix-eval-jobs
[21.11] nix-eval-jobs: fix build
2022-03-14 17:33:00 +00:00
R. Ryantm
e61f1841f9 firefox-esr-91-unwrapped: 91.7.0esr -> 91.7.1esr
(cherry picked from commit 7f25d6e079)
2022-03-14 17:24:21 +00:00
Martin Weinelt
d6d6772cdf firefox: 98.0 -> 98.0.1
https://www.mozilla.org/en-US/firefox/98.0.1/releasenotes/
(cherry picked from commit 552cfc008a)
2022-03-14 17:24:12 +00:00
Martin Weinelt
a731c9b753 weechat: fix certificate validation with modified gnutls options
Fixes: https://weechat.org/doc/security/WSA-2022-1/
2022-03-14 18:14:58 +01:00
Alyssa Ross
f68de1e2f8 wget: 1.21.2 -> 1.21.3
(cherry picked from commit 1d76c5b669)
2022-03-14 08:50:18 -07:00
Alyssa Ross
7600cacc9b tuxguitar: 1.5.4 -> 1.5.5
Fixes: CVE-2020-14940
(cherry picked from commit ce6c41ac6deecc8e5ae3c2ca8fed8bbf2edd70ea)
2022-03-14 08:21:55 -07:00
Dmitriy
64eee4ce43 obsidian: 0.13.23 -> 0.13.30 (#160469)
(cherry picked from commit 64a0f750db)
2022-03-14 08:15:21 -07:00
Philipp Riegger
5ef04fc42c factorio-experimental: 1.1.53 -> 1.1.56
(cherry picked from commit 90aa1ce3cc)
2022-03-14 08:14:52 -07:00
Charlotte 🦝 Delenk
af74d66442 factorio-*: 1.1.50->1.1.53
(cherry picked from commit 5cfcd0b5b2)
2022-03-14 08:14:52 -07:00
Raito Bezarius
c633677ade factorio-experimental: 1.1.48 -> 1.1.50
(cherry picked from commit c813baeb0f)
2022-03-14 08:14:52 -07:00
Luke Granger-Brown
c93c4f80f4 factorio: 1.1.46 -> 1.1.48
(cherry picked from commit 62363f5e19)
2022-03-14 08:14:52 -07:00
Luke Granger-Brown
312397fc36 factorio-experimental: 1.1.45 -> 1.1.48
(cherry picked from commit 0d0763c951)
2022-03-14 08:14:52 -07:00
Robert Scott
632ec9c8db Merge pull request #164009 from risicle/ris-nats-server-CVE-2022-26652-r21.11
[21.11] nats-server: add patch for CVE-2022-26652
2022-03-14 00:46:29 +00:00
Robert Scott
fcfedc7890 nats-server: add patch for CVE-2022-26652 2022-03-14 00:19:50 +00:00
github-actions[bot]
d81dcd87bd Merge staging-next-21.11 into staging-21.11 2022-03-14 00:13:54 +00:00
github-actions[bot]
0a6e698c33 Merge release-21.11 into staging-next-21.11 2022-03-14 00:13:20 +00:00
Sander van der Burg
9155d7b663 Merge pull request #164041 from svanderburg/fixtomcat-stable
[21.11] nixos/tomcat: configure default group and fix broken default package
2022-03-13 23:00:46 +01:00
Sander van der Burg
b149db13df nixos/tomcat: add basic test case using the example app
(cherry picked from commit 86fafe5f50)
2022-03-13 21:58:34 +01:00
Michael Weiss
6802ac2759 Merge pull request #164035 from NixOS/backport-163529-to-release-21.11
[Backport release-21.11] signal-desktop: 5.34.0 -> 5.35.0
2022-03-13 21:57:32 +01:00
Sander van der Burg
75d79fe1e6 nixos/tomcat: configure default group and fix broken default package reference
Without this fix, evaluating a NixOS configuration with Tomcat enabled and the
default settings results in the following evaluation error:

Failed assertions:
- users.users.tomcat.group is unset. This used to default to
nogroup, but this is unsafe. For example you can create a group
for this user with:
users.users.tomcat.group = "tomcat";
users.groups.tomcat = {};

(cherry picked from commit d12186a601)
2022-03-13 21:56:34 +01:00
Eduardo Quiros
dc703fd947 signal-desktop: 5.34.0 -> 5.35.0
(cherry picked from commit e46bfadd6d)
2022-03-13 19:43:55 +00:00
Jörg Thalheim
1d30e837a6 nix-eval-jobs: fix build 2022-03-13 19:46:37 +01:00
Robert Scott
a39763f726 Merge pull request #163022 from alyssais/cve-2021-4145
[21.11] qemu: fix CVE-2021-4145
2022-03-13 17:38:15 +00:00
Joerie de Gram
1495f6b2cd udisks: move util-linux to buildInputs
This fixes cross compilation.

(cherry picked from commit 9742335d83)
2022-03-13 10:14:22 +00:00
nixpkgs-upkeep-bot
606a397625 vscode: 1.65.1 -> 1.65.2
(cherry picked from commit 2a6d639705)
2022-03-13 06:18:17 +00:00
github-actions[bot]
a567bfc745 Merge staging-next-21.11 into staging-21.11 2022-03-13 00:13:28 +00:00
github-actions[bot]
6e304db159 Merge release-21.11 into staging-next-21.11 2022-03-13 00:12:49 +00:00
Vladimír Čunát
0f85665118 Merge #162184: staging-next: 21.11 iteration 8 2022-03-12 23:03:47 +01:00
Thiago Kenji Okada
679a6cda23 Merge pull request #163899 from NixOS/backport-163504-to-release-21.11
[Backport release-21.11] spidermonkey_91: 91.6.0 -> 91.7.0
2022-03-12 21:36:34 +00:00
Will Young
c679d87f0d spidermonkey_91: 91.6.0 -> 91.7.0
(cherry picked from commit acb148bd32)
2022-03-12 20:56:33 +00:00
Thiago Kenji Okada
ae8dc831c8 Merge pull request #163834 from erikarvstedt/fix-mattermost-on-newer-nix
[NixOS 21.11] nixos/mattermost: fix evaluation with Nix >= 2.6
2022-03-12 20:56:11 +00:00
Thiago Kenji Okada
90802c7833 Merge pull request #163615 from NixOS/backport-162992-to-release-21.11
[Backport release-21.11] minidlna: 1.3.0 -> 1.3.1
2022-03-12 20:48:47 +00:00
Thiago Kenji Okada
eb080a1620 Merge pull request #163800 from NixOS/backport-163454-to-release-21.11
[Backport release-21.11] nixos/doc: update rl-2111 w.r.t. iptables-nft migration
2022-03-12 20:43:23 +00:00
Thiago Kenji Okada
fa389debba Merge pull request #163817 from NixOS/backport-163792-to-release-21.11
[Backport release-21.11] meshcentral: 0.9.79 -> 0.9.98
2022-03-12 20:42:01 +00:00
Thiago Kenji Okada
8c4d3699e0 Merge pull request #163896 from NixOS/backport-163034-to-release-21.11
[Backport release-21.11] signal-desktop: Transfer maintainership
2022-03-12 20:35:42 +00:00
Michael Weiss
4f2cf539a1 signal-desktop: Transfer maintainership
I was actively maintaining the package but stopped using it since the
Ozone/Wayland support broke (e06082eda0 - and I was already migrating
away from Signal anyway).

Mic92 kindly offered to take over and equirosa also offered to become
active again. So it should be in good hands :)
And thank you ixmatus for packaging Signal-Desktop in Nixpkgs.

(cherry picked from commit 52cbeeda30)
2022-03-12 20:06:19 +00:00
Michael Weiss
1feaa242b9 Merge pull request #163889 from NixOS/backport-163054-to-release-21.11
[Backport release-21.11] signal-desktop: 5.33.0 -> 5.34.0
2022-03-12 21:02:37 +01:00
Jörg Thalheim
9572c54168 signal-desktop: 5.33.0 -> 5.34.0
(cherry picked from commit 7d0dde3b3a)
2022-03-12 19:18:47 +00:00
Vladimír Čunát
3fc870f5a9 Merge #162856: looking-glass-client: disable native optimizations
...into release-21.11
2022-03-12 17:14:39 +01:00
Vladimír Čunát
e9e22d296b Merge #163551: thunderbird*: 91.6.2 -> 91.7.0 (into release-21.11) 2022-03-12 17:11:38 +01:00
TredwellGit
e3c697f701 Merge pull request #163809 from NixOS/backport-163782-to-release-21.11
[Backport release-21.11] Linux kernels 2022-03-11
2022-03-12 12:58:12 +00:00
Erik Arvstedt
e1e5358f33 nixos/mattermost: fix evaluation with Nix >= 2.6 2022-03-12 13:28:22 +01:00
R. Ryantm
6b9cad5c4b meshcentral: 0.9.79 -> 0.9.98
(cherry picked from commit 7e64ba9dc8)
2022-03-12 11:09:44 +00:00
Linus Heckemann
dbb9baf720 Merge pull request #163816 from NixOS/backport-158933-to-release-21.11
[Backport release-21.11] meshcentral: 0.9.59 -> 0.9.79
2022-03-12 12:04:24 +01:00
R. Ryantm
3c11197638 meshcentral: 0.9.59 -> 0.9.79
(cherry picked from commit 15a8db204eb6145fd3abd2ce92762bcac4d1e5e0)
2022-03-12 10:57:32 +00:00
TredwellGit
4c86c8404c linux_latest-libre: 18613 -> 18627
(cherry picked from commit 75db629894)
2022-03-12 10:15:38 +00:00
TredwellGit
f2e28b00ed linux-rt_5_4: 5.4.182-rt70 -> 5.4.182-rt71
(cherry picked from commit 4bf71faa06)
2022-03-12 10:15:38 +00:00
TredwellGit
ecc1aa4c50 linux-rt_5_10: 5.10.100-rt62 -> 5.10.104-rt63
(cherry picked from commit 3d1e0b2e17)
2022-03-12 10:15:38 +00:00
TredwellGit
db8e8276a9 linux: 5.4.183 -> 5.4.184
(cherry picked from commit c01eed31ba)
2022-03-12 10:15:38 +00:00
TredwellGit
5ec2ee2d51 linux: 5.16.13 -> 5.16.14
(cherry picked from commit 51d907345a)
2022-03-12 10:15:38 +00:00
TredwellGit
e6af67fd6e linux: 5.15.27 -> 5.15.28
(cherry picked from commit eafbf22558)
2022-03-12 10:15:38 +00:00
TredwellGit
228772d51d linux: 5.10.104 -> 5.10.105
(cherry picked from commit a9e63526e2)
2022-03-12 10:15:38 +00:00
TredwellGit
2ad05eb997 linux: 4.9.305 -> 4.9.306
(cherry picked from commit 5de1f9ac31)
2022-03-12 10:15:38 +00:00
TredwellGit
c4baac8cb8 linux: 4.19.233 -> 4.19.234
(cherry picked from commit 3d434fc0d9)
2022-03-12 10:15:38 +00:00
TredwellGit
b5104c476a linux: 4.14.270 -> 4.14.271
(cherry picked from commit ceafc68dce)
2022-03-12 10:15:38 +00:00
Florian Klink
03dab6bae4 nixos/doc: update rl-2111 w.r.t. iptables-nft migration
Follow-up on https://github.com/NixOS/nixpkgs/pull/161426.

Explain why having legacy iptables rules installed can lead to confusing
firewall behaviour, and provide some guidance on how to fix this.

(cherry picked from commit 788abdba4b)
2022-03-12 09:22:13 +00:00
github-actions[bot]
a42ec2a776 Merge staging-next-21.11 into staging-21.11 2022-03-12 00:12:32 +00:00
github-actions[bot]
9079661c38 Merge release-21.11 into staging-next-21.11 2022-03-12 00:11:54 +00:00
Nicolas Benes
f4a235894d tor-browser-bundle-bin: 11.0.6 -> 11.0.7
(cherry picked from commit 291dcf35ae)
2022-03-11 09:05:20 -08:00
adisbladis
6af668d26c zfs: 2.1.2 -> 2.1.3
(cherry picked from commit f445a7668c)
2022-03-11 09:03:09 -08:00
Eduard Bachmakov
b6942ccf8a marktext: 0.16.3 -> 0.17.1
Add myself to maintainers.

(cherry picked from commit aed984807a)
2022-03-11 09:01:10 -08:00
TredwellGit
4d051c3e6d Merge pull request #163382 from NixOS/backport-163367-to-release-21.11
[Backport release-21.11] Linux kernels 2022-03-08
2022-03-11 07:54:22 +00:00
github-actions[bot]
6a8a3cbfd4 Merge staging-next-21.11 into staging-21.11 2022-03-11 00:14:22 +00:00
github-actions[bot]
a30210eb16 Merge release-21.11 into staging-next-21.11 2022-03-11 00:13:49 +00:00
Sander van der Burg
021efecf96 Merge pull request #163627 from NixOS/backport-163606-to-release-21.11
[Backport release-21.11] Bump Disnix to 0.10.2
2022-03-11 00:03:19 +01:00
Sander van der Burg
3edc941330 disnixos: 0.9.1 -> 0.9.2
(cherry picked from commit edbf04d5b2)
2022-03-10 22:28:28 +00:00
Sander van der Burg
1b9580f4aa disnix: 0.10.1 -> 0.10.2
(cherry picked from commit 836bfe371d)
2022-03-10 22:28:28 +00:00
Robert Scott
e790118788 nixosTests.minidlna: fix by performing requests by IP
a little ugly, but minidlna now checks requests Host: header and
only accepts requests using an IPv4 address to avoid DNS-rebinding
attacks.

(cherry picked from commit 97572a798c)
2022-03-10 21:39:12 +00:00
Martin Weinelt
91065b2884 minidlna: add passthrough test
(cherry picked from commit d5633c504f)
2022-03-10 21:39:12 +00:00
Martin Weinelt
809215c6fa minidlna: 1.3.0 -> 1.3.1
Prevents DNS rebinding attacks through malicious remote web servers.

https://www.openwall.com/lists/oss-security/2022/03/03/1

Fixes: CVE-2022-26505
(cherry picked from commit a63d445772)
2022-03-10 21:39:12 +00:00
Kim Lindberger
bacbfd713b Merge pull request #163195 from NixOS/backport-162095-to-release-21.11
[Backport release-21.11] nixos/keycloak: fix database provisioning issues
2022-03-10 18:27:18 +01:00
R. Ryantm
5aa911fb69 brave: 1.36.109 -> 1.36.111
(cherry picked from commit 49b033388b)
2022-03-10 08:52:10 -08:00
nixpkgs-upkeep-bot
ab4402cdab vscode: 1.65.0 -> 1.65.1
(cherry picked from commit 6befb128a0)
2022-03-10 08:51:49 -08:00
nixpkgs-upkeep-bot
66f46c3be7 vscodium: 1.65.0 -> 1.65.1
(cherry picked from commit 73d797b751)
2022-03-10 08:51:37 -08:00
Thomas Tuegel
4e5bf8730e Merge pull request #163446 from ttuegel/knewstuff-21.11
Backport KNewStuff/Discover cache expiration patches
2022-03-10 05:58:19 -06:00
taku0
1018577384 thunderbird: 91.6.2 -> 91.7.0
(cherry picked from commit 5364044fd7bfd55aea4212b87bd662b429f72ffb)
2022-03-10 10:55:22 +00:00
taku0
37ca5c7254 thunderbird-bin: 91.6.2 -> 91.7.0
(cherry picked from commit 0284145d08c987356c43f4629a5d3fd0fc08d398)
2022-03-10 10:55:22 +00:00
Yaya
f5ed345047 [Backport release-21.11] gitlab: 14.7.4 -> 14.8.2 (#162237)
(cherry picked from commit 09abb37955ca992608cc32732f9a837d87cbda20)
2022-03-10 09:08:59 +01:00
github-actions[bot]
3cbca1535e Merge staging-next-21.11 into staging-21.11 2022-03-10 00:13:41 +00:00
github-actions[bot]
c3a0bd0615 Merge release-21.11 into staging-next-21.11 2022-03-10 00:12:29 +00:00
Zhaofeng Li
d1c6012617 colmena: 0.2.1 -> 0.2.2
(cherry picked from commit a3ccb2105b)
2022-03-09 15:24:40 -08:00
Martin Weinelt
d59edd3833 Merge pull request #163350 from NixOS/backport-163344-to-release-21.11 2022-03-09 17:40:10 +01:00
Thomas Tuegel
167d687b6c discover: Backport cache expiry patch 2022-03-09 07:42:51 -06:00
Thomas Tuegel
b71f1694b9 knewstuff: Backport cache expiration patches 2022-03-09 07:42:50 -06:00
Martin Weinelt
b99542dff8 Merge pull request #163381 from NixOS/backport-163197-to-release-21.11 2022-03-09 12:43:45 +01:00
Vladimír Čunát
056010084e Merge #163369: firefox-bin: 97.0.2 -> 98.0
Also firefox-esr: 91.6.1esr -> 91.7.0esr
(but not plain `firefox`)
...into release-21.11
2022-03-09 09:03:57 +01:00
github-actions[bot]
dc83e705dc Merge staging-next-21.11 into staging-21.11 2022-03-09 00:13:02 +00:00
github-actions[bot]
59f830518e Merge release-21.11 into staging-next-21.11 2022-03-09 00:12:16 +00:00
TredwellGit
292e20c6a6 linux-rt_5_4: 5.4.177-rt69 -> 5.4.182-rt70
(cherry picked from commit 109f094395)
2022-03-08 22:03:24 +00:00
TredwellGit
b73057013f linux: 5.4.182 -> 5.4.183
(cherry picked from commit eff61b45d0)
2022-03-08 22:03:24 +00:00
TredwellGit
efbe226118 linux: 5.16.12 -> 5.16.13
(cherry picked from commit d7d0cf60f9)
2022-03-08 22:03:24 +00:00
TredwellGit
920a6bda1b linux: 5.15.26 -> 5.15.27
(cherry picked from commit 639fd7c52a)
2022-03-08 22:03:24 +00:00
TredwellGit
867d3db483 linux: 5.10.103 -> 5.10.104
(cherry picked from commit d095019a82)
2022-03-08 22:03:24 +00:00
TredwellGit
312752ac5a linux: 4.9.304 -> 4.9.305
(cherry picked from commit f22e8f94cf)
2022-03-08 22:03:24 +00:00
TredwellGit
1a7ea923ba linux: 4.19.232 -> 4.19.233
(cherry picked from commit ba5cca9c79)
2022-03-08 22:03:24 +00:00
TredwellGit
6ef078183d linux: 4.14.269 -> 4.14.270
(cherry picked from commit e2aab2e9fd)
2022-03-08 22:03:24 +00:00
Martin Weinelt
e38daf4e66 firefox: 97.0.2 -> 98.0
https://www.mozilla.org/en-US/firefox/98.0/releasenotes/
(cherry picked from commit 7e5b346bd4)
2022-03-08 21:48:26 +00:00
Martin Weinelt
6996ec574c firefox: prune maintainer list
(cherry picked from commit 0b59e7976a)
2022-03-08 20:02:12 +00:00
Martin Weinelt
f963ae98de firefox-esr: 91.6.1esr -> 91.7.0esr
https://www.mozilla.org/en-US/firefox/91.7.0/releasenotes/
(cherry picked from commit 3c0a13d2d5)
2022-03-08 20:02:12 +00:00
Martin Weinelt
27089599b9 firefox-bin: 97.0.2 -> 98.0
https://www.mozilla.org/en-US/firefox/98.0/releasenotes/
(cherry picked from commit 657b329f83)
2022-03-08 20:02:12 +00:00
Alyssa Ross
f53c984ce9 waybar: 0.9.9 -> 0.9.10
(cherry picked from commit f64ee7de7a)
2022-03-08 11:12:59 -08:00
Martin Weinelt
5de3fc92f6 nixos/matrix-synapse: drop webclient references, removed in 1.53.0 2022-03-08 20:08:23 +01:00
Sumner Evans
4fb792c527 matrix-synapse: 1.53.0 -> 1.54.0
(cherry picked from commit 422ce80e9a)
2022-03-08 16:45:10 +00:00
Sumner Evans
428244bc34 element-{desktop,}: 1.10.4 -> 1.10.6
(cherry picked from commit 0d64fcc14e)
2022-03-08 08:01:13 -08:00
Robert Hensing
a0852c0af5 nixos/nix-daemon: Ensure continued availability of daemon socket
As `nix-daemon.service` does not make use of `ExecStop`, we prefer
to keep the socket up and available. This is important for machines
that run Nix-based services, such as automated build, test, and deploy
services, that expect the daemon socket to be available at all times.

See committed inline comment for further explanation.

(cherry picked from commit b550b4b6f8)
2022-03-08 07:42:10 -08:00
Janne Heß
9a923886e4 Merge pull request #163334 from NixOS/backport-163328-to-release-21.11
[Backport release-21.11] icingaweb2: 2.9.5 -> 2.9.6
2022-03-08 16:00:26 +01:00
Janne Heß
7943ea371b icingaweb2: 2.9.5 -> 2.9.6
(cherry picked from commit 3bea94f0f8)
2022-03-08 14:34:36 +00:00
Izorkin
c3dc2e2c07 nginxModules: add option disableIPC
The disableIPC option is required to checking enabled nginxModules
and disable the SystemCallFilter IPC filter.

(cherry picked from commit b672e4dd2c)
2022-03-08 16:12:49 +03:00
Izorkin
58040d58ae nixos/nginx: tengine requires allowing @ipc calls
(cherry picked from commit 7376f4e34f)
2022-03-08 16:11:47 +03:00
Mario Rodas
4c5a60a38a nodejs-17_x: 17.4.0 -> 17.5.0
https://github.com/nodejs/node/releases/tag/v17.5.0
(cherry picked from commit ec4b194eef)
2022-03-07 16:52:54 -08:00
Mario Rodas
500f78957a nodejs-16_x: 16.13.2 -> 16.14.0
https://github.com/nodejs/node/releases/tag/v16.14.0
(cherry picked from commit 28e31514a7)
2022-03-07 16:52:03 -08:00
Mario Rodas
0932142903 nodejs-14_x: 14.18.3 -> 14.19.0
https://github.com/nodejs/node/releases/tag/v14.19.0
(cherry picked from commit 680824ed2e)
2022-03-07 16:52:02 -08:00
Mario Rodas
e8292cb6b7 nodejs-12_x: 12.22.9 -> 12.22.10
https://github.com/nodejs/node/releases/tag/v12.22.10
(cherry picked from commit 8620427158)
2022-03-07 16:52:02 -08:00
github-actions[bot]
b51de988c3 Merge staging-next-21.11 into staging-21.11 2022-03-08 00:12:26 +00:00
github-actions[bot]
47c40acd22 Merge release-21.11 into staging-next-21.11 2022-03-08 00:11:50 +00:00
midchildan
1e3754b780 nixosTests.keycloak: replace libtidy with html-tidy
Follow-up of cc700ad55b.

(cherry picked from commit 0334498c74)
2022-03-07 19:18:42 +00:00
midchildan
1d4bfc6195 nixos/keycloak: fix database provisioning issues
This fixes the following issues with the database provisioning script
included in the services.keycloak module:

- It lacked permission to access the DB password file specified in the
  module option 'services.keycloak.database.passwordFile'.

- It prevented Keycloak from starting after the second time if the user
  chose MySQL for the database.

(cherry picked from commit dc5bd4b375)
2022-03-07 19:18:42 +00:00
Maciej Krüger
9b1c7ba323 Merge pull request #163190 from NixOS/backport-157438-to-release-21.11 2022-03-07 18:58:33 +01:00
Simon Bruder
e73cf5cf68 nixos/nitter: add package option
(cherry picked from commit be636c6c96)
2022-03-07 17:55:20 +00:00
Sandro
8ee7335de9 Update pkgs/applications/networking/browsers/vivaldi/default.nix
(cherry picked from commit 99a3b2b5cf8383e17812220c300617cfd5dce5f1)
2022-03-07 09:27:46 -08:00
Steven Kou
14b42183f3 vivaldi: add libpulseaudio as optional dependency
(cherry picked from commit 87821aed1c6e1368cc9f3bab72ed5adfb0d4ab4a)
2022-03-07 09:27:46 -08:00
Alyssa Ross
e99e859ba7 tor: 0.4.6.9 -> 0.4.6.10
(cherry picked from commit 742424ccf6)
2022-03-07 17:14:52 +00:00
Alyssa Ross
5e749bd7dd tor.updateScript: update verification/signing keys
Upstream no longers signs the tarball directly; instead they sign the
sha256sum file[1].  Also, the signing keys have changed, and the
latest release is signed with a key we didn't have before.

[1]: dd17604bb3

(cherry picked from commit 9307a4d328)
2022-03-07 17:14:52 +00:00
Anderson Torres
2f1649c6b2 Merge pull request #163167 from NixOS/backport-160251-to-release-21.11
[Backport release-21.11] distrobox: init at 1.2.13
2022-03-07 14:09:28 -03:00
Átila Saraiva
20f7a6e9ac distrobox: init at 1.2.13
(cherry picked from commit c2fc98a4aa)
2022-03-07 15:47:47 +00:00
Vladimír Čunát
17ee68bc36 Merge #163049: thunderbird*: 91.6.1 -> 91.6.2 (into release-21.11) 2022-03-07 12:13:00 +01:00
Bobby Rong
3e53230d49 Merge pull request #162258 from NixOS/backport-161974-to-release-21.11
[Backport release-21.11] remote-touchpad: 1.1.0 -> 1.2.0
2022-03-07 16:42:50 +08:00
Bobby Rong
ad69f91486 Merge pull request #162198 from wamserma/release-21.11-bierner
[21.11] vscode-extensions.bierner.{emojisense, markdown-emoji, markdown-checkbox}: init
2022-03-07 16:40:32 +08:00
Bobby Rong
6f80a5e8ec Merge pull request #163072 from NixOS/backport-162638-to-release-21.11
[Backport release-21.11] qrcp: 0.8.4 -> 0.8.5
2022-03-07 10:10:01 +08:00
github-actions[bot]
f78c5c44b0 Merge staging-next-21.11 into staging-21.11 2022-03-07 00:13:18 +00:00
github-actions[bot]
e7de038941 Merge release-21.11 into staging-next-21.11 2022-03-07 00:12:42 +00:00
Francesco Gazzetta
71b0e10c80 qrcp: 0.8.4 -> 0.8.5
(cherry picked from commit ad87eff3af)
2022-03-06 22:13:27 +00:00
Jörg Thalheim
59ee4cee79 Merge pull request #163059 from NixOS/backport-159611-to-release-21.11
[Backport release-21.11] nix-build-uncached: 1.1.0 -> 1.1.1
2022-03-06 20:39:39 +00:00
R. Ryantm
12cfef4969 nix-build-uncached: 1.1.0 -> 1.1.1
(cherry picked from commit e51bb574bb)
2022-03-06 20:36:09 +00:00
taku0
020ace9163 thunderbird: 91.6.1 -> 91.6.2
(cherry picked from commit 93aeade556)
2022-03-06 19:14:16 +00:00
taku0
e7d58ee850 thunderbird-bin: 91.6.1 -> 91.6.2
(cherry picked from commit e08090e479)
2022-03-06 19:14:16 +00:00
Renaud
2ebb6c1e5a Merge pull request #162896 from c0bw3b/backport/i2pd
[21.11] i2pd: 2.39.0 -> 2.41.0
2022-03-06 18:37:36 +01:00
Alyssa Ross
b5f883a326 qemu: fix CVE-2021-4145
Fixes: https://github.com/NixOS/nixpkgs/issues/160707
2022-03-06 15:34:05 +00:00
Alyssa Ross
c15df73786 qemu: 6.1.0 -> 6.1.1
Fixes: https://github.com/NixOS/nixpkgs/pull/161345 ("[21.11] qemu: add patch for fixing IO errors")
2022-03-06 14:32:16 +00:00
Robert Scott
ecba7cdaed qemu: fixup basic tests, enable in passthru.tests
these may not be reliable enough to enable by default, but enabling
them as a passthru may allow us to get a feel for which platforms
have trouble with them

(cherry picked from commit 5adc3817a0)
2022-03-06 13:03:03 +00:00
Michael Weiss
e60613a04e Merge pull request #162994 from NixOS/backport-162926-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 98.0.4758.102 -> 99.0.4844.51
2022-03-06 14:00:52 +01:00
Michael Weiss
f9bd91a930 ungoogled-chromium: 98.0.4758.102 -> 99.0.4844.51
(cherry picked from commit 16fbf26530)
2022-03-06 11:23:00 +00:00
tomberek
c00e157a8f Merge pull request #162843 from NixOS/backport-162544-to-release-21.11
[Backport release-21.11] brave: 1.35.103 -> 1.36.109
2022-03-06 02:56:37 -05:00
github-actions[bot]
3bdc348d03 Merge staging-next-21.11 into staging-21.11 2022-03-06 00:13:32 +00:00
github-actions[bot]
574bd9bb7e Merge release-21.11 into staging-next-21.11 2022-03-06 00:12:56 +00:00
tomberek
2c34ff3843 Merge pull request #160350 from LeSuisse/mysql80-8.0.28-21.11
[21.11] mysql80: 8.0.26 -> 8.0.28
2022-03-05 15:31:44 -05:00
Martin Weinelt
b29586bb1c Merge pull request #161897 from risicle/ris-wolfssl-CVE-2022-25638-CVE-2022-25640-r21.11 2022-03-05 20:17:38 +01:00
tomberek
aa16d40b19 Merge pull request #157401 from LeSuisse/mysql57-5.7.37-21.11
[21.11] mysql57: 5.7.27 -> 5.7.37
2022-03-05 14:17:09 -05:00
Martin Weinelt
41f102cbf1 Merge pull request #162899 from NixOS/backport-162787-to-release-21.11 2022-03-05 16:48:57 +01:00
Martin Weinelt
477efc10eb kea: 2.0.1 -> 2.0.2
https://downloads.isc.org/isc/kea/2.0.2/Kea-2.0.2-ReleaseNotes.txt
(cherry picked from commit 5bf2471bb0)
2022-03-05 14:37:43 +00:00
R. Ryantm
ed422d5ce3 i2pd: 2.40.0 -> 2.41.0
(cherry picked from commit 626d04ffb0)
2022-03-05 15:26:58 +01:00
Luflosi
f3b46c374a i2pd: install systemd service file and man page
The systemd service file could be useful in the future for use in the i2pd NixOS module.

(cherry picked from commit 577d4ef239)
2022-03-05 15:26:42 +01:00
R. Ryantm
96510a9e47 i2pd: 2.39.0 -> 2.40.0
(cherry picked from commit 0f2fb3b302)
2022-03-05 15:26:05 +01:00
Renaud
b40fbc1f11 Merge pull request #162412 from NixOS/backport-153920-to-release-21.11
[Backport release-21.11] geckodriver: 0.29.1 -> 0.30.0
2022-03-05 14:54:03 +01:00
Vladimír Čunát
23327899e0 Merge #162861: firefox*: patch-level updates (security)
...into release-21.11
2022-03-05 14:33:47 +01:00
Maximilian Bosch
b3f36fe93d Merge pull request #162879 from NixOS/backport-162637-to-release-21.11
[Backport release-21.11] grafana: 8.4.2 -> 8.4.3
2022-03-05 13:23:54 +01:00
Maximilian Bosch
ef429cbbbf grafana: 8.4.2 -> 8.4.3
ChangeLog: https://github.com/grafana/grafana/releases/tag/v8.4.3
(cherry picked from commit a7b6e8bc6e)
2022-03-05 11:50:38 +00:00
Maximilian Bosch
c5fa828399 Merge pull request #162818 from NixOS/backport-162481-to-release-21.11
[Backport release-21.11] Linux kernels 2022-03-03
2022-03-05 12:46:14 +01:00
Martin Weinelt
36e9ee4885 firefox-esr: 91.6.0esr -> 91.6.1esr
https://www.mozilla.org/en-US/firefox/91.6.1/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-09/

Fixes: CVE-2022-26485, CVE-2022-26486
(cherry picked from commit b2f3e4165e)
2022-03-05 08:07:57 +00:00
Martin Weinelt
e954f7e69f firefox-bin: 97.0.1 -> 97.0.2
https://www.mozilla.org/en-US/firefox/97.0.2/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-09/

Fixes: CVE-2022-26485, CVE-2022-26486
(cherry picked from commit 83bcfbbb70)
2022-03-05 08:07:57 +00:00
Martin Weinelt
d06aef3c33 firefox: 97.0.1 -> 97.0.2
https://www.mozilla.org/en-US/firefox/97.0.2/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-09/

Fixes: CVE-2022-26485, CVE-2022-26486
(cherry picked from commit 2dea8d9145)
2022-03-05 08:07:57 +00:00
Vladimír Čunát
784be11259 Revert "python3Packages.xmltodict: disable incompatible expat tests"
This reverts commit 5b8af8ce590df0a81; or cherry-picks c18eab5a31.
2022-03-05 08:21:04 +01:00
Vladimír Čunát
b80b398c16 expat: 2.4.6 -> 2.4.7
This primarily fixes regressions in various other packages
after the expat security fixes.

(cherry picked from commit 48a007306b)
2022-03-05 08:20:39 +01:00
Babbaj
8189171d02 looking-glass-client: disable native optimizations
(cherry picked from commit 2d6fa5a0ec)
2022-03-05 06:56:14 +00:00
TredwellGit
03bb519e4c brave: 1.35.103 -> 1.36.109
https://github.com/brave/brave-browser/blob/master/CHANGELOG_DESKTOP.md#136109
(cherry picked from commit 7276b95fe4)
2022-03-05 03:07:14 +00:00
github-actions[bot]
7ab0e54e5f Merge staging-next-21.11 into staging-21.11 2022-03-05 00:12:54 +00:00
github-actions[bot]
1a590695e9 Merge release-21.11 into staging-next-21.11 2022-03-05 00:12:13 +00:00
TredwellGit
35cd7bf905 linux/hardened/patches/5.4: 5.4.180-hardened1 -> 5.4.182-hardened1
(cherry picked from commit 4556ebf12d)
2022-03-04 21:36:22 +00:00
TredwellGit
f5ef6d5c5b linux/hardened/patches/5.15: 5.15.24-hardened1 -> 5.15.26-hardened1
(cherry picked from commit d7697b5795)
2022-03-04 21:36:22 +00:00
TredwellGit
595990a213 linux/hardened/patches/5.10: 5.10.101-hardened1 -> 5.10.103-hardened1
(cherry picked from commit aa3c676b11)
2022-03-04 21:36:22 +00:00
TredwellGit
a9694081f6 linux/hardened/patches/4.19: 4.19.230-hardened1 -> 4.19.232-hardened1
(cherry picked from commit aff940fa49)
2022-03-04 21:36:22 +00:00
TredwellGit
01bdc277d3 linux/hardened/patches/4.14: 4.14.267-hardened1 -> 4.14.269-hardened1
(cherry picked from commit 481665d3b4)
2022-03-04 21:36:22 +00:00
TredwellGit
a7ee564b0f linux: 5.4.181 -> 5.4.182
(cherry picked from commit ab27204ab6)
2022-03-04 21:36:22 +00:00
TredwellGit
4299760445 linux: 5.16.11 -> 5.16.12
(cherry picked from commit b61740b76d)
2022-03-04 21:36:22 +00:00
TredwellGit
9944db76db linux: 5.15.25 -> 5.15.26
(cherry picked from commit e802ed8656)
2022-03-04 21:36:22 +00:00
TredwellGit
4c05982cfd linux: 5.10.102 -> 5.10.103
(cherry picked from commit 04ffdc56f5)
2022-03-04 21:36:22 +00:00
TredwellGit
d5e9a89cb6 linux: 4.9.303 -> 4.9.304
(cherry picked from commit 480bf9b1da)
2022-03-04 21:36:21 +00:00
TredwellGit
151494d576 linux: 4.19.231 -> 4.19.232
(cherry picked from commit ad2c5846d3)
2022-03-04 21:36:21 +00:00
TredwellGit
b6cbabe0c6 linux: 4.14.268 -> 4.14.269
(cherry picked from commit d9dc2d6547)
2022-03-04 21:36:21 +00:00
R. Ryantm
c78fc23f10 cmark-gfm: 0.29.0.gfm.2 -> 0.29.0.gfm.3
(cherry picked from commit 6874a12a72)
2022-03-04 09:47:32 -08:00
nixpkgs-upkeep-bot
dc36549694 vscode: 1.64.2 -> 1.65.0
(cherry picked from commit d9a87bf933)
2022-03-04 09:14:56 -08:00
nixpkgs-upkeep-bot
2a51d1ba65 vscodium: 1.64.2 -> 1.65.0
(cherry picked from commit ba21f946e3)
2022-03-04 09:14:48 -08:00
Léo Gaspard
47cd670293 super-productivity: update electron to version 13, as 11 is EOL 2022-03-04 16:09:08 +01:00
Brian Leung
45683ebfdb macvim: 8.2.1719 -> 8.2.3455
(cherry picked from commit e5307bdda5)
2022-03-04 11:22:19 +00:00
Artturin
0fc9d50c31 discord-canary: 0.0.133 -> 0.0.134
(cherry picked from commit d50924f33b)
2022-03-03 17:47:37 -08:00
github-actions[bot]
315e5d21f7 Merge staging-next-21.11 into staging-21.11 2022-03-04 00:14:36 +00:00
github-actions[bot]
b5b8b76c30 Merge release-21.11 into staging-next-21.11 2022-03-04 00:14:00 +00:00
Michael Weiss
7a6f7df2e4 Merge pull request #162534 from NixOS/backport-162417-to-release-21.11
[Backport release-21.11] chromium: 98.0.4758.102 -> 99.0.4844.51
2022-03-03 22:28:13 +01:00
Artturi
c230579e89 Merge pull request #162669 from NixOS/backport-160159-to-release-21.11 2022-03-03 23:06:57 +02:00
Dmitriy
80c0bc2be8 discord-ptb: 0.0.27 -> 0.0.29
(cherry picked from commit aaa34c96d0)
2022-03-03 20:47:51 +00:00
Michael Weiss
4e95b7ba65 Merge pull request #162543 from NixOS/backport-161866-to-release-21.11
[Backport release-21.11] signal-desktop: 5.31.1 -> 5.33.0
2022-03-03 21:32:48 +01:00
Bobby Rong
ba8466b6f9 Merge pull request #161642 from bobby285271/pantheon-stable
[21.11] Pantheon 6.1 backports 2022-02-24
2022-03-03 22:10:39 +08:00
Bobby Rong
cc8e6fffe0 pantheon.elementary-greeter: 6.0.1 -> 6.0.2
(cherry picked from commit 4646e7f59c)
2022-03-03 21:04:00 +08:00
Bobby Rong
35bedf2f89 pantheon.elementary-greeter: actually fix the crash
Fixed a use-after-free issue where logged_in_context is used in update_style().
There are several reports for this but upstream has no action for this so far during the 6.x cycle.
See the provided link for more details.

(cherry picked from commit f29955df81)

Note: the above is the original commit message, the patch has been accepted on upstream.
2022-03-03 21:04:00 +08:00
Bobby Rong
d9e512f743 Revert "pantheon.elementary-greeter: add patch for revert pull request 566"
This reverts commit 34d5d14fd0.

(cherry picked from commit 2a376bb3da)
2022-03-03 21:04:00 +08:00
Bobby Rong
9e6b95b105 pantheon.elementary-photos: 2.7.3 -> 2.7.4
(cherry picked from commit be1e44b7d2)
2022-03-03 21:03:59 +08:00
Bobby Rong
4d2e15d120 nixos/pantheon: stop setting GTK_CSD=1
See https://github.com/elementary/gala/issues/244

(cherry picked from commit ede5fff929)
2022-03-03 21:03:56 +08:00
github-actions[bot]
8da31b5650 Merge staging-next-21.11 into staging-21.11 2022-03-03 00:38:11 +00:00
github-actions[bot]
953bfe5f8b Merge release-21.11 into staging-next-21.11 2022-03-03 00:31:48 +00:00
Michael Weiss
910d2eb4a2 signal-desktop: 5.32.0 -> 5.33.0
(cherry picked from commit 6faf5f22a8)
2022-03-02 22:04:38 +00:00
R. Ryantm
2fd6c33a9e signal-desktop: 5.31.1 -> 5.32.0
(cherry picked from commit 9e6e31f193)
2022-03-02 22:04:38 +00:00
Michael Weiss
ed02c2ba03 Merge pull request #162533 from primeos/backports/signal-desktop
[21.11] signal-desktop: 5.30.0 -> 5.31.1
2022-03-02 22:59:53 +01:00
Michael Weiss
e428b6c368 chromium: 98.0.4758.102 -> 99.0.4844.51
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop.html

This update includes 28 security fixes.

CVEs:
CVE-2022-0789 CVE-2022-0790 CVE-2022-0791 CVE-2022-0792 CVE-2022-0793
CVE-2022-0794 CVE-2022-0795 CVE-2022-0796 CVE-2022-0797 CVE-2022-0798
CVE-2022-0799 CVE-2022-0800 CVE-2022-0801 CVE-2022-0802 CVE-2022-0803
CVE-2022-0804 CVE-2022-0805 CVE-2022-0806 CVE-2022-0807 CVE-2022-0808
CVE-2022-0809

(cherry picked from commit cb0ed4703b)
2022-03-02 21:30:55 +00:00
R. Ryantm
da62026eed signal-desktop: 5.30.0 -> 5.31.1
(cherry picked from commit d3ebd7d525)
2022-03-02 22:25:58 +01:00
Michael Weiss
c2f29deff4 Merge pull request #162526 from primeos/chromium-backport
[21.11] Prepare for backporting Chromium M99
2022-03-02 22:22:42 +01:00
Francesco Gazzetta
0ad8b80439 Revert "vengi-tools: remove failing roundtrip test"
This reverts commit 50dae31a14.

(cherry picked from commit 97879bb90d)
2022-03-02 12:24:55 -08:00
Francesco Gazzetta
bf8c600555 vengi-tools: 0.0.17 -> 0.0.18
(cherry picked from commit 7d87dadcea)
2022-03-02 12:24:55 -08:00
Francesco Gazzetta
9a48c1aace vengi-tools: update repo and website URLs
engine -> vengi

(cherry picked from commit 97c0ce62ad)
2022-03-02 12:24:55 -08:00
Francesco Gazzetta
6f1e15331a vengi-tools: remove failing roundtrip test
(cherry picked from commit 50dae31a14)
2022-03-02 12:24:55 -08:00
Francesco Gazzetta
aaab70dfc7 vengi-tools: add convert all formats test
(cherry picked from commit 8ed1c05622)
2022-03-02 12:24:55 -08:00
Francesco Gazzetta
f2e3266eb8 vengi-tools: 0.0.14 -> 0.0.17
(cherry picked from commit e175845d61)
2022-03-02 12:24:55 -08:00
Francesco Gazzetta
4c66f4bc88 warzone2100: 4.2.4 -> 4.2.6
(cherry picked from commit ffa839f4f9)
2022-03-02 11:42:32 -08:00
Michael Weiss
ce98f1ad3e chromiumBeta: 99.0.4844.45 -> 99.0.4844.51
(cherry picked from commit c70635eedb)
2022-03-02 20:36:03 +01:00
Michael Weiss
ab30922455 chromiumBeta: Fix the build
This "fixes" the following error:
gen/shim_headers/opus_shim/third_party/opus/src/include/opus.h:5:10: error: 'opus.h' file not found with <angled> include; use "quotes" instead
         ^~~~~~~~
         "opus.h"

Our system library isn't discovered anymore so I'm switching to the bundled
Opus library for now since I don't have time to look into it.

(cherry picked from commit 1bdf7862e3)
2022-03-02 20:36:03 +01:00
Michael Weiss
ed2b047dfe chromium{Beta,Dev}: Switch to LLVM 14
This fixes the following build error:
[24751/48400] ACTION //components/url_formatter/spoof_checks/top_domains:generate_top_domain_list_variables_file(//build/toolchain/linux/unbundle:default)d_tmp/browser_command.mojom-webui.js.mojom-webui.jsui.js
FAILED: gen/components/url_formatter/spoof_checks/top_domains/top500-domains-inc.cc
python3 ../../build/gn_run_binary.py make_top_domain_list_variables ../../components/url_formatter/spoof_checks/top_domains/domains.list top500_domains gen/components/url_formatter/spoof_checks/top_domains/top500-domains-inc.cc
make_top_domain_list_variables failed with exit code -4

The "make_top_domain_list_variables" program fails due to a SIGILL error
(illegal instruction). See:
- https://bugs.chromium.org/p/chromium/issues/detail?id=1273966
  - https://reviews.llvm.org/D115015
  - https://bugs.chromium.org/p/chromium/issues/detail?id=1269407

(cherry picked from commit c0952b6478)
2022-03-02 20:36:02 +01:00
Michael Weiss
a23a1843f9 chromiumDev: 100.0.4892.0 -> 100.0.4896.12
(cherry picked from commit 154e13a556)
2022-03-02 20:36:02 +01:00
Michael Weiss
bc978b3340 chromiumBeta: 99.0.4844.35 -> 99.0.4844.45
(cherry picked from commit 05b2b4e3cb)
2022-03-02 20:36:02 +01:00
Michael Weiss
75293781d6 chromium: Suffix instead of prefix ${xdg-utils}/bin to $PATH
This is important so that users can choose to use other implementations
(e.g., self-written Bash scripts).
We only provide xdg-utils as a fallback in case the system isn't
properly configured.

(cherry picked from commit 37a19c55df)
2022-03-02 20:36:01 +01:00
Adam Joseph
1e2403582d chromium: use pkgsBuildHost.jre8_headless instead of pkgsBuildHost.jre8
Chromium appears to require bin/java at build-time.  This patch causes
the chromium derivation to use jre8_headless instead of jre8, in order
to avoid dragging in all of gnome.

(cherry picked from commit 02ae3defed)
2022-03-02 20:36:01 +01:00
Michael Weiss
e0048bfd10 chromiumDev: 100.0.4878.0 -> 100.0.4892.0
(cherry picked from commit 6a8989c038)
2022-03-02 20:36:01 +01:00
Michael Weiss
7fbfe41ce3 chromiumBeta: 99.0.4844.27 -> 99.0.4844.35
(cherry picked from commit 4891cd5c66)
2022-03-02 20:36:01 +01:00
Michael Weiss
c936dc9ddc chromiumDev: 100.0.4867.0 -> 100.0.4878.0
(cherry picked from commit 2e969aa1d7)
2022-03-02 20:36:00 +01:00
FliegendeWurst
ebdb817cb9 google-chrome: remove gconf dependency
(cherry picked from commit 3b0e22f1e7)
2022-03-02 20:36:00 +01:00
Michael Weiss
88ace2a89a chromiumBeta: 99.0.4844.17 -> 99.0.4844.27
(cherry picked from commit c05f46f8bc)
2022-03-02 20:36:00 +01:00
Brandon Weeks
b7575de10c google-chrome: passthrough CHROME_WRAPPER environment variable
The XDG desktop menu entries created by Chrome for Progressive Web Apps
are currently broken due to Exec being set to the path of the upstream
Chrome wrapper instead of the Nixpkgs wrapper. This causes Chrome to
crash becaues LD_LIBRARY_PATH is not set.

Chrome obtains the path to be included in the menu entry from the
CHROME_WRAPPER environment variable, which is currently set by the
upstream wrapper to its own path. By setting the variable to the path of
the Nixpkgs wrapper instead, launching PWAs works as expected.

https://source.chromium.org/chromium/chromium/src/+/main:chrome/browser/shell_integration_linux.cc
https://source.chromium.org/chromium/chromium/src/+/main:chrome/installer/linux/common/wrapper
(cherry picked from commit 4ec7d05099)
2022-03-02 20:35:57 +01:00
Michael Weiss
ff0ddf1ddf chromiumDev: 99.0.4844.16 -> 100.0.4867.0
(cherry picked from commit 0ac7096740)
2022-03-02 20:35:03 +01:00
Michael Weiss
2043d539df chromiumBeta: 98.0.4758.80 -> 99.0.4844.17
(cherry picked from commit 1d902f69ef)
2022-03-02 20:35:03 +01:00
Wout Mertens
622514a902 chromium: no need to eval makeWrapper
(cherry picked from commit ee1c5b7856)
2022-03-02 20:34:03 +01:00
Michael Weiss
4c7acd97f0 Merge pull request #162424 from primeos/backports/llvmPackages_14
[21.11] Backport llvmPackages_14
2022-03-02 20:30:35 +01:00
github-actions[bot]
ec38a8c824 Merge staging-next-21.11 into staging-21.11 2022-03-02 00:36:52 +00:00
github-actions[bot]
bf3b4d19c2 Merge release-21.11 into staging-next-21.11 2022-03-02 00:31:52 +00:00
Michael Weiss
0a0a14f9d8 llvmPackages_14: Mark broken packages
I quickly went over the latest Hydra evaluation:
https://hydra.nixos.org/eval/1746327?filter=llvmPackages_14&compare=1746266&full=#tabs-still-fail

(cherry picked from commit 5040ab9149)
2022-03-01 23:40:06 +01:00
Michael Weiss
10dc23d1cf llvmPackages_14.lld: Update fix-root-src-dir.patch to fix the build
(cherry picked from commit 3bce8227a0)
2022-03-01 23:39:39 +01:00
Michael Weiss
902069f8b1 llvmPackages_14: 2022-01-07 -> 14.0.0-rc1
(cherry picked from commit 323837f7db)
2022-03-01 23:39:39 +01:00
Michael Weiss
d4eb3d27f9 llvmPackages_14: Replace tabs in lld/default.nix
This fixes a CI warning [0]:
Run cat "$HOME/changed_files" | xargs -r editorconfig-checker -disable-indent-size
pkgs/development/compilers/llvm/14/lld/default.nix:
	28: Wrong indent style found (tabs instead of spaces)
	29: Wrong indent style found (tabs instead of spaces)
	30: Wrong indent style found (tabs instead of spaces)

[0]: https://github.com/NixOS/nixpkgs/runs/5351700772

(cherry picked from commit 45cd41de23)
2022-03-01 23:39:24 +01:00
Michael Weiss
9bbba5cb8e llvmPackages_14: init at 2022-01-07
This is a temporary hack until I have time to update the patches for
14.0.0-rc1. We need llvmPackages_14 *NOW* for Chromium M99.

(cherry picked from commit d61e45b686)
2022-03-01 23:38:53 +01:00
Michael Weiss
3527e5941e llvmPackages_14: Copy the files from llvmPackages_git
(cherry picked from commit e2ba45f5ab)
2022-03-01 23:38:53 +01:00
Robert Scott
b099eaa0e0 python3Packages.b2sdk: also relax arrow constraints for python>=3.6 2022-03-01 11:28:11 -08:00
Fabian Affolter
02cebc91b9 python3Packages.b2sdk: add format
(cherry picked from commit c8d355433e)
2022-03-01 11:28:11 -08:00
R. Ryantm
48af54a724 python310Packages.b2sdk: 1.14.0 -> 1.14.1
(cherry picked from commit 05f6cdcdaa)
2022-03-01 11:28:11 -08:00
R. Ryantm
aa06695134 python38Packages.b2sdk: 1.13.0 -> 1.14.0
(cherry picked from commit bb2e1f4bc8)
2022-03-01 11:28:11 -08:00
Joel
e0929ee894 electron_16: 16.0.9 -> 16.0.10
(cherry picked from commit 2f89b8818f)
2022-03-01 11:16:05 -08:00
Joel
f28cc75d7b electron_15: 15.3.7 -> 15.4.0
(cherry picked from commit 9af2d06fb0)
2022-03-01 11:16:05 -08:00
Joel
ca89f99ade geckodriver: 0.29.1 -> 0.30.0
(cherry picked from commit a2bcf4393d)
2022-03-01 19:03:46 +00:00
Solene Rapenne
9774dc9f91 clamav: remove freshclam service dependency
(cherry picked from commit 317ca6bb4e)
2022-03-01 08:32:13 -08:00
Dr Perceptron
90406803f6 pythonPackages.cerberus: missing propagated build input
(cherry picked from commit 0caffbdff4)
2022-03-01 08:31:15 -08:00
github-actions[bot]
84bd8fc130 Merge staging-next-21.11 into staging-21.11 2022-03-01 00:37:16 +00:00
github-actions[bot]
53a52dec8e Merge release-21.11 into staging-next-21.11 2022-03-01 00:32:49 +00:00
Robert Scott
25da763fee python3Packages.celery: add patch for CVE-2021-23727 2022-02-28 14:55:35 -08:00
Vladimír Čunát
8c0bfe4477 Merge #162188: glibc: 2.33-117 -> 2.33-123 (into staging-next-21.11) 2022-02-28 21:36:42 +01:00
Vladimír Čunát
7c66c8ae30 Merge #161364: libtiff: patch CVE-2022-0561, CVE-2022-0562
...into staging-next-21.11
I forgot to check for such PRs when starting the iteration,
but fortunately there aren't so many binaries yet.
2022-02-28 21:35:24 +01:00
Átila Saraiva
c07a1620ff oil-buku: init at 0.3.2
(cherry picked from commit d3f07498cd)
2022-02-28 19:47:11 +00:00
schnusch
e33225183e remote-touchpad: 1.1.0 -> 1.2.0
(cherry picked from commit f85f8cc304)
2022-02-28 19:06:03 +00:00
Artturi
7bb8599a66 Merge pull request #162180 from NixOS/backport-157592-to-release-21.11 2022-02-28 20:48:07 +02:00
Jonathan Ringer
5b8af8ce59 python3Packages.xmltodict: disable incompatible expat tests
(cherry picked from commit 0451c289d3)
2022-02-28 14:30:09 +01:00
Markus S. Wamser
ce2ca4e28c vscode-extensions.bierner.markdown-emoji: init at 0.2.1 2022-02-28 12:06:53 +01:00
Markus S. Wamser
0dab47a58d vscode-extensions.bierner.markdown-checkbox: init at 0.3.1 2022-02-28 12:06:06 +01:00
Markus S. Wamser
4921f16375 vscode-extensions.bierner.emojisense: init at 0.9.0 2022-02-28 12:05:18 +01:00
Vladimír Čunát
321b67a744 Merge #157275: remote-touchpad: 1.0.5 -> 1.1.0 (into release-21.11) 2022-02-28 11:34:47 +01:00
TredwellGit
db1a6104d6 glibc: 2.33-117 -> 2.33-123 2022-02-28 10:45:49 +01:00
Vladimír Čunát
f7dcc890c0 Merge branch 'staging-21.11' into staging-next-21.11 2022-02-28 10:20:32 +01:00
Will Dietz
3cd8a62e77 samurai: apply upstream CVE fixes (security)
CVE-2021-30218 CVE-2021-30219

(cherry picked from commit a08b85f477)
2022-02-28 08:54:14 +00:00
Wout Mertens
7972ea4ecd Merge pull request #162159 from NixOS/backport-162152-to-release-21.11
[Backport release-21.11] netdata: fix protobuf support
2022-02-28 07:00:13 +01:00
Wout Mertens
2a40810fee netdata: fix protobuf support
(cherry picked from commit f8c560e285)
2022-02-28 05:29:44 +00:00
Artturi
475dea6ff7 Merge pull request #150747 from NixOS/backport-150513-to-release-21.11 2022-02-28 07:15:37 +02:00
Artturi
c2f028e51c Merge pull request #149643 from NixOS/backport-149075-to-release-21.11 2022-02-28 07:14:17 +02:00
Artturi
16f2f0d1cd Merge pull request #149676 from NixOS/backport-149633-to-release-21.11 2022-02-28 07:12:39 +02:00
Artturi
03e42cd111 Merge pull request #149772 from NixOS/backport-149624-to-release-21.11 2022-02-28 07:07:20 +02:00
Artturi
43a0966d08 Merge pull request #151691 from NixOS/backport-146861-to-release-21.11 2022-02-28 07:05:51 +02:00
Artturi
63613d5080 Merge pull request #161823 from NixOS/backport-161127-to-release-21.11 2022-02-28 07:04:08 +02:00
Artturi
e02e023929 Merge pull request #160397 from NixOS/backport-154793-to-release-21.11 2022-02-28 07:03:19 +02:00
Artturi
f9a2160b0b Merge pull request #161397 from NixOS/backport-160627-to-release-21.11 2022-02-28 07:02:26 +02:00
Artturi
c89ca80a6d Merge pull request #154032 from NixOS/backport-150999-to-release-21.11 2022-02-28 06:59:28 +02:00
Artturi
a460a06806 Merge pull request #154107 from NixOS/backport-153589-to-release-21.11 2022-02-28 06:54:30 +02:00
Artturi
cf35889fa0 Merge pull request #149528 from NixOS/backport-149523-to-release-21.11 2022-02-28 06:52:04 +02:00
Artturi
04b90df5cf Merge pull request #150028 from NixOS/backport-147497-to-release-21.11 2022-02-28 06:50:09 +02:00
Artturi
b5b5d05370 Merge pull request #151692 from NixOS/backport-149041-to-release-21.11 2022-02-28 06:49:16 +02:00
Artturi
fdf670ddb4 Merge pull request #161994 from NixOS/backport-161895-to-release-21.11 2022-02-28 06:46:40 +02:00
Artturi
52bcbe4588 Merge pull request #161839 from NixOS/backport-154109-to-release-21.11 2022-02-28 06:44:04 +02:00
Artturi
54a5b661d1 Merge pull request #161232 from NixOS/backport-160741-to-staging-21.11 2022-02-28 06:38:39 +02:00
Artturi
40a635c396 Merge pull request #161894 from NixOS/backport-160507-to-release-21.11 2022-02-28 06:37:52 +02:00
Artturi
a454edcfec Merge pull request #158260 from NixOS/backport-149713-to-release-21.11 2022-02-28 06:36:15 +02:00
Artturi
3a81abb5f2 Merge pull request #154225 from NixOS/backport-151693-to-release-21.11 2022-02-28 06:30:41 +02:00
Artturi
0852db1769 Merge pull request #153579 from NixOS/backport-153571-to-release-21.11 2022-02-28 06:29:15 +02:00
Artturi
98e8e2c655 Merge pull request #153511 from NixOS/backport-148164-to-release-21.11 2022-02-28 06:19:55 +02:00
Artturi
27341ecdd7 Merge pull request #157526 from NixOS/backport-157217-to-release-21.11 2022-02-28 06:18:41 +02:00
github-actions[bot]
c93a0bd481 [Backport release-21.11] rubyPackages.addressable: 2.4.0 -> 2.8.0 (#157891)
Co-authored-by: Thomas Gerbet <thomas@gerbet.me>
2022-02-28 06:17:59 +02:00
R. Ryantm
a25df4c2b7 pjsip: 2.11.1 -> 2.12
(cherry picked from commit 5534c689cb)
2022-02-27 17:20:58 -08:00
github-actions[bot]
0776045c54 Merge staging-next-21.11 into staging-21.11 2022-02-28 00:14:44 +00:00
github-actions[bot]
71d612dd4b Merge release-21.11 into staging-next-21.11 2022-02-28 00:14:00 +00:00
Lara
aee1e37187 gitlab: 14.7.3 -> 14.7.4
https://about.gitlab.com/releases/2022/02/25/critical-security-release-gitlab-14-8-2-released/
(cherry picked from commit 7b58ac4434467379b225564eae639e256f65dee7)
2022-02-27 15:11:33 -08:00
Anderson Torres
0f16296972 Merge pull request #162109 from AndersonTorres/fix-elisp-release
[21.11] emacs packages: machine+hand updated at 2022-02-17
2022-02-27 17:05:44 -03:00
AndersonTorres
11264a390b [21.11] emacs packages: machine+hand updated at 2022-02-17
Cherry-picked automagically from dc68f203cc0d495dcd271d973590511adb1aaa6
2022-02-27 15:33:48 -03:00
github-actions[bot]
f47f47a12b [Backport release-21.11] memtest86-efi: 8.4 -> 9.3.1000 (#160490)
Co-authored-by: TredwellGit <tredwell@tutanota.com>
2022-02-27 19:31:21 +02:00
github-actions[bot]
fc78d3e420 [Backport staging-21.11] cyrus_sasl: 2.1.27 -> 2.1.28 (#162046)
Co-authored-by: illustris <rharikrishnan95@gmail.com>
Co-authored-by: Martin Weinelt <hexa@darmstadt.ccc.de>
2022-02-27 19:23:52 +02:00
github-actions[bot]
1552cae9f4 Merge staging-next-21.11 into staging-21.11 2022-02-27 00:15:51 +00:00
github-actions[bot]
d534a28b9f Merge release-21.11 into staging-next-21.11 2022-02-27 00:15:20 +00:00
Aaron Andersen
2f49c5ff23 redmine: 4.2.3 -> 4.2.4
(cherry picked from commit 25489d9628)
2022-02-26 16:52:57 +00:00
Mario Rodas
1622abf0e7 Merge pull request #161733 from c0bw3b/backport/fscrypt
[21.11] fscrypt-experimental: 0.3.0 -> 0.3.3
2022-02-26 09:17:23 -05:00
Artturi
f1e8e187f9 Merge pull request #161891 from NixOS/backport-161748-to-release-21.11
[Backport release-21.11] Linux kernels 2022-02-23
2022-02-26 06:01:30 +02:00
github-actions[bot]
ff2c33a4b9 Merge staging-next-21.11 into staging-21.11 2022-02-26 00:12:27 +00:00
github-actions[bot]
5ae21cecd9 Merge release-21.11 into staging-next-21.11 2022-02-26 00:11:51 +00:00
Robert Scott
acf18a10e8 wolfssl: add patches for CVE-2022-25638 & CVE-2022-25640 2022-02-25 23:12:58 +00:00
Martin Weinelt
377e123d59 wallabag: 2.4.2 -> 2.4.3
https://github.com/wallabag/wallabag/releases/tag/2.4.3
(cherry picked from commit 71a8819e3d)
2022-02-25 22:49:33 +00:00
Maximilian Bosch
e8534a5a47 Merge pull request #161819 from NixOS/backport-161722-to-release-21.11
[Backport release-21.11] grafana: 8.4.1 -> 8.4.2
2022-02-25 23:44:49 +01:00
TredwellGit
9640657940 linux_latest-libre: 18587 -> 18613
(cherry picked from commit 16b568a8fd)
2022-02-25 22:32:53 +00:00
TredwellGit
ad4587b5a0 linux: 5.4.180 -> 5.4.181
(cherry picked from commit 8236ce5d1b)
2022-02-25 22:32:53 +00:00
TredwellGit
74ca42f501 linux: 5.16.10 -> 5.16.11
(cherry picked from commit 5d84cca2bc)
2022-02-25 22:32:53 +00:00
TredwellGit
f83b9cfc6e linux: 5.15.24 -> 5.15.25
(cherry picked from commit 5ecbcef8e9)
2022-02-25 22:32:53 +00:00
TredwellGit
0aab648a3e linux: 5.10.101 -> 5.10.102
(cherry picked from commit 4975bf0463)
2022-02-25 22:32:53 +00:00
TredwellGit
7c12fe9851 linux: 4.9.302 -> 4.9.303
(cherry picked from commit 6dd9c2a588)
2022-02-25 22:32:53 +00:00
TredwellGit
2e489ad931 linux: 4.19.230 -> 4.19.231
(cherry picked from commit 8585beaf0a)
2022-02-25 22:32:53 +00:00
TredwellGit
bad23028c2 linux: 4.14.267 -> 4.14.268
(cherry picked from commit a8a1714ba0)
2022-02-25 22:32:53 +00:00
Maximilian Bosch
a22bd30538 Merge pull request #161592 from NixOS/backport-161452-to-release-21.11
[Backport release-21.11] Linux kernels 2022-02-22
2022-02-25 20:43:54 +01:00
Izorkin
365c1f3f11 nixos/peertube: add python path
(cherry picked from commit e0616741d1)
2022-02-25 13:43:28 +00:00
Izorkin
c56148c6fb peertube: 4.0.0 -> 4.1.0
(cherry picked from commit fd00aa150c)
2022-02-25 13:43:28 +00:00
Izorkin
f9065c6056 nixos/peertube: fix youtube-dl import
(cherry picked from commit c2296c3ec2)
2022-02-25 13:43:28 +00:00
Izorkin
eb26a4ca0b peertube: remove unused packages and modules
(cherry picked from commit f1352f4ffe)
2022-02-25 13:43:28 +00:00
Izorkin
2b79e8cff0 peertube: 3.4.1 -> 4.0.0
(cherry picked from commit 5ef18e6343)
2022-02-25 13:43:28 +00:00
Fabian Affolter
59ed36e82b yara: 4.1.3 -> 4.2.0-rc1
(cherry picked from commit 4e64bd5e4c)
2022-02-25 11:58:31 +00:00
Maximilian Bosch
f68129fb17 grafana: 8.4.1 -> 8.4.2
ChangeLog: https://github.com/grafana/grafana/releases/v8.4.2
(cherry picked from commit 8b9fc0e6ab)
2022-02-25 11:48:02 +00:00
Anderson Torres
441bf3f59a Merge pull request #161753 from AndersonTorres/release-21.11
[21.11] elisp-packages: updated at 2022-02-24
2022-02-25 08:15:06 -03:00
Martin Weinelt
8dc912f0ec Merge pull request #160897 from NixOS/backport-160826-to-staging-21.11 2022-02-25 11:40:17 +01:00
Martin Weinelt
d8daab5a9d Merge pull request #161647 from NixOS/backport-161595-to-staging-21.11 2022-02-25 11:11:18 +01:00
AndersonTorres
8f1db0ac4b [21.11] elisp-packages: updated at 2022-02-24 2022-02-24 22:38:06 -03:00
github-actions[bot]
58f489c836 Merge staging-next-21.11 into staging-21.11 2022-02-25 00:12:34 +00:00
github-actions[bot]
d77f29e5a9 Merge release-21.11 into staging-next-21.11 2022-02-25 00:11:56 +00:00
Alyssa Ross
74908426a2 seatd: 0.6.3 -> 0.6.4
https://lists.sr.ht/~kennylevinsen/seatd-announce/%3CETEO7R.QG8B1KGD531R1%40kl.wtf%3E

No CVE yet.

(cherry picked from commit e4957ce420f79ec03d953c3c44f277016aaa7d04)
2022-02-24 23:26:03 +00:00
R. RyanTM
5e70c45fbf fscrypt-experimental: 0.3.1 -> 0.3.3
* fscrypt-experimental: 0.3.1 -> 0.3.2 (#160747)

* fscrypt-experimental: 0.3.2 -> 0.3.3

Fixes CVE-2022-25326
Fixes CVE-2022-25327
Fixes CVE-2022-25328

Co-authored-by: Renaud <c0bw3b@users.noreply.github.com>
2022-02-24 23:02:34 +01:00
Michael Weiss
89323246e5 fscrypt-experimental: 0.3.0 -> 0.3.1 2022-02-24 23:02:00 +01:00
lewo
9a4a51bb83 Merge pull request #161634 from NixOS/backport-161388-to-release-21.11
[Backport release-21.11] openstack-metadata-fetcher: do not fail if no user-data is provided
2022-02-24 18:13:44 +01:00
Florian Klink
66b29facaf Merge pull request #161682 from NixOS/backport-161426-to-release-21.11
[Backport release-21.11] nixos/doc: improve release notes for iptables-nft and systemd with nftables backend
2022-02-24 17:50:14 +01:00
Florian Klink
12160fe3b5 nixos/doc: improve release notes for iptables-nft and systemd with nftables backend
This change probably wasn't documented sufficiently in the release
notes, neither the fact systemd stopped using iptables on its own in
case of nf_tables support.

Fixes #156041.

(cherry picked from commit 753a43caf0)
2022-02-24 16:28:11 +00:00
Robert Scott
8c2b475b24 flac: 1.3.3 -> 1.3.4
(cherry picked from commit c7d1c41680)
2022-02-24 11:27:04 +00:00
Antoine Eiche
899de6f8bf openstack-metadata-fetcher: do not fail if no user-data is provided
When no user-data is provided, the OpenStack metadata server doesn't
expose the user-data route.

(cherry picked from commit 413afdae6e)
2022-02-24 09:21:36 +00:00
Kim Lindberger
5785efcf72 Merge pull request #161563 from NixOS/backport-160463-to-release-21.11
[Backport release-21.11] gitlab: 14.7.2 -> 14.7.3
2022-02-24 09:58:53 +01:00
github-actions[bot]
b48ddd35d4 Merge staging-next-21.11 into staging-21.11 2022-02-24 00:12:30 +00:00
github-actions[bot]
eae4700c20 Merge release-21.11 into staging-next-21.11 2022-02-24 00:11:51 +00:00
TredwellGit
4b7e6453d9 linux/hardened/patches/5.4: 5.4.177-hardened1 -> 5.4.180-hardened1
(cherry picked from commit 73c5ccbf21)
2022-02-23 23:55:21 +00:00
TredwellGit
cc223b8ac8 linux/hardened/patches/5.15: 5.15.21-hardened1 -> 5.15.24-hardened1
(cherry picked from commit d9a881c99b)
2022-02-23 23:55:21 +00:00
TredwellGit
8c435035b1 linux/hardened/patches/5.10: 5.10.98-hardened1 -> 5.10.101-hardened1
(cherry picked from commit 99c4179120)
2022-02-23 23:55:21 +00:00
TredwellGit
45363631be linux/hardened/patches/4.19: 4.19.227-hardened1 -> 4.19.230-hardened1
(cherry picked from commit 745de513d6)
2022-02-23 23:55:21 +00:00
TredwellGit
e911686599 linux/hardened/patches/4.14: 4.14.264-hardened1 -> 4.14.267-hardened1
(cherry picked from commit 16e2d243d0)
2022-02-23 23:55:21 +00:00
TredwellGit
3f45600588 linux-rt_5_10: 5.10.78-rt55 -> 5.10.100-rt62
(cherry picked from commit 0e5ebf54d5)
2022-02-23 23:55:21 +00:00
ajs124
4275a321be matrix-synapse: 1.52.0 -> 1.53.0
(cherry picked from commit f6956a44e1)
2022-02-23 13:42:45 -08:00
R. Ryantm
35f897b79b python310Packages.matrix-common: 1.0.0 -> 1.1.0
(cherry picked from commit b86b8a8a28)
2022-02-23 13:42:45 -08:00
ajs124
63599de578 Merge pull request #161252 from helsinki-systems/bkp/21.11/php
[21.11] php updates
2022-02-23 20:21:20 +01:00
Lara
07e86325b1 gitlab: 14.7.2 -> 14.7.3
(cherry picked from commit eb84f592c6)
2022-02-23 18:18:49 +00:00
Wout Mertens
759e24c7d9 Merge pull request #161357 from wmertens/netdata-backport-33
netdata: 1.32.1 -> 1.33.1 + protobuf support
2022-02-23 17:50:47 +01:00
Robert Hensing
fc465bce8b Merge pull request #161541 from NixOS/backport-161526-to-release-21.11
[Backport release-21.11] Cassandra update
2022-02-23 16:34:13 +01:00
Robert Hensing
7f442b5f54 cassandra_3_11: 3.11.10 -> 3.11.12
(cherry picked from commit d806547deb)
2022-02-23 15:29:43 +00:00
Robert Hensing
90c3d98fd5 cassandra_3_0: 3.0.24 -> 3.0.26
(cherry picked from commit 313acb6cc2)
2022-02-23 15:29:43 +00:00
Robert Hensing
7376f64881 cassandra: Remove javadoc which is not shipped in new versions
(cherry picked from commit 72ddd738f4)
2022-02-23 15:29:43 +00:00
github-actions[bot]
679d696e25 Merge staging-next-21.11 into staging-21.11 2022-02-23 00:13:24 +00:00
github-actions[bot]
42aace52cf Merge release-21.11 into staging-next-21.11 2022-02-23 00:12:46 +00:00
Felix Bühler
e293c918e0 Merge pull request #160508 from Stunkymonkey/backport-160200-to-release-21.11
mediaelch: fix loading of libmediainfo
2022-02-22 23:45:56 +01:00
Stig
c99d2a0b6e Merge pull request #160026 from NixOS/backport-149591-to-release-21.11
[Backport release-21.11] update modsecurity packages
2022-02-22 22:00:07 +01:00
Vladimír Čunát
e7b63e3596 libtiff: standardize the patch URLs
https://github.com/NixOS/nixpkgs/pull/161295#discussion_r812233936
(cherry picked from commit ba2687fcfb)
2022-02-22 21:14:11 +01:00
Artturi
1b227c7026 Merge pull request #161347 from NixOS/backport-161258-to-release-21.11 2022-02-22 20:56:51 +02:00
Guillaume Girol
0c46a08c2b Merge pull request #161409 from NixOS/backport-161403-to-release-21.11
[Backport release-21.11] mtxclient: 0.6.1 -> 0.6.2
2022-02-22 18:46:50 +00:00
Philipp
e0327af02f mtxclient: 0.6.1 -> 0.6.2
(cherry picked from commit 79dd82eadd)
2022-02-22 18:15:27 +00:00
Jakub Kozłowski
bfd9014667 bloop: 1.4.12 -> 1.4.13
(cherry picked from commit 005a23e06f)
2022-02-22 16:58:44 +00:00
Robert Scott
6942c8ed65 libtiff: add patches for CVE-2022-0561 & CVE-2022-0562
(cherry picked from commit 7d6abd197c)
2022-02-22 12:50:55 +00:00
Wout Mertens
0978762fcd netdata: 1.32.1 -> 1.33.1 + protobuf support 2022-02-22 12:46:12 +01:00
Alyssa Ross
d67fe6202b kmod-blacklist-ubuntu: don't refer to grep/xargs
64b4af5296 ("kmod-blacklist-ubuntu: 22-1.1ubuntu1 -> 28-1ubuntu4")
doubled the size of the default initramfs.  This happened because the
upgrade introduced this configuration:

	remove iwlwifi \
	(/sbin/lsmod | grep -o -e ^iwlmvm -e ^iwldvm -e ^iwlwifi | xargs /sbin/rmmod) \
	&& /sbin/modprobe -r mac80211

This meant that the grep and xargs substitutions, which had been
inactive for years, suddenly became active again and became part of
kmod-blacklist-ubuntu's closure.

Since we're already using /run/booted-system for the kmod binaries,
I think it's okay to use it for grep and xargs as well.  Both are
required NixOS packages, so they're guaranteed to be there.

Large increases in initramfs size are problematic, because it's often
not possible for users to do anything about them.  It's not always
possible to increase the size of /boot, because some filesystems like
ZFS don't support being shrunk to make way for a bigger /boot.

(cherry picked from commit 0100a75801)
2022-02-22 10:24:03 +00:00
github-actions[bot]
76684cbf6f Merge staging-next-21.11 into staging-21.11 2022-02-22 00:12:37 +00:00
github-actions[bot]
e941da9fd0 Merge release-21.11 into staging-next-21.11 2022-02-22 00:11:57 +00:00
Congee
491ad20776 racket: support aarch64-darwin
According to https://reviews.llvm.org/D96164, aarch64-darwin executables
require at least an ad hoc signature.

The build tool from the racket repo tries to sign $out/bin/racket but
errors out, because that binary already has a signature.

It is not clear yet at which stage the signature was introduced. This
patch removes the existing signature always before calling
add-ad-hoc-signature to circumvent that error.

(cherry picked from commit 152b59855d)
2022-02-21 16:09:30 -08:00
Mario Rodas
cc81cf4811 racket: 8.3 -> 8.4
https://download.racket-lang.org/v8.4.html
(cherry picked from commit 2b24509585)
2022-02-21 15:01:29 -08:00
AndersonTorres
fa0b1d59c7 mednafen: 1.26.1 -> 1.29.0
(cherry picked from commit 09640927e7)
2022-02-21 14:47:11 -08:00
Jan Solanti
8199a1d49a renderdoc: 1.17 -> 1.18
(cherry picked from commit 4591082c61)
2022-02-21 14:38:41 -08:00
Ryan Hendrickson
0843e0b952 firefox-beta-bin: 96.0b3 -> 98.0b5 2022-02-21 14:34:57 -08:00
Ryan Hendrickson
86c8456d90 firefox-devedition-bin: 96.0b3 -> 98.0b5 2022-02-21 14:34:57 -08:00
Robert Scott
957d9185f9 swtpm: 0.6.1 -> 0.6.2 2022-02-21 14:34:38 -08:00
Janne Heß
3ae52e6fa0 libspf2: Switch to a more supported upstream
This includes fixes for:
- CVE-2021-33912
- CVE-2021-33913
- other buffer/use-after-free fixes

GitHub: security issue https://github.com/NixOS/nixpkgs/issues/160671
GitHub: master PR https://github.com/NixOS/nixpkgs/pull/149589

(cherry picked from commit 24c6b28737)
(cherry picked from commit 49135f955c70709e4c20c0a6d19f77574c9784de)
2022-02-21 14:34:31 -08:00
Pasquale
882d652098 nixos/xdg-portals: add portals' desktop files to XDG_DATA_DIRS
(cherry picked from commit e9c4910524)
2022-02-21 14:33:59 -08:00
nixpkgs-upkeep-bot
b169357271 vscodium: 1.64.0 -> 1.64.2
(cherry picked from commit 04cced10b7)
2022-02-21 14:30:31 -08:00
Maximilian Bosch
395d130c1c element-{web,desktop}: 1.10.1 -> 1.10.4
ChangeLogs (desktop):
* https://github.com/vector-im/element-desktop/releases/tag/v1.10.2
* https://github.com/vector-im/element-desktop/releases/tag/v1.10.3
* https://github.com/vector-im/element-desktop/releases/tag/v1.10.4

ChangeLogs (web):
* https://github.com/vector-im/element-web/releases/tag/v1.10.2
* https://github.com/vector-im/element-web/releases/tag/v1.10.3
* https://github.com/vector-im/element-web/releases/tag/v1.10.4

(cherry picked from commit d7bec7a127)
2022-02-21 14:29:22 -08:00
Winter
1cf9b4410c nixos/doc: fix mention of reading test logs
(cherry picked from commit c772c572cf)
2022-02-21 14:28:50 -08:00
R. Ryantm
d56ad03b43 duktape: 2.6.0 -> 2.7.0
(cherry picked from commit af98faa428)
2022-02-21 14:25:00 -08:00
Sandro Jäckel
d2aad35a33 nixos/locate: PRUNE_BIND_MOUNTSFR -> PRUNE_BIND_MOUNTS
PRUNE_BIND_MOUNTSFR seems to be a typo.
The man page only mentions it in a header and further in the paragraph
it is PRUNE_BIND_MOUNTS.

Also breaks plocate which complains about the unknown option.
2022-02-21 14:23:55 -08:00
Daniel Olsen
67ad875b01 hydrus: 473 -> 474
(cherry picked from commit 3997d8b9b6)
2022-02-21 14:23:12 -08:00
Robert Schütz
7048145b7b imagemagick: 7.1.0-25 -> 7.1.0-26
(cherry picked from commit 879fb14bd4817b0b181d079b03138da775976b56)
2022-02-21 22:01:34 +01:00
7c6f434c
fcb9b8e5c7 Merge pull request #161137 from NixOS/backport-153963-to-staging-21.11
[Backport staging-21.11] llvmPackages_13.clang: add nostdlibinc flag
2022-02-21 17:34:33 +00:00
Vladimír Čunát
a290b35e1e Merge #160384: mariadb: 10.6.5 -> 10.6.7 (into release-21.11) 2022-02-21 17:52:39 +01:00
Pol Dellaiera
5ac0241482 php80: 8.0.14 -> 8.0.16
(cherry picked from commit 60dfe5bd6c)
2022-02-21 16:58:56 +01:00
Pol Dellaiera
567f383bcc php74: 7.4.27 -> 7.4.28
(cherry picked from commit b1cd925484)
2022-02-21 16:58:56 +01:00
Martin Weinelt
278f22b46c polkit: Patch unauthenticated file descriptor leak
https://gitlab.freedesktop.org/polkit/polkit/-/issues/170
https://www.openwall.com/lists/oss-security/2022/02/18/1

Fixes: CVE-2021-4115
(cherry picked from commit 08a80b7b00)
2022-02-21 13:31:24 +00:00
Vladimír Čunát
2130cf7532 Merge #161184: maintainers: remove linarcx (into release-21.11) 2022-02-21 08:58:10 +01:00
Mario Rodas
195201ecbb maintainers: remove linarcx
(cherry picked from commit 438d759bb4)
2022-02-21 07:55:05 +00:00
Sebastian Pipping
eb722edfb3 expat: 2.4.5 -> 2.4.6
(cherry picked from commit 08bd5cbf9c)
2022-02-21 12:03:30 +08:00
Martin Weinelt
f0b2ba0d57 Merge pull request #161088 from NixOS/backport-160723-to-release-21.11 2022-02-21 02:49:24 +01:00
Martin Weinelt
27627149b7 Merge pull request #160895 from NixOS/backport-160470-to-staging-21.11 2022-02-21 02:30:52 +01:00
Jyun-Yan You
e370659408 llvmPackages_13.clang: add nostdlibinc flag
This patch adds nostdlibinc flag after parsing arguments
instead of sed substitution.

Fix #151879

(cherry picked from commit 2fe19fe24a)
2022-02-21 00:52:36 +00:00
github-actions[bot]
3529750958 Merge staging-next-21.11 into staging-21.11 2022-02-21 00:12:51 +00:00
github-actions[bot]
7ab7ce206e Merge release-21.11 into staging-next-21.11 2022-02-21 00:12:12 +00:00
Martin Weinelt
a406844445 libxslt: Fix use-after-free in xsltApplyTemplates
Fixes: CVE-2021-30560
(cherry picked from commit 54806020fa)
2022-02-20 20:26:47 +01:00
Robert Scott
40ef692a55 nats-server: add patch for CVE-2022-24450 2022-02-20 12:53:36 -05:00
Kerstin Humm
d37369da34 mastodon: apply upstream patch for CVE-2022-0432
4d6d4b43c6

Co-authored-by: Robert Scott <github@humanleg.org.uk>
(cherry picked from commit a8121ca80e)
2022-02-20 17:08:29 +00:00
7c6f434c
cc244a8ef1 Merge pull request #161041 from NixOS/backport-160929-to-release-21.11
[Backport release-21.11] libreoffice: add `java.logging` to minimal JRE
2022-02-20 11:08:53 +00:00
Maximilian Bosch
9233546feb libreoffice: add java.logging to minimal JRE
This is e.g. required to properly use the Langtool-plugin[1] which
otherwise fails like this:

    java.lang.NoClassDefFoundError: java/util/logging/Logger

Fixes #160315

[1] https://extensions.libreoffice.org/en/extensions/show/languagetool

(cherry picked from commit b308b06c22)
2022-02-20 10:43:34 +00:00
davidak
cd6f664b75 Merge pull request #161028 from NixOS/backport-160424-to-release-21.11
[Backport release-21.11] phoronix-test-suite: 10.8.1 -> 10.8.2
2022-02-20 10:39:38 +01:00
R. Ryantm
59ed4fc571 phoronix-test-suite: 10.8.1 -> 10.8.2
(cherry picked from commit a7c9fa3eab)
2022-02-20 08:29:49 +00:00
Mario Rodas
26608f8a42 Merge pull request #161004 from NixOS/backport-160944-to-release-21.11
[Backport release-21.11] radare2: 5.6.0 -> 5.6.2
2022-02-20 00:26:34 -05:00
arkivm
e4da1114ff radare2: 5.6.0 -> 5.6.2
(cherry picked from commit 0560db5867)
2022-02-20 04:54:22 +00:00
Bobby Rong
8a915444b0 Merge pull request #160903 from NixOS/backport-160209-to-release-21.11
[Backport release-21.11] libhomfly: fix pname
2022-02-20 10:51:58 +08:00
github-actions[bot]
5929f27523 Merge staging-next-21.11 into staging-21.11 2022-02-20 00:14:17 +00:00
github-actions[bot]
73bde9be5d Merge release-21.11 into staging-next-21.11 2022-02-20 00:13:45 +00:00
Renaud
5ea05afbde Merge pull request #149647 from NixOS/backport-149504-to-release-21.11
[Backport release-21.11] brscan5: fix nixos test
2022-02-19 23:16:06 +01:00
Maximilian Bosch
f857468759 Merge pull request #160873 from NixOS/backport-160729-to-release-21.11
[Backport release-21.11] grafana-image-renderer: 3.3.0 -> 3.4.0
2022-02-19 19:52:17 +01:00
Renaud
91e2727c16 Merge pull request #150590 from Yarny0/tsm-client-2111
[21.11] tsm-client: 8.1.8.0 -> 8.1.13.3 (security update)
2022-02-19 19:48:16 +01:00
Maximilian Bosch
c92ca8c7ba grafana-image-renderer: fix build on 21.11
We don't support `nativeBuildInputs` for `pkgConfig` here yet, so
working around it.
2022-02-19 19:14:04 +01:00
Renaud
04761aae82 Merge pull request #152876 from NixOS/backport-151628-to-release-21.11
[Backport release-21.11] btop: 1.1.2 -> 1.1.3
2022-02-19 18:42:25 +01:00
Mario Rodas
ed4e0cd508 Merge pull request #160519 from NixOS/backport-160499-to-release-21.11
[Backport release-21.11] discord: 0.0.16 -> 0.0.17
2022-02-19 12:12:29 -05:00
Maciej Krüger
f6ea271239 Merge pull request #160892 from NixOS/backport-160084-to-release-21.11 2022-02-19 17:15:04 +01:00
Renaud
f38aeaae74 Merge pull request #156260 from NixOS/backport-152014-to-release-21.11
[Backport release-21.11] staticjinja: 4.1.1 -> 4.1.2, add minimal template test
2022-02-19 16:01:03 +01:00
Mauricio Collares
357a07e725 libhomfly: fix pname
(cherry picked from commit 4ec82c7bab)
2022-02-19 14:11:18 +00:00
Bobby Rong
62132d7701 Merge pull request #160558 from NixOS/backport-160405-to-release-21.11
[Backport release-21.11] brave: 1.35.101 -> 1.35.103
2022-02-19 21:44:09 +08:00
Sebastian Pipping
f6340fa906 expat: 2.4.4 -> 2.4.5 (security)
(cherry picked from commit 62b1a57752)
2022-02-19 13:39:12 +00:00
Átila Saraiva
0cb6c5d586 swaytools: init at 0.1.0
(cherry picked from commit e93bb42cd7)
2022-02-19 13:15:02 +00:00
Maximilian Bosch
13b7252add grafana-image-renderer: 3.3.0 -> 3.4.0
ChangeLog: https://github.com/grafana/grafana-image-renderer/releases/tag/v3.4.0
(cherry picked from commit 99a0019000)
2022-02-19 10:52:53 +00:00
lewo
fa1114a804 Merge pull request #159870 from NixOS/backport-159687-to-release-21.11
[Backport release-21.11] postfix: 3.6.4 -> 3.6.5
2022-02-19 11:50:51 +01:00
Vladimír Čunát
e512ff6042 Merge #160814: firefox*: 97.0 -> 97.0.1 (into release-21.11) 2022-02-19 09:38:19 +01:00
Bobby Rong
6b40d786ad Merge pull request #160511 from pacien/gscan2pdf-fix-tarball-url
[21.11] gscan2pdf: fix download URL
2022-02-19 15:10:03 +08:00
Artturi
190bf6b7f2 Merge pull request #160785 from NixOS/backport-160093-to-release-21.11
[Backport release-21.11] lens: 5.2.6 -> 5.3.4
2022-02-19 03:40:05 +02:00
Martin Weinelt
b712f8e64f firefox-bin: 97.0 -> 97.0.1
https://www.mozilla.org/en-US/firefox/97.0.1/releasenotes/
(cherry picked from commit 5fc0d7fd37)
2022-02-19 01:01:29 +00:00
Martin Weinelt
2bd5364dfe firefox: 97.0 -> 97.0.1
https://www.mozilla.org/en-US/firefox/97.0.1/releasenotes/
(cherry picked from commit 7e23a7fb82)
2022-02-19 01:01:29 +00:00
Martin Weinelt
e8d50c4bf4 Merge pull request #160570 from NixOS/backport-160528-to-release-21.11 2022-02-19 01:45:38 +01:00
Maximilian Bosch
3d30ff24ab Merge pull request #160749 from NixOS/backport-159261-to-release-21.11
[Backport release-21.11] Linux kernels 2022-02-16
2022-02-19 01:22:37 +01:00
github-actions[bot]
2fed8cd950 Merge staging-next-21.11 into staging-21.11 2022-02-19 00:13:22 +00:00
github-actions[bot]
5c204adf71 Merge release-21.11 into staging-next-21.11 2022-02-19 00:12:45 +00:00
Renaud
f01d139a5c Merge pull request #157925 from NixOS/backport-157903-to-release-21.11
[Backport release-21.11] connman: 1.40 -> 1.41
2022-02-19 00:08:49 +01:00
Otavio Salvador
4fed9432db lens: 5.2.6 -> 5.3.4
Fixes: #158957.
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit d44c641f64c00e39db6233029cf305ff64118326)
2022-02-18 22:38:49 +00:00
Maximilian Bosch
781558ee08 Merge pull request #160731 from NixOS/backport-160512-to-release-21.11
[Backport release-21.11] grafana: 8.3.6 -> 8.4.1
2022-02-18 20:59:55 +01:00
Renaud
fe4505cc9b Merge pull request #160737 from NixOS/backport-158102-to-release-21.11
[Backport release-21.11] bingrep: 0.8.5 -> 0.9.0
2022-02-18 20:45:34 +01:00
TredwellGit
9341e90b7a linux-rt_5_10: 5.10.90-rt60 -> 5.10.78-rt55
(cherry picked from commit 504c829864)
2022-02-18 19:25:13 +00:00
TredwellGit
17ba0a0a5c linux: 5.4.178 -> 5.4.180
(cherry picked from commit 3995fb76d0)
2022-02-18 19:25:13 +00:00
TredwellGit
5453c3ae84 linux: 5.16.8 -> 5.16.10
(cherry picked from commit 1dda49a41b)
2022-02-18 19:25:13 +00:00
TredwellGit
ebeb339318 linux: 5.15.22 -> 5.15.24
(cherry picked from commit 6d5687355d)
2022-02-18 19:25:13 +00:00
TredwellGit
f841818b90 linux: 5.10.99 -> 5.10.101
(cherry picked from commit ce699eaba7)
2022-02-18 19:25:13 +00:00
TredwellGit
0c4241e1bb linux: 4.9.300 -> 4.9.302
(cherry picked from commit 897193e107)
2022-02-18 19:25:12 +00:00
TredwellGit
ac8f8c5e78 linux: 4.19.228 -> 4.19.230
(cherry picked from commit 801a4cba9d)
2022-02-18 19:25:12 +00:00
TredwellGit
8cde302f2c linux: 4.14.265 -> 4.14.267
(cherry picked from commit a496a2c904)
2022-02-18 19:25:12 +00:00
Renaud
0bc71cc780 bingrep: 0.8.5 -> 0.9.0
(cherry picked from commit 91bbd31068)
2022-02-18 18:16:29 +00:00
Maximilian Bosch
d321cc84f0 grafana: 8.3.6 -> 8.4.1
ChangeLog: https://github.com/grafana/grafana/releases/tag/v8.4.0
ChangeLog: https://github.com/grafana/grafana/releases/tag/v8.4.1
(cherry picked from commit 3ebd1d226f)
2022-02-18 17:18:09 +00:00
Martin Weinelt
ec7f9e0ab4 webkitgtk: 2.34.5 -> 2.34.6
https://webkitgtk.org/security/WSA-2022-0003.html

Fixes: CVE-2022-22620
(cherry picked from commit cf6944227c)
2022-02-18 06:15:31 +00:00
TredwellGit
cc61972bfa brave: 1.35.101 -> 1.35.103
https://github.com/brave/brave-browser/blob/master/CHANGELOG_DESKTOP.md#135103
(cherry picked from commit e70f9e5121)
2022-02-18 04:45:51 +00:00
Bobby Rong
4afca382d8 Merge pull request #160169 from NixOS/backport-158826-to-release-21.11
[Backport release-21.11] hydrus: 472 -> 473
2022-02-18 12:45:30 +08:00
Bobby Rong
b68340cbd4 Merge pull request #160524 from NixOS/backport-158834-to-release-21.11
[Backport release-21.11] jless: init at 0.7.1
2022-02-18 11:58:45 +08:00
github-actions[bot]
edf9eef446 Merge staging-next-21.11 into staging-21.11 2022-02-18 00:11:16 +00:00
github-actions[bot]
a87821c613 Merge release-21.11 into staging-next-21.11 2022-02-18 00:10:43 +00:00
Jean-Francois Chevrette
7e15e46631 add jfchevrette to maintainers
(cherry picked from commit 359687c5b0)
2022-02-17 23:57:23 +00:00
Jean-Francois Chevrette
66753d7d1b jless: init at 0.7.1
(cherry picked from commit e646b64ebb)
2022-02-17 23:57:23 +00:00
Shea Levy
685ef17fed discord: 0.0.16 -> 0.0.17
(cherry picked from commit e0c8e584ae)
2022-02-17 23:23:10 +00:00
Maximilian Bosch
9767dc3d58 Merge pull request #160509 from Ma27/backport-mautrix-whatsapp
[21.11] mautrix-whatsapp: 0.2.3 -> 0.2.4
2022-02-17 23:33:50 +01:00
Alyssa Ross
f7d2ba2942 virtiofsd: init at 1.0.0
(cherry picked from commit dc78ae3dc453384049994e41cd8ad7b29e6d644e)
2022-02-17 22:29:28 +00:00
pacien
ca4d11bd89 gscan2pdf: fix download URL
The former one returns a 404 not found error.

(cherry picked from commit 015b5e052239bf6fec6a11da3a8671af980d1214)
2022-02-17 23:16:25 +01:00
Charlotte Van Petegem
8332344e31 mautrix-whatsapp: 0.2.3 -> 0.2.4
(cherry picked from commit d9c6b1fc1f)
2022-02-17 22:35:19 +01:00
Felix Buehler
44056bb657 mediaelch: fix loading of libmediainfo
(cherry picked from commit 64d9b62ab9)
2022-02-17 22:32:52 +01:00
maxine [they]
d78f209f27 Merge pull request #160317 from NixOS/backport-159090-to-release-21.11
[Backport release-21.11] vscode: 1.64.0 -> 1.64.2
2022-02-17 21:07:55 +01:00
Janne Heß
84592b5fb3 mariadb: Fix Darwin build
(cherry picked from commit 6f7baddf2f)
2022-02-17 19:12:33 +01:00
ajs124
fed91582ae mariadb_106: 10.6.6 -> 10.6.7
(cherry picked from commit 45ab3705c8)
2022-02-17 19:12:33 +01:00
Martin Weinelt
fb64408f33 util-linux: 2.37.3 -> 2.37.4
Fixes: CVE-2022-0563
(cherry picked from commit 05d293c2bf)
2022-02-17 09:37:34 -08:00
Silvan Mosberger
cf381cc106 Merge pull request #160474 from NixOS/revert-156073-backport-155522-to-release-21.11
Revert "[Backport release-21.11] types.singleLineStr: strings that don't contain '\n'"
2022-02-17 17:29:31 +01:00
Graham Christensen
f2943c9c3e Revert "[Backport release-21.11] types.singleLineStr: strings that don't contain '\n'" 2022-02-17 10:02:10 -05:00
Robert Schütz
aefc44db81 imagemagick: 7.1.0-24 -> 7.1.0-25
(cherry picked from commit f4c05d7609260dc71d22c94b333a5759d5c01f03)
2022-02-17 13:56:48 +01:00
Niklas Hambüchen
05c0c6ce7b Merge pull request #160421 from NixOS/backport-160304-to-release-21.11
[Backport release-21.11] thunderbird: 91.6.0 -> 91.6.1, thunderbird-bin: 91.5.1 -> 91.6.1 [High security fix]
2022-02-17 13:17:24 +01:00
taku0
e6df5f5821 thunderbird: 91.6.0 -> 91.6.1
(cherry picked from commit 14f5ef756b)
2022-02-17 04:28:05 +00:00
taku0
2f0ccb7cd7 thunderbird-bin: 91.5.1 -> 91.6.1
(cherry picked from commit 27b06df6e0)
2022-02-17 04:28:05 +00:00
github-actions[bot]
00d5229c6a Merge staging-next-21.11 into staging-21.11 2022-02-17 00:10:33 +00:00
github-actions[bot]
6def7ac40d Merge release-21.11 into staging-next-21.11 2022-02-17 00:09:53 +00:00
Jean-Francois Chevrette
d404b5ff04 add jfchevrette as maintainers
(cherry picked from commit 8102b3efe0da8a7527597f8ec43e05f801413dde)
2022-02-16 23:59:34 +00:00
Jean-Francois Chevrette
b60594109e add support for aarch64-darwin and x86_64-darwin
(cherry picked from commit 23b88f85c8797337038f090895973d211968d64a)
2022-02-16 23:59:34 +00:00
Pascal Bach
62a2a1be29 Merge pull request #160368 from NixOS/backport-160270-to-release-21.11
[Backport release-21.11] Update Nextcloud
2022-02-16 21:35:47 +01:00
TredwellGit
4124cb932b nextcloud22: 22.2.4 -> 22.2.5
https://github.com/nextcloud/server/releases/tag/v22.2.5
(cherry picked from commit 27bc756249)
2022-02-16 20:32:30 +00:00
TredwellGit
c16976ee40 nextcloud21: 21.0.8 -> 21.0.9
https://github.com/nextcloud/server/releases/tag/v21.0.9
(cherry picked from commit 7602ca0e8e)
2022-02-16 20:32:30 +00:00
TredwellGit
7b386c0aba nextcloud23: 23.0.1 -> 23.0.2
https://github.com/nextcloud/server/releases/tag/v23.0.2
(cherry picked from commit f4c0c77682)
2022-02-16 20:32:30 +00:00
Michael Weiss
9fe60667c8 Merge pull request #160362 from NixOS/backport-160354-to-release-21.11
[Backport release-21.11] chromium: 98.0.4758.80 -> 98.0.4758.102
2022-02-16 21:15:16 +01:00
Michael Weiss
070a5db7b2 Merge pull request #160356 from NixOS/backport-160274-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 98.0.4758.80 -> 98.0.4758.102
2022-02-16 21:14:47 +01:00
Nikolay Amiantov
5d93176952 nixos/manual: use system nixpkgs to build pxe image
The command in example is expected to be run from nixpkgs checkout, but
there's no explanation of this. Let's just use system nixpkgs: most
users will have it just working and those who use git checkouts will
figure it out.

(cherry picked from commit bd7a47e27b4b25984e53e0e50735f3a3ad574cf2)
2022-02-16 22:54:44 +03:00
Michael Weiss
765547221e chromium: 98.0.4758.80 -> 98.0.4758.102
https://chromereleases.googleblog.com/2022/02/stable-channel-update-for-desktop_14.html

This update includes 11 security fixes. Google is aware of reports that
an exploit for CVE-2022-0609 exists in the wild.

CVEs:
CVE-2022-0603 CVE-2022-0604 CVE-2022-0605 CVE-2022-0606 CVE-2022-0607
CVE-2022-0608 CVE-2022-0609 CVE-2022-0610

(cherry picked from commit 7e948a6c9a)
2022-02-16 19:53:15 +00:00
Michael Adler
63cf81a827 ungoogled-chromium: 98.0.4758.80 -> 98.0.4758.102
(cherry picked from commit 46d1691d5c)
2022-02-16 19:17:16 +00:00
Thomas Gerbet
43cb6598c0 mysql: 8.0.27 -> 8.0.28
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-28.html
(cherry picked from commit b054a140f4)
2022-02-16 19:02:36 +01:00
R. Ryantm
f209a49be2 mysql80: 8.0.26 -> 8.0.27
(cherry picked from commit bfd6db1574)
2022-02-16 19:02:22 +01:00
nixpkgs-upkeep-bot
7c3e91f979 vscode: 1.64.0 -> 1.64.2
(cherry picked from commit 55834d4ca5)
2022-02-16 11:32:12 +00:00
Manuel Bärenz
2128d0aa28 Merge pull request #158417 from NixOS/backport-158200-to-release-21.11
[Backport release-21.11] vscode, vscodium: 1.63.2 -> 1.64.0
2022-02-16 12:27:25 +01:00
Pavol Rusnak
8b4a40e452 Merge pull request #160306 from prusnak/electron-21.11
[21.11] update Electron
2022-02-16 12:10:24 +01:00
TredwellGit
558c4796a5 electron_16: 16.0.8 -> 16.0.9
https://github.com/electron/electron/releases/tag/v16.0.9
(cherry picked from commit 41de21a2a1)
2022-02-16 10:44:10 +01:00
TredwellGit
22afbdc630 electron_15: 15.3.6 -> 15.3.7
https://github.com/electron/electron/releases/tag/v15.3.7
(cherry picked from commit f2c15707a7)
2022-02-16 10:44:05 +01:00
TredwellGit
62dd7a2ac2 electron_14: 14.2.5 -> 14.2.6
https://github.com/electron/electron/releases/tag/v14.2.6
(cherry picked from commit e7ce85d8d4)
2022-02-16 10:43:57 +01:00
github-actions[bot]
f72c47f948 Merge staging-next-21.11 into staging-21.11 2022-02-16 00:11:11 +00:00
github-actions[bot]
fff6d2126d Merge release-21.11 into staging-next-21.11 2022-02-16 00:10:34 +00:00
Michael Weiss
cdc68dca91 Merge pull request #160064 from NixOS/backport-158143-to-release-21.11
[Backport release-21.11] signal-desktop: 5.29.1 -> 5.30.0
2022-02-15 22:35:16 +01:00
Martin Weinelt
ed065cad8e speex: patch zero division vector in wave header parser
Fixes: CVE-2020-23903
(cherry picked from commit 1eb584fc15)
2022-02-15 12:47:34 -08:00
Robert Scott
bc900d7db9 Merge pull request #160185 from mweinelt/21.11/icecat
[21.11] icecat-bin: mark as insecure
2022-02-15 20:33:02 +00:00
Ryan Mulligan
991b145894 Merge pull request #160044 from NixOS/backport-157646-to-release-21.11
[Backport release-21.11] discourse: 2.8.0.beta11 -> 2.9.0.beta1
2022-02-15 10:43:58 -08:00
Guillaume Girol
cfa94453ad Merge pull request #160078 from NixOS/backport-157197-to-release-21.11
[Backport release-21.11] btdu: init at 0.3.1
2022-02-15 17:48:33 +00:00
Martin Weinelt
4f80d46c5e icecat-bin: mark as insecure
This was EOL by the time it was introduced into nixpkgs and should have
never gotten merged in the first place.

Browsers are complex beasts, and those that haven't seen an update in
two years simply cannot be secure.
2022-02-15 17:11:32 +01:00
Daniel Olsen
b207cc18eb hydrus: 472 -> 473
(cherry picked from commit 5f909309d2)
2022-02-15 13:28:50 +00:00
Átila Saraiva
f873a41b5e btdu: init at 0.3.1
(cherry picked from commit df600977da)
2022-02-15 01:03:26 +00:00
Átila Saraiva
4c4363597a maintainer: add atila
(cherry picked from commit a773c4cdcf)
2022-02-15 01:03:26 +00:00
github-actions[bot]
e37bad8fce Merge staging-next-21.11 into staging-21.11 2022-02-15 00:11:33 +00:00
github-actions[bot]
590d78c977 Merge release-21.11 into staging-next-21.11 2022-02-15 00:10:59 +00:00
github-actions[bot]
6e23cb0fa9 gitlab: 14.7.1 -> 14.7.2 (#159908)
https://about.gitlab.com/releases/2022/02/08/gitlab-14-7-2-released/
(cherry picked from commit 9fdd3875dc)

Co-authored-by: Lara <lara@uwu.is>
2022-02-15 00:41:28 +01:00
R. Ryantm
a2c3f74100 signal-desktop: 5.29.1 -> 5.30.0
(cherry picked from commit 40bc60f594)
2022-02-14 23:00:24 +00:00
Ryan Mulligan
fa89761ad9 discourse: 2.8.0.beta11 -> 2.9.0.beta1
(cherry picked from commit c0ddbde02f)
2022-02-14 20:46:53 +00:00
Izorkin
f323d9574b modsecurity-crs: init at 3.3.2
(cherry picked from commit 8b37c4d5c4)
2022-02-14 19:01:05 +00:00
Izorkin
2f1d271615 nginxModules.modsecurity-nginx: 1.0.1 -> 1.0.2
(cherry picked from commit 842d0d9ed7)
2022-02-14 19:01:05 +00:00
Izorkin
e7ba2cfbb3 libmodsecurity: 3.0.4 -> 3.0.6
(cherry picked from commit 3240410ac0)
2022-02-14 19:01:05 +00:00
Artturi
8a9cd45885 Merge pull request #159979 from NixOS/backport-159769-to-release-21.11 2022-02-14 16:36:33 +02:00
R. Ryantm
0527698d93 psi-plus: 1.5.1596 -> 1.5.1600
(cherry picked from commit 9df062704e)
2022-02-14 12:08:55 +00:00
Vladimír Čunát
a03ae0e6d0 Merge #158493: staging-next: 21.11 iteration 7 - 2022-02-07 2022-02-14 12:16:40 +01:00
github-actions[bot]
b400ca31a9 Merge staging-next-21.11 into staging-21.11 2022-02-14 00:10:52 +00:00
github-actions[bot]
fbb8dd1ea9 Merge release-21.11 into staging-next-21.11 2022-02-14 00:10:14 +00:00
Robert Schütz
b61bf7a96a imagemagick: 7.1.0-23 -> 7.1.0-24
https://github.com/ImageMagick/ImageMagick/blob/7.1.0-24/ChangeLog
(cherry picked from commit 5a07a32f30)
2022-02-13 23:58:28 +01:00
Martin Weinelt
69f5b013a5 postfix: 3.6.4 -> 3.6.5
http://www.postfix.org/announcements/postfix-3.6.5.html
(cherry picked from commit 31b5e1998d)
2022-02-13 17:50:27 +00:00
Martin Weinelt
840bd34563 Merge pull request #159688 from NixOS/backport-158816-to-release-21.11 2022-02-13 18:45:07 +01:00
Mario Rodas
c28fb0a467 Merge pull request #159723 from mweinelt/21.11/timescaledb
[21.11] postgresqlPackages.timescaledb: 2.5.0 -> 2.5.1
2022-02-13 06:06:20 -05:00
Martin Weinelt
b387b73606 wireshark: 3.4.11 -> 3.4.12
https://www.wireshark.org/docs/relnotes/wireshark-3.4.12.html

Fixes: CVE-2021-4190
2022-02-12 20:15:52 -08:00
Mario Rodas
705b9d44c8 postgresqlPackages.timescaledb: 2.5.1 -> 2.5.2
https://github.com/timescale/timescaledb/releases/tag/2.5.2
(cherry picked from commit db885e4c25)
2022-02-13 03:16:08 +01:00
Mario Rodas
89b7cd0f2e postgresqlPackages.timescaledb: 2.5.0 -> 2.5.1
https://github.com/timescale/timescaledb/releases/tag/2.5.1
(cherry picked from commit 0bf7da2e18)
2022-02-13 03:16:04 +01:00
github-actions[bot]
31c096b31d Merge staging-next-21.11 into staging-21.11 2022-02-13 00:12:00 +00:00
github-actions[bot]
75098e6519 Merge release-21.11 into staging-next-21.11 2022-02-13 00:11:18 +00:00
Mario Rodas
d6570631ca Merge pull request #159690 from NixOS/backport-159674-to-staging-21.11
[Backport staging-21.11] postgresql: 10.19 -> 10.20, 11.14 -> 11.15, 12.9 -> 12.10, 13.5 -> 13.6, 14.1 -> 14.2
2022-02-12 18:58:38 -05:00
Martin Weinelt
ad4ff657e0 Merge pull request #158722 from risicle/ris-pillow-CVE-2022-22817p2-CVE-2022-24303-r21.11 2022-02-13 00:57:37 +01:00
Martin Weinelt
1a1499ff64 Merge pull request #159102 from NixOS/backport-158817-to-release-21.11 2022-02-13 00:34:09 +01:00
Mario Rodas
112517da52 postgresql_14: 14.1 -> 14.2
https://www.postgresql.org/docs/release/14.2/
(cherry picked from commit 4cc1cb3646)
2022-02-12 23:25:22 +00:00
Mario Rodas
5e68e04406 postgresql_13: 13.5 -> 13.6
https://www.postgresql.org/docs/release/13.6/
(cherry picked from commit 42722790c8)
2022-02-12 23:25:22 +00:00
Mario Rodas
37e20df79d postgresql_12: 12.9 -> 12.10
https://www.postgresql.org/docs/release/12.10/
(cherry picked from commit c6b58fecd0)
2022-02-12 23:25:22 +00:00
Mario Rodas
b9f705f899 postgresql_11: 11.14 -> 11.15
https://www.postgresql.org/docs/release/11.15/
(cherry picked from commit 726aad3796)
2022-02-12 23:25:22 +00:00
Mario Rodas
505b2773d7 postgresql_10: 10.19 -> 10.20
https://www.postgresql.org/docs/release/10.20/
(cherry picked from commit fb3637ef1d)
2022-02-12 23:25:22 +00:00
ajs124
b23b334f15 matrix-synapse: 1.51.0 -> 1.52.0
(cherry picked from commit 62eb700727)
2022-02-12 23:12:57 +00:00
Artturi
34e7171c68 Merge pull request #159632 from NixOS/backport-159112-to-release-21.11
[Backport release-21.11] discord-canary: 0.0.132 -> 0.0.133
2022-02-12 22:20:42 +02:00
wackbyte
f7188fa63b discord-canary: 0.0.280 -> 0.0.283 (darwin)
(cherry picked from commit 3e5aee615b)
2022-02-12 19:31:45 +00:00
wackbyte
12a57b4bba discord-canary: 0.0.132 -> 0.0.133 (linux)
(cherry picked from commit 8bfdab3549)
2022-02-12 19:31:45 +00:00
Devin Singh
d525154528 discord-ptb: 0.0.58 -> 0.0.59
(cherry picked from commit adebfd54d4)
2022-02-12 10:35:02 -08:00
Artturi
446f106e13 Merge pull request #159584 from NixOS/backport-155020-to-release-21.11 2022-02-12 19:17:07 +02:00
Devin Singh
a38a57b623 discord: add derivations for {x86_64,aarch64}-darwin
(cherry picked from commit 8a6cde9143)
2022-02-12 16:42:11 +00:00
Nicolas Benes
534b76d3c9 tor-browser-bundle-bin: 11.0.4 -> 11.0.6
(cherry picked from commit c0350b9e43)
2022-02-12 08:39:40 -08:00
Samuel Gräfenstein
9b9877b76f ungoogled-chromium: fix build
(cherry picked from commit 157807406c)
2022-02-12 08:37:56 -08:00
Michael Weiss
35c586725f ungoogled-chromium: 97.0.4692.99 -> 98.0.4758.80
(cherry picked from commit a12cfff5b2)
2022-02-12 08:37:56 -08:00
Artturi
8233c34175 Merge pull request #159577 from NixOS/backport-153835-to-release-21.11 2022-02-12 18:36:53 +02:00
Joel
6eb8fc7863 discord-ptb: 0.0.26 -> 0.0.27
(cherry picked from commit ff11138831)
2022-02-12 16:12:34 +00:00
Artturi
291835cbb9 Merge pull request #157051 from NixOS/backport-157019-to-release-21.11 2022-02-12 17:47:54 +02:00
Mario Rodas
6582b4c3d2 Merge pull request #157182 from NixOS/backport-157150-to-release-21.11
[Backport release-21.11] bcachefs: 2021-12 -> 2022-01
2022-02-12 09:17:32 -05:00
Mario Rodas
2ef44a4451 Merge pull request #159547 from NixOS/backport-159015-to-release-21.11
[Backport release-21.11] rbw: 1.4.1 -> 1.4.3
2022-02-12 08:52:22 -05:00
Congee
c227ea5412 rbw: 1.4.1 -> 1.4.3
(cherry picked from commit 596543f23d)
2022-02-12 13:20:35 +00:00
Kim Lindberger
e20d05b1e7 Merge pull request #159502 from NixOS/backport-159266-to-release-21.11
[Backport release-21.11] nomachine-client: 7.6.2 -> 7.8.2
2022-02-12 11:47:01 +01:00
talyz
4375594517 nomachine-client: 7.6.2 -> 7.8.2
(cherry picked from commit d68d1caa84)
2022-02-12 10:41:30 +00:00
Vladimír Čunát
55ce6168d2 Re-revert "firefox: 96.0.3 -> 97.0"
This reverts commit f17a7eee8d.
/cc the original PR #158663.
2022-02-12 08:59:20 +01:00
Vladimír Čunát
5d5add4d89 Merge branch 'release-21.11' into staging-next-21.11 2022-02-12 08:58:21 +01:00
Vladimír Čunát
a059230e1c Merge #158663: firefox + thunderbird updates
...into release-21.11
This time really with excluding the update of `firefox` attribute.

(Sigh, once again I got caught by refs/remotes/pr/$num on GitHub
 being updated slower than anticipated.)
2022-02-12 08:54:21 +01:00
Vladimír Čunát
2a91047efa Merge #158663: firefox + thunderbird updates
...into release-21.11
But the main update of `firefox` attribute to 97 was not included yet.
2022-02-12 08:51:24 +01:00
Vladimír Čunát
f17a7eee8d Revert "firefox: 96.0.3 -> 97.0"
This reverts commit 6c4ce75c8b.
It needs updated nss; let's do this later (e.g. staging-next-21.11).
2022-02-12 08:50:03 +01:00
github-actions[bot]
1030cafcdc Merge staging-next-21.11 into staging-21.11 2022-02-12 00:11:19 +00:00
github-actions[bot]
3b879e6fd0 Merge release-21.11 into staging-next-21.11 2022-02-12 00:10:45 +00:00
Maximilian Bosch
b1396e289d Merge pull request #159231 from NixOS/backport-158634-to-release-21.11
[Backport release-21.11] Linux kernels 2022-02-08
2022-02-11 18:35:08 +01:00
TredwellGit
8124d17ead linux/hardened/patches/5.4: 5.4.176-hardened1 -> 5.4.177-hardened1
(cherry picked from commit 7083902015)
2022-02-11 12:45:59 +00:00
TredwellGit
4f74d1d570 linux/hardened/patches/5.15: 5.15.19-hardened1 -> 5.15.21-hardened1
(cherry picked from commit c1247874a0)
2022-02-11 12:45:59 +00:00
TredwellGit
81e0e74210 linux/hardened/patches/5.10: 5.10.96-hardened1 -> 5.10.98-hardened1
(cherry picked from commit eb1f381ef7)
2022-02-11 12:45:59 +00:00
TredwellGit
b492fbc02a linux-rt_5_4: 5.4.170-rt68 -> 5.4.177-rt69
(cherry picked from commit bfebdb721a)
2022-02-11 12:45:59 +00:00
TredwellGit
0f0bb6944b linux: 5.4.177 -> 5.4.178
(cherry picked from commit 47b93d55ca)
2022-02-11 12:45:59 +00:00
TredwellGit
b715301ed5 linux: 5.16.7 -> 5.16.8
(cherry picked from commit 66d35b39d2)
2022-02-11 12:45:59 +00:00
TredwellGit
61f1e87f95 linux: 5.15.21 -> 5.15.22
(cherry picked from commit 1bc4054d28)
2022-02-11 12:45:59 +00:00
TredwellGit
ad14be2575 linux: 5.10.98 -> 5.10.99
(cherry picked from commit 0de53960d0)
2022-02-11 12:45:59 +00:00
TredwellGit
f6d4365a7e linux: 4.9.299 -> 4.9.300
(cherry picked from commit 8bdae55b6d)
2022-02-11 12:45:59 +00:00
TredwellGit
6f1e5f2768 linux: 4.19.227 -> 4.19.228
(cherry picked from commit c8b3b1b1ab)
2022-02-11 12:45:59 +00:00
TredwellGit
07e5b2d2d6 linux: 4.14.264 -> 4.14.265
(cherry picked from commit 8cb0337364)
2022-02-11 12:45:59 +00:00
Linus Heckemann
c8c5faff75 Merge pull request #159215 from NixOS/backport-158948-to-release-21.11
[Backport release-21.11] hydra-unstable: remove `ma27` from maintainer list
2022-02-11 13:35:58 +01:00
Maximilian Bosch
ce822131e3 hydra-unstable: remove ma27 from maintainer list
I'm deploying my own Hydra via flakes for a while now and while this
package actually needs more love and a few updates, I don't have the
capacity to take care of this.

(cherry picked from commit a215ce7fa5)
2022-02-11 11:45:33 +00:00
Martin Weinelt
cb25e2d276 grafana: 8.3.5 -> 8.3.6
(cherry picked from commit f7364c195c)
2022-02-11 01:35:07 +00:00
github-actions[bot]
0609d8e890 Merge staging-next-21.11 into staging-21.11 2022-02-11 00:11:52 +00:00
github-actions[bot]
11eeca4528 Merge release-21.11 into staging-next-21.11 2022-02-11 00:11:14 +00:00
Jörg Thalheim
bce8fb8760 radare2: 5.5.4 -> 5.6.0
(cherry picked from commit 90afb85ad3)
2022-02-10 14:01:39 -08:00
Sergei Trofimovich
357503c90d radare2: 5.5.2 -> 5.5.4
(cherry picked from commit 174e7331bf)
2022-02-10 14:01:39 -08:00
Jörg Thalheim
0288286720 radare2: 5.4.2 -> 5.5.2
(cherry picked from commit 6fa6514e56)
2022-02-10 14:01:39 -08:00
R. Ryantm
e4e8e5b2dc brave: 1.35.100 -> 1.35.101
(cherry picked from commit b9b0cb220f5fe4adc163244fd50ee142b5fad77e)
2022-02-10 11:46:55 -08:00
Renaud
731da64d26 Merge pull request #155771 from NixOS/backport-155568-to-release-21.11
[Backport release-21.11] palemoon: 29.4.3 -> 29.4.4
2022-02-10 19:11:58 +01:00
Renaud
cd655d3845 Merge pull request #158991 from NixOS/backport-157571-to-release-21.11
[Backport release-21.11] anki: apply patch to replace deprecated method
2022-02-10 18:33:33 +01:00
rnhmjoj
0a46bf0f5f ddcutil: 1.2.1 -> 1.2.2
(cherry picked from commit fb12f39f36)
2022-02-10 09:15:24 -08:00
Berk Ozkutuk
23c64c234f anki: apply patch to replace deprecated method
(cherry picked from commit 38fa6d6041)
2022-02-10 16:59:19 +00:00
Renaud
0d1d5d7e36 Merge pull request #157587 from NixOS/backport-157431-to-release-21.11
[Backport release-21.11] perlPackages.Appcpanminus: 1.7044 -> 1.7045, patch https by default
2022-02-10 17:34:19 +01:00
Renaud
cbd1d07130 Merge pull request #157613 from NixOS/backport-157600-to-release-21.11
[Backport release-21.11] confluent-cli: init at 2.4.0
2022-02-10 17:27:09 +01:00
Will
7adc9c14ec spidermonkey_91: 91.4.0 -> 91.6.0
(cherry picked from commit 3e75cee198)
2022-02-09 21:58:03 -08:00
Franz Pletz
85347dff3a grafana: 8.3.4 -> 8.3.5
https://grafana.com/blog/2022/02/08/grafana-7.5.15-and-8.3.5-released-with-moderate-severity-security-fixes

Fixes CVE-2022-21702, CVE-2022-21703, CVE-2022-21713.

(cherry picked from commit 94c73cb74f)
2022-02-09 21:24:38 -08:00
R. Ryantm
5612d18274 webkitgtk: 2.34.4 -> 2.34.5
https://webkitgtk.org/2022/02/09/webkitgtk2.34.5-released.html
https://webkitgtk.org/security/WSA-2022-0002.html

Fixes: CVE-2022-22589, CVE-2022-22590, CVE-2022-22592
(cherry picked from commit 641899248d)
2022-02-09 21:23:22 -08:00
Guillaume Girol
ebd90a47ca collectd: don't build with xen plugin by default
xen was marked as insecure

(cherry picked from commit 0955a4fa35)
2022-02-09 21:21:56 -08:00
Guillaume Girol
23110dec7a nixos/collectd: add nixos test
(cherry picked from commit b55a253e15)
2022-02-09 21:21:56 -08:00
rnhmjoj
fb6e2df571 nixos/wireless: don't attempt fallback on WPA3 only networks
(cherry picked from commit 3b8fa47f58)
2022-02-09 21:15:53 -08:00
rnhmjoj
841700a6a7 nixos/wireless: implement opportunistic WPA3
It turns out it's actually possible to fall back to WPA2 in case the
authentication fails with WPA3. This was suggested to me in the hostapd
mailing list: add another network block with only WPA2 and lower
priority, for each network with WPA3. For clients with missing/broken
WPA3, wpa_supplicant will:

1. try the network block with higher priority first
2. fail and temporarily disable the network block
3. try the fallback network block and connect

This takes a little more time (still <5s) because wpa_supplicant
retries a couple times before disabling the network block, but it allows
old client to gracefully fall back to WPA2 on mixed WPA2/WPA3 networks.

To avoid downgrade attacks, clients with proper WPA3 should disable
this; in the future we may want to disable this option by default.

(cherry picked from commit 2eed89bbe1)
2022-02-09 21:15:53 -08:00
rnhmjoj
ad8028720e nixos/wireless: enable PMF by default
Alternative solution to PR #152443.
This fixes authentication failures to WPA3 networks (issue #151729)
by enabling protected management frames.
Note: old client without 802.11w support will still fail.

(cherry picked from commit 2f5ced6d7c)
2022-02-09 21:15:53 -08:00
Renaud
7c42c4e3f1 chef-dk: install all binaries
When using pname+version all binaries other than `chef` are missing

Fixes #70171

(cherry picked from commit e73edac05b)
2022-02-09 21:13:20 -08:00
Martin Weinelt
241ef81f32 microcodeIntel: 20210608 -> 20220207
https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20220207
(cherry picked from commit 1189d2c1f1)
2022-02-09 21:11:38 -08:00
Bobby Rong
457e70297b Merge pull request #158235 from NixOS/backport-157917-to-release-21.11
[Backport release-21.11] hydrus: 471 -> 472
2022-02-10 10:45:59 +08:00
github-actions[bot]
c60197bad1 Merge staging-next-21.11 into staging-21.11 2022-02-10 00:11:42 +00:00
github-actions[bot]
999239e1ab Merge release-21.11 into staging-next-21.11 2022-02-10 00:11:07 +00:00
Robert Schütz
fe56b7e73a Merge pull request #158387 from greizgh/seahub-8.0.8
[21.11] seahub: 8.0.7 -> 8.0.8
2022-02-09 19:53:34 +00:00
Vladimír Čunát
a1cbd313e1 Merge #158139: stdenv/check-meta: add note for Flake usage
...into release-21.11
2022-02-09 20:03:12 +01:00
Kerstin Humm
36043abed1 imagemagick: 7.1.0-22 -> 7.1.0-23
(cherry picked from commit 884b8ebc8e)
2022-02-09 18:59:11 +01:00
Andreas
d1f73e6ed3 Falkon: 3.1.0 -> 3.2.0
(cherry picked from commit 49ff7e72e48f8e3849f09f20991135219c12e147)
2022-02-09 06:19:27 -08:00
Maximilian Bosch
6ae70d9699 Merge pull request #158784 from NixOS/backport-158723-to-release-21.11
[Backport release-21.11] epson-escpr2: 1.1.45 -> 1.1.46
2022-02-09 15:12:26 +01:00
Maximilian Bosch
e6151292b6 Merge pull request #158785 from NixOS/backport-158691-to-release-21.11
[Backport release-21.11] passExtensions.pass-audit: 1.1 -> 1.2
2022-02-09 15:12:18 +01:00
ajs124
e47a6cc920 nss: 3.74 -> 3.75
(cherry picked from commit de76433f54)
2022-02-09 06:08:07 -08:00
ajs124
d5114ad3b1 nss: 3.73.1 -> 3.74
(cherry picked from commit da28ed7df0)
2022-02-09 06:08:07 -08:00
R. RyanTM
a580eeda1b nss: 3.73 -> 3.73.1 (#151041)
(cherry picked from commit 8a4345ee0d)
2022-02-09 06:08:07 -08:00
Markus S. Wamser
254aac5fac pythonPackages.cchardet: fix build on non-x86_64
(cherry picked from commit 34afacfd78)
+ align python test invocation with master
2022-02-09 06:06:07 -08:00
Maximilian Bosch
5b8e9052ba passExtensions.pass-audit: 1.1 -> 1.2
ChangeLog: https://github.com/roddhjav/pass-audit/blob/v1.2/CHANGELOG.md#12---2022-01-30
(cherry picked from commit d34a465327)
2022-02-09 13:43:43 +00:00
Maximilian Bosch
426dccd39c epson-escpr2: 1.1.45 -> 1.1.46
(cherry picked from commit 69e2db3900)
2022-02-09 13:42:56 +00:00
Vladimír Čunát
585b60b938 thunderbird: 91.5.1 -> 91.6.0
This also fixes build after firefox-esr update (commit 95fab681e2)
https://www.thunderbird.net/en-US/thunderbird/91.6.0/releasenotes/

(cherry picked from commit ca54a649b6)
2022-02-09 10:09:10 +01:00
github-actions[bot]
263898f0ae Merge staging-next-21.11 into staging-21.11 2022-02-09 00:10:47 +00:00
github-actions[bot]
e616bc0785 Merge release-21.11 into staging-next-21.11 2022-02-09 00:10:03 +00:00
Robert Scott
e49f6a66e6 python3Packages.pillow: add patches for CVE-2022-22817 (part 2) & CVE-2022-24303 2022-02-08 22:43:23 +00:00
Robert Scott
592b893530 Merge pull request #156397 from NixOS/backport-155457-to-release-21.11
[Backport release-21.11] onionshare: 2.4 -> 2.5
2022-02-08 22:09:26 +00:00
Naïm Favier
f35868c968 packages-config.nix: ignore haskellPackages.hs-mesos 2022-02-08 22:03:34 +01:00
Naïm Favier
203b75a160 rPackages: fix evaluation
Removes uses of aliases
2022-02-08 22:03:34 +01:00
Guillaume Girol
59db851ddf evolution-data-server: 3.42.2 -> 3.42.3
(cherry picked from commit aba6be0888)
2022-02-08 12:50:15 -08:00
R. Ryantm
12f5595c99 evolution-data-server: 3.42.1 -> 3.42.2
(cherry picked from commit 74d8cc0190)
2022-02-08 12:50:15 -08:00
Vladimír Čunát
61204aa82e knot-dns: 3.1.5 -> 3.1.6
https://gitlab.nic.cz/knot/knot-dns/-/tags/v3.1.6
(cherry picked from commit 92b6d3e35b6c6cea6cf61cdade79902bb722fcaf)
2022-02-08 12:26:10 -08:00
ajs124
ece421e837 jitsi-meet-electron: 2.8.11 -> 2022.1.1
(cherry picked from commit f38985d36981b8c4527419b7d4f22449570875b6)
2022-02-08 12:06:00 -08:00
Jonathan Ringer
f8abd95c57 release.nix: fix packages.json.br for tarball
(cherry picked from commit 3ff943fbb87382f69fbed0245c37e7c5e7c97b97)
2022-02-08 11:39:00 -08:00
Martin Weinelt
bb26eae716 firefox-bin: 96.0.3 -> 97.0
(cherry picked from commit f448fc7394)
2022-02-08 20:30:55 +01:00
Martin Weinelt
95fab681e2 firefox-esr-91: 91.5.1esr -> 91.6.0esr
(cherry picked from commit 38219f7cc7)
2022-02-08 20:30:54 +01:00
Martin Weinelt
6c4ce75c8b firefox: 96.0.3 -> 97.0
(cherry picked from commit a41acde05c)
2022-02-08 20:30:54 +01:00
Alyssa Ross
d41e24ae77 rustc_1_57: init at 1.57.0
(cherry picked from commit f56f3f7dcc)
2022-02-08 20:30:49 +01:00
Maximilian Bosch
a47f6c3006 clickhouse-backup: init at 1.2.2
Tool to create & restore backups of ClickHouse databases with support
for miscellaneous cloud storages.

(cherry picked from commit 6020c755ed)
2022-02-08 11:18:50 -08:00
Tom Prince
1056d54a73 amazon-ec2-utils: 1.2 -> 2.0
This also replaces the ec2-utils package, which is an older version.

(cherry picked from commit 653a3e4ed0)
2022-02-08 09:56:45 -08:00
Erik Arvstedt
937c428faa nixos/nginx: remove @mincore from SystemCallFilter
cherry picked from commit 26ea046ed7

See: https://github.com/NixOS/nixpkgs/pull/148695
2022-02-08 09:52:12 -08:00
Kerstin Humm
f146593b4b nixos/documentation: add placeholder option meta.buildDocsInSandbox for backwards compat 2022-02-08 09:45:55 -08:00
Vincent Laporte
4d6f58a94e ocamlPackages.core: 0.11.2 → 0.11.3
(cherry picked from commit c41a96b876125784771de99173a5de88be51159c)
2022-02-08 09:44:52 -08:00
Lassulus
963fe43513 Merge pull request #158097 from NixOS/backport-152770-to-release-21.11
[Backport release-21.11] nixos/hardware/hackrf: new module
2022-02-08 14:58:15 +01:00
Vincent Laporte
c028f42d38 ocamlPackages.ocsigen_server: fix install
(cherry picked from commit b0a3ceae85)
2022-02-08 13:05:17 +01:00
Pavol Rusnak
11a998f6cb Merge pull request #158574 from NixOS/backport-158555-to-release-21.11
[Backport release-21.11] electron: mark versions <= 13 as EOL
2022-02-08 10:12:25 +01:00
Brandon Weeks
0da8d17312 electron: mark versions <= 13 as EOL
(cherry picked from commit 0184f0e0a5)
2022-02-08 08:55:51 +00:00
Vladimír Čunát
5081b7d711 Merge #158540: CODEOWNERS: fix jonringer entry (into release-21.11) 2022-02-08 09:27:56 +01:00
Greizgh
cfbbb9133c seahub: init at 8.0.8
(cherry picked from commit 4094fcb66f)
2022-02-08 08:05:08 +01:00
Robert Schütz
b07e43801f python3Packages.seahub: remove
It is not a Python module.

(cherry picked from commit f081decbac)
2022-02-08 08:04:41 +01:00
Robert Schütz
61f39604d0 python3Packages.seaserv: use correct Python version
(cherry picked from commit 23b5627b7a)
2022-02-08 08:04:32 +01:00
Robert Schütz
bbff4aa072 python3Packages.pysearpc: use correct Python version
(cherry picked from commit 14ded1fd6f)
2022-02-08 08:04:27 +01:00
Renaud
6694ab975b mailutils: 3.12 -> 3.13
Announce: https://lists.gnu.org/archive/html/info-gnu/2021-08/msg00002.html

This release disables escape sequences in non-interactive mode,
fixing vulnerabilities associated with `fail2ban` or `smartd`

Fixes #133951
Closes #158397

(cherry picked from commit 199f5ef929)
2022-02-07 19:03:25 -08:00
Jonathan Ringer
9c856b7d91 CODEOWNERS: fix jonringer entry 2022-02-07 18:48:49 -08:00
github-actions[bot]
2df89328b7 Merge staging-next-21.11 into staging-21.11 2022-02-08 00:11:14 +00:00
github-actions[bot]
7af5814475 Merge release-21.11 into staging-next-21.11 2022-02-08 00:10:40 +00:00
Franz Pletz
df6de0bb8b Merge pull request #158363 from NixOS/backport-158237-to-release-21.11 2022-02-07 21:45:48 +01:00
Vladimír Čunát
9952879fe2 Merge branch 'staging-21.11' into staging-next-21.11 2022-02-07 18:17:19 +01:00
Vladimír Čunát
528f5aba15 Merge #152227: gstreamer: backport device discovery fix
...into staging-21.11
2022-02-07 18:11:17 +01:00
Martin Weinelt
ce392883ae Merge pull request #157285 from LeSuisse/jadx-1.3.2-21.11 2022-02-07 15:44:57 +01:00
Bobby Rong
c9045e3d7b Merge pull request #158458 from NixOS/backport-158445-to-release-21.11
[Backport release-21.11] vscode-extensions.stkb.rewrap: 1.16.0 -> 1.16.1
2022-02-07 19:01:26 +08:00
Bobby Rong
dca166c154 Merge pull request #158457 from NixOS/backport-158446-to-release-21.11
[Backport release-21.11] vscode-extensions.davidanson.vscode-markdownlint: 0.45.0 -> 0.46.0
2022-02-07 19:01:10 +08:00
datafoo
9943920fc8 vscode-extensions.stkb.rewrap: 1.16.0 -> 1.16.1
(cherry picked from commit c53cdc07d0)
2022-02-07 10:15:47 +00:00
datafoo
7bf46ff347 vscode-extensions.davidanson.vscode-markdownlint: 0.45.0 -> 0.46.0
(cherry picked from commit 97e6067dd9)
2022-02-07 10:14:45 +00:00
Bobby Rong
df71cad777 vscodium: 1.63.2 -> 1.64.0
(cherry picked from commit 6d982a2c88)
2022-02-07 00:36:34 +00:00
Bobby Rong
7c88dfec0f vscode: 1.63.2 -> 1.64.0
(cherry picked from commit 0c618de480)
2022-02-07 00:36:34 +00:00
Luke Granger-Brown
521e4d7d13 Merge pull request #158383 from NixOS/backport-155927-to-release-21.11
[Backport release-21.11] seafile-server: 8.0.7 -> 8.0.8
2022-02-07 00:29:53 +00:00
github-actions[bot]
c38c12e0aa Merge staging-next-21.11 into staging-21.11 2022-02-07 00:10:47 +00:00
github-actions[bot]
cb949f97ff Merge release-21.11 into staging-next-21.11 2022-02-07 00:10:14 +00:00
Vladimír Čunát
d203279fc3 Merge #158361: libtiff: patch CVE-2022-22844 (into staging-21.11) 2022-02-06 22:27:32 +01:00
Vladimír Čunát
8297db77b8 Merge #158265: glibc: 2.33-108 -> 2.33-117 (into staging-21.11) 2022-02-06 22:26:21 +01:00
Ben Siraphob
1797e3f7b1 Merge pull request #158385 from NixOS/backport-157336-to-release-21.11
[Backport release-21.11] lib: Improve library docs
2022-02-06 20:06:15 +00:00
Jan Tojnar
83a0e092af lib.sources: Improve docs
Change comment type so than nixdoc picks them up into Nixpkgs manual.
Also improve phrasing a bit and move stuff around so that it is formatted better.

(cherry picked from commit 1e1396aafc)
2022-02-06 18:17:51 +00:00
Jan Tojnar
349163c58f lib.trivial: Change comment type before concat function
C-style comment was being picked up by nixdoc as a documentation comment for the function.

(cherry picked from commit 2f012d93ed)
2022-02-06 18:17:51 +00:00
Robert Schütz
a02deddf42 seafile-server: add passthru.tests
(cherry picked from commit adad47dfc2)
2022-02-06 18:08:01 +00:00
Greizgh
6c89cc2564 seafile-server: 8.0.7 -> 8.0.8
(cherry picked from commit e4041ec226)
2022-02-06 18:08:01 +00:00
rnhmjoj
59dd6b67b5 gstreamer: backport device discovery fix
This is a backport of recent changes[1][2] in gstdevicemonitor.c
that fix the device discovery failing entirely when one provider fails
(eg. if pulseaudio support is enabled but no daemon is running).

[1]: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/679
[2]: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/1189
2022-02-06 18:14:31 +01:00
Vladimír Čunát
0208481543 Merge #157461: smarty3: 3.1.39 -> 3.1.44 (into release-21.11) 2022-02-06 16:49:48 +01:00
Robert Hensing
cd1d12ff2d Merge pull request #158267 from jonringer/jonringer-release-CODEOWNER
CODEOWNERS: add jonringer for all backport PRs
2022-02-06 16:42:56 +01:00
7c6f434c
02dc562a03 Merge pull request #158362 from NixOS/backport-158360-to-release-21.11
[Backport release-21.11] firejail: 0.9.66 -> 0.9.68
2022-02-06 15:40:39 +00:00
TredwellGit
2a241df15e linux: 5.4.176 -> 5.4.177
(cherry picked from commit 6961464057)
2022-02-06 15:37:50 +00:00
TredwellGit
eda05f44d1 linux: 5.16.5 -> 5.16.7
(cherry picked from commit d890ab3785)
2022-02-06 15:37:50 +00:00
TredwellGit
cc4ef08c5c linux: 5.15.19 -> 5.15.21
(cherry picked from commit 52dad95367)
2022-02-06 15:37:50 +00:00
TredwellGit
cd76e19fc9 linux: 5.10.96 -> 5.10.98
(cherry picked from commit 671e3e3ab9)
2022-02-06 15:37:50 +00:00
Zane van Iperen
4083a183e8 firejail: 0.9.66 -> 0.9.68
Fixes #153430

(cherry picked from commit 36b1dedddd)
2022-02-06 15:00:28 +00:00
Peter Hoeg
811af3aa01 collectd-data: we only need collectd.src - not collectd.out
(cherry picked from commit b087d2c4989591357966b6226bd552716dbb85b1)
2022-02-06 15:36:45 +01:00
Robert Scott
70440288bc libtiff: add patch for CVE-2022-22844
(cherry-picked from 0f049646e6)
2022-02-06 14:20:36 +00:00
github-actions[bot]
df4f1f7cc3 gocyclo: 2015-02-08 -> 0.4.0 (#158009)
We're pulling from a random fork, so switch to the actual upstream.

Also change to use buildGoModule instead of buildGoPackage.

(cherry picked from commit b8f6ce151a)

Co-authored-by: Zane van Iperen <zane@zanevaniperen.com>
Co-Authored-By: Martin <stackshadow@evilbrain.de>
2022-02-06 13:36:01 +08:00
adisbladis
d49a447c18 Merge pull request #158305 from adisbladis/types-typed-ast-backport
[backport release-21.11] python39Packages.types-typed-ast: init 1.5.1
2022-02-06 12:27:50 +12:00
github-actions[bot]
ec7c7e9acf Merge staging-next-21.11 into staging-21.11 2022-02-06 00:14:36 +00:00
github-actions[bot]
8a898ccbff Merge release-21.11 into staging-next-21.11 2022-02-06 00:14:02 +00:00
Fabian Affolter
ccc8d6c004 python3Packages.types-typed-ast: 1.5.0 -> 1.5.1
(cherry picked from commit 187396f80f)
2022-02-06 11:54:20 +12:00
Sandro Jäckel
ad6f8749c4 python39Packages.types-typed-ast: 1.4.4 -> 1.5.0
(cherry picked from commit 8bd7e5c162)
2022-02-06 11:54:14 +12:00
superherointj
cb1996ed49 python39Packages.types-typed-ast: init 1.4.4
Co-authored-by: @jnetod @veehaitch @nbraud
(cherry picked from commit 5f2f409a26)
2022-02-06 11:53:26 +12:00
Robert Scott
a3996a5396 Merge pull request #158071 from NixOS/backport-158050-to-release-21.11
[Backport release-21.11] graphicsmagick: fix use of delegates in conversions
2022-02-05 21:02:52 +00:00
Jonathan Ringer
7a771785d6 CODEOWNERS: add jonringer for all backport PRs 2022-02-05 11:00:09 -08:00
TredwellGit
c1f2167480 glibc: 2.33-108 -> 2.33-117
(cherry picked from commit f02dc53800)
2022-02-05 18:00:06 +00:00
Sean Buckley
64460348e7 vmware-horizon-client: 2106.1 -> 2111
(cherry picked from commit beb568ccbd)
2022-02-05 17:00:14 +00:00
Luke Granger-Brown
1b55bc5d4b Merge pull request #157885 from pacien/21.11-mercurial-5.9.3-patch-6d2ddea0721a
[21.11] mercurial: backport fix for compat with 6.1
2022-02-05 14:23:20 +00:00
Daniel Olsen
cce6adf133 hydrus: 471 -> 472
(cherry picked from commit d274444a68)
2022-02-05 12:24:32 +00:00
Michele Guerini Rocco
86a930ab2c Merge pull request #158155 from NixOS/backport-157744-to-release-21.11
[Backport release-21.11] qtwebengine: 5.15.7 -> 5.15.8
2022-02-05 10:23:18 +01:00
Rok Garbas
88dcc4ff3b limesurvey: 3.23.7+201006 -> 3.27.33+220125
(cherry picked from commit 53be4bd13c)
2022-02-04 17:56:42 -08:00
github-actions[bot]
cd85df8b4c Merge staging-next-21.11 into staging-21.11 2022-02-05 00:11:42 +00:00
github-actions[bot]
fbc7de473f Merge release-21.11 into staging-next-21.11 2022-02-05 00:10:58 +00:00
Michael Weiss
4c52690cb1 Merge pull request #158160 from NixOS/backport-157878-to-release-21.11
[Backport release-21.11] chromium: 97.0.4692.99 -> 98.0.4758.80
2022-02-04 22:44:45 +01:00
Maximilian Bosch
3d535b8fd7 Merge pull request #158122 from NixOS/backport-157982-to-release-21.11
[Backport release-21.11] Linux kernels 2022-02-03
2022-02-04 22:15:40 +01:00
Michael Weiss
460cdecbb9 chromium: 97.0.4692.99 -> 98.0.4758.80
https://chromereleases.googleblog.com/2022/02/stable-channel-update-for-desktop.html

This update includes 27 security fixes.

CVEs:
CVE-2022-0452 CVE-2022-0453 CVE-2022-0454 CVE-2022-0455 CVE-2022-0456
CVE-2022-0457 CVE-2022-0458 CVE-2022-0459 CVE-2022-0460 CVE-2022-0461
CVE-2022-0462 CVE-2022-0463 CVE-2022-0464 CVE-2022-0465 CVE-2022-0466
CVE-2022-0467 CVE-2022-0468 CVE-2022-0469 CVE-2022-0470

(cherry picked from commit b904f58031)
2022-02-04 21:13:41 +00:00
Michael Weiss
a67236af77 Merge pull request #158036 from primeos/chromium-backport
[21.11] Prepare for backporting Chromium M98
2022-02-04 22:08:26 +01:00
rnhmjoj
59c61b4434 qtwebengine: 5.15.7 -> 5.15.8
(cherry picked from commit 00f80f36d2)
2022-02-04 19:47:57 +00:00
Maximilian Bosch
c5d73b0315 Merge pull request #157762 from Ma27/backport-plausible
[21.11] plausible: 1.4.0 -> 1.4.4 (security)
2022-02-04 20:16:04 +01:00
matthewcroughan
14ffd3027d stdenv/check-meta: add note for Flake usage
Flake users that use a command like `nix build nixpkgs#hello` on a
broken/insecure package will not be able to use an environment variable
to override that behavior, unless they pass `--impure` to the command.

Co-authored-by: pkharvey <kayharvey@protonmail.com>
(cherry picked from commit 36f2aa12e67216f7112e76786728f7842799674e)
2022-02-04 16:44:04 +00:00
Maximilian Bosch
ed0af3c31d Merge pull request #157859 from NixOS/backport-157746-to-release-21.11
[Backport release-21.11] element-{web,desktop}: 1.9.9 -> 1.10.1
2022-02-04 17:21:48 +01:00
TredwellGit
69c39cf6d4 linux/hardened/patches/5.4: 5.4.173-hardened1 -> 5.4.176-hardened1
(cherry picked from commit eaa576d028)
2022-02-04 13:57:02 +00:00
TredwellGit
569a547259 linux/hardened/patches/5.15: 5.15.16-hardened1 -> 5.15.19-hardened1
(cherry picked from commit 3e23004d64)
2022-02-04 13:57:02 +00:00
TredwellGit
429a0deecc linux/hardened/patches/5.10: 5.10.93-hardened1 -> 5.10.96-hardened1
(cherry picked from commit f529fa4f4e)
2022-02-04 13:57:02 +00:00
TredwellGit
cd90acaf2b linux/hardened/patches/4.19: 4.19.225-hardened1 -> 4.19.227-hardened1
(cherry picked from commit 84bf08c27e)
2022-02-04 13:57:02 +00:00
TredwellGit
ca31b487b3 linux/hardened/patches/4.14: 4.14.262-hardened1 -> 4.14.264-hardened1
(cherry picked from commit 665abd5257)
2022-02-04 13:57:02 +00:00
TredwellGit
2e9a6972fa linux_latest-libre: 18517 -> 18587
(cherry picked from commit 35f965fc61)
2022-02-04 13:57:02 +00:00
TredwellGit
b281570497 linux: 5.4.175 -> 5.4.176
(cherry picked from commit 4ee1c3ad90)
2022-02-04 13:57:02 +00:00
TredwellGit
6cba0c8388 linux: 5.16.4 -> 5.16.5
(cherry picked from commit 5aeb99768b)
2022-02-04 13:57:02 +00:00
TredwellGit
e7197b53a8 linux: 5.15.18 -> 5.15.19
(cherry picked from commit af5cda7f79)
2022-02-04 13:57:02 +00:00
TredwellGit
7e0114f13b linux: 5.10.95 -> 5.10.96
(cherry picked from commit a752a2371a)
2022-02-04 13:57:02 +00:00
TredwellGit
627cb4ad48 linux: 4.4.301 -> 4.4.302
(cherry picked from commit 4e53ba1b1b)
2022-02-04 13:57:01 +00:00
Lara
e296ed03e4 nixos/gitlab: Add additional paths to systemd.tmpfiles.rules
This fixes the NixOS gitlab test failure since gitlab 14.7.0.
2022-02-04 11:57:05 +01:00
Lara
613bfe7fd3 [Backport release-21.11] gitlab: 14.6.2 -> 14.7.1
This effectively reverts commit f007b794c7
as well.
2022-02-04 11:57:05 +01:00
Ivan Jager
a57e0b0da9 nixos/hardware/rtl-sdr: Fix description
(cherry picked from commit 0d7fc6f090)
2022-02-04 09:37:17 +00:00
Ivan Jager
3421f09323 nixos/hardware/hackrf: new module
This is a very this module to enable the
hackrf udev rules and ensure the "plugdev"
group they use exists.

(cherry picked from commit ca0fbf9739)
2022-02-04 09:37:16 +00:00
Vladimír Čunát
487d175486 Merge #157372: flink: 1.14.0 -> 1.14.2 (into release-21.11) 2022-02-04 08:07:24 +01:00
github-actions[bot]
cc747cdf19 bumblebee: fix source url
(cherry picked from commit 63f93a91d4)

Co-authored-by: busti <oss@busti.cool>
2022-02-04 13:48:05 +08:00
Robert Scott
50db726090 graphicsmagick: add passthru regression test for issue #157920
use a pdf from the documentation of `graphviz` as it's already a
dependency

(cherry picked from commit e379b45caa)
2022-02-04 01:10:10 +00:00
Robert Scott
28629797aa graphicsmagick: fix use of delegates in conversions
fixes #157920.

nuking the references in `magick_config.h` also nuked the references to
the package's own `delegates.mgk`, needed for determining which external
tools to use for handling of e.g. pdf files.

(cherry picked from commit 2eb5c569a8)
2022-02-04 01:10:09 +00:00
github-actions[bot]
a85028178c Merge staging-next-21.11 into staging-21.11 2022-02-04 00:10:30 +00:00
github-actions[bot]
4b8e1f137e Merge release-21.11 into staging-next-21.11 2022-02-04 00:09:56 +00:00
Martin Weinelt
a7d373886e Merge pull request #157904 from NixOS/backport-157704-to-staging-21.11 2022-02-04 00:10:00 +01:00
Martin Weinelt
d16c9b97f0 Merge pull request #157692 from NixOS/backport-157586-to-staging-21.11 2022-02-03 23:14:00 +01:00
Pascal Bach
adae402640 Merge pull request #158030 from NixOS/backport-157936-to-release-21.11
[Backport release-21.11] element-desktop: update electron_13 -> electron_15
2022-02-03 22:13:15 +01:00
Michael Weiss
1994dfa21d chromiumDev: 99.0.4844.11 -> 99.0.4844.16
(cherry picked from commit 47f0427d15)
2022-02-03 21:26:00 +01:00
Michael Weiss
d303befb57 chromiumBeta: 98.0.4758.74 -> 98.0.4758.80
(cherry picked from commit 87711ba56b)
2022-02-03 21:26:00 +01:00
Michael Weiss
2d27291f09 chromiumDev: 99.0.4840.0 -> 99.0.4844.11
(cherry picked from commit eb78072935)
2022-02-03 21:25:59 +01:00
Michael Weiss
5971c610e4 chromiumBeta: 98.0.4758.66 -> 98.0.4758.74
(cherry picked from commit b0b0ffd466)
2022-02-03 21:25:59 +01:00
Michael Weiss
a6aac66897 chromiumDev: Fix the configuration phase
This fixes:
--------------------------------------------------------------------------------
configuring
ERROR at //ui/gtk/BUILD.gn:17:1: Assertion failed.
assert(use_gio, "GIO is required for building with GTK")
^-----
GIO is required for building with GTK
See //content/shell/BUILD.gn:308:15: which caused the file to be included.
    deps += [ "//ui/gtk" ]
              ^---------
--------------------------------------------------------------------------------

But there's still another build issue(s) left:
--------------------------------------------------------------------------------
[25491/48383] ACTION //components/url_formatter/spoof_checks/top_domains:generate_top_domain_list_variables_file(//build/toolchain/linux/unbundle:default)d_tmp/browser_command.mojom-webui.jsab_page_third_party.mojom-webui.js
FAILED: gen/components/url_formatter/spoof_checks/top_domains/top500-domains-inc.cc
python3 ../../build/gn_run_binary.py make_top_domain_list_variables ../../components/url_formatter/spoof_checks/top_domains/domains.list top500_domains gen/components/url_formatter/spoof_checks/top_domains/top500-domains-inc.cc
make_top_domain_list_variables failed with exit code -4
ninja: build stopped: subcommand failed.
--------------------------------------------------------------------------------

(cherry picked from commit e8b241cdba)
2022-02-03 21:25:59 +01:00
Michael Weiss
535ff955a9 chromium: get-commit-message.py: Improve the parsing
The latest announcement uses the following structure: "Google is aware
the exploits for CVE-2021-37975 and CVE-2021-37976 exist in the wild."
(https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_30.html)

(cherry picked from commit d0ed7ee0b0)
2022-02-03 21:25:59 +01:00
Michael Weiss
cb8e1946cd chromiumDev: 99.0.4818.0 -> 99.0.4840.0
(cherry picked from commit 9970f3d56e)
2022-02-03 21:25:58 +01:00
Brandon Weeks
969006c993 google-chrome: add /run/opengl-driver/share/vulkan/icd.d/ to path
NixOS stores ICDs at /run/opengl-driver/share/vulkan/icd.d/. Because
Chrome ships its own vulkan-loader and doesn't use the NixOS system
vulkan-loader, Chrome won't search the /run/opengl-driver directory
withou either adding it to the path or patching Chrome's libvulkan.so.1.

This change adds "${addOpenGLRunpath.driverLink}/share" unconditionally
to the path. addOpenGLRunpath is the same module that NixOS system
vulkan-loader uses as the path.

Tested by running `VK_LOADER_DEBUG=all google-chrome-unstable
--enable-features=Vulkan` and verifying Vulkan is enabled with
chrome://gpu.

(cherry picked from commit 007af34263)
2022-02-03 21:25:58 +01:00
Michael Weiss
eedf3b1e18 chromiumBeta: 98.0.4758.54 -> 98.0.4758.66
(cherry picked from commit 10bc0b32d8)
2022-02-03 21:25:58 +01:00
Brandon Weeks
6a5b59c2d8 google-chrome: fix hardware acceleration on Wayland (#155447)
Fix #103049.

(cherry picked from commit c3e8270c3a)
2022-02-03 21:25:58 +01:00
Michael Weiss
6f9a0da2d2 chromium: Backport important fixes for Wayland
This is 843508dad4 for M97 (upstream didn't backport them so far).

(cherry picked from commit a8affa912c)
2022-02-03 21:25:57 +01:00
Michael Weiss
3702a2147e chromiumBeta: 98.0.4758.48 -> 98.0.4758.54
(cherry picked from commit 61affb7d91)
2022-02-03 21:25:57 +01:00
Michael Weiss
ba587e2630 chromiumDev: 98.0.4758.9 -> 99.0.4818.0
(cherry picked from commit 9cf4be40d3)
2022-02-03 21:25:57 +01:00
Michael Weiss
e812cb81e0 chromiumBeta: 97.0.4692.71 -> 98.0.4758.48
(cherry picked from commit 1be7e76731)
2022-02-03 21:25:57 +01:00
Michael Weiss
2ec280866b chromiumDev: Backport important fixes for Wayland
This will be required to prevent crashes on Wayland compositors that
support version 4 of the wl_output protocol (available since Wayland
1.20.0).  This should affect any compositor that is based on wlroots
0.15.0 and soon more. Upstream will hopefully backport those patches
soon (if not we could also apply them to M97 - only two trivial
changes are necessary to apply the first patch).

More information:
- Chromium bug report: https://bugs.chromium.org/p/chromium/issues/detail?id=1279574
- wlroots bug report: https://gitlab.freedesktop.org/wlroots/wlroots/-/issues/3344

(cherry picked from commit 843508dad4)
2022-02-03 21:25:56 +01:00
Pascal Bach
2a5f05c0b8 Merge pull request #158029 from NixOS/backport-157933-to-release-21.11
[Backport release-21.11] brave: 1.34.81 -> 1.35.100
2022-02-03 21:00:32 +01:00
TredwellGit
6a8987365b element-desktop: update electron_13 -> electron_15
https://github.com/vector-im/element-desktop/blob/v1.10.1/package.json#L64
(cherry picked from commit 2571561c50)
2022-02-03 19:46:03 +00:00
TredwellGit
c544e9360d brave: 1.34.81 -> 1.35.100
https://github.com/brave/brave-browser/blob/master/CHANGELOG_DESKTOP.md#135100
(cherry picked from commit 8ab663aaa5)
2022-02-03 19:45:53 +00:00
Kerstin Humm
895c42edf4 mastodon: 3.4.5 -> 3.4.6
fixes CVE-2022-24307

(cherry picked from commit a4944d382745fbbfab97882fbe441f8d7b5a298e)
2022-02-03 14:50:25 +01:00
Pavol Rusnak
4da27abaeb Merge pull request #157979 from NixOS/backport-157968-to-release-21.11
[Backport release-21.11] trezor-suite: 21.12.2 -> 22.1.1
2022-02-03 12:31:06 +01:00
vdovhanych
9a7b637992 trezor-suite: 21.12.2 -> 22.1.1
(cherry picked from commit e0a91196b5)
2022-02-03 11:05:31 +00:00
Pavol Rusnak
51012716b6 Merge pull request #157964 from NixOS/backport-157934-to-release-21.11
[Backport release-21.11] electron_13: 13.6.8 -> 13.6.9
2022-02-03 10:25:08 +01:00
TredwellGit
5e3cfec3c0 electron_13: 13.6.8 -> 13.6.9
https://github.com/electron/electron/releases/tag/v13.6.9
(cherry picked from commit cd17b35b1c)
2022-02-03 09:15:17 +00:00
Thomas Gerbet
4367f9dc00 connman: 1.40 -> 1.41
Fixes CVE-2022-23096
Changelog:
https://git.kernel.org/pub/scm/network/connman/connman.git/commit/?id=4a27c58ad8b1afd980ebe122ca178c7f659c025e

(cherry picked from commit e9ac83ebb5)
2022-02-03 01:48:33 +00:00
github-actions[bot]
37fc920f8f Merge staging-next-21.11 into staging-21.11 2022-02-03 00:11:34 +00:00
github-actions[bot]
db9f9e6f33 Merge release-21.11 into staging-next-21.11 2022-02-03 00:11:00 +00:00
Robert Scott
56b02eaa81 Merge pull request #157897 from LeSuisse/quassel-CVE-2021-34825-21.11
[21.11] quassel: apply patches to fix CVE-2021-34825
2022-02-02 22:13:30 +00:00
Martin Weinelt
19c11cf796 python3Packages.django_3: 3.2.11 -> 3.2.12
https://www.djangoproject.com/weblog/2022/feb/01/security-releases/

Fixes: CVE-2022-23833, CVE-2022-22818
(cherry picked from commit 1194b292d9)
2022-02-02 21:49:04 +00:00
Martin Weinelt
660357b9ac python3Packages.django_2: 2.2.26 -> 2.2.27
https://www.djangoproject.com/weblog/2022/feb/01/security-releases/

Fixes: CVE-2022-23833, CVE-2022-22818
(cherry picked from commit 4c8019a8e5)
2022-02-02 21:49:04 +00:00
Thomas Gerbet
b0c0117ab3 quassel: apply patches to fix CVE-2021-34825
Patches comes from the PR fixing the issue quassel/quassel#581
2022-02-02 21:37:01 +01:00
Robert Scott
da911ccd4c Merge pull request #157462 from NixOS/backport-157138-to-release-21.11
[Backport release-21.11] bind: 9.16.16 -> 9.16.25
2022-02-02 19:43:06 +00:00
pacien
6ec8abbb7f mercurial: backport fix for compat with 6.1
Backported from mercurial 6.0.2 (commit hg#6d2ddea0721a).

See https://www.mercurial-scm.org/pipermail/mercurial-packaging/2022-February/000325.html
2022-02-02 20:06:18 +01:00
Kerstin Humm
ff77f2922f mastodon: 3.4.4 -> 3.4.5
(cherry picked from commit f2422ab8b4c93422e53e10d5a4ba266536cd101a)
2022-02-02 17:52:23 +01:00
Kerstin Humm
2e9c247b9f mastodon: 3.4.1 -> 3.4.4
update.sh --ver v3.4.4 --patches ./resolutions.patch

(cherry picked from commit e67685910d)
2022-02-02 17:52:23 +01:00
Pavol Rusnak
2ba56a2b49 Merge pull request #157853 from mdlayher/release-21.11
[Backport release-21.11] corerad: 0.3.4 -> 1.0.0
2022-02-02 17:29:21 +01:00
Maximilian Bosch
6a37719b90 element-{web,desktop}: 1.9.9 -> 1.10.1
ChangeLogs:
* https://github.com/vector-im/element-web/releases/tag/v1.10.0
* https://github.com/vector-im/element-web/releases/tag/v1.10.1

(cherry picked from commit f558c4a5d6)
2022-02-02 16:11:02 +00:00
Matt Layher
bb936c3175 [Backport release-21.11] corerad: 0.3.4 -> 1.0.0
Signed-off-by: Matt Layher <mdlayher@gmail.com>
2022-02-02 10:10:36 -05:00
markuskowa
ff5ff36e0e Merge pull request #157795 from NixOS/backport-157598-to-release-21.11
[Backport release-21.11] nixos/slurm: fix startup of slurmd
2022-02-02 12:02:05 +01:00
Bobby Rong
fe6f909f7d Merge pull request #157113 from NixOS/backport-156913-to-release-21.11
[Backport release-21.11] hydrus: 470b -> 471
2022-02-02 16:53:43 +08:00
Pascal Bach
f6ddd55d5f Merge pull request #157738 from mweinelt/21.11/samba
[21.11] samba: 4.15.3 -> 4.15.5
2022-02-02 08:56:41 +01:00
Markus Kowalewski
737f9c82ed nixos/slurm: fix startup of slurmd
* make slurmd depend on network target to ensure basic networking
  is available on startup. This fixes behaviour
  where slurmd fails with "error: get_addr_info: getaddrinfo() failed".
* Use tmpfiles.d to ensure spool directory exists on start up.

(cherry picked from commit 270da0a115)
2022-02-02 03:53:49 +00:00
github-actions[bot]
b6a5f8ccdc Merge staging-next-21.11 into staging-21.11 2022-02-02 00:11:29 +00:00
github-actions[bot]
6af4dd9d29 Merge release-21.11 into staging-next-21.11 2022-02-02 00:10:51 +00:00
Thomas Gerbet
8f7bb8841a mbedtls: 2.26.0 -> 2.28.0
Changes:
https://github.com/ARMmbed/mbedtls/releases/tag/v2.27.0
https://github.com/ARMmbed/mbedtls/releases/tag/v2.28.0

Security advisories:
https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2021-07-1
https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2021-07-2
https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2021-12

(cherry picked from commit 700c8b6703)
2022-02-01 19:08:05 -05:00
markuskowa
1687a0d723 Merge pull request #157576 from NixOS/backport-157456-to-release-21.11
[Backport release-21.11] atheme: 7.2.11 -> 7.2.12
2022-02-01 22:20:02 +01:00
Renaud
004a354cf0 Merge pull request #157740 from NixOS/backport-157253-to-release-21.11
[Backport release-21.11] navidrome: 0.47.0 -> 0.47.5
2022-02-01 22:14:16 +01:00
Maximilian Bosch
1823b03c0b plausible: 1.4.3 -> 1.4.4 (#157335)
ChangeLog: https://github.com/plausible/analytics/releases/tag/v1.4.4
(cherry picked from commit 376934f4b7)
2022-02-01 22:14:07 +01:00
Maximilian Bosch
5415e04d34 plausible: 1.4.0 -> 1.4.3
ChangeLog: https://github.com/plausible/analytics/blob/v1.4.3/CHANGELOG.md#unreleased

Also makes the option `services.plausible.releaseCookiePath` mandatory[1]: since Elixir
1.13 the `RELEASE_COOKIE` env-var *must* be set, otherwise the startup
fails[2]. Since we drop `$out/releases/COOKIE` in the `fixupPhase` of
`mixRelease` and Elixir seems to always attempt to generate such a
file[3], I figured it's reasonable to just make it mandatory now.

Closes #155575

[1] https://nixos.org/manual/nixos/stable/options.html#opt-services.plausible.releaseCookiePath
[2] f24eb2c1ef /
    https://github.com/elixir-lang/elixir/issues/11114
[3] https://hexdocs.pm/mix/Mix.Tasks.Release.html, see `:cookie`

(cherry picked from commit e211c94b94)
2022-02-01 22:14:06 +01:00
Thomas Gerbet
8c05d700d8 navidrome: 0.47.0 -> 0.47.5
Fixes CVE-2022-23857
https://github.com/navidrome/navidrome/releases/tag/v0.47.5

(cherry picked from commit 24bed7aa03)
2022-02-01 19:57:44 +00:00
Renaud
5fc9b600d9 Merge pull request #157737 from NixOS/backport-157378-to-release-21.11
[Backport release-21.11] librecad: apply patch for CVE-2021-45342
2022-02-01 20:51:20 +01:00
Martin Weinelt
3eaf79094c samba: 4.15.3 -> 4.15.5
https://www.openwall.com/lists/oss-security/2022/02/01/1

Fixes: CVE-2021-44141, CVE-2021-44142, CEV-2022-0336
(cherry picked from commit da86fe2cd6)
(cherry picked from commit d4aac5cd60)
2022-02-01 20:12:45 +01:00
Thomas Gerbet
424aab574b librecad: apply patch for CVE-2021-45342
https://github.com/LibreCAD/LibreCAD/issues/1464
(cherry picked from commit 6896348d0f)
2022-02-01 19:11:12 +00:00
Paul Grandperrin
ad92555be1 (vscode|vscodium)-fhs: fix missing desktop icon
(cherry picked from commit 5150255146)
2022-02-01 07:57:00 -08:00
Vladimír Čunát
d1ec053bf5 Merge #157192: thunderbird: 91.5.0 -> 91.5.1
...into release-21.11
2022-02-01 13:57:49 +01:00
Vladimír Čunát
b9f04df8ff Merge #157446: thunderbird-bin: 91.5.0 -> 91.5.1
...into release-21.11
2022-02-01 13:48:01 +01:00
Sebastian Pipping
ab1335cf30 expat: 2.4.3 -> 2.4.4
(cherry picked from commit 93d05cd472)
2022-02-01 12:30:28 +00:00
Pavol Rusnak
8064278d5c Merge pull request #157662 from NixOS/backport-157608-to-release-21.11
[Backport release-21.11] Update Electron
2022-02-01 11:46:13 +01:00
TredwellGit
aab2c9bc20 electron_16: 16.0.7 -> 16.0.8
https://github.com/electron/electron/releases/tag/v16.0.8
(cherry picked from commit 2fd87d4313)
2022-02-01 09:26:33 +00:00
TredwellGit
6cfef91e1b electron_15: 15.3.5 -> 15.3.6
https://github.com/electron/electron/releases/tag/v15.3.6
(cherry picked from commit 97184d6ca3)
2022-02-01 09:26:33 +00:00
TredwellGit
588c378afe electron_14: 14.2.4 -> 14.2.5
https://github.com/electron/electron/releases/tag/v14.2.5
(cherry picked from commit 65ea1a8bf1)
2022-02-01 09:26:33 +00:00
Maximilian Bosch
8c90eeeaa7 Merge pull request #157616 from Ma27/bump-gitea-2111
[21.11] gitea: 1.15.10 -> 1.15.11
2022-02-01 09:55:40 +01:00
Bobby Rong
fb584c7cb2 Merge pull request #156723 from bobby285271/pantheon-stable
[21.11] Pantheon 6.1 backports 2022-01-25
2022-02-01 16:19:21 +08:00
Jaka Hudoklin
fb8e0a8228 Merge pull request #157541 from wamserma/containerd-bump-1.5.9
[21.11] containerd: 1.5.7 -> 1.5.9 (security)
2022-02-01 09:11:00 +01:00
Maximilian Bosch
6802cfbdbf gitea: 1.15.10 -> 1.15.11
ChangeLog: https://github.com/go-gitea/gitea/releases/tag/v1.15.11
2022-02-01 01:21:36 +01:00
github-actions[bot]
def8eb00ab Merge staging-next-21.11 into staging-21.11 2022-02-01 00:13:08 +00:00
github-actions[bot]
3e23bb5c1f Merge release-21.11 into staging-next-21.11 2022-02-01 00:11:54 +00:00
Ricardo G
1b612cf588 confluent-cli: init at 2.4.0
(cherry picked from commit 0ef4c010377e68e61e0b0040f5690a8b5ad13b3c)
2022-02-01 00:08:18 +00:00
Stig Palmquist
f843022024 perlPackages.Appcpanminus: use TLS endpoints by default
(cherry picked from commit 52cac2a6e4)
2022-01-31 21:09:37 +00:00
Stig Palmquist
6d52099ba5 perlPackages.Appcpanminus: add dep for tls support
(cherry picked from commit 9cbd42c6de)
2022-01-31 21:09:37 +00:00
Stig Palmquist
52b3bc2fc1 perlPackages.Appcpanminus: 1.7044 -> 1.7045
(cherry picked from commit 829b3f6adf)
2022-01-31 21:09:36 +00:00
Dmitry Kalinkin
0d90976026 pythonPackages.brotli: don't use deepClone
It's not reproducible

(cherry picked from commit f2b9aa4929af180848f3751c5947188cdd6b6e9b)
2022-01-31 12:25:53 -08:00
R. Ryantm
020d63c7e9 pipenv: 2021.11.23 -> 2022.1.8
(cherry picked from commit 06b0520f3ce87dcda9abaabea07ee0b7006d9c7f)
2022-01-31 12:08:44 -08:00
Martin Weinelt
df1e884f6b atheme: 7.2.11 -> 7.2.12
General authentication bypass in Atheme IRC services with InspIRCd 3

https://www.openwall.com/lists/oss-security/2022/01/30/4
(cherry picked from commit 053e8cddf6)
2022-01-31 19:49:45 +00:00
Kerstin Humm
9da6813ce9 imagemagick: 7.1.0-20 -> 7.1.0-22
(cherry picked from commit 42dbc27ed4)
2022-01-31 19:35:10 +00:00
Renaud
c3c308f392 Merge pull request #157551 from NixOS/backport-157160-to-release-21.11
[Backport release-21.11] soci: pull in fix for backend search path
2022-01-31 20:33:43 +01:00
Lorenz Brun
eedba3f406 soci: pull in fix for backend search path
(cherry picked from commit b7649f9bfc)
2022-01-31 18:11:05 +00:00
ajs124
e3bd7c272c Merge pull request #157539 from mweinelt/21.11/fix-smartctl-exporter-capab-typo
[21.11] prometheus.exporters.smartctl: multiple fixes
2022-01-31 18:41:59 +01:00
Danielle Lancashire
fce56604cc containerd: 1.5.8 -> 1.5.9
(cherry picked from commit 8553a5d3dc)
2022-01-31 17:42:17 +01:00
R. Ryantm
df6bb5ff21 containerd: 1.5.7 -> 1.5.8
(cherry picked from commit 4baf742d97)
2022-01-31 17:41:56 +01:00
Martin Weinelt
8c92103479 nixos/smartctl-exporter: fix typo in rawio capab
(cherry picked from commit 9d8a23f66e)
2022-01-31 17:40:22 +01:00
Martin Weinelt
d071904cc5 prometheus.exporters.smartctl: Fix autodiscovery
When no devices are given the exporter tries to autodiscover available
disks. The previous DevicePolicy was however preventing the exporter
from accessing any device at all, since only explicitly mentioned ones
were allowed.

This commit adds an allow rule for several device classes that I could
find on my machines, that gets set when no devices are explicitly
configured.

There is an existing problem with nvme devices, that expose a character
device at `/dev/nvme0`, and a (namespaced) block device at
`/dev/nvme0n1`. The character device does not come with permissions that
we could give to the exporter without further impacting the hardening.

  crw------- 1 root root 247, 0 27. Jan 03:10 /dev/nvme0
  brw-rw---- 1 root disk 259, 0 27. Jan 03:10 /dev/nvme0n1

The autodiscovery only finds the character device, which the exporter
unfortunately does not have access to.

However a simple udev rule can be used to resolve this:

  services.udev.extraRules = ''
    SUBSYSTEM=="nvme", KERNEL=="nvme[0-9]*", GROUP="disk"
  '';

Unfortunately I'm not fully aware of the security implications this
change carries and we should question upstream (systemd) why they did
not include such a rule.
The disk group has no members on any of my machines.

  ❯ getent group disk
  disk:x:6:

(cherry picked from commit 12c26aca1f)
2022-01-31 17:40:16 +01:00
Martin Weinelt
ed0cb8aa19 prometheus.exporters.smartctl: Allow RAWIO
This allows the exporter to perform SCSI commands and interact with hpsa
and cciss devices.

(cherry picked from commit f860b289d4)
2022-01-31 17:40:11 +01:00
Jakub Kozłowski
adb33750ed scala-cli: 0.0.9 -> 0.1.0
(cherry picked from commit e023c8d6d9b89de1b5ea506f2a255171bc6bd8fe)
2022-01-31 15:03:26 +00:00
Maximilian Bosch
17f073ee6b Merge pull request #157453 from NixOS/backport-157286-to-release-21.11
[Backport release-21.11] Kernels 2022-01-29
2022-01-31 12:57:51 +01:00
Maximilian Bosch
460fcea242 Merge pull request #157385 from NixOS/backport-157375-to-release-21.11
[Backport release-21.11] wiki-js: 2.5.272 -> 2.5.274
2022-01-31 12:38:18 +01:00
Maximilian Bosch
6e240d9ca1 Merge pull request #157389 from NixOS/backport-157270-to-release-21.11
[Backport release-21.11] nextcloud: 21.0.7 -> 21.0.8, 22.2.3 -> 22.2.4, 23.0.0 -> 23.0.1
2022-01-31 12:36:55 +01:00
Stig
ceaca99802 Merge pull request #157323 from NixOS/backport-157250-to-release-21.11
[Backport release-21.11] perlPackages.ImageExifTool: 12.29 -> 12.39
2022-01-31 02:30:50 +01:00
Thomas Gerbet
8f89db1bc3 bind: 9.16.16 -> 9.16.25
Fixes CVE-2021-25219.
https://downloads.isc.org/isc/bind9/9.16.25/doc/arm/html/notes.html

(cherry picked from commit 4cfcbac24a)
2022-01-31 00:13:34 +00:00
Thomas Gerbet
e6049c1dee smarty3: 3.1.39 -> 3.1.44
Fixes CVE-2021-29454.
https://github.com/smarty-php/smarty/blob/v3.1.44/CHANGELOG.md

(cherry picked from commit 61833e4db0)
2022-01-31 00:13:07 +00:00
github-actions[bot]
9c87c621e5 Merge staging-next-21.11 into staging-21.11 2022-01-31 00:10:54 +00:00
github-actions[bot]
59b00290e6 Merge release-21.11 into staging-next-21.11 2022-01-31 00:10:16 +00:00
Maximilian Bosch
5de8cd42be Merge pull request #156380 from Ma27/backport-mautrix-telegram
[21.11] mautrix-telegram: 0.10.2 -> 0.11.1
2022-01-31 00:53:01 +01:00
TredwellGit
b0775c00f9 linux: 5.4.174 -> 5.4.175
(cherry picked from commit 2c30d76cd2)
2022-01-30 22:44:49 +00:00
TredwellGit
26d898edbd linux: 5.16.3 -> 5.16.4
(cherry picked from commit 46708c6a5b)
2022-01-30 22:44:49 +00:00
TredwellGit
9796816e0c linux: 5.15.17 -> 5.15.18
(cherry picked from commit 2461a530ff)
2022-01-30 22:44:49 +00:00
TredwellGit
4e5d14e7a5 linux: 5.10.94 -> 5.10.95
(cherry picked from commit e21b404b64)
2022-01-30 22:44:49 +00:00
TredwellGit
c7fd7b7219 linux: 4.9.298 -> 4.9.299
(cherry picked from commit dd0e39a900)
2022-01-30 22:44:49 +00:00
TredwellGit
b8b7e5a3ce linux: 4.4.300 -> 4.4.301
(cherry picked from commit be3505956a)
2022-01-30 22:44:49 +00:00
TredwellGit
1acc5407fd linux: 4.19.226 -> 4.19.227
(cherry picked from commit 291e5ba35e)
2022-01-30 22:44:49 +00:00
TredwellGit
fc8c597b86 linux: 4.14.263 -> 4.14.264
(cherry picked from commit 4d7d225171)
2022-01-30 22:44:49 +00:00
taku0
a3297377e2 thunderbird-bin: 91.5.0 -> 91.5.1
(cherry picked from commit 16f9a4831d)
2022-01-30 20:25:06 +00:00
Robert Schütz
a5491add7e python3Packages.mat2: 0.12.2 -> 0.12.3
(cherry picked from commit a989a4b55cf350f189f690500d5d6918f0285747)
2022-01-30 19:56:10 +00:00
Stig
83a53b4adf Merge pull request #157321 from NixOS/backport-157176-to-release-21.11
[Backport release-21.11] perlPackages.CPAN: 2.28 -> 2.29
2022-01-30 18:53:26 +01:00
Stig
07914f2e8e Merge pull request #157296 from NixOS/backport-157174-to-release-21.11
[Backport release-21.11] perlPackages.CPANChecksums: 2.12 -> 2.14
2022-01-30 18:33:39 +01:00
Janne Heß
f045ae5cdd Merge pull request #154620 from NixOS/backport-154320-to-release-21.11
[Backport release-21.11] nscd service: fix ordering and start automatically
2022-01-30 16:55:29 +01:00
Thomas Gerbet
0d9c29fc98 mysql57: 5.7.27 -> 5.7.37
Changes:
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-37.html
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-36.html
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-35.html
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-34.html
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-33.html
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-32.html
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-31.html
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-30.html
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-29.html
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-28.html

(cherry picked from commit 55561105fa)
2022-01-30 15:31:40 +01:00
Lara
b0999cd7e7 nextcloud23: 23.0.0 -> 23.0.1
(cherry picked from commit 7d87529de9)
2022-01-30 11:53:12 +00:00
Lara
afd9215a07 nextcloud22: 22.2.3 -> 22.2.4
(cherry picked from commit f6038cf1ee)
2022-01-30 11:53:12 +00:00
Lara
9817e72276 nextcloud21: 21.0.7 -> 21.0.8
(cherry picked from commit e5da53ba72)
2022-01-30 11:53:12 +00:00
Maximilian Bosch
a6c8888b4d wiki-js: 2.5.272 -> 2.5.274
ChangeLog: https://github.com/Requarks/wiki/releases/tag/2.5.274
(cherry picked from commit 9690362f62)
2022-01-30 11:03:40 +00:00
Joerie de Gram
5c526049c7 flink: 1.14.0 -> 1.14.2
Fixes CVE-2021-44228 and CVE-2021-45046 (#150288).

(cherry picked from commit 63840cef0e)
2022-01-30 08:12:07 +00:00
adisbladis
0f316e4d72 Merge pull request #157159 from NixOS/backport-149448-to-release-21.11
[Backport release-21.11] podman: 3.4.2 -> 3.4.3
2022-01-30 12:48:40 +12:00
github-actions[bot]
2fd849fdc7 Merge staging-next-21.11 into staging-21.11 2022-01-30 00:11:41 +00:00
github-actions[bot]
23febf865f Merge release-21.11 into staging-next-21.11 2022-01-30 00:10:57 +00:00
Thomas Gerbet
7a2f2bcc1e perlPackages.ImageExifTool: 12.29 -> 12.39
Fixes CVE-2022-23935.
https://exiftool.org/history.html

(cherry picked from commit 3be5d9cfce)
2022-01-29 22:49:03 +00:00
Thomas Gerbet
d5147b22b5 perlPackages.CPAN: 2.28 -> 2.29
Fixes CVE-2020-16156
https://metacpan.org/release/ANDK/CPAN-2.29/source/Changes

(cherry picked from commit e6d73949cf)
2022-01-29 22:45:16 +00:00
Vladimír Čunát
d46f6eaa6a Merge #156696: staging-next: 21.11 iteration 6 2022-01-29 19:07:54 +01:00
Thomas Gerbet
a22ca8ac19 perlPackages.CPANChecksums: 2.12 -> 2.14
Fixes CVE-2020-16155.
https://metacpan.org/release/ANDK/CPAN-Checksums-2.14/source/Changes

(cherry picked from commit 929a256be4)
2022-01-29 16:18:31 +00:00
Thomas Gerbet
61a34324ea jadx: 1.3.1 -> 1.3.2
Fixes CVE-2022-0219
https://github.com/skylot/jadx/releases/tag/v1.3.2

(cherry picked from commit e9c56180a6)
2022-01-29 15:21:44 +01:00
Vincent Haupert
1bd40d8cbe jadx: 1.3.0 -> 1.3.1
(cherry picked from commit 8c31e96aab)
2022-01-29 15:21:05 +01:00
Vincent Haupert
82a0cb02b0 jadx: 1.2.0 -> 1.3.0
(cherry picked from commit 89369e069d)
2022-01-29 15:21:05 +01:00
Robert Scott
0309816962 Merge pull request #157181 from NixOS/backport-157064-to-release-21.11
[Backport release-21.11] varnish60: 6.0.9 -> 6.0.10, varnish70: 7.0.1 -> 7.0.2
2022-01-29 13:33:27 +00:00
schnusch
913b601bac remote-touchpad: 1.0.5 -> 1.1.0
(cherry picked from commit 1ac72e43ac)
2022-01-29 12:58:02 +01:00
Maximilian Bosch
93ad51ab52 Merge pull request #157212 from NixOS/backport-157203-to-release-21.11
[Backport release-21.11] prometheus-postgres-exporter: 0.10.0 -> 0.10.1
2022-01-29 10:05:36 +01:00
Sandro
46450f2f65 Merge pull request #157167 from FliegendeWurst/21.11-bundler-2.2.33 2022-01-29 02:54:12 +01:00
R. Ryantm
ee5606ced9 zstd: 1.5.1 -> 1.5.2
(cherry picked from commit 8993696d2e12b6b9378584529005e5fd28f985bc)
2022-01-28 17:42:39 -08:00
Maximilian Bosch
8487458f42 prometheus-postgres-exporter: 0.10.0 -> 0.10.1
ChangeLog: https://github.com/prometheus-community/postgres_exporter/releases/tag/v0.10.1
(cherry picked from commit 46d4c9e6a4)
2022-01-29 00:18:46 +00:00
github-actions[bot]
5329e4f9c6 Merge staging-next-21.11 into staging-21.11 2022-01-29 00:10:16 +00:00
github-actions[bot]
0bc5b1b3f6 Merge release-21.11 into staging-next-21.11 2022-01-29 00:09:36 +00:00
Robert Scott
ecb828d862 expat: add patch for CVE-2022-23990
(cherry picked from commit 6388abaa92510fbe7c9584a62b723375f8df79ea)
2022-01-28 15:24:03 -08:00
TredwellGit
cce050d067 glibc: 2.33-78 -> 2.33-108
(cherry picked from commit 00caaf1e9a)
2022-01-28 15:14:12 -08:00
Maximilian Bosch
2d3d6d2550 Merge pull request #156773 from NixOS/backport-156756-to-release-21.11
[Backport release-21.11] matrix-synapse: 1.50.2 -> 1.51.0
2022-01-28 23:42:28 +01:00
Maximilian Bosch
76e07ffcff Merge pull request #156782 from NixOS/backport-156316-to-release-21.11
[Backport release-21.11] wiki-js: 2.5.268 -> 2.5.272
2022-01-28 23:42:16 +01:00
Vladimír Čunát
01863d5a1b Merge branch 'release-21.11' into staging-next-21.11 2022-01-28 23:39:01 +01:00
Vladimír Čunát
5c789ef49e Merge #156128: webkitgtk: 2.34.3 -> 2.34.4
...into staging-next-21.11
2022-01-28 23:36:20 +01:00
Maximilian Bosch
6432cd1045 Merge pull request #156307 from lheckemann/fsl-mc-uapi-21.11
[21.11] linux: enable FSL_MC_UAPI_SUPPORT
2022-01-28 23:33:38 +01:00
Sergei Trofimovich
f9bd4cc69c zstd: 1.5.0 -> 1.5.1
While at it added trivial updater plumbing.

(cherry picked from commit ebaf0d9b3b309194183e5712b0d9612f29279ff5)
2022-01-28 13:45:08 -08:00
R. Ryantm
b2ebad1ded thunderbird-unwrapped: 91.5.0 -> 91.5.1
(cherry picked from commit 16a14fbc13)
2022-01-28 20:34:11 +00:00
Madoura
4368324b02 bcachefs-tools: 2021-12-25 -> 2022-01-12
(cherry picked from commit 3f81985d74)
2022-01-28 18:47:55 +00:00
Madoura
905069f727 linux_testing-bcachefs: 2021-12-26 -> 2022-01-12
(cherry picked from commit 067201c3cc)
2022-01-28 18:47:55 +00:00
Robert Scott
133a3ea14a varnish60: 6.0.9 -> 6.0.10
(cherry picked from commit cf2bdd298b)
2022-01-28 18:40:54 +00:00
Robert Scott
c99306a2e9 varnish70: 7.0.1 -> 7.0.2
(cherry picked from commit 683d5696e3)
2022-01-28 18:40:54 +00:00
davidak
a25caed5e1 Merge pull request #157117 from NixOS/backport-157000-to-release-21.11
[Backport release-21.11] phoronix-test-suite: 10.8.0 -> 10.8.1
2022-01-28 18:24:37 +01:00
FliegendeWurst
e4bfee8d2a bundler: 2.2.24 -> 2.2.33 2022-01-28 17:41:32 +01:00
zowoq
093981adb5 podman: 3.4.2 -> 3.4.3
https://github.com/containers/podman/releases/tag/v3.4.3
(cherry picked from commit 56a556cdb1a8b60cd2cd7c5eb769ca856e0612ed)
2022-01-28 15:45:13 +00:00
Thomas Gerbet
8ec4c8c48c phoronix-test-suite: 10.8.0 -> 10.8.1
Fixes CVE-2022-0238
https://github.com/phoronix-test-suite/phoronix-test-suite/releases/tag/v10.8.1

(cherry picked from commit 6896f3beb7)
2022-01-28 10:19:03 +00:00
Daniel Olsen
bfe59271ef hydrus: 470b -> 471
(cherry picked from commit e5dfca887c)
2022-01-28 09:20:59 +00:00
github-actions[bot]
32aa3d7829 libesmtp: 1.0.6 -> 1.1.0
[Backport release-21.11] libesmtp: 1.0.6 -> 1.1.0 (#157105)
* libesmtp: 1.0.6 -> 1.1.0

(cherry picked from commit 41745cbd34d10b3049ef0a39af34116039bbd297)

* libesmtp: refresh meta attributes
New homepage and SPDX 3.0 license identifier

(cherry picked from commit 0857994abce7d4dfed3288296ef0dc13015a7fd0)

Co-authored-by: FliegendeWurst <2012gdwu+github@posteo.de>
Co-authored-by: Renaud <c0bw3b@users.noreply.github.com>
2022-01-28 09:11:03 +01:00
Vincent Laporte
95845832c6 tamarin-prover: install emacs-mode
(cherry picked from commit f5284831d163480c21c8ce9330189035718b7611)
2022-01-28 06:01:33 +01:00
github-actions[bot]
741fdb7e29 [Backport release-21.11] fix MTP support on KDE Plasma and Dolphin (#156981)
* fix MTP support on KDE Plasma and Dolphin

(cherry picked from commit c1e4f4d661296c36886d81952862a6efb1fdccd4)

* Update pkgs/applications/kde/kio-extras.nix

Co-authored-by: ElXreno <elxreno@gmail.com>
(cherry picked from commit a2415efca6b4405c7af24ff71009d28565b080f8)

Co-authored-by: Oleg Kapitonov <kapitonov1987@gmail.com>
Co-authored-by: Peter Hoeg <peter@hoeg.com>
2022-01-28 12:13:30 +08:00
TredwellGit
746001202d linux: 5.4.173 -> 5.4.174
(cherry picked from commit 7e76358a03)
2022-01-27 17:11:26 -08:00
TredwellGit
701bcda998 linux: 5.16.2 -> 5.16.3
(cherry picked from commit 35ba4ae7a4)
2022-01-27 17:11:26 -08:00
TredwellGit
10fb4415dc linux: 5.15.16 -> 5.15.17
(cherry picked from commit 532ede5712)
2022-01-27 17:11:26 -08:00
TredwellGit
1ed2f1ac8f linux: 5.10.93 -> 5.10.94
(cherry picked from commit b14eceedca)
2022-01-27 17:11:26 -08:00
TredwellGit
8a10a55c97 linux: 4.9.297 -> 4.9.298
(cherry picked from commit 7b55056304)
2022-01-27 17:11:26 -08:00
TredwellGit
8c106fcde6 linux: 4.4.299 -> 4.4.300
(cherry picked from commit c0b2ac9b7a)
2022-01-27 17:11:26 -08:00
TredwellGit
a0909dd5b2 linux: 4.19.225 -> 4.19.226
(cherry picked from commit e0781196f7)
2022-01-27 17:11:26 -08:00
TredwellGit
4033ce28f1 linux: 4.14.262 -> 4.14.263
(cherry picked from commit 388633adc5)
2022-01-27 17:11:26 -08:00
github-actions[bot]
5aa54daed0 Merge staging-next-21.11 into staging-21.11 2022-01-28 00:15:42 +00:00
github-actions[bot]
d379877791 Merge release-21.11 into staging-next-21.11 2022-01-28 00:15:04 +00:00
Thomas Gerbet
26b6d54b1a flatpak: 1.12.2 -> 1.12.4
Fixes CVE-2021-43860 and CVE-2022-21682

Changes:
https://github.com/flatpak/flatpak/releases/tag/1.12.4
https://github.com/flatpak/flatpak/releases/tag/1.12.3

Security advisories:
https://github.com/flatpak/flatpak/security/advisories/GHSA-qpjc-vq3c-572j
https://github.com/flatpak/flatpak/security/advisories/GHSA-8ch7-5j3h-g4fx

(cherry picked from commit a4f05760dc80d89905c29e958e9464c536afbac8)
2022-01-27 15:45:32 -08:00
Thomas Gerbet
617a2726b0 keepalived: fixes CVE-2021-44225
https://github.com/advisories/GHSA-jpw2-cwxg-4qv8
2022-01-27 15:41:03 -08:00
Robert Hensing
a31164f185 Merge pull request #157057 from NixOS/backport-156857-to-release-21.11
[Backport release-21.11] doc/coding-conventions: Fix version attribute suffix to match reality
2022-01-27 22:43:19 +01:00
Renaud
e7668071d3 Merge pull request #156842 from FliegendeWurst/21.11-htmldoc-1.9.14
[21.11] htmldoc: 1.9.12 -> 1.9.14
2022-01-27 22:33:30 +01:00
Robert Hensing
24c71af92a doc/coding-conventions: Fix version attribute suffix to match reality
The current doc is wildly out of touch with reality. A regex search shows
the following stats.

```
Style example  Frequency  Regex used
nix-2-5:            8     [a-zA-Z]-[0-9]+(-[0-9]+)+ =
nix-2_5:           17     [a-zA-Z]-[0-9]+(_[0-9]+)+ =
nix_2_5:          689     [a-zA-Z]_[0-9]+(_[0-9]+)+ =
nix_2-5:            1     [a-zA-Z]_[0-9]+(-[0-9]+)+ =
```

(cherry picked from commit daca830722)
2022-01-27 21:21:26 +00:00
ajs124
43cf70e3c8 Merge pull request #156900 from NixOS/backport-156875-to-release-21.11
[Backport release-21.11] linux: upgrade hardened kernel 5.x (CVE-2022-0185)
2022-01-27 22:20:36 +01:00
Robert Schütz
35f4cba307 postfix: 3.6.3 -> 3.6.4
http://www.postfix.org/announcements/postfix-3.6.4.html
(cherry picked from commit a783365e227a25f2871da13f4422de4c4feebf39)
2022-01-27 12:54:44 -08:00
Thomas Gerbet
f7a365866f flatpak-builder: 1.2.0 -> 1.2.2
Changes:
https://github.com/flatpak/flatpak-builder/releases/tag/1.2.2
https://github.com/flatpak/flatpak-builder/releases/tag/1.2.1

Security advisory:
https://github.com/flatpak/flatpak/security/advisories/GHSA-8ch7-5j3h-g4fx

(cherry picked from commit 06084eba20b64964ffd54d06e8b0a2835da338b1)
2022-01-27 12:48:28 -08:00
Daniel Olsen
2f53264cd4 nixos/mx-puppet-discord: Change systemd unit description to avoid newline
(cherry picked from commit 5288bcab0a)
2022-01-27 20:45:25 +00:00
Michael Weiss
71745c1423 signal-desktop: 5.29.0 -> 5.29.1
(cherry picked from commit eeb0e220cd)
2022-01-27 12:41:26 -08:00
Michael Weiss
626b6f1aa5 signal-desktop: 5.28.0 -> 5.29.0
(cherry picked from commit 497a16f2a6)
2022-01-27 12:41:26 -08:00
Michael Weiss
ba7b386ba2 signal-desktop: 5.27.1 -> 5.28.0
This update breaks Ozone/Wayland due to an Electron update [0].
This isn't ideal but we cannot block Signal-Desktop updates indefinitely
based on that. It's an upstream issue that is tracked by both
Signal-Desktop [1] and Electron [2]. Unfortunately, there are no known
fixes/workarounds yet.

[0]: 46ddcc50f9
[1]: https://github.com/signalapp/Signal-Desktop/issues/5719
[2]: https://github.com/electron/electron/issues/32436

(cherry picked from commit e06082eda0)
2022-01-27 12:41:26 -08:00
Bernardo Meurer
1d3ea6254a Merge pull request #157028 from NixOS/backport-156937-to-release-21.11
[Backport release-21.11] firefox: 96.0.2 -> 96.0.3; firefox-bin: 96.0.2 -> 96.0.3; firefox-esr-91: 91.5.0esr -> 91.5.1esr
2022-01-27 11:47:00 -08:00
Martin Weinelt
3a3927e5e4 firefox-bin: 96.0.2 -> 96.0.3
(cherry picked from commit 7fdbbd0efc)
2022-01-27 17:45:58 +00:00
Martin Weinelt
1be45979e9 firefox-esr-91: 91.5.0esr -> 91.5.1esr
(cherry picked from commit c06f1fe43e)
2022-01-27 17:45:58 +00:00
Martin Weinelt
86a846a718 firefox: 96.0.2 -> 96.0.3
(cherry picked from commit c978d968e3)
2022-01-27 17:45:58 +00:00
Janne Heß
97885bb7dd Merge pull request #156920 from wamserma/release-fix-imagemagick
[21.11] imagemagick: apply upstream patch to fix perlPackages.ImageMagick
2022-01-27 15:15:22 +01:00
Bobby Rong
35b291f8a0 pantheon.elementary-capnet-assist: 2.4.0 -> 2.4.1
(cherry picked from commit c6fd5ab6a6)
2022-01-27 21:08:17 +08:00
Bobby Rong
b144023d43 pantheon.switchboard-plug-network: 2.4.1 -> 2.4.2
(cherry picked from commit 2739552590)
2022-01-27 21:08:00 +08:00
Bobby Rong
5a386efa8c xdg-desktop-portal-pantheon: 1.0.1 -> 1.1.0
(cherry picked from commit 9fcaa4b33e)

Note that the attrPath for this package on nixos-unstable is different.
2022-01-27 21:07:31 +08:00
Bobby Rong
36f1252b2f pantheon.elementary-files: 6.1.1 -> 6.1.2
(cherry picked from commit 56642610e7)
2022-01-27 21:06:25 +08:00
Vladimír Čunát
61d3a18ad2 Merge #156939: go: 1.16.9 -> 1.16.13 (into staging-next-21.11) 2022-01-27 13:10:45 +01:00
Pavol Rusnak
242d8aef0f Merge pull request #156991 from NixOS/backport-156982-to-release-21.11
[Backport release-21.11] electron_13: 13.6.7 -> 13.6.8
2022-01-27 12:30:56 +01:00
TredwellGit
4d0e435dd8 electron_13: 13.6.7 -> 13.6.8
https://github.com/electron/electron/releases/tag/v13.6.8
(cherry picked from commit 7a2cc7b491)
2022-01-27 11:29:22 +00:00
Mario Rodas
e10e86daef Merge pull request #156942 from NixOS/backport-156886-to-release-21.11
[Backport release-21.11] streamlink: 3.1.0 -> 3.1.1
2022-01-27 06:10:41 -05:00
Eelco Dolstra
f1be2cd02d Merge pull request #156751 from NixOS/backport-156587-to-release-21.11
[Backport release-21.11] Improve check that evaluation does not depend on the Nixpkgs path
2022-01-27 11:58:31 +01:00
Jan Tojnar
d614ac351f Merge pull request #156980 from NixOS/backport-156944-to-release-21.11
[Backport release-21.11] tbb: fix pcTemplate url
2022-01-27 11:24:59 +01:00
Dmitry Kalinkin
be94395dc0 tbb: fix pcTemplate url
(cherry picked from commit 55888a24cf)
2022-01-27 09:59:46 +00:00
Martin Weinelt
4c3f44ad68 Merge pull request #156968 from NixOS/backport-156880-to-release-21.11 2022-01-27 10:27:03 +01:00
Wout Mertens
adf535eb69 Merge pull request #155006 from NixOS/backport-154863-to-release-21.11
[Backport release-21.11] sqlcipher: enable JSON1 extension
2022-01-27 09:43:24 +01:00
Cole Helbling
18bcc89839 doas: 6.8.1 -> 6.8.2
https://github.com/Duncaen/OpenDoas/compare/v6.8.1...v6.8.2
(cherry picked from commit 7a75977e06)
2022-01-27 08:39:20 +00:00
Markus S. Wamser
cfe31f4f6a imagemagick: apply upstream patch to fix perlPackages.ImageMagick
(cherry picked from commit a4eda7a9300477102b27214b19aebd9ddb1d0617)
2022-01-27 08:48:02 +01:00
D Anzorge
7b38cdc036 streamlink: 3.1.0 -> 3.1.1
(cherry picked from commit 9cd3ed6e8c)
2022-01-27 03:24:46 +00:00
Bobby Rong
043f3d6493 Merge pull request #156940 from NixOS/backport-156868-to-release-21.11
[Backport release-21.11] colmena: 0.2.0 -> 0.2.1
2022-01-27 11:14:31 +08:00
Zhaofeng Li
a2dcb8babf colmena: 0.2.0 -> 0.2.1
(cherry picked from commit e81a21bcd5)
2022-01-27 02:42:51 +00:00
zowoq
48252717f2 go_1_16: 1.16.12 -> 1.16.13
(cherry picked from commit d50b6bff89)
2022-01-26 18:25:43 -08:00
zowoq
2ca8a684ca go_1_16: 1.16.11 -> 1.16.12
(cherry picked from commit 5d33b5183b)
2022-01-26 18:25:36 -08:00
zowoq
2a69b46078 go_1_16: 1.16.10 -> 1.16.11
(cherry picked from commit 2100043ba9)
2022-01-26 18:25:28 -08:00
zowoq
227e9f6c4e go_1_16: 1.16.9 -> 1.16.10
(cherry picked from commit cc8cade9ba)
2022-01-26 18:25:22 -08:00
Anderson Torres
6c4b9f1a2f Merge pull request #156928 from NixOS/backport-156883-to-release-21.11
[21.11] libvlc: fix build
2022-01-26 22:41:33 -03:00
ajs124
1746a0cf70 libvlc: fix build
(cherry picked from commit 59539a3d3e)
2022-01-27 01:25:43 +01:00
github-actions[bot]
60fe9932bb Merge staging-next-21.11 into staging-21.11 2022-01-27 00:10:38 +00:00
github-actions[bot]
927c3bbd7e Merge release-21.11 into staging-next-21.11 2022-01-27 00:09:59 +00:00
0x4A6F
d7f79af1ee Merge pull request #156915 from NixOS/backport-156701-to-release-21.11
[Backport release-21.11] xen: mark unsupported versions as vulnerable
2022-01-26 23:34:28 +01:00
Martin Weinelt
31606a6b78 xen: mark unsupported versions as vulnerable
Our support for Xen lacks maintenance and since Xen has monthly security
advisories it is reasonable to assume our version is affected by a
multitude of security problems that are fixed upstream.

How many advisories? Browsing oss-security shows the following number of
advisories in each of the following years:

2022: 3
2021: 53
2020: 54
2019: 46 <-- we are *here*

https://xenbits.xen.org/docs/unstable/support-matrix.html
(cherry picked from commit 39341ed38b)
2022-01-26 22:31:14 +00:00
Renaud
b22bdc7743 Merge pull request #156896 from NixOS/backport-156889-to-release-21.11
[Backport release-21.11] rng-tools: fix path to opensc-pkcs11 shared lib
2022-01-26 22:27:39 +01:00
Gregor Pogacnik
095e54262f linux: upgrade hardened kernel (CVE-2022-0185)
5.4.172 -> 5.4.173, 5.10.92 -> 5.10.93, 5.15.15 -> 5.15.16

(cherry picked from commit a86365b055)
2022-01-26 20:18:33 +00:00
Renaud
d627a50513 rng-tools: fix path to opensc-pkcs11.so
Changes upstream made the patching on rngd.c irrelevant

(cherry picked from commit 96e055fba4)
2022-01-26 19:50:02 +00:00
Thiago Kenji Okada
61a3b95464 Merge pull request #156848 from FliegendeWurst/21.11-go-1.17.5
[21.11] go: 1.17.3 -> 1.17.5
2022-01-26 15:43:21 -03:00
Vladimír Čunát
7554997bf4 Merge #156872: nixos/kresd: Fix invalid regular expression
... into release-21.11
The problem has only been confirmed to occur on *-darwin.
2022-01-26 17:23:33 +01:00
Martin Puppe
3da7bacc5c Fix invalid regular expression #156861
Empty parantheses are not supported in regular expressions on
Darwin/macOS. The old regular expression produces an error during
evaluation. This commit fixes that.

Nix‘s `builtins.match` works with extend POSIX regular expressions. The
specification for these regular expression states[^1] that the result
for a left paranthesis immediately followed by a right paranthesis
outside of a bracket expression is undefined.

[^1]: https://pubs.opengroup.org/onlinepubs/9699919799/basedefs/V1_chap09.html#tag_09_04_03

(cherry picked from commit 6a96992fe0)
2022-01-26 16:11:32 +00:00
github-actions[bot]
3403d6e58b libredirect: fix build for aarch64-darwin (PR #156839)
(cherry picked from commit 4bde5a3a68 / PR #156460)

Co-authored-by: Jonathan Ringer <jonringer117@gmail.com>
Co-authored-by: Vladimír Čunát <v@cunat.cz>
2022-01-26 14:43:18 +01:00
Wout Mertens
dc57826da0 sqlcipher: grab CFLAGS from sqlite
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit 3fc8be277d)
2022-01-26 14:21:54 +01:00
Wout Mertens
362665d2fe sqlcipher: sync flags with sqlite
(cherry picked from commit e6988feaac)
2022-01-26 14:21:54 +01:00
Wout Mertens
85d6a7f6a7 sqlcipher: enable JSON1 extension
(cherry picked from commit f52d6fb31d)
2022-01-26 14:21:53 +01:00
Anderson Torres
65caf7cf6d Merge pull request #156834 from NixOS/backport-155725-to-release-21.11
[Backport release-21.11] live555: 2019.11.22 -> 2022.01.21
2022-01-26 09:11:09 -03:00
zowoq
f5bde1ba4e go_1_17: 1.17.4 -> 1.17.5
(cherry picked from commit 388f0db0af)
2022-01-26 12:54:21 +01:00
zowoq
66981e105d go_1_17: 1.17.3 -> 1.17.4
(cherry picked from commit bb9bd465b6)
2022-01-26 12:54:21 +01:00
R. Ryantm
1e711c2a25 htmldoc: 1.9.13 -> 1.9.14
(cherry picked from commit a712326cfb)
2022-01-26 12:47:44 +01:00
R. Ryantm
21a90b0009 htmldoc: 1.9.12 -> 1.9.13
(cherry picked from commit 5e67953f20)
2022-01-26 12:47:44 +01:00
FliegendeWurst
9f34ef8196 vlc: patch for recent live555 versions
(cherry picked from commit ca07883f10)
2022-01-26 11:11:23 +00:00
FliegendeWurst
8bd7d61055 live555: 2019.11.22 -> 2022.01.21
(cherry picked from commit 460fdfce74)
2022-01-26 11:11:23 +00:00
github-actions[bot]
e2f351ec7c Merge staging-next-21.11 into staging-21.11 2022-01-26 00:11:06 +00:00
github-actions[bot]
dd3d5178cb Merge release-21.11 into staging-next-21.11 2022-01-26 00:10:31 +00:00
Maximilian Bosch
cdb0b58330 wiki-js: 2.5.268 -> 2.5.272
ChangeLog: https://github.com/Requarks/wiki/releases/tag/2.5.272
(cherry picked from commit e5e0fc67ae)
2022-01-25 23:21:49 +00:00
Sumner Evans
1707b231a2 matrix-synapse: 1.50.2 -> 1.51.0
(cherry picked from commit 9bdb1f9287)
2022-01-25 22:10:21 +00:00
Maximilian Bosch
b3d86c56c7 Merge pull request #156674 from NixOS/backport-156553-to-release-21.11
[Backport release-21.11] matrix-synapse: 1.50.1 -> 1.50.2
2022-01-25 23:05:53 +01:00
Wout Mertens
923b830906 Merge pull request #154864 from NixOS/backport-149126-to-release-21.11
[Backport release-21.11] sqlcipher: 4.4.3 -> 4.5.0
2022-01-25 21:36:22 +01:00
Martin Weinelt
e01bf5cc7f polkit: fix local priviledge escalation in pkexec
> We discovered a Local Privilege Escalation (from any user to root) in
> polkit's pkexec, a SUID-root program that is installed by default on
> every major Linux distribution

https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt

Fixes: CVE-2021-4034
(cherry picked from commit 9e01b06585edf96bd9acaa4235e4f8a0922eedd9)
2022-01-25 12:08:08 -08:00
Eelco Dolstra
01b7f0dda2 pathDerivation: Copy path
Otherwise you end up with a derivation that refers to the original
path (which is not in the Nix store and not accessible to
builders). This caused the derivation paths for the docbookrx package
(removed on master) to depend on the location of the nixpkgs source
tree.

(cherry picked from commit 55ae086747)
2022-01-25 19:13:49 +00:00
Eelco Dolstra
7b8f2c9f93 Check that nix-env output doesn't depend on the Nixpkgs location
(cherry picked from commit cb2f8a87d5)
2022-01-25 19:13:49 +00:00
Ryan Mulligan
904464936a Merge pull request #156727 from NixOS/backport-154951-to-release-21.11
[Backport release-21.11] discourse: 2.8.0.beta10 -> 2.8.0.beta11
2022-01-25 07:43:14 -08:00
Ryan Mulligan
04f55766d9 discourse: 2.8.0.beta10 -> 2.8.0.beta11
https://meta.discourse.org/t/2-8-0-beta11-user-will-not-be-mentioned-warning-updated-emoji-and-more/214752

Small fix to a patch but otherwise I just ran the update scripts.

(cherry picked from commit 3d2cb0d6a2)
2022-01-25 15:40:31 +00:00
Franz Pletz
f35647861c Merge pull request #156714 from NixOS/backport-156703-to-release-21.11 2022-01-25 16:09:07 +01:00
Bobby Rong
88556dfdf7 pantheon.elementary-tasks: 6.1.0 -> 6.2.0
(cherry picked from commit f01e14c731)
2022-01-25 23:06:54 +08:00
Bobby Rong
6f9934fad9 pantheon.elementary-mail: 6.3.1 -> 6.4.0
(cherry picked from commit 5faa988b1f)
2022-01-25 23:06:44 +08:00
Bobby Rong
fb7a8489a4 pantheon.elementary-greeter: add patch for revert pull request 566
There are several reports upstream but no actions are taken so far.

(cherry picked from commit 34d5d14fd0)
2022-01-25 23:06:32 +08:00
Bobby Rong
69bedc5b9d pantheon.elementary-session-settings: fix xsession TryExec
Otherwise Pantheon may not appear in display managers.

(cherry picked from commit 45ec3d3d4a)
2022-01-25 23:05:55 +08:00
Bobby Rong
59fbbdb102 pantheon.elementary-calendar: 6.0.3 -> 6.1.0
(cherry picked from commit ac06871a54)
2022-01-25 23:05:40 +08:00
Francesco Gazzetta
a0fe2846a7 shattered-pixel-dungeon: 1.1.0 -> 1.1.2
(cherry picked from commit 6beb585135)
2022-01-25 14:40:08 +00:00
Franz Pletz
84f800ef24 Merge pull request #156704 from panicgh/tbb 2022-01-25 15:34:07 +01:00
Nicolas Benes
ceafc334cc tor-browser-bundle-bin: Keep files when store path has not changed
Originally, some TBB files in the user's $HOME are always deleted on
startup, and as a result, addons are not loaded automatically at
startup. For example, NoScript is disabled by default and needs a manual
reload cycle (dis-/enable by hand).

This change preserves the files with the addon information as long as
the contained store path is the same, i.e. TBB was not modified.  When
TBB is updated, the files are removed as before, so that they don't
contain paths to the store location of the (now outdated) previous TBB.
A manual reload addon cycle is necessary once.

(cherry picked from commit 8985aca004)
2022-01-25 14:12:11 +01:00
Vladimír Čunát
e778452049 Merge #155496: nixos/malloc: fix scudo on non-x86_64
... into release-21.11
2022-01-25 13:34:42 +01:00
Vladimír Čunát
25b2f4479c Merge branch 'staging-21.11' into staging-next-21.11 2022-01-25 13:27:47 +01:00
Vladimír Čunát
693413c7f7 Merge #156692: glibc: 2.33-71 -> 2.33-78 (into staging-21.11) 2022-01-25 13:20:41 +01:00
Vladimír Čunát
38f022a09e glibc: 2.33-71 -> 2.33-78 (security)
https://www.openwall.com/lists/oss-security/2022/01/24/4
(cherry picked from commit 13ab7d097f)
2022-01-25 12:14:48 +00:00
Martin Weinelt
7c8f47ab16 Merge pull request #156683 from NixOS/backport-156607-to-staging-21.11 2022-01-25 13:06:05 +01:00
R. Ryantm
7c92177991 meshcentral: 0.9.56 -> 0.9.59
(cherry picked from commit 5c630dbeaa)
2022-01-25 11:55:35 +01:00
R. Ryantm
82120c42f9 meshcentral: 0.9.50 -> 0.9.56
(cherry picked from commit d4f617aa73)
2022-01-25 11:55:35 +01:00
Martin Weinelt
e7ecc4c517 Merge pull request #156452 from FliegendeWurst/vim-4186-21.11 2022-01-25 11:45:54 +01:00
Robert Scott
2b8a6ddd58 expat: add patches for CVE-2022-23852
(cherry picked from commit 4292c49b93)
2022-01-25 10:30:58 +00:00
Vladimír Čunát
4dc08cb402 gnutls: patch a security issue (low severity)
On NixPkgs master it's instead addressed by update, PR #156588.
The upstream patch is really simple;
it seems worthwhile for staging-21.11.
2022-01-25 11:05:38 +01:00
Vladimír Čunát
31013e4666 Merge #156676: util-linux: 2.37.2 -> 2.37.3 (into staging-21.11)
Two CVEs get fixed, no other changes:
https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/v2.37/v2.37.3-ReleaseNotes
2022-01-25 10:46:02 +01:00
Martin Weinelt
e38e5f869d util-linux: 2.37.2 -> 2.37.3
(cherry picked from commit 87f2bae5ee)
2022-01-25 09:42:17 +00:00
Sumner Evans
155d636df3 matrix-synapse: 1.50.1 -> 1.50.2
(cherry picked from commit 73e2f41ea2)
2022-01-25 09:29:49 +00:00
Weijia Wang
7f063ec4b8 ocamlPackages.uunf: fix aarch64-linux build
(cherry picked from commit b0d8fd8c957ce40a4073e7da7a2b5c263120f88f)
2022-01-25 10:08:45 +01:00
Martin Weinelt
0b299f0466 strongswan: add strongswan-swanctl test to passthru.tests
(cherry picked from commit 6c76d36a3b)
2022-01-25 00:22:36 -08:00
Martin Weinelt
8ce99226fc strongswan: 5.9.4 -> 5.9.5
(cherry picked from commit c292a8799f)
2022-01-25 00:22:36 -08:00
Mario Rodas
b43b9585a0 Merge pull request #156593 from DeeUnderscore/backport/streamlink-3.1.0
[21.11] streamlink: 3.0.1 -> 3.1.0
2022-01-24 20:58:12 -05:00
github-actions[bot]
331eb274bf Merge staging-next-21.11 into staging-21.11 2022-01-25 00:10:52 +00:00
github-actions[bot]
a808b37819 Merge release-21.11 into staging-next-21.11 2022-01-25 00:10:18 +00:00
D Anzorge
25608d7dd7 streamlink: 3.0.1 -> 3.1.0
(cherry picked from 86cc0e8fc2)
2022-01-24 20:21:17 +01:00
Thiago Kenji Okada
b1f2623e3c Merge pull request #156552 from NixOS/backport-156527-to-release-21.11
[Backport release-21.11] irods: Don't use builtins.nixVersion
2022-01-24 14:24:59 -03:00
Franz Pletz
5c0fef4ec8 Merge pull request #156549 from NixOS/backport-156408-to-release-21.11 2022-01-24 18:10:32 +01:00
Eelco Dolstra
003c9cad16 irods: Don't use builtins.nixVersion
The value of builtins.nixVersion should never be used except to bail
out if it's too old. It causes the evaluation result to depend on the
version of Nix, so e.g. the binary cache doesn't work.

(cherry picked from commit 5762b8c8a5)
2022-01-24 16:27:02 +00:00
Daniel Olsen
2d3f43bd97 nixos/nginx: Add defaultListenAddresses option
Lets you specify the default listen address if none are listed in the vhost configuration.

Useful for hosts with more than one ip

(cherry picked from commit ab7e6995ac)
2022-01-24 16:14:36 +00:00
Michele Guerini Rocco
e929d2f7a1 Merge pull request #156546 from NixOS/backport-156529-to-release-21.11
[Backport release-21.11] libreswan: Fix ExecStopPost paths
2022-01-24 17:07:12 +01:00
Janne Heß
b4c00b5061 libreswan: Fix ExecStopPost paths
(cherry picked from commit 3fb4165098)
2022-01-24 15:55:28 +00:00
Vladimír Čunát
a38c452028 Merge #156219: samba 4.15.1 -> 4.15.3 (into release-21.11) 2022-01-24 12:10:40 +01:00
FliegendeWurst
c0c238c131 vim: 8.2.3877 -> 8.2.4186
(cherry picked from commit ea5a1dd5e7)
2022-01-24 09:08:11 +01:00
R. Ryantm
ee064ef57a vim: 8.2.3848 -> 8.2.3877
(cherry picked from commit f0cf6c3918)
2022-01-24 09:08:11 +01:00
legendofmiracles
58e731f057 vim: 8.2.3451 -> 8.2.3848
(cherry picked from commit 134376e256)
2022-01-24 09:08:11 +01:00
R. RyanTM
aaef22612f phoronix-test-suite: 10.6.1 -> 10.8.0
Fix CVE-2022-0157

(cherry picked from commit 9ef985aa84)
2022-01-24 08:38:22 +01:00
R. Ryantm
579045162b phoronix-test-suite: 10.2.2 -> 10.6.1
(cherry picked from commit 713096b520)
2022-01-24 08:38:22 +01:00
Louis Bettens
bfb988d125 onionshare: 2.4 -> 2.5
(cherry picked from commit 23f87f4b69)
2022-01-24 00:12:54 +00:00
Louis Bettens
228c05c29d snowflake: init at 2.0.1
(cherry picked from commit ccfbc1e98d)
2022-01-24 00:12:54 +00:00
Louis Bettens
2226d6d03b python3Packages.cepa: init at 1.8.3
(cherry picked from commit d124b87875)
2022-01-24 00:12:54 +00:00
github-actions[bot]
1a0cafc927 Merge staging-next-21.11 into staging-21.11 2022-01-24 00:10:45 +00:00
github-actions[bot]
ebfde26c00 Merge release-21.11 into staging-next-21.11 2022-01-24 00:10:01 +00:00
Yureka
2c3c30ace0 nixos/mautrix-telegram: run alembic only if available
(cherry picked from commit 407d75ae11)
2022-01-23 23:34:50 +01:00
Yureka
b63d966286 mautrix-telegram: 0.10.2 -> 0.11.1
Backport of the commits
* 4713109cae (mautrix-telegram: 0.10.2 -> 0.11.0)
* 0630d5c381 (mautrix-telegram: remove alembic passthru)
* 2d42d654aa (mautrix-telegram: 0.11.0 -> 0.11.1)

Also added an override for `mautrix` since we cannot backport these
updates as it'd break at least `mautrix-signal`.

While this is technically a breaking change, we don't really have a
choice since Telegram expects all kinds of consuming software to also
display & support "Promotions", otherwise these apps will be
deactivated. To quote the message I got from Telegram in December:

> We ask that you make sure that these sponsored messages are supported and
> properly displayed in your app by January 1, 2022. Unfortunately, Telegram
> cannot financially sustain apps that support Telegram Channels but do not
> display official sponsored messages – such apps will have to be disconnected.
2022-01-23 23:34:15 +01:00
Jonathan Ringer
604c44137d nixos/systemd-boot: fix error output
(cherry picked from commit 87502df43b)
2022-01-23 10:04:55 -08:00
R. Ryantm
7210e7ba34 samba: 4.15.2 -> 4.15.3
(cherry picked from commit 886235de96)
2022-01-23 17:35:29 +01:00
R. Ryantm
ecce7d87aa samba: 4.15.1 -> 4.15.2
(cherry picked from commit 39d9d22eec)
2022-01-23 17:35:28 +01:00
Linus Heckemann
a38b4530fc Merge pull request #156323 from NixOS/backport-156249-to-release-21.11
[Backport release-21.11] python310Packages.mattermostdriver: 7.3.1 -> 7.3.2
2022-01-23 15:33:25 +01:00
R. Ryantm
40972bc450 python310Packages.mattermostdriver: 7.3.1 -> 7.3.2
(cherry picked from commit 607c7e95dc)
2022-01-23 14:32:44 +00:00
Alvar Penning
918dbfa0c6 imagemagick: 7.1.0-19 -> 7.1.0-20
https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.0-20
(cherry picked from commit 74783209bf1905108fc5de24fbe273bcd2287168)
2022-01-23 14:02:34 +01:00
Bobby Rong
399c76c4fa Merge pull request #155767 from NixOS/backport-155739-to-release-21.11
[Backport release-21.11] hydrus: 469 -> 470b
2022-01-23 20:25:48 +08:00
Linus Heckemann
0c5fd380c7 linux: enable FSL_MC_UAPI_SUPPORT
(cherry picked from commit 588db2a720)
2022-01-23 13:10:03 +01:00
Vladimír Čunát
328a13433f Merge #156176: python3Packages.ipython: patch CVE-2022-21699
...into staging-21.11
2022-01-23 11:13:45 +01:00
Vladimír Čunát
32eee87774 Merge #156087: mesa: 21.2.5 - > 21.2.6 (into staging-21.11) 2022-01-23 09:20:10 +01:00
Mario Rodas
5b970ac9c2 Merge pull request #156250 from NixOS/backport-156198-to-release-21.11
[Backport release-21.11] brave: 1.34.80 -> 1.34.81
2022-01-22 23:50:39 -05:00
Francesco Gazzetta
bb6a6bb2a6 staticjinja: add minimal template test
(cherry picked from commit 937b599abe)
2022-01-23 04:29:47 +00:00
Francesco Gazzetta
d21392e487 staticjinja: 4.1.1 -> 4.1.2
(cherry picked from commit 6e453fe75c)
2022-01-23 04:29:47 +00:00
TredwellGit
0ddf22097f brave: 1.34.80 -> 1.34.81
https://github.com/brave/brave-browser/blob/master/CHANGELOG_DESKTOP.md#13481
(cherry picked from commit fafa1363f9)
2022-01-23 02:24:49 +00:00
github-actions[bot]
41a964db7c Merge staging-next-21.11 into staging-21.11 2022-01-23 00:11:10 +00:00
github-actions[bot]
ce137879e5 Merge release-21.11 into staging-next-21.11 2022-01-23 00:10:34 +00:00
Michael Weiss
3d35529a48 Merge pull request #156084 from NixOS/backport-155966-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 97.0.4692.71 -> 97.0.4692.99
2022-01-22 23:01:51 +01:00
Michael Weiss
f2a25f6ad0 mesa: 21.2.5 -> 21.2.6
(cherry picked from commit 63a370df6f)
2022-01-22 13:06:36 -08:00
Vladimír Čunát
698aacc52a Merge #155880: rustc: patch CVE-2022-21658 (into staging-21.11) 2022-01-22 20:10:34 +01:00
Vladimír Čunát
0ec18d1ab6 Merge #155507: e2fsprogs: 1.46.4 -> 1.46.5 (into staging-21.11) 2022-01-22 20:08:19 +01:00
Robert Scott
089318fdd8 python3Packages.ipython: add patch for CVE-2022-21699
add a hacky checkPhase just covering this fix
2022-01-22 17:02:11 +00:00
Guillaume Girol
b2d0283ab1 Merge pull request #154652 from NixOS/backport-147544-to-release-21.11
[Backport release-21.11] stdenv: move overriden stdenv in closure
2022-01-22 15:43:20 +00:00
Michael Weiss
d238056042 Merge pull request #156166 from NixOS/backport-156156-to-release-21.11
[Backport release-21.11] signal-desktop: 5.27.0 -> 5.27.1
2022-01-22 15:32:27 +01:00
pennae
6005756c8f Merge pull request #156073 from NixOS/backport-155522-to-release-21.11
[Backport release-21.11] types.singleLineStr: strings that don't contain '\n'
2022-01-22 14:10:57 +00:00
Mario Rodas
eec5944c1f Merge pull request #156143 from NixOS/backport-156120-to-release-21.11
[Backport release-21.11] firefox-bin: 96.0 -> 96.0.2
2022-01-22 08:04:27 -05:00
Mario Rodas
56a35df86d Merge pull request #156164 from NixOS/backport-156075-to-release-21.11
[Backport release-21.11] yt-dlp: 2021.12.27 -> 2022.1.21
2022-01-22 08:02:44 -05:00
Michael Weiss
4b15a7b3a3 signal-desktop: 5.27.0 -> 5.27.1
Version 5.27.1 is the last version with working Ozone/Wayland support
but we'll have to update to a more recent version soon.
See [0] for more details.

[0]: https://github.com/NixOS/nixpkgs/pull/154003

(cherry picked from commit 1f7d88bba2)
2022-01-22 12:53:32 +00:00
Sandro Jäckel
c2999f4d4d yt-dlp: 2021.12.27 -> 2022.1.21
(cherry picked from commit 36b052a6d5)
2022-01-22 12:30:07 +00:00
Bobby Rong
1e1bfff7af Merge pull request #155861 from NixOS/backport-154892-to-release-21.11
[Backport release-21.11] sfxr-qt: 1.3.0 -> 1.4.0
2022-01-22 19:50:28 +08:00
Vladimír Čunát
9db11f3ad4 Merge #156149: expat: 2.4.2 -> 2.4.3 (security, into staging-21.11) 2022-01-22 10:19:04 +01:00
Sebastian Pipping
e7637c23ba expat: 2.4.2 -> 2.4.3 (security)
(cherry picked from commit 890ea19c1b)
2022-01-22 09:17:59 +00:00
taku0
3338207067 firefox-bin: 96.0 -> 96.0.2
(cherry picked from commit 6d40232a01)
2022-01-22 08:34:45 +00:00
Vladimír Čunát
ce13897b3e Merge #153917: libredirect: build fat library on darwin
... for x86_64, arm64, arm64e (into staging-21.11)
2022-01-22 09:02:59 +01:00
Lorenz Brun
329db841ba accountsservice: build with systemd to allow user switching
(cherry picked from commit a1a7963636d0c5187e342b7fc4a821abce7bdfb1)
2022-01-22 08:56:59 +01:00
Martin Weinelt
a1d36a93ee webkitgtk: 2.34.3 -> 2.34.4
https://webkitgtk.org/security/WSA-2022-0001.html
(cherry picked from commit a574ff9929)
2022-01-22 02:56:16 +00:00
Martin Weinelt
fd2624ba10 Merge pull request #156044 from NixOS/backport-156020-to-release-21.11 2022-01-22 02:14:57 +01:00
github-actions[bot]
3960b6bb85 Merge staging-next-21.11 into staging-21.11 2022-01-22 00:10:22 +00:00
github-actions[bot]
9c07185605 Merge release-21.11 into staging-next-21.11 2022-01-22 00:09:33 +00:00
Maximilian Bosch
7e0f6295d7 Merge pull request #156103 from NixOS/backport-155064-to-release-21.11
[Backport release-21.11] matrix-synapse: 1.49.2 -> 1.50.1
2022-01-22 00:01:40 +01:00
Maximilian Bosch
0c4c30c914 Merge pull request #155866 from NixOS/backport-154984-to-staging-21.11
[Backport staging-21.11] glibc: 2.33-62 -> 2.33-71
2022-01-21 23:50:26 +01:00
Sumner Evans
1c3a52b956 matrix-synapse: 1.49.2 -> 1.50.1
(cherry picked from commit ae7e8b427e)
2022-01-21 22:34:35 +00:00
Sumner Evans
eb8840aa59 matrix_common: init at 1.0.0
New required dependency for matrix-synapse

(cherry picked from commit af080751af)
2022-01-21 22:34:35 +00:00
Maximilian Bosch
aa0e5e461c Merge pull request #155526 from NixOS/backport-145258-to-release-21.11
[Backport release-21.11] steam: fix `/etc/resolv.conf` reference in FHS env
2022-01-21 23:25:50 +01:00
Kim Lindberger
a7581e0728 Merge pull request #155898 from talyz/backport-keycloak-loadcredential
[21.11] nixos/keycloak: Use LoadCredential to load secrets + module formatting
2022-01-21 23:21:22 +01:00
Maximilian Bosch
e84444b14c Merge pull request #156092 from NixOS/backport-156038-to-release-21.11
[Backport release-21.11] grafana: 8.3.3 -> 8.3.4
2022-01-21 22:00:45 +01:00
Maximilian Bosch
aff4e8b7bc grafana: 8.3.3 -> 8.3.4
ChangeLog: https://github.com/grafana/grafana/releases/tag/v8.3.4
(cherry picked from commit b1a80228a6)
2022-01-21 20:10:49 +00:00
Michael Weiss
e58739a061 Merge pull request #156085 from NixOS/backport-155965-to-release-21.11
[Backport release-21.11] chromium: 97.0.4692.71 -> 97.0.4692.99
2022-01-21 21:01:55 +01:00
Michael Weiss
1425a0bb16 chromium: 97.0.4692.71 -> 97.0.4692.99
https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop_19.html

This update includes 26 security fixes.

CVEs:
CVE-2022-0289 CVE-2022-0290 CVE-2022-0291 CVE-2022-0292 CVE-2022-0293
CVE-2022-0294 CVE-2022-0295 CVE-2022-0296 CVE-2022-0297 CVE-2022-0298
CVE-2022-0300 CVE-2022-0301 CVE-2022-0302 CVE-2022-0303 CVE-2022-0304
CVE-2022-0305 CVE-2022-0306 CVE-2022-0307 CVE-2022-0308 CVE-2022-0309
CVE-2022-0310 CVE-2022-0311

(cherry picked from commit a1c5e5bc40)
2022-01-21 18:53:20 +00:00
Michael Weiss
0eaed68d5d ungoogled-chromium: 97.0.4692.71 -> 97.0.4692.99
(cherry picked from commit fc8ddca83b)
2022-01-21 18:51:31 +00:00
pennae
de287abdd1 Merge pull request #156031 from NixOS/backport-155854-to-release-21.11
[Backport release-21.11] nixos/networking: fix assertion on IPMasquerade
2022-01-21 17:04:38 +00:00
Jules Aguillon
5d69648226 types.singleLineStr: Improve description
Co-authored-by: pennae <82953136+pennae@users.noreply.github.com>
(cherry picked from commit 1394bfc32a)
2022-01-21 16:44:03 +00:00
Jules Aguillon
efa53b4e51 types.singleLineStr: Allow and trim trailing \n
Allow a \n character at the end of the string and remove it during the
merge function.

An option of this type will resolve to the value "foo" whether it is set
to "foo" or "foo\n".

This is useful when using 'builtins.readFile' or ''-strings, which might
add an unintended newline (for example, bash trim the final newline from
a subshell).

(cherry picked from commit 4baf8548fb)
2022-01-21 16:44:03 +00:00
Jules Aguillon
03dc83a53c types.singleLineStr: Disallow \r
(cherry picked from commit f25a13212b)
2022-01-21 16:44:03 +00:00
Jules Aguillon
deb63b0aae types.singleLineStr: strings that don't contain '\n'
Add a new type, inheriting 'types.str' but checking whether the value
doesn't contain any newline characters.

The motivation comes from a problem with the
'users.users.${u}.openssh.authorizedKeys' option.
It is easy to unintentionally insert a newline character at the end of a
string, or even in the middle, for example:

    restricted_ssh_keys = command: keys:
      let
        prefix = ''
          command="${command}",no-pty,no-agent-forwarding,no-port-forwarding,no-X11-forwarding
        '';
      in map (key: "${prefix} ${key}") keys;

The 'prefix' string ends with a newline, which ends up in the middle of
a key entry after a few manipulations.

This is problematic because the key file is built by concatenating all
the keys with 'concatStringsSep "\n"', with result in two entries for
the faulty key:

    ''
      command="...",options...
      MY_KEY
    ''

This is hard to debug and might be dangerous. This is now caught at
build time.

(cherry picked from commit df590070b0)
2022-01-21 16:44:03 +00:00
Patrick Hilhorst
ea9fd65474 Merge pull request #156049 from NixOS/backport-155234-to-release-21.11 2022-01-21 16:42:37 +01:00
Bobby Rong
e31e42dfde Merge pull request #155469 from jyooru/backport/brave
[Backport release-21.11] brave: 1.33.106 -> 1.34.80
2022-01-21 20:29:49 +08:00
Patrick Hilhorst
e87b979ddf python3Packages.mutmut: init at 2.2.0
(cherry picked from commit 4326ef50cf)
2022-01-21 11:27:17 +00:00
R. Ryantm
85a74f0506 firefox-unwrapped: 96.0.1 -> 96.0.2
(cherry picked from commit 5125259130)
2022-01-21 10:43:07 +00:00
Maximilian Bosch
a3afed866e Merge pull request #156023 from NixOS/backport-155929-to-release-21.11
[Backport release-21.11] Kernels 2022-01-20
2022-01-21 09:59:35 +01:00
datafoo
4c43cc75e1 nixos/networking: fix assertion on IPMasquerade
(cherry picked from commit 9bfb803dce)
2022-01-21 08:29:13 +00:00
TredwellGit
9120690f7c linux: 5.4.172 -> 5.4.173
(cherry picked from commit 89cc4c1ee6)
2022-01-21 07:41:46 +00:00
TredwellGit
03e75b74b4 linux: 5.16.1 -> 5.16.2
(cherry picked from commit 581019ba48)
2022-01-21 07:41:46 +00:00
TredwellGit
316cc60b9a linux: 5.15.15 -> 5.15.16
(cherry picked from commit fea530a537)
2022-01-21 07:41:46 +00:00
TredwellGit
b4ca747e4f linux: 5.10.92 -> 5.10.93
(cherry picked from commit 6c1f8548a2)
2022-01-21 07:41:46 +00:00
Maximilian Bosch
0900f4777b Merge pull request #155576 from NixOS/backport-155298-to-release-21.11
[Backport release-21.11] Kernels 2022-01-16
2022-01-21 08:36:15 +01:00
Konrad Borowski
ffdd9f9b71 rustc: add patch for CVE-2022-21658 2022-01-21 08:14:36 +01:00
adisbladis
2c9afd35b5 Merge pull request #155995 from Lunarequest/backport-155464-to-release-21.11
Backport epson-201401w to release 21.11
2022-01-21 16:37:37 +12:00
Luna D. Dragon
4fc52a6d6c epson-201401w: init at 1.0.0 2022-01-21 07:49:57 +05:30
Luna D. Dragon
ceb877a222 maintainers: add lunarequest 2022-01-21 07:49:26 +05:30
github-actions[bot]
27c9319879 Merge staging-next-21.11 into staging-21.11 2022-01-21 00:10:52 +00:00
github-actions[bot]
94d5a99ad5 Merge release-21.11 into staging-next-21.11 2022-01-21 00:10:09 +00:00
Robert Scott
c9c7a00737 Merge pull request #155916 from cole-h/backport-155079-to-release-21.11
[21.11] openssl_1_1: fix build on Darwin
2022-01-20 23:52:46 +00:00
Maximilian Bosch
6f07605b69 Merge pull request #155723 from NixOS/backport-155416-to-release-21.11
[Backport release-21.11] element: 1.9.8 -> 1.9.9
2022-01-20 20:32:22 +01:00
taku0
428ccb4296 openssl: remove with lib
See https://github.com/NixOS/nixpkgs/pull/150733/files#r785279764

(cherry picked from commit 6475634e96af4c3ab578d90b7942c15aeffa0e62)
2022-01-20 09:29:37 -08:00
taku0
02fb718a3e openssl_1_1: fix build on Darwin
See https://github.com/NixOS/nixpkgs/pull/150733/files#r785279118

(cherry picked from commit c46627d81abeeeb3eba54c2820d437d58c4e2b01)
2022-01-20 09:24:20 -08:00
talyz
d4fc6e3579 nixos/keycloak: Reformat the code with nixpkgs-fmt 2022-01-20 17:24:35 +01:00
talyz
18163a922e nixos/keycloak: Inherit library functions and builtins
Instead of referencing all library functions through `lib.` and
builtins through `builtins.` at every invocation, inherit them into
the appropriate scope.
2022-01-20 17:24:24 +01:00
talyz
f37efe47f8 nixos/keycloak: Use LoadCredential to load secrets
Use systemd's LoadCredential mechanism to make the secret files
available to the service.

This gets rid of the privileged part of the ExecPreStart script which
only served to copy these files and assign the correct
permissions. There's been issues with this approach when used in
combination with DynamicUser, where sometimes the user isn't created
before the ExecPreStart script runs, causing the error

install: invalid user ‘keycloak’

This should fix that issue.

Unfortunately, all of the ExecPreStart script had to be moved to
ExecStart, since credentials aren't provided to ExecPreStart. See
https://github.com/systemd/systemd/issues/19604.
2022-01-20 17:20:43 +01:00
ajs124
bd39211a3b Merge pull request #150377 from NixOS/backport-150292-to-release-21.11
[Backport release-21.11] libreoffice-still: 7.1.7.2 -> 7.1.8.1
2022-01-20 16:14:14 +01:00
TredwellGit
8fd73939cc glibc: 2.33-62 -> 2.33-71
https://sourceware.org/bugzilla/show_bug.cgi?id=22542
https://nvd.nist.gov/vuln/detail/CVE-2022-23219

https://sourceware.org/bugzilla/show_bug.cgi?id=28768
https://nvd.nist.gov/vuln/detail/CVE-2022-23218
(cherry picked from commit 8dd2546e75)
2022-01-20 12:41:03 +00:00
Vladimír Čunát
cab4c601a7 Merge #154080: gdal: patch CVE-2021-45943 (into release-21.11) 2022-01-20 13:23:30 +01:00
Francesco Gazzetta
3b5caeb721 sfxr-qt: 1.3.0 -> 1.4.0
And some formatting

(cherry picked from commit d7d893c17a)
2022-01-20 11:52:21 +00:00
TredwellGit
69c37c350c [21.11] brave: 1.33.106 -> 1.34.80
https://github.com/brave/brave-browser/blob/master/CHANGELOG_DESKTOP.md#13480
(cherry picked from commit b1a677f080)

Reason: Security vulnerability: #155316
2022-01-20 21:21:54 +10:00
Domen Kožar
5553db5223 Update nixos/modules/services/system/cachix-agent/default.nix
Co-authored-by: pennae <82953136+pennae@users.noreply.github.com>
(cherry picked from commit 91cc0cf63b)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-01-20 12:15:55 +01:00
Domen Kožar
f8f114e33e nixos: add cachix-agent service
(cherry picked from commit 42994be64b)
Signed-off-by: Domen Kožar <domen@dev.si>
2022-01-20 12:15:47 +01:00
Fabian Affolter
330da7601f Merge pull request #155737 from risicle/ris-wolfssl-CVE-2022-23408-r21.11
[21.11] wolfssl: add patch for CVE-2022-23408
2022-01-20 11:26:02 +01:00
Michele Guerini Rocco
78e106cc97 Merge pull request #155734 from NixOS/backport-155535-to-release-21.11
[Backport release-21.11] libreswan: 4.5 -> 4.6
2022-01-20 08:42:03 +01:00
R. Ryantm
34ac404301 palemoon: 29.4.3 -> 29.4.4
(cherry picked from commit d04b212b37)
2022-01-20 02:29:40 +00:00
Daniel Olsen
9f084d4929 hydrus: 469 -> 470b
(cherry picked from commit c7193ca132)
2022-01-20 02:01:46 +00:00
Martin Weinelt
437f6c6f3d Merge pull request #155589 from NixOS/backport-152085-to-release-21.11 2022-01-20 03:00:21 +01:00
Martin Weinelt
e442e6dc38 Merge pull request #153079 from Mic92/sbt-backport 2022-01-20 02:58:51 +01:00
Martin Weinelt
e7a2dd1d1c Merge pull request #155765 from risicle/ris-wireshark-3.4.11-21.11 2022-01-20 02:53:18 +01:00
Graham Christensen
8f7f8a9d11 Merge pull request #155680 from NixOS/backport-155591-to-release-21.11
[Backport release-21.11] pijul: 1.0.0-alpha.57 -> 1.0.0-beta
2022-01-19 20:25:52 -05:00
github-actions[bot]
d3ce858cce Merge staging-next-21.11 into staging-21.11 2022-01-20 00:11:15 +00:00
github-actions[bot]
fc303c5776 Merge release-21.11 into staging-next-21.11 2022-01-20 00:10:42 +00:00
Robert Scott
32e5604fbc wireshark: 3.4.10 -> 3.4.11 2022-01-19 21:56:52 +00:00
rnhmjoj
9d3057ff82 libreswan: fix more binary paths
(cherry picked from commit 4db154ca61)
2022-01-19 21:47:38 +00:00
rnhmjoj
0c995115dd nixos/tests/libreswan: fixup 739c51ae4e
(cherry picked from commit 741a585052)
2022-01-19 21:47:37 +00:00
Robert Scott
5a0b189af6 libreswan: 4.5 -> 4.6
(cherry picked from commit edd7f7c6e1)
2022-01-19 21:47:37 +00:00
Luke Granger-Brown
73dd4dd334 Merge pull request #155713 from NixOS/backport-155243-to-release-21.11
[Backport release-21.11] waybar: 0.9.8 -> 0.9.9
2022-01-19 21:23:08 +00:00
Sumner Evans
eaa54d631c element: 1.9.8 -> 1.9.9
(cherry picked from commit bddd365d79)
2022-01-19 21:16:53 +00:00
Luke Granger-Brown
e3c840d7d9 waybar: add catch2 dep, required for running tests
(cherry picked from commit eda3747c9f)
2022-01-19 20:04:18 +00:00
Luke Granger-Brown
253af10e3b waybar: 0.9.8 -> 0.9.9
(cherry picked from commit 41ec26879a)
2022-01-19 20:04:18 +00:00
Robert Scott
99a390e65f wolfssl: add patch for CVE-2022-23408 2022-01-19 19:46:43 +00:00
Vladyslav M
6105fe758a pijul: 1.0.0-alpha.57 -> 1.0.0-beta
(cherry picked from commit 9671380d66)
2022-01-19 17:35:22 +00:00
pennae
77aa71f66f Merge pull request #155670 from NixOS/backport-155652-to-release-21.11
[Backport release-21.11] nixos/mosquitto: add package option
2022-01-19 16:30:35 +00:00
datafoo
d03fbfa412 nixos/mosquitto: add package option
(cherry picked from commit 1d3f0903a8)
2022-01-19 16:23:31 +00:00
Mario Rodas
8e31fc1173 Merge pull request #155461 from NixOS/backport-152172-to-release-21.11
[Backport release-21.11] alfis: 0.6.9 -> 0.6.10
2022-01-19 07:18:46 -05:00
R. Ryantm
70a147e82b powershell: 7.2.0 -> 7.2.1
(cherry picked from commit 0bec88c4f7)
2022-01-19 09:39:59 +00:00
TredwellGit
7a5dce84a8 linux/hardened/patches/5.4: 5.4.171-hardened1 -> 5.4.172-hardened1
(cherry picked from commit 7c410af47e)
2022-01-19 08:40:52 +00:00
TredwellGit
d7aff5c961 linux/hardened/patches/5.15: 5.15.14-hardened1 -> 5.15.15-hardened1
(cherry picked from commit 632c0297ce)
2022-01-19 08:40:52 +00:00
TredwellGit
b49301976c linux/hardened/patches/5.10: 5.10.91-hardened1 -> 5.10.92-hardened1
(cherry picked from commit 7bc3a9ee46)
2022-01-19 08:40:52 +00:00
TredwellGit
5a36159486 linux: 5.4.171 -> 5.4.172
(cherry picked from commit 3aec9d28ba)
2022-01-19 08:40:52 +00:00
TredwellGit
775721005d linux: 5.16 -> 5.16.1
(cherry picked from commit ea3bccf3b8)
2022-01-19 08:40:52 +00:00
TredwellGit
fd67991396 linux: 5.15.14 -> 5.15.15
(cherry picked from commit 05ad09bd54)
2022-01-19 08:40:52 +00:00
TredwellGit
9faa7a5a4d linux: 5.10.91 -> 5.10.92
(cherry picked from commit 0b04210a04)
2022-01-19 08:40:51 +00:00
Jörg Thalheim
e7c77ae35b Merge pull request #155562 from NixOS/backport-150360-to-release-21.11
[Backport release-21.11] netboot: Support cmdline variable from netboot.xyz
2022-01-19 08:06:22 +00:00
Bobby Rong
9217ba5b73 Merge pull request #155550 from NixOS/backport-155241-to-release-21.11
[Backport release-21.11] renderdoc: 1.16 -> 1.17
2022-01-19 16:04:14 +08:00
Michael Hoang
8304bbf29d netboot: Support cmdline variable from netboot.xyz
(cherry picked from commit 7e7510de4a)
2022-01-19 06:57:10 +00:00
Jan Solanti
c5b49241ad renderdoc: 1.16 -> 1.17
Also set up updateScript since there haven't been any particularly
dramatic changes requiring modifications to the expression in a while.

(cherry picked from commit 1f42b69c67)
2022-01-19 03:56:57 +00:00
Bobby Rong
06fe1eb2aa Merge pull request #155358 from NixOS/backport-155192-to-release-21.11
[Backport release-21.11] git-workspace: 0.8.0 -> 0.9.0
2022-01-19 11:19:57 +08:00
Maximilian Bosch
572112fd9d Merge pull request #155104 from NixOS/backport-155031-to-release-21.11
[Backport release-21.11] gitea: 1.15.9 -> 1.15.10
2022-01-19 01:24:19 +01:00
Maximilian Bosch
659640cf88 Merge pull request #155402 from Ma27/backport-mautrix-whatsapp
[21.11] mautrix-whatsapp: 0.2.2 -> 0.2.3
2022-01-19 01:22:18 +01:00
github-actions[bot]
f83ce033af Merge staging-next-21.11 into staging-21.11 2022-01-19 00:11:55 +00:00
github-actions[bot]
7a4a3f2a73 Merge release-21.11 into staging-next-21.11 2022-01-19 00:11:16 +00:00
Maximilian Bosch
13574a98f3 steam: fix /etc/resolv.conf reference in FHS env
It seems as if it's a problem if `/etc/resolv.conf` is a symlink to
`/run/systemd/resolve/stub-resolv.conf` which is the case when using
`systemd-resolved.service`:

    bwrap: Can't bind mount /oldroot/etc/resolv.conf on /newroot/etc/resolv.conf: Unable to mount source on destination: No such file or directory

I confirmed that by following the symlink of `/etc/resolv.conf`
(pointing to `/run/systemd/resolve/stub-resolv.conf`) with `readlink -f`
the issues are all gone.

(cherry picked from commit f3f82d8330)
2022-01-18 22:03:19 +00:00
Alyssa Ross
1c68efa3f7 e2fsprogs: add meta.changelog
(cherry picked from commit 3b8dc52c3f6fb59e32f7c66dd73b45733480dc3f)
2022-01-18 18:26:50 +00:00
Alyssa Ross
43c560cbb9 e2fsprogs: 1.46.4 -> 1.46.5
(cherry picked from commit 7cb7d96e3ebe8d3805f339c796a94402678ac42d)
2022-01-18 18:26:50 +00:00
06kellyjac
8c1bb37983 nixos/malloc: fix scudo on non-x86_64 machines
(cherry picked from commit 9ac11c0762)
2022-01-18 16:47:46 +00:00
Janne Heß
610d4ea275 Merge pull request #155480 from NixOS/backport-153279-to-release-21.11
[Backport release-21.11] element-desktop: fix "Sqlcipher support is missing"
2022-01-18 17:10:26 +01:00
Austin Butler
0d175f4852 element-desktop: fix "Sqlcipher support is missing"
(cherry picked from commit b85a059738)
2022-01-18 14:38:51 +00:00
pennae
d296da4200 Merge pull request #155470 from NixOS/backport-155443-to-release-21.11
[Backport release-21.11] nixos/modules/syncthing: add 22000/udp to firewall
2022-01-18 13:41:09 +00:00
Zane van Iperen
1d8d5c7870 nixos/modules/syncthing: add 22000/udp to firewall
(cherry picked from commit f533a6d2bd)
2022-01-18 12:31:08 +00:00
R. Ryantm
75bcf25f42 alfis: 0.6.9 -> 0.6.10
(cherry picked from commit f84139ef5e)
2022-01-18 10:11:24 +00:00
pennae
116c2a27f9 Merge pull request #155412 from NixOS/backport-155407-to-release-21.11
[Backport release-21.11] nixos/mosquitto: wait for network-online.target, not network.target
2022-01-18 10:09:57 +00:00
Elis Hirwing
668e5097cc Merge pull request #155366 from NixOS/backport-155122-to-release-21.11
[Backport release-21.11] php: 7.4.26 -> 7.4.27, 8.0.13 -> 8.0.14
2022-01-18 07:48:07 +01:00
Bobby Rong
fa35cb50ab Merge pull request #155434 from NixOS/backport-152126-to-release-21.11
[Backport release-21.11] mkFranzDerivation: fix tray icon on Wayland
2022-01-18 11:40:53 +08:00
github-actions[bot]
48d619083b Merge staging-next-21.11 into staging-21.11 2022-01-18 00:11:08 +00:00
github-actions[bot]
ed098e67a3 Merge release-21.11 into staging-next-21.11 2022-01-18 00:10:29 +00:00
Henri Menke
d545bced5c mkFranzDerivation: fix tray icon on Wayland
(cherry picked from commit 8a9a6919de)
2022-01-17 23:41:44 +00:00
Martin Weinelt
6105454ca2 Merge pull request #155268 from mweinelt/21.11/hostapd 2022-01-17 22:17:10 +01:00
pennae
28800039b4 nixos/mosquitto: wait for network-online.target, not network.target
network.target is reached earlier, but with much fewer services
available. DNS is likely to be not functional before
network-online.target, so waiting for that seems better for that reason
alone. the existing backends for network-online.target all seem to do
reasonable things (wait until all links are in *some* stable state), so
we shouldn't lose anything from waiting.

(cherry picked from commit dc101d9fef)
2022-01-17 20:41:16 +00:00
Robert Scott
47748f3fd3 lighttpd: add patch for CVE-2022-22707
(cherry picked from commit e8146a035f3aba0fb6a16e7b08cd3fc64ddf8d8b)
2022-01-17 20:15:39 +01:00
Charlotte Van Petegem
8ce19aff91 mautrix-whatsapp: 0.2.2 -> 0.2.3
(cherry picked from commit 6070532451)
2022-01-17 19:33:24 +01:00
Dmitry Kalinkin
5ffbd54eea Revert "Revert "expat: 2.4.1 -> 2.4.2 (#151445)""
This reverts commit 92d02948f5.

Placing to staging-21.11
2022-01-17 13:29:51 -05:00
Dmitry Kalinkin
dc839b299d Merge branch 'staging-next-21.11' into staging-21.11 2022-01-17 13:29:33 -05:00
Dmitry Kalinkin
92d02948f5 Revert "expat: 2.4.1 -> 2.4.2 (#151445)"
This reverts commit 34e50e23ca.

Should have gone to staging
2022-01-17 13:27:24 -05:00
Maximilian Bosch
2b0847ed35 Merge pull request #154801 from NixOS/backport-154467-to-release-21.11
[Backport release-21.11] ferdi: 5.6.5 -> 5.6.10
2022-01-17 18:49:50 +01:00
Janne Heß
6c51681d38 Merge pull request #155388 from NixOS/backport-155374-to-release-21.11
[Backport release-21.11] uriparser: Fix cross building
2022-01-17 18:24:56 +01:00
Janne Heß
a10d4fd1e4 uriparser: Fix cross building
When cross building, we need to disable building tests or cmake will
complain about the missing gtest.

Also switching from targetPlatform to buildPlatform caused doCheck to be
properly set to false

(cherry picked from commit 9049874ff1)
2022-01-17 15:37:24 +00:00
sternenseemann
6afc3b137a release.nix: fix eval with aarch64-, but not x86_64-darwin supported
We emit a few jobs conditionally on supportDarwin which only checked for
x86_64-darwin in the past. This change makes it more modular by
transforming it into an attribute set which holds the two darwin
arches. Jobs needing aarch64-darwin or x86_64-darwin are now only
emitted if their respective platform is actually in supportedSystems.

This issue was discovered because the staging-next-21.11 jobset had
commented out x86_64-darwin (presumably due to a build load issue).

(cherry picked from commit 533eb9866c)
2022-01-17 16:15:35 +01:00
Sergei Trofimovich
34e50e23ca expat: 2.4.1 -> 2.4.2 (#151445)
(cherry picked from commit 5400fb8000)
2022-01-17 08:28:36 -05:00
Patrick Hilhorst
dddab8718e Merge pull request #153858 from NixOS/backport-153273-to-release-21.11 2022-01-17 13:16:34 +01:00
Bobby Rong
4f344f49de Merge pull request #155365 from NixOS/backport-155305-to-release-21.11
[Backport release-21.11] vscode-extensions.stkb.rewrap: 1.15.4 -> 1.16.0
2022-01-17 20:05:29 +08:00
Pol Dellaiera
279f614b02 php: 8.0.13 -> 8.0.14
(cherry picked from commit 5fc1a37f1b)
2022-01-17 11:46:37 +00:00
Pol Dellaiera
c3cbfb738b php: 7.4.26 -> 7.4.27
(cherry picked from commit 6e4afa39a5)
2022-01-17 11:46:37 +00:00
datafoo
f7971d7872 vscode-extensions.stkb.rewrap: 1.15.4 -> 1.16.0
(cherry picked from commit 31dda65403)
2022-01-17 11:44:53 +00:00
misuzu
e6b8a80de8 git-workspace: 0.8.0 -> 0.9.0
(cherry picked from commit cb5578639be8ce68ae8c286c942de11057d396a5)
2022-01-17 10:46:19 +00:00
Kim Lindberger
b28d5bc405 Merge pull request #155201 from NixOS/backport-154193-to-release-21.11
[Backport release-21.11] keycloak: 15.1.0 -> 16.1.0 + module improvements
2022-01-17 11:45:46 +01:00
Bobby Rong
fc618794a5 Merge pull request #155271 from blitz/tailscale-update
[21.11] tailscale: 1.14.6 -> 1.20.1
2022-01-17 10:59:44 +08:00
ajs124
31f4289c2b Merge pull request #155164 from NixOS/backport-154976-to-release-21.11
[Backport release-21.11] Kernels 2022-01-14
2022-01-17 03:52:43 +01:00
github-actions[bot]
4f758acc76 Merge staging-next-21.11 into staging-21.11 2022-01-17 00:11:01 +00:00
github-actions[bot]
996865b26b Merge release-21.11 into staging-next-21.11 2022-01-17 00:10:27 +00:00
Martin Weinelt
2f3a49ec91 wpa_supplicant: patch patch SAE/EAP-pwd side-channel attack update 2 2022-01-16 23:20:04 +01:00
Martin Weinelt
145cfeb353 hostapd: patch SAE/EAP-pwd side-channel attack update 2 2022-01-16 23:14:24 +01:00
Ivan Petkov
59d81c4669 tailscale: 1.18.2 -> 1.20.1
https://github.com/tailscale/tailscale/releases/tag/v1.20.1
(cherry picked from commit cca85c7c3d)
2022-01-16 22:41:06 +01:00
Brad Fitzpatrick
1f2d201572 tailscale: remove old xversion tag
Tailscale stopped using that tag several releases ago.

(cherry picked from commit 6675c8e96d)
2022-01-16 22:40:58 +01:00
Thomas Gerbet
669554806d tailscale: 1.18.1 -> 1.18.2
https://github.com/tailscale/tailscale/releases/tag/v1.18.2
(cherry picked from commit 73f84c6a7e)
2022-01-16 22:40:51 +01:00
James Walker
9783ad7df4 tailscale: 1.14.6 -> 1.18.1
(cherry picked from commit 42a7e36904)
2022-01-16 22:40:41 +01:00
Ninjatrappeur
046cead56e Merge pull request #155127 from NixOS/backport-155126-to-release-21.11 2022-01-16 18:31:22 +01:00
Michael Weiss
8a70a6808c Merge pull request #155141 from NixOS/backport-155138-to-release-21.11
[Backport release-21.11] signal-desktop: Fix "Failed to load GLES library: libGLESv2.so.2"
2022-01-16 17:01:19 +01:00
Bobby Rong
87351f3ef6 Merge pull request #150551 from justinas/backport-freon-45
[21.11] gnomeExtensions.freon: 44 -> 45, patch binary paths
2022-01-16 19:04:00 +08:00
Nikolay Amiantov
7c86d4d694 keycloak service: allow to set empty frontend URL
This together with extraConfig:

{
  "subsystem=undertow"."server=default-server"."http-listener=default"."proxy-address-forwarding" = true;
  "subsystem=undertow"."server=default-server"."https-listener=https"."proxy-address-forwarding" = true;
}

Allows to run Keycloak behind a reverse proxy that provides
X-Forwarded-* headers.

(cherry picked from commit 97a0cf62f0)
2022-01-16 10:31:47 +00:00
Nikolay Amiantov
dfc7a28565 keycloak service: add themes support
Custom themes can be packaged and then added using `themes` config
attribute.

(cherry picked from commit 84f70eefd1)
2022-01-16 10:31:47 +00:00
Nikolay Amiantov
67bcf35756 keycloak service: use 'attrsOf anything' for extraConfig
(cherry picked from commit a42abe27c0)
2022-01-16 10:31:47 +00:00
Nikolay Amiantov
b0e3fee9f1 keycloak service: update HTTPS configuration
Keycloak 16.1.0 uses different way to configure HTTPS.
This requires us to order commands correctly, otherwise linked
objects will fail.

(cherry picked from commit 827267a27f)
2022-01-16 10:31:47 +00:00
Nikolay Amiantov
f483cdd569 keycloak service: ordering for CLI script
Allow update commands in the script to be ordered using `mkOrder`.
If we encounter ordered sub-objects we sort them by priority.

To implement this we now explicitly pass current node in `recurse`,
which also allows us to clean up edge case for top-level node.

Also refactor `recurse` to avoid passing result text argument; we
weren't tail recursive before anyway.

(cherry picked from commit 3c7e78cc6a)
2022-01-16 10:31:47 +00:00
Nikolay Amiantov
ff90bbc69b keycloak: 15.1.0 -> 16.1.0
(cherry picked from commit 9bbcc98e30)
2022-01-16 10:31:47 +00:00
Jörg Thalheim
cbf106ac07 Merge pull request #154977 from zhaofengli/dpdk-armv8-generic-backport
[Backport release-21.11] dpdk: add ARMv8 sandboxed build support
2022-01-16 07:19:50 +00:00
Bobby Rong
2bf8d0b948 Merge pull request #155087 from hiljusti/backport-sigi-to-21.11
[Backport release-21.11] sigi: init at 3.0.0
2022-01-16 10:21:45 +08:00
Martin Weinelt
48b9f474ec Merge pull request #155165 from NixOS/backport-154994-to-release-21.11 2022-01-16 03:15:37 +01:00
Martin Weinelt
e33c377713 linux: enable BPF_UNPRIV_DEFAULT_OFF between 5.10 and 5.15
Disable unprivileged access to BPF syscalls to prevent denial of service
and privilege escalation via

a) potential speculative execution side-channel-attacks on unmitigated
hardware[0]

or

b) unvalidated memory access in ringbuffer helper functions[1].

Fixes: CVE-2021-4204, CVE-2022-23222

[0] https://ebpf.io/summit-2021-slides/eBPF_Summit_2021-Keynote-Daniel_Borkmann-BPF_and_Spectre.pdf
[1] https://www.openwall.com/lists/oss-security/2022/01/13/1

(cherry picked from commit 3ee206291a)
2022-01-16 00:51:25 +00:00
TredwellGit
cd4d8bb9f8 linux/hardened/patches/5.4: 5.4.170-hardened1 -> 5.4.171-hardened1
(cherry picked from commit e19681509b)
2022-01-16 00:45:13 +00:00
TredwellGit
278c1020f0 linux/hardened/patches/5.15: 5.15.12-hardened1 -> 5.15.14-hardened1
(cherry picked from commit ead5545be3)
2022-01-16 00:45:12 +00:00
TredwellGit
651899366e linux/hardened/patches/5.10: 5.10.89-hardened1 -> 5.10.91-hardened1
(cherry picked from commit f14a7feff2)
2022-01-16 00:45:12 +00:00
TredwellGit
265c5cedd1 linux/hardened/patches/4.19: 4.19.224-hardened1 -> 4.19.225-hardened1
(cherry picked from commit 56224051e3)
2022-01-16 00:45:12 +00:00
TredwellGit
9947f4d403 linux/hardened/patches/4.14: 4.14.261-hardened1 -> 4.14.262-hardened1
(cherry picked from commit 230a6813d9)
2022-01-16 00:45:12 +00:00
TredwellGit
ce24d922ec linux-rt_5_4: 5.4.161-rt67 -> 5.4.170-rt68
(cherry picked from commit c5f9bb4d21)
2022-01-16 00:45:12 +00:00
Bobby Rong
68daf636f8 Merge pull request #155125 from cpu/cpu-21.11-backport-blightmud-3.5.0
[21.11] blightmud: init at 3.5.0
2022-01-16 08:38:22 +08:00
github-actions[bot]
e4bdfd5c17 Merge staging-next-21.11 into staging-21.11 2022-01-16 00:11:57 +00:00
github-actions[bot]
ed69a50061 Merge release-21.11 into staging-next-21.11 2022-01-16 00:11:14 +00:00
Renaud
d3d8d8c2b7 Merge pull request #154269 from NixOS/backport-153844-to-release-21.11
[Backport release-21.11] mosquitto: 2.0.12 -> 2.0.14
2022-01-15 23:41:41 +01:00
Martin Weinelt
6445e67c4e Merge pull request #155114 from NixOS/backport-155100-to-release-21.11 2022-01-15 23:28:59 +01:00
Michael Weiss
fa0eb6d8e3 signal-desktop: Fix "Failed to load GLES library: libGLESv2.so.2"
A new symlink is required to fix the following error:
[3744707:0100/000000.911609:ERROR:egl_util.cc(74)] Failed to load GLES library: libGLESv2.so.2: libGLESv2.so.2: cannot open shared object file: No such file or directory
zsh: segmentation fault (core dumped) signal-desktop --enable-features=UseOzonePlatform --ozone-platform=wayland

The GPU acceleration still fails (not sure if it worked before) but at least
"signal-desktop --enable-features=UseOzonePlatform --ozone-platform=wayland"
launches again (without "--disable-gpu"):
[40492:0115/184719.611780:ERROR:gpu_process_host.cc(968)] GPU process exited unexpectedly: exit_code=139
[40492:0115/184720.256775:ERROR:gpu_process_host.cc(968)] GPU process exited unexpectedly: exit_code=139
[40492:0115/184720.892093:ERROR:gpu_process_host.cc(968)] GPU process exited unexpectedly: exit_code=139
[40620:0115/184721.033949:ERROR:sandbox_linux.cc(376)] InitializeSandbox() called with multiple threads in process gpu-process.
[40620:0115/184721.069600:ERROR:gl_utils.cc(318)] [.RendererMainThread-0x227200113f00]GL Driver Message (OpenGL, Performance, GL_CLOSE_PATH_NV, High): GPU stall due to ReadPixels
[40620:0115/184721.133265:ERROR:gl_utils.cc(318)] [.RendererMainThread-0x227200113f00]GL Driver Message (OpenGL, Performance, GL_CLOSE_PATH_NV, High): GPU stall due to ReadPixels
[40620:0115/184721.158341:ERROR:gl_utils.cc(318)] [.RendererMainThread-0x227200113f00]GL Driver Message (OpenGL, Performance, GL_CLOSE_PATH_NV, High): GPU stall due to ReadPixels

(After three GPU process crashes Chromium should automatically fall back
to software rendering.)

Fix #155050 (it only fixes the crashes though, not the underlying
issue, but that's likely all we can do for the moment as other Linux
distributions are affected as well; Ozone/Wayland is just not stable yet)

(cherry picked from commit 892a9971b0)
2022-01-15 18:36:57 +00:00
Félix Baylac-Jacqué
67f0afeab9 prosody: remove outdated passthrough test reference
4369bebd9a removed the prosody-mysql
test. We forgot to remove the associated passthru test entry in the
prosody derivation.

(cherry picked from commit 3469429c39)
2022-01-15 16:06:16 +00:00
Bobby Rong
1aced6f702 Merge pull request #155124 from NixOS/backport-155120-to-release-21.11
[Backport release-21.11] doc: fix broken link
2022-01-15 23:46:10 +08:00
Nicolas Benes
36001c7c7f doc: fix broken link
The file was renamed/modified in 3f40ca4 but the documentation was not
updated. Closes #155049.

(cherry picked from commit 5c8d6d6cee)
2022-01-15 15:39:25 +00:00
Daniel McCarney
f4443e4375 blightmud: init at 3.5.0
Blightmud is a terminal client for connecting to Multi User Dungeon
(MUD) games. It is written in Rust and supports TLS, GMCP, MSDP, MCCP2,
tab completion, text searching and a split view for scrolling. Blightmud
can be customized with Lua scripting for aliases, triggers, timers,
customized status bars, and more. Blightmud supports several
accessibility features including an optional built-in text-to-speech
engine and a screen reader friendly mode.

For nixpkgs it is largely a standard derivation for a rust project using
`rustPlatform.buildRustPackage`. There is some customization required
for the optional text-to-speech (TTS) engine support. In this case the
derivation must also set the `LIBCLANG_PATH` and customize
`BINDGEN_EXTRA_CLANG_ARGS` in order for a required crate to be able to
`rust-bindgen` the `libspeechd` dependency it wraps. Lastly the
derivation has to skip some integration-style tests that don't play
nicely with the nixpkgs build environment - the majority of unit tests
work so they are left running in the check phase.

Since the TTS support brings in heavy dependencies, but is a useful
accessibility feature, the Blightmud derivation is added to
`all-packages.nix` twice:

1. the `blightmud` attribute builds a configuration without TTS support.
2. the `blightmud-tts` attribute builds a configuration _with_ TTS
   support.

The new Blightmud derivation is placed in `pkgs/games/blightmud/`
following the precedent set by another packaged GUI-based MUD client,
`mudlet` with `pkgs/games/mudlet/`.

(cherry picked from commit ae1bee344a)
2022-01-15 10:37:21 -05:00
Ninjatrappeur
c2d19f7eb1 Merge pull request #155088 from NixOS/backport-155039-to-release-21.11 2022-01-15 16:35:55 +01:00
Martin Weinelt
37b9206f05 firefox-bin: 96.0 -> 96.0.1
https://www.mozilla.org/en-US/firefox/96.0.1/releasenotes/
(cherry picked from commit 570e93c25e)
2022-01-15 14:10:52 +00:00
Martin Weinelt
952052ecc1 firefox: 96.0 -> 96.0.1
https://www.mozilla.org/en-US/firefox/96.0.1/releasenotes/
(cherry picked from commit 4c3a07ffe0)
2022-01-15 14:10:52 +00:00
techknowlogick
abba695570 gitea: 1.15.9 -> 1.15.10
(cherry picked from commit 07d7fdce3e)
2022-01-15 21:35:49 +08:00
techknowlogick
69572e7e95 maintainers: add techknowlogick
(cherry picked from commit eaff5241bf)
2022-01-15 21:35:48 +08:00
Vladimír Čunát
69f169c5f0 Merge #155097: ocamlPackages.ca-certs: disable broken tests
...into release-21.11
2022-01-15 14:28:06 +01:00
Renaud
2e3c11ab40 Merge pull request #155040 from NixOS/backport-155019-to-release-21.11
[Backport release-21.11] clamav: 0.103.3 -> 0.103.5
2022-01-15 14:09:40 +01:00
Pavol Rusnak
82fdbcc7be Merge pull request #155096 from NixOS/backport-155072-to-release-21.11
[Backport release-21.11] electron: mark versions <= 12 as EOL
2022-01-15 12:33:19 +01:00
sternenseemann
786f33e89b ocamlPackages.ca-certs: disable test suite expecting nss db
nss-cacert has updated a few certificates, including Google's which
breaks the test suite of ca-certs expecting the old version.

(cherry picked from commit d1cc3df792ff0cc1169709b3a86cc7f70c3ed947)
2022-01-15 11:32:43 +00:00
Brandon Weeks
f9ebdb983d electron: mark versions <= 12 as EOL
(cherry picked from commit 79e607c351)
2022-01-15 11:31:34 +00:00
Renaud
dfd48fa9e8 Merge pull request #154609 from NixOS/backport-154505-to-release-21.11
[Backport release-21.11] strace: 5.15 -> 5.16
2022-01-15 12:14:45 +01:00
Renaud
98254e5a7e Merge pull request #154847 from NixOS/backport-154844-to-release-21.11
[Backport release-21.11] tig: 2.5.4 -> 2.5.5
2022-01-15 11:33:31 +01:00
Yarny0
c818935fdf tsm-client: 8.1.13.2 -> 8.1.13.3
Link to Security Bulletin:
https://www.ibm.com/support/pages/node/6540692 (CVE-2021-44832)

cherry-picked from https://github.com/NixOS/nixpkgs/pull/138386
2022-01-15 10:57:52 +01:00
Yarny0
ca48de2ae7 tsm-client: 8.1.13.1 -> 8.1.13.2
Link to Security Bulletin:
https://www.ibm.com/support/pages/node/6537640 (CVE-2021-45105, CVE-2021-45046)

cherry-picked from https://github.com/NixOS/nixpkgs/pull/138386
2022-01-15 10:57:52 +01:00
Yarny0
18c833046e tsm-client: 8.1.13.0 -> 8.1.13.1
Link to Security Bulletin:
https://www.ibm.com/support/pages/node/6527080 (CVE-2021-44228)

cherry-picked from https://github.com/NixOS/nixpkgs/pull/138386
2022-01-15 10:57:52 +01:00
Yarny0
8c5a51a174 tsm-client: use rpm source instead of deb/Ubuntu
IBM publishes their IBM Spectrum Protect client
for Linux in two flavors:

* "Linux x86_64 client"
* "Linux x86_64 Ubuntu client"

Up to this commit, nixpkgs used the Ubuntu
flavor to build its `tsm-client` derivation.
However, the history of published archive files in

* https://public.dhe.ibm.com/storage/tivoli-storage-management/maintenance/client/v8r1/Linux/
* https://public.dhe.ibm.com/storage/tivoli-storage-management/patches/client/v8r1/Linux/

suggests that updates in the fourth level of
the version numbers (e.g. 8.1.13.0 -> 8.1.13.1)
do not get published as Ubuntu flavor.
It order to be able to always use the latest release,
this commit switches to the non-Ubuntu flavor.
The non-Ubuntu archive contains rpm files,
so this commit switches from `ar` to `rpmextract`.
Instead of unpacking all deb files,
the build recipe now unpacks all _but one_ rpm file:
The file `TIVsm-WEBGUI.x86_64.rpm` apparently
contains a plugin that is not included
in the Ubuntu version (see note below).
Comparing the old and the new derivation's output indicates
that this choice minimizes the difference between the results:

The output of the old (Ubuntu flavor) derivation contains:
* `commons-codec-1.6.jar`
* `share/` with changelog and copyright information
  for the packages `gskssl64` and `gskcrypt64`

The output of the new (non-Ubuntu flavor) derivation contains:
* `lib64`, symlink to `lib`
* `commons-codec-1.14.jar`
* `opt/tivoli/tsm/license/{api,baclient}/sm/`
  with license agreement files in many languages

Besides these differences, the outputs' file names are equal.

Note: I don't know what functionality
`TIVsm-WEBGUI.x86_64.rpm` actually provides.
Unpacking it with the other rpm files makes patchelf complain
about missing X11 libraries, so in order to include it here,
one would likely need to add those to `buildInputs`.
However, as the old (Ubuntu flavor) `tsm-client` package
did not contain this functionality and as I cannot test
or use it in any way, I opted to not include it now.
If we want to include this with a later commit,
we should add another package build option (like `enableGui`)
so that the default `tsm-client` package does not pull in
X11 libraries and its closure size therefore stays small.

cherry-picked/adapted from https://github.com/NixOS/nixpkgs/pull/138386
2022-01-15 10:57:52 +01:00
Yarny0
f976478dd9 tsm-client: 8.1.8.0 -> 8.1.13.0
tsm-client now links against openssl;
patchelf complains without it.

Links to IBM's "Authorized Program Analysis Report"s
(something like release notes),
to READMEs, and to Security Bulletins,
for all updates between 8.1.8.0 and 8.1.13.0:

* 8.1.9.x
  * APARs: https://www.ibm.com/support/pages/node/1077159
  * READMEs: https://www.ibm.com/support/pages/node/1108473
  * https://www.ibm.com/support/pages/node/1107261 (CVE-2018-2025)
  * https://www.ibm.com/support/pages/node/1107777 (CVE-2019-4406)

* 8.1.10.x
  * APARs: https://www.ibm.com/support/pages/node/6223098
  * READMEs: https://www.ibm.com/support/pages/node/6223388
  * https://www.ibm.com/support/pages/node/6221448 (CVE-2020-4494, CVE-2020-4406)
  * https://www.ibm.com/support/pages/node/6245356 (CVE-2020-2654)
  * https://www.ibm.com/support/pages/node/6245366 (CVE-2015-4000)

* 8.1.11.x
  * APARs: https://www.ibm.com/support/pages/node/6367203
  * READMEs: https://www.ibm.com/support/pages/node/6367205
  * https://www.ibm.com/support/pages/node/6371646
  * https://www.ibm.com/support/pages/node/6371650
  * https://www.ibm.com/support/pages/node/6371652

* 8.1.12.x
  * APARs: https://www.ibm.com/support/pages/node/6429561
  * READMEs: https://www.ibm.com/support/pages/node/6443671
  * https://www.ibm.com/support/pages/node/6445503 (CVE-2021-20532)
  * https://www.ibm.com/support/pages/node/6445497 (CVE-2021-29672, CVE-2021-20546)
  * https://www.ibm.com/support/pages/node/6445489 (CVE-2020-1971, CVE-2021-23840, CVE-2021-23841)
  * https://www.ibm.com/support/pages/node/6445483 (CVE-2020-27221, CVE-2020-14782)

* 8.1.13.x
  * APARs: https://www.ibm.com/support/pages/node/6524936
  * READMEs: https://www.ibm.com/support/pages/node/6524938
  * https://www.ibm.com/support/pages/node/6524706 (CVE-2021-39048)
  * https://www.ibm.com/support/pages/node/6524712 (CVE-2021-3712, CVE-2021-3711)

cherry-picked/adapted from https://github.com/NixOS/nixpkgs/pull/138386
2022-01-15 10:57:51 +01:00
Yarny0
5afa0bab43 tsm-client: update URL structure
IBM has changed the URL structures of their support web pages.
The commit at hand updates most URLs and
in particular the package update instructions
so they follow the new structure.
It also calculates the source download URL from the
version number, so package updates no longer have to
update the URL in addition to the version string.

cherry-picked from https://github.com/NixOS/nixpkgs/pull/138386
2022-01-15 10:57:51 +01:00
Andreas Rammhold
82b7bfb41f nixos/tests: remove broken prosody-mysql test
The test has been broken for some time and the test errors are
non-obvious. None of the current maintainers know how to fix it so it is
better to get rid of it then to keep a continously failing test.

(cherry picked from commit 4369bebd9a)
2022-01-15 09:18:02 +00:00
Andreas Rammhold
bd11da5fc6 prosody: 0.11.10 -> 0.11.12
This fixes CVE-2022-0217 [0].

[0] https://prosody.im/security/advisory_20220113/

(cherry picked from commit 8b8fbbf1fa)
2022-01-15 09:18:02 +00:00
♪ hiljusti 🎮
78200d6de1 sigi: 2.1.1 -> 3.0.0
(cherry picked from commit 022fc3ab02)
2022-01-15 01:09:45 -08:00
♪ hiljusti 🎮
d43ee23e8d sigi: init at 2.1.1
(cherry picked from commit bea08efd68)
2022-01-15 01:09:30 -08:00
♪ hiljusti 🎮
53b33ce88c maintainers: add hiljusti
(cherry picked from commit fff02c347c)
2022-01-15 01:09:20 -08:00
Vladimír Čunát
8e82ab3a62 Merge #154531: nixos/kresd: fix IPv6 scope syntax
...into release-21.11
2022-01-15 09:01:14 +01:00
Bobby Rong
a8c382a641 Merge pull request #154841 from NixOS/backport-153792-to-release-21.11
[Backport release-21.11] hydrus: 467 -> 469
2022-01-15 13:49:00 +08:00
Jonathan Ringer
770f85fdff linuxPackages.nvidia_x11_beta: 495.29.05 -> 510.39.01
(cherry picked from commit 53a5395626bd5f5c5d0557dd6ed3f8c4eeec54fa)
2022-01-14 17:28:07 -08:00
Maximilian Bosch
45d43a7a41 Merge pull request #153268 from NixOS/backport-153210-to-release-21.11
[Backport release-21.11] element-{web,desktop}: 1.9.7 -> 1.9.8
2022-01-15 02:01:21 +01:00
github-actions[bot]
881ffd5296 Merge staging-next-21.11 into staging-21.11 2022-01-15 00:10:57 +00:00
github-actions[bot]
e6509ed444 Merge release-21.11 into staging-next-21.11 2022-01-15 00:10:19 +00:00
Solene Rapenne
44f68efb70 clamav: 0.103.3 -> 0.103.5
(cherry picked from commit 50ede5f4e0)
2022-01-14 21:31:52 +00:00
Thiago Kenji Okada
3ddd960a3b Merge pull request #153935 from NixOS/backport-153515-to-release-21.11
[Backport release-21.11] nixos-rebuild: do not resolve flake path
2022-01-14 17:06:37 -03:00
github-actions[bot]
5c128cda9c gitlab: 14.6.1 -> 14.6.2 (#155002)
https://about.gitlab.com/releases/2022/01/11/security-release-gitlab-14-6-2-released/

Resolves #154960

(cherry picked from commit b7d5cf1245e1184f69513b3fc3c5825c1addcc7d)

Co-authored-by: Lara <lara@uwu.is>
2022-01-14 18:06:46 +01:00
Alyssa Ross
afa8670aa7 netbsd.compat: don't use musl's sys/cdefs.h
When building glib statically, a Meson check would fail, because the
check would interpret any warning as failure, and it would see the
warning that the musl sys/cdefs.h emits about the file being
deprecated.

(cherry picked from commit 2b9c5958a1)
2022-01-14 17:18:25 +01:00
Alyssa Ross
777249186f pkgsStatic.netbsd: fix nbtool_config.h conflicts
In pkgsStatic, /all/ build inputs are propagated.  This means that
netbsd.compat was propagated, along with its setup hook, which broke
static glib builds because glib defines a function with the same name
as one in nbtool_config.h, and nbtool_config.h was being automatically
included in every C file processed by the compiler, in any transitive
dependent of netbsd.compat's setup hook.

To fix this, rather than forcing nbtool_config.h to be included for
_every_ C file in a derivation that depends on netbsd.compat, modify
the NetBSD-specific mkDerivation to detect files that need the header,
and patch it in there where appropriate.  That way, only files that
are part of NetBSD will be affected, not all transitive dependents.

(cherry picked from commit 7be5fbf70f)
2022-01-14 17:18:25 +01:00
Pavol Rusnak
fe6f208d68 Merge pull request #154990 from NixOS/backport-154978-to-release-21.11
[Backport release-21.11] Update Electron
2022-01-14 10:47:25 +01:00
TredwellGit
676259ece6 electron_16: 16.0.6 -> 16.0.7
https://github.com/electron/electron/releases/tag/v16.0.7
(cherry picked from commit b409d14ef1)
2022-01-14 08:51:56 +00:00
TredwellGit
5c895789e6 electron_15: 15.3.4 -> 15.3.5
https://github.com/electron/electron/releases/tag/v15.3.5
(cherry picked from commit 459949f7a1)
2022-01-14 08:51:56 +00:00
TredwellGit
0bea0452ab electron_14: 14.2.3 -> 14.2.4
https://github.com/electron/electron/releases/tag/v14.2.4
(cherry picked from commit dc0e14368a)
2022-01-14 08:51:56 +00:00
TredwellGit
942a93d7ac electron_13: 13.6.6 -> 13.6.7
https://github.com/electron/electron/releases/tag/v13.6.7
(cherry picked from commit 1e540bba5a)
2022-01-14 08:51:56 +00:00
Zak B. Elep
f8be2bd928 Merge pull request #152407 from NixOS/backport-150538-to-release-21.11
[Backport release-21.11] convos: 6.26 -> 6.42
2022-01-14 15:14:01 +08:00
Pierre Bourdon
8daebcbeb0 dpdk: add ARMv8 sandboxed build support
DPDK defaults to reading machine info from /sys unless specific platform
info is provided at configure time. Tell it to build a generic version
instead of trying to optimize based on the build host.
2022-01-13 18:27:12 -08:00
Robert Scott
7f6df6405f python3Packages.pillow: add patches for CVE-2022-22815 CVE-2022-22816 CVE-2022-22817 2022-01-13 16:28:45 -08:00
github-actions[bot]
4bf9aa4cdf Merge staging-next-21.11 into staging-21.11 2022-01-14 00:11:09 +00:00
github-actions[bot]
9fd1c55a4e Merge release-21.11 into staging-next-21.11 2022-01-14 00:10:30 +00:00
Vladimír Čunát
b809f895a9 Merge #154489: staging-next: 21.11 iteration 5 - 2022-01-11 2022-01-13 23:08:26 +01:00
sternenseemann
1a26ef2927 Merge remote-tracking branch 'origin/release-21.11' into staging-next-21.11 2022-01-13 21:37:36 +01:00
Janne Heß
ac6af9a0be Merge pull request #154931 from mweinelt/21.11/cryptsetup
[21.11] cryptsetup: 2.4.1 -> 2.4.3
2022-01-13 21:32:27 +01:00
Martin Weinelt
6ed4e6eb56 cryptsetup: 2.4.2 -> 2.4.3
(cherry picked from commit 99ee04b5d1)
2022-01-13 21:10:01 +01:00
R. Ryantm
72d20e514e cryptsetup: 2.4.1 -> 2.4.2
(cherry picked from commit 4ed0620c9a)
2022-01-13 21:09:54 +01:00
Ryan Burns
414dcbafa4 Merge pull request #153301 from NixOS/backport-153146-to-release-21.11
[Backport release-21.11] aws-c-s3: 0.1.27 -> 0.1.30
2022-01-13 11:47:39 -08:00
Kevin Cox
1e74d72586 Merge pull request #154916 from NixOS/backport-154787-to-release-21.11
[Backport release-21.11] bloop: 1.4.11 -> 1.4.12
2022-01-13 13:49:14 -05:00
Bernardo Meurer
c98acaec24 Merge pull request #154893 from NixOS/backport-154870-to-release-21.11 2022-01-13 18:12:30 +00:00
Kevin Rauscher
b9ab0e62b3 bloop: 1.4.11 -> 1.4.12
(cherry picked from commit da5f261fdf)
2022-01-13 18:10:49 +00:00
Vladimír Čunát
3bd5dedc19 Merge #154714: linux: updates 2022-01-11 (into release-21.11) 2022-01-13 16:27:20 +01:00
taku0
9c6e867751 thunderbird-bin: 91.4.1 -> 91.5.0
(cherry picked from commit d49cc4d00e)
2022-01-13 14:50:57 +00:00
taku0
1147afb85c thunderbird: 91.4.1 -> 91.5.0
(cherry picked from commit e12befeada)
2022-01-13 14:50:57 +00:00
Bobby Rong
00d17d8ddc Merge pull request #154278 from schnusch/remote-touchpad-21.11
[21.11] remote-touchpad: 1.0.4 -> 1.0.5
2022-01-13 18:04:34 +08:00
R. Ryantm
a836a5d677 sqlcipher: 4.4.3 -> 4.5.0
(cherry picked from commit 1e4ded4dec1a44eed872afc49743c65bb62b6e9e)
2022-01-13 09:32:51 +00:00
Matthias Beyer
fe1b0e857b tig: 2.5.4 -> 2.5.5
Signed-off-by: Matthias Beyer <mail@beyermatthias.de>
(cherry picked from commit e6ea8407a3)
2022-01-13 08:04:37 +00:00
Daniel Olsen
77848788ef hydrus: 468 -> 469
(cherry picked from commit 7738de9075)
2022-01-13 07:01:53 +00:00
Daniel Olsen
1a0ed943e9 hydrus: 467 -> 468
(cherry picked from commit 0e5389c1f8)
2022-01-13 07:01:53 +00:00
github-actions[bot]
9984cda465 Merge staging-next-21.11 into staging-21.11 2022-01-13 00:11:39 +00:00
github-actions[bot]
1ec0d18e69 Merge release-21.11 into staging-next-21.11 2022-01-13 00:11:02 +00:00
Alyssa Ross
b991bbd41e nixos/stage-1: update udev.log_level name in docs
I was confused why I couldn't find a mention of udev.log_priority in
systemd-udevd.service(8).  It turns out that it was renamed[1] to
udev.log_level.  The old name is still accepted, but it'll avoid
further confusion if we use the new name in our documentation.

[1]: 64a3494c3d

(cherry picked from commit 6a1ea53c13dd624c2ac1aa91ebffc4fab61cf222)
2022-01-12 23:58:16 +00:00
Martin Weinelt
aaf6559bd1 Merge pull request #154812 from NixOS/backport-154779-to-release-21.11 2022-01-12 23:46:57 +01:00
FliegendeWurst
5ee25e2a7a tor-browser-bundle-bin: 11.0.3 -> 11.0.4
(cherry picked from commit 1b8861e0d4)
2022-01-12 22:06:35 +00:00
Jonathan Ringer
9be3564765 spire: init at 1.1.2
(cherry picked from commit 933c7f0902)
2022-01-12 12:35:32 -08:00
R. Ryantm
129877d61c ferdi: 5.6.5 -> 5.6.10
(cherry picked from commit 2875c98aaf)
2022-01-12 20:11:43 +00:00
Mario Rodas
285bb1eb13 Merge pull request #154777 from mohe2015/backport-154474-to-release-21.11
[21.11] nodejs-{17,16,14,12}_x: security updates
2022-01-12 13:13:37 -05:00
Moritz Hedtke
884ac2016e nodejs-12_x: 12.22.7 -> 12.22.9
(cherry picked from commit d1de6589a4)
2022-01-12 17:44:37 +01:00
Moritz Hedtke
706407ff75 nodejs-14_x: 14.18.1 -> 14.18.3
(cherry picked from commit 2cfe7ecbc9)
2022-01-12 17:44:36 +01:00
Moritz Hedtke
dcbb438588 nodejs-16_x: 16.13.0 -> 16.13.2
(cherry picked from commit 2ac55cedc9)
2022-01-12 17:44:32 +01:00
Moritz Hedtke
acc1494a9a nodejs-17_x: 17.1.0 -> 17.3.1
(cherry picked from commit 4bfeab40d6)
2022-01-12 17:44:16 +01:00
Wout Mertens
4f33d3ce4f Merge pull request #154712 from NixOS/backport-147248-to-release-21.11
[Backport release-21.11] nixos/netdata: add configDir option
2022-01-12 18:15:14 +02:00
Roosembert Palacios
d0d8fb323f prometheus-bind-exporter: 0.4.0 -> 0.5.0
Signed-off-by: Roosembert Palacios <roosemberth@posteo.ch>
(cherry picked from commit 8efd3bacc2)
2022-01-12 10:37:02 -05:00
Artturi
ef47d9e6f8 Merge pull request #154719 from NixOS/backport-154698-to-release-21.11 2022-01-12 16:30:10 +02:00
Martin Weinelt
502a74ebf3 batman-adv: 2021.1 -> 2021.4
https://www.open-mesh.org/news/106
https://www.open-mesh.org/news/105
https://www.open-mesh.org/news/104
(cherry picked from commit fccd2117f26e40d26311c70fe985814666ad925d)
2022-01-12 14:11:35 +00:00
Alyssa Ross
babb6fc77d linux_latest: 5.15.12 -> 5.16
(cherry picked from commit 6c411d1579ca5a8a2febf32a123fcf2fc754fc94)
2022-01-12 14:11:35 +00:00
Yureka
8a390f8aef pleroma: 2.4.1 -> 2.4.2
(cherry picked from commit e8a97b657117835d34e88bb42c259c0bb7cb8faf)
2022-01-12 14:11:37 +01:00
Renaud
d698c24268 Merge pull request #154747 from c0bw3b/backport/mill
[Backport release-21.11] mill: 0.9.10 -> 0.9.12
2022-01-12 13:16:49 +01:00
R. RyanTM
206b31ae75 mill: 0.9.11 -> 0.9.12
* mill: 0.9.11 -> 0.9.12 (#154634)

* mill: update homepage

Co-authored-by: Renaud <c0bw3b@users.noreply.github.com>
(cherry picked from commit 9292a52ce0)
2022-01-12 12:16:27 +01:00
R. Ryantm
2da185036a mill: 0.9.10 -> 0.9.11
(cherry picked from commit fb5e054a5c)
2022-01-12 12:15:54 +01:00
Infinidoge
9ad4552482 discord-canary: 0.0.131 -> 0.0.132
(cherry picked from commit 6bc0a0443a)
2022-01-12 08:51:57 +00:00
Kim Lindberger
bd11019686 Merge pull request #154655 from NixOS/backport-152766-to-release-21.11
[Backport release-21.11] nixos/elasticsearch: fix postStart to allow non-localhost listenAddress
2022-01-12 09:44:00 +01:00
adisbladis
ac8af779f9 Merge pull request #154711 from NixOS/backport-154703-to-release-21.11
[Backport release-21.11] poetry2nix: 1.24.1 -> 1.26.0
2022-01-12 20:19:39 +12:00
TredwellGit
acc68f6f37 linux: 5.4.170 -> 5.4.171
(cherry picked from commit 61dd0c8e85)
2022-01-12 08:17:15 +00:00
TredwellGit
14025a8d66 linux: 5.15.13 -> 5.15.14
(cherry picked from commit 4cf69dc13a)
2022-01-12 08:17:15 +00:00
TredwellGit
19c7fe87a9 linux: 5.10.90 -> 5.10.91
(cherry picked from commit caa8c4963d)
2022-01-12 08:17:15 +00:00
TredwellGit
e6ed922049 linux: 4.9.296 -> 4.9.297
(cherry picked from commit 84e167d8b3)
2022-01-12 08:17:15 +00:00
TredwellGit
cb57af0a3c linux: 4.4.298 -> 4.4.299
(cherry picked from commit e30d75558e)
2022-01-12 08:17:15 +00:00
TredwellGit
acc002877d linux: 4.19.224 -> 4.19.225
(cherry picked from commit 7bf2f23df2)
2022-01-12 08:17:15 +00:00
TredwellGit
80bc239df5 linux: 4.14.261 -> 4.14.262
(cherry picked from commit 169ed1335f)
2022-01-12 08:17:14 +00:00
misuzu
23feb008b3 nixos/netdata: expose /etc/netdata
(cherry picked from commit 768d0d6098)
2022-01-12 07:48:22 +00:00
misuzu
d22cf88b87 nixos/netdata: add configDir option
This option makes the complete netdata configuration directory available for
modification. The default configuration is merged with changes
defined in the configDir option.

Co-authored-by: Michael Raitza <spacefrogg-github@meterriblecrew.net>
(cherry picked from commit 9e6145c73b)
2022-01-12 07:48:21 +00:00
adisbladis
cb279ea1d4 poetry2nix: 1.24.1 -> 1.25.0
(cherry picked from commit 1d820c2224)
2022-01-12 07:45:51 +00:00
Jörg Thalheim
0248b18079 Merge pull request #154657 from NixOS/backport-154307-to-release-21.11
[Backport release-21.11] nixos/vmware-guest: add mptspi kernel module to initrd
2022-01-12 05:20:48 +00:00
Martin Weinelt
34e50ce58f Merge pull request #154377 from NixOS/backport-154354-to-release-21.11 2022-01-12 05:30:25 +01:00
Andreas Fehn
9acedfd7ef elvish: fix building unusable executable
Two executables with conflicting names were build where the latter one
will not start the interactive shell.

(cherry picked from commit 54e83f150d)
2022-01-11 16:23:55 -08:00
github-actions[bot]
852a0745ad Merge staging-next-21.11 into staging-21.11 2022-01-12 00:12:35 +00:00
github-actions[bot]
aa6bb8eaf0 Merge release-21.11 into staging-next-21.11 2022-01-12 00:11:42 +00:00
Alyssa Ross
801c111fb7 COPYING: 2021 -> 2022
(cherry picked from commit bf601a58aa)
2022-01-11 22:51:24 +00:00
Mark Sagi-Kazar
f76af45dda nixos/vmware-guest: add mptspi kernel module to initrd
Required by VMware Fusion

See details in nix-community/nixos-generators#132

Signed-off-by: Mark Sagi-Kazar <mark.sagikazar@gmail.com>
(cherry picked from commit 06771b90b2)
2022-01-11 21:28:24 +00:00
Jean-Philippe Cugnet
fe3f0be8eb nixos/elasticsearch: fix postStart to allow non-localhost listenAddress
Before this fix, if the listenAddress is set to something else than 127.0.0.1,
the service fails to detect that Elasticsearch has properly started and stop.

(cherry picked from commit 40fb59cfc3)
2022-01-11 21:20:53 +00:00
Vladimir Serov
46e952e7d7 CODEOWNERS: added cab404
(cherry picked from commit 706988fd49)
2022-01-11 21:03:47 +00:00
Vladimir Serov
5dfcdb67bb stdenv: move overriden stdenv in closure
Before that, base stdenv passed non-makeOverridable version of itself
inside. This cause it to be lost on package-name.stdenv.

(cherry picked from commit 523c701c0b)
2022-01-11 21:03:47 +00:00
Alyssa Ross
6d45ccee67 linuxPackages.jool: 4.1.5 -> 4.1.6
This release adds Linux 5.16 compatibility.

(cherry picked from commit a35652f40f)
2022-01-11 20:04:21 +00:00
Alyssa Ross
96b492b267 linuxPackages.lttng-modules: 2.13.0 -> 2.13.1
This release adds Linux 5.16 compatibility.

(cherry picked from commit 1febc39a5a)
2022-01-11 20:04:06 +00:00
Alyssa Ross
b098248894 linuxPackages.exfat-nofuse: assert -> meta.broken
We don't need to check versions any more, because we no longer package
any kernels older than 4.4, so this is broken for all kernel versions
in Nixpkgs.

(cherry picked from commit 2424687448)
2022-01-11 20:03:48 +00:00
Alyssa Ross
64508fa0e8 virtualbox: 6.1.28 -> 6.1.30
The guest additions currently don't build, either before or after this
change, but upgrading is still good because it gets us Linux 5.16
compatibility for the kernel module.

(cherry picked from commit dcabc91904)
2022-01-11 20:03:27 +00:00
Lassulus
bf709881f9 Merge pull request #153651 from 4z3/backport-153426-to-release-21.11
[Backport release-21.11] nixos/pipewire: add systemWide option
2022-01-11 20:20:14 +01:00
embr
05f3de54d5 qodem: init at 1.0.1
(cherry picked from commit 7a981b212678d77f5de0b913027cd7e3c52a6762)
2022-01-11 18:05:20 +00:00
Nikolay Amiantov
b7d57edcce nscd service: fix ordering and start automatically
During working on #150837 I discovered that `google-oslogin` test
started failing, and so did some of my development machines. Turns out
it was because nscd doesn't start by default; rather it's wanted by
NSS lookup targets, which are not always fired up.

To quote from section on systemd.special(7) on `nss-user-lookup.target`:

> All services which provide parts of the user/group database should be
> ordered before this target, and pull it in.

Following this advice and comparing our unit to official `sssd.service`
unit (which is a similar service), we now pull NSS lookup targets from
the service, while starting it with `multi-user.target`.

(cherry picked from commit b451eca621)
2022-01-11 17:52:50 +00:00
R. Ryantm
3106c1ac2f strace: 5.15 -> 5.16
(cherry picked from commit bd26e374a53208eba35855297c7a06e0c53fdcfe)
2022-01-11 17:23:41 +00:00
Alyssa Ross
bfd2cc73e9 spamassassin: support for fetching rules over HTTPS
sa-update.service starts by making an HTTP GET request to
http://spamassassin.apache.org/updates/MIRRORED.BY, which now
redirects to HTTPS.  Since we didn't have the appropriate library
available to handle HTTPS, rule updates would fail:

Jan 03 12:35:03 atuin systemd[1]: Starting sa-update.service...
Jan 03 12:35:10 atuin sa-update-start[1250]: Update available for channel updates.spamassassin.org: 1895535 -> 1896618
Jan 03 12:35:10 atuin sa-update-start[1250]: http: (lwp) hotpatching IO::Socket::INET by module IO::Socket::IP
Jan 03 12:35:11 atuin sa-update-start[1250]: http: (lwp) GET http://spamassassin.apache.org/updates/MIRRORED.BY, 501 Protocol scheme 'https' is not supported (LWP::Protocol::https not installed)
Jan 03 12:35:11 atuin sa-update-start[1250]: error: unable to refresh mirrors file for channel updates.spamassassin.org, using old file
Jan 03 12:35:11 atuin sa-update-start[1250]: error: no mirror data available for channel updates.spamassassin.org
Jan 03 12:35:11 atuin sa-update-start[1250]: channel 'updates.spamassassin.org': MIRRORED.BY file contents were missing, channel failed
Jan 03 12:35:11 atuin sa-update-start[1250]: Update failed, exiting with code 4
Jan 03 12:35:11 atuin systemd[1]: sa-update.service: Main process exited, code=exited, status=4/NOPERMISSION
Jan 03 12:35:11 atuin systemd[1]: sa-update.service: Failed with result 'exit-code'.
Jan 03 12:35:11 atuin systemd[1]: Failed to start sa-update.service.

(cherry picked from commit 7169ada492c3d163a86fee7483ea9f99523f3c00)
2022-01-11 17:07:32 +00:00
Jonathan Ringer
3d2aee7a90 tribler: lint 2022-01-11 08:39:03 -08:00
Martin Weinelt
c30c55e9be firefox-bin: 95.0.2 -> 96.0
(cherry picked from commit c8681ada72)
2022-01-11 13:04:56 +01:00
Martin Weinelt
3204144659 firefox-91-esr: 91.4.1esr -> 91.5.0esr
(cherry picked from commit 4ab147dc22)
2022-01-11 13:04:56 +01:00
Martin Weinelt
e1f545a815 firefox: 95.0.2 -> 96.0
(cherry picked from commit 74cba0680a)
2022-01-11 13:04:55 +01:00
Vladimír Čunát
acbf5b7186 nixos/kresd: fix IPv6 scope syntax
The systemd syntax is suprising to me, but I suppose it's worth being
compatible as people might be sharing it with other modules.
Our regexp is lenient on IPv6 address part, so this is actually
backwards compatible (i.e. you can put the scope at either place).

(cherry picked from commit 180213a0ac)
2022-01-11 12:00:57 +00:00
Vladimír Čunát
74a3cc6566 knot-resolver: 5.4.3 -> 5.4.4
This is basically just no-op.  Only version number changes.
https://gitlab.nic.cz/knot/knot-resolver/-/tags/v5.4.4

(cherry picked from commit 1071b77c21)
2022-01-11 12:00:57 +00:00
Vladimír Čunát
0b7f14b630 Merge branch 'staging-21.11' into staging-next-21.11 2022-01-11 10:24:59 +01:00
Bobby Rong
b2168f22fd Merge pull request #154475 from NixOS/backport-154414-to-release-21.11
[21.11] Pantheon 6.1 backports 2022-01-11
2022-01-11 16:56:20 +08:00
Bobby Rong
b4bff41830 pantheon.switchboard-plug-bluetooth: add wingpanel-indicator-bluetooth to buildInputs
See 7904ac5764/src/Services/Manager.vala (L29)

(cherry picked from commit a399af5bb2)
2022-01-11 16:40:59 +08:00
Bobby Rong
2df762e8ef pantheon.elementary-videos: 2.8.1 -> 2.8.3
(cherry picked from commit 7d5300d2f2)
2022-01-11 08:22:07 +00:00
Anderson Torres
386234e2a6 Merge pull request #154375 from NixOS/backport-151529-to-release-21.11
[Backport release-21.11] elvish: 0.16.3 -> 0.17.0
2022-01-11 00:16:38 -03:00
R. Ryantm
1993410c7e elvish: 0.16.3 -> 0.17.0
(cherry picked from commit bb64576d36)
2022-01-11 01:45:58 +00:00
github-actions[bot]
606bcd9da1 Merge staging-next-21.11 into staging-21.11 2022-01-11 00:11:45 +00:00
github-actions[bot]
bf061d447f Merge release-21.11 into staging-next-21.11 2022-01-11 00:11:01 +00:00
Jean-Baptiste Giraudeau
a63d64471f varnish: build modules for varnish 6 & 7.
(cherry picked from commit b43c61a806a398c3b33c50ef04e77488fc97e89a)
2022-01-10 15:14:16 -08:00
github-actions[bot]
71df0bba7a gitlab: 14.6.0 -> 14.6.1 (#153811)
(cherry picked from commit e1cae8c30cbe9a5f6b256cfc43fd9a636e1be2d1)

Co-authored-by: Lara <lara@uwu.is>
2022-01-10 23:39:35 +01:00
Renaud
ae659e5468 Merge pull request #153748 from NixOS/backport-153399-to-release-21.11
[Backport release-21.11] pijul: 1.0.0-alpha.56 -> 1.0.0-alpha.57
2022-01-10 19:11:10 +01:00
Alyssa Ross
99e70932eb linuxPackages.kvmfr: mark broken on Linux 5.16
(cherry picked from commit 871b03cc67)
2022-01-10 16:34:19 +00:00
Bobby Rong
5d3420c128 Merge pull request #154170 from NixOS/backport-154110-to-release-21.11
[Backport release-21.11] commit-formatter: init at 0.2.1
2022-01-10 23:40:52 +08:00
Bernardo Meurer
881a13b2bd Merge pull request #154256 from TheKK/backport-153501-to-release-21.11
[Backport release-21.11] nixos/gvfs: fix libmtp udev package path for realz
2022-01-10 13:50:58 +00:00
schnusch
4566492375 remote-touchpad: 1.0.4 -> 1.0.5
(cherry picked from commit cacd9fcfb0)
2022-01-10 13:19:04 +01:00
datafoo
048bd4528d mosquitto: 2.0.12 -> 2.0.14
(cherry picked from commit c788416d11)
2022-01-10 10:38:03 +00:00
Jan Tojnar
99029b07f8 nixos/gvfs: fix libmtp udev package path for realz
bin is the primary output so the previous attempt at fixing this
(2d7fc66c79)
was a no-op.

(cherry picked from commit dafaecb3b9)
2022-01-10 14:41:05 +08:00
R. Ryantm
649af30f13 linuxKernel.packages.linux_5_15_hardened.vhba: 20211023 -> 20211218
(cherry picked from commit b10f0dc1ee0048ccff9f4a2da4f6f333414fefdb)
2022-01-10 03:19:35 +00:00
Thiago Kenji Okada
79c7b6a353 Merge pull request #154219 from NixOS/backport-153775-to-release-21.11
[Backport release-21.11] clojure-lsp: fix build on macOS
2022-01-09 23:59:32 -03:00
Thiago Kenji Okada
e74848c095 clojure-lsp: fix build on macOS
Instead of setting the environment variable using Nix, use `preBuild`
hook to inject the value `DTLV_LIB_EXTRACT_DIR` on directly to
`nativeImageBuildArgs`. This will allow us to use a dynamically value
generated with `mktemp -d`.

Fix issue #153765.

(cherry picked from commit e1c79ccfe4)
2022-01-10 02:32:14 +00:00
Robert Scott
20f6f4178d Merge pull request #154053 from NixOS/backport-150449-to-staging-21.11
[Backport staging-21.11] libjxl: fix/enable for aarch64
2022-01-10 00:53:47 +00:00
Jörg Thalheim
d4301363eb Merge pull request #154210 from NixOS/backport-154016-to-release-21.11
[Backport release-21.11] jetbrains.goland: Fix debugging
2022-01-10 00:48:38 +00:00
diogox
af8f743276 Update pkgs/applications/editors/jetbrains/default.nix
Co-authored-by: Jörg Thalheim <Mic92@users.noreply.github.com>
(cherry picked from commit 4cb152fcea)
2022-01-10 00:34:55 +00:00
Diogo Xavier
2b9e967b02 jetbrains.goland: Fix debugging
(cherry picked from commit 76034fee72)
2022-01-10 00:34:55 +00:00
Luke Granger-Brown
ba492027f4 Merge pull request #154165 from NixOS/backport-153903-to-release-21.11
[Backport release-21.11] netdata: 1.31.0 -> 1.32.1
2022-01-10 00:22:07 +00:00
github-actions[bot]
71ced474ae Merge staging-next-21.11 into staging-21.11 2022-01-10 00:11:54 +00:00
github-actions[bot]
11bccde243 Merge release-21.11 into staging-next-21.11 2022-01-10 00:11:07 +00:00
Martin Weinelt
7137f5e105 Merge pull request #151137 from knl/fix-python-3.10-on-21.11 2022-01-10 01:01:29 +01:00
Elliot
825a94f702 commit-formatter: init at 0.2.1
Update pkgs/applications/version-management/commit-formatter/default.nix

Co-authored-by: Bobby Rong <rjl931189261@126.com>

Update pkgs/applications/version-management/commit-formatter/default.nix

Co-authored-by: Fabian Affolter <mail@fabian-affolter.ch>

Update pkgs/applications/version-management/commit-formatter/default.nix

Co-authored-by: Bobby Rong <rjl931189261@126.com>
(cherry picked from commit 1ed1e00d2b)
2022-01-09 18:13:22 +00:00
Izorkin
2fe59436b4 netdata: 1.31.0 -> 1.32.1
(cherry picked from commit 4b4022db06)
2022-01-09 17:23:31 +00:00
Izorkin
f4e2c6bd2a netdata: go.d.plugin: 0.28.1 -> 0.31.0
(cherry picked from commit 156393e104)
2022-01-09 17:23:30 +00:00
sternenseemann
56238790ce llvmPackages_*.clang: pick clangUseLLVM if targetPlatform.useLLVM
libcxxClang still depends on cc wrapper's gccForLibs for libgcc which is
not available when useLLVM is set. In such cases we need to switch to
clangUseLLVM and (try) to use compiler-rt instead.

Resolves #153759: pkgsLLVM.llvmPackages.stdenv now correctly
clangUseLLVM as cc, allowing compilation to work as expected.

(cherry picked from commit e238f456b8)
2022-01-09 17:00:08 +01:00
sternenseemann
806e5ab309 llvmPackages_*: respect cc for target when choosing C++ flavour
llvmPackages_*.clang should check the default compiler for the package
set it is targeting (targetPackages.stdenv.cc) instead of the compiler
that has been used to build it (stdenv.cc) in order to get some sense of
whether to use libc++ or libstdc++.

Since we are now inspecting targetPackages in the llvmPackages.clang
attribute, we need to avoid using it in the cross stdenv — which just
forces us to explicitly request libcxxClang for darwin instead of
relying on the clang attribute to pick it for us.

We also need to do something similar for targetPackages.stdenv.cc: Here
the llvmPackages.clang logic would work as we want (inspect
targetPackages.stdenv.cc and if it doesn't exist, make the choice based
on stdenv.cc), but it gets locked in a cycle with the previous package.
We can easily break this, however: We know that the previous set had
clang and the next one doesn't exist, so we'd choose libcxxClang any day
of the week.

(cherry picked from commit 766f5ffb76)
2022-01-09 17:00:08 +01:00
sternenseemann
af91000a7c wrapCCWith: rely on the new bintools attribute for default value
wrapCCWith shipped its own, but imperfect duplication of the logic we
use to choose the bintools for the *next* stage by inspecting
targetPlatform.

This change should ensure that C compilers relying on the default
behavior of wrapCCWith should end up with the same bintools als
theirStage.bintools. In particular, this makes
pkgsLLVM.llvmPackages.stdenv correctly use the LLVM bintools instead of
GNU binutils.

(cherry picked from commit 17c5a15c89)
2022-01-09 17:00:08 +01:00
Vladimír Čunát
9d9ed15180 Merge #150917: python3Packages.lxml: 4.6.3 -> 4.6.5
... into staging-21.11
2022-01-09 14:35:52 +01:00
Vladimír Čunát
cef66cdf3c Merge #153216: glibc: 2.33-59 -> 2.33-62 (into staging-21.11) 2022-01-09 14:32:12 +01:00
ajs124
9d554bb2f0 cacert: 3.71 -> 3.74
(cherry picked from commit eb9b64fc32, PR #153769)
2022-01-09 14:26:09 +01:00
Moritz Angermann
0c6ffefff9 llvmPackages_12.llvm: create fix-llvm-issue-49955.patch
This patch addresses llvm/llvm-project#49955

(cherry picked from commit afca44c064196df9f0271e680bd5fb0373a0becb)
2022-01-09 12:15:44 +01:00
Nikolay Amiantov
7e5fd25ce5 uwsgi service: deduplicate plugins list
Duplicates can lead to unnecessary `uwsgi` rebuilds and conflicts.

(cherry picked from commit 2be5e93ecc)
2022-01-09 06:53:58 +00:00
Nikolay Amiantov
91bb3baea7 uwsgi service: redefine PATH envvar
Previously if user had `PATH` variable set we would define several
`PATH` variables and trigger a conflict.

(cherry picked from commit 4be78f0dd3)
2022-01-09 06:53:58 +00:00
adisbladis
00acdb2aa8 Merge pull request #154069 from NixOS/backport-154066-to-release-21.11
[Backport release-21.11] emacs.pkgs.melpa*: Fix version numbers with negative numbers
2022-01-09 12:13:23 +12:00
adisbladis
965cf11d35 emacs.pkgs.melpa*: Fix version number checks if number is zero
(cherry picked from commit 8c161f6a62)
2022-01-09 13:12:23 +13:00
github-actions[bot]
514759af33 Merge staging-next-21.11 into staging-21.11 2022-01-09 00:11:49 +00:00
github-actions[bot]
743cb82164 Merge release-21.11 into staging-next-21.11 2022-01-09 00:11:05 +00:00
adisbladis
a1c205ba8f emacs.pkgs.melpa*: Fix version numbers with negative numbers
(cherry picked from commit 7f7252093f)
2022-01-08 23:48:52 +00:00
Martin Weinelt
72a8f23f8a Merge pull request #154057 from NixOS/backport-153927-to-release-21.11 2022-01-09 00:36:50 +01:00
Robert Scott
f52bf3e230 gdal: add patch for CVE-2021-45943 2022-01-08 22:40:12 +00:00
Jakub Kądziołka
0bee66fce8 deluge: 2.0.3 -> 2.0.5
(cherry picked from commit 58add1bf84)
2022-01-08 22:11:39 +00:00
Robert Scott
2cab1bd501 libjxl: fix/enable for aarch64
(cherry picked from commit f24cab5396)
2022-01-08 21:36:33 +00:00
Robert Scott
6fa556fa2c Merge pull request #152214 from NixOS/backport-148163-to-release-21.11
[Backport release-21.11] uwsgi: fix compiling against php 8, bump to 2.0.20
2022-01-08 21:31:26 +00:00
Sebastian Pipping
42993dd7b6 uriparser: 0.9.5 -> 0.9.5 (security, fixes #153777)
(cherry picked from commit 86b4d69a1488057fee23e9809822c31eb91ad78b)
2022-01-08 15:52:47 -05:00
Jan Solanti
c0d6b6c816 pipewire: 0.3.40 -> 0.3.42
(cherry picked from commit 3d5c55e8e4)
2022-01-08 18:54:53 +00:00
Jörg Thalheim
f530bcb143 Merge pull request #153926 from NixOS/backport-153918-to-release-21.11
[Backport release-21.11] fio: add missing six dependency
2022-01-08 18:19:09 +00:00
Renaud
180d0d5943 Merge pull request #154012 from NixOS/backport-153171-to-release-21.11
[Backport release-21.11] nexus: 3.32.0-03 -> 3.37.3-02
2022-01-08 18:02:01 +01:00
Martin Weinelt
e29ec35be0 Merge pull request #153919 from NixOS/backport-153889-to-release-21.11 2022-01-08 16:20:06 +01:00
R. Ryantm
c12cfeab5b nexus: 3.32.0-03 -> 3.37.3-02
(cherry picked from commit 7d8c9ff115)
2022-01-08 14:59:03 +00:00
Maximilian Bosch
9a0ff8e080 Merge pull request #153207 from NixOS/backport-153004-to-release-21.11
[Backport release-21.11] wiki-js: 2.5.260 -> 2.5.268
2022-01-08 13:02:38 +01:00
Maximilian Bosch
9388dd514d Merge pull request #152815 from NixOS/backport-152324-to-release-21.11
[Backport release-21.11] epson-escpr2: 1.1.42 -> 1.1.45
2022-01-08 13:01:40 +01:00
Maximilian Bosch
bdf49796ba Merge pull request #153269 from NixOS/backport-153203-to-release-21.11
[Backport release-21.11] prometheus-openldap-exporter: 2.1.4 -> 2.2.0
2022-01-08 13:00:43 +01:00
Michael Weiss
98bed847b5 Merge pull request #153909 from NixOS/backport-153861-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 96.0.4664.110 -> 97.0.4692.71
2022-01-08 11:01:30 +01:00
Maximilian Bosch
ed68205831 Merge pull request #153934 from NixOS/backport-153738-to-release-21.11
[Backport release-21.11] Kernels 2022-01-06
2022-01-08 10:37:44 +01:00
Thiago Kenji Okada
9f5daf3284 nixos-rebuild: remove jq
Was only used in the code removed in commit
c274d045ac.

(cherry picked from commit c75bc3abc7)
2022-01-08 02:23:18 +00:00
Thiago Kenji Okada
49d0ae2a78 nixos-rebuild: do not resolve flake path
The removed lines converted the flake path passed by the command line
from `/some/path` to `git+file:///some/path`.

This technically shouldn't cause any issues, however running
`nixos-rebuild switch` inside a directory `/nix/store` will cause the
switch to fail and leave a partially construct generation (see issue #144811
for details).

By itself this shouldn't be too much of an issue, however thanks to
another issue in `systemd-boot-builder.py` this can leave the system
in a broken state for those using `boot.loader.systemd-boot` (AFAIK the
default), where future `nixos-rebuild switch` will fail
(see issue #93694 for details).

The issue can be fixed by running
`nix-env -p /nix/var/nix/profiles/system --delete-generations old`,
however this makes newbies very confused and it is showing in our
support threads in Matrix and Discourse (see
https://discourse.nixos.org/t/need-help-on-failure-of-building-my-configuration/16842).

Keep in mind this is a workaround. The actual issue seems to be in nix
itself (see: https://github.com/NixOS/nix/issues/5510).

See also #150065 for an alternative fix that caused other issues.

Kudos for @figsoda for figuring out this fix.

(cherry picked from commit c274d045ac)
2022-01-08 02:23:18 +00:00
TredwellGit
30cba27869 linux/hardened/patches/5.4: 5.4.169-hardened1 -> 5.4.170-hardened1
(cherry picked from commit a40d8182da)
2022-01-08 01:44:22 +00:00
TredwellGit
6dccbe4341 linux/hardened/patches/4.19: 4.19.223-hardened1 -> 4.19.224-hardened1
(cherry picked from commit 2fe8933a62)
2022-01-08 01:44:22 +00:00
TredwellGit
87604c0da4 linux/hardened/patches/4.14: 4.14.260-hardened1 -> 4.14.261-hardened1
(cherry picked from commit 99a4be5a2d)
2022-01-08 01:44:22 +00:00
TredwellGit
475c496d90 linux-rt_5_10: 5.10.87-rt59 -> 5.10.90-rt60
(cherry picked from commit fa0e80ce0d)
2022-01-08 01:44:22 +00:00
TredwellGit
af6c2d21e0 linux: 5.4.169 -> 5.4.170
(cherry picked from commit 4594d2494f)
2022-01-08 01:44:22 +00:00
TredwellGit
e61f84471b linux: 5.15.12 -> 5.15.13
(cherry picked from commit 066a0b1197)
2022-01-08 01:44:22 +00:00
TredwellGit
23c0a2852a linux: 5.10.89 -> 5.10.90
(cherry picked from commit 6bcc2e3529)
2022-01-08 01:44:22 +00:00
TredwellGit
a70992e47c linux: 4.9.295 -> 4.9.296
(cherry picked from commit b2ac2d62f8)
2022-01-08 01:44:22 +00:00
TredwellGit
6e6ce3458f linux: 4.4.297 -> 4.4.298
(cherry picked from commit 0fb1f45869)
2022-01-08 01:44:22 +00:00
TredwellGit
bedb350c61 linux: 4.19.223 -> 4.19.224
(cherry picked from commit e22fa956c3)
2022-01-08 01:44:22 +00:00
TredwellGit
0a322c04a9 linux: 4.14.260 -> 4.14.261
(cherry picked from commit ce05c553ad)
2022-01-08 01:44:22 +00:00
Jörg Thalheim
daec3524d4 fio: add missing six dependency
(cherry picked from commit de6739642c)
2022-01-08 00:27:24 +00:00
github-actions[bot]
dc9260396a Merge staging-next-21.11 into staging-21.11 2022-01-08 00:11:00 +00:00
github-actions[bot]
5deaf6d9d9 Merge release-21.11 into staging-next-21.11 2022-01-08 00:10:24 +00:00
Martin Weinelt
4ac60af97f wordpress: 5.8.2 -> 5.8.3
(cherry picked from commit 267d073ac0)
2022-01-07 23:46:22 +00:00
Moritz Angermann
c552be03e8 libredirect: build fat library for x86_64, arm64, arm64e on darwin
macOS's dyld can be rather picky as to what dylib it accepts. This
even changes across macOS versions. Therefore we now build a fat
dylib with all three architectures (x86_64, arm64, arm64e). This
should then be compatible with pretty much any macOS's dyld.

(cherry picked from commit a655bc02a78cbfdb6a87148503a0f2031efdd49a)
2022-01-07 23:36:57 +00:00
Michael Adler
1f2f062d17 ungoogled-chromium: 96.0.4664.110 -> 97.0.4692.71
(cherry picked from commit 77eb74e19d)
2022-01-07 22:27:46 +00:00
Fabian Affolter
36480448d4 python3Packages.discordpy: relax aiohttp constraint
(cherry picked from commit 2dbcf92154)
2022-01-07 14:10:16 -08:00
Martin Weinelt
b279398354 Merge pull request #153597 from NixOS/backport-153477-to-staging-21.11 2022-01-07 21:01:57 +01:00
sternenseemann
4d0de00053 llvmPackages_*.libllvm: make llvm-config and llvm-config equivalent
LLVM's build system creates NATIVE/bin/llvm-config by reexecuting cmake
with entirely new flags. Problematically, the `CMAKE_INSTALL_*` flags
are not inherited, causing llvm-config-native to return wrong
installation paths, e. g. CMAKE_INSTALL_LIBDIR would default to `lib64`
on x86_64-linux. Previously this was masked by outputs.patch which
replaced ActiveLibDir with a string passed in from Nix, however
`--cmakedir` for example would turn out to be wrong always, breaking
cross-compilation of e. g. lld.

Additionally LLVM_ENABLE_RTTI needs to be repassed, as it is used to
determine if RTTI is available. Passing LLVM_LINK_LLVM_DYLIB is crucial
if we are building LLVM non-statically: It influences the --shared-mode
flag (which should indicate that -lLLVM is enough to link all
components) and makes --link-shared work in the first place,
i. e. llvm-config-native believes the built shared libs don't exist
unless we repass this flag.

Passing LLVM_LINK_LLVM_DYLIB=ON, however, makes the native build produce
a full libLLVM.so which is something we don't want, so we introduce a
patch which forces llvm-config to link statically against the LLVM
components it needs.

(cherry picked from commit e10edcc27810bdbf3dc15c47860bf2a34cfddc24)
2022-01-07 19:55:42 +01:00
sternenseemann
c162a08083 llvmPackages*.libllvm: drop outputs.patch for llvm-config.patch
Due to gnu-install-dirs.patch llvm-config will return correct results
for --link-shared as well as --link-static even without this patch.

(cherry picked from commit 677a94fd9e145fb1d473528cf000d8ea7ca1ae69)
2022-01-07 19:55:42 +01:00
sternenseemann
260faba296 llvmPackages_*.clang: stop passing LLVM_CONFIG_PATH unnecessarily
Starting with LLVM 8, clang does no longer use llvm-config to detect the
LLVM installation: https://github.com/llvm/llvm-project/commit/e4faa5c7986b7
Consequently, there is no point passing LLVM_CONFIG_PATH (in fact the
variable is unused currently).

(cherry picked from commit c58517aeed)
2022-01-07 19:53:49 +01:00
Jean-Baptiste Giraudeau
d89eab1e42 varnish: use jemalloc instead of glibc's malloc on linux.
this is the recommanded default, as glibc cause memory leaks:

 "We ran into a problem with glibc's malloc on Linux where it seemed
 like it failed to ever give memory back to the OS, causing the system
 to swap. We have now switched to jemalloc which appears not to have
 this problem." (from varnish-cache/doc/changes.rst)

(cherry picked from commit 24ce179bacd8e7a82557b02fbab037bc3a3b71b0)
2022-01-07 09:53:58 -08:00
datafoo
ebd6ab9707 vscode-extensions.stkb.rewrap: 1.14.0 -> 1.15.4
(cherry picked from commit 94c5e47f9a)
2022-01-07 09:51:19 -08:00
datafoo
58af93b9a4 vscode-extensions.davidanson.vscode-markdownlint: 0.42.1 -> 0.45.0
(cherry picked from commit 53caa40811)
2022-01-07 09:51:09 -08:00
datafoo
a45fc58f9f vscode-extensions.bungcip.better-toml: init at 0.3.2
(cherry picked from commit c7218b3f7e)
2022-01-07 09:47:03 -08:00
datafoo
ed46bfda0b vscode-extensions.jakebecker.elixir-ls: init at 0.9.0
(cherry picked from commit 4e2ca8b0a9)
2022-01-07 09:39:54 -08:00
Patrick Hilhorst
7ae962ca8c nixos/test-driver: also passthru driverInteractive
(cherry picked from commit d4dc638d77)
2022-01-07 15:09:00 +00:00
Martin Weinelt
60dd7bc997 Merge pull request #153755 from NixOS/backport-153745-to-release-21.11 2022-01-07 14:11:38 +01:00
Bobby Rong
bbbcd88de7 Merge pull request #153822 from NixOS/backport-153731-to-release-21.11
[Backport release-21.11] vscode-extensions.apollographql.vscode-apollo: init at 1.19.9
2022-01-07 21:05:09 +08:00
datafoo
354be380ff vscode-extensions.apollographql.vscode-apollo: init at 1.19.9
(cherry picked from commit 3035c4ab5c)
2022-01-07 10:14:51 +00:00
datafoo
71e3d5aa1a maintainers: add datafoo
(cherry picked from commit d6f2a19ff4)
2022-01-07 10:14:51 +00:00
Vladimír Čunát
5e39ca30d0 Merge #153627: opentoonz: 1.4.0 -> 1.5.0 (into release-21.11) 2022-01-07 09:49:22 +01:00
7c6f434c
2cdb43cbd7 Merge pull request #150378 from NixOS/backport-150291-to-release-21.11
[Backport release-21.11] libreoffice-fresh: 7.2.3.2 -> 7.2.5.2
2022-01-07 07:03:17 +00:00
adisbladis
c1034ed1c4 Merge pull request #152306 from NixOS/backport-152289-to-release-21.11
[Backport release-21.11] nixos/gvfs: fix libmtp udev package path
2022-01-07 15:35:50 +12:00
TredwellGit
2cecd003b5 libreoffice-fresh: 7.2.4.1 -> 7.2.5.2
Fixes https://github.com/NixOS/nixpkgs/issues/153436

(cherry picked from commit 14927bdce6)
2022-01-07 10:26:31 +08:00
github-actions[bot]
6deff708bf Merge staging-next-21.11 into staging-21.11 2022-01-07 00:12:00 +00:00
github-actions[bot]
c3d45eecee Merge release-21.11 into staging-next-21.11 2022-01-07 00:11:15 +00:00
Robert Scott
36948c6dd0 Merge pull request #153716 from LeSuisse/rizin-0.3.2-21.11
[21.11] rizin: 0.3.0 -> 0.3.2
2022-01-06 22:57:59 +00:00
Robert Scott
887a08912c Merge pull request #153636 from risicle/ris-openexr-CVE-2021-45942-r21.11
[21.11] openexr, openexr_3: add patch for CVE-2021-45942
2022-01-06 22:19:14 +00:00
Robert Scott
538c7e1a6a Merge pull request #152153 from NixOS/backport-149488-to-staging-21.11
[Backport staging-21.11] gmp, gmp5: add patch for CVE-2021-43618
2022-01-06 19:07:39 +00:00
Vladimír Čunát
c4d19d6e5c Merge #153754: apacheHttpd: 2.4.51 -> 2.4.52 (into release-21.11) 2022-01-06 19:50:22 +01:00
Moritz Hedtke
5d2da877b7 nixos/wordpress: Disable directory indexes
Fixes #151159
Confirmed using path http://localhost/wp-includes/

(cherry picked from commit bb358d6566)
2022-01-06 18:18:09 +00:00
R. Ryantm
2ecec88245 apacheHttpd: 2.4.51 -> 2.4.52
(cherry picked from commit 78700df942)
2022-01-06 18:13:36 +00:00
Vladyslav M
1854839588 pijul: 1.0.0-alpha.56 -> 1.0.0-alpha.57
(cherry picked from commit 3aae5c9376)
2022-01-06 17:31:07 +00:00
Michael Weiss
e8b8f80a5d Merge pull request #153739 from NixOS/backport-153728-to-release-21.11
[Backport release-21.11] signal-desktop: 5.26.1 -> 5.27.0
2022-01-06 17:10:04 +01:00
Maximilian Bosch
9115600e01 Merge pull request #153669 from NixOS/backport-153522-to-release-21.11
[Backport release-21.11] Kernels 2022-01-04
2022-01-06 16:44:21 +01:00
Michael Weiss
5707157edc signal-desktop: 5.26.1 -> 5.27.0
(cherry picked from commit dd4432a118)
2022-01-06 15:27:33 +00:00
Renaud
952aee0d0d cutter: 2.0.3 -> 2.0.4
(cherry picked from commit 1307805c33)
2022-01-06 12:49:40 +01:00
Thomas Gerbet
2a435d281e rizin: 0.3.1 -> 0.3.2
Fixes CVE-2021-43814
https://github.com/rizinorg/rizin/releases/tag/v0.3.2

(cherry picked from commit 5ef18697ff)
2022-01-06 12:48:42 +01:00
R. Ryantm
cb68a9edb2 rizin: 0.3.0 -> 0.3.1
(cherry picked from commit e6f7d88851)
2022-01-06 12:48:42 +01:00
Bobby Rong
d3179446ef Merge pull request #153642 from NixOS/backport-153109-to-release-21.11
[Backport release-21.11] psi-plus: 1.5.1582 -> 1.5.1596
2022-01-06 11:50:41 +08:00
TredwellGit
ef8f77063c linux/hardened/patches/5.4: 5.4.167-hardened1 -> 5.4.169-hardened1
(cherry picked from commit babb121da8)
2022-01-06 01:41:19 +00:00
TredwellGit
04e020102b linux/hardened/patches/5.15: 5.15.10-hardened1 -> 5.15.12-hardened1
(cherry picked from commit 5bea8cae1c)
2022-01-06 01:41:18 +00:00
TredwellGit
30fbdc8730 linux/hardened/patches/5.10: 5.10.87-hardened1 -> 5.10.89-hardened1
(cherry picked from commit b23f71e805)
2022-01-06 01:41:18 +00:00
TredwellGit
d6e2ed060f linux/hardened/patches/4.19: 4.19.221-hardened1 -> 4.19.223-hardened1
(cherry picked from commit c389f9ace8)
2022-01-06 01:41:18 +00:00
TredwellGit
8da34915f4 linux/hardened/patches/4.14: 4.14.258-hardened1 -> 4.14.260-hardened1
(cherry picked from commit aa88b7f3ec)
2022-01-06 01:41:18 +00:00
github-actions[bot]
04ddea9ca5 Merge staging-next-21.11 into staging-21.11 2022-01-06 00:11:31 +00:00
github-actions[bot]
ded4353e3a Merge release-21.11 into staging-next-21.11 2022-01-06 00:10:54 +00:00
Wael Nasreddine
e67c94a1ad [Backport release-21.11] onlykey: set the group correctly in the udev rule (#153626)
Co-authored-by: Wael M. Nasreddine <wael.nasreddine@gmail.com>
2022-01-05 15:05:37 -08:00
tv
b5a66b3432 nixos/pipewire: add systemWide option 2022-01-05 23:44:04 +01:00
R. Ryantm
ddb1e3dcd8 psi-plus: 1.5.1582 -> 1.5.1596
(cherry picked from commit 7f64539e77)
2022-01-05 21:44:08 +00:00
Michael Weiss
feed45d391 Merge pull request #153635 from NixOS/backport-153523-to-release-21.11
[Backport release-21.11] chromium: 96.0.4664.110 -> 97.0.4692.71
2022-01-05 21:54:08 +01:00
Robert Scott
5793edfe90 openexr_3: add patch for CVE-2021-45942
the CVE description is currently suggesting
db217f29df
as the fix, but it is wrong

checked this patch does silence valgrind's complaints with
reproducer file https://oss-fuzz.com/download?testcase_id=5275682339422208

(cherry picked from commit 04c0fa2d3a)
2022-01-05 19:30:22 +00:00
Robert Scott
01c1cb6da5 openexr: add patch for CVE-2021-45942
the CVE description is currently suggesting
db217f29df
as the fix, but it is wrong

checked this patch does silence valgrind's complaints with
reproducer file https://oss-fuzz.com/download?testcase_id=5275682339422208

(cherry picked from commit a238071df4)
2022-01-05 19:30:22 +00:00
Michael Weiss
1f1351befa chromium: 96.0.4664.110 -> 97.0.4692.71
https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html

This update includes 37 security fixes.

CVEs:
CVE-2022-0096 CVE-2022-0097 CVE-2022-0098 CVE-2022-0099 CVE-2022-0100
CVE-2022-0101 CVE-2022-0102 CVE-2022-0103 CVE-2022-0104 CVE-2022-0105
CVE-2022-0106 CVE-2022-0107 CVE-2022-0108 CVE-2022-0109 CVE-2022-0110
CVE-2022-0111 CVE-2022-0112 CVE-2022-0113 CVE-2022-0114 CVE-2022-0115
CVE-2022-0116 CVE-2022-0117 CVE-2022-0118 CVE-2022-0120

(cherry picked from commit 43a33f1f01)
2022-01-05 19:13:43 +00:00
Michael Weiss
bcadd7560f Merge pull request #153624 from primeos/chromium-backport
[21.11] Prepare for backporting Chromium M97
2022-01-05 20:06:08 +01:00
Scott Worley
8270794e34 opentoonz-libtiff: Note knownVulnerabilities
(cherry picked from commit 920c5cd2b4)
2022-01-05 18:42:13 +00:00
Scott Worley
cb6a45386b opentoonz: 1.4.0 -> 1.5.0
(The qtbase diamond-dependency problem was resolved in 4bac8a7a00)

(cherry picked from commit a20e31bf09)
2022-01-05 18:42:13 +00:00
Wael M. Nasreddine
ab4d4f144e onlykey: set the group correctly in the udev rule
(cherry picked from commit d59dc2d5edce007ed779aaff00195dd664ad7a68)
2022-01-05 18:34:31 +00:00
Michael Weiss
ed2999df91 chromiumBeta: 97.0.4692.56 -> 97.0.4692.71
(cherry picked from commit 7f3d3af98d)
2022-01-05 19:13:06 +01:00
Konstantin Alekseev
61482189d3 chromedriver: add support for aarch64-darwin
(cherry picked from commit 6e0a2c1c54)
2022-01-05 19:13:05 +01:00
Brian McGee
2e15415fed google-chrome: add pre and post install hooks
This makes it easier to override the derivation

(cherry picked from commit 234c7cf431)
2022-01-05 19:13:05 +01:00
Michael Weiss
e37bf7d818 chromiumDev: 98.0.4750.0 -> 98.0.4758.9
(cherry picked from commit c169d1d5f3)
2022-01-05 19:13:05 +01:00
Michael Weiss
d9a01284dd chromiumBeta: 97.0.4692.45 -> 97.0.4692.56
(cherry picked from commit afb8f63d90)
2022-01-05 19:13:05 +01:00
Michael Weiss
04626d1b20 chromiumBeta: 97.0.4692.36 -> 97.0.4692.45
(cherry picked from commit c80eda54d5)
2022-01-05 19:13:04 +01:00
Michael Weiss
1c04820980 chromiumDev: 98.0.4736.0 -> 98.0.4750.0
(cherry picked from commit 426f695797)
2022-01-05 19:13:04 +01:00
Michael Weiss
637bda368b chromiumBeta: 97.0.4692.20 -> 97.0.4692.36
(cherry picked from commit bab515f768)
2022-01-05 19:13:04 +01:00
Michael Weiss
321f37a913 chromiumDev: 98.0.4710.4 -> 98.0.4736.0
(cherry picked from commit cb91e61c56)
2022-01-05 19:13:03 +01:00
sternenseemann
59fc3fd57f llvmPackages_{12,13,git}.compiler-rt: remove new runtimes in useLLVM
LLVM 12 added the memory profiling runtime and LLVM 13 the ORC
runtime. Both need a libc in order to build (or at least headers not
present in clang's resource root), so we'll disable them for any sort of
baremetal-ish build. memprof likely doesn't work in a baremetal
situation at all, orc is unknown. Whether both would compile with musl
is to be checked.

(cherry picked from commit b591a98be43218e8ef5b71148f807c62d0b8bbe7)
2022-01-05 18:50:31 +01:00
Adrian Lucrèce Céleste
df702a2585 jenkins: 2.303.1 -> 2.303.3
(cherry picked from commit 3c5996d1e6)
2022-01-05 16:38:00 +01:00
Martin Weinelt
cf4dc97831 python3Packages.django_3: 3.2.9 -> 3.2.11
(cherry picked from commit ade38fcf21)
2022-01-05 13:20:10 +00:00
Martin Weinelt
ae7297cb3f python3Packages.django_2: 2.2.24 -> 2.2.26
(cherry picked from commit ffcf2ec833)
2022-01-05 13:20:10 +00:00
Pavol Rusnak
95a1a7708f Merge pull request #153585 from NixOS/backport-153521-to-release-21.11
[Backport release-21.11] Update Electron
2022-01-05 11:47:20 +01:00
TredwellGit
059bf5a0b1 electron_16: 16.0.5 -> 16.0.6
https://github.com/electron/electron/releases/tag/v16.0.6
(cherry picked from commit 24ba4098a8)
2022-01-05 10:36:11 +00:00
TredwellGit
b297cbd192 electron_13: 13.6.3 -> 13.6.6
https://github.com/electron/electron/releases/tag/v13.6.4
https://github.com/electron/electron/releases/tag/v13.6.5
https://github.com/electron/electron/releases/tag/v13.6.6
(cherry picked from commit aeb6554ea1)
2022-01-05 10:36:11 +00:00
Moritz Angermann
37787a368d Export static libc, libm, libdl from the prebuilt crt as well.
Adds enable{Static,Shared} flags as well.

(cherry picked from commit cc545663ce)
2022-01-05 09:00:33 +00:00
Drew Risinger
45c2f7389d python3Packages.scikit-learn: fix compatibility with openblas 0.3.18
Different versions of openblas can yield slightly different results,
which can cause scikit-learn tests to fail.
Issue was fixed in https://github.com/scikit-learn/scikit-learn/issues/21340
Closes #153202.
2022-01-05 09:56:20 +01:00
7c6f434c
c2ee1baea8 Merge pull request #153569 from NixOS/backport-153518-to-release-21.11
[Backport release-21.11] Gajim fixes
2022-01-05 07:15:01 +00:00
Nikolay Amiantov
5d09db8827 gajim: add plugin installer
Workaround upstream issue https://dev.gajim.org/gajim/gajim/-/issues/10719.

(cherry picked from commit 7e041d3446)
2022-01-05 06:15:19 +00:00
Nikolay Amiantov
62dedf1241 gajim: fix tests
`test` directory actually also contains various libraries and broken
tests. Test failure happens when `test/lib/gajim_mocks.py` is attempted
to run as a test.

Upstream only runs no_gui tests:
e0f58cfc78/.gajim-ci.yml (L18)

We now explicitly run only tests from `no_gui` and `unit`.

(cherry picked from commit c138c66dcb)
2022-01-05 06:15:19 +00:00
github-actions[bot]
b55c978b7a Merge staging-next-21.11 into staging-21.11 2022-01-05 00:11:17 +00:00
github-actions[bot]
ebdfc13bbd Merge release-21.11 into staging-next-21.11 2022-01-05 00:10:34 +00:00
Thiago Kenji Okada
d1029cdb3c Merge pull request #153510 from kalbasit/update-vivaldi
vivaldi: backport updates and improvements from unstable
2022-01-04 20:35:52 -03:00
Vincent Haupert
aeb3f488d9 nixos/github-runner: refactor tokens handling
This commit changes how we deal with the current token, i.e., the token
which may exist from a previous runner registration, and the configured
token, i.e., the path set for the respective NixOS configuration option.

Until now, we copied the configured and the current token (if any) to
the runtime directory to compare them. The path of the current token may
reference a file which is only accessible to specific users (even only
root). Therefore, we ran the copying of credentials with elevated
privileges by prefixing the `ExecStartPre=` script with a `+` (see
systemd.service(5)). In this script, we also changed the owner of the
files to the service user. Apparently, however, the user/group pair
sometimes did not exist because we use `DynamicUser=`.

To address this issue, we no longer change the owner of the file.
Instead, we change the file permissions to 0666 to allow the runner
configuration script (runs with full sandboxing) to read-write the file.
Due to the current permissions of the runtime directory (0755), this
would expose the token. Therefore, we process the tokens in the state
directory, which is only accessible to the service user.

If a new token file exists in the state directory, the configuration
script should trigger a new runner registration. Afterward, it deletes
the new token file. The token is still available using the path of the
current token which is inaccessible within the service's sandbox.

(cherry picked from commit 3cf9508c72)
2022-01-04 19:55:13 +00:00
Steven Kou
17c7e5126f vivaldi: add commandLineArgs
(cherry picked from commit ce08f09cc9)
2022-01-04 11:45:06 -08:00
Steven Kou
685549357b vivaldi: add vaapi support
(cherry picked from commit 645d8b2ddf)
2022-01-04 11:44:45 -08:00
Robert Scott
91ff19373c Merge pull request #153270 from NixOS/backport-152967-to-staging-21.11
[Backport staging-21.11] apacheHttpd: 2.4.51 -> 2.4.52
2022-01-04 19:44:18 +00:00
Steven Kou
9d23eef82c vivaldi: 4.3.2439.44-1 -> 5.0.2497.32-1
(cherry picked from commit 402296bca8)
2022-01-04 11:44:15 -08:00
Bobby Rong
e359d31cb9 Merge pull request #153349 from NixOS/backport-153337-to-release-21.11
[Backport release-21.11] lean: 3.35.0 -> 3.35.1
2022-01-04 12:37:30 +08:00
Anderson Torres
d68e9c1507 Merge pull request #153410 from NixOS/backport-153407-to-release-21.11
[Backport release-21.11] mpv: 0.34.0 -> 0.34.1
2022-01-03 21:18:48 -03:00
github-actions[bot]
91e74f6b4f Merge staging-next-21.11 into staging-21.11 2022-01-04 00:10:59 +00:00
github-actions[bot]
4dbdf6b3d3 Merge release-21.11 into staging-next-21.11 2022-01-04 00:10:21 +00:00
R. Ryantm
be6cf40e65 apk-tools: 2.12.8 -> 2.12.9
(cherry picked from commit db54e33ba697b31c4b27d2ccbf25ecb47e6f5321)
2022-01-03 23:41:07 +00:00
adisbladis
714460c14f mpv: 0.34.0 -> 0.34.1
(cherry picked from commit ddc858382c)
2022-01-03 23:27:40 +00:00
ajs124
c6019d8efb Merge pull request #153391 from NixOS/backport-153366-to-release-21.11
[Backport release-21.11] gnustep.base: fix issue with UTF-8 BOM
2022-01-03 22:13:20 +01:00
ajs124
d35db0ddda gnustep.base: fix issue with UTF-8 BOM
(cherry picked from commit c2ed098285)
2022-01-03 20:46:13 +00:00
Bernardo Meurer
7eae7caac4 Merge pull request #152249 from NixOS/backport-151139-to-release-21.11
[Backport release-21.11] firmwareLinuxNonfree: 20211027 -> 20211216
2022-01-03 16:51:39 +00:00
Renaud
da12a212f6 Merge pull request #151914 from NixOS/backport-151354-to-release-21.11
[Backport release-21.11] eolie: switch back to normal webkitgtk
2022-01-03 16:59:21 +01:00
Bernardo Meurer
984bd4f393 Merge pull request #152360 from NixOS/backport-152251-to-release-21.11
[Backport release-21.11] roon-server: 1.8-850 -> 1.8-880
2022-01-03 15:45:00 +00:00
Mauricio Collares
3f685f3e4b lean: 3.35.0 -> 3.35.1
(cherry picked from commit 5b3eac3130)
2022-01-03 15:44:03 +00:00
Bernardo Meurer
1ca794a45b Merge pull request #153299 from taku0/thunderbird-bin-91.4.1_release-21.11
[21.11] thunderbird: 91.4.0 -> 91.4.1, thunderbird-bin: 91.3.2 -> 91.4.1
2022-01-03 15:42:50 +00:00
ajs124
3a399d8e64 Merge pull request #153330 from NixOS/backport-148140-to-release-21.11
[Backport release-21.11] knot-resolver: 5.4.2 -> 5.4.3
2022-01-03 15:01:16 +01:00
Vladimír Čunát
5be9a12951 knot-resolver: 5.4.2 -> 5.4.3
https://gitlab.nic.cz/knot/knot-resolver/-/tags/v5.4.3
(cherry picked from commit 93ee1a9cb0)
2022-01-03 13:37:36 +00:00
Bobby Rong
66003e02e6 Merge pull request #153322 from NixOS/backport-153308-to-release-21.11
[Backport release-21.11] jitsi-meet-electron: add pipewire screensharing support
2022-01-03 21:37:02 +08:00
Fabian Hauser
9064afcbae jitsi-meet-electron: add pipewire screensharing support
(cherry picked from commit df58301110)
2022-01-03 13:04:10 +00:00
Bobby Rong
c38ff70415 Merge pull request #153313 from NixOS/backport-153307-to-release-21.11
[Backport release-21.11] vscode-extensions.dbaeumer.vscode-eslint: 2.1.14 -> 2.2.2
2022-01-03 19:06:12 +08:00
Fabian Hauser
cf30284b1e vscode-extensions.dbaeumer.vscode-eslint: 2.1.14 -> 2.2.2
(cherry picked from commit d1f2289198)
2022-01-03 11:01:59 +00:00
Ryan Burns
758fdf70e4 aws-c-s3: 0.1.27 -> 0.1.30
(cherry picked from commit 2ef7df5a6c25f8bca01e6dc11f4e434ba8c22ce1)
2022-01-03 06:57:51 +00:00
taku0
d0467261a5 thunderbird: 91.4.0 -> 91.4.1
(cherry picked from commit 95011c834a)
2022-01-03 15:06:34 +09:00
taku0
de90ff0442 thunderbird-bin: 91.4.0 -> 91.4.1
(cherry picked from commit b02d1064cb)
2022-01-03 15:05:30 +09:00
Bernardo Meurer
15860e27c5 thunderbird-bin: 91.3.2 -> 91.4.0
(cherry picked from commit b9e3d2fede)
2022-01-03 15:05:26 +09:00
Ryan Burns
81cea446d0 Merge pull request #153274 from NixOS/backport-153002-to-release-21.11
[Backport release-21.11] bandwidth: 1.10.4 -> 1.11.2
2022-01-02 17:00:56 -08:00
github-actions[bot]
1fd0956153 Merge staging-next-21.11 into staging-21.11 2022-01-03 00:11:29 +00:00
github-actions[bot]
f2eddd326e Merge release-21.11 into staging-next-21.11 2022-01-03 00:10:51 +00:00
Ryan Burns
e099857756 bandwidth: 1.10.4 -> 1.11.2
(cherry picked from commit 68e39c2f98)
2022-01-02 23:05:00 +00:00
R. Ryantm
bb6c373078 apacheHttpd: 2.4.51 -> 2.4.52
(cherry picked from commit 78700df942)
2022-01-02 22:15:40 +00:00
Maximilian Bosch
c52c3567c2 prometheus-openldap-exporter: 2.1.4 -> 2.2.0
ChangeLog: https://github.com/tomcz/openldap_exporter/releases/tag/v2.2.0
(cherry picked from commit f562adfab8)
2022-01-02 22:13:34 +00:00
Maximilian Bosch
a2f1fa2abf element-{web,desktop}: 1.9.7 -> 1.9.8
ChangeLog: https://github.com/vector-im/element-desktop/releases/tag/v1.9.8
ChangeLog: https://github.com/vector-im/element-web/releases/tag/v1.9.8
(cherry picked from commit 1fc8d58bd9)
2022-01-02 22:11:06 +00:00
Emery Hemingway
08370e1e27 nncp: 7.7.0 -> 8.0.2
This update introduces an encrypted packet format that is
incompatible with releases older than 8.0.0.

Backport of commit 2d4524eb8c
2022-01-02 19:13:43 +01:00
Maximilian Bosch
3d0bc50933 Merge pull request #153223 from NixOS/backport-151922-to-release-21.11
[Backport release-21.11] gitea: 1.15.7 -> 1.15.9
2022-01-02 18:01:10 +01:00
Jörg Thalheim
dc9760dc61 Merge pull request #153212 from Ma27/backport-ferdi
[21.11] ferdi: 5.6.4 -> 5.6.5
2022-01-02 16:27:01 +00:00
Maximilian Bosch
4ce83cf775 gitea: 1.15.7 -> 1.15.9
ChangeLog: https://github.com/go-gitea/gitea/releases/tag/v1.15.8
ChangeLog: https://github.com/go-gitea/gitea/releases/tag/v1.15.9
(cherry picked from commit 8cb0ae287c)
2022-01-02 15:44:00 +00:00
Maximilian Bosch
158505cfb7 Merge pull request #153205 from NixOS/backport-153044-to-release-21.11
[Backport release-21.11] roundcube: 1.5.1 -> 1.5.2
2022-01-02 15:30:46 +01:00
TredwellGit
291a3b2918 glibc: 2.33-59 -> 2.33-62
(cherry picked from commit afcb6d3e10)
2022-01-02 14:20:36 +00:00
derjohn
6bf1bd6350 ferdi: 5.6.4 -> 5.6.5 (#152239)
(cherry picked from commit 64346a8685)
2022-01-02 14:42:53 +01:00
R. Ryantm
3ebdc98f0b wiki-js: 2.5.260 -> 2.5.268
(cherry picked from commit 30ac4e6534)
2022-01-02 13:23:57 +00:00
R. Ryantm
b49cfc8fbd roundcube: 1.5.1 -> 1.5.2
(cherry picked from commit c630bcd3e7)
2022-01-02 13:16:40 +00:00
github-actions[bot]
a0a081735c Merge staging-next-21.11 into staging-21.11 2022-01-02 00:11:23 +00:00
github-actions[bot]
3a70619628 Merge release-21.11 into staging-next-21.11 2022-01-02 00:10:43 +00:00
John Ericson
83f0e7da1e Merge pull request #153090 from NixOS/backport-153068-to-staging-21.11
[Backport staging-21.11] Check link type based on expanded parameters
2022-01-01 10:27:20 -08:00
Moritz Angermann
f6054e21a6 Check link type based on expanded parameters
So far we've ignored response files in arguments, and did not
check linkType against expanded parameters.  This means if
we have `-static` in a @reponse-file, linkType will not be
set to `-static` as we never check against the expanded arguments
from response files.

(cherry picked from commit 14996789a1)
2022-01-01 18:15:59 +00:00
Jörg Thalheim
e730d9ebd3 sbt: 1.5.7 -> 1.5.8 2022-01-01 16:52:22 +01:00
Bobby Rong
d1e59cfc49 Merge pull request #153064 from NixOS/backport-148857-to-release-21.11
[Backport release-21.11] meshlab: 2020.12 -> 2021.10
2022-01-01 22:20:39 +08:00
Zane van Iperen
1e16d4b65d meshlab: 2020.12 -> 2021.10
* De-vendors boost and xercesc
* Enables CGAL

(cherry picked from commit 7c0942ba57)
2022-01-01 12:00:33 +00:00
Michele Guerini Rocco
9e27e2e6bb Merge pull request #152940 from NixOS/backport-152594-to-release-21.11
[Backport release-21.11] security/wrappers: remove C compiler from the nixos/security.wrappers…
2022-01-01 11:01:14 +01:00
Michele Guerini Rocco
64e6eff5b1 Merge pull request #152941 from NixOS/backport-152897-to-release-21.11
[Backport release-21.11] mutt: 2.1.4 -> 2.1.5
2022-01-01 10:57:30 +01:00
Bobby Rong
7ed58927b8 Merge pull request #153019 from NixOS/backport-152984-to-release-21.11
[Backport release-21.11] treewide: fix homepages with permanent redirect to https (2)
2022-01-01 09:44:51 +08:00
Ben Siraphob
a2b06fa6d3 milkytracker: fix meta.homepage
(cherry picked from commit 3bedb63be96113ef68e8edde21dba3f6f6fba6a6)
2022-01-01 01:40:53 +00:00
Ben Siraphob
59352dd768 pbrt: fix meta.homepage
(cherry picked from commit 6ffd6401e980699fbf2bf03d60f1de4a8fdc2fdb)
2022-01-01 01:40:53 +00:00
Ben Siraphob
93f03c1a0f mkgmap: fix meta.homepage
(cherry picked from commit 874b1186a9aba7e1780810f264c9e373a08d9d4d)
2022-01-01 01:40:53 +00:00
Ben Siraphob
eccac97a99 mkgmap-splitter: fix meta.homepage
(cherry picked from commit 80c1981cd620020f5f88a41c0f507d494e42c160)
2022-01-01 01:40:53 +00:00
Ben Siraphob
93589d4533 openfst: fix meta.homepage
(cherry picked from commit 2bf68ff9e7f8286758e242b06c8e7696541dac36)
2022-01-01 01:40:53 +00:00
Ben Siraphob
63e7c67ab7 pekwm: fix meta.homepage
(cherry picked from commit b74f29e6e8ad00bb3ca5d71201f783a84bf3944b)
2022-01-01 01:40:53 +00:00
Ben Siraphob
e3bb5a327d opengrm-ngram: fix meta.homepage
(cherry picked from commit 1baad9bfb6bb293e6b02c29d4046da726fc26c9b)
2022-01-01 01:40:53 +00:00
Ben Siraphob
545ec36ed9 premake: fix meta.homepage
(cherry picked from commit d96f843157c1b783783f7863ec0e27a85cd60304)
2022-01-01 01:40:53 +00:00
Ben Siraphob
fea56fe3e0 meteor: fix meta.homepage
(cherry picked from commit f5c380b978a16b6d69f7daa48acc7663c095d610)
2022-01-01 01:40:53 +00:00
Ben Siraphob
a8329d0522 mysqltuner: fix meta.homepage
(cherry picked from commit 8b14880949ffa9bd89c91882d3321a02608a8d96)
2022-01-01 01:40:53 +00:00
Ben Siraphob
a2d47f1e3d popfile: fix meta.homepage
(cherry picked from commit 5a0075e7c11d542fc702aa6d0d8c0eeb38536a68)
2022-01-01 01:40:53 +00:00
Ben Siraphob
273d6bfad9 microscheme: fix meta.homepage
(cherry picked from commit 4b9cbc118f8814a2f47e70325ee8d94d160a9eb8)
2022-01-01 01:40:53 +00:00
github-actions[bot]
1a27325a1e Merge staging-next-21.11 into staging-21.11 2022-01-01 00:10:51 +00:00
github-actions[bot]
351c348d89 Merge release-21.11 into staging-next-21.11 2022-01-01 00:10:12 +00:00
Martin Weinelt
2ca20fd653 nodejs: mark versions older than 12 as vulnerable
NodeJS 10 has reached EOL since 2021/04.

(cherry picked from commit f0b4870640)
2021-12-31 15:23:06 -05:00
Maximilian Bosch
698a544828 Merge pull request #152707 from NixOS/backport-152597-to-release-21.11
[Backport release-21.11] Kernels 2021-12-29
2021-12-31 20:20:08 +01:00
Maximilian Bosch
0ce911b5c0 Merge pull request #152819 from NixOS/backport-152555-to-release-21.11
[Backport release-21.11] hedgedoc: fix build
2021-12-31 20:20:03 +01:00
Jörg Thalheim
f8d88f2961 Merge pull request #152959 from NixOS/backport-152749-to-release-21.11
[Backport release-21.11] python3Packages.libnacl: fix build on 32-bit platforms
2021-12-31 17:37:49 +00:00
Enno Richter
fbc07f0262 python3Packages.libnacl: fix build on 32-bit platforms
(cherry picked from commit c71bc6a805)
2021-12-31 15:53:45 +00:00
Matthias Beyer
372d56d76f mutt: 2.1.4 -> 2.1.5
Signed-off-by: Matthias Beyer <mail@beyermatthias.de>
(cherry picked from commit 60dfe7dd08)
2021-12-31 14:13:50 +00:00
Julien Moutinho
65e5ccc9f9 security/wrappers: remove C compiler from the nixos/security.wrappers AppArmor profile
(cherry picked from commit 0e5611e0be)
2021-12-31 14:13:38 +00:00
Ryan Burns
00fa9c23cf Merge pull request #152825 from NixOS/backport-147984-to-release-21.11
[Backport release-21.11] forge: fix build
2021-12-30 21:40:39 -08:00
R. Ryantm
a4054d8165 btop: 1.1.2 -> 1.1.3
(cherry picked from commit 9bd8d83f93)
2021-12-31 05:21:47 +00:00
7c6f434c
2cf5bc5ea3 Merge pull request #152755 from NixOS/backport-152705-to-release-21.11
[Backport release-21.11] glusterfs: fix version info
2021-12-31 01:09:24 +00:00
github-actions[bot]
201ef3b51b Merge staging-next-21.11 into staging-21.11 2021-12-31 00:10:56 +00:00
github-actions[bot]
c2cda066e9 Merge release-21.11 into staging-next-21.11 2021-12-31 00:10:22 +00:00
Ryan Burns
b915810e34 forge: fix build
The build was failing due to mismatched libstdc++ between
stdenv.cc and cudatoolkit.cc. This can be fixed by bumping
the build-time cudatoolkit to 11, which is able to use the
same cc as stdenv.

(cherry picked from commit e263bdd82b)
2021-12-30 23:12:08 +00:00
Yureka
85fae8ae0b hedgedoc: fix build
(cherry picked from commit bdf8bb5f6346f90785641bd6a27ca13a111404e8)
2021-12-30 22:34:45 +00:00
Yureka
2933169c84 Revert "hedgedoc: 1.9.0 -> 1.9.2"
This reverts commit f5c724877e.

(cherry picked from commit 171b011a69733c459c30b47cec7b70c516078194)
2021-12-30 22:34:44 +00:00
7c6f434c
eae19fff64 Merge pull request #152746 from NixOS/backport-152409-to-release-21.11
[Backport release-21.11] singular: backport patch to fix docbuilding with >= 64 cpus
2021-12-30 22:17:20 +00:00
Maximilian Bosch
a042312846 epson-escpr2: 1.1.42 -> 1.1.45
New upstream release.

Also dropped the `web.archive.org`-usage: when I took over maintainership
over the package I continued to update that, but actually it's not
strictly needed because `copy-tarballs.pl` already takes care of copying
the src to `tarballs.nixos.org` (since it's redistributable).

(cherry picked from commit 87ee865bd6)
2021-12-30 22:00:32 +00:00
Cole Helbling
c7295777c9 nixos/test-driver: add (functional) timeouts to more functions
A retry timeout doesn't really help if the thing it's retrying may block
forever.

(cherry picked from commit e62b8020f3)
2021-12-30 11:41:47 -08:00
Cole Helbling
a9f78ab7c2 nixos/test-driver: add timeout parameter to execute
(cherry picked from commit 363d7f3ae8)
2021-12-30 11:41:47 -08:00
Cole Helbling
2bf5a904f0 nixos/test-driver: give more functions nested labels
This will make it easier to trace through the test execution without
having to scroll through the entire kernel output.

(cherry picked from commit af765f3abd)
2021-12-30 11:41:36 -08:00
Cole Helbling
11ec91d759 nixos/test-driver: more context when step finishes
When displaying the amount of time some step took, with no other
context, it becomes nigh impossible (especially in longer tests) to see
when specific steps finished.

(cherry picked from commit c6ee63259a)
2021-12-30 11:41:36 -08:00
Thiago Kenji Okada
8a053bc225 Merge pull request #152752 from NixOS/backport-152735-to-release-21.11
[Backport release-21.11] babashka: 0.7.0 -> 0.7.3
2021-12-30 15:11:46 -03:00
Jörg Thalheim
24677d5db7 Merge pull request #152643 from NixOS/backport-152614-to-release-21.11
[Backport release-21.11] unicorn: 2.0.0-rc4 -> 2.0.0-rc5
2021-12-30 17:50:14 +00:00
Bjørn Forsman
7913713f00 glusterfs: fix version info
A build script in glusterfs uses /bin/bash interpreter and fails to get
the version from the VERSION file at build time:

  sh: build-aux/pkg-version: /bin/bash: bad interpreter: No such file or directory
  sh: build-aux/pkg-version: /bin/bash: bad interpreter: No such file or directory
  sh: build-aux/pkg-version: /bin/bash: bad interpreter: No such file or directory
  [...]

The result is that `gluster --version` doesn't include a version number.
Fixup the shebang to get the version info.

(cherry picked from commit 7e399b7078)
2021-12-30 17:24:47 +00:00
Thiago Kenji Okada
7d5a23afd6 babashka: 0.7.0 -> 0.7.3
(cherry picked from commit 192cd3cd39)
2021-12-30 17:09:00 +00:00
Mauricio Collares
4e39259eba singular: backport patch to fix docbuilding with >= 64 cpus
(cherry picked from commit ec0c4a001f)
2021-12-30 16:39:12 +00:00
Lara
f6dc47d9d8 gitlab: 14.5.2 -> 14.6.0
(cherry picked from commit 6e1978ee81dd35651e3410fa33c52e04a105433a)
2021-12-30 15:20:35 +01:00
TredwellGit
499da55cb6 linux: 5.4.168 -> 5.4.169
(cherry picked from commit 5e8e09d3a3)
2021-12-30 13:51:48 +00:00
TredwellGit
3c6b9f16ef linux: 5.15.11 -> 5.15.12
(cherry picked from commit fcbeb94323)
2021-12-30 13:51:48 +00:00
TredwellGit
da78115629 linux: 5.10.88 -> 5.10.89
(cherry picked from commit 6504d5dae6)
2021-12-30 13:51:48 +00:00
TredwellGit
d83471f5fe linux: 4.9.294 -> 4.9.295
(cherry picked from commit 8ad124f2b0)
2021-12-30 13:51:48 +00:00
TredwellGit
a1df6156e4 linux: 4.4.296 -> 4.4.297
(cherry picked from commit 2f1863ce77)
2021-12-30 13:51:48 +00:00
TredwellGit
a33c5426a6 linux: 4.19.222 -> 4.19.223
(cherry picked from commit e1dd7fb45f)
2021-12-30 13:51:48 +00:00
TredwellGit
0a3a143440 linux: 4.14.259 -> 4.14.260
(cherry picked from commit e3d0e08e8e)
2021-12-30 13:51:47 +00:00
Michael Weiss
8d373df05f Merge pull request #152633 from cleeyv/backport-chromium
[21.11] chromium: Install libvulkan.so.1 and vk_swiftshader_icd.json
2021-12-30 11:36:10 +01:00
Robert Scott
5d4f4b9f8a python3Packages.keystone-engine: fix build for non-x86 linux
(cherry picked from commit addd745ca3)
2021-12-29 22:52:18 -08:00
Robert Scott
c8d9bdc08c python3Packages.angr: fix build for non-x86 linux
(cherry picked from commit 6a733a18fd)
2021-12-29 22:52:18 -08:00
Robert Scott
782674816f unicorn: 2.0.0-rc4 -> 2.0.0-rc5
(cherry picked from commit bdb8ba829c)
2021-12-30 06:08:15 +00:00
Enno Richter
cec1018cca python39Packages.frozendict: fix build on non-x86_64 systems
(cherry picked from commit 687b1233c2)
2021-12-29 18:35:37 -08:00
Mario Rodas
63f848de74 Merge pull request #152635 from NixOS/backport-152620-to-release-21.11
[Backport release-21.11] yt-dlp: 2021.12.25 -> 2021.12.27
2021-12-29 19:24:12 -05:00
github-actions[bot]
c8dee75ae7 Merge staging-next-21.11 into staging-21.11 2021-12-30 00:10:48 +00:00
github-actions[bot]
670c11d0da Merge release-21.11 into staging-next-21.11 2021-12-30 00:10:07 +00:00
Sandro Jäckel
8bc2e3ce36 yt-dlp: 2021.12.25 -> 2021.12.27
(cherry picked from commit 9919f32394)
2021-12-29 23:57:34 +00:00
Bobby Rong
8588b14a39 Merge pull request #152603 from NixOS/backport-152599-to-release-21.11
[Backport release-21.11] blockhash: update meta.homepage
2021-12-30 01:13:47 +08:00
Ben Siraphob
afbfa6630d blockhash: update meta.homepage
(cherry picked from commit 42b3533fa8)
2021-12-29 17:02:12 +00:00
Ben Siraphob
04b53f5a1b Merge pull request #152593 from NixOS/backport-152591-to-release-21.11
[Backport release-21.11] treewide: fix homepages with permanent redirect to https
2021-12-29 23:46:18 +07:00
Ben Siraphob
1996b3b52f treewide: fix homepages with permanent redirect to https
(cherry picked from commit 39a0a70d29)
2021-12-29 15:27:29 +00:00
Dmitry Kalinkin
e101dc111a yoda: 1.9.3 -> 1.9.4
(cherry picked from commit 47081b2553)
2021-12-29 01:33:23 -05:00
Bobby Rong
fe15c5a6bc Merge pull request #152564 from NixOS/backport-152473-to-release-21.11
[Backport release-21.11] ghidra: update homepage
2021-12-29 14:14:00 +08:00
Bobby Rong
751ed1f569 Merge pull request #152563 from NixOS/backport-152464-to-release-21.11
[Backport release-21.11] ammonite: fix homepage
2021-12-29 14:13:16 +08:00
Jonathan Ringer
ece61aa2f4 ghidra: update homepage
(cherry picked from commit df1c411c2a)
2021-12-29 06:12:56 +00:00
Jonathan Ringer
7ce842f439 ammonite: fix homepage
(cherry picked from commit 57c1ae5848)
2021-12-29 06:12:03 +00:00
Bobby Rong
4e0ed34123 Merge pull request #152562 from NixOS/backport-152479-to-release-21.11
[Backport release-21.11] graphene: fix homepage
2021-12-29 14:11:05 +08:00
Bobby Rong
47cb107c06 Merge pull request #152561 from NixOS/backport-152488-to-release-21.11
[Backport release-21.11] klettres: update homepage
2021-12-29 14:10:35 +08:00
Bobby Rong
7e5435133b Merge pull request #152560 from NixOS/backport-152483-to-release-21.11
[Backport release-21.11] icestorm: update homepage
2021-12-29 14:10:26 +08:00
Jonathan Ringer
b96207b663 graphene: fix homepage
(cherry picked from commit 4892198bc8)
2021-12-29 06:10:20 +00:00
Bobby Rong
1547736b98 Merge pull request #152559 from NixOS/backport-152490-to-release-21.11
[Backport release-21.11] kturtle: update homepage
2021-12-29 14:09:59 +08:00
Jonathan Ringer
982890ee94 klettres: update homepage
(cherry picked from commit 1b8c414047)
2021-12-29 06:09:54 +00:00
Jonathan Ringer
4df855e226 icestorm: update homepage
(cherry picked from commit 7c517f25ce)
2021-12-29 06:09:51 +00:00
Jonathan Ringer
9b4d801fd7 kturtle: update homepage
(cherry picked from commit 441a30ab24)
2021-12-29 06:08:51 +00:00
Bobby Rong
2652561e3e Merge pull request #152553 from NixOS/backport-152551-to-release-21.11
[Backport release-21.11] gtksourceviewmm4: update homepage
2021-12-29 11:37:24 +08:00
Bobby Rong
09e2781060 gtksourceviewmm4: update homepage
previous homepage no longer exists

(cherry picked from commit fe339e7bb3)
2021-12-29 03:37:04 +00:00
github-actions[bot]
edc00c1f87 gtksourceviewmm: update homepage
previous homepage no longer exists

(cherry picked from commit 6aab02a1de)
2021-12-29 11:31:24 +08:00
Bobby Rong
4502db003b Merge pull request #152548 from NixOS/backport-152530-to-release-21.11
[Backport release-21.11] inherd-quake: fix pname, set meta.mainProgram
2021-12-29 10:25:19 +08:00
Bobby Rong
d9901428c8 Merge pull request #152549 from NixOS/backport-152486-to-release-21.11
[Backport release-21.11] kipi-plugins: update homepage
2021-12-29 10:20:48 +08:00
Jonathan Ringer
ff811eabec kipi-plugins: update homepage
(cherry picked from commit 73bcd3556e)
2021-12-29 02:19:16 +00:00
Bobby Rong
e9e6963139 inherd-quake: update cargoSha256
(cherry picked from commit cdf40cdec5)
2021-12-29 02:11:40 +00:00
Bobby Rong
f8c167a473 inherd-quake: fix pname, set meta.mainProgram
(cherry picked from commit 487f0c6dbe)
2021-12-29 02:11:39 +00:00
Bobby Rong
92ceedc645 Merge pull request #152545 from NixOS/backport-152478-to-release-21.11
[Backport release-21.11] grantlee: update homepage
2021-12-29 09:47:41 +08:00
Bobby Rong
9677bf8f68 Merge pull request #152546 from NixOS/backport-152468-to-release-21.11
[Backport release-21.11] spark: avoid https redirect
2021-12-29 09:47:30 +08:00
Jonathan Ringer
66dac4f27e spark: avoid https redirect
(cherry picked from commit 005ec0e68f)
2021-12-29 01:46:41 +00:00
Jonathan Ringer
31762be481 grantlee: update homepage
(cherry picked from commit e46438d504)
2021-12-29 01:46:23 +00:00
Bobby Rong
6a92c36a0a Merge pull request #152544 from NixOS/backport-152482-to-release-21.11
[Backport release-21.11] ibniz: update homepage
2021-12-29 09:43:54 +08:00
Jonathan Ringer
99e515c383 ibniz: update homepage
(cherry picked from commit 6b6c9bc928)
2021-12-29 01:43:07 +00:00
Bobby Rong
e0959a9a67 Merge pull request #152542 from NixOS/backport-152484-to-release-21.11
[Backport release-21.11] kafka: update homepage
2021-12-29 09:27:57 +08:00
Bobby Rong
920d8ca020 Merge pull request #152543 from NixOS/backport-152485-to-release-21.11
[Backport release-21.11] kalzium: update homepage
2021-12-29 09:27:45 +08:00
Jonathan Ringer
5c00481f15 kalzium: update homepage
(cherry picked from commit c2fadb5556)
2021-12-29 01:24:08 +00:00
Jonathan Ringer
57f4493c99 kafka: update homepage
(cherry picked from commit a37bebd666)
2021-12-29 01:23:29 +00:00
Bobby Rong
c6b57e0cdc Merge pull request #152540 from NixOS/backport-152467-to-release-21.11
[Backport release-21.11] apache-airflow: avoid https redirect
2021-12-29 09:17:44 +08:00
Bobby Rong
b02af431a8 Merge pull request #152541 from NixOS/backport-152466-to-release-21.11
[Backport release-21.11] ant: fix redirect
2021-12-29 09:17:36 +08:00
Jonathan Ringer
55e16a0c4d ant: fix redirect
(cherry picked from commit 4879b9c8bd)
2021-12-29 01:15:22 +00:00
Jonathan Ringer
07e09d27b3 apache-airflow: avoid https redirect
(cherry picked from commit 4efb30a66b)
2021-12-29 01:14:55 +00:00
Bobby Rong
796c321709 Merge pull request #152539 from NixOS/backport-152470-to-release-21.11
[Backport release-21.11] ceph: update homepage
2021-12-29 09:14:28 +08:00
Jonathan Ringer
d295df2ff8 ceph: update homepage
(cherry picked from commit 09bd298765)
2021-12-29 01:13:50 +00:00
Bobby Rong
ce7997f0ea Merge pull request #152538 from NixOS/backport-152472-to-release-21.11
[Backport release-21.11] gf2x: update homepage
2021-12-29 09:11:49 +08:00
Jonathan Ringer
9a04af5496 gf2x: update homepage
(cherry picked from commit 6828c4d0ff)
2021-12-29 01:11:30 +00:00
Bobby Rong
087614dee7 Merge pull request #152537 from NixOS/backport-152476-to-release-21.11
[Backport release-21.11] gnome.power-manager: update homepage
2021-12-29 09:09:38 +08:00
Bobby Rong
5ee3719ba2 Merge pull request #152536 from NixOS/backport-152489-to-release-21.11
[Backport release-21.11] python3Packages.certifi: update homepage
2021-12-29 09:09:28 +08:00
Jonathan Ringer
d15855536e gnome.power-manager: update homepage
(cherry picked from commit c40db3150d)
2021-12-29 01:07:18 +00:00
Jonathan Ringer
962178b412 python3Packages.certifi: update homepage
(cherry picked from commit a3703b1ac8)
2021-12-29 01:05:36 +00:00
Bobby Rong
344c117b03 Merge pull request #152535 from NixOS/backport-152492-to-release-21.11
[Backport release-21.11] libbitcoin: update homepage
2021-12-29 09:02:34 +08:00
Jonathan Ringer
a5675709f3 libbitcoin: update homepage
(cherry picked from commit 3b4e6f5823)
2021-12-29 01:01:42 +00:00
Bobby Rong
120f25d648 Merge pull request #152534 from NixOS/backport-152491-to-release-21.11
[Backport release-21.11] lfe: update homepage
2021-12-29 08:55:40 +08:00
Bobby Rong
9f2f2e9889 Merge pull request #152531 from NixOS/backport-152497-to-release-21.11
[Backport release-21.11] luaPackages.lgi: update homepage
2021-12-29 08:54:50 +08:00
Bobby Rong
85cc28b2a9 Merge pull request #152532 from NixOS/backport-152494-to-release-21.11
[Backport release-21.11] linux-phc-intel: update homepage
2021-12-29 08:54:40 +08:00
Bobby Rong
dca15b4c20 Merge pull request #152533 from NixOS/backport-152493-to-release-21.11
[Backport release-21.11] libnotify: update homepage
2021-12-29 08:54:13 +08:00
Jonathan Ringer
c3b413858d lfe: update homepage
(cherry picked from commit 524a50d75e)
2021-12-29 00:53:48 +00:00
Jonathan Ringer
fcad57ff34 libnotify: update homepage
(cherry picked from commit b5996f37ca)
2021-12-29 00:52:33 +00:00
Jonathan Ringer
925be5b02f linux-phc-intel: update homepage
(cherry picked from commit 8fea5898ec)
2021-12-29 00:51:25 +00:00
Jonathan Ringer
3c7f6c509c luaPackages.lgi: update homepage
(cherry picked from commit 8ee0a5f4bf)
2021-12-29 00:49:44 +00:00
github-actions[bot]
ca34aed660 Merge staging-next-21.11 into staging-21.11 2021-12-29 00:10:56 +00:00
github-actions[bot]
a09caf8093 Merge release-21.11 into staging-next-21.11 2021-12-29 00:10:20 +00:00
Thiago Kenji Okada
35f6f91a2e Merge pull request #152450 from NixOS/backport-152245-to-release-21.11
[Backport release-21.11] gimp: 2.10.28 → 2.10.30
2021-12-28 19:21:22 -03:00
Jonathan Ringer
db1258a948 luaPackages.ldoc: update homepage
(cherry picked from commit 3750e4d11fef1be9a04e5e34fc712c25f4edd0f4)
2021-12-28 11:04:21 -08:00
Bobby Rong
4fe043fcc2 Merge pull request #152457 from NixOS/backport-152339-to-release-21.11
[Backport release-21.11] Quake: init 0.3.0
2021-12-28 22:42:10 +08:00
Elliot Xu
4de4bedd7f quake: init at 0.3.0
Update pkgs/applications/misc/inherd-quake/default.nix

Co-authored-by: Bobby Rong <rjl931189261@126.com>

Update pkgs/applications/misc/inherd-quake/default.nix

Co-authored-by: Bobby Rong <rjl931189261@126.com>

Update pkgs/applications/misc/inherd-quake/default.nix

Co-authored-by: Bobby Rong <rjl931189261@126.com>

Update pkgs/applications/misc/inherd-quake/default.nix

Co-authored-by: Bobby Rong <rjl931189261@126.com>
(cherry picked from commit 4a578ce659)
2021-12-28 14:20:41 +00:00
Elliot Xu
bdefc658a5 maintainers: add elliot
(cherry picked from commit c749d3a90d)
2021-12-28 14:20:40 +00:00
Thiago Kenji Okada
ea91331e8c Merge pull request #152401 from Madouura/back/ares
[Backport release-21.11] ares: init at 126
2021-12-28 10:30:42 -03:00
Thiago Kenji Okada
ef557a8e41 Merge pull request #152426 from NixOS/backport-152384-to-release-21.11
[Backport release-21.11] buildGraalvmNativeImage: fix meta
2021-12-28 10:15:46 -03:00
Michele Guerini Rocco
e6413c7f29 Merge pull request #152453 from NixOS/backport-152445-to-release-21.11
[Backport release-21.11] pirate-get: 0.4.0 -> 0.4.1
2021-12-28 13:55:44 +01:00
rnhmjoj
011487d8d5 pirate-get: 0.4.0 -> 0.4.1
(cherry picked from commit 793050f2c9)
2021-12-28 12:46:15 +00:00
Jan Tojnar
972d5a9dc9 gimp: 2.10.28 → 2.10.30
https://www.gimp.org/news/2021/12/21/gimp-2-10-30-released/
(cherry picked from commit e6c3e3d394)
2021-12-28 12:23:05 +00:00
Jan Tojnar
ac0f1061f7 gegl: 0.4.32 → 0.4.34
https://gitlab.gnome.org/GNOME/gegl/-/compare/GEGL_0_4_32...GEGL_0_4_34
(cherry picked from commit b072f7ec19)
2021-12-28 12:23:04 +00:00
7c6f434c
fe856f4d07 Merge pull request #152147 from NixOS/backport-150788-to-release-21.11
[Backport release-21.11] lapack: add patch for CVE-2021-4048
2021-12-28 11:25:24 +00:00
Jörg Thalheim
0a82b48305 Merge pull request #152435 from NixOS/backport-150896-to-release-21.11
[Backport release-21.11] jetbrains.goland: Fix debugging
2021-12-28 10:27:48 +00:00
Kim Lindberger
0f54d18302 Merge pull request #152380 from NixOS/backport-151650-to-release-21.11
[Backport release-21.11] discourse: 2.8.0.beta9 -> 2.8.0.beta10; update plugins
2021-12-28 11:27:43 +01:00
Jörg Thalheim
97e780b5dc Merge pull request #152340 from NixOS/backport-151768-to-release-21.11
[Backport release-21.11] ghidra: 10.1 -> 10.1.1
2021-12-28 10:09:46 +00:00
Diogo Xavier
513937fec9 jetbrains.goland: Fix debugging
(cherry picked from commit 0b4a0ac786)
2021-12-28 10:01:10 +00:00
Jörg Thalheim
fee31fb9e4 Merge pull request #152425 from NixOS/backport-152261-to-release-21.11
[Backport release-21.11] mediathekview: CVE-2021-45105 (log4j) mitigation
2021-12-28 08:57:20 +00:00
Thiago Kenji Okada
8e78a0199f clj-kondo: fix typo
(cherry picked from commit 34b93d2007)
2021-12-28 07:29:04 +00:00
Thiago Kenji Okada
d3f8d10a5e buildGraalvmNativeImage: fix meta
(cherry picked from commit 24f9dcd06b)
2021-12-28 07:29:04 +00:00
André-Patrick Bubel
0012967499 mediathekview: CVE-2021-45105 (log4j) mitigation
Remove the affected JndiLookup.class until we can update to the lastest
Mediathekview version.

(cherry picked from commit 2a360652e2)
2021-12-28 07:20:22 +00:00
Bobby Rong
25e4939b6d Merge pull request #152419 from NixOS/backport-152382-to-release-21.11
[Backport release-21.11] doc/python: remove 3.6 from the list of cpython versions
2021-12-28 13:30:33 +08:00
Yevhen Shymotiuk
49b142f910 doc/python: remove 3.6 from the list of cpython versions
(cherry picked from commit 08d3a002db)
2021-12-28 05:29:00 +00:00
adisbladis
77a71b79ec Merge pull request #152418 from adisbladis/poetry2nix_1_24_1-backport-21_11
[21.11] poetry2nix: 1.21.0 -> 1.24.1
2021-12-28 17:16:12 +12:00
Bobby Rong
45048df9e9 Merge pull request #152396 from NixOS/backport-150331-to-release-21.11
[Backport release-21.11] babashka: 0.6.8 -> 0.7.0
2021-12-28 13:02:20 +08:00
adisbladis
92ee26407e poetry2nix: 1.23.0 -> 1.24.1
(cherry picked from commit 4d6da24d18)
2021-12-27 20:59:06 -08:00
adisbladis
b29cd27038 poetry2nix: 1.22.0 -> 1.23.0
(cherry picked from commit 56751653a9)
2021-12-27 20:58:14 -08:00
Lionello Lunesu
dbc28cb64b poetry2nix: 1.21.0 -> 1.22.0
(cherry picked from commit d63606d759)
2021-12-27 20:58:04 -08:00
Bobby Rong
b5f4274974 Merge pull request #152388 from OPNA2608/backport/21.11/ptcollab
[21.11] ptcollab: Unbreak on Darwin, 0.5.0.1 -> 0.5.0.3
2021-12-28 10:50:51 +08:00
davidak
aabc055631 Merge pull request #152410 from NixOS/backport-152398-to-release-21.11
[Backport release-21.11] bcachefs: 2021-11 -> 2021-12
2021-12-28 03:32:10 +01:00
Madoura
b350289df2 bcachefs-tools: 2021-11-06 -> 2021-12-25
(cherry picked from commit 1595230f47)
2021-12-28 01:48:26 +00:00
Madoura
76798dba5d linux_testing-bcachefs: 2021-11-06 -> 2021-12-26
(cherry picked from commit 40f0507288)
2021-12-28 01:48:26 +00:00
Stig Palmquist
5442929a8e convos: 6.26 -> 6.42
(cherry picked from commit e7b7042e42)
2021-12-28 01:10:19 +00:00
Stig Palmquist
f4a9e22781 perlPackages.TextMarkdownHoedown: init at 1.03
(cherry picked from commit a979570718)
2021-12-28 01:10:19 +00:00
Stig Palmquist
e05b07ee29 perlPackages.MojoliciousPluginSyslog: 0.04 -> 0.05
(cherry picked from commit dba7c6a07c)
2021-12-28 01:10:19 +00:00
Stig Palmquist
767e41c683 perlPackages.CryptPassphraseBcrypt: init at 0.001
(cherry picked from commit 0ac9fe175e)
2021-12-28 01:10:19 +00:00
Stig Palmquist
3b89370e8f perlPackages.CryptPassphraseArgon2: 0.002 -> 0.003
(cherry picked from commit 382e055888)
2021-12-28 01:10:19 +00:00
Madoura
93736b5d8c maintainers: add Madouura
(cherry picked from commit 86630d9a5f)
2021-12-27 18:29:15 -06:00
github-actions[bot]
c6854c5c7c Merge staging-next-21.11 into staging-21.11 2021-12-28 00:10:41 +00:00
github-actions[bot]
aec9f05c67 Merge release-21.11 into staging-next-21.11 2021-12-28 00:10:06 +00:00
Madoura
f7104d497e ares: init at 126
(cherry picked from commit b83dac8bd1)
2021-12-27 17:49:40 -06:00
R. Ryantm
a233b208b1 babashka: 0.6.8 -> 0.7.0
(cherry picked from commit ebbae48908)
2021-12-27 23:29:18 +00:00
Michael Weiss
07eb146d72 chromium: Install libvulkan.so.1
This might be required for experimental Vulkan support, see:
https://github.com/NixOS/nixpkgs/issues/150398

Note: Google Chrome distributes it as well.
(cherry picked from commit 075338beb2)

Reason: fixes nixos/jibri bug since upgrade to chromium 96 on Nov 15:
https://hydra.nixos.org/job/nixos/trunk-combined/nixos.tests.jibri.x86_64-linux
2021-12-27 18:06:06 -05:00
Michael Weiss
7843e02066 chromium: Install vk_swiftshader_icd.json
This should be required for Vulkan support via SwiftShader but I wasn't
able to test/confirm it yet (according to strace Chromium never tried to
load that file). The relevant flags for using Chromium with SwiftShader
are documented at [0] and SwiftShader's ANGLE documentation [1] mentions
the relevant files. See also [2], [3], and [4] for more details.

[0]: https://source.chromium.org/chromium/chromium/src/+/master:docs/gpu/swiftshader.md;drc=046f987e020baba45ffb3061b3ee3d960d6ce981
[1]: 2413491078/docs/ANGLE.md
[2]: 2413491078/README.md
[3]: ca9efe3f1c/docs/LoaderInterfaceArchitecture.md
[4]: https://bugs.archlinux.org/task/72652

(cherry picked from commit 66352e3ee4)

Reason: related to libvulkan.so.1 fix for for nixos/jibri
2021-12-27 18:03:58 -05:00
Martin Weinelt
e2ef8c5427 Merge pull request #152374 from NixOS/backport-152311-to-release-21.11 2021-12-27 23:30:01 +01:00
OPNA2608
4dd3482413 ptcollab: 0.5.0.1 -> 0.5.0.3
(cherry picked from commit 98077c6486)
2021-12-27 23:26:03 +01:00
OPNA2608
00707e45e1 ptcollab: Unbreak on Darwin
(cherry picked from commit 6237d9f952)
2021-12-27 23:25:42 +01:00
talyz
d9a7c77bcb discourse: Forward the used system and pkgs attributes to the tests
The system attribute is otherwise deduced from the system the
evaluation runs on, which could be incorrect if using remote
builders.

(cherry picked from commit ae77e2fb78)
2021-12-27 22:04:44 +00:00
talyz
355641edb0 discourse: Add aarch64-linux to the list of platforms to be removed
...in the update script and remove it from the Gemfile.lock. Having
it there causes a failure with the error message:

Could not find libv8-node-16.10.0.0-aarch64-linux in any of the
sources (Bundler::GemNotFound)

And since we're not using the prebuilt binary packages anyway, we
don't need it there in the first place.

(cherry picked from commit 1138af5637)
2021-12-27 22:04:44 +00:00
Ryan Mulligan
af9d50cc27 discourse: 2.8.0.beta9 -> 2.8.0.beta10; update plugins
(cherry picked from commit 50832be998)
2021-12-27 22:04:43 +00:00
Robert Gerus
a7b4eecfd3 nixos/kea: fixes for the systemd units
Fix a typo in the kea-dhcp-ddns-server unit definition, and add a
KEA_LOCKFILE_DIR environment variable without which kea daemons try to
access a lockfile under /var/run/kea path, which is prevented by
systemd's ProtectSystem (or one of the other Protect*) mechanism.
kea-dhcp-ddns-server doesn't react to updates from dhcp4 server at all
without it.

(cherry picked from commit 6faa7ad3fc)
2021-12-27 21:05:31 +00:00
adisbladis
58ced1df9b Merge pull request #152364 from NixOS/backport-152328-to-release-21.11
[Backport release-21.11] emacs: Add withXinput2 argument
2021-12-28 08:51:40 +12:00
Have a good time
57fa810569 emacs: Add withXinput2 argument
(cherry picked from commit 3fdeef8a7e)
2021-12-27 20:15:12 +00:00
Bernardo Meurer
f9632ed00c roon-server: explicitly set dontConfigure/Build
(cherry picked from commit 795469df58)
2021-12-27 18:26:06 +00:00
Bernardo Meurer
1bffe9dc34 roon-server: 1.8-850 -> 1.8-880
(cherry picked from commit 2d18e3a33d)
2021-12-27 18:26:06 +00:00
Joerie de Gram
40ded2bd35 ghidra: 10.1 -> 10.1.1
Fixes CVE-2021-45105 (#150288)

(cherry picked from commit 2654041a66)
2021-12-27 12:24:16 +00:00
Dmitry Kalinkin
d887ac7aee root: fix installation of bin/rootcint and bin/genreflex
(cherry picked from commit d5bdb7d39d)
2021-12-26 21:39:36 -05:00
Bernardo Meurer
f4ae07ffca nixos/gvfs: fix libmtp udev package path
As pointed out by @sigprof[1] my bump of libmtp silently broke this, as I
moved the udev files out of the bin output of the pkg.

[1]: https://github.com/NixOS/nixpkgs/pull/144290#discussion_r775266642

(cherry picked from commit 2d7fc66c79)
2021-12-27 02:35:04 +00:00
Robert Scott
c7900c5e78 lapack: add patch for CVE-2021-4048
(cherry picked from commit 6d952e40483a6951d585b79070872e81909409a9)
2021-12-27 02:02:38 +00:00
Dennis Gosnell
1dd3dc3bc3 Merge pull request #152290 from NixOS/backport-152282-to-release-21.11
[Backport release-21.11] haskellPackages.nix-thunk: Document patches
2021-12-27 10:39:06 +09:00
Robert Schütz
511f486595 imagemagick: 7.1.0-17 -> 7.1.0-19
(cherry picked from commit 33031122521a59baf7b2dee117b180b9adba30e7)
2021-12-27 02:32:52 +01:00
github-actions[bot]
ddfb4d96c2 Merge staging-next-21.11 into staging-21.11 2021-12-27 00:11:06 +00:00
github-actions[bot]
51d046f2f4 Merge release-21.11 into staging-next-21.11 2021-12-27 00:10:33 +00:00
John Ericson
d1595d8249 haskellPackages.nix-thunk: Document patches
As requested in
https://github.com/NixOS/nixpkgs/pull/150635#discussion_r770152144

Sorry I didn't notice the existing comments and do this from the get-go.

(cherry picked from commit e22939cc80)
2021-12-26 23:23:36 +00:00
John Ericson
4104aaa738 Merge pull request #150915 from NixOS/backport-150635-to-release-21.11
[Backport release-21.11] haskellPackages.{github,nix-thunk}: Fix
2021-12-26 14:07:21 -08:00
TredwellGit
a828dde2f8 firmwareLinuxNonfree: 20211027 -> 20211216
(cherry picked from commit f1edf331df)
2021-12-26 16:27:10 +00:00
Pavol Rusnak
04bd2d1a47 Merge pull request #152238 from NixOS/backport-152224-to-release-21.11
[Backport release-21.11] Update Electron
2021-12-26 16:07:51 +01:00
ajs124
562d520bf8 Merge pull request #152233 from NixOS/backport-151754-to-release-21.11
[Backport release-21.11] sope: 5.3.0 -> 5.4.0
2021-12-26 15:56:31 +01:00
TredwellGit
bc5bf063d4 electron_16: 16.0.4 -> 16.0.5
https://github.com/electron/electron/releases/tag/v16.0.5
(cherry picked from commit f3a39a335f)
2021-12-26 14:33:25 +00:00
TredwellGit
91f55d446e electron_15: 15.3.3 -> 15.3.4
https://github.com/electron/electron/releases/tag/v15.3.4
(cherry picked from commit 760cec731e)
2021-12-26 14:33:24 +00:00
TredwellGit
2fbce4d992 electron_14: 14.2.2 -> 14.2.3
https://github.com/electron/electron/releases/tag/v14.2.3
(cherry picked from commit 6c011c17a0)
2021-12-26 14:33:24 +00:00
ajs124
41f85cb0e4 sogo: 5.3.0 -> 5.4.0
(cherry picked from commit cfcbe0d16d)
2021-12-26 14:04:22 +00:00
R. Ryantm
21b14239eb sope: 5.3.0 -> 5.4.0
(cherry picked from commit d03e0c1405)
2021-12-26 14:04:22 +00:00
Maciej Krüger
9541cc36e3 Merge pull request #152143 from NixOS/backport-152122-to-release-21.11 2021-12-26 14:26:17 +01:00
Дамјан Георгиевски
570e3c83f2 uwsgi: non-weird postPatch :)
(cherry picked from commit fffd75e23c)
2021-12-26 11:23:39 +00:00
Дамјан Георгиевски
8901477400 uwsgi: fix "Missing arginfo for uwsgi_version()" errors at runtime
https://github.com/unbit/uwsgi/issues/2356
<b>Warning</b>:  Missing arginfo for uwsgi_version() in <b>Unknown</b> on line <b>0</b><br />

(cherry picked from commit 0ebda3cfb8)
2021-12-26 11:23:39 +00:00
Дамјан Георгиевски
1932f6f6e8 uwsgi: the php 8.x library is just libphp.so, not libphp8
patch taken from the archlinux PKGBUILD
dc8835dbc3/trunk/PKGBUILD (L106)

(cherry picked from commit f403517f58)
2021-12-26 11:23:39 +00:00
Дамјан Георгиевски
04c36d136f uwsgi bump version to 2.0.20, compatible with php8
uwsgi 2.0.19.1 fails to compile with php8
https://uwsgi-docs.readthedocs.io/en/latest/Changelog-2.0.20.html

(cherry picked from commit e8ee414455)
2021-12-26 11:23:39 +00:00
Bobby Rong
9cc7fe9290 Merge pull request #152187 from NixOS/backport-152010-to-release-21.11
[Backport release-21.11] warzone2100: 4.2.3 -> 4.2.4, add version test
2021-12-26 14:01:13 +08:00
Francesco Gazzetta
a71711b59b warzone2100: add version test
(cherry picked from commit f7324ddff5)
2021-12-26 05:24:56 +00:00
Francesco Gazzetta
84baf9e990 warzone2100: 4.2.3 -> 4.2.4
(cherry picked from commit b95b332c3d)
2021-12-26 05:24:55 +00:00
Bobby Rong
0a64ebc0a1 Merge pull request #152179 from NixOS/backport-152176-to-release-21.11
[Backport release-21.11] jmeter: 5.4.2 -> 5.4.3
2021-12-26 11:38:10 +08:00
Bryan A. S
2e422b62c9 jmeter: 5.4.2 -> 5.4.3
Update log4j to 2.17.0 (fix CVE-2021-45105)

(cherry picked from commit b3a2f0c036)
2021-12-26 03:35:14 +00:00
Thiago Kenji Okada
3596c5f738 Merge pull request #152148 from NixOS/backport-151658-to-staging-21.11
[Backport staging-21.11] binutils: add patch for CVE-2021-45078
2021-12-25 23:32:54 -03:00
github-actions[bot]
0d553169fd Merge staging-next-21.11 into staging-21.11 2021-12-26 00:11:28 +00:00
github-actions[bot]
ad9ad714c8 Merge release-21.11 into staging-next-21.11 2021-12-26 00:10:53 +00:00
Robert Scott
28d56560d3 gmp5: add patch for CVE-2021-43618
(cherry picked from commit 7ba37884e2)
2021-12-25 22:50:14 +00:00
Robert Scott
44856a6551 gmp: add patch for CVE-2021-43618
(cherry picked from commit d35c79a419)
2021-12-25 22:50:14 +00:00
Robert Scott
b04e5f4d1b binutils: add patch for CVE-2021-45078
(cherry picked from commit bcf076104ac84a190fe11f6a1c3a66aa8e6ebede)
2021-12-25 22:06:06 +00:00
Maciej Krüger
ee5e433591 Merge pull request #152142 from NixOS/backport-152139-to-release-21.11 2021-12-25 22:50:00 +01:00
fortuneteller2k
3a1804a149 linux_xanmod: remove duplicate android kernel options
and enable WINESYNC in kernel config

(cherry picked from commit de06c5e8e8)
2021-12-25 21:49:21 +00:00
zowoq
fa6bb06b03 yt-dlp: 2021.12.1 -> 2021.12.25
https://github.com/yt-dlp/yt-dlp/releases/tag/2021.12.25
(cherry picked from commit 1ffcaf4a73)
2021-12-25 21:48:52 +00:00
Vincent Laporte
f8416fa894 scheherazade-new: 3.200 → 3.300
(cherry picked from commit 59a1e944cda7cca6be4b04455a3d34ce1af1261d)
2021-12-25 21:56:58 +01:00
Thiago Kenji Okada
6979c0e49b Merge pull request #152068 from NixOS/backport-152033-to-release-21.11
[Backport release-21.11] emacs: Add withPgtk argument
2021-12-25 11:50:50 -03:00
Maximilian Bosch
ce2c9b7770 Merge pull request #152076 from NixOS/backport-151792-to-release-21.11
[Backport release-21.11] Kernels 2021-12-22
2021-12-25 12:36:46 +01:00
TredwellGit
eacf3bc803 linux_latest-libre: 18484 -> 18517
(cherry picked from commit 387250dce5)
2021-12-25 10:10:36 +00:00
TredwellGit
1e69f74e67 linux-rt_5_10: 5.10.83-rt58 -> 5.10.87-rt59
(cherry picked from commit 0cb00d51f7)
2021-12-25 10:10:36 +00:00
TredwellGit
40fa8d0d95 linux: 5.4.167 -> 5.4.168
(cherry picked from commit fbd944d91d)
2021-12-25 10:10:36 +00:00
TredwellGit
ef872066bf linux: 5.15.10 -> 5.15.11
(cherry picked from commit fa7b495239)
2021-12-25 10:10:36 +00:00
TredwellGit
43ada01509 linux: 5.10.87 -> 5.10.88
(cherry picked from commit 9b43bf552f)
2021-12-25 10:10:36 +00:00
TredwellGit
ecf8d50e2d linux: 4.9.293 -> 4.9.294
(cherry picked from commit 2ccbef604f)
2021-12-25 10:10:36 +00:00
TredwellGit
fc1ab454a2 linux: 4.4.295 -> 4.4.296
(cherry picked from commit 11486e8377)
2021-12-25 10:10:36 +00:00
TredwellGit
10fd4c8c98 linux: 4.19.221 -> 4.19.222
(cherry picked from commit 545cffb0b5)
2021-12-25 10:10:36 +00:00
TredwellGit
7d20a1a427 linux: 4.14.258 -> 4.14.259
(cherry picked from commit b375970256)
2021-12-25 10:10:36 +00:00
Maximilian Bosch
692c905f58 Merge pull request #150722 from NixOS/backport-147606-to-release-21.11
[Backport release-21.11] udisks2 - 2.8.4 -> 2.9.4
2021-12-25 11:10:28 +01:00
Maximilian Bosch
3dae6fdb81 Merge pull request #151924 from NixOS/backport-151817-to-release-21.11
[Backport release-21.11] matrix-synapse: 1.49.0 -> 1.49.2
2021-12-25 11:08:30 +01:00
Maximilian Bosch
8441b6e946 Merge pull request #151985 from NixOS/backport-151526-to-release-21.11
[Backport release-21.11] tor-browser-bundle-bin: 11.0.2 -> 11.0.3
2021-12-25 11:07:23 +01:00
Maximilian Bosch
b2b0326aa4 Merge pull request #151991 from NixOS/backport-151481-to-release-21.11
[Backport release-21.11] nixos/privacyidea: increase buffer-size of uwsgi from 4096 to 8192
2021-12-25 09:27:28 +01:00
adisbladis
c1abaec45c emacs: Add withPgtk argument
Recently Emacs merged the pgtk branch.

(cherry picked from commit dbc5845320)
2021-12-25 08:06:25 +00:00
github-actions[bot]
7e5abdffdd Merge staging-next-21.11 into staging-21.11 2021-12-25 00:09:53 +00:00
github-actions[bot]
e0afcce58d Merge release-21.11 into staging-next-21.11 2021-12-25 00:09:17 +00:00
Thiago Kenji Okada
4c78062c41 Merge pull request #152019 from NixOS/backport-152002-to-release-21.11
[Backport release-21.11] rnix-lsp: 0.2.1 -> 0.2.3
2021-12-24 20:24:05 -03:00
Maximilian Bosch
7ca7357f88 rnix-lsp: 0.2.1 -> 0.2.3
ChangeLog: https://github.com/nix-community/rnix-lsp/blob/release-0.2.x/CHANGELOG.md#v023---2021-12-24

* Update `rnix` to 0.10.1 for support of new Nix 2.4 language features.
* Fix test-suite on Darwin.

(cherry picked from commit 495123d5d11cbfe12c6bbea5ab0f49ac2cb2bd7d)
2021-12-24 16:14:28 +00:00
markuskowa
d3a3d962c8 Merge pull request #152013 from NixOS/backport-151594-to-release-21.11
[Backport release-21.11] geogebra: 5-0-662-0 -> 5-0-680-0
2021-12-24 17:03:30 +01:00
FliegendeWurst
e68218782a geogebra: 5-0-662-0 -> 5-0-680-0
(cherry picked from commit c080917139)
2021-12-24 15:20:03 +00:00
Artturi
3cf86e98a1 Merge pull request #148546 from NixOS/revert-147715-p/tested-keymap 2021-12-24 16:55:24 +02:00
Maximilian Bosch
ac6b600f22 Merge pull request #151088 from NixOS/backport-151063-to-release-21.11
[Backport release-21.11] graylog: 3.3.15 -> 3.3.16
2021-12-24 15:28:38 +01:00
Vincent Laporte
00f84d37a2 coqPackages.mathcomp-word: init at 1.0
(cherry picked from commit b6b1a7368abf0d6966da6bca4742e6349f831f6a)
2021-12-24 13:59:32 +01:00
markuskowa
0722e9e512 Merge pull request #151999 from NixOS/backport-151988-to-release-21.11
[Backport release-21.11] slurm: 21.08.4.1 -> 21.08.5.1
2021-12-24 12:57:55 +01:00
7c6f434c
e19011ee8f Merge pull request #151996 from NixOS/backport-148367-to-staging-21.11
[Backport staging-21.11] llvmPackages_*.llvm: fix llvm-config-native with static libs
2021-12-24 11:47:27 +00:00
R. Ryantm
76745fac36 slurm: 21.08.4.1 -> 21.08.5.1
(cherry picked from commit eb543d3b02)
2021-12-24 11:16:26 +00:00
Ryan Burns
0263955500 llvmPackages_*.llvm: fix llvm-config-native with static libs
Since both static and shared libs are installed to the same `lib`
output, we override the ActiveLibDir unconditionally.

Fixes `llvm-config-native --link-static --libs`

(cherry picked from commit 544707d6a4)
2021-12-24 10:29:02 +00:00
Maximilian Bosch
470d6239b8 nixos/privacyidea: increase buffer-size of uwsgi from 4096 to 8192
When accessing the Audit log, I get an HTTP 502 when the frontend
requests `/audit` and I get the following error in my `nginx`-log:

    Dec 20 22:12:48 ldap nginx[336]: 2021/12/20 22:12:48 [error] 336#336: *8421 recv() failed (104: Connection reset by peer) while reading response header from upstream, client: 10.237.0.1, server: _, request: "GET /audit/?action=**&action_detail=**&administrator=**&client=**&date=**&duration=**&info=**&page=1&page_size=10&policies=**&privacyidea_server=**&realm=**&resolver=**&serial=**&sortorder=desc&startdate=**&success=**&tokentype=**&user=** HTTP/1.1", upstream: "uwsgi://unix:/run/privacyidea/socket:", host: "ldap.ist.nicht-so.sexy", referrer: "https://ldap.ist.nicht-so.sexy/"

This is because of an "invalid request block size"-error according to
`journalctl -u privacyidea.service`:

    Dec 20 22:12:48 ldap uwsgi[10721]: invalid request block size: 4245 (max 4096)...skip

Increasing the buffer to 8192 fixes the problem for me.

(cherry picked from commit 8f9f754271)
2021-12-24 09:25:33 +00:00
FliegendeWurst
21adc803d6 tor-browser-bundle-bin: 11.0.2 -> 11.0.3
(cherry picked from commit 082cfaaef3)
2021-12-24 08:16:45 +00:00
Vladimír Čunát
0cbeeeec53 Merge #151587: staging-next: 21.11 iteration 4 2021-12-24 08:38:15 +01:00
github-actions[bot]
ec22e2099d Merge staging-next-21.11 into staging-21.11 2021-12-24 00:10:40 +00:00
github-actions[bot]
8d3c61eb76 Merge release-21.11 into staging-next-21.11 2021-12-24 00:09:59 +00:00
Thiago Kenji Okada
503599d052 Merge pull request #151906 from NixOS/backport-151517-to-release-21.11
[Backport release-21.11] firefox: use libvpx instead of libvpx_1_8
2021-12-23 21:00:32 -03:00
R. Ryantm
32bfa38cc9 matrix-synapse: 1.49.0 -> 1.49.2
(cherry picked from commit 1064d4d260)
2021-12-23 23:11:43 +00:00
Artturin
fba3858295 eolie: switch back to normal webkitgtk
i i can't reproduce the issue mentioned in #95559

(cherry picked from commit 1bb3af849a)
2021-12-23 21:34:55 +00:00
Nick Cao
5e6ae2aa93 firefox: use libvpx instead of libvpx_1_8
(cherry picked from commit 038b313075)
2021-12-23 20:08:50 +00:00
Thiago Kenji Okada
64c7e3388b Merge pull request #151888 from NixOS/backport-151384-to-release-21.11
[Backport release-21.11] firefox-unwrapped: 95.0.1 -> 95.0.2
2021-12-23 15:13:27 -03:00
Thiago Kenji Okada
d9f653102a Merge pull request #151487 from NixOS/backport-151331-to-release-21.11
[Backport release-21.11] hedgedoc: 1.9.0 -> 1.9.2
2021-12-23 12:33:56 -03:00
Thiago Kenji Okada
ef5dc194da Merge pull request #151486 from NixOS/backport-151317-to-release-21.11
[Backport release-21.11] wiki-js: 2.5.219 -> 2.5.260
2021-12-23 12:33:28 -03:00
Thiago Kenji Okada
b53c2b8d55 Merge pull request #151485 from NixOS/backport-151322-to-release-21.11
[Backport release-21.11] gotify-cli: 2.2.0 -> 2.2.1
2021-12-23 12:33:09 -03:00
Thiago Kenji Okada
1e44b6b303 Merge pull request #151483 from NixOS/backport-151314-to-release-21.11
[Backport release-21.11] grafana: 8.3.2 -> 8.3.3
2021-12-23 12:32:47 -03:00
Thiago Kenji Okada
3746807930 Merge pull request #151735 from NixOS/backport-150922-to-release-21.11
[Backport release-21.11] nixos/systemd: set TZDIR for PID 1
2021-12-23 12:18:26 -03:00
Thiago Kenji Okada
41ca52df33 Merge pull request #151718 from NixOS/backport-151276-to-release-21.11
[Backport release-21.11] Update nixos-rebuild man page to reflect target-host change
2021-12-23 12:12:53 -03:00
Thiago Kenji Okada
fc09e91019 Merge pull request #151730 from NixOS/backport-151619-to-release-21.11
[Backport release-21.11] webkitgtk: 2.34.1 -> 2.34.3
2021-12-23 12:11:55 -03:00
Thiago Kenji Okada
1cfebd0dc9 Merge pull request #151756 from NixOS/backport-151426-to-release-21.11
[Backport release-21.11] knot-dns: 3.1.4 -> 3.1.5
2021-12-23 12:10:03 -03:00
Thiago Kenji Okada
b542cc4070 Merge pull request #151789 from NixOS/backport-151689-to-release-21.11
[Backport release-21.11] haskell.compiler.ghcjs: Don't use upstream `config.sub`
2021-12-23 12:08:44 -03:00
Thiago Kenji Okada
6e38890909 Merge pull request #151825 from NixOS/backport-151769-to-release-21.11
[Backport release-21.11] signal-desktop: 5.26.0 -> 5.26.1
2021-12-23 11:59:43 -03:00
Thiago Kenji Okada
7c1bbbf4c8 Merge pull request #151827 from NixOS/backport-149761-to-release-21.11
[Backport release-21.11] emacsMacport: 8.2 -> 8.3
2021-12-23 11:59:23 -03:00
R. Ryantm
b41f6c791b firefox-unwrapped: 95.0.1 -> 95.0.2
(cherry picked from commit a233df3bc9)
2021-12-23 14:49:33 +00:00
Thiago Kenji Okada
77b753c3fa Merge pull request #151452 from NixOS/backport-151279-to-release-21.11
[Backport release-21.11] firefox-bin: 95.0 -> 95.0.2
2021-12-23 11:39:54 -03:00
Vincent Laporte
1158f34639 ocamlPackages.batteries: 3.3.0 → 3.4.0
(cherry picked from commit 15d9d0372ee21180aa050be3a775fe848bef99e0)
2021-12-23 13:55:29 +01:00
Michele Guerini Rocco
801ff5e672 Merge pull request #151793 from rnhmjoj/pr-mutt-backport
[21.11] mutt: 2.1.3 -> 2.1.4
2021-12-23 10:34:37 +01:00
Bobby Rong
bf57de8a8e Merge pull request #151859 from NixOS/backport-151852-to-release-21.11
[Backport release-21.11] hydrus: 466 -> 467
2021-12-23 12:54:28 +08:00
Daniel Olsen
f5567b9863 hydrus: 466 -> 467
(cherry picked from commit d41201d708)
2021-12-23 04:42:21 +00:00
Bobby Rong
cc128aa9be Merge pull request #151854 from NixOS/backport-149407-to-release-21.11
[Backport release-21.11] swift: Fix test failure during build
2021-12-23 10:29:01 +08:00
Connor Brewster
fa19398167 Use lib.makeLibraryPath
(cherry picked from commit 9ce1ca6400)
2021-12-23 02:04:44 +00:00
Connor Brewster
074fb9e2a7 swift: Fix libuuid path in LIBRARY_PATH that was causing a test failure
(cherry picked from commit 7ff4e9a588)
2021-12-23 02:04:44 +00:00
github-actions[bot]
aeba94742b Merge staging-next-21.11 into staging-21.11 2021-12-23 00:11:20 +00:00
github-actions[bot]
94ae5ece49 Merge release-21.11 into staging-next-21.11 2021-12-23 00:10:22 +00:00
Vincent Laporte
4b61d56f8d qarte: 4.12.0 → 4.15.1
(cherry picked from commit 34daca300ed34357e03e36025b73b714175c34d4)
2021-12-22 22:08:39 +01:00
Atemu
ce161baf2b emacsMacport: 8.2 -> 8.3
(cherry picked from commit 24198ef746)
2021-12-22 20:50:42 +00:00
Atemu
d95cb32c4c emacsMacport: don't explicitly unpack the tarballs as gzip
tar's -z flag only works for gzip-compressed tarballs. When passed a tarball
compressed with a different compressor (like xz), tar will fail to extract it.

Since tar can auto-detect a compressed tarball and use the appropriate
decompressor itself since forever, this is unecessary now.

(cherry picked from commit a6f973b534)
2021-12-22 20:50:42 +00:00
R. Ryantm
afea693827 signal-desktop: 5.26.0 -> 5.26.1
(cherry picked from commit db68f29fa0)
2021-12-22 20:41:54 +00:00
Vincent Laporte
b28b01e6b6 coqPackages.ITree: enable for Coq 8.14
(cherry picked from commit 1a43a19e595d94d80d7d10c6643d0fc136f231d4)
2021-12-22 20:56:04 +01:00
Vincent Laporte
b2d7785c12 coqPackages.paco: 4.0.2 → 4.1.2
(cherry picked from commit 0d3608631fd5d17023e178d2fc34620f12f062f1)
2021-12-22 20:56:04 +01:00
Sergei Trofimovich
6f8d2731af mutt: 2.1.3 -> 2.1.4
(cherry picked from commit de20b501f4)
2021-12-22 18:30:15 +01:00
Gabriella Gonzalez
e8463f646c haskell.compiler.ghcjs: Don't use upstream config.sub
Before this change the `ghcjs` build fails with:

```
checking host system type... Invalid configuration `js-ghcjs': machine `js-unknown' not recognized
configure: error: …/bin/bash …/configured-ghcjs-src/lib/boot/pkg/unix/config.sub js-ghcjs failed
```

This fails because the `updateAutotoolsGnuConfigScriptsHook` overrides the
`config.sub` in the `unix` boot package to use the newer upstream
version of `config.sub`, but the newer version is incompatible with the
`js-ghcjs` host string used to configure the `unix` package.  The
fix is to undo the override, because the `config.sub` vendored within
`ghc` supports the host string correctly.

(cherry picked from commit 69125bc160)
2021-12-22 17:06:14 +00:00
Tomas Bravo
8d9c1c0ee9 nix-prefetch-git: fix incorrect mktemp usage
(cherry picked from commit d969af836c7d85fc5a7de456425fb6f58a1e49f2)
2021-12-22 17:19:29 +01:00
Vladimír Čunát
267943798d knot-dns: make passthru.tests usable on non-Linux
(cherry picked from commit b1c17320af)
2021-12-22 13:20:42 +00:00
Vladimír Čunát
fdca9124da knot-dns: add knot-resolver build into passthru.tests
(cherry picked from commit c83103e77c)
2021-12-22 13:20:42 +00:00
Vladimír Čunát
eb13450fa3 knot-dns: 3.1.4 -> 3.1.5
https://gitlab.nic.cz/knot/knot-dns/-/tags/v3.1.5
(cherry picked from commit 0fe64c6929)
2021-12-22 13:20:42 +00:00
Bobby Rong
ba447e151c Merge pull request #150540 from NixOS/backport-150527-to-release-21.11
[Backport release-21.11] nixos/nextcloud: update warning for MariaDB >= 10.6
2021-12-22 19:20:51 +08:00
Naïm Favier
3ea5c9e92b nixos/systemd: set TZDIR for PID 1
Fixes #105049

(cherry picked from commit 901d4f13a3)
2021-12-22 10:56:28 +00:00
Bobby Rong
b8b1cceab6 Merge pull request #151438 from NixOS/backport-147024-to-release-21.11
[Backport release-21.11] heisenbridge: 1.7.0 -> 1.7.1
2021-12-22 18:54:17 +08:00
Bobby Rong
669de386eb Merge pull request #150354 from NixOS/backport-149989-to-release-21.11
[Backport release-21.11] papermc: 1.17.1r97 -> 1.17.1r399
2021-12-22 18:44:37 +08:00
Vladimír Čunát
5d7ab00b9c Merge #151402: doc: avoid nix-env -i without -A
...into release-21.11
2021-12-22 11:28:32 +01:00
Philipp
eff0dee5f6 webkitgtk: 2.34.2 -> 2.34.3
(cherry picked from commit f6cd576e45)
2021-12-22 10:21:34 +00:00
R. Ryantm
a0a7812f02 webkitgtk: 2.34.1 -> 2.34.2
(cherry picked from commit e3ebd4e356)
2021-12-22 10:21:34 +00:00
Ben Darwin
d44a01ad3d ocamlPackages.parany: 12.1.1 -> 12.1.2
(cherry picked from commit 18e4576a2da839182e57d9f510097604f1b1bdf5)
2021-12-22 11:02:54 +01:00
Vladimír Čunát
c57a303beb Merge #151723: firefox-(devedition|beta)-bin: 95.0b3 -> 96.0b3
...into release-21.11
2021-12-22 10:35:23 +01:00
teutat3s
37cd72554b firefox-devedition-bin: 95.0b3 -> 96.0b3
(cherry picked from commit 3b5daad286)
2021-12-22 09:34:37 +00:00
teutat3s
92517bc8b2 firefox-beta-bin: 95.0b3 -> 96.0b3
(cherry picked from commit 259625d3a7)
2021-12-22 09:34:37 +00:00
Tom Prince
dd6ce66f8e Move where a couple of existing packages are disabled on python2.
This moves where the package are disabled to `pkgs/top-level/python2-packages.nix`.

(cherry picked from commit 427912ea93)
2021-12-22 01:14:10 -08:00
Tom Prince
ee6f76cb0a Fix some places where python2 packages fail to evaluate.
I unfortunately still depend on some python2 packages. It appears
that these two packages fail to evaluate, in a way that `tryEval`
doesn't catch. This changes them to be explicitly disabled there.

(cherry picked from commit deaec9f289)

This also includes disabling tensorflow-bin_2 which has been removed
from master.
2021-12-22 01:14:10 -08:00
rembo10
d7efe6714b Update nixos-rebuild man page to reflect target-host change
See:
https://github.com/NixOS/nixpkgs/pull/126614
(cherry picked from commit 558375993e156c3c5034368f32ff9fd5c87f5604)
2021-12-22 09:00:21 +00:00
Vincent Laporte
32e6b02de8 ocamlPackages.containers: 3.4 → 3.6.1
(cherry picked from commit 5ff32323d93e2b740f545d182be8d7d3c280abe7)
2021-12-22 09:51:13 +01:00
R. Ryantm
f2e04449c1 dogecoin: 1.14.4 -> 1.14.5
(cherry picked from commit ec3c8d827a)
2021-12-22 05:37:49 +00:00
Olli Helenius
c6d6f46238 dotty: use latest JDK
(cherry picked from commit 2ea18c6aee)
2021-12-22 05:30:23 +00:00
Olli Helenius
b06044be20 scala_2_13: use latest JDK
Java 17 and 18 are supported since 2.13.7:

    https://docs.scala-lang.org/overviews/jdk-compatibility/overview.html

(cherry picked from commit a9ff768b99)
2021-12-22 05:30:23 +00:00
Olli Helenius
336ef24d1b scala_2_12: use latest JDK
Java 17 and 18 are supported since 2.12.15:

    https://docs.scala-lang.org/overviews/jdk-compatibility/overview.html

(cherry picked from commit 7cc95a01de)
2021-12-22 05:30:23 +00:00
github-actions[bot]
16744beecc Merge staging-next-21.11 into staging-21.11 2021-12-22 00:11:20 +00:00
github-actions[bot]
036d307134 Merge release-21.11 into staging-next-21.11 2021-12-22 00:10:42 +00:00
Dmitry Kalinkin
746b1b9d69 Merge pull request #150729 from veprbl/pr/tensorflow_2_4_4
[21.11] python3Packages.tensorflow: 2.4.2 -> 2.4.4
2021-12-21 17:13:28 -05:00
Martin Weinelt
02fbc90fbb openssl_1_1: 1.1.1l -> 1.1.1m
(cherry picked from commit 29f216c48a)
2021-12-21 15:56:14 -05:00
Robert Scott
97f08db6e2 Merge pull request #151610 from NixOS/backport-150762-to-release-21.11
[Backport release-21.11] nomad: 1.1.6 -> 1.1.8, nomad_1_0: 1.0.12 -> 1.0.13
2021-12-21 20:51:34 +00:00
Michele Guerini Rocco
89088960de Merge pull request #151585 from NixOS/backport-151535-to-release-21.11
[Backport release-21.11] nheko: 0.9.0 -> 0.9.1 and dependencies
2021-12-21 21:35:29 +01:00
Robert Scott
ffafec7b6a nomad: 1.1.6 -> 1.1.8
(cherry picked from commit 8068953a63)
2021-12-21 18:25:41 +00:00
Robert Scott
6c3b14f252 nomad_1_0: 1.0.12 -> 1.0.13
(cherry picked from commit 5c5068cb10)
2021-12-21 18:25:41 +00:00
Robert Scott
c386b80f04 Merge pull request #148711 from risicle/ris-pure-ftpd-CVE-2021-40524-r21.11
[21.11] pure-ftpd: add patch for CVE-2021-40524
2021-12-21 18:23:01 +00:00
Thiago Kenji Okada
2a513bab2c Merge pull request #151606 from NixOS/backport-151598-to-release-21.11
[Backport release-21.11] shellhub-agent: 0.8.1 -> 0.8.2
2021-12-21 15:22:12 -03:00
Otavio Salvador
70772360e7 shellhub-agent: 0.8.1 -> 0.8.2
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit 46865ea66f)
2021-12-21 17:42:43 +00:00
Philipp
6e205934b5 nheko: 0.9.0 -> 0.9.1
(cherry picked from commit f1dad29597)
2021-12-21 15:08:12 +00:00
Philipp
e51ed859e9 mtxclient: 0.6.0 -> 0.6.1
(cherry picked from commit 9e623420e7)
2021-12-21 15:08:12 +00:00
Philipp
d570c001e0 coeurl: 0.1.0 -> 0.1.1
(cherry picked from commit ecded07b30)
2021-12-21 15:08:12 +00:00
Michele Guerini Rocco
9ab7d12287 Merge pull request #151516 from NixOS/backport-151418-to-release-21.11
[Backport release-21.11] imv: 4.3.0 -> 4.3.1
2021-12-21 10:09:48 +01:00
Vladimír Čunát
bf80365582 Merge #151521: libjpeg: 2.1.0 -> 2.1.2 into staging-21.11 2021-12-21 09:45:20 +01:00
R. Ryantm
a4a0442656 libjpeg: 2.1.0 -> 2.1.2
(cherry picked from commit 3eca393729)
2021-12-21 08:00:26 +00:00
Emery Hemingway
a36549783f imv: 4.3.0 -> 4.3.1
Package update, split outputs, sources moved to SourceHut.

(cherry picked from commit 8c509d504d)
2021-12-21 07:14:13 +00:00
Bobby Rong
9aeb6f0818 Merge pull request #151495 from NixOS/backport-151493-to-release-21.11
[Backport release-21.11] wingpanel-indicator-ayatana: unstable-2021-12-01 -> unstable-2021-12-18
2021-12-21 10:24:17 +08:00
Bobby Rong
f6c0ce5e4a wingpanel-indicator-ayatana: unstable-2021-12-01 -> unstable-2021-12-18
(cherry picked from commit faa933d4c0)
2021-12-21 02:19:46 +00:00
Bobby Rong
eb2393c095 Merge pull request #151231 from NixOS/backport-150435-to-release-21.11
[Backport release-21.11] psi-plus: add WebP support
2021-12-21 09:11:38 +08:00
Bobby Rong
c6b7bf32bc Merge pull request #151310 from schnusch/remote-touchpad-21.11
remote-touchpad: 1.0.2 -> 1.0.4
2021-12-21 08:55:23 +08:00
Maximilian Bosch
16c8a42423 hedgedoc: 1.9.0 -> 1.9.2
ChangeLogs:
* https://github.com/hedgedoc/hedgedoc/releases/tag/1.9.1
* https://github.com/hedgedoc/hedgedoc/releases/tag/1.9.2

(cherry picked from commit f5c724877e)
2021-12-21 00:40:43 +00:00
Maximilian Bosch
f7df4bb98a wiki-js: 2.5.219 -> 2.5.260
ChangeLogs:
* https://github.com/Requarks/wiki/releases/tag/2.5.254
* https://github.com/Requarks/wiki/releases/tag/2.5.255
* https://github.com/Requarks/wiki/releases/tag/2.5.260

Closes #150400

(cherry picked from commit 8d3a362748)
2021-12-21 00:39:39 +00:00
Maximilian Bosch
fa363472c9 gotify-cli: 2.2.0 -> 2.2.1
Changes: https://github.com/gotify/cli/compare/v2.2.0...v2.2.1
(cherry picked from commit eeea72560c)
2021-12-21 00:38:56 +00:00
Maximilian Bosch
41ca62f25b grafana: 8.3.2 -> 8.3.3
ChangeLog: https://github.com/grafana/grafana/releases/tag/v8.3.3

Note: I had to copy `defaults.ini` from the Git repo rather than from
`srcStatic`. This is because the `srcStatic`-variant missed some config
changes[1] which caused the test to fail like this:

    postgresql # [   24.754735] grafana-start[900]: Failed to start grafana. error: section "tracing.opentelemetry.jaeger" does not exist
    postgresql # [   24.756013] grafana-start[900]: section "tracing.opentelemetry.jaeger" does not exist
    postgresql # [   24.762057] systemd[1]: grafana.service: Main process exited, code=exited, status=1/FAILURE
    postgresql # [   24.765443] systemd[1]: grafana.service: Failed with result 'exit-code'.
    postgresql # [   24.767419] systemd[1]: grafana.service: Consumed 1.598s CPU time, no IP traffic.

[1] d993b12415 (diff-0c326c4f02797b088fc566e64fbfe2162390f52f2fec1483ec3a413a7f11c910)

(cherry picked from commit 8af12f8ebd)
2021-12-21 00:20:32 +00:00
github-actions[bot]
72ac7ea6a6 Merge staging-next-21.11 into staging-21.11 2021-12-21 00:12:47 +00:00
github-actions[bot]
d972ebd109 Merge release-21.11 into staging-next-21.11 2021-12-21 00:10:26 +00:00
Dmitry Kalinkin
406c65c7ae python3Packages.tensorflow: apply an extra patch for protobuf unvendoing 2021-12-20 17:58:05 -05:00
Alexander Tsvyashchenko
3462399bbc python3Packages.tensorflow: switched to Nix-provided protobuf. (#150887)
This prevents conflicts with other Python packages that also use protobuf, see e.g. #150765.

(cherry picked from commit 487bb1b1e2)
2021-12-20 17:58:05 -05:00
taku0
d7868aeb10 firefox-bin: 95.0.1 -> 95.0.2
(cherry picked from commit cd2e8e2949)
2021-12-20 19:47:07 +00:00
taku0
b414cb2729 firefox-bin: 95.0 -> 95.0.1
(cherry picked from commit 3ee12cf528)
2021-12-20 19:47:07 +00:00
Bernardo Meurer
c0ce302c56 Merge pull request #150844 from NixOS/backport-148107-to-release-21.11
[Backport release-21.11] llvmPackages_13.clang: revert D100879 and re-enable jemalloc for firefox
2021-12-20 11:46:16 -08:00
Sander van der Burg
df6791e6e5 Merge pull request #151435 from NixOS/backport-151349-to-release-21.11
[Backport release-21.11] opencbm: init at 0.4.99.103
2021-12-20 19:43:16 +01:00
Sumner Evans
896d266847 heisenbridge: add patch for compatibility with aiohttp 3.8.0
(cherry picked from commit f8fddafe3c)
2021-12-20 18:17:45 +00:00
Sumner Evans
35da605d85 heisenbridge: 1.7.0 -> 1.7.1
(cherry picked from commit cda90888f2)
2021-12-20 18:17:45 +00:00
Sander van der Burg
2691ae78b1 opencbm: init at 0.4.99.103
(cherry picked from commit d7781bebee)
2021-12-20 17:13:45 +00:00
Aaron Andersen
d9e97453eb Merge pull request #151385 from NixOS/backport-151382-to-release-21.11
[Backport release-21.11] kodi.packages.netflix: 1.16.2 -> 1.18.2
2021-12-20 07:34:05 -05:00
Maximilian Bosch
122cf7099b Merge pull request #149954 from NixOS/backport-149725-to-release-21.11
[Backport release-21.11] nvme-cli: 1.15 -> 1.16
2021-12-20 11:08:06 +01:00
Guillaume Girol
fe4cc5eb03 doc: minimize mentions of nix-env -i without -A in nixpkgs manual
(cherry picked from commit a15fbab8e9)
2021-12-20 10:05:48 +00:00
Bobby Rong
86453059bf Merge pull request #150634 from bobby285271/pantheon-stable
[21.11] Pantheon 6.1
2021-12-20 16:32:50 +08:00
Jörg Thalheim
367d7180df Merge pull request #151327 from NixOS/backport-151089-to-release-21.11
[Backport release-21.11] ferdi: 5.6.3 -> 5.6.4
2021-12-20 07:32:27 +00:00
Fabian Affolter
e4f659fee6 Merge pull request #151373 from risicle/ris-flask-appbuilder-3.3.4-21.11
[21.11] python3Packages.flask-appbuilder: 3.3.3 -> 3.3.4
2021-12-20 08:30:37 +01:00
Aaron Andersen
54195f0524 kodi.packages.netflix: 1.16.2 -> 1.18.2
(cherry picked from commit 3063366c4d)
2021-12-20 03:30:06 +00:00
Bobby Rong
dd33d0fa6c pkgs/pantheon: fix typo
(cherry picked from commit 52f2c2500a)
2021-12-20 10:34:30 +08:00
Bobby Rong
d5449c95e9 pantheon.wingpanel: 3.0.1 -> 3.0.2
(cherry picked from commit 42e445f257)
2021-12-20 10:34:30 +08:00
Bobby Rong
60ec6f845a wingpanel-indicator-ayatana: init at unstable-2021-12-01
(cherry picked from commit 7cc11f76af)
2021-12-20 10:34:30 +08:00
Bobby Rong
56155f459d pantheon-tweaks: move to pkgs/desktops/pantheon/third-party
(cherry picked from commit 5afe0ddcf3)
2021-12-20 10:34:29 +08:00
Bobby Rong
2e56a06816 pkgs/pantheon: format
(cherry picked from commit a51958171b)
2021-12-20 10:34:29 +08:00
Bobby Rong
9e84251315 pantheon.wingpanel-indicator-notifications: 6.0.3 -> 6.0.4
(cherry picked from commit 4eca6d89f9)
2021-12-20 10:34:29 +08:00
Bobby Rong
e80a43781d pantheon.elementary-videos: 2.8.0 -> 2.8.1
(cherry picked from commit 70edac040a)
2021-12-20 10:34:28 +08:00
Bobby Rong
bb5589ed42 pantheon.elementary-dock: unstable-2021-11-08 -> unstable-2021-12-08
(cherry picked from commit 29a064842d)
2021-12-20 10:34:28 +08:00
Bobby Rong
8e65c2a935 pantheon.gala: clear indicator background for window switcher
(cherry picked from commit 836e8247fa)
2021-12-20 10:34:28 +08:00
Bobby Rong
d38819c466 pantheon.elementary-terminal: 6.0.0 -> 6.0.1
(cherry picked from commit 46605c6305)
2021-12-20 10:34:27 +08:00
Bobby Rong
3e3f58d81a pantheon.elementary-mail: 6.3.0 -> 6.3.1
(cherry picked from commit 3977638aaa)
2021-12-20 10:34:27 +08:00
Bobby Rong
1ea2e9ad91 pantheon.elementary-tasks: 6.0.4 -> 6.1.0
(cherry picked from commit 7cd7809839)
2021-12-20 10:34:27 +08:00
Bobby Rong
b6ee09b5f5 pantheon.switchboard-plug-onlineaccounts: 6.2.2 -> 6.3.0
(cherry picked from commit 2ce09af75c)
2021-12-20 10:34:27 +08:00
Bobby Rong
d17fc00533 pantheon.elementary-camera: 6.0.2 -> 6.0.3
(cherry picked from commit 3aaf4a1dbb)
2021-12-20 10:34:26 +08:00
Bobby Rong
faad938913 pantheon.elementary-calculator: 1.7.1 -> 1.7.2
(cherry picked from commit 80747a50f1)
2021-12-20 10:34:26 +08:00
Bobby Rong
ce0f0c8915 pantheon.elementary-screenshot: 6.0.1 -> 6.0.2
(cherry picked from commit 2eafe1f468)
2021-12-20 10:34:26 +08:00
Bobby Rong
bbc8e08b6a pantheon.elementary-wallpapers: 6.0.0 -> 6.1.0
(cherry picked from commit cddd16a0a8)
2021-12-20 10:34:25 +08:00
Bobby Rong
bd92e4cb69 Revert "nixos/pantheon: mention latest appcenter changes in manual"
This reverts commit d49d9a24b7.

(cherry picked from commit c65f6852e4)
2021-12-20 10:34:25 +08:00
Bobby Rong
54d0eb8a75 Revert "nixos/pantheon: cleanup FAQ section"
This reverts commit cd58f44937.

(cherry picked from commit 1eef9ae2d1)
2021-12-20 10:34:25 +08:00
Bobby Rong
6649b1dee7 pantheon.appcenter: re-add patch for disable packagekit backend
It makes no sense to wait any longer as the app is totally not working specifically on NixOS.

(cherry picked from commit 3aa4359254)
2021-12-20 10:34:24 +08:00
Bobby Rong
e65902b05d pantheon.evince: use upstream patch
(cherry picked from commit 508d45f8b5)
2021-12-20 10:34:24 +08:00
Bobby Rong
939bf969f6 pantheon.wingpanel-applications-menu: 2.10.1 -> 2.10.2
(cherry picked from commit 7befc2e4ba)
2021-12-20 10:34:24 +08:00
Bobby Rong
5eab35fd4a pantheon.wingpanel-indicator-datetime: 2.3.1 -> 2.4.0
(cherry picked from commit ec371d9365)
2021-12-20 10:34:23 +08:00
Bobby Rong
21e34ce23c pantheon.wingpanel-indicator-notifications: 6.0.2 -> 6.0.3
(cherry picked from commit fd19c43b13)
2021-12-20 10:34:23 +08:00
Bobby Rong
b037e8a64a pantheon.appcenter: 3.9.0 -> 3.9.1
(cherry picked from commit 01bc1d1b62)
2021-12-20 10:34:23 +08:00
Bobby Rong
1fd3d97a45 pantheon.elementary-files: 6.1.0 -> 6.1.1
(cherry picked from commit e2ff3faf03)
2021-12-20 10:34:20 +08:00
github-actions[bot]
66d2a5c98c Merge staging-next-21.11 into staging-21.11 2021-12-20 00:11:10 +00:00
github-actions[bot]
08ee5a49e7 Merge release-21.11 into staging-next-21.11 2021-12-20 00:10:29 +00:00
Martin Weinelt
22e54eed4f Merge pull request #151305 from NixOS/backport-151009-to-release-21.11 2021-12-20 00:20:13 +01:00
Robert Scott
948a3e264a python3Packages.flask-appbuilder: 3.3.3 -> 3.3.4
addressing CVE-2021-41265
2021-12-19 23:10:23 +00:00
adisbladis
1a1ba3cdd5 melpa2nix: Ignore large file warnings
While we haven't encountered any problems related to this in MELPA
it's just a matter of time (this just happened for an ELPA package
(phps-mode)).

(cherry picked from commit 4192dce538)
2021-12-19 13:06:36 -05:00
adisbladis
2962c28d56 emacs: Ignore large file warnings for native compilation
This was blocking building phps-mode with native compilation enabled.

(cherry picked from commit 9a86a53ec5)
2021-12-19 13:06:36 -05:00
Anderson Torres
d29cd70485 Merge pull request #151316 from NixOS/backport-151068-to-release-21.11
[Backport release-21.11] mautrix-whatsapp: 0.2.1 -> 0.2.2
2021-12-19 15:00:41 -03:00
Jörg Thalheim
50e05cb3ba ferdi: 5.6.3 -> 5.6.4
(cherry picked from commit 2a0e5bdfcf)
2021-12-19 15:29:14 +00:00
Charlotte Van Petegem
ba587068ee mautrix-whatsapp: 0.2.1 -> 0.2.2
(cherry picked from commit 2593fe10f7)
2021-12-19 14:58:52 +00:00
schnusch
de8c456021 remote-touchpad: 1.0.2 -> 1.0.4
(cherry picked from commit fbee1459e6)
2021-12-19 15:09:56 +01:00
Vincent Laporte
fa8aa7ff59 ocamlPackages.iter: 1.2.1 → 1.3
(cherry picked from commit 2b38c5c549dd810009b8d1ba7926ca003d001129)
2021-12-19 15:01:29 +01:00
R. Ryantm
b300583943 firefox-esr-91-unwrapped: 91.4.0esr -> 91.4.1esr
(cherry picked from commit 5ae25b97ad)
2021-12-19 12:39:55 +00:00
Mario Rodas
e6377ff355 Merge pull request #151264 from NixOS/backport-148497-to-release-21.11
[Backport release-21.11] python3Packages.capstone: enable for non-x86
2021-12-19 00:24:00 -05:00
Robert Scott
aee882a0d2 python3Packages.capstone: enable for non-x86
(cherry picked from commit 5e58aed938)
2021-12-19 04:56:07 +00:00
Bobby Rong
251df4d855 Merge pull request #149858 from NixOS/backport-149829-to-release-21.11
[Backport release-21.11] vscode, vscodium: 1.62.3 -> 1.63.2
2021-12-19 11:55:23 +08:00
github-actions[bot]
0f4ec0a1b2 Merge staging-next-21.11 into staging-21.11 2021-12-19 00:11:21 +00:00
github-actions[bot]
8ad7b9d871 Merge release-21.11 into staging-next-21.11 2021-12-19 00:10:44 +00:00
Viacheslav Lotsmanov
6639552622 psi-plus: add WebP support
Add “qtimageformats” dependency that provides “libqwebp.so”.

(cherry picked from commit 397bcbe410)
2021-12-18 20:29:12 +00:00
Martin Weinelt
75f3534c98 Merge pull request #151070 from NixOS/backport-151013-to-release-21.11 2021-12-18 21:08:25 +01:00
Markus Kowalewski
52d9b2e0e1 mpich: 3.4.2 -> 3.4.3
(cherry picked from commit 47e354b105)
2021-12-18 19:43:07 +01:00
sternenseemann
8e13e19956 sacc: 1.04 -> 1.05
(cherry picked from commit f13eb927bb)
2021-12-18 19:32:14 +01:00
Mario Rodas
77099e562d Merge pull request #151214 from NixOS/backport-151166-to-release-21.11
[Backport release-21.11] youtube-dl: 2021.06.06 -> 2021.12.17
2021-12-18 11:58:23 -05:00
Mario Rodas
007929b429 Merge pull request #151174 from NixOS/backport-148226-to-release-21.11
[Backport release-21.11] starship: build with notification support
2021-12-18 11:57:59 -05:00
Sandro Jäckel
0a77f83426 youtube-dl: 2021.06.06 -> 2021.12.17
(cherry picked from commit 001c75d537)
2021-12-18 16:26:00 +00:00
Maximilian Bosch
aecab6adbd Merge pull request #151122 from NixOS/backport-149387-to-release-21.11
[Backport release-21.11] matrix-synapse: 1.48.0 -> 1.49.0
2021-12-18 17:19:17 +01:00
Maximilian Bosch
c0d8092843 Merge pull request #151205 from NixOS/backport-150726-to-release-21.11
[Backport release-21.11] Kernels 2021-12-17
2021-12-18 17:17:25 +01:00
Nicolas Benes
0350e81da5 waf: 2.0.22 -> 2.0.23
(cherry picked from commit 228e362c92210d718b98ba7a4a11463f2b237321)
2021-12-18 11:11:14 -05:00
TredwellGit
24d5141fba linux/hardened/patches/5.4: 5.4.164-hardened1 -> 5.4.167-hardened1
(cherry picked from commit 8d4c056723)
2021-12-18 15:16:34 +00:00
TredwellGit
42ef310374 linux/hardened/patches/5.15: 5.15.7-hardened1 -> 5.15.10-hardened1
(cherry picked from commit f51d19746a)
2021-12-18 15:16:34 +00:00
TredwellGit
40e291e868 linux/hardened/patches/5.10: 5.10.84-hardened1 -> 5.10.87-hardened1
(cherry picked from commit a900de3567)
2021-12-18 15:16:34 +00:00
TredwellGit
f445979e1e linux/hardened/patches/4.19: 4.19.220-hardened1 -> 4.19.221-hardened1
(cherry picked from commit 8e317ff982)
2021-12-18 15:16:34 +00:00
TredwellGit
be734aa1cc linux/hardened/patches/4.14: 4.14.257-hardened1 -> 4.14.258-hardened1
(cherry picked from commit d9fdc409d1)
2021-12-18 15:16:34 +00:00
TredwellGit
ec001a8aff linux: 5.4.164 -> 5.4.167
(cherry picked from commit a1470e23da)
2021-12-18 15:16:34 +00:00
TredwellGit
9908529b84 linux: 5.15.7 -> 5.15.10
(cherry picked from commit 8955b58c5e)
2021-12-18 15:16:34 +00:00
TredwellGit
9fc9e423ac linux: 5.10.84 -> 5.10.87
(cherry picked from commit 72b54385a5)
2021-12-18 15:16:34 +00:00
TredwellGit
095c61d149 linux: 4.9.292 -> 4.9.293
(cherry picked from commit 837103a484)
2021-12-18 15:16:34 +00:00
TredwellGit
72166d1378 linux: 4.4.294 -> 4.4.295
(cherry picked from commit 2deb4377d5)
2021-12-18 15:16:34 +00:00
TredwellGit
00d00ce3f1 linux: 4.19.220 -> 4.19.221
(cherry picked from commit 9eacb2bb44)
2021-12-18 15:16:33 +00:00
TredwellGit
f695896127 linux: 4.14.257 -> 4.14.258
(cherry picked from commit 860b4c92b8)
2021-12-18 15:16:33 +00:00
0x4A6F
f0b399ca33 Merge pull request #151179 from NixOS/backport-151145-to-release-21.11
[Backport release-21.11] unifi5: Follow new mitigation guidelines
2021-12-18 16:10:20 +01:00
0x4A6F
dd8838a474 unifi: Disable unsupported options in NixOS tests 2021-12-18 15:20:33 +01:00
Robert Scott
76fdcfe47c Merge pull request #151183 from NixOS/backport-151124-to-release-21.11
[Backport release-21.11] tightvnc: mark as insecure (fixes #150704)
2021-12-18 12:56:57 +00:00
Ingo Blechschmidt
c3c1fe5d2c tightvnc: mark as insecure (fixes #150704)
(cherry picked from commit 034d277c6e)
2021-12-18 12:55:40 +00:00
Bobby Rong
e04acf2c29 Merge pull request #151180 from NixOS/backport-149841-to-release-21.11
[Backport release-21.11] hydrus: 464 -> 466
2021-12-18 20:46:46 +08:00
Daniel Olsen
d00c51336c hydrus: 464 -> 466
(cherry picked from commit 95db526b4d)
2021-12-18 12:10:48 +00:00
Zhaofeng Li
9b61df347c unifi: Add NixOS tests
(cherry picked from commit 8bbae8e558)
2021-12-18 12:05:07 +00:00
Zhaofeng Li
88827f479c unifi5: Follow new mitigation guidelines
Simply disabling lookups isn't enough, and the JndiLookup class must be
removed:

https://web.archive.org/web/20211217085954/https://logging.apache.org/log4j/2.x/security.html
(cherry picked from commit a4bcad541e)
2021-12-18 12:05:06 +00:00
Bobby Rong
30429c472f Merge pull request #151176 from NixOS/backport-150536-to-release-21.11
[Backport release-21.11] fbcat: small refactor, fix fbgrab dependencies
2021-12-18 19:50:23 +08:00
0x4A6F
7ebe799577 Merge pull request #150931 from NixOS/backport-150893-to-release-21.11
[Backport release-21.11] unifi6: 6.5.54 -> 6.5.55
2021-12-18 12:44:31 +01:00
Bobby Rong
058f304d41 Merge pull request #151175 from NixOS/backport-150974-to-release-21.11
[Backport release-21.11] mednaffe: remove gtk2
2021-12-18 19:03:48 +08:00
OPNA2608
797518689d fbcat: small refactor, fix fbgrab dependencies
(cherry picked from commit fa5eb09a66)
2021-12-18 10:52:19 +00:00
Robert Hensing
cc5ddb53e6 Merge pull request #151172 from NixOS/backport-151150-to-release-21.11
[Backport release-21.11] dockerTools.buildImage: Fix incorrect layer unpack order before executing runAsRoot script
2021-12-18 11:46:55 +01:00
Zane van Iperen
1a4ec50e7d mednaffe: remove gtk2
Upstream has removed support for it.

(cherry picked from commit c061809b07fdddd5db20ff789adf95e62f6f947a)
2021-12-18 10:20:08 +00:00
arcnmx
10a3629901 starship: build with notification support
(cherry picked from commit e57ef4569e)
2021-12-18 10:18:55 +00:00
Andrew Brooks
6488267d31 nixos/tests/docker-tools: add test for pre-runAsRoot layer unpack order
(cherry picked from commit 57718902e3)
2021-12-18 10:08:16 +00:00
Andrew Brooks
f75a48ba1b dockerTools.buildImage: unpack base image layers in correct order
(cherry picked from commit 69ffb0004a)
2021-12-18 10:08:16 +00:00
Pavol Rusnak
842f42399c Merge pull request #151170 from NixOS/backport-151160-to-release-21.11
[Backport release-21.11] tor: 0.4.6.8 -> 0.4.6.9
2021-12-18 10:59:42 +01:00
R. Ryantm
cd91413145 tor: 0.4.6.8 -> 0.4.6.9
(cherry picked from commit af2d3a9958)
2021-12-18 09:53:37 +00:00
R. Ryantm
8ec9a3a692 vscodium: 1.63.1 -> 1.63.2
(cherry picked from commit f3bf177c82)
2021-12-18 17:47:03 +08:00
R. Ryantm
de2417de34 vscode: 1.63.1 -> 1.63.2
(cherry picked from commit d06fdce895)
2021-12-18 17:46:56 +08:00
Bobby Rong
057dc63563 Merge pull request #151055 from NixOS/backport-148425-to-release-21.11
[Backport release-21.11] shellhub-agent: 0.7.2 -> 0.8.1
2021-12-18 17:37:21 +08:00
Bobby Rong
2627c4b795 Merge pull request #151091 from NixOS/backport-148736-to-release-21.11
[Backport release-21.11] gnome.gnome-flashback: 3.42.0 → 3.42.1
2021-12-18 10:31:13 +08:00
Bobby Rong
8ff9daebca Merge pull request #151126 from NixOS/backport-151081-to-release-21.11
[Backport release-21.11] gnome.epiphany: 41.0 → 41.2
2021-12-18 10:30:10 +08:00
github-actions[bot]
ba906044ba Merge staging-next-21.11 into staging-21.11 2021-12-18 00:10:31 +00:00
github-actions[bot]
dd28adb5d8 Merge release-21.11 into staging-next-21.11 2021-12-18 00:09:56 +00:00
Linus Heckemann
91cf338a4c Merge pull request #151130 from NixOS/backport-150115-to-release-21.11
[Backport release-21.11] audacity: fix unclean shutdown due to sqlite error
2021-12-18 00:09:30 +01:00
Nikola Knezevic
561bc25fa4 fix: Python 3.10 doesn't need ctypes.util.find_library() patch
This patch is only needed on Python 3.9 version, as it is included in
3.10.0 release.
2021-12-17 23:09:19 +01:00
Jan Tojnar
5c55a03cb3 Remove myself from codeowners 2021-12-17 22:21:41 +01:00
Simon Bruder
9dbc8ecbb7 audacity: fix unclean shutdown due to sqlite error
This applies a patch from upstream[1] that replaces the previously used
method of using the SQLITE_DBPAGE virtual table extension.

This fixes audacity hanging when closing it, which leads to it having to
be killed. That results in incompletely saved project files which
triggers the file recovery dialogue on every start.

Fixes #130347.

[1] https://github.com/audacity/audacity/pull/1802

(cherry picked from commit fed4002ba3)
2021-12-17 21:20:28 +00:00
Bobby Rong
bf817932d6 gnome.epiphany: 41.0 → 41.2
https://gitlab.gnome.org/GNOME/epiphany/-/blob/gnome-41/NEWS
(cherry picked from commit 16595b8841)
2021-12-17 20:52:18 +00:00
Vincent Laporte
c1b30c2b05 ocamlPackages.yaml: enable tests with OCaml ≥ 4.08
(cherry picked from commit 5cfce4fef9a9b4d611e2b5bbde4d6dbd8e791562)
2021-12-17 21:19:59 +01:00
Vincent Laporte
416f9d5b58 ocamlPackages.mdx: 1.11.0 → 1.11.1
(cherry picked from commit 954136fda359b5975f90ac4ce13888fdcadae29f)
2021-12-17 21:19:59 +01:00
Sumner Evans
83ac60cab3 matrix-synapse: 1.48.0 -> 1.49.0
(cherry picked from commit c0a6554847)
2021-12-17 19:55:52 +00:00
Bobby Rong
28abc4e43a Merge pull request #150642 from NixOS/backport-149639-to-release-21.11
[Backport release-21.11] mindustry: 126.1 -> 126.2
2021-12-17 22:53:07 +08:00
Thiago Kenji Okada
89f7275ac5 Merge pull request #151087 from NixOS/backport-151080-to-release-21.11
[Backport release-21.11] jmeter: 5.4.1 -> 5.4.2
2021-12-17 10:23:48 -03:00
Franz Pletz
f59b5f54e9 Merge pull request #151086 from NixOS/backport-150750-to-release-21.11
[Backport release-21.11] mattermost: 5.37.2 -> 5.37.5
2021-12-17 14:17:00 +01:00
Franz Pletz
c4c8d2c420 Merge pull request #151085 from NixOS/backport-151073-to-release-21.11
[Backport release-21.11] kea: 2.0.0 -> 2.0.1
2021-12-17 14:16:34 +01:00
Franz Pletz
49bbe43fcf Merge pull request #151084 from NixOS/backport-150923-to-release-21.11
[Backport release-21.11] zfs: 2.1.1 → 2.1.2
2021-12-17 14:16:14 +01:00
Patrick Chilton
bb3a47dd33 gnome.gnome-flashback: 3.42.0 → 3.42.1
https://ftp.gnome.org/pub/GNOME/sources/gnome-flashback/3.42/gnome-flashback-3.42.1.news
(cherry picked from commit 2fde20d45c)
2021-12-17 13:09:23 +00:00
Thomas Gerbet
abbb56eb4c graylog: 3.3.15 -> 3.3.16
Bump log4j 2 to 2.6.0.
https://www.graylog.org/post/announcing-graylog-v3-3-16

(cherry picked from commit ea5bc4fe75)
2021-12-17 12:51:39 +00:00
Bryan A. S
331dbd2043 jmeter: 5.4.1 -> 5.4.2
fix for CVE-2021-44228

(cherry picked from commit f582f65ad4)
2021-12-17 12:46:02 +00:00
Franz Pletz
6cc8212328 Merge pull request #151047 from NixOS/backport-147807-to-release-21.11
[Backport release-21.11] pythonPackages.tokenizers: fix darwin build
2021-12-17 13:36:37 +01:00
Ryan Mulligan
e3f40a9d1e mattermost: 5.37.2 -> 5.37.5
(cherry picked from commit 2c1902f6aa)
2021-12-17 12:35:40 +00:00
Martin Weinelt
08d709e024 kea: 2.0.0 -> 2.0.1
(cherry picked from commit 084e8834f5)
2021-12-17 12:28:25 +00:00
Andrew Marshall
91d0343529 zfs: 2.1.1 -> 2.1.2
(cherry picked from commit 04ae83ae6b)
2021-12-17 12:27:05 +00:00
Andrew Marshall
bc946968eb zfs: Update repository
zfsonlinux/zfs redirects to openzfs/zfs.

(cherry picked from commit 9339e8e093)
2021-12-17 12:27:05 +00:00
Bobby Rong
fa12c60d17 Merge pull request #151074 from NixOS/backport-145777-to-release-21.11
[Backport release-21.11] flameshot: fix under KDE wayland
2021-12-17 18:56:42 +08:00
oxalica
b99e655194 flameshot: fix under KDE wayland
This is required since KWin relies on absolute paths in `Exec=` to find a process'
corresponding desktop file and check if it's allowed to take screenshot.

(cherry picked from commit fda144875f)
2021-12-17 10:53:36 +00:00
R. Ryantm
e5e977b25e firefox-unwrapped: 95.0 -> 95.0.1
(cherry picked from commit d76ff3c3f1)
2021-12-17 09:37:53 +00:00
github-actions[bot]
2809f818bd [Backport release-21.11] coqPackages.serapi: init at 8.14.0+0.14.0 for Coq 8.14 & OCaml < 4.12 (#150468)
(cherry picked from commit 9ec8e46141)
2021-12-17 10:30:59 +01:00
Bobby Rong
1bb0098a11 Merge pull request #150991 from NixOS/backport-150072-to-release-21.11
[Backport release-21.11] ipfs: 0.10.0 → 0.11.0
2021-12-17 15:40:20 +08:00
Otavio Salvador
fddfed9224 shellhub-agent: 0.7.2 -> 0.8.1
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit 482a9f3776)
2021-12-17 07:09:23 +00:00
Dmitry Kalinkin
5c453d82fc pythonPackages.tokenizers: fix darwin build
(cherry picked from commit bf98858c0f)
2021-12-17 03:41:28 +00:00
github-actions[bot]
717b53d52f Merge staging-next-21.11 into staging-21.11 2021-12-17 00:10:33 +00:00
github-actions[bot]
f85b2603cb Merge release-21.11 into staging-next-21.11 2021-12-17 00:09:53 +00:00
Martin Weinelt
71f906f1cf Merge pull request #150954 from mweinelt/21.11/mediawiki 2021-12-17 01:05:07 +01:00
Martin Weinelt
cf92ba460c Merge pull request #151033 from NixOS/backport-151029-to-release-21.11 2021-12-17 00:55:07 +01:00
Robert Scott
43e48ba7ee Merge pull request #151012 from NixOS/backport-150614-to-release-21.11
[Backport release-21.11] libtoxcore: 0.2.12 -> 0.2.13
2021-12-16 23:36:15 +00:00
Andreas Rammhold
71d967bb4f nixos/snapserver: use the correct bind address arguments
Snapserver expects the arguments `--tcp.bind_to_address` and
`--http.bind_to_address` instead of the `--tcp.address` (and http
equivalent) versions.

This caused the process to listen on `0.0.0.0` (for TCP and HTTP
sockets) regardless of the configuration value. It also never listend on
the IPv6 address `::` as our module system made the user believe.

This commit fixes the above issue and ensures that (at least for the TCP
socket) that our default `::` does indeed allow connections via IPv6
(to localhost aka ::1).

(cherry picked from commit c9c93b0add)
2021-12-16 22:56:57 +00:00
Thiago Kenji Okada
7bab8b5427 Merge pull request #151027 from NixOS/backport-150975-to-release-21.11
[Backport release-21.11] Revert "nixos-rebuild: switch to tmpDir during rebuilds"
2021-12-16 19:42:35 -03:00
Thiago Kenji Okada
169c7173a5 Revert "nixos-rebuild: switch to tmpDir during rebuilds"
This seems to break
`boot.kernelPackages = config.boot.zfs.package.latestCompatibleLinuxPackages`
causing it to use `linuxPackages`.

(cherry picked from commit e6ca3fc976)
2021-12-16 22:19:44 +00:00
Robert Scott
caa487ee7c libtoxcore: 0.2.12 -> 0.2.13
(cherry picked from commit bbf825544e)
2021-12-16 20:13:02 +00:00
Thiago Kenji Okada
e595955c0b Merge pull request #150995 from NixOS/backport-150811-to-release-21.11
[Backport release-21.11] sbt: 1.5.6 -> 1.5.7
2021-12-16 15:40:07 -03:00
sternenseemann
35ed93a957 fcft: install documentation to separate outputs
(cherry picked from commit 6ffc5e7005952e3f20e3641288e49f02f00c187b)
2021-12-16 19:03:48 +01:00
sternenseemann
e1512ce318 fcft: 2.5.0 -> 2.5.1
https://codeberg.org/dnkl/fcft/releases/tag/2.5.1
(cherry picked from commit 1db2304efad218f7746090c209a9eade8d10f6be)
2021-12-16 19:03:48 +01:00
sternenseemann
d5422ba447 s6-man-pages: 2.11.0.0.2 -> 2.11.0.0.5
(cherry picked from commit c68820a676d997cd926e412e940ac0f70661cdfa)
2021-12-16 18:19:19 +01:00
sternenseemann
464e152564 lib.systems.supported: remove aarch64-darwin from Tier 3 list
While it is a fact of life that aarch64-darwin is built on Hydra, it has
never formally been elevated from the Tier 7 state it was originally
assigned in RFC 0046. Since platform Tier status is not only
descriptive, but also normative, a consensus to commit to supporting
aarch64-darwin would need to be reached.

(cherry picked from commit 2d04319d0cba452a2dc00410b2afdbc18ede28b6)
2021-12-16 18:18:26 +01:00
Thiago Kenji Okada
2873e4b0eb Merge pull request #150976 from NixOS/backport-149374-to-release-21.11
[Backport release-21.11] mednaffe: 0.9.1 -> 0.9.2
2021-12-16 14:18:19 -03:00
JesusMtnez
b80d20b6b6 sbt: 1.5.6 -> 1.5.7
(cherry picked from commit 92faf59b44)
2021-12-16 17:17:23 +00:00
Jörg Thalheim
5d35f3e0d3 Merge pull request #150984 from NixOS/backport-150023-to-release-21.11
[Backport release-21.11] opensnitch: fix daemon cant find iptables in PATH
2021-12-16 17:11:14 +00:00
Fabián Heredia Montiel
eefa3b6d4a ipfshttpclient: disable more failing tests
(cherry picked from commit 22fc83bfd6)
2021-12-16 16:55:17 +00:00
Luflosi
b20cb4ee51 ipfshttpclient: disable pubsub tests
(cherry picked from commit 06076c212d)
2021-12-16 16:55:17 +00:00
Fabián Heredia Montiel
e48f61636a ipfs: 0.10.0 → 0.11.0
(cherry picked from commit 57d1c4c92c)
2021-12-16 16:55:17 +00:00
Kim Lindberger
b448fe7d00 Merge pull request #150986 from talyz/elk-backport
[21.11] elk7: 7.11.1 -> 7.16.1, 6.8.3 -> 6.8.21 + add filebeat module and tests
2021-12-16 17:47:44 +01:00
talyz
82ecc368f4 rl-21.11: Note the addition of the filebeat service 2021-12-16 17:23:50 +01:00
talyz
d032da658b elk6: 6.8.3 -> 6.8.21
The latest version includes a fix for CVE-2021-44228.

(cherry picked from commit b617526c2b)
2021-12-16 17:18:05 +01:00
talyz
92b0427c6c python3Packages.parsedmarc.tests: Fix breakage
- Don't use the deprecated elasticsearch7-oss package
- Improve jq query robustness and add tracing

(cherry picked from commit b38f44c8b7)
2021-12-16 17:17:18 +01:00
talyz
65cdf44b89 nixos/filebeat: Add initial module and test
Filebeat is an open source file harvester, mostly used to fetch logs
files and feed them into logstash.

This module can be used instead of journalbeat if used with
`filebeat7` and configured with the `journald` input.

(cherry picked from commit 6c9c2b4734)
2021-12-16 17:17:12 +01:00
Jonas Heinrich
cbed61a3c2 opensnitch: fix daemon cant find iptables in PATH
(cherry picked from commit 4d6cb6b4c8)
2021-12-16 16:17:08 +00:00
Jonas Heinrich
c10f384446 opensnitch: fix daemon cant find iptables in PATH
(cherry picked from commit a05790a5bf)
2021-12-16 16:17:08 +00:00
talyz
bd8496ff4f nixosTests.elk: Improve reliability and compatibility with ELK 7.x
- Use comparisons in jq instead of grepping
- Match for `.hits.total.value` if version >= 7, otherwise it always
  passes
- Make curl fail if requests fails

(cherry picked from commit 9647a429ed)
2021-12-16 17:17:07 +01:00
talyz
386506c268 elk7: 7.11.1 -> 7.16.1
(cherry picked from commit 6c5a533797)
2021-12-16 17:17:01 +01:00
R. Ryantm
f4f67d4efa mednaffe: 0.9.1 -> 0.9.2
(cherry picked from commit fd354779e3)
2021-12-16 15:10:52 +00:00
Joel
6cc6270a4f minecraft-server: 1.18 -> 1.18.1 (#149982)
(cherry picked from commit b835bec4d7)
2021-12-16 15:38:10 +01:00
Robin Townsend
59090dd834 minecraft-server: 1.17.1 -> 1.18
(cherry picked from commit 43ec279d77)
2021-12-16 15:38:09 +01:00
Thiago Kenji Okada
a861e93f76 Merge pull request #150944 from NixOS/backport-148842-to-release-21.11
[Backport release-21.11] openrussian-cli: force lua 5.3
2021-12-16 11:21:30 -03:00
Bobby Rong
4848ec81cd Merge pull request #150971 from NixOS/backport-149814-to-release-21.11
[Backport release-21.11] gnonograms: 1.4.5 -> 2.0.0
2021-12-16 22:18:02 +08:00
Francesco Gazzetta
d7f3bad890 gnonograms: 1.4.5 -> 2.0.0
(cherry picked from commit 2c2e6383a8)
2021-12-16 14:16:07 +00:00
markuskowa
cc7a78b2b8 Merge pull request #150946 from sheepforce/qcelemental
[Backport 21.11] qcelemental: 0.23.0 -> 0.24.0
2021-12-16 14:32:24 +01:00
Phillip Seeber
e0c586a033 qcelemental: disabled pubchem tests (trying network on darwin) 2021-12-16 14:03:11 +01:00
Martin Weinelt
15e9593766 mediawiki: 1.36.2 -> 1.36.3 2021-12-16 11:55:38 +01:00
Vincent Laporte
92c00af3da ocamlPackages.estring: remove broken
(cherry picked from commit ea2f45793d)
2021-12-16 11:33:05 +01:00
Vincent Laporte
2dfa2d76eb ocamlPackages.faillib: remove at 111.17.00
This is a legacy library for OCaml < 4.06

(cherry picked from commit 7aa74d9a13)
2021-12-16 11:33:05 +01:00
Phillip Seeber
982cd1e888 python3.pkgs.qcelemental: 0.23.0 -> 0.24.0
python3.pkgs.qcelemental: whitespace

whitespace

whitespace

qcelemental: checkPhase

(cherry picked from commit 51f4d2d2cd)
2021-12-16 11:04:01 +01:00
Zane van Iperen
6626bc544d openrussian-cli: force lua 5.3
And some cleanups.

(cherry picked from commit 57e7a01eb3)
2021-12-16 10:03:26 +00:00
Zhaofeng Li
cbe7a84cdc unifi6: 6.5.54 -> 6.5.55
(cherry picked from commit b85117304e9ccc0c11088466904eefe7fb9d2821)
2021-12-16 05:46:00 +00:00
Robert Scott
afe3035028 python3Packages.lxml: 4.6.3 -> 4.6.5 2021-12-16 00:37:50 +00:00
github-actions[bot]
017fb54c28 Merge staging-next-21.11 into staging-21.11 2021-12-16 00:10:21 +00:00
John Ericson
6f93bc0658 haskellPackages: regenerate package set based on current config
This commit has been generated by maintainers/scripts/haskell/regenerate-hackage-packages.sh

(cherry picked from commit bbac1b393a0511c3709a2070f9b88d6fba4dfb50)
2021-12-16 00:10:03 +00:00
John Ericson
8538411cf1 haskellPackages.{github,nix-thunk}: Fix
(cherry picked from commit eef30d9132c9dbd68d88999264b3e4bcdd42ae4d)
2021-12-16 00:10:03 +00:00
github-actions[bot]
d5aae03871 Merge release-21.11 into staging-next-21.11 2021-12-16 00:09:40 +00:00
Thiago Kenji Okada
432864f33c Merge pull request #150865 from LeSuisse/21.11-vault-1.8.6
[21.11] vault{,bin}: 1.8.4 -> 1.8.6
2021-12-15 20:34:04 -03:00
Thiago Kenji Okada
221cec1f5a Merge pull request #150892 from NixOS/backport-150874-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 96.0.4664.93 -> 96.0.4664.110
2021-12-15 20:31:27 -03:00
Thiago Kenji Okada
7b42742edb Merge pull request #150909 from NixOS/backport-150872-to-release-21.11
[Backport release-21.11] bitwarden: 1.29.1 -> 1.30.0
2021-12-15 20:29:40 -03:00
Jan Tojnar
560dc1d8e9 Remove myself from maintainers (#150900)
Done with `sed -i -E '/^\s+jtojnar\s*$/d;s/ @?jtojnar//g' (rg ' jtojnar|^\s+jtojnar\s*$' -l -g '!maintainers/maintainer-list.nix')`.
(Always check the `rg` result beforehand to avoid corruption.)
2021-12-15 18:00:55 -05:00
Sebastian Sellmeier
44bfb8116d bitwarden: 1.29.1 -> 1.30.0
(cherry picked from commit 77b099d8f6)
2021-12-15 22:56:03 +00:00
Vladimír Čunát
982457a29a Merge #150890: phpExtensions: skip performance sensitive tests
...into release-21.11
2021-12-15 22:06:22 +01:00
Michael Weiss
a0c873a574 ungoogled-chromium: 96.0.4664.93 -> 96.0.4664.110
(cherry picked from commit af2536fe77)
2021-12-15 20:36:20 +00:00
Konrad Borowski
44ce9a3f62 phpExtensions: skip performance sensitive tests
(cherry picked from commit 0af523ae77)
2021-12-15 20:32:53 +00:00
Michael Weiss
7b079de6ba Merge pull request #150875 from NixOS/backport-150756-to-release-21.11
[Backport release-21.11] signal-desktop: 5.25.1 -> 5.26.0
2021-12-15 21:31:20 +01:00
Michael Weiss
dc2b26bc9b signal-desktop: 5.25.1 -> 5.26.0
(cherry picked from commit f2027d7f7f)
2021-12-15 18:39:50 +00:00
Thomas Gerbet
6c5a24b8f0 [21.11] vault{,bin}: 1.8.4 -> 1.8.6
https://github.com/hashicorp/vault/releases/tag/v1.8.5
https://github.com/hashicorp/vault/releases/tag/v1.8.6
2021-12-15 18:20:33 +01:00
Ryan Mulligan
9367ef512d Merge pull request #150781 from NixOS/backport-149787-to-release-21.11
[Backport release-21.11] python38Packages.cpyparsing: 2.4.7.1.0.0 -> 2.4.7.1.1.0
2021-12-15 08:01:39 -08:00
Thiago Kenji Okada
eb23f6713d Merge pull request #150857 from NixOS/backport-150065-to-release-21.11
[Backport release-21.11] nixos-rebuild: switch to tmpDir during rebuilds
2021-12-15 12:26:21 -03:00
Thiago Kenji Okada
576a9fc463 Merge pull request #150773 from NixOS/backport-150742-to-release-21.11
[Backport release-21.11] xorg.xorgserver: apply CVE patches
2021-12-15 12:22:34 -03:00
Thiago Kenji Okada
88f739b444 nixos-rebuild: switch to tmpDir during rebuilds
This is a workaround for issue #144811 until this issue is either fixed
on nix itself.

(cherry picked from commit f88bd76fcd)
2021-12-15 15:05:49 +00:00
Thiago Kenji Okada
c94176b78d Merge pull request #150848 from thiagokokada/backport-149661-to-release-21.11
[Backport release-21.11] firefox-bin: 94.0.2 -> 95.0
2021-12-15 11:35:33 -03:00
Thiago Kenji Okada
2595eec357 Merge pull request #150845 from NixOS/backport-150816-to-release-21.11
[Backport release-21.11] palemoon: 29.4.2.1 -> 29.4.3
2021-12-15 11:34:52 -03:00
Thiago Kenji Okada
4ce0b95905 Merge pull request #150814 from NixOS/backport-144501-to-staging-21.11
[Backport staging-21.11] openblas: 0.3.17 -> 0.3.18
2021-12-15 11:29:34 -03:00
Bernardo Meurer
9daab44409 firefox-bin: 94.0.2 -> 95.0
(cherry picked from commit e0da0b7c6a)
2021-12-15 11:16:13 -03:00
R. Ryantm
58111f2858 palemoon: 29.4.2.1 -> 29.4.3
(cherry picked from commit 8e84252247)
2021-12-15 13:53:39 +00:00
oxalica
c7b6958702 firefox: re-enable jemalloc
(cherry picked from commit cd44576bff)
2021-12-15 13:49:57 +00:00
oxalica
d4c307aaea llvmPackages_13.clang: revert D100879
The malloc alignment assumption is incorrect for jemalloc and causes
mis-compilation in firefox.

https://reviews.llvm.org/D100879
https://bugzilla.mozilla.org/show_bug.cgi?id=1741454
(cherry picked from commit 754460f861)
2021-12-15 13:49:57 +00:00
Nikolay Amiantov
61aeb6703f youtrack: 2021.1.13597 -> 2021.4.35970
Log4j vulnerability fix, move to JDK 17.

(cherry picked from commit 3b6a6505f1)
2021-12-15 16:42:02 +03:00
Martin Weinelt
6265be549c Merge pull request #150821 from NixOS/backport-150817-to-release-21.11 2021-12-15 12:24:08 +01:00
Martin Weinelt
5dfcb21cc0 openssl_3_0: 3.0.0 -> 3.0.1
(cherry picked from commit 35a11522ba)
2021-12-15 10:25:40 +00:00
R. Ryantm
065d1fad7a openblas: 0.3.17 -> 0.3.18
(cherry picked from commit 39f9fd70e4)
2021-12-15 09:36:25 +00:00
Bobby Rong
fa5624dde4 Merge pull request #149640 from NixOS/backport-149524-to-release-21.11
[Backport release-21.11] psi-plus: 1.5.1576 -> 1.5.1582
2021-12-15 17:00:02 +08:00
Vincent Laporte
42a5675e88 ocamlPackages.pa_ounit: remove at 113.00.00
(cherry picked from commit 0f503310e4d6529fb82e29f5c5eaa669120dab61)
2021-12-15 08:02:23 +01:00
Vincent Laporte
9e86ba2437 ocamlPackages.pa_bench: remove at 113.00.00
This is a legacy package for OCaml ≤ 4.02

(cherry picked from commit 0a63a4bb878759f928a4495a26fc5eebedeb8790)
2021-12-15 08:02:23 +01:00
R. Ryantm
24dd9a82e7 vscodium: 1.63.0 -> 1.63.1
(cherry picked from commit 3558190aa0)
2021-12-15 12:56:36 +08:00
nixpkgs-upkeep-bot
bd7f2de57c vscode: 1.63.0 -> 1.63.1
(cherry picked from commit e21ca17af2)
2021-12-15 12:56:19 +08:00
Artturi
6e0b7f0c7a Merge pull request #148442 from NixOS/backport-145768-to-staging-21.11
[Backport staging-21.11] linux: CONFIG_ASHMEM=y, CONFIG_ANDROID=y
2021-12-15 03:51:22 +02:00
Kevin Cox
546ad56133 Merge pull request #150782 from NixOS/backport-150660-to-release-21.11
[Backport release-21.11] kotlin{-native}: 1.6.0 → 1.6.10
2021-12-14 20:28:09 -05:00
github-actions[bot]
ee8ff1d828 Merge staging-next-21.11 into staging-21.11 2021-12-15 00:10:31 +00:00
github-actions[bot]
545d81faec Merge release-21.11 into staging-next-21.11 2021-12-15 00:09:54 +00:00
adisbladis
b3c227557b Merge pull request #150780 from NixOS/backport-150777-to-release-21.11
[Backport release-21.11] emacs: Use string replacement for gvfs tramp detection rather than a patch
2021-12-15 11:38:40 +12:00
Subhrajyoti Sen
560a45e98c kotlin{-native}: 1.6.0 → 1.6.10
(cherry picked from commit 00d0e55437)
2021-12-14 23:07:00 +00:00
R. Ryantm
dc975b2ac4 python38Packages.cpyparsing: 2.4.7.1.0.0 -> 2.4.7.1.1.0
(cherry picked from commit cf04dbd558)
2021-12-14 23:06:20 +00:00
adisbladis
df2cb91284 emacs: Use string replacement for gvfs tramp detection rather than a patch
The patches are unwieldy to manage, especially with the automated packaging flows in the Emacs overlay.

(cherry picked from commit 4b89ac58bb)
2021-12-14 23:02:56 +00:00
adisbladis
55a8b28339 emacs: Remove unused gvfs patch
(cherry picked from commit 21961650ea)
2021-12-14 23:02:56 +00:00
adisbladis
5d770fa908 Merge pull request #150720 from NixOS/backport-148860-to-release-21.11
[Backport release-21.11] runc: 1.0.2 -> 1.0.3
2021-12-15 10:51:14 +12:00
Vladimír Čunát
fd459cea14 xorg.xorgserver: apply CVE patches
(cherry picked from commit 7101e3e580)
2021-12-14 22:08:34 +00:00
Thiago Kenji Okada
2a9ed54bae Merge pull request #150758 from wamserma/fix-calibre-cve
[21.11] calibre: fix CVE-2021-44686 (security)
2021-12-14 18:06:17 -03:00
adisbladis
1eee62bbda Merge pull request #150608 from collares/backport-148236-to-release-21.11
[Backport release-21.11] emacsPackages.orgPackages: deprecated
2021-12-15 09:05:52 +12:00
Markus S. Wamser
bb15985b4f [21.11] calibre: fix CVE-2021-44686 (security) 2021-12-14 21:35:10 +01:00
Thiago Kenji Okada
8ea89b10ea Merge pull request #150740 from NixOS/backport-150736-to-release-21.11
[Backport release-21.11] gping: add NixOS support patch
2021-12-14 17:26:12 -03:00
Anders Kaseorg
348ba9ec80 openafs: run nixpkgs-fmt
Signed-off-by: Anders Kaseorg <andersk@mit.edu>
(cherry picked from commit 1a3b084c63)
2021-12-14 19:07:02 +00:00
Anders Kaseorg
0fdcf6418a openafs: 1.8.8 → 1.8.8.1
Signed-off-by: Anders Kaseorg <andersk@mit.edu>
(cherry picked from commit 43c93f6131)
2021-12-14 19:07:02 +00:00
Michael Weiss
9486bbd96d Merge pull request #150735 from NixOS/backport-150715-to-release-21.11
[Backport release-21.11] chromium: 96.0.4664.93 -> 96.0.4664.110
2021-12-14 19:02:28 +01:00
Otavio Salvador
6fb2d969d9 gping: add NixOS support patch
This backport a patch made to add NixOS as a supported Operating System
fixing the wrong rendering issues I faced during test.

Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit 4516cecba0)
2021-12-14 17:51:03 +00:00
Michael Weiss
d4d92cc66e chromium: 96.0.4664.93 -> 96.0.4664.110
https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html

This update includes 5 security fixes. Google is aware of reports that
an exploit for CVE-2021-4102 exists in the wild.

CVEs:
CVE-2021-4098 CVE-2021-4099 CVE-2021-4100 CVE-2021-4101 CVE-2021-4102

(cherry picked from commit 9528f0d87e)
2021-12-14 17:16:17 +00:00
Dmitry Kalinkin
e279392431 python3Packages.tensorflow: 2.4.2 -> 2.4.4 2021-12-14 11:49:17 -05:00
Kaushal M
37dc8abc0f udisks2 - 2.8.4 -> 2.9.4
Update to a version that supports the ntfs3 kernel module.

(cherry picked from commit 5750281892)
2021-12-14 14:45:55 +00:00
zowoq
f88342cb01 runc: 1.0.2 -> 1.0.3
https://github.com/opencontainers/runc/releases/tag/v1.0.3
(cherry picked from commit db70d35c839e1cd4c1e59e6a1db3cb91c88c0632)
2021-12-14 14:42:02 +00:00
7c6f434c
ce635e9dca Merge pull request #150650 from NixOS/backport-150610-to-release-21.11
[Backport release-21.11] apache-jena: 4.2.0 -> 4.3.1; apache-jena-fuseki: 4.2.0 -> 4.3.1
2021-12-14 13:33:09 +00:00
Kim Lindberger
67edf411ca Merge pull request #150653 from NixOS/backport-150553-to-release-21.11
[Backport release-21.11] keycloak: 15.0.2 -> 15.1.0
2021-12-14 10:59:25 +01:00
talyz
17b36ae877 keycloak: 15.0.2 -> 15.1.0
(cherry picked from commit b94a1f842a)
2021-12-14 09:30:52 +00:00
Joerie de Gram
794c4847d2 apache-jena: 4.2.0 -> 4.3.1; apache-jena-fuseki: 4.2.0 -> 4.3.1
Fixes CVE-2021-44228. See #150288.

(cherry picked from commit d2d9d4c862)
2021-12-14 09:01:40 +00:00
Maximilian Huber
da1aa87572 mindustry: 126.1 -> 126.2
Signed-off-by: Maximilian Huber <gh@maxhbr.de>
(cherry picked from commit 18914a9355)
2021-12-14 07:00:52 +00:00
Bobby Rong
d2f47b7dcd Merge pull request #150619 from NixOS/backport-149946-to-release-21.11
[Backport release-21.11] latte-dock: 0.10.0 -> 0.10.4
2021-12-14 09:01:49 +08:00
leo60228
45d245bf82 latte-dock: 0.10.0 -> 0.10.4
(cherry picked from commit 8713ef19486f88cd82c6860a72fc98ad9a136ae0)
2021-12-14 00:34:13 +00:00
Robert Scott
c2c8529b45 Merge pull request #150161 from risicle/ris-mahotas-freeimage-r21.11
[21.11] python3Packages.mahotas: fix freeimage support
2021-12-14 00:23:42 +00:00
github-actions[bot]
4ef54c9d1c Merge staging-next-21.11 into staging-21.11 2021-12-14 00:10:55 +00:00
github-actions[bot]
c90e993eef Merge release-21.11 into staging-next-21.11 2021-12-14 00:10:18 +00:00
Thiago Kenji Okada
c52fe20e10 Merge pull request #150599 from NixOS/backport-150507-to-release-21.11
[Backport release-21.11] emacs: Add sqlite support introduced in Emacs 29
2021-12-13 21:01:10 -03:00
Vonfry
aa673c5194 emacsPackages.orgPackages: deprecated
org elpa is deprecated and moved into gnu elpa and nongnu elpa.

link: nix-community/emacs-overlay#191
(cherry picked from commit 932ab304f0)
2021-12-13 20:05:42 -03:00
Brian Leung
e64ab9c980 emacs: Add sqlite support introduced in Emacs 29
(cherry picked from commit 7c8fae3b8b)
2021-12-13 21:30:49 +00:00
Maximilian Bosch
7d5ec2a2b4 Merge pull request #150523 from Ma27/signald-cve-2021-44228-21.11
[21.11] signald: incorporate log4j update for CVE-2021-44228
2021-12-13 22:26:40 +01:00
0x4A6F
ada144e74f Merge pull request #150594 from NixOS/backport-150511-to-release-21.11
[Backport release-21.11] graylog: 3.3.14 -> 3.3.15
2021-12-13 22:16:16 +01:00
Thomas Gerbet
05f265d22a graylog: 3.3.14 -> 3.3.15
This release included a fix for the Log4j vulnerability.
https://www.graylog.org/post/graylog-update-for-log4j

(cherry picked from commit 6dd67c31d2)
2021-12-13 20:38:18 +00:00
Robert Scott
a898a9d1f0 Merge pull request #150406 from NixOS/backport-150289-to-release-21.11
[Backport release-21.11] zap: 2.11.0 -> 2.11.1
2021-12-13 20:25:45 +00:00
Robert Scott
a116a0c187 Merge pull request #150310 from xfix/metabase-for-21.11
[21.11] metabase: 0.38.0 -> 0.38.6
2021-12-13 20:05:21 +00:00
sternenseemann
91b1b0ada3 foot: 1.10.2 -> 1.10.3
https://codeberg.org/dnkl/foot/releases/tag/1.10.3
(cherry picked from commit 3c855f2fd4)
2021-12-13 20:12:49 +01:00
Franz Pletz
66b41fd8da Merge pull request #150582 from NixOS/backport-150550-to-release-21.11
[Backport release-21.11] olm: 3.2.6 -> 3.2.8
2021-12-13 19:52:26 +01:00
Franz Pletz
efa903ef36 Merge pull request #150578 from NixOS/backport-150558-to-release-21.11
[Backport release-21.11] element-*: 1.9.6 -> 1.9.7
2021-12-13 19:26:02 +01:00
Franz Pletz
91d280fca1 Merge pull request #150581 from NixOS/backport-150562-to-release-21.11
[Backport release-21.11] schildichat: 1.9.0-sc.1 -> 1.9.7-sc.1
2021-12-13 19:15:58 +01:00
Alvar Penning
27893bd8bf olm: 3.2.6 -> 3.2.8
This security release fixes a "high severity issue" that has not yet
been further described.

https://matrix.org/blog/2021/12/03/pre-disclosure-upcoming-security-release-of-libolm-and-matrix-js-sdk
(cherry picked from commit 74ca17a777)
2021-12-13 18:13:04 +00:00
Yureka
e0cb1d3199 schildichat: 1.9.0-sc.1 -> 1.9.7-sc.1
(cherry picked from commit 127a5753d3)
2021-12-13 18:11:35 +00:00
Philipp
4b0c83f02f element-*: 1.9.6 -> 1.9.7
(cherry picked from commit 691111d99f)
2021-12-13 18:00:42 +00:00
Justinas Stankevicius
f31ae3355a gnomeExtensions.freon: 44 -> 45, patch binary paths
(cherry picked from commit 702dfffa06)

Reason: adds compatibility w/ GNOME 41 (default in 21.11)
and lessens the reliance on globally installed packages.
2021-12-13 17:19:04 +02:00
Malte
900b69e7e9 nixos/nextcloud: update warning for MariaDB >= 10.6
(cherry picked from commit 7c43256291)
2021-12-13 14:25:17 +00:00
Vincent Laporte
c95b2e9952 jackline: use default version of OCaml
(cherry picked from commit a106f705050b5ecbc70d2e1d753429efa9db8198)
2021-12-13 13:47:51 +01:00
Maximilian Bosch
6e7ff9d338 signald: incorporate log4j update for CVE-2021-44228
Equivalent to 79ab6a8382 on `master`, but
against 0.14.1.

Relevant for #150288
2021-12-13 13:15:15 +01:00
Janne Heß
24e95b0052 Merge pull request #150425 from pennae/backport-150329-to-release-21.11 2021-12-13 12:06:11 +01:00
Felix Buehler
675049c5c1 why3.withProvers: add dontUnpack
(cherry picked from commit 6e0bc1f976829203e37cd35205b9ff58341c619d)
2021-12-13 10:51:07 +01:00
Yestin L. Harrison
53563b81ea camlp4: add new versions
(cherry picked from commit f389b36d2681b6b06508de8e26ca5dfee88aed55)
2021-12-13 09:22:12 +01:00
Zhaofeng Li
5bbf1ed271 nixos/unifi: Apply log4j2 mitigation
(cherry picked from commit e992604bf0)
2021-12-13 03:37:30 +01:00
Zhaofeng Li
b3213c1520 unifi6: 6.4.54 -> 6.5.54
(cherry picked from commit 48feb21a3c)
2021-12-13 03:37:12 +01:00
github-actions[bot]
5a9a0b1e33 Merge staging-next-21.11 into staging-21.11 2021-12-13 00:10:37 +00:00
github-actions[bot]
3303bbc199 Merge release-21.11 into staging-next-21.11 2021-12-13 00:09:48 +00:00
Thiago Kenji Okada
1c79570a96 Merge pull request #150442 from NixOS/backport-150413-to-release-21.11
[Backport release-21.11] shattered-pixel-dungeon: 1.0.0 -> 1.1.0
2021-12-12 19:01:28 -03:00
Thiago Kenji Okada
ad09cd37bd Merge pull request #150462 from NixOS/backport-150276-to-release-21.11
[Backport release-21.11] drogon: 1.7.3 -> 1.7.4
2021-12-12 17:18:37 -03:00
Maximilian Bosch
1b70776645 Merge pull request #150465 from NixOS/backport-149620-to-release-21.11
[Backport release-21.11] Kernels 2021-12-08
2021-12-12 21:03:58 +01:00
Guillaume Girol
ea8d9c2fad Merge pull request #149896 from symphorien/ocaml-lsp-ocaml-4.13
[21.11] ocamlPackages.jsonrpc: 1.8.3 → 1.9
2021-12-12 19:50:25 +00:00
TredwellGit
4c8d68d29e linux/hardened/patches/5.4: 5.4.163-hardened1 -> 5.4.164-hardened1
(cherry picked from commit dc7d9307ae)
2021-12-12 19:24:55 +00:00
TredwellGit
a307b6fe91 linux/hardened/patches/5.15: 5.15.6-hardened1 -> 5.15.7-hardened1
(cherry picked from commit 935a3eb77b)
2021-12-12 19:24:55 +00:00
TredwellGit
e2f055c0a1 linux/hardened/patches/5.10: 5.10.83-hardened1 -> 5.10.84-hardened1
(cherry picked from commit 4e28ad8780)
2021-12-12 19:24:55 +00:00
TredwellGit
35ca10626f linux/hardened/patches/4.19: 4.19.219-hardened1 -> 4.19.220-hardened1
(cherry picked from commit ac0487fe56)
2021-12-12 19:24:55 +00:00
TredwellGit
4d665fbf8d linux/hardened/patches/4.14: 4.14.256-hardened1 -> 4.14.257-hardened1
(cherry picked from commit 8448ac947f)
2021-12-12 19:24:55 +00:00
TredwellGit
58b3bb11a2 linux-rt_5_4: 5.4.161-rt66 -> 5.4.161-rt67
(cherry picked from commit 7f32450344)
2021-12-12 19:24:55 +00:00
TredwellGit
9be9b32331 linux-rt_5_10: 5.10.78-rt56 -> 5.10.83-rt58
(cherry picked from commit 7952853749)
2021-12-12 19:24:55 +00:00
TredwellGit
68adac5060 linux: 5.4.163 -> 5.4.164
(cherry picked from commit 21de99d456)
2021-12-12 19:24:55 +00:00
TredwellGit
742060322a linux: 5.15.6 -> 5.15.7
(cherry picked from commit 935be58f5c)
2021-12-12 19:24:54 +00:00
TredwellGit
db90044540 linux: 5.10.83 -> 5.10.84
(cherry picked from commit 2e7590e84f)
2021-12-12 19:24:54 +00:00
TredwellGit
e48e3aa01f linux: 4.9.291 -> 4.9.292
(cherry picked from commit ad844d0a89)
2021-12-12 19:24:54 +00:00
TredwellGit
b213dfeb92 linux: 4.4.293 -> 4.4.294
(cherry picked from commit 0d0bc6032d)
2021-12-12 19:24:54 +00:00
TredwellGit
7eb16fb32c linux: 4.19.219 -> 4.19.220
(cherry picked from commit 8a9c48a65d)
2021-12-12 19:24:54 +00:00
TredwellGit
5bc7fa5ba3 linux: 4.14.256 -> 4.14.257
(cherry picked from commit 9cc83854e0)
2021-12-12 19:24:54 +00:00
Maximilian Bosch
f7a3276ced Merge pull request #149489 from NixOS/backport-147446-to-release-21.11
[Backport release-21.11] Kernels 2021-12-01
2021-12-12 20:19:41 +01:00
Maximilian Bosch
968685e51f Merge pull request #150452 from NixOS/backport-150410-to-release-21.11
[Backport release-21.11] grafana: 8.3.1 -> 8.3.2, fix CVE-2021-43813, CVE-2021-43815
2021-12-12 20:12:51 +01:00
urlordjames
cb4da6be75 drogon: 1.7.3 -> 1.7.4
(cherry picked from commit f9610acae1)
2021-12-12 18:51:53 +00:00
Artturi
a14b2f2639 Merge pull request #150459 from NixOS/backport-149929-to-release-21.11 2021-12-12 20:40:16 +02:00
OPNA2608
27f6dfc57e libsidplayfp: fix tests on x86_64-darwin
(cherry picked from commit 875ea5d71b)
2021-12-12 18:18:35 +00:00
Maximilian Bosch
3e5475fb7f grafana: 8.3.1 -> 8.3.2, fix CVE-2021-43813, CVE-2021-43815
ChangeLog: https://github.com/grafana/grafana/releases/tag/v8.3.2
(cherry picked from commit 3c8f6c5407)
2021-12-12 16:58:29 +00:00
Francesco Gazzetta
d46f6e0b28 shattered-pixel-dungeon: 1.0.0 -> 1.1.0
(cherry picked from commit 4c764d4dbf)
2021-12-12 15:22:06 +00:00
Joerie de Gram
d7e0ee3b3a zap: 2.11.0 -> 2.11.1
Fixes CVE-2021-44228 #150288

(cherry picked from commit be4883e218)
2021-12-12 11:50:35 +00:00
Vladimír Čunát
32e954df31 Merge #149835: thunderbird: 91.3.2 -> 91.4.0 (into release-21.11) 2021-12-12 09:40:32 +01:00
TredwellGit
d67a4bad86 libreoffice-fresh: 7.2.3.2 -> 7.2.4.1
(cherry picked from commit 9c36e9cb9a)
2021-12-12 05:59:34 +00:00
TredwellGit
25783a67f2 libreoffice-still: 7.1.7.2 -> 7.1.8.1
(cherry picked from commit 9cd228f3e3)
2021-12-12 05:58:50 +00:00
Mario Rodas
eaae0d3e83 Merge pull request #150348 from NixOS/backport-150145-to-release-21.11
[Backport release-21.11] fluentd: 1.7.0 -> 1.14.3
2021-12-11 20:55:13 -05:00
Aaron Janse
01299d235b Update pkgs/games/papermc/default.nix
Co-authored-by: Joel <jyooru+github@protonmail.ch>
(cherry picked from commit 53d7554d151c54489175fedca7f45a85d72ee59f)
2021-12-12 01:46:57 +00:00
Aaron Janse
c53981f935 Update pkgs/games/papermc/default.nix
Co-authored-by: Joel <jyooru+github@protonmail.ch>
(cherry picked from commit 86f325b117bcc45d44f05a5a4da89c2d03bb41c4)
2021-12-12 01:46:57 +00:00
Aaron Janse
2f6c77b730 papermc: 1.17.1r97 -> 1.17.1r399
(cherry picked from commit f994bbb83f3d2fe3053b9bd16f25689b76e9356f)
2021-12-12 01:46:57 +00:00
Robert Scott
73411b0002 fluentd: 1.7.0 -> 1.14.3
(cherry picked from commit 2abba831e3)
2021-12-12 01:06:25 +00:00
github-actions[bot]
6eb08df677 Merge staging-next-21.11 into staging-21.11 2021-12-12 00:11:03 +00:00
github-actions[bot]
06d299853c Merge release-21.11 into staging-next-21.11 2021-12-12 00:10:27 +00:00
Konrad Borowski
c5cece7d8b metabase: add passthru tests
(cherry picked from commit 9eee84f9f0)
2021-12-11 22:44:37 +01:00
Konrad Borowski
5467131758 metabase: 0.38.0 -> 0.38.6 2021-12-11 22:43:17 +01:00
Guillaume Girol
b9a9a7bb96 Merge pull request #150304 from NixOS/backport-148696-to-release-21.11
[Backport release-21.11] Fix the syntax error on tt-rss config file
2021-12-11 21:39:56 +00:00
Pavol Rusnak
688e40a988 Merge pull request #150301 from NixOS/backport-150293-to-release-21.11
[Backport release-21.11] qt515.qtwebkit: fix build on darwin
2021-12-11 22:28:39 +01:00
Martin Weinelt
e372f86e2e Merge pull request #149568 from NixOS/staging-next-21.11 2021-12-11 22:19:56 +01:00
Mats Rauhala
0f97e2110f tt-rss-module handle situations without any password
(cherry picked from commit 0eaecd60cb)
2021-12-11 21:01:11 +00:00
Mats Rauhala
bb9c1df41a Fix the syntax error on tt-rss config file
(cherry picked from commit de16da59f2)
2021-12-11 21:01:11 +00:00
Pavol Rusnak
8c77a32d11 qt515.qtwebkit: fix build on darwin
This fixes the build on darwin by correcting the patch which no longer applies.

(cherry picked from commit 1bc0716555)
2021-12-11 20:47:12 +00:00
Maximilian Bosch
72121eb172 Merge pull request #149719 from NixOS/backport-149153-to-staging-21.11
[Backport staging-21.11] systemd: 249.5 -> 249.7 & various fixes
2021-12-11 20:20:26 +01:00
Jonathan Ringer
7796065f51 libbass: disable until upstream provides stable urls
(cherry picked from commit 7e8f4423a8)
2021-12-11 10:08:36 -08:00
Maximilian Bosch
0ae823e633 Merge pull request #150273 from NixOS/backport-149606-to-release-21.11
[Backport release-21.11] tor-browser-bundle-bin: 11.0 -> 11.0.2
2021-12-11 18:14:34 +01:00
elsirion
bd6c2298c1 tor-browser-bundle-bin: 11.0 -> 11.0.2
(cherry picked from commit 6b2221bdf2)
2021-12-11 16:44:01 +00:00
Michael Weiss
2e8bc435ab Merge pull request #150238 from NixOS/backport-150148-to-release-21.11
[Backport release-21.11] signal-desktop: 5.25.0 -> 5.25.1
2021-12-11 14:28:41 +01:00
Michael Weiss
bd57376e3b signal-desktop: 5.25.0 -> 5.25.1
(cherry picked from commit 87a51f78e4)
2021-12-11 12:40:16 +00:00
Jörg Thalheim
453bcb8380 Merge pull request #150211 from Mic92/ghidra-backport
[21.11] ghidra: 10.0 -> 10.1 (security)
2021-12-11 09:08:05 +00:00
Joerie de Gram
7cbdb8642e ghidra: 10.0.4 -> 10.1
Fixes CVE-2021-44228 (Apache Log4j JNDI RCE). Closes #150153.

(cherry picked from commit 89206c507e)
2021-12-11 09:56:36 +01:00
Benjamin Asbach
c892823afa ghidra: 10.0 -> 10.0.4
(cherry picked from commit e0db47bd82)
2021-12-11 09:56:32 +01:00
Bobby Rong
1ab2e8edfc Merge pull request #150184 from NixOS/backport-150152-to-release-21.11
[Backport release-21.11] fswebcam: fix src url
2021-12-11 12:27:36 +08:00
Artturi
4d9294ffa9 Merge pull request #150183 from NixOS/backport-150149-to-release-21.11
[Backport release-21.11] virt-manager: fix wmclass
2021-12-11 06:08:04 +02:00
R. Ryantm
6dcf45f675 fswebcam: fix src url
(cherry picked from commit 19a86aab13)
2021-12-11 04:05:38 +00:00
Joerie de Gram
211c29e090 virt-manager: fix wmclass
Use `dontWrapGApps` to prevent double wrapping from breaking wmclass

Fixes #150120

(cherry picked from commit 056f498ccf)
2021-12-11 03:40:53 +00:00
Maximilian Bosch
554a1d40f9 Merge pull request #150035 from NixOS/backport-149091-to-release-21.11
[Backport release-21.11] element-{web,desktop}: 1.9.5 -> 1.9.6
2021-12-11 02:29:51 +01:00
Robert Scott
167ce06eaa python3Packages.mahotas: fix freeimage support
use a much stronger binding to our specific freeimage that
works reliably on linux. previously it didn't and the tests
covering freeimage support were just being skipped as they
assumed it to be disabled.

once the binding works it reveals slight breakage in the tests
themselves, mostly fixed with an upstream patch (skipping
one remaining breakage). these breakages were already
revealing themselves on darwin as the freeimage binding was
"working" there.

(cherry picked from c81cf6a242 with
modifications)
2021-12-11 00:20:54 +00:00
github-actions[bot]
9eeff7536c Merge staging-next-21.11 into staging-21.11 2021-12-11 00:10:45 +00:00
github-actions[bot]
b6a0557423 Merge release-21.11 into staging-next-21.11 2021-12-11 00:10:10 +00:00
Martin Weinelt
b5f75cbc8d Merge pull request #150155 from NixOS/backport-150106-to-release-21.11 2021-12-11 00:26:50 +01:00
Guillaume Girol
22b172114b Merge pull request #150134 from NixOS/backport-149478-to-release-21.11
[Backport release-21.11] micromamba: fix libyamlcpp dependency
2021-12-10 23:23:14 +00:00
Jonathan Ringer
07c7371efe python3Packages.ansible-lint: limit xdist cores to NIX_BUILD_CORES
(cherry picked from commit e3bb91c48b)
2021-12-10 23:21:20 +00:00
Pavol Rusnak
ee86a9620a Merge pull request #150137 from prusnak/trezor-suite
trezor-suite: 21.10.2 -> 21.12.2
2021-12-10 22:32:58 +01:00
Pavol Rusnak
bcd928571e trezor-suite: 21.11.2 -> 21.12.2
(cherry picked from commit 389c60770a)
2021-12-10 22:30:50 +01:00
TredwellGit
6448134cef trezor-suite: 21.10.2 -> 21.11.2
https://github.com/trezor/trezor-suite/releases/tag/v21.11.1
https://github.com/trezor/trezor-suite/releases/tag/v21.11.2
(cherry picked from commit 0dd351d423)
2021-12-10 22:30:21 +01:00
Pavol Rusnak
373dc80e04 Merge pull request #150126 from rnhmjoj/pr-monero-back
monero{,-gui}: 0.17.2.3 -> 0.17.3.0
2021-12-10 22:22:15 +01:00
Mauricio Scheffer
d876268460 micromamba: fix libyamlcpp dependency
(cherry picked from commit 8c595361d1)
2021-12-10 21:18:06 +00:00
rnhmjoj
c8afa48af7 monero{,-gui}: 0.17.2.3 -> 0.17.3.0 2021-12-10 19:41:30 +01:00
Martin Weinelt
573095944e python3Packages.ansible-base: 2.10.15 -> 2.10.16
(cherry picked from commit bdcef51650)
2021-12-10 10:33:46 -08:00
Martin Weinelt
aa6cc5f022 python3Packages.ansible-core: 2.12.0 -> 2.12.1
(cherry picked from commit 18354eb210)
2021-12-10 10:33:46 -08:00
Rasmus Précenth
cf8f41fe11 sbt: 1.5.5 -> 1.5.6
CVE-2021-44228: https://github.com/apache/logging-log4j2/pull/608
(cherry picked from commit 819b6d1c0e37575c40e4ff8c46d2f5ba7478d7ac)
2021-12-10 11:24:28 -05:00
Sumner Evans
24702d103a element-{web,desktop}: 1.9.5 -> 1.9.6
(cherry picked from commit 6f0fb4fe8e)
2021-12-10 11:06:16 +00:00
Mikael Voss
6e7d040cf2 modules/nix-daemon: Amend daemon(CPU|IO)Sched(Policy|Class) description
Suggest appropriate values for various types of systems and add some
formatting.

(cherry picked from commit 8c654134d6c9f177fcf78b8fdcad2e8c06c13e73)
2021-12-10 10:34:54 +00:00
github-actions[bot]
4e674086d9 nixos/networkd: add RoutingPolicyRule Type option (#149304)
(cherry picked from commit 9fa4e4ba07c97532c9c9ba15be1621b4e164ede3)

Co-authored-by: Yureka <yuka@yuka.dev>
2021-12-10 11:28:36 +01:00
github-actions[bot]
19a7514207 nixos/jitsi-videobridge: Mitigate CVE-2021-44228 (#150027)
This commit mitigates a remote code execution vulnerability in the log4j
library.

(cherry picked from commit 4925948fa1df80814700f45bfadfe64715e71332)

Co-authored-by: Lara <lara@uwu.is>
2021-12-10 11:28:05 +01:00
Vincent Laporte
8d5704dc12 proverif: 2.03 → 2.04
(cherry picked from commit cc61ed1f5d8f0d56eee5684a8d11b475606065ca)
2021-12-10 09:39:41 +01:00
R. Ryantm
9ce2035e4d librsvg: 2.52.3 -> 2.52.4
(cherry picked from commit c6c167d6a1fe83c14d8d0435b739fe71a92b5c2d)
2021-12-09 21:42:44 -08:00
Artturi
e1565dd80e Merge pull request #149644 from NixOS/backport-149604-to-release-21.11 2021-12-10 04:32:27 +02:00
Artturi
d9f03ab6d2 Merge pull request #148563 from NixOS/backport-148384-to-release-21.11 2021-12-10 04:31:08 +02:00
Artturi
51730052e2 Merge pull request #148891 from NixOS/backport-148862-to-release-21.11 2021-12-10 04:28:05 +02:00
Artturi
062e5559ac Merge pull request #149307 from NixOS/backport-149198-to-release-21.11 2021-12-10 04:25:39 +02:00
Artturi
0299d298bc Merge pull request #149037 from NixOS/backport-148649-to-release-21.11 2021-12-10 04:23:35 +02:00
Artturi
4f1b2dd0dc Merge pull request #148499 from NixOS/backport-148476-to-release-21.11 2021-12-10 04:23:03 +02:00
Artturi
47a2dbbafc Merge pull request #149960 from NixOS/backport-149936-to-release-21.11 2021-12-10 04:14:17 +02:00
Artturin
65ce36f613 nixos/qemu-vm: add -device virtio-keyboard to opts
by default a ps/2 keyboard input is used which seems to cause issues
on aarch64-linux when the machine is used high load, causing the keymap
qwertz test to always fail and azerty to sometimes fail
See https://github.com/NixOS/nixpkgs/issues/147294

(cherry picked from commit 39c5525cb1)
2021-12-10 02:06:45 +00:00
Bobby Rong
463ae7b448 Merge pull request #148352 from NixOS/backport-147771-to-release-21.11
[Backport release-21.11] xsos: init at 0.7.19
2021-12-10 09:59:37 +08:00
R. Ryantm
48e4d69893 nvme-cli: 1.15 -> 1.16
(cherry picked from commit e829d9f369)
2021-12-10 01:14:17 +00:00
github-actions[bot]
8c68c6fa96 Merge staging-next-21.11 into staging-21.11 2021-12-10 00:10:28 +00:00
github-actions[bot]
6c995568bc Merge release-21.11 into staging-next-21.11 2021-12-10 00:09:50 +00:00
Vladimír Čunát
0b0a1bdee0 Merge #149903: knot-resolver: patch an issue 2021-12-09 20:32:55 +01:00
Erik Arvstedt
065fec456f fontconfig: add upstream patch to fix font style detection
(cherry picked from commit 9e0a35863a)
2021-12-09 20:13:12 +01:00
Vladimír Čunát
8b5fb9b523 knot-resolver: patch a possibly unpleasant issue
No more releasing in 2021.

(cherry picked from commit 02d8ed2eb1)
2021-12-09 19:01:39 +00:00
ajs124
ca304f91a5 Merge pull request #149890 from NixOS/backport-149658-to-release-21.11
[Backport release-21.11] spidermonkey_91: 91.3.0 -> 91.4.0
2021-12-09 18:23:43 +00:00
Will
5b66aa1b55 spidermonkey_91: 91.3.0 -> 91.4.0
(cherry picked from commit e9876058d2)
2021-12-09 17:37:10 +00:00
Thiago Kenji Okada
a495e0fce7 Merge pull request #149864 from NixOS/backport-146321-to-release-21.11
[Backport release-21.11] mongodb: 3.6.13 -> 3.6.23, 4.0.12 -> 4.0.27, 4.2.8 -> 4.2.17
2021-12-09 13:08:27 -03:00
Thiago Kenji Okada
aa9df12fde Merge pull request #149793 from NixOS/backport-149766-to-release-21.11
[Backport release-21.11] ceph: 16.2.6 -> 16.2.7
2021-12-09 12:56:45 -03:00
Thiago Kenji Okada
fe4ebb5a53 Merge pull request #149856 from NixOS/backport-149844-to-release-21.11
[Backport release-21.11] privoxy: 3.0.32 -> 3.0.33
2021-12-09 11:48:53 -03:00
Bryan A. S
d5e6b40eb0 mongodb-4_2: 4.2.8 -> 4.2.17
(cherry picked from commit 3108f8dd7c)
2021-12-09 14:40:12 +00:00
Bryan A. S
9a3afa989a mongodb-4_0: 4.0.12 -> 4.0.27
(cherry picked from commit 6aa95a5ea8)
2021-12-09 14:40:12 +00:00
Bryan A. S
38d0a38bdf mongodb-3_6: 3.6.13 -> 3.6.23
(cherry picked from commit 373dd89275)
2021-12-09 14:40:12 +00:00
Bobby Rong
62a41a6b87 vscodium: 1.62.3 -> 1.63.0
(cherry picked from commit 0265685614)
2021-12-09 14:09:59 +00:00
Bobby Rong
bc7fb14b6e vscode: 1.62.3 -> 1.63.0
(cherry picked from commit 521958cb8f)
2021-12-09 14:09:59 +00:00
Martin Weinelt
574672efe1 privoxy: 3.0.32 -> 3.0.33
(cherry picked from commit 9a4da4a8a0)
2021-12-09 13:53:15 +00:00
Guillaume Girol
3fdfd93819 ocamlPackages.jsonrpc: 1.8.3 → 1.9
(cherry picked from commit 8f7e8ee23d)
edited to not upgrade ocaml-lsp to 1.9 on ocaml < 4.12
2021-12-09 12:00:00 +00:00
Kim Lindberger
81b4e2d21f Merge pull request #149677 from NixOS/backport-147506-to-release-21.11
[Backport release-21.11] discourse: 2.7.9 -> 2.8.0.beta9
2021-12-09 12:29:58 +01:00
R. Ryantm
05ac496022 thunderbird-unwrapped: 91.3.2 -> 91.4.0
(cherry picked from commit 901064350e)
2021-12-09 11:25:40 +00:00
Jörg Thalheim
f7def68d28 Merge pull request #149777 from NixOS/backport-149244-to-staging-21.11
[Backport staging-21.11] kmod: switch the priority of module dirs
2021-12-09 08:21:44 +00:00
Niklas Hambüchen
54cd463a82 ceph: 16.2.6 -> 16.2.7. Fixes data-loss upgrade bug.
See https://ceph.io/en/news/blog/2021/v16-2-7-pacific-released/

(cherry picked from commit a9bdcf8a82)
2021-12-09 06:51:03 +00:00
Niklas Hambüchen
4699438d87 ceph: Remove obsolete scipy override.
The mentioned bugs have merged linked pull requests a long time ago:

* b9dea87ff1
  in Ceph v15.1.0
* f701ed8b26
  in Ceph v16.1.0

(cherry picked from commit c6cb7badab)
2021-12-09 06:51:03 +00:00
Jamie McClymont
ff17a0fffe pythonPackages.requests-toolbelt: disable time-dependant tests
Tests include certificates and fail because they are expired.

Upstream issue exists but has been ignored: https://github.com/requests/toolbelt/issues/306

closes #147776

(cherry picked from commit 62df72857c)
2021-12-08 22:18:21 -08:00
Artturin
e3624bed49 kmod: add myself(artturin) as a maintainer
(cherry picked from commit 86ae2154c2)
2021-12-09 03:54:30 +00:00
Artturin
6bcf40e1a8 kmod: switch the priority of module dirs
make "/run/booted-system/kernel-modules" be searched first

Fixes https://github.com/NixOS/nixpkgs/issues/146383
modprobe: ERROR: could not insert 'zram': Invalid argument

(cherry picked from commit 453968c01a)
2021-12-09 03:54:30 +00:00
Daniel Olsen
1602ffb579 nixos/dokuwiki: Use php74 for the phpfpm pool
php8 does not work and is not supported

(cherry picked from commit 1681c0b49e)
2021-12-09 03:25:18 +00:00
Artturi
31f7491819 Merge pull request #149688 from NixOS/backport-149665-to-release-21.11
[Backport release-21.11] make-squashfs: use $NIX_BUILD_CORES
2021-12-09 04:52:29 +02:00
Thiago Kenji Okada
aea4ba46b1 Merge pull request #149735 from NixOS/backport-147956-to-release-21.11
[Backport release-21.11] direnv: 2.28.0 -> 2.29.0
2021-12-08 21:45:21 -03:00
github-actions[bot]
05ba6ccfe0 Merge staging-next-21.11 into staging-21.11 2021-12-09 00:10:23 +00:00
github-actions[bot]
333c3bc159 Merge release-21.11 into staging-next-21.11 2021-12-09 00:09:46 +00:00
zowoq
513123f5b1 direnv: 2.28.0 -> 2.29.0
https://github.com/direnv/direnv/releases/tag/v2.29.0
(cherry picked from commit 8c5661153ad8ca4ac91a8769acccac99e9680e43)
2021-12-08 22:27:16 +00:00
Florian Klink
3b1e4c3cf2 Merge pull request #149371 from NixOS/backport-147498-to-release-21.11
[Backport release-21.11] nixos/acme: Disable bash tracing
2021-12-08 23:24:11 +01:00
ajs124
e13472d150 systemd: reference upstream discussion for 0019-core-handle-lookup-paths-being-symlinks.patch
(cherry picked from commit e2f009e5a2)
2021-12-08 21:34:11 +00:00
Arian van Putten
ec0131da46 nixos/systemd: remove nss-{user,}-lookup.target from multi-user.target
There is no real harm having them there; but it means these units really
only become active if there is a service providing the underlying
functionality.

nss-lookup.target should not be pulled in unconditionally. It should be
pulled in by providers of DNS lookups. E.g. systemd-resolved.service has
a Wants=nss-lookup.target, Before=nss-lookup.target. So once
systemd-resolved.service has finished starting up; other units that rely
on DNS can be started; but if systemd-resolved is not enabled; those
units can start up immediately.

Same story goes for nss-user-lookup.target and daemons like sssd.

From https://systemd.io/UIDS-GIDS/:

 Note that nss-user-lookup.target is a passive unit: in order to
 minimize synchronization points on systems that don’t need it the unit
 is pulled into the initial transaction only if there’s at least one
 service that really needs it, and that means only if there’s a service
 providing the local user database somehow through IPC or suchlike.

(cherry picked from commit 3efbd53c1b)
2021-12-08 21:34:11 +00:00
Arian van Putten
1084b163cf nixos/systemd: remove local-fs.target, swap.target from multi-user.target
Since https://github.com/NixOS/nixpkgs/pull/56184/files  local-fs.target
is already pulled in by sysinit.target

swap.target has always already been pulled in by sysinit.target

(cherry picked from commit b4d7911263)
2021-12-08 21:34:11 +00:00
Arian van Putten
043ddf1600 systemd: move systemd-tmpfiles-setup-dev.service back to early boot
It was originally moved because of nixops autoLuks feature which
has been unsupported for a while.

See:
* https://github.com/NixOS/nixpkgs/issues/62211
* https://github.com/NixOS/nixops/pull/1156#issuecomment-605339705

systemd-tmpfiles-setup-dev.service needs to run very  early (even before
udev runs) because udev rules assume static device nodes already exist
even before udev is started. If these static device nodes do not exist;
systemd might have trouble mounting filesystems that require static
device nodes (like loopfs and btrfs).

(cherry picked from commit d4e4d27dff)
2021-12-08 21:34:11 +00:00
ajs124
fb96af48d0 systemd: align kmod-static-nodes.service with kmod paths
(cherry picked from commit 32e30e84f6)
2021-12-08 21:34:11 +00:00
ajs124
50d0279715 systemd: 249.5 -> 249.7
(cherry picked from commit 84a769c071)
2021-12-08 21:34:11 +00:00
Florian Klink
af174ee5cf Merge pull request #149708 from NixOS/backport-149206-to-release-21.11
[Backport release-21.11] grafana-agent: 0.20.0 -> 0.21.2
2021-12-08 22:15:45 +01:00
Thiago Kenji Okada
a2572d5a85 Merge pull request #149703 from NixOS/backport-149691-to-release-21.11
[Backport release-21.11] ungoogled-chromium: 96.0.4664.45 -> 96.0.4664.93
2021-12-08 18:13:07 -03:00
Martin Weinelt
50ef906223 Merge pull request #149669 from NixOS/backport-149544-to-release-21.11 2021-12-08 21:38:13 +01:00
Florian Klink
8e087945de grafana-agent: 0.21.1 -> 0.21.2
Fixes CVE-2021-41090

(cherry picked from commit be57a90b6f29e03be768e7b1ac7cac191a44ba34)
2021-12-08 20:27:32 +00:00
R. Ryantm
a26ef7e2eb grafana-agent: 0.20.0 -> 0.21.1
(cherry picked from commit b858582482b71bb33ad8abf04d060b30940cf143)
2021-12-08 20:27:32 +00:00
Martin Weinelt
c311ad8774 Merge pull request #149659 from NixOS/backport-149590-to-release-21.11 2021-12-08 21:19:48 +01:00
Michael Weiss
1fdc549788 ungoogled-chromium: 96.0.4664.45 -> 96.0.4664.93
(cherry picked from commit a5782a2b53)
2021-12-08 19:46:03 +00:00
Artturin
5dbf874b68 make-squashfs: use $NIX_BUILD_CORES or 48 cores if above 48
by default all cores are used

hoping this will fix the hydra i686 squashfs build issues as all the
failures were using 64 cores

Parallel mksquashfs: Using 64 processors
Creating 4.0 filesystem on ..., block size 1048576.
FATAL ERROR: mangle2:: xz compress failed with error code 5

(cherry picked from commit eea6baad50)
2021-12-08 18:24:27 +00:00
Lassulus
330ba2d27d Merge pull request #149683 from NixOS/backport-149650-to-release-21.11
[Backport release-21.11] steam: 1.0.0.73 -> 1.0.0.74
2021-12-08 19:18:37 +01:00
lassulus
9b971972d8 steam: 1.0.0.73 -> 1.0.0.74
(cherry picked from commit 9deb6bf336)
2021-12-08 18:01:40 +00:00
talyz
1373cfd5b9 discourse: Don't patch the public path
Instead of patching the path to /public in Discourse's sources, make
the nginx configuration refer to the symlink in the discourse
package which points to the real path.

When there is a mismatch between the path nginx serves and the path
Discourse thinks it serves, we can run into issues like files not
being served - at least when sendfile requests from the ruby app are
processed by nginx. The issue I ran into most recently is that backup
downloads don't work.

Since Discourse refers to the public directory relative to the Rails
root in many places, it's much easier to just sync this path to the
nginx configuration than trying to patch all occurrences in the
sources. This should hopefully mean less potential for breakage in
future Discourse releases, too.

(cherry picked from commit 125bb7dac1)
2021-12-08 17:19:59 +00:00
talyz
a9381e7a6a discourse: update.py: Improve version handling, use pinned plugins
Add a DiscourseVersion class which handles Discourse's version
numbering properly when sorting - beta versions are sorted lower than
their respective release versions. It can also return both its version
number and equivalent git tag, removing the need for `rev2version` and
manually adding `v` to the front.

Using DiscourseVersion instead of LooseVersion, we can list all
current version number tags from the `discourse` repo and sort them
correctly, giving us the latest one, regardless of type; i.e. we don't
have to filter for only release versions or beta versions anymore.

This also implements the plugin pinning algorithm laid out here:
https://meta.discourse.org/t/pinning-plugin-and-theme-versions-for-older-discourse-installs/156971
to make sure we don't upgrade plugins further than what's compatible
with our currently packaged Discourse version. While it likely won't
matter much most of the time if we continue packaging the beta
versions, it could be helpful if we decide to go back to packaging
release versions or if we run into issues with future upgrades. In
that case, the plugins could still be updated safely even though we're
not on the latest version of Discourse.

(cherry picked from commit 4fb343c87e)
2021-12-08 17:19:59 +00:00
talyz
5f44fc1aec discourse.plugins: Update all plugins to their latest versions
Also, add support for updating plugins which keep gem versions in
files at the root of the repo (discourse-prometheus) and replace the
`up-plugin.sh` script with a README file pointing to the plugin
packaging documentation.

(cherry picked from commit ab042d6452)
2021-12-08 17:19:59 +00:00
talyz
f7f02efa71 discourse: 2.7.9 -> 2.8.0.beta9
Update to the latest beta, since upstream advocates for it. See
https://github.com/NixOS/nixpkgs/issues/146308 for more info.

(cherry picked from commit e2415dbb8f)
2021-12-08 17:19:59 +00:00
talyz
e741498579 nodejs: Provide a static v8 library output
Since building nodejs also builds v8, one way to get a static v8
library is to manually assemble it from the leftover object
files. This seems like an easier way to get an up-to-date v8 library
than trying to keep the v8 package updated.

(cherry picked from commit 679398b160)
2021-12-08 17:19:59 +00:00
Vincent Laporte
31964744c7 coqPackages.mathcomp-bigenough: 1.0.0 → 1.0.1
(cherry picked from commit f5ca72dcf3)
2021-12-08 17:17:20 +00:00
R. Ryantm
bbff3a01d3 firefox-esr-91-unwrapped: 91.3.0esr -> 91.4.0esr
(cherry picked from commit 8474bbde74)
2021-12-08 16:59:49 +00:00
ajs124
49898d692f firefox: 94.0.2 -> 95.0
(cherry picked from commit 340ede9984)
2021-12-08 16:07:52 +00:00
Jörg Thalheim
ef9a8ddc6d Merge pull request #149636 from NixOS/backport-149605-to-release-21.11
[Backport release-21.11] agg: Fix darwin build
2021-12-08 15:24:44 +00:00
Matt Christ
f0e97ca684 brscan5: fix nixos test
import 're' so we can do regex stuff in this test

(cherry picked from commit 7b1d8bd182)
2021-12-08 15:11:18 +00:00
Jörg Thalheim
295dcc83f8 Merge pull request #149646 from NixOS/backport-149587-to-release-21.11
[Backport release-21.11] nixos/snapraid: fix evaluation
2021-12-08 15:10:22 +00:00
David Knaack
6dc498b75f nixos/snapraid: fix evaluation
Use string concatenation operator (`+`) instead of incorrect list concatenation operator (`++`)

(cherry picked from commit 28db2a481d)
2021-12-08 15:02:49 +00:00
Jörg Thalheim
00279b9134 Merge pull request #149641 from NixOS/backport-149625-to-release-21.11
[Backport release-21.11] doc: ruby-section: add workaround for platform-specific gems
2021-12-08 14:59:45 +00:00
R. Ryantm
50d282f96b libsidplayfp: 2.3.0 -> 2.3.1
(cherry picked from commit 4e0f65ce17)
2021-12-08 14:48:55 +00:00
R. Ryantm
a6dd7a2861 linuxKernel.packages.linux_5_15.system76-power: 1.1.18 -> 1.1.20
(cherry picked from commit e2fcc2e69c)
2021-12-08 14:44:58 +00:00
Yannick Markus
a5224ff20e doc: ruby-section: add workaround for platform-specific gems
(cherry picked from commit b8a221262b)
2021-12-08 14:42:10 +00:00
R. Ryantm
eb4006dddc psi-plus: 1.5.1576 -> 1.5.1582
(cherry picked from commit 913a1014a4)
2021-12-08 14:41:27 +00:00
Dario Bertini
7f4ccc54e0 agg: Fix darwin build
This had been broken with #136095

(cherry picked from commit 2e7a032139)
2021-12-08 14:33:01 +00:00
Anderson Torres
d61b48982e Merge pull request #149508 from NixOS/backport-149396-to-release-21.11
[Backport release-21.11] fakeroute: change upstream
2021-12-08 10:31:03 -03:00
Thiago Kenji Okada
ec0f986931 Merge pull request #149503 from NixOS/backport-149496-to-release-21.11
[Backport release-21.11] Bibata cursors update
2021-12-08 09:44:10 -03:00
Janne Heß
13988bf29e Merge pull request #149588 from NixOS/backport-149253-to-release-21.11
[Backport release-21.11] icingaweb2: 2.9.4 -> 2.9.5
2021-12-08 11:27:28 +01:00
R. Ryantm
31ac51e369 icingaweb2: 2.9.4 -> 2.9.5
(cherry picked from commit b9fc29de15)
2021-12-08 10:24:44 +00:00
John Ericson
405e472db9 llvmPackages: Make sure we can attempt to cross-compile the tools
(cherry picked from commit 0c9716ad3c)
2021-12-08 05:36:56 +00:00
Martin Weinelt
50b41ae048 python3Packages.django_2: 2.2.24 -> 2.2.25
(cherry picked from commit 24f959ebf3a0c638c91a80960dee701bedd3a663)
2021-12-07 20:18:49 -08:00
Martin Weinelt
3258df6ef8 python3Packages.django_3: 3.2.9 -> 3.2.10
(cherry picked from commit b4ad673b1fc58970209528718b0b496e362f0169)
2021-12-07 20:18:49 -08:00
Zane van Iperen
85e68f75da fakeroute: change upstream
Original upstream has been purged, switch to a mirror.
See https://github.com/NixOS/nixpkgs/issues/149201 for details.

(cherry picked from commit cab9136841)
2021-12-08 03:53:35 +00:00
Thiago Kenji Okada
3f629e3dd5 Merge pull request #149498 from NixOS/backport-149072-to-release-21.11
[Backport release-21.11] nixUnstable: 2.5pre20211126 -> 2.5pre20211206
2021-12-08 00:46:10 -03:00
Adson Cicilioti
df0c674890 clickgen: run tests with pytestCheckHook
(cherry picked from commit 2d91877c37)
2021-12-08 02:39:07 +00:00
Adson Cicilioti
84d475bb0b bibata-cursors-translucent: unstable-2019-09-13 -> 1.1.1
(cherry picked from commit 15e4cefbea)
2021-12-08 02:39:07 +00:00
Adson Cicilioti
1b97c07a86 bibata-extra-cursors: 0.3 -> 1.0.1
(cherry picked from commit 408ecd60d4)
2021-12-08 02:39:07 +00:00
Adson Cicilioti
8a9b5bf5bf bibata-cursors: 0.4.2 -> 1.1.2
(cherry picked from commit b8fbdc8852)
2021-12-08 02:39:07 +00:00
Adson Cicilioti
9bf9cfb5e8 clickgen: init at 1.1.9
(cherry picked from commit 7e48f4294e)
2021-12-08 02:39:07 +00:00
Adson Cicilioti
07ae717076 maintainers: add AdsonCicilioti
(cherry picked from commit 5c647de65f)
2021-12-08 02:39:06 +00:00
Martin Weinelt
e833481d24 Merge pull request #148770 from risicle/ris-libjxl-CVE-2021-22563-r21.11 2021-12-08 02:04:30 +01:00
Artturin
3a922211a8 nixUnstable: 2.5pre20211126 -> 2.5pre20211206
(cherry picked from commit 8764e76473)
2021-12-08 00:57:53 +00:00
TredwellGit
4e97b3838d linux_5_14: remove
https://lwn.net/ml/linux-kernel/1637500331152110@kroah.com/
https://github.com/openzfs/zfs/issues/12786
(cherry picked from commit dae043cacae9dd43e74cb76a9709a250b584c074)
2021-12-08 00:21:25 +00:00
TredwellGit
48a5b44767 linux/hardened/patches/5.4: 5.4.160-hardened1 -> 5.4.163-hardened1
(cherry picked from commit 3bb4418f19665d58957641ca442ed59f85ade75e)
2021-12-08 00:21:25 +00:00
TredwellGit
6ab656307b linux/hardened/patches/5.15: 5.15.3-hardened1 -> 5.15.6-hardened1
(cherry picked from commit 5c8d2f4fdb2f7a101a445d4da8fc2da18a62f21a)
2021-12-08 00:21:25 +00:00
TredwellGit
c097c01a7b linux/hardened/patches/5.10: 5.10.80-hardened1 -> 5.10.83-hardened1
(cherry picked from commit 3084c7289538fa4e2b68dce329051e8b891c885d)
2021-12-08 00:21:25 +00:00
TredwellGit
bf559254f8 linux/hardened/patches/4.19: 4.19.217-hardened1 -> 4.19.219-hardened1
(cherry picked from commit e0069f5cc1e01305f93b2cda25d9d5a376d97348)
2021-12-08 00:21:25 +00:00
TredwellGit
d9634b0abf linux/hardened/patches/4.14: 4.14.255-hardened1 -> 4.14.256-hardened1
(cherry picked from commit 0f0e9a2a7cde85de7dcfca2e41cf0d207c72dc07)
2021-12-08 00:21:25 +00:00
TredwellGit
4f17a9628a linux-rt_5_4: 5.4.154-rt65 -> 5.4.161-rt66
(cherry picked from commit ced6cfdc53ba7630570f3779ec3607aef4757234)
2021-12-08 00:21:25 +00:00
TredwellGit
34a6a8da2e linux-rt_5_10: 5.10.78-rt55 -> 5.10.78-rt56
(cherry picked from commit 396a5f074f1dbbc334bd5d50fa8586e076bfcbf7)
2021-12-08 00:21:25 +00:00
TredwellGit
0246dd549c linux: 5.4.161 -> 5.4.163
(cherry picked from commit 316f926d4488f29d3596ef55758694812e3c4f25)
2021-12-08 00:21:25 +00:00
TredwellGit
65e4feff6e linux: 5.15.4 -> 5.15.6
(cherry picked from commit 43df89f381d1c0c19780bd89934a06a642fd9317)
2021-12-08 00:21:25 +00:00
TredwellGit
810189823c linux: 5.10.81 -> 5.10.83
(cherry picked from commit a98d42b3106451de30ab9738098c69b31f981c8d)
2021-12-08 00:21:25 +00:00
TredwellGit
ff8f2c33c0 linux: 4.9.290 -> 4.9.291
(cherry picked from commit e6d513660c26edb94f12e29e2007b8d3f91810be)
2021-12-08 00:21:25 +00:00
TredwellGit
cc94c113d2 linux: 4.4.292 -> 4.4.293
(cherry picked from commit a1cfb71863ce71f6e194012da2daa44d234dbee5)
2021-12-08 00:21:24 +00:00
TredwellGit
fd16e2acdd linux: 4.19.217 -> 4.19.219
(cherry picked from commit b9170e6ce5043d81beefa4f8f97854dd90259884)
2021-12-08 00:21:24 +00:00
TredwellGit
7bd9b917c3 linux: 4.14.255 -> 4.14.256
(cherry picked from commit 7a779a23845fcdb6cbf980c0fac6f285d078d44a)
2021-12-08 00:21:24 +00:00
Martin Weinelt
7a196411f7 Merge pull request #148368 from NixOS/backport-146477-to-staging-21.11 2021-12-08 01:16:18 +01:00
Zhaofeng Li
87bf98f551 qemu: Add patch for socket_sockaddr_to_address_unix assertion errors
See also:
- http://bugs.debian.org/993145
- https://bugs.archlinux.org/task/72115

(cherry picked from commit 2544cf289e4b78f3f16cb4f142b4a67f7eb8d6aa)
2021-12-08 00:13:31 +00:00
github-actions[bot]
2a76e45003 Merge staging-next-21.11 into staging-21.11 2021-12-08 00:11:04 +00:00
github-actions[bot]
9adddde0a0 Merge release-21.11 into staging-next-21.11 2021-12-08 00:10:25 +00:00
Thiago Kenji Okada
edee910cc9 Merge pull request #149464 from NixOS/backport-149445-to-release-21.11
[Backport release-21.11] pcsx2: 2021-10-28 -> 1.7.2105 & wayland support
2021-12-07 19:54:42 -03:00
Thiago Kenji Okada
d42de7c5bd Merge pull request #149452 from NixOS/backport-149438-to-release-21.11
[Backport release-21.11] chromium: 96.0.4664.45 -> 96.0.4664.93
2021-12-07 19:40:02 -03:00
Samuel Gräfenstein
2a6ca38ce0 pcsx2: build with wayland support
(cherry picked from commit 2dd0edd99a)
2021-12-07 22:15:42 +00:00
Samuel Gräfenstein
06a6a71d2d pcsx2: 2021-10-28 -> 1.7.2105
(cherry picked from commit c84ac918fc)
2021-12-07 22:15:42 +00:00
Maximilian Bosch
115b17b19b Merge pull request #148585 from NixOS/backport-148294-to-release-21.11
[Backport release-21.11] grafana: 8.2.5 -> 8.3.1
Closes #149434
2021-12-07 23:08:07 +01:00
Maximilian Bosch
14c51e1f85 Merge pull request #148670 from NixOS/backport-148576-to-release-21.11
[Backport release-21.11] gitea: 1.15.6 -> 1.15.7
2021-12-07 23:07:25 +01:00
sternenseemann
b7ac3dd81d foot: 1.10.1 -> 1.10.2
https://codeberg.org/dnkl/foot/releases/tag/1.10.2
(cherry picked from commit b3223b6eb3762015670ffb61be70516f34398c93)
2021-12-07 22:18:32 +01:00
Thomas Gerbet
946cc175b7 grafana: 8.3.0 -> 8.3.1
Fixes CVE-2021-43798.
https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-3-1/

(cherry picked from commit b207a9d87d)
2021-12-07 22:03:20 +01:00
Michael Weiss
0cbbcb1593 chromium: 96.0.4664.45 -> 96.0.4664.93
https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html

This update includes 22 security fixes.

CVEs:
CVE-2021-4052 CVE-2021-4053 CVE-2021-4079 CVE-2021-4054 CVE-2021-4078
CVE-2021-4055 CVE-2021-4056 CVE-2021-4057 CVE-2021-4058 CVE-2021-4059
CVE-2021-4061 CVE-2021-4062 CVE-2021-4063 CVE-2021-4064 CVE-2021-4065
CVE-2021-4066 CVE-2021-4067 CVE-2021-4068

(cherry picked from commit 4939140e0f)
2021-12-07 20:45:47 +00:00
R. Ryantm
3f6853083a nomad-autoscaler: 0.3.3 -> 0.3.4
(cherry picked from commit 9c57b07cc14a01e4f4e6ab04b92e93f819b7db88)
2021-12-07 12:23:21 -08:00
Pavol Rusnak
a6772c54b8 Merge pull request #149430 from NixOS/backport-149420-to-release-21.11
[Backport release-21.11] bpytop: unbreak on aarch64-darwin
2021-12-07 21:15:13 +01:00
Bjørn Forsman
938a36cfce Revert "nixos/ddclient: fix permission for ddclient.conf (#148179)"
This reverts commit 6af3d13bec.

Reported by @arcnmx
(https://github.com/NixOS/nixpkgs/pull/148179#issuecomment-987197656):

  Does this not completely break the service? It doesn't change the
  owner to the same as the ddclient server (which is somewhat difficult
  due to it being a DynamicUser), so this now makes the service
  completely unusable because the config is only readable by its owner,
  root:

    ddclient[871397]: WARNING:  file /run/ddclient/ddclient.conf: Cannot open file '/run/ddclient/ddclient.conf'. (Permission denied)

  Given that the RuntimeDirectory was only readable by the ddclient
  service, the warning this PR fixes was spurious and not indicative of
  an actual information leak. I'm not sure of what a quick fix would be
  due to DynamicUser, but would at least request a revert of this so the
  service can work again?

(cherry picked from commit 6a6a40d2aec8329298f63ff5699e8c3c8047040a)
2021-12-07 20:15:14 +01:00
Pavol Rusnak
22a052720d bpytop: unbreak on aarch64-darwin
(cherry picked from commit 46a774d376)
2021-12-07 19:02:20 +00:00
ajs124
a6ffb58af5 Merge pull request #149372 from NixOS/backport-149338-to-release-21.11
[Backport release-21.11] dovecot + pigeonhole: 2.3.17 -> 2.3.17.1
2021-12-07 17:09:38 +00:00
Vincent Laporte
9d4eb8d5ee ocamlPackages.lablgtk-extras: disable for OCaml ≥ 4.13
(cherry picked from commit bf826b2f981b7bd64fa4c0d26206a3f66aafe869)
2021-12-07 17:22:27 +01:00
Vincent Laporte
f15760c568 ocamlPackages.lablgl: 1.05 → 1.06
(cherry picked from commit 36da962593f1b777fe9836fbbf57efb17c27e6ec)
2021-12-07 17:22:10 +01:00
Vincent Laporte
c4b34ac698 ocamlPackages.js_build_tools: remove at 113.33.06
(cherry picked from commit ea0a6053a842a384f3577f5ba7a52f0c6a8d7a71)
2021-12-07 17:21:40 +01:00
Vincent Laporte
eeb2e86fd0 ocamlPackages.buildOcamlJane: remove
(cherry picked from commit 0a5d36c801278faa09acad4c3aa47c87f1a8eeeb)
2021-12-07 17:21:40 +01:00
Vincent Laporte
6cd61399ee pkgs/development/ocaml-modules/janestreet/: remove dead code
(cherry picked from commit 670d35a94942752d774797e941d7e65fc46a33fe)
2021-12-07 17:21:40 +01:00
Vincent Laporte
ee56f02599 ocamlPackages.variantslib: remove at 109.15.03 & 113.33.03
(cherry picked from commit fcb1c3f74e17673e3022c340b0057be47456e1cd)
2021-12-07 17:21:40 +01:00
Vincent Laporte
3029164f9a ocamlPackages.typerep: remove at 112.24.00 & 113.33.03
(cherry picked from commit f982e669db56728faec8b7986fe5b42605872a86)
2021-12-07 17:21:40 +01:00
Vincent Laporte
660e51b301 ocamlPackages.fieldslib: remove at 109.20.03 & 113.33.03
(cherry picked from commit 9c434b76119621f75e385df8e65be29f1ae5f489)
2021-12-07 17:21:40 +01:00
Vincent Laporte
b3f426e083 ocamlPackages.bin_prot: remove at 112.24.00 & 113.33.03
(cherry picked from commit 397d3302a96cb07d763b1554751baf7644e1af8d)
2021-12-07 17:21:40 +01:00
Thiago Kenji Okada
a59ec49eb0 Merge pull request #149332 from NixOS/backport-147537-to-release-21.11
[Backport release-21.11] python2Packages.jinja2: fix tests
2021-12-07 12:55:22 -03:00
Janne Heß
1bd4bbd49b Merge pull request #149370 from NixOS/backport-149318-to-release-21.11
[Backport release-21.11] tmate-ssh-server: mark as insecure
2021-12-07 15:25:15 +01:00
ajs124
b7400d8a75 dovecot_pigeonhole: 0.5.17 -> 0.5.17.1
(cherry picked from commit 0475ca4a3a)
2021-12-07 14:23:16 +00:00
ajs124
e5a46acd35 dovecot: 2.3.17 -> 2.3.17.1
(cherry picked from commit d0913cf400)
2021-12-07 14:23:16 +00:00
Janne Heß
23a2a33d78 nixos/acme: Allow disabling bash tracing
This is horrible if you want to debug failures that happened during
system switches but your 30-ish acme clients spam the log with the same
messages over and over again.

(cherry picked from commit e37aab2130)
2021-12-07 14:18:48 +00:00
philipp
c40627e6d4 tmate-ssh-server: mark as insecure
(cherry picked from commit 91bc99e964)
2021-12-07 14:18:12 +00:00
0x4A6F
6b19a0ef81 Merge pull request #149309 from NixOS/backport-136693-to-release-21.11
[Backport release-21.11] matrix-alertmanager: init at 0.5.0
2021-12-07 12:59:01 +01:00
Yureka
80653a5d5f matrix-alertmanager: fix and re-run update script
The update script wrote the updated dependency files to the wrong
location.

(cherry picked from commit a7a662bf3d)
2021-12-07 12:28:14 +01:00
Yureka
35c7096dc7 matrix-alertmanager: fix homepage url
(cherry picked from commit 784fae488c)
2021-12-07 12:28:09 +01:00
github-actions[bot]
1ae3e34fc7 gitlab: 14.5.1 -> 14.5.2 (#149315)
https://about.gitlab.com/releases/2021/12/06/security-release-gitlab-14-5-2-released/
(cherry picked from commit 563950aa80c1c333cc7721ec7a333804bae70cba)

Co-authored-by: Lara <lara@uwu.is>
2021-12-07 11:52:05 +01:00
Ryan Burns
68de7f60b9 python2Packages.jinja2: fix tests
Fixes:
```
INTERNALERROR> _OptionError: unknown warning category: 'ResourceWarning'
```

(cherry picked from commit 23188a5f00)
2021-12-07 10:46:55 +00:00
Yureka
c774584b13 matrix-alertmanager: init at 0.5.0
(cherry picked from commit 4c3783cbf52cf9e9b419daee08c7c0e39477e2aa)
2021-12-07 09:24:39 +00:00
R. Ryantm
df2581fbe7 ripasso-cursive: 0.5.1 -> 0.5.2
(cherry picked from commit 2f9c355b2b)
2021-12-07 09:22:40 +00:00
sternenseemann
d7710bf549 haskell.compiler.*: use targetCC for hasGold check
This is a bit shorter and more consistent with the rest of the file.

(cherry picked from commit 19fc229294)
2021-12-07 00:39:28 -08:00
sternenseemann
b2a6f70183 haskell.compiler.*: assert that host->target == build->target tools
CC, CXX, LD, AR, …, LLC, OPT and CLANG will be invoked by GHC's build
system at build time in the build->target role. However, since we are
passing absolute paths, they will get saved in GHC's settings file and
later invoked at runtime, when they should be host->target. This means
that the build->target and host->target tools need to be the same for
our built GHC to work properly which is what we guard using these new
asserts.

Being able to drop these asserts would be a step towards cross-compiling
GHC (as opposed to building a GHC cross-compiler which still works).

(cherry picked from commit c23e14e33f)
2021-12-07 00:39:28 -08:00
sternenseemann
2717ee493c haskell.compiler.ghc921: check if ld.gold is available in useLdGold
Since 4c75874560 it is possible to
introspect if ld.gold is contained in the used bintools, so we can also
check if it is available before deciding to use it as done in the other
GHC derivations in 0908812372.

(cherry picked from commit b2e4708105)
2021-12-07 00:39:28 -08:00
Vincent Laporte
826c4bf7f9 ocamlPackages.optcomp: remove broken
(cherry picked from commit 1e4148203674f0342f1883e6d87c6e15d843e640)
2021-12-07 09:38:01 +01:00
Vincent Laporte
4a3ed7a200 ocamlPackages.ocsigen_deriving: 0.8.1 → 0.8.2
(cherry picked from commit c5f62582ed16866e78b211c3d3a38f6702d320a6)
2021-12-07 09:38:01 +01:00
Artturi
28d078b023 Merge pull request #149218 from NixOS/backport-147023-to-release-21.11 2021-12-07 05:35:54 +02:00
wackbyte
bd607a442b groove: 5.7.4 -> 5.8.1 and jre -> jre8
I tested OpenJDK11 but it didn't seem to work.

(cherry picked from commit 6a2815218d)
2021-12-07 03:16:58 +00:00
Thiago Kenji Okada
d2501f68e2 Merge pull request #149176 from NixOS/backport-149104-to-release-21.11
[Backport release-21.11] exfatprogs: 1.1.2 -> 1.1.3
2021-12-06 22:36:56 -03:00
R. Ryantm
529eab6380 exfatprogs: 1.1.2 -> 1.1.3
(cherry picked from commit 2a0981099e)
2021-12-07 00:40:30 +00:00
github-actions[bot]
c982f51917 Merge staging-next-21.11 into staging-21.11 2021-12-07 00:10:21 +00:00
github-actions[bot]
831a93f990 Merge release-21.11 into staging-next-21.11 2021-12-07 00:09:42 +00:00
Thiago Kenji Okada
74e4be758e Merge pull request #149116 from NixOS/backport-138800-to-release-21.11
[Backport release-21.11]  sabnzbd: 3.4.0 -> 3.4.2, add missing dependencies, add a simple test
2021-12-06 19:06:15 -03:00
0x4A6F
a9c618c430 Merge pull request #149123 from NixOS/backport-148098-to-release-21.11
[Backport release-21.11] colmena: init at 0.2.0
2021-12-06 22:02:13 +01:00
Zhaofeng Li
3340cc7cf5 colmena: init at 0.2.0
(cherry picked from commit 9c5f93a473)
2021-12-06 20:23:14 +00:00
Johannes Schleifenbaum
ca7b4993c1 sabnzbd: 3.4.1 -> 3.4.2
(cherry picked from commit dce448995cd82806d5e02e2b836b724ba4ec700f)
2021-12-06 20:12:35 +00:00
Johannes Schleifenbaum
ba86ee6c05 sabnzbd: 3.4.0 -> 3.4.1
(cherry picked from commit 66d7ca8797d67e731a611a2b8b5f883f24a04947)
2021-12-06 20:12:35 +00:00
Johannes Schleifenbaum
9c258af44c sabnzbd: add simple test
(cherry picked from commit 774c57e9af87c7bfa3a53b211b09fb49179c9f9d)
2021-12-06 20:12:35 +00:00
Johannes Schleifenbaum
c4ce763cbb sabnzbd: add jojosch as maintainer
(cherry picked from commit 1eaed159a462de849dc958aac9c0b9c17b987916)
2021-12-06 20:12:35 +00:00
Johannes Schleifenbaum
bf21a32f37 sabnzbd: add missing dependencies
(cherry picked from commit 89f90a0e356b2d7ecdfa43b5313f92d085face6b)
2021-12-06 20:12:35 +00:00
Thiago Kenji Okada
6aaaf3b250 Merge pull request #149054 from NixOS/backport-144772-to-release-21.11
[Backport release-21.11] arduino: use buildFHSUserEnv to support compilation of boards
2021-12-06 14:08:16 -03:00
Janne Heß
01525b4631 Merge pull request #148793 from NixOS/backport-148776-to-release-21.11
[Backport release-21.11] nginxModules.pam: 1.5.2 -> 1.5.3
2021-12-06 18:02:31 +01:00
Michele Guerini Rocco
5a2fcc5668 Merge pull request #149032 from NixOS/backport-149004-to-release-21.11
[Backport release-21.11] ddcutil: 1.2.0 -> 1.2.1
2021-12-06 17:33:18 +01:00
Felix Buehler
80708687e2 arduino: use buildFHSUserEnv to support compilation of boards
(cherry picked from commit 5e4c4fe76ed641b2e2312f0c7318816b2cc3a6c7)
2021-12-06 16:10:42 +00:00
Artturin
1812d06e0a nixos: add sgx group with gid 304
fix Unknown group 'sgx', ignoring message from udev

(cherry picked from commit fc4df13e26)
2021-12-06 15:09:15 +00:00
R. Ryantm
73823a5007 ddcutil: 1.2.0 -> 1.2.1
(cherry picked from commit 4065ea45e6)
2021-12-06 14:49:03 +00:00
Kim Lindberger
ceed89289d Merge pull request #148447 from NixOS/backport-148302-to-release-21.11
[Backport release-21.11] gitlab: 14.5.0 -> 14.5.1
2021-12-06 15:11:59 +01:00
Kim Lindberger
43959b1461 Merge pull request #148936 from NixOS/backport-148467-to-release-21.11
[Backport release-21.11] Revert "google-compute-engine: 20190124 -> 20200113.0 (#131761)"
2021-12-06 15:08:16 +01:00
Maximilian Bosch
f0dc90a727 Merge pull request #148289 from NixOS/backport-148261-to-release-21.11
[Backport release-21.11] clipman: 1.6.0 -> 1.6.1
2021-12-06 14:52:25 +01:00
Maximilian Bosch
54e1c356ea Merge pull request #148284 from NixOS/backport-148271-to-release-21.11
[Backport release-21.11] strace: 5.14 -> 5.15
2021-12-06 14:52:16 +01:00
Maximilian Bosch
08f201fc3d Merge pull request #148298 from NixOS/backport-147897-to-release-21.11
[Backport release-21.11] roundcube: 1.5.0 -> 1.5.1
2021-12-06 14:52:05 +01:00
Maximilian Bosch
f683c62dd0 Merge pull request #148299 from NixOS/backport-147315-to-release-21.11
[Backport release-21.11] element-desktop: 1.9.4 -> 1.9.5
2021-12-06 14:51:52 +01:00
Kerstin Humm
93a707704d imagemagick: 7.1.0-16 -> 7.1.0-17
(cherry picked from commit 7617df63c2)
2021-12-06 11:43:59 +01:00
talyz
a2dd351b6a Revert "google-compute-engine: 20190124 -> 20200113.0 (#131761)"
This reverts commit 1748291445.

This upgrade broke the google-compute-config module. See
https://github.com/NixOS/nixpkgs/pull/144761 for more info.

(cherry picked from commit 5a4ea496b6)
2021-12-06 08:55:54 +00:00
R. Ryantm
35c72a8af1 whatsapp-for-linux: 1.3.0 -> 1.3.1
(cherry picked from commit cec054b345)
2021-12-06 06:20:52 +00:00
Maciej Krüger
0f98576790 Merge pull request #148856 from NixOS/backport-148640-to-release-21.11 2021-12-06 05:47:39 +01:00
Johannes Schleifenbaum
6806b7977f dbeaver: add webkitgtk and glib-networking for webbrowser support
(cherry picked from commit f957447d22)
2021-12-06 04:37:10 +00:00
Bobby Rong
bbc4931b95 Merge pull request #148840 from NixOS/backport-148823-to-release-21.11
[Backport release-21.11] pantheon-tweaks: 1.0.2 -> 1.0.3
2021-12-06 11:50:11 +08:00
Bobby Rong
333a43fccf pantheon-tweaks: 1.0.2 -> 1.0.3
(cherry picked from commit 67b751ccb8)
2021-12-06 03:27:29 +00:00
github-actions[bot]
24e888cb7b Merge staging-next-21.11 into staging-21.11 2021-12-06 00:10:37 +00:00
github-actions[bot]
24be3912bd Merge release-21.11 into staging-next-21.11 2021-12-06 00:09:55 +00:00
Janne Heß
850f725ba9 nginxModules.pam: 1.5.2 -> 1.5.3
This fixes deny statements:
https://github.com/sto/ngx_http_auth_pam_module/issues/25

(cherry picked from commit b9811a5aeb)
2021-12-05 23:37:28 +00:00
Pavol Rusnak
545e796e02 Merge pull request #148790 from NixOS/backport-148788-to-release-21.11
[Backport release-21.11] gcc-arm-embedded-{6,7,8}: enable on aarch64-darwin
2021-12-06 00:16:45 +01:00
Pavol Rusnak
09edc8d35d gcc-arm-embedded-{6,7,8}: enable on aarch64-darwin
(using x86_64-darwin binaries, these can be run if rosetta is installed)

(cherry picked from commit c3557f2e64)
2021-12-05 23:03:47 +00:00
Kerstin Humm
2ba3922bb8 qgis: add erictapen as maintainer
(cherry picked from commit 2d0c11c034)
2021-12-05 22:51:36 +01:00
Lancelot SIX
665c731ad4 qgis: 3.16.13 -> 3.16.14
(cherry picked from commit e5adc91d63)
Signed-off-by: Lancelot SIX <lsix@lancelotsix.com>
2021-12-05 22:51:36 +01:00
Sean Heath
6b025f0193 Update permissions for ddclient.conf file
When running ddclient with the current configuration we receive this warning:
```
WARNING:  file /run/ddclient/ddclient.conf: file /run/ddclient/ddclient.conf must be accessible only by its owner.
```

This change should adjust the permissions for the ddclient.conf file to be -r-------- (read only by owner)

(cherry picked from commit f5582528aaa639d4835fb09869ea8e590d8acaee)
2021-12-05 20:43:01 +01:00
Bjørn Forsman
92b09689de nixos/collectd: add missing group
While upgrading my NixOS system I was greeted by this error:

  error:
  Failed assertions:
  - users.users.collectd.group is unset. This used to default to
  nogroup, but this is unsafe. For example you can create a group
  for this user with:
  users.users.collectd.group = "collectd";
  users.groups.collectd = {};

Let's fix it.

(cherry picked from commit 05bc708a7f)
2021-12-05 20:41:56 +01:00
Robert Scott
9184c19b25 libjxl: add patch for CVE-2021-22564 2021-12-05 19:26:36 +00:00
Jörg Thalheim
3a15a21e57 Merge pull request #148608 from NixOS/backport-148052-to-release-21.11
[Backport release-21.11] jetbrains: 2021.2.3 -> 2021.3
2021-12-05 17:18:22 +00:00
Felix Schröter
9c7491d3cf nixos/ddclient: support all special characters in password
(cherry picked from commit f0bd0f3e4c2383c0ecb646835ef68f69675b4031)
2021-12-05 14:59:12 +01:00
Pavol Rusnak
af780ad9aa Merge pull request #148704 from NixOS/backport-148536-to-release-21.11
[Backport release-21.11] tor: fix build on aarch64-darwin by disabling tests
2021-12-05 14:46:22 +01:00
Pavol Rusnak
2db4054fe0 tor: fix build on aarch64-darwin by disabling tests
(cherry picked from commit 118ed78ec7)
2021-12-05 12:49:05 +00:00
Domen Kožar
df9e592716 Merge pull request #148286 from NixOS/backport-148251-to-release-21.11
[Backport release-21.11] qemu: fix darwin build
2021-12-05 12:47:17 +00:00
Jörg Thalheim
9c3248ad12 Merge pull request #148688 from NixOS/backport-148678-to-release-21.11
[Backport release-21.11] autorandr: install zsh completions
2021-12-05 11:12:23 +00:00
Lassulus
7c923e4150 Merge pull request #148687 from NixOS/backport-148403-to-release-21.11
[Backport release-21.11] writers.makePythonWriter: disable flake8 checks for Python 2
2021-12-05 12:09:32 +01:00
Bobby Rong
2cc262640b Merge pull request #148689 from NixOS/backport-148415-to-release-21.11
[Backport release-21.11] Revert "nixos/borgbackup: specify systemd WorkingDirectory"
2021-12-05 19:07:04 +08:00
Kerstin Humm
bc550e43c8 Revert "nixos/borgbackup: specify systemd WorkingDirectory"
This reverts commit 62ab77a322.

This broke nixosTests.borgbackup:
https://github.com/NixOS/nixpkgs/pull/143995#issuecomment-985136152

(cherry picked from commit ac8a9c3f03)
2021-12-05 10:07:08 +00:00
Anund
15b630b0e2 autorandr: install zsh completions
autorandr includes functional zsh completions upstream they just lack
a make target to install the relevant file. For some consistency use the
direct file for both zsh and bash rather than just zsh. Note this
changes the resulting bash completion filename from just 'autorandr' to
'autorandr.bash'

See https://github.com/phillipberndt/autorandr/issues/197

(cherry picked from commit bdda2cca74)
2021-12-05 10:03:48 +00:00
Enno Richter
47862786b2 writers.makePythonWriter: drop flake8 checks for Python 2 scripts
(cherry picked from commit 10c725dc6b)
2021-12-05 09:55:46 +00:00
Enno Richter
c23daa2a9b python2Packages.flake8: disable since flake8 v4 dropped Python 2 support
(cherry picked from commit 138c3b5816)
2021-12-05 09:55:45 +00:00
Jörg Thalheim
958468d0ae Merge pull request #148652 from NixOS/backport-148625-to-release-21.11
[Backport release-21.11] wireshark: 3.4.9 -> 3.4.10
2021-12-05 09:49:40 +00:00
Jörg Thalheim
af0bc76ac2 Merge pull request #148656 from NixOS/backport-148281-to-release-21.11
[Backport release-21.11] apk-tools: 2.12.7 -> 2.12.8
2021-12-05 09:48:57 +00:00
Pavol Rusnak
6f06097308 Merge pull request #148560 from NixOS/backport-148516-to-release-21.11
[Backport release-21.11] electrum-ltc: 3.3.8.1 -> 4.0.9.3
2021-12-05 10:12:22 +01:00
Pavol Rusnak
ba550f4693 Merge pull request #148681 from NixOS/backport-148677-to-release-21.11
[Backport release-21.11] Update Electron
2021-12-05 10:11:13 +01:00
TredwellGit
292c635812 electron_16: 16.0.2 -> 16.0.4
https://github.com/electron/electron/releases/tag/v16.0.3
https://github.com/electron/electron/releases/tag/v16.0.4
(cherry picked from commit d400ed3e66)
2021-12-05 09:06:45 +00:00
TredwellGit
0124d1a261 electron_15: 15.3.2 -> 15.3.3
https://github.com/electron/electron/releases/tag/v15.3.3
(cherry picked from commit cdb43790ea)
2021-12-05 09:06:45 +00:00
TredwellGit
e58eee8f97 electron_14: 14.2.1 -> 14.2.2
https://github.com/electron/electron/releases/tag/v14.2.2
(cherry picked from commit c8eb62f29d)
2021-12-05 09:06:45 +00:00
TredwellGit
f565d6d9c5 electron_13: 13.6.2 -> 13.6.3
https://github.com/electron/electron/releases/tag/v13.6.3
(cherry picked from commit 36c85e0048)
2021-12-05 09:06:45 +00:00
Jörg Thalheim
1375f6a90c Merge pull request #148642 from Lassulus/buildbot_fix
[21.11] buildbot 3.3.0 -> 3.4.0, unbreak buildbot
2021-12-05 09:05:32 +00:00
maralorn
cdd6fd92ee Merge pull request #148665 from felixsinger/pkgs/coreboot-toolchain/bp-fixes
[Backport release-21.11] coreboot-toolchain: Backport fixes
2021-12-05 06:33:19 +01:00
Maximilian Bosch
295ccf8739 gitea: 1.15.6 -> 1.15.7
ChangeLog: https://github.com/go-gitea/gitea/releases/tag/v1.15.7
(cherry picked from commit da4ca766df)
2021-12-05 05:29:52 +00:00
Andreas Rammhold
6fd68dddc6 coreboot-toolchain: refactor the package set structure
Previously we were unable to override individual attributes within the
coreboot-toolchain packageset. By using callPackage on each of the
attributes individually we retain the ability to call the override
function to inject custom dependencies into the build.

(cherry picked from commit 3cd5413447)
2021-12-05 06:13:51 +01:00
Felix Singer
b9ecb8e3de coreboot-toolchain: Fix building
The sub-packages of coreboot-toolchain don't build currently. Fix that
by using recurseIntoAttrs.

Signed-off-by: Felix Singer <felixsinger@posteo.net>
(cherry picked from commit 39a3cf5367)
2021-12-05 06:13:23 +01:00
Jan Tojnar
1b9a09cbf6 Merge pull request #148662 from NixOS/backport-148658-to-staging-21.11
[Backport staging-21.11] Revert "neard: fix build"
2021-12-05 03:53:25 +01:00
Jan Tojnar
9285e9b70a Merge pull request #148660 from NixOS/backport-148193-to-staging-21.11
[Backport staging-21.11] dbus-python: fix configure dependency on python3
2021-12-05 03:53:05 +01:00
Martin Weinelt
b1fa84f946 Merge pull request #148661 from NixOS/backport-148659-to-release-21.11 2021-12-05 03:51:06 +01:00
Martin Weinelt
1e5b26abfd Merge pull request #148657 from NixOS/backport-147056-to-release-21.11 2021-12-05 03:50:46 +01:00
Jan Tojnar
95a93404d2 Revert "neard: fix build"
It breaks at runtime since it still depends on PyGTK.

https://github.com/NixOS/nixpkgs/pull/148193 is the proper fix.
(cherry picked from commit 341032407f)
2021-12-05 02:34:51 +00:00
Martin Weinelt
3b952e904c nixos/doc/manual/release-notes/rl-2111: add prometheus-smartctl-exporter
(cherry picked from commit 68dc5484e9)
2021-12-05 02:28:01 +00:00
dadada
c7ee4d2a75 dbus-python: fix configure dependency on python3
See https://github.com/NixOS/nixpkgs/pull/144095#pullrequestreview-804181903

(cherry picked from commit 02b507e0dc)
2021-12-05 02:10:49 +00:00
Martin Weinelt
ee2be076a2 nixos/tests/prometheus.exporters.smartctl: init
Starts the exporter, checks it answers via HTTP, checks that it can't
detect the device type of the virtual disk.

(cherry picked from commit 02316a4565)
2021-12-05 02:05:16 +00:00
Martin Weinelt
c3b87cab16 nixos/smartctl-exporter: init
(cherry picked from commit 386a1e79eb)
2021-12-05 02:05:16 +00:00
Martin Weinelt
3f6499829b prometheus-smartctl-exporter: init at unstable-2020-11-14
Includes a rebased version of
https://github.com/prometheus-community/smartctl_exporter/pull/18 which
collided with other patchsets.

(cherry picked from commit 0f4340da1d)
2021-12-05 02:05:16 +00:00
Alyssa Ross
4d50ae3430 apk-tools: 2.12.7 -> 2.12.8
(cherry picked from commit c283a575ab)
2021-12-05 01:13:36 +00:00
Thiago Kenji Okada
6577fea132 Merge pull request #148449 from kyren/shairport-sync-group-fix-backport
[Backport release-21.11] Fix shairport-sync module to create and set an explicit group
2021-12-04 22:09:09 -03:00
Thomas Gerbet
a9323e8b99 wireshark: 3.4.9 -> 3.4.10
https://www.wireshark.org/docs/relnotes/wireshark-3.4.10.html
This release fixes a bunch of security issues.

(cherry picked from commit 6cf2385f15)
2021-12-05 00:36:40 +00:00
github-actions[bot]
4ad06d5a3e Merge staging-next-21.11 into staging-21.11 2021-12-05 00:10:57 +00:00
github-actions[bot]
05dce6121b Merge release-21.11 into staging-next-21.11 2021-12-05 00:10:17 +00:00
Robert Scott
82f811e6ed pure-ftpd: add patch for CVE-2021-40524 2021-12-04 23:51:52 +00:00
Artturi
669f4c6440 Merge pull request #148609 from NixOS/backport-148182-to-release-21.11 2021-12-05 00:28:26 +02:00
Ben Wolsieffer
7ab58a26ad buildbot: 3.3.0 -> 3.4.0
(cherry picked from commit 3721ed202f)
2021-12-04 23:22:28 +01:00
Ben Wolsieffer
7ca03fbdea python3Packages.pyramid_mako: fix compatibility with pyramid>=2.0
Apply a patch taht I have submitted upstream to fix the build.

(cherry picked from commit 020812f37c)
2021-12-04 23:21:11 +01:00
Artturi
f60bdc3a34 Merge pull request #148635 from NixOS/backport-145732-to-release-21.11 2021-12-04 23:35:27 +02:00
gardspirito
fb258cc84f nixos/mx-puppet-discord: provide registration file & fix typo in settings example
(cherry picked from commit a3358146df)
2021-12-04 21:16:48 +00:00
kyren
8061234cc5 Fix shairport-sync module to create and set an explicit group
(cherry picked from commit c23851c)
2021-12-04 15:08:48 -05:00
Pascal Bach
510df24e58 Merge pull request #148587 from Ma27/backport-nc23
[21.11] nextcloud23: init at 23.0.0
2021-12-04 20:52:44 +01:00
Artturin
523e00aed0 pocket-casts: switch to electron_14
(cherry picked from commit 50d7facb9b)
2021-12-04 17:03:34 +00:00
Artturin
dbe84e2bc4 binance: switch to electron_13
electron-14 resulted in blank screen on start

(cherry picked from commit df22f8eeae)
2021-12-04 17:03:34 +00:00
Artturin
8744b4fd5e whalebird: switch to electron_14
(cherry picked from commit 77fd7e9d37)
2021-12-04 17:03:33 +00:00
Artturin
2e91fd0862 thedesk: switch to electron-14
(cherry picked from commit 58546a5f78)
2021-12-04 17:03:33 +00:00
Artturin
872183bd08 etcher: switch to electron_14
(cherry picked from commit 53ded9e4ca)
2021-12-04 17:03:33 +00:00
Artturin
d28bbe114f geogebra6: switch to electron_14
arch uses electron_14 for their package
electron_12 is eol

(cherry picked from commit 3c35508df5)
2021-12-04 17:03:33 +00:00
Artturi
4334bbe638 Merge pull request #148597 from NixOS/backport-147202-to-release-21.11 2021-12-04 18:58:45 +02:00
Konrad Borowski
fc75b17e5c jetbrains: 2021.2.3 -> 2021.3
(cherry picked from commit 3bc5c9a8ac)
2021-12-04 16:53:28 +00:00
voidless
db4208b2c4 geogebra6 6-0-644-0 -> 6-0-676-0
(cherry picked from commit a34736a38f)
2021-12-04 14:58:23 +00:00
Artturi
67f88db7a9 Merge pull request #148500 from NixOS/backport-147032-to-release-21.11
[Backport release-21.11] fwupd: 1.7.1 → 1.7.2
2021-12-04 16:12:22 +02:00
Maximilian Bosch
102d74f679 nextcloud23: init at 23.0.0
Backport #148301 to release-21.11. We have multiple attributes for
different majors, so this is technically a new package that can be
backported.

The defaults aren't changed, so `nextcloud22` is still the default for
NixOS 21.11.

Co-authored-by: Ilan Joselevich <personal@ilanjoselevich.com>
2021-12-04 14:57:53 +01:00
Thiago Kenji Okada
e64d759342 Merge pull request #148577 from NixOS/backport-148457-to-release-21.11
[Backport release-21.11] gnomeExtensions.x11-gestures:  can't find Touchegg
2021-12-04 10:57:09 -03:00
Maximilian Bosch
0f9d299456 grafana: 8.2.5 -> 8.3.0
ChangeLog: https://github.com/grafana/grafana/releases/tag/v8.3.0
(cherry picked from commit 05f3d0b587)
2021-12-04 13:51:24 +00:00
Adson Silva Cicilioti
1bb595d61d gnomeExtensions.x11-gestures: can't find Touchegg
(cherry picked from commit d205f7e6af)
2021-12-04 13:01:40 +00:00
Adson Cicilioti
42188960de gnomeExtensions.x11-gestures: can't find Touchegg
(cherry picked from commit 05e82bfdc2)
2021-12-04 13:01:40 +00:00
Jörg Thalheim
ce487485e9 Merge pull request #148488 from NixOS/backport-148458-to-release-21.11
[Backport release-21.11] nixos/snapraid: relax permissions of snapraid-sync
2021-12-04 12:50:32 +00:00
Vincent Laporte
2f6ec4c215 frama-c: 23.1 (Vanadium) → 24.0 (Chromium)
(cherry picked from commit 5bfd2f00611c1779fcf82e16453f6d2df329f452)
2021-12-04 09:25:42 +00:00
Louis Bettens
3564db559b electrum-ltc: 3.3.8.1 -> 4.0.9.3
rewritten based on the electrum derivation

(cherry picked from commit 719beec27a)
2021-12-04 08:33:33 +00:00
Anderson Torres
66c4ae20a3 Merge pull request #148295 from NixOS/backport-148087-to-release-21.11
[Backport release-21.11] plan9port: add DarwinTools to buildInputs on darwin
2021-12-04 01:40:13 -03:00
Artturi
e34c537986 Merge pull request #148545 from NixOS/backport-148491-to-release-21.11 2021-12-04 05:09:17 +02:00
Artturin
58c73dc0ae nixos/test-driver: add 10ms delay to send_key
attempt to fix https://github.com/NixOS/nixpkgs/issues/147294

(cherry picked from commit 60422ba2ea)
2021-12-04 02:46:59 +00:00
Artturi
a2a9407f40 Revert "nixosTests.keymap.qwertz: reduce platforms in tested" 2021-12-04 04:41:26 +02:00
Artturi
6318fe0780 Merge pull request #148485 from NixOS/backport-148201-to-release-21.11 2021-12-04 04:39:06 +02:00
Thiago Kenji Okada
d4265b506a Merge pull request #148451 from NixOS/backport-148108-to-release-21.11
[Backport release-21.11] nixos/lxd-image-server: fix logrotate
2021-12-03 21:36:07 -03:00
github-actions[bot]
19701f3fae Merge staging-next-21.11 into staging-21.11 2021-12-04 00:09:46 +00:00
github-actions[bot]
f7be4ba5a4 Merge release-21.11 into staging-next-21.11 2021-12-04 00:09:11 +00:00
Martin Weinelt
2e9ef0023d Merge pull request #148419 from mweinelt/21.11/release-notes-fixups 2021-12-04 00:43:33 +01:00
Artturi
0815c6542e Merge pull request #148527 from NixOS/backport-148381-to-release-21.11
[Backport release-21.11] globalprotect-openconnect: use ver rev instead of commit & correct sh…
2021-12-04 01:41:16 +02:00
Artturin
5a7281f32d globalprotect-openconnect: use ver rev instead of commit & correct sha256
(cherry picked from commit cf7ea5b6b5)
2021-12-03 23:10:50 +00:00
Jonathan Ringer
f543cb7329 agate: fix meta
old link is dead

(cherry picked from commit 161d757a3a4bf40a722816c814481353f4be18be)
2021-12-03 12:48:50 -08:00
Artturin
fdbcb5192b nixos/tests: fix nix-serve path
nixos/tests: rename nix-ssh-serve to nix-serve-ssh

nixos/tests/nix-serve-ssh: add --experimental-features

nixos-serve: add nix-serve-ssh to passthru.tests
(cherry picked from commit d87d5731d5)
2021-12-03 21:45:43 +02:00
Martin Weinelt
7a1e329447 Merge pull request #148505 from NixOS/backport-148471-to-release-21.11 2021-12-03 20:39:17 +01:00
Maximilian Bosch
c3e4c445aa nixos/prometheus-postfix-exporter: whitelist addr-family AF_UNIX
Otherwise, `postfix_up{path="/var/lib/postfix/queue/public/showq"}` will
always be `0` indicating an postfix outage because this is a unix domain
socket that cannot be connected to:

    2021/12/03 14:50:46 Failed to scrape showq socket: dial unix /var/lib/postfix/queue/public/showq: socket: address family not supported by protocol

(cherry picked from commit 8e6d403e65)
2021-12-03 19:30:47 +00:00
Jan Tojnar
887feb52f7 fwupd: fix EFI capsule path
This was omitted in 1.7.1 update

(cherry picked from commit 47f11b5c01e4b9e3e4f2d8c6b20531d77b46b157)
2021-12-03 19:03:58 +00:00
Jan Tojnar
4968b5ad7b fwupd: 1.7.1 → 1.7.2
https://github.com/fwupd/fwupd/releases/tag/1.7.2
(cherry picked from commit 1f2da44fcea0b54512de9f3d807c481dcbd4aaee)
2021-12-03 19:03:58 +00:00
Astro
36fffe80cc quake3e: fix libcurl.so.4 location
(cherry picked from commit 863ef0dd47)
2021-12-03 18:45:23 +00:00
Dmitry Kalinkin
159d5def72 pythonPackages.awkward: 1.5.1 -> 1.7.0
(cherry picked from commit cdf88255ce)
2021-12-03 13:32:44 -05:00
github-actions[bot]
7eab4b23da [Backport release-21.11] neovim: prepend extraMakeWrapperArgs in wrapper with a space (#148455)
Co-authored-by: Maximilian Bosch <maximilian@mbosch.me>
2021-12-03 19:29:58 +01:00
Thiago Kenji Okada
e278289055 Merge pull request #148478 from NixOS/backport-148382-to-release-21.11
[Backport release-21.11] nixos/lightdm: fix tmpfile by changing 0 to -
2021-12-03 15:12:12 -03:00
lunik1
7e7260ef02 nixos/snapraid: relax permissions of snapraid-sync
Remove PrivateDevices to silence warning about SnapRAID being
unable to access disk UUIDs.

Add CAP_FOWNER when touch is enabled so file time stamps can be
set.

(cherry picked from commit 6073b099d0)
2021-12-03 18:04:07 +00:00
Artturin
b89763f302 nix-serve: fix NIX_SECRET_KEY_FILE
(cherry picked from commit 2fb77151e8)
2021-12-03 17:55:10 +00:00
Artturin
fe0570ef86 nixos/lightdm: fix tmpfile by changing 0 to -
Closes https://github.com/NixOS/nixpkgs/issues/116631

(cherry picked from commit ebbfccf8a0)
2021-12-03 17:35:02 +00:00
Thiago Kenji Okada
82e2a6f2a4 Merge pull request #148461 from NixOS/backport-148045-to-release-21.11
[Backport release-21.11] mxu11x0: 1.4 -> 4.1
2021-12-03 13:55:40 -03:00
Jörg Thalheim
18d16b291f Merge pull request #148459 from NixOS/backport-147531-to-release-21.11
[Backport release-21.11] python3Packages.flake8-polyfill: disable failing tests
2021-12-03 16:32:52 +00:00
Jörg Thalheim
d27d6f4a6a Merge pull request #148460 from NixOS/backport-147543-to-release-21.11
[Backport release-21.11] llvmPackages_13.libcxx: require gcc >=10 on gcc platforms
2021-12-03 16:24:15 +00:00
Vikram Narayanan
7df5131a3d mxu11x0: 1.4 -> 4.1
(cherry picked from commit 154c9d52dc)
2021-12-03 16:12:37 +00:00
Robert Scott
7f09672a20 llvmPackages_13.libcxx: require gcc >=10 on gcc platforms
specifically aarch64. as of version 13 libcxx does not build on gcc9.

(cherry picked from commit 54a487505a)
2021-12-03 16:10:57 +00:00
Fabian Affolter
b892d2ae7c python3Packages.flake8-polyfill: disable failing tests
(cherry picked from commit 8959f7b211)
2021-12-03 16:09:11 +00:00
Fabian Affolter
cd1f6e8e2d python3Packages.pylint-django: disable failing tests
(cherry picked from commit 82e26e0974)
2021-12-03 16:09:11 +00:00
Fabian Affolter
b6f639c4f3 python3Packages.pep8-naming: add patch to fix tests
(cherry picked from commit d08d54ced8)
2021-12-03 16:09:11 +00:00
Jörg Thalheim
d1beb8af88 Merge pull request #147405 from erictapen/21.11/nbclient
[21.11] python3Packages.nbclient: 0.5.8 -> 0.5.9
2021-12-03 16:07:16 +00:00
Maciej Krüger
b74ba65a70 nixos/lxd-image-server: fix logrotate
(cherry picked from commit 7a89ee6171)
2021-12-03 15:11:16 +00:00
Vincent Laporte
7897c4a1ee coqPackages.equations: 1.2.4 → 1.3 (for Coq 8.13)
(cherry picked from commit ad50413d542d63713778aa2202bcb70dfae91ad9)
2021-12-03 16:03:37 +01:00
Maciej Krüger
bc88b0a142 Merge pull request #148446 from NixOS/backport-147365-to-release-21.11 2021-12-03 15:43:49 +01:00
talyz
0449aeb00a gitlab: 14.5.0 -> 14.5.1
(cherry picked from commit 19494f7eda)
2021-12-03 14:43:40 +00:00
Florian Franzen
695e883639 nixos/waydroid: enable kernel psi interface if required
(cherry picked from commit 64a0cf0df2)
2021-12-03 14:42:09 +00:00
Kim Lindberger
1706baab5e Merge pull request #148297 from NixOS/backport-147848-to-release-21.11
[Backport release-21.11] gitlab: 14.4.2 -> 14.5.0
2021-12-03 15:39:34 +01:00
Thiago Kenji Okada
1b5e2c3ba0 Merge pull request #148440 from NixOS/backport-148432-to-release-21.11
[Backport release-21.11] isync: 1.4.3 -> 1.4.4
2021-12-03 11:29:39 -03:00
Matt Votava
c1968ed909 linux: CONFIG_ASHMEM=y, CONFIG_ANDROID=y
This enables ashmem, binder so waydroid/anbox works with
the provided linux kernel

Cherry-picked from https://github.com/NixOS/nixpkgs/pull/102341

(cherry picked from commit c2e142d8ae)
2021-12-03 14:24:45 +00:00
Alvar Penning
0865894cb8 isync: 1.4.3 -> 1.4.4
Fixes CVE-2021-3657 and CVE-2021-44143 and closes #147884

(cherry picked from commit 8500a748bb)
2021-12-03 14:11:40 +00:00
Thiago Kenji Okada
975ca69ac5 Merge pull request #148429 from NixOS/backport-148423-to-release-21.11
[Backport release-21.11] cargo-wipe: 0.3.1 -> 0.3.2
2021-12-03 10:59:42 -03:00
Robert Scott
1227d3631d Merge pull request #148229 from NixOS/backport-148073-to-release-21.11
[Backport release-21.11] libxc: fix darwin build
2021-12-03 13:28:51 +00:00
Otavio Salvador
76e90c7d13 cargo-wipe: 0.3.1 -> 0.3.2
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit 77c4dbb017)
2021-12-03 12:49:46 +00:00
Gabriel Ebner
4974e7ee9f Merge pull request #148422 from NixOS/backport-148418-to-release-21.11
[Backport release-21.11] m17n_lib: fix m17n-db support
2021-12-03 13:13:02 +01:00
Gabriel Ebner
1be65149a1 m17n_lib: fix m17n-db support
(cherry picked from commit b5b74c914e)
2021-12-03 11:53:31 +00:00
Martin Weinelt
65dce1be45 nixos/doc/manual/release-notes/rl-2111: fix multiple option links
(cherry picked from commit 34d4676e9d)
2021-12-03 12:26:46 +01:00
Martin Weinelt
1eab3303ba nixos/doc/manual/release-notes/rl-2111: move highlights introduction
(cherry picked from commit d1da5658a6)
2021-12-03 12:26:09 +01:00
Jörg Thalheim
19df09617d Merge pull request #148325 from thiagokokada/nix-update-use-nix_2_4
[21.11] nix-update: use nix_2_4
2021-12-03 08:18:31 +00:00
sternenseemann
c64c17e838 haskell.compiler.*: disable useLLVM also for SPARC and PowerPC
These targets also have NCG support, but they are tested less (in fact
SPARC seems to be untested atm) and may have issues. In such cases being
able to fallback to -fllvm without rebuilding the compiler could be
useful. OTOH GHC will default to -fasm and the backends probably work
well enough in most cases.

(cherry picked from commit 8f1a52ac33)
2021-12-02 19:40:03 -08:00
sternenseemann
b81a146d84 haskell.compiler.*: don't useLLVM if aarch64-darwin NCG is available
aarch64-darwin NCG was added in 9.2.1 which makes it unnecessary to
include LLVM in the wrapper.

(cherry picked from commit ef081bf305)
2021-12-02 19:40:03 -08:00
sternenseemann
6fcb0f89bc haskell.compiler.*: use isScript over grepping for #!
(cherry picked from commit a7c564596e)
2021-12-02 19:40:03 -08:00
sternenseemann
b48a21c747 haskell.compiler.*: prefix PATH with runtimeDeps
This will prevent freak accidents where the wrong tools are used because
they are in PATH by chance.

(cherry picked from commit 035f20bc6b)
2021-12-02 19:40:03 -08:00
sternenseemann
4397f7078e pkgsMusl.haskell.compiler.ghc884: return accurate platforms
(cherry picked from commit b2c2215f60)
2021-12-02 19:40:03 -08:00
sternenseemann
9edffdafc5 haskell.compiler.ghc884: re-enable aarch64-linux
Since we inherit the platform list from the bootstrap GHC, we get
differing lists depending on which platform we evaluate the platform
list on (depending on whether 8.10.2 or 8.6.5 is used). This leads to
Hydra thinking aarch64-linux is not supported as it evaluates on
x86_64-linux usually.

(cherry picked from commit 55b8d8c1bf)
2021-12-02 19:40:03 -08:00
sternenseemann
f5d6f58469 haskell.compiler.*: be clear about LLVM build->target role
Since LLVM itself doesn't depend on target at all, this doesn't change
anything *in effect* (i. e. rebuild count should be zero), but it is
more clear about the intention and what LLVM is used for here (i. e. in
depsBuildTarget).

(cherry picked from commit 156d8d619c)
2021-12-02 19:40:03 -08:00
sternenseemann
0c6f4e99e8 haskell.compiler.ghc865Binary: remove aarch64-linux from platforms
GHC 8.6.5 will always segfault on aarch64-linux and at this point
it's not realistic we'll ever fix this.

(cherry picked from commit b9f1582106)
2021-12-02 19:40:03 -08:00
sternenseemann
ce6827cd2e haskell.compiler.*: upgrade to latest supported LLVM version
Source:

* (8.6.5: https://www.haskell.org/ghc/download_ghc_8_6_5.html)
* (8.8.4: https://www.haskell.org/ghc/download_ghc_8_8_4.html)
* (8.10.2: https://www.haskell.org/ghc/download_ghc_8_10_2.html)
* 8.10.7: https://www.haskell.org/ghc/download_ghc_8_10_7.html
* (9.0.1: https://www.haskell.org/ghc/download_ghc_9_0_1.html)
* 9.2.1: https://www.haskell.org/ghc/download_ghc_9_2_1.html
* HEAD: 3ab3631f41/configure.ac (L674)

(cherry picked from commit 9e1f438a76)
2021-12-02 19:40:03 -08:00
sternenseemann
bf91ed77db haskell.compiler.ghc901: drop LLVM version to 9
GHC 9.0.1 only supports LLVM 9 and spews a lot of warnings about LLVM 10
when using the LLVM backend atm.

See also: https://www.haskell.org/ghc/download_ghc_9_0_1.html

(cherry picked from commit 5a568ea36f)
2021-12-02 19:40:03 -08:00
sternenseemann
0061cc84e2 haskellPackages: always inherit llvmPackages from ghc's passthru
This means we only have to update the llvmPackages attribute in one
place now and should prevent situations like with 8.6.5 where different
versions would be used in the package set compared to the compiler
build.

Drop comments in the configuration-ghc-X.Y.x.nix files as well, since
LLVM version isn't tied to the compiler minor version at
all (e. g. 8.10.2 and 8.10.7 have different support ranges).

(cherry picked from commit d7ff8061be)
2021-12-02 19:40:03 -08:00
sternenseemann
1f62b3598b haskell.compiler.ghc865Binary: build with correct LLVM version
See https://gitlab.haskell.org/ghc/ghc/-/wikis/commentary/compiler/backends/llvm/installing#llvm-support

(cherry picked from commit e191321866)
2021-12-02 19:40:03 -08:00
sternenseemann
fe6a47384d ghcWithPackages: rename withLLVM to useLLVM
useLLVM is what we are using in the GHC derivations already -- for
better or for worse -- so we should rename the argument here for
consistency which we are free to do as this is purely internal at the
moment (with overriding being impossible).

(cherry picked from commit c32095b400)
2021-12-02 19:40:03 -08:00
sternenseemann
dc80b6913c ghcWithPackages: GHC 8.10.7 still needs LLVM for aarch64-darwin
This check was wrong and caused by a bit of confusion on my part.
GHC >= 8.10.5 && < 9 supports aarch64-darwin via LLVM and GHC >= 9.2.1
introduces the NCG backend for aarch64-darwin.

(cherry picked from commit 2f98c1824c)
2021-12-02 19:40:03 -08:00
sternenseemann
d6233a1544 ghcWithPackages: list missing targets with NCG available
Based on https://gitlab.haskell.org/ghc/ghc/-/wikis/platforms, although
it sadly doesn't list when the backends were introduced.

* PowerPC, x86 (and x86_64) and Sparc have been supported for longer.

* aarch64-darwin is new in 9.2.1 and backported to 8.10.5, 8.10.6 and
  8.10.7 (check is dumb here since we'll grep for 8.10.7 anyways when
  upgrading)

Fixes ghcWithPackages failing to evaluate on aarch64-darwin because of
missing support for the platform in LLVM 9's compiler-rt.

(cherry picked from commit 571f3e504b)
2021-12-02 19:40:03 -08:00
sternenseemann
940a0e2c66 ghcWithPackages: check targetPlatform to decide if NCG is available
The availability of native codegen (which allows us to disable the LLVM
backend by default) hinges on the target platform of the compiler (that
is GHC), not on the platform it runs on (the host platform).

(cherry picked from commit cfdc073da4)
2021-12-02 19:40:03 -08:00
Alexandre Esteves
facbbb48eb ghcHEAD: fix mingw build
(cherry picked from commit 8c17cc993b)
2021-12-02 19:40:03 -08:00
Jakub Kozłowski
45c527ae2d scala-cli: 0.0.8 -> 0.0.9
(cherry picked from commit 2b7b0684e4afc1df3ffcf2b6844070b91482bd21)
2021-12-02 19:13:42 -08:00
John Ericson
6a18930500 Merge pull request #148369 from NixOS/backport-147983-to-release-21.11
[Backport release-21.11] top-level: add depsHostHost splicing
2021-12-02 22:03:16 -05:00
Jakub Kozłowski
a797c56f8b bloop: 1.4.9 -> 1.4.11
(cherry picked from commit e6902ae93dbb8a2183c1b2e081ebe94996945c6b)
2021-12-02 18:37:50 -08:00
Jakub Kozłowski
6de8e9faa1 bloop: add kubukoz as maintainer
(cherry picked from commit d69f9000713e3b648227fc5379fa5421e4b88217)
2021-12-02 18:37:50 -08:00
Thiago Kenji Okada
ea6a2ad7c6 Merge pull request #148356 from NixOS/backport-148324-to-release-21.11
[Backport release-21.11] babashka: 0.6.7 -> 0.6.8
2021-12-02 23:24:54 -03:00
Ryan Burns
b3bd76908f top-level: add depsHostHost splicing
This was originally made to throw because pkgsHostHost was unimplemented.
Now that we have the full range of pkgs*, we can add this normally.

(cherry picked from commit c47f991435)
2021-12-03 02:06:23 +00:00
Martin Weinelt
109e3dc72f python39: backport patch to accomodate system library changes in Big Sur
(cherry picked from commit 9738723b2486cfe9988abbff0c873cce5cba1849)
(cherry picked from commit a43a2eacb322c3799aa6eadd0061db1a3c176b78)
2021-12-03 02:04:08 +00:00
midchildan
e5fbea2a22 llvmPackages_git: build with llvmPackages_11 on Darwin 2021-12-02 17:47:58 -08:00
midchildan
311bb78e27 llvmPackages_git.libcxx: fix darwin build
(cherry picked from commit 24d1fc7c73)
2021-12-02 17:47:58 -08:00
Ryan Burns
ef37b192f3 llvmPackages_{13,git}.clang: build clang-tools-extra
This is already done for previous versions of clang which use
a release tarball, but must be done differently for the more
recent versions which use fetchFromGitHub.

Fixes clang-tools clangd wrapper

(cherry picked from commit dd8ad828de)
2021-12-02 16:20:00 -08:00
github-actions[bot]
710ad3f424 Merge staging-next-21.11 into staging-21.11 2021-12-03 00:10:33 +00:00
github-actions[bot]
6cb2febbc1 Merge release-21.11 into staging-next-21.11 2021-12-03 00:09:56 +00:00
Thiago Kenji Okada
bc370a619c babashka: 0.6.7 -> 0.6.8
(cherry picked from commit 6b2b907130)
2021-12-02 23:20:37 +00:00
nixinator
edd037b151 xsos:init at 0.7.19
(cherry picked from commit 18bab16610)
2021-12-02 22:52:31 +00:00
Patrick Hilhorst
dc6b93f729 Merge pull request #148309 from NixOS/backport-147297-to-release-21.11 2021-12-02 22:19:06 +01:00
Michael Weiss
050a92eb4d Merge pull request #148214 from NixOS/backport-148210-to-release-21.11
[Backport release-21.11] signal-desktop: 5.24.0 -> 5.25.0
2021-12-02 21:37:07 +01:00
Thiago Kenji Okada
75f67433e2 nix-update: use nix_2_4 2021-12-02 17:26:55 -03:00
Artturi
94724efb7b Merge pull request #148272 from NixOS/backport-148270-to-release-21.11 2021-12-02 22:03:41 +02:00
Tom
44ffab49ce wl-mirror: init at 0.5.0
(cherry picked from commit b71ed45cfc)
2021-12-02 20:58:42 +01:00
Thiago Kenji Okada
3233d16907 Merge pull request #148320 from NixOS/backport-148285-to-release-21.11
[Backport release-21.11] pop-icon-theme: remove some dependencies
2021-12-02 16:53:50 -03:00
Patrick Hilhorst
438448ba85 Merge pull request #148314 from NixOS/backport-147296-to-release-21.11 2021-12-02 20:47:24 +01:00
José Romildo
10fa59eb03 pop-icon-theme: restrict platforms to linux
(cherry picked from commit 82ee5f20c7)
2021-12-02 19:20:37 +00:00
José Romildo
b9d4794ff9 pop-icon-theme: remove some dependencies
- Some third-party inherits have been removed from the icon theme by
upstream. See https://github.com/pop-os/icon-theme/pull/100

(cherry picked from commit 2ae84eb551)
2021-12-02 19:20:37 +00:00
Robert Hensing
db6bea6809 Merge pull request #148255 from NixOS/backport-147049-to-release-21.11
[Backport release-21.11] nixops: fix dependencies
2021-12-02 19:52:54 +01:00
Tom
61be44a7ee wlr-protocols: init at unstable-2021-11-01
(cherry picked from commit 3664cbde79)
2021-12-02 18:30:11 +00:00
Martin Weinelt
8e87ea5566 Merge pull request #148242 from dotlambda/21.11-fix-home-assistant 2021-12-02 19:01:15 +01:00
AmineChikhaoui
5ba0850e6b ec2-amis: add release 21.11
(cherry picked from commit 779b40baac7503fb33fa4fe47ff77d409bb8c797)
2021-12-02 12:05:02 -05:00
Sumner Evans
49e82dfdce element-desktop: 1.9.4 -> 1.9.5
(cherry picked from commit e0eb89f391)
2021-12-02 16:49:23 +00:00
Maximilian Bosch
6ab547310f roundcube: 1.5.0 -> 1.5.1
ChangeLog: https://github.com/roundcube/roundcubemail/releases/tag/1.5.1
(cherry picked from commit ce91a90d7a)
2021-12-02 16:47:21 +00:00
Yureka
6a055ab17b gitaly: use custom libgit2 commit
(cherry picked from commit f146c92955)
2021-12-02 16:33:41 +00:00
Lara
42f9ff6178 gitlab: 14.4.2 -> 14.5.0
(cherry picked from commit e2668f6a7b)
2021-12-02 16:33:41 +00:00
Jörg Thalheim
df84d3ea84 Merge pull request #148291 from NixOS/backport-148256-to-release-21.11
[Backport release-21.11] mcomix: fix invalid .desktop icon name
2021-12-02 16:30:42 +00:00
Yestin L. Harrison
aad23cbae5 plan9port: add DarwinTools to buildInputs on darwin
(cherry picked from commit 0fd4de2ae2)
2021-12-02 16:28:07 +00:00
Jörg Thalheim
33bef262ce Merge pull request #148292 from NixOS/backport-148262-to-release-21.11
[Backport release-21.11] python3Packages.pyarrow: fix darwin build for when a build flag is false
2021-12-02 16:11:23 +00:00
Dmitry Kalinkin
149b64d8eb python3Packages.pyarrow: fix darwin build for when a build flag is false
nix-repl> with import <nixpkgs> {}; stdenv.mkDerivation { name="test"; true = true; false = false; }
«derivation /nix/store/2xk4hhfnaqymwq0iw9hxi5a34a8dbywz-test.drv»

nix show-derivation /nix/store/2xk4hhfnaqymwq0iw9hxi5a34a8dbywz-test.drv | grep -E '(true|false)'
      "false": "",
      "true": "1"

  File "setup.py", line 77, in strtobool
    raise ValueError("invalid truth value %r" % (val,))
ValueError: invalid truth value ''

(cherry picked from commit e5690827b5)
2021-12-02 15:38:47 +00:00
Anund
38009c349c mcomix: fix invalid .desktop icon name
The postInstall step for this package copies an icon to the hicolor icon
theme under the name mcomix3.png (${pname}). The applications
mcomix.desktop references the icon by Icon=mcomix. The means the copied
icon ends up with the "wrong" filename making lookup following the xdg
standard break. This change updates the icon reference in the .desktop
file to match what is currently being installed.

(cherry picked from commit f524d70519)
2021-12-02 15:37:42 +00:00
Maximilian Bosch
349de46036 clipman: 1.6.0 -> 1.6.1
ChangeLog: https://github.com/yory8/clipman/releases/tag/v1.6.1
(cherry picked from commit 2d02482582)
2021-12-02 15:09:19 +00:00
Jörg Thalheim
84ecf2489b qemu: fix darwin build
(cherry picked from commit 56ea0c9308)
2021-12-02 14:46:27 +00:00
Maximilian Bosch
5d7a669191 strace: 5.14 -> 5.15
ChangeLog: https://github.com/strace/strace/releases/tag/v5.15
(cherry picked from commit a0909777c8626fcb6d7f3fd8b0f978bf867265fc)
2021-12-02 14:34:01 +00:00
Thiago Kenji Okada
80e818c0fb Merge pull request #148275 from NixOS/backport-148245-to-release-21.11
[Backport release-21.11] flat-remix-icon-theme: 20200710 -> 20211106
2021-12-02 11:00:13 -03:00
Thiago Kenji Okada
14751b965d Merge pull request #148276 from NixOS/backport-148239-to-release-21.11
[Backport release-21.11] pop-gtk-theme: 2020-06-30 -> 2021-08-19
2021-12-02 10:59:07 -03:00
Robert Schütz
6bb4295706 python2Packages.construct: skip tests that require broken packages
(cherry picked from commit 192bbb938c)
2021-12-02 10:50:22 -03:00
Robert Schütz
f5d477195e python3Packages.html5lib: use pytestCheckHook
(cherry picked from commit 49cf63ccc9)
2021-12-02 10:50:22 -03:00
Thiago Kenji Okada
83992d6137 Merge pull request #148243 from NixOS/backport-148212-to-release-21.11
[Backport release-21.11] hydrus: 463 -> 464
2021-12-02 10:45:56 -03:00
Thiago Kenji Okada
e88cab3e79 Merge pull request #148269 from NixOS/backport-147395-to-release-21.11
[Backport release-21.11] coqPackages.coqprime: 8.12 → 8.14.1
2021-12-02 10:45:29 -03:00
Thiago Kenji Okada
6cd5b2319a Merge pull request #148266 from NixOS/backport-148248-to-release-21.11
[Backport release-21.11] zerotierone: 1.8.3 -> 1.8.4
2021-12-02 10:44:33 -03:00
José Romildo Malaquias
d368991563 Merge pull request #148277 from NixOS/backport-148246-to-release-21.11
[Backport release-21.11] pop-icon-theme: 2020-03-04 -> 2021-11-17
2021-12-02 10:44:28 -03:00
Thiago Kenji Okada
7c0be839d2 Merge pull request #148273 from NixOS/backport-147641-to-release-21.11
[Backport release-21.11] mathematica: Install desktop items
2021-12-02 10:42:56 -03:00
Adson Cicilioti
862c245ff0 pop-icon-theme: 2020-03-04 -> 2021-11-17
(cherry picked from commit 9487f3aeba)
2021-12-02 13:37:24 +00:00
Adson Cicilioti
7055f06d2f flat-remix-icon-theme: 20200710 -> 20211106
(cherry picked from commit 552f9ca765)
2021-12-02 13:35:12 +00:00
Adson Cicilioti
6da2b6fad6 pop-gtk-theme: 2020-06-30 -> 2021-08-19
(cherry picked from commit bf8af0b8d4)
2021-12-02 13:35:11 +00:00
qbg
a6d2090240 mathematica: prefer substituteInPlace over sed
Reduces the amount of escaping needed for these literal string replacements.

(cherry picked from commit 2bdaa8d08300460f24bb3be13e99a6a658ae4207)
2021-12-02 13:21:22 +00:00
qbg
0a95797646 mathematica: Install desktop items
Install the desktop items so users can launch Mathematica from their desktop environment, notebooks are associated with Mathematica, etc.

(cherry picked from commit 97da277f17313357cf38f1a2e744fdc1e42aa168)
2021-12-02 13:21:22 +00:00
Artturin
7fcd125916 snappy: add patch to re-enable RTTI
(cherry picked from commit a810f7676c)
2021-12-02 13:15:09 +00:00
Vincent Laporte
a236047f54 coqPackages.coqprime: 8.12 → 8.14.1
(cherry picked from commit 35d7106031202a336559da0fe17e50fc9aa2dd77)
2021-12-02 12:21:35 +00:00
misuzu
3be672b10a zerotierone: 1.8.3 -> 1.8.4
(cherry picked from commit c89523fd1ebd81a26e1f221bd634dfe68dfa7225)
2021-12-02 11:10:00 +00:00
Maciej Krüger
6525c02d2b Merge pull request #148260 from NixOS/backport-148237-to-release-21.11 2021-12-02 11:53:12 +01:00
Adson Cicilioti
38ac24be75 flat-remix-gtk: 20201129 -> 20211130
(cherry picked from commit d86329b7cd)
2021-12-02 10:26:56 +00:00
Mario Rodas
2d03af3737 Merge pull request #148254 from NixOS/backport-147343-to-release-21.11
[Backport release-21.11] ruby: 2.7.4 -> 2.7.5, 3.0.2 -> 3.0.3
2021-12-02 05:21:21 -05:00
Charlotte Van Petegem
67999f351b ruby: 2.7.4 -> 2.7.5, 3.0.2 -> 3.0.3
(cherry picked from commit 26038de225)
2021-12-02 09:28:59 +00:00
Robert Schütz
4763215938 home-assistant: downgrade dependencies
https://github.com/NixOS/nixpkgs/pull/145602 introduced versions of
aiohttp and async_timeout that are incompatible with Home Assistant and
many of its dependencies.  Since reverting that PR would be a mass
rebuild we only switch back to the old versions for Home Assistant.
2021-12-01 20:52:01 -08:00
Daniel Olsen
bd150e03e0 hydrus: 463 -> 464
(cherry picked from commit ecb836f4dd)
2021-12-02 04:48:02 +00:00
github-actions[bot]
5b80f23502 nss: 3.72 -> 3.73 (#148228)
Update done by running the `nss` and `cacert` update scripts, then
running nixpkgs-check to validate things look good enough to be thrown
at hydra

(cherry picked from commit bb64e52399592decc6f0c7ef26f8ebde1f960dac)

Co-authored-by: Léo Gaspard <leo@gaspard.io>
2021-12-02 02:54:34 +01:00
Thiago Kenji Okada
78bca059cd Merge pull request #148231 from NixOS/backport-148220-to-release-21.11
[Backport release-21.11] materia-theme: 20200916 -> 20210322
2021-12-01 22:29:14 -03:00
Thiago Kenji Okada
0d3c5de1f6 Merge pull request #148230 from NixOS/backport-148183-to-release-21.11
[Backport release-21.11] pinta: 1.6 -> 1.7.1
2021-12-01 22:15:44 -03:00
Adson Cicilioti
5c44296795 materia-theme: 20200916 -> 20210322
(cherry picked from commit 5b0af75786)
2021-12-02 01:09:07 +00:00
Thiago Kenji Okada
7c19ae4aa6 pinta: 1.6 -> 1.7.1
(cherry picked from commit 5dfface8d5)
2021-12-02 00:50:30 +00:00
Robert Scott
93dcace9ac libxc: fix darwin build
(cherry picked from commit f0a01556c7)
2021-12-02 00:40:17 +00:00
github-actions[bot]
270e4b69e7 Merge staging-next-21.11 into staging-21.11 2021-12-02 00:10:12 +00:00
github-actions[bot]
02e129d2b2 Merge release-21.11 into staging-next-21.11 2021-12-02 00:09:32 +00:00
Michael Weiss
9b715717c3 signal-desktop: 5.24.0 -> 5.25.0
(cherry picked from commit 755320fe14)
2021-12-01 22:54:50 +00:00
Artturi
ba8956c791 Merge pull request #147925 from NixOS/backport-147733-to-release-21.11 2021-12-02 00:42:58 +02:00
Artturi
89e203c9f0 Merge pull request #147918 from NixOS/backport-128145-to-release-21.11 2021-12-02 00:41:41 +02:00
Thiago Kenji Okada
ca6663117f Merge pull request #147932 from NixOS/backport-144454-to-release-21.11
[Backport release-21.11] jpsxdec: init at 1.05
2021-12-01 19:35:27 -03:00
Thiago Kenji Okada
dd982189c1 Merge pull request #148025 from NixOS/backport-147718-to-release-21.11
[Backport release-21.11] python3Packages.pyarrow: enable dataset and flight modules
2021-12-01 19:30:04 -03:00
Thiago Kenji Okada
d36c4c8643 Merge pull request #147978 from NixOS/backport-146824-to-release-21.11
[Backport release-21.11] aws-c-*: bump to latest
2021-12-01 19:29:27 -03:00
Thiago Kenji Okada
803414a638 Merge pull request #147931 from NixOS/backport-146464-to-staging-21.11
[Backport staging-21.11] postgresql: 9.6.23 -> 9.6.24, 10.18 -> 10.19, 11.13 -> 11.14, 12.8 -> 12.9, 13.4 -> 13.5, 14.0 -> 14.1
2021-12-01 19:28:33 -03:00
Thiago Kenji Okada
57d71010ef Merge pull request #148032 from NixOS/backport-148005-to-release-21.11
[Backport release-21.11] warzone2100: 4.2.2 -> 4.2.3
2021-12-01 19:27:43 -03:00
Thiago Kenji Okada
40fa883937 Merge pull request #148200 from NixOS/backport-147719-to-release-21.11
[Backport release-21.11] unbound-full: fix the build again
2021-12-01 19:26:20 -03:00
Martin Weinelt
fbba9e7af5 Merge pull request #148202 from NixOS/backport-148180-to-release-21.11 2021-12-01 23:15:38 +01:00
Thiago Kenji Okada
493198e0d6 Merge pull request #148192 from NixOS/backport-148188-to-release-21.11
[Backport release-21.11] clj-kondo: 2021.10.19 -> 2021.12.01
2021-12-01 18:58:58 -03:00
Martin Weinelt
563375a223 esphome: apply patch to fix subprocess usage
(cherry picked from commit a542c7c8c5)
2021-12-01 21:28:13 +00:00
Martin Weinelt
7743501941 esphome: 2021.10.1 -> 2021.11.4
(cherry picked from commit f69af24c74)
2021-12-01 21:28:13 +00:00
Vladimír Čunát
d868445b74 unbound-full: fix the build again
... by not avoiding openssl dependency in .lib.
dnstap part of code ran into issues with this during checkPhase.

The benefit of withSlimLib is mainly for `unbound`;
for the fuller builds it doesn't seem important.

(cherry picked from commit 9a0723cc3f)
2021-12-01 21:20:23 +00:00
Thiago Kenji Okada
1401612c84 clj-kondo: 2021.10.19 -> 2021.12.01
(cherry picked from commit 1195e8cecc)
2021-12-01 20:49:59 +00:00
Kira Bruneau
301179fade Merge pull request #148187 from NixOS/backport-148093-to-release-21.11
[Backport release-21.11] protontricks: 1.6.1 → 1.6.2
2021-12-01 15:29:02 -05:00
Kira Bruneau
7c0aac7a63 protontricks: 1.6.1 → 1.6.2
(cherry picked from commit bc25e8f24f)
2021-12-01 20:22:42 +00:00
Martin Schwaighofer
82dab2172a qemu, runInLinuxVM: change default cpu to qemu64
The flag -cpu max leaves QEMU 6.1.0 stuck on some systems,
for example when /dev/kvm is not read-writable.
This does not happen with -cpu qemu64.

Getting stuck like that is a regression in 6.1.0 not yet present in 6.0.0
and should be fixed with 6.2.0 according to early testing with rc1.

We should consider reverting this change when we merge QEMU 6.2.0.
See #146526.

fixes #141596

(cherry picked from commit abbe8cbc4843c213947abef70eb11f10ebea96f1)
2021-12-01 19:49:34 +00:00
Martin Schwaighofer
5aafeded5b qemu: emit warnings when KVM acceleration is not usable
This fixes the qemu-kvm wrapper we add for convenience
silently not using KVM, when the system would support it
by at least leaving an indication in the log that the build ran
slower because it ran without KVM.

(cherry picked from commit 5718276542100f9e779f2c2113e3d0f6c45da054)
2021-12-01 19:49:34 +00:00
Martin Schwaighofer
fd5d262d79 qemu, runInLinuxVM: fix KVM availability check
KVM should only be considered abailable if /dev/kvm exists and
is read-writable by the user that is trying to launch it.

The previous check for existance only had the consequence that
on some Linux distributions running VMs with Nix's QEMU only worked
if KVM was NOT installed.

fixes #124371

(cherry picked from commit 046392279ca41abc36e61a839d4679e40f6e9a3c)
2021-12-01 19:49:34 +00:00
Robert Hensing
15e3d0cecd Merge pull request #148173 from NixOS/backport-140992-to-release-21.11
[Backport release-21.11] Add aarch64 AMIs
2021-12-01 20:21:33 +01:00
Robert Hensing
1d5cfac9f1 amazon-ec2-amis: Add aarch64 amis
(cherry picked from commit 00563d4f07)
2021-12-01 18:00:58 +00:00
Robert Hensing
eab845a526 ec2-amis.nix -> amazon-ec2-amis.nix, new format
(cherry picked from commit 5a6c43dda3)
2021-12-01 18:00:58 +00:00
Dmitry Kalinkin
19b97c8698 Merge pull request #148148 from veprbl/pr/tensorflow_h5py_patch
[21.11] python3Packages.tensorflow: patch for compatibility with h5py 3.0.0+
2021-12-01 12:18:09 -05:00
Vincent Laporte
a640d8394f compcert: fix for Coq 8.14.1
(cherry picked from commit 482c273534482e95000c4419a213788dddbfb159)
2021-12-01 16:06:54 +01:00
Thiago Kenji Okada
7391cce2c8 Merge pull request #148155 from NixOS/backport-148100-to-release-21.11
[Backport release-21.11] ncspot: 0.9.0 -> 0.9.2
2021-12-01 11:47:41 -03:00
Mario Rodas
c6df6d5094 ncspot: 0.9.0 -> 0.9.2
https://github.com/hrkfdn/ncspot/releases/tag/v0.9.1
https://github.com/hrkfdn/ncspot/releases/tag/v0.9.2
(cherry picked from commit eea9da363d)
2021-12-01 13:57:26 +00:00
Thiago Kenji Okada
0e776e0edc Merge pull request #148081 from NixOS/backport-147598-to-release-21.11
[Backport release-21.11] suricata: 6.0.3 -> 6.0.4
2021-12-01 10:43:40 -03:00
Thiago Kenji Okada
84e509d8a3 Merge pull request #148074 from NixOS/backport-147390-to-release-21.11
[Backport release-21.11] matrix-synapse: 1.47.1 -> 1.48.0
2021-12-01 10:43:14 -03:00
Thiago Kenji Okada
06a8de434e Merge pull request #148118 from NixOS/backport-148096-to-release-21.11
[Backport release-21.11] mrtrix: 3.0.2 -> unstable-2021-11-25
2021-12-01 10:41:39 -03:00
Francesco Gazzetta
5b0c1f79dd nixosTests.vengi-tools: init
(cherry picked from commit 324e9f686e)
2021-12-01 08:35:27 -05:00
Francesco Gazzetta
70a50a33ce vengi-tools: init at 0.0.14
(cherry picked from commit 218f143514)
2021-12-01 08:35:27 -05:00
Thiago Kenji Okada
3ed1b7b023 Merge pull request #148126 from NixOS/backport-148069-to-release-21.11
[Backport release-21.11] pythonPackages.debugpy: add aarch64-linux compile flags
2021-12-01 10:27:46 -03:00
Dmitry Kalinkin
3ffa5512dc [21.11] python3Packages.tensorflow: patch for compatibility with h5py 3.0.0+ 2021-12-01 08:25:08 -05:00
Thiago Kenji Okada
ef6d032a6e Merge pull request #148142 from NixOS/backport-147249-to-release-21.11
[Backport release-21.11] coq_8_14: 8.14.0 → 8.14.1
2021-12-01 10:23:32 -03:00
Vincent Laporte
37a7d2c271 coq_8_14: 8.14.0 → 8.14.1
And build Coq ≥ 8.14 with OCaml 4.12

(cherry picked from commit 7c973564b86f4cd9d755afcf78f21f7b258c2ab6)
2021-12-01 12:50:54 +00:00
Vincent Laporte
abca7d975e coqPackages.serapi: remove with Coq 8.14
(cherry picked from commit 0b40bc9df9ff70ba17773ba4c9cf3c5ee7163aac)
2021-12-01 12:50:54 +00:00
Vincent Laporte
bbb796562b ocamlPackages.merlin: 4.3.1 → 4.4
(cherry picked from commit 0c5915f44389e0dc844872128937b83bbd0bd333)
2021-12-01 13:45:55 +01:00
Bobby Rong
3cd2f44f81 Merge pull request #148119 from NixOS/backport-147374-to-release-21.11
[Backport release-21.11] stretchly: 1.7.0 -> 1.8.1
2021-12-01 19:55:58 +08:00
Mauricio Collares
55f738bf77 pythonPackages.debugpy: add aarch64-linux compile flags
(cherry picked from commit ed5709050c)
2021-12-01 11:24:57 +00:00
Bobby Rong
ca074856ea Merge pull request #148120 from NixOS/backport-148092-to-release-21.11
[Backport release-21.11] lush2: remove package
2021-12-01 18:55:45 +08:00
Vikram Narayanan
b36a27af4c lush2: remove package
No releases or activity after v2.0.1 (since 2011)

(cherry picked from commit 12cb138006)
2021-12-01 10:37:38 +00:00
oxalica
6676054884 stretchly: 1.7.0 -> 1.8.1
It contains the fix of a critical bug which which shows empty window and
basically lock users out.
4f0df79bc6

(cherry picked from commit edc83a9bf0)
2021-12-01 10:33:09 +00:00
Vikram Narayanan
5867d6cdd8 mrtrix: 3.0.2 -> unstable-2021-11-25
The latest stable version fails to build with latest eigen (> 3).
https://github.com/MRtrix3/mrtrix3/pull/2368

(cherry picked from commit b1d95dca56)
2021-12-01 10:31:19 +00:00
Jörg Thalheim
397351c53e Merge pull request #147998 from Mic92/nix-direnv
[21.11]: fix useFlake in nix-direnv
2021-12-01 10:11:09 +00:00
Bobby Rong
b31ca028d7 Merge pull request #147369 from bobby285271/pantheon-stable
[21.11] Pantheon 6.0.4
2021-12-01 16:15:25 +08:00
Artturi
3ea8b118b2 Merge pull request #148078 from NixOS/backport-148002-to-release-21.11
[Backport release-21.11] nextcloud21: 21.0.5 -> 21.0.7
2021-12-01 09:33:44 +02:00
Artturi
828ff2bb85 Merge pull request #148057 from NixOS/backport-146533-to-release-21.11
[Backport release-21.11] nixos/nginx: fix start when recommendedOptimisation is off
2021-12-01 09:31:22 +02:00
Maciej Krüger
3c8b28abda Merge pull request #148105 from NixOS/backport-148097-to-release-21.11 2021-12-01 08:00:44 +01:00
zowoq
71547a6a00 yt-dlp: 2021.11.10.1 -> 2021.12.1
https://github.com/yt-dlp/yt-dlp/releases/tag/2021.12.01
(cherry picked from commit 5ecb046485)
2021-12-01 06:40:18 +00:00
Artturi
c7b4ee906c Merge pull request #147949 from NixOS/backport-147560-to-release-21.11 2021-12-01 05:56:03 +02:00
github-actions[bot]
a5afff6cbd Merge staging-next-21.11 into staging-21.11 2021-12-01 00:11:22 +00:00
github-actions[bot]
5dd82408fb Merge release-21.11 into staging-next-21.11 2021-12-01 00:10:48 +00:00
Thomas Gerbet
644525083a suricata: 6.0.3 -> 6.0.4
https://forum.suricata.io/t/suricata-6-0-4-and-5-0-8-released/1942
Fixes CVE-2021-37592.

(cherry picked from commit 856a428ecf)
2021-11-30 22:30:11 +00:00
Robert Scott
6bfd8c700f Merge pull request #148018 from NixOS/backport-147935-to-release-21.11
[Backport release-21.11] cppe, python3Packages.cppe: fix build with clang
2021-11-30 22:24:33 +00:00
philipp
f2f48f1c01 nextcloud21: 21.0.5 -> 21.0.7
(cherry picked from commit b5a27cef4b)
2021-11-30 21:41:47 +00:00
Sumner Evans
88a4d7d1f4 matrix-synapse: 1.47.1 -> 1.48.0
(cherry picked from commit 1b6daffd84)
2021-11-30 21:23:26 +00:00
Artturi
41eb5d0d3b Merge pull request #148056 from NixOS/backport-147635-to-release-21.11 2021-11-30 22:54:06 +02:00
Thiago Kenji Okada
2e0e4c1bd9 Merge pull request #148030 from NixOS/backport-148022-to-release-21.11
[Backport release-21.11] babashka: 0.6.5 -> 0.6.7
2021-11-30 17:26:15 -03:00
Sandro
6a65c74d12 nixos/nginx: fix start when recommendedOptimisation is off
Also done by other distros for example Fedora https://bodhi.fedoraproject.org/updates/FEDORA-2020-78690e2cdd

(cherry picked from commit 9cb930ff68)
2021-11-30 20:20:46 +00:00
Vikram Narayanan
531dae6532 vowpalwabbit: fix build
(cherry picked from commit 9c431b8569)
2021-11-30 20:19:22 +00:00
Robert Scott
f1d1b6b55a Merge pull request #147988 from NixOS/backport-147954-to-release-21.11
[Backport release-21.11] python3Packages.pyvex: fix build for aarch64-linux
2021-11-30 20:13:20 +00:00
Kerstin Humm
35d624300b scribusUnstable: patch for harfbuzz 3.0
(cherry picked from commit 283e178e6c)
2021-11-30 20:15:03 +01:00
Kerstin Humm
8342db590d scribusUnstable: clarify license
(cherry picked from commit 79e5ac3df4)
2021-11-30 20:15:03 +01:00
Artturi
7f4c97e1e1 Merge pull request #147961 from NixOS/backport-147939-to-release-21.11 2021-11-30 20:16:20 +02:00
Artturi
5ef932f972 Merge pull request #147976 from NixOS/backport-147967-to-release-21.11 2021-11-30 20:10:43 +02:00
Francesco Gazzetta
f366a8caa3 warzone2100: 4.2.2 -> 4.2.3
(cherry picked from commit 87aed70b18)
2021-11-30 16:39:08 +00:00
Thiago Kenji Okada
44a450dc8b babashka: 0.6.5 -> 0.6.7
(cherry picked from commit 6700494410)
2021-11-30 16:10:21 +00:00
Sandro
0785e6316b Merge pull request #148023 from thiagokokada/nixpkgs-review-use-nix-24 2021-11-30 17:05:36 +01:00
Phillip Cloud
15be21ccfb python3Packages.pyarrow: enable flight module
(cherry picked from commit da8dfd5128)
2021-11-30 15:07:10 +00:00
Phillip Cloud
c43ec919ae python3Packages.pyarrow: enable dataset module
(cherry picked from commit 442468f4ad)
2021-11-30 15:07:10 +00:00
Thiago Kenji Okada
f3757e3320 nixpkgs-review: use nix_2_4 2021-11-30 11:55:52 -03:00
Robert Scott
d7839267cb python3Packages.cppe: fix build with clang
(cherry picked from commit f2ce374855)
2021-11-30 14:04:23 +00:00
Robert Scott
2ebca01c80 cppe: fix build with clang
(cherry picked from commit 7cbda5539d)
2021-11-30 14:04:23 +00:00
github-actions[bot]
96b4157790 nixos/acme: fix typo in docs
(cherry picked from commit 1e3b1e19aa49d47cc663db1b07312dd1fbe6fef8)

Co-authored-by: Roman Frołow <rofrol@gmail.com>
2021-11-30 21:39:06 +08:00
Jörg Thalheim
5f9bb7f371 nix-direnv: use nix_2_4
fixes https://github.com/NixOS/nixpkgs/issues/147974
2021-11-30 11:03:20 +01:00
Jörg Thalheim
09ec5e68dc Revert "nix-direnv: use nix (2.4) and remove enableFlakes"
This reverts commit c03040cfd5.
2021-11-30 10:57:42 +01:00
Bobby Rong
9fd82b4dd0 pantheon.elementary-files: drop filechooser-portal-hardcode-gsettings-for-nixos.patch
(cherry picked from commit 0a989ec7ca)
2021-11-30 17:10:39 +08:00
Bobby Rong
5b966518ce pantheon.elementary-files: 6.0.4 -> 6.1.0
(cherry picked from commit 94d1b0d541)
2021-11-30 17:10:39 +08:00
Bobby Rong
36c54caf30 pantheon.elementary-code: remove zeitgeist from buildInputs
(cherry picked from commit c0966f8571)
2021-11-30 17:10:39 +08:00
Bobby Rong
3421916499 pantheon.switchboard: remove clutter-gtk from buildInputs
(cherry picked from commit b1005e8b3d)
2021-11-30 17:10:39 +08:00
Bobby Rong
2a4446a175 pkgs/pantheon: remove unused pantheon from args
(cherry picked from commit 7bec0408e7)
2021-11-30 17:10:38 +08:00
Bobby Rong
dd160ba3c7 pantheon.switchboard-plug-onlineaccounts: 6.2.1 -> 6.2.2
(cherry picked from commit 9949f1009d)
2021-11-30 17:10:38 +08:00
Bobby Rong
f8bd98726b pantheon.wingpanel-indicator-datetime: use upstreamed patch
(cherry picked from commit ca71d0b22a)
2021-11-30 17:10:38 +08:00
Bobby Rong
3ae62e6e62 pantheon.wingpanel-applications-menu: 2.9.1 -> 2.10.1
(cherry picked from commit a54db1668b)
2021-11-30 17:10:38 +08:00
Bobby Rong
da475fa087 pantheon.gala: 6.2.1 -> 6.3.0
(cherry picked from commit d5aaed533c)
2021-11-30 17:10:38 +08:00
Bobby Rong
15a7a81611 pantheon.elementary-code: 6.0.1 -> 6.1.0
(cherry picked from commit 5a61f08144)
2021-11-30 17:10:38 +08:00
Bobby Rong
a4a01603fa pantheon.elementary-dock: unstable-2021-07-16 -> unstable-2021-11-08
(cherry picked from commit 7e43f2f850)
2021-11-30 17:10:37 +08:00
Bobby Rong
80cf8a68b7 pantheon.elementary-icon-theme: 6.0.0 -> 6.1.0
(cherry picked from commit 87a5c67107)
2021-11-30 17:10:37 +08:00
Bobby Rong
4826051256 pantheon.elementary-gtk-theme: 6.1.0 -> 6.1.1
(cherry picked from commit 2361a73786)
2021-11-30 17:10:37 +08:00
Bobby Rong
2a4ad08206 pantheon.granite: 6.1.2 -> 6.2.0
(cherry picked from commit 110e1931ce)
2021-11-30 17:10:37 +08:00
Bobby Rong
9337a88fc2 pantheon.switchboard-plug-pantheon-shell: 6.0.0 -> 6.1.0
(cherry picked from commit e5afe95fe7)
2021-11-30 17:10:37 +08:00
Bobby Rong
ff9563ad05 pantheon.elementary-onboarding: 6.0.0 -> 6.1.0
(cherry picked from commit a9f302e1a2)
2021-11-30 17:10:37 +08:00
Bobby Rong
7811213408 pantheon.appcenter: 3.8.2 -> 3.9.0
(cherry picked from commit 59c9786c5b)
2021-11-30 17:10:37 +08:00
Bobby Rong
9b729138d9 pantheon.switchboard-plug-security-privacy: 2.2.5 -> 2.3.0
(cherry picked from commit 884945d69c)
2021-11-30 17:10:36 +08:00
Bobby Rong
7580f49fc1 pantheon.elementary-camera: 6.0.1 -> 6.0.2
(cherry picked from commit 079cbad8d9)
2021-11-30 17:10:36 +08:00
Bobby Rong
e3f6a6e92d pantheon.wingpanel-indicator-network: 2.3.1 -> 2.3.2
(cherry picked from commit 26c04f9942)
2021-11-30 17:10:36 +08:00
Bobby Rong
818cb2a6ab pantheon.switchboard-plug-keyboard: 2.5.1 -> 2.6.0
(cherry picked from commit f3b5da17e8)
2021-11-30 17:10:36 +08:00
Bobby Rong
159e6637c0 pantheon.switchboard-plug-sound: 2.2.7 -> 2.3.0
(cherry picked from commit 96e5b267fd)
2021-11-30 17:10:36 +08:00
Robert Scott
0ca07bbe85 python3Packages.pyvex: fix build for aarch64-linux
(cherry picked from commit eefac98f1a)
2021-11-30 08:15:35 +00:00
Bobby Rong
a69248d067 Merge pull request #147972 from NixOS/backport-147944-to-release-21.11
[Backport release-21.11] frogatto-data: 2020-12-17 -> 2021-11-29
2021-11-30 14:02:20 +08:00
Ryan Burns
ea9b10b451 aws-c-io: 0.10.12 -> 0.10.13
(cherry picked from commit 184f853239)
2021-11-30 04:52:48 +00:00
Ryan Burns
dae67f6209 aws-c-cal: 0.5.11 -> 0.5.12
(cherry picked from commit f09fff1e1f)
2021-11-30 04:52:48 +00:00
Ryan Burns
8e9c4eb652 aws-c-mqtt: 0.7.8 -> 0.7.9
(cherry picked from commit 181ee83bff)
2021-11-30 04:52:48 +00:00
Ryan Burns
b7dcc76890 aws-c-auth: 0.6.5 -> 0.6.8
(cherry picked from commit ec72084598)
2021-11-30 04:52:48 +00:00
Ryan Burns
cb29fe37e9 s2n-tls: 1.0.17 -> 1.3.0
(cherry picked from commit 5929241023)
2021-11-30 04:52:47 +00:00
Ryan Burns
b9651a8f39 aws-crt-cpp: 0.17.0 -> 0.17.8
(cherry picked from commit 2eb081deb2)
2021-11-30 04:52:47 +00:00
Ryan Burns
7d75970813 aws-c-http: 0.6.8 -> 0.6.10
(cherry picked from commit ea80624cdc)
2021-11-30 04:52:47 +00:00
Ryan Burns
e8d01304c6 aws-c-common: 0.6.14 -> 0.6.17
(cherry picked from commit 9d21602e75)
2021-11-30 04:52:47 +00:00
Artturin
86b29f990e nixos/tests/installer: increase /boot sizes to 100MB
(cherry picked from commit c19234d0df)
2021-11-30 04:40:44 +00:00
Lluís Batlle i Rossell
3e888697c5 frogatto-data: 2020-12-17 -> 2021-11-29
Updating the engine required updating the data. Otherwise a crash would
happen at the 2nd level (out of the main house).

(cherry picked from commit f30f9c8aa8)
2021-11-30 03:45:38 +00:00
Timothy DeHerrera
a7ecde854a 21.11 Release Notes: fix typos
(cherry picked from commit b1faa37cdf)
2021-11-29 21:23:31 -05:00
Tom Bereknyei
64e3e0952a [21.11] update README.md
[21.11] update upgrading

[21.11] update release date

run generation

(cherry picked from commit af92f1c0cc)
2021-11-29 21:23:31 -05:00
Artturi
98ce47dd6e Revert "nixos/hidpi: add xserver dpi"
(cherry picked from commit 04a499cdde)
2021-11-30 00:54:47 +00:00
Thiago Kenji Okada
393c5357a0 Merge pull request #147952 from NixOS/backport-147894-to-release-21.11
[Backport release-21.11] fira-code: 5.2 → 6
2021-11-29 21:17:08 -03:00
Thiago Kenji Okada
8906ff1971 Merge pull request #147895 from NixOS/backport-147376-to-release-21.11
[Backport release-21.11] nixUnstable: 2.5pre20211007 -> 2.5pre20211126
2021-11-29 21:13:00 -03:00
github-actions[bot]
a502a50a88 Merge staging-next-21.11 into staging-21.11 2021-11-30 00:10:30 +00:00
github-actions[bot]
0974d877ab Merge release-21.11 into staging-next-21.11 2021-11-30 00:09:53 +00:00
Thiago Kenji Okada
f7e1c9f7c8 Merge pull request #147928 from NixOS/backport-147556-to-release-21.11
[Backport release-21.11] steamPackages.steam-runtime: 0.20210906.1 -> 0.20211102.0
2021-11-29 21:09:37 -03:00
Martin Weinelt
ff75369c09 Merge pull request #147843 from mweinelt/21.11/mediawiki 2021-11-30 00:59:27 +01:00
Fabián Heredia Montiel
36f06c1ee3 fira-code: 5.2 → 6
(cherry picked from commit 4d3ed16dd8)
2021-11-29 22:53:53 +00:00
Artturin
2ee7f2c453 grub2: fix buildPackage bash shebang
(cherry picked from commit 8191c8e226)
2021-11-29 22:46:14 +00:00
Artturin
4f06ac1644 grub2: switch to release tarball
for the localization files

(cherry picked from commit 76e515cb26)
2021-11-29 22:46:14 +00:00
Artturi
b1cd9a32c2 Merge pull request #147929 from NixOS/backport-147732-to-release-21.11 2021-11-29 23:43:26 +02:00
Artturi
c7addf512b Merge pull request #147926 from NixOS/backport-147276-to-release-21.11 2021-11-29 22:25:18 +02:00
Artturi
ed30ac8c5d Merge pull request #147582 from NixOS/backport-147550-to-release-21.11 2021-11-29 22:12:38 +02:00
Artturi
40684b21ce Merge pull request #147855 from NixOS/backport-147766-to-release-21.11 2021-11-29 22:12:02 +02:00
Artturi
8506ae32fe Merge pull request #147856 from NixOS/backport-147775-to-release-21.11 2021-11-29 22:11:45 +02:00
Artturi
cc31ff2bc0 Merge pull request #147841 from NixOS/backport-147834-to-release-21.11 2021-11-29 22:09:09 +02:00
Artturi
d1d93b341b Merge pull request #147816 from NixOS/backport-147735-to-release-21.11 2021-11-29 22:08:20 +02:00
Artturi
9d2b3f4884 Merge pull request #147811 from NixOS/backport-147806-to-release-21.11 2021-11-29 22:07:39 +02:00
Artturi
2e86d9d877 Merge pull request #147777 from NixOS/backport-146573-to-staging-21.11 2021-11-29 22:07:12 +02:00
Artturi
4e999b3e14 Merge pull request #147741 from NixOS/backport-146403-to-release-21.11 2021-11-29 22:07:02 +02:00
Artturi
a8803aa095 Merge pull request #147726 from NixOS/backport-147399-to-release-21.11 2021-11-29 22:06:14 +02:00
Zane van Iperen
db620d7715 jpsxdec: init at 1.05
(cherry picked from commit b560894545)
2021-11-29 20:04:32 +00:00
Mario Rodas
b4835440bc postgresql_14: 14.0 -> 14.1
https://www.postgresql.org/docs/release/14.1/
(cherry picked from commit 85852b941d)
2021-11-29 19:51:34 +00:00
Mario Rodas
94dce4f2bf postgresql_13: 13.4 -> 13.5
https://www.postgresql.org/docs/release/13.5/
(cherry picked from commit 67abda7877)
2021-11-29 19:51:34 +00:00
Mario Rodas
07e6b440b8 postgresql_12: 12.8 -> 12.9
https://www.postgresql.org/docs/release/12.9/
(cherry picked from commit c046c5d6ff)
2021-11-29 19:51:34 +00:00
Mario Rodas
4ba18cf214 postgresql_11: 11.13 -> 11.14
https://www.postgresql.org/docs/release/11.14/
(cherry picked from commit b701405be7)
2021-11-29 19:51:34 +00:00
Mario Rodas
4eb1b44060 postgresql_10: 10.18 -> 10.19
https://www.postgresql.org/docs/release/10.19/
(cherry picked from commit 1d35ef9ee0)
2021-11-29 19:51:34 +00:00
Mario Rodas
87c27e4b5c postgresql_9_6: 9.6.23 -> 9.6.24
https://www.postgresql.org/docs/release/9.6.24/
(cherry picked from commit 7f523aa88a)
2021-11-29 19:51:34 +00:00
Pol Dellaiera
9aa248f94a symfony-cli: bump and support more platforms.
(cherry picked from commit 693bc570717c3145b674289a67e6a21f63c834ef)
2021-11-29 19:36:25 +00:00
TredwellGit
03080a1f10 steamPackages.steam-runtime: 0.20210906.1 -> 0.20211102.0
(cherry picked from commit dbda557c64)
2021-11-29 19:34:50 +00:00
Vladimír Čunát
d62a48f522 xorg.xf86videomach64: drop the ancient driver
It doesn't seems worth keeping it alive.  Broken by commit 0649fcdf2.
(I hope I did this right without regenerating.)

(cherry picked from commit 0c0f340c22)
2021-11-29 19:32:47 +00:00
TredwellGit
45e1cb1c84 libreoffice-fresh: 7.2.2.2 -> 7.2.3.2
(cherry picked from commit 722bfae487)
2021-11-29 19:28:01 +00:00
figsoda
23cb0aca1f Merge pull request #147922 from NixOS/backport-147915-to-release-21.11
[Backport release-21.11] pgbouncer: 1.16.0 -> 1.16.1
2021-11-29 13:55:52 -05:00
1000101
22c62c13b5 pgbouncer: 1.16.0 -> 1.16.1
(cherry picked from commit dbd39c4d41)
2021-11-29 18:50:41 +00:00
markuskowa
a0fda469f7 Merge pull request #147850 from NixOS/backport-147839-to-release-21.11
[Backport release-21.11] ucx: add optional Cuda support
2021-11-29 19:41:07 +01:00
Lluís Batlle i Rossell
5f39102589 tribler: 7.4.4 -> 7.10.0
This also adds old versions of apispec and webargs that tribler
requires, and aiohttp-apispec as well.

(cherry picked from commit 2d083acf66)
2021-11-29 18:28:22 +00:00
Artturin
1cbf15fabc nixUnstable: 2.5pre20211007 -> 2.5pre20211126
(cherry picked from commit c192da17cc)
2021-11-29 15:31:35 +00:00
Vikram Narayanan
a2211453ae ncgopher: 0.2.0 -> 0.3.0
(cherry picked from commit 8a69eb8701)
2021-11-29 14:33:25 +00:00
Drew Risinger
a4a2c1be8e python3Packages.qiskit-aqua: disable slow tests
These tests were timing out, they pass locally but can overrun the timeout threshold depending on system load and speed.

System load shouldn't cause hydra failures, so disabling.

(cherry picked from commit c5b6e8a0fd)
2021-11-29 14:32:19 +00:00
Maximilian Bosch
6c639bebff Merge pull request #147748 from NixOS/backport-147672-to-staging-21.11
[Backport staging-21.11] glibc: 2.33-56 -> 2.33-59
2021-11-29 15:32:12 +01:00
Maximilian Bosch
0d6679d40c Merge pull request #147795 from NixOS/backport-147626-to-release-21.11
[Backport release-21.11] vorta: 0.7.8 -> 0.8.2
2021-11-29 15:32:03 +01:00
Maximilian Bosch
317927ae16 Merge pull request #147842 from NixOS/backport-147510-to-release-21.11
[Backport release-21.11] privacyidea: 3.6.2 -> 3.6.3
2021-11-29 15:31:55 +01:00
Markus Kowalewski
1131ea96cf ucx: add optional Cuda support
(cherry picked from commit 24fb8db66d)
2021-11-29 13:43:14 +00:00
Martin Weinelt
d6d494513c mediawiki: 1.36.1 -> 1.36.2
(cherry picked from commit cd12d81d53)
2021-11-29 13:02:18 +01:00
Maximilian Bosch
4b5602605d privacyidea: 3.6.2 -> 3.6.3
ChangeLog: https://github.com/privacyidea/privacyidea/blob/v3.6.3/Changelog#L1-L5

* This package still needs `sqlsoup`, so I unmarked it as broken which
  is fine since it's building with sqlalchemy v1.3.
* There's a small difference between the `git`-tag and the PyPI tarball,
  but it's non-functional[1].

[1] https://github.com/privacyidea/privacyidea/issues/2921

(cherry picked from commit a805549e43)
2021-11-29 11:29:38 +00:00
Lucas Savva
045ce94e55 nixos/acme: Fix rate limiting of selfsigned services
Closes NixOS/nixpkgs#147348

I was able to reproduce this intermittently in the
test suite during the tests for HTTPd. Adding
StartLimitIntervalSec=0 to disable rate limiting
for these services works fine. I added it anywhere
there was a ConditionPathExists.

(cherry picked from commit be952aba1c)
2021-11-29 11:02:56 +00:00
Vincent Laporte
877bc00322 obelisk: 0.5.2 → 0.6.0
(cherry picked from commit 52fc1808c95c9bf82c960ae510714bc06d511364)
2021-11-29 10:50:43 +01:00
Vincent Laporte
9d5275d015 coqPackages.coqhammer: 1.3.1 → 1.3.2
(cherry picked from commit e5f41e735d8e6b41f27dd3dd7cf40cd740b8d6f2)
2021-11-29 10:43:47 +01:00
Vincent Laporte
05bcb29564 compcert: 3.9 → 3.10
Enable for Coq 8.14

Use default version of OCaml (instead of 4.05)

VST is not ready for CompCert 3.10, so it still uses 3.9

(cherry picked from commit fa22c7cda37ad4c1fd7056e0b86d03b273699277)
2021-11-29 10:33:09 +01:00
markuskowa
70602e9261 Merge pull request #147740 from NixOS/backport-144253-to-release-21.11
[Backport release-21.11] pyscf: 1.7.6.post1 -> 2.0.1
2021-11-29 09:10:18 +01:00
Lluís Batlle i Rossell
55ee221efb frogatto: 2021-05-24 -> 2021-11-23
And fix build

(cherry picked from commit 873042271a)
2021-11-29 08:01:45 +00:00
Julien Moutinho
a9a3b199c8 stig: fix build
(cherry picked from commit 77e9c5d38c)
2021-11-29 07:43:50 +00:00
Bobby Rong
8e6b391462 Revert "nixos/test/boot: nix verify -> nix store verify"
This reverts commit 6a4d2207b1.
2021-11-28 23:48:15 -05:00
Bobby Rong
5e2f144e73 Merge pull request #147754 from artemist/rnix-lsp-21.11
[21.11] rnix-lsp: Use nix 2.4
2021-11-29 10:34:52 +08:00
Bobby Rong
c7eaa731c7 Merge pull request #147787 from NixOS/backport-147736-to-release-21.11
[Backport release-21.11] pijul: 1.0.0-alpha.55 → 1.0.0-alpha.56
2021-11-29 10:21:34 +08:00
Artemis Tosini
bb22eb6d8b rnix-lsp: Use nix 2.4
In e6548105b7 rnix-lsp switched back to
using the default nix because it was moved to 2.4. However, in
e3b7448f23 the default nix moved back to 2.3.16.
As rnix-lsp requires at least nix 2.4 for tests to succeed, the tests
started failing
2021-11-29 01:52:21 +00:00
Maximilian Bosch
e1dd426976 vorta: 0.7.8 -> 0.8.2
ChangeLogs:
* https://github.com/borgbase/vorta/releases/tag/v0.8.0
* https://github.com/borgbase/vorta/releases/tag/v0.8.1
* https://github.com/borgbase/vorta/releases/tag/v0.8.2

(cherry picked from commit 4aa2320ec1)
2021-11-29 01:36:32 +00:00
Fabián Heredia Montiel
23df138727 pijul: 1.0.0-alpha.55 → 1.0.0-alpha.56
(cherry picked from commit b9f6ee2e2f)
2021-11-29 00:41:29 +00:00
Robert Scott
b60abb76f1 Merge pull request #147779 from NixOS/backport-147751-to-release-21.11
[Backport release-21.11] python3Packages.pywal: fix darwin hydra build
2021-11-29 00:00:39 +00:00
Robert Scott
f753917dd6 Merge pull request #147781 from NixOS/backport-147761-to-release-21.11
[Backport release-21.11] netatalk: fix build
2021-11-28 23:41:04 +00:00
Vikram Narayanan
95293a782b netatalk: fix build
(cherry picked from commit 0a9dd29c98)
2021-11-28 22:38:41 +00:00
Robert Scott
56710e1546 python3Packages.pywal: use $TMPDIR in tests
darwin hydra can fail to access /tmp

(cherry picked from commit 1e3b8e3fd8)
2021-11-28 22:12:00 +00:00
Sandro Jäckel
fc57c00f5e systemd: enable elfutils support for stack traces in coredump
(cherry picked from commit 9c9dffbf7a)
2021-11-28 22:07:46 +00:00
Sandro Jäckel
70e6fd5186 systemd: enable zstd compression support
(cherry picked from commit 78d93d3698)
2021-11-28 22:07:46 +00:00
Thiago Kenji Okada
a80798e6a2 Merge pull request #147774 from NixOS/backport-147756-to-release-21.11
[Backport release-21.11] neard: fix build
2021-11-28 18:55:03 -03:00
Phillip Cloud
67f8d1befb parquet-tools: fix tests for arrow-cpp 6.0.1
(cherry picked from commit ebe33362a8)
2021-11-28 16:51:23 -05:00
Dmitry Kalinkin
81d5b0d404 arrow-cpp: build without jemalloc on aarch64-darwin to fix build
(cherry picked from commit e3e77ee8a4)
2021-11-28 16:51:23 -05:00
Dmitry Kalinkin
4441ec3523 python3Packages.pyarrow: fix sandboxed build on darwin
(cherry picked from commit 9fff252dcf)
2021-11-28 16:51:23 -05:00
Dmitry Kalinkin
d00785c2a6 arrow-cpp: fix sandboxed build on darwin
(cherry picked from commit c5a0962ddd)
2021-11-28 16:51:23 -05:00
Phillip Cloud
e1b57b1e1e arrow-cpp: 6.0.0 -> 6.0.1
(cherry picked from commit 92c45083e5)
2021-11-28 16:51:23 -05:00
Vikram Narayanan
101fdf5e23 neard: fix build
(cherry picked from commit 32067bb159)
2021-11-28 21:34:31 +00:00
Thiago Kenji Okada
82d0120083 Merge pull request #147750 from NixOS/backport-147622-to-release-21.11
[Backport release-21.11] libretro.pcsx2: init at unstable-2021-11-27
2021-11-28 16:43:29 -03:00
Vladimír Čunát
f083474000 Revert "nixos/tests/misc: fix nix 2.4 support"
This reverts commit 546d60c5e6.
Fixes nixosTests.misc after reverting nix version in PR #147511.
2021-11-28 14:35:13 -05:00
Thiago Kenji Okada
f2afa0270c libretro: fix core platforms
(cherry picked from commit 5c589d83ed)
2021-11-28 18:46:24 +00:00
Thiago Kenji Okada
8562c5aaa1 libretro: remove "-DCMAKE_BUILD_TYPE=Release"
(cherry picked from commit 7ff536edd6)
2021-11-28 18:46:23 +00:00
Thiago Kenji Okada
331baaca9c libretro.pcsx2: init at unstable-2021-11-27
Thanks for @jnetod help.

(cherry picked from commit 6f05bc3791)
2021-11-28 18:46:23 +00:00
Vladimír Čunát
2255d4d5e1 Merge #147715: nixosTests.keymap.qwertz: reduce platforms
... in `tested` (into release-21.11)
2021-11-28 19:44:17 +01:00
Vladimír Čunát
3c2e73c2ea nixosTests.keymap.qwertz: reduce platforms in tested
In particular, aarch64-linux variant doesn't work on Hydra,
so at least avoid this blocking the 21.11 channel.
2021-11-28 19:42:16 +01:00
TredwellGit
261cd9d904 glibc: 2.33-56 -> 2.33-59
(cherry picked from commit 98ab93d191)
2021-11-28 18:36:47 +00:00
Jan Tojnar
86cfb75f1f Fix eval with nix-env -qas
At least on NixOS, it fails to evaluate as follows:

	$ nix-env -qaPs -f .
	error: attribute '__propagatedImpureHostDeps' missing

(cherry picked from commit b8c07facaa)
2021-11-28 17:47:32 +00:00
Phillip Seeber
018d77058c pyscf: 1.7.6.post1 -> 2.0.1
pyscf: hash

pyscf: limit test suite to single core

pyscf: adapting test suite

pyscf: fix pythonpath for tests

pyscf: formatting

pyscf: platforms

remove log

pyscf: enable uadc module

pyscf: platforms

pyscf: formatting

pyscf: disable instable N3 CI test

pyscf: formating

pyscf: increase ulimit

pyscf: ulimit files

pyscf: remove ulimit -n

(cherry picked from commit 21ca2dec9f)
2021-11-28 17:36:31 +00:00
Phillip Seeber
17f6ccd914 cppe: init at 0.3.1
cppe: move pytestCheckHook to checkInputs

cppe: hash

cppe: license and hash

cppe: formatting

python3.pkgs.cppe: more tests

cppe: formatting

cppe: formatting

cppe: platforms

cppe: platforms

(cherry picked from commit 938a9e00c5)
2021-11-28 17:36:31 +00:00
sheepforce
a6c31fc2f9 python3.pkgs.polarizationsolver: init at 00424ac4
polarizationsolver: expose

polyrizationsolver: formatting

polarizationsolver: platforms

polarizationsolver: platforms

polarizationsolver: license

polarizationsolver: remove redundant platform

(cherry picked from commit a6a5114653)
2021-11-28 17:36:31 +00:00
sheepforce
3d739203c8 python3.pkgs.fields: init at 5.0.0
fields: expose package

fields: formatting

fields: platforms

fields: platforms

fields: remove redundant platform

(cherry picked from commit dbd7ba5f5f)
2021-11-28 17:36:31 +00:00
Phillip Seeber
7c94fd01e0 libxc: force 3rd and 4th derivatives compilation
libxc: formatting

libxc: platforms

(cherry picked from commit 2a9baed906)
2021-11-28 17:36:31 +00:00
Phillip Seeber
6038e2a8df libcint: 4.4.0 -> 4.4.6
libcint: formatting and features

libcint: platforms

(cherry picked from commit dd7f587346)
2021-11-28 17:36:31 +00:00
ajs124
0ccf2f5c94 Merge pull request #147720 from NixOS/backport-146488-to-release-21.11
[Backport release-21.11] php74: 7.4.25 -> 7.4.26, php80: 8.0.12 -> 8.0.13
2021-11-28 18:24:26 +01:00
Daniel Olsen
8de64b808a hydrus: 462 -> 463
(cherry picked from commit 0fff6b89ea)
2021-11-28 15:58:46 +00:00
Daniel Olsen
8c2e9701aa nixos/doc: Add note about big updates regarding hydrus to release notes
(cherry picked from commit 40fb87f5ca)
2021-11-28 15:58:46 +00:00
ajs124
36be1049b3 php80Extensions.xmlreader: fix build
(cherry picked from commit cede244af9)
2021-11-28 14:48:03 +00:00
ajs124
8d41fc092e php80: 8.0.12 -> 8.0.13
Fixes CVE-2021-21707

(cherry picked from commit 6dfffc7d49)
2021-11-28 14:48:03 +00:00
ajs124
7021d298d0 php74: 7.4.25 -> 7.4.26
Fixes CVE-2021-21707

(cherry picked from commit 183cc6ea80)
2021-11-28 14:48:03 +00:00
Thiago Kenji Okada
f71736e772 Merge pull request #147717 from NixOS/backport-147696-to-release-21.11
[Backport release-21.11] storm: 2.2.0 -> 2.3.0
2021-11-28 11:47:08 -03:00
Thiago Kenji Okada
0d1f71a6b0 Merge pull request #147716 from NixOS/backport-147664-to-release-21.11
[Backport release-21.11] slicer: fix build
2021-11-28 11:38:07 -03:00
Thomas Gerbet
8cbf091c3a storm: 2.2.0 -> 2.3.0
Fixes CVE-2021-38294 and CVE-2021-40865.
https://storm.apache.org/2021/09/27/storm230-released.html

(cherry picked from commit 840af81e55)
2021-11-28 14:27:56 +00:00
Thiago Kenji Okada
836f07ba68 Merge pull request #147602 from NixOS/backport-147569-to-release-21.11
[Backport release-21.11] invidious/lsquic: fix build
2021-11-28 11:27:22 -03:00
Vikram Narayanan
83036951ea slicer: fix build
(cherry picked from commit 182c8be433)
2021-11-28 14:15:07 +00:00
Thiago Kenji Okada
7a5d5a88fb Merge pull request #147712 from NixOS/backport-146915-to-release-21.11
[Backport release-21.11] pulseaudio-dlna: unstable-2017-11-01 -> unstable-2021-11-09
2021-11-28 11:08:46 -03:00
Florian Klink
1049108040 pulseaudio-dlna: ensure pactl is available
pulseaudio-dlna shells out to pactl to configure sinks and sources.
As pactl might not be in $PATH, add --suffix it (so pactl configured by the
user get priority)

(cherry picked from commit f567ff4440)
2021-11-28 13:43:10 +00:00
Florian Klink
487c762d0b pulseaudio-dlna: minor cleanups
(cherry picked from commit b1204359fa)
2021-11-28 13:43:10 +00:00
Florian Klink
b2ae150f86 pulseaudio-dlna: unstable-2017-11-01 -> unstable-2021-11-09
This moves pulseaudio-dlna to a more recent fork, which works with
Python 3.

(cherry picked from commit 467aead38e)
2021-11-28 13:43:10 +00:00
Bobby Rong
4cf625d838 Merge pull request #147495 from NixOS/backport-146166-to-release-21.11
[Backport release-21.11] nodePackages.teck-programmer: fix build
2021-11-28 21:27:33 +08:00
Bobby Rong
71c2e2cf1a Merge pull request #147703 from NixOS/backport-147699-to-release-21.11
[Backport release-21.11] gromacs: fix double precission build on aarch64
2021-11-28 21:19:50 +08:00
Bobby Rong
7b1eb2827d Merge pull request #147704 from NixOS/backport-147656-to-release-21.11
[Backport release-21.11] dero: remove package
2021-11-28 21:17:49 +08:00
Robert Scott
df4f3f8371 Merge pull request #147700 from NixOS/backport-147643-to-release-21.11
[Backport release-21.11] docbookrx: fix build
2021-11-28 12:55:39 +00:00
Vikram Narayanan
9be5459139 dero: remove package
Package is not maintained since 2018 and officially retired
https://github.com/deroproject/dero/blob/master/README.md

(cherry picked from commit ef646cac0031e379b384d1e3ad734366e9bc7392)
2021-11-28 12:48:28 +00:00
Markus Kowalewski
0da1c32e6f gromacs: fix double precission build on aarch64
(cherry picked from commit 5cfe3c4e82)
2021-11-28 12:47:24 +00:00
Vikram Narayanan
96890e8359 docbookrx: fix build
(cherry picked from commit b35726542e)
2021-11-28 12:22:47 +00:00
Michele Guerini Rocco
6e4d89f058 Merge pull request #147675 from NixOS/backport-147637-to-release-21.11
[Backport release-21.11] pdns-recursor: 4.5.6 -> 4.5.7
2021-11-28 10:45:44 +01:00
rnhmjoj
5da69c12d8 pdns-recursor: 4.5.6 -> 4.5.7
(cherry picked from commit ade2d34d4f)
2021-11-28 09:04:18 +00:00
Artturi
cf7b7d404e Merge pull request #147654 from NixOS/backport-147323-to-release-21.11
[Backport release-21.11] nixos/vmware-guest: add display-manager to after and
2021-11-28 07:29:03 +02:00
Artturin
4781b4aeb3 nixos/vmware-guest: add display-manager to after and
add ConditionVirtualization

and remove unneeded before and wants which are not in the upstream
package, the wantedBy should be enough

(cherry picked from commit 21585dc683)
2021-11-28 05:01:22 +00:00
Thiago Kenji Okada
be5d1a3896 Merge pull request #147642 from thiagokokada/backport-147628-to-release-21.11
[Backport release-21.11] delta: 0.9.2 -> 0.10.2
2021-11-27 22:57:57 -03:00
zowoq
87a122f681 delta: 0.10.1 -> 0.10.2
https://github.com/dandavison/delta/releases/tag/0.10.2
(cherry picked from commit 909df3fa25)
2021-11-27 22:16:07 -03:00
zowoq
6c2b7d8535 delta: 0.10.0 -> 0.10.1
https://github.com/dandavison/delta/releases/tag/0.10.1
(cherry picked from commit 4ea35c4c20)
2021-11-27 22:16:02 -03:00
Sandro
3cb164e0f0 delta: add SuperSandro2000 as maintainer
(cherry picked from commit 31b46dd7f9)
2021-11-27 22:15:51 -03:00
Sandro Jäckel
c9fa27e6f2 delta: 0.9.2 -> 0.10.0
(cherry picked from commit 122b0e0602)
2021-11-27 22:15:42 -03:00
Thiago Kenji Okada
15ee7dfe71 Merge pull request #147632 from NixOS/backport-147568-to-release-21.11
[Backport release-21.11] janus-gateway: fix build
2021-11-27 21:36:00 -03:00
Thiago Kenji Okada
dbc6935d0b Merge pull request #147633 from NixOS/backport-147618-to-release-21.11
[Backport release-21.11] btop: 1.1.0 -> 1.1.2
2021-11-27 21:31:55 -03:00
markuskowa
914abe56d9 Merge pull request #147634 from NixOS/backport-147631-to-release-21.11
[Backport release-21.11] octopus: 11.2 -> 11.3
2021-11-28 01:31:46 +01:00
Markus Kowalewski
751cc30827 octopus: 11.2 -> 11.3
(cherry picked from commit 8fb36866b8)
2021-11-27 23:40:53 +00:00
Fabian Affolter
14b02837df btop: 1.1.0 -> 1.1.2
(cherry picked from commit 609ab2cdc4)
2021-11-27 23:25:27 +00:00
Vikram Narayanan
7d5450fa3f janus-gateway: fix build
(cherry picked from commit 84730c9f5d)
2021-11-27 23:17:06 +00:00
Tom Bereknyei
ec75887faf Revert "nix-fallback-paths.nix: Update to 2.4"
This reverts commit 58a9cca8cd.
2021-11-27 18:16:27 -05:00
Tom Bereknyei
0365b9ad37 Revert "lib/tests/sources: update to Nix 2.4 cli syntax"
This reverts commit 90c1cdd93f.
2021-11-27 18:16:27 -05:00
Tom Bereknyei
89d47cf2a0 Revert "lib/tests/modules.sh: update to Nix 2.4 syntax"
This reverts commit fd4390146e.
2021-11-27 18:16:27 -05:00
Tom Bereknyei
e3b7448f23 nixStable: 2.4 -> 2.3.16
Revert due to regressions. This is meant to be only for the 21.11
release. See
https://discourse.nixos.org/t/nix-2-4-and-what-s-next/16257 for
additional information.
2021-11-27 18:16:27 -05:00
Timothy DeHerrera
4ccbed8c9c Merge pull request #147620 from NixOS/backport-147609-to-release-21.11
[Backport release-21.11] Revert "Merge pull request #141192 from helsinki-systems/feat/improve…
2021-11-27 11:47:27 -07:00
Michael Weiss
7abd52203d Revert "Merge pull request #141192 from helsinki-systems/feat/improved-socket-handling2"
This reverts commit 57961d2b83, reversing
changes made to b04f913afc.
(I.e. this reverts PR #141192.)

While well-intended, this change does unfortunately introduce very
serious regressions that are especially disruptive/noticeable on desktop
systems (e.g. users of Sway will loose their graphical session when
running "nixos-rebuild switch").

Therefore, this change has to be reverted ASAP instead of trying to fix
it in "production".
Note: An updated version should be extensively discussed, reviewed, and
tested before re-landing this change as an earlier version also had to
be reverted for the exact same issues [0].

Fix: #146727

[0]: https://github.com/NixOS/nixpkgs/pull/73871#issuecomment-559783752

(cherry picked from commit 1cfecb636b)
2021-11-27 18:13:20 +00:00
Vikram Narayanan
d8b2b0209b invidious/lsquic: fix build
(cherry picked from commit ed3cfc8abe)
2021-11-27 15:41:07 +00:00
Anderson Torres
f4bba5b4c7 Merge pull request #147593 from NixOS/backport-147535-to-release-21.11
[Backport release-21.11] zydis: 3.2.0 -> 3.2.1
2021-11-27 10:54:23 -03:00
AndersonTorres
c43b2a294b zydis: add myself as maintainer
(cherry picked from commit 73b3f81d96)
2021-11-27 13:32:38 +00:00
AndersonTorres
334a4e3dfb zydis: 3.2.0 -> 3.2.1
(cherry picked from commit 51ab665ad7)
2021-11-27 13:32:38 +00:00
TredwellGit
b2719a4013 electron_16: 16.0.1 -> 16.0.2
https://github.com/electron/electron/releases/tag/v16.0.2
(cherry picked from commit ee74e6547d)
2021-11-27 10:30:15 +00:00
Domen Kožar
415728e905 Merge pull request #147579 from NixOS/backport-147043-to-release-21.11
[Backport release-21.11] ocaml: Fix aarch64-darwin build
2021-11-27 10:57:29 +01:00
Domen Kožar
2805cb2640 Merge pull request #147548 from NixOS/backport-147419-to-release-21.11
[Backport release-21.11] gnuradio3_8packages.ais: fix build
2021-11-27 10:43:03 +01:00
Vikram Narayanan
1995a8eb7a ocaml: Fix aarch64-darwin build
(cherry picked from commit 528716bb8e)
2021-11-27 09:42:28 +00:00
Domen Kožar
b78041aeaa Merge pull request #147571 from NixOS/backport-147536-to-release-21.11
[Backport release-21.11] tsung: use Python 3
2021-11-27 10:42:06 +01:00
Fabian Affolter
03e38006d3 tsung: use Python 3
(cherry picked from commit bf730c8e2f)
2021-11-27 08:19:32 +00:00
Vikram Narayanan
3295941fd1 gnuradio3_8packages.ais: fix build
(cherry picked from commit 22b72c17bb)
2021-11-26 23:06:48 +00:00
Thiago Kenji Okada
4963187a14 Merge pull request #147545 from NixOS/backport-147490-to-release-21.11
[Backport release-21.11] modules/nix-daemon: Add missing mk(Rename|Removed)OptionModule
2021-11-26 19:55:27 -03:00
markuskowa
3abd6819df Merge pull request #147533 from NixOS/backport-147529-to-release-21.11
[Backport release-21.11] openmpi: 4.1.1 -> 4.1.2
2021-11-26 23:44:28 +01:00
Mikael Voss
ba2f392d55 modules/nix-daemon: Add missing mk(Rename|Removed)OptionModule
Commit 3a92a1a replaced the nix.daemonNiceLevel and nix.daemonIONiceLevel
options. This commit adds appropriate mk(Rename|Removed)OptionModule.

(cherry picked from commit 257e92258e)
2021-11-26 22:35:42 +00:00
Markus Kowalewski
b294ab366a openmpi: 4.1.1 -> 4.1.2
(cherry picked from commit 7287bf05aa)
2021-11-26 21:21:35 +00:00
Domen Kožar
af2b7bf4b0 Merge pull request #147514 from midchildan/fix/libcxx-darwin-staging
[Backport release-21.11] llvmPackages_13.libcxx: fix darwin build
2021-11-26 21:38:09 +01:00
Domen Kožar
91c12917e1 Merge pull request #147505 from NixOS/backport-147422-to-release-21.11
[Backport release-21.11] ocaml: heed hardeningDisable flags set for individual versions, fixing many coq versions on darwin
2021-11-26 21:29:38 +01:00
Thiago Kenji Okada
6e98787d1e Merge pull request #147519 from NixOS/backport-147382-to-release-21.11
[Backport release-21.11] varnish60: 6.0.8 -> 6.0.9
2021-11-26 16:15:09 -03:00
ajs124
e26792d904 varnish60: 6.0.8 -> 6.0.9
(cherry picked from commit 31fdf8b75e)
2021-11-26 18:47:07 +00:00
midchildan
24f6348660 llvmPackages_13: build with llvmPackages_11 on Darwin 2021-11-27 01:51:57 +09:00
midchildan
eb7ebfb59c llvmPackages_13.libcxx: fix darwin build
(cherry picked from commit 845225e7ab)
2021-11-27 01:48:25 +09:00
Thiago Kenji Okada
89369f880a Merge pull request #147508 from thiagokokada/backport-147136-to-release-21.11
[Backport release 21.11] buildGraalvmNativeImage: init
2021-11-26 13:35:25 -03:00
Thiago Kenji Okada
958e6f9ab7 Merge pull request #147493 from NixOS/backport-147156-to-release-21.11
[Backport release-21.11] imagemagick: 7.1.0-15 -> 7.1.0-16
2021-11-26 12:57:40 -03:00
Thiago Kenji Okada
529c0edf72 buildGraalvmNativeImage: allow nativeImageBuildArgs to be overwritten
(cherry picked from commit a5c0f59bf7)
2021-11-26 12:46:56 -03:00
Thiago Kenji Okada
1ef566898e buildGraalvmNativeImage: fix meta, add --verbose flag
(cherry picked from commit f1c16183c8)
2021-11-26 12:46:44 -03:00
Thiago Kenji Okada
2abebee8b2 zprint: use buildGraalvmNativeImage
(cherry picked from commit e9766a85bd)
2021-11-26 12:46:40 -03:00
Thiago Kenji Okada
a997c18acc buildGraalvmNativeImage: default executable to pname
(cherry picked from commit d352856ea2)
2021-11-26 12:46:36 -03:00
Thiago Kenji Okada
3341799b98 jet: use buildGraalvmNativeImage
(cherry picked from commit 3100248dbb)
2021-11-26 12:46:33 -03:00
Thiago Kenji Okada
e9c5e523da clj-kondo: use buildGraalvmNativeImage
(cherry picked from commit a277e9d457)
2021-11-26 12:46:19 -03:00
Thiago Kenji Okada
70d023db49 clojure-lsp: use buildGraalvmNativeImage
(cherry picked from commit 7c632551c1)
2021-11-26 12:46:16 -03:00
Thiago Kenji Okada
d31aaf3c3a babashka: use buildGraalvmNativeImage
(cherry picked from commit 052fb6a228)
2021-11-26 12:46:13 -03:00
Thiago Kenji Okada
b412d2e769 buildGraalvmNativeImage: init
For now it only takes care of the single Jar <-> single Executable case.
This will take care of the majority (all?) use cases we have in nixpkgs
currently.

(cherry picked from commit 1415e30830)
2021-11-26 12:46:10 -03:00
Thiago Kenji Okada
0450d82508 Merge pull request #147501 from NixOS/backport-147459-to-release-21.11
[Backport release-21.11] Fix bash completion for stable nix-* commands with Nix 2.4
2021-11-26 12:43:10 -03:00
Aaron Andersen
a4df490585 Merge pull request #147504 from NixOS/backport-140743-to-release-21.11
[Backport release-21.11] nixos/acme: add an option for reloading systemd services after renewal
2021-11-26 09:37:43 -05:00
Robert Scott
791531028f ocaml: heed hardeningDisable flags set for individual versions
specifically this re-fixes ocaml 4.09 on clang by allowing its
hardeningDisable flags to take effect

(cherry picked from commit dc523cbb80)
2021-11-26 14:17:56 +00:00
Domen Kožar
24fbd9aa56 Merge pull request #147492 from NixOS/backport-147188-to-release-21.11
[Backport release-21.11] perlPackages.DistZilla: shortenPerlShebang on Darwin
2021-11-26 15:12:20 +01:00
Poscat
cc47d0d2f9 nixos/acme: add an option for reloading systemd services after renewal
(cherry picked from commit 88ad030bba8b90da97ac9638b0eec693fe78fc03)
2021-11-26 13:58:40 +00:00
Samuel Dionne-Riel
af945e4f0a nix-bash-completions: Reduce priority for Nix 2.4
Reducing the priority makes the system build prefer the Nix-provided
completions, for e.g. the new `nix` commands.

(cherry picked from commit 8608d393e8)
2021-11-26 13:37:25 +00:00
Samuel Dionne-Riel
68971fcd94 nixos: Provide nix-bash-completions again for stable commands
(cherry picked from commit 8e92630aae)
2021-11-26 13:37:25 +00:00
Jonathan Ringer
94ebde0d0e nodePackages.teck-programmer: fix build
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit 7be91b05bb)
2021-11-26 12:39:53 +00:00
Kerstin Humm
da25fe99c9 imagemagick: 7.1.0-15 -> 7.1.0-16
(cherry picked from commit 63ea61bcf0)
2021-11-26 12:20:51 +00:00
Mark Martinez
1324c7b8a7 perlPackages.DistZilla: shortenPerlShebang on Darwin
(cherry picked from commit b382ed47fd)
2021-11-26 12:13:44 +00:00
Shea Levy
8d73a66599 Merge branch 'bump-nix-plugins' into release-21.11 2021-11-26 06:48:49 -05:00
Bobby Rong
b34d0163e6 Merge pull request #147461 from NixOS/backport-147235-to-release-21.11
[Backport release-21.11] trilium: 0.48.6 -> 0.48.7
2021-11-26 15:52:09 +08:00
FliegendeWurst
1eda1b0121 trilium: 0.48.6 -> 0.48.7
(cherry picked from commit d2f4828871)
2021-11-26 07:33:50 +00:00
Artturi
191d498f20 Merge pull request #147417 from NixOS/backport-147397-to-release-21.11
[Backport release-21.11] graphviz_2_32, guitone: remove
2021-11-26 02:55:21 +02:00
Artturi
1e56179e56 Merge pull request #147431 from NixOS/backport-147423-to-release-21.11
[Backport release-21.11] python3Packages.pythonegardia: add patch for search path
2021-11-26 02:50:48 +02:00
Fabian Affolter
86013417ef python3Packages.pythonegardia: add patch for search path
(cherry picked from commit a952e5579b)
2021-11-25 23:20:37 +00:00
Artturi
dcfcd33a2c Merge pull request #147393 from NixOS/backport-147328-to-release-21.11 2021-11-26 00:17:15 +02:00
Kerstin Humm
63be96f65e graphviz_2_32: remove
It is broken and their is no usage in current nixpkgs.

Also the notice about its necessity is from 2014:
08131bd5d5

(cherry picked from commit 1d2c379e3b)
2021-11-25 21:20:05 +00:00
Kerstin Humm
5ebcd990a2 guitone: remove package
Guitone isn't used in Nixpkgs anywhere. It hasn't seen a release in 11 years
(6a09974e0f) and is unmaintained in
Nixpkgs. Also it's the sole remaining user of graphviz_2_32, which
should be removed as well.

(cherry picked from commit 86b2661837)
2021-11-25 21:20:05 +00:00
github-actions[bot]
a1ea9a0354 qemu: only include alsa-lib for alsa support
(cherry picked from commit 4b5c3d9376)

Co-authored-by: Alyssa Ross <hi@alyssa.is>
2021-11-25 16:02:35 -05:00
Artturi
ad61a44b4f Merge pull request #147407 from NixOS/backport-147210-to-release-21.11 2021-11-25 22:59:02 +02:00
Artturi
59131fe17f Merge pull request #147410 from NixOS/backport-147387-to-release-21.11 2021-11-25 22:58:24 +02:00
Jörg Thalheim
e4b974abd9 nix-eval-jobs: switch to nix stable
This also should make prevent breakages like https://github.com/NixOS/nixpkgs/pull/147376

(cherry picked from commit 856ce74b01)
2021-11-25 20:22:36 +00:00
Thiago Kenji Okada
02d15bbf53 Merge pull request #147391 from NixOS/backport-146958-to-release-21.11
[Backport release-21.11] Add missing libretro cores
2021-11-25 17:21:26 -03:00
Alyssa Ross
bbe83d7fe6 qemu: never use bundled Meson
It's better to fail to build if our version of Meson isn't compatible
with QEMU's, so we'll know something is wrong.  Otherwise, we'll get
subtle breakages that only manifest at runtime, which I think might be
what happened in 9e403b19a1 ("qemu: 5.1.0 -> 5.2.0") to necessitate
autoPatchelfHook.

(cherry picked from commit aa58876daf11fb082c5b74f143fba80f94b024a3)
2021-11-25 19:57:20 +00:00
Kerstin Humm
19a00b7ff3 python3Packages.nbclient: 0.5.8 -> 0.5.9
This also unbreaks the build, as for some reason the bin directory is
empty when doCheck = true and then the postFixup fails.

(cherry picked from commit a6c95f2706)
2021-11-25 20:42:02 +01:00
Vikram Narayanan
157f18a8cf yfinance: fix build
(cherry picked from commit 7402bc6c2e)
2021-11-25 18:37:21 +00:00
Thiago Kenji Okada
66a3f079dd libretro.blastem: init at unstable-2021-11-22
(cherry picked from commit 0e8e7c819c)
2021-11-25 18:19:02 +00:00
Thiago Kenji Okada
4758598be2 libretro: unstable-2021-11-16 -> unstable-2021-11-22
(cherry picked from commit 82b4887f1e)
2021-11-25 18:19:02 +00:00
Thiago Kenji Okada
31a0fd340f libretro.bsnes-hd: init at unstable-2021-11-22
(cherry picked from commit 9aee0414e0)
2021-11-25 18:19:02 +00:00
Thiago Kenji Okada
163b02910f libretro.bsnes: init at unstable-2021-11-22
(cherry picked from commit 2fe3827806)
2021-11-25 18:19:02 +00:00
Thiago Kenji Okada
83b3c244b4 libretro.mesen-s: init at unstable-2021-11-22
(cherry picked from commit d204860bf5)
2021-11-25 18:19:02 +00:00
Thiago Kenji Okada
8a1996baf6 libretro.mesen: switch to libretro/mesen
The original repository was abandoned.

(cherry picked from commit d03b66c4a6)
2021-11-25 18:19:01 +00:00
Thiago Kenji Okada
8878e56c56 libretro.melonds: init at unstable-2021-11-22
(cherry picked from commit 18bc6a9efe)
2021-11-25 18:19:01 +00:00
Thiago Kenji Okada
60258cd14f retroarch: switch from libretro-super to libretro-core-info
(cherry picked from commit 0d9f8458a6)
2021-11-25 18:19:01 +00:00
Thiago Kenji Okada
2ee2ba91b9 libretro.beetle-saturn-hw: remove
This core never worked as intended:
https://github.com/libretro/libretro-core-info/issues/8.

(cherry picked from commit 716deb5afb)
2021-11-25 18:19:01 +00:00
Thiago Kenji Okada
732fe0294a libretro.bsnes-mercury-{balanced,performance}: init at unstable-2021-11-16
(cherry picked from commit 17c37fe0bd)
2021-11-25 18:19:01 +00:00
Thiago Kenji Okada
9c36e80c81 libretro: expose mkLibeRetroCore function
This will allow users to package their own core derivations if they want
without necessary submitting to nixpkgs.

(cherry picked from commit 702c8f29fb)
2021-11-25 18:19:01 +00:00
Thiago Kenji Okada
acc46f1409 libretro.swanstation: init at unstable-2021-11-21
Sadly the original repository (stenzek/duckstation) is missing the
necessary files to build a libretro core, so we need to use the fork
instead.

(cherry picked from commit 994719881a)
2021-11-25 18:19:01 +00:00
Thiago Kenji Okada
79bd863190 libretro: make update.py script accept individual cores to update
(cherry picked from commit 33478a118c)
2021-11-25 18:19:01 +00:00
Artturi
7918d1c96b Merge pull request #147133 from NixOS/backport-147037-to-release-21.11 2021-11-25 19:23:57 +02:00
Artturi
cfe433d34f Merge pull request #147337 from NixOS/backport-147322-to-release-21.11 2021-11-25 19:22:57 +02:00
Artturi
7a7de52d11 Merge pull request #147341 from NixOS/backport-147173-to-release-21.11 2021-11-25 19:21:35 +02:00
Artturi
10276782a2 Merge pull request #147356 from NixOS/backport-147326-to-release-21.11 2021-11-25 19:21:22 +02:00
Artturi
4624e8775a Merge pull request #147383 from NixOS/backport-144449-to-release-21.11 2021-11-25 19:21:11 +02:00
Zane van Iperen
84a66218e9 protoc-gen-go-vtproto: init at 0.2.0
(cherry picked from commit aefd67192ea8ceff69cb9feedac676f97f905587)
2021-11-25 17:06:00 +00:00
Wael Nasreddine
f0c8f37376 Merge pull request #147284 from NixOS/backport-147097-to-release-21.11
[Backport release-21.11] bazel_4: Fix Bazel-built protoc segfault on macOS Monterey
2021-11-25 08:51:36 -08:00
Artturi
49a965f08d Merge pull request #147364 from NixOS/backport-146835-to-release-21.11
[Backport release-21.11] swayr: 0.7.0 -> 0.10.0
2021-11-25 16:05:36 +02:00
Thiago Kenji Okada
f49ee27c15 Merge pull request #147362 from NixOS/backport-147132-to-release-21.11
[Backport release-21.11] kratos: 0.7.6-alpha.1 -> 0.8.0-alpha.3
2021-11-25 10:47:35 -03:00
polykernel
0933c9acc7 swayr: 0.7.0 -> 0.10.0
(cherry picked from commit 7d310da826)
2021-11-25 13:41:07 +00:00
Anderson Torres
0b22897e08 Merge pull request #147353 from NixOS/backport-147247-to-release-21.11
[Backport release-21.11] audacious: 4.0.5 -> 4.1
2021-11-25 10:34:10 -03:00
Artturi
e40ee7f7b1 Merge pull request #147336 from NixOS/backport-147268-to-release-21.11
[Backport release-21.11] radeontop: 1.3 -> 1.4
2021-11-25 15:33:54 +02:00
Vladyslav Burzakovskyy
5653990ff4 kratos: 0.7.6-alpha.1 -> 0.8.0-alpha.3
(cherry picked from commit 4deec4ec53)
2021-11-25 13:23:38 +00:00
Vikram Narayanan
dcd36cba13 glymur: fix build
(cherry picked from commit 6dc23393d9)
2021-11-25 12:04:08 +00:00
Zane van Iperen
4cbacf85dc audacious: 4.0.5 -> 4.1
(cherry picked from commit ee718148c8)
2021-11-25 11:30:35 +00:00
Mathieu Westphal
29adfbfdd4 Updating F3D URLs for F3D migration
(cherry picked from commit a3cff8804fa4d11993d0054598f9cb36764446b8)
2021-11-25 08:16:43 +00:00
legendofmiracles
f5b9183859 ArchiSteamFarm: fix build
(cherry picked from commit 1eeffcbc01)
2021-11-25 07:16:18 +00:00
Domen Kožar
9ef5252db8 Merge pull request #147314 from NixOS/backport-147192-to-release-21.11
[Backport release-21.11] python3Packages.pyeclib: fix for darwin
2021-11-25 08:10:04 +01:00
Bjørn Forsman
f684632908 radeontop: 1.3 -> 1.4
It installs itself to $out/bin/ instead of $out/sbin/ now.

(cherry picked from commit 162546972b)
2021-11-25 06:35:56 +00:00
Dmitry Kalinkin
6d58566abd yoda: 1.9.2 -> 1.9.3
(cherry picked from commit d9e78207b6)
2021-11-25 00:55:16 -05:00
John Ericson
ac15fee49c Merge pull request #147318 from NixOS/backport-145107-to-release-21.11
[Backport release-21.11] build-support/rust: Fix sysroot for cross
2021-11-24 19:33:56 -05:00
John Ericson
5a709fd1f1 build-support/rust/sysroot/src: Use dont* instead of phase list
Making this separate commit because the original was moved out just the
way it was done before.

(cherry picked from commit 05efb8ed91)
2021-11-24 23:48:16 +00:00
John Ericson
b43bd0f0b5 Update script as rust-src layout has changed
Use stub lib so `core` and `alloc` are handled symmetrically.

(cherry picked from commit c9c3de0131)
2021-11-24 23:48:16 +00:00
John Ericson
7bdb287329 build-support/rust: Split out sysroot src derivation
Hoping to make it usable for `buildRustCrate` too.

(cherry picked from commit cbd00bab80)
2021-11-24 23:48:16 +00:00
John Ericson
8d36793dde rustcSrc: Reduce duplication
(cherry picked from commit 2c7f62379f)
2021-11-24 23:48:16 +00:00
Robert Scott
bc1944e4e5 python3Packages.pyeclib: fix for darwin
(cherry picked from commit 01296d775d)
2021-11-24 23:36:49 +00:00
Jan Tojnar
1066ac7ce9 Merge pull request #147301 from NixOS/backport-147292-to-release-21.11
[Backport release-21.11] sushi: fix runtime
2021-11-24 23:19:41 +01:00
Jan Tojnar
1eef408bf2 gnome.sushi: Enable more codecs
(cherry picked from commit f9212df975)
2021-11-24 21:36:03 +00:00
Jan Tojnar
9a41b4088b gnome.sushi: Fix runtime
(cherry picked from commit fda27cf38e)
2021-11-24 21:36:02 +00:00
Wael M. Nasreddine
b16d2ce858 bazel_4: Fix Bazel-built protoc segfault on macOS Monterey
This was fixed by enabling the user_link_flags_feature for macosx cc_toolchain_config.

References:
- https://github.com/bazelbuild/bazel/issues/14216
- https://github.com/bazelbuild/bazel/pull/14275

(cherry picked from commit dc8d4f31132eece959b481e30949ba5e3308e5ea)
2021-11-24 19:00:02 +00:00
Jonathan Ringer
ecf2a783b7 azure-cli: remove PEP420 patching to azure packages
(cherry picked from commit b731f025e0fc40717ecac8d9d426fae9695bfd41)
2021-11-24 10:22:54 -08:00
Jonathan Ringer
45a476b3ad azure-cli: 2.29.1 -> 2.30.0
(cherry picked from commit 005e8ca904d1b40df926df2112ca8ab47c6e49f7)
2021-11-24 10:22:54 -08:00
Jonathan Ringer
de936ccab3 python3Packages.azure-mgmt-servicelinker: init at 1.0.0b1
(cherry picked from commit f60fbca1aff7541f71d7a7bd1852fd929b1bf468)
2021-11-24 10:22:54 -08:00
Jonathan Ringer
ed88476bb3 python3Packages.azure-synapse-artifacts: 0.9.0 -> 0.10.0
(cherry picked from commit 8f9b6ec8147d53853d75602fb3d064fc88115f8b)
2021-11-24 10:22:54 -08:00
Jonathan Ringer
1d18baf55d python3Packages.azure-storage-blob: 12.8.1 -> 12.9.0
(cherry picked from commit cccca83e45f789081f733b29c7c437aa6758d3ca)
2021-11-24 10:22:54 -08:00
Jonathan Ringer
2e30172861 python3Packages.azure-mgmt-loganalytics: 11.0.0 -> 12.0.0
(cherry picked from commit 3b946af08e865df4b97f1d89455de787299d34fb)
2021-11-24 10:22:54 -08:00
Jonathan Ringer
e5bf410e99 python3Packages.azure-mgmt-keyvault: 9.2.0 -> 9.3.0
(cherry picked from commit 70c7ebb5d7f3c13d6ef283bf0ffc74ddec1ebecf)
2021-11-24 10:22:54 -08:00
Jonathan Ringer
5f2cee2316 python3Packages.azure-mgmt-cognitiveservices: 12.0.0 -> 13.0.0
(cherry picked from commit 5426ad1979908a8f0285dad20bc4a90a0f28d0be)
2021-11-24 10:22:54 -08:00
Jonathan Ringer
ff2082119b python3Packages.azure-eventgrid: 4.5.0 -> 4.7.1
(cherry picked from commit f6169d64945b282ad5d5731338e4d84516b81dd2)
2021-11-24 10:22:54 -08:00
Jonathan Ringer
06bd2e37d6 python3Packages.azure-core: 1.17.0 -> 1.20.1
(cherry picked from commit d8247404ef1b317e2c0f515f48c8502ced9274b2)
2021-11-24 10:22:54 -08:00
Vladimír Čunát
46725ae611 Merge #147252: xorg.xorgserver: apply upstream patch
... into release-21.11
2021-11-24 18:27:27 +01:00
Vladimír Čunát
cd37dfb95b Merge #147274: firefox-(devedition|beta)-bin: 94.0b2 -> 95.0b3 2021-11-24 18:22:45 +01:00
Thiago Kenji Okada
c146c3a5db Merge pull request #147271 from NixOS/backport-147168-to-release-21.11
[Backport release-21.11] varnish70: 7.0.0 -> 7.0.1
2021-11-24 14:15:05 -03:00
teutat3s
aef01a7e7f firefox-devedition-bin: 94.0b2 -> 95.0b3
(cherry picked from commit 422e19f7fe)
2021-11-24 17:07:36 +00:00
teutat3s
60d9aa27d0 firefox-beta-bin: 94.0b2 -> 95.0b3
(cherry picked from commit 4b92778d54)
2021-11-24 17:07:36 +00:00
ajs124
7ece17dade varnish70: 7.0.0 -> 7.0.1
(cherry picked from commit d1d48675c4)
2021-11-24 16:46:12 +00:00
Thiago Kenji Okada
b1b29acdee Merge pull request #147259 from NixOS/backport-146322-to-release-21.11
[Backport release-21.11] translate-shell: added missing (runtime) dependency on hexdump
2021-11-24 12:13:23 -03:00
Thiago Kenji Okada
d18ab49559 Merge pull request #147257 from NixOS/backport-147255-to-release-21.11
[Backport release-21.11] htop-vim: add meta.mainProgram
2021-11-24 11:24:36 -03:00
GOKOP
23ed0ced91 translate-shell: fixed indentation in default.nix
(cherry picked from commit 907ac61491)
2021-11-24 13:50:40 +00:00
GOKOP
23b52cf64e translate-shell: added missing dependency on hexdump
(cherry picked from commit 9e2669e4cd)
2021-11-24 13:50:40 +00:00
Samuel Gräfenstein
d7c5b5221e htop-vim: add meta.mainProgram
(cherry picked from commit 63a61947b9)
2021-11-24 13:48:18 +00:00
Thiago Kenji Okada
2e651faae0 Merge pull request #147231 from NixOS/backport-147201-to-release-21.11
[Backport release-21.11] python3Packages.datatable: fix for non-x86
2021-11-24 10:29:26 -03:00
Thiago Kenji Okada
1f9788fd87 Merge pull request #147254 from thiagokokada/backport-146730-to-release-21.11
[Backport release-21.11] htop-vim: init at unstable-2021-10-1
2021-11-24 10:19:31 -03:00
Thiago Kenji Okada
1f8cf59935 Merge pull request #147251 from NixOS/backport-147167-to-release-21.11
[Backport release-21.11] libreoffice: replace `openjdk` runtime-input with minimal JRE
2021-11-24 10:19:04 -03:00
Thiago Kenji Okada
783de9e18e htop-vim: init at unstable-2021-10-11 2021-11-24 09:59:23 -03:00
Vladimír Čunát
9103a7fbe7 xorg.xf86videoqxl: patch build after bool rename
(cherry picked from commit a7f2cd867a)
2021-11-24 12:23:21 +00:00
Vladimír Čunát
9d5df19071 xorg.xorgserver: apply upstream patch
This fixes xorg.xf86videovmware build (channel blocker).

(cherry picked from commit 0649fcdf26)
2021-11-24 12:23:21 +00:00
Maximilian Bosch
08fa2c16dd libreoffice: replace openjdk runtime-input with minimal JRE
Previously, `pkgs.libreoffice` had a total closure-size of 2.4GB where
`pkgs.openjdk` was a significant part:

    $ nix path-info ./result -Sh
    /nix/store/7xyfklmiz2azcnrfa8n9cz12dyyqc85r-libreoffice-7.1.7.2	   2.4G
    $ nix path-info ./result -shr | grep openjdk
    /nix/store/qcn7ihaak9g8ayyj4995ila2z0pkm37i-openjdk-17.0.1+12             	 643.6M

However we need exactly two components:

* a `javac` from `pkgs.openjdk`
* a minimal runtime (i.e. a JRE) for `libofficebean.so` where
  `libjawt.so` is also available.

I moved `jdk` to the `nativeBuildInputs` to ensure that `javac` is still
available in the build-environment and created a minimal JRE that seems
sufficient.

Now, the total closure-size is reduced by ~29.1% (basically the 600M
from `pkgs.openjdk`):

    $ nix path-info ./result -Sh
    /nix/store/zv34xijv64k7sz7rv50g3v6y59qg7p8k-libreoffice-7.1.7.2	   1.7G

(cherry picked from commit 2f9426ad83)
2021-11-24 12:09:58 +00:00
github-actions[bot]
b0ad371100 pytho3Packages.m3u8: use upstream patch
Follow up to 2b84c77b3e (python3Packages.m3u8: fix build on Hydra
(x86_64-darwin), 2021-11-19), now with upstream patch.

(cherry picked from commit 40c3bc3b08)

Co-authored-by: Sebastián Mancilla <smancill@smancill.dev>
2021-11-24 03:08:00 -05:00
Robert Scott
88c4b8a26f python3Packages.datatable: fix for non-x86
(cherry picked from commit 764aa245e17da3451abfa6b0e0c15f8fcfe95d14)
2021-11-24 07:01:38 +00:00
Artturi
a7e4a67cc1 Merge pull request #147214 from NixOS/backport-147205-to-release-21.11
[Backport release-21.11] mariadb: fix build on non-x86_64 linux
2021-11-24 05:09:58 +02:00
Vika Shleina
7eefdd54ad mariadb: fix build on non-x86_64 linux
pmdk is only available on x86_64-linux, yet included in other platforms.

Things tested:
 - build on x86_64-linux is the same (substituted from binary cache)
 - build on aarch64-linux doesn't crash now with an "unsupported system"

(cherry picked from commit ccb2baa615)
2021-11-24 01:32:24 +00:00
github-actions[bot]
036895751d [Backport release-21.11] Revert msize related commits (#147212)
Co-authored-by: Artturin <Artturin@artturin.com>
2021-11-24 02:56:02 +02:00
Thiago Kenji Okada
5b780cd4b0 Merge pull request #147211 from NixOS/backport-146933-to-release-21.11
[Backport release-21.11] dolphin-emu-beta: add update script, 5.0-15260 -> 5.0-15445
2021-11-23 21:41:22 -03:00
leo60228
24080a4660 dolphin-emu-beta: 5.0-15260 -> 5.0-15445
(cherry picked from commit c21b630d01)
2021-11-24 00:19:24 +00:00
leo60228
d105db9b88 dolphin-emu-beta: add update script
(cherry picked from commit 8de1b1bd48)
2021-11-24 00:19:24 +00:00
Thiago Kenji Okada
c06de2f6ab Merge pull request #147209 from NixOS/backport-147130-to-release-21.11
[Backport release-21.11] xmrig-mo: 6.15.0-mo1 -> 6.15.3-mo1
2021-11-23 21:15:47 -03:00
Thiago Kenji Okada
0fbebfd09a Merge pull request #147104 from NixOS/backport-146968-to-release-21.11
[Backport release-21.11] shaderc: include darwin libtool
2021-11-23 21:05:29 -03:00
Thiago Kenji Okada
350af91884 Merge pull request #147203 from NixOS/backport-147155-to-release-21.11
[Backport release-21.11]  python3Packages.detect-secrets: fix several disabled tests and build on darwin
2021-11-23 21:04:01 -03:00
Thiago Kenji Okada
c728578419 Merge pull request #147208 from NixOS/backport-147150-to-release-21.11
[Backport release-21.11] actionlint: 1.6.6 -> 1.6.8
2021-11-23 20:56:38 -03:00
Victor Freire
2d123c144f xmrig-mo: 6.15.0-mo1 -> 6.15.3-mo1
(cherry picked from commit 41cb4807ae)
2021-11-23 23:55:51 +00:00
Thiago Kenji Okada
45e8d21404 Merge pull request #147207 from NixOS/backport-147143-to-release-21.11
[Backport release-21.11] pipenv: 2021.11.9 -> 2021.11.23
2021-11-23 20:54:43 -03:00
Thiago Kenji Okada
66ea9af1be Merge pull request #147134 from NixOS/backport-143672-to-release-21.11
[Backport release-21.11] flatpak-builder: 1.0.14 -> 1.2.0
2021-11-23 20:53:12 -03:00
Thiago Kenji Okada
4fc6517ca1 Merge pull request #147164 from NixOS/backport-146731-to-release-21.11
[Backport release-21.11] thunderbird: 91.3.1 -> 91.3.2, thunderbird-bin: 91.3.0 -> 91.3.2
2021-11-23 20:51:41 -03:00
R. Ryantm
2e717b5f1e actionlint: 1.6.6 -> 1.6.8
(cherry picked from commit c9012aa712)
2021-11-23 23:38:15 +00:00
R. Ryantm
47c620a4de pipenv: 2021.11.9 -> 2021.11.23
(cherry picked from commit 66c2813707)
2021-11-23 23:31:48 +00:00
Sebastián Mancilla
958c7f0e50 python3Packages.detect-secrets: fix disabled tests and build on Darwin
- Clone the sources and leave the .git directory, and add Git to
  checkInputs to fix several failing tests (they use Git commands and
  expect to be inside a Git repository).

- Exclude a test failing on darwin.

(cherry picked from commit 29185d80e9)
2021-11-23 23:12:38 +00:00
Thiago Kenji Okada
70201e3246 Merge pull request #147135 from NixOS/backport-146868-to-release-21.11
[Backport release-21.11] Kernels 2021-11-21
2021-11-23 20:11:01 -03:00
Thiago Kenji Okada
329f234a2b Merge pull request #147178 from NixOS/backport-147139-to-staging-21.11
[Backport release-21.11] nnn: 4.3 → 4.4
2021-11-23 17:49:34 -03:00
Nikolay Korotkiy
26981cc345 nnn: 4.3 -> 4.4
(cherry picked from commit da3825a61f)
2021-11-23 20:28:16 +00:00
Thiago Kenji Okada
927abe0e7a Merge pull request #147076 from NixOS/backport-146639-to-release-21.11
[Backport release-21.11] thunderbird: reintroduce buildconfig patch to reduce closure size
2021-11-23 16:25:45 -03:00
Robert Scott
3d82502f2f python3Packages.cwcwidth: fix tests on darwin
use the same locale settings used by upstream's CI:
2bc4360474/.github/workflows/build.yaml (L33)

this has the effect of skipping some otherwise-failing tests on
darwin. seems slightly counterproductive but who am i to judge?

(cherry picked from commit 62b8957343e50cf50893ae58aaec623aeec9c39a)
2021-11-23 11:18:10 -08:00
Thiago Kenji Okada
fc9708b420 Merge pull request #147162 from NixOS/backport-146997-to-release-21.11
[Backport release-21.11] nordic: install the kde related themes
2021-11-23 15:20:22 -03:00
Thiago Kenji Okada
a47d24221a Merge pull request #147161 from thiagokokada/backport-147087-to-staging-21.11
[Backport release-21.11] slack: 4.2.1 -> 4.2.2
2021-11-23 15:19:48 -03:00
Thiago Kenji Okada
890beac459 Merge pull request #147160 from NixOS/backport-147154-to-release-21.11
[Backport release-21.11] warzone2100: 4.2.1 -> 4.2.2
2021-11-23 15:18:22 -03:00
taku0
797f561ef0 thunderbird: 91.3.1 -> 91.3.2
(cherry picked from commit bdae026114)
2021-11-23 18:01:49 +00:00
taku0
ab7e5092b8 thunderbird-bin: 91.3.0 -> 91.3.2
(cherry picked from commit 5ba8683709)
2021-11-23 18:01:48 +00:00
JesusMtnez
bd8abab7bf slack: 4.21.1 -> 4.22.0
(cherry picked from commit fff44a9c1a)
2021-11-23 15:00:45 -03:00
José Romildo
689e978e12 nordic: this git revision was released as stable
(cherry picked from commit ddc8642476)
2021-11-23 17:59:25 +00:00
José Romildo
1e0946e830 nordic: install the kde related themes
(cherry picked from commit 98fd890f48)
2021-11-23 17:59:25 +00:00
Francesco Gazzetta
6238d95fbc warzone2100: 4.2.1 -> 4.2.2
(cherry picked from commit e9f119566a)
2021-11-23 17:56:44 +00:00
Thiago Kenji Okada
4dc72e79cf Merge pull request #147141 from NixOS/backport-147120-to-release-21.11
[Backport release-21.11] corrosion: fix darwin build
2021-11-23 14:41:04 -03:00
Thiago Kenji Okada
b02e112e55 Merge pull request #147129 from NixOS/backport-146953-to-release-21.11
[Backport release-21.11] Gnome shell extensions: improvements
2021-11-23 14:40:14 -03:00
Thiago Kenji Okada
52257c0188 Merge pull request #147128 from NixOS/backport-146571-to-release-21.11
[Backport release-21.11] palemoon: 29.4.1 -> 29.4.2.1
2021-11-23 14:37:21 -03:00
Kerstin Humm
da5bf32659 imagemagick: 7.1.0-14 -> 7.1.0-15
(cherry picked from commit d3c7e5801f)
2021-11-23 17:48:57 +01:00
Finn Behrens
da53d876fa corrosion: fix darwin build
(cherry picked from commit 938989c5238462b5f629bfabc45aa858d2e8129a)
2021-11-23 16:19:20 +00:00
Artturi
0d638f17bb Merge pull request #147057 from sternenseemann/foot-1.10.1 2021-11-23 17:53:50 +02:00
TredwellGit
be370c5719 linux_zen: 5.15.2-zen1 -> 5.15.3-zen1
(cherry picked from commit ef17d66328)
2021-11-23 15:35:16 +00:00
TredwellGit
d2adbf2c44 linux_latest-libre: 18473 -> 18484
(cherry picked from commit 541a3a7332)
2021-11-23 15:35:16 +00:00
TredwellGit
167cd2af04 linux: 5.4.160 -> 5.4.161
(cherry picked from commit 392ccc5431)
2021-11-23 15:35:16 +00:00
TredwellGit
ee5389aa3c linux: 5.15.3 -> 5.15.4
(cherry picked from commit d789aebb56)
2021-11-23 15:35:16 +00:00
TredwellGit
6b174464a0 linux: 5.14.20 -> 5.14.21
(cherry picked from commit df8b7f5d06)
2021-11-23 15:35:16 +00:00
TredwellGit
c92cac02f4 linux: 5.10.80 -> 5.10.81
(cherry picked from commit 06629bb117)
2021-11-23 15:35:15 +00:00
Jan Tojnar
7233f09994 flatpak-builder: 1.0.14 → 1.2.0
- https://github.com/flatpak/flatpak-builder/releases/tag/1.1.1
- https://github.com/flatpak/flatpak-builder/releases/tag/1.1.2
- https://github.com/flatpak/flatpak-builder/releases/tag/1.2.0

Move patches just after src
Add debugedit dependency

(cherry picked from commit bd9179343a)
2021-11-23 15:25:53 +00:00
Jan Tojnar
f6e3df971f debugedit: unstable-2021-07-05 → 5.0
https://sourceware.org/git/?p=debugedit.git;a=shortlog;h=refs/tags/debugedit-5.0
(cherry picked from commit 0bbd6b822e)
2021-11-23 15:25:53 +00:00
Jan Tojnar
4304d1e852 gtk4.updateScript: correct policy
4.5.0 is unstable

(cherry picked from commit ad4ff3050d)
2021-11-23 15:14:42 +00:00
Jan Tojnar
128d5c0d18 libhandy: 1.4.0 → 1.5.0
https://ftp.gnome.org/pub/GNOME/sources/libhandy/1.5/libhandy-1.5.0.news

Adds style manager but unlike with libadwaita, it is opt-in so existing apps should not be affected:
https://gitlab.gnome.org/GNOME/libhandy/-/merge_requests/782#note_1257929

(cherry picked from commit e2b522ca01)
2021-11-23 15:14:42 +00:00
Jan Tojnar
58e3341445 gupnp-tools: 0.10.1 → 0.10.2
https://ftp.gnome.org/pub/GNOME/sources/gupnp-tools/0.10/gupnp-tools-0.10.2.news
(cherry picked from commit c87458e002)
2021-11-23 15:14:42 +00:00
Jan Tojnar
24f8034f6c gnome-builder: 41.1 → 41.2
https://ftp.gnome.org/pub/GNOME/sources/gnome-builder/41/gnome-builder-41.2.news
(cherry picked from commit 74a4876377)
2021-11-23 15:14:42 +00:00
Jan Tojnar
e096cdb68f gtk-vnc: 1.2.0 → 1.3.0
https://ftp.gnome.org/pub/GNOME/sources/gtk-vnc/1.3/gtk-vnc-1.3.0.news
(cherry picked from commit de1413c396)
2021-11-23 15:14:42 +00:00
Jan Tojnar
e08a3c268b gnome.gnome-screenshot: 40.0 → 41.0
https://ftp.gnome.org/pub/GNOME/sources/gnome-screenshot/41/gnome-screenshot-41.0.news
(cherry picked from commit e9f6e6c49f)
2021-11-23 15:14:42 +00:00
Jan Tojnar
ec59583f67 gnome.gnome-flashback: 3.40.0 → 3.42.0
https://ftp.gnome.org/pub/GNOME/sources/gnome-flashback/3.42/gnome-flashback-3.42.0.news
(cherry picked from commit 1ad7180e21)
2021-11-23 15:14:42 +00:00
Jan Tojnar
1f4ebe2fb5 evince: 41.2 → 41.3
https://ftp.gnome.org/pub/GNOME/sources/evince/41/evince-41.3.news
(cherry picked from commit e102c85c09)
2021-11-23 15:14:42 +00:00
Jan Tojnar
e3febdefff gnome.cheese: 41.0 → 41.1
https://ftp.gnome.org/pub/GNOME/sources/cheese/41/cheese-41.1.news
(cherry picked from commit 7635358235)
2021-11-23 15:14:42 +00:00
piegames
e71a79b78c gnomeExtensions: improve README
Document that the all-packages.nix needs to be updated too (this was forgotten
in the GNOME 41 update). Also fixed typos.

(cherry picked from commit e41a7715a2)
2021-11-23 14:20:31 +00:00
piegames
6b75050865 gnomeExtensions: improve override mechanism
The reduced reduncancy should help us avoid making some copy-paste errors,
as happened previously. Also, increased ergonomics.

(cherry picked from commit bc1f025afb)
2021-11-23 14:20:30 +00:00
piegames
fc002648f1 gnomeExtensions: expose gnome41Extensions in top-level
(cherry picked from commit 4a82bca530)
2021-11-23 14:20:30 +00:00
AndersonTorres
f04dc0a9b3 palemoon: factor mozconfig in a new file
It makes easier to understand and customize the building.

(cherry picked from commit 17dc5d7faa)
2021-11-23 13:58:18 +00:00
AndersonTorres
85a0f13ae3 palemoon: 29.4.1 -> 29.4.2.1
(cherry picked from commit 4041bc1830)
2021-11-23 13:58:18 +00:00
Maximilian Bosch
c6702166a6 Merge pull request #147124 from NixOS/backport-147116-to-release-21.11
[Backport release-21.11] matrix-synapse: 1.47.0 -> 1.47.1
2021-11-23 14:39:14 +01:00
eyjhb
c31ce6034b matrix-synapse: 1.47.0 -> 1.47.1
(cherry picked from commit 1cc5df0346)
2021-11-23 12:58:14 +00:00
Ana Hobden
f16cbd579b libtool: add meta.platforms and make cctools Darwin only
Signed-off-by: Ana Hobden <operator@hoverbear.org>
(cherry picked from commit bcb0427773)
2021-11-23 09:13:26 +00:00
Ana Hobden
6543d38122 shaderc: include darwin libtool
Signed-off-by: Ana Hobden <operator@hoverbear.org>
(cherry picked from commit e86fa71ba6)
2021-11-23 09:13:26 +00:00
github-actions[bot]
00b47a821d libcanberra-gtk3: mark as unbroken on darwin
gtk3-x11 was fixed by #132239.

(cherry picked from commit 74d907ad05)

Co-authored-by: Sebastián Mancilla <smancill@smancill.dev>
2021-11-23 02:30:44 -05:00
Evils
4350e484ec kicad: 5.1.11 -> 5.1.12
very minor change
5.1.11 was never officially released
  due to a re-tag

(cherry picked from commit 1f77bca43fb7ed68322fd3e3eae69cdc0094c0bc)
2021-11-23 15:22:01 +08:00
Francesco Gazzetta
1dbb98fab6 glm: fix aarch64-darwin build by fixing cmake warnings
(cherry picked from commit bebf8a19dd85b167d6c3f02f63a899982f9ab6c8)
2021-11-22 23:21:18 -08:00
arcnmx
b026e1cf87 python3Packages.hangups: fix async-timeout
(cherry picked from commit 9c390b6b38)
2021-11-22 21:55:56 -05:00
sternenseemann
20b36ff5dc nixos/documentation: index devman by default if enabled
It's quite ridiculous that we currently require manual intervention just
to have devman indexed if dev.enable == true.

(cherry picked from commit 2d59c66ea7e5fa7db2df18bc689c3e011debab73)
2021-11-22 20:57:42 -05:00
oxalica
75e4aacfc5 thunderbird: reintroduce buildconfig patch to reduce closure size
This (partially) reverts commit 9ea377439e.

(cherry picked from commit 7e899fd18e)
2021-11-23 01:39:31 +00:00
Jason A. Donenfeld
a80357ba7d Revert "wireguard-tools: allow system resolvconf implementation if available"
(cherry picked from commit 7727ce7c3b)
2021-11-23 08:53:35 +08:00
sternenseemann
7a200487a1 foot: 1.9.2 -> 1.10.1
https://codeberg.org/dnkl/foot/releases/tag/1.10.0
https://codeberg.org/dnkl/foot/releases/tag/1.10.1

Themes account for ~1/6th of foot's size, so installing them to a
separate output seems like a decent idea.

(cherry picked from commit a18f40f0e2)
2021-11-22 23:12:41 +01:00
Timothy DeHerrera
e3e553c5f5 21.11 Beta Release 2021-11-22 14:20:27 -07:00
1727 changed files with 41281 additions and 37965 deletions

22
.github/CODEOWNERS vendored
View File

@@ -7,6 +7,9 @@
# For documentation on this file, see https://help.github.com/articles/about-codeowners/
# Mentioned users will get code review requests.
# Release managers, release branch only
* @jonringer
# This file
/.github/CODEOWNERS @edolstra
@@ -32,7 +35,7 @@
/pkgs/top-level/stage.nix @nbp @Ericson2314 @matthewbauer
/pkgs/top-level/splice.nix @Ericson2314 @matthewbauer
/pkgs/top-level/release-cross.nix @Ericson2314 @matthewbauer
/pkgs/stdenv/generic @Ericson2314 @matthewbauer
/pkgs/stdenv/generic @Ericson2314 @matthewbauer @cab404
/pkgs/stdenv/cross @Ericson2314 @matthewbauer
/pkgs/build-support/cc-wrapper @Ericson2314 @orivej
/pkgs/build-support/bintools-wrapper @Ericson2314 @orivej
@@ -43,10 +46,8 @@
/pkgs/build-support/writers @lassulus @Profpatsch
# Nixpkgs documentation
/maintainers/scripts/db-to-md.sh @jtojnar @ryantm
/maintainers/scripts/doc @jtojnar @ryantm
/doc/build-aux/pandoc-filters @jtojnar
/doc/contributing/contributing-to-documentation.chapter.md @jtojnar
/maintainers/scripts/db-to-md.sh @ryantm
/maintainers/scripts/doc @ryantm
# NixOS Internals
/nixos/default.nix @nbp @infinisil
@@ -70,13 +71,6 @@
# NixOS integration test driver
/nixos/lib/test-driver @tfc
# Updaters
## update.nix
/maintainers/scripts/update.nix @jtojnar
/maintainers/scripts/update.py @jtojnar
## common-updater-scripts
/pkgs/common-updater/scripts/update-source-version @jtojnar
# Python-related code and docs
/maintainers/scripts/update-python-libraries @FRidh
/pkgs/top-level/python-packages.nix @FRidh @jonringer
@@ -205,9 +199,9 @@
/doc/languages-frameworks/php.section.md @NixOS/php @aanderse @etu @globin @ma27 @talyz
/nixos/tests/php @NixOS/php @aanderse @etu @globin @ma27 @talyz
/pkgs/build-support/build-pecl.nix @NixOS/php @aanderse @etu @globin @ma27 @talyz
/pkgs/development/interpreters/php @jtojnar @NixOS/php @aanderse @etu @globin @ma27 @talyz
/pkgs/development/interpreters/php @NixOS/php @aanderse @etu @globin @ma27 @talyz
/pkgs/development/php-packages @NixOS/php @aanderse @etu @globin @ma27 @talyz
/pkgs/top-level/php-packages.nix @jtojnar @NixOS/php @aanderse @etu @globin @ma27 @talyz
/pkgs/top-level/php-packages.nix @NixOS/php @aanderse @etu @globin @ma27 @talyz
# Podman, CRI-O modules and related
/nixos/modules/virtualisation/containers.nix @NixOS/podman @zowoq

View File

@@ -1,4 +1,4 @@
Copyright (c) 2003-2021 Eelco Dolstra and the Nixpkgs/NixOS contributors
Copyright (c) 2003-2022 Eelco Dolstra and the Nixpkgs/NixOS contributors
Permission is hereby granted, free of charge, to any person obtaining
a copy of this software and associated documentation files (the

View File

@@ -46,9 +46,9 @@ Nixpkgs and NixOS are built and tested by our continuous integration
system, [Hydra](https://hydra.nixos.org/).
* [Continuous package builds for unstable/master](https://hydra.nixos.org/jobset/nixos/trunk-combined)
* [Continuous package builds for the NixOS 21.05 release](https://hydra.nixos.org/jobset/nixos/release-21.05)
* [Continuous package builds for the NixOS 21.11 release](https://hydra.nixos.org/jobset/nixos/release-21.11)
* [Tests for unstable/master](https://hydra.nixos.org/job/nixos/trunk-combined/tested#tabs-constituents)
* [Tests for the NixOS 21.05 release](https://hydra.nixos.org/job/nixos/release-21.05/tested#tabs-constituents)
* [Tests for the NixOS 21.11 release](https://hydra.nixos.org/job/nixos/release-21.11/tested#tabs-constituents)
Artifacts successfully built with Hydra are published to cache at
https://cache.nixos.org/. When successful build and test criteria are

View File

@@ -29,7 +29,7 @@ How to add a new (major) version of the Linux kernel to Nixpkgs:
4. If needed you can also run `make menuconfig`:
```ShellSession
$ nix-env -i ncurses
$ nix-env -f "<nixpkgs>" -iA ncurses
$ export NIX_CFLAGS_LINK=-lncurses
$ make menuconfig ARCH=arch
```

View File

@@ -224,7 +224,7 @@ There are a few naming guidelines:
- Dashes in the package name _should_ be preserved in new variable names, rather than converted to underscores or camel cased — e.g., `http-parser` instead of `http_parser` or `httpParser`. The hyphenated style is preferred in all three package names.
- If there are multiple versions of a package, this _should_ be reflected in the variable names in `all-packages.nix`, e.g. `json-c-0-9` and `json-c-0-11`. If there is an obvious “default” version, make an attribute like `json-c = json-c-0-9;`. See also [](#sec-versioning)
- If there are multiple versions of a package, this _should_ be reflected in the variable names in `all-packages.nix`, e.g. `json-c_0_9` and `json-c_0_11`. If there is an obvious “default” version, make an attribute like `json-c = json-c_0_9;`. See also [](#sec-versioning)
## File naming and organisation {#sec-organisation}

View File

@@ -43,13 +43,13 @@
- nixpkgs:
- update pkg
- `nix-env -i pkg-name -f <path to your local nixpkgs folder>`
- `nix-env -iA pkg-attribute-name -f <path to your local nixpkgs folder>`
- add pkg
- Make sure its in `pkgs/top-level/all-packages.nix`
- `nix-env -i pkg-name -f <path to your local nixpkgs folder>`
- `nix-env -iA pkg-attribute-name -f <path to your local nixpkgs folder>`
- _If you dont want to install pkg in you profile_.
- `nix-build -A pkg-attribute-name <path to your local nixpkgs folder>/default.nix` and check results in the folder `result`. It will appear in the same directory where you did `nix-build`.
- If you did `nix-env -i pkg-name` you can do `nix-env -e pkg-name` to uninstall it from your system.
- `nix-build -A pkg-attribute-name <path to your local nixpkgs folder>` and check results in the folder `result`. It will appear in the same directory where you did `nix-build`.
- If you installed your package with `nix-env`, you can run `nix-env -e pkg-name` where `pkg-name` is as reported by `nix-env -q` to uninstall it from your system.
- NixOS and its modules:
- You can add new module to your NixOS configuration file (usually its `/etc/nixos/configuration.nix`). And do `sudo nixos-rebuild test -I nixpkgs=<path to your local nixpkgs folder> --fast`.
@@ -227,7 +227,7 @@ digraph {
}
```
[This GitHub Action](https://github.com/NixOS/nixpkgs/blob/master/.github/workflows/merge-staging.yml) brings changes from `master` to `staging-next` and from `staging-next` to `staging` every 6 hours.
[This GitHub Action](https://github.com/NixOS/nixpkgs/blob/master/.github/workflows/periodic-merge-6h.yml) brings changes from `master` to `staging-next` and from `staging-next` to `staging` every 6 hours.
### Master branch {#submitting-changes-master-branch}

View File

@@ -15,12 +15,12 @@ Modes of use of `emscripten`:
If you want to work with `emcc`, `emconfigure` and `emmake` as you are used to from Ubuntu and similar distributions you can use these commands:
* `nix-env -i emscripten`
* `nix-env -f "<nixpkgs>" -iA emscripten`
* `nix-shell -p emscripten`
* **Declarative usage**:
This mode is far more power full since this makes use of `nix` for dependency management of emscripten libraries and targets by using the `mkDerivation` which is implemented by `pkgs.emscriptenStdenv` and `pkgs.buildEmscriptenPackage`. The source for the packages is in `pkgs/top-level/emscripten-packages.nix` and the abstraction behind it in `pkgs/development/em-modules/generic/default.nix`.
This mode is far more power full since this makes use of `nix` for dependency management of emscripten libraries and targets by using the `mkDerivation` which is implemented by `pkgs.emscriptenStdenv` and `pkgs.buildEmscriptenPackage`. The source for the packages is in `pkgs/top-level/emscripten-packages.nix` and the abstraction behind it in `pkgs/development/em-modules/generic/default.nix`. From the root of the nixpkgs repository:
* build and install all packages:
* `nix-env -iA emscriptenPackages`

View File

@@ -5,10 +5,7 @@
The easiest way to get a working idris version is to install the `idris` attribute:
```ShellSession
$ # On NixOS
$ nix-env -i nixos.idris
$ # On non-NixOS
$ nix-env -i nixpkgs.idris
$ nix-env -f "<nixpkgs>" -iA idris
```
This however only provides the `prelude` and `base` libraries. To install idris with additional libraries, you can use the `idrisPackages.with-packages` function, e.g. in an overlay in `~/.config/nixpkgs/overlays/my-idris.nix`:

View File

@@ -24,18 +24,10 @@ You can test building an Octave package as follows:
$ nix-build -A octavePackages.symbolic
```
When building Octave packages with `nix-build`, the `buildOctavePackage` function adds `octave-octaveVersion` to; the start of the package's name attribute.
This can be required when installing the package using `nix-env`:
To install it into your user profile, run this command from the root of the repository:
```ShellSession
$ nix-env -i octave-6.2.0-symbolic
```
Although, you can also install it using the attribute name:
```ShellSession
$ nix-env -i -A octavePackages.symbolic
$ nix-env -f. -iA octavePackages.symbolic
```
You can build Octave with packages by using the `withPackages` passed-through function.

View File

@@ -58,13 +58,7 @@ in `all-packages.nix`. You can test building a Perl package as follows:
$ nix-build -A perlPackages.ClassC3
```
`buildPerlPackage` adds `perl-` to the start of the name attribute, so the package above is actually called `perl-Class-C3-0.21`. So to install it, you can say:
```ShellSession
$ nix-env -i perl-Class-C3
```
(Of course you can also install using the attribute name: `nix-env -i -A perlPackages.ClassC3`.)
To install it with `nix-env` instead: `nix-env -f. -iA perlPackages.ClassC3`.
So what does `buildPerlPackage` do? It does the following:
@@ -135,9 +129,11 @@ This will remove the `-I` flags from the shebang line, rewrite them in the `use
Nix expressions for Perl packages can be generated (almost) automatically from CPAN. This is done by the program `nix-generate-from-cpan`, which can be installed as follows:
```ShellSession
$ nix-env -i nix-generate-from-cpan
$ nix-env -f "<nixpkgs>" -iA nix-generate-from-cpan
```
Substitute `<nixpkgs>` by the path of a nixpkgs clone to use the latest version.
This program takes a Perl module name, looks it up on CPAN, fetches and unpacks the corresponding package, and prints a Nix expression on standard output. For example:
```ShellSession

View File

@@ -764,7 +764,7 @@ and in this case the `python38` interpreter is automatically used.
### Interpreters {#interpreters}
Versions 2.7, 3.6, 3.7, 3.8 and 3.9 of the CPython interpreter are available as
Versions 2.7, 3.7, 3.8 and 3.9 of the CPython interpreter are available as
respectively `python27`, `python37`, `python38` and `python39`. The
aliases `python2` and `python3` correspond to respectively `python27` and
`python39`. The attribute `python` maps to `python2`. The PyPy interpreters

View File

@@ -201,6 +201,19 @@ $ nix-shell --run 'ruby -rpg -e "puts PG.library_version"'
Of course for this use-case one could also use overlays since the configuration for `pg` depends on the `postgresql` alias, but for demonstration purposes this has to suffice.
### Platform-specific gems
Right now, bundix has some issues with pre-built, platform-specific gems: [bundix PR #68](https://github.com/nix-community/bundix/pull/68).
Until this is solved, you can tell bundler to not use platform-specific gems and instead build them from source each time:
- globally (will be set in `~/.config/.bundle/config`):
```shell
$ bundle config set force_ruby_platform true
```
- locally (will be set in `<project-root>/.bundle/config`):
```shell
$ bundle config set --local force_ruby_platform true
```
### Adding a gem to the default gemset {#adding-a-gem-to-the-default-gemset}
Now that you know how to get a working Ruby environment with Nix, it's time to go forward and start actually developing with Ruby. We will first have a look at how Ruby gems are packaged on Nix. Then, we will look at how you can use development mode with your code.

View File

@@ -20,17 +20,26 @@ let
readFile
;
# Returns the type of a path: regular (for file), symlink, or directory
pathType = p: getAttr (baseNameOf p) (readDir (dirOf p));
/*
Returns the type of a path: regular (for file), symlink, or directory.
*/
pathType = path: getAttr (baseNameOf path) (readDir (dirOf path));
# Returns true if the path exists and is a directory, false otherwise
pathIsDirectory = p: if pathExists p then (pathType p) == "directory" else false;
/*
Returns true if the path exists and is a directory, false otherwise.
*/
pathIsDirectory = path: if pathExists path then (pathType path) == "directory" else false;
# Returns true if the path exists and is a regular file, false otherwise
pathIsRegularFile = p: if pathExists p then (pathType p) == "regular" else false;
/*
Returns true if the path exists and is a regular file, false otherwise.
*/
pathIsRegularFile = path: if pathExists path then (pathType path) == "regular" else false;
# Bring in a path as a source, filtering out all Subversion and CVS
# directories, as well as backup files (*~).
/*
A basic filter for `cleanSourceWith` that removes
directories of version control system, backup files (*~)
and some generated files.
*/
cleanSourceFilter = name: type: let baseName = baseNameOf (toString name); in ! (
# Filter out version control software files/directories
(baseName == ".git" || type == "directory" && (baseName == ".svn" || baseName == "CVS" || baseName == ".hg")) ||
@@ -48,43 +57,48 @@ let
(type == "unknown")
);
# Filters a source tree removing version control files and directories using cleanSourceWith
#
# Example:
# cleanSource ./.
/*
Filters a source tree removing version control files and directories using cleanSourceFilter.
Example:
cleanSource ./.
*/
cleanSource = src: cleanSourceWith { filter = cleanSourceFilter; inherit src; };
# Like `builtins.filterSource`, except it will compose with itself,
# allowing you to chain multiple calls together without any
# intermediate copies being put in the nix store.
#
# lib.cleanSourceWith {
# filter = f;
# src = lib.cleanSourceWith {
# filter = g;
# src = ./.;
# };
# }
# # Succeeds!
#
# builtins.filterSource f (builtins.filterSource g ./.)
# # Fails!
#
# Parameters:
#
# src: A path or cleanSourceWith result to filter and/or rename.
#
# filter: A function (path -> type -> bool)
# Optional with default value: constant true (include everything)
# The function will be combined with the && operator such
# that src.filter is called lazily.
# For implementing a filter, see
# https://nixos.org/nix/manual/#builtin-filterSource
#
# name: Optional name to use as part of the store path.
# This defaults to `src.name` or otherwise `"source"`.
#
cleanSourceWith = { filter ? _path: _type: true, src, name ? null }:
/*
Like `builtins.filterSource`, except it will compose with itself,
allowing you to chain multiple calls together without any
intermediate copies being put in the nix store.
Example:
lib.cleanSourceWith {
filter = f;
src = lib.cleanSourceWith {
filter = g;
src = ./.;
};
}
# Succeeds!
builtins.filterSource f (builtins.filterSource g ./.)
# Fails!
*/
cleanSourceWith =
{
# A path or cleanSourceWith result to filter and/or rename.
src,
# Optional with default value: constant true (include everything)
# The function will be combined with the && operator such
# that src.filter is called lazily.
# For implementing a filter, see
# https://nixos.org/nix/manual/#builtin-filterSource
# Type: A function (path -> type -> bool)
filter ? _path: _type: true,
# Optional name to use as part of the store path.
# This defaults to `src.name` or otherwise `"source"`.
name ? null
}:
let
orig = toSourceAttributes src;
in fromSourceAttributes {
@@ -116,9 +130,11 @@ let
satisfiesSubpathInvariant = src ? satisfiesSubpathInvariant && src.satisfiesSubpathInvariant;
};
# Filter sources by a list of regular expressions.
#
# E.g. `src = sourceByRegex ./my-subproject [".*\.py$" "^database.sql$"]`
/*
Filter sources by a list of regular expressions.
Example: src = sourceByRegex ./my-subproject [".*\.py$" "^database.sql$"]
*/
sourceByRegex = src: regexes:
let
isFiltered = src ? _isLibCleanSourceWith;
@@ -153,8 +169,11 @@ let
pathIsGitRepo = path: (tryEval (commitIdFromGitRepo path)).success;
# Get the commit id of a git repo
# Example: commitIdFromGitRepo <nixpkgs/.git>
/*
Get the commit id of a git repo.
Example: commitIdFromGitRepo <nixpkgs/.git>
*/
commitIdFromGitRepo =
let readCommitFromFile = file: path:
let fileName = toString path + "/" + file;

View File

@@ -4,7 +4,9 @@
{ lib }:
rec {
# List of systems that are built by Hydra.
hydra = tier1 ++ tier2 ++ tier3;
hydra = tier1 ++ tier2 ++ tier3 ++ [
"aarch64-darwin"
];
tier1 = [
"x86_64-linux"
@@ -16,7 +18,6 @@ rec {
];
tier3 = [
"aarch64-darwin"
"armv6l-linux"
"armv7l-linux"
"i686-linux"

View File

@@ -62,17 +62,17 @@ checkConfigError() {
# Check boolean option.
checkConfigOutput "false" config.enable ./declare-enable.nix
checkConfigError 'The option .* does not exist. Definition values:\n\s*- In .*: true' config.enable ./define-enable.nix
checkConfigError 'The option .* does not exist. Definition values:\n- In .*: true' config.enable ./define-enable.nix
# Check integer types.
# unsigned
checkConfigOutput "42" config.value ./declare-int-unsigned-value.nix ./define-value-int-positive.nix
checkConfigError 'A definition for option .* is not of type.*unsigned integer.*. Definition values:\n\s*- In .*: -23' config.value ./declare-int-unsigned-value.nix ./define-value-int-negative.nix
checkConfigError 'A definition for option .* is not of type.*unsigned integer.*. Definition values:\n- In .*: -23' config.value ./declare-int-unsigned-value.nix ./define-value-int-negative.nix
# positive
checkConfigError 'A definition for option .* is not of type.*positive integer.*. Definition values:\n\s*- In .*: 0' config.value ./declare-int-positive-value.nix ./define-value-int-zero.nix
checkConfigError 'A definition for option .* is not of type.*positive integer.*. Definition values:\n- In .*: 0' config.value ./declare-int-positive-value.nix ./define-value-int-zero.nix
# between
checkConfigOutput "42" config.value ./declare-int-between-value.nix ./define-value-int-positive.nix
checkConfigError 'A definition for option .* is not of type.*between.*-21 and 43.*inclusive.*. Definition values:\n\s*- In .*: -23' config.value ./declare-int-between-value.nix ./define-value-int-negative.nix
checkConfigError 'A definition for option .* is not of type.*between.*-21 and 43.*inclusive.*. Definition values:\n- In .*: -23' config.value ./declare-int-between-value.nix ./define-value-int-negative.nix
# Check either types
# types.either
@@ -125,7 +125,7 @@ checkConfigOutput 'true' "$@" ./define-enable.nix ./define-attrsOfSub-foo-enable
set -- config.enable ./define-enable.nix ./declare-enable.nix
checkConfigOutput "true" "$@"
checkConfigOutput "false" "$@" ./disable-define-enable.nix
checkConfigError "The option .*enable.* does not exist. Definition values:\n\s*- In .*: true" "$@" ./disable-declare-enable.nix
checkConfigError "The option .*enable.* does not exist. Definition values:\n- In .*: true" "$@" ./disable-declare-enable.nix
checkConfigError "attribute .*enable.* in selection path .*config.enable.* not found" "$@" ./disable-define-enable.nix ./disable-declare-enable.nix
checkConfigError "attribute .*enable.* in selection path .*config.enable.* not found" "$@" ./disable-enable-modules.nix
@@ -142,18 +142,18 @@ checkConfigError 'infinite recursion encountered' "$@"
# Check _module.check.
set -- config.enable ./declare-enable.nix ./define-enable.nix ./define-attrsOfSub-foo.nix
checkConfigError 'The option .* does not exist. Definition values:\n\s*- In .*' "$@"
checkConfigError 'The option .* does not exist. Definition values:\n- In .*' "$@"
checkConfigOutput "true" "$@" ./define-module-check.nix
# Check coerced value.
checkConfigOutput "\"42\"" config.value ./declare-coerced-value.nix
checkConfigOutput "\"24\"" config.value ./declare-coerced-value.nix ./define-value-string.nix
checkConfigError 'A definition for option .* is not.*string or signed integer convertible to it.*. Definition values:\n\s*- In .*: \[ \]' config.value ./declare-coerced-value.nix ./define-value-list.nix
checkConfigError 'A definition for option .* is not.*string or signed integer convertible to it.*. Definition values:\n- In .*: \[ \]' config.value ./declare-coerced-value.nix ./define-value-list.nix
# Check coerced value with unsound coercion
checkConfigOutput "12" config.value ./declare-coerced-value-unsound.nix
checkConfigError 'A definition for option .* is not of type .*. Definition values:\n\s*- In .*: "1000"' config.value ./declare-coerced-value-unsound.nix ./define-value-string-bigint.nix
checkConfigError 'json.exception.parse_error' config.value ./declare-coerced-value-unsound.nix ./define-value-string-arbitrary.nix
checkConfigError 'A definition for option .* is not of type .*. Definition values:\n- In .*: "1000"' config.value ./declare-coerced-value-unsound.nix ./define-value-string-bigint.nix
checkConfigError 'unrecognised JSON value' config.value ./declare-coerced-value-unsound.nix ./define-value-string-arbitrary.nix
# Check mkAliasOptionModule.
checkConfigOutput "true" config.enable ./alias-with-priority.nix
@@ -169,7 +169,7 @@ checkConfigOutput "foo" config.submodule.foo ./declare-submoduleWith-special.nix
## shorthandOnlyDefines config behaves as expected
checkConfigOutput "true" config.submodule.config ./declare-submoduleWith-shorthand.nix ./define-submoduleWith-shorthand.nix
checkConfigError 'is not of type `boolean' config.submodule.config ./declare-submoduleWith-shorthand.nix ./define-submoduleWith-noshorthand.nix
checkConfigError "You're trying to declare a value of type \`bool'\n\s*rather than an attribute-set for the option" config.submodule.config ./declare-submoduleWith-noshorthand.nix ./define-submoduleWith-shorthand.nix
checkConfigError "You're trying to declare a value of type \`bool'\nrather than an attribute-set for the option" config.submodule.config ./declare-submoduleWith-noshorthand.nix ./define-submoduleWith-shorthand.nix
checkConfigOutput "true" config.submodule.config ./declare-submoduleWith-noshorthand.nix ./define-submoduleWith-noshorthand.nix
## submoduleWith should merge all modules in one swoop
@@ -193,7 +193,7 @@ checkConfigOutput "true" config.submodule.enable ./declare-submoduleWith-path.ni
checkConfigOutput "true" config.enable ./disable-recursive/main.nix
checkConfigOutput "true" config.enable ./disable-recursive/{main.nix,disable-foo.nix}
checkConfigOutput "true" config.enable ./disable-recursive/{main.nix,disable-bar.nix}
checkConfigError 'The option .* does not exist. Definition values:\n\s*- In .*: true' config.enable ./disable-recursive/{main.nix,disable-foo.nix,disable-bar.nix}
checkConfigError 'The option .* does not exist. Definition values:\n- In .*: true' config.enable ./disable-recursive/{main.nix,disable-foo.nix,disable-bar.nix}
# Check that imports can depend on derivations
checkConfigOutput "true" config.enable ./import-from-store.nix
@@ -277,7 +277,7 @@ checkConfigOutput baz config.value.nested.bar.baz ./types-anything/mk-mods.nix
## types.functionTo
checkConfigOutput "input is input" config.result ./functionTo/trivial.nix
checkConfigOutput "a b" config.result ./functionTo/merging-list.nix
checkConfigError 'A definition for option .fun.\[function body\]. is not of type .string.. Definition values:\n\s*- In .*wrong-type.nix' config.result ./functionTo/wrong-type.nix
checkConfigError 'A definition for option .fun.\[function body\]. is not of type .string.. Definition values:\n- In .*wrong-type.nix' config.result ./functionTo/wrong-type.nix
checkConfigOutput "b a" config.result ./functionTo/list-order.nix
checkConfigOutput "a c" config.result ./functionTo/merging-attrs.nix

View File

@@ -23,10 +23,6 @@ pkgs.runCommand "nixpkgs-lib-tests" {
export NIX_STORE_DIR=$TEST_ROOT/store
export PAGER=cat
cacheDir=$TEST_ROOT/binary-cache
mkdir -p $NIX_CONF_DIR
echo "experimental-features = nix-command" >> $NIX_CONF_DIR/nix.conf
nix-store --init
cp -r ${../.} lib

View File

@@ -26,7 +26,7 @@ touch {README.md,module.o,foo.bar}
# nix-instantiate doesn't write out the source, only computing the hash, so
# this uses the experimental nix command instead.
dir="$(nix eval --impure --raw --expr '(with import <nixpkgs/lib>; "${
dir="$(nix eval --raw '(with import <nixpkgs/lib>; "${
cleanSource ./.
}")')"
(cd $dir; find) | sort -f | diff -U10 - <(cat <<EOF
@@ -37,7 +37,7 @@ EOF
) || die "cleanSource 1"
dir="$(nix eval --impure --raw --expr '(with import <nixpkgs/lib>; "${
dir="$(nix eval --raw '(with import <nixpkgs/lib>; "${
cleanSourceWith { src = '"$work"'; filter = path: type: ! hasSuffix ".bar" path; }
}")')"
(cd $dir; find) | sort -f | diff -U10 - <(cat <<EOF
@@ -47,7 +47,7 @@ dir="$(nix eval --impure --raw --expr '(with import <nixpkgs/lib>; "${
EOF
) || die "cleanSourceWith 1"
dir="$(nix eval --impure --raw --expr '(with import <nixpkgs/lib>; "${
dir="$(nix eval --raw '(with import <nixpkgs/lib>; "${
cleanSourceWith { src = cleanSource '"$work"'; filter = path: type: ! hasSuffix ".bar" path; }
}")')"
(cd $dir; find) | sort -f | diff -U10 - <(cat <<EOF

View File

@@ -61,11 +61,11 @@ rec {
pipe = val: functions:
let reverseApply = x: f: f x;
in builtins.foldl' reverseApply val functions;
/* note please dont add a function like `compose = flip pipe`.
This would confuse users, because the order of the functions
in the list is not clear. With pipe, its obvious that it
goes first-to-last. With `compose`, not so much.
*/
# note please dont add a function like `compose = flip pipe`.
# This would confuse users, because the order of the functions
# in the list is not clear. With pipe, its obvious that it
# goes first-to-last. With `compose`, not so much.
## Named versions corresponding to some builtin operators.

View File

@@ -278,6 +278,12 @@
githubId = 1250775;
name = "Adolfo E. García Castro";
};
AdsonCicilioti = {
name = "Adson Cicilioti";
email = "adson.cicilioti@live.com";
github = "AdsonCicilioti";
githubId = 6278398;
};
adsr = {
email = "as@php.net";
github = "adsr";
@@ -1057,6 +1063,12 @@
githubId = 55833;
name = "Troels Henriksen";
};
atila = {
name = "Átila Saraiva";
email = "atilasaraiva@gmail.com";
github = "AtilaSaraiva";
githubId = 29521461;
};
atkinschang = {
email = "atkinschang+nixpkgs@gmail.com";
github = "AtkinsChang";
@@ -2599,6 +2611,12 @@
email = "christoph.senjak@googlemail.com";
name = "Christoph-Simon Senjak";
};
datafoo = {
email = "34766150+datafoo@users.noreply.github.com";
github = "datafoo";
githubId = 34766150;
name = "datafoo";
};
davhau = {
email = "d.hauer.it@gmail.com";
name = "David Hauer";
@@ -3343,6 +3361,12 @@
githubId = 103082;
name = "Ed Brindley";
};
elliot = {
email = "hack00mind@gmail.com";
github = "Eliot00";
githubId = 18375468;
name = "Elliot Xu";
};
elliottvillars = {
email = "elliottvillars@gmail.com";
github = "elliottvillars";
@@ -4667,6 +4691,12 @@
github = "higebu";
githubId = 733288;
};
hiljusti = {
name = "J.R. Hill";
email = "hiljusti@so.dang.cool";
github = "hiljusti";
githubId = 17605298;
};
hinton = {
email = "t@larkery.com";
name = "Tom Hinton";
@@ -5387,6 +5417,16 @@
githubId = 143075;
name = "James Felix Black";
};
jfchevrette = {
email = "jfchevrette@gmail.com";
github = "jfchevrette";
githubId = 3001;
name = "Jean-Francois Chevrette";
keys = [{
longkeyid = "rsa4096/0x67A0585801290DC6";
fingerprint = "B612 96A9 498E EECD D5E9 C0F0 67A0 5858 0129 0DC6";
}];
};
jflanglois = {
email = "yourstruly@julienlanglois.me";
github = "jflanglois";
@@ -6691,12 +6731,6 @@
githubId = 36448130;
name = "Michael Brantley";
};
linarcx = {
email = "linarcx@gmail.com";
github = "linarcx";
githubId = 10884422;
name = "Kaveh Ahangar";
};
linc01n = {
email = "git@lincoln.hk";
github = "linc01n";
@@ -6753,6 +6787,12 @@
githubId = 22085373;
name = "Luis Hebendanz";
};
lunarequest = {
email = "nullarequest@vivlaid.net";
github = "Lunarequest";
githubId = 30698906;
name = "Advaith Madhukar"; #this is my legal name, I prefer Luna; please keep that in mind!
};
lionello = {
email = "lio@lunesu.com";
github = "lionello";
@@ -7022,6 +7062,12 @@
githubId = 109141;
name = "Georges Dubus";
};
Madouura = {
email = "madouura@gmail.com";
github = "Madouura";
githubId = 93990818;
name = "Madoura";
};
mafo = {
email = "Marc.Fontaine@gmx.de";
github = "MarcFontaine";
@@ -8616,6 +8662,12 @@
githubId = 158758;
name = "Oliver Dunkl";
};
ofek = {
email = "oss@ofek.dev";
github = "ofek";
githubId = 9677399;
name = "Ofek Lev";
};
offline = {
email = "jaka@x-truder.net";
github = "offlinehacker";
@@ -11382,6 +11434,12 @@
githubId = 2389333;
name = "Andy Tockman";
};
techknowlogick = {
email = "techknowlogick@gitea.io";
github = "techknowlogick";
githubId = 164197;
name = "techknowlogick";
};
Technical27 = {
email = "38222826+Technical27@users.noreply.github.com";
github = "Technical27";

View File

@@ -74,7 +74,7 @@ with lib.maintainers; {
};
freedesktop = {
members = [ jtojnar ];
members = [ ];
scope = "Maintain Freedesktop.org packages for graphical desktop.";
};
@@ -105,7 +105,6 @@ with lib.maintainers; {
gnome = {
members = [
hedning
jtojnar
dasj19
maxeaubrey
];

View File

@@ -4,19 +4,19 @@ The test itself can be run interactively. This is particularly useful
when developing or debugging a test:
```ShellSession
$ nix-build nixos/tests/login.nix -A driverInteractive
$ nix-build . -A nixosTests.login.driverInteractive
$ ./result/bin/nixos-test-driver --interactive
starting VDE switch for network 1
>
[...]
>>>
```
You can then take any Python statement, e.g.
```py
> start_all()
> test_script()
> machine.succeed("touch /tmp/foo")
> print(machine.succeed("pwd")) # Show stdout of command
>>> start_all()
>>> test_script()
>>> machine.succeed("touch /tmp/foo")
>>> print(machine.succeed("pwd")) # Show stdout of command
```
The function `test_script` executes the entire test script and drops you

View File

@@ -24,8 +24,8 @@ After building/downloading all required dependencies, this will perform
a build that starts a QEMU/KVM virtual machine containing a NixOS
system. The virtual machine mounts the Nix store of the host; this makes
VM creation very fast, as no disk image needs to be created. Afterwards,
you can view a pretty-printed log of the test:
you can view a log of the test:
```ShellSession
$ firefox result/log.html
$ nix-store --read-log result
```

View File

@@ -5,19 +5,19 @@
useful when developing or debugging a test:
</para>
<programlisting>
$ nix-build nixos/tests/login.nix -A driverInteractive
$ nix-build . -A nixosTests.login.driverInteractive
$ ./result/bin/nixos-test-driver --interactive
starting VDE switch for network 1
&gt;
[...]
&gt;&gt;&gt;
</programlisting>
<para>
You can then take any Python statement, e.g.
</para>
<programlisting language="python">
&gt; start_all()
&gt; test_script()
&gt; machine.succeed(&quot;touch /tmp/foo&quot;)
&gt; print(machine.succeed(&quot;pwd&quot;)) # Show stdout of command
&gt;&gt;&gt; start_all()
&gt;&gt;&gt; test_script()
&gt;&gt;&gt; machine.succeed(&quot;touch /tmp/foo&quot;)
&gt;&gt;&gt; print(machine.succeed(&quot;pwd&quot;)) # Show stdout of command
</programlisting>
<para>
The function <literal>test_script</literal> executes the entire test

View File

@@ -26,9 +26,9 @@ machine: QEMU running (pid 8841)
perform a build that starts a QEMU/KVM virtual machine containing a
NixOS system. The virtual machine mounts the Nix store of the host;
this makes VM creation very fast, as no disk image needs to be
created. Afterwards, you can view a pretty-printed log of the test:
created. Afterwards, you can view a log of the test:
</para>
<programlisting>
$ firefox result/log.html
$ nix-store --read-log result
</programlisting>
</section>

View File

@@ -7,11 +7,11 @@
<para>
These instructions assume that you have an existing PXE or iPXE
infrastructure and simply want to add the NixOS installer as another
option. To build the necessary files from a recent version of
option. To build the necessary files from your current version of
nixpkgs, you can run:
</para>
<programlisting>
nix-build -A netboot.x86_64-linux nixos/release.nix
nix-build -A netboot.x86_64-linux '&lt;nixpkgs/nixos/release.nix&gt;'
</programlisting>
<para>
This will create a <literal>result</literal> directory containing: *

View File

@@ -12,7 +12,7 @@
<listitem>
<para>
<emphasis>Stable channels</emphasis>, such as
<link xlink:href="https://nixos.org/channels/nixos-21.05"><literal>nixos-21.05</literal></link>.
<link xlink:href="https://nixos.org/channels/nixos-21.11"><literal>nixos-21.11</literal></link>.
These only get conservative bug fixes and package upgrades. For
instance, a channel update may cause the Linux kernel on your
system to be upgraded from 4.19.34 to 4.19.38 (a minor bug fix),
@@ -33,7 +33,7 @@
<listitem>
<para>
<emphasis>Small channels</emphasis>, such as
<link xlink:href="https://nixos.org/channels/nixos-21.05-small"><literal>nixos-21.05-small</literal></link>
<link xlink:href="https://nixos.org/channels/nixos-21.11-small"><literal>nixos-21.11-small</literal></link>
or
<link xlink:href="https://nixos.org/channels/nixos-unstable-small"><literal>nixos-unstable-small</literal></link>.
These are identical to the stable and unstable channels
@@ -60,8 +60,8 @@
<para>
When you first install NixOS, youre automatically subscribed to the
NixOS channel that corresponds to your installation source. For
instance, if you installed from a 21.05 ISO, you will be subscribed
to the <literal>nixos-21.05</literal> channel. To see which NixOS
instance, if you installed from a 21.11 ISO, you will be subscribed
to the <literal>nixos-21.11</literal> channel. To see which NixOS
channel youre subscribed to, run the following as root:
</para>
<programlisting>
@@ -76,17 +76,17 @@ nixos https://nixos.org/channels/nixos-unstable
</programlisting>
<para>
(Be sure to include the <literal>nixos</literal> parameter at the
end.) For instance, to use the NixOS 21.05 stable channel:
end.) For instance, to use the NixOS 21.11 stable channel:
</para>
<programlisting>
# nix-channel --add https://nixos.org/channels/nixos-21.05 nixos
# nix-channel --add https://nixos.org/channels/nixos-21.11 nixos
</programlisting>
<para>
If you have a server, you may want to use the <quote>small</quote>
channel instead:
</para>
<programlisting>
# nix-channel --add https://nixos.org/channels/nixos-21.05-small nixos
# nix-channel --add https://nixos.org/channels/nixos-21.11-small nixos
</programlisting>
<para>
And if you want to live on the bleeding edge:
@@ -146,7 +146,7 @@ system.autoUpgrade.allowReboot = true;
also specify a channel explicitly, e.g.
</para>
<programlisting language="bash">
system.autoUpgrade.channel = https://nixos.org/channels/nixos-21.05;
system.autoUpgrade.channel = https://nixos.org/channels/nixos-21.11;
</programlisting>
</section>
</chapter>

View File

@@ -1,9 +1,5 @@
<section xmlns="http://docbook.org/ns/docbook" xmlns:xlink="http://www.w3.org/1999/xlink" xml:id="sec-release-21.11">
<title>Release 21.11 (“Porcupine”, 2021.11/??)</title>
<para>
In addition to numerous new and upgraded packages, this release has
the following highlights:
</para>
<title>Release 21.11 (“Porcupine”, 2021/11/30)</title>
<itemizedlist spacing="compact">
<listitem>
<para>
@@ -14,20 +10,60 @@
</itemizedlist>
<section xml:id="sec-release-21.11-highlights">
<title>Highlights</title>
<para>
In addition to numerous new and upgraded packages, this release
has the following highlights:
</para>
<itemizedlist>
<listitem>
<para>
Nix has been updated to version 2.4, reference its
The default Nix version remains at 2.3.16. Nix has not been
updated to version 2.4 due to regressions in non-experimental
behavior. To upgrade to 2.4, use the
<literal>nixos-unstable</literal> branch or set the
<literal>nix.package</literal> option to either of
<literal>nixFlakes</literal> or <literal>nix_2_4</literal>
packages. The <literal>nixUnstable</literal> attribute is a
pre-release of Nix 2.5. Read the
<link xlink:href="https://discourse.nixos.org/t/nix-2-4-released/15822">release
notes</link> for more information on what has changed. The
previous version of Nix, 2.3.16, remains available for the
time being in the <literal>nix_2_3</literal> package.
notes</link> for more information on upcoming changes. Please
help us improve Nix by providing any
<link xlink:href="https://github.com/NixOS/nix/issues">breakage
reports</link>.
</para>
</listitem>
<listitem>
<para>
<literal>iptables</literal> now uses
<literal>nf_tables</literal> backend.
<literal>iptables</literal> is now using
<literal>nf_tables</literal> under the hood, by using
<literal>iptables-nft</literal>, similar to
<link xlink:href="https://wiki.debian.org/nftables#Current_status">Debian</link>
and
<link xlink:href="https://fedoraproject.org/wiki/Changes/iptables-nft-default">Fedora</link>.
This means, <literal>ip[6]tables</literal>,
<literal>arptables</literal> and <literal>ebtables</literal>
commands will actually show rules from some specific tables in
the <literal>nf_tables</literal> kernel subsystem. In case
youre migrating from an older release without rebooting,
there might be cases where you end up with iptable rules
configured both in the legacy <literal>iptables</literal>
kernel backend, as well as in the <literal>nf_tables</literal>
backend. This can lead to confusing firewall behaviour. An
<literal>iptables-save</literal> after switching will complain
about <quote>iptables-legacy tables present</quote>. Its
probably best to reboot after the upgrade, or manually
removing all legacy iptables rules (via the
<literal>iptables-legacy</literal> package).
</para>
</listitem>
<listitem>
<para>
systemd got an <literal>nftables</literal> backend, and
configures (networkd) rules in their own
<literal>io.systemd.*</literal> tables. Check
<literal>nft list ruleset</literal> to see these rules, not
<literal>iptables-save</literal> (which only shows
<literal>iptables</literal>-created rules.
</para>
</listitem>
<listitem>
@@ -37,7 +73,7 @@
</listitem>
<listitem>
<para>
kOps now defaults to 1.21.1, which uses containerd as the
kops now defaults to 1.21.1, which uses containerd as the
default runtime.
</para>
</listitem>
@@ -84,13 +120,13 @@
</listitem>
<listitem>
<para>
Activation scripts can now opt int to be run when running
<literal>nixos-rebuild dry-activate</literal> and detect the
dry activation by reading <literal>$NIXOS_ACTION</literal>.
This allows activation scripts to output what they would
change if the activation was really run. The users/modules
activation script supports this and outputs some of is
actions.
Activation scripts can now, optionally, be run during a
<literal>nixos-rebuild dry-activate</literal> and can detect
the dry activation by reading
<literal>$NIXOS_ACTION</literal>. This allows activation
scripts to output what they would change if the activation was
really run. The users/modules activation script supports this
and outputs some of is actions.
</para>
</listitem>
<listitem>
@@ -172,6 +208,41 @@
</listitem>
</itemizedlist>
</listitem>
<listitem>
<para>
ORY Kratos was updated to version 0.8.0-alpha.3
</para>
<itemizedlist spacing="compact">
<listitem>
<para>
This release requires you to run SQL migrations. Please,
as always, create a backup of your database first!
</para>
</listitem>
<listitem>
<para>
The SDKs are now generated with tag v0alpha2 to reflect
that some signatures have changed in a breaking fashion.
Please update your imports from v0alpha1 to v0alpha2.
</para>
</listitem>
<listitem>
<para>
The SMTPS scheme used in courier config URL with
cleartext/StartTLS/TLS SMTP connection types is now only
supporting implicit TLS. For StartTLS and cleartext SMTP,
please use the SMTP scheme instead.
</para>
</listitem>
<listitem>
<para>
for more details, see
<link xlink:href="https://github.com/ory/kratos/releases/tag/v0.8.0-alpha.1">Release
Notes</link>.
</para>
</listitem>
</itemizedlist>
</listitem>
</itemizedlist>
</section>
<section xml:id="sec-release-21.11-new-services">
@@ -220,14 +291,14 @@
<para>
<link xlink:href="https://www.isc.org/kea/">Kea</link>, ISCs
2nd generation DHCP and DDNS server suite. Available at
<link xlink:href="options.html#opt-services.kea">services.kea</link>.
<link xlink:href="options.html#opt-services.kea.dhcp4">services.kea</link>.
</para>
</listitem>
<listitem>
<para>
<link xlink:href="https://owncast.online/">owncast</link>,
self-hosted video live streaming solution. Available at
<link xlink:href="options.html#opt-services.owncast">services.owncast</link>.
<link xlink:href="options.html#opt-services.owncast.enable">services.owncast</link>.
</para>
</listitem>
<listitem>
@@ -235,7 +306,7 @@
<link xlink:href="https://joinpeertube.org/">PeerTube</link>,
developed by Framasoft, is the free and decentralized
alternative to video platforms. Available at
<link xlink:href="options.html#opt-services.peertube">services.peertube</link>.
<link xlink:href="options.html#opt-services.peertube.enable">services.peertube</link>.
</para>
</listitem>
<listitem>
@@ -489,6 +560,23 @@
<link linkend="opt-services.ananicy.enable">services.ananicy</link>.
</para>
</listitem>
<listitem>
<para>
<link xlink:href="https://github.com/prometheus-community/smartctl_exporter">smartctl_exporter</link>,
a Prometheus exporter for
<link xlink:href="https://en.wikipedia.org/wiki/S.M.A.R.T.">S.M.A.R.T.</link>
data. Available as
<link xlink:href="options.html#opt-services.prometheus.exporters.smartctl.enable">services.prometheus.exporters.smartctl</link>.
</para>
</listitem>
<listitem>
<para>
<link xlink:href="https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-overview.html">filebeat</link>,
a lightweight shipper for forwarding and centralizing log
data. Available as
<link linkend="opt-services.filebeat.enable">services.filebeat</link>.
</para>
</listitem>
</itemizedlist>
</section>
<section xml:id="sec-release-21.11-incompatibilities">
@@ -1376,6 +1464,15 @@ Superuser created successfully.
for those who want to have all RetroArch cores available.
</para>
</listitem>
<listitem>
<para>
The Linux kernel for security reasons now restricts access to
BPF syscalls via <literal>BPF_UNPRIV_DEFAULT_OFF=y</literal>.
Unprivileged access can be reenabled via the
<literal>kernel.unprivileged_bpf_disabled</literal> sysctl
knob.
</para>
</listitem>
</itemizedlist>
</section>
<section xml:id="sec-release-21.11-notable-changes">
@@ -1825,15 +1922,6 @@ Superuser created successfully.
encapsulation.
</para>
</listitem>
<listitem>
<para>
Changing systemd <literal>.socket</literal> units now restarts
them and stops the service that is activated by them.
Additionally, services with
<literal>stopOnChange = false</literal> dont break anymore
when they are socket-activated.
</para>
</listitem>
<listitem>
<para>
The <literal>virtualisation.libvirtd</literal> module has been
@@ -1987,6 +2075,27 @@ Superuser created successfully.
file.
</para>
</listitem>
<listitem>
<para>
hydrus has been upgraded from version <literal>438</literal>
to <literal>463</literal>. Since upgrading between releases
this old is advised against, be sure to have a backup of your
data before upgrading. For details, see
<link xlink:href="https://hydrusnetwork.github.io/hydrus/help/getting_started_installing.html#big_updates">the
hydrus manual</link>.
</para>
</listitem>
<listitem>
<para>
<literal>pkgs.emacsPackages.orgPackages</literal> is removed
because org elpa is deprecated. The packages in the top level
of <literal>pkgs.emacsPackages</literal>, such as org and
org-contrib, refer to the ones in
<literal>pkgs.emacsPackages.elpaPackages</literal> and
<literal>pkgs.emacsPackages.nongnuPackages</literal> where the
new versions will release.
</para>
</listitem>
</itemizedlist>
</section>
</section>

View File

@@ -5,11 +5,11 @@ setup.
These instructions assume that you have an existing PXE or iPXE
infrastructure and simply want to add the NixOS installer as another
option. To build the necessary files from a recent version of nixpkgs,
option. To build the necessary files from your current version of nixpkgs,
you can run:
```ShellSession
nix-build -A netboot.x86_64-linux nixos/release.nix
nix-build -A netboot.x86_64-linux '<nixpkgs/nixos/release.nix>'
```
This will create a `result` directory containing: \* `bzImage` -- the

View File

@@ -6,7 +6,7 @@ expressions and associated binaries. The NixOS channels are updated
automatically from NixOS's Git repository after certain tests have
passed and all packages have been built. These channels are:
- *Stable channels*, such as [`nixos-21.05`](https://nixos.org/channels/nixos-21.05).
- *Stable channels*, such as [`nixos-21.11`](https://nixos.org/channels/nixos-21.11).
These only get conservative bug fixes and package upgrades. For
instance, a channel update may cause the Linux kernel on your system
to be upgraded from 4.19.34 to 4.19.38 (a minor bug fix), but not
@@ -19,7 +19,7 @@ passed and all packages have been built. These channels are:
radical changes between channel updates. It's not recommended for
production systems.
- *Small channels*, such as [`nixos-21.05-small`](https://nixos.org/channels/nixos-21.05-small)
- *Small channels*, such as [`nixos-21.11-small`](https://nixos.org/channels/nixos-21.11-small)
or [`nixos-unstable-small`](https://nixos.org/channels/nixos-unstable-small).
These are identical to the stable and unstable channels described above,
except that they contain fewer binary packages. This means they get updated
@@ -38,8 +38,8 @@ newest supported stable release.
When you first install NixOS, you're automatically subscribed to the
NixOS channel that corresponds to your installation source. For
instance, if you installed from a 21.05 ISO, you will be subscribed to
the `nixos-21.05` channel. To see which NixOS channel you're subscribed
instance, if you installed from a 21.11 ISO, you will be subscribed to
the `nixos-21.11` channel. To see which NixOS channel you're subscribed
to, run the following as root:
```ShellSession
@@ -54,16 +54,16 @@ To switch to a different NixOS channel, do
```
(Be sure to include the `nixos` parameter at the end.) For instance, to
use the NixOS 21.05 stable channel:
use the NixOS 21.11 stable channel:
```ShellSession
# nix-channel --add https://nixos.org/channels/nixos-21.05 nixos
# nix-channel --add https://nixos.org/channels/nixos-21.11 nixos
```
If you have a server, you may want to use the "small" channel instead:
```ShellSession
# nix-channel --add https://nixos.org/channels/nixos-21.05-small nixos
# nix-channel --add https://nixos.org/channels/nixos-21.11-small nixos
```
And if you want to live on the bleeding edge:
@@ -114,5 +114,5 @@ the new generation contains a different kernel, initrd or kernel
modules. You can also specify a channel explicitly, e.g.
```nix
system.autoUpgrade.channel = https://nixos.org/channels/nixos-21.05;
system.autoUpgrade.channel = https://nixos.org/channels/nixos-21.11;
```

View File

@@ -535,12 +535,8 @@
</para>
<para>
If <option>--build-host</option> is not explicitly specified,
<option>--build-host</option> will implicitly be set to the same value as
<option>--target-host</option>. So, if you only specify
<option>--target-host</option> both building and activation will take
place remotely (and no build artifacts will be copied to the local
machine).
If <option>--build-host</option> is not explicitly specified, building
will take place locally.
</para>
<para>

View File

@@ -3,10 +3,15 @@
xmlns:xi="http://www.w3.org/2001/XInclude">
<title>NixOS Reference Pages</title>
<info>
<author><personname><firstname>Eelco</firstname><surname>Dolstra</surname></personname>
<author>
<personname><firstname>Eelco</firstname><surname>Dolstra</surname></personname>
<contrib>Author</contrib>
</author>
<copyright><year>2007-2020</year><holder>Eelco Dolstra</holder>
<author>
<personname><othername>The Nixpkgs/NixOS contributors</othername></personname>
<contrib>Author</contrib>
</author>
<copyright><year>2007-2022</year><holder>Eelco Dolstra and the Nixpkgs/NixOS contributors</holder>
</copyright>
</info>
<xi:include href="man-configuration.xml" />

View File

@@ -1,18 +1,33 @@
# Release 21.11 (“Porcupine”, 2021.11/??) {#sec-release-21.11}
In addition to numerous new and upgraded packages, this release has the following highlights:
# Release 21.11 (“Porcupine”, 2021/11/30) {#sec-release-21.11}
- Support is planned until the end of June 2022, handing over to 22.05.
## Highlights {#sec-release-21.11-highlights}
- Nix has been updated to version 2.4, reference its [release notes](https://discourse.nixos.org/t/nix-2-4-released/15822) for more information on what has changed. The previous version of Nix, 2.3.16, remains available for the time being in the `nix_2_3` package.
In addition to numerous new and upgraded packages, this release has the following highlights:
- `iptables` now uses `nf_tables` backend.
- The default Nix version remains at 2.3.16. Nix has not been updated to version 2.4 due to regressions in non-experimental behavior. To upgrade to 2.4, use the `nixos-unstable` branch or set the `nix.package` option to either of `nixFlakes` or `nix_2_4` packages. The `nixUnstable` attribute is a pre-release of Nix 2.5. Read the [release notes](https://discourse.nixos.org/t/nix-2-4-released/15822) for more information on upcoming changes. Please help us improve Nix by providing any [breakage reports](https://github.com/NixOS/nix/issues).
- `iptables` is now using `nf_tables` under the hood, by using `iptables-nft`,
similar to [Debian](https://wiki.debian.org/nftables#Current_status) and
[Fedora](https://fedoraproject.org/wiki/Changes/iptables-nft-default).
This means, `ip[6]tables`, `arptables` and `ebtables` commands will actually
show rules from some specific tables in the `nf_tables` kernel subsystem.
In case you're migrating from an older release without rebooting, there might
be cases where you end up with iptable rules configured both in the legacy
`iptables` kernel backend, as well as in the `nf_tables` backend.
This can lead to confusing firewall behaviour. An `iptables-save` after
switching will complain about "iptables-legacy tables present".
It's probably best to reboot after the upgrade, or manually removing all
legacy iptables rules (via the `iptables-legacy` package).
- systemd got an `nftables` backend, and configures (networkd) rules in their
own `io.systemd.*` tables. Check `nft list ruleset` to see these rules, not
`iptables-save` (which only shows `iptables`-created rules.
- PHP now defaults to PHP 8.0, updated from 7.4.
- kOps now defaults to 1.21.1, which uses containerd as the default runtime.
- kops now defaults to 1.21.1, which uses containerd as the default runtime.
- `python3` now defaults to Python 3.9, updated from Python 3.8.
@@ -25,7 +40,7 @@ In addition to numerous new and upgraded packages, this release has the followin
- Hadoop now defaults to Hadoop 3, updated from 2.
- JournalNode, ZKFS and HTTPFS services have been added.
- Activation scripts can now opt int to be run when running `nixos-rebuild dry-activate` and detect the dry activation by reading `$NIXOS_ACTION`.
- Activation scripts can now, optionally, be run during a `nixos-rebuild dry-activate` and can detect the dry activation by reading `$NIXOS_ACTION`.
This allows activation scripts to output what they would change if the activation was really run.
The users/modules activation script supports this and outputs some of is actions.
@@ -50,6 +65,12 @@ In addition to numerous new and upgraded packages, this release has the followin
- This breaks connections to old SSH daemons as ssh-rsa host keys and ssh-rsa public keys that were signed with SHA-1 are disabled by default now
- These can be re-enabled, see the [OpenSSH changelog](https://www.openssh.com/txt/release-8.8) for details
- ORY Kratos was updated to version 0.8.0-alpha.3
- This release requires you to run SQL migrations. Please, as always, create a backup of your database first!
- The SDKs are now generated with tag v0alpha2 to reflect that some signatures have changed in a breaking fashion. Please update your imports from v0alpha1 to v0alpha2.
- The SMTPS scheme used in courier config URL with cleartext/StartTLS/TLS SMTP connection types is now only supporting implicit TLS. For StartTLS and cleartext SMTP, please use the SMTP scheme instead.
- for more details, see [Release Notes](https://github.com/ory/kratos/releases/tag/v0.8.0-alpha.1).
## New Services {#sec-release-21.11-new-services}
- [btrbk](https://digint.ch/btrbk/index.html), a backup tool for btrfs subvolumes, taking advantage of btrfs specific capabilities to create atomic snapshots and transfer them incrementally to your backup locations. Available as [services.btrbk](options.html#opt-services.brtbk.instances).
@@ -62,11 +83,11 @@ In addition to numerous new and upgraded packages, this release has the followin
- [Jibri](https://github.com/jitsi/jibri), a service for recording or streaming a Jitsi Meet conference. Available as [services.jibri](options.html#opt-services.jibri.enable).
- [Kea](https://www.isc.org/kea/), ISCs 2nd generation DHCP and DDNS server suite. Available at [services.kea](options.html#opt-services.kea).
- [Kea](https://www.isc.org/kea/), ISCs 2nd generation DHCP and DDNS server suite. Available at [services.kea](options.html#opt-services.kea.dhcp4).
- [owncast](https://owncast.online/), self-hosted video live streaming solution. Available at [services.owncast](options.html#opt-services.owncast).
- [owncast](https://owncast.online/), self-hosted video live streaming solution. Available at [services.owncast](options.html#opt-services.owncast.enable).
- [PeerTube](https://joinpeertube.org/), developed by Framasoft, is the free and decentralized alternative to video platforms. Available at [services.peertube](options.html#opt-services.peertube).
- [PeerTube](https://joinpeertube.org/), developed by Framasoft, is the free and decentralized alternative to video platforms. Available at [services.peertube](options.html#opt-services.peertube.enable).
- [sourcehut](https://sr.ht), a collection of tools useful for software development. Available as [services.sourcehut](options.html#opt-services.sourcehut.enable).
@@ -141,6 +162,10 @@ In addition to numerous new and upgraded packages, this release has the followin
- Auto nice daemons [ananicy](https://github.com/Nefelim4ag/Ananicy) and [ananicy-cpp](https://gitlab.com/ananicy-cpp/ananicy-cpp/). Available as [services.ananicy](#opt-services.ananicy.enable).
- [smartctl_exporter](https://github.com/prometheus-community/smartctl_exporter), a Prometheus exporter for [S.M.A.R.T.](https://en.wikipedia.org/wiki/S.M.A.R.T.) data. Available as [services.prometheus.exporters.smartctl](options.html#opt-services.prometheus.exporters.smartctl.enable).
- [filebeat](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-overview.html), a lightweight shipper for forwarding and centralizing log data. Available as [services.filebeat](#opt-services.filebeat.enable).
## Backward Incompatibilities {#sec-release-21.11-incompatibilities}
- The NixOS VM test framework, `pkgs.nixosTest`/`make-test-python.nix`, now requires detaching commands such as `succeed("foo &")` and `succeed("foo | xclip -i")` to close stdout.
@@ -409,6 +434,8 @@ In addition to numerous new and upgraded packages, this release has the followin
- `retroArchCores` has been removed. This means that using `nixpkgs.config.retroarch` to customize RetroArch cores is not supported anymore. Instead, use package overrides, for example: `retroarch.override { cores = with libretro; [ citra snes9x ]; };`. Also, `retroarchFull` derivation is available for those who want to have all RetroArch cores available.
- The Linux kernel for security reasons now restricts access to BPF syscalls via `BPF_UNPRIV_DEFAULT_OFF=y`. Unprivileged access can be reenabled via the `kernel.unprivileged_bpf_disabled` sysctl knob.
## Other Notable Changes {#sec-release-21.11-notable-changes}
@@ -514,8 +541,6 @@ In addition to numerous new and upgraded packages, this release has the followin
- `networking.sits` now supports Foo-over-UDP encapsulation.
- Changing systemd `.socket` units now restarts them and stops the service that is activated by them. Additionally, services with `stopOnChange = false` don't break anymore when they are socket-activated.
- The `virtualisation.libvirtd` module has been refactored and updated with new options:
- `virtualisation.libvirtd.qemu*` options (e.g.: `virtualisation.libvirtd.qemuRunAsRoot`) were moved to [`virtualisation.libvirtd.qemu`](options.html#opt-virtualisation.libvirtd.qemu) submodule,
- software TPM1/TPM2 support (e.g.: Windows 11 guests) ([`virtualisation.libvirtd.qemu.swtpm`](options.html#opt-virtualisation.libvirtd.qemu.swtpm)),
@@ -543,3 +568,7 @@ In addition to numerous new and upgraded packages, this release has the followin
- `julia` now refers to `julia-stable` instead of `julia-lts`. In practice this means it has been upgraded from `1.0.4` to `1.5.4`.
- RetroArch has been upgraded from version `1.8.5` to `1.9.13.2`. Since the previous release was quite old, if you're having issues after the upgrade, please delete your `$XDG_CONFIG_HOME/retroarch/retroarch.cfg` file.
- hydrus has been upgraded from version `438` to `463`. Since upgrading between releases this old is advised against, be sure to have a backup of your data before upgrading. For details, see [the hydrus manual](https://hydrusnetwork.github.io/hydrus/help/getting_started_installing.html#big_updates).
- `pkgs.emacsPackages.orgPackages` is removed because org elpa is deprecated. The packages in the top level of `pkgs.emacsPackages`, such as org and org-contrib, refer to the ones in `pkgs.emacsPackages.elpaPackages` and `pkgs.emacsPackages.nongnuPackages` where the new versions will release.

View File

@@ -61,7 +61,7 @@ in rec {
args = extraArgs;
specialArgs =
{ modulesPath = builtins.toString ../modules; } // specialArgs;
}) config options _module type;
}) config options _module type extendModules;
# These are the extra arguments passed to every module. In
# particular, Nixpkgs is passed through the "pkgs" argument.

View File

@@ -21,8 +21,15 @@ stdenv.mkDerivation {
# for nix-store --load-db.
cp $closureInfo/registration nix-path-registration
# 64 cores on i686 does not work
# fails with FATAL ERROR: mangle2:: xz compress failed with error code 5
if ((NIX_BUILD_CORES > 48)); then
NIX_BUILD_CORES=48
fi
# Generate the squashfs image.
mksquashfs nix-path-registration $(cat $closureInfo/store-paths) $out \
-no-hardlinks -keep-as-directory -all-root -b 1048576 -comp ${comp}
-no-hardlinks -keep-as-directory -all-root -b 1048576 -comp ${comp} \
-processors $NIX_BUILD_CORES
'';
}

View File

@@ -22,7 +22,7 @@ rec {
else throw "Unknown QEMU serial device for system '${pkgs.stdenv.hostPlatform.system}'";
qemuBinary = qemuPkg: {
x86_64-linux = "${qemuPkg}/bin/qemu-kvm -cpu max";
x86_64-linux = "${qemuPkg}/bin/qemu-kvm -cpu qemu64";
armv7l-linux = "${qemuPkg}/bin/qemu-system-arm -enable-kvm -machine virt -cpu host";
aarch64-linux = "${qemuPkg}/bin/qemu-system-aarch64 -enable-kvm -machine virt,gic-version=host -cpu host";
powerpc64le-linux = "${qemuPkg}/bin/qemu-system-ppc64 -machine powernv";

View File

@@ -171,7 +171,7 @@ class Logger:
yield
self.drain_log_queue()
toc = time.time()
self.log("({:.2f} seconds)".format(toc - tic))
self.log("(finished: {}, in {:.2f} seconds)".format(message, toc - tic))
self.xml.endElement("nest")
@@ -490,23 +490,24 @@ class Machine:
return rootlog.nested(msg, my_attrs)
def wait_for_monitor_prompt(self) -> str:
assert self.monitor is not None
answer = ""
while True:
undecoded_answer = self.monitor.recv(1024)
if not undecoded_answer:
break
answer += undecoded_answer.decode()
if answer.endswith("(qemu) "):
break
return answer
with self.nested("waiting for monitor prompt"):
assert self.monitor is not None
answer = ""
while True:
undecoded_answer = self.monitor.recv(1024)
if not undecoded_answer:
break
answer += undecoded_answer.decode()
if answer.endswith("(qemu) "):
break
return answer
def send_monitor_command(self, command: str) -> str:
message = ("{}\n".format(command)).encode()
self.log("sending monitor command: {}".format(command))
assert self.monitor is not None
self.monitor.send(message)
return self.wait_for_monitor_prompt()
with self.nested("sending monitor command: {}".format(command)):
message = ("{}\n".format(command)).encode()
assert self.monitor is not None
self.monitor.send(message)
return self.wait_for_monitor_prompt()
def wait_for_unit(self, unit: str, user: Optional[str] = None) -> None:
"""Wait for a systemd unit to get into "active" state.
@@ -533,7 +534,12 @@ class Machine:
return state == "active"
retry(check_active)
with self.nested(
"waiting for unit {}{}".format(
unit, f" with user {user}" if user is not None else ""
)
):
retry(check_active)
def get_unit_info(self, unit: str, user: Optional[str] = None) -> Dict[str, str]:
status, lines = self.systemctl('--no-pager show "{}"'.format(unit), user)
@@ -597,9 +603,14 @@ class Machine:
break
return "".join(output_buffer)
def execute(self, command: str, check_return: bool = True) -> Tuple[int, str]:
def execute(
self, command: str, check_return: bool = True, timeout: Optional[int] = 900
) -> Tuple[int, str]:
self.connect()
if timeout is not None:
command = "timeout {} sh -c {}".format(timeout, shlex.quote(command))
out_command = f"( set -euo pipefail; {command} ) | (base64 --wrap 0; echo)\n"
assert self.shell
self.shell.send(out_command.encode())
@@ -629,12 +640,12 @@ class Machine:
pass_fds=[self.shell.fileno()],
)
def succeed(self, *commands: str) -> str:
def succeed(self, *commands: str, timeout: Optional[int] = None) -> str:
"""Execute each command and check that it succeeds."""
output = ""
for command in commands:
with self.nested("must succeed: {}".format(command)):
(status, out) = self.execute(command)
(status, out) = self.execute(command, timeout=timeout)
if status != 0:
self.log("output: {}".format(out))
raise Exception(
@@ -643,12 +654,12 @@ class Machine:
output += out
return output
def fail(self, *commands: str) -> str:
def fail(self, *commands: str, timeout: Optional[int] = None) -> str:
"""Execute each command and check that it fails."""
output = ""
for command in commands:
with self.nested("must fail: {}".format(command)):
(status, out) = self.execute(command)
(status, out) = self.execute(command, timeout=timeout)
if status == 0:
raise Exception(
"command `{}` unexpectedly succeeded".format(command)
@@ -664,14 +675,14 @@ class Machine:
def check_success(_: Any) -> bool:
nonlocal output
status, output = self.execute(command)
status, output = self.execute(command, timeout=timeout)
return status == 0
with self.nested("waiting for success: {}".format(command)):
retry(check_success, timeout)
return output
def wait_until_fails(self, command: str) -> str:
def wait_until_fails(self, command: str, timeout: int = 900) -> str:
"""Wait until a command returns failure.
Throws an exception on timeout.
"""
@@ -679,7 +690,7 @@ class Machine:
def check_failure(_: Any) -> bool:
nonlocal output
status, output = self.execute(command)
status, output = self.execute(command, timeout=timeout)
return status != 0
with self.nested("waiting for failure: {}".format(command)):
@@ -752,7 +763,8 @@ class Machine:
status, _ = self.execute("nc -z localhost {}".format(port))
return status != 0
retry(port_is_closed)
with self.nested("waiting for TCP port {} to be closed"):
retry(port_is_closed)
def start_job(self, jobname: str, user: Optional[str] = None) -> Tuple[int, str]:
return self.systemctl("start {}".format(jobname), user)
@@ -886,24 +898,25 @@ class Machine:
retry(screen_matches)
def wait_for_console_text(self, regex: str) -> None:
self.log("waiting for {} to appear on console".format(regex))
# Buffer the console output, this is needed
# to match multiline regexes.
console = io.StringIO()
while True:
try:
console.write(self.last_lines.get())
except queue.Empty:
self.sleep(1)
continue
console.seek(0)
matches = re.search(regex, console.read())
if matches is not None:
return
with self.nested("waiting for {} to appear on console".format(regex)):
# Buffer the console output, this is needed
# to match multiline regexes.
console = io.StringIO()
while True:
try:
console.write(self.last_lines.get())
except queue.Empty:
self.sleep(1)
continue
console.seek(0)
matches = re.search(regex, console.read())
if matches is not None:
return
def send_key(self, key: str) -> None:
key = CHAR_TO_KEY.get(key, key)
self.send_monitor_command("sendkey {}".format(key))
time.sleep(0.01)
def start(self) -> None:
if self.booted:
@@ -1014,7 +1027,7 @@ class Machine:
)
return any(pattern.search(name) for name in names)
with self.nested("Waiting for a window to appear"):
with self.nested("waiting for a window to appear"):
retry(window_is_visible)
def sleep(self, secs: int) -> None:

View File

@@ -76,7 +76,7 @@ rec {
};
# Run an automated test suite in the given virtual network.
runTests = { driver, pos }:
runTests = { driver, driverInteractive, pos }:
stdenv.mkDerivation {
name = "vm-test-run-${driver.testName}";
@@ -93,7 +93,7 @@ rec {
'';
passthru = driver.passthru // {
inherit driver;
inherit driver driverInteractive;
};
inherit pos; # for better debugging
@@ -275,7 +275,7 @@ rec {
passMeta = drv: drv // lib.optionalAttrs (t ? meta) {
meta = (drv.meta or { }) // t.meta;
};
in passMeta (runTests { inherit driver pos; });
in passMeta (runTests { inherit driver pos driverInteractive; });
in
test // {

View File

@@ -22,8 +22,15 @@ let
'';
};
scudo = {
libPath = "${pkgs.llvmPackages_latest.compiler-rt}/lib/linux/libclang_rt.scudo-x86_64.so";
scudo = let
platformMap = {
aarch64-linux = "aarch64";
x86_64-linux = "x86_64";
};
systemPlatform = platformMap.${pkgs.stdenv.hostPlatform.system} or (throw "scudo not supported on ${pkgs.stdenv.hostPlatform.system}");
in {
libPath = "${pkgs.llvmPackages_latest.compiler-rt}/lib/linux/libclang_rt.scudo-${systemPlatform}.so";
description = ''
A user-mode allocator based on LLVM Sanitizers CombinedAllocator,
which aims at providing additional mitigations against heap based

View File

@@ -558,6 +558,7 @@ in {
input.gid = ids.gids.input;
kvm.gid = ids.gids.kvm;
render.gid = ids.gids.render;
sgx.gid = ids.gids.sgx;
shadow.gid = ids.gids.shadow;
};

View File

@@ -1,4 +1,4 @@
{ config, pkgs ,lib ,... }:
{ config, pkgs, lib, ... }:
with lib;
@@ -13,13 +13,13 @@ with lib;
options.xdg.portal = {
enable =
mkEnableOption "<link xlink:href='https://github.com/flatpak/xdg-desktop-portal'>xdg desktop integration</link>"//{
mkEnableOption "<link xlink:href='https://github.com/flatpak/xdg-desktop-portal'>xdg desktop integration</link>" // {
default = false;
};
extraPortals = mkOption {
type = types.listOf types.package;
default = [];
default = [ ];
description = ''
List of additional portals to add to path. Portals allow interaction
with system, like choosing files or taking screenshots. At minimum,
@@ -46,25 +46,36 @@ with lib;
let
cfg = config.xdg.portal;
packages = [ pkgs.xdg-desktop-portal ] ++ cfg.extraPortals;
joinedPortals = pkgs.symlinkJoin {
joinedPortals = pkgs.buildEnv {
name = "xdg-portals";
paths = cfg.extraPortals;
paths = packages;
pathsToLink = [ "/share/xdg-desktop-portal/portals" "/share/applications" ];
};
in mkIf cfg.enable {
in
mkIf cfg.enable {
assertions = [
{ assertion = (cfg.gtkUsePortal -> cfg.extraPortals != []);
message = "Setting xdg.portal.gtkUsePortal to true requires a portal implementation in xdg.portal.extraPortals such as xdg-desktop-portal-gtk or xdg-desktop-portal-kde.";
{
assertion = cfg.extraPortals != [ ];
message = "Setting xdg.portal.enable to true requires a portal implementation in xdg.portal.extraPortals such as xdg-desktop-portal-gtk or xdg-desktop-portal-kde.";
}
];
services.dbus.packages = packages;
services.dbus.packages = packages;
systemd.packages = packages;
environment.sessionVariables = {
GTK_USE_PORTAL = mkIf cfg.gtkUsePortal "1";
XDG_DESKTOP_PORTAL_DIR = "${joinedPortals}/share/xdg-desktop-portal/portals";
environment = {
# fixes screen sharing on plasmawayland on non-chromium apps by linking
# share/applications/*.desktop files
# see https://github.com/NixOS/nixpkgs/issues/145174
systemPackages = [ joinedPortals ];
pathsToLink = [ "/share/applications" ];
sessionVariables = {
GTK_USE_PORTAL = mkIf cfg.gtkUsePortal "1";
XDG_DESKTOP_PORTAL_DIR = "${joinedPortals}/share/xdg-desktop-portal/portals";
};
};
};
}

View File

@@ -0,0 +1,23 @@
{ config, lib, pkgs, ... }:
let
cfg = config.hardware.hackrf;
in
{
options.hardware.hackrf = {
enable = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
Enables hackrf udev rules and ensures 'plugdev' group exists.
This is a prerequisite to using HackRF devices without being root, since HackRF USB descriptors will be owned by plugdev through udev.
'';
};
};
config = lib.mkIf cfg.enable {
services.udev.packages = [ pkgs.hackrf ];
users.groups.plugdev = { };
};
}

View File

@@ -14,5 +14,5 @@ KERNEL=="ttyACM*", ATTRS{idVendor}=="1d50", ATTRS{idProduct}=="60fc", MODE:="066
#
ATTRS{idVendor}=="16c0", ATTRS{idProduct}=="04[789B]?", ENV{ID_MM_DEVICE_IGNORE}="1"
ATTRS{idVendor}=="16c0", ATTRS{idProduct}=="04[789A]?", ENV{MTP_NO_PROBE}="1"
SUBSYSTEMS=="usb", ATTRS{idVendor}=="16c0", ATTRS{idProduct}=="04[789ABCD]?", GROUP+="plugdev"
KERNEL=="ttyACM*", ATTRS{idVendor}=="16c0", ATTRS{idProduct}=="04[789B]?", GROUP+="plugdev"
SUBSYSTEMS=="usb", ATTRS{idVendor}=="16c0", ATTRS{idProduct}=="04[789ABCD]?", GROUP="plugdev"
KERNEL=="ttyACM*", ATTRS{idVendor}=="16c0", ATTRS{idProduct}=="04[789B]?", GROUP="plugdev"

View File

@@ -5,10 +5,14 @@ let
in {
options.hardware.rtl-sdr = {
enable = lib.mkEnableOption ''
Enables rtl-sdr udev rules, ensures 'plugdev' group exists, and blacklists DVB kernel modules.
This is a prerequisite to using devices supported by rtl-sdr without being root, since rtl-sdr USB descriptors will be owned by plugdev through udev.
'';
enable = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
Enables rtl-sdr udev rules, ensures 'plugdev' group exists, and blacklists DVB kernel modules.
This is a prerequisite to using devices supported by rtl-sdr without being root, since rtl-sdr USB descriptors will be owned by plugdev through udev.
'';
};
};
config = lib.mkIf cfg.enable {

View File

@@ -12,6 +12,5 @@ with lib;
boot.loader.systemd-boot.consoleMode = mkDefault "1";
# TODO Find reasonable defaults X11 & wayland
services.xserver.dpi = lib.mkDefault 192;
};
}

View File

@@ -94,7 +94,9 @@ with lib;
system.build.netbootIpxeScript = pkgs.writeTextDir "netboot.ipxe" ''
#!ipxe
kernel ${pkgs.stdenv.hostPlatform.linux-kernel.target} init=${config.system.build.toplevel}/init initrd=initrd ${toString config.boot.kernelParams}
# Use the cmdline variable to allow the user to specify custom kernel params
# when chainloading this script from other iPXE scripts like netboot.xyz
kernel ${pkgs.stdenv.hostPlatform.linux-kernel.target} init=${config.system.build.toplevel}/init initrd=initrd ${toString config.boot.kernelParams} ''${cmdline}
initrd initrd
boot
'';

View File

@@ -1,7 +1,7 @@
{
x86_64-linux = "/nix/store/hapw7q1fkjxvprnkcgw9ppczavg4daj2-nix-2.4";
i686-linux = "/nix/store/8qlvh8pp5j8wgrzj3is2jlbhgrwgsiy9-nix-2.4";
aarch64-linux = "/nix/store/h48lkygcqj4hdibbdnpl67q7ks6vkrd6-nix-2.4";
x86_64-darwin = "/nix/store/c3mvzszvyzakvcp9spnjvsb8m2bpjk7m-nix-2.4";
aarch64-darwin = "/nix/store/hbfqs62r0hga2yr4zi5kc7fzhf71bq9n-nix-2.4";
x86_64-linux = "/nix/store/nzp4m3cmm7wawk031byh8jg4cdzjq212-nix-2.3.16";
i686-linux = "/nix/store/zsaza9pwim617ak15fsc31lv65b9w3in-nix-2.3.16";
aarch64-linux = "/nix/store/7f6z40gyd405yd50qkyzwilnqw106bx8-nix-2.3.16";
x86_64-darwin = "/nix/store/c43kyri67ia8mibs0id5ara7gqwlkybf-nix-2.3.16";
aarch64-darwin = "/nix/store/6jwhak3cvsgnbqs540n27g8pxnk427fr-nix-2.3.16";
}

View File

@@ -62,32 +62,32 @@ mount --rbind /sys "$mountPoint/sys"
# modified from https://github.com/archlinux/arch-install-scripts/blob/bb04ab435a5a89cd5e5ee821783477bc80db797f/arch-chroot.in#L26-L52
chroot_add_resolv_conf() {
local chrootdir=$1 resolv_conf=$1/etc/resolv.conf
local chrootDir="$1" resolvConf="$1/etc/resolv.conf"
[[ -e /etc/resolv.conf ]] || return 0
# Handle resolv.conf as a symlink to somewhere else.
if [[ -L $chrootdir/etc/resolv.conf ]]; then
if [[ -L "$resolvConf" ]]; then
# readlink(1) should always give us *something* since we know at this point
# it's a symlink. For simplicity, ignore the case of nested symlinks.
# We also ignore the possibility if `../`s escaping the root.
resolv_conf=$(readlink "$chrootdir/etc/resolv.conf")
if [[ $resolv_conf = /* ]]; then
resolv_conf=$chrootdir$resolv_conf
# We also ignore the possibility of `../`s escaping the root.
resolvConf="$(readlink "$resolvConf")"
if [[ "$resolvConf" = /* ]]; then
resolvConf="$chrootDir$resolvConf"
else
resolv_conf=$chrootdir/etc/$resolv_conf
resolvConf="$chrootDir/etc/$resolvConf"
fi
fi
# ensure file exists to bind mount over
if [[ ! -f $resolv_conf ]]; then
install -Dm644 /dev/null "$resolv_conf" || return 1
if [[ ! -f "$resolvConf" ]]; then
install -Dm644 /dev/null "$resolvConf" || return 1
fi
mount --bind /etc/resolv.conf "$resolv_conf"
mount --bind /etc/resolv.conf "$resolvConf"
}
chroot_add_resolv_conf "$mountPoint" || print "ERROR: failed to set up resolv.conf"
chroot_add_resolv_conf "$mountPoint" || echo "$0: failed to set up resolv.conf" >&2
(
# If silent, write both stdout and stderr of activation script to /dev/null

View File

@@ -80,6 +80,10 @@ let
];
};
# list of man outputs currently active intended for use as default values
# for man-related options, thus "man" is included unconditionally.
activeManOutputs = [ "man" ] ++ lib.optionals cfg.dev.enable [ "devman" ];
in
{
@@ -130,7 +134,7 @@ in
name = "man-paths";
paths = config.environment.systemPackages;
pathsToLink = [ "/share/man" ];
extraOutputsToInstall = ["man"];
extraOutputsToInstall = activeManOutputs;
ignoreCollisions = true;
};
defaultText = literalDocBook "all man pages in <option>config.environment.systemPackages</option>";
@@ -226,7 +230,7 @@ in
(mkIf cfg.man.enable {
environment.systemPackages = [ pkgs.man-db ];
environment.pathsToLink = [ "/share/man" ];
environment.extraOutputsToInstall = [ "man" ] ++ optional cfg.dev.enable "devman";
environment.extraOutputsToInstall = activeManOutputs;
environment.etc."man_db.conf".text =
let
manualCache = pkgs.runCommandLocal "man-cache" { } ''

View File

@@ -351,6 +351,7 @@ in
hqplayer = 319;
moonraker = 320;
distcc = 321;
pipewire = 322;
# When adding a uid, make sure it doesn't match an existing gid. And don't use uids above 399!
@@ -638,7 +639,7 @@ in
qemu-libvirtd = 301;
kvm = 302; # default udev rules from systemd requires these
render = 303; # default udev rules from systemd requires these
# zeronet = 304; # removed 2019-01-03
sgx = 304; # default udev rules from systemd requires these
lirc = 305;
lidarr = 306;
slurm = 307;
@@ -656,6 +657,7 @@ in
hqplayer = 319;
moonraker = 320;
distcc = 321;
pipewire = 322;
# When adding a gid, make sure it doesn't match an existing
# uid. Users and groups with the same name should have equal

View File

@@ -202,7 +202,7 @@ in {
PRUNEFS="${lib.concatStringsSep " " cfg.pruneFS}"
PRUNENAMES="${lib.concatStringsSep " " cfg.pruneNames}"
PRUNEPATHS="${lib.concatStringsSep " " cfg.prunePaths}"
PRUNE_BIND_MOUNTSFR="${lib.boolToString cfg.pruneBindMounts}"
PRUNE_BIND_MOUNTS="${if cfg.pruneBindMounts then "yes" else "no"}"
'';
};
};

View File

@@ -54,6 +54,18 @@ in
'';
};
buildDocsInSandbox = mkOption {
type = types.bool // {
merge = loc: defs: defs;
};
internal = true;
default = false;
description = ''
This is an effectless placeholder, so modules from master don't fail to evaluate on systems based on nixos-21.11.
See <link xlink:href="https://github.com/NixOS/nixpkgs/pull/149532"/>
'';
};
};
};

View File

@@ -76,7 +76,7 @@ in
defaultChannel = mkOption {
internal = true;
type = types.str;
default = "https://nixos.org/channels/nixos-unstable";
default = "https://nixos.org/channels/nixos-21.11";
description = "Default NixOS channel to which the root user is subscribed.";
};

View File

@@ -51,6 +51,7 @@
./hardware/gkraken.nix
./hardware/flirc.nix
./hardware/i2c.nix
./hardware/hackrf.nix
./hardware/sensor/hddtemp.nix
./hardware/sensor/iio.nix
./hardware/keyboard/teck.nix
@@ -446,6 +447,7 @@
./services/hardware/xow.nix
./services/logging/SystemdJournal2Gelf.nix
./services/logging/awstats.nix
./services/logging/filebeat.nix
./services/logging/fluentd.nix
./services/logging/graylog.nix
./services/logging/heartbeat.nix
@@ -953,6 +955,7 @@
./services/security/vault.nix
./services/security/vaultwarden/default.nix
./services/security/yubikey-agent.nix
./services/system/cachix-agent/default.nix
./services/system/cloud-init.nix
./services/system/dbus.nix
./services/system/earlyoom.nix

View File

@@ -77,6 +77,7 @@ let
unitConfig = {
ConditionPathExists = "!/var/lib/acme/.minica/key.pem";
StartLimitIntervalSec = 0;
};
serviceConfig = commonServiceConfig // {
@@ -235,6 +236,7 @@ let
unitConfig = {
ConditionPathExists = "!/var/lib/acme/${cert}/key.pem";
StartLimitIntervalSec = 0;
};
serviceConfig = commonServiceConfig // {
@@ -314,13 +316,17 @@ let
if [ -e renewed ]; then
rm renewed
${data.postRun}
${optionalString (data.reloadServices != [])
"systemctl --no-block try-reload-or-restart ${escapeShellArgs data.reloadServices}"
}
fi
'');
};
# Working directory will be /tmp
script = ''
set -euxo pipefail
${optionalString data.enableDebugLogs "set -x"}
set -euo pipefail
# This reimplements the expiration date check, but without querying
# the acme server first. By doing this offline, we avoid errors
@@ -433,6 +439,8 @@ let
default = "_mkMergedOptionModule";
};
enableDebugLogs = mkEnableOption "debug logging for this certificate" // { default = cfg.enableDebugLogs; };
webroot = mkOption {
type = types.nullOr types.str;
default = null;
@@ -474,6 +482,15 @@ let
description = "Group running the ACME client.";
};
reloadServices = mkOption {
type = types.listOf types.str;
default = [];
description = ''
The list of systemd services to call <code>systemctl try-reload-or-restart</code>
on.
'';
};
postRun = mkOption {
type = types.lines;
default = "";
@@ -602,6 +619,8 @@ in {
options = {
security.acme = {
enableDebugLogs = mkEnableOption "debug logging for all certificates by default" // { default = true; };
validMinDays = mkOption {
type = types.int;
default = 30;

View File

@@ -253,7 +253,7 @@ chmod 400 /var/lib/secrets/certs.secret
</programlisting>
<para>
Now you're all set to generate certs! You should monitor the first invokation
Now you're all set to generate certs! You should monitor the first invocation
by running <literal>systemctl start acme-example.com.service &amp;
journalctl -fu acme-example.com.service</literal> and watching its log output.
</para>

View File

@@ -244,8 +244,6 @@ in
security.apparmor.includes."nixos/security.wrappers" = ''
include "${pkgs.apparmorRulesFromClosure { name="security.wrappers"; } [
securityWrapper
pkgs.stdenv.cc.cc
pkgs.stdenv.cc.libc
]}"
'';

View File

@@ -54,12 +54,12 @@ let
# tcp json rpc
++ [ "--tcp.enabled ${toString cfg.tcp.enable}" ]
++ optionals cfg.tcp.enable [
"--tcp.address ${cfg.tcp.listenAddress}"
"--tcp.bind_to_address ${cfg.tcp.listenAddress}"
"--tcp.port ${toString cfg.tcp.port}" ]
# http json rpc
++ [ "--http.enabled ${toString cfg.http.enable}" ]
++ optionals cfg.http.enable [
"--http.address ${cfg.http.listenAddress}"
"--http.bind_to_address ${cfg.http.listenAddress}"
"--http.port ${toString cfg.http.port}"
] ++ optional (cfg.http.docRoot != null) "--http.doc_root \"${toString cfg.http.docRoot}\"");

View File

@@ -152,7 +152,6 @@ let
serviceConfig = {
# The service's only task is to ensure that the specified path exists
Type = "oneshot";
WorkingDirectory = cfg.path;
};
wantedBy = [ "multi-user.target" ];
};

View File

@@ -354,6 +354,7 @@ in
wantedBy = [ "multi-user.target" ];
after = [ "systemd-tmpfiles-clean.service" ];
requires = [ "network.target" ];
serviceConfig = {
Type = "forking";
@@ -363,12 +364,12 @@ in
ExecReload = "${pkgs.coreutils}/bin/kill -HUP $MAINPID";
LimitMEMLOCK = "infinity";
};
preStart = ''
mkdir -p /var/spool
'';
};
systemd.tmpfiles.rules = mkIf cfg.client.enable [
"d /var/spool/slurmd 755 root root -"
];
services.openssh.forwardX11 = mkIf cfg.client.enable (mkDefault true);
systemd.services.slurmctld = mkIf (cfg.server.enable) {

View File

@@ -10,6 +10,8 @@ let
stateDir = "%S/${systemdDir}";
# %L: Log directory root (usually /var/log); see systemd.unit(5)
logsDir = "%L/${systemdDir}";
# Name of file stored in service state directory
currentConfigTokenFilename = ".current-token";
in
{
options.services.github-runner = {
@@ -143,13 +145,11 @@ in
ExecStart = "${cfg.package}/bin/runsvc.sh";
# Does the following, sequentially:
# - Copy the current and the previous `tokenFile` to the $RUNTIME_DIRECTORY
# and make it accessible to the service user to allow for a content
# comparison.
# - If the module configuration or the token has changed, clear the state directory.
# - Configure the runner.
# - Copy the configured `tokenFile` to the $STATE_DIRECTORY and make it
# inaccessible to the service user.
# - If the module configuration or the token has changed, purge the state directory,
# and create the current and the new token file with the contents of the configured
# token. While both files have the same content, only the later is accessible by
# the service user.
# - Configure the runner using the new token file. When finished, delete it.
# - Set up the directory structure by creating the necessary symlinks.
ExecStartPre =
let
@@ -172,37 +172,20 @@ in
currentConfigPath = "$STATE_DIRECTORY/.nixos-current-config.json";
runnerRegistrationConfig = getAttrs [ "name" "tokenFile" "url" "runnerGroup" "extraLabels" ] cfg;
newConfigPath = builtins.toFile "${svcName}-config.json" (builtins.toJSON runnerRegistrationConfig);
currentConfigTokenFilename = ".current-token";
newConfigTokenFilename = ".new-token";
runnerCredFiles = [
".credentials"
".credentials_rsaparams"
".runner"
];
ownConfigTokens = writeScript "own-config-tokens" ''
# Copy current and new token file to runtime dir and make it accessible to the service user
cp ${escapeShellArg cfg.tokenFile} "$RUNTIME_DIRECTORY/${newConfigTokenFilename}"
chmod 600 "$RUNTIME_DIRECTORY/${newConfigTokenFilename}"
chown "$USER" "$RUNTIME_DIRECTORY/${newConfigTokenFilename}"
if [[ -e "$STATE_DIRECTORY/${currentConfigTokenFilename}" ]]; then
cp "$STATE_DIRECTORY/${currentConfigTokenFilename}" "$RUNTIME_DIRECTORY/${currentConfigTokenFilename}"
chmod 600 "$RUNTIME_DIRECTORY/${currentConfigTokenFilename}"
chown "$USER" "$RUNTIME_DIRECTORY/${currentConfigTokenFilename}"
fi
'';
disownConfigTokens = writeScript "disown-config-tokens" ''
# Make the token inaccessible to the runner service user
chmod 600 "$STATE_DIRECTORY/${currentConfigTokenFilename}"
chown root:root "$STATE_DIRECTORY/${currentConfigTokenFilename}"
'';
unconfigureRunner = writeScript "unconfigure" ''
differs=
# Set `differs = 1` if current and new runner config differ or if `currentConfigPath` does not exist
${pkgs.diffutils}/bin/diff -q '${newConfigPath}' "${currentConfigPath}" >/dev/null 2>&1 || differs=1
# Also trigger a registration if the token content changed
${pkgs.diffutils}/bin/diff -q \
"$RUNTIME_DIRECTORY"/{${currentConfigTokenFilename},${newConfigTokenFilename}} \
"$STATE_DIRECTORY"/${currentConfigTokenFilename} \
${escapeShellArg cfg.tokenFile} \
>/dev/null 2>&1 || differs=1
if [[ -n "$differs" ]]; then
@@ -210,13 +193,18 @@ in
echo "The old runner will still appear in the GitHub Actions UI." \
"You have to remove it manually."
find "$STATE_DIRECTORY/" -mindepth 1 -delete
# Copy the configured token file to the state dir and allow the service user to read the file
install --mode=666 ${escapeShellArg cfg.tokenFile} "$STATE_DIRECTORY/${newConfigTokenFilename}"
# Also copy current file to allow for a diff on the next start
install --mode=600 ${escapeShellArg cfg.tokenFile} "$STATE_DIRECTORY/${currentConfigTokenFilename}"
fi
'';
configureRunner = writeScript "configure" ''
empty=$(ls -A "$STATE_DIRECTORY")
if [[ -z "$empty" ]]; then
if [[ -e "$STATE_DIRECTORY/${newConfigTokenFilename}" ]]; then
echo "Configuring GitHub Actions Runner"
token=$(< "$RUNTIME_DIRECTORY"/${newConfigTokenFilename})
token=$(< "$STATE_DIRECTORY"/${newConfigTokenFilename})
RUNNER_ROOT="$STATE_DIRECTORY" ${cfg.package}/bin/config.sh \
--unattended \
--work "$RUNTIME_DIRECTORY" \
@@ -233,8 +221,7 @@ in
rm -rf "$STATE_DIRECTORY/_diag/"
# Cleanup token from config
rm -f "$RUNTIME_DIRECTORY"/${currentConfigTokenFilename}
mv "$RUNTIME_DIRECTORY"/${newConfigTokenFilename} "$STATE_DIRECTORY/${currentConfigTokenFilename}"
rm "$STATE_DIRECTORY/${newConfigTokenFilename}"
# Symlink to new config
ln -s '${newConfigPath}' "${currentConfigPath}"
@@ -249,10 +236,8 @@ in
'';
in
map (x: "${x} ${escapeShellArgs [ stateDir runtimeDir logsDir ]}") [
"+${ownConfigTokens}" # runs as root
unconfigureRunner
"+${unconfigureRunner}" # runs as root
configureRunner
"+${disownConfigTokens}" # runs as root
setupRuntimeDir
];
@@ -265,6 +250,13 @@ in
StateDirectoryMode = "0700";
WorkingDirectory = runtimeDir;
InaccessiblePaths = [
# Token file path given in the configuration
cfg.tokenFile
# Token file in the state directory
"${stateDir}/${currentConfigTokenFilename}"
];
# By default, use a dynamically allocated user
DynamicUser = true;

View File

@@ -183,6 +183,11 @@ in {
preStart = ''
touch ${cfg.configFile}
if ! test -e ${cfg.databaseDir}/.erlang.cookie; then
touch ${cfg.databaseDir}/.erlang.cookie
chmod 600 ${cfg.databaseDir}/.erlang.cookie
dd if=/dev/random bs=16 count=1 | base64 > ${cfg.databaseDir}/.erlang.cookie
fi
'';
environment = {
@@ -192,6 +197,7 @@ in {
# 3. the extraConfig from the module options
# 4. the locally writable config file, which couchdb itself writes to
ERL_FLAGS= ''-couch_ini ${cfg.package}/etc/default.ini ${configFile} ${pkgs.writeText "couchdb-extra.ini" cfg.extraConfig} ${cfg.configFile}'';
HOME =''${cfg.databaseDir}'';
};
serviceConfig = {

View File

@@ -54,7 +54,7 @@ in
systemd.packages = [ cfg.package ];
services.udev.packages = [ pkgs.libmtp.bin ];
services.udev.packages = [ pkgs.libmtp.out ];
# Needed for unwrapped applications
environment.variables.GIO_EXTRA_MODULES = [ "${cfg.package}/lib/gio/modules" ];

View File

@@ -94,6 +94,12 @@ in {
config = mkIf cfg.enable {
environment.systemPackages = [ cfg.package ];
systemd.packages = [ cfg.package ];
# Enable either system or user units.
systemd.services.pipewire-media-session.enable = config.services.pipewire.systemWide;
systemd.user.services.pipewire-media-session.enable = !config.services.pipewire.systemWide;
systemd.services.pipewire-media-session.wantedBy = [ "pipewire.service" ];
systemd.user.services.pipewire-media-session.wantedBy = [ "pipewire.service" ];
environment.etc."pipewire/media-session.d/media-session.conf" = {

View File

@@ -123,6 +123,22 @@ in {
pulse = {
enable = mkEnableOption "PulseAudio server emulation";
};
systemWide = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
If true, a system-wide PipeWire service and socket is enabled
allowing all users in the "pipewire" group to use it simultaneously.
If false, then user units are used instead, restricting access to
only one user.
Enabling system-wide PipeWire is however not recommended and disabled
by default according to
https://github.com/PipeWire/pipewire/blob/master/NEWS
'';
};
};
};
@@ -148,9 +164,20 @@ in {
# PipeWire depends on DBUS but doesn't list it. Without this booting
# into a terminal results in the service crashing with an error.
systemd.services.pipewire.bindsTo = [ "dbus.service" ];
systemd.user.services.pipewire.bindsTo = [ "dbus.service" ];
# Enable either system or user units. Note that for pipewire-pulse there
# are only user units, which work in both cases.
systemd.sockets.pipewire.enable = cfg.systemWide;
systemd.services.pipewire.enable = cfg.systemWide;
systemd.user.sockets.pipewire.enable = !cfg.systemWide;
systemd.user.services.pipewire.enable = !cfg.systemWide;
systemd.sockets.pipewire.wantedBy = lib.mkIf cfg.socketActivation [ "sockets.target" ];
systemd.user.sockets.pipewire.wantedBy = lib.mkIf cfg.socketActivation [ "sockets.target" ];
systemd.user.sockets.pipewire-pulse.wantedBy = lib.mkIf (cfg.socketActivation && cfg.pulse.enable) ["sockets.target"];
systemd.user.services.pipewire.bindsTo = [ "dbus.service" ];
services.udev.packages = [ cfg.package ];
# If any paths are updated here they must also be updated in the package test.
@@ -194,7 +221,22 @@ in {
environment.sessionVariables.LD_LIBRARY_PATH =
lib.optional cfg.jack.enable "${cfg.package.jack}/lib";
users = lib.mkIf cfg.systemWide {
users.pipewire = {
uid = config.ids.uids.pipewire;
group = "pipewire";
extraGroups = [
"audio"
"video"
] ++ lib.optional config.security.rtkit.enable "rtkit";
description = "Pipewire system service user";
isSystemUser = true;
};
groups.pipewire.gid = config.ids.gids.pipewire;
};
# https://gitlab.freedesktop.org/pipewire/pipewire/-/issues/464#note_723554
systemd.services.pipewire.environment."PIPEWIRE_LINK_PASSIVE" = "1";
systemd.user.services.pipewire.environment."PIPEWIRE_LINK_PASSIVE" = "1";
};
}

View File

@@ -0,0 +1,253 @@
{ config, lib, utils, pkgs, ... }:
let
inherit (lib)
attrValues
literalExpression
mkEnableOption
mkIf
mkOption
types;
cfg = config.services.filebeat;
json = pkgs.formats.json {};
in
{
options = {
services.filebeat = {
enable = mkEnableOption "filebeat";
package = mkOption {
type = types.package;
default = pkgs.filebeat;
defaultText = literalExpression "pkgs.filebeat";
example = literalExpression "pkgs.filebeat7";
description = ''
The filebeat package to use.
'';
};
inputs = mkOption {
description = ''
Inputs specify how Filebeat locates and processes input data.
This is like <literal>services.filebeat.settings.filebeat.inputs</literal>,
but structured as an attribute set. This has the benefit
that multiple NixOS modules can contribute settings to a
single filebeat input.
An input type can be specified multiple times by choosing a
different <literal>&lt;name></literal> for each, but setting
<xref linkend="opt-services.filebeat.inputs._name_.type"/>
to the same value.
See <link xlink:href="https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html"/>.
'';
default = {};
type = types.attrsOf (types.submodule ({ name, ... }: {
freeformType = json.type;
options = {
type = mkOption {
type = types.str;
default = name;
description = ''
The input type.
Look for the value after <literal>type:</literal> on
the individual input pages linked from
<link xlink:href="https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html"/>.
'';
};
};
}));
example = literalExpression ''
{
journald.id = "everything"; # Only for filebeat7
log = {
enabled = true;
paths = [
"/var/log/*.log"
];
};
};
'';
};
modules = mkOption {
description = ''
Filebeat modules provide a quick way to get started
processing common log formats. They contain default
configurations, Elasticsearch ingest pipeline definitions,
and Kibana dashboards to help you implement and deploy a log
monitoring solution.
This is like <literal>services.filebeat.settings.filebeat.modules</literal>,
but structured as an attribute set. This has the benefit
that multiple NixOS modules can contribute settings to a
single filebeat module.
A module can be specified multiple times by choosing a
different <literal>&lt;name></literal> for each, but setting
<xref linkend="opt-services.filebeat.modules._name_.module"/>
to the same value.
See <link xlink:href="https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules.html"/>.
'';
default = {};
type = types.attrsOf (types.submodule ({ name, ... }: {
freeformType = json.type;
options = {
module = mkOption {
type = types.str;
default = name;
description = ''
The name of the module.
Look for the value after <literal>module:</literal> on
the individual input pages linked from
<link xlink:href="https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules.html"/>.
'';
};
};
}));
example = literalExpression ''
{
nginx = {
access = {
enabled = true;
var.paths = [ "/path/to/log/nginx/access.log*" ];
};
error = {
enabled = true;
var.paths = [ "/path/to/log/nginx/error.log*" ];
};
};
};
'';
};
settings = mkOption {
type = types.submodule {
freeformType = json.type;
options = {
output.elasticsearch.hosts = mkOption {
type = with types; listOf str;
default = [ "127.0.0.1:9200" ];
example = [ "myEShost:9200" ];
description = ''
The list of Elasticsearch nodes to connect to.
The events are distributed to these nodes in round
robin order. If one node becomes unreachable, the
event is automatically sent to another node. Each
Elasticsearch node can be defined as a URL or
IP:PORT. For example:
<literal>http://192.15.3.2</literal>,
<literal>https://es.found.io:9230</literal> or
<literal>192.24.3.2:9300</literal>. If no port is
specified, <literal>9200</literal> is used.
'';
};
filebeat = {
inputs = mkOption {
type = types.listOf json.type;
default = [];
internal = true;
description = ''
Inputs specify how Filebeat locates and processes
input data. Use <xref
linkend="opt-services.filebeat.inputs"/> instead.
See <link xlink:href="https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html"/>.
'';
};
modules = mkOption {
type = types.listOf json.type;
default = [];
internal = true;
description = ''
Filebeat modules provide a quick way to get started
processing common log formats. They contain default
configurations, Elasticsearch ingest pipeline
definitions, and Kibana dashboards to help you
implement and deploy a log monitoring solution.
Use <xref linkend="opt-services.filebeat.modules"/> instead.
See <link xlink:href="https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules.html"/>.
'';
};
};
};
};
default = {};
example = literalExpression ''
{
settings = {
output.elasticsearch = {
hosts = [ "myEShost:9200" ];
username = "filebeat_internal";
password = { _secret = "/var/keys/elasticsearch_password"; };
};
logging.level = "info";
};
};
'';
description = ''
Configuration for filebeat. See
<link xlink:href="https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-reference-yml.html"/>
for supported values.
Options containing secret data should be set to an attribute
set containing the attribute <literal>_secret</literal> - a
string pointing to a file containing the value the option
should be set to. See the example to get a better picture of
this: in the resulting
<filename>filebeat.yml</filename> file, the
<literal>output.elasticsearch.password</literal>
key will be set to the contents of the
<filename>/var/keys/elasticsearch_password</filename> file.
'';
};
};
};
config = mkIf cfg.enable {
services.filebeat.settings.filebeat.inputs = attrValues cfg.inputs;
services.filebeat.settings.filebeat.modules = attrValues cfg.modules;
systemd.services.filebeat = {
description = "Filebeat log shipper";
wantedBy = [ "multi-user.target" ];
wants = [ "elasticsearch.service" ];
after = [ "elasticsearch.service" ];
serviceConfig = {
ExecStartPre = pkgs.writeShellScript "filebeat-exec-pre" ''
set -euo pipefail
umask u=rwx,g=,o=
${utils.genJqSecretsReplacementSnippet
cfg.settings
"/var/lib/filebeat/filebeat.yml"
}
'';
ExecStart = ''
${cfg.package}/bin/filebeat -e \
-c "/var/lib/filebeat/filebeat.yml" \
--path.data "/var/lib/filebeat"
'';
Restart = "always";
StateDirectory = "filebeat";
};
};
};
}

View File

@@ -28,7 +28,6 @@ in
type = types.package;
default = pkgs.journalbeat;
defaultText = literalExpression "pkgs.journalbeat";
example = literalExpression "pkgs.journalbeat7";
description = ''
The journalbeat package to use
'';

View File

@@ -22,7 +22,7 @@ in
};
recheckInterval = mkOption {
type = types.int;
type = types.ints.unsigned;
default = 2000;
description = "Interval in milliseconds between farm rechecks.";
};
@@ -70,7 +70,7 @@ in
};
maxPower = mkOption {
type = types.int;
type = types.ints.unsigned;
default = 113;
description = "Miner max watt usage.";
};
@@ -85,7 +85,7 @@ in
config = mkIf cfg.enable {
systemd.services.ethminer = {
path = [ pkgs.cudatoolkit ];
path = optional (cfg.toolkit == "cuda") [ pkgs.cudatoolkit ];
description = "ethminer ethereum mining service";
wantedBy = [ "multi-user.target" ];
after = [ "network.target" ];
@@ -97,7 +97,7 @@ in
Restart = "always";
};
environment = {
environment = mkIf (cfg.toolkit == "cuda") {
LD_LIBRARY_PATH = "${config.boot.kernelPackages.nvidia_x11}/lib";
};

View File

@@ -1094,7 +1094,9 @@ in {
"d ${gitlabConfig.production.shared.path} 0750 ${cfg.user} ${cfg.group} -"
"d ${gitlabConfig.production.shared.path}/artifacts 0750 ${cfg.user} ${cfg.group} -"
"d ${gitlabConfig.production.shared.path}/lfs-objects 0750 ${cfg.user} ${cfg.group} -"
"d ${gitlabConfig.production.shared.path}/packages 0750 ${cfg.user} ${cfg.group} -"
"d ${gitlabConfig.production.shared.path}/pages 0750 ${cfg.user} ${cfg.group} -"
"d ${gitlabConfig.production.shared.path}/terraform_state 0750 ${cfg.user} ${cfg.group} -"
"L+ /run/gitlab/config - - - - ${cfg.statePath}/config"
"L+ /run/gitlab/log - - - - ${cfg.statePath}/log"
"L+ /run/gitlab/tmp - - - - ${cfg.statePath}/tmp"

View File

@@ -53,7 +53,10 @@ in
User = cfg.user;
Group = cfg.group;
StateDirectory = "jellyfin";
StateDirectoryMode = "0700";
CacheDirectory = "jellyfin";
CacheDirectoryMode = "0700";
UMask = "0077";
ExecStart = "${cfg.package}/bin/jellyfin --datadir '/var/lib/${StateDirectory}' --cachedir '/var/cache/${CacheDirectory}'";
Restart = "on-failure";

View File

@@ -292,7 +292,7 @@ in {
description = ''
List of resources to host on this listener.
'';
example = ["client" "webclient" "federation"];
example = ["client" "federation"];
};
compress = mkOption {
type = types.bool;
@@ -317,7 +317,7 @@ in {
tls = true;
x_forwarded = false;
resources = [
{ names = ["client" "webclient"]; compress = true; }
{ names = ["client" ]; compress = true; }
{ names = ["federation"]; compress = false; }
];
}];
@@ -733,7 +733,7 @@ in {
after = [ "network.target" ] ++ optional hasLocalPostgresDB "postgresql.service";
wantedBy = [ "multi-user.target" ];
preStart = ''
${cfg.package}/bin/homeserver \
${cfg.package}/bin/synapse_homeserver \
--config-path ${configFile} \
--keys-directory ${cfg.dataDir} \
--generate-keys
@@ -753,7 +753,7 @@ in {
chmod 0600 ${cfg.dataDir}/homeserver.signing.key
'')) ];
ExecStart = ''
${cfg.package}/bin/homeserver \
${cfg.package}/bin/synapse_homeserver \
${ concatMapStringsSep "\n " (x: "--config-path ${x} \\") ([ configFile ] ++ cfg.extraConfigFiles) }
--keys-directory ${cfg.dataDir}
'';

View File

@@ -142,7 +142,7 @@ in {
--config='${settingsFile}' \
--registration='${registrationFile}'
fi
'' + lib.optionalString (pkgs.mautrix-telegram ? alembic) ''
# run automatic database init and migration scripts
${pkgs.mautrix-telegram.alembic}/bin/alembic -x config='${settingsFile}' upgrade head
'';

View File

@@ -39,7 +39,7 @@ in {
#defaults to sqlite but can be configured to use postgresql with
#connstring
database.filename = "${dataDir}/mx-puppet-discord/database.db";
database.filename = "${dataDir}/database.db";
logging = {
console = "info";
lineDateFormat = "MMM-D HH:mm:ss.SSS";
@@ -76,10 +76,7 @@ in {
config = mkIf cfg.enable {
systemd.services.mx-puppet-discord = {
description = ''
mx-puppet-discord is a discord puppeting bridge for matrix.
It handles bridging private and group DMs, as well as Guilds (servers).
'';
description = "Matrix to Discord puppeting bridge";
wantedBy = [ "multi-user.target" ];
wants = [ "network-online.target" ] ++ cfg.serviceDependencies;
@@ -110,7 +107,9 @@ in {
UMask = 0027;
ExecStart = ''
${pkgs.mx-puppet-discord}/bin/mx-puppet-discord -c ${settingsFile}
${pkgs.mx-puppet-discord}/bin/mx-puppet-discord \
-c ${settingsFile} \
-f ${registrationFile}
'';
};
};

View File

@@ -49,6 +49,13 @@ in
services.nitter = {
enable = mkEnableOption "If enabled, start Nitter.";
package = mkOption {
default = pkgs.nitter;
type = types.package;
defaultText = literalExpression "pkgs.nitter";
description = "The nitter derivation to use.";
};
server = {
address = mkOption {
type = types.str;
@@ -78,8 +85,8 @@ in
staticDir = mkOption {
type = types.path;
default = "${pkgs.nitter}/share/nitter/public";
defaultText = literalExpression ''"''${pkgs.nitter}/share/nitter/public"'';
default = "${cfg.package}/share/nitter/public";
defaultText = literalExpression ''"''${config.services.nitter.package}/share/nitter/public"'';
description = "Path to the static files directory.";
};
@@ -306,8 +313,8 @@ in
Environment = [ "NITTER_CONF_FILE=/var/lib/nitter/nitter.conf" ];
# Some parts of Nitter expect `public` folder in working directory,
# see https://github.com/zedeus/nitter/issues/414
WorkingDirectory = "${pkgs.nitter}/share/nitter";
ExecStart = "${pkgs.nitter}/bin/nitter";
WorkingDirectory = "${cfg.package}/share/nitter";
ExecStart = "${cfg.package}/bin/nitter";
ExecStartPre = "${preStart}";
AmbientCapabilities = lib.mkIf (cfg.server.port < 1024) [ "CAP_NET_BIND_SERVICE" ];
Restart = "on-failure";

View File

@@ -74,6 +74,8 @@ in
imports = [
(mkRenamedOptionModule [ "nix" "useChroot" ] [ "nix" "useSandbox" ])
(mkRenamedOptionModule [ "nix" "chrootDirs" ] [ "nix" "sandboxPaths" ])
(mkRenamedOptionModule [ "nix" "daemonIONiceLevel" ] [ "nix" "daemonIOSchedPriority" ])
(mkRemovedOptionModule [ "nix" "daemonNiceLevel" ] "Consider nix.daemonCPUSchedPolicy instead.")
];
###### interface
@@ -190,15 +192,28 @@ in
example = "batch";
description = ''
Nix daemon process CPU scheduling policy. This policy propagates to
build processes. other is the default scheduling policy for regular
tasks. The batch policy is similar to other, but optimised for
non-interactive tasks. idle is for extremely low-priority tasks
that should only be run when no other task requires CPU time.
build processes. <literal>other</literal> is the default scheduling
policy for regular tasks. The <literal>batch</literal> policy is
similar to <literal>other</literal>, but optimised for
non-interactive tasks. <literal>idle</literal> is for extremely
low-priority tasks that should only be run when no other task
requires CPU time.
Please note that while using the idle policy may greatly improve
responsiveness of a system performing expensive builds, it may also
slow down and potentially starve crucial configuration updates
during load.
Please note that while using the <literal>idle</literal> policy may
greatly improve responsiveness of a system performing expensive
builds, it may also slow down and potentially starve crucial
configuration updates during load.
<literal>idle</literal> may therefore be a sensible policy for
systems that experience only intermittent phases of high CPU load,
such as desktop or portable computers used interactively. Other
systems should use the <literal>other</literal> or
<literal>batch</literal> policy instead.
For more fine-grained resource control, please refer to
<citerefentry><refentrytitle>systemd.resource-control
</refentrytitle><manvolnum>5</manvolnum></citerefentry> and adjust
<option>systemd.services.nix-daemon</option> directly.
'';
};
@@ -208,13 +223,20 @@ in
example = "idle";
description = ''
Nix daemon process I/O scheduling class. This class propagates to
build processes. best-effort is the default class for regular tasks.
The idle class is for extremely low-priority tasks that should only
perform I/O when no other task does.
build processes. <literal>best-effort</literal> is the default
class for regular tasks. The <literal>idle</literal> class is for
extremely low-priority tasks that should only perform I/O when no
other task does.
Please note that while using the idle scheduling class can improve
responsiveness of a system performing expensive builds, it might also
slow down or starve crucial configuration updates during load.
Please note that while using the <literal>idle</literal> scheduling
class can improve responsiveness of a system performing expensive
builds, it might also slow down or starve crucial configuration
updates during load.
<literal>idle</literal> may therefore be a sensible class for
systems that experience only intermittent phases of high I/O load,
such as desktop or portable computers used interactively. Other
systems should use the <literal>best-effort</literal> class.
'';
};
@@ -546,7 +568,7 @@ in
[ nix
pkgs.nix-info
]
++ optional (config.programs.bash.enableCompletion && !versionAtLeast nixVersion "2.4pre") pkgs.nix-bash-completions;
++ optional (config.programs.bash.enableCompletion) pkgs.nix-bash-completions;
environment.etc."nix/nix.conf".source = nixConf;
@@ -611,6 +633,40 @@ in
};
restartTriggers = [ nixConf ];
# `stopIfChanged = false` changes to switch behavior
# from stop -> update units -> start
# to update units -> restart
#
# The `stopIfChanged` setting therefore controls a trade-off between a
# more predictable lifecycle, which runs the correct "version" of
# the `ExecStop` line, and on the other hand the availability of
# sockets during the switch, as the effectiveness of the stop operation
# depends on the socket being stopped as well.
#
# As `nix-daemon.service` does not make use of `ExecStop`, we prefer
# to keep the socket up and available. This is important for machines
# that run Nix-based services, such as automated build, test, and deploy
# services, that expect the daemon socket to be available at all times.
#
# Notably, the Nix client does not retry on failure to connect to the
# daemon socket, and the in-process RemoteStore instance will disable
# itself. This makes retries infeasible even for services that are
# aware of the issue. Failure to connect can affect not only new client
# processes, but also new RemoteStore instances in existing processes,
# as well as existing RemoteStore instances that have not saturated
# their connection pool.
#
# Also note that `stopIfChanged = true` does not kill existing
# connection handling daemons, as one might wish to happen before a
# breaking Nix upgrade (which is rare). The daemon forks that handle
# the individual connections split off into their own sessions, causing
# them not to be stopped by systemd.
# If a Nix upgrade does require all existing daemon processes to stop,
# nix-daemon must do so on its own accord, and only when the new version
# starts and detects that Nix's persistent state needs an upgrade.
stopIfChanged = false;
};
# Set up the environment variables for running Nix.

View File

@@ -132,7 +132,12 @@ in {
users.users = optionalAttrs (cfg.user == "collectd") {
collectd = {
isSystemUser = true;
group = "collectd";
};
};
users.groups = optionalAttrs (cfg.user == "collectd") {
collectd = {};
};
};
}

View File

@@ -19,8 +19,17 @@ let
"${wrappedPlugins}/libexec/netdata/plugins.d"
] ++ cfg.extraPluginPaths;
configDirectory = pkgs.runCommand "netdata-config-d" { } ''
mkdir $out
${concatStringsSep "\n" (mapAttrsToList (path: file: ''
mkdir -p "$out/$(dirname ${path})"
ln -s "${file}" "$out/${path}"
'') cfg.configDir)}
'';
localConfig = {
global = {
"config directory" = "/etc/netdata/conf.d";
"plugins directory" = concatStringsSep " " plugins;
};
web = {
@@ -130,6 +139,26 @@ in {
'';
};
configDir = mkOption {
type = types.attrsOf types.path;
default = {};
description = ''
Complete netdata config directory except netdata.conf.
The default configuration is merged with changes
defined in this option.
Each top-level attribute denotes a path in the configuration
directory as in environment.etc.
Its value is the absolute path and must be readable by netdata.
Cannot be combined with configText.
'';
example = literalExpression ''
"health_alarm_notify.conf" = pkgs.writeText "health_alarm_notify.conf" '''
sendmail="/path/to/sendmail"
''';
"health.d" = "/run/secrets/netdata/health.d";
'';
};
enableAnalyticsReporting = mkOption {
type = types.bool;
default = false;
@@ -150,11 +179,14 @@ in {
}
];
environment.etc."netdata/netdata.conf".source = configFile;
environment.etc."netdata/conf.d".source = configDirectory;
systemd.services.netdata = {
description = "Real time performance monitoring";
after = [ "network.target" ];
wantedBy = [ "multi-user.target" ];
path = (with pkgs; [ curl gawk iproute2 which ])
path = (with pkgs; [ curl gawk iproute2 which procps ])
++ lib.optional cfg.python.enable (pkgs.python3.withPackages cfg.python.extraPackages)
++ lib.optional config.virtualisation.libvirtd.enable (config.virtualisation.libvirtd.package);
environment = {
@@ -162,8 +194,12 @@ in {
} // lib.optionalAttrs (!cfg.enableAnalyticsReporting) {
DO_NOT_TRACK = "1";
};
restartTriggers = [
config.environment.etc."netdata/netdata.conf".source
config.environment.etc."netdata/conf.d".source
];
serviceConfig = {
ExecStart = "${cfg.package}/bin/netdata -P /run/netdata/netdata.pid -D -c ${configFile}";
ExecStart = "${cfg.package}/bin/netdata -P /run/netdata/netdata.pid -D -c /etc/netdata/netdata.conf";
ExecReload = "${pkgs.util-linux}/bin/kill -s HUP -s USR1 -s USR2 $MAINPID";
TimeoutStopSec = 60;
Restart = "on-failure";

View File

@@ -61,6 +61,7 @@ let
"rtl_433"
"script"
"snmp"
"smartctl"
"smokeping"
"sql"
"surfboard"

View File

@@ -25,6 +25,10 @@ in {
};
};
serviceOpts = {
after = [
"kea-dhcp4-server.service"
"kea-dhcp6-server.service"
];
serviceConfig = {
User = "kea";
ExecStart = ''

View File

@@ -46,11 +46,11 @@ in
serviceConfig = {
ExecStart = ''
${pkgs.prometheus-nginx-exporter}/bin/nginx-prometheus-exporter \
--nginx.scrape-uri '${cfg.scrapeUri}' \
--nginx.ssl-verify ${boolToString cfg.sslVerify} \
--web.listen-address ${cfg.listenAddress}:${toString cfg.port} \
--web.telemetry-path ${cfg.telemetryPath} \
--prometheus.const-labels ${concatStringsSep "," cfg.constLabels} \
--nginx.scrape-uri='${cfg.scrapeUri}' \
--nginx.ssl-verify=${boolToString cfg.sslVerify} \
--web.listen-address=${cfg.listenAddress}:${toString cfg.port} \
--web.telemetry-path=${cfg.telemetryPath} \
--prometheus.const-labels=${concatStringsSep "," cfg.constLabels} \
${concatStringsSep " \\\n " cfg.extraFlags}
'';
};

View File

@@ -76,6 +76,9 @@ in
serviceOpts = {
serviceConfig = {
DynamicUser = false;
# By default, each prometheus exporter only gets AF_INET & AF_INET6,
# but AF_UNIX is needed to read from the `showq`-socket.
RestrictAddressFamilies = [ "AF_UNIX" ];
ExecStart = ''
${pkgs.prometheus-postfix-exporter}/bin/postfix_exporter \
--web.listen-address ${cfg.listenAddress}:${toString cfg.port} \

View File

@@ -0,0 +1,75 @@
{ config, lib, pkgs, options }:
with lib;
let
cfg = config.services.prometheus.exporters.smartctl;
format = pkgs.formats.yaml {};
configFile = format.generate "smartctl-exporter.yml" {
smartctl_exporter = {
bind_to = "${cfg.listenAddress}:${toString cfg.port}";
url_path = "/metrics";
smartctl_location = "${pkgs.smartmontools}/bin/smartctl";
collect_not_more_than_period = cfg.maxInterval;
devices = cfg.devices;
};
};
in {
port = 9633;
extraOpts = {
devices = mkOption {
type = types.listOf types.str;
default = [];
example = literalExpression ''
[ "/dev/sda", "/dev/nvme0n1" ];
'';
description = ''
Paths to the disks that will be monitored. Will autodiscover
all disks if none given.
'';
};
maxInterval = mkOption {
type = types.str;
default = "60s";
example = "2m";
description = ''
Interval that limits how often a disk can be queried.
'';
};
};
serviceOpts = {
serviceConfig = {
AmbientCapabilities = [
"CAP_SYS_RAWIO"
"CAP_SYS_ADMIN"
];
CapabilityBoundingSet = [
"CAP_SYS_RAWIO"
"CAP_SYS_ADMIN"
];
DevicePolicy = "closed";
DeviceAllow = lib.mkOverride 100 (
if cfg.devices != [] then
cfg.devices
else [
"block-blkext rw"
"block-sd rw"
"char-nvme rw"
]
);
ExecStart = ''
${pkgs.prometheus-smartctl-exporter}/bin/smartctl_exporter -config ${configFile}
'';
PrivateDevices = lib.mkForce false;
ProtectProc = "invisible";
ProcSubset = "pid";
SupplementaryGroups = [ "disk" ];
SystemCallFilter = [
"@system-service"
"~@privileged @resources"
];
};
};
}

View File

@@ -31,8 +31,8 @@ let
preStart = ''
install ${configFile} /run/${RuntimeDirectory}/ddclient.conf
${lib.optionalString (cfg.configFile == null) (if (cfg.passwordFile != null) then ''
password=$(head -n 1 ${cfg.passwordFile})
sed -i "s/^password=$/password=$password/" /run/${RuntimeDirectory}/ddclient.conf
password=$(printf "%q" "$(head -n 1 "${cfg.passwordFile}")")
sed -i "s|^password=$|password=$password|" /run/${RuntimeDirectory}/ddclient.conf
'' else ''
sed -i '/^password=$/d' /run/${RuntimeDirectory}/ddclient.conf
'')}

View File

@@ -217,6 +217,8 @@ in
"-Dnet.java.sip.communicator.SC_HOME_DIR_NAME" = "videobridge";
"-Djava.util.logging.config.file" = "/etc/jitsi/videobridge/logging.properties";
"-Dconfig.file" = pkgs.writeText "jvb.conf" (toHOCON jvbConfig);
# Mitigate CVE-2021-44228
"-Dlog4j2.formatMsgNoLookups" = true;
} // (mapAttrs' (k: v: nameValuePair "-D${k}" v) cfg.extraProperties);
in
{

View File

@@ -236,6 +236,7 @@ in
environment = {
KEA_PIDFILE_DIR = "/run/kea";
KEA_LOCKFILE_DIR = "/run/kea";
};
restartTriggers = [
@@ -271,6 +272,7 @@ in
environment = {
KEA_PIDFILE_DIR = "/run/kea";
KEA_LOCKFILE_DIR = "/run/kea";
};
restartTriggers = [
@@ -313,6 +315,7 @@ in
environment = {
KEA_PIDFILE_DIR = "/run/kea";
KEA_LOCKFILE_DIR = "/run/kea";
};
restartTriggers = [
@@ -353,6 +356,7 @@ in
environment = {
KEA_PIDFILE_DIR = "/run/kea";
KEA_LOCKFILE_DIR = "/run/kea";
};
restartTriggers = [
@@ -361,7 +365,7 @@ in
serviceConfig = {
ExecStart = "${package}/bin/kea-dhcp-ddns -c /etc/kea/dhcp-ddns.conf ${lib.escapeShellArgs cfg.dhcp-ddns.extraArgs}";
AmbientCapabilites = [
AmbientCapabilities = [
"CAP_NET_BIND_SERVICE"
];
CapabilityBoundingSet = [

View File

@@ -7,15 +7,16 @@ let
# Convert systemd-style address specification to kresd config line(s).
# On Nix level we don't attempt to precisely validate the address specifications.
# The optional IPv6 scope spec comes *after* port, perhaps surprisingly.
mkListen = kind: addr: let
al_v4 = builtins.match "([0-9.]+):([0-9]+)" addr;
al_v6 = builtins.match "\\[(.+)]:([0-9]+)" addr;
al_v4 = builtins.match "([0-9.]+):([0-9]+)($)" addr;
al_v6 = builtins.match "\\[(.+)]:([0-9]+)(%.*|$)" addr;
al_portOnly = builtins.match "([0-9]+)" addr;
al = findFirst (a: a != null)
(throw "services.kresd.*: incorrect address specification '${addr}'")
[ al_v4 al_v6 al_portOnly ];
port = last al;
addrSpec = if al_portOnly == null then "'${head al}'" else "{'::', '0.0.0.0'}";
port = elemAt al 1;
addrSpec = if al_portOnly == null then "'${head al}${elemAt al 2}'" else "{'::', '0.0.0.0'}";
in # freebind is set for compatibility with earlier kresd services;
# it could be configurable, for example.
''

View File

@@ -55,9 +55,8 @@ in
path = "/var/log/lxd-image-server/lxd-image-server.log";
frequency = "daily";
keep = 21;
user = "lxd-image-server";
group = cfg.group;
extraConfig = ''
create 755 lxd-image-server ${cfg.group}
missingok
compress
delaycompress

View File

@@ -136,7 +136,7 @@ let
+ concatStringsSep "\n"
(plainLines
++ optional (plainLines != []) ''
${pkgs.mosquitto}/bin/mosquitto_passwd -U "$file"
${cfg.package}/bin/mosquitto_passwd -U "$file"
''
++ hashedLines));
@@ -444,6 +444,15 @@ let
globalOptions = with types; {
enable = mkEnableOption "the MQTT Mosquitto broker";
package = mkOption {
type = package;
default = pkgs.mosquitto;
defaultText = literalExpression "pkgs.mosquitto";
description = ''
Mosquitto package to use.
'';
};
bridges = mkOption {
type = attrsOf bridgeOptions;
default = {};
@@ -556,7 +565,7 @@ in
systemd.services.mosquitto = {
description = "Mosquitto MQTT Broker Daemon";
wantedBy = [ "multi-user.target" ];
after = [ "network.target" ];
after = [ "network-online.target" ];
serviceConfig = {
Type = "notify";
NotifyAccess = "main";
@@ -565,7 +574,7 @@ in
RuntimeDirectory = "mosquitto";
WorkingDirectory = cfg.dataDir;
Restart = "on-failure";
ExecStart = "${pkgs.mosquitto}/bin/mosquitto -c ${configFile}";
ExecStart = "${cfg.package}/bin/mosquitto -c ${configFile}";
ExecReload = "${pkgs.coreutils}/bin/kill -HUP $MAINPID";
# Hardening

View File

@@ -37,8 +37,6 @@ in
nix-store --generate-binary-cache-key key-name secret-key-file public-key-file
```
Make sure user `nix-serve` has read access to the private key file.
For more details see <citerefentry><refentrytitle>nix-store</refentrytitle><manvolnum>1</manvolnum></citerefentry>.
'';
};
@@ -61,16 +59,22 @@ in
path = [ config.nix.package.out pkgs.bzip2.bin ];
environment.NIX_REMOTE = "daemon";
environment.NIX_SECRET_KEY_FILE = cfg.secretKeyFile;
script = ''
${lib.optionalString (cfg.secretKeyFile != null) ''
export NIX_SECRET_KEY_FILE="$CREDENTIALS_DIRECTORY/NIX_SECRET_KEY_FILE"
''}
exec ${pkgs.nix-serve}/bin/nix-serve --listen ${cfg.bindAddress}:${toString cfg.port} ${cfg.extraParams}
'';
serviceConfig = {
Restart = "always";
RestartSec = "5s";
ExecStart = "${pkgs.nix-serve}/bin/nix-serve " +
"--listen ${cfg.bindAddress}:${toString cfg.port} ${cfg.extraParams}";
User = "nix-serve";
Group = "nix-serve";
DynamicUser = true;
LoadCredential = lib.optionalString (cfg.secretKeyFile != null)
"NIX_SECRET_KEY_FILE:${cfg.secretKeyFile}";
};
};
};

View File

@@ -1,7 +1,6 @@
{ config, lib, pkgs, ... }:
with lib;
let
python = pkgs.python3Packages.python;
cfg = config.services.seafile;
settingsFormat = pkgs.formats.ini { };
@@ -220,9 +219,7 @@ in {
'';
};
seahub = let
penv = (pkgs.python3.withPackages (ps: with ps; [ gunicorn seahub ]));
in {
seahub = {
description = "Seafile Server Web Frontend";
wantedBy = [ "seafile.target" ];
partOf = [ "seafile.target" ];
@@ -230,8 +227,7 @@ in {
requires = [ "seaf-server.service" ];
restartTriggers = [ seahubSettings ];
environment = {
PYTHONPATH =
"${pkgs.python3Packages.seahub}/thirdpart:${pkgs.python3Packages.seahub}:${penv}/${python.sitePackages}";
PYTHONPATH = "${pkgs.seahub.pythonPath}:${pkgs.seahub}/thirdpart:${pkgs.seahub}";
DJANGO_SETTINGS_MODULE = "seahub.settings";
CCNET_CONF_DIR = ccnetDir;
SEAFILE_CONF_DIR = dataDir;
@@ -248,7 +244,7 @@ in {
LogsDirectory = "seafile";
ConfigurationDirectory = "seafile";
ExecStart = ''
${penv}/bin/gunicorn seahub.wsgi:application \
${pkgs.seahub.python.pkgs.gunicorn}/bin/gunicorn seahub.wsgi:application \
--name seahub \
--workers ${toString cfg.workers} \
--log-level=info \
@@ -261,27 +257,27 @@ in {
preStart = ''
mkdir -p ${seahubDir}/media
# Link all media except avatars
for m in `find ${pkgs.python3Packages.seahub}/media/ -maxdepth 1 -not -name "avatars"`; do
for m in `find ${pkgs.seahub}/media/ -maxdepth 1 -not -name "avatars"`; do
ln -sf $m ${seahubDir}/media/
done
if [ ! -e "${seafRoot}/.seahubSecret" ]; then
${penv}/bin/python ${pkgs.python3Packages.seahub}/tools/secret_key_generator.py > ${seafRoot}/.seahubSecret
${pkgs.seahub.python}/bin/python ${pkgs.seahub}/tools/secret_key_generator.py > ${seafRoot}/.seahubSecret
chmod 400 ${seafRoot}/.seahubSecret
fi
if [ ! -f "${seafRoot}/seahub-setup" ]; then
# avatars directory should be writable
install -D -t ${seahubDir}/media/avatars/ ${pkgs.python3Packages.seahub}/media/avatars/default.png
install -D -t ${seahubDir}/media/avatars/groups ${pkgs.python3Packages.seahub}/media/avatars/groups/default.png
install -D -t ${seahubDir}/media/avatars/ ${pkgs.seahub}/media/avatars/default.png
install -D -t ${seahubDir}/media/avatars/groups ${pkgs.seahub}/media/avatars/groups/default.png
# init database
${pkgs.python3Packages.seahub}/manage.py migrate
${pkgs.seahub}/manage.py migrate
# create admin account
${pkgs.expect}/bin/expect -c 'spawn ${pkgs.python3Packages.seahub}/manage.py createsuperuser --email=${cfg.adminEmail}; expect "Password: "; send "${cfg.initialAdminPassword}\r"; expect "Password (again): "; send "${cfg.initialAdminPassword}\r"; expect "Superuser created successfully."'
echo "${pkgs.python3Packages.seahub.version}-sqlite" > "${seafRoot}/seahub-setup"
${pkgs.expect}/bin/expect -c 'spawn ${pkgs.seahub}/manage.py createsuperuser --email=${cfg.adminEmail}; expect "Password: "; send "${cfg.initialAdminPassword}\r"; expect "Password (again): "; send "${cfg.initialAdminPassword}\r"; expect "Superuser created successfully."'
echo "${pkgs.seahub.version}-sqlite" > "${seafRoot}/seahub-setup"
fi
if [ $(cat "${seafRoot}/seahub-setup" | cut -d"-" -f1) != "${pkgs.python3Packages.seahub.version}" ]; then
if [ $(cat "${seafRoot}/seahub-setup" | cut -d"-" -f1) != "${pkgs.seahub.version}" ]; then
# update database
${pkgs.python3Packages.seahub}/manage.py migrate
echo "${pkgs.python3Packages.seahub.version}-sqlite" > "${seafRoot}/seahub-setup"
${pkgs.seahub}/manage.py migrate
echo "${pkgs.seahub.version}-sqlite" > "${seafRoot}/seahub-setup"
fi
'';
};

View File

@@ -45,6 +45,15 @@ in
'';
};
group = mkOption {
type = types.str;
default = "shairport";
description = ''
Group account name under which to run shairport-sync. The account
will be created.
'';
};
};
};
@@ -58,13 +67,17 @@ in
services.avahi.publish.enable = true;
services.avahi.publish.userServices = true;
users.users.${cfg.user} =
{ description = "Shairport user";
users = {
users.${cfg.user} = {
description = "Shairport user";
isSystemUser = true;
createHome = true;
home = "/var/lib/shairport-sync";
group = cfg.group;
extraGroups = [ "audio" ] ++ optional config.hardware.pulseaudio.enable "pulse";
};
groups.${cfg.group} = {};
};
systemd.services.shairport-sync =
{
@@ -73,6 +86,7 @@ in
wantedBy = [ "multi-user.target" ];
serviceConfig = {
User = cfg.user;
Group = cfg.group;
ExecStart = "${pkgs.shairport-sync}/bin/shairport-sync ${cfg.arguments}";
RuntimeDirectory = "shairport-sync";
};

View File

@@ -448,7 +448,7 @@ in {
default = false;
example = true;
description = ''
Whether to open the default ports in the firewall: TCP 22000 for transfers
Whether to open the default ports in the firewall: TCP/UDP 22000 for transfers
and UDP 21027 for discovery.
If multiple users are running Syncthing on this machine, you will need
@@ -484,7 +484,7 @@ in {
networking.firewall = mkIf cfg.openDefaultPorts {
allowedTCPPorts = [ 22000 ];
allowedUDPPorts = [ 21027 ];
allowedUDPPorts = [ 21027 22000 ];
};
systemd.packages = [ pkgs.syncthing ];

View File

@@ -9,14 +9,45 @@ let
cfg = config.networking.wireless;
wpa3Protocols = [ "SAE" "FT-SAE" ];
hasMixedWPA = opts:
let
hasWPA3 = !mutuallyExclusive opts.authProtocols wpa3Protocols;
others = subtractLists wpa3Protocols opts.authProtocols;
in hasWPA3 && others != [];
# Gives a WPA3 network higher priority
increaseWPA3Priority = opts:
opts // optionalAttrs (hasMixedWPA opts)
{ priority = if opts.priority == null
then 1
else opts.priority + 1;
};
# Creates a WPA2 fallback network
mkWPA2Fallback = opts:
opts // { authProtocols = subtractLists wpa3Protocols opts.authProtocols; };
# Networks attrset as a list
networkList = mapAttrsToList (ssid: opts: opts // { inherit ssid; })
cfg.networks;
# List of all networks (normal + generated fallbacks)
allNetworks =
if cfg.fallbackToWPA2
then map increaseWPA3Priority networkList
++ map mkWPA2Fallback (filter hasMixedWPA networkList)
else networkList;
# Content of wpa_supplicant.conf
generatedConfig = concatStringsSep "\n" (
(mapAttrsToList mkNetwork cfg.networks)
(map mkNetwork allNetworks)
++ optional cfg.userControlled.enable (concatStringsSep "\n"
[ "ctrl_interface=/run/wpa_supplicant"
"ctrl_interface_group=${cfg.userControlled.group}"
"update_config=1"
])
++ [ "pmf=1" ]
++ optional cfg.scanOnLowSignal ''bgscan="simple:30:-70:3600"''
++ optional (cfg.extraConfig != "") cfg.extraConfig);
@@ -32,7 +63,7 @@ let
finalConfig = ''"$RUNTIME_DIRECTORY"/wpa_supplicant.conf'';
# Creates a network block for wpa_supplicant.conf
mkNetwork = ssid: opts:
mkNetwork = opts:
let
quote = x: ''"${x}"'';
indent = x: " " + x;
@@ -42,7 +73,7 @@ let
else opts.pskRaw;
options = [
"ssid=${quote ssid}"
"ssid=${quote opts.ssid}"
(if pskString != null || opts.auth != null
then "key_mgmt=${concatStringsSep " " opts.authProtocols}"
else "key_mgmt=NONE")
@@ -174,6 +205,18 @@ in {
'';
};
fallbackToWPA2 = mkOption {
type = types.bool;
default = true;
description = ''
Whether to fall back to WPA2 authentication protocols if WPA3 failed.
This allows old wireless cards (that lack recent features required by
WPA3) to connect to mixed WPA2/WPA3 access points.
To avoid possible downgrade attacks, disable this options.
'';
};
environmentFile = mkOption {
type = types.nullOr types.path;
default = null;

View File

@@ -204,7 +204,7 @@ in
postStart = ''
# Make sure elasticsearch is up and running before dependents
# are started
while ! ${pkgs.curl}/bin/curl -sS -f http://localhost:${toString cfg.port} 2>/dev/null; do
while ! ${pkgs.curl}/bin/curl -sS -f http://${cfg.listenAddress}:${toString cfg.port} 2>/dev/null; do
sleep 1
done
'';

View File

@@ -9,7 +9,7 @@ let
pkg = pkgs.clamav;
toKeyValue = generators.toKeyValue {
mkKeyValue = generators.mkKeyValueDefault {} " ";
mkKeyValue = generators.mkKeyValueDefault { } " ";
listsAsDuplicateKeys = true;
};
@@ -30,7 +30,7 @@ in
settings = mkOption {
type = with types; attrsOf (oneOf [ bool int str (listOf str) ]);
default = {};
default = { };
description = ''
ClamAV configuration. Refer to <link xlink:href="https://linux.die.net/man/5/clamd.conf"/>,
for details on supported values.
@@ -59,7 +59,7 @@ in
settings = mkOption {
type = with types; attrsOf (oneOf [ bool int str (listOf str) ]);
default = {};
default = { };
description = ''
freshclam configuration. Refer to <link xlink:href="https://linux.die.net/man/5/freshclam.conf"/>,
for details on supported values.
@@ -104,7 +104,6 @@ in
systemd.services.clamav-daemon = mkIf cfg.daemon.enable {
description = "ClamAV daemon (clamd)";
after = optional cfg.updater.enable "clamav-freshclam.service";
requires = optional cfg.updater.enable "clamav-freshclam.service";
wantedBy = [ "multi-user.target" ];
restartTriggers = [ clamdConfigFile ];
@@ -134,7 +133,7 @@ in
systemd.services.clamav-freshclam = mkIf cfg.updater.enable {
description = "ClamAV virus database updater (freshclam)";
restartTriggers = [ freshclamConfigFile ];
after = [ "network-online.target" ];
preStart = ''
mkdir -m 0755 -p ${stateDir}
chown ${clamavUser}:${clamavGroup} ${stateDir}

View File

@@ -102,17 +102,19 @@ in
# Taken from: https://github.com/oauth2-proxy/oauth2-proxy/blob/master/providers/providers.go
provider = mkOption {
type = types.enum [
"google"
"adfs"
"azure"
"bitbucket"
"digitalocean"
"facebook"
"github"
"keycloak"
"gitlab"
"google"
"keycloak"
"keycloak-oidc"
"linkedin"
"login.gov"
"bitbucket"
"nextcloud"
"digitalocean"
"oidc"
];
default = "google";

View File

@@ -200,6 +200,7 @@ in
systemd.services.privacyidea = let
piuwsgi = pkgs.writeText "uwsgi.json" (builtins.toJSON {
uwsgi = {
buffer-size = 8192;
plugins = [ "python3" ];
pythonpath = "${penv}/${uwsgi.python3.sitePackages}";
socket = "/run/privacyidea/socket";

View File

@@ -0,0 +1,57 @@
{ config, pkgs, lib, ... }:
with lib;
let
cfg = config.services.cachix-agent;
in {
meta.maintainers = [ lib.maintainers.domenkozar ];
options.services.cachix-agent = {
enable = mkEnableOption "Cachix Deploy Agent: https://docs.cachix.org/deploy/";
name = mkOption {
type = types.str;
description = "Agent name, usually same as the hostname";
default = config.networking.hostName;
defaultText = "config.networking.hostName";
};
profile = mkOption {
type = types.nullOr types.str;
default = null;
description = "Profile name, defaults to 'system' (NixOS).";
};
package = mkOption {
type = types.package;
default = pkgs.cachix;
defaultText = literalExpression "pkgs.cachix";
description = "Cachix Client package to use.";
};
credentialsFile = mkOption {
type = types.path;
default = "/etc/cachix-agent.token";
description = ''
Required file that needs to contain CACHIX_AGENT_TOKEN=...
'';
};
};
config = mkIf cfg.enable {
systemd.services.cachix-agent = {
description = "Cachix Deploy Agent";
after = ["network-online.target"];
path = [ config.nix.package ];
wantedBy = [ "multi-user.target" ];
# don't restart while changing
reloadIfChanged = true;
serviceConfig = {
Restart = "on-failure";
EnvironmentFile = cfg.credentialsFile;
ExecStart = "${cfg.package}/bin/cachix deploy agent ${cfg.name} ${if cfg.profile != null then profile else ""}";
};
};
};
}

View File

@@ -50,7 +50,9 @@ in
systemd.services.nscd =
{ description = "Name Service Cache Daemon";
wantedBy = [ "nss-lookup.target" "nss-user-lookup.target" ];
before = [ "nss-lookup.target" "nss-user-lookup.target" ];
wants = [ "nss-lookup.target" "nss-user-lookup.target" ];
wantedBy = [ "multi-user.target" ];
environment = { LD_LIBRARY_PATH = nssModulesPath; };

View File

@@ -606,6 +606,7 @@ in
connection_reaper_interval = 30;
relative_url_root = null;
message_bus_max_backlog_size = 100;
message_bus_clear_every = 50;
secret_key_base = cfg.secretKeyBaseFile;
fallback_assets_path = null;
@@ -621,12 +622,13 @@ in
max_user_api_reqs_per_minute = 20;
max_user_api_reqs_per_day = 2880;
max_admin_api_reqs_per_key_per_minute = 60;
max_admin_api_reqs_per_minute = 60;
max_reqs_per_ip_per_minute = 200;
max_reqs_per_ip_per_10_seconds = 50;
max_asset_reqs_per_ip_per_10_seconds = 200;
max_reqs_per_ip_mode = "block";
max_reqs_rate_limit_on_private = false;
skip_per_ip_rate_limit_trust_level = 1;
force_anonymous_min_queue_seconds = 1;
force_anonymous_min_per_10_seconds = 3;
background_requests_max_queue_length = 0.5;
@@ -646,6 +648,9 @@ in
enable_email_sync_demon = false;
max_digests_enqueued_per_30_mins_per_site = 10000;
cluster_name = null;
multisite_config_path = "config/multisite.yml";
enable_long_polling = null;
long_polling_interval = null;
};
services.redis.enable = lib.mkDefault (cfg.redis.host == "localhost");
@@ -825,7 +830,7 @@ in
appendHttpConfig = ''
# inactive means we keep stuff around for 1440m minutes regardless of last access (1 week)
# levels means it is a 2 deep heirarchy cause we can have lots of files
# levels means it is a 2 deep hierarchy cause we can have lots of files
# max_size limits the size of the cache
proxy_cache_path /var/cache/nginx inactive=1440m levels=1:2 keys_zone=discourse:10m max_size=600m;
@@ -837,7 +842,7 @@ in
inherit (cfg) sslCertificate sslCertificateKey enableACME;
forceSSL = lib.mkDefault tlsEnabled;
root = "/run/discourse/public";
root = "${cfg.package}/share/discourse/public";
locations =
let
@@ -889,7 +894,7 @@ in
"~ ^/uploads/" = proxy {
extraConfig = cache_1y + ''
proxy_set_header X-Sendfile-Type X-Accel-Redirect;
proxy_set_header X-Accel-Mapping /run/discourse/public/=/downloads/;
proxy_set_header X-Accel-Mapping ${cfg.package}/share/discourse/public/=/downloads/;
# custom CSS
location ~ /stylesheet-cache/ {
@@ -911,7 +916,7 @@ in
"~ ^/admin/backups/" = proxy {
extraConfig = ''
proxy_set_header X-Sendfile-Type X-Accel-Redirect;
proxy_set_header X-Accel-Mapping /run/discourse/public/=/downloads/;
proxy_set_header X-Accel-Mapping ${cfg.package}/share/discourse/public/=/downloads/;
'';
};
"~ ^/(svg-sprite/|letter_avatar/|letter_avatar_proxy/|user_avatar|highlight-js|stylesheets|theme-javascripts|favicon/proxied|service-worker)" = proxy {
@@ -938,7 +943,7 @@ in
};
"/downloads/".extraConfig = ''
internal;
alias /run/discourse/public/;
alias ${cfg.package}/share/discourse/public/;
'';
};
};

View File

@@ -297,7 +297,7 @@ services.discourse = {
the script:
<programlisting language="bash">
./update.py update-plugins
</programlisting>.
</programlisting>
</para>
<para>

Some files were not shown because too many files have changed in this diff Show More