Compare commits

..

4412 Commits

Author SHA1 Message Date
John Ericson
022caabb5f Merge pull request #185612 from obsidiansystems/buildRustCrate-21.05-no-choke-on-dep
[Backport release 21.05] buildRustCrate: don't try to set CARGO_FEATURE_ variables for dep: fe…
2022-08-07 19:21:33 -04:00
Faye Duxovni
d5baefeb34 buildRustCrate: don't try to set CARGO_FEATURE_ variables for dep: features
These features are internal-only, have special characters that bash
doesn't support in variable names, and aren't normally given
environment variables by cargo as far as I can tell.

(cherry picked from commit ede639a8d63f2c6da0944cab441955ca16e9cce5)
(cherry picked from commit a94a643de9)
2022-08-07 19:11:15 -04:00
John Ericson
7ca652795e Merge pull request #184824 from obsidiansystems/backport-21.05
[backport release-21.05] Two recent backports from 21.11
2022-08-02 10:40:23 -04:00
John Ericson
15f7c3baa8 buildRustCrate: Add support for standard library deps
We are replicating one mechanism behind `-Z build-std`.

There isn't yet crate2nix support for this, but one can (and I do) add
the missing stdlib deps (for this feature to pick up) with overrides.

(cherry picked from commit cc29693a09)
(cherry picked from commit 5aef865cef)
(cherry picked from commit c19d19615c)
2022-08-02 09:11:47 -04:00
John Ericson
84d01504b2 compiler-rt: Fix "bare metal" case boolean logic
It is possible to both be bare metal and have a libc (newlib).

This libc doesn't provide very much --- not enough for CMake to think
the C toolchain works. We therefore adjust our logic so we hit the "bare
metal" case with or without libc.

The "use LLVM" bootstrap is intentionally not affected.

(cherry picked from commit bf39e32272)
(cherry picked from commit c820cd8cee)
(cherry picked from commit 0a284ae9b9)
2022-08-02 09:06:27 -04:00
John Ericson
7618fa361a Merge pull request #182180 from obsidiansystems/rust-platform-respect-fields-21.05
[Backport release-21.06] build-support/rust/lib: make arch and os functions respect target JSON
2022-07-20 11:05:54 -04:00
John Ericson
bb97a48cea build-support/rust/lib: make arch and os functions respect target JSON
(cherry picked from commit 39811b1da9)
(cherry picked from commit b49c1ce29f)
(cherry picked from commit 38d5ec716a)
2022-07-20 02:48:33 -04:00
Noah Fontes
046ee4af7a autoPatchelfHook: fix packages that use stdenvNoCC
autoPatchelfHook actually doesn't depend on stdenv and only needs
bintools (with its wrapper). This change uses $NIX_BINTOOLS instead of
$NIX_CC and makes the dependency on bintools explicit.

(cherry picked from commit a7f5e8321e)

Conflicts:
  pkgs/top-level/all-packages.nix
2022-06-12 13:42:59 +02:00
Noah Fontes
c96de39707 autoPatchelfHook: improve arch/ABI compatibility
Fully enabling crossSystem support for autoPatchelfHook came with some
perhaps unintended consequences of being a bit more aggressive about
patching ELF files from architectures/ABIs that differ from the target
(previously, those files would be ignored because ldd usually couldn't
handle them).

This change adds architecture and rough OS ABI detection to the script
so that it doesn't try to blindly replace the interpreter of files that
can't possibly use that interpreter, and also makes sure it doesn't
accidentally use libraries of other architectures/ABIs.

(cherry picked from commit 4765a3e153)
2022-06-12 13:42:59 +02:00
Noah Fontes
ff01aca26f autoPatchelfHook: fix detection under crossSystem
In #84415, autoPatchelfHook was taught to use the correct path to the
readelf binary when a crossSystem is specified. Unfortunately, the
remainder of the functionality in the script depended on ldd, which only
reads ELF files of its own architecture. It has the further unfortunate
quality of not reporting any useful error, but rather that the file is
not a dynamic executable.

This change uses patchelf to directly analyze the DT_NEEDED tags in the
target files instead, which correctly works across architectures. It
also updates the use of objdump to be prefix-aware $OBJDUMP (which would
have been required in the PR mentioned above, but we never made it that
far into the script execution).

(cherry picked from commit b79483d2b7)
2022-06-12 13:42:59 +02:00
Robert Hensing
1a7c2f41c3 pkgs: Add _type = "pkgs"
(cherry picked from commit ad1e2500ef)
(cherry picked from commit aec730a0af)
2022-05-02 09:51:01 +02:00
Renaud
530a53dcbc Merge pull request #150591 from Yarny0/tsm-client-2105
[21.05] tsm-client: 8.1.8.0 -> 8.1.13.3 (security update)
2022-02-19 19:41:54 +01:00
Renaud
0fd9ee1aa3 Merge pull request #154727 from ymatsiuk/ymatsiuk/teleport-6.2.26
[21.05] teleport: 6.1.3 -> 6.2.26
2022-01-15 11:57:30 +01:00
Yarny0
21c7cb508a tsm-client: 8.1.13.2 -> 8.1.13.3
Link to Security Bulletin:
https://www.ibm.com/support/pages/node/6540692 (CVE-2021-44832)

cherry-picked from https://github.com/NixOS/nixpkgs/pull/138386
2022-01-15 10:57:03 +01:00
Yarny0
a554d56780 tsm-client: 8.1.13.1 -> 8.1.13.2
Link to Security Bulletin:
https://www.ibm.com/support/pages/node/6537640 (CVE-2021-45105, CVE-2021-45046)

cherry-picked from https://github.com/NixOS/nixpkgs/pull/138386
2022-01-15 10:57:03 +01:00
Yarny0
d81dbbef88 tsm-client: 8.1.13.0 -> 8.1.13.1
Link to Security Bulletin:
https://www.ibm.com/support/pages/node/6527080 (CVE-2021-44228)

cherry-picked from https://github.com/NixOS/nixpkgs/pull/138386
2022-01-15 10:57:03 +01:00
Yarny0
24d65987d5 tsm-client: use rpm source instead of deb/Ubuntu
IBM publishes their IBM Spectrum Protect client
for Linux in two flavors:

* "Linux x86_64 client"
* "Linux x86_64 Ubuntu client"

Up to this commit, nixpkgs used the Ubuntu
flavor to build its `tsm-client` derivation.
However, the history of published archive files in

* https://public.dhe.ibm.com/storage/tivoli-storage-management/maintenance/client/v8r1/Linux/
* https://public.dhe.ibm.com/storage/tivoli-storage-management/patches/client/v8r1/Linux/

suggests that updates in the fourth level of
the version numbers (e.g. 8.1.13.0 -> 8.1.13.1)
do not get published as Ubuntu flavor.
It order to be able to always use the latest release,
this commit switches to the non-Ubuntu flavor.
The non-Ubuntu archive contains rpm files,
so this commit switches from `ar` to `rpmextract`.
Instead of unpacking all deb files,
the build recipe now unpacks all _but one_ rpm file:
The file `TIVsm-WEBGUI.x86_64.rpm` apparently
contains a plugin that is not included
in the Ubuntu version (see note below).
Comparing the old and the new derivation's output indicates
that this choice minimizes the difference between the results:

The output of the old (Ubuntu flavor) derivation contains:
* `commons-codec-1.6.jar`
* `share/` with changelog and copyright information
  for the packages `gskssl64` and `gskcrypt64`

The output of the new (non-Ubuntu flavor) derivation contains:
* `lib64`, symlink to `lib`
* `commons-codec-1.14.jar`
* `opt/tivoli/tsm/license/{api,baclient}/sm/`
  with license agreement files in many languages

Besides these differences, the outputs' file names are equal.

Note: I don't know what functionality
`TIVsm-WEBGUI.x86_64.rpm` actually provides.
Unpacking it with the other rpm files makes patchelf complain
about missing X11 libraries, so in order to include it here,
one would likely need to add those to `buildInputs`.
However, as the old (Ubuntu flavor) `tsm-client` package
did not contain this functionality and as I cannot test
or use it in any way, I opted to not include it now.
If we want to include this with a later commit,
we should add another package build option (like `enableGui`)
so that the default `tsm-client` package does not pull in
X11 libraries and its closure size therefore stays small.

cherry-picked/adapted from https://github.com/NixOS/nixpkgs/pull/138386
2022-01-15 10:57:03 +01:00
Yarny0
9a2bdc5c7a tsm-client: 8.1.8.0 -> 8.1.13.0
tsm-client now links against openssl;
patchelf complains without it.

Links to IBM's "Authorized Program Analysis Report"s
(something like release notes),
to READMEs, and to Security Bulletins,
for all updates between 8.1.8.0 and 8.1.13.0:

* 8.1.9.x
  * APARs: https://www.ibm.com/support/pages/node/1077159
  * READMEs: https://www.ibm.com/support/pages/node/1108473
  * https://www.ibm.com/support/pages/node/1107261 (CVE-2018-2025)
  * https://www.ibm.com/support/pages/node/1107777 (CVE-2019-4406)

* 8.1.10.x
  * APARs: https://www.ibm.com/support/pages/node/6223098
  * READMEs: https://www.ibm.com/support/pages/node/6223388
  * https://www.ibm.com/support/pages/node/6221448 (CVE-2020-4494, CVE-2020-4406)
  * https://www.ibm.com/support/pages/node/6245356 (CVE-2020-2654)
  * https://www.ibm.com/support/pages/node/6245366 (CVE-2015-4000)

* 8.1.11.x
  * APARs: https://www.ibm.com/support/pages/node/6367203
  * READMEs: https://www.ibm.com/support/pages/node/6367205
  * https://www.ibm.com/support/pages/node/6371646
  * https://www.ibm.com/support/pages/node/6371650
  * https://www.ibm.com/support/pages/node/6371652

* 8.1.12.x
  * APARs: https://www.ibm.com/support/pages/node/6429561
  * READMEs: https://www.ibm.com/support/pages/node/6443671
  * https://www.ibm.com/support/pages/node/6445503 (CVE-2021-20532)
  * https://www.ibm.com/support/pages/node/6445497 (CVE-2021-29672, CVE-2021-20546)
  * https://www.ibm.com/support/pages/node/6445489 (CVE-2020-1971, CVE-2021-23840, CVE-2021-23841)
  * https://www.ibm.com/support/pages/node/6445483 (CVE-2020-27221, CVE-2020-14782)

* 8.1.13.x
  * APARs: https://www.ibm.com/support/pages/node/6524936
  * READMEs: https://www.ibm.com/support/pages/node/6524938
  * https://www.ibm.com/support/pages/node/6524706 (CVE-2021-39048)
  * https://www.ibm.com/support/pages/node/6524712 (CVE-2021-3712, CVE-2021-3711)

cherry-picked/adapted from https://github.com/NixOS/nixpkgs/pull/138386
2022-01-15 10:57:03 +01:00
Yarny0
02dfeba708 tsm-client: update URL structure
IBM has changed the URL structures of their support web pages.
The commit at hand updates most URLs and
in particular the package update instructions
so they follow the new structure.
It also calculates the source download URL from the
version number, so package updates no longer have to
update the URL in addition to the version string.

cherry-picked from https://github.com/NixOS/nixpkgs/pull/138386
2022-01-15 10:57:03 +01:00
Yurii Matsiuk
8b19b93859 teleport: 6.1.3 -> 6.2.26 2022-01-12 10:36:22 +01:00
Vladimír Čunát
df12367756 Merge #153619: hyperscan: fix build (into release-21.05) 2022-01-09 14:18:08 +01:00
Vladimír Čunát
81f44dbfe8 Merge #153003: unicorn: add patch for CVE-2021-44078
... into release-21.05
2022-01-09 14:08:22 +01:00
Vladimír Čunát
c68e3678f4 Merge #152424: mediathekview: CVE-2021-45105 (log4j) mitigation
... into release-21.05
2022-01-09 11:04:33 +01:00
Vladimír Čunát
903b8cc6f2 Merge #152460: gegl_0_4: patch CVE-2021-45463 (into release-21.05) 2022-01-09 11:01:17 +01:00
Jörg Thalheim
6db08005e3 hyperscan: fix build
(cherry picked from commit 76c1bb8106)
2022-01-05 20:11:16 +03:00
Vladimír Čunát
88579effa7 Merge #152850: staging-next: 21.05 2021-12-31
Hydra looks OK, only a few thousand x86_64-darwin builds are queued now.
2022-01-03 18:09:46 +01:00
Bernardo Meurer
23c10dbe32 Merge pull request #152248 from NixOS/backport-151139-to-release-21.05
[Backport release-21.05] firmwareLinuxNonfree: 20211027 -> 20211216
2022-01-03 16:51:46 +00:00
github-actions[bot]
c8251a649b Merge release-21.05 into staging-next-21.05 2022-01-01 00:09:03 +00:00
Robert Scott
46050f5dd7 unicorn: add patch for CVE-2021-44078 2021-12-31 22:10:23 +00:00
Ryan Burns
932ec35ff8 Merge pull request #152824 from NixOS/backport-147984-to-release-21.05
[Backport release-21.05] forge: fix build
2021-12-30 21:40:25 -08:00
Martin Weinelt
cb284f78db Merge pull request #152152 from NixOS/backport-149488-to-staging-21.05 2021-12-31 02:45:45 +01:00
Martin Weinelt
b18b4565f8 Merge pull request #152831 from risicle/ris-binutils-2.35.2-r21.05 2021-12-31 02:45:06 +01:00
Martin Weinelt
6e47f75fb5 Merge pull request #152353 from risicle/ris-binutils-CVE-2021-3487-CVE-2021-45078-r21.05 2021-12-31 02:44:53 +01:00
github-actions[bot]
2363cd1d70 Merge staging-next-21.05 into staging-21.05 2021-12-31 00:09:43 +00:00
github-actions[bot]
5bba55eb6e Merge release-21.05 into staging-next-21.05 2021-12-31 00:09:02 +00:00
Fabián Heredia Montiel
4562867249 binutils: 2.35.1 → 2.35.2
CVEs:

- https://nvd.nist.gov/vuln/detail/CVE-2020-35448 (3.3 Low)
- https://nvd.nist.gov/vuln/detail/CVE-2021-20284 (5.5 Medium)
- https://nvd.nist.gov/vuln/detail/CVE-2021-20294 (7.8 High)

(cherry picked from commit f378420360)
2021-12-30 23:37:54 +00:00
Ryan Burns
17e610c5d7 forge: fix build
The build was failing due to mismatched libstdc++ between
stdenv.cc and cudatoolkit.cc. This can be fixed by bumping
the build-time cudatoolkit to 11, which is able to use the
same cc as stdenv.

(cherry picked from commit e263bdd82b)
2021-12-30 23:11:57 +00:00
Maximilian Bosch
b7516e083a Merge pull request #152075 from NixOS/backport-151792-to-release-21.05
[Backport release-21.05] Kernels 2021-12-22
2021-12-30 14:58:03 +01:00
github-actions[bot]
c9e66260ba Merge staging-next-21.05 into staging-21.05 2021-12-29 00:09:40 +00:00
github-actions[bot]
e60c3e2abb Merge release-21.05 into staging-next-21.05 2021-12-29 00:08:58 +00:00
Robert Scott
8730eba0ff gegl_0_4: add patch for CVE-2021-45463 2021-12-28 15:02:57 +00:00
Robert Scott
d6b043ab97 Merge pull request #152359 from risicle/ris-lapack-CVE-2021-4048-r21.05
[21.05] lapack: add patch for CVE-2021-4048
2021-12-28 11:32:20 +00:00
André-Patrick Bubel
bdd4c549c6 mediathekview: CVE-2021-45105 (log4j) mitigation
Remove the affected JndiLookup.class until we can update to the lastest
Mediathekview version.

(cherry picked from commit 2a360652e2)
2021-12-28 07:20:08 +00:00
Robert Scott
7bca80140f Merge pull request #150295 from ius/zap-2.11.1_21.05
[21.05] zap: 2.10.0 -> 2.11.1
2021-12-28 01:07:31 +00:00
github-actions[bot]
28bdca0b6e Merge staging-next-21.05 into staging-21.05 2021-12-28 00:09:34 +00:00
github-actions[bot]
c9a97ff47b Merge release-21.05 into staging-next-21.05 2021-12-28 00:09:01 +00:00
Robert Scott
2e02b48a9c binutils: add patch for CVE-2021-45078 (#151658)
(cherry picked from commit 6a6756ce7e)
2021-12-27 14:00:15 +00:00
Fabián Heredia Montiel
ed69a1f758 binutils: patch CVE-2021-3487
(cherry picked from commit 745023e01a)
2021-12-27 14:00:02 +00:00
Robert Scott
e22c217c07 lapack: add patch for CVE-2021-4048
(cherry picked from commit 6d952e40483a6951d585b79070872e81909409a9)
2021-12-27 13:06:36 +00:00
Robert Schütz
582a1d6c97 imagemagick: 7.1.0-17 -> 7.1.0-19
(cherry picked from commit 2c526159cf)
2021-12-27 13:08:47 +01:00
Kerstin Humm
501ad5c0cb imagemagick: 7.1.0-16 -> 7.1.0-17
(cherry picked from commit 7617df63c2)
2021-12-27 13:08:47 +01:00
Kerstin Humm
25c393bd4d imagemagick: 7.1.0-15 -> 7.1.0-16
(cherry picked from commit 63ea61bcf0)
2021-12-27 13:08:47 +01:00
Kerstin Humm
c84e053e5e imagemagick: 7.1.0-14 -> 7.1.0-15
(cherry picked from commit d3c7e5801f)
2021-12-27 13:08:47 +01:00
Kerstin Humm
8db2826309 imagemagick: 7.1.0-13 -> 7.1.0-14
(cherry picked from commit 4d5800ed10)
2021-12-27 13:08:47 +01:00
TredwellGit
db5e9de662 firmwareLinuxNonfree: 20211027 -> 20211216
(cherry picked from commit f1edf331df)
2021-12-26 16:27:01 +00:00
Robert Scott
7e597098ba gmp5: add patch for CVE-2021-43618
(cherry picked from commit 7ba37884e2)
2021-12-25 22:50:06 +00:00
Robert Scott
a1329cff6e gmp: add patch for CVE-2021-43618
(cherry picked from commit d35c79a419)
2021-12-25 22:50:06 +00:00
TredwellGit
4c6ede108d linux_latest-libre: 18484 -> 18517
(cherry picked from commit 387250dce5)
2021-12-25 10:10:27 +00:00
TredwellGit
d5a076aa71 linux-rt_5_10: 5.10.83-rt58 -> 5.10.87-rt59
(cherry picked from commit 0cb00d51f7)
2021-12-25 10:10:27 +00:00
TredwellGit
b1c59850b6 linux: 5.4.167 -> 5.4.168
(cherry picked from commit fbd944d91d)
2021-12-25 10:10:27 +00:00
TredwellGit
bb32312f76 linux: 5.15.10 -> 5.15.11
(cherry picked from commit fa7b495239)
2021-12-25 10:10:26 +00:00
TredwellGit
a87c7e104b linux: 5.10.87 -> 5.10.88
(cherry picked from commit 9b43bf552f)
2021-12-25 10:10:26 +00:00
TredwellGit
74c9d02489 linux: 4.9.293 -> 4.9.294
(cherry picked from commit 2ccbef604f)
2021-12-25 10:10:26 +00:00
TredwellGit
a3a0752e7d linux: 4.4.295 -> 4.4.296
(cherry picked from commit 11486e8377)
2021-12-25 10:10:26 +00:00
TredwellGit
9a73364d52 linux: 4.19.221 -> 4.19.222
(cherry picked from commit 545cffb0b5)
2021-12-25 10:10:26 +00:00
TredwellGit
33c8bc6f4e linux: 4.14.258 -> 4.14.259
(cherry picked from commit b375970256)
2021-12-25 10:10:26 +00:00
github-actions[bot]
206cd2521f Merge staging-next-21.05 into staging-21.05 2021-12-24 00:09:21 +00:00
github-actions[bot]
b2d797154c Merge release-21.05 into staging-next-21.05 2021-12-24 00:08:47 +00:00
Thiago Kenji Okada
dde1557825 Merge pull request #151889 from thiagokokada/backport-151384-to-release-21.05
[Backport release-21.05] firefox-unwrapped: 95.0.1 -> 95.0.2
2021-12-23 15:12:37 -03:00
Thiago Kenji Okada
c326047316 Merge pull request #151459 from risicle/ris-flask-appbuilder-3.3.4-r21.05
[21.05] python3Packages.flask-appbuilder: 3.3.2 -> 3.3.4
2021-12-23 12:38:26 -03:00
Thiago Kenji Okada
79a57c3c4c Merge pull request #151392 from NixOS/backport-151063-to-release-21.05
[Backport release-21.05] graylog: 3.3.15 -> 3.3.16
2021-12-23 12:37:54 -03:00
Thiago Kenji Okada
f2d73fc8c1 Merge pull request #151781 from ius/ghidra-21.05
[21.05] ghidra: fix CVE-2021-45046, CVE-2021-45105
2021-12-23 12:18:42 -03:00
R. Ryantm
2aa5f2e2e5 firefox-unwrapped: 95.0.1 -> 95.0.2
(cherry picked from commit a233df3bc9)
2021-12-23 11:58:08 -03:00
Thiago Kenji Okada
7823ca5e34 Merge pull request #151451 from NixOS/backport-151279-to-release-21.05
[Backport release-21.05] firefox-bin: 95.0 -> 95.0.2
2021-12-23 11:39:41 -03:00
github-actions[bot]
884fff02cc Merge staging-next-21.05 into staging-21.05 2021-12-23 00:09:41 +00:00
github-actions[bot]
6acba2617b Merge release-21.05 into staging-next-21.05 2021-12-23 00:08:49 +00:00
Joerie de Gram
7759198f51 ghidra: fix CVE-2021-45046, CVE-2021-45105
Upgrade bundled log4j to 2.12.3 (#150288)
2021-12-22 17:12:17 +01:00
Bobby Rong
3f0e4de0c2 Merge pull request #150353 from NixOS/backport-149989-to-release-21.05
[Backport release-21.05] papermc: 1.17.1r97 -> 1.17.1r399
2021-12-22 18:41:40 +08:00
github-actions[bot]
88cfba4020 Merge staging-next-21.05 into staging-21.05 2021-12-22 00:09:57 +00:00
github-actions[bot]
77e7f9fcc6 Merge release-21.05 into staging-next-21.05 2021-12-22 00:09:17 +00:00
Robert Scott
02ccb83b59 Merge pull request #151611 from NixOS/backport-148711-to-release-21.05
[Backport release-21.05] pure-ftpd: add patch for CVE-2021-40524
2021-12-21 21:26:17 +00:00
Robert Scott
6ec0b338d7 pure-ftpd: add patch for CVE-2021-40524
(cherry picked from commit 82f811e6ed)
2021-12-21 18:27:39 +00:00
Robert Scott
cbdbb39ad6 Merge pull request #149426 from risicle/ris-zydis-3.1.0-CVE-2021-41253-r21.05
[21.05] zydis: add patch for CVE-2021-41253
2021-12-21 18:22:21 +00:00
github-actions[bot]
b5ff6db033 Merge staging-next-21.05 into staging-21.05 2021-12-21 00:09:51 +00:00
github-actions[bot]
8b1e9ea486 Merge release-21.05 into staging-next-21.05 2021-12-21 00:09:13 +00:00
Robert Scott
f554182d85 python3Packages.flask-appbuilder: 3.3.3 -> 3.3.4
addressing CVE-2021-41265

(cherry picked from commit 948a3e264a)
2021-12-20 20:37:57 +00:00
Fabian Affolter
2eba7fa966 python3Packages.flask-appbuilder: 3.3.2 -> 3.3.3
(cherry picked from commit 0aca277bfb)
2021-12-20 20:36:25 +00:00
taku0
e3cddacac1 firefox-bin: 95.0.1 -> 95.0.2
(cherry picked from commit cd2e8e2949)
2021-12-20 19:46:58 +00:00
taku0
05d165ebfd firefox-bin: 95.0 -> 95.0.1
(cherry picked from commit 3ee12cf528)
2021-12-20 19:46:58 +00:00
Martin Weinelt
a0899f0665 Merge pull request #151376 from mweinelt/21.05/firefox 2021-12-20 11:28:27 +01:00
Thomas Gerbet
68deecd639 graylog: 3.3.15 -> 3.3.16
Bump log4j 2 to 2.6.0.
https://www.graylog.org/post/announcing-graylog-v3-3-16

(cherry picked from commit ea5bc4fe75)
2021-12-20 07:58:49 +00:00
github-actions[bot]
8e3b0cce6d Merge staging-next-21.05 into staging-21.05 2021-12-20 00:09:50 +00:00
github-actions[bot]
7c61676e2b Merge release-21.05 into staging-next-21.05 2021-12-20 00:09:13 +00:00
R. Ryantm
7cbc0bfe92 firefox-esr-91-unwrapped: 91.4.0esr -> 91.4.1esr
(cherry picked from commit 5ae25b97ad)
2021-12-20 00:33:18 +01:00
R. Ryantm
0c94973d82 firefox-unwrapped: 95.0 -> 95.0.1
(cherry picked from commit d76ff3c3f1)
2021-12-20 00:32:35 +01:00
Artturi
171b8d99b0 Merge pull request #151326 from mweinelt/21.05/virtiokb
[21.05] nixos/qemu-vm: add -device virtio-keyboard to opts
2021-12-20 01:22:02 +02:00
Artturin
eef8ee13b5 nixos/qemu-vm: add -device virtio-keyboard to opts
by default a ps/2 keyboard input is used which seems to cause issues
on aarch64-linux when the machine is used high load, causing the keymap
qwertz test to always fail and azerty to sometimes fail
See https://github.com/NixOS/nixpkgs/issues/147294

(cherry picked from commit 39c5525cb1)
2021-12-19 16:26:20 +01:00
Maximilian Bosch
86abaced1a Merge pull request #151204 from NixOS/backport-150726-to-release-21.05
[Backport release-21.05] Kernels 2021-12-17
2021-12-19 15:54:58 +01:00
Vladimír Čunát
15356173c2 Merge #151141: staging-next: 2021-12-18 into release-21.05 2021-12-19 10:47:58 +01:00
0x4A6F
f35d838e73 Merge pull request #151178 from NixOS/backport-151145-to-release-21.05
[Backport release-21.05] unifi5: Follow new mitigation guidelines
2021-12-19 09:45:49 +01:00
0x4A6F
e000da59d4 unifi: Adjust NixOS tests to 21.05
- increase virtualisation.memorySize
- use renamed option openPorts
- remove unsupported timeout in wait_until_succeeds

Co-authored-by: Zhaofeng Li <hello@zhaofeng.li>
2021-12-19 09:30:52 +01:00
Bobby Rong
b4892c44bc Merge pull request #150592 from NixOS/backport-150310-to-release-21.05
[Backport release-21.05] [21.11] metabase: 0.38.0 -> 0.38.6
2021-12-19 11:29:57 +08:00
github-actions[bot]
2db1281d28 Merge staging-next-21.05 into staging-21.05 2021-12-19 00:10:05 +00:00
github-actions[bot]
cac890fb3e Merge release-21.05 into staging-next-21.05 2021-12-19 00:09:27 +00:00
TredwellGit
300d05cd03 linux/hardened/patches/5.4: 5.4.164-hardened1 -> 5.4.167-hardened1
(cherry picked from commit 8d4c056723)
2021-12-18 15:16:23 +00:00
TredwellGit
9cb442956f linux/hardened/patches/5.15: 5.15.7-hardened1 -> 5.15.10-hardened1
(cherry picked from commit f51d19746a)
2021-12-18 15:16:23 +00:00
TredwellGit
080c85c306 linux/hardened/patches/5.10: 5.10.84-hardened1 -> 5.10.87-hardened1
(cherry picked from commit a900de3567)
2021-12-18 15:16:23 +00:00
TredwellGit
c7da340a4b linux/hardened/patches/4.19: 4.19.220-hardened1 -> 4.19.221-hardened1
(cherry picked from commit 8e317ff982)
2021-12-18 15:16:23 +00:00
TredwellGit
ff4646c98d linux/hardened/patches/4.14: 4.14.257-hardened1 -> 4.14.258-hardened1
(cherry picked from commit d9fdc409d1)
2021-12-18 15:16:23 +00:00
TredwellGit
36bfe84696 linux: 5.4.164 -> 5.4.167
(cherry picked from commit a1470e23da)
2021-12-18 15:16:23 +00:00
TredwellGit
99b08366b9 linux: 5.15.7 -> 5.15.10
(cherry picked from commit 8955b58c5e)
2021-12-18 15:16:23 +00:00
TredwellGit
10e08b9b11 linux: 5.10.84 -> 5.10.87
(cherry picked from commit 72b54385a5)
2021-12-18 15:16:23 +00:00
TredwellGit
588809723c linux: 4.9.292 -> 4.9.293
(cherry picked from commit 837103a484)
2021-12-18 15:16:23 +00:00
TredwellGit
4d983472d7 linux: 4.4.294 -> 4.4.295
(cherry picked from commit 2deb4377d5)
2021-12-18 15:16:23 +00:00
TredwellGit
d9c8d0647d linux: 4.19.220 -> 4.19.221
(cherry picked from commit 9eacb2bb44)
2021-12-18 15:16:23 +00:00
TredwellGit
f9104638ae linux: 4.14.257 -> 4.14.258
(cherry picked from commit 860b4c92b8)
2021-12-18 15:16:23 +00:00
Robert Scott
2949ed3653 Merge pull request #151182 from NixOS/backport-151124-to-release-21.05
[Backport release-21.05] tightvnc: mark as insecure (fixes #150704)
2021-12-18 12:56:45 +00:00
Ingo Blechschmidt
d95603039c tightvnc: mark as insecure (fixes #150704)
(cherry picked from commit 034d277c6e)
2021-12-18 12:55:29 +00:00
Martin Weinelt
564f81d25b Merge pull request #150904 from 0x4A6F/backport-150511-to-release-21.05 2021-12-18 13:41:09 +01:00
Zhaofeng Li
61cb7ab54a unifi: Add NixOS tests
(cherry picked from commit 8bbae8e558)
2021-12-18 12:04:57 +00:00
Zhaofeng Li
f3d2e8d08b unifi5: Follow new mitigation guidelines
Simply disabling lookups isn't enough, and the JndiLookup class must be
removed:

https://web.archive.org/web/20211217085954/https://logging.apache.org/log4j/2.x/security.html
(cherry picked from commit a4bcad541e)
2021-12-18 12:04:57 +00:00
github-actions[bot]
512bdf8abc Merge staging-next-21.05 into staging-21.05 2021-12-17 00:09:09 +00:00
github-actions[bot]
e9aafa2e29 Merge release-21.05 into staging-next-21.05 2021-12-17 00:08:30 +00:00
Martin Weinelt
6fe28d7c4d Merge pull request #150956 from mweinelt/21.05/mediawiki 2021-12-17 01:08:05 +01:00
Martin Weinelt
f979bea86d Merge pull request #151032 from NixOS/backport-151029-to-release-21.05 2021-12-17 00:55:24 +01:00
Robert Scott
df77c6d60f Merge pull request #151011 from NixOS/backport-150614-to-release-21.05
[Backport release-21.05] libtoxcore: 0.2.12 -> 0.2.13
2021-12-16 23:36:22 +00:00
Andreas Rammhold
d4689a9f01 nixos/snapserver: use the correct bind address arguments
Snapserver expects the arguments `--tcp.bind_to_address` and
`--http.bind_to_address` instead of the `--tcp.address` (and http
equivalent) versions.

This caused the process to listen on `0.0.0.0` (for TCP and HTTP
sockets) regardless of the configuration value. It also never listend on
the IPv6 address `::` as our module system made the user believe.

This commit fixes the above issue and ensures that (at least for the TCP
socket) that our default `::` does indeed allow connections via IPv6
(to localhost aka ::1).

(cherry picked from commit c9c93b0add)
2021-12-16 22:56:48 +00:00
Thiago Kenji Okada
ffc620372d Merge pull request #151026 from NixOS/backport-150975-to-release-21.05
[Backport release-21.05] Revert "nixos-rebuild: switch to tmpDir during rebuilds"
2021-12-16 19:42:38 -03:00
Thiago Kenji Okada
428f8f48de Revert "nixos-rebuild: switch to tmpDir during rebuilds"
This seems to break
`boot.kernelPackages = config.boot.zfs.package.latestCompatibleLinuxPackages`
causing it to use `linuxPackages`.

(cherry picked from commit e6ca3fc976)
2021-12-16 22:19:34 +00:00
Maximilian Bosch
822f370d65 Merge pull request #150484 from Ma27/kernels-21.05
[21.05] Kernels 2021-12-0{1,8}
2021-12-16 23:13:21 +01:00
Robert Scott
b1a3714e24 libtoxcore: 0.2.12 -> 0.2.13
(cherry picked from commit bbf825544e)
2021-12-16 20:12:50 +00:00
Joel
7da8092d46 minecraft-server: 1.18 -> 1.18.1 (#149982)
(cherry picked from commit b835bec4d7)
2021-12-16 15:40:53 +01:00
Robin Townsend
6a3b096ba4 minecraft-server: 1.17.1 -> 1.18
(cherry picked from commit 43ec279d77)
2021-12-16 15:40:51 +01:00
Robin Townsend
8b7bc9fb89 minecraft-server: 1.17 -> 1.17.1
(cherry picked from commit 57d0e94d86)
2021-12-16 15:40:50 +01:00
Thomas Gerbet
0f0982c529 graylog: 3.3.14 -> 3.3.15
This release included a fix for the Log4j vulnerability.
https://www.graylog.org/post/graylog-update-for-log4j
2021-12-16 14:46:49 +01:00
FadenB
b35a7d5edd graylog: 3.3.9 -> 3.3.14 2021-12-16 14:46:29 +01:00
Martin Weinelt
705ca783a4 mediawiki: 1.35.4 -> 1.35.5 2021-12-16 11:59:01 +01:00
github-actions[bot]
63ae862d80 Merge staging-next-21.05 into staging-21.05 2021-12-16 00:09:00 +00:00
github-actions[bot]
e2add42dd6 Merge release-21.05 into staging-next-21.05 2021-12-16 00:08:24 +00:00
Thiago Kenji Okada
6d684ea3ad Merge pull request #150889 from NixOS/backport-150885-to-release-21.05
[Backport release-21.05] phpExtensions: skip performance sensitive tests
2021-12-15 20:32:55 -03:00
Thiago Kenji Okada
eaa1d15871 Merge pull request #150891 from NixOS/backport-150874-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 96.0.4664.93 -> 96.0.4664.110
2021-12-15 20:31:30 -03:00
Thiago Kenji Okada
149feb6f51 Merge pull request #150906 from risicle/ris-openblas-CVE-2021-4048-r21.05
[21.05] openblas: add patch for CVE-2021-4048
2021-12-15 20:31:20 -03:00
Robert Scott
2b8584b89d Merge pull request #150274 from NixOS/backport-144301-to-release-21.05
[Backport release-21.05] barrier: 2.3.3 -> 2.4.0
2021-12-15 22:55:39 +00:00
Robert Scott
aa5960c0a0 openblas: add patch for CVE-2021-4048
using patch from upstream lapack because it's functionally identical
and comes in one part instead of 4
2021-12-15 22:39:07 +00:00
0x4A6F
457de9029a Merge pull request #150589 from pstn/backport-150558-to-release-21.05
[21.05] element-*: 1.9.2 -> 1.9.7
2021-12-15 22:53:55 +01:00
Michael Weiss
1d8c076298 ungoogled-chromium: 96.0.4664.93 -> 96.0.4664.110
(cherry picked from commit af2536fe77)
2021-12-15 20:36:11 +00:00
Konrad Borowski
f6247ca5be phpExtensions: skip performance sensitive tests
(cherry picked from commit 0af523ae77)
2021-12-15 20:32:43 +00:00
Thiago Kenji Okada
f70ec54793 Merge pull request #150772 from NixOS/backport-150742-to-release-21.05
[Backport release-21.05] xorg.xorgserver: apply CVE patches
2021-12-15 12:28:15 -03:00
Thiago Kenji Okada
afd872d5f9 Merge pull request #150856 from NixOS/backport-150065-to-release-21.05
[Backport release-21.05] nixos-rebuild: switch to tmpDir during rebuilds
2021-12-15 12:23:39 -03:00
Thiago Kenji Okada
06cb11191c nixos-rebuild: switch to tmpDir during rebuilds
This is a workaround for issue #144811 until this issue is either fixed
on nix itself.

(cherry picked from commit f88bd76fcd)
2021-12-15 15:05:38 +00:00
Thiago Kenji Okada
d7cbdf9c85 Merge pull request #150849 from thiagokokada/backport-149661-to-release-21.05
[Backport release-21.05] firefox-bin: 94.0.2 -> 95.0
2021-12-15 11:35:12 -03:00
Bernardo Meurer
a63d15f4b0 firefox-bin: 94.0.2 -> 95.0
(cherry picked from commit e0da0b7c6a)
2021-12-15 11:18:42 -03:00
github-actions[bot]
c43162d4e0 Merge staging-next-21.05 into staging-21.05 2021-12-15 00:09:19 +00:00
github-actions[bot]
076af0a5c6 Merge release-21.05 into staging-next-21.05 2021-12-15 00:08:43 +00:00
Vladimír Čunát
bcb7a87e83 xorg.xorgserver: apply CVE patches
(cherry picked from commit 7101e3e580)
2021-12-14 22:08:26 +00:00
Anderson Torres
fd9d0ea3c5 Merge pull request #150760 from wamserma/fix-calibre-cve-2105
[21.05] calibre: fix CVE-2021-44686 (security)
2021-12-14 18:18:17 -03:00
Markus S. Wamser
6b0656668b [21.05] calibre: fix CVE-2021-44686 (security) 2021-12-14 21:52:04 +01:00
Michael Weiss
32b3c9c903 Merge pull request #150734 from NixOS/backport-150715-to-release-21.05
[Backport release-21.05] chromium: 96.0.4664.93 -> 96.0.4664.110
2021-12-14 19:02:58 +01:00
Michael Weiss
474ef6217e chromium: 96.0.4664.93 -> 96.0.4664.110
https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html

This update includes 5 security fixes. Google is aware of reports that
an exploit for CVE-2021-4102 exists in the wild.

CVEs:
CVE-2021-4098 CVE-2021-4099 CVE-2021-4100 CVE-2021-4101 CVE-2021-4102

(cherry picked from commit 9528f0d87e)
2021-12-14 17:16:08 +00:00
Martin Weinelt
0f54876e56 Merge pull request #150716 from NixOS/backport-139673-to-release-21.05 2021-12-14 17:55:12 +01:00
Philipp
fcfe228a61 element-*: 1.9.2 -> 1.9.7 2021-12-14 17:07:14 +01:00
Martin Weinelt
d900bdb4b2 edk2: 202102 -> 202108
(cherry picked from commit ccbdef3b20)
2021-12-14 14:32:19 +00:00
github-actions[bot]
6792e50f30 Merge staging-next-21.05 into staging-21.05 2021-12-14 00:09:35 +00:00
github-actions[bot]
314d2701cd Merge release-21.05 into staging-next-21.05 2021-12-14 00:08:51 +00:00
Maximilian Bosch
c5f1ee9822 Merge pull request #150526 from Ma27/signald-cve-2021-44228-21.05
[21.05] signald: incorporate log4j update for CVE-2021-44228
2021-12-13 22:26:32 +01:00
Konrad Borowski
847f0a33a6 metabase: add passthru tests
(cherry picked from commit 9eee84f9f0)
(cherry picked from commit c5cece7d8b)
2021-12-13 20:11:20 +00:00
Konrad Borowski
519423492b metabase: 0.38.0 -> 0.38.6
(cherry picked from commit 5467131758)
2021-12-13 20:11:20 +00:00
Maximilian Bosch
39a70b1d00 signald: incorporate log4j update for CVE-2021-44228
Equivalent to 79ab6a8382 on `master`, but
against 0.14.1.

Relevant for #150288
2021-12-13 13:19:04 +01:00
Janne Heß
c00268dcd7 Merge pull request #150426 from pennae/backport-150329-to-release-21.05 2021-12-13 12:05:46 +01:00
github-actions[bot]
079913fcbe Merge staging-next-21.05 into staging-21.05 2021-12-13 00:09:12 +00:00
github-actions[bot]
d71f0652d7 Merge release-21.05 into staging-next-21.05 2021-12-13 00:08:32 +00:00
Maximilian Bosch
95f4344a47 Merge pull request #150466 from Ma27/grafana-security-21.05
[21.05] grafana: 7.5.11 -> 7.5.12, fix CVE-2021-43813
2021-12-12 22:23:10 +01:00
TredwellGit
4c572e8602 linux/hardened/patches/5.4: 5.4.163-hardened1 -> 5.4.164-hardened1
(cherry picked from commit dc7d9307ae)
2021-12-12 20:53:57 +01:00
TredwellGit
37aed422a0 linux/hardened/patches/5.15: 5.15.6-hardened1 -> 5.15.7-hardened1
(cherry picked from commit 935a3eb77b)
2021-12-12 20:53:56 +01:00
TredwellGit
ea3e98c97d linux/hardened/patches/5.10: 5.10.83-hardened1 -> 5.10.84-hardened1
(cherry picked from commit 4e28ad8780)
2021-12-12 20:53:54 +01:00
TredwellGit
2e826cce59 linux/hardened/patches/4.19: 4.19.219-hardened1 -> 4.19.220-hardened1
(cherry picked from commit ac0487fe56)
2021-12-12 20:53:53 +01:00
TredwellGit
3b2459de68 linux/hardened/patches/4.14: 4.14.256-hardened1 -> 4.14.257-hardened1
(cherry picked from commit 8448ac947f)
2021-12-12 20:53:51 +01:00
TredwellGit
b28e58db65 linux-rt_5_4: 5.4.161-rt66 -> 5.4.161-rt67
(cherry picked from commit 7f32450344)
2021-12-12 20:53:50 +01:00
TredwellGit
079e841b3a linux-rt_5_10: 5.10.78-rt56 -> 5.10.83-rt58
(cherry picked from commit 7952853749)
2021-12-12 20:53:48 +01:00
TredwellGit
93b482c1b9 linux: 5.4.163 -> 5.4.164
(cherry picked from commit 21de99d456)
2021-12-12 20:53:47 +01:00
TredwellGit
e7cfec4cb4 linux: 5.15.6 -> 5.15.7
(cherry picked from commit 935be58f5c)
2021-12-12 20:53:45 +01:00
TredwellGit
2f90410931 linux: 5.10.83 -> 5.10.84
(cherry picked from commit 2e7590e84f)
2021-12-12 20:53:43 +01:00
TredwellGit
a51d91b6dc linux: 4.9.291 -> 4.9.292
(cherry picked from commit ad844d0a89)
2021-12-12 20:53:42 +01:00
TredwellGit
3915b5bab9 linux: 4.4.293 -> 4.4.294
(cherry picked from commit 0d0bc6032d)
2021-12-12 20:53:40 +01:00
TredwellGit
115cdcf61d linux: 4.19.219 -> 4.19.220
(cherry picked from commit 8a9c48a65d)
2021-12-12 20:53:38 +01:00
TredwellGit
8296abcb68 linux: 4.14.256 -> 4.14.257
(cherry picked from commit 9cc83854e0)
2021-12-12 20:53:37 +01:00
TredwellGit
8337791e29 linux_5_14: remove
https://lwn.net/ml/linux-kernel/1637500331152110@kroah.com/
https://github.com/openzfs/zfs/issues/12786
(cherry picked from commit 04bbfd1b88)
2021-12-12 20:52:28 +01:00
TredwellGit
78e74f6421 linux/hardened/patches/5.4: 5.4.160-hardened1 -> 5.4.163-hardened1
(cherry picked from commit a93b636340)
2021-12-12 20:41:09 +01:00
TredwellGit
811ca7392d linux/hardened/patches/5.15: 5.15.3-hardened1 -> 5.15.6-hardened1
(cherry picked from commit a4a70dcab4)
2021-12-12 20:41:07 +01:00
TredwellGit
4d1b2f78cc linux/hardened/patches/5.10: 5.10.80-hardened1 -> 5.10.83-hardened1
(cherry picked from commit 55969e856c)
2021-12-12 20:41:06 +01:00
TredwellGit
cd795f3d8c linux/hardened/patches/4.19: 4.19.217-hardened1 -> 4.19.219-hardened1
(cherry picked from commit cfd35502f6)
2021-12-12 20:41:04 +01:00
TredwellGit
374d5579fb linux/hardened/patches/4.14: 4.14.255-hardened1 -> 4.14.256-hardened1
(cherry picked from commit d2bfac4ff9)
2021-12-12 20:41:03 +01:00
TredwellGit
504091d8f3 linux-rt_5_4: 5.4.154-rt65 -> 5.4.161-rt66
(cherry picked from commit b4a903e20d)
2021-12-12 20:41:01 +01:00
TredwellGit
325a1b0d36 linux-rt_5_10: 5.10.78-rt55 -> 5.10.78-rt56
(cherry picked from commit 962956db96)
2021-12-12 20:40:34 +01:00
TredwellGit
5f5583ea1e linux: 5.4.161 -> 5.4.163
(cherry picked from commit 8a260ea0f3)
2021-12-12 20:40:29 +01:00
TredwellGit
dbd09b6929 linux: 5.15.4 -> 5.15.6
(cherry picked from commit cd32471748)
2021-12-12 20:40:27 +01:00
TredwellGit
9ba894f7dd linux: 5.10.81 -> 5.10.83
(cherry picked from commit 342e0a3df9)
2021-12-12 20:40:26 +01:00
TredwellGit
e0c3fa10d7 linux: 4.9.290 -> 4.9.291
(cherry picked from commit 9fc610cf3f)
2021-12-12 20:40:24 +01:00
TredwellGit
d313bf04cb linux: 4.4.292 -> 4.4.293
(cherry picked from commit cc06653c46)
2021-12-12 20:40:23 +01:00
TredwellGit
5b557f5263 linux: 4.19.217 -> 4.19.219
(cherry picked from commit 0868920a42)
2021-12-12 20:40:21 +01:00
TredwellGit
16c1a94379 linux: 4.14.255 -> 4.14.256
(cherry picked from commit f4f1bfd261)
2021-12-12 20:39:58 +01:00
Maximilian Bosch
583ab1d48d grafana: 7.5.11 -> 7.5.12
Fixes CVE-2021-43813[1], a directory-traversal vulnerability for
`.md`-files (for authenticated users only).

ChangeLog: https://github.com/grafana/grafana/releases/tag/v7.5.12

[1] https://nvd.nist.gov/vuln/detail/CVE-2021-43813
2021-12-12 20:28:59 +01:00
Thiago Kenji Okada
a891ce7dc2 Merge pull request #150389 from vcunat/p/thunderbird-21.05
[21.05] thunderbird: 91.3.1 -> 91.4.0
2021-12-12 11:39:55 -03:00
Zhaofeng Li
22e78143f2 nixos/unifi: Apply log4j2 mitigation
(cherry picked from commit e992604bf0)
2021-12-12 14:31:07 +01:00
Vladimír Čunát
55ac78d5cf thunderbird: 91.3.1 -> 91.4.0
(Cherry-picked from 901064350e, skipping 91.3.2.)
2021-12-12 09:47:38 +01:00
Aaron Janse
979b216eaf Update pkgs/games/papermc/default.nix
Co-authored-by: Joel <jyooru+github@protonmail.ch>
(cherry picked from commit 53d7554d151c54489175fedca7f45a85d72ee59f)
2021-12-12 01:46:49 +00:00
Aaron Janse
8f4958a80f Update pkgs/games/papermc/default.nix
Co-authored-by: Joel <jyooru+github@protonmail.ch>
(cherry picked from commit 86f325b117bcc45d44f05a5a4da89c2d03bb41c4)
2021-12-12 01:46:49 +00:00
Aaron Janse
e7f4fc8348 papermc: 1.17.1r97 -> 1.17.1r399
(cherry picked from commit f994bbb83f3d2fe3053b9bd16f25689b76e9356f)
2021-12-12 01:46:48 +00:00
github-actions[bot]
a5aa0487a9 Merge staging-next-21.05 into staging-21.05 2021-12-12 00:09:50 +00:00
github-actions[bot]
ff3a0797f0 Merge release-21.05 into staging-next-21.05 2021-12-12 00:09:08 +00:00
Joerie de Gram
a4d8be7f2a zap: 2.11.0 -> 2.11.1
Fixes CVE-2021-44228 #150288
2021-12-11 20:28:58 +01:00
R. Ryantm
ca5346dbd1 zap: 2.10.0 -> 2.11.0 2021-12-11 20:28:49 +01:00
R. Ryantm
79a7044515 barrier: 2.3.3 -> 2.4.0
(cherry picked from commit 135ac287c2)
2021-12-11 16:48:45 +00:00
Jörg Thalheim
499ca2a9f6 Merge pull request #150159 from ius/ghidra-21.05
[21.05] ghidra: 9.2.3 -> 9.2.4
2021-12-11 05:54:02 +00:00
Joerie de Gram
c226964723 ghidra: fix CVE-2021-44228 2021-12-11 01:17:15 +01:00
Joerie de Gram
88516fbfdb ghidra: 9.2.3 -> 9.2.4 2021-12-11 01:10:45 +01:00
github-actions[bot]
526547a436 Merge staging-next-21.05 into staging-21.05 2021-12-11 00:09:29 +00:00
github-actions[bot]
40f0d1036f Merge release-21.05 into staging-next-21.05 2021-12-11 00:08:40 +00:00
Vladimír Čunát
3b42299178 Merge #149902: knot-resolver: patch an issue 2021-12-10 10:55:58 +01:00
github-actions[bot]
997be7c49a Merge staging-next-21.05 into staging-21.05 2021-12-10 00:09:12 +00:00
github-actions[bot]
1af6187ef7 Merge release-21.05 into staging-next-21.05 2021-12-10 00:08:37 +00:00
Vladimír Čunát
e3b7406273 knot-resolver: patch a possibly unpleasant issue
No more releasing in 2021.

(cherry picked from commit 02d8ed2eb1)
2021-12-09 19:01:29 +00:00
Thiago Kenji Okada
db200f7cf4 Merge pull request #149855 from NixOS/backport-149844-to-release-21.05
[Backport release-21.05] privoxy: 3.0.32 -> 3.0.33
2021-12-09 11:48:02 -03:00
Martin Weinelt
33ae825dc9 privoxy: 3.0.32 -> 3.0.33
(cherry picked from commit 9a4da4a8a0)
2021-12-09 13:53:06 +00:00
Martin Weinelt
5894b65492 Merge pull request #149752 from NixOS/backport-147994-to-release-21.05 2021-12-09 13:58:37 +01:00
Jamie McClymont
c2aeccf844 pythonPackages.requests-toolbelt: disable time-dependant tests
Tests include certificates and fail because they are expired.

Upstream issue exists but has been ignored: https://github.com/requests/toolbelt/issues/306

closes #147776

(cherry picked from commit 62df72857c)
2021-12-09 00:23:58 +00:00
github-actions[bot]
03936e5e27 Merge staging-next-21.05 into staging-21.05 2021-12-09 00:09:03 +00:00
github-actions[bot]
007c3c3c78 Merge release-21.05 into staging-next-21.05 2021-12-09 00:08:21 +00:00
Thiago Kenji Okada
70b96897b3 Merge pull request #149702 from NixOS/backport-149691-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 96.0.4664.45 -> 96.0.4664.93
2021-12-08 18:13:16 -03:00
Thiago Kenji Okada
19a6007d94 Merge pull request #149682 from NixOS/backport-149650-to-release-21.05
[Backport release-21.05] steam: 1.0.0.73 -> 1.0.0.74
2021-12-08 17:34:51 -03:00
Martin Weinelt
e1e72d029c Merge pull request #149674 from mweinelt/21.05/firefox 2021-12-08 20:53:30 +01:00
Michael Weiss
725e891f4a ungoogled-chromium: 96.0.4664.45 -> 96.0.4664.93
(cherry picked from commit a5782a2b53)
2021-12-08 19:45:54 +00:00
R. Ryantm
fd0136ab42 firefox-esr-91-unwrapped: 91.3.0esr -> 91.4.0esr
(cherry picked from commit 8474bbde74)
2021-12-08 20:00:41 +01:00
ajs124
fc837143ac firefox: 94.0.2 -> 95.0
(cherry picked from commit 340ede9984)
2021-12-08 20:00:41 +01:00
lassulus
a9d50fffdc steam: 1.0.0.73 -> 1.0.0.74
(cherry picked from commit 9deb6bf336)
2021-12-08 18:01:31 +00:00
Martin Weinelt
2531be91f1 Merge pull request #149571 from mweinelt/21.05/python/django3 2021-12-08 17:45:35 +01:00
Martin Weinelt
9ed6c15985 python3Packages.django_2: 2.2.24 -> 2.2.25
(cherry picked from commit bd080376d3)
2021-12-08 10:04:20 +01:00
Martin Weinelt
76c37efabe python3Packages.django_3: 3.2.9 -> 3.2.10
(cherry picked from commit 8f6c98f535)
2021-12-08 10:04:16 +01:00
R. Ryantm
67595c8e82 python38Packages.django_3: 3.2.8 -> 3.2.9
(cherry picked from commit 07b54fd95d)
2021-12-08 02:17:55 +01:00
R. RyanTM
2611c63a4e python38Packages.django_3: 3.2.7 -> 3.2.8
(cherry picked from commit b2539bac63)
2021-12-08 02:17:50 +01:00
R. RyanTM
1f8374b0be python38Packages.django_3: 3.2.5 -> 3.2.7
(cherry picked from commit e951c8214e)
2021-12-08 02:17:44 +01:00
github-actions[bot]
6b71e17dc6 Merge staging-next-21.05 into staging-21.05 2021-12-08 00:09:22 +00:00
github-actions[bot]
f0d369506b Merge release-21.05 into staging-next-21.05 2021-12-08 00:08:42 +00:00
Alyssa Ross
fe56507bd3 apk-tools: 2.12.7 -> 2.12.8
(cherry picked from commit c283a575ab)
2021-12-08 00:08:03 +00:00
Martin Weinelt
25001940bb Merge pull request #148718 from NixOS/backport-143649-to-release-21.05 2021-12-07 23:45:03 +01:00
Thiago Kenji Okada
2868fe6222 Merge pull request #149451 from NixOS/backport-149438-to-release-21.05
[Backport release-21.05] chromium: 96.0.4664.45 -> 96.0.4664.93
2021-12-07 19:40:21 -03:00
Michael Weiss
1b628f4927 chromium: 96.0.4664.45 -> 96.0.4664.93
https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html

This update includes 22 security fixes.

CVEs:
CVE-2021-4052 CVE-2021-4053 CVE-2021-4079 CVE-2021-4054 CVE-2021-4078
CVE-2021-4055 CVE-2021-4056 CVE-2021-4057 CVE-2021-4058 CVE-2021-4059
CVE-2021-4061 CVE-2021-4062 CVE-2021-4063 CVE-2021-4064 CVE-2021-4065
CVE-2021-4066 CVE-2021-4067 CVE-2021-4068

(cherry picked from commit 4939140e0f)
2021-12-07 20:45:38 +00:00
Janne Heß
f951c09079 Merge pull request #149369 from NixOS/backport-149318-to-release-21.05
[Backport release-21.05] tmate-ssh-server: mark as insecure
2021-12-07 15:25:19 +01:00
philipp
2807f906a7 tmate-ssh-server: mark as insecure
(cherry picked from commit 91bc99e964)
2021-12-07 14:18:00 +00:00
github-actions[bot]
df17618772 Merge staging-next-21.05 into staging-21.05 2021-12-07 00:09:08 +00:00
github-actions[bot]
d71992c944 Merge release-21.05 into staging-next-21.05 2021-12-07 00:08:32 +00:00
Robert Scott
f7fc10f371 zydis: add patch for CVE-2021-41253 2021-12-06 23:48:21 +00:00
Janne Heß
0406ec2871 Merge pull request #148792 from NixOS/backport-148776-to-release-21.05
[Backport release-21.05] nginxModules.pam: 1.5.2 -> 1.5.3
2021-12-06 18:02:50 +01:00
Maximilian Bosch
4a8751d694 Merge pull request #148288 from NixOS/backport-148271-to-release-21.05
[Backport release-21.05] strace: 5.14 -> 5.15
2021-12-06 14:52:36 +01:00
github-actions[bot]
bb463e9758 Merge staging-next-21.05 into staging-21.05 2021-12-06 00:09:13 +00:00
github-actions[bot]
20e7f46f56 Merge release-21.05 into staging-next-21.05 2021-12-06 00:08:34 +00:00
Janne Heß
3315e4c29f nginxModules.pam: 1.5.2 -> 1.5.3
This fixes deny statements:
https://github.com/sto/ngx_http_auth_pam_module/issues/25

(cherry picked from commit b9811a5aeb)
2021-12-05 23:37:19 +00:00
John Ericson
131b8c31f3 Merge pull request #148697 from blitz/copy-desktop-items
[21.05] copyDesktopItems: fix handling of plain paths
2021-12-05 12:25:49 -05:00
R. Ryantm
1077d66ecb exiv2: 0.27.4 -> 0.27.5
(cherry picked from commit 7127f494ef)
2021-12-05 14:53:09 +00:00
ash
788ee7755e copyDesktopItems: fix handling of plain paths
(cherry picked from commit c6b0247067)
2021-12-05 12:11:31 +01:00
Pavol Rusnak
87cfc98a55 Merge pull request #148559 from NixOS/backport-148516-to-release-21.05
[Backport release-21.05] electrum-ltc: 3.3.8.1 -> 4.0.9.3
2021-12-05 10:12:04 +01:00
Louis Bettens
e2fe018f3d electrum-ltc: 3.3.8.1 -> 4.0.9.3
rewritten based on the electrum derivation

(cherry picked from commit 719beec27a)
2021-12-04 08:33:22 +00:00
github-actions[bot]
21cda18fd5 Merge staging-next-21.05 into staging-21.05 2021-12-04 00:08:28 +00:00
github-actions[bot]
5e9bf297b6 Merge release-21.05 into staging-next-21.05 2021-12-04 00:07:53 +00:00
Jonathan Ringer
b86b6bc5e7 agate: fix meta
old link is dead

(cherry picked from commit 161d757a3a4bf40a722816c814481353f4be18be)
2021-12-03 12:49:03 -08:00
Thiago Kenji Okada
c383928ee1 Merge pull request #148441 from thiagokokada/backport-148432-to-release-21.05
[Backport release-21.05] isync 1.4.2 -> 1.4.4
2021-12-03 11:37:44 -03:00
Alvar Penning
56cb40bc60 isync: 1.4.3 -> 1.4.4
Fixes CVE-2021-3657 and CVE-2021-44143 and closes #147884

(cherry picked from commit 8500a748bb)
2021-12-03 11:15:12 -03:00
Michael Weiss
c4cbbed186 isync: 1.4.2 -> 1.4.3
(cherry picked from commit 09bbf2d3ec)
2021-12-03 11:15:05 -03:00
Patrick Hilhorst
5854a24cfc Merge pull request #148308 from NixOS/backport-147297-to-release-21.05 2021-12-03 10:40:18 +01:00
Linus Heckemann
63ca6c5a1c Merge pull request #148001 from mayflower/backport-freerdp
[21.05] freerdp: 2.3.2 -> 2.4.1
2021-12-03 10:11:11 +01:00
Vladimír Čunát
e18cdf908b Merge #148390: nixosTests.keymap.qwertz: reduce platforms
... in `tested` job (into release-21.05)
2021-12-03 08:52:02 +01:00
Vladimír Čunát
3aa7278f27 nixosTests.keymap.qwertz: reduce platforms in tested
In particular, aarch64-linux variant doesn't work on Hydra,
so at least avoid this blocking the 21.11 channel.

(cherry picked from commit 3c2e73c2ea)
2021-12-03 07:37:31 +00:00
github-actions[bot]
640fe18028 Merge staging-next-21.05 into staging-21.05 2021-12-03 00:09:19 +00:00
github-actions[bot]
d7e86ae230 Merge release-21.05 into staging-next-21.05 2021-12-03 00:08:38 +00:00
Patrick Hilhorst
e351994424 Merge pull request #148313 from NixOS/backport-147296-to-release-21.05 2021-12-02 22:18:58 +01:00
Tom
0755fb2eb6 maintainers: add twitchyliquid64
(cherry picked from commit 8e88b57e05)
2021-12-02 20:54:56 +01:00
Tom
16e964615e wlr-protocols: init at unstable-2021-11-01
(cherry picked from commit 3664cbde79)
2021-12-02 18:30:00 +00:00
Tom
b40eb036e3 wl-mirror: init at 0.5.0
(cherry picked from commit b71ed45cfc)
2021-12-02 17:51:14 +00:00
Maximilian Bosch
ed0aa7dacc strace: 5.14 -> 5.15
ChangeLog: https://github.com/strace/strace/releases/tag/v5.15
(cherry picked from commit a0909777c8626fcb6d7f3fd8b0f978bf867265fc)
2021-12-02 14:52:42 +00:00
Martin Weinelt
43cdc5b364 Merge pull request #148225 from mweinelt/21.05/nss 2021-12-02 14:35:35 +01:00
Jörg Thalheim
3bd5c5d11a Merge pull request #148259 from NixOS/backport-148251-to-release-21.05
[Backport release-21.05] qemu: fix darwin build
2021-12-02 10:34:32 +00:00
Jörg Thalheim
d73ee4b11e qemu: fix darwin build
(cherry picked from commit 56ea0c9308)
2021-12-02 10:25:32 +00:00
Martin Weinelt
bb4549215a nss_3_53: mark vulnerable to CVE-2021-43527 2021-12-02 02:36:10 +01:00
Yureka
bf4f00e380 xmlsec: use latest nss
The issues mentioned seem to be fixed in the latest xmlsec release

(cherry picked from commit 4f93f4b82b)
2021-12-02 02:18:45 +01:00
R. RyanTM
1eb20dbf39 xmlsec: 1.2.31 -> 1.2.32
(cherry picked from commit 19822abfed)
2021-12-02 02:18:45 +01:00
Martin Weinelt
34d063e013 nss_latest: 3.71 -> 3.73 2021-12-02 02:00:01 +01:00
ajs124
e9b8abb76b nspr: 4.31 -> 4.32
NSPR 4.32 contains the following changes:
- implement new socket option PR_SockOpt_DontFrag
- support larger DNS records by increasing the default buffer size for DNS queries

See https://bugzilla.mozilla.org/buglist.cgi?resolution=FIXED&query_format=advanced&product=NSPR&target_milestone=4.32

(cherry picked from commit fc141011d2)
2021-12-02 01:44:15 +01:00
ajs124
3bca30968b nspr: 4.30 -> 4.31
(cherry picked from commit 4d17360d17)
2021-12-02 01:44:11 +01:00
Martin Weinelt
6323555a43 nss: 3.68 -> 3.68.1 2021-12-02 01:17:22 +01:00
ajs124
de649c32b3 nss: 3.67 -> 3.68
(cherry picked from commit 04bc2667d1)
2021-12-02 01:13:43 +01:00
ajs124
fd06c41764 nss: 3.66 -> 3.67
(cherry picked from commit 1128dadcd8)
2021-12-02 01:13:39 +01:00
Zhaofeng Li
61d25e4634 nss: Set NSS_USE_64=1 for 64-bit platforms
The config script does that automatically for a few architectures [1],
but on 64-bit platforms that are not listed (like riscv64) the
freebl build fails. Debian always adds the USE_64=1 flag when
compiling on 64-bit architectures (they use legacy make instead of gyp),
and we should do that as well to fix the general problem at the cost of
a mass rebuild.

[1] 0ef2306a62/coreconf/config.gypi (l212)
[2] c446c61808/debian/rules (L66)

(cherry picked from commit 345e777888)
2021-12-02 01:13:34 +01:00
ajs124
5b13e00735 nss: 3.64 -> 3.66
(cherry picked from commit db82e8c2e2)
2021-12-02 01:13:13 +01:00
github-actions[bot]
62834f3218 Merge staging-next-21.05 into staging-21.05 2021-12-02 00:08:55 +00:00
github-actions[bot]
3dd82a8b0f Merge release-21.05 into staging-next-21.05 2021-12-02 00:08:17 +00:00
Thiago Kenji Okada
fb8e85783e Merge pull request #147927 from NixOS/backport-147556-to-release-21.05
[Backport release-21.05] steamPackages.steam-runtime: 0.20210906.1 -> 0.20211102.0
2021-12-01 19:31:57 -03:00
Martin Schwaighofer
74bb9d68ac qemu: emit warnings when KVM acceleration is not usable
This fixes the qemu-kvm wrapper we add for convenience
silently not using KVM, when the system would support it
by at least leaving an indication in the log that the build ran
slower because it ran without KVM.

(cherry picked from commit 5718276542100f9e779f2c2113e3d0f6c45da054)
2021-12-01 19:48:18 +00:00
Martin Schwaighofer
fde29c6d73 qemu, runInLinuxVM: fix KVM availability check
KVM should only be considered abailable if /dev/kvm exists and
is read-writable by the user that is trying to launch it.

The previous check for existance only had the consequence that
on some Linux distributions running VMs with Nix's QEMU only worked
if KVM was NOT installed.

fixes #124371

(cherry picked from commit 046392279ca41abc36e61a839d4679e40f6e9a3c)
2021-12-01 19:48:18 +00:00
Thiago Kenji Okada
68b8c58a04 Merge pull request #148077 from NixOS/backport-148002-to-release-21.05
[Backport release-21.05] nextcloud21: 21.0.5 -> 21.0.7
2021-12-01 10:42:45 -03:00
Maciej Krüger
cd8bc0a089 Merge pull request #148104 from NixOS/backport-148097-to-release-21.05 2021-12-01 08:02:40 +01:00
zowoq
9127f7d848 yt-dlp: 2021.11.10.1 -> 2021.12.1
https://github.com/yt-dlp/yt-dlp/releases/tag/2021.12.01
(cherry picked from commit 5ecb046485)
2021-12-01 06:40:09 +00:00
github-actions[bot]
c62f003b8f Merge staging-next-21.05 into staging-21.05 2021-12-01 00:10:10 +00:00
github-actions[bot]
9e5a956240 Merge release-21.05 into staging-next-21.05 2021-12-01 00:09:28 +00:00
philipp
4f4a4e1866 nextcloud21: 21.0.5 -> 21.0.7
(cherry picked from commit b5a27cef4b)
2021-11-30 21:41:37 +00:00
Michele Guerini Rocco
69caefdbc6 Merge pull request #147999 from NixOS/backport-142535-to-release-21.05
[Backport release-21.05] qutebrowser: 2.3.1 -> 2.4.0
2021-11-30 11:41:53 +01:00
R. Ryantm
67ab43974a freerdp: 2.4.0 -> 2.4.1
(cherry picked from commit 700c0c5be3)
2021-11-30 11:35:50 +01:00
R. RyanTM
a2463667bf freerdp: 2.3.2 -> 2.4.0
(cherry picked from commit 9730596ace)
2021-11-30 11:35:49 +01:00
Charlotte Van Petegem
244d4c31c4 qutebrowser: 2.3.1 -> 2.4.0
(cherry picked from commit ba4c80bcec)
2021-11-30 10:08:00 +00:00
Thiago Kenji Okada
64d8080526 Merge pull request #147951 from NixOS/backport-147894-to-release-21.05
[Backport release-21.05] fira-code: 5.2 → 6
2021-11-29 21:16:19 -03:00
github-actions[bot]
b80e74ad7a Merge staging-next-21.05 into staging-21.05 2021-11-30 00:09:17 +00:00
github-actions[bot]
0c30cea066 Merge release-21.05 into staging-next-21.05 2021-11-30 00:08:21 +00:00
Fabián Heredia Montiel
52e2f05d0d fira-code: 5.2 → 6
(cherry picked from commit 4d3ed16dd8)
2021-11-29 22:53:43 +00:00
Ryan Burns
fa6e472862 Merge pull request #147940 from NixOS/backport-134485-to-release-21.05
[Backport release-21.05] uclibc: 1.0.37 -> 1.0.38
2021-11-29 14:22:23 -08:00
R. RyanTM
1d8d8376bb uclibc: 1.0.37 -> 1.0.38
(cherry picked from commit 925fc9c700)
2021-11-29 21:42:06 +00:00
Artturi
724f012f9b Merge pull request #147876 from NixOS/backport-143974-to-release-21.05 2021-11-29 22:11:25 +02:00
Martin Weinelt
7c700fb598 Merge pull request #147919 from 0x4A6F/backport-145348-to-release-21.05 2021-11-29 20:44:32 +01:00
TredwellGit
1d9e3f6bfb steamPackages.steam-runtime: 0.20210906.1 -> 0.20211102.0
(cherry picked from commit dbda557c64)
2021-11-29 19:34:41 +00:00
0x4A6F
bc3e4c972b routinator: 0.10.1 -> 0.10.2
(cherry picked from commit a5f1139b54)
2021-11-29 19:39:49 +01:00
misuzu
5b6c399f28 freeswitch: 1.10.6 -> 1.10.7
(cherry picked from commit 88f3af6d1e)
2021-11-29 14:58:27 +00:00
misuzu
69d18e78b9 libks: init at 1.7.0
(cherry picked from commit 40b22c0172)
2021-11-29 14:58:27 +00:00
misuzu
68116e534a sofia-sip: 1.13.3 -> 1.13.6
(cherry picked from commit a74bb811a1)
2021-11-29 14:58:27 +00:00
Maximilian Bosch
2553aee74f Merge pull request #147723 from helsinki-systems/bkp/21.05/php
[21.05] php74: 7.4.25 -> 7.4.26, php80: 8.0.12 -> 8.0.13
2021-11-29 15:32:24 +01:00
Martin Weinelt
db6647ab28 Merge pull request #147796 from mweinelt/21.05/mediawiki 2021-11-29 13:18:51 +01:00
Martin Weinelt
7cb5930842 mediawiki: 1.35.2 -> 1.35.4 2021-11-29 02:45:21 +01:00
github-actions[bot]
dba978622a Merge staging-next-21.05 into staging-21.05 2021-11-29 00:08:52 +00:00
github-actions[bot]
9d60caaa34 Merge release-21.05 into staging-next-21.05 2021-11-29 00:08:16 +00:00
ajs124
3d8054f526 php80Extensions.xmlreader: fix build
manual backport of cede244af9
2021-11-28 16:01:54 +01:00
ajs124
cc57af5b0a php80: 8.0.12 -> 8.0.13
Fixes CVE-2021-21707

(cherry picked from commit 6dfffc7d49)
2021-11-28 15:59:41 +01:00
ajs124
a827ecc94e php74: 7.4.25 -> 7.4.26
Fixes CVE-2021-21707

(cherry picked from commit 183cc6ea80)
2021-11-28 15:59:00 +01:00
Martin Weinelt
a284564b7f Merge pull request #142029 from risicle/ris-libressl-CVE-2021-41581-r21.05 2021-11-28 15:33:14 +01:00
github-actions[bot]
06fa5a722e Merge staging-next-21.05 into staging-21.05 2021-11-28 00:09:54 +00:00
github-actions[bot]
211069ec69 Merge release-21.05 into staging-next-21.05 2021-11-28 00:09:21 +00:00
Robert Scott
9b2fd29751 Merge pull request #139965 from risicle/ris-wolfssl-CVE-2021-38597-r21.05
[21.05] wolfssl: add patch for CVE-2021-38597
2021-11-27 18:24:29 +00:00
Benjamin Staffin
4f37689c8a org-packages 2021-09-29 (#143880)
(cherry picked from commit a9dffd937e)

Co-authored-by: AndersonTorres <torres.anderson.85@protonmail.com>
2021-11-26 19:36:35 -05:00
github-actions[bot]
c5ce6a0005 Merge staging-next-21.05 into staging-21.05 2021-11-27 00:08:51 +00:00
github-actions[bot]
35e41d8537 Merge release-21.05 into staging-next-21.05 2021-11-27 00:08:08 +00:00
Thiago Kenji Okada
3d68a238ba Merge pull request #147518 from NixOS/backport-147382-to-release-21.05
[Backport release-21.05] varnish60: 6.0.8 -> 6.0.9
2021-11-26 16:15:07 -03:00
ajs124
6885f76a15 varnish60: 6.0.8 -> 6.0.9
(cherry picked from commit 31fdf8b75e)
2021-11-26 18:46:58 +00:00
github-actions[bot]
61453d6c0e Merge staging-next-21.05 into staging-21.05 2021-11-26 00:08:38 +00:00
github-actions[bot]
edeb5b2ecf Merge release-21.05 into staging-next-21.05 2021-11-26 00:08:04 +00:00
Janne Heß
3bea86e918 Merge pull request #134956 from NixOS/backport-134829-to-release-21.05 2021-11-25 22:23:34 +01:00
Artturi
744825905c Merge pull request #142842 from NixOS/backport-118960-to-release-21.05 2021-11-25 19:19:13 +02:00
Wael Nasreddine
60be966a8a Merge pull request #147283 from NixOS/backport-147097-to-release-21.05
[Backport release-21.05] bazel_4: Fix Bazel-built protoc segfault on macOS Monterey
2021-11-25 08:51:18 -08:00
Jacek Galowicz
3a94afc813 Merge pull request #146978 from blitz/onedrive-backport
[21.05] onedrive: 2.4.11 -> 2.4.13
2021-11-25 16:58:41 +01:00
github-actions[bot]
4fe8abb3d6 Merge staging-next-21.05 into staging-21.05 2021-11-25 00:08:40 +00:00
github-actions[bot]
824556a6a0 Merge release-21.05 into staging-next-21.05 2021-11-25 00:08:05 +00:00
John Ericson
91e6a9a656 Merge pull request #147317 from NixOS/backport-145107-to-release-21.05
[Backport release-21.05] build-support/rust: Fix sysroot for cross
2021-11-24 19:04:20 -05:00
John Ericson
1345e3174f build-support/rust/sysroot/src: Use dont* instead of phase list
Making this separate commit because the original was moved out just the
way it was done before.

(cherry picked from commit 05efb8ed91)
2021-11-24 23:48:07 +00:00
John Ericson
86a9908523 Update script as rust-src layout has changed
Use stub lib so `core` and `alloc` are handled symmetrically.

(cherry picked from commit c9c3de0131)
2021-11-24 23:48:06 +00:00
John Ericson
ca6a80d8de build-support/rust: Split out sysroot src derivation
Hoping to make it usable for `buildRustCrate` too.

(cherry picked from commit cbd00bab80)
2021-11-24 23:48:06 +00:00
John Ericson
8e08c4eb11 rustcSrc: Reduce duplication
(cherry picked from commit 2c7f62379f)
2021-11-24 23:48:06 +00:00
Wael M. Nasreddine
4aef02d8a1 bazel_4: Fix Bazel-built protoc segfault on macOS Monterey
This was fixed by enabling the user_link_flags_feature for macosx cc_toolchain_config.

References:
- https://github.com/bazelbuild/bazel/issues/14216
- https://github.com/bazelbuild/bazel/pull/14275

(cherry picked from commit dc8d4f31132eece959b481e30949ba5e3308e5ea)
2021-11-24 18:59:53 +00:00
Janne Heß
71683e8f41 Merge pull request #146640 from imlonghao/borgmatic/release-21.05
[Backport release-21.05] borgmatic: 1.5.12 -> 1.5.18
2021-11-24 18:55:56 +01:00
Thiago Kenji Okada
7066ed7b1f Merge pull request #147258 from NixOS/backport-146322-to-release-21.05
[Backport release-21.05] translate-shell: added missing (runtime) dependency on hexdump
2021-11-24 11:25:56 -03:00
Kim Lindberger
43bbfd4994 Merge pull request #145677 from yayayayaka/gitlab-14.4.2-21.05
[Backport release-21.05] gitlab: 14.4.1 -> 14.4.2
2021-11-24 15:06:24 +01:00
GOKOP
d3374d3f7d translate-shell: fixed indentation in default.nix
(cherry picked from commit 907ac61491)
2021-11-24 13:50:30 +00:00
GOKOP
5360dfffed translate-shell: added missing dependency on hexdump
(cherry picked from commit 9e2669e4cd)
2021-11-24 13:50:30 +00:00
github-actions[bot]
36e2bc18b9 Merge staging-next-21.05 into staging-21.05 2021-11-24 00:08:48 +00:00
github-actions[bot]
e48d3592cc Merge release-21.05 into staging-next-21.05 2021-11-24 00:08:06 +00:00
Thiago Kenji Okada
9c43581935 Merge pull request #147137 from Ma27/backport-kernels
[21.05] Kernel backports
2021-11-23 20:24:14 -03:00
Rick van Schijndel
a373ae0c34 astroid: 2.5.1 -> 2.5.3
This does not update to the latest version from the 2.5.x range,
since the build fails with that. It appears to be trying to access
an url, which is not allowed in the sandbox.

Since this is just a drive-by, I think this is better than keeping
all those packages broken on hydra, since the build is broken with 2.5.1
2021-11-23 11:00:42 -08:00
Vladimír Čunát
ea6fd78029 Merge #146652: thunderbird: 91.3.0 -> 91.3.1 (into release-21.05) 2021-11-23 18:51:28 +01:00
eyjhb
f4c83273a0 matrix-synapse: 1.47.0 -> 1.47.1
(cherry picked from commit 1cc5df0346)
2021-11-23 14:26:09 +01:00
Emil Karlson
d40e3139cb linux: do not build in DRM_SIMPLEDRM on newer kernels
After linux 5.14.11 FB_SIMPLE conflicts with DRM_SIMPLEDRM, which
will fail configuration, when DRM_SIMPLEDRM is configured as a module
and FB_SIMPLE gets requested as builtin.

Do not enable DRM_SIMPLEDRM as a temporary workaround, until good
enough migration path is found.

(cherry picked from commit 2ef28fb77d)
2021-11-23 12:38:35 +01:00
TredwellGit
11972fcdec linux_latest-libre: 18473 -> 18484
(cherry picked from commit 541a3a7332)
2021-11-23 12:35:43 +01:00
TredwellGit
c0f8e6efd6 linux: 5.4.160 -> 5.4.161
(cherry picked from commit 392ccc5431)
2021-11-23 12:35:42 +01:00
TredwellGit
bca8f95cd1 linux: 5.15.3 -> 5.15.4
(cherry picked from commit d789aebb56)
2021-11-23 12:35:41 +01:00
TredwellGit
16ac988929 linux: 5.14.20 -> 5.14.21
(cherry picked from commit df8b7f5d06)
2021-11-23 12:35:40 +01:00
TredwellGit
98d510a593 linux: 5.10.80 -> 5.10.81
(cherry picked from commit 06629bb117)
2021-11-23 12:35:40 +01:00
github-actions[bot]
02efcfc42a Merge staging-next-21.05 into staging-21.05 2021-11-23 00:09:00 +00:00
github-actions[bot]
b497e66240 Merge release-21.05 into staging-next-21.05 2021-11-23 00:08:15 +00:00
Artturi
09650059d7 Merge pull request #141644 from NixOS/backport-141572-to-release-21.05 2021-11-22 23:09:39 +02:00
Artturi
383bd9f76d Merge pull request #145517 from NixOS/backport-145086-to-release-21.05 2021-11-22 21:56:46 +02:00
Artturi
4df8a92912 Merge pull request #130505 from NixOS/backport-130439-to-release-21.05 2021-11-22 21:50:00 +02:00
Artturi
8f0f92fa64 Merge pull request #135930 from NixOS/backport-135922-to-release-21.05 2021-11-22 21:45:37 +02:00
Artturi
83294d4f68 Merge pull request #142237 from NixOS/backport-126874-to-release-21.05 2021-11-22 21:45:19 +02:00
Artturi
2b1408999f Merge pull request #142378 from NixOS/backport-139932-to-release-21.05 2021-11-22 21:44:21 +02:00
Artturi
707122a9f0 Merge pull request #143052 from NixOS/backport-142789-to-release-21.05 2021-11-22 21:42:29 +02:00
Maximilian Bosch
df7ea2a906 Merge pull request #146821 from Ma27/backport-kernels
[21.05] Kernel backports
2021-11-22 20:39:35 +01:00
Artturi
4d287a5b35 Merge pull request #142738 from NixOS/backport-133067-to-release-21.05 2021-11-22 21:37:45 +02:00
Artturi
80569bb00f Merge pull request #135287 from NixOS/backport-135260-to-release-21.05 2021-11-22 21:34:48 +02:00
Artturi
b046fa3df6 Merge pull request #128162 from NixOS/backport-128048-to-release-21.05 2021-11-22 21:32:09 +02:00
github-actions[bot]
56f2fc5f9f nixos/grafana: Change services.grafana.provision.datasources.*.type to be open (#127064
Co-authored-by: Erik Skytthe <ers@dbc.dk>
2021-11-22 21:28:18 +02:00
Artturi
a63a35be35 Merge pull request #133814 from NixOS/backport-133806-to-release-21.05 2021-11-22 21:26:03 +02:00
Artturi
0f72bd5486 Merge pull request #138620 from NixOS/backport-138445-to-release-21.05 2021-11-22 21:25:16 +02:00
Artturi
34133d4f5b Merge pull request #133525 from NixOS/backport-133405-to-release-21.05 2021-11-22 21:24:43 +02:00
Artturi
5097c8b9c9 Merge pull request #141686 from NixOS/backport-141674-to-release-21.05 2021-11-22 21:23:37 +02:00
Artturi
5c5528cb4a Merge pull request #142045 from NixOS/backport-137147-to-release-21.05 2021-11-22 21:23:21 +02:00
Artturi
f527c0bd3f Merge pull request #139527 from NixOS/backport-139456-to-release-21.05 2021-11-22 21:18:13 +02:00
Artturi
39f25492f8 Merge pull request #146380 from NixOS/backport-146268-to-release-21.05 2021-11-22 21:16:45 +02:00
Artturi
1a9e153dca Merge pull request #144245 from NixOS/backport-143252-to-release-21.05 2021-11-22 21:16:17 +02:00
Artturi
b2d4706ebb Merge pull request #145562 from NixOS/backport-145524-to-release-21.05 2021-11-22 21:13:24 +02:00
Artturi
2208d557c2 Merge pull request #136068 from NixOS/backport-135891-to-release-21.05 2021-11-22 21:00:22 +02:00
Artturi
9086e06141 Merge pull request #141282 from NixOS/backport-141276-to-release-21.05 2021-11-22 20:56:40 +02:00
Artturi
1f157d7773 Merge pull request #137570 from NixOS/backport-137562-to-release-21.05 2021-11-22 20:44:15 +02:00
Artturi
7f84838a56 Merge pull request #136554 from NixOS/backport-134460-to-release-21.05 2021-11-22 20:43:10 +02:00
Artturi
e2d9c5539f Merge pull request #139872 from NixOS/backport-138860-to-release-21.05 2021-11-22 20:42:21 +02:00
Michael Fellinger
b573241ac4 stage2: use atomic bind mounts
(cherry picked from commit e629023c0742f2726e1b2bb52d3c04fc28f7c00c)
2021-11-22 10:41:41 -08:00
Artturi
02f6d1e162 Merge pull request #145829 from NixOS/backport-123489-to-release-21.05 2021-11-22 20:32:54 +02:00
Artturi
b6dbf8aec5 Merge pull request #146687 from NixOS/backport-145754-to-release-21.05 2021-11-22 20:25:35 +02:00
Martin Weinelt
25166e68be Merge pull request #146942 from mweinelt/21.05/firefox 2021-11-22 17:02:21 +01:00
R. RyanTM
a3229309dc onedrive: 2.4.12 -> 2.4.13
(cherry picked from commit daae03bb4f)
2021-11-22 10:20:38 +01:00
Peter Hoeg
94b1638066 onedrive: 2.4.11 -> 2.4.12
(cherry picked from commit 4489d3e844)
2021-11-22 10:20:32 +01:00
Artturi
02ee434b10 Merge pull request #146962 from NixOS/backport-138231-to-release-21.05 2021-11-22 06:04:21 +02:00
Ryan Burns
77c452b132 cudatoolkit: fix build
This is a workaround for a segfault in patchelf
when attempting to set an empty rpath

(cherry picked from commit 810e595e4e)
2021-11-22 03:31:34 +00:00
github-actions[bot]
e4b9e308f3 Merge staging-next-21.05 into staging-21.05 2021-11-22 00:08:48 +00:00
github-actions[bot]
fd9083e7e7 Merge release-21.05 into staging-next-21.05 2021-11-22 00:08:12 +00:00
taku0
6ab6ca780a firefox-bin: 94.0 -> 94.0.2
(cherry picked from commit b7b835e59c)
2021-11-22 00:15:27 +01:00
taku0
65c4e26cb4 firefox: 94.0.1 -> 94.0.2
(cherry picked from commit 35f3429e98)
2021-11-22 00:13:35 +01:00
oxalica
4bfa6c0bee firefox: add a patch fixing deadlock
(cherry picked from commit 2774c726b4)
2021-11-22 00:13:35 +01:00
Martin Weinelt
85fe098949 firefox: 94.0 -> 94.0.1
(cherry picked from commit 8f499b97ad)
2021-11-22 00:11:54 +01:00
Thiago Kenji Okada
d5c4e868ce Merge pull request #146866 from NixOS/backport-145955-to-release-21.05
[Backport release-21.05] bsdiff: security and bug fixes
2021-11-21 09:31:11 -03:00
alyaeanyx
ca026c598c bsdiff: disable bugfix patches for darwin
(cherry picked from commit 4d57666646)
2021-11-21 12:16:10 +00:00
alyaeanyx
5af994f4f3 bsdiff: fix patch
(cherry picked from commit 200ffaa072)
2021-11-21 12:16:09 +00:00
alyaeanyx
20a73840e2 bsdiff: add patch to default.nix
(cherry picked from commit 47a9d5e419)
2021-11-21 12:16:08 +00:00
alyaeanyx
b59ca81400 bsdiff: fix patch file for aarch64-linux
(cherry picked from commit 842a855325)
2021-11-21 12:16:07 +00:00
alyaeanyx
8158855f67 bspatch: security and bug fixes
(cherry picked from commit 84245c843f)
2021-11-21 12:16:05 +00:00
github-actions[bot]
dfa808522d Merge staging-next-21.05 into staging-21.05 2021-11-21 00:09:02 +00:00
github-actions[bot]
8cbc37247f Merge release-21.05 into staging-next-21.05 2021-11-21 00:08:29 +00:00
Vladimír Čunát
d5b65f812c Merge branch 'staging-next-21.05' into release-21.05 2021-11-20 23:43:01 +01:00
Maximilian Bosch
2c441a5b8c Merge pull request #146482 from NixOS/backport-146448-to-release-21.05
[Backport release-21.05] nextcloud22: 22.2.2 -> 22.2.3
2021-11-20 23:21:45 +01:00
TredwellGit
85ae7afa83 linux/hardened/patches/5.4: 5.4.159-hardened1 -> 5.4.160-hardened1
(cherry picked from commit 170255c3a3)
2021-11-20 23:19:29 +01:00
TredwellGit
72149d8ee1 linux/hardened/patches/5.15: 5.15.2-hardened1 -> 5.15.3-hardened1
(cherry picked from commit 6383327644)
2021-11-20 23:19:28 +01:00
TredwellGit
884cda3ad9 linux/hardened/patches/5.14: 5.14.18-hardened1 -> 5.14.20-hardened1
(cherry picked from commit cc0a75815d)
2021-11-20 23:19:27 +01:00
TredwellGit
cafba1ae18 linux/hardened/patches/5.10: 5.10.78-hardened1 -> 5.10.80-hardened1
(cherry picked from commit 51bd34b742)
2021-11-20 23:19:26 +01:00
TredwellGit
5e78718283 linux_latest-libre: 18452 -> 18473
(cherry picked from commit c871adc77c)
2021-11-20 23:19:25 +01:00
TredwellGit
fdb4ba60ac linux: 5.4.159 -> 5.4.160
(cherry picked from commit 83c1df7574)
2021-11-20 23:19:24 +01:00
TredwellGit
00e5379a66 linux: 5.15.2 -> 5.15.3
(cherry picked from commit be5a54e952)
2021-11-20 23:19:24 +01:00
TredwellGit
3c0fada90f linux: 5.14.18 -> 5.14.20
(cherry picked from commit 654052abbb)
2021-11-20 23:19:23 +01:00
TredwellGit
6b8631f847 linux: 5.10.79 -> 5.10.80
(cherry picked from commit 8cf6618d0c)
2021-11-20 23:19:22 +01:00
TredwellGit
136d57942a linux/hardened/patches/5.15: init at 5.15.2-hardened1
(cherry picked from commit c783c8d859)
2021-11-20 23:16:45 +01:00
TredwellGit
47e533ba42 linux/hardened/patches/5.4: 5.4.158-hardened1 -> 5.4.159-hardened1
(cherry picked from commit db13d848fc)
2021-11-20 23:15:00 +01:00
TredwellGit
97be57b39e linux/hardened/patches/5.14: 5.14.17-hardened1 -> 5.14.18-hardened1
(cherry picked from commit b868e78282)
2021-11-20 23:14:59 +01:00
TredwellGit
b821e2a98f linux/hardened/patches/4.19: 4.19.216-hardened1 -> 4.19.217-hardened1
(cherry picked from commit 57d9fd1791)
2021-11-20 23:14:58 +01:00
TredwellGit
1382dc825c linux/hardened/patches/4.14: 4.14.254-hardened1 -> 4.14.255-hardened1
(cherry picked from commit 9b6fb581af)
2021-11-20 23:14:57 +01:00
TredwellGit
bb3c35d7e9 linux-rt_5_10: 5.10.73-rt54 -> 5.10.78-rt55
(cherry picked from commit 38d1f15fe4)
2021-11-20 23:14:36 +01:00
github-actions[bot]
d89b38817a Merge staging-next-21.05 into staging-21.05 2021-11-20 00:08:18 +00:00
github-actions[bot]
bc6a962b3b Merge release-21.05 into staging-next-21.05 2021-11-20 00:07:16 +00:00
Michael Weiss
7e653e0217 Merge pull request #146684 from NixOS/backport-146433-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 95.0.4638.69 -> 96.0.4664.45
2021-11-19 23:04:26 +01:00
Eduard Bachmakov
7b4da337c0 marktext: 0.16.2 -> 0.16.3
Add .desktop file, icons in the process.

(cherry picked from commit 40e650fa3d)
2021-11-19 21:58:43 +00:00
Michael Weiss
82efe0e18b ungoogled-chromium: 95.0.4638.69 -> 96.0.4664.45
(cherry picked from commit 4e77c7efc6)
2021-11-19 21:44:44 +00:00
Michael Weiss
09d2a9e9cc Merge pull request #146679 from NixOS/backport-146184-to-release-21.05
[Backport release-21.05] chromium: 95.0.4638.69 -> 96.0.4664.45
2021-11-19 22:39:59 +01:00
Michael Weiss
1deff92615 chromium: 95.0.4638.69 -> 96.0.4664.45
https://chromereleases.googleblog.com/2021/11/stable-channel-update-for-desktop.html

This update includes 25 security fixes.

CVEs:
CVE-2021-38007 CVE-2021-38008 CVE-2021-38009 CVE-2021-38006
CVE-2021-38005 CVE-2021-38010 CVE-2021-38011 CVE-2021-38012
CVE-2021-38013 CVE-2021-38014 CVE-2021-38015 CVE-2021-38016
CVE-2021-38017 CVE-2021-38018 CVE-2021-38019 CVE-2021-38020
CVE-2021-38021 CVE-2021-38022

(cherry picked from commit a39908a7cb)
2021-11-19 21:26:40 +00:00
Michael Weiss
64f362d93d Merge pull request #146676 from primeos/chromium-backport
[21.05] Chromium backport (prepare for M96)
2021-11-19 22:21:26 +01:00
Michael Weiss
343f425ffe chromiumDev: 97.0.4692.8 -> 97.0.4692.20
(cherry picked from commit f5e6bb8c75)
2021-11-19 22:02:59 +01:00
Michael Weiss
617926a51d chromiumBeta: 96.0.4664.35 -> 96.0.4664.45
(cherry picked from commit 177ab8af28)
2021-11-19 22:02:56 +01:00
Michael Weiss
0121829245 chromiumDev: 97.0.4688.2 -> 97.0.4692.8
(cherry picked from commit c4e467e4c8)
2021-11-19 22:02:54 +01:00
Michael Weiss
c511054da1 chromiumDev: 97.0.4682.3 -> 97.0.4688.2
(cherry picked from commit 00460bd6e2)
2021-11-19 22:02:52 +01:00
Michael Weiss
20ae529015 chromiumBeta: 96.0.4664.27 -> 96.0.4664.35
(cherry picked from commit 41dbc0a995)
2021-11-19 22:02:50 +01:00
Michael Weiss
fe74de7185 nixos/tests/chromium: Add a workaround to fix the test for M96+
Some upstream changes broke the automatic fallback to SwiftShader.
Without this workaround the GPU initialization fails (apparently due to requiring Vulkan):
machine # libva error: vaGetDriverNameByIndex() failed with unknown libva error, driver_name = (null)
machine # [1001:1001:1101/104304.000625:ERROR:viz_main_impl.cc(161)] Exiting GPU process due to errors during initialization
machine # libva error: vaGetDriverNameByIndex() failed with unknown libva error, driver_name = (null)
machine # [1052:1052:1101/104305.060496:ERROR:viz_main_impl.cc(161)] Exiting GPU process due to errors during initialization
machine # [1084:1084:1101/104305.165898:ERROR:angle_platform_impl.cc(44)] Display.cpp:894 (initialize): ANGLE Display::initialize error 0: Internal Vulkan error (-3): Initialization of an object could not be completed for implementation-specific reasons, in ../../third_party/angle/src/libANGLE/renderer/vulkan/RendererVk.cpp, initialize:1048.
machine # [1084:1084:1101/104305.171191:ERROR:gl_surface_egl.cc(782)] EGL Driver message (Critical) eglInitialize: Internal Vulkan error (-3): Initialization of an object could not be completed for implementation-specific reasons, in ../../third_party/angle/src/libANGLE/renderer/vulkan/RendererVk.cpp, initialize:1048.
machine # [1084:1084:1101/104305.178707:ERROR:gl_surface_egl.cc(1382)] eglInitialize SwANGLE failed with error EGL_NOT_INITIALIZED
machine # [1084:1084:1101/104305.180111:ERROR:gl_ozone_egl.cc(20)] GLSurfaceEGL::InitializeOneOff failed.
machine # [1084:1084:1101/104305.189760:ERROR:viz_main_impl.cc(161)] Exiting GPU process due to errors during initialization
machine # [1092:1092:1101/104305.233470:ERROR:gpu_init.cc(457)] Passthrough is not supported, GL is disabled, ANGLE is

This workaround restores the previous result:
machine # [1004:1004:1101/104551.131190:ERROR:gpu_init.cc(457)] Passthrough is not supported, GL is swiftshader, ANGLE is

The workaround is only required for Chromium, not Google Chrome.

(cherry picked from commit a188a74486)
2021-11-19 22:02:48 +01:00
Michael Weiss
e347dd73a7 chromiumDev: 97.0.4676.0 -> 97.0.4682.3
(cherry picked from commit b497744a24)
2021-11-19 22:02:47 +01:00
Michael Weiss
9ab3c8fca2 chromiumBeta: 96.0.4664.18 -> 96.0.4664.27
(cherry picked from commit 362f6990a6)
2021-11-19 22:02:45 +01:00
Michael Weiss
1bfe347351 chromiumDev: 96.0.4664.18 -> 97.0.4676.0
(cherry picked from commit 471e147fd0)
2021-11-19 22:02:43 +01:00
Michael Weiss
14d34e9700 chromiumBeta: 95.0.4638.54 -> 96.0.4664.18
(cherry picked from commit 889f0df41b)
2021-11-19 22:02:41 +01:00
Michael Weiss
bbb61d24fa chromiumDev: 96.0.4664.9 -> 96.0.4664.18
(cherry picked from commit cb5742f0f7)
2021-11-19 22:02:39 +01:00
Vladimír Čunát
9af4b5dddd thunderbird-unwrapped: 91.3.0 -> 91.3.1
(cherry-picked from commit 1b7f9b01fb / PR #146143)
2021-11-19 19:02:36 +01:00
imlonghao
cb96cea42d borgmatic: 1.5.12 -> 1.5.18 2021-11-19 23:13:05 +08:00
Bobby Rong
80153940cc Merge pull request #146595 from NixOS/backport-146563-to-release-21.05
[Backport release-21.05] vscode: 1.62.2 -> 1.62.3
2021-11-19 22:29:10 +08:00
Patrick Hilhorst
18f6302f7d Merge pull request #146624 from NixOS/backport-146617-to-release-21.05 2021-11-19 14:22:12 +01:00
nixpkgs-upkeep-bot
c4fd2fb714 vscodium: 1.62.2 -> 1.62.3
(cherry picked from commit 02b7827778)
2021-11-19 13:00:13 +00:00
Pavol Rusnak
24528474d2 Merge pull request #146453 from prusnak/electron-21.05
electron_12: 12.2.2 -> 12.2.3
2021-11-19 11:04:27 +01:00
nixpkgs-upkeep-bot
e2e500adbd vscode: 1.62.2 -> 1.62.3
(cherry picked from commit 669740ba93)
2021-11-19 08:55:51 +00:00
Maximilian Bosch
e64f4352e5 nextcloud22: 22.2.2 -> 22.2.3
ChangeLog: https://nextcloud.com/changelog/#22-2-3
(cherry picked from commit 0196fd79b7)
2021-11-18 13:13:26 +00:00
TredwellGit
f99821ba62 electron_12: 12.2.2 -> 12.2.3
https://github.com/electron/electron/releases/tag/v12.2.3
(cherry picked from commit c96842ed01)
2021-11-18 01:38:31 +01:00
github-actions[bot]
5f9eeee755 Merge staging-next-21.05 into staging-21.05 2021-11-18 00:10:34 +00:00
github-actions[bot]
92d4a74ae1 Merge release-21.05 into staging-next-21.05 2021-11-18 00:09:31 +00:00
Janne Heß
2e4a1ac9c7 Merge pull request #145847 from taku0/thunderbird-bin-91.3.0_release-21.05
[21.05] thunderbird, thunderbird-bin: 91.2.1 -> 91.3.0 [High security updates]
2021-11-17 12:22:04 +01:00
ajs124
2cd5acb919 nixos/nginx: fix SystemCallFilter after 1fc113f0df
(cherry picked from commit c408cd921f)
2021-11-17 11:07:17 +00:00
ajs124
243cc81e5c nginxStable: 1.20.1 -> 1.20.2
(cherry picked from commit 1fc113f0df)
2021-11-17 11:07:16 +00:00
github-actions[bot]
6404e3b13c Merge staging-next-21.05 into staging-21.05 2021-11-17 00:08:38 +00:00
github-actions[bot]
677d5a56be Merge release-21.05 into staging-next-21.05 2021-11-17 00:08:01 +00:00
Maximilian Bosch
63ea979ddb Merge pull request #144090 from erictapen/21.05/imagemagick-7.1.0-13
[21.05] imagemagick: 7.1.0-9 -> 7.1.0-13
2021-11-16 20:53:45 +01:00
Michael Francis
f79bafde9c Update openvswitch.nix
(cherry picked from commit 80830373f0)
2021-11-16 17:13:43 +01:00
Kim Lindberger
80b68be3b4 Merge pull request #146181 from talyz/qt512-big-sur-fix-staging-21.05
qt512: Make apps work on macOS Big Sur
2021-11-16 14:19:45 +01:00
Mario Rodas
01eaa66bb6 Merge pull request #146207 from NixOS/backport-145913-to-release-21.05
[Backport release-21.05] libmysofa: 1.2.0 -> 1.2.1
2021-11-15 23:15:56 -05:00
Thomas Gerbet
871e826301 libmysofa: 1.2.0 -> 1.2.1
Fixes CVE-2021-3756.
https://huntr.dev/bounties/7ca8d9ea-e2a6-4294-af28-70260bb53bc1/

(cherry picked from commit 936b628018)
2021-11-16 03:03:31 +00:00
github-actions[bot]
4c7dbfe744 Merge staging-next-21.05 into staging-21.05 2021-11-16 00:08:44 +00:00
github-actions[bot]
b41fad0fab Merge release-21.05 into staging-next-21.05 2021-11-16 00:08:07 +00:00
Janne Heß
c83297105d Merge pull request #146176 from NixOS/backport-146106-to-release-21.05 2021-11-15 23:12:26 +01:00
TredwellGit
91443a960a steam: 1.0.0.72 -> 1.0.0.73
(cherry picked from commit e682fd7c83)
2021-11-15 20:02:40 +00:00
talyz
3582493242 qt512: Make apps work on macOS Big Sur
Make Qt applications work on macOS Big Sur even if they're built with
an older version of the macOS SDK (<10.14 - we're currently using
10.12). This issue is fixed in 5.12.11, but it requires macOS SDK
10.13 to build. See https://bugreports.qt.io/browse/QTBUG-87014 for
more info.

(cherry picked from commit 39ce18a7ec)
2021-11-15 21:00:09 +01:00
linj
01cf9b60d1 linux: enable TCP_CONG_ADVANCED
TCP_CONG_ADVANCED is enabled by default on x86_64[1] in the upstream.
Although it is not the case for aarch64[2], many distributions, such as
Debian[3], Fedora[4] and Gentoo[5], choose to enable it in their
distribution kernel.

With this patch, aarch64 users can choose many other TCP congestion
algorithms, which may improve their network performance.

[1]: 7ddb58cb0e/arch/x86/configs/x86_64_defconfig (L71)
[2]: 7ddb58cb0e/arch/arm64/configs/defconfig
[3]: e2d14375d7/debian/config/config (L7063)
[4]: 836165dd2d/f/kernel-aarch64-fedora.config
[5]: 5808eb2f06/sys-kernel/gentoo-kernel/gentoo-kernel-5.10.77.ebuild (L27)

(cherry picked from commit 555aa76120)
2021-11-15 10:03:03 -08:00
taku0
0a8bc59854 wrapFirefox: fix icon linking for Thunderbird
Firefox has its icons in
`/lib/firefox-bin-*/browser/chrome/icons/default` while Thunderbird has
`/lib/thunderbird/chrome/icons/default`.

Fixes https://github.com/NixOS/nixpkgs/pull/143942#issuecomment-963418080.

(cherry picked from commit 881d3fae72)
2021-11-15 18:28:26 +01:00
Artturi
32954394c6 Merge pull request #139975 from sersorrel/backport-wrapappimage 2021-11-15 18:13:03 +02:00
Robert Hensing
3766a8f7f4 Merge pull request #145806 from Atemu/nix_2_3-alias
[21.05] nix: add nix_2_3 alias
2021-11-15 15:15:27 +01:00
Mario Rodas
46251a79f7 Merge pull request #145917 from NixOS/backport-145880-to-release-21.05
[Backport release-21.05] hiredis: 1.0.0 -> 1.0.2
2021-11-14 21:40:46 -05:00
github-actions[bot]
6e8c86a6ea Merge staging-next-21.05 into staging-21.05 2021-11-15 00:08:39 +00:00
github-actions[bot]
901f9b3f1b Merge release-21.05 into staging-next-21.05 2021-11-15 00:08:04 +00:00
Thomas Gerbet
638d5005bd hiredis: 1.0.0 -> 1.0.2
Fixes CVE-2021-32765.
https://github.com/redis/hiredis/security/advisories/GHSA-hfm9-39pp-55p2

(cherry picked from commit a1ab38dfc5)
2021-11-14 11:55:38 +00:00
taku0
90e4bdc38e thunderbird-bin: 91.2.1 -> 91.3.0
(cherry picked from commit 06708435d1)
2021-11-14 13:04:43 +09:00
taku0
74071e382d thunderbird: 91.2.1 -> 91.3.0 2021-11-14 13:04:38 +09:00
Arthur Gautier
195d5816cd isl: isl.gforge.inria.fr has been taken offline
https://issues.guix.gnu.org/42162
https://github.com/dockcross/dockcross/issues/606
https://groups.google.com/g/isl-development/c/JGaMo2VUu_8
https://giters.com/coq/opam-coq-archive/issues/1298?amp=1

Signed-off-by: Arthur Gautier <baloo@superbaloo.net>
(cherry picked from commit 53a60ad361)
2021-11-13 21:00:48 -05:00
Robert Schütz
e57b0e6c0c dvd-slideshow: use ffmpeg instead of ffmpeg_3
(cherry picked from commit 0e527631be)
2021-11-14 00:48:00 +00:00
github-actions[bot]
1eaca20668 Merge staging-next-21.05 into staging-21.05 2021-11-14 00:08:48 +00:00
github-actions[bot]
3c184115a8 Merge release-21.05 into staging-next-21.05 2021-11-14 00:08:13 +00:00
Thiago Kenji Okada
7378d0cc45 Merge pull request #145515 from NixOS/backport-142884-to-release-21.05
[Backport release-21.05] vista-fonts: install cambria.ttc as well
2021-11-13 20:34:53 -03:00
Martin Weinelt
396fa4d9ad Merge pull request #145499 from risicle/ris-distributed-CVE-2021-42343-r21.05 2021-11-13 23:56:33 +01:00
Atemu
864219a45f nix: add nix_2_3 alias
This is necessary for sanely referencing nix 2.3 in both stable and unstable
2021-11-13 23:21:03 +01:00
Martin Weinelt
bda6235509 Merge pull request #145749 from Ma27/roundcube-security 2021-11-13 22:46:26 +01:00
Martin Weinelt
b29b7c619c Merge pull request #145784 from mohe2015/update-wordpress-5.7.4 2021-11-13 21:56:37 +01:00
Moritz Hedtke
16d58f0368 wordpress: 5.7.3 -> 5.7.4 2021-11-13 20:59:15 +01:00
Maximilian Bosch
c0d77bdc81 Merge pull request #145755 from NixOS/backport-145671-to-release-21.05
[Backport release-21.05] Kernels 2021-11-12
2021-11-13 15:38:22 +01:00
Maximilian Bosch
e99c97b281 Merge pull request #145624 from NixOS/backport-145560-to-release-21.05
[Backport release-21.05] nextcloud22: 22.2.0 -> 22.2.2
2021-11-13 14:59:38 +01:00
TredwellGit
03a679ce37 linux/hardened/patches/5.4: 5.4.157-hardened1 -> 5.4.158-hardened1
(cherry picked from commit 5bb24d504b)
2021-11-13 13:55:26 +00:00
TredwellGit
c5fe1d027e linux/hardened/patches/5.14: 5.14.16-hardened1 -> 5.14.17-hardened1
(cherry picked from commit dd5de73eba)
2021-11-13 13:55:25 +00:00
TredwellGit
7afedc89a3 linux/hardened/patches/5.10: 5.10.77-hardened1 -> 5.10.78-hardened1
(cherry picked from commit 3b035cff60)
2021-11-13 13:55:24 +00:00
TredwellGit
fea13d45e6 linux/hardened/patches/4.19: 4.19.215-hardened1 -> 4.19.216-hardened1
(cherry picked from commit b5353b2905)
2021-11-13 13:55:23 +00:00
TredwellGit
824262590c linux: 5.4.158 -> 5.4.159
(cherry picked from commit c6d6891185)
2021-11-13 13:55:22 +00:00
TredwellGit
016a93649a linux: 5.15.1 -> 5.15.2
(cherry picked from commit e5d1ac060f)
2021-11-13 13:55:21 +00:00
TredwellGit
542de6654e linux: 5.14.17 -> 5.14.18
(cherry picked from commit 43ebf91176)
2021-11-13 13:55:20 +00:00
TredwellGit
9a4ff725fe linux: 5.10.78 -> 5.10.79
(cherry picked from commit 6caad489e2)
2021-11-13 13:55:19 +00:00
TredwellGit
7373fea7b1 linux: 4.9.289 -> 4.9.290
(cherry picked from commit e2e9427873)
2021-11-13 13:55:18 +00:00
TredwellGit
3995616719 linux: 4.4.291 -> 4.4.292
(cherry picked from commit cf1d695ba6)
2021-11-13 13:55:17 +00:00
TredwellGit
af955bb666 linux: 4.19.216 -> 4.19.217
(cherry picked from commit c3bbc214cd)
2021-11-13 13:55:16 +00:00
TredwellGit
cbcb8e6676 linux: 4.14.254 -> 4.14.255
(cherry picked from commit d35645f077)
2021-11-13 13:55:15 +00:00
Maximilian Bosch
61c309686c Merge pull request #145551 from Ma27/backport-linux-5.15.1
[21.05] linux: 5.15 -> 5.15.1
2021-11-13 14:51:14 +01:00
Robbert Gurdeep Singh
c1e3c2783b nextcloud22: 22.2.1 -> 22.2.2
This includes a fix for a preformance regression:
https://github.com/nextcloud/server/pull/29682

(cherry picked from commit 95ca86f925)
2021-11-13 14:15:34 +01:00
Maximilian Bosch
fcf46ce73d roundcube: 1.4.11 -> 1.4.12
ChangeLog: https://github.com/roundcube/roundcubemail/releases/tag/1.4.12

This fixes a XSS[1] and a SQL-injection[2] vulnerability. Both are
already fixed on 1.5.0 which is available on `nixos-unstable`[3].

[1] https://github.com/roundcube/roundcubemail/pull/8193
[2] 4e1358b4dc
[3] https://nixpk.gs/pr-tracker.html?pr=142148
2021-11-13 13:52:19 +01:00
Vladimír Čunát
68d4f5970b Merge #145719: linux_5_15: drop option removed upstream 2021-11-13 09:27:13 +01:00
Vladimír Čunát
aac09a28d6 linux_5_15: drop option removed upstream
On nixpkgs master this was done in commit 146c830cff.
2021-11-13 09:02:19 +01:00
Bobby Rong
df696225f7 Merge pull request #145611 from NixOS/backport-145568-to-release-21.05
[Backport release-21.05] vscode: 1.62.1 -> 1.62.2
2021-11-13 11:23:20 +08:00
github-actions[bot]
57150a7a99 Merge staging-next-21.05 into staging-21.05 2021-11-13 00:08:35 +00:00
github-actions[bot]
a76d5118ad Merge release-21.05 into staging-next-21.05 2021-11-13 00:07:56 +00:00
Thiago Kenji Okada
103597bd08 Merge pull request #145572 from NixOS/backport-145569-to-release-21.05
[Backport release-21.05] ferdi: 5.6.2 -> 5.6.3
2021-11-12 20:11:16 -03:00
Lara
e0c811d224 [Backport release-21.05] gitlab: 14.4.1 -> 14.4.2 2021-11-12 20:27:24 +00:00
Patrick Hilhorst
1adf5530ae Merge pull request #145635 from NixOS/backport-145621-to-release-21.05 2021-11-12 19:01:41 +01:00
nixpkgs-upkeep-bot
9639b9cb92 vscodium: 1.62.1 -> 1.62.2
(cherry picked from commit 5f0b60a463)
2021-11-12 15:29:54 +00:00
Maximilian Bosch
7e759d3840 nextcloud22: 22.2.0 -> 22.2.1
ChangeLog: https://nextcloud.com/changelog/#22-2-1
(cherry picked from commit 2c00db1ead)
2021-11-12 12:14:43 +00:00
Maximilian Bosch
456726cf61 Merge pull request #143224 from NixOS/backport-143195-to-release-21.05
[Backport release-21.05] firmwareLinuxNonfree: 2021-09-19 -> 20211027
2021-11-12 11:48:33 +01:00
nixpkgs-upkeep-bot
aa2de1909b vscode: 1.62.1 -> 1.62.2
(cherry picked from commit fda6439cea)
2021-11-12 10:41:00 +00:00
Bobby Rong
fdd594aef4 Merge pull request #145366 from NixOS/backport-145350-to-release-21.05
[Backport release-21.05] vscodium: 1.62.0 -> 1.62.1
2021-11-12 09:43:30 +08:00
Bobby Rong
def7131489 Merge pull request #145361 from NixOS/backport-145290-to-release-21.05
[Backport release-21.05] vscode: 1.62.0 -> 1.62.1
2021-11-12 09:33:58 +08:00
Maximilian Bosch
69745bf117 ferdi: 5.6.2 -> 5.6.3
ChangeLog: https://github.com/getferdi/ferdi/releases/tag/v5.6.3
(cherry picked from commit ed55160728)
2021-11-12 01:04:48 +00:00
Maximilian Bosch
f94790f788 Merge pull request #144944 from NixOS/backport-144871-to-release-21.05
[Backport release-21.05] vagrant: 2.2.18 -> 2.2.19
2021-11-12 01:31:34 +01:00
github-actions[bot]
3f2d715a77 Merge staging-next-21.05 into staging-21.05 2021-11-12 00:08:39 +00:00
github-actions[bot]
112086b305 Merge release-21.05 into staging-next-21.05 2021-11-12 00:07:58 +00:00
Jan Solanti
a3e70a49b4 pipewire-media-session: 0.4.0 -> 0.4.1
(cherry picked from commit 3119604c2d)
2021-11-11 23:24:59 +00:00
Jan Solanti
0106bb4703 pipewire: 0.3.39 -> 0.3.40
(cherry picked from commit c1a493bdcd)
2021-11-11 23:24:58 +00:00
Maximilian Bosch
980395c962 linux: apply fix for 5.15
From 146c830cff
2021-11-11 23:02:56 +01:00
TredwellGit
ca1e25a2b2 linux: 5.15 -> 5.15.1
(cherry picked from commit 235c88c094)
2021-11-11 22:34:17 +01:00
Maximilian Bosch
a841ca6bc9 Merge pull request #144361 from xaverdh/linux-5.15-backport
Linux 5.15 backport
2021-11-11 22:11:28 +01:00
Robert Scott
374dadb2bc Merge pull request #139225 from risicle/ris-gd-2.3.2-CVE-2021-40812p-r21.05
[21.05] gd: 2.3.0 -> 2.3.2, add patch for partial CVE-2021-40812 fix
2021-11-11 19:50:12 +00:00
Anderson Torres
2236090bfb Merge pull request #145516 from NixOS/backport-145422-to-release-21.05
[Backport release-21.05] youtube-dl: fix youtube.com download throttling
2021-11-11 16:44:09 -03:00
Michael Weiss
e138fb167b Merge pull request #145425 from NixOS/backport-145412-to-release-21.05
[Backport release-21.05] signal-desktop: 5.23.0 -> 5.23.1
2021-11-11 19:32:35 +01:00
Timothy DeHerrera
438d48e915 Merge pull request #145508 from NixOS/backport-145442-to-release-21.05
[Backport release-21.05] amis: enable setting ami boot mode on registration
2021-11-11 10:15:06 -07:00
Sandro Jäckel
84f620c270 go_1_17: 1.17.2 -> 1.17.3
(cherry picked from commit 32ef30ce24)
2021-11-11 16:59:41 +00:00
Robert Helgesson
d88e8e8136 youtube-dl: fix youtube.com download throttling
(cherry picked from commit f21e29d83b)
2021-11-11 16:57:15 +00:00
Linus Heckemann
0be80359bf vista-fonts: install cambria.ttc as well
(cherry picked from commit ae3ce3861c)
2021-11-11 16:48:51 +00:00
Timothy DeHerrera
ff3fd14d32 create-amis.sh: possible deprecation
(cherry picked from commit f0aec20cd7)
2021-11-11 16:22:43 +00:00
Timothy DeHerrera
ccecbf0906 amis: enable setting ami boot mode on registration
This is important since legacy bios mode is still the default for Intel
and AMD based instances on AWS. That is, even if your image is setup to
use UEFI on the OS level, the AMI will still use BIOS unless the boot
mode is explicitly set during registration.

(cherry picked from commit ed4170733c)
2021-11-11 16:22:42 +00:00
Robert Scott
1b1ffffdea python3Packages.distributed: add patch for CVE-2021-42343 2021-11-11 14:42:40 +00:00
Artturi
78ebdef420 Merge pull request #145358 from Artturin/backport-144921-to-release-21.05 2021-11-11 14:30:20 +02:00
Maciej Krüger
cfac20316e Merge pull request #145457 from NixOS/backport-145456-to-release-21.05
[Backport release-21.05] yt-dlp: 2021.10.22 -> 2021.11.10.1
2021-11-11 07:27:07 +01:00
Mario Rodas
fac1b7eebd yt-dlp: 2021.10.22 -> 2021.11.10.1
https://github.com/yt-dlp/yt-dlp/releases/tag/2021.11.10
https://github.com/yt-dlp/yt-dlp/releases/tag/2021.11.10.1
(cherry picked from commit 479787df3a)
2021-11-11 06:17:56 +00:00
github-actions[bot]
6b0874bb71 Merge staging-next-21.05 into staging-21.05 2021-11-11 00:08:34 +00:00
github-actions[bot]
2ed426c379 Merge release-21.05 into staging-next-21.05 2021-11-11 00:07:54 +00:00
Michael Weiss
653931ad57 signal-desktop: 5.23.0 -> 5.23.1
(cherry picked from commit 995569833b)
2021-11-10 21:59:19 +00:00
nixpkgs-upkeep-bot
6093c02b9a vscodium: 1.62.0 -> 1.62.1
(cherry picked from commit bb17e2c937)
2021-11-10 14:55:16 +00:00
nixpkgs-upkeep-bot
af0c3fd833 vscode: 1.62.0 -> 1.62.1
(cherry picked from commit 26d329e7a8)
2021-11-10 14:31:23 +00:00
Artturi
9e86f5f7a1 Merge pull request #145356 from NixOS/backport-144259-to-release-21.05 2021-11-10 15:55:51 +02:00
TredwellGit
285c70498b linux: 5.4.157 -> 5.4.158
(cherry picked from commit 0be2bcf928)
2021-11-10 15:51:13 +02:00
TredwellGit
15df37a8cb linux: 5.14.16 -> 5.14.17
(cherry picked from commit ded9d6fd05)
2021-11-10 15:49:46 +02:00
TredwellGit
0fb27fa826 linux: 5.10.77 -> 5.10.78
(cherry picked from commit 154f16fc53)
2021-11-10 15:49:45 +02:00
TredwellGit
ffed4b14a1 linux: 4.19.215 -> 4.19.216
(cherry picked from commit 69d066da70)
2021-11-10 15:49:45 +02:00
Artturin
fdf49a58e7 firefox-bin: add libXtst and libXrandr to lib path
firefox nightly now requires libXtst.so.6
without this change firefox nightly from the mozilla overlay fails to
start

added libXrandr too since libxul.so requires it
libXrandr.so.2 => not found
libXtst.so.6 => not found

(cherry picked from commit d9c66e55a02806df891ca3356b11724b77acd850)
2021-11-10 13:24:25 +00:00
Timothy DeHerrera
33c866c82b create_amis.sh: fix logic for non-zfs amis
(cherry picked from commit d280c11aa61ed3d9fadb8571bc2da4dc0f1562fb)
2021-11-09 16:26:05 -08:00
github-actions[bot]
26ec0ee47e Merge staging-next-21.05 into staging-21.05 2021-11-10 00:08:17 +00:00
github-actions[bot]
fb90142847 Merge release-21.05 into staging-next-21.05 2021-11-10 00:07:43 +00:00
Jörg Thalheim
430e190b64 Merge pull request #145129 from helsinki-systems/upd/mariadb-2105
mariadb: 10.5.10 -> 10.5.13
2021-11-09 20:49:42 +00:00
Thiago Kenji Okada
6382f88798 Merge pull request #145094 from lincolnauster/skype-update
skypeforlinux: 8.75.0.140 -> 8.77.0.97
2021-11-09 15:03:51 -03:00
github-actions[bot]
edd116ff1d Merge staging-next-21.05 into staging-21.05 2021-11-09 00:12:39 +00:00
github-actions[bot]
a9a39562a1 Merge release-21.05 into staging-next-21.05 2021-11-09 00:11:41 +00:00
ajs124
65aff4d8ea mariadb: 10.5.10 -> 10.5.13
https://mariadb.com/kb/en/mariadb-10511-release-notes/
https://mariadb.com/kb/en/mariadb-10512-release-notes/
https://mariadb.com/kb/en/mariadb-10513-release-notes/

Fixes CVE-2021-35604
2021-11-08 23:45:23 +01:00
Lancelot SIX
eac01391ec skypeforlinux: 8.75.0.140 -> 8.77.0.97
In addition to the SHA and version update, an extra required dependency on
libxshmfence is added.
2021-11-08 10:50:04 -07:00
Thiago Kenji Okada
e74894146a Merge pull request #144971 from NixOS/backport-144677-to-release-21.05
[Backport release-21.05] vscode: 1.61.2 -> 1.62.0
2021-11-07 22:07:34 -03:00
github-actions[bot]
2df3904e37 Merge staging-next-21.05 into staging-21.05 2021-11-08 00:09:28 +00:00
github-actions[bot]
13234783a3 Merge release-21.05 into staging-next-21.05 2021-11-08 00:08:46 +00:00
John Ericson
b865967452 Merge pull request #145007 from Ericson2314/backport-144193-to-release-21.05
[backport release-21.05] build-support/rust: Organize
2021-11-07 15:49:37 -05:00
John Ericson
67aa63e5e2 build-support/rust: Organize
- `toRustTarget` and friends pulled out from rust tools into rust
   library. Since they don't depend on any packages they can be more
   widely useable.

 - `build-rust-package` gets its own directory

 - `fetch-cargo-tarball` gets its own directory

(cherry picked from commit 18ed048c7b)
2021-11-07 20:03:11 +00:00
Janne Heß
9555e0baac Merge pull request #144914 from NixOS/backport-144911-to-release-21.05
[Backport release-21.05] signal-desktop: 5.22.0 -> 5.23.0
2021-11-07 19:33:21 +01:00
Vladimír Čunát
046e1d6c92 Merge #144296: firefox*: major updates (into release-21.05) 2021-11-07 17:51:45 +01:00
Mario Rodas
ba289f32b5 Merge pull request #144973 from NixOS/backport-144873-to-release-21.05
[Backport release-21.05] vscodium: 1.61.2 -> 1.62.0
2021-11-07 05:33:35 -05:00
nixpkgs-upkeep-bot
6de733c34e vscodium: 1.61.2 -> 1.62.0
(cherry picked from commit 0867441532)
2021-11-07 09:30:31 +00:00
nixpkgs-upkeep-bot
1f77fc8762 vscode: 1.61.2 -> 1.62.0
(cherry picked from commit 3702a81873)
2021-11-07 08:55:34 +00:00
github-actions[bot]
c7102a67df Merge staging-next-21.05 into staging-21.05 2021-11-07 00:08:42 +00:00
github-actions[bot]
45b359db08 Merge release-21.05 into staging-next-21.05 2021-11-07 00:08:12 +00:00
Maximilian Bosch
e120d6bd04 vagrant: 2.2.18 -> 2.2.19
ChangeLog: https://github.com/hashicorp/vagrant/blob/v2.2.19/CHANGELOG.md#2219-november-5-2021
(cherry picked from commit fe175c8e9a)
2021-11-06 22:42:56 +00:00
Michael Weiss
a18dc9b1e3 signal-desktop: 5.22.0 -> 5.23.0
(cherry picked from commit ed83ff9bcc)
2021-11-06 18:41:02 +00:00
Maximilian Bosch
ce48bcdde8 Merge pull request #144770 from NixOS/backport-144058-to-release-21.05
[Backport release-21.05] Kernels 2021-11-02
2021-11-06 12:02:24 +01:00
github-actions[bot]
b997c403eb Merge staging-next-21.05 into staging-21.05 2021-11-06 00:07:58 +00:00
github-actions[bot]
dfdd7ec8da Merge release-21.05 into staging-next-21.05 2021-11-06 00:07:24 +00:00
Wael Nasreddine
5c02380de3 python3Packages.snowflake-connector-python: fix build (#144682)
(cherry picked from commit 9fa5bc45bb)

Co-authored-by: Jonathan Ringer <jonringer117@gmail.com>
2021-11-05 11:50:31 -07:00
TredwellGit
be7cfa7be7 linux/hardened/patches/5.4: 5.4.155-hardened1 -> 5.4.157-hardened1
(cherry picked from commit 5564761e1e)
2021-11-05 17:36:16 +00:00
TredwellGit
12159ee228 linux/hardened/patches/5.14: 5.14.14-hardened1 -> 5.14.16-hardened1
(cherry picked from commit ac29586638)
2021-11-05 17:36:15 +00:00
TredwellGit
08ed409e51 linux/hardened/patches/5.10: 5.10.75-hardened1 -> 5.10.77-hardened1
(cherry picked from commit 0b37e93d6b)
2021-11-05 17:36:14 +00:00
TredwellGit
84623a4196 linux/hardened/patches/4.19: 4.19.213-hardened1 -> 4.19.215-hardened1
(cherry picked from commit d4efdd46c7)
2021-11-05 17:36:13 +00:00
TredwellGit
ae204e9ec3 linux/hardened/patches/4.14: 4.14.252-hardened1 -> 4.14.254-hardened1
(cherry picked from commit 6cbce22479)
2021-11-05 17:36:11 +00:00
TredwellGit
77f67c676b linux_latest-libre: 18413 -> 18452
(cherry picked from commit 962be21e1d)
2021-11-05 17:36:10 +00:00
TredwellGit
49142fdf19 linux: 5.4.156 -> 5.4.157
(cherry picked from commit a2dd7acdd8)
2021-11-05 17:36:09 +00:00
TredwellGit
2000097db4 linux: 5.14.15 -> 5.14.16
(cherry picked from commit 104950bafd)
2021-11-05 17:36:08 +00:00
TredwellGit
bc6402b439 linux: 5.10.76 -> 5.10.77
(cherry picked from commit 4deb3cf76a)
2021-11-05 17:36:07 +00:00
TredwellGit
7fbf1d3418 linux: 4.9.288 -> 4.9.289
(cherry picked from commit 5cab1474d9)
2021-11-05 17:36:06 +00:00
TredwellGit
e73d614d6b linux: 4.4.290 -> 4.4.291
(cherry picked from commit 6292af0d46)
2021-11-05 17:36:04 +00:00
TredwellGit
8af4c2d940 linux: 4.19.214 -> 4.19.215
(cherry picked from commit c1f9eef4bc)
2021-11-05 17:36:03 +00:00
TredwellGit
8974d61d61 linux: 4.14.253 -> 4.14.254
(cherry picked from commit 6ad7cc4323)
2021-11-05 17:36:02 +00:00
github-actions[bot]
4bd5595618 Merge staging-next-21.05 into staging-21.05 2021-11-05 00:08:30 +00:00
github-actions[bot]
9243033752 Merge release-21.05 into staging-next-21.05 2021-11-05 00:07:48 +00:00
Janne Heß
96ded94eb0 Merge pull request #144599 from vcunat/p/knot-dns_bump-21.05
[21.05] knot-dns: 3.0.9 -> 3.0.10
2021-11-04 23:56:54 +01:00
Maximilian Bosch
eb85a2adb9 Merge pull request #144274 from NixOS/backport-143177-to-release-21.05
[Backport release-21.05] matrix-synapse: 1.45.1 -> 1.46.0
2021-11-04 22:10:08 +01:00
Vladimír Čunát
55420d7083 Merge #143942: thunderbird*: 91.1.1 -> 91.2.1 (into release-21.05) 2021-11-04 17:43:44 +01:00
Vladimír Čunát
12c1c3baf0 unstable job: fix after thunderbird switch
We also switched to unwrapped thunderbird on nixpkgs master
in commit 8b1c14045d.
2021-11-04 13:20:40 +01:00
Vladimír Čunát
440d437c82 thunderbird: 78.x -> 91.x
.. as we consider 78.x insecure.
2021-11-04 12:35:19 +01:00
Vladimír Čunát
e7f2911fed knot-dns: 3.0.9 -> 3.0.10
https://gitlab.nic.cz/knot/knot-dns/-/tags/v3.0.10
2021-11-04 12:22:46 +01:00
github-actions[bot]
0123415297 Merge staging-next-21.05 into staging-21.05 2021-11-04 00:08:25 +00:00
github-actions[bot]
db3545b77e Merge release-21.05 into staging-next-21.05 2021-11-04 00:07:45 +00:00
R. Ryantm
8d2920fcaf firefox-esr-91-unwrapped: 91.2.0esr -> 91.3.0esr
(cherry picked from commit 4c9202e36e)
2021-11-03 16:23:57 +01:00
Martin Weinelt
95b508e695 firefox: 93.0 -> 94.0
(cherry picked from commit 0cf88beb7b)
2021-11-03 16:23:56 +01:00
Martin Weinelt
1652c35291 nss_latest: 3.70 -> 3.71 2021-11-03 13:35:49 +01:00
Martin Weinelt
28d980df02 rust_1_55: init
Required for the latest Firefox builds.
2021-11-03 13:35:49 +01:00
Sandro
2fd5c69fa6 Merge pull request #144384 from saschagrunert/nixos-21.05-k8s 2021-11-03 10:54:15 +01:00
Sascha Grunert
935a0a4298 kubernetes: 1.21.1 -> 1.21.6
Signed-off-by: Sascha Grunert <sgrunert@redhat.com>
2021-11-03 09:27:30 +01:00
Dominik Xaver Hörl
2a4bc078c4 nixos/kernel: test 5.15 kernel 2021-11-03 08:26:34 +01:00
Dominik Xaver Hörl
5714befdce linux_latest_hardened: pin version to 5.14 2021-11-03 08:25:53 +01:00
Dominik Xaver Hörl
1fcac2a148 linux_latest: 5.14 -> 5.15 2021-11-03 08:08:53 +01:00
Dominik Xaver Hörl
fd81bcee12 linux: init 5.15 2021-11-03 07:50:35 +01:00
Maciej Krüger
b239cf7ba0 Merge pull request #144322 from r-burns/qemu-security-2105 2021-11-03 07:07:42 +01:00
Maciej Krüger
007fa0702a Merge pull request #144356 from NixOS/backport-144349-to-release-21.05 2021-11-03 07:02:57 +01:00
Maciej Krüger
3bf0fc341a Merge pull request #144355 from NixOS/backport-144289-to-release-21.05 2021-11-03 07:02:29 +01:00
taku0
b5777416ff firefox-bin: 93.0 -> 94.0
(cherry picked from commit 7d427ce6a0)
2021-11-03 06:02:25 +00:00
Maximilian Bosch
f3df16db3a mautrix-whatsapp: 0.1.9 -> 0.1.10
ChangeLog: https://github.com/mautrix/whatsapp/releases/tag/v0.1.10
(cherry picked from commit 3f24252df0)
2021-11-03 06:01:27 +00:00
Ryan Burns
4f9ab13922 qemu: patch CVE-2021-3544
This is a 5-part patch series for a series of related memory leaks,
backported from qemu 6.1.0.
2021-11-02 18:10:51 -07:00
github-actions[bot]
a2b13b6978 Merge staging-next-21.05 into staging-21.05 2021-11-03 00:08:13 +00:00
github-actions[bot]
83b82d2269 Merge release-21.05 into staging-next-21.05 2021-11-03 00:07:38 +00:00
Martin Weinelt
11b021c67e firefox-esr: migrate to firefox-esr-91 2021-11-02 23:42:18 +01:00
Martin Weinelt
2d89624983 firefox-esr-78: mark as vulnerable
This is a browser, the 78 ESR series is end of life, so we can expect
this browser to be a security vulnerability any day.

Recommend everyone to move to ESR 91.
2021-11-02 23:40:02 +01:00
Sumner Evans
49091f050f matrix-synapse: 1.45.1 -> 1.46.0
https://github.com/matrix-org/synapse/releases/tag/v1.46.0
(cherry picked from commit f4a8302016)
2021-11-02 19:15:21 +00:00
Patrick Hilhorst
043dc386ca Merge pull request #142458 from Synthetica9/backport-patchelf-0.13-to-21.05 2021-11-02 20:10:47 +01:00
Robin Gloster
3dc6784ba4 atlassian-jira: 8.19.0 -> 8.20.1
(cherry picked from commit e14e80d145)
2021-11-02 11:55:15 -07:00
Meghea Iulian
c23a02bd1e atlassian-jira: 8.16.1 -> 8.19
(cherry picked from commit dc2002ce44)
2021-11-02 11:55:15 -07:00
Robin Gloster
00eac904ca atlassian-confluence: 7.12.2 -> 7.14.1
(cherry picked from commit 2aaf958e3f)
2021-11-02 11:55:15 -07:00
elseym
c6482c12d9 atlassian-confluence: 7.11.0 -> 7.12.2
(cherry picked from commit 50839b4498)
2021-11-02 11:55:15 -07:00
Robin Gloster
983c59f729 atlassian-crowd: 4.2.0 -> 4.4.0
(cherry picked from commit c8218905eb)
2021-11-02 11:55:15 -07:00
Justin Sleep
71590d4edb linux: build in Cherryview pinctrl driver
This allows integrated keyboards on Braswell and Cherryview devices to function properly.

(cherry picked from commit 64ae396829)
2021-11-02 13:55:18 +00:00
github-actions[bot]
11ee8420b6 Merge staging-next-21.05 into staging-21.05 2021-11-02 00:08:12 +00:00
github-actions[bot]
9ef84ffeaf Merge release-21.05 into staging-next-21.05 2021-11-02 00:07:34 +00:00
Kim Lindberger
372e59d2af Merge pull request #144009 from jansol/release-21.05
[Backport release-21.05] pipewire: 0.3.36 -> 0.3.39
2021-11-01 23:49:14 +01:00
Vladimír Čunát
01b884f222 Merge #144101: pidgin: use system certificates (into release-21.05) 2021-11-01 12:24:03 +01:00
Evgeny Kurnevsky
687fd09c28 pidgin: use system certificates to fix letsencrypt
(cherry picked from commit bf0c0cc767)
2021-11-01 11:22:17 +00:00
Kerstin Humm
3c07885b3a imagemagick: 7.1.0-9 -> 7.1.0-13 2021-11-01 10:40:59 +01:00
Kerstin Humm
9fe53aefc9 imagemagick: 7.1.0-8 -> 7.1.0-9
(cherry picked from commit 075c492243)
2021-11-01 10:38:54 +01:00
Artturi
c503d78069 Merge pull request #129315 from fortuneteller2k/backport-xanmod-5.13 2021-11-01 10:31:52 +02:00
github-actions[bot]
ad3e5d58f3 Merge staging-next-21.05 into staging-21.05 2021-11-01 00:09:07 +00:00
github-actions[bot]
8a30d1e590 Merge release-21.05 into staging-next-21.05 2021-11-01 00:08:28 +00:00
Domen Kožar
f0869b1a2c Merge pull request #144021 from NixOS/backport-144016-to-release-21.05
[Backport release-21.05] honcho: 1.0.1 -> 1.1.0, fix the package
2021-10-31 15:33:08 -07:00
Maximilian Bosch
b43e55f22b Merge pull request #143437 from NixOS/backport-143404-to-release-21.05
[Backport release-21.05] mautrix-whatsapp: 0.1.8 -> 0.1.9
2021-10-31 22:57:05 +01:00
Domen Kožar
8a7935d97e honcho: 1.0.1 -> 1.1.0, fix the package
(cherry picked from commit 059feb3ccf)
2021-10-31 18:13:02 +00:00
Jan Solanti
24e5cb9ba5 pipewire: 0.3.38 -> 0.3.39
Split pipewire-media-session into its own package
2021-10-31 18:29:26 +02:00
Jan Solanti
15aca14b46 pipewire-media-session: init at 0.4.0 2021-10-31 18:21:46 +02:00
Jan Solanti
82791b7599 pipewire: 0.3.37 -> 0.3.38 2021-10-31 18:20:57 +02:00
Jan Solanti
beb1373e15 pipewire: 0.3.36 -> 0.3.37 2021-10-31 18:20:57 +02:00
Robert Scott
3c0f229486 Merge pull request #143303 from r-burns/qemu-security-2105
[21.05] qemu: fix CVE-2021-3527, CVE-2021-3682, CVE-2021-3713
2021-10-31 16:09:30 +00:00
Pavol Rusnak
7bb26f4abc Merge pull request #143426 from prusnak/tor-21.05
[21.05] tor: 0.4.5.10 -> 0.4.5.11
2021-10-31 13:54:57 +01:00
taku0
5f60ed2d7c thunderbird: mark 78.14.0 insecure 2021-10-31 15:37:13 +09:00
taku0
69d4ee18d7 thunderbird: 91.1.1 -> 91.2.1 2021-10-31 15:31:21 +09:00
taku0
6d18bf0042 thunderbird-bin: 91.1.2 -> 91.2.1 2021-10-31 15:27:13 +09:00
taku0
7349374c44 thunderbird-bin: 91.1.1 -> 91.1.2 2021-10-31 15:27:09 +09:00
github-actions[bot]
868a5fe782 Merge staging-next-21.05 into staging-21.05 2021-10-31 00:08:44 +00:00
github-actions[bot]
4f5d7e9422 Merge release-21.05 into staging-next-21.05 2021-10-31 00:08:05 +00:00
Michael Weiss
e3699f9a4b Merge pull request #143819 from primeos/ungoogled-chromium-backport
[21.05] ungoogled-chromium: 95.0.4638.54 -> 95.0.4638.69
2021-10-30 18:22:03 +02:00
Michael Weiss
db2b776077 ungoogled-chromium: 95.0.4638.54 -> 95.0.4638.69
(cherry picked from commit d71409c0de)
2021-10-30 11:54:22 +02:00
Michael Weiss
3854b45b21 Merge pull request #143816 from primeos/chromium-backport
[21.05] chromium: 95.0.4638.54 -> 95.0.4638.69
2021-10-30 11:53:25 +02:00
Maximilian Bosch
666bedc36c Merge pull request #143761 from Ma27/backport-epson-escpr2
[21.05] epson-escpr2: 1.1.38 -> 1.1.42
2021-10-30 11:22:30 +02:00
Michael Weiss
4bfe628c58 Merge pull request #142514 from NixOS/backport-142450-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 94.0.4606.81 -> 95.0.4638.54
2021-10-30 11:17:43 +02:00
Michael Weiss
a7e7c9a328 chromium: 95.0.4638.54 -> 95.0.4638.69
https://chromereleases.googleblog.com/2021/10/stable-channel-update-for-desktop_28.html

This update includes 8 security fixes. Google is aware that exploits for
CVE-2021-38000 and CVE-2021-38003 exist in the wild.

CVEs:
CVE-2021-37997 CVE-2021-37998 CVE-2021-37999 CVE-2021-38000
CVE-2021-38001 CVE-2021-38002 CVE-2021-38003

(cherry picked from commit 8dae7bc0f5)
2021-10-30 11:12:06 +02:00
github-actions[bot]
f4a36d4e9e Merge staging-next-21.05 into staging-21.05 2021-10-30 00:07:59 +00:00
github-actions[bot]
2fea1b17a7 Merge release-21.05 into staging-next-21.05 2021-10-30 00:07:25 +00:00
Maximilian Bosch
fc3c987767 epson-escpr2: 1.1.38 -> 1.1.42
(cherry picked from commit b9170bf9e0)
2021-10-30 00:00:11 +02:00
Michael Weiss
6c0c301463 Merge pull request #143744 from primeos/signal-desktop-backport
[21.05] signal-desktop: 5.21.0 -> 5.22.0
2021-10-29 23:43:10 +02:00
Michael Weiss
e47f00a7c7 signal-desktop: 5.21.0 -> 5.22.0 2021-10-29 23:07:19 +02:00
Kim Lindberger
8416cc284e Merge pull request #143397 from talyz/21-05-gitlab-14.4.1
[21.05] gitlab: 14.3.3 -> 14.4.1
2021-10-29 15:10:03 +02:00
talyz
b72647dc3a gitlab: 14.3.3 -> 14.4.1 2021-10-29 13:41:48 +02:00
Maximilian Bosch
e5faf9d034 Merge pull request #143466 from Ma27/backport-linux-changes
[21.05] linux: changes for #140281
2021-10-29 13:27:40 +02:00
github-actions[bot]
7e741e7361 Merge staging-next-21.05 into staging-21.05 2021-10-29 00:08:21 +00:00
github-actions[bot]
d120f6225f Merge release-21.05 into staging-next-21.05 2021-10-29 00:07:44 +00:00
Eduardo Sánchez Muñoz
66d6ec6ed2 maintainers: remove eduardosm 2021-10-28 14:23:25 -07:00
Maximilian Bosch
f47c57802e linux: build hardened kernel with matching releases
Until now we merged kernel updates even if no hardened versions were
available yet. On one hand we don't want to delay patch-level updates,
on the other hand users of hardened kernels have frequent breakage now[1].

This change aims to provide a solution this issue:

* The hardened patchset now references the kernel version it's released
  for (including a sha256 hash for the fixed-output path of the source
  tarball).
* The `hardenedKernelFor`-function doesn't just append hardened patches
  now, but also overrides version & src to match the kernel version the
  patch was built & tested for.

Refs #140281

[1] https://hydra.nixos.org/job/nixos/trunk-combined/nixpkgs.linuxPackages_hardened.kernel.x86_64-linux/all

(cherry picked from commit bb5aa0109b)
2021-10-28 22:26:22 +02:00
Maximilian Bosch
f48b51e12e linux: create maintainer team
Now there are a few more folks who should get pinged on kernel changes:

    $ nix-instantiate -E 'with import ./. {}; (map (x: x.github) linux.meta.maintainers)' --eval  --strict
    [ "TredwellGit" "mweinelt" "ma27" "nequissimus" "alyssais" "thoughtpolice" ]

Refs #140281

(cherry picked from commit 65930caffe)
2021-10-28 21:58:39 +02:00
Artturi
dcc34fe9e1 Merge pull request #143448 from NixOS/backport-122585-to-release-21.05
[Backport release-21.05] tor-browser-bundle-bin: Add eff.org mirror
2021-10-28 22:18:24 +03:00
jakobrs
0116578123 tor-browser-bundle-bin: Add eff.org mirror
(cherry picked from commit 7325f6a4f1)
2021-10-28 19:04:08 +00:00
Charlotte Van Petegem
ce6cefbd96 mautrix-whatsapp: 0.1.8 -> 0.1.9
(cherry picked from commit 5e447cfae5)
2021-10-28 18:07:07 +00:00
Maximilian Bosch
a6e34d50fc Merge pull request #143355 from Ma27/php73-cve-2021-21703
[21.05] php73: 7.3.29 -> 7.3.32
2021-10-28 19:43:41 +02:00
Pavol Rusnak
01738ca44d tor: 0.4.5.10 -> 0.4.5.11 2021-10-28 19:08:16 +02:00
Ryan Mulligan
ecaaffb02e Merge pull request #143291 from NixOS/backport-143275-to-release-21.05
[Backport release-21.05] [CVSS 10.0] discourse: 2.7.8 -> 2.7.9
2021-10-28 07:06:00 -07:00
Maximilian Bosch
25ff65fe34 php73: 7.3.29 -> 7.3.32
ChangeLog: https://www.php.net/ChangeLog-7.php#7.3.32 and below.
2021-10-28 12:53:40 +02:00
Ryan Burns
e2110b6a0a qemu: fix CVE-2021-3527, CVE-2021-3682, CVE-2021-3713
Backport patches for 6.0.0
2021-10-27 22:15:38 -07:00
TredwellGit
969ba0f1c9 discourse: 2.7.8 -> 2.7.9
https://nvd.nist.gov/vuln/detail/CVE-2021-41163
(cherry picked from commit 44ffcb8362)
2021-10-28 03:41:51 +00:00
figsoda
06b49ba179 Merge pull request #143135 from NixOS/backport-143131-to-release-21.05
[Backport release-21.05] electron: mark versions <= 11 as EOL
2021-10-27 22:50:21 -04:00
github-actions[bot]
2fc1c24aac Merge staging-next-21.05 into staging-21.05 2021-10-28 00:08:04 +00:00
github-actions[bot]
a63ab93ae0 Merge release-21.05 into staging-next-21.05 2021-10-28 00:07:31 +00:00
Maximilian Bosch
d14d83a369 Merge pull request #143183 from NixOS/backport-143113-to-release-21.05
[Backport release-21.05] Kernels 2021-10-27
2021-10-28 00:20:56 +02:00
TredwellGit
df3c294daa firmwareLinuxNonfree: 2021-09-19 -> 20211027
(cherry picked from commit 8c0c31d545)
2021-10-27 20:50:37 +00:00
Michael Weiss
0a6b8f9b69 Merge pull request #143201 from NixOS/backport-143044-to-release-21.05
[Backport release-21.05] signal-desktop: 5.20.0 -> 5.21.0
2021-10-27 21:42:05 +02:00
figsoda
dcdd69dcdc Merge pull request #143212 from NixOS/backport-132008-to-release-21.05
[Backport release-21.05] multimc: don't re-distribute package
2021-10-27 15:20:58 -04:00
Tristan Gosselin-Hane
28188b0b42 multimc: don't re-distribute package
Fixes NixOS#131983

(cherry picked from commit 8dfddb341ebaf718904722692dbbcd1d5d9d5e12)
2021-10-27 19:06:27 +00:00
Tristan Gosselin-Hane
27db642c65 multimc: change license to asl20
(cherry picked from commit 9a8f5b712fa5beb86659dd1f2d0a830c16f4cfc9)
2021-10-27 19:06:26 +00:00
Michael Weiss
7f1ea2dc2d signal-desktop: 5.20.0 -> 5.21.0
(cherry picked from commit 374ab216aa)
2021-10-27 18:19:31 +00:00
TredwellGit
7868d08c53 linux_latest-libre: 18380 -> 18413
(cherry picked from commit 748cc60427)
2021-10-27 16:07:47 +00:00
TredwellGit
4d8b9a6846 linux-rt_5_4: 5.4.143-rt64 -> 5.4.154-rt65
(cherry picked from commit 55af4f5da2)
2021-10-27 16:07:46 +00:00
TredwellGit
35fe117f23 linux: 5.4.155 -> 5.4.156
(cherry picked from commit 67e5b8b626)
2021-10-27 16:07:45 +00:00
TredwellGit
c34af3c32f linux: 5.14.14 -> 5.14.15
(cherry picked from commit 0719e92d1b)
2021-10-27 16:07:44 +00:00
TredwellGit
01915f55ea linux: 5.10.75 -> 5.10.76
(cherry picked from commit 4bd2c087e0)
2021-10-27 16:07:43 +00:00
TredwellGit
fbdac79b1a linux: 4.9.287 -> 4.9.288
(cherry picked from commit 19735ff280)
2021-10-27 16:07:42 +00:00
TredwellGit
f9c1a37c60 linux: 4.4.289 -> 4.4.290
(cherry picked from commit 3a69f006d9)
2021-10-27 16:07:41 +00:00
TredwellGit
75c0de2495 linux: 4.19.213 -> 4.19.214
(cherry picked from commit b7efb90537)
2021-10-27 16:07:40 +00:00
TredwellGit
7670a0e6c6 linux: 4.14.252 -> 4.14.253
(cherry picked from commit 20e62a2b01)
2021-10-27 16:07:38 +00:00
Divam Narula
ce5e240b2b ghcjs: Enable on darwin (#139067)
(cherry picked from commit d032f60c37)
2021-10-27 15:52:48 +00:00
(cdep)illabout
4ecfdc7f46 haskell.compiler.ghcjs: mark hydraPlatforms as none because output is too large
(cherry picked from commit 3389aab889)
2021-10-27 15:52:48 +00:00
Pavol Rusnak
220eee37cb electron: mark versions <= 11 as EOL
(cherry picked from commit ec8ccb1f42)
2021-10-27 11:47:57 +00:00
Maximilian Bosch
de6f737cbd Merge pull request #143054 from Ma27/php-backport
[21.05] php: 7.4.24 -> 7.4.25, 8.0.11 -> 8.0.12, fix CVE-2021-21703
2021-10-27 12:51:11 +02:00
Artturi
ddee258d88 Merge pull request #142927 from NixOS/backport-124486-to-release-21.05
[Backport release-21.05] nixos/boot: properly override the kernel in boot.kernelPatches
2021-10-27 04:53:51 +03:00
github-actions[bot]
7f635887d8 Merge staging-next-21.05 into staging-21.05 2021-10-27 00:08:24 +00:00
github-actions[bot]
cbb57d28ee Merge release-21.05 into staging-next-21.05 2021-10-27 00:07:44 +00:00
Maximilian Bosch
1b8d9c1854 php80: 8.0.11 -> 8.0.12, fix CVE-2021-21703
Details: https://nvd.nist.gov/vuln/detail/CVE-2021-21703
ChangeLog: https://www.php.net/ChangeLog-8.php#8.0.12
(cherry picked from commit ab5c10c42a)
2021-10-26 23:42:53 +02:00
Maximilian Bosch
a17528c284 php74: 7.4.24 -> 7.4.25, fix CVE-2021-21703
Details: https://nvd.nist.gov/vuln/detail/CVE-2021-21703
ChangeLog: https://www.php.net/ChangeLog-7.php#7.4.25
(cherry picked from commit af404d852f)
2021-10-26 23:42:27 +02:00
Dmitry Kalinkin
86c1469748 python3Packages.hg-git: init at 0.10.2
(cherry picked from commit 412d572942)
2021-10-26 21:12:52 +00:00
oxalica
5ebb1dca9b flameshot: fix desktop Exec path and autostart directory location
(cherry picked from commit ccb84b735be81e6e7f4360c9d3eb4b9fe512c8d5)
2021-10-26 22:37:34 +02:00
Kerstin Humm
c99f062210 imagemagick6: 6.9.12-19 -> 6.9.12-26
(cherry picked from commit 8705d0826f)
2021-10-26 20:00:51 +02:00
Ben Siraphob
dc07d8b6cc Merge pull request #141021 from risicle/ris-vyper-0.3.0-r21.05
[21.05] python3Packages.vyper: 0.2.11 -> 0.3.0
2021-10-26 11:52:35 -05:00
Timothy DeHerrera
e5eb3a7a63 Merge pull request #142985 from NixOS/backport-122445-to-release-21.05
[Backport release-21.05] freeswitch: 1.10.5 > 1.10.6
2021-10-26 09:31:26 -06:00
misuzu
ad861506ba freeeswitch: enable strictDeps
(cherry picked from commit ef32c9e3b8)
2021-10-26 12:11:33 +00:00
misuzu
0833ed32f3 freeeswitch: move perl, which and yasm to nativeBuildInputs
(cherry picked from commit 85fb843759)
2021-10-26 12:11:33 +00:00
misuzu
9a7d06d4ab freeswitch: 1.10.5 > 1.10.6
(cherry picked from commit a7b56e41d4)
2021-10-26 12:11:32 +00:00
Dominik Xaver Hörl
f2281f6186 nixos/boot: properly override the kernel in boot.kernelPatches
Previously the code took the kernelPatches of the final derivation, which
might or might not be what was passed to the derivation in the original call.
The previous behaviour caused various hacks to become neccessary to avoid duplicates in kernelPatches.

(cherry picked from commit 436f61c878)
2021-10-26 07:46:54 +00:00
Kevin Quick
b13688e515 nixos/nix-daemon: assert system or systems for buildMachines.
Commit 5395397f removed the assertions from the buildMachines to
ensure that either system or systems is set for each buildmachine.

This patch re-implements those assertions.

The symptom is that if both system and systems are omitted, then the
/etc/machines file has the wrong number of columns and any attempt to
run a `nix` operation that has to perform a build will fail with a
`strtoull` exception.

(cherry picked from commit 58921a4904)
2021-10-25 10:06:31 +00:00
github-actions[bot]
b79b93b634 Merge staging-next-21.05 into staging-21.05 2021-10-25 00:08:27 +00:00
github-actions[bot]
208b031d54 Merge release-21.05 into staging-next-21.05 2021-10-25 00:07:47 +00:00
R. RyanTM
b3ce8310eb filebot: 4.9.3 -> 4.9.4
(cherry picked from commit 6b18e415e8)
2021-10-24 12:03:23 +00:00
Sebastian
3b1789322f nixos/bookstack: fix error message output (#142722) 2021-10-24 18:16:54 +08:00
github-actions[bot]
a8df0daf01 Merge staging-next-21.05 into staging-21.05 2021-10-24 00:08:41 +00:00
github-actions[bot]
6218f9980a Merge release-21.05 into staging-next-21.05 2021-10-24 00:08:00 +00:00
Maciej Krüger
95eed9b64e Merge pull request #142692 from NixOS/backport-142691-to-release-21.05 2021-10-23 23:27:41 +02:00
zowoq
fa8441ba44 yt-dlp: 2021.10.10 -> 2021.10.22
https://github.com/yt-dlp/yt-dlp/releases/tag/2021.10.22
(cherry picked from commit 38b81820ee)
2021-10-23 21:23:21 +00:00
Maximilian Bosch
ea8a8b9c52 Merge pull request #142426 from NixOS/backport-142342-to-release-21.05
[Backport release-21.05] Kernels 2021-10-20
2021-10-23 13:32:15 +02:00
Artturi
07819d494d Merge pull request #142636 from NixOS/backport-139004-to-release-21.05 2021-10-23 08:13:23 +03:00
Atemu
3c07a4fe8e lutris: propagate important meta attrs to FHSEnv wrapper
Closes https://github.com/NixOS/nixpkgs/pull/81107

(cherry picked from commit 1fc860b9ed)
2021-10-23 04:20:50 +00:00
Ryan Mulligan
605dc2af25 Merge pull request #142615 from NixOS/backport-142607-to-release-21.05
[Backport release-21.05] discourse: Fix the public directory path reported by Discourse
2021-10-22 20:18:00 -07:00
github-actions[bot]
5b615ede0a Merge staging-next-21.05 into staging-21.05 2021-10-23 00:08:07 +00:00
github-actions[bot]
faf80fa69f Merge release-21.05 into staging-next-21.05 2021-10-23 00:07:30 +00:00
talyz
23e841c5b7 discourse: Fix the public directory path reported by Discourse
Change the path to the public directory reported by Discourse
to its real path instead of the symlink in the store, since
the store path won't be matched by any nginx rules.

Fixes #142528.

(cherry picked from commit 1fb77e822b)
2021-10-22 23:29:50 +00:00
Artturi
c3eedc900f Merge pull request #142572 from NixOS/backport-140343-to-release-21.05 2021-10-23 02:14:12 +03:00
Artturin
0719766dee cfdyndns: fix startAt by setting it to *:0/5 instead of 5 minutes
5 minutes is invalid for startAt

(cherry picked from commit 2e4938eb6a)
2021-10-22 13:57:59 +00:00
Vincent Laporte
b0274abf85 tamarin-prover: 1.6.0 → 1.6.1
(cherry picked from commit 05838a1632cab4f0371356666ed57f0be01575a9)
2021-10-22 08:13:56 +02:00
Michael Adler
4d6cfda283 ungoogled-chromium: 94.0.4606.81 -> 95.0.4638.54
(cherry picked from commit a8f4267547)
2021-10-21 19:45:44 +00:00
Domen Kožar
e37e0382f0 patchelf: 0.12 -> 0.13 2021-10-21 12:36:12 +02:00
github-actions[bot]
96f29fcae8 Merge staging-next-21.05 into staging-21.05 2021-10-21 00:08:34 +00:00
github-actions[bot]
a175a54f0d Merge release-21.05 into staging-next-21.05 2021-10-21 00:07:57 +00:00
Maximilian Bosch
d8eb814a24 Merge pull request #142355 from mayflower/vim-backport
[21.05] vim: 8.2.2567 -> 8.2.3451
2021-10-21 00:40:26 +02:00
Maximilian Bosch
55e93ae9eb Merge pull request #142335 from NixOS/backport-141382-to-release-21.05
[Backport release-21.05] matrix-synapse: 1.44.0 -> 1.45.1
2021-10-20 23:47:04 +02:00
TredwellGit
775fb6d1a8 linux/hardened/patches/5.4: 5.4.152-hardened1 -> 5.4.154-hardened1
(cherry picked from commit 75dbbe37be)
2021-10-20 21:44:05 +00:00
TredwellGit
9e26201347 linux/hardened/patches/5.14: 5.14.11-hardened1 -> 5.14.13-hardened1
(cherry picked from commit cf9f5f74dd)
2021-10-20 21:44:04 +00:00
TredwellGit
6592fdf573 linux/hardened/patches/5.10: 5.10.72-hardened1 -> 5.10.74-hardened1
(cherry picked from commit e94db0f89c)
2021-10-20 21:44:03 +00:00
TredwellGit
015f1c52a6 linux/hardened/patches/4.19: 4.19.210-hardened1 -> 4.19.212-hardened1
(cherry picked from commit a33fc5384b)
2021-10-20 21:44:02 +00:00
TredwellGit
8c2bb7c9c7 linux/hardened/patches/4.14: 4.14.250-hardened1 -> 4.14.251-hardened1
(cherry picked from commit cf0d47c505)
2021-10-20 21:44:01 +00:00
TredwellGit
ff19141e7f linux: 5.4.154 -> 5.4.155
(cherry picked from commit 25ef63bb78)
2021-10-20 21:44:00 +00:00
TredwellGit
0c2ae8ea8f linux: 5.14.13 -> 5.14.14
(cherry picked from commit a96f1a866a)
2021-10-20 21:43:59 +00:00
TredwellGit
3cf2064cb4 linux: 5.10.74 -> 5.10.75
(cherry picked from commit a3edfb9ee5)
2021-10-20 21:43:57 +00:00
TredwellGit
6670573707 linux: 4.19.212 -> 4.19.213
(cherry picked from commit e4f4df78fa)
2021-10-20 21:43:56 +00:00
TredwellGit
bde6dc5c3a linux: 4.14.251 -> 4.14.252
(cherry picked from commit c4d7df2b7b)
2021-10-20 21:43:55 +00:00
Maximilian Bosch
6ea1791344 matrix-synapse: 1.45.0 -> 1.45.1
ChangeLog: https://github.com/matrix-org/synapse/releases/tag/v1.45.1
(cherry picked from commit b25c2fbed9)
2021-10-20 22:09:37 +02:00
Michael Weiss
70904d4a99 Merge pull request #142252 from primeos/chromium-backport
[21.05] chromium: 94.0.4606.81 -> 95.0.4638.54
2021-10-20 21:37:24 +02:00
Patrick Hilhorst
c1dd303d5d Merge pull request #142376 from NixOS/backport-142347-to-release-21.05 2021-10-20 19:06:34 +02:00
Maximilian Bosch
7f52606b19 Merge pull request #142142 from NixOS/backport-142000-to-release-21.05
[Backport release-21.05] Kernels 2021-10-17
2021-10-20 18:36:35 +02:00
Mario Rodas
10434b5402 pgsync: 0.6.7 -> 0.6.8
(cherry picked from commit 09784546d6)
2021-10-20 15:25:02 +00:00
nixpkgs-upkeep-bot
00dab64943 vscodium: 1.61.1 -> 1.61.2
(cherry picked from commit 214721f8c5)
2021-10-20 15:10:12 +00:00
maxine [they]
f46390a873 Merge pull request #142329 from NixOS/backport-142271-to-release-21.05 2021-10-20 15:31:02 +02:00
maxine [they]
b49f3cefb1 Merge pull request #142356 from mayflower/backport-containerd 2021-10-20 15:30:27 +02:00
R. RyanTM
24f2d609d1 vim: 8.2.3337 -> 8.2.3451 (#138870)
(cherry picked from commit 1bd288093e)
2021-10-20 15:21:34 +02:00
Danielle Lancashire
d48b10a82d containerd: 1.5.5 -> 1.5.7
(cherry picked from commit aabceb8539)
2021-10-20 15:08:39 +02:00
R. RyanTM
a34c5e29ec containerd: 1.5.4 -> 1.5.5
(cherry picked from commit b58b4a85c4)
2021-10-20 15:08:35 +02:00
R. RyanTM
c2bdd22e9d vim: 8.2.2567 -> 8.2.3337
(cherry picked from commit b40c96c340)
2021-10-20 15:04:05 +02:00
Sumner Evans
3cf9eece52 matrix-synapse: 1.44.0 -> 1.45.0
(cherry picked from commit cd5ff4fe24)
2021-10-20 11:02:02 +00:00
nixpkgs-upkeep-bot
2e1350b2ee vscode: 1.61.1 -> 1.61.2
(cherry picked from commit b7428350b9)
2021-10-20 10:25:41 +00:00
github-actions[bot]
eec1992f34 Merge staging-next-21.05 into staging-21.05 2021-10-20 00:08:36 +00:00
github-actions[bot]
dd597c613c Merge release-21.05 into staging-next-21.05 2021-10-20 00:08:02 +00:00
Michael Weiss
dc7c702c4e chromium: 94.0.4606.81 -> 95.0.4638.54
https://chromereleases.googleblog.com/2021/10/stable-channel-update-for-desktop_19.html

This update includes 19 security fixes.

CVEs:
CVE-2021-37981 CVE-2021-37982 CVE-2021-37983 CVE-2021-37984
CVE-2021-37985 CVE-2021-37986 CVE-2021-37987 CVE-2021-37988
CVE-2021-37989 CVE-2021-37990 CVE-2021-37991 CVE-2021-37992
CVE-2021-37993 CVE-2021-37996 CVE-2021-37994 CVE-2021-37995

(cherry picked from commit 820b99a77d)
2021-10-19 22:29:22 +02:00
Michael Weiss
12c7b8e13e chromiumBeta: 95.0.4638.49 -> 95.0.4638.54
(cherry picked from commit 338e629f0c)
2021-10-19 22:29:21 +02:00
Michael Weiss
98b786b341 chromiumDev: Fix the build
(cherry picked from commit b0581c2699)
2021-10-19 22:29:19 +02:00
Michael Weiss
0f95b33218 chromiumDev: 96.0.4662.6 -> 96.0.4664.9
(cherry picked from commit df1531f3dc)
2021-10-19 22:29:17 +02:00
Michael Weiss
10828b560b chromium: Drop Python 2
Yay, finally!... \o/ :)
Upstream issue: https://crbug.com/942720

(cherry picked from commit ae522fb7f9)
2021-10-19 22:29:16 +02:00
Michael Weiss
2bf603406b chromiumBeta: 95.0.4638.40 -> 95.0.4638.49
(cherry picked from commit d7e522e803)
2021-10-19 22:29:14 +02:00
Michael Weiss
101abfd618 chromium: Start dropping Python 2
(cherry picked from commit 7e6d80740d)
2021-10-19 22:29:13 +02:00
Michael Weiss
6011e236a5 chromiumDev: 96.0.4655.0 -> 96.0.4662.6
(cherry picked from commit 35a26a5b21)
2021-10-19 22:29:11 +02:00
Michael Weiss
05a460398d chromiumBeta: 95.0.4638.32 -> 95.0.4638.40
(cherry picked from commit a15be1c5f6)
2021-10-19 22:29:09 +02:00
Michael Weiss
fc512032a7 chromiumBeta: 95.0.4638.17 -> 95.0.4638.32
(cherry picked from commit a41e19ca71)
2021-10-19 22:29:08 +02:00
Michael Weiss
d7c4b627a7 chromiumDev: 96.0.4651.0 -> 96.0.4655.0
(cherry picked from commit 1f7f87396c)
2021-10-19 22:29:07 +02:00
José Luis Lafuente
a161b1460d google-chrome: add pipewire dependency
chromium derivation already depends on pipewire. This is required to
share your screen on wayland

(cherry picked from commit 29efb76ab6)
2021-10-19 22:29:05 +02:00
Michael Weiss
37c13136ac chromiumDev: 95.0.4638.17 -> 96.0.4651.0
(cherry picked from commit eba807d594)
2021-10-19 22:29:04 +02:00
legendofmiracles
a9a3b49f8e espanso: add runtime dependencies correctly, nixos/espanso remove path hack
(cherry picked from commit 3e7ec42d68)
2021-10-19 17:02:20 +00:00
maxine [they]
8fe3b97ef4 Merge pull request #141929 from risicle/ris-go-1.17-r21.05
[21.05] go_1_17: init at 1.17.2
2021-10-19 18:43:26 +02:00
Pavol Rusnak
7da20531b7 Merge pull request #142212 from prusnak/trezor-suite-21.05
[21.05] trezor-suite: 21.5.1 -> 21.10.2
2021-10-19 15:22:36 +02:00
Pavol Rusnak
4d4d6e13df trezor-suite: 21.9.2 -> 21.10.2
(cherry picked from commit 7a1ccd76de)
2021-10-19 15:20:50 +02:00
TredwellGit
4ebd0bfe01 trezor-suite: 21.7.1 -> 21.9.2
https://github.com/trezor/trezor-suite/releases/tag/v21.8.1
https://github.com/trezor/trezor-suite/releases/tag/v21.9.1
https://github.com/trezor/trezor-suite/releases/tag/v21.9.2
(cherry picked from commit 13d725f6cd)
2021-10-19 15:20:45 +02:00
TredwellGit
3ed13b4e11 trezor-suite: 21.6.1 -> 21.7.1
https://github.com/trezor/trezor-suite/releases/tag/v21.6.2
https://github.com/trezor/trezor-suite/releases/tag/v21.7.1
(cherry picked from commit 6bc106b604)
2021-10-19 15:20:39 +02:00
Max Hille
73346f192d trezor-suite: remove sandbox startup
(cherry picked from commit ca3af0a389)
2021-10-19 15:20:34 +02:00
TredwellGit
f5c0f60a21 trezor-suite: 21.5.1 -> 21.6.1
https://github.com/trezor/trezor-suite/releases/tag/v21.6.1
(cherry picked from commit 3737a26a18)
2021-10-19 15:20:29 +02:00
Pavol Rusnak
64a023805c Merge pull request #141339 from prusnak/electron-21.05
[21.05] electron_12: 12.2.1 -> 12.2.2
2021-10-19 10:04:20 +02:00
github-actions[bot]
0c17cca35e Merge staging-next-21.05 into staging-21.05 2021-10-19 00:08:23 +00:00
github-actions[bot]
9c89572fd7 Merge release-21.05 into staging-next-21.05 2021-10-19 00:07:48 +00:00
Fabián Heredia Montiel
bfb0f099f0 linux-rt_5_10: 5.10.65-rt53 -> 5.10.73-rt54
(cherry picked from commit 8b9b630e10)
2021-10-18 21:03:34 +00:00
Fabián Heredia Montiel
69a9f948a0 linux: 5.4.153 -> 5.4.154
(cherry picked from commit 664c8144e4)
2021-10-18 21:03:33 +00:00
Fabián Heredia Montiel
28153f9fe0 linux: 5.14.12 -> 5.14.13
(cherry picked from commit a69ff911a3)
2021-10-18 21:03:32 +00:00
Fabián Heredia Montiel
5f2e66e545 linux: 5.10.73 -> 5.10.74
(cherry picked from commit 6b68a5efc1)
2021-10-18 21:03:31 +00:00
Fabián Heredia Montiel
638c4a396c linux: 4.9.286 -> 4.9.287
(cherry picked from commit dc4916976e)
2021-10-18 21:03:30 +00:00
Fabián Heredia Montiel
29286ee93d linux: 4.4.288 -> 4.4.289
(cherry picked from commit e2efd3de26)
2021-10-18 21:03:29 +00:00
Fabián Heredia Montiel
4b55e135ed linux: 4.19.211 -> 4.19.212
(cherry picked from commit 5275780c12)
2021-10-18 21:03:28 +00:00
Fabián Heredia Montiel
5d4c2af1a7 linux: 4.14.250 -> 4.14.251
(cherry picked from commit 62cd542b26)
2021-10-18 21:03:27 +00:00
Pascal Wittmann
51d80a9fc4 Merge pull request #142118 from NixOS/backport-142028-to-release-21.05
[Backport release-21.05] nixos/subsonic: use jre8
2021-10-18 21:56:52 +02:00
Pascal Wittmann
668bbeb2d2 nixos/subsonic: use jre8
The latest version of Subsonic (6.1.6) does not suport Java SE 9 or later
because it depends on the JAXB APIs. Those are considered to be Java EE
APIs are no longer contained on the default classpath in Java SE 9 and
are completely removed in Java SE 11..

(cherry picked from commit 14c5fe8c1b)
2021-10-18 18:49:29 +00:00
Vladimír Čunát
f001876680 Merge #140998: nix: 2.3.15 -> 2.3.16 (into release-21.05) 2021-10-18 11:57:24 +02:00
leo60228
199a0ffe94 multimc: user-provided client ID
(cherry picked from commit 82397b844d)
2021-10-18 00:43:35 +00:00
leo60228
9b0e1cc2a6 multimc: unstable-2021-06-21 -> unstable-2021-09-08
(cherry picked from commit fd48ed5022)
2021-10-18 00:43:35 +00:00
github-actions[bot]
bc2ea55f9a Merge staging-next-21.05 into staging-21.05 2021-10-18 00:08:50 +00:00
github-actions[bot]
6bc09c2cec Merge release-21.05 into staging-next-21.05 2021-10-18 00:08:08 +00:00
Robert Scott
ea8e7d2377 libressl_3_2: add patch for CVE-2021-41581
(cherry picked & modified from commit 01cc988d96)
2021-10-17 22:07:09 +01:00
Michael Weiss
0d05030c80 Merge pull request #141958 from NixOS/backport-141911-to-release-21.05
[Backport release-21.05] signal-desktop: 5.19.0 -> 5.20.0
2021-10-17 13:11:45 +02:00
Maciej Krüger
874af6b484 Merge pull request #141956 from roosemberth/backport-ytdlp 2021-10-17 12:53:59 +02:00
Sandro Jäckel
98a3003e2a yt-dlp: 2021.9.25 -> 2021.10.10 2021-10-17 12:33:56 +02:00
R. RyanTM
6d31c97d24 python38Packages.yt-dlp: 2021.9.2 -> 2021.9.25 2021-10-17 12:33:56 +02:00
Atemu
af706fce73 yt-dlp: add option to install a youtube-dl alias
youtube-dl development seems to have stalled and yt-dlp is the de-facto upstream
nowadays. This provides an easy way to use yt-dlp as a drop-in replacement:

    youtube-dl = yt-dlp.override { withAlias = true; };
2021-10-17 12:33:55 +02:00
Kid
12973b2af5 yt-dlp: remove obsolete postPatch 2021-10-17 12:33:54 +02:00
Ilan Joselevich
bb5e5bf09a yt-dlp: 2021.08.10 -> 2021.9.2 2021-10-17 12:33:53 +02:00
Mario Rodas
1f2818d65d yt-dlp: use PyPI tarball 2021-10-17 12:33:52 +02:00
Sandro Jäckel
8cc518e2a1 yt-dlp: 2021.08.02 -> 2021.08.10 2021-10-17 12:33:51 +02:00
Maciej Krüger
035e4a2462 yt-dlp: 2021.07.21 -> 2021.08.02 2021-10-17 12:33:46 +02:00
Michael Weiss
b0522cfa67 signal-desktop: 5.19.0 -> 5.20.0
(cherry picked from commit 9b3ef21bff)
2021-10-17 09:09:18 +00:00
Maciej Krüger
5ae4146460 yt-dlp: init at 2021.07.21
(cherry picked from commit e40ceba3fc)
2021-10-17 10:34:25 +02:00
Artturi
88b914e7e4 Merge pull request #126216 from NixOS/backport-125525-to-release-21.05 2021-10-17 05:00:32 +03:00
github-actions[bot]
8ef58c0959 Merge staging-next-21.05 into staging-21.05 2021-10-17 00:09:00 +00:00
github-actions[bot]
f751ffc04a Merge release-21.05 into staging-next-21.05 2021-10-17 00:08:20 +00:00
zowoq
f76bb8d91f go_1_17: 1.17.1 -> 1.17.2
(cherry picked from commit 615989e078)
2021-10-16 23:47:37 +01:00
zowoq
071ec50522 buildGo117{Module,Package}: disable, go_1_17: disable on x86_64-darwin
(cherry picked from commit 9675a865c9)
2021-10-16 23:47:19 +01:00
zowoq
a21112d352 go_1_17: init at 1.17.1
(cherry picked from commit 273ff5cf17)
2021-10-16 23:46:51 +01:00
Michael Raskin
3f7c00fe13 Merge pull request #141900 from NixOS/backport-141896-to-release-21.05
[Backport release-21.05] alpine: 2.24 → 2.25
2021-10-16 19:54:39 +00:00
Maximilian Bosch
2c06efb24e Merge pull request #141898 from NixOS/backport-141499-to-release-21.05
[Backport release-21.05] Kernels 2021-10-13
2021-10-16 21:32:58 +02:00
Fabián Heredia Montiel
f32fb0fec6 alpine: 2.24 → 2.25
(cherry picked from commit e849909813)
2021-10-16 18:56:17 +00:00
TredwellGit
3bf1ccc956 linux: 5.4.152 -> 5.4.153
(cherry picked from commit 08d4bb6e7a)
2021-10-16 18:43:14 +00:00
TredwellGit
21274608a8 linux: 5.14.11 -> 5.14.12
(cherry picked from commit 39189bc4f0)
2021-10-16 18:43:13 +00:00
TredwellGit
0ecbad5a42 linux: 5.10.72 -> 5.10.73
(cherry picked from commit 4f59512c0c)
2021-10-16 18:43:12 +00:00
TredwellGit
73e52b0f89 linux: 4.19.210 -> 4.19.211
(cherry picked from commit 821d8339f8)
2021-10-16 18:43:11 +00:00
Maximilian Bosch
2ec14d6c79 Merge pull request #141855 from Ma27/kernel-backports
[21.05] Kernel backports
2021-10-16 20:39:00 +02:00
Aaron Andersen
d892ba359c Merge pull request #141655 from NixOS/backport-141438-to-release-21.05
[Backport release-21.05] redmine: 4.2.2 -> 4.2.3
2021-10-16 10:36:31 -04:00
Maximilian Bosch
102423a3c6 Merge pull request #141420 from NixOS/backport-141364-to-release-21.05
[Backport release-21.05] element-{web,desktop}: 1.9.0 -> 1.9.2
2021-10-16 15:45:04 +02:00
Maximilian Bosch
44ef22423f element-desktop: regenerate yarn deps with yarn2nix from 21.05 2021-10-16 15:07:13 +02:00
Maximilian Bosch
9d7b660576 element-desktop: 1.9.0 -> 1.9.2
ChangeLog: https://github.com/vector-im/element-desktop/releases/tag/v1.9.2
(cherry picked from commit 6f2e2dc7795d20073fa62c1c98f2daf7b8ee6587)
2021-10-16 15:05:56 +02:00
Maximilian Bosch
ba0a1ce211 element-web: 1.9.0 -> 1.9.2
ChangeLog: https://github.com/vector-im/element-web/releases/tag/v1.9.2
(cherry picked from commit b021b8bebd9c8b5e66450519d06fb500e6ac48b8)
2021-10-16 15:05:56 +02:00
Maximilian Bosch
f1e8a51254 linux-libre: unbreak
(cherry picked from commit a8498f08bf)
2021-10-16 10:46:59 +02:00
github-actions[bot]
b4643ab5e2 Merge staging-next-21.05 into staging-21.05 2021-10-16 00:08:51 +00:00
github-actions[bot]
57832f7ded Merge release-21.05 into staging-next-21.05 2021-10-16 00:08:11 +00:00
Timothy DeHerrera
170a9678c7 Merge pull request #141560 from kanashimia/lowdown-0.9.2-backport
[21.05] lowdown-0-9: 0.9.0 -> 0.9.2
2021-10-15 17:24:48 -06:00
TredwellGit
0bf9a9ec4f linux/hardened/patches/5.4: 5.4.150-hardened1 -> 5.4.152-hardened1
(cherry picked from commit c7b05f54df)
2021-10-16 00:11:58 +02:00
TredwellGit
f753f63fe6 linux/hardened/patches/5.14: 5.14.9-hardened1 -> 5.14.11-hardened1
(cherry picked from commit 331bb5fcec)
2021-10-16 00:11:58 +02:00
TredwellGit
c6b4f1cb24 linux/hardened/patches/5.10: 5.10.70-hardened1 -> 5.10.72-hardened1
(cherry picked from commit 42dd28857d)
2021-10-16 00:11:57 +02:00
TredwellGit
80f26c622d linux/hardened/patches/4.19: 4.19.208-hardened1 -> 4.19.210-hardened1
(cherry picked from commit 8df94e6d31)
2021-10-16 00:11:56 +02:00
TredwellGit
2a46e86ddc linux/hardened/patches/4.14: 4.14.248-hardened1 -> 4.14.250-hardened1
(cherry picked from commit 6e94404dc3)
2021-10-16 00:11:56 +02:00
TredwellGit
b522d3a193 linux_latest-libre: 18314 -> 18380
(cherry picked from commit 86589e8cd3)
2021-10-16 00:11:55 +02:00
TredwellGit
df541aa447 linux: 5.4.151 -> 5.4.152
(cherry picked from commit 1d14ebf414)
2021-10-16 00:11:54 +02:00
TredwellGit
7a53e53cd2 linux: 5.14.10 -> 5.14.11
(cherry picked from commit e2be686e0a)
2021-10-16 00:11:53 +02:00
TredwellGit
604d9d9d7a linux: 5.10.71 -> 5.10.72
(cherry picked from commit 2363ead003)
2021-10-16 00:11:53 +02:00
TredwellGit
c4e43b9b47 linux: 4.9.285 -> 4.9.286
(cherry picked from commit 049968322b)
2021-10-16 00:11:52 +02:00
TredwellGit
c52a6ac109 linux: 4.4.287 -> 4.4.288
(cherry picked from commit 97f30440d9)
2021-10-16 00:11:51 +02:00
TredwellGit
90928280cf linux: 4.19.209 -> 4.19.210
(cherry picked from commit 4d1cd369c8)
2021-10-16 00:11:50 +02:00
TredwellGit
1b86320ebb linux: 4.14.249 -> 4.14.250
(cherry picked from commit ac66a2835c)
2021-10-16 00:11:50 +02:00
Tim Steinbach
5f80692d25 linux_latest-libre: 18298 -> 18314
(cherry picked from commit 6a6ff4d0d8)
2021-10-16 00:11:49 +02:00
Artturi
83667ff60a Merge pull request #141767 from NixOS/backport-141759-to-release-21.05 2021-10-15 22:45:40 +03:00
nixpkgs-upkeep-bot
186fe09e08 vscodium: 1.61.0 -> 1.61.1
(cherry picked from commit 50b636fd0e)
2021-10-15 13:34:20 +00:00
Robert Helgesson
c2d521459d emacs-sv-kalender: 1.9 -> 1.11
(cherry picked from commit a319637efbc3ed5500f4e5965c816c3bcc97495a)
2021-10-15 14:08:11 +02:00
github-actions[bot]
0be0270d48 Merge staging-next-21.05 into staging-21.05 2021-10-15 00:08:14 +00:00
github-actions[bot]
c4c49929aa Merge release-21.05 into staging-next-21.05 2021-10-15 00:07:40 +00:00
Fabián Heredia Montiel
1c7804bc30 dico: python2 → python3
(cherry picked from commit ca75c34190)
2021-10-14 23:44:52 +00:00
maxine [they]
bcf61418b6 Merge pull request #141679 from NixOS/backport-141672-to-release-21.05
[Backport release-21.05] vscode: 1.61.0 -> 1.61.1
2021-10-15 00:54:49 +02:00
R. RyanTM
613e50edb7 vscode: 1.61.0 -> 1.61.1
(cherry picked from commit 28a6e2c176)
2021-10-14 22:46:33 +00:00
Robert Scott
2b8743c7f7 Merge pull request #141243 from risicle/ris-tremor-rs-0.11.6-r21.05
[21.05] tremor-rs: 0.11.2 -> 0.11.6
2021-10-14 21:28:01 +01:00
Aaron Andersen
49135ac962 redmine: 4.2.2 -> 4.2.3
(cherry picked from commit a67f960cfc)
2021-10-14 17:48:21 +00:00
Kim Lindberger
7ced81749a Merge pull request #141624 from NixOS/backport-141619-to-release-21.05
[Backport release-21.05] gitlab: 14.3.2 -> 14.3.3
2021-10-14 18:22:25 +02:00
Fabián Heredia Montiel
dcbd707764 crystal: 1.1.1 → 1.2.0
(cherry picked from commit 75d7a40d2e)
2021-10-14 15:43:37 +00:00
Fabián Heredia Montiel
2797da452c crystal: 1.0.0 → 1.1.1
(cherry picked from commit 8a9d300a10)
2021-10-14 15:43:36 +00:00
Maximilian Bosch
a255ac3b23 Merge pull request #141129 from Ma27/nextcloud-secret-backport
[21.05] nixos/nextcloud: put secrets into the environment of nextcloud-setup.service
2021-10-14 15:53:15 +02:00
Lara
06fd3da981 gitlab: 14.3.2 -> 14.3.3
(cherry picked from commit e7331d2e85)
2021-10-14 12:03:20 +00:00
Michael Raskin
0ebb82a648 Merge pull request #141620 from NixOS/backport-141612-to-release-21.05
[Backport release-21.05] leo2: 1.6.2 → 1.7.0
2021-10-14 11:33:46 +00:00
Vincent Laporte
95510a94a5 leo2: 1.6.2 → 1.7.0
Fix build with recent C++ compilers

Use a more recent OCaml (4.05)

(cherry picked from commit cafe9f88fc)
2021-10-14 11:05:40 +00:00
github-actions[bot]
6e7be5a24f Merge staging-next-21.05 into staging-21.05 2021-10-14 00:08:17 +00:00
github-actions[bot]
6c283c1657 Merge release-21.05 into staging-next-21.05 2021-10-14 00:07:38 +00:00
Kanashimia
6aa64a1137 lowdown-0-9: 0.9.0 -> 0.9.2 2021-10-13 22:09:58 +03:00
Vincent Laporte
564cb4d81d alt-ergo: 2.4.0 → 2.4.1
(cherry picked from commit 0abc796ce281eeb737039c12613734d33611658b)
2021-10-13 10:50:22 +02:00
Mario Rodas
6421c8df26 Merge pull request #141460 from marsam/backport-nodejs-21.05
[21.05] nodejs: 12.22.6 -> 12.22.7, 14.17.6 -> 14.18.1, 16.8.0 -> 16.11.1
2021-10-13 01:37:44 -05:00
R. RyanTM
6159be2511 nodejs: 14.18.0 -> 14.18.1
(cherry picked from commit 574ab51aa9)
2021-10-13 00:27:53 -05:00
R. RyanTM
1084c0387c nodejs-16_x: 16.11.0 -> 16.11.1
(cherry picked from commit ed75efa878)
2021-10-13 00:25:31 -05:00
R. RyanTM
9a317d9513 nodejs-12_x: 12.22.6 -> 12.22.7
(cherry picked from commit 611da87f3f)
2021-10-13 00:25:28 -05:00
Mario Rodas
cae668bd06 nodejs-16_x: 16.10.0 -> 16.11.0
https://github.com/nodejs/node/releases/tag/v16.11.0
(cherry picked from commit 545fca99f2)
2021-10-13 00:25:23 -05:00
R. RyanTM
c4f4ea01f3 nodejs: 14.17.6 -> 14.18.0
(cherry picked from commit f5a81c9e61)
2021-10-13 00:25:20 -05:00
R. RyanTM
de72e6df13 nodejs-16_x: 16.9.1 -> 16.10.0
(cherry picked from commit 76ba113d71)
2021-10-13 00:25:17 -05:00
Mario Rodas
24201b1848 nodejs-16_x: 16.9.0 -> 16.9.1
https://github.com/nodejs/node/releases/tag/v16.9.1
(cherry picked from commit 35f805cf9f)
2021-10-13 00:25:14 -05:00
Mario Rodas
404f0f62c5 nodejs-16_x: 16.8.0 -> 16.9.0
https://github.com/nodejs/node/releases/tag/v16.9.0
(cherry picked from commit f60eca11ef)
2021-10-13 00:25:11 -05:00
github-actions[bot]
e882bcae43 [Backport release-21.05] teamviewer: fix #96633, #44307 and #97148 + 15.15.5 -> 15.18.5 -> 15.22.3 (#141439)
* teamviewer: fix issue #96633

Fix teamviewer's breakage post 15.5.3 -> 15.15.5.

Teamviewer client was no longer able to connect to its backing
server as it now uses dbus to do so. Following changes were
required:

 -  add missing dbus and polkit service/policy files to package.
 -  add missing dbus lib to `LD_LIBRARY_PATH`.

Changes to the nixos module as a separate changeset.

(cherry picked from commit 506966d156)

* nixos/teamviewer: fix issue #96633

Add teamviewer package as a dbus package now that the
client / server communication depends on dbus.

(cherry picked from commit 200e959995)

* nixos/teamviewer: fix issue #44307

Move to a forefront launch of the daemon. Doing so allowed us
to move the service from forking to simple to avoid the
missing pid  error log.

Also:

 -  Make the dbus dependency explicit.

(cherry picked from commit 953bbc0d73)

* teamviewer: 15.15.5 -> 15.18.5

Upgrading to the last version still using qt5.14. Later version
will be using qt5.15 which is not in 21.05 stable branch.

This fixes us the crash observed in 15.15.5 when stopping
the service.

(cherry picked from commit db889eb913)

* teamviewer: refactor executable wrapping

This centralizes `PATH` and `LD_LIBRARY_PATH`, avoid multiple
layers of wrappers.

Refactor as suggested by @Artturin in PR provided patch:
<https://github.com/NixOS/nixpkgs/pull/140076#issuecomment-934770391>.

(cherry picked from commit c55bc5bfd3)

* teamviewer: fix 97148 (busybox installed issue)

Simply add `coreutils` as a runtime dependency which will
prevent teamviewer from using incomplete busybox implementation
of expected gnu binaries.

As suggested by @Artturin in PR comment:
<https://github.com/NixOS/nixpkgs/pull/140076#issuecomment-934770391>.

(cherry picked from commit 4fb188e1d1)

* teamviewer: 15.18.5 -> 15.22.3

Required move from libsForQt514 -> libsForQt515.

Note that this changset won't be backportable to 21.05.

(cherry picked from commit 975ab7f3a0)

Co-authored-by: Raymond Gauthier <jraygauthier@gmail.com>
2021-10-13 05:17:24 +03:00
github-actions[bot]
b63fb59b30 Merge staging-next-21.05 into staging-21.05 2021-10-13 00:09:33 +00:00
github-actions[bot]
e1cd43c934 Merge release-21.05 into staging-next-21.05 2021-10-13 00:07:37 +00:00
adisbladis
83070001ea Merge pull request #141389 from NixOS/backport-141379-to-release-21.05
[Backport release-21.05] nanopb: Use protoc from buildPackages
2021-10-12 17:37:22 -05:00
Maximilian Bosch
1950b856d2 Merge pull request #140085 from helsinki-systems/fix/cve-2021-41617
[staging-21.05] openssh: Fix CVE-2021-41617
2021-10-12 22:34:46 +02:00
adisbladis
4e14b76286 nanopb: Use protoc from buildPackages
This fixes cross compilation.

(cherry picked from commit d8b35aa96b)
2021-10-12 18:08:34 +00:00
Silvan Mosberger
d50679e56e Merge pull request #141099 from roberth/nixos-21.05-compat-136909
[21.05] lib.{literalExpression, literalDocBook}: init as shims
2021-10-12 18:18:33 +02:00
Andrea Scarpino
f134749c7e yubikey-manager: patch path of pkill binary (#138941)
(cherry picked from commit 36304fc89d)

Co-authored-by: Yureka <yuka@yuka.dev>
2021-10-12 11:21:29 -04:00
TredwellGit
a712a75ef5 electron_12: 12.2.1 -> 12.2.2
https://github.com/electron/electron/releases/tag/v12.2.2
(cherry picked from commit edbfad1cd5)
2021-10-12 09:09:36 +02:00
github-actions[bot]
3bbc3c36e4 Merge staging-next-21.05 into staging-21.05 2021-10-12 00:08:01 +00:00
github-actions[bot]
0f3c2219a5 Merge release-21.05 into staging-next-21.05 2021-10-12 00:07:23 +00:00
Martin Weinelt
46d06b8aef ansible_2_9: 2.9.26 -> 2.9.27
(cherry picked from commit 390c80228c)
2021-10-11 19:11:43 +00:00
Martin Weinelt
afa5208182 ansible_2_10: 2.10.14 -> 2.10.15
(cherry picked from commit 8be8e6da4e)
2021-10-11 19:11:42 +00:00
Martin Weinelt
6a7e233617 ansible_2_11: 2.11.5 -> 2.11.6
(cherry picked from commit 7ec67dc03c)
2021-10-11 19:11:41 +00:00
Michele Guerini Rocco
79c970a7bb Merge pull request #141277 from NixOS/backport-140723-to-release-21.05
[Backport release-21.05] nixos/fontdir: always link the font directory
2021-10-11 20:28:20 +02:00
rnhmjoj
36d4e53859 nixos/fontdir: always link the font directory
This fixes the fonts directory availability when not running an xserver,
such as headless machines.

(cherry picked from commit a27dc95e72)
2021-10-11 17:45:58 +00:00
Martin Weinelt
b31ab18db6 Merge pull request #140863 from mohe2015/security/wordpress/5.7.3 2021-10-11 17:50:43 +02:00
Domen Kožar
85fafd9024 Merge branch 'release-21.05' into backport-139456-to-release-21.05 2021-10-11 04:49:15 -05:00
Bobby Rong
b313502c71 Merge pull request #141052 from NixOS/backport-141046-to-release-21.05
[Backport release-21.05] vscodium: 1.60.2 -> 1.61.0
2021-10-11 14:46:54 +08:00
github-actions[bot]
d10611cf2d Merge staging-next-21.05 into staging-21.05 2021-10-11 00:08:27 +00:00
github-actions[bot]
377a886760 Merge release-21.05 into staging-next-21.05 2021-10-11 00:07:46 +00:00
Robert Scott
6bc516c45c tremor-rs: 0.11.5 -> 0.11.6
(cherry picked from commit 1837100096)
2021-10-10 23:18:53 +01:00
Akshat Agarwal
b6ffcd17f8 tremor-rs: 0.11.2 -> 0.11.5
(cherry picked from commit 491994686f)
2021-10-10 23:17:33 +01:00
Michael Weiss
7dbe547cf8 Merge pull request #141209 from NixOS/backport-141023-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 94.0.4606.71 -> 94.0.4606.81
2021-10-10 23:48:45 +02:00
Aaron Andersen
3f09236d1e Merge pull request #140981 from NixOS/backport-140969-to-release-21.05
[Backport release-21.05] apacheHttpd: 2.4.50 -> 2.4.51
2021-10-10 17:13:05 -04:00
Robert Scott
e11386a1a6 Merge pull request #141017 from risicle/ris-fix-tix-darwin-r21.05
[21.05] tix: fix build on darwin
2021-10-10 22:02:30 +01:00
Michael Weiss
2ec9c0824a ungoogled-chromium: 94.0.4606.71 -> 94.0.4606.81
(cherry picked from commit 383928815f)
2021-10-10 20:07:02 +00:00
Maximilian Bosch
93ca5ab64f Merge pull request #141163 from lheckemann/release-21.05
[21.05] Revert "nixos/nextcloud: temp fix for MariaDB >=10.6"
2021-10-10 10:04:17 +02:00
Linus Heckemann
4c0edbbb08 Revert "nixos/nextcloud: temp fix for MariaDB >=10.6"
This reverts commit f182b8d23b.

This doesn't need to be on 21.05, because 21.05 doesn't have MariaDB
10.6.

It shouldn't be on 21.05 because the package version warning mentions
21.11, which is confusing and misleading.
2021-10-10 09:34:53 +02:00
github-actions[bot]
f8ecdce26d Merge staging-next-21.05 into staging-21.05 2021-10-10 00:09:50 +00:00
github-actions[bot]
68c697bcb8 Merge release-21.05 into staging-next-21.05 2021-10-10 00:08:07 +00:00
Ryan Burns
9a40f18db3 Merge pull request #141125 from r-burns/fetchmail
[21.05] fetchmail: 6.4.20 -> 6.4.22
2021-10-09 11:51:15 -07:00
Maximilian Bosch
e33cbdc2de nixos/nextcloud: put secrets into the environment of nextcloud-setup.service
The `$(</path/to/file)`-expansion appears verbatim in the cmdline of
`nextcloud-occ` which means that an unprivileged user could find
sensitive values (i.e. admin password & database password) by monitoring
`/proc/<pid>/cmdline`.

Now, these values don't appear in a command line anymore, but will be
passed as environment variables to `nextcloud-occ`.

(cherry picked from commit 9f37d6aee0)
2021-10-09 20:05:38 +02:00
Thomas Gerbet
7e52686fc8 fetchmail: 6.4.21 -> 6.4.22
Fixes CVE-2021-39272.

(cherry picked from commit 34c98d248e)
2021-10-09 10:57:45 -07:00
Sandro Jäckel
7b1bdbff58 fetchmail: cleanup
(cherry picked from commit cb2d6f5b4a)
2021-10-09 10:57:38 -07:00
R. RyanTM
5c5ca64a83 fetchmail: 6.4.20 -> 6.4.21
(cherry picked from commit 1d8b058fa0)
2021-10-09 10:56:45 -07:00
Michael Weiss
e358eec704 Merge pull request #141030 from NixOS/backport-141020-to-release-21.05
[Backport release-21.05] chromium: 94.0.4606.71 -> 94.0.4606.81
2021-10-09 19:01:09 +02:00
Pavol Rusnak
7cdc04db5a Merge pull request #140352 from prusnak/electron-21.05
electron_12: 12.1.2 -> 12.2.1
2021-10-09 17:56:41 +02:00
Robert Hensing
dcfdb79b09 lib.{literalExpression, literalDocBook}: init as shims
Compatibility shims for https://github.com/NixOS/nixpkgs/pull/136909
2021-10-09 15:00:00 +02:00
Maximilian Bosch
0c106b8ef3 Merge pull request #140748 from Ma27/bump-grafana-2105
[21.05] grafana: 7.5.10 -> 7.5.11, fix CVE-2021-39226
2021-10-09 13:33:45 +02:00
nixpkgs-upkeep-bot
16d37ec2a2 vscodium: 1.60.2 -> 1.61.0
(cherry picked from commit d02c87a392)
2021-10-09 00:59:59 +00:00
github-actions[bot]
5e115d6e65 Merge staging-next-21.05 into staging-21.05 2021-10-09 00:07:28 +00:00
github-actions[bot]
595b8e0d99 Merge release-21.05 into staging-next-21.05 2021-10-09 00:06:54 +00:00
Maximilian Bosch
0f4ceae398 Merge pull request #140522 from sternenseemann/stable-lowdown-0.9.0
[21.05]  nixUnstable: 2.4pre20210922 -> 2.4pre20211006 ; init lowdown-0-9
2021-10-09 01:57:33 +02:00
Maximilian Bosch
0dde2c5c55 Merge pull request #140991 from NixOS/backport-139916-to-release-21.05
[Backport release-21.05] matrix-synapse: 1.43.0 -> 1.44.0
2021-10-09 00:44:08 +02:00
Michael Weiss
b68a066466 chromium: 94.0.4606.71 -> 94.0.4606.81
https://chromereleases.googleblog.com/2021/10/stable-channel-update-for-desktop.html

This update includes 4 security fixes.

CVEs:
CVE-2021-37977 CVE-2021-37978 CVE-2021-37979 CVE-2021-37980

(cherry picked from commit d406bca746)
2021-10-08 21:38:26 +00:00
R. RyanTM
8201f9bb69 python38Packages.vyper: 0.2.16 -> 0.3.0
(cherry picked from commit e47dd11f4a)
2021-10-08 21:56:19 +01:00
R. RyanTM
abe56759a8 python38Packages.vyper: 0.2.15 -> 0.2.16
(cherry picked from commit 1025f27189)
2021-10-08 21:55:57 +01:00
Ben Siraphob
6744ef6777 vyper: 0.2.11 -> 0.2.15
(cherry picked from commit 63510151a8)
2021-10-08 21:55:30 +01:00
Ryan Burns
469c60729c tix: fix build on darwin
(cherry picked from commit 56d9b43336)
2021-10-08 21:45:47 +01:00
Ryan Burns
6daa24234f tk: fix missing definition in macOS header
(cherry picked from commit a86e1f5dac)
2021-10-08 21:45:15 +01:00
Bruno BELANYI
ac9ea0dbd9 python3Packages.pypdf3: init at 1.0.5
(cherry picked from commit fb81b07672)
2021-10-08 11:14:44 -07:00
Pavel Borzenkov
73fbbdab68 calibre-web: 0.6.12 -> 0.6.13
calibre-web no longer starts without proper calibre DB path configured,
so the default testcase (completely unconfigured) is removed.

(cherry picked from commit 80f7656229)
2021-10-08 11:14:44 -07:00
Bruno BELANYI
89a82934e3 calibre-web: 0.6.11 -> 0.6.12
(cherry picked from commit 62bdc5114a)
2021-10-08 11:14:44 -07:00
Arthur Gautier
0ec1a295f4 nix: 2.3.15 -> 2.3.16
Signed-off-by: Arthur Gautier <baloo@superbaloo.net>
(cherry picked from commit 202554980a)
2021-10-08 16:16:34 +00:00
Domen Kožar
ce7a1190a0 Merge pull request #140986 from NixOS/backport-140972-to-release-21.05
[Backport release-21.05] vscode: 1.60.2 -> 1.61.0
2021-10-08 11:14:43 -05:00
Sumner Evans
ece2e27a1f matrix-synapse: 1.43.0 -> 1.44.0
(cherry picked from commit 4813681933)
2021-10-08 15:33:12 +00:00
nixpkgs-upkeep-bot
9380a68a99 vscode: 1.60.2 -> 1.61.0
(cherry picked from commit ebf42c50c7)
2021-10-08 14:47:56 +00:00
Aaron Andersen
97c8870372 apacheHttpd: 2.4.50 -> 2.4.51
(cherry picked from commit 7381e553a5)
2021-10-08 14:07:53 +00:00
Maximilian Bosch
bc66bad58c Merge pull request #140903 from NixOS/backport-140765-to-release-21.05
[Backport release-21.05] Kernels 2021-10-07
2021-10-08 15:50:23 +02:00
figsoda
0fcfd8743d Merge pull request #140978 from NixOS/backport-140736-to-release-21.05
[Backport release-21.05] github-runner: 2.283.1 -> 2.283.3
2021-10-08 09:45:09 -04:00
Vincent Haupert
287cf39c34 github-runner: 2.283.1 -> 2.283.3
(cherry picked from commit f6db206386)
2021-10-08 13:27:25 +00:00
figsoda
af281087f8 Merge pull request #140936 from NixOS/backport-139023-to-release-21.05
[Backport release-21.05] github-runner: 2.282.1 -> 2.283.1
2021-10-08 08:09:04 -04:00
R. RyanTM
55c082a0b4 github-runner: 2.282.1 -> 2.283.1
(cherry picked from commit e095423d1b)
2021-10-08 06:24:50 +00:00
figsoda
2f47065bcd Merge pull request #134922 from NixOS/backport-126035-to-release-21.05
[Backport release-21.05] gitui: 0.16.0 -> 0.16.1
2021-10-07 22:50:48 -04:00
figsoda
b9e787a6c4 Merge pull request #135304 from NixOS/backport-135150-to-release-21.05
[Backport release-21.05] nixos/rspamd: Avoid empty postfix service
2021-10-07 22:49:12 -04:00
figsoda
7b0b7ff241 Merge pull request #138194 from NixOS/backport-138115-to-release-21.05
[Backport release-21.05] github-runner: 2.282.0 -> 2.282.1
2021-10-07 22:46:40 -04:00
figsoda
b6d56faa55 Merge pull request #137036 from NixOS/backport-137016-to-release-21.05
[Backport release-21.05] ccloud-cli: 1.25 > 1.39
2021-10-07 22:45:42 -04:00
figsoda
89ac315820 Merge pull request #139584 from NixOS/backport-139457-to-release-21.05
[Backport release-21.05] feh: 3.7.1 -> 3.7.2
2021-10-07 22:43:00 -04:00
github-actions[bot]
e5a64907e5 Merge staging-next-21.05 into staging-21.05 2021-10-08 00:08:01 +00:00
github-actions[bot]
804d67f970 Merge release-21.05 into staging-next-21.05 2021-10-08 00:07:28 +00:00
TredwellGit
f6bf69beca linux: 5.4.150 -> 5.4.151
(cherry picked from commit d609f3d79b)
2021-10-07 22:04:20 +00:00
TredwellGit
2e9cb70a2a linux: 5.14.9 -> 5.14.10
(cherry picked from commit 86eb5c0943)
2021-10-07 22:04:19 +00:00
TredwellGit
4388bb53c9 linux: 5.10.70 -> 5.10.71
(cherry picked from commit 6a1f123725)
2021-10-07 22:04:18 +00:00
TredwellGit
50e3d6910d linux: 4.9.284 -> 4.9.285
(cherry picked from commit e7e463220d)
2021-10-07 22:04:17 +00:00
TredwellGit
c3b82359c4 linux: 4.4.285 -> 4.4.287
(cherry picked from commit 1dfb79c887)
2021-10-07 22:04:16 +00:00
TredwellGit
f818ceb30a linux: 4.19.208 -> 4.19.209
(cherry picked from commit 098ad9636c)
2021-10-07 22:04:15 +00:00
TredwellGit
9785fffe00 linux: 4.14.248 -> 4.14.249
(cherry picked from commit 8d2f3a9fb1)
2021-10-07 22:04:14 +00:00
Robert Scott
96cf5a2b2d Merge pull request #140785 from risicle/ris-onionshare-known-vulnerabilities-r21.05
[21.05] onionshare: mark as vulnerable to CVE-2021-41867, CVE-2021-41868
2021-10-07 20:33:54 +01:00
Doron Behar
b1f47c7167 Merge pull request #140654 from kini/backport/zoom-us-version-updates 2021-10-07 19:16:47 +00:00
Timothy DeHerrera
781b1f8e3a create-amis.sh: fix typo
(cherry picked from commit 3988440b124fc0576fda52d9753a640c1304dcd1)
2021-10-07 09:43:49 -07:00
Timothy DeHerrera
db82eef3ec create-amis.sh: use status message
The progress ID is fairly useless. Status message is more useful for
humans.

(cherry picked from commit 4410ccc211c9127f343d8dceada26e9ba0f72687)
2021-10-07 09:43:49 -07:00
Timothy DeHerrera
ff568a49ec create-amis.sh: add support for the ZFS AMIs
(cherry picked from commit 46bbf738eaebf82cf59391d38f5a9d77ecf53049)
2021-10-07 09:43:49 -07:00
Timothy DeHerrera
9e5f907d1d create-amis.sh: allow uploading private AMIs
(cherry picked from commit 423a70d4ee31bc9b1bbac3ccbb87b7085826fd81)
2021-10-07 09:43:49 -07:00
Timothy DeHerrera
e33873f610 create-amis.sh: make vars overridable from env
(cherry picked from commit 0ffd7d80cab0e5e3e152d678e0107be3438cfda8)
2021-10-07 09:43:49 -07:00
Neubauer, Sebastian
b61229ffe8 arcanist: Update certs to fix letsencrypt
Due to the old root certificate used by letsencrypt expiring, arcanist
could not connect anymore to servers using letsencrypt (like
reviews.llvm.org).

Fix it by using the default nix certificates.

(cherry picked from commit 93eb7786c9)
2021-10-07 11:50:20 -04:00
Moritz Hedtke
ac2dea2208 wordpress: 5.7.2 -> 5.7.3 2021-10-07 17:08:28 +02:00
Artturi
ab54145047 Merge pull request #140859 from NixOS/backport-132077-to-release-21.05
[Backport release-21.05] cargo-criterion: 1.0.1 -> 1.1.0
2021-10-07 17:47:54 +03:00
R. RyanTM
bb3fe4d426 cargo-criterion: 1.0.1 -> 1.1.0
(cherry picked from commit 4e0d282b7f)
2021-10-07 14:22:46 +00:00
Sergei Trofimovich
4bf640bb9b nixUnstable: pre20211001 -> pre20211006
The specific reason to update is to pull in logging fix:
  c6718a9d950214 "Don't reset the logger in a vfork"

Otherwise 'nix build' does not report build progress correctly.

(cherry picked from commit 5323bc0f14)
2021-10-07 12:12:49 +02:00
Martin Weinelt
215c25348c Merge pull request #140759 from mweinelt/21.05/firefox 2021-10-07 10:39:40 +02:00
github-actions[bot]
2042cbaaca Merge staging-next-21.05 into staging-21.05 2021-10-07 00:06:53 +00:00
github-actions[bot]
5d59ca3a0e Merge release-21.05 into staging-next-21.05 2021-10-07 00:06:17 +00:00
Artturi
49017a1c5a Merge pull request #140728 from NixOS/backport-140716-to-release-21.05
[Backport release-21.05] steam: 1.0.0.70 -> 1.0.0.72
2021-10-07 02:49:07 +03:00
Artturi
378104a43e Merge pull request #140729 from NixOS/backport-140711-to-release-21.05
[Backport release-21.05] steamPackages.steam-runtime: 0.20210630.0 -> 0.20210906.1
2021-10-07 02:48:17 +03:00
John Ericson
07c32b3213 Merge pull request #138322 from obsidiansystems/fix-build-rust-crate-cross-21.05
[Backport release-21.05] buildRustCrate: Fix some things for cross builds
2021-10-06 19:20:03 -04:00
John Ericson
da95ae8e3d buildRustCrate: Don't override the linker during cross
lld is sometimes need. The caller can do that instead.
2021-10-06 19:02:32 -04:00
John Ericson
680ff1bb81 buildRustCrate: Add extraRustcOptsForBuildRs
`extraRustcOpts` should not be used for build.rs, lest it contain
host-platform-specific options during cross builds.
2021-10-06 19:02:27 -04:00
Michael Weiss
b8f6eb7300 Merge pull request #140793 from NixOS/backport-140782-to-release-21.05
[Backport release-21.05] signal-desktop: 5.18.1 -> 5.19.0
2021-10-06 22:01:19 +02:00
Michael Weiss
4600fc24a2 signal-desktop: 5.18.1 -> 5.19.0
(cherry picked from commit b9bc0b9480)
2021-10-06 19:07:32 +00:00
Robert Scott
751c22c7f5 onionshare: mark as vulnerable to CVE-2021-41867, CVE-2021-41868
bumping to a fixed version would require bumping tor, and patching
doesn't appear simple.
2021-10-06 18:32:43 +01:00
Michael Weiss
36a05ec28e Merge pull request #140680 from NixOS/backport-140659-to-release-21.05
[Backport release-21.05] signal-desktop: 5.18.0 -> 5.18.1
2021-10-06 19:15:06 +02:00
Vladimír Čunát
e81d8c1fdc Merge branch 'staging-next-21.05' into release-21.05 2021-10-06 18:36:09 +02:00
Martin Weinelt
9fc7bea600 firefox-bin: 92.0.1 -> 93.0
(cherry picked from commit 50bf075202)
2021-10-06 15:00:32 +02:00
Martin Weinelt
93e9e59d63 firefox-esr-78: 78.14.0esr -> 78.15.0esr
(cherry picked from commit e4574610ca)
2021-10-06 15:00:23 +02:00
Martin Weinelt
e09bee748f firefox-esr-91: 91.1.0esr -> 91.2.0esr
(cherry picked from commit 1edb8c9622)
2021-10-06 14:59:54 +02:00
Martin Weinelt
5c7df0b18c firefox: 92.0.1 -> 93.0
(cherry picked from commit 7dfcaf5e73)
2021-10-06 14:59:13 +02:00
Martin Weinelt
980a9792cd Merge pull request #140653 from alyssais/firefox-bin-21.05 2021-10-06 14:55:29 +02:00
github-actions[bot]
e3c40a63c5 Merge staging-next-21.05 into staging-21.05 2021-10-06 12:04:29 +00:00
github-actions[bot]
abc23b9979 Merge release-21.05 into staging-next-21.05 2021-10-06 12:03:51 +00:00
Maximilian Bosch
75415b03c0 grafana: 7.5.10 -> 7.5.11, fix CVE-2021-39226
ChangeLog: https://github.com/grafana/grafana/releases/tag/v7.5.11
Follow-up on 21.05 for #140718
2021-10-06 13:15:56 +02:00
Aaron Andersen
6bef9f9f85 Merge pull request #140631 from NixOS/backport-140606-to-release-21.05
[Backport release-21.05] apacheHttpd: 2.4.49 -> 2.4.50
2021-10-06 05:52:41 -04:00
TredwellGit
78412cdde1 steamPackages.steam-runtime: 0.20210630.0 -> 0.20210906.1
(cherry picked from commit 7e5136fcc4)
2021-10-06 07:46:27 +00:00
TredwellGit
93f8812cbb steam: 1.0.0.70 -> 1.0.0.72
(cherry picked from commit 5ac32013ca)
2021-10-06 07:43:51 +00:00
github-actions[bot]
f043bf40d1 Merge staging-next-21.05 into staging-21.05 2021-10-06 00:03:33 +00:00
github-actions[bot]
511690c873 Merge release-21.05 into staging-next-21.05 2021-10-06 00:02:54 +00:00
Michael Weiss
991271a13e signal-desktop: 5.18.0 -> 5.18.1
(cherry picked from commit d98ed0520b)
2021-10-05 20:57:06 +00:00
Alyssa Ross
a73053ed88 firefox-bin: fix license
The Mozilla Trademark Policy is not a license, and applies equally to
our own source builds of Firefox, so it doesn't make sense to mark the
package as unfree because of that.

Quoting <about:license>:

> Binaries of this product have been made available to you by the
> Mozilla Project under the Mozilla Public License 2.0 (MPL).

Since all this does is download a large binary and wrap it, there's
still no point in it ending up in cache.nixos.org, so disable it on
Hydra now that Hydra would otherwise try to build it.

(cherry picked from commit 6a71c7eb1acc70e5cc023dc7e1c9d1a144b9ca82)
2021-10-05 20:02:37 +00:00
Sandro
16de7c2931 Merge pull request #140656 from Ma27/mautrix-telegram-2105-eval 2021-10-05 20:13:55 +02:00
Maximilian Bosch
3100e48e86 mautrix-telegram: fix eval 2021-10-05 20:07:02 +02:00
github-actions[bot]
057172c591 Merge staging-next-21.05 into staging-21.05 2021-10-05 18:03:08 +00:00
github-actions[bot]
77d8348f02 Merge release-21.05 into staging-next-21.05 2021-10-05 18:02:33 +00:00
Alyssa Ross
9177707228 firefox-bin: 92.0 -> 92.0.1
(cherry picked from commit b256715457)
2021-10-05 17:52:04 +00:00
Tim Steinbach
da7dc9f0fe firefox-bin-unwrapped: 91.0.2 -> 92.0
(cherry picked from commit 0247d6f922)
2021-10-05 17:51:02 +00:00
Clemens Lutz
3b736b932c zoom-us: 5.7.31792.0820 -> 5.8.0.16
Old versions have been blacklisted serverside.

(cherry picked from commit 54c3a9d6f8)
2021-10-05 10:08:41 -07:00
Emmanuel Rosa
0be7f243d7 zoom-us: 5.7.29123.0808 -> 5.7.31792.0820
Old versions have been blacklisted serverside.

(cherry picked from commit 5bb77e3ad9)
2021-10-05 10:08:26 -07:00
R. RyanTM
c486a1117b zoom-us: 5.7.28991.0726 -> 5.7.29123.0808
Old versions have been blacklisted serverside.

(cherry picked from commit cc7a5e69e3)
2021-10-05 10:08:09 -07:00
Vanilla
cab4612319 zoom-us: 5.7.28852.0718 -> 5.7.28991.0726
Old versions have been blacklisted serverside.

(cherry picked from commit 8d3fd95037)
2021-10-05 10:01:11 -07:00
Maximilian Bosch
4f7121d8d0 Merge pull request #140633 from NixOS/backport-140592-to-release-21.05
[Backport release-21.05] mautrix-telegram: add `prometheus-client` for metrics
2021-10-05 17:41:28 +02:00
Maximilian Bosch
e484541615 mautrix-telegram: add prometheus-client for metrics
With this change I can do

    metrics:
        enabled: true
        listen_port: 8080

and retrieve metrics from `localhost:8080` for the telegram bridge.

(cherry picked from commit 9f9e32238b)
2021-10-05 15:38:32 +00:00
Aaron Andersen
7c8412bccc apacheHttpd: 2.4.49 -> 2.4.50
(cherry picked from commit b17c155720)
2021-10-05 15:34:06 +00:00
github-actions[bot]
c031c9869f Merge staging-next-21.05 into staging-21.05 2021-10-05 12:02:52 +00:00
github-actions[bot]
4c04a989b3 Merge release-21.05 into staging-next-21.05 2021-10-05 12:02:15 +00:00
Bobby Rong
aff647e270 Merge pull request #140449 from michaeladler/backport-140203-to-release-21.05
[21.05] brave: 1.25.68 -> 1.30.87
2021-10-05 16:29:02 +08:00
github-actions[bot]
97c6ed64eb Merge staging-next-21.05 into staging-21.05 2021-10-05 00:03:31 +00:00
github-actions[bot]
7d0d1045a0 Merge release-21.05 into staging-next-21.05 2021-10-05 00:02:51 +00:00
Mario Rodas
89c71aa978 Merge pull request #140491 from NixOS/backport-140482-to-release-21.05
[Backport release-21.05] redis: 6.2.5 -> 6.2.6
2021-10-04 18:26:10 -05:00
maralorn
9590b4283d Merge pull request #140518 from sternenseemann/hls-fix-stable
[21.05] haskell-language-server: remove ghc8107 from the wrapper
2021-10-04 22:02:08 +02:00
sternenseemann
a8dc6be3c8 nixUnstable: 2.4pre20210922 -> 2.4pre20211001
Now depends on lowdown >= 0.9.

(cherry picked from commit 25da0b3bbb)
2021-10-04 21:48:58 +02:00
sternenseemann
fe5e97cd74 lowdown-0-9: init at 0.9.0
Backport 6ea6a232cc as a separate
attribute to save us from a breaking change (newer version needed
by nixUnstable).
2021-10-04 21:46:43 +02:00
sternenseemann
849fed9f96 haskell-language-server: remove ghc8107 from the wrapper
GHC 8.10.7 is only in 21.05 for bootstrapping GHCJS, so it shouldn't be
included in the hls wrapper. This change was a result of an overeager
backport and we'll revert it here.

Also rollback some unnecessary change to release-haskell.nix, so it can
be used for testing evaluation still.
2021-10-04 21:31:30 +02:00
John Ericson
6314733b4e Merge pull request #140507 from obsidiansystems/newlib-nano-21.05
[backport release 21.05]: newlib: Add parameter for "nano" variant
2021-10-04 15:21:22 -04:00
Lara
6d0ceff09d gitlab: 14.3.1 -> 14.3.2
(cherry picked from commit b00924518c5b580ffec242e4c7ee8521ce041ac7)
2021-10-04 20:55:06 +02:00
John Ericson
92162ff87f newlib-nano: Init
This ensures CI tests the nano variant. It also makes it easier to use
with `libc = "newlib-nano";` in a platform description.

(cherry picked from commit e3ff6189f6)
2021-10-04 13:53:03 -04:00
Mario Rodas
4c4cc6f430 redis: 6.2.5 -> 6.2.6
https://github.com/redis/redis/releases/tag/6.2.6
(cherry picked from commit 6ea41eaabb)
2021-10-04 14:52:52 +00:00
github-actions[bot]
7d30fb1ad9 Merge staging-next-21.05 into staging-21.05 2021-10-04 12:03:11 +00:00
github-actions[bot]
905a205f48 Merge release-21.05 into staging-next-21.05 2021-10-04 12:02:33 +00:00
Kim Lindberger
751110a6f6 Merge pull request #140454 from NixOS/backport-140133-to-release-21.05
[Backport release-21.05] discourse: Make sure the notification email setting applies
2021-10-04 11:37:43 +02:00
talyz
1c5946027c discourse: Make sure the notification email setting applies
Discourse normally overrides the default notification email setting,
which makes the `notificationEmailAddress` setting ineffective. Add a
patch to remove this override.

Fixes #140114.

(cherry picked from commit 917a0cfe47)
2021-10-04 08:03:15 +00:00
Michael Adler
a3903d58c2 brave: 1.25.68 -> 1.30.87
this fixes many high-severity CVEs

(cherry picked from commit b2f46b6e80)
2021-10-04 08:56:59 +02:00
github-actions[bot]
d551e4d6c7 Merge staging-next-21.05 into staging-21.05 2021-10-04 06:03:05 +00:00
github-actions[bot]
2e93bc0a52 Merge release-21.05 into staging-next-21.05 2021-10-04 06:02:28 +00:00
Bobby Rong
2406a0b2b8 Merge pull request #140269 from NixOS/backport-140219-to-release-21.05
[Backport release-21.05] vscodium: 1.60.1 -> 1.60.2
2021-10-04 13:32:38 +08:00
github-actions[bot]
dba3b2add4 Merge staging-next-21.05 into staging-21.05 2021-10-04 00:03:51 +00:00
github-actions[bot]
19307fbe2b Merge release-21.05 into staging-next-21.05 2021-10-04 00:03:14 +00:00
Lara
8df64b01d9 gitlab: 14.2.4 -> 14.3.1
(cherry picked from commit fbd051169d315593042344b1b1b6438db91914ce)
2021-10-03 23:38:12 +02:00
ajs124
80c3715e2c Merge pull request #140395 from NixOS/backport-140371-to-release-21.05
[Backport release-21.05] openssh_hpn/openssh_gssapi: Add CVE-2021-41617
2021-10-03 22:26:07 +02:00
github-actions[bot]
28796cd12c Merge staging-next-21.05 into staging-21.05 2021-10-03 18:03:08 +00:00
github-actions[bot]
14d9fbcd6c Merge release-21.05 into staging-next-21.05 2021-10-03 18:02:13 +00:00
Maximilian Bosch
9de38b8522 Merge pull request #138803 from NixOS/backport-138020-to-release-21.05
[Backport release-21.05] tor-browser-bundle-bin: 10.5.5 -> 10.5.6
2021-10-03 19:55:46 +02:00
Sandro
d550d4ebd5 Merge pull request #140391 from nlewo/foreman 2021-10-03 19:06:41 +02:00
Janne Heß
eeb23319ec openssh_hpn/openssh_gssapi: Add CVE-2021-41617
(cherry picked from commit bc56346bcd)
2021-10-03 16:26:23 +00:00
Antoine Eiche
cbc3b23cf0 foreman: bundled with 2.1.4
The version update has been cherrypicked from master where bundle has
been updated to 2.2.20. It was then failing to run with:

    ./result/bin/foreman
    Warning: the running version of Bundler (2.1.4) is older than the version that created the lockfile (2.2.20). We suggest you to upgrade to the version that created the lockfile by running `gem install bundler:2.2.20`.
    Traceback (most recent call last):
    	2: from ./result/bin/foreman:20:in `<main>'
    	1: from /nix/store/ggqacj06n6qfm1iww0bih9ph0j89wcna-bundler-2.1.4/lib/ruby/gems/2.7.0/gems/bundler-2.1.4/lib/bundler/rubygems_integration.rb:413:in `block in replace_bin_path'
    /nix/store/ggqacj06n6qfm1iww0bih9ph0j89wcna-bundler-2.1.4/lib/ruby/gems/2.7.0/gems/bundler-2.1.4/lib/bundler/rubygems_integration.rb:374:in `block in replace_bin_path': can't find executable foreman for gem foreman. foreman is not currently included in the bundle, perhaps you meant to add it to your Gemfile? (Gem::Exception)
2021-10-03 17:38:08 +02:00
figsoda
7aa0a65b00 Merge pull request #140384 from NixOS/backport-139925-to-release-21.05
[Backport release-21.05] psi-notify: move systemd unit to $out/lib
2021-10-03 11:16:13 -04:00
Eduard Bachmakov
336da77eac psi-notify: move systemd unit to $out/lib
In $out/share it is NOT picked up into /etc/systemd/... when psi-notify is
added to configuration.systemd.packages .

(Originally put in $out/share b/c a hook copies from $out/lib into there
... so why not just put there? This is why.)

(cherry picked from commit a774af3605)
2021-10-03 15:13:17 +00:00
José Romildo
7daf35532d xfce.xfce4-notifyd: enable starting the daemon via DBus
Start daemon via DBus instead of regular session autostart (which is
the default)

(cherry picked from commit b81ba2e919)
2021-10-03 15:32:46 +02:00
github-actions[bot]
937e114200 Merge staging-next-21.05 into staging-21.05 2021-10-03 12:03:05 +00:00
github-actions[bot]
58ba3deac4 Merge release-21.05 into staging-next-21.05 2021-10-03 12:02:32 +00:00
Michael Weiss
7bc4490174 Merge pull request #140262 from NixOS/backport-140195-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 94.0.4606.61 -> 94.0.4606.71
2021-10-03 13:50:59 +02:00
TredwellGit
13834caa45 electron_12: 12.1.2 -> 12.2.1
https://github.com/electron/electron/releases/tag/v12.2.0
https://github.com/electron/electron/releases/tag/v12.2.1
(cherry picked from commit 8ce19c9399)
2021-10-03 09:55:17 +02:00
github-actions[bot]
87ae26dcc8 Merge staging-next-21.05 into staging-21.05 2021-10-03 00:04:01 +00:00
github-actions[bot]
1b5f78eb1e Merge release-21.05 into staging-next-21.05 2021-10-03 00:03:22 +00:00
Lassulus
966add9f99 Merge pull request #140084 from NixOS/backport-139931-to-release-21.05
[Backport release-21.05] exim: 4.94.2 -> 4.95
2021-10-03 01:07:55 +02:00
maxine [they]
8686a8f1f8 Merge pull request #138795 from NixOS/backport-138761-to-release-21.05
[Backport release-21.05] webkitgtk: 2.32.3 -> 2.32.4
2021-10-02 23:03:49 +02:00
github-actions[bot]
f3cbc81608 [Backport release-21.05] analog: Fix substitution so it can find its language files (#140313)
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
Co-authored-by: Philippe Hürlimann <p@hurlimann.org>
Co-authored-by: Artturi <Artturin@artturin.com>
2021-10-02 23:24:44 +03:00
github-actions[bot]
b7f5285467 Merge staging-next-21.05 into staging-21.05 2021-10-02 18:02:51 +00:00
github-actions[bot]
ab96577bde Merge release-21.05 into staging-next-21.05 2021-10-02 18:02:19 +00:00
Vladimír Čunát
400994665e Merge #140243: Revert "fragments: init at 1.5"
...into release-21.05
2021-10-02 18:49:48 +02:00
Maximilian Bosch
520179f220 Merge pull request #140187 from Ma27/backport-php
[21.05] php: 7.4.23 -> 7.4.24, 8.0.10 -> 8.0.11
2021-10-02 14:07:58 +02:00
nixpkgs-upkeep-bot
87d735ca6b vscodium: 1.60.1 -> 1.60.2
(cherry picked from commit 4da83b53d9)
2021-10-02 12:05:14 +00:00
github-actions[bot]
7150f605ae Merge staging-next-21.05 into staging-21.05 2021-10-02 12:02:45 +00:00
github-actions[bot]
3b675b8346 Merge release-21.05 into staging-next-21.05 2021-10-02 12:02:12 +00:00
Michael Weiss
438faef08c ungoogled-chromium: 94.0.4606.61 -> 94.0.4606.71
(cherry picked from commit 360707c5d6)
2021-10-02 10:16:06 +00:00
Michael Weiss
0d47c5af6d Merge pull request #140251 from NixOS/backport-140194-to-release-21.05
[Backport release-21.05] chromium: 94.0.4606.61 -> 94.0.4606.71
2021-10-02 12:11:23 +02:00
Maximilian Bosch
31dc6d3c50 Merge pull request #140215 from NixOS/backport-140110-to-release-21.05
[Backport release-21.05] Kernels 2021-09-30
2021-10-02 11:08:07 +02:00
Vladimír Čunát
c3e1395498 Revert part of "Merge #140069: transmission: fixes ..."
This reverts commit ff12d52832, reversing
changes made to 92609f3d9b (partially).
2021-10-02 11:06:48 +02:00
Michael Weiss
670ee4d5b6 chromium: 94.0.4606.61 -> 94.0.4606.71
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_30.html

This update includes 4 security fixes. Google is aware the exploits for
CVE-2021-37975 and CVE-2021-37976 exist in the wild.

CVEs:
CVE-2021-37974 CVE-2021-37975 CVE-2021-37976

(cherry picked from commit ce50eda394)
2021-10-02 08:07:36 +00:00
Vladimír Čunát
7dc32438a8 Revert "[Backport release-21.05] fragments: init at 1.5" 2021-10-02 08:58:27 +02:00
github-actions[bot]
7b5bae994e Merge staging-next-21.05 into staging-21.05 2021-10-02 00:09:53 +00:00
github-actions[bot]
9734485fcc Merge release-21.05 into staging-next-21.05 2021-10-02 00:09:08 +00:00
TredwellGit
60ca87841f linux/hardened/patches/5.4: 5.4.149-hardened1 -> 5.4.150-hardened1
(cherry picked from commit 642ca73937)
2021-10-01 23:34:04 +00:00
TredwellGit
068683802e linux/hardened/patches/5.14: 5.14.8-hardened1 -> 5.14.9-hardened1
(cherry picked from commit dd93aec4c4)
2021-10-01 23:34:04 +00:00
TredwellGit
925681abe4 linux/hardened/patches/5.10: 5.10.69-hardened1 -> 5.10.70-hardened1
(cherry picked from commit f178ff4a04)
2021-10-01 23:34:03 +00:00
TredwellGit
6f5e339c3d linux: 5.4.149 -> 5.4.150
(cherry picked from commit 6937daff0d)
2021-10-01 23:34:02 +00:00
TredwellGit
c124a09c04 linux: 5.14.8 -> 5.14.9
(cherry picked from commit b540e8b5a9)
2021-10-01 23:34:01 +00:00
TredwellGit
433135b468 linux: 5.10.69 -> 5.10.70
(cherry picked from commit 8417ed79d8)
2021-10-01 23:34:01 +00:00
Maximilian Bosch
e134154396 Merge pull request #139662 from NixOS/backport-139658-to-release-21.05
[Backport release-21.05] Kernels 2021-09-27
2021-10-01 22:34:24 +02:00
Maximilian Bosch
6385534d45 Merge pull request #140188 from NixOS/backport-140159-to-release-21.05
[Backport release-21.05] nextcloud: misc changes
2021-10-01 21:46:28 +02:00
Maximilian Bosch
50b29bf6aa nixos/nextcloud: run tests against each Nextcloud instance
(cherry picked from commit 10703a8c92)
2021-10-01 19:13:18 +00:00
Maximilian Bosch
c1541b370a nixos/nextcloud: use php8 where possible
(cherry picked from commit 66edc1e846)
2021-10-01 19:13:17 +00:00
Michele Guerini Rocco
d8e7c12bbd Merge pull request #140183 from NixOS/backport-140172-to-release-21.05
[Backport release-21.05] rxvt-unicode: fix terminfo path
2021-10-01 20:50:23 +02:00
Guillaume Girol
b1e31c7711 Merge pull request #139522 from NixOS/backport-136079-to-release-21.05
[Backport release-21.05] libaom: disable NEON on armv7l
2021-10-01 18:44:52 +00:00
Maximilian Bosch
d4c8773058 Merge pull request #140181 from yayayayaka/backport-140089-to-release-21.05
[Backport release-21.05] nextcloud: 20.0.12 -> 20.0.13, 21.0.4 -> 21.0.5, 22.1.1 -> 22.2.0
2021-10-01 20:30:01 +02:00
Maximilian Bosch
4ae8eeacc2 php80: 8.0.10 -> 8.0.11
ChangeLog: https://www.php.net/ChangeLog-8.php#8.0.11
(cherry picked from commit 6b9eefb85f)
2021-10-01 20:29:33 +02:00
Maximilian Bosch
9f4d20b4bf php74: 7.4.23 -> 7.4.24
ChangeLog: https://www.php.net/ChangeLog-7.php#7.4.24
(cherry picked from commit 13d37ebb64)
2021-10-01 20:29:13 +02:00
Artturin
f83bc9fb22 rxvt-unicode: fix terminfo path
(cherry picked from commit 937f349b5f)
2021-10-01 18:18:56 +00:00
Maximilian Bosch
f182b8d23b nixos/nextcloud: temp fix for MariaDB >=10.6
The MariaDB version 10.6 doesn't seem supported with current Nextcloud
versions and the test fails with the following error[1]:

    nextcloud # [   14.950034] nextcloud-setup-start[1001]: Error while trying to initialise the database: An exception occurred while executing a query: SQLSTATE[HY000]: General error: 4047 InnoDB refuses to write tables with ROW_FORMAT=COMPRESSED or KEY_BLOCK_SIZE.

According to a support-thread in upstream's Discourse[2] this is because
of a missing support so far.

Considering that we haven't received any bugreports so far - even though
the issue already exists on master - and the workaround[3] appears to
work fine, an evaluation warning for administrators should be
sufficient.

[1] https://hydra.nixos.org/build/155015223
[2] https://help.nextcloud.com/t/update-to-next-cloud-21-0-2-has-get-an-error/117028/15
[3] setting `innodb_read_only_compressed=0`

(cherry picked from commit 675e262f5a)
2021-10-01 20:04:06 +02:00
github-actions[bot]
2eeba48bbd Merge staging-next-21.05 into staging-21.05 2021-10-01 18:03:09 +00:00
github-actions[bot]
17cc353f31 Merge release-21.05 into staging-next-21.05 2021-10-01 18:02:37 +00:00
Lara
57b924eab1 nextcloud: 20.0.12 -> 20.0.13, 21.0.4 -> 21.0.5, 22.1.1 -> 22.2.0
(cherry picked from commit 49573709c5)
2021-10-01 20:02:22 +02:00
Vladimír Čunát
ff12d52832 Merge #140069: transmission: fixes to make a test work
...into release-21.05
2021-10-01 17:45:52 +02:00
github-actions[bot]
f8f9e6f437 Merge staging-next-21.05 into staging-21.05 2021-10-01 12:04:44 +00:00
github-actions[bot]
b1892a4013 Merge release-21.05 into staging-next-21.05 2021-10-01 12:02:27 +00:00
Maximilian Bosch
92609f3d9b Merge pull request #139791 from NixOS/backport-139647-to-release-21.05
[Backport release-21.05] element-{web,desktop}: 1.8.5 -> 1.9.0
2021-10-01 12:19:03 +02:00
Bernardo Meurer
40868780fc Merge pull request #140124 from NixOS/backport-138942-to-release-21.05
[Backport release-21.05] firmwareLinuxNonfree: 2021-08-18 -> 2021-09-19
2021-10-01 07:22:45 +00:00
TredwellGit
9bbfc06da2 firmwareLinuxNonfree: 2021-08-18 -> 2021-09-19
(cherry picked from commit 892f937370)
2021-10-01 06:27:23 +00:00
Bernardo Meurer
f38941f819 Merge pull request #134834 from NixOS/backport-134648-to-release-21.05
[Backport release-21.05] firmwareLinuxNonfree: 2021-07-16 -> 2021-08-18
2021-10-01 06:23:17 +00:00
github-actions[bot]
1cae807ecb Merge staging-next-21.05 into staging-21.05 2021-10-01 00:05:07 +00:00
github-actions[bot]
02f5a85d1e Merge release-21.05 into staging-next-21.05 2021-10-01 00:04:35 +00:00
Janne Heß
5b0c0168e9 openssh: Fix CVE-2021-41617 2021-10-01 00:00:33 +02:00
ajs124
328e22af39 exim: 4.94.2 -> 4.95
(cherry picked from commit cc9e7f0b04)
2021-09-30 21:24:51 +00:00
Michael Weiss
f46082db32 Merge pull request #140044 from NixOS/backport-140029-to-release-21.05
[Backport release-21.05] signal-desktop: 5.17.2 -> 5.18.0
2021-09-30 21:40:15 +02:00
Vladimír Čunát
c28d983bf6 transmission: fixes to make one test work again
Broken by 37134b607 (PR #134007).

(cherry picked from commit ec4a159100)
2021-09-30 19:22:15 +00:00
github-actions[bot]
655637cf45 Merge staging-next-21.05 into staging-21.05 2021-09-30 18:02:49 +00:00
github-actions[bot]
738b76e19d Merge release-21.05 into staging-next-21.05 2021-09-30 18:02:18 +00:00
Michael Weiss
5fcf023482 signal-desktop: 5.17.2 -> 5.18.0
(cherry picked from commit 802321a442)
2021-09-30 14:06:49 +00:00
Maximilian Bosch
47bf4156ee Merge pull request #140032 from NixOS/backport-139810-to-release-21.05
[Backport release-21.05] grocy: 3.1.1 -> 3.1.2
2021-09-30 14:51:54 +02:00
Maximilian Bosch
ce206ce87f grocy: 3.1.1 -> 3.1.2
ChangeLog: https://github.com/grocy/grocy/releases/tag/v3.1.2
(cherry picked from commit d8ff7944ed)
2021-09-30 12:35:26 +00:00
github-actions[bot]
8903a71506 Merge staging-next-21.05 into staging-21.05 2021-09-30 12:07:34 +00:00
github-actions[bot]
2574011b20 Merge release-21.05 into staging-next-21.05 2021-09-30 12:03:58 +00:00
Martin Weinelt
22dcaf9a53 Merge pull request #140017 from Ma27/backport-linux5.13-removal 2021-09-30 12:29:00 +02:00
Maximilian Bosch
8079b1a3c8 linux_5_13: drop
5.13.19 was the last 5.13 release and the version is now EOL[1].

[1] https://lwn.net/Articles/869747/

(cherry picked from commit 01eb8ec98a)
2021-09-30 11:13:19 +02:00
github-actions[bot]
a314cf308e Merge staging-next-21.05 into staging-21.05 2021-09-30 06:05:44 +00:00
github-actions[bot]
66c64b804c Merge release-21.05 into staging-next-21.05 2021-09-30 06:03:58 +00:00
adisbladis
182eea7232 Merge pull request #139994 from NixOS/backport-139987-to-release-21.05
[Backport release-21.05] poetry2nix: 1.20.0 -> 1.21.0
2021-09-29 22:24:26 -05:00
adisbladis
44999232a9 poetry2nix: 1.20.0 -> 1.21.0
(cherry picked from commit c779050edb)
2021-09-30 03:09:34 +00:00
John Ericson
d1c08981f6 newlib: Add parameter for "nano" variant 2021-09-29 21:27:31 -04:00
Artturi
20e9966c78 Merge pull request #139924 from NixOS/backport-132650-to-release-21.05
[Backport release-21.05] rambox: 0.7.7 -> 0.7.8
2021-09-30 03:47:07 +03:00
github-actions[bot]
d8f7853e39 Merge staging-next-21.05 into staging-21.05 2021-09-30 00:03:45 +00:00
github-actions[bot]
cbbd1e611b Merge release-21.05 into staging-next-21.05 2021-09-30 00:03:01 +00:00
Martin Weinelt
ed4615e016 Merge pull request #139962 from risicle/ris-routinator-0.10.1-r21.05
[21.05] routinator: 0.8.3 -> 0.10.1
2021-09-30 01:53:53 +02:00
Anders Kaseorg
3d4775b6b9 appimageTools.wrapAppImage: Fix passing arguments to wrapped executable
appimage-exec.sh parses its arguments with getopts, so we need to
delimit arguments intended for the wrapped executable with ‘--’, in
case some of them begin with ‘-’.

Without this fix, a wrapped application like Zulip Desktop can’t be
opened the normal way using the .desktop file, which includes
‘Exec=zulip --no-sandbox %U’ (as per the electron-builder default):

$ gtk-launch zulip.desktop
/usr/bin/appimage-exec.sh: illegal option -- -
Usage: appimage-run [appimage-run options] <AppImage> [AppImage options]
[…]

Signed-off-by: Anders Kaseorg <andersk@mit.edu>
(cherry picked from commit b5160bba86)
2021-09-29 23:44:24 +01:00
Robert Scott
3db7732704 wolfssl: add patch for CVE-2021-38597 2021-09-29 22:04:55 +01:00
0x4A6F
13c798e8e7 routinator: 0.10.0 -> 0.10.1
(cherry picked from commit 01af935180)
2021-09-29 20:12:06 +01:00
0x4A6F
abed7897c8 routinator: 0.9.0 -> 0.10.0
(cherry picked from commit adfe946418)
2021-09-29 20:11:17 +01:00
0x4A6F
d777260d58 routinator: 0.8.3 -> 0.9.0
(cherry picked from commit ffae5e3650)
2021-09-29 20:10:47 +01:00
github-actions[bot]
16db3b8a8d Merge staging-next-21.05 into staging-21.05 2021-09-29 18:03:02 +00:00
github-actions[bot]
c15a59afdf Merge release-21.05 into staging-next-21.05 2021-09-29 18:02:26 +00:00
Domen Kožar
413a0aa722 Merge pull request #139945 from NixOS/backport-139942-to-release-21.05
[Backport release-21.05] wgetpaste: 2.30 -> 2.32
2021-09-29 12:56:08 -05:00
Sergei Trofimovich
5ecf60dcc2 wgetpaste: 2.30 -> 2.32
2.30 can's paste to `dpaste` (default driver). 2.32 has it fixed
by using v2 endpoint. While at it switch homepage to github project.

(cherry picked from commit 17927dee09)
2021-09-29 17:22:13 +00:00
Anderson Torres
d0ad2b1c52 Merge pull request #138356 from NixOS/backport-138298-to-release-21.05
[Backport release-21.05] palemoon: 29.4.0.2 -> 29.4.1
2021-09-29 12:50:00 -03:00
Adomas Jatužis
064121ec5a rambox: 0.7.7 -> 0.7.8
(cherry picked from commit ff783132f0)
2021-09-29 15:21:54 +00:00
Domen Kožar
ee90403e14 Merge pull request #139586 from maxeaubrey/21.05_vscode_1.60.2
[21.05] vscode: 1.57.1 -> 1.60.2
2021-09-29 07:35:53 -05:00
Ryan Mulligan
4b7b04754a Merge pull request #139323 from NixOS/backport-139180-to-release-21.05
[Backport release-21.05] discourse: enable restoring backups bigger than RAM
2021-09-29 05:33:49 -07:00
github-actions[bot]
8b4d753f3a Merge staging-next-21.05 into staging-21.05 2021-09-29 12:03:00 +00:00
github-actions[bot]
e89a953e68 Merge release-21.05 into staging-next-21.05 2021-09-29 12:02:23 +00:00
R. RyanTM
27fe565f49 libytnef: 1.9.3 -> 2.0
(cherry picked from commit dfc537bcb2)
2021-09-29 10:30:23 +00:00
github-actions[bot]
94255ffab5 [Backport release-21.05] chromedriver: add dbus to libraries, correct LD_LIBRARY_PATH wrapping (#139838)
* chromedriver: add dbus to libraries

It is apparently required since version 94.

Fixes issue #139547

(cherry picked from commit 433b2bc44487c90c33cb58d87434a287e6d43b15)

* chromedriver: remove extraneous LD_LIBRARY_PATH in wrapProgram

wrapProgram already prepends passed value to the specified environment
variable; no need to specify it explicitly.

(cherry picked from commit 38ddfe7f3ff206888806302539def70b80ef427b)

* chromedriver: add a package test checking the reported version

(cherry picked from commit 1106f4bafc0b444384c171c63ca78b8b6676842e)

* Update pkgs/development/tools/selenium/chromedriver/default.nix

(cherry picked from commit 852612eac99dc403c0ea09a5daca9b65b5b7e123)

Co-authored-by: Ivan Timokhin <nixpkgs@ivan.timokhin.name>
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
2021-09-29 09:24:17 +03:00
github-actions[bot]
223b9b5cb5 Merge staging-next-21.05 into staging-21.05 2021-09-29 00:03:05 +00:00
github-actions[bot]
4e9035a9ea Merge release-21.05 into staging-next-21.05 2021-09-29 00:02:29 +00:00
Artturi
82891b5e2c Merge pull request #139807 from NixOS/backport-135142-to-release-21.05
[Backport release-21.05] canon-cups-ufr2: update url
2021-09-29 00:28:28 +03:00
Matt McHenry
0e2946abec canon-cups-ufr2: update url
(cherry picked from commit 8771d6a7b0)
2021-09-28 21:05:32 +00:00
Artturi
2ec66a67fd Merge pull request #139790 from NixOS/backport-139786-to-release-21.05 2021-09-28 21:58:16 +03:00
github-actions[bot]
eaedd0b5ac Merge staging-next-21.05 into staging-21.05 2021-09-28 18:02:49 +00:00
github-actions[bot]
046f88fee0 Merge release-21.05 into staging-next-21.05 2021-09-28 18:02:14 +00:00
Sumner Evans
13edaf4d7d element-desktop: 1.8.5 -> 1.9.0
(cherry picked from commit 406221cda3)
2021-09-28 17:57:41 +00:00
Sumner Evans
9f0a70ddc3 element-web: 1.8.5 -> 1.9.0
(cherry picked from commit 4484be0a52)
2021-09-28 17:57:40 +00:00
Artturin
ada8a1c0f0 onlyoffice: wrap correctly and force xcb since onlyoffice doesn't
support wayland

(cherry picked from commit c75c37de7e)
2021-09-28 17:52:55 +00:00
Linus Heckemann
4e2a251552 Merge pull request #139666 from Ma27/backport-rnix-lsp
[21.05] rnix-lsp: 0.1.0 -> 0.2.1
2021-09-28 18:05:20 +02:00
Maximilian Bosch
bc787aef50 Merge pull request #139705 from NixOS/backport-139444-to-release-21.05
[Backport release-21.05] wiki-js: 2.5.214 -> 2.5.219
2021-09-28 14:18:23 +02:00
github-actions[bot]
1e70fc5bc3 Merge staging-next-21.05 into staging-21.05 2021-09-28 12:03:07 +00:00
github-actions[bot]
319d14cf41 Merge release-21.05 into staging-next-21.05 2021-09-28 12:02:31 +00:00
Jörg Thalheim
96bf839ef6 Merge pull request #139697 from oxalica/bp/fix/to-rust-target
[21.05] fix toRustTarget for windows
2021-09-28 09:37:55 +01:00
Maximilian Bosch
1cd12e483a wiki-js: 2.5.214 -> 2.5.219
ChangeLog: https://github.com/Requarks/wiki/releases/tag/2.5.219
(cherry picked from commit e12d71e71b)
2021-09-28 07:38:14 +00:00
Maximilian Bosch
ce6b39b6be Merge pull request #139238 from Ma27/backport-hedgedoc
[21.05] hedgedoc: 1.8.2 -> 1.9.0, fixes CVE-2021-39175
2021-09-28 09:33:57 +02:00
Robin Stumm
c9049f71dd rust.toRustTarget: fix for windows
change vendor from "w64" to "pc"
broken since 91718534f1

(cherry picked from commit d89c29deb8)
2021-09-28 14:23:36 +08:00
Maximilian Bosch
9c28f1f958 rnix-lsp: 0.1.0 -> 0.2.1
ChangeLog: https://github.com/nix-community/rnix-lsp/blob/v0.2.1/CHANGELOG.md#v021---2021-09-23
(cherry picked from commit 3bcfecc268)
2021-09-27 23:32:50 +02:00
TredwellGit
0fd3917aa6 linux/hardened/patches/5.4: 5.4.148-hardened1 -> 5.4.149-hardened1
(cherry picked from commit a92a208a9d)
2021-09-27 20:47:50 +00:00
TredwellGit
e62dfb6de9 linux/hardened/patches/5.14: 5.14.7-hardened1 -> 5.14.8-hardened1
(cherry picked from commit 05ed561fb6)
2021-09-27 20:47:49 +00:00
TredwellGit
ee4a4412a1 linux/hardened/patches/5.10: 5.10.68-hardened1 -> 5.10.69-hardened1
(cherry picked from commit c4ea02fc5c)
2021-09-27 20:47:48 +00:00
TredwellGit
559153f267 linux/hardened/patches/4.19: 4.19.207-hardened1 -> 4.19.208-hardened1
(cherry picked from commit 9e78068b04)
2021-09-27 20:47:47 +00:00
TredwellGit
cb8066b193 linux/hardened/patches/4.14: 4.14.247-hardened1 -> 4.14.248-hardened1
(cherry picked from commit 1e05c4eae9)
2021-09-27 20:47:46 +00:00
github-actions[bot]
39c450fe20 Merge staging-next-21.05 into staging-21.05 2021-09-27 18:02:55 +00:00
github-actions[bot]
7b28d51e7e Merge release-21.05 into staging-next-21.05 2021-09-27 18:02:19 +00:00
Kim Lindberger
1224e4bec7 Merge pull request #139629 from NixOS/backport-139201-to-release-21.05
[Backport release-21.05] discourse: 2.7.7 -> 2.7.8, update plugins
2021-09-27 16:31:06 +02:00
talyz
ec588badc4 discourse: Enable jhead, which is no longer marked vulnerable
(cherry picked from commit ed8c4e01d9)
2021-09-27 13:37:42 +00:00
talyz
e93c033a3b discourse.plugins.discourse-yearly-review: Update
(cherry picked from commit e4ed6b5929)
2021-09-27 13:37:41 +00:00
talyz
df8becc53f discourse.plugins.discourse-spoiler-alert: Update
(cherry picked from commit 957eaf8237)
2021-09-27 13:37:40 +00:00
talyz
61fab89e08 discourse.plugins.discourse-solved: Update
(cherry picked from commit fd084acb95)
2021-09-27 13:37:40 +00:00
talyz
cb35abb6c1 discourse.plugins.discourse-math: Update
(cherry picked from commit b1aa7efd36)
2021-09-27 13:37:39 +00:00
talyz
9c26876e2b discourse.plugins.discourse-github: Update
(cherry picked from commit 97034cfa1c)
2021-09-27 13:37:38 +00:00
talyz
125bceeb25 discourse.plugins.discourse-checklist: Update
(cherry picked from commit d583001723)
2021-09-27 13:37:38 +00:00
talyz
394d86a424 discourse.plugins.discourse-canned-replies: Update
(cherry picked from commit 1e62b64b90)
2021-09-27 13:37:37 +00:00
talyz
1d1a2bbf2b discourse.plugins.discourse-calendar: Update
(cherry picked from commit d62ea8705b)
2021-09-27 13:37:36 +00:00
talyz
cb502f9b10 discourse: 2.7.7 -> 2.7.8
(cherry picked from commit 73e8eb91c1)
2021-09-27 13:37:35 +00:00
Maximilian Bosch
99749136f9 Merge pull request #139615 from NixOS/backport-139551-to-release-21.05
[Backport release-21.05] Kernels 2021-09-26
2021-09-27 14:17:16 +02:00
github-actions[bot]
4a0e130c84 Merge staging-next-21.05 into staging-21.05 2021-09-27 12:03:06 +00:00
github-actions[bot]
0a8668a4bf Merge release-21.05 into staging-next-21.05 2021-09-27 12:02:27 +00:00
TredwellGit
74d0889655 linux/hardened/patches/5.4: 5.4.147-hardened1 -> 5.4.148-hardened1
(cherry picked from commit bb21f231cf)
2021-09-27 09:57:32 +00:00
TredwellGit
4b3fd66a5b linux/hardened/patches/5.14: 5.14.6-hardened1 -> 5.14.7-hardened1
(cherry picked from commit 5b71d92f9a)
2021-09-27 09:57:32 +00:00
TredwellGit
1febaecabb linux/hardened/patches/5.10: 5.10.67-hardened1 -> 5.10.68-hardened1
(cherry picked from commit 34fe5d827c)
2021-09-27 09:57:31 +00:00
TredwellGit
8a0a9f3597 linux/hardened/patches/4.19: 4.19.206-hardened1 -> 4.19.207-hardened1
(cherry picked from commit b754a3c355)
2021-09-27 09:57:30 +00:00
TredwellGit
422b30ce66 linux/hardened/patches/4.14: 4.14.246-hardened1 -> 4.14.247-hardened1
(cherry picked from commit 7b29a72e54)
2021-09-27 09:57:29 +00:00
TredwellGit
7da735d204 linux: 5.4.148 -> 5.4.149
(cherry picked from commit fa3a710526)
2021-09-27 09:57:29 +00:00
TredwellGit
eaccf16f05 linux: 5.14.7 -> 5.14.8
(cherry picked from commit 10fee833c9)
2021-09-27 09:57:28 +00:00
TredwellGit
27e5593772 linux: 5.10.68 -> 5.10.69
(cherry picked from commit bba95d3763)
2021-09-27 09:57:27 +00:00
TredwellGit
05e033d6f1 linux: 4.9.283 -> 4.9.284
(cherry picked from commit bb9a54d5ee)
2021-09-27 09:57:26 +00:00
TredwellGit
d1df9958b6 linux: 4.4.284 -> 4.4.285
(cherry picked from commit bae26c4e05)
2021-09-27 09:57:25 +00:00
TredwellGit
6195899398 linux: 4.19.207 -> 4.19.208
(cherry picked from commit 7fad98993c)
2021-09-27 09:57:24 +00:00
TredwellGit
a560026ecd linux: 4.14.247 -> 4.14.248
(cherry picked from commit b0f3a99f00)
2021-09-27 09:57:24 +00:00
Maximilian Bosch
78822fca19 Merge pull request #138949 from NixOS/backport-138925-to-release-21.05
[Backport release-21.05] Kernels 2021-09-22
2021-09-27 11:52:39 +02:00
github-actions[bot]
a912975e75 Merge staging-next-21.05 into staging-21.05 2021-09-27 06:03:02 +00:00
github-actions[bot]
6d3537a3e7 Merge release-21.05 into staging-next-21.05 2021-09-27 06:02:23 +00:00
nixpkgs-upkeep-bot
8632b3922a vscode: 1.60.1 -> 1.60.2
(cherry picked from commit a946fb970f)
2021-09-27 02:37:02 +02:00
nixpkgs-upkeep-bot
b70218db54 vscode: 1.60.0 -> 1.60.1
(cherry picked from commit 268c8d77ca)
2021-09-27 02:36:42 +02:00
nixpkgs-upkeep-bot
7599b5057e vscode: 1.59.1 -> 1.60.0
(cherry picked from commit cff78ebaf6)
2021-09-27 02:36:31 +02:00
nixpkgs-upkeep-bot
794bb33740 vscode: 1.59.0 -> 1.59.1
(cherry picked from commit cc58f8419d)
2021-09-27 02:36:23 +02:00
upkeep-bot
f2d755f324 vscode: 1.58.2 -> 1.59.0
(cherry picked from commit 58647d0bbf)
2021-09-27 02:36:13 +02:00
upkeep-bot
32ff63b188 vscode: 1.58.0 -> 1.58.2
(cherry picked from commit e10404fa9c)
2021-09-27 02:35:51 +02:00
Matthew Leach
b28239938a vscode: Add arm64-darwin support
Download and extract the prebuilt arm64-darwin archive.

(cherry picked from commit 7f8828230f)
2021-09-27 02:35:44 +02:00
upkeep-bot
25e8436734 vscode: 1.57.1 -> 1.58.0
(cherry picked from commit d47d49711d)
2021-09-27 02:35:00 +02:00
Maximilian Bosch
4370771dbc feh: 3.7.1 -> 3.7.2
ChangeLog: https://feh.finalrewind.org/archive/3.7.2/
(cherry picked from commit 646cb17cdb)
2021-09-27 00:25:52 +00:00
Artturi
8e1306519d Merge pull request #139490 from NixOS/backport-137563-to-release-21.05
[Backport release-21.05] jitsi-meet: 1.0.5056 -> 1.0.5307
2021-09-27 03:19:19 +03:00
Artturi
c02b9cd15e Merge pull request #139487 from NixOS/backport-137559-to-release-21.05
[Backport release-21.05] jicofo: 1.0-756 -> 1.0-798
2021-09-27 03:18:58 +03:00
Artturi
c94bf92a45 Merge pull request #139488 from NixOS/backport-137568-to-release-21.05
[Backport release-21.05] jitsi-videobridge: 2.1-508-gb24f756c -> 2.1-551-g2ad6eb0b
2021-09-27 03:18:42 +03:00
github-actions[bot]
56ecd91ff4 Merge staging-next-21.05 into staging-21.05 2021-09-27 00:03:11 +00:00
github-actions[bot]
a0da4b7b0c Merge release-21.05 into staging-next-21.05 2021-09-27 00:02:34 +00:00
Robert Scott
7baaef39fe Merge pull request #139575 from NixOS/backport-124297-to-release-21.05
[Backport release-21.05] lief: 0.11.4 -> 0.11.5
2021-09-27 00:00:01 +01:00
Martin Weinelt
ac914045db Merge pull request #137022 from Flakebi/salt-backport 2021-09-27 00:26:34 +02:00
R. RyanTM
0352b72f3c lief: 0.11.4 -> 0.11.5
(cherry picked from commit 9d396b5600)
2021-09-26 21:54:38 +00:00
github-actions[bot]
af98bd1601 Merge staging-next-21.05 into staging-21.05 2021-09-26 18:02:51 +00:00
github-actions[bot]
f7ed81bce2 Merge release-21.05 into staging-next-21.05 2021-09-26 18:02:14 +00:00
Michael Weiss
8d943dfce6 Merge pull request #139539 from NixOS/backport-139415-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 94.0.4606.54 -> 94.0.4606.61
2021-09-26 18:49:48 +02:00
Michael Weiss
d604d3ee9c ungoogled-chromium: 94.0.4606.54 -> 94.0.4606.61
(cherry picked from commit d66e4eea85)
2021-09-26 14:40:22 +00:00
Doron Behar
e7eebf5fc3 Merge pull request #139481 from hrhino/backport/128077 2021-09-26 12:39:30 +00:00
github-actions[bot]
c132283c77 Merge staging-next-21.05 into staging-21.05 2021-09-26 12:02:55 +00:00
github-actions[bot]
80b9a8838b Merge release-21.05 into staging-next-21.05 2021-09-26 12:02:23 +00:00
zimbatm
983c209630 foreman: add more platform support
See
https://www.moncefbelyamani.com/understanding-the-gemfile-lock-file/

Apparently you now have to manually add all the platforms that a gem is
supported on.

(cherry picked from commit cda1e49784)
2021-09-26 11:02:21 +00:00
Kranium Gikos Mendoza
2fea3122d4 libaom: disable NEON on armv7l
(cherry picked from commit b7066a57de)
2021-09-26 09:29:19 +00:00
Fabián Heredia Montiel
fd8a7fd07d nvidia_x11: 470.57.02 → 470.63.01
(cherry picked from commit ff0dfaaee0)

Required since the kernel upgrade on 21.05, compilation for the driver
fails on 5.14.

See [this
comment][https://github.com/NixOS/nixpkgs/issues/132840#issuecomment-920847065]
for more details.
2021-09-26 08:53:04 +02:00
github-actions[bot]
41f3858764 Merge staging-next-21.05 into staging-21.05 2021-09-26 06:03:15 +00:00
github-actions[bot]
6fbe5ba8d2 Merge release-21.05 into staging-next-21.05 2021-09-26 06:02:30 +00:00
Artturi
4ad195e3f4 Merge pull request #139495 from NixOS/backport-139485-to-release-21.05
[Backport release-21.05] libnatpmp: make files in $out/lib executable
2021-09-26 06:45:29 +03:00
Artturin
23ca79f291 libnatpmp: make files in $out/lib executable
Fixes https://github.com/NixOS/nixpkgs/issues/139197

(cherry picked from commit be3bc77e31)
2021-09-26 02:02:22 +00:00
github-actions[bot]
f50ff4443d Merge staging-next-21.05 into staging-21.05 2021-09-26 00:03:23 +00:00
github-actions[bot]
bf21cf4da2 Merge release-21.05 into staging-next-21.05 2021-09-26 00:02:39 +00:00
R. RyanTM
5b2ff56444 jitsi-meet: 1.0.5056 -> 1.0.5307
(cherry picked from commit f7e646df7f)
2021-09-25 23:14:13 +00:00
Maximilian Bosch
36a3756d71 hedgedoc: fix build by re-running yarn2nix
Failing Hydra build: https://hydra.nixos.org/build/154209534

(cherry picked from commit 0a2615fe2f52c5743fd3a6cb3bd40558bdf31ee5)
2021-09-26 01:12:44 +02:00
Maximilian Bosch
c20fbabd9b yarn2nix: run nix-prefetch-git with --fetch-submodules
`pkgs.fetchgit` uses `fetchSubmodules = true;` by default, however
`nix-prefetch-git` doesn't. This means that hashes for a Git repository
with fetched submodules will be wrong in `yarn.nix`.

Considering that this got unnoticed before, it seems as if this case is
an exception to a certain degree.

An exemplary problem is the last `hedgedoc` update[1] where
`js-sequence-diagrams` - a Git repo with submodules - from upstream's
package.json caused a hash mismatch. This got unnoticed because
`nix-build --check` doesn't seem to reveal these issues for fixed-output
derivations.

[1] https://github.com/NixOS/nixpkgs/pull/139238

(cherry picked from commit 46c98ae1327b7d14af1927fda971762e5ee53dfe)
2021-09-26 01:12:43 +02:00
R. RyanTM
6d6a713644 jitsi-videobridge: 2.1-508-gb24f756c -> 2.1-551-g2ad6eb0b
(cherry picked from commit 065abed6de)
2021-09-25 22:52:59 +00:00
R. RyanTM
583694193f jicofo: 1.0-756 -> 1.0-798
(cherry picked from commit e35934cc4f)
2021-09-25 22:52:31 +00:00
Robert Scott
47b0bee8b4 Merge pull request #139440 from NixOS/backport-139401-to-release-21.05
[Backport release-21.05] perlPackages.ConvertASN1: 0.27 -> 0.33
2021-09-25 22:48:27 +01:00
Doron Behar
ce711cc113 imagej: 150 -> 153
(cherry picked from commit 796ae067c4)
2021-09-25 17:33:55 -04:00
Doron Behar
d16a1e9975 imagej: Add desktop item and icon
(cherry picked from commit 0750062126)
2021-09-25 17:33:44 -04:00
Doron Behar
487300c6aa imagej: reformat expression
- Use 1 line per input argument.
- Don't use let ... in if not needed.
- Use ${version} in url string.
- Run hooks in explicit installPhase.

(cherry picked from commit e1d6051d81)
2021-09-25 17:33:35 -04:00
github-actions[bot]
9c4b557682 Merge staging-next-21.05 into staging-21.05 2021-09-25 18:02:48 +00:00
github-actions[bot]
f91be95473 Merge release-21.05 into staging-next-21.05 2021-09-25 18:02:16 +00:00
Maciej Krüger
9f371831e2 Merge pull request #139446 from NixOS/backport-138623-to-release-21.05 2021-09-25 19:07:54 +02:00
figsoda
4df9f1a69b Merge pull request #139417 from sersorrel/backport-playerctl-v2.4.1
[21.05] playerctl: 2.3.1 -> 2.4.1
2021-09-25 12:39:32 -04:00
Maximilian Bosch
9e29f211ba nixUnstable: 2.4pre20210908_3c56f62 -> 2.4pre20210922_bcd73eb
Changes: 3c56f62...bcd73eb

I figured that now with an actual 2.4 release around the corner[1] we
could bump it a bit more often considering that it seems to contain
mostly bugfixes, so that upstream receives a bit more feedback.

[1] https://discourse.nixos.org/t/tweag-nix-dev-update-17/15037

(cherry picked from commit 615d368aa0)
2021-09-25 15:32:55 +00:00
maralorn
42142cc1bc Merge pull request #139423 from NixOS/backport-139336-to-release-21.05
[Backport release-21.05] nix-output-monitor: 1.0.3.2 -> 1.0.3.3
2021-09-25 17:19:04 +02:00
figsoda
77f2a47595 Merge pull request #139405 from eduarrrd/backport
[21.05] psi-notify: init at 1.2.1
2021-09-25 10:26:26 -04:00
Thomas Gerbet
acf683f0b8 perlPackages.ConvertASN1: 0.27 -> 0.33
Fixes CVE-2013-7488.
https://metacpan.org/dist/Convert-ASN1/changes

(cherry picked from commit ccb5c2285b)
2021-09-25 13:49:01 +00:00
github-actions[bot]
3406379bcf Merge staging-next-21.05 into staging-21.05 2021-09-25 12:03:22 +00:00
github-actions[bot]
957812c288 Merge release-21.05 into staging-next-21.05 2021-09-25 12:02:26 +00:00
Malte Brandy
17ee0b23fe nix-output-monitor: 1.0.3.2 -> 1.0.3.3
(cherry picked from commit f779a0ff03)
2021-09-25 11:50:22 +00:00
maralorn
23e9876f22 Merge pull request #139340 from NixOS/backport-138250-to-release-21.05
[Backport release-21.05] nix-output-monitor: 1.0.3.1 -> 1.0.3.2
2021-09-25 13:32:02 +02:00
R. RyanTM
f203c41098 playerctl: 2.3.1 -> 2.4.1
(cherry picked from commit b01290e0ec)

Reason: fixes a crash with TrackList and Playlists interfaces [1]

[1]: https://github.com/altdesktop/playerctl/pull/215
2021-09-25 11:33:12 +01:00
Michael Weiss
2502b34166 Merge pull request #139329 from NixOS/backport-139318-to-release-21.05
[Backport release-21.05] chromium: 94.0.4606.54 -> 94.0.4606.61
2021-09-25 11:55:23 +02:00
Eduard Bachmakov
418a762043 psi-notify: init at 1.2.1
(cherry picked from commit 37ec684a5c)
2021-09-25 11:32:27 +02:00
github-actions[bot]
4bca328a88 Merge staging-next-21.05 into staging-21.05 2021-09-25 00:03:24 +00:00
github-actions[bot]
0332c24d29 Merge release-21.05 into staging-next-21.05 2021-09-25 00:02:43 +00:00
Michael Weiss
02b76b0515 Merge pull request #139358 from primeos/ungoogled-chromium-backport
[21.05] ungoogled-chromium: 93.0.4577.82 -> 94.0.4606.54
2021-09-25 00:50:41 +02:00
Michael Weiss
0f19ca835b ungoogled-chromium: name -> pname
A partial backport of e4e631ebb8 to keep the diff minimal.
2021-09-25 00:14:35 +02:00
Michael Weiss
c20993fbc9 ungoogled-chromium: 93.0.4577.82 -> 94.0.4606.54
(cherry picked from commit afaf8d094b)
2021-09-25 00:12:59 +02:00
Michael Weiss
143a7453f0 chromiumBeta: 94.0.4606.54 -> 95.0.4638.17
(cherry picked from commit b946851593)
2021-09-25 00:10:01 +02:00
Daniel Fullmer
398d614203 zerotierone: 1.6.5 -> 1.6.6
(cherry picked from commit 62207eec01)
2021-09-24 21:27:26 +02:00
github-actions[bot]
72e691ca4b Merge staging-next-21.05 into staging-21.05 2021-09-24 18:02:54 +00:00
github-actions[bot]
77473f9d35 Merge release-21.05 into staging-next-21.05 2021-09-24 18:02:19 +00:00
Malte Brandy
a94c6e2dc4 nix-output-monitor: 1.0.3.1 -> 1.0.3.2
(cherry picked from commit a96fe065ee)
2021-09-24 17:49:27 +00:00
Michael Weiss
df409303ab chromium: 94.0.4606.54 -> 94.0.4606.61
(cherry picked from commit 15bb3ac5a9)
2021-09-24 14:01:33 +00:00
Ryan Mulligan
d3bee2a63a discourse: enable restoring backups bigger than RAM
When restoring a backup, discourse decompresses the backup archive in
the /share/discourse/tmp dir. Before this change, it is linked to /run
which is typically backed by memory, so the backup will fail to
restore if you do not have enough memory on your system to contain the
backup. This has already happened to me on two small forums.

This moves tmp to the StateDirectory /var/lib/discourse/tmp which is
typically backed by disk.

(cherry picked from commit f933c68374)
2021-09-24 12:35:53 +00:00
Kim Lindberger
b897a166cb Merge pull request #139203 from NixOS/backport-138852-to-release-21.05
[Backport release-21.05] nixos/discourse: add discourse.admin.skipCreate option
2021-09-24 14:30:17 +02:00
github-actions[bot]
feab58fc4f Merge staging-next-21.05 into staging-21.05 2021-09-24 12:02:51 +00:00
github-actions[bot]
8090103df5 Merge release-21.05 into staging-next-21.05 2021-09-24 12:02:14 +00:00
Michael Weiss
43003625e9 Merge pull request #139220 from primeos/chromium-backport
[21.05] chromium: 93.0.4577.82 -> 94.0.4606.54
2021-09-24 12:20:21 +02:00
Flakebi
e6e7e3df1b salt: 3003.2 -> 3003.3
(cherry picked from commit 4ad4ae68c4)
2021-09-24 09:59:34 +02:00
Flakebi
348d0b0626 salt: 3003.1 -> 3003.2
(cherry picked from commit da3e650494)
2021-09-24 09:59:27 +02:00
Flakebi
962a2f26a0 salt: 3003 -> 3003.1
Need to patch out the contextvars dependency (which is included in
python 3.7+).
The same patch is discussed in arch:
https://bugs.archlinux.org/task/71344

(cherry picked from commit c0b46c6b59)
2021-09-24 09:59:20 +02:00
Ryan Burns
de3cec2c60 Merge pull request #139161 from NixOS/backport-138952-to-staging-21.05
[Backport staging-21.05] ffmpeg: patch CVE-2021-38171 and CVE-2021-38291
2021-09-23 21:05:44 -07:00
Maximilian Bosch
4eb0a2b3cb hedgedoc: 1.8.2 -> 1.9.0, fixes CVE-2021-39175
ChangeLog: https://github.com/hedgedoc/hedgedoc/releases/tag/1.9.0

As documented in the Nix expression, I unfortunately had to patch
`yarn.lock` manually (the `yarn.nix` result isn't affected by this). By
adding a `git+https`-prefix to
`midi "https://github.com/paulrosen/MIDI.js.git#abcjs"` in the lock-file
I ensured that `yarn` actually uses the `MIDI.js` from the offline-cache
from `yarn2nix` rather than trying to download a tarball from GitHub.

Also, this release contains a fix for CVE-2021-39175 which doesn't seem
to be backported to 1.8. To quote NVD[1]:

> In versions prior to 1.9.0, an unauthenticated attacker can inject
> arbitrary JavaScript into the speaker-notes of the slide-mode feature
> by embedding an iframe hosting the malicious code into the slides or by
> embedding the HedgeDoc instance into another page.

Even though it "only" has a medium rating by NVD (6.1), this seems
rather problematic to me (also, GitHub rates this as "High"), so it's
actually a candidate for a backport.

[1] https://nvd.nist.gov/vuln/detail/CVE-2021-39175

(cherry picked from commit 0a10c17c8d)
2021-09-23 23:33:29 +02:00
Robert Scott
f303ebf548 gd: 2.3.0 -> 2.3.2, add patch for partial CVE-2021-40812 fix
(cherry picked from commit 4afafc0893)
2021-09-23 21:02:10 +01:00
Michael Weiss
2347b9a7db chromium: 93.0.4577.82 -> 94.0.4606.54
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_21.html

This update includes 19 security fixes.

CVEs:
CVE-2021-37956 CVE-2021-37957 CVE-2021-37958 CVE-2021-37959
CVE-2021-37960 CVE-2021-37961 CVE-2021-37962 CVE-2021-37963
CVE-2021-37964 CVE-2021-37965 CVE-2021-37966 CVE-2021-37967
CVE-2021-37968 CVE-2021-37969 CVE-2021-37970 CVE-2021-37971
CVE-2021-37972

(cherry picked from commit 8d8b451f72)
2021-09-23 21:48:17 +02:00
Michael Weiss
a45d7e5e19 chromiumDev: 95.0.4638.10 -> 95.0.4638.17
(cherry picked from commit 56d99a7351)
2021-09-23 21:48:15 +02:00
Michael Weiss
86f857ec11 chromiumBeta: 94.0.4606.50 -> 94.0.4606.54
(cherry picked from commit 7af2448b6c)
2021-09-23 21:48:14 +02:00
github-actions[bot]
94d0274f26 Merge staging-next-21.05 into staging-21.05 2021-09-23 18:02:56 +00:00
github-actions[bot]
0542387d10 Merge release-21.05 into staging-next-21.05 2021-09-23 18:02:20 +00:00
Kerstin Humm
056a3c1fae imagemagick: 7.1.0-6 -> 7.1.0-8
(cherry picked from commit 279bff87fe)
2021-09-23 19:37:29 +02:00
Ryan Mulligan
3061914340 nixos/discourse: add discourse.admin.skipCreate option
(cherry picked from commit 6a9003f316)
2021-09-23 17:14:07 +00:00
adisbladis
1afcc8f843 Merge pull request #139190 from adisbladis/2105-poetry2nix-1_20_0
poetry2nix: 1.16.1 -> 1.20.0 (21.05)
2021-09-23 11:43:53 -05:00
adisbladis
f285202340 poetry2nix: 1.16.1 -> 1.20.0 2021-09-23 11:18:17 -05:00
Bernardo Meurer
d28990704d Merge pull request #139098 from taku0/thunderbird-bin-91.1.1_release-21.05
[21.05]  thunderbird, thunderbird-bin: 91.1.0 -> 91.1.1
2021-09-23 16:13:25 +00:00
TredwellGit
67d593a330 ffmpeg: patch CVE-2021-38171 and CVE-2021-38291
https://nvd.nist.gov/vuln/detail/CVE-2021-38171
https://nvd.nist.gov/vuln/detail/CVE-2021-38291
(cherry picked from commit b1f41c9184)
2021-09-23 13:31:50 +00:00
github-actions[bot]
4df0e9f666 Merge staging-next-21.05 into staging-21.05 2021-09-23 12:03:36 +00:00
github-actions[bot]
b500417d25 Merge release-21.05 into staging-next-21.05 2021-09-23 12:03:00 +00:00
Moritz Hedtke
d22c3a6bc1 discord: 0.0.15 → 0.0.16
(cherry picked from commit a22f268894)
2021-09-22 23:22:11 -07:00
github-actions[bot]
461b839beb Merge staging-next-21.05 into staging-21.05 2021-09-23 06:02:58 +00:00
github-actions[bot]
2aa54c26ef Merge release-21.05 into staging-next-21.05 2021-09-23 06:02:28 +00:00
taku0
5a690eb641 thunderbird: 91.1.0 -> 91.1.1
no-buildconfig-90.patch is applied by firefox/common.nix.

D124361.diff is incorporated into the upstream:
https://bugzilla.mozilla.org/show_bug.cgi?id=1727113
2021-09-23 12:38:10 +09:00
taku0
22fb3ec5a0 thunderbird-bin: 91.1.0 -> 91.1.1 2021-09-23 12:34:53 +09:00
John Ericson
2091b11642 Merge pull request #139055 from obsidiansystems/dn-backport-21.05-add-ghcjs
[backport release-21.05] ghcjs 8.10.7: init
2021-09-22 22:24:56 -04:00
Divam
af724c4240 Remove old ghcjs files
(cherry picked from commit 0918598005)
2021-09-23 10:14:39 +09:00
Divam
9ec3ff57c7 ghcjs: init at 8.10.7
The src points to the obsidiansystems repo as it has the ghcjs ported from
8.10.5 to 8.10.7, and a bunch of other fixes (#812, #811, #809)

(cherry picked from commit ba25b274f4)
Modified the stm_2_5_0_1 -> stm_2_5_0_0
2021-09-23 10:14:39 +09:00
Divam
365f138754 haskellPackages.happy_1_19_12: init at 1.19.12
(generated by maintainers/scripts/haskell/regenerate-hackage-packages.sh)

(cherry picked from commit be7c76ae64)
2021-09-23 09:59:36 +09:00
Divam
68580f0806 haskellPackages.ghcjs-base: 0.2.0.0 -> 0.2.0.3
(cherry picked from commit c8b255cf25)
2021-09-23 09:58:16 +09:00
John Ericson
2350b8c328 Merge pull request #139037 from obsidiansystems/ghc-8_10_7-21.05
[backport release-21.05] ghc 8.10.7: init
2021-09-22 20:31:42 -04:00
Divam
b1814ba4b1 ghc: add the Cabal ghcjs support patch
(cherry picked from commit feac31b1f0)
2021-09-23 00:13:41 +00:00
Alexandre Esteves
48048824c4 ghc8.10.7: fix mingw build
(cherry picked from commit eea8e3eace)
2021-09-23 00:13:41 +00:00
sternenseemann
65c3102d78 ghc: 8.10.6 -> 8.10.7
https://www.haskell.org/ghc/download_ghc_8_10_7.html

(cherry picked from commit 9eca744cc0)
2021-09-23 00:13:41 +00:00
sternenseemann
56a9ec15ff ghc 8.10.6: Init
Backport which adds, rather than updates, the GHC release.

----

The only big change is required for darwin since GHC 8.10.5 now
runs xattr in the install phase on darwin:

* 11e1dcde0d
* ec451cac39

Unfortunately, it uses the host /usr/bin/xattr by default which is
present in the build due to a lack of sandboxing on darwin. That xattr
version however still requires Python 2.7 whereas Python 3.8 is in PATH
in our build. We solve this by setting the XATTR environment variable.

We can't use python3Packages.xattr since GHC expects Apple's fork of
xattr which provides some extra flags to utilize.

Co-authored-by: Cheng Shao <cheng.shao@tweag.io>

(Adapted from cb330ce4f0)
2021-09-23 00:13:41 +00:00
sternenseemann
b83620af90 darwin.xattr: init at 61.60.1
(cherry picked from commit 283d622397)
2021-09-23 00:13:40 +00:00
github-actions[bot]
1955284241 Merge staging-next-21.05 into staging-21.05 2021-09-23 00:05:26 +00:00
github-actions[bot]
73118ee56b Merge release-21.05 into staging-next-21.05 2021-09-23 00:03:46 +00:00
Robert Scott
5c8efd0034 Merge pull request #137369 from NixOS/backport-134007-to-release-21.05
[Backport release-21.05] fragments: init at 1.5
2021-09-22 21:32:21 +01:00
github-actions[bot]
44a5bf6583 Merge staging-next-21.05 into staging-21.05 2021-09-22 18:02:55 +00:00
github-actions[bot]
46a071899f Merge release-21.05 into staging-next-21.05 2021-09-22 18:02:19 +00:00
TredwellGit
e04cf3d707 linux: 5.4.147 -> 5.4.148
(cherry picked from commit 3fac07b82827c4cfa33892e09484e6406805dd57)
2021-09-22 14:01:36 +00:00
TredwellGit
4fb126fd16 linux: 5.14.6 -> 5.14.7
(cherry picked from commit 1c9f17fb9a1f3d47c393c19e1f8ca511ca6003be)
2021-09-22 14:01:36 +00:00
TredwellGit
4c482c8806 linux: 5.10.67 -> 5.10.68
(cherry picked from commit a70237df86464ed69b12bdbf178ac8d0ddc1004e)
2021-09-22 14:01:35 +00:00
TredwellGit
08a2d25f1b linux: 4.9.282 -> 4.9.283
(cherry picked from commit 49a443bd0a5f5f884e32bc3a67b5580a718a73df)
2021-09-22 14:01:34 +00:00
TredwellGit
9a87d91efa linux: 4.4.283 -> 4.4.284
(cherry picked from commit cd0d8fe6ee5c3c83f1814ac6dc57ff8e3e95d0c8)
2021-09-22 14:01:33 +00:00
TredwellGit
ebf6ced326 linux: 4.19.206 -> 4.19.207
(cherry picked from commit e4d0654060fb7321ec18f2d3e60c28ae816ac900)
2021-09-22 14:01:32 +00:00
TredwellGit
c1aefa39a4 linux: 4.14.246 -> 4.14.247
(cherry picked from commit 5e7bea92a24e5627817d0ad245fe09a0c1b48afd)
2021-09-22 14:01:31 +00:00
Pavol Rusnak
e42f91e090 Merge pull request #138930 from NixOS/backport-138927-to-release-21.05
[Backport release-21.05] electron_12: 12.1.1 -> 12.1.2
2021-09-22 14:10:52 +02:00
github-actions[bot]
caef8694df Merge staging-next-21.05 into staging-21.05 2021-09-22 12:03:23 +00:00
github-actions[bot]
3ab20e4ba4 Merge release-21.05 into staging-next-21.05 2021-09-22 12:02:42 +00:00
TredwellGit
4f0a4caae0 electron_12: 12.1.1 -> 12.1.2
https://github.com/electron/electron/releases/tag/v12.1.2
(cherry picked from commit e39bc2d9af)
2021-09-22 11:09:27 +00:00
Jörg Thalheim
83413f4780 Merge pull request #138828 from hmenke/zfs
[21.05] zfs: Linux 5.14 compatibility
2021-09-22 07:20:06 +01:00
Artturi
9e819a3383 Merge pull request #138755 from NixOS/backport-136493-to-staging-21.05
[Backport staging-21.05] qt5.qtbase: Enable parallel building
2021-09-22 06:54:02 +03:00
github-actions[bot]
9e4aee2133 Merge staging-next-21.05 into staging-21.05 2021-09-22 00:03:02 +00:00
github-actions[bot]
47a6b7ccf4 Merge release-21.05 into staging-next-21.05 2021-09-22 00:02:28 +00:00
Robert Scott
2216c1b659 Merge pull request #138851 from NixOS/revert-138557-backport-138417-to-staging-21.05
Revert "[Backport staging-21.05] gd: 2.3.0 -> 2.3.3"
2021-09-22 00:39:19 +01:00
Robert Scott
e0bcfe1ae3 Revert "[Backport staging-21.05] gd: 2.3.0 -> 2.3.3" 2021-09-22 00:31:09 +01:00
Artturi
12f3f58f48 Merge pull request #138796 from NixOS/backport-138762-to-release-21.05
[Backport release-21.05] nginx: fix URLs by taking from a specific commit
2021-09-21 23:47:31 +03:00
Maximilian Bosch
30442ab6d4 Merge pull request #138835 from NixOS/backport-138705-to-release-21.05
[Backport release-21.05] matrix-synapse: 1.42.0 -> 1.43.0
2021-09-21 22:41:04 +02:00
Sumner Evans
8d6407e5a4 matrix-synapse: 1.42.0 -> 1.43.0
(cherry picked from commit a8fbb74572)
2021-09-21 19:46:20 +00:00
Henri Menke
6c840afdc5 zfsUnstable: 2.1.0 -> 2.1.1 2021-09-21 20:33:02 +02:00
Henri Menke
2179499ba7 zfs: 2.0.5 -> 2.0.6 2021-09-21 20:32:48 +02:00
Maximilian Bosch
543cf1d543 Merge pull request #138804 from Ma27/backport-matrix-test
[21.05] matrix-synapse: enable parallel tests
2021-09-21 20:05:27 +02:00
github-actions[bot]
e872581176 Merge staging-next-21.05 into staging-21.05 2021-09-21 18:02:58 +00:00
github-actions[bot]
045a7ba01b Merge release-21.05 into staging-next-21.05 2021-09-21 18:02:23 +00:00
embr
04c2339cc1 nixos/mastodon: Add configurable web- and streaming concurrency
Might as well do this while I'm at it.

(cherry picked from commit 0d719125baee88e2e8d29e6bb2ff3100ba1b2da0)
2021-09-21 19:41:32 +02:00
embr
4f8927c417 nixos/mastodon: Fix sidekiq's DB_POOL, add configurable concurrency
The `services.mastodon` module currently hardcodes sidekiq's concurrency
to 25, but doesn't set a DB pool size, which defaults to 5 or the number
of configured web threads.

(This behaviour is very strange, and arguably a mastodon bug.)

This also makes sidekiq's concurrency configurable, because 25 is a tad
high for the hardware I'm running it on.

(cherry picked from commit e8fd7792d1eeb4ea4943cc34525da1159ab50bc9)
2021-09-21 19:41:32 +02:00
FliegendeWurst
64da7fe56f tor-browser-bundle-bin: 10.5.5 -> 10.5.6
(cherry picked from commit 582e0a4926)
2021-09-21 12:13:16 +00:00
pennae
5c7c36a483 matrix-synapse: enable parallel tests
(cherry picked from commit 7574cf28fe)
2021-09-21 14:11:37 +02:00
Maximilian Bosch
cb996bbf84 Merge pull request #138794 from NixOS/backport-138481-to-release-21.05
[Backport release-21.05] Kernels 2021-09-18
2021-09-21 14:06:14 +02:00
github-actions[bot]
da098cd9b9 Merge staging-next-21.05 into staging-21.05 2021-09-21 12:03:16 +00:00
github-actions[bot]
199a113b66 Merge release-21.05 into staging-next-21.05 2021-09-21 12:02:38 +00:00
Lara
eb24e2e6b1 gitlab: 14.2.3 -> 14.2.4
(cherry picked from commit e5f70272c5)
2021-09-21 13:22:10 +02:00
James Kay
a53682d9f3 nginx: fix URLs by taking from a specific commit
I'm not sure this is the best way to get these patches, but it's better than `master` (at commit `e9617f553284b170a8b520d051ac1fc1b83cff30` on `nginx` these patches moved into a `nginx` subdirectory, breaking the build unless the patches are cached).

(cherry picked from commit c5d8765113)
2021-09-21 11:18:24 +00:00
ajs124
c52baeabe2 webkitgtk: 2.32.3 -> 2.32.4
https://webkitgtk.org/security/WSA-2021-0005.html
(cherry picked from commit 7e7a4021e8)
2021-09-21 11:12:41 +00:00
TredwellGit
b752e7829b linux/hardened/patches/5.14: 5.14.5-hardened1 -> 5.14.6-hardened1
(cherry picked from commit b8b772a1da)
2021-09-21 10:52:24 +00:00
TredwellGit
0731d03f57 linux/hardened/patches/5.13: 5.13.18-hardened1 -> 5.13.19-hardened1
(cherry picked from commit a41022ed40)
2021-09-21 10:52:23 +00:00
TredwellGit
174c38c553 linux/hardened/patches/5.10: 5.10.66-hardened1 -> 5.10.67-hardened1
(cherry picked from commit 4a9ffb82ae)
2021-09-21 10:52:23 +00:00
TredwellGit
16e4fb1aad linux-rt_5_10: 5.10.59-rt52 -> 5.10.65-rt53
(cherry picked from commit 3e87ddbf57)
2021-09-21 10:52:22 +00:00
TredwellGit
76bdc20f22 linux: 5.14.5 -> 5.14.6
(cherry picked from commit 51b0e44980)
2021-09-21 10:52:21 +00:00
TredwellGit
4dcfb25299 linux: 5.13.18 -> 5.13.19
(cherry picked from commit 748679c0d3)
2021-09-21 10:52:21 +00:00
TredwellGit
02e05becea linux: 5.10.66 -> 5.10.67
(cherry picked from commit 66760dcbd5)
2021-09-21 10:52:20 +00:00
github-actions[bot]
7a7495bcb8 Merge staging-next-21.05 into staging-21.05 2021-09-21 00:03:22 +00:00
github-actions[bot]
9990b7618f Merge release-21.05 into staging-next-21.05 2021-09-21 00:02:47 +00:00
sternenseemann
3397f0ede9 gitit: 0.13.0.0 -> 0.15.0.0
Resolves #138664
2021-09-21 00:15:21 +02:00
adisbladis
dfe2998cba qt5.qtbase: Enable parallel building
(cherry picked from commit 54a62ba008)
2021-09-20 21:52:21 +00:00
github-actions[bot]
efd7aed56a Merge staging-next-21.05 into staging-21.05 2021-09-20 12:03:02 +00:00
github-actions[bot]
dee256af41 Merge release-21.05 into staging-next-21.05 2021-09-20 12:02:27 +00:00
Kim Lindberger
49c1d39164 Merge pull request #138606 from NixOS/backport-138160-to-release-21.05
[Backport release-21.05] pipewire: 0.3.35 -> 0.3.36
2021-09-20 12:51:29 +02:00
Michael Weiss
ae29263816 Merge pull request #138567 from primeos/ungoogled-chromium-backport
[21.05] ungoogled-chromium: 92.0.4515.159 -> 93.0.4577.82
2021-09-20 11:07:31 +02:00
Jörg Thalheim
53063b4e3c libsixel: 1.8.6 -> 1.10.1
- Switched to maintained fork of libsixel
- Linked CVEs were fixed in 1.10.1

(cherry picked from commit 8668224108)
2021-09-20 07:57:19 +00:00
Jan Solanti
701e0a55b0 pipewire: 0.3.35 -> 0.3.36
(cherry picked from commit 996b51ee85)
2021-09-20 06:27:38 +00:00
Kim Lindberger
d15b1724c9 Merge pull request #138118 from NixOS/backport-137533-to-release-21.05
[Backport release-21.05] pipewire: 0.3.34 -> 0.3.35
2021-09-20 08:22:10 +02:00
github-actions[bot]
b26321cc1b Merge staging-next-21.05 into staging-21.05 2021-09-20 06:03:12 +00:00
github-actions[bot]
c8b62412a7 Merge release-21.05 into staging-next-21.05 2021-09-20 06:02:32 +00:00
Doron Behar
14bc56e94a Merge pull request #138557 from NixOS/backport-138417-to-staging-21.05 2021-09-20 04:57:28 +00:00
Martin Weinelt
60f651c276 Merge pull request #138355 from mweinelt/21.05/ansible 2021-09-20 02:39:37 +02:00
figsoda
27885874ed Merge pull request #138593 from NixOS/backport-138546-to-release-21.05
[Backport release-21.05] cawbird: 1.4.1 -> 1.4.2
2021-09-19 20:25:06 -04:00
Trolli Schmittlauch
8f5774b774 cawbird: 1.4.1 -> 1.4.2
maintenance and bugfix release, see upstream changelog https://github.com/IBBoard/cawbird/releases/tag/v1.4.2

(cherry picked from commit 1e7edcb21f)
2021-09-20 00:20:20 +00:00
github-actions[bot]
da1535999c Merge staging-next-21.05 into staging-21.05 2021-09-20 00:03:37 +00:00
github-actions[bot]
51e0fd2901 Merge release-21.05 into staging-next-21.05 2021-09-20 00:03:04 +00:00
figsoda
038f11b863 Merge pull request #138556 from NixOS/backport-138518-to-release-21.05
[Backport release-21.05] haproxy: 2.3.13 -> 2.3.14
2021-09-19 17:49:02 -04:00
Michael Weiss
af4338e6e7 ungoogled-chromium: 92.0.4515.159 -> 93.0.4577.82
(cherry picked from commit f8b837c808)
2021-09-19 22:27:44 +02:00
Yureka
f7be049abd chromiumDev: fix build
(cherry picked from commit a34f7dbb73)
2021-09-19 22:26:40 +02:00
Michael Weiss
559b5adf07 chromiumDev: 95.0.4636.4 -> 95.0.4638.10
(cherry picked from commit 6a40706d51)
2021-09-19 22:26:40 +02:00
Michael Weiss
1f71320536 chromiumBeta: 94.0.4606.41 -> 94.0.4606.50
(cherry picked from commit a11784ab9c)
2021-09-19 22:26:39 +02:00
Michael Weiss
25bbb6bfcc chromiumDev: 95.0.4628.3 -> 95.0.4636.4
(cherry picked from commit 6094ee5b4f)
2021-09-19 22:26:38 +02:00
Michael Weiss
57b9911c36 chromiumBeta: 94.0.4606.31 -> 94.0.4606.41
(cherry picked from commit 05c0b2743f)
2021-09-19 22:26:36 +02:00
Robert Scott
fc4cae6760 gd: 2.3.0 -> 2.3.3
remove now-included patch

this partially resolves CVE-2021-40812

(cherry picked from commit d6f49708212822b6a3c0fe598f3a20abf8676990)
2021-09-19 18:06:44 +00:00
Thomas Gerbet
8799bbcb22 haproxy: 2.3.13 -> 2.3.14
Fixes CVE-2021-40346.

(cherry picked from commit 0bdde7ecdf)
2021-09-19 18:06:09 +00:00
github-actions[bot]
5908cfc30b Merge staging-next-21.05 into staging-21.05 2021-09-19 18:02:58 +00:00
github-actions[bot]
1181e3fd06 Merge release-21.05 into staging-next-21.05 2021-09-19 18:02:26 +00:00
Robert Scott
d7789bdd9f Merge pull request #138543 from NixOS/backport-138522-to-release-21.05
[Backport release-21.05] wget: 1.21.1 -> 1.21.2
2021-09-19 18:02:19 +01:00
Thomas Gerbet
c1f3dffbee wget: 1.21.1 -> 1.21.2
Fixes CVE-2021-31879.

(cherry picked from commit 303cce3fa06ef9bd97e9fcd35b8c5be683800995)
2021-09-19 15:57:38 +00:00
github-actions[bot]
0e9c6b5f88 Merge staging-next-21.05 into staging-21.05 2021-09-19 12:02:33 +00:00
github-actions[bot]
2f30c1dada Merge release-21.05 into staging-next-21.05 2021-09-19 12:02:02 +00:00
Bjørn Forsman
79cfaa09fa phoronix-test-suite: run missing hooks: preInstall, postInstall
(cherry picked from commit ef44879599)
2021-09-19 11:45:41 +02:00
Michael Raskin
317f0270aa Merge pull request #138456 from NixOS/backport-138430-to-release-21.05
[Backport release-21.05] atftp: 0.7.4 -> 0.7.5, enable tests
2021-09-19 08:51:30 +00:00
github-actions[bot]
717e1b10c7 Merge staging-next-21.05 into staging-21.05 2021-09-19 00:03:32 +00:00
github-actions[bot]
6c5cbd1e21 Merge release-21.05 into staging-next-21.05 2021-09-19 00:02:55 +00:00
Robert Scott
2bfe1df1f9 atftp: enable tests
(cherry picked from commit 70da176466)
2021-09-18 20:04:01 +00:00
Robert Scott
d62d02793c atftp: 0.7.4 -> 0.7.5
(cherry picked from commit 1084233889)
2021-09-18 20:04:00 +00:00
Michael Weiss
6120ac5cd2 Merge pull request #138455 from NixOS/backport-138411-to-release-21.05
[Backport release-21.05] signal-desktop: 5.17.1 -> 5.17.2
2021-09-18 21:31:09 +02:00
Michael Weiss
a263221d7a signal-desktop: 5.17.1 -> 5.17.2
(cherry picked from commit f9958a835a)
2021-09-18 19:08:07 +00:00
github-actions[bot]
2ab68f611c Merge staging-next-21.05 into staging-21.05 2021-09-18 18:03:20 +00:00
github-actions[bot]
252b84db57 Merge release-21.05 into staging-next-21.05 2021-09-18 18:02:40 +00:00
Maximilian Bosch
edcae2fea3 Merge pull request #138426 from NixOS/backport-138304-to-release-21.05
[Backport release-21.05] ferdi: 5.6.0 -> 5.6.2
2021-09-18 19:00:11 +02:00
Maximilian Bosch
f58d72cad1 ferdi: 5.6.0 -> 5.6.2
ChangeLogs:
* https://github.com/getferdi/ferdi/releases/tag/v5.6.1
* https://github.com/getferdi/ferdi/releases/tag/v5.6.2

(cherry picked from commit 11f81f9071)
2021-09-18 14:19:14 +00:00
github-actions[bot]
c1ac24653b Merge staging-next-21.05 into staging-21.05 2021-09-18 12:03:04 +00:00
github-actions[bot]
e71a8d2db9 Merge release-21.05 into staging-next-21.05 2021-09-18 12:02:27 +00:00
Maximilian Bosch
89882817b7 Merge pull request #138331 from sumnerevans/backport-137869-to-release-21.05
[21.05] element-{web,desktop}: 1.8.4 -> 1.8.5
2021-09-18 13:55:06 +02:00
Maximilian Bosch
6cc3bda369 element-desktop: fix eval 2021-09-18 13:29:56 +02:00
Alyssa Ross
8268ee4368 squashfs-tools-ng: 1.1.2 -> 1.1.3
(cherry picked from commit 6e25d39cfd)
2021-09-18 11:26:31 +00:00
Michael Weiss
6a3729e4da Merge pull request #137897 from NixOS/backport-137888-to-release-21.05
[Backport release-21.05] chromium: 93.0.4577.63 -> 93.0.4577.82
2021-09-18 12:12:37 +02:00
github-actions[bot]
de45944195 Merge staging-next-21.05 into staging-21.05 2021-09-18 06:04:21 +00:00
github-actions[bot]
fb2ea82526 Merge release-21.05 into staging-next-21.05 2021-09-18 06:03:18 +00:00
Artturi
75c1664b44 Merge pull request #138238 from drupol/backport-138177-to-release-21.05
[Backport release-21.05] symfony-cli: 4.26.0 -> 4.26.3
2021-09-18 05:33:58 +03:00
OPNA2608
4d57dddc80 palemoon: 29.4.0.2 -> 29.4.1
(cherry picked from commit 0597172c12)
2021-09-18 02:17:21 +00:00
Martin Weinelt
5db0a5d9a8 ansible_2_9: 2.9.25 -> 2.9.26
(cherry picked from commit 662df6f4ab)
2021-09-18 03:51:41 +02:00
Martin Weinelt
e651e0ed60 ansible_2_10: 2.10.13 -> 2.10.14
(cherry picked from commit 4156a5516d)
2021-09-18 03:51:41 +02:00
Martin Weinelt
68ba4fd43c ansible_2_11: 2.11.4 -> 2.11.5
(cherry picked from commit 31f932af46)
2021-09-18 03:51:41 +02:00
Martin Weinelt
c1aea1347e ansible_2_11.collections: 4.4.0 -> 4.5.0
(cherry picked from commit 6cb6e67ba1)
2021-09-18 03:51:41 +02:00
Jörg Thalheim
248a53d37a ansible: fix https url
(cherry picked from commit b113d0c203)
2021-09-18 03:51:41 +02:00
Martin Weinelt
8fef5752e4 python3Packages.ansible: 2.9.24 -> 2.9.25
(cherry picked from commit 351eacd7b9)
2021-09-18 03:51:41 +02:00
Martin Weinelt
27a85d3fb6 python3Packages.ansible-core.collections: 4.2.0 -> 4.4.0
(cherry picked from commit 9dd696bebb)
2021-09-18 03:51:41 +02:00
Martin Weinelt
47a2720118 python3Packages.ansible-core: 2.11.3 -> 2.11.4
(cherry picked from commit aed6574b7e)
2021-09-18 03:51:41 +02:00
Martin Weinelt
b72e5dddca python3Packages.ansible-base: 2.10.12 -> 2.10.13
(cherry picked from commit a02ec1002d)
2021-09-18 03:51:41 +02:00
Austin Butler
8fa3d05020 pythonPackages.resolvelib: 0.7.1 -> 0.5.5
(cherry picked from commit c070b9e4f5)
2021-09-18 03:51:41 +02:00
Martin Weinelt
a7635ed014 python3Packages.resolvelib: 0.7.0 -> 0.7.1
(cherry picked from commit 50140f70d5)
2021-09-18 03:51:41 +02:00
Martin Weinelt
c2a0f606fc python3Packages.ansible: 2.9.23 -> 2.9.24
(cherry picked from commit a9206d8c4c)
2021-09-18 03:51:41 +02:00
Martin Weinelt
94bdd1f98c python3Packages.ansible-core.collections: 4.1.0 -> 4.2.0
(cherry picked from commit dc1137bc98)
2021-09-18 03:51:41 +02:00
Martin Weinelt
98f655786a python3Packages.ansible-base: 2.10.11 -> 2.10.12
(cherry picked from commit 32d5641120)
2021-09-18 03:51:41 +02:00
Martin Weinelt
0c9daa6b7a python3Packages.ansible-core: 2.11.2 -> 2.11.3
(cherry picked from commit 1e462be4eb)
2021-09-18 03:51:40 +02:00
Martin Weinelt
ba21a7bc10 ansible, ansible_2_10: internalize collections package
This drops the python3Packages.ansible-collections attribute in favor of
a local callPackage that overwrites the collections package per ansible
version.

(cherry picked from commit ca618d6401)
2021-09-18 03:51:40 +02:00
Martin Weinelt
10f8ee55fe ansible: 2.11.1 -> 2.11.2
(cherry picked from commit bedf7abd6a)
2021-09-18 03:51:40 +02:00
R. RyanTM
6ae0a35f2c ansible: 2.11.0 -> 2.11.1
(cherry picked from commit 41f507b1ef)
2021-09-18 03:51:40 +02:00
Martin Weinelt
e3bd81828b ansible_2_11: init 2021-09-18 03:51:40 +02:00
Martin Weinelt
6a7d63f3d6 python3Packages.ansible-core: init at 2.11.0
(cherry picked from commit 8e390750e3)
2021-09-18 03:51:40 +02:00
Martin Weinelt
658b63c41b python3Packages.resolvelib: init at 0.7.0
(cherry picked from commit 23414c5026)
2021-09-18 03:51:40 +02:00
Sandro Jäckel
231881e440 python3Packages.commentjson: init at 0.9.0
(cherry picked from commit b36764fcbe)
2021-09-18 03:51:40 +02:00
github-actions[bot]
1b379960f0 Merge staging-next-21.05 into staging-21.05 2021-09-18 00:03:24 +00:00
github-actions[bot]
7def88012f Merge release-21.05 into staging-next-21.05 2021-09-18 00:02:49 +00:00
Sumner Evans
b194ad04ea element-{web,desktop}: 1.8.4 -> 1.8.5
(cherry picked from commit 04732d7c56)

See https://github.com/NixOS/nixpkgs/pull/137869
2021-09-17 17:45:30 -04:00
John Ericson
dba5c42f73 Merge pull request #138320 from NixOS/backport-138305-to-release-21.05
[Backport release-21.05] cc-wrapper: Add support for -mthumb / -marm
2021-09-17 15:15:43 -04:00
John Ericson
7ff267798e cc-wrapper: Add support for -mthumb / -marm
(cherry picked from commit d3407f1a3b)
2021-09-17 19:03:07 +00:00
github-actions[bot]
4d34318507 Merge staging-next-21.05 into staging-21.05 2021-09-17 18:03:01 +00:00
github-actions[bot]
8accc2f968 Merge release-21.05 into staging-next-21.05 2021-09-17 18:02:27 +00:00
ajs124
2c75ca9c41 Merge pull request #138276 from NeQuissimus/2105_hardened_backport
[21.05] Hardened kernels backports
2021-09-17 18:04:05 +02:00
Maximilian Bosch
9723430b08 Merge pull request #138282 from NixOS/backport-138114-to-release-21.05
[Backport release-21.05] wireguard-tools: 1.0.20210424 -> 1.0.20210914
2021-09-17 16:41:42 +02:00
ajs124
756786068f linux/hardened/patches/5.14: 5.14.4-hardened1 -> 5.14.5-hardened1
(cherry picked from commit 9f34448a98)
2021-09-17 10:16:51 -04:00
ajs124
939149de74 linux/hardened/patches/5.4: 5.4.146-hardened1 -> 5.4.147-hardened1
(cherry picked from commit 36e21638f5)
2021-09-17 10:16:50 -04:00
ajs124
e6b00f2f5f linux/hardened/patches/5.13: 5.13.17-hardened1 -> 5.13.18-hardened1
(cherry picked from commit 7c04d2e390)
2021-09-17 10:16:50 -04:00
ajs124
f35f202e06 linux/hardened/patches/5.10: 5.10.65-hardened1 -> 5.10.66-hardened1
(cherry picked from commit 031afe4faa)
2021-09-17 10:16:50 -04:00
Maximilian Bosch
0e29479866 wireguard-tools: 1.0.20210424 -> 1.0.20210914
ChangeLog: https://lists.zx2c4.com/pipermail/wireguard/2021-September/007049.html

This doesn't seem to have any implications for NixOS users, but appears
to have a few fixes that seem relevant to Darwin users including:

    wg-quick: darwin: account for "link#XX" gateways

    On macOS, under specific configurations, the `netstat -nr -f inet` and
    `netstat -nr -f inet6` outputs break gateway collection.

(cherry picked from commit d37ab4d0ee)
2021-09-17 13:55:18 +00:00
Maximilian Bosch
cdc1eaf2f4 Merge pull request #138162 from NixOS/backport-138149-to-release-21.05
[Backport release-21.05] Kernels 2021-09-16
2021-09-17 15:51:34 +02:00
github-actions[bot]
0727e24c5c Merge staging-next-21.05 into staging-21.05 2021-09-17 12:02:59 +00:00
github-actions[bot]
08374b2bd8 Merge release-21.05 into staging-next-21.05 2021-09-17 12:02:25 +00:00
happysalada
30d0257247 vscodium: fix sha256 on linux
(cherry picked from commit 65a010bcea)
2021-09-17 19:10:27 +09:00
nixpkgs-upkeep-bot
5f4c5d41ea vscodium: 1.60.0 -> 1.60.1
(cherry picked from commit 4828eb7ae4)
2021-09-17 19:10:27 +09:00
R. RyanTM
912279a742 symfony-cli: 4.26.0 -> 4.26.3
(cherry picked from commit ff6fb898ac)
2021-09-17 09:25:41 +02:00
github-actions[bot]
2757c95daf Merge staging-next-21.05 into staging-21.05 2021-09-17 00:04:52 +00:00
github-actions[bot]
719329b2d9 Merge release-21.05 into staging-next-21.05 2021-09-17 00:04:13 +00:00
Pavol Rusnak
ebf419e737 Merge pull request #137988 from prusnak/electron-21.05
[21.05] electron_12: 12.1.0 -> 12.1.1
2021-09-17 00:21:07 +02:00
R. RyanTM
e14424cb36 github-runner: 2.282.0 -> 2.282.1
(cherry picked from commit af750c6f54)
2021-09-16 21:35:02 +00:00
Luke Granger-Brown
6ffcbaf54d Merge pull request #138171 from NixOS/backport-136194-to-release-21.05
[Backport release-21.05] apr: add patch for CVE-2021-35940
2021-09-16 21:06:57 +01:00
Luke Granger-Brown
b9e98053fe Merge pull request #138170 from NixOS/backport-138136-to-release-21.05
[Backport release-21.05] apacheHttpd: 2.4.48 -> 2.4.49
2021-09-16 21:05:50 +01:00
Robert Scott
ef698f793f apr: add patch for CVE-2021-35940
(cherry picked from commit c6c39b5944)
2021-09-16 18:45:22 +00:00
Aaron Andersen
6fbf63ac60 apacheHttpd: 2.4.48 -> 2.4.49
(cherry picked from commit 0518560cf1)
2021-09-16 18:34:07 +00:00
TredwellGit
6c5790dfb6 linux/hardened/patches/5.4: 5.4.144-hardened1 -> 5.4.146-hardened1
(cherry picked from commit 00c500e9fc)
2021-09-16 16:18:21 +00:00
TredwellGit
fbc340ce50 linux/hardened/patches/5.14: 5.14.2-hardened1 -> 5.14.4-hardened1
(cherry picked from commit 60b7113164)
2021-09-16 16:18:20 +00:00
TredwellGit
cc619f3c02 linux/hardened/patches/5.13: 5.13.15-hardened1 -> 5.13.17-hardened1
(cherry picked from commit a8de1dcd2b)
2021-09-16 16:18:19 +00:00
TredwellGit
a1b9329753 linux/hardened/patches/5.10: 5.10.63-hardened1 -> 5.10.65-hardened1
(cherry picked from commit 48e902a2ef)
2021-09-16 16:18:19 +00:00
TredwellGit
49d3b04cd9 linux: 5.4.145 -> 5.4.147
(cherry picked from commit 100f0569b5)
2021-09-16 16:18:18 +00:00
TredwellGit
9b42fb070f linux: 5.14.3 -> 5.14.5
(cherry picked from commit 4a05e7297c)
2021-09-16 16:18:17 +00:00
TredwellGit
2521537c8f linux: 5.13.16 -> 5.13.18
(cherry picked from commit 4954336e2b)
2021-09-16 16:18:16 +00:00
TredwellGit
a3a2df2aaa linux: 5.10.64 -> 5.10.66
(cherry picked from commit 6c829ce083)
2021-09-16 16:18:15 +00:00
github-actions[bot]
f903c39d88 Merge staging-next-21.05 into staging-21.05 2021-09-16 12:03:28 +00:00
github-actions[bot]
0d2ff3fbab Merge release-21.05 into staging-next-21.05 2021-09-16 12:02:44 +00:00
Patrick Hilhorst
4d71703763 Merge pull request #137439 from NixOS/backport-137328-to-release-21.05 2021-09-16 13:34:36 +02:00
Jan Solanti
66528906a5 pipewire: enable manpages
(cherry picked from commit 044da009d1)
2021-09-16 09:48:45 +00:00
Jan Solanti
eae9551832 pipewire: 0.3.34 -> 0.3.35
(cherry picked from commit f4fbb21176)
2021-09-16 09:48:45 +00:00
github-actions[bot]
d8bd6671da Merge staging-next-21.05 into staging-21.05 2021-09-15 12:02:43 +00:00
github-actions[bot]
b4cf42c516 Merge release-21.05 into staging-next-21.05 2021-09-15 12:02:09 +00:00
Jörg Thalheim
8dd8bd8be7 Merge pull request #137984 from NixOS/backport-137673-to-release-21.05
[Backport release-21.05] github-runner: 2.281.1 -> 2.282.0, prevent self-update
2021-09-15 12:44:29 +01:00
TredwellGit
e6b75fcb70 electron_12: 12.1.0 -> 12.1.1
https://github.com/electron/electron/releases/tag/v12.1.1
(cherry picked from commit 40d83a9a21)
2021-09-15 11:58:00 +02:00
Vincent Haupert
d58baa249b github-runner: 2.281.1 -> 2.282.0
(cherry picked from commit cd641476cf)
2021-09-15 09:50:00 +00:00
Vincent Haupert
ca41e07801 github-runner: prevent self-updates
As of yet, a patch caused the runner to discard update messages.
Unfortunately, GitHub keeps sending update messages to outdated runners
causing them to no longer pick up jobs.

This commit causes the runner to send a high version to GitHub which
should be more recent for quite a time. That way, GitHub does not send
update message and keeps scheduling jobs even for outdated runners.

Naturally, an oudated runner can still break at any time as GitHub's
current approach assumes that all runners are always up-to-date. We
should still strive for quick nixpkgs updates but this patch should give
us some time.

(cherry picked from commit e8bbcc79fd)
2021-09-15 09:49:59 +00:00
Vincent Haupert
04e8a8cd56 github-runner: use dummy SHA-1 as GitInfoCommitHash
The runner only references `GitInfoCommitHash`/`CommitHash` to print
informational log entries. To allow for just referencing the tag of a
version instead of the commit hash, this commit sets the value of the
`GitInfoCommitHash` to a static dummy value.

(cherry picked from commit cc5c902fdf)
2021-09-15 09:49:58 +00:00
Jörg Thalheim
cffe74fead Merge pull request #137162 from NixOS/backport-136988-to-release-21.05
[Backport release-21.05] github-runner: 2.279.0 -> 2.281.1
2021-09-15 10:45:26 +01:00
Michael Weiss
4c2e7becf1 Merge pull request #137889 from NixOS/backport-137759-to-release-21.05
[Backport release-21.05] signal-desktop: 5.17.0 -> 5.17.1
2021-09-15 10:54:25 +02:00
github-actions[bot]
eb58d7a208 Merge staging-next-21.05 into staging-21.05 2021-09-15 00:03:19 +00:00
github-actions[bot]
1158f0ecc1 Merge release-21.05 into staging-next-21.05 2021-09-15 00:02:46 +00:00
Vladimír Čunát
a59d9b39f1 Merge branch 'staging-next-21.05' into release-21.05 2021-09-14 23:10:11 +02:00
Michael Weiss
762bb52325 chromium: 93.0.4577.63 -> 93.0.4577.82
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop.html

This update includes 11 security fixes. Google is aware that exploits
for CVE-2021-30632 and CVE-2021-30633 exist in the wild.

CVEs:
CVE-2021-30625 CVE-2021-30626 CVE-2021-30627 CVE-2021-30628
CVE-2021-30629 CVE-2021-30630 CVE-2021-30631 CVE-2021-30632
CVE-2021-30633

(cherry picked from commit 61e54424ba)
2021-09-14 21:06:36 +00:00
R. RyanTM
224196a661 signal-desktop: 5.17.0 -> 5.17.1
(cherry picked from commit e3c0374da4)
2021-09-14 20:46:52 +00:00
github-actions[bot]
84bab5e90c Merge staging-next-21.05 into staging-21.05 2021-09-14 18:02:49 +00:00
github-actions[bot]
7f31a4f82d Merge release-21.05 into staging-next-21.05 2021-09-14 18:02:14 +00:00
Guillaume Girol
f7c79f29ac Merge pull request #137311 from symphorien/evolution-stable-update
[21.05] evolution, evolution-ews, evolution-data-server: backport patch release bumps
2021-09-14 17:21:42 +00:00
Bernardo Meurer
f5db08830f Merge pull request #137683 from NixOS/backport-137671-to-release-21.05
[Backport release-21.05] firefox-unwrapped: workaround issues on non-Gnome wayland WM's on FF 92
2021-09-14 16:24:33 +00:00
github-actions[bot]
de1c435656 Merge staging-next-21.05 into staging-21.05 2021-09-14 12:02:50 +00:00
github-actions[bot]
1d1b9bf49a Merge release-21.05 into staging-next-21.05 2021-09-14 12:02:14 +00:00
Maximilian Bosch
626ae0eeba element-desktop: apply patch to run on Wayland (#137666)
See upstream PR#261[1] for further reference. Previously, the
`enable-features`-setting was entirely discarded due to an earlier
regression resulting in an attempt to start `element-desktop` in
Wayland-mode without all necessary components.

Closes #137377

[1] https://github.com/vector-im/element-desktop/pull/261

(cherry picked from commit 5a0d0ec1cf)
2021-09-14 10:30:05 +02:00
github-actions[bot]
85e990280d Merge staging-next-21.05 into staging-21.05 2021-09-14 06:03:14 +00:00
github-actions[bot]
beeed5079f Merge release-21.05 into staging-next-21.05 2021-09-14 06:02:32 +00:00
Robert Scott
667c06be31 Merge pull request #137428 from risicle/ris-flask-appbuilder-3.3.2-r21.05
[21.05] python3Packages.flask-appbuilder: 3.3.0 -> 3.3.2
2021-09-14 01:20:28 +01:00
github-actions[bot]
c8b84c65f0 Merge staging-next-21.05 into staging-21.05 2021-09-14 00:03:05 +00:00
github-actions[bot]
7206c7cf0b Merge release-21.05 into staging-next-21.05 2021-09-14 00:02:30 +00:00
Bernardo Meurer
25532a7fbb firefox-unwrapped: workaround issues on non-Gnome wayland WM's on FF 92
Closes: #137649
(cherry picked from commit dfccb3045e)
2021-09-13 12:53:50 -07:00
Timothy DeHerrera
f789739acc Merge pull request #137665 from NixOS/backport-106574-to-release-21.05
[Backport release-21.05] nixos/amazonImageZfs: init
2021-09-13 13:48:12 -06:00
Timothy DeHerrera
bee37e3ee0 Merge pull request #137676 from NixOS/backport-135568-to-release-21.05
[Backport release-21.05] ZFS: expand on boot
2021-09-13 13:48:00 -06:00
github-actions[bot]
5e2307a006 Merge staging-next-21.05 into staging-21.05 2021-09-13 18:03:49 +00:00
github-actions[bot]
fa10ff02d6 Merge release-21.05 into staging-next-21.05 2021-09-13 18:03:02 +00:00
Your Name
76e99647cd services.zfs.expandOnBoot: support expanding pools on boot
Either enumerating a list of pools to expand or expanding
all pools on boot.

(cherry picked from commit 4bb4bcc30c)
2021-09-13 17:42:07 +00:00
Maximilian Bosch
37eb0155b8 Merge pull request #137663 from NixOS/backport-137645-to-release-21.05
[Backport release-21.05] element-{web,desktop}: 1.8.2 -> 1.8.4
2021-09-13 18:58:08 +02:00
Graham Christensen
337eb213cf amazon images: extend the image-info.json to have a disks object
Having a disks object with a dictionary of all the disks and their
properties makes it easier to process multi-disk images.

Note the rename of `label` to `system_label` is because `$label`i
is something of a special token to jq.

(cherry picked from commit 71b3d18181)
2021-09-13 16:20:47 +00:00
Graham Christensen
a989fd1885 NixOS/amazonImageZfs: init
Introduce an AWS EC2 AMI which supports aarch64 and x86_64 with a ZFS
root.

This uses `make-zfs-image` which implies two EBS volumes are needed
inside EC2, one for boot, one for root. It should not matter which
is identified `xvda` and which is `xvdb`, though I have always
uploaded `boot` as `xvda`.

(cherry picked from commit bd38b059ea)
2021-09-13 16:20:46 +00:00
Graham Christensen
5d0154f812 nixos/make-zfs-image: init
This is a private interface for internal NixOS  use. It is similar
to `make-disk-image` except it is much more opinionated about what
kind of disk image it'll make.

Specifically, it will always create *two* disks:

1. a `boot` disk formatted with FAT in a hybrid GPT mode.
2. a `root` disk which is completely owned by a single zpool.

The partitioning and FAT decisions should make the resulting images
bootable under EFI or BIOS, with systemd-boot or grub.

The root disk's zpools options are highly customizable, including
fully customizable datasets and their options.

Because the boot disk and partition are highly opinionated, it is
expected that the `boot` disk will be mounted at `/boot`. It is
always labeled ESP even on BIOS boot systems.

In order for the datasets to be mounted properly, the `datasets`
passed in to `make-zfs-image` are turned in to NixOS configuration
stored at /etc/nixos/configuration.nix inside the VM.
NOTE: The function accepts a system configuration in the `config`
argument. The *caller* must manually configure the system
in `config` to have each specified `dataset` be represented
by a corresponding `fileSystems` entry.

One way to test the resulting images is with qemu:

```sh
boot=$(find ./result/ -name '*.boot.*');
root=$(find ./result/ -name '*.root.*');

echo '`Ctrl-a h` to get help on the monitor';
echo '`Ctrl-a x` to exit';

qemu-kvm \
    -nographic \
    -cpu max \
    -m 16G \
    -drive file=$boot,snapshot=on,index=0,media=disk \
    -drive file=$root,snapshot=on,index=1,media=disk \
    -boot c \
    -net user \
    -net nic \
    -msg timestamp=on
```

(cherry picked from commit 076f6e2d94)
2021-09-13 16:20:46 +00:00
Maximilian Bosch
f3510c5ee3 element-desktop: 1.8.2 -> 1.8.4
ChangeLog: https://github.com/vector-im/element-desktop/releases/tag/v1.8.4
(cherry picked from commit c81983ec9f)
2021-09-13 16:18:25 +00:00
Maximilian Bosch
9a984970b6 element-web: 1.8.2 -> 1.8.4
ChangeLog: https://github.com/vector-im/element-web/releases/tag/v1.8.4
(cherry picked from commit 55d25c13bd)
2021-09-13 16:18:25 +00:00
ajs124
b3083bc693 Merge pull request #137629 from drupol/update/php-7.4.21-to-7.4.23-backport-to-release-21.05
[Backport release-21.05] php74: 7.4.21 -> 7.4.23
2021-09-13 17:06:43 +02:00
ajs124
9544502814 Merge pull request #137655 from talyz/backport-php-8.0.10
[21.05] php80: 8.0.8 -> 8.0.10
2021-09-13 17:05:59 +02:00
Maximilian Bosch
85cdc98680 php80: 8.0.8 -> 8.0.10
ChangeLog: https://www.php.net/ChangeLog-8.php#8.0.10

(cherry picked from commit ab8017a2dd)
2021-09-13 16:09:39 +02:00
Maciej Krüger
f35f8db4b8 Merge pull request #137648 from NixOS/backport-137642-to-release-21.05
[Backport release-21.05] rPackages.RMySQL: fix package
2021-09-13 15:11:19 +02:00
Maciej Krüger
f5fb1a3080 rPackages.RMySQL: fix package
(cherry picked from commit a286dc9ef2)
2021-09-13 12:51:07 +00:00
github-actions[bot]
ecf565257b Merge staging-next-21.05 into staging-21.05 2021-09-13 12:02:54 +00:00
github-actions[bot]
0a354b4c0c Merge release-21.05 into staging-next-21.05 2021-09-13 12:02:22 +00:00
Vladimír Čunát
e9e40f6873 Merge #137572: Kernels 2021-09-12 (into staging-21.05) 2021-09-13 11:11:17 +02:00
Pol Dellaiera
72eba819ce php74: 7.4.21 -> 7.4.23
(cherry picked from commit 3fbb55710d)
2021-09-13 10:56:56 +02:00
Vladimír Čunát
9a3277af47 Merge #132287: jetty: 9.4.41.v20210516 -> 9.4.43.v20210629
...into release-21.05
2021-09-13 10:53:15 +02:00
Vladimír Čunát
dc5ab54b55 Merge #137455: go_1_16: 1.16.7 -> 1.16.8 (into staging-21.05) 2021-09-13 10:43:57 +02:00
Vladimír Čunát
99ee77dd6d Merge #137574: libexif: 0.6.22 -> 0.6.23 (into staging-21.05) 2021-09-13 10:40:25 +02:00
Vladimír Čunát
2082c70be4 Merge #137548: ghostscript: add passthru.tests (into staging-21.05) 2021-09-13 10:34:20 +02:00
Vladimír Čunát
4333ebdb1e Merge #137042: libgcrypt: 1.9.3 -> 1.9.4 (into staging-21.05) 2021-09-13 10:32:57 +02:00
Vladimír Čunát
52f01f7af7 Merge #136785: libarchive: 3.5.1 -> 3.5.2 (into staging-21.05) 2021-09-13 10:29:27 +02:00
Vladimír Čunát
1455454a93 Merge #136770: python3Packages.pillow: 8.3.1 -> 8.3.2 (into staging-21.05) 2021-09-13 10:24:37 +02:00
Vladimír Čunát
dd00c92fba Merge #135655: spidermonkey_78: fix build on armv7l (into staging-21.05) 2021-09-13 10:22:02 +02:00
github-actions[bot]
920bbd58f0 Merge staging-next-21.05 into staging-21.05 2021-09-13 00:03:38 +00:00
github-actions[bot]
45dff769df Merge release-21.05 into staging-next-21.05 2021-09-13 00:03:00 +00:00
Mario Rodas
53c72f9981 Merge pull request #137374 from risicle/ris-flask-restx-CVE-2021-32838
[21.05] python38Packages.flask-restx: add patch for CVE-2021-32838
2021-09-12 17:00:54 -05:00
Kerstin Humm
f569e48576 libexif: 0.6.22 -> 0.6.23
(cherry picked from commit 139cfd80d0)
2021-09-12 21:24:44 +00:00
Maximilian Bosch
042bd4f47b nixos/kernel: add 5.14 to kernel test-suite
Same as 2444c11431 on master.
2021-09-12 23:15:14 +02:00
Kerstin Humm
91fd4cf610 imagemagick: 7.1.0-5 -> 7.1.0-6
(cherry picked from commit 3e0e70d1d3)
2021-09-12 22:56:31 +02:00
Maximilian Bosch
92109a3f58 Merge pull request #137554 from NixOS/backport-137132-to-release-21.05
[Backport release-21.05] nixos/privacyidea: use `sudo(8)` that's configured via the module
2021-09-12 22:54:39 +02:00
TredwellGit
34570a89c0 linux-rt_5_4: 5.4.143-rt63 -> 5.4.143-rt64
(cherry picked from commit 5698fc0dfc)
2021-09-12 20:28:59 +00:00
TredwellGit
6541cd74b4 linux: 5.4.144 -> 5.4.145
(cherry picked from commit be590b86e2)
2021-09-12 20:28:59 +00:00
TredwellGit
316e874406 linux: 5.14.2 -> 5.14.3
(cherry picked from commit b81ac24356)
2021-09-12 20:28:58 +00:00
TredwellGit
e8a16eaa0d linux: 5.13.15 -> 5.13.16
(cherry picked from commit f0878c65eb)
2021-09-12 20:28:58 +00:00
TredwellGit
551b0b44c9 linux: 5.10.63 -> 5.10.64
(cherry picked from commit 71348196a0)
2021-09-12 20:28:57 +00:00
OPNA2608
f6268a8e31 corrscope: Fix ffmpeg package to ffmpeg-full
Otherwise it complains about missing ffplay.

(cherry picked from commit 271b6edba2)
2021-09-12 20:27:12 +00:00
TredwellGit
0d85dce13f steam: fix steamwebhelper
Fixes https://github.com/NixOS/nixpkgs/issues/137279 and https://github.com/ValveSoftware/steam-runtime/issues/462.

(cherry picked from commit 64c6851fd3acb13440bbffccf1fe386702725291)
2021-09-12 12:13:37 -07:00
Maximilian Bosch
5a17bb5d2b nixos/privacyidea: use sudo(8) that's configured via the module
(cherry picked from commit 69e75754d5)
2021-09-12 18:13:58 +00:00
github-actions[bot]
6a4d524347 Merge staging-next-21.05 into staging-21.05 2021-09-12 18:02:51 +00:00
github-actions[bot]
6f77cc7a91 Merge release-21.05 into staging-next-21.05 2021-09-12 18:02:21 +00:00
Maximilian Bosch
cedaaad5f5 Merge pull request #137545 from NixOS/backport-135751-to-release-21.05
[Backport release-21.05] nixos/promtail: Allow write access to positions file if not in CacheDirectory
2021-09-12 18:56:08 +02:00
Robert Scott
bf76456a65 ghostscript: add passthru.tests.test-corpus-render
this simply attempts rendering every ps/eps/pdf file in the ghostscript
test corpus

(cherry picked from commit 57692f6d3e)
2021-09-12 16:40:49 +00:00
Maximilian Bosch
bb1ccebd17 Merge pull request #137434 from NixOS/backport-137281-to-release-21.05
[Backport release-21.05] Kernels 2021-09-10
2021-09-12 18:22:24 +02:00
Maximilian Bosch
ee5a613395 Merge pull request #137266 from NixOS/backport-137187-to-release-21.05
[Backport release-21.05] Kernels 2021-09-09
2021-09-12 18:21:53 +02:00
Zhaofeng Li
f69c32ec21 nixos/promtail: Allow write access to positions file if not in CacheDirectory
Because of `ProtectSystem=strict`, Promtail cannot write to the positions
file if it's not in its `CacheDirectory` (the default value).

(cherry picked from commit b6ad701a2c)
2021-09-12 16:21:38 +00:00
Maximilian Bosch
1c67ae83db Merge pull request #137409 from NixOS/backport-136463-to-release-21.05
[Backport release-21.05] nixUnstable: 2.4pre20210802_47e96bb -> 2.4pre20210908_3c56f62
2021-09-12 18:20:13 +02:00
Maximilian Bosch
bad0efd147 Merge pull request #137524 from NixOS/backport-137510-to-release-21.05
[Backport release-21.05] wiki-js: 2.5.201 -> 2.5.214
2021-09-12 18:19:27 +02:00
Vladimír Čunát
e85f0175e3 Merge #137522: qt514.qt3d: fix upstream URL (into release-21.05) 2021-09-12 15:14:23 +02:00
Maximilian Bosch
caef9da135 wiki-js: 2.5.201 -> 2.5.214
ChangeLog: https://github.com/Requarks/wiki/releases/tag/2.5.214
(cherry picked from commit 75eaccdcbc)
2021-09-12 12:51:18 +00:00
Sergei Trofimovich
ad6e478766 qt514.qt3d: fix upstream URL
hydra can't build qt514.qt3d binary as it fails to fetch the tarball
from outdated source from:
    https://download.qt.io/official_releases/qt/
as it only contains `5.12`, `5.15`, `6.0` and `6.2`.

`/archive` still has the releases:
    https://download.qt.io/archive/qt/5.14/5.14.2/submodules/

Let's use those instead.

(cherry picked from commit 042119cade)
2021-09-12 12:48:55 +00:00
github-actions[bot]
4c43ed426c Merge staging-next-21.05 into staging-21.05 2021-09-12 12:03:41 +00:00
github-actions[bot]
605a18a027 Merge release-21.05 into staging-next-21.05 2021-09-12 12:03:10 +00:00
Vladimír Čunát
f9aaed3713 Merge #137298: thunderbird-bin: 91.0.3 -> 91.1.0 (into release-21.05) 2021-09-12 10:50:41 +02:00
Pavol Rusnak
a414ce0044 Merge pull request #136676 from prusnak/electron-21.05
[21.05] Electron updates
2021-09-12 10:13:03 +02:00
zowoq
c05d4e82d3 go_1_16: 1.16.7 -> 1.16.8
(cherry picked from commit a9dd9983de642b0d4522f2dc3cafa2be65562f7c)
2021-09-12 00:57:11 +00:00
github-actions[bot]
74cd4669ab Merge staging-next-21.05 into staging-21.05 2021-09-12 00:03:34 +00:00
github-actions[bot]
3130b7418d Merge release-21.05 into staging-next-21.05 2021-09-12 00:02:57 +00:00
nixpkgs-upkeep-bot
0602caca99 vscodium: 1.59.1 -> 1.60.0
(cherry picked from commit 93fea775e17c1266d0ff592dc63e0bfdc252be6c)
2021-09-11 21:00:11 +00:00
Tim Steinbach
075f639909 linux/hardened/patches/5.14: init at 5.14.2-hardened1
(cherry picked from commit 820d68d2dc)
2021-09-11 20:33:43 +00:00
Tim Steinbach
1309fb071c linux/hardened/patches/5.13: 5.13.14-hardened1 -> 5.13.15-hardened1
(cherry picked from commit 02b5c3b291)
2021-09-11 20:33:43 +00:00
Tim Steinbach
d9f651a0d2 linux/hardened/patches/5.10: 5.10.62-hardened1 -> 5.10.63-hardened1
(cherry picked from commit 3fe64b3728)
2021-09-11 20:33:42 +00:00
Artturi
05d063d9e6 Merge pull request #137414 from Artturin/backport-129273-to-release-21.05 2021-09-11 22:47:27 +03:00
Robert Scott
8125cc6fa7 python3Packages.flask-appbuilder: 3.3.1 -> 3.3.2
(cherry picked from commit 3f795e071d)
2021-09-11 19:49:58 +01:00
Ivan Tkachev
bcebae6c0b python3Packages.flask-appbuilder: 3.3.0 -> 3.3.1
(cherry picked from commit a3510b8eb6)
2021-09-11 19:49:41 +01:00
Guillaume Girol
63118e3dc5 Merge pull request #129454 from OPNA2608/update/openmpt123-0.5.10/21.05
[21.05] openmpt123: 0.5.8 -> 0.5.11
2021-09-11 18:12:26 +00:00
github-actions[bot]
e4d6c52ebf Merge staging-next-21.05 into staging-21.05 2021-09-11 18:03:18 +00:00
github-actions[bot]
5016004756 Merge release-21.05 into staging-next-21.05 2021-09-11 18:02:25 +00:00
Bernardo Meurer
ff224c89bd firefox: increase silent timeout to 14400s (4h)
Fixes: #129115
Replaces: #129212
(cherry picked from commit 919e2a98ac)
2021-09-11 20:59:21 +03:00
Maximilian Bosch
21c1c063da nixUnstable: 2.4pre20210802_47e96bb -> 2.4pre20210908_3c56f62
Main motivation for is the bugfix regarding flake-follows and
path-inputs[1]. An overview over all changes - mostly bugfixes -
can be found on GitHub[2].

[1] https://github.com/NixOS/nix/pull/4641
[2] 47e96bb...3c56f62093

(cherry picked from commit 04b552c323)
2021-09-11 17:07:42 +00:00
Bernardo Meurer
f661394e53 Merge pull request #137229 from nh2/thunderbird-CVE-2021-38495-21.05
[21.05] thunderbird: Update to fix CVE-2021-38495
2021-09-11 17:06:20 +00:00
Robert Scott
fbef3e574e python38Packages.flask-restx: add patch for CVE-2021-32838 2021-09-11 13:35:56 +01:00
Angus Trau
ccbc5e9a0e fragments: init at 1.5
(cherry picked from commit 1a7238dd32)
2021-09-11 10:58:56 +00:00
Angus Trau
1f61c32532 transmission: fix missing optional dependencies
(cherry picked from commit 37134b6072)
2021-09-11 10:58:55 +00:00
Angus Trau
cbb56e4837 libutp: init at unstable-2017-01-02
(cherry picked from commit adc89ca60d)
2021-09-11 10:58:55 +00:00
Angus Trau
1c49316e4d dht: init at 0.25
(cherry picked from commit 54099a0676)
2021-09-11 10:58:54 +00:00
OPNA2608
7c42b2adae openmpt123: 0.5.10 -> 0.5.11
(cherry picked from commit 68178096c6)

Excluding treewide renaming of this package.
2021-09-10 21:05:32 +02:00
Shamrock Lee
8abb3e29d4 [21.05] thunderbird-bin: 91.0.3 -> 91.1.0
Backport from #137175

Use release-source.nix changed in commit
706f6c57be

High-security fixes
2021-09-11 00:44:50 +08:00
Michael Raskin
9b13260e5f Merge pull request #136579 from maxeaubrey/21.05_glib_2.68.4
[21.05] glib: 2.68.2 -> 2.68.4
2021-09-10 15:49:47 +00:00
Tim Steinbach
a79fc9eb07 linux: 5.14.1 -> 5.14.2
(cherry picked from commit af1cc206a2018de2022a15166f06d8f3948d8456)
2021-09-10 12:05:22 +00:00
Tim Steinbach
582f4b93ef linux: 5.13.14 -> 5.13.15
(cherry picked from commit 1caac87c555b9a623dba47d621a7d8c8dae609a4)
2021-09-10 12:05:21 +00:00
Tim Steinbach
3fef4a375d linux: 5.10.62 -> 5.10.63
(cherry picked from commit 2262394b585370bfa87c70580f68dd16d33b4436)
2021-09-10 12:05:20 +00:00
github-actions[bot]
cc6415fd63 Merge staging-next-21.05 into staging-21.05 2021-09-10 12:03:08 +00:00
github-actions[bot]
ecae4d6bed Merge release-21.05 into staging-next-21.05 2021-09-10 12:02:34 +00:00
Martin Weinelt
8b0b81dab1 nss_latest: 3.68 -> 3.70 2021-09-10 08:00:45 -04:00
Martin Weinelt
cfeb077a73 firefox-78-esr: 78.13.1esr -> 78.14.0esr
(cherry picked from commit d11cd01ad1)
2021-09-10 08:00:45 -04:00
Martin Weinelt
c1f2adc76f firefox-91-esr: 91.0.1esr -> 91.1.0esr
(cherry picked from commit b31a7ba002)
2021-09-10 08:00:45 -04:00
Tim Steinbach
c810cc5632 firefox-unwrapped: 91.0.2 -> 92.0
(cherry picked from commit 21c5ff7850)
2021-09-10 08:00:45 -04:00
Martin Weinelt
528d6e2b8b Merge pull request #137208 from vcunat/p/knot-dns_bump
[21.05] knot-dns: 3.0.8 -> 3.0.9
2021-09-10 13:50:18 +02:00
Jörg Thalheim
bf6c393ba4 clang-tools: fix missing extra tools
fixes https://github.com/NixOS/nixpkgs/issues/128909

(cherry picked from commit f69522b227)
2021-09-10 13:05:38 +02:00
Michael Weiss
bde61d72f0 Merge pull request #137231 from NixOS/backport-137227-to-release-21.05
[Backport release-21.05] signal-desktop: 5.16.0 -> 5.17.0
2021-09-10 11:04:53 +02:00
Michael Weiss
b374471c04 signal-desktop: 5.16.0 -> 5.17.0
(cherry picked from commit 894ff4f2e4)
2021-09-09 21:33:44 +00:00
Niklas Hambüchen
de1ff3208f thunderbird-78: 78.13.0 -> 78.14.0
Fixes CVE-2021-38495:

https://www.mozilla.org/en-US/security/advisories/mfsa2021-41/#CVE-2021-38495
2021-09-09 22:56:08 +02:00
Niklas Hambüchen
2bb004dde3 thunderbird-91: 91.0.3 -> 91.1.0
Fixes CVE-2021-38495:

https://www.mozilla.org/en-US/security/advisories/mfsa2021-41/#CVE-2021-38495
2021-09-09 22:56:08 +02:00
Vladimír Čunát
7e6d1241ef knot-dns: 3.0.8 -> 3.0.9
(NixPkgs master is on 3.1.x already.)
https://gitlab.nic.cz/knot/knot-dns/-/tags/v3.0.9
2021-09-09 19:59:55 +02:00
Artturi
2861c42cc0 Merge pull request #136258 from NixOS/backport-135493-to-staging-21.05
[Backport staging-21.05] blas: fix library id on darwin
2021-09-09 19:32:44 +03:00
Ilan Joselevich
cfe6bd054c evolution-data-server: 3.40.3 -> 3.40.4 2021-09-09 15:16:53 +02:00
R. RyanTM
d526496577 evolution-data-server: 3.40.2 -> 3.40.3 2021-09-09 15:16:23 +02:00
R. RyanTM
56701ba000 evolution-ews: 3.40.1 -> 3.40.3 2021-09-09 15:15:03 +02:00
R. RyanTM
22cb735c09 evolution: 3.40.1 -> 3.40.3 2021-09-09 15:14:53 +02:00
Vincent Haupert
364426a01d github-runner: adapt to latest lttng-ust
ref: ab2501bd17
(cherry picked from commit 1614fc6eb6)
2021-09-09 07:40:18 +00:00
Vincent Haupert
ae4d181d6a github-runner: 2.279.0 -> 2.281.1
(cherry picked from commit ebcf2468ac)
2021-09-09 07:40:17 +00:00
Vincent Haupert
9214e84299 github-runner: make derivation easier to override
(cherry picked from commit 0d1e42786e)
2021-09-09 07:40:17 +00:00
github-actions[bot]
65cae77e59 Merge staging-next-21.05 into staging-21.05 2021-09-09 00:03:58 +00:00
github-actions[bot]
96f82c947f Merge release-21.05 into staging-next-21.05 2021-09-09 00:02:55 +00:00
Maximilian Bosch
276671abd1 Merge pull request #137130 from herrwiese/backport-135335-to-release-21.05
[backport release-21.05] grocy: 3.1.0 -> 3.1.1
2021-09-08 23:15:38 +02:00
R. RyanTM
168f530891 grocy: 3.1.0 -> 3.1.1
(cherry picked from commit e52facaf75)
2021-09-08 21:51:00 +02:00
github-actions[bot]
7e76877332 Merge staging-next-21.05 into staging-21.05 2021-09-08 18:02:50 +00:00
github-actions[bot]
f65f8a98dc Merge release-21.05 into staging-next-21.05 2021-09-08 18:02:12 +00:00
Tim Steinbach
b5c0ce5bef jenkins: 2.289.3 → 2.303.1
(cherry picked from commit 1342c4648b)
2021-09-08 18:04:54 +02:00
R. RyanTM
9778fa8f68 jenkins: 2.289.2 -> 2.289.3
(cherry picked from commit 7bc3dafc44)
2021-09-08 18:04:54 +02:00
Pamplemousse
30048c7078 nixos/modules/jenkins: Test the CLI
Signed-off-by: Pamplemousse <xav.maso@gmail.com>
(cherry picked from commit 4f093b8fdb)
2021-09-08 18:04:54 +02:00
Pamplemousse
3b60f6b0fd nixos/modules/jenkins: Add option to add CLI
Signed-off-by: Pamplemousse <xav.maso@gmail.com>
(cherry picked from commit 4265efef54)
2021-09-08 18:04:54 +02:00
Pamplemousse
49ce509559 jenkins: Create the jenkins-cli command
Signed-off-by: Pamplemousse <xav.maso@gmail.com>
(cherry picked from commit 6f6c649ec6)
2021-09-08 18:04:54 +02:00
R. RyanTM
2cf1fe5491 jenkins: 2.289.1 -> 2.289.2
(cherry picked from commit ad67354d1d)
2021-09-08 18:04:54 +02:00
R. RyanTM
4b14b10ffb jenkins: 2.277.4 -> 2.289.1
(cherry picked from commit 14a6aedeea)
2021-09-08 18:04:54 +02:00
Maximilian Bosch
c795f5af9f Merge pull request #137084 from NixOS/backport-136388-to-release-21.05
[Backport release-21.05] matrix-synapse: 1.41.1 -> 1.42.0
2021-09-08 17:53:23 +02:00
github-actions[bot]
ac9deb8dd4 Merge staging-next-21.05 into staging-21.05 2021-09-08 12:03:14 +00:00
github-actions[bot]
9bca1eee8d Merge release-21.05 into staging-next-21.05 2021-09-08 12:02:35 +00:00
Domen Kožar
12eb1d16ae Merge pull request #137087 from NixOS/backport-137086-to-release-21.05
[Backport release-21.05] foreman: 0.78.0 -> 0.87.2
2021-09-08 13:02:40 +02:00
zimbatm
c8c1922743 foreman: 0.78.0 -> 0.87.2
Fixes #90776

(cherry picked from commit 50793c3c45)
2021-09-08 10:03:25 +00:00
Sumner Evans
6ec23d9f3e matrix-synapse: 1.41.1 -> 1.42.0
(cherry picked from commit 8c6e887e75)
2021-09-08 09:09:35 +00:00
Michael Raskin
af7b550cd4 Merge pull request #137065 from NixOS/backport-137041-to-release-21.05
[Backport release-21.05] botan2: 2.18.0 -> 2.18.1, add patch for CVE-2021-40529
2021-09-08 07:00:46 +00:00
Robert Scott
2addd4e3ca botan: mark as vulnerable to CVE-2021-40529
(cherry picked from commit 785fa836a1)
2021-09-08 05:07:42 +00:00
Robert Scott
e8fe5c4eb4 botan2: add patch for CVE-2021-40529
(cherry picked from commit 63bf10c848)
2021-09-08 05:07:41 +00:00
Robert Scott
57ff6689cc botan2: 2.18.0 -> 2.18.1
(cherry picked from commit 509b969a18)
2021-09-08 05:07:40 +00:00
Robert Scott
0f6e8f74d2 libgcrypt: 1.9.3 -> 1.9.4
(cherry picked from commit e75b181a6a)
2021-09-08 00:26:28 +00:00
github-actions[bot]
feaee24fe8 Merge staging-next-21.05 into staging-21.05 2021-09-08 00:03:44 +00:00
github-actions[bot]
528d95d90e Merge release-21.05 into staging-next-21.05 2021-09-08 00:03:01 +00:00
Ricardo G
f201ecec33 ccloud-cli: 1.25 > 1.39
(cherry picked from commit a9e174c1ad7bd8ed2ac88891742bdcf01404e72a)
2021-09-07 22:25:50 +00:00
ajs124
93a7cb4aa5 Merge pull request #137029 from NixOS/backport-136944-to-release-21.05
[Backport release-21.05] linux_{4_14,4_19,5_4,5_10,5_13}_hardened: update patches
2021-09-07 23:25:28 +02:00
Bernardo Meurer
be513967cf linux_5_13_hardened: 5.13.13 -> 5.13.14
(cherry picked from commit abfa8098ac)
2021-09-07 21:00:11 +00:00
Bernardo Meurer
32ebfb9dc2 linux_5_10_hardened: 5.10.61 -> 5.10.62
(cherry picked from commit 1aba1d891f)
2021-09-07 21:00:10 +00:00
Bernardo Meurer
916f1c5d7b linux_5_4_hardened: 5.4.143 -> 5.4.144
(cherry picked from commit 8169d9283e)
2021-09-07 21:00:10 +00:00
Bernardo Meurer
e063d8c1b9 linux_4_19_hardened: 4.19.205 -> 4.19.206
(cherry picked from commit 1c0e5d13a9)
2021-09-07 21:00:09 +00:00
Bernardo Meurer
f6bb624285 linux_4_14_hardened: 4.14.245 -> 4.14.246
(cherry picked from commit 17681be1d3)
2021-09-07 21:00:09 +00:00
github-actions[bot]
c81f5fb6e0 Merge staging-next-21.05 into staging-21.05 2021-09-07 00:03:15 +00:00
github-actions[bot]
36ff6c97b8 Merge release-21.05 into staging-next-21.05 2021-09-07 00:02:43 +00:00
Artturi
e421291bdd Merge pull request #136933 from NixOS/backport-136789-to-release-21.05 2021-09-07 00:44:17 +03:00
Artturin
26522be526 gnome.gnome-boxes: add qemu to path
(cherry picked from commit ba1ecbea39)
2021-09-06 21:02:33 +00:00
github-actions[bot]
c4577c408b Merge staging-next-21.05 into staging-21.05 2021-09-06 12:02:48 +00:00
github-actions[bot]
d308622f68 Merge release-21.05 into staging-next-21.05 2021-09-06 12:02:15 +00:00
Domen Kožar
fd6dba4719 Merge pull request #136392 from NixOS/backport-135819-to-release-21.05
[Backport release-21.05] pipewire: 0.3.33 -> 0.3.34
2021-09-06 13:24:38 +02:00
github-actions[bot]
16780bf5f0 Merge staging-next-21.05 into staging-21.05 2021-09-06 00:03:18 +00:00
github-actions[bot]
890658fe0c Merge release-21.05 into staging-next-21.05 2021-09-06 00:02:44 +00:00
Vladimír Čunát
7cf9185aae Merge #136685: thunderbird-91: patch an addon problem 2021-09-05 20:54:26 +02:00
github-actions[bot]
a2a6c041d8 Merge staging-next-21.05 into staging-21.05 2021-09-05 18:02:36 +00:00
github-actions[bot]
8a634100a9 Merge release-21.05 into staging-next-21.05 2021-09-05 18:02:04 +00:00
Robert Scott
1bfd789f3f python3Packages.pillow: 8.3.1 -> 8.3.2
disable test test_pyroma

(cherry picked from commit 9683168300)
2021-09-05 18:16:43 +01:00
Robert Scott
8ecb35368a Merge pull request #136787 from NixOS/backport-136364-to-release-21.05
[Backport release-21.05] fig2dev: 3.2.8a -> 3.2.8b
2021-09-05 17:36:35 +01:00
Thomas Gerbet
66fad9ba44 fig2dev: 3.2.8a -> 3.2.8b
This appears to fix a serie of buffer overflow.
8f11139e53/

(cherry picked from commit 4cacbf4746)
2021-09-05 12:50:29 +00:00
Martin Weinelt
1e5c35dfbc Merge pull request #136328 from risicle/ris-fossil-2.14.2-r21.05
[21.05] fossil: 2.14 -> 2.14.2
2021-09-05 14:39:01 +02:00
R. RyanTM
8e236ada20 libarchive: 3.5.1 -> 3.5.2
(cherry picked from commit b8bfe4d74c)
2021-09-05 12:33:29 +00:00
Martin Weinelt
ce1037cc59 Merge pull request #136536 from NixOS/backport-136457-to-release-21.05 2021-09-05 14:28:20 +02:00
Martin Weinelt
fdf3828d6b Merge pull request #136724 from risicle/ris-inetutils-CVE-2021-40491-r21.05
[21.05] inetutils: add patch for CVE-2021-40491
2021-09-05 14:12:17 +02:00
github-actions[bot]
60cf7c2527 Merge staging-next-21.05 into staging-21.05 2021-09-05 12:03:18 +00:00
github-actions[bot]
d0b89d535f Merge release-21.05 into staging-next-21.05 2021-09-05 12:02:36 +00:00
Vladimír Čunát
01ee796103 Merge #136753: linux: only configure IDE to "no" pre-5.14 2021-09-05 08:24:44 +02:00
Florian Klink
71254658c9 linux: only configure IDE to "no" pre-5.14
When trying to build a 5.14 (rc-*), this fails to build otherwise:

> error: unused option: IDE

(cherry picked from commit ced7721191)
2021-09-05 06:20:25 +00:00
github-actions[bot]
a854f54669 Merge staging-next-21.05 into staging-21.05 2021-09-05 00:03:25 +00:00
github-actions[bot]
1742ac6e0e Merge release-21.05 into staging-next-21.05 2021-09-05 00:02:44 +00:00
Mario Rodas
f4f1a95775 Merge pull request #136728 from marsam/backport-postgresql-21.05
[21.05] postgresql: 9.6.22 -> 9.6.23, 10.17 -> 10.18, 11.12 -> 11.13, 12.7 -> 12.8, 13.3 -> 13.4
2021-09-04 18:43:26 -05:00
Mario Rodas
a3658bf3ec Merge pull request #136717 from marsam/backport-nodejs-21.05
[21.05] nodejs: 12.22.4 -> 12.22.6, 14.17.4 -> 14.17.6, 16.4.1 -> 16.8.0
2021-09-04 17:11:45 -05:00
Robert Scott
67cacbf02e inetutils: add patch for CVE-2021-40491 2021-09-04 22:00:18 +01:00
github-actions[bot]
ab452a517e Merge staging-next-21.05 into staging-21.05 2021-09-04 18:02:55 +00:00
github-actions[bot]
ffe2d5fae9 Merge release-21.05 into staging-next-21.05 2021-09-04 18:02:19 +00:00
Maximilian Bosch
074ce6058c Merge pull request #136495 from risicle/ris-squashfs-CVE-2021-40153-r21.05
[21.05] squashfsTools: add patch for CVE-2021-40153
2021-09-04 19:09:55 +02:00
Maximilian Bosch
de8a6369e1 Merge pull request #136679 from NixOS/backport-136598-to-release-21.05
[Backport release-21.05] Kernels 2021-09-03
2021-09-04 19:06:43 +02:00
Yureka
2ce87422bf thunderbird: patch for #134433
(cherry picked from commit afaced2746)
2021-09-04 15:04:48 +02:00
Maximilian Bosch
a75daa8c05 Merge pull request #136481 from sumnerevans/backport-136311-to-release-21.05-2
[Backport release-21.05] element-{web,desktop}: 1.8.1 -> 1.8.2
2021-09-04 14:58:57 +02:00
Maximilian Bosch
f76e9fe351 Merge pull request #136466 from NixOS/backport-136462-to-release-21.05
[Backport release-21.05] strace: 5.13 -> 5.14
2021-09-04 14:54:49 +02:00
github-actions[bot]
c21cdb12c2 Merge staging-next-21.05 into staging-21.05 2021-09-04 12:02:43 +00:00
github-actions[bot]
b8ed26ab9f Merge release-21.05 into staging-next-21.05 2021-09-04 12:02:06 +00:00
Tim Steinbach
36d8ad8d21 linux_latest-libre: 18268 -> 18298
(cherry picked from commit 6dfc0ee85005e8160ad643f4e7da32ad052b9f92)
2021-09-04 11:46:56 +00:00
Tim Steinbach
de0bb1fd9d linux-rt_5_4: 5.4.138-rt62 -> 5.4.143-rt63
(cherry picked from commit 1ed0214d01662e2c8d22ef5bcc0fda1c7422e94c)
2021-09-04 11:46:55 +00:00
Tim Steinbach
678b3c6bfc linux: 5.4.143 -> 5.4.144
(cherry picked from commit c9a4ef4d58df21ae1690258d0ca14d46b8119617)
2021-09-04 11:46:54 +00:00
Tim Steinbach
7495560f0c linux: 5.14 -> 5.14.1
(cherry picked from commit a91cc86d2991e661e2c53a64389be540f9da7704)
2021-09-04 11:46:54 +00:00
Tim Steinbach
ce9fcd89ab linux: 5.13.13 -> 5.13.14
(cherry picked from commit ff64785c049beaaa8b1c16d5ffe322ea8d68bb62)
2021-09-04 11:46:53 +00:00
Tim Steinbach
06bdbe3a2b linux: 5.10.61 -> 5.10.62
(cherry picked from commit 777135f8a00a1f2780cbb793335401cb24e0342c)
2021-09-04 11:46:52 +00:00
Tim Steinbach
80fd0c5fb3 linux: 4.9.281 -> 4.9.282
(cherry picked from commit 59f9cc8f99acfa23479f146167b6005ef9e7229b)
2021-09-04 11:46:52 +00:00
Tim Steinbach
628efd9154 linux: 4.4.282 -> 4.4.283
(cherry picked from commit adae328a3b8f95c7ca412ff454d5d9ccc99a79bd)
2021-09-04 11:46:51 +00:00
Tim Steinbach
8155bbc8e6 linux: 4.19.205 -> 4.19.206
(cherry picked from commit 84b31619da46908c6c8b2f5ca8a641edb101f037)
2021-09-04 11:46:50 +00:00
Tim Steinbach
1395fb5573 linux: 4.14.245 -> 4.14.246
(cherry picked from commit b9c9f0a21176ea16301b96c07cd0418a0af6c64c)
2021-09-04 11:46:50 +00:00
Maximilian Bosch
a6800d5c8e Merge pull request #136235 from NixOS/backport-136150-to-release-21.05
[Backport release-21.05] linux_latest: 5.13.13 -> 5.14
2021-09-04 13:42:13 +02:00
Bernardo Meurer
230d003e01 electron_12: 12.0.18 -> 12.1.0
(cherry picked from commit 26f46d56f8)
2021-09-04 12:48:33 +02:00
Bernardo Meurer
8b49c9b578 electron_11: 11.4.12 -> 11.5.0
(cherry picked from commit b989a80b90)
2021-09-04 12:48:26 +02:00
Michael Weiss
ac1fe4e3d7 Merge pull request #136631 from primeos/chromium-backport
[21.05] chromium: 92.0.4515.159 -> 93.0.4577.63
2021-09-04 11:21:38 +02:00
Michael Weiss
5d4839d6c4 Merge pull request #136639 from NixOS/backport-136633-to-release-21.05
[Backport release-21.05] signal-desktop: 5.15.0 -> 5.16.0
2021-09-04 11:20:25 +02:00
Michael Weiss
a72240c5c6 Merge pull request #136640 from NixOS/backport-136629-to-release-21.05
[Backport release-21.05] llvmPackages_13.compiler-rt: Mark as broken on Aarch64
2021-09-04 11:19:34 +02:00
Florian Klink
5d2a5a9a4c Merge pull request #136594 from NixOS/backport-136564-to-release-21.05
[Backport release-21.05] gitlab: 14.2.1 -> 14.2.3
2021-09-04 11:19:24 +02:00
github-actions[bot]
40abc418bb Merge staging-next-21.05 into staging-21.05 2021-09-04 00:03:39 +00:00
github-actions[bot]
3d6b9811f4 Merge release-21.05 into staging-next-21.05 2021-09-04 00:02:58 +00:00
Robert Scott
90de298d15 Merge pull request #136504 from wamserma/backport-mc-135690
[21.05] mc: 4.8.26 -> 4.8.27
2021-09-04 00:44:42 +01:00
Michael Weiss
478fecce96 llvmPackages_13.compiler-rt: Mark as broken on Aarch64
To avoid unnecessary builds but this needs to be fixed ASAP. Chromium
already depends on it and a lot of additional packages, including Mesa,
will depend on it after the stable release.

(cherry picked from commit 5661f7dbee)
2021-09-03 22:30:22 +00:00
Michael Weiss
06f9502809 signal-desktop: 5.15.0 -> 5.16.0
(cherry picked from commit c5130a6205)
2021-09-03 22:29:11 +00:00
Michael Weiss
546c9a981b chromium: 92.0.4515.159 -> 93.0.4577.63
https://chromereleases.googleblog.com/2021/08/stable-channel-update-for-desktop_31.html

This update includes 27 security fixes.

CVEs:
CVE-2021-30606 CVE-2021-30607 CVE-2021-30608 CVE-2021-30609
CVE-2021-30610 CVE-2021-30611 CVE-2021-30612 CVE-2021-30613
CVE-2021-30614 CVE-2021-30615 CVE-2021-30616 CVE-2021-30617
CVE-2021-30618 CVE-2021-30619 CVE-2021-30620 CVE-2021-30621
CVE-2021-30622 CVE-2021-30623 CVE-2021-30624

(cherry picked from commit d04f44f7e8)
2021-09-03 23:05:31 +02:00
Michael Weiss
ac663e69a3 Merge pull request #136575 from primeos/chromium-backport
[21.05] Backport the required commits for the Chromium M93 update
2021-09-03 23:04:10 +02:00
github-actions[bot]
ed81bc5bd3 Merge staging-next-21.05 into staging-21.05 2021-09-03 18:02:46 +00:00
github-actions[bot]
0780692b0e Merge release-21.05 into staging-next-21.05 2021-09-03 18:02:13 +00:00
Patrick Hilhorst
2efd71f11f Merge pull request #136608 from NixOS/backport-136580-to-release-21.05
[Backport release-21.05] vscode,vscodium: fix moving files to the trash
2021-09-03 18:54:15 +02:00
Naïm Favier
e67b69d9a2 vscode,vscodium: fix moving files to the trash
Put gio in PATH so that VSCode is able to move files to the trash.

(cherry picked from commit a75326417d)
2021-09-03 16:13:10 +00:00
Yureka
544ad3ea4b gitlab: add back grpc patch
They downgraded grpc in the fix release

(cherry picked from commit f007b794c7)
2021-09-03 14:33:07 +00:00
Yureka
d8e386b70d gitlab: 14.2.1 -> 14.2.3
(cherry picked from commit 6ede6d2740)
2021-09-03 14:33:07 +00:00
Kim Lindberger
355b6d3675 Merge pull request #136572 from yu-re-ka/feature/gitaly-git2go-name-backport
[21.05] gitaly: Fix gitaly-git2go binary name
2021-09-03 16:28:26 +02:00
Domen Kožar
b60ccb80ad Merge pull request #136585 from NixOS/backport-136475-to-release-21.05
[Backport release-21.05] nixos/pipewire: use absolute path for jack libs
2021-09-03 16:13:13 +02:00
Artturin
3adca1abf6 nixos/pipewire: use absolute path for jack libs
(cherry picked from commit 756e60344f)
2021-09-03 13:40:40 +00:00
Maxine Aubrey
8477cb78b5 glib: 2.68.3 -> 2.68.4
- https://gitlab.gnome.org/GNOME/glib/-/releases/2.68.4

(cherry picked from commit 0074a8fb8f)
2021-09-03 14:24:05 +02:00
Alyssa Ross
047ab44301 glib: 2.68.2 -> 2.68.3
(cherry picked from commit 57bbd4e524)
2021-09-03 14:23:59 +02:00
github-actions[bot]
140ea6fb03 Merge staging-next-21.05 into staging-21.05 2021-09-03 12:02:47 +00:00
github-actions[bot]
cb5d86d6ab Merge release-21.05 into staging-next-21.05 2021-09-03 12:02:15 +00:00
Michael Weiss
b0c90ba71b chromiumDev: 95.0.4621.4 -> 95.0.4628.3
(cherry picked from commit 79725cdc4d)
2021-09-03 13:59:35 +02:00
Michael Weiss
3bfe8801e3 chromiumBeta: 94.0.4606.20 -> 94.0.4606.31
(cherry picked from commit 55e9fc9666)
2021-09-03 13:59:34 +02:00
Michael Weiss
21edf9c42f chromium: Move the version helper functions into default.nix
Those functions can be required anywhere in the Nix expressions for
Chromium and therefore they should be defined in default.nix and
inherited where necessary.

This fixes the chromiumBeta build which failed because I forgot to
update the channel conditional when the beta channel advanced to M94.
This is exactly why the version based conditionals should be used
everywhere.

(cherry picked from commit 186315def7)
2021-09-03 13:59:33 +02:00
Michael Weiss
dae2c39b9e chromiumDev: 94.0.4606.20 -> 95.0.4621.4
(cherry picked from commit 04fa5e852a)
2021-09-03 13:59:32 +02:00
Michael Weiss
2af37d53bd chromiumBeta: 93.0.4577.58 -> 94.0.4606.20
(cherry picked from commit 33a4dae995)
2021-09-03 13:59:31 +02:00
Michael Weiss
dd2d264062 chromiumDev: 94.0.4606.12 -> 94.0.4606.20
(cherry picked from commit 5bb4a67959)
2021-09-03 13:59:30 +02:00
Michael Weiss
3de9ca8a8d chromiumBeta: 93.0.4577.51 -> 93.0.4577.58
(cherry picked from commit d0dad3f519)
2021-09-03 13:59:29 +02:00
Michael Weiss
9e0211b13c google-chrome-dev: Fix the build
crashpad_handler was renamed to chrome_crashpad_handler.

(cherry picked from commit 88336eea95)
2021-09-03 13:59:28 +02:00
Michael Weiss
d3e31a97e3 chromiumDev: 94.0.4603.0 -> 94.0.4606.12
I've upstreamed fix-missing-atspi2-dependency.patch.

(cherry picked from commit 6ca181b360)
2021-09-03 13:59:24 +02:00
Michael Weiss
3fa4af5d29 chromiumBeta: 93.0.4577.42 -> 93.0.4577.51
(cherry picked from commit 2834fea828)
2021-09-03 13:58:07 +02:00
Michael Weiss
d3f6410eff chromium: Document the main gn build flags
(cherry picked from commit a1fdebcef0)
2021-09-03 13:58:06 +02:00
Michael Weiss
1ec8df7a95 chromiumDev: Fix the installation phase
(cherry picked from commit dd36a7c487)
2021-09-03 13:58:05 +02:00
Michael Weiss
f2e8955366 chromiumBeta: 93.0.4577.25 -> 93.0.4577.42
(cherry picked from commit badee4e70a)
2021-09-03 13:58:04 +02:00
Michael Weiss
3670f55599 chromiumBeta: Build with LLVM 13
(cherry picked from commit 403ce1a9a3)
2021-09-03 13:58:01 +02:00
Michael Weiss
905b1242d8 chromiumDev: 94.0.4595.0 -> 94.0.4603.0
(cherry picked from commit 624cb8bc2b)
2021-09-03 13:56:31 +02:00
Michael Weiss
4c19443f54 chromium: Restructure the code
This should make it a little bit easier to read. The (native) build
inputs and options now have a consistent order, defaultDependencies and
yasm aren't required anymore, and this adds some brief comments.
Note: The third_party/node/linux/node-linux-x64/bin/node change causes
rebuilds.

(cherry picked from commit 4a5b367259)
2021-09-03 13:56:30 +02:00
Michael Weiss
c803b6f93a chromiumBeta: 93.0.4577.18 -> 93.0.4577.25
(cherry picked from commit 39d95aa8e9)
2021-09-03 13:56:29 +02:00
Michael Weiss
d14b18dd69 chromiumDev: Fix the build
Note: I've only tested this with llvmPackages_git but it should work
with llvmPackages_13 as well.

fieldtrial_testing_like_official_build was renamed to
disable_fieldtrial_testing_config:
486e9d58c0

(cherry picked from commit 1e372f4004)
2021-09-03 13:56:28 +02:00
Kim Lindberger
9117f2a7d9 gitaly: Fix gitaly-git2go binary name (#136569)
e7f8fe4f67
changed the binary name to always end with its module version. This
makes sure gitaly's internal version references are set to the package
version and renames the binary, postfixing it with the package
version.

(cherry picked from commit d14e9188d1)
2021-09-03 13:52:57 +02:00
Michael Weiss
b5d1601f7a Merge pull request #136562 from primeos/llvm-backport
[21.05] Backport LLVM 13
2021-09-03 13:34:11 +02:00
Michael Weiss
7055f658d9 Merge pull request #136561 from primeos/chromium-backport
[21.05] Backport the first batch of Chromium patches
2021-09-03 11:52:51 +02:00
Michael Weiss
56ebee647a llvmPackages_13: 13.0.0-rc1 -> 13.0.0-rc2
Upstream backported 5060224d9eed8b8359ed5090bb7c577b8575e9e7:
93da37dc58

(cherry picked from commit bac15390f5)
2021-09-03 11:40:30 +02:00
Yureka
90cb748196 llvmPackages_13.libcxx: mark as broken on darwin
(cherry picked from commit f8230bb0f4)
2021-09-03 11:40:29 +02:00
Yureka
373402fb6d llvm_13: fix tests on non-x86 platforms
(cherry picked from commit 48d1e393c0)
2021-09-03 11:40:28 +02:00
Yureka
036e4b3df8 llvm_13: workaround for llvm bug 50611
https://bugs.llvm.org/show_bug.cgi?id=50611
(cherry picked from commit 91b15b6dcf)
2021-09-03 11:40:27 +02:00
Michael Weiss
bcfaa8041c pkgsi686Linux.llvmPackages_13.compiler-rt: fix build
Ported from a7c4537a72.

(cherry picked from commit c8db49f0a9)
2021-09-03 11:40:26 +02:00
Michael Weiss
81aa38b83d llvmPackages_13.lldb: python into lib & wrap binary
Ported from cc7740ae77.

(cherry picked from commit a5f0733461)
2021-09-03 11:40:25 +02:00
Michael Weiss
11d06468b3 llvmPackages_13.lldb: fix python lldb library
Ported from e097f7efc7.

(cherry picked from commit a6defaf953)
2021-09-03 11:40:25 +02:00
Michael Weiss
80f644e0d2 llvmPackages_13.compiler-rt: fix build on darwin
Ported from cf4e1b9e62.

(cherry picked from commit 6a1354b1fc)
2021-09-03 11:40:24 +02:00
Michael Weiss
cb51b0e984 llvmPackages_13.clang: fix linker invocation with LLVMgold plugin
Ported from 3530837417.

(cherry picked from commit c858c42002)
2021-09-03 11:40:23 +02:00
Michael Weiss
90c3f09977 llvmPackages_13: init at 13.0.0-rc1
(cherry picked from commit 2540b66ba6)
2021-09-03 11:40:19 +02:00
Michael Weiss
ebd2a830dc llvmPackages_13: Copy from llvmPackages_git
(cherry picked from commit f3f86d4722)
2021-09-03 11:39:05 +02:00
Michael Weiss
7ab6adf608 chromium: get-commit-message.py: Support specifying a version
This makes the usage from update.py more robust.
It also adds a workaround for [0] which currently lacks a title.

[0]: https://chromereleases.googleblog.com/2021/08/the-stable-channel-has-been-updated-to.html

(cherry picked from commit 9bc2d82b55)
2021-09-03 11:30:41 +02:00
Michael Weiss
ba876b30f2 chromiumDev: 93.0.4577.18 -> 94.0.4595.0
(cherry picked from commit f9eb20c0a9)
2021-09-03 11:30:40 +02:00
Michael Weiss
c46ea2796f chromium: update.py: Implement automatic committing of the updates
This functionality saves some unnecessary work.

(cherry picked from commit e143dc53b2)
2021-09-03 11:30:39 +02:00
Felix Buehler
1361a07a95 chromium: remove phases
(cherry picked from commit 2ae5f1a6b8)
2021-09-03 11:30:38 +02:00
Michael Weiss
3ababf6d04 chromium: Drop our closure_compiler patch for Java
Hopefully the Java dependency can be dropped soon:
https://bugs.chromium.org/p/chromium/issues/detail?id=1192875#c5

(cherry picked from commit 8505750ac8)
2021-09-03 11:28:51 +02:00
Michael Weiss
701cb52607 chromium: Drop two gn overrides that are not required anymore
The chromium and chromiumBeta builds still succeed.

(cherry picked from commit 2682531c67)
2021-09-03 11:27:08 +02:00
Michael Weiss
65b3f3f186 chromium: Restructure gnFlags
This doesn't cause any rebuilds because we use a set but should make it
a bit easier to understand what's going on. This also moves two flags
that where incorrectly in "optionalAttrs pulseSupport" (enabled by
default) out of there.
The native client deprecation is stated here:
https://developer.chrome.com/docs/native-client/

(cherry picked from commit 555c3afaf2)
2021-09-03 11:27:08 +02:00
Michael Weiss
aa0e9cfd1e chromiumBeta: 92.0.4515.107 -> 93.0.4577.18
(cherry picked from commit d7ab681b7a)
2021-09-03 11:27:07 +02:00
Michael Weiss
e77d77484a chromiumDev: 93.0.4577.15 -> 93.0.4577.18
(cherry picked from commit 7f8de3536a)
2021-09-03 11:27:06 +02:00
Michael Weiss
1ffa4bbbd6 chromiumDev: 93.0.4577.8 -> 93.0.4577.15
(cherry picked from commit 68adc7b81c)
2021-09-03 11:27:05 +02:00
Michael Weiss
cb026a4a09 chromiumDev: Fix the build
Our system FFmpeg version is too outdated and Snappy causes a linking
failure (I didn't have time to investigate yet). Hopefully we can revert
this before the stable release of M93.

(cherry picked from commit bd22d2425c)
2021-09-03 11:27:05 +02:00
Michael Weiss
4dbbc50b30 chromium: Merge the installPhase command strings
This wasn't done in 97570d30c7 to allow reusing chromiumBeta builds
(without having to perform any changes) in the meantime.

(cherry picked from commit 9ac3188552)
2021-09-03 11:27:04 +02:00
Michael Weiss
81c33c7969 chromium: Minimize the diff to nixos-unstable
Keeping the diff minimal makes backporting updates easier.
This is basically e9e5f5f84d backported for Chromium.
2021-09-03 11:23:03 +02:00
nixpkgs-upkeep-bot
0950b449b5 vscodium: 1.59.1 -> 1.59.1
(cherry picked from commit 5ecadf00522c7ecbfef64a41f9402722040ccedb)
2021-09-03 16:55:08 +09:00
R. RyanTM
7ca2251d7b protonmail-bridge: 1.6.9 -> 1.8.7
(cherry picked from commit 398a322672)
2021-09-03 07:48:22 +00:00
Mikael Heino
6647b720f7 ntfs-3g: update homepage
(cherry picked from commit 7ca49a701a)
2021-09-03 01:48:02 +00:00
Mikael Heino
319068cc94 ntfs-3g: 2017.3.23 -> 2021.8.22
New version has important security fixes.

(cherry picked from commit 0c35c72ed4)
2021-09-03 01:48:01 +00:00
github-actions[bot]
a1049e285e Merge staging-next-21.05 into staging-21.05 2021-09-03 00:03:31 +00:00
github-actions[bot]
7a5873a0dd Merge release-21.05 into staging-next-21.05 2021-09-03 00:02:58 +00:00
adisbladis
2fe9d531d0 Merge pull request #136494 from NixOS/backport-136228-to-release-21.05
[Backport release-21.05] qt5.qt3d: init module
2021-09-02 17:11:13 -05:00
Sergei Trofimovich
c3798535b8 mc: 4.8.26 -> 4.8.27
(cherry picked from commit 326209f037)
2021-09-02 22:35:11 +02:00
adisbladis
ed77a24bb5 qt5.qt3d: init module
(cherry picked from commit a7432ad311)
2021-09-02 19:11:00 +00:00
adisbladis
edf806cf27 Merge pull request #136490 from NixOS/backport-123011-to-staging-21.05
[Backport staging-21.05] bluez: Disable kernel-dependent test test-mesh-crypto
2021-09-02 14:10:33 -05:00
Robert Scott
792dba27aa squashfsTools: add patch for CVE-2021-40153 2021-09-02 19:22:21 +01:00
github-actions[bot]
667cd91ecc Merge staging-next-21.05 into staging-21.05 2021-09-02 18:03:02 +00:00
Josef Kemetmüller
bebbeb1918 bluez: Disable kernel dependent test-mesh-crypto
I'm having trouble building bluez on a CentOS 7.9 builder.
Turns out that the test-mesh-crypto test depends on the following Linux
kernel configuration items:
CONFIG_CRYPTO_[USER|USER_API|USER_API_AEAD|USER_API_HASH|AES|CCM|AEAD|CMAC]
and will fail if run wih an incompatible kernel with the following error
message:

    ...
    IVindex              = 12345678
    NetworkNonce         = 00800000011201000012345678
                           00800000011201000012345678 => PASS
    PrivacyRandom        = 000000000012345678b5e5bfdacbaf6c
                           000000000012345678fffd034b50057e => FAIL
    FAIL unit/test-mesh-crypto (exit status: 1)

I found the same bug reported on Gentoo https://bugs.gentoo.org/704190.
Their fix is to only run the test if the kernel options are available,
which we don't want to do for build reproducibility.
Instead we just want to skip the test unconditionally. As it's simpler
to completely override the test instead of patching the build system, we
opt for doing just that.

(cherry picked from commit 05c517698d)
2021-09-02 18:02:37 +00:00
github-actions[bot]
eb8ef5940d Merge release-21.05 into staging-next-21.05 2021-09-02 18:02:28 +00:00
Michael Weiss
6bfe71f2a4 Revert "chromium: 92.0.4515.159 -> 93.0.4577.63"
This reverts commit acf91fbac7.
Reason: I didn't pay enough attention, this lacks additional backports,
sorry!
2021-09-02 17:55:10 +02:00
Michael Weiss
ea2023628b Merge pull request #136386 from NixOS/backport-136373-to-release-21.05
[Backport release-21.05] chromium: 92.0.4515.159 -> 93.0.4577.63
2021-09-02 17:53:25 +02:00
Sumner Evans
7ddb48c45f element-{web,desktop}: 1.8.1 -> 1.8.2
(cherry picked from commit 29c70e8b88)
2021-09-02 09:06:19 -06:00
Anderson Torres
ec1c2a06cb Merge pull request #136424 from NixOS/backport-136382-to-release-21.05
[Backport release-21.05] palemoon: 29.4.0.1 -> 29.4.0.2
2021-09-02 10:21:00 -03:00
Maximilian Bosch
2960083854 strace: 5.13 -> 5.14
ChangeLog: https://github.com/strace/strace/releases/tag/v5.14
(cherry picked from commit e58cba3ca4a4a29800f1780c30cbe0c46a76efdd)
2021-09-02 12:52:40 +00:00
github-actions[bot]
c48f16aef0 Merge staging-next-21.05 into staging-21.05 2021-09-02 12:02:51 +00:00
github-actions[bot]
453a47f57e Merge release-21.05 into staging-next-21.05 2021-09-02 12:02:17 +00:00
Maximilian Bosch
796e823083 Merge pull request #134492 from NixOS/backport-134335-to-release-21.05
[Backport release-21.05] element-{web,desktop}: 1.7.34 -> 1.8.1
2021-09-02 13:44:14 +02:00
Martin Weinelt
b642e782d8 Merge pull request #136458 from mweinelt/21.05/fix-httplib2 2021-09-02 13:22:16 +02:00
Robert Schütz
32d97638ed python3Packages.httplib2: fix tests
(cherry picked from commit f019d3adb2)
2021-09-02 13:02:12 +02:00
Martin Weinelt
8db3d39036 Merge pull request #136450 from LeSuisse/mosquitto-2.0.12-21.05 2021-09-02 13:00:35 +02:00
Thomas Gerbet
476832f9ba mosquitto: 2.0.11 -> 2.0.12
https://github.com/eclipse/mosquitto/blob/v2.0.12/ChangeLog.txt
(cherry picked from commit d4c75580c1)
2021-09-02 10:56:25 +02:00
Thomas Gerbet
24caf232b7 mosquitto: 2.0.10 -> 2.0.11
Fixes CVE-2021-34431.

https://github.com/eclipse/mosquitto/blob/v2.0.11/ChangeLog.txt
(cherry picked from commit ded0f0ede6)
2021-09-02 10:56:21 +02:00
github-actions[bot]
5625cf3495 Merge staging-next-21.05 into staging-21.05 2021-09-02 00:03:28 +00:00
github-actions[bot]
c836f35b5a Merge release-21.05 into staging-next-21.05 2021-09-02 00:02:55 +00:00
OPNA2608
5feba0ecf7 palemoon: 29.4.0.1 -> 29.4.0.2
(cherry picked from commit 080b148604)
2021-09-01 23:37:42 +00:00
Vladimír Čunát
3e09410da0 Merge branch 'staging-next-21.05' into release-21.05
There's not even half of all binaries yet, but let's move this forward
and get the -small channel going with secure openssl.
2021-09-01 22:48:45 +02:00
Pavol Rusnak
abd8e8f9fb Merge pull request #136099 from prusnak/electron-21.05
[21.05] electron_12: 12.0.17 -> 12.0.18
2021-09-01 22:47:55 +02:00
Martin Weinelt
71be98642c Merge pull request #136342 from mweinelt/21.05/firefox 2021-09-01 21:01:06 +02:00
Ilan Joselevich
1c7d3cae8c pipewire: 0.3.33 -> 0.3.34
(cherry picked from commit 70de7b5b45)
2021-09-01 14:56:15 +00:00
Michael Weiss
acf91fbac7 chromium: 92.0.4515.159 -> 93.0.4577.63
https://chromereleases.googleblog.com/2021/08/stable-channel-update-for-desktop_31.html

This update includes 27 security fixes.

CVEs:
CVE-2021-30606 CVE-2021-30607 CVE-2021-30608 CVE-2021-30609
CVE-2021-30610 CVE-2021-30611 CVE-2021-30612 CVE-2021-30613
CVE-2021-30614 CVE-2021-30615 CVE-2021-30616 CVE-2021-30617
CVE-2021-30618 CVE-2021-30619 CVE-2021-30620 CVE-2021-30621
CVE-2021-30622 CVE-2021-30623 CVE-2021-30624

(cherry picked from commit d04f44f7e8)
2021-09-01 13:53:53 +00:00
github-actions[bot]
8c5bd93046 Merge staging-next-21.05 into staging-21.05 2021-09-01 12:03:03 +00:00
github-actions[bot]
f3307f7b93 Merge release-21.05 into staging-next-21.05 2021-09-01 12:02:24 +00:00
Pascal Bach
110a2c9ebb Merge pull request #136268 from NixOS/backport-135929-to-release-21.05
[Backport release-21.05] nextcloud22: 22.1.0 -> 22.1.1
2021-09-01 09:24:39 +02:00
Mario Rodas
1b7893c31a postgresql_13: 13.3 -> 13.4
https://www.postgresql.org/docs/release/13.4/
(cherry picked from commit 3290dd08a2)
2021-09-01 04:20:00 +00:00
Mario Rodas
d04c1e30be postgresql_12: 12.7 -> 12.8
https://www.postgresql.org/docs/release/12.8/
(cherry picked from commit 677b27c24e)
2021-09-01 04:20:00 +00:00
Mario Rodas
1f3805f7bb postgresql_11: 11.12 -> 11.13
https://www.postgresql.org/docs/release/11.13/
(cherry picked from commit 34418e4c2a)
2021-09-01 04:20:00 +00:00
Mario Rodas
44a33d44a6 postgresql_10: 10.17 -> 10.18
https://www.postgresql.org/docs/release/10.18/
(cherry picked from commit 4c5bf33b5d)
2021-09-01 04:20:00 +00:00
Mario Rodas
297d8d1547 postgresql_9_6: 9.6.22 -> 9.6.23
https://www.postgresql.org/docs/release/9.6.23/
(cherry picked from commit 957a9bd035)
2021-09-01 04:20:00 +00:00
github-actions[bot]
ca68084d67 Merge staging-next-21.05 into staging-21.05 2021-09-01 00:03:13 +00:00
github-actions[bot]
b6598fc6c3 Merge release-21.05 into staging-next-21.05 2021-09-01 00:02:38 +00:00
Martin Weinelt
441c74d110 firefox-bin: 91.0.1 -> 91.0.2
(cherry picked from commit f6187a43a0)
2021-08-31 23:54:36 +02:00
Martin Weinelt
8bddec8899 firefox: 91.0.1 -> 91.0.2
(cherry picked from commit 01b534e888)
2021-08-31 23:54:36 +02:00
Robert Scott
df7a756cbc Merge pull request #136325 from NixOS/backport-136167-to-release-21.05
[Backport release-21.05] grilo: add patch for CVE-2021-39365
2021-08-31 21:48:58 +01:00
Maximilian Bosch
26ca44909e Merge pull request #136327 from NixOS/backport-135958-to-release-21.05
[Backport release-21.05] nixos/nextcloud: add some notes for `Error: Command "upgrade" is not defined.`
2021-08-31 21:48:51 +02:00
Robert Scott
5d3e86447d fossil: 2.14 -> 2.14.2 2021-08-31 19:58:02 +01:00
Maximilian Bosch
ebd597d2f3 nixos/nextcloud: apply doc fixes suggested by fabaff
Co-authored-by: Fabian Affolter <mail@fabian-affolter.ch>
(cherry picked from commit 767bb4e4bb)
2021-08-31 18:54:20 +00:00
Maximilian Bosch
c19b0bf9de nixos/nextcloud: add some notes for Error: Command "upgrade" is not defined.
This error occurs if `nextcloud-occ maintenance:install` fails and the
`upgrade` command is attempted to be executed afterwards.

Due to the nature of the installer we can't do much about it, so I guess
it makes sense to add some notes about it. The other notes in the
`Pitfalls`-section are semantically a list of different topics, so I
changed that accordingly now.

Closes #111175

(cherry picked from commit 561418f996)
2021-08-31 18:54:20 +00:00
Robert Scott
867aab7eed grilo: add patch for CVE-2021-39365
(cherry picked from commit f4153fb02c)
2021-08-31 18:35:55 +00:00
github-actions[bot]
f29dbbb4de Merge staging-next-21.05 into staging-21.05 2021-08-31 18:03:06 +00:00
github-actions[bot]
b5d8a72c06 Merge release-21.05 into staging-next-21.05 2021-08-31 18:02:32 +00:00
Jonathan Ringer
977f89b349 stdenv/native: fix bintools import
(cherry picked from commit fa38ff677af719ad8a44e9c70dc6f4fc0c5e09e9)
2021-08-31 10:38:39 -07:00
Maximilian Bosch
4b7e51865e Merge pull request #136298 from NixOS/backport-136296-to-release-21.05
[Backport release-21.05] matrix-synapse: 1.41.0 -> 1.41.1
2021-08-31 17:43:56 +02:00
Robin Townsend
5b68d15c08 matrix-synapse: 1.41.0 -> 1.41.1
https://github.com/matrix-org/synapse/releases/tag/v1.41.1
(cherry picked from commit 5947c59899)
2021-08-31 14:50:37 +00:00
github-actions[bot]
91f7d8fc80 Merge staging-next-21.05 into staging-21.05 2021-08-31 12:03:12 +00:00
github-actions[bot]
2f340a6f22 Merge release-21.05 into staging-next-21.05 2021-08-31 12:02:36 +00:00
maxine [they]
60712d4a70 Merge pull request #136219 from maxeaubrey/21.05_vault_1.7.4
[21.05] vault{,-bin}: 1.7.2 -> 1.7.4
2021-08-31 13:06:24 +02:00
Diep Pham
62f9f5688a dcmtk: support darwin platform
(cherry picked from commit 604ad25af49ac679bb28419b35237dcba46bb6d9)
2021-08-31 03:51:53 -04:00
Maximilian Bosch
46d36e4abf nextcloud22: 22.1.0 -> 22.1.1
Changes: https://github.com/nextcloud/server/compare/v22.1.0...v22.1.1
(cherry picked from commit 6907126241)
2021-08-31 07:34:47 +00:00
Vladimír Čunát
cc6a9e8509 Merge #136076: thunderbird*: -> 91.0.3 (into release-21.05) 2021-08-31 09:27:49 +02:00
Jörg Thalheim
95cfdb2449 Merge pull request #136129 from blitz/tuxedo-keyboard-21.05
[21.05] tuxedo-keyboard: 3.0.5 -> 3.0.8
2021-08-31 08:26:01 +01:00
Pavol Rusnak
274de11138 bear: unbreak on aarch64-darwin
we have recent macOS SDK on aarch64-darwin, only x86_64-darwin is broken

(cherry picked from commit 999f55ee01)
2021-08-31 03:15:26 -04:00
Dmitry Kalinkin
d294ef4aa9 blas: fix library id on darwin
dyld: lazy symbol binding failed: Symbol not found: _dsyevd_
  Referenced from: /nix/store/lr8grz1knmh6vc7j830gni0ka68qf1lk-xfitter-2.0.1/bin/xfitter
  Expected in: /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/libBLAS.dylib
(cherry picked from commit de4c61a515)
2021-08-31 02:32:36 +00:00
github-actions[bot]
37f55ad10c Merge staging-next-21.05 into staging-21.05 2021-08-31 00:03:22 +00:00
github-actions[bot]
82dfb51aee Merge release-21.05 into staging-next-21.05 2021-08-31 00:02:38 +00:00
Alyssa Ross
4cc8956845 linux_latest-libre: 18260 -> 18268
(cherry picked from commit e6f7a48269fd807a1cc65335aad6f5ce2ba367d8)
2021-08-30 20:28:52 +00:00
Alyssa Ross
e16cacff39 linux_latest: 5.13.13 -> 5.14
(cherry picked from commit 5d1c50837be54312b71ac83ddc1d1b6629d09073)
2021-08-30 20:28:51 +00:00
Niklas Hambüchen
d79fc9d53b Merge pull request #136210 from maxeaubrey/21.05_consul_1.9.9
[21.05] consul: 1.9.8 -> 1.9.9
2021-08-30 20:54:36 +02:00
Maxine Aubrey
7b69f87d91 vault-bin: 1.7.2 -> 1.7.4
- https://github.com/hashicorp/vault/releases/tag/v1.7.3
- https://github.com/hashicorp/vault/releases/tag/v1.7.4
2021-08-30 20:42:34 +02:00
Maxine Aubrey
4780757785 vault: 1.7.2 -> 1.7.4
- https://github.com/hashicorp/vault/releases/tag/v1.7.3
- https://github.com/hashicorp/vault/releases/tag/v1.7.4
2021-08-30 20:42:10 +02:00
github-actions[bot]
54e5fbf291 Merge staging-next-21.05 into staging-21.05 2021-08-30 18:02:41 +00:00
github-actions[bot]
e7d5ebf374 Merge release-21.05 into staging-next-21.05 2021-08-30 18:02:09 +00:00
Maxine Aubrey
773661d5ea consul: 1.9.8 -> 1.9.9
- https://github.com/hashicorp/consul/releases/tag/v1.9.9
2021-08-30 19:55:58 +02:00
Stig
c94065f916 Merge pull request #134534 from nomeata/backport-133596
[21.05] listadmin: init at 2.73
2021-08-30 14:42:47 +02:00
github-actions[bot]
c890442d8a Merge staging-next-21.05 into staging-21.05 2021-08-30 12:02:38 +00:00
Vladimír Čunát
baf718497f Merge #136118: ffmpeg*: revert backport of doCheck = true 2021-08-30 12:21:35 +02:00
Julian Stecklina
52269b659e linuxPackages.tuxedo-keyboard: expose all kernel modules
This commit exposes in addition to the tuxedo-keyboard module:

- clevo_acpi
- clevo_wmi
- tuxedo_io

These modules are required to run the Tuxedo Control Center.

(cherry picked from commit 2e6d563067)
2021-08-30 00:58:37 +02:00
Julian Stecklina
e17d7f323b linuxPackages.tuxedo-keyboard: 3.0.7 -> 3.0.8
(cherry picked from commit f7286acdae)
2021-08-30 00:58:35 +02:00
fortuneteller2k
84b9c18a47 linuxPackages.tuxedo-keyboard: 3.0.5 -> 3.0.7
(cherry picked from commit c7ec86b689)
2021-08-30 00:58:22 +02:00
Robert Scott
efedf9a09e Revert "[Backport staging-21.05] ffmpeg, ffmpeg-full: enable basic tests" 2021-08-29 20:24:06 +01:00
github-actions[bot]
edd8ce83bf Merge staging-next-21.05 into staging-21.05 2021-08-29 18:02:32 +00:00
Vladimír Čunát
a936d2f6ab Merge #135990: openssl: 1.1.1k -> 1.1.1l (into staging-next-21.05) 2021-08-29 18:24:44 +02:00
TredwellGit
ca90a3f923 electron_12: 12.0.17 -> 12.0.18
https://github.com/electron/electron/releases/tag/v12.0.18
(cherry picked from commit f3840694a6)
2021-08-29 15:17:05 +02:00
github-actions[bot]
557ef93801 Merge staging-next-21.05 into staging-21.05 2021-08-29 12:03:03 +00:00
github-actions[bot]
4a34132b64 Merge release-21.05 into staging-next-21.05 2021-08-29 12:02:20 +00:00
Maximilian Bosch
7fc63651a2 Merge pull request #136067 from NixOS/backport-135946-to-release-21.05
[Backport release-21.05] nixos/nextcloud: remove invalid `--database-table-prefix` option
2021-08-29 11:40:17 +02:00
Jörg Thalheim
5faf4632f7 Merge pull request #136017 from Atemu/backport/update/linux_zen
[Backport release-21.05] linux_zen
2021-08-29 08:30:14 +01:00
taku0
f6cc01231f thunderbird: 91.0.2 -> 91.0.3 2021-08-29 13:33:23 +09:00
taku0
27b0342488 thunderbird: 91.0.1 -> 91.0.2 2021-08-29 13:32:53 +09:00
taku0
fbcafb595e thunderbird: 91.0 -> 91.0.1 2021-08-29 13:32:17 +09:00
taku0
9e62fc08b4 thunderbird-bin: 91.0.2 -> 91.0.3 2021-08-29 13:31:07 +09:00
taku0
578dab9abc thunderbird-bin: 91.0.1 -> 91.0.2 2021-08-29 13:31:06 +09:00
taku0
218c0c1f10 thunderbird-bin: 91.0 -> 91.0.1 2021-08-29 13:31:06 +09:00
taku0
46698ec293 thunderbird-bin: 78.13.0 -> 91.0
(cherry picked from commit 0fbf6afa4d)
2021-08-29 13:28:35 +09:00
Maximilian Bosch
b32a89a82c nixos/mautrix-telegram: loosen umask to keep config.json writable
This is needed because `mautrix-telegram --generate-registration`
appears to need write-access to `config.json` as well.

Closes #135884

(cherry picked from commit bae65a3c06)
2021-08-28 22:10:04 +00:00
Maximilian Bosch
0db1a5ee44 nixos/nextcloud: remove invalid --database-table-prefix option
This doesn't work anymore and thus breaks the installation leaving a
broken `/var/lib/nextcloud`.

It isn't a big deal since we set this value in the override config
before, so the correct table-prefix is still used. In order to confirm
that, I decided to add a custom prefix to the basic test.

(cherry picked from commit eaeb4fe04e)
2021-08-28 22:04:40 +00:00
github-actions[bot]
b936b903be Merge staging-next-21.05 into staging-21.05 2021-08-28 18:02:34 +00:00
github-actions[bot]
d0559018de Merge release-21.05 into staging-next-21.05 2021-08-28 18:01:58 +00:00
talyz
698186588f gitlab: Enable puma's systemd notify support
(cherry picked from commit 3dd17ae22f)
2021-08-28 16:03:12 +02:00
talyz
2572e2550a gitlab: 14.1.2 -> 14.2.1
(cherry picked from commit 99387372d5)
2021-08-28 16:03:12 +02:00
Jörg Thalheim
846fa972d5 linux_zen: 5.13.12-zen1 -> 5.13.13-zen1
(cherry picked from commit 093349c14e)
2021-08-28 09:13:04 +02:00
Jörg Thalheim
c07d3055ca linux_zen: 5.13.10-zen1 -> 5.13.12-zen1
(cherry picked from commit 5e6958fa75)
2021-08-28 09:12:42 +02:00
github-actions[bot]
7cf5e6d634 Merge staging-next-21.05 into staging-21.05 2021-08-28 06:03:19 +00:00
github-actions[bot]
e01e42f38e Merge release-21.05 into staging-next-21.05 2021-08-28 06:02:46 +00:00
Artturi
7d46ea4c96 Merge pull request #135991 from NixOS/backport-135952-to-release-21.05
[Backport release-21.05] vintagestory: init at 1.15.5
2021-08-28 04:20:44 +03:00
Artturin
861412d485 vintagestory: init at 1.15.5
(cherry picked from commit 176705c295)
2021-08-28 00:47:49 +00:00
Martin Weinelt
3d0d142b75 openssl: 1.1.1k -> 1.1.1l
(cherry picked from commit 174868d4fa)
2021-08-28 00:31:58 +00:00
github-actions[bot]
d7de50e46e Merge staging-next-21.05 into staging-21.05 2021-08-28 00:03:29 +00:00
github-actions[bot]
cb4c3defc4 Merge release-21.05 into staging-next-21.05 2021-08-28 00:02:56 +00:00
Maximilian Bosch
15be51fdaa Merge pull request #135933 from NixOS/backport-135844-to-release-21.05
[Backport release-21.05] Kernels 2021-08-26
2021-08-28 00:12:14 +02:00
Pavol Rusnak
0b2bfa8948 Merge pull request #135927 from prusnak/electron-21.05
[21.05] Electron updates
2021-08-27 23:18:28 +02:00
adisbladis
0fcc42d48c Merge pull request #135940 from TredwellGit/release-21.05_go-ethereum
[Urgent] [Backport release-21.05] go-ethereum: 1.10.6 -> 1.10.8
2021-08-27 13:51:21 -05:00
github-actions[bot]
40dd0fe859 Merge staging-next-21.05 into staging-21.05 2021-08-27 18:03:06 +00:00
github-actions[bot]
9addd9a877 Merge release-21.05 into staging-next-21.05 2021-08-27 18:02:29 +00:00
TredwellGit
8be58bdd5b go-ethereum: 1.10.6 -> 1.10.8
https://www.coindesk.com/tech/2021/08/27/ethereum-faces-chain-split-as-node-operators-fail-to-update-geth-hotfix/

Backport of:
https://github.com/NixOS/nixpkgs/pull/127060
https://github.com/NixOS/nixpkgs/pull/133745
https://github.com/NixOS/nixpkgs/pull/135065
https://github.com/NixOS/nixpkgs/pull/135629
2021-08-27 17:42:30 +00:00
TredwellGit
e5b4b37c5a linux/hardened/patches/5.4: 5.4.142-hardened1 -> 5.4.143-hardened1
(cherry picked from commit e2fbc79e446ce1695b09da9521e339d6e3e2a5d0)
2021-08-27 16:28:40 +00:00
TredwellGit
53a6232591 linux/hardened/patches/5.13: init at 5.13.13-hardened1
(cherry picked from commit b9f854004e76fd448ca8f41e444593038eaefdff)
2021-08-27 16:28:40 +00:00
TredwellGit
e22a87d1d2 linux/hardened/patches/5.10: 5.10.60-hardened1 -> 5.10.61-hardened1
(cherry picked from commit efcb008ba44845e3aec2a3d2d44e53f2ea4dac26)
2021-08-27 16:28:39 +00:00
TredwellGit
5aeb5af282 linux/hardened/patches/4.19: 4.19.204-hardened1 -> 4.19.205-hardened1
(cherry picked from commit 885a18686b2ba40d527b27c12a2e72d3b1ecda19)
2021-08-27 16:28:39 +00:00
TredwellGit
1d1f808935 linux/hardened/patches/4.14: 4.14.244-hardened1 -> 4.14.245-hardened1
(cherry picked from commit d002bb6e6f35cbb4de3df5e41d53906c5d983e2f)
2021-08-27 16:28:38 +00:00
TredwellGit
ac519a8f84 linux_latest-libre: 18239 -> 18260
(cherry picked from commit 5b94350a90c86c69d2d8e2bea14dc490d3b219e8)
2021-08-27 16:28:37 +00:00
TredwellGit
b137e4f19f linux-rt_5_10: 5.10.56-rt49 -> 5.10.59-rt52
(cherry picked from commit 0adbd0852faa0baf26e4be9e1a23e9819431fcf9)
2021-08-27 16:28:37 +00:00
TredwellGit
ceb5fc136c linux: 5.4.142 -> 5.4.143
(cherry picked from commit 48183dde30f12435bc59f92d9de3ca0cbcfddb7c)
2021-08-27 16:28:36 +00:00
TredwellGit
9dfb717fb9 linux: 5.13.12 -> 5.13.13
(cherry picked from commit ca0b7b4e189583f44b0e53eb029dab45e45f03c6)
2021-08-27 16:28:35 +00:00
TredwellGit
d3dd950f8c linux: 5.10.60 -> 5.10.61
(cherry picked from commit 78eea2b5d20e33616492242ba82966f9b2609036)
2021-08-27 16:28:35 +00:00
TredwellGit
f77576ec34 linux: 4.9.280 -> 4.9.281
(cherry picked from commit 4442d7b8ddd5c826baad3c541d16a317be447e54)
2021-08-27 16:28:34 +00:00
TredwellGit
9f131e8464 linux: 4.4.281 -> 4.4.282
(cherry picked from commit 083c38da7abd7956a3ed47df3b0b2da75d124c0f)
2021-08-27 16:28:34 +00:00
TredwellGit
c180aa5608 linux: 4.19.204 -> 4.19.205
(cherry picked from commit 88be0cc40c26eb5152443d0d3f542a1c5aea8954)
2021-08-27 16:28:33 +00:00
TredwellGit
c498bc0180 linux: 4.14.244 -> 4.14.245
(cherry picked from commit 637878c8af79298ad8e3d905d95907488f7f1696)
2021-08-27 16:28:32 +00:00
TredwellGit
f21f841312 wireshark: 3.4.7 -> 3.4.8
https://www.wireshark.org/docs/relnotes/wireshark-3.4.8.html
(cherry picked from commit af5ec6d616)
2021-08-27 16:05:29 +00:00
TredwellGit
693e0026be electron_12: 12.0.16 -> 12.0.17
https://github.com/electron/electron/releases/tag/v12.0.17
(cherry picked from commit 0e6f0724c6)
2021-08-27 17:38:00 +02:00
TredwellGit
f472a05558 electron_11: 11.4.11 -> 11.4.12
https://github.com/electron/electron/releases/tag/v11.4.12
(cherry picked from commit 032baedc97)
2021-08-27 17:37:55 +02:00
Michael Weiss
74d017edb6 Merge pull request #135917 from NixOS/backport-135910-to-release-21.05
[Backport release-21.05] signal-desktop: 5.14.0 -> 5.15.0
2021-08-27 16:58:49 +02:00
Michael Weiss
5c71a1080f signal-desktop: 5.14.0 -> 5.15.0
(cherry picked from commit b49afb3fe6)
2021-08-27 14:28:58 +00:00
github-actions[bot]
8b4a3cdef6 Merge staging-next-21.05 into staging-21.05 2021-08-27 12:02:53 +00:00
github-actions[bot]
95b8fd5ac9 Merge release-21.05 into staging-next-21.05 2021-08-27 12:02:18 +00:00
Maximilian Bosch
80cf67ff60 Merge pull request #135896 from NixOS/backport-135773-to-release-21.05
[Backport release-21.05] vorta: 0.7.7 -> 0.7.8
2021-08-27 13:57:11 +02:00
Maximilian Bosch
9541ff65ae vorta: 0.7.7 -> 0.7.8
ChangeLog: https://github.com/borgbase/vorta/releases/tag/v0.7.8
(cherry picked from commit 5ab6a61ada)
2021-08-27 11:13:42 +00:00
Joachim Breitner
b720376c7c ocamlPackages.vlq: init at 0.2.1
(cherry picked from commit 91a55816dda6ac8caef47bfa3ff4bcf832ff4b3b)
2021-08-27 10:31:06 +02:00
davidak
5009ca7bd0 Merge pull request #135738 from NixOS/backport-125307-to-staging-21.05
[Backport staging-21.05] tk-8_6: fix hash after tcl-8_6 update
2021-08-26 18:56:04 +02:00
github-actions[bot]
1babb212b7 Merge staging-next-21.05 into staging-21.05 2021-08-26 12:02:49 +00:00
github-actions[bot]
11914a0a34 Merge release-21.05 into staging-next-21.05 2021-08-26 12:02:16 +00:00
Maximilian Bosch
9d6766c0f0 Merge pull request #135766 from NixOS/backport-135032-to-release-21.05
[Backport release-21.05] tor-browser-bundle-bin: 10.5.2 -> 10.5.5
2021-08-26 13:06:13 +02:00
Lux
1351d271d3 tor-browser-bundle-bin: 10.5.2 -> 10.5.5
(cherry picked from commit bd6f316efa)
2021-08-26 09:42:39 +00:00
Mario Rodas
a2303a63e4 nodejs-16_x: 16.7.0 -> 16.8.0
https://github.com/nodejs/node/releases/tag/v16.8.0
(cherry picked from commit 372b7ce697)
2021-08-25 22:30:44 -05:00
Ricardo M. Correia
0d44dce530 tk-8_6: fix hash after tcl-8_6 update
tcl-8_6 was updated in 4fb92ae60d from
8.6.9 -> 8.6.11 but tk's hash wasn't updated at the same time,
which means the current hash was still from tk 8.6.9 rather than 8.6.11.

(cherry picked from commit d9bf02324a)
2021-08-26 03:13:56 +00:00
github-actions[bot]
ba4aef5a48 Merge staging-next-21.05 into staging-21.05 2021-08-26 00:03:26 +00:00
github-actions[bot]
98962e17c4 Merge release-21.05 into staging-next-21.05 2021-08-26 00:02:52 +00:00
Martin Weinelt
51a53aea36 Merge pull request #135700 from risicle/ris-icinga2-2.12.6-r21.05
[21.05] icinga2: 2.12.4 -> 2.12.6
2021-08-26 01:56:34 +02:00
Martin Weinelt
b199038e38 Merge pull request #135713 from NixOS/backport-135706-to-release-21.05 2021-08-26 01:20:36 +02:00
Janne Heß
dacd1104f6 flexoptix-app: 5.9.0 -> 5.11.0 and fixes
This update is required because the autoupdater prevents the app from
running without being updated (which is not possible because it is a
store path).
So this updates the app and patches out the updater (essentially it
never thinks it needs to update, even though it prints on the command
line that it should).

Also fix the desktop item.

(cherry picked from commit 9aa05d18b7)
2021-08-25 23:00:19 +00:00
Marc Seeger
2fcab17583 unixODBC: Add additional URL
(cherry picked from commit 811af99f75)
2021-08-25 22:49:29 +02:00
Robert Scott
6a01d735d9 icinga2: 2.12.4 -> 2.12.6 2021-08-25 21:39:25 +01:00
Robert Scott
7255b8c354 Merge pull request #135648 from NixOS/backport-135592-to-release-21.05
[Backport release-21.05] haproxy: 2.3.10 -> 2.3.13
2021-08-25 20:42:28 +01:00
github-actions[bot]
99f20e24c7 Merge staging-next-21.05 into staging-21.05 2021-08-25 18:02:53 +00:00
github-actions[bot]
3bac9b7b8a Merge release-21.05 into staging-next-21.05 2021-08-25 18:02:18 +00:00
Bjørn Forsman
e887706c1f eagle: put the desktop icon where it can be found
Apparently $out/share/icons/ doesn't work anymore, but
$out/share/pixmaps/ do.

(cherry picked from commit 7f6cb5a226)
2021-08-25 19:13:01 +02:00
Florian Klink
e24074676b Merge pull request #135318 from NixOS/backport-132347-to-release-21.05
[Backport release-21.05] captive-browser: fix empty string in interface args
2021-08-25 16:20:05 +02:00
github-actions[bot]
570e6260ae Merge staging-next-21.05 into staging-21.05 2021-08-25 12:03:15 +00:00
github-actions[bot]
0fbbb4e6ff Merge release-21.05 into staging-next-21.05 2021-08-25 12:02:40 +00:00
Ben Wolsieffer
9b1ef47ae3 spidermonkey_78: fix build on armv7l
Adds a patch from Debian to fix a build failure on armv7l.

(cherry picked from commit 1b1e681d77)
2021-08-25 10:18:56 +00:00
Robert Scott
f74adda653 haproxy: 2.3.10 -> 2.3.13
(cherry picked from commit b919ded180)
2021-08-25 08:30:58 +00:00
Maximilian Bosch
bc1a0f5681 Merge pull request #135595 from NixOS/backport-134671-to-release-21.05
[Backport release-21.05] matrix-synapse: 1.40.0 -> 1.41.0
2021-08-25 10:28:02 +02:00
github-actions[bot]
35a048c8bc Merge staging-next-21.05 into staging-21.05 2021-08-25 00:03:46 +00:00
github-actions[bot]
97b39a6dc2 Merge release-21.05 into staging-next-21.05 2021-08-25 00:03:07 +00:00
Maximilian Bosch
ba6124b621 Merge pull request #135591 from Ma27/fix-mautrix-telegram
[21.05] mautrix-telegram: fix crash
2021-08-25 00:22:07 +02:00
Sumner Evans
7da0e25749 matrix-synapse: 1.40.0 -> 1.41.0
(cherry picked from commit 2f1030b3ad)
2021-08-24 20:36:45 +00:00
Michael Raskin
64fa98757b Merge pull request #135587 from NixOS/backport-135582-to-release-21.05
[Backport release-21.05] acpi_call: 1.2.1 -> 1.2.2
2021-08-24 20:03:50 +00:00
Julian Stecklina
4462377467 acpi_call: 1.2.1 -> 1.2.2
(cherry picked from commit 016e8cf78c)
2021-08-24 19:37:18 +00:00
Maximilian Bosch
4aa2488fd1 mautrix-telegram: fix crash
The previous backport of `mautrix-telegram`[1] appears to be a mistake
of mine (sorry for that!), unfortunately v0.9 isn't forward-compatible
due to a database migration, so this change can't be reversed.

The primary issue was that `telethon` was too old, so I decided to
upgrade it to 1.21 which is what I had on my 21.05-based tracking
branch while using `mautrix-telegram` anyways, so that's proven to work.

Closes #135583

[1] e1042038ac / cd84b8ad8b
2021-08-24 21:28:15 +02:00
github-actions[bot]
7956bcb2f5 Merge staging-next-21.05 into staging-21.05 2021-08-24 18:03:04 +00:00
github-actions[bot]
f90cf6b7f8 Merge release-21.05 into staging-next-21.05 2021-08-24 18:02:30 +00:00
Martin Weinelt
ae2717f11b Merge pull request #134072 from risicle/ris-openvswitch-CVE-2021-36980-r21.05
[21.05] openvswitch: add patch for CVE-2021-36980
2021-08-24 19:49:01 +02:00
Maximilian Bosch
9001cc3080 Merge pull request #134344 from NixOS/backport-132559-to-release-21.05
[Backport release-21.05] matrix-synapse: 1.39.0 -> 1.40.0
2021-08-24 19:02:50 +02:00
adisbladis
3b049d720a Merge pull request #135549 from Prillan/emacs-elpa-fetcher
emacs: Add custom elpa fetcher (backport)
2021-08-24 10:42:17 -05:00
Martin Weinelt
47d1b12472 Merge pull request #134858 from NixOS/backport-134751-to-staging-21.05
[Backport staging-21.05] c-ares: enable parallel building
2021-08-24 16:49:31 +02:00
Martin Weinelt
6a54c3357f Merge pull request #133252 from mweinelt/21.05/cpython/update 2021-08-24 16:48:58 +02:00
Kerstin Humm
ea4cbf4b3a imagemagick: 7.1.0-4 -> 7.1.0-5
(cherry picked from commit 042229148d)
2021-08-24 15:36:47 +02:00
Martin Weinelt
3209ef6364 Merge pull request #135215 from NixOS/backport-135125-to-release-21.05
[Backport release-21.05] python3Packages.yamale: 3.0.4 -> 3.0.8
2021-08-24 15:24:52 +02:00
Martin Weinelt
4b16abddba Merge pull request #134839 from risicle/ris-rsync-CVE-2020-14387-r21.05 2021-08-24 15:13:03 +02:00
Martin Weinelt
a4463ff45c Merge pull request #134222 from NixOS/backport-117235-to-release-21.05 2021-08-24 15:10:53 +02:00
Martin Weinelt
b2c5035d6e Merge pull request #134260 from risicle/ris-ndpi-CVE-2021-36082-r21.05
[21.05] ndpi: add patch for CVE-2021-36082
2021-08-24 15:08:44 +02:00
Martin Weinelt
d818c9fd75 Merge pull request #134278 from NixOS/backport-133375-to-staging-21.05
[Backport staging-21.05] c-ares: 1.17.1 -> 1.17.2
2021-08-24 15:03:30 +02:00
Martin Weinelt
f0a1234576 Merge pull request #134062 from NixOS/backport-132984-to-release-21.05
[Backport release-21.05] folly: 2021.01.25.00 -> 2021.08.02.00
2021-08-24 14:42:18 +02:00
adisbladis
6a5fc6beca emacs.pkgs.elpaPackages: Use custom elpa fetcher 2021-08-24 14:26:57 +02:00
adisbladis
66966119f3 emacs: Add custom elpa fetcher
Elpa only serves the latest version of a given package uncompressed.
Once that release is no longer the latest & greatest it gets archived and compressed
meaning that both the URL and the hash changes.

To work around this issue we fall back to the URL with the .lz suffix and if that's the
one we downloaded we uncompress the file to ensure the hash matches regardless of compression.
2021-08-24 14:26:44 +02:00
github-actions[bot]
cf43eb79df Merge staging-next-21.05 into staging-21.05 2021-08-24 06:07:33 +00:00
github-actions[bot]
a05256d07a Merge release-21.05 into staging-next-21.05 2021-08-24 06:03:27 +00:00
Wael Nasreddine
d5aadbefd6 Merge pull request #134966 from NixOS/backport-134838-to-release-21.05
[Backport release-21.05] onlykey: init at 5.3.3
2021-08-23 19:38:43 -07:00
github-actions[bot]
8c2f34ae9d Merge staging-next-21.05 into staging-21.05 2021-08-24 00:03:10 +00:00
github-actions[bot]
1b3e2491d5 Merge release-21.05 into staging-next-21.05 2021-08-24 00:02:29 +00:00
Maximilian Bosch
4fc6d88dc7 Merge pull request #135296 from mguentner/backport_21_05_twisted_21_07_for_matrix_synapse
[Backport 21.05] override twisted 20.3.0 -> 21.7.0 for matrix-synapse
2021-08-23 23:19:57 +02:00
Maximilian Bosch
0f22a1d8b1 Merge pull request #135448 from EggBaconAndSpam/glibc-2.32-54
glibc: 2.32-48 -> 2.32-54
2021-08-23 22:41:06 +02:00
Pavol Rusnak
c85312506e Merge pull request #135466 from risicle/ris-tor-0.4.5.10-r21.05
[21.05] tor: 0.4.5.9 -> 0.4.5.10
2021-08-23 22:28:12 +02:00
Robert Scott
2bafc080b4 tor: 0.4.5.9 -> 0.4.5.10 2021-08-23 19:43:53 +01:00
github-actions[bot]
4f299d6ab6 Merge staging-next-21.05 into staging-21.05 2021-08-23 18:02:44 +00:00
github-actions[bot]
7326883996 Merge release-21.05 into staging-next-21.05 2021-08-23 18:02:13 +00:00
Sandro
983bd5b78c Merge pull request #135436 from NixOS/backport-129194-to-release-21.05
[Backport release-21.05] pythonPackages.pillow-simd: revert update to 8.1.2
2021-08-23 15:59:03 +02:00
Frederik Ramcke
3ecbe36e8d glibc: 2.32-48 -> 2.32-54 2021-08-23 15:41:52 +02:00
github-actions[bot]
04e6f86cda Merge staging-next-21.05 into staging-21.05 2021-08-23 12:04:11 +00:00
github-actions[bot]
fcc8fc6323 Merge release-21.05 into staging-next-21.05 2021-08-23 12:02:40 +00:00
Sandro Jäckel
364e84d0fc pythonPackages.pillow-simd: revert update to 8.1.2
(cherry picked from commit d4cd4061d4)
2021-08-23 11:20:27 +00:00
maralorn
dcb27f623f Merge pull request #135431 from nomeata/unbreak-haskell-ci-release
[21.05] haskell-ci: no longer mark as broken
2021-08-23 12:47:56 +02:00
sternenseemann
c367ee7bda haskell-ci: no longer mark as broken
haskell-ci just builds (again?) without any necessary changes

(cherry picked from commit 1be4cb6748)
2021-08-23 12:17:29 +02:00
github-actions[bot]
4b6bb2fd52 Merge staging-next-21.05 into staging-21.05 2021-08-23 00:03:25 +00:00
github-actions[bot]
e4d36f95cb Merge release-21.05 into staging-next-21.05 2021-08-23 00:02:38 +00:00
Robert Scott
871e8c4d58 Merge pull request #135305 from NixOS/backport-135250-to-release-21.05
[Backport release-21.05] python3Packages.markdown2: 2.4.0 -> 2.4.1
2021-08-22 23:57:30 +01:00
Michael Weiss
835bdf1b65 Merge pull request #135327 from NixOS/backport-135228-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 92.0.4515.131 -> 92.0.4515.159
2021-08-22 21:33:54 +02:00
Michael Weiss
fe10697bd0 ungoogled-chromium: 92.0.4515.131 -> 92.0.4515.159
(cherry picked from commit 76ab90294e)
2021-08-22 19:13:31 +00:00
Mario Rodas
32e7630d8a nodejs-16_x: 16.6.2 -> 16.7.0
https://github.com/nodejs/node/releases/tag/v16.7.0
(cherry picked from commit f3706ab27f)
2021-08-22 13:45:05 -05:00
github-actions[bot]
200313cca5 Merge staging-next-21.05 into staging-21.05 2021-08-22 18:02:39 +00:00
github-actions[bot]
7f5fb8d345 Merge release-21.05 into staging-next-21.05 2021-08-22 18:02:09 +00:00
Ankit Pandey
66e129b194 captive-browser: fix empty string in interface args
Fixes nmcli being passed an empty string before the interface name,
which would stop captive-browser from starting up.

(cherry picked from commit 910f233fb7)
2021-08-22 17:44:31 +00:00
Fabian Affolter
fe6b8c4b0f python3Packages.markdown2: 2.4.0 -> 2.4.1
(cherry picked from commit 5b4b1cbfc4)
2021-08-22 15:13:49 +00:00
Victor Nawothnig
d6e9b8d66f nixos/rspamd: Avoid empty postfix service
(cherry picked from commit 942d78d9cd)
2021-08-22 15:10:19 +00:00
Maximilian Güntner
e9d616380b matrix-synapse: override twisted 20.3.0 -> 21.7.0
see upstream issues:

https://github.com/twisted/twisted/pull/1225#issuecomment-788560006
https://github.com/matrix-org/synapse/issues/6211
2021-08-22 16:46:45 +02:00
Maximilian Güntner
e6e8fe7633 nixos/tests/matrix-synapse: add email regression test case
twisted is used in matrix-synapse for smtp handling.
Mostly this is used for password resets, but also notifications
are delivered that way.

older versions of twisted require the e-mail server to
have TLS1.0 enabled.

Obviously, quite a lot of servers have this disabled which means
synapse won't be able to deliver mails using such servers.

matrix-synapse issue:

https://github.com/matrix-org/synapse/issues/6211
2021-08-22 16:46:44 +02:00
Vladimír Čunát
4e749dc0a1 Merge #135245: linux_*_hardened: update (into release-21.05) 2021-08-22 16:29:57 +02:00
R. RyanTM
b74eb05e06 ptcollab: 0.4.1 -> 0.4.2
(cherry picked from commit 8ed936a10b)
2021-08-22 14:11:11 +00:00
ajs124
7e07a7e299 linuxPackages_5_4_hardened: 5.4.141 -> 5.4.142
(cherry picked from commit 5659733165)
2021-08-22 09:49:01 +00:00
ajs124
9690490f18 linuxPackages_5_10_hardened: 5.10.59 -> 5.10.60
(cherry picked from commit 883db296a2)
2021-08-22 09:49:01 +00:00
ajs124
9bb174c59e linuxPackages_5_4_hardened: 5.4.139 -> 5.4.141
(cherry picked from commit b9b1fc1b38)
2021-08-22 09:49:00 +00:00
ajs124
329105e4a9 linuxPackages_5_10_hardened: 5.10.57 -> 5.10.59
(cherry picked from commit 580d4b687f)
2021-08-22 09:49:00 +00:00
ajs124
676c5aa6bf linuxPackages_4_19_hardened: 4.19.202 -> 4.19.204
(cherry picked from commit a438b96c9e)
2021-08-22 09:48:59 +00:00
ajs124
0cdce1e22b linuxPackages_4_14_hardened: 4.14.243 -> 4.14.244
(cherry picked from commit 1120eafa97)
2021-08-22 09:48:59 +00:00
ajs124
6c74fc118a linuxPackages_hardened: fix update.py
this is kind of hack, idk how this worked before, tbh

(cherry picked from commit e82f9673c5)
2021-08-22 09:48:58 +00:00
Robert Scott
938357ce19 python3Packages.yamale: 3.0.4 -> 3.0.8
(cherry picked from commit 58078da425)
2021-08-22 07:22:05 +00:00
github-actions[bot]
6708356f5e Merge staging-next-21.05 into staging-21.05 2021-08-22 00:03:19 +00:00
github-actions[bot]
ffa9f6e94e Merge release-21.05 into staging-next-21.05 2021-08-22 00:02:47 +00:00
Robert Scott
422b95f54f Merge pull request #135086 from risicle/ris-radare2-CVE-2021-3673
[21.05] radare2: add patch for CVE-2021-3673
2021-08-21 23:38:55 +01:00
Robert Scott
0be4a28183 Merge pull request #135001 from jasonrm/backport/134767-to-21.05
[21.05] mysql80: fix build on darwin
2021-08-21 23:22:06 +01:00
Wael Nasreddine
11e6372341 Merge pull request #135092 from NixOS/backport-134764-to-release-21.05
[Backport release-21.05] onlykey-agent: init at 1.0.2
2021-08-21 12:43:19 -07:00
Kim Lindberger
c37b973071 Merge pull request #135096 from NixOS/backport-135090-to-release-21.05
[Backport release-21.05] nomachine-client: 7.4.1 -> 7.6.2
2021-08-21 20:07:03 +02:00
github-actions[bot]
75a5007c16 Merge staging-next-21.05 into staging-21.05 2021-08-21 18:03:21 +00:00
github-actions[bot]
761da7d723 Merge release-21.05 into staging-next-21.05 2021-08-21 18:02:40 +00:00
talyz
d6e092c25f nomachine-client: 7.4.1 -> 7.6.2
(cherry picked from commit 73bae61cda)
2021-08-21 17:58:15 +00:00
Wael M. Nasreddine
5794e35b25 onlykey-agent: init at 1.0.2
(cherry picked from commit 8b8cd493ef)
2021-08-21 17:14:04 +00:00
Robert Scott
12a8c6cdce radare2: add patch for CVE-2021-3673 2021-08-21 17:09:51 +01:00
Maciej Krüger
d3fbdb26a2 Merge pull request #135074 from NixOS/backport-134616-to-release-21.05
[Backport release-21.05] Fix Jetbrains on NixOS: Add e2fsprogs
2021-08-21 16:26:52 +02:00
Florian Beeres
9295a53afc Add e2fsprogs to jetbrains
Without this dependency JetBrains editors, on NixOS, will throw errors
about a missing object file:
java.lang.UnsatisfiedLinkError: libe2p.so

(cherry picked from commit 70f3763e146432eca9cf7d792e7d2d12684e1c5f)
2021-08-21 12:36:34 +00:00
github-actions[bot]
6e7ac86ae6 Merge staging-next-21.05 into staging-21.05 2021-08-21 12:03:40 +00:00
github-actions[bot]
e590a93591 Merge release-21.05 into staging-next-21.05 2021-08-21 12:03:01 +00:00
Jörg Thalheim
a0a2f6b6ef linux_zen: add update script
(cherry picked from commit e4db1c8847)
2021-08-21 10:04:20 +00:00
Jörg Thalheim
5264329acd linuxPackages_zen: 5.13.9 -> 5.13.10-zen1
(cherry picked from commit 27edf4ccb4)
2021-08-21 10:04:19 +00:00
R. RyanTM
2d2c39dcc3 openmpt123: 0.5.9 -> 0.5.10
(cherry picked from commit 4cb042ecb5)
2021-08-21 10:28:40 +02:00
OPNA2608
e5610bf14d openmpt123: Add maintainer, 0.5.8 -> 0.5.9
(cherry picked from commit dfc39e61f4)
2021-08-21 10:28:33 +02:00
Vladimír Čunát
219a77ea26 Merge branch 'staging-21.05' into release-21.05
ffmpeg isn't such a huge rebuild, so let's do this directly.
2021-08-21 09:38:38 +02:00
github-actions[bot]
fa539d9341 Merge staging-next-21.05 into staging-21.05 2021-08-21 06:02:59 +00:00
github-actions[bot]
e3954ffd47 Merge release-21.05 into staging-next-21.05 2021-08-21 06:02:16 +00:00
Luke Granger-Brown
275cdcb119 Merge pull request #135025 from NixOS/backport-134726-to-staging-21.05
[Backport staging-21.05] ffmpeg, ffmpeg-full: enable basic tests
2021-08-21 04:39:26 +01:00
Zane van Iperen
bd84f4a6ed nixos/gitea: init/migrate db in startup script
(cherry picked from commit 99d8d553da)
2021-08-21 12:24:40 +09:00
Zane van Iperen
9d0618433a nixos/gitea: use gitea to refresh hooks and keys
Gitea now provides this functionality as an admin command.
Is significantly faster, especially on slow disks.

(cherry picked from commit c854b85702)
2021-08-21 12:24:40 +09:00
Robert Scott
1c8ff5cfc7 ffmpeg-full: enable basic tests
(cherry picked from commit 4b658eda80)
2021-08-21 02:46:00 +00:00
Robert Scott
7361aaeb5e ffmpeg: enable basic tests
(cherry picked from commit 649f0ed1a8)
2021-08-21 02:46:00 +00:00
Luke Granger-Brown
84b0bedef2 Merge pull request #135022 from NixOS/backport-134363-to-release-21.05
[Backport release-21.05] warzone2100: 4.1.1 -> 4.1.3
2021-08-21 03:33:49 +01:00
Francesco Gazzetta
9e28807d03 warzone2100: 4.1.1 -> 4.1.3
(cherry picked from commit 4b5f0bfa39)
2021-08-21 00:24:37 +00:00
github-actions[bot]
124ccc3fcd Merge staging-next-21.05 into staging-21.05 2021-08-21 00:03:23 +00:00
github-actions[bot]
ee693ed5f1 Merge release-21.05 into staging-next-21.05 2021-08-21 00:02:49 +00:00
Anderson Torres
f5c2a9a8de Merge pull request #134844 from NixOS/backport-134591-to-release-21.05
[Backport release-21.05] palemoon: 29.3.0 -> 29.4.0.1
2021-08-20 19:33:38 -03:00
Maximilian Bosch
b86db7692f Merge pull request #134933 from Ma27/backport-mautrix-telegram
[21.05] mautrix telegram: 0.10.0 -> 0.10.1
2021-08-21 00:06:56 +02:00
Jason R. McNeil
698d69b2f5 mysql80: fix build on darwin
sw_vers is called during build since 8.0.26

- 83b87ae7f8

Fixes #132288

(cherry picked from commit 5c452f15af)
2021-08-20 13:59:15 -07:00
github-actions[bot]
90fe936535 Merge staging-next-21.05 into staging-21.05 2021-08-20 18:02:52 +00:00
github-actions[bot]
45315a0f53 Merge release-21.05 into staging-next-21.05 2021-08-20 18:02:19 +00:00
Maximilian Bosch
1dc32d71d5 Merge pull request #134947 from NixOS/backport-134692-to-release-21.05
[Backport release-21.05] Kernels 2021-08-18
2021-08-20 18:50:37 +02:00
Wael M. Nasreddine
3e55f1df9d onlykey: parse the version from package.json
(cherry picked from commit 7c27d012ae)
2021-08-20 16:25:24 +00:00
Wael M. Nasreddine
e9bc98c9cb onlykey: npm install ignore scripts instead of hacking nw urlbase
(cherry picked from commit 5a1a8df251)
2021-08-20 16:25:24 +00:00
Wael M. Nasreddine
8582286fa0 onlykey: init at 5.3.3
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit f4498d1118)
2021-08-20 16:25:23 +00:00
Wael Nasreddine
46bb19ea0f Merge pull request #134859 from kalbasit/update-onlykey-cli
[Backport release-21.05] onlykey-cli: 1.2.2 -> 1.2.5
2021-08-20 09:15:30 -07:00
Kim Lindberger
64f5c7c6fd Merge pull request #134799 from NixOS/backport-132475-to-release-21.05
[Backport release-21.05] discourseAllPlugins: init discourse-ldap-auth
2021-08-20 18:06:54 +02:00
ajs124
bb74e9be2f sogo: 5.1.1 -> 5.2.0
https://github.com/inverse-inc/sogo/releases/tag/SOGo-5.2.0
(cherry picked from commit 5fdc39a49d)
2021-08-20 14:10:16 +00:00
ajs124
5b5ddcf940 sope: 5.1.1 -> 5.2.0
(cherry picked from commit 794ebddc88)
2021-08-20 14:10:16 +00:00
TredwellGit
68a87a1d8e linux_latest-libre: 18210 -> 18239
(cherry picked from commit 4512ae3044)
2021-08-20 12:12:15 +00:00
TredwellGit
d91ef03f45 linux-rt_5_10: 5.10.56-rt48 -> 5.10.56-rt49
(cherry picked from commit 10472677e1)
2021-08-20 12:12:15 +00:00
TredwellGit
552f2172c6 linux: 5.4.139 -> 5.4.142
(cherry picked from commit 0055f78736)
2021-08-20 12:12:14 +00:00
TredwellGit
6953c465cc linux: 5.13.11 -> 5.13.12
(cherry picked from commit 7ff40c8d9e)
2021-08-20 12:12:14 +00:00
TredwellGit
0c0320e4b9 linux: 5.10.57 -> 5.10.60
(cherry picked from commit ab311a8b25)
2021-08-20 12:12:13 +00:00
TredwellGit
4f323dd3cb linux: 4.19.202 -> 4.19.204
(cherry picked from commit b7a564432b)
2021-08-20 12:12:13 +00:00
TredwellGit
637741d8e1 linux: 4.14.243 -> 4.14.244
(cherry picked from commit 2b71c4caac)
2021-08-20 12:12:13 +00:00
github-actions[bot]
4027eff0c6 Merge staging-next-21.05 into staging-21.05 2021-08-20 12:03:28 +00:00
github-actions[bot]
3961e9ebfa Merge release-21.05 into staging-next-21.05 2021-08-20 12:02:35 +00:00
Pavol Rusnak
bd21f646da Merge pull request #133371 from prusnak/electron-21.05
[21.05] Update electron_{11,12}
2021-08-20 13:50:50 +02:00
Maximilian Bosch
05e5b69ac8 mautrix-telegram: override mautrix to version 0.10.4
This is needed since 0.10.1 of mautrix-telegram, but it'd be a breaking
change of mautrix, which can be used for any kind of matrix client, so I
don't really want to break it.
2021-08-20 11:17:04 +02:00
Maximilian Bosch
e1042038ac mautrix-telegram: 2021-08-12 -> 0.10.1
ChangeLog: https://github.com/mautrix/telegram/releases/tag/v0.10.1
(cherry picked from commit dd39ec87f4)
2021-08-20 11:10:53 +02:00
Fabian Affolter
cd84b8ad8b mautrix-telegram: 0.10.0 -> unstable-2021-08-12
(cherry picked from commit 682f35087a)
2021-08-20 11:10:49 +02:00
Maximilian Bosch
3ddfcfc8d7 Merge pull request #134788 from Ma27/backport-ffmpeg
[21.05] ffmpeg: apply patches for CVE-2021-3811{4,5} & incorrect segment length
2021-08-20 11:05:59 +02:00
R. RyanTM
2657c03322 gitui: 0.16.0 -> 0.16.1
(cherry picked from commit d4963ae435)
2021-08-20 06:10:56 +00:00
github-actions[bot]
daff3827c7 Merge staging-next-21.05 into staging-21.05 2021-08-20 06:03:18 +00:00
github-actions[bot]
8622928256 Merge release-21.05 into staging-next-21.05 2021-08-20 06:02:38 +00:00
Vladimír Čunát
50d17a4663 Merge #134651: firefox*: patch updates (into release-21.05) 2021-08-20 07:39:38 +02:00
Vladimír Čunát
7cacb795a9 Merge branch 'staging-next-21.05' into release-21.05
https://hydra.nixos.org/eval/1697302
2021-08-20 07:38:11 +02:00
Wael M. Nasreddine
b64d6f2d3c onlykey-cli: update 1.2.2 -> 1.2.5
(cherry picked from commit 98f344f0da)
2021-08-19 12:48:53 -07:00
Wael M. Nasreddine
50d1f373a3 python3Packages.onlykey-solo-python: init at 0.0.28
(cherry picked from commit d136766caa)
2021-08-19 12:47:40 -07:00
TredwellGit
c9a0a88184 c-ares: enable parallel building
(cherry picked from commit b2ae763c42)
2021-08-19 19:43:21 +00:00
OPNA2608
80505d1a07 palemoon: 29.4.0 -> 29.4.0.1
(cherry picked from commit 1875fba4c4)
2021-08-19 18:54:25 +00:00
OPNA2608
3f828fea6e palemoon: 29.3.0 -> 29.4.0
(cherry picked from commit aa08cc4290)
2021-08-19 18:54:25 +00:00
Robert Scott
41a38db165 rsync: add patch for CVE-2020-14387
(cherry picked from commit a08ee2292c)
2021-08-19 19:24:10 +01:00
github-actions[bot]
74f8b36dee Merge staging-next-21.05 into staging-21.05 2021-08-19 18:02:52 +00:00
github-actions[bot]
0325df84d0 Merge release-21.05 into staging-next-21.05 2021-08-19 18:02:16 +00:00
Yurii Matsiuk
04bd0636a1 firmwareLinuxNonfree: 2021-07-16 -> 2021-08-18
(cherry picked from commit 3239c7bc8d)
2021-08-19 17:37:29 +00:00
Ryan Mulligan
6feba8ac10 discourseAllPlugins: init discourse-ldap-auth
(cherry picked from commit 70d29c5cf4)
2021-08-19 13:32:24 +00:00
Kim Lindberger
a1007637ce Merge pull request #133624 from talyz/discourse-backports
[21.05] discourse: 2.7.5 -> 2.7.7, plugins and fixes
2021-08-19 15:27:08 +02:00
github-actions[bot]
38b1b1de47 Merge staging-next-21.05 into staging-21.05 2021-08-19 12:03:49 +00:00
github-actions[bot]
3a81d95bdf Merge release-21.05 into staging-next-21.05 2021-08-19 12:02:42 +00:00
TredwellGit
568b939c3e ffmpeg: patch CVE-2021-33815 and CVE-2021-38114
https://nvd.nist.gov/vuln/detail/CVE-2021-33815
https://nvd.nist.gov/vuln/detail/CVE-2021-38114
(cherry picked from commit a83f82576b)
2021-08-19 13:19:25 +02:00
Izorkin
81ed9fd47b ffmpeg_4: fix incorrect segment length in hls
(cherry picked from commit ae8dd3c149)
2021-08-19 13:19:20 +02:00
Michael Weiss
f9698c475d Merge pull request #134414 from NixOS/backport-134409-to-release-21.05
[Backport release-21.05] chromium: 92.0.4515.131 -> 92.0.4515.159
2021-08-19 10:59:51 +02:00
Michael Weiss
d64c771c8e Merge pull request #134719 from NixOS/backport-134704-to-release-21.05
[Backport release-21.05] signal-desktop: 5.13.1 -> 5.14.0
2021-08-19 10:36:36 +02:00
Vladimír Čunát
46c853dfc2 Merge #134714: gpgme: move flaky patch URL to local file
(cherry picked from commit 4c88dc6a70)
2021-08-19 09:56:11 +02:00
github-actions[bot]
57607e810f Merge staging-next-21.05 into staging-21.05 2021-08-19 06:02:49 +00:00
github-actions[bot]
119d0ca33a Merge release-21.05 into staging-next-21.05 2021-08-19 06:02:14 +00:00
Wael Nasreddine
c7315b77ef Merge pull request #134759 from NixOS/backport-124815-to-release-21.05
[Backport release-21.05] config.hardware.onlykey: update the udev rules for onlykey
2021-08-18 21:07:04 -07:00
Wael M. Nasreddine
dff77786cf config.hardware.onlykey: update the udev rules for onlykey
The udev rules were updated upstream without an explanation as you can
see in [this comment][commit].

[commit]: 0bcf928ada

(cherry picked from commit eab36fabf6)
2021-08-19 03:25:13 +00:00
Wael M. Nasreddine
6c50c69d97 config.hardware.onlykey: move the module into its own folder
(cherry picked from commit 1f9e019260)
2021-08-19 03:25:13 +00:00
github-actions[bot]
dad73ee885 Merge staging-next-21.05 into staging-21.05 2021-08-19 00:03:51 +00:00
github-actions[bot]
2311e122d4 Merge release-21.05 into staging-next-21.05 2021-08-19 00:02:39 +00:00
Maximilian Bosch
7bbafa9a3c Merge pull request #134299 from NixOS/backport-124942-to-release-21.05
[Backport release-21.05] gitui: 0.15.0 -> 0.16.0
2021-08-19 01:09:53 +02:00
Michael Weiss
da2591ed04 signal-desktop: 5.13.1 -> 5.14.0
(cherry picked from commit 8a4a84c83a)
2021-08-18 21:25:02 +00:00
Martin Weinelt
7d0ad48e23 firefox-bin: 91.0 -> 91.0.1
(cherry picked from commit 027b2ac2eb)
2021-08-18 15:37:42 +02:00
Martin Weinelt
ba1de1358b firefox-esr-78: 78.12.0esr -> 78.13.0esr
(cherry picked from commit ab44b4dea7)
2021-08-18 15:37:42 +02:00
Martin Weinelt
5f63cddc87 firefox-esr-91: 91.0esr -> 91.0.1esr
(cherry picked from commit 2ad22bbb52)
2021-08-18 15:37:42 +02:00
Martin Weinelt
5fe44d0661 firefox: 91.0 -> 91.0.1
(cherry picked from commit 010a316966)
2021-08-18 15:37:41 +02:00
github-actions[bot]
008f7e4f05 Merge staging-next-21.05 into staging-21.05 2021-08-18 12:03:03 +00:00
github-actions[bot]
8b74ece217 Merge release-21.05 into staging-next-21.05 2021-08-18 12:02:26 +00:00
Vladimír Čunát
7bbca9877c Merge #134298: linux_5_12: remove (into release-21.05) 2021-08-18 09:26:59 +02:00
github-actions[bot]
739352cb60 Merge staging-next-21.05 into staging-21.05 2021-08-18 06:04:28 +00:00
github-actions[bot]
9b9c8e4fda Merge release-21.05 into staging-next-21.05 2021-08-18 06:03:41 +00:00
Vladimír Čunát
4050fb937f Merge #134354: gpgme: fix failing patch download
(cherry picked from commit 91b178c3f0)
2021-08-18 07:31:39 +02:00
github-actions[bot]
6772be8a5d Merge staging-next-21.05 into staging-21.05 2021-08-18 00:03:17 +00:00
github-actions[bot]
4955c065ca Merge release-21.05 into staging-next-21.05 2021-08-18 00:02:34 +00:00
talyz
18902d1e12 discourse: update.py: Remove native platforms in plugin lock files..
...and add ruby.

(cherry picked from commit 12ff4b79e4)
2021-08-17 23:16:54 +02:00
talyz
ba5434c984 discourse.mkDiscoursePlugin: Handle repos with gems directories
Some plugin repos already have a `gems` directory. This lets the
packager choose whether it should be kept and the nix packaged ruby
gems should be copied into it or if it should be removed in favor of
our ruby gems.

(cherry picked from commit 04e6b03fa9)
2021-08-17 23:16:47 +02:00
talyz
fd169abf9b discourse.plugins: Make the updater able to package plugins
Let the update.py script handle the initial, repetitive task of
packaging new plugins. With this in place, the plugin only needs to be
added to the list in `update-plugins` and most of the work will be
done automatically when the script is run. Metadata still needs to be
filled in manually and some packages may of course require additional
work/patching.

(cherry picked from commit f8096460bd)
2021-08-17 23:16:41 +02:00
talyz
08fde82d77 discourse.plugins.discourse-github: Update
(cherry picked from commit 4197b6dd14)
2021-08-17 23:16:34 +02:00
talyz
af15cbe6b0 discourse: Change the path to the auto generated plugin assets
Change the path to the auto generated plugin assets, which defaults to
the plugin's directory and isn't writable at the time of asset
generation.

(cherry picked from commit 443b318ee9)
2021-08-17 23:16:28 +02:00
talyz
080e4e43fb discourse.tests: Test the appropriate discourse package
Perform the tests on the package that the `tests` attribute is a child
of, i.e. if `discourseAllPlugins.tests` is built, the tests will run
with the `discourseAllPlugins` package, not the `discourse` package as
previously.

(cherry picked from commit 6fd5a40cca)
2021-08-17 23:16:18 +02:00
talyz
639e1d9639 discourse: Remove leftover link to unused plugins directory
(cherry picked from commit bb14315d51)
2021-08-17 23:13:55 +02:00
talyz
202c17a806 discourse.plugins.discourse-data-explorer: Update
(cherry picked from commit 6f26527358)
2021-08-17 23:13:49 +02:00
talyz
700cfb0fc3 discourse.plugins.discourse-solved: Update
(cherry picked from commit 92b758266e)
2021-08-17 23:13:43 +02:00
talyz
fddb277d03 discourse.plugins.discourse-canned-replies: Update
(cherry picked from commit 5d94e3bfc9)
2021-08-17 23:13:36 +02:00
talyz
4a30a10e62 discourse.plugins.discourse-calendar: Update
(cherry picked from commit d1a63bf19c)
2021-08-17 23:13:30 +02:00
talyz
f2533d47c8 discourse: 2.7.5 -> 2.7.7
(cherry picked from commit c97ae4ad8e)
2021-08-17 23:13:23 +02:00
Felix Buehler
c193cf6ed9 discourse.mkDiscoursePlugin: remove phases
(cherry picked from commit 4f62b05137)
2021-08-17 23:12:50 +02:00
Ryan Mulligan
8b8ccc0fd8 discourseAllPlugins: add discourse-calendar
(cherry picked from commit 858b0157e5)
2021-08-17 23:12:44 +02:00
Ryan Mulligan
48f779f37d discourse/update.py: add missing plugins
(cherry picked from commit 32e24e792c)
2021-08-17 23:12:39 +02:00
Ryan Mulligan
a9358e80fc discourseAllPlugins: init discourse-migratepassword
(cherry picked from commit 85d7eb75c9)
2021-08-17 23:12:33 +02:00
Ryan Mulligan
d0064e3868 discourseAllPlugins: init discourse-data-explorer
(cherry picked from commit 601db31c26)
2021-08-17 23:12:28 +02:00
Ryan Mulligan
3c3cd97025 discourseAllPlugins: init discourse-checklist
(cherry picked from commit eb02dc0c4a)
2021-08-17 23:12:19 +02:00
Joachim Breitner
e628ab6544 listadmin: init at 2.73
fixes #133239

(cherry picked from commit 53fc34dcf0)
2021-08-17 22:36:03 +02:00
Michael Raskin
97c5d0cbe7 Merge pull request #134504 from NixOS/backport-134493-to-release-21.05
[Backport release-21.05] monotone: fix key encryption
2021-08-17 18:44:23 +00:00
Michael Raskin
f037cc9ff4 monotone: fix key encryption
(cherry picked from commit 5dd7c7a079)
2021-08-17 18:02:17 +00:00
Sumner Evans
5ad7e84023 element-{web,desktop}: 1.7.34 -> 1.8.1
(cherry picked from commit dba043d448)
2021-08-17 17:07:26 +00:00
github-actions[bot]
c1e5f0fe3c Merge staging-next-21.05 into staging-21.05 2021-08-17 12:03:22 +00:00
github-actions[bot]
98c6091c14 Merge release-21.05 into staging-next-21.05 2021-08-17 12:02:47 +00:00
Michael Weiss
587b190c8a chromium: 92.0.4515.131 -> 92.0.4515.159
https://chromereleases.googleblog.com/2021/08/stable-channel-update-for-desktop.html

This update includes 9 security fixes.

CVEs:
CVE-2021-30598 CVE-2021-30599 CVE-2021-30600 CVE-2021-30601
CVE-2021-30602 CVE-2021-30603 CVE-2021-30604

(cherry picked from commit 1c476a2b6d)
2021-08-17 08:55:42 +00:00
Jörg Thalheim
8c3b502c7c Merge pull request #134406 from NixOS/backport-134340-to-release-21.05
[Backport release-21.05] nixos: fix release notes about linux_latest version
2021-08-17 08:28:55 +01:00
Jörg Thalheim
dad2c73c36 Merge pull request #134405 from NixOS/backport-134402-to-release-21.05
[Backport release-21.05] nixos-generators: 1.3.0 -> 1.4.0
2021-08-17 08:28:22 +01:00
Bjørn Forsman
991e12bfdb nixos: fix release notes about linux_latest version
It's version 5.13, not 5.12.

(cherry picked from commit a37965f7c5)
2021-08-17 07:12:42 +00:00
lassulus
05e6f69901 nixos-generators: 1.3.0 -> 1.4.0
(cherry picked from commit e701bc3bfb)
2021-08-17 07:04:35 +00:00
github-actions[bot]
95dde93451 Merge staging-next-21.05 into staging-21.05 2021-08-17 06:03:01 +00:00
github-actions[bot]
c3f08e6146 Merge release-21.05 into staging-next-21.05 2021-08-17 06:02:28 +00:00
github-actions[bot]
8ac4e2037a drawpile,drawpile-server-headless: 2.1.17 -> 2.1.19
(cherry picked from commit 5919a42546)
2021-08-16 21:54:13 -04:00
github-actions[bot]
1220237519 Merge staging-next-21.05 into staging-21.05 2021-08-17 00:03:42 +00:00
github-actions[bot]
444e630f23 Merge release-21.05 into staging-next-21.05 2021-08-17 00:02:41 +00:00
Michael Weiss
543d4ecac2 Merge pull request #134200 from primeos/security-backports-for-21.05
[21.05] glances: 3.1.7 -> 3.2.3
2021-08-16 22:36:55 +02:00
Robert Scott
6d41a79a0e Merge pull request #134013 from NixOS/backport-131867-to-release-21.05
[Backport release-21.05] traefik: 2.4.8 -> 2.4.13
2021-08-16 20:40:19 +01:00
Robert Scott
c44b9fa44b Merge pull request #134083 from NixOS/backport-134001-to-release-21.05
[Backport release-21.05] redmine: 4.2.1 -> 4.2.2
2021-08-16 20:39:41 +01:00
Maximilian Bosch
268946d9ca matrix-synapse: fix startup
(cherry picked from commit 5a01d3ac1f)
2021-08-16 19:15:37 +00:00
Maximilian Bosch
2a18679767 Revert "matrix-synapse: fix homeserver script"
This reverts commit 4444860f07.

(cherry picked from commit 21eb8c5b37)
2021-08-16 19:15:36 +00:00
Sumner Evans
11cb4d0680 matrix-synapse: fix homeserver script
(cherry picked from commit 4444860f07)
2021-08-16 19:15:36 +00:00
Sumner Evans
1948243193 matrix-synapse: 1.39.0 -> 1.40.0
(cherry picked from commit 6f434ed48c)
2021-08-16 19:15:35 +00:00
Maximilian Bosch
94c989365d Merge pull request #134297 from NixOS/backport-134205-to-release-21.05
[Backport release-21.05] Kernels 2021-08-15
2021-08-16 20:48:48 +02:00
Robert Scott
9c7404d96f Merge pull request #134004 from NixOS/backport-132689-to-staging-21.05
[Backport staging-21.05] libsndfile: 1.0.30 -> 1.0.31
2021-08-16 19:12:29 +01:00
github-actions[bot]
0d8777fc55 Merge staging-next-21.05 into staging-21.05 2021-08-16 18:02:59 +00:00
github-actions[bot]
62d737b061 Merge release-21.05 into staging-next-21.05 2021-08-16 18:02:26 +00:00
Bernardo Meurer
8f311b4f5e Merge pull request #134291 from yu-re-ka/feature/21-05-thunderbird-91
[21.05] thunderbird-91: init at 91.0
2021-08-16 17:02:29 +00:00
Jörg Thalheim
e81def80a4 Merge pull request #134308 from NixOS/backport-121693-to-release-21.05
[Backport release-21.05] llvm_11: disable failing 'dependent-libraries.test' on armv7l
2021-08-16 15:47:23 +01:00
github-actions[bot]
62750a0b34 Merge staging-next-21.05 into staging-21.05 2021-08-16 12:04:20 +00:00
github-actions[bot]
0f0eda905a Merge release-21.05 into staging-next-21.05 2021-08-16 12:03:37 +00:00
misuzu
49f3fda496 llvm_11: disable failing 'dependent-libraries.test' on armv7l
(cherry picked from commit 23ab123640)
2021-08-16 10:39:28 +00:00
Samuel Rivas
b3743e6325 haskellPackages.readline: fix Setup.hs to work with Cabal 3
See https://github.com/NixOS/nixpkgs/pull/111985/ for previous discussion

(cherry picked from commit b950ecaf3a49662ba92e6c978aa472155eddd47f)
2021-08-16 12:12:46 +02:00
Antonio Yang
a54234df3a gitui: 0.15.0 -> 0.16.0
(cherry picked from commit a8daff8b1a)
2021-08-16 09:19:12 +00:00
TredwellGit
aa1af91878 linux_5_12: remove
https://lwn.net/ml/linux-kernel/1626791065147152@kroah.com/
(cherry picked from commit 957f0485da)
2021-08-16 09:12:57 +00:00
TredwellGit
b77e4da370 linux: 5.13.10 -> 5.13.11
(cherry picked from commit f2e78916b9)
2021-08-16 09:11:43 +00:00
TredwellGit
52d43e083d linux: 4.9.279 -> 4.9.280
(cherry picked from commit 9e9933a76b)
2021-08-16 09:11:43 +00:00
TredwellGit
68e1d642c9 linux: 4.4.280 -> 4.4.281
(cherry picked from commit 039764362b)
2021-08-16 09:11:42 +00:00
Maximilian Bosch
5d89a1188e Merge pull request #133640 from NixOS/backport-133627-to-release-21.05
[Backport release-21.05] Kernels 2021-08-12
2021-08-16 11:07:50 +02:00
Yureka
c9f62c7d3e thunderbird-91: init at 91.0 2021-08-16 09:14:54 +02:00
Martin Weinelt
59838d6ce0 c-ares: 1.17.1 -> 1.17.2
(cherry picked from commit fe7d21caf21c8a8f864a1dc94ba6324cd2175fc4)
2021-08-16 01:28:43 +00:00
github-actions[bot]
b21d979cd5 Merge staging-next-21.05 into staging-21.05 2021-08-16 00:03:16 +00:00
github-actions[bot]
4ae23495c2 Merge release-21.05 into staging-next-21.05 2021-08-16 00:02:45 +00:00
Florian Klink
46cc7df0bb Merge pull request #134026 from NixOS/backport-133718-to-release-21.05
[Backport release-21.05] python38Packages.authlib: 0.15.3 -> 0.15.4
2021-08-15 22:07:47 +02:00
Robert Scott
7b11c26712 ndpi: add patch for CVE-2021-36082 2021-08-15 19:11:48 +01:00
github-actions[bot]
deda3ec7f3 Merge staging-next-21.05 into staging-21.05 2021-08-15 18:02:37 +00:00
github-actions[bot]
bab396e579 Merge release-21.05 into staging-next-21.05 2021-08-15 18:02:05 +00:00
R. RyanTM
a49928582f postsrsd: 1.10 -> 1.11
(cherry picked from commit 6c81f56887)
2021-08-15 15:03:00 +00:00
R. RyanTM
fc893e1176 glances: 3.2.2 -> 3.2.3
(cherry picked from commit 98d8f2e8fe)
2021-08-15 15:21:51 +02:00
R. RyanTM
aafca18a5c glances: 3.2.1 -> 3.2.2
(cherry picked from commit f1561b7f4d)
2021-08-15 15:21:50 +02:00
Michael Weiss
3c9c1bc642 glances: 3.2.0 -> 3.2.1
(cherry picked from commit c05bef5bc5)
2021-08-15 15:21:49 +02:00
Michael Weiss
09e9715cc0 glances: 3.1.7 -> 3.2.0
(cherry picked from commit 035ba51146)
2021-08-15 15:21:48 +02:00
ajs124
8ac785da98 Merge pull request #134074 from helsinki-systems/upd/claws-mail-2105
claws-mail: 3.17.8 -> 3.18.0, 3.99.0 -> 4.0.0
2021-08-15 15:17:23 +02:00
Aaron Andersen
ee2569ff54 redmine: 4.2.1 -> 4.2.2
(cherry picked from commit 23c541189c)
2021-08-15 00:27:07 +00:00
Alvar Penning
1bc92c1ba2 claws-mail: 3.17.8 -> 4.0.0
With Claws Mail's latest double release of 3.18.0 and 4.0.0, the package
will refer to the more "modern" GTK+ 3 release, major version four. The
GTK+ 2 release, major version 3, is now available in the
`claws-mail-gtk2` package.

In other words, this commit bumps the GTK+ 2 version from 3.17.8 to
3.18.0, the previously unstable GTK+ 3 version 3.99.0 to 4.0.0 and
changes the default to GTK+ 3.

(cherry picked from commit 26f52bf6b5)
2021-08-14 23:51:02 +02:00
Robert Scott
61a9a2d6d7 openvswitch: add patch for CVE-2021-36980 2021-08-14 22:26:16 +01:00
Michael Raskin
a299d9db22 Merge pull request #133841 from rb2k/gtk_patch_21_05
[21.05] gtk3: replace bugzilla patch with local file.
2021-08-14 20:21:52 +00:00
github-actions[bot]
683ece44f8 Merge staging-next-21.05 into staging-21.05 2021-08-14 18:02:44 +00:00
github-actions[bot]
18261d032e Merge release-21.05 into staging-next-21.05 2021-08-14 18:02:12 +00:00
R. RyanTM
d273ad0310 folly: 2021.01.25.00 -> 2021.08.02.00
(cherry picked from commit 34892123a4)
2021-08-14 17:22:58 +00:00
R. RyanTM
58baeceeae python38Packages.authlib: 0.15.3 -> 0.15.4
(cherry picked from commit 87bfa2b709)
2021-08-14 14:19:39 +00:00
Luke Granger-Brown
4d5716f0f8 Merge pull request #134011 from NixOS/backport-133009-to-release-21.05
[Backport release-21.05] asterisk: 13.38.2 -> 13.38.3, 16.17.0 -> 16.19.1, 17.9.3 -> 17.9.4, 18.3.0 -> 18.5.1
2021-08-14 14:44:20 +01:00
Maxine Aubrey
a657d429c9 nixos/traefik: wait for first success
possible fix for #115418

(cherry picked from commit 34add8ca59)
2021-08-14 13:11:54 +00:00
Maxine Aubrey
5ae7f11e35 traefik: 2.4.8 -> 2.4.13
(cherry picked from commit 4a97603613)
2021-08-14 13:11:54 +00:00
Yorick van Pelt
a8a96f20e6 asterisk: fix missing newline in json
(cherry picked from commit 823ac16450)
2021-08-14 13:02:03 +00:00
Yorick van Pelt
67ca9c8126 asterisk: 13.38.2 -> 13.38.3, 16.17.0 -> 16.19.1, 17.9.3 -> 17.9.4, 18.3.0 -> 18.5.1
auto-updated using ./update.py

(cherry picked from commit 8d53c9c4e6)
2021-08-14 13:02:03 +00:00
Yorick van Pelt
21047ba83f asterisk: add update script
(cherry picked from commit ab3980e73a)
2021-08-14 13:02:03 +00:00
Thomas Gerbet
c39b79e047 libsndfile: 1.0.30 -> 1.0.31
Fixes CVE-2021-3246.

https://github.com/libsndfile/libsndfile/releases/tag/1.0.31
(cherry picked from commit 88c53421a7)
2021-08-14 12:17:12 +00:00
github-actions[bot]
d54801368d Merge staging-next-21.05 into staging-21.05 2021-08-14 12:06:13 +00:00
github-actions[bot]
8e45c4e6e1 Merge release-21.05 into staging-next-21.05 2021-08-14 12:02:52 +00:00
Michael Weiss
ca084144c6 Merge pull request #133986 from NixOS/backport-133938-to-release-21.05
[Backport release-21.05] signal-desktop: 5.13.0 -> 5.13.1
2021-08-14 13:31:59 +02:00
Michael Weiss
0f09ebb8a2 signal-desktop: 5.13.0 -> 5.13.1
(cherry picked from commit 759dd3036f)
2021-08-14 11:13:26 +00:00
Marc Seeger
c752f9e15d [21.05] gtk3: replace bugzilla patch with local file. 2021-08-13 15:56:18 -07:00
Wael M. Nasreddine
0088f5fa6d openjdk11: fix the share/man symlink on darwin
(cherry picked from commit 8dcfd8f20a)
2021-08-13 20:21:03 +00:00
github-actions[bot]
37c6e07f24 Merge staging-next-21.05 into staging-21.05 2021-08-13 18:03:01 +00:00
github-actions[bot]
502ca77191 Merge release-21.05 into staging-next-21.05 2021-08-13 18:02:26 +00:00
Artturi
a445f58298 Merge pull request #133654 from Artturin/backport-130515 2021-08-13 17:33:30 +03:00
github-actions[bot]
fd0ab00ca0 Merge staging-next-21.05 into staging-21.05 2021-08-13 12:03:03 +00:00
github-actions[bot]
aba2b21a65 Merge release-21.05 into staging-next-21.05 2021-08-13 12:02:30 +00:00
Michael Raskin
5ece35e8b4 Merge pull request #133748 from NixOS/backport-133619-to-release-21.05
[Backport release-21.05] liberation-circuit: init at 1.3
2021-08-13 11:47:18 +00:00
Angus Trau
c21331c85e liberation-circuit: init at 1.3
(cherry picked from commit 005f28eca8)
2021-08-13 11:09:53 +00:00
Angus Trau
8f3bacf3d9 allegro5: fix native dialog addon
(cherry picked from commit 72cfa909f4)
2021-08-13 11:09:52 +00:00
github-actions[bot]
e308a26a04 Merge staging-next-21.05 into staging-21.05 2021-08-13 00:03:10 +00:00
github-actions[bot]
852906c677 Merge release-21.05 into staging-next-21.05 2021-08-13 00:02:35 +00:00
Artturi
6de09630fb Merge pull request #133682 from NixOS/backport-133666-to-release-21.05
[Backport release-21.05] nomacs: fix animated WebP support
2021-08-13 02:55:54 +03:00
Timothy DeHerrera
3222d2415c Merge pull request #133684 from NixOS/backport-133678-to-release-21.05
[Backport release-21.05] signal-desktop: 5.12.2 -> 5.13.0
2021-08-12 16:35:36 -06:00
Michael Weiss
920934d188 signal-desktop: 5.12.2 -> 5.13.0
(cherry picked from commit 31a1875106)
2021-08-12 21:56:27 +00:00
TredwellGit
d64de005c0 nomacs: fix animated WebP support
(cherry picked from commit e7e995ec2f)
2021-08-12 21:54:18 +00:00
Artturi
7bd542a5e9 Merge pull request #133563 from NixOS/backport-133204-to-release-21.05
[Backport release-21.05] nixos/xserver: fix a display-manager race condition
2021-08-13 00:32:27 +03:00
Artturi
63eb5399c8 Merge pull request #133642 from NixOS/backport-133304-to-release-21.05
[Backport release-21.05] nixos/gdm: disable the gdm services as it is redundant
2021-08-13 00:31:57 +03:00
Artturi
3376676de0 Merge pull request #133171 from NixOS/backport-127493-to-release-21.05
[Backport release-21.05] gnomeExtensions.gsconnect: 46 -> 47
2021-08-13 00:07:33 +03:00
Ivan Malison
54b8add427 git-sync: unstable-2015-10-24 -> unstable-2021-07-14 (#130306)
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
2021-08-12 22:04:27 +03:00
Jörg Thalheim
ff0fa55543 git-sync: use postFixup instead of fixupPhase
(cherry picked from commit d804b24b6be14c2d264b7381e32d02401fef3327)
2021-08-12 22:04:24 +03:00
Ivan Malison
ef37ea7fe8 git-sync: Wrap both binaries
(cherry picked from commit 633993eee29d4a0092ea12b58741c108718a7308)
2021-08-12 22:04:20 +03:00
Artturi
a996e2ce32 Merge pull request #133590 from NixOS/backport-133456-to-release-21.05 2021-08-12 21:50:00 +03:00
Artturi
c20adcfd62 Merge pull request #133630 from NixOS/backport-133398-to-release-21.05
[Backport release-21.05] zoom-us: Do not apply screen scaling twice
2021-08-12 21:48:26 +03:00
github-actions[bot]
09a4e06850 Merge staging-next-21.05 into staging-21.05 2021-08-12 18:02:57 +00:00
github-actions[bot]
0d050f6b48 Merge release-21.05 into staging-next-21.05 2021-08-12 18:02:25 +00:00
Artturin
2fac4b6d00 nixos/gdm: disable the gdm services as it is redundant
and causes issues

(cherry picked from commit 47f6591706)
2021-08-12 17:44:00 +00:00
TredwellGit
1cd2856e04 linux-rt_5_4: 5.4.129-rt61 -> 5.4.138-rt62
(cherry picked from commit 89a50ded98)
2021-08-12 17:27:20 +00:00
TredwellGit
08b33c754d linux: 5.13.9 -> 5.13.10
(cherry picked from commit ff1408d8b0)
2021-08-12 17:27:20 +00:00
TredwellGit
ad40c4059c linux: 4.4.279 -> 4.4.280
(cherry picked from commit 20ed07939e)
2021-08-12 17:27:19 +00:00
Thomas Tuegel
7aa7a4dcae zoom-us: Do not apply screen scaling twice
(cherry picked from commit 445f8c544c)
2021-08-12 16:01:35 +00:00
Martin Weinelt
ad6e733d63 Merge pull request #133613 from NixOS/backport-133571-to-release-21.05
[Backport release-21.05] firefox: fix enableOfficialBranding
2021-08-12 15:48:50 +02:00
Sean Buckley
8139ad25a3 firefox: fix enableOfficialBranding
(cherry picked from commit 9290873838)
2021-08-12 11:04:07 +00:00
taku0
df5b7b3312 thunderbird-bin: 78.12.0 -> 78.13.0
(cherry picked from commit 676a38befc)
2021-08-12 06:40:08 +00:00
taku0
9d123427c9 thunderbird-bin: fix parameter of updateScript
(cherry picked from commit df5e0bb678)
2021-08-12 06:40:08 +00:00
taku0
a8de6d1fdc thunderbird: 78.12.0 -> 78.13.0
(cherry picked from commit 13a68b47c4)
2021-08-12 06:40:07 +00:00
github-actions[bot]
b6f18f52d2 Merge staging-next-21.05 into staging-21.05 2021-08-12 06:02:37 +00:00
github-actions[bot]
31e10ca1aa Merge release-21.05 into staging-next-21.05 2021-08-12 06:02:06 +00:00
Artturi
ae9890eb6a Merge pull request #131926 from NixOS/backport-131609-to-staging-21.05
[Backport staging-21.05] aspell: fix buffer overflow in objstack
2021-08-12 05:01:36 +03:00
Artturi
e14fad1ad5 Merge pull request #133526 from NixOS/backport-133286-to-release-21.05
[Backport release-21.05] linux_zen: 5.13.7 -> 5.13.9
2021-08-12 04:59:04 +03:00
Artturi
76f688cc39 Merge pull request #127360 from NixOS/backport-127335-to-release-21.05 2021-08-12 04:49:40 +03:00
Artturi
1f9945566e Merge pull request #133524 from NixOS/backport-133502-to-release-21.05
[Backport release-21.05] fwupd: 1.5.7 -> 1.5.12
2021-08-12 04:47:28 +03:00
Artturi
b684f30fd3 Merge pull request #133477 from NixOS/backport-133462-to-release-21.05
[Backport release-21.05] sparse: add perl to buildInputs
2021-08-12 04:44:55 +03:00
Artturi
b6f76e22d7 Merge pull request #133564 from NixOS/backport-133528-to-release-21.05
[Backport release-21.05] libspf2: Fix CVE-2021-20314
2021-08-12 04:43:14 +03:00
Janne Heß
2fd6748972 libspf2: Fix CVE-2021-20314
There is no new release yet (see mailing list post on oss-security), so
I'm picking the commit that fixes the CVE.

There is another security flaw (without a CVE number) that is also
mentioned in the oss-security announcement but it is not explained which
commit patches the problem.

(cherry picked from commit 46b7a5be1c)
2021-08-12 00:43:36 +00:00
Johannes Arnold
8404ac09e7 nixos/xserver: fix a display-manager race condition
(cherry picked from commit 358ab44a45)
2021-08-12 00:40:15 +00:00
github-actions[bot]
fd0652d86a Merge staging-next-21.05 into staging-21.05 2021-08-12 00:03:19 +00:00
github-actions[bot]
275de75c6b Merge release-21.05 into staging-next-21.05 2021-08-12 00:02:45 +00:00
Mario Rodas
dc9e1a31fb nodejs-16_x: 16.6.1 -> 16.6.2
https://github.com/nodejs/node/releases/tag/v16.6.2
(cherry picked from commit 898660842e)
2021-08-11 19:02:00 -05:00
Sandro
658f8be372 Merge pull request #133548 from angustrau/backport-maintainer 2021-08-11 23:52:18 +02:00
Angus Trau
27d72aa5fa maintainers: add angustrau 2021-08-12 07:21:13 +10:00
Aaron Andersen
8df67e7b59 Merge pull request #133506 from NixOS/backport-133499-to-release-21.05
[Backport release-21.05] apacheHttpdPackages.mod_auth_mellon: 0.17.0 -> 0.18.0
2021-08-11 14:42:12 -04:00
github-actions[bot]
56c80ce384 Merge staging-next-21.05 into staging-21.05 2021-08-11 18:02:58 +00:00
github-actions[bot]
af7ef2e741 Merge release-21.05 into staging-next-21.05 2021-08-11 18:02:24 +00:00
Roman Volosatovs
9485d3ab3b linux_zen: 5.13.7 -> 5.13.9
(cherry picked from commit a9bf9c44e5)
2021-08-11 16:55:23 +00:00
Atemu
ae3a8da8d3 linux_lqx: 5.12.19 -> 5.13.9
(cherry picked from commit 2aaf41173d)
2021-08-11 16:52:08 +00:00
Maxine Aubrey
2f24078a01 fwupd: 1.5.7 -> 1.5.12
- https://github.com/fwupd/fwupd/releases/tag/1.5.8
- https://github.com/fwupd/fwupd/releases/tag/1.5.9
- https://github.com/fwupd/fwupd/releases/tag/1.5.10
- https://github.com/fwupd/fwupd/releases/tag/1.5.11
- https://github.com/fwupd/fwupd/releases/tag/1.5.12

(cherry picked from commit 2f3e3c788e)
2021-08-11 16:28:42 +00:00
Timothy DeHerrera
927ce1afc1 Merge pull request #133518 from NixOS/backport-133482-to-release-21.05
[Backport release-21.05] hydra-unstable: add missing perl deps
2021-08-11 09:46:16 -06:00
Timothy DeHerrera
dca7265b6d Merge pull request #133519 from NixOS/backport-132739-to-release-21.05
[Backport release-21.05] nixUnstable: 2.4pre20210707_02dd6bb -> 2.4pre20210802_47e96bb
2021-08-11 09:46:03 -06:00
happysalada
e6591fd024 hydra-unstable: 2021-05-03 -> 2021-08-11
(cherry picked from commit 25722c43d12b2331676157ee5e9247f21c436000)
2021-08-11 15:35:11 +00:00
happysalada
1d182a795d nixUnstable: 2.4pre20210707_02dd6bb -> 2.4pre20210802_47e96bb
(cherry picked from commit f578589a2ba19a17f468dba84a7b2e14b91d3a6e)
2021-08-11 15:35:11 +00:00
Maximilian Bosch
8e23fff674 perlPackages: update newly introduced libraries for catalyst-prometheus to latest versions
* CatalystPluginPrometheusTiny: 0.005 -> 0.006
* PrometheusTiny: 0.007 -> 0.008
* PrometheusTinyShared: 0.023 -> 0.024

Co-authored-by: Stig <stig@stig.io>
(cherry picked from commit 94a5b4ecf7)
2021-08-11 15:35:06 +00:00
Maximilian Bosch
7742dc6e0e hydra-unstable: add missing perl deps
(cherry picked from commit 9c6dc5d264)
2021-08-11 15:35:06 +00:00
Maximilian Bosch
f251b6b264 perlPackages/CatalystPluginPrometheusTiny: init at 0.005
(cherry picked from commit c0bc42310b)
2021-08-11 15:35:05 +00:00
sternenseemann
f6551e1efa clojure: fix clj script
At some point the clj script stopped just calling clojure, but instead
$bin_dir/clojure. As a result we now need to additionally substitute
BINDIR in the clj script.
2021-08-11 15:43:58 +02:00
Aaron Andersen
cc07aecb10 apacheHttpdPackages.mod_auth_mellon: 0.17.0 -> 0.18.0
(cherry picked from commit 3f4692120b)
2021-08-11 13:35:20 +00:00
github-actions[bot]
40bd2e2f24 Merge staging-next-21.05 into staging-21.05 2021-08-11 12:02:49 +00:00
github-actions[bot]
d67e6cf39a Merge release-21.05 into staging-next-21.05 2021-08-11 12:02:14 +00:00
Niklas Hambüchen
2da6605a52 Merge pull request #133468 from rski/release-21.05
CONTRIBUTING.md: Move to repo root, where it is more visible.
2021-08-11 14:01:51 +02:00
Emil Karlson
8ad9b064fd sparse: add perl to buildInputs
cgcc command has shebang of /usr/bin/perl, which obviously does not
work for nixos, adding perl to buildInputs seems to make all the magic
happen, as per usual.

(cherry picked from commit e7836bc5a5)
2021-08-11 08:13:43 +00:00
Niklas Hambüchen
d76b42c680 CONTRIBUTING.md: Move to repo root, where it is more visible.
We found that many users found it difficult to locate this document.

Github supports it in the root, see:
https://docs.github.com/en/communities/setting-up-your-project-for-healthy-contributions/setting-guidelines-for-repository-contributors

(cherry picked from commit 3c29ced243)

This fixes the links on the nixos.org website, the stable branch
docs point to master on github, so both master and the release branch
need to have the file in the same location.

fixes https://github.com/NixOS/nixos-homepage/issues/736
2021-08-11 09:42:10 +03:00
github-actions[bot]
87eac968ec Merge staging-next-21.05 into staging-21.05 2021-08-10 18:03:15 +00:00
github-actions[bot]
28cf122744 Merge release-21.05 into staging-next-21.05 2021-08-10 18:02:38 +00:00
Martin Weinelt
2d6ab6c6b9 Merge pull request #133390 from NixOS/backport-133388-to-release-21.05 2021-08-10 17:01:02 +02:00
Vladimír Čunát
5cd415124f nixos/tests: unbreak the tested job
I expect it suffices that the channel only blocks on one firefox ESR
test - the one for the default ESR.  I didn't want to have the
information about the default in two places, so either of the tests will
be evaluated twice (but to the same *.drv I hope).

(cherry picked from commit c0097aa84a)
2021-08-10 14:34:09 +00:00
Martin Weinelt
ca4d6bc0e1 Merge pull request #133367 from NixOS/backport-133216-to-release-21.05
[Backport release-21.05] gpsd: 3.22 -> 3.23
2021-08-10 15:04:03 +02:00
TredwellGit
0701d20ed9 electron_12: 12.0.15 -> 12.0.16
https://github.com/electron/electron/releases/tag/v12.0.16
(cherry picked from commit 4f7a4bd0fe)
2021-08-10 13:45:34 +01:00
TredwellGit
821a567bf8 electron_11: 11.4.10 -> 11.4.11
https://github.com/electron/electron/releases/tag/v11.4.11
(cherry picked from commit 79744f0ea0)
2021-08-10 13:44:52 +01:00
R. RyanTM
bb5548940e gpsd: 3.22 -> 3.23
Clean up unnecessary dependencies, update license. Add todo to generate
asciidoctor documentation.

(cherry picked from commit 65db4268d0)
2021-08-10 12:18:35 +00:00
github-actions[bot]
fb75bb0676 Merge staging-next-21.05 into staging-21.05 2021-08-10 12:06:39 +00:00
Vladimír Čunát
b43522a1f5 Merge #132834: go security bumps (into release-21.05) 2021-08-10 14:04:13 +02:00
github-actions[bot]
167e69e157 Merge release-21.05 into staging-next-21.05 2021-08-10 12:03:42 +00:00
Vladimír Čunát
923725473a Merge branch 'staging-next-21.05' into release-21.05
https://hydra.nixos.org/eval/1694658
2021-08-10 14:02:40 +02:00
Martin Weinelt
786e450930 nss_latest: 3.67 -> 3.68 2021-08-10 12:34:47 +02:00
Martin Weinelt
4012d5b533 firefox: use nspr_latest for 91 and later 2021-08-10 12:31:10 +02:00
Martin Weinelt
fe2138efeb nspr_latest: init at 4.32 2021-08-10 12:27:57 +02:00
Maciej Krüger
8808f27a6b Merge pull request #133330 from NixOS/backport-132878-to-release-21.05
[Backport release-21.05] gitea: 1.14.5 -> 1.14.6
2021-08-10 10:47:43 +02:00
Maximilian Bosch
20f400d745 gitea: 1.14.5 -> 1.14.6
ChangeLog: https://github.com/go-gitea/gitea/releases/tag/v1.14.6
(cherry picked from commit b15a7c718e)
2021-08-10 08:24:23 +00:00
github-actions[bot]
bf36f6b818 Merge staging-next-21.05 into staging-21.05 2021-08-10 06:03:32 +00:00
github-actions[bot]
3ecc0d7b58 Merge release-21.05 into staging-next-21.05 2021-08-10 06:02:28 +00:00
Martin Weinelt
855adf3d0a firefox-bin: 90.0.2 -> 91.0
(cherry picked from commit cae3d9fff46c6cc0de8bea56dee45d07b0d773f8)
2021-08-10 14:54:58 +09:00
Martin Weinelt
6c6d0f971f firefox-esr-91: init at 91.0esr
(cherry picked from commit d5f7fc95a9ec5798618d10fd04a3ef91aa08de76)
2021-08-10 14:54:58 +09:00
Martin Weinelt
ae16816ff5 firefox: 90.0.2 -> 91.0
(cherry picked from commit e5c09425317c1df3457e23f1475f82949fdf6781)
2021-08-10 14:54:58 +09:00
Artturi
9eb3be2890 Merge pull request #131553 from fgaz/backport/21.05/warzone2100/4.1.1 2021-08-10 05:47:23 +03:00
github-actions[bot]
af54073773 Merge staging-next-21.05 into staging-21.05 2021-08-09 18:02:45 +00:00
github-actions[bot]
ab6e8b0faa Merge release-21.05 into staging-next-21.05 2021-08-09 18:02:12 +00:00
Jonathan Ringer
b09c989b82 nomad-autoscaler: init at 0.3.3
(cherry picked from commit b432c3ca0d)
2021-08-09 08:34:54 -07:00
Martin Weinelt
23d5366206 Merge pull request #129436 from NixOS/backport-121750-to-release-21.05
[Backport release-21.05] nixos/acme: Ensure certs are always protected
2021-08-09 16:15:37 +02:00
Martin Weinelt
51e3908199 Merge pull request #133173 from risicle/ris-tor-0.4.5.9-r21.05
[21.05] tor: 0.4.5.7 -> 0.4.5.9
2021-08-09 16:12:02 +02:00
Martin Weinelt
72288487d9 Merge pull request #133154 from risicle/ris-wolfssl-CVE-2021-37155-r21.05
[21.05] wolfssl: add patches for CVE-2021-37155
2021-08-09 16:09:19 +02:00
Martin Weinelt
eb3091ac76 cpython: fix permissions on venv activation scripts
Previously these ended up without u+w permissions which meant they could
not be regenerated, which was hugely annoying when these venvs were for
example created and recreated in a nix-shell.

(cherry picked from commit 4fa69858d9)
2021-08-09 15:43:21 +02:00
github-actions[bot]
840f8cc3b2 Merge staging-next-21.05 into staging-21.05 2021-08-09 12:03:20 +00:00
github-actions[bot]
7d8133e751 Merge release-21.05 into staging-next-21.05 2021-08-09 12:02:40 +00:00
Martin Weinelt
d1a75c3c1d python310: 3.10.0b3 -> 3.10.0rc1
(cherry picked from commit ebc4dae8cb)
2021-08-09 13:39:04 +02:00
Martin Weinelt
98163bd246 python37: 3.7.10 -> 3.7.11
(cherry picked from commit b322c5ecaa)
2021-08-09 13:38:38 +02:00
Martin Weinelt
d7b9ef367f python36: 3.6.13 -> 3.6.14
(cherry picked from commit e1e245f203)
2021-08-09 13:38:32 +02:00
Martin Weinelt
de46e983af python39: 3.9.5 -> 3.9.6
(cherry picked from commit 360c50f11d)
2021-08-09 13:38:22 +02:00
Martin Weinelt
4c5903aabe python38: 3.8.10 -> 3.8.11
(cherry picked from commit 250f0514f2)
2021-08-09 13:37:00 +02:00
Martin Weinelt
ec7dfbf84b python310: 3.10.0a5 -> 3.10.0b3
(cherry picked from commit bb696403b0)
2021-08-09 13:36:46 +02:00
Martin Weinelt
d8fa6239c7 python39: 3.9.4 -> 3.9.5
(cherry picked from commit 7ca18ab93f)
2021-08-09 13:36:40 +02:00
Martin Weinelt
02e3a73813 python38: 3.8.9 -> 3.8.10
(cherry picked from commit 3898eb1897)
2021-08-09 13:36:35 +02:00
Martin Weinelt
fadca09121 Merge pull request #133213 from NixOS/backport-133200-to-release-21.05 2021-08-09 13:32:35 +02:00
upkeep-bot
5f177fef48 vscodium: 1.58.2 -> 1.59.0
(cherry picked from commit 4de2fe7518d594a681152c446f9e5bd064de99ea)
2021-08-09 17:05:47 +09:00
TredwellGit
295b867eb7 linux/hardened/patches/5.4: 5.4.134-hardened1 -> 5.4.139-hardened1
(cherry picked from commit cbb5ca89ca)
2021-08-09 02:52:56 +00:00
TredwellGit
bb8734ccd6 linux/hardened/patches/5.10: 5.10.52-hardened1 -> 5.10.57-hardened1
(cherry picked from commit 7aae6061b6)
2021-08-09 02:52:55 +00:00
TredwellGit
b96d4ac43a linux/hardened/patches/4.19: 4.19.198-hardened1 -> 4.19.202-hardened1
(cherry picked from commit 0a41183454)
2021-08-09 02:52:55 +00:00
TredwellGit
e3c440a92b linux/hardened/patches/4.14: 4.14.240-hardened1 -> 4.14.243-hardened1
(cherry picked from commit b84eecf9fc)
2021-08-09 02:52:54 +00:00
TredwellGit
d6ebcc1109 linux-rt_5_10: 5.10.52-rt47 -> 5.10.56-rt48
(cherry picked from commit 8425e47a74)
2021-08-09 02:52:54 +00:00
TredwellGit
e80cfad9f9 linux: 5.4.134 -> 5.4.139
(cherry picked from commit b570def284)
2021-08-09 02:52:53 +00:00
TredwellGit
86cdede3f8 linux: 5.13.8 -> 5.13.9
(cherry picked from commit d416101b65)
2021-08-09 02:52:53 +00:00
TredwellGit
e9d400d134 linux: 5.10.52 -> 5.10.57
(cherry picked from commit cde6046992)
2021-08-09 02:52:52 +00:00
TredwellGit
9f9dc1688f linux: 4.9.278 -> 4.9.279
(cherry picked from commit a5713826c4)
2021-08-09 02:52:52 +00:00
TredwellGit
59bacd23a6 linux: 4.4.278 -> 4.4.279
(cherry picked from commit 1adb289851)
2021-08-09 02:52:51 +00:00
TredwellGit
000622e70a linux: 4.19.198 -> 4.19.202
(cherry picked from commit 553c6ef12a)
2021-08-09 02:52:51 +00:00
TredwellGit
6f1bdd343d linux: 4.14.240 -> 4.14.243
(cherry picked from commit 26ec7c39bb)
2021-08-09 02:52:50 +00:00
github-actions[bot]
be1b94ec70 Merge staging-next-21.05 into staging-21.05 2021-08-09 00:03:33 +00:00
github-actions[bot]
444dac9eaf Merge release-21.05 into staging-next-21.05 2021-08-09 00:02:48 +00:00
Artturi
9d5f7324c2 Merge pull request #131554 from NixOS/backport-127875-to-release-21.05
[Backport release-21.05] binutils: apply R_ARM_COPY.patch only when cross-compiling to armv7l
2021-08-09 01:11:30 +03:00
Domen Kožar
8485c05212 Merge pull request #133116 from NixOS/pipewire-21.05-backport
Pipewire 21.05 backport: 0.3.30 -> 0.3.33
2021-08-08 23:15:18 +02:00
Ilan Joselevich
3ca9226b93 maintainers: add kranzes
(cherry picked from commit dff520a9e0)
Signed-off-by: Domen Kožar <domen@dev.si>
2021-08-08 22:08:56 +02:00
Ilan Joselevich
45ea565f6d pipewire: updated JSON configs
(cherry picked from commit a876500f5d)
Signed-off-by: Domen Kožar <domen@dev.si>
2021-08-08 21:56:57 +02:00
Ilan Joselevich
1472b2446e pipewire: added kranzes (myself) as a maintainer
(cherry picked from commit 779472d9bc)
Signed-off-by: Domen Kožar <domen@dev.si>
2021-08-08 21:55:44 +02:00
github-actions[bot]
5bb3f62a52 Merge staging-next-21.05 into staging-21.05 2021-08-08 18:02:47 +00:00
github-actions[bot]
9c8a139d61 Merge release-21.05 into staging-next-21.05 2021-08-08 18:02:14 +00:00
Robert Scott
08252a1cc4 tor: 0.4.5.7 -> 0.4.5.9 2021-08-08 18:29:32 +01:00
R. RyanTM
a21ac816fa gnomeExtensions.gsconnect: 46 -> 47
(cherry picked from commit 3cd3aa74ba)
2021-08-08 17:28:03 +00:00
Robert Scott
192a522abb wolfssl: add patches for CVE-2021-37155 2021-08-08 15:52:25 +01:00
Robert Scott
348bc5de8b Merge pull request #133111 from NixOS/backport-125133-to-release-21.05
[Backport release-21.05] vhd2vl: fix build error
2021-08-08 13:55:51 +01:00
Martin Weinelt
e78cb53f25 Merge pull request #133000 from NixOS/backport-132735-to-release-21.05
[Backport release-21.05] nixos/victoriametrics: set LimitNOFILE=1048576 to fix panic and restart loop
2021-08-08 14:36:00 +02:00
github-actions[bot]
f15cd760a5 Merge staging-next-21.05 into staging-21.05 2021-08-08 12:02:43 +00:00
github-actions[bot]
36f97cd5de Merge release-21.05 into staging-next-21.05 2021-08-08 12:02:07 +00:00
Sander van der Burg
90a001a7b8 Merge pull request #133038 from svanderburg/backport-add-desktopitems
[Backport release-21.05] add desktopitems
2021-08-08 13:22:23 +02:00
Ilan Joselevich
5b229b829a libfreeaptx: init at 0.1.1
(cherry picked from commit b0467a4f53)
Signed-off-by: Domen Kožar <domen@dev.si>
2021-08-08 12:43:27 +02:00
Ilan Joselevich
06d377ce0a pipewire: libopenaptx -> libfreeaptx
(cherry picked from commit 549666bd96)
Signed-off-by: Domen Kožar <domen@dev.si>
2021-08-08 12:39:46 +02:00
Ilan Joselevich
02a8bdcdc9 pipewire: 0.3.32 -> 0.3.33
(cherry picked from commit dab7fef97b)
Signed-off-by: Domen Kožar <domen@dev.si>
2021-08-08 12:39:38 +02:00
Jan Solanti
c7da07623e pipewire: 0.3.31 -> 0.3.32
(cherry picked from commit c6ff26b19f)
Signed-off-by: Domen Kožar <domen@dev.si>
2021-08-08 12:39:19 +02:00
arcnmx
7be67825c8 nixos/pipewire: add bluez hardware database
(cherry picked from commit ef532a0443)
Signed-off-by: Domen Kožar <domen@dev.si>
2021-08-08 12:39:11 +02:00
arcnmx
4ef889251c pipewire: 0.3.30 -> 0.3.31
(cherry picked from commit eb7e40f9c9)
Signed-off-by: Domen Kožar <domen@dev.si>
2021-08-08 12:38:52 +02:00
Jörg Thalheim
d6aa85f7ff vhd2vl: apply linting suggestions
(cherry picked from commit e7235d863c)
2021-08-08 10:16:10 +00:00
sophrosyne97
0c6243e00f vhd2vl: fix build error
(cherry picked from commit 0c2c703891)
2021-08-08 10:16:10 +00:00
Jörg Thalheim
7174a61367 Merge pull request #130269 from NixOS/backport-125205-to-release-21.05
[Backport release-21.05] k3s: token file
2021-08-08 11:09:03 +01:00
Yuka
3a5ff18d64 mautrix-telegram: add inputs for E2BE support (#132979)
https://docs.mau.fi/bridges/general/end-to-bridge-encryption.html
(cherry picked from commit f1d1ed4f02)
2021-08-08 11:09:23 +02:00
github-actions[bot]
8c47337f31 Merge staging-next-21.05 into staging-21.05 2021-08-08 06:02:59 +00:00
github-actions[bot]
07e5ffa19f Merge release-21.05 into staging-next-21.05 2021-08-08 06:02:25 +00:00
André Vitor de Lima Matos
6ae8e459f5 nvidia_x11: fix suspend script paths since 470.57.02 (#131838)
nvidia 470.57.02 changed the path of `nvidia-sleep.sh` and systemd
scripts, making `builder.sh` miss them and suspend-to-ram on systems
where `hardware.nvidia.powerManagement.enable = true` is set fail.

(cherry picked from commit 3f4bb8ff5a)
2021-08-07 22:41:22 -07:00
Herman Fries
253365e354 nvidia_x11: 460.73.01 -> 470.57.02
(cherry picked from commit 03100da5a7)

Reason: Fixes driver build failures for the 5.13 kernel
2021-08-07 22:41:22 -07:00
Artturi
688f1ab9c5 Merge pull request #130330 from unclechu/backport-129710-to-release-21.05
psi-plus: backport “add more build options” to release-21.05
2021-08-08 08:28:59 +03:00
Mario Rodas
4795a1882d nodejs-16_x: 16.5.0 -> 16.6.1
https://github.com/nodejs/node/releases/tag/v16.6.0
https://github.com/nodejs/node/releases/tag/v16.6.1
(cherry picked from commit 0066c05ae2)
2021-08-08 04:20:00 +00:00
Martin Weinelt
5b252d8e07 Merge pull request #133065 from NixOS/backport-133057-to-release-21.05
[Backport release-21.05] lynx: add patch for CVE-2021-38165
2021-08-08 02:24:45 +02:00
Artturi
7e43079af9 Merge pull request #133062 from NixOS/backport-132966-to-release-21.05
[Backport release-21.05] blueman: 2.2.1 -> 2.2.2
2021-08-08 03:04:57 +03:00
github-actions[bot]
3801c0f13b Merge staging-next-21.05 into staging-21.05 2021-08-08 00:03:44 +00:00
github-actions[bot]
238870ee1c Merge release-21.05 into staging-next-21.05 2021-08-08 00:03:04 +00:00
matthewcroughan
7030245979 lynx: add patch for CVE-2021-38165
Co-authored-by: nixinator <33lockdown33@protonmail.com>
Co-authored-by: John Bargman <darthpjb@gmail.com>
Co-authored-by: Martin Weinelt <hexa@darmstadt.ccc.de>
(cherry picked from commit ddce0ec126)
2021-08-07 23:45:48 +00:00
R. RyanTM
6741d9501e blueman: 2.2.1 -> 2.2.2
(cherry picked from commit 7f3755e67a)
2021-08-07 23:39:23 +00:00
Artturi
43acb01642 Merge pull request #133040 from NixOS/backport-124452-to-release-21.05
[Backport release-21.05] SDL_Pango: fix darwin build
2021-08-07 23:26:26 +03:00
Maximilian Bosch
ab5a244050 Merge pull request #133041 from NixOS/backport-133015-to-release-21.05
[Backport release-21.05] mautrix-whatsapp: 0.1.7 -> 0.1.8
2021-08-07 21:47:24 +02:00
Charlotte Van Petegem
a9c04292f2 mautrix-whatsapp: specify agpl3plus license
e.g. f4a7394b67/bridgestate.go
mentions the option of using a later version.

(cherry picked from commit a6692271eb)
2021-08-07 19:29:15 +00:00
Charlotte Van Petegem
598282f8ed mautrix-whatsapp: update repository location
(cherry picked from commit 57e6214370)
2021-08-07 19:29:15 +00:00
Charlotte Van Petegem
0fe73dc3bb mautrix-whatsapp: 0.1.7 -> 0.1.8
(cherry picked from commit bb550a67d8)
2021-08-07 19:29:14 +00:00
Stéphan Kochen
72f3f8cc82 SDL_Pango: fix darwin build
(cherry picked from commit 056d7221aa)
2021-08-07 19:15:25 +00:00
Sander van der Burg
22f37f4aee dhewm: add desktop item
(cherry picked from commit f7ae4163e0)
2021-08-07 20:36:20 +02:00
Sander van der Burg
b6e71616f8 quakespasm: add desktop item
(cherry picked from commit 55c21071de)
2021-08-07 20:36:02 +02:00
Sander van der Burg
07d959d0b0 gzdoom: add desktop item
(cherry picked from commit 246ac3167d)
2021-08-07 20:34:08 +02:00
github-actions[bot]
cf38c80016 Merge staging-next-21.05 into staging-21.05 2021-08-07 18:02:47 +00:00
github-actions[bot]
f2268420f0 Merge release-21.05 into staging-next-21.05 2021-08-07 18:02:13 +00:00
Maximilian Bosch
d25508ce3a Merge pull request #133025 from avdv/backport-132043-to-release-21.05
jetbrains: Fix update.pl script for MPS and update [21.05 backport]
2021-08-07 18:08:36 +02:00
Maximilian Bosch
fa27de52c7 Merge pull request #133023 from NixOS/backport-132920-to-release-21.05
[Backport release-21.05] nextcloud: 20.0.11 -> 20.0.12, 21.0.3 -> 21.0.4, 22.0.0 -> 22.1.0
2021-08-07 17:40:42 +02:00
Maximilian Bosch
8d3bc3ae55 nextcloud22: 22.0.0 -> 22.1.0
ChangeLog: https://nextcloud.com/changelog/#22-1-0
(cherry picked from commit 985d9f39ae)
2021-08-07 15:09:49 +00:00
Maximilian Bosch
7c1e6bd61f nextcloud21: 21.0.3 -> 21.0.4
ChangeLog: https://nextcloud.com/changelog/#21-0-4
(cherry picked from commit 20707acda8)
2021-08-07 15:09:49 +00:00
Maximilian Bosch
06c9e35f11 nextcloud20: 20.0.11 -> 20.0.12
ChangeLog: https://nextcloud.com/changelog/#20-0-12
(cherry picked from commit be5d310839)
2021-08-07 15:09:48 +00:00
Artturi
e60eb84b7c Merge pull request #132999 from NixOS/backport-132945-to-release-21.05
[Backport release-21.05] stdenv/check-meta: add maxSilent
2021-08-07 15:05:22 +03:00
Ivan Kozik
b047dfa13d nixos/victoriametrics: set LimitNOFILE=1048576 to fix panic and restart loop
This fixes:

```
systemd[1]: Started VictoriaMetrics time series database.
victoria-metrics[379550]: 2021-08-04T19:33:39.833Z        panic        VictoriaMetrics/lib/storage/partition.go:954        FATAL: unrecoverable error when merging small parts in the partition "/var/lib/victoriametrics/data/small/2021_08": cannot open source part for merging: cannot open metaindex file in stream mode: cannot open file "/var/lib/victoriametrics/data/small/2021_08/1228_1228_20210804184120.712_20210804184121.899_16982E83CD7A763A/metaindex.bin": open /var/lib/victoriametrics/data/small/2021_08/1228_1228_20210804184120.712_20210804184121.899_16982E83CD7A763A/metaindex.bin: too many open files
victoria-metrics[379550]: panic: FATAL: unrecoverable error when merging small parts in the partition "/var/lib/victoriametrics/data/small/2021_08": cannot open source part for merging: cannot open metaindex file in stream mode: cannot open file "/var/lib/victoriametrics/data/small/2021_08/1228_1228_20210804184120.712_20210804184121.899_16982E83CD7A763A/metaindex.bin": open /var/lib/victoriametrics/data/small/2021_08/1228_1228_20210804184120.712_20210804184121.899_16982E83CD7A763A/metaindex.bin: too many open files
victoria-metrics[379550]: goroutine 629 [running]:
victoria-metrics[379550]: github.com/VictoriaMetrics/VictoriaMetrics/lib/logger.logMessage(0xbb3ea1, 0x5, 0xc001113800, 0x1e7, 0x4)
victoria-metrics[379550]:         github.com/VictoriaMetrics/VictoriaMetrics/lib/logger/logger.go:270 +0xc69
victoria-metrics[379550]: github.com/VictoriaMetrics/VictoriaMetrics/lib/logger.logLevelSkipframes(0x1, 0xbb3ea1, 0x5, 0xbe3f8b, 0x4b, 0xc000bb3f88, 0x2, 0x2)
victoria-metrics[379550]:         github.com/VictoriaMetrics/VictoriaMetrics/lib/logger/logger.go:138 +0xd1
victoria-metrics[379550]: github.com/VictoriaMetrics/VictoriaMetrics/lib/logger.logLevel(...)
victoria-metrics[379550]:         github.com/VictoriaMetrics/VictoriaMetrics/lib/logger/logger.go:130
victoria-metrics[379550]: github.com/VictoriaMetrics/VictoriaMetrics/lib/logger.Panicf(...)
victoria-metrics[379550]:         github.com/VictoriaMetrics/VictoriaMetrics/lib/logger/logger.go:126
victoria-metrics[379550]: github.com/VictoriaMetrics/VictoriaMetrics/lib/storage.(*partition).smallPartsMerger(0xc0014d7980)
victoria-metrics[379550]:         github.com/VictoriaMetrics/VictoriaMetrics/lib/storage/partition.go:954 +0x145
victoria-metrics[379550]: github.com/VictoriaMetrics/VictoriaMetrics/lib/storage.(*partition).startMergeWorkers.func1(0xc0014d7980)
victoria-metrics[379550]:         github.com/VictoriaMetrics/VictoriaMetrics/lib/storage/partition.go:933 +0x2b
victoria-metrics[379550]: created by github.com/VictoriaMetrics/VictoriaMetrics/lib/storage.(*partition).startMergeWorkers
victoria-metrics[379550]:         github.com/VictoriaMetrics/VictoriaMetrics/lib/storage/partition.go:932 +0x6c
systemd[1]: victoriametrics.service: Main process exited, code=exited, status=2/INVALIDARGUMENT
systemd[1]: victoriametrics.service: Failed with result 'exit-code'.
systemd[1]: victoriametrics.service: Consumed 587ms CPU time, received 6.5K IP traffic, sent 1.7K IP traffic.
systemd[1]: victoriametrics.service: Scheduled restart job, restart counter is at 2064.
systemd[1]: Stopped VictoriaMetrics time series database.
systemd[1]: victoriametrics.service: Consumed 587ms CPU time, received 6.5K IP traffic, sent 1.7K IP traffic.
systemd[1]: Starting VictoriaMetrics time series database...
```

(cherry picked from commit fb6fbcb85c)
2021-08-07 10:39:13 +00:00
Artturin
afcc2a1bed stdenv/check-meta: add maxSilent
Hydra supports it
https://github.com/NixOS/hydra/blob/master/src/hydra-eval-jobs/hydra-eval-jobs.cc#L172

(cherry picked from commit 40944bbab7)
2021-08-07 10:35:21 +00:00
Claudio Bley
8163847c78 jetbrains: Check for 64 bit specific fsnotifier
In April, 2021, Jetbrains announced the end of support for 32-bit OS
IntelliJ-based IDEs[1]:

> The final major version that will be guaranteed to run on a 32-bit OS will be
> v2021.1 for all IntelliJ-based IDEs, including AppCode, Clion, DataGrip, GoLand,
> IntelliJ IDEA, PhpStorm, PyCharm, Rider, RubyMine, and WebStorm.

[1]: https://blog.jetbrains.com/idea/2021/04/end-of-support-for-32-bit-operating-systems-in-intellij-based-ides/

(cherry picked from commit 147d36b474)
2021-08-07 09:26:07 +02:00
Claudio Bley
149875adc2 jetbrains: Update
clion               : 2021.1.2 -> 2021.2
datagrip            : 2021.1.3 -> 2021.2
goland              : 2021.1.3 -> 2021.2
idea-community      : 2021.1.3 -> 2021.2
idea-ultimate       : 2021.1.3 -> 2021.2
mps                 : 2021.1   -> 2021.1.1
phpstorm            : 2021.1.4 -> 2021.2
pycharm-community   : 2021.1.3 -> 2021.2
pycharm-professional: 2021.1.3 -> 2021.2
rider               : 2021.1.3 -> 2021.1.5
ruby-mine           : 2021.1.2 -> 2021.2
webstorm            : 2021.1.2 -> 2021.2
(cherry picked from commit 544e20e24b)
2021-08-07 09:26:07 +02:00
Claudio Bley
887bf8b20a jetbrains: Fix update.pl script for MPS
Jetbrains seems to have deviated from the usual URL pattern of
`/<product>/<version>/<name>-<version>.<ext>` by only using the major.minor part
of the version number in the first URL segment for MPS.

(cherry picked from commit 597f94bd8a)
2021-08-07 09:26:02 +02:00
github-actions[bot]
eeaf5b3a23 Merge staging-next-21.05 into staging-21.05 2021-08-07 00:03:22 +00:00
github-actions[bot]
d4458f0116 Merge release-21.05 into staging-next-21.05 2021-08-07 00:02:41 +00:00
Artturi
e06ef38b52 Merge pull request #130470 from NixOS/backport-130397-to-release-21.05
[Backport release-21.05] firmwareLinuxNonfree: 2021-05-11 -> 2021-07-16
2021-08-07 01:49:56 +03:00
Artturi
cb0ce8db8a Merge pull request #131500 from NixOS/backport-130681-to-release-21.05
[Backport release-21.05] containerd: 1.5.2 -> 1.5.4
2021-08-07 01:46:38 +03:00
Artturi
97369376e1 Merge pull request #127901 from NixOS/backport-127884-to-release-21.05
[Backport release-21.05] clamav: 0.103.2 -> 0.103.3
2021-08-07 01:45:16 +03:00
Artturi
ae1773ad51 Merge pull request #125814 from NixOS/backport-125804-to-release-21.05
[Backport release-21.05] buildFhsUserenv: don't leak mounts to other processes
2021-08-07 01:37:50 +03:00
Artturi
8bd8141ca9 Merge pull request #126327 from NixOS/backport-126093-to-release-21.05 2021-08-07 01:32:40 +03:00
Artturi
3755587738 Merge pull request #125643 from NixOS/backport-125374-to-release-21.05 2021-08-07 01:31:43 +03:00
Artturi
c20c5fe502 Merge pull request #132940 from NixOS/backport-132888-to-release-21.05 2021-08-07 01:18:30 +03:00
github-actions[bot]
b42cffe97f [Backport release-21.05] Add JSON package to gitolite environment. (#127799)
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
Co-authored-by: Lassulus <github@lassul.us>
Co-authored-by: Stanisław Barzowski <stanislaw.barzowski@gmail.com>
2021-08-07 01:17:03 +03:00
ajs124
2f5664a9a7 dovecot_pigeonhole: 0.5.15 -> 0.5.16
(cherry picked from commit a161e14867)
2021-08-06 21:38:28 +00:00
ajs124
149e6005de dovecot: 2.3.15 -> 2.3.16
(cherry picked from commit 0184b07908)
2021-08-06 21:38:27 +00:00
Artturi
e95258eaf1 Merge pull request #132748 from NixOS/backport-127986-to-release-21.05
[Backport release-21.05] generate-expr-from-tarballs.pl: use nix-shell as script interpreter
2021-08-07 00:29:31 +03:00
Artturi
7396b68a4c Merge pull request #125253 from NixOS/backport-124853-to-release-21.05 2021-08-07 00:27:00 +03:00
Artturi
e2a629767a Merge pull request #128614 from NixOS/backport-128492-to-release-21.05
[Backport release-21.05] gnuradio: 3.9.1.0 -> 3.9.2.0
2021-08-07 00:20:31 +03:00
Artturi
a870b495c3 Merge pull request #128977 from NixOS/backport-128865-to-release-21.05 2021-08-07 00:17:26 +03:00
Artturi
a8deceff73 Merge pull request #126582 from NixOS/backport-123513-to-release-21.05
[Backport release-21.05] oraclejdk*: use latest ffmpeg
2021-08-07 00:16:44 +03:00
Artturi
7ffde509bf Merge pull request #132514 from NixOS/backport-132508-to-release-21.05
[Backport release-21.05] chromium: 92.0.4515.107 -> 92.0.4515.131
2021-08-07 00:13:20 +03:00
Artturi
84567da68b Merge pull request #124833 from NixOS/backport-124239-to-release-21.05
[Backport release-21.05] helio-workstation: 3.4 -> 3.6
2021-08-07 00:12:18 +03:00
Artturi
ee7f613bab Merge pull request #126317 from NixOS/backport-126269-to-release-21.05
[Backport release-21.05] wasm-bindgen-cli: 0.2.73 -> 0.2.74
2021-08-07 00:11:46 +03:00
Artturi
c46a7373e7 Merge pull request #129438 from NixOS/backport-126158-to-release-21.05
[Backport release-21.05] nixos/btrfs: handle new checksum types in initrd
2021-08-07 00:10:39 +03:00
Artturi
2148d5542d Merge pull request #131183 from NixOS/backport-126556-to-release-21.05
[Backport release-21.05] libreoffice-fresh: 7.1.3.2 -> 7.1.4.2
2021-08-07 00:08:17 +03:00
Artturi
368f8f0437 Merge pull request #127582 from NixOS/backport-127568-to-release-21.05
[Backport release-21.05] gnuradio.pkgs.ais: 2015-12-20 -> 2020-08-13
2021-08-07 00:06:36 +03:00
Artturi
29f76e65d0 Merge pull request #131730 from NixOS/backport-130851-to-staging-21.05
[Backport staging-21.05] kernel: enable MOUSE_PS2_VMMOUSE
2021-08-07 00:06:03 +03:00
Artturi
ec5c0144d9 Merge pull request #126442 from NixOS/backport-125668-to-release-21.05
[Backport release-21.05] glibc: fix build vs host tool confusion
2021-08-07 00:04:10 +03:00
Artturi
a616e47487 Merge pull request #125270 from NixOS/backport-125263-to-release-21.05
[Backport release-21.05] gnomeExtensions: allowAliases should default to true if unset
2021-08-07 00:03:21 +03:00
Artturi
b30c8f36b8 Merge pull request #128329 from NixOS/backport-128313-to-release-21.05
[Backport release-21.05] pan: fix build and format
2021-08-07 00:02:50 +03:00
Artturi
10f3dfbfb8 Merge pull request #125017 from NixOS/backport-125005-to-release-21.05
[Backport release-21.05] plex: 1.23.0.4482-62106842a -> 1.23.1.4602-280ab6053
2021-08-07 00:02:00 +03:00
Artturi
c5111db64f Merge pull request #125481 from NixOS/backport-124722-to-release-21.05
[Backport release-21.05] nvidia-x11: 465.27 -> 465.31
2021-08-07 00:00:24 +03:00
Artturi
51830a116f Merge pull request #131479 from NixOS/backport-127251-to-release-21.05 2021-08-06 23:56:58 +03:00
Artturi
7adc4211ac Merge pull request #128120 from NixOS/backport-128054-to-release-21.05 2021-08-06 23:55:28 +03:00
Artturi
f547ea71e6 Merge pull request #126028 from NixOS/backport-125929-to-release-21.05
[Backport release-21.05] tor-browser-bundle: delete unused extensions.nix
2021-08-06 23:54:33 +03:00
Artturi
156a73ee6c Merge pull request #125410 from NixOS/backport-125333-to-release-21.05
[Backport release-21.05] pantalaimon: install manuals
2021-08-06 23:50:53 +03:00
Artturi
4df937003c Merge pull request #131933 from NixOS/backport-131890-to-release-21.05
[Backport release-21.05] stretchly: 1.6.0 -> 1.7.0
2021-08-06 23:49:13 +03:00
Artturi
04cd79393b Merge pull request #131936 from NixOS/backport-131091-to-release-21.05
[Backport release-21.05] github-runner: 2.278.0 -> 2.279.0
2021-08-06 23:48:27 +03:00
Artturi
9f9f6563cc Merge pull request #126238 from NixOS/backport-126226-to-release-21.05
[Backport release-21.05] minecraft-server: 1.16.5 -> 1.17
2021-08-06 23:47:13 +03:00
Artturi
c83d5580dd Merge pull request #130990 from NixOS/backport-130918-to-release-21.05
[Backport release-21.05] ferdi: 5.6.0-beta.6 -> 5.6.0
2021-08-06 23:41:11 +03:00
Artturi
688d3b9285 Merge pull request #129358 from NixOS/backport-129227-to-release-21.05
[Backport release-21.05] kjv: 2018-12-25 -> 2021-03-11
2021-08-06 23:39:43 +03:00
Artturi
927f4545a1 Merge pull request #131000 from NixOS/backport-130965-to-release-21.05
[Backport release-21.05] nexus: fix #130754 by using jre8_headless
2021-08-06 23:38:53 +03:00
Artturi
3feef91c01 [Backport release-21.05] silicon: 0.4.1 -> 0.4.2 (#125939)
[Backport release-21.05] silicon: 0.4.1 -> 0.4.2
2021-08-06 23:34:25 +03:00
github-actions[bot]
6030171d83 [Backport release-21.05] yandex-disk: 0.1.5.1039 -> 0.1.6.1074 (#131403)
Co-authored-by: Aleksandr Petrosyan <a-p-petrosyan@yandex.ru>
2021-08-06 23:32:21 +03:00
Artturi
155ab1ce13 Merge pull request #125142 from NixOS/backport-124398-to-release-21.05
[Backport release-21.05] dconf2nix: 0.0.7 -> 0.0.8
2021-08-06 23:26:43 +03:00
Artturi
e76ea216ce Merge pull request #125254 from NixOS/backport-125097-to-release-21.05
[Backport release-21.05] usbutils: 012 -> 013
2021-08-06 23:25:24 +03:00
Artturi
16676ae668 Merge pull request #125278 from NixOS/backport-125172-to-release-21.05
[Backport release-21.05] metals: 0.10.3 -> 0.10.4
2021-08-06 23:22:49 +03:00
Artturi
0faef908e6 Merge pull request #129801 from NixOS/backport-129770-to-release-21.05 2021-08-06 23:22:04 +03:00
Ninjatrappeur
40188b6763 Merge pull request #132898 from NixOS/backport-132887-to-release-21.05
[Backport release-21.05] prosody: 0.11.9 -> 0.11.10
2021-08-06 22:13:26 +02:00
Artturi
9ed7cdcbf7 Merge pull request #127422 from NixOS/backport-127387-to-release-21.05
[Backport release-21.05] connman: 1.39 -> 1.40
2021-08-06 21:44:23 +03:00
github-actions[bot]
4bd56dee3e Merge staging-next-21.05 into staging-21.05 2021-08-06 18:02:40 +00:00
github-actions[bot]
b538b863a6 Merge release-21.05 into staging-next-21.05 2021-08-06 18:02:07 +00:00
Artturi
2aeed2e3db Merge pull request #127446 from NixOS/backport-126745-to-release-21.05
[Backport release-21.05] spice: 0.14.2 -> 0.15.0
2021-08-06 20:30:39 +03:00
Artturi
6756b98479 Merge pull request #127803 from NixOS/backport-127794-to-release-21.05 2021-08-06 20:27:39 +03:00
Artturi
e5ba0beadd Merge pull request #126511 from NixOS/backport-126404-to-release-21.05
[Backport release-21.05] firefox: Make CUPS printers visible in the print dialog
2021-08-06 20:26:24 +03:00
Artturi
739b046784 Merge pull request #130178 from NixOS/backport-129978-to-release-21.05 2021-08-06 20:05:54 +03:00
Artturi
ce542c57dd Merge pull request #125285 from NixOS/backport-125096-to-release-21.05
[Backport release-21.05] sane-airscan: 0.99.24 -> 0.99.26
2021-08-06 19:20:19 +03:00
Artturi
762123e6a0 Merge pull request #131806 from NixOS/backport-127832-to-staging-21.05 2021-08-06 19:17:11 +03:00
Artturi
dbdca07483 Merge pull request #127579 from NixOS/backport-124468-to-release-21.05
[Backport release-21.05] jbang: 0.70.0 -> 0.71.1
2021-08-06 17:42:32 +03:00
Artturi
af5f7e15a0 Merge pull request #125224 from NixOS/backport-124991-to-release-21.05
[Backport release-21.05] nixos/pam: use new plasma5Packages, fixes #124973
2021-08-06 17:17:39 +03:00
Artturi
2a76448f95 Merge pull request #125817 from NixOS/backport-125744-to-release-21.05
[Backport release-21.05] gnome3.gnome-boxes: add qemu as dependency
2021-08-06 17:15:18 +03:00
Artturi
308f996b80 Merge pull request #126011 from NixOS/backport-125908-to-release-21.05
[Backport release-21.05] gnome.eog: 40.1 -> 40.2
2021-08-06 17:11:51 +03:00
Artturi
a1ce519452 Merge pull request #131903 from NixOS/backport-131782-to-release-21.05
[Backport release-21.05] vscode-extensions.ms-vscode-remote.remote-ssh: 0.50.0 -> 0.65.7
2021-08-06 17:06:33 +03:00
Artturi
5d90ab34ed Merge pull request #132870 from NixOS/backport-132323-to-release-21.05
[Backport release-21.05] gnome.caribou: add patch for CVE-2021-3567
2021-08-06 17:03:09 +03:00
Artturi
9582db8df4 Merge pull request #126139 from NixOS/backport-124776-to-release-21.05 2021-08-06 17:01:43 +03:00
Artturi
0cc1a01d6a Merge pull request #126960 from NixOS/backport-123720-to-release-21.05
[Backport release-21.05] nixos-rebuild: fix creating ./result symlink for flakes
2021-08-06 16:59:35 +03:00
ajs124
bcf6e43b9e prosody: 0.11.9 -> 0.11.10
fix CVE-2021-37601

annoucement: https://blog.prosody.im/prosody-0.11.10-released/
(cherry picked from commit b977d45922)
2021-08-06 13:56:55 +00:00
Artturi
6a694d5e9e Merge pull request #125013 from NixOS/backport-124601-to-release-21.05 2021-08-06 16:34:51 +03:00
Artturi
e49224303f Merge pull request #125176 from NixOS/backport-125171-to-release-21.05
[Backport release-21.05] zsh-completions: 0.32.0 -> 0.33.0
2021-08-06 16:32:42 +03:00
Artturi
fccc43bcb3 Merge pull request #131199 from NixOS/backport-130989-to-release-21.05
[Backport release-21.05] virtscreen: unbreak
2021-08-06 16:30:03 +03:00
Artturi
5cd85f76b8 Merge pull request #130997 from NixOS/backport-130966-to-release-21.05
[Backport release-21.05] strawberry: add glib-networking to fix  #112334
2021-08-06 16:27:33 +03:00
Artturi
a9919ec147 Merge pull request #131200 from NixOS/backport-128812-to-release-21.05 2021-08-06 15:41:04 +03:00
github-actions[bot]
a756373c2e Merge staging-next-21.05 into staging-21.05 2021-08-06 12:03:15 +00:00
github-actions[bot]
9a2f59177f Merge release-21.05 into staging-next-21.05 2021-08-06 12:02:27 +00:00
Maximilian Bosch
cdc1d0f436 Merge pull request #132741 from NixOS/backport-132719-to-release-21.05
[Backport release-21.05] Kernels 2021-08-04
2021-08-06 13:36:55 +02:00
Martin Weinelt
8704644df1 Merge pull request #131984 from risicle/ris-tensorflow-2.4.2-r21.05 2021-08-06 12:02:17 +02:00
github-actions[bot]
5ed554543c [Backport release-21.05] terraria-server: update source URL (#132855)
* terraria-server: update source URL

The old URL redirects to the main page.

(cherry picked from commit 1e919bfeedae2abefb520a4fad7e9e37e98be8e0)

* Apply suggestions from code review

Co-authored-by: Naïm Favier <n@monade.li>
Co-authored-by: Jörg Thalheim <Mic92@users.noreply.github.com>
2021-08-06 10:01:37 +01:00
Robert Scott
712325e1db gnome.caribou: add patch for CVE-2021-3567
adding vala requirement as patching triggers a rerun on valac, also
needing a fix for semi-modern vala support

(cherry picked from commit f13ed32490)
2021-08-06 08:35:59 +00:00
Michael Weiss
b5510dc4d4 Merge pull request #132822 from NixOS/backport-132798-to-release-21.05
[Backport release-21.05] signal-desktop: 5.12.1 -> 5.12.2
2021-08-06 10:08:53 +02:00
github-actions[bot]
d84b1db0c2 Merge staging-next-21.05 into staging-21.05 2021-08-06 06:02:45 +00:00
github-actions[bot]
468d2096e9 Merge release-21.05 into staging-next-21.05 2021-08-06 06:02:08 +00:00
Jörg Thalheim
bfaa8ec1c7 Merge pull request #132831 from maxeaubrey/21.05_nomad_1.0.9
[21.05] nomad_1_0: 1.0.6 -> 1.0.9
2021-08-06 05:59:03 +01:00
github-actions[bot]
ab516c022b Merge staging-next-21.05 into staging-21.05 2021-08-06 00:03:42 +00:00
github-actions[bot]
3fd53c052c Merge release-21.05 into staging-next-21.05 2021-08-06 00:02:59 +00:00
zowoq
944fd2b224 go_1_16: 1.16.6 -> 1.16.7
(cherry picked from commit 869e4a894e)
2021-08-05 23:12:50 +00:00
zowoq
9b73e93818 go_1_15: 1.15.14 -> 1.15.15
(cherry picked from commit 1d3f4cd77f)
2021-08-05 23:12:50 +00:00
Maxine Aubrey
571e90be6e nomad_1_0: 1.0.8 -> 1.0.9
(cherry picked from commit f6eb8281ad)
2021-08-06 00:59:44 +02:00
Danielle Lancashire
1ab753b5b1 nomad_1_0: 1.0.7 -> 1.0.8
(cherry picked from commit d4655879fb)
2021-08-06 00:59:38 +02:00
Maxine Aubrey
bf6fcdcaf9 nomad_1_0: 1.0.6 -> 1.0.7
(cherry picked from commit dfe732d3c1)
2021-08-06 00:59:29 +02:00
Artturi
178da37860 Merge pull request #132668 from Artturin/backport-132599-to-release-21.05
[Backport 21.05] linuxPackages.evdi: unstable-2021-06-11 -> unstable-2021-07-7
2021-08-06 01:38:51 +03:00
Artturi
71102fbdab Merge pull request #132658 from Artturin/backport-132373-to-release-21.05
[Backport release-21.05] samba4: add wrapPythonPrograms
2021-08-06 01:37:19 +03:00
Artturi
0ecae3799f Merge pull request #132720 from Artturin/backport-132459-to-release-21.05
[Backport release-21.05] ocrmypdf: 11.7.3 -> 12.3.0
2021-08-05 23:54:07 +03:00
Michael Weiss
e96ec15bc4 signal-desktop: 5.12.1 -> 5.12.2
(cherry picked from commit bba311e5df)
2021-08-05 20:46:23 +00:00
Robert Scott
733682c329 Merge pull request #128675 from NixOS/backport-127172-to-release-21.05
[Backport release-21.05] exiv2: 0.27.3 -> 0.27.4
2021-08-05 19:09:32 +01:00
github-actions[bot]
d0393d3344 Merge staging-next-21.05 into staging-21.05 2021-08-05 18:05:37 +00:00
github-actions[bot]
76e9cdbe64 Merge release-21.05 into staging-next-21.05 2021-08-05 18:04:53 +00:00
Wael Nasreddine
34f504c33d Merge pull request #132789 from NixOS/backport-132780-to-release-21.05
[Backport release-21.05] gitlab: 14.1.1 -> 14.1.2
2021-08-05 19:02:10 +03:00
Vladimír Čunát
98d66e4541 Merge #132753: 'staging-next-21.05' into release-21.05 2021-08-05 17:26:53 +02:00
Yureka
7036ca99ae gitlab: 14.1.1 -> 14.1.2
(cherry picked from commit 5957f4edb9)
2021-08-05 14:32:11 +00:00
Martin Weinelt
b2d256095a Merge pull request #132778 from NixOS/backport-132772-to-release-21.05
[Backport release-21.05] mupdf: apply patch for CVE-2021-37220
2021-08-05 14:55:51 +02:00
Michael Weiss
1ce07d770b Merge pull request #132757 from NixOS/backport-132695-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 91.0.4472.164 -> 92.0.4515.131
2021-08-05 14:28:03 +02:00
Yureka
ff1ea3a36c nixos/tests/gitlab: disable gitlab-pages tests
(cherry picked from commit 6b021012c5)
2021-08-05 14:17:01 +02:00
Yureka
274b5f5099 gitlab: 14.1.0 -> 14.1.1
https://about.gitlab.com/releases/2021/07/28/gitlab-14-1-1-released/
(cherry picked from commit 5a69fb930d)
2021-08-05 14:17:01 +02:00
Frederik Ramcke
5e6c3593d6 mupdf: apply patch for CVE-2021-37220
(cherry picked from commit 2ac25f65a4)
2021-08-05 12:11:27 +00:00
Michael Weiss
8c589a79c8 Merge pull request #132771 from NixOS/backport-132756-to-release-21.05
[Backport release-21.05] signal-desktop: 5.12.0 -> 5.12.1
2021-08-05 14:08:44 +02:00
github-actions[bot]
4649ffce0c Merge staging-next-21.05 into staging-21.05 2021-08-05 12:03:42 +00:00
github-actions[bot]
f3cd217988 Merge release-21.05 into staging-next-21.05 2021-08-05 12:03:07 +00:00
Stig
2689e7a5a4 Merge pull request #132664 from NixOS/backport-131414-to-release-21.05
[Backport release-21.05] perlPackages.SQLTranslator: fix some scripts issues
2021-08-05 12:50:08 +02:00
Michael Weiss
7df18c5b76 signal-desktop: 5.12.0 -> 5.12.1
(cherry picked from commit f11652f0a6)
2021-08-05 10:37:19 +00:00
Michael Weiss
fa62bb8fac ungoogled-chromium: 91.0.4472.164 -> 92.0.4515.131
(cherry picked from commit 45c32f59a5)
2021-08-05 09:26:03 +00:00
TredwellGit
c8700d7b96 generate-expr-from-tarballs.pl: use nix-shell as script interpreter
(cherry picked from commit f6ea60666c)
2021-08-05 08:13:35 +00:00
TredwellGit
ab3104a98d linux: 5.13.7 -> 5.13.8
(cherry picked from commit ba2b85dbbb)
2021-08-05 07:16:13 +00:00
TredwellGit
44afd0cf9a linux: 4.9.277 -> 4.9.278
(cherry picked from commit aea5caaeab)
2021-08-05 07:16:13 +00:00
TredwellGit
cee88fa02a linux: 4.4.277 -> 4.4.278
(cherry picked from commit 202b9e6536)
2021-08-05 07:16:12 +00:00
Antoine Martin
7959da7f6e ocrmypdf: 11.7.3 -> 12.3.0 (#130175) 2021-08-05 03:19:52 +03:00
github-actions[bot]
851f4c9d1a Merge staging-next-21.05 into staging-21.05 2021-08-05 00:03:12 +00:00
github-actions[bot]
40b757ff44 Merge release-21.05 into staging-next-21.05 2021-08-05 00:02:29 +00:00
Artturin
f187ac728a gollum: add additional dependencies
(cherry picked from commit 3bdccfedaf0078eac4cae00e0646d8f0a8c1cfcf)
2021-08-04 23:44:03 +02:00
Robert Scott
368e8bcf0c Merge pull request #132671 from NixOS/backport-132594-to-release-21.05
[Backport release-21.05] putty: 0.75 -> 0.76
2021-08-04 22:28:34 +01:00
Kerstin Humm
71c30320f9 glimpse: add graphviz as runtime dependency
Fixes https://github.com/NixOS/nixpkgs/issues/132405

See also:
https://gitlab.gnome.org/GNOME/gegl/-/issues/279
f83fd22c4b

(cherry picked from commit 8d67153deb)
2021-08-04 23:22:37 +02:00
Jörg Thalheim
43cea7b6e4 python3Packages.gym: fix build
Tested by running one of their code examples

(cherry picked from commit 13cef56185)
2021-08-04 13:44:15 -07:00
Maximilian Bosch
0d70ff95e1 Merge pull request #132630 from NixOS/backport-132471-to-release-21.05
[Backport release-21.05] Kernels 2021-08-02
2021-08-04 22:24:30 +02:00
davidak
4e241b6e3f Merge pull request #132691 from NixOS/backport-131305-to-release-21.05
[Backport release-21.05] nixos-icons: fix icons not installed when documentation disabled
2021-08-04 21:51:21 +02:00
Robert Scott
0c98790627 Merge pull request #132662 from NixOS/backport-130833-to-release-21.05
[Backport release-21.05] convos: 6.24 -> 6.26
2021-08-04 20:42:19 +01:00
davidak
3f0926f6b5 nixos-icons: fix icons not installed when documentation disabled
(cherry picked from commit aa8373ab1b)
2021-08-04 19:39:21 +00:00
github-actions[bot]
7601759c8c Merge staging-next-21.05 into staging-21.05 2021-08-04 18:02:49 +00:00
github-actions[bot]
422ead75f0 Merge release-21.05 into staging-next-21.05 2021-08-04 18:02:13 +00:00
Thomas Gerbet
ebb083c259 putty: 0.75 -> 0.76
Fixes CVE-2021-36367.

(cherry picked from commit e78c51a0e9)
2021-08-04 14:53:13 +00:00
R. RyanTM
b1ee3bc424 apk-tools: 2.12.6 -> 2.12.7
(cherry picked from commit 28b3dc9186)
2021-08-04 14:42:18 +00:00
Artturin
2989536017 linuxPackages.evdi: unstable-2021-06-11 -> unstable-2021-07-7
(cherry picked from commit 335632575c)
2021-08-04 17:24:51 +03:00
pacien
eb4a65f315 perlPackages.SQLTranslator: add missing deps
This adds missing dependencies for the `sqlt*` scripts provided in
the SQLTranslator package.

(cherry picked from commit d65cee7b07)
2021-08-04 14:08:02 +00:00
Stig Palmquist
f344d8ba41 perlPackages.SQLTranslator: fix scripts shebang
(cherry picked from commit cc4f71d619)
2021-08-04 14:08:01 +00:00
Stig Palmquist
4e4300ec8c perlPackages.LinkEmbedder: 1.18 -> 1.20
(cherry picked from commit 38357d7306)
2021-08-04 13:58:50 +00:00
Stig Palmquist
924971d8b8 convos: 6.24 -> 6.26
(cherry picked from commit 21ba59294d)
2021-08-04 13:58:50 +00:00
Mario Rodas
bcbbb4bc44 nodejs-16_x: add patch for CVE-2021-22930
(cherry picked from commit c73d1006a2)
2021-08-04 08:22:00 -05:00
Artturin
508ebecf06 samba4: add wrapPythonPrograms
(cherry picked from commit 507d310cdad329035b5c631bbf806654fe96a0f3)
2021-08-04 15:48:55 +03:00
Mario Rodas
e9448d6282 Revert "nodejs-16_x: 16.5.0 -> 16.6.0"
Node.js 16.6.0 fails to build on Darwin

This reverts commit f5de4158dd.

(cherry picked from commit ae780c6e7d)
2021-08-04 07:17:19 -05:00
Michael Weiss
935e4fafbb Merge pull request #132644 from NixOS/backport-132639-to-release-21.05
[Backport release-21.05] signal-desktop: 5.11.0 -> 5.12.0
2021-08-04 14:10:42 +02:00
github-actions[bot]
31051cd4f6 Merge staging-next-21.05 into staging-21.05 2021-08-04 12:03:03 +00:00
github-actions[bot]
0d1b8f5bca Merge release-21.05 into staging-next-21.05 2021-08-04 12:02:27 +00:00
Domen Kožar
465daf79b4 Merge pull request #132608 from rb2k/21_05_hg_fix_apple_sdk
[21.05] nixos/apple-sdk: 11.0 -> 11.1
2021-08-04 13:38:32 +02:00
maralorn
d867206bb8 Merge pull request #132641 from sternenseemann/cabal2nix-2.18.0
[21.05] cabal2nix: 2.17.0 -> 2.18.0
2021-08-04 12:06:49 +02:00
Michael Weiss
d10d928193 signal-desktop: 5.11.0 -> 5.12.0
(cherry picked from commit f734643f00)
2021-08-04 09:54:55 +00:00
sternenseemann
259f027a4b cabal2nix: 2.17.0 -> 2.18.0
https://github.com/NixOS/cabal2nix/blob/v2.18.0/CHANGELOG.md

2.18.0 mostly brings bug fixes, especially the one fixing the unclear
error message if a cabal file was missing (which was forgotten in the
changelog). It is not technically a non-breaking change since the
Haskell API changed.

Since there shouldn't be any breakage for users and all known reverse
dependencies of cabal2nix have been broken for a while, the benefits
of backporting outweigh the risks.
2021-08-04 11:41:08 +02:00
TredwellGit
f8aab36f81 linux_latest-libre: 18191 -> 18210
(cherry picked from commit e56d304d73)
2021-08-04 07:50:01 +00:00
TredwellGit
31b4f817e8 linux: 5.13.6 -> 5.13.7
(cherry picked from commit b4aa8884d1)
2021-08-04 07:50:01 +00:00
TredwellGit
2c47a4e052 linux: 4.9.276 -> 4.9.277
(cherry picked from commit 32c78c9e12)
2021-08-04 07:50:00 +00:00
TredwellGit
8829f5bf2b linux: 4.4.276 -> 4.4.277
(cherry picked from commit 7d0b3f65aa)
2021-08-04 07:50:00 +00:00
Vincent Laporte
ae42a59565 qarte: 4.6.0 → 4.12.0
(cherry picked from commit 5af58916df9f9192499263ec2c798a3e1a9218c1)
2021-08-04 09:42:36 +02:00
github-actions[bot]
8f25e22fcc Merge staging-next-21.05 into staging-21.05 2021-08-04 06:02:33 +00:00
github-actions[bot]
d57a0c4cd9 Merge release-21.05 into staging-next-21.05 2021-08-04 06:02:02 +00:00
Robert Scott
3e83eba072 rabbitmq-server: add patches for multiple CVEs
CVE-2021-22116
CVE-2021-32718
CVE-2021-32719
2021-08-04 12:09:05 +09:00
github-actions[bot]
a554558db7 Merge staging-next-21.05 into staging-21.05 2021-08-04 00:03:13 +00:00
github-actions[bot]
c65cc9d28b Merge release-21.05 into staging-next-21.05 2021-08-04 00:02:37 +00:00
Anbang Wen
b13df33199 nixos/apple-sdk: 11.0 -> 11.1
The previous URL is a dead link. This commit updates it and bump the
SDK version to 11.1.

(cherry picked from commit 2565e3bba6)
2021-08-03 15:59:45 -07:00
Silvan Mosberger
6745921e23 Merge pull request #132602 from NixOS/backport-131267-to-release-21.05
[Backport release-21.05] lib: fix functionArgs for functors
2021-08-04 00:47:59 +02:00
David Arnold
e07870c95e lib: fix functionArgs for functors
`functionArgs` should give valid results on
functions that have been identified with `lib.isFunction`
instead of erroring out.

(cherry picked from commit cf8e219b7e)
2021-08-03 22:07:22 +00:00
Guillaume Girol
2bd2119bf3 Merge pull request #131938 from chuahou/update-flameshot-backport-21.05
[21.05] Backport flameshot update from 0.9.0 -> 0.10.1
2021-08-03 21:46:40 +00:00
davidak
8d5fd4302f Merge pull request #132577 from NixOS/backport-132575-to-release-21.05
[Backport release-21.05] restic: 0.12.0 -> 0.12.1
2021-08-03 21:36:07 +02:00
Serg Nesterov
5bdfd956f1 restic: 0.12.0 -> 0.12.1
(cherry picked from commit c69f341a05)
2021-08-03 19:11:43 +00:00
github-actions[bot]
a9e1012368 Merge staging-next-21.05 into staging-21.05 2021-08-03 18:02:54 +00:00
github-actions[bot]
fa297ea736 Merge release-21.05 into staging-next-21.05 2021-08-03 18:02:18 +00:00
Artturin
fbec1356fa perlPackages.PerlMagick: 7.0.10 -> 7.0.11-1
(cherry picked from commit 55692c5a0a)
2021-08-03 18:56:27 +02:00
Jörg Thalheim
51cfc3c6db Merge pull request #132536 from NixOS/backport-129413-to-release-21.05
[Backport release-21.05] nixos/binfmt: run binfmt activation script after mounting /run
2021-08-03 17:35:01 +01:00
Silvan Mosberger
6f2e900e10 Merge pull request #132482 from Infinisil/vbox-size-backport
[backport] vbox-image: add new option to set free space in image
2021-08-03 17:38:11 +02:00
github-actions[bot]
98f5aba8cb Merge staging-next-21.05 into staging-21.05 2021-08-03 12:03:48 +00:00
github-actions[bot]
0bbe89d8e6 Merge release-21.05 into staging-next-21.05 2021-08-03 12:03:04 +00:00
Kazutoshi Noguchi
3d3ced33c9 nixos/binfmt: run binfmt activation script after mounting /run
binfmt activation script creates /run/binfmt before mounting /run
when system activation.

To fix it I added dependency to specialfs to binfmt activation
script.

(cherry picked from commit bf22778585)
2021-08-03 11:24:05 +00:00
Maximilian Bosch
4feab93d28 Merge pull request #132462 from NixOS/backport-132438-to-release-21.05
[Backport release-21.05] element-{web,desktop}: 1.7.33 -> 1.7.34
2021-08-03 11:52:21 +02:00
Michael Weiss
dc7227dbd8 chromium: 92.0.4515.107 -> 92.0.4515.131
https://chromereleases.googleblog.com/2021/08/the-stable-channel-has-been-updated-to.html

This update includes 10 security fixes.

CVEs:
CVE-2021-30590 CVE-2021-30591 CVE-2021-30592 CVE-2021-30593
CVE-2021-30594 CVE-2021-30596 CVE-2021-30597

(cherry picked from commit 7015db7881)
2021-08-03 08:01:59 +00:00
Vladimír Čunát
ebcb3fce2b Merge #132501: knot-dns: disable tests broken on aarch64-darwin 2021-08-03 09:18:18 +02:00
Vladimír Čunát
2a18907734 knot-dns: disable tests broken on aarch64-darwin
Upstream is aware but they don't have a fix yet.
I'm not aware of NixPkgs being used for another platform
affected by this (e.g. ppc64le).

(cherry picked from commit 895ce97eea)
2021-08-03 06:29:57 +00:00
github-actions[bot]
cfd18a549e Merge staging-next-21.05 into staging-21.05 2021-08-03 06:03:36 +00:00
github-actions[bot]
dec47f5e9d Merge release-21.05 into staging-next-21.05 2021-08-03 06:02:56 +00:00
davidak
8549835351 Merge pull request #125246 from NixOS/backport-123895-to-release-21.05
[Backport release-21.05] bazel_4: 4.0.0 -> 4.1.0
2021-08-03 06:51:54 +02:00
davidak
1fb9572267 Merge pull request #125221 from NixOS/backport-124404-to-release-21.05
[Backport release-21.05] Small option type adjustments
2021-08-03 06:33:12 +02:00
davidak
3682a03cc8 Merge pull request #126456 from fgaz/backport/21.05/shattered-pixel-dungeon/0.9.3
[backport 21.05] shattered-pixel-dungeon: 0.9.2 -> 0.9.3
2021-08-03 06:09:14 +02:00
Luke Granger-Brown
2194711ae0 nixos/virtualbox-image: cast baseImageFreeSpace into str
This fixes an evaluation error that's blocking the nixos-unstable
channel (#132328).

(cherry picked from commit b5fab53628)
2021-08-03 02:47:14 +02:00
lassulus
a2a5df1e63 vbox-image: add new option to set free space in image
(cherry picked from commit a6700d75f3)
2021-08-03 02:45:28 +02:00
github-actions[bot]
8b5b236a70 Merge staging-next-21.05 into staging-21.05 2021-08-03 00:03:17 +00:00
github-actions[bot]
29bcf81336 Merge release-21.05 into staging-next-21.05 2021-08-03 00:02:37 +00:00
Maximilian Bosch
b812e1f413 Merge pull request #132463 from NixOS/backport-131583-to-release-21.05
[Backport release-21.05] seahorse: add glib-networking for sync
2021-08-03 00:04:34 +02:00
Sebastian Sellmeier
dd05346f79 seahorse: add glib-networking for sync
(cherry picked from commit 9f629693f3)
2021-08-02 21:26:25 +00:00
Sumner Evans
5d16df2ab1 element-{web,desktop}: 1.7.33 -> 1.7.34
(cherry picked from commit d1ec2fae86)
2021-08-02 21:24:50 +00:00
Maximilian Bosch
bbd7696843 Merge pull request #132440 from NixOS/backport-132338-to-release-21.05
[Backport release-21.05] nixos/captive-browser: fix startup
2021-08-02 22:19:56 +02:00
Linus Heckemann
c15e294a60 Merge pull request #132441 from Ma27/backport-captive-browser
[21.05] captive-browser: 2019-04-16 -> 2021-08-01
2021-08-02 20:55:55 +02:00
Maximilian Bosch
655cc5e747 captive-browser: 2019-04-16 -> 2021-08-01
Had to do this manually, because this `name`->`pname` "refactoring"
makes automated backports impossible.

Changes: 08450562e5...9c707dc32a
(cherry picked from commit bee0468d7b)
2021-08-02 20:31:44 +02:00
Maximilian Bosch
985d2d0dec nixos/captive-browser: fix startup
It seems as since Chromium 92, `chromium` crashes on startup if
`XDG_CONFIG_HOME` points to a read-only (store-)path.

(cherry picked from commit 8c35a69a6e)
2021-08-02 18:22:00 +00:00
github-actions[bot]
79348ac652 Merge staging-next-21.05 into staging-21.05 2021-08-02 18:03:06 +00:00
github-actions[bot]
c7d12b8159 Merge release-21.05 into staging-next-21.05 2021-08-02 18:02:34 +00:00
Domen Kožar
39b51feb80 Merge pull request #132432 from NixOS/backport-132431-to-release-21.05
[Backport release-21.05] enableRedistributableFirmware: add rtw89-firmware
2021-08-02 18:46:49 +02:00
Domen Kožar
07255eea7b enableRedistributableFirmware: add rtw89-firmware
(cherry picked from commit 749620cd4f)
2021-08-02 15:56:36 +00:00
github-actions[bot]
16f1e824e8 Merge release-21.05 into staging-next-21.05 2021-08-02 12:02:41 +00:00
Jörg Thalheim
4280aed6fe Merge pull request #132314 from NixOS/backport-132247-to-release-21.05
[Backport release-21.05] linux_zen: 5.13.5 -> 5.13.7
2021-08-02 12:16:20 +01:00
Robert Scott
d4590d2100 Merge pull request #132276 from NixOS/backport-132099-to-release-21.05
[Backport release-21.05] python3Packages.tensorflow: add patch fixing NotImplementedError with numpy 1.20
2021-08-02 09:27:49 +01:00
davidak
74e2faf596 Merge pull request #127576 from NixOS/backport-127435-to-release-21.05
[Backport release-21.05] sweet: add gtk-engine-murrine
2021-08-02 08:39:10 +02:00
Maximilian Bosch
c8d3bf8c02 Merge pull request #132336 from NixOS/backport-132235-to-release-21.05
[Backport release-21.05] epson-escpr2: 1.1.34 -> 1.1.38
2021-08-02 08:37:04 +02:00
github-actions[bot]
18fd910d83 Merge staging-next-21.05 into staging-21.05 2021-08-02 06:03:39 +00:00
github-actions[bot]
e90ec145d2 Merge release-21.05 into staging-next-21.05 2021-08-02 06:03:06 +00:00
Jonathan Ringer
71e370e534 mill: 0.9.6 -> 0.9.9
Use the `${version}-assembly` artifact, which avoids
having to download it using the release script

(cherry picked from commit 74090eb68a2fd8e0a6ef0000f36a784ed2d27194)
2021-08-01 22:56:38 -07:00
davidak
59f8ccb41f Merge pull request #131961 from NixOS/backport-131954-to-release-21.05
[Backport release-21.05] python3Packages.trezor: 0.12.2 -> 0.12.3
2021-08-02 06:53:03 +02:00
ajs124
e04ad378fd grub2: 2.06-rc1 -> 2.06
* GCC 10 support.
* clang 10 support.
* SBAT support.
* LUKS2 support.
* Drop small MBR gap support.
* Xen Security Modules (XSM/FLASK) support.
* The lockdown mechanism similar to the Linux kernel one.
* Disable the os-prober by default.
* Many backports of GRUB distros specific patches.
* BootHole and BootHole2 fixes.
* XFS bigtime support.
* ...and tons of other fixes and cleanups...

(cherry picked from commit 963b0a1dbf)
2021-08-01 20:43:18 -07:00
github-actions[bot]
abbdf9574b Merge staging-next-21.05 into staging-21.05 2021-08-02 00:03:12 +00:00
github-actions[bot]
bfed1c52a9 Merge release-21.05 into staging-next-21.05 2021-08-02 00:02:34 +00:00
Robert Hensing
60c4e61a61 Merge pull request #132363 from NixOS/backport-131814-to-release-21.05
[Backport release-21.05] nixos/nix-daemon: fix registry flake type
2021-08-02 01:49:18 +02:00
David Arnold
a791442a31 nixos/nix-daemon: fix registry flake type
Before this commit, the `flake` option was typed with `types.unspecified`.

This type get's merged via [`mergeDefaultOption`](ebb592a04c/lib/options.nix (L119-L128)), which has a line
```nix
else if all isFunction list then x: mergeDefaultOption loc (map (f: f x) list)
```

`lib.isFunction` detects an attrs in the shape of `{__functor = ...}` as
a function and hence this line substitutes such attrs with a function
(f: f x).

If now, a flake input has a `__functor` as it's output, this will
coerce the once attrs to a function. This breaks a lot of things later
in the stack, for example a later `lib.filterAttrs seive <LAMBDA>` will
fail for obious reasons.

According to @infinisil, `types.unspecified` is due to deprecation. In
the meantime this PR provides a specific fix for the specific problem
discovered.

(cherry picked from commit ecae25c3ef)
2021-08-01 22:09:08 +00:00
Robert Hensing
3ed3b163aa Merge pull request #131876 from NixOS/backport-131760-to-release-21.05
[Backport release-21.05] nixos/installer: force root fs type
2021-08-01 23:06:37 +02:00
Maximilian Bosch
260df793d8 epson-escpr2: 1.1.34 -> 1.1.38
(cherry picked from commit 738f92f2ba)
2021-08-01 17:12:15 +00:00
Jörg Thalheim
c0e25740a5 linux_zen: actually enable patchset
(cherry picked from commit 604d0dd0d6)
2021-08-01 13:32:42 +00:00
Jörg Thalheim
cb52ea7042 linux_zen: 5.13.5 -> 5.13.7
(cherry picked from commit 6e9195f668)
2021-08-01 13:32:41 +00:00
github-actions[bot]
9856e7e6f2 Merge staging-next-21.05 into staging-21.05 2021-08-01 12:08:23 +00:00
github-actions[bot]
a34e238b77 Merge release-21.05 into staging-next-21.05 2021-08-01 12:04:03 +00:00
Jörg Thalheim
16bf3980bf Merge pull request #132284 from NixOS/backport-132213-to-release-21.05
[Backport release-21.05] viber: add 'QML2_IMPORT_PATH' to the wrap
2021-08-01 09:12:29 +01:00
Jörg Thalheim
c4b6bc90d9 Merge pull request #132189 from NixOS/backport-130087-to-release-21.05
[Backport release-21.05] bat: 0.18.1 -> 0.18.2
2021-08-01 09:11:55 +01:00
Jörg Thalheim
44acc5e771 Merge pull request #132204 from yu-re-ka/feature/tdesktop-2-8-11-backport
[21.05] tdesktop: 2.7.5 -> 2.8.11
2021-08-01 09:08:25 +01:00
cas1no
29e7bc3d7d viber: add 'QML2_IMPORT_PATH' to the wrap
(cherry picked from commit 3209d25fd2)
2021-08-01 07:48:15 +00:00
R. RyanTM
28340fc228 jetty: 9.4.41.v20210516 -> 9.4.43.v20210629
Closes #132133
2021-08-01 14:47:14 +07:00
Robert Scott
ca81552645 python3Packages.tensorflow: add patch fixing NotImplementedError with numpy 1.20
see upstream pr https://github.com/tensorflow/tensorflow/pull/47957

(cherry picked from commit 42bfc11356)
2021-08-01 03:41:21 +00:00
github-actions[bot]
720c9087d4 Merge staging-next-21.05 into staging-21.05 2021-08-01 00:04:25 +00:00
github-actions[bot]
63ecd177a7 Merge release-21.05 into staging-next-21.05 2021-08-01 00:03:46 +00:00
Maximilian Bosch
914fbc482e Merge pull request #132002 from sumnerevans/backport-130808-to-release-21.05
matrix-synapse: 1.38.1 -> 1.39.0
2021-07-31 22:37:48 +02:00
github-actions[bot]
d50446be40 Merge staging-next-21.05 into staging-21.05 2021-07-31 18:02:41 +00:00
github-actions[bot]
0f11de473b Merge release-21.05 into staging-next-21.05 2021-07-31 18:02:11 +00:00
Robert Scott
36dd3023be Merge pull request #131923 from NixOS/backport-131898-to-release-21.05
[Backport release-21.05] fetchmail: 6.4.16 -> 6.4.20
2021-07-31 18:08:05 +01:00
Frederik Ramcke
3142a8ca9a cairo: add patch for CVE-2020-35492 (PR: #131949)
(cherry picked from commit e591a6235d)
2021-07-31 16:18:31 +02:00
github-actions[bot]
77ce40acda Merge staging-next-21.05 into staging-21.05 2021-07-31 12:03:19 +00:00
github-actions[bot]
ae67f15901 Merge release-21.05 into staging-next-21.05 2021-07-31 12:02:46 +00:00
Yureka
3b70be46a8 gitlab: 14.0.5 -> 14.1.0
(cherry picked from commit ac20e17cc8)
2021-07-31 13:43:09 +02:00
Nick Cao
b96fa3c4c1 tdesktop: 2.8.4 -> 2.8.11
(cherry picked from commit e57ccfdaf3)
2021-07-31 12:40:26 +02:00
Michael Weiss
9b1bd6f7c7 tdesktop: Drop the enchant2 and dee dependencies
Ilya Fedin informed me that they aren't required anymore. Thanks :)

(cherry picked from commit 733756ccfc)
2021-07-31 12:40:08 +02:00
Ilan Joselevich
789b90fb34 tdesktop: 2.8.3 -> 2.8.4
(cherry picked from commit b7515545b5)
2021-07-31 12:40:08 +02:00
Michael Weiss
1d6b8ef74b tdesktop: 2.8.1 -> 2.8.3
(cherry picked from commit 3864c36b79)
2021-07-31 12:40:08 +02:00
Michael Weiss
11620afb1a kotatogram-desktop: Copy the old tg_owt.nix from tdesktop
The current tg_owt version (since the update of tdesktop to version
2.8.0 in 0d509d366d) isn't compatible with kotatogram-desktop anymore.

(cherry picked from commit f287805faf)
2021-07-31 12:40:08 +02:00
Michael Weiss
1de73b5b66 tdesktop: 2.8.0 -> 2.8.1
This also improves the packaging (see #128219).

(cherry picked from commit dc87cf5298)
2021-07-31 12:40:08 +02:00
Michael Weiss
d73ddfe782 tdesktop: 2.7.5 -> 2.8.0
(cherry picked from commit 0d509d366d)
2021-07-31 12:40:07 +02:00
Vladimír Čunát
11c662074e Merge #131892: nix-fallback-paths.nix: 2.3.14 -> 2.3.15
... into release-21.05 as a part of fixing #126141.
(I think; I don't know how often the fallback gets used in practice.)
2021-07-31 08:57:18 +02:00
06kellyjac
ea0b0e31e1 bat: 0.18.1 -> 0.18.2
(cherry picked from commit ebf9a91123ccbfaf42bbc91c5fb897bfbd4d0721)
2021-07-31 06:06:12 +00:00
github-actions[bot]
c5139eb6a1 Merge staging-next-21.05 into staging-21.05 2021-07-31 06:04:41 +00:00
Vlad M
deb02744a8 Merge pull request #129343 from NixOS/backport-129332-to-release-21.05
[Backport release-21.05] pijul: 1.0.0-alpha.48 → 1.0.0-alpha.50
2021-07-31 09:04:00 +03:00
github-actions[bot]
37ee880fe6 Merge release-21.05 into staging-next-21.05 2021-07-31 06:03:03 +00:00
Artturin
bb8978a77c openmw: add wrapQtAppsHook
dontWrapQtApps was blanket added in
5590e365e4

(cherry picked from commit 854265777ced27a1d0b1bdead26463ce021bb779)
2021-07-30 21:42:49 -04:00
github-actions[bot]
0ca91c032a Merge staging-next-21.05 into staging-21.05 2021-07-31 00:03:02 +00:00
github-actions[bot]
9e2decf274 Merge release-21.05 into staging-next-21.05 2021-07-31 00:02:22 +00:00
Samuel Dionne-Riel
c8b1c99164 Merge pull request #132073 from NixOS/backport-132046-to-release-21.05
[Backport release-21.05] nix(Stable): 2.3.14 -> 2.3.15
2021-07-30 16:50:01 -04:00
Samuel Dionne-Riel
a8d7cc1d00 Merge pull request #132162 from NixOS/backport-132100-to-release-21.05
[Backport release-21.05] linux/common-config.nix: disable LPAE on armv7l-linux
2021-07-30 16:09:01 -04:00
Ben Wolsieffer
cab8dfb6f6 linux/common-config.nix: disable LPAE on armv7l-linux
LPAE was enabled to support native armv7l builders running in QEMU on aarch64,
but this option disables support for processors which don't support LPAE, which
are still relatively common. In particular, Beaglebones use the Cortex-A8, which
doesn't support LPAE.

Also, if you attempt to boot an LPAE kernel on a CPU that doesn't support it,
it fails before even earlycon is initialized. This makes the problem difficult
to debug without enabling CONFIG_DEBUG_LL or using a hardware debugger.

(cherry picked from commit 988c12faed)
2021-07-30 19:44:27 +00:00
Sander van der Burg
84d9062180 Merge pull request #132088 from NixOS/backport-131864-to-release-21.05
[Backport release-21.05] rott: init at 1.1.2
2021-07-30 20:37:19 +02:00
Sander van der Burg
10320a355a rott: init at 1.1.2
(cherry picked from commit 946ad968ff)
2021-07-30 16:13:07 +00:00
Vladimír Čunát
de3a57327f nix(Stable): 2.3.14 -> 2.3.15
(cherry picked from commit 9bd0be76b2)
2021-07-30 13:17:54 +00:00
github-actions[bot]
f0f8138529 Merge staging-next-21.05 into staging-21.05 2021-07-30 12:02:51 +00:00
github-actions[bot]
eddb3c9d5c Merge release-21.05 into staging-next-21.05 2021-07-30 12:02:20 +00:00
Jörg Thalheim
528a5c4420 Merge pull request #132028 from NixOS/backport-132011-to-release-21.05
[Backport release-21.05] nixos/bird: fix bird/bird6 description
2021-07-30 10:40:02 +01:00
Martin Weinelt
de1bca4cb8 Merge pull request #131588 from NixOS/staging-next-21.05 2021-07-30 10:54:17 +02:00
Frederik Rietdijk
c32a9d4158 python2 and python3: build unoptimized bytecode again
In 9d03ff5222 I made the CPython builds
reproducible. This required not generating default unoptimized bytecode.
I was under the impression the optimized bytecode would be used then,
but you need to opt-in on that. Not having the default bytecode resulted
in a significant performance hit. Therefore, bytecode is generated again
in this commit, and thereby the builds are no longer reproducible.

https://bugs.python.org/issue29708
(cherry picked from commit 23e348bfe2)
2021-07-30 09:33:04 +02:00
Wael Nasreddine
703e32094c Merge pull request #131977 from NixOS/backport-129447-to-release-21.05
[Backport release-21.05] vault: fix build for darwin
2021-07-29 23:54:40 -07:00
Martin Weinelt
0c50198047 nixos/bird: fix bird/bird6 description
(cherry picked from commit d902365913)
2021-07-30 06:44:37 +00:00
github-actions[bot]
1ea742607e Merge staging-next-21.05 into staging-21.05 2021-07-30 00:03:43 +00:00
github-actions[bot]
43cf3bc049 Merge release-21.05 into staging-next-21.05 2021-07-30 00:03:06 +00:00
Robert Scott
da141a2543 python3Packages.tensorflow: 2.4.1 -> 2.4.2
(cherry picked from commit 98fa0f29bc)
2021-07-29 23:07:31 +01:00
adisbladis
15379213a4 Merge pull request #131990 from iceman-p/backport-131189-to-release-21.05
[21.05] go-ethereum: 1.10.5 -> 1.10.6
2021-07-29 16:36:49 -05:00
Sumner Evans
b784cafa84 matrix-synapse: 1.38.1 -> 1.39.0
(cherry picked from commit 2044dcf1bb)
2021-07-29 15:12:04 -06:00
Mario Rodas
c74bb01278 Merge pull request #131985 from marsam/backport-nodejs-release-21.05
[21.05] nodejs: 12.22.2 -> 12.22.4, 14.17.2 -> 14.17.4
2021-07-29 14:28:43 -05:00
R. RyanTM
cd9a630d15 go-ethereum: 1.10.5 -> 1.10.6
Hard fork is scheduled for August 4th and version on release-21.05 will
fall out of consensus.

(cherry picked from commit e661c7b92b)
2021-07-29 14:56:41 -04:00
Mario Rodas
5c93bb912e nodejs-14_x: 14.17.3 -> 14.17.4
https://github.com/nodejs/node/releases/tag/v14.17.4
(cherry picked from commit c7a1fddc2f)
2021-07-29 13:24:00 -05:00
Mario Rodas
ce18ca3fa5 nodejs-12_x: 12.22.3 -> 12.22.4
https://github.com/nodejs/node/releases/tag/v12.22.4
(cherry picked from commit 91587443b6)
2021-07-29 13:23:59 -05:00
Mario Rodas
f0546d1453 nodejs-14_x: 14.17.2 -> 14.17.3
https://github.com/nodejs/node/releases/tag/v14.17.3
(cherry picked from commit 3826b56c7e)
2021-07-29 13:23:29 -05:00
Mario Rodas
f4ebd64916 nodejs-12_x: 12.22.2 -> 12.22.3
https://github.com/nodejs/node/releases/tag/v12.22.3
(cherry picked from commit 7ad9243042)
2021-07-29 13:23:29 -05:00
Daniël de Kok
7cb947ef54 python3Packages.tensorflow: 2.4.0 -> 2.4.1
Changelog:
https://github.com/tensorflow/tensorflow/releases/tag/v2.4.1
(cherry picked from commit ef3322507a)
2021-07-29 19:21:16 +01:00
github-actions[bot]
eb280e0cf6 Merge staging-next-21.05 into staging-21.05 2021-07-29 18:02:53 +00:00
github-actions[bot]
f9b747d533 Merge release-21.05 into staging-next-21.05 2021-07-29 18:02:20 +00:00
Jason Felice
8cee48a0b2 vault, vault-bin: fix build for darwin
Closes #129443

(cherry picked from commit e0cda3708a)
2021-07-29 16:45:37 +00:00
Michael Weiss
ca137ac841 Merge pull request #131941 from NixOS/backport-131932-to-release-21.05
[Backport release-21.05] signal-desktop: 5.10.0 -> 5.11.0
2021-07-29 18:41:07 +02:00
Maximilian Bosch
6bbafdcd4e Merge pull request #131957 from NixOS/backport-131879-to-release-21.05
[Backport release-21.05] vagrant: 2.2.17 -> 2.2.18
2021-07-29 16:57:57 +02:00
Pavol Rusnak
0e9aa7d71c python3Packages.trezor: 0.12.2 -> 0.12.3
(cherry picked from commit f2821e16ac)
2021-07-29 14:26:47 +00:00
Maximilian Bosch
4dd3d35102 vagrant: 2.2.17 -> 2.2.18
ChangeLog: https://github.com/hashicorp/vagrant/blob/v2.2.18/CHANGELOG.md#2218-july-27-2021
(cherry picked from commit 9f0ced4a68)
2021-07-29 14:00:18 +00:00
github-actions[bot]
d228dbd8d8 Merge staging-next-21.05 into staging-21.05 2021-07-29 12:03:06 +00:00
github-actions[bot]
1785d7020c Merge release-21.05 into staging-next-21.05 2021-07-29 12:02:32 +00:00
Michael Weiss
d8b84d9618 signal-desktop: 5.10.0 -> 5.11.0
(cherry picked from commit ce6a51bd14)
2021-07-29 11:10:21 +00:00
Sandro
e1fbb93088 Merge pull request #131536 from chuahou/update-flameshot
flameshot: 0.10.0 -> 0.10.1
(cherry picked from commit 8963fb9ff9)
2021-07-29 18:30:54 +08:00
Ryan Horiguchi
ec25a3db05 flameshot: 0.9.0 -> 0.10.0
(cherry picked from commit 7937fefa78)
2021-07-29 18:26:20 +08:00
Vincent Haupert
e09e2140f5 github-runner: 2.278.0 -> 2.279.0
(cherry picked from commit ebac942e1c2708f02a5982dbf450ae412739cffe)
2021-07-29 10:12:31 +00:00
Vladimír Čunát
f90d817036 linuxPackages_latest.perf: fix build
Broken by kernel updates; NixPkgs master fixed this in a128e443c,
but I decided to be more conservative.
2021-07-29 11:55:38 +02:00
Harrison Houghton
85924eaaa8 bpftools: fix
At some point the name of the doc-tool script changed and we stopped
patching up the shabang line. The new one is just scripts/bpf_doc.py.

(cherry picked from commit 8997f8cc70)
2021-07-29 09:42:48 +00:00
oxalica
e675310bab stretchly: 1.6.0 -> 1.7.0
It contains a bug fix for electron process leak on every break.

https://github.com/hovancik/stretchly/issues/925
(cherry picked from commit 327e6a993f)
2021-07-29 09:42:35 +00:00
Martin Weinelt
abc2a76cb5 aspell: fix buffer overflow in objstack
Fixes: CVE-2019-25051
(cherry picked from commit 000fe8c92ccbf44c91d48235bd5ecb9773b223ed)
2021-07-29 08:54:10 +00:00
Martin Weinelt
187fa36724 fetchmail: 6.4.16 -> 6.4.20
Fixes: CVE-2021-36386
(cherry picked from commit 975a9d2e4b)
2021-07-29 07:21:14 +00:00
github-actions[bot]
5010d50240 Merge staging-next-21.05 into staging-21.05 2021-07-29 06:03:41 +00:00
github-actions[bot]
7b2fe6b372 Merge release-21.05 into staging-next-21.05 2021-07-29 06:03:06 +00:00
Mario Rodas
726a6358b9 nodejs-16_x: 16.5.0 -> 16.6.0
https://github.com/nodejs/node/releases/tag/v16.6.0
(cherry picked from commit f5de4158dd)
2021-07-29 04:20:00 +00:00
Anderson Torres
2262d7863a Merge pull request #130816 from NixOS/backport-130783-to-release-21.05
[Backport release-21.05] palemoon: 29.2.1 -> 29.3.0
2021-07-29 00:15:35 -03:00
github-actions[bot]
4e6b00de06 Merge staging-next-21.05 into staging-21.05 2021-07-29 00:03:44 +00:00
github-actions[bot]
e6c1d10f4b Merge release-21.05 into staging-next-21.05 2021-07-29 00:03:09 +00:00
Angus Trau
5570d49718 vscode-extensions.ms-vscode-remote.remote-ssh: 0.50.0 -> 0.65.7
(cherry picked from commit 0cefe482dd)
2021-07-28 23:31:15 +00:00
Martin Weinelt
c72c4650de Merge pull request #131899 from NixOS/backport-126687-to-release-21.05
[Backport release-21.05] exif: add patches for CVE-2021-27815
2021-07-29 00:41:17 +02:00
Robert Scott
33c7f751dc exif: add patches for CVE-2021-27815
(cherry picked from commit 764a102f35)
2021-07-28 22:13:23 +00:00
Martin Weinelt
2bc35baa85 Merge pull request #131290 from risicle/ris-libslirp-4.6.1-r21.05 2021-07-29 00:05:56 +02:00
Eelco Dolstra
3460fd6959 nix-fallback-paths.nix: Update to 2.3.15
(cherry picked from commit 512ee6db39)
2021-07-28 21:52:32 +00:00
Robert Scott
92760b1dce Merge pull request #131512 from risicle/ris-varnish-CVE-2021-36740
[21.05] varnish: bump, add patches for CVE-2021-36740
2021-07-28 22:36:48 +01:00
Sandro
3aeb81fd62 Merge pull request #131792 from hax404/21.05-fix-openvswitch
[21.05] nixos/openvswitch: Only include ipsecTools if using ipsec
2021-07-28 21:28:39 +00:00
Eelco Dolstra
5092dae98d Merge pull request #131837 from NixOS/backport-131831-to-release-21.05
[Backport release-21.05] nixos-rebuild: Set inherit_errexit
2021-07-28 22:53:44 +02:00
David Arnold
f6754032ee nixos/installer: force root fs type
installer media can be used on top of existing host configs. In such
scenarions, root fs types will already be defined.

Before this change, this will inevitably lead to the following error:
```console
error: The option `fileSystems./.fsType' has conflicting definition values:
       - In `/nix/store/2nl5cl4mf6vnldpbxhrbzfh0n8rsv9fm-source/DevOS/os/hardware/common.nix': "ext4"
       - In `/nix/store/jbch90yqx6gg1h3fq30jjj2b6h6jfjgs-source/nixos/modules/installer/cd-dvd/iso-image.nix': "tmpfs"
```

With this patch, the installers will override those values according to
their own local requirement.

Use `mkOverride 60` so that conscientious overriding specially targeted
at the installer, e.g. with `mkForce` is still straight forward.

(cherry picked from commit c219fdffad)
2021-07-28 20:27:51 +00:00
Franz Pletz
a1943f4729 Merge pull request #131847 from NixOS/backport-131478-to-release-21.05
[Backport release-21.05] libgrss: add patch for CVE-2016-20011
2021-07-28 21:30:23 +02:00
Franz Pletz
a3eb736f6c Merge pull request #131850 from NixOS/backport-131819-to-release-21.05
[Backport release-21.05] linux: 5.13.5 -> 5.13.6
2021-07-28 20:36:09 +02:00
Florian Klink
5d432c2453 linux: 5.13.5 -> 5.13.6
(cherry picked from commit b167e08781)
2021-07-28 18:15:47 +00:00
github-actions[bot]
13a8dfa5d5 Merge staging-next-21.05 into staging-21.05 2021-07-28 18:03:13 +00:00
github-actions[bot]
98530c2e9e Merge release-21.05 into staging-next-21.05 2021-07-28 18:02:32 +00:00
Robert Scott
e3ebd9cdb7 libgrss: add patch for CVE-2016-20011
(cherry picked from commit b50d7d0683)
2021-07-28 17:49:18 +00:00
Charlotte Van Petegem
084d0a9dce qutebrowser: 2.3.0 -> 2.3.1
(cherry picked from commit 0cdf7b5da9)
2021-07-28 19:25:29 +02:00
Franz Pletz
be037c144d Merge pull request #131805 from Atemu/backport/update/zen-kernels
[21.05] zen-kernels: update
2021-07-28 19:15:03 +02:00
Eelco Dolstra
8f5794cbda nixos-rebuild: Set inherit_errexit
Without this, failure of nixBuild() and nixFlakeBuild() was ignored
(since bash doesn't inherit 'set -e' in subshells by default), so the
script would proceed with a bogus ./result link, e.g.

  ++ readlink -f /tmp/nixos-rebuild.NfHKxx/result
  + pathToConfig='/nix/store/m7dvk6an18cpr95qn5wnig2600qhv6w7-nix-2.4pre20210727_706777a/bin/nix
  /tmp/nixos-rebuild.NfHKxx/result'
  + '[' test = switch -o test = boot ']'
  + copyToTarget '/nix/store/m7dvk6an18cpr95qn5wnig2600qhv6w7-nix-2.4pre20210727_706777a/bin/nix
  /tmp/nixos-rebuild.NfHKxx/result'
  + '[' '' = '' ']'
  + '[' test = switch -o test = boot -o test = test -o test = dry-activate ']'
  + targetHostCmd /nix/store/m7dvk6an18cpr95qn5wnig2600qhv6w7-nix-2.4pre20210727_706777a/bin/nix /tmp/nixos-rebuild.NfHKxx/result/bin/switch-to-configuration test
  + '[' -z '' ']'
  + sudo -- /nix/store/m7dvk6an18cpr95qn5wnig2600qhv6w7-nix-2.4pre20210727_706777a/bin/nix /tmp/nixos-rebuild.NfHKxx/result/bin/switch-to-configuration test
  error: '/tmp/nixos-rebuild.NfHKxx/result/bin/switch-to-configuration' is not a recognised command
  Try '/nix/store/m7dvk6an18cpr95qn5wnig2600qhv6w7-nix-2.4pre20210727_706777a/bin/nix --help' for more information.
  + echo 'warning: error(s) occurred while switching to the new configuration'
  warning: error(s) occurred while switching to the new configuration

(cherry picked from commit 0ad27c8653)
2021-07-28 16:32:56 +00:00
github-actions[bot]
b999ed3d24 Merge staging-next-21.05 into staging-21.05 2021-07-28 12:03:15 +00:00
github-actions[bot]
02ded84748 Merge release-21.05 into staging-next-21.05 2021-07-28 12:02:37 +00:00
AndersonTorres
2a9cad505d poppler: 21.05.0 -> 21.06.1
(cherry picked from commit 004970b152)
2021-07-28 11:54:48 +00:00
AndersonTorres
3c21bbebb6 poppler_0_61: cosmetical rewrite 0.61.nix
(cherry picked from commit a4e85ae2b8)
2021-07-28 11:54:48 +00:00
AndersonTorres
a47fae9c6a poppler_utils: cosmetical rewrite all-packages.nix
(cherry picked from commit 6943ac5dd7)
2021-07-28 11:54:47 +00:00
Atemu
cd82f6616f linux_zen: 5.12.19 -> 5.13.5
(cherry picked from commit caa1c955c9)
2021-07-28 13:50:45 +02:00
Atemu
55e768eefd linux_lqx: 5.12.17 -> 5.12.19
(cherry picked from commit b15b762d87)
2021-07-28 13:50:30 +02:00
Atemu
4820c77a40 linux_zen: 5.12.14 -> 5.12.19
(cherry picked from commit 349ff1b29e)
2021-07-28 13:50:30 +02:00
Atemu
3650339f63 linux_lqx: 5.12.14 -> 5.12.17
(cherry picked from commit 85f28b5c4f)
2021-07-28 13:49:17 +02:00
Jörg Thalheim
ccd782596c Merge pull request #131784 from NixOS/backport-131765-to-release-21.05
[Backport release-21.05] gpodder: fix gtk3 wrapping
2021-07-28 11:15:35 +01:00
Sander van der Burg
382039c05a Merge pull request #131785 from NixOS/backport-131735-to-release-21.05
[Backport release-21.05] ecwolf: fix compilation on darwin
2021-07-28 10:23:12 +02:00
Sander van der Burg
099ec68772 ecwolf: fix compilation on darwin
(cherry picked from commit f65e1d8793)
2021-07-28 07:48:59 +00:00
Jörg Thalheim
c4037352d1 Update pkgs/applications/audio/gpodder/default.nix
(cherry picked from commit 0f2685217c7402175988cbb2c525ab072da41904)
2021-07-28 07:14:03 +00:00
Jörg Thalheim
a16a4a91ab gpodder: fix gtk3 wrapping
(cherry picked from commit 7355b2bc3d7cb11bd8764a99f31f098ef1849143)
2021-07-28 07:14:02 +00:00
github-actions[bot]
edbd80ae97 Merge staging-next-21.05 into staging-21.05 2021-07-28 06:03:54 +00:00
github-actions[bot]
cfef8879de Merge release-21.05 into staging-next-21.05 2021-07-28 06:03:16 +00:00
ajs124
0562809586 Merge pull request #131698 from mweinelt/21.05/mysql
[21.05] mysql 8.0.22 -> 8.0.26
2021-07-28 02:24:17 +02:00
github-actions[bot]
dd8ba8e1d6 Merge staging-next-21.05 into staging-21.05 2021-07-28 00:03:16 +00:00
github-actions[bot]
cb0014146e Merge release-21.05 into staging-next-21.05 2021-07-28 00:02:37 +00:00
Sander van der Burg
ed9f1dc5c0 Merge pull request #131727 from NixOS/backport-131593-to-release-21.05
[Backport release-21.05] ecwolf: init at 1.3.3
2021-07-27 23:14:13 +02:00
Jeremy Kolb
a8a7b26adb kernel: enable MOUSE_PS2_VMMOUSE
Turns VMware guest mouse support on in the kernel. This is needed for running Wayland and non-root X in a VMWare guest. In a pre-Wayland world the `xf86-input-vmmouse` userspace driver would have handled this for us. This allows the mouse to properly work in a vmware guest (for example it can now leave the vmware window).

See: https://github.com/vmware/open-vm-tools/issues/528
(cherry picked from commit 1207e7581f)
2021-07-27 20:36:15 +00:00
Sander van der Burg
6992766507 ecwolf: init at 1.3.3
(cherry picked from commit de9913708c)
2021-07-27 19:58:15 +00:00
github-actions[bot]
7b42f47d0b Merge staging-next-21.05 into staging-21.05 2021-07-27 18:02:51 +00:00
github-actions[bot]
39ddb4745d Merge release-21.05 into staging-next-21.05 2021-07-27 18:02:15 +00:00
Michael Francis
6526d0e5c3 Only include ipsecTools if using ipsec
(cherry picked from commit adc368d2fc)
2021-07-27 19:46:56 +02:00
Martin Weinelt
e3e90d53a8 mysql80: 8.0.25 -> 8.0.26
(cherry picked from commit c3c2ca1ba0)
2021-07-27 17:24:45 +02:00
Giulio De Pasquale
457eb2fdb3 mysql 8.0.22 -> 8.0.25
(cherry picked from commit f6d3da9061)
2021-07-27 17:24:31 +02:00
Luke Granger-Brown
39a99c37d2 Merge pull request #131689 from rb2k/21_05_hg_fix
[Backport release-21.05] mercurial: use working patch links
2021-07-27 16:14:12 +01:00
Luke Granger-Brown
5ea98b810c mercurial: fix patch links again
The conclusion is that Phabricator does not, in fact, generate stable
patch links. In any case, these have landed, so we can just use the
patches from Mercurial's hgweb instance instead, which should be more
stable.

(cherry picked from commit 67444f8a39)
2021-07-27 07:55:52 -07:00
Niklas Hambüchen
0a532d8b22 Merge pull request #128818 from NixOS/backport-128546-to-release-21.05
[Backport release-21.05] kubernetes: make tests pass by fixing a conntrack-tools dep and a missing dir
2021-07-27 16:18:00 +02:00
github-actions[bot]
d97a9acfd6 Merge staging-next-21.05 into staging-21.05 2021-07-27 12:03:08 +00:00
github-actions[bot]
5d113ea732 Merge release-21.05 into staging-next-21.05 2021-07-27 12:02:35 +00:00
Sandro
1bd5157b2c Merge pull request #130829 from NixOS/backport-130273-to-release-21.05 2021-07-27 11:37:02 +00:00
github-actions[bot]
770db2f4e0 Merge staging-next-21.05 into staging-21.05 2021-07-27 06:03:10 +00:00
github-actions[bot]
0aa5191556 Merge release-21.05 into staging-next-21.05 2021-07-27 06:02:15 +00:00
Domen Kožar
82151321ee Merge pull request #129773 from pca006132/backport
[21.05] rtw89: init at 2021-07-03
2021-07-27 06:51:03 +02:00
Aaron Andersen
d935d519dc Merge pull request #131575 from NixOS/backport-131209-to-release-21.05
[Backport release-21.05] hydroxide: 0.2.18 -> 0.2.19
2021-07-26 21:32:22 -04:00
github-actions[bot]
0744732cab Merge staging-next-21.05 into staging-21.05 2021-07-27 00:03:15 +00:00
github-actions[bot]
17caed6521 Merge release-21.05 into staging-next-21.05 2021-07-27 00:02:38 +00:00
Martin Weinelt
35eedec9c2 Merge pull request #131584 from NixOS/backport-131484-to-release-21.05
[Backport release-21.05] Kernels 2021-07-25
2021-07-27 00:26:37 +02:00
Robert Scott
8d894f90d4 varnish62, varnish63: add patch for CVE-2021-36740 2021-07-26 22:19:15 +01:00
Robert Scott
88e99266e6 varnish60: 6.0.7 -> 6.0.8 2021-07-26 22:19:15 +01:00
Alyssa Ross
93ab0e3fcd apk-tools: 2.12.5 -> 2.12.6
Fixes: CVE-2021-36159
(cherry picked from commit 29475a58af)
2021-07-26 20:42:10 +00:00
github-actions[bot]
89c0dff795 Merge staging-next-21.05 into staging-21.05 2021-07-26 18:03:01 +00:00
github-actions[bot]
a5e3dc56f3 Merge release-21.05 into staging-next-21.05 2021-07-26 18:02:28 +00:00
Sander van der Burg
438263cb11 Merge pull request #131586 from svanderburg/backport-eduke32
[Backport release-21.05] eduke32: 20200907 -> 20210722
2021-07-26 19:53:01 +02:00
Martin Weinelt
d952d009b0 Merge pull request #131231 from NixOS/backport-130547-to-staging-21.05
[Backport staging-21.05] imagemagick: 7.1.0-2 -> 7.1.0-4
2021-07-26 18:36:14 +02:00
Martin Weinelt
066cc148f3 Merge pull request #131568 from NixOS/backport-131560-to-release-21.05
[Backport release-21.05] feh: 3.7 -> 3.7.1
2021-07-26 18:30:03 +02:00
TredwellGit
8b60c185fa linux_latest-libre: 18165 -> 18191
(cherry picked from commit 2004b7b08dc1d96a5603d3138545865c036a6081)
2021-07-26 15:47:29 +00:00
TredwellGit
2f7a5aa75a linux-rt_5_10: 5.10.47-rt46 -> 5.10.52-rt47
(cherry picked from commit ee688c5c0e5c5a08f292308f1c41be84604c7e43)
2021-07-26 15:47:29 +00:00
TredwellGit
92566fadc9 linux: 5.13.4 -> 5.13.5
(cherry picked from commit 286fa7b708fa932a6955b796628486c13f5fee24)
2021-07-26 15:47:28 +00:00
Sander van der Burg
6da1f11195 eduke32: 20200907 -> 20210722
(cherry picked from commit 94ac68c879)
2021-07-26 16:58:31 +02:00
R. RyanTM
e1489da3b2 hydroxide: 0.2.18 -> 0.2.19
(cherry picked from commit 23e2cf23bc)
2021-07-26 12:58:24 +00:00
github-actions[bot]
32d47b2571 Merge staging-next-21.05 into staging-21.05 2021-07-26 12:03:04 +00:00
github-actions[bot]
c0e47b56a6 Merge release-21.05 into staging-next-21.05 2021-07-26 12:02:32 +00:00
R. RyanTM
bfd24c0bd8 feh: 3.7 -> 3.7.1
(cherry picked from commit 1493f098f8)
2021-07-26 10:46:14 +00:00
Martin Weinelt
c8569c32ba Merge pull request #131546 from taku0/firefox-bin-90.0.2_release-21.05 2021-07-26 11:56:15 +02:00
misuzu
fd5d487ef4 binutils: apply R_ARM_COPY.patch only when cross-compiling to armv7l
Applying R_ARM_COPY.patch when not cross-compiling breaks native armv7l builds.

(cherry picked from commit 5aad70e8be)
2021-07-26 07:30:13 +00:00
Francesco Gazzetta
b69f8981c8 warzone2100: 4.1.0 -> 4.1.1
(cherry picked from commit 6be2cb762e)
2021-07-26 09:21:28 +02:00
Maximilian Bosch
91903ceb29 Merge pull request #131256 from NixOS/backport-131188-to-release-21.05
[Backport release-21.05] prometheus-openldap-exporter: 2.1 -> 2.1.4
2021-07-26 09:21:28 +02:00
Francesco Gazzetta
8fb41def7c warzone2100: 4.0.1 -> 4.1.0
(cherry picked from commit 299f265ce5)
2021-07-26 09:21:13 +02:00
Francesco Gazzetta
9e4f215465 warzone2100: better fix for absolute bindir
(cherry picked from commit b5b5dbb62d)
2021-07-26 09:20:38 +02:00
Maximilian Bosch
e6c441a5dc Merge pull request #131524 from NixOS/backport-131217-to-release-21.05
[Backport release-21.05] element-{web,desktop}: 1.7.31 -> 1.7.33
2021-07-26 09:13:44 +02:00
Michael Weiss
4f6946867e Merge pull request #131461 from primeos/chromium-backport
[21.05] chromium: 91.0.4472.164 -> 92.0.4515.107
2021-07-26 08:49:13 +02:00
github-actions[bot]
d3f7cf9de9 Merge staging-next-21.05 into staging-21.05 2021-07-26 06:03:30 +00:00
github-actions[bot]
0a98627383 Merge release-21.05 into staging-next-21.05 2021-07-26 06:02:57 +00:00
taku0
caf1219646 firefox: 90.0.1 -> 90.0.2
(cherry picked from commit 82feb11201)
2021-07-26 14:08:16 +09:00
taku0
1096ca11df firefox-bin: 90.0.1 -> 90.0.2
(cherry picked from commit b14e317177)
2021-07-26 14:08:16 +09:00
taku0
633edf7793 firefox: 90.0 -> 90.0.1
(cherry picked from commit 1ad4db95fb)
2021-07-26 14:08:15 +09:00
taku0
b27e930fd2 firefox-bin: 90.0 -> 90.0.1
(cherry picked from commit 928c7dbb61)
2021-07-26 14:08:15 +09:00
R. RyanTM
05309458ba erlangR23: 23.3.4.4 -> 23.3.4.5
(cherry picked from commit 53d45d04f5ba0e58bd6cc5dac23cb79f02d7a328)
2021-07-26 10:20:25 +09:00
github-actions[bot]
892702123d Merge staging-next-21.05 into staging-21.05 2021-07-26 00:03:56 +00:00
github-actions[bot]
4c48e43d39 Merge release-21.05 into staging-next-21.05 2021-07-26 00:03:19 +00:00
Maximilian Bosch
0bf820521a element-desktop: try to fix localization issues
I know that the en_EN.json vs. en-us.json is a nasty hack, but I don't
really understand where this `en-us.json` is supposed to be coming from.

(cherry picked from commit b856b19540)
2021-07-25 22:32:51 +00:00
Maximilian Bosch
a955535eae element-desktop: 1.7.31 -> 1.7.33
ChangeLogs:
* https://github.com/vector-im/element-desktop/releases/tag/v1.7.33
* https://github.com/vector-im/element-desktop/releases/tag/v1.7.32

(cherry picked from commit 07620c8697)
2021-07-25 22:32:50 +00:00
Maximilian Bosch
ac90c8d510 element-web: 1.7.31 -> 1.7.33
ChangeLogs:
* https://github.com/vector-im/element-web/releases/tag/v1.7.33
* https://github.com/vector-im/element-web/releases/tag/v1.7.33-rc.1
* https://github.com/vector-im/element-web/releases/tag/v1.7.32
* https://github.com/vector-im/element-web/releases/tag/v1.7.32-rc.1

(cherry picked from commit 040fabf509)
2021-07-25 22:32:50 +00:00
Elis Hirwing
23098f2037 Merge pull request #131501 from NixOS/backport-131483-to-release-21.05
[Backport release-21.05] phpPackages.composer: 2.1.3 -> 2.1.5
2021-07-25 22:32:27 +02:00
Thomas Gerbet
8fea6a45a0 phpPackages.composer: 2.1.3 -> 2.1.5
https://github.com/composer/composer/releases/tag/2.1.4
https://github.com/composer/composer/releases/tag/2.1.5
(cherry picked from commit 8c59a77a04)
2021-07-25 18:21:48 +00:00
github-actions[bot]
e6ee5601f9 Merge staging-next-21.05 into staging-21.05 2021-07-25 18:03:16 +00:00
github-actions[bot]
0693039bd8 Merge release-21.05 into staging-next-21.05 2021-07-25 18:01:59 +00:00
R. RyanTM
2ed8950cb1 containerd: 1.5.2 -> 1.5.4
(cherry picked from commit 4d6cdf3550c45621749d6dd6747065e1a4f25baa)
2021-07-25 17:51:04 +00:00
adisbladis
ecd1adcea0 Merge pull request #130579 from NixOS/backport-127145-to-release-21.05
[Backport release-21.05] containerd: 1.5.1 -> 1.5.2
2021-07-25 12:43:16 -05:00
Robert Schütz
9317b77a1d imagemagick6: 6.9.12-17 -> 6.9.12-19
(cherry picked from commit 3bb091640bc7deb719759deab43cd2e206520b2a)
2021-07-25 16:31:55 +02:00
OPNA2608
f6f4c4ac26 soundtracker: Fix on Darwin
(cherry picked from commit ade48138df)
2021-07-25 13:37:25 +00:00
Francesco Gazzetta
9cd2c7a627 soundtracker: 1.0.1 -> 1.0.2.1
(cherry picked from commit 7cc5590b92)
2021-07-25 13:37:25 +00:00
Luke Granger-Brown
cf2e6fa8dd Merge pull request #131456 from NixOS/backport-125946-to-release-21.05
[Backport release-21.05] docker: 20.10.6 -> 20.10.7
2021-07-25 14:02:24 +01:00
Ryan Mulligan
807a22965a Merge pull request #130303 from NixOS/backport-128633-to-release-21.05
[Backport release-21.05] discord: fix updater script
2021-07-25 05:57:33 -07:00
github-actions[bot]
48b0dbb885 Merge staging-next-21.05 into staging-21.05 2021-07-25 12:02:56 +00:00
github-actions[bot]
46a3e2b42d Merge release-21.05 into staging-next-21.05 2021-07-25 12:02:20 +00:00
Michael Weiss
37eae1967a Merge pull request #131363 from oxalica/fix/tdesktop-voice-chat-backport
[21.05] tdesktop: fix calls, dlopen and bundle fonts
2021-07-25 13:21:02 +02:00
Michael Weiss
4e8d55ce61 nixos/tests/chromium: Drop the workaround for Chrome GPU crashes
This regression was fixed by 51d83077ff.

(cherry picked from commit 4ec2b24603)
2021-07-25 13:04:53 +02:00
Michael Weiss
6dbb8d5098 nixos/tests/chromium: Check the version and that it's an official build
This also prints and screenshots the output of chrome://version which
contains useful information.

Outputs (stable, beta, ungoogled, chrome-stable, chrome-beta, chrome-dev):
Chromium	92.0.4515.107 (Official Build) (64-bit)
Chromium        92.0.4515.107 (Official Build) (64-bit)
Chromium        91.0.4472.164 (Official Build, ungoogled-chromium) (64-bit)
Google Chrome   92.0.4515.107 (Official Build) (64-bit)
Google Chrome   92.0.4515.107 (Official Build) beta (64-bit)
Google Chrome   93.0.4577.8 (Official Build) dev (64-bit)

(cherry picked from commit 7b3c054514)
2021-07-25 13:04:52 +02:00
Michael Weiss
8b75191bea chromium: Fix the Ozone/Wayland support
The stable channel update to M92 (97570d30c7) broke the Wayland support:
$ chromium --enable-features=UseOzonePlatform --ozone-platform=wayland
[31712:31712:0721/114725.940557:ERROR:wayland_connection.cc(137)] Failed to load wayland client libraries.
[31712:31712:0721/114725.940641:FATAL:ozone_platform_wayland.cc(177)] Failed to initialize Wayland platform
[0721/114725.947566:ERROR:process_memory_range.cc(75)] read out of range
Trace/breakpoint trap (core dumped)

(cherry picked from commit bb651d27fd)
2021-07-25 13:04:11 +02:00
Michael Weiss
a04e7e7ee4 chromium: 91.0.4472.164 -> 92.0.4515.107
https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop_20.html

This update includes 35 security fixes.

CVEs:
CVE-2021-30565 CVE-2021-30566 CVE-2021-30567 CVE-2021-30568
CVE-2021-30569 CVE-2021-30571 CVE-2021-30572 CVE-2021-30573
CVE-2021-30574 CVE-2021-30575 CVE-2021-30576 CVE-2021-30577
CVE-2021-30578 CVE-2021-30579 CVE-2021-30580 CVE-2021-30581
CVE-2021-30582 CVE-2021-30583 CVE-2021-30584 CVE-2021-30585
CVE-2021-30586 CVE-2021-30587 CVE-2021-30588 CVE-2021-30589

Note: This won't be the smoothest update. Chromium seems to be fine but
requires gtk3 in $LD_LIBRARY_PATH to find libgtk-3.so.0 (otherwise it
crashes during startup) but Google Chrome fails to initialize
("GPU process exited unexpectedly: exit_code=132") and requires
"--use-gl=angle --use-angle=swiftshader" for hardware(?) acceleration
(which seems to work work fine and performant but SwiftShader should
actually use the CPU instead of the GPU).

(cherry picked from commit 97570d30c7)
2021-07-25 13:04:11 +02:00
Mark Vainomaa
ae97d0fb4d docker: add @mikroskeem to maintainers
(cherry picked from commit e2b28504ab)
2021-07-25 10:32:11 +00:00
Mark Vainomaa
867a90866e docker: narrow patchShebangs
(cherry picked from commit fc38adafea)
2021-07-25 10:32:11 +00:00
Mark Vainomaa
66b051a576 docker: enable buildx support by default
(cherry picked from commit 2c7bdb05de)
2021-07-25 10:32:11 +00:00
Mark Vainomaa
405f6e41f8 docker: improve readability, drop unneeded substitutes
(cherry picked from commit 1553e742f5)
2021-07-25 10:32:10 +00:00
Mark Vainomaa
3d0968b53e docker: 20.10.6 -> 20.10.7
(cherry picked from commit ff2c16095d)
2021-07-25 10:32:10 +00:00
Michael Weiss
52e4b484ca Merge pull request #131453 from primeos/chromium-backport
[21.05] Backport the test improvements for Chromium (+ wrapper fix)
2021-07-25 12:23:26 +02:00
Luke Granger-Brown
2a947f5987 Merge pull request #131436 from NixOS/backport-131394-to-release-21.05
[Backport release-21.05] apache-directory-studio: 2.0.0-M15 -> 2.0.0-M17
2021-07-25 10:52:16 +01:00
Luke Granger-Brown
b74321f81d Merge pull request #131451 from NixOS/backport-131377-to-release-21.05
[Backport release-21.05] lrzsz: add patch for CVE-2018-10195
2021-07-25 10:48:09 +01:00
Michael Weiss
2eaf9b409a chromium: Check the text rendering
This should catch regressions like #131074 in the future. In that case a
glibc update caused a regression that caused most of the text to become
invisible (just not the "Web Store" we've already been checking for).

(cherry picked from commit 11400dcd65)
2021-07-25 11:37:57 +02:00
Michael Weiss
24599a5ba6 nixos/tests/chromium: Print the content of chrome://{sandbox,gpu}
This can be very useful when running the test headless or e.g. when
looking at Hydra logs. Especially the chrome://gpu content contains a
lot of interesting information.
I also decided to refactor the test_new_win() function to avoid
duplicate code and rely less on xdo.

(cherry picked from commit c33015a0c9)
2021-07-25 11:37:57 +02:00
Michael Weiss
90e44d2f1c nixos/tests/chromium: Refactor launching the browser process
It should now be more flexible and less error-prone.

(cherry picked from commit 8c52061b1f)
2021-07-25 11:37:57 +02:00
Michael Weiss
a20f9eb0ec nixos/tests/chromium: Fix the test for M92+
Unfortunately there are some regressions in the GPU code that cause
Chromium and Google Chrome to crash, e.g.:
machine # [0709/084047.890436:ERROR:process_memory_range.cc(75)] read out of range[   30.153484] show_signal: 20 callbacks suppressed
machine # [   30.153490] traps: chrome[1036] trap invalid opcode ip:55af03357b29 sp:7ffeaa69ad10 error:0 in chrome[55aefe7a4000+81ec000]
machine #
machine # [0709/084047.955039:ERROR:file_io_posix.cc(144)] open /sys/devices/system/cpu/cpu0/cpufreq/scaling_cur_freq: No such file or directory (2)
machine # [0709/084047.955078:ERROR:file_io_posix.cc(144)] open /sys/devices/system/cpu/cpu0/cpufreq/scaling_max_freq: No such file or directory (2)
machine # [   30.126905] systemd[1]: Created slice system-systemd\x2dcoredump.slice.
machine # [   30.137012] systemd[1]: Started Process Core Dump (PID 1038/UID 0).
machine # [   30.571987] systemd-coredump[1039]: Process 1036 (chrome) of user 1000 dumped core.
machine # [992:1021:0709/084048.501937:ERROR:gpu_process_host.cc(995)] GPU process exited unexpectedly: exit_code=132
machine # [   30.594747] systemd[1]: systemd-coredump@0-1038-0.service: Succeeded.

Hopefully this'll be fixed upstream before the final release (there are
bug reports for it) but for the meantime we have to launch the beta and
dev versions with "--use-gl=angle --use-angle=swiftshader".

(cherry picked from commit f9645002a2)
2021-07-25 11:37:56 +02:00
sternenseemann
3e6648699f chromium: move ed and makeWrapper into nativeBuildInputs
This most notably fixes cross _evaluation_ of chromium which previously
would fail because makeWrapper relies on runtimeShell which is not
available in the HostTarget package set.

I tested that the native chromium build still works, but haven't tried
cross compiling it yet. There very well may be additional errors, but at
least they will be build errors, not hard to understand evaluation
errors.

(cherry picked from commit 524aa1c87c)
2021-07-25 11:37:56 +02:00
Michael Weiss
40325d6d4a Merge pull request #131449 from primeos/chromium-backport
[21.05] Preparations for backporting Chromium M92
2021-07-25 11:37:34 +02:00
Luke Granger-Brown
b3ba3fa85e Merge pull request #131448 from NixOS/backport-130320-to-release-21.05
[Backport release-21.05] firecracker: 0.24.3 -> 0.24.4
2021-07-25 10:35:41 +01:00
Luke Granger-Brown
5122cec8cb Merge pull request #131447 from NixOS/backport-131440-to-release-21.05
[Backport release-21.05] google-chrome: add pciutils dep to avoid GPU process crashing
2021-07-25 10:35:32 +01:00
Robert Scott
edf50c4c2b lrzsz: add patch for CVE-2018-10195
provide gettext because modifying source files triggers
localization regeneration

(cherry picked from commit edc01d05a9)
2021-07-25 09:30:22 +00:00
Luke Granger-Brown
1eafebd452 Merge pull request #125927 from NixOS/backport-125761-to-release-21.05
[Backport release-21.05] gnome.gnome-calendar: 40.1 -> 40.2
2021-07-25 10:15:46 +01:00
Luke Granger-Brown
e506b846c2 Merge pull request #125928 from NixOS/backport-125752-to-release-21.05
[Backport release-21.05] epiphany: 40.1 -> 40.2
2021-07-25 10:15:36 +01:00
Luke Granger-Brown
4d03ae59fb Merge pull request #125851 from NixOS/backport-125569-to-release-21.05
[Backport release-21.05] gupnp: apply the patch for CVE-2021-33516
2021-07-25 10:15:30 +01:00
Danielle Lancashire
507eabd549 firecracker: 0.24.3 -> 0.24.4
Updated firecracker to v0.24.4. This required updating the buildPhase to
point to new compilation result paths.

Formatting changes were performed by `nix-update --format`

(cherry picked from commit 6fc6e325e6)
2021-07-25 09:15:24 +00:00
Luke Granger-Brown
31d8fc0b52 Merge pull request #125924 from NixOS/backport-125774-to-release-21.05
[Backport release-21.05] gnome.gnome-boxes: 40.1 -> 40.2
2021-07-25 10:15:13 +01:00
Luke Granger-Brown
10282fa17b Merge pull request #125925 from NixOS/backport-125771-to-release-21.05
[Backport release-21.05] gnome.gnome-software: 40.1 -> 40.2
2021-07-25 10:15:07 +01:00
Luke Granger-Brown
2267d4b801 Merge pull request #125926 from NixOS/backport-125757-to-release-21.05
[Backport release-21.05] evolution-data-server: 3.40.1 -> 3.40.2
2021-07-25 10:14:54 +01:00
Luke Granger-Brown
17b1b28402 Merge pull request #130978 from NixOS/backport-124799-to-release-21.05
[Backport release-21.05] nixos/unbound: fix define-tag option
2021-07-25 10:14:27 +01:00
Michael Weiss
a45acbc8e3 chromium: remove bendlas as maintainer
Their last Chromium commit is a52d7674cc from 2019.
Thank you for maintaining Chromium in the past.

(cherry picked from commit d4612af2c0)
2021-07-25 11:12:33 +02:00
Michael Weiss
9ede7cd91b chromiumDev: 93.0.4573.0 -> 93.0.4577.8
(cherry picked from commit 503dc62d04)
2021-07-25 11:12:32 +02:00
Michael Weiss
03f1833d1a chromiumBeta: 92.0.4515.101 -> 92.0.4515.107
(cherry picked from commit 5c6608144f)
2021-07-25 11:12:32 +02:00
Michael Weiss
741f8416c7 chromium: get-commit-message.py: Improve the parsing
The current stable release announcement [0] uses more HTML tags which
broke the detection of "fixes" and "zero_days". Proper HTML parsing
could be done using html.parser [1] but for our purposes the naive regex
trick works well enough.

[0]: https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop.html
[1]: https://docs.python.org/3/library/html.parser.html

(cherry picked from commit 3e93811d93)
2021-07-25 11:12:31 +02:00
Michael Weiss
affa0971db chromiumBeta: 92.0.4515.93 -> 92.0.4515.101
(cherry picked from commit b22b804e67)
2021-07-25 11:12:30 +02:00
Michael Weiss
4857d71209 chromiumDev: 93.0.4557.4 -> 93.0.4573.0
(cherry picked from commit 96a3799050)
2021-07-25 11:12:30 +02:00
Michael Weiss
fe5ef8dbc0 chromiumBeta: 92.0.4515.80 -> 92.0.4515.93
(cherry picked from commit a571f3a945)
2021-07-25 11:12:29 +02:00
Luke Granger-Brown
3af6b9cbe6 Merge pull request #130289 from NixOS/backport-123291-to-release-21.05
[Backport release-21.05] docker: 20.10.2 -> 20.10.6
2021-07-25 10:12:27 +01:00
Michael Weiss
9f9708fac7 chromiumBeta: Install crashpad_handler
This executable is required to fix a startup error.
TODO: Refactor the Nix expressions to allow chromiumVersionAtLeast, etc.
"everywhere" and investigate the VM test failure.

(cherry picked from commit ef7f020ec8)
2021-07-25 11:10:07 +02:00
Michael Weiss
1728c037de chromiumBeta: 92.0.4515.70 -> 92.0.4515.80
(cherry picked from commit 11237c7d83)
2021-07-25 11:10:06 +02:00
Michael Weiss
c0a0749d1c chromiumDev: 93.0.4549.3 -> 93.0.4557.4
Would need to temporarily remove "ffmpeg" from gnSystemLibraries and
disable use_thin_lto to fix the build (theoretically).

(cherry picked from commit 5cae434566)
2021-07-25 11:10:06 +02:00
Michael Weiss
9c2bdffc2a chromiumDev: Fix build errors due to the older system FFmpeg
The final linking still fails though, even with llvm-git.
We might have to diable use_thin_lto for now:
ld.lld: error: undefined symbol: snappy::Compress(char const*, unsigned long, std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> >*)
>>> referenced by compression_module.cc
>>>               thinlto-cache/Thin-ed5ed5.tmp.o:(reporting::CompressionModule::CompressRecord(std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> >, base::OnceCallback<void (std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> >, absl::optional<reporting::CompressionInformation>)>) const)
clang-13: error: linker command failed with exit code 1 (use -v to see invocation)

(cherry picked from commit fcdcb81936)
2021-07-25 11:10:05 +02:00
Michael Weiss
d6b4569f80 chromiumBeta: 92.0.4515.59 -> 92.0.4515.70
(cherry picked from commit e829ab8d65)
2021-07-25 11:10:04 +02:00
Michael Weiss
04accba48c chromiumDev: 93.0.4542.2 -> 93.0.4549.3
(cherry picked from commit c8fe353d8b)
2021-07-25 11:10:04 +02:00
Michael Weiss
4ee0ab1564 chromiumDev: Fix building from the release tarball
See https://bugs.chromium.org/p/chromium/issues/detail?id=1215229.
Before this the build failed with this error:
[101/47617] ACTION //build/util:chromium_git_revision(//build/toolchain/linux/unbundle:default)oaded_data.pbchain/linux/unbundle:default)
FAILED: gen/build/util/chromium_git_revision.h
python3 ../../build/util/lastchange.py --header gen/build/util/chromium_git_revision.h --revision-id-only --revision-id-prefix @ -m\ CHROMIUM_GIT_REVISION
ERROR:root:Failed to get git top directory from '/build/chromium-93.0.4542.2/build/util': Git command 'git git rev-parse --show-toplevel' in /build/chromium-93.0.4542.2/build/util failed: [Errno 2] No such file or directory: 'git'

(cherry picked from commit 8af443906d)
2021-07-25 11:10:03 +02:00
Michael Weiss
dcf696ee71 chromiumBeta: 92.0.4515.51 -> 92.0.4515.59
(cherry picked from commit 28b48376b9)
2021-07-25 11:10:02 +02:00
Michael Weiss
08c330473e chromiumDev: 93.0.4535.3 -> 93.0.4542.2
(cherry picked from commit 0876f689d7)
2021-07-25 11:10:02 +02:00
Michael Weiss
385d6c0d60 chromiumBeta: 92.0.4515.40 -> 92.0.4515.51
(cherry picked from commit 558cb984de)
2021-07-25 11:10:01 +02:00
Luke Granger-Brown
2cc557dcae Merge pull request #129171 from eduardosm/seafile
[Backport release-21.05] seafile-shared: 8.0.1 -> 8.0.3, seafile-client: 8.0.1 -> 8.0.3
2021-07-25 10:07:45 +01:00
Luke Granger-Brown
43aa33d9c2 google-chrome: avoid crash under some situations
If our Chrome derivation is Vulkan enabled, the Chrome GPU process
reliably crashes for me under M92 using the proprietary Nvidia drivers.
This is because the PCI-based GPU detection path fails, and we attempt
to use the Vulkan fallback instead, which then crashes(!!)

Including libpci allows us to use Angle's
src/gpu_info_util/SystemInfo_libpci.cpp path instead, which doesn't
crash, unlike src/gpu_info_util/SystemInfo_vulkan.cpp.

(cherry picked from commit 51d83077ff)
2021-07-25 09:06:09 +00:00
Luke Granger-Brown
01c8ed0ba0 Merge pull request #131438 from angustrau/backport-zoom-us-5.7.28852.0718
[21.05] zoom-us: 5.7.26030.0627 -> 5.7.28852.0718
2021-07-25 09:31:33 +01:00
Angus Trau
ae6a552c88 zoom-us: 5.7.26030.0627 -> 5.7.28852.0718
(cherry picked from commit c2461f0d67)
2021-07-25 17:35:48 +10:00
Martin Weinelt
31f84bb17a apache-directory-studio: 2.0.0-M15 -> 2.0.0-M17
(cherry picked from commit 6d318b6585c5b12244c91b82e12c732356e4959a)
2021-07-25 07:20:10 +00:00
Vladimír Čunát
719e9f31c2 Merge #130786: mesa: 21.0.1 -> 21.1.4 (into staging-21.05) 2021-07-25 07:50:04 +02:00
ash lea
af428afe37 mesa: fix datadir location
(cherry picked from commit 9bf469e6488b5835ac83ccc5ca7f7f63c1f7a0dd)
2021-07-24 19:26:46 -07:00
github-actions[bot]
7533ec9452 Merge staging-next-21.05 into staging-21.05 2021-07-24 18:03:34 +00:00
github-actions[bot]
1a9a78fa43 Merge release-21.05 into staging-next-21.05 2021-07-24 18:02:18 +00:00
Daneel S. Yaitskov
973910f5c3 override ap-normalize version with 0.1.0.1 (#130946)
haskellPackages.ap-normalize: 0.1.0.0 -> 0.1.0.1

Co-authored-by: Daniil Iaitskov <daniil.iaitskov@soostone.com>
Co-authored-by: sternenseemann <0rpkxez4ksa01gb3typccl0i@systemli.org>
2021-07-24 14:56:18 +02:00
github-actions[bot]
5210d03fca Merge staging-next-21.05 into staging-21.05 2021-07-24 12:03:14 +00:00
github-actions[bot]
9814d5da91 Merge release-21.05 into staging-next-21.05 2021-07-24 12:02:33 +00:00
Oleksii Filonenko
9f4966b7e1 Merge pull request #131240 from NixOS/backport-129451-to-release-21.05
[Backport release-21.05] hugo: 0.84.4 -> 0.85.0
2021-07-24 13:50:53 +03:00
Michele Guerini Rocco
ccae2fed21 Merge pull request #131214 from rnhmjoj/staging-21.05
[21.05] kbd: update search-paths.patch
2021-07-24 09:50:17 +02:00
davidak
537678cb1e Merge pull request #131211 from NixOS/backport-130814-to-release-21.05
[Backport release-21.05] man-pages: 5.11 -> 5.12
2021-07-24 08:14:20 +02:00
github-actions[bot]
b0b24df92d Merge staging-next-21.05 into staging-21.05 2021-07-24 00:03:36 +00:00
github-actions[bot]
d25f52a1e6 Merge release-21.05 into staging-next-21.05 2021-07-24 00:02:56 +00:00
zowoq
1fc8847792 libslirp: 4.6.0 -> 4.6.1
https://gitlab.freedesktop.org/slirp/libslirp/-/releases/v4.6.1
(cherry picked from commit 7ce24d4b85)
2021-07-24 00:38:20 +01:00
zowoq
94cc94a40c libslirp: 4.5.0 -> 4.6.0
https://gitlab.freedesktop.org/slirp/libslirp/-/releases/v4.6.0
(cherry picked from commit 8d25d8c55d)
2021-07-24 00:37:13 +01:00
Graham Christensen
1a52f18432 Merge pull request #131287 from NixOS/backport-131266-to-release-21.05
[Backport release-21.05] webkitgtk: 2.32.1 -> 2.32.3
2021-07-23 19:29:06 -04:00
Philipp Bartsch
ea8fc4327f webkitgtk: 2.32.1 -> 2.32.3
Relevant security advisory:
https://webkitgtk.org/security/WSA-2021-0004.html

CVEs:
CVE-2021-1817,  CVE-2021-1820,  CVE-2021-1825,  CVE-2021-1826,
CVE-2021-21775, CVE-2021-21779, CVE-2021-21806, CVE-2021-30661,
CVE-2021-30663, CVE-2021-30665, CVE-2021-30666, CVE-2021-30682,
CVE-2021-30689, CVE-2021-30720, CVE-2021-30734, CVE-2021-30744,
CVE-2021-30749, CVE-2021-30758, CVE-2021-30761, CVE-2021-30762,
CVE-2021-30795, CVE-2021-30797, CVE-2021-30799

(cherry picked from commit 3bb38198e9)
2021-07-23 23:09:31 +00:00
github-actions[bot]
9860c61f4f Merge staging-next-21.05 into staging-21.05 2021-07-23 18:02:56 +00:00
github-actions[bot]
967de8a3ae Merge release-21.05 into staging-next-21.05 2021-07-23 18:02:22 +00:00
Maximilian Bosch
91c154210e Merge pull request #131251 from NixOS/backport-131215-to-release-21.05
[Backport release-21.05] grocy: 3.0.1 -> 3.1.0
2021-07-23 18:45:55 +02:00
oxalica
18f9a94bcd tdesktop: bundle the default font
It's worth to think about setting -DDESKTOP_APP_USE_PACKAGED_FONTS=OFF
since it's impossible to install fonts as dependencies of packages with
Nix and tdesktop's widgets are developed only with Open Sans in mind (it
has a lot of hardcoded values and wide fonts like DejaVu may
even go out of widgets' bounds)

https://github.com/NixOS/nixpkgs/pull/130827#issuecomment-885212649
(cherry picked from commit 27585b9897)
2021-07-24 00:43:50 +08:00
Maximilian Bosch
3192d960ae prometheus-openldap-exporter: 2.1 -> 2.1.4
ChangeLogs:
* https://github.com/tomcz/openldap_exporter/releases/tag/v2.1.1
* https://github.com/tomcz/openldap_exporter/releases/tag/v2.1.2
* https://github.com/tomcz/openldap_exporter/releases/tag/v2.1.3
* https://github.com/tomcz/openldap_exporter/releases/tag/v2.1.4

(cherry picked from commit c078dbc307)
2021-07-23 16:43:18 +00:00
oxalica
e0952c6afd tdesktop: patch dlopen paths
(cherry picked from commit 6019d8abff)
2021-07-24 00:42:00 +08:00
oxalica
0006f72f88 tdesktop: use bundled libtgvoip
(cherry picked from commit 2a12ba467c)
2021-07-24 00:36:52 +08:00
Jonathan Ringer
cab2d34df6 zfsUnstable: 2.1.0-rc8 -> 2.1.0
(cherry picked from commit 6f1b155d37)
2021-07-23 09:19:24 -07:00
TredwellGit
02552c7074 zfsUnstable: 2.1.0-rc7 -> 2.1.0-rc8
https://github.com/openzfs/zfs/releases/tag/zfs-2.1.0-rc8
(cherry picked from commit 5ef8322daa)
2021-07-23 09:19:24 -07:00
TredwellGit
5841063b6c zfsUnstable: 2.1.0-rc6 -> 2.1.0-rc7
https://github.com/openzfs/zfs/releases/tag/zfs-2.1.0-rc7
(cherry picked from commit eeb255207d)
2021-07-23 09:19:24 -07:00
TredwellGit
ddb061d9a4 zfsUnstable: 2.1.0-rc5 -> 2.1.0-rc6
https://github.com/openzfs/zfs/releases/tag/zfs-2.1.0-rc6
(cherry picked from commit 917884725d)
2021-07-23 09:19:24 -07:00
Maximilian Bosch
e94b0c2a22 grocy: 3.0.1 -> 3.1.0
ChangeLog: https://github.com/grocy/grocy/releases/tag/v3.1.0
(cherry picked from commit 07b51f58df)
2021-07-23 15:57:43 +00:00
Luflosi
e2aab2ed33 ipfs: 0.9.0 -> 0.9.1
https://github.com/ipfs/go-ipfs/releases/tag/v0.9.1
(cherry picked from commit 7a4b26853a)
2021-07-23 08:49:15 -07:00
Luflosi
576fd29e84 ipfs: install ipfs-hardened.service as well
This will be useful for hardening the IPFS NixOS module in the future.

(cherry picked from commit ad34c7697a)
2021-07-23 08:49:15 -07:00
R. RyanTM
87c348a890 hugo: 0.84.4 -> 0.85.0
(cherry picked from commit fc956a6d2c)
2021-07-23 13:54:21 +00:00
Sandro
fa6a56bf12 Merge pull request #131234 from NixOS/backport-129138-to-release-21.05
[Backport release-21.05] hugo: 0.84.3 -> 0.84.4
2021-07-23 15:12:25 +02:00
R. RyanTM
f1e98f91f7 hugo: 0.84.3 -> 0.84.4
(cherry picked from commit 93a665e66d)
2021-07-23 12:43:26 +00:00
Sandro
13783058ec Merge pull request #130961 from NixOS/backport-128725-to-release-21.05 2021-07-23 14:33:30 +02:00
Vladimír Čunát
2e65ac6695 Merge #130529: llvmPackages_12: 12.0.0 -> 12.0.1
...into staging-21.05
2021-07-23 14:28:19 +02:00
Kerstin Humm
4e7285921e imagemagick: 7.1.0-2 -> 7.1.0-4
(cherry picked from commit 937dae1dad)
2021-07-23 12:10:50 +00:00
github-actions[bot]
3da4cec89e Merge staging-next-21.05 into staging-21.05 2021-07-23 12:03:20 +00:00
github-actions[bot]
c67b0ef366 Merge release-21.05 into staging-next-21.05 2021-07-23 12:02:35 +00:00
Maximilian Bosch
b5ac68f7e8 Merge pull request #131219 from NixOS/backport-129732-to-release-21.05
[Backport release-21.05] nextcloud: remove expires header
2021-07-23 13:02:58 +02:00
Valentin Conrad
6a09c14a33 nextcloud: remove expires header
nextcloud default nginx config did not include the expires config
see: https://docs.nextcloud.com/server/latest/admin_manual/installation/nginx.html

(cherry picked from commit ceef268c4b)
2021-07-23 10:33:24 +00:00
Azure Zanculmarktum
b9d9d2901f kbd: update search-paths.patch
Backport of 6f89feaedd
2021-07-23 11:51:10 +02:00
Alyssa Ross
e7c07d8edb man-pages: 5.11 -> 5.12
Build system has changed slightly, necessitating the change in makeFlags.

(cherry picked from commit a05062d0dd)
2021-07-23 09:37:19 +00:00
Alyssa Ross
54ed469293 squashfs-tools-ng: 1.1.1 -> 1.1.2
tar2sqfs seems to work on the source tarball.

(cherry picked from commit bbdf2e931a)
2021-07-23 09:31:22 +00:00
Artturin
91469eef74 hplip: add -n to gzip to improve reproducibility
(cherry picked from commit 1422563f54)
2021-07-23 08:47:04 +00:00
Artturin
607be851e4 hplip: hardcode ppdc path to fix #44230
the ppdc: Warning - overlapping filename can be ignored
https://bugs.launchpad.net/hplip/+bug/1756967

(cherry picked from commit 46c7445c34)
2021-07-23 08:47:04 +00:00
Artturin
e2770d3b95 virtscreen: unbreak
(cherry picked from commit 5871962ba5)
2021-07-23 08:44:05 +00:00
Maximilian Bosch
ec06d6e70f Merge pull request #131192 from NixOS/backport-131153-to-release-21.05
[Backport release-21.05] bemenu: 0.6.2 -> 0.6.3
2021-07-23 10:41:01 +02:00
R. RyanTM
5e8e24e6ba bemenu: 0.6.2 -> 0.6.3
(cherry picked from commit d10ccb2b33)
2021-07-23 08:20:58 +00:00
TredwellGit
ed0a5e1d81 libreoffice-fresh: 7.1.3.2 -> 7.1.4.2
(cherry picked from commit b1db7c902b)
2021-07-23 07:06:52 +00:00
Maxine Aubrey
cdda69f6b7 networkmanager: 1.30.4 -> 1.30.6 2021-07-23 02:20:26 +02:00
github-actions[bot]
0418a54ab8 Merge staging-next-21.05 into staging-21.05 2021-07-23 00:03:14 +00:00
github-actions[bot]
6dfb0d0f39 Merge release-21.05 into staging-next-21.05 2021-07-23 00:02:40 +00:00
Luke Granger-Brown
bf12f607af Merge pull request #130726 from NixOS/backport-128879-to-release-21.05
[Backport release-21.05] jetbrains: updates
2021-07-22 20:19:41 +01:00
Sumner Evans
2c3f0793dd matrix-synapse: 1.38.0 -> 1.38.1
(cherry picked from commit d9b7e47007)
2021-07-22 11:48:28 -07:00
github-actions[bot]
9d4289de18 Merge staging-next-21.05 into staging-21.05 2021-07-22 18:02:48 +00:00
github-actions[bot]
8c1d120aa9 Merge release-21.05 into staging-next-21.05 2021-07-22 18:02:15 +00:00
Maximilian Bosch
e4f95387e2 Merge pull request #131086 from NixOS/backport-128649-to-release-21.05
[Backport release-21.05] zsh: fix nixUnstable completions
2021-07-22 18:30:20 +02:00
Bernardo Meurer
468689615b Merge pull request #130456 from uvNikita/backport-steam-runtime-20210630
[Backport release-21.05] steamPackages.steam-runtime: 20210527.0 -> 20210630.0
2021-07-22 09:23:49 -07:00
Sander van der Burg
5b526c90ca Merge pull request #130992 from svanderburg/backport-lha
[Backport release-21.05] lha: init at 2021-07-01
2021-07-22 18:14:27 +02:00
Timothy DeHerrera
6322c5baf7 zsh: include completions for nix-* commands
(cherry picked from commit 6dbf8c0409)
2021-07-22 14:29:13 +00:00
Timothy DeHerrera
b16eb24c4d zsh: format module with nixpkgs-fmt
(cherry picked from commit 9ad645dce8)
2021-07-22 14:29:13 +00:00
Timothy DeHerrera
a37709b232 zsh: remove conflicting nixUnstable completions
(cherry picked from commit d687fe88fd)
2021-07-22 14:29:13 +00:00
github-actions[bot]
0676ba181a Merge staging-next-21.05 into staging-21.05 2021-07-22 12:03:06 +00:00
github-actions[bot]
2f87f0af26 Merge release-21.05 into staging-next-21.05 2021-07-22 12:02:28 +00:00
Michael Weiss
fd6da5164a Merge pull request #131056 from NixOS/backport-131053-to-release-21.05
[Backport release-21.05] signal-desktop: 5.9.0 -> 5.10.0
2021-07-22 13:47:52 +02:00
Sander van der Burg
d240845bbb lha: init at 2021-07-01
(cherry picked from commit c450894477)
2021-07-22 13:47:25 +02:00
Mario Rodas
153334b225 Merge pull request #131052 from NixOS/backport-131015-to-release-21.05
[Backport release-21.05] redis: 6.2.4 -> 6.2.5
2021-07-22 06:36:23 -05:00
Michael Weiss
bdf036229a signal-desktop: 5.9.0 -> 5.10.0
(cherry picked from commit 8c1f8ac915)
2021-07-22 10:50:12 +00:00
Sandro
2b651977aa Merge pull request #131010 from asbachb/backport/openjdk11 2021-07-22 12:21:30 +02:00
Mario Rodas
43c41565f7 redis: 6.2.4 -> 6.2.5
https://github.com/redis/redis/releases/tag/6.2.5
(cherry picked from commit b155b06e1d)
2021-07-22 10:05:13 +00:00
Robert Hensing
348a2aaee0 Merge pull request #130952 from NixOS/backport-129574-to-release-21.05
[Backport release-21.05] nixUnstable: 2.4pre20210601_5985b8b -> 2.4pre20210707_02dd6bb
2021-07-22 09:09:24 +02:00
Benjamin Asbach
cd0a0d23e3 openjdk: 11.0.11+9 -> 11.0.12+7 2021-07-21 19:48:18 -06:00
Benjamin Asbach
e1a569f341 openjdk: 11.0.10+11 -> 11.0.11+9
fixes #128407
2021-07-21 19:48:14 -06:00
Artturin
2c6da5545f nexus: use jre8_headless
(cherry picked from commit 787feb03db)
2021-07-22 00:25:28 +00:00
Artturin
1a9c8739fd strawberry: add glib-networking
(cherry picked from commit e060a95153)
2021-07-22 00:18:03 +00:00
github-actions[bot]
1b0b5ba489 Merge staging-next-21.05 into staging-21.05 2021-07-22 00:03:21 +00:00
github-actions[bot]
fa506132b2 Merge release-21.05 into staging-next-21.05 2021-07-22 00:02:42 +00:00
Maximilian Bosch
991e8aee2d ferdi: 5.6.0-beta.6 -> 5.6.0
ChangeLogs: https://github.com/getferdi/ferdi/blob/v5.6.0/CHANGELOG.md#560-beta8-2021-07-16
(cherry picked from commit 2354e8f84f)
2021-07-21 21:33:30 +00:00
Alyssa Ross
677b13b2c5 linuxPackages_latest: 5.12.12 -> 5.13
Fixes: 367a53a82b ("linux_5_13: init at 5.13")
(cherry picked from commit 0c21d0fd70)
2021-07-21 22:24:17 +02:00
Marc 'risson' Schmitt
49cd45c508 nixos/unbound: fix define-tag option
Signed-off-by: Marc 'risson' Schmitt <marc.schmitt@risson.space>
(cherry picked from commit 6b12cff0b5)
2021-07-21 20:12:10 +00:00
Janne Heß
8fe750c560 systemd: Patch CVE-2021-33910
(cherry picked from commit b361dcf0bd)
2021-07-21 21:56:15 +02:00
TredwellGit
2822d00c6a linux/hardened/patches/5.4: 5.4.133-hardened1 -> 5.4.134-hardened1
(cherry picked from commit ac887a4abc)
2021-07-21 21:54:48 +02:00
TredwellGit
454e3fc4af linux/hardened/patches/5.12: 5.12.18-hardened1 -> 5.12.19-hardened1
(cherry picked from commit a718b4ae91)
2021-07-21 21:54:48 +02:00
TredwellGit
d528d58746 linux/hardened/patches/5.10: 5.10.51-hardened1 -> 5.10.52-hardened1
(cherry picked from commit 60e9f5c2d7)
2021-07-21 21:54:48 +02:00
TredwellGit
3e9e9473cb linux/hardened/patches/4.19: 4.19.197-hardened1 -> 4.19.198-hardened1
(cherry picked from commit 8bf83e8c87)
2021-07-21 21:54:48 +02:00
TredwellGit
0a96eec012 linux/hardened/patches/4.14: 4.14.239-hardened1 -> 4.14.240-hardened1
(cherry picked from commit 02f4b95e1d)
2021-07-21 21:54:48 +02:00
TredwellGit
dacef47f62 linux: 5.4.133 -> 5.4.134
(cherry picked from commit ebd057e9ef)
2021-07-21 21:54:48 +02:00
TredwellGit
6b8d902600 linux: 5.13.3 -> 5.13.4
(cherry picked from commit 5b3a23670c)
2021-07-21 21:54:48 +02:00
TredwellGit
33f224ada6 linux: 5.12.18 -> 5.12.19
(cherry picked from commit a703195804)
2021-07-21 21:54:48 +02:00
TredwellGit
243d04c444 linux: 5.10.51 -> 5.10.52
(cherry picked from commit f61350ac89)
2021-07-21 21:54:48 +02:00
TredwellGit
6f6efc8dda linux: 4.9.275 -> 4.9.276
(cherry picked from commit c6eff0d2f5)
2021-07-21 21:54:48 +02:00
TredwellGit
8e34af05ab linux: 4.4.275 -> 4.4.276
(cherry picked from commit 067c21c964)
2021-07-21 21:54:48 +02:00
TredwellGit
0df57cdc24 linux: 4.19.197 -> 4.19.198
(cherry picked from commit 9c153cccd2)
2021-07-21 21:54:48 +02:00
TredwellGit
21c1bbc973 linux: 4.14.239 -> 4.14.240
(cherry picked from commit 82af4b58ee)
2021-07-21 21:54:48 +02:00
Sander van der Burg
8b42f57303 Merge pull request #130957 from svanderburg/backport-arj
[Backport release-21.05] arj: init at 3.10.22
2021-07-21 20:15:44 +02:00
github-actions[bot]
0e01d263c5 Merge staging-next-21.05 into staging-21.05 2021-07-21 18:03:05 +00:00
github-actions[bot]
15959e08e7 Merge release-21.05 into staging-next-21.05 2021-07-21 18:02:21 +00:00
R. RyanTM
b93ac6d197 hugo: 0.84.2 -> 0.84.3
(cherry picked from commit f9b78ee700)
2021-07-21 16:45:21 +00:00
Sander van der Burg
33574c5708 arj: init at 3.10.22
(cherry picked from commit 37601fd76d)
2021-07-21 18:29:19 +02:00
Robert Hensing
648f26faa4 boehmgc_{nix,nixUnstable}: Move into {nix,nixUnstable}.passthru
Do not pollute top-level, but do provide allow the derivations to
be accessed for debugging and reuse if necessary.

(cherry picked from commit 2c2e1db91d)
2021-07-21 16:07:46 +00:00
Robert Hensing
60370d7133 nixUnstable: patch boehmgc (nix#4944)
As has been done in https://github.com/NixOS/nix/pull/4944

This introduces the boehmgc_nix and boehmgc_nixUnstable attributes
which are useful for external packages that link with Nix and its
boehmgc.

(cherry picked from commit 596ac242af)
2021-07-21 16:07:45 +00:00
Jonathan Ringer
12e0c5c76c nixUnstable: 2.4pre20210601_5985b8b -> 2.4pre20210707_02dd6bb
(cherry picked from commit 2d1568561b)
2021-07-21 16:07:45 +00:00
Oleksii Filonenko
50df1c4a23 Merge pull request #130784 from NixOS/backport-128568-to-release-21.05
[Backport release-21.05] hugo: 0.84.1 -> 0.84.2
2021-07-21 18:00:49 +03:00
Thomas Tuegel
7e3eed28fe Merge pull request #130155 from LeSuisse/kimages-CVE-2021-36083-21.05
[21.05] libsForQt5.kimageformats: fix CVE-2021-36083
2021-07-21 09:49:04 -05:00
github-actions[bot]
04226cded8 Merge staging-next-21.05 into staging-21.05 2021-07-21 12:03:11 +00:00
github-actions[bot]
3d958577c1 Merge release-21.05 into staging-next-21.05 2021-07-21 12:02:35 +00:00
Maximilian Bosch
5aefc30fb8 Merge pull request #130797 from NixOS/backport-130538-to-release-21.05
[Backport release-21.05] nixStable: 2.3.12 -> 2.3.14
2021-07-21 13:35:42 +02:00
Maximilian Bosch
5eac9206a5 Merge pull request #130798 from NixOS/backport-130603-to-release-21.05
[Backport release-21.05] strace: 5.12 -> 5.13
2021-07-21 13:35:00 +02:00
Maximilian Bosch
4025281959 Merge pull request #130879 from NixOS/backport-130635-to-release-21.05
[Backport release-21.05] Kernels 2021-07-19
2021-07-21 13:22:43 +02:00
github-actions[bot]
844c5b9888 Merge staging-next-21.05 into staging-21.05 2021-07-21 06:04:16 +00:00
github-actions[bot]
c5c692a1cc Merge release-21.05 into staging-next-21.05 2021-07-21 06:03:02 +00:00
Jan Tojnar
63ee5cd99a nixos/ddccontrol: init
(cherry picked from commit fc1e0e863c)
2021-07-20 22:32:07 -04:00
Jan Tojnar
24ca69c906 ddccontrol: install systemd service
(cherry picked from commit 27b9fe1e53)
2021-07-20 22:32:07 -04:00
github-actions[bot]
26238c0328 Merge staging-next-21.05 into staging-21.05 2021-07-21 00:03:59 +00:00
github-actions[bot]
94fe75c399 Merge release-21.05 into staging-next-21.05 2021-07-21 00:03:19 +00:00
TredwellGit
ba6476e992 linux/hardened/patches/5.4: 5.4.132-hardened1 -> 5.4.133-hardened1
(cherry picked from commit e87737ca60)
2021-07-20 22:50:51 +00:00
TredwellGit
94ff9e7b2d linux/hardened/patches/5.12: 5.12.17-hardened1 -> 5.12.18-hardened1
(cherry picked from commit 9e10f08e10)
2021-07-20 22:50:51 +00:00
TredwellGit
0d3b5af09e linux/hardened/patches/5.10: 5.10.50-hardened1 -> 5.10.51-hardened1
(cherry picked from commit 8e75e31ae4)
2021-07-20 22:50:50 +00:00
TredwellGit
09c21c10fc linux: 5.4.132 -> 5.4.133
(cherry picked from commit 1e8af69feb)
2021-07-20 22:50:50 +00:00
TredwellGit
612d04e1d6 linux: 5.13.2 -> 5.13.3
(cherry picked from commit 72bcb1ace3)
2021-07-20 22:50:50 +00:00
TredwellGit
720802452a linux: 5.12.17 -> 5.12.18
(cherry picked from commit 72d6452921)
2021-07-20 22:50:49 +00:00
TredwellGit
f1a0f33c5f linux: 5.10.50 -> 5.10.51
(cherry picked from commit a5ee0aede3)
2021-07-20 22:50:49 +00:00
Maximilian Bosch
46f9b120e8 Merge pull request #130292 from NixOS/backport-130281-to-release-21.05
[Backport release-21.05] Kernels 2021-07-15
2021-07-20 23:57:39 +02:00
github-actions[bot]
5b9c604201 Merge staging-next-21.05 into staging-21.05 2021-07-20 18:02:55 +00:00
github-actions[bot]
f8bca54ac1 Merge release-21.05 into staging-next-21.05 2021-07-20 18:02:18 +00:00
FliegendeWurst
70f944bdee tor-browser-bundle-bin: 10.0.18 -> 10.5.2
(cherry picked from commit 42e69ba13f)
2021-07-20 17:50:16 +00:00
OPNA2608
00c107a333 palemoon: 29.2.1 -> 29.3.0
(cherry picked from commit dbbbb190b1)
2021-07-20 16:50:49 +00:00
Robert Scott
f3414d7d2b qemu: add patches for CVE-2021-3545 & CVE-2021-3546
(cherry picked from commit cddea297f2)
2021-07-20 16:39:04 +00:00
Maximilian Bosch
b52c349b48 strace: 5.12 -> 5.13
ChangeLog: https://github.com/strace/strace/releases/tag/v5.13
(cherry picked from commit 3ed08b0555)
2021-07-20 15:13:32 +00:00
Maximilian Bosch
792c0160c6 nixStable: 2.3.12 -> 2.3.14
Changes: https://github.com/NixOS/nix/compare/2.3.12...2.3.14

Since this is a bugfix release that wasn't pushed to `nixpkgs`, I
decided to take care of it.

As it's usually done in `upload-release.pl`[1], I updated the
fallback-paths accordingly and used eval `1687468`[2] for this with Nix
2.3.14.

Also added a fallback-path for `aarch64-darwin` as Nix 2.3.14 seems to
support this now[3].

[1] https://github.com/NixOS/nix/blob/2.3-maintenance/maintainers/upload-release.pl
[2] https://hydra.nixos.org/eval/1687468
[3] 14262b86cc

(cherry picked from commit e66237af15)
2021-07-20 15:13:18 +00:00
R. RyanTM
10d8aa8003 hugo: 0.84.1 -> 0.84.2
(cherry picked from commit 0432fe1034)
2021-07-20 13:48:17 +00:00
Oleksii Filonenko
8ee0dfbfd3 Merge pull request #130775 from NixOS/backport-128095-to-release-21.05
[Backport release-21.05] hugo: 0.84.0 -> 0.84.1
2021-07-20 16:39:44 +03:00
Eelco Dolstra
10e32cce2a copy-tarballs.pl: Handle SRI hashes
This should fix

  Jul 20 07:16:12 bastion mirror-tarballs-start[21663]: Use of uninitialized value $algo in concatenation (.) or string at ./maintainers/scripts/copy-tarballs.pl line 80.
  Jul 20 07:16:12 bastion mirror-tarballs-start[21663]: Use of uninitialized value in subroutine entry at ./maintainers/scripts/copy-tarballs.pl line 185.
  Jul 20 07:16:13 bastion mirror-tarballs-start[21663]: error: unknown hash algorithm '' at ./maintainers/scripts/copy-tarballs.pl line 185.

(cherry picked from commit c48be3c17d)
2021-07-20 14:52:31 +02:00
Eelco Dolstra
f05736ab58 warrant: Remove space from URL
(cherry picked from commit 21b39527bf)
2021-07-20 14:52:31 +02:00
Eelco Dolstra
b4ec6596aa taskwarrior: Remove space from URL
(cherry picked from commit fc125d06bc)
2021-07-20 14:52:30 +02:00
R. RyanTM
be870d6d3a hugo: 0.84.0 -> 0.84.1
(cherry picked from commit c20a180937)
2021-07-20 12:50:47 +00:00
Oleksii Filonenko
2d31210a3a Merge pull request #130720 from NixOS/backport-127451-to-release-21.05 2021-07-20 15:27:52 +03:00
Arnout Engelen
5b59140997 jetbrains: updates
(cherry picked from commit 41b86910e8)
2021-07-20 07:55:08 +00:00
R. RyanTM
a69a7c2217 hugo: 0.83.1 -> 0.84.0
(cherry picked from commit 6a5010cfb8)
2021-07-20 07:28:54 +00:00
Michael Weiss
c6f1d6bf1e mesa: 21.1.3 -> 21.1.4 2021-07-20 01:03:31 -04:00
Michael Weiss
d7b32a155a mesa: 21.1.2 -> 21.1.3
I've also updated the URL for the RISC-V patch in case the content of
the old URL will change (not sure if that's possible after a merge
request is merged but now that the patch is upstream it seems like a
good idea regardless; and the content has actually already changed so
the old hash wasn't correct anymore).
2021-07-20 01:03:28 -04:00
Zhaofeng Li
21ffa4a1b3 mesa: Add patch for RISC-V driver selection 2021-07-20 01:03:25 -04:00
Jonathan Ringer
89ed4b143d mesa: fix darwin build 2021-07-20 01:00:09 -04:00
Michael Weiss
00f0ce0618 mesa: 21.1.1 -> 21.1.2 2021-07-20 01:00:06 -04:00
Michael Weiss
71e0180f6f mesa: 21.0.3 -> 21.1.1
Note: This update likely causes some issues when running an application
that has a direct dependency on Mesa (e.g. Sway and XWayland) and was
compiled against a different Nixpkgs revision. See 7106fca0fe for more
details regarding that issue.
2021-07-20 01:00:03 -04:00
Michael Weiss
e0e0ca92a6 mesa: 21.0.1 -> 21.0.3
Note: The update to Mesa 21.0.2 was reverted (25ae1fd29f) because it
caused major issues with Sway (segfault on startup [0]).
This is still the case and might affect all packages that directly
depend on "mesa" (for libgbm or libglapi) but it only causes issues when
the package depends on a "mesa" version that differs from "mesa.drivers"
used for "/run/opengl-driver/". I've noticed this while testing Mesa
updates with the NixOS option "hardware.opengl.package" (as usual)
instead of rebuilding my whole system (which would work). Unfortunately
this can/will likely also cause issues when mixing different channels,
using Flakes/Overlays, etc.

The cause of this should be similar to [1] ("mesa" updates now cause the
same issues that "glibc" updates already do, maybe triggered by certain
Mesa changes) and some additional discussions is in [2],[3].

Note: Don't backport this to NixOS 21.05, at least not without careful
consideration.

[0]: https://github.com/NixOS/nixpkgs/pull/118753#issuecomment-818950977
[1]: https://github.com/NixOS/nixpkgs/issues/95808
[2]: https://github.com/NixOS/nixpkgs/pull/120325
[3]: https://github.com/NixOS/nixpkgs/pull/119558
2021-07-20 01:00:00 -04:00
Michael Weiss
c0b6513803 mesa: Cleanup enableRadv (not used anymore) 2021-07-20 00:59:49 -04:00
github-actions[bot]
263da55900 Merge staging-next-21.05 into staging-21.05 2021-07-19 12:02:54 +00:00
github-actions[bot]
37526ae1e0 Merge release-21.05 into staging-next-21.05 2021-07-19 12:02:19 +00:00
Maximilian Bosch
4181644d09 Merge pull request #130575 from NixOS/backport-130562-to-release-21.05
[Backport release-21.05] Kernels 2021-07-18
2021-07-19 09:24:43 +02:00
Kim Lindberger
2fa8b636af Merge pull request #130271 from NixOS/backport-129464-to-release-21.05
[Backport release-21.05] discourse: Updates and fixes
2021-07-19 08:26:30 +02:00
github-actions[bot]
804de3ebec Merge staging-next-21.05 into staging-21.05 2021-07-19 00:03:39 +00:00
github-actions[bot]
06b06a16b6 Merge release-21.05 into staging-next-21.05 2021-07-19 00:02:56 +00:00
Anderson Torres
6b940846e9 Merge pull request #130582 from svanderburg/add-fs-uae-frontend-stable
[Backport release-21.05] fs-uae-launcher: init at 3.0.5
2021-07-18 20:20:07 -03:00
Maximilian Bosch
d5369485e0 Merge pull request #130536 from Ma27/2105-grafana
[21.05] grafana: 7.5.9 -> 7.5.10
2021-07-18 23:49:37 +02:00
Sander van der Burg
2689890bce fs-uae-launcher: init at 3.0.5
(cherry picked from commit f123928ec1)
2021-07-18 23:14:26 +02:00
Artturin
6a1885ca6d discord: symlink Discord to discord to be consistent
with distros such as arch

(cherry picked from commit f0adbd1d9f71473fd21b245b867c3235a3b2846a)
2021-07-18 14:03:19 -07:00
zowoq
c557fc6061 runc: use buildGoModule
(cherry picked from commit d152d3cc423f102b183c25d9f0aeb9eab414a9d8)
2021-07-18 20:00:43 +00:00
Jonathan Ringer
5a7a7e2b30 containerd: 1.5.1 -> 1.5.2, use buildGoModule
(cherry picked from commit daed0cc14f83ecde8190feba3e80246d5a2b88a3)
2021-07-18 20:00:43 +00:00
TredwellGit
49809d08b5 linux/hardened/patches/5.4: 5.4.130-hardened1 -> 5.4.132-hardened1
(cherry picked from commit f011a85f28)
2021-07-18 18:59:28 +00:00
TredwellGit
e662fb27af linux/hardened/patches/5.12: 5.12.15-hardened1 -> 5.12.17-hardened1
(cherry picked from commit e6ed15ffc4)
2021-07-18 18:59:28 +00:00
TredwellGit
1989fef2a9 linux/hardened/patches/5.10: 5.10.48-hardened1 -> 5.10.50-hardened1
(cherry picked from commit b724837096)
2021-07-18 18:59:28 +00:00
TredwellGit
5a3ca4155f linux/hardened/patches/4.19: 4.19.196-hardened1 -> 4.19.197-hardened1
(cherry picked from commit 888c46fe62)
2021-07-18 18:59:27 +00:00
TredwellGit
c060b9e244 linux/hardened/patches/4.14: 4.14.238-hardened1 -> 4.14.239-hardened1
(cherry picked from commit 73667e11f3)
2021-07-18 18:59:27 +00:00
TredwellGit
0bacfc6d6a linux-rt_5_10: 5.10.47-rt45 -> 5.10.47-rt46
(cherry picked from commit 9e7fd90e15)
2021-07-18 18:59:26 +00:00
TredwellGit
72df626b31 linux: 5.4.130 -> 5.4.132
(cherry picked from commit 5d99998e07)
2021-07-18 18:59:26 +00:00
TredwellGit
f507e4793b linux: 5.12.15 -> 5.12.17
(cherry picked from commit 677dcff2aa)
2021-07-18 18:59:26 +00:00
TredwellGit
0f9b1b3bec linux: 5.10.48 -> 5.10.50
(cherry picked from commit a2259ae9a6)
2021-07-18 18:59:25 +00:00
TredwellGit
32e57d3b3a linux: 4.19.196 -> 4.19.197
(cherry picked from commit cb978946c1)
2021-07-18 18:59:25 +00:00
TredwellGit
13bce99087 linux: 4.14.238 -> 4.14.239
(cherry picked from commit e3eace9baa)
2021-07-18 18:59:24 +00:00
github-actions[bot]
e03b5e0de8 Merge staging-next-21.05 into staging-21.05 2021-07-18 18:02:49 +00:00
github-actions[bot]
69aec0b491 Merge release-21.05 into staging-next-21.05 2021-07-18 18:02:17 +00:00
Robert Scott
c41fdc54ac Merge pull request #129339 from paumr/backport_cnijfilter_4_00_bugfix
[21.05] cnijfilter_4_00: fix broken build
2021-07-18 15:09:50 +01:00
github-actions[bot]
56e08b77af Merge staging-next-21.05 into staging-21.05 2021-07-18 12:04:16 +00:00
github-actions[bot]
f622b5aa42 Merge release-21.05 into staging-next-21.05 2021-07-18 12:03:12 +00:00
Jörg Thalheim
e80a619241 Merge pull request #130530 from NixOS/backport-130146-to-release-21.05
[Backport release-21.05] treewide: convert all links git.archlinux.org to github.com/archlinux…
2021-07-18 12:03:38 +01:00
Jörg Thalheim
a3a2205e49 Merge pull request #126165 from erdnaxe/backport
[21.05] libgudev: support cross-compilation by disabling introspection and vala
2021-07-18 11:47:51 +01:00
Maximilian Bosch
eaa8e6543c grafana: 7.5.9 -> 7.5.10
ChangeLog: https://github.com/grafana/grafana/releases/tag/v7.5.10

On `master` (i.e. 21.11) we already have Grafana 8.0, but I don't really
want to backport this major release, so it's fair IMHO to update Grafana
here to make sure that 21.05-users still get bugfixes.
2021-07-18 12:11:04 +02:00
Sandro Jäckel
efd1d6fe1b treewide: convert all links git.archlinux.org to github.com/archlinux/svntogit-*
(cherry picked from commit 388a4ef423)
2021-07-18 09:17:54 +00:00
Michael Weiss
111e281dd8 llvmPackages_12: 12.0.0 -> 12.0.1
(cherry picked from commit 9a761a4fc8)
2021-07-18 09:12:34 +00:00
Michael Weiss
f4ba3aa382 Merge pull request #130516 from NixOS/backport-130438-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 91.0.4472.114 -> 91.0.4472.164
2021-07-18 10:55:02 +02:00
Michael Weiss
d313fefef8 ungoogled-chromium: 91.0.4472.114 -> 91.0.4472.164
(cherry picked from commit c5e29c786f)
2021-07-18 05:02:13 +00:00
github-actions[bot]
679c5a275a Merge staging-next-21.05 into staging-21.05 2021-07-18 00:03:22 +00:00
github-actions[bot]
ed300216ad Merge release-21.05 into staging-next-21.05 2021-07-18 00:02:47 +00:00
Robert Scott
fb831daa53 exiv2: fix for darwin by providing libiconv
(cherry picked from commit 698d433e74)
2021-07-18 00:49:13 +01:00
Thomas Gerbet
4b9818b455 apacheAnt_1_9: 1.9.15 -> 1.9.16
Fixes CVE-2021-36373 and CVE-2021-36374.

(cherry picked from commit 1e1e536488)
2021-07-17 22:19:15 +00:00
Thomas Gerbet
6fe8066aa0 ant: 1.10.9 -> 1.10.11
Fixes CVE-2021-36373 and CVE-2021-36374.

(cherry picked from commit c83fdf9a36)
2021-07-17 22:19:15 +00:00
Ben Siraphob
268dee8429 Merge pull request #129728 from prusnak/electron-21.05
[21.05] Update Electron
2021-07-18 01:18:03 +07:00
github-actions[bot]
1c34eae5cc Merge staging-next-21.05 into staging-21.05 2021-07-17 18:02:31 +00:00
github-actions[bot]
1bf00c66cc Merge release-21.05 into staging-next-21.05 2021-07-17 18:02:00 +00:00
Jörg Thalheim
dd0139d3f0 Merge pull request #130455 from NixOS/backport-130436-to-release-21.05
[Backport release-21.05] putty: 0.74 -> 0.75
2021-07-17 18:56:04 +01:00
TredwellGit
2abfe1a93b firmwareLinuxNonfree: 2021-05-11 -> 2021-07-16
(cherry picked from commit ea4358edf2)
2021-07-17 17:49:43 +00:00
Martin Weinelt
2170b885b9 Merge pull request #130449 from NixOS/backport-130435-to-release-21.05
[Backport release-21.05] openresty: 1.19.3.1 -> 1.19.3.2
2021-07-17 19:09:26 +02:00
Maximilian Bosch
a61bb245a6 Merge pull request #130362 from NixOS/backport-130358-to-release-21.05
[Backport release-21.05] gitea: 1.14.4 -> 1.14.5
2021-07-17 15:59:28 +02:00
Herman Fries
f8a3b92fb2 steamPackages.steam-runtime: 20210527.0 -> 20210630.0
(cherry picked from commit 7cae055159)
2021-07-17 15:49:20 +02:00
Thomas Gerbet
01e9acfe66 putty: 0.74 -> 0.75
Fixes CVE-2021-36367.

(cherry picked from commit 2931283a42)
2021-07-17 13:18:39 +00:00
Jörg Thalheim
0a96dbc8b6 Merge pull request #130428 from NixOS/backport-125387-to-release-21.05
[Backport release-21.05] python2Packages.convertdate: fix hash
2021-07-17 14:12:51 +01:00
Robert Scott
460f322171 Merge pull request #130293 from NixOS/backport-130290-to-release-21.05
[Backport release-21.05] fig2dev: apply patch for CVE-2021-3561
2021-07-17 13:47:03 +01:00
Robert Scott
c6adf089e0 Merge pull request #129336 from NixOS/backport-129239-to-release-21.05
[Backport release-21.05] trafficserver: 9.0.1 -> 9.0.2
2021-07-17 13:35:26 +01:00
Thomas Gerbet
b840bd41db openresty: 1.19.3.1 -> 1.19.3.2
Fixes CVE-2021-23017.

https://openresty.org/en/ann-1019003002.html
(cherry picked from commit 2dbdca1aa4)
2021-07-17 12:09:02 +00:00
github-actions[bot]
aabde49ee7 Merge staging-next-21.05 into staging-21.05 2021-07-17 12:04:03 +00:00
github-actions[bot]
571bc24140 Merge release-21.05 into staging-next-21.05 2021-07-17 12:03:01 +00:00
Martin Weinelt
ad6d20a5b2 Merge pull request #130372 from NixOS/backport-130365-to-release-21.05
[Backport release-21.05] knot-dns: 3.0.7 -> 3.0.8
2021-07-17 13:05:01 +02:00
TredwellGit
e5eac6b830 wireshark: 3.4.6 -> 3.4.7
https://www.wireshark.org/docs/relnotes/wireshark-3.4.7.html
(cherry picked from commit c9fbd30220499365baa0e7a5ea217c4ddd690e35)
2021-07-17 10:36:54 +02:00
Dmitry Kalinkin
1ad8c705fa python3Packages.matplotlib: 3.4.1 -> 3.4.2
(cherry picked from commit 20a4f271bd)
2021-07-17 09:07:51 +02:00
Ricardo M. Correia
61ed04ae69 python2Packages.convertdate: fix hash
This derivation was introduced in commit
e1d60a05af with version 2.2.2 but the
sha256 hash in that commit actually corresponded to version 2.2.1,
as you can see below:

$ nix-prefetch-github --rev "v2.2.1" fitnr convertdate | jq '.sha256'
"1xgi7x9b9kxm0q51bqnmwdm5lp8vwhx5yk4d1b23r37spz9dbhw5"

(cherry picked from commit 3e84c7ea0d3872e660ba0f3a8c2a0971e7df5dd6)
2021-07-17 07:06:21 +00:00
github-actions[bot]
ee9c8badba Merge staging-next-21.05 into staging-21.05 2021-07-17 06:03:11 +00:00
github-actions[bot]
79b2a8c40d Merge release-21.05 into staging-next-21.05 2021-07-17 06:02:40 +00:00
upkeep-bot
b2f87e0043 vscodium: 1.58.1 -> 1.58.2
(cherry picked from commit ff76c0c0b86155d5354d25b8885a8f8cad556b39)
2021-07-17 11:35:34 +09:00
github-actions[bot]
364d1f2758 Merge staging-next-21.05 into staging-21.05 2021-07-17 00:03:22 +00:00
github-actions[bot]
8679a612b1 Merge release-21.05 into staging-next-21.05 2021-07-17 00:02:44 +00:00
TredwellGit
8b39c06e41 steamPackages.steam-fhsenv: fix Proton
LLVM must match version required by Mesa.

Fixes https://github.com/NixOS/nixpkgs/issues/127068

(cherry picked from commit b4d3ea24beddd761a40020e043fbe2979c518dbf)
2021-07-16 15:34:43 -07:00
Michael Weiss
0379b62657 Merge pull request #130363 from NixOS/backport-130360-to-release-21.05
[Backport release-21.05] chromium: 91.0.4472.114 -> 91.0.4472.164
2021-07-16 21:42:56 +02:00
github-actions[bot]
33a3371924 Merge staging-next-21.05 into staging-21.05 2021-07-16 18:02:57 +00:00
github-actions[bot]
96da6f4bae Merge release-21.05 into staging-next-21.05 2021-07-16 18:02:19 +00:00
Martin Weinelt
d6df83eafd Merge pull request #130344 from NixOS/backport-130084-to-release-21.05
[Backport release-21.05]  firefox-bin: 89.0.1 -> 90.0,  firefox-esr: 78.11.0esr -> 78.12.0esr
2021-07-16 19:45:37 +02:00
Vladimír Čunát
1e22652d66 knot-dns: 3.0.7 -> 3.0.8
https://gitlab.nic.cz/knot/knot-dns/-/tags/v3.0.8
(cherry picked from commit 6582dd7e12)
2021-07-16 12:43:37 +00:00
github-actions[bot]
e835f94441 Merge staging-next-21.05 into staging-21.05 2021-07-16 12:03:07 +00:00
github-actions[bot]
f97336e6d8 Merge release-21.05 into staging-next-21.05 2021-07-16 12:02:28 +00:00
Wael Nasreddine
292d8209ed Merge pull request #130200 from maxeaubrey/21.05_go_backports 2021-07-16 04:56:11 -07:00
Michael Weiss
76430622b7 chromium: 91.0.4472.114 -> 91.0.4472.164
https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop.html

This update includes 8 security fixes. Google is aware of reports that
an exploit for CVE-2021-30563 exists in the wild.

CVEs:
CVE-2021-30559 CVE-2021-30541 CVE-2021-30560 CVE-2021-30561
CVE-2021-30562 CVE-2021-30563 CVE-2021-30564

(cherry picked from commit 27523cad1e)
2021-07-16 10:24:41 +00:00
Maximilian Bosch
70ff5095e8 gitea: 1.14.4 -> 1.14.5
ChangeLog: https://github.com/go-gitea/gitea/releases/tag/v1.14.5
(cherry picked from commit a8e46cd7dc1d7fdd3a09e4d07aa634f9f2f65bff)
2021-07-16 10:14:43 +00:00
taku0
dfeaca8a8d firefox-esr: 78.11.0esr -> 78.12.0esr
(cherry picked from commit 8cef5c9fea)
2021-07-16 07:37:18 +00:00
taku0
b56e661a78 firefox-bin: 89.0.1 -> 90.0
(cherry picked from commit 089c534c21)
2021-07-16 07:37:18 +00:00
ajs124
7cdd285163 libgcrypt: add meta.changelog
(cherry picked from commit 7bb9050610491bbe46959dbf9b52faef02e7ffdc)
2021-07-15 23:36:16 -07:00
R. RyanTM
87a0a02fa1 libgcrypt: 1.9.2 -> 1.9.3
(cherry picked from commit a19036237e28d707a8b0962ec00094eebf75e58e)
2021-07-15 23:36:16 -07:00
github-actions[bot]
5e5af706ab Merge staging-next-21.05 into staging-21.05 2021-07-16 06:02:54 +00:00
github-actions[bot]
9c7cbd182c Merge release-21.05 into staging-next-21.05 2021-07-16 06:02:14 +00:00
Niklas Hambüchen
a165aeceda Merge pull request #130313 from maxeaubrey/21.05_consul_1.9.8
[21.05] consul: 1.9.7 -> 1.9.8
2021-07-16 02:36:15 +02:00
Viacheslav Lotsmanov
c4a4920b2d psi-plus: add more build options (#129710)
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit 53ca0b1664)
2021-07-16 03:30:44 +03:00
Maxine Aubrey
e1c8c73695 consul: 1.9.7 -> 1.9.8 2021-07-16 00:00:06 +02:00
Sandro
cdbfb44f48 Update pkgs/applications/networking/instant-messengers/discord/base.nix
(cherry picked from commit 1f62e37efbf92dffe80a759dfb54281c7e4834a7)
2021-07-15 20:18:13 +00:00
Moritz Hedtke
bef3886537 discord-canary: 0.0.125 → 0.0.126
(cherry picked from commit 06d387bfb2efd319db7cf4d7af048da9bba3a766)
2021-07-15 20:18:13 +00:00
Moritz Hedtke
77d82ccb4f discord: Fix autoupdate script
It didn't properly detect which of the versions it updated.

(cherry picked from commit 83af8ef00e33affadd1df45af48866f24625566c)
2021-07-15 20:18:13 +00:00
github-actions[bot]
151e0680aa Merge staging-next-21.05 into staging-21.05 2021-07-15 18:03:23 +00:00
github-actions[bot]
a6be221647 Merge release-21.05 into staging-next-21.05 2021-07-15 18:02:44 +00:00
talyz
955cdd607f discourse: 2.7.4 -> 2.7.5
(cherry picked from commit 60d78d7f1f)
2021-07-15 19:59:04 +02:00
Thomas Gerbet
04644c993d fig2dev: apply patch for CVE-2021-3561
(cherry picked from commit 57aff6b0ae)
2021-07-15 17:28:12 +00:00
TredwellGit
46309746ce linux_latest-libre: 18132 -> 18165
(cherry picked from commit 26af402042)
2021-07-15 17:25:35 +00:00
TredwellGit
06ce7d7587 linux-rt_5_4: 5.4.123-rt59 -> 5.4.129-rt61
(cherry picked from commit 2913c53891)
2021-07-15 17:25:34 +00:00
TredwellGit
f8217ded54 linux: 5.13.1 -> 5.13.2
(cherry picked from commit d2f67b4efb)
2021-07-15 17:25:34 +00:00
TredwellGit
bb58b98cd0 linux: 4.9.274 -> 4.9.275
(cherry picked from commit aa445dcd9a)
2021-07-15 17:25:34 +00:00
TredwellGit
4df31dbabd linux: 4.4.274 -> 4.4.275
(cherry picked from commit 0637e4c7c6)
2021-07-15 17:25:33 +00:00
Mark Vainomaa
ee02d8d854 docker: bump runc to 1.0-rc95, fixing CVE-2021-30465
(cherry picked from commit 53600565fdb811bc7ac59d73eb59065d575658f2)
2021-07-15 16:51:10 +00:00
Mark Vainomaa
ba333b130b docker: use commit hashes instead of tags, fix containerd sha256
(cherry picked from commit 0068eea01f2462e327ffbe858c34e7a945f1d3be)
2021-07-15 16:51:10 +00:00
Mark Vainomaa
0e0356c8b7 docker: drop unused argument, use pname instead of name
(cherry picked from commit aacce6cc4bc962d6e435016c5427e3ed4a51c983)
2021-07-15 16:51:10 +00:00
Mark Vainomaa
863262a874 docker: 20.10.2 -> 20.10.6
(cherry picked from commit 3620b33d0b61a24ccacb312982a5b1e810904c29)
2021-07-15 16:51:09 +00:00
Jörg Thalheim
b106a26a4d Merge pull request #130245 from neonfuz/backport-129870-to-release-21.05
papermc: 1.16.5r771 -> 1.17.1r97
2021-07-15 15:13:48 +01:00
talyz
32c19b6bf8 discourse: Remove architecture bound platforms from Gemfile.lock
Maybe bundix doesn't handle them properly? They cause runtime issues
and don't seem necessary when the binary gems are built from scratch
anyway.

(cherry picked from commit a2dbc3af1d)
2021-07-15 12:54:01 +00:00
talyz
23c806f963 nixos/discourse: Update plugin documentation
Update the documentation regarding plugins to reflect recent changes.

(cherry picked from commit 20548f050e)
2021-07-15 12:54:00 +00:00
talyz
09ccf575cd discourseAllPlugins: Provide a discourse derivation with all plugins
(cherry picked from commit eb122119a0)
2021-07-15 12:54:00 +00:00
talyz
23cdb918f0 discourse: Add update-plugins action to update.py
(cherry picked from commit 3300282db3)
2021-07-15 12:53:59 +00:00
talyz
d57e97faef discourse.plugins: Update and add metadata
(cherry picked from commit d3bc5d5b7a)
2021-07-15 12:53:59 +00:00
Kim Lindberger
5fd730e210 Merge pull request #128823 from NixOS/backport-127931-to-release-21.05
[Backport release-21.05] discourse: Fix plugin support
2021-07-15 14:50:11 +02:00
Jörg Thalheim
eacc0f7750 k3s: add tokenFile option
To avoid having secrets in the nix store.

(cherry picked from commit 11a38f62f0)
2021-07-15 12:40:46 +00:00
Jörg Thalheim
d15de4c6db nixos/k3s: add to environment.systemPackages for adminstration
(cherry picked from commit 852739337b)
2021-07-15 12:40:46 +00:00
github-actions[bot]
ffab06907b Merge staging-next-21.05 into staging-21.05 2021-07-15 12:03:04 +00:00
github-actions[bot]
f11fbdf2da Merge release-21.05 into staging-next-21.05 2021-07-15 12:02:30 +00:00
Michael Weiss
330acb7fb7 Merge pull request #130255 from NixOS/backport-130253-to-release-21.05
[Backport release-21.05] signal-desktop: 5.8.0 -> 5.9.0
2021-07-15 11:42:36 +02:00
Robert Hensing
9d230170bc Merge pull request #126586 from vs49688/vgmstream
[21.05] vgmstream: init at r1050-3448-g77cc431b
2021-07-15 11:33:33 +02:00
Michael Weiss
fa46c42246 signal-desktop: 5.8.0 -> 5.9.0
(cherry picked from commit 1a81de7c72)
2021-07-15 09:25:01 +00:00
Robert Hensing
0ce211ba1b Merge pull request #130177 from unclechu/backport-add-json2yaml-to-toplevel-to-release-21.05
Backport “add json2yaml to top-level” to release-21.05
2021-07-15 11:03:06 +02:00
Robert Hensing
63f6eb0512 Merge pull request #130215 from NixOS/backport-130165-to-release-21.05
[Backport release-21.05]  thunderbird, thunderbird-bin: 78.11.0 -> 78.12.0 [High security fixes]
2021-07-15 09:16:58 +02:00
Sage Raflik
0d3a413302 papermc: 1.16.5r771 -> 1.17.1r97 2021-07-14 21:43:48 -05:00
github-actions[bot]
4d5e3a47b5 Merge staging-next-21.05 into staging-21.05 2021-07-15 00:03:19 +00:00
github-actions[bot]
822b4206cd Merge release-21.05 into staging-next-21.05 2021-07-15 00:02:46 +00:00
Martin Weinelt
1f4e50f03c Merge pull request #130186 from mweinelt/21.05/firefox 2021-07-14 23:39:07 +02:00
taku0
edb21b3dbc thunderbird: 78.11.0 -> 78.12.0
(cherry picked from commit db3297a081)
2021-07-14 19:34:48 +00:00
taku0
42d458e74b thunderbird-bin: 78.11.0 -> 78.12.0
(cherry picked from commit 9cff3c556f)
2021-07-14 19:34:47 +00:00
Maxine Aubrey
3034d322a9 go_1_16: 1.16.5 -> 1.16.6
(cherry picked from commit 4695639fde)
2021-07-14 17:43:50 +02:00
Maxine Aubrey
11beeade2d go_1_15: 1.15.13 -> 1.15.14
(cherry picked from commit 25eb6344d0)
2021-07-14 17:43:44 +02:00
zowoq
8f3ec9ee43 go: cleanup
(cherry picked from commit 88f1ca731c)
2021-07-14 17:43:37 +02:00
zowoq
46fc5b82ea go: format with nixpkgs-fmt
(cherry picked from commit 3a365e0e50)
2021-07-14 17:43:31 +02:00
zowoq
43a526d41d go: add runHooks to bootstrap binary
(cherry picked from commit 99697d891d)
2021-07-14 17:43:22 +02:00
Martin Weinelt
8728b288d1 firefox: use nss_latest for firefox >= 90 2021-07-14 16:32:30 +02:00
ajs124
88320091fa firefox: 89.0.2 -> 90.0
make gtk3Support non-optional, because it hasn't been for a long time
also make gtk2 conditional on firefox older than 90, because we can get
rid of it with firefox 90, but it's still needed by the current ESR
release

(cherry picked from commit b332794adf)
2021-07-14 16:32:30 +02:00
Martin Weinelt
282afa0245 nss_latest: init at 3.67
Required for the latest and greatest firefox release
2021-07-14 16:32:17 +02:00
Mario Rodas
b8ecf1d179 nodejs-16_x: 16.4.2 -> 16.5.0
https://github.com/nodejs/node/releases/tag/v16.5.0
(cherry picked from commit cf8defb1dd)
2021-07-14 08:27:09 -05:00
Sandro
ef3ff52c1e Update pkgs/applications/virtualization/open-vm-tools/default.nix
(cherry picked from commit c619e11879529877bd102b5f1eeff7e78daa4c87)
2021-07-14 13:18:02 +00:00
Jeremy Kolb
91fcbe8f4f Remove unused dependencies
(cherry picked from commit 5f093827334ab825c8e9f9fc367ad20adbd7103a)
2021-07-14 13:18:01 +00:00
Jeremy Kolb
22180dc1d0 Update pkgs/applications/virtualization/open-vm-tools/default.nix
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit 808ee853e73efd91fcff13059ff9cc8777e85af9)
2021-07-14 13:18:01 +00:00
Jeremy Kolb
94f0dea33b open-vm-tools: Copy the udev files over correctly
(cherry picked from commit 42ea61bc7dacc8360eb87152635f5f14f003c18d)
2021-07-14 13:18:01 +00:00
Jeremy Kolb
936f34d99c open-vm-tools: 11.2.5 -> 11.3.0
Move to the latest version of open-vm-tools. This fixes automatic KMS.

(cherry picked from commit 398cab1a2b7a957a5abc6a5f19089f09ae07df78)
2021-07-14 13:18:00 +00:00
Viacheslav Lotsmanov
9cf9f71b9e Add “json2yaml” to top-level
(cherry picked from commit a863d6d8b1)
2021-07-14 16:08:17 +03:00
github-actions[bot]
bb5465316f Merge staging-next-21.05 into staging-21.05 2021-07-14 12:03:14 +00:00
github-actions[bot]
212ea57f9e Merge release-21.05 into staging-next-21.05 2021-07-14 12:02:37 +00:00
upkeep-bot
1672da0dfd vscodium: 1.58.0 -> 1.58.1
(cherry picked from commit de51394821f6da571554d9470fb1e3c2b7460f20)
2021-07-14 20:47:57 +09:00
Maximilian Bosch
fc9369b884 Merge pull request #130137 from NixOS/backport-129570-to-release-21.05
[Backport release-21.05] matrix-synapse: 1.37.1 -> 1.38.0
2021-07-14 10:30:49 +02:00
Thomas Gerbet
07b2b092be libsForQt5.kimageformats: fix CVE-2021-36083
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit 3d260a2d0e)
2021-07-14 10:08:43 +02:00
Sumner Evans
5b42238926 matrix-synapse: 1.37.1 -> 1.38.0
(cherry picked from commit 8b055178de)
2021-07-13 22:19:14 +00:00
github-actions[bot]
7cb1bc3204 Merge staging-next-21.05 into staging-21.05 2021-07-13 18:03:32 +00:00
github-actions[bot]
67f0be2d0f Merge release-21.05 into staging-next-21.05 2021-07-13 18:02:56 +00:00
ajs124
2a96414d7e Merge pull request #130108 from NixOS/backport-130086-to-release-21.05
[Backport release-21.05] icingaweb2: 2.8.2 -> 2.8.3
2021-07-13 18:21:47 +02:00
R. RyanTM
92080580a4 icingaweb2: 2.8.2 -> 2.8.3
(cherry picked from commit df3aa47c5a)
2021-07-13 15:49:19 +00:00
Yureka
d36cd9e039 nixos/gitlab: improve psql assertion message
(cherry picked from commit c5a0551dc4)
2021-07-13 15:27:21 +02:00
Yureka
aff1607b17 gitlab: 14.0.2 -> 14.0.5
https://about.gitlab.com/releases/2021/07/06/gitlab-14-0-3-released/
https://about.gitlab.com/releases/2021/07/07/critical-security-release-gitlab-14-0-4-released/
https://about.gitlab.com/releases/2021/07/08/gitlab-14-0-5-released/
(cherry picked from commit 6510a13611)
2021-07-13 15:27:21 +02:00
Yureka
ebe13e59aa gitlab: 14.0.1 -> 14.0.2
https://about.gitlab.com/releases/2021/07/01/security-release-gitlab-14-0-2-released/
(cherry picked from commit a023b6c4722663e8e481daf2e593eb917d8daec0)
2021-07-13 15:27:21 +02:00
Yureka
7b1021ce28 nixos/tests/gitlab: use postgresql 13
Since 21.05 still defaults to 11, we need to set this (as does every
user).
2021-07-13 15:27:21 +02:00
Yureka
e4deb36262 nixos/gitlab: require at least postgresql 12
(cherry picked from commit 2297eb35e5)
2021-07-13 15:27:21 +02:00
Yureka
e8e5b8a9bb gitlab: 13.12.4 -> 14.0.1
https://about.gitlab.com/releases/2021/06/22/gitlab-14-0-released/
https://about.gitlab.com/releases/2021/06/24/gitlab-14-0-1-released/
(cherry picked from commit facd0c68cc)
2021-07-13 15:27:21 +02:00
sternenseemann
3ebb71b547 apostrophe: fix HTML export by referencing fira fonts from store
pandoc can embed fonts and stylesheets on export which apostrophe uses —
however it has hardcoded paths for the fonts which only work in the
flatpak version, so we need to substitute them.

(cherry picked from commit 4e1acab880f0c27741810754c237dfd50e9be5f8)
2021-07-13 14:42:24 +02:00
github-actions[bot]
281c472a87 Merge staging-next-21.05 into staging-21.05 2021-07-13 12:03:01 +00:00
github-actions[bot]
b4cec2daa8 Merge release-21.05 into staging-next-21.05 2021-07-13 12:02:22 +00:00
Robin Gloster
8b98eb8fd1 Merge pull request #130050 from Ma27/backport-nextcloud
[21.05] nextcloud: version updates
2021-07-13 03:00:46 -05:00
github-actions[bot]
9ed221b890 Merge staging-next-21.05 into staging-21.05 2021-07-13 00:02:58 +00:00
github-actions[bot]
a784de8a26 Merge release-21.05 into staging-next-21.05 2021-07-13 00:02:25 +00:00
Maximilian Bosch
f8b79de69e nextcloud22: init at 22.0.0
Simplified, non-breaking version of e05f4101c1.
2021-07-12 23:27:57 +02:00
Maximilian Bosch
b58ae55e22 nextcloud19: 19.0.6 -> 19.0.13
This basically has two reasons:

* I forgot to remove v19 here and I don't want to break this now. Going
  up to the most recent patch-level is the least we can do.
* With a changed version, the `permittedInsecurePackages`-setting in
  people's deployments has to change, so people will actually notice the
  EOL of v19.
2021-07-12 23:14:59 +02:00
Maximilian Bosch
edfe11b535 nextcloud19: make it clear that it's EOL
I actually wanted to remove it before 21.05, but unfortunately I forgot
about this. This is a less drastic way of getting rid of v19 in contrast
to the actual breaking change in master[1].

[1] b922990a8e
2021-07-12 23:12:19 +02:00
Maximilian Bosch
50fb3a1eeb nextcloud20: 20.0.7 -> 20.0.11
ChangeLog: https://nextcloud.com/changelog/#20-0-11
(cherry picked from commit d45672d059)
2021-07-12 21:53:34 +02:00
Benno Bielmeier
6856ce6a4a nextcloud: 21.0.2 -> 21.0.3
(cherry picked from commit 765c1b3144)
2021-07-12 21:53:34 +02:00
upkeep-bot
a7512bb64b vscodium: 1.57.1 -> 1.58.0
(cherry picked from commit 2201e7d8ce)
2021-07-13 04:13:06 +09:00
upkeep-bot
e2f293ddf6 vscodium: 1.57.0 -> 1.57.1
(cherry picked from commit 955df64c44)
2021-07-13 04:13:06 +09:00
upkeep-bot
cc6ae106aa vscodium: 1.56.2 -> 1.57.0
(cherry picked from commit 39fd960ee1)
2021-07-13 04:13:06 +09:00
github-actions[bot]
0dc09a8693 Merge staging-next-21.05 into staging-21.05 2021-07-12 12:03:17 +00:00
github-actions[bot]
f3b0b41bd0 Merge release-21.05 into staging-next-21.05 2021-07-12 12:02:42 +00:00
Linus Heckemann
92802efe42 Merge pull request #130000 from Ma27/backport-wlroots
[21.05] wlroots: 0.14.0 -> 0.14.1
2021-07-12 10:43:02 +02:00
Michael Weiss
46667847c0 wlroots: 0.14.0 -> 0.14.1
(cherry picked from commit 7632ba310e)
2021-07-12 10:11:43 +02:00
github-actions[bot]
ed7a470f93 Merge staging-next-21.05 into staging-21.05 2021-07-12 06:06:34 +00:00
github-actions[bot]
b9fbdb6b8f Merge release-21.05 into staging-next-21.05 2021-07-12 06:03:29 +00:00
Dmitry Kalinkin
07909ad7f4 blender: 2.93.0 -> 2.93.1
(cherry picked from commit 520c2971d1)
2021-07-11 21:13:38 -04:00
github-actions[bot]
acdd2da56e Merge staging-next-21.05 into staging-21.05 2021-07-12 00:03:17 +00:00
github-actions[bot]
cd1654a4ee Merge release-21.05 into staging-next-21.05 2021-07-12 00:02:36 +00:00
Martin Weinelt
79d92ab090 Merge pull request #129778 from NixOS/staging-next-21.05 2021-07-11 23:41:19 +02:00
ajs124
a18e883c9b Merge pull request #127730 from NixOS/backport-127705-to-release-21.05
[Backport release-21.05] nginxModules.rtmp: 1.2.1 -> 1.2.2
2021-07-11 22:25:09 +02:00
github-actions[bot]
8c2dd05bac Merge staging-next-21.05 into staging-21.05 2021-07-11 18:08:39 +00:00
github-actions[bot]
597a6aad6d Merge release-21.05 into staging-next-21.05 2021-07-11 18:03:22 +00:00
Gabriel Ebner
f130eb0777 Merge pull request #129944 from NixOS/backport-129223-to-release-21.05
[Backport release-21.05] ccls: set resource directory
2021-07-11 18:18:50 +02:00
Gabriel Ebner
7f255c6b23 ccls: set resource directory
Fixes #126936

(cherry picked from commit db37a86453)
2021-07-11 14:44:40 +00:00
github-actions[bot]
842f4277ee Merge staging-next-21.05 into staging-21.05 2021-07-10 18:02:47 +00:00
github-actions[bot]
c1f5dd7be2 Merge release-21.05 into staging-next-21.05 2021-07-10 18:02:00 +00:00
Mario Rodas
ee7d443869 Merge pull request #129814 from NixOS/backport-128936-to-staging-21.05
[Backport staging-21.05] pythonPackages.pillow: 8.2.0 -> 8.3.1
2021-07-10 08:42:54 -05:00
markuskowa
cf59fbd539 Merge pull request #129842 from NixOS/backport-129839-to-release-21.05
[Backport release-21.05] linuxptp: 3.1 -> 3.1.1
2021-07-10 14:18:49 +02:00
github-actions[bot]
aa67f6896b Merge staging-next-21.05 into staging-21.05 2021-07-10 12:05:43 +00:00
github-actions[bot]
6500937b9b Merge release-21.05 into staging-next-21.05 2021-07-10 12:02:59 +00:00
Markus Kowalewski
a49908946c linuxptp: 3.1 -> 3.1.1
fixes CVEs 2021-3570 and 2021-3571

(cherry picked from commit 4d881f9149)
2021-07-10 11:29:04 +00:00
Jörg Thalheim
54db964a8b Merge pull request #125159 from NixOS/backport-125121-to-release-21.05
[Backport release-21.05] nixos/lib/make-ext4-fs: Fix: `resize2fs -M' can leave insufficient slack
2021-07-10 09:28:17 +01:00
github-actions[bot]
ad632ccb0a Merge staging-next-21.05 into staging-21.05 2021-07-10 06:07:46 +00:00
github-actions[bot]
e0f1b871c3 Merge release-21.05 into staging-next-21.05 2021-07-10 06:06:04 +00:00
Mario Rodas
07dd884d4c python38Packages.pillow: 8.3.0 -> 8.3.1
https://pillow.readthedocs.io/en/stable/releasenotes/8.3.1.html
(cherry picked from commit 6635489576)
2021-07-10 02:35:49 +00:00
Evan Stoll
c40e9cc00a pythonPackages.pillow: 8.2.0 -> 8.3.0
add support for defusedxml

(cherry picked from commit e202771a89)
2021-07-10 02:35:48 +00:00
aszlig
9376bf7b34 ip2unix: 2.1.3 -> 2.1.4
Upstream changes:

  * Fix ordering between systemd socket file descriptor names and rules.
  * Fix usage of C library path as discovered by Meson.

Signed-off-by: aszlig <aszlig@nix.build>
(cherry picked from commit 8b7f8e2e69)
2021-07-10 02:17:18 +02:00
github-actions[bot]
4cdb9a0cc3 Merge staging-next-21.05 into staging-21.05 2021-07-10 00:03:10 +00:00
github-actions[bot]
9b0fff08dc Merge release-21.05 into staging-next-21.05 2021-07-10 00:02:34 +00:00
Francesco Gazzetta
f1a6b028cd powermanga: init at 0.93.1
(cherry picked from commit 0851d84fed)
2021-07-09 23:03:53 +00:00
Francesco Gazzetta
6d732c1deb tecnoballz: init at 0.93.1
(cherry picked from commit ff1b1874f8)
2021-07-09 23:03:53 +00:00
illustris
8b5fcedfc9 nixos/jitsi-meet: update nixos tests
- remove check for `connected .JID: focus@auth.server` because
	- log format was changed in c1945ea6cb
	- connection.getUser() in jicofo also appears to be broken, returning null instead of username
	- testing for this log line shouldn't be necessary, as we also test for "Authenticated as focus@auth.server"

- remove check for `External component successfully authenticated` because
	- [JVB no longer uses component](https://community.jitsi.org/t/jvb-not-connecting/91157/2)

- increase VM memory

(cherry picked from commit 85aa4bf92b)
2021-07-10 00:02:59 +02:00
illustris
fa8a6d7e0a nixos/jitsi-meet: include jitsi prosody plugins in prosody extraPluginPaths
(cherry picked from commit e0089c38ca)
2021-07-10 00:02:59 +02:00
illustris
0e73108529 jitsi-meet-prosody: init at 1.0.5056
(cherry picked from commit 5e49c97d29)
2021-07-10 00:02:59 +02:00
illustris
27d38294c6 nixos/jitsi-meet: Update jitsi prosody configs
Changes made as per b6f7f8fba7

(cherry picked from commit 34b9ba2e61)
2021-07-10 00:02:59 +02:00
illustris
df1e470c4b jicofo: 1.0-690 -> 1.0-756
(cherry picked from commit aea0f9ce1f)
2021-07-10 00:02:59 +02:00
illustris
2df327ab56 jitsi-videobridge: 2.1-416 -> 2.1-508
(cherry picked from commit d0d7946c03)
2021-07-10 00:02:59 +02:00
illustris
f58e00875d jitsi-meet: stable/jitsi-meet_5390 -> stable/jitsi-meet_5963
(cherry picked from commit a415ec434f)
2021-07-10 00:02:59 +02:00
github-actions[bot]
dbe6c02d1b Merge staging-next-21.05 into staging-21.05 2021-07-09 18:03:04 +00:00
github-actions[bot]
86455fbb91 Merge release-21.05 into staging-next-21.05 2021-07-09 18:02:31 +00:00
Maximilian Bosch
f5a0ce0b99 Merge pull request #129745 from NixOS/backport-129699-to-release-21.05
[Backport release-21.05] Kernels 2021-07-08
2021-07-09 19:59:10 +02:00
Robert Hensing
65ccaa51c7 cacert: Add Haskell x509-system compatibility
This allows cacert to be used with Haskell-based fetchers like
you would with regular OpenSSL-based fetchers:

  buildInputs = [ cacert ];

(cherry picked from commit 5d57104d84)
2021-07-09 10:34:15 -07:00
Vladimír Čunát
e8b7ccc8f9 Merge #129505: openexr: 2.5.3 -> 2.5.7 (into staging-21.05) 2021-07-09 19:18:00 +02:00
pca006132
b675049ea4 rtw89: init at 2021-07-03 (#129325)
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit 7d86536529)
2021-07-10 00:57:06 +08:00
github-actions[bot]
33fe7f083b Merge staging-next-21.05 into staging-21.05 2021-07-09 12:03:13 +00:00
github-actions[bot]
a81246cf88 Merge release-21.05 into staging-next-21.05 2021-07-09 12:02:37 +00:00
Maximilian Bosch
ca09581e5e Merge pull request #129626 from NixOS/backport-129618-to-release-21.05
[Backport release-21.05] vagrant: 2.2.16 -> 2.2.17
2021-07-09 13:24:12 +02:00
TredwellGit
cf4327321a linux/hardened/patches/5.4: 5.4.129-hardened1 -> 5.4.130-hardened1
(cherry picked from commit 43fba78fec)
2021-07-09 10:48:18 +00:00
TredwellGit
50cc793e18 linux/hardened/patches/5.12: 5.12.14-hardened1 -> 5.12.15-hardened1
(cherry picked from commit 9af983cd00)
2021-07-09 10:48:18 +00:00
TredwellGit
84cb8b4796 linux/hardened/patches/5.10: 5.10.47-hardened1 -> 5.10.48-hardened1
(cherry picked from commit b36d829bb1)
2021-07-09 10:48:18 +00:00
TredwellGit
2e9e07c10b linux-rt_5_10: 5.10.41-rt42 -> 5.10.47-rt45
(cherry picked from commit 25b73ac6a2)
2021-07-09 10:48:17 +00:00
TredwellGit
2d453b51a6 linux: 5.4.129 -> 5.4.130
(cherry picked from commit 32235d4868)
2021-07-09 10:48:17 +00:00
TredwellGit
f0b011fd73 linux: 5.13 -> 5.13.1
(cherry picked from commit ea4cb23952)
2021-07-09 10:48:17 +00:00
TredwellGit
fef417a726 linux: 5.12.14 -> 5.12.15
(cherry picked from commit e0f9f09c17)
2021-07-09 10:48:16 +00:00
TredwellGit
d7353f445e linux: 5.10.47 -> 5.10.48
(cherry picked from commit 9462b074a8)
2021-07-09 10:48:16 +00:00
TredwellGit
b13797cf99 electron_12: 12.0.12 -> 12.0.14
https://github.com/electron/electron/releases/tag/v12.0.13
https://github.com/electron/electron/releases/tag/v12.0.14
(cherry picked from commit b413babf72)
2021-07-09 10:20:32 +02:00
TredwellGit
ffb6f1fc6b electron_11: 11.4.9 -> 11.4.10
https://github.com/electron/electron/releases/tag/v11.4.10
(cherry picked from commit 7cb4e3bb01)
2021-07-09 10:20:25 +02:00
github-actions[bot]
78c11731b4 Merge staging-next-21.05 into staging-21.05 2021-07-08 18:02:44 +00:00
github-actions[bot]
a49cebfd6a Merge release-21.05 into staging-next-21.05 2021-07-08 18:02:12 +00:00
Maximilian Bosch
6056345805 Merge pull request #129349 from NixOS/backport-128538-to-release-21.05
[Backport release-21.05] Kernels 2021-06-28
2021-07-08 19:56:38 +02:00
Anderson Torres
5436a1fd65 Merge pull request #128459 from Ma27/backport-sway
[21.05] sway: 1.6 -> 1.6.1, wlroots: 0.13.0 -> 0.14.0
2021-07-08 11:30:06 -03:00
Michael Weiss
a6e07df310 Merge pull request #129641 from NixOS/backport-129633-to-release-21.05
[Backport release-21.05] signal-desktop: 5.7.1 -> 5.8.0
2021-07-08 14:46:11 +02:00
Michael Weiss
0f88b5e546 signal-desktop: 5.7.1 -> 5.8.0
(cherry picked from commit 5a5d6a785a)
2021-07-08 12:12:56 +00:00
github-actions[bot]
455ec36268 Merge staging-next-21.05 into staging-21.05 2021-07-08 12:03:13 +00:00
github-actions[bot]
ca802b75e7 Merge release-21.05 into staging-next-21.05 2021-07-08 12:02:35 +00:00
Maximilian Bosch
628768830b vagrant: 2.2.16 -> 2.2.17
ChangeLog: https://github.com/hashicorp/vagrant/blob/v2.2.17/CHANGELOG.md#2217-july-7-2021
(cherry picked from commit adc9b2b439)
2021-07-08 09:11:40 +00:00
Jörg Thalheim
dc3497f188 Merge pull request #129495 from delan/backport/bore-0.3.3
[Backport release-21.05] bore: init at 0.3.3 (#129295)
2021-07-08 07:48:37 +01:00
Jörg Thalheim
fa5cb7a31d Merge pull request #129605 from NixOS/backport-129590-to-release-21.05
[Backport release-21.05] turbovnc: Fix that setting JAVA_HOME breaks vncviewer. Fixes #129582
2021-07-08 07:12:12 +01:00
Jörg Thalheim
7a41876e2e Merge pull request #129568 from NixOS/backport-127917-to-release-21.05
[Backport release-21.05] linux-kernel: Add dell drivers on 5.12+
2021-07-08 07:09:19 +01:00
Jörg Thalheim
0fe1422ff0 Merge pull request #129525 from NixOS/backport-129258-to-release-21.05
[Backport release-21.05] zen-kernels: 5.12.9 -> 5.12.14
2021-07-08 07:08:45 +01:00
github-actions[bot]
7760054b64 Merge staging-next-21.05 into staging-21.05 2021-07-08 06:03:30 +00:00
github-actions[bot]
bb1de8d8cd Merge release-21.05 into staging-next-21.05 2021-07-08 06:02:39 +00:00
Jörg Thalheim
2e8702c21e Merge pull request #129494 from NixOS/backport-129446-to-release-21.05
[Backport release-21.05] gitea: 1.14.3 -> 1.14.4
2021-07-08 06:26:39 +01:00
Niklas Hambüchen
cdf6905e25 turbovnc: Fix that setting JAVA_HOME breaks vncviewer. Fixes #129582
(cherry picked from commit b7dd636f24)
2021-07-08 05:22:46 +00:00
Jörg Thalheim
bc8e2b283c Merge pull request #129603 from NixOS/backport-129581-to-release-21.05
[Backport release-21.05] nixos/doc: Fix synopsis for nixos-rebuild(8)
2021-07-08 06:12:13 +01:00
Lara
b7853679fc nixos/doc: Fix synopsis for nixos-rebuild(8)
(cherry picked from commit 22a7874024)
2021-07-08 04:48:04 +00:00
Mario Rodas
cbac932542 Merge pull request #129599 from NixOS/backport-129586-to-release-21.05
[Backport release-21.05] ruby: 2.6.7 -> 2.6.8, 2.7.3 -> 2.7.4, 3.0.1 -> 3.0.2
2021-07-07 22:36:21 -05:00
Mario Rodas
752d341f68 ruby_3_0: 3.0.1 -> 3.0.2
https://www.ruby-lang.org/en/news/2021/07/07/ruby-3-0-2-released/
(cherry picked from commit afd61a6069)
2021-07-08 03:11:51 +00:00
Mario Rodas
3e4c3a12d8 ruby_2_7: 2.7.3 -> 2.7.4
https://www.ruby-lang.org/en/news/2021/07/07/ruby-2-7-4-released/
(cherry picked from commit 5f9f17cc11)
2021-07-08 03:11:51 +00:00
Mario Rodas
94496bd7da ruby_2_6: 2.6.7 -> 2.6.8
https://www.ruby-lang.org/en/news/2021/07/07/ruby-2-6-8-released/
(cherry picked from commit 2d420c1559)
2021-07-08 03:11:50 +00:00
Mario Rodas
b97454a2e5 ruby: update RVM patchsets
(cherry picked from commit 6d4b46a56d)
2021-07-08 03:11:50 +00:00
Mario Rodas
977b522d31 Merge pull request #129588 from NixOS/backport-125696-to-release-21.05
[Backport release-21.05] nixos/postgresqlBackup: only replace if successful
2021-07-07 19:06:31 -05:00
github-actions[bot]
997532f793 Merge staging-next-21.05 into staging-21.05 2021-07-08 00:03:45 +00:00
github-actions[bot]
9c2d4051a8 Merge release-21.05 into staging-next-21.05 2021-07-08 00:02:47 +00:00
Robert Hensing
809cc5bf28 nixos/postgresqlBackup: Only replace backup when successful
Previously, a failed backup would always overwrite ${db}.sql.gz,
because the bash `>` redirect truncates the file; even if the
backup was going to fail.
On the next run, the ${db}.prev.sql.gz backup would be
overwritten by the bad ${db}.sql.gz.

Now, if the backup fails, the ${db}.in-progress.sql.gz is in an
unknown state, but ${db}.sql.gz will not be written.
On the next run, ${db}.prev.sql.gz (our only good backup) will
not be overwritten because ${db}.sql.gz does not exist.

(cherry picked from commit 81c8189a84)
2021-07-07 23:45:22 +00:00
Robert Hensing
44c232bbeb nixos/postgresqlBackup: Use PATH for readability
(cherry picked from commit c586e42763)
2021-07-07 23:45:22 +00:00
ckie
c06613c25d tor-browser-bundle-bin: 10.0.17 -> 10.0.18
(cherry picked from commit 4539cc164d)
2021-07-07 23:13:28 +02:00
roblabla
a9eb5aa7ff linux-kernel: Add dell drivers on 5.12+
(cherry picked from commit be03cf01f3)
2021-07-07 19:38:21 +00:00
github-actions[bot]
b73d2baff4 Merge staging-next-21.05 into staging-21.05 2021-07-07 18:02:44 +00:00
github-actions[bot]
decab02eae Merge release-21.05 into staging-next-21.05 2021-07-07 18:02:08 +00:00
Bruno Bigras
97554dd958 yggdrasil: 0.3.16 -> 0.4.0 (#129326)
The global yggdrasil network had a breaking protocol change

(cherry picked from commit 7265334f1a)
2021-07-07 13:22:28 -04:00
Pol Dellaiera
bd09551248 Bump GoLand and Datagrip.
(cherry picked from commit 4b064d11b15ed470f30200435245acdab7637778)
2021-07-07 08:28:57 -07:00
Michele Guerini Rocco
4d1e1c597d Merge pull request #129539 from rnhmjoj/pdns-back
pdns-recursor: 4.5.1 -> 4.5.4
2021-07-07 17:25:36 +02:00
rnhmjoj
779c81ec25 pdns-recursor: 4.5.1 -> 4.5.4 2021-07-07 16:03:29 +02:00
Atemu
261e8c7b98 zen-kernels: 5.12.9 -> 5.12.14
(cherry picked from commit 6733b6fb05)
2021-07-07 10:41:19 +00:00
Linus Heckemann
50af195f17 openexr: 2.5.3 -> 2.5.7
Fixes CVE-2021-3598

(cherry picked from commit 094ecab1a1)
2021-07-07 06:43:41 +00:00
github-actions[bot]
edba2d6e08 Merge staging-next-21.05 into staging-21.05 2021-07-07 06:03:22 +00:00
github-actions[bot]
11f817ede9 Merge release-21.05 into staging-next-21.05 2021-07-07 06:02:39 +00:00
Delan Azabani
e77385a232 bore: init at 0.3.3 (#129295)
(cherry picked from commit 8eb54b8e09)
2021-07-07 11:49:22 +08:00
Maximilian Bosch
b65f5d48a6 gitea: 1.14.3 -> 1.14.4
ChangeLog: https://github.com/go-gitea/gitea/releases/tag/v1.14.4
(cherry picked from commit 1e7417a55285407c8d57f79c78477c2d16ea4b95)
2021-07-07 03:22:20 +00:00
Sandro
133a81c2ec Merge pull request #129476 from unclechu/backport-psi-plus-bugfix-missed-gstreamer-dependencies-to-release-21.05 2021-07-07 03:00:26 +02:00
github-actions[bot]
82b9af92b4 Merge staging-next-21.05 into staging-21.05 2021-07-07 00:03:17 +00:00
github-actions[bot]
beef5b5c63 Merge release-21.05 into staging-next-21.05 2021-07-07 00:02:41 +00:00
Ben Siraphob
a5a9936a60 electron-cash: fix build on darwin
(cherry picked from commit a2c311fc1d)
2021-07-06 20:57:02 +00:00
Viacheslav Lotsmanov
654d8f9971 psi-plus: bugfix for missing gstreamer dependencies
Voice messages don’t work without gstreamer “base” and “good” plugins.
This change adds a an override for GST_PLUGIN_SYSTEM_PATH_1_0
environment variable providing necessary dependencies.

(cherry picked from commit 20d4e8bd39)
2021-07-06 23:12:05 +03:00
Vladimír Čunát
9d1350d9d5 Merge #129412: makeself: disable tests for now
Also improve the busybox-sandbox-shell.
(cherry picked from commit 00c86ad146)
The makeself problem is blocking the nixos-21.05 channel now.
2021-07-06 21:55:52 +02:00
Atemu
95fc4eb09d nixos/btrfs: handle new checksum types in initrd
Can't mount a root formatted with those otherwise

(cherry picked from commit e85f2f43bda6e0fe245005b710091f854a7f0200)
2021-07-06 14:00:40 +00:00
Lucas Savva
c192fd5d4c nixos/acme: Ensure certs are always protected
As per #121293, I ensured the UMask is set correctly
and removed any unnecessary chmod/chown/chgrp commands.
The test suite already partially covered permissions
checking but I added an extra check for the selfsigned
cert permissions.

(cherry picked from commit 083aba4f83)
2021-07-06 13:14:03 +00:00
github-actions[bot]
c4534a22dc Merge staging-next-21.05 into staging-21.05 2021-07-06 06:02:45 +00:00
github-actions[bot]
d0f8cc4c65 Merge release-21.05 into staging-next-21.05 2021-07-06 06:02:13 +00:00
Robert Schütz
d3ebf03151 python2Packages.certifi: init at 2019.11.28
We use the sources from 2019.11.28 to build, but inherit the cert bundle
from the maintained Python3-only version of certifi.

Co-authored-by: adisbladis <adisbladis@gmail.com>
(cherry picked from commit ada27b88e2)
2021-07-05 21:27:18 -07:00
fortuneteller2k
111c0c12be linux_xanmod: 5.12.13 -> 5.13.0
(cherry picked from commit 741f6efc6b)
2021-07-06 10:24:47 +08:00
github-actions[bot]
d3526b9312 Merge staging-next-21.05 into staging-21.05 2021-07-06 00:03:10 +00:00
github-actions[bot]
2cba83ecca Merge release-21.05 into staging-next-21.05 2021-07-06 00:02:35 +00:00
fortuneteller2k
3cd12115c5 linux_xanmod: 5.12.12 -> 5.12.13
(cherry picked from commit 419e4299a6)
2021-07-05 14:55:17 -07:00
Martin Weinelt
03d3dc1666 libuv: add patch for CVE-2021-22918
> libuv was vulnerable to out-of-bounds reads in the uv__idna_toascii()
> function which is used to convert strings to ASCII. This is called by
> the DNS resolution function and can lead to information disclosures or
> crashes.

b7466e31e4

Fixes: CVE-2021-22918
(cherry picked from commit 742b8f71f7)
2021-07-05 14:49:55 -07:00
Samuel Gräfenstein
431eed7521 kjv: 2018-12-25 -> 2021-03-11
(cherry picked from commit 6461cc71c3)
2021-07-05 18:34:38 +00:00
Maximilian Bosch
7ebf2d4f9b Merge pull request #129271 from NixOS/backport-129252-to-release-21.05
[Backport release-21.05] tcpdump: 4.99.0 -> 4.99.1
2021-07-05 20:22:50 +02:00
Yurii Matsiuk
d06db41bb7 linux/hardened/patches/5.4: 5.4.127-hardened1 -> 5.4.129-hardened1
(cherry picked from commit 338286e6b0)
2021-07-05 18:13:10 +00:00
Yurii Matsiuk
24d3d7b72c linux/hardened/patches/5.12: 5.12.12-hardened1 -> 5.12.14-hardened1
(cherry picked from commit 6643bf87ae)
2021-07-05 18:13:09 +00:00
Yurii Matsiuk
faa6d6b9b1 linux/hardened/patches/5.10: 5.10.45-hardened1 -> 5.10.47-hardened1
(cherry picked from commit 344bf9c20e)
2021-07-05 18:13:09 +00:00
Yurii Matsiuk
99d53a0c89 linux/hardened/patches/4.19: 4.19.195-hardened1 -> 4.19.196-hardened1
(cherry picked from commit 5a058ab384)
2021-07-05 18:13:09 +00:00
Yurii Matsiuk
15f8e24bc6 linux/hardened/patches/4.14: 4.14.237-hardened1 -> 4.14.238-hardened1
(cherry picked from commit c732335067)
2021-07-05 18:13:09 +00:00
Yurii Matsiuk
926c9aabc7 linux: 5.4.127 -> 5.4.129
(cherry picked from commit 5da58d1f67)
2021-07-05 18:13:08 +00:00
Yurii Matsiuk
b0214fccfb linux: 5.12.12 -> 5.12.14
(cherry picked from commit d28212b084)
2021-07-05 18:13:08 +00:00
Yurii Matsiuk
a18dea6fb6 linux: 5.10.45 -> 5.10.47
(cherry picked from commit f52103a4e6)
2021-07-05 18:13:08 +00:00
Yurii Matsiuk
dc34cf70c8 linux: 4.9.273 -> 4.9.274
(cherry picked from commit 24a5777be9)
2021-07-05 18:13:07 +00:00
Yurii Matsiuk
e168b5bcc9 linux: 4.4.273 -> 4.4.274
(cherry picked from commit ffdd1ac776)
2021-07-05 18:13:07 +00:00
Yurii Matsiuk
d638fb5525 linux: 4.19.195 -> 4.19.196
(cherry picked from commit a5394f31e8)
2021-07-05 18:13:07 +00:00
Yurii Matsiuk
78ff5dfec2 linux: 4.14.237 -> 4.14.238
(cherry picked from commit 1c15f4eef1)
2021-07-05 18:13:06 +00:00
Yurii Matsiuk
bc1ca1fa6b Revert "linux: fix regression in bridge VLAN configuration"
This reverts commit 24a08441d5.

(cherry picked from commit 2f0d1e41e2)
2021-07-05 18:13:06 +00:00
github-actions[bot]
e6d2640290 Merge staging-next-21.05 into staging-21.05 2021-07-05 18:02:58 +00:00
github-actions[bot]
956c0c163d Merge release-21.05 into staging-next-21.05 2021-07-05 18:02:21 +00:00
Fabián Heredia Montiel
2e755f3add pijul: 1.0.0-alpha.48 → 1.0.0-alpha.50
(cherry picked from commit bb6bdc62ec)
2021-07-05 16:47:04 +00:00
paumr
340976f347 cnijfilter_4_00: fix broken build
30286ebcc1 updated glibc to 2.32.
This removed the deprecated <sys/sysctl.h> header, which caused a build
error on this package.
Since this header doesn't seem to be required it was removed with this
patch.

(cherry picked from commit c9f2aeec17)
2021-07-05 18:25:41 +02:00
Thomas Gerbet
c57281c274 trafficserver: 9.0.1 -> 9.0.2
Fixes CVE-2021-32566 and CVE-2021-32567.

(cherry picked from commit d41e86c67f)
2021-07-05 16:07:35 +00:00
Bjørn Forsman
688f6ec8d7 nixos/hamster: fix programs.hamster.enable text
mkEnableOption already adds "Whether to enable" and ends with a ".", so
remove that duplication from the help text.

Also reword it slightly while at it.

(cherry picked from commit 5d3dca497b)
2021-07-05 14:32:16 +02:00
Mario Rodas
9f5b3edda9 nodejs-16_x: 16.4.1 -> 16.4.2
https://github.com/nodejs/node/releases/tag/v16.4.2
(cherry picked from commit 77f710d74c)
2021-07-05 04:20:00 +00:00
Mario Rodas
46fc920ae8 nodejs-14_x: 14.17.5 -> 14.17.6
https://github.com/nodejs/node/releases/tag/v14.17.6
(cherry picked from commit aff25d4cf0)
2021-09-01 07:37:51 -05:00
Mario Rodas
7dc3972bf5 nodejs-14_x: 14.17.4 -> 14.17.5
https://github.com/nodejs/node/releases/tag/v14.17.5
(cherry picked from commit 2a14fcb7f9)
2021-08-11 19:01:00 -05:00
Mario Rodas
ffffe30c14 nodejs-12_x: 12.22.5 -> 12.22.6
https://github.com/nodejs/node/releases/tag/v12.22.6
(cherry picked from commit 00fa834e55)
2021-09-01 07:37:23 -05:00
Mario Rodas
ffe7604c23 nodejs-12_x: 12.22.4 -> 12.22.5
https://github.com/nodejs/node/releases/tag/v12.22.5
(cherry picked from commit 16adcc430c)
2021-08-11 19:00:00 -05:00
Fabian Affolter
b77d450779 tcpdump: 4.99.0 -> 4.99.1
(cherry picked from commit 228adbbf71)
2021-07-04 20:29:05 +00:00
github-actions[bot]
e2056bc4b2 Merge staging-next-21.05 into staging-21.05 2021-07-04 00:03:23 +00:00
github-actions[bot]
013ea05e19 Merge release-21.05 into staging-next-21.05 2021-07-04 00:02:39 +00:00
Eduardo Sánchez Muñoz
4e3128d349 seafile-client: update source hash
It looks like the tag has been modified

(cherry picked from commit 1a4c9851c2)
2021-07-03 21:40:37 +02:00
Eduardo Sánchez Muñoz
4ab3794325 seafile-shared: update source hash
It looks like the tag has been modified

(cherry picked from commit 8f901848bf)
2021-07-03 21:40:18 +02:00
Eduardo Sánchez Muñoz
39e0ac53f8 seafile-client: 8.0.1 -> 8.0.3
(cherry picked from commit 004d1683b8)
2021-07-03 21:36:34 +02:00
Eduardo Sánchez Muñoz
6a36dabcfa seafile-shared: 8.0.1 -> 8.0.3
(cherry picked from commit 7644ef6f57)
2021-07-03 21:36:23 +02:00
Aaron Andersen
806c01c9f9 Merge pull request #128840 from NixOS/backport-126284-to-release-21.05
[Backport release-21.05] zabbixAgent: add bash to $PATH
2021-07-03 15:12:06 -04:00
github-actions[bot]
a581dcb108 Merge staging-next-21.05 into staging-21.05 2021-07-03 18:02:47 +00:00
github-actions[bot]
b657e42102 Merge release-21.05 into staging-next-21.05 2021-07-03 18:02:14 +00:00
Jörg Thalheim
9143023abb Merge pull request #129159 from NixOS/backport-129155-to-release-21.05
[Backport release-21.05] doc: point out that nixos-21.05 has gnuradio 3.9
2021-07-03 18:58:39 +01:00
Jörg Thalheim
7001c0cf15 Merge pull request #129158 from NixOS/backport-129153-to-release-21.05
[Backport release-21.05] doc: fix link to kodi-19.0 announcement
2021-07-03 18:58:16 +01:00
Bjørn Forsman
5ca9576f49 doc: point out that nixos-21.05 has gnuradio 3.9
Logically re-apply 64c70a8c4c ("doc: point out that nixos-21.05 has gnuradio
3.9"), because it was lost in the conversion from docbook to markdown, in
commit 32c2dd304d ("docs: nixos release notes to CommonMark (2105)").

(Apparently we have both .md and .xml release notes now, and CI fails
unless they have the same content (after .md processing), so update the
.xml file to match...)

(cherry picked from commit cfe8c3a75eaa427f48bc93b15c65b826c00d7401)
2021-07-03 17:44:27 +00:00
Bjørn Forsman
950142c900 doc: fix link to kodi-19.0 announcement
Logically re-apply 7afaacf9a8 ("doc: fix link to kodi-19.0 announcement"),
because it was lost in the conversion from docbook to markdown, in commit
32c2dd304d ("docs: nixos release notes to CommonMark (2105)").

(Hm, apparently we have *both* docbook and markdown? CI failed before I
updated the .xml file.)

(cherry picked from commit c2a3ff28be9712b598d84cdc94a7894ca59c772c)
2021-07-03 17:44:02 +00:00
Vladimír Čunát
fdaa714f38 Merge branch 'staging-next-21.05' into release-21.05 2021-07-03 15:17:49 +02:00
davidak
883e7d81a2 Merge pull request #128707 from NixOS/backport-128316-to-release-21.05
[Backport release-21.05] pantheon.notes-up: 2.0.2 -> unstable-2020-12-29
2021-07-03 15:02:15 +02:00
github-actions[bot]
d2c547f5b3 Merge staging-next-21.05 into staging-21.05 2021-07-03 12:03:13 +00:00
github-actions[bot]
f69d5bc5d0 Merge release-21.05 into staging-next-21.05 2021-07-03 12:02:32 +00:00
Jörg Thalheim
2a0b054afa Merge pull request #124935 from NixOS/backport-124690-to-release-21.05
[Backport release-21.05] bitwarden: 1.24.6 -> 1.26.4
2021-07-03 11:17:49 +01:00
Jörg Thalheim
9cc09d4302 Merge pull request #129078 from NixOS/backport-129012-to-release-21.05
[Backport release-21.05] python3Packages.django_3: 3.2.4 -> 3.2.5
2021-07-03 07:47:04 +01:00
Jörg Thalheim
fbf817714e Merge pull request #129073 from Mic92/dpdk-backport
[21.05] linuxPackages.dpdk: remove alias
2021-07-03 07:17:49 +01:00
Jörg Thalheim
fa55b0121e Merge pull request #128445 from maxeaubrey/21.05_go_1.16
[21.05] go_1_16: 1.16.4 -> 1.16.5
2021-07-03 07:06:11 +01:00
github-actions[bot]
978b57f31d Merge staging-next-21.05 into staging-21.05 2021-07-03 06:04:23 +00:00
Jörg Thalheim
c1bddbe5a1 Merge pull request #129077 from NixOS/backport-129042-to-release-21.05
[Backport release-21.05] tlaToolbox: fix crash on file open dialog
2021-07-03 07:02:57 +01:00
github-actions[bot]
31d5f83f39 Merge release-21.05 into staging-next-21.05 2021-07-03 06:02:17 +00:00
Martin Weinelt
a115c9d5e0 python3Packages.django_3: 3.2.4 -> 3.2.5
(cherry picked from commit d7e08efa95)
2021-07-03 05:51:20 +00:00
Sarunas Valaskevicius
15e437c635 tlaToolbox: fix crash on file open dialog
(cherry picked from commit 5b69b1f3fe)
2021-07-03 05:50:45 +00:00
Jörg Thalheim
035c6b0ee9 linuxPackages.dpdk: remove alias
This was causing evaluation errors in some instances.

Fixes https://github.com/NixOS/nixpkgs/issues/127275

(cherry picked from commit 0e82a32697)
2021-07-03 06:17:45 +02:00
Jörg Thalheim
fe80e34fef Merge pull request #126738 from NixOS/backport-126060-to-release-21.05
[Backport release-21.05] dpdk-kmods: init at 2021-04-21
2021-07-03 05:06:36 +01:00
Luke Granger-Brown
06f48c14d6 Merge pull request #129056 from NixOS/backport-128794-to-release-21.05
[Backport release-21.05] ceph: Enable cephfs-shell and use system liburing
2021-07-03 02:56:14 +01:00
ajs124
6ef0575e0f Merge pull request #128913 from helsinki-systems/bkp/21.05/php
[21.05] php73: 7.3.28 -> 7.3.29, php74: 7.4.20 -> 7.4.21, php80: 8.0.7 -> 8.0.8
2021-07-03 02:50:05 +02:00
Mario Rodas
91b3d48d6e Merge pull request #129053 from marsam/backport-128928-to-release-21.05
[21.05] nodejs: 12.22.1 -> 12.22.2, 14.17.0 -> 14.17.2, 16.2.0 -> 16.4.1
2021-07-02 19:47:46 -05:00
Luke Granger-Brown
03fb82074c Merge pull request #128699 from NixOS/backport-123474-to-release-21.05
[Backport release-21.05] yaxg: use ffmpeg instead of ffmpeg_3
2021-07-03 01:43:12 +01:00
Janne Heß
bae7213808 ceph: Enable cephfs-shell and use system liburing
(cherry picked from commit 196a7136a9)
2021-07-03 00:38:05 +00:00
github-actions[bot]
00ed470603 Merge staging-next-21.05 into staging-21.05 2021-07-03 00:06:44 +00:00
github-actions[bot]
a9f1434ec7 Merge release-21.05 into staging-next-21.05 2021-07-03 00:03:28 +00:00
Mario Rodas
6af75274fc beam: update reference to nodejs package
nodejs-15_x has reached EOL, and removed from nixpkgs.

(cherry picked from commit 39916f933e)
2021-07-02 18:43:50 -05:00
Mario Rodas
5225ed8b95 nodejs-15_x: remove expression
Node.js 15 has reached EOL on June 1, 2021.

(cherry picked from commit fd918d34bd)
2021-07-02 18:43:50 -05:00
Mario Rodas
0cde4bf18f nodejs-16_x: 16.4.0 -> 16.4.1
https://github.com/nodejs/node/releases/tag/v16.4.1
(cherry picked from commit 4f90b61a11)
2021-07-02 18:43:49 -05:00
Mario Rodas
3de5eef80f nodejs-14_x: 14.17.1 -> 14.17.2
https://github.com/nodejs/node/releases/tag/v14.17.2
(cherry picked from commit 282c97bb27)
2021-07-02 18:43:49 -05:00
Mario Rodas
77f9266ab7 nodejs-12_x: 12.22.1 -> 12.22.2
https://github.com/nodejs/node/releases/tag/v12.22.2
(cherry picked from commit a7a66aa2ea)
2021-07-02 18:43:48 -05:00
Mario Rodas
1e27742a0c nodejs-16_x: 16.3.0 -> 16.4.0
https://github.com/nodejs/node/releases/tag/v16.4.0
(cherry picked from commit c50bd80253)
2021-07-02 18:43:31 -05:00
Mario Rodas
37573d9874 nodejs-16_x: 16.2.0 -> 16.3.0
https://github.com/nodejs/node/releases/tag/v16.3.0
(cherry picked from commit 969eb59f2f)
2021-07-02 18:43:30 -05:00
Mario Rodas
e12702b599 nodejs-14_x: 14.17.0 -> 14.17.1
https://github.com/nodejs/node/releases/tag/v14.17.1
(cherry picked from commit 3a61dc3cae)
2021-07-02 18:41:22 -05:00
Luke Granger-Brown
917357a287 nixos/tests/kernel-generic: fix evaluation
This is breaking the tarball build, because #128502 depends on this test
existing. After this commit, nixpkgs.tarball once again evaluates.

(cherry picked from commit 0dccbe2729)
2021-07-02 13:50:19 -07:00
Yurii Matsiuk
23b6a0735b linux_5_13: init at 5.13
(cherry picked from commit 367a53a82b)
2021-07-02 13:50:19 -07:00
Lengyel Balázs
db3b901f0b linux-kernel: update config for 5.13
(cherry picked from commit 2ac508d578)
2021-07-02 13:50:19 -07:00
John Ericson
4a448d3240 Merge pull request #129001 from obsidiansystems/ipfs_latest-for-stable
[21.05] ipfs: Add 0.9.0 in addition
2021-07-02 16:07:50 -04:00
Maximilian Bosch
4dab07340d Revert "libdrm: 2.4.105 -> 2.4.106"
This reverts commit edba06511c.
2021-07-02 20:52:55 +02:00
John Ericson
0b2fbb2fef ipfs: Add 0.9.0 in addition
IPFS evolves quite fast. The network protocol is compatible, but we
don't want to force migrations on stable, so we add a new version
instead.

See #100676 for last time we did this.

(Adapted from from commit d96ccfaf16)
2021-07-02 14:43:56 +00:00
John Ericson
aa24875207 ipfs: prepare to add 0.9 in addition
(cherry picked from commit 27949d611a)
2021-07-02 14:36:46 +00:00
Philipp Hausmann
d2352585bc slimserver: Fix user creation
(cherry picked from commit 8bfd84cf3c)
2021-07-02 10:58:22 +00:00
github-actions[bot]
c75ea2baa8 Merge staging-next-21.05 into staging-21.05 2021-07-02 00:05:13 +00:00
github-actions[bot]
fee3e6f902 Merge release-21.05 into staging-next-21.05 2021-07-02 00:04:25 +00:00
Robert Scott
21b696caf3 python3Packages.fastapi: 0.65.0 -> 0.65.2
resolves CVE-2021-32677

(cherry picked from commit f582fd6475)
2021-07-01 14:54:38 -07:00
Robert Scott
0949abcecd python3Packages.pydantic: 1.8.1 -> 1.8.2
resolves CVE-2021-29510

(cherry picked from commit 7bc6972957)
2021-07-01 14:54:38 -07:00
Andrew Childs
f77d176ec6 root: use pure CoreSymbolication on Darwin
The current build works by linking against CoreSymbolication in
/System/Library/PrivateFrameworks. This is impure and doesn't work in
newer versions of macOS.

See https://github.com/NixOS/nixpkgs/issues/128576

(cherry picked from commit 55dcd99859)
2021-07-01 13:56:15 -07:00
Martin Weinelt
3866043a12 Merge pull request #126280 from risicle/ris-datasette-CVE-2021-32670-r21.05
[21.05] python3Packages.datasette: add patch for CVE-2021-32670
2021-07-01 21:43:30 +02:00
ajs124
0319a28db8 phpPackages.dom: make patch conditional
corresponds to 4c424870e6, but we still
need the patch for php73
2021-07-01 21:21:17 +02:00
ajs124
beb567f715 php73: 7.3.28 -> 7.3.29
fixes CVE-2021-21705 and CVE-2021-21704

not cherry-picked from master, because that does not have php73 anymore
2021-07-01 20:57:54 +02:00
ajs124
ff22a4aecb php80: 8.0.7 -> 8.0.8
fixes CVE-2021-21705 and CVE-2021-21704
also various other bugs, see https://www.php.net/ChangeLog-8.php#8.0.8
for a complete changelog

(cherry picked from commit d0c10fc34c)
2021-07-01 20:49:46 +02:00
ajs124
d530ad5185 php74: 7.4.20 -> 7.4.21
fixes CVE-2021-21705 and CVE-2021-21704

(cherry picked from commit cf9fe3942e)
2021-07-01 20:49:20 +02:00
github-actions[bot]
530b7adc94 Merge staging-next-21.05 into staging-21.05 2021-07-01 18:02:43 +00:00
github-actions[bot]
13282759f6 Merge release-21.05 into staging-next-21.05 2021-07-01 18:02:09 +00:00
Jonathan Ringer
acc107f4be nixos/test/vault: fix assertion logic
"vault status" now returns exit code 2 when the
vault is still unsealed.

(cherry picked from commit 7737a0fc9c890bca80cd42d898f04edf6bf8f850)
2021-07-01 08:40:14 -07:00
Jonathan Ringer
2ff2298f07 vault: wrap with gawk glibc
Binary will shell out awk and getent

(cherry picked from commit 8161c0930504be8c30c51fa36374d751d3850b03)
2021-07-01 08:40:14 -07:00
Jonathan Ringer
3540e860f6 vault-bin: wrap with gawk glibc
Binary will shell out awk and getent

(cherry picked from commit 2c402cc7606684c595375bf78faedec23ef9913f)
2021-07-01 08:40:14 -07:00
Maximilian Bosch
ceff17c474 Merge pull request #128815 from NixOS/backport-128777-to-release-21.05
[Backport release-21.05] matrix-synapse: 1.37.0 -> 1.37.1
2021-07-01 14:22:29 +02:00
github-actions[bot]
0aefcd50cd Merge staging-next-21.05 into staging-21.05 2021-07-01 12:02:47 +00:00
github-actions[bot]
5cc5b72070 Merge release-21.05 into staging-next-21.05 2021-07-01 12:02:12 +00:00
Michael Weiss
b68c1fea12 Merge pull request #128864 from NixOS/backport-128860-to-release-21.05
[Backport release-21.05] signal-desktop: 5.7.0 -> 5.7.1
2021-07-01 11:35:19 +02:00
Michael Weiss
78ee2e1314 signal-desktop: 5.7.0 -> 5.7.1
(cherry picked from commit 37749817ad)
2021-07-01 09:17:24 +00:00
Peter Hoeg
dcb0bd97a2 wp-cli: 2.4.0 -> 2.5.0
(cherry picked from commit 298f1b18cb114f0f4d9c5a5eda8566a4946ae480)
2021-07-01 16:43:52 +08:00
Aaron Andersen
0315b6a3c7 zabbixAgent: add bash to $PATH
(cherry picked from commit a0a11fd22c)
2021-07-01 03:11:24 +00:00
github-actions[bot]
9f8cafe9c6 Merge staging-next-21.05 into staging-21.05 2021-07-01 00:03:14 +00:00
github-actions[bot]
5052d11c95 Merge release-21.05 into staging-next-21.05 2021-07-01 00:02:42 +00:00
talyz
71474d1e41 discourse: Add a proper plugin builder + a few initial packages
Some discourse plugins have Ruby dependencies and require a
specialized builder. This introduces a generic builder that can be
used whether the plugin has Ruby dependencies or not. It also adds a
set of pre-packaged plugins available through `discourse.plugins` and
provides an easy way to add more.

(cherry picked from commit 7671b90919)
2021-06-30 22:07:26 +00:00
talyz
0a64a8b87c discourse: Patch sources instead of using replace-literal
(cherry picked from commit f0ae7fdf7e)
2021-06-30 22:07:25 +00:00
talyz
3b84448e67 discourse: Fix plugin support
For plugins to work properly, their assets need to be precompiled
along with the rest of Discourse's assets. This means we need to build
new packages when the list of plugins change.

(cherry picked from commit 9af3672f4f)
2021-06-30 22:07:25 +00:00
Alexandru Scvortov
3ee32f0ea9 kubernetes: fix conntrack-tools package name, missing dir, and tests
(cherry picked from commit ab1567e812)
2021-06-30 21:26:24 +00:00
Edward Tjörnhammar
beb05a45aa jetbrains: updates
jetbrains.clion: 2021.1.1 -> 2021.1.2
jetbrains.datagrip: 2021.1.1 -> 2021.1.2
jetbrains.goland: 2021.1.1 -> 2021.1.2
jetbrains.idea-community: 2021.1.1 -> 2021.1.2
jetbrains.idea-ultimate: 2021.1.1 -> 2021.1.2
jetbrains.rider: 2021.1.2 -> 2021.1.3
jetbrains.webstorm: 2021.1.1 -> 2021.1.2

(cherry picked from commit 0bc05c2a1fa3a0ec8b51141b4794dbbed3fda732)
2021-06-30 14:12:52 -07:00
Sumner Evans
95a329a5d3 matrix-synapse: 1.37.0 -> 1.37.1
(cherry picked from commit 9d694395a8)
2021-06-30 20:52:10 +00:00
John Ericson
4337a821b8 buildRustCrate: Fix extra cross args
Do proper list separation, use ld not cc because rustc doesn't `-Wl,`.
2021-06-30 15:49:49 +00:00
Michael Weiss
1534df8902 Merge pull request #128771 from NixOS/backport-128619-to-release-21.05
[Backport release-21.05] signal-desktop: 5.6.2 -> 5.7.0
2021-06-30 17:48:14 +02:00
Michael Weiss
eb5a500b13 signal-desktop: 5.6.2 -> 5.7.0
(cherry picked from commit ea8bbfcae0)
2021-06-30 13:33:51 +00:00
Eduardo Sánchez Muñoz
e9148dc1c3 gnuradio3_8: 3.8.3.0 -> 3.8.3.1
(cherry picked from commit c8d0af7cff)
2021-06-30 00:24:41 -07:00
taku0
4a55c281f9 firefox: 89.0.1 -> 89.0.2
(cherry picked from commit cab7d36885)
2021-06-30 00:17:48 -07:00
taku0
6e66e25b06 firefox-bin: 89.0.1 -> 89.0.2
(cherry picked from commit 9c732514b7)
2021-06-30 00:17:48 -07:00
Mustafa Çalışkan
27b388113c multimc: hardcode jdk paths and use latest jdk by default
(cherry picked from commit 3fd5108780)
2021-06-30 00:06:03 -07:00
Mustafa Çalışkan
1374abeed1 multimc: 0.6.12 -> unstable-2021-06-21
(cherry picked from commit 46c373b5e5)
2021-06-30 00:06:03 -07:00
Zane van Iperen
f6aab9913b exfatprogs: init at 1.1.2
(cherry picked from commit a2292607a632f0dd4d4374ee16df2246292af478)
2021-06-29 23:56:46 -07:00
Sumner Evans
4ae8822f0a matrix-synapse: 1.36.0 -> 1.37.0
(cherry picked from commit 4de7808be3)
2021-06-29 23:53:27 -07:00
Luke Granger-Brown
8e109c5d8b pomerium: 0.13.3 -> 0.13.6
Fixes for:

 * GHSA-35vc-w93w-75c2 (CVE-2021-29651)
 * GHSA-fv82-r8qv-ch4v (CVE-2021-29652)

Closes #128410.
2021-06-29 23:25:44 -07:00
fortuneteller2k
6a033a0b1b pantheon.notes-up, notes-up: 2.0.2 -> unstable-2020-12-29
(cherry picked from commit 069c13eac9e40c4d41187da521b52a8c2cd7d3c9)
2021-06-30 01:25:52 +00:00
Robert Schütz
6c78cbfd6c yaxg: use ffmpeg instead of ffmpeg_3
(cherry picked from commit d496275b80)
2021-06-30 00:12:27 +00:00
Sandro
d2d1d3f189 Merge pull request #128487 from emmanuelrosa/jetty-cve
jetty: 9.4.39.v20210325 -> 9.4.41.v20210516
2021-06-30 01:48:39 +02:00
Maximilian Bosch
4ab914495c Merge pull request #128465 from NixOS/backport-128452-to-release-21.05
[Backport release-21.05] epson-escpr2: 1.1.25 -> 1.1.34
2021-06-30 00:01:30 +02:00
Mica Semrick
d9461786d3 exiv2: 0.27.3 -> 0.27.4
(cherry picked from commit 492e221ff9)
2021-06-29 21:13:09 +00:00
Eduardo Sánchez Muñoz
d9102c8aca gnuradio: 3.9.1.0 -> 3.9.2.0
- Add sopysdr support.
- Remove some workarounds around upstream issues.

(cherry picked from commit a7260e81fc)
2021-06-29 11:13:30 +00:00
Michele Guerini Rocco
71326cd12d Merge pull request #128596 from NixOS/backport-128520-to-release-21.05
[Backport release-21.05] qutebrowser: 2.2.3 -> 2.3.0
2021-06-29 09:31:02 +02:00
Charlotte Van Petegem
4fae706ade qutebrowser: 2.2.3 -> 2.3.0
(cherry picked from commit 7286fc29c5)
2021-06-29 06:55:14 +00:00
Michael Ashton
5079a07985 unison: patch 2.51.3
Add patch which fixes builds with (at least) ocaml 4.12.0, and
remove build constraint for 4.09.  Necessary because unison built
with 4.09 is not compatible with unison built with 4.12, e.g. on
recent Homebrew.

(cherry picked from commit 7282b4fc0389217c60fe788cb80d10f3e80e447d)
2021-06-29 08:23:38 +02:00
Robert Scott
0c699a515d Merge pull request #128441 from NixOS/backport-126532-to-release-21.05
[Backport release-21.05] olm: 3.2.2 -> 3.2.4
2021-06-29 00:19:57 +01:00
Linus Heckemann
623912568d Merge pull request #128555 from NixOS/backport-128479-to-release-21.05
[Backport release-21.05] tinc_pre: 1.1pre17 -> 1.1pre18
2021-06-28 23:23:12 +02:00
lassulus
2bd76aec3f tinc_pre: 1.1pre17 -> 1.1pre18
(cherry picked from commit d71d7ecef1)
2021-06-28 20:59:36 +00:00
Jonathan Ringer
bb60ebee93 Merge remote-tracking branch 'origin/release-21.05' into staging-next-21.05 2021-06-28 10:04:12 -07:00
Sandro
990eb36e53 Update pkgs/os-specific/linux/mwprocapture/default.nix
(cherry picked from commit 92d2a0ddeeb5e19e1bb3c43996bc0a18ddaf13a9)
2021-06-28 08:37:52 -07:00
Phil Wetzel
9af0e6e076 mwprocapture: 1.2.4177 -> 1.3.0.4236
(cherry picked from commit 4f22c47193b2608d4d28cd831d54c5bd384a29a5)
2021-06-28 08:37:52 -07:00
Jörg Thalheim
e10bc6e6dc Merge pull request #128446 from maxeaubrey/21.05_go_1.15
[21.05] go_1_15: 1.15.12 -> 1.15.13
2021-06-28 15:46:49 +01:00
Martin Weinelt
7f1993cdd2 Merge pull request #128499 from NixOS/backport-128495-to-release-21.05
[Backport release-21.05] wireless-regdb: 2020.04.29 -> 2021.04.21
2021-06-28 14:32:29 +02:00
Robert Schütz
bf3efb9692 ghostwriter: 2.0.1 -> 2.0.2
https://github.com/wereturtle/ghostwriter/releases/tag/2.0.2
(cherry picked from commit 596ae9e8a366d5279369f636bdf7bdd68ff31e70)
2021-06-28 14:14:54 +02:00
Yurii Matsiuk
08cd58d2a4 wireless-regdb: 2020.04.29 -> 2021.04.21
(cherry picked from commit 5ca20c29fa)
2021-06-28 12:14:48 +00:00
R. RyanTM
5c4faf5e5a jetty: 9.4.39.v20210325 -> 9.4.41.v20210516
backport jetty-9.4.41.v20210516 to nixos-21.05
to address CVE-2021-28169.

Closes #128381

(cherry picked from commit 8bfc237eb3)
2021-06-28 15:58:24 +07:00
Jörg Thalheim
f77036342e Merge pull request #128478 from Mic92/radare2-backport
[release-21.05] radare2: 5.3.0 -> 5.3.1
2021-06-28 07:37:49 +01:00
Maciej Krüger
2af67be4fc Merge pull request #128480 from mkg20001/maback 2021-06-28 08:23:48 +02:00
Maciej Krüger
1a409bd977 [Backport release-21.05] matomo: 4.2.1 -> 4.3.1
(cherry picked from commit 41ebb21aa46045d02fb8e7240c5f3fb01f7b1581)
2021-06-28 08:18:06 +02:00
Jörg Thalheim
07a29b5565 radare2: 5.3.0 -> 5.3.1
(cherry picked from commit 9afd1530d7)
2021-06-28 08:01:21 +02:00
Maximilian Bosch
b183984c47 epson-escpr2: 1.1.25 -> 1.1.34
(cherry picked from commit 6b0a1dfd4c)
2021-06-27 21:47:30 +00:00
Michele Guerini Rocco
1d7058d82d Merge pull request #128391 from NixOS/backport-128282-to-release-21.05
[Backport release-21.05] nixos/duplicity: fix typo in subcommand
2021-06-27 19:35:34 +02:00
zowoq
d08b831a2c go_1_16: 1.16.4 -> 1.16.5
(cherry picked from commit b3a05d2ccb)
2021-06-27 19:19:48 +02:00
zowoq
b718514bcd go_1_15: 1.15.12 -> 1.15.13
(cherry picked from commit d038f95450)
2021-06-27 19:19:24 +02:00
Alvar Penning
398c74fcd6 olm: 3.2.2 -> 3.2.4
(cherry picked from commit 660be4bfb2)
2021-06-27 16:58:10 +00:00
Dima
892a6d4ce6 nixos/duplicity: fix typo in subcommand
In https://github.com/NixOS/nixpkgs/pull/120622 cleanup options were
added, but `remove-all-inc-of-but-n-full` was misspelled and as such
was not functioning.

(cherry picked from commit 0a977cf125)
2021-06-27 16:38:12 +00:00
fortuneteller2k
4a774ab8f4 pan: fix build and format
(cherry picked from commit efe2e4e8c2)
2021-06-27 16:22:05 +00:00
Niklas Hambüchen
df8bcca5fb Merge pull request #128161 from NixOS/backport-128150-to-release-21.05
[Backport release-21.05] etcd: refactor the service to add etcd to systemPackages instead of the etcdctl alias
2021-06-27 14:28:07 +02:00
Vladimír Čunát
a58ab1cef0 Merge #127383: firefox*: 89.0 -> 89.0.1 (into release-21.05) 2021-06-27 09:42:16 +02:00
Robert Schütz
aa41a0df68 imagemagick7: 7.1.0-1 -> 7.1.0-2
(cherry picked from commit 1eef635d2376c7539b8b69d1058e0ae1a753d6fb)
2021-06-26 22:42:03 +02:00
Robert Schütz
8b705c3ffe Merge pull request #128209 from NixOS/backport-128178-to-release-21.05
[Backport release-21.05] imagemagick6: 6.9.12-16 -> 6.9.12-17
2021-06-26 20:10:51 +02:00
Robert Schütz
5b7119dcca imagemagick6: 6.9.12-16 -> 6.9.12-17
(cherry picked from commit adb518b5e94024462781bced3baa8a5ab05bd0d0)
2021-06-26 14:44:34 +00:00
Michael Weiss
a563a3c2d1 sway: 1.6 -> 1.6.1
Since wlroots 0.14 setting WLR_RENDERER_ALLOW_SOFTWARE=1 to allow
software rendering is now enforced [0].

[0]: https://github.com/swaywm/wlroots/pull/2810

(cherry picked from commit 73d7f08b4d)
2021-06-26 13:46:17 +02:00
Michael Weiss
bec2f8e481 wlroots: 0.13.0 -> 0.14.0
The new release comes with breaking changes so we temporarily introduce
wlroots_0_13 for packages that don't yet support wlroots 0.14.
For the rest of the packages the required upstream patches for this new
wlroots release are fetched (if feasible).

(cherry picked from commit 203c8edcda)
2021-06-26 13:46:17 +02:00
Michael Weiss
edba06511c libdrm: 2.4.105 -> 2.4.106
(cherry picked from commit 9057122e0f)
2021-06-26 13:46:16 +02:00
Florian Klink
9b0b85c868 Merge pull request #128146 from flokli/backport-add-missing-keep-baud
nixos/getty: add missing --keep-baud
2021-06-26 12:47:21 +02:00
Daniel Olsen
f2dc3cc2cd maintainers/teams: Add dandellion to matrix team
(cherry picked from commit 44a982a006)
2021-06-26 01:43:03 +00:00
Daniel Olsen
dce77c58c0 matrix-synapse: Add txredisapi as dependency when using redis
(cherry picked from commit 55e325032b)
2021-06-26 01:43:03 +00:00
Daniel Olsen
78747d071a pythonPackages.txredisapi: Add unit test
(cherry picked from commit f7f52a4fbf)
2021-06-26 01:43:02 +00:00
Daniel Olsen
986e784fe7 pythonPackages.txredisapi: init at 1.4.7
(cherry picked from commit 6d90bc1c11)
2021-06-26 01:43:02 +00:00
Alexandru Scvortov
733b7eedff etcd: fix old aliased package name to make tests pass
(cherry picked from commit e08b3f0c85)
2021-06-26 01:36:30 +00:00
Florian Klink
f4b92c2975 nixos/getty: add missing --keep-baud
systemd ships `units/serial-getty@.service.m4` with the `--keep-baud`
option.

We override that unit, and didn't add the `--keep-baud` option. (We have
it in our other getty options there).

Having `--keep-baud` in `serial-getty@` makes a lot of sense - the
console keeps working if it's initialized with a less standard baud
rate, such as the [Helios64](https://wiki.kobol.io/helios64/intro/).

(cherry picked from commit ba42d639f1)
2021-06-25 23:32:04 +02:00
Florian Klink
b72bde7c4a Merge pull request #128142 from NixOS/backport-128082-to-release-21.05
[Backport release-21.05] nixos/sdcard: make firmware partition offset configurable
2021-06-25 23:30:07 +02:00
Florian Klink
e453a9ed9b nixos/sdcard: make firmware partition offset configurable
Different boards using u-boot SPL require to write to different
locations. Sometimes, the 8MiB gap isn't sufficient - rk3399 boards
write to 0x16384 for example, which is at 8MiB, thus overriding the
fat32 partition with the SPL.

(cherry picked from commit 1db54a5522)
2021-06-25 20:55:28 +00:00
Marco A L Barbosa
b8b8cfa29c audit: use hostPlatform.isStatic instead of targetPlatform.isStatic
(cherry picked from commit 0034539aba)
2021-06-25 17:54:58 +00:00
Harrison Houghton
0630946f2c sourcetrail: fix
The LLVM headers it wants to copy are in
llvmPackages.clang-unwrapped.lib, not llvmPackages.clang-unwrapped.

(cherry picked from commit 76e2eb2d74)
2021-06-25 17:21:59 +00:00
Domen Kožar
265e982c9d Merge pull request #128110 from NixOS/backport-128108-to-release-21.05
[Backport release-21.05] blueman: 2.1.4 -> 2.2.1
2021-06-25 17:09:14 +02:00
Domen Kožar
e30a20ee46 blueman: 2.1.4 -> 2.2.1
(cherry picked from commit 1bb478f5be)
2021-06-25 14:49:12 +00:00
Michael Weiss
c83cd13ac2 Merge pull request #128100 from NixOS/backport-128091-to-release-21.05
[Backport release-21.05] signal-desktop: 5.6.1 -> 5.6.2
2021-06-25 15:46:20 +02:00
Michael Weiss
dcd4d90508 signal-desktop: 5.6.1 -> 5.6.2
(cherry picked from commit 07fdb0c375)
2021-06-25 13:09:55 +00:00
Elis Hirwing
e4d5cafe58 Merge pull request #126743 from etu/backport-21.05-php-extensions-updates
[Backport 21.05] php.extensions: Updates to multiple extensions
2021-06-25 12:34:16 +02:00
Jonathan Ringer
5299f12e63 Merge branch 'staging-next-21.05' into staging-21.05 2021-06-25 00:15:49 -07:00
Maxine Aubrey
8112fbe212 consul: 1.9.6 -> 1.9.7
(cherry picked from commit 0fdfa3172d)
2021-06-24 18:13:28 -07:00
R. RyanTM
b41d5aa715 consul: 1.9.5 -> 1.9.6
(cherry picked from commit 35ea60a0ff)
2021-06-24 18:13:28 -07:00
Robert Schütz
001f78ff00 zfs: 2.0.4 -> 2.0.5
https://github.com/openzfs/zfs/releases/tag/zfs-2.0.5
(cherry picked from commit ec8dbc11aa)
2021-06-24 16:01:59 -07:00
Maximilian Bosch
a4293c1d82 Merge pull request #128045 from NixOS/backport-128025-to-release-21.05
[Backport release-21.05] stellarium: 0.21.0 -> 0.21.1
2021-06-24 23:52:09 +02:00
Maximilian Bosch
2c1a36d521 stellarium: 0.21.0 -> 0.21.1
ChangeLog: https://github.com/Stellarium/stellarium/releases/tag/v0.21.1
(cherry picked from commit ea56e08d62)
2021-06-24 21:28:54 +00:00
Mario Rodas
c720e790df entr: fix segfault on darwin
(cherry picked from commit 23e36778a1)
2021-06-24 15:35:41 -04:00
Sandro
1301236557 Merge pull request #127928 from Ma27/bump-grafana-7-21.05
[21.05] grafana: 7.5.7 -> 7.5.9
2021-06-24 14:14:43 +02:00
Sandro
ca7d12ab5a Merge pull request #127992 from prusnak/electron-21.05 2021-06-24 13:46:33 +02:00
TredwellGit
0ad342052e xorg.libX11: 1.7.1 -> 1.7.2
https://lists.x.org/archives/xorg-announce/2021-June/003092.html
(cherry picked from commit e46a6ab222)
2021-06-24 10:26:02 +00:00
Jörg Thalheim
0b8b127125 Merge pull request #127877 from NixOS/backport-126014-to-release-21.05
[Backport release-21.05] all Jetbrains products: update to latest version
2021-06-24 10:17:41 +02:00
TredwellGit
549c222243 electron_12: 12.0.11 -> 12.0.12
https://github.com/electron/electron/releases/tag/v12.0.12
(cherry picked from commit c1f9347282)
2021-06-24 09:27:07 +02:00
TredwellGit
eba91e45a8 electron_11: 11.4.8 -> 11.4.9
https://github.com/electron/electron/releases/tag/v11.4.9
(cherry picked from commit 942f13fb87)
2021-06-24 09:26:21 +02:00
TredwellGit
64946bc3c2 xorg.libX11: 1.7.0 -> 1.7.1
https://lists.x.org/archives/xorg-announce/2021-May/003089.html
https://lists.x.org/archives/xorg-announce/2021-May/003088.html
(cherry picked from commit fa8d1b336d)
2021-06-24 06:37:52 +00:00
Shea Levy
f60fb4f6d0 terraform-providers.grafana: Fix download URL.
Apologies for the pushes straight to release without PR, I will follow
the new workflow moving forward. Unfortunately my last push broke the
package in a way that was invisible locally due to the source already
being downloaded... A perfect example of why we should let ofborg
build!
2021-06-23 17:57:40 -04:00
Shea Levy
387f1644ae terraform-providers.grafana: 1.10.0 -> 1.12.0
Requires backport due to https://github.com/grafana/terraform-provider-grafana/issues/212

(cherry picked from commit 08931215f4)
2021-06-23 17:41:08 -04:00
Maximilian Bosch
e4fe40fc56 Merge pull request #127238 from NixOS/backport-126616-to-release-21.05
[Backport release-21.05] pass: 1.7.3 -> 1.7.4
2021-06-23 21:12:34 +02:00
Maximilian Bosch
8498610343 Merge pull request #127831 from NixOS/backport-127699-to-release-21.05
[Backport release-21.05] element-{desktop,web}: 1.7.30 -> 1.7.31
2021-06-23 21:12:18 +02:00
Martin Weinelt
9246be50d6 Merge pull request #127366 from NixOS/backport-127340-to-release-21.05
[Backport release-21.05] appgate-sdp: 5.4.0 -> 5.4.2
2021-06-23 21:11:56 +02:00
Lancelot SIX
ac67481429 nettle: 3.7.2 -> 3.7.3
See https://lists.gnu.org/archive/html/info-gnu/2021-06/msg00002.html
for release information.

(cherry picked from commit be77650f3c)
2021-06-23 11:57:37 -07:00
Ryan Mulligan
01ae5cf705 Merge pull request #127939 from ryantm/backport-21.05-release-notes
[backport 21.05] docs: nixos release notes to CommonMark (2105)
2021-06-23 11:27:09 -07:00
David Arnold
8f89e4b6a1 docs: nixos release notes to CommonMark (2105)
docs: nixos release notes (revise code blocks)

docs: nixos release notes (fix opt links outside of code blocks)

docs: nixos release notes (fix opt links inside of code blocks)

went fishing with:

```console
rg -A1 \
   --multiline \
   --multiline-dotall \
   '<programlisting>[^</programlisting>]+' \
| rg linkend
```

docs: nixos release notes (prettier)

docs: nixos release notes (restore admonition from prettier destriction)

docs: nixos release notes (recreate xml files)

docs: nixos release notes (fix code block indentation)

docs: nixos release notes (diff after converting with https://github.com/NixOS/nixpkgs/pull/127270)
(cherry picked from commit 32c2dd304d)
2021-06-23 10:56:48 -07:00
Maximilian Bosch
e579ac33d2 grafana: 7.5.7 -> 7.5.9
ChangeLog: https://github.com/grafana/grafana/releases/tag/v7.5.8
ChangeLog: https://github.com/grafana/grafana/releases/tag/v7.5.9

While I don't think we should backport Grafana 8 to 21.05 without a good
reason, it still makes sense to apply patch-updates of v7 here.
2021-06-23 17:54:56 +02:00
Maximilian Bosch
2f752379bc Merge pull request #127789 from fortuneteller2k/backport-xanmod
[21.05] linux_xanmod: 5.12.5 -> 5.12.12
2021-06-23 15:23:16 +02:00
Maximilian Bosch
5ce08bc7b7 Merge pull request #127772 from NixOS/backport-127428-to-release-21.05
[Backport release-21.05] Kernels 2021-06-18
2021-06-23 15:23:06 +02:00
R. RyanTM
1cc810383a clamav: 0.103.2 -> 0.103.3
(cherry picked from commit 271c827b0e)
2021-06-23 13:15:48 +00:00
Jean-Marie Gaillourdet
d70ec738b3 all Jetbrains products: update to latest version
clion: 2020.2.1 -> 2021.1.2
datagrip: 2020.2.2 -> 2021.1.2
goland: 2020.2.2 -> 2021.1.2
idea-community: 2020.2.1 -> 2021.1.2
idea-ultimate: 2020.2.1 -> 2021.1.2
mps: 2020.1.4 -> 2021.1
phpstorm: 2020.2.1 -> 2021.1.3
pycharm-community: 2020.2.1 -> 2021.1.2
pycharm-professional: 2020.2.1 -> 2021.1.2
rider: 2020.2.1 -> 2021.1.3
ruby-mine: 2020.2.1 -> 2021.1.2
webstorm: 2020.2.1 -> 2021.1.2

These updates have all been generated with the newly fixed update.pl
script.

The script update.pl, which gets the latest versions from upstream
web server, has been failing for roughly half a year. It failed to
handle the new url pattern of MPS. The script and the url pattern
is updated to work with the latest version.

The clion specific postFixup hook had to be adapted, because names
of shared libraries changed.

(cherry picked from commit 8593496928ebacc8d0779ff5706b8d511dbc0177)
(cherry picked from commit a887b48e1d)
2021-06-23 09:10:12 +00:00
upkeep-bot
0ccd0d9136 vscode: 1.57.0 -> 1.57.1
(cherry picked from commit 1642cf81b3)
2021-06-23 16:03:54 +09:00
Michael Weiss
015d169c3f Merge pull request #127845 from NixOS/backport-127840-to-release-21.05
[Backport release-21.05] signal-desktop: 5.5.0 -> 5.6.1
2021-06-23 01:24:29 +02:00
Michael Weiss
aa6f5b6f91 signal-desktop: 5.5.0 -> 5.6.1
(cherry picked from commit 150a2f0b2e)
2021-06-22 22:56:36 +00:00
Martin Weinelt
3119030bdc Merge pull request #127843 from mweinelt/21.05/ansible 2021-06-23 00:51:21 +02:00
Martin Weinelt
eab26236af ansible_2_9: 2.9.22 -> 2.9.23
(cherry picked from commit e578f0f7d0)
2021-06-23 00:29:30 +02:00
Martin Weinelt
e352b011c2 ansible_2_10: 2.10.10 -> 2.10.11
(cherry picked from commit 10be06813d)
2021-06-23 00:29:25 +02:00
Milan Pässler
323d2080cb ansible_2_9: 2.9.21 -> 2.9.22
(cherry picked from commit 53448012e8)
2021-06-23 00:28:47 +02:00
Milan Pässler
3276bd576d ansible_2_10: 2.10.9 -> 2.10.10
(cherry picked from commit 6960d3b170)
2021-06-23 00:27:03 +02:00
TredwellGit
a5810d38e3 element-{desktop,web}: 1.7.30 -> 1.7.31
https://github.com/vector-im/element-web/blob/v1.7.31/CHANGELOG.md
https://github.com/vector-im/element-desktop/blob/v1.7.31/CHANGELOG.md
(cherry picked from commit 3eb0354b76)
2021-06-22 21:21:31 +00:00
Maximilian Bosch
dfc7bf3a65 Merge pull request #127651 from NixOS/backport-127637-to-release-21.05
[Backport release-21.05] vorta: 0.7.6 -> 0.7.7
2021-06-22 19:07:50 +02:00
Maximilian Bosch
4432fd7d23 Merge pull request #126594 from NixOS/backport-126551-to-staging-21.05
[Backport staging-21.05] glibc: 2.32-46 -> 2.32-48
2021-06-22 17:40:43 +02:00
Robert Hensing
eca1edd70d Merge pull request #127720 from NixOS/backport-127628-to-release-21.05
[Backport release-21.05] nixosTest: Force system.nixos.revision constant
2021-06-22 16:35:32 +02:00
fortuneteller2k
6fb054dda0 linux_xanmod: 5.12.5 -> 5.12.12
(cherry picked from commit 4fa80ae13a)
2021-06-22 22:20:24 +08:00
Francesco Gazzetta
fd334c5224 twemoji-color-font: 13.0.1 -> 13.1.0
(cherry picked from commit e0c9a230ce)
2021-06-22 14:18:56 +00:00
Jan Tojnar
f5d1823254 gnomeExtensions: Fix the package names
I did not realize the attribute names are derived from the Nix package names
so I accidentally, renamed them in https://github.com/NixOS/nixpkgs/pull/124295.

(cherry picked from commit 571d540abf)
2021-06-22 14:38:18 +02:00
Robert Schütz
944dafd903 Merge pull request #127780 from NixOS/backport-127775-to-staging-21.05
[Backport staging-21.05] imagemagick: 7.1.0-0 -> 7.1.0-1
2021-06-22 13:50:15 +02:00
Robert Schütz
d62fcd1c20 imagemagick6: 6.9.12-15 -> 6.9.12-16
(cherry picked from commit 4b1e53a46dd1315aee3639cad59c6fc66ea2597b)
2021-06-22 13:29:41 +02:00
Kerstin Humm
b867767ba1 imagemagick: 7.1.0-0 -> 7.1.0-1
(cherry picked from commit 1688ff519b)
2021-06-22 10:54:02 +00:00
TredwellGit
220b8ca902 linux: fix regression in bridge VLAN configuration
(cherry picked from commit 24a08441d5)
2021-06-22 08:41:57 +00:00
TredwellGit
1f180eafdb linux/hardened/patches/5.4: 5.4.126-hardened1 -> 5.4.127-hardened1
(cherry picked from commit df60fdef55)
2021-06-22 08:41:57 +00:00
TredwellGit
d2c67458d9 linux/hardened/patches/5.12: 5.12.11-hardened1 -> 5.12.12-hardened1
(cherry picked from commit d1e2575c4c)
2021-06-22 08:41:57 +00:00
TredwellGit
33ec269818 linux/hardened/patches/5.10: 5.10.44-hardened1 -> 5.10.45-hardened1
(cherry picked from commit cfd71fa4b5)
2021-06-22 08:41:57 +00:00
TredwellGit
f8a4c84f1b linux_latest-libre: 18115 -> 18132
(cherry picked from commit c43cd094c7)
2021-06-22 08:41:56 +00:00
TredwellGit
e539ffea84 linux: 5.4.126 -> 5.4.127
(cherry picked from commit 7c23102d03)
2021-06-22 08:41:56 +00:00
TredwellGit
257571a908 linux: 5.12.11 -> 5.12.12
(cherry picked from commit c4df7bfef7)
2021-06-22 08:41:56 +00:00
TredwellGit
085ba8376c linux: 5.10.44 -> 5.10.45
(cherry picked from commit 67ff76420c)
2021-06-22 08:41:56 +00:00
Michele Guerini Rocco
20d353f649 Merge pull request #127540 from NixOS/backport-127284-to-release-21.05
[Backport release-21.05] nixos-rebuild: fix --use-remote-sudo
2021-06-22 09:49:19 +02:00
Alvar Penning
8cdb09ee5e nginxModules.rtmp: 1.2.1 -> 1.2.2
This new release fixes segfaults,
https://github.com/arut/nginx-rtmp-module/compare/v1.2.1...v1.2.2

(cherry picked from commit 3690ae13a4)
2021-06-22 00:12:15 +00:00
Robert Scott
0e03bcd641 Merge pull request #127596 from elohmeier/sylpheed-bp
[21.05] sylpheed: Use SNI; fixes TLSv1.3 to imap.gmail.com
2021-06-21 22:19:49 +01:00
ajs124
94e57e81dd Merge pull request #127719 from NixOS/backport-127667-to-release-21.05
[Backport release-21.05] dovecot: 2.3.14 -> 2.3.15
2021-06-21 23:10:51 +02:00
David Arnold
1fd5950faa nixosTest: Force system.nixos.revision constant
nixos tests are blended with other system configurations, hence
their settings must be either enforced or defaulted.

This particular setting is set via lib.nixosSystem as
`system.nixos.revision = final.mkIf (self ? rev) self.rev;` which would
mean that without this change no flake generated nixos could be blended
with nixos testing.

This setting was made previously constant in
169c6b4b14 in order to avoid pointless
rebuilds of the testing VMs, but was set without enforcing it.

(cherry picked from commit 8bbdff4581)
2021-06-21 20:41:47 +00:00
ajs124
c466620ad2 dovecout: fix systemd unit dir
the configure flag we were using was dropped in
a42bb363b4

(cherry picked from commit 5fa6e9c403)
2021-06-21 20:23:26 +00:00
ajs124
1f762dbf63 dovecot_pigeonhole: add myself as maintainer
and fix licensing information

(cherry picked from commit fd83b193ac)
2021-06-21 20:23:26 +00:00
ajs124
c7db318b24 dovecot_pigeonhole: 0.5.14 -> 0.5.15
(cherry picked from commit 0187e72b57)
2021-06-21 20:23:25 +00:00
ajs124
0761599dd1 dovecot: add licenses
(cherry picked from commit 0fb5b6c648)
2021-06-21 20:23:25 +00:00
ajs124
588eb83ca7 dovecot: 2.3.14 -> 2.3.15
(cherry picked from commit 075fb19d81)
2021-06-21 20:23:25 +00:00
Kim Lindberger
3c6f3f84af Merge pull request #127679 from NixOS/revert-125407-patch-2
[21.05] Revert "php/generic: Allow to extend PHP_INI_SCAN_DIR"
2021-06-21 18:07:45 +02:00
Kim Lindberger
b04df2100f Merge pull request #127652 from NixOS/backport-127454-to-release-21.05
[Backport release-21.05] keycloak: 13.0.1 -> 14.0.0
2021-06-21 16:32:55 +02:00
Kim Lindberger
65a1707f25 Revert "[21.05] php/generic: Allow to extend PHP_INI_SCAN_DIR" 2021-06-21 16:08:31 +02:00
Sandro
0d85f682c5 Merge pull request #127388 from eduardosm/dash-to-panel 2021-06-21 13:31:22 +02:00
Michael Weiss
b66e719374 Merge pull request #127650 from NixOS/backport-127549-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 91.0.4472.101 -> 91.0.4472.114
2021-06-21 12:24:02 +02:00
Michael Weiss
c16274a260 Merge pull request #127458 from NixOS/backport-127426-to-release-21.05
[Backport release-21.05] chromium: fix APNG support
2021-06-21 12:01:36 +02:00
R. RyanTM
184202407f keycloak: 13.0.1 -> 14.0.0
(cherry picked from commit 0b204c6f48)
2021-06-21 09:59:00 +00:00
Maximilian Bosch
c2a1eb0bc6 vorta: 0.7.6 -> 0.7.7
ChangeLog: https://github.com/borgbase/vorta/releases/tag/v0.7.7
(cherry picked from commit 5244b041dc)
2021-06-21 09:54:37 +00:00
Michael Weiss
e8d68469fc ungoogled-chromium: 91.0.4472.101 -> 91.0.4472.114
(cherry picked from commit 4e201c1c3c)
2021-06-21 09:53:28 +00:00
Bjørn Forsman
d99688bba4 doc: point out that nixos-21.05 has gnuradio 3.9
Reading the release notes I got the impression that the latest (and
default) was GR3.8, but it is in fact 3.9. Make that more obvioius.

(cherry picked from commit c789c53ce55d26d4963b48cb109fd3f02838fa11)
2021-06-21 10:24:50 +02:00
Eduardo Sánchez Muñoz
e9194c796f gnomeExtensions.dash-to-panel: 40 -> 43
Supports GNOME 40

(cherry picked from commit 49ad3f7a53)
2021-06-20 23:37:44 +02:00
Enno Richter
2876d250e9 sylpheed: Use SNI; fixes TLSv1.3 to imap.gmail.com
(cherry picked from commit f28175adcf)
2021-06-20 22:28:01 +02:00
Bjørn Forsman
c40c611ff9 doc: fix link to kodi-19.0 announcement
(cherry picked from commit 14c8246c0c69e3cf48d332ede319238ec36247ed)
2021-06-20 20:10:29 +02:00
Kim Lindberger
8201fae0e3 Merge pull request #127575 from NixOS/backport-127063-to-release-21.05
[Backport release-21.05] nixos/fail2ban: Remove `reloadIfChanged = true`
2021-06-20 20:08:37 +02:00
Bjørn Forsman
2d857bc5fe gnomeExtensions.system-monitor: 2021-05-04 -> 2021-06-19
Fixes crash when opening "Preferences" in NixOS with GNOME 40.

Closes #123260.

(cherry picked from commit 7073a3722f)
2021-06-20 19:08:28 +02:00
Bjørn Forsman
ad213d9539 gnuradio.pkgs.ais: 2015-12-20 -> 2020-08-13
This adds support for GR3.8.

(cherry picked from commit 3e8fb944c2)
2021-06-20 16:55:06 +00:00
Sandro
e46a54b058 Merge pull request #127563 from dotlambda/certifi-disable-21.05
[21.05] pythonPackages.certifi: does not support python2
2021-06-20 18:38:53 +02:00
R. RyanTM
09ea65e0e2 jbang: 0.70.0 -> 0.71.1
(cherry picked from commit 717c938124)
2021-06-20 16:18:46 +00:00
Artturin
38a141da1c sweet: add gtk-engine-murrine
(cherry picked from commit 3ff86ab576)
2021-06-20 16:03:52 +00:00
talyz
d726b9c204 nixos/fail2ban: Remove reloadIfChanged = true
This makes the service fail when upgrading the package, so let's
properly restart it instead.

(cherry picked from commit b4c069b147)
2021-06-20 16:01:18 +00:00
Sandro
2e15be0725 Merge pull request #127393 from drupol/release-21.05
symfony-cli: 4.25.2 -> 4.25.4
2021-06-20 17:41:43 +02:00
Robert Schütz
e5ecc9fbfd pythonPackages.certifi: does not support python2
Support was officially dropped in
5efdd48f71

(cherry picked from commit 7748af9fff)
2021-06-20 15:48:14 +02:00
github-actions[bot]
60e4d510c2 [Backport release-21.05] linkerd: 2020-05-01 -> edge-21.6.2 (#127154) 2021-06-20 08:34:48 -03:00
Artturin
9d8db40541 mailspring: add wrapGAppsHook
(cherry picked from commit 64c69fa288)
2021-06-20 12:55:38 +02:00
rnhmjoj
d81e14f491 nixos-rebuild: fix --use-remote-sudo
Currently fails with:

  $ nixos-rebuild test --target-host myhost --use-remote-sudo
  building Nix...
  sudo: /run/current-system/sw/bin/sudo must be owned by uid 0 and have the setuid bit set

It seems setting an explicit PATH in the ssh command overrides the
remote setuid wrappers.

(cherry picked from commit 35a8d78e44)
2021-06-20 09:23:20 +00:00
Maximilian Bosch
e3c88e2a94 Merge pull request #127464 from Ma27/backport-diff-so-fancy
[21.05] gitAndTools.diff-so-fancy: 4.1.0 -> 4.1.2
2021-06-20 10:18:22 +02:00
Jan Tojnar
6613a30c5e gnomeExtensions: normalize pnames
They should have gnome-shell-extension prefix like most other extension packages.
This is what other distros listed on Repology use so Repology will be able to unify them.

Exception is chrome-gnome-shell, which is estabilished under that name.

(cherry picked from commit 5ba789eeca)
2021-06-20 08:54:10 +02:00
ajs124
f56b207e75 thunderbird: pass gnupg to passthru.updateScript
this fixes the tarball job

(cherry picked from commit 4e6e9adcd4 / PR #127504)
2021-06-20 08:28:44 +02:00
Michele Guerini Rocco
031e1105f2 Merge pull request #127507 from NixOS/backport-127368-to-release-21.05
[Backport release-21.05] searx: patch to fix a crash
2021-06-20 00:37:56 +02:00
rnhmjoj
459ad47968 searx: patch to fix a crash
If the `default_doi_resolver` and `use_default_settings` are used
together searx crashes.

(cherry picked from commit 2a90b3329b)
2021-06-19 22:10:57 +00:00
Thomas Gerbet
59979f8746 pythonPackages.impacket: 0.9.22 -> 0.9.23
Fixes CVE-2021-31800.
https://github.com/SecureAuthCorp/impacket/releases/tag/impacket_0_9_23

(cherry picked from commit 31c39c11ca)
2021-06-19 11:00:33 -07:00
Robert Schütz
f0393ff216 Merge pull request #127483 from NixOS/backport-127478-to-release-21.05
[Backport release-21.05] getmail6: 6.16 -> 6.17
2021-06-19 19:31:27 +02:00
Robert Schütz
426c25db0d getmail6: 6.16 -> 6.17
https://github.com/getmail6/getmail6/releases/tag/v6.17
(cherry picked from commit fbf187aafe)
2021-06-19 17:17:56 +00:00
Maximilian Bosch
2a27281bc1 gitAndTools.diff-so-fancy: 1.4.1 -> 1.4.2
ChangeLog: https://github.com/so-fancy/diff-so-fancy/releases/tag/v1.4.2
(cherry picked from commit d387353590)
2021-06-19 15:12:49 +02:00
Sandro Jäckel
73167dd575 diff-so-fancy: 1.4.0 -> 1.4.1
(cherry picked from commit 15eb917faf)
2021-06-19 15:12:49 +02:00
TredwellGit
fbeb67dd93 chromium: fix APNG support
https://bugs.chromium.org/p/chromium/issues/detail?id=752403
(cherry picked from commit 52651ca62a)
2021-06-19 11:17:50 +00:00
Michael Weiss
3f6b386e54 Merge pull request #127339 from NixOS/backport-127334-to-release-21.05
[Backport release-21.05] chromium: 91.0.4472.106 -> 91.0.4472.114
2021-06-19 12:17:53 +02:00
Thomas Gerbet
62f818272f spice: 0.14.2 -> 0.15.0
Fixes CVE-2021-20201.

(cherry picked from commit 05c0b157dca604b98d057951715cb01cdfe0e1af)
2021-06-19 07:51:13 +00:00
Maximilian Bosch
3532b90afe Merge pull request #127184 from NixOS/backport-127155-to-release-21.05
[Backport release-21.05] Kernels 2021-06-17
2021-06-19 01:23:01 +02:00
Maximilian Bosch
8c642ae6db Merge pull request #127409 from NixOS/backport-127380-to-release-21.05
[Backport release-21.05] gitea: 1.14.2 -> 1.14.3
2021-06-19 00:25:10 +02:00
Las Safin
55c5775d8f connman: 1.39 -> 1.40
(cherry picked from commit 12bc6bff40)
2021-06-18 22:12:43 +00:00
Robert Scott
d38e37ccf1 Merge pull request #126613 from NixOS/backport-125472-to-release-21.05
[Backport release-21.05] llvmPackages_12.compiler-rt: fix build on darwin
2021-06-18 22:45:26 +01:00
Robert Scott
cacfad81c1 Merge pull request #127403 from NixOS/backport-127159-to-release-21.05
[Backport release-21.05] bosh-cli: 6.4.3 -> 6.4.4
2021-06-18 21:47:05 +01:00
Maximilian Bosch
15d6e41814 gitea: 1.14.2 -> 1.14.3
ChangeLog: https://github.com/go-gitea/gitea/releases/tag/v1.14.3
(cherry picked from commit d5edee8113)
2021-06-18 20:41:00 +00:00
R. RyanTM
798a2dfaa7 bosh-cli: 6.4.3 -> 6.4.4
(cherry picked from commit dd1b930646)
2021-06-18 19:56:26 +00:00
Robert Scott
0e9b707b1d Merge pull request #126631 from NixOS/backport-126601-to-release-21.05
[Backport release-21.05] bosh-cli: init at 6.4.3
2021-06-18 20:38:20 +01:00
Pol Dellaiera
fc2b15a4f2 Bump from 4.25.2 to 4.25.4.
(cherry picked from commit ad8bc531cc)
2021-06-18 21:07:47 +02:00
taku0
1bdbbeb81b firefox/update.nix: Use fingerprint instead of keyid
(cherry picked from commit eaef28d6c4)
2021-06-18 17:40:15 +00:00
taku0
cc335b0e78 firefox-bin/update.nix: Use fingerprint instead of keyid
Co-authored-by: stigtsp <stig@stig.io>
(cherry picked from commit 044aab9fc2)
2021-06-18 17:40:15 +00:00
taku0
baeee9e9e0 firefox-bin: 89.0 -> 89.0.1
(cherry picked from commit 84306f5aae)
2021-06-18 17:40:15 +00:00
taku0
c1573ea19b firefox: 89.0 -> 89.0.1
(cherry picked from commit e330adceb9)
2021-06-18 17:40:15 +00:00
taku0
d612e8ab4a firefox, firefox-bin: fetch GPG key from keyring
(cherry picked from commit 1415289e67)
2021-06-18 17:40:15 +00:00
taku0
a84016df15 firefox: fix parameter of update.nix for ESR version
(cherry picked from commit 6aaaa019ce)
2021-06-18 17:40:14 +00:00
taku0
3987314eba firefox: use SHA512SUM in update.nix
(cherry picked from commit 8432387de2)
2021-06-18 17:40:14 +00:00
R. RyanTM
450eab40ac appgate-sdp: 5.4.0 -> 5.4.2
(cherry picked from commit 8c6c14f7a6)
2021-06-18 15:14:59 +00:00
Yurii Matsiuk
b587c9883b bluejeans: 2.21.3.2 -> 2.22.0.87
(cherry picked from commit 3601c66133)
2021-06-18 14:15:49 +00:00
Yurii Matsiuk
4be685dbdd bluejeans: add update script
(cherry picked from commit ba379085a0)
2021-06-18 14:15:49 +00:00
Michael Weiss
3715be19ec chromium: 91.0.4472.106 -> 91.0.4472.114
https://chromereleases.googleblog.com/2021/06/stable-channel-update-for-desktop_17.html

This update includes 4 security fixes. Google is aware that an exploit
for CVE-2021-30554 exists in the wild.

CVEs:
CVE-2021-30554 CVE-2021-30555 CVE-2021-30556 CVE-2021-30557

(cherry picked from commit 0505ed81bc)
2021-06-18 10:48:25 +00:00
Alyssa Ross
bad3ccd099 makeDBusConf: make apparmor argument optional
The only in-tree use of this is the DBus NixOS module, which always
passes apparmor (but the services.dbus.apparmor option defaults to
"disabled").  Set the default in the function as well so other users
of the function can take advantage of it.

(cherry picked from commit e9f45cc69d6fb2a2e2446ce9606eb7e9c376959f)
2021-06-17 20:20:32 +00:00
sternenseemann
17c83897a5 pass: 1.7.3 -> 1.7.4
Mostly bug fixes, the following changes were required in the package:

* set-correct-program-name-for-sleep.patch needed to be rebased,
  b08781e2a6e183986eb1c24f51cdeff879b7a6af partially implemented
  the changes done in this patch, so we don't need to touch
  password-store.sh anymore.

* Remove wayland patch since it is part of the release now

* Reworked assert logic wrt to x11-/wayland- and dmenuSupport:
  passmenu now supports wayland as well via dmenu-wayland. Sadly
  the choice of menu is not changeable, pending
  https://lists.zx2c4.com/pipermail/password-store/2021-January/004363.html

* Rebased no-darwin-getopt.patch

* Note that f.el is no longer required

Reviews would be appreciated, I might've missed something.

(cherry picked from commit 9b794eb21a)
2021-06-17 16:32:19 +00:00
TredwellGit
efb61e9e83 linux/hardened/patches/5.4: 5.4.125-hardened1 -> 5.4.126-hardened1
(cherry picked from commit 98642dcfd9)
2021-06-17 04:45:40 +00:00
TredwellGit
55875793a1 linux/hardened/patches/5.12: 5.12.10-hardened1 -> 5.12.11-hardened1
(cherry picked from commit ec53be76f2)
2021-06-17 04:45:40 +00:00
TredwellGit
d14bae7155 linux/hardened/patches/5.10: 5.10.43-hardened1 -> 5.10.44-hardened1
(cherry picked from commit 9e42f0075a)
2021-06-17 04:45:40 +00:00
TredwellGit
5abf0043a3 linux/hardened/patches/4.19: 4.19.194-hardened1 -> 4.19.195-hardened1
(cherry picked from commit 00eb48b68b)
2021-06-17 04:45:40 +00:00
TredwellGit
c96a2fc4c9 linux/hardened/patches/4.14: 4.14.236-hardened1 -> 4.14.237-hardened1
(cherry picked from commit a7b1c72c5e)
2021-06-17 04:45:39 +00:00
TredwellGit
60151d59c3 linux: 5.4.125 -> 5.4.126
(cherry picked from commit d0860fef88)
2021-06-17 04:45:39 +00:00
TredwellGit
c6d46ca2e4 linux: 5.12.10 -> 5.12.11
(cherry picked from commit 14510ff4ea)
2021-06-17 04:45:39 +00:00
TredwellGit
b7afdec506 linux: 5.10.43 -> 5.10.44
(cherry picked from commit 5382c2856d)
2021-06-17 04:45:39 +00:00
TredwellGit
81536c15d3 linux: 4.9.272 -> 4.9.273
(cherry picked from commit b9d8e45251)
2021-06-17 04:45:39 +00:00
TredwellGit
18da963255 linux: 4.4.272 -> 4.4.273
(cherry picked from commit ecf27f78d3)
2021-06-17 04:45:38 +00:00
TredwellGit
76cb349cb2 linux: 4.19.194 -> 4.19.195
(cherry picked from commit c6e07a72e7)
2021-06-17 04:45:38 +00:00
TredwellGit
ae8b337041 linux: 4.14.236 -> 4.14.237
(cherry picked from commit 5efcab85a6)
2021-06-17 04:45:38 +00:00
Martin Weinelt
246502ae2d Merge pull request #126553 from NixOS/backport-126422-to-release-21.05
[Backport release-21.05] apacheHttpd: 2.4.47 -> 2.4.48
2021-06-17 01:05:00 +02:00
Martin Weinelt
36bb4e1ebe Merge pull request #127141 from NixOS/backport-125770-to-release-21.05
[Backport release-21.05] nixos/acme: Remove an incorrect assertion from tests
2021-06-17 00:55:45 +02:00
Mewp
38088e7229 nixos/acme: Remove an incorrect assertion from tests
Commit 3a2e0c36e7 has removed
`--reuse-key` from default renew options, yet the tests still expected
keys not to change. This assertion is now removed, as they are supposed
to change on each renew/change.

(cherry picked from commit b00bcf21ab)
2021-06-16 22:03:03 +00:00
Sandro
50236d44c0 Merge pull request #127122 from NixOS/backport-123843-to-release-21.05 2021-06-16 23:53:25 +02:00
Martin Weinelt
460e210a58 Merge pull request #127132 from NixOS/backport-126521-to-staging-21.05
[Backport staging-21.05] dhcp: 4.4.2 -> 4.4.2-P1
2021-06-16 22:40:47 +02:00
Thomas Gerbet
fb93bad76c dhcp: 4.4.2 -> 4.4.2-P1
Fixes CVE-2021-25217.
https://kb.isc.org/docs/cve-2021-25217

(cherry picked from commit efc86b71a4)
2021-06-16 20:16:28 +00:00
Martin Weinelt
a21b8237f1 microcodeIntel: 20210216 -> 20210608
(cherry picked from commit d94f35f69b)
2021-06-16 13:12:03 -07:00
Artturin
2629acdcb0 discord-canary: 0.0.124 -> 0.0.125
(cherry picked from commit 7c7adc7b20)
2021-06-16 13:03:35 -07:00
Jan Tojnar
0e9cfa787f doc/gnome: document GIO modules
In particular, that glib-networking is required for TLS support.

(cherry picked from commit 653bd18d51)
2021-06-16 12:49:08 -07:00
OPNA2608
213c7f5bbe ptcollab: 0.4.0 -> 0.4.1
(cherry picked from commit dffffdc912)
2021-06-16 12:48:41 -07:00
lunik1
b682bf2892 Update pkgs/misc/emulators/ppsspp/default.nix
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit 89cbb28f64)
2021-06-16 18:50:00 +00:00
lunik1
70bbb7063c ppsspp: fix build against ffmpeg 4.4
(cherry picked from commit babd906230)
2021-06-16 18:50:00 +00:00
Michael Weiss
314d647bf7 Merge pull request #127113 from NixOS/backport-127109-to-release-21.05
[Backport release-21.05] signal-desktop: 5.4.1 -> 5.5.0
2021-06-16 20:14:18 +02:00
Michael Weiss
4561a449da signal-desktop: 5.4.1 -> 5.5.0
(cherry picked from commit fcda0d80a3)
2021-06-16 17:18:06 +00:00
Sandro
947f18f297 Merge pull request #127105 from NixOS/backport-127050-to-release-21.05 2021-06-16 18:31:26 +02:00
06kellyjac
7de7910c12 deno: 1.11.0 -> 1.11.1
(cherry picked from commit a58e5facde)
2021-06-16 15:57:29 +00:00
Vincent Laporte
9420363b95 ocamlPackages.lwt: 5.4.0 → 5.4.1
(cherry picked from commit 13e6c217524f53e44e65a55d58461b12fadc2043)
2021-06-16 17:31:36 +02:00
Martin Weinelt
0d40179fd4 Merge pull request #127076 from NixOS/backport-127044-to-release-21.05 2021-06-16 14:00:21 +02:00
Vladimír Čunát
73d3525b3d knot-dns: add passthru.tests
I hope I got the conventions right (found in doc/stdenv/meta.chapter.md)

(cherry picked from commit cf0b179b5e)
2021-06-16 11:40:01 +00:00
Vladimír Čunát
26febe6bdc knot-dns: 3.0.6 -> 3.0.7
Fixes various bugs and introduces a few requested features.
https://gitlab.nic.cz/knot/knot-dns/-/tags/v3.0.7

(cherry picked from commit 28dd3b6177)
2021-06-16 11:40:01 +00:00
Robert Schütz
5b79115614 Merge pull request #125567 from risicle/ris-python-websockets-CVE-2018-1000518-redux-r21.05
[21.05] python3Packages.websockets: add patch for CVE-2021-33880
2021-06-16 13:27:50 +02:00
Michael Weiss
2cd7bc6b9e Merge pull request #126933 from NixOS/backport-126924-to-release-21.05
[Backport release-21.05] chromium: 91.0.4472.101 -> 91.0.4472.106
2021-06-16 12:56:10 +02:00
Martin Weinelt
b8780177a7 Merge pull request #127016 from mweinelt/21.05/solanum 2021-06-16 12:18:53 +02:00
Maximilian Bosch
b3761f1173 Merge pull request #125967 from NixOS/backport-125953-to-release-21.05
[Backport release-21.05] matrix-appservice-discord: increase test timeout
2021-06-16 11:48:48 +02:00
Maximilian Bosch
e6fa9bb865 Merge pull request #127055 from NixOS/backport-126607-to-release-21.05
[Backport release-21.05] matrix-synapse: 1.35.1 -> 1.36.0
2021-06-16 11:20:21 +02:00
Kim Lindberger
b6cef599a4 Merge pull request #125407 from dxops/patch-2
[21.05] php/generic: Allow to extend PHP_INI_SCAN_DIR
2021-06-16 10:48:42 +02:00
Sumner Evans
3840b4082c matrix-synapse: 1.35.1 -> 1.36.0
(cherry picked from commit 3acb9eb23f)
2021-06-16 08:35:39 +00:00
Serhii Zhuravel
c46cf1c4e6 Allow to extend PHP_INI_SCAN_DIR
Fixes #109383
Master 9fb4d19c2e
2021-06-16 11:23:00 +03:00
github-actions[bot]
17c0585cd1 [Backport release-21.05] texlive: allow substitutes for texlive packages (#126866)
* texlive: allow substitutes for texlive packages

(cherry picked from commit 0f1e7e09b56cc8d98c5d02b87dd2626be9456d9c)

(cherry picked from commit 54cd3b840d4043322da7cfefd3a7d8ee80d68bc4)

Co-authored-by: Vincenzo Mantova <xworld21@users.sf.net>
2021-06-16 09:33:33 +02:00
Kim Lindberger
dfbaf6023d Merge pull request #127014 from NixOS/backport-126969-to-release-21.05
[Backport release-21.05] discourse: 2.7.0 -> 2.7.4
2021-06-16 09:26:57 +02:00
Maximilian Bosch
25fab5232e Merge pull request #127023 from NixOS/backport-126988-to-release-21.05
[Backport release-21.05] mautrix-whatsapp: unstable-2021-06-15 -> 0.1.7
2021-06-16 08:41:54 +02:00
Maximilian Bosch
f6ed1a99f4 mautrix-whatsapp: unstable-2021-06-15 -> 0.1.7
ChangeLog: https://github.com/tulir/mautrix-whatsapp/releases/tag/v0.1.7

Not a functional change as I already included all the fixes in my
previous bump, but I think it's better to use a stable tag by default to
build :)

(cherry picked from commit 6e4ce70535)
2021-06-16 01:48:55 +00:00
Sandro
d0f7ecb335 Merge pull request #126942 from markuskowa/pr-openblas-avx512
[21.05] openblas: disable AVX512, make optional
2021-06-16 03:24:28 +02:00
Martin Weinelt
b36d51733c solanum: clarify license to be gpl2 or later
(cherry picked from commit 2441e82399)
2021-06-16 02:09:13 +02:00
Martin Weinelt
6ee61426da nixos/solanum: implement reload and allow config changes
Reload only works with a static configuration path as there is no way to
pass the dynamically generated config path to a running solanum
instance, therefore we symlink the configuration to
/etc/solanum/ircd.conf.

But that will prevent reloads of the ircd, because the systemd unit
wouldn't change when the configuration changes. That is why we add the
actual location of the config file to restartTriggers and enable
reloadIfChanged, so changes will not restart, but reload on changes.

(cherry picked from commit 60c62214f5)
2021-06-16 02:09:04 +02:00
lassulus
0a8684cadd solanum: remove obsolete BANDB settings/patches
(cherry picked from commit 8eb5701aaf)
2021-06-16 02:09:00 +02:00
talyz
4eec52ae4e discourse: 2.7.0 -> 2.7.4
(cherry picked from commit f7fb0d20a6)
2021-06-15 23:21:04 +00:00
Martin Weinelt
c0c5925832 Merge pull request #127009 from NixOS/backport-125890-to-release-21.05 2021-06-16 01:02:05 +02:00
Martin Weinelt
225f11b219 Merge pull request #127011 from NixOS/backport-125011-to-release-21.05
[Backport release-21.05] solanum: fix MOTD
2021-06-16 00:56:51 +02:00
Christine Dodrill
f5c9fcff45 solanum: fix MOTD
Previously this defaulted to the default MOTD in the solanum source
tree, and I don't want my friends to laugh at me. Includes a patch to
the tests to ensure that the MOTD is actually set.

This replicates the fix done in #109705 (solanum is a fork of charybdis,
so they share fundamental logic for this).

Signed-off-by: Christine Dodrill <me@christine.website>
(cherry picked from commit b1fe9fab6f)
2021-06-15 22:54:15 +00:00
Martin Weinelt
24bf8db5a6 Merge pull request #127008 from NixOS/backport-125302-to-staging-21.05
[Backport staging-21.05] spidermonkey_78: 78.8.0 -> 78.11.0
2021-06-16 00:46:49 +02:00
Martin Weinelt
3fb4c3765f mfc9140cdncupswrapper: init at 1.1.4-0
(cherry picked from commit 76f168a4f1)
2021-06-15 22:45:28 +00:00
Martin Weinelt
a7797852a3 mfc9140cdnlpr: init at 1.1.2-1
(cherry picked from commit f52c8862c9)
2021-06-15 22:45:28 +00:00
Martin Weinelt
6a5755d960 spidermonkey_78: 78.8.0 -> 78.11.0
(cherry picked from commit c0a0f6ceee)
2021-06-15 22:44:19 +00:00
Martin Weinelt
f3df87c34e Merge pull request #126370 from NixOS/backport-126245-to-release-21.05
[Backport release-21.05] matrix-appservice-irc: 0.26.0 -> 0.26.1
2021-06-15 23:58:18 +02:00
Robert Hensing
6dc9b7d832 Merge pull request #126986 from NixOS/backport-126922-to-release-21.05
[Backport release-21.05] nixos/ssh: Add an example of verbatim keys
2021-06-15 22:50:37 +02:00
Maximilian Bosch
cf267b0e40 Merge pull request #126974 from NixOS/backport-126966-to-release-21.05
[Backport release-21.05] mautrix-whatsapp: 0.1.6 -> unstable-2021-06-15
2021-06-15 22:41:43 +02:00
Robert Hensing
91d03cd360 nixos/ssh: Document authorizedKeysFiles properly
(cherry picked from commit dab747106e)
2021-06-15 19:42:28 +00:00
Robert Hensing
89ecb51a6a nixos/ssh: Add an example of verbatim keys
This confused someone on SO.

(cherry picked from commit 8352cc9a23)
2021-06-15 19:42:27 +00:00
Jörg Thalheim
bb1af496c5 Merge pull request #126757 from cmm/backport-clangd-wrapper-fix
clang-tools: fix clangd
2021-06-15 20:05:12 +02:00
Maximilian Bosch
123ba7a68b mautrix-whatsapp: 0.1.6 -> unstable-2021-06-15
On `master` there are a few more bugfixes. Most notably, each message
sent by me was marked as "not sent" by WhatsApp for the last four days
until you hit a "Resend" in WhatsApp.

As the update to the latest `master` has solved the issue and being able
to correctly send messages is one of the core features of this package,
I decided to update the package in `nixpkgs` as well.

(cherry picked from commit 5c7156faf1)
2021-06-15 17:44:36 +00:00
Guillaume Girol
c98f59e292 Merge pull request #126700 from symphorien/ttrss-tumblr-gdpr-stable
[21.05] tt-rss-plugin-tumblr-gdpr: 2.1 -> 2.2
2021-06-15 17:37:51 +00:00
Domen Kožar
57606ed0af Merge pull request #126605 from NixOS/backport-125311-to-release-21.05
[Backport release-21.05] pipewire: 0.3.27 -> 0.3.30
2021-06-15 18:44:16 +02:00
Kim Lindberger
ddc012dbea Merge pull request #126959 from NixOS/backport-126380-to-release-21.05
[Backport release-21.05] gitlab: Make sure the FOSS version isn't identified as EE
2021-06-15 18:00:01 +02:00
ajs124
e6d907f59e Merge pull request #126951 from NixOS/backport-126741-to-release-21.05
[Backport release-21.05] sogo: 5.0.1 -> 5.1.1
2021-06-15 17:43:34 +02:00
Samuel Gräfenstein
044a0d06c7 nixos-rebuild: fix creating ./result symlink for flakes
(cherry picked from commit 531dc2e0f12673cce9cc6ea3dc5fd8bfef39c9bf)
2021-06-15 15:21:24 +00:00
talyz
d3d1674b3f gitlab: Make sure the FOSS version isn't identified as EE
(cherry picked from commit 8f16b16291)
2021-06-15 15:16:10 +00:00
Kim Lindberger
34b9ccb9c8 Merge pull request #126956 from NixOS/backport-126892-to-release-21.05
[Backport release-21.05] gitlab: 13.12.3 -> 13.12.4
2021-06-15 17:10:34 +02:00
Milan Pässler
bcdb378e19 gitlab: 13.12.3 -> 13.12.4
https://about.gitlab.com/releases/2021/06/14/gitlab-13-12-4-released/
(cherry picked from commit 5c04139da2)
2021-06-15 14:55:09 +00:00
Martin Weinelt
7d3289094d Merge pull request #126948 from stigtsp/package/convos-6.24-backport-21.05 2021-06-15 16:24:32 +02:00
github-actions[bot]
fe67150321 prometheus-node-exporter: fix version info (#126722)
Closes #126359

(cherry picked from commit ad5830098f6add9a4fae2b0fe01afcd374292eaa)

Co-authored-by: Maximilian Bosch <maximilian@mbosch.me>
2021-06-15 10:12:28 -04:00
Thomas Gerbet
df5b0a3a8e sope: 5.0.1 -> 5.1.1
(cherry picked from commit 2e10f973b5)
2021-06-15 14:01:08 +00:00
Thomas Gerbet
9ec98998e2 sogo: 5.0.1 -> 5.1.1
Fixes CVE-2021-33054.
https://github.com/inverse-inc/sogo/blob/SOGo-5.1.1/CHANGELOG.md

(cherry picked from commit f528b1e43e)
2021-06-15 14:01:08 +00:00
Stig Palmquist
f13ce435a4 convos: 6.11 -> 6.24
(cherry picked from commit 09b17967b3)
2021-06-15 15:46:41 +02:00
Stig Palmquist
b0b44c1c1d perlPackages.MojoliciousPluginWebpack: 0.14 -> 1.01
(cherry picked from commit f09f0be183)
2021-06-15 15:46:30 +02:00
Sandro
856dc82a7f Merge pull request #126654 from drupol/feature/add-symfony-cli-backport 2021-06-15 15:02:46 +02:00
Markus Kowalewski
95bb2c374f openblas: disable AVX512, make optional
This effectly reverts 383075f38b.

Some AVX512 optimized kernels seem to be broken in openblas.
See https://github.com/NixOS/nixpkgs/issues/124250.

(cherry picked from commit 5946bc724f)
2021-06-15 13:58:20 +02:00
Michael Weiss
f47f0e58dc chromium: 91.0.4472.101 -> 91.0.4472.106
https://chromereleases.googleblog.com/2021/06/stable-channel-update-for-desktop_14.html
(cherry picked from commit 8540133fb7)
2021-06-15 11:17:15 +00:00
Domen Kožar
6c784b44c7 Merge pull request #126852 from NixOS/backport-126844-to-release-21.05
[Backport release-21.05] openssl: fix Darwin cross infinite recursion
2021-06-15 12:00:16 +02:00
Maximilian Bosch
8db24dec53 Merge pull request #126827 from NixOS/backport-126789-to-release-21.05
[Backport release-21.05] linuxPackages_5_4.wireguard: 1.0.20210424 -> 1.0.20210606
2021-06-14 23:04:59 +02:00
Simon Thoby
9d0a88e91f nixos/services/torrent/transmission.nix: add the web UI files to apparmor allowed paths
(cherry picked from commit f02264af82)
2021-06-14 22:22:14 +02:00
Alyssa Ross
cc7a4e5312 openssl: fix Darwin cross infinite recursion
stdenv depends on openssl, and isGNU depends on stdenv.

Thanks-to: sternenseemann <0rpkxez4ksa01gb3typccl0i@systemli.org>
Fixes: https://github.com/NixOS/nixpkgs/issues/126829
(cherry picked from commit 502de3c377)
2021-06-14 17:06:34 +00:00
Kim Lindberger
32d2d13094 Merge pull request #126824 from NixOS/backport-126812-to-release-21.05
[Backport release-21.05] gitlab: 13.12.2 -> 13.12.3
2021-06-14 15:55:34 +02:00
Pol Dellaiera
b2ecbc070f maintainers: add drupol
(cherry picked from commit 4e1dcacc30)
2021-06-14 14:38:22 +02:00
Pol Dellaiera
e4fe0a62ae symfony-cli: init at 4.25.2
(cherry picked from commit f1bbe0c2ca)
2021-06-14 14:38:14 +02:00
Maximilian Bosch
3437fe775d linuxPackages_5_4.wireguard: 1.0.20210424 -> 1.0.20210606
ChangeLog: https://lists.zx2c4.com/pipermail/wireguard/2021-June/006781.html
(cherry picked from commit 96c89ab82a)
2021-06-14 11:53:30 +00:00
Milan Pässler
852f6f8f7d gitlab: 13.12.2 -> 13.12.3
(cherry picked from commit d62aac819b)
2021-06-14 11:34:13 +00:00
sternenseemann
9a84eb7ec8 haskell.compiler.*: pull in unwrapped bintools for darwin
GHC calls otool on darwin which is contained in the
stdenv.cc.bintools.bintools derivation and thus needs adding to the
runtime PATH of GHC. Since this is toolchain specific technically, we
check for cctools instead of darwin (although I don't know if GHC
or nixpkgs work on macOS without cctools).

This fixes usage of GHC in an environment where otool is not available
and more specifically in stdenvNoCC which is used by writers.writeHaskell.
Resolves #123228.

(cherry picked from commit 118b28a127)
2021-06-14 12:21:22 +02:00
Vladimír Čunát
3988964387 sqlite tools: fix download hash after update
Clearly a copy&paste error in commit 14a274763e.  Now it builds.

(cherry picked from commit 34c88a4d5c)
2021-06-14 08:30:53 +02:00
Artturin
641efce99b nvidia-optical-flow-sdk: 1.0 -> 2.0
(cherry picked from commit 04e8ab8fdf8c8009741a8ebb26e4cd8e2cb6bd61)
2021-06-13 23:04:23 -07:00
Artturin
13d6008df1 opencv: update cuda_opt_flow.patch
(cherry picked from commit e3ec283df10cbe5e87c240d28afd81c72f8226b2)
2021-06-13 23:04:23 -07:00
Vincent Laporte
162c4e4e16 ocamlPackages.ppx_import: disable checks
(cherry picked from commit ecf820740a0b576361dac53778a4e6e2e6338287)
2021-06-14 03:52:03 +02:00
Maximilian Bosch
93963c27b9 Merge pull request #126502 from NixOS/backport-126468-to-release-21.05
[Backport release-21.05] tmux: 3.2 -> 3.2a
2021-06-13 22:45:38 +02:00
Robert Schütz
bc3694b59c imagemagick: 7.0.11-14 -> 7.1.0-0
(cherry picked from commit 50967b77c0051ee7a5ca8d974d3cc43bf5069a5a)
2021-06-13 22:01:06 +02:00
Robert Schütz
f822238b76 imagemagick6: 6.9.12-14 -> 6.9.12-15
(cherry picked from commit 929ddc6fa567c99bfaeada7927f6e52ef4de5025)
2021-06-13 21:16:16 +02:00
Vladimír Čunát
c15b784d29 Merge branch 'staging-next-21.05' into release-21.05
PR #126251.  I think it's high time.  Hydra's eval
https://hydra.nixos.org/eval/1677846
isn't perfect yet, but there doesn't seem to be anything really risky.
2021-06-13 21:12:02 +02:00
Kerstin Humm
757e57a0a2 imagemagick: 7.0.11-13 -> 7.0.11-14
(cherry picked from commit 31a8c0e5c4)
2021-06-13 21:05:51 +02:00
Michael Livshin
37d81fb867 clang-tools: fix clangd
Whatever change has necessitated
https://github.com/NixOS/nixpkgs/pull/122044, it also broke clangd --
<clang-wrapper>/resource-root/include is no longer automagically
searched for includes, which kills pretty much any indexing since that
directory contains vital stuff like stddef.h etc.

Fix by appending the directory to CPATH & CPLUS_INCLUDE_PATH in the
clangd wrapper.

(cherry picked from commit 8e06a39574)
2021-06-13 17:57:42 +03:00
Michael Weiss
e7c31a0eae Merge pull request #126740 from NixOS/backport-126662-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 91.0.4472.77 -> 91.0.4472.101
2021-06-13 13:52:50 +02:00
Elis Hirwing
7821201018 php.extensions.swoole: 4.6.4 -> 4.6.7
(cherry picked from commit 2fc9594844)
2021-06-13 12:24:35 +02:00
Elis Hirwing
2d08d4cfd0 php.extensions.maxminddb: 1.10.0 -> 1.10.1
(cherry picked from commit 9e12aefc41)
2021-06-13 12:23:35 +02:00
Elis Hirwing
519f5b1887 php.extensions.event: 3.0.2 -> 3.0.4
(cherry picked from commit b169c6d5e8)
2021-06-13 12:23:20 +02:00
Elis Hirwing
0c09dcb45f php.extensions.ast: 1.0.10 -> 1.0.12
(cherry picked from commit c082df8e62)
2021-06-13 12:23:04 +02:00
Elis Hirwing
43a783ebdf php.extensions.igbinary: 3.2.1 -> 3.2.2
(cherry picked from commit 8307e75f80)
2021-06-13 12:22:41 +02:00
Elis Hirwing
417ee18054 php.extensions.mongodb: 1.9.0 -> 1.9.1
(cherry picked from commit 06ea32f7bf)
2021-06-13 12:22:08 +02:00
Elis Hirwing
d1646f426f php.extensions.pcov: 1.0.8 -> 1.0.9
(cherry picked from commit 8a5d4b6328)
2021-06-13 12:21:33 +02:00
Elis Hirwing
64867ce1b9 php.extensions.protobuf: 3.14.0 -> 3.17.2
(cherry picked from commit c79d977ca1)
2021-06-13 12:20:18 +02:00
Elis Hirwing
460f69e000 php.extensions.redis: 5.3.3 -> 5.3.4
(cherry picked from commit 867a4d38d7)
2021-06-13 12:18:12 +02:00
Michael Weiss
39762d2342 ungoogled-chromium: 91.0.4472.77 -> 91.0.4472.101
(cherry picked from commit 3952d19175)
2021-06-13 09:59:36 +00:00
Jörg Thalheim
21a1ba4fce dpdk-kmods: init at 2021-04-21
In the last release dpdk moved the uio_igb driver to a different package
Without it dpdk is not very useful.

(cherry picked from commit 0d2276ec34)
2021-06-13 09:40:56 +00:00
Elis Hirwing
9bb5ef1389 php.extensions.xdebug: 3.0.3 -> 3.0.4
(cherry picked from commit a4e774d3b0)
2021-06-13 11:33:18 +02:00
Martin Weinelt
1f91fd1040 Merge pull request #126736 from Lassulus/weechat-matrix
[21.05] weechatScripts.weechat-matrix: fix matrix_sso_helper path
2021-06-13 11:32:41 +02:00
Robert Gerus
ac93a00745 weechatScripts.weechat-matrix: fix matrix_sso_helper path
server.py tries to launch a matrix_sso_helper binary when connecting to
a homeserver that uses some SSO mechanism instead of plain login and
password, but doesn't have $out/bin in $PATH.

Using substituteInPlace to patch server.py so that the helper process is
started by using its actual filesystem location instead of relying on
$PATH.

Fixes: https://github.com/NixOS/nixpkgs/issues/124186
(cherry picked from commit f7ccc5f35d)
2021-06-13 11:29:58 +02:00
Matthieu Coudron
889a9b7c11 pythonPackages: set mainProgram to pname by default
Calling `nix run poetry` or another python package usually fails
because of the "pythonX" prefix in name.
Adjust mainProgram to ignore that prefix.

(cherry picked from commit b59875ef23dabddceda3673a7559ebbede9ab6aa)
2021-06-13 10:36:12 +02:00
Luke Granger-Brown
b3872ff69c Merge pull request #126716 from risicle/ris-envoy-1.16.4-r21.05
[21.05] envoy: 1.16.2 -> 1.16.4, addressing CVE-2021-29258
2021-06-13 00:41:34 +01:00
Robert Scott
dd24b1bc0a envoy: 1.16.2 -> 1.16.4
resolving CVE-2021-29258
2021-06-12 22:59:29 +01:00
Sandro
81b3481d79 Merge pull request #126528 from NixOS/backport-126303-to-release-21.05
[Backport release-21.05] deno: 1.10.3 -> 1.11.0
2021-06-12 18:26:11 +02:00
Vladimír Čunát
1ba7a494bf Merge #126619: knot-resolver: skip tests on aarch64-darwin
(cherry picked from commit 9affc60b0c)
It looks good on nixpkgs master (and other platforms don't even rebuild):
https://hydra.nixos.org/build/145261694
2021-06-12 16:51:53 +02:00
Guillaume Girol
c5811ce005 tt-rss-plugin-tumblr-gdpr: 2.1 -> 2.2
fixes adding a new feed to ttrss.
the release only contains the fix, so it's low risk.
It's not a backport because the plugin has become unnecessary so we are
simply removing it from unstable.
2021-06-12 12:00:00 +00:00
Vladimír Čunát
6d286be97a Merge branch 'release-21.05' into staging-next-21.05
This brings not that many rebuilds but still some.
2021-06-12 07:21:42 +02:00
Timothy Klim
20fb587164 sbt: 1.5.1 -> 1.5.3
(cherry picked from commit 7c74293590f5ff12920d9a46da84983b6c156e04)
2021-06-11 19:04:11 -04:00
Robert Scott
b76c86678d bosh-cli: init at 6.4.3
(cherry picked from commit 8f3bf74e1c)
2021-06-11 22:45:52 +00:00
Bjørn Forsman
c3094b06ce qcachegrind: license gpl2 -> gpl2Plus
According to https://apps.kde.org/kcachegrind/.

(cherry picked from commit 1b1f196fe6)
2021-06-11 23:09:20 +02:00
Bjørn Forsman
bfff2cbbcd qcachegrind: fix fatal Could not find the Qt platform plugin "xcb" in ""
(cherry picked from commit 16cbc80a93)
2021-06-11 23:09:20 +02:00
Bjørn Forsman
0d417a343c nixos/jenkins: test declarative jobs
(cherry picked from commit a655b71201)
2021-06-11 23:08:41 +02:00
Bjørn Forsman
a0fc6a7861 nixos/jenkins-job-builder: add support for folder jobs
Add support for folder jobs
(https://plugins.jenkins.io/cloudbees-folder/) by reworking the service
to support nested jobs.

This also fixes this deprecation warning (as a happy side effect):

  WARNING:jenkins_jobs.cli.subcommand.test:(Deprecated) The default output behavior of `jenkins-jobs test` when given the --output flag will change in JJB 3.0. Instead of writing jobs to OUTPUT/jobname; they will be written to OUTPUT/jobname/config.xml. The new behavior can be enabled by the passing `--config-xml` parameter

(cherry picked from commit 4bcb22e17a)
2021-06-11 23:08:41 +02:00
Dmitry Kalinkin
af3e82ab87 llvmPackages_12.compiler-rt: fix build on darwin
```
/tmp/nix-build-compiler-rt-libc-12.0.0.drv-0/compiler-rt-12.0.0.src/lib/sanitizer_common/sanitizer_mac.cpp:617:7: error: use of undeclared
      identifier 'TARGET_OS_IOS'
  if (TARGET_OS_IOS || TARGET_OS_TV) return 6;
      ^
/tmp/nix-build-compiler-rt-libc-12.0.0.drv-0/compiler-rt-12.0.0.src/lib/sanitizer_common/sanitizer_mac.cpp:617:24: error: use of undeclared
      identifier 'TARGET_OS_TV'
  if (TARGET_OS_IOS || TARGET_OS_TV) return 6;
                       ^
/tmp/nix-build-compiler-rt-libc-12.0.0.drv-0/compiler-rt-12.0.0.src/lib/sanitizer_common/sanitizer_mac.cpp:618:7: error: use of undeclared
      identifier 'TARGET_OS_WATCH'
  if (TARGET_OS_WATCH) return 13;
      ^
/tmp/nix-build-compiler-rt-libc-12.0.0.drv-0/compiler-rt-12.0.0.src/lib/sanitizer_common/sanitizer_mac.cpp:687:7: error: use of undeclared
      identifier 'TARGET_OS_IOS'
  if (TARGET_OS_IOS || TARGET_OS_TV)
      ^
/tmp/nix-build-compiler-rt-libc-12.0.0.drv-0/compiler-rt-12.0.0.src/lib/sanitizer_common/sanitizer_mac.cpp:687:24: error: use of undeclared
      identifier 'TARGET_OS_TV'
  if (TARGET_OS_IOS || TARGET_OS_TV)
                       ^
/tmp/nix-build-compiler-rt-libc-12.0.0.drv-0/compiler-rt-12.0.0.src/lib/sanitizer_common/sanitizer_mac.cpp:689:12: error: use of undeclared
      identifier 'TARGET_OS_WATCH'
  else if (TARGET_OS_WATCH)
           ^
6 errors generated.
```

(cherry picked from commit cf4e1b9e62)
2021-06-11 16:45:59 +00:00
Kerstin Humm
30457b3fbd imagemagick: 6.9.12-12 -> 6.9.12-14
(cherry picked from commit 99f12af681)
2021-06-11 17:23:13 +02:00
Jan Solanti
c2628780fc pipewire: 0.3.27 -> 0.3.30
(cherry picked from commit c702cc4321)
2021-06-11 14:52:30 +00:00
Maximilian Bosch
39c1857cd5 Merge pull request #126589 from NixOS/backport-126540-to-release-21.05
[Backport release-21.05] Kernels 2021-06-10
2021-06-11 16:48:23 +02:00
TredwellGit
d7dce44057 glibc: 2.32-46 -> 2.32-48
https://sourceware.org/bugzilla/show_bug.cgi?id=27896
https://nvd.nist.gov/vuln/detail/CVE-2021-33574
(cherry picked from commit e58564267b)
2021-06-11 12:42:27 +00:00
TredwellGit
01f05483e3 linux/hardened/patches/5.4: 5.4.124-hardened1 -> 5.4.125-hardened1
(cherry picked from commit c22128ed44)
2021-06-11 11:55:05 +00:00
TredwellGit
a4b3179732 linux/hardened/patches/5.12: 5.12.9-hardened1 -> 5.12.10-hardened1
(cherry picked from commit 889319446c)
2021-06-11 11:55:05 +00:00
TredwellGit
6d28511e7f linux/hardened/patches/5.10: 5.10.42-hardened1 -> 5.10.43-hardened1
(cherry picked from commit 0879f36d2b)
2021-06-11 11:55:05 +00:00
TredwellGit
e08fc97b07 linux/hardened/patches/4.19: 4.19.193-hardened1 -> 4.19.194-hardened1
(cherry picked from commit 940bf55cab)
2021-06-11 11:55:04 +00:00
TredwellGit
2eff1ca451 linux/hardened/patches/4.14: 4.14.235-hardened1 -> 4.14.236-hardened1
(cherry picked from commit e77f16cbcb)
2021-06-11 11:55:04 +00:00
TredwellGit
0bfc50ac94 linux: 5.4.124 -> 5.4.125
(cherry picked from commit 7cf65d0f4a)
2021-06-11 11:55:04 +00:00
TredwellGit
e7a8f48d6b linux: 5.12.9 -> 5.12.10
(cherry picked from commit fd44ed986c)
2021-06-11 11:55:04 +00:00
TredwellGit
a5bfe124f9 linux: 5.10.42 -> 5.10.43
(cherry picked from commit 121dbb9653)
2021-06-11 11:55:04 +00:00
TredwellGit
134c38917e linux: 4.9.271 -> 4.9.272
(cherry picked from commit 2961093d9b)
2021-06-11 11:55:03 +00:00
TredwellGit
52f177d27c linux: 4.4.271 -> 4.4.272
(cherry picked from commit a31fb79270)
2021-06-11 11:55:03 +00:00
TredwellGit
2cfe71a243 linux: 4.19.193 -> 4.19.194
(cherry picked from commit 89a533e7df)
2021-06-11 11:55:03 +00:00
TredwellGit
40c83d56e0 linux: 4.14.235 -> 4.14.236
(cherry picked from commit a6d113ad1b)
2021-06-11 11:55:03 +00:00
Zane van Iperen
a45b498a3a vgmstream: init at r1050-3738-g7cfa1f29 (#125492)
(cherry picked from commit 19ff8bd943)

Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
2021-06-11 21:04:27 +10:00
Louis Bettens
de24120898 oraclejdk*: use latest ffmpeg
(cherry picked from commit 50cb5bc35c)
2021-06-11 10:10:58 +00:00
Maciej Krüger
0f4f2317c1 Merge pull request #126576 from mkg20001/x2go-backport 2021-06-11 09:50:42 +00:00
Maciej Krüger
6d9d295e38 [Backport release-21.05] x2goclient: unstable-2019-07-24 -> 4.1.2.2, fix #78907
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit c4100d81bd)
2021-06-11 11:35:20 +02:00
Jörg Thalheim
3fdff5f4b0 Merge pull request #126548 from NixOS/backport-126513-to-release-21.05
[Backport release-21.05] nixos-rebuild: Pass flakes flags when doing local flakes build
2021-06-11 09:04:28 +02:00
Anderson Torres
6d301bb54e Merge pull request #126460 from NixOS/backport-126341-to-release-21.05
[Backport release-21.05] palemoon: 29.2.0 -> 29.2.1
2021-06-11 01:18:28 -03:00
Alyssa Ross
8d292bd4f7 apacheHttpd: 2.4.47 -> 2.4.48
(cherry picked from commit 8da3370dbd62379bbc14fc57ba04a10f7456690f)
2021-06-11 00:22:01 +00:00
Chuck
c764b9f946 nixos-rebuild: Pass flakes flags when doing local flakes build
(cherry picked from commit 1c80856545)
2021-06-10 22:31:01 +00:00
R. RyanTM
e7928186d9 deno: 1.10.3 -> 1.11.0
(cherry picked from commit c374fd03ff)
2021-06-10 19:25:30 +00:00
Michael Weiss
2311321709 Merge pull request #126506 from primeos/chromium-backport
[21.05] chromium: 91.0.4472.77 -> 91.0.4472.101
2021-06-10 20:59:02 +02:00
Michal Sojka
3eb0a0f921 firefox: Make CUPS printers visible in the print dialog
Firefox 81 introduced a new print dialog. Under NixOS, this dialog
offers only "Save as PDF" as the destination. To print to a real
printer, one has to click "Print using the system dialog" and print
from there. This is not only one unnecessary extra click, but the
system dialog also does not offer preview.

With this commit, Firefox starts offering real printers in its
printing dialog, removing the above mentioned deficiencies.

CUPS is needed because Firefox uses dlopen() to load libcups.so.2 at
runtime. See
https://searchfox.org/mozilla-central/rev/b52cf6bbe214bd9d93ed9333d0403f7d556ad7c8/widget/nsCUPSShim.cpp#28

(cherry picked from commit 5102a12471)
2021-06-10 17:47:30 +00:00
Maximilian Bosch
2c15e457a1 Merge pull request #126503 from NixOS/backport-126330-to-release-21.05
[Backport release-21.05] vorta: 0.7.5 -> 0.7.6
2021-06-10 19:32:19 +02:00
Michael Weiss
0312d6fcf7 chromiumDev: Install crashpad_handler
This executable is required to fix a startup error:
[990:990:0609/092114.482805:FATAL:double_fork_and_exec.cc(131)] execv /nix/store/k02xhxzn6sn2cihaal68wwsyk8cg9pkg-chromium-unwrapped-93.0.4535.3/libexec/chromium/crashpad_handler: No such file or directory (2)

Unfortunately Chromium M93 still segfaults in the VM test:
machine # [0610/100626.225850:ERROR:process_memory_range.cc(75)] read out of range
machine # [0610/100626.227312:ERROR:file_io_posix.cc(144)] open /sys/devices/system/cpu/cpu0/cpufreq/scaling_cur_freq: No such file or directory (2)
machine # [0610/100626.240410:ERROR:file_io_posix.cc(144)] open /sys/devices/system/cpu/cpu0/cpufreq/scaling_max_freq: No such file or directory (2)
machine # [   19.810981] systemd-coredump[1015]: Process 987 (chromium) of user 1000 dumped core.

(cherry picked from commit 1d6a0d3cf2)
2021-06-10 19:25:42 +02:00
Michael Weiss
06924553df chromium: get-commit-message.py: Support a new 0-day sentence
The current stable release announcement [0] uses a slightly different
message/structure.

[0]: https://chromereleases.googleblog.com/2021/06/stable-channel-update-for-desktop.html

(cherry picked from commit c02ac479ba)
2021-06-10 19:25:42 +02:00
Michael Weiss
ede696c79d chromium: 91.0.4472.77 -> 91.0.4472.101
https://chromereleases.googleblog.com/2021/06/stable-channel-update-for-desktop.html

This update includes 14 security fixes. Google is aware that an exploit
for CVE-2021-30551 exists in the wild.

CVEs:
CVE-2021-30544 CVE-2021-30545 CVE-2021-30546 CVE-2021-30547
CVE-2021-30548 CVE-2021-30549 CVE-2021-30550 CVE-2021-30551
CVE-2021-30552 CVE-2021-30553

(cherry picked from commit 053f1dc490)
2021-06-10 19:25:41 +02:00
Michael Weiss
b6a71637a9 chromiumDev: Revert a patch to fix the build with LLVM 12
The build was failing with:
clang++: error: unknown argument: '-fsanitize-ignorelist=../../tools/cfi/ignores.txt'

(cherry picked from commit 950b321244)
2021-06-10 19:25:41 +02:00
Michael Weiss
146ff19f4f chromiumDev: 93.0.4530.5 -> 93.0.4535.3
(cherry picked from commit 5915f689b4)
2021-06-10 19:25:40 +02:00
Michael Weiss
c15df2350d chromiumDev: 92.0.4515.40 -> 93.0.4530.5
(cherry picked from commit 2c9e2b6875)
2021-06-10 19:25:40 +02:00
Michael Weiss
b60b15b410 chromiumBeta: 91.0.4472.77 -> 92.0.4515.40
(cherry picked from commit c6890330f5)
2021-06-10 19:25:39 +02:00
Michael Weiss
c92cc2463d chromiumDev: 92.0.4515.20 -> 92.0.4515.40
(cherry picked from commit cf6496e72b)
2021-06-10 19:25:39 +02:00
Michael Weiss
ddde2dd1d2 chromiumDev: 92.0.4512.4 -> 92.0.4515.20
(cherry picked from commit 136addaa6e)
2021-06-10 19:25:38 +02:00
Michael Weiss
180983e6ef chromiumBeta: 91.0.4472.69 -> 91.0.4472.77
(cherry picked from commit b6f54db787)
2021-06-10 19:25:38 +02:00
Maximilian Bosch
8b1de204e5 vorta: 0.7.5 -> 0.7.6
ChangeLog: https://github.com/borgbase/vorta/releases/tag/v0.7.6
(cherry picked from commit 7e6776d373)
2021-06-10 17:15:59 +00:00
Mario Rodas
98614ed9c6 tmux: 3.2 -> 3.2a
(cherry picked from commit a192797f61)
2021-06-10 17:14:34 +00:00
Sandro
01447140b7 Merge pull request #126480 from mayflower/backport-bemenu 2021-06-10 18:39:23 +02:00
José Romildo Malaquias
0fb12554c4 Merge pull request #126433 from vs49688/arcfix2
[21.05] arc-theme: restore metacity theme
2021-06-10 13:19:54 -03:00
Martin Weinelt
0f924f7864 Merge pull request #126087 from NixOS/backport-125669-to-release-21.05
[Backport release-21.05] firefox-bin: Avoid including both the wrapped and unwrapped versions.
2021-06-10 16:42:40 +02:00
R. RyanTM
cd90d41ea4 bemenu: 0.6.1 -> 0.6.2
(cherry picked from commit 11925bdc32)
2021-06-10 15:27:07 +02:00
R. RyanTM
02dc0c404e bemenu: 0.6.0 -> 0.6.1
(cherry picked from commit 4e8c42184f)
2021-06-10 15:26:35 +02:00
Sarah Brofeldt
d8b126507f Merge pull request #126467 from stig/backport-126335-to-release-21.05
[21.05] aws-iam-authenticator: 0.5.2 -> 0.5.3
2021-06-10 12:57:27 +02:00
Stig Brautaset
313740d907 aws-iam-authenticator: 0.5.2 -> 0.5.3
I had to work around inconsistent vendoring; see
https://github.com/kubernetes-sigs/aws-iam-authenticator/issues/377

(cherry picked from commit 38e40a73fe)
2021-06-10 11:13:20 +01:00
OPNA2608
450dd077e4 palemoon: 29.2.0 -> 29.2.1
(cherry picked from commit dc30d972bb)
2021-06-10 09:16:33 +00:00
Francesco Gazzetta
57c0c1104f shattered-pixel-dungeon: 0.9.2 -> 0.9.3
(cherry picked from commit 9306fb9f3d)
2021-06-10 09:59:49 +02:00
Elis Hirwing
cedcf2565c Merge pull request #126455 from NixOS/backport-126447-to-release-21.05
[Backport release-21.05] phpPackages.composer: 2.1.2 -> 2.1.3
2021-06-10 09:22:11 +02:00
Thomas Gerbet
ed2781ec60 phpPackages.composer: 2.1.2 -> 2.1.3
https://github.com/composer/composer/releases/tag/2.1.3
(cherry picked from commit 2db2aa2b95)
2021-06-10 07:09:00 +00:00
Andrew Childs
d5f98e8345 glibc: fix build vs host tool confusion
Fixes cross compilation from aarch64-linux -> armv7l-linux

(cherry picked from commit e57b58bd0e)
2021-06-10 05:29:18 +00:00
Zane van Iperen
93b972e2bb arc-theme: restore metacity theme
Fixes theme usage on MATE.

(cherry picked from commit 6aa70348df)
2021-06-10 11:30:28 +10:00
Robert Scott
a1446cc63d python3Packages.websockets: add patch for CVE-2021-33880
this is a reintroduction of CVE-2018-1000518 which i had been calling
CVE-2018-1000518-redux before it got its own CVE assigned

(cherry picked from commit aba83e7f87)

(yes, a forward cherry-pick because i fully expected the websockets
9.1 to make it into 21.05)
2021-06-09 19:57:36 +01:00
Michael Weiss
86d8a48762 Merge pull request #126365 from NixOS/backport-126343-to-release-21.05
[Backport release-21.05] signal-desktop: 5.4.0 -> 5.4.1
2021-06-09 16:17:42 +02:00
piegames
19a1348fbb matrix-appservice-irc: 0.26.0 -> 0.26.1
(cherry picked from commit 6a18a9a2c5)
2021-06-09 13:59:33 +00:00
Sandro
0f94f37283 Merge pull request #126349 from NixOS/backport-126134-to-release-21.05
[Backport release-21.05] opentabletdriver: 0.5.3.1 -> 0.5.3.2
2021-06-09 15:32:48 +02:00
Michael Weiss
d69ca2fb50 signal-desktop: 5.4.0 -> 5.4.1
(cherry picked from commit 6a11eafbc9)
2021-06-09 13:25:41 +00:00
Maximilian Bosch
1ccfdad225 Merge pull request #126239 from NixOS/backport-125469-to-release-21.05
[Backport release-21.05] Kernels 2021-06-03
2021-06-09 15:14:32 +02:00
Martin Weinelt
69d5c98833 Merge pull request #126358 from NixOS/backport-126271-to-release-21.05 2021-06-09 15:06:23 +02:00
Martin Weinelt
e9434d6728 nixos/tests/custom-ca: disable firefox test integration
Firefox has been decoupled from the system certificate store since the
nss p11-kit integration in combination with our cacert package does not
expose CKA_NSS_MOZILLA_CA_POLICY, which among other things is required
for addon updates.

(cherry picked from commit 2d4ed9bae6)
2021-06-09 12:55:23 +00:00
Martin Weinelt
0647103d18 firefox: use nss without p11-kit
Quickfix to allow firefox to recognize certificates as trusted by
Mozilla.

Related: #126065
(cherry picked from commit 42e25d855f)
2021-06-09 12:55:23 +00:00
Thiago Kenji Okada
8d0c4b749d opentabletdriver: 0.5.3.1 -> 0.5.3.2
(cherry picked from commit 4211a977d4)
2021-06-09 11:19:34 +00:00
Maximilian Bosch
3993e891e4 nixos/tests/kernel-generic: fix evaluation
The test doesn't evaluate since #125469 because Linux 5.11 got removed
as it's EOL.

As this fixes the evaluation of the test and it only removes a
declaration that was apparently forgotten, I figured that a push to
unbreak the test is fine.

(cherry picked from commit 10eab5b6b3)
2021-06-09 13:03:14 +02:00
oxalica
eed26e1d22 fcitx5: fix update script
(cherry picked from commit fbedf830ea)
2021-06-09 08:25:50 +00:00
oxalica
2b8629de9a fcitx5-chinese-addons: 5.0.3 -> 5.0.6
(cherry picked from commit 1be9422725)
2021-06-09 08:25:50 +00:00
oxalica
7b7362b5f5 xcb-imdkit: 1.0.2 -> 1.0.3
This fixes an input issue with alacritty/xterm, see https://github.com/fcitx/fcitx5/issues/254

(cherry picked from commit 46ac936b00)
2021-06-09 08:25:50 +00:00
oxalica
6207e92757 libime: 1.0.3 -> 1.0.7
(cherry picked from commit b951fc0e94)
2021-06-09 08:25:50 +00:00
zimbatm
e7768c7dfa wasm-bindgen-cli: 0.2.73 -> 0.2.74
(cherry picked from commit ca27566a8a)
2021-06-09 06:42:39 +00:00
Daniel Nagy
60cce7e5e1 blender: add libharu as dependency
This allows to export Grease Pencil drawings as pdfs. For more
information, see:

https://wiki.blender.org/wiki/Reference/Release_Notes/2.93/Grease_Pencil

https://developer.blender.org/rBa8a92cd15a52
(cherry picked from commit d847851a37)
2021-06-09 01:18:50 -04:00
Natan Lao
b3ec6fd959 nixos/nvidia: fix hardware.nvidia.package example
(cherry picked from commit 86a31cc9719ed409d523d4f738aa2a994d79ff9e)
2021-06-08 20:59:02 -07:00
Robert Scott
eabf99b8d8 python3Packages.datasette: add patch for CVE-2021-32670
enable included test
2021-06-09 00:04:28 +01:00
Jonathan Ringer
8e20586f52 Merge branch 'staging-next-21.05' into staging-21.05 2021-06-08 12:21:49 -07:00
Yurii Matsiuk
48b5af66d9 linux: remove 5.11
(cherry picked from commit 73f7db3ecd9f2ca744ed82d7bfc954601c591350)
2021-06-08 18:26:34 +00:00
Yurii Matsiuk
a01a648543 linux/hardened/patches/5.4: 5.4.122-hardened1 -> 5.4.124-hardened1
(cherry picked from commit 598dadab6ee7552d429db1e25a8379b4d5a518c5)
2021-06-08 18:26:34 +00:00
Yurii Matsiuk
fd3156d46f linux/hardened/patches/5.12: 5.12.7-hardened1 -> 5.12.9-hardened1
(cherry picked from commit 405b66f9773fee406e1d05843e5b52d26daa4c59)
2021-06-08 18:26:34 +00:00
Yurii Matsiuk
961ffc28db linux/hardened/patches/5.10: 5.10.40-hardened1 -> 5.10.42-hardened1
(cherry picked from commit 9395f64db2e9e8b7c8bd72e0aa91490428b83969)
2021-06-08 18:26:34 +00:00
Yurii Matsiuk
6bec4b45c6 linux/hardened/patches/4.19: 4.19.192-hardened1 -> 4.19.193-hardened1
(cherry picked from commit ac9d2af41f3ca372d50719225f7e029321312e46)
2021-06-08 18:26:34 +00:00
Yurii Matsiuk
7da6c0c3c9 linux/hardened/patches/4.14: 4.14.234-hardened1 -> 4.14.235-hardened1
(cherry picked from commit adb9d3b15240bc8272cfb023beee9e035df4027b)
2021-06-08 18:26:33 +00:00
Yurii Matsiuk
8d8739976a linux_latest-libre: 18096 -> 18115
(cherry picked from commit b599c482957ff3991ee45474f02c3b617df87ece)
2021-06-08 18:26:33 +00:00
Yurii Matsiuk
4a79e6ce2b linux-rt_5_4: 5.4.115-rt57 -> 5.4.123-rt59
(cherry picked from commit 759559f3d3f57aeb76a38d8d47e481fe68767d81)
2021-06-08 18:26:33 +00:00
Yurii Matsiuk
6a671c3d4a linux-rt_5_10: 5.10.35-rt39 -> 5.10.41-rt42
(cherry picked from commit b42424bdd0946c167becd3ffa2d169d5e08877ed)
2021-06-08 18:26:33 +00:00
Yurii Matsiuk
6a0f53fd68 linux: 5.4.123 -> 5.4.124
(cherry picked from commit 32d11bc730a489d79825dc6e6c3d0de1f310ebdd)
2021-06-08 18:26:33 +00:00
Yurii Matsiuk
7a527b80a4 linux: 5.12.8 -> 5.12.9
(cherry picked from commit 638dd47cd4adf14e8bdf7045acee10c1642528e9)
2021-06-08 18:26:33 +00:00
Yurii Matsiuk
48c065427c linux: 5.10.41 -> 5.10.42
(cherry picked from commit 3d8eaa87efac4063cd1474e0f17078d0f16b2863)
2021-06-08 18:26:32 +00:00
Yurii Matsiuk
b21519e899 linux: 4.9.270 -> 4.9.271
(cherry picked from commit 3739547f71399e6b689682f64376ea47055563e4)
2021-06-08 18:26:32 +00:00
Yurii Matsiuk
11c473038b linux: 4.4.270 -> 4.4.271
(cherry picked from commit eab8c884b84d6e89177430306a2ce8e2319a148d)
2021-06-08 18:26:32 +00:00
Yurii Matsiuk
e9d5f300eb linux: 4.19.192 -> 4.19.193
(cherry picked from commit df489760a1f346e71e6d61c93f80da029128d292)
2021-06-08 18:26:32 +00:00
Yurii Matsiuk
11bdcb66bd linux: 4.14.234 -> 4.14.235
(cherry picked from commit 14c5ae2a443f4296fd37bc556b7cf7aba2ac8033)
2021-06-08 18:26:32 +00:00
Yurii Matsiuk
e28f728bdf linux: 5.4.122 -> 5.4.123
(cherry picked from commit fd37913b5699c23ef59dd0bb3a38ab92d8ed82de)
2021-06-08 18:26:31 +00:00
Yurii Matsiuk
68f2116f10 linux: 5.12.7 -> 5.12.8
(cherry picked from commit 85b9e08436dd3cb37707fffd93b0d2dea30b99d1)
2021-06-08 18:26:31 +00:00
Yurii Matsiuk
1e9c68521c linux: 5.10.40 -> 5.10.41
(cherry picked from commit 78aaa23acecfbfd977d22bf3a7050c9a27c815fa)
2021-06-08 18:26:31 +00:00
Peter Simons
89093fdbc0 minecraft-server: 1.16.5 -> 1.17
(cherry picked from commit 65a8bff54c03f748cb9442108701156eb90179b3)
2021-06-08 18:21:12 +00:00
Jonathan Ringer
a76d51dc52 steam/fhsenv: add pipewire as hard requirement
(cherry picked from commit 1817df0beb89a26050c5e1a7f9a12e4256cab427)
2021-06-08 10:12:58 -07:00
rnhmjoj
f2c9d568c8 nixos/wireless: only warn for no interfaces
A hard failure breaks the NixOS installer, which can't possibly
know the interface names in advance.

(cherry picked from commit be01320a6c)
2021-06-08 08:52:41 -07:00
rnhmjoj
df9df54d63 Revert "nixos/wireless: make wireless.interfaces mandatory"
This reverts commit 030a521adc.

(cherry picked from commit eba5f5c1e5)
2021-06-08 08:52:41 -07:00
Sandro
e041608a92 Merge pull request #126031 from NixOS/backport-125902-to-release-21.05
[Backport release-21.05] linuxPackages_4_4.v4l2loopback: fix build for 4.4 kernels
2021-06-08 17:30:45 +02:00
José Romildo
f2046813e2 numix-solarized-gtk-theme: 20200910 -> 20210522
(cherry picked from commit 9b743d9bbb)
2021-06-08 08:27:31 -07:00
Sandro
3d04c4066f Merge pull request #125899 from NixOS/backport-125717-to-release-21.05 2021-06-08 17:08:54 +02:00
Alvar Penning
3ee4422849 rPackages.lwgeom: fix build
(cherry picked from commit 8bf4f7e2f3)
2021-06-08 07:56:39 -07:00
R. RyanTM
52147880d7 marvin: 21.3.0 -> 21.9.0
(cherry picked from commit cb70ce62ab)
2021-06-08 07:54:23 -07:00
fortuneteller2k
ba61fdde58 openafs_1_9, linuxPackages.openafs_1_9: 1.9.0 -> 1.9.1
(cherry picked from commit 5f394e5ef5)
2021-06-08 14:31:03 +00:00
Janne Heß
c525d5cf31 389-base: Add CVE-2021-3514
(cherry picked from commit fb7a3e1086debb3c47f0881724caccaa1a82642c)
2021-06-08 11:59:05 +00:00
Kim Lindberger
541e7d51c5 Merge pull request #126194 from NixOS/backport-126163-to-release-21.05
[Backport release-21.05] phpPackages.composer: 2.1.1 -> 2.1.2
2021-06-08 13:52:27 +02:00
Thomas Gerbet
42a8930480 phpPackages.composer: 2.1.1 -> 2.1.2
https://github.com/composer/composer/releases/tag/2.1.2
(cherry picked from commit b30d8c49e8)
2021-06-08 11:49:12 +00:00
Jörg Thalheim
633ab195e9 Merge pull request #126176 from NixOS/backport-126137-to-release-21.05
[Backport release-21.05] nix-direnv: make flakes support optional and off by default
2021-06-08 10:20:51 +02:00
Luke Worth
60f31b6692 nix-direnv: make flakes support optional
`nix-direnv` depends on `nixUnstable` for flakes support, but that
causes it to print a warning unless your user is trusted or the
`experimental-features` setting is enabled. Neither of these are
desirable (note that setting `experimental-features` in nix.conf causes
warnings on `nixStable`).

Since flakes are experimental, this commit makes `nixStable` the default
and optionally allows `nixUnstable` with a new flag `enableFlakes`,
prioritising a good experience for users not using experimental
features.

(cherry picked from commit 03310df843)
2021-06-08 07:58:48 +00:00
Rick van Schijndel
20d9ca119b libgudev: support cross-compilation by disabling introspection and vala
(cherry picked from commit 05aa68850c)
2021-06-08 08:54:18 +02:00
davidak
0507e901b3 Merge pull request #126144 from NixOS/backport-126138-to-release-21.05
[Backport release-21.05] steamPackages.steam-runtime: 0.20210317.0 -> 0.20210527.0
2021-06-08 05:14:45 +02:00
Artturin
a29ce4a574 steamPackages.steam-runtime: 0.20210317.0 -> 0.20210527.0
(cherry picked from commit 2033f37fb2)
2021-06-08 02:19:15 +00:00
Sage Raflik
01c2ac927a dwm: added neonfuz as maintainer
(cherry picked from commit d4bfc63516385d29f6b300caa945228beeed7244)
2021-06-08 01:17:18 +00:00
Sage Raflik
0b1af950c1 dwm: restored config patch interface
(cherry picked from commit 6e9a1ab020cfdfb3cce4a88a8da118729e319645)
2021-06-08 01:17:18 +00:00
Jan Tojnar
403fb2db47 nixos/gnome: fix option label
It is no longer GNOME 3.

(cherry picked from commit 99fcca7b6b)
2021-06-07 17:34:08 -07:00
Martin Weinelt
ba13b8263f Merge pull request #126120 from NixOS/backport-126115-to-release-21.05
[Backport release-21.05] dino: 0.2.0 -> 0.2.1
2021-06-07 23:55:18 +02:00
Maximilian Bosch
766a6da74d Merge pull request #126123 from NixOS/backport-126102-to-release-21.05
[Backport release-21.05] element: 1.7.29 -> 1.7.30
2021-06-07 23:25:15 +02:00
Michael Weiss
2644ec4c7b Merge pull request #126117 from NixOS/backport-126073-to-release-21.05
[Backport release-21.05] isync: 1.4.1 -> 1.4.2
2021-06-07 23:07:59 +02:00
TredwellGit
f1880322f3 element: 1.7.29 -> 1.7.30
https://github.com/vector-im/element-web/blob/v1.7.30/CHANGELOG.md
https://github.com/vector-im/element-desktop/blob/v1.7.30/CHANGELOG.md
(cherry picked from commit 445e3ce0e8)
2021-06-07 20:46:43 +00:00
Félix Baylac-Jacqué
a5ea989814 dino: 0.2.0 -> 0.2.1
Fixes https://nvd.nist.gov/vuln/detail/CVE-2021-33896.

The current 9acb54df9254609f2fe4de83c9047d408412de28 patch landed in
dino as 4592b72dfa324d8a4b9f8c25b359110889b2206c. Removing it from the
patch list.

(cherry picked from commit 70173c1519)
2021-06-07 20:17:09 +00:00
Dominique Martinet
7f537766b3 isync: 1.4.1 -> 1.4.2
Fixes CVE-2021-3578: possible remote code execution

https://sourceforge.net/p/isync/mailman/message/37297759/
(cherry picked from commit 254a89e7d5)
2021-06-07 20:06:18 +00:00
Vladimír Čunát
75029d2f14 Merge #125624: thunderbird*: 78.10.2 -> 78.11.0 2021-06-07 20:14:16 +02:00
Nicolas B. Pierron
440f0ac466 firefox-bin: Avoid including both the wrapped and unwrapped version when using nix run command.
In order to make the man pages accessible, the previous code used
nix-support/propagated-user-env-packages. However this file is also used to set
the PATH when the application is executed with `nix run`, thus including the
wrapped and the wrappee in the environment.

Having the wrappee enumerated first in the environment caused `firefox` to
default to the wrappee, and as such not being able to find a proper GTK. This
was a source of failures while opening a file-picker.

This change removes the code to propagate the wrappe in the environment, as the
man pages are already linked in the wrapper output.

(cherry picked from commit efef092ba5)
2021-06-07 16:08:19 +00:00
Luke Granger-Brown
60f3e3675b Merge pull request #126030 from NixOS/backport-125922-to-release-21.05
[Backport release-21.05] tor-browser-bundle-bin: 10.0.16 -> 10.0.17
2021-06-07 09:53:55 +01:00
fortuneteller2k
fe6ece008b linuxPackages_4_4.v4l2loopback: fix build for 4.4 kernels
(cherry picked from commit 943d26cf3b)
2021-06-07 00:48:26 +00:00
FliegendeWurst
debf52168f tor-browser-bundle-bin: 10.0.16 -> 10.0.17
(cherry picked from commit 0fc1a3d0d8)
2021-06-07 00:46:59 +00:00
FliegendeWurst
92353fcd62 tor-browser-bundle: delete unused extensions.nix
(cherry picked from commit 1b73aa2aea)
2021-06-07 00:45:13 +00:00
AmineChikhaoui
77e8ea81e3 ec2-amis: add release 21.05
(cherry picked from commit b7d74194b49c3b3f85d52e85054283211bce6c11)
2021-06-06 17:09:30 -07:00
R. RyanTM
d6c7d92ae0 gnome.eog: 40.1 -> 40.2
(cherry picked from commit 381dcecd65)
2021-06-06 20:54:03 +00:00
Luke Granger-Brown
dbf7af9afc Merge pull request #125996 from NixOS/backport-125632-to-staging-21.05
[Backport staging-21.05] python3Packages.certifi: 2020.12.5 -> 2021.05.30
2021-06-06 20:50:31 +01:00
Fabian Affolter
d607e3143f python3Packages.certifi: enable tests
(cherry picked from commit 19f90b99e7)
2021-06-06 19:23:11 +00:00
Fabian Affolter
4af78d9ddb python3Packages.certifi: 2020.12.5 -> 2021.05.30
(cherry picked from commit 32e061be52)
2021-06-06 19:23:11 +00:00
Ulrik Strid
5e61b8b537 ocamlPackages.uri: 4.0.0 → 4.2.0
(cherry picked from commit b69138f54157d0532988d074f12f7c4f2721dc9a)
2021-06-06 19:01:29 +02:00
Luke Granger-Brown
337b1bc454 Merge pull request #125720 from NixOS/backport-121663-to-release-21.05
[Backport release-21.05] lightworks: 14.0.0 -> 2021.2
2021-06-06 17:42:27 +01:00
Vojtěch Káně
5da4cd9607 lightworks: fix audio playback
(cherry picked from commit 201cc75bcb)
2021-06-06 16:17:46 +00:00
pacien
1b06bcfeea matrix-appservice-discord: increase test timeout
Hydra and my local machine are sometimes hitting the default timeout.
See https://hydra.nixos.org/build/138032455/nixlog/8/tail

(cherry picked from commit 92f62de6f1)
2021-06-06 15:53:17 +00:00
pacien
1d3122f3fc maintainers/teams: remove pacien from the matrix team
I prefer to focus only on the individual packages which I know.

(cherry picked from commit b24cc395cc)
2021-06-06 15:53:17 +00:00
Mario Rodas
81deb02e78 Merge pull request #125933 from NixOS/backport-125100-to-release-21.05
[Backport release-21.05] treesitter: include CXX headers compiling with clang Darwin
2021-06-06 08:46:20 -05:00
fortuneteller2k
1bfe734716 silicon: 0.4.1 -> 0.4.2
(cherry picked from commit 78952c80b4)
2021-06-06 11:06:45 +00:00
Aaron Andersen
2554fcbe1b Merge pull request #125806 from NixOS/backport-125266-to-release-21.05
[Backport release-21.05] zabbix.agent2: create a symlink which is compatible with the zabbixAg…
2021-06-06 07:00:28 -04:00
Carlos Hernandez
439fb88380 tree-sitter: explicitly incl CXX headers on Darwin
clang needs to find headers + libraries for compiling with libc++.
On Darwin we will include CXX headers when compiling C.

This closes #124396

(cherry picked from commit 99b351b4bd)
2021-06-06 10:27:00 +00:00
R. RyanTM
f2484c64f3 epiphany: 40.1 -> 40.2
(cherry picked from commit 006b7037ed92edd275254eda19a8d0c2a1e2762b)
2021-06-06 09:42:25 +00:00
R. RyanTM
e2b9878556 gnome.gnome-calendar: 40.1 -> 40.2
(cherry picked from commit 356c50f0782ff9d933bbcfe753083a9b9702d4d6)
2021-06-06 09:42:06 +00:00
R. RyanTM
67f11fe4a0 evolution-data-server: 3.40.1 -> 3.40.2
(cherry picked from commit c8b5bc9cbc4acb9e8325b8c18dbf5adcb4ab6745)
2021-06-06 09:42:04 +00:00
R. RyanTM
e4a75d3654 gnome.gnome-software: 40.1 -> 40.2
(cherry picked from commit 51f510882bce75effedf6922da13952741a92003)
2021-06-06 09:41:56 +00:00
R. RyanTM
c383af78a1 gnome.gnome-boxes: 40.1 -> 40.2
(cherry picked from commit 1c9adfdc815596ae4853a8a0776b0910ce3df180)
2021-06-06 09:41:51 +00:00
Maximilian Bosch
43e16aa54f Merge pull request #125845 from NixOS/backport-125835-to-release-21.05
[Backport release-21.05] evcxr: 0.9.0 -> 0.10.0
2021-06-06 11:00:39 +02:00
Maximilian Bosch
8c07cdfedd Merge pull request #125915 from NixOS/backport-125861-to-release-21.05
[Backport release-21.05] youtube-dl: 2021.05.16 -> 2021.06.06
2021-06-06 11:00:29 +02:00
Michele Guerini Rocco
313fd7922c Merge pull request #125917 from NixOS/backport-125288-to-release-21.05
[Backport release-21.05] nixos/wireless: make wireless.interfaces mandatory
2021-06-06 10:59:29 +02:00
rnhmjoj
662f2d19b3 nixos/wireless: make wireless.interfaces mandatory
This is the only way to solve issue #101963, for now.

(cherry picked from commit 030a521adc)
2021-06-06 08:38:28 +00:00
zowoq
829e821768 youtube-dl: 2021.05.16 -> 2021.06.06
https://github.com/ytdl-org/youtube-dl/releases/tag/2021.06.06
(cherry picked from commit df82caf8df)
2021-06-06 08:31:30 +00:00
Vladimír Čunát
3776ceb792 Merge #125141: firefox-bin: 88.0.1 -> 89.0 (into release-21.05) 2021-06-06 09:17:58 +02:00
Kim Lindberger
64393daa54 Merge pull request #125821 from NixOS/backport-125699-to-release-21.05
[Backport release-21.05] treewide: Fix mysql alias deprecation breakage
2021-06-06 08:53:44 +02:00
Artturin
9e1f63c0d2 discord-canary: 0.0.123 -> 0.0.124
(cherry picked from commit f3dac01a71)
2021-06-06 03:54:09 +00:00
Sandro
ff5802403d Merge pull request #125877 from NixOS/backport-125316-to-release-21.05 2021-06-06 03:32:43 +02:00
Sandro
d5363c41e4 Merge pull request #125878 from NixOS/backport-125310-to-release-21.05 2021-06-06 03:32:28 +02:00
Sandro
8d05832f26 Update pkgs/development/libraries/box2d/default.nix
(cherry picked from commit 8fc57b0632120aad0ca9bbd3165616f9db2d06bd)
2021-06-06 00:08:22 +00:00
Ricardo M. Correia
186f49f5eb box2d: fix hash
The upstream tarball changed. Specifically, files now extract onto a
box2d-2.3.1/ directory rather than Box2D-2.3.1/. The files themselves
(and their contents) seem to remain the same.

(cherry picked from commit a8b85f6d68d4fc96a0f8473aa38a3e773b82c4f0)
2021-06-06 00:08:22 +00:00
Sandro
a0940c6ee4 Update pkgs/development/libraries/sundials/default.nix
(cherry picked from commit 248748e0408d1d9a8d43e4df0dc18bfe297c4887)
2021-06-06 00:08:20 +00:00
Ricardo M. Correia
c7d7f1881e sundials: fix download URL and hash
The old URL doesn't seem to be available anymore (fails with 403
Forbidden error).

The tarball in the new URL contains a few changes from the old one, so
the hash has changed.

Specifically, only the following files have changed:

sundials-5.7.0/doc/arkode/ark_examples.pdf
sundials-5.7.0/doc/arkode/ark_guide.pdf
sundials-5.7.0/doc/cvode/cv_examples.pdf
sundials-5.7.0/doc/cvode/cv_guide.pdf
sundials-5.7.0/doc/cvodes/cvs_examples.pdf
sundials-5.7.0/doc/cvodes/cvs_guide.pdf
sundials-5.7.0/doc/ida/ida_examples.pdf
sundials-5.7.0/doc/ida/ida_guide.pdf
sundials-5.7.0/doc/idas/idas_examples.pdf
sundials-5.7.0/doc/idas/idas_guide.pdf
sundials-5.7.0/doc/kinsol/kin_examples.pdf
sundials-5.7.0/doc/kinsol/kin_guide.pdf

(cherry picked from commit 4ab604c4c436505c98eb11e4a5c0323a1a835279)
2021-06-06 00:08:19 +00:00
Sandro
275a275cf7 [Backport release-21.05] viber: use webarchive for a stable source (#125868)
Co-authored-by: Artturin <Artturin@artturin.com>
2021-06-06 02:04:01 +02:00
Sandro
17d3c8bc81 Merge pull request #125871 from NixOS/backport-125431-to-release-21.05 2021-06-06 02:02:13 +02:00
Sandro
f6485e48e0 Merge pull request #125849 from NixOS/backport-125779-to-release-21.05 2021-06-06 01:55:46 +02:00
Ricardo M. Correia
8912beda2d replace: fix URL and hash
The old URL wasn't available anymore.

There is a minor version change but it's only an unimportant change to
the Makefile and some changes to the documentation.

(cherry picked from commit 908569cf06)
2021-06-05 23:43:33 +00:00
Sandro
f5b4a46849 Merge pull request #125340 from NixOS/backport-125282-to-release-21.05
[Backport release-21.05] sqlx-cli: 0.5.2 -> 0.5.5
2021-06-06 01:34:06 +02:00
Sandro
cf6dd96175 Merge pull request #125839 from NixOS/backport-125530-to-release-21.05
[Backport release-21.05] earthly: add missing buildFlags and tags
2021-06-06 01:32:53 +02:00
Sandro
d7b50ba9b5 Merge pull request #125231 from NixOS/backport-124716-to-release-21.05
[Backport release-21.05] brave: 1.24.86 -> 1.25.68
2021-06-06 01:32:36 +02:00
Sandro
1d4a389534 Merge pull request #125012 from NixOS/backport-124574-to-release-21.05
[Backport release-21.05] singularity: 3.7.3 -> 3.7.4
2021-06-06 01:32:27 +02:00
Artturin
d5b481dd69 viber: use webarchive for a stable source
(cherry picked from commit 24ba97a40b)
2021-06-05 23:16:08 +00:00
Maximilian Bosch
6178c4009c gitAndTools.tig: 2.5.3 -> 2.5.4
ChangeLog: https://github.com/jonas/tig/releases/tag/tig-2.5.4
(cherry picked from commit cd7a26eb8c)
2021-06-05 23:42:47 +02:00
Thomas Gerbet
2ab1f8ded8 gupnp: apply the patch for CVE-2021-33516
Fixes CVE-2021-33516.
https://discourse.gnome.org/t/security-relevant-releases-for-gupnp-issue-cve-2021-33516/6536

(cherry picked from commit 78d2a14bb8)
2021-06-05 21:33:52 +00:00
lassulus
f604d15d15 python3Packages.subliminal: readd again
(cherry picked from commit c78fe7aa78)
2021-06-05 21:31:27 +00:00
Maximilian Bosch
4ce72a0473 evcxr: 0.9.0 -> 0.10.0
ChangeLog: https://github.com/google/evcxr/blob/v0.10.0/RELEASE_NOTES.md#version-0100
(cherry picked from commit 2d2c58970a)
2021-06-05 21:09:59 +00:00
Mario Rodas
15087f578c Merge pull request #125820 from NixOS/backport-125751-to-staging-21.05
[Backport staging-21.05] postgresql: 9.6.21 -> 9.6.22, 10.16 -> 10.17, 11.11 -> 11.12, 12.6 -> 12.7, 13.2 -> 13.3
2021-06-05 15:05:04 -05:00
Artturin
b4a822688b earthly: add missing buildFlags and tags
(cherry picked from commit a5bf3427fb)
2021-06-05 19:53:06 +00:00
Robert Scott
5de44c1575 Merge pull request #125621 from etu/backport-php-upgrades
[21.05] php: php upgrades
2021-06-05 20:40:48 +01:00
Maximilian Bosch
54305f13e8 Merge pull request #125807 from NixOS/backport-123657-to-release-21.05
[Backport release-21.05] Kernels 2021-05-26
2021-06-05 20:38:21 +02:00
talyz
a60818cacd treewide: Fix mysql alias deprecation breakage
62733b37b4 broke evaluation in all
places `pkgs.mysql` was used. Fix this by changing all occurrences to
`pkgs.mariadb`.

(cherry picked from commit 59e0120aa5)
2021-06-05 17:11:40 +00:00
Martin Weinelt
4a7770bfd6 postgresql_9_6: 9.6.21 -> 9.6.22
Fixes: CVE-2021-32027, CVE-2021-32028
(cherry picked from commit 062e1e595f)
2021-06-05 17:09:24 +00:00
Martin Weinelt
731e67c871 postgresql_10: 10.16 -> 10.17
Fixes: CVE-2021-32027, CVE-2021-32028
(cherry picked from commit 376197bc5e)
2021-06-05 17:09:24 +00:00
Martin Weinelt
8d97696b86 postgresql_11: 11.11 -> 11.12
Fixes: CVE-2021-32027, CVE-2021-32028, CVE-2021-32029
(cherry picked from commit daedf20fa6)
2021-06-05 17:09:24 +00:00
Martin Weinelt
942a01e232 postgresql_12: 12.6 -> 12.7
Fixes: CVE-2021-32027, CVE-2021-32028, CVE-2021-32029
(cherry picked from commit b786157de8)
2021-06-05 17:09:23 +00:00
Martin Weinelt
894d6ab2de postgresql_13: 13.2 -> 13.3
Fixes: CVE-2021-32027, CVE-2021-32028, CVE-2021-32029
(cherry picked from commit 3318a937ef)
2021-06-05 17:09:23 +00:00
Jan Tojnar
e3ede71a0f teams: remove jtojnar on stable 2021-06-05 18:27:16 +02:00
Aaron Janse
d5dc09b57b gnome-boxes: add qemu as dependency
(cherry picked from commit 795021ada5)
2021-06-05 16:22:41 +00:00
Jörg Thalheim
1dfa9b73db buildFhsUserenv: don't leak mounts to other processes
If run as root we were leaking mounts to the parent namespace,
which lead to an error when removing the temporary mountroot.
To fix this we remount the whole tree as private as soon as we created
the new mountenamespace.

(cherry picked from commit 43908f4c1d)
2021-06-05 16:06:56 +00:00
Stefan Frijters
db819f1626 openrgb: Fix udev rules with hardcoded /bin/chmod
New rules introduced in openrgb 0.6.

openrgb: Implement nixpkgs-review suggestions

* warning: missing-phase-hooks
* warning: unclear-gpl
* warning: unnecessary-parallel-building

(cherry picked from commit 84dc04c2db2f45237658e1178f22057f49a6b95f)
2021-06-05 08:26:00 -07:00
Yurii Matsiuk
099d0e5cb2 linux/hardened/patches/5.4: 5.4.121-hardened1 -> 5.4.122-hardened1
(cherry picked from commit 1ce119e9bb)
2021-06-05 15:07:38 +00:00
Yurii Matsiuk
5e4a63c145 linux/hardened/patches/5.12: 5.12.6-hardened1 -> 5.12.7-hardened1
(cherry picked from commit cdc6a4cc1e)
2021-06-05 15:07:37 +00:00
Yurii Matsiuk
45c9ea8fdb linux/hardened/patches/5.10: 5.10.39-hardened1 -> 5.10.40-hardened1
(cherry picked from commit 46ca914a5e)
2021-06-05 15:07:37 +00:00
Yurii Matsiuk
10afabfad5 linux/hardened/patches/4.19: 4.19.191-hardened1 -> 4.19.192-hardened1
(cherry picked from commit 938ea32339)
2021-06-05 15:07:37 +00:00
Yurii Matsiuk
f5fa39d4a1 linux/hardened/patches/4.14: 4.14.233-hardened1 -> 4.14.234-hardened1
(cherry picked from commit 52e8c2d165)
2021-06-05 15:07:37 +00:00
Yurii Matsiuk
79115d6a82 linux: 5.4.121 -> 5.4.122
(cherry picked from commit c16011b1d9)
2021-06-05 15:07:36 +00:00
Yurii Matsiuk
d0d7b4af7e linux: 5.12.6 -> 5.12.7
(cherry picked from commit 01cc705d4a)
2021-06-05 15:07:36 +00:00
Yurii Matsiuk
a5c46f1388 linux: 5.10.39 -> 5.10.40
(cherry picked from commit bed18f5019)
2021-06-05 15:07:36 +00:00
Yurii Matsiuk
55be7efd2e linux: 4.9.269 -> 4.9.270
(cherry picked from commit 7d57471efa)
2021-06-05 15:07:36 +00:00
Yurii Matsiuk
e8c17e37ea linux: 4.4.269 -> 4.4.270
(cherry picked from commit 819f6a5d8c)
2021-06-05 15:07:35 +00:00
Yurii Matsiuk
876f1db8eb linux: 4.19.191 -> 4.19.192
(cherry picked from commit bd12ba9643)
2021-06-05 15:07:35 +00:00
Yurii Matsiuk
cd8ea3fcd0 linux: 4.14.233 -> 4.14.234
(cherry picked from commit 91233c46e3)
2021-06-05 15:07:35 +00:00
Yurii Matsiuk
a361101945 linux/hardened/patches/5.12: init at 5.12.6-hardened1
(cherry picked from commit 6c6f9a5abf)
2021-06-05 15:07:35 +00:00
Yurii Matsiuk
9b91d0c98a linux/hardened/patches/5.4: 5.4.119-hardened1 -> 5.4.121-hardened1
(cherry picked from commit 63f5c51430)
2021-06-05 15:07:34 +00:00
Yurii Matsiuk
8c3ed02c5b linux/hardened/patches/5.11: 5.11.21-hardened1 -> 5.11.22-hardened1
(cherry picked from commit ac7c67ea0c)
2021-06-05 15:07:34 +00:00
Yurii Matsiuk
3270f6e74f linux/hardened/patches/5.10: 5.10.37-hardened1 -> 5.10.39-hardened1
(cherry picked from commit f8df946b8b)
2021-06-05 15:07:34 +00:00
Yurii Matsiuk
1537b18b66 linux/hardened/patches/4.19: 4.19.190-hardened1 -> 4.19.191-hardened1
(cherry picked from commit 38a17bf835)
2021-06-05 15:07:33 +00:00
Yurii Matsiuk
641eac3f62 linux/hardened/patches/4.14: 4.14.232-hardened1 -> 4.14.233-hardened1
(cherry picked from commit 96806043e7)
2021-06-05 15:07:33 +00:00
Yurii Matsiuk
8d3861572f linux_latest-libre: 18063 -> 18096
(cherry picked from commit be8af32578)
2021-06-05 15:07:33 +00:00
Yurii Matsiuk
ff2eb0479e linux: 5.4.120 -> 5.4.121
(cherry picked from commit 44ed8b845d)
2021-06-05 15:07:33 +00:00
Yurii Matsiuk
17c7ef67ea linux: 5.12.5 -> 5.12.6
(cherry picked from commit 6485d14e6d)
2021-06-05 15:07:32 +00:00
Yurii Matsiuk
a8f69347be linux: 5.10.38 -> 5.10.39
(cherry picked from commit 43730b18ea)
2021-06-05 15:07:32 +00:00
Yurii Matsiuk
537d97790b linux: 4.9.268 -> 4.9.269
(cherry picked from commit e51c114dfe)
2021-06-05 15:07:32 +00:00
Yurii Matsiuk
853bb573e9 linux: 4.4.268 -> 4.4.269
(cherry picked from commit 7d15d50717)
2021-06-05 15:07:32 +00:00
Yurii Matsiuk
5e4829822c linux: 4.19.190 -> 4.19.191
(cherry picked from commit be7fc1bdee)
2021-06-05 15:07:31 +00:00
Yurii Matsiuk
747ca0c87f linux: 4.14.232 -> 4.14.233
(cherry picked from commit c5545b7e42)
2021-06-05 15:07:31 +00:00
Yurii Matsiuk
73710f8803 linux: 5.4.119 -> 5.4.120
(cherry picked from commit ce48d2c593)
2021-06-05 15:07:31 +00:00
Yurii Matsiuk
1e4ff1a71e linux: 5.12.4 -> 5.12.5
(cherry picked from commit a76a720665)
2021-06-05 15:07:31 +00:00
Yurii Matsiuk
64809ba107 linux: 5.11.21 -> 5.11.22
(cherry picked from commit 701282a87a)
2021-06-05 15:07:30 +00:00
Yurii Matsiuk
07dd7d248d linux: 5.10.37 -> 5.10.38
(cherry picked from commit 9a0a33f6b1)
2021-06-05 15:07:30 +00:00
Aaron Andersen
373aeac41f zabbix.agent2: create a symlink which is compatible with the zabbixAgent module
(cherry picked from commit 99e3741957)
2021-06-05 15:03:09 +00:00
Sandro
f00749660d Merge pull request #125528 from wizeman/u/fix-gitrepo-backport
[21.05] gitRepo: Add import to ssl module to avoid runtime error (#125373)
2021-06-05 16:52:59 +02:00
Robert Hensing
1fe3b399a3 Merge pull request #125783 from NixOS/backport-125625-to-release-21.05
[Backport release-21.05] doc: Fix make in nix-shell
2021-06-05 15:14:54 +02:00
Robert Scott
f0f9b4ef89 Merge pull request #125782 from NixOS/backport-125645-to-release-21.05
[Backport release-21.05] wireshark: 3.4.5 -> 3.4.6
2021-06-05 13:53:35 +01:00
Robert Scott
ee7d49b968 Merge pull request #125784 from NixOS/backport-125566-to-release-21.05
[Backport release-21.05] pam_u2f: 1.1.0 -> 1.1.1
2021-06-05 13:34:11 +01:00
Maximilian Bosch
01ec377896 Merge pull request #125786 from NixOS/backport-125732-to-release-21.05
[Backport release-21.05] rambox: unmaintain & mark as insecure
2021-06-05 14:08:35 +02:00
Maximilian Bosch
d54d20e1c1 Merge pull request #125787 from NixOS/backport-125723-to-release-21.05
[Backport release-21.05] ferdi: 5.6.0-beta.5 -> 5.6.0-beta.6, improve XWayland support
2021-06-05 14:08:24 +02:00
Ilan Joselevich
b7833a0724 jitsi-meet-electron: 2.8.5 -> 2.8.6
(cherry picked from commit 29c70d515a)
2021-06-05 14:05:15 +02:00
Guillaume Girol
49acb91cbf gpxlab: update license
(cherry picked from commit 87c98dcdfc1778f8988e3d430cfe847b56a26f5c)
2021-06-05 14:04:15 +02:00
Nikolay Korotkiy
3e1e2b277f gpxlab: fix localization
(cherry picked from commit b931540229865e96ed515f0a041960c45a3069c2)
2021-06-05 14:04:15 +02:00
Eduardo Sánchez Muñoz
4a6b102088 teams: enable appindicator tray icon support
(cherry picked from commit de7986d7af)
2021-06-05 13:58:48 +02:00
fortuneteller2k
9a3a0f39f9 vocal: fix build
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit 01ef9faecb)
2021-06-05 13:57:25 +02:00
InternetUnexplorer
bc0d018a6b renoise: 3.3.1 -> 3.3.2
(cherry picked from commit 78b1168234)
2021-06-05 13:55:13 +02:00
Serg Nesterov
ce9c83cee0 tmuxinator: 2.0.2 -> 2.0.3
tmuxinator 2.0.3 fixes a compatibility warning with tmux 2.3, which is
the version packaged on NixOS 21.05.

See https://github.com/tmuxinator/tmuxinator/issues/814

(cherry picked from commit 28ab65b586)
2021-06-05 13:53:59 +02:00
Maximilian Bosch
1eb5ab963a ferdi: 5.6.0-beta.5 -> 5.6.0-beta.6, improve XWayland support
ChangeLog: 1886c8abed/CHANGELOG.md (560-beta6-2021-05-31)

Even though this isn't explicitly noted in the Changelog, this seems to
have fixed the Element integration for me.

Additionally, I added a (hacky) `xdg-open` wrapper which removes the
`GDK_BACKEND` variable to fix the XWayland integration[1]. The problem
is that if a Firefox is running with Wayland (`ferdi` is running under
X11) and `GDK_BACKEND=x11` is passed to the `xdg-open` (and thus
`firefox`) process, Firefox refuses to start since another instance of
it is running under Wayland (but attempts to start in X11 mode because of
`GDK_BACKEND=x11`).

[1] https://github.com/electron/electron/issues/28436

(cherry picked from commit cd4ad7d2fe)
2021-06-05 11:44:32 +00:00
Maximilian Bosch
ef186b47af rambox: unmaintain & mark as insecure
Rambox hasn't had a stable release in a while and an increasing number
of issues which is why I don't intend to use this anymore.

While taking a closer look at the source I also realized that it uses
Electron 7.2.4[1]. This is not only EOLed[2], it also contains a few
security vulnerabilities which is why I decided to mark it as insecure.

A few (most likely not all) vulnerabilities can be found by looking at
the Electron 7 changelog[3]: after 7.2.4 there were a few more releases
with security backports - mostly from Chromium. Security issues that
were found later on (and are probably exploitable on the dependency
chain of rambox) aren't listed here. I only added two issues that seemed
applicable to `rambox`, but I haven't researched enough to check the
other ones.

[1] https://github.com/ramboxapp/community-edition/blob/0.7.7/package.json#L70
[2] https://www.electronjs.org/docs/tutorial/support#currently-supported-versions
[3] https://www.electronjs.org/releases/stable?version=7

(cherry picked from commit e2a15cd395)
2021-06-05 11:44:21 +00:00
Thomas Gerbet
91c7763b9d pam_u2f: 1.1.0 -> 1.1.1
Fixes CVE-2021-31924
https://www.yubico.com/support/security-advisories/ysa-2021-03/

Changelog: https://github.com/Yubico/pam-u2f/blob/pam_u2f-1.1.1/NEWS
(cherry picked from commit b5afbd350d)
2021-06-05 11:33:09 +00:00
Jan Tojnar
f0dfe62190 doc: Fix make in nix-shell
When running make manually, makeFlags will not be passed. Let’s just use an environment variable.

(cherry picked from commit 034a9c0e16aab12978bb4a1c1f0e86c64778b388)
2021-06-05 11:29:01 +00:00
TredwellGit
e2fccba4ef wireshark: 3.4.5 -> 3.4.6
https://www.wireshark.org/docs/relnotes/wireshark-3.4.6.html
(cherry picked from commit 15974f58b8)
2021-06-05 11:25:01 +00:00
Michael Weiss
527c0bbf84 Merge pull request #125773 from NixOS/backport-125724-to-release-21.05
[Backport release-21.05] signal-desktop: 5.3.0 -> 5.4.0
2021-06-05 12:17:35 +02:00
Martin Weinelt
36b2126e54 Merge pull request #125762 from NixOS/backport-125749-to-release-21.05
[Backport release-21.05] python3Packages.aiomultiprocess: disable failing tests
2021-06-05 12:03:58 +02:00
Michael Weiss
08866897e3 signal-desktop: 5.3.0 -> 5.4.0
(cherry picked from commit f5be28bcc9)
2021-06-05 09:35:26 +00:00
Martin Weinelt
e7c8f2ff73 python3Packages.aiomultiprocess: disable failing tests
These tests fail from time to time and bring the whole test suite to a
timeout.

https://github.com/omnilib/aiomultiprocess/issues/97
(cherry picked from commit c8261a34f8)
2021-06-05 08:12:04 +00:00
Vladimír Čunát
99995bc930 zstd.patches: clean up
This was discussed on PR #125185.
2021-06-05 07:34:46 +02:00
Vladimír Čunát
7b686ba07b Merge branch 'release-21.05' into staging-21.05 2021-06-05 07:30:40 +02:00
Jörg Thalheim
0edbcd01f6 Merge pull request #125349 from Mic92/containerd-backport
[21.05] containerd: fix checksum
2021-06-05 07:28:48 +02:00
Vojtěch Káně
9f537a52df lightworks: 2021.2 -> 2021.2.1
(cherry picked from commit a9edf3b544)
2021-06-04 19:11:09 +00:00
Vojtěch Káně
089308ac91 lightworks: add me as a maintainer
(cherry picked from commit ccb691c7d1)
2021-06-04 19:11:08 +00:00
Vojtěch Káně
e387f0600c lightworks: 14.0.0 -> 2021.2
(cherry picked from commit 2c3d045bc3)
2021-06-04 19:11:08 +00:00
Maximilian Bosch
aa57635767 Merge pull request #125684 from NixOS/backport-125483-to-release-21.05
[Backport release-21.05] nixos/prometheus-exporters: improve docs & fix rspamd exporter
2021-06-04 17:36:38 +02:00
Sandro
503638304e Merge pull request #125526 from wizeman/u/fix-libraspberrypi-url-backport
[21.05] libraspberrypi: fix URL
2021-06-04 17:18:22 +02:00
Maximilian Bosch
3c8dcd902a nixos/mail-exporter: add note about rspamd marking probe mails as spam
(cherry picked from commit ba9768f314)
2021-06-04 14:14:35 +00:00
Maximilian Bosch
d7fbcd60a3 nixos/dovecot-exporter: fix documentation for old stats
(cherry picked from commit 6fb847c556)
2021-06-04 14:14:35 +00:00
Maximilian Bosch
619cf60d25 nixos/rspamd-exporter: fix metrics
In 0.3.0 of the json-exporter[1] it was switched to a different jsonpath
library which made some changes - especially for spaces in keys -
necessary. Also I decided to remove the pretty-printed JSON as this
would interfere with the bash quoting too much. If one needs
pretty-printed output, they can still pipe the output to `jq`.

[1] https://github.com/prometheus-community/json_exporter/releases/tag/v0.3.0

(cherry picked from commit 976d668e5c)
2021-06-04 14:14:35 +00:00
stigtsp
5f244caea7 Merge pull request #125646 from stigtsp/package/perl-Mojolicious-9.19-backport-21.05
[21.05] perlPackages.Mojolicious: 9.17 -> 9.19
2021-06-04 14:54:40 +02:00
Elis Hirwing
02957ca57b php80: 8.0.6 -> 8.0.7
https://www.php.net/ChangeLog-8.php#8.0.7
(cherry picked from commit 6b7b002544)
2021-06-04 14:11:10 +02:00
Robert Hensing
f52ff6ed96 arion: 0.1.2.0 -> 0.1.3.0 2021-06-04 14:02:39 +02:00
lsix
65a1f5fbdc Merge pull request #125436 from NixOS/backport-125375-to-staging-21.05
[Backport staging-21.05] python3Packages.django: 2.2.22 -> 2.2.24; python3Packages.django3_: 3.2.2 -> 3.2.4
2021-06-04 12:03:03 +01:00
Zak B. Elep
467ae337e8 perlPackages.Mojolicious: 9.17 -> 9.19
(cherry picked from commit 15f6e4ed3b)
2021-06-04 12:21:36 +02:00
Vonfry
1e20589c4b fcitx5-table-extra: 5.0.2 -> 5.0.4
(cherry picked from commit 7f705f7b08)
2021-06-04 10:06:12 +00:00
Vonfry
835320ae4e fcitx5-table-other: 5.0.3 -> 5.0.5
(cherry picked from commit b40e526658)
2021-06-04 10:06:12 +00:00
Vonfry
5a3bcadc54 fcitx5-rime: 5.0.4 -> 5.0.6
(cherry picked from commit d49f66e971)
2021-06-04 10:06:12 +00:00
Vonfry
e6d8d9a5f8 fcitx5-lua: 5.0.4 -> 5.0.5
(cherry picked from commit 058df25e05)
2021-06-04 10:06:12 +00:00
Vonfry
10d45f3fda fcitx5-gtk: 5.0.3 -> 5.0.7
(cherry picked from commit 55dfc47900)
2021-06-04 10:06:12 +00:00
Vonfry
d3779267b9 fcitx5-configtool: 5.0.4 -> 5.0.5
(cherry picked from commit 1a63a40bc7)
2021-06-04 10:06:11 +00:00
Vonfry
548459289a fcitx5: 5.0.4 -> 5.0.8
(cherry picked from commit 1c71ffe5af)
2021-06-04 10:06:11 +00:00
Sandro
e829bef3ca Merge pull request #125633 from NixOS/backport-125537-to-release-21.05
[Backport release-21.05] nixos/release-notes: Fix link to GNOME 40 release notes
2021-06-04 11:40:03 +02:00
Sandro
67cda28baa Merge pull request #125635 from NixOS/backport-125394-to-release-21.05
[Backport release-21.05] win-spice: say yes to all 7z dialogs
2021-06-04 11:39:52 +02:00
Maximilian Bosch
3dd3f4e578 Merge pull request #125629 from NixOS/backport-125536-to-release-21.05
[Backport release-21.05] matrix-synapse: 1.35.0 -> 1.35.1
2021-06-04 11:25:17 +02:00
fortuneteller2k
96882387e5 win-spice: say yes to all 7z dialogs
(cherry picked from commit 0c245a39a9)
2021-06-04 09:22:28 +00:00
Anders Kaseorg
19f959fccb nixos/release-notes: Fix link to GNOME 40 release notes
Signed-off-by: Anders Kaseorg <andersk@mit.edu>
(cherry picked from commit a681951902)
2021-06-04 09:17:01 +00:00
Sumner Evans
b5cec505c1 matrix-synapse: 1.35.0 -> 1.35.1
(cherry picked from commit 10cbea574d)
2021-06-04 08:43:14 +00:00
Thomas Gerbet
f8455aefe9 phpPackages.composer: 2.1.0 -> 2.1.1
https://github.com/composer/composer/releases/tag/2.1.1
(cherry picked from commit 5ae9ac3e88)
2021-06-04 10:14:16 +02:00
Vladimír Čunát
3903d2d41d Merge #125139: firefox: 88.0.1 -> 89.0 (into release-21.05) 2021-06-04 09:35:18 +02:00
taku0
a593d12cec thunderbird-bin: 78.10.2 -> 78.11.0
(cherry picked from commit 79f71ef9aa)
2021-06-04 07:31:00 +00:00
taku0
5527182b0b thunderbird: 78.10.2 -> 78.11.0
(cherry picked from commit 7267b80c71)
2021-06-04 07:31:00 +00:00
Elis Hirwing
fb4f4addaf php.packages.composer: 2.0.13 -> 2.1.0
(cherry picked from commit 5880c1c4bf)
2021-06-04 09:04:06 +02:00
Elis Hirwing
f11b59b21b php80: 8.0.5 -> 8.0.6
https://www.php.net/ChangeLog-8.php#8.0.6
(cherry picked from commit a3c966cc7a)
2021-06-04 09:02:59 +02:00
Elis Hirwing
f035fa6ede php74: 7.4.18 -> 7.4.20
https://www.php.net/ChangeLog-7.php#7.4.19
https://www.php.net/ChangeLog-7.php#7.4.20
(cherry picked from commit 23548b2552)
2021-06-04 09:02:48 +02:00
Vladimír Čunát
729e236f7a Merge #125593: polkit: Fix authentication bypass vulnerability 2021-06-04 08:47:51 +02:00
Jonathan Ringer
4c2e84394c linuxPackages.ati_drivers_x11: move to alias set
(cherry picked from commit 095e6fdd126c91f3196bf19cbbc5caf8d6c292a9)
2021-06-03 23:01:50 -07:00
Jonathan Ringer
d0db001244 tdesktop: add optional dependencies
(cherry picked from commit fa3517c57a831f56fdb5c60f573ac1c70d5f16eb)
2021-06-03 22:24:50 -07:00
Jonathan Ringer
1de618903e tdesktop: 2.7.4 -> 2.7.5
(cherry picked from commit be72f6a7ce5f2cefbfc7ade175669494e65c3d8a)
2021-06-03 22:24:50 -07:00
Martin Weinelt
715c85757b polkit: Fix local privilege escalation vulnerability
Fixes a local privilege escalation using polkit_system_bus_name_get_creds_sync()

Fixes: CVE-2021-3560
(cherry picked from commit 26ac1d5db9)
2021-06-04 00:36:44 +00:00
Martin Weinelt
c0e22c259c Merge pull request #125582 from NixOS/backport-125576-to-release-21.05 2021-06-04 01:31:34 +02:00
Martin Weinelt
4827d347cc matrix-synapse.tools.synadm: init at 0.29
(cherry picked from commit 7efe82966d)
2021-06-03 23:15:30 +00:00
Martin Weinelt
47f12a4002 python3Packages.click-option-group: init at 0.5.3
(cherry picked from commit c06b1086c0)
2021-06-03 23:15:29 +00:00
Robert Scott
9cfa9a79cc Merge pull request #125353 from petabyteboy/feature/gitlab-13-12-2-backport
[21.05] gitlab: 13.12.0 -> 13.12.2
2021-06-03 22:33:34 +01:00
Robert Scott
4714dcf148 Merge pull request #125385 from mweinelt/21.05/lasso
[21.05] lasso: Fix signature verification in AuthnResponse messages
2021-06-03 20:44:50 +01:00
Martin Weinelt
54fd06550c Merge pull request #125546 from NixOS/backport-125105-to-release-21.05 2021-06-03 20:56:27 +02:00
Martin Weinelt
58bf12dbbf samba4Full: disable glusterfs support
The samba package was marked as broken, when enableGlusterFS is true.

The samba build with glusterfs fails due to API breakage that I am
unable to debug:

[3562/4088] Compiling source3/modules/vfs_virusfilter.c
../../source3/modules/vfs_glusterfs.c: In function ‘vfs_gluster_pread’:
../../source3/modules/vfs_glusterfs.c:856:8: error: too few arguments to function ‘glfs_pread’
  856 |  ret = glfs_pread(glfd, data, n, offset, 0);
      |        ^~~~~~~~~~
In file included from ../../source3/modules/vfs_glusterfs.c:41:
/nix/store/0gzaf6fqgfxfns19zlc07dyjqigj7ak7-glusterfs-9.0/include/glusterfs/api/glfs.h:713:1: note: declared here
  713 | glfs_pread(glfs_fd_t *fd, void *buf, size_t count, off_t offset, int flags,
      | ^~~~~~~~~~
../../source3/modules/vfs_glusterfs.c: In function ‘vfs_gluster_pread_do’:
../../source3/modules/vfs_glusterfs.c:938:16: error: too few arguments to function ‘glfs_pread’
  938 |   state->ret = glfs_pread(state->fd, state->buf, state->count,
      |                ^~~~~~~~~~
In file included from ../../source3/modules/vfs_glusterfs.c:41:
/nix/store/0gzaf6fqgfxfns19zlc07dyjqigj7ak7-glusterfs-9.0/include/glusterfs/api/glfs.h:713:1: note: declared here
  713 | glfs_pread(glfs_fd_t *fd, void *buf, size_t count, off_t offset, int flags,
      | ^~~~~~~~~~
../../source3/modules/vfs_glusterfs.c: In function ‘vfs_gluster_pwrite_do’:
../../source3/modules/vfs_glusterfs.c:1077:16: error: too few arguments to function ‘glfs_pwrite’
 1077 |   state->ret = glfs_pwrite(state->fd, state->buf, state->count,
      |                ^~~~~~~~~~~
In file included from ../../source3/modules/vfs_glusterfs.c:41:
/nix/store/0gzaf6fqgfxfns19zlc07dyjqigj7ak7-glusterfs-9.0/include/glusterfs/api/glfs.h:717:1: note: declared here
  717 | glfs_pwrite(glfs_fd_t *fd, const void *buf, size_t count, off_t offset,
      | ^~~~~~~~~~~
../../source3/modules/vfs_glusterfs.c: In function ‘vfs_gluster_pwrite’:
../../source3/modules/vfs_glusterfs.c:1161:8: error: too few arguments to function ‘glfs_pwrite’
 1161 |  ret = glfs_pwrite(glfd, data, n, offset, 0);
      |        ^~~~~~~~~~~
In file included from ../../source3/modules/vfs_glusterfs.c:41:
/nix/store/0gzaf6fqgfxfns19zlc07dyjqigj7ak7-glusterfs-9.0/include/glusterfs/api/glfs.h:717:1: note: declared here
  717 | glfs_pwrite(glfs_fd_t *fd, const void *buf, size_t count, off_t offset,
      | ^~~~~~~~~~~
../../source3/modules/vfs_glusterfs.c: In function ‘vfs_gluster_fsync_do’:
../../source3/modules/vfs_glusterfs.c:1287:16: error: too few arguments to function ‘glfs_fsync’
 1287 |   state->ret = glfs_fsync(state->fd);
      |                ^~~~~~~~~~
In file included from ../../source3/modules/vfs_glusterfs.c:41:
/nix/store/0gzaf6fqgfxfns19zlc07dyjqigj7ak7-glusterfs-9.0/include/glusterfs/api/glfs.h:790:1: note: declared here
  790 | glfs_fsync(glfs_fd_t *fd, struct glfs_stat *prestat,
      | ^~~~~~~~~~
../../source3/modules/vfs_glusterfs.c: In function ‘vfs_gluster_ftruncate’:
../../source3/modules/vfs_glusterfs.c:1621:8: error: too few arguments to function ‘glfs_ftruncate’
 1621 |  ret = glfs_ftruncate(glfd, offset);
      |        ^~~~~~~~~~~~~~
In file included from ../../source3/modules/vfs_glusterfs.c:41:
/nix/store/0gzaf6fqgfxfns19zlc07dyjqigj7ak7-glusterfs-9.0/include/glusterfs/api/glfs.h:768:1: note: declared here
  768 | glfs_ftruncate(glfs_fd_t *fd, off_t length, struct glfs_stat *prestat,
      | ^~~~~~~~~~~~~~

../../source3/modules/vfs_virusfilter.c: In function ‘quarantine_create_dir’:
../../source3/modules/vfs_virusfilter.c:132:13: warning: implicit declaration of function ‘strlcat’; did you mean ‘strncat’? [-Wimplicit-function-declaration]
  132 |   cat_len = strlcat(new_dir, "/", len + 1);
      |             ^~~~~~~
      |             strncat

Waf: Leaving directory `/build/samba-4.14.4/bin/default'
Build failed
 -> task in 'vfs_glusterfs.objlist' failed with exit status 1 (run with -v to display more information)

(cherry picked from commit fac761a55a)
2021-06-03 18:19:49 +00:00
Maxine Aubrey
282a4d554e samba: add missing python dependencies for ldap and domain controller
(cherry picked from commit b760ab8cfb)
2021-06-03 18:19:49 +00:00
Otavio Salvador
8b0cabcf5c gitRepo: Add import to ssl module to avoid runtime error (#125373)
Co-authored-by: Ricardo M. Correia <rcorreia@wizy.org>
(cherry picked from commit 8f166b95c9)
2021-06-03 18:23:35 +02:00
Ricardo M. Correia
3b96c770a8 libraspberrypi: fix URL
(cherry picked from commit 3915d2fd27)
2021-06-03 18:08:13 +02:00
Jonathan Ringer
592df52aa1 nix: 2.3.11 -> 2.3.12
(cherry picked from commit ff50095bd4121f35e1ca73b4df68912db1bff2a4)
2021-06-03 08:11:52 -07:00
Jonathan Ringer
b78bd862e3 nixUnstable: 2.4pre20210503_6d2553a -> 2.4pre20210601_5985b8b5
(cherry picked from commit f7fe3008d106b8b8834a4f64868ae386a9b26e08)
2021-06-03 08:11:52 -07:00
Samuel Dionne-Riel
7953561a9d iso-image: Improve disk detection
This should help in rare hardware-specific situations where the root is
not automatically detected properly.

We search using a marker file. This should help some weird UEFI setups
where the root is set to `(hd0,msdos2)` by default.

Defaulting to `(hd0)` by looking for the ESP **will break themeing**. It
is unclear why, but files in `(hd0,msdos2)` are not all present as they
should be.

This also fixes an issue introduced with cb5c4fcd3c
where rEFInd stopped booting in many cases. This is because it ended up
using (hd0) rather than using the `search` which was happening
beforehand, which in turn uses (hd0,msdos2), which is the ESP.
Putting back the `search` here fixes that.

(cherry picked from commit 20b023b5ea)
2021-06-03 08:03:07 -07:00
Samuel Dionne-Riel
2f5e4928c0 iso-image: unqualified root → ($root)
This technically changes nothing. In practice `$root` is always the
"CWD", whether searched for automatically or not.

But this serves to announce we are relying on `$root`... I guess...

(cherry picked from commit c9bb054dd6)
2021-06-03 08:03:07 -07:00
Samuel Dionne-Riel
190f44da28 iso-image: change date on all files
It may be that in some conditions dates earlier than 1980 on FAT on GRUB
2.06~ish will cause failures

https://github.com/NixOS/nixpkgs/issues/123376#issuecomment-845515035
(cherry picked from commit 15eaed0718)
2021-06-03 08:03:07 -07:00
Samuel Dionne-Riel
8cb2ce0f52 iso-image: Force gfxmode
https://www.gnu.org/software/grub/manual/grub/html_node/gfxmode.html
(cherry picked from commit f93f0e72e9)
2021-06-03 08:03:07 -07:00
Sandro
91afc72d9e Merge pull request #125342 from NixOS/backport-125334-to-release-21.05
[Backport release-21.05] matterbridge: 1.12.1 -> 1.12.2
2021-06-03 16:42:43 +02:00
Domen Kožar
0f8f64b54e Merge pull request #125475 from NixOS/backport-125372-to-release-21.05
[Backport release-21.05] nixos/tests/test-driver: add shell_interact
2021-06-03 13:11:46 +02:00
Timothy Klim
a72d67f426 nvidia-x11: 465.27 -> 465.31
(cherry picked from commit 29e6e27d4f)
2021-06-03 10:51:40 +00:00
Patrick Hilhorst
9452c8fb4b nixos/tests/test-driver: make it clear when shell is ready
Co-authored-by: Domen Kožar <domen@enlambda.com>
(cherry picked from commit fd739c4dee)
2021-06-03 09:49:17 +00:00
Patrick Hilhorst
5ed752dd35 nixos/tests/test-driver: mention drawback
(cherry picked from commit 2871442731)
2021-06-03 09:49:17 +00:00
Patrick Hilhorst
9046996543 nixos/tests/test-driver: document shell_interact
(cherry picked from commit 9469433e34)
2021-06-03 09:49:17 +00:00
Patrick Hilhorst
e3e37d20ce nixos/tests/test-driver: add shell_interact
(cherry picked from commit 5a589b5ba8)
2021-06-03 09:49:17 +00:00
Dmitry Kalinkin
2d1b9ef5e7 blender: fix darwin build
(cherry picked from commit dca87350f4)
2021-06-03 04:30:30 -04:00
Jonas Carpay
eab4608a67 blender: 2.92.0 -> 2.93.0
(cherry picked from commit ff60dfcc7f)
2021-06-03 04:30:30 -04:00
github-actions[bot]
6feba09c53 redis: 6.2.3 -> 6.2.4 (#125444)
https://github.com/redis/redis/releases/tag/6.2.4
(cherry picked from commit 8d34fb204c)

Co-authored-by: Mario Rodas <marsam@users.noreply.github.com>
2021-06-03 00:45:22 -04:00
Martin Weinelt
40203c4061 Merge pull request #125336 from NixOS/backport-125306-to-release-21.05
[Backport release-21.05] firefox-esr: 78.10.1esr -> 78.11.0esr
2021-06-03 05:12:51 +02:00
adisbladis
a1acedfd1d Merge pull request #125406 from eduardosm/dr14_tmeter
[21.05] dr14_tmeter: use ffmpeg 4
2021-06-02 20:17:57 -05:00
Dennis Gosnell
e5e05cd00f Merge pull request #125433 from sternenseemann/greenclip-fix
[21.05] haskellPackages.greenclip: unbreak
2021-06-03 09:30:14 +09:00
Martin Weinelt
db7ab2c8d2 python3Packages.django_3: 3.2.2 -> 3.2.4
https://docs.djangoproject.com/en/dev/releases/3.2.4/
https://www.djangoproject.com/weblog/2021/jun/02/security-releases/

Fixes: CVE-2021-33203, CVE-2021-33571
(cherry picked from commit 794c6633b6)
2021-06-03 00:21:45 +00:00
Martin Weinelt
781ccf32d0 python3Packages.django: 2.2.22 -> 2.2.24
https://docs.djangoproject.com/en/dev/releases/2.2.24/
https://www.djangoproject.com/weblog/2021/jun/02/security-releases/

Fixes: CVE-2021-33203, CVE-2021-33571
(cherry picked from commit 6c7db95fea)
2021-06-03 00:21:44 +00:00
Milan
4691b50a4e gitlab: 13.12.0 -> 13.12.2
https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/
Backport of #125271
(cherry picked from commit 2a1c29ef4b)
2021-06-03 00:54:21 +02:00
sternenseemann
ca783d93bb haskellPackages.greenclip: unmark as broken
libXScrnSaver is passed correctly now, so greenclip builds again.
2021-06-03 00:40:43 +02:00
sternenseemann
29a8095f13 hackage-packages.nix: Regenerate based on current config
This commit has been generated by maintainers/scripts/haskell/regenerate-hackage-packages.sh

Main point here is to apply the new cabal2nix-unstable generation with
a libNixName entry for libXScrnSaver, so greenclip builds again.
2021-06-03 00:35:41 +02:00
(cdep)illabout
7c53004026 haskellPackages.cabal2nix-unstable: update to latest version from github
(cherry picked from commit 259177f109)
2021-06-03 00:30:40 +02:00
Maximilian Bosch
f365fa7c5e Merge pull request #125425 from NixOS/backport-124407-to-release-21.05
[Backport release-21.05] synapse: 1.34.0 -> 1.35.0
2021-06-03 00:22:45 +02:00
Michele Guerini Rocco
d0f1a29ed0 Merge pull request #125411 from NixOS/backport-125392-to-release-21.05
[Backport release-21.05] pdns-recursor: disable on i686-linux
2021-06-02 23:53:25 +02:00
Sumner Evans
3f68a16c3e synapse: 1.34.0 -> 1.35.0
(cherry picked from commit c6a546e996)
2021-06-02 21:46:19 +00:00
rnhmjoj
98f321b5bb pdns-recursor: disable on i686-linux
Support for 32-bit platforms with no 64-bit time_t has ended.
See https://mailman.powerdns.com/pipermail/pdns-users/2021-May/027220.html

(cherry picked from commit cbfd8831a1)
2021-06-02 18:52:06 +00:00
Johannes Schleifenbaum
424a8e18f5 pantalaimon: install manuals
(cherry picked from commit f42a1d9df5)
2021-06-02 18:00:01 +00:00
Eduardo Sánchez Muñoz
aedd9a2dc6 dr14_tmeter: use ffmpeg 4
migrate away from ffmpeg_3 (https://github.com/NixOS/nixpkgs/issues/120705)

(cherry picked from commit 0b32978596)
2021-06-02 19:40:46 +02:00
Robert Hensing
297970378b Merge pull request #125341 from hercules-ci/backport-podman-improvements
[Backport release-21.05] podman improvements
2021-06-02 18:23:15 +02:00
Robert Hensing
68e821b051 Merge pull request #125388 from NixOS/backport-125216-to-release-21.05
[Backport release-21.05] dockerTools: Fix passthru image tag
2021-06-02 17:19:19 +02:00
Martin Weinelt
bbdaa7f504 Merge pull request #125309 from NixOS/backport-124982-to-staging-21.05
[Backport staging-21.05] curl: add patches for CVE-2021-22897, CVE-2021-22898 & CVE-2021-22901
2021-06-02 17:12:13 +02:00
Robert Hensing
fc30ee8ce7 dockerTools: Fix passthru image tag
It should match the actual image tag.
This fixes the problem introduced in 00996b5e03
https://github.com/NixOS/nixpkgs/pull/115491#pullrequestreview-672789901

(cherry picked from commit ff55c41fac)
2021-06-02 15:02:31 +00:00
Martin Weinelt
bdf95a994e lasso: Fix signature verification in AuthnResponse messages
Fixes: CVE-2021-28091
2021-06-02 16:49:11 +02:00
Martin Weinelt
3308be986a Merge pull request #125344 from helsinki-systems/bkp/21.05/cacert 2021-06-02 15:47:27 +02:00
Andreas Rammhold
e2960f429b cacerts: Make updater script aware of the nss_latest attribute
Usually, on the stable channel, we have a nss_latest attribute that is
more up to date than the nss attribute (which is usually frozen during
branch-off and only receives security updates). Cacerts are a sensitive
matter and should be updated more frequently than the stable NSS package,
if required. By making the update script aware of the nss_latest
attribute we can prefer that when it exists.

By having this change in the unstable branch of Nixpgks we can carry it
from release to release without requiring more churn from those doing
the stable release maintenance.

(cherry picked from commit 4e318bcca1)
2021-06-02 15:17:44 +02:00
Michele Guerini Rocco
5285a51c2e Merge pull request #125368 from NixOS/backport-125289-to-release-21.05
[Backport release-21.05] qutebrowser: 2.2.2 -> 2.2.3
2021-06-02 14:54:51 +02:00
Vladimír Čunát
4b04e53f2a Merge branch 'staging-21.05' into release-21.05
It's a bit older version of the branch, as it has binaries from
https://hydra.nixos.org/eval/1674261
2021-06-02 13:59:29 +02:00
Robert Schütz
5b6ba9f492 python3Packages.adblock: fix build on Darwin
(cherry picked from commit 9f9de0069c)
2021-06-02 11:54:54 +00:00
Robert Schütz
22e2e017df qutebrowser: 2.2.2 -> 2.2.3
https://github.com/qutebrowser/qutebrowser/releases/tag/v2.2.3
(cherry picked from commit 29043644b0)
2021-06-02 11:54:54 +00:00
Thomas Depierre
0894deca29 beam-packages: drop erlang R18 R19 R20 and cuter
(cherry picked from commit f55c3e2f21)
2021-06-02 19:23:26 +09:00
Michele Guerini Rocco
5bf359c593 Merge pull request #125343 from NixOS/backport-124891-to-release-21.05
[Backport release-21.05] antimony: add desktop item
2021-06-02 11:38:05 +02:00
Jörg Thalheim
5dfad380ad containerd: fix checksum 2021-06-02 11:30:23 +02:00
ajs124
ffcb3c66fa cacert: 3.63 -> 3.66
mozilla says this is CA version 2.50, up from 2.48 in nss 3.63

(cherry picked from commit e579e93b65)
2021-06-02 10:55:51 +02:00
Robert Hensing
eaba7870ff Merge pull request #125338 from NixOS/backport-124494-to-release-21.05
[Backport release-21.05] dockerTools: Allow omitting all store paths
2021-06-02 10:22:59 +02:00
zowoq
0684f78698 nixos/podman-network-socket-ghostunnel: move condition to include socket
(cherry picked from commit 72f54c32a6)
2021-06-02 10:20:11 +02:00
Robert Hensing
eeefa0a65d podman: Add nixosTests.podman-dnsname to tests
(cherry picked from commit 1d781e5c80)
2021-06-02 10:20:11 +02:00
Robert Hensing
c758b69375 nixos/podman-dnsname: init
(cherry picked from commit 54f2f1e5f1)
2021-06-02 10:20:11 +02:00
Robert Hensing
9e4729617b nixos/podman: Add defaultNetwork.extraPlugins
(cherry picked from commit d81631fb98)
2021-06-02 10:20:11 +02:00
Robert Hensing
f28df17dfa nixos/containers: Add virtualisation.containers.containersConf.cniPlugins
(cherry picked from commit efba949352)
2021-06-02 10:20:11 +02:00
Robert Hensing
03e08759f7 dnsname-cni: Use wrapper instead of patch for dnsmasq
The patch proved to be an incomplete solution while developing
nixosTests.podman-dnsname

(cherry picked from commit 6517779349)
2021-06-02 10:20:11 +02:00
Robert Hensing
29ee113277 podman: Add iproute2, fixing docker network rm
(cherry picked from commit db31d8354d)
2021-06-02 10:20:11 +02:00
Robert Hensing
833b005e37 nixos/podman-network-socket-ghostunnel: init
(cherry picked from commit b6570e7238)
2021-06-02 10:20:10 +02:00
Robert Hensing
ffde2bb4a1 nixos/podman: Add generic networkSocket interface
(cherry picked from commit 52844efcd6)
2021-06-02 10:20:10 +02:00
Robert Hensing
0c5e6d0bea nixos/podman: Add dockerSocket.enable
(cherry picked from commit ff4d83a667)
2021-06-02 10:20:10 +02:00
Robert Hensing
db05ed8b0d nixos/podman: Change podman socket to new podman group
(cherry picked from commit fb8b0a3843)
2021-06-02 10:20:10 +02:00
zowoq
f63aff597b nixos/podman: install cni config from package
(cherry picked from commit 30ae7e4ba9)
2021-06-02 10:20:10 +02:00
zowoq
17ba99dd68 podman: install cni config
(cherry picked from commit fd59022ee9)
2021-06-02 10:20:10 +02:00
Nick Cao
0919b5c419 podman: add systemd to rpath
(cherry picked from commit ada45ac3ae)
2021-06-02 10:20:10 +02:00
Mark Vainomaa
d33aa3d0d3 dnsname-cni: init at 1.1.1
(cherry picked from commit 5826e90206)
2021-06-02 10:20:10 +02:00
Mark Vainomaa
73f566b2ad maintainers: add mikroskeem
(cherry picked from commit f830b000fc)
2021-06-02 10:20:10 +02:00
cwyc
508f877ab9 antimony: add desktop item
(cherry picked from commit b80463f8d5)
2021-06-02 08:18:16 +00:00
legendofmiracles
2d5507fcd1 matterbridge: 1.12.1 -> 1.12.2
(cherry picked from commit a08f23039c)
2021-06-02 08:18:02 +00:00
Greizgh
2234f20897 sqlx-cli: 0.5.2 -> 0.5.5
(cherry picked from commit d8c7fbe7616d40d1ee68c803660de4c4ae6770d9)
2021-06-02 08:10:23 +00:00
Robert Hensing
fb8409427c dockerTools: Allow omitting all store paths
Adds includeStorePaths, allowing the omission of the store paths.
You generally want to leave it on, but tooling may disable this
to insert the store paths more efficiently via other means, such
as bind mounting the host store.

(cherry picked from commit 5259d66b74)
2021-06-02 07:51:33 +00:00
Robert Hensing
2e0ff58c76 dockerTools: Format
(cherry picked from commit 69de7cc12a)
2021-06-02 07:51:32 +00:00
zowoq
32c5e04919 docker: add clientOnly / docker-client
Currently the docker client is only available on non-linux platforms as `docker`,
this makes the client available on linux and other platforms as `docker-client`.

(cherry picked from commit 7233acd515)
2021-06-02 09:14:21 +02:00
Martin Weinelt
8ab70f5edc firefox-esr: 78.10.1esr -> 78.11.0esr
https://www.mozilla.org/en-US/firefox/78.11.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2021-24/
(cherry picked from commit f42ea75dec)
2021-06-02 06:53:38 +00:00
Robert Scott
1e0edddaff curl: add patches for CVE-2021-22897, CVE-2021-22898 & CVE-2021-22901
(cherry picked from commit 742c60f6f8)
2021-06-02 00:35:37 +00:00
Martin Weinelt
bb8a5e5484 Merge pull request #125305 from NixOS/backport-125300-to-release-21.05
[Backport release-21.05] botamusique: unstable-2021-05-19 -> unstable-2021-06-01
2021-06-02 02:28:57 +02:00
Martin Weinelt
4a2d2ac6f1 botamusique: unstable-2021-05-19 -> unstable-2021-06-01
(cherry picked from commit dbb7e6bc8a)
2021-06-02 00:00:06 +00:00
Robert Scott
1c1eefa5e6 Merge pull request #125219 from NixOS/backport-125178-to-release-21.05
[Backport release-21.05] deno: 1.10.2 -> 1.10.3
2021-06-02 00:17:53 +01:00
Robert Scott
adfdebe96c Merge pull request #125277 from NixOS/backport-125148-to-release-21.05
[Backport release-21.05] stagit: 0.9.5 → 0.9.6
2021-06-01 22:37:25 +01:00
Sebastian Sellmeier
63cb180895 sane-airscan: 0.99.24 -> 0.99.26
(cherry picked from commit 19120ab497)
2021-06-01 20:54:37 +00:00
Robert Scott
5237039cc1 Merge pull request #125230 from NixOS/backport-124603-to-release-21.05
[Backport release-21.05] php.buildPecl: Add checkPhase
2021-06-01 21:00:19 +01:00
Kevin Rauscher
cd1db1c857 metals: 0.10.3 -> 0.10.4
(cherry picked from commit 7c6cfaa13c)
2021-06-01 19:16:47 +00:00
Nikolay Korotkiy
1e15757384 stagit: 0.9.5 → 0.9.6
(cherry picked from commit dd068ab0e0)
2021-06-01 19:16:34 +00:00
Michele Guerini Rocco
3e45cf0eec Merge pull request #125269 from NixOS/backport-125245-to-release-21.05
[Backport release-21.05] warzone2100: fix build
2021-06-01 21:02:38 +02:00
Robert Scott
7c1d76fbeb Merge pull request #125126 from NixOS/backport-125111-to-release-21.05
[Backport release-21.05] lua5_4: 5.4.2 -> 5.4.3
2021-06-01 19:44:38 +01:00
Robert Scott
0c988f04d7 Merge pull request #125249 from NixOS/backport-124995-to-release-21.05
[Backport release-21.05] ijq: 0.2.3 → 0.3.4
2021-06-01 19:38:40 +01:00
Robert Scott
6f38e99a9e Merge pull request #125248 from NixOS/backport-124986-to-release-21.05
[Backport release-21.05] libccd: fix pkgconfig file paths
2021-06-01 19:32:36 +01:00
Anders Kaseorg
c3e7192dd5 gnomeExtensions: allowAliases should default to true if unset
Make this use of config.allowAliases consistent with every other use
in the tree.

Signed-off-by: Anders Kaseorg <andersk@mit.edu>
(cherry picked from commit 4f0cf23ea3)
2021-06-01 18:30:44 +00:00
rnhmjoj
047b146b74 warzone2100: fix build
I'm not sure how the build broke[1] or how it worked before, but
the problem is zip is being used in place of p7zip, which obviously
fail as the flags have different meanings.

[1]: https://hydra.nixos.org/build/143354937

(cherry picked from commit 302d6b1b8b)
2021-06-01 18:19:01 +00:00
davidak
890d9c809c Merge pull request #125143 from NixOS/backport-124971-to-staging-21.05
[Backport staging-21.05] kbd: patch paths to decompressors
2021-06-01 20:06:53 +02:00
Robert Scott
dbfaab83a8 Merge pull request #125247 from NixOS/backport-124996-to-release-21.05
[Backport release-21.05] schismtracker: 20200412 -> 20210525
2021-06-01 18:13:16 +01:00
Sebastian Sellmeier
cc8409db5c usbutils: 012 -> 013
(cherry picked from commit bafd47b370)
2021-06-01 16:40:07 +00:00
Sandro
790d9970f1 Update pkgs/development/libraries/editline/default.nix
(cherry picked from commit c9149241a0abbfadfb9fc9b26b0bd539e47f7da0)
2021-06-01 16:35:31 +00:00
oxalica
d9a0f81c7d editline: add patch to fix Home and End key in tmux
`nix repl` is affected by this usability issue.

(cherry picked from commit f0d26341adad9207d57edbb80736126ba2a295f2)
2021-06-01 16:35:31 +00:00
oxalica
cc59369933 editline: 1.17.0 -> 1.17.1
(cherry picked from commit c63268512b513cc31b2c55376245d9d8d1f0099a)
2021-06-01 16:35:30 +00:00
Jan Tojnar
cd3aba49e9 ijq: 0.2.3 → 0.3.4
https://github.com/gpanders/ijq/compare/v0.2.3...v0.3.4
(cherry picked from commit 691a876749de1029f150b3ff7e23cf92403510a4)
2021-06-01 16:06:36 +00:00
Ben Wolsieffer
8c6a3a60e5 libccd: fix pkgconfig file paths
libccd has the common bug of assuming CMAKE_INSTALL_*DIR is relative. I have
submitted the fix upstream, but don't have much hope of getting it merged
because there have been no updates since 2018.

(cherry picked from commit 3d2092ab58)
2021-06-01 16:06:26 +00:00
Pavol Rusnak
0121624e3b schismtracker: 20200412 -> 20210525
(cherry picked from commit 20b1b6e68b)
2021-06-01 16:06:24 +00:00
Dmitry Ivankov
12fa8699c3 bazel_4: 4.0.0 -> 4.1.0
https://github.com/bazelbuild/bazel/releases/tag/4.1.0

other minor changes:
- grep for /bin/ rather than /bin for blanket substitute
- invoke {pre,post}{Build,Install} hooks

(cherry picked from commit a15204fcc0)
2021-06-01 16:03:08 +00:00
Fabian Affolter
e2e4a34717 Merge pull request #125229 from NixOS/backport-125225-to-release-21.05
[Backport release-21.05] changelog: fix typo
2021-06-01 17:30:36 +02:00
Robert Scott
71de7777c2 Merge pull request #125164 from NixOS/backport-125160-to-release-21.05
[Backport release-21.05] delve: disable source fortify at runtime
2021-06-01 16:15:30 +01:00
R. RyanTM
b17110e2de brave: 1.24.86 -> 1.25.68
(cherry picked from commit f625036c9e)
2021-06-01 14:43:02 +00:00
Marco Sirabella
89e61ccf69 php.buildPecl: Add checkPhase
Also update phpPackages' to use NO_INTERACTION

(cherry picked from commit 3a66432f26)
2021-06-01 14:38:16 +00:00
Sandro
d790395393 changelog: fix typo
(cherry picked from commit 8217ea5000)
2021-06-01 14:36:54 +00:00
Robert Scott
37b13b3d08 Merge pull request #125226 from NixOS/backport-124892-to-release-21.05
[Backport release-21.05] yara: 4.0.5 -> 4.1.1
2021-06-01 15:34:44 +01:00
Vladimír Čunát
9660a9f481 Merge #125185: zstd: patch test flakiness on i686 2021-06-01 16:09:50 +02:00
Shea Levy
cf0f4ade63 Merge branch 'discord-backport' into release-21.05 2021-06-01 10:04:41 -04:00
Robert Scott
abc7f8ee12 yara: add enableStatic mode
useful because tests can be enabled in this mode

(cherry picked from commit 8cda1cc59e)
2021-06-01 14:02:39 +00:00
Robert Scott
529b6eee47 yara: 4.0.5 -> 4.1.1
(cherry picked from commit 2d7f554229)
2021-06-01 14:02:39 +00:00
Sandro
79b7348294 Merge pull request #124818 from NixOS/backport-124200-to-release-21.05 2021-06-01 15:41:32 +02:00
Julien Moutinho
437b2bfe18 nixos/pam: use new plasma5Packages, fixes #124973
(cherry picked from commit 61654ca131)
2021-06-01 13:30:11 +00:00
Daniel Nagy
4d837a7a98 nixos/monero: set port type to types.port
(cherry picked from commit e57465a617)
2021-06-01 13:15:25 +00:00
Daniel Nagy
ab496da138 nixos/gitlab: set port type to types.port
(cherry picked from commit cc5517da4c)
2021-06-01 13:15:25 +00:00
Daniel Nagy
28e57cb0c7 nixos/matrix-synapse: set port type to types.port
(cherry picked from commit 8e760f4858)
2021-06-01 13:15:24 +00:00
Daniel Nagy
fda7b06830 nixos/syncserver: set port type to types.port
(cherry picked from commit 65b32a0afe)
2021-06-01 13:15:24 +00:00
Daniel Nagy
2c97740c47 nixos/gitDaemon: set port type to types.port
(cherry picked from commit 048c45679f)
2021-06-01 13:15:24 +00:00
Daniel Nagy
98d6d1dbf7 nixos/redis: set port type to types.port
(cherry picked from commit 0cde374a76)
2021-06-01 13:15:24 +00:00
Daniel Nagy
d71b353d15 nixos/discourse: set port type to types.port
(cherry picked from commit 73f9c29a2c)
2021-06-01 13:15:24 +00:00
Daniel Nagy
24e35b8c44 nixos/terraria: adapt option types
(cherry picked from commit 137924cc96)
2021-06-01 13:15:24 +00:00
Daniel Nagy
33ce03a653 nixos/lighttpd: set port type to types.port
(cherry picked from commit 941fd008ed)
2021-06-01 13:15:23 +00:00
Daniel Nagy
dad9958503 nixos/darkhttpd: set port type to types.port
(cherry picked from commit a5321aecfb)
2021-06-01 13:15:23 +00:00
R. RyanTM
0462a6da7a deno: 1.10.2 -> 1.10.3
(cherry picked from commit c89224c2d3)
2021-06-01 13:06:32 +00:00
Kerstin Humm
705afa0294 haskellPackages.webify: unbreak, jailbreak, as patches are not upstreamable atm
(cherry picked from commit b401b43209)
2021-06-01 13:36:02 +02:00
Kerstin Humm
a87958a49d haskellPackages.hakyll: unbreak, jailbreak, patch for pandoc version
(cherry picked from commit 8f33bb975d)
2021-06-01 13:35:40 +02:00
Jonathan Ringer
a1d551b23b discord: fix runtime linking
(cherry picked from commit c5bed409b2)
2021-06-01 07:34:28 -04:00
wearemnr
803502aaae discord: 0.0.14 -> 0.0.15
(cherry picked from commit 501e54080d)
2021-06-01 07:34:18 -04:00
Jörg Thalheim
3182caa035 Merge pull request #125173 from NixOS/backport-125158-to-release-21.05
[Backport release-21.05] radare2: 5.2.1 -> 5.3.0
2021-06-01 13:13:11 +02:00
Vladimír Čunát
cb58ba1c55 zstd: patch test flakiness on i686
https://hydra.nixos.org/build/143933617/nixlog/246/tail
The last attempt I see on 21.05 has failed:
https://hydra.nixos.org/build/144447049#tabs-buildsteps
2021-06-01 11:22:50 +02:00
Sandro
4eb41db7d8 Merge pull request #124595 from mohe2015/backport-124347-21.05 2021-06-01 10:01:00 +02:00
Jörg Thalheim
9d541e4a1e Merge pull request #125175 from NixOS/backport-125174-to-release-21.05
[Backport release-21.05] nginx: fix link to discussion explaining why "with" is not used
2021-06-01 09:38:28 +02:00
Vonfry
fbc09eb843 zsh-completions: 0.32.0 -> 0.33.0
(cherry picked from commit f777cb75fb)
2021-06-01 07:30:59 +00:00
Vincent Bernat
4718cb50f5 nginx: fix link to discussion explaining why "with" is not used
This is because we are in a huge "rec" that takes precedence for
symbols in its scope, despite the more nested "with".

(cherry picked from commit 7ee8945a12)
2021-06-01 07:30:28 +00:00
Jörg Thalheim
25ffebcb62 radare2: 5.2.1 -> 5.3.0
(cherry picked from commit bfaa9f175b)
2021-06-01 07:17:08 +00:00
Jörg Thalheim
739359e2c6 Merge pull request #125055 from NixOS/backport-124544-to-release-21.05
[Backport release-21.05] vmTools: update current lts versions of ubuntu/debian
2021-06-01 08:14:50 +02:00
Jörg Thalheim
c5a8c12866 Update pkgs/development/tools/delve/default.nix
Co-authored-by: Dmitry Kalinkin <dmitry.kalinkin@gmail.com>
(cherry picked from commit c9927ba895)
2021-06-01 06:10:02 +00:00
Jörg Thalheim
58301adb35 delve: disable source fortify at runtime
(cherry picked from commit b48e56c746)
2021-06-01 06:10:02 +00:00
Damien Diederen
d300b598da nixos/lib/make-ext4-fs: Fix: `resize2fs -M' can leave insufficient slack
The root filesystem resizing step, `resize2fs -M', does not provide any
control over the amount of slack left in the result.  It can produce an
arbitrarily tight fit, depending on how well the payload aligns with
ext4 data structures.

This is problematic, as NixOS must create a few files and directories
during its first boot, before the root is enlarged to match the size of
the containing SD card.

An overly tight fit can cause failures in the first stage:

    mkdir: can't create directory '/mnt-root/proc': No space left on device

or in the second stage:

    install: cannot create directory '/var': No space left on device

A previous version of `make-ext4-fs' (before PR #79368) was explicitly
"reserving" 16 MiB of free space in the final filesystem.  Manually
calculating the size of an ext4 filesystem is a perilous endeavor,
however, and the method it employed was apparently unreliable.

Reverting is consequently not a good option.

A solution would be to create some sort of "balloon" occupying inodes
and blocks in the image prior to invoking `resize2fs -M', and to remove
these temporary files/directories before the compression step.

This changeset takes the simpler approach of simply dropping the
resizing step.

Note that this does *not* result in a larger image in general, as the
current procedure does not truncate the `.img' file anyway.  In fact, it
has been observed to yield *smaller* compressed images---probably
because of some "noise" left after resizing.  E.g., before-vs-after:

    -r--r--r-- 2 root root 607M  1. Jan 1970  nixos-sd-image-21.11pre-git-x86_64-linux.img.zst

    -r--r--r-- 2 root root 606M  1. Jan 1970  nixos-sd-image-21.11pre-git-x86_64-linux.img.zst

(cherry picked from commit 7c2adb1d5c)
2021-06-01 04:58:07 +00:00
Jonathan Ringer
7e9b0dff97 nixos/release-notes: move non-highlights to other mentions
(cherry picked from commit 9a3e8699976bd673f9f4eee64e254ccb7a1fadce)
2021-05-31 20:06:55 -07:00
Jonathan Ringer
a8eeea419e nixos/release-notes: Initial grooming of release notes
(cherry picked from commit f15d286aaca6f7bd9f246c72978992ea8bb73e63)
2021-05-31 20:06:55 -07:00
Jonathan Ringer
9e2c334e52 nixos/doc/releases: update stable release info to 21.05
(cherry picked from commit 545ba18df2ca2077d6c1a69e02648ad88dd5d968)
2021-05-31 20:06:32 -07:00
Konstantin Alekseev
7f0f0b2807 sqlite: 3.35.2 -> 3.35.5
(cherry picked from commit 3c1bcd240bb437680b69775d5c324449a02dd135)
2021-05-31 18:19:48 -07:00
Martin Weinelt
66959b52fd firefox: 88.0.1 -> 89.0
https://www.mozilla.org/en-US/firefox/89.0/releasenotes/
(cherry picked from commit bcc35ef63f)
2021-06-01 03:04:54 +02:00
oxalica
a9f685005e nixos/tests/kbd-setfont-decompress: init
(cherry picked from commit 7fb927c9e5)
2021-06-01 00:13:53 +00:00
oxalica
b35b0a5f04 kbd: patch paths to decompressors
(cherry picked from commit 449132738d)
2021-06-01 00:13:53 +00:00
Gabriel Volpe
a6a62cb3b4 dconf2nix: 0.0.7 -> 0.0.8
(cherry picked from commit 4ea29081fb)
2021-06-01 00:04:48 +00:00
taku0
4b2920f7d7 firefox-bin: 88.0.1 -> 89.0
(cherry picked from commit bb2070754c)
2021-05-31 23:45:16 +00:00
Martin Weinelt
05a82f0f46 rust-cbindgen_latest: init at 0.19.0 2021-06-01 01:25:19 +02:00
Martin Weinelt
3a2e0c36e7 Merge pull request #125134 from NixOS/backport-124950-to-release-21.05
[Backport release-21.05] nixos/acme: don't use --reuse-key
2021-06-01 01:17:42 +02:00
Vincent Bernat
cbe0e663ec nixos/acme: don't use --reuse-key
Reusing the same private/public key on renewal has two issues:

 - some providers don't accept to sign the same public key
   again (Buypass Go SSL)

 - keeping the same private key forever partly defeats the purpose of
   renewing the certificate often

Therefore, let's remove this option. People wanting to keep the same
key can set extraLegoRenewFlags to `[ --reuse-key ]` to keep the
previous behavior. Alternatively, we could put this as an option whose
default value is true.

(cherry picked from commit 632c8e1d54)
2021-05-31 23:02:21 +00:00
Jonathan Ringer
75f90eedcf Merge pull request #124341 from NixOS/staging-next-21.05
[21.05] Staging next
2021-05-31 13:50:08 -07:00
Janne Heß
f2cabb18e0 lua5_4: 5.4.2 -> 5.4.3
(cherry picked from commit 490970ae8b34107aa5e092629271ac7739407478)
2021-05-31 20:25:03 +00:00
Jonathan Ringer
7b601ada77 Merge remote-tracking branch 'origin/release-21.05' into staging-next-21.05 2021-05-31 12:44:56 -07:00
Martin Weinelt
0c2e856ea0 Merge pull request #125094 from NixOS/backport-124446-to-release-21.05
[Backport release-21.05] weechatScripts.wee-slack: 2.7.0 -> 2.8.0
2021-05-31 18:53:03 +02:00
Robert Scott
1c27669fea Merge pull request #125045 from NixOS/backport-124802-to-release-21.05
[Backport release-21.05] tilt: 0.18.10 -> 0.20.5
2021-05-31 17:50:30 +01:00
Robert Scott
ab98a6e109 Merge pull request #125057 from NixOS/backport-124730-to-release-21.05
[Backport release-21.05] morph: 1.5.0 -> 1.6.0
2021-05-31 15:53:49 +01:00
Robert Scott
1293a26299 Merge pull request #125058 from NixOS/backport-124762-to-release-21.05
[Backport release-21.05] tailscale: 1.8.5 -> 1.8.6
2021-05-31 15:48:02 +01:00
Robert Scott
cdf6c6106b Merge pull request #125056 from NixOS/backport-124702-to-release-21.05
[Backport release-21.05] fioctl: 0.16 -> 0.17
2021-05-31 15:42:31 +01:00
Martin Weinelt
9bbf2ec131 weechatScripts.wee-slack: 2.7.0 -> 2.8.0
https://github.com/wee-slack/wee-slack/releases/tag/v2.8.0
(cherry picked from commit d7de7087fc)
2021-05-31 14:21:13 +00:00
Maximilian Bosch
9130b8c465 Merge pull request #125085 from NixOS/backport-125066-to-release-21.05
[Backport release-21.05] radare2: add patch for CVE-2021-32613
2021-05-31 16:03:49 +02:00
Maximilian Bosch
aa9f441226 radare2: add patch for CVE-2021-32613
Closes #124670
See also https://nvd.nist.gov/vuln/detail/CVE-2021-32613

(cherry picked from commit 16ce969340)
2021-05-31 13:00:34 +00:00
Robert Scott
ef423b1205 Merge pull request #125060 from NixOS/backport-124791-to-release-21.05
[Backport release-21.05] v2ray: 4.38.3 -> 4.39.2
2021-05-31 13:54:15 +01:00
Robert Scott
c87afd2553 Merge pull request #125061 from NixOS/backport-124771-to-release-21.05
[Backport release-21.05] libxlsxwriter: 1.0.5 -> 1.0.6
2021-05-31 13:43:22 +01:00
Robert Scott
a8b758696c Merge pull request #125064 from NixOS/backport-125007-to-release-21.05
[Backport release-21.05] postgresqlPackages.pg_partman: 4.4.1 -> 4.5.1
2021-05-31 12:36:58 +01:00
Robert Scott
9ad5d4d363 postgresqlPackages.pg_partman: 4.4.1 -> 4.5.1
addressing CVE-2021-33204

(cherry picked from commit 29b5264841)
2021-05-31 10:48:29 +00:00
Michael Weiss
cbd00766e4 Merge pull request #125054 from NixOS/backport-124957-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 90.0.4430.212 -> 91.0.4472.77
2021-05-31 12:27:56 +02:00
Robert Schütz
6cac8dd5d9 libxlsxwriter: 1.0.5 -> 1.0.6
https://github.com/jmcnamara/libxlsxwriter/releases/tag/RELEASE_1.0.6
(cherry picked from commit 5d873fde23)
2021-05-31 10:15:28 +00:00
Serval
41734b6851 v2ray: 4.38.3 -> 4.39.2
(cherry picked from commit c6f2290810)
2021-05-31 10:15:02 +00:00
蛇崩乃音
8479c43fa2 tailscale: 1.8.3 -> 1.8.5
(cherry picked from commit 57f67a8ec0)
2021-05-31 10:09:03 +00:00
Sandro
556951a923 Merge pull request #124796 from risicle/ris-hdbscan-disable-another-flaky-test-r21.05
[21.05] python3Packages.hdbscan: disable another flaky test
2021-05-31 12:08:48 +02:00
Thomas Gerbet
b9fd21fe40 morph: 1.5.0 -> 1.6.0
https://github.com/DBCDK/morph/releases/tag/v1.6.0
(cherry picked from commit 03465e588b)
2021-05-31 10:07:32 +00:00
matthewcroughan
7ca8def3b9 fioctl: 0.16 -> 0.17
(cherry picked from commit 005f0008a7)
2021-05-31 10:01:13 +00:00
Jörg Thalheim
81136a1c96 vmTools: update current maintained debian versions
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit eb0034927d)
2021-05-31 09:57:31 +00:00
Jörg Thalheim
11cd670ca0 vmTools: update current lts versions of ubuntu
(cherry picked from commit e71c4f4628)
2021-05-31 09:57:31 +00:00
Michael Weiss
2127c48d06 ungoogled-chromium: 90.0.4430.212 -> 91.0.4472.77
(cherry picked from commit 6c638ee6b1)
2021-05-31 09:51:05 +00:00
Maximilian Bosch
d25ea6a0d2 Merge pull request #125048 from NixOS/backport-124960-to-release-21.05
[Backport release-21.05] neomutt: add patch for CVE-2021-32055
2021-05-31 10:23:40 +02:00
Robert Scott
ad8e636a3e neomutt: add patch for CVE-2021-32055
no upstream release yet

(cherry picked from commit edcde75b98)
2021-05-31 08:07:35 +00:00
David Birks
a30a33bbff tilt: 0.18.10 -> 0.20.5
(cherry picked from commit 2aa7662279)
2021-05-31 07:20:30 +00:00
Sandro
3b7c820173 Merge pull request #124927 from NixOS/backport-124211-to-release-21.05
[Backport release-21.05] betterdiscordctl: 1.7.1 -> 2.0.0
2021-05-31 09:13:58 +02:00
SCOTT-HAMILTON
91efaf3393 libiio: fix build with wrong libxml2 find_package
Co-authored-by: Dmitry Kalinkin <dmitry.kalinkin@gmail.com>
(cherry picked from commit 660c4a822c)
2021-05-31 02:40:27 -04:00
Jörg Thalheim
3018bf4b9e Merge pull request #125015 from NixOS/backport-94881-to-release-21.05
[Backport release-21.05] mblaze: fix mcom to use file utility.
2021-05-31 08:24:56 +02:00
Maxine Aubrey
6ce4fb99f4 plex: 1.23.0.4482-62106842a -> 1.23.1.4602-280ab6053
(cherry picked from commit 2c988b6132)
2021-05-31 01:09:34 +00:00
guillaumecherel
aa2efdf901 Update pkgs/applications/networking/mailreaders/mblaze/default.nix
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit 1e777e5ef02c89594bb1d2b772417df0ee176dcf)
2021-05-31 01:01:49 +00:00
guillaumecherel
ebdf00f038 Update pkgs/applications/networking/mailreaders/mblaze/default.nix
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
(cherry picked from commit e9d4b68fdc43af8e85868ae589eda51ce088c3e8)
2021-05-31 01:01:49 +00:00
Guillaume Chérel
7f016e24c7 Wrap mcom to add dependencies to PATH.
(cherry picked from commit 6dde14306092e81b58fc9b2b9082d138ab311cd8)
2021-05-31 01:01:48 +00:00
Sandro
a2e86da944 Merge pull request #124984 from NixOS/backport-124980-to-release-21.05
[Backport release-21.05] sageWithDoc: fix documentation symlinks
2021-05-31 03:00:57 +02:00
Tobias Happ
0699e902e6 teamspeak_server: add missing runHook commands
(cherry picked from commit 88b0d669e470b35399c1c0d226f8c42ff6aab55b)
2021-05-31 00:59:43 +00:00
Tobias Happ
b6951a764a teamspeak_server: 3.13.3 -> 3.13.5
(cherry picked from commit d0773a3c1fe74a85e8e0c9624d363fa69091b9c7)
2021-05-31 00:59:43 +00:00
Tobias Happ
c60da1cb0d teamspeak_server: fix updateScript
(cherry picked from commit 18f28923c6dd34aec04ca95ebeb2384fe9249db3)
2021-05-31 00:59:43 +00:00
Sandro
0a28f8dc51 Merge pull request #125009 from NixOS/backport-124851-to-release-21.05 2021-05-31 02:59:00 +02:00
Justin Bedo
71499e0374 singularity: 3.7.3 -> 3.7.4
(cherry picked from commit 044ba9b560)
2021-05-31 00:57:49 +00:00
Dmitry Kalinkin
b0e7f01080 arrow-cpp: 4.0.0 -> 4.0.1
(cherry picked from commit cff04883e8)
2021-05-31 00:02:29 +00:00
github-actions[bot]
fc924fc34e xfitter: remove hardeningDisable = [ "format" ]; (#125001)
Not needed after f42aa7e1 ('cc-wrapper: set FC when langFortran is on')

(cherry picked from commit b72b3c5571)

Co-authored-by: Dmitry Kalinkin <dmitry.kalinkin@gmail.com>
2021-05-30 19:13:01 -04:00
Robert Scott
478f5d49f6 Merge pull request #124994 from NixOS/backport-124455-to-release-21.05
[Backport release-21.05] schismtracker: fix darwin build
2021-05-30 23:58:36 +01:00
Sandro
c91f853b0d Merge pull request #124998 from NixOS/backport-124111-to-release-21.05
[Backport release-21.05] python3Packages.drf-jwt: 1.19.0 -> 1.19.1
2021-05-31 00:56:59 +02:00
Robert Schütz
76fcaa085f python3Packages.drf-jwt: 1.19.0 -> 1.19.1
https://github.com/Styria-Digital/django-rest-framework-jwt/blob/1.19.1/CHANGELOG.md
(cherry picked from commit ffa6f1573c)
2021-05-30 22:30:33 +00:00
Stéphan Kochen
a2f6fc7092 schismtracker: fix darwin build
(cherry picked from commit e649cfc1e9)
2021-05-30 21:39:59 +00:00
Robert Scott
07ca3a021f Merge pull request #124953 from NixOS/backport-124732-to-release-21.05
[Backport release-21.05] icinga2: 2.12.3 -> 2.12.4
2021-05-30 22:27:51 +01:00
Robert Scott
ec2d3871f7 Merge pull request #124970 from NixOS/backport-124457-to-release-21.05
[Backport release-21.05] ocamlPackages.tyxml: 4.4.0 → 4.5.0
2021-05-30 22:24:56 +01:00
markuskowa
a027e1fa05 Merge pull request #124985 from NixOS/backport-124952-to-release-21.05
[Backport release-21.05] halide: Fix build
2021-05-30 20:59:09 +02:00
Vladimír Čunát
013a9ad03b Merge branch 'release-21.05' into staging-21.05 2021-05-30 20:21:58 +02:00
Christian Kögler
cd8efe13e0 halide: Fix build
(cherry picked from commit ba677b14dd)
2021-05-30 18:13:07 +00:00
Mauricio Collares
1834af74e3 sageWithDoc: fix documentation symlinks
(cherry picked from commit 2c7d2ce295)
2021-05-30 18:02:11 +00:00
Robert Scott
0e2b7ebdde Merge pull request #124822 from NixOS/backport-124792-to-release-21.05
[Backport release-21.05] b3sum: 0.3.7 -> 0.3.8
2021-05-30 17:32:04 +01:00
TredwellGit
35b4a78d9a lz4: patch CVE-2021-3520 and null pointer dereference
(cherry picked from commit 2acd087dca)
2021-05-30 16:06:32 +00:00
Robert Scott
a74605831e Merge pull request #124830 from NixOS/backport-124065-to-release-21.05
[Backport release-21.05] bjumblr: 1.4.2 -> 1.6.6
2021-05-30 16:24:28 +01:00
Robert Scott
439b6d5c2c Merge pull request #124825 from NixOS/backport-124784-to-release-21.05
[Backport release-21.05] corerad: 0.3.0 -> 0.3.1
2021-05-30 16:22:25 +01:00
Martin Weinelt
4cd3fd238d Merge pull request #124968 from NixOS/backport-124947-to-release-21.05 2021-05-30 17:21:40 +02:00
Robert Scott
95d4bdbaae Merge pull request #124832 from NixOS/backport-124109-to-release-21.05
[Backport release-21.05] tellico: 3.4 -> 3.4.1
2021-05-30 16:21:01 +01:00
Ulrik Strid
e3a1e350ba ocamlPackages.tyxml: 4.4.0 → 4.5.0
(cherry picked from commit 3fcd7a46dc4576f65c7bcd13ee12a71a456df904)
2021-05-30 15:05:47 +00:00
Janne Heß
4f9eadefdc Update nixos/modules/virtualisation/libvirtd.nix
Co-authored-by: Martin Weinelt <mweinelt@users.noreply.github.com>
(cherry picked from commit 964fc7cfef)
2021-05-30 14:56:41 +00:00
Janne Heß
c072a18797 nixos/libvirtd: Take ethertypes from iptables-nftables-compat
iptables is currently defined in `all-packages.nix` to be
iptables-compat. That package does however not contain `ethertypes`.
Only `iptables-nftables-compat` contains this file so the symlink
dangles.

(cherry picked from commit 2eeecef3fc)
2021-05-30 14:56:41 +00:00
Robert Scott
0c39e877ec Merge pull request #124908 from NixOS/backport-124859-to-release-21.05
[Backport release-21.05] python3Packages.smhi-pkg: 1.0.14 -> 1.0.15
2021-05-30 14:42:15 +01:00
Robert Scott
ab9f3f2f9e Merge pull request #124922 from NixOS/backport-124911-to-release-21.05
[Backport release-21.05] catgirl: 1.7 -> 1.8
2021-05-30 13:54:29 +01:00
Robert Scott
9fd05bb58f Merge pull request #124937 from NixOS/backport-124066-to-release-21.05
[Backport release-21.05] Gxplugins-Lv2: 0.8 -> 0.9
2021-05-30 13:51:08 +01:00
Robert Scott
d9df705215 Merge pull request #124933 from NixOS/backport-124575-to-release-21.05
[Backport release-21.05] goattracker,goattracker-stereo: 2.75 -> 2.76, 2.76 -> 2.77
2021-05-30 13:39:13 +01:00
Robert Scott
6ca456a1c9 Merge pull request #124934 from NixOS/backport-124325-to-release-21.05
[Backport release-21.05] babashka: 0.4.1 -> 0.4.3
2021-05-30 13:30:34 +01:00
R. RyanTM
2afcd85748 icinga2: 2.12.3 -> 2.12.4
(cherry picked from commit 5be9a1d161)
2021-05-30 12:30:25 +00:00
Robert Scott
a33878b687 Merge pull request #124930 from NixOS/backport-124222-to-release-21.05
[Backport release-21.05] kooha: 1.1.3 -> 1.2.1
2021-05-30 12:52:07 +01:00
Robert Scott
07796133d4 Merge pull request #124931 from NixOS/backport-124904-to-release-21.05
[Backport release-21.05] gitRepo: 2.14.5 -> 2.15.3
2021-05-30 12:49:41 +01:00
Robert Scott
bae3f3be2a Merge pull request #124928 from NixOS/backport-124713-to-release-21.05
[Backport release-21.05] getdata: add security patch from Debian
2021-05-30 12:46:21 +01:00
Robert Scott
60c22bd341 Merge pull request #124929 from NixOS/backport-124918-to-release-21.05
[Backport release-21.05] newsflash: fix build
2021-05-30 12:44:32 +01:00
Robert Scott
2063939edd Merge pull request #124940 from NixOS/backport-124351-to-release-21.05
[Backport release-21.05] sacad: 2.3.4 -> 2.4.0
2021-05-30 12:33:13 +01:00
Michele Guerini Rocco
c399b0f178 Merge pull request #124946 from NixOS/backport-123253-to-release-21.05
[Backport release-21.05] vapoursynth: improve plugin dependency resolution
2021-05-30 11:31:35 +02:00
Kim Lindberger
4c4a45e284 Merge pull request #124945 from NixOS/backport-124472-to-release-21.05
[Backport release-21.05] keycloak: 13.0.0 -> 13.0.1
2021-05-30 10:47:01 +02:00
Robert Schütz
f63370194e Merge pull request #124926 from NixOS/backport-124874-to-release-21.05
[Backport release-21.05] pika-backup: 0.3.1 -> 0.3.2
2021-05-30 10:40:04 +02:00
markuskowa
3d7ced7b59 Merge pull request #124923 from NixOS/backport-124893-to-release-21.05
[Backport release-21.05] welle-io: 2.2 -> 2.3
2021-05-30 10:37:47 +02:00
Simon Bruder
bad208a3e6 vapoursynth: improve plugin dependency resolution
Some python packages (e.g. functools32) are conditionally disabled for
certain interpreter versions by having them return null instead of a
derivation. `getRecursivePropagatedBuildInputs` fails if such a package
is part of the dependency tree. This commit makes it only recurse into
derivations and ignore everything else.

This also deduplicates the final plugin list to improve startup time.

(cherry picked from commit 9b3a2e66b1)
2021-05-30 08:26:24 +00:00
R. RyanTM
b3197b1334 keycloak: 13.0.0 -> 13.0.1
(cherry picked from commit 153eed5204)
2021-05-30 07:41:53 +00:00
Robert Schütz
e3ddcfdf2c capture: use ffmpeg instead of ffmpeg_3
(cherry picked from commit 36f7a012b7)
2021-05-29 23:58:51 -04:00
Sandro
2a0ab9f511 Merge pull request #124924 from NixOS/backport-124898-to-release-21.05
[Backport release-21.05] gotty: 2.0.0-alpha.3 -> 1.2.0
2021-05-30 05:29:23 +02:00
fortuneteller2k
0659aeb14f sacad: 2.3.4 -> 2.4.0
(cherry picked from commit 753452f808)
2021-05-30 03:20:42 +00:00
Sandro
04d804d0ab Merge pull request #124932 from NixOS/backport-124920-to-release-21.05
[Backport release-21.05] twine: add top-level entry
2021-05-30 05:07:27 +02:00
Bart Brouns
9b98f80829 Gxplugins-Lv2: 0.8 -> 0.9
(cherry picked from commit a9c375563e)
2021-05-30 02:32:21 +00:00
239
32153b7d59 bitwarden: 1.24.6 -> 1.26.4
(cherry picked from commit cdffcc9048)
2021-05-30 02:30:30 +00:00
Thiago Kenji Okada
e04a17a37e babashka: add thiagokokada as maintainer
(cherry picked from commit 9eee935ec232fffeda4917dba800967cf222eb0c)
2021-05-30 02:30:26 +00:00
Thiago Kenji Okada
20387998ce babashka: 0.4.1 -> 0.4.3
(cherry picked from commit 113fc7d71c1797983b4f3c40cf470befacb7fc04)
2021-05-30 02:30:26 +00:00
Francesco Gazzetta
0557b7bfb1 goattracker,goattracker-stereo: 2.75 -> 2.76, 2.76 -> 2.77
(cherry picked from commit 70dc16dec8)
2021-05-30 02:29:54 +00:00
Sandro
52223c3d1d Merge pull request #124827 from NixOS/backport-124685-to-release-21.05
[Backport release-21.05] terraria-server: 1.4.2.2 -> 1.4.2.3
2021-05-30 04:23:30 +02:00
Sandro Jäckel
c99249df0f twine: add top-level entry
(cherry picked from commit 166e67b4de)
2021-05-30 02:20:11 +00:00
Otavio Salvador
1f6295e555 gitRepo: Add updateScript support for easier upgrade in future
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit ee498167d0f1d4825baa0d7d6f98bb7424db19e8)
2021-05-30 02:20:06 +00:00
Otavio Salvador
042c54b758 gitRepo: add missing preInstall and postInstall hooks calls
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit 9d161bd45c40168a8aa83667fa4bf1b600ccc262)
2021-05-30 02:20:06 +00:00
Otavio Salvador
a5a6efd9b4 gitRepo: Drop unnecessary patch
The import-ssl-module.patch does not seem to be need and the tool seem
to be working just fine. Drop the patch.

Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit 94d5fd438d6df069d6d303fb046e430f6118a93a)
2021-05-30 02:20:06 +00:00
Otavio Salvador
6eac23ff6a gitRepo: add myself as maintainer
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit 3a37d115ef369c03810a2339a09449d5c18a103d)
2021-05-30 02:20:05 +00:00
Otavio Salvador
a51efd1bb4 gitRepo: 2.14.5 -> 2.15.3
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
(cherry picked from commit 19807e4ced2eea5c8f52a6e86df24e10ebb15367)
2021-05-30 02:20:05 +00:00
Austin Butler
8a6d0863c5 kooha: 1.1.3 -> 1.2.1
(cherry picked from commit 3d8311849e)
2021-05-30 02:19:51 +00:00
figsoda
4a4105f069 newsflash: fix build
(cherry picked from commit b0b823be50)
2021-05-30 02:14:00 +00:00
Sandro
4330bdd244 Update pkgs/development/libraries/getdata/default.nix
(cherry picked from commit 1b77912d10ba5a5e8ddf7853f00ac3cb841d59bf)
2021-05-30 02:08:03 +00:00
Vincent Laporte
81c84a9194 getdata: add security patch from Debian
(cherry picked from commit 14bb4b8f9aed4b1e04c0edab0851c31144ccd7e3)
2021-05-30 02:08:03 +00:00
Dusk Banks
9cab6e0dd4 betterdiscordctl: 1.7.1 -> 2.0.0
(cherry picked from commit 35a1e99d7a)
2021-05-30 02:04:55 +00:00
Robert Schütz
d27b376262 pika-backup: 0.3.1 -> 0.3.2
https://gitlab.gnome.org/World/pika-backup/-/tags/v0.3.2
(cherry picked from commit 52c24e9fbe)
2021-05-30 02:04:12 +00:00
Pavol Rusnak
725af5376f gotty: 2.0.0-alpha.3 -> 1.2.0
new upstream, versioning scheme changed back to v 1.x

(cherry picked from commit 5a8cd34dba)
2021-05-30 01:53:51 +00:00
Markus Kowalewski
a217eed6b8 welle-io: 2.2 -> 2.3
(cherry picked from commit af44c17b5d)
2021-05-30 01:52:44 +00:00
xfnw
e57ea488f9 catgirl: 1.7 -> 1.8
(cherry picked from commit 645446afa5)
2021-05-30 01:49:20 +00:00
Fabian Affolter
efbb010dfb python3Packages.smhi-pkg: 1.0.14 -> 1.0.15
(cherry picked from commit ebbc5a8728ac7002e9f86a0dfdbb660d50f6d689)
2021-05-29 23:13:17 +00:00
Fabian Affolter
fb75a2a13f python3Packages.pyrituals: 0.0.2 -> 0.0.3
(cherry picked from commit e678ecdc0d0dd9149330cf525939a451c4248b7d)
2021-05-29 16:08:57 -07:00
Robert Schütz
6460c5ce33 openvpn-auth-ldap: 2.0.3+deb6.1 -> 2.0.4
(cherry picked from commit f734a05c8c01f54e14432c2adb92d9291c69bb18)
2021-05-29 15:57:16 -07:00
Martin Weinelt
c1757ad15a Merge pull request #124895 from NixOS/backport-124839-to-release-21.05
[Backport release-21.05] nixos/wordpress: regenerate secret keys if misspelled key name is found
2021-05-30 00:46:56 +02:00
Dmitry Kalinkin
7198e20169 webkitgtk: fix on darwin
(cherry picked from commit 61e49ba58b)
2021-05-29 18:39:16 -04:00
markuskowa
fb64e7de78 Merge pull request #124896 from NixOS/backport-124890-to-release-21.05
[Backport release-21.05] mpich: 3.4.1 -> 3.4.2
2021-05-29 22:57:05 +02:00
github-actions[bot]
8dc1b48597 cargo-raze: fix darwin (#124343)
* cargo-raze: fix darwin

Disable tests on darwin as they've started failing after the latest update: #119531

Example failure: https://hydra.nixos.org/build/143411545

* Update pkgs/development/tools/rust/cargo-raze/default.nix

Co-authored-by: Sandro <sandro.jaeckel@gmail.com>

(cherry picked from commit 48b6b8b8c6)
2021-05-29 16:50:27 -04:00
Markus Kowalewski
58ba40336c mpich: 3.4.1 -> 3.4.2
(cherry picked from commit 0853275727)
2021-05-29 20:17:55 +00:00
Martin Weinelt
f4d6d51a09 nixos/wordpress: regenerate secret keys if misspelled key name is found
A secret key generated by the nixos module was misspelled, which could
possibly impact the security of session cookies.

To recover from this situation we will wipe all security keys that were
previously generated by the NixOS module, when the misspelled one is
found. This will result in all session cookies being invalidated. This
is confirmed by the wordpress documentation:

> You can change these at any point in time to invalidate all existing
> cookies. This does mean that all users will have to login again.

https://wordpress.org/support/article/editing-wp-config-php/#security-keys

Meanwhile this issue shouldn't be too grave, since the salting function
of wordpress will rely on the concatenation of both the user-provided
and automatically generated values, that are stored in the database.

> Secret keys are located in two places: in the database and in the
> wp-config.php file. The secret key in the database is randomly
> generated and will be appended to the secret keys in wp-config.php.

https://developer.wordpress.org/reference/functions/wp_salt/

Fixes: 2adb03fdae ("nixos/wordpress:
generate secrets locally")

Reported-by: Moritz Hedtke <Moritz.Hedtke@t-online.de>
(cherry picked from commit 724ed08df0)
2021-05-29 20:16:47 +00:00
Maximilian Bosch
e7f90ce89c Merge pull request #124821 from NixOS/backport-124408-to-release-21.05
[Backport release-21.05] virt-manager: fix missing cdrtools
2021-05-29 20:37:14 +02:00
Pavol Rusnak
1166a744e3 Merge pull request #124130 from prusnak/cocotb-21.05
[21.05] python3Packages.cocotb: 1.5.1 -> 1.5.2
2021-05-29 19:52:22 +02:00
Guillaume Girol
c30d29421b Merge pull request #124879 from NixOS/backport-124798-to-release-21.05
[Backport release-21.05] paperwork: 2.0.2 -> 2.0.3 and compile user manual
2021-05-29 16:33:30 +00:00
Symphorien Gibol
78268a73a1 paperwork: 2.0.2 -> 2.0.3 and compile user manual
(cherry picked from commit dc3054b4ae)
2021-05-29 15:01:48 +00:00
Robert Schütz
c258bb29a3 Merge pull request #124759 from dotlambda/whipper-fix
[21.05] whipper: fix
2021-05-29 15:33:20 +02:00
David Guibert
42a8ab0dbe step-ca: use latest buildGoModule
(cherry picked from commit acf134771c)
2021-05-29 13:09:07 +02:00
David Guibert
08e23c65c1 step-cli: 0.15.3-22 -> 0.15.16
(cherry picked from commit 1270b79771)
2021-05-29 13:09:07 +02:00
David Guibert
f6db4eba25 step-ca: 0.15.11 -> 0.15.15
(cherry picked from commit f9eedc3457)
2021-05-29 13:09:02 +02:00
Robert Schütz
6eba052712 Merge pull request #124275 from lunik1/libretro-ppsspp-ffmpeg4-backport
[21.05] libretro.ppsspp: backport update and fix build against ffmpeg 4.4
2021-05-29 12:48:36 +02:00
Robert Schütz
417b79b504 samba: 4.13.7 -> 4.14.4
fixes https://www.samba.org/samba/security/CVE-2021-20254.html

(cherry picked from commit 2db53555ee297acb1dbce22e4342ac6f37e14407)
2021-05-28 23:06:49 -07:00
Robert Schütz
a68c14446b python3Packages.cssutils: 2.2.0 -> 2.3.0
https://github.com/jaraco/cssutils/blob/v2.3.0/CHANGES.rst
(cherry picked from commit ade1f796cb)
2021-05-28 22:20:46 -07:00
Robert Schütz
0bfc2cc9ea spotdl: 3.5.2 -> 3.6.1
https://github.com/spotDL/spotify-downloader/releases/tag/v3.6.0
https://github.com/spotDL/spotify-downloader/releases/tag/v3.6.1
(cherry picked from commit 7683afc895)
2021-05-28 22:17:51 -07:00
talyz
b423efaeeb nixos/discourse: Assert deployed PostgreSQL version
Assert that the PostgreSQL version being deployed is the one used
upstream. Allow the user to override this assertion, since it's not
always possible or preferable to use the recommended one.

(cherry picked from commit 544adbfcab2e92c2fe5774cae67f2edf165eb97e)
2021-05-28 22:16:10 -07:00
Ryan Mulligan
4594e54063 nixos/discourse: Add rsync dependency
It is used for backup importing.

(cherry picked from commit e9c5ee1c4e48dc996773ccdbc0347f18fad31db9)
2021-05-28 22:16:10 -07:00
talyz
ce5587e7bb discourse: 2.6.5 -> 2.7.0
(cherry picked from commit 42b8e7685d5fe5280f8f6101a6d19016b92f3a5c)
2021-05-28 22:16:10 -07:00
Daniël de Kok
c892433d7b softmaker-office: 1030 -> 1032
(cherry picked from commit 854c4ad2d9)
2021-05-28 22:13:27 -04:00
Sandro
6ca6be2bbf Merge pull request #124835 from NixOS/backport-124819-to-release-21.05
[Backport release-21.05] gitAndTools.delta: 0.7.1 -> 0.8.0
2021-05-29 03:49:17 +02:00
Zhaofeng Li
25115a31d7 xpra: Add NVENC support
(cherry picked from commit 80e86f8871)
2021-05-28 21:39:53 -04:00
Zhaofeng Li
a5cbb1a436 nv-codec-headers-10: init at 10.0.26.2
(cherry picked from commit 13f114593b)
2021-05-28 21:39:53 -04:00
Dominik Xaver Hörl
fa5915bebb rl-2105: mention linux_latest and potential zfs issues
(cherry picked from commit 7953b6e532be68c76e0e02bf6c83ff9350ad529e)
2021-05-28 18:32:16 -07:00
Dominik Xaver Hörl
c50592961a linuxPackages_latest: update to 5.12
(cherry picked from commit 755db9a1e9a35c185f7d6c0463025e94ef44622e)
2021-05-28 18:32:16 -07:00
Mario Rodas
53ad00cfc3 gitAndTools.delta: 0.7.1 -> 0.8.0
https://github.com/dandavison/delta/releases/tag/0.8.0
(cherry picked from commit 4052d0eceb)
2021-05-29 01:31:34 +00:00
Niklas Hambüchen
b73e47d3d7 nixos/wireguard: Remove .path systemd unit for privkey. Fixes #123203
As per `man systemd.path`:

> When a service unit triggered by a path unit terminates
> (regardless whether it exited successfully or failed),
> monitored paths are checked immediately again,
> **and the service accordingly restarted instantly**.

Thus the existence of the path unit made it impossible to stop the
wireguard service using e.g.

    systemctl stop wireguard-wg0.service

Systemd path units are not intended for program inputs such
as private key files.
This commit simply removes this usage; the private key is still
generated by the `generateKeyServiceUnit`.

(cherry picked from commit d344dccf3d)
2021-05-28 18:28:35 -07:00
Сухарик
df81c53bc9 helio-workstation: 3.4 -> 3.6
(cherry picked from commit d6ad9712ef)
2021-05-29 01:20:13 +00:00
Peter Hoeg
36f8feac81 tellico: 3.4 -> 3.4.1
(cherry picked from commit 1bfabf6fba)
2021-05-29 01:14:45 +00:00
Bart Brouns
8d914c1157 bjumblr: 1.4.2 -> 1.6.6
(cherry picked from commit de9f169ecc)
2021-05-29 01:07:01 +00:00
greaka
7b1072b4ff terraria-server: 1.4.2.2 -> 1.4.2.3
(cherry picked from commit 4e9bd87f5a)
2021-05-29 01:02:37 +00:00
Matt Layher
d981999780 corerad: 0.3.0 -> 0.3.1
Signed-off-by: Matt Layher <mdlayher@gmail.com>
(cherry picked from commit 39b4c8f9af)
2021-05-29 00:56:22 +00:00
Vladyslav M
ad947d5fa6 b3sum: 0.3.7 -> 0.3.8
(cherry picked from commit 42d671a80d)
2021-05-29 00:51:22 +00:00
Sandro
b08b7cd9b7 Apply suggestions from code review
(cherry picked from commit 902ce1df42adc35ca871c5b7c00d0b6dad145749)
2021-05-29 00:50:47 +00:00
superherointj
84fd858633 virt-manager: fix missing cdrtools
(cherry picked from commit 13f3200cd056e44886f063e8d785460b172523df)
2021-05-29 00:50:47 +00:00
Pacman99
b9c25438fd mx-puppet-discord: set pname
(cherry picked from commit 166aabe0c7)
2021-05-29 00:34:29 +00:00
Pacman99
684d2e7924 matrix-appservice-slack: set pname
(cherry picked from commit a811e7385c)
2021-05-29 00:34:29 +00:00
Pacman99
c444b9f55b matrix-appservice-irc: set pname
(cherry picked from commit 41e46599ea)
2021-05-29 00:34:29 +00:00
Sandro
d5d7312426 Merge pull request #124805 from prusnak/electron-21.05 2021-05-29 02:09:24 +02:00
Domen Kožar
8a5ec66c40 patray: Yet another tray pulseaudio frontend
(cherry picked from commit 4758dd4814)
2021-05-28 18:36:24 -04:00
Domen Kožar
5b3858527f pythonPackages.google-api-python-client: 2.0.2 -> 2.6.0
(cherry picked from commit 184b453090)
2021-05-28 18:36:24 -04:00
fortuneteller2k
b1a828fa56 fetchutils: remove DESTDIR, use PREFIX, change owner
(cherry picked from commit feef79647f1da6fe2e06e9cfc72dd923641a3c7e)
2021-05-28 18:35:43 -04:00
Martin Weinelt
75d84510e1 Merge pull request #124787 from mohe2015/backport-124516
[21.05] wordpress: 5.7.1 -> 5.7.2
2021-05-29 00:35:00 +02:00
Stefan Frijters
18cd14175f doc/coding-conventions: Add documentation for fetchpatch optional arguments
(cherry picked from commit 585f63b364)
2021-05-28 18:34:45 -04:00
Mitsuhiro Nakamura
5b52f151e1 feedgnuplot: 1.51 -> 1.58
(cherry picked from commit b9bf2ab441)
2021-05-28 18:33:53 -04:00
Mitsuhiro Nakamura
831bf15565 feedgnuplot: fix perl shebang
(cherry picked from commit 75176e353c)
2021-05-28 18:33:53 -04:00
Michael Raskin
47ed684380 Merge pull request #124801 from dotlambda/CVE-2020-18032
[21.05] graphviz: patch CVE-2020-18032
2021-05-28 21:15:34 +00:00
Maximilian Bosch
d77e68bedf Merge pull request #124793 from NixOS/backport-124121-to-release-21.05
[Backport release-21.05] libreoffice-still: 7.0.4.2 -> 7.0.6.2
2021-05-28 23:06:09 +02:00
TredwellGit
04fcd9e107 electron_10: 10.4.5 -> 10.4.7
https://github.com/electron/electron/releases/tag/v10.4.6
https://github.com/electron/electron/releases/tag/v10.4.7
(cherry picked from commit f8fbfa538b)
2021-05-28 23:03:44 +02:00
TredwellGit
836e34d53a electron_11: 11.4.6 -> 11.4.7
https://github.com/electron/electron/releases/tag/v11.4.7
(cherry picked from commit 505298f812)
2021-05-28 23:03:39 +02:00
TredwellGit
361dbda2ca electron_12: 12.0.7 -> 12.0.9
https://github.com/electron/electron/releases/tag/v12.0.8
https://github.com/electron/electron/releases/tag/v12.0.9
(cherry picked from commit a0426609c8)
2021-05-28 23:03:33 +02:00
Robert Schütz
2899292e07 graphviz: patch CVE-2020-18032
(cherry picked from commit b4e8099795)
2021-05-28 22:17:21 +02:00
Maximilian Bosch
9588f49304 Merge pull request #124794 from NixOS/backport-124703-to-release-21.05
[Backport release-21.05] Revert "element-desktop: set dbus default for firefox"
2021-05-28 22:13:43 +02:00
Maximilian Bosch
eff32c3626 Merge pull request #124797 from NixOS/backport-124790-to-release-21.05
[Backport release-21.05] diffoscope: 175 -> 176
2021-05-28 22:08:25 +02:00
Arthur Gautier
4e172daaa6 diffoscope: 175 -> 176
Signed-off-by: Arthur Gautier <baloo@superbaloo.net>
(cherry picked from commit fd2e675e7c)
2021-05-28 19:38:56 +00:00
Robert Scott
5621b77a7e python3Packages.hdbscan: disable another flaky test
(cherry picked from commit 5bae3c6746)
2021-05-28 20:30:32 +01:00
Evils
6350467e7b Revert "element-desktop: set dbus default for firefox"
This reverts commit becc715b89.

(cherry picked from commit 6377bc3662)
2021-05-28 19:28:58 +00:00
Thomas Gerbet
7e7e91f8e2 libreoffice-still: 7.0.4.2 -> 7.0.6.2
This will avoid false positives with CVE-2021-25631 [0] (only impact
Windows).
It also includes bugfixes:
https://wiki.documentfoundation.org/Releases/7.0.5/RC1
https://wiki.documentfoundation.org/Releases/7.0.5/RC2
https://wiki.documentfoundation.org/Releases/7.0.6/RC1
https://wiki.documentfoundation.org/Releases/7.0.6/RC2

[0] https://www.libreoffice.org/about-us/security/advisories/cve-2021-25631/

(cherry picked from commit f7b33e0334)
2021-05-28 19:25:16 +00:00
Ivan Kozik
02daee80bc nixos/bitwarden_rs: fix startup on 32 thread machines
LimitNPROC=64 is too low for bitwarden_rs to start on a 32 thread machine.
Remove the limit.

This fixes:

```
bitwarden_rs[38701]: /--------------------------------------------------------------------\
bitwarden_rs[38701]: |                       Starting Bitwarden_RS                        |
bitwarden_rs[38701]: |--------------------------------------------------------------------|
bitwarden_rs[38701]: | This is an *unofficial* Bitwarden implementation, DO NOT use the   |
bitwarden_rs[38701]: | official channels to report bugs/features, regardless of client.   |
bitwarden_rs[38701]: | Send usage/configuration questions or feature requests to:         |
bitwarden_rs[38701]: |   https://bitwardenrs.discourse.group/                             |
bitwarden_rs[38701]: | Report suspected bugs/issues in the software itself at:            |
bitwarden_rs[38701]: |   https://github.com/dani-garcia/bitwarden_rs/issues/new           |
bitwarden_rs[38701]: \--------------------------------------------------------------------/
bitwarden_rs[38701]: [INFO] No .env file found.
bitwarden_rs[38701]: [2021-05-24 03:34:41.121][bitwarden_rs::api::core::sends][INFO] Initiating send deletion
bitwarden_rs[38701]: [2021-05-24 03:34:41.122][start][INFO] Rocket has launched from http://127.0.0.1:8222
bitwarden_rs[38701]: [2021-05-24 03:34:41.126][panic][ERROR] thread 'unnamed' panicked at 'failed to spawn thread: Os { code: 11, kind: WouldBlock, message: "Resource temporarily unavailable" }': /build/rustc-1.52.1-src/library/std/src/thread/mod.rs:620
bitwarden_rs[38701]:    0: bitwarden_rs::init_logging::{{closure}}
bitwarden_rs[38701]:    1: std::panicking::rust_panic_with_hook
bitwarden_rs[38701]:    2: std::panicking::begin_panic_handler::{{closure}}
bitwarden_rs[38701]:    3: std::sys_common::backtrace::__rust_end_short_backtrace
bitwarden_rs[38701]:    4: rust_begin_unwind
bitwarden_rs[38701]:    5: core::panicking::panic_fmt
bitwarden_rs[38701]:    6: core::result::unwrap_failed
bitwarden_rs[38701]:    7: hyper::server::listener::spawn_with
bitwarden_rs[38701]:    8: hyper::server::listener::ListenerPool<A>::accept
bitwarden_rs[38701]:    9: std::sys_common::backtrace::__rust_begin_short_backtrace
bitwarden_rs[38701]:   10: core::ops::function::FnOnce::call_once{{vtable.shim}}
bitwarden_rs[38701]:   11: std::sys::unix::thread::Thread::new::thread_start
bitwarden_rs[38701]:   12: start_thread
bitwarden_rs[38701]:   13: __GI___clone
bitwarden_rs[38701]: [2021-05-24 03:34:41.126][panic][ERROR] thread 'main' panicked at 'internal error: entered unreachable code: the call to `handle_threads` should block on success': /build/bitwarden_rs-1.20.0-vendor.tar.gz/rocket/src/rocket.rs:751
bitwarden_rs[38701]:    0: bitwarden_rs::init_logging::{{closure}}
bitwarden_rs[38701]:    1: std::panicking::rust_panic_with_hook
bitwarden_rs[38701]:    2: std::panicking::begin_panic_handler::{{closure}}
bitwarden_rs[38701]:    3: std::sys_common::backtrace::__rust_end_short_backtrace
bitwarden_rs[38701]:    4: rust_begin_unwind
bitwarden_rs[38701]:    5: core::panicking::panic_fmt
bitwarden_rs[38701]:    6: rocket::rocket::Rocket::launch
bitwarden_rs[38701]:    7: bitwarden_rs::main
bitwarden_rs[38701]:    8: std::sys_common::backtrace::__rust_begin_short_backtrace
bitwarden_rs[38701]:    9: std::rt::lang_start::{{closure}}
bitwarden_rs[38701]:   10: std::rt::lang_start_internal
bitwarden_rs[38701]:   11: main
```

(cherry picked from commit d95960e275)
2021-05-28 11:36:54 -07:00
Hedtke, Moritz
fcddce0f10 wordpress: 5.7.1 -> 5.7.2
(cherry picked from commit 5fa469b6f2)
2021-05-28 20:34:51 +02:00
Fabián Heredia Montiel
79c5dbb549 pgsync: 0.6.6 → 0.6.7
(cherry picked from commit cc855b1331)
2021-05-28 11:34:51 -07:00
Antoine R. Dumont (@ardumont)
80df101aa8 mediatomb/gerbera: Add release note information for 21.03
Note that it made into 2 entries, one about new options in the first section.
Another in the breaking compatibility section due to the openFirewall option
which changes the behavior.

Co-authored-by: schmittlauch <t.schmittlauch+nixos@orlives.de>
(cherry picked from commit 93a80a4390499b4204cf6836bcc6cab5debecccb)
2021-05-28 11:21:30 -07:00
Robert Schütz
377de4787e Merge pull request #124757 from dotlambda/mediatomb-ffmpeg
[21.05] mediatomb: use ffmpeg instead of ffmpeg_3
2021-05-28 17:25:41 +02:00
Robert Schütz
078af61232 whipper: fix
(cherry picked from commit df7eecceb5)
2021-05-28 16:29:33 +02:00
Robert Schütz
989c034206 mediatomb: use ffmpeg instead of ffmpeg_3 (#123487)
(cherry picked from commit 81abd8d0ac)
2021-05-28 16:10:23 +02:00
David
8d31a9d644 rebar3: 3.16.0 -> 3.16.1
(cherry picked from commit d706be982a)
2021-05-28 20:43:11 +09:00
Robert Schütz
1c212ecbb8 Merge pull request #124707 from dotlambda/openvpn-2.5.2
[21.05] openvpn: 2.5.0 -> 2.5.2, openvpn_24: 2.4.9 -> 2.4.11
2021-05-28 10:20:03 +02:00
Thomas Gerbet
88144f9b91 openvpn_24: 2.4.9 -> 2.4.11
Fixes CVE-2020-15078.
https://community.openvpn.net/openvpn/wiki/CVE-2020-15078

(cherry picked from commit e2df9554b0)
2021-05-28 01:02:33 +02:00
Thomas Gerbet
6929dd4f0b openvpn: 2.5.0 -> 2.5.2
Fixes CVE-2020-15078.
https://community.openvpn.net/openvpn/wiki/CVE-2020-15078

(cherry picked from commit 82f90f892f)
2021-05-28 01:02:33 +02:00
Robert Schütz
2371e028f6 Merge pull request #124701 from jchw-forks/lightspark-ffmpeg-backport
[21.05] lightspark: ffmpeg_3 -> ffmpeg
2021-05-28 00:19:16 +02:00
John Chadwick
47c51cc3bf lightspark: ffmpeg_3 -> ffmpeg
(cherry picked from commit 24129003fd)
2021-05-27 14:42:25 -07:00
Dmitry Kalinkin
46a5d32fc9 qhull: add fixDarwinDylibNames
(cherry picked from commit e34b559109)
cc #124578
2021-05-27 16:55:02 -04:00
Michael Weiss
6029acc019 Merge pull request #124598 from primeos/backports
[21.05] nixos/tests/{sway,cagebreak}: Disable on aarch64-linux
2021-05-27 18:56:31 +02:00
Michael Weiss
5e74829b72 nixos/tests/{sway,cagebreak}: Disable on aarch64-linux
The tests timeout on AArch64 (e.g. [0] and [1]), likely because the QEMU
option "-vga virtio" isn't supported there (unfortunately I currently
lack access to an AArch64 system with NixOS to investigate).

This also affects the test for Cage but that one is already limited to
x86_64-linux.

[0]: https://hydra.nixos.org/build/144148809
[1]: https://hydra.nixos.org/build/144103034

(cherry picked from commit abb9ea73f7)
2021-05-27 17:43:06 +02:00
Michael Lingelbach
676ddafd3d nixos/dendrite: remove (#124524)
* The options tlsKey and tlsCert require being accessible by DynamicUser at runtime, which currently requires copying the files into the matrix service state directory. Fixing this might require breaking changes. Thus the module should not be included in a stable release.
2021-05-27 10:41:05 +02:00
Trolli Schmittlauch
611cedc127 poppler: build with nss by default for signature support
Since 21.01, poppler supports PDF signing. As applications like okular
start to make use of that feature, nss support for poppler is enabled by
default to avoid unnecessary package duplication.
When building a `minimal` version of poppler, nss is disabled as well.

closes #120928

(cherry picked from commit 5f9862d524ee0ec1edcaa450fff4f54f4f5cc68e)
2021-05-27 03:48:21 -04:00
Sandro
ff00b8c0d1 Merge pull request #124565 from nbren12/jupyterlab-backport 2021-05-27 05:16:18 +02:00
Sandro
17293ccdfc Merge pull request #124448 from mweinelt/21.05/home-assistant
[21.05] home-assistant: disable flaky test in prometheus component
2021-05-27 05:14:07 +02:00
Noah D. Brenowitz
c8a75ccf74 python3Packages.nbclassic: allow darwin network tests
(cherry picked from commit f1096cd92c)
2021-05-26 19:33:40 -07:00
Noah D. Brenowitz
a0011e1118 python3Packages.jupyterlab_server: allow darwin networking
(cherry picked from commit 7c29b3e082)
2021-05-26 19:33:40 -07:00
Noah D. Brenowitz
a2547d21eb python3Packages.jupyter_server: allow local networking
(cherry picked from commit 1244ddc7c6)
2021-05-26 19:33:40 -07:00
Sandro
e7e53babb6 Merge pull request #124515 from primeos/signal-desktop-backport 2021-05-27 04:30:52 +02:00
Sandro
0a086ee342 Merge pull request #124509 from dotlambda/backport-124391 2021-05-27 04:30:18 +02:00
Sandro
837f80023d Merge pull request #124526 from risicle/ris-devpi-client-server-darwin-allow-local-networking-r21.05 2021-05-27 03:49:58 +02:00
Sandro
83fb69d685 Merge pull request #124527 from risicle/ris-python-xgboost-darwin-fix-r21.05 2021-05-27 03:47:21 +02:00
Sandro
51cf39407b Merge pull request #124555 from hrhino/backport/fix/python3Packages/acoustics
acoustics: fix
2021-05-27 02:57:27 +02:00
Robert Scott
deb0a4259f python3Packages.mat2: fix tests against ffmpeg 4.4
seems upstream have already noticed this breakage and have fixed it
in master

(cherry picked from commit 6d8b59ab30)
2021-05-26 19:44:58 -04:00
Harrison Houghton
5369265a53 acoustics: fix
There's a bit of LaTeX math code in a comment in a test file:

```
    .. math:: L = 10 \cdot \\log_{10}{\\left(\\frac{MS}{p_r^2} \\right)}
```

which of course should be `\\cdot`.

I could patch it, but I think skipping deprecation warnings in tests is
probably ok... (If nothing else it's easier.)

(cherry picked from commit dbc085cb44)
2021-05-26 19:32:26 -04:00
austinbutler
84a08eb98d stellar-core: 0.5.1 -> 17.0.0 (#123294)
(cherry picked from commit 2a6db4c056)
2021-05-26 19:30:48 -04:00
Maximilian Bosch
95f6c0b7e0 nixos/release-notes: fix slaptest command for openldap section
When running - as suggested - `slaptest -f slapd.conf $TMPDIR` I get the
following result:

    [root@ldap:/tmp/tmp.De46ABIbFf]# slaptest -f /nix/store/lks3ihydj40ff6yqvz0k33ycrc9vbyry-slapd.conf $TMPDIR
    usage: slaptest [-v] [-d debuglevel] [-f configfile] [-F configdir] [-o <name>[=<value>]] [-n databasenumber] [-u] [-Q]

    [root@ldap:/tmp/tmp.De46ABIbFf]# echo $?
    1

Adding a `-F` option fixes the issue.

(cherry picked from commit b5a12b4b61)
2021-05-26 22:35:51 +02:00
Maximilian Bosch
25eaf1083f diffoscope: fix build
ZHF #122042
Failing Hydra build: https://hydra.nixos.org/build/143815905

Currently the diff-check for `.mp3`-files is failing. The only reason
for that is that right now is that there are too spaces too much on the
last line[1].

[1] https://salsa.debian.org/reproducible-builds/diffoscope/-/blob/175/tests/data/mp3_expected_diff

(cherry picked from commit ea55d23cd8)
2021-05-26 22:35:51 +02:00
Sandro
4a40836097 Merge pull request #124533 from DeterminateSystems/tf-provider-hydra-21.05
[21.05] terraform-providers.hydra: 0.1.0 -> 0.1.1
2021-05-26 22:17:24 +02:00
Cole Helbling
573cdf2df2 terraform-providers.hydra: 0.1.1 -> 0.1.2
(cherry picked from commit 4c7cf79b36)
2021-05-26 12:23:14 -07:00
Robert Scott
169371366d Merge pull request #124477 from LeSuisse/sssd-1.16.5-21.05
[21.05] sssd: 1.16.4 -> 1.16.5
2021-05-26 20:13:31 +01:00
Michele Guerini Rocco
ed35898dd1 Merge pull request #124529 from rnhmjoj/openconnect-21.05
[21.05] openconnect-head: init at 2021-05-05
2021-05-26 21:02:45 +02:00
Robert Scott
8ac5876aac python3Packages.xgboost: fix tests for darwin
(cherry picked from commit 4ef1d33c7c)
2021-05-26 19:22:30 +01:00
Robert Scott
2c8139ee6b devpi-server: set __darwinAllowLocalNetworking
allowing tests to pass on sandboxed darwin

(cherry picked from commit 46e66614d9)
2021-05-26 19:11:21 +01:00
Robert Scott
828cf19e1e devpi-client: set __darwinAllowLocalNetworking
allowing tests to pass on sandboxed darwin

(cherry picked from commit 995d2d87c8)
2021-05-26 19:09:50 +01:00
rnhmjoj
b6f4ae45b7 openconnect: fix license information
The project seems to be licensed under LGPL 2.1 *only*.

(cherry picked from commit 61f556a60b)
2021-05-26 19:43:40 +02:00
rnhmjoj
fc8280a67c openconnect-head: init at 2021-05-05
(cherry picked from commit 2d1090a058)
2021-05-26 19:43:36 +02:00
Gabriel Ebner
84ad09b57b Merge pull request #124518 from collares/olean-backport
[21.05] lean: substitute release commit sha1
2021-05-26 19:22:26 +02:00
Mauricio Collares
97eba634e4 lean: substitute release commit sha1 2021-05-26 13:47:23 -03:00
Michael Weiss
8eb8032b1d signal-desktop: 5.2.1 -> 5.3.0
(cherry picked from commit 5be62dca8c)
2021-05-26 18:13:33 +02:00
Sandro Jäckel
0b4994f714 nixos/kresd: tell resolveconf to use local resolver
(cherry picked from commit 140828ce38)
2021-05-26 17:24:55 +02:00
Harrison Houghton
6ac38da61b pinball: fix
There was an override of autoconfHook to use automake 1.15.x; I'm not
sure what changed since this package was added but it explicitly needs
1.16.1 or greater for the submodule libltdl.

Anyhow, just remove the override.

(cherry picked from commit 3e4aeea693)
2021-05-26 08:07:53 -07:00
Andrew Childs
d2920be368 darwin/make-bootstrap-tools: move "lib" from install name to rpath
The rpath structure for the bootstrap tools was reworked to minimize
the amount of rewriting required on unpack, but the test was not
updated to match the different structure.

Additionally [1] builds that use the bootstrap version of libc++
cannot find libc++abi if the reference includes the "lib"
component (ie, libc++ refers to libc++abi with
@rpath/lib/libc++abi.dylib).

[1] https://logs.nix.samueldr.com/nix-darwin/2021-05-18#4993282

Test failure observed on Hydra: https://hydra.nixos.org/build/143130126

(cherry picked from commit 38207735f4)
2021-05-26 08:05:16 -07:00
Michele Guerini Rocco
677fab12a9 Merge pull request #124488 from rnhmjoj/mpl-21.05
[21.05] pythonPackages.matplotlib: fix headless detection
2021-05-26 14:48:31 +02:00
rnhmjoj
6aa537a98d pythonPackages.matplotlib: add licenses
(cherry picked from commit 7672576a0d)
2021-05-26 14:20:01 +02:00
rnhmjoj
a6ac81209b pythonPackages.matplotlib: remove unsused arguments
(cherry picked from commit 3a3e1134a8)
2021-05-26 14:19:57 +02:00
rnhmjoj
b7ce7d761c pythonPackages.matplotlib: fix headless detection
The default backend is chosen based on the content of the $DISPLAY
variable *and* a successfull call to libX11, loaded via dlopen().
The test fails because dlopen looks in /usr/lib and /lib, so matplotlib
falls back to a headless backend.

To reproduce try running:

    $ nix-shell -I nixpkgs=$PWD -p \
      'python3.withPackages (p: [ p.matplotlib ])' --run python
    >>> import matplotlib.pyplot as plt
    >>> assert plt.get_backend() == "TkAgg"

(cherry picked from commit 7e2ec8f8a1)
2021-05-26 14:19:45 +02:00
Thomas Gerbet
feff71106d sssd: 1.16.4 -> 1.16.5
Fixes CVE-2018-16838.
https://sssd.io/release-notes/sssd-1.16.5.html

(cherry picked from commit affda4029f)
2021-05-26 12:04:22 +02:00
DavHau
97fc742ae6 scikit-learn: disable some tests for darwin
(cherry picked from commit 4af47234fa)
2021-05-26 00:29:23 -07:00
Noah D. Brenowitz
ff776b403a python3Packages.scikitlearn: disable flaky tests
* Disable all tests of the NuSVC estimator that use memmap'd data
* build in serial on darwin

Resolves #121988

(cherry picked from commit cb2891b8c8)
2021-05-26 00:29:23 -07:00
Martin Weinelt
813b3b2a0c Revert "python3Packages.pywemo: disable failing test"
This reverts commit 60c98baf17.

The original issue was a result of a libxml2 regression that has since
been fixed.
2021-05-26 04:56:46 +02:00
Martin Weinelt
af053d10fb Merge remote-tracking branch 'origin/release-21.05' into staging-next-21.05 2021-05-26 04:56:26 +02:00
Martin Weinelt
66fdd3939d home-assistant: disable flaky test in prometheus component
______________________________ test_view[pyloop] _______________________________
[gw49] linux -- Python 3.8.9 /nix/store/7i305r9i4rsb1hmqwkdmphjf430niq3l-python3-3.8.9/bin/python3.8
hass = <homeassistant.core.HomeAssistant object at 0xffff56d041c0>
hass_client = <function hass_client.<locals>.auth_client at 0xffff56a11ca0>
    async def test_view(hass, hass_client):
        """Test prometheus metrics view."""
        client = await prometheus_client(hass, hass_client)
        resp = await client.get(prometheus.API_ENDPOINT)

        assert resp.status == 200
        assert resp.headers["content-type"] == CONTENT_TYPE_TEXT_PLAIN
        body = await resp.text()
        body = body.split("\n")

        assert len(body) > 3

        assert "# HELP python_info Python platform information" in body
        assert (
            "# HELP python_gc_objects_collected_total "
            "Objects collected during gc" in body
        )

        assert (
            'temperature_c{domain="sensor",'
            'entity="sensor.outside_temperature",'
            'friendly_name="Outside Temperature"} 15.6' in body
        )

        assert (
            'battery_level_percent{domain="sensor",'
            'entity="sensor.outside_temperature",'
            'friendly_name="Outside Temperature"} 12.0' in body
        )

        assert (
            'current_temperature_c{domain="climate",'
            'entity="climate.heatpump",'
            'friendly_name="HeatPump"} 25.0' in body
        )

>       assert (
            'humidifier_target_humidity_percent{domain="humidifier",'
            'entity="humidifier.humidifier",'
            'friendly_name="Humidifier"} 68.0' in body
        )
E       assert 'humidifier_target_humidity_percent{domain="humidifier",entity="humidifier.humidifier",friendly_name="Humidifier"} 68.0' in ['# HELP python_gc_objects_collected_total Objects collected during gc', '# TYPE python_gc_objects_collected_total cou...al{generation="2"} 175103.0', '# HELP python_gc_objects_uncollectable_total Uncollectable object found during GC', ...]
tests/components/prometheus/test_init.py:130: AssertionError
---------------------------- Captured stderr setup -----------------------------
DEBUG:asyncio:Using selector: EpollSelector
------------------------------ Captured log setup ------------------------------
DEBUG    asyncio:selector_events.py:59 Using selector: EpollSelector
----------------------------- Captured stderr call -----------------------------
INFO:homeassistant.loader:Loaded prometheus from homeassistant.components.prometheus
INFO:homeassistant.loader:Loaded http from homeassistant.components.http
DEBUG:homeassistant.setup:Dependency prometheus will wait for dependencies ['http']
INFO:homeassistant.setup:Setting up http
INFO:homeassistant.setup:Setup of domain http took 0.0 seconds
DEBUG:homeassistant.core:Bus:Handling <Event component_loaded[L]: component=http>
INFO:homeassistant.setup:Setting up prometheus
INFO:homeassistant.setup:Setup of domain prometheus took 0.0 seconds
DEBUG:homeassistant.core:Bus:Handling <Event component_loaded[L]: component=prometheus>
INFO:homeassistant.loader:Loaded sensor from homeassistant.components.sensor
INFO:homeassistant.loader:Loaded demo from homeassistant.components.demo
INFO:homeassistant.setup:Setting up sensor
INFO:homeassistant.setup:Setup of domain sensor took 0.0 seconds
DEBUG:homeassistant.setup:Dependency demo will wait for dependencies ['conversation', 'zone', 'group']
DEBUG:homeassistant.core:Bus:Handling <Event component_loaded[L]: component=sensor>
INFO:homeassistant.loader:Loaded conversation from homeassistant.components.conversation
INFO:homeassistant.loader:Loaded zone from homeassistant.components.zone
INFO:homeassistant.setup:Setting up conversation
INFO:homeassistant.loader:Loaded group from homeassistant.components.group
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=conversation, service=process>
INFO:homeassistant.setup:Setup of domain conversation took 0.0 seconds
INFO:homeassistant.loader:Loaded climate from homeassistant.components.climate
INFO:homeassistant.setup:Setting up zone
DEBUG:homeassistant.core:Bus:Handling <Event component_loaded[L]: component=conversation>
INFO:homeassistant.setup:Setting up group
INFO:homeassistant.setup:Setting up climate
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=climate, service=turn_on>
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=climate, service=turn_off>
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=climate, service=set_hvac_mode>
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=climate, service=set_preset_mode>
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=climate, service=set_aux_heat>
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=climate, service=set_temperature>
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=climate, service=set_humidity>
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=climate, service=set_fan_mode>
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=climate, service=set_swing_mode>
INFO:homeassistant.setup:Setup of domain climate took 0.0 seconds
DEBUG:homeassistant.setup:Dependency demo will wait for dependencies ['zone', 'group']
DEBUG:homeassistant.core:Bus:Handling <Event component_loaded[L]: component=climate>
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=group, service=reload>
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=group, service=set>
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=group, service=remove>
INFO:homeassistant.setup:Setup of domain group took 0.1 seconds
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=zone, service=reload>
DEBUG:homeassistant.core:Bus:Handling <Event component_loaded[L]: component=group>
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=zone.home, old_state=None, new_state=<state zone.home=zoning; latitude=32.87336, longitude=-117.22743, radius=100, passive=False, editable=True, friendly_name=test home, icon=mdi:home @ 2021-05-12T16:02:29.918726+00:00>>
DEBUG:homeassistant.components.prometheus:Handling state update for zone.home
INFO:homeassistant.setup:Setup of domain zone took 0.1 seconds
DEBUG:homeassistant.core:Bus:Handling <Event component_loaded[L]: component=zone>
INFO:homeassistant.setup:Setting up demo
INFO:homeassistant.setup:Setup of domain demo took 0.0 seconds
DEBUG:homeassistant.core:Bus:Handling <Event component_loaded[L]: component=demo>
INFO:homeassistant.components.sensor:Setting up sensor.demo
INFO:homeassistant.components.climate:Setting up climate.demo
INFO:homeassistant.helpers.entity_registry:Registered new sensor.demo entity: sensor.outside_temperature
DEBUG:homeassistant.core:Bus:Handling <Event entity_registry_updated[L]: action=create, entity_id=sensor.outside_temperature>
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=sensor.outside_temperature, old_state=None, new_state=<state sensor.outside_temperature=15.6; battery_level=12, unit_of_measurement=°C, friendly_name=Outside Temperature, device_class=temperature @ 2021-05-12T16:02:29.931161+00:00>>
INFO:homeassistant.helpers.entity_registry:Registered new sensor.demo entity: sensor.outside_humidity
DEBUG:homeassistant.core:Bus:Handling <Event entity_registry_updated[L]: action=create, entity_id=sensor.outside_humidity>
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=sensor.outside_humidity, old_state=None, new_state=<state sensor.outside_humidity=54; unit_of_measurement=%, friendly_name=Outside Humidity, device_class=humidity @ 2021-05-12T16:02:29.933965+00:00>>
INFO:homeassistant.helpers.entity_registry:Registered new sensor.demo entity: sensor.carbon_monoxide
DEBUG:homeassistant.components.prometheus:Handling state update for sensor.outside_humidity
DEBUG:homeassistant.core:Bus:Handling <Event entity_registry_updated[L]: action=create, entity_id=sensor.carbon_monoxide>
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=sensor.carbon_monoxide, old_state=None, new_state=<state sensor.carbon_monoxide=54; unit_of_measurement=ppm, friendly_name=Carbon monoxide, device_class=carbon_monoxide @ 2021-05-12T16:02:29.954947+00:00>>
INFO:homeassistant.helpers.entity_registry:Registered new sensor.demo entity: sensor.carbon_dioxide
DEBUG:homeassistant.components.prometheus:Handling state update for sensor.carbon_monoxide
DEBUG:homeassistant.core:Bus:Handling <Event entity_registry_updated[L]: action=create, entity_id=sensor.carbon_dioxide>
DEBUG:homeassistant.components.prometheus:Handling state update for sensor.outside_temperature
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=sensor.carbon_dioxide, old_state=None, new_state=<state sensor.carbon_dioxide=54; battery_level=14, unit_of_measurement=ppm, friendly_name=Carbon dioxide, device_class=carbon_dioxide @ 2021-05-12T16:02:29.958608+00:00>>
INFO:homeassistant.helpers.entity_registry:Registered new climate.demo entity: climate.heatpump
DEBUG:homeassistant.core:Bus:Handling <Event entity_registry_updated[L]: action=create, entity_id=climate.heatpump>
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=climate.heatpump, old_state=None, new_state=<state climate.heatpump=heat; hvac_modes=['heat', 'off'], min_temp=7.0, max_temp=35.0, current_temperature=25.0, temperature=20.0, hvac_action=heating, friendly_name=HeatPump, supported_features=1 @ 2021-05-12T16:02:29.970499+00:00>>
DEBUG:homeassistant.components.prometheus:Handling state update for sensor.carbon_dioxide
DEBUG:homeassistant.components.prometheus:Handling state update for climate.heatpump
INFO:homeassistant.helpers.entity_registry:Registered new climate.demo entity: climate.hvac
DEBUG:homeassistant.core:Bus:Handling <Event entity_registry_updated[L]: action=create, entity_id=climate.hvac>
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=climate.hvac, old_state=None, new_state=<state climate.hvac=cool; hvac_modes=['off', 'heat', 'cool', 'auto', 'dry', 'fan_only'], min_temp=7, max_temp=35, min_humidity=30, max_humidity=99, fan_modes=['On Low', 'On High', 'Auto Low', 'Auto High', 'Off'], swing_modes=['Auto', '1', '2', '3', 'Off'], current_temperature=22, temperature=21, target_temp_high=None, target_temp_low=None, current_humidity=54, humidity=67, fan_mode=On High, hvac_action=cooling, swing_mode=Off, aux_heat=off, friendly_name=Hvac, supported_features=111 @ 2021-05-12T16:02:29.980988+00:00>>
INFO:homeassistant.helpers.entity_registry:Registered new climate.demo entity: climate.ecobee
DEBUG:homeassistant.core:Bus:Handling <Event entity_registry_updated[L]: action=create, entity_id=climate.ecobee>
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=climate.ecobee, old_state=None, new_state=<state climate.ecobee=heat_cool; hvac_modes=['heat_cool', 'cool', 'heat'], min_temp=7, max_temp=35, fan_modes=['On Low', 'On High', 'Auto Low', 'Auto High', 'Off'], preset_modes=['home', 'eco'], swing_modes=['Auto', '1', '2', '3', 'Off'], current_temperature=23, target_temp_high=24, target_temp_low=21, fan_mode=Auto Low, preset_mode=home, swing_mode=Auto, friendly_name=Ecobee, supported_features=58 @ 2021-05-12T16:02:29.984441+00:00>>
DEBUG:homeassistant.components.prometheus:Handling state update for climate.hvac
DEBUG:homeassistant.components.prometheus:Handling state update for climate.ecobee
INFO:homeassistant.loader:Loaded humidifier from homeassistant.components.humidifier
INFO:homeassistant.setup:Setting up humidifier
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=humidifier, service=turn_on>
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=humidifier, service=turn_off>
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=humidifier, service=toggle>
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=humidifier, service=set_mode>
DEBUG:homeassistant.core:Bus:Handling <Event service_registered[L]: domain=humidifier, service=set_humidity>
INFO:homeassistant.setup:Setup of domain humidifier took 0.0 seconds
INFO:homeassistant.components.humidifier:Setting up humidifier.demo
DEBUG:homeassistant.core:Bus:Handling <Event component_loaded[L]: component=humidifier>
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=sensor.television_energy, old_state=None, new_state=<state sensor.television_energy=74; unit_of_measurement=kWh, friendly_name=Television Energy @ 2021-05-12T16:02:30.004051+00:00>>
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=sensor.radio_energy, old_state=None, new_state=<state sensor.radio_energy=14; unit_of_measurement=kWh, friendly_name=Radio Energy, device_class=power @ 1970-01-02T00:00:00+00:00>>
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=sensor.electricity_price, old_state=None, new_state=<state sensor.electricity_price=0.123; unit_of_measurement=SEK/kWh, friendly_name=Electricity price @ 2021-05-12T16:02:30.007311+00:00>>
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=sensor.wind_direction, old_state=None, new_state=<state sensor.wind_direction=25; unit_of_measurement=°, friendly_name=Wind Direction @ 2021-05-12T16:02:30.008486+00:00>>
DEBUG:homeassistant.components.prometheus:Handling state update for sensor.television_energy
DEBUG:homeassistant.components.prometheus:Handling state update for sensor.radio_energy
DEBUG:homeassistant.components.prometheus:Handling state update for sensor.electricity_price
DEBUG:homeassistant.components.prometheus:Handling state update for sensor.wind_direction
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=sensor.sps30_pm_1um_weight_concentration, old_state=None, new_state=<state sensor.sps30_pm_1um_weight_concentration=3.7069; unit_of_measurement=µg/m³, friendly_name=SPS30 PM <1µm Weight concentration @ 2021-05-12T16:02:30.042774+00:00>>
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=humidifier.humidifier, old_state=None, new_state=<state humidifier.humidifier=on; min_humidity=0, max_humidity=100, humidity=68, friendly_name=Humidifier, supported_features=0, device_class=humidifier @ 2021-05-12T16:02:30.048191+00:00>>
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=humidifier.dehumidifier, old_state=None, new_state=<state humidifier.dehumidifier=on; min_humidity=0, max_humidity=100, humidity=54, friendly_name=Dehumidifier, supported_features=0, device_class=dehumidifier @ 2021-05-12T16:02:30.049812+00:00>>
DEBUG:homeassistant.core:Bus:Handling <Event state_changed[L]: entity_id=humidifier.hygrostat, old_state=None, new_state=<state humidifier.hygrostat=on; min_humidity=0, max_humidity=100, available_modes=['home', 'eco'], humidity=50, mode=home, friendly_name=Hygrostat, supported_features=1 @ 2021-05-12T16:02:30.051561+00:00>>
DEBUG:homeassistant.components.http.auth:Authenticated 127.0.0.1 for /api/prometheus using bearer token
DEBUG:homeassistant.components.prometheus:Handling state update for sensor.sps30_pm_1um_weight_concentration
DEBUG:homeassistant.components.http.view:Serving /api/prometheus to 127.0.0.1 (auth: True)
DEBUG:homeassistant.components.prometheus:Handling state update for humidifier.hygrostat
DEBUG:homeassistant.components.prometheus:Handling state update for humidifier.dehumidifier
DEBUG:homeassistant.components.prometheus:Handling state update for humidifier.humidifier
DEBUG:homeassistant.components.prometheus:Received Prometheus metrics request
INFO:aiohttp.access:127.0.0.1 [12/May/2021:16:02:30 +0000] "GET /api/prometheus HTTP/1.1" 200 12216 "-" "Python/3.8 aiohttp/3.7.4.post0"
------------------------------ Captured log call -------------------------------
INFO     homeassistant.loader:loader.py:344 Loaded prometheus from homeassistant.components.prometheus
INFO     homeassistant.loader:loader.py:344 Loaded http from homeassistant.components.http
DEBUG    homeassistant.setup:setup.py:130 Dependency prometheus will wait for dependencies ['http']
INFO     homeassistant.setup:setup.py:217 Setting up http
INFO     homeassistant.setup:setup.py:265 Setup of domain http took 0.0 seconds
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event component_loaded[L]: component=http>
INFO     homeassistant.setup:setup.py:217 Setting up prometheus
INFO     homeassistant.setup:setup.py:265 Setup of domain prometheus took 0.0 seconds
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event component_loaded[L]: component=prometheus>
INFO     homeassistant.loader:loader.py:344 Loaded sensor from homeassistant.components.sensor
INFO     homeassistant.loader:loader.py:344 Loaded demo from homeassistant.components.demo
INFO     homeassistant.setup:setup.py:217 Setting up sensor
INFO     homeassistant.setup:setup.py:265 Setup of domain sensor took 0.0 seconds
DEBUG    homeassistant.setup:setup.py:130 Dependency demo will wait for dependencies ['conversation', 'zone', 'group']
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event component_loaded[L]: component=sensor>
INFO     homeassistant.loader:loader.py:344 Loaded conversation from homeassistant.components.conversation
INFO     homeassistant.loader:loader.py:344 Loaded zone from homeassistant.components.zone
INFO     homeassistant.setup:setup.py:217 Setting up conversation
INFO     homeassistant.loader:loader.py:344 Loaded group from homeassistant.components.group
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=conversation, service=process>
INFO     homeassistant.setup:setup.py:265 Setup of domain conversation took 0.0 seconds
INFO     homeassistant.loader:loader.py:344 Loaded climate from homeassistant.components.climate
INFO     homeassistant.setup:setup.py:217 Setting up zone
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event component_loaded[L]: component=conversation>
INFO     homeassistant.setup:setup.py:217 Setting up group
INFO     homeassistant.setup:setup.py:217 Setting up climate
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=climate, service=turn_on>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=climate, service=turn_off>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=climate, service=set_hvac_mode>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=climate, service=set_preset_mode>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=climate, service=set_aux_heat>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=climate, service=set_temperature>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=climate, service=set_humidity>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=climate, service=set_fan_mode>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=climate, service=set_swing_mode>
INFO     homeassistant.setup:setup.py:265 Setup of domain climate took 0.0 seconds
DEBUG    homeassistant.setup:setup.py:130 Dependency demo will wait for dependencies ['zone', 'group']
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event component_loaded[L]: component=climate>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=group, service=reload>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=group, service=set>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=group, service=remove>
INFO     homeassistant.setup:setup.py:265 Setup of domain group took 0.1 seconds
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=zone, service=reload>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event component_loaded[L]: component=group>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=zone.home, old_state=None, new_state=<state zone.home=zoning; latitude=32.87336, longitude=-117.22743, radius=100, passive=False, editable=True, friendly_name=test home, icon=mdi:home @ 2021-05-12T16:02:29.918726+00:00>>
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for zone.home
INFO     homeassistant.setup:setup.py:265 Setup of domain zone took 0.1 seconds
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event component_loaded[L]: component=zone>
INFO     homeassistant.setup:setup.py:217 Setting up demo
INFO     homeassistant.setup:setup.py:265 Setup of domain demo took 0.0 seconds
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event component_loaded[L]: component=demo>
INFO     homeassistant.components.sensor:entity_platform.py:217 Setting up sensor.demo
INFO     homeassistant.components.climate:entity_platform.py:217 Setting up climate.demo
INFO     homeassistant.helpers.entity_registry:entity_registry.py:297 Registered new sensor.demo entity: sensor.outside_temperature
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event entity_registry_updated[L]: action=create, entity_id=sensor.outside_temperature>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=sensor.outside_temperature, old_state=None, new_state=<state sensor.outside_temperature=15.6; battery_level=12, unit_of_measurement=°C, friendly_name=Outside Temperature, device_class=temperature @ 2021-05-12T16:02:29.931161+00:00>>
INFO     homeassistant.helpers.entity_registry:entity_registry.py:297 Registered new sensor.demo entity: sensor.outside_humidity
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event entity_registry_updated[L]: action=create, entity_id=sensor.outside_humidity>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=sensor.outside_humidity, old_state=None, new_state=<state sensor.outside_humidity=54; unit_of_measurement=%, friendly_name=Outside Humidity, device_class=humidity @ 2021-05-12T16:02:29.933965+00:00>>
INFO     homeassistant.helpers.entity_registry:entity_registry.py:297 Registered new sensor.demo entity: sensor.carbon_monoxide
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for sensor.outside_humidity
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event entity_registry_updated[L]: action=create, entity_id=sensor.carbon_monoxide>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=sensor.carbon_monoxide, old_state=None, new_state=<state sensor.carbon_monoxide=54; unit_of_measurement=ppm, friendly_name=Carbon monoxide, device_class=carbon_monoxide @ 2021-05-12T16:02:29.954947+00:00>>
INFO     homeassistant.helpers.entity_registry:entity_registry.py:297 Registered new sensor.demo entity: sensor.carbon_dioxide
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for sensor.carbon_monoxide
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event entity_registry_updated[L]: action=create, entity_id=sensor.carbon_dioxide>
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for sensor.outside_temperature
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=sensor.carbon_dioxide, old_state=None, new_state=<state sensor.carbon_dioxide=54; battery_level=14, unit_of_measurement=ppm, friendly_name=Carbon dioxide, device_class=carbon_dioxide @ 2021-05-12T16:02:29.958608+00:00>>
INFO     homeassistant.helpers.entity_registry:entity_registry.py:297 Registered new climate.demo entity: climate.heatpump
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event entity_registry_updated[L]: action=create, entity_id=climate.heatpump>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=climate.heatpump, old_state=None, new_state=<state climate.heatpump=heat; hvac_modes=['heat', 'off'], min_temp=7.0, max_temp=35.0, current_temperature=25.0, temperature=20.0, hvac_action=heating, friendly_name=HeatPump, supported_features=1 @ 2021-05-12T16:02:29.970499+00:00>>
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for sensor.carbon_dioxide
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for climate.heatpump
INFO     homeassistant.helpers.entity_registry:entity_registry.py:297 Registered new climate.demo entity: climate.hvac
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event entity_registry_updated[L]: action=create, entity_id=climate.hvac>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=climate.hvac, old_state=None, new_state=<state climate.hvac=cool; hvac_modes=['off', 'heat', 'cool', 'auto', 'dry', 'fan_only'], min_temp=7, max_temp=35, min_humidity=30, max_humidity=99, fan_modes=['On Low', 'On High', 'Auto Low', 'Auto High', 'Off'], swing_modes=['Auto', '1', '2', '3', 'Off'], current_temperature=22, temperature=21, target_temp_high=None, target_temp_low=None, current_humidity=54, humidity=67, fan_mode=On High, hvac_action=cooling, swing_mode=Off, aux_heat=off, friendly_name=Hvac, supported_features=111 @ 2021-05-12T16:02:29.980988+00:00>>
INFO     homeassistant.helpers.entity_registry:entity_registry.py:297 Registered new climate.demo entity: climate.ecobee
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event entity_registry_updated[L]: action=create, entity_id=climate.ecobee>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=climate.ecobee, old_state=None, new_state=<state climate.ecobee=heat_cool; hvac_modes=['heat_cool', 'cool', 'heat'], min_temp=7, max_temp=35, fan_modes=['On Low', 'On High', 'Auto Low', 'Auto High', 'Off'], preset_modes=['home', 'eco'], swing_modes=['Auto', '1', '2', '3', 'Off'], current_temperature=23, target_temp_high=24, target_temp_low=21, fan_mode=Auto Low, preset_mode=home, swing_mode=Auto, friendly_name=Ecobee, supported_features=58 @ 2021-05-12T16:02:29.984441+00:00>>
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for climate.hvac
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for climate.ecobee
INFO     homeassistant.loader:loader.py:344 Loaded humidifier from homeassistant.components.humidifier
INFO     homeassistant.setup:setup.py:217 Setting up humidifier
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=humidifier, service=turn_on>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=humidifier, service=turn_off>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=humidifier, service=toggle>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=humidifier, service=set_mode>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event service_registered[L]: domain=humidifier, service=set_humidity>
INFO     homeassistant.setup:setup.py:265 Setup of domain humidifier took 0.0 seconds
INFO     homeassistant.components.humidifier:entity_platform.py:217 Setting up humidifier.demo
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event component_loaded[L]: component=humidifier>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=sensor.television_energy, old_state=None, new_state=<state sensor.television_energy=74; unit_of_measurement=kWh, friendly_name=Television Energy @ 2021-05-12T16:02:30.004051+00:00>>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=sensor.radio_energy, old_state=None, new_state=<state sensor.radio_energy=14; unit_of_measurement=kWh, friendly_name=Radio Energy, device_class=power @ 1970-01-02T00:00:00+00:00>>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=sensor.electricity_price, old_state=None, new_state=<state sensor.electricity_price=0.123; unit_of_measurement=SEK/kWh, friendly_name=Electricity price @ 2021-05-12T16:02:30.007311+00:00>>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=sensor.wind_direction, old_state=None, new_state=<state sensor.wind_direction=25; unit_of_measurement=°, friendly_name=Wind Direction @ 2021-05-12T16:02:30.008486+00:00>>
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for sensor.television_energy
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for sensor.radio_energy
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for sensor.electricity_price
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for sensor.wind_direction
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=sensor.sps30_pm_1um_weight_concentration, old_state=None, new_state=<state sensor.sps30_pm_1um_weight_concentration=3.7069; unit_of_measurement=µg/m³, friendly_name=SPS30 PM <1µm Weight concentration @ 2021-05-12T16:02:30.042774+00:00>>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=humidifier.humidifier, old_state=None, new_state=<state humidifier.humidifier=on; min_humidity=0, max_humidity=100, humidity=68, friendly_name=Humidifier, supported_features=0, device_class=humidifier @ 2021-05-12T16:02:30.048191+00:00>>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=humidifier.dehumidifier, old_state=None, new_state=<state humidifier.dehumidifier=on; min_humidity=0, max_humidity=100, humidity=54, friendly_name=Dehumidifier, supported_features=0, device_class=dehumidifier @ 2021-05-12T16:02:30.049812+00:00>>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event state_changed[L]: entity_id=humidifier.hygrostat, old_state=None, new_state=<state humidifier.hygrostat=on; min_humidity=0, max_humidity=100, available_modes=['home', 'eco'], humidity=50, mode=home, friendly_name=Hygrostat, supported_features=1 @ 2021-05-12T16:02:30.051561+00:00>>
DEBUG    homeassistant.components.http.auth:auth.py:127 Authenticated 127.0.0.1 for /api/prometheus using bearer token
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for sensor.sps30_pm_1um_weight_concentration
DEBUG    homeassistant.components.http.view:view.py:120 Serving /api/prometheus to 127.0.0.1 (auth: True)
DEBUG    homeassistant.components.prometheus:__init__.py:491 Received Prometheus metrics request
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for humidifier.hygrostat
INFO     aiohttp.access:web_log.py:206 127.0.0.1 [12/May/2021:16:02:30 +0000] "GET /api/prometheus HTTP/1.1" 200 12216 "-" "Python/3.8 aiohttp/3.7.4.post0"
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for humidifier.dehumidifier
DEBUG    homeassistant.components.prometheus:__init__.py:152 Handling state update for humidifier.humidifier
--------------------------- Captured stderr teardown ---------------------------
DEBUG:homeassistant.core:Bus:Handling <Event homeassistant_stop[L]>
DEBUG:homeassistant.core:Bus:Handling <Event homeassistant_final_write[L]>
INFO:tests.common:Writing data to auth: {'version': 1, 'key': 'auth', 'data': {'users': [{'id': '7addd24334454b2fa200bec8bca48fb7', 'group_ids': ['system-admin'], 'is_owner': False, 'is_active': True, 'name': 'Mock User', 'system_generated': False}], 'groups': [{'id': 'system-admin', 'name': 'Administrators'}, {'id': 'system-users', 'name': 'Users'}, {'id': 'system-read-only', 'name': 'Read Only'}], 'credentials': [{'id': 'mock-credential-id', 'user_id': '7addd24334454b2fa200bec8bca48fb7', 'auth_provider_type': 'homeassistant', 'auth_provider_id': None, 'data': {'username': 'admin'}}], 'refresh_tokens': [{'id': '6c4c17c1d99848ef922f8e3d91e047e8', 'user_id': '7addd24334454b2fa200bec8bca48fb7', 'client_id': 'https://example.com/app', 'client_name': None, 'client_icon': None, 'token_type': 'normal', 'created_at': '2021-05-12T16:02:29.787536+00:00', 'access_token_expiration': 1800.0, 'token': 'f6360b0454c9a629a55879cf598e44469f96fb84ba590a4e1b54a096289b4fa65ab044f54d56ef38cfac698c26840e6025a67062ca3fc8bfa324093451bf12eb', 'jwt_key': 'e15fba373768d8be7a4c3b4055213e5fa6a9e443bcfe406e519b91f38cffc1fcf8463ffa86ec5b8824591f123f6f7059a4c15dcfcd30db3a673c3b9da4dd9dd3', 'last_used_at': '2021-05-12T16:02:29.787737+00:00', 'last_used_ip': None, 'credential_id': 'mock-credential-id', 'version': '2021.5.3'}]}}
INFO:tests.common:Writing data to core.entity_registry: {'version': 1, 'key': 'core.entity_registry', 'data': {'entities': [{'entity_id': 'sensor.outside_temperature', 'config_entry_id': None, 'device_id': None, 'area_id': None, 'unique_id': 'sensor_1', 'platform': 'demo', 'name': None, 'icon': None, 'disabled_by': None, 'capabilities': None, 'supported_features': 0, 'device_class': 'temperature', 'unit_of_measurement': '°C', 'original_name': 'Outside Temperature', 'original_icon': None}, {'entity_id': 'sensor.outside_humidity', 'config_entry_id': None, 'device_id': None, 'area_id': None, 'unique_id': 'sensor_2', 'platform': 'demo', 'name': None, 'icon': None, 'disabled_by': None, 'capabilities': None, 'supported_features': 0, 'device_class': 'humidity', 'unit_of_measurement': '%', 'original_name': 'Outside Humidity', 'original_icon': None}, {'entity_id': 'sensor.carbon_monoxide', 'config_entry_id': None, 'device_id': None, 'area_id': None, 'unique_id': 'sensor_3', 'platform': 'demo', 'name': None, 'icon': None, 'disabled_by': None, 'capabilities': None, 'supported_features': 0, 'device_class': 'carbon_monoxide', 'unit_of_measurement': 'ppm', 'original_name': 'Carbon monoxide', 'original_icon': None}, {'entity_id': 'sensor.carbon_dioxide', 'config_entry_id': None, 'device_id': None, 'area_id': None, 'unique_id': 'sensor_4', 'platform': 'demo', 'name': None, 'icon': None, 'disabled_by': None, 'capabilities': None, 'supported_features': 0, 'device_class': 'carbon_dioxide', 'unit_of_measurement': 'ppm', 'original_name': 'Carbon dioxide', 'original_icon': None}, {'entity_id': 'climate.heatpump', 'config_entry_id': None, 'device_id': None, 'area_id': None, 'unique_id': 'climate_1', 'platform': 'demo', 'name': None, 'icon': None, 'disabled_by': None, 'capabilities': {'hvac_modes': ['heat', 'off'], 'min_temp': 7.0, 'max_temp': 35.0}, 'supported_features': 1, 'device_class': None, 'unit_of_measurement': None, 'original_name': 'HeatPump', 'original_icon': None}, {'entity_id': 'climate.hvac', 'config_entry_id': None, 'device_id': None, 'area_id': None, 'unique_id': 'climate_2', 'platform': 'demo', 'name': None, 'icon': None, 'disabled_by': None, 'capabilities': {'hvac_modes': ['off', 'heat', 'cool', 'auto', 'dry', 'fan_only'], 'min_temp': 7, 'max_temp': 35, 'min_humidity': 30, 'max_humidity': 99, 'fan_modes': ['On Low', 'On High', 'Auto Low', 'Auto High', 'Off'], 'swing_modes': ['Auto', '1', '2', '3', 'Off']}, 'supported_features': 111, 'device_class': None, 'unit_of_measurement': None, 'original_name': 'Hvac', 'original_icon': None}, {'entity_id': 'climate.ecobee', 'config_entry_id': None, 'device_id': None, 'area_id': None, 'unique_id': 'climate_3', 'platform': 'demo', 'name': None, 'icon': None, 'disabled_by': None, 'capabilities': {'hvac_modes': ['heat_cool', 'cool', 'heat'], 'min_temp': 7, 'max_temp': 35, 'fan_modes': ['On Low', 'On High', 'Auto Low', 'Auto High', 'Off'], 'preset_modes': ['home', 'eco'], 'swing_modes': ['Auto', '1', '2', '3', 'Off']}, 'supported_features': 58, 'device_class': None, 'unit_of_measurement': None, 'original_name': 'Ecobee', 'original_icon': None}]}}
DEBUG:homeassistant.core:Bus:Handling <Event homeassistant_close[L]>
---------------------------- Captured log teardown -----------------------------
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event homeassistant_stop[L]>
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event homeassistant_final_write[L]>
INFO     tests.common:common.py:1013 Writing data to auth: {'version': 1, 'key': 'auth', 'data': {'users': [{'id': '7addd24334454b2fa200bec8bca48fb7', 'group_ids': ['system-admin'], 'is_owner': False, 'is_active': True, 'name': 'Mock User', 'system_generated': False}], 'groups': [{'id': 'system-admin', 'name': 'Administrators'}, {'id': 'system-users', 'name': 'Users'}, {'id': 'system-read-only', 'name': 'Read Only'}], 'credentials': [{'id': 'mock-credential-id', 'user_id': '7addd24334454b2fa200bec8bca48fb7', 'auth_provider_type': 'homeassistant', 'auth_provider_id': None, 'data': {'username': 'admin'}}], 'refresh_tokens': [{'id': '6c4c17c1d99848ef922f8e3d91e047e8', 'user_id': '7addd24334454b2fa200bec8bca48fb7', 'client_id': 'https://example.com/app', 'client_name': None, 'client_icon': None, 'token_type': 'normal', 'created_at': '2021-05-12T16:02:29.787536+00:00', 'access_token_expiration': 1800.0, 'token': 'f6360b0454c9a629a55879cf598e44469f96fb84ba590a4e1b54a096289b4fa65ab044f54d56ef38cfac698c26840e6025a67062ca3fc8bfa324093451bf12eb', 'jwt_key': 'e15fba373768d8be7a4c3b4055213e5fa6a9e443bcfe406e519b91f38cffc1fcf8463ffa86ec5b8824591f123f6f7059a4c15dcfcd30db3a673c3b9da4dd9dd3', 'last_used_at': '2021-05-12T16:02:29.787737+00:00', 'last_used_ip': None, 'credential_id': 'mock-credential-id', 'version': '2021.5.3'}]}}
INFO     tests.common:common.py:1013 Writing data to core.entity_registry: {'version': 1, 'key': 'core.entity_registry', 'data': {'entities': [{'entity_id': 'sensor.outside_temperature', 'config_entry_id': None, 'device_id': None, 'area_id': None, 'unique_id': 'sensor_1', 'platform': 'demo', 'name': None, 'icon': None, 'disabled_by': None, 'capabilities': None, 'supported_features': 0, 'device_class': 'temperature', 'unit_of_measurement': '°C', 'original_name': 'Outside Temperature', 'original_icon': None}, {'entity_id': 'sensor.outside_humidity', 'config_entry_id': None, 'device_id': None, 'area_id': None, 'unique_id': 'sensor_2', 'platform': 'demo', 'name': None, 'icon': None, 'disabled_by': None, 'capabilities': None, 'supported_features': 0, 'device_class': 'humidity', 'unit_of_measurement': '%', 'original_name': 'Outside Humidity', 'original_icon': None}, {'entity_id': 'sensor.carbon_monoxide', 'config_entry_id': None, 'device_id': None, 'area_id': None, 'unique_id': 'sensor_3', 'platform': 'demo', 'name': None, 'icon': None, 'disabled_by': None, 'capabilities': None, 'supported_features': 0, 'device_class': 'carbon_monoxide', 'unit_of_measurement': 'ppm', 'original_name': 'Carbon monoxide', 'original_icon': None}, {'entity_id': 'sensor.carbon_dioxide', 'config_entry_id': None, 'device_id': None, 'area_id': None, 'unique_id': 'sensor_4', 'platform': 'demo', 'name': None, 'icon': None, 'disabled_by': None, 'capabilities': None, 'supported_features': 0, 'device_class': 'carbon_dioxide', 'unit_of_measurement': 'ppm', 'original_name': 'Carbon dioxide', 'original_icon': None}, {'entity_id': 'climate.heatpump', 'config_entry_id': None, 'device_id': None, 'area_id': None, 'unique_id': 'climate_1', 'platform': 'demo', 'name': None, 'icon': None, 'disabled_by': None, 'capabilities': {'hvac_modes': ['heat', 'off'], 'min_temp': 7.0, 'max_temp': 35.0}, 'supported_features': 1, 'device_class': None, 'unit_of_measurement': None, 'original_name': 'HeatPump', 'original_icon': None}, {'entity_id': 'climate.hvac', 'config_entry_id': None, 'device_id': None, 'area_id': None, 'unique_id': 'climate_2', 'platform': 'demo', 'name': None, 'icon': None, 'disabled_by': None, 'capabilities': {'hvac_modes': ['off', 'heat', 'cool', 'auto', 'dry', 'fan_only'], 'min_temp': 7, 'max_temp': 35, 'min_humidity': 30, 'max_humidity': 99, 'fan_modes': ['On Low', 'On High', 'Auto Low', 'Auto High', 'Off'], 'swing_modes': ['Auto', '1', '2', '3', 'Off']}, 'supported_features': 111, 'device_class': None, 'unit_of_measurement': None, 'original_name': 'Hvac', 'original_icon': None}, {'entity_id': 'climate.ecobee', 'config_entry_id': None, 'device_id': None, 'area_id': None, 'unique_id': 'climate_3', 'platform': 'demo', 'name': None, 'icon': None, 'disabled_by': None, 'capabilities': {'hvac_modes': ['heat_cool', 'cool', 'heat'], 'min_temp': 7, 'max_temp': 35, 'fan_modes': ['On Low', 'On High', 'Auto Low', 'Auto High', 'Off'], 'preset_modes': ['home', 'eco'], 'swing_modes': ['Auto', '1', '2', '3', 'Off']}, 'supported_features': 58, 'device_class': None, 'unit_of_measurement': None, 'original_name': 'Ecobee', 'original_icon': None}]}}
DEBUG    homeassistant.core:core.py:709 Bus:Handling <Event homeassistant_close[L]>

(cherry picked from commit df1bf616ae)
2021-05-26 04:54:13 +02:00
Izorkin
65d4fff84d nginxMainline: 1.20.0 -> 1.21.0
(cherry picked from commit 0a7feef809)
2021-05-25 14:52:24 -07:00
Izorkin
6e4f30b5a0 nginxStable: 1.20.0 -> 1.20.1
(cherry picked from commit 919dd5497a)
2021-05-25 14:52:24 -07:00
Michael Weiss
f75079b072 chromium: 90.0.4430.212 -> 91.0.4472.77
https://chromereleases.googleblog.com/2021/05/stable-channel-update-for-desktop_25.html

This update includes 32 security fixes.

CVEs:
CVE-2021-30521 CVE-2021-30522 CVE-2021-30523 CVE-2021-30524
CVE-2021-30525 CVE-2021-30526 CVE-2021-30527 CVE-2021-30528
CVE-2021-30529 CVE-2021-30530 CVE-2021-30531 CVE-2021-30532
CVE-2021-30533 CVE-2021-30534 CVE-2021-30535 CVE-2021-21212
CVE-2021-30536 CVE-2021-30537 CVE-2021-30538 CVE-2021-30539
CVE-2021-30540

(cherry picked from commit e522464f9a)
2021-05-25 14:48:06 -07:00
Martin Weinelt
0a1ddb21f2 Merge pull request #124395 from mweinelt/21.05/python/pywemo
[21.05] python3Packages.pywemo: disable failing test
2021-05-25 23:27:11 +02:00
Milan Pässler
a555872f04 gitlab: 13.11.2 -> 13.12.0
(cherry picked from commit 1ded8ef44e)
2021-05-25 23:00:11 +02:00
Milan Pässler
8418b1397c gitlab: add Gemfile fix to update script
Since some GitLab versions, we need to remove the mail-smtp-pool
dependency from the Gemfile, or do other modifications.
Let's add those changes, that will probably be needed in the next
version as well, to the update script.

(cherry picked from commit 0c8f5b7b44)
2021-05-25 23:00:11 +02:00
lunik1
e3f7168d86 libretro.ppsspp: update to v1.11 and fix build againt ffmpeg 4.4
(cherry picked from commit a5a5088eae)
2021-05-25 16:49:02 +01:00
Zane van Iperen
92e46f3619 navidrome: 0.42.1 -> 0.43.0
(cherry picked from commit 88305beb43)
2021-05-25 08:46:47 -07:00
Martin Weinelt
ab28c480e2 Merge pull request #124326 from sumnerevans/element-1.7.29-backport-21.05
element: 1.7.28 -> 1.7.29 (backport to 21.05)
2021-05-25 17:37:58 +02:00
Martin Weinelt
60c98baf17 python3Packages.pywemo: disable failing test
With libxml2 2.9.12 this test started failing, it was reported upstream
at https://github.com/pywemo/pywemo/issues/268.

(cherry picked from commit a0160c0ae8)
2021-05-25 17:33:29 +02:00
Sumner Evans
c2e9a51cdc element: 1.7.28 -> 1.7.29
(cherry picked from commit cdd56a425c)
2021-05-25 09:22:35 -06:00
Jörg Thalheim
bc71efad3e Merge pull request #124312 from tomfitzhenry/backport-serial-port-docs
[21.05] nixos/manual: document how to install over a serial port
2021-05-25 08:29:17 +01:00
Michael Lingelbach
3f0d62871e girara: fix build on darwin (#124337)
(cherry picked from commit 34a84c4b0e)
2021-05-25 03:15:04 -04:00
Jonathan Ringer
7e49e3ea89 Merge remote-tracking branch 'origin/release-21.05' into staging-next-21.05 2021-05-25 00:02:45 -07:00
Jan Tojnar
1b1608a7b8 libxml2: Work around lxml API misuse
(cherry picked from commit 7099f24c4a)
2021-05-24 23:56:08 -07:00
Jonathan Ringer
befda3568c exempi: disable tests for i686
Unable to find boost unittest framework.

Tests are still ran on the x86_64 platform

(cherry picked from commit 266f6ee63a)
2021-05-24 23:53:37 -07:00
Luka Blaskovic
76e136bb5e rustc: 1_52, use correct llvm version 2021-05-24 23:47:14 -07:00
Graham Christensen
b3a9a3e19f terraform-providers.hydra: 0.1.0 -> 0.1.1
(cherry picked from commit 0e91b031f6)
2021-05-24 18:27:24 -07:00
Tom Fitzhenry
3c0ee5ac10 nixos/manual: document how to install over a serial port
https://github.com/NixOS/nixpkgs/issues/58198
(cherry picked from commit 81e04717e8)
2021-05-25 08:46:20 +10:00
Arnout Engelen
0ef2fe6f77 Merge pull request #124180 from Atemu/backport/minimalIso-remove-ruby2.7
[21.05] minimalIso: remove ruby2.7
2021-05-24 22:29:22 +02:00
Gabriel Ebner
b7f77e07b2 Merge pull request #124272 from gebner/ccls-headers-2105
[21.05] ccls: fix libc++ header path
2021-05-24 18:47:29 +02:00
Gabriel Ebner
baedf2c785 ccls: fix libc++ header path
(cherry picked from commit eef236e8ef)
2021-05-24 17:44:27 +02:00
Domen Kožar
0ae5309111 Merge pull request #124258 from domenkozar/revert-sandbox-path-21.05
Revert "nixos/nix-daemon: fix sandbox-paths option"
2021-05-24 15:37:55 +02:00
regnat
0cebbdf687 Revert "nixos/nix-daemon: fix sandbox-paths option"
This reverts commit aeeee447bc.

(cherry picked from commit 113823669b)
Signed-off-by: Domen Kožar <domen@dev.si>
2021-05-24 15:20:58 +02:00
Michael Weiss
97b94af4eb Merge pull request #124182 from primeos/signal-desktop-backport
[21.05] Revert "signal-desktop: Add a Python wrapper to re-encrypt DBs"
2021-05-24 14:50:37 +02:00
Mario Rodas
3cb8557ce1 Merge pull request #124229 from LeSuisse/redis-6.2.3-21.05
[21.05] redis: 6.2.1 -> 6.2.3
2021-05-24 04:39:06 -05:00
Maximilian Bosch
a4b270df3a Merge pull request #124231 from talyz/21.05-php-dom
[21.05] phpExtensions.dom: fix build
2021-05-24 10:50:16 +02:00
Maximilian Bosch
2bffd5fef9 phpExtensions.dom: fix build
ZHF #122042

(cherry picked from commit 53951c0c14)
2021-05-24 09:24:47 +02:00
Jörg Thalheim
0c67f4a204 odp-dpdk: 1.22.0.0_DPDK_18.11 -> 1.27.0.0_DPDK_19.11
(cherry picked from commit b50d58d988)
2021-05-24 09:18:28 +02:00
Jörg Thalheim
c443ac73f2 pktgen: 19.12.0 -> 21.05.0
(cherry picked from commit 9d002b110e)
2021-05-24 09:18:27 +02:00
Jörg Thalheim
ee76949241 spdk: 20.04.1 -> 21.04
(cherry picked from commit 00a7a0f609)
2021-05-24 09:18:27 +02:00
Jörg Thalheim
40b3403d59 dpdk: 20.05 -> 21.02
(cherry picked from commit a443ea7d01)
2021-05-24 09:18:26 +02:00
Thomas Gerbet
35f631618f redis: 6.2.1 -> 6.2.3
Fixes CVE-2021-29477 and CVE-2021-29478.

https://github.com/redis/redis/blob/6.2.3/00-RELEASENOTES
(cherry picked from commit 0d1b14161a)
2021-05-24 08:44:43 +02:00
Atemu
d77ece7e27 Revert "git: Use asciidoctor instead of asciidoc for manpages"
This reverts commit bbf96d898b.

Removes dependency on ruby 2.7 and isn't much slower.

See https://github.com/NixOS/nixpkgs/pull/123502 for more info

(cherry picked from commit 88c2c543bf)
2021-05-23 22:04:26 +02:00
Atemu
036b557bd9 libndctl: build docs with asciidoc instead of asciidoctor
Removes dependency on ruby 2.7 and isn't much slower

(cherry picked from commit 786579c0b8)
2021-05-23 22:04:25 +02:00
Kerstin Humm
ecff4216d5 imagemagick: 7.0.11-12 -> 7.0.11.13
(cherry picked from commit c2521a6b36)
2021-05-23 09:51:43 -07:00
Kerstin Humm
b0eb9dfebb imagemagick: 7.0.11-9 -> 7.0.11-12
(cherry picked from commit 1738b9877a)
2021-05-23 09:51:43 -07:00
John Ericson
62f3f8954c Merge pull request #124149 from sternenseemann/pkg-config-mangling-21.05
[21.05] pkg-config-wrapper: mangle PKG_CONFIG_PATH{,_FOR_BUILD} correctly
2021-05-23 09:41:39 -07:00
John Ericson
e3dc52bcb2 Merge pull request #124150 from sternenseemann/clang-fix-llvmgold-path-21.05
[21.05] llvmPackages*.clang: fix linker invocation with LLVMgold plugin
2021-05-23 09:26:29 -07:00
Kim Lindberger
df25a8867f Merge pull request #124138 from talyz/21.05-php-iconv-errno
[21.05] php74.extensions.iconv: fix error signalling
2021-05-23 17:48:31 +02:00
Robert Scott
0548d93697 Merge pull request #124145 from dotlambda/igraph-arpack-darwin-blas-paths
[21.05] igraph,arpack: correct libblas.dylib's path on darwin, fixing python3Packages.python-igraph
2021-05-23 16:02:09 +01:00
Guillaume Girol
bfa9bc365d Merge pull request #124148 from hyperfekt/mount-pstore-quiet
nixos/filesystems: condition mount-pstore.service on unmounted /sys/fs/pstore (once more)
2021-05-23 13:52:37 +00:00
Guillaume Girol
1c1e5094d9 Merge pull request #123902 from hyperfekt/mount-pstore-quiet
nixos/filesystems: condition mount-pstore.service on unmounted /sys/fs/pstore

(cherry picked from commit d7555732bc)

Reason: activation throws an error from failing to start the unit
2021-05-23 15:04:41 +02:00
sternenseemann
3a165fda92 llvmPackages*.clang: fix linker invocation with LLVMgold plugin
When using GNU binutils, clang passes the LLVMgold.so plugin to the
linker for certain operations that require special support in the linker
like doing link time optimization (LTO). When passing the plugin to the
linker's command line, clang assumes that llvm and itself are installed
in the same prefix and thus `/path/to/clang/bin/../lib/LLVMgold.so` is
the plugin.

Since we install clang and llvm to separate store paths, this assumption
does not hold. When clang-unwrapped only had a single output, we worked
around this issue by symlinking `$out/lib/LLVMgold.so` to
`${llvm}/lib/LLVMgold.so`. However since we split all llvm packages into
multiple outputs clang's `$out` no longer has a lib directory and clang
can't discover clangs lib output on its own. As a result LTO was broken.

Instead of introducing yet another hack and having a symlink to
LLVMgold.so in `$out/lib` (despite having `$lib/lib` as well), we patch
clang to use a hard coded path to `${libllvm.lib}/lib` for discovering
`LLVMgold.so`.

Resolves #123361.

(cherry picked from commit 3530837417)
2021-05-23 14:48:58 +02:00
sternenseemann
771d69953d pkg-config-wrapper: mangle PKG_CONFIG_PATH{,_FOR_BUILD} correctly
Previously, mangleVarList would be used which would concatenate the
variables using a space as a separator. Paths are however separated by
`:` in PKG_CONFIG_PATH leading to entries being broken.

This is fixed by introducing mangleVarListGeneric which allows us to
specify the desired separator.

Reproducer for the issue prior to this change:

    $ nix-shell -A pkgsLLVM.wayland
    [nix-shell] $ pkg-config --libs expat
    Package expat was not found in the pkg-config search path.
    Perhaps you should add the directory containing `expat.pc'
    to the PKG_CONFIG_PATH environment variable
    No package 'expat' found
    $ printf 'Host: %s\nBuild: %s' $PKG_CONFIG_PATH $PKG_CONFIG_PATH_FOR_BUILD
    Host: /nix/store/5h308a4ab8w7prcp8iflh5pnl78mayi2-expat-2.2.10-x86_64-unknown-linux-gnu-dev/lib/pkgconfig:/nix/store/z3y9ska2h4l1map25m195iq577g7g3gz-libxml2-x86_64-unknown-linux-gnu-2.9.12-dev/lib/pkgconfig:/nix/store/lbz5m1s0r7zn0cxvl21czfspli6ribzb-zlib-1.2.11-x86_64-unknown-linux-gnu-dev/lib/pkgconfig:/nix/store/rfhvp8r8n3ygpzh8j0l34lk8hwwi3z0h-libffi-3.3-x86_64-unknown-linux-gnu-dev/lib/pkgconfig
    Build: /nix/store/dw11ywy7qwfz53qisz0dggbgix88jah2-wayland-1.19.0-bin/lib/pkgconfig

strace reveals the issue:

    stat("/nix/store/dw11ywy7qwfz53qisz0dggbgix88jah2-wayland-1.19.0-bin/lib/pkgconfig /nix/store/5h308a4ab8w7prcp8iflh5pnl78mayi2-expat-2.2.10-x86_64-unknown-linux-gnu-dev/lib/pkgconfig/expat-uninstalled.pc", 0x7fff49829fa0) = -1 ENOENT (No such file or directory)

In the pkg-config wrapper $PKG_CONFIG_PATH_FOR_BUILD and
$PKG_CONFIG_PATH are concatenated with a space which leads to two paths
being messed up. This issue likely only affects native cross
compilation.

(cherry picked from commit b11d65c850)
2021-05-23 14:40:00 +02:00
Christian Kögler
7375cb1c0e neovide: Fix build caused by llvm multi output 2021-05-23 14:34:23 +02:00
Robert Scott
b7e6b86c74 igraph: fix libblas.dylib's path on darwin
(cherry picked from commit 73df171f26)
2021-05-23 13:52:32 +02:00
Robert Scott
6514fc8f6b arpack: fix libblas.dylib's path on darwin
(cherry picked from commit 1241d9fae3)
2021-05-23 13:52:32 +02:00
Jan Tojnar
b39ac7cf2b php74.extensions.iconv: fix error signalling
The configure script checks whether iconv supports errno. Unfortunately, on PHP < 8, the test program includes $PHP_ICONV_H_PATH, which defaults to FHS path so it fails to build:

	conftest.c:13:10: fatal error: /usr/include/iconv.h: No such file or directory
	   13 | #include </usr/include/iconv.h>
	      |          ^~~~~~~~~~~~~~~~~~~~~~

That causes the feature check to report a false negative, leading PHP to use a degraded code that returns PHP_ICONV_ERR_UNKNOWN when error occurs, breaking granular error handling in applications.

To prevent this, let’s just include <iconv.h>.

PHP 8 just uses include path so the detection works there: 7bd1d70341

(cherry picked from commit 024243bac4)
2021-05-23 13:13:11 +02:00
Pavol Rusnak
1de0b0e5eb python3Packages.cocotb: 1.5.1 -> 1.5.2
this switches from GitHub to PyPi, because the build requires
a proper release tarball

also PyPi release does contain tests, so we don't strictly require
GitHub checkout

(cherry picked from commit 0f2201119b)
2021-05-23 12:46:56 +02:00
Pavol Rusnak
fadd5dd5ae python3Packages.cocotb-bus: init at 0.1.1
(cherry picked from commit ff555e8f88)
2021-05-23 12:46:48 +02:00
Florian Klink
075ab49dc2 qtwebengine: only set -webengine-webrtc-pipewire with qt >= 5.15
This fails the build of qt514.qtwebengine otherwise:

```
QMAKEPATH=/nix/store/29n056mi3pji6si51b128pa67b1qr7wq-qtbase-5.14.2-dev:/nix/store/g7wady1f1r23wlmy4q1f3b8j2fj5q2sq-qtdeclarative-dev:/nix/store/xfqnh2pma99915d4gsanls68z1jikcpx-qtsvg-dev:/nix/store/zlnsjdj5yv1ivi1miq49j9gp382byl35-qtlocation-dev:/nix/store/lb7cidi60cabpa7swv51xnss9045vqzi-qtmultimedia-dev:/nix/store/jrk6bcqihxwsszwy6rwy2vnfc2sb4rv9-qtwebchannel-dev
qmake PREFIX=/nix/store/pa3jhipp59f6ykh9k8l8z8jf88k52bz8-qtwebengine NIX_OUTPUT_OUT=/nix/store/pa3jhipp59f6ykh9k8l8z8jf88k52bz8-qtwebengine NIX_OUTPUT_DEV=/nix/store/jngs3qilw9iiv97rawb9sb9sd6qdbp2s-qtwebengine-dev NIX_OUTPUT_BIN=/nix/store/91hqv88qvg2wb91lv1h1pd4d8wwrkd5d-qtwebengine-bin NIX_OUTPUT_DOC=/nix/store/jngs3qilw9iiv97rawb9sb9sd6qdbp2s-qtwebengine-dev/share/doc/qt-5.14.2 NIX_OUTPUT_QML=/nix/store/91hqv88qvg2wb91lv1h1pd4d8wwrkd5d-qtwebengine-bin/lib/qt-5.14.2/qml NIX_OUTPUT_PLUGIN=/nix/store/91hqv88qvg2wb91lv1h1pd4d8wwrkd5d-qtwebengine-bin/lib/qt-5.14.2/plugins CONFIG+=release -- -system-ffmpeg -webengine-webrtc-pipewire -proprietary-codecs
Info: creating stash file /build/qtwebengine-everywhere-src-5.14.2/.qmake.stash
Info: creating cache file /build/qtwebengine-everywhere-src-5.14.2/.qmake.cache
ERROR: Unknown command line option '-webengine-webrtc-pipewire'.
builder for '/nix/store/g6dvr7789sswmahlxc6zs5pr8k2g5pgy-qtwebengine.drv' failed with exit code 3
```

Also, only bring in pipewire_0_2 if we enable pipewire support.

(cherry picked from commit 4cbb20402a)
2021-05-23 12:37:07 +02:00
Michael Weiss
13e13349bd Revert "signal-desktop: Add a Python wrapper to re-encrypt DBs"
This reverts commit 45bd7b39a4.

The database for users on NixOS 20.09 is still encrypted so we don't
need this wrapper for users that upgrade from NixOS 20.09 to 21.05.
2021-05-23 11:37:15 +02:00
Vladimír Čunát
ddc60bec55 Merge #123133: curlftpfs: fix sandboxed builds on darwin
(cherry picked from commit 29f57e4752)
2021-05-23 08:19:50 +02:00
Jonathan Ringer
11f5b3279d Merge pull request #124090 from jonringer/backport-staging-next
[21.05] Backport staging next
2021-05-22 19:40:52 -07:00
Jonathan Ringer
8e7956833a Revert "21.11 is Porcupine!"
This reverts commit ff1ded3e20.
2021-05-22 19:08:29 -07:00
Jonathan Ringer
d547493e0c Revert "nixos/doc: add md-to-db.sh, convert "Building Your Own NixOS CD" to CommonMark"
This reverts commit 6c14851943.
2021-05-22 19:08:27 -07:00
Jonathan Ringer
f05e41b6f4 Revert "CODEOWNERS: add ryantm to /nixos/doc"
This reverts commit a67febac45.
2021-05-22 19:08:25 -07:00
Jonathan Ringer
4a974e6695 Revert "nixos/doc: convert "Contributing to this manual" to CommonMark"
This reverts commit 7501467903.
2021-05-22 19:08:23 -07:00
Jonathan Ringer
c294c2fb40 Revert "nixos/doc: add 21.11 release notes stub"
This reverts commit 6543c61311.
2021-05-22 19:08:15 -07:00
Jonathan Ringer
c2bb4bad68 Merge remote-tracking branch 'origin/master' into backport-staging-next
Forgot to merge staging-next into master before branching off.
This is meant to include the additional stabilization changes.
2021-05-22 18:48:23 -07:00
Jonathan Ringer
12c5acf376 21.05 beta release 2021-05-22 17:56:13 -07:00
33107 changed files with 835255 additions and 2501166 deletions

View File

@@ -55,33 +55,25 @@ trim_trailing_whitespace = unset
[*.lock]
indent_size = unset
# Although Markdown/CommonMark allows using two trailing spaces to denote
# a hard line break, we do not use that feature in nixpkgs since
# it forces the surrounding paragraph to become a <literallayout> which
# does not wrap reasonably.
# Instead of a hard line break, start a new paragraph by inserting a blank line.
[*.md]
trim_trailing_whitespace = true
# binaries
[*.nib]
end_of_line = unset
insert_final_newline = unset
trim_trailing_whitespace = unset
charset = unset
[eggs.nix]
trim_trailing_whitespace = unset
[nixos/modules/services/networking/ircd-hybrid/*.{conf,in}]
trim_trailing_whitespace = unset
[nixos/tests/systemd-networkd-vrf.nix]
trim_trailing_whitespace = unset
[pkgs/build-support/dotnetenv/Wrapper/**]
end_of_line = unset
indent_style = unset
insert_final_newline = unset
trim_trailing_whitespace = unset
[pkgs/build-support/upstream-updater/**]
indent_style = unset
trim_trailing_whitespace = unset
[pkgs/development/compilers/elm/registry.dat]
end_of_line = unset
insert_final_newline = unset
@@ -96,12 +88,9 @@ trim_trailing_whitespace = unset
[pkgs/tools/misc/timidity/timidity.cfg]
trim_trailing_whitespace = unset
[pkgs/tools/virtualization/ovftool/*.ova]
end_of_line = unset
[pkgs/tools/security/enpass/data.json]
insert_final_newline = unset
trim_trailing_whitespace = unset
charset = unset
[lib/tests/*.plist]
indent_style = tab
insert_final_newline = unset
[pkgs/top-level/emscripten-packages.nix]
trim_trailing_whitespace = unset

View File

@@ -1,41 +0,0 @@
# This file contains a list of commits that are not likely what you
# are looking for in a blame, such as mass reformatting or renaming.
# You can set this file as a default ignore file for blame by running
# the following command.
#
# $ git config blame.ignoreRevsFile .git-blame-ignore-revs
#
# To temporarily not use this file add
# --ignore-revs-file=""
# to your blame command.
#
# The ignoreRevsFile can't be set globally due to blame failing if the file isn't present.
# To not have to set the option in every repository it is needed in,
# save the following script in your path with the name "git-bblame"
# now you can run
# $ git bblame $FILE
# to use the .git-blame-ignore-revs file if it is present.
#
# #!/usr/bin/env bash
# repo_root=$(git rev-parse --show-toplevel)
# if [[ -e $repo_root/.git-blame-ignore-revs ]]; then
# git blame --ignore-revs-file="$repo_root/.git-blame-ignore-revs" $@
# else
# git blame $@
# fi
# nixos/modules/rename: Sort alphabetically
1f71224fe86605ef4cd23ed327b3da7882dad382
# manual: fix typos
feddd5e7f8c6f8167b48a077fa2a5394dc008999
# nixos: fix module paths in rename.nix
d08ede042b74b8199dc748323768227b88efcf7c
# fix indentation in mk-python-derivation.nix
d1c1a0c656ccd8bd3b25d3c4287f2d075faf3cf3
# fix indentation in meteor default.nix
a37a6de881ec4c6708e6b88fd16256bbc7f26bbd

2
.gitattributes vendored
View File

@@ -1,6 +1,4 @@
**/deps.nix linguist-generated
**/deps.json linguist-generated
**/deps.toml lingust-generated
**/node-packages.nix linguist-generated
pkgs/applications/editors/emacs-modes/*-generated.nix linguist-generated

208
.github/CODEOWNERS vendored
View File

@@ -6,10 +6,6 @@
#
# For documentation on this file, see https://help.github.com/articles/about-codeowners/
# Mentioned users will get code review requests.
#
# IMPORTANT NOTE: in order to actually get pinged, commit access is required.
# This also holds true for GitHub teams. Since almost none of our teams have write
# permissions, you need to list all members of the team with commit access individually.
# This file
/.github/CODEOWNERS @edolstra
@@ -23,12 +19,11 @@
# Libraries
/lib @edolstra @nbp @infinisil
/lib/systems @alyssais @nbp @ericson2314 @matthewbauer
/lib/systems @nbp @ericson2314 @matthewbauer
/lib/generators.nix @edolstra @nbp @Profpatsch
/lib/cli.nix @edolstra @nbp @Profpatsch
/lib/debug.nix @edolstra @nbp @Profpatsch
/lib/asserts.nix @edolstra @nbp @Profpatsch
/lib/path.* @infinisil @fricklerhandwerk
# Nixpkgs Internals
/default.nix @nbp
@@ -38,34 +33,15 @@
/pkgs/top-level/splice.nix @Ericson2314 @matthewbauer
/pkgs/top-level/release-cross.nix @Ericson2314 @matthewbauer
/pkgs/stdenv/generic @Ericson2314 @matthewbauer
/pkgs/stdenv/generic/check-meta.nix @Ericson2314 @matthewbauer @piegamesde
/pkgs/stdenv/cross @Ericson2314 @matthewbauer
/pkgs/build-support/cc-wrapper @Ericson2314
/pkgs/build-support/bintools-wrapper @Ericson2314
/pkgs/build-support/cc-wrapper @Ericson2314 @orivej
/pkgs/build-support/bintools-wrapper @Ericson2314 @orivej
/pkgs/build-support/setup-hooks @Ericson2314
/pkgs/build-support/setup-hooks/auto-patchelf.sh @layus
/pkgs/build-support/setup-hooks/auto-patchelf.py @layus
/pkgs/pkgs-lib @infinisil
/pkgs/build-support/setup-hooks/auto-patchelf.sh @aszlig
# Nixpkgs build-support
/pkgs/build-support/writers @lassulus @Profpatsch
# Nixpkgs make-disk-image
/doc/builders/images/makediskimage.section.md @raitobezarius
/nixos/lib/make-disk-image.nix @raitobezarius
# Nixpkgs documentation
/maintainers/scripts/db-to-md.sh @jtojnar @ryantm
/maintainers/scripts/doc @jtojnar @ryantm
/doc/* @fricklerhandwerk
/doc/build-aux/pandoc-filters @jtojnar
/doc/builders/trivial-builders.chapter.md @fricklerhandwerk
/doc/contributing/ @fricklerhandwerk
/doc/contributing/contributing-to-documentation.chapter.md @jtojnar @fricklerhandwerk
/doc/stdenv @fricklerhandwerk
/doc/using @fricklerhandwerk
# NixOS Internals
/nixos/default.nix @nbp @infinisil
/nixos/lib/from-env.nix @nbp @infinisil
@@ -83,22 +59,10 @@
/nixos/doc/manual/development/writing-modules.xml @nbp
/nixos/doc/manual/man-nixos-option.xml @nbp
/nixos/modules/installer/tools/nixos-option.sh @nbp
/nixos/modules/system @dasJ
/nixos/modules/system/activation/bootspec.nix @grahamc @cole-h @raitobezarius
/nixos/modules/system/activation/bootspec.cue @grahamc @cole-h @raitobezarius
# NixOS integration test driver
/nixos/lib/test-driver @tfc
# NixOS QEMU virtualisation
/nixos/virtualisation/qemu-vm.nix @raitobezarius
# Systemd
/nixos/modules/system/boot/systemd.nix @NixOS/systemd
/nixos/modules/system/boot/systemd @NixOS/systemd
/nixos/lib/systemd-*.nix @NixOS/systemd
/pkgs/os-specific/linux/systemd @NixOS/systemd
# Updaters
## update.nix
/maintainers/scripts/update.nix @jtojnar
@@ -107,11 +71,12 @@
/pkgs/common-updater/scripts/update-source-version @jtojnar
# Python-related code and docs
/maintainers/scripts/update-python-libraries @FRidh
/pkgs/development/interpreters/python @FRidh
/doc/languages-frameworks/python.section.md @FRidh @mweinelt
/pkgs/development/tools/poetry2nix @adisbladis
/pkgs/development/interpreters/python/hooks @FRidh @jonringer
/maintainers/scripts/update-python-libraries @FRidh
/pkgs/top-level/python-packages.nix @FRidh @jonringer
/pkgs/development/interpreters/python @FRidh
/pkgs/development/python-modules @FRidh @jonringer
/doc/languages-frameworks/python.section.md @FRidh
/pkgs/development/tools/poetry2nix @adisbladis
# Haskell
/doc/languages-frameworks/haskell.section.md @cdepillabout @sternenseemann @maralorn
@@ -123,44 +88,42 @@
/pkgs/top-level/haskell-packages.nix @cdepillabout @sternenseemann @maralorn
# Perl
/pkgs/development/interpreters/perl @stigtsp @zakame @dasJ
/pkgs/top-level/perl-packages.nix @stigtsp @zakame @dasJ
/pkgs/development/perl-modules @stigtsp @zakame @dasJ
/pkgs/development/interpreters/perl @volth @stigtsp
/pkgs/top-level/perl-packages.nix @volth @stigtsp
/pkgs/development/perl-modules @volth @stigtsp
# R
/pkgs/applications/science/math/R @jbedo
/pkgs/development/r-modules @jbedo
/pkgs/applications/science/math/R @peti
/pkgs/development/r-modules @peti
# Ruby
/pkgs/development/interpreters/ruby @marsam
/pkgs/development/ruby-modules @marsam
# Rust
/pkgs/development/compilers/rust @Mic92 @zowoq @winterqt @figsoda
/pkgs/build-support/rust @zowoq @winterqt @figsoda
/doc/languages-frameworks/rust.section.md @zowoq @winterqt @figsoda
/pkgs/development/compilers/rust @Mic92 @LnL7 @zowoq
/pkgs/build-support/rust @andir @danieldk @zowoq
# Darwin-related
/pkgs/stdenv/darwin @NixOS/darwin-maintainers
/pkgs/os-specific/darwin @NixOS/darwin-maintainers
# C compilers
/pkgs/development/compilers/gcc @matthewbauer
/pkgs/development/compilers/llvm @matthewbauer @RaitoBezarius
/pkgs/development/compilers/llvm @matthewbauer
# Compatibility stuff
/pkgs/top-level/unix-tools.nix @matthewbauer
/pkgs/development/tools/xcbuild @matthewbauer
# Audio
/nixos/modules/services/audio/botamusique.nix @mweinelt
/nixos/modules/services/audio/snapserver.nix @mweinelt
/nixos/tests/modules/services/audio/botamusique.nix @mweinelt
/nixos/tests/snapcast.nix @mweinelt
# Browsers
/pkgs/applications/networking/browsers/firefox @mweinelt
# Certificate Authorities
pkgs/data/misc/cacert/ @ajs124 @lukegb @mweinelt
pkgs/development/libraries/nss/ @ajs124 @lukegb @mweinelt
pkgs/development/python-modules/buildcatrust/ @ajs124 @lukegb @mweinelt
# Beam-related (Erlang, Elixir, LFE, etc)
/pkgs/development/beam-modules @gleber
/pkgs/development/interpreters/erlang @gleber
/pkgs/development/interpreters/lfe @gleber
/pkgs/development/interpreters/elixir @gleber
/pkgs/development/tools/build-managers/rebar @gleber
/pkgs/development/tools/build-managers/rebar3 @gleber
/pkgs/development/tools/erlang @gleber
# Jetbrains
/pkgs/applications/editors/jetbrains @edwtjo
@@ -188,40 +151,21 @@ pkgs/development/python-modules/buildcatrust/ @ajs124 @lukegb @mweinelt
/nixos/tests/hardened.nix @joachifm
/pkgs/os-specific/linux/kernel/hardened-config.nix @joachifm
# Home Automation
/nixos/modules/services/misc/home-assistant.nix @mweinelt
/nixos/modules/services/misc/zigbee2mqtt.nix @mweinelt
/nixos/tests/home-assistant.nix @mweinelt
/nixos/tests/zigbee2mqtt.nix @mweinelt
/pkgs/servers/home-assistant @mweinelt
/pkgs/tools/misc/esphome @mweinelt
# Network Time Daemons
/pkgs/tools/networking/chrony @thoughtpolice
/pkgs/tools/networking/ntp @thoughtpolice
/pkgs/tools/networking/openntpd @thoughtpolice
/nixos/modules/services/networking/ntp @thoughtpolice
# Network
/pkgs/tools/networking/kea/default.nix @mweinelt
/pkgs/tools/networking/babeld/default.nix @mweinelt
/nixos/modules/services/networking/babeld.nix @mweinelt
/nixos/modules/services/networking/kea.nix @mweinelt
/nixos/modules/services/networking/knot.nix @mweinelt
/nixos/modules/services/monitoring/prometheus/exporters/kea.nix @mweinelt
/nixos/tests/babeld.nix @mweinelt
/nixos/tests/kea.nix @mweinelt
/nixos/tests/knot.nix @mweinelt
# Dhall
/pkgs/development/dhall-modules @Gabriella439 @Profpatsch @ehmry
/pkgs/development/interpreters/dhall @Gabriella439 @Profpatsch @ehmry
/pkgs/development/dhall-modules @Gabriel439 @Profpatsch @ehmry
/pkgs/development/interpreters/dhall @Gabriel439 @Profpatsch @ehmry
# Idris
/pkgs/development/idris-modules @Infinisil
# Bazel
/pkgs/development/tools/build-managers/bazel @Profpatsch
/pkgs/development/tools/build-managers/bazel @mboes @Profpatsch
# NixOS modules for e-mail and dns services
/nixos/modules/services/mail/mailman.nix @peti
@@ -230,18 +174,19 @@ pkgs/development/python-modules/buildcatrust/ @ajs124 @lukegb @mweinelt
/nixos/modules/services/mail/rspamd.nix @peti
# Emacs
/pkgs/applications/editors/emacs/elisp-packages @adisbladis
/pkgs/applications/editors/emacs @adisbladis
/pkgs/top-level/emacs-packages.nix @adisbladis
/pkgs/applications/editors/emacs-modes @adisbladis
/pkgs/applications/editors/emacs @adisbladis
/pkgs/top-level/emacs-packages.nix @adisbladis
# Neovim
/pkgs/applications/editors/neovim @figsoda @jonringer @teto
/pkgs/applications/editors/neovim @jonringer
/pkgs/applications/editors/neovim @teto
# VimPlugins
/pkgs/applications/editors/vim/plugins @figsoda @jonringer
/pkgs/misc/vim-plugins @jonringer @softinio
# VsCode Extensions
/pkgs/applications/editors/vscode/extensions @jonringer
/pkgs/misc/vscode-extensions @jonringer
# Prometheus exporter modules and tests
/nixos/modules/services/monitoring/prometheus/exporters.nix @WilliButz
@@ -249,72 +194,33 @@ pkgs/development/python-modules/buildcatrust/ @ajs124 @lukegb @mweinelt
/nixos/tests/prometheus-exporters.nix @WilliButz
# PHP interpreter, packages, extensions, tests and documentation
/doc/languages-frameworks/php.section.md @aanderse @etu @globin @ma27 @talyz
/nixos/tests/php @aanderse @etu @globin @ma27 @talyz
/pkgs/build-support/build-pecl.nix @aanderse @etu @globin @ma27 @talyz
/pkgs/development/interpreters/php @jtojnar @aanderse @etu @globin @ma27 @talyz
/pkgs/development/php-packages @aanderse @etu @globin @ma27 @talyz
/pkgs/top-level/php-packages.nix @jtojnar @aanderse @etu @globin @ma27 @talyz
/doc/languages-frameworks/php.section.md @NixOS/php
/nixos/tests/php @NixOS/php
/pkgs/build-support/build-pecl.nix @NixOS/php
/pkgs/development/interpreters/php @NixOS/php
/pkgs/development/php-packages @NixOS/php
/pkgs/top-level/php-packages.nix @NixOS/php
# Podman, CRI-O modules and related
/nixos/modules/virtualisation/containers.nix @zowoq @adisbladis
/nixos/modules/virtualisation/cri-o.nix @zowoq @adisbladis
/nixos/modules/virtualisation/podman @zowoq @adisbladis
/nixos/tests/cri-o.nix @zowoq @adisbladis
/nixos/tests/podman @zowoq @adisbladis
/nixos/modules/virtualisation/containers.nix @NixOS/podman @zowoq
/nixos/modules/virtualisation/cri-o.nix @NixOS/podman @zowoq
/nixos/modules/virtualisation/podman.nix @NixOS/podman @zowoq
/nixos/tests/cri-o.nix @NixOS/podman @zowoq
/nixos/tests/podman.nix @NixOS/podman @zowoq
# Docker tools
/pkgs/build-support/docker @roberth
/nixos/tests/docker-tools* @roberth
/doc/builders/images/dockertools.section.md @roberth
/pkgs/build-support/docker @roberth @utdemir
/nixos/tests/docker-tools-overlay.nix @roberth
/nixos/tests/docker-tools.nix @roberth
/doc/builders/images/dockertools.xml @roberth
# Blockchains
/pkgs/applications/blockchains @mmahut @RaghavSood
# Go
/doc/languages-frameworks/go.section.md @kalbasit @Mic92 @zowoq
/pkgs/build-support/go @kalbasit @Mic92 @zowoq
/pkgs/development/compilers/go @kalbasit @Mic92 @zowoq
# GNOME
/pkgs/desktops/gnome @jtojnar
/pkgs/desktops/gnome/extensions @piegamesde @jtojnar
/pkgs/build-support/make-hardcode-gsettings-patch @jtojnar
/pkgs/development/go-modules @kalbasit @Mic92 @zowoq
/pkgs/development/go-packages @kalbasit @Mic92 @zowoq
# Cinnamon
/pkgs/desktops/cinnamon @mkg20001
# nim
/pkgs/development/compilers/nim @ehmry
/pkgs/development/nim-packages @ehmry
/pkgs/top-level/nim-packages.nix @ehmry
# terraform providers
/pkgs/applications/networking/cluster/terraform-providers @zowoq
# kubernetes
/nixos/doc/manual/configuration/kubernetes.chapter.md @zowoq
/nixos/modules/services/cluster/kubernetes @zowoq
/nixos/tests/kubernetes @zowoq
/pkgs/applications/networking/cluster/kubernetes @zowoq
# Matrix
/pkgs/servers/heisenbridge @piegamesde
/pkgs/servers/matrix-conduit @piegamesde
/nixos/modules/services/misc/heisenbridge.nix @piegamesde
/nixos/modules/services/misc/matrix-conduit.nix @piegamesde
/nixos/tests/matrix-conduit.nix @piegamesde
# Dotnet
/pkgs/build-support/dotnet @IvarWithoutBones
/pkgs/development/compilers/dotnet @IvarWithoutBones
# Node.js
/pkgs/build-support/node/build-npm-package @winterqt
/pkgs/build-support/node/fetch-npm-deps @winterqt
/doc/languages-frameworks/javascript.section.md @winterqt
# OCaml
/pkgs/build-support/ocaml @romildo @ulrikstrid
/pkgs/development/compilers/ocaml @romildo @ulrikstrid
/pkgs/development/ocaml-modules @romildo @ulrikstrid

View File

@@ -7,35 +7,37 @@ assignees: ''
---
### Describe the bug
**Describe the bug**
A clear and concise description of what the bug is.
### Steps To Reproduce
**To Reproduce**
Steps to reproduce the behavior:
1. ...
2. ...
3. ...
### Expected behavior
**Expected behavior**
A clear and concise description of what you expected to happen.
### Screenshots
**Screenshots**
If applicable, add screenshots to help explain your problem.
### Additional context
**Additional context**
Add any other context about the problem here.
### Notify maintainers
**Notify maintainers**
<!--
Please @ people who are in the `meta.maintainers` list of the offending package or module.
If in doubt, check `git blame` for whoever last touched something.
-->
### Metadata
**Metadata**
Please run `nix-shell -p nix-info --run "nix-info -m"` and paste the result.
```console
[user@system:~]$ nix-shell -p nix-info --run "nix-info -m"
output here
Maintainer information:
```yaml
# a list of nixpkgs attributes affected by the problem
attribute:
# a list of nixos modules affected by the problem
module:
```

View File

@@ -1,39 +0,0 @@
---
name: Build failure
about: Create a report to help us improve
title: 'Build failure: PACKAGENAME'
labels: '0.kind: build failure'
assignees: ''
---
### Steps To Reproduce
Steps to reproduce the behavior:
1. build *X*
### Build log
```
log here if short otherwise a link to a gist
```
### Additional context
Add any other context about the problem here.
### Notify maintainers
<!--
Please @ people who are in the `meta.maintainers` list of the offending package or module.
If in doubt, check `git blame` for whoever last touched something.
-->
### Metadata
Please run `nix-shell -p nix-info --run "nix-info -m"` and paste the result.
```console
[user@system:~]$ nix-shell -p nix-info --run "nix-info -m"
output here
```

View File

@@ -1,32 +0,0 @@
---
name: Missing or incorrect documentation
about: Help us improve the Nixpkgs and NixOS reference manuals
title: 'Documentation: '
labels: '9.needs: documentation'
assignees: ''
---
## Problem
<!-- describe your problem -->
## Proposal
<!-- propose a solution (optional) -->
## Checklist
<!-- make sure this issue is not redundant or obsolete -->
- [ ] checked [latest Nixpkgs manual] \([source][nixpkgs-source]) and [latest NixOS manual] \([source][nixos-source])
- [ ] checked [open documentation issues] for possible duplicates
- [ ] checked [open documentation pull requests] for possible solutions
[latest Nixpkgs manual]: https://nixos.org/manual/nixpkgs/unstable/
[latest NixOS manual]: https://nixos.org/manual/nixos/unstable/
[nixpkgs-source]: https://github.com/NixOS/nixpkgs/tree/master/doc
[nixos-source]: https://github.com/NixOS/nixpkgs/tree/master/nixos/doc/manual
[open documentation issues]: https://github.com/NixOS/nixpkgs/issues?q=is%3Aissue+is%3Aopen+label%3A%229.needs%3A+documentation%22
[open documentation pull requests]: https://github.com/NixOS/nixpkgs/pulls?q=is%3Aopen+is%3Apr+label%3A%228.has%3A+documentation%22%2C%226.topic%3A+documentation%22

View File

@@ -1,17 +1,24 @@
---
name: Out-of-date package reports
about: For packages that are out-of-date
title: 'Update request: PACKAGENAME OLDVERSION → NEWVERSION'
title: ''
labels: '9.needs: package (update)'
assignees: ''
---
- Package name:
- Latest released version:
<!-- Search your package here: https://search.nixos.org/packages?channel=unstable -->
- Current version on the unstable channel:
- Current version on the stable/release channel:
###### Checklist
<!-- Note that these are hard requirements -->
<!--
You can use the "Go to file" functionality on github to find the package
Then you can go to the history for this package
Find the latest "package_name: old_version -> new_version" commit
The "new_version" is the the current version of the package
-->
- [ ] Checked the [nixpkgs master branch](https://github.com/NixOS/nixpkgs)
<!--
Type the name of your package and try to find an open pull request for the package
If you find an open pull request, you can review it!
@@ -19,10 +26,23 @@ There's a high chance that you'll have the new version right away while helping
-->
- [ ] Checked the [nixpkgs pull requests](https://github.com/NixOS/nixpkgs/pulls)
**Notify maintainers**
###### Project name
`nix search` name:
<!--
The current version can be found easily with the same process than above for checking the master branch
If an open PR is present for the package, take this version as the current one and link to the PR
-->
current version:
desired version:
<!-- If the search.nixos.org result shows no maintainers, tag the person that last updated the package. -->
###### Notify maintainers
<!--
Search your package here: https://search.nixos.org/packages?channel=unstable
If no maintainer is listed for your package, tag the person that last updated the package
-->
-----
maintainers:
Note for maintainers: Please tag this issue in your PR.
###### Note for maintainers
Please tag this issue in your PR.

View File

@@ -1,15 +1,14 @@
---
name: Packaging requests
about: For packages that are missing
title: 'Package request: PACKAGENAME'
title: ''
labels: '0.kind: packaging request'
assignees: ''
---
**Project description**
<!-- Describe the project a little: -->
_describe the project a little_
**Metadata**

View File

@@ -1,31 +0,0 @@
---
name: Unreproducible package
about: A package that does not produce a bit-by-bit reproducible result each time it is built
title: ''
labels: [ '0.kind: enhancement', '6.topic: reproducible builds' ]
assignees: ''
---
Building this package twice does not produce the bit-by-bit identical result each time, making it harder to detect CI breaches. You can read more about this at https://reproducible-builds.org/ .
Fixing bit-by-bit reproducibility also has additional advantages, such as avoiding hard-to-reproduce bugs, making content-addressed storage more effective and reducing rebuilds in such systems.
### Steps To Reproduce
```
nix-build '<nixpkgs>' -A ... --check --keep-failed
```
You can use `diffoscope` to analyze the differences in the output of the two builds.
To view the build log of the build that produced the artifact in the binary cache:
```
nix-store --read-log $(nix-instantiate '<nixpkgs>' -A ...)
```
### Additional context
(please share the relevant fragment of the diffoscope output here,
and any additional analysis you may have done)

View File

@@ -1,40 +1,27 @@
###### Description of changes
<!--
For package updates please link to a changelog or describe changes, this helps your fellow maintainers discover breaking updates.
For new packages please briefly describe the package or provide a link to its homepage.
-->
###### Things done
<!-- Please check what applies. Note that these are not hard requirements but merely serve as information for reviewers. -->
- Built on platform(s)
- [ ] x86_64-linux
- [ ] aarch64-linux
- [ ] x86_64-darwin
- [ ] aarch64-darwin
- [ ] For non-Linux: Is `sandbox = true` set in `nix.conf`? (See [Nix manual](https://nixos.org/manual/nix/stable/command-ref/conf-file.html))
- [ ] Tested, as applicable:
- [NixOS test(s)](https://nixos.org/manual/nixos/unstable/index.html#sec-nixos-tests) (look inside [nixos/tests](https://github.com/NixOS/nixpkgs/blob/master/nixos/tests))
- and/or [package tests](https://nixos.org/manual/nixpkgs/unstable/#sec-package-tests)
- or, for functions and "core" functionality, tests in [lib/tests](https://github.com/NixOS/nixpkgs/blob/master/lib/tests) or [pkgs/test](https://github.com/NixOS/nixpkgs/blob/master/pkgs/test)
- made sure NixOS tests are [linked](https://nixos.org/manual/nixpkgs/unstable/#ssec-nixos-tests-linking) to the relevant packages
- [ ] Tested compilation of all packages that depend on this change using `nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD"`. Note: all changes have to be committed, also see [nixpkgs-review usage](https://github.com/Mic92/nixpkgs-review#usage)
- [ ] Tested basic functionality of all binary files (usually in `./result/bin/`)
- [23.05 Release Notes (or backporting 22.11 Release notes)](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#generating-2305-release-notes)
- [ ] (Package updates) Added a release notes entry if the change is major or breaking
- [ ] (Module updates) Added a release notes entry if the change is significant
- [ ] (Module addition) Added a release notes entry if adding a new NixOS module
- [ ] Fits [CONTRIBUTING.md](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md).
<!--
To help with the large amounts of pull requests, we would appreciate your
reviews of other pull requests, especially simple package updates. Just leave a
comment describing what you have tested in the relevant package/service.
Reviewing helps to reduce the average time-to-merge for everyone.
Thanks a lot if you do!
List of open PRs: https://github.com/NixOS/nixpkgs/pulls
Reviewing guidelines: https://nixos.org/manual/nixpkgs/unstable/#chap-reviewing-contributions
-->
###### Motivation for this change
###### Things done
<!-- Please check what applies. Note that these are not hard requirements but merely serve as information for reviewers. -->
- [ ] Tested using sandboxing ([nix.useSandbox](https://nixos.org/nixos/manual/options.html#opt-nix.useSandbox) on NixOS, or option `sandbox` in [`nix.conf`](https://nixos.org/nix/manual/#sec-conf-file) on non-NixOS linux)
- Built on platform(s)
- [ ] NixOS
- [ ] macOS
- [ ] other Linux distributions
- [ ] Tested via one or more NixOS test(s) if existing and applicable for the change (look inside [nixos/tests](https://github.com/NixOS/nixpkgs/blob/master/nixos/tests))
- [ ] Tested compilation of all pkgs that depend on this change using `nix-shell -p nixpkgs-review --run "nixpkgs-review wip"`
- [ ] Tested execution of all binary files (usually in `./result/bin/`)
- [ ] Added a release notes entry if the change is major or breaking
- [ ] Fits [CONTRIBUTING.md](https://github.com/NixOS/nixpkgs/blob/master/.github/CONTRIBUTING.md).

View File

@@ -1,10 +1,9 @@
# Stale bot information
- Thanks for your contribution!
- Our stale bot will never close an issue or PR.
- To remove the stale label, just leave a new comment.
- _How to find the right people to ping?_ &rarr; [`git blame`](https://git-scm.com/docs/git-blame) to the rescue! (or GitHub's history and blame buttons.)
- You can always ask for help on [our Discourse Forum](https://discourse.nixos.org/), [our Matrix room](https://matrix.to/#/#nix:nixos.org), or on the [#nixos IRC channel](https://web.libera.chat/#nixos).
- You can always ask for help on [our Discourse Forum](https://discourse.nixos.org/) or on the [#nixos IRC channel](https://webchat.freenode.net/#nixos).
## Suggestions for PRs

View File

@@ -1,6 +0,0 @@
version: 2
updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"

43
.github/labeler.yml vendored
View File

@@ -5,25 +5,22 @@
- pkgs/development/libraries/agda/**/*
- pkgs/top-level/agda-packages.nix
"6.topic: bsd":
- pkgs/os-specific/bsd/**/*
- pkgs/stdenv/freebsd/**/*
"6.topic: cinnamon":
- pkgs/desktops/cinnamon/**/*
- nixos/modules/services/x11/desktop-managers/cinnamon.nix
- nixos/tests/cinnamon.nix
"6.topic: emacs":
- nixos/modules/services/editors/emacs.nix
- nixos/modules/services/editors/emacs.xml
- nixos/tests/emacs-daemon.nix
- pkgs/applications/editors/emacs/elisp-packages/**/*
- pkgs/applications/editors/emacs-modes/**/*
- pkgs/applications/editors/emacs/**/*
- pkgs/build-support/emacs/**/*
- pkgs/top-level/emacs-packages.nix
"6.topic: Enlightenment DE":
- nixos/modules/services/x11/desktop-managers/enlightenment.nix
- pkgs/desktops/enlightenment/**/*
- pkgs/development/python-modules/python-efl/*
"6.topic: erlang":
- doc/languages-frameworks/beam.section.md
- pkgs/development/beam-modules/**/*
@@ -47,8 +44,9 @@
"6.topic: golang":
- doc/languages-frameworks/go.section.md
- pkgs/build-support/go/**/*
- pkgs/development/compilers/go/**/*
- pkgs/development/go-modules/**/*
- pkgs/development/go-packages/**/*
"6.topic: haskell":
- doc/languages-frameworks/haskell.section.md
@@ -70,28 +68,8 @@
- pkgs/development/lua-modules/**/*
- pkgs/top-level/lua-packages.nix
"6.topic: Lumina DE":
- nixos/modules/services/x11/desktop-managers/lumina.nix
- pkgs/desktops/lumina/**/*
"6.topic: LXQt":
- nixos/modules/services/x11/desktop-managers/lxqt.nix
- pkgs/desktops/lxqt/**/*
"6.topic: mate":
- nixos/modules/services/x11/desktop-managers/mate.nix
- nixos/tests/mate.nix
- pkgs/desktops/mate/**/*
"6.topic: nixos":
- nixos/**/*
- pkgs/os-specific/linux/nixos-rebuild/**/*
"6.topic: nim":
- doc/languages-frameworks/nim.section.md
- pkgs/development/compilers/nim/*
- pkgs/development/nim-packages/**/*
- pkgs/top-level/nim-packages.nix
"6.topic: ocaml":
- doc/languages-frameworks/ocaml.section.md
@@ -157,12 +135,7 @@
"6.topic: vim":
- doc/languages-frameworks/vim.section.md
- pkgs/applications/editors/vim/**/*
- pkgs/applications/editors/vim/plugins/**/*
- nixos/modules/programs/neovim.nix
- pkgs/applications/editors/neovim/**/*
"6.topic: vscode":
- pkgs/applications/editors/vscode/**/*
- pkgs/misc/vim-plugins/**/*
"6.topic: xfce":
- nixos/doc/manual/configuration/xfce.xml

3
.github/stale.yml vendored
View File

@@ -5,5 +5,6 @@ exemptLabels:
- "1.severity: security"
- "2.status: never-stale"
staleLabel: "2.status: stale"
markComment: false
markComment: |
I marked this as stale due to inactivity. &rarr; [More info](https://github.com/NixOS/nixpkgs/blob/master/.github/STALE-BOT.md)
closeComment: false

View File

@@ -1,35 +0,0 @@
name: Backport
on:
pull_request_target:
types: [closed, labeled]
# WARNING:
# When extending this action, be aware that $GITHUB_TOKEN allows write access to
# the GitHub repository. This means that it should not evaluate user input in a
# way that allows code injection.
permissions:
contents: read
jobs:
backport:
permissions:
contents: write # for korthout/backport-action to create branch
pull-requests: write # for korthout/backport-action to create PR to backport
name: Backport Pull Request
if: github.repository_owner == 'NixOS' && github.event.pull_request.merged == true && (github.event_name != 'labeled' || startsWith('backport', github.event.label.name))
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
with:
ref: ${{ github.event.pull_request.head.sha }}
- name: Create backport PRs
uses: korthout/backport-action@v1.2.0
with:
# Config README: https://github.com/korthout/backport-action#backport-action
copy_labels_pattern: 'severity:\ssecurity'
pull_description: |-
Bot-based backport to `${target_branch}`, triggered by a label in #${pull_number}.
* [ ] Before merging, ensure that this backport complies with the [Criteria for Backporting](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#criteria-for-backporting-changes).
* Even as a non-commiter, if you find that it does not comply, leave a comment.

View File

@@ -1,29 +0,0 @@
name: Basic evaluation checks
on:
workflow_dispatch
# pull_request:
# branches:
# - master
# - release-**
# push:
# branches:
# - master
# - release-**
permissions:
contents: read
jobs:
tests:
runs-on: ubuntu-latest
# we don't limit this action to only NixOS repo since the checks are cheap and useful developer feedback
steps:
- uses: actions/checkout@v3
- uses: cachix/install-nix-action@v20
- uses: cachix/cachix-action@v12
with:
# This cache is for the nixpkgs repo checks and should not be trusted or used elsewhere.
name: nixpkgs-ci
signingKey: '${{ secrets.CACHIX_SIGNING_KEY }}'
# explicit list of supportedSystems is needed until aarch64-darwin becomes part of the trunk jobset
- run: nix-build pkgs/top-level/release.nix -A tarball.nixpkgs-basic-release-checks --arg supportedSystems '[ "aarch64-darwin" "aarch64-linux" "x86_64-linux" "x86_64-darwin" ]'

View File

@@ -1,24 +0,0 @@
name: "Check that maintainer list is sorted"
on:
pull_request_target:
paths:
- 'maintainers/maintainer-list.nix'
permissions:
contents: read
jobs:
nixos:
runs-on: ubuntu-latest
if: github.repository_owner == 'NixOS'
steps:
- uses: actions/checkout@v3
with:
# pull_request_target checks out the base branch by default
ref: refs/pull/${{ github.event.pull_request.number }}/merge
- uses: cachix/install-nix-action@v20
with:
# explicitly enable sandbox
extra_nix_config: sandbox = true
- name: Check that maintainer-list.nix is sorted
run: nix-instantiate --eval maintainers/scripts/check-maintainers-sorted.nix

View File

@@ -1,21 +0,0 @@
#!/usr/bin/env nix-shell
#! nix-shell -i bash -p html-tidy
set -euo pipefail
shopt -s inherit_errexit
normalize() {
tidy \
--anchor-as-name no \
--coerce-endtags no \
--escape-scripts no \
--fix-backslash no \
--fix-style-tags no \
--fix-uri no \
--indent yes \
--wrap 0 \
< "$1" \
2> /dev/null
}
diff -U3 <(normalize "$1") <(normalize "$2")

View File

@@ -4,13 +4,8 @@ on:
branches:
- master
- release-**
permissions:
contents: read
jobs:
build:
permissions:
contents: write # for peter-evans/commit-comment to comment on commit
runs-on: ubuntu-latest
if: github.repository_owner == 'NixOS'
env:
@@ -21,13 +16,10 @@ jobs:
id: ismerge
run: |
ISMERGE=$(curl -H 'Accept: application/vnd.github.groot-preview+json' -H "authorization: Bearer ${{ secrets.GITHUB_TOKEN }}" https://api.github.com/repos/${{ env.GITHUB_REPOSITORY }}/commits/${{ env.GITHUB_SHA }}/pulls | jq -r '.[] | select(.merge_commit_sha == "${{ env.GITHUB_SHA }}") | any')
echo "ismerge=$ISMERGE" >> $GITHUB_OUTPUT
# github events are eventually consistent, so wait until changes propagate to thier DB
- run: sleep 60
if: steps.ismerge.outputs.ismerge != 'true'
echo "::set-output name=ismerge::$ISMERGE"
- name: Warn if the commit was a direct push
if: steps.ismerge.outputs.ismerge != 'true'
uses: peter-evans/commit-comment@v2
uses: peter-evans/commit-comment@v1
with:
body: |
@${{ github.actor }}, you pushed a commit directly to master/release branch

View File

@@ -11,31 +11,36 @@ on:
jobs:
tests:
runs-on: ubuntu-latest
if: "github.repository_owner == 'NixOS' && !contains(github.event.pull_request.title, '[skip treewide]')"
if: github.repository_owner == 'NixOS'
steps:
- name: Get list of changed files from PR
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
echo 'PR_DIFF<<EOF' >> $GITHUB_ENV
gh api \
repos/NixOS/nixpkgs/pulls/${{github.event.number}}/files --paginate \
| jq '.[] | select(.status != "removed") | .filename' \
> "$HOME/changed_files"
- name: print list of changed files
run: |
cat "$HOME/changed_files"
- uses: actions/checkout@v3
>> $GITHUB_ENV
echo 'EOF' >> $GITHUB_ENV
- uses: actions/checkout@v2
with:
# pull_request_target checks out the base branch by default
ref: refs/pull/${{ github.event.pull_request.number }}/merge
- uses: cachix/install-nix-action@v20
if: env.PR_DIFF
- uses: cachix/install-nix-action@v13
if: env.PR_DIFF
with:
# nixpkgs commit is pinned so that it doesn't break
# editorconfig-checker 2.4.0
nix_path: nixpkgs=https://github.com/NixOS/nixpkgs/archive/c473cc8714710179df205b153f4e9fa007107ff9.tar.gz
nix_path: nixpkgs=https://github.com/NixOS/nixpkgs/archive/f93ecc4f6bc60414d8b73dbdf615ceb6a2c604df.tar.gz
- name: install editorconfig-checker
run: nix-env -iA editorconfig-checker -f '<nixpkgs>'
if: env.PR_DIFF
- name: Checking EditorConfig
if: env.PR_DIFF
run: |
cat "$HOME/changed_files" | nix-shell -p editorconfig-checker --run 'xargs -r editorconfig-checker -disable-indent-size'
echo "$PR_DIFF" | xargs editorconfig-checker -disable-indent-size
- if: ${{ failure() }}
run: |
echo "::error :: Hey! It looks like your changes don't follow our editorconfig settings. Read https://editorconfig.org/#download to configure your editor so you never see this error again."

View File

@@ -4,11 +4,6 @@ on:
pull_request_target:
types: [edited, opened, synchronize, reopened]
# WARNING:
# When extending this action, be aware that $GITHUB_TOKEN allows some write
# access to the GitHub API. This means that it should not evaluate user input in
# a way that allows code injection.
permissions:
contents: read
pull-requests: write
@@ -16,9 +11,9 @@ permissions:
jobs:
labels:
runs-on: ubuntu-latest
if: "github.repository_owner == 'NixOS' && !contains(github.event.pull_request.title, '[skip treewide]')"
if: github.repository_owner == 'NixOS'
steps:
- uses: actions/labeler@v4
- uses: actions/labeler@v3
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
sync-labels: true

View File

@@ -12,28 +12,19 @@ on:
jobs:
nixos:
runs-on: ubuntu-latest
if: github.repository_owner == 'NixOS'
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v2
with:
# pull_request_target checks out the base branch by default
ref: refs/pull/${{ github.event.pull_request.number }}/merge
- uses: cachix/install-nix-action@v20
- uses: cachix/install-nix-action@v13
with:
# explicitly enable sandbox
extra_nix_config: sandbox = true
- uses: cachix/cachix-action@v12
- uses: cachix/cachix-action@v9
with:
# This cache is for the nixpkgs repo checks and should not be trusted or used elsewhere.
# This cache is for the nixos/nixpkgs manual builds and should not be trusted or used elsewhere.
name: nixpkgs-ci
signingKey: '${{ secrets.CACHIX_SIGNING_KEY }}'
- name: Building NixOS manual with DocBook options
- name: Building NixOS manual
run: NIX_PATH=nixpkgs=$(pwd) nix-build --option restrict-eval true nixos/release.nix -A manual.x86_64-linux
- name: Building NixOS manual with Markdown options
run: |
export NIX_PATH=nixpkgs=$(pwd)
nix-build \
--option restrict-eval true \
--arg configuration '{ documentation.nixos.options.allowDocBook = false; }' \
nixos/release.nix \
-A manual.x86_64-linux

View File

@@ -8,24 +8,22 @@ on:
- master
paths:
- 'doc/**'
- 'lib/**'
jobs:
nixpkgs:
runs-on: ubuntu-latest
if: github.repository_owner == 'NixOS'
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v2
with:
# pull_request_target checks out the base branch by default
ref: refs/pull/${{ github.event.pull_request.number }}/merge
- uses: cachix/install-nix-action@v20
- uses: cachix/install-nix-action@v13
with:
# explicitly enable sandbox
extra_nix_config: sandbox = true
- uses: cachix/cachix-action@v12
- uses: cachix/cachix-action@v9
with:
# This cache is for the nixpkgs repo checks and should not be trusted or used elsewhere.
# This cache is for the nixos/nixpkgs manual builds and should not be trusted or used elsewhere.
name: nixpkgs-ci
signingKey: '${{ secrets.CACHIX_SIGNING_KEY }}'
- name: Building Nixpkgs manual

View File

@@ -1,64 +0,0 @@
name: "Check NixOS Manual DocBook rendering against MD rendering"
on:
schedule:
# * is a special character in YAML so you have to quote this string
# Check every 24 hours
- cron: '0 0 * * *'
permissions:
contents: read
jobs:
check-rendering-equivalence:
permissions:
pull-requests: write # for peter-evans/create-or-update-comment to create or update comment
if: github.repository_owner == 'NixOS'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: cachix/install-nix-action@v20
with:
# explicitly enable sandbox
extra_nix_config: sandbox = true
- uses: cachix/cachix-action@v12
with:
# This cache is for the nixpkgs repo checks and should not be trusted or used elsewhere.
name: nixpkgs-ci
signingKey: '${{ secrets.CACHIX_SIGNING_KEY }}'
- name: Build DocBook and MD manuals
run: |
export NIX_PATH=nixpkgs=$(pwd)
nix-build \
--option restrict-eval true \
-o docbook nixos/release.nix \
-A manual.x86_64-linux
nix-build \
--option restrict-eval true \
--arg configuration '{ documentation.nixos.options.allowDocBook = false; }' \
-o md nixos/release.nix \
-A manual.x86_64-linux
- name: Compare DocBook and MD manuals
id: check
run: |
export NIX_PATH=nixpkgs=$(pwd)
.github/workflows/compare-manuals.sh \
docbook/share/doc/nixos/options.html \
md/share/doc/nixos/options.html
# if the manual can't be built we don't want to notify anyone.
# while this may temporarily hide rendering failures it will be a lot
# less noisy until all nixpkgs pull requests have stopped using
# docbook for option docs.
- name: Comment on failure
uses: peter-evans/create-or-update-comment@v3
if: ${{ failure() && steps.check.conclusion == 'failure' }}
with:
issue-number: 189318
body: |
Markdown and DocBook manuals do not agree.
Check https://github.com/NixOS/nixpkgs/actions/runs/${{ github.run_id }} for details.

41
.github/workflows/merge-staging.yml vendored Normal file
View File

@@ -0,0 +1,41 @@
name: "merge staging(-next)"
on:
schedule:
# * is a special character in YAML so you have to quote this string
# Merge every 6 hours
- cron: '0 */6 * * *'
jobs:
sync-branch:
if: github.repository == 'NixOS/nixpkgs'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- name: Merge master into staging-next
id: staging_next
uses: devmasx/merge-branch@v1.3.1
with:
type: now
from_branch: master
target_branch: staging-next
github_token: ${{ secrets.GITHUB_TOKEN }}
- name: Merge staging-next into staging
id: staging
uses: devmasx/merge-branch@v1.3.1
with:
type: now
from_branch: staging-next
target_branch: staging
github_token: ${{ secrets.GITHUB_TOKEN }}
- name: Comment on failure
uses: peter-evans/create-or-update-comment@v1
if: ${{ failure() }}
with:
issue-number: 105153
body: |
An automatic merge${{ (steps.staging_next.outcome == 'failure' && ' from master to staging-next') || ((steps.staging.outcome == 'failure' && ' from staging-next to staging') || '') }} [failed](https://github.com/NixOS/nixpkgs/actions/runs/${{ github.run_id }}).

View File

@@ -1,26 +0,0 @@
name: "No channel PR"
on:
pull_request:
branches:
- 'nixos-**'
- 'nixpkgs-**'
permissions:
contents: read
jobs:
fail:
permissions:
contents: none
name: "This PR is is targeting a channel branch"
runs-on: ubuntu-latest
steps:
- run: |
cat <<EOF
The nixos-* and nixpkgs-* branches are pushed to by the channel
release script and should not be merged into directly.
Please target the equivalent release-* branch or master instead.
EOF
exit 1

View File

@@ -1,33 +0,0 @@
name: "Set pending OfBorg status"
on:
pull_request_target:
# Sets the ofborg-eval status to "pending" to signal that we are waiting for
# OfBorg even if it is running late. The status will be overwritten by OfBorg
# once it starts evaluation.
# WARNING:
# When extending this action, be aware that $GITHUB_TOKEN allows (restricted) write access to
# the GitHub repository. This means that it should not evaluate user input in a
# way that allows code injection.
permissions:
contents: read
jobs:
action:
if: github.repository_owner == 'NixOS'
permissions:
statuses: write
runs-on: ubuntu-latest
steps:
- name: "Set pending OfBorg status"
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
curl \
-X POST \
-H "Accept: application/vnd.github.v3+json" \
-H "Authorization: Bearer $GITHUB_TOKEN" \
-d '{"context": "ofborg-eval", "state": "pending", "description": "Waiting for OfBorg..."}' \
"https://api.github.com/repos/NixOS/nixpkgs/commits/${{ github.event.pull_request.head.sha }}/statuses"

21
.github/workflows/pending-clear.yml vendored Normal file
View File

@@ -0,0 +1,21 @@
name: "clear pending status"
on:
check_suite:
types: [ completed ]
jobs:
action:
runs-on: ubuntu-latest
steps:
- name: clear pending status
if: github.repository_owner == 'NixOS' && github.event.check_suite.app.name == 'OfBorg'
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
curl \
-X POST \
-H "Accept: application/vnd.github.v3+json" \
-H "Authorization: token $GITHUB_TOKEN" \
-d '{"state": "success", "target_url": " ", "description": " ", "context": "Wait for ofborg"}' \
"https://api.github.com/repos/NixOS/nixpkgs/statuses/${{ github.event.check_suite.head_sha }}"

20
.github/workflows/pending-set.yml vendored Normal file
View File

@@ -0,0 +1,20 @@
name: "set pending status"
on:
pull_request_target:
jobs:
action:
runs-on: ubuntu-latest
steps:
- name: set pending status
if: github.repository_owner == 'NixOS'
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
curl \
-X POST \
-H "Accept: application/vnd.github.v3+json" \
-H "Authorization: token $GITHUB_TOKEN" \
-d '{"state": "pending", "target_url": " ", "description": "This pending status will be cleared when ofborg starts eval.", "context": "Wait for ofborg"}' \
"https://api.github.com/repos/NixOS/nixpkgs/statuses/${{ github.event.pull_request.head.sha }}"

View File

@@ -1,59 +0,0 @@
# This action periodically merges base branches into staging branches.
# This is done to
# * prevent conflicts or rather resolve them early
# * make all potential breakage happen on the staging branch
# * and make sure that all major rebuilds happen before the staging
# branch gets merged back into its base branch.
name: "Periodic Merges (24h)"
on:
schedule:
# * is a special character in YAML so you have to quote this string
# Merge every 24 hours
- cron: '0 0 * * *'
permissions:
contents: read
jobs:
periodic-merge:
permissions:
contents: write # for devmasx/merge-branch to merge branches
pull-requests: write # for peter-evans/create-or-update-comment to create or update comment
if: github.repository_owner == 'NixOS'
runs-on: ubuntu-latest
strategy:
# don't fail fast, so that all pairs are tried
fail-fast: false
# certain branches need to be merged in order, like master->staging-next->staging
# and disabling parallelism ensures the order of the pairs below.
max-parallel: 1
matrix:
pairs:
- from: master
into: haskell-updates
- from: release-22.11
into: staging-next-22.11
- from: staging-next-22.11
into: staging-22.11
name: ${{ matrix.pairs.from }} → ${{ matrix.pairs.into }}
steps:
- uses: actions/checkout@v3
- name: ${{ matrix.pairs.from }} → ${{ matrix.pairs.into }}
uses: devmasx/merge-branch@1.4.0
with:
type: now
from_branch: ${{ matrix.pairs.from }}
target_branch: ${{ matrix.pairs.into }}
github_token: ${{ secrets.GITHUB_TOKEN }}
- name: Comment on failure
uses: peter-evans/create-or-update-comment@v3
if: ${{ failure() }}
with:
issue-number: 105153
body: |
Periodic merge from `${{ matrix.pairs.from }}` into `${{ matrix.pairs.into }}` has [failed](https://github.com/NixOS/nixpkgs/actions/runs/${{ github.run_id }}).

View File

@@ -1,57 +0,0 @@
# This action periodically merges base branches into staging branches.
# This is done to
# * prevent conflicts or rather resolve them early
# * make all potential breakage happen on the staging branch
# * and make sure that all major rebuilds happen before the staging
# branch gets merged back into its base branch.
name: "Periodic Merges (6h)"
on:
schedule:
# * is a special character in YAML so you have to quote this string
# Merge every 6 hours
- cron: '0 */6 * * *'
permissions:
contents: read
jobs:
periodic-merge:
permissions:
contents: write # for devmasx/merge-branch to merge branches
pull-requests: write # for peter-evans/create-or-update-comment to create or update comment
if: github.repository_owner == 'NixOS'
runs-on: ubuntu-latest
strategy:
# don't fail fast, so that all pairs are tried
fail-fast: false
# certain branches need to be merged in order, like master->staging-next->staging
# and disabling parallelism ensures the order of the pairs below.
max-parallel: 1
matrix:
pairs:
- from: master
into: staging-next
- from: staging-next
into: staging
name: ${{ matrix.pairs.from }} → ${{ matrix.pairs.into }}
steps:
- uses: actions/checkout@v3
- name: ${{ matrix.pairs.from }} → ${{ matrix.pairs.into }}
uses: devmasx/merge-branch@1.4.0
with:
type: now
from_branch: ${{ matrix.pairs.from }}
target_branch: ${{ matrix.pairs.into }}
github_token: ${{ secrets.GITHUB_TOKEN }}
- name: Comment on failure
uses: peter-evans/create-or-update-comment@v3
if: ${{ failure() }}
with:
issue-number: 105153
body: |
Periodic merge from `${{ matrix.pairs.from }}` into `${{ matrix.pairs.into }}` has [failed](https://github.com/NixOS/nixpkgs/actions/runs/${{ github.run_id }}).

134
.github/workflows/rebase.yml vendored Normal file
View File

@@ -0,0 +1,134 @@
on:
issue_comment:
types:
- created
# This action allows people with write access to the repo to rebase a PRs base branch
# by commenting `/rebase ${branch}` on the PR while avoiding CODEOWNER notifications.
jobs:
rebase:
runs-on: ubuntu-latest
if: github.repository_owner == 'NixOS' && github.event.issue.pull_request != '' && contains(github.event.comment.body, '/rebase')
steps:
- uses: peter-evans/create-or-update-comment@v1
with:
comment-id: ${{ github.event.comment.id }}
reactions: eyes
- uses: scherermichael-oss/action-has-permission@1.0.6
id: check-write-access
with:
required-permission: write
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: check permissions
run: |
echo "Commenter doesn't have write access to the repo"
exit 1
if: "! steps.check-write-access.outputs.has-permission"
- name: setup
run: |
curl "https://api.github.com/repos/${{ github.repository }}/pulls/${{ github.event.issue.number }}" 2>/dev/null >pr.json
cat <<EOF >>"$GITHUB_ENV"
CAN_MODIFY=$(jq -r '.maintainer_can_modify' pr.json)
COMMITS=$(jq -r '.commits' pr.json)
CURRENT_BASE=$(jq -r '.base.ref' pr.json)
PR_BRANCH=$(jq -r '.head.ref' pr.json)
COMMENT_BRANCH=$(echo ${{ github.event.comment.body }} | awk "/^\/rebase / {print \$2}")
PULL_REQUEST=${{ github.event.issue.number }}
EOF
rm pr.json
- name: check branch
env:
PERMANENT_BRANCHES: "haskell-updates|master|nixos|nixpkgs|python-unstable|release|staging"
VALID_BRANCHES: "haskell-updates|master|python-unstable|release-20.09|staging|staging-20.09|staging-next"
run: |
message() {
cat <<EOF
Can't rebase $PR_BRANCH from $CURRENT_BASE onto $COMMENT_BRANCH (PR:$PULL_REQUEST COMMITS:$COMMITS)
EOF
}
if ! [[ "$COMMENT_BRANCH" =~ ^($VALID_BRANCHES)$ ]]; then
cat <<EOF
Check that the branch from the comment is valid:
$(message)
This action can only rebase onto these branches:
$VALID_BRANCHES
\`/rebase \${branch}\` must be at the start of the line
EOF
exit 1
fi
if [[ "$COMMENT_BRANCH" == "$CURRENT_BASE" ]]; then
cat <<EOF
Check that the branch from the comment isn't the current base branch:
$(message)
EOF
exit 1
fi
if [[ "$COMMENT_BRANCH" == "$PR_BRANCH" ]]; then
cat <<EOF
Check that the branch from the comment isn't the current branch:
$(message)
EOF
exit 1
fi
if [[ "$PR_BRANCH" =~ ^($PERMANENT_BRANCHES) ]]; then
cat <<EOF
Check that the PR branch isn't a permanent branch:
$(message)
EOF
exit 1
fi
if [[ "$CAN_MODIFY" != "true" ]]; then
cat <<EOF
Check that maintainers can edit the PR branch:
$(message)
EOF
exit 1
fi
- uses: actions/checkout@v2
with:
fetch-depth: 0
- name: rebase pull request
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
git config --global user.email "41898282+github-actions[bot]@users.noreply.github.com"
git config --global user.name "github-actions[bot]"
git fetch origin
gh pr checkout "$PULL_REQUEST"
git rebase \
--onto="$(git merge-base origin/"$CURRENT_BASE" origin/"$COMMENT_BRANCH")" \
"HEAD~$COMMITS"
git push --force
curl \
-X POST \
-H "Accept: application/vnd.github.v3+json" \
-H "Authorization: token $GITHUB_TOKEN" \
-d "{ \"base\": \"$COMMENT_BRANCH\" }" \
"https://api.github.com/repos/${{ github.repository }}/pulls/$PULL_REQUEST"
curl \
-X PATCH \
-H "Accept: application/vnd.github.v3+json" \
-H "Authorization: token $GITHUB_TOKEN" \
-d '{ "state": "closed" }' \
"https://api.github.com/repos/${{ github.repository }}/pulls/$PULL_REQUEST"
- uses: peter-evans/create-or-update-comment@v1
with:
issue-number: ${{ github.event.issue.number }}
body: |
Rebased, please reopen the pull request to restart CI
- uses: peter-evans/create-or-update-comment@v1
if: failure()
with:
issue-number: ${{ github.event.issue.number }}
body: |
[Failed to rebase](https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }})

View File

@@ -1,69 +0,0 @@
name: "Update terraform-providers"
on:
schedule:
- cron: "0 3 * * *"
workflow_dispatch:
permissions:
contents: read
jobs:
tf-providers:
permissions:
contents: write # for peter-evans/create-pull-request to create branch
pull-requests: write # for peter-evans/create-pull-request to create a PR
if: github.repository_owner == 'NixOS' && github.ref == 'refs/heads/master' # ensure workflow_dispatch only runs on master
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: cachix/install-nix-action@v20
with:
nix_path: nixpkgs=channel:nixpkgs-unstable
- name: setup
id: setup
run: |
echo "title=terraform-providers: update $(date -u +"%Y-%m-%d")" >> $GITHUB_OUTPUT
- name: update terraform-providers
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git config user.name "github-actions[bot]"
echo | nix-shell \
maintainers/scripts/update.nix \
--argstr commit true \
--argstr keep-going true \
--argstr max-workers 2 \
--argstr path terraform-providers
- name: get failed updates
run: |
echo 'FAILED<<EOF' >> $GITHUB_ENV
git ls-files --others >> $GITHUB_ENV
echo 'EOF' >> $GITHUB_ENV
# cleanup logs of failed updates so they aren't included in the PR
- name: clean repo
run: |
git clean -f
- name: create PR
uses: peter-evans/create-pull-request@v5
with:
body: |
Automatic update by [update-terraform-providers](https://github.com/NixOS/nixpkgs/blob/master/.github/workflows/update-terraform-providers.yml) action.
https://github.com/NixOS/nixpkgs/actions/runs/${{ github.run_id }}
These providers failed to update:
```
${{ env.FAILED }}
```
Check that all providers build with:
```
@ofborg build terraform.full
```
If there is more than ten commits in the PR `ofborg` won't build it automatically and you will need to use the above command.
branch: terraform-providers-update
delete-branch: false
title: ${{ steps.setup.outputs.title }}
token: ${{ secrets.GITHUB_TOKEN }}

13
.gitignore vendored
View File

@@ -2,20 +2,12 @@
,*
.*.swp
.*.swo
.\#*
\#*\#
.idea/
.vscode/
outputs/
result-*
result
!pkgs/development/python-modules/result
result-*
/doc/NEWS.html
/doc/NEWS.txt
/doc/manual.html
/doc/manual.pdf
/result
/source/
.version-suffix
.DS_Store
@@ -28,6 +20,3 @@ __pycache__
# generated by pkgs/common-updater/update-script.nix
update-git-commits.txt
# JetBrains IDEA module declaration file
/nixpkgs.iml

View File

@@ -1,14 +0,0 @@
ajs124 <git@ajs124.de> <ajs124@users.noreply.github.com>
Anderson Torres <torres.anderson.85@protonmail.com>
Daniel Løvbrøtte Olsen <me@dandellion.xyz> <daniel.olsen99@gmail.com>
Fabian Affolter <mail@fabian-affolter.ch> <fabian@affolter-engineering.ch>
Janne Heß <janne@hess.ooo> <dasJ@users.noreply.github.com>
Jörg Thalheim <joerg@thalheim.io> <Mic92@users.noreply.github.com>
Martin Weinelt <hexa@darmstadt.ccc.de> <mweinelt@users.noreply.github.com>
R. RyanTM <ryantm-bot@ryantm.com>
Robert Hensing <robert@roberthensing.nl> <roberth@users.noreply.github.com>
Sandro Jäckel <sandro.jaeckel@gmail.com>
Sandro Jäckel <sandro.jaeckel@gmail.com> <sandro.jaeckel@sap.com>
superherointj <5861043+superherointj@users.noreply.github.com>
Vladimír Čunát <v@cunat.cz> <vcunat@gmail.com>
Vladimír Čunát <v@cunat.cz> <vladimir.cunat@nic.cz>

View File

@@ -1 +1 @@
23.05
21.05

View File

@@ -1,7 +1,7 @@
# How to contribute
Note: contributing implies licensing those contributions
under the terms of [COPYING](COPYING), which is an MIT-like license.
under the terms of [COPYING](../COPYING), which is an MIT-like license.
## Opening issues
@@ -11,16 +11,12 @@ under the terms of [COPYING](COPYING), which is an MIT-like license.
## Submitting changes
Read the ["Submitting changes"](https://nixos.org/nixpkgs/manual/#chap-submitting-changes) section of the nixpkgs manual. It explains how to write, test, and iterate on your change, and which branch to base your pull request against.
Below is a short excerpt of some points in there:
* Format the commit messages in the following way:
```
(pkg-name | nixos/<module>): (from -> to | init at version | refactor | etc)
(Motivation for change. Link to release notes. Additional information.)
(Motivation for change. Additional information.)
```
For consistency, there should not be a period at the end of the commit message's summary line (the first line of the commit message).
@@ -29,7 +25,6 @@ Below is a short excerpt of some points in there:
* nginx: init at 2.0.1
* firefox: 54.0.1 -> 55.0
https://www.mozilla.org/en-US/firefox/55.0/releasenotes/
* nixos/hydra: add bazBaz option
Dual baz behavior is needed to do foo.
@@ -38,109 +33,32 @@ Below is a short excerpt of some points in there:
The old config generation system used impure shell scripts and could break in specific circumstances (see #1234).
* `meta.description` should:
* Be short, just one sentence.
* Be capitalized.
* Not start with the package name.
* More generally, it should not refer to the package name.
* Not end with a period (or any punctuation for that matter).
* Aim to inform while avoiding subjective language.
* Not have a period at the end.
* `meta.license` must be set and fit the upstream license.
* If there is no upstream license, `meta.license` should default to `lib.licenses.unfree`.
* If in doubt, try to contact the upstream developers for clarification.
* `meta.maintainers` must be set.
See the nixpkgs manual for more details on [standard meta-attributes](https://nixos.org/nixpkgs/manual/#sec-standard-meta-attributes).
See the nixpkgs manual for more details on [standard meta-attributes](https://nixos.org/nixpkgs/manual/#sec-standard-meta-attributes) and on how to [submit changes to nixpkgs](https://nixos.org/nixpkgs/manual/#chap-submitting-changes).
## Writing good commit messages
In addition to writing properly formatted commit messages, it's important to include relevant information so other developers can later understand *why* a change was made. While this information usually can be found by digging code, mailing list/Discourse archives, pull request discussions or upstream changes, it may require a lot of work.
Package version upgrades usually allow for simpler commit messages, including attribute name, old and new version, as well as a reference to the relevant release notes/changelog. Every once in a while a package upgrade requires more extensive changes, and that subsequently warrants a more verbose message.
Pull requests should not be squash merged in order to keep complete commit messages and GPG signatures intact and must not be when the change doesn't make sense as a single commit.
This means that, when addressing review comments in order to keep the pull request in an always mergeable status, you will sometimes need to rewrite your branch's history and then force-push it with `git push --force-with-lease`.
Useful git commands that can help a lot with this are `git commit --patch --amend` and `git rebase --interactive`. For more details consult the git man pages or online resources like [git-rebase.io](https://git-rebase.io/) or [The Pro Git Book](https://git-scm.com/book/en/v2/Git-Tools-Rewriting-History).
## Rebasing between branches (i.e. from master to staging)
From time to time, changes between branches must be rebased, for example, if the
number of new rebuilds they would cause is too large for the target branch. When
rebasing, care must be taken to include only the intended changes, otherwise
many CODEOWNERS will be inadvertently requested for review. To achieve this,
rebasing should not be performed directly on the target branch, but on the merge
base between the current and target branch.
In the following example, we assume that the current branch, called `feature`,
is based on `master`, and we rebase it onto the merge base between
`master` and `staging` so that the PR can eventually be retargeted to
`staging` without causing a mess. The example uses `upstream` as the remote for `NixOS/nixpkgs.git`
while `origin` is the remote you are pushing to.
```console
# Rebase your commits onto the common merge base
git rebase --onto upstream/staging... upstream/master
# Force push your changes
git push origin feature --force-with-lease
```
The syntax `upstream/staging...` is equivalent to `upstream/staging...HEAD` and
stands for the merge base between `upstream/staging` and `HEAD` (hence between
`upstream/staging` and `upstream/master`).
Then change the base branch in the GitHub PR using the *Edit* button in the upper
right corner, and switch from `master` to `staging`. *After* the PR has been
retargeted it might be necessary to do a final rebase onto the target branch, to
resolve any outstanding merge conflicts.
```console
# Rebase onto target branch
git rebase upstream/staging
# Review and fixup possible conflicts
git status
# Force push your changes
git push origin feature --force-with-lease
```
For package version upgrades and such a one-line commit message is usually sufficient.
## Backporting changes
Follow these steps to backport a change into a release branch in compliance with the [commit policy](https://nixos.org/nixpkgs/manual/#submitting-changes-stable-release-branches).
You can add a label such as `backport release-22.11` to a PR, so that merging it will
automatically create a backport (via [a GitHub Action](.github/workflows/backport.yml)).
This also works for PR's that have already been merged, and might take a couple of minutes to trigger.
You can also create the backport manually:
1. Take note of the commits in which the change was introduced into `master` branch.
2. Check out the target _release branch_, e.g. `release-22.11`. Do not use a _channel branch_ like `nixos-22.11` or `nixpkgs-22.11-darwin`.
2. Check out the target _release branch_, e.g. `release-20.09`. Do not use a _channel branch_ like `nixos-20.09` or `nixpkgs-20.09`.
3. Create a branch for your change, e.g. `git checkout -b backport`.
4. When the reason to backport is not obvious from the original commit message, use `git cherry-pick -xe <original commit>` and add a reason. Otherwise use `git cherry-pick -x <original commit>`. That's fine for minor version updates that only include security and bug fixes, commits that fixes an otherwise broken package or similar. Please also ensure the commits exists on the master branch; in the case of squashed or rebased merges, the commit hash will change and the new commits can be found in the merge message at the bottom of the master pull request.
5. Push to GitHub and open a backport pull request. Make sure to select the release branch (e.g. `release-22.11`) as the target branch of the pull request, and link to the pull request in which the original change was committed to `master`. The pull request title should be the commit title with the release version as prefix, e.g. `[22.11]`.
5. Push to GitHub and open a backport pull request. Make sure to select the release branch (e.g. `release-20.09`) as the target branch of the pull request, and link to the pull request in which the original change was comitted to `master`. The pull request title should be the commit title with the release version as prefix, e.g. `[20.09]`.
6. When the backport pull request is merged and you have the necessary privileges you can also replace the label `9.needs: port to stable` with `8.has: port to stable` on the original pull request. This way maintainers can keep track of missing backports easier.
## Criteria for Backporting changes
Anything that does not cause user or downstream dependency regressions can be backported. This includes:
- New Packages / Modules
- Security / Patch updates
- Version updates which include new functionality (but no breaking changes)
- Services which require a client to be up-to-date regardless. (E.g. `spotify`, `steam`, or `discord`)
- Security critical applications (E.g. `firefox`)
## Generating 23.05 Release Notes
<!--
note: title unchanged even though we don't need regeneration because extant
PRs will link here. definitely change the title for 23.11 though.
-->
Documentation in nixpkgs is transitioning to a markdown-centric workflow. In the past release notes required a translation step to convert from markdown to a compatible docbook document, but this is no longer necessary.
Steps for updating 23.05 Release notes:
1. Edit `nixos/doc/manual/release-notes/rl-2305.section.md` with the desired changes
2. Commit changes to `rl-2305.section.md`.
## Reviewing contributions
See the nixpkgs manual for more details on how to [Review contributions](https://nixos.org/nixpkgs/manual/#chap-reviewing-contributions).

View File

@@ -1,4 +1,4 @@
Copyright (c) 2003-2023 Eelco Dolstra and the Nixpkgs/NixOS contributors
Copyright (c) 2003-2021 Eelco Dolstra and the Nixpkgs/NixOS contributors
Permission is hereby granted, free of charge, to any person obtaining
a copy of this software and associated documentation files (the

View File

@@ -1,19 +1,14 @@
<p align="center">
<a href="https://nixos.org#gh-light-mode-only">
<img src="https://raw.githubusercontent.com/NixOS/nixos-homepage/master/logo/nixos-hires.png" width="500px" alt="NixOS logo"/>
</a>
<a href="https://nixos.org#gh-dark-mode-only">
<img src="https://raw.githubusercontent.com/NixOS/nixos-artwork/master/logo/nixos-white.png" width="500px" alt="NixOS logo"/>
</a>
<a href="https://nixos.org/nixos"><img src="https://nixos.org/logo/nixos-hires.png" width="500px" alt="NixOS logo" /></a>
</p>
<p align="center">
<a href="https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md"><img src="https://img.shields.io/github/contributors-anon/NixOS/nixpkgs" alt="Contributors badge" /></a>
<a href="https://opencollective.com/nixos"><img src="https://opencollective.com/nixos/tiers/supporter/badge.svg?label=supporters&color=brightgreen" alt="Open Collective supporters" /></a>
<a href="https://www.codetriage.com/nixos/nixpkgs"><img src="https://www.codetriage.com/nixos/nixpkgs/badges/users.svg" alt="Code Triagers badge" /></a>
<a href="https://opencollective.com/nixos"><img src="https://opencollective.com/nixos/tiers/supporter/badge.svg?label=Supporter&color=brightgreen" alt="Open Collective supporters" /></a>
</p>
[Nixpkgs](https://github.com/nixos/nixpkgs) is a collection of over
80,000 software packages that can be installed with the
60,000 software packages that can be installed with the
[Nix](https://nixos.org/nix/) package manager. It also implements
[NixOS](https://nixos.org/nixos/), a purely-functional Linux distribution.
@@ -26,10 +21,10 @@
# Community
* [Discourse Forum](https://discourse.nixos.org/)
* [Matrix Chat](https://matrix.to/#/#community:nixos.org)
* [IRC - #nixos on freenode.net](irc://irc.freenode.net/#nixos)
* [NixOS Weekly](https://weekly.nixos.org/)
* [Community-maintained wiki](https://nixos.wiki/)
* [Community-maintained list of ways to get in touch](https://nixos.wiki/wiki/Get_In_Touch#Chat) (Discord, Telegram, IRC, etc.)
* [Community-maintained list of ways to get in touch](https://nixos.wiki/wiki/Get_In_Touch#Chat) (Discord, Matrix, Telegram, other IRC channels, etc.)
# Other Project Repositories
@@ -51,14 +46,14 @@ Nixpkgs and NixOS are built and tested by our continuous integration
system, [Hydra](https://hydra.nixos.org/).
* [Continuous package builds for unstable/master](https://hydra.nixos.org/jobset/nixos/trunk-combined)
* [Continuous package builds for the NixOS 22.11 release](https://hydra.nixos.org/jobset/nixos/release-22.11)
* [Continuous package builds for the NixOS 20.09 release](https://hydra.nixos.org/jobset/nixos/release-20.09)
* [Tests for unstable/master](https://hydra.nixos.org/job/nixos/trunk-combined/tested#tabs-constituents)
* [Tests for the NixOS 22.11 release](https://hydra.nixos.org/job/nixos/release-22.11/tested#tabs-constituents)
* [Tests for the NixOS 20.09 release](https://hydra.nixos.org/job/nixos/release-20.09/tested#tabs-constituents)
Artifacts successfully built with Hydra are published to cache at
https://cache.nixos.org/. When successful build and test criteria are
met, the Nixpkgs expressions are distributed via [Nix
channels](https://nixos.org/manual/nix/stable/package-management/channels.html).
channels](https://nixos.org/nix/manual/#sec-channels).
# Contributing
@@ -102,8 +97,7 @@ Foundation](https://nixos.org/nixos/foundation.html). To ensure the
continuity and expansion of the NixOS infrastructure, we are looking
for donations to our organization.
You can donate to the NixOS foundation through [SEPA bank
transfers](https://nixos.org/donate.html) or by using Open Collective:
You can donate to the NixOS foundation by using Open Collective:
<a href="https://opencollective.com/nixos#support"><img src="https://opencollective.com/nixos/tiers/supporter.svg?width=890" /></a>

3
doc/.gitignore vendored
View File

@@ -6,6 +6,3 @@ functions/library/locations.xml
highlightjs
manual-full.xml
out
result
result-*
media

View File

@@ -1,27 +1,8 @@
MD_TARGETS=$(addsuffix .xml, $(basename $(shell find . -type f -regex '.*\.md$$' -not -name README.md)))
PANDOC ?= pandoc
pandoc_media_dir = media
# NOTE: Keep in sync with conversion script (/maintainers/scripts/db-to-md.sh).
# TODO: Remove raw-attribute when we can get rid of DocBook altogether.
pandoc_commonmark_enabled_extensions = +attributes+fenced_divs+footnotes+bracketed_spans+definition_lists+pipe_tables+raw_attribute
# Not needed:
# - docbook-reader/citerefentry-to-rst-role.lua (only relevant for DocBook → MarkDown/rST/MyST)
pandoc_flags = --extract-media=$(pandoc_media_dir) \
--lua-filter=$(PANDOC_LUA_FILTERS_DIR)/diagram-generator.lua \
--lua-filter=build-aux/pandoc-filters/myst-reader/roles.lua \
--lua-filter=$(PANDOC_LINK_MANPAGES_FILTER) \
--lua-filter=build-aux/pandoc-filters/docbook-writer/rst-roles.lua \
--lua-filter=build-aux/pandoc-filters/docbook-writer/labelless-link-is-xref.lua \
-f commonmark$(pandoc_commonmark_enabled_extensions)+smart
.PHONY: all
all: validate format out/html/index.html out/epub/manual.epub
.PHONY: render-md
render-md: ${MD_TARGETS}
.PHONY: debug
debug:
nix-shell --run "xmloscopy --docbook5 ./manual.xml ./manual-full.xml"
@@ -41,7 +22,7 @@ fix-misc-xml:
.PHONY: clean
clean:
rm -f ${MD_TARGETS} doc-support/result .version manual-full.xml functions/library/locations.xml functions/library/generated
rm -rf ./out/ ./highlightjs ./media
rm -rf ./out/ ./highlightjs
.PHONY: validate
validate: manual-full.xml doc-support/result
@@ -58,7 +39,7 @@ out/html/index.html: doc-support/result manual-full.xml style.css highlightjs
mkdir -p out/html/highlightjs/
cp -r highlightjs out/html/
cp -r $(pandoc_media_dir) out/html/
cp -r media out/html/
cp ./overrides.css out/html/
cp ./style.css out/html/style.css
@@ -73,7 +54,7 @@ out/epub/manual.epub: manual-full.xml
doc-support/result/epub.xsl \
./manual-full.xml
cp -r $(pandoc_media_dir) out/epub/scratch/OEBPS
cp -r media out/epub/scratch/OEBPS
cp ./overrides.css out/epub/scratch/OEBPS
cp ./style.css out/epub/scratch/OEBPS
mkdir -p out/epub/scratch/OEBPS/images/callouts/
@@ -108,12 +89,16 @@ functions/library/generated: doc-support/result
ln -rfs ./doc-support/result/function-docs functions/library/generated
%.section.xml: %.section.md
$(PANDOC) $^ -t docbook \
$(pandoc_flags) \
-o $@
pandoc $^ -t docbook \
--extract-media=media \
--lua-filter=$(PANDOC_LUA_FILTERS_DIR)/diagram-generator.lua \
-f markdown+smart \
| cat > $@
%.chapter.xml: %.chapter.md
$(PANDOC) $^ -t docbook \
pandoc $^ -t docbook \
--top-level-division=chapter \
$(pandoc_flags) \
-o $@
--extract-media=media \
--lua-filter=$(PANDOC_LUA_FILTERS_DIR)/diagram-generator.lua \
-f markdown+smart \
| cat > $@

View File

@@ -1,23 +0,0 @@
--[[
Converts Code AST nodes produced by pandocs DocBook reader
from citerefentry elements into AST for corresponding role
for reStructuredText.
We use subset of MyST syntax (CommonMark with features from rST)
so lets use the rST AST for rST features.
Reference: https://www.sphinx-doc.org/en/master/usage/restructuredtext/roles.html#role-manpage
]]
function Code(elem)
elem.classes = elem.classes:map(function (x)
if x == 'citerefentry' then
elem.attributes['role'] = 'manpage'
return 'interpreted-text'
else
return x
end
end)
return elem
end

View File

@@ -1,34 +0,0 @@
--[[
Converts Link AST nodes with empty label to DocBook xref elements.
This is a temporary script to be able use cross-references conveniently
using syntax taken from MyST, while we still use docbook-xsl
for generating the documentation.
Reference: https://myst-parser.readthedocs.io/en/latest/using/syntax.html#targets-and-cross-referencing
]]
local function starts_with(start, str)
return str:sub(1, #start) == start
end
local function escape_xml_arg(arg)
amps = arg:gsub('&', '&amp;')
amps_quotes = amps:gsub('"', '&quot;')
amps_quotes_lt = amps_quotes:gsub('<', '&lt;')
return amps_quotes_lt
end
function Link(elem)
has_no_content = #elem.content == 0
targets_anchor = starts_with('#', elem.target)
has_no_attributes = elem.title == '' and elem.identifier == '' and #elem.classes == 0 and #elem.attributes == 0
if has_no_content and targets_anchor and has_no_attributes then
-- xref expects idref without the pound-sign
target_without_hash = elem.target:sub(2, #elem.target)
return pandoc.RawInline('docbook', '<xref linkend="' .. escape_xml_arg(target_without_hash) .. '" />')
end
end

View File

@@ -1,44 +0,0 @@
--[[
Converts AST for reStructuredText roles into corresponding
DocBook elements.
Currently, only a subset of roles is supported.
Reference:
List of roles:
https://www.sphinx-doc.org/en/master/usage/restructuredtext/roles.html
manpage:
https://tdg.docbook.org/tdg/5.1/citerefentry.html
file:
https://tdg.docbook.org/tdg/5.1/filename.html
]]
function Code(elem)
if elem.classes:includes('interpreted-text') then
local tag = nil
local content = elem.text
if elem.attributes['role'] == 'manpage' then
tag = 'citerefentry'
local title, volnum = content:match('^(.+)%((%w+)%)$')
if title == nil then
-- No volnum in parentheses.
title = content
end
content = '<refentrytitle>' .. title .. '</refentrytitle>' .. (volnum ~= nil and ('<manvolnum>' .. volnum .. '</manvolnum>') or '')
elseif elem.attributes['role'] == 'file' then
tag = 'filename'
elseif elem.attributes['role'] == 'command' then
tag = 'command'
elseif elem.attributes['role'] == 'option' then
tag = 'option'
elseif elem.attributes['role'] == 'var' then
tag = 'varname'
elseif elem.attributes['role'] == 'env' then
tag = 'envar'
end
if tag ~= nil then
return pandoc.RawInline('docbook', '<' .. tag .. '>' .. content .. '</' .. tag .. '>')
end
end
end

View File

@@ -1,28 +0,0 @@
{ pkgs ? import ../../.. {} }:
let
inherit (pkgs) lib;
manpageURLs = lib.importJSON (pkgs.path + "/doc/manpage-urls.json");
in pkgs.writeText "link-manpages.lua" ''
--[[
Adds links to known man pages that aren't already in a link.
]]
local manpage_urls = {
${lib.concatStringsSep "\n" (lib.mapAttrsToList (man: url:
" [${builtins.toJSON man}] = ${builtins.toJSON url},") manpageURLs)}
}
traverse = 'topdown'
-- Returning false as the second value aborts processing of child elements.
function Link(elem)
return elem, false
end
function Code(elem)
local is_man_role = elem.classes:includes('interpreted-text') and elem.attributes['role'] == 'manpage'
if is_man_role and manpage_urls[elem.text] ~= nil then
return pandoc.Link(elem, manpage_urls[elem.text]), false
end
end
''

View File

@@ -1,36 +0,0 @@
--[[
Replaces Str AST nodes containing {role}, followed by a Code node
by a Code node with attrs that would be produced by rST reader
from the role syntax.
This is to emulate MyST syntax in Pandoc.
(MyST is a CommonMark flavour with rST features mixed in.)
Reference: https://myst-parser.readthedocs.io/en/latest/syntax/syntax.html#roles-an-in-line-extension-point
]]
function Inlines(inlines)
for i = #inlines-1,1,-1 do
local first = inlines[i]
local second = inlines[i+1]
local correct_tags = first.tag == 'Str' and second.tag == 'Code'
if correct_tags then
-- docutils supports alphanumeric strings separated by [-._:]
-- We are slightly more liberal for simplicity.
-- Allow preceding punctuation (eg '('), otherwise '({file}`...`)'
-- does not match. Also allow anything followed by a non-breaking space
-- since pandoc emits those after certain abbreviations (e.g. e.g.).
local prefix, role = first.text:match('^(.*){([-._+:%w]+)}$')
if role ~= nil and (prefix == '' or prefix:match("^.*[%p ]$") ~= nil) then
if prefix == '' then
inlines:remove(i)
else
first.text = prefix
end
second.attributes['role'] = role
second.classes:insert('interpreted-text')
end
end
end
return inlines
end

View File

@@ -1,25 +0,0 @@
--[[
Replaces Code nodes with attrs that would be produced by rST reader
from the role syntax by a Str AST node containing {role}, followed by a Code node.
This is to emulate MyST syntax in Pandoc.
(MyST is a CommonMark flavour with rST features mixed in.)
Reference: https://myst-parser.readthedocs.io/en/latest/syntax/syntax.html#roles-an-in-line-extension-point
]]
function Code(elem)
local role = elem.attributes['role']
if elem.classes:includes('interpreted-text') and role ~= nil then
elem.classes = elem.classes:filter(function (c)
return c ~= 'interpreted-text'
end)
elem.attributes['role'] = nil
return {
pandoc.Str('{' .. role .. '}'),
elem,
}
end
end

View File

@@ -1,55 +1,8 @@
# Fetchers {#chap-pkgs-fetchers}
Building software with Nix often requires downloading source code and other files from the internet.
`nixpkgs` provides *fetchers* for different protocols and services. Fetchers are functions that simplify downloading files.
When using Nix, you will frequently need to download source code and other files from the internet. Nixpkgs comes with a few helper functions that allow you to fetch fixed-output derivations in a structured way.
## Caveats {#chap-pkgs-fetchers-caveats}
Fetchers create [fixed output derivations](https://nixos.org/manual/nix/stable/#fixed-output-drvs) from downloaded files.
Nix can reuse the downloaded files via the hash of the resulting derivation.
The fact that the hash belongs to the Nix derivation output and not the file itself can lead to confusion.
For example, consider the following fetcher:
```nix
fetchurl {
url = "http://www.example.org/hello-1.0.tar.gz";
hash = "sha256-lTeyxzJNQeMdu1IVdovNMtgn77jRIhSybLdMbTkf2Ww=";
};
```
A common mistake is to update a fetchers URL, or a version parameter, without updating the hash.
```nix
fetchurl {
url = "http://www.example.org/hello-1.1.tar.gz";
hash = "sha256-lTeyxzJNQeMdu1IVdovNMtgn77jRIhSybLdMbTkf2Ww=";
};
```
**This will reuse the old contents**.
Remember to invalidate the hash argument, in this case by setting the `hash` attribute to an empty string.
```nix
fetchurl {
url = "http://www.example.org/hello-1.1.tar.gz";
hash = "";
};
```
Use the resulting error message to determine the correct hash.
```
error: hash mismatch in fixed-output derivation '/path/to/my.drv':
specified: sha256-AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=
got: sha256-lTeyxzJNQeMdu1IVdovNMtgn77jRIhSybLdMbTkf2Ww=
```
A similar problem arises while testing changes to a fetcher's implementation. If the output of the derivation already exists in the Nix store, test failures can go undetected. The [`invalidateFetcherByDrvHash`](#tester-invalidateFetcherByDrvHash) function helps prevent reusing cached derivations.
## `fetchurl` and `fetchzip` {#fetchurl}
Two basic fetchers are `fetchurl` and `fetchzip`. Both of these have two required arguments, a URL and a hash. The hash is typically `hash`, although many more hash algorithms are supported. Nixpkgs contributors are currently recommended to use `hash`. This hash will be used by Nix to identify your source. A typical usage of `fetchurl` is provided below.
The two fetcher primitives are `fetchurl` and `fetchzip`. Both of these have two required arguments, a URL and a hash. The hash is typically `sha256`, although many more hash algorithms are supported. Nixpkgs contributors are currently recommended to use `sha256`. This hash will be used by Nix to identify your source. A typical usage of fetchurl is provided below.
```nix
{ stdenv, fetchurl }:
@@ -58,136 +11,68 @@ stdenv.mkDerivation {
name = "hello";
src = fetchurl {
url = "http://www.example.org/hello.tar.gz";
hash = "sha256-BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB=";
sha256 = "1111111111111111111111111111111111111111111111111111";
};
}
```
The main difference between `fetchurl` and `fetchzip` is in how they store the contents. `fetchurl` will store the unaltered contents of the URL within the Nix store. `fetchzip` on the other hand, will decompress the archive for you, making files and directories directly accessible in the future. `fetchzip` can only be used with archives. Despite the name, `fetchzip` is not limited to .zip files and can also be used with any tarball.
The main difference between `fetchurl` and `fetchzip` is in how they store the contents. `fetchurl` will store the unaltered contents of the URL within the Nix store. `fetchzip` on the other hand will decompress the archive for you, making files and directories directly accessible in the future. `fetchzip` can only be used with archives. Despite the name, `fetchzip` is not limited to .zip files and can also be used with any tarball.
## `fetchpatch` {#fetchpatch}
`fetchpatch` works very similarly to `fetchurl` with the same arguments expected. It expects patch files as a source and performs normalization on them before computing the checksum. For example, it will remove comments or other unstable parts that are sometimes added by version control systems and can change over time.
- `relative`: Similar to using `git-diff`'s `--relative` flag, only keep changes inside the specified directory, making paths relative to it.
- `stripLen`: Remove the first `stripLen` components of pathnames in the patch.
- `decode`: Pipe the downloaded data through this command before processing it as a patch.
- `extraPrefix`: Prefix pathnames by this string.
- `excludes`: Exclude files matching these patterns (applies after the above arguments).
- `includes`: Include only files matching these patterns (applies after the above arguments).
- `revert`: Revert the patch.
Note that because the checksum is computed after applying these effects, using or modifying these arguments will have no effect unless the `hash` argument is changed as well.
`fetchpatch` works very similarly to `fetchurl` with the same arguments expected. It expects patch files as a source and performs normalization on them before computing the checksum. For example it will remove comments or other unstable parts that are sometimes added by version control systems and can change over time.
Most other fetchers return a directory rather than a single file.
Other fetcher functions allow you to add source code directly from a VCS such as subversion or git. These are mostly straightforward nambes based on the name of the command used with the VCS system. Because they give you a working repository, they act most like `fetchzip`.
## `fetchsvn` {#fetchsvn}
## `fetchsvn`
Used with Subversion. Expects `url` to a Subversion directory, `rev`, and `hash`.
Used with Subversion. Expects `url` to a Subversion directory, `rev`, and `sha256`.
## `fetchgit` {#fetchgit}
## `fetchgit`
Used with Git. Expects `url` to a Git repo, `rev`, and `hash`. `rev` in this case can be full the git commit id (SHA1 hash) or a tag name like `refs/tags/v1.0`.
Used with Git. Expects `url` to a Git repo, `rev`, and `sha256`. `rev` in this case can be full the git commit id (SHA1 hash) or a tag name like `refs/tags/v1.0`.
Additionally, the following optional arguments can be given: `fetchSubmodules = true` makes `fetchgit` also fetch the submodules of a repository. If `deepClone` is set to true, the entire repository is cloned as opposing to just creating a shallow clone. `deepClone = true` also implies `leaveDotGit = true` which means that the `.git` directory of the clone won't be removed after checkout.
Additionally the following optional arguments can be given: `fetchSubmodules = true` makes `fetchgit` also fetch the submodules of a repository. If `deepClone` is set to true, the entire repository is cloned as opposing to just creating a shallow clone. `deepClone = true` also implies `leaveDotGit = true` which means that the `.git` directory of the clone won't be removed after checkout.
If only parts of the repository are needed, `sparseCheckout` can be used. This will prevent git from fetching unnecessary blobs from server, see [git sparse-checkout](https://git-scm.com/docs/git-sparse-checkout) for more information:
## `fetchfossil`
```nix
{ stdenv, fetchgit }:
Used with Fossil. Expects `url` to a Fossil archive, `rev`, and `sha256`.
stdenv.mkDerivation {
name = "hello";
src = fetchgit {
url = "https://...";
sparseCheckout = [
"directory/to/be/included"
"another/directory"
];
hash = "sha256-AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=";
};
}
```
## `fetchcvs`
## `fetchfossil` {#fetchfossil}
Used with CVS. Expects `cvsRoot`, `tag`, and `sha256`.
Used with Fossil. Expects `url` to a Fossil archive, `rev`, and `hash`.
## `fetchhg`
## `fetchcvs` {#fetchcvs}
Used with CVS. Expects `cvsRoot`, `tag`, and `hash`.
## `fetchhg` {#fetchhg}
Used with Mercurial. Expects `url`, `rev`, and `hash`.
Used with Mercurial. Expects `url`, `rev`, and `sha256`.
A number of fetcher functions wrap part of `fetchurl` and `fetchzip`. They are mainly convenience functions intended for commonly used destinations of source code in Nixpkgs. These wrapper fetchers are listed below.
## `fetchFromGitea` {#fetchfromgitea}
## `fetchFromGitHub`
`fetchFromGitea` expects five arguments. `domain` is the gitea server name. `owner` is a string corresponding to the Gitea user or organization that controls this repository. `repo` corresponds to the name of the software repository. These are located at the top of every Gitea HTML page as `owner`/`repo`. `rev` corresponds to the Git commit hash or tag (e.g `v1.0`) that will be downloaded from Git. Finally, `hash` corresponds to the hash of the extracted directory. Again, other hash algorithms are also available but `hash` is currently preferred.
## `fetchFromGitHub` {#fetchfromgithub}
`fetchFromGitHub` expects four arguments. `owner` is a string corresponding to the GitHub user or organization that controls this repository. `repo` corresponds to the name of the software repository. These are located at the top of every GitHub HTML page as `owner`/`repo`. `rev` corresponds to the Git commit hash or tag (e.g `v1.0`) that will be downloaded from Git. Finally, `hash` corresponds to the hash of the extracted directory. Again, other hash algorithms are also available, but `hash` is currently preferred.
`fetchFromGitHub` expects four arguments. `owner` is a string corresponding to the GitHub user or organization that controls this repository. `repo` corresponds to the name of the software repository. These are located at the top of every GitHub HTML page as `owner`/`repo`. `rev` corresponds to the Git commit hash or tag (e.g `v1.0`) that will be downloaded from Git. Finally, `sha256` corresponds to the hash of the extracted directory. Again, other hash algorithms are also available but `sha256` is currently preferred.
`fetchFromGitHub` uses `fetchzip` to download the source archive generated by GitHub for the specified revision. If `leaveDotGit`, `deepClone` or `fetchSubmodules` are set to `true`, `fetchFromGitHub` will use `fetchgit` instead. Refer to its section for documentation of these options.
## `fetchFromGitLab` {#fetchfromgitlab}
## `fetchFromGitLab`
This is used with GitLab repositories. The arguments expected are very similar to `fetchFromGitHub` above.
This is used with GitLab repositories. The arguments expected are very similar to fetchFromGitHub above.
## `fetchFromGitiles` {#fetchfromgitiles}
## `fetchFromGitiles`
This is used with Gitiles repositories. The arguments expected are similar to `fetchgit`.
This is used with Gitiles repositories. The arguments expected are similar to fetchgit.
## `fetchFromBitbucket` {#fetchfrombitbucket}
## `fetchFromBitbucket`
This is used with BitBucket repositories. The arguments expected are very similar to fetchFromGitHub above.
## `fetchFromSavannah` {#fetchfromsavannah}
## `fetchFromSavannah`
This is used with Savannah repositories. The arguments expected are very similar to `fetchFromGitHub` above.
This is used with Savannah repositories. The arguments expected are very similar to fetchFromGitHub above.
## `fetchFromRepoOrCz` {#fetchfromrepoorcz}
## `fetchFromRepoOrCz`
This is used with repo.or.cz repositories. The arguments expected are very similar to `fetchFromGitHub` above.
This is used with repo.or.cz repositories. The arguments expected are very similar to fetchFromGitHub above.
## `fetchFromSourcehut` {#fetchfromsourcehut}
## `fetchFromSourcehut`
This is used with sourcehut repositories. Similar to `fetchFromGitHub` above,
it expects `owner`, `repo`, `rev` and `hash`, but don't forget the tilde (~)
in front of the username! Expected arguments also include `vc` ("git" (default)
or "hg"), `domain` and `fetchSubmodules`.
If `fetchSubmodules` is `true`, `fetchFromSourcehut` uses `fetchgit`
or `fetchhg` with `fetchSubmodules` or `fetchSubrepos` set to `true`,
respectively. Otherwise, the fetcher uses `fetchzip`.
## `requireFile` {#requirefile}
`requireFile` allows requesting files that cannot be fetched automatically, but whose content is known.
This is a useful last-resort workaround for license restrictions that prohibit redistribution, or for downloads that are only accessible after authenticating interactively in a browser.
If the requested file is present in the Nix store, the resulting derivation will not be built, because its expected output is already available.
Otherwise, the builder will run, but fail with a message explaining to the user how to provide the file. The following code, for example:
```
requireFile {
name = "jdk-${version}_linux-x64_bin.tar.gz";
url = "https://www.oracle.com/java/technologies/javase-jdk11-downloads.html";
sha256 = "94bd34f85ee38d3ef59e5289ec7450b9443b924c55625661fffe66b03f2c8de2";
}
```
results in this error message:
```
***
Unfortunately, we cannot download file jdk-11.0.10_linux-x64_bin.tar.gz automatically.
Please go to https://www.oracle.com/java/technologies/javase-jdk11-downloads.html to download it yourself, and add it to the Nix store
using either
nix-store --add-fixed sha256 jdk-11.0.10_linux-x64_bin.tar.gz
or
nix-prefetch-url --type sha256 file:///path/to/jdk-11.0.10_linux-x64_bin.tar.gz
***
```
This is used with sourcehut repositories. The arguments expected are very similar to fetchFromGitHub above. Don't forget the tilde (~) in front of the user name!

View File

@@ -9,7 +9,4 @@
<xi:include href="images/dockertools.section.xml" />
<xi:include href="images/ocitools.section.xml" />
<xi:include href="images/snaptools.section.xml" />
<xi:include href="images/portableservice.section.xml" />
<xi:include href="images/makediskimage.section.xml" />
<xi:include href="images/binarycache.section.xml" />
</chapter>

View File

@@ -2,7 +2,7 @@
`pkgs.appimageTools` is a set of functions for extracting and wrapping [AppImage](https://appimage.org/) files. They are meant to be used if traditional packaging from source is infeasible, or it would take too long. To quickly run an AppImage file, `pkgs.appimage-run` can be used as well.
::: {.warning}
::: warning
The `appimageTools` API is unstable and may be subject to backwards-incompatible changes in the future.
:::
@@ -35,7 +35,7 @@ appimageTools.wrapType2 { # or wrapType1
name = "patchwork";
src = fetchurl {
url = "https://github.com/ssbc/patchwork/releases/download/v3.11.4/Patchwork-3.11.4-linux-x86_64.AppImage";
hash = "sha256-OqTitCeZ6xmWbqYTXp8sDrmVgTNjPZNW0hzUPW++mq4=";
sha256 = "1blsprpkvm0ws9b96gb36f0rbf8f5jgmw4x6dsb1kswr4ysf591s";
};
extraPkgs = pkgs: with pkgs; [ ];
}

View File

@@ -1,49 +0,0 @@
# pkgs.mkBinaryCache {#sec-pkgs-binary-cache}
`pkgs.mkBinaryCache` is a function for creating Nix flat-file binary caches. Such a cache exists as a directory on disk, and can be used as a Nix substituter by passing `--substituter file:///path/to/cache` to Nix commands.
Nix packages are most commonly shared between machines using [HTTP, SSH, or S3](https://nixos.org/manual/nix/stable/package-management/sharing-packages.html), but a flat-file binary cache can still be useful in some situations. For example, you can copy it directly to another machine, or make it available on a network file system. It can also be a convenient way to make some Nix packages available inside a container via bind-mounting.
Note that this function is meant for advanced use-cases. The more idiomatic way to work with flat-file binary caches is via the [nix-copy-closure](https://nixos.org/manual/nix/stable/command-ref/nix-copy-closure.html) command. You may also want to consider [dockerTools](#sec-pkgs-dockerTools) for your containerization needs.
## Example {#sec-pkgs-binary-cache-example}
The following derivation will construct a flat-file binary cache containing the closure of `hello`.
```nix
mkBinaryCache {
rootPaths = [hello];
}
```
- `rootPaths` specifies a list of root derivations. The transitive closure of these derivations' outputs will be copied into the cache.
Here's an example of building and using the cache.
Build the cache on one machine, `host1`:
```shellSession
nix-build -E 'with import <nixpkgs> {}; mkBinaryCache { rootPaths = [hello]; }'
```
```shellSession
/nix/store/cc0562q828rnjqjyfj23d5q162gb424g-binary-cache
```
Copy the resulting directory to the other machine, `host2`:
```shellSession
scp result host2:/tmp/hello-cache
```
Substitute the derivation using the flat-file binary cache on the other machine, `host2`:
```shellSession
nix-build -A hello '<nixpkgs>' \
--option require-sigs false \
--option trusted-substituters file:///tmp/hello-cache \
--option substituters file:///tmp/hello-cache
```
```shellSession
/nix/store/gl5a41azbpsadfkfmbilh9yk40dh5dl0-hello-2.12.1
```

View File

@@ -1,6 +1,6 @@
# pkgs.dockerTools {#sec-pkgs-dockerTools}
`pkgs.dockerTools` is a set of functions for creating and manipulating Docker images according to the [Docker Image Specification v1.2.0](https://github.com/moby/moby/blob/master/image/spec/v1.2.md#docker-image-specification-v120). Docker itself is not used to perform any of the operations done by these functions.
`pkgs.dockerTools` is a set of functions for creating and manipulating Docker images according to the [ Docker Image Specification v1.2.0 ](https://github.com/moby/moby/blob/master/image/spec/v1.2.md#docker-image-specification-v120). Docker itself is not used to perform any of the operations done by these functions.
## buildImage {#ssec-pkgs-dockerTools-buildImage}
@@ -20,12 +20,7 @@ buildImage {
fromImageName = null;
fromImageTag = "latest";
copyToRoot = pkgs.buildEnv {
name = "image-root";
paths = [ pkgs.redis ];
pathsToLink = [ "/bin" ];
};
contents = pkgs.redis;
runAsRoot = ''
#!${pkgs.runtimeShell}
mkdir -p /data
@@ -36,9 +31,6 @@ buildImage {
WorkingDir = "/data";
Volumes = { "/data" = { }; };
};
diskSize = 1024;
buildVMMemorySize = 512;
}
```
@@ -54,25 +46,19 @@ The above example will build a Docker image `redis/latest` from the given base i
- `fromImageTag` can be used to further specify the tag of the base image within the repository, in case an image contains multiple tags. By default it's `null`, in which case `buildImage` will peek the first tag available for the base image.
- `copyToRoot` is a derivation that will be copied in the new layer of the resulting image. This can be similarly seen as `ADD contents/ /` in a `Dockerfile`. By default it's `null`.
- `contents` is a derivation that will be copied in the new layer of the resulting image. This can be similarly seen as `ADD contents/ /` in a `Dockerfile`. By default it's `null`.
- `runAsRoot` is a bash script that will run as root in an environment that overlays the existing layers of the base image with the new resulting layer, including the previously copied `contents` derivation. This can be similarly seen as `RUN ...` in a `Dockerfile`.
> **_NOTE:_** Using this parameter requires the `kvm` device to be available.
- `config` is used to specify the configuration of the containers that will be started off the built image in Docker. The available options are listed in the [Docker Image Specification v1.2.0](https://github.com/moby/moby/blob/master/image/spec/v1.2.md#image-json-field-descriptions).
- `architecture` is _optional_ and used to specify the image architecture, this is useful for multi-architecture builds that don't need cross compiling. If not specified it will default to `hostPlatform`.
- `diskSize` is used to specify the disk size of the VM used to build the image in megabytes. By default it's 1024 MiB.
- `buildVMMemorySize` is used to specify the memory size of the VM to build the image in megabytes. By default it's 512 MiB.
- `config` is used to specify the configuration of the containers that will be started off the built image in Docker. The available options are listed in the [ Docker Image Specification v1.2.0 ](https://github.com/moby/moby/blob/master/image/spec/v1.2.md#image-json-field-descriptions).
After the new layer has been created, its closure (to which `contents`, `config` and `runAsRoot` contribute) will be copied in the layer itself. Only new dependencies that are not already in the existing layers will be copied.
At the end of the process, only one new single layer will be produced and added to the resulting image.
The resulting repository will only list the single image `image/tag`. In the case of [the `buildImage` example](#ex-dockerTools-buildImage), it would be `redis/latest`.
The resulting repository will only list the single image `image/tag`. In the case of [the `buildImage` example](#ex-dockerTools-buildImage) it would be `redis/latest`.
It is possible to inspect the arguments with which an image was built using its `buildArgs` attribute.
@@ -95,17 +81,13 @@ pkgs.dockerTools.buildImage {
name = "hello";
tag = "latest";
created = "now";
copyToRoot = pkgs.buildEnv {
name = "image-root";
paths = [ pkgs.hello ];
pathsToLink = [ "/bin" ];
};
contents = pkgs.hello;
config.Cmd = [ "/bin/hello" ];
}
```
Now the Docker CLI will display a reasonable date and sort the images as expected:
and now the Docker CLI will display a reasonable date and sort the images as expected:
```ShellSession
$ docker images
@@ -113,7 +95,7 @@ REPOSITORY TAG IMAGE ID CREATED SIZE
hello latest de2bf4786de6 About a minute ago 25.2MB
```
However, the produced images will not be binary reproducible.
however, the produced images will not be binary reproducible.
## buildLayeredImage {#ssec-pkgs-dockerTools-buildLayeredImage}
@@ -137,15 +119,13 @@ Create a Docker image with many of the store paths being on their own layer to i
`contents` _optional_
: Top-level paths in the container. Either a single derivation, or a list of derivations.
: Top level paths in the container. Either a single derivation, or a list of derivations.
*Default:* `[]`
`config` _optional_
`architecture` is _optional_ and used to specify the image architecture, this is useful for multi-architecture builds that don't need cross compiling. If not specified it will default to `hostPlatform`.
: Run-time configuration of the container. A full list of the options available is in the [Docker Image Specification v1.2.0](https://github.com/moby/moby/blob/master/image/spec/v1.2.md#image-json-field-descriptions).
: Run-time configuration of the container. A full list of the options are available at in the [ Docker Image Specification v1.2.0 ](https://github.com/moby/moby/blob/master/image/spec/v1.2.md#image-json-field-descriptions).
*Default:* `{}`
@@ -171,12 +151,6 @@ Create a Docker image with many of the store paths being on their own layer to i
: Shell commands to run while creating the archive for the final layer in a fakeroot environment. Unlike `extraCommands`, you can run `chown` to change the owners of the files in the archive, changing fakeroot's state instead of the real filesystem. The latter would require privileges that the build user does not have. Static binaries do not interact with the fakeroot environment. By default all files in the archive will be owned by root.
`enableFakechroot` _optional_
: Whether to run in `fakeRootCommands` in `fakechroot`, making programs behave as though `/` is the root of the image being created, while files in the Nix store are available as usual. This allows scripts that perform installation in `/` to work as expected. Considering that `fakechroot` is implemented via the same mechanism as `fakeroot`, the same caveats apply.
*Default:* `false`
### Behavior of `contents` in the final image {#dockerTools-buildLayeredImage-arg-contents}
Each path directly listed in `contents` will have a symlink in the root of the image.
@@ -215,9 +189,9 @@ pkgs.dockerTools.buildLayeredImage {
Increasing the `maxLayers` increases the number of layers which have a chance to be shared between different images.
Modern Docker installations support up to 128 layers, but older versions support as few as 42.
Modern Docker installations support up to 128 layers, however older versions support as few as 42.
If the produced image will not be extended by other Docker builds, it is safe to set `maxLayers` to `128`. However, it will be impossible to extend the image further.
If the produced image will not be extended by other Docker builds, it is safe to set `maxLayers` to `128`. However it will be impossible to extend the image further.
The first (`maxLayers-2`) most "popular" paths will have their own individual layers, then layer \#`maxLayers-1` will contain all the remaining "unpopular" paths, and finally layer \#`maxLayers` will contain the Image configuration.
@@ -233,7 +207,7 @@ The image produced by running the output script can be piped directly into `dock
$(nix-build) | docker load
```
Alternatively, the image be piped via `gzip` into `skopeo`, e.g., to copy it into a registry:
Alternatively, the image be piped via `gzip` into `skopeo`, e.g. to copy it into a registry:
```ShellSession
$(nix-build) | gzip --fast | skopeo copy docker-archive:/dev/stdin docker://some_docker_registry/myimage:tag
@@ -249,10 +223,10 @@ Its parameters are described in the example below:
pullImage {
imageName = "nixos/nix";
imageDigest =
"sha256:473a2b527958665554806aea24d0131bacec46d23af09fef4598eeab331850fa";
"sha256:20d9485b25ecfd89204e843a962c1bd70e9cc6858d65d7f5fadc340246e2116b";
finalImageName = "nix";
finalImageTag = "2.11.1";
sha256 = "sha256-qvhj+Hlmviz+KEBVmsyPIzTB3QlVAFzwAY1zDPIBGxc=";
finalImageTag = "1.11";
sha256 = "0mqjy3zq2v6rrhizgb9nvhczl87lcfphq9601wcprdika2jz7qh8";
os = "linux";
arch = "x86_64";
}
@@ -312,44 +286,7 @@ The parameters relative to the base image have the same synopsis as described in
The `name` argument is the name of the derivation output, which defaults to `fromImage.name`.
## Environment Helpers {#ssec-pkgs-dockerTools-helpers}
Some packages expect certain files to be available globally.
When building an image from scratch (i.e. without `fromImage`), these files are missing.
`pkgs.dockerTools` provides some helpers to set up an environment with the necessary files.
You can include them in `copyToRoot` like this:
```nix
buildImage {
name = "environment-example";
copyToRoot = with pkgs.dockerTools; [
usrBinEnv
binSh
caCertificates
fakeNss
];
}
```
### usrBinEnv {#sssec-pkgs-dockerTools-helpers-usrBinEnv}
This provides the `env` utility at `/usr/bin/env`.
### binSh {#sssec-pkgs-dockerTools-helpers-binSh}
This provides `bashInteractive` at `/bin/sh`.
### caCertificates {#sssec-pkgs-dockerTools-helpers-caCertificates}
This sets up `/etc/ssl/certs/ca-certificates.crt`.
### fakeNss {#sssec-pkgs-dockerTools-helpers-fakeNss}
Provides `/etc/passwd` and `/etc/group` that contain root and nobody.
Useful when packaging binaries that insist on using nss to look up
username/groups (like nginx).
### shadowSetup {#ssec-pkgs-dockerTools-shadowSetup}
## shadowSetup {#ssec-pkgs-dockerTools-shadowSetup}
This constant string is a helper for setting up the base files for managing users and groups, only if such files don't exist already. It is suitable for being used in a [`buildImage` `runAsRoot`](#ex-dockerTools-buildImage-runAsRoot) script for cases like in the example below:
@@ -359,7 +296,7 @@ buildImage {
runAsRoot = ''
#!${pkgs.runtimeShell}
${pkgs.dockerTools.shadowSetup}
${shadowSetup}
groupadd -r redis
useradd -r -g redis redis
mkdir /data
@@ -369,171 +306,3 @@ buildImage {
```
Creating base files like `/etc/passwd` or `/etc/login.defs` is necessary for shadow-utils to manipulate users and groups.
## fakeNss {#ssec-pkgs-dockerTools-fakeNss}
If your primary goal is providing a basic skeleton for user lookups to work,
and/or a lesser privileged user, adding `pkgs.fakeNss` to
the container image root might be the better choice than a custom script
running `useradd` and friends.
It provides a `/etc/passwd` and `/etc/group`, containing `root` and `nobody`
users and groups.
It also provides a `/etc/nsswitch.conf`, configuring NSS host resolution to
first check `/etc/hosts`, before checking DNS, as the default in the absence of
a config file (`dns [!UNAVAIL=return] files`) is quite unexpected.
You can pair it with `binSh`, which provides `bin/sh` as a symlink
to `bashInteractive` (as `/bin/sh` is configured as a shell).
```nix
buildImage {
name = "shadow-basic";
copyToRoot = pkgs.buildEnv {
name = "image-root";
paths = [ binSh pkgs.fakeNss ];
pathsToLink = [ "/bin" "/etc" "/var" ];
};
}
```
## buildNixShellImage {#ssec-pkgs-dockerTools-buildNixShellImage}
Create a Docker image that sets up an environment similar to that of running `nix-shell` on a derivation.
When run in Docker, this environment somewhat resembles the Nix sandbox typically used by `nix-build`, with a major difference being that access to the internet is allowed.
It additionally also behaves like an interactive `nix-shell`, running things like `shellHook` and setting an interactive prompt.
If the derivation is fully buildable (i.e. `nix-build` can be used on it), running `buildDerivation` inside such a Docker image will build the derivation, with all its outputs being available in the correct `/nix/store` paths, pointed to by the respective environment variables like `$out`, etc.
::: {.warning}
The behavior doesn't match `nix-shell` or `nix-build` exactly and this function is known not to work correctly for e.g. fixed-output derivations, content-addressed derivations, impure derivations and other special types of derivations.
:::
### Arguments {#ssec-pkgs-dockerTools-buildNixShellImage-arguments}
`drv`
: The derivation on which to base the Docker image.
Adding packages to the Docker image is possible by e.g. extending the list of `nativeBuildInputs` of this derivation like
```nix
buildNixShellImage {
drv = someDrv.overrideAttrs (old: {
nativeBuildInputs = old.nativeBuildInputs or [] ++ [
somethingExtra
];
});
# ...
}
```
Similarly, you can extend the image initialization script by extending `shellHook`
`name` _optional_
: The name of the resulting image.
*Default:* `drv.name + "-env"`
`tag` _optional_
: Tag of the generated image.
*Default:* the resulting image derivation output path's hash
`uid`/`gid` _optional_
: The user/group ID to run the container as. This is like a `nixbld` build user.
*Default:* 1000/1000
`homeDirectory` _optional_
: The home directory of the user the container is running as
*Default:* `/build`
`shell` _optional_
: The path to the `bash` binary to use as the shell. This shell is started when running the image.
*Default:* `pkgs.bashInteractive + "/bin/bash"`
`command` _optional_
: Run this command in the environment of the derivation, in an interactive shell. See the `--command` option in the [`nix-shell` documentation](https://nixos.org/manual/nix/stable/command-ref/nix-shell.html?highlight=nix-shell#options).
*Default:* (none)
`run` _optional_
: Same as `command`, but runs the command in a non-interactive shell instead. See the `--run` option in the [`nix-shell` documentation](https://nixos.org/manual/nix/stable/command-ref/nix-shell.html?highlight=nix-shell#options).
*Default:* (none)
### Example {#ssec-pkgs-dockerTools-buildNixShellImage-example}
The following shows how to build the `pkgs.hello` package inside a Docker container built with `buildNixShellImage`.
```nix
with import <nixpkgs> {};
dockerTools.buildNixShellImage {
drv = hello;
}
```
Build the derivation:
```console
nix-build hello.nix
```
these 8 derivations will be built:
/nix/store/xmw3a5ln29rdalavcxk1w3m4zb2n7kk6-nix-shell-rc.drv
...
Creating layer 56 from paths: ['/nix/store/crpnj8ssz0va2q0p5ibv9i6k6n52gcya-stdenv-linux']
Creating layer 57 with customisation...
Adding manifests...
Done.
/nix/store/cpyn1lc897ghx0rhr2xy49jvyn52bazv-hello-2.12-env.tar.gz
Load the image:
```console
docker load -i result
```
0d9f4c4cd109: Loading layer [==================================================>] 2.56MB/2.56MB
...
ab1d897c0697: Loading layer [==================================================>] 10.24kB/10.24kB
Loaded image: hello-2.12-env:pgj9h98nal555415faa43vsydg161bdz
Run the container:
```console
docker run -it hello-2.12-env:pgj9h98nal555415faa43vsydg161bdz
```
[nix-shell:/build]$
In the running container, run the build:
```console
buildDerivation
```
unpacking sources
unpacking source archive /nix/store/8nqv6kshb3vs5q5bs2k600xpj5bkavkc-hello-2.12.tar.gz
...
patching script interpreter paths in /nix/store/z5wwy5nagzy15gag42vv61c2agdpz2f2-hello-2.12
checking for references to /build/ in /nix/store/z5wwy5nagzy15gag42vv61c2agdpz2f2-hello-2.12...
Check the build result:
```console
$out/bin/hello
```
Hello, world!

View File

@@ -1,108 +0,0 @@
# `<nixpkgs/nixos/lib/make-disk-image.nix>` {#sec-make-disk-image}
`<nixpkgs/nixos/lib/make-disk-image.nix>` is a function to create _disk images_ in multiple formats: raw, QCOW2 (QEMU), QCOW2-Compressed (compressed version), VDI (VirtualBox), VPC (VirtualPC).
This function can create images in two ways:
- using `cptofs` without any virtual machine to create a Nix store disk image,
- using a virtual machine to create a full NixOS installation.
When testing early-boot or lifecycle parts of NixOS such as a bootloader or multiple generations, it is necessary to opt for a full NixOS system installation.
Whereas for many web servers, applications, it is possible to work with a Nix store only disk image and is faster to build.
NixOS tests also use this function when preparing the VM. The `cptofs` method is used when `virtualisation.useBootLoader` is false (the default). Otherwise the second method is used.
## Features {#sec-make-disk-image-features}
For reference, read the function signature source code for documentation on arguments: <https://github.com/NixOS/nixpkgs/blob/master/nixos/lib/make-disk-image.nix>.
Features are separated in various sections depending on if you opt for a Nix-store only image or a full NixOS image.
### Common {#sec-make-disk-image-features-common}
- arbitrary NixOS configuration
- automatic or bound disk size: `diskSize` parameter, `additionalSpace` can be set when `diskSize` is `auto` to add a constant of disk space
- multiple partition table layouts: EFI, legacy, legacy + GPT, hybrid, none through `partitionTableType` parameter
- OVMF or EFI firmwares and variables templates can be customized
- root filesystem `fsType` can be customized to whatever `mkfs.${fsType}` exist during operations
- root filesystem label can be customized, defaults to `nix-store` if it's a Nix store image, otherwise `nixpkgs/nixos`
- arbitrary code can be executed after disk image was produced with `postVM`
- the current nixpkgs can be realized as a channel in the disk image, which will change the hash of the image when the sources are updated
- additional store paths can be provided through `additionalPaths`
### Full NixOS image {#sec-make-disk-image-features-full-image}
- arbitrary contents with permissions can be placed in the target filesystem using `contents`
- a `/etc/nixpkgs/nixos/configuration.nix` can be provided through `configFile`
- bootloaders are supported
- EFI variables can be mutated during image production and the result is exposed in `$out`
- boot partition size when partition table is `efi` or `hybrid`
### On bit-to-bit reproducibility {#sec-make-disk-image-features-reproducibility}
Images are **NOT** deterministic, please do not hesitate to try to fix this, source of determinisms are (not exhaustive) :
- bootloader installation have timestamps
- SQLite Nix store database contain registration times
- `/etc/shadow` is in a non-deterministic order
A `deterministic` flag is available for best efforts determinism.
## Usage {#sec-make-disk-image-usage}
To produce a Nix-store only image:
```nix
let
pkgs = import <nixpkgs> {};
lib = pkgs.lib;
make-disk-image = import <nixpkgs/nixos/lib/make-disk-image.nix>;
in
make-disk-image {
inherit pkgs lib;
config = {};
additionalPaths = [ ];
format = "qcow2";
onlyNixStore = true;
partitionTableType = "none";
installBootLoader = false;
touchEFIVars = false;
diskSize = "auto";
additionalSpace = "0M"; # Defaults to 512M.
copyChannel = false;
}
```
Some arguments can be left out, they are shown explicitly for the sake of the example.
Building this derivation will provide a QCOW2 disk image containing only the Nix store and its registration information.
To produce a NixOS installation image disk with UEFI and bootloader installed:
```nix
let
pkgs = import <nixpkgs> {};
lib = pkgs.lib;
make-disk-image = import <nixpkgs/nixos/lib/make-disk-image.nix>;
evalConfig = import <nixpkgs/nixos/lib/eval-config.nix>;
in
make-disk-image {
inherit pkgs lib;
config = evalConfig {
modules = [
{
fileSystems."/" = { device = "/dev/vda"; fsType = "ext4"; autoFormat = true; };
boot.grub.device = "/dev/vda";
}
];
};
format = "qcow2";
onlyNixStore = false;
partitionTableType = "legacy+gpt";
installBootLoader = true;
touchEFIVars = true;
diskSize = "auto";
additionalSpace = "0M"; # Defaults to 512M.
copyChannel = false;
memSize = 2048; # Qemu VM memory size in megabytes. Defaults to 1024M.
}
```

View File

@@ -1,10 +1,10 @@
# pkgs.ociTools {#sec-pkgs-ociTools}
`pkgs.ociTools` is a set of functions for creating containers according to the [OCI container specification v1.0.0](https://github.com/opencontainers/runtime-spec). Beyond that, it makes no assumptions about the container runner you choose to use to run the created container.
`pkgs.ociTools` is a set of functions for creating containers according to the [OCI container specification v1.0.0](https://github.com/opencontainers/runtime-spec). Beyond that it makes no assumptions about the container runner you choose to use to run the created container.
## buildContainer {#ssec-pkgs-ociTools-buildContainer}
This function creates a simple OCI container that runs a single command inside of it. An OCI container consists of a `config.json` and a rootfs directory. The nix store of the container will contain all referenced dependencies of the given command.
This function creates a simple OCI container that runs a single command inside of it. An OCI container consists of a `config.json` and a rootfs directory.The nix store of the container will contain all referenced dependencies of the given command.
The parameters of `buildContainer` with an example value are described below:
@@ -30,8 +30,8 @@ buildContainer {
}
```
- `args` specifies a set of arguments to run inside the container. This is the only required argument for `buildContainer`. All referenced packages inside the derivation will be made available inside the container.
- `args` specifies a set of arguments to run inside the container. This is the only required argument for `buildContainer`. All referenced packages inside the derivation will be made available inside the container
- `mounts` specifies additional mount points chosen by the user. By default only a minimal set of necessary filesystems are mounted into the container (e.g procfs, cgroupfs)
- `readonly` makes the container's rootfs read-only if it is set to true. The default value is false `false`.
- `readonly` makes the container\'s rootfs read-only if it is set to true. The default value is false `false`.

View File

@@ -1,81 +0,0 @@
# pkgs.portableService {#sec-pkgs-portableService}
`pkgs.portableService` is a function to create _portable service images_,
as read-only, immutable, `squashfs` archives.
systemd supports a concept of [Portable Services](https://systemd.io/PORTABLE_SERVICES/).
Portable Services are a delivery method for system services that uses two specific features of container management:
* Applications are bundled. I.e. multiple services, their binaries and
all their dependencies are packaged in an image, and are run directly from it.
* Stricter default security policies, i.e. sandboxing of applications.
This allows using Nix to build images which can be run on many recent Linux distributions.
The primary tool for interacting with Portable Services is `portablectl`,
and they are managed by the `systemd-portabled` system service.
::: {.note}
Portable services are supported starting with systemd 239 (released on 2018-06-22).
:::
A very simple example of using `portableService` is described below:
[]{#ex-pkgs-portableService}
```nix
pkgs.portableService {
pname = "demo";
version = "1.0";
units = [ demo-service demo-socket ];
}
```
The above example will build an squashfs archive image in `result/$pname_$version.raw`. The image will contain the
file system structure as required by the portable service specification, and a subset of the Nix store with all the
dependencies of the two derivations in the `units` list.
`units` must be a list of derivations, and their names must be prefixed with the service name (`"demo"` in this case).
Otherwise `systemd-portabled` will ignore them.
::: {.note}
The `.raw` file extension of the image is required by the portable services specification.
:::
Some other options available are:
- `description`, `homepage`
Are added to the `/etc/os-release` in the image and are shown by the portable services tooling.
Default to empty values, not added to os-release.
- `symlinks`
A list of attribute sets {object, symlink}. Symlinks will be created in the root filesystem of the image to
objects in the Nix store. Defaults to an empty list.
- `contents`
A list of additional derivations to be included in the image Nix store, as-is. Defaults to an empty list.
- `squashfsTools`
Defaults to `pkgs.squashfsTools`, allows you to override the package that provides `mksquashfs`.
- `squash-compression`, `squash-block-size`
Options to `mksquashfs`. Default to `"xz -Xdict-size 100%"` and `"1M"` respectively.
A typical usage of `symlinks` would be:
```nix
symlinks = [
{ object = "${pkgs.cacert}/etc/ssl"; symlink = "/etc/ssl"; }
{ object = "${pkgs.bash}/bin/bash"; symlink = "/bin/sh"; }
{ object = "${pkgs.php}/bin/php"; symlink = "/usr/bin/php"; }
];
```
to create these symlinks for legacy applications that assume them existing globally.
Once the image is created, and deployed on a host in `/var/lib/portables/`, you can attach the image and run the service. As root run:
```console
portablectl attach demo_1.0.raw
systemctl enable --now demo.socket
systemctl enable --now demo.service
```
::: {.note}
See the [man page](https://www.freedesktop.org/software/systemd/man/portablectl.html) of `portablectl` for more info on its usage.
:::

View File

@@ -14,7 +14,7 @@ Currently, `makeSnap` does not support creating GUI stubs.
The following expression packages GNU Hello as a Snapcraft snap.
``` {#ex-snapTools-buildSnap-hello .nix}
```{#ex-snapTools-buildSnap-hello .nix}
let
inherit (import <nixpkgs> { }) snapTools hello;
in snapTools.makeSnap {
@@ -33,9 +33,9 @@ in snapTools.makeSnap {
## Build a Graphical Snap {#ssec-pkgs-snapTools-build-a-snap-firefox}
Graphical programs require many more integrations with the host. This example uses Firefox as an example because it is one of the most complicated programs we could package.
Graphical programs require many more integrations with the host. This example uses Firefox as an example, because it is one of the most complicated programs we could package.
``` {#ex-snapTools-buildSnap-firefox .nix}
```{#ex-snapTools-buildSnap-firefox .nix}
let
inherit (import <nixpkgs> { }) snapTools firefox;
in snapTools.makeSnap {

View File

@@ -1,6 +1,6 @@
# Cataclysm: Dark Days Ahead {#cataclysm-dark-days-ahead}
## How to install Cataclysm DDA {#how-to-install-cataclysm-dda}
## How to install Cataclysm DDA
To install the latest stable release of Cataclysm DDA to your profile, execute
`nix-env -f "<nixpkgs>" -iA cataclysm-dda`. For the curses build (build
@@ -34,7 +34,7 @@ cataclysm-dda.override {
}
```
## Important note for overriding packages {#important-note-for-overriding-packages}
## Important note for overriding packages
After applying `overrideAttrs`, you need to fix `passthru.pkgs` and
`passthru.withMods` attributes either manually or by using `attachPkgs`:
@@ -69,7 +69,7 @@ in
goodExample2.withMods (_: []) # parallel building enabled
```
## Customizing with mods {#customizing-with-mods}
## Customizing with mods
To install Cataclysm DDA with mods of your choice, you can use `withMods`
attribute:
@@ -103,7 +103,7 @@ let
owner = "Someone";
repo = "AwesomeMod";
rev = "...";
hash = "...";
sha256 = "...";
};
# Path to be installed in the unpacked source (default: ".")
modRoot = "contents/under/this/path/will/be/installed";

View File

@@ -4,13 +4,13 @@ The [Citrix Workspace App](https://www.citrix.com/products/workspace-app/) is a
## Basic usage {#sec-citrix-base}
The tarball archive needs to be downloaded manually, as the license agreements of the vendor for [Citrix Workspace](https://www.citrix.com/downloads/workspace-app/linux/workspace-app-for-linux-latest.html) needs to be accepted first. Then run `nix-prefetch-url file://$PWD/linuxx64-$version.tar.gz`. With the archive available in the store, the package can be built and installed with Nix.
The tarball archive needs to be downloaded manually as the license agreements of the vendor for [Citrix Workspace](https://www.citrix.de/downloads/workspace-app/linux/workspace-app-for-linux-latest.html) needs to be accepted first. Then run `nix-prefetch-url file://$PWD/linuxx64-$version.tar.gz`. With the archive available in the store the package can be built and installed with Nix.
## Citrix Self-service {#sec-citrix-selfservice}
## Citrix Selfservice {#sec-citrix-selfservice}
The [self-service](https://support.citrix.com/article/CTX200337) is an application managing Citrix desktops and applications. Please note that this feature only works with at least citrix_workspace_20_06_0 and later versions.
The [selfservice](https://support.citrix.com/article/CTX200337) is an application managing Citrix desktops and applications. Please note that this feature only works with at least citrix_workspace_20_06_0 and later versions.
In order to set this up, you first have to [download the `.cr` file from the Netscaler Gateway](https://its.uiowa.edu/support/article/102186). After that, you can configure the `selfservice` like this:
In order to set this up, you first have to [download the `.cr` file from the Netscaler Gateway](https://its.uiowa.edu/support/article/102186). After that you can configure the `selfservice` like this:
```ShellSession
$ storebrowse -C ~/Downloads/receiverconfig.cr
@@ -19,7 +19,7 @@ $ selfservice
## Custom certificates {#sec-citrix-custom-certs}
The `Citrix Workspace App` in `nixpkgs` trusts several certificates [from the Mozilla database](https://curl.haxx.se/docs/caextract.html) by default. However, several companies using Citrix might require their own corporate certificate. On distros with imperative packaging, these certs can be stored easily in [`$ICAROOT`](https://citrix.github.io/receiver-for-linux-command-reference/), however this directory is a store path in `nixpkgs`. In order to work around this issue, the package provides a simple mechanism to add custom certificates without rebuilding the entire package using `symlinkJoin`:
The `Citrix Workspace App` in `nixpkgs` trusts several certificates [from the Mozilla database](https://curl.haxx.se/docs/caextract.html) by default. However several companies using Citrix might require their own corporate certificate. On distros with imperative packaging these certs can be stored easily in [`$ICAROOT`](https://developer-docs.citrix.com/projects/receiver-for-linux-command-reference/en/13.7/), however this directory is a store path in `nixpkgs`. In order to work around this issue the package provides a simple mechanism to add custom certificates without rebuilding the entire package using `symlinkJoin`:
```nix
with import <nixpkgs> { config.allowUnfree = true; };

View File

@@ -4,7 +4,7 @@
## Compiling without AVX support {#compiling-without-avx-support}
Especially older CPUs don't support [AVX](https://en.wikipedia.org/wiki/Advanced_Vector_Extensions) (Advanced Vector Extensions) instructions that are used by DLib to optimize their algorithms.
Especially older CPUs don\'t support [AVX](https://en.wikipedia.org/wiki/Advanced_Vector_Extensions) (Advanced Vector Extensions) instructions that are used by DLib to optimize their algorithms.
On the affected hardware errors like `Illegal instruction` will occur. In those cases AVX support needs to be disabled:

View File

@@ -8,9 +8,9 @@ Nixpkgs provides a number of packages that will install Eclipse in its various f
$ nix-env -f '<nixpkgs>' -qaP -A eclipses --description
```
Once an Eclipse variant is installed, it can be run using the `eclipse` command, as expected. From within Eclipse, it is then possible to install plugins in the usual manner by either manually specifying an Eclipse update site or by installing the Marketplace Client plugin and using it to discover and install other plugins. This installation method provides an Eclipse installation that closely resemble a manually installed Eclipse.
Once an Eclipse variant is installed it can be run using the `eclipse` command, as expected. From within Eclipse it is then possible to install plugins in the usual manner by either manually specifying an Eclipse update site or by installing the Marketplace Client plugin and using it to discover and install other plugins. This installation method provides an Eclipse installation that closely resemble a manually installed Eclipse.
If you prefer to install plugins in a more declarative manner, then Nixpkgs also offer a number of Eclipse plugins that can be installed in an _Eclipse environment_. This type of environment is created using the function `eclipseWithPlugins` found inside the `nixpkgs.eclipses` attribute set. This function takes as argument `{ eclipse, plugins ? [], jvmArgs ? [] }` where `eclipse` is a one of the Eclipse packages described above, `plugins` is a list of plugin derivations, and `jvmArgs` is a list of arguments given to the JVM running the Eclipse. For example, say you wish to install the latest Eclipse Platform with the popular Eclipse Color Theme plugin and also allow Eclipse to use more RAM. You could then add:
If you prefer to install plugins in a more declarative manner then Nixpkgs also offer a number of Eclipse plugins that can be installed in an _Eclipse environment_. This type of environment is created using the function `eclipseWithPlugins` found inside the `nixpkgs.eclipses` attribute set. This function takes as argument `{ eclipse, plugins ? [], jvmArgs ? [] }` where `eclipse` is a one of the Eclipse packages described above, `plugins` is a list of plugin derivations, and `jvmArgs` is a list of arguments given to the JVM running the Eclipse. For example, say you wish to install the latest Eclipse Platform with the popular Eclipse Color Theme plugin and also allow Eclipse to use more RAM. You could then add
```nix
packageOverrides = pkgs: {
@@ -22,15 +22,15 @@ packageOverrides = pkgs: {
}
```
to your Nixpkgs configuration (`~/.config/nixpkgs/config.nix`) and install it by running `nix-env -f '<nixpkgs>' -iA myEclipse` and afterward run Eclipse as usual. It is possible to find out which plugins are available for installation using `eclipseWithPlugins` by running:
to your Nixpkgs configuration (`~/.config/nixpkgs/config.nix`) and install it by running `nix-env -f '<nixpkgs>' -iA myEclipse` and afterward run Eclipse as usual. It is possible to find out which plugins are available for installation using `eclipseWithPlugins` by running
```ShellSession
$ nix-env -f '<nixpkgs>' -qaP -A eclipses.plugins --description
```
If there is a need to install plugins that are not available in Nixpkgs then it may be possible to define these plugins outside Nixpkgs using the `buildEclipseUpdateSite` and `buildEclipsePlugin` functions found in the `nixpkgs.eclipses.plugins` attribute set. Use the `buildEclipseUpdateSite` function to install a plugin distributed as an Eclipse update site. This function takes `{ name, src }` as argument, where `src` indicates the Eclipse update site archive. All Eclipse features and plugins within the downloaded update site will be installed. When an update site archive is not available, then the `buildEclipsePlugin` function can be used to install a plugin that consists of a pair of feature and plugin JARs. This function takes an argument `{ name, srcFeature, srcPlugin }` where `srcFeature` and `srcPlugin` are the feature and plugin JARs, respectively.
If there is a need to install plugins that are not available in Nixpkgs then it may be possible to define these plugins outside Nixpkgs using the `buildEclipseUpdateSite` and `buildEclipsePlugin` functions found in the `nixpkgs.eclipses.plugins` attribute set. Use the `buildEclipseUpdateSite` function to install a plugin distributed as an Eclipse update site. This function takes `{ name, src }` as argument where `src` indicates the Eclipse update site archive. All Eclipse features and plugins within the downloaded update site will be installed. When an update site archive is not available then the `buildEclipsePlugin` function can be used to install a plugin that consists of a pair of feature and plugin JARs. This function takes an argument `{ name, srcFeature, srcPlugin }` where `srcFeature` and `srcPlugin` are the feature and plugin JARs, respectively.
Expanding the previous example with two plugins using the above functions, we have:
Expanding the previous example with two plugins using the above functions we have
```nix
packageOverrides = pkgs: {
@@ -43,11 +43,11 @@ packageOverrides = pkgs: {
name = "myplugin1-1.0";
srcFeature = fetchurl {
url = "http:///features/myplugin1.jar";
hash = "sha256-123";
sha256 = "123";
};
srcPlugin = fetchurl {
url = "http:///plugins/myplugin1.jar";
hash = "sha256-123";
sha256 = "123";
};
});
(plugins.buildEclipseUpdateSite {
@@ -55,7 +55,7 @@ packageOverrides = pkgs: {
src = fetchurl {
stripRoot = false;
url = "http:///myplugin2.zip";
hash = "sha256-123";
sha256 = "123";
};
});
];

View File

@@ -1,11 +1,11 @@
# Elm {#sec-elm}
To start a development environment, run:
To start a development environment do
```ShellSession
nix-shell -p elmPackages.elm elmPackages.elm-format
```
To update the Elm compiler, see `nixpkgs/pkgs/development/compilers/elm/README.md`.
To update the Elm compiler, see <filename>nixpkgs/pkgs/development/compilers/elm/README.md</filename>.
To package Elm applications, [read about elm2nix](https://github.com/hercules-ci/elm2nix#elm2nix).

View File

@@ -20,7 +20,7 @@ The Emacs package comes with some extra helpers to make it easier to configure.
}
```
You can install it like any other packages via `nix-env -iA myEmacs`. However, this will only install those packages. It will not `configure` them for us. To do this, we need to provide a configuration file. Luckily, it is possible to do this from within Nix! By modifying the above example, we can make Emacs load a custom config file. The key is to create a package that provides a `default.el` file in `/share/emacs/site-start/`. Emacs knows to load this file automatically when it starts.
You can install it like any other packages via `nix-env -iA myEmacs`. However, this will only install those packages. It will not `configure` them for us. To do this, we need to provide a configuration file. Luckily, it is possible to do this from within Nix! By modifying the above example, we can make Emacs load a custom config file. The key is to create a package that provide a `default.el` file in `/share/emacs/site-start/`. Emacs knows to load this file automatically when it starts.
```nix
{
@@ -101,16 +101,16 @@ You can install it like any other packages via `nix-env -iA myEmacs`. However, t
}
```
This provides a fairly full Emacs start file. It will load in addition to the user's personal config. You can always disable it by passing `-q` to the Emacs command.
This provides a fairly full Emacs start file. It will load in addition to the user's presonal config. You can always disable it by passing `-q` to the Emacs command.
Sometimes `emacs.pkgs.withPackages` is not enough, as this package set has some priorities imposed on packages (with the lowest priority assigned to Melpa Unstable, and the highest for packages manually defined in `pkgs/top-level/emacs-packages.nix`). But you can't control these priorities when some package is installed as a dependency. You can override it on a per-package-basis, providing all the required dependencies manually, but it's tedious and there is always a possibility that an unwanted dependency will sneak in through some other package. To completely override such a package, you can use `overrideScope'`.
Sometimes `emacs.pkgs.withPackages` is not enough, as this package set has some priorities imposed on packages (with the lowest priority assigned to Melpa Unstable, and the highest for packages manually defined in `pkgs/top-level/emacs-packages.nix`). But you can't control this priorities when some package is installed as a dependency. You can override it on per-package-basis, providing all the required dependencies manually - but it's tedious and there is always a possibility that an unwanted dependency will sneak in through some other package. To completely override such a package you can use `overrideScope'`.
```nix
overrides = self: super: rec {
haskell-mode = self.melpaPackages.haskell-mode;
...
};
((emacsPackagesFor emacs).overrideScope' overrides).withPackages
((emacsPackagesFor emacs).overrideScope' overrides).emacs.pkgs.withPackages
(p: with p; [
# here both these package will use haskell-mode of our own choice
ghc-mod

View File

@@ -1,18 +0,0 @@
# /etc files {#etc}
Certain calls in glibc require access to runtime files found in `/etc` such as `/etc/protocols` or `/etc/services` -- [getprotobyname](https://linux.die.net/man/3/getprotobyname) is one such function.
On non-NixOS distributions these files are typically provided by packages (i.e., [netbase](https://packages.debian.org/sid/netbase)) if not already pre-installed in your distribution. This can cause non-reproducibility for code if they rely on these files being present.
If [iana-etc](https://hydra.nixos.org/job/nixos/trunk-combined/nixpkgs.iana-etc.x86_64-linux) is part of your `buildInputs`, then it will set the environment variables `NIX_ETC_PROTOCOLS` and `NIX_ETC_SERVICES` to the corresponding files in the package through a setup hook.
```bash
> nix-shell -p iana-etc
[nix-shell:~]$ env | grep NIX_ETC
NIX_ETC_SERVICES=/nix/store/aj866hr8fad8flnggwdhrldm0g799ccz-iana-etc-20210225/etc/services
NIX_ETC_PROTOCOLS=/nix/store/aj866hr8fad8flnggwdhrldm0g799ccz-iana-etc-20210225/etc/protocols
```
Nixpkg's version of [glibc](https://github.com/NixOS/nixpkgs/blob/master/pkgs/development/libraries/glibc/default.nix) has been patched to check for the existence of these environment variables. If the environment variables are *not* set, then it will attempt to find the files at the default location within `/etc`.

View File

@@ -1,18 +1,17 @@
# Firefox {#sec-firefox}
## Build wrapped Firefox with extensions and policies {#build-wrapped-firefox-with-extensions-and-policies}
## Build wrapped Firefox with extensions and policies
The `wrapFirefox` function allows to pass policies, preferences and extensions that are available to Firefox. With the help of `fetchFirefoxAddon` this allows to build a Firefox version that already comes with add-ons pre-installed:
The `wrapFirefox` function allows to pass policies, preferences and extension that are available to firefox. With the help of `fetchFirefoxAddon` this allows build a firefox version that already comes with addons pre-installed:
```nix
{
# Nix firefox addons only work with the firefox-esr package.
myFirefox = wrapFirefox firefox-esr-unwrapped {
myFirefox = wrapFirefox firefox-unwrapped {
nixExtensions = [
(fetchFirefoxAddon {
name = "ublock"; # Has to be unique!
url = "https://addons.mozilla.org/firefox/downloads/file/3679754/ublock_origin-1.31.0-an+fx.xpi";
hash = "sha256-2e73AbmYZlZXCP5ptYVcFjQYdjDp4iPoEPEOSCVF5sA=";
sha256 = "1h768ljlh3pi23l27qp961v1hd0nbj2vasgy11bmcrlqp40zgvnr";
})
];
@@ -26,14 +25,10 @@ The `wrapFirefox` function allows to pass policies, preferences and extensions t
Pocket = false;
Snippets = false;
};
UserMessaging = {
ExtensionRecommendations = false;
SkipOnboarding = true;
};
SecurityDevices = {
# Use a proxy module rather than `nixpkgs.config.firefox.smartcardSupport = true`
"PKCS#11 Proxy Module" = "${pkgs.p11-kit}/lib/p11-kit-proxy.so";
};
UserMessaging = {
ExtensionRecommendations = false;
SkipOnboarding = true;
};
};
extraPrefs = ''
@@ -44,12 +39,11 @@ The `wrapFirefox` function allows to pass policies, preferences and extensions t
}
```
If `nixExtensions != null`, then all manually installed add-ons will be uninstalled from your browser profile.
To view available enterprise policies, visit [enterprise policies](https://github.com/mozilla/policy-templates#enterprisepoliciesenabled)
or type into the Firefox URL bar: `about:policies#documentation`.
Nix installed add-ons do not have a valid signature, which is why signature verification is disabled. This does not compromise security because downloaded add-ons are checksummed and manual add-ons can't be installed. Also, make sure that the `name` field of `fetchFirefoxAddon` is unique. If you remove an add-on from the `nixExtensions` array, rebuild and start Firefox: the removed add-on will be completely removed with all of its settings.
If `nixExtensions != null` then all manually installed addons will be uninstalled from your browser profile.
To view available enterprise policies visit [enterprise policies](https://github.com/mozilla/policy-templates#enterprisepoliciesenabled)
or type into the Firefox url bar: `about:policies#documentation`.
Nix installed addons do not have a valid signature, which is why signature verification is disabled. This does not compromise security because downloaded addons are checksumed and manual addons can't be installed. Also make sure that the `name` field of fetchFirefoxAddon is unique. If you remove an addon from the nixExtensions array, rebuild and start Firefox the removed addon will be completly removed with all of its settings.
## Troubleshooting {#sec-firefox-troubleshooting}
If add-ons are marked as broken or the signature is invalid, make sure you have Firefox ESR installed. Normal Firefox does not provide the ability anymore to disable signature verification for add-ons thus nix add-ons get disabled by the normal Firefox binary.
If addons do not appear installed although they have been defined in your nix configuration file reset the local addon state of your Firefox profile by clicking `help -> restart with addons disabled -> restart -> refresh firefox`. This can happen if you switch from manual addon mode to nix addon mode and then back to manual mode and then again to nix addon mode.
If add-ons do not appear installed despite being defined in your nix configuration file, reset the local add-on state of your Firefox profile by clicking `Help -> More Troubleshooting Information -> Refresh Firefox`. This can happen if you switch from manual add-on mode to nix add-on mode and then back to manual mode and then again to nix add-on mode.

View File

@@ -36,7 +36,7 @@ using `buildFishPlugin` and running unit tests with the `fishtape` test runner.
## Fish wrapper {#sec-fish-wrapper}
The `wrapFish` package is a wrapper around Fish which can be used to create
Fish shells initialized with some plugins as well as completions, configuration
Fish shells initialised with some plugins as well as completions, configuration
snippets and functions sourced from the given paths. This provides a convenient
way to test Fish plugins and scripts without having to alter the environment.

View File

@@ -24,10 +24,10 @@ packages on macOS:
checking for fuse.h... no
configure: error: No fuse.h found.
This happens on autoconf based projects that use `AC_CHECK_HEADERS` or
This happens on autoconf based projects that uses `AC_CHECK_HEADERS` or
`AC_CHECK_LIBS` to detect libfuse, and will occur even when the `fuse` package
is included in `buildInputs`. It happens because libfuse headers throw an error
on macOS if the `FUSE_USE_VERSION` macro is undefined. Many projects do define
on macOS if the `FUSE_USE_VERSION` macro is undefined. Many proejcts do define
`FUSE_USE_VERSION`, but only inside C source files. This results in the above
error at configure time because the configure script would attempt to compile
sample FUSE programs without defining `FUSE_USE_VERSION`.

View File

@@ -4,9 +4,9 @@ This package is an ibus-based completion method to speed up typing.
## Activating the engine {#sec-ibus-typing-booster-activate}
IBus needs to be configured accordingly to activate `typing-booster`. The configuration depends on the desktop manager in use. For detailed instructions, please refer to the [upstream docs](https://mike-fabian.github.io/ibus-typing-booster/).
IBus needs to be configured accordingly to activate `typing-booster`. The configuration depends on the desktop manager in use. For detailed instructions, please refer to the [upstream docs](https://mike-fabian.github.io/ibus-typing-booster/documentation.html).
On NixOS, you need to explicitly enable `ibus` with given engines before customizing your desktop to use `typing-booster`. This can be achieved using the `ibus` module:
On NixOS you need to explicitly enable `ibus` with given engines before customizing your desktop to use `typing-booster`. This can be achieved using the `ibus` module:
```nix
{ pkgs, ... }: {
@@ -19,7 +19,7 @@ On NixOS, you need to explicitly enable `ibus` with given engines before customi
## Using custom hunspell dictionaries {#sec-ibus-typing-booster-customize-hunspell}
The IBus engine is based on `hunspell` to support completion in many languages. By default, the dictionaries `de-de`, `en-us`, `fr-moderne` `es-es`, `it-it`, `sv-se` and `sv-fi` are in use. To add another dictionary, the package can be overridden like this:
The IBus engine is based on `hunspell` to support completion in many languages. By default the dictionaries `de-de`, `en-us`, `fr-moderne` `es-es`, `it-it`, `sv-se` and `sv-fi` are in use. To add another dictionary, the package can be overridden like this:
```nix
ibus-engines.typing-booster.override { langs = [ "de-at" "en-gb" ]; }
@@ -31,7 +31,7 @@ _Note: each language passed to `langs` must be an attribute name in `pkgs.hunspe
The `ibus-engines.typing-booster` package contains a program named `emoji-picker`. To display all emojis correctly, a special font such as `noto-fonts-emoji` is needed:
On NixOS, it can be installed using the following expression:
On NixOS it can be installed using the following expression:
```nix
{ pkgs, ... }: { fonts.fonts = with pkgs; [ noto-fonts-emoji ]; }

View File

@@ -17,7 +17,6 @@
<xi:include href="kakoune.section.xml" />
<xi:include href="linux.section.xml" />
<xi:include href="locales.section.xml" />
<xi:include href="etc-files.section.xml" />
<xi:include href="nginx.section.xml" />
<xi:include href="opengl.section.xml" />
<xi:include href="shell-helpers.section.xml" />

View File

@@ -4,7 +4,7 @@ The Nix expressions to build the Linux kernel are in [`pkgs/os-specific/linux/ke
The function that builds the kernel has an argument `kernelPatches` which should be a list of `{name, patch, extraConfig}` attribute sets, where `name` is the name of the patch (which is included in the kernels `meta.description` attribute), `patch` is the patch itself (possibly compressed), and `extraConfig` (optional) is a string specifying extra options to be concatenated to the kernel configuration file (`.config`).
The kernel derivation exports an attribute `features` specifying whether optional functionality is or isnt enabled. This is used in NixOS to implement kernel-specific behaviour. For instance, if the kernel has the `iwlwifi` feature (i.e., has built-in support for Intel wireless chipsets), then NixOS doesnt have to build the external `iwlwifi` package:
The kernel derivation exports an attribute `features` specifying whether optional functionality is or isnt enabled. This is used in NixOS to implement kernel-specific behaviour. For instance, if the kernel has the `iwlwifi` feature (i.e. has built-in support for Intel wireless chipsets), then NixOS doesnt have to build the external `iwlwifi` package:
```nix
modulesTree = [kernel]
@@ -14,28 +14,28 @@ modulesTree = [kernel]
How to add a new (major) version of the Linux kernel to Nixpkgs:
1. Copy the old Nix expression (e.g., `linux-2.6.21.nix`) to the new one (e.g., `linux-2.6.22.nix`) and update it.
1. Copy the old Nix expression (e.g. `linux-2.6.21.nix`) to the new one (e.g. `linux-2.6.22.nix`) and update it.
2. Add the new kernel to the `kernels` attribute set in `linux-kernels.nix` (e.g., create an attribute `kernel_2_6_22`).
2. Add the new kernel to `all-packages.nix` (e.g., create an attribute `kernel_2_6_22`).
3. Now were going to update the kernel configuration. First unpack the kernel. Then for each supported platform (`i686`, `x86_64`, `uml`) do the following:
1. Make a copy from the old config (e.g., `config-2.6.21-i686-smp`) to the new one (e.g., `config-2.6.22-i686-smp`).
1. Make an copy from the old config (e.g. `config-2.6.21-i686-smp`) to the new one (e.g. `config-2.6.22-i686-smp`).
2. Copy the config file for this platform (e.g., `config-2.6.22-i686-smp`) to `.config` in the kernel source tree.
2. Copy the config file for this platform (e.g. `config-2.6.22-i686-smp`) to `.config` in the kernel source tree.
3. Run `make oldconfig ARCH={i386,x86_64,um}` and answer all questions. (For the uml configuration, also add `SHELL=bash`.) Make sure to keep the configuration consistent between platforms (i.e., dont enable some feature on `i686` and disable it on `x86_64`).
3. Run `make oldconfig ARCH={i386,x86_64,um}` and answer all questions. (For the uml configuration, also add `SHELL=bash`.) Make sure to keep the configuration consistent between platforms (i.e. dont enable some feature on `i686` and disable it on `x86_64`).
4. If needed, you can also run `make menuconfig`:
4. If needed you can also run `make menuconfig`:
```ShellSession
$ nix-env -f "<nixpkgs>" -iA ncurses
$ nix-env -i ncurses
$ export NIX_CFLAGS_LINK=-lncurses
$ make menuconfig ARCH=arch
```
5. Copy `.config` over the new config file (e.g., `config-2.6.22-i686-smp`).
5. Copy `.config` over the new config file (e.g. `config-2.6.22-i686-smp`).
4. Test building the kernel: `nix-build -A linuxKernel.kernels.kernel_2_6_22`. If it compiles, ship it! For extra credit, try booting NixOS with it.
4. Test building the kernel: `nix-build -A kernel_2_6_22`. If it compiles, ship it! For extra credit, try booting NixOS with it.
5. It may be that the new kernel requires updating the external kernel modules and kernel-dependent packages listed in the `linuxPackagesFor` function in `linux-kernels.nix` (such as the NVIDIA drivers, AUFS, etc.). If the updated packages arent backwards compatible with older kernels, you may need to keep the older versions around.
5. It may be that the new kernel requires updating the external kernel modules and kernel-dependent packages listed in the `linuxPackagesFor` function in `all-packages.nix` (such as the NVIDIA drivers, AUFS, etc.). If the updated packages arent backwards compatible with older kernels, you may need to keep the older versions around.

View File

@@ -1,5 +1,5 @@
# Locales {#locales}
To allow simultaneous use of packages linked against different versions of `glibc` with different locale archive formats, Nixpkgs patches `glibc` to rely on `LOCALE_ARCHIVE` environment variable.
To allow simultaneous use of packages linked against different versions of `glibc` with different locale archive formats Nixpkgs patches `glibc` to rely on `LOCALE_ARCHIVE` environment variable.
On non-NixOS distributions, this variable is obviously not set. This can cause regressions in language support or even crashes in some Nixpkgs-provided programs. The simplest way to mitigate this problem is exporting the `LOCALE_ARCHIVE` variable pointing to `${glibcLocales}/lib/locale/locale-archive`. The drawback (and the reason this is not the default) is the relatively large (a hundred MiB) size of the full set of locales. It is possible to build a custom set of locales by overriding parameters `allLocales` and `locales` of the package.
On non-NixOS distributions this variable is obviously not set. This can cause regressions in language support or even crashes in some Nixpkgs-provided programs. The simplest way to mitigate this problem is exporting the `LOCALE_ARCHIVE` variable pointing to `${glibcLocales}/lib/locale/locale-archive`. The drawback (and the reason this is not the default) is the relatively large (a hundred MiB) size of the full set of locales. It is possible to build a custom set of locales by overriding parameters `allLocales` and `locales` of the package.

View File

@@ -4,8 +4,8 @@
## ETags on static files served from the Nix store {#sec-nginx-etag}
HTTP has a couple of different mechanisms for caching to prevent clients from having to download the same content repeatedly if a resource has not changed since the last time it was requested. When nginx is used as a server for static files, it implements the caching mechanism based on the [`Last-Modified`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Last-Modified) response header automatically; unfortunately, it works by using filesystem timestamps to determine the value of the `Last-Modified` header. This doesn't give the desired behavior when the file is in the Nix store because all file timestamps are set to 0 (for reasons related to build reproducibility).
HTTP has a couple different mechanisms for caching to prevent clients from having to download the same content repeatedly if a resource has not changed since the last time it was requested. When nginx is used as a server for static files, it implements the caching mechanism based on the [`Last-Modified`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Last-Modified) response header automatically; unfortunately, it works by using filesystem timestamps to determine the value of the `Last-Modified` header. This doesn't give the desired behavior when the file is in the Nix store, because all file timestamps are set to 0 (for reasons related to build reproducibility).
Fortunately, HTTP supports an alternative (and more effective) caching mechanism: the [`ETag`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/ETag) response header. The value of the `ETag` header specifies some identifier for the particular content that the server is sending (e.g., a hash). When a client makes a second request for the same resource, it sends that value back in an `If-None-Match` header. If the ETag value is unchanged, then the server does not need to resend the content.
Fortunately, HTTP supports an alternative (and more effective) caching mechanism: the [`ETag`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/ETag) response header. The value of the `ETag` header specifies some identifier for the particular content that the server is sending (e.g. a hash). When a client makes a second request for the same resource, it sends that value back in an `If-None-Match` header. If the ETag value is unchanged, then the server does not need to resend the content.
As of NixOS 19.09, the nginx package in Nixpkgs is patched such that when nginx serves a file out of `/nix/store`, the hash in the store path is used as the `ETag` header in the HTTP response, thus providing proper caching functionality. This happens automatically; you do not need to do modify any configuration to get this behavior.

View File

@@ -4,12 +4,12 @@ OpenGL support varies depending on which hardware is used and which drivers are
Broadly, we support both GL vendors: Mesa and NVIDIA.
## NixOS Desktop {#nixos-desktop}
## NixOS Desktop
The NixOS desktop or other non-headless configurations are the primary target for OpenGL libraries and applications. The current solution for discovering which drivers are available is based on [libglvnd](https://gitlab.freedesktop.org/glvnd/libglvnd). `libglvnd` performs "vendor-neutral dispatch", trying a variety of techniques to find the system's GL implementation. In practice, this will be either via standard GLX for X11 users or EGL for Wayland users, and supporting either NVIDIA or Mesa extensions.
## Nix on GNU/Linux {#nix-on-gnulinux}
## Nix on GNU/Linux
If you are using a non-NixOS GNU/Linux/X11 desktop with free software video drivers, consider launching OpenGL-dependent programs from Nixpkgs with Nixpkgs versions of `libglvnd` and `mesa.drivers` in `LD_LIBRARY_PATH`. For Mesa drivers, the Linux kernel version doesn't have to match nixpkgs.
For proprietary video drivers, you might have luck with also adding the corresponding video driver package.
For proprietary video drivers you might have luck with also adding the corresponding video driver package.

View File

@@ -4,7 +4,7 @@ Some packages provide the shell integration to be more useful. But unlike other
- `fzf` : `fzf-share`
E.g. `fzf` can then be used in the `.bashrc` like this:
E.g. `fzf` can then used in the `.bashrc` like this:
```bash
source "$(fzf-share)/completion.bash"

View File

@@ -2,25 +2,24 @@
## Steam in Nix {#sec-steam-nix}
Steam is distributed as a `.deb` file, for now only as an i686 package (the amd64 package only has documentation). When unpacked, it has a script called `steam` that in Ubuntu (their target distro) would go to `/usr/bin`. When run for the first time, this script copies some files to the user's home, which include another script that is the ultimate responsible for launching the steam binary, which is also in `$HOME`.
Steam is distributed as a `.deb` file, for now only as an i686 package (the amd64 package only has documentation). When unpacked, it has a script called `steam` that in Ubuntu (their target distro) would go to `/usr/bin`. When run for the first time, this script copies some files to the user's home, which include another script that is the ultimate responsible for launching the steam binary, which is also in \$HOME.
Nix problems and constraints:
- We don't have `/bin/bash` and many scripts point there. Same thing for `/usr/bin/python`.
- We don't have `/bin/bash` and many scripts point there. Similarly for `/usr/bin/python`.
- We don't have the dynamic loader in `/lib`.
- The `steam.sh` script in `$HOME` cannot be patched, as it is checked and rewritten by steam.
- The `steam.sh` script in \$HOME can not be patched, as it is checked and rewritten by steam.
- The steam binary cannot be patched, it's also checked.
The current approach to deploy Steam in NixOS is composing a FHS-compatible chroot environment, as documented [here](http://sandervanderburg.blogspot.nl/2013/09/composing-fhs-compatible-chroot.html). This allows us to have binaries in the expected paths without disrupting the system, and to avoid patching them to work in a non FHS environment.
## How to play {#sec-steam-play}
Use `programs.steam.enable = true;` if you want to add steam to `systemPackages` and also enable a few workarounds as well as Steam controller support or other Steam supported controllers such as the DualShock 4 or Nintendo Switch Pro Controller.
Use `programs.steam.enable = true;` if you want to add steam to systemPackages and also enable a few workarrounds aswell as Steam controller support or other Steam supported controllers such as the DualShock 4 or Nintendo Switch Pr.
## Troubleshooting {#sec-steam-troub}
- **Steam fails to start. What do I do?**
Try to run
```ShellSession
@@ -32,31 +31,38 @@ Use `programs.steam.enable = true;` if you want to add steam to `systemPackages`
- **Using the FOSS Radeon or nouveau (nvidia) drivers**
- The `newStdcpp` parameter was removed since NixOS 17.09 and should not be needed anymore.
- Steam ships statically linked with a version of `libcrypto` that conflicts with the one dynamically loaded by radeonsi_dri.so. If you get the error:
- Steam ships statically linked with a version of libcrypto that conflics with the one dynamically loaded by radeonsi_dri.so. If you get the error
```
steam.sh: line 713: 7842 Segmentation fault (core dumped)
```
have a look at [this pull request](https://github.com/NixOS/nixpkgs/pull/20269).
- **Java**
1. There is no java in steam chrootenv by default. If you get a message like:
1. There is no java in steam chrootenv by default. If you get a message like
```
/home/foo/.local/share/Steam/SteamApps/common/towns/towns.sh: line 1: java: command not found
```
```
/home/foo/.local/share/Steam/SteamApps/common/towns/towns.sh: line 1: java: command not found
```
you need to add:
You need to add
```nix
steam.override { withJava = true; };
```
```nix
steam.override { withJava = true; };
```
## steam-run {#sec-steam-run}
The FHS-compatible chroot used for Steam can also be used to run other Linux games that expect a FHS environment. To use it, install the `steam-run` package and run the game with:
The FHS-compatible chroot used for steam can also be used to run other linux games that expect a FHS environment. To do it, add
```nix
pkgs.steam.override ({
nativeOnly = true;
newStdcpp = true;
}).run
```
to your configuration, rebuild, and run the game with
```
steam-run ./foo

View File

@@ -0,0 +1,13 @@
<section xmlns="http://docbook.org/ns/docbook"
xmlns:xlink="http://www.w3.org/1999/xlink"
xml:id="unfree-software">
<title>Unfree software</title>
<para>
All users of Nixpkgs are free software users, and many users (and developers) of Nixpkgs want to limit and tightly control their exposure to unfree software. At the same time, many users need (or want) to run some specific pieces of proprietary software. Nixpkgs includes some expressions for unfree software packages. By default unfree software cannot be installed and doesnt show up in searches. To allow installing unfree software in a single Nix invocation one can export <literal>NIXPKGS_ALLOW_UNFREE=1</literal>. For a persistent solution, users can set <literal>allowUnfree</literal> in the Nixpkgs configuration.
</para>
<para>
Fine-grained control is possible by defining <literal>allowUnfreePredicate</literal> function in config; it takes the <literal>mkDerivation</literal> parameter attrset and returns <literal>true</literal> for unfree packages that should be allowed.
</para>
</section>

View File

@@ -4,7 +4,7 @@ Urxvt, also known as rxvt-unicode, is a highly customizable terminal emulator.
## Configuring urxvt {#sec-urxvt-conf}
In `nixpkgs`, urxvt is provided by the package `rxvt-unicode`. It can be configured to include your choice of plugins, reducing its closure size from the default configuration which includes all available plugins. To make use of this functionality, use an overlay or directly install an expression that overrides its configuration, such as:
In `nixpkgs`, urxvt is provided by the package `rxvt-unicode`. It can be configured to include your choice of plugins, reducing its closure size from the default configuration which includes all available plugins. To make use of this functionality, use an overlay or directly install an expression that overrides its configuration, such as
```nix
rxvt-unicode.override {
@@ -58,14 +58,14 @@ rxvt-unicode.override {
## Packaging urxvt plugins {#sec-urxvt-pkg}
Urxvt plugins resides in `pkgs/applications/misc/rxvt-unicode-plugins`. To add a new plugin, create an expression in a subdirectory and add the package to the set in `pkgs/applications/misc/rxvt-unicode-plugins/default.nix`.
Urxvt plugins resides in `pkgs/applications/misc/rxvt-unicode-plugins`. To add a new plugin create an expression in a subdirectory and add the package to the set in `pkgs/applications/misc/rxvt-unicode-plugins/default.nix`.
A plugin can be any kind of derivation, the only requirement is that it should always install perl scripts in `$out/lib/urxvt/perl`. Look for existing plugins for examples.
If the plugin is itself a Perl package that needs to be imported from other plugins or scripts, add the following passthrough:
If the plugin is itself a perl package that needs to be imported from other plugins or scripts, add the following passthrough:
```nix
passthru.perlPackages = [ "self" ];
```
This will make the urxvt wrapper pick up the dependency and set up the Perl path accordingly.
This will make the urxvt wrapper pick up the dependency and set up the perl path accordingly.

View File

@@ -1,6 +1,6 @@
# WeeChat {#sec-weechat}
# Weechat {#sec-weechat}
WeeChat can be configured to include your choice of plugins, reducing its closure size from the default configuration which includes all available plugins. To make use of this functionality, install an expression that overrides its configuration, such as:
Weechat can be configured to include your choice of plugins, reducing its closure size from the default configuration which includes all available plugins. To make use of this functionality, install an expression that overrides its configuration such as
```nix
weechat.override {configure = {availablePlugins, ...}: {
@@ -13,7 +13,7 @@ If the `configure` function returns an attrset without the `plugins` attribute,
The plugins currently available are `python`, `perl`, `ruby`, `guile`, `tcl` and `lua`.
The Python and Perl plugins allows the addition of extra libraries. For instance, the `inotify.py` script in `weechat-scripts` requires D-Bus or libnotify, and the `fish.py` script requires `pycrypto`. To use these scripts, use the plugin's `withPackages` attribute:
The python and perl plugins allows the addition of extra libraries. For instance, the `inotify.py` script in `weechat-scripts` requires D-Bus or libnotify, and the `fish.py` script requires `pycrypto`. To use these scripts, use the plugin's `withPackages` attribute:
```nix
weechat.override { configure = {availablePlugins, ...}: {
@@ -41,7 +41,7 @@ weechat.override {
configure = { availablePlugins, ... }: {
init = ''
/set foo bar
/server add libera irc.libera.chat
/server add freenode chat.freenode.org
'';
};
}
@@ -49,7 +49,7 @@ weechat.override {
Further values can be added to the list of commands when running `weechat --run-command "your-commands"`.
Additionally, it's possible to specify scripts to be loaded when starting `weechat`. These will be loaded before the commands from `init`:
Additionally it's possible to specify scripts to be loaded when starting `weechat`. These will be loaded before the commands from `init`:
```nix
weechat.override {
@@ -64,7 +64,7 @@ weechat.override {
}
```
In `nixpkgs` there's a subpackage which contains derivations for WeeChat scripts. Such derivations expect a `passthru.scripts` attribute, which contains a list of all scripts inside the store path. Furthermore, all scripts have to live in `$out/share`. An exemplary derivation looks like this:
In `nixpkgs` there's a subpackage which contains derivations for WeeChat scripts. Such derivations expect a `passthru.scripts` attribute which contains a list of all scripts inside the store path. Furthermore all scripts have to live in `$out/share`. An exemplary derivation looks like this:
```nix
{ stdenv, fetchurl }:
@@ -73,7 +73,7 @@ stdenv.mkDerivation {
name = "exemplary-weechat-script";
src = fetchurl {
url = "https://scripts.tld/your-scripts.tar.gz";
hash = "...";
sha256 = "...";
};
passthru.scripts = [ "foo.py" "bar.lua" ];
installPhase = ''

View File

@@ -2,7 +2,7 @@
The Nix expressions for the X.org packages reside in `pkgs/servers/x11/xorg/default.nix`. This file is automatically generated from lists of tarballs in an X.org release. As such it should not be modified directly; rather, you should modify the lists, the generator script or the file `pkgs/servers/x11/xorg/overrides.nix`, in which you can override or add to the derivations produced by the generator.
## Katamari Tarballs {#katamari-tarballs}
## Katamari Tarballs
X.org upstream releases used to include [katamari](https://en.wiktionary.org/wiki/%E3%81%8B%E3%81%9F%E3%81%BE%E3%82%8A) releases, which included a holistic recommended version for each tarball, up until 7.7. To create a list of tarballs in a katamari release:
@@ -14,11 +14,11 @@ cat $(PRINT_PATH=1 nix-prefetch-url $url | tail -n 1) \
| sort > "tarballs-$release.list"
```
## Individual Tarballs {#individual-tarballs}
## Individual Tarballs
The upstream release process for [X11R7.8](https://x.org/wiki/Releases/7.8/) does not include a planned katamari. Instead, each component of X.org is released as its own tarball. We maintain `pkgs/servers/x11/xorg/tarballs.list` as a list of tarballs for each individual package. This list includes X.org core libraries and protocol descriptions, extra newer X11 interface libraries, like `xorg.libxcb`, and classic utilities which are largely unused but still available if needed, like `xorg.imake`.
## Generating Nix Expressions {#generating-nix-expressions}
## Generating Nix Expressions
The generator is invoked as follows:
@@ -29,6 +29,6 @@ cd pkgs/servers/x11/xorg
For each of the tarballs in the `.list` files, the script downloads it, unpacks it, and searches its `configure.ac` and `*.pc.in` files for dependencies. This information is used to generate `default.nix`. The generator caches downloaded tarballs between runs. Pay close attention to the `NOT FOUND: $NAME` messages at the end of the run, since they may indicate missing dependencies. (Some might be optional dependencies, however.)
## Overriding the Generator {#overriding-the-generator}
## Overriding the Generator
If the expression for a package requires derivation attributes that the generator cannot figure out automatically (say, `patches` or a `postInstall` hook), you should modify `pkgs/servers/x11/xorg/overrides.nix`.

View File

@@ -6,8 +6,5 @@
This chapter describes several special builders.
</para>
<xi:include href="special/fhs-environments.section.xml" />
<xi:include href="special/makesetuphook.section.xml" />
<xi:include href="special/mkshell.section.xml" />
<xi:include href="special/darwin-builder.section.xml" />
<xi:include href="special/vm-tools.section.xml" />
</chapter>

View File

@@ -1,149 +0,0 @@
# darwin.builder {#sec-darwin-builder}
`darwin.builder` provides a way to bootstrap a Linux builder on a macOS machine.
This requires macOS version 12.4 or later.
This also requires that port 22 on your machine is free (since Nix does not
permit specifying a non-default SSH port for builders).
You will also need to be a trusted user for your Nix installation. In other
words, your `/etc/nix/nix.conf` should have something like:
```
extra-trusted-users = <your username goes here>
```
To launch the builder, run the following flake:
```ShellSession
$ nix run nixpkgs#darwin.builder
```
That will prompt you to enter your `sudo` password:
```
+ sudo --reset-timestamp /nix/store/…-install-credentials.sh ./keys
Password:
```
… so that it can install a private key used to `ssh` into the build server.
After that the script will launch the virtual machine and automatically log you
in as the `builder` user:
```
<<< Welcome to NixOS 22.11.20220901.1bd8d11 (aarch64) - ttyAMA0 >>>
Run 'nixos-help' for the NixOS manual.
nixos login: builder (automatic login)
[builder@nixos:~]$
```
> Note: When you need to stop the VM, run `shutdown now` as the `builder` user.
To delegate builds to the remote builder, add the following options to your
`nix.conf` file:
```
# - Replace ${ARCH} with either aarch64 or x86_64 to match your host machine
# - Replace ${MAX_JOBS} with the maximum number of builds (pick 4 if you're not sure)
builders = ssh-ng://builder@localhost ${ARCH}-linux /etc/nix/builder_ed25519 ${MAX_JOBS} - - - c3NoLWVkMjU1MTkgQUFBQUMzTnphQzFsWkRJMU5URTVBQUFBSUpCV2N4Yi9CbGFxdDFhdU90RStGOFFVV3JVb3RpQzVxQkorVXVFV2RWQ2Igcm9vdEBuaXhvcwo=
# Not strictly necessary, but this will reduce your disk utilization
builders-use-substitutes = true
```
… and then restart your Nix daemon to apply the change:
```ShellSession
$ sudo launchctl kickstart -k system/org.nixos.nix-daemon
```
## Example flake usage
```
{
inputs = {
nixpkgs.url = "github:nixos/nixpkgs/nixpkgs-22.11-darwin";
darwin.url = "github:lnl7/nix-darwin/master";
darwin.inputs.nixpkgs.follows = "nixpkgs";
};
outputs = { self, darwin, nixpkgs, ... }@inputs:
let
inherit (darwin.lib) darwinSystem;
system = "aarch64-darwin";
pkgs = nixpkgs.legacyPackages."${system}";
linuxSystem = builtins.replaceStrings [ "darwin" ] [ "linux" ] system;
darwin-builder = nixpkgs.lib.nixosSystem {
system = linuxSystem;
modules = [
"${nixpkgs}/nixos/modules/profiles/macos-builder.nix"
{ virtualisation.host.pkgs = pkgs; }
];
};
in {
darwinConfigurations = {
machine1 = darwinSystem {
inherit system;
modules = [
{
nix.distributedBuilds = true;
nix.buildMachines = [{
hostName = "ssh://builder@localhost";
system = linuxSystem;
maxJobs = 4;
supportedFeatures = [ "kvm" "benchmark" "big-parallel" ];
}];
launchd.daemons.darwin-builder = {
command = "${darwin-builder.config.system.build.macos-builder-installer}/bin/create-builder";
serviceConfig = {
KeepAlive = true;
RunAtLoad = true;
StandardOutPath = "/var/log/darwin-builder.log";
StandardErrorPath = "/var/log/darwin-builder.log";
};
};
}
];
};
};
};
}
```
## Reconfiguring the builder
Initially you should not change the builder configuration else you will not be
able to use the binary cache. However, after you have the builder running locally
you may use it to build a modified builder with additional storage or memory.
To do this, you just need to set the `virtualisation.darwin-builder.*` parameters as
in the example below and rebuild.
```
darwin-builder = nixpkgs.lib.nixosSystem {
system = linuxSystem;
modules = [
"${nixpkgs}/nixos/modules/profiles/macos-builder.nix"
{
virtualisation.host.pkgs = pkgs;
virtualisation.darwin-builder.diskSize = 5120;
virtualisation.darwin-builder.memorySize = 1024;
virtualisation.darwin-builder.hostPort = 33022;
virtualisation.darwin-builder.workingDirectory = "/var/lib/darwin-builder";
}
];
```
You may make any other changes to your VM in this attribute set. For example,
you could enable Docker or X11 forwarding to your Darwin host.

View File

@@ -1,6 +1,6 @@
# buildFHSEnv {#sec-fhs-environments}
# buildFHSUserEnv {#sec-fhs-environments}
`buildFHSEnv` provides a way to build and run FHS-compatible lightweight sandboxes. It creates an isolated root with bound `/nix/store`, so its footprint in terms of disk space needed is quite small. This allows one to run software which is hard or unfeasible to patch for NixOS -- 3rd-party source trees with FHS assumptions, games distributed as tarballs, software with integrity checking and/or external self-updated binaries. It uses Linux namespaces feature to create temporary lightweight environments which are destroyed after all child processes exit, without root user rights requirement. Accepted arguments are:
`buildFHSUserEnv` provides a way to build and run FHS-compatible lightweight sandboxes. It creates an isolated root with bound `/nix/store`, so its footprint in terms of disk space needed is quite small. This allows one to run software which is hard or unfeasible to patch for NixOS -- 3rd-party source trees with FHS assumptions, games distributed as tarballs, software with integrity checking and/or external self-updated binaries. It uses Linux namespaces feature to create temporary lightweight environments which are destroyed after all child processes exit, without root user rights requirement. Accepted arguments are:
- `name`
Environment name.
@@ -18,19 +18,17 @@
Additional commands to be executed for finalizing the derivation with runner script.
- `runScript`
A command that would be executed inside the sandbox and passed all the command line arguments. It defaults to `bash`.
- `profile`
Optional script for `/etc/profile` within the sandbox.
One can create a simple environment using a `shell.nix` like that:
```nix
{ pkgs ? import <nixpkgs> {} }:
(pkgs.buildFHSEnv {
(pkgs.buildFHSUserEnv {
name = "simple-x11-env";
targetPkgs = pkgs: (with pkgs;
[ udev
alsa-lib
alsaLib
]) ++ (with pkgs.xorg;
[ libX11
libXcursor
@@ -38,12 +36,10 @@ One can create a simple environment using a `shell.nix` like that:
]);
multiPkgs = pkgs: (with pkgs;
[ udev
alsa-lib
alsaLib
]);
runScript = "bash";
}).env
```
Running `nix-shell` would then drop you into a shell with these libraries and binaries available. You can use this to run closed-source applications which expect FHS structure without hassles: simply change `runScript` to the application path, e.g. `./bin/start.sh` -- relative paths are supported.
Additionally, the FHS builder links all relocated gsettings-schemas (the glib setup-hook moves them to `share/gsettings-schemas/${name}/glib-2.0/schemas`) to their standard FHS location. This means you don't need to wrap binaries with `wrapGAppsHook`.

View File

@@ -1,37 +0,0 @@
# pkgs.makeSetupHook {#sec-pkgs.makeSetupHook}
`pkgs.makeSetupHook` is a builder that produces hooks that go in to `nativeBuildInputs`
## Usage {#sec-pkgs.makeSetupHook-usage}
```nix
pkgs.makeSetupHook {
name = "something-hook";
propagatedBuildInputs = [ pkgs.commandsomething ];
depsTargetTargetPropagated = [ pkgs.libsomething ];
} ./script.sh
```
#### setup hook that depends on the hello package and runs hello and @shell@ is substituted with path to bash {#sec-pkgs.makeSetupHook-usage-example}
```nix
pkgs.makeSetupHook {
name = "run-hello-hook";
propagatedBuildInputs = [ pkgs.hello ];
substitutions = { shell = "${pkgs.bash}/bin/bash"; };
passthru.tests.greeting = callPackage ./test { };
meta.platforms = lib.platforms.linux;
} (writeScript "run-hello-hook.sh" ''
#!@shell@
hello
'')
```
## Attributes {#sec-pkgs.makeSetupHook-attributes}
* `name` Set the name of the hook.
* `propagatedBuildInputs` Runtime dependencies (such as binaries) of the hook.
* `depsTargetTargetPropagated` Non-binary dependencies.
* `meta`
* `passthru`
* `substitutions` Variables for `substituteAll`

View File

@@ -1,37 +1,17 @@
# pkgs.mkShell {#sec-pkgs-mkShell}
`pkgs.mkShell` is a specialized `stdenv.mkDerivation` that removes some
repetition when using it with `nix-shell` (or `nix develop`).
`pkgs.mkShell` is a special kind of derivation that is only useful when using
it combined with `nix-shell`. It will in fact fail to instantiate when invoked
with `nix-build`.
## Usage {#sec-pkgs-mkShell-usage}
Here is a common usage example:
```nix
{ pkgs ? import <nixpkgs> {} }:
pkgs.mkShell {
# specify which packages to add to the shell environment
packages = [ pkgs.gnumake ];
inputsFrom = [ pkgs.hello pkgs.gnutar ];
shellHook = ''
export DEBUG=1
'';
# add all the dependencies, of the given packages, to the shell environment
inputsFrom = with pkgs; [ hello gnutar ];
}
```
## Attributes {#sec-pkgs-mkShell-attributes}
* `name` (default: `nix-shell`). Set the name of the derivation.
* `packages` (default: `[]`). Add executable packages to the `nix-shell` environment.
* `inputsFrom` (default: `[]`). Add build dependencies of the listed derivations to the `nix-shell` environment.
* `shellHook` (default: `""`). Bash statements that are executed by `nix-shell`.
... all the attributes of `stdenv.mkDerivation`.
## Building the shell {#sec-pkgs-mkShell-building}
This derivation output will contain a text file that contains a reference to
all the build inputs. This is useful in CI where we want to make sure that
every derivation, and its dependencies, build properly. Or when creating a GC
root so that the build dependencies don't get garbage-collected.

View File

@@ -1,148 +0,0 @@
# vmTools {#sec-vm-tools}
A set of VM related utilities, that help in building some packages in more advanced scenarios.
## `vmTools.createEmptyImage` {#vm-tools-createEmptyImage}
A bash script fragment that produces a disk image at `destination`.
### Attributes
* `size`. The disk size, in MiB.
* `fullName`. Name that will be written to `${destination}/nix-support/full-name`.
* `destination` (optional, default `$out`). Where to write the image files.
## `vmTools.runInLinuxVM` {#vm-tools-runInLinuxVM}
Run a derivation in a Linux virtual machine (using Qemu/KVM).
By default, there is no disk image; the root filesystem is a `tmpfs`, and the Nix store is shared with the host (via the [9P protocol](https://wiki.qemu.org/Documentation/9p#9p_Protocol)).
Thus, any pure Nix derivation should run unmodified.
If the build fails and Nix is run with the `-K/--keep-failed` option, a script `run-vm` will be left behind in the temporary build directory that allows you to boot into the VM and debug it interactively.
### Attributes
* `preVM` (optional). Shell command to be evaluated *before* the VM is started (i.e., on the host).
* `memSize` (optional, default `512`). The memory size of the VM in MiB.
* `diskImage` (optional). A file system image to be attached to `/dev/sda`.
Note that currently we expect the image to contain a filesystem, not a full disk image with a partition table etc.
### Examples
Build the derivation hello inside a VM:
```nix
{ pkgs }: with pkgs; with vmTools;
runInLinuxVM hello
```
Build inside a VM with extra memory:
```nix
{ pkgs }: with pkgs; with vmTools;
runInLinuxVM (hello.overrideAttrs (_: { memSize = 1024; }))
```
Use VM with a disk image (implicitly sets `diskImage`, see [`vmTools.createEmptyImage`](#vm-tools-createEmptyImage)):
```nix
{ pkgs }: with pkgs; with vmTools;
runInLinuxVM (hello.overrideAttrs (_: {
preVM = createEmptyImage {
size = 1024;
fullName = "vm-image";
};
}))
```
## `vmTools.extractFs` {#vm-tools-extractFs}
Takes a file, such as an ISO, and extracts its contents into the store.
### Attributes
* `file`. Path to the file to be extracted.
Note that currently we expect the image to contain a filesystem, not a full disk image with a partition table etc.
* `fs` (optional). Filesystem of the contents of the file.
### Examples
Extract the contents of an ISO file:
```nix
{ pkgs }: with pkgs; with vmTools;
extractFs { file = ./image.iso; }
```
## `vmTools.extractMTDfs` {#vm-tools-extractMTDfs}
Like [](#vm-tools-extractFs), but it makes use of a [Memory Technology Device (MTD)](https://en.wikipedia.org/wiki/Memory_Technology_Device).
## `vmTools.runInLinuxImage` {#vm-tools-runInLinuxImage}
Like [](#vm-tools-runInLinuxVM), but instead of using `stdenv` from the Nix store, run the build using the tools provided by `/bin`, `/usr/bin`, etc. from the specified filesystem image, which typically is a filesystem containing a [FHS](https://en.wikipedia.org/wiki/Filesystem_Hierarchy_Standard)-based Linux distribution.
## `vmTools.makeImageTestScript` {#vm-tools-makeImageTestScript}
Generate a script that can be used to run an interactive session in the given image.
### Examples
Create a script for running a Fedora 27 VM:
```nix
{ pkgs }: with pkgs; with vmTools;
makeImageTestScript diskImages.fedora27x86_64
```
Create a script for running an Ubuntu 20.04 VM:
```nix
{ pkgs }: with pkgs; with vmTools;
makeImageTestScript diskImages.ubuntu2004x86_64
```
## `vmTools.diskImageFuns` {#vm-tools-diskImageFuns}
A set of functions that build a predefined set of minimal Linux distributions images.
### Images
* Fedora
* `fedora26x86_64`
* `fedora27x86_64`
* CentOS
* `centos6i386`
* `centos6x86_64`
* `centos7x86_64`
* Ubuntu
* `ubuntu1404i386`
* `ubuntu1404x86_64`
* `ubuntu1604i386`
* `ubuntu1604x86_64`
* `ubuntu1804i386`
* `ubuntu1804x86_64`
* `ubuntu2004i386`
* `ubuntu2004x86_64`
* `ubuntu2204i386`
* `ubuntu2204x86_64`
* Debian
* `debian10i386`
* `debian10x86_64`
* `debian11i386`
* `debian11x86_64`
### Attributes
* `size` (optional, defaults to `4096`). The size of the image, in MiB.
* `extraPackages` (optional). A list names of additional packages from the distribution that should be included in the image.
### Examples
8GiB image containing Firefox in addition to the default packages:
```nix
{ pkgs }: with pkgs; with vmTools;
diskImageFuns.ubuntu2004x86_64 { extraPackages = [ "firefox" ]; size = 8192; }
```
## `vmTools.diskImageExtraFuns` {#vm-tools-diskImageExtraFuns}
Shorthand for `vmTools.diskImageFuns.<attr> { extraPackages = ... }`.
## `vmTools.diskImages` {#vm-tools-diskImages}
Shorthand for `vmTools.diskImageFuns.<attr> { }`.

View File

@@ -1,211 +0,0 @@
# Testers {#chap-testers}
This chapter describes several testing builders which are available in the <literal>testers</literal> namespace.
## `hasPkgConfigModule` {#tester-hasPkgConfigModule}
Checks whether a package exposes a certain `pkg-config` module.
Example:
```nix
passthru.tests.pkg-config = testers.hasPkgConfigModule {
package = finalAttrs.finalPackage;
moduleName = "libfoo";
}
```
## `testVersion` {#tester-testVersion}
Checks the command output contains the specified version
Although simplistic, this test assures that the main program
can run. While there's no substitute for a real test case,
it does catch dynamic linking errors and such. It also provides
some protection against accidentally building the wrong version,
for example when using an 'old' hash in a fixed-output derivation.
Examples:
```nix
passthru.tests.version = testers.testVersion { package = hello; };
passthru.tests.version = testers.testVersion {
package = seaweedfs;
command = "weed version";
};
passthru.tests.version = testers.testVersion {
package = key;
command = "KeY --help";
# Wrong '2.5' version in the code. Drop on next version.
version = "2.5";
};
passthru.tests.version = testers.testVersion {
package = ghr;
# The output needs to contain the 'version' string without any prefix or suffix.
version = "v${version}";
};
```
## `testBuildFailure` {#tester-testBuildFailure}
Make sure that a build does not succeed. This is useful for testing testers.
This returns a derivation with an override on the builder, with the following effects:
- Fail the build when the original builder succeeds
- Move `$out` to `$out/result`, if it exists (assuming `out` is the default output)
- Save the build log to `$out/testBuildFailure.log` (same)
Example:
```nix
runCommand "example" {
failed = testers.testBuildFailure (runCommand "fail" {} ''
echo ok-ish >$out
echo failing though
exit 3
'');
} ''
grep -F 'ok-ish' $failed/result
grep -F 'failing though' $failed/testBuildFailure.log
[[ 3 = $(cat $failed/testBuildFailure.exit) ]]
touch $out
'';
```
While `testBuildFailure` is designed to keep changes to the original builder's
environment to a minimum, some small changes are inevitable.
- The file `$TMPDIR/testBuildFailure.log` is present. It should not be deleted.
- `stdout` and `stderr` are a pipe instead of a tty. This could be improved.
- One or two extra processes are present in the sandbox during the original
builder's execution.
- The derivation and output hashes are different, but not unusual.
- The derivation includes a dependency on `buildPackages.bash` and
`expect-failure.sh`, which is built to include a transitive dependency on
`buildPackages.coreutils` and possibly more. These are not added to `PATH`
or any other environment variable, so they should be hard to observe.
## `testEqualContents` {#tester-equalContents}
Check that two paths have the same contents.
Example:
```nix
testers.testEqualContents {
assertion = "sed -e performs replacement";
expected = writeText "expected" ''
foo baz baz
'';
actual = runCommand "actual" {
# not really necessary for a package that's in stdenv
nativeBuildInputs = [ gnused ];
base = writeText "base" ''
foo bar baz
'';
} ''
sed -e 's/bar/baz/g' $base >$out
'';
}
```
## `testEqualDerivation` {#tester-testEqualDerivation}
Checks that two packages produce the exact same build instructions.
This can be used to make sure that a certain difference of configuration,
such as the presence of an overlay does not cause a cache miss.
When the derivations are equal, the return value is an empty file.
Otherwise, the build log explains the difference via `nix-diff`.
Example:
```nix
testers.testEqualDerivation
"The hello package must stay the same when enabling checks."
hello
(hello.overrideAttrs(o: { doCheck = true; }))
```
## `invalidateFetcherByDrvHash` {#tester-invalidateFetcherByDrvHash}
Use the derivation hash to invalidate the output via name, for testing.
Type: `(a@{ name, ... } -> Derivation) -> a -> Derivation`
Normally, fixed output derivations can and should be cached by their output
hash only, but for testing we want to re-fetch everytime the fetcher changes.
Changes to the fetcher become apparent in the drvPath, which is a hash of
how to fetch, rather than a fixed store path.
By inserting this hash into the name, we can make sure to re-run the fetcher
every time the fetcher changes.
This relies on the assumption that Nix isn't clever enough to reuse its
database of local store contents to optimize fetching.
You might notice that the "salted" name derives from the normal invocation,
not the final derivation. `invalidateFetcherByDrvHash` has to invoke the fetcher
function twice: once to get a derivation hash, and again to produce the final
fixed output derivation.
Example:
```nix
tests.fetchgit = testers.invalidateFetcherByDrvHash fetchgit {
name = "nix-source";
url = "https://github.com/NixOS/nix";
rev = "9d9dbe6ed05854e03811c361a3380e09183f4f4a";
hash = "sha256-7DszvbCNTjpzGRmpIVAWXk20P0/XTrWZ79KSOGLrUWY=";
};
```
## `nixosTest` {#tester-nixosTest}
Run a NixOS VM network test using this evaluation of Nixpkgs.
NOTE: This function is primarily for external use. NixOS itself uses `make-test-python.nix` directly. Packages defined in Nixpkgs [reuse NixOS tests via `nixosTests`, plural](#ssec-nixos-tests-linking).
It is mostly equivalent to the function `import ./make-test-python.nix` from the
[NixOS manual](https://nixos.org/nixos/manual/index.html#sec-nixos-tests),
except that the current application of Nixpkgs (`pkgs`) will be used, instead of
letting NixOS invoke Nixpkgs anew.
If a test machine needs to set NixOS options under `nixpkgs`, it must set only the
`nixpkgs.pkgs` option.
### Parameter {#tester-nixosTest-parameter}
A [NixOS VM test network](https://nixos.org/nixos/manual/index.html#sec-nixos-tests), or path to it. Example:
```nix
{
name = "my-test";
nodes = {
machine1 = { lib, pkgs, nodes, ... }: {
environment.systemPackages = [ pkgs.hello ];
services.foo.enable = true;
};
# machine2 = ...;
};
testScript = ''
start_all()
machine1.wait_for_unit("foo.service")
machine1.succeed("hello | foo-send")
'';
}
```
### Result {#tester-nixosTest-result}
A derivation that runs the VM test.
Notable attributes:
* `nodes`: the evaluated NixOS configurations. Useful for debugging and exploring the configuration.
* `driverInteractive`: a script that launches an interactive Python session in the context of the `testScript`.

View File

@@ -35,10 +35,10 @@ This works just like `runCommand`. The only difference is that it also provides
## `runCommandLocal` {#trivial-builder-runCommandLocal}
Variant of `runCommand` that forces the derivation to be built locally, it is not substituted. This is intended for very cheap commands (<1s execution time). It saves on the network round-trip and can speed up a build.
Variant of `runCommand` that forces the derivation to be built locally, it is not substituted. This is intended for very cheap commands (<1s execution time). It saves on the network roundrip and can speed up a build.
::: {.note}
This sets [`allowSubstitutes` to `false`](https://nixos.org/nix/manual/#adv-attr-allowSubstitutes), so only use `runCommandLocal` if you are certain the user will always have a builder for the `system` of the derivation. This should be true for most trivial use cases (e.g., just copying some files to a different location or adding symlinks) because there the `system` is usually the same as `builtins.currentSystem`.
::: note
This sets [`allowSubstitutes` to `false`](https://nixos.org/nix/manual/#adv-attr-allowSubstitutes), so only use `runCommandLocal` if you are certain the user will always have a builder for the `system` of the derivation. This should be true for most trivial use cases (e.g. just copying some files to a different location or adding symlinks), because there the `system` is usually the same as `builtins.currentSystem`.
:::
## `writeTextFile`, `writeText`, `writeTextDir`, `writeScript`, `writeScriptBin` {#trivial-builder-writeText}
@@ -47,133 +47,9 @@ These functions write `text` to the Nix store. This is useful for creating scrip
Many more commands wrap `writeTextFile` including `writeText`, `writeTextDir`, `writeScript`, and `writeScriptBin`. These are convenience functions over `writeTextFile`.
Here are a few examples:
```nix
# Writes my-file to /nix/store/<store path>
writeTextFile {
name = "my-file";
text = ''
Contents of File
'';
}
# See also the `writeText` helper function below.
# Writes executable my-file to /nix/store/<store path>/bin/my-file
writeTextFile {
name = "my-file";
text = ''
Contents of File
'';
executable = true;
destination = "/bin/my-file";
}
# Writes contents of file to /nix/store/<store path>
writeText "my-file"
''
Contents of File
'';
# Writes contents of file to /nix/store/<store path>/share/my-file
writeTextDir "share/my-file"
''
Contents of File
'';
# Writes my-file to /nix/store/<store path> and makes executable
writeScript "my-file"
''
Contents of File
'';
# Writes my-file to /nix/store/<store path>/bin/my-file and makes executable.
writeScriptBin "my-file"
''
Contents of File
'';
# Writes my-file to /nix/store/<store path> and makes executable.
writeShellScript "my-file"
''
Contents of File
'';
# Writes my-file to /nix/store/<store path>/bin/my-file and makes executable.
writeShellScriptBin "my-file"
''
Contents of File
'';
```
## `concatTextFile`, `concatText`, `concatScript` {#trivial-builder-concatText}
These functions concatenate `files` to the Nix store in a single file. This is useful for configuration files structured in lines of text. `concatTextFile` takes an attribute set and expects two arguments, `name` and `files`. `name` corresponds to the name used in the Nix store path. `files` will be the files to be concatenated. You can also set `executable` to true to make this file have the executable bit set.
`concatText` and`concatScript` are simple wrappers over `concatTextFile`.
Here are a few examples:
```nix
# Writes my-file to /nix/store/<store path>
concatTextFile {
name = "my-file";
files = [ drv1 "${drv2}/path/to/file" ];
}
# See also the `concatText` helper function below.
# Writes executable my-file to /nix/store/<store path>/bin/my-file
concatTextFile {
name = "my-file";
files = [ drv1 "${drv2}/path/to/file" ];
executable = true;
destination = "/bin/my-file";
}
# Writes contents of files to /nix/store/<store path>
concatText "my-file" [ file1 file2 ]
# Writes contents of files to /nix/store/<store path>
concatScript "my-file" [ file1 file2 ]
```
## `writeShellApplication` {#trivial-builder-writeShellApplication}
This can be used to easily produce a shell script that has some dependencies (`runtimeInputs`). It automatically sets the `PATH` of the script to contain all of the listed inputs, sets some sanity shellopts (`errexit`, `nounset`, `pipefail`), and checks the resulting script with [`shellcheck`](https://github.com/koalaman/shellcheck).
For example, look at the following code:
```nix
writeShellApplication {
name = "show-nixos-org";
runtimeInputs = [ curl w3m ];
text = ''
curl -s 'https://nixos.org' | w3m -dump -T text/html
'';
}
```
Unlike with normal `writeShellScriptBin`, there is no need to manually write out `${curl}/bin/curl`, setting the PATH
was handled by `writeShellApplication`. Moreover, the script is being checked with `shellcheck` for more strict
validation.
## `symlinkJoin` {#trivial-builder-symlinkJoin}
This can be used to put many derivations into the same directory structure. It works by creating a new derivation and adding symlinks to each of the paths listed. It expects two arguments, `name`, and `paths`. `name` is the name used in the Nix store path for the created derivation. `paths` is a list of paths that will be symlinked. These paths can be to Nix store derivations or any other subdirectory contained within.
Here is an example:
```nix
# adds symlinks of hello and stack to current build and prints "links added"
symlinkJoin { name = "myexample"; paths = [ pkgs.hello pkgs.stack ]; postBuild = "echo links added"; }
```
This creates a derivation with a directory structure like the following:
```
/nix/store/sglsr5g079a5235hy29da3mq3hv8sjmm-myexample
|-- bin
| |-- hello -> /nix/store/qy93dp4a3rqyn2mz63fbxjg228hffwyw-hello-2.10/bin/hello
| `-- stack -> /nix/store/6lzdpxshx78281vy056lbk553ijsdr44-stack-2.1.3.1/bin/stack
`-- share
|-- bash-completion
| `-- completions
| `-- stack -> /nix/store/6lzdpxshx78281vy056lbk553ijsdr44-stack-2.1.3.1/share/bash-completion/completions/stack
|-- fish
| `-- vendor_completions.d
| `-- stack.fish -> /nix/store/6lzdpxshx78281vy056lbk553ijsdr44-stack-2.1.3.1/share/fish/vendor_completions.d/stack.fish
...
```
## `writeReferencesToFile` {#trivial-builder-writeReferencesToFile}
@@ -219,5 +95,5 @@ produces an output path `/nix/store/<hash>-runtime-references` containing
/nix/store/<hash>-hello-2.10
```
but none of `hello`'s dependencies because those are not referenced directly
but none of `hello`'s dependencies, because those are not referenced directly
by `hi`'s output.

View File

@@ -6,7 +6,7 @@
- Do not use tab characters, i.e. configure your editor to use soft tabs. For instance, use `(setq-default indent-tabs-mode nil)` in Emacs. Everybody has different tab settings so its asking for trouble.
- Use `lowerCamelCase` for variable names, not `UpperCamelCase`. Note, this rule does not apply to package attribute names, which instead follow the rules in [](#sec-package-naming).
- Use `lowerCamelCase` for variable names, not `UpperCamelCase`. Note, this rule does not apply to package attribute names, which instead follow the rules in <xref linkend="sec-package-naming"/>.
- Function calls with attribute set arguments are written as
@@ -181,50 +181,38 @@
rev = "${version}";
```
- Building lists conditionally _should_ be done with `lib.optional(s)` instead of using `if cond then [ ... ] else null` or `if cond then [ ... ] else [ ]`.
```nix
buildInputs = lib.optional stdenv.isDarwin iconv;
```
instead of
```nix
buildInputs = if stdenv.isDarwin then [ iconv ] else null;
```
As an exception, an explicit conditional expression with null can be used when fixing a important bug without triggering a mass rebuild.
If this is done a follow up pull request _should_ be created to change the code to `lib.optional(s)`.
- Arguments should be listed in the order they are used, with the exception of `lib`, which always goes first.
- The top-level `lib` must be used in the master and 21.05 branch over its alias `stdenv.lib` as it now causes evaluation errors when aliases are disabled which is the case for ofborg.
`lib` is unrelated to `stdenv`, and so `stdenv.lib` should only be used as a convenience alias when developing locally to avoid having to modify the function inputs just to test something out.
## Package naming {#sec-package-naming}
The key words _must_, _must not_, _required_, _shall_, _shall not_, _should_, _should not_, _recommended_, _may_, and _optional_ in this section are to be interpreted as described in [RFC 2119](https://tools.ietf.org/html/rfc2119). Only _emphasized_ words are to be interpreted in this way.
In Nixpkgs, there are generally three different names associated with a package:
- The `pname` attribute of the derivation. This is what most users see, in particular when using `nix-env`.
- The `name` attribute of the derivation (excluding the version part). This is what most users see, in particular when using `nix-env`.
- The variable name used for the instantiated package in `all-packages.nix`, and when passing it as a dependency to other functions. Typically this is called the _package attribute name_. This is what Nix expression authors see. It can also be used when installing using `nix-env -iA`.
- The filename for (the directory containing) the Nix expression.
Most of the time, these are the same. For instance, the package `e2fsprogs` has a `pname` attribute `"e2fsprogs"`, is bound to the variable name `e2fsprogs` in `all-packages.nix`, and the Nix expression is in `pkgs/os-specific/linux/e2fsprogs/default.nix`.
Most of the time, these are the same. For instance, the package `e2fsprogs` has a `name` attribute `"e2fsprogs-version"`, is bound to the variable name `e2fsprogs` in `all-packages.nix`, and the Nix expression is in `pkgs/os-specific/linux/e2fsprogs/default.nix`.
There are a few naming guidelines:
- The `pname` attribute _should_ be identical to the upstream package name.
- The `name` attribute _should_ be identical to the upstream package name.
- The `pname` and the `version` attribute _must not_ contain uppercase letters — e.g., `"mplayer" instead of `"MPlayer"`.
- The `name` attribute _must not_ contain uppercase letters — e.g., `"mplayer-1.0rc2"` instead of `"MPlayer-1.0rc2"`.
- The `version` attribute _must_ start with a digit e.g`"0.3.1rc2".
- The version part of the `name` attribute _must_ start with a digit (following a dash) — e.g., `"hello-0.3.1rc2"`.
- If a package is not a release but a commit from a repository, then the `version` attribute _must_ be the date of that (fetched) commit. The date _must_ be in `"unstable-YYYY-MM-DD"` format.
- If a package is not a release but a commit from a repository, then the version part of the name _must_ be the date of that (fetched) commit. The date _must_ be in `"YYYY-MM-DD"` format. Also append `"unstable"` to the name - e.g., `"pkgname-unstable-2014-09-23"`.
- Dashes in the package `pname` _should_ be preserved in new variable names, rather than converted to underscores or camel cased — e.g., `http-parser` instead of `http_parser` or `httpParser`. The hyphenated style is preferred in all three package names.
- Dashes in the package name _should_ be preserved in new variable names, rather than converted to underscores or camel cased — e.g., `http-parser` instead of `http_parser` or `httpParser`. The hyphenated style is preferred in all three package names.
- If there are multiple versions of a package, this _should_ be reflected in the variable names in `all-packages.nix`, e.g. `json-c_0_9` and `json-c_0_11`. If there is an obvious “default” version, make an attribute like `json-c = json-c_0_9;`. See also [](#sec-versioning)
- If there are multiple versions of a package, this _should_ be reflected in the variable names in `all-packages.nix`, e.g. `json-c-0-9` and `json-c-0-11`. If there is an obvious “default” version, make an attribute like `json-c = json-c-0-9;`. See also <xref linkend="sec-versioning" />
## File naming and organisation {#sec-organisation}
@@ -260,10 +248,6 @@ When in doubt, consider refactoring the `pkgs/` tree, e.g. creating new categori
- `development/tools/build-managers` (e.g. `gnumake`)
- **If its a _language server_:**
- `development/tools/language-servers` (e.g. `ccls` or `rnix-lsp`)
- **Else:**
- `development/tools/misc` (e.g. `binutils`)
@@ -342,10 +326,6 @@ A (typically large) program with a distinct user interface, primarily used inter
- `applications/terminal-emulators` (e.g. `alacritty` or `rxvt` or `termite`)
- **If its a _file manager_:**
- `applications/file-managers` (e.g. `mc` or `ranger` or `pcmanfm`)
- **If its for _video playback / editing_:**
- `applications/video` (e.g. `vlc`)
@@ -430,10 +410,9 @@ In the file `pkgs/top-level/all-packages.nix` you can find fetch helpers, these
```nix
src = fetchgit {
url = "git@github.com:NixOS/nix.git"
url = "git://github.com/NixOS/nix.git";
rev = "1f795f9f44607cc5bec70d1300150bfefcef2aae";
hash = "sha256-7D4m+saJjbSFP5hOwpQq2FGR2rr+psQMTcyb1ZvtXsQ=";
sha256 = "1cw5fszffl5pkpa6s6wjnkiv6lm5k618s32sp60kvmvpy7a2v9kg";
}
```
@@ -443,7 +422,7 @@ In the file `pkgs/top-level/all-packages.nix` you can find fetch helpers, these
src = fetchgit {
url = "https://github.com/NixOS/nix.git";
rev = "1f795f9f44607cc5bec70d1300150bfefcef2aae";
hash = "sha256-7D4m+saJjbSFP5hOwpQq2FGR2rr+psQMTcyb1ZvtXsQ=";
sha256 = "1cw5fszffl5pkpa6s6wjnkiv6lm5k618s32sp60kvmvpy7a2v9kg";
}
```
@@ -454,14 +433,11 @@ In the file `pkgs/top-level/all-packages.nix` you can find fetch helpers, these
owner = "NixOS";
repo = "nix";
rev = "1f795f9f44607cc5bec70d1300150bfefcef2aae";
hash = "ha256-7D4m+saJjbSFP5hOwpQq2FGR2rr+psQMTcyb1ZvtXsQ=";
sha256 = "1i2yxndxb6yc9l6c99pypbd92lfq5aac4klq7y2v93c9qvx2cgpc";
}
```
When fetching from GitHub, commits must always be referenced by their full commit hash. This is because GitHub shares commit hashes among all forks and returns `404 Not Found` when a short commit hash is ambiguous. It already happens for some short, 6-character commit hashes in `nixpkgs`.
It is a practical vector for a denial-of-service attack by pushing large amounts of auto generated commits into forks and was already [demonstrated against GitHub Actions Beta](https://blog.teddykatz.com/2019/11/12/github-actions-dos.html).
Find the value to put as `hash` by running `nix-shell -p nix-prefetch-github --run "nix-prefetch-github --rev 1f795f9f44607cc5bec70d1300150bfefcef2aae NixOS nix"`.
Find the value to put as `sha256` by running `nix run -f '<nixpkgs>' nix-prefetch-github -c nix-prefetch-github --rev 1f795f9f44607cc5bec70d1300150bfefcef2aae NixOS nix` or `nix-prefetch-url --unpack https://github.com/NixOS/nix/archive/1f795f9f44607cc5bec70d1300150bfefcef2aae.tar.gz`.
## Obtaining source hash {#sec-source-hashes}
@@ -485,23 +461,15 @@ Preferred source hash type is sha256. There are several ways to get it.
4. Extracting hash from local source tarball can be done with `sha256sum`. Use `nix-prefetch-url file:///path/to/tarball` if you want base32 hash.
5. Fake hash: set the hash to one of
5. Fake hash: set fake hash in package expression, perform build and extract correct hash from error Nix prints.
- `""`
- `lib.fakeHash`
- `lib.fakeSha256`
- `lib.fakeSha512`
For package updates it is enough to change one symbol to make hash fake. For new packages, you can use `lib.fakeSha256`, `lib.fakeSha512` or any other fake hash.
in the package expression, attempt build and extract correct hash from error messages.
::: {.warning}
You must use one of these four fake hashes and not some arbitrarily-chosen hash.
See [](#sec-source-hashes-security).
:::
This is last resort method when reconstructing source URL is non-trivial and `nix-prefetch-url -A` isnt applicable (for example, [one of `kodi` dependencies](https://github.com/NixOS/nixpkgs/blob/d2ab091dd308b99e4912b805a5eb088dd536adb9/pkgs/applications/video/kodi/default.nix#L73)). The easiest way then would be replace hash with a fake one and rebuild. Nix build will fail and error message will contain desired hash.
This is last resort method when reconstructing source URL is non-trivial and `nix-prefetch-url -A` isn't applicable (for example, [one of `kodi` dependencies](https://github.com/NixOS/nixpkgs/blob/d2ab091dd308b99e4912b805a5eb088dd536adb9/pkgs/applications/video/kodi/default.nix#L73")). The easiest way then would be replace hash with a fake one and rebuild. Nix build will fail and error message will contain desired hash.
::: warning
This method has security problems. Check below for details.
:::
### Obtaining hashes securely {#sec-source-hashes-security}
@@ -513,7 +481,7 @@ Let's say Man-in-the-Middle (MITM) sits close to your network. Then instead of f
- `https://` URLs are secure in methods 1, 2, 3;
- `https://` URLs are secure in method 5 *only if* you use one of the listed fake hashes. If you use any other hash, `fetchurl` will pass `--insecure` to `curl` and may then degrade to HTTP in case of TLS certificate expiration.
- `https://` URLs are not secure in method 5. When obtaining hashes with fake hash method, TLS checks are disabled. So refetch source hash from several different networks to exclude MITM scenario. Alternatively, use fake hash method to make Nix error, but instead of extracting hash from error, extract `https://` URL and prefetch it with method 1.
## Patches {#sec-patches}
@@ -524,15 +492,13 @@ patches = [
(fetchpatch {
name = "fix-check-for-using-shared-freetype-lib.patch";
url = "http://git.ghostscript.com/?p=ghostpdl.git;a=patch;h=8f5d285";
hash = "sha256-uRcxaCjd+WAuGrXOmGfFeu79cUILwkRdBu48mwcBE7g=";
sha256 = "1f0k043rng7f0rfl9hhb89qzvvksqmkrikmm38p61yfx51l325xr";
})
];
```
Otherwise, you can add a `.patch` file to the `nixpkgs` repository. In the interest of keeping our maintenance burden to a minimum, only patches that are unique to `nixpkgs` should be added in this way.
If a patch is available online but does not cleanly apply, it can be modified in some fixed ways by using additional optional arguments for `fetchpatch`. Check [](#fetchpatch) for details.
```nix
patches = [ ./0001-changes.patch ];
```
@@ -557,41 +523,26 @@ If you do need to do create this sort of patch file, one way to do so is with gi
4. Use git to create a diff, and pipe the output to a patch file:
```ShellSession
$ git diff -a > nixpkgs/pkgs/the/package/0001-changes.patch
$ git diff > nixpkgs/pkgs/the/package/0001-changes.patch
```
If a patch is available online but does not cleanly apply, it can be modified in some fixed ways by using additional optional arguments for `fetchpatch`:
- `stripLen`: Remove the first `stripLen` components of pathnames in the patch.
- `extraPrefix`: Prefix pathnames by this string.
- `excludes`: Exclude files matching this pattern.
- `includes`: Include only files matching this pattern.
- `revert`: Revert the patch.
Note that because the checksum is computed after applying these effects, using or modifying these arguments will have no effect unless the `sha256` argument is changed as well.
## Package tests {#sec-package-tests}
Tests are important to ensure quality and make reviews and automatic updates easy.
The following types of tests exists:
Nix package tests are a lightweight alternative to [NixOS module tests](https://nixos.org/manual/nixos/stable/#sec-nixos-tests). They can be used to create simple integration tests for packages while the module tests are used to test services or programs with a graphical user interface on a NixOS VM. Unittests that are included in the source code of a package should be executed in the `checkPhase`.
* [NixOS **module tests**](https://nixos.org/manual/nixos/stable/#sec-nixos-tests), which spawn one or more NixOS VMs. They exercise both NixOS modules and the packaged programs used within them. For example, a NixOS module test can start a web server VM running the `nginx` module, and a client VM running `curl` or a graphical `firefox`, and test that they can talk to each other and display the correct content.
* Nix **package tests** are a lightweight alternative to NixOS module tests. They should be used to create simple integration tests for packages, but cannot test NixOS services, and some programs with graphical user interfaces may also be difficult to test with them.
* The **`checkPhase` of a package**, which should execute the unit tests that are included in the source code of a package.
Here in the nixpkgs manual we describe mostly _package tests_; for _module tests_ head over to the corresponding [section in the NixOS manual](https://nixos.org/manual/nixos/stable/#sec-nixos-tests).
### Writing inline package tests {#ssec-inline-package-tests-writing}
For very simple tests, they can be written inline:
```nix
{ …, yq-go }:
buildGoModule rec {
passthru.tests = {
simple = runCommand "${pname}-test" {} ''
echo "test: 1" | ${yq-go}/bin/yq eval -j > $out
[ "$(cat $out | tr -d $'\n ')" = '{"test":1}' ]
'';
};
}
```
### Writing larger package tests {#ssec-package-tests-writing}
### Writing package tests {#ssec-package-tests-writing}
This is an example using the `phoronix-test-suite` package with the current best practices.
@@ -620,7 +571,7 @@ let
inherit (phoronix-test-suite) pname version;
in
runCommand "${pname}-tests" { meta.timeout = 60; }
runCommand "${pname}-tests" { meta.timeout = 3; }
''
# automatic initial setup to prevent interactive questions
${phoronix-test-suite}/bin/phoronix-test-suite enterprise-setup >/dev/null
@@ -654,38 +605,3 @@ Here are examples of package tests:
- [Spacy annotation test](https://github.com/NixOS/nixpkgs/blob/master/pkgs/development/python-modules/spacy/annotation-test/default.nix)
- [Libtorch test](https://github.com/NixOS/nixpkgs/blob/master/pkgs/development/libraries/science/math/libtorch/test/default.nix)
- [Multiple tests for nanopb](https://github.com/NixOS/nixpkgs/blob/master/pkgs/development/libraries/nanopb/default.nix)
### Linking NixOS module tests to a package {#ssec-nixos-tests-linking}
Like [package tests](#ssec-package-tests-writing) as shown above, [NixOS module tests](https://nixos.org/manual/nixos/stable/#sec-nixos-tests) can also be linked to a package, so that the tests can be easily run when changing the related package.
For example, assuming we're packaging `nginx`, we can link its module test via `passthru.tests`:
```nix
{ stdenv, lib, nixosTests }:
stdenv.mkDerivation {
...
passthru.tests = {
nginx = nixosTests.nginx;
};
...
}
```
### Import From Derivation {#ssec-import-from-derivation}
Import From Derivation (IFD) is disallowed in Nixpkgs for performance reasons:
[Hydra] evaluates the entire package set, and sequential builds during evaluation would increase evaluation times to become impractical.
[Hydra]: https://github.com/NixOS/hydra
Import From Derivation can be worked around in some cases by committing generated intermediate files to version control and reading those instead.
<!-- TODO: remove the following and link to Nix manual once https://github.com/NixOS/nix/pull/7332 is merged -->
See also [NixOS Wiki: Import From Derivation].
[NixOS Wiki: Import From Derivation]: https://nixos.wiki/wiki/Import_From_Derivation

View File

@@ -1,6 +1,6 @@
# Contributing to this documentation {#chap-contributing}
The sources of the Nixpkgs manual are in the [doc](https://github.com/NixOS/nixpkgs/tree/master/doc) subdirectory of the Nixpkgs repository. The manual is still partially written in DocBook but it is progressively being converted to [Markdown](#sec-contributing-markup).
The DocBook sources of the Nixpkgs manual are in the [doc](https://github.com/NixOS/nixpkgs/tree/master/doc) subdirectory of the Nixpkgs repository.
You can quickly check your edits with `make`:
@@ -22,97 +22,3 @@ $ nix-shell
```
If the build succeeds, the manual will be in `./result/share/doc/nixpkgs/manual.html`.
## Syntax {#sec-contributing-markup}
As per [RFC 0072](https://github.com/NixOS/rfcs/pull/72), all new documentation content should be written in [CommonMark](https://commonmark.org/) Markdown dialect.
Additional syntax extensions are available, all of which can be used in NixOS option documentation. The following extensions are currently used:
- []{#ssec-contributing-markup-anchors}
Explicitly defined **anchors** on headings, to allow linking to sections. These should be always used, to ensure the anchors can be linked even when the heading text changes, and to prevent conflicts between [automatically assigned identifiers](https://github.com/jgm/commonmark-hs/blob/master/commonmark-extensions/test/auto_identifiers.md).
It uses the widely compatible [header attributes](https://github.com/jgm/commonmark-hs/blob/master/commonmark-extensions/test/attributes.md) syntax:
```markdown
## Syntax {#sec-contributing-markup}
```
::: {.note}
NixOS option documentation does not support headings in general.
:::
- []{#ssec-contributing-markup-anchors-inline}
**Inline anchors**, which allow linking arbitrary place in the text (e.g. individual list items, sentences…).
They are defined using a hybrid of the link syntax with the attributes syntax known from headings, called [bracketed spans](https://github.com/jgm/commonmark-hs/blob/master/commonmark-extensions/test/bracketed_spans.md):
```markdown
- []{#ssec-gnome-hooks-glib} `glib` setup hook will populate `GSETTINGS_SCHEMAS_PATH` and then `wrapGAppsHook` will prepend it to `XDG_DATA_DIRS`.
```
- []{#ssec-contributing-markup-automatic-links}
If you **omit a link text** for a link pointing to a section, the text will be substituted automatically. For example, `[](#chap-contributing)` will result in [](#chap-contributing).
This syntax is taken from [MyST](https://myst-parser.readthedocs.io/en/latest/using/syntax.html#targets-and-cross-referencing).
- []{#ssec-contributing-markup-inline-roles}
If you want to link to a man page, you can use `` {manpage}`nix.conf(5)` ``, which will turn into {manpage}`nix.conf(5)`. The references will turn into links when a mapping exists in {file}`doc/manpage-urls.json`.
A few markups for other kinds of literals are also available:
- `` {command}`rm -rfi` `` turns into {command}`rm -rfi`
- `` {env}`XDG_DATA_DIRS` `` turns into {env}`XDG_DATA_DIRS`
- `` {file}`/etc/passwd` `` turns into {file}`/etc/passwd`
- `` {option}`networking.useDHCP` `` turns into {option}`networking.useDHCP`
- `` {var}`/etc/passwd` `` turns into {var}`/etc/passwd`
These literal kinds are used mostly in NixOS option documentation.
This syntax is taken from [MyST](https://myst-parser.readthedocs.io/en/latest/syntax/syntax.html#roles-an-in-line-extension-point). Though, the feature originates from [reStructuredText](https://www.sphinx-doc.org/en/master/usage/restructuredtext/roles.html#role-manpage) with slightly different syntax.
- []{#ssec-contributing-markup-admonitions}
**Admonitions**, set off from the text to bring attention to something.
It uses pandocs [fenced `div`s syntax](https://github.com/jgm/commonmark-hs/blob/master/commonmark-extensions/test/fenced_divs.md):
```markdown
::: {.warning}
This is a warning
:::
```
which renders as
> ::: {.warning}
> This is a warning.
> :::
The following are supported:
- [`caution`](https://tdg.docbook.org/tdg/5.0/caution.html)
- [`important`](https://tdg.docbook.org/tdg/5.0/important.html)
- [`note`](https://tdg.docbook.org/tdg/5.0/note.html)
- [`tip`](https://tdg.docbook.org/tdg/5.0/tip.html)
- [`warning`](https://tdg.docbook.org/tdg/5.0/warning.html)
- []{#ssec-contributing-markup-definition-lists}
[**Definition lists**](https://github.com/jgm/commonmark-hs/blob/master/commonmark-extensions/test/definition_lists.md), for defining a group of terms:
```markdown
pear
: green or yellow bulbous fruit
watermelon
: green fruit with red flesh
```
which renders as
> pear
> : green or yellow bulbous fruit
>
> watermelon
> : green fruit with red flesh
For contributing to the legacy parts, please see [DocBook: The Definitive Guide](https://tdg.docbook.org/) or the [DocBook rocks! primer](https://web.archive.org/web/20200816233747/https://docbook.rocks/).

View File

@@ -9,7 +9,7 @@ To add a package to Nixpkgs:
$ cd nixpkgs
```
2. Find a good place in the Nixpkgs tree to add the Nix expression for your package. For instance, a library package typically goes into `pkgs/development/libraries/pkgname`, while a web browser goes into `pkgs/applications/networking/browsers/pkgname`. See [](#sec-organisation) for some hints on the tree organisation. Create a directory for your package, e.g.
2. Find a good place in the Nixpkgs tree to add the Nix expression for your package. For instance, a library package typically goes into `pkgs/development/libraries/pkgname`, while a web browser goes into `pkgs/applications/networking/browsers/pkgname`. See <xref linkend="sec-organisation" /> for some hints on the tree organisation. Create a directory for your package, e.g.
```ShellSession
$ mkdir pkgs/development/libraries/libfoo
@@ -34,7 +34,7 @@ To add a package to Nixpkgs:
- Apache HTTPD: [`pkgs/servers/http/apache-httpd/2.4.nix`](https://github.com/NixOS/nixpkgs/blob/master/pkgs/servers/http/apache-httpd/2.4.nix). A bunch of optional features, variable substitutions in the configure flags, a post-install hook, and miscellaneous hackery.
- buildMozillaMach: [`pkgs/applications/networking/browser/firefox/common.nix`](https://github.com/NixOS/nixpkgs/blob/master/pkgs/applications/networking/browsers/firefox/common.nix). A reusable build function for Firefox, Thunderbird and Librewolf.
- Thunderbird: [`pkgs/applications/networking/mailreaders/thunderbird/default.nix`](https://github.com/NixOS/nixpkgs/blob/master/pkgs/applications/networking/mailreaders/thunderbird/default.nix). Lots of dependencies.
- JDiskReport, a Java utility: [`pkgs/tools/misc/jdiskreport/default.nix`](https://github.com/NixOS/nixpkgs/blob/master/pkgs/tools/misc/jdiskreport/default.nix). Nixpkgs doesnt have a decent `stdenv` for Java yet so this is pretty ad-hoc.

View File

@@ -1,6 +1,6 @@
# Reviewing contributions {#chap-reviewing-contributions}
::: {.warning}
::: warning
The following section is a draft, and the policy for reviewing is still being discussed in issues such as [#11166](https://github.com/NixOS/nixpkgs/issues/11166) and [#20836](https://github.com/NixOS/nixpkgs/issues/20836).
:::
@@ -35,18 +35,15 @@ Reviewing process:
- Building the package locally.
- pull requests are often targeted to the master or staging branch, and building the pull request locally when it is submitted can trigger many source builds.
- It is possible to rebase the changes on nixos-unstable or nixpkgs-unstable for easier review by running the following commands from a nixpkgs clone.
```ShellSession
$ git fetch origin nixos-unstable
$ git fetch origin pull/PRNUMBER/head
$ git rebase --onto nixos-unstable BASEBRANCH FETCH_HEAD
```
- The first command fetches the nixos-unstable branch.
- The second command fetches the pull request changes, `PRNUMBER` is the number at the end of the pull request title and `BASEBRANCH` the base branch of the pull request.
- The third command rebases the pull request changes to the nixos-unstable branch.
- The [nixpkgs-review](https://github.com/Mic92/nixpkgs-review) tool can be used to review a pull request content in a single command. `PRNUMBER` should be replaced by the number at the end of the pull request title. You can also provide the full github pull request url.
```ShellSession
$ nix-shell -p nixpkgs-review --run "nixpkgs-review pr PRNUMBER"
```
@@ -103,8 +100,7 @@ Sample template for a new package review is provided below.
- [ ] `meta.maintainers` is set
- [ ] build time only dependencies are declared in `nativeBuildInputs`
- [ ] source is fetched using the appropriate function
- [ ] the list of `phases` is not overridden
- [ ] when a phase (like `installPhase`) is overridden it starts with `runHook preInstall` and ends with `runHook postInstall`.
- [ ] phases are respected
- [ ] patches that are remotely available are fetched with `fetchpatch`
##### Possible improvements
@@ -122,10 +118,10 @@ Reviewing process:
- [CODEOWNERS](https://help.github.com/articles/about-codeowners/) will make GitHub notify users based on the submitted changes, but it can happen that it misses some of the package maintainers.
- Ensure that the module tests, if any, are succeeding.
- Ensure that the introduced options are correct.
- Type should be appropriate (string related types differs in their merging capabilities, `loaOf` and `string` types are deprecated).
- Type should be appropriate (string related types differs in their merging capabilities, `optionSet` and `string` types are deprecated).
- Description, default and example should be provided.
- Ensure that option changes are backward compatible.
- `mkRenamedOptionModuleWith` provides a way to make option changes backward compatible.
- `mkRenamedOptionModule` and `mkAliasOptionModule` functions provide way to make option changes backward compatible.
- Ensure that removed options are declared with `mkRemovedOptionModule`
- Ensure that changes that are not backward compatible are mentioned in release notes.
- Ensure that documentations affected by the change is updated.
@@ -157,7 +153,7 @@ Reviewing process:
- Ensure that the module tests, if any, are succeeding.
- Ensure that the introduced options are correct.
- Type should be appropriate (string related types differs in their merging capabilities, `loaOf` and `string` types are deprecated).
- Type should be appropriate (string related types differs in their merging capabilities, `optionSet` and `string` types are deprecated).
- Description, default and example should be provided.
- Ensure that module `meta` field is present
- Maintainers should be declared in `meta.maintainers`.
@@ -185,111 +181,6 @@ Sample template for a new module review is provided below.
##### Comments
```
## Individual maintainer list {#reviewing-contributions-individual-maintainer-list}
When adding users to `maintainers/maintainer-list.nix`, the following
checks should be performed:
- If the user has specified a GPG key, verify that the commit is
signed by their key.
First, validate that the commit adding the maintainer is signed by
the key the maintainer listed. Check out the pull request and
compare its signing key with the listed key in the commit.
If the commit is not signed or it is signed by a different user, ask
them to either recommit using that key or to remove their key
information.
Given a maintainter entry like this:
``` nix
{
example = {
email = "user@example.com";
name = "Example User";
keys = [{
fingerprint = "0000 0000 2A70 6423 0AED 3C11 F04F 7A19 AAA6 3AFE";
}];
}
};
```
First receive their key from a keyserver:
$ gpg --recv-keys 0xF04F7A19AAA63AFE
gpg: key 0xF04F7A19AAA63AFE: public key "Example <user@example.com>" imported
gpg: Total number processed: 1
gpg: imported: 1
Then check the commit is signed by that key:
$ git log --show-signature
commit b87862a4f7d32319b1de428adb6cdbdd3a960153
gpg: Signature made Wed Mar 12 13:32:24 2003 +0000
gpg: using RSA key 000000002A7064230AED3C11F04F7A19AAA63AFE
gpg: Good signature from "Example User <user@example.com>
Author: Example User <user@example.com>
Date: Wed Mar 12 13:32:24 2003 +0000
maintainers: adding example
and validate that there is a `Good signature` and the printed key
matches the user's submitted key.
Note: GitHub's "Verified" label does not display the user's full key
fingerprint, and should not be used for validating the key matches.
- If the user has specified a `github` account name, ensure they have
also specified a `githubId` and verify the two match.
Maintainer entries that include a `github` field must also include
their `githubId`. People can and do change their GitHub name
frequently, and the ID is used as the official and stable identity
of the maintainer.
Given a maintainer entry like this:
``` nix
{
example = {
email = "user@example.com";
name = "Example User";
github = "ghost";
githubId = 10137;
}
};
```
First, make sure that the listed GitHub handle matches the author of
the commit.
Then, visit the URL `https://api.github.com/users/ghost` and
validate that the `id` field matches the provided `githubId`.
## Maintainer teams {#reviewing-contributions-maintainer-teams}
Feel free to create a new maintainer team in `maintainers/team-list.nix`
when a group is collectively responsible for a collection of packages.
Use taste and personal judgement when deciding if a team is warranted.
Teams are allowed to define their own rules about membership.
For example, some teams will represent a business or other group which
wants to carefully track its members. Other teams may be very open about
who can join, and allow anybody to participate.
When reviewing changes to a team, read the team's scope and the context
around the member list for indications about the team's membership
policy.
In any case, request reviews from the existing team members. If the team
lists no specific membership policy, feel free to merge changes to the
team after giving the existing members a few days to respond.
*Important:* If a team says it is a closed group, do not merge additions
to the team without an approval by at least one existing member.
## Other submissions {#reviewing-contributions-other-submissions}
Other type of submissions requires different reviewing steps.
@@ -302,12 +193,6 @@ Container system, boot system and library changes are some examples of the pull
It is possible for community members that have enough knowledge and experience on a special topic to contribute by merging pull requests.
In case the PR is stuck waiting for the original author to apply a trivial
change (a typo, capitalisation change, etc.) and the author allowed the members
to modify the PR, consider applying it yourself. (or commit the existing review
suggestion) You should pay extra attention to make sure the addition doesn't go
against the idea of the original PR and would not be opposed by the author.
<!--
The following paragraphs about how to deal with unactive contributors is just a proposition and should be modified to what the community agrees to be the right policy.

View File

@@ -43,13 +43,13 @@
- nixpkgs:
- update pkg
- `nix-env -iA pkg-attribute-name -f <path to your local nixpkgs folder>`
- `nix-env -i pkg-name -f <path to your local nixpkgs folder>`
- add pkg
- Make sure its in `pkgs/top-level/all-packages.nix`
- `nix-env -iA pkg-attribute-name -f <path to your local nixpkgs folder>`
- `nix-env -i pkg-name -f <path to your local nixpkgs folder>`
- _If you dont want to install pkg in you profile_.
- `nix-build -A pkg-attribute-name <path to your local nixpkgs folder>` and check results in the folder `result`. It will appear in the same directory where you did `nix-build`.
- If you installed your package with `nix-env`, you can run `nix-env -e pkg-name` where `pkg-name` is as reported by `nix-env -q` to uninstall it from your system.
- `nix-build -A pkg-attribute-name <path to your local nixpkgs folder>/default.nix` and check results in the folder `result`. It will appear in the same directory where you did `nix-build`.
- If you did `nix-env -i pkg-name` you can do `nix-env -e pkg-name` to uninstall it from your system.
- NixOS and its modules:
- You can add new module to your NixOS configuration file (usually its `/etc/nixos/configuration.nix`). And do `sudo nixos-rebuild test -I nixpkgs=<path to your local nixpkgs folder> --fast`.
@@ -71,12 +71,11 @@ Security fixes are submitted in the same way as other changes and thus the same
- If a new version fixing the vulnerability has been released, update the package;
- If the security fix comes in the form of a patch and a CVE is available, then add the patch to the Nixpkgs tree, and apply it to the package.
The name of the patch should be the CVE identifier, so e.g. `CVE-2019-13636.patch`; If a patch is fetched the name needs to be set as well, e.g.:
```nix
(fetchpatch {
name = "CVE-2019-11068.patch";
url = "https://gitlab.gnome.org/GNOME/libxslt/commit/e03553605b45c88f0b4b2980adfbbb8f6fca2fd6.patch";
hash = "sha256-SEKe/8HcW0UBHCfPTTOnpRlzmV2nQPPeL6HOMxBZd14=";
sha256 = "0pkpb4837km15zgg6h57bncp66d5lwrlvkr73h0lanywq7zrwhj8";
})
```
@@ -90,18 +89,17 @@ There is currently no policy when to remove a package.
Before removing a package, one should try to find a new maintainer or fix smaller issues first.
### Steps to remove a package from Nixpkgs {#steps-to-remove-a-package-from-nixpkgs}
### Steps to remove a package from Nixpkgs
We use jbidwatcher as an example for a discontinued project here.
1. Have Nixpkgs checked out locally and up to date.
1. Create a new branch for your change, e.g. `git checkout -b jbidwatcher`
1. Remove the actual package including its directory, e.g. `git rm -rf pkgs/applications/misc/jbidwatcher`
1. Remove the actual package including its directory, e.g. `rm -rf pkgs/applications/misc/jbidwatcher`
1. Remove the package from the list of all packages (`pkgs/top-level/all-packages.nix`).
1. Add an alias for the package name in `pkgs/top-level/aliases.nix` (There is also `pkgs/applications/editors/vim/plugins/aliases.nix`. Package sets typically do not have aliases, so we can't add them there.)
1. Add an alias for the package name in `pkgs/top-level/aliases.nix` (There is also `pkgs/misc/vim-plugins/aliases.nix`. Package sets typically do not have aliases, so we can't add them there.)
For example in this case:
```
jbidwatcher = throw "jbidwatcher was discontinued in march 2021"; # added 2021-03-15
```
@@ -167,30 +165,24 @@ Packages with automated tests are much more likely to be merged in a timely fash
### Tested compilation of all pkgs that depend on this change using `nixpkgs-review` {#submitting-changes-tested-compilation}
If you are updating a packages version, you can use `nixpkgs-review` to make sure all packages that depend on the updated package still compile correctly. The `nixpkgs-review` utility can look for and build all dependencies either based on uncommitted changes with the `wip` option or specifying a GitHub pull request number.
If you are updating a packages version, you can use nixpkgs-review to make sure all packages that depend on the updated package still compile correctly. The `nixpkgs-review` utility can look for and build all dependencies either based on uncommited changes with the `wip` option or specifying a github pull request number.
Review changes from pull request number 12345:
review changes from pull request number 12345:
```ShellSession
nix-shell -p nixpkgs-review --run "nixpkgs-review pr 12345"
nix run nixpkgs.nixpkgs-review -c nixpkgs-review pr 12345
```
Alternatively, with flakes (and analogously for the other commands below):
review uncommitted changes:
```ShellSession
nix run nixpkgs#nixpkgs-review -- pr 12345
nix run nixpkgs.nixpkgs-review -c nixpkgs-review wip
```
Review uncommitted changes:
review changes from last commit:
```ShellSession
nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
```
Review changes from last commit:
```ShellSession
nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD"
nix run nixpkgs.nixpkgs-review -c nixpkgs-review rev HEAD
```
### Tested execution of all binary files (usually in `./result/bin/`) {#submitting-changes-tested-execution}
@@ -199,7 +191,7 @@ Its important to test any executables generated by a build when you change or
### Meets Nixpkgs contribution standards {#submitting-changes-contribution-standards}
The last checkbox is fits [CONTRIBUTING.md](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md). The contributing document has detailed information on standards the Nix community has for commit messages, reviews, licensing of contributions you make to the project, etc... Everyone should read and understand the standards the community has for contributing before submitting a pull request.
The last checkbox is fits [CONTRIBUTING.md](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md). The contributing document has detailed information on standards the Nix community has for commit messages, reviews, licensing of contributions you make to the project, etc\... Everyone should read and understand the standards the community has for contributing before submitting a pull request.
## Hotfixing pull requests {#submitting-changes-hotfixing-pull-requests}
@@ -233,7 +225,7 @@ digraph {
}
```
[This GitHub Action](https://github.com/NixOS/nixpkgs/blob/master/.github/workflows/periodic-merge-6h.yml) brings changes from `master` to `staging-next` and from `staging-next` to `staging` every 6 hours; these are the blue arrows in the diagram above. The purple arrows in the diagram above are done manually and much less frequently. You can get an idea of how often these merges occur by looking at the git history.
[This GitHub Action](https://github.com/NixOS/nixpkgs/blob/master/.github/workflows/merge-staging.yml) brings changes from `master` to `staging-next` and from `staging-next` to `staging` every 6 hours.
### Master branch {#submitting-changes-master-branch}
@@ -242,35 +234,19 @@ The `master` branch is the main development branch. It should only see non-break
### Staging branch {#submitting-changes-staging-branch}
The `staging` branch is a development branch where mass-rebuilds go. Mass rebuilds are commits that cause rebuilds for many packages, like more than 500 (or perhaps, if it's 'light' packages, 1000). It should only see non-breaking mass-rebuild commits. That means it is not to be used for testing, and changes must have been well tested already. If the branch is already in a broken state, please refrain from adding extra new breakages.
During the process of a releasing a new NixOS version, this branch or the release-critical packages can be restricted to non-breaking changes.
The `staging` branch is a development branch where mass-rebuilds go. It should only see non-breaking mass-rebuild commits. That means it is not to be used for testing, and changes must have been well tested already. If the branch is already in a broken state, please refrain from adding extra new breakages.
### Staging-next branch {#submitting-changes-staging-next-branch}
The `staging-next` branch is for stabilizing mass-rebuilds submitted to the `staging` branch prior to merging them into `master`. Mass-rebuilds must go via the `staging` branch. It must only see non-breaking commits that are fixing issues blocking it from being merged into the `master` branch.
The `staging-next` branch is for stabilizing mass-rebuilds submitted to the `staging` branch prior to merging them into `master`. Mass-rebuilds should go via the `staging` branch. It should only see non-breaking commits that are fixing issues blocking it from being merged into the `master ` branch.
If the branch is already in a broken state, please refrain from adding extra new breakages. Stabilize it for a few days and then merge into master.
During the process of a releasing a new NixOS version, this branch or the release-critical packages can be restricted to non-breaking changes.
### Stable release branches {#submitting-changes-stable-release-branches}
The same staging workflow applies to stable release branches, but the main branch is called `release-*` instead of `master`.
For cherry-picking a commit to a stable release branch (“backporting”), use `git cherry-pick -x <original commit>` so that the original commit id is included in the commit.
Example branch names: `release-21.11`, `staging-21.11`, `staging-next-21.11`.
Most changes added to the stable release branches are cherry-picked (“backported”) from the `master` and staging branches.
#### Automatically backporting a Pull Request {#submitting-changes-stable-release-branches-automatic-backports}
Assign label `backport <branch>` (e.g. `backport release-21.11`) to the PR and a backport PR is automatically created after the PR is merged.
#### Manually backporting changes {#submitting-changes-stable-release-branches-manual-backports}
Cherry-pick changes via `git cherry-pick -x <original commit>` so that the original commit id is included in the commit message.
Add a reason for the backport when it is not obvious from the original commit message. You can do this by cherry picking with `git cherry-pick -xe <original commit>`, which allows editing the commit message. This is not needed for minor version updates that include security and bug fixes but don't add new features or when the commit fixes an otherwise broken package.
Add a reason for the backport by using `git cherry-pick -xe <original commit>` instead when it is not obvious from the original commit message. It is not needed when it's a minor version update that includes security and bug fixes but don't add new features or when the commit fixes an otherwise broken package.
Here is an example of a cherry-picked commit message with good reason description:
@@ -289,14 +265,3 @@ Other examples of reasons are:
- Previously the build would fail due to, e.g., `getaddrinfo` not being defined
- The previous download links were all broken
- Crash when starting on some X11 systems
#### Acceptable backport criteria {#acceptable-backport-criteria}
The stable branch does have some changes which cannot be backported. Most notable are breaking changes. The desire is to have stable users be uninterrupted when updating packages.
However, many changes are able to be backported, including:
- New Packages / Modules
- Security / Patch updates
- Version updates which include new functionality (but no breaking changes)
- Services which require a client to be up-to-date regardless. (E.g. `spotify`, `steam`, or `discord`)
- Security critical applications (E.g. `firefox`)

View File

@@ -1,5 +1,6 @@
{ pkgs ? (import ./.. { }), nixpkgs ? { }}:
let
lib = pkgs.lib;
doc-support = import ./doc-support { inherit pkgs nixpkgs; };
in pkgs.stdenv.mkDerivation {
name = "nixpkgs-manual";
@@ -14,16 +15,12 @@ in pkgs.stdenv.mkDerivation {
xmlformat
];
src = pkgs.nix-gitignore.gitignoreSource [] ./.;
src = lib.cleanSource ./.;
postPatch = ''
ln -s ${doc-support} ./doc-support/result
'';
preBuild = ''
make -j$NIX_BUILD_CORES render-md
'';
installPhase = ''
dest="$out/share/doc/nixpkgs"
mkdir -p "$(dirname "$dest")"
@@ -39,5 +36,4 @@ in pkgs.stdenv.mkDerivation {
# Environment variables
PANDOC_LUA_FILTERS_DIR = "${pkgs.pandoc-lua-filters}/share/pandoc/filters";
PANDOC_LINK_MANPAGES_FILTER = import build-aux/pandoc-filters/link-manpages.nix { inherit pkgs; };
}

View File

@@ -1,25 +1,7 @@
{ pkgs ? (import ../.. {}), nixpkgs ? { }}:
let
inherit (pkgs) lib;
inherit (lib) hasPrefix removePrefix;
libsets = [
{ name = "asserts"; description = "assertion functions"; }
{ name = "attrsets"; description = "attribute set functions"; }
{ name = "strings"; description = "string manipulation functions"; }
{ name = "versions"; description = "version string functions"; }
{ name = "trivial"; description = "miscellaneous functions"; }
{ name = "lists"; description = "list manipulation functions"; }
{ name = "debug"; description = "debugging functions"; }
{ name = "options"; description = "NixOS / nixpkgs option handling"; }
{ name = "path"; description = "path functions"; }
{ name = "filesystem"; description = "filesystem functions"; }
{ name = "sources"; description = "source filtering functions"; }
{ name = "cli"; description = "command-line serialization functions"; }
];
locationsXml = import ./lib-function-locations.nix { inherit pkgs nixpkgs libsets; };
functionDocs = import ./lib-function-docs.nix { inherit locationsXml pkgs libsets; };
locationsXml = import ./lib-function-locations.nix { inherit pkgs nixpkgs; };
functionDocs = import ./lib-function-docs.nix { inherit locationsXml pkgs; };
version = pkgs.lib.version;
epub-xsl = pkgs.writeText "epub.xsl" ''
@@ -41,29 +23,6 @@ let
<xsl:import href="${./parameters.xml}"/>
</xsl:stylesheet>
'';
# NB: This file describes the Nixpkgs manual, which happens to use module
# docs infra originally developed for NixOS.
optionsDoc = pkgs.nixosOptionsDoc {
inherit (pkgs.lib.evalModules {
modules = [ ../../pkgs/top-level/config.nix ];
class = "nixpkgsConfig";
}) options;
documentType = "none";
transformOptions = opt:
opt // {
declarations =
map
(decl:
if hasPrefix (toString ../..) (toString decl)
then
let subpath = removePrefix "/" (removePrefix (toString ../..) (toString decl));
in { url = "https://github.com/NixOS/nixpkgs/blob/master/${subpath}"; name = subpath; }
else decl)
opt.declarations;
};
};
in pkgs.runCommand "doc-support" {}
''
mkdir result
@@ -71,14 +30,13 @@ in pkgs.runCommand "doc-support" {}
cd result
ln -s ${locationsXml} ./function-locations.xml
ln -s ${functionDocs} ./function-docs
ln -s ${optionsDoc.optionsDocBook} ./config-options.docbook.xml
ln -s ${pkgs.docbook5}/xml/rng/docbook/docbook.rng ./docbook.rng
ln -s ${pkgs.docbook_xsl_ns}/xml/xsl ./xsl
ln -s ${epub-xsl} ./epub.xsl
ln -s ${xhtml-xsl} ./xhtml.xsl
ln -s ${./xmlformat.conf} ./xmlformat.conf
ln -s ${../../nixos/doc/xmlformat.conf} ./xmlformat.conf
ln -s ${pkgs.documentation-highlighter} ./highlightjs
echo -n "${version}" > ./version

View File

@@ -1,36 +1,26 @@
# Generates the documentation for library functions via nixdoc.
# Generates the documentation for library functons via nixdoc. To add
# another library function file to this list, the include list in the
# file `doc/functions/library.xml` must also be updated.
{ pkgs, locationsXml, libsets }:
{ pkgs ? import ./.. {}, locationsXml }:
with pkgs; stdenv.mkDerivation {
name = "nixpkgs-lib-docs";
src = ../../lib;
src = ./../../lib;
buildInputs = [ nixdoc ];
installPhase = ''
function docgen {
# TODO: wrap lib.$1 in <literal>, make nixdoc not escape it
if [[ -e "../lib/$1.nix" ]]; then
nixdoc -c "$1" -d "lib.$1: $2" -f "$1.nix" > "$out/$1.xml"
else
nixdoc -c "$1" -d "lib.$1: $2" -f "$1/default.nix" > "$out/$1.xml"
fi
echo "<xi:include href='$1.xml' />" >> "$out/index.xml"
nixdoc -c "$1" -d "$2" -f "../lib/$1.nix" > "$out/$1.xml"
}
mkdir -p "$out"
cat > "$out/index.xml" << 'EOF'
<?xml version="1.0" encoding="utf-8"?>
<root xmlns:xi="http://www.w3.org/2001/XInclude">
EOF
${lib.concatMapStrings ({ name, description }: ''
docgen ${name} ${lib.escapeShellArg description}
'') libsets}
echo "</root>" >> "$out/index.xml"
mkdir -p $out
ln -s ${locationsXml} $out/locations.xml
docgen strings 'String manipulation functions'
docgen trivial 'Miscellaneous functions'
docgen lists 'List manipulation functions'
docgen debug 'Debugging functions'
docgen options 'NixOS / nixpkgs option handling'
'';
}

View File

@@ -1,24 +1,24 @@
{ pkgs, nixpkgs ? { }, libsets }:
{ pkgs ? (import ./.. { }), nixpkgs ? { }}:
let
revision = pkgs.lib.trivial.revisionWithDefault (nixpkgs.rev or "master");
revision = pkgs.lib.trivial.revisionWithDefault (nixpkgs.revision or "master");
libDefPos = prefix: set:
builtins.concatMap
(name: [{
name = builtins.concatStringsSep "." (prefix ++ [name]);
libDefPos = set:
builtins.map
(name: {
name = name;
location = builtins.unsafeGetAttrPos name set;
}] ++ nixpkgsLib.optionals
(builtins.length prefix == 0 && builtins.isAttrs set.${name})
(libDefPos (prefix ++ [name]) set.${name})
) (builtins.attrNames set);
})
(builtins.attrNames set);
libset = toplib:
builtins.map
(subsetname: {
subsetname = subsetname;
functions = libDefPos [] toplib.${subsetname};
functions = libDefPos toplib.${subsetname};
})
(builtins.map (x: x.name) libsets);
(builtins.filter
(name: builtins.isAttrs toplib.${name})
(builtins.attrNames toplib));
nixpkgsLib = pkgs.lib;

View File

@@ -2,18 +2,13 @@
<xsl:stylesheet
xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
version="1.0">
<xsl:param name="chapter.autolabel" select="0" />
<xsl:param name="part.autolabel" select="0" />
<xsl:param name="preface.autolabel" select="0" />
<xsl:param name="reference.autolabel" select="0" />
<xsl:param name="section.autolabel" select="0" />
<xsl:param name="section.autolabel" select="1" />
<xsl:param name="section.label.includes.component.label" select="1" />
<xsl:param name="html.stylesheet" select="'style.css overrides.css highlightjs/mono-blue.css'" />
<xsl:param name="html.script" select="'./highlightjs/highlight.pack.js ./highlightjs/loader.js'" />
<xsl:param name="xref.with.number.and.title" select="0" />
<xsl:param name="xref.with.number.and.title" select="1" />
<xsl:param name="use.id.as.filename" select="1" />
<xsl:param name="generate.section.toc.level" select="1" />
<xsl:param name="toc.section.depth" select="0" />
<xsl:param name="admon.style" select="''" />
<xsl:param name="callout.graphics.extension" select="'.svg'" />
<xsl:param name="generate.consistent.ids" select="1" />
</xsl:stylesheet>

View File

@@ -7,8 +7,8 @@
The nixpkgs repository has several utility functions to manipulate Nix expressions.
</para>
<xi:include href="functions/library.xml" />
<xi:include href="functions/generators.section.xml" />
<xi:include href="functions/debug.section.xml" />
<xi:include href="functions/prefer-remote-fetch.section.xml" />
<xi:include href="functions/nix-gitignore.section.xml" />
<xi:include href="functions/generators.xml" />
<xi:include href="functions/debug.xml" />
<xi:include href="functions/prefer-remote-fetch.xml" />
<xi:include href="functions/nix-gitignore.xml" />
</chapter>

View File

@@ -1,5 +0,0 @@
# Debugging Nix Expressions {#sec-debug}
Nix is a unityped, dynamic language, this means every value can potentially appear anywhere. Since it is also non-strict, evaluation order and what ultimately is evaluated might surprise you. Therefore it is important to be able to debug nix expressions.
In the `lib/debug.nix` file you will find a number of functions that help (pretty-)printing values while evaluation is running. You can even specify how deep these values should be printed recursively, and transform them on the fly. Please consult the docstrings in `lib/debug.nix` for usage information.

14
doc/functions/debug.xml Normal file
View File

@@ -0,0 +1,14 @@
<section xmlns="http://docbook.org/ns/docbook"
xmlns:xlink="http://www.w3.org/1999/xlink"
xmlns:xi="http://www.w3.org/2001/XInclude"
xml:id="sec-debug">
<title>Debugging Nix Expressions</title>
<para>
Nix is a unityped, dynamic language, this means every value can potentially appear anywhere. Since it is also non-strict, evaluation order and what ultimately is evaluated might surprise you. Therefore it is important to be able to debug nix expressions.
</para>
<para>
In the <literal>lib/debug.nix</literal> file you will find a number of functions that help (pretty-)printing values while evaluation is runnnig. You can even specify how deep these values should be printed recursively, and transform them on the fly. Please consult the docstrings in <literal>lib/debug.nix</literal> for usage information.
</para>
</section>

Some files were not shown because too many files have changed in this diff Show More